Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package talloc for openSUSE:Factory checked 
in at 2026-10-01 17:00:01
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/talloc (Old)
 and      /work/SRC/openSUSE:Factory/.talloc.new.1253 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "talloc"

Thu Oct  1 17:00:01 2026 rev:49 rq:1381908 version:2.5.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/talloc/talloc.changes    2026-05-29 
18:04:29.115850899 +0200
+++ /work/SRC/openSUSE:Factory/.talloc.new.1253/talloc.changes  2026-10-01 
17:01:30.056341080 +0200
@@ -1,0 +2,39 @@
+Thu Oct  1 11:29:54 UTC 2026 - Matej Cepl <[email protected]>
+
+- Fix building of the `man` multibuild.
+
+-------------------------------------------------------------------
+Wed Sep 30 00:02:41 UTC 2026 - Matej Cepl <[email protected]>
+
+- Extend talloc-python3.5-fix-soabi_name.patch to preserve
+  underscores in PYTHON_LIBNAME_SO_ABI_FLAG as well as public
+  library filenames. This keeps the pkg-config Libs entry
+  consistent with the installed libpytalloc-util library and
+  fixes Samba linking without a post-install name substitution.
+- Declare the python-rpm-macros build dependency explicitly and
+  update the man-page build-cycle comment for the separate
+  multibuild flavor.
+
+-------------------------------------------------------------------
+Mon Sep 28 15:51:03 UTC 2026 - Noel Power <[email protected]>
+
+- Update to 2.5.0
+  * alloc: Add talloc_asprintf_addsep()
+  * lib:talloc:testsuite remove unread global test_abort_stop
+  * Replace memset_s() with memset_explicit()
+
+-------------------------------------------------------------------
+Sat Sep 12 11:51:20 UTC 2026 - Matej Cepl <[email protected]>
+
+- Convert the package to _multibuild flavors: the man pages are
+  now built from the "man" flavor of talloc.spec instead of
+  a generated talloc-man.spec, so pre_checkin.sh, talloc-man.spec
+  and talloc-man.changes are gone. No need to maintain duplicate
+  files.
+- Merge the duplicated %if blocks in the spec file and give the
+  man flavor its own summary and description.
+- Remove use of obsolete %py3* macros, use only the maintained
+  ones from `python-rpm-macros` package.
+- Make rpmlint happy.
+
+-------------------------------------------------------------------

Old:
----
  pre_checkin.sh
  talloc-2.4.4.tar.asc
  talloc-2.4.4.tar.gz
  talloc-man.changes
  talloc-man.spec

New:
----
  talloc-2.5.0.tar.asc
  talloc-2.5.0.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ talloc.spec ++++++
--- /var/tmp/diff_new_pack.L4Xd6Y/_old  2026-10-01 17:01:30.907376683 +0200
+++ /var/tmp/diff_new_pack.L4Xd6Y/_new  2026-10-01 17:01:30.910376809 +0200
@@ -1,7 +1,7 @@
 #
 # spec file for package talloc
 #
-# Copyright (c) 2026 SUSE LLC
+# Copyright (c) 2026 SUSE LLC and contributors
 #
 # All modifications and additions to the file contributed by third parties
 # remain the property of their copyright owners, unless otherwise agreed
@@ -16,37 +16,45 @@
 #
 
 
-%{!?py3_soflags:  %global py3_soflags cpython-%{python3_version_nodots}m}
-%{!?py3_soflags_dash:   %global py3_soflags_dash %(echo %{py3_soflags} | sed 
"s/_/-/g")}
-%{!?py3_incdir:  %global py3_incdir %(%{__python3} -c "import sysconfig as s; 
print(s.get_path('include'))")}
-%define build_man 0
-
-%if %{build_man}
-Name:           talloc-man
-BuildRequires:  doxygen
+%global flavor @BUILD_FLAVOR@%{nil}
+%if "%{flavor}" == "man"
+%define psuffix -man
+%bcond_without man
 %else
-Name:           talloc
-BuildRequires:  autoconf
-BuildRequires:  docbook-xsl-stylesheets
-BuildRequires:  libxslt
-BuildRequires:  pkg-config
-BuildRequires:  python3-base
-BuildRequires:  python3-devel
-#!BuildIgnore:  python
+%define psuffix %{nil}
+%bcond_with man
 %endif # build_man
-URL:            http://talloc.samba.org/
-Version:        2.4.4
+Name:           talloc%{?psuffix}
+Version:        2.5.0
 Release:        0
-Summary:        Samba talloc Library
+%if %{with man}
+Summary:        Man pages for the talloc library
+%else
+Summary:        Samba core memory allocator
+%endif
 License:        LGPL-3.0-or-later
 Group:          Development/Libraries/C and C++
+URL:            https://talloc.samba.org/
 Source:         https://download.samba.org/pub/talloc/talloc-%{version}.tar.gz
 Source1:        https://download.samba.org/pub/talloc/talloc-%{version}.tar.asc
+Source50:       talloc.keyring
+%if %{without man}
 Source4:        baselibs.conf
+%endif
 Patch0:         talloc-python3.5-fix-soabi_name.patch
-Source50:       talloc.keyring
-BuildRoot:      %{_tmppath}/%{name}-%{version}-build
+%if %{with man}
+BuildRequires:  doxygen
+%else
 %{?suse_build_hwcaps_libs}
+BuildRequires:  autoconf
+BuildRequires:  docbook-xsl-stylesheets
+BuildRequires:  libxslt
+BuildRequires:  pkgconfig
+BuildRequires:  python-rpm-macros
+BuildRequires:  python3-base
+BuildRequires:  python3-devel
+#!BuildIgnore:  python
+%endif # with man
 
 %description
 Talloc is a hierarchical, reference counted memory pool system with
@@ -54,8 +62,11 @@
 
 It is the core memory allocator used in Samba.
 
-%if ! %{build_man}
+%if %{with man}
+This package contains the manual pages for the talloc API.
+%endif
 
+%if %{without man}
 %package -n libtalloc2
 Summary:        Samba talloc library
 Group:          System/Libraries
@@ -71,13 +82,12 @@
 
 %package -n libtalloc-devel
 Summary:        Libraries and Header Files to Develop Programs with talloc2 
Support
-# Man pages are built in a 2nd spec file in order to break a build cycle with 
doxygen->cmake->krb5->libtalloc
+# Build man pages in the separate "man" flavor to break the
+# doxygen->cmake->krb5->libtalloc build cycle.
 Group:          Development/Libraries/C and C++
-%if 0%{?suse_version} > 1030
-Recommends:     %{name}-man
-%endif
 Requires:       libtalloc2 = %{version}
-Requires:       pkg-config
+Requires:       pkgconfig
+Recommends:     %{name}-man
 
 %description -n libtalloc-devel
 Talloc is a hierarchical, reference counted memory pool system with
@@ -91,7 +101,8 @@
 Summary:        Python3 bindings for the Talloc library
 Group:          Development/Libraries/Python
 Requires:       libtalloc2 = %{version}
-Obsoletes:      python-talloc
+Provides:       python-talloc = %{version}-%{release}
+Obsoletes:      python-talloc < %{version}-%{release}
 
 %description -n python3-talloc
 This package contains the Python3 bindings for the Talloc library.
@@ -99,21 +110,33 @@
 %package -n python3-talloc-devel
 Summary:        Developer tools for the Talloc library
 Group:          Development/Libraries/Python
-Requires:       pkg-config
+Requires:       pkgconfig
 Requires:       python3-talloc = %{version}
-Obsoletes:      python-talloc-devel
+Provides:       python-talloc-devel = %{version}-%{release}
+Obsoletes:      python-talloc-devel < %{version}-%{release}
 
 %description -n python3-talloc-devel
 Libraries and Header Files to Develop Programs with python3-talloc Support
 
-%endif # ! build_man
+%endif # without man
 
 %prep
-%setup -n talloc-%{version} -q
-%autopatch -p1
+%autosetup -p1 -n talloc-%{version}
 
