Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package yq for openSUSE:Factory checked in 
at 2026-07-28 17:57:08
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/yq (Old)
 and      /work/SRC/openSUSE:Factory/.yq.new.2004 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "yq"

Tue Jul 28 17:57:08 2026 rev:28 rq:1367922 version:4.53.3

Changes:
--------
--- /work/SRC/openSUSE:Factory/yq/yq.changes    2026-07-26 11:32:15.518535667 
+0200
+++ /work/SRC/openSUSE:Factory/.yq.new.2004/yq.changes  2026-07-28 
18:04:26.102231376 +0200
@@ -1,0 +2,6 @@
+Mon Jul 27 06:20:41 UTC 2026 - Egbert Eich <[email protected]>
+
+- Update the golang.org/x/net dependency to version v0.57.0
+  to fix CVE-2026-39821 for good (bsc#1267199).
+
+-------------------------------------------------------------------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.lrSQy2/_old  2026-07-28 18:04:26.806256009 +0200
+++ /var/tmp/diff_new_pack.lrSQy2/_new  2026-07-28 18:04:26.810256150 +0200
@@ -1,5 +1,5 @@
-mtime: 1784963510
-commit: e822d2c7367bbc7452d6187bba2e3a46c01bf8de34cca43fe2fddace3efccf06
+mtime: 1785134146
+commit: 0de16494f362c5c2de08e60f1e7b72994a6150746581830bc09eeb2fee2a8e49
 url: https://src.opensuse.org/utilities/yq.git
 revision: main
 

++++++ _service ++++++
--- /var/tmp/diff_new_pack.lrSQy2/_old  2026-07-28 18:04:26.854257689 +0200
+++ /var/tmp/diff_new_pack.lrSQy2/_new  2026-07-28 18:04:26.858257829 +0200
@@ -2,7 +2,7 @@
   <service name="download_files" mode="manual"/>
   <service name="go_modules" mode="manual">
    <param name="replace">
-    golang.org/x/net=golang.org/x/[email protected]
+    golang.org/x/net=golang.org/x/[email protected]
    </param>
    <param name="replace">
     golang.org/x/text=golang.org/x/[email protected]

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-07-27 08:35:46.000000000 +0200
@@ -0,0 +1,4 @@
+*.obscpio
+*.osc
+_build.*
+.pbuild

++++++ vendor.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/go.mod new/go.mod
--- old/go.mod  2026-07-25 09:07:07.000000000 +0200
+++ new/go.mod  2026-07-27 08:26:37.000000000 +0200
@@ -22,7 +22,7 @@
        go.yaml.in/yaml/v4 v4.0.0-rc.4
        golang.org/x/mod v0.37.0
        golang.org/x/net v0.56.0
-       golang.org/x/text v0.37.0
+       golang.org/x/text v0.40.0
 )
 
 require (
@@ -34,12 +34,12 @@
        github.com/mattn/go-isatty v0.0.20 // indirect
        github.com/mitchellh/go-wordwrap v1.0.1 // indirect
        golang.org/x/sync v0.21.0 // indirect
-       golang.org/x/sys v0.46.0 // indirect
+       golang.org/x/sys v0.47.0 // indirect
        golang.org/x/tools v0.47.0 // indirect
 )
 
 go 1.25.0
 
-replace golang.org/x/net => golang.org/x/net v0.55.0
+replace golang.org/x/net => golang.org/x/net v0.57.0
 
 replace golang.org/x/text => golang.org/x/text v0.39.0
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/go.sum new/go.sum
--- old/go.sum  2026-07-25 09:07:07.000000000 +0200
+++ new/go.sum  2026-07-27 08:26:37.000000000 +0200
@@ -72,13 +72,13 @@
 go.yaml.in/yaml/v4 v4.0.0-rc.4/go.mod 
h1:aZqd9kCMsGL7AuUv/m/PvWLdg5sjJsZ4oHDEnfPPfY0=
 golang.org/x/mod v0.37.0 h1:vF1DjpVEshcIqoEaauuHebaLk1O1forxjxBaVn884JQ=
 golang.org/x/mod v0.37.0/go.mod h1:m8S8VeM9r4dzDwjrKO0a1sZP3YjeMamRRlD+fmR2Q/0=
-golang.org/x/net v0.55.0 h1:bcvxaJn3e1U6InsFWt1JUq1aSjnRxLzT2rtD2KfkDF8=
-golang.org/x/net v0.55.0/go.mod h1:L5U2KuzuOe1lY7Z+aWVIKK6qEeJXnXV9yzGA+WCHJww=
+golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE=
+golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU=
 golang.org/x/sync v0.21.0 h1:HLII4xRRTtCRkxYp4HNFF0Js/Og6q2i++KXbg0gHCwM=
 golang.org/x/sync v0.21.0/go.mod 
h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
 golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
-golang.org/x/sys v0.46.0 h1:noSf2Fq6F8DBgS+LysIkx7rIExoNHJsxOAtPp4rthXw=
-golang.org/x/sys v0.46.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
+golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
+golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
 golang.org/x/text v0.39.0 h1:UbZz4pLOvn600D6Oh6GGEI6VAmndrEBLv8/6BEXzyus=
 golang.org/x/text v0.39.0/go.mod 
h1:3UwRclnC2g0TU9x8PZiyfOajCd1zaUNHF9cvqcQZ+ZM=
 golang.org/x/tools v0.47.0 h1:7Kn5x/d1svx/PzryTsqeoZN4TZwqeH5pGWjefhLi/1Q=
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/net/html/entity.go 
new/vendor/golang.org/x/net/html/entity.go
--- old/vendor/golang.org/x/net/html/entity.go  2026-07-25 09:07:07.000000000 
+0200
+++ new/vendor/golang.org/x/net/html/entity.go  2026-07-27 08:26:37.000000000 
+0200
@@ -2156,9 +2156,8 @@
 
 // HTML entities that are two unicode codepoints.
 var entity2 = map[string][2]rune{
-       // TODO(nigeltao): Handle replacements that are wider than their names.
-       // "nLt;":                     {'\u226A', '\u20D2'},
-       // "nGt;":                     {'\u226B', '\u20D2'},
+       "nLt;":                     {'\u226A', '\u20D2'},
+       "nGt;":                     {'\u226B', '\u20D2'},
        "NotEqualTilde;":           {'\u2242', '\u0338'},
        "NotGreaterFullEqual;":     {'\u2267', '\u0338'},
        "NotGreaterGreater;":       {'\u226B', '\u0338'},
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/net/html/escape.go 
new/vendor/golang.org/x/net/html/escape.go
--- old/vendor/golang.org/x/net/html/escape.go  2026-07-25 09:07:07.000000000 
+0200
+++ new/vendor/golang.org/x/net/html/escape.go  2026-07-27 08:26:37.000000000 
+0200
@@ -6,6 +6,7 @@
 
 import (
        "bytes"
+       "slices"
        "strings"
        "unicode/utf8"
 )
@@ -50,25 +51,24 @@
        // 0x0D->'\u000D' is a no-op.
 }
 
-// unescapeEntity reads an entity like "&lt;" from b[src:] and writes the
-// corresponding "<" to b[dst:], returning the incremented dst and src cursors.
-// Precondition: b[src] == '&' && dst <= src.
-// attribute should be true if parsing an attribute value.
-func unescapeEntity(b []byte, dst, src int, attribute bool) (dst1, src1 int) {
+// unescapeEntity attempts to consume a character reference from s[src:],
+// returning the rune, potential second rune, and number of bytes consumed
+// (which indicates the length of the character reference). It is assumed that
+// the first byte of s is '&'. attribute should be true if parsing an attribute
+// value.
+func unescapeEntity(s []byte, attribute bool) (rune, rune, int) {
        // 
https://html.spec.whatwg.org/multipage/syntax.html#consume-a-character-reference
 
        // i starts at 1 because we already know that s[0] == '&'.
-       i, s := 1, b[src:]
+       i := 1
 
        if len(s) <= 1 {
-               b[dst] = b[src]
-               return dst + 1, src + 1
+               return '&', 0, 1
        }
 
        if s[i] == '#' {
-               if len(s) <= 3 { // We need to have at least "&#.".
-                       b[dst] = b[src]
-                       return dst + 1, src + 1
+               if len(s) <= 2 { // We need to have at least "&#".
+                       return '&', 0, 1
                }
                i++
                c := s[i]
@@ -78,34 +78,43 @@
                        i++
                }
 
