head 1.38; access; symbols pkgsrc-2026Q3:1.38.0.2 pkgsrc-2026Q3-base:1.38 pkgsrc-2026Q2:1.36.0.2 pkgsrc-2026Q2-base:1.36 pkgsrc-2026Q1:1.35.0.2 pkgsrc-2026Q1-base:1.35 pkgsrc-2025Q4:1.30.0.2 pkgsrc-2025Q4-base:1.30 pkgsrc-2025Q3:1.27.0.2 pkgsrc-2025Q3-base:1.27 pkgsrc-2025Q2:1.25.0.2 pkgsrc-2025Q2-base:1.25 pkgsrc-2025Q1:1.22.0.2 pkgsrc-2025Q1-base:1.22 pkgsrc-2024Q4:1.19.0.2 pkgsrc-2024Q4-base:1.19 pkgsrc-2024Q3:1.17.0.2 pkgsrc-2024Q3-base:1.17 pkgsrc-2024Q2:1.13.0.2 pkgsrc-2024Q2-base:1.13 pkgsrc-2024Q1:1.12.0.2 pkgsrc-2024Q1-base:1.12 pkgsrc-2023Q4:1.10.0.2 pkgsrc-2023Q4-base:1.10 pkgsrc-2023Q3:1.6.0.2 pkgsrc-2023Q3-base:1.6 pkgsrc-2023Q2:1.3.0.2 pkgsrc-2023Q2-base:1.3; locks; strict; comment @# @; 1.38 date 2026.09.02.19.19.31; author wiz; state Exp; branches; next 1.37; commitid zpzI5PV474Zt65UG; 1.37 date 2026.06.25.08.25.50; author wiz; state Exp; branches; next 1.36; commitid Fg5R4ok5Lg1OG9LG; 1.36 date 2026.04.29.07.05.49; author wiz; state Exp; branches 1.36.2.1; next 1.35; commitid ovGneyvPmNa86PDG; 1.35 date 2026.03.11.07.08.39; author wiz; state Exp; branches 1.35.2.1; next 1.34; commitid 51uwF0XR6IxKGwxG; 1.34 date 2026.01.19.19.25.40; author gutteridge; state Exp; branches; next 1.33; commitid LseGcsO72VdFk2rG; 1.33 date 2026.01.12.11.03.55; author mef; state Exp; branches; next 1.32; commitid wqhxjYDfVNurQ5qG; 1.32 date 2026.01.12.09.09.09; author mef; state Exp; branches; next 1.31; commitid aOmD0kHCJYbHd5qG; 1.31 date 2026.01.07.08.06.33; author wiz; state Exp; branches; next 1.30; commitid XVnCL6Y0dcw92rpG; 1.30 date 2025.11.05.09.30.18; author wiz; state Exp; branches; next 1.29; commitid px4c4WKsLlMrwlhG; 1.29 date 2025.10.24.03.59.51; author riastradh; state Exp; branches; next 1.28; commitid 2eyC8ALAqOg15MfG; 1.28 date 2025.10.05.19.16.03; author js; state Exp; branches; next 1.27; commitid 9JaPjKj3Fx79LpdG; 1.27 date 2025.09.12.07.32.12; author wiz; state Exp; branches; next 1.26; commitid DdEIbjQzKh3yBoaG; 1.26 date 2025.08.26.15.08.11; author leot; state Exp; branches; next 1.25; commitid 8Ykex2NJIg7MFf8G; 1.25 date 2025.06.05.04.43.21; author adam; state Exp; branches; next 1.24; commitid W3DkmBzhdzuOQEXF; 1.24 date 2025.05.28.09.43.53; author wiz; state Exp; branches; next 1.23; commitid qOG5zAqfxeCAKEWF; 1.23 date 2025.04.16.21.27.24; author adam; state Exp; branches; next 1.22; commitid R3xcEJsN1pKT0kRF; 1.22 date 2025.02.13.18.24.34; author adam; state Exp; branches; next 1.21; commitid 0vkUGF1zIwPJZkJF; 1.21 date 2025.02.09.00.28.21; author rillig; state Exp; branches; next 1.20; commitid INWsP1OU4yG5aJIF; 1.20 date 2025.02.05.08.51.31; author wiz; state Exp; branches; next 1.19; commitid SJXK3RA6Xg2X4gIF; 1.19 date 2024.12.11.09.24.32; author wiz; state Exp; branches; next 1.18; commitid LkfK5LzQSTE844BF; 1.18 date 2024.11.06.08.19.26; author wiz; state Exp; branches; next 1.17; commitid 9ZDyoXwpX4WsPywF; 1.17 date 2024.09.18.10.49.50; author adam; state Exp; branches; next 1.16; commitid 707AsNoNM0aJehqF; 1.16 date 2024.09.12.19.19.09; author adam; state Exp; branches; next 1.15; commitid qmhH0cnfv1DnfypF; 1.15 date 2024.07.31.08.02.35; author adam; state Exp; branches; next 1.14; commitid qzmZbEAsPfrYSXjF; 1.14 date 2024.07.24.07.28.04; author wiz; state Exp; branches; next 1.13; commitid DX9Kz6ObiQjbV3jF; 1.13 date 2024.05.23.04.15.35; author adam; state Exp; branches; next 1.12; commitid iys24LZwCyKsQ4bF; 1.12 date 2024.03.27.13.53.35; author wiz; state Exp; branches; next 1.11; commitid pDht3uMqK8DASN3F; 1.11 date 2024.01.31.07.21.08; author wiz; state Exp; branches; next 1.10; commitid 7VFJhhcbraswvzWE; 1.10 date 2023.12.07.07.50.54; author wiz; state Exp; branches; next 1.9; commitid WMAtlUogIrWmrvPE; 1.9 date 2023.10.22.13.34.31; author js; state Exp; branches; next 1.8; commitid gJhHQSDLZgSxOCJE; 1.8 date 2023.10.11.07.16.03; author adam; state Exp; branches; next 1.7; commitid T4Q2lxBgB4rQ4bIE; 1.7 date 2023.09.29.10.45.04; author tnn; state Exp; branches; next 1.6; commitid dAZl3hJDVWWzCEGE; 1.6 date 2023.09.13.08.15.05; author adam; state Exp; branches 1.6.2.1; next 1.5; commitid wgIhh7e2Z5NXiAEE; 1.5 date 2023.07.26.08.31.17; author adam; state Exp; branches; next 1.4; commitid OuGJtSV5xAkcYhyE; 1.4 date 2023.07.19.08.06.20; author wiz; state Exp; branches; next 1.3; commitid e4raWfX5tbhE3oxE; 1.3 date 2023.06.09.12.52.12; author riastradh; state Exp; branches; next 1.2; commitid KzszMHhvJNRtVgsE; 1.2 date 2023.05.31.20.19.46; author nikita; state Exp; branches; next 1.1; commitid lD5bw1viJdlIG9rE; 1.1 date 2023.05.31.20.17.52; author nikita; state Exp; branches; next ; commitid 91og5lNBaaVbG9rE; 1.36.2.1 date 2026.06.28.11.52.24; author bsiegert; state Exp; branches; next ; commitid 157FW2ouCjmTKyLG; 1.35.2.1 date 2026.05.07.22.32.38; author maya; state Exp; branches; next ; commitid Pkj4PKzHOTP9YVEG; 1.6.2.1 date 2023.10.13.09.38.41; author bsiegert; state Exp; branches; next ; commitid TCZilKP5EYvZNrIE; desc @@ 1.38 log @curl: update to 8.22.0. This release includes the following changes: o gssapi: add support for Apple GSS Framework [72] o hardening: add API guards [64] o RFC 9421 HTTP Message Signatures support [108] o spnego: block NTLM fallback in SPNEGO negotiation [151] o TLS: drop support for TLS-SRP [71] o vquic: add option to use Apple fast UDP [137] This release includes the following bugfixes: o altsvc: continue after unknown parameters [198] o asyn-thrdd: retry link-local ipv6 if missing scope id [118] o autotools: minor fixes and improvements [33] o build: always use local `inet_pton()`/`inet_ntop()` implementations [56] o build: assume POSIX `select()` is available [166] o build: clear `Require.private` for static-only builds in `libcurl.pc` [188] o build: drop `dirent.h` and `opendir()` detections on Windows [186] o build: drop detecting `gettimeofday()` on Windows [184] o build: drop superfluous `STDC_HEADERS` macro [51] o build: enable thread-safe `getaddrinfo()` for OpenBSD [35] o build: minor debug option message fixes/improvements [200] o build: require `!NDEBUG` for debug-enabled (aka development) builds [202] o build: strip duplicate spaces after `Libs.private:` in `libcurl.pc` [191] o build: strip trailing spaces from `libcurl.pc` [194] o cd2nroff: fix backslashes for 4-space indent lines [104] o cd2nroff: stricter checks for asterisks for italics [73] o cf-ngtcp2-cmn: de-duplicate `ngtcp2_conn_client_new()` call code [156] o cf-ngtcp2-cmn: initialize new callback ptr for ngtcp2 1.24.0+ [52] o cf-socket: avoid broken NetBSD SOCK_NONBLOCK [275] o cf-socket: disable TCP SYN retransmissions for localhost on Windows [164] o cfilters: fix event-based connection shutdown [91] o clock: save one call [286] o cmake/FindLibgsasl: fix to set `LIBGSASL_VERSION` with pkg-config detection [229] o cmake: check libgsasl version at configure time [277] o cmake: dedupe expressions into local vars in `cmake_uninstall.in.cmake` [9] o cmake: fix not to build `tunits` when `BUILD_CURL_EXE=OFF` [7] o cmake: flatten build tree, tidy up base dir variables [12] o cmake: minor improvements to `cmake_uninstall.in.cmake` [54] o cmake: optimize OpenSSL fork detection [228] o cmake: replace `remove` command with `rm` and pass arg safely [11] o cmake: robustify base path in local file reference [15] o cmake: stop probing unused `float.h` for `STDC_HEADERS` [10] o cmake: use built-in variable and target property dump functions with CMake 4.5+ [155] o config-riscos.h: delete handcrafted RISC OS config header, in favor of autotools [178] o config-win32.h: drop UWP, c-ares, simplify more [231] o config-win32.h: limit use to MSVC IDE Project builds [193] o configure: clarify --enable-debug option [133] o configure: fix misleading error messages [42] o configure: link `-lcrypt32` instead of `-lm` for wolfSSL on Windows [79] o configure: only check in the watt library if WATT_ROOT is set [120] o configure: remove double check for GnuTLS [21] o configure: set ldap lib to no by default for non-finds [18] o conncache: apply multi limits to transfers using a shared pool [41] o conncache: conn upkeep/alive: move and enhance [152] o conncache: connection alive checks intervals [20] o conncache: don't assume curl_off_t increment wrap-around [138] o conncache: guess maxconnects different [289] o connect: connection close tweaks [112] o connect: only set connect timer on first socket [206] o connection reuse: age check [261] o connection reuse: check SSL configs when doing a scheme upgrade [249] o connections: use admin handles only for maintenance [213] o content_encoding: exact-match the identity transfer-coding token [189] o content_encoding: give a clear error on multi-member gzip [46] o cookie: cookies set for an exact PSL domain is host-only [304] o cookie: improve TAB handling [258] o cookie: refuse to load cookies set against a PSL domain [139] o CREDENTIALS.md: remove comment about empty user/pass [50] o ctype: exclude control bytes from ISPRINT and ISGRAPH [119] o curl: help category cleanups [169] o curl_gssapi: document/update feature availability [145] o curl_threads: always use native threads/mutex on Windows [185] o curl_trc: remove unused expire timers [147] o curl_url_set.md: expand the CURLU_NO_AUTHORITY description [134] o curl_ws_meta.md: polish and better vocabulary [19] o CURLOPT_HEADERFUNCTION.md: document folded header unfolding [53] o CURLOPT_SOCKOPTFUNCTION.md: ALREADY_CONNECTED does not work for HTTP/3 [262] o CURLOPT_SSH_*_KEYFILE: used for setting up, then no more [48] o CURLOPT_UNRESTRICTED_AUTH.md: 'Authorization', not 'Authentication' [74] o CURLOPT_USERNAME.md: ambient username caveats [271] o CURLSHOPT_(UN)SHARE.md: do not modify shares while in use [44] o curlx_inet_ntop: return `CURLcode`, drop setting `errno` [237] o curlx_inet_pton: drop setting `errno` on error [236] o DEPRECATE.md: HTTP/2 Server Push gets removed in March 2027 [174] o dict: avoid busy-loop in sendf() when the socket is not writable [99] o dist: fix to drop test bundle .c files from the source tarball [305] o dnsd: fix bounds check in `read_https_alpn_part()` [143] o docs/INTERNALS.md -> docs/DEPENDENCIES.md [127] o docs: clarify that cookies need domain set to match [224] o docs: connection reuse behavior for socket callbacks [219] o docs: make 5 example snippets compile cleanly with clang [192] o docs: mention possible auth option conflicts [114] o docs: remove doubled word in SECURITY-ADVISORY.md [183] o DoH: improvements [203] o easy: fix unused global on non-Windows [292] o easy_lock: silence `portability-no-assembler` with clang-tidy 23.1.0+ [291] o FAQ: correct an option typo [278] o file: support directory listing on Windows [205] o filter: change time reporting [235] o FTP: fix TLS session reuse on the data connection [80] o ftp: reject control bytes in ACCT and alternative-to-user [26] o gitignore: maintenance updates [170] o gopher: fix partial sends of CRLF [288] o gopher: reject CR and LF in the selector [1] o h2 push: use squeaky clean easy handle [246] o h2: bootstrap max streams from multi handle if in use [132] o h3-proxy: fix NULL deref when non-:status header arrives before :status [167] o Happy Eyeballing v3: resolution delay of 25ms [232] o header api: add guards [168] o headers: name the arguments the way the definitions name them [234] o HISTORY.md: PSL support in 2015 o HISTORY: add when c-ares support was introduced (2004) o HISTORY: September 1999: started using CVS o hostip: only cache negative resolves for authoritative answers [16] o hsts: only match the exact strings [269] o http digest: tie peer/credentials on input [264] o http2: make server push transfers inherit share from parent [81] o http2: remove assert in ingress processing [272] o http: avoid length underflow in Curl_compareheader [78] o http: custom Authorization: header overrides Negotiate [223] o http: fix non-tunneling proxy hostname use [116] o http: stop dropping large custom headers [69] o http: trim custom header name before the Authorization drop [17] o httpsrr: DoH with HTTPS, fix response handling [113] o idn: restore `MultiByteToWideChar()` `MB_ERR_INVALID_CHARS` flag [103] o imap: APPEND CRLF fix [256] o include: include when building for modern Linux. [308] o INSTALL.md: add building-from-source overview section [29] o INTERNALS.md: require quiche 0.20.0+ [101] o ipv6 scope_id: set from first peer [242] o keylog: add a random size argument to Curl_tls_keylog_write() [180] o ldap: base64-encode LDIF values beginning with colon or less-than [218] o ldap: reject control characters in URL-decoded filter values [196] o ldap: support empty username and password [106] o ldap: support insecure mode for Windows native LDAP [3] o lib1587: fix gcc `-Wconversion` with LibreSSL on Windows, test in CI [6] o lib2405: adjust for non-threaded builds [149] o lib: add "Curl_" prefix to two global functions [84] o lib: add multi_wakeup_internal [86] o lib: drop unused `system_win32.h` includes [290] o lib: fix 'ns' -> 'us' in trace messages [57] o lib: new easy option string storage [215] o lib: optimize struct layouts for reduced memory usage [212] o lib: ratelimit timestamps [14] o lib: silence gcc-16 compiler warnings `-Wmaybe-uninitialized` [243] o lib: update mentions of the legacy "sessionhandle" [157] o libcurl.md: emphasize that the output needs checking [259] o libcurl.pc: add `License` tag [190] o libcurl.pc: add Copyright tag to the pkgconf file o libcurl.pc: add the Link.ABI and Source tags [210] o macos sectrust: fail ocsp verify when not builtin [252] o Makefile.am: improve etags [257] o mbedtls: enforce verifyhost when verifypeer is disabled [208] o mbedtls: replace `memset()` with `psa_hash_operation_init()` [28] o md5: replace magic numbers with `MD5_DIGEST_LEN` [122] o mime.c: avoid integer overflow in base64 size calculation [105] o mime: reject CR and LF in mail part name and filename [30] o mod_curltest: fix compiler warnings [49] o mprintf: acknowledge %F [245] o mprintf: avoid never-ending loop for positive-infinite [247] o mprintf: fix long double output [250] o mqtt: reject control bytes in the topic [43] o multi: cap expire times to INT_MAX internally [216] o multi: forbid curl_easy_pause from within multi socket callback [22] o multi: hold timeout values in 'int' instead of 'long' [165] o multi: remove #if 0'ed code that uses old struct [150] o multi: shrink expire timer indices [199] o multi: timeout improvements [209] o multi: use index list for expire timeouts [197] o multi: xfer table initial size and growth [255] o multihandle: move two struct fields [163] o ngtcp2+openssL: fix early data [225] o ngtcp2: avoid NULL deref in cf_ngtcp2_send [260] o ngtcp2: clean up after ngtcp2 in `curl_global_cleanup` [126] o ngtcp2: let verify failures win over expiry processing errors [98] o openldap: handle Curl_sasl_continue() returns better [45] o openssl+sectrust: fix session reuse [4] o openssl+sectrust: move session verified set into result check [82] o openssl: avoid conn reuse if provider is used [214] o openssl: avoid strlen() on the data from OpenSSL [280] o openssl: aws-lc ocsp workaround [263] o openssl: drop unused pre-OpenSSL3 `ctx_option_t` typedef [8] o openssl: fix DER buffer leak in Apple SecTrust verification [217] o openssl: no server cert is only okay if also not pinned [226] o openssl: prefer modern API flavors for `EVP_MD_CTX` new/free [47] o openssl: replace stray legacy API variant with `EVP_DigestInit_ex()` [27] o os400: port latest header files changes to ILE/RPG interface [241] o os400: rewrite upper ebcdic wrappers using dynbuf [227] o progress: cleanup, less memory [179] o protocol: simpler Curl_getn_scheme runs faster [239] o proxy: CONNECT trailers handling [251] o psl: update a comment to understandable English [162] o pytest: update two H3 tests for nghttp3 1.18.0+ [158] o quic: upload improvements [276] o quiche: set the max field section size [100] o rtsp: refactor method handling and improve error checks [161] o runtests: allow comments in `setenv` section, merge sections in test433 [89] o runtests: fix `mode="warn"` tests passing unconditionally, fix test 1752 [66] o runtests: flush cached test parts when (re)loading a file [95] o runtests: restore `-k` option and actively process as no-op [32] o sasl: fix zero-length response encoding [36] o schannel: add ALPN support for mingw-w64 <9 and =128-bit pointers [107] o url: fix handling of empty user in NTLM matching [221] o url: fix negotiate/ntlm connection reuse [176] o url: reject control codes in credentials set via CURLOPT [70] o urlapi: allow URLs to not have userauth (hostname) [92] o urlapi: avoid dedotdotify() if possible [182] o urlapi: clear password buffer on error path [121] o urlapi: do not keep an internal port string [31] o urlapi: improved return codes [148] o urlapi: preserve empty markers in relative URLs [61] o urldata: cleanups [175] o urldata: drop four strings from the aptr struct [136] o urldata: sort the connectdata struct fields by size [177] o VERSIONS.md: document Rock-solid curl releases [201] o vms: fix symbol typo and missing closing quotes in `config_h.com` [124] o vquic: add Curl_ prefix to some global functions [76] o vquic: initialize new callback slot for nghttp3 v1.18.0+ [87] o vquic: silence `-Wmissing-field-initializers` for nghttp3/ngtcp2 callback tables [159] o vquic: use ngtcp2 v1.25.0 new close2 callback [154] o vssh: keyfile use cleanups [83] o vssh: silence gcc-11 `-Wnull-dereference`, dedupe `CURL_EASY_STR()` calls [240] o vtls: move 'native_ca_store' ssl_config_data => ssl_primary_config [211] o vtls_scache: use case sensitive path match o VULN-DISCLOSURE-POLICY.md: issues that should be found by tests are LOW [5] o wcurl: import v2026.08.30 [279] o websocket: pause writing and meta data fix [135] o winsock: drop redundant version checks at initialization [284] o wolfssl: do not run Curl_wssl_setup_x509_store() twice [265] o wolfssl: fix build for wolfssl without bio chain support [75] o ws: fix write callback error handling [204] o ws: pause/unpause write handling [55] @ text @# $NetBSD: Makefile.common,v 1.37 2026/06/25 08:25:50 wiz Exp $ # used by www/libcurl-gnutls/Makefile DISTNAME= curl-8.22.0 CATEGORIES= www MASTER_SITES= https://curl.se/download/ EXTRACT_SUFX= .tar.xz MAINTAINER= leot@@NetBSD.org HOMEPAGE= https://curl.se/ COMMENT= Client that groks URLs # not completely, but near enough LICENSE= mit DISTINFO_FILE?= ${.CURDIR}/../../www/curl/distinfo PATCHDIR?= ${.CURDIR}/../../www/curl/patches BUILD_DEFS+= IPV6_READY TEST_DEPENDS+= ${PYPKGPREFIX}-impacket-[0-9]*:../../net/py-impacket USE_TOOLS+= nroff perl USE_LIBTOOL= yes GNU_CONFIGURE= yes GNU_CONFIGURE_ICONV= no # Some systems use bundles instead of directories; this needs configuring # because curl doesn't use default validation. .if !empty(SSLCERTBUNDLE) CONFIGURE_ARGS+= --with-ca-bundle=${SSLCERTBUNDLE} .else CONFIGURE_ARGS+= --with-ca-path=${SSLCERTS} .endif CONFIGURE_ARGS+= --with-zlib=${BUILDLINK_PREFIX.zlib} CONFIGURE_ARGS+= --without-libpsl PKGCONFIG_OVERRIDE= libcurl.pc.in TEST_TARGET= check REPLACE_PERL+= tests/*.pl tests/*/*.pl REPLACE_PYTHON+= tests/*.py PYTHON_FOR_BUILD_ONLY= test .include "../../devel/gettext-lib/buildlink3.mk" .include "../../devel/zlib/buildlink3.mk" .include "../../lang/python/application.mk" .include "../../mk/pthread.buildlink3.mk" @ 1.37 log @curl: update to 8.21.0. Lots of security fixes. Changes: curl: named globs in output filename for upload glob references HTTP/3: add proxy CONNECT and MASQUE CONNECT-UDP support (ngtcp2 QUIC) http2: remove stream dependency tracking lib: drop support for CURLAUTH_DIGEST_IE libssh: add support for SHA256 host public keys tool_urlglob: add named globs Bugfixes: _ENVIRONMENT.md. Windows does case insensitive env variables _URL.md: remove the zone-id mention AmigaOS: curl_setup.h avoid explicit_bzero with clib2 AmigaOS: fix build fallouts, re-add to CI asyn-thrdd: add IPv6 guards asyn-thrdd: fix result processing without wakeup socketpair autotools: mbedtls detection fixes BINDINGS: Update Hollywood link BUFQ.md: re-sync with source code build: enable `-Wlogical-op` picky warning for GCC 4.4+ build: omit zlib pkg-config reference for Android cf-h2-prox: fix peer leak cf-h2-proxy: drop interim responses cf-https-connect: do not engage on proxy origin cf-ip-happy.c: minor comment typo cf-ip-happy: update documentation cf-socket: make Curl_addr2string static cf-socket: set scope_id for IPv6 link-local addresses cf-socket: store errno from do_connect in ctx->error cfilters: fix busy loop on blocked transfers chunked: reject invalid bytes in trailer CIPHERS.md: fix the example that uses only TLS 1.3 cmake/FindGSS: drop "MIT Unknown" version value, related tidy ups cmake/FindGSS: drop CMake <3.16 compatibility logic cmake/FindGSS: fix comment, adjust custom flavor property name cmake/FindGSS: prioritize MIT over GNU in pkg-config detection cmake: auto-select static nghttp2/nghttp3/ngtcp2 Config cmake: export/forward `NGTCP2_CRYPTO_BACKEND` cmake: fix three issues generating lib options in config files cmake: fix zstd CMake config name cmake: opt in `MSVC_VERSION` 1951 to picky warnings cmake: quote `COMPONENTS` string in `curl-config.in.cmake` cmake: simplify `LINK_ONLY` imported target extraction config2setopts: use default protocol properly connect: remove deref of freed pointer in trace call content_encoding: fix limit failure message content_encoding: fix non-last chunked rejection content_encoding: timeout during slow decoding cookie: check __Secure- and __Host- case sensitively when read from file cookie: compare path case sensitively cookie: reject control octets in file-loaded cookies cookie: simplify strstore(), remove outdated comment cookie: tailmatch the domains for secure override cookie: trim trailing dots when checking PSL creds: add sasl service name creds: create with empty user+pass creds: mask OAuth bearer token in trace logs creds: remove two unused functions curl_easy_pause.md: rephrase the stream cache when pause clause curl_easy_setopt.md: change options when no transfer runs curl_formdata: fix to pass long where missing, document `CURLFORM_NAMELENGTH` curl_multi_assign.md: clarify lifetime curl_ntlm_core: fix nettle 4+ builds in certain MultiSSL combos curl_ntlm_core: propagate DES `CryptEncrypt()` error curl_sha512_256: fix result code on error CURLINFO_CONTENT_LENGTH_UPLOAD_T.md: expand CURLMOPT_SOCKETFUNCTION.md: this sends *all* file descriptors CURLOPT_CHUNK_BGN_FUNCTION: target is there for symlinks only CURLOPT_DISALLOW_USERNAME_IN_URL: is for CURLOPT_URL only CURLOPT_DOH_URL.md: does not inherit proxy options CURLOPT_ECH.md: simplify the description language CURLOPT_HAPROXYPROTOCOL.md: only sent for newly setup connections CURLOPT_MAXFILESIZE: clarify this also works for on-going transfers CURLOPT_PINNEDPUBLICKEY.md: does not apply for other origins CURLOPT_PORT.md: use stronger language CURLOPT_SHARE: warn about early remove CURLOPT_SSH_HOSTKEYFUNCTION.md: for new connections only CURLOPT_WRITEFUNCTION.md: mention redirects CURLOPT_WRITEFUNCTION.md: remove stray reference to HSTS delta: harden external command invocations digest: escape control codes too digest: flush proxy state on proxy or credential change digest: flush state on origin or credential change dns-httpsrr-lookup: use origin, not peer dnscache: remove Curl_dns_entry_link docs/libcurl: fix the version for curl_multi_socket_action docs: end "...can be used several times..." sentences with period docs: fix --follow doc typo docs: fix a couple of typos docs: fix grammar and wording in FAQ docs: fix odd wording in CONTRIBUTE.md docs: note CURLOPT_PINNEDPUBLICKEY has no effect on legacy LDAP backend docs: returned header size reflects HTTP/1-style format doh: cap the maximum TTL to 24 hours doh: stricter HTTPS RNAME parsing ECH: cleanups event: fix wakeup consumption ftp: avoid accessing EPSV response one byte past the NULL ftp: remove 2 Curl_resolv_blocking() calls ftp: remove bits.ftp_use_control_ssl ftplistparser: clear strings.target if not symlink gnutls: allow building with nettle 4.0 gnutls: fix more nettle 4+ compatibility issues gnutls: require 3.7.2 for earlydata gsasl: fix potential double free gtls: fix ignored return and uninitialized status in OCSP check gtls: fix some typos gtls: minor fixes and improvements gtls: use the correct return code in trace output gtls: verify OCSP response signature in gtls_verify_ocsp_status h3-proxy: fix callback return values, and a typo in tests hostip: remove unused MAX_HOSTCACHE_LEN and MAX_DNS_CACHE_SIZE hsts.md: mention multiple curl invokes effect hsts: duplicate live HSTS data in curl_easy_duphandle http-proxy: verify CONNECT response headers HTTP3.md: update quiche build http: don't pass on set cookies to new origins http: prefer chunked encoding over Content-Length: 0 http: reject spurious CR bytes in headers http_digest: return better error idn: replace header guards with forward declaration INSTALL-CMAKE.md: document CMake environment variables INTERNALS.md: document minimum nghttp3 and ngtcp2 versions KNOWN_BUGS.md: remove fixed GnuTLS <-> OpenSSL incompat bug KNOWN_BUGS: remove stale Threads::Threads entry krb5_sspi: fix error message on `DecryptMessage()` fail ldap: base64 encode binary LDIF values with WinLDAP ldap: fix minor leak on write callback error ldap: fix to not leak `attribute` on OOM (WinLDAP) ldap: switch off chasing referrals lib678: fix to not be perma-skipped lib: make `__STDC_VERSION__` literals `L` (where missing) lib: transfer origin and proxy handling lib: two minor typos libcurl-easy.md: minor clarifications libssh2: do not use deprecated macros when unavailable libssh2: drop stray double-negative from `strncmp()` result libssh2: fix to return error code on missing parameter libssh2: replace macro names with non-misspelled alternatives libssh2: save non-standard port to `known_hosts` libssh2: sync version check with INTERNALS.md libssh2: use non-deprecated `libssh2_knownhost_addc()` libssh: map SSH_KNOWN_HOSTS_OTHER to CURLKHMATCH_MISMATCH m4: drop redundant conditions in TLS library detections Makefile.am: drop test1190 listed twice managen: apply minor fixes and improvements mbedtls: null-terminate the private key blob mk-unity.pl: `#include`, and not concatenate input headers mqtt: return error on truncated Remaining Length mqtt: validate PINGRESP and DISCONNECT have remaining_length == 0 multi: handle pause in multi socket callback multi: remove a stale comment multi: silence gcc 16 `-Wnull-dereference`, bump CI job to test multi: xfers_really_alive netrc: remember and check filename loaded netrc: scanner refactor ngtcp2: fail handshake directly openssl: do not mix OpenSSL int result with `CURLcode` variable os400sys: fix theoretical length overflows peer.h: fix typo in comment pingpong: reject nul byte in server response line progress: fix CURLINFO time reporting psl: require libpsl 0.16.0 (2016-12-10) or greater pytest: pass `--disable` to curl pytest: re-enable test test_05_01 and test_05_02 for quiche 0.29.0+ pythonlint.sh: make it fail on error, fix ruff warnings in pytest quic: count zero length packets against max ratelimits: use minimal burst rate RELEASE-PROCEDURE.md: update coming release dates resolve: mention in error that IP address is expected rtsp: bump buf after rtsp_filter_rtp() runner.pm: apply minor correctness fix runner.pm: set `CURL_TESTNUM` for `precheck` commands runtests: fix tests for curl builds with embedded CA bundle rustls: error on CURLOPT_CRLFILE with native CA store schannel: check `schannel_sha256sum()` success, and more schannel: enforce Extended Key Usage for custom CA roots schannel: error on TLS 1.3-only with cipher list schannel: fix https proxy for client cert and certinfo schannel: fix revoke_best_effort setting for proxy schannel: use fopen instead CreateFile schannel_verify: avoid out of blob access schannel_verify: simplify CryptQueryObject use scripts: catch Credits-to contributors SECURITY-ADVISORY.md: expand setopt: changing the proxy port is also a proxy change setopt: clear proxy auth properly on NULL setopt: clear the "custom" CA booleans when set to NULL setopt: CURLOPT_MAXCONNECTS set to 0 restores default value setopt: defref the old referer when setting a new setopt: fix to honor `CURLOPT_PROXY_CAINFO_BLOB` over Native CA setopt: gate a few proxy TLS options by checking backend support setopt: more careful cleanup of the HSTS cache setopt: return error if received `curl_blob->data` is NULL show-headers.md: mention bold headers and --no-styled-output sigv4: URL encode the username in the header smb: constify `strchr()` result variable smb: integer overflow proof a size check smbserver: update internal id generation for Python 3 socket: introduce `SOCK_EAGAIN()` and use it socket: use name `sockerr` for socket error variables socks_sspi: invalid response length is a fatal error socks_sspi: store socks5_gssapi_enctype spnego_sspi: honor CURLOPT_GSSAPI_DELEGATION for Windows SSPI spnego_sspi: preserve distinction btw policy-only and uncond delegation src: fix comment typos src: sync nghttp2 versions checks with current requirements ssl native_ca_store: always reinit SSLCERTS: document 8.19.0 default Native CA builds (Windows) sspi: clear SSPI credentials on AcquireCredentialsHandle failure sspi: free libcurl allocated memory with curlx_free telnet: drop an `int` cast no longer necessary telnet: drop redundant interim variables telnet: fix error message typos telnet: fix old copy-paste typo in variable name telnet: honor CURLOPT_TIMEOUT in send_telnet_data() test1588: use %TESTNUMBER, not hard-coded number test1981: explicitly set the locale tests: add `cookies` feature to some tests tests: add an assert to avoid IPC blocking tests: add the "--resolve" keyword to tests that lack it tests: fix unit1636 with --disable-progress-meter tftp: avoid the timeout calc if the timeout is crazy tftp: stricter option name checks tidy-up: add space around operators, where missing tidy-up: apply clang-format fixes tidy-up: drop stray casts for allocated pointers tidy-up: miscellaneous tls: fix incomplete mTLS config in conn reuse and session cache tls: wolfssl: fixes for PQC key shares tool: warn when --ssl and --ftp-ssl-control override each other tool_formparse.c: fix two minor comment typos tool_formparse: polish error message + make two functions static tool_formparse: tool2curlparts is no longer recursive tool_help: rectify a bad assert tool_operhlp: avoid NULL to %s tool_urlglob: avoid overflow at end of range tool_urlglob: better 'Duplicate glob name' position tool_urlglob: make globbing error reported for correct position tool_writeout: fix %time{} output for %s transfer: clear referer when set to NULL unit1675: fix potential memory leak on dynbuf fail path unix-sockets: ignore proxy settings URL-SYNTAX: document more URL parsing details url: compare full origin when setting credentials url: connection credentials origin url: connection reuse fixes for starttls url: detect proxy changes read from environment url: don't log bits.close state url: fix connection reuse for starttls protocols url: keep the question mark for empty queries url: remove superfluous check url: url_match_destination fix urlapi: accept 0X prefix in IPv4 address as well urlapi: change more lowercase percent-encoded to uppercase urlapi: compare zone-id in Curl_url_same_origin() urlapi: consume trailing dots after IPv4 numerical addresses urlapi: deny hostnames with more than one trailing dot urlapi: drop base fragment on empty redirect urlapi: fix an issue parsing file URLs urlapi: fix memleaks on error in `parse_hostname_login()` urlapi: fix redirect handling if CURLU_NO_GUESS_SCHEME is set urlapi: forbid '|' in host urlapi: handle redirect without set scheme with default-scheme urlapi: URL decode hostname before IP address normalization user-agent.md: mention double quotes too var: use a dedicated pointer for the alloc verify-release: verify more thoroughly with git vquic: drop stray casts for `iovec.iov_len` vtls: more large buffer support and error checks for SHA-256 vtls: use Curl_safecmp for CRLfile and pinned_key comparison vtls_scache: include signature_algorithms in the SSL peer cache key vtls_spack: drop redundant macro fallbacks VULN-DISCLOSURE-POLICY.md: emphasize comm as a human VULN-DISCLOSURE-POLICY.md: emphasize the no email thank you part VULN-DISCLOSURE-POLICY.md: test code is not secure VULN-DISCLOSURE-POLICY: non-released code websockets: auto-tunnel through http proxy websockets: buffer upgrade data at connection level windows: update MS SDK versions in comments winldap: avoid NULL pointer deref on `ldap_get_dn()` fail ws: make pong sending lazy x509asn1: fix DH public key parameter extraction x509asn1: fix operator order in do_pubkey @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.36 2026/04/29 07:05:49 wiz Exp $ d4 1 a4 1 DISTNAME= curl-8.21.0 @ 1.36 log @curl: update to 8.20.0. This release includes the following changes: o async-thrdd: use thread queue for resolving [144] o build: make NTLM disabled by default [90] o cmake: drop support for CMake 3.17 and older [108] o lib: add thread pool and queue [74] o lib: drop support for < c-ares 1.16.0 [64] o lib: make SMB support opt-in [18] o multi.h: add CURLMNWC_CLEAR_ALL [127] o rtmp: drop support [91] This release includes the following bugfixes: o altsvc: cap the list at 5,000 entries [183] o altsvc: drop the prio field from the struct [185] o altsvc: skip expired entries read from file [187] o asyn-ares: connect async [220] o asyn-ares: drop orphaned variable references [86] o asyn-ares: fix HTTPS-lookup when not on port 443 [100] o asyn-thrdd: drop redundant `result` check [291] o asyn-thrdd: fix clang-tidy unused value warning [125] o async-ares: fix query counter handling [195] o autotools: limit checksrc target to ignore non-repo test sources [12] o badwords-all: exit with correct code on errors [50] o badwords: combine the whitelisting into a single regex [1] o badwords: detect the the and with with [51] o badwords: only check comments and strings in source code [61] o badwords: rework exceptions, fix many of them [15] o boringssl: fix more coexist cases with Schannel/WinCrypt [170] o build: adjust/add casts to fix `-Wformat-signedness` [218] o build: assume `snprintf()` in `mprintf`, drop feature check [107] o build: compiler warning silencing tidy-ups [4] o build: drop `openssl` module dependency for BoringSSL from `libcurl.pc` [33] o build: drop duplicate `pthread.h` includes [158] o build: drop redundant `USE_QUICHE` guards [159] o build: enable `-Wimplicit-int-enum-cast` compiler warning, fix issues [84] o build: fix `-Wformat-signedness` by adjusting printf masks [226] o build: link `bcrypt.lib` via vcxproj files [239] o build: skip detecting `pipe2()` for Apple targets [227] o build: stop building and installing `runtests.1` and `testcurl.1` [235] o cf-https-connect: silence `-Wimplicit-int-enum-cast` with HTTPS-RR [132] o cf-https-connect: silence `-Wimplicit-int-enum-cast` with HTTPS-RR [63] o cf-ip-happy: limit concurrent attempts [191] o cf-socket: avoid low risk integer overflow on ancient Solaris [56] o cfilters: fix Curl_pollset_poll() return code mixup [206] o clang-tidy: avoid assignments in `if` expressions [175] o clang-tidy: enable more checks, fix fallouts [254] o cmake: add CMake Config-based dependency detection [87] o cmake: add CMake Config-based dependency detection for c-ares, wolfSSL [134] o cmake: do not install `wcurl` when `BUILD_CURL_EXE=OFF` [265] o cmake: do not install shell completions when `BUILD_CURL_EXE=OFF` [263] o cmake: document functions used from Windows system DLLs [103] o cmake: enable pthreads for BoringSSL/AWS-LC [196] o cmake: resolve targets recursively when generating `libcurl.pc` [45] o cmake: rework binutils ld hack to not read `LOCATION` property [41] o cmake: silence bad library `Threads::Threads` warning [131] o cmake: use `AIX` built-in variable (with CMake 4.0+) [163] o config2setopts: make --capath work in proxy disabled builds [113] o configure: fix `--with-ngtcp2=` option for crypto libs [26] o configure: fix LibreSSL ngtcp2 1.15.0+ crypto lib selection logic [3] o configure: prefer dependency-specific variables over `$withval` [35] o configure: remove superfluous experimental warning for HTTP/3 [169] o configure: silence useless clang warnings in C89 builds [156] o configure: tidy up comments [202] o connect: fix typo on error message o cookie: fix rejection when tabs in value [189] o curl-wolfssl.m4: fix to use the correct value for pkg-config directory [36] o curl.h: replace macros with C++-friendly method to enforce 3 args [110] o curl_ctype.h: fix spelling in a couple of locally used macros [28] o curl_get_line: error out on read errors [9] o curl_get_line: fix potential infinite loop when filename is a directory [46] o curl_ngtcp2: extend and update callbacks for 1.22.0+ [165] o curl_ntlm_core: drop redundant PP condition [140] o curl_ntlm_core: use wolfCrypt DES API with wolfSSL [200] o curl_setup.h: drop stray/unused `USE_OPENSSL_QUIC` guard [210] o curl_sha512_256: support delegating to wolfSSL API [149] o curl_version_info.md: clarify age details [69] o CURLOPT_HAPROXY_CLIENT_IP.md: mention assumption on data format [96] o CURLOPT_RTSP_SESSION_ID.md: clarify reuse "dangers" [270] o CURLOPT_RTSP_SESSION_ID.md: expand the comment [267] o CURLOPT_RTSP_SESSION_ID.md: minor language fix o CURLOPT_SOCKS5_AUTH.md: an access property [212] o CURLOPT_SSL_CTX_FUNCTION.md: expand on effects connection reuse [105] o CURLOPT_UPLOAD_FLAGS.md: expand [223] o curlx_now(), prevent zero timestamp [93] o DEPRECATE: fix minor release number typo o digest: pass in the user name quoted (as well) [34] o dns: https-eyeballing async [229] o dnscache: own source file, improvements [116] o docs/cmdline-opts/write-out.md: tls_earlydata was adeded in 8.13.0 o docs/cmdline-opts: tidy up retry-connrefused [190] o docs/lib: fix typos [53] o docs/libcurl: improve easy setopt examples [266] o docs: clarify retry-max-time timing [294] o docs: CURLOPT_LOGIN_OPTIONS is a login property [228] o docs: enable more compiler warnings for C snippets, fix 3 finds [71] o docs: list more dependencies for running Python HTTP tests [123] o docs: mention more zip bomb precautions [166] o docs: minor wording tweaks o docs: noproxy wants the punycoded hostname version [214] o docs: SSH host verification is done at connect time [197] o docs: use the correct CURLOPT_WRITEFUNCTION signature [142] o doh: fix memory-leak when doing a second DoH resolve [55] o doh: remove superfluous doh_req check [222] o examples/websocket: fix to sleep more on Windows [92] o examples: drop warning silencers no longer hit [14] o examples: fix typo in comment [75] o file: init fd to -1 to prevent close fd 0 on early failure [40] o fopen: for temp files, inherit permissions only for owner [146] o ftp: do not strdup DATA hostname [29] o ftp: make the MDTM date parser stricter (again) [115] o ftp: reject PWD responses containing control characters [95] o gcc: guard `#pragma diagnostic` in core code for <4.6 [94] o generate.bat: remove extra % from VC11 and VC12 runs o genserv.pl: make external calls safe [119] o getinfo: initialize `PureInfo` field `used_proxy` [43] o getinfo: repair CURLINFO_TLS_SESSION [193] o gnutls: fix clang-tidy warning with !verbose [126] o gtls: fail for large files in `load_file()` [174] o h3: HTTPS-RR use in HTTP/3 [221] o Happy Eyeballs: add resolution time delay [238] o haproxy: use correct ip version on client supplied address [275] o hostip: clear the sockaddr_in6 structure before use [20] o hostip: init the curl_jmpenv_lock appropriately [278] o hostip: resolve user supplied ip addresses [259] o HSTS: cap the list [177] o hsts: make the HSTS read callback handle name dupes [141] o hsts: skip expired HSTS entries read from file [188] o hsts: when a dupe host adds subdomains, use that [130] o http2: clear the h2 session at delete [99] o http2: prevent secure schemes pushed over insecure connections [181] o http2: return error on OOM in push headers [65] o HTTP3.md: drop outdated mentions of OpenSSL-QUIC [2] o http: clear credentials better on redirect [204] o http: clear digest nonce on cross-orgin redirect [269] o http: clear the proxy credentials as well on port or scheme change [246] o http: fix auth_used and auth_avail [154] o http: fix Curl_compareheader for multi value headers [11] o http: make Curl_compareheader handle multiple commas in header o http: on 303, switch to GET [208] o http: use header_has_value() instead of duplicate code [251] o imap: reset the UIDVALIDITY state between transfers [7] o include: drop 'will' from public headers [73] o INSTALL.md: update Cygwin instructions [198] o keylog.h: replace literal number with macro in declaration [171] o keylog: drop unused/redundant includes and guards [172] o ldap: drop duplicate `ldap_set_option()` on Windows [42] o ldap: fix to initialize cleartext connection on Windows [49] o lib1560: fix comment typo o lib1960: fix test failure [255] o lib: accept larger input to md5/hmac/sha256/sha512 functions [194] o lib: always use Curl_1st_fatal instead of Curl_1st_err [89] o lib: fix typos in comments [240] o lib: make resolving HTTPS DNS records reliable: [176] o lib: minor comment typos [237] o lib: move request specific allocations to the request struct [256] o lib: replace `PRI*32` printf masks with C89 ones [201] o libssh2: allocate libssh2-friendly memory in kbd_callback [225] o libssh2: fix error handling on quote errors [21] o libssh: fix 64-bit printf mask for mingw-w64 <=6.0.0 [215] o libssh: fix `-Wsign-compare` in 32-bit builds [217] o libssh: path length precaution [164] o libssh: propagate error back in SFTP function [178] o libtest: drop duplicate include [111] o location/follow: mention netrc [138] o man: fix argument type for `CURLSHOPT_[UN]SHARE` options [211] o mbedtls: cleanup more without care for 'initialized' [262] o mbedtls: fix ECJPAKE matching [135] o mbedtls: remove failf() call with first argument as NULL [249] o md4, md5: switch to wolfCrypt API in wolfSSL builds [139] o mime: only allow 40 levels of calls [241] o misc: fix code quality findings [209] o mk-ca-bundle.pl: make `ca-bundle.crt` timestamp match `certdata.txt`'s [44] o multi: enhance pending handles fairness [284] o multi: fix connection retry for non-http [180] o multi: improve wakeup and wait code [118] o netrc: find login-less password when user is given in URL [6] o netrc: remove unused parsenetrc() macro for netrc-disabled [121] o netrc: skip malformed macdef lines [67] o openssl channel_binding: lookup digest algorithm without NID [117] o openssl: drop obsolete SSLv2 logic [27] o openssl: fix build with 4.0.0-beta1 no-deprecated [184] o openssl: fix memory leaks in ECH code (OpenSSL 3) [78] o openssl: fix unused variable warnings in !verbose builds [252] o openssl: trace count of found / imported Windows native CA roots [8] o OS400: add new definitions to the ILE/RPG binding. [153] o os400sys: fix typo in comment (symetry -> symmetry) [58] o parsedate: bsearch the time zones [232] o parsedate: fix wrong treatment of "military time zones" [182] o parsedate: refactor [230] o perl: harden external command invocations [133] o progress: count amount of data "delivered" to application [66] o protocol.h: fix the CURLPROTO_MASK [31] o protocol: disable connection reuse for SMB(S) [199] o protocol: use scheme names lowercase [38] o proxy: chunked response, error code [143] o pytest: add additional quiche check for flaky test_05_01 [22] o pytest: check 429 handling [268] o rand: use `BCryptGenRandom()` in UWP builds [88] o ratelimit: reset on start [150] o request: reset resp_trailer in new requests [186] o runtests: skip setting ed25519 SSH key format [264] o rustls: fix memory leak on repeated SSLKEYLOGFILE fails [280] o rustls: handle EOF during initial handshake [203] o schannel: increase renegotiation timeout to 60 seconds [261] o scripts: drop redundant double-quotes: `"$var"` -> `$var` (Perl) [109] o scripts: harden / tidy up more Perl `system()` calls [70] o sectrust: fail on missing OCSP stapling [250] o sendf: fix CR detection if no LF is in the chunk [219] o setopt: clear proxy auth properties when switching [192] o setopt: fix typos in comments [257] o setopt: move CURLOPT_CURLU [260] o setup connection filter: mark as setup [234] o sha256, sha512_256: switch to wolfCrypt API [147] o sha256: support delegating to wolfSSL API [148] o share: concurrency handling, easy updates [104] o share: do bitshifts after the type is checked to be valid [216] o socks: reject zero-length GSSAPI/SSPI tokens from proxy [157] o socks: use dns filter for resolving [244] o spelling: fix typos [173] o src: use ftruncate() unconditionally [128] o sshserver.pl: harden more `system()` calls [81] o sshserver.pl: pass command-line to `system()` safely [82] o strerr: correct the strerror_s() return code condition [25] o sws: fix potential OOB write [80] o synctime: fix off-by-one read and write to a read-only buffer (Windows) [85] o test 766: flag as timing-dependent [136] o test1675: unit tests for URL API helper functions [248] o test459: switch to mode="warn" for stderr check [5] o testcurl.pl: replace shell commands with Perl `rmtree()` [76] o tests/unit/README: describe how to unit test static functions [60] o tests: avoid infinite recursion for `make check` [253] o tests: use %b64[] instead of "raw" base64 [245] o tool: check for curlinfo->age when determining if ssh backend [77] o tool: fix memory mixups [106] o tool: fix retries in parallel mode [137] o tool: fix two more allocator mismatches [155] o tool_cb_hdr: only truncate etags output when regular file [129] o tool_cb_rea: make waitfd() return void [168] o tool_cb_wrt: fix no-clobber error handling [39] o tool_cfgable: free the SSL signature algorithms [62] o tool_dirhie: fix to create drive-relative directory [276] o tool_formparse: propagate my_get_line errors when reading headers [102] o tool_getparam: use correct free function for libcurl memory [68] o tool_ipfs: accept IPFS gateway URL without set port number [13] o tool_msgs: avoid null pointer deref for early errors [98] o tool_operate: actually apply the --parallel-max-host limit [167] o tool_operate: drop the scheme-guessing in the -G handling [54] o tool_operate: fix condition for loading `curl-ca-bundle.crt` (Windows) [79] o tool_operate: fix memory-leak on failed uploads [124] o tool_operate: fix minor memory-leak on early error [23] o tool_operate: reset the upload glob counter for next URL [162] o tool_operhlp: fix `add_file_name_to_url()` result on OOM [32] o tool_operhlp: iterate through all slashes to find name [114] o tool_operhlp: propagate low-level OOM in `add_file_name_to_url()` [112] o tool_setopt: return error on OOM correctly [152] o tool_urlglob: fix memory-leak on glob range overflow [19] o top-complexity: prevent filename-based shell injection risk [101] o transfer: clear the old autoreferer [236] o transfer: clear the URL pointer in OOM to avoid UAF [179] o transfer: enable custom methods again on next transfer [30] o transfer: enhance secure check [10] o unit1675: fix `-Wformat-signedness` [274] o url: do not reuse a non-tls starttls connection if new requires TLS [145] o url: improve connection reuse on negotiate [160] o url: init req.no_body in DO so that it works for h2 push [161] o url: set default upload flags to CURLULFLAG_SEEN [224] o url: use the socks type for socks proxy [47] o url: use URL for url even in comments [52] o urlapi: fix handling of "file:///" [122] o urlapi: make dedotdotify handle leading dots correctly [97] o urlapi: same origin tests [213] o urlapi: stop extracting hostname from file:// URLs on Windows [247] o urlapi: verify the last letter of a scheme when set explicitly [16] o urldata.h: fix typo and lingering backtick [279] o urldata: connection bit ipv6_ip is wrong [59] o urldata: import port types and conn destination format [57] o urldata: make hstslist only present in HSTS builds [120] o urldata: make speeder_c uint32 [37] o urldata: move cookiehost to struct SingleRequest [242] o urldata: remove trailers_state [17] o vquic: fix variable name in fallback code [207] o vtls: fix comment typos and tidy up a type [285] o vtls: log when key logging is enabled. [288] o vtls_scache: check reentrancy [243] o vtls_scache: include cert_blob independently of verifypeer [231] o wolfssl: document v5.0.0 (2021-11-01) as minimum required [151] o wolfssl: fix `-Wmissing-prototypes` [233] o wolfssl: fix handling of abrupt connection close [24] o write-out.md: minor language fix [273] o write-out.md: tls_earlydata was adeded in 8.13.0 o ws: fix a blocking curl_ws_send() to report written length correctly [258] o x509asn1: fix to return error in an error case from `encodeOID()` [83] o x509asn1: fixed and adapted for ASN1tostr unit testing [48] o x509asn1: improve encodeOID [72] Planned upcoming removals include: o local crypto implementations o NTLM o SMB o TLS-SRP support See https://curl.se/dev/deprecate.html @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.35 2026/03/11 07:08:39 wiz Exp $ d4 1 a4 1 DISTNAME= curl-8.20.0 @ 1.36.2.1 log @Pullup ticket #7142 - requested by taca www/curl: security fix Revisions pulled up: - www/curl/Makefile 1.308 - www/curl/Makefile.common 1.37 - www/curl/distinfo 1.227 - www/curl/patches/patch-configure deleted - www/curl/patches/patch-lib_curl__sha512__256.c deleted - www/curl/patches/patch-lib_md5.c deleted - www/curl/patches/patch-lib_multi.c deleted - www/curl/patches/patch-lib_sha256.c deleted - www/curl/patches/patch-lib_vtls_gtls.c deleted - www/libcurl-gnutls/Makefile 1.27 --- Module Name: pkgsrc Committed By: wiz Date: Thu Jun 25 08:25:51 UTC 2026 Modified Files: pkgsrc/www/curl: Makefile Makefile.common distinfo Removed Files: pkgsrc/www/curl/patches: patch-configure patch-lib_curl__sha512__256.c patch-lib_md5.c patch-lib_multi.c patch-lib_sha256.c patch-lib_vtls_gtls.c Log Message: curl: update to 8.21.0. Lots of security fixes. Changes: curl: named globs in output filename for upload glob references HTTP/3: add proxy CONNECT and MASQUE CONNECT-UDP support (ngtcp2 QUIC) http2: remove stream dependency tracking lib: drop support for CURLAUTH_DIGEST_IE libssh: add support for SHA256 host public keys tool_urlglob: add named globs Bugfixes: _ENVIRONMENT.md. Windows does case insensitive env variables _URL.md: remove the zone-id mention AmigaOS: curl_setup.h avoid explicit_bzero with clib2 AmigaOS: fix build fallouts, re-add to CI asyn-thrdd: add IPv6 guards asyn-thrdd: fix result processing without wakeup socketpair autotools: mbedtls detection fixes BINDINGS: Update Hollywood link BUFQ.md: re-sync with source code build: enable `-Wlogical-op` picky warning for GCC 4.4+ build: omit zlib pkg-config reference for Android cf-h2-prox: fix peer leak cf-h2-proxy: drop interim responses cf-https-connect: do not engage on proxy origin cf-ip-happy.c: minor comment typo cf-ip-happy: update documentation cf-socket: make Curl_addr2string static cf-socket: set scope_id for IPv6 link-local addresses cf-socket: store errno from do_connect in ctx->error cfilters: fix busy loop on blocked transfers chunked: reject invalid bytes in trailer CIPHERS.md: fix the example that uses only TLS 1.3 cmake/FindGSS: drop "MIT Unknown" version value, related tidy ups cmake/FindGSS: drop CMake <3.16 compatibility logic cmake/FindGSS: fix comment, adjust custom flavor property name cmake/FindGSS: prioritize MIT over GNU in pkg-config detection cmake: auto-select static nghttp2/nghttp3/ngtcp2 Config cmake: export/forward `NGTCP2_CRYPTO_BACKEND` cmake: fix three issues generating lib options in config files cmake: fix zstd CMake config name cmake: opt in `MSVC_VERSION` 1951 to picky warnings cmake: quote `COMPONENTS` string in `curl-config.in.cmake` cmake: simplify `LINK_ONLY` imported target extraction config2setopts: use default protocol properly connect: remove deref of freed pointer in trace call content_encoding: fix limit failure message content_encoding: fix non-last chunked rejection content_encoding: timeout during slow decoding cookie: check __Secure- and __Host- case sensitively when read from file cookie: compare path case sensitively cookie: reject control octets in file-loaded cookies cookie: simplify strstore(), remove outdated comment cookie: tailmatch the domains for secure override cookie: trim trailing dots when checking PSL creds: add sasl service name creds: create with empty user+pass creds: mask OAuth bearer token in trace logs creds: remove two unused functions curl_easy_pause.md: rephrase the stream cache when pause clause curl_easy_setopt.md: change options when no transfer runs curl_formdata: fix to pass long where missing, document `CURLFORM_NAMELENGTH` curl_multi_assign.md: clarify lifetime curl_ntlm_core: fix nettle 4+ builds in certain MultiSSL combos curl_ntlm_core: propagate DES `CryptEncrypt()` error curl_sha512_256: fix result code on error CURLINFO_CONTENT_LENGTH_UPLOAD_T.md: expand CURLMOPT_SOCKETFUNCTION.md: this sends *all* file descriptors CURLOPT_CHUNK_BGN_FUNCTION: target is there for symlinks only CURLOPT_DISALLOW_USERNAME_IN_URL: is for CURLOPT_URL only CURLOPT_DOH_URL.md: does not inherit proxy options CURLOPT_ECH.md: simplify the description language CURLOPT_HAPROXYPROTOCOL.md: only sent for newly setup connections CURLOPT_MAXFILESIZE: clarify this also works for on-going transfers CURLOPT_PINNEDPUBLICKEY.md: does not apply for other origins CURLOPT_PORT.md: use stronger language CURLOPT_SHARE: warn about early remove CURLOPT_SSH_HOSTKEYFUNCTION.md: for new connections only CURLOPT_WRITEFUNCTION.md: mention redirects CURLOPT_WRITEFUNCTION.md: remove stray reference to HSTS delta: harden external command invocations digest: escape control codes too digest: flush proxy state on proxy or credential change digest: flush state on origin or credential change dns-httpsrr-lookup: use origin, not peer dnscache: remove Curl_dns_entry_link docs/libcurl: fix the version for curl_multi_socket_action docs: end "...can be used several times..." sentences with period docs: fix --follow doc typo docs: fix a couple of typos docs: fix grammar and wording in FAQ docs: fix odd wording in CONTRIBUTE.md docs: note CURLOPT_PINNEDPUBLICKEY has no effect on legacy LDAP backend docs: returned header size reflects HTTP/1-style format doh: cap the maximum TTL to 24 hours doh: stricter HTTPS RNAME parsing ECH: cleanups event: fix wakeup consumption ftp: avoid accessing EPSV response one byte past the NULL ftp: remove 2 Curl_resolv_blocking() calls ftp: remove bits.ftp_use_control_ssl ftplistparser: clear strings.target if not symlink gnutls: allow building with nettle 4.0 gnutls: fix more nettle 4+ compatibility issues gnutls: require 3.7.2 for earlydata gsasl: fix potential double free gtls: fix ignored return and uninitialized status in OCSP check gtls: fix some typos gtls: minor fixes and improvements gtls: use the correct return code in trace output gtls: verify OCSP response signature in gtls_verify_ocsp_status h3-proxy: fix callback return values, and a typo in tests hostip: remove unused MAX_HOSTCACHE_LEN and MAX_DNS_CACHE_SIZE hsts.md: mention multiple curl invokes effect hsts: duplicate live HSTS data in curl_easy_duphandle http-proxy: verify CONNECT response headers HTTP3.md: update quiche build http: don't pass on set cookies to new origins http: prefer chunked encoding over Content-Length: 0 http: reject spurious CR bytes in headers http_digest: return better error idn: replace header guards with forward declaration INSTALL-CMAKE.md: document CMake environment variables INTERNALS.md: document minimum nghttp3 and ngtcp2 versions KNOWN_BUGS.md: remove fixed GnuTLS <-> OpenSSL incompat bug KNOWN_BUGS: remove stale Threads::Threads entry krb5_sspi: fix error message on `DecryptMessage()` fail ldap: base64 encode binary LDIF values with WinLDAP ldap: fix minor leak on write callback error ldap: fix to not leak `attribute` on OOM (WinLDAP) ldap: switch off chasing referrals lib678: fix to not be perma-skipped lib: make `__STDC_VERSION__` literals `L` (where missing) lib: transfer origin and proxy handling lib: two minor typos libcurl-easy.md: minor clarifications libssh2: do not use deprecated macros when unavailable libssh2: drop stray double-negative from `strncmp()` result libssh2: fix to return error code on missing parameter libssh2: replace macro names with non-misspelled alternatives libssh2: save non-standard port to `known_hosts` libssh2: sync version check with INTERNALS.md libssh2: use non-deprecated `libssh2_knownhost_addc()` libssh: map SSH_KNOWN_HOSTS_OTHER to CURLKHMATCH_MISMATCH m4: drop redundant conditions in TLS library detections Makefile.am: drop test1190 listed twice managen: apply minor fixes and improvements mbedtls: null-terminate the private key blob mk-unity.pl: `#include`, and not concatenate input headers mqtt: return error on truncated Remaining Length mqtt: validate PINGRESP and DISCONNECT have remaining_length == 0 multi: handle pause in multi socket callback multi: remove a stale comment multi: silence gcc 16 `-Wnull-dereference`, bump CI job to test multi: xfers_really_alive netrc: remember and check filename loaded netrc: scanner refactor ngtcp2: fail handshake directly openssl: do not mix OpenSSL int result with `CURLcode` variable os400sys: fix theoretical length overflows peer.h: fix typo in comment pingpong: reject nul byte in server response line progress: fix CURLINFO time reporting psl: require libpsl 0.16.0 (2016-12-10) or greater pytest: pass `--disable` to curl pytest: re-enable test test_05_01 and test_05_02 for quiche 0.29.0+ pythonlint.sh: make it fail on error, fix ruff warnings in pytest quic: count zero length packets against max ratelimits: use minimal burst rate RELEASE-PROCEDURE.md: update coming release dates resolve: mention in error that IP address is expected rtsp: bump buf after rtsp_filter_rtp() runner.pm: apply minor correctness fix runner.pm: set `CURL_TESTNUM` for `precheck` commands runtests: fix tests for curl builds with embedded CA bundle rustls: error on CURLOPT_CRLFILE with native CA store schannel: check `schannel_sha256sum()` success, and more schannel: enforce Extended Key Usage for custom CA roots schannel: error on TLS 1.3-only with cipher list schannel: fix https proxy for client cert and certinfo schannel: fix revoke_best_effort setting for proxy schannel: use fopen instead CreateFile schannel_verify: avoid out of blob access schannel_verify: simplify CryptQueryObject use scripts: catch Credits-to contributors SECURITY-ADVISORY.md: expand setopt: changing the proxy port is also a proxy change setopt: clear proxy auth properly on NULL setopt: clear the "custom" CA booleans when set to NULL setopt: CURLOPT_MAXCONNECTS set to 0 restores default value setopt: defref the old referer when setting a new setopt: fix to honor `CURLOPT_PROXY_CAINFO_BLOB` over Native CA setopt: gate a few proxy TLS options by checking backend support setopt: more careful cleanup of the HSTS cache setopt: return error if received `curl_blob->data` is NULL show-headers.md: mention bold headers and --no-styled-output sigv4: URL encode the username in the header smb: constify `strchr()` result variable smb: integer overflow proof a size check smbserver: update internal id generation for Python 3 socket: introduce `SOCK_EAGAIN()` and use it socket: use name `sockerr` for socket error variables socks_sspi: invalid response length is a fatal error socks_sspi: store socks5_gssapi_enctype spnego_sspi: honor CURLOPT_GSSAPI_DELEGATION for Windows SSPI spnego_sspi: preserve distinction btw policy-only and uncond delegation src: fix comment typos src: sync nghttp2 versions checks with current requirements ssl native_ca_store: always reinit SSLCERTS: document 8.19.0 default Native CA builds (Windows) sspi: clear SSPI credentials on AcquireCredentialsHandle failure sspi: free libcurl allocated memory with curlx_free telnet: drop an `int` cast no longer necessary telnet: drop redundant interim variables telnet: fix error message typos telnet: fix old copy-paste typo in variable name telnet: honor CURLOPT_TIMEOUT in send_telnet_data() test1588: use %TESTNUMBER, not hard-coded number test1981: explicitly set the locale tests: add `cookies` feature to some tests tests: add an assert to avoid IPC blocking tests: add the "--resolve" keyword to tests that lack it tests: fix unit1636 with --disable-progress-meter tftp: avoid the timeout calc if the timeout is crazy tftp: stricter option name checks tidy-up: add space around operators, where missing tidy-up: apply clang-format fixes tidy-up: drop stray casts for allocated pointers tidy-up: miscellaneous tls: fix incomplete mTLS config in conn reuse and session cache tls: wolfssl: fixes for PQC key shares tool: warn when --ssl and --ftp-ssl-control override each other tool_formparse.c: fix two minor comment typos tool_formparse: polish error message + make two functions static tool_formparse: tool2curlparts is no longer recursive tool_help: rectify a bad assert tool_operhlp: avoid NULL to %s tool_urlglob: avoid overflow at end of range tool_urlglob: better 'Duplicate glob name' position tool_urlglob: make globbing error reported for correct position tool_writeout: fix %time{} output for %s transfer: clear referer when set to NULL unit1675: fix potential memory leak on dynbuf fail path unix-sockets: ignore proxy settings URL-SYNTAX: document more URL parsing details url: compare full origin when setting credentials url: connection credentials origin url: connection reuse fixes for starttls url: detect proxy changes read from environment url: don't log bits.close state url: fix connection reuse for starttls protocols url: keep the question mark for empty queries url: remove superfluous check url: url_match_destination fix urlapi: accept 0X prefix in IPv4 address as well urlapi: change more lowercase percent-encoded to uppercase urlapi: compare zone-id in Curl_url_same_origin() urlapi: consume trailing dots after IPv4 numerical addresses urlapi: deny hostnames with more than one trailing dot urlapi: drop base fragment on empty redirect urlapi: fix an issue parsing file URLs urlapi: fix memleaks on error in `parse_hostname_login()` urlapi: fix redirect handling if CURLU_NO_GUESS_SCHEME is set urlapi: forbid '|' in host urlapi: handle redirect without set scheme with default-scheme urlapi: URL decode hostname before IP address normalization user-agent.md: mention double quotes too var: use a dedicated pointer for the alloc verify-release: verify more thoroughly with git vquic: drop stray casts for `iovec.iov_len` vtls: more large buffer support and error checks for SHA-256 vtls: use Curl_safecmp for CRLfile and pinned_key comparison vtls_scache: include signature_algorithms in the SSL peer cache key vtls_spack: drop redundant macro fallbacks VULN-DISCLOSURE-POLICY.md: emphasize comm as a human VULN-DISCLOSURE-POLICY.md: emphasize the no email thank you part VULN-DISCLOSURE-POLICY.md: test code is not secure VULN-DISCLOSURE-POLICY: non-released code websockets: auto-tunnel through http proxy websockets: buffer upgrade data at connection level windows: update MS SDK versions in comments winldap: avoid NULL pointer deref on `ldap_get_dn()` fail ws: make pong sending lazy x509asn1: fix DH public key parameter extraction x509asn1: fix operator order in do_pubkey --- Module Name: pkgsrc Committed By: wiz Date: Thu Jun 25 08:26:28 UTC 2026 Modified Files: pkgsrc/www/libcurl-gnutls: Makefile Log Message: libcurl-gnutls: update to 8.21.0. Match curl. @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.36 2026/04/29 07:05:49 wiz Exp $ d4 1 a4 1 DISTNAME= curl-8.21.0 @ 1.35 log @curl: update to 8.19.0. curl and libcurl 8.19.0 Public curl releases: 273 Command line options: 273 curl_easy_setopt() options: 308 Public functions in libcurl: 100 Contributors: 3619 This release includes the following changes: o we stopped the bug bounty [23] o cmake: add `CURL_BUILD_EVERYTHING` option [51] o initial support for MQTTS [81] o tool: support fractions for --limit-rate and --max-filesize [79] o tool_cb_hdr: with -J, use the redirect name as a backup [147] o vquic: drop support for OpenSSL-QUIC [80] o windows: add build option to use the native CA store [82] o windows: bump minimum to Vista (from XP) [12] This release includes the following bugfixes: o altsvc: only accept 17 byte dates from files [22] o asyn-ares: abort with OOM error when Curl_dnscache_mk_entry fails [107] o async-ares: blocking resolve timeout handling, better [239] o badwords: move into ./scripts, speed up [187] o build: add missing `GENERATEDCERTS` files [210] o build: adjust minimum version for some clang picky warnings [211] o build: check `MSG_NOSIGNAL` directly, drop detection and interim macro [26] o build: constify `memchr()`/`strchr()`/etc result variables (cont.) [85] o build: detect and include `inttypes.h` again [13] o build: do not include wolfSSL header in `curl_setup.h` [215] o build: drop duplicate C includes [54] o build: drop global suppression of `-Wformat-nonliteral`, fix fallouts [19] o build: drop unused `snprintf()` feature check on Windows [261] o build: fix `-Wunused-macros` warnings, and related tidy-ups [176] o build: fix building rare combinations [109] o build: fully omit verbose strings and code when disabled [113] o build: globally suppress DJGPP warnings in `FD_SET()` [56] o build: merge TrackMemory (`CURLDEBUG`) into debug-enabled option [46] o build: move curl stat struct type to the curlx namespace [156] o build: opt-in MSVC to C99-style verbose logging logic [108] o build: require POSIX `strdup()` [159] o build: tidy up and dedupe `strdup` functions [162] o cf-socket: ignore SOCK_CLOEXEC etc for socktype equality checks [226] o cf-socket: use SOCK_CLOEXEC in socket_open when available [130] o checksrc-all.pl: skip non-repository files [144] o checksrc: do not apply `BANNEDFUNC` to struct member functions [35] o checksrc: warn for leading spaces before the preprocessor hash [72] o clang-tidy: add missing and delete redundant parentheses [155] o clang-tidy: add more missing parentheses in macro values [224] o clang-tidy: avoid/silence `bugprone-not-null-terminated-result` [222] o clang-tidy: check `bugprone-macro-parentheses`, fix fallouts [212] o clang-tidy: drop redundant conditions reported by `misc-redundant-expression` [217] o clang-tidy: enable `bugprone-signed-char-misuse`, fix fallouts [227] o clang-tidy: enable more checks [225] o clang-tidy: enable scanning headers [205] o clang-tidy: fix issues found with build-fuzzing [275] o clang-tidy: silence more minor issues found by v22 [276] o cmake/FindMbedTLS: add workaround for missing static MSVC `mbedcrypto.lib` 4.0.0 [174] o cmake: add `CURL_DROP_UNUSED` option to reduce binary sizes [105] o cmake: add native clang-tidy support for tests, with concatenated sources [223] o cmake: always build curlu and curltool test libs in unity mode [190] o cmake: always define `CURL::win32_winsock` on Windows in `curl-config.cmake` [104] o cmake: convert `curl_add_clang_tidy_test_target()` macro to function [281] o cmake: enable binutils ld workaround for all toolchains at build-time [57] o cmake: fix `LOCATION` property access condition (debug) [241] o cmake: fix `LOCATION` property read errors in target debug function [243] o cmake: fix building with `CMAKE_FIND_PACKAGE_PREFER_CONFIG=ON` [254] o cmake: fix confusing error when a dependency is undetected in `curl-config.cmake` [169] o cmake: fix logic for openssl/zlib binutils ld workaround [71] o cmake: fix passing system header directories to clang-tidy for tests [221] o cmake: fix system include directory position for clang-tidy in tests [284] o cmake: improve clang-tidy test command-line reproduction [242] o cmake: minor fixes to test targets after prev [214] o cmake: normalize uppercase hex winver (for display) [191] o cmake: omit `curl.rc` from curltool lib [209] o cmake: reference OpenSSL and ZLIB imported targets only when enabled [41] o cmake: replace internal option with a new `tt` (test tools) target [220] o cmake: silence potential unused var warnings in C++ test snippet [201] o cmake: silence silly Apple clang warnings in C89 mode, test in CI [14] o cmake: silence useless compiler warnings triggered by the FASTBuild generator [43] o cmake: skip binutils ld hack if zlib/openssl target is not `IMPORTED` [90] o cmake: warn for invalid `CURL_TARGET_WINDOWS_VERSION` values [192] o cmke: add `*_USE_STATIC_LIBS` options for 9 dependencies [49] o config-plan9: set `HAVE_STDINT_H` again [17] o config2setopts: acknowledge OOM error from CURLOPT_MIMEPOST [120] o config2setopts: fix for --disable-aws build configuration [34] o configure: drop always true `if` check (Windows) [250] o content_encoding: return 'identity' if none other exists [235] o curl: add -I and -i to -h important [135] o curl: limit Windows-specific code to Windows builds, other tidy-ups [48] o curl_easy_nextheader.md: a new transfer invalidates 'prev' [69] o curl_get_line: drop single-use macro [93] o curl_multi_perform.md: resolve inconsistency [143] o curl_ntlm_core: merge two `#if` blocks [177] o curl_setup.h: drop extra header guard for internal include [91] o curl_setup.h: merge back single-use internal header `curl_setup_once.h` [78] o curl_setup.h: simplify curl memory macro mappings [163] o curl_setup_once: allow CURL_DEBUGASSERT for customization [125] o CURLINFO_CONTENT_LENGTH_DOWNLOAD_T.md: fix available protocols [97] o curlx: drop unused `curlx_saferealloc()` [161] o digest: escape double quotes and backslashes in realm and nonce [83] o digest: fix memory leak in auth_create_digest_http_message() [263] o digest: handle quotes in the path [50] o docs/INSTALL: update configure details [45] o docs/libcurl: unify WARNING use [89] o docs: add LibreELEC to DISTROS.md o docs: add reproducible example for generating man page [95] o docs: avoid starting sentences with However, [175] o docs: avoid using the word 'magic' [256] o docs: clarify --ipv4 and --ipv6 [149] o docs: document the need for a 64-bit type and stdint.h [118] o docs: drop basically [229] o docs: explicitly call out Slowloris as not a security flaw [6] o docs: fix grammar nitpicks [128] o docs: handle error in `curl_global_init*` examples [204] o docs: replace instances of the vague qualifier 'quite' [171] o docs: reword explanation of --variable option [150] o docs: some nitpicks [277] o docs: use dot instead of comma at end of sentences [168] o easy: reset errorbuf on eyeballing success [179] o easy: reset pausing when resetting request [218] o examples/usercertinmem: use modern OpenSSL API, drop mentions of RSA [188] o examples: improve OpenSSL certificate examples [248] o examples: omit forward declarations, apply misc fixes [60] o FAQ: syntax improvements [230] o fopen.h: simplify curl memory macro mappings [160] o ftp: replace a `curlx_free()` with `curlx_dyn_free()` [86] o ftp: split ftp_state_use_port into sub functions [172] o GOVERNANCE.md: Post-Daniel BDFL [31] o gss: exclude verbose error logic from non-verbose builds [122] o h2+h3: align stream close handling [131] o hostip.c: fix leak of addrinfo [11] o hostip6: remove debug-only code [24] o hostip: fix unreachable code in rare build configuration [74] o http/3: add description for known server error codes [15] o http1: fix potential NULL dereference in `Curl_h1_req_parse_read()` [268] o http: only send bearer if auth is allowed [228] o http_aws_sigv4: fix query normalization of %2b [117] o imap: add a check for Curl_meta_get() [157] o imap: check `imap_sendf()` printf masks at compile-time [67] o imap: skip literals inside quoted strings [30] o include: avoid recursive macros [182] o include: mask computed auth/proto bitmasks to 32 bits [145] o INSTALL-CMAKE.md: document Apple framework options [53] o INSTALL.md: fix typo [278] o INSTALL.md: suggest `-Wl,-dead_strip` for Apple targets [68] o KNOWN_BUGS.md: absolute Unix domain filename for SOCKS on Windows [37] o ldap: silence clang-tidy v22 warning [279] o ldap: silence potential unused variable warning (OS400) [55] o lib: delete unused local includes [181] o lib: disable websockets early if no http [140] o lib: make sigpipe handling more lazy [52] o lib: reorder protocol functions to avoid forward declarations (email) [76] o lib: reorder protocol functions to avoid forward declarations (ftp) [75] o lib: reorder protocol functions to avoid forward declarations (misc cont.) [66] o lib: reorder protocol functions to avoid forward declarations (misc) [77] o lib: reorder protocol functions to avoid forward declarations (ssh) [65] o lib: separate scheme info from protocol implementation [42] o lib: skip compiling code with features disabled [189] o lib: use (u)int64_t instead of long long [39] o libcurl docs: reduce 'since ...' in descriptions [28] o libcurl-security.md: fix typos and add a point about URLs o libtests: drop two redundant `memset()`s [110] o Makefile.am: delete RPM targets referencing non-existent files [9] o Makefile.am: drop stray VC project files from dist [5] o managen: silence Perl warnings [141] o mbedtls: guard TLS 1.3 + session tickets usage inside ifdef [260] o mbedtls: no pinnedpubkey wo MBEDTLS_SSL_KEEP_PEER_CERTIFICATE [29] o mbedtls: remove newline from failf() call [25] o mbedtls: split mbed_connect_step1 into sub functions [166] o md4, md5: drop redundant forward declarations [64] o md4, md5: replace custom types with `uint32_t` [111] o memdebug: include `backtrace.h` as system header [148] o mime: drop fallback for unused `R_OK` macro [58] o mimepost: allocate main struct on-demand [20] o mk-ca-bundle.pl: drop support for obsolete/insecure fingerprint algos [138] o mod_curltest: silence unused argument compiler warning [63] o mprintf: drop old sprintf fallback [7] o mprintf: rename internal enum to avoid collision with AmigaOS symbol [183] o mprintf: silence clang-tidy `readability-suspicious-call-argument` [262] o mprintf: use `_snprintf()` when compiled with VS2013 and older [280] o mqtt: better too-big-message-check [73] o mqtt: fix EOF handling [231] o mqtt: verify Remaining Length for CONNACK and PUBACK [153] o msvc: drop exception, make `BIT()` a bitfield with Visual Studio [2] o msvc: VS2026: unlock picky warning in cmake, test in CI [198] o multi: avoid a theoretical 32-bit wrap [186] o multi: fix unreachable code compiler warning [264] o multi: probe for IPv6 functionality in multi_init() [114] o multi: split multi_runsingle into sub functions [197] o multi: update timer unconditionally in multi_remove_handle [158] o ngtcp2: stabilize recv [18] o noproxy: simplify, don't mix const non-const in strchr() [88] o openldap: avoid forward declarations in ldaps code [62] o openssl+ech: workaround for insecure handshakes [238] o openssl: adapt to OpenSSL master adding const to more APIs [253] o OpenSSL: check reuse of sessions for verify status [142] o openssl: disable local keylog feature if built-in upstream [178] o openssl: fix compiler warning with OpenSSL master [193] o openssl: fix potential NULL dereference when loading certs (Windows) [165] o openssl: fix potential OOB read in debug/verbose logging [216] o plan9: drop special build and orphaned references [33] o proxy-auth: additional tests [232] o pytest: remove 03_02 [127] o quiche: use PRIu64 for outputting the stream id [184] o rand: drop impossible preprocessor branches (wincrypt) [246] o rand: drop scan-build silencer [245] o ratelimit: download finetune [16] o request.h: rename parameter 'buf' to 'req' in Curl_req_send [219] o REUSE: drop broken reference to `MAIL-ETIQUETTE` [59] o rtsp: fix assertion failure on zero-length RTP payload [180] o rtspd: fix to check `realloc()` result [173] o runtests: pass config filename to stunnel in native format (Windows) [94] o schannel: refactor: reduce variable scopes, fix comment, fix indent [196] o send: drop `CURL_UNCONST()` from buffer argument on most platforms [116] o setopt: fix checking range for CURLOPT_MAXCONNECTS [92] o setopt: refuse blobs with zero length [167] o setup-os400.h: drop no longer used custom type `u_int32_t` [112] o sigpipe: unset SA_SIGINFO since it is using sa_handler [40] o silent.md: also mention it shuts off warning messages [213] o smb: free the path in the request struct properly [137] o smb: include arpa/inet.h for NonStop [195] o socket: check result of SO_NOSIGPIPE [124] o socketpair: clear 'err' when retrying due to EINTR [233] o socketpair: set SO_NOSIGPIPE where possible [103] o socks: ensure DNS is freed in failure cases. [247] o src: simplify declaring `curl_ca_embed` [185] o ssh: dedupe state change function [99] o stop using the word 'just' [257] o sws: prevent "connection monitor" to say disconnect twice o synctime: fix use of uninitialized buffer on non-Windows [234] o system_win32: replace manual init code with `curlx_now_init()` call [170] o tests/server/sockfilt: avoid possible endless loop on Windows [101] o tests/server: drop unused `curlx/version_win32.c` [151] o tests/server: fix to clear the complete `srvr_sockaddr_union_t` variable [207] o tests/server: tidy-up error messages (Windows) [102] o tests: avoid assignment in `if` conditions in `first.h` [126] o tests: convert base64 data to %b64[] [87] o tftp: correct the filename length check [70] o timeout handling: auto-detect effective timeout [121] o tls: add new SSLSUPP flags for several options [32] o tls: remove checks for DEFAULT [136] o tool: enable header separation for HTTPS proxies [106] o tool: improve config error messaging [208] o