 %build
-%if ! %{build_man}
+%if %{with man}
+doxygen doxy.config
+
+%install
+# Install API documentation
+mkdir -p "%{buildroot}/%{_mandir}"
+cp -a doc/man/* "%{buildroot}/%{_mandir}/"
+
+%files
+%{_mandir}/man3/libtalloc*.3%{?ext_man}
+%{_mandir}/man3/talloc*.3%{?ext_man}
+
+%else
 export CFLAGS="%{optflags} -D_GNU_SOURCE -D_LARGEFILE64_SOURCE 
-DIDMAP_RID_SUPPORT_TRUSTED_DOMAINS"
 CONFIGURE_OPTIONS="\
        --prefix=%{_prefix} \
@@ -124,19 +147,11 @@
        --bundled-libraries=NONE \
        --builtin-libraries=replace \
 "
+# The waf based build system does not understand the %%configure macro
 PYTHONARCHDIR=%{python3_sitearch} ./configure ${CONFIGURE_OPTIONS}
-make %{?_smp_mflags} \
-       all
-
-%else
-
-doxygen doxy.config
-
-%endif # ! build_man
+%make_build all
 
-%if ! %{build_man}
 %check
-%if 0%{?suse_version} != 1110 || "%{_build_arch}" == "x86_64"
 %if "%{qemu_user_space_build}" == "1"
 echo "skipping test on qemu userspace build due to AT_RANDOM not changing"
 %else # qemu_user_space_build == 1
@@ -144,61 +159,35 @@
 ln test_magic_differs* lib/talloc/
 LD_LIBRARY_PATH=bin/shared make test
 %endif # qemu_user_space_build == 1
-%endif # suse_version != 1110; fails for i586 and ppc64
-%endif # ! build_man
 
 %install
-%if ! %{build_man}
 %make_install
 rm -r "%{buildroot}/%{_mandir}"
-mkdir -p %{buildroot}/%{py3_incdir}
-mv %{buildroot}/%{_includedir}/pytalloc.h %{buildroot}/%{py3_incdir}/pytalloc.h
-sed -i 's;${prefix}/include;%{py3_incdir};g' 
%{buildroot}/%{_libdir}/pkgconfig/pytalloc-util.%{py3_soflags}.pc
-sed -i 
's;-lpytalloc-util.%{py3_soflags_dash};-lpytalloc-util.%{py3_soflags};g' 
%{buildroot}/%{_libdir}/pkgconfig/pytalloc-util.%{py3_soflags}.pc
-%else
+mkdir -p %{buildroot}/%{python3_sysconfig_path include}
+mv %{buildroot}/%{_includedir}/pytalloc.h 
%{buildroot}/%{python3_sysconfig_path include}/pytalloc.h
+sed -i 's;${prefix}/include;%{python3_sysconfig_path include};g' 
%{buildroot}/%{_libdir}/pkgconfig/pytalloc-util.%{python3_sysconfig_var 
SOABI}.pc
 
-# Install API documentation
-mkdir -p "%{buildroot}/%{_mandir}"
-cp -a doc/man/* "%{buildroot}/%{_mandir}/"
-
-%endif  # ! build_man
-
-%if ! %{build_man}
 %post -n libtalloc2 -p /sbin/ldconfig
-
 %postun -n libtalloc2 -p /sbin/ldconfig
-
 %post -n python3-talloc -p /sbin/ldconfig
-
 %postun -n python3-talloc -p /sbin/ldconfig
 
 %files -n libtalloc2
-%defattr(-,root,root)
 %{_libdir}/libtalloc.so.*
 
 %files -n libtalloc-devel
-%defattr(-,root,root)
 %{_includedir}/talloc.h
 %{_libdir}/libtalloc.so
 %{_libdir}/pkgconfig/talloc.pc
 
 %files -n python3-talloc
-%defattr(-,root,root)
-%{_libdir}/libpytalloc-util.%{py3_soflags}.so.*
-%{python3_sitearch}/talloc.%{py3_soflags}.so
+%{_libdir}/libpytalloc-util.%{python3_sysconfig_var SOABI}.so.*
+%{python3_sitearch}/talloc.%{python3_sysconfig_var SOABI}.so
 
 %files -n python3-talloc-devel
-%defattr(-,root,root)
-%{py3_incdir}/pytalloc.h
-%{_libdir}/pkgconfig/pytalloc-util.%{py3_soflags}.pc
-%{_libdir}/libpytalloc-util.%{py3_soflags}.so
-
-%else
-
-%files
-%defattr(-,root,root)
-%{_mandir}/man3/libtalloc*.3.*
-%{_mandir}/man3/talloc*.3.*
+%{python3_sysconfig_path include}/pytalloc.h
+%{_libdir}/pkgconfig/pytalloc-util.%{python3_sysconfig_var SOABI}.pc
+%{_libdir}/libpytalloc-util.%{python3_sysconfig_var SOABI}.so
 
-%endif # ! build_man
+%endif # with man
 

++++++ _multibuild ++++++
--- /var/tmp/diff_new_pack.L4Xd6Y/_old  2026-10-01 17:01:30.949378440 +0200
+++ /var/tmp/diff_new_pack.L4Xd6Y/_new  2026-10-01 17:01:30.955378691 +0200
@@ -1,5 +1,5 @@
 <multibuild>
-  <package>talloc-man</package>
+  <package>man</package>
 </multibuild>
 
 