+               i0 := i
                x := '\x00'
                for i < len(s) {
                        c = s[i]
-                       i++
+                       var d rune
+                       var mult rune
                        if hex {
+                               mult = 16
                                if '0' <= c && c <= '9' {
-                                       x = 16*x + rune(c) - '0'
-                                       continue
+                                       d = rune(c) - '0'
                                } else if 'a' <= c && c <= 'f' {
-                                       x = 16*x + rune(c) - 'a' + 10
-                                       continue
+                                       d = rune(c) - 'a' + 10
                                } else if 'A' <= c && c <= 'F' {
-                                       x = 16*x + rune(c) - 'A' + 10
-                                       continue
+                                       d = rune(c) - 'A' + 10
+                               } else {
+                                       break
+                               }
+                       } else {
+                               mult = 10
+                               if '0' <= c && c <= '9' {
+                                       d = rune(c) - '0'
+                               } else {
+                                       break
                                }
-                       } else if '0' <= c && c <= '9' {
-                               x = 10*x + rune(c) - '0'
-                               continue
                        }
-                       if c != ';' {
-                               i--
+                       if x <= 0x10FFFF {
+                               x = mult*x + d
                        }
-                       break
+                       i++
                }
 
-               if i <= 3 { // No characters matched.
-                       b[dst] = b[src]
-                       return dst + 1, src + 1
+               if i == i0 { // No characters matched.
+                       return '&', 0, 1
+               }
+
+               if i < len(s) && s[i] == ';' {
+                       i++
                }
 
                if 0x80 <= x && x <= 0x9F {
@@ -116,7 +125,7 @@
                        x = '\uFFFD'
                }
 
-               return dst + utf8.EncodeRune(b[dst:], x), src + i
+               return x, 0, i
        }
 
        // Consume the maximum number of characters possible, with the
@@ -141,10 +150,9 @@
        } else if attribute && entityName[len(entityName)-1] != ';' && len(s) > 
i && s[i] == '=' {
                // No-op.
        } else if x := entity[entityName]; x != 0 {
-               return dst + utf8.EncodeRune(b[dst:], x), src + i
+               return x, 0, i
        } else if x := entity2[entityName]; x[0] != 0 {
-               dst1 := dst + utf8.EncodeRune(b[dst:], x[0])
-               return dst1 + utf8.EncodeRune(b[dst1:], x[1]), src + i
+               return x[0], x[1], i
        } else if !attribute {
                maxLen := len(entityName) - 1
                if maxLen > longestEntityWithoutSemicolon {
@@ -152,35 +160,67 @@
                }
                for j := maxLen; j > 1; j-- {
                        if x := entity[entityName[:j]]; x != 0 {
-                               return dst + utf8.EncodeRune(b[dst:], x), src + 
j + 1
+                               return x, 0, j + 1
                        }
                }
        }
 
-       dst1, src1 = dst+i, src+i
-       copy(b[dst:dst1], b[src:src1])
-       return dst1, src1
+       return '&', 0, 1
 }
 
-// unescape unescapes b's entities in-place, so that "a&lt;b" becomes "a<b".
-// attribute should be true if parsing an attribute value.
+// unescape unescapes b's entites, so that "a&lt;b" becomes "a<b". It attempts
+// to do so in place, but if the unescaped value is longer than the input it
+// allocates a new slice. attribute should be true if parsing an attribute
+// value.
 func unescape(b []byte, attribute bool) []byte {
-       for i, c := range b {
-               if c == '&' {
-                       dst, src := unescapeEntity(b, i, i, attribute)
-                       for src < len(b) {
-                               c := b[src]
-                               if c == '&' {
-                                       dst, src = unescapeEntity(b, dst, src, 
attribute)
-                               } else {
-                                       b[dst] = c
-                                       dst, src = dst+1, src+1
-                               }
+       firstAmp := slices.Index(b, '&')
+       if firstAmp == -1 {
+               return b
+       }
+
+       out := b[:firstAmp]
+       src := firstAmp
+       reusingB := true
+       for src < len(b) {
+               if b[src] != '&' {
+                       out = append(out, b[src])
+                       src++
+                       continue
+               }
+
+               r1, r2, entityNameLen := unescapeEntity(b[src:], attribute)
+               if entityNameLen == 1 && r1 == '&' {
+                       // Not an entity
+                       out = append(out, '&')
+                       src++
+                       continue
+               }
+
+               // Compute replacement length
+               replLen := utf8.RuneLen(r1)
+               if r2 != 0 {
+                       replLen += utf8.RuneLen(r2)
+               }
+
+               // If the name of the entity is shorter than the width of the
+               // replacement runes then we need to expand the output slice to
+               // fit the replacement.
+               if replLen > entityNameLen {
+                       if reusingB {
+                               out = slices.Clone(out)
+                               reusingB = false
                        }
-                       return b[0:dst]
+                       out = slices.Grow(out, replLen)
                }
+               out = utf8.AppendRune(out, r1)
+               if r2 != 0 {
+                       out = utf8.AppendRune(out, r2)
+               }
+
+               src += entityNameLen
        }
-       return b
+
+       return out
 }
 
 // lower lower-cases the A-Z bytes in b in-place, so that "aBc" becomes "abc".
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/net/html/foreign.go 
new/vendor/golang.org/x/net/html/foreign.go
--- old/vendor/golang.org/x/net/html/foreign.go 2026-07-25 09:07:07.000000000 
+0200
+++ new/vendor/golang.org/x/net/html/foreign.go 2026-07-27 08:26:37.000000000 
+0200
@@ -23,7 +23,7 @@
                }
                switch a.Key {
                case "xlink:actuate", "xlink:arcrole", "xlink:href", 
"xlink:role", "xlink:show",
-                       "xlink:title", "xlink:type", "xml:base", "xml:lang", 
"xml:space", "xmlns:xlink":
+                       "xlink:title", "xlink:type", "xml:lang", "xml:space", 
"xmlns:xlink":
                        j := strings.Index(a.Key, ":")
                        aa[i].Namespace = a.Key[:j]
                        aa[i].Key = a.Key[j+1:]
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/net/html/parse.go 
new/vendor/golang.org/x/net/html/parse.go
--- old/vendor/golang.org/x/net/html/parse.go   2026-07-25 09:07:07.000000000 
+0200
+++ new/vendor/golang.org/x/net/html/parse.go   2026-07-27 08:26:37.000000000 
+0200
@@ -63,7 +63,7 @@
 // Stop tags for use in popUntil. These come from section 12.2.4.2.
 var (
        defaultScopeStopTags = map[string][]a.Atom{
-               "":     {a.Applet, a.Caption, a.Html, a.Table, a.Td, a.Th, 
a.Marquee, a.Object, a.Template},
+               "":     {a.Applet, a.Caption, a.Html, a.Table, a.Td, a.Th, 
a.Marquee, a.Object, a.Template, a.Select},
                "math": {a.AnnotationXml, a.Mi, a.Mn, a.Mo, a.Ms, a.Mtext},
                "svg":  {a.Desc, a.ForeignObject, a.Title},
        }
@@ -78,7 +78,6 @@
        tableScope
        tableRowScope
        tableBodyScope
-       selectScope
 )
 