tool: improve error/warning messages when output filename sanitization fails [36] o tool: rename curl handle and result variable in `--libcurl`-generated code [146] o tool: return code variable consistency [84] o tool_cb_hdr: suppress header output when --out-null [10] o tool_cb_prg: drop duplicate preprocessor logic [119] o tool_dirhie: drop superfluous `F_OK` fallback (Windows) [8] o tool_doswin: avoid memory-leak with CURL_FN_SANITIZE_* [236] o tool_doswin: avoid Windowsisms in socket code (cont.) [134] o tool_doswin: avoid Windowsisms in socket code [139] o tool_doswin: document `ENABLE_VIRTUAL_TERMINAL_PROCESSING` toolchain support [44] o tool_getparam: avoid `-Wcomma` with Apple clang in C89 mode [38] o tool_operate: remove 'else' for VMS [3] o tool_operate: reset the URL --url-query between --next [237] o typos: silence false positives found in C code [164] o unit3205: suppress two clang-tidy false positives [206] o URL-SYNTAX.md: fix port number mistakes for IMAP and LDAP [200] o url.c: code/comment cleanup around conn creation [132] o url.h: fix `-Wdocumentation` [61] o url: fix reuse of connections using HTTP Negotiate [100] o urlapi: use U_CURLU_URLDECODE when toggling it off unsigned [255] o urldata.h: remove two forward-declared structs not used [4] o urldata: byebye `conn->hostname_resolve` [240] o urldata: change 'keep_post' into three distinct bitfields [21] o urldata: convert 'long' fields to fixed variable types [47] o urldata: switch to uint* types [1] o usercertinmem: use the correct cert BIO [249] o verbose.md: explain the { and } prefixes [96] o vquic: fix unused variable warning reported by clang-tidy [152] o vquic: handle SOCKEMSGSIZE correctly [129] o vtls: dedupe common on-session-reuse logic [98] o vtls: use ALPN http/1.0 & http/1.1 for HTTP/1.0 requests [123] o VULN-DISCLOSURE-POLICY.md: push reports to the web form [154] o VULN-DISCLOSURE-POLICY.md: use hackerone [202] o winapi: use FormatMessageA instead of FormatMessageW [115] o windows: `USE_WINSOCK` to guard winsock2 code (where missing) [133] o windows: determine `RtlVerifyVersionInfo` address on global init [258] o windows: tidy up `wincrypt.h` / BoringSSL/AWS-LC coexist workaround [203] o wolfssl: fix build without USE_BIO_CHAIN [27] o ws/tftp: include header file even when protocol disabled [194] o x509asn1: make encodeOID stop on too long input [199] @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.34 2026/01/19 19:25:40 gutteridge Exp $ d4 1 a4 1 DISTNAME= curl-8.19.0 @ 1.35.2.1 log @Pullup ticket #7096 - requested by taca www/curl: Security fix Revisions pulled up: - www/curl/Makefile.common 1.36 - www/curl/PLIST 1.108 - www/curl/distinfo 1.224 --- Module Name: pkgsrc Committed By: wiz Date: Wed Apr 29 07:05:49 UTC 2026 Modified Files: pkgsrc/www/curl: Makefile.common PLIST distinfo Log Message: curl: update to 8.20.0. This release includes the following changes: o async-thrdd: use thread queue for resolving [144] o build: make NTLM disabled by default [90] o cmake: drop support for CMake 3.17 and older [108] o lib: add thread pool and queue [74] o lib: drop support for < c-ares 1.16.0 [64] o lib: make SMB support opt-in [18] o multi.h: add CURLMNWC_CLEAR_ALL [127] o rtmp: drop support [91] This release includes the following bugfixes: o altsvc: cap the list at 5,000 entries [183] o altsvc: drop the prio field from the struct [185] o altsvc: skip expired entries read from file [187] o asyn-ares: connect async [220] o asyn-ares: drop orphaned variable references [86] o asyn-ares: fix HTTPS-lookup when not on port 443 [100] o asyn-thrdd: drop redundant `result` check [291] o asyn-thrdd: fix clang-tidy unused value warning [125] o async-ares: fix query counter handling [195] o autotools: limit checksrc target to ignore non-repo test sources [12] o badwords-all: exit with correct code on errors [50] o badwords: combine the whitelisting into a single regex [1] o badwords: detect the the and with with [51] o badwords: only check comments and strings in source code [61] o badwords: rework exceptions, fix many of them [15] o boringssl: fix more coexist cases with Schannel/WinCrypt [170] o build: adjust/add casts to fix `-Wformat-signedness` [218] o build: assume `snprintf()` in `mprintf`, drop feature check [107] o build: compiler warning silencing tidy-ups [4] o build: drop `openssl` module dependency for BoringSSL from `libcurl.pc` [33] o build: drop duplicate `pthread.h` includes [158] o build: drop redundant `USE_QUICHE` guards [159] o build: enable `-Wimplicit-int-enum-cast` compiler warning, fix issues [84] o build: fix `-Wformat-signedness` by adjusting printf masks [226] o build: link `bcrypt.lib` via vcxproj files [239] o build: skip detecting `pipe2()` for Apple targets [227] o build: stop building and installing `runtests.1` and `testcurl.1` [235] o cf-https-connect: silence `-Wimplicit-int-enum-cast` with HTTPS-RR [132] o cf-https-connect: silence `-Wimplicit-int-enum-cast` with HTTPS-RR [63] o cf-ip-happy: limit concurrent attempts [191] o cf-socket: avoid low risk integer overflow on ancient Solaris [56] o cfilters: fix Curl_pollset_poll() return code mixup [206] o clang-tidy: avoid assignments in `if` expressions [175] o clang-tidy: enable more checks, fix fallouts [254] o cmake: add CMake Config-based dependency detection [87] o cmake: add CMake Config-based dependency detection for c-ares, wolfSSL [134] o cmake: do not install `wcurl` when `BUILD_CURL_EXE=OFF` [265] o cmake: do not install shell completions when `BUILD_CURL_EXE=OFF` [263] o cmake: document functions used from Windows system DLLs [103] o cmake: enable pthreads for BoringSSL/AWS-LC [196] o cmake: resolve targets recursively when generating `libcurl.pc` [45] o cmake: rework binutils ld hack to not read `LOCATION` property [41] o cmake: silence bad library `Threads::Threads` warning [131] o cmake: use `AIX` built-in variable (with CMake 4.0+) [163] o config2setopts: make --capath work in proxy disabled builds [113] o configure: fix `--with-ngtcp2=` option for crypto libs [26] o configure: fix LibreSSL ngtcp2 1.15.0+ crypto lib selection logic [3] o configure: prefer dependency-specific variables over `$withval` [35] o configure: remove superfluous experimental warning for HTTP/3 [169] o configure: silence useless clang warnings in C89 builds [156] o configure: tidy up comments [202] o connect: fix typo on error message o cookie: fix rejection when tabs in value [189] o curl-wolfssl.m4: fix to use the correct value for pkg-config directory [36] o curl.h: replace macros with C++-friendly method to enforce 3 args [110] o curl_ctype.h: fix spelling in a couple of locally used macros [28] o curl_get_line: error out on read errors [9] o curl_get_line: fix potential infinite loop when filename is a directory [46] o curl_ngtcp2: extend and update callbacks for 1.22.0+ [165] o curl_ntlm_core: drop redundant PP condition [140] o curl_ntlm_core: use wolfCrypt DES API with wolfSSL [200] o curl_setup.h: drop stray/unused `USE_OPENSSL_QUIC` guard [210] o curl_sha512_256: support delegating to wolfSSL API [149] o curl_version_info.md: clarify age details [69] o CURLOPT_HAPROXY_CLIENT_IP.md: mention assumption on data format [96] o CURLOPT_RTSP_SESSION_ID.md: clarify reuse "dangers" [270] o CURLOPT_RTSP_SESSION_ID.md: expand the comment [267] o CURLOPT_RTSP_SESSION_ID.md: minor language fix o CURLOPT_SOCKS5_AUTH.md: an access property [212] o CURLOPT_SSL_CTX_FUNCTION.md: expand on effects connection reuse [105] o CURLOPT_UPLOAD_FLAGS.md: expand [223] o curlx_now(), prevent zero timestamp [93] o DEPRECATE: fix minor release number typo o digest: pass in the user name quoted (as well) [34] o dns: https-eyeballing async [229] o dnscache: own source file, improvements [116] o docs/cmdline-opts/write-out.md: tls_earlydata was adeded in 8.13.0 o docs/cmdline-opts: tidy up retry-connrefused [190] o docs/lib: fix typos [53] o docs/libcurl: improve easy setopt examples [266] o docs: clarify retry-max-time timing [294] o docs: CURLOPT_LOGIN_OPTIONS is a login property [228] o docs: enable more compiler warnings for C snippets, fix 3 finds [71] o docs: list more dependencies for running Python HTTP tests [123] o docs: mention more zip bomb precautions [166] o docs: minor wording tweaks o docs: noproxy wants the punycoded hostname version [214] o docs: SSH host verification is done at connect time [197] o docs: use the correct CURLOPT_WRITEFUNCTION signature [142] o doh: fix memory-leak when doing a second DoH resolve [55] o doh: remove superfluous doh_req check [222] o examples/websocket: fix to sleep more on Windows [92] o examples: drop warning silencers no longer hit [14] o examples: fix typo in comment [75] o file: init fd to -1 to prevent close fd 0 on early failure [40] o fopen: for temp files, inherit permissions only for owner [146] o ftp: do not strdup DATA hostname [29] o ftp: make the MDTM date parser stricter (again) [115] o ftp: reject PWD responses containing control characters [95] o gcc: guard `#pragma diagnostic` in core code for <4.6 [94] o generate.bat: remove extra % from VC11 and VC12 runs o genserv.pl: make external calls safe [119] o getinfo: initialize `PureInfo` field `used_proxy` [43] o getinfo: repair CURLINFO_TLS_SESSION [193] o gnutls: fix clang-tidy warning with !verbose [126] o gtls: fail for large files in `load_file()` [174] o h3: HTTPS-RR use in HTTP/3 [221] o Happy Eyeballs: add resolution time delay [238] o haproxy: use correct ip version on client supplied address [275] o hostip: clear the sockaddr_in6 structure before use [20] o hostip: init the curl_jmpenv_lock appropriately [278] o hostip: resolve user supplied ip addresses [259] o HSTS: cap the list [177] o hsts: make the HSTS read callback handle name dupes [141] o hsts: skip expired HSTS entries read from file [188] o hsts: when a dupe host adds subdomains, use that [130] o http2: clear the h2 session at delete [99] o http2: prevent secure schemes pushed over insecure connections [181] o http2: return error on OOM in push headers [65] o HTTP3.md: drop outdated mentions of OpenSSL-QUIC [2] o http: clear credentials better on redirect [204] o http: clear digest nonce on cross-orgin redirect [269] o http: clear the proxy credentials as well on port or scheme change [246] o http: fix auth_used and auth_avail [154] o http: fix Curl_compareheader for multi value headers [11] o http: make Curl_compareheader handle multiple commas in header o http: on 303, switch to GET [208] o http: use header_has_value() instead of duplicate code [251] o imap: reset the UIDVALIDITY state between transfers [7] o include: drop 'will' from public headers [73] o INSTALL.md: update Cygwin instructions [198] o keylog.h: replace literal number with macro in declaration [171] o keylog: drop unused/redundant includes and guards [172] o ldap: drop duplicate `ldap_set_option()` on Windows [42] o ldap: fix to initialize cleartext connection on Windows [49] o lib1560: fix comment typo o lib1960: fix test failure [255] o lib: accept larger input to md5/hmac/sha256/sha512 functions [194] o lib: always use Curl_1st_fatal instead of Curl_1st_err [89] o lib: fix typos in comments [240] o lib: make resolving HTTPS DNS records reliable: [176] o lib: minor comment typos [237] o lib: move request specific allocations to the request struct [256] o lib: replace `PRI*32` printf masks with C89 ones [201] o libssh2: allocate libssh2-friendly memory in kbd_callback [225] o libssh2: fix error handling on quote errors [21] o libssh: fix 64-bit printf mask for mingw-w64 <=6.0.0 [215] o libssh: fix `-Wsign-compare` in 32-bit builds [217] o libssh: path length precaution [164] o libssh: propagate error back in SFTP function [178] o libtest: drop duplicate include [111] o location/follow: mention netrc [138] o man: fix argument type for `CURLSHOPT_[UN]SHARE` options [211] o mbedtls: cleanup more without care for 'initialized' [262] o mbedtls: fix ECJPAKE matching [135] o mbedtls: remove failf() call with first argument as NULL [249] o md4, md5: switch to wolfCrypt API in wolfSSL builds [139] o mime: only allow 40 levels of calls [241] o misc: fix code quality findings [209] o mk-ca-bundle.pl: make `ca-bundle.crt` timestamp match `certdata.txt`'s [44] o multi: enhance pending handles fairness [284] o multi: fix connection retry for non-http [180] o multi: improve wakeup and wait code [118] o netrc: find login-less password when user is given in URL [6] o netrc: remove unused parsenetrc() macro for netrc-disabled [121] o netrc: skip malformed macdef lines [67] o openssl channel_binding: lookup digest algorithm without NID [117] o openssl: drop obsolete SSLv2 logic [27] o openssl: fix build with 4.0.0-beta1 no-deprecated [184] o openssl: fix memory leaks in ECH code (OpenSSL 3) [78] o openssl: fix unused variable warnings in !verbose builds [252] o openssl: trace count of found / imported Windows native CA roots [8] o OS400: add new definitions to the ILE/RPG binding. [153] o os400sys: fix typo in comment (symetry -> symmetry) [58] o parsedate: bsearch the time zones [232] o parsedate: fix wrong treatment of "military time zones" [182] o parsedate: refactor [230] o perl: harden external command invocations [133] o progress: count amount of data "delivered" to application [66] o protocol.h: fix the CURLPROTO_MASK [31] o protocol: disable connection reuse for SMB(S) [199] o protocol: use scheme names lowercase [38] o proxy: chunked response, error code [143] o pytest: add additional quiche check for flaky test_05_01 [22] o pytest: check 429 handling [268] o rand: use `BCryptGenRandom()` in UWP builds [88] o ratelimit: reset on start [150] o request: reset resp_trailer in new requests [186] o runtests: skip setting ed25519 SSH key format [264] o rustls: fix memory leak on repeated SSLKEYLOGFILE fails [280] o rustls: handle EOF during initial handshake [203] o schannel: increase renegotiation timeout to 60 seconds [261] o scripts: drop redundant double-quotes: `"$var"` -> `$var` (Perl) [109] o scripts: harden / tidy up more Perl `system()` calls [70] o sectrust: fail on missing OCSP stapling [250] o sendf: fix CR detection if no LF is in the chunk [219] o setopt: clear proxy auth properties when switching [192] o setopt: fix typos in comments [257] o setopt: move CURLOPT_CURLU [260] o setup connection filter: mark as setup [234] o sha256, sha512_256: switch to wolfCrypt API [147] o sha256: support delegating to wolfSSL API [148] o share: concurrency handling, easy updates [104] o share: do bitshifts after the type is checked to be valid [216] o socks: reject zero-length GSSAPI/SSPI tokens from proxy [157] o socks: use dns filter for resolving [244] o spelling: fix typos [173] o src: use ftruncate() unconditionally [128] o sshserver.pl: harden more `system()` calls [81] o sshserver.pl: pass command-line to `system()` safely [82] o strerr: correct the strerror_s() return code condition [25] o sws: fix potential OOB write [80] o synctime: fix off-by-one read and write to a read-only buffer (Windows) [85] o test 766: flag as timing-dependent [136] o test1675: unit tests for URL API helper functions [248] o test459: switch to mode="warn" for stderr check [5] o testcurl.pl: replace shell commands with Perl `rmtree()` [76] o tests/unit/README: describe how to unit test static functions [60] o tests: avoid infinite recursion for `make check` [253] o tests: use %b64[] instead of "raw" base64 [245] o tool: check for curlinfo->age when determining if ssh backend [77] o tool: fix memory mixups [106] o tool: fix retries in parallel mode [137] o tool: fix two more allocator mismatches [155] o tool_cb_hdr: only truncate etags output when regular file [129] o tool_cb_rea: make waitfd() return void [168] o tool_cb_wrt: fix no-clobber error handling [39] o tool_cfgable: free the SSL signature algorithms [62] o tool_dirhie: fix to create drive-relative directory [276] o tool_formparse: propagate my_get_line errors when reading headers [102] o tool_getparam: use correct free function for libcurl memory [68] o tool_ipfs: accept IPFS gateway URL without set port number [13] o tool_msgs: avoid null pointer deref for early errors [98] o tool_operate: actually apply the --parallel-max-host limit [167] o tool_operate: drop the scheme-guessing in the -G handling [54] o tool_operate: fix condition for loading `curl-ca-bundle.crt` (Windows) [79] o tool_operate: fix memory-leak on failed uploads [124] o tool_operate: fix minor memory-leak on early error [23] o tool_operate: reset the upload glob counter for next URL [162] o tool_operhlp: fix `add_file_name_to_url()` result on OOM [32] o tool_operhlp: iterate through all slashes to find name [114] o tool_operhlp: propagate low-level OOM in `add_file_name_to_url()` [112] o tool_setopt: return error on OOM correctly [152] o tool_urlglob: fix memory-leak on glob range overflow [19] o top-complexity: prevent filename-based shell injection risk [101] o transfer: clear the old autoreferer [236] o transfer: clear the URL pointer in OOM to avoid UAF [179] o transfer: enable custom methods again on next transfer [30] o transfer: enhance secure check [10] o unit1675: fix `-Wformat-signedness` [274] o url: do not reuse a non-tls starttls connection if new requires TLS [145] o url: improve connection reuse on negotiate [160] o url: init req.no_body in DO so that it works for h2 push [161] o url: set default upload flags to CURLULFLAG_SEEN [224] o url: use the socks type for socks proxy [47] o url: use URL for url even in comments [52] o urlapi: fix handling of "file:///" [122] o urlapi: make dedotdotify handle leading dots correctly [97] o urlapi: same origin tests [213] o urlapi: stop extracting hostname from file:// URLs on Windows [247] o urlapi: verify the last letter of a scheme when set explicitly [16] o urldata.h: fix typo and lingering backtick [279] o urldata: connection bit ipv6_ip is wrong [59] o urldata: import port types and conn destination format [57] o urldata: make hstslist only present in HSTS builds [120] o urldata: make speeder_c uint32 [37] o urldata: move cookiehost to struct SingleRequest [242] o urldata: remove trailers_state [17] o vquic: fix variable name in fallback code [207] o vtls: fix comment typos and tidy up a type [285] o vtls: log when key logging is enabled. [288] o vtls_scache: check reentrancy [243] o vtls_scache: include cert_blob independently of verifypeer [231] o wolfssl: document v5.0.0 (2021-11-01) as minimum required [151] o wolfssl: fix `-Wmissing-prototypes` [233] o wolfssl: fix handling of abrupt connection close [24] o write-out.md: minor language fix [273] o write-out.md: tls_earlydata was adeded in 8.13.0 o ws: fix a blocking curl_ws_send() to report written length correctly [258] o x509asn1: fix to return error in an error case from `encodeOID()` [83] o x509asn1: fixed and adapted for ASN1tostr unit testing [48] o x509asn1: improve encodeOID [72] Planned upcoming removals include: o local crypto implementations o NTLM o SMB o TLS-SRP support See https://curl.se/dev/deprecate.html @ text @d1 1 a1 1 # $NetBSD$ d4 1 a4 1 DISTNAME= curl-8.20.0 @ 1.34 log @curl & libcurl-gnutls: fix BUILDLINK_API_DEPENDS.openssl The assignment shouldn't be placed in Makefile.common for more than one reason (openssl is a build option, it should be propagated to packages that link against libcurl, and, though harmless, makes no sense being applied to libcurl-gnutls). Related to PR pkg/59899. Also likely related to: https://mail-index.netbsd.org/tech-pkg/2026/01/16/msg031893.html @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.33 2026/01/12 11:03:55 mef Exp $ d4 1 a4 1 DISTNAME= curl-8.18.0 @ 1.33 log @PR pkg/59899 Another Fix for NetBSD/9.4, by BUILDLINK_API_DEPENDS.openssl+ As suggested by leot@@ See: https://mail-index.netbsd.org/pkgsrc-changes/2026/01/12/msg337875.html Thanks a lot, @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.32 2026/01/12 09:09:09 mef Exp $ a26 2 BUILDLINK_API_DEPENDS.openssl+= openssl>=3.0 @ 1.32 log @(www/curl) Fix build for NetBSD/9.4 by PREFER_PKGSRC @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.31 2026/01/07 08:06:33 wiz Exp $ d27 1 a27 4 .include "../../mk/bsd.prefs.mk" .if ${OPSYS} == "NetBSD" && ${OPSYS_VERSION} < 090500 PREFER_PKGSRC+= openssl .endif @ 1.31 log @curl: update to 8.18.0. This release includes the following changes: o build: drop support for VS2008 (Windows) [62] o build: drop Windows CE / CeGCC support [69] o gnutls: drop support for GnuTLS < 3.6.5 [167] o gnutls: implement CURLOPT_CAINFO_BLOB [168] o openssl: bump minimum OpenSSL version to 3.0.0 [60] This release includes the following bugfixes: o _PROGRESS.md: add the E unit, mention kibibyte [24] o alt-svc: more flexibility on same destination [298] o altsvc: accept ma/persist per alternative entry [287] o altsvc: make it one malloc instead of three per entry [266] o AmigaOS: increase minimum stack size for tool_main [137] o apple sectrust: fix ancient evaluation [327] o apple-sectrust: always ask when `native_ca_store` is in use [162] o asyn-ares: handle Curl_dnscache_mk_entry() OOM error [199] o asyn-ares: remove hostname free on OOM [122] o asyn-thrdd: fix Curl_async_getaddrinfo() on systems without getaddrinfo [265] o asyn-thrdd: release rrname if ares_init_options fails [41] o auth: always treat Curl_auth_ntlm_get() returning NULL as OOM [186] o autotools: add nettle library detection via pkg-config (for GnuTLS) [178] o autotools: drop autoconf <2.59 compatibility code (zz60-xc-ovr) [70] o autotools: fix LargeFile feature display on Windows (after prev patch) [276] o autotools: tidy-up `if` expressions [275] o badwords: add fist -> first, fix fallouts [388] o badwords: catch and fix threading-related words [320] o badwords: fix issues found in scripts and other files [142] o badwords: fix issues found in tests [156] o build: add build-level `CURL_DISABLE_TYPECHECK` options [163] o build: exclude clang prereleases from compiler warning options [154] o build: replace `-pedantic` with `-Wpedantic` when supported [306] o build: set `-Wno-format-signedness` [288] o build: tidy-up MSVC CRT warning suppression macros [140] o ccsidcurl: make curl_mime_data_ccsid() use the converted size [74] o cf-h1-proxy: support folded headers in CONNECT responses [296] o cf-https-connect: allocate ctx at first in cf_hc_create() [79] o cf-socket: drop feature check for `IPV6_V6ONLY` on Windows [210] o cf-socket: enable Win10 `TCP_KEEP*` options with old SDKs [323] o cf-socket: limit use of `TCP_KEEP*` to Windows 10.0.16299+ at runtime [157] o cf-socket: return OOM error if socket() fails due to OOM [341] o cf-socket: trace ignored errors [97] o cfilters: make conn_forget_socket a private libssh function [109] o checksrc.pl: detect assign followed by more than one space [26] o cmake: adjust defaults for target platforms not supporting shared libs [35] o cmake: define dependencies as `IMPORTED` interface targets [223] o cmake: delete unused file `CMake/CMakeConfigurableFile.in` [363] o cmake: disable `CURL_CA_PATH` auto-detection if `USE_APPLE_SECTRUST=ON` [16] o cmake: fix `ws2_32` reference in `curl-config.cmake` [201] o cmake: honor `CURL_DISABLE_INSTALL` and `CURL_ENABLE_EXPORT_TARGET` [106] o cmake: replace deprecated `OPENSSL_FOUND` with `OpenSSL_FOUND` [310] o cmake: replace deprecated `PERL_FOUND` with `Perl_FOUND` [312] o cmake: save and restore `CMAKE_MODULE_PATH` in `curl-config.cmake` [222] o cmake: set found status to OFF when not found (for compression deps) [359] o code: minor indent fixes before closing braces [107] o CODE_STYLE.md: sync banned function list with checksrc.pl [243] o compressed.md: might generate a huge amount of bytes [227] o config-win32.h: delete obsolete, non-Windows comments [295] o config-win32.h: drop unused/obsolete `CURL_HAS_OPENLDAP_LDAPSDK` [278] o config2setopts: add space in cookie header with multiple -b [344] o config2setopts: bail out if curl_url_get() returns OOM [102] o config2setopts: exit if curl_url_set() fails on OOM [105] o configure: delete unused variable [294] o conncache: silence `-Wnull-dereference` on gcc 14 RISC-V 64 [17] o conncontrol: reuse handling [170] o connect: reshuffle Curl_timeleft_ms to avoid 'redundant condition' [100] o connection: attached transfer count [228] o content_encoding: avoid strcpy [331] o cookie. return proper error on OOM [330] o cookie: allocate the main struct once cookie is fine [259] o cookie: flush better [218] o cookie: only keep and use the canonical cleaned up path [256] o cookie: propagate errors better, cleanup the internal API [118] o cookie: return error on OOM [131] o cookie: when parsing a cookie header, delay all allocations until okay [258] o cshutdn: acknowledge FD_SETSIZE for shutdown descriptors [25] o curl: fix progress meter in parallel mode [15] o curl_fopen: do not pass invalid mode flags to `open()` on Windows [84] o curl_gssapi: make sure Curl_gss_log_error() has an initialized buffer [257] o curl_ntlm_core: fix DES_* symbols for some wolfSSL builds [281] o curl_quiche: refuse headers with CR, LF or null bytes [333] o curl_sasl: if redirected, require permission to use bearer [250] o curl_sasl: make Curl_sasl_decode_mech compare case insensitively [160] o curl_setup.h: document more funcs flagged by `_CRT_SECURE_NO_WARNINGS` [124] o curl_setup.h: drop stray `#undef stat` (Windows) [103] o curl_setup.h: drop superfluous parenthesis from `Curl_safefree` macro [242] o curl_threads: don't do another malloc if the first fails [345] o curl_trc: delete unused DoH remains [272] o CURLINFO: remove 'get' and 'get the' from each short desc [50] o CURLINFO_SCHEME/PROTOCOL: they return the "scheme" for a "transfer" [48] o CURLINFO_TLS_SSL_PTR.md: remove CURLINFO_TLS_SESSION text [49] o CURLMOPT_SOCKETFUNCTION.md: fix the callback argument use [206] o CURLOPT_ACCEPT_ENCODING.md: warn about the expansion [224] o CURLOPT_FOLLOWLOCATION.md: s/Authentication:/Authorization:/ [283] o CURLOPT_HAPROXY_CLIENT_IP.md: emphasize reused connection use [328] o CURLOPT_READFUNCTION.md: clarify the size of the buffer [47] o CURLOPT_SSH_KEYFUNCTION.md: fix minor indent mistake in example o curlx/fopen: replace open CRT functions their with `_s` counterparts (Windows) [204] o curlx/multibyte: stop setting macros for non-Windows [226] o curlx/strerr: use `strerror_s()` on Windows [75] o curlx: add `curlx_rename()`, fix to support long filenames on Windows [354] o curlx: curlx_strcopy() instead of strcpy() [326] o curlx: limit use of system allocators to the minimum possible [169] o curlx: replace `mbstowcs`/`wcstombs` with `_s` counterparts (Windows) [143] o curlx: replace `sprintf` with `snprintf` [194] o curlx: use curl alloc in `curlx_win32_stat()` (Windows) [360] o curlx: use curlx allocators in non-memdebug builds (Windows) [155] o DEPRECATE: add CMake <3.18 deprecation for April 2026 [291] o digest: fix OWS and escaped quote handling [391] o digest_sspi: fix a memory leak on error path [149] o digest_sspi: properly free sspi identity [12] o DISTROS.md: add OpenBSD [126] o DISTROS: fix a Mageia URL o DISTROS: remove broken URLs for buildroot o doc: some returned in-memory data may not be altered [196] o Dockerfile: update debian:bookworm-slim digest to e899040 [305] o docs/libcurl: fix C formatting nits [207] o docs: add a note about --compressed to note about binary output [381] o docs: clarify how to do unix domain sockets with SOCKS proxy [240] o docs: fix checksrc `EQUALSPACE` warnings [21] o docs: fix time_posttransfer output unit as seconds [335] o docs: mention umask need when curl creates files [56] o docs: remove dead URLs o docs: rename CURLcode variables to 'result' o docs: spell it Rustls with a capital R [181] o docs: switch more URLs to https:// [229] o docs: use .example URLs for proxies o docs: use mresult as variable name for CURLMcode o escape: add a length check in curl_easy_escape [284] o example: fix formatting nits [232] o examples/crawler: fix variable [92] o examples/multi-uv: fix invalid req->data access [177] o examples/threaded-ssl: delete in favor of `examples/threaded` [318] o examples/threaded: fix race condition [101] o examples: fix minor typo [203] o examples: make functions/data static where missing [139] o examples: tidy-up headers and includes [138] o examples: use 64-bit `fstat` on Windows [301] o FAQ/TODO/KNOWN_BUGS: convert to markdown [307] o FAQ: fix hackerone URL o file: do not pass invalid mode flags to `open()` on upload (Windows) [83] o formdata: validate callback is non-NULL before use [267] o ftp: make EPRT connections non-blocking [268] o ftp: refactor a piece of code by merging the repeated part [40] o ftp: remove #ifdef for define that is always defined [76] o ftp: return better on OOM in two places [343] o ftp: return from ftp_state_use_port immediately on OOM [338] o getenv: drop internal 1-to-1 wrapper [334] o getinfo: improve perf in debug mode [99] o gnutls: add PROFILE_MEDIUM as default [233] o gnutls: report accurate error when TLS-SRP is not built-in [18] o gtls: add return checks and optimize the code [2] o gtls: Call keylog_close in cleanup o gtls: skip session resumption when verifystatus is set o h2/h3: handle methods with spaces [146] o headers: add length argument to Curl_headers_push() [309] o hostcheck: fail wildcard match if host starts with a dot [235] o hostip.h: drop redundant `setjmp.h` include [380] o hostip: don't store negative lookup on OOM [61] o hostip: make more functions return CURLcode [202] o hostip: only store negative response for CURLE_COULDNT_RESOLVE_HOST [183] o hsts: propagate and error out correctly on OOM [130] o hsts: use one malloc instead of two per entry [263] o http: acknowledge OOM errors from Curl_input_ntlm [185] o http: avoid two strdup()s and do minor simplifications [144] o http: error on OOM when creating range header [59] o http: fix OOM exit in Curl_http_follow [179] o http: handle oom error from Curl_input_digest() [192] o http: replace atoi use in Curl_http_follow with curlx_str_number [65] o http: return OOM errors from hsts properly [262] o http: the :authority header should never contain user+password [147] o http: unfold response headers earlier [277] o idn: avoid allocations and wcslen on Windows [247] o idn: clarify null-termination on Windows [324] o idn: fix memory leak in `win32_ascii_to_idn()` [173] o idn: use curlx allocators on Windows [165] o imap: check buffer length before accessing it [308] o imap: make sure Curl_pgrsSetDownloadSize() does not overflow [200] o inet_ntop: avoid the strlen() [371] o INSTALL-CMAKE.md: document static option defaults more [37] o krb5: fix detecting channel binding feature [187] o krb5_sspi: unify a part of error handling [80] o ldap: call ldap_init() before setting the options [236] o ldap: drop PP logic for old, unsupported, Windows SDKs [279] o ldap: improve detection of Apple LDAP [174] o ldap: provide version for "legacy" ldap as well [254] o lib/sendf.h: forward declare two structs [221] o lib: cleanup for some typos about spaces and code style [3] o lib: create unitprotos.h in the builddir, not srcdir [322] o lib: drop unused or duplicate `curlx/timeval.h` includes [384] o lib: drop unused protocol headers [270] o lib: eliminate size_t casts [112] o lib: error for OOM when extracting URL query [127] o lib: fix formatting nits (part 2) [253] o lib: fix formatting nits (part 3) [248] o lib: fix formatting nits [215] o lib: fix gssapi.h include on IBMi [55] o lib: name the main CURLMcode variable 'mresult' [316] o lib: refactor the type of funcs which have useless return and checks [1] o lib: replace `_tcsncpy`/`wcsncpy`/`wcscpy` with `_s` counterparts (Windows) [164] o lib: timer stats improvements [190] o lib: use `SOCKET_WRITABLE()`/`SOCKET_READABLE()` where possible [350] o libssh2: add paths to error messages for quote commands [114] o libssh2: cleanup ssh_force_knownhost_key_type [64] o libssh2: consider strdup() failures OOM and return correctly [72] o libssh2: replace atoi() in ssh_force_knownhost_key_type [63] o libssh: fix state machine loop to progress as it should o libssh: properly free sftp_attributes [153] o libssh: require private key or user-agent for public key auth [293] o libssh: set both knownhosts options to the same file [271] o libtests: replace `atoi()` with `curlx_str_number()` [120] o limit-rate: add example using --limit-rate and --max-time together [89] o localtime: detect thread-safe alternatives and use them [325] o m4/sectrust: fix test(1) operator [4] o manage: expand the 'libcurl support required' message [208] o mbedTLS: cleanup insecure/deprecated code [351] o mbedtls: fix potential use of uninitialized `nread` [8] o mbedtls: sync format across log messages [213] o mbedtls_threadlock: avoid calloc, use array [244] o mdlinkcheck: ignore IP numbers, allow '@@' in raw URLs o mdlinkcheck: only look for markdown links in markdown files [311] o memdebug: add mutex for thread safety [184] o memdebug: fix realloc logging [286] o mk-ca-bundle.md: the file format docs URL is permaredirected [188] o mk-ca-bundle.pl: default to SHA256 fingerprints with `-t` option [73] o mk-ca-bundle.pl: use `open()` with argument list to replace backticks [71] o mqtt: reject overly big messages [39] o mqtt: return error when a too large packet is decoded [366] o multi: make max_total_* members size_t [158] o multi: remove MSTATE_TUNNELING [297] o multi: simplify admin handle processing [189] o multibyte: limit `curlx_convert_*wchar*()` functions to Unicode builds [135] o ngtcp2+openssl: fix leak of session [172] o ngtcp2: remove the unused Curl_conn_is_ngtcp2 function [85] o ngtcp2: retune window sizes [365] o noproxy: fix build on systems without IPv6 [264] o noproxy: fix ipv6 handling [239] o noproxy: replace atoi with curlx_str_number [67] o openssl: exit properly on OOM when getting certchain [133] o openssl: fix a potential memory leak of bio_out [150] o openssl: fix a potential memory leak of params.cert [151] o openssl: fix building against no-dsa openssl [386] o openssl: fix building against no-ocsp openssl with Apple SecTrust [385] o openssl: no verify failf message unless strict [166] o openssl: release ssl_session if sess_reuse_cb fails [43] o openssl: remove code handling default version [28] o openssl: simplify `HAVE_KEYLOG_CALLBACK` guard [212] o openssl: stop checking for `OPENSSL_NO_SHA*` macros [382] o openssl: stop checking for `OPENSSL_NO_TLSEXT` macro [383] o openssl: toggling CURLSSLOPT_NO_PARTIALCHAIN makes a different CA cache [313] o OS400/ccsidcurl: fix curl_easy_setopt_ccsid for non-converted blobs [94] o OS400/makefile.sh: fix shellcheck warning SC2038 [86] o os400sys: replace `strcpy()` with `memcpy()` [273] o osslq: code readability [5] o progress: make it one column narrower [352] o progress: narrower time display, multiple fixes [369] o progress: show fewer digits [78] o projects/README.md: Markdown fixes [148] o pytest fixes and improvements [159] o pytest: add tests using sshd [303] o pytest: disable two H3 earlydata tests for all platforms (was: macOS) [116] o pytest: do not ignore server issues [329] o pytest: enable OCSP test 17_08 for LibreSSL [364] o pytest: fix and improve reliability [251] o pytest: improve stragglers [252] o pytest: quiche flakiness [280] o pytest: skip H2 tests if feature missing from curl [46] o quiche: use client writer [255] o ratelimit blocking: fix busy loop [290] o ratelimit: redesign [209] o rtmp: fix double-free on URL parse errors [27] o rtmp: precaution for a potential integer truncation [54] o rtmp: stop redefining `setsockopt` system symbol on Windows [211] o runner.pm: run memanalyzer as a Perl module [260] o runtests: add options to set minimum number of tests, use them [302] o runtests: detect bad libssh differently for test 1459 [11] o runtests: drop Python 2 support remains [45] o runtests: enable torture testing with threaded resolver [176] o runtests: improve XML prolog check, enable `-w` permanently, fix two tests [231] o runtests: make memanalyzer a Perl module (for 1.1-2x speed-up per test run) [238] o rustls: fix a potential memory issue [81] o rustls: minor adjustment of sizeof() [38] o rustls: simplify init err path [219] o rustls: verify that verifier_builder is not NULL [220] o schannel: cap the maximum allowed size for loading cert [274] o schannel: fix memory leak of cert_store_path on four error paths [23] o schannel: replace atoi() with curlx_str_number() [119] o schannel: use Win8 `CERT_NAME_SEARCH_ALL_NAMES_FLAG` with old SDKs [321] o schannel_verify: fix a memory leak of cert_context [152] o scripts: fix shellcheck SC2046 warnings [90] o scripts: use end-of-options marker in `find -exec` commands [87] o setopt: disable CURLOPT_HAPROXY_CLIENT_IP on NULL [30] o setopt: when setting bad protocols, don't store them [9] o sftp: fix range downloads in both SSH backends [82] o slist: constify Curl_slist_append_nodup() string argument [195] o smb: fix a size check to be overflow safe [161] o socketpair: drop redundant `_WIN32` branch and include [367] o socks_sspi: use free() not FreeContextBuffer() [93] o source: misc typos [372] o speedcheck: do not trigger low speed cancel on transfers with CURL_READFUNC_PAUSE [113] o speedlimit: also reset on send unpausing [197] o src: drop redundant definition of `BIT()` [357] o src: fix formatting nits [246] o ssh: tracing and better pollset handling [230] o sspi: fix memory leaks on error paths in `Curl_create_sspi_identity()` [237] o sws: fix binding to unix socket on Windows [214] o synctime: tidy up, make it work on all platforms [269] o telnet: abort on bad suboption sequence [300] o telnet: replace atoi for BINARY handling with curlx_str_number [66] o TEST-SUITE.md: correct the man page's path [136] o test07_22: fix flakiness [95] o test1475: consistently use %CR in headers [234] o test1498: disable 'HTTP PUT from stdin' test on Windows [115] o test2045: replace HTML multi-line comment markup with `#` comments [36] o test318: tweak the name a little o test3207: enable memdebug for this test again [249] o test363: delete stray character (typo) from a section tag [52] o test568: fix codespell, catch it next time early in CI [299] o test568: remove what looks like an email and a URL [304] o test787: fix possible typo `&` -> `%` in curl option [241] o test96: fix to accept non-unity memdump content with MSVC [339] o tests/data: move `--libcurl` output to external data files [34] o tests/data: replace hard-coded test numbers with `%TESTNUMBER` [33] o tests/data: support using native newlines on disk, drop `.gitattributes` [91] o tests/server: do not fall back to original data file in `test2fopen()` [32] o tests/server: fix initialization on Windows Vista+ [216] o tests/server: replace `atoi()` and `atol()` with `curlx_str_number()` [110] o tests: add `%AMP` macro, use it in two tests [245] o tests: add a standard