++++++ talloc-2.4.4.tar.gz -> talloc-2.5.0.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/talloc-2.4.4/ABI/pytalloc-util-2.5.0.sigs 
new/talloc-2.5.0/ABI/pytalloc-util-2.5.0.sigs
--- old/talloc-2.4.4/ABI/pytalloc-util-2.5.0.sigs       1970-01-01 
01:00:00.000000000 +0100
+++ new/talloc-2.5.0/ABI/pytalloc-util-2.5.0.sigs       2026-07-31 
17:51:00.182474400 +0200
@@ -0,0 +1,16 @@
+_pytalloc_check_type: int (PyObject *, const char *)
+_pytalloc_get_mem_ctx: TALLOC_CTX *(PyObject *)
+_pytalloc_get_name: const char *(PyObject *)
+_pytalloc_get_ptr: void *(PyObject *)
+_pytalloc_get_type: void *(PyObject *, const char *)
+pytalloc_BaseObject_PyType_Ready: int (PyTypeObject *)
+pytalloc_BaseObject_check: int (PyObject *)
+pytalloc_BaseObject_size: size_t (void)
+pytalloc_Check: int (PyObject *)
+pytalloc_GenericObject_reference_ex: PyObject *(TALLOC_CTX *, void *)
+pytalloc_GenericObject_steal_ex: PyObject *(TALLOC_CTX *, void *)
+pytalloc_GetBaseObjectType: PyTypeObject *(void)
+pytalloc_GetObjectType: PyTypeObject *(void)
+pytalloc_reference_ex: PyObject *(PyTypeObject *, TALLOC_CTX *, void *)
+pytalloc_steal: PyObject *(PyTypeObject *, void *)
+pytalloc_steal_ex: PyObject *(PyTypeObject *, TALLOC_CTX *, void *)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/talloc-2.4.4/ABI/talloc-2.5.0.sigs 
new/talloc-2.5.0/ABI/talloc-2.5.0.sigs
--- old/talloc-2.4.4/ABI/talloc-2.5.0.sigs      1970-01-01 01:00:00.000000000 
+0100
+++ new/talloc-2.5.0/ABI/talloc-2.5.0.sigs      2026-07-31 17:51:00.182474400 
+0200
@@ -0,0 +1,68 @@
+_talloc: void *(const void *, size_t)
+_talloc_array: void *(const void *, size_t, unsigned int, const char *)
+_talloc_free: int (void *, const char *)
+_talloc_get_type_abort: void *(const void *, const char *, const char *)
+_talloc_memdup: void *(const void *, const void *, size_t, const char *)
+_talloc_move: void *(const void *, const void *)
+_talloc_pooled_object: void *(const void *, size_t, const char *, unsigned 
int, size_t)
+_talloc_realloc: void *(const void *, void *, size_t, const char *)
+_talloc_realloc_array: void *(const void *, void *, size_t, unsigned int, 
const char *)
+_talloc_realloc_array_zero: void *(const void *, void *, size_t, unsigned int, 
const char *)
+_talloc_reference_loc: void *(const void *, const void *, const char *)
+_talloc_set_destructor: void (const void *, int (*)(void *))
+_talloc_steal_loc: void *(const void *, const void *, const char *)
+_talloc_zero: void *(const void *, size_t, const char *)
+_talloc_zero_array: void *(const void *, size_t, unsigned int, const char *)
+talloc_asprintf: char *(const void *, const char *, ...)
+talloc_asprintf_addbuf: void (char **, const char *, ...)
+talloc_asprintf_addsep: void (char **, const char *, const char *, ...)
+talloc_asprintf_append: char *(char *, const char *, ...)
+talloc_asprintf_append_buffer: char *(char *, const char *, ...)
+talloc_autofree_context: void *(void)
+talloc_check_name: void *(const void *, const char *)
+talloc_disable_null_tracking: void (void)
+talloc_enable_leak_report: void (void)
+talloc_enable_leak_report_full: void (void)
+talloc_enable_null_tracking: void (void)
+talloc_enable_null_tracking_no_autofree: void (void)
+talloc_find_parent_byname: void *(const void *, const char *)
+talloc_free_children: void (void *)
+talloc_get_name: const char *(const void *)
+talloc_get_size: size_t (const void *)
+talloc_increase_ref_count: int (const void *)
+talloc_init: void *(const char *, ...)
+talloc_is_parent: int (const void *, const void *)
+talloc_named: void *(const void *, size_t, const char *, ...)
+talloc_named_const: void *(const void *, size_t, const char *)
+talloc_parent: void *(const void *)
+talloc_parent_name: const char *(const void *)
+talloc_pool: void *(const void *, size_t)
+talloc_realloc_fn: void *(const void *, void *, size_t)
+talloc_reference_count: size_t (const void *)
+talloc_reparent: void *(const void *, const void *, const void *)
+talloc_report: void (const void *, FILE *)
+talloc_report_depth_cb: void (const void *, int, int, void (*)(const void *, 
int, int, int, void *), void *)
+talloc_report_depth_file: void (const void *, int, int, FILE *)
+talloc_report_full: void (const void *, FILE *)
+talloc_set_abort_fn: void (void (*)(const char *))
+talloc_set_log_fn: void (void (*)(const char *))
+talloc_set_log_stderr: void (void)
+talloc_set_memlimit: int (const void *, size_t)
+talloc_set_name: const char *(const void *, const char *, ...)
+talloc_set_name_const: void (const void *, const char *)
+talloc_show_parents: void (const void *, FILE *)
+talloc_strdup: char *(const void *, const char *)
+talloc_strdup_append: char *(char *, const char *)
+talloc_strdup_append_buffer: char *(char *, const char *)
+talloc_strndup: char *(const void *, const char *, size_t)
+talloc_strndup_append: char *(char *, const char *, size_t)
+talloc_strndup_append_buffer: char *(char *, const char *, size_t)
+talloc_test_get_magic: int (void)
+talloc_total_blocks: size_t (const void *)
+talloc_total_size: size_t (const void *)
+talloc_unlink: int (const void *, void *)
+talloc_vasprintf: char *(const void *, const char *, va_list)
+talloc_vasprintf_append: char *(char *, const char *, va_list)
+talloc_vasprintf_append_buffer: char *(char *, const char *, va_list)
+talloc_version_major: int (void)
+talloc_version_minor: int (void)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/talloc-2.4.4/buildtools/wafsamba/samba_autoconf.py 
new/talloc-2.5.0/buildtools/wafsamba/samba_autoconf.py
--- old/talloc-2.4.4/buildtools/wafsamba/samba_autoconf.py      2026-01-06 
15:31:26.426848600 +0100
+++ new/talloc-2.5.0/buildtools/wafsamba/samba_autoconf.py      2026-05-29 
12:38:01.427556800 +0200
@@ -733,11 +733,16 @@
                                     }
                                     ''',
                                     execute=0,
-                                    cflags=[ '-Werror', 
'-Wp,-D_FORTIFY_SOURCE=2', stack_protect_flag],
+                                    cflags=[
+                                        '-Werror',
+                                        
'-Wp,-U_FORTIFY_SOURCE,-D_FORTIFY_SOURCE=3',
+                                        stack_protect_flag
+                                    ],
                                     mandatory=False,
                                     msg='Checking if compiler accepts %s' % 
(stack_protect_flag))
         if flag_supported:
             conf.ADD_CFLAGS('%s' % (stack_protect_flag))
+            conf.ADD_CFLAGS('-Wp,-U_FORTIFY_SOURCE,-D_FORTIFY_SOURCE=3')
             break
 
     flag_supported = conf.check(fragment='''
@@ -807,6 +812,12 @@
                         testflags=True)
         conf.ADD_CFLAGS('-Werror=old-style-definition -Wold-style-definition',
                         testflags=True)
+        conf.ADD_CFLAGS('-Werror=array-bounds',
+                        testflags=True)
+        conf.ADD_CFLAGS('-Werror=stringop-overflow',
+                        testflags=True)
+        conf.ADD_CFLAGS('-Werror=tautological-compare',
+                        testflags=True)
 
         conf.ADD_CFLAGS('-Wformat=2 -Wno-format-y2k', testflags=True)
         conf.ADD_CFLAGS('-Wno-format-zero-length', testflags=True)
@@ -841,7 +852,6 @@
 
         if not Options.options.disable_warnings_as_errors:
             conf.ADD_NAMED_CFLAGS('PICKY_CFLAGS', '-Werror 
-Wno-error=deprecated-declarations', testflags=True)
-            conf.ADD_NAMED_CFLAGS('PICKY_CFLAGS', 
'-Wno-error=tautological-compare', testflags=True)
             conf.ADD_NAMED_CFLAGS('PICKY_CFLAGS', '-Wno-error=cast-align', 
testflags=True)
 
     if Options.options.fatal_errors:
@@ -1035,5 +1045,5 @@
         conf.env.undefined_ldflags = conf.ADD_LDFLAGS('-Wl,-no-undefined', 
testflags=True)
 
         if (conf.env.undefined_ignore_ldflags == [] and
-            conf.CHECK_LDFLAGS(['-undefined', 'dynamic_lookup'])):
-            conf.env.undefined_ignore_ldflags = ['-undefined', 
'dynamic_lookup']
+            conf.CHECK_LDFLAGS(['-Wl,-undefined,dynamic_lookup'])):
+            conf.env.undefined_ignore_ldflags = 
['-Wl,-undefined,dynamic_lookup']
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/talloc-2.4.4/buildtools/wafsamba/samba_cross.py 
new/talloc-2.5.0/buildtools/wafsamba/samba_cross.py
--- old/talloc-2.4.4/buildtools/wafsamba/samba_cross.py 2026-01-06 
15:31:26.426848600 +0100
+++ new/talloc-2.5.0/buildtools/wafsamba/samba_cross.py 2026-04-28 
17:46:25.387831700 +0200
@@ -26,7 +26,7 @@
     # don't care about its actual content (the tests should
     # yield one-line output in order to comply with the cross-answer
     # format)
-    retstring = retstring.strip()
+    retstring = retstring.strip("\n")
     if len(retstring.split('\n')) > 1:
         retstring = ''
     answer = (retcode, retstring)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/talloc-2.4.4/buildtools/wafsamba/samba_install.py 
new/talloc-2.5.0/buildtools/wafsamba/samba_install.py
--- old/talloc-2.4.4/buildtools/wafsamba/samba_install.py       2026-01-06 
15:31:26.426848600 +0100
+++ new/talloc-2.5.0/buildtools/wafsamba/samba_install.py       2026-04-28 
17:46:25.388831600 +0200
@@ -175,7 +175,8 @@
 
 
 ##############################
-# handle the creation of links for libraries and binaries in the build tree
+# handle the creation of links for libraries, binaries and generated
+# items in the build tree
 
 @feature('symlink_lib')
 @after('apply_link')
@@ -234,3 +235,31 @@
             return
         os.unlink(bldpath)
     os.symlink(binpath, bldpath)
+
+
+@feature('symlink_generated')
+def symlink_generated(self):
+    """Symlink a generated file into the build directory."""
+    target = self.target
+    if isinstance(target, list):
+        if len(target) > 1:
+            return
+        target = target[0]
+
+    if target.endswith('.inst'):
+        return
+
+    genpath = os.path.join(self.path.get_bld().abspath(), target)
+    bldpath = os.path.join(self.bld.env.BUILD_DIRECTORY, target)
+
+    if os.path.lexists(bldpath):
+        if os.path.islink(bldpath) and os.readlink(bldpath) == genpath:
+            return
+        os.unlink(bldpath)
+
+    def run_symlink_generated(_):
+        os.symlink(genpath, bldpath)
+
+    # This way the symlink is always created after genpath, so is
+    # never dangling.
+    self.bld.add_post_fun(run_symlink_generated)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/talloc-2.4.4/buildtools/wafsamba/samba_third_party.py 
new/talloc-2.5.0/buildtools/wafsamba/samba_third_party.py
--- old/talloc-2.4.4/buildtools/wafsamba/samba_third_party.py   2026-01-20 
16:58:35.136438000 +0100
+++ new/talloc-2.5.0/buildtools/wafsamba/samba_third_party.py   2026-04-28 
17:46:25.389831800 +0200
@@ -18,13 +18,13 @@
 