 // popUntil pops the stack of open elements at the highest element whose tag
@@ -133,10 +132,6 @@
                                if tagAtom == a.Html || tagAtom == a.Table || 
tagAtom == a.Template {
                                        return -1
                                }
-                       case selectScope:
-                               if tagAtom != a.Optgroup && tagAtom != a.Option 
{
-                                       return -1
-                               }
                        default:
                                panic(fmt.Sprintf("html: internal error: 
indexOfElementInScope unknown scope: %d", s))
                        }
@@ -460,21 +455,6 @@
                }
 
                switch n.DataAtom {
-               case a.Select:
-                       if !last {
-                               for ancestor, first := n, p.oe[0]; ancestor != 
first; {
-                                       ancestor = p.oe[p.oe.index(ancestor)-1]
-                                       switch ancestor.DataAtom {
-                                       case a.Template:
-                                               p.im = inSelectIM
-                                               return
-                                       case a.Table:
-                                               p.im = inSelectInTableIM
-                                               return
-                                       }
-                               }
-                       }
-                       p.im = inSelectIM
                case a.Td, a.Th:
                        // TODO: remove this divergence from the HTML5 spec.
                        //
@@ -1002,7 +982,10 @@
                        p.popUntil(buttonScope, a.P)
                        p.addElement()
                case a.Button:
-                       p.popUntil(defaultScope, a.Button)
+                       if p.elementInScope(defaultScope, a.Button) {
+                               p.generateImpliedEndTags()
+                               p.popUntil(defaultScope, a.Button)
+                       }
                        p.reconstructActiveFormattingElements()
                        p.addElement()
                        p.framesetOK = false
@@ -1040,7 +1023,18 @@
                        p.framesetOK = false
                        p.im = inTableIM
                        return true
-               case a.Area, a.Br, a.Embed, a.Img, a.Input, a.Keygen, a.Wbr:
+               case a.Area, a.Br, a.Embed, a.Img, a.Keygen, a.Wbr:
+                       p.reconstructActiveFormattingElements()
+                       p.addElement()
+                       p.oe.pop()
+                       p.acknowledgeSelfClosingTag()
+                       p.framesetOK = false
+               case a.Input:
+                       if p.fragment && p.context.DataAtom == a.Select {
+                               // Ignore the token.
+                               return true
+                       }
+                       p.popUntil(defaultScope, a.Select)
                        p.reconstructActiveFormattingElements()
                        p.addElement()
                        p.oe.pop()
@@ -1061,7 +1055,13 @@
                        p.oe.pop()
                        p.acknowledgeSelfClosingTag()
                case a.Hr:
-                       p.popUntil(buttonScope, a.P)
+                       if p.elementInScope(buttonScope, a.P) {
+                               p.generateImpliedEndTags("p")
+                               p.popUntil(defaultScope, a.P)
+                       }
+                       if p.elementInScope(defaultScope, a.Select) {
+                               p.generateImpliedEndTags()
+                       }
                        p.addElement()
                        p.oe.pop()
                        p.acknowledgeSelfClosingTag()
@@ -1095,13 +1095,30 @@
                        // Don't let the tokenizer go into raw text mode when 
scripting is disabled.
                        p.tokenizer.NextIsNotRawText()
                case a.Select:
+                       if p.fragment && p.context.DataAtom == a.Select {
+                               // Ignore the token.
+                               return true
+                       } else if p.popUntil(defaultScope, a.Select) {
+                               return true
+                       }
                        p.reconstructActiveFormattingElements()
                        p.addElement()
                        p.framesetOK = false
-                       p.im = inSelectIM
                        return true
-               case a.Optgroup, a.Option:
-                       if p.top().DataAtom == a.Option {
+               case a.Option:
+                       if p.elementInScope(defaultScope, a.Select) {
+                               p.generateImpliedEndTags("optgroup")
+                               // If oe has option element in scope, parse 
error?
+                       } else if p.top().DataAtom == a.Option {
+                               p.oe.pop()
+                       }
+                       p.reconstructActiveFormattingElements()
+                       p.addElement()
+               case a.Optgroup:
+                       if p.elementInScope(defaultScope, a.Select) {
+                               p.generateImpliedEndTags()
+                               // If oe has option or optgroup element in 
scope, parse error?
+                       } else if p.top().DataAtom == a.Option {
                                p.oe.pop()
                        }
                        p.reconstructActiveFormattingElements()
@@ -1149,7 +1166,12 @@
                                return false
                        }
                        return true
-               case a.Address, a.Article, a.Aside, a.Blockquote, a.Button, 
a.Center, a.Details, a.Dialog, a.Dir, a.Div, a.Dl, a.Fieldset, a.Figcaption, 
a.Figure, a.Footer, a.Header, a.Hgroup, a.Listing, a.Main, a.Menu, a.Nav, a.Ol, 
a.Pre, a.Search, a.Section, a.Summary, a.Ul:
+               case a.Address, a.Article, a.Aside, a.Blockquote, a.Button, 
a.Center, a.Details, a.Dialog, a.Dir, a.Div, a.Dl, a.Fieldset, a.Figcaption, 
a.Figure, a.Footer, a.Header, a.Hgroup, a.Listing, a.Main, a.Menu, a.Nav, a.Ol, 
a.Pre, a.Search, a.Section, a.Select, a.Summary, a.Ul:
+                       if !p.elementInScope(defaultScope, p.tok.DataAtom) {
+                               // Ignore the token.
+                               return true
+                       }
+                       p.generateImpliedEndTags()
                        p.popUntil(defaultScope, p.tok.DataAtom)
                case a.Form:
                        if p.oe.contains(a.Template) {
@@ -1488,17 +1510,6 @@
                        }
                        p.addElement()
                        p.form = p.oe.pop()
-               case a.Select:
-                       p.reconstructActiveFormattingElements()
-                       switch p.top().DataAtom {
-                       case a.Table, a.Tbody, a.Tfoot, a.Thead, a.Tr:
-                               p.fosterParenting = true
-                       }
-                       p.addElement()
-                       p.fosterParenting = false
-                       p.framesetOK = false
-                       p.im = inSelectInTableIM
-                       return true
                }
        case EndTagToken:
                switch p.tok.DataAtom {
@@ -1547,12 +1558,6 @@
                        p.clearActiveFormattingElements()
                        p.im = inTableIM
                        return false
-               case a.Select:
-                       p.reconstructActiveFormattingElements()
-                       p.addElement()
-                       p.framesetOK = false
-                       p.im = inSelectInTableIM
-                       return true
                }
        case EndTagToken:
                switch p.tok.DataAtom {
@@ -1762,12 +1767,6 @@
                        }
                        // Ignore the token.
                        return true
-               case a.Select:
-                       p.reconstructActiveFormattingElements()
-                       p.addElement()
-                       p.framesetOK = false
-                       p.im = inSelectInTableIM
-                       return true
                }
        case EndTagToken:
                switch p.tok.DataAtom {
@@ -1798,118 +1797,6 @@
        return inBodyIM(p)
 }
 
-// Section 12.2.6.4.16.
-func inSelectIM(p *parser) bool {
-       switch p.tok.Type {
-       case TextToken:
-               p.addText(strings.Replace(p.tok.Data, "\x00", "", -1))
-       case StartTagToken:
-               switch p.tok.DataAtom {
-               case a.Html:
-                       return inBodyIM(p)
-               case a.Option:
-                       if p.top().DataAtom == a.Option {
-                               p.oe.pop()
-                       }
-                       p.addElement()
-               case a.Optgroup:
-                       if p.top().DataAtom == a.Option {
-                               p.oe.pop()
-                       }
-                       if p.top().DataAtom == a.Optgroup {
-                               p.oe.pop()
-                       }
-                       p.addElement()
-               case a.Select:
-                       if !p.popUntil(selectScope, a.Select) {
-                               // Ignore the token.
-                               return true
-                       }
-                       p.resetInsertionMode()
-               case a.Input, a.Keygen, a.Textarea:
-                       if p.elementInScope(selectScope, a.Select) {
-                               p.parseImpliedToken(EndTagToken, a.Select, 
a.Select.String())
-                               return false
-                       }
-                       // In order to properly ignore <textarea>, we need to 
change the tokenizer mode.
-                       p.tokenizer.NextIsNotRawText()
-                       // Ignore the token.
-                       return true
-               case a.Script, a.Template:
-                       return inHeadIM(p)
-               case a.Iframe, a.Noembed, a.Noframes, a.Noscript, a.Plaintext, 
a.Style, a.Title, a.Xmp:
-                       // Don't let the tokenizer go into raw text mode when 
there are raw tags
-                       // to be ignored. These tags should be ignored from the 
tokenizer
-                       // properly.
-                       p.tokenizer.NextIsNotRawText()
-                       // Ignore the token.
-                       return true
-               }
-       case EndTagToken:
-               switch p.tok.DataAtom {
-               case a.Option:
-                       if p.top().DataAtom == a.Option {
-                               p.oe.pop()
-                       }
-               case a.Optgroup:
-                       i := len(p.oe) - 1
-                       if p.oe[i].DataAtom == a.Option {
-                               i--
-                       }
-                       if p.oe[i].DataAtom == a.Optgroup {
-                               p.oe = p.oe[:i]
-                       }
-               case a.Select:
-                       if !p.popUntil(selectScope, a.Select) {
-                               // Ignore the token.
-                               return true
-                       }
-                       p.resetInsertionMode()
-               case a.Template:
-                       return inHeadIM(p)
-               }
-       case CommentToken:
-               p.addChild(&Node{
-                       Type: CommentNode,
-                       Data: p.tok.Data,
-               })
-       case DoctypeToken:
-               // Ignore the token.
-               return true
-       case ErrorToken:
-               return inBodyIM(p)
-       }
-
-       return true
-}
-
-// Section 12.2.6.4.17.
-func inSelectInTableIM(p *parser) bool {
-       switch p.tok.Type {
-       case StartTagToken, EndTagToken:
-               switch p.tok.DataAtom {
-               case a.Caption, a.Table, a.Tbody, a.Tfoot, a.Thead, a.Tr, a.Td, 
a.Th:
-                       if p.tok.Type == EndTagToken && 
!p.elementInScope(tableScope, p.tok.DataAtom) {
-                               // Ignore the token.
-                               return true
-                       }
-                       // This is like p.popUntil(selectScope, a.Select), but 
it also
-                       // matches <math select>, not just <select>. Matching 
the MathML
-                       // tag is arguably incorrect (conceptually), but it 
mimics what
-                       // Chromium does.
-                       for i := len(p.oe) - 1; i >= 0; i-- {
-                               if n := p.oe[i]; n.DataAtom == a.Select {
-                                       p.oe = p.oe[:i]
-                                       break
-                               }
-                       }
-                       p.resetInsertionMode()
-                       return false
-               }
-       }
-       return inSelectIM(p)
-}
-
 // Section 12.2.6.4.18.
 func inTemplateIM(p *parser) bool {
        switch p.tok.Type {
@@ -2174,7 +2061,7 @@
 