log line for alloc failures [319] o tests: allow 2500-2503 to use ~2MB malloc [31] o tests: drop redundant parenthesis from two macro expressions [376] o tests: fix formatting nits [225] o tests: rename CURLMcode variables to mresult o tftp: release filename if conn_get_remote_addr fails [42] o tftpd: fix/tidy up `open()` mode flags [57] o tidy-up: avoid `(())`, clang-format fixes and more [141] o tidy-up: move `CURL_UNCONST()` out from macro `curl_unicodefree()` [121] o tidy-up: URLs (cont.) and mdlinkcheck [285] o tidy-up: URLs [182] o TODO: remove a mandriva.com reference o tool: consider (some) curl_easy_setopt errors fatal [7] o tool: log when loading .curlrc in verbose mode [191] o tool_cfgable: free ssl-sessions at exit [123] o tool_doswin: clear pointer when thread takes ownership [198] o tool_doswin: increase allowable length of path sanitizer [289] o tool_doswin: remove the max length check [374] o tool_getparam: simplify the --rate parser [373] o tool_getparam: use memdup0() instead of malloc + copy [390] o tool_getparam: verify that a file exists for some options [134] o tool_help: add checks to avoid unsigned wrap around [14] o tool_ipfs: check return codes better [20] o tool_msgs: make voutf() use stack instead of heap [125] o tool_operate: exit on curl_share_setopt errors [108] o tool_operate: fix a case of ignoring return code in operate() [128] o tool_operate: fix case of ignoring return code in single_transfer [129] o tool_operate: remove redundant condition [19] o tool_operate: return error for OOM in append2query [217] o tool_operate: use curlx_str_number instead of atoi [68] o tool_paramhlp: refuse --proto remove all protocols [10] o tool_paramhlp: remove a malloc+free from proto2num() [378] o tool_paramhlp: simplify number parsing [375] o tool_progress: fix large time outputs and decimal size display [379] o tool_urlglob: acknowledge OOM in peek_ipv6 [175] o tool_urlglob: clean up used memory on errors better [44] o tool_urlglob: constify an argument [361] o tool_urlglob: fix propagating OOM error from `sanitize_file_name()` [342] o tool_urlglob: support globs as long as config line lengths [282] o tool_writeout: bail out proper on OOM [104] o url: fix return code for OOM in parse_proxy() [193] o url: if curl_url_get() fails due to OOM, error out properly [205] o url: if OOM in parse_proxy() return error [132] o url: return error at once when OOM in netrc handling [332] o urlapi: fix mem-leaks in curl_url_get error paths [22] o urlapi: handle OOM properly when setting URL [180] o urlapi: return OOM correctly from parse_hostname_login() [337] o verify-release: update to avoid shellcheck warning SC2034 [88] o vquic-tls/gnutls: call Curl_gtls_verifyserver unconditionally [96] o vquic: do not pass invalid mode flags to `open()` (Windows) [58] o vquic: do_sendmsg full init [171] o vquic: ignore 0-length UDP packets [336] o vquic: initialize new callback in nghttp3 1.14.0+ [317] o vtls: drop unused `use_alpn` from `ssl_connect_data` struct [355] o vtls: fix CURLOPT_CAPATH use [51] o vtls: handle possible malicious certs_num from peer [53] o vtls: pinned key check [98] o VULN-DISCLOSURE-POLICY.md: CRLF in data [349] o wcurl: import v2025.11.09 [29] o wcurl: import v2026.01.05 [315] o windows: assume `USE_WIN32_LARGE_FILES` [292] o windows: fix `CreateFile()` calls to support long filenames [356] o windows: use `_strdup()` instead of `strdup()` where missing [145] o wolfSSL: able to differentiate between IP and DNS in alt names [13] o wolfssl: avoid NULL dereference in OOM situation [77] o wolfssl: fix a potential memory leak of session [6] o wolfssl: fix cipher list, skip 5.8.4 regression [117] o wolfssl: fix possible assert with `!HAVE_NO_EX` wolfSSL builds [261] o wolfssl: proof use of wolfSSL_i2d_SSL_SESSION [314] o wolfssl: simplify wssl_send_earlydata [111] o ws: replace a cast by matching the format string [358] o x509asn1: drop unused `hostcheck.h`, `vtls_int.h` includes [340] @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.30 2025/11/05 09:30:18 wiz Exp $ d26 6 @ 1.30 log @curl: update to 8.17.0. This release includes the following changes: o build: drop Heimdal support [267] o build: drop the winbuild build system [81] o krb5: drop support for Kerberos FTP [43] o libssh2: up the minimum requirement to 1.9.0 [85] o multi: add notifications API [250] o progress: expand to use 6 characters per size [234] o ssl: support Apple SecTrust configurations [240] o tool_getparam: add --knownhosts [204] o vssh: drop support for wolfSSH [58] o wcurl: import v2025.11.04 [431] o write-out: make %header{} able to output *all* occurrences of a header [25] This release includes the following bugfixes: o ares: fix leak in tracing [91] o asyn-ares: remove wrong comment about the callback argument [306] o asyn-ares: use the duped hostname pointer for all calls [158] o asyn-thrdd resolver: clear timeout when done [97] o asyn-thrdd: drop pthread_cancel [30] o autotools: add support for libgsasl auto-detection via pkg-config [112] o autotools: capitalize Rustls in the log output [106] o autotools: drop detection of ancient OpenSSL libs RSAglue and rsaref [354] o autotools: fix duplicate UNIX and BSD flags in buildinfo.txt [113] o autotools: fix silly mistake in clang detection for buildinfo.txt [114] o autotools: make --enable-code-coverage support llvm/clang [79] o autotools: merge `if`s in GnuTLS/OpenSSL feature detection [385] o aws-lc: re-enable large read-ahead with v1.61.0 again [16] o base64: accept zero length argument to base64_encode [82] o build: address some -Weverything warnings, update picky warnings [74] o build: avoid overriding system open and stat symbols [141] o build: avoid overriding system symbols for fopen functions [150] o build: avoid overriding system symbols for socket functions [68] o build: show llvm/clang in platform flags and buildinfo.txt [126] o c-ares: when resolving failed, persist error [270] o cf-h2-proxy: break loop on edge case [140] o cf-ip-happy: mention unix domain path, not port number [161] o cf-socket: always check Curl_cf_socket_peek() return code [198] o cf-socket: check params and remove accept procondition [197] o cf-socket: make set_local_ip void, and remove failf() [390] o cf-socket: set FD_CLOEXEC on all sockets opened [273] o cf-socket: tweak a memcpy() to read better [177] o cf-socket: use the right byte order for ports in bindlocal [61] o cfilter: unlink and discard [46] o cfilters: check return code from Curl_pollset_set_out_only() [402] o checksrc: allow disabling warnings on FIXME/TODO comments [324] o checksrc: catch banned functions when preceded by ( [146] o checksrc: fix possible endless loop when detecting BANNEDFUNC [149] o checksrc: fix possible endless loops in the banned function logic [220] o checksrc: fix to handle ) predecing a banned function [229] o checksrc: reduce directory-specific exceptions [228] o CI.md: refresh [280] o cmake/FindGSS: dedupe pkg-config module strings [277] o cmake/FindGSS: drop wrong header check for GNU GSS [278] o cmake/FindGSS: fix pkg-config fallback logic for CMake <3.16 [189] o cmake/FindGSS: simplify/de-dupe lib setup [253] o cmake/FindGSS: whitespace/formatting [268] o cmake: add and use local FindGnuTLS module [379] o cmake: add CURL_CODE_COVERAGE option [78] o cmake: build the "all" examples source list dynamically [245] o cmake: clang detection tidy-ups [116] o cmake: drop exclamation in comment looking like a name [160] o cmake: fix `HAVE_GNUTLS_SRP` detection after adding local FindGnuTLS module [458] o cmake: fix building docs when the base directory contains .3 [18] o cmake: fix Linux pre-fill `HAVE_POSIX_STRERROR_R` (when `_CURL_PREFILL=ON`) o cmake: fix Linux pre-fills for non-glibc (when `_CURL_PREFILL=ON`) [372] o cmake: minor Heimdal flavour detection fix [269] o cmake: pre-fill three more type sizes on Windows [244] o cmake: say 'absolute path' in option descriptions and docs [378] o cmake: support building some complicated examples, build them in CI [235] o cmake: use modern alternatives for get_filename_component() [102] o cmake: use more COMPILER_OPTIONS, LINK_OPTIONS / LINK_FLAGS [152] o cmdline-docs: extended, clarified, refreshed [28] o cmdline-opts/_PROGRESS.md: explain the suffixes [154] o configure: add "-mt" for pthread support on HP-UX [52] o conn: fix hostname move on connection reuse [272] o conncache: prevent integer overflow in maxconnects calculation [438] o connect: for CONNECT_ONLY, CURLOPT_TIMEOUT does not apply [404] o connect: remove redundant condition in shutdown start [289] o cookie: avoid saving a cookie file if no transfer was done [11] o cookie: only count accepted cookies in Curl_cookie_add [364] o cookie: remove the temporary file on (all) errors [356] o cpool: make bundle->dest an array; fix UB [218] o curl.h: remove incorrect comment about CURLOPT_PINNEDPUBLICKEY [320] o curl_easy_getinfo: error code on NULL arg [2] o curl_easy_setopt.md: add missing CURLOPT_POSTFIELDS [319] o curl_mem_undef.h: limit to CURLDEBUG for non-memalloc overrides [19] o curl_ngtcp2: fix `-Wunreachable-code` with H3 !verbose !unity clang [383] o curl_osslq: error out properly if BIO_ADDR_rawmake() fails [184] o curl_path: make sure just whitespace is illegal [351] o Curl_resolv: fix comment. 'entry' argument is not optional [187] o curl_slist_append.md: clarify that a NULL pointer is not acceptable [72] o curl_threads: delete WinCE fallback branch [233] o CURLINFO_FTP_ENTRY_PATH.md: this is for SFTP as well [8] o CURLOPT_COOKIEFILE.md: clarify when the cookies are loaded [159] o CURLOPT_COPYPOSTFIELDS.md: used with MQTT and RTSP as well [457] o CURLOPT_HEADER/WRITEFUNCTION.md: drop '* size' since size is always 1 [63] o CURLOPT_MAXLIFETIME_CONN: make default 24 hours [10] o CURLOPT_POSTFIELDSIZE*: these also work for MQTT and RTSP [395] o CURLOPT_SERVER_RESPONSE_TIMEOUT*: add default and see-also [397] o CURLOPT_SSL_VERIFYHOST.md: add see-also to two other VERIFYHOST options [32] o CURLOPT_TIMECONDITION.md: works for FILE and FTP as well [27] o cw-out: fix EAGAIN handling on pause [452] o cw-out: unify the error handling pattern in cw_out_do_write [414] o digest_sspi: fix two memory leaks in error branches [77] o dist: do not distribute CI.md [29] o docs/cmdline-opts: drop double quotes from GLOBBING and URL examples [238] o docs/libcurl: clarify some timeout option behavior [15] o docs/libcurl: remove ancient version references [7] o docs/libcurl: use lowercase must [5] o docs: expand on quoting rules for file names in SFTP quote [300] o docs: fix/tidy code fences [87] o doh: cleanup resources on error paths [434] o doswin: CloseHandle the thread on shutdown [307] o easy_getinfo: check magic, Curl_close safety [3] o ECH.md: make OpenSSL branch clone instructions work [430] o examples/chkspeed: portable printing when outputting curl_off_t values [365] o examples/http2-serverpush: fix file handle leaks [428] o examples/sessioninfo: cast printf string mask length to int [232] o examples/sessioninfo: do not disable security [255] o examples/synctime: fix null termination assumptions [297] o examples/synctime: make the sscanf not overflow the local buffer [252] o examples/usercertinmem: avoid stripping const [247] o examples/websocket: fix use of uninitialized rlen [346] o examples: call curl_global_cleanup() where missing [323] o examples: check more errors, fix cleanups, scope variables [318] o examples: drop unused curl/mprintf.h includes [224] o examples: fix build issues in 'complicated' examples [243] o examples: fix more potential resource leaks, and more [426] o examples: fix two build issues surfaced with WinCE [223] o examples: fix two issues found by CodeQL [35] o examples: fix two more cases of stat() TOCTOU [147] o examples: improve global init, error checks and returning errors [321] o examples: replace casts with `curl_off_t` printf masks [358] o examples: return curl_easy_perform() results [322] o firefox-db2pem.sh: add macOS support, tidy-ups [348] o form.md: drop reference to MANUAL [178] o ftp: add extra buffer length check [195] o ftp: check errors on remote ip for data connection [423] o ftp: fix ftp_do_more returning with *completep unset [122] o ftp: fix port number range loop for PORT commands [66] o ftp: fix the 213 scanner memchr buffer limit argument [196] o ftp: improve fragile check for first digit > 3 [194] o ftp: reduce size of some struct fields [418] o ftp: remove 'newhost' and 'newport' from the ftp_conn struct [419] o ftp: remove misleading comments [193] o ftp: remove the retr_size_saved struct field [416] o ftp: remove the state_saved struct field [417] o ftp: replace strstr() in ;type= handling [313] o ftp: simplify the 150/126 size scanner [288] o gnutls: check conversion of peer cert chain [275] o gnutls: fix re-handshake comments [422] o gssapi: make channel binding conditional on GSS_C_CHANNEL_BOUND_FLAG [446] o gtls: avoid potential use of uninitialized variable in trace output [83] o gtls: check the return value of gnutls_pubkey_init() [456] o header.md: see-also --proxy-header and vice versa [396] o hmac: free memory properly on errors [377] o hostip: don't store negative resolves due unrelated errors [256] o hostip: fix infof() output for non-ipv6 builds using IPv6 address [338] o hostip: remove leftover INT_MAX check in Curl_dnscache_prune [88] o http2: check push header names by length first [261] o http2: cleanup pushed newhandle on fail [260] o http2: ingress handling edge cases [259] o HTTP3: clarify the status for "old" OpenSSL, not current [394] o http: check the return value of strdup [437] o http: fix `-Wunreachable-code` in !websockets !unity builds [443] o http: fix `-Wunused-variable` in !alt-svc !proxy !ws builds [442] o http: handle user-defined connection headers [165] o http: look for trailing 'type=' in ftp:// without strstr [315] o http: make Content-Length parser more WHATWG [183] o http: only accept ';' as a separator for custom headers [407] o http: return error for a second Location: header [393] o http_aws_sigv4: check the return value of curl_maprintf() [381] o http_proxy: fix adding custom proxy headers [424] o httpsrr: free old pointers when storing new [57] o httpsrr: send HTTPS query to the right target [435] o imap: fix custom FETCH commands to handle literal responses [441] o imap: parse and use UIDVALIDITY as a number [420] o imap: treat capabilities case insensitively [345] o INSTALL-CMAKE.md: add manual configuration examples [360] o INSTALL-CMAKE.md: document useful build targets [215] o INSTALL-CMAKE.md: fix descriptions for LDAP dependency options [382] o INSTALL: update the list of known operating systems [325] o INTERNALS: drop Winsock 2.2 from the dependency list [162] o ip-happy: do not set unnecessary timeout [95] o ip-happy: prevent event-based stall on retry [155] o kerberos: bump minimum to 1.3 (2003-07-08), drop legacy logic [279] o kerberos: drop logic for MIT Kerberos <1.2.3 (pre-2002) versions [285] o kerberos: stop including gssapi/gssapi_generic.h [282] o krb5: fix output_token allocators in the GSS debug stub (Windows) [326] o krb5: return appropriate error on send failures [22] o krb5_gssapi: fix memory leak on error path [190] o krb5_sspi: the chlg argument is NOT optional [200] o ldap: avoid null ptr deref on failure [284] o ldap: do not base64 encode zero length string [42] o ldap: do not pass a \n to failf() [370] o ldap: tidy-up types, fix error code confusion [191] o lib1514: fix return code mixup [304] o lib: delete unused crypto header includes [384] o lib: drop unused include and duplicate guards [226] o lib: fix build error with verbose strings disabled [173] o lib: remove newlines from failf() calls [366] o lib: remove personal names from comments [168] o lib: SSL connection reuse [301] o lib: stop NULL-checking conn->passwd and ->user [309] o lib: upgrade/multiplex handling [136] o libcurl-multi.md: added curl_multi_get_offt mention [53] o libcurl-security.md: mention long-running connections [6] o libssh/libssh2: reject quote command lines with too much data [299] o libssh/sftp: fix resume corruption by avoiding O_APPEND with rresume [263] o libssh2/sftp: fix resume corruption by avoiding O_APPEND with rresume [262] o libssh2/sftp_realpath: change state consistently [185] o libssh2: avoid risking using an uninitialized local struct field [209] o libssh2: bail out on chgrp and chown number parsing errors [202] o libssh2: clarify that sshp->path is always at least one byte [201] o libssh2: drop two redundant null-terminations [26] o libssh2: error check and null-terminate in ssh_state_sftp_readdir_link() [34] o libssh2: fix EAGAIN return in ssh_state_auth_agent [290] o libssh2: fix return code for EAGAIN [186] o libssh2: use sockindex consistently [302] o libssh: acknowledge SSH_AGAIN in the SFTP state machine [89] o libssh: catch a resume point larger than the size [281] o libssh: clarify myssh_block2waitfor [92] o libssh: drop two unused assignments [104] o libssh: error on bad chgrp number [71] o libssh: error on bad chown number and store the value [64] o libssh: fix range parsing error handling mistake [120] o libssh: make atime and mtime cap the timestamp instead of wrap [283] o libssh: react on errors from ssh_scp_read [24] o libssh: return out of memory correctly if aprintf fails [60] o libssh: return the proper error for readdir problems [355] o Makefile.example: bump default example from FTP to HTTPS [389] o Makefile.example: fix option order [231] o Makefile.example: make default options more likely to work [388] o Makefile.example: simplify and make it configurable [20] o managen: ignore version mentions < 7.66.0 [55] o managen: render better manpage references/links [54] o managen: strict protocol check [109] o managen: verify the options used in example lines [181] o mbedtls: add support for 4.0.0 [344] o mbedtls: check result of setting ALPN [127] o mbedtls: fix building with <3.6.1 [400] o mbedtls: fix building with sha-256 missing from PSA [391] o mbedtls: handle WANT_WRITE from mbedtls_ssl_read() [145] o md4: drop mbedtls implementation (not available in mbedtls v3+) [406] o mdlinkcheck: reject URLs containing quotes [174] o memdup0: handle edge case [241] o mime: fix unpausing of readers [375] o mime: fix use of fseek() [334] o multi.h: add CURLMINFO_LASTENTRY [51] o multi: check the return value of strdup() [436] o multi_ev: remove unnecessary data check that confuses analysers [167] o netrc: when the cached file is discarded, unmark it as loaded [409] o nghttp3: return NGHTTP3_ERR_CALLBACK_FAILURE from recv_header [227] o ngtcp2: add a comment explaining write result handling [340] o ngtcp2: adopt ngtcp2_conn_get_stream_user_data if available [362] o ngtcp2: check error code on connect failure [13] o ngtcp2: close just-opened QUIC stream when submit_request fails [222] o ngtcp2: compare idle timeout in ms to avoid overflow [248] o ngtcp2: fix early return [131] o ngtcp2: fix handling of blocked stream data [236] o ngtcp2: fix returns when TLS verify failed [251] o ngtcp2: overwrite rate-limits defaults [444] o noproxy: fix the IPV6 network mask pattern match [166] o NTLM: disable if DES support missing from OpenSSL or mbedTLS [399] o ntlm: improved error path on bad incoming NTLM TYPE3 message [412] o openldap/ldap; check for binary attribute case insensitively [445] o openldap: avoid indexing the result at -1 for blank responses [44] o openldap: check ber_sockbuf_add_io() return code [163] o openldap: check ldap_get_option() return codes [119] o openldap: do not pass newline to infof() [368] o openldap: fix memory-leak in error path [287] o openldap: fix memory-leak on oldap_do's exit path [286] o openldap: limit max incoming size [347] o openssl-quic: check results better [132] o openssl-quic: handle error in SSL_get_stream_read_error_code [129] o openssl-quic: ignore unexpected streams opened by server [176] o openssl: better return code checks when logging cert data [342] o openssl: call SSL_get_error() with proper error [207] o openssl: check CURL_SSLVERSION_MAX_DEFAULT properly [447] o openssl: clear retry flag on x509 error [130] o openssl: combine all the x509-store flags [451] o openssl: fail if more than MAX_ALLOWED_CERT_AMOUNT certs [339] o openssl: fail the transfer if ossl_certchain() fails [23] o openssl: fix build for v1.0.2 [225] o openssl: fix peer certificate leak in channel binding [258] o openssl: fix resource leak in provider error path [376] o openssl: fix unable do typo in failf() calls [341] o openssl: free UI_METHOD on exit path [373] o openssl: make the asn1_object_dump name null terminated [56] o openssl: only try engine/provider if a cert file/name is provided [415] o openssl: set io_need always [99] o openssl: skip session resumption when verifystatus is set [230] o os400: document threads handling in code. [254] o OS400: fix a use-after-free/double-free case [142] o osslq: set idle timeout to 0 [237] o pingpong: remove two old leftover debug infof() calls o pop3: check for CAPA responses case insensitively [439] o pop3: fix CAPA response termination detection [427] o pop3: function could get the ->transfer field wrong [292] o pytest: skip specific tests for no-verbose builds [171] o quic: fix min TLS version handling [14] o quic: ignore EMSGSIZE on receive [4] o quic: improve UDP GRO receives [330] o quic: remove data_idle handling [311] o quiche: fix possible leaks on teardown [205] o quiche: fix verbose message when ip quadruple cannot be obtained. [128] o quiche: handle tls fail correctly [266] o quiche: when ingress processing fails, return that error code [103] o rtsp: use explicit postfieldsize if specified [401] o runtests: tag tests that require curl verbose strings [172] o rustls: exit on error [335] o rustls: fix clang-tidy warning [107] o rustls: fix comment describing cr_recv() [117] o rustls: limit snprintf proper in cr_keylog_log_cb() [343] o rustls: make read_file_into not reject good files [328] o rustls: pass the correct result to rustls_failf [242] o rustls: typecast variable for safer trace output [69] o rustls: use %zu for size_t in failf() format string [121] o sasl: clear canceled mechanism instead of toggling it [41] o schannel: assign result before using it [62] o schannel: fix memory leak [363] o schannel: handle Curl_conn_cf_send() errors better [352] o schannel: lower the maximum allowed time to block to 7 seconds [333] o schannel: properly close the certfile on error [450] o schannel_verify: do not call infof with an appended \n [371] o schannel_verify: fix mem-leak in Curl_verify_host [208] o schannel_verify: use more human friendly error messages [96] o scp/sftp: fix disconnect [350] o scripts: pass -- before passing xargs [349] o setopt: accept *_SSL_VERIFYHOST set to 2L [31] o setopt: allow CURLOPT_DNS_CACHE_TIMEOUT set to -1 [257] o setopt: fix unused variable warning in minimal build [332] o setopt: make CURLOPT_MAXREDIRS accept -1 (again) [1] o singleuse.pl: fix string warning [392] o smb: adjust buffer size checks [45] o smb: transfer debugassert to real check [303] o smtp: check EHLO responses case insensitively [50] o smtp: fix EOB handling [410] o smtp: return value ignored [357] o socks: advance iobuf instead of reset [276] o socks: avoid UAF risk in error path [359] o socks: deny server basic-auth if not configured [264] o socks: handle error in verbose trace gracefully [94] o socks: handle premature close [246] o socks: make Curl_blockread_all return CURLcode [67] o socks: properly maintain the status of 'done' [405] o socks: rewwork, cleaning up socks state handling [135] o socks_gssapi: also reset buffer length after free [429] o socks_gssapi: make the gss_context a local variable [144] o socks_gssapi: reject too long tokens [90] o socks_gssapi: remove superfluous releases of the gss_recv_token [139] o socks_gssapi: remove the forced "no protection" [143] o socks_gssapi: replace `gss_release_buffer()` with curl free [386] o socks_sspi: bail out on too long fields [137] o socks_sspi: fix memory cleanup calls [40] o socks_sspi: remove the enforced mode clearing [291] o socks_sspi: restore non-blocking socket on error paths [48] o socks_sspi: use the correct free function [331] o socksd: remove --bindonly mention, there is no such option [305] o spelling: fix new finds by typos-cli 1.39.0 [454] o src/var: remove dead code [369] o ssl-session-cache: check use on config and availability [448] o ssl-sessions.md: mark option experimental [12] o strerror: drop workaround for SalfordC win32 header bug [214] o sws: fix checking sscanf() return value [17] o sws: pass in socket reference to allow function to close it [298] o tcp-nodelay.md: expand the documentation [153] o telnet: ignore empty suboptions [86] o telnet: make bad_option() consider NULL a bad option too [192] o telnet: make printsub require another byte input [21] o telnet: print DISPlay LOCation in printsub without mutating buffer [216] o telnet: refuse IAC codes in content [111] o telnet: return error if WSAEventSelect fails [180] o telnet: return error on crazy TTYPE or XDISPLOC lengths [123] o telnet: send failure logged but not returned [175] o telnet: use pointer[0] for "unknown" option instead of pointer[i] [217] o test1100: fix missing `` section [432] o tests/libtest/cli*: fix init/deinit, leaks, and more [455] o tests/server: drop pointless memory allocation overrides [219] o tests/server: drop unsafe open() override in signal handler (Windows) [151] o tftp: check and act on tftp_set_timeouts() returning error [38] o tftp: check for trailing ";mode=" in URL without strstr [312] o tftp: default timeout per block is now 15 seconds [156] o tftp: error requests for blank filenames [296] o tftp: handle tftp_multi_statemach() return code [65] o tftp: pin the first used address [110] o tftp: propagate expired timer from tftp_state_timeout() [39] o tftp: return error if it hits an illegal state [138] o tftp: return error when sendto() fails [59] o thread: errno on thread creation [271] o tidy-up: assortment of small fixes [115] o tidy-up: avoid using the reserved macro namespace [76] o tidy-up: fcntl.h includes [98] o tidy-up: update MS links, allow long URLs via checksrc [73] o tidy-up: URLs [101] o time-cond.md: refer to the singular curl_getdate man page [148] o TLS: IP address verification, extend test [398] o TODO: fix a typo [93] o TODO: remove already implemented or bad items [36] o tool: fix exponential retry delay [47] o tool_cb_hdr: fix fwrite check in header callback [49] o tool_cb_hdr: size is always 1 [70] o tool_cb_rea: use poll instead of select if available [329] o tool_cfgable: remove superfluous free calls [403] o tool_doswin: fix to use curl socket functions [108] o tool_filetime: cap crazy file times instead of erroring [327] o tool_filetime: replace cast with the fitting printf mask (Windows) [212] o tool_formparse: rewrite the headers file parser [374] o tool_getparam/set_rate: skip the multiplication on overflow [84] o tool_getparam: always disable "lib-ids" for tracing [169] o tool_getparam: make --fail and --fail-with-body override each other [293] o tool_getparam: warn if provided header looks malformed [179] o tool_ipfs: check the return value of curl_url_get for gwpath [453] o tool_ipfs: simplify the ipfs gateway logic [337] o tool_msgs: make errorf() show if --show-error [294] o tool_operate: improve wording in retry message [37] o tool_operate: keep failed partial download for retry auto-resume [210] o tool_operate: keep the progress meter for --out-null [33] o tool_operate: move the checks that skip ca cert detection [449] o tool_operate: retry on HTTP response codes 522 and 524 [317] o tool_operate: return error on strdup() failure [336] o tool_paramhlp: remove outdated comment in str2tls_max() [367] o tool_parsecfg: detect and error on recursive --config use [380] o tool_progress: handle possible integer overflows [164] o tool_progress: make max5data() use an algorithm [170] o transfer: avoid busy loop with tiny speed limit [100] o transfer: fix retry for empty downloads on reuse [411] o transfer: reset retry count on each request [310] o unit1323: sync time types and printf masks, drop casts [211] o unit1664: drop casts, expand masks to full values [221] o url: make Curl_init_userdefined return void [213] o urldata: FILE is not a list-only protocol [9] o urldata: make 'retrycount' a single byte [308] o urldata: make redirect counter 16 bit [295] o vauth/digest: improve the digest parser [203] o version: add GSS backend name and version [353] o vquic: fix idle-timeout checks (ms<-->ns), 64-bit log & honor 0=no-timeout [249] o vquic: fix recvmsg loop for max_pkts [421] o vquic: handling of io improvements [239] o vquic: sending non-gso packets fix for EAGAIN [265] o vtls: alpn setting, check proto parameter [134] o vtls: check final cfilter node in find_ssl_filter [440] o vtls: drop duplicate `CURL_SHA256_DIGEST_LENGTH` definition [387] o vtls: properly handle SSL shutdown timeout [433] o vtls: remove call to PKCS12_PBE_add() [408] o vtls: unify the error handling in ssl_cf_connect(). [413] o vtls_int.h: clarify data_pending [124] o vtls_scache: fix race condition [157] o wcurl: sync to +dev snapshot [425] o windows: replace _beginthreadex() with CreateThread() [80] o windows: stop passing unused, optional argument for Win9x compatibility [75] o windows: use consistent format when showing error codes [199] o windows: use native error code types more [206] o wolfssl: check BIO read parameters [133] o wolfssl: clear variable to avoid uninitialized use [361] o wolfssl: fix error check in shutdown [105] o wolfssl: fix resource leak in verify_pinned error paths [314] o wolfssl: no double get_error() detail [188] o ws: clarify an error message [125] o ws: fix some edge cases [274] o ws: fix type conversion check [316] o ws: reject curl_ws_recv called with NULL buffer with a buflen [118] @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.29 2025/10/24 03:59:51 riastradh Exp $ d4 1 a4 1 DISTNAME= curl-8.17.0 @ 1.29 log @www/curl, www/libcurl-gnutls: Move PKGREVISION from Makefile.common. pkglint complains, rightly: it wasn't necessary to revbump www/libcurl-gnutls by putting PKGREVISION=1 in Makefile.common, because www/libcurl-gnutls's build options didn't change; it was only necessary to revbump www/curl because www/curl's build options did change in a way that affects buildlink3.mk. But since we already did the revbump, let's keep it. No functional change intended: both packages retain the same PKGREVISION, but pkglint is happier now. @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.28 2025/10/05 19:16:03 js Exp $ d4 1 a4 1 DISTNAME= curl-8.16.0 @ 1.28 log @www/curl: Revbump for new option @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.27 2025/09/12 07:32:12 wiz Exp $ a4 1 PKGREVISION= 1 @ 1.27 log @curl: update to 8.16.0. This release includes the following changes: o build: bump minimum required mingw-w64 to v3.0 (from v1.0) [33] o curl: add --follow [129] o curl: add --out-null [101] o curl: add --parallel-max-host to limit concurrent connections per host [81] o curl: make --retry-delay and --retry-max-time accept decimal seconds [112] o hostip: cache negative name resolves [175] o ip happy eyeballing: keep attempts running [80] o mbedtls: bump minimum version required to 3.2.0 [180] o multi: add curl_multi_get_offt [56] o multi: add CURLMOPT_NETWORK_CHANGED to signal network changed [84] o netrc: use the NETRC environment variable (first) if set [70] o smtp: allow suffix behind a mail address for RFC 3461 [127] o tls: make default TLS version be minimum 1.2 [71] o tool_getparam: add support for `--longopt=value` [69] o vquic: drop msh3 [8] o websocket: support CURLOPT_READFUNCTION [193] o writeout: add %time{} [74] This release includes the following bugfixes: o _PROTOCOLS.md: mention file:// is only for absolute paths [102] o acinclude: --with-ca-fallback only works with OpenSSL [217] o alpn: query filter [104] o ares: destroy channel on shutdown [178] o ares: use `ares_strerror()` to retrieve error messages [236] o asyn-thrdd: fix --disable-socketpair builds [235] o asyn-thrdd: fix Curl_async_pollset without socketpair [205] o asyn-thrdd: fix no `HAVE_GETADDRINFO` builds [214] o asyn-thrdd: manage DEFERRED and locks better [228] o autotools: make curl-config executable [253] o aws-lc: do not use large buffer [250] o BINDINGS.md: add LibQurl [156] o bufq: add integer overflow checks before chunk allocations [108] o bufq: removed "Useless Assignment" [188] o bufq: simplify condition [207] o build: allow libtests/clients to use libcurl dependencies directly [87] o build: disable `TCP_NODELAY` for emscripten [176] o build: enable _GNU_SOURCE on GNU/Hurd [27] o build: extend GNU C guards to clang where applicable, fix fallouts [61] o build: fix build errors/warnings in rare configurations [7] o build: fix disable-verbose [48] o build: fix mingw-w64 version guard for mingw32ce [124] o build: if no perl, fix to use the pre-built hugehelp, if present [144] o build: link to Apple frameworks required by static wolfSSL [40] o build: support LibreSSL native crypto lib with ngtcp2 1.15.0+ [209] o build: tidy up compiler definition for tests [37] o cf-https-connect: delete unused declaration [15] o clang-tidy: disable `clang-analyzer-security.ArrayBound` [265] o cmake: `CURL_CA_FALLBACK` only works with OpenSSL [215] o cmake: capitalize 'Rustls' in the config summary o cmake: defer building `unitprotos.h` till a test target needs it [75] o cmake: define `WIN32_LEAN_AND_MEAN` for examples [159] o cmake: drop redundant unity mode for `curlinfo` [155] o cmake: enable `-Wall` for MSVC 1944 [128] o cmake: fix `ENABLE_UNIX_SOCKETS=OFF` with pre-fill enabled on unix o cmake: fix setting LTO properties on the wrong targets [258] o cmake: fix to disable Schannel and SSPI for non-Windows targets o cmake: fix to restrict `SystemConfiguration` to macOS [139] o cmake: honor `CMAKE_C_FLAGS` in test 1119 and 1167 [206] o cmake: improve error message for invalid HTTP/3 MultiSSL configs [187] o cmake: keep websockets disabled if HTTP is disabled o cmake: make `runtests` targets build the curl tool [32] o cmake: make the ExternalProject test work [183] o cmake: omit linking duplicate/unnecessary libs to tests & examples [45] o cmake: re-add simple test target, and name it `tests` [142] o cmake: set `CURL_DIRSUFFIX` automatically in multi-config builds [154] o CODE_STYLE: sync with recent `checksrc.pl` updates [49] o config-win32.h: do not use winsock2 `inet_ntop()`/`inet_pton()` [58] o configure: if no perl, disable unity and shell completion, related tidy ups [137] o configure: tidy up internal names in ngtcp2 ossl detection logic [212] o connectdata: remove primary+secondary ip_quadruple [126] o connection: terminate after goaway [62] o contrithanks: fix for BSD `sed` tool [98] o cookie: don't treat the leading slash as trailing [185] o cookie: remove expired cookies before listing [158] o curl-config: remove X prefix use [138] o curl/system.h: fix for GCC 3.3.x and older [38] o curl: make the URL indexes 64 bit [117] o curl: tool_read_cb fix of segfault [18] o curl_addrinfo: drop workaround for old-mingw [14] o curl_easy_ssls_export: make the example more clear [78] o curl_fnmatch, servers: drop local macros in favour of `sizeof()` [21] o curl_mime_data_cb.md: mention what datasize is for [107] o curl_ossl: extend callback table for nghttp3 1.11.0 [46] o curl_setup.h: include `stdint.h` earlier [260] o curl_setup.h: move UWP detection after `config-win32.h` (revert) [51] o curl_setup.h: move UWP detection after `config-win32.h` [23] o CURLINFO_FILETIME*.md: correct the examples [242] o CURLOPT: bump `CURL_REDIR_*` macros to `long` [110] o CURLOPT: bump `CURL_SSLVERSION_*` macros to `long` [149] o CURLOPT: bump `CURLALTSVC_*` macros to `long` [96] o CURLOPT: bump `CURLFTP*` enums to `long`, drop casts [54] o CURLOPT: bump `CURLHEADER_*` macros to `long`, drop casts [94] o CURLOPT: bump `CURLPROTO_*` macros to `long` [148] o CURLOPT: bump `CURLPROXY_*` enums to `long`, drop casts [95] o CURLOPT: bump `CURLWS_NOAUTOPONG`, `CURLWS_RAW_MODE` macros to `long` [150] o CURLOPT: bump remaining macros to `long` [147] o CURLOPT: drop redundant `long` casts [55] o CURLOPT: replace `(long)` cast with `L` suffix for `CURLHSTS_*` macros o CURLOPT_HTTP_VERSION: mention new default value [179] o CURLOPT_SSL_CTX_*: replace the base64 with XXXX [171] o delta: fix warnings, fix for non-GNU `date` tool [99] o DEPRECATE.md: drop old OpenSSL versions [266] o DEPRECATE.md: drop support for c-ares versions before 1.16.0 [191] o DEPRECATE.md: drop support for Windows XP/2003 [31] o DEPRECATE.md: remove leftover "nothing" [57] o DISTROS.md: add Haiku [39] o docs/cmdline-opts: the auth types are not mutually exclusive [103] o docs: add CURLOPT type change history, drop casts where present [143] o docs: add major incident section to vuln disclosure policy [271] o docs: fix link CONTRIBUTE.md link [192] o docs: fix name in curl_easy_ssls_export man page [12] o docs: fix typo (staring -> starting) [211] o docs: point two broken links to archive.org [134] o docs: put `<>` within backticks in titles [261] o doh: rename symbols to avoid collision with mingw-w64 headers [66] o easy handle: check validity on external calls [28] o examples: drop long cast for `CURLALTSVC_*` o examples: make `CURLPIPE_MULTIPLEX` fallback `long` [233] o examples: remove base64 encoded chunks from examples [189] o examples: remove href_extractor.c [186] o ftp: store dir components as start+len instead of memdup'ing [198] o ftp: use 'conn' instead of 'data->conn' [208] o gnutls: fix building with older supported GnuTLS versions [241] o gnutls: some small cleanups [41] o hmac: return error if init fails [2] o hostip: do DNS cache pruning in milliseconds [132] o HTTP3.md: avoid `configure` issue for ngtcp2 1.14.0+ compatibility [182] o http: const up readonly H2_NON_FIELD [10] o http: do the cookie list access under lock [270] o http: silence `-Warray-bounds` with gcc 13+ [44] o idn: reject conversions that end up as a zero length hostname [273] o inet_pton, inet_ntop: drop declarations when unused [59] o lib1560: fix memory leak when run without UTF-8 support [17] o lib1560: replace an `int` with `bool` [97] o lib2700: use `testnum` [151] o lib517: use `LL` 64-bit literals & re-enable a test case (`time_t`) [100] o lib: drop `UNUSED_PARAM` macro [259] o libcurl: reset rewind flag in curl_easy_reset() [184] o libssh: Use sftp_aio instead of sftp_async for sftp_recv [92] o libtests: update format strings to avoid casts, drop some macros [109] o libtests: use `FMT_SOCKET_T`, drop more casts [136] o managen: reset text mode at end of table marker [145] o mbedtls: check for feature macros instead of version [166] o mdlinkcheck: handle links with a