 @conf
 def CHECK_CMOCKA(conf):
-    return conf.CHECK_BUNDLED_SYSTEM_PKG('cmocka', minversion='1.1.3')
+    return conf.CHECK_BUNDLED_SYSTEM_PKG('cmocka', minversion='1.1.8')
 
 Build.BuildContext.CHECK_CMOCKA = CHECK_CMOCKA
 
 @conf
 def CHECK_SOCKET_WRAPPER(conf):
-    return conf.CHECK_BUNDLED_SYSTEM_PKG('socket_wrapper', minversion='1.5.0')
+    return conf.CHECK_BUNDLED_SYSTEM_PKG('socket_wrapper', minversion='1.5.2')
 Build.BuildContext.CHECK_SOCKET_WRAPPER = CHECK_SOCKET_WRAPPER
 
 @conf
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/talloc-2.4.4/buildtools/wafsamba/samba_utils.py 
new/talloc-2.5.0/buildtools/wafsamba/samba_utils.py
--- old/talloc-2.4.4/buildtools/wafsamba/samba_utils.py 2026-01-20 
16:58:35.136438000 +0100
+++ new/talloc-2.5.0/buildtools/wafsamba/samba_utils.py 2026-04-28 
17:46:25.389831800 +0200
@@ -360,43 +360,6 @@
     return result
 
 
-# make sure we have md5. some systems don't have it
-try:
-    from hashlib import md5
-    # Even if hashlib.md5 exists, it may be unusable.
-    # Try to use MD5 function. In FIPS mode this will cause an exception
-    # and we'll get to the replacement code
-    foo = md5(b'abcd')
-except:
-    try:
-        import md5
-        # repeat the same check here, mere success of import is not enough.
-        # Try to use MD5 function. In FIPS mode this will cause an exception
-        foo = md5.md5(b'abcd')
-    except:
-        Context.SIG_NIL = hash('abcd')
-        class replace_md5(object):
-            def __init__(self):
-                self.val = None
-            def update(self, val):
-                self.val = hash((self.val, val))
-            def digest(self):
-                return str(self.val)
-            def hexdigest(self):
-                return self.digest().encode('hex')
-        def replace_h_file(filename):
-            f = open(filename, 'rb')
-            m = replace_md5()
-            while (filename):
-                filename = f.read(100000)
-                m.update(filename)
-            f.close()
-            return m.digest()
-        Utils.md5 = replace_md5
-        Task.md5 = replace_md5
-        Utils.h_file = replace_h_file
-
-
 def LOAD_ENVIRONMENT():
     '''load the configuration environment, allowing access to env vars
        from new commands'''
@@ -472,7 +435,7 @@
                 Logs.zones = ['runner']
             if Logs.verbose > 2:
                 Logs.zones = ['*']
-        elif opt[0].isupper() and opt.find('=') != -1:
+        elif (opt[0].isupper() or opt[0] == '_') and '=' in opt:
             # this allows us to set waf options on the make command line
             # for example, if you do "make FOO=blah", then we set the
             # option 'FOO' in Options.options, to blah. If you look in 
wafsamba/wscript
@@ -507,6 +470,16 @@
                                       _args=_args,
                                       cwd=cwd,
                                       allow_unknown=allow_unknown)
+    commands = []
+    for arg in leftover_args:
+        if '=' in arg and (arg.startswith('_') or arg[0].isupper()):
+            # We assume this is an environment setting argument, not a
+            # build target.
+            k, v = arg.split('=', 1)
+            setattr(options, k, v)
+        else:
+            commands.append(arg)
+
     CHECK_MAKEFLAGS(options)
     if options.jobs == 1:
         #
@@ -526,7 +499,7 @@
                 return
         from waflib import Runner
         Runner.Spawner = NoOpSpawner
-    return options, leftover_args
+    return options, commands
 Options.OptionsContext.parse_cmd_args = wafsamba_options_parse_cmd_args
 
 option_groups = {}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/talloc-2.4.4/buildtools/wafsamba/wafsamba.py 
new/talloc-2.5.0/buildtools/wafsamba/wafsamba.py
--- old/talloc-2.4.4/buildtools/wafsamba/wafsamba.py    2026-01-06 
15:31:26.426848600 +0100
+++ new/talloc-2.5.0/buildtools/wafsamba/wafsamba.py    2026-04-28 
17:46:25.390831700 +0200
@@ -916,7 +916,9 @@
                     header_path=None,
                     vars=None,
                     dep_vars=None,
-                    always=False):
+                    always=False,
+                    symlink=False,
+                    chmod=None):
     '''A generic source generator target'''
 
     if dep_vars is None:
@@ -938,9 +940,18 @@
     if shell:
         rule = "set -e; " + rule
 
+    if symlink:
+        features = 'symlink_generated'
+        use_cache = False
+    else:
+        features = ''
+        use_cache = True
+
     bld.SET_BUILD_GROUP(group)
     t = bld(
         rule=rule,
+        features=features,
+        cache_rule=use_cache,
         source=bld.EXPAND_VARIABLES(source, vars=vars),
         shell=shell,
         target=target,
@@ -949,6 +960,7 @@
         ext_out='.c',
         samba_type='GENERATOR',
         dep_vars = dep_vars,
+        chmod=chmod,
         name=name)
 
     if vars is None:
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/talloc-2.4.4/lib/replace/README 
new/talloc-2.5.0/lib/replace/README
--- old/talloc-2.4.4/lib/replace/README 2026-01-20 16:58:35.160438000 +0100
+++ new/talloc-2.5.0/lib/replace/README 2026-04-28 17:46:25.516834300 +0200
@@ -1,7 +1,7 @@
-This subsystem ensures that we can always use a certain core set of 
-functions and types, that are either provided by the OS or by replacement 
-functions / definitions in this subsystem. The aim is to try to stick 
-to POSIX functions in here as much as possible. Convenience functions 
+This subsystem ensures that we can always use a certain core set of
+functions and types, that are either provided by the OS or by replacement
+functions / definitions in this subsystem. The aim is to try to stick
+to POSIX functions in here as much as possible. Convenience functions
 that are available on no platform at all belong in other subsystems
 (such as LIBUTIL).
 
@@ -72,7 +72,7 @@
 realpath
 poll
 setproctitle
-memset_s
+memset_explicit
 
 Types:
 bool
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/talloc-2.4.4/lib/replace/replace.c 
new/talloc-2.5.0/lib/replace/replace.c
--- old/talloc-2.4.4/lib/replace/replace.c      2026-01-20 16:58:35.160438000 
+0100
+++ new/talloc-2.5.0/lib/replace/replace.c      2026-04-28 17:46:25.516834300 
+0200
@@ -1,4 +1,4 @@
-/* 
+/*
    Unix SMB/CIFS implementation.
    replacement routines for broken systems
    Copyright (C) Andrew Tridgell 1992-1998
@@ -8,7 +8,7 @@
      ** NOTE! The following LGPL license applies to the replace
      ** library. This does NOT imply that all of Samba is released
      ** under the LGPL
-   
+
    This library is free software; you can redistribute it and/or
    modify it under the terms of the GNU Lesser General Public
    License as published by the Free Software Foundation; either
@@ -37,6 +37,10 @@
 #include <sys/syscall.h>
 #endif
 
+#ifdef HAVE_SYS_PRCTL_H
+#include <sys/prctl.h>
+#endif
+
 #ifdef _WIN32
 #define mkdir(d,m) _mkdir(d)
 #endif
@@ -91,7 +95,7 @@
 #endif
 