 const whitespaceOrNUL = whitespace + "\x00"
 
-// Section 12.2.6.5
+// Section 13.2.6.5
 func parseForeignContent(p *parser) bool {
        switch p.tok.Type {
        case TextToken:
@@ -2189,28 +2076,26 @@
                        Data: p.tok.Data,
                })
        case StartTagToken:
-               if !p.fragment {
-                       b := breakout[p.tok.Data]
-                       if p.tok.DataAtom == a.Font {
-                       loop:
-                               for _, attr := range p.tok.Attr {
-                                       switch attr.Key {
-                                       case "color", "face", "size":
-                                               b = true
-                                               break loop
-                                       }
+               b := breakout[p.tok.Data]
+               if p.tok.DataAtom == a.Font {
+               loop:
+                       for _, attr := range p.tok.Attr {
+                               switch attr.Key {
+                               case "color", "face", "size":
+                                       b = true
+                                       break loop
                                }
                        }
-                       if b {
-                               for i := len(p.oe) - 1; i >= 0; i-- {
-                                       n := p.oe[i]
-                                       if n.Namespace == "" || 
htmlIntegrationPoint(n) || mathMLTextIntegrationPoint(n) {
-                                               p.oe = p.oe[:i+1]
-                                               break
-                                       }
+               }
+               if b {
+                       for i := len(p.oe) - 1; i >= 0; i-- {
+                               n := p.oe[i]
+                               if n.Namespace == "" || htmlIntegrationPoint(n) 
|| mathMLTextIntegrationPoint(n) {
+                                       p.oe = p.oe[:i+1]
+                                       break
                                }
-                               return false
                        }
+                       return p.im(p)
                }
                current := p.adjustedCurrentNode()
                switch current.Namespace {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/net/html/token.go 
new/vendor/golang.org/x/net/html/token.go
--- old/vendor/golang.org/x/net/html/token.go   2026-07-25 09:07:07.000000000 
+0200
+++ new/vendor/golang.org/x/net/html/token.go   2026-07-27 08:26:37.000000000 
+0200
@@ -704,7 +704,11 @@
        for i := 0; i < 2; i++ {
                c[i] = z.readByte()
                if z.err != nil {
+                       // bogus comment
                        z.data.end = z.raw.end
+                       if i == 1 && c[0] == '>' {
+                               z.data.end--
+                       }
                        return CommentToken
                }
        }
@@ -732,6 +736,13 @@
        for i := 0; i < len(s); i++ {
                c := z.readByte()
                if z.err != nil {
+                       if z.err == io.EOF {
+                               // Back up to read the fragment of "DOCTYPE" 
again, reset
+                               // z.err to signal EOF on the next call
+                               z.raw.end = z.data.start
+                               z.err = nil
+                               return false
+                       }
                        z.data.end = z.raw.end
                        return false
                }
@@ -757,6 +768,13 @@
        for i := 0; i < len(s); i++ {
                c := z.readByte()
                if z.err != nil {
+                       if z.err == io.EOF {
+                               // Back up to read the fragment of "[CDATA[" 
again, reset
+                               // z.err to signal EOF on the next call
+                               z.raw.end = z.data.start
+                               z.err = nil
+                               return false
+                       }
                        z.data.end = z.raw.end
                        return false
                }
@@ -883,7 +901,7 @@
                z.readTagAttrKey()
                z.readTagAttrVal()
                // Save pendingAttr if saveAttr and that attribute has a 
non-empty key, and the key hasn't been seen before.
-               key := 
strings.ToLower(string(z.buf[z.pendingAttr[0].start:z.pendingAttr[0].end]))
+               key := 
string(lower(bytes.Clone(z.buf[z.pendingAttr[0].start:z.pendingAttr[0].end])))
                if saveAttr && z.pendingAttr[0].start != z.pendingAttr[0].end 
&& !z.attrNames[key] {
                        z.attr = append(z.attr, z.pendingAttr)
                        z.attrNames[key] = true
@@ -1206,7 +1224,7 @@
        if z.data.start < z.data.end {
                switch z.tt {
                case StartTagToken, EndTagToken, SelfClosingTagToken:
-                       s := z.buf[z.data.start:z.data.end]
+                       s := bytes.ReplaceAll(z.buf[z.data.start:z.data.end], 
nul, replacement)
                        z.data.start = z.raw.end
                        z.data.end = z.raw.end
                        return lower(s), z.nAttrReturned < len(z.attr)
@@ -1224,8 +1242,8 @@
                case StartTagToken, SelfClosingTagToken:
                        x := z.attr[z.nAttrReturned]
                        z.nAttrReturned++
-                       key = z.buf[x[0].start:x[0].end]
-                       val = z.buf[x[1].start:x[1].end]
+                       key = bytes.ReplaceAll(z.buf[x[0].start:x[0].end], nul, 
replacement)
+                       val = bytes.ReplaceAll(z.buf[x[1].start:x[1].end], nul, 
replacement)
                        return lower(key), unescape(convertNewlines(val), 
true), z.nAttrReturned < len(z.attr)
                }
        }
@@ -1282,9 +1300,22 @@
                attrNames: make(map[string]bool),
        }
        if contextTag != "" {
+               // Per the "Parsing HTML Fragments" portion of the spec:
+               //    For performance reasons, an implementation that does not 
report errors
+               //    and that uses the actual state machine described in this 
specification
+               //    directly could use the PLAINTEXT state instead of the 
RAWTEXT and script
+               //    data states where those are mentioned in the list above. 
Except for
+               //    rules regarding parse errors, they are equivalent, since 
there is no
+               //    appropriate end tag token in the fragment case, yet they 
involve far
+               //    fewer state transitions.
+               //
+               // As such we just set everything to plaintext, which makes 
some complex parsing
+               // cases somewhat simpler.
                switch s := strings.ToLower(contextTag); s {
-               case "iframe", "noembed", "noframes", "noscript", "plaintext", 
"script", "style", "title", "textarea", "xmp":
+               case "title", "textarea":
                        z.rawTag = s
+               case "style", "xmp", "iframe", "noembed", "noframes", "script", 
"noscript", "plaintext":
+                       z.rawTag = "plaintext"
                }
        }
        return z
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/syscall_linux.go 
new/vendor/golang.org/x/sys/unix/syscall_linux.go
--- old/vendor/golang.org/x/sys/unix/syscall_linux.go   2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/syscall_linux.go   2026-07-27 
08:26:37.000000000 +0200
@@ -1874,6 +1874,7 @@
 //sys  Dup3(oldfd int, newfd int, flags int) (err error)
 //sysnb        EpollCreate1(flag int) (fd int, err error)
 //sysnb        EpollCtl(epfd int, op int, fd int, event *EpollEvent) (err 
error)
+//sys  EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) = 
SYS_EPOLL_PWAIT
 //sys  Eventfd(initval uint, flags int) (fd int, err error) = SYS_EVENTFD2
 //sys  Exit(code int) = SYS_EXIT_GROUP
 //sys  Fallocate(fd int, mode uint32, off int64, len int64) (err error)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/syscall_linux_386.go 
new/vendor/golang.org/x/sys/unix/syscall_linux_386.go
--- old/vendor/golang.org/x/sys/unix/syscall_linux_386.go       2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/syscall_linux_386.go       2026-07-27 
08:26:37.000000000 +0200
@@ -20,7 +20,6 @@
 