leading slash properly [195] o memanalyze: fix warnings [22] o memory: make function overrides work reliably in unity builds [93] o multi event: remove only announced [25] o multi: don't insert a node into the splay tree twice [68] o multi: fix assert in multi_getsock() [53] o multi: fix bad splay management [133] o multi: process pending, one by one [90] o multi: replace remaining EXPIRE_RUN_NOW [67] o multissl: initialize when requesting a random number [30] o ngtcp2: extend callback tables for nghttp3 1.11.0 and ngtcp2 1.14.0 [47] o ngtcp2: handshake timeout should be equal to --connect-timeout [262] o ngtcp2: use custom mem funcs [204] o openldap: fix `-Wtentative-definition-compat` [268] o openssl: add and use `HAVE_BORINGSSL_LIKE` internal macro [222] o openssl: add and use `HAVE_OPENSSL3` internal macro [223] o openssl: assume `OPENSSL_VERSION_NUMBER` [181] o openssl: auto-pause on verify callback retry [167] o openssl: check SSL_write() length on retries [152] o openssl: clear errors after a failed `d2i_X509()` [161] o openssl: drop more legacy cruft [224] o openssl: drop redundant `HAVE_OPENSSL_VERSION` macro [221] o openssl: drop redundant version check [246] o openssl: drop single-use interim macro `USE_OPENSSL_SRP` [201] o openssl: enable `HAVE_KEYLOG_CALLBACK` for AWS-LC [220] o openssl: merge two `#if` blocks [218] o openssl: output unescaped utf8 x509 issuer/subject DNs [169] o openssl: remove legacy cruft, document macro guards [231] o openssl: save and restore OpenSSL error queue in two functions [172] o openssl: some small cleanups [42] o openssl: split cert_stuff into smaller sub functions [72] o openssl: sync an AWS-LC guard with BoringSSL [199] o openssl: use `RSA_flags()` again with BoringSSL [219] o parallel-max: bump the max value to 65535 [86] o parsedate: make Curl_getdate_capped able to return epoch [229] o processhelp.pm: fix to use the correct null device on Windows [164] o processhelp.pm: use `Win32::Process*` perl modules if available [200] o projects: drop unused logic from `generate.bat` [157] o projects: fix Windows project 'clean' function [203] o pytest: add SOCKS tests and scoring [9] o pytest: fix test_17_09_ssl_min_max for BoringSSL [197] o pytest: increase server KeepAliveTimeout [26] o pytest: relax error check on test_07_22 [16] o resolving: dns error tracing [196] o runtests: assume `Time::HiRes`, drop Perl Win32 dependency [163] o runtests: remove warning message [230] o runtests: replace `--ci` with `--buidinfo`, show OS/Perl version again [247] o runtests: show still running tests when nothing has happened for a while [227] o schannel: add an error message for client cert not found [165] o schannel: assume `CERT_CHAIN_REVOCATION_CHECK_CHAIN` [114] o schannel: drop fallbacks for 4 macros [121] o schannel: drop fallbacks for unused `BCRYPT_*` macros [122] o schannel: drop old-mingw special case [77] o schannel: fix recent update for mingw32ce [123] o schannel: fix renegotiation [202] o schannel: improve handshake procedure [239] o schannel: not supported with UWP, drop redundant code [105] o schannel: use if(result) like the code style says [125] o scripts: enable strict warnings in Perl where missing, fix fallouts [63] o scripts: fix two Perl uninitialized value warnings [60] o sendf: getting less data than "max allowed" is okay [170] o servers: convert two macros to scoped static const strings [89] o setopt: refactor out the booleans from setopt_long to setopt_bool [83] o setopt: split out cookielist() and cookiefile() [130] o socks: do_SOCKS5: Fix invalid buffer content on short send [43] o socks_sspi: simplify, clean up Curl_SOCKS5_gssapi_negotiate [237] o spacecheck.pl: when detecting unicode, mention line number [85] o spacecheck: warn for 3+ empty lines in a row, fix fallouts [240] o spelling: file system [232] o test1148: drop redundant `LC_NUMBER=` env setting [13] o test1557: pass `long` type to `multi_setopt()` [234] o test1560: set locale/codeset with `LC_ALL` (was: `LANG`), test in CI [19] o test1560: skip some URLs if UTF-8 is not supported [34] o test1: raise alloc limits [11] o test428: re-enable for Windows [5] o test436: fix running on Windows with `_curlrc` present [153] o test: add `cygwin` feature and use it (test 1056, 1517) [249] o tests/ech_tests.sh: indent, if/for style, inline ifs [131] o tests: constify command-line arguments [82] o tests: delete unused commands [177] o tests: drop unused `BLANK` envs, unset `CURL_NOT_SET` [248] o tests: drop unused `CURL_FORCEHOST` envs [36] o tests: fix perl warnings in http2-server, http3-server [119] o tests: fix prechecks to call the bundle libtest tool [120] o tests: fix UTF-8 detection, per-test `LC_*` settings, CI coverage [6] o tests: merge clients into libtests, drop duplicate code [76] o tests: remove the QUIT filters [210] o tests: set `CURL_ENTROPY` per test, not globally [35] o tests: unset some envs instead of blanking them [4] o threaded-resolver: fix shutdown [252] o tidy-up: `Curl_thread_create()` callback return type [20] o tidy-up: move literal to the right side of comparisons [65] o tidy-up: prefer `ifdef`/`ifndef` for single checks [64] o tls: CURLINFO_TLS_SSL_PTR testing [79] o TODO: remove session export item [194] o TODO: remove the expand ~ idea [216] o tool_cb_wrt: stop alloc/free for every chunk windows console output [140] o tool_filetime: accept setting negative filetime [256] o tool_getparam: let --trace-config override -v [238] o tool_getparam: warn on more unicode prefixes [275] o tool_operate: avoid superfluous strdup'ing output [1] o tool_operate: use stricter curl_multi_setopt() arguments [225] o tool_operate: use the correct config pointer [115] o tool_paramhlp: fix secs2ms() [116] o tool_parsecfg: use dynbuf for quoted arguments [162] o tool_urlglob: add integer overflow protection [244] o tool_urlglob: polish, cleanups, improvements [141] o typecheck-gcc: add type checks for curl_multi_setopt() [226] o unit-tests: build the unitprotos.h from here [73] o unit2604: avoid `UNCONST()` [135] o URL-SYNTAX.md: drop link to codepoints.net to pass linkcheck [190] o urlapi: allow more path characters "raw" when asked to URL encode [146] o urldata: reduce two long struct fields to unsigned short [174] o urlglob: only accept 255 globs o vquic-tls: fix SSL backend type for QUIC connections using gnutls [29] o vquic: replace assert [254] o vquic: use curl_getenv [168] o vtls: set seen http version on successful ALPN [160] o websocket example: cast print values to unsigned int [251] o websocket: handling of PONG frames [213] o websocket: improve handling of 0-len frames [269] o websocket: reset upload_done when sending data [245] o windows: assume `ADDRESS_FAMILY`, drop feature checks [88] o windows: document toolchain support for `CERT_NAME_SEARCH_ALL_NAMES_FLAG` o windows: document toolchain support for some macros (cont.) [111] o windows: document toolchain support for some macros [113] o windows: drop `CRYPT_E_*` macro fallbacks, limit one to mingw32ce [118] o windows: drop two interim, single-use macros [106] o windows: drop unused `curlx/version_win32.h` includes [52] o windows: fix `if_nametoindex()` detection with autotools, improve with cmake [24] o windows: include `wincrypt.h` before `iphlpapi.h` for mingw-w64 <6 [50] o windows: target version macro tidy-ups [3] o wolfssl: rename ML-KEM hybrids to match IETF draft [173] o write-out.md: header_json is not included the json object [243] o ws: avoid NULL pointer deref in curl_ws_recv [91] o ws: get a new mask for each new outgoing frame [255] @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.26 2025/08/26 15:08:11 leot Exp $ d5 1 @ 1.26 log @curl: Update to 8.15.0 Changes: 8.15.0 This release includes the following changes: o TLS: remove support for Secure Transport and BearSSL This release includes the following bugfixes: o altsvc: accept 'clear' without semicolon as well o asyn-ares: remove redundant NULL check o asyn-thrdd: free the previous name before strdup'ing the new o autotools: detect and link `brotlicommon` library for brotli o autotools: drop `$top_builddir/src` from src header path o autotools: drop headers from src mk-unity rules (fixup) o autotools: drop no longer necessary `--srcdir` unity options o autotools: drop redundant `Makefile.inc` from `EXTRA_DIST` in src o autotools: simplify configuration in tests, examples o bufq: change read/write signatures o bufq: remove the unused Curl_bufq_unwrite function o build: assume `sys/socket.h`, `sys/time.h` on non-Windows (as in `curl/curl.h`) o build: drop `HAVE_SYS_SOCKET_H` and `HAVE_SYS_TIME_H` macros o build: drop explicit curlx from hdr paths, refer headers with `curlx/` prefix o build: drop unused variables in tests o build: fix libcurltool with cmake and tunits, related tidy-ups o build: split `.c` and `.h` file lists in tests o build: stop checking for `sys/stat.h` o build: stubgss tidy-ups (in tests) o build: sync build scripts between client/libtest o build: tidy up `Makefile.inc` use in lib and src o build: tidy up header paths, use srcdir where possible o cf-socket: make socket data_pending a nop o checksrc-all: rewrite in Perl, remove `checksrc.bat` o checksrc: reduce exceptions, apply again to curlx o cmake/FindGSS: fix processing C header path options o cmake/FindGSS: initialize result variables o cmake: `curl_add_clang_tidy_test_target` tidy-ups o cmake: build `stubgss` library for libtests to match autotools o cmake: check USE_WINDOWS_SSPI when adding secur32 to CURL_LIBS o cmake: configure c-ares header directory in project root (was: lib) o cmake: document OpenSSL and ngtcp2 crypto lib custom variables o cmake: drop never propagated C macros o cmake: drop passing redundant `CURL_STATICLIB` in examples and clients o cmake: drop redundant macro from test clients o cmake: drop reference to future variable o cmake: enable soversion by default for OpenHarmony OS o cmake: fix `curl_add_clang_tidy_test_target` when no `-D` option o cmake: fix generator expression in docs/examples o cmake: gather options recursively in `curl_add_clang_tidy_test_target` o cmake: make docs depend on support files o cmake: move `OUTPUT` argument in the `add_custom_command()` line o cmake: omit clang-tidy on internal libs curlu and curltool o cmake: replace `cmakelint` with `cmake-lint` from `cmakelang`, fix issues o cmake: replace the way clang-tidy verifies tests, fix issues found o cmake: simplify handling generated `lib1521.c` in libtests o cmake: sync `target_link_libraries()` order in tests more o cmake: sync tests scripts by using the variable `BUNDLE` o cmake: sync tests scripts with each other and autotools (more) o cmake: use `target_link_options()` when available o config-win32: fix default targets, shorten macro logic o configure: order LDAP after the SSL libraries o connect: drop unused struct member o connection: clarify `transport` o connection: eliminate member `remote_addr` o curl-config: fix whitespace in usage text o curl.h: make CURL_IPRESOLVE_* symbols defined as longs o curl.h: make CURLSSLOPT_* symbols defined as longs o curl.h: remove the "RESERVED" error codes o curl: implement non-blocking STDIN read on Windows o curl: improve non-blocking STDIN performance o curl: remove the global argument from many functions o curl: unify pointer names to global config o curl_get_line: make sure lines end with newline o curl_memory.h: fix to undefine `accept4` o curl_path: make SFTP handle a path like /~ properly. o curlinfo: provide the 'digest' feature o CURLSHOPT_SHARE.md: mention multi-threading requires callbacks o DEPRECATE.md: add VS2005 removal to the list o digest: fix build with disabled digest auth o DISTROS: update NixOS link o docs,tests: fix english grammar "allow to" -> "allow to" o docs/CONTRIBUTE: fix broken link o docs/examples: add ftp-delete.c o docs: beef up examples/websocket.c o docs: fix broken link in CODE_REVIEW.md o docs: fix broken link in INSTALL.md o docs: fix docs for CURLOPT_PREQUOTE after #17616 o docs: fix documentation of connect_only 2 o docs: fix two typos o docs: mention that the netrc file works without port numbers o docs: mention the as-is concept generically o docs: note SSLS-EXPORT feature in -ssl-sessions doc o docs: reflect that delimiter-separated capath is only OpenSSL o docs: sync -tls-earlydata support w/ CURLOPT_SSL_OPTIONS o docs: warn about lifetime in CURLOPT_CLOSESOCKET* o easy: fix comment-documentation o easygetopt: fix curl logo in header comment o firefox-db2pem: avoid use of eval in script o ftp: fix prequotes for a directory in URL o ftplistparser: split parse_unix into sub functions o h2_serverpush: fix file handle leaks reported by clang-tidy o h3: fix query of concurrent streams o http/3: report handshake with version and cipher as for TCP connections o http2: do not delay RST send on aborted transfer o http2: fix var types in is_alive() implementations o http: explicitly ignore parsing errors for Retry-After o http: fix build with cookies and HSTS disabled o http_ntlm: protect against null deref o http_ntlm: remove unreachable code o INSTALL.md: cygwin details and add source code link o ldap: avoid automake caching issues with LDAP library names o ldap: if ldap-lib is sufficient, add it to LIBS. o ldap: initial support for --with-ldap option o lib2082: drop `typedef struct` o lib: address singleuse issues o lib: avoid reusing unclean connection o lib: drop two interim macros in favor of native libcurl API calls o lib: fix unused parameter/function compiler warnings o lib: make `CURLX_SET_BINMODE()` and use it o lib: make `curlx_wait_ms()` and use it o lib: replace scache no-op macros with `#ifdef` o lib: stop `time()` debug overrides at the end of source in altsvc, hsts o lib: unify recv/send function signatures o libcurl-env.md: drop LOGNAME, USER and NTLMUSER o libcurl.m4: fix indentation o libssh2: remove use of 'initialised' for cleanup o libssh: de-complex myssh_statemach_act() o libssh: fix readdir issues o libtests: make test 1503,1504,1505 use the 1502 binary o libtests: more header tidy-ups o libtests: stop building the sames source multiple times o memdebug.h: #undef `fclose` before defining it o memdebug.h: eliminate global macro `CURL_MT_LOGFNAME_BUFSIZE` o memdebug: include in unity batch o memory: stop overriding unused `wcsdup()`/`_wcsdup()` system functions o memory: tidy up `_tcsdup()` override o misc: fix typos o mk-lib1521: replace `printf` with `curl_mprintf` o multi: add dirty bitset o multi: do no expire a blocked transfer o multi: fix polling with pending input o multi: remove careful bounds check as coverity says it is not needed o multi: xfer table/bitset, handle limits o ngtcp2: fix coverity warning about result handling o openssl: enable readahead o openssl: error on SSL_ERROR_SYSCALL o openssl: fix handling of buffered data o openssl: fix openssl engine use o openssl: fix pkcs11 provider available check o os400: upgrade ILE/RPG bindings with latest definitions. o pingpong: on disconnect, check for unflushed pingpong state o projects/build-openssl.bat: remove o pytest test_07_70, weaken early data check o pytest: adapt for runs with openssl-1.1.1 o pytest: disable test_07_37 and test_07_36 with openssl's quic o quic: implement CURLINFO_TLS_SSL_PTR o RELEASE-PROCEDURE.md: update docs/VERSIONS o runtests.pl: fix sprintf() using one too many %s o runtests: fix `LD_PRELOAD` detection for cmake-built curl binaries o runtests: support memory-limits per test o rustls: apply memory function overrides, fixing an ECH buffer free o rustls: don't try printing the not provided file o schannel: allow partial chains for manual peer verification o schannel: drop Windows 2000 compatibility logic o scorecard: flame graphs and documentation o SCP/SFTP: avoid busy loop after EAGAIN o scripts: fix to quote the copyright email address o socks: fix query when filter context is null o system.h: remove some macros o test1117: reduce write delays o test1175: fix to run, and fix documentation issues detected o test1222: fix for out-of-tree and no-libcurl-manual builds o test1499, 1599: use `%LOGDIR` o test1499: verify two chunked responses on reused connection o test1596: let test pass after year 2036 o test1706: pass include directory to `managen` for out-of-tree builds o tests/client: drop autotools logic no longer necessary o tests/client: use `curl_mfprintf()` o tests/dnsd: read config from file o tests/http/clients: drop hack and use `curl_setup.h` again o tests/http/clients: move to tests/client o tests/http/requirements: remove multipart o tests/libtest: call `curlx_now_init()` for unit 1399, 2600 (Windows) o tests/libtest: drop `TEST_HANG_TIMEOUT` redefinition hack o tests/libtest: drop a checksrc exception o tests/libtest: use `curltime` from curlx o tests/server/util.c: include netinet/in6.h o tests/server: de-dupe/merge three `sockdaemon()` clones into one o tests/server: drop `memdebug.h` o tests/server: make all global vars/funcs static o tests/server: move memory init to `memptr.c` o tests/servers.pm: add more ways to figure out current user o tests: always make bundles, adapt build and tests o tests: bundle http clients, de-dupe, enable for MSVC o tests: constify, make consts static o tests: drop `BUNDLE_SRC` variable o tests: drop mk-bundle exceptions o tests: drop unused or redundant includes o tests: drop useless "nodist_SOURCES" assignments o tests: fail torture if !valgrind&threaded resolver o tests: fix 1301, 1308 to fail on error o tests: fix `BUNDLE` variable references in `Makefile.am` o tests: make all names < 75 characters long o tests: make individual test sources compile cleanly o tests: make sshserver less verbose o tests: move `curlcheck.h` to libtest as `unitcheck.h` o tests: move GSS-API dynamic stub into debug-mode libcurl o tests: torture: don't duplicate valgrind command o tests: use %b64[] to base64 data o tests: use %b64[] to base64 data in 2056, 2057 o tftpd: use `CURLMIN()` macro o tidy-up: replace `` with `"memdebug.h"` (src, units) o tls: remove Curl_ssl false_start o tool1621: drop unused internal libcurl headers o tool_getparam: fix --ftp-pasv o tool_operate: fix return code when --retry is used but not triggered o tool_paramhelp: fix language in comments o top-complexity: lower max allowed complexity threshold to 90 o unit tests: extract "private" prototypes at build time o unit1302: expand the base64 encode/decode tests o url: fix connection lifetime checks o url: fix NULL deref with bad password when no user is provided o urlapi: simplify and split into sub functions o urlapi: use uppercase hex encoding o vauth: move auth structs to conn meta data o vtls: change send/recv signatures of tls backends o vtls: fix a copy-pasted early data comment typo o vtls: log rustls negotiated KEX group name o vtls: prefer ciphersuite to cipher in msgs o vtls: prefer rustls-ffi ciphersuite name API o VULN-DISCLOSURE-POLICY.md: fix typos o VULN-DISCLOSURE-POLICY: all reports should be disclosed o VULN-DISCLOSURE-POLICY: exclude not installed software o VULN-DISCLOSURE-POLICY: minor language polish o warnless: drop parts of the `read`/`write` preprocessor hack (Windows) o warnless: replace `read()`/`write()` wrapper functions with macros (Windows) o windows: drop redundant `curl_wcsdup_callback` callback o windows: fixup `fopen()` in `CURLDEBUG` builds o windows: reduce/stop loading DLLs at runtime o wolfssl: add support for ML_KEM hybrids o ws: drop redundant `CURL_EXTERN` from function definitions o xfer: manage pause bits @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.25 2025/06/05 04:43:21 adam Exp $ d4 1 a4 1 DISTNAME= curl-8.15.0 @ 1.25 log @curl: updated to 8.14.1 Changes in 8.14.1 Bugfixes: asyn-thrdd: fix cleanup when RR fails due to OOM autotools: recognize more Linux targets when setting `-D_GNU_SOURCE` BUG-BOUNTY.md. mention the medium bounty amount in 2025 cmake: fix missed version number for multi-pkg-config detections cmdline-docs: mention HTTP resumed uploads to be shaky curl: make -N handled correctly curl: upload from '.' fix dllmain: exclude from Cygwin builds docs/tests: remove mention of hyper docs: fix typos ftp: fix teardown of DATA connection in done http: fail early when rewind of input failed when following redirects license: update some copyright links to curl.se memanalyze.pl: fix getaddrinfo/freeaddrinfo checks misc: fix spelling misc: we write *an* IPv6 address multi: fix add_handle resizing spelling: 'a' vs 'an' spelling: call it null-terminate consistently test1510: fix expectation tests: await portfile to be complete tests: fix checks for https-mtls proto tests: improve server start reliability tests: move test docs into /docs tests: re-enable 1510, document heimdal memleak tests: test mtls also w/ clientAuth EKU only tests: test mtls with --insecure tls BIOs: handle BIO_CTRL_EOF correctly tool_getparam: make --no-anyauth not be accepted tool_getparam: refactored, simplified tool_getparam: remove two nextarg NULL checks VULN-DISCLOSURE-POLICY.md: the distros list wants <= 7 days embargo wolfssl: fix sending of early data ws: handle blocked sends better ws: tests and fixes @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.24 2025/05/28 09:43:53 wiz Exp $ d4 1 a4 1 DISTNAME= curl-8.14.1 @ 1.24 log @*curl*: update to 8.14.0 This release includes the following changes: o mqtt: send ping at upkeep interval [49] o schannel: handle pkcs12 client certificates containing CA certificates [58] o TLS: add CURLOPT_SSL_SIGNATURE_ALGORITHMS and --sigalgs [113] o vquic: ngtcp2 + openssl support [96] o wcurl: import v2025.04.20 script + docs [97] o websocket: add option to disable auto-pong reply [52] This release includes the following bugfixes: o _SEEALSO.md: remove spaces around command and man page section [166] o asny-thrdd: fix detach from running thread [191] o asnyc-thrdd: explain how this is okay with a comment [200] o asyn resolver code improvements [50] o async-threaded resolver: use ref counter [10] o async: DoH improvements [99] o autotools: detect `wolfSSL_set_quic_use_legacy_code` like cmake does [104] o autotools: install shell completion files on cross build [119] o aws-sigv4: allow a blank string [86] o build: check required rustls-ffi version [46] o build: enable gcc-12/13+, clang-10+ picky warnings [147] o build: enable gcc-15 picky warnings [133] o certs: drop unused `default_bits` from `.prm` files [45] o cf-https-connect: use the passed in dns struct pointer [64] o cf-socket: fix FTP accept connect [153] o cfilters: remove assert [120] o cmake/FindNGTCP2: simplify multi-pkg-config detection [27] o cmake: append picky warnings to `CMAKE_REQUIRED_FLAGS` as string [68] o cmake: avoid 'target is imported but not globally visible' when consuming libcurl with old cmake [125] o cmake: do not install `mk-ca-bundle` script and manpage [101] o cmake: enable `-Wall` for MSVC when `PICKY_COMPILER=ON` [100] o cmake: extend integration tests [139] o cmake: fix `fish` install directory detection via `pkg-config` [123] o cmake: fix nghttp3 static linking with `USE_OPENSSL_QUIC=ON` [79] o cmake: fix option() and mark_as_advanced() mixed order [111] o cmake: fix shell completion install when just one flavor is enabled [73] o cmake: honor individual picky option overrides found in `CMAKE_C_FLAGS` [146] o cmake: install shell completions for cross-builds [112] o cmake: link `crypt32` for OpenSSL feature detection [105] o cmake: merge `CURL_WERROR` logic into `PickyWarnings.cmake` [66] o cmake: prefer `COMPILE_OPTIONS` over `CMAKE_C_FLAGS` for custom C options [72] o cmake: quotes, whitespace, use `VERSION_GREATER_EQUAL` [33] o cmake: revert `CURL_LTO` behavior for multi-config generators [74] o cmake: set `BUILDING_LIBCURL` directly for unit test targets [174] o cmake: stop deleting `-W` from `CMAKE_C_FLAGS` (MSVC) [155] o cmake: tidy up and document feature detections in dependencies [107] o cmake: use `CMAKE_COMPILE_WARNING_AS_ERROR` if available [154] o cmake: use `INCLUDE_DIRECTORIES` prop to specify local header dirs [47] o cmake: use `LIB_NAME` in `curl-config.cmake.in` [148] o cmake: use absolute paths for completion targets [40] o cmake: use the `LINK_OPTIONS` property with CMake 3.13+ [78] o configure: catch asking for double resolver without https-rr [82] o configure: fix --disable-rt [20] o configure: restore link checks [25] o configure: suppress command not found for brew [235] o conncache: make Curl_cpool_init return void [15] o connect: shutdown timer fix [132] o content_encoding: Transfer-Encoding parser improvements [31] o CONTRIBUTE: add project guidelines for AI use [76] o contrithanks.sh: drop set -e [6] o cpool/cshutdown: force close connections under pressure [80] o curl: fix memory leak when -h is used in config file [161] o curl: only warn once for --manual in manual-disabled build [205] o curl_get_line: handle lines ending on the buffer boundary [62] o curl_krb5: only use functions if FTP is still enabled [21] o curl_multibyte: fixup low-level calls, include in unity builds [55] o curl_osslq: remove a leftover debug fprintf() call [140] o curl_url_get.md: don't call it normalized [212] o curl_version_info.md: clarify ssl_version for MultiSSL [145] o CURLMOPT_TIMERFUNCTION.md: correct the example [162] o CURLOPT_ERRORBUFFER.md: buffer is read only after curl takes ownership [93] o CURLOPT_FOLLOWLOCATION.md: switch to GET => no body [208] o CURLOPT_READFUNCTION.md: mention the seek callback [209] o CURLOPT_XFERINFOFUNCTION.md: fix the callback return type in example [122] o curlx: move the docs to docs/internals/ [184] o DEPRECATE.md: drop support for VS2008 [214] o DEPRECATE.md: drop Windows CE support [216] o dist: drop duplicate entry from `CMAKE_DIST` [88] o dns_entry: move from conn to data->state [178] o Dockerfile: update debian:bookworm-slim Docker digest to 90522ee [211] o docs/INSTALL.md: drop reference to removed configure option [83] o docs/libcurl: fix type and prototype problems in examples [121] o docs/libcurl: make examples build with picky compiler options [84] o docs/libcurl: mention sensitive data/headers [206] o docs: add missing return statement in examples [85] o docs: fix incorrect shell substitution in docker run example command [51] o docs: fix typo in retry.md [192] o docs: update distros links o doh: httpsrr fix [71] o doh: make sure CURLOPT_PROTOCOLS is set a with a "long" arg [124] o doh: reduce the DNS request buffer size [70] o easy_reset: fix dohfor_mid member [63] o ECH: reference the OpenSSL ECH feature branch [186] o etag-save.md: mention how using both options is a good idea [108] o eventfd: fix feature guards [24] o formdata: cleanups [219] o ftp: fix bug in failed init [179] o ftp: fix race in upload handling [207] o ftplistparser: add two overflow preventions [173] o ftplistparser: split up into more functions [215] o generate.bat: exclude curlinfo.c from legacy VS projects [175] o genserv.pl: fail with a message if `openssl` is missing or failing [14] o headers: enforce a max number of response header to accept [163] o headers: set an error message on illegal response headers [181] o hostip: fix build without threaded-resolver and without DoH [17] o hostip: show the correct name on proxy resolve error [37] o http2: fix stream window size after unpausing [34] o HTTP3.md: fix incorrect variable placeholders [30] o http: fix a build error when all auths are disabled [16] o http: fix HTTP/2 handling of TE request header using "trailers" [130] o http: in alt-svc negotiation only allow supported HTTP versions [59] o http_aws_sigv4: add additional verbose log statements [39] o http_aws_sigv4: improve sigv4 url encoding and canonicalization [240] o http_chunks: narrow variable scope for 'trlen' [199] o http_negotiate: fix non-SSL build with GSSAPI [23] o https-connect: fix httpsrr target check [36] o HTTPSRR.md: clarify somewhat [137] o if2ip: build the function also if FTP is present [19] o imap: remove redundant condition [196] o INSTALL-CMAKE.md: fix typo o INSTALL.md: update the minimal libcurl size example o KNOWN_BUGS: fix link in sivg4 issue 16.3 [26] o lib/src/docs/test: improve curl_easy_setopt() calls [116] o lib1560: use hex notation, drop non-ASCII exception [182] o lib3026: drop DLL pre-load perf mitigation for old mingw [222] o lib: add const to clientwriter tables o lib: drop curlx_getpid, use fake pid in SMB [172] o lib: include files using known path [48] o lib: make Curl_easyopts const [44] o lib: unify conversions to/from hex [3] o libcurl-tutorial.md: fix read callback explanation [118] o libssh: add NULL check for Curl_meta_get() [201] o libssh: fix memory leak [168] o libssh: remove a condition that always equals false [202] o libtest/first: stop defining MEMDEBUG_NODEFINES [32] o libtests: define CURL_DISABLE_DEPRECATION first [177] o make: clean tests better [60] o mbedtls: TLS 1.3 is max when mbedtls has 1.3 support [109] o metahash: add asserts to help analyzers [171] o mk-ca-bundle.pl: follow redirects [53] o mk-ca-bundle: switch URLs to GitHub versions [195] o mkhelp: fix to not generate a line-ending space in some cases [103] o mqtt: use conn/easy meta hash [141] o multi: do transfer book keeping using mid [91] o multi: init_do(): check result [114] o netrc: avoid NULL deref on weird input [167] o netrc: avoid strdup NULL [198] o netrc: deal with null token better [150] o ngtcp2: clarify ignoring of result [131] o openssl-quic: avoid potential `-Wnull-dereference`, add assert [126] o openssl-quic: fix printf mask [102] o openssl-quic: fix shutdown when stream not open [11] o openssl: enable builds for *both* engines and providers [115] o openssl: set the cipher string before doing private cert [138] o parsedate: provide Curl_wkday also for GnuTLS builds [13] o processhelp.pm: always call `taskkill` with `-f` (force) [69] o processhelp.pm: avoid potential endless loop, log more (Windows) [5] o progress: avoid integer overflow when gathering total transfer size [128] o pytest tls: extend coverage [217] o pytest-xdist: pytest in parallel [204] o pytest: add pinnedpubkey test cases [232] o pytest: give parameterised tests better ids for read- and parsability [142] o pytest: make test_07_22 more lenient to exit codes [90] o quic: no local idle connection timeout, ngtcp2 keep-alive [61] o rand: update comment on Curl_rand_bytes weak random [35] o RELEASE-PROCEDURE.md: release candidate git tagging explained [143] o rtsp: remove redundant condition [197] o runtests: add retry option to reduce flakiness [106] o runtests: fix indentation o runtests: recognize lowercase `windows` in `curl -V` [77] o runtests: remove server verification after start [89] o runtests: split `SSH_PWD` into `SCP_PWD` and `SFTP_PWD`, and more [75] o rustls: make max size of cert and key reasonable [41] o sasl: give help when unable to select AUTH [213] o scripts: completion.pl: sort the completion file for all shells [9] o scripts: drop unused import, formatting [95] o scripts: fix --opts-dir help in completion.pl o scripts: fix perl indentation, whitespace, semicolons [127] o sectransp: fix building for macOS Sierra and older [151] o setopt: provide info for CURLE_BAD_FUNCTION_ARGUMENT [180] o smb: avoid integer overflow on weird input date [129] o socket: use accept4 when available [7] o socketpair: support pipe2 where available [56] o spacecheck.pl: check for non-ASCII chars, fix fallouts [187] o spacecheck.pl: verify `tests/data/test*` for non-ASCII chars [189] o src: drop strcase.[ch] from tool builds [157] o src: include memdebug.h consistently with angle brackets <> [160] o src: rename curlx_safefree to tool_safefree [164] o test1173.pl: whitelist some option-looking names that aren't options [203] o test1658: add unit test for the HTTPS RR decoder [28] o test: make unittest 1308 into a libtest [4] o tests/ech_tests.sh: sync shebang with rest of bash scripts [42] o tests/FILEFORMAT.md: clarify %hex[] formatting [188] o tests/FILEFORMAT.md: document the aws feature [156] o tests/README.md: document --test-duphandle [8] o tests/README.md: list the openssl tool among the prerequisites [12] o tests/server/dnsd: basic DNS server for test suite [92] o tests/server: check for `stream != NULL` in mqttd [194] o tests/server: fix typo in comment o tests/server: stop using libcurl string comparisons [185] o tests/server: stop using libcurl's printf functions [190] o tests/serverhelp: remove last remnants of http-pipe server [1] o tests/tunit: make a separate directory for tool-based unit tests [54] o tests: add aws feature to the related tests [159] o tests: Add https-mtls server to force client auth [57] o tests: fix some test tag mismatches o tests: mark ipfs tests to require ipfs [2] o tests: move a boolean variable out of the path section o tests: prefer `--insecure` over `-k` [43] o tests: provide all non-ascii data hex encoded [183] o tests: remove some unused test case sections o tests: require IPv6 for 1265, 1324, 2086 [87] o tests: separate tunit tests from unit tests more [176] o tests: stop using libcurl's strdup [170] o tests: unify test case keywords o tests: use a more portable null device path [38] o TODO: remove "nicer lacking perl message" [117] o tool_cb_write.c: handle EINTR on flush [65] o tool_getparam: clear argument only when needed [98] o tool_operate: make retrycheck() a separate function [218] o tool_operate: when retrying, only truncate regular files [165] o tool_paramhlp: avoid integer overflow in secs2ms() [152] o tool_parsecfg: make get_line handle lines ending on the buffer boundary [81] o typecheck-gcc.h: fix the typechecks [110] o urlapi: redirecting to "" is considered fine [149] o urlapi: remove unneeded guards around PUNY2IDN [193] o urldata: remove the unused struct field 'hide_progress' [220] o VERSIONS: list all past releases [22] o vquic: consistent name for the stream struct across backends [135] o vquic: init for every call to recvmsg [134] o vtls: avoid NULL deref on bad PEM input [169] o vtls: fix build with ssl but without http [18] o VULN-DISCLOSURE-POLICY: use of weak algos [94] o winbuild: add the deprecation warning to the README [29] o winbuild: curl_get_line is not used for tool builds [158] o windows: fix builds targeting WinXP, test it in CI [227] o wolfssl: fix to enable ALPN when available [67] o ws: fix the header replace check [144] o ws: store protocol context as connection meta data [136] @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.23 2025/04/16 21:27:24 adam Exp $ d4 1 a4 1 DISTNAME= curl-8.14.0 @ 1.23 log @curl libcurl-gnutls: updated to 8.13.0 Changes 8.13.0: curl: add write-out variable 'tls_earlydata' curl: make --url support a file with URLs gnutls: set priority via --ciphers IMAP: add CURLOPT_UPLOAD_FLAGS and --upload-flags lib: add CURLFOLLOW_OBEYCODE and CURLFOLLOW_FIRSTONLY OpenSSL/quictls: add support for TLSv1.3 early data rustls: add support for CERTINFO rustls: add support for SSLKEYLOGFILE rustls: support ECH w/ DoH lookup for config rustls: support native platform verifier var: add a '64dec' function that can base64 decode a string wolfssl: tls early data support bugfixes @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.22 2025/02/13 18:24:34 adam Exp $ d4 1 a4 1 DISTNAME= curl-8.13.0 @ 1.22 log @curl: updated to 8.12.1 8.12.1 Bugfixes: all: remove FIXME and TODO comments asyn-thread: fix build with `CURL_DISABLE_SOCKETPAIR` asyn-thread: fix HTTPS RR crash asyn-thread: fix the returned bitmask from Curl_resolver_getsock asyn-thread: survive a c-ares channel set to NULL build: add tool_hugehelp.c into IBMi build checksrc.pl: warn on FIXME/TODO comments cmake/Find: set `_FOUND` for compatibility when found via `pkg-config` cmake: add integration tests, run them in CI cmake: always reference OpenSSL and ZLIB via imported targets cmake: avoid unnecessary `-L` for implicit link dirs cmake: drop `LDAP_DEPRECATED=1` macro, to sync with autotools cmake: fix `HAVE_GETHOSTBYNAME_R_*` detections with `CURL_WERROR=ON` cmake: fix to detect `HAVE_OPENSSL_SRP` in MSVC UWP builds cmake: fix/add missing feature detections for Windows/MS-DOS cmake: initialize variables where missing cmake: lib order fixes for picky linkers (e.g. binutils `ld`) cmake: normalize before matching paths with syspaths cmake: respect `GNUTLS_CFLAGS` when detected via `pkg-config` cmake: respect `GNUTLS_LIBRARY_DIRS` in `libcurl.pc` and `curl-config` cmake: save a line with `CMAKE_C_IMPLICIT_LINK_DIRECTORIES` exclusion cmake: tidy up string append and list prepend syntax configure/cmake: check for realpath configure/cmake: set asyn-rr a feature only if httpsrr is enabled content_encoding: #error on too old zlib curl_global_sslset.md: Add SSL backend names CURLOPT_SSH_KNOWNHOSTS.md: strongly recommend using this CURLSHOPT_SHARE.md: adjust for the new SSL session cache docs: better explain multi-part byte range behavior docs: use valid example domain names generate.bat: remove curl_get_line.c from the curlx file list header.md: mention `Authorization:` and `Cookie:` special treatment imap: TLS upgrade fix INTERNALS: fix c-ares, as we actually support 1.6.0 or later ldap: drop support for legacy Novell LDAP SDK lib: include necessary headers for `inet_ntop`/`inet_pton` lib: silence LibreSSL collision warning on non-MSVC Windows libssh2: comparison is always true because rc <= -1 libssh2: raise lowest supported version to 1.2.8 libssh: drop support for libssh older than 0.9.0 libssh: silence `-Wconversion` with a cast (Windows 32-bit) netrc: return code cleanup, fix missing file error openssl-quic: ignore ciphers for h3 openssl: fix out of scope variables in goto pop3: TLS upgrade fix runtests: fix the disabling of the memory tracking runtests: quote commands to support paths with spaces scache: add magic checks smb: silence `-Warray-bounds` with gcc 13+ smtp: TLS upgrade fix SPONSORS.md: clarify that we don't promise goods or services test1516: avoid failure due to spaces in path test2080: simplify, avoid the null byte tests: fix test 558, 1330 for MSVC, allow TrackMemory with MSVC in cmake tidy-up: make per-file `ARRAYSIZE` macros global as `CURL_ARRAYSIZE` tool_cfgable: sort struct fields by size, use bitfields for booleans tool_getparam: add "TLS required" flag for each such option tool_progress: fix percent output of large parallel transfers tool_ssls: switch to tool-specific get_line function verbose.md: mention how carriage-return might occur in headers vquic: make the "disable GSO" use infof, not failf vtls: fix multissl-init vtsl: eliminate 'data->state.ssl_scache' wakeup_write: make sure the eventfd write sends eight bytes wolfssl: silence compiler warning (MSVC 2019), simplify existing @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.21 2025/02/09 00:28:21 rillig Exp $ d4 1 a4 1 DISTNAME= curl-8.12.1 @ 1.21 log @don't add unknown configure option for libiconv in a few packages @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.20 2025/02/05 08:51:31 wiz Exp $ d4 1 a4 1 DISTNAME= curl-8.12.0 @ 1.20 log @curl: update to 8.12.0. curl and libcurl 8.12.0 Public curl releases: 264 Command line options: 267 curl_easy_setopt() options: 306 Public functions in libcurl: 96 Contributors: 3332 This release includes the following changes: o curl: add byte range support to --variable reading from file [56] o curl: make --etag-save acknowledge --create-dirs [31] o getinfo: fix CURLINFO_QUEUE_TIME_T and add 'time_queue' var [55] o getinfo: provide info which auth was used for HTTP and proxy [40] o hyper: drop support [57] o openssl: add support to use keys and certificates from PKCS#11 provider [77] o QUIC: 0RTT for gnutls via CURLSSLOPT_EARLYDATA [61] o vtls: feature ssls-export for SSL session im-/export [141] This release includes the following bugfixes: o altsvc: avoid integer overflow in expire calculation [16] o altsvc: return error on dot-only name [178] o android: add CI jobs, buildinfo, cmake docs, disable `CURL_USE_PKGCONFIG` by default [185] o asyn-ares: acknowledge CURLOPT_DNS_SERVERS set to NULL [190] o asyn-ares: fix memory leak [233] o asyn-ares: initial HTTPS resolve support [166] o asyn-thread: use c-ares to resolve HTTPS RR [205] o async-thread: avoid closing eventfd twice [9] o autotools: add support for mingw UWP builds [192] o autotools: silence gcc warnings in libtool code [96] o binmode: convert to macro and use it from tests [44] o build: delete `-Wsign-conversion` related FIXMEs [137] o build: drop `-Winline` picky warning [53] o build: drop `tool_hugehelp.c.cvs`, tidy up macros, drop `buildconf.bat` [200] o build: drop macro used to enable `-Wsign-conversion` warnings in CI [224] o build: drop unused feature macros, update exception list [51] o build: fix `-Wtrampolines` picky warning for gcc 4.x versions [156] o build: fix compiling with GCC 4.x versions [214] o build: fix the tidy targets for autotools [52] o build: fix unsigned `time_t` detection for cmake, MS-DOS, AmigaOS [104] o build: replace configure check with PP condition (Android <21) [97] o build: stop detecting `sched_yield()` on Windows [176] o c-ares: fix/tidy-up macro initializations, avoid a deprecated function [209] o cd2nroff: do not insist on quoted <> within backticks [222] o cd2nroff: support "none" as a TLS backend [29] o cf-https-connect: look into httpsrr alpns when available [152] o cf-socket: error if address can't be copied [72] o cfilters: kill connection filter events attach+detach [217] o checksrc.bat: remove explicit SNPRINTF bypass [174] o checksrc: ban use of sscanf() [7] o checksrc: check for return with parens around a value/name [130] o checksrc: exclude generated bundle files to avoid race condition [235] o checksrc: fix the return() checker [35] o checksrc: introduce 'banfunc' to ban specific functions [117] o cmake/Find: add `iphlpapi` for c-ares, omit syslibs if dep not found [203] o cmake/FindLDAP: avoid empty 'Requires' item when omitting `pkg-config` module [90] o cmake/FindLDAP: avoid framework locations for libs too (Apple) [122] o cmake/FindLibpsl: protect against `pkg-config` "half-detection" [89] o cmake/FindLibssh: sync header comment with other modules o cmake/FindMbedTLS: drop lib duplicates early [17] o cmake: add `librtmp` Find module [86] o cmake: add LDAP Find module [46] o cmake: add native `pkg-config` detection for remaining Find modules [37] o cmake: allow `CURL_LTO` regardless of `CURL_BUILD_TYPE`, enable in CI [88] o cmake: clang-cl improvements [42] o cmake: delete accidental debug message o cmake: deprecate winbuild, add migration guide from legacy build methods [157] o cmake: detect mingw-w64 version, pre-fill `HAVE_STRTOK_R` [179] o cmake: do not store `MINGW64_VERSION` in cache [175] o cmake: drop `CURL_USE_PKGCONFIG` from `curl-config.cmake.in` [208] o cmake: drop `fseeko()` pre-fill and check for Windows [201] o cmake: drop duplicate Windows cache value [81] o cmake: drop redundant FOUND checks (libgsasl, libssh, libuv) [49] o cmake: drop redundant opening/closing `.