 #ifndef HAVE_STRLCAT
-/* like strncat but does not 0 fill the buffer and always null 
+/* like strncat but does not 0 fill the buffer and always null
    terminates. bufsize is the length of the buffer, which should
    be one more than the maximum resulting string length */
 size_t rep_strlcat(char *d, const char *s, size_t bufsize)
@@ -116,7 +120,7 @@
 
 #ifndef HAVE_MKTIME
 /*******************************************************************
-a mktime() replacement for those who don't have it - contributed by 
+a mktime() replacement for those who don't have it - contributed by
 C.A. Lademann <[email protected]>
 Corrections by [email protected]
 ********************************************************************/
@@ -137,7 +141,7 @@
     return((time_t)-1);
 
   n = t->tm_year + 1900 - 1;
-  epoch = (t->tm_year - 70) * YEAR + 
+  epoch = (t->tm_year - 70) * YEAR +
     ((n / 4 - n / 100 + n / 400) - (1969 / 4 - 1969 / 100 + 1969 / 400)) * DAY;
 
   y = t->tm_year + 1900;
@@ -147,7 +151,7 @@
     epoch += mon [m] * DAY;
     if(m == 1 && y % 4 == 0 && (y % 100 != 0 || y % 400 == 0))
       epoch += DAY;
-    
+
     if(++m > 11) {
       m = 0;
       y++;
@@ -156,7 +160,7 @@
 
   epoch += (t->tm_mday - 1) * DAY;
   epoch += t->tm_hour * HOUR + t->tm_min * MINUTE + t->tm_sec;
-  
+
   if((u = localtime(&epoch)) != NULL) {
     t->tm_sec = u->tm_sec;
     t->tm_min = u->tm_min;
@@ -176,7 +180,7 @@
 
 #ifndef HAVE_INITGROUPS
 /****************************************************************************
- some systems don't have an initgroups call 
+ some systems don't have an initgroups call
 ****************************************************************************/
 int rep_initgroups(char *name, gid_t id)
 {
@@ -194,7 +198,7 @@
        int    i,j;
        struct group *g;
        char   *gr;
-       
+
        if((grouplst = malloc(sizeof(gid_t) * max_gr)) == NULL) {
                errno = ENOMEM;
                return -1;
@@ -250,9 +254,9 @@
 
        if (d < s) {
                /* we can forward copy */
-               if (s-d >= sizeof(int) && 
-                   !(s%sizeof(int)) && 
-                   !(d%sizeof(int)) && 
+               if (s-d >= sizeof(int) &&
+                   !(s%sizeof(int)) &&
+                   !(d%sizeof(int)) &&
                    !(size%sizeof(int))) {
                        /* do it all as words */
                        int *idest = (int *)dest;
@@ -267,9 +271,9 @@
                }
        } else {
                /* must backward copy */
-               if (d-s >= sizeof(int) && 
-                   !(s%sizeof(int)) && 
-                   !(d%sizeof(int)) && 
+               if (d-s >= sizeof(int) &&
+                   !(s%sizeof(int)) &&
+                   !(d%sizeof(int)) &&
                    !(size%sizeof(int))) {
                        /* do it all as words */
                        int *idest = (int *)dest;
@@ -281,7 +285,7 @@
                        char *cdest = (char *)dest;
                        char *csrc = (char *)src;
                        for (i=size-1;i>=0;i--) cdest[i] = csrc[i];
-               }      
+               }
        }
        return(dest);
 }
@@ -334,16 +338,16 @@
  size_t rep_strnlen(const char *s, size_t max)
 {
         size_t len;
-  
+
         for (len = 0; len < max; len++) {
                 if (s[len] == '\0') {
                         break;
                 }
         }
-        return len;  
+        return len;
 }
 #endif
-  
+
 #ifndef HAVE_STRNDUP
 /**
  Some platforms don't have strndup.
@@ -351,7 +355,7 @@
 char *rep_strndup(const char *s, size_t n)
 {
        char *ret;
-       
+
        n = strnlen(s, n);
        ret = malloc(n+1);
        if (!ret)
@@ -407,7 +411,7 @@
 
 /*****************************************************************
  Possibly replace mkstemp if it is broken.
-*****************************************************************/  
+*****************************************************************/
 
 #ifndef HAVE_SECURE_MKSTEMP
 int rep_mkstemp(char *template)
@@ -425,7 +429,7 @@
 char *rep_mkdtemp(char *template)
 {
        char *dname;
-       
+
        if ((dname = mktemp(template))) {
                if (mkdir(dname, 0700) >= 0) {
                        return dname;
@@ -532,7 +536,7 @@
 {
 #ifdef HAVE_STRTOQ
        return strtoq(str, endptr, base);
-#elif defined(HAVE___STRTOLL) 
+#elif defined(HAVE___STRTOLL)
        return __strtoll(str, endptr, base);
 #elif SIZEOF_LONG == SIZEOF_LONG_LONG
        return (long long int) strtol(str, endptr, base);
@@ -568,7 +572,7 @@
 {
 #ifdef HAVE_STRTOUQ
        return strtouq(str, endptr, base);
-#elif defined(HAVE___STRTOULL) 
+#elif defined(HAVE___STRTOULL)
        return __strtoull(str, endptr, base);
 #elif SIZEOF_LONG == SIZEOF_LONG_LONG
        return (unsigned long long int) strtoul(str, endptr, base);
@@ -599,7 +603,7 @@
 #endif /* HAVE_STRTOULL */
 
 #ifndef HAVE_SETENV
-int rep_setenv(const char *name, const char *value, int overwrite) 
+int rep_setenv(const char *name, const char *value, int overwrite)
 {
        char *p;
        size_t l1, l2;
@@ -644,10 +648,10 @@
        for (i=0;environ[i];i++) /* noop */ ;
 
        count=i;
-       
+
        for (i=0;i<count;) {
                if (strncmp(environ[i], name, len) == 0 && environ[i][len] == 
'=') {
-                       /* note: we do _not_ free the old variable here. It is 
unsafe to 
+                       /* note: we do _not_ free the old variable here. It is 
unsafe to
                           do so, as the pointer may not have come from malloc 
*/
                        memmove(&environ[i], &environ[i+1], 
(count-i)*sizeof(char *));
                        count--;
@@ -688,7 +692,7 @@
 #endif
 