 // 64-bit file system and 32-bit uid calls
 // (386 default is 32-bit file system and 16-bit uid).
-//sys  EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error)
 //sys  Fadvise(fd int, offset int64, length int64, advice int) (err error) = 
SYS_FADVISE64_64
 //sys  Fchown(fd int, uid int, gid int) (err error) = SYS_FCHOWN32
 //sys  Fstat(fd int, stat *Stat_t) (err error) = SYS_FSTAT64
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/syscall_linux_amd64.go 
new/vendor/golang.org/x/sys/unix/syscall_linux_amd64.go
--- old/vendor/golang.org/x/sys/unix/syscall_linux_amd64.go     2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/syscall_linux_amd64.go     2026-07-27 
08:26:37.000000000 +0200
@@ -6,7 +6,6 @@
 
 package unix
 
-//sys  EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error)
 //sys  Fadvise(fd int, offset int64, length int64, advice int) (err error) = 
SYS_FADVISE64
 //sys  Fchown(fd int, uid int, gid int) (err error)
 //sys  Fstat(fd int, stat *Stat_t) (err error)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/syscall_linux_arm.go 
new/vendor/golang.org/x/sys/unix/syscall_linux_arm.go
--- old/vendor/golang.org/x/sys/unix/syscall_linux_arm.go       2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/syscall_linux_arm.go       2026-07-27 
08:26:37.000000000 +0200
@@ -44,7 +44,6 @@
 
 // 64-bit file system and 32-bit uid calls
 // (16-bit uid calls are not always supported in newer kernels)
-//sys  EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error)
 //sys  Fchown(fd int, uid int, gid int) (err error) = SYS_FCHOWN32
 //sys  Fstat(fd int, stat *Stat_t) (err error) = SYS_FSTAT64
 //sys  Fstatat(dirfd int, path string, stat *Stat_t, flags int) (err error) = 
SYS_FSTATAT64
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/syscall_linux_arm64.go 
new/vendor/golang.org/x/sys/unix/syscall_linux_arm64.go
--- old/vendor/golang.org/x/sys/unix/syscall_linux_arm64.go     2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/syscall_linux_arm64.go     2026-07-27 
08:26:37.000000000 +0200
@@ -8,7 +8,6 @@
 
 import "unsafe"
 
-//sys  EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) = 
SYS_EPOLL_PWAIT
 //sys  Fadvise(fd int, offset int64, length int64, advice int) (err error) = 
SYS_FADVISE64
 //sys  Fchown(fd int, uid int, gid int) (err error)
 //sys  Fstat(fd int, stat *Stat_t) (err error)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/vendor/golang.org/x/sys/unix/syscall_linux_loong64.go 
new/vendor/golang.org/x/sys/unix/syscall_linux_loong64.go
--- old/vendor/golang.org/x/sys/unix/syscall_linux_loong64.go   2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/syscall_linux_loong64.go   2026-07-27 
08:26:37.000000000 +0200
@@ -8,7 +8,6 @@
 
 import "unsafe"
 
-//sys  EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) = 
SYS_EPOLL_PWAIT
 //sys  Fadvise(fd int, offset int64, length int64, advice int) (err error) = 
SYS_FADVISE64
 //sys  Fchown(fd int, uid int, gid int) (err error)
 //sys  Fstatfs(fd int, buf *Statfs_t) (err error)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/vendor/golang.org/x/sys/unix/syscall_linux_mips64x.go 
new/vendor/golang.org/x/sys/unix/syscall_linux_mips64x.go
--- old/vendor/golang.org/x/sys/unix/syscall_linux_mips64x.go   2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/syscall_linux_mips64x.go   2026-07-27 
08:26:37.000000000 +0200
@@ -6,7 +6,6 @@
 
 package unix
 
-//sys  EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error)
 //sys  Fadvise(fd int, offset int64, length int64, advice int) (err error) = 
SYS_FADVISE64
 //sys  Fchown(fd int, uid int, gid int) (err error)
 //sys  Fstatfs(fd int, buf *Statfs_t) (err error)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/syscall_linux_mipsx.go 
new/vendor/golang.org/x/sys/unix/syscall_linux_mipsx.go
--- old/vendor/golang.org/x/sys/unix/syscall_linux_mipsx.go     2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/syscall_linux_mipsx.go     2026-07-27 
08:26:37.000000000 +0200
@@ -13,7 +13,6 @@
 
 func Syscall9(trap, a1, a2, a3, a4, a5, a6, a7, a8, a9 uintptr) (r1, r2 
uintptr, err syscall.Errno)
 
-//sys  EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error)
 //sys  Fadvise(fd int, offset int64, length int64, advice int) (err error) = 
SYS_FADVISE64
 //sys  Fchown(fd int, uid int, gid int) (err error)
 //sys  Ftruncate(fd int, length int64) (err error) = SYS_FTRUNCATE64
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/syscall_linux_ppc.go 
new/vendor/golang.org/x/sys/unix/syscall_linux_ppc.go
--- old/vendor/golang.org/x/sys/unix/syscall_linux_ppc.go       2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/syscall_linux_ppc.go       2026-07-27 
08:26:37.000000000 +0200
@@ -11,7 +11,6 @@
        "unsafe"
 )
 
-//sys  EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error)
 //sys  Fchown(fd int, uid int, gid int) (err error)
 //sys  Fstat(fd int, stat *Stat_t) (err error) = SYS_FSTAT64
 //sys  Fstatat(dirfd int, path string, stat *Stat_t, flags int) (err error) = 
SYS_FSTATAT64
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/syscall_linux_ppc64x.go 
new/vendor/golang.org/x/sys/unix/syscall_linux_ppc64x.go
--- old/vendor/golang.org/x/sys/unix/syscall_linux_ppc64x.go    2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/syscall_linux_ppc64x.go    2026-07-27 
08:26:37.000000000 +0200
@@ -6,7 +6,6 @@
 
 package unix
 
-//sys  EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error)
 //sys  Fadvise(fd int, offset int64, length int64, advice int) (err error) = 
SYS_FADVISE64
 //sys  Fchown(fd int, uid int, gid int) (err error)
 //sys  Fstat(fd int, stat *Stat_t) (err error)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/vendor/golang.org/x/sys/unix/syscall_linux_riscv64.go 
new/vendor/golang.org/x/sys/unix/syscall_linux_riscv64.go
--- old/vendor/golang.org/x/sys/unix/syscall_linux_riscv64.go   2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/syscall_linux_riscv64.go   2026-07-27 
08:26:37.000000000 +0200
@@ -8,7 +8,6 @@
 
 import "unsafe"
 
-//sys  EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) = 
SYS_EPOLL_PWAIT
 //sys  Fadvise(fd int, offset int64, length int64, advice int) (err error) = 
SYS_FADVISE64
 //sys  Fchown(fd int, uid int, gid int) (err error)
 //sys  Fstat(fd int, stat *Stat_t) (err error)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/syscall_linux_s390x.go 
new/vendor/golang.org/x/sys/unix/syscall_linux_s390x.go
--- old/vendor/golang.org/x/sys/unix/syscall_linux_s390x.go     2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/syscall_linux_s390x.go     2026-07-27 
08:26:37.000000000 +0200
@@ -10,7 +10,6 @@
        "unsafe"
 )
 
