There are 32 open security issues in trixie.
You can find information about how to handle these issues in the security team's documentation.
There are 13 open security issues in forky.
There are 32 open security issues in bullseye.
There are 33 open security issues in bookworm.
You can find information about how to handle these issues in the security team's documentation.
commit ffc7a4b2b0e64d3e9e2ce87e4794de3824201dd0
Author: James McCoy <jamessan@debian.org>
Date: Sun Jul 26 22:16:38 2026 -0400
Add historical changelog entry for #987060
Signed-off-by: James McCoy <jamessan@debian.org>
commit 29fd19d5187aca559538ba4edc9d96ea98d2666e
Author: James McCoy <jamessan@debian.org>
Date: Sun Jul 26 22:10:41 2026 -0400
Add historical changelog entry for #977141
Signed-off-by: James McCoy <jamessan@debian.org>
commit cad36fb22f84298e7927a4a7ca278ac073ae823b
Author: James McCoy <jamessan@debian.org>
Date: Sun Jul 26 21:26:58 2026 -0400
Revert "Skip Test_clientserver_serverlist_list() and Test_remote_serverlist()"
This reverts commit bc3877dbef2220fbb74d333e55f5340c6a1b2e8c.
Upstream fixed the tests to work when running the tests without access
to a GUI environment.
commit 6771679f1d85ac0f1e62cd0e499e9d9e94178cec
Author: James McCoy <jamessan@debian.org>
Date: Sun Jul 26 21:26:27 2026 -0400
Refresh patch
Gbp-Dch: ignore
Signed-off-by: James McCoy <jamessan@debian.org>
commit ab2ad00bbc1e49032c91f62dc2ee185bdc85ecca
Author: James McCoy <jamessan@debian.org>
Date: Sun Jul 26 21:25:22 2026 -0400
Start changelog for v9.2.0858
Closes: #1140942
Signed-off-by: James McCoy <jamessan@debian.org>
commit bf71bfbff6889df66bdc110afaf7ab0b52b525e6
Merge: dc1584177 70da6c1a9
Author: James McCoy <jamessan@debian.org>
Date: Sun Jul 26 21:18:34 2026 -0400
Merge tag 'v9.2.0858' into debian/sid
v9.2.0858
commit dc1584177389c30c858e96a24c2d46208f946399
Author: James McCoy <jamessan@debian.org>
Date: Tue Jul 7 21:46:34 2026 -0400
release vim 2:9.2.0782-1
Signed-off-by: James McCoy <jamessan@debian.org>
commit bc3877dbef2220fbb74d333e55f5340c6a1b2e8c
Author: James McCoy <jamessan@debian.org>
Date: Tue Jul 7 06:18:29 2026 -0400
Skip Test_clientserver_serverlist_list() and Test_remote_serverlist()
These tests currently fail when run without access to X.
Revisit once https://github.com/vim/vim/pull/20719 and
https://github.com/vim/vim/pull/20716 are resolved.
Signed-off-by: James McCoy <jamessan@debian.org>
commit 9f6ca07bd5d4e6adbad89c6e67c55a73a8174c36
Author: James McCoy <jamessan@debian.org>
Date: Sat Jul 4 10:42:28 2026 -0400
d/copyright: Add stanza for syntax/ssh{allowedsigners,authorizedkeys,knownhosts,publickey}.vim
Signed-off-by: James McCoy <jamessan@debian.org>
commit d143d81ed7e4029876e6c5cb4f4c6fe7d4206237
Author: James McCoy <jamessan@debian.org>
Date: Sat Jul 4 10:29:55 2026 -0400
Start changelog for v9.2.0782
Closes: #1139728
Closes: #1139729
Closes: #1139730
Closes: #1140775
Signed-off-by: James McCoy <jamessan@debian.org>
commit 142d9acf912af8654bd854cae70c9d8123ea0627
Merge: b850129d3 834b8d218
Author: James McCoy <jamessan@debian.org>
Date: Sat Jul 4 09:20:34 2026 -0400
Merge tag 'v9.2.0782' into debian/sid
v9.2.0782
Signed-off-by: James McCoy <jamessan@debian.org>
commit b850129d3f91fa5c105800d4697e8cf6b945a38b
Author: James McCoy <jamessan@debian.org>
Date: Sat May 23 22:35:31 2026 -0400
release package vim version 2:9.2.0524-1
Signed-off-by: James McCoy <jamessan@debian.org>
commit ee0166cd6bd608d025bae665c4642f692867fa89
Author: James McCoy <jamessan@debian.org>
Date: Sat May 23 22:31:30 2026 -0400
Remove obsolete --enable-sockerserver switch
The functionality has changed and is always available when channels are
Signed-off-by: James McCoy <jamessan@debian.org>
commit b6f1b9613b6c35b8ac484f6c19b3e24172616338
Author: James McCoy <jamessan@debian.org>
Date: Sat May 23 21:01:04 2026 -0400
Disable gtk4 configure check until new UI stabilizes
Signed-off-by: James McCoy <jamessan@debian.org>
commit 651753743227b2d955a66256c8016ddfc487d031
Author: James McCoy <jamessan@debian.org>
Date: Sat May 23 21:00:35 2026 -0400
Start changelog for v9.2.0524
Signed-off-by: James McCoy <jamessan@debian.org>
commit 48bb2bb53769dd861526e5cc3294ae60b9fcea73
Merge: 8cbc77e95 9a920e825
Author: James McCoy <jamessan@debian.org>
Date: Sat May 23 20:58:26 2026 -0400
Merge tag 'v9.2.0524' into debian/sid
v9.2.0524
commit 9a920e82546dace49a0a88dced80d29a39efbdb0
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Sat May 23 19:56:10 2026 +0000
patch 9.2.0524: spell: buffer overflow with many affix or compound flags
Problem: spell: a word in a .dic file with many postponed prefix or
compound flags overflows the fixed-size store_afflist[MAXWLEN]
buffer in get_pfxlist() and get_compflags().
Solution: Add bounds checks (Yasuhiro Matsumoto).
closes: #20286
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 5e3056ee83f321dfbb597975e955b0e4f9058280
Author: Antonio Giovanni Colombo <azc100@gmail.com>
Date: Sat May 23 19:21:42 2026 +0000
translation(it): Update Italian manpage
Signed-off-by: Antonio Giovanni Colombo <azc100@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit fccc2adc