 #ifndef HAVE_DUP2
-int rep_dup2(int oldfd, int newfd) 
+int rep_dup2(int oldfd, int newfd)
 {
        errno = ENOSYS;
        return -1;
@@ -944,44 +948,201 @@
 #ifndef HAVE_SETPROCTITLE
 void rep_setproctitle(const char *fmt, ...)
 {
+#if defined(HAVE_PRCTL) && defined(PR_SET_MM_MAP) && defined(__NR_brk)
+       /*
+        * Implementation based on setproctitle from lcx under LGPL-2.1+
+        * https://github.com/lxc/lxc/
+        *
+        * Using PR_SET_MM_MAP requires CAP_SYS_RESOURCE.
+        */
+       static char *proctitle = NULL;
+       char *tmp_proctitle = NULL;
+       char buf[2048] = {0};
+       char title[2048] = {0};
+       va_list ap;
+       char *ptr = NULL;
+       FILE *f = NULL;
+       size_t title_len;
+       int ret = 0;
+       struct prctl_mm_map prctl_map = {
+               .exe_fd = -1,
+       };
+       long brk_val = 0;
+       /* See `man proc_pid_stat.5` */
+       unsigned long start_code = 0;            // 26
+       unsigned long end_code = 0;              // 27
+       unsigned long start_stack = 0;           // 28
+
+       unsigned long start_data = 0;            // 45
+       unsigned long end_data = 0;              // 46
+       unsigned long start_brk = 0;             // 47
+       unsigned long arg_start = 0;             // 48
+       unsigned long arg_end = 0;               // 49
+       unsigned long env_start = 0;             // 50
+       unsigned long env_end = 0;               // 51
+
+       f = fopen("/proc/self/stat", "r");
+       if (f == NULL) {
+               return;
+       }
+
+       ptr = fgets(buf, sizeof(buf), f);
+       fclose(f);
+       if (ptr == NULL) {
+               return;
+       }
+
+       /*
+        * Find the last ')' to skip the comm field which can contain spaces and
+        * maybe ')'.
+        */
+       ptr = strrchr(buf, ')');
+       if (ptr == NULL || ptr[1] == '\0') {
+               return;
+       }
+       ptr += 2; // Skip ') '
+
+       /* See `man proc_pid_stat.5` */
+       ret = sscanf(
+               ptr,
+               "%*c "        // 3 (state)
+               "%*d "        // 4 (ppid)
+               "%*d "        // 5 (pgrp)
+               "%*d "        // 6 (session)
+               "%*d "        // 7 (tty_nr)
+               "%*d "        // 8 (tpgid)
+               "%*u "        // 9 (flags)
+               "%*u "        // 10 (minflt)
+               "%*u "        // 11 (cminflt)
+               "%*u "        // 12 (majflt)
+               "%*u "        // 13 (cmajflt)
+               "%*u "        // 14 (utime)
+               "%*u "        // 15 (stime)
+               "%*d "        // 16 (cutime)
+               "%*d "        // 17 (cstime)
+               "%*d "        // 18 (priority)
+               "%*d "        // 19 (nice)
+               "%*d "        // 20 (num_threads)
+               "%*d "        // 21 (itrealvalue)
+               "%*u "        // 22 (starttime)
+               "%*u "        // 23 (vsize)
+               "%*d "        // 24 (rss)
+               "%*u "        // 25 (rsslim)
+               "%lu "        // 26 (start_code)
+               "%lu "        // 27 (end_code)
+               "%lu "        // 28 (start_stack)
+               "%*u "        // 29 (kstkesp)
+               "%*u "        // 30 (kstkeip)
+               "%*u "        // 31 (signal)
+               "%*u "        // 32 (blocked)
+               "%*u "        // 33 (sigignore)
+               "%*u "        // 34 (sigcatch)
+               "%*u "        // 35 (wchan)
+               "%*u "        // 36 (nswap)
+               "%*u "        // 37 (cnswap)
+               "%*d "        // 38 (exit_signal)
+               "%*d "        // 39 (processor)
+               "%*d "        // 40 (rt_priority)
+               "%*u "        // 41 (policy)
+               "%*u "        // 42 (delayacct_blkio_ticks)
+               "%*u "        // 43 (guest_time)
+               "%*d "        // 44 (cguest_time)
+               "%lu "        // 45 (start_data)
+               "%lu "        // 46 (end_data)
+               "%lu "        // 47 (start_brk)
+               "%lu "        // 48 (arg_start)
+               "%lu "        // 49 (arg_end)
+               "%lu "        // 50 (env_start)
+               "%lu",        // 51 (env_end)
+               &start_code,  // 26
+               &end_code,    // 27
+               &start_stack, // 28
+               &start_data,  // 45
+               &end_data,    // 46
+               &start_brk,   // 47
+               &arg_start,   // 48
+               &arg_end,     // 49
+               &env_start,   // 50
+               &env_end      // 51
+       );
+       if (ret != 10) {
+               return;
+       }
+
+       va_start(ap, fmt);
+       ret = vsnprintf(title, sizeof(title), fmt, ap);
+       va_end(ap);
+       if (ret <= 0) {
+               return;
+       }
+       /*
+        * Include the null byte here, because in the calculations below
+        * we want to have room for it.
+        */
+       title_len = ret + 1;
+
+       /* This will leak memory */
+       tmp_proctitle = realloc(proctitle, title_len);
+       if (tmp_proctitle == NULL) {
+               return;
+       }
+       proctitle = tmp_proctitle;
+
+       arg_start = (uint64_t)proctitle;
+       arg_end = arg_start + title_len;
+
+       brk_val = syscall(__NR_brk, 0);
+       if (brk_val < 0) {
+               return;
+       }
+
+       prctl_map = (struct prctl_mm_map) {
+               .start_code = start_code,
+               .end_code = end_code,
+               .start_stack = start_stack,
+               .start_data = start_data,
+               .end_data = end_data,
+               .start_brk = start_brk,
+               .brk = brk_val,
+               .arg_start = arg_start,
+               .arg_end = arg_end,
+               .env_start = env_start,
+               .env_end = env_end,
+               .auxv = NULL,
+               .auxv_size = 0,
+               .exe_fd = -1,
+       };
+
+       ret = prctl(PR_SET_MM,
+                   PR_SET_MM_MAP,
+                   (long)&prctl_map,
+                   sizeof(prctl_map),
+                   0);
+       if (ret == 0) {
+               strlcpy((char *)arg_start, title, title_len);
+       }
+#endif /* HAVE_PRCTL */
 }
 #endif
+
 #ifndef HAVE_SETPROCTITLE_INIT
 void rep_setproctitle_init(int argc, char *argv[], char *envp[])
 {
 }
 #endif
 
-#ifndef HAVE_MEMSET_S
-# ifndef RSIZE_MAX
-#  define RSIZE_MAX (SIZE_MAX >> 1)
-# endif
-
-int rep_memset_s(void *dest, size_t destsz, int ch, size_t count)
+#ifndef HAVE_MEMSET_EXPLICIT
+void *rep_memset_explicit(void *block, int c, size_t size)
 {
-       if (dest == NULL) {
-               return EINVAL;
-       }
-
-       if (destsz > RSIZE_MAX ||
-           count > RSIZE_MAX ||
-           count > destsz) {
-               return ERANGE;
-       }
-
-#if defined(HAVE_MEMSET_EXPLICIT)
-       memset_explicit(dest, ch, count);
-#else /* HAVE_MEMSET_EXPLICIT */
-       memset(dest, ch, count);
-# if defined(HAVE_GCC_VOLATILE_MEMORY_PROTECTION)
+       void *ptr = memset(block, c, size);
+#ifdef HAVE_GCC_VOLATILE_MEMORY_PROTECTION
        /* See http://llvm.org/bugs/show_bug.cgi?id=15495 */
-       __asm__ volatile("" : : "g"(dest) : "memory");
-# endif /* HAVE_GCC_VOLATILE_MEMORY_PROTECTION */
-#endif /* HAVE_MEMSET_EXPLICIT */
+       __asm__ volatile("" : : "g"(block) : "memory");
+#endif /* HAVE_GCC_VOLATILE_MEMORY_PROTECTION */
 
-       return 0;
+       return ptr;
 }
-#endif /* HAVE_MEMSET_S */
+#endif
 
 #ifndef HAVE_GETPROGNAME
 # ifndef HAVE_PROGRAM_INVOCATION_SHORT_NAME
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/talloc-2.4.4/lib/replace/replace.h 
new/talloc-2.5.0/lib/replace/replace.h
--- old/talloc-2.4.4/lib/replace/replace.h      2026-01-20 16:58:35.160438000 
+0100
+++ new/talloc-2.5.0/lib/replace/replace.h      2026-08-02 15:52:26.998183500 
+0200
@@ -468,6 +468,22 @@
 #endif
 #endif
 
+#ifndef PACKED_STRUCT
+#if __has_attribute(packed) || (__GNUC__ >= 3)
+#define PACKED_STRUCT __attribute__((packed))
+#else
+#define PACKED_STRUCT
+#endif
+#endif
+
+#ifndef _ALIGNED_
+#if __has_attribute(aligned) || (__GNUC__ >= 3)
+#define _ALIGNED_(n) __attribute__((aligned(n)))
+#else
+#define _ALIGNED_(n)
+#endif
+#endif
+
 #if !defined(HAVE_VDPRINTF) || !defined(HAVE_C99_VSNPRINTF)
 #define vdprintf rep_vdprintf
 int rep_vdprintf(int fd, const char *format, va_list ap) PRINTF_ATTRIBUTE(2,0);
@@ -792,6 +808,26 @@
 /** Type-safe version of discard_const */
 #define discard_const_p(type, ptr) ((type *)discard_const(ptr))
 
+/*
+ * Hack to suppress clang cast-align warnings.
+ *
+ * Before using this macro:
+ *    can you copy the data using memcpy?
+ *    can you call talloc_get_type_abort?
+ *
+ * If using
+ *    was the data allocated with talloc/malloc, in that case it should
+ *    be correctly aligned
+ *
+ *    consider using check_alignment from lib/util/alignment.h to verify
+ *    the alignment.
+ *
+ * call via the discard_align_p macro to maintain type safety
+ *
+ */
+#define discard_align(ptr) ((void *)((uintptr_t)(ptr)))
+#define discard_align_p(type, ptr) ((type *)discard_align(ptr))
+
 #ifndef __STRING
 #define __STRING(x)    #x
 #endif
@@ -811,50 +847,50 @@
 /**
  * Zero a structure.
  */
-#define ZERO_STRUCT(x) memset_s((char *)&(x), sizeof(x), 0, sizeof(x))
+#define ZERO_STRUCT(x) memset_explicit((char *)&(x), 0, sizeof(x))
 