-//sys  EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error)
 //sys  Fadvise(fd int, offset int64, length int64, advice int) (err error) = 
SYS_FADVISE64
 //sys  Fchown(fd int, uid int, gid int) (err error)
 //sys  Fstat(fd int, stat *Stat_t) (err error)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/vendor/golang.org/x/sys/unix/syscall_linux_sparc64.go 
new/vendor/golang.org/x/sys/unix/syscall_linux_sparc64.go
--- old/vendor/golang.org/x/sys/unix/syscall_linux_sparc64.go   2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/syscall_linux_sparc64.go   2026-07-27 
08:26:37.000000000 +0200
@@ -6,7 +6,6 @@
 
 package unix
 
-//sys  EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error)
 //sys  Fadvise(fd int, offset int64, length int64, advice int) (err error) = 
SYS_FADVISE64
 //sys  Fchown(fd int, uid int, gid int) (err error)
 //sys  Fstat(fd int, stat *Stat_t) (err error)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/zerrors_linux.go 
new/vendor/golang.org/x/sys/unix/zerrors_linux.go
--- old/vendor/golang.org/x/sys/unix/zerrors_linux.go   2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zerrors_linux.go   2026-07-27 
08:26:37.000000000 +0200
@@ -1359,6 +1359,7 @@
        FAN_UNLIMITED_MARKS                         = 0x20
        FAN_UNLIMITED_QUEUE                         = 0x10
        FD_CLOEXEC                                  = 0x1
+       FD_PIDFS_ROOT                               = -0x2712
        FD_SETSIZE                                  = 0x400
        FF0                                         = 0x0
        FIB_RULE_DEV_DETACHED                       = 0x8
@@ -1970,6 +1971,8 @@
        MADV_DONTNEED                               = 0x4
        MADV_DONTNEED_LOCKED                        = 0x18
        MADV_FREE                                   = 0x8
+       MADV_GUARD_INSTALL                          = 0x66
+       MADV_GUARD_REMOVE                           = 0x67
        MADV_HUGEPAGE                               = 0xe
        MADV_HWPOISON                               = 0x64
        MADV_KEEPONFORK                             = 0x13
@@ -2114,7 +2117,7 @@
        MS_NOSEC                                    = 0x10000000
        MS_NOSUID                                   = 0x2
        MS_NOSYMFOLLOW                              = 0x100
-       MS_NOUSER                                   = -0x80000000
+       MS_NOUSER                                   = 0x80000000
        MS_POSIXACL                                 = 0x10000
        MS_PRIVATE                                  = 0x40000
        MS_RDONLY                                   = 0x1
@@ -3786,6 +3789,9 @@
        TCPOPT_TIMESTAMP                            = 0x8
        TCPOPT_TSTAMP_HDR                           = 0x101080a
        TCPOPT_WINDOW                               = 0x3
+       TCP_AO_KEYF_EXCLUDE_OPT                     = 0x2
+       TCP_AO_KEYF_IFINDEX                         = 0x1
+       TCP_AO_MAXKEYLEN                            = 0x50
        TCP_CC_INFO                                 = 0x1a
        TCP_CM_INQ                                  = 0x24
        TCP_CONGESTION                              = 0xd
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/zsyscall_linux.go 
new/vendor/golang.org/x/sys/unix/zsyscall_linux.go
--- old/vendor/golang.org/x/sys/unix/zsyscall_linux.go  2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zsyscall_linux.go  2026-07-27 
08:26:37.000000000 +0200
@@ -700,6 +700,23 @@
 
 // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
 
+func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) {
+       var _p0 unsafe.Pointer
+       if len(events) > 0 {
+               _p0 = unsafe.Pointer(&events[0])
+       } else {
+               _p0 = unsafe.Pointer(&_zero)
+       }
+       r0, _, e1 := Syscall6(SYS_EPOLL_PWAIT, uintptr(epfd), uintptr(_p0), 
uintptr(len(events)), uintptr(msec), 0, 0)
+       n = int(r0)
+       if e1 != 0 {
+               err = errnoErr(e1)
+       }
+       return
+}
+
+// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
+
 func Eventfd(initval uint, flags int) (fd int, err error) {
        r0, _, e1 := Syscall(SYS_EVENTFD2, uintptr(initval), uintptr(flags), 0)
        fd = int(r0)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/zsyscall_linux_386.go 
new/vendor/golang.org/x/sys/unix/zsyscall_linux_386.go
--- old/vendor/golang.org/x/sys/unix/zsyscall_linux_386.go      2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zsyscall_linux_386.go      2026-07-27 
08:26:37.000000000 +0200
@@ -45,23 +45,6 @@
 
 // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
 
-func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) {
-       var _p0 unsafe.Pointer
-       if len(events) > 0 {
-               _p0 = unsafe.Pointer(&events[0])
-       } else {
-               _p0 = unsafe.Pointer(&_zero)
-       }
-       r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), 
uintptr(len(events)), uintptr(msec), 0, 0)
-       n = int(r0)
-       if e1 != 0 {
-               err = errnoErr(e1)
-       }
-       return
-}
-
-// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
-
 func Fadvise(fd int, offset int64, length int64, advice int) (err error) {
        _, _, e1 := Syscall6(SYS_FADVISE64_64, uintptr(fd), uintptr(offset), 
uintptr(offset>>32), uintptr(length), uintptr(length>>32), uintptr(advice))
        if e1 != 0 {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/zsyscall_linux_amd64.go 
new/vendor/golang.org/x/sys/unix/zsyscall_linux_amd64.go
--- old/vendor/golang.org/x/sys/unix/zsyscall_linux_amd64.go    2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zsyscall_linux_amd64.go    2026-07-27 
08:26:37.000000000 +0200
@@ -45,23 +45,6 @@
 
 // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
 
-func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) {
-       var _p0 unsafe.Pointer
-       if len(events) > 0 {
-               _p0 = unsafe.Pointer(&events[0])
-       } else {
-               _p0 = unsafe.Pointer(&_zero)
-       }
-       r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), 
uintptr(len(events)), uintptr(msec), 0, 0)
-       n = int(r0)
-       if e1 != 0 {
-               err = errnoErr(e1)
-       }
-       return
-}
-
-// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
-
 func Fadvise(fd int, offset int64, length int64, advice int) (err error) {
        _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), 
uintptr(length), uintptr(advice), 0, 0)
        if e1 != 0 {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/zsyscall_linux_arm.go 
new/vendor/golang.org/x/sys/unix/zsyscall_linux_arm.go
--- old/vendor/golang.org/x/sys/unix/zsyscall_linux_arm.go      2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zsyscall_linux_arm.go      2026-07-27 
08:26:37.000000000 +0200
@@ -213,23 +213,6 @@
 
 // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
 
-func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) {
-       var _p0 unsafe.Pointer
-       if len(events) > 0 {
-               _p0 = unsafe.Pointer(&events[0])
-       } else {
-               _p0 = unsafe.Pointer(&_zero)
-       }
-       r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), 
uintptr(len(events)), uintptr(msec), 0, 0)
-       n = int(r0)
-       if e1 != 0 {
-               err = errnoErr(e1)
-       }
-       return
-}
-
-// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
-
 func Fchown(fd int, uid int, gid int) (err error) {
        _, _, e1 := Syscall(SYS_FCHOWN32, uintptr(fd), uintptr(uid), 
uintptr(gid))
        if e1 != 0 {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/zsyscall_linux_arm64.go 
new/vendor/golang.org/x/sys/unix/zsyscall_linux_arm64.go
--- old/vendor/golang.org/x/sys/unix/zsyscall_linux_arm64.go    2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zsyscall_linux_arm64.go    2026-07-27 
08:26:37.000000000 +0200
@@ -45,23 +45,6 @@
 
 // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
 
-func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) {
-       var _p0 unsafe.Pointer
-       if len(events) > 0 {
-               _p0 = unsafe.Pointer(&events[0])
-       } else {
-               _p0 = unsafe.Pointer(&_zero)
-       }
-       r0, _, e1 := Syscall6(SYS_EPOLL_PWAIT, uintptr(epfd), uintptr(_p0), 
uintptr(len(events)), uintptr(msec), 0, 0)
-       n = int(r0)
-       if e1 != 0 {
-               err = errnoErr(e1)
-       }
-       return
-}
-
-// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
-
 func Fadvise(fd int, offset int64, length int64, advice int) (err error) {
        _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), 
uintptr(length), uintptr(advice), 0, 0)
        if e1 != 0 {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/vendor/golang.org/x/sys/unix/zsyscall_linux_loong64.go 
new/vendor/golang.org/x/sys/unix/zsyscall_linux_loong64.go
--- old/vendor/golang.org/x/sys/unix/zsyscall_linux_loong64.go  2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zsyscall_linux_loong64.go  2026-07-27 
08:26:37.000000000 +0200
@@ -45,23 +45,6 @@
 
 // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
 
-func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) {
-       var _p0 unsafe.Pointer
-       if len(events) > 0 {
-               _p0 = unsafe.Pointer(&events[0])
-       } else {
-               _p0 = unsafe.Pointer(&_zero)
-       }
-       r0, _, e1 := Syscall6(SYS_EPOLL_PWAIT, uintptr(epfd), uintptr(_p0), 
uintptr(len(events)), uintptr(msec), 0, 0)
-       n = int(r0)
-       if e1 != 0 {
-               err = errnoErr(e1)
-       }
-       return
-}
-
-// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
-
 func Fadvise(fd int, offset int64, length int64, advice int) (err error) {
        _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), 
uintptr(length), uintptr(advice), 0, 0)
        if e1 != 0 {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/zsyscall_linux_mips.go 
new/vendor/golang.org/x/sys/unix/zsyscall_linux_mips.go
--- old/vendor/golang.org/x/sys/unix/zsyscall_linux_mips.go     2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zsyscall_linux_mips.go     2026-07-27 
08:26:37.000000000 +0200
@@ -45,23 +45,6 @@
 
 // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
 
-func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) {
-       var _p0 unsafe.Pointer
-       if len(events) > 0 {
-               _p0 = unsafe.Pointer(&events[0])
-       } else {
-               _p0 = unsafe.Pointer(&_zero)
-       }
-       r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), 
uintptr(len(events)), uintptr(msec), 0, 0)
-       n = int(r0)
-       if e1 != 0 {
-               err = errnoErr(e1)
-       }
-       return
-}
-
-// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
-
 func Fadvise(fd int, offset int64, length int64, advice int) (err error) {
        _, _, e1 := Syscall9(SYS_FADVISE64, uintptr(fd), 0, 
uintptr(offset>>32), uintptr(offset), uintptr(length>>32), uintptr(length), 
uintptr(advice), 0, 0)
        if e1 != 0 {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/vendor/golang.org/x/sys/unix/zsyscall_linux_mips64.go 
new/vendor/golang.org/x/sys/unix/zsyscall_linux_mips64.go
--- old/vendor/golang.org/x/sys/unix/zsyscall_linux_mips64.go   2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zsyscall_linux_mips64.go   2026-07-27 
08:26:37.000000000 +0200
@@ -45,23 +45,6 @@
 
 // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
 
-func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) {
-       var _p0 unsafe.Pointer
-       if len(events) > 0 {
-               _p0 = unsafe.Pointer(&events[0])
-       } else {
-               _p0 = unsafe.Pointer(&_zero)
-       }
-       r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), 
uintptr(len(events)), uintptr(msec), 0, 0)
-       n = int(r0)
-       if e1 != 0 {
-               err = errnoErr(e1)
-       }
-       return
-}
-
-// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
-
 func Fadvise(fd int, offset int64, length int64, advice int) (err error) {
        _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), 
uintptr(length), uintptr(advice), 0, 0)
        if e1 != 0 {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/vendor/golang.org/x/sys/unix/zsyscall_linux_mips64le.go 
new/vendor/golang.org/x/sys/unix/zsyscall_linux_mips64le.go
--- old/vendor/golang.org/x/sys/unix/zsyscall_linux_mips64le.go 2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zsyscall_linux_mips64le.go 2026-07-27 
08:26:37.000000000 +0200
@@ -45,23 +45,6 @@
 
 // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
 
-func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) {
-       var _p0 unsafe.Pointer
-       if len(events) > 0 {
-               _p0 = unsafe.Pointer(&events[0])
-       } else {
-               _p0 = unsafe.Pointer(&_zero)
-       }
-       r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), 
uintptr(len(events)), uintptr(msec), 0, 0)
-       n = int(r0)
-       if e1 != 0 {
-               err = errnoErr(e1)
-       }
-       return
-}
-
-// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
-
 func Fadvise(fd int, offset int64, length int64, advice int) (err error) {
        _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), 
uintptr(length), uintptr(advice), 0, 0)
        if e1 != 0 {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/vendor/golang.org/x/sys/unix/zsyscall_linux_mipsle.go 
new/vendor/golang.org/x/sys/unix/zsyscall_linux_mipsle.go
--- old/vendor/golang.org/x/sys/unix/zsyscall_linux_mipsle.go   2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zsyscall_linux_mipsle.go   2026-07-27 
08:26:37.000000000 +0200
@@ -45,23 +45,6 @@
 
 // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
 
-func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) {
-       var _p0 unsafe.Pointer
-       if len(events) > 0 {
-               _p0 = unsafe.Pointer(&events[0])
-       } else {
-               _p0 = unsafe.Pointer(&_zero)
-       }
-       r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), 
uintptr(len(events)), uintptr(msec), 0, 0)
-       n = int(r0)
-       if e1 != 0 {
-               err = errnoErr(e1)
-       }
-       return
-}
-
-// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
-
 func Fadvise(fd int, offset int64, length int64, advice int) (err error) {
        _, _, e1 := Syscall9(SYS_FADVISE64, uintptr(fd), 0, uintptr(offset), 
uintptr(offset>>32), uintptr(length), uintptr(length>>32), uintptr(advice), 0, 
0)
        if e1 != 0 {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc.go 
new/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc.go
--- old/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc.go      2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc.go      2026-07-27 
08:26:37.000000000 +0200
@@ -45,23 +45,6 @@
 
 // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
 
-func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) {
-       var _p0 unsafe.Pointer
-       if len(events) > 0 {
-               _p0 = unsafe.Pointer(&events[0])
-       } else {
-               _p0 = unsafe.Pointer(&_zero)
-       }
-       r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), 
uintptr(len(events)), uintptr(msec), 0, 0)
-       n = int(r0)
-       if e1 != 0 {
-               err = errnoErr(e1)
-       }
-       return
-}
-
-// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
-
 func Fchown(fd int, uid int, gid int) (err error) {
        _, _, e1 := Syscall(SYS_FCHOWN, uintptr(fd), uintptr(uid), uintptr(gid))
        if e1 != 0 {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64.go 
new/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64.go
--- old/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64.go    2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64.go    2026-07-27 
08:26:37.000000000 +0200
@@ -45,23 +45,6 @@
 
 // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
 
-func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) {
-       var _p0 unsafe.Pointer
-       if len(events) > 0 {
-               _p0 = unsafe.Pointer(&events[0])
-       } else {
-               _p0 = unsafe.Pointer(&_zero)
-       }
-       r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), 
uintptr(len(events)), uintptr(msec), 0, 0)
-       n = int(r0)
-       if e1 != 0 {
-               err = errnoErr(e1)
-       }
-       return
-}
-
-// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
-
 func Fadvise(fd int, offset int64, length int64, advice int) (err error) {
        _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), 
uintptr(length), uintptr(advice), 0, 0)
        if e1 != 0 {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64le.go 
new/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64le.go
--- old/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64le.go  2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64le.go  2026-07-27 
08:26:37.000000000 +0200
@@ -45,23 +45,6 @@
 
 // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
 
-func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) {
-       var _p0 unsafe.Pointer
-       if len(events) > 0 {
-               _p0 = unsafe.Pointer(&events[0])
-       } else {
-               _p0 = unsafe.Pointer(&_zero)
-       }
-       r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), 
uintptr(len(events)), uintptr(msec), 0, 0)
-       n = int(r0)
-       if e1 != 0 {
-               err = errnoErr(e1)
-       }
-       return
-}
-
-// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
-
 func Fadvise(fd int, offset int64, length int64, advice int) (err error) {
        _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), 
uintptr(length), uintptr(advice), 0, 0)
        if e1 != 0 {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/vendor/golang.org/x/sys/unix/zsyscall_linux_riscv64.go 
new/vendor/golang.org/x/sys/unix/zsyscall_linux_riscv64.go
--- old/vendor/golang.org/x/sys/unix/zsyscall_linux_riscv64.go  2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zsyscall_linux_riscv64.go  2026-07-27 
08:26:37.000000000 +0200
@@ -45,23 +45,6 @@
 
 // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
 
-func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) {
-       var _p0 unsafe.Pointer
-       if len(events) > 0 {
-               _p0 = unsafe.Pointer(&events[0])
-       } else {
-               _p0 = unsafe.Pointer(&_zero)
-       }
-       r0, _, e1 := Syscall6(SYS_EPOLL_PWAIT, uintptr(epfd), uintptr(_p0), 
uintptr(len(events)), uintptr(msec), 0, 0)
-       n = int(r0)
-       if e1 != 0 {
-               err = errnoErr(e1)
-       }
-       return
-}
-
-// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
-
 func Fadvise(fd int, offset int64, length int64, advice int) (err error) {
        _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), 
uintptr(length), uintptr(advice), 0, 0)
        if e1 != 0 {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/unix/zsyscall_linux_s390x.go 
new/vendor/golang.org/x/sys/unix/zsyscall_linux_s390x.go
--- old/vendor/golang.org/x/sys/unix/zsyscall_linux_s390x.go    2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zsyscall_linux_s390x.go    2026-07-27 
08:26:37.000000000 +0200
@@ -45,23 +45,6 @@
 
 // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
 
-func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) {
-       var _p0 unsafe.Pointer
-       if len(events) > 0 {
-               _p0 = unsafe.Pointer(&events[0])
-       } else {
-               _p0 = unsafe.Pointer(&_zero)
-       }
-       r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), 
uintptr(len(events)), uintptr(msec), 0, 0)
-       n = int(r0)
-       if e1 != 0 {
-               err = errnoErr(e1)
-       }
-       return
-}
-
-// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
-
 func Fadvise(fd int, offset int64, length int64, advice int) (err error) {
        _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), 
uintptr(length), uintptr(advice), 0, 0)
        if e1 != 0 {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/vendor/golang.org/x/sys/unix/zsyscall_linux_sparc64.go 
new/vendor/golang.org/x/sys/unix/zsyscall_linux_sparc64.go
--- old/vendor/golang.org/x/sys/unix/zsyscall_linux_sparc64.go  2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/unix/zsyscall_linux_sparc64.go  2026-07-27 
08:26:37.000000000 +0200
@@ -45,23 +45,6 @@
 
 // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
 
-func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) {
-       var _p0 unsafe.Pointer
-       if len(events) > 0 {
-               _p0 = unsafe.Pointer(&events[0])
-       } else {
-               _p0 = unsafe.Pointer(&_zero)
-       }
-       r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), 
uintptr(len(events)), uintptr(msec), 0, 0)
-       n = int(r0)
-       if e1 != 0 {
-               err = errnoErr(e1)
-       }
-       return
-}
-
-// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT
-
 func Fadvise(fd int, offset int64, length int64, advice int) (err error) {
        _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), 
uintptr(length), uintptr(advice), 0, 0)
        if e1 != 0 {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/windows/security_windows.go 
new/vendor/golang.org/x/sys/windows/security_windows.go
--- old/vendor/golang.org/x/sys/windows/security_windows.go     2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/windows/security_windows.go     2026-07-27 
08:26:37.000000000 +0200
@@ -1109,17 +1109,53 @@
 )
 
 // This type is the union inside of TRUSTEE and must be created using one of 
the TrusteeValueFrom* functions.
+//
+// Go pointers stored in a TrusteeValue must be pinned using [runtime.Pinner]
+// for the lifetime of the TrusteeValue.
 type TrusteeValue uintptr
 
+// TrusteeValueFromString is unsafe and should not be used.
+//
+// It returns a uintptr containing a reference to newly-allocated memory
+// which will be freed by the garbage collector.
+// There is no way for the caller to safely reference this memory.
+//
+// To create a [TrusteeValue] from a string, use:
+//
+//     p, err := windows.UTF16PtrFromString(s)
+//     if err != nil {
+//             // handle error
+//     }
+//
+//     // Pin the string for as long as it is used.
+//     var pinner runtime.Pinner
+//     pinner.Pin(p)
+//     defer pinner.Unpin()
+//
+//     tv := TrusteeValue(unsafe.Pointer(p))
+//
+// Deprecated: TrusteeValueFromString is unsafe and should not be used.
 func TrusteeValueFromString(str string) TrusteeValue {
        return TrusteeValue(unsafe.Pointer(StringToUTF16Ptr(str)))
 }
+
+// TrusteeValueFromSID returns a [TrusteeValue] referencing sid.
+//
+// The caller must pin sid using a [runtime.Pinner] for the lifetime of the 
TrusteeValue.
 func TrusteeValueFromSID(sid *SID) TrusteeValue {
        return TrusteeValue(unsafe.Pointer(sid))
 }
+
+// TrusteeValueFromObjectsAndSid returns a [TrusteeValue] referencing 
objectsAndSid.
+//
+// The caller must pin objectsAndSid using a [runtime.Pinner] for the lifetime 
of the TrusteeValue.
 func TrusteeValueFromObjectsAndSid(objectsAndSid *OBJECTS_AND_SID) 
TrusteeValue {
        return TrusteeValue(unsafe.Pointer(objectsAndSid))
 }
+
+// TrusteeValueFromObjectsAndName returns a [TrusteeValue] referencing 
objectsAndName.
+//
+// The caller must pin objectsAndName using a [runtime.Pinner] for the 
lifetime of the TrusteeValue.
 func TrusteeValueFromObjectsAndName(objectsAndName *OBJECTS_AND_NAME) 
TrusteeValue {
        return TrusteeValue(unsafe.Pointer(objectsAndName))
 }
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/windows/syscall_windows.go 
new/vendor/golang.org/x/sys/windows/syscall_windows.go
--- old/vendor/golang.org/x/sys/windows/syscall_windows.go      2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/windows/syscall_windows.go      2026-07-27 
08:26:37.000000000 +0200
@@ -1728,11 +1728,15 @@
 // the more common *uint16 string type.
 func NewNTString(s string) (*NTString, error) {
        var nts NTString
-       s8, err := BytePtrFromString(s)
+       s8, err := ByteSliceFromString(s)
        if err != nil {
                return nil, err
        }
-       RtlInitString(&nts, s8)
+       // The source string plus its terminating NUL must fit within 
MAX_USHORT.
+       if len(s8) > MAX_USHORT {
+               return nil, syscall.EINVAL
+       }
+       RtlInitString(&nts, &s8[0])
        return &nts, nil
 }
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/golang.org/x/sys/windows/types_windows.go 
new/vendor/golang.org/x/sys/windows/types_windows.go
--- old/vendor/golang.org/x/sys/windows/types_windows.go        2026-07-25 
09:07:07.000000000 +0200
+++ new/vendor/golang.org/x/sys/windows/types_windows.go        2026-07-27 
08:26:37.000000000 +0200
@@ -169,6 +169,7 @@
        FORMAT_MESSAGE_ARGUMENT_ARRAY  = 8192
        FORMAT_MESSAGE_MAX_WIDTH_MASK  = 255
 
+       MAX_USHORT    = 0xffff
        MAX_PATH      = 260
        MAX_LONG_PATH = 32768
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/modules.txt new/vendor/modules.txt
--- old/vendor/modules.txt      2026-07-25 09:07:07.000000000 +0200
+++ new/vendor/modules.txt      2026-07-27 08:26:37.000000000 +0200
@@ -124,7 +124,7 @@
 golang.org/x/mod/module
 golang.org/x/mod/semver
 golang.org/x/mod/zip
-# golang.org/x/net v0.56.0 => golang.org/x/net v0.55.0
+# golang.org/x/net v0.56.0 => golang.org/x/net v0.57.0
 ## explicit; go 1.25.0
 golang.org/x/net/html
 golang.org/x/net/html/atom
@@ -132,11 +132,11 @@
 # golang.org/x/sync v0.21.0
 ## explicit; go 1.25.0
 golang.org/x/sync/errgroup
-# golang.org/x/sys v0.46.0
+# golang.org/x/sys v0.47.0
 ## explicit; go 1.25.0
 golang.org/x/sys/unix
 golang.org/x/sys/windows
-# golang.org/x/text v0.37.0 => golang.org/x/text v0.39.0
+# golang.org/x/text v0.40.0 => golang.org/x/text v0.39.0
 ## explicit; go 1.25.0
 golang.org/x/text/encoding
 golang.org/x/text/encoding/charmap
@@ -178,5 +178,5 @@
 golang.org/x/tools/internal/typeparams
 golang.org/x/tools/internal/typesinternal
 golang.org/x/tools/internal/versions
-# golang.org/x/net => golang.org/x/net v0.55.0
+# golang.org/x/net => golang.org/x/net v0.57.0
 # golang.org/x/text => golang.org/x/text v0.39.0

Reply via email to