*` from `MATCH` expressions [64] o cmake: drop unused `HAVE_SYS_XATTR_H` detection [79] o cmake: drop VS2010 "Dialog Hell" workaround added in 2013 [136] o cmake: extend zlib's `AUTO` option to brotli, zstd and enable if found [36] o cmake: fix `net/in.h` detection for MS-DOS [103] o cmake: improve `curl_dumpvars()` and move to `Utilities.cmake` [50] o cmake: make libpsl required by default [45] o cmake: make system libraries `dl`, `m`, `pthread` customizable [123] o cmake: move `pkg-config` names to Find modules [87] o cmake: move GSS init before feature detections [93] o cmake: move mingw UWP workaround from GHA to `CMakeLists.txt` [194] o cmake: namespace functions and macros [41] o cmake: optimize out 4 picky warning option detections with gcc [78] o cmake: pick a better IPv6 feature flag when assembling the feature list [132] o cmake: pre-fill `HAVE_STDATOMIC_H`, `HAVE_ATOMIC` for mingw-w64 [180] o cmake: pre-fill `HAVE_STDINT_H` on Windows [149] o cmake: prefer dash-style MSVC options [216] o cmake: publish/check supported protocols/features via `CURLConfig.cmake` [100] o cmake: replace `unset(VAR)` with `set(VAR "")` for init [43] o cmake: sync OpenSSL QUIC fork detection with autotools [102] o cmake: use `CMAKE_REQUIRED_LINK_DIRECTORIES` [48] o cmake: use `STREQUAL` to detect Linux [68] o cmake: warn for OpenSSL versions missing TLS 1.3 support [221] o cmdline-opts/version.md: describe multissl, mention SSLS-EXPORT [170] o completion.pl: add completion for paths after @@ for fish [82] o config-mac: drop `MACOS_SSL_SUPPORT` macro [63] o config: drop unused code and variables [135] o configure: do not inline 'dnl' comments o configure: drop unused detections and macros [105] o configure: streamline Windows large file feature check [138] o configure: UWP and Android follow-up fixes [184] o conncache: count shutdowns against host and max limits [154] o conncache: result_cb comment removed from function docs [1] o content_encoding: drop support for zlib before 1.2.0.4 [211] o content_encoding: namespace GZIP flag constants [147] o content_encoding: put the decomp buffers into the writer structs [210] o content_encoding: support use of custom libzstd memory functions [186] o cookie: cap expire times to 400 days [111] o cookie: fix crash in netscape cookie parsing [84] o cookie: parse only the exact expire date [3] o curl-functions.m4: fix indentation in `CURL_SIZEOF()` [131] o curl: return error if etag options are used with multiple URLs [5] o curl_multi_fdset: include the shutdown connections in the set [168] o curl_multi_waitfds.md: tidy up the example [162] o curl_multibyte: support Windows paths longer than MAX_PATH [76] o curl_setup: fix missing `ADDRESS_FAMILY` type in rare build cases [144] o curl_sha512_256: rename symbols to the curl namespace [124] o curl_url_set.md: adjust the added-in to 7.62.0 [94] o curl_ws_recv.md: fix typo o CURLOPT_CONNECT_ONLY.md: an easy handle with this option set cannot be reused [164] o CURLOPT_PROXY.md: clarify the crendential support in proxy URLs [66] o CURLOPT_RESOLVE.md: fix wording [30] o CURLOPT_SEEKFUNCTION.md: used for FTP, HTTP and SFTP (only) [109] o docs/BUGS.md: remove leading space from a link o docs/cmdline-opts/_ENVIRONMENT.md: minor language fix [119] o docs/cmdline-opts/location.md: fix typos for location flag [226] o docs/HTTP-COOKIES.md: link to more information [125] o docs/HTTPSRR.md: initial HTTPS RR documentation [204] o docs/libcurl/opts: clarify the return values [114] o docs/libcurl: return value overhall [120] o docs/TLS-SESSIONS: fix typo, the->they [189] o docs: document the behavior of -- in the curl command line [198] o docs: use lowercase curl and libcurl [113] o doh: cleanups and extended HTTPS RR code [161] o doh: send HTTPS RR requests for all HTTP(S) transfers [160] o easy: allow connect-only handle reuse with easy_perform [232] o easy: make curl_easy_perform() return error if connection still there [163] o easy_lock: use Sleep(1) for thread yield on old Windows [191] o ECH: update APIs to those agreed with OpenSSL maintainers [101] o examples/block-ip: drop redundant `memory.h` include o examples/block-ip: show how to block IP addresses [74] o examples/complicated: fix warnings, bump deprecated callback, tidy up [59] o examples/synctime.c: remove references to dead URLs and functionality [62] o examples: make them compile with compatibility functions disabled (Windows) [58] o examples: use return according to code style o file: drop `OPEN_NEEDS_ARG3` option [91] o file: fix Android compiler warning [85] o gitignore: add generated unity sources for lib and src o GnuTLS: fix 'time_appconnect' for early data [127] o hash: add asserts in hash_element_dtor() [126] o HTTP/2: strip TE request header [140] o http2: fix data_pending check [241] o http2: fix value stored to 'result' is never read [71] o http: fix build with `CURL_DISABLE_COOKIES` [95] o http: ignore invalid Retry-After times [107] o http_aws_sigv4: Fix invalid compare function handling zero-length pairs [24] o https-connect: start next immediately on failure [223] o INFRASTRUCTURE.md: project infra [99] o INSTALL-CMAKE.md: fix punctuation o INSTALL.md: add CMake examples for macOS and iOS [242] o INSTALL.md: document VS2008 and mingw-w64 [165] o INTERNALS.md: sync wolfSSL version requirement with source code o lib517: extend the getdate test with quotes and leading "junk" [4] o lib: clarify 'conn->httpversion' [213] o lib: redirect handling by protocol handler [212] o lib: remove `__EMX__` guards [83] o lib: replace `inline` redefine with `CURL_INLINE` macro [47] o lib: supress deprecation warnings in apple builds [32] o lib: TLS session ticket caching reworked [60] o libcurl/opts: do not save files in dirs where attackers have access [199] o Makefile.dist: delete [237] o Makefile.mk: drop in favour of autotools and cmake (MS-DOS, AmigaOS3) [38] o mbedtls: fix handling of blocked sends [116] o mbedtls: PSA can be used independently of TLS 1.3 (avoid runtime errors) [219] o mime: explicitly rewind subparts at attachment time. [80] o mprintf: fix integer handling in float precision [173] o mprintf: terminate snprintf output on windows [172] o msvc: add missing push/pop for warning pragmas [236] o msvc: assume `_INTEGRAL_MAX_BITS >= 64` [158] o msvc: drop checks for ancient versions [133] o msvc: fix building with `HAVE_INET_NTOP` and MSVC <=1900 [151] o msvc: require VS2005 for large file support [143] o msvc: tidy up `_CRT_*_NO_DEPRECATE` definitions [148] o multi: fix curl_multi_waitfds reporting of fd_count [73] o multi: fix return code for an already-removed easy handle [106] o multihandle: add an ssl_scache here [129] o multissl: auto-enable `OPENSSL_COEXIST` for wolfSSL + OpenSSL [92] o multissl: make openssl + wolfssl builds work [34] o netrc: 'default' with no credentials is not a match [108] o netrc: fix password-only entries [28] o netrc: restore _netrc fallback logic [6] o ngtcp2: fix memory leak on connect failure [225] o ngtcp2: fix two cases of value stored never read [65] o openssl: define `HAVE_KEYLOG_CALLBACK` before use [227] o openssl: drop unused `HAVE_SSL_GET_SHUTDOWN` macro [228] o openssl: fix ECH logic [67] o osslq: use SSL_poll to determine writeability of QUIC streams [139] o projects/Windows: remove wolfSSL from legacy projects [75] o projects: fix `INSTALL-CMAKE.md` references o pytest: remove 'repeat' parameter [182] o pytest: use httpd/apache2 directly, no apachectl [169] o RELEASE-PROCEDURE.md: mention how to publish security advisories [2] o runtests.pl: fix precedence issue [207] o scripts/mdlinkcheck: markdown link checker [19] o sectransp: free certificate on error [12] o select: avoid a NULL deref in cwfds_add_sock [128] o smb: fix compiler warning [112] o src: add `CURL_STRICMP()` macro, use `_stricmp()` on Windows [54] o src: drop support for `CURL_TESTDIR` debug env [121] o src: omit hugehelp and ca-embed from libcurltool [215] o ssl session cache: change cache dimensions [159] o strparse: string parsing helper functions [8] o symbols-in-versions: update version for LIBCURL_VERSION and LIBCURL_VERSION_NUM [193] o system.h: add 64-bit curl_off_t definitions for NonStop [11] o system.h: drop compilers lacking 64-bit integer type (Windows/MS-DOS) [155] o system.h: drop duplicate and no-op code [153] o system.h: fix indentation [142] o telnet: handle single-byte input option [177] o test1960: don't close the socket too early [220] o test483: require cookie support [98] o tests/http/clients: use proper sleep() call on NonStop [10] o tests: change the behavior of swsbounce [202] o tests: stop promoting perl warnings to fatal errors o TheArtOfHttpScripting.md: rewrite double 'that' [115] o tidy-up: `curl_setup.h`, `curl_setup_once.h`, `config-win32ce.h` [146] o tidy-up: drop parenthesis around `return` expression [167] o tidy-up: drop parenthesis around `return` values [134] o tidy-up: extend `CURL_O_BINARY` to lib and tests [195] o TLS: check connection for SSL use, not handler [181] o tool_formparse.c: make curlx_uztoso a static in here [39] o tool_formparse: accept digits in --form type= strings [33] o tool_getparam: ECH param parsing refix [150] o tool_getparam: fail --hostpubsha256 if libssh2 is not used [229] o tool_getparam: fix "Ignored Return Value" [21] o tool_getparam: fix memory leak on error in parse_ech [14] o tool_getparam: fix the ECH parser [20] o tool_operate: make --etag-compare always accept a non-existing file [22] o transfer: fix CURLOPT_CURLU override logic [171] o urlapi: fix redirect to a new fragment or query (only) [118] o urldata: tweak the UserDefined struct [240] o variable.md: mention --expand-variable for variables to variables [13] o variable.md: show function use with examples [18] o version: fix the IDN feature for winidn and appleidn [187] o vquic: fix 4th function call argument is an uninitialized value [70] o vquic: make vquic_send_packets not return without setting psent [69] o vtls: fix default SSL backend as a fallback [231] o vtls: only remember the expiry timestamp in session cache [110] o vtls: remove 'detach/attach' functions from TLS handler struct [25] o vtls: remove unusued 'check_cxn' from TLS handler struct [26] o vtls: replace "none"-functions with NULL pointers [27] o VULN-DISCLOSURE-POLICY.md: mention the not setting CVSS [23] o VULN-DISCLOSURE-POLICY: on legacy dependencies [239] o websocket: fix message send corruption [188] o windows: drop dupe macros, detect `CURL_OS` for WinCE ARM, indentation [183] o windows: drop redundant `USE_WIN32_SMALL_FILES` macro [145] o windows: drop two missed `buildconf.bat` references o windows: merge `config-win32ce.h` into `config-win32.h` [196] o ws-docs: extend WebSocket documentation [206] o ws-docs: remove the outdated texts saying ws support is experimental [15] o ws: reject frames with unknown reserved bits set [230] o x509asn1: add parse recursion limit [197] @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.19 2024/12/11 09:24:32 wiz Exp $ d25 1 @ 1.19 log @curl: update to 8.11.1. This release includes the following bugfixes: o build: fix ECH to always enable HTTPS RR [35] o build: fix MSVC UWP builds [32] o build: omit certain deps from `libcurl.pc` unless found via `pkg-config` [27] o build: use `_fseeki64()` on Windows, drop detections [41] o cmake: do not echo most inherited `LDFLAGS` to config files [55] o cmake: drop cmake args list from `buildinfo.txt` [8] o cmake: include `wolfssl/options.h` first [53] o cmake: remove legacy unused IMMEDIATE keyword [21] o cmake: restore cmake args list in `buildinfo.txt` [26] o cmake: set `CURL_STATICLIB` for static lib when `SHARE_LIB_OBJECT=OFF` [64] o cmake: sync GSS config code with other deps [28] o cmake: typo in comment o cmake: work around `ios.toolchain.cmake` breaking feature-detections [37] o cmakelint: fix to check root `CMakeLists.txt` [36] o cmdline/ech.md: formatting cleanups [13] o configure: add FIXMEs for disabled pkg-config references o configure: do not echo most inherited `LDFLAGS` to config files [31] o configure: replace `$#` shell syntax [25] o cookie: treat cookie name case sensitively [4] o curl-rustls.m4: keep existing `CPPFLAGS`/`LDFLAGS` when detected [40] o curl.h: mark two error codes as obsolete [19] o curl: --continue-at is mutually exclusive with --no-clobber [51] o curl: --continue-at is mutually exclusive with --range [61] o curl: --continue-at is mutually exclusive with --remove-on-error [50] o curl: --test-duphandle in debug builds runs "duphandled" [6] o curl: do more command line parsing in sub functions [71] o curl: rename struct var to fix AIX build [24] o curl: use realtime in trace timestamps [52] o curl_multi_socket_all.md: soften the deprecation warning [56] o CURLOPT_PREREQFUNCTION.md: add result code on failure [23] o digest: produce a shorter cnonce in Digest headers [70] o DISTROS: update Alt Linux links o dmaketgz: use --no-cache when building docker image [66] o docs: bring back ALTSVC.md and HSTS.md [76] o docs: document default `User-Agent` [57] o docs: suggest --ssl-reqd instead of --ftp-ssl [62] o duphandle: also init netrc [3] o ECH: enable support for the AWS-LC backend [5] o hostip: don't use the resolver for FQDN localhost [45] o http_negotiate: allow for a one byte larger channel binding buffer [63] o http_proxy: move dynhds_add_custom here from http.c [18] o KNOWN_BUGS: setting a disabled option should return CURLE_NOT_BUILT_IN [74] o krb5: fix socket/sockindex confusion, MSVC compiler warnings [22] o lib: fixes for wolfSSL OPENSSL_COEXIST [73] o libssh: use libssh sftp_aio to upload file [47] o libssh: when using IPv6 numerical address, add brackets [43] o macos: disable gcc `availability` workaround as needed [7] o mbedtls: call psa_crypt_init() in global init [2] o mime: fix reader stall on small read lengths [65] o mk-ca-bundle: remove CKA_NSS_SERVER_DISTRUST_AFTER conditions [39] o mprintf: fix the integer overflow checks [44] o multi: add clarifying comment for wakeup_write() [9] o multi: fix callback for `CURLMOPT_TIMERFUNCTION` not being called again when... [48] o netrc: address several netrc parser flaws [17] o netrc: support large file, longer lines, longer tokens [14] o nghttp2: use custom memory functions [1] o OpenSSL: improvde error message on expired certificate [59] o openssl: remove three "Useless Assignments" [72] o openssl: stop using SSL_CTX_ function prefix for our functions [20] o os400: Fix IBMi builds [33] o os400: Fix IBMi EBCDIC conversion of arguments [34] o pytest: add test for use of CURLMOPT_MAX_HOST_CONNECTIONS [60] o rtsp: check EOS in the RTSP receive and return an error code [49] o schannel: remove TLS 1.3 ciphersuite-list support [54] o setopt: fix CURLOPT_HTTP_CONTENT_DECODING [15] o setopt: fix missing options for builds without HTTP & MQTT [10] o show-headers.md: clarify the headers are saved with the data [58] o socket: handle binding to "host!" [16] o socketpair: fix enabling `USE_EVENTFD` [30] o strtok: use namespaced `strtok_r` macro instead of redefining it [29] o tests: add the ending time stamp in testcurl.pl o tests: re-enable 2086, and 472, 1299, 1613 for Windows [38] o TODO: consider OCSP stapling by default [11] o tool_formparse: remove use of sscanf() [68] o tool_getparam: parse --localport without using sscanf [67] o tool_getpass: fix UWP `-Wnull-dereference` [46] o tool_getpass: replace `getch()` call with `_getch()` on Windows [42] o tool_urlglob: parse character globbing range without sscanf [69] o vtls: fix compile warning when ALPN is not available [12] @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.18 2024/11/06 08:19:26 wiz Exp $ d4 1 a4 1 DISTNAME= curl-8.11.1 @ 1.18 log @*curl*: update to 8.11.0 This release includes the following changes: o curl: --create-dirs works for --dump-header as well [4] o gtls: Add P12 format support [9] o ipfs: add options to disable [8] o TLS: TLSv1.3 earlydata support for curl [140] o WebSockets: make support official (non-experimental) [106] This release includes the following bugfixes: o alt-svc: honor data->state.httpwant [19] o altsvc: avoid using local buffer and memcpy [124] o asyn-ares: remove typecast, fix expire [113] o autotools: add support for 'unity' builds, enable in CI [15] o bearssl: avoid strpcy() when generating TLS version log message [120] o bearssl: improved session handling, test exceptions [233] o bufq: unwrite fix [121] o build: add `ldap` to `libcurl.pc` `Requires:` [139] o build: add pytest targets [71] o build: clarify CA embed is for curl tool, mark default, improve summary [72] o build: detect and use `_setmode()` with Cygwin/MSYS, also use on Windows [136] o build: disable warning `-Wunreachable-code-break` [195] o build: fix clang-cl builds, add CI job [254] o build: fix cross-compile check for poll with bionic [70] o build: fix possible `-Wformat-overflow` in lib557 [85] o build: limit arc4random detection to no-SSL configs [43] o build: show if CA bundle to embed was found [83] o build: tidy up and improve versioned-symbols options [5] o build: tidy up deprecation suppression, enable warnings for clang [12] o certs: add missing `-CAcreateserial` option for LibreSSL [247] o checksrc: add check for spaces around logical AND operators [220] o checksrc: Added checks for colon operator in ternary expressions [77] o checksrc: check for spaces around '?', '>' and '<' [46] o ci: dump `curl_config.h` to log in all jobs [199] o CI: run with standard mod_http2 [214] o cmake, Makefile.mk: use -isystem for headers, silence BearSSL issues [37] o cmake/FindCares: fix version detection for c-ares 1.34.1 [209] o cmake/FindNGTCP2: use library path as hint for finding crypto module [40] o cmake: add missed variable to comment o cmake: add native `pkg-config` detection for mbedTLS, MSH3, Quiche, Rustls, wolfSSL [149] o cmake: allow building tests in unity mode [31] o cmake: apply `WIN32_LEAN_AND_MEAN` to all feature checks o cmake: avoid setting `BUILD_TESTING` [179] o cmake: clear package version after `pkg-config` detection [207] o cmake: delete unused NEED_LBER_H, HAVE_LDAP_H [38] o cmake: detect `HAVE_NETINET_IN6_H`, `HAVE_CLOSESOCKET_CAMEL`, `HAVE_PROTO_BSDSOCKET_H` [132] o cmake: detect GNU GSS [127] o cmake: disable default OpenSSL if BearSSL, GnuTLS or Rustls is enabled [44] o cmake: do not propagate unused `HAVE_GSSAPI_GSSAPI_KRB5_H` to C [131] o cmake: document `-D` and env build options [208] o cmake: drop obsolete items from `TODO` and `INSTALL-CMAKE` [228] o cmake: drop redundant assignments [49] o cmake: drop redundant zlib var, rename function (internals) [50] o cmake: expand CURL_USE_PKGCONFIG to non-cross MINGW [13] o cmake: fix broken dependency chain for cmdline-opts, tidy-ups [11] o cmake: fix compile warnings for clang-cl [218] o cmake: fix missing spacing in log message [205] o cmake: limit `CURL_STATIC_CRT` to MSVC [217] o cmake: make `test-ci` target skip building dependencies [88] o cmake: mark as advanced some internal Find* variables [212] o cmake: readd `generate-curl.1` dependency for `src` just in case [86] o cmake: rename LDAP dependency config variables to match Find modules [144] o cmake: replace `check_include_file_concat()` for LDAP and GSS detection [143] o cmake: replace `CURL_*_DIR` with `{PROJECT,CMAKE_CURRENT}_*_DIR` [211] o cmake: require quictls (or fork) when using msh3 on non-Windows [14] o cmake: separate target for examples, optimize CI, fix fallouts [16] o cmake: set version for `project()` and add CPack support [123] o cmake: stop adding dependency headers to global `CMAKE_REQUIRED_INCLUDES` [146] o cmake: sync torture test parallelism with autotools [35] o cmake: tidy up `CURL_DISABLE_FORM_API` initialization [225] o cmake: tidy up and shorten symbol hiding initialization [213] o cmake: tidy up line order o cmake: tidy up picky warning initialization [215] o cmake: tidy-ups and rebase fixups [191] o cmake: tweaks around debug mode and hidden symbols [194] o cmake: untangle feature detection interdependencies [198] o cmake: use `list(APPEND)` on `CURL_INCLUDES` [223] o cmake: use OpenSSL for LDAP detection only if available [102] o cmake: use the `BSD` variable [210] o config: rename the OS define to CURL_OS to reduce collision risk [256] o configure: add GSS to `libcurl.pc` `Depends:` [126] o configure: catch Apple in more target triplets [6] o configure: drop duplicate feature checks for `poll()`, `if_nametoindex()` [135] o configure: drop unused bare `socket.h` detection [133] o configure: improve help string for some options [78] o conncache: find bundle again in case it is removed [129] o conncache: more efficient implementation of cpool_remove_bundle [176] o cookie: overhaul and cleanup [142] o curl-rustls.m4: set linker flags to allow rustls build on macos [186] o curl.h: remove the struct pointer for CURL/CURLSH/CURLM typedefs [174] o curl: add build options for safe/no CA bundle search (Windows) [26] o curl: detect ECH support dynamically, not at build time [230] o curl_addrinfo: support operating systems with only getaddrinfo(3) [239] o curl_multi_perform.md: fix typo [224] o curl_trc: fix build with verbose messages disabled [79] o curl_url_set.md: document HOST handling when URL is parsed [2] o curl_ws_recv.md: the 'meta' pointer is only returned on success [221] o curl_ws_recv: return recv 0 and point meta to NULL on all errors [222] o CURLMOPT_PIPELINING.md: clarify that CURLPIPE_NOTHING is not default [54] o CURLOPT_APPEND.md: goes for SFTP as well [128] o CURLOPT_HEADERFUNCTION.md: do not modify the passed in buffer [107] o DISABLED: disable test 1060 with hyper [154] o DISTROS: avoid use of "very" o Dockerfile: update Docker digest to d830561 [226] o docs/cmdline-opts: GnuTLS supports PKCS#11 URI in --cert option [101] o docs: clarify FTP over HTTP proxy functionality somewhat [203] o docs: fix a typo in some cipher options o ech: spelling, whitespace, say `--ech` default config [137] o ftp: fix 0-length last write on upload from stdin [76] o ftp: move listen handling to socket filter [183] o GHA: optimize test prereq steps [188] o gnutls: use session cache for QUIC [196] o hsts: avoid the local buffer and memcpy on lookup [125] o hsts: improve subdomain handling [158] o hsts: support "implied LWS" properly around max-age [229] o http2: auto reset stream on server eos [147] o http_aws_sigv4: avoid local buffer and strcpy [92] o INSTALL-CMAKE.md: mention focus on shared libraries [73] o INSTALL-CMAKE: fix punctuation and a typo o INSTALL.md: fix a typo that slipped in to RISC OS o json.md: cli-option `--json` is an alias of `--data-binary` [89] o lib, src, tests: added space around ternary expressions [56] o lib/cw-out: initialize 'flush_all' directly [62] o lib/src: white space edits to comply better with code style [47] o lib: avoid assigning 'result' temporarily [97] o lib: fix disabled-verbose-strings + enable-debug build warnings o lib: fix unity builds with BearSSL, MSH3, Quiche, OmniOS [32] o lib: move curl_path.[ch] into vssh/ [182] o lib: msnprintf tidy-ups [245] o lib: remove Curl_ prefix from static functions [202] o lib: remove function pointer typecasts for hmac/sha256/md5 [175] o lib: use bool/TRUE/FALSE properly [48] o libcurl/opts: improve phrasing for connection cap related options [145] o libssh.c: handle EGAINS during proto-connect correctly [23] o libssh2: delete duplicate `break` [190] o libssh2: put the readdir buffers into struct [170] o libssh2: use the Curl_* memory functions to avoid memdebug [22] o libssh2: use the filename buffer when getting the homedir [169] o libtests: generate the lib1521 atomically [148] o mbedTLS: fix handling of TLSv1.3 sessions [184] o mbedtls: handle session as blobs [234] o mbedtls: remove failf() use from mbedtls_random [255] o mk-lib1521: fix the long return code check [204] o mprintf: do not ignore length modifiers of `%o`, `%x`, `%X` [164] o mprintf: treat `%o` as unsigned, add tests for `%o`, `%x`, `%X` [162] o mqtt: fix mqtt.md wording and add clearer explanation [172] o multi.c: make stronger check for paused transfer before asserting [24] o multi.c: warn/assert on stall only without timer [80] o multi: avoid reading whole struct pointer from pointer [10] o multi: convert Curl_follow to static multi_follow [141] o multi: make curl_multi_cleanup invalidate magic latter [159] o multi: make multi_handle_timeout use the connect timeout [98] o multi: split multi_runsingle into sub functions [200] o negotiate: conditional check around GSS & SSL specific code [1] o netrc: cache the netrc file in memory [138] o ngtcp2: do not loop on recv [251] o ngtcp2: set max window size to 10x of initial (128KB) [232] o openssl quic: populate x509 store before handshake [117] o openssl: convert a memcpy to dynbuf use [57] o openssl: extend the OpenSSL error messages [238] o openssl: improve retries on shutdown [151] o openssl: remove two strcpy() calls [64] o OS400: don't delete source files when building with debug [235] o packages/OS400/curlmain: remove the strncpy calls [155] o processhelp.pm: improve taskkill calls (Windows) [52] o pytest: fix run against multissl curl [236] o pytest: improve pytest_07_42a reliability [118] o pytest: include `buildinfo.txt` in the output [189] o pytest: include curl version string and python platform in log [242] o pytest: show curl features and protocols [150] o quic: use send/recvmmsg when available [93] o quic: use the session cache with wolfSSL as well [231] o request: on shutdown send, proceed normally on timeout [18] o runtests.md: suggest a value for -j for torture tests o runtests: add comment for handle64 pathsep requirement o runtests: drop unused code for old/classic-mingw support [87] o runtests: pass single backslashes with Windows Perl [243] o runtests: use deterministic sort for `TESTINFO` lines [201] o schannel: fix TLS cert verification by IP SAN [253] o schannel: ignore error on recv beyond close notify [167] o schannel: reclassify extra-verbose schannel_recv messages [153] o select: use poll() if existing, avoid poll() with no sockets [75] o sendf: add condition to max-filesize check [3] o server/mqttd: fix two memory leaks [178] o setopt: avoid superfluous length checks before strcmp() [105] o setopt: return error for bad input to CURLOPT_RTSP_REQUEST [240] o setopt_cptr: make overflow check only done when needed [241] o singleuse: make `git grep` faster, add Apple `nm` support [109] o smb: do not redefine `getpid` on Windows [187] o smb: replace use of strcpy() with snprintf() [122] o socks_gssapi: switch to dynbuf from buffer with strcpy [42] o source: avoid use of 'very' in comments o src/lib: remove redundant ternary operators [244] o src: guard for double declaration of `curl_ca_embed` in unity builds [166] o sws: fix unused static function with `TCP_NODELAY` undefined [134] o telnet: avoid two strcpy() by pointing to the strings instead [99] o test1035: convert host name back to utf8 as should be [63] o test1515: add tracing and more debug info [119] o test1540: add debug logging [58] o test190: replace %FTPTIME2 with a fixed value [34] o test1915: add tracing and connect timeout [114] o test1915: remove wrong comment o test2502: add libtest debug tracing [60] o test504: fix handling on pending connect [59] o testrun: explicitly set proper IP address for stunnel listen/connect [61] o tests/http: fix ubuntu GnuTLS CI failures [161] o tests/scorecard: allow remote server test [171] o tests/server/util.c: remove use of strncpy [156] o tests/valgrind.pm: fix warnings with no valgrind report to show [25] o tests/valgrind.supp: remove a travis suppression, add a Debian [116] o tests: add and use `%PERL` variable to refer to the Perl binary [82] o tests: add codeset-utf8 as a feature [66] o tests: add file: tests with existing files [45] o tests: allow pytests to run in out-of-tree builds [192] o tests: capture stdin to get the vsftpd version number [165] o tests: change Python code style to pass ruff checks o tests: check http/2 and http/3 server responsiveness [28] o tests: delete duplicate macro check [53] o tests: enable additional ruff Python lint options o tests: fix `%POSIX_PWD` on native Windows Perl [111] o tests: fix callback signatures to please UndefinedBehaviorSanitizer [173] o tests: Fix FILEFORMAT directive [206] o tests: fix keyword for test1411 o tests: fix shell quoting on native Windows Perl [110] o tests: fix some Python typing issues o tests: fixup `checkcmd` `PATH` on non-unixy platforms [108] o tests: improve mqtt server handling [27] o tests: introduce %CLIENT6IP-NB [67] o tests: let openssl generate random cert serials [91] o tests: libtests and unit tests need explicit #include memdebug [7] o tests: make precheck for HTTP on 127.0.0.1 into a feature [68] o tests: Only log warnings or worse by default in smbserver [33] o tests: postcheck is now in verify [69] o tests: remove all valgrind disable instructions [21] o tests: remove debug requirement on 38 tests [100] o tests: remove the %FTPTIME3 variable [41] o tests: replace `%PWD` with `%FILE_PWD` for `file://` [84] o tests: replace `%PWD` with `%SSH_PWD` in SCP/SFTP tests [112] o tests: replace hard-coded `/dev/null` with variable [81] o tests: simplify `pathhelp.pm`, avoid using external tools [95] o tests: speed up builds with single-binary test bundles [29] o tests: testrunner fairness [39] o tests: testrunner reliability improvements [55] o tests: use '-4' where needed [17] o tests: use a set for several of the curl_props [249] o tftp: avoid two memcpy/strcpy [94] o tidy-up: rename CURL_WINDOWS_APP to CURL_WINDOWS_UWP [36] o tls: avoid abusing CURLE_SSL_ENGINE_INITFAILED [246] o tool: support --show-headers AND --remote-header-name [103] o tool_doswin: simplify; remove unused options and strncpy calls [65] o tool_getparam: drop unused time() call [177] o tool_getparam: replace two uses of strncpy(), ban strncpy [157] o tool_operate: make --skip-existing work for --parallel [180] o tool_operate: reuse the schannel backend check [130] o tool_xattr: create the user.creator xattr attribute [197] o unit1307: tidy up Apple OS detection [252] o unit1660: fix unreachable code warning in no-SSL builds [30] o url: connection reuse on h3 connections [20] o url: use same credentials on redirect [181] o urlapi: drop unused header [51] o urlapi: normalize the IPv6 address [115] o version: minor cleanups [152] o version: say quictls in MSH3 builds [219] o vquic: fix compiler warning with gcc + MUSL [168] o vquic: recv_mmsg, use fewer, but larger buffers [250] o vtls: convert Curl_pin_peer_pubkey to use dynbuf [74] o vtls: convert pubkey_pem_to_der to use dynbuf [90] o warnless: remove curlx_sktosi and curlx_sitosk [104] o winbuild/README: consolidate command prompt section [193] o winbuild/README: document how to clean a build [163] o winbuild: add initial wolfSSL support [227] o winbuild: drop `gen_resp_file.bat` [248] o wolfssl: convert malloc + memcpys to dynbuf for cipher string [96] o wolfSSL: fix handling of TLSv1.3 sessions [185] o wolfssl: no more use of the OpenSSL API [216] o wolfssl: use old version API without openssl extra [160] @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.17 2024/09/18 10:49:50 adam Exp $ d4 1 a4 1 DISTNAME= curl-8.11.0 @ 1.17 log @curl: updated to 8.10.1 Changes in 8.10.1 Bugfixes: autotools: fix `--with-ca-embed` build rule cmake: ensure `CURL_USE_OPENSSL`/`USE_OPENSSL_QUIC` are set in sync cmake: fix MSH3 to appear on the feature list connect: store connection info when really done CURLMOPT_TIMERFUNCTION.md: emphasize that only a single timer should run FTP: partly revert eeb7c1280742f5c8fa48a4340fc1e1a1a2c7075a http2: when uploading data from stdin, fix eos forwarding http: make max-filesize check not count ignored bodies lib: fix AF_INET6 use outside of USE_IPV6 libcurl-docs: CURLINFO_LOCAL_* work for QUIC as well as TCP multi: check that the multi handle is valid in curl_multi_assign QUIC: on connect, keep on trying on draining server request: correctly reset the eos_sent flag runtests: accecpt 'quictls' as OpenSSL compatible rustls: fixed minor logic bug in default cipher selection rustls: rustls-ffi 0.14.0 update rustls: support strong CSRNG data setopt: remove superfluous use of ternary expressions singleuse: drop `Curl_memrchr()` for no-HTTP builds test537: cap the rlimit max this test runs tests: tweak lock file handling and timers tool_cb_wrt: use "curl_response" if no file name in URL transfer: fix sendrecv() without interim poll vtls: fix `Curl_ssl_conn_config_match` doc param @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.16 2024/09/12 19:19:09 adam Exp $ d4 1 a4 1 DISTNAME= curl-8.10.1 @ 1.16 log @curl: updated to 8.10.0 Changes in 8.10.0 autotools: add `--enable-windows-unicode` option curl: --help [option] displays documentation for given cmdline option curl: add --skip-existing curl: for -O, use "default" as filename when the URL has none curl: make --rate accept "number of units" curl: make --show-headers the same as --include curl: support --dump-header % to direct to stderr curl: support embedding a CA bundle and --dump-ca-embed curl: support repeated use of the verbose option; -vv etc curl: use libuv for parallel transfers with --test-event getinfo: add CURLINFO_POSTTRANSFER_TIME_T mbedtls: add CURLOPT_TLS13_CIPHERS support rustls: add support for setting TLS version and ciphers vtls: stop offering alpn http/1.1 for http2-prior-knowledge wolfssl: add CURLOPT_TLS13_CIPHERS support wolfssl: add support for ssl cert blob / ssl key blob options Bugfixes ... @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.15 2024/07/31 08:02:35 adam Exp $ d4 1 a4 1 DISTNAME= curl-8.10.0 a21 2 PYTHON_VERSIONS_INCOMPATIBLE= 27 @ 1.15 log @curl: updated to 8.9.1 Changes in 8.9.1 Bugfixes: cmake: detect `libssh` via `pkg-config` cmake: detect `nettle` when building with GnuTLS cmake: drop `if(PKG_CONFIG_FOUND)` guard for `pkg_check_modules()` configure: limit `__builtin_available` test to Darwin connect: fix connection shutdown for event based processing contrithanks.sh: use -F with -v to match lines as strings curl: more defensive socket code for --ip-tos CURLOPT_SSL_CTX_FUNCTION.md: mention CA caching CURLSHOPT_SHARE.md: mention sessions/cookies as not thread-safe example/multi-uv: remove the use of globals ftpserver.pl: make POP3 LIST serve content from the test file GHA/windows: increase timeout for vcpkg build step lib: survive some NULL input args macos: fix Apple SDK bug workaround for non-macOS targets misc: cleanup after removing years from copyright os400: build cli manual. os400: workaround an IBM ASCII run-time library bug RELEASE-PROCEDURE.md: remove the initial build step runtests: fold timing details with GHA, sync `-r` tflags tests: provide FTP directory contents in the test file tidy-up: URL updates TODO: thread-safe sharing transfer: speed limiting fix for 32bit systems vtls: avoid forward declaration in MultiSSL builds wolfSSL: allow wolfSSL's implementation of kyber to be used wolfssl: avoid calling get_cached_x509_store if store is uncachable wolfssl: CA store share fix x509asn1: unittests and fixes for gtime2str @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.14 2024/07/24 07:28:04 wiz Exp $ d4 1 a4 1 DISTNAME= curl-8.9.1 a38 6 SUBST_CLASSES+= python SUBST_STAGE.python= pre-configure SUBST_MESSAGE.python= Adjust hard-coded python invocations SUBST_FILES.python= tests/data/test1451 SUBST_SED.python= -e 's,python,${PYTHONBIN},g' @ 1.14 log @curl: update to 8.9.0. This release includes the following changes: o curl: add --ip-tos (IP Type of Service / Traffic Class) [42] o curl: add --mptcp [29] o curl: add --vlan-priority [107] o curl: add -w '%{num_retries} [65] o gnutls: support CA caching [90] o mbedtls: support CURLOPT_CERTINFO [116] o noproxy: patterns need to be comma separated [75] o socket: support binding to interface *AND* IP [80] o tcpkeepalive: add CURLOPT_TCP_KEEPCNT and --keepalive-cnt [103] o urlapi: add CURLU_NO_GUESS_SCHEME [72] o wolfssl: support CA caching [73] This release includes the following bugfixes: o (lib)curl.rc: set debug flag also for `CURLDEBUG` and `UNITTESTS` [2] o asyn-thread: avoid using GetAddrInfoExW with impersonation [7] o aws-sigv4: url encode the canonical path [55] o BINDINGS: update java link to one that exists [115] o build: add Debug, TrackMemory, ECH to feature list [218] o build: add more supported attributes to the IAR compiler [46] o build: fix llvm 16 or older + Xcode 15 or newer, and gcc [240] o build: fix llvm 17 and older + macOS SDK 14.4 and newer [230] o build: sync warning options between autotools, cmake & compilers [244] o build: tidy up `__builtin_available` feature checks (Apple) [241] o build: untangle `CURLDEBUG` and `DEBUGBUILD` macros [9] o build: use `#error` instead of invalid syntax [212] o cd2nroff: convert two warnings to errors [135] o cd2nroff: use an empty "##" to signal end of .IP sequence [56] o cf-socket: improve SO_SNDBUF update for Winsock [27] o cf-socket: optimize curlx_nonblock() and check its return error [151] o cf-socket: remove obsolete recvbuf [203] o cf-socket: remove two "useless" assignments [238] o cfilters: make Curl_conn_connect always assign 'done' [60] o cmake: add CURL_USE_GSASL option with detection + CI test [133] o cmake: allow `ENABLE_CURLDEBUG=OFF` with `ENABLE_DEBUG=ON` [26] o cmake: allow SOVERSION override with `CURL_LIBCURL_SOVERSION` [120] o cmake: alpha-sort feature list [161] o cmake: always build unit tests with the `testdeps` target [20] o cmake: bring `curl-config.cmake` closer to `FindCURL` [130] o cmake: create `configurehelp.pm` like autotools does [252] o cmake: delete unused `HAVE_LIBSSH2`, `HAVE_LIBSOCKET` macros [251] o cmake: detect `libidn2` also via `pkg-config` [239] o cmake: enable SOVERSION for Cygwin and `CMAKE_DLL_NAME_WITH_SOVERSION` [119] o cmake: fix `-Wredundant-decls` in unity/mingw-w64 builds [15] o cmake: fix brotli lib order [3] o cmake: fix building `unit1600` due to missing `ssl/openssl.h` [222] o cmake: fix building in unity mode [4] o cmake: fix building with both md4 and md5 in unity mode [13] o cmake: fix builds with detected libidn2 lib but undetected header [221] o cmake: fix feature and protocol lists for SecureTransport [194] o cmake: fix quotes when appending multiple options (SecureTransport) [139] o cmake: fix test 1013 with websockets enabled and no TLS [47] o cmake: improve wolfSSL detection [190] o cmake: show protocols, then features [180] o cmake: stop setting SOVERSION for the static lib target [127] o cmake: sync CA bundle/path detection with autotools [253] o cmake: sync protocol/feature list with `curl -V` output [182] o cmake: use `APPLE` instead of `CMAKE_SYSTEM_NAME` string [24] o cmake: whitespace, formatting/tidy-up in comments [25] o cmdline-docs: "added in" cleanups [171] o cmdline-docs: fix `--proxy-ca-native` example + tidy-ups [181] o cmdline-opts/_PROTOCOLS.md: mention WS(S) [94] o cmdline-opts/ech.md: shorten the help text [93] o cmdline-opts/fail.md: expand and clarify [95] o cmdline-opts/interface.md: expand the documentation [66] o cmdline-opts: category cleanup [196] o cmdline-opts: expand the parallel explanations [98] o cmdline-opts: shorten six help texts [178] o cmdline: expand proxy option explanations [97] o code: language cleanup in comments [186] o configure: CA bundle/path detection fixes [254] o configure: fix `SystemConfiguration` detection [243] o configure: fix pkg-config library name 'libnghttp3' [138] o configure: fix pkg-config names (zstd, ngtcp2*) [170] o configure: limit `SystemConfiguration` test to non-c-ares, IPv6 builds [242] o configure: remove 'deeper' checks for `AC_CHECK_FUNCS` [23] o configure: require a QUIC library if nghttp3 is used [142] o configure: sort feature list, lowercase protocols, use backticks [206] o configure: use `$EGREP` in place of `grep -E` [41] o configure: use AC_MSG_WARN for TLS/experimental warning texts [122] o connect-to.md: expand with examples [147] o connection: shutdown TLS (for FTP) better [104] o cookie-jar.md: see also --junk-session-cookies [144] o curl-config: revert to backticks to support old target envs [88] o curl: allow etag and content-disposition for 3xx reply [117] o curl: bsearch the --write-out variable name [102] o curl: check for --disable case *sensitively* [199] o curl: list categories in --help [219] o curl: make warnings and other messages aware of terminal width [58] o curl: output "flying saucers" with leading carriage return [121] o curl_easy_escape: elaborate a little on encoding a URL [193] o curl_mprintf.md: add missing comma o curl_multi_poll.md: expand the example with an custom file descriptor [21] o curl_str[n]equal.md: tidy up text to make them stand-alone [195] o curl_url_set.md: libcurl only parses :// URLs [48] o curl_url_set: elaborate on scheme guessing [191] o curldown: make 'added-in:' a mandatory header field [226] o CURLOPT_CONNECTTIMEOUT*: clarify, document the milliseond version [105] o CURLOPT_ECH.md: remove repeated 'if' [109] o CURLOPT_NETRC.md: clarify what it does on Windows [140] o CURLOPT_RESOLVE.md: mention hostname can be wildcard ('*') [150] o CURLOPT_SSL_VERIFYHOST.md: refresh [224] o CURLOPT_TLSAUTH_PASSWORD/USERNAME.md: language fixups [155] o DISTROS: add a link to the list archive [22] o DISTROS: add AlmaLinux package source link o DISTROS: add MSYS2 (native) links [100] o docs/cmdline-opts: fix mail-auth example TLD typo [35] o docs/cmdline-opts: remove two superfluous "Added in" mentions [143] o docs/libcurl: polish the single-line descriptions [159] o docs/Makefile.am: make curl-config.1 install [14] o docs: reference non deprecated libcurl options [113] o docs: start markdown headers with capital letter where applicable [236] o doh-insecure.md: expand [96] o doh: fix cleanup [228] o doh: fix leak and zero-length HTTPS RR crash [227] o dump-header.md: mention minus for stdout [149] o examples/threaded-ssl: remove locking callback code [83] o examples: add missing binaries to .gitignore [106] o examples: delete unused includes [10] o examples: fix compiling with MSVC [34] o examples: suppress deprecation warnings locally [211] o FEATURES.md: refresh [208] o file: separate fake headers and body with a stand-alone CRLF [137] o ftp: remove redundant null pointer check in loop condition [256] o get.d: clarify the explanation [32] o GHA/windows: add MSVC wolfSSL job with test [250] o GHA/windows: ignore FTP test results for old-mingw-w64 o GHA: add MSVC UWP job, expand jobs with more options [216] o GHA: detect and warn for more English contractions [123] o GHA: disable MQTT and WebSocket tests in Windows jobs [63] o GHA: disable TFTP tests in Windows jobs o GHA: enable tests 1139, 1177, 1477 on Windows [59] o GHA: improve vcpkg cache, add BoringSSL ECH and LibreSSL MSVC jobs [215] o GHA: unify http3 workflows into one [77] o GHA: use vcpkg to install packages for MSVC jobs [145] o GIT-INFO.md: remove version requirements [209] o gnutls: improve TLS shutdown [62] o gnutls: pass in SNI name, not hostname when checking cert [114] o help: add flags to output and ssh categories [202] o hostip: skip error check for infallible function call [237] o http/3: add shutdown support [154] o http/3: resume upload on ack if we have more data to send [232] o http: remove "struct HTTP" [134] o http: write last header line late [44] o idn: fix ß with AppleIDN [220] o idn: make macidn fail before trying conversion if name too long [235] o idn: tweak buffer use when converting with macidn [245] o lib/v*: tidy up types and casts [64] o lib: add a few DEBUGASSERT(data) to aid code analyzers [187] o lib: add failure reason on bind errors [247] o lib: fix gcc warning in certain debug builds [19] o lib: fix thread entry point to return `DWORD` on WinCE [85] o lib: graceful connection shutdown [162] o lib: prefer `var = time(NULL)` over `time(&var)` [52] o lib: tidy up types and casts [92] o lib: xfer_setup and non-blocking shutdown [111] o libcurl-docs: make option lists alpha-sorted [214] o libcurl-easy.md: now *more* than 300 options [233] o libcurl.pc: add `Requires.private`, `Requires` for static linking [129] o libcurl.pc: add more `Requires.private`/`Requires` dependencies [189] o libssh: remove CURLOPT_SSL_VERIFYHOST check [36] o macos: add workaround for gcc, non-c-ares, IPv6, compile error [213] o macos: undo `availability` macro enabled by Homebrew gcc [231] o managen: "added in" fixes [131] o managen: cleanups to generate nicer-looking output [141] o managen: error on trailing blank lines in input files [165] o managen: fix removing backticks from subtitles [179] o managen: insert final .fi for files ending with a quote [174] o managen: introduce "Multi: per-URL" [176] o managen: only output .RE for manpage output [156] o managen: output tabs for each 8 leading spaces [164] o managen: warn on excessively long help texts [87] o MANUAL.md: wrap two example urls that overrun styling [234] o mbedtls: check version before getting tls version [261] o mbedtls: check version for cipher id [12] o mbedtls: correct the error message for cert blob parsing failure [225] o mbedtls: send close-notify on close [11] o mbedtls: v3.6.0 workarounds [89] o md4: fix compilation with OpenSSL 1.x with md4 disabled [255] o misc: fix typos [108] o mk-ca-bundle.pl: delay 'curl -V' execution until it is needed [168] o multi: add multi->proto_hash, a key-value store for protocol data [37] o multi: do a final progress update on connect failure [248] o multi: fix multi_wait() timeout handling [51] o multi: fix pollset during RESOLVING phase [166] o multi: multi_getsock(), check correct socket [167] o ngtcp2+quictls: fix cert-status use [173] o noproxy: test bad ipv6 net size first [82] o openssl/gnutls: rectify the TLS version checks for QUIC [61] o openssl: fix %-specifier in infof() call [57] o openssl: fix hostname handling when using ECH [78] o openssl: stop duplicate ssl key logging for legacy OpenSSL [49] o os400: make it compilable again [128] o pytest: add ftp upload tests [16] o pytest: include testenv/vsftpd.py in dist tarball [99] o quic: enable UDP GRO [157] o quic: openssl quic, cmake and doc version update to 3.3.0 [148] o quic: require at least OpenSSL 3.3 for QUIC [158] o quic: update to quiche 0.22.0 [175] o quiche: fix operand of ‘?:’ changes signedness [177] o request.md: language fix [70] o request: change the struct field bodywrites to a bool, only for hyper [132] o reuse: switch to REUSE 3.2 and REUSE.toml [184] o runtests: show name and keywords for failed tests in summary [249] o runtests: sort test IDs in summary lines [33] o runtests: support %DATE for YYYY-MM-DD of right now o runtests: support %VERNUM o runtests: support crlf="yes" for the section o sectransp: fix `HAVE_BUILTIN_AVAILABLE` checks to not emit warnings [210] o sectransp: fix clang compiler warnings, stop silencing them [223] o sectransp: remove large cipher table [76] o sectransp: use common code for cipher suite lookup [54] o sendf: fix CRLF conversion of input [258] o smtp: for starttls, do full upgrade [260] o socket: change TCP keepalive from ms to seconds on DragonFly BSD [74] o socket: use SOCK_NONBLOCK to eliminate extra system call [86] o socketpair: add `eventfd` and use `SOCK_NONBLOCK` for `socketpair()` [81] o src/Makefile.am: remove SUBDIRS assignment [172] o system_win32: add missing curl.h include [160] o tcpkeepalive: support TCP keep-alive parameters on Solaris <11.4 [91] o test1119: adapt for `.md` input [204] o test1139: scan .md files instead of .3 ones [197] o test1175: scan libcurl-errors.md, not the generated .3 version [188] o test1486: verify that write-out.md and tool_writeout.c are in sync [112] o test2600: disable on win32 [259] o test: add test1484, for HEAD with content [18] o test: add test1546, chunked not last transfer encoding [17] o tests/scripts: call it 'manpage' (single word) [229] o tests: add pytest for --ciphers and --tls13-ciphers options [38] o tests: delete `CharConv` remains [201] o tests: delete redundant `!MSDOS` guard [84] o tests: extend user/password parsing test1620 [40] o tests: fix sshd IdentityFile path for MinGW/Cygwin [217] o tests: fix sshd UserKnownHostsFile path for MinGW/Cygwin o tests: include current directory when running test Perl commands [205] o tests: log "Throwing away" messages before throwing away o tests: run with "--trace-config all" to provide even more info [6] o tests: sync feature names with `curl -V` [257] o tests: test_17_ssl_use.py clarify mbedTLS TLSv1.3 support [43] o tests: use exec when spawning nghttpx [45] o tidy-up: use consistent casing for Windows directories [28] o TODO: remove some old, clarify, add something [31] o tool_cb_hdr: return error for failed header writes [30] o tool_operate: avoid explicitly setting verifypeer to 1 [39] o tool_operate: simplify return code handling from url_proto() [198] o tool_writeout: get certinfo only when needing it [101] o trace-ascii.md: mention "%" for stderr [146] o transfer: avoid polling socket every transfer loop [200] o transfer: conn close on paused upload [8] o transfer: do not use EXPIRE_NOW while blocked [124] o transfer: remove curl_upload_refill_watermark, no longer used [50] o transfer: set CSELECT_IN if there is data pending [118] o unit2604: use 'unitfail' instead of 'error' variable [153] o url: allow DoH transfers to override max connection limit [68] o urlapi: remove unused definition of HOST_BAD [262] o variable.md: make example use expand [207] o verify-synopsis.pl: work with .md files [185] o vms: fixed language in comment [110] o vtls: deprioritize Secure Transport [71] o vtls: replace addsessionid with set_sessionid [183] o winbuild: fix PE version info debug flag [1] o winbuild: MS-DOS batch tidy-ups [163] o winbuild: remove outdated WIN32 defines [5] o windows: fix UWP builds, add GHA job [79] o winsock: move SO_SNDBUF update into cf-socket [53] o wolfssl: assume key_file equal to clientcert if no key_file [169] o wolfssl: use larger error buffer when formatting errors [246] o x509asn1: add some common ECDSA OIDs [67] o x509asn1: ASN1tostr() should fail when 'constructed' is set [125] o x509asn1: fallback to dotted OID representation [69] o x509asn1: make Curl_extract_certinfo store error message [136] o x509asn1: prevent NULL dereference [152] o x509asn1: remove superfluous free() o x509asn1: remove two static variables [126] @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.13 2024/05/23 04:15:35 adam Exp $ d4 1 a4 1 DISTNAME= curl-8.9.0 @ 1.13 log @curl libcurl-gnutls: updated to 8.8.0 8.8.0 Changes: curl_version_info: provide librtmp version file: add support for directory listings idn: add native AppleIDN (icucore) support for macOS/iOS lib: add curl_multi_waitfds mbedTLS: implement CURLOPT_SSL_CIPHER_LIST option NTLM_WB: drop support TLS: add support for ECH (Encrypted Client Hello) urlapi: add CURLU_GET_EMPTY for empty queries and fragments Bugfixes: appveyor: drop unnecessary `--clean-first` cmake option appveyor: guard against crash-build with VS2008 appveyor: make gcc 6 mingw64 job build-only asyn-thread: fix curl_global_cleanup crash in Windows asyn-thread: fix Curl_thread_create result check autotools: delete unused functions autotools: fix `HAVE_IOCTLSOCKET_FIONBIO` test for gcc 14 autotools: only probe for SGI MIPS compilers on IRIX bearssl: fix compiler warnings bearssl: use common code for cipher suite lookup bufq: remove duplicate word in comment BUG-BOUNTY.md: clarify the third party situation build: prefer `USE_IPV6` macro internally (was: `ENABLE_IPV6`) build: remove MacOSX-Framework script cd2nroff/manage: use UTC when SOURCE_DATE_EPOCH is set cf-https-connect: use timeouts as unsigned ints cf-socket: don't try getting local IP without socket cf-socket: remove references to l_ip, l_port ci: add curl-for-win builds: Linux MUSL, macOS, Windows cmake: add `BUILD_EXAMPLES` option to build examples cmake: add librtmp/rtmpdump option and detection cmake: check fseeko after detecting HAVE_FILE_OFFSET_BITS cmake: do not pass linker flags to the static library tool cmake: enable `-pedantic-errors` for clang when `CURL_WERROR=ON` cmake: FindNGHTTP2 add static lib name to find_library call cmake: fix `CURL_WERROR=ON` for old CMake and use it in GHA/linux-old cmake: fix `HAVE_IOCTLSOCKET_FIONBIO` test with gcc 14 cmake: fixup `DEPENDS` filename cmake: forward `USE_LIBRTMP` option to C cmake: generate misc manpages and install `mk-ca-bundle.pl` cmake: initialize `BUILD_TESTING` before first use cmake: speed up libcurl doc building again cmake: tidy-up to use `WORKING_DIRECTORY` cmake: use namespaced custom target names cmdline-docs: fix make install with configure --disable-docs configure: error on missing perl if docs or manual is enabled configure: make --disable-docs imply --disable-manual content_encoding: brotli and others, pass through 0-length writes content_encoding: ignore duplicate chunked encoding content_encoding: reject transfer-encoding after chunked contrithanks: honor `CURLWWW` variable curl-confopts.m4: define CARES_NO_DEPRECATED when c-ares is used curl.h: change CURL_SSLVERSION_* from enum to defines curl: make --help adapt to the terminal width curl: use curl_getenv instead of the curlx_ version Curl_creader_read: init two variables to avoid using them uninited curl_easy_pause.md: use correct defines in example curl_getdate.md: document two-digit year handling curl_global_trace.md: shorten the description curl_multibyte: remove access() function wrapper for Windows curl_path: make Curl_get_pathname use dynbuf curl_setup.h: add support for IAR compiler curl_setup.h: detect 'inline' support curl_sha512_256: do not use workaround for NetBSD when not needed curl_sha512_256: fix detection of OpenSSL 1.1.1 or later curl_url_get.md: clarify queries and fragments and CURLU_GET_EMPTY CURLINFO_REQUEST_SIZE: fixed, add tests for transfer infos reported CURLOPT_WRITEFUNCTION.md: fix the callback proto in the example cw-out: improved error handling DEPRECATE.md: TLS libraries without 1.3 support digest: replace strcpy for empty string with simple assignment dist: `set -eu`, fix shellcheck, make reproducible and smaller tarballs dist: add files missing from release tarball dist: add reproducible dir entries to tarballs dist: do not require Perl in `maketgz` dist: remove the curl-config.1 from the tarball dist: verify tarball reproducibility in CI DISTROS: add patch and issues link for curl-for-win DISTROS: Cygwin updates dllmain: Call OpenSSL thread cleanup for Windows and Cygwin doc: pytest `--repeat` -> `--count` docs/cmdline-opts: invoke managen using a relative path docs/cmdline-opts: mention STARTTLS for --ssl and --ssl-reqd docs: add CURLOPT_NOPROGRESS to CURLOPT_XFERINFOFUNCTION example docs: clarify CURLOPT_MAXFILESIZE and CURLOPT_MAXFILESIZE_LARGE docs: fix some CURLINFO examples doh: fix typo in comment doh: remove unused function prototype dynbuf: fix returncode on memory error examples: fix/silence `-Wsign-conversion` EXPERIMENTAL: add graduation requirements for each feature file: remove useless assignment ftp: add tracing support ftp: fix build for CURL_DISABLE_VERBOSE_STRINGS ftp: fix socket leak on rare error GHA: add NetBSD, OpenBSD, FreeBSD/arm64 and OmniOS jobs GHA: add shellcheck job and fix warnings, shell tidy-ups GHA: add valgrind to a wolfSSL build GHA: on macOS remove $HOME/.curlrc GHA: pin dependencies gnutls: lazy init the trust settings h3/ngtcp2: improve error handling hash: change 'slots' to size_t from int hash: delete unused debug function hsts: explicitly skip blank lines hsts: remove single-use single-line function http tests: in CI skip test_02_23* for quiche http2 + ngtcp2: pass CURLcode errors from callbacks http2, http3: decouple stream state from easy handle http2: emit RST when client write fails http3: quiche+ngtcp2 improvements http: acknowledge a returned error code http: HEAD response body tolerance http: reject HTTP major version switch mid connection http: remove redundant check http: with chunked POST forced, disable length check on read callback http_aws_sigv4: remove useless assignment idn: make Curl_idnconvert_hostname() use Curl_idn_decode() if2ip: make the buf_size arg a size_t INSTALL-CMAKE.md: explain `cmake -G ` krb5: use dynbuf ldap: fix unused variables (seen on OmniOS) lib/cf-h1-proxy: silence compiler warnings (gcc 14) lib: add trace support for client reads and writes lib: bump hash sizes to `size_t` lib: clear the easy handle's saved errno before transfer lib: fix compiler warnings (gcc) lib: make protocol handlers store scheme name lowercase lib: merge `ENABLE_QUIC` C macro into `USE_HTTP3` lib: remove two instances of "only only" messages lib: silence `-Wsign-conversion` in base64, strcase, mprintf lib: silence warnings on comma misuse lib: use `#error` instead of invalid syntax in `curl_setup_once.h` lib: use multi instead of multi_easy for the active multi libcurl-opts: mention pipelining less libssh2: delete redundant feature guard libssh2: replace `access()` with `stat()` libssh2: set length to 0 if strdup failed m4: fix rustls pkg-config codepath MAIL-ETIQUETTE: convert to markdown makefile: remove the sorting from the vc-ide action maketgz: put docs/RELEASE-TOOL.md into the tarball managen: fix the option sort order mbedtls: call mbedtls_ssl_setup() after RNG callback is set mbedtls: cut off trailing newlines from debug logs mbedtls: fix building with v3 in CMake Unity mode mbedtls: support TLS 1.3 mime: avoid using access() misc: fix typos misc: fix typos, quoting and spelling mprintf: check fputc error rather than matching returned character mqtt: when Curl_xfer_recv returns error, don't use nread multi: avoid memory-leak risk multi: introduce SETUP state for better timeouts multi: multi_wait improvements multi: remove the unused Curl_preconnect function multi: remove useless assignment multi: timeout handles even without connection openldap: create ldap URLs correctly for IPv6 addresses openssl: do not set SSL_MODE_RELEASE_BUFFERS openssl: revert keylog_callback support for LibreSSL OS400: fix shellcheck warnings in scripts projects: drop MSVC project files for recent versions pytest: add DELETE tests, check server version pytest: fixes for recent python, add FTP tests quic: fixup duplicate static function name (for cmake unity) quiche: expire all active transfers on connection close quiche: trust its timeout handling RELEASE-PROCEDURE: mention an initial working build request: make Curl_req_init return void request: paused upload on completed download, assess connection reuse: add copyright + license info to individual docs/*.md files ROADMAP: remove completed entries, mention websocket rustls: fix handshake done handling rustls: fix partial send handling rustls: remove incorrect SSLSUPP_TLS13_CIPHERSUITES flag rustsls: fix error code on receive sendf: fix two typos in comments sendf: useless assignment in cr_lc_read() setopt: acknowledge errors proper for CURLOPT_COOKIEJAR setopt: make the setstropt_userpwd args compulsory setopt: remove check for 'option' that is always true setopt: warn on Curl_set*opt() uses not using the return value smtp: result of Curl_bufq_cread was not used socket: remove redundant call to getsockname socketpair: fix compilation when USE_UNIX_SOCKETS is not defined src: tidy up types, add necessary casts telnet: check return code from fileno() tests/http: fix compiler warning tests: add -q as first option when invoking curl for tests tests: check caddy server version to match test expectations tests: enable test 1117 for hyper tests: fix feature case in test1481 tests: fix test 1167 to skip digit-only symbols tests: make the unit test result type `CURLcode` tests: Mark tftpd timer function as noreturn tests: tidy up types in server code tls: fix SecureTransport + BearSSL cmake unity builds tls: remove EXAMPLEs from deprecated options tls: use shared init code for TCP+QUIC tool: move tool_ftruncate64 to tool_util.c tool_cb_rea: limit rate unpause for -T . uploads tool_cfgable: free {proxy_}cipher13_list on exit tool_getparam: output warning for leading unicode quote character tool_getparam: remove two redundant conditions tool_operate: don't truncate the etag save file by default tool_operate: init vars unconditionally in post_per_transfer tool_paramhlp: remove duplicate assign tool_xattr: "guess" URL scheme if none is provided tool_xattr: in debug builds, act normally if CURL_FAKE_XATTR is not set transfer: remove useless assignment url: do not URL decode proxy crendentials url: fix use of an uninitialized variable url: make parse_login_details use memdup0 url: remove duplicate call to Curl_conncache_remove_conn when pruning urlapi: allow setting port number zero urlapi: fix relative redirects to fragment-only urldata: remove fields not used depending on used features vauth: make two functions void that always just returned OK version: use msnprintf instead of strncpy vquic-tls: use correct cert name check API for wolfSSL vquic: use CURL_FORMAT_CURL_OFF_T for 64 bit printf output vtls: TLS session storage overhaul wakeup_create: use FD_CLOEXEC/SOCK_CLOEXEC warnless: delete orphan declarations websocket: avoid memory leak in error path winbuild: add ENABLE_WEBSOCKETS option winbuild: use $(RC) correctly wolfssl: plug memory leak in wolfssl_connect_step2() x509asn1: return error on missing OID @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.12 2024/03/27 13:53:35 wiz Exp $ d4 1 a4 1 DISTNAME= curl-8.8.0 @ 1.12 log @curl: update to 8.7.1. Security fix release. Fixed in 8.7.1 - March 27 2024 8.7.1 Bugfixes: Fixed empty tool_hugehelp.c file Fixed in 8.7.0 - March 27 2024 Changes: configure: add --disable-docs flag CURLINFO_USED_PROXY: return bool whether the proxy was used digest: support SHA-512/256 DoH: add trace configuration write-out: add '%{proxy_used}' Bugfixes: ALTSVC.md: correct a typo asyn-ares: fix data race warning asyn-thread: use wakeup_close to close the read descriptor badwords: use hostname, not host name BINDINGS: add mcurl, the python binding bufq: writing into a softlimit queue cannot be partial c-hyper: add header collection writer in hyper builds cd2nroff: gen: make `\>` in input to render as plain '>' in output cd2nroff: remove backticks from titles checksrc.pl: fix handling .checksrc with CRLF cmake: add USE_OPENSSL_QUIC support cmake: add warning for using TLS libraries without 1.3 support cmake: enable `ENABLE_CURL_MANUAL` by default cmake: fix `CURL_WINDOWS_SSPI=ON` with Schannel disabled cmake: fix function description in comment cmake: fix install for older CMake versions cmake: fix libcurl.pc and curl-config library specifications cmdline-docs/Makefile: avoid using a fixed temp file name cmdline-docs: quote and angle bracket cleanup cmdline-opts/_EXITCODES: sync with libcurl-errors cmdline-opts/_VARIABLES.md: improve the description cmdline-opts/_VERSION: provide %VERSION correctly cmdline-opts: shorter help texts configure: add pkg-config support to rustls detection configure: add warning for using TLS libraries without 1.3 support configure: build & install shell completions when enabled configure: do not link with nghttp3 unless necessary configure: Don't build shell completions when disabled configure: Don't make shell completions without perl configure: find libpsl with pkg-config connect.c: fix typo CONTRIBUTE: update the section on documentation format cookie.md: provide an example sending a fixed cookie cookie: if psl fails, reject the cookie curl: exit on config file parser errors curl: make --libcurl output better CURLOPT_*SSLVERSION curl: when allocating variables, add the name into the struct curl_setup.h: add curl_uint64_t internal type curldown: fix email address in Copyright CURLMOPT_MAX*: mention what happens if changed mid-transfer CURLOPT_INTERFACE.md: remove spurious amp, add see-also CURLOPT_POSTQUOTE.md: fix typo CURLOPT_SSL_CTX_FUNCTION.md: no promises of lifetime after return CURLOPT_WRITEFUNCTION.md: typo fix digest: add check for hashing error dist: make sure the http tests are in the tarball DISTROS: add document with distro pointers docs/libcurl: add TLS backend info for all TLS options docs/libcurl: generate PROTOCOLS from meta-data docs: add missing slashes to SChannel client certificate documentation docs: add necessary setup for nghttp3 docs: ascii version of manpage without nroff docs: dist curl*.1 and install without perl docs: make curldown do angle brackets like markdown docs: make each libcurl man specify protocol(s) docs: make sure curl.1 is included in dist tarballs docs: update minimal binary size in INSTALL.md docs: use present tense examples: use present tense in comments file: use xfer buf for file:// transfers fopen: fix narrowing conversion warning on 32-bit Android form-string.md: correct the example ftp: do lineend conversions in client writer ftp: fix socket wait activity in ftp_domore_getsock ftp: tracing improvements ftp: treat a 226 arriving before data as a signal to read data gen.pl: make the "manpageification" faster gen: make `\>` in input to render as plain '>' in output getparam: make --ftp-ssl work again GHA/linux: add sysctl trick to work-around GitHub runner issue GIT-INFO: convert to markdown GOVERNANCE: document the core team header.md: remove backslash, make nicer markdown HTTP/2: write response directly http2, http3: return CURLE_PARTIAL_FILE when bytes were received http2: fix push discard http2: memory errors in the push callbacks are fatal http2: minor tweaks to optimize two struct sizes http2: push headers better cleanup http2: remove the third (unused) argument from http2_data_done() HTTP3.md: adjust the OpenSSL QUIC install instructions http: better error message for HTTP/1.x response without status line http: improve response header handling, save cpu cycles http: move headers collecting to writer http: remove stale comment about rewindbeforesend http: separate response parsing from response action http_chunks: fix the accounting of consumed bytes http_chunks: remove unused 'endptr' variable https-proxy: use IP address and cert with ip in alt names hyper: implement unpausing via client reader ipv6.md: mention IPv4 mapped addresses KNOWN_BUGS: POP3 issue when reading small chunks lib1598: fix `CURLOPT_POSTFIELDSIZE` usage lib582: remove code causing warning that is never run lib: add `void *ctx` to reader/writer instances lib: convert Curl_get_line to use dynbuf lib: Curl_read/Curl_write clarifications lib: enhance client reader resume + rewind lib: initialize output pointers to NULL before calling strto[ff,l,ul] lib: keep conn IP information together lib: move 'done' parameter to SingleRequests lib: remove curl_mimepart object when CURL_DISABLE_MIME libcurl-docs: cleanups libcurl-security.md: Active FTP passes on the local IP address libssh/libssh2: return error on too big range MANUAL.md: fix typo mbedtls: fix building when MBEDTLS_X509_REMOVE_INFO flag is defined mbedtls: fix pytest for newer versions mbedtls: properly cleanup the thread-shared entropy mbedtls: use mbedtls_ssl_conf_{min|max}_tls_version md4: include strdup.h for the memdup proto mime: add client reader misc: fix typos in docs and lib mkhelp: simplify the generated hugehelp program mprintf: fix format prefix I32/I64 for windows compilers multi: add xfer_buf to multi handle multi: fix multi_sock handling of select_bits multi: make add_handle free any multi_easy ngtcp2: no recvbuf for stream ntml_wb: fix buffer type typo OpenSSL QUIC: adapt to v3.3.x openssl-quic: check on Windows that socket conv to int is possible openssl-quic: fix BIO leak and Windows warning openssl-quic: fix unity build, casing, indentation OS400: avoid using awk in the build scripts paramhlp: fix CRLF-stripping files with "-d @@file" proxy1.0.md: fix example pytest: adapt to API change request: clarify message when request has been sent off rustls: make curl compile with 0.12.0 schannel: fix hang on unexpected server close scripts: fix cijobs.pl for Azure and GHA sendf: ignore response body to HEAD setopt: fix check for CURLOPT_PROXY_TLSAUTH_TYPE value setopt: fix disabling all protocols sha512_256: add support for GnuTLS and OpenSSL smtp: fix STARTTLS SPONSORS: describe the basics strtoofft: fix the overflow check test 1541: verify getinfo values on first header callback test1165: improve pattern matching tests: support setting/using blank content env variables TIMER_STARTTRANSFER: set the same for everyone TLS: start shutdown only when peer did not already close TODO: update 13.11 with more information tool_cb_hdr: only parse etag + content-disposition for 2xx tool_getparam: accept a blank -w "" tool_getparam: handle non-existing (out of range) short-options tool_operate: change precedence of server Retry-After time tool_operate: do not set CURLOPT_QUICK_EXIT in debug builds trace-config.md: remove the mutexed options list transfer.c: break receive loop in speed limited transfers transfer: improve Windows SO_SNDBUF update limit urldata: move authneg bit from conn to Curl_easy version: allow building with ancient libpsl vquic-tls: fix the error code returned for bad CA file vtls: fix tls proxy peer verification vtls: revert "receive max buffer" + add test case VULN-DISCLOSURE-POLICY.md: update detail about CVE requests websocket: fix curl_ws_recv() wolfSSL: do not call the stub function wolfSSL_BIO_set_init() write-out.md: clarify error handling details @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.11 2024/01/31 07:21:08 wiz Exp $ d4 1 a4 1 DISTNAME= curl-8.7.1 d15 3 @ 1.11 log @*curl*: update to 8.6.0 This release includes the following changes: o add CURLE_TOO_LARGE [48] o add CURLINFO_QUEUE_TIME_T [76] o add CURLOPT_SERVER_RESPONSE_TIMEOUT_MS: add [39] o asyn-thread: use GetAddrInfoExW on >= Windows 8 [55] o configure: make libpsl detection failure cause error [109] o docs/cmdline: change to .md for cmdline docs [77] o docs: introduce "curldown" for libcurl man page format [102] o runtests: support -gl. Like -g but for lldb. [47] This release includes the following bugfixes: o altsvc: free 'as' when returning error [23] o appveyor: replace PowerShell with bash + parallel autotools [54] o appveyor: switch to out-of-tree builds [29] o asyn-ares: with modern c-ares, use its default timeout [127] o build: delete unused `HAVE_{GSSHEIMDAL,GSSMIT,HEIMDAL}` [4] o build: delete/replace clang warning pragmas [111] o build: enable missing OpenSSF-recommended warnings, with fixes [11] o build: fix `-Wconversion`/`-Wsign-conversion` warnings [26] o build: fix Windows ADDRESS_FAMILY detection [35] o build: more `-Wformat` fixes [40] o build: remove redundant `CURL_PULL_*` settings [8] o cf-h1-proxy: no CURLOPT_USERAGENT in CONNECT with hyper [133] o cf-socket: show errno in tcpkeepalive error messages [120] o CI/distcheck: run full tests [31] o cmake: add option to disable building docs o cmake: fix generation for system name iOS [53] o cmake: fix typo [5] o cmake: freshen up docs/INSTALL.cmake [101] o cmake: prefill/cache `HAVE_STRUCT_SOCKADDR_STORAGE` [45] o cmake: rework options to enable curl and libcurl docs [161] o cmake: when USE_MANUAL=YES, build the curl.1 man page [113] o cmdline-opts/write-out.d: remove spurious double quotes o cmdline-opts: update availability for the *-ca-native options [66] o cmdline/gen: fix the sorting of the man page options [33] o configure: add libngtcp2_crypto_boringssl detection [155] o configure: fix no default int compile error in ipv6 detection [69] o configure: when enabling QUIC, check that TLS supports QUIC [87] o connect: remove margin from eyeballer alloc [79] o content_encoding: change return code to typedef'ed enum [94] o cookie.d: document use of empty string to enable cookie engine [106] o cookie: avoid fopen with empty file name [24] o curl.h: CURLOPT_DNS_SERVERS is only available with c-ares [131] o curl: show ipfs and ipns as supported "protocols" [15] o curl_easy_getinfo.3: remove the wrong time value count [116] o curl_multi_fdset.3: remove mention of null pointer support [134] o CURLINFO_REFERER.3: clarify that it is the *request* header [70] o CURLOPT_AUTOREFERER.3: mention CURLINFO_REFERER o CURLOPT_POSTFIELDS.3: fix incorrect C string escape in example [27] o CURLOPT_SSH_*_KEYFILE: clarify [57] o dist: add tests/errorcodes.pl to the tarball [6] o docs: clean up Protocols: for cmdline options [32] o docs: describe and highlight super cookies [80] o docs: do not start lines/sentences with So, But nor And [140] o docs: install curl.1 with cmake [166] o docs: mention env vars not used by schannel [124] o doh: remove unused local variable [34] o examples: add four new examples [99] o file+ftp: use stack buffers instead of data->state.buffer [138] o ftp: handle the PORT parsing without allocation [44] o ftp: use dynbuf to store entrypath [83] o ftp: use memdup0 to store the OS from a SYST 215 response [82] o ftpserver.pl: send 213 SIZE response without spurious newline o gen.pl: support ## for doing .IP in table-like lists [105] o gen: do italics/bold for a range of letters, not just single word [78] o GHA: add a job scanning for "bad words" in markdown [164] o GHA: bump ngtcp2, gnutls, mod_h2, quiche [158] o gnutls: fix build with --disable-verbose [3] o haproxy-clientip.d: document the arg [68] o headers: make sure the trailing newline is not stored [97] o headers: remove assert from Curl_headers_push [115] o hostip: return error immediately when Curl_ip2addr() fails [19] o hsts: remove assert for zero length domain [96] o http2: improved on_stream_close/data_done handling [49] o http3/quiche: fix result code on a stream reset [91] o http3: initial support for OpenSSL 3.2 QUIC stack [110] o http: adjust_pollset fix [85] o http: check for "Host:" case insensitively [154] o http: fix off-by-one error in request method length check [14] o http: only act on 101 responses when they are HTTP/1.1 [98] o http: remove comment reference to a removed solution [156] o http: use stack scratch buffer [150] o http_proxy: a blank CURLOPT_USERAGENT should not be used in CONNECT [90] o krb5: add prototype to silence clang warnings on mvsnprintf() [119] o lib: add debug log outputs for CURLE_BAD_FUNCTION_ARGUMENT [62] o lib: error out on multissl + http3 [13] o lib: fix variable undeclared error caused by `infof` changes [2] o lib: reduce use of strncpy [30] o lib: rename Curl_strndup to Curl_memdup0 to avoid misunderstanding [36] o lib: replace readwrite with write_resp [137] o lib: strndup/memdup instead of malloc, memcpy and null-terminate [42] o libssh2: use `libssh2_session_callback_set2()` with v1.11.1 [103] o libssh: improve the deprecation warning dismissal [20] o libssh: supress warnings without version check [18] o Makefile.am: fix the MSVC project generation [22] o Makefile.mk: drop Windows support [12] o mbedtls: fix `-Wnull-dereference` and `-Wredundant-decls` [117] o mbedtls: free the entropy when threaded [46] o mime: use memdup0 instead of malloc + memcpy [63] o mksymbolsmanpage.pl: provide references to where the symbol is used o mprintf: overhaul and bugfixes [52] o mqtt: use stack scratch buffer for recv+publish [148] o multi: remove total timer reset in file_do() while fetching file:// [89] o ngtcp2: put h3 at the front of alpn [58] o ntlm_wb: do not use data->state.buffer any longer [151] o openldap: fix an LDAP crash [75] o openldap: fix STARTTLS [67] o openssl: re-match LibreSSL deinit with init [17] o openssl: when verifystatus fails, remove session id from cache [100] o OS400: sync ILE/RPG binding [114] o pingpong: stop using the download buffer [159] o pop3: replace calloc + memcpy with memdup0 [60] o pytest: scorecard tracking CPU and RSS [157] o quiche: return CURLE_HTTP3 on send to invalid stream [65] o readwrite_data: loop less [21] o Revert "urldata: move async resolver state from easy handle to connectdata" [16] o rtsp: deal with borked server responses [129] o runtests: for mode="text" on , fix newlines on both parts [64] o sasl: make login option string override http auth [142] o schannel: fix `-Warith-conversion` gcc 13 warning [28] o sectransp: do verify_cert without memdup for blobs [93] o sectransp_ make TLSCipherNameForNumber() available in non-verbose config [1] o sendf: fix compiler warning with CURL_DISABLE_HEADERS_API [38] o setopt: clear mimepost when formp is freed [92] o setopt: use memdup0 when cloning COPYPOSTFIELDS [107] o socks: fix generic output string to say SOCKS instead of SOCKS4 [144] o socks: use own buffer instead of data->state.buffer [143] o ssh: fix namespace of two local macros [51] o ssh: use stack scratch buffer for seeks [146] o strerror: repair get_winsock_error() [56] o system.h: sync mingw `CURL_TYPEOF_CURL_SOCKLEN_T` with other compilers [9] o system_win32: fix a function pointer assignment warning [71] o telnet: use dynbuf instad of malloc for escape buffer [108] o telnet: use stack scratch buffer for do [149] o tests/server: delete workaround for old-mingw [25] o tests: avoid int/size_t conversion size/sign warnings [163] o tests: respect $TMPDIR when creating unix domain sockets [50] o tool: make parser reject blank arguments if not supported [86] o tool: prepend output_dir in header callback [95] o tool_getparam: bsearch cmdline options [74] o tool_getparam: do not try to expand without an argument [59] o tool_getparam: stop supporting `@@filename` style for --cookie [121] o tool_listhelp: regenerate after recent .d updates [61] o tool_operate: make --remove-on-error only remove "real" files [125] o tool_operate: stop setting the file comment on Amiga [128] o transfer: adjust_pollset improvements [81] o transfer: fix upload rate limiting, add test cases [37] o transfer: make the select_bits_paused condition check both directions [104] o transfer: remove warning: Value stored to 'blen' is never read [136] o url: don't set default CA paths for Secure Transport backend [126] o url: for disabled protocols, mention if found in redirect [7] o urlapi: remove assert [162] o verify-examples.pl: fail verification on unescaped backslash [72] o version: show only the libpsl version, not its dependencies [130] o vquic: extract TLS setup into own source [88] o vtls: fix missing multissl version info [73] o vtls: receive max buffer [139] o vtls: remove the Curl_cft_ssl_proxy object if CURL_DISABLE_PROXY [41] o websockets: check for negative payload lengths [123] o websockets: refactor decode chain [122] o windows: delete redundant headers [43] o windows: simplify detecting and using system headers [10] o wolfssl: load certificate *chain* for PEM client certs [84] o x509asn1: remove code for WANT_VERIFYHOST [132] o x509asn1: switch from malloc to dynbuf [112] @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.10 2023/12/07 07:50:54 wiz Exp $ d4 1 a4 1 DISTNAME= curl-8.6.0 @ 1.10 log @curl: update to 8.5.0 Security fix release. @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.9 2023/10/22 13:34:31 js Exp $ d4 1 a4 1 DISTNAME= curl-8.5.0 d19 1 a19 1 PYTHON_VERSIONS_INCOMPATIBLE= 27 # py-impacket d21 1 a21 1 USE_TOOLS+= nroff perl:test @ 1.9 log @curl: Make brotli an option This fixes the linker errors on Fedora 39 for me. Apparently curl picks up the headers and assumes the libraries must exist then. Explicitly disabling brotli when not using it or depending on the buildlink when enabling it fixes this. @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.8 2023/10/11 07:16:03 adam Exp $ d4 1 a4 2 DISTNAME= curl-8.4.0 PKGREVISION= 1 @ 1.8 log @curl libcurl-gnutls: updated to 8.4.0 Fixed in 8.4.0 - October 11 2023 Changes: curl: add support for the IPFS protocols via HTTP gateway curl_multi_get_handles: get easy handles from a multi handle mingw: delete support for legacy mingw.org toolchain Bugfixes: acinclude.m4: Document proper system truststore on FreeBSD appveyor: fix yamlint issues, indent appveyor: rewrite batch in PowerShell + CI improvements autotools: adjust `CURL_CA_PATH` value to CMake autotools: restore `HAVE_IOCTL_*` detections base64: also build for curl bufq: remove Curl_bufq_skip_and_shift (unused) build: delete checks for C89 standard headers build: do not publish `HAVE_BORINGSSL`, `HAVE_AWSLC` macros cf-socket: simulate slow/blocked receives in debug cmake, configure: also link with CoreServices cmake: add check for suseconds_t cmake: add feature checks for `memrchr` and `getifaddrs` cmake: add missing checks cmake: delete old `HAVE_LDAP_URL_PARSE` logic cmake: detect `HAVE_CLOCK_GETTIME_MONOTONIC_RAW` cmake: detect `HAVE_GETADDRINFO_THREADSAFE` cmake: detect `sys/wait.h` and `netinet/udp.h` cmake: detect TLS-SRP in OpenSSL/wolfSSL/GnuTLS cmake: disable unity mode with Windows Unicode + TrackMemory cmake: fix `HAVE_LDAP_SSL`, `HAVE_LDAP_URL_PARSE` on non-Windows cmake: fix `HAVE_WRITABLE_ARGV` detection cmake: fix duplicate symbols when linking tests cmake: fix missing `zlib.h` when compiling `libcurltool` cmake: fix stderr initialization in unity builds cmake: fix the help text to the static build option in CMakeLists.txt cmake: fix unity builds for more build combinations cmake: fix unity symbol collisions in h2 builds cmake: fix unity with Windows Unicode + TrackMemory cmake: improve OpenLDAP builds cmake: lib `CURL_STATICLIB` fixes (Windows) cmake: move global headers to specific checks cmake: pre-cache `HAVE_BASENAME` for mingw-w64 and MSVC cmake: pre-cache `HAVE_POLL_FINE` on Windows cmake: tidy-up `NOT_NEED_LBER_H` detection cmake: validate `CURL_DEFAULT_SSL_BACKEND` config value configure: check for the capath by default configure: remove unused checks configure: replace adhoc domain with `localhost` in tests configure: sort AC_CHECK_FUNCS connect: expire the timeout when trying next connect: only start the happy eyeballs timer when needed cookie: do not store the expire or max-age strings cookie: remove unnecessary struct fields cookie: set ->running in cookie_init even if data is NULL create-dirs.d: clarify it also uses --output-dirs curl.h: mark CURLSSLBACKEND_NSS as deprecated since 8.3.0 curl_easy_pause.3: mention h2/h3 buffering curl_easy_pause.3: mention it works within callbacks curl_easy_pause: set "in callback" true on exit if true CURLOPT_DEBUGFUNCTION.3: warn about internal handles docs/libcurl/opts/Makefile.inc: add missing manpage files docs: adapt SEE ALSO sections to new requirements docs: explain how PINNEDPUBLICKEY is independent of VERIFYPEER docs: replace made up domains with example.com docs: update curl man page references docs: use CURLSSLBACKEND_NONE doh: inherit DEBUGFUNCTION/DATA escape: replace Curl_isunreserved with ISUNRESERVED FAQ: How do I upgrade curl.exe in Windows? GHA/linux: run singleuse to detect single-use global functions GHA: add workflow to compare configure vs cmake outputs h2-proxy: remove left-over mistake in drain_tunnel() h2: testcase and fix for pausing h2 streams h3: add support for ngtcp2 with AWS-LC builds http2: refused stream handling for retry http: fix CURL_DISABLE_BEARER_AUTH breakage http: h1/h2 proxy unification http: remove wrong comment for http_should_fail http: use per-request counter to check too large headers http_aws_sigv4: fix sorting with empty parts idn: fix WinIDN null ptr deref on bad host idn: if idn2_check_version returns NULL, return error inet_ntop: add typecast to silence Coverity lib: disambiguate Curl_client_write flag semantics lib: enable hmac for digest as well lib: failf/infof compiler warnings lib: let the max filesize option stop too big transfers too lib: move handling of `data->req.writer_stack` into Curl_client_write() lib: provide and use Curl_hexencode lib: remove TIME_WITH_SYS_TIME lib: use wrapper for curl_mime_data fseek callback libssh2: fix error message on failed pubkey-from-file libssh: cap SFTP packet size sent Makefile.mk: always set `CURL_STATICLIB` for lib (Windows) MANUAL.md: change domain to example.com misc: better random strings MQTT: improve receive of ACKs multi: do CURLM_CALL_MULTI_PERFORM at two more places multi: fix small timeouts multi: remove Curl_multi_dump multi: round the timeout up to prevent early wakeups multi: set CURLM_CALL_MULTI_PERFORM after switch to DOING_MORE openssl: improve ssl shutdown handling openssl: use X509_ALGOR_get0 instead of reaching into X509_ALGOR pytest: exclude test_03_goaway in CI runs due to timing dependency quic: set ciphers/curves the same way regular TLS does quiche: fix build error with --with-ca-fallback RELEASE-PROCEDURE.md: updated coming release dates runtests: display the test status if tests appear hung runtests: eliminate a warning on old perl versions socks: return error if hostname too long for remote resolve src/mkhelp: make generated code pass `checksrc` test1056: disable on Windows test1474: disable test on NetBSD, OpenBSD and Solaris 10 test1592: greatly increase the maximum test timeout test1903: actually verify the cookies after the test test1906: set a lower timeout since it's hit on Windows test2600: remove special case handling for USE_ALARM_TIMEOUT test650: fix an end tag typo test661: return from test early in case of curl error test: add missing s tests: close the shell used to start sshd tests: fix a race condition in ftp server disconnect tests: fix compiler warnings tests: Fix zombie processes left behind by FTP tests. tests: improve SLOWDOWN test reliability by reducing sent data tests: increase lib571 timeout from 3s to 30s tests: log the test result code after each libtest tests: propagate errors in libtests tests: set --expect100-timeout to improve test reliability tests: show which curl tool `runtests.pl` is using tests: stop overriding the lock timeout tftpd: always use curl's own tftp.h tool: use our own stderr variable tool_cb_wrt: fix debug assertion tool_getparam: accept variable expansion on file names too tool_setopt: remove unused function tool_setopt_flags upload-file.d: describe the file name slash/backslash handling url: fall back to http/https proxy env-variable if ws/wss not set url: fix netrc info message warnless: remove unused functions wolfssh: do cleanup in Curl_ssh_cleanup wolfssl: allow capath with CURLOPT_CAINFO_BLOB wolfssl: if CURLOPT_CAINFO_BLOB is set, ignore the CA files wolfssl: ignore errors in CA path @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.7 2023/09/29 10:45:04 tnn Exp $ d5 1 @ 1.7 log @curl: fix libcurl breakage on macOS 14, via upstream Autoreconfed with upstream m4 changes and relevant hunks extracted manually. patch-configure can be reverted when curl is updated past 8.4.0. @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.6 2023/09/13 08:15:05 adam Exp $ d4 1 a4 2 DISTNAME= curl-8.3.0 PKGREVISION= 1 @ 1.6 log @curl libcurl-gnutls: updated to 8.3.0 Fixed in 8.3.0 - September 13 2023 Changes: curl: make %output{} in -w specify a file to write to gskit: remove lib: --disable-bindlocal builds curl without local binding support nss: remove support for this TLS library tool: add "variable" support trace: make tracing available in non-debug builds url: change default value for CURLOPT_MAXREDIRS to 30 urlapi: CURLU_PUNY2IDN - convert from punycode to IDN name wolfssl: support loading system CA certificates Bugfixes: altsvc: accept and parse IPv6 addresses in response headers asyn-ares: reduce timeout to 2000ms aws-sigv4: canonicalize the query aws-sigv4: fix having date header twice in some cases aws-sigv4: handle no-value user header entries bearssl: don't load CA certs when peer verification is disabled bearssl: handshake fix, provide proper get_select_socks() implementation build: fix portability of mancheck and checksrc targets build: streamline non-UWP wincrypt detections c-hyper: adjust the hyper to curlcode conversion c-hyper: fix memory leaks in `Curl_http` cf-haproxy: make CURLOPT_HAPROXY_CLIENT_IP set the *source* IP cf-socket: log successful interface bind CI/cirrus: disable python install on FreeBSD CI: add a 32-bit i686 Linux build CI: add caching to many jobs CI: move on to ngtcp2 v0.19.1 CI: move the Alpine build from Cirrus to GHA CI: ngtcp2-linux: use separate caches for tls libraries CI: remove Windows builds from Cirrus, without replacement CI: switch macOS ARM build from Cirrus to Circle CI CI: use master again for wolfssl cirrus: install everthing with pkg, avoid pip cmake: add GnuTLS option cmake: add support for `CURL_DEFAULT_SSL_BACKEND` cmake: add support for single libcurl compilation pass cmake: allow `SHARE_LIB_OBJECT=ON` on all platforms cmake: assume `wldap32` availability on Windows cmake: cache more config and delete unused ones cmake: detect `SSL_set0_wbio` in OpenSSL cmake: drop `HAVE_LIBWINMM` and `HAVE_LIBWS2_32` feature checks cmake: fix to use variable for the curl namespace cmake: fixup H2 duplicate symbols for unity builds cmake: set SIZEOF_LONG_LONG in curl_config.h cmake: support building static and shared libcurl in one go cmdline-docs: make sure to phrase it as "added in ...." cmdline-docs: use present tense, not future cmdline-opts/docs: mention the negative option part cmdline-opts/page-header: clarify stronger that !opt == URL cmdline-opts/page-header: reorder, clean up configure, cmake, lib: more form api deprecation configure: fix `HAVE_TIME_T_UNSIGNED` check configure: trust pkg-config when it's used for zlib configure: use the pkg-config --libs-only-l flag for libssh2 connect: stop halving the remaining timeout when less than 600 ms left cookie-jar.d: emphasize that this option is ONLY writing cookies crypto: ensure crypto initialization works curl_url_get/set.3: add missing semicolon in SYNOPSIS CURLINFO_CERTINFO.3: better explain curl_certinfo struct CURLINFO_TLS_SSL_PTR.3: clarify a recommendation CURLOPT_*TIMEOUT*: extend and clarify CURLOPT_SSL_VERIFYPEER.3: mention it does not load CA certs when disabled CURLOPT_URL.3: add two URL API calls in the see-also section CURLOPT_URL.3: explain curl_url_set() uses the same parser digest: Use hostname to generate spn instead of realm disable.d: explain --disable not implemented prior to 7.50.0 docs/cmdline-opts/gen.pl: hide "added in" before 7.50.0 docs/cmdline-opts: match the current output docs/cmdline-opts: spellfixes, typos and polish docs/cmdline: add small "warning" to verbose options docs/cmdline: remove repeated working for negotiate + ntlm docs/HYPER.md: document a workaround for a link error docs: add curl_global_trace to some SEE ALSO sections docs: link to the website versions instead of markdowns docs: mark --ssl-revoke-best-effort as Schannel specific docs: mention critical files in same directories as curl saves docs: removing "pausing transfers" from HYPER.md. docs: rewrite to present tense easy: remove #ifdefs to make code easier on the eye egd: delete feature detection and related source code ftp: fix temp write of ipv6 address gen.pl: escape all dashes (ascii minus) to avoid unicode hyphens gen.pl: replace all single quotes with aq GHA: adding quiche workflow headers: accept leading whitespaces on first response header http2: avoid too early connection re-use/multiplexing http2: cleanup trace messages http2: disable asssertion blocking OSSFuzz testing http2: fix in h2 proxy tunnel: progress in ingress on sending http2: polish things around POST http2: upgrade tests and add fix for non-existing stream http3/ngtcp2: shorten handshake, trace cleanup http3: quiche, handshake optimization, trace cleanup http: close the connection after a late 417 is received http: do not require a user name when using CURLAUTH_NEGOTIATE http: fix sending of large requests http: remove the p_pragma struct field http: return error when receiving too large header set hyper: fix a progress upload counter bug hyper: fix ownership problems hyper: remove `hyptransfer->endtask` imap: add a check for failing strdup() imap: remove the only sscanf() call in the IMAP code include.d: explain headers not printed with --fail before 7.75.0 include/curl/mprintf.h: add __attribute__ for the prototypes krb5: fix "implicit conversion loses integer precision" warnings lib: add ability to disable auths individually lib: build fixups when built with most things disabled lib: fix a few *printf() flag mistakes lib: fix null ptr derefs and uninitialized vars (h2/h3) lib: move mimepost data from ->req.p.http to ->state libtest: use curl_free() to free libcurl allocated data list-only.d: mention SFTP as supported protocol macOS: fix target detection more misc: fix various typos multi.h: the 'revents' field of curl_waitfd is supported multi: more efficient pollfd count for poll multi: remove 'processing: ' debug message ngtcp2: fix handling of large requests openssl: auto-detect `SSL_R_TLSV13_ALERT_CERTIFICATE_REQUIRED` openssl: clear error queue after SSL_shutdown openssl: make aws-lc version support OCSP openssl: Support async cert verify callback openssl: switch to modern init for LibreSSL 2.7.0+ openssl: use `SSL_CTX_set_ciphersuites` with LibreSSL 3.4.1 openssl: use `SSL_CTX_set_keylog_callback` with LibreSSL 3.5.0 openssl: when CURLOPT_SSL_CTX_FUNCTION is registered, init x509 store before os400: build test servers os400: do not check translatable options at build time os400: implement CLI tool page-footer: QLOGDIR works with ngtcp2 and quiche page-header: move up a URL paragraph from GLOBBING to URL pytest: fix check for slow_network skips to only apply when intended quic: don't set SNI if hostname is an IP address quiche: adjust quiche `QUIC_IDLE_TIMEOUT` to 60s quiche: enable quiche to handle timeout events resolve: use PF_INET6 family lookups when CURL_IPRESOLVE_V6 is set revert "schannel: reverse the order of certinfo insertions" schannel: fix ordering of cert chain info schannel: fix user-set legacy algorithms in Windows 10 & 11 schannel: verify hostname independent of verify cert sectransp: fix compiler warnings sectransp: prevent CFRelease() of NULL secureserver.pl: fix stunnel path quoting secureserver.pl: fix stunnel version parsing SECURITY-PROCESS.md: not a sec issue: Tricking user to run a cmdline system.h: add CURL_OFF_T definitions on HP-UX with HP aCC test1304: build and skip without netrc support test1554: check translatable string options in OS400 wrapper test1608: make it build and get skipped without shuffle DNS support test687/688: two more basic --xattr tests tests/tftpd+mqttd: make variables static to silence picky warnings tests: add 'large-time' as a testable feature tests: add support for nested %if conditions tests: don't call HTTP errors OK in test cases tests: ensure `libcurl.def` contains all exports tests: fix h3 server check and parallel instances tests: TLS session sharing test tests: update cookie expiry dates to far in the future time-cond.d: mention what happens on a missing file tool: avoid including leading spaces in the Location hyperlink tool: change some fopen failures from warnings to errors tool: make the length argument an int for printf()-.* flags tool_cb_wrt: fix invalid unicode for windows console tool_filetime: make -z work with file dates before 1970 tool_operate: allow both SSL_CERT_FILE and SSL_CERT_DIR tool_operate: make aws-sigv4 not require TLS to be used tool_paramhlp: improve str2num(): avoid unnecessary call to strlen() tool_urlglob: use the correct format specifier for curl_off_t in msnprintf transfer: also stop the sending on closed connection transfer: don't set TIMER_STARTTRANSFER on first send unit2600: fix build warning if built without verbose messages url: remove infof() output for "still name resolving" urlapi: fix heap buffer overflow urlapi: make sure zoneid is also duplicated in curl_url_dup urlapi: return CURLUE_BAD_HOSTNAME if puny2idn encoding fails urlapi: setting a blank URL ("") is not an ok URL vquic: show stringified messages for errno vtls: clarify "ALPN: offers" message winbuild: improve check for static zlib wolfSSL: avoid the OpenSSL compat API when not needed workflows/macos.yml: disable zstd and alt-svc in the http-only build write-out.d: clarify %{time_starttransfer} ws: fix spelling mistakes in examples and tests @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.5 2023/07/26 08:31:17 adam Exp $ d5 1 @ 1.6.2.1 log @Pullup ticket #6809 - requested by leot www/curl: security fix Revisions pulled up (via patch): - www/curl/Makefile.common 1.8 - www/curl/PLIST 1.96 - www/curl/distinfo 1.199 - www/curl/patches/patch-configure 1.18 - www/libcurl-gnutls/distinfo 1.6 --- Module Name: pkgsrc Committed By: adam Date: Wed Oct 11 07:16:03 UTC 2023 Modified Files: pkgsrc/www/curl: Makefile.common PLIST distinfo pkgsrc/www/curl/patches: patch-configure pkgsrc/www/libcurl-gnutls: distinfo Log Message: curl libcurl-gnutls: updated to 8.4.0 Fixed in 8.4.0 - October 11 2023 Changes: curl: add support for the IPFS protocols via HTTP gateway curl_multi_get_handles: get easy handles from a multi handle mingw: delete support for legacy mingw.org toolchain Bugfixes: acinclude.m4: Document proper system truststore on FreeBSD appveyor: fix yamlint issues, indent appveyor: rewrite batch in PowerShell + CI improvements autotools: adjust `CURL_CA_PATH` value to CMake autotools: restore `HAVE_IOCTL_*` detections base64: also build for curl bufq: remove Curl_bufq_skip_and_shift (unused) build: delete checks for C89 standard headers build: do not publish `HAVE_BORINGSSL`, `HAVE_AWSLC` macros cf-socket: simulate slow/blocked receives in debug cmake, configure: also link with CoreServices cmake: add check for suseconds_t cmake: add feature checks for `memrchr` and `getifaddrs` cmake: add missing checks cmake: delete old `HAVE_LDAP_URL_PARSE` logic cmake: detect `HAVE_CLOCK_GETTIME_MONOTONIC_RAW` cmake: detect `HAVE_GETADDRINFO_THREADSAFE` cmake: detect `sys/wait.h` and `netinet/udp.h` cmake: detect TLS-SRP in OpenSSL/wolfSSL/GnuTLS cmake: disable unity mode with Windows Unicode + TrackMemory cmake: fix `HAVE_LDAP_SSL`, `HAVE_LDAP_URL_PARSE` on non-Windows cmake: fix `HAVE_WRITABLE_ARGV` detection cmake: fix duplicate symbols when linking tests cmake: fix missing `zlib.h` when compiling `libcurltool` cmake: fix stderr initialization in unity builds cmake: fix the help text to the static build option in CMakeLists.txt cmake: fix unity builds for more build combinations cmake: fix unity symbol collisions in h2 builds cmake: fix unity with Windows Unicode + TrackMemory cmake: improve OpenLDAP builds cmake: lib `CURL_STATICLIB` fixes (Windows) cmake: move global headers to specific checks cmake: pre-cache `HAVE_BASENAME` for mingw-w64 and MSVC cmake: pre-cache `HAVE_POLL_FINE` on Windows cmake: tidy-up `NOT_NEED_LBER_H` detection cmake: validate `CURL_DEFAULT_SSL_BACKEND` config value configure: check for the capath by default configure: remove unused checks configure: replace adhoc domain with `localhost` in tests configure: sort AC_CHECK_FUNCS connect: expire the timeout when trying next connect: only start the happy eyeballs timer when needed cookie: do not store the expire or max-age strings cookie: remove unnecessary struct fields cookie: set ->running in cookie_init even if data is NULL create-dirs.d: clarify it also uses --output-dirs curl.h: mark CURLSSLBACKEND_NSS as deprecated since 8.3.0 curl_easy_pause.3: mention h2/h3 buffering curl_easy_pause.3: mention it works within callbacks curl_easy_pause: set "in callback" true on exit if true CURLOPT_DEBUGFUNCTION.3: warn about internal handles docs/libcurl/opts/Makefile.inc: add missing manpage files docs: adapt SEE ALSO sections to new requirements docs: explain how PINNEDPUBLICKEY is independent of VERIFYPEER docs: replace made up domains with example.com docs: update curl man page references docs: use CURLSSLBACKEND_NONE doh: inherit DEBUGFUNCTION/DATA escape: replace Curl_isunreserved with ISUNRESERVED FAQ: How do I upgrade curl.exe in Windows? GHA/linux: run singleuse to detect single-use global functions GHA: add workflow to compare configure vs cmake outputs h2-proxy: remove left-over mistake in drain_tunnel() h2: testcase and fix for pausing h2 streams h3: add support for ngtcp2 with AWS-LC builds http2: refused stream handling for retry http: fix CURL_DISABLE_BEARER_AUTH breakage http: h1/h2 proxy unification http: remove wrong comment for http_should_fail http: use per-request counter to check too large headers http_aws_sigv4: fix sorting with empty parts idn: fix WinIDN null ptr deref on bad host idn: if idn2_check_version returns NULL, return error inet_ntop: add typecast to silence Coverity lib: disambiguate Curl_client_write flag semantics lib: enable hmac for digest as well lib: failf/infof compiler warnings lib: let the max filesize option stop too big transfers too lib: move handling of `data->req.writer_stack` into Curl_client_write() lib: provide and use Curl_hexencode lib: remove TIME_WITH_SYS_TIME lib: use wrapper for curl_mime_data fseek callback libssh2: fix error message on failed pubkey-from-file libssh: cap SFTP packet size sent Makefile.mk: always set `CURL_STATICLIB` for lib (Windows) MANUAL.md: change domain to example.com misc: better random strings MQTT: improve receive of ACKs multi: do CURLM_CALL_MULTI_PERFORM at two more places multi: fix small timeouts multi: remove Curl_multi_dump multi: round the timeout up to prevent early wakeups multi: set CURLM_CALL_MULTI_PERFORM after switch to DOING_MORE openssl: improve ssl shutdown handling openssl: use X509_ALGOR_get0 instead of reaching into X509_ALGOR pytest: exclude test_03_goaway in CI runs due to timing dependency quic: set ciphers/curves the same way regular TLS does quiche: fix build error with --with-ca-fallback RELEASE-PROCEDURE.md: updated coming release dates runtests: display the test status if tests appear hung runtests: eliminate a warning on old perl versions socks: return error if hostname too long for remote resolve src/mkhelp: make generated code pass `checksrc` test1056: disable on Windows test1474: disable test on NetBSD, OpenBSD and Solaris 10 test1592: greatly increase the maximum test timeout test1903: actually verify the cookies after the test test1906: set a lower timeout since it's hit on Windows test2600: remove special case handling for USE_ALARM_TIMEOUT test650: fix an end tag typo test661: return from test early in case of curl error test: add missing s tests: close the shell used to start sshd tests: fix a race condition in ftp server disconnect tests: fix compiler warnings tests: Fix zombie processes left behind by FTP tests. tests: improve SLOWDOWN test reliability by reducing sent data tests: increase lib571 timeout from 3s to 30s tests: log the test result code after each libtest tests: propagate errors in libtests tests: set --expect100-timeout to improve test reliability tests: show which curl tool `runtests.pl` is using tests: stop overriding the lock timeout tftpd: always use curl's own tftp.h tool: use our own stderr variable tool_cb_wrt: fix debug assertion tool_getparam: accept variable expansion on file names too tool_setopt: remove unused function tool_setopt_flags upload-file.d: describe the file name slash/backslash handling url: fall back to http/https proxy env-variable if ws/wss not set url: fix netrc info message warnless: remove unused functions wolfssh: do cleanup in Curl_ssh_cleanup wolfssl: allow capath with CURLOPT_CAINFO_BLOB wolfssl: if CURLOPT_CAINFO_BLOB is set, ignore the CA files wolfssl: ignore errors in CA path @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.8 2023/10/11 07:16:03 adam Exp $ d4 1 a4 1 DISTNAME= curl-8.4.0 @ 1.5 log @curl: updated to 8.2.1 8.2.1 Bugfixes: amigaos: fix sys/mbuf.h m_len macro clash amissl: add missing signal.h include amissl: fix AmiSSL v5 detection cfilters: rename close/connect functions to avoid clashes ciphers.d: put URL in first column cmake: add `libcurlu`/`libcurltool` for unit tests cmake: update ngtcp2 detection configure: check for nghttp2_session_get_stream_local_window_size CONTRIBUTE: drop mention of copyright year ranges CONTRIBUTE: fix syntax in commit message description curl_multi_wait.3: fix arg quoting to doc macro .BR docs: mark two TLS options for TLS, not SSL docs: provide more see also for cipher options hostip: return IPv6 first for localhost resolves http2: fix regression on upload EOF handling http: VLH, very large header test and fixes libcurl-errors.3: add CURLUE_OK os400: correct EXPECTED_STRING_LASTZEROTERMINATED quiche: fix lookup of transfer at multi quiche: fix segfault and other things rustls: update rustls-ffi 0.10.0 socks: print ipv6 address within brackets src/mkhelp: strip off escape sequences tool: fix tool_seek_cb build when SIZEOF_CURL_OFF_T > SIZEOF_OFF_T transfer: do not clear the credentials on redirect to absolute URL unittest: remove unneeded *_LDADD websocket: rename arguments/variables to match docs @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.4 2023/07/19 08:06:20 wiz Exp $ d4 1 a4 1 DISTNAME= curl-8.2.1 @ 1.4 log @curl, libcurl-gnutls: update to 8.2.0 This release includes the following changes: o curl: add --ca-native and --proxy-ca-native [24] o curl: add --trace-ids [53] o CURLOPT_MAIL_RCPT_ALLOWFAILS: replace CURLOPT_MAIL_RCPT_ALLLOWFAILS [5] o haproxy: add --haproxy-clientip flag to set client IPs [23] o lib: add CURLINFO_CONN_ID and CURLINFO_XFER_ID [54] This release includes the following bugfixes: o bufq: make write/pass methods more robust [21] o build: drop unused/redundant `HAVE_WINLDAP_H` [25] o cf-socket: don't bypass fclosesocket callback if cancelled before connect [114] o cf-socket: move ctx declaration under HAVE_GETPEERNAME [91] o cf-socket: skip getpeername()/getsockname for TFTP [65] o checksrc: modernise perl file open [87] o checksrc: quote the file name to work with "funny" letters [93] o CI: brew fix for openssl in default path [116] o CI: don't install impacket if tests are not run o CI: enable parallel make in more builds o circleci: install impacket & wolfssl 5.6.0 [1] o cmake: add support for "unity" builds [13] o cmake: make use of snprintf [102] o cmake: stop CMake from quietly ignoring missing Brotli [81] o configure: add check for ldap_init_fd [80] o configure: fix run-compiler for old /bin/sh [4] o configure: the --without forms of the options are also gone [79] o connect-timeout.d: mention that the DNS lookup is included [85] o curl.h: include for vxworks [78] o curl: count uploaded data to stop at the originally given size [14] o curl: return error when asked to use an unsupported HTTP version [113] o curl_easy_nextheader.3: add missing open parenthesis examples [74] o curl_log: evaluate log statement only when transfer is verbose [8] o curl_mprintf.3: minor fix of the example o curl_pushheader_byname/bynum.3: document in their own man pages [37] o curl_url_set: enforce the max string length check for all parts [38] o CURLOPT_AWS_SIGV4.3: remove unused variable from example [11] o CURLOPT_INFILESIZE.3: mention -1 triggers chunked [55] o CURLOPT_MIMEPOST.3: clarify what setting to NULL means [95] o CURLOPT_SSH_PRIVATE_KEYFILE.3: expand on the file search [31] o docs/libcurl/libcurl.3: cleanups and improvements [46] o docs: add more .IP after .RE to fix indentation of generate paragraphs [82] o docs: fix missing parameter names in examples [41] o docs: update CURLOPT_UPLOAD.3 [63] o docs: update HTTP3.md for newer ngtcp2 and nghttp3 [28] o docs: use a space after RFC when spelling out RFC numbers [105] o example/connect-to: show CURLOPT_CONNECT_TO [47] o example/crawler: also set CURLOPT_AUTOREFERER [35] o example/crawler: make it use a few more options o example/default-scheme: set the default scheme for schemeless URLs [67] o example/hsts-preload: show one way to HSTS preload [68] o example/http2-download: set CURLOPT_BUFFERSIZE [34] o example/ipv6: feature CURLOPT_ADDRESS_SCOPE in use [27] o example/maxconnects: set maxconnect example [98] o example/opensslthreadlock: remove [59] o examples/ftpuploadresume.c: add use of CURLOPT_ACCEPTTIMEOUT_MS [39] o examples/http-options: show how to send "OPTIONS *" [69] o examples/https.c: use CURLOPT_CA_CACHE_TIMEOUT [19] o examples/multi-debugcallback.c: avoid the bool typedef [29] o examples/smtp-mime: use CURLOPT_MAIL_RCPT_ALLOWFAILS [71] o examples/unixsocket.c: example using CURLOPT_UNIX_SOCKET_PATH [40] o examples/websocket.c: websocket example using CONNECT_ONLY [17] o examples: make use of CURLOPT_(REDIR_|)PROTOCOLS_STR [70] o fopen: fix conversion warning on 32-bit Android [49] o fopen: optimize [101] o hostip.c: Move macOS-specific calls into global init call [104] o HTTP/2: upload handling fixes [56] o http2: better support for --limit-rate [7] o http2: error stream resets with code CURLE_HTTP2_STREAM [84] o http2: fix crash in handling stream weights [76] o http2: fix variable type [50] o http2: h2 and h2-PROXY connection alive check fixes [83] o http2: raise header limitations above and beyond [73] o http2: send HEADER & DATA together if possible [99] o http2: treat initial SETTINGS as a WINDOW_UPDATE [100] o HTTP3.md: update openssl version [57] o http3/ngtcp2: upload EAGAIN handling [108] o http: rectify the outgoing Cookie: header field size check [72] o hyper: fix EOF handling on input [66] o hyper: unslow [51] o imap-append.c: update to make it more likely to work [106] o imap: Provide method to disable SASL if it is advertised [75] o krb5: add typecast to please Coverity o libcurl-url.3: also mention CURLUPART_ZONEID o libcurl-ws.3. WebSocket API overview [48] o libssh2: provide error message when setting host key type fails [9] o libssh2: use custom memory functions [12] o ngtcp2: assigning timeout, but value is overwritten before used [103] o ngtcp2: build with 0.17.0 and nghttp3 0.13.0 [96] o ngtcp2: use ever increasing timestamp in io [32] o quiche: avoid NULL deref in debug logging [97] o quiche: fix defects found in latest coverity report [94] o quote.d: fix indentation of generated paragraphs [86] o runtests: abort test run after failure without -a [3] o runtests: better handle ^C during slow tests o runtests: consistently write the test check summary block o runtests: create multiple test runners when requested [20] o runtests: include missing valgrind package [89] o runtests: make test file directories in log/N [44] o runtests: rename server command file o runtests: use more consistent failure lines o runtests: work around a perl without SIGUSR1 [88] o runtests; give each server a unique log lock file [43] o scripts: Fix GHA matrix job detection in cijobs.pl o sectransp: fix EOF handling [92] o system.h: remove __IBMC__/__IBMCPP__ guards and apply to all z/OS compiles [10] o test2600: fix the description [90] o test427: verify sending more cookies than fit in a 8190 bytes line [61] o tests/http: Add mod_h2 directive `H2ProxyRequests` [77] o tests/servers.pm: pick unused port number with a server socket [16] o tests/servers: generate temp names in /tmp for unix domain sockets [6] o tests: fix error messages & handling around sockets [30] o tests: improve reliability of TFTP tests o testutil: allow multiple %-operators on the same line [62] o timeval: use CLOCK_MONOTONIC_RAW if available [52] o tls13-ciphers.d: include Schannel [36] o tool: remove exclamation marks from error/warning messages o tool: remove newlines from all helpf/notef/warnf/errorf calls [15] o tool_easysrc.h: correct `easysrc_perform` for `CURL_DISABLE_LIBCURL_OPTION` [109] o tool_getparam: fix comment [22] o tool_operate: allow cookie lines up to 8200 bytes [60] o tool_parsecfg: accept line lengths up to 10M [115] o tool_urlglob: use curl_off_t instead of longs [2] o tool_writeout_json: fix encoding of control characters [107] o transfer: clear credentials when redirecting to absolute URL [64] o urlapi: have *set(PATH) prepend a slash if one is missing [42] o urlapi: scheme must start with alpha [26] o vtls: avoid memory leak if sha256 call fails [58] o websocket-cb: example doing WebSocket download using callback [18] o wolfssl: detect when TLS 1.2 support is not built into wolfssl [111] o wolfssl: support setting CA certificates as blob [110] o ws: make the curl_ws_meta() return pointer a const [45] @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.3 2023/06/09 12:52:12 riastradh Exp $ d4 1 a4 1 DISTNAME= curl-8.2.0 @ 1.3 log @www/curl: Need Perl only for running tests. @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.2 2023/05/31 20:19:46 nikita Exp $ d4 1 a4 1 DISTNAME= curl-8.1.2 @ 1.2 log @libcurl-gnutls: update to version 8.1.2, use Makefile fragment @ text @d1 1 a1 1 # $NetBSD: Makefile.common,v 1.1 2023/05/31 20:17:52 nikita Exp $ d21 1 a21 1 USE_TOOLS+= nroff perl @ 1.1 log @curl: create Makefile.common, to be used by curl and libcurl-gnutls @ text @d1 2 a2 1 # $NetBSD: Makefile,v 1.272 2023/05/31 08:52:59 adam Exp $ @