 /**
  * Zero a structure given a pointer to the structure.
  */
 #define ZERO_STRUCTP(x) do { \
        if ((x) != NULL) { \
-               memset_s((char *)(x), sizeof(*(x)), 0, sizeof(*(x))); \
+               memset_explicit((char *)(x), 0, sizeof(*(x))); \
        } \
 } while(0)
 
 /**
  * Zero a structure given a pointer to the structure - no zero check
  */
-#define ZERO_STRUCTPN(x) memset_s((char *)(x), sizeof(*(x)), 0, sizeof(*(x)))
+#define ZERO_STRUCTPN(x) memset_explicit((char *)(x), 0, sizeof(*(x)))
 
 /**
  * Zero an array - note that sizeof(array) must work - ie. it must not be a
  * pointer
  */
-#define ZERO_ARRAY(x) memset_s((char *)(x), sizeof(x), 0, sizeof(x))
+#define ZERO_ARRAY(x) memset_explicit((char *)(x), 0, sizeof(x))
 
 /**
  * Zero a given len of an array
  */
-#define ZERO_ARRAY_LEN(x, l) memset_s((char *)(x), (l), 0, (l))
+#define ZERO_ARRAY_LEN(x, l) memset_explicit((char *)(x), 0, (l))
 
 /**
  * Explicitly zero data from memory. This is guaranteed to be not optimized
  * away.
  */
-#define BURN_DATA(x) memset_s((char *)&(x), sizeof(x), 0, sizeof(x))
+#define BURN_DATA(x) memset_explicit((char *)&(x), 0, sizeof(x))
 
 /**
  * Explicitly zero data from memory. This is guaranteed to be not optimized
  * away.
  */
-#define BURN_DATA_SIZE(x, s) memset_s((char *)&(x), (s), 0, (s))
+#define BURN_DATA_SIZE(x, s) memset_explicit((char *)&(x), 0, (s))
 
 /**
  * Explicitly zero data from memory. This is guaranteed to be not optimized
  * away.
  */
-#define BURN_PTR_SIZE(x, s) memset_s((x), (s), 0, (s))
+#define BURN_PTR_SIZE(x, s) memset_explicit((x), 0, (s))
 
 /**
  * Explicitly zero data in string. This is guaranteed to be not optimized
@@ -863,7 +899,7 @@
 #define BURN_STR(x)    do { \
                                if ((x) != NULL) { \
                                        size_t s = strlen(x); \
-                                       memset_s((x), s, 0, s); \
+                                       memset_explicit((x), 0, s); \
                                } \
                        } while(0)
 
@@ -990,9 +1026,9 @@
 void rep_setproctitle_init(int argc, char *argv[], char *envp[]);
 #endif
 
-#ifndef HAVE_MEMSET_S
-#define memset_s rep_memset_s
-int rep_memset_s(void *dest, size_t destsz, int ch, size_t count);
+#ifndef HAVE_MEMSET_EXPLICIT
+#define memset_explicit rep_memset_explicit
+void *rep_memset_explicit(void *block, int c, size_t size);
 #endif
 
 #ifndef HAVE_GETPROGNAME
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/talloc-2.4.4/lib/replace/tests/test_memset_explicit.c 
new/talloc-2.5.0/lib/replace/tests/test_memset_explicit.c
--- old/talloc-2.4.4/lib/replace/tests/test_memset_explicit.c   1970-01-01 
01:00:00.000000000 +0100
+++ new/talloc-2.5.0/lib/replace/tests/test_memset_explicit.c   2026-04-28 
17:46:25.518834400 +0200
@@ -0,0 +1,99 @@
+#include <stdarg.h>
+#include <stddef.h>
+#include <stdint.h>
+#include <setjmp.h>
+#include <cmocka.h>
+
+#include "lib/replace/replace.h"
+
+
+/*
+ * To check that a memset_explicit string is being memset when it
+ * appears unused, we meed to be sneaky in our check -- otherwise the
+ * check counts as a use.
+ *
+ * We are sneaky by using a function that seens to take an int
+ * argument which is really a pointer, and we hide that it is a
+ * pointer by masking it.
+ *
+ * For these tests we don't use talloc because the talloc magic gets
+ * in the way a little bit.
+ */
+
+#define MASK 0x12345678
+
+__attribute__((noinline))
+static void check_memset_explicit(intmax_t p, const char *expected, size_t len)
+{
+       size_t i;
+       char *secret = (char *) (p ^ MASK);
+       for (i = 0; i < len; i++) {
+               assert_int_equal(secret[i], expected[i]);
+       }
+}
+
+
+__attribute__((noinline))
+static char *get_secret(off_t offset)
+{
+       char * secret = malloc(7 + offset);
+       memset(secret, 0, 7 + offset);
+       memcpy(secret + offset, "secret", 7);
+       /* avoiding *this* being elided */
+       print_message("secret is '%s'\n", secret);
+       asm("");
+       return secret;
+}
+
+
+static void test_memset_explicit(void ** state)
+{
+       uintptr_t p;
+       char zeros[7] = {0};
+       char *secret = get_secret(0);
+       p = ((uintptr_t)secret) ^ MASK;
+       memset_explicit(secret, 'o', 3);
+       check_memset_explicit(p, "oooret", 7);
+       memset_explicit(secret, 0, 7);
+       check_memset_explicit(p, zeros, 7);
+       free(secret);
+}
+
+static void test_memset_explicit_double_alloc(void ** state)
+{
+       size_t i, found;
+       uintptr_t p, q;
+       char *secret = get_secret(20);
+       p = (uintptr_t)secret ^ MASK;
+       memset_explicit(secret, 'x', 23);
+       free(secret);
+       /*
+        * Now we malloc the same size again, and hope we got the
+        * block we just freed.
+        */
+       found = 0;
+       for (i = 0; i < 1000; i++) {
+               secret = malloc(27);
+               q = (uintptr_t)secret ^ MASK;
+               if (q == p) {
+                       q = (uintptr_t)(secret + 20) ^ MASK;
+                       check_memset_explicit(q, "xxxret", 7);
+                       found ++;
+               }
+               free(secret);
+       }
+       print_message("found freed pointer %zu/1000 times \n",
+               found);
+}
+
+int main(void)
+{
+       const struct CMUnitTest tests[] = {
+               cmocka_unit_test(test_memset_explicit),
+               cmocka_unit_test(test_memset_explicit_double_alloc),
+       };
+       if (! isatty(1)) {
+               cmocka_set_message_output(CM_OUTPUT_SUBUNIT);
+       }
+       return cmocka_run_group_tests(tests, NULL, NULL);
+}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/talloc-2.4.4/lib/replace/wscript 
new/talloc-2.5.0/lib/replace/wscript
--- old/talloc-2.4.4/lib/replace/wscript        2026-01-20 16:58:35.160438000 
+0100
+++ new/talloc-2.5.0/lib/replace/wscript        2026-08-02 15:52:26.998183500 
+0200
@@ -439,7 +439,7 @@
                        msg='Checking for posix_fallocate-capable libc'):
         conf.CHECK_FUNCS('posix_fallocate')
 
-    conf.CHECK_FUNCS('prctl dirname basename')
+    conf.CHECK_FUNCS('dirname basename')
 
     strlcpy_in_bsd = False
 
@@ -890,7 +890,7 @@
                   'utime', 'utimes', 'dup2', 'chown', 'link', 'readlink',
                   'symlink', 'lchown', 'realpath', 'memmem', 'vdprintf',
                   'dprintf', 'get_current_dir_name', 'copy_file_range',
-                  'strerror_r', 'clock_gettime', 'memset_s'],
+                  'strerror_r', 'clock_gettime', 'memset_explicit'],
     'timegm.c': ['timegm'],
     # Note: C99_VSNPRINTF is not a function, but a special condition
     # for replacement
@@ -973,6 +973,11 @@
                      deps='replace replace-test',
                      install=False)
 
