* run tests with ./node
* remove addons from test-ci suite, because it creates a dependency loop
nodejs -> node-gyp -> nodejs which is painful to manage.
* disabled because it requires stdin:
+ test-stdout-close-unref
+ test-regress-GH-746
* test-tick-processor fails on ppc64 and s390x, currently investigated
https://github.com/nodejs/node/issues/2471
* test-cluster-disconnect sometimes fails on busy buildd, forwarded upstream
https://github.com/nodejs/node/issues/3383
* test-fs-watch is flaky, might be related to https://github.com/nodejs/node/issues/4082
* huge timeout value for all platforms, buildd could be busy
* test-npm-install and test-release-npm must fail, debian package dfsg-repacked npm out
* ability to override CI_NATIVE_SUITES, CI_JS_SUITES
* disable tests failing because DNS is disabled
* sequential/test-http2-session-timeout is flaky https://github.com/nodejs/node/issues/20628
If the default security level is overwritten at build time of openssl
then it is needed to lower it again for nodejs in order to pass the
testsuite because it is using smoil keys.
Signed-off-by: Sebastian Andrzej Siewior <sebastian@breakpoint.cc>
Gbp-Pq: Topic build
Gbp-Pq: Name openssl_config_explicit_lower.patch
* Team upload
* Fix CVE-2026-48618:
A flaw in Node.js TLS hostname handling can cause Node.js
unicode dot separator handling can lead to tls wildcard-depth
authentication bypass due to resolver and verifier hostname
normalization mismatch
* Fix CVE-2026-48618:
A flaw in Node.js TLS hostname handling can cause Node.js unicode
dot separator handling can lead to tls wildcard-depth
authentication bypass due to resolver and verifier hostname
normalization mismat. This can lead to confidentiality impact
or bypass of the intended security boundary under
affected configurations.
* Fix CVE-2026-48928: case-sensitive SNI context matching
The regex constructed by server.addContext() lacked the case-insensitive
flag, causing uppercase or mixed-case SNI hostnames from ClientHello to
miss their intended context and fall back to the default context. This
violates RFC 6066 Section 3, which states that DNS hostnames are
case-insensitive. In mTLS configurations with per-tenant contexts, this
allowed bypassing client certificate authorization by simply
uppercasing the SNI hostname.
* Fix CVE-2026-48930:
A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames
can lead to silent authority rebinding due to c-string truncation
in resolver bindings.
* Fix CVE-2026-48931:
HTTP Agent can cause a client to accept as valid a response
that is send before the client has sent the request.
* Fix CVE-2026-48933:
A flaw in Node.js WebCrypto implementation can crash the process
if the input of `subtle.encrypt()` is a multiple of 2GiB.
* Fix CVE-2026-48934:
A flaw in Node.js TLS host verification can cause an attacker
to bypass certification validation.
* Fix CVE-2026-56846
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained
header blocks evade maxSessionMemory
and enable remote memory exhaustion.
* Fix CVE-2026-56848:
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()`
to be called re-entrantly while `nghttp2_session_mem_recv()` is executing,
resulting in a heap-use-after-free.
* Fix CVE-2026-56850:
A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array
key collisions, allowing mutual TLS (mTLS) client identities to be
reused across requests configured with different client certificates.
* Fix CVE-2026-58042:
A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process
When a DNS Response Contains More Than 256 A Records.
Repeated triggering of this condition can lead to denial of service.
* Fix CVE-2026-58040:
An incomplete fix has been identified in Node.js:
HTTPS Agent TLS session reuse skips hostname verification across
identity policies (incomplete fix of CVE-2026-48934).
* Fix FTBFS due to openssl changes