+    bld.SAMBA_BINARY('test_memset_explicit',
+                     source='tests/test_memset_explicit.c',
+                     deps='cmocka replace',
+                     for_selftest=True)
+
     # build replacements for stdint.h and stdbool.h if needed
     bld.SAMBA_GENERATOR('replace_stdint_h',
                         rule='cp ${SRC} ${TGT}',
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/talloc-2.4.4/talloc.c new/talloc-2.5.0/talloc.c
--- old/talloc-2.4.4/talloc.c   2026-01-20 16:58:35.160438000 +0100
+++ new/talloc-2.5.0/talloc.c   2026-07-31 17:51:00.183474300 +0200
@@ -2750,13 +2750,8 @@
        return s;
 }
 
-/*
- * Function to make string-building simple by handling intermediate
- * realloc failures. See for example commit a37ea9d750e1.
- */
-_PUBLIC_ void talloc_asprintf_addbuf(char **ps, const char *fmt, ...)
+static void talloc_vasprintf_addbuf(char **ps, const char *fmt, va_list ap)
 {
-       va_list ap;
        char *s = *ps;
        char *t = NULL;
 
@@ -2764,9 +2759,7 @@
                return;
        }
 
-       va_start(ap, fmt);
        t = talloc_vasprintf_append_buffer(s, fmt, ap);
-       va_end(ap);
 
        if (t == NULL) {
                /* signal failure to the next caller */
@@ -2778,6 +2771,35 @@
 }
 
 /*
+ * Function to make string-building simple by handling intermediate
+ * realloc failures. See for example commit a37ea9d750e1.
+ */
+_PUBLIC_ void talloc_asprintf_addbuf(char **ps, const char *fmt, ...)
+{
+       va_list ap;
+       va_start(ap, fmt);
+       talloc_vasprintf_addbuf(ps, fmt, ap);
+       va_end(ap);
+}
+
+_PUBLIC_ void talloc_asprintf_addsep(char **ps,
+                                    const char *sep,
+                                    const char *fmt,
+                                    ...)
+{
+       va_list ap;
+       char *s = *ps;
+
+       if ((s != NULL) && (s[0] != '\0')) {
+               talloc_asprintf_addbuf(ps, "%s", sep);
+       }
+
+       va_start(ap, fmt);
+       talloc_vasprintf_addbuf(ps, fmt, ap);
+       va_end(ap);
+}
+
+/*
   alloc an array, checking for integer overflow in the array size
 */
 _PUBLIC_ void *_talloc_array(const void *ctx, size_t el_size, unsigned count, 
const char *name)
@@ -2837,7 +2859,7 @@
 
        if (newsize > existing) {
                size_t to_zero = newsize - existing;
-               memset_s(((char *)newptr) + existing, to_zero, 0, to_zero);
+               memset_explicit(((char *)newptr) + existing, 0, to_zero);
        }
 
        return newptr;
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/talloc-2.4.4/talloc.h new/talloc-2.5.0/talloc.h
--- old/talloc-2.4.4/talloc.h   2026-01-06 15:31:26.558850500 +0100
+++ new/talloc-2.5.0/talloc.h   2026-07-31 17:51:00.184474500 +0200
@@ -56,7 +56,7 @@
  */
 
 #define TALLOC_VERSION_MAJOR 2
-#define TALLOC_VERSION_MINOR 4
+#define TALLOC_VERSION_MINOR 5
 
 _PUBLIC_ int talloc_version_major(void);
 _PUBLIC_ int talloc_version_minor(void);
@@ -1626,6 +1626,26 @@
        PRINTF_ATTRIBUTE(2,3);
 
 /**
+ * @brief Build up a string buffer of multiple elements with a separator
+ *
+ * @param[in] ps Pointer to the talloc'ed string to be extended
+ * @param[in] fmt The format string
+ * @param[in] ... The parameters used to fill fmt.
+ *
+ * If you want to build up "a,b,c" from "a", "b" and "c" you have to
+ * take care of the "," with custom code. This function assumes that
+ * "*ps" is prepared with talloc_strdup(.., "") and adds "sep" before
+ * the asprintf if "*ps" is not an empty string.
+ *
+ * It inherits memory allocation behaviour from
+ * talloc_asprintf_addbuf().
+ */
+_PUBLIC_ void talloc_asprintf_addsep(char **ps,
+                                    const char *sep,
+                                    const char *fmt,
+                                    ...) PRINTF_ATTRIBUTE(3, 4);
+
+/**
  * @brief Format a string.
  *
  * This function is the talloc equivalent of the C library function 
asprintf(3).
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/talloc-2.4.4/testsuite.c new/talloc-2.5.0/testsuite.c
--- old/talloc-2.4.4/testsuite.c        2026-01-06 15:31:26.558850500 +0100
+++ new/talloc-2.5.0/testsuite.c        2026-05-26 14:50:11.756024600 +0200
@@ -115,7 +115,6 @@
        } \
 } while (0)
 
-static unsigned int test_abort_count;
 
 #if 0
 static void test_abort_fn(const char *reason)
@@ -133,7 +132,6 @@
 
 static void test_abort_stop(void)
 {
-       test_abort_count = 0;
        talloc_set_abort_fn(NULL);
 }
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/talloc-2.4.4/wscript new/talloc-2.5.0/wscript
--- old/talloc-2.4.4/wscript    2026-01-06 15:31:26.558850500 +0100
+++ new/talloc-2.5.0/wscript    2026-07-31 17:51:00.185474400 +0200
@@ -1,7 +1,7 @@
 #!/usr/bin/env python
 
 APPNAME = 'talloc'
-VERSION = '2.4.4'
+VERSION = '2.5.0'
 
 import os
 import sys

++++++ talloc-python3.5-fix-soabi_name.patch ++++++
--- /var/tmp/diff_new_pack.L4Xd6Y/_old  2026-10-01 17:01:31.257391326 +0200
+++ /var/tmp/diff_new_pack.L4Xd6Y/_new  2026-10-01 17:01:31.263391577 +0200
@@ -1,7 +1,13 @@
-diff -ruNp a/buildtools/wafsamba/wafsamba.py b/buildtools/wafsamba/wafsamba.py
---- a/buildtools/wafsamba/wafsamba.py  2024-05-16 13:52:58.561283248 +0200
-+++ b/buildtools/wafsamba/wafsamba.py  2024-05-16 13:54:32.297195397 +0200
-@@ -309,7 +309,7 @@ def SAMBA_LIBRARY(bld, libname, source,
+---
+ buildtools/wafsamba/samba_python.py |    2 +-
+ buildtools/wafsamba/wafsamba.py     |    2 +-
+ 2 files changed, 2 insertions(+), 2 deletions(-)
+
+Index: talloc-2.4.4/buildtools/wafsamba/wafsamba.py
+===================================================================
+--- talloc-2.4.4.orig/buildtools/wafsamba/wafsamba.py  2026-01-06 
15:31:26.426848600 +0100
++++ talloc-2.4.4/buildtools/wafsamba/wafsamba.py       2026-09-30 
01:16:27.743392982 +0200
+@@ -312,7 +312,7 @@
      if bundled_name is not None:
          pass
      elif target_type == 'PYTHON' or realname or not private_library:
@@ -10,4 +16,17 @@
      else:
          assert (private_library is True and realname is None)
          bundled_name = PRIVATE_NAME(bld, libname.replace('_', '-'))
+Index: talloc-2.4.4/buildtools/wafsamba/samba_python.py
+===================================================================
+--- talloc-2.4.4.orig/buildtools/wafsamba/samba_python.py      2026-01-06 
15:31:26.426848600 +0100
++++ talloc-2.4.4/buildtools/wafsamba/samba_python.py   2026-09-30 
02:02:31.888253384 +0200
+@@ -58,7 +58,7 @@
+     abi_pattern = os.path.splitext(conf.env['pyext_PATTERN'])[0]
+     conf.env['PYTHON_SO_ABI_FLAG'] = abi_pattern % ''
+     conf.env['PYTHON_LIBNAME_SO_ABI_FLAG'] = (
+-        conf.env['PYTHON_SO_ABI_FLAG'].replace('_', '-'))
++        conf.env['PYTHON_SO_ABI_FLAG'])
+ 
+     for lib in conf.env['LINKFLAGS_PYEMBED']:
+         if lib.startswith('-L'):
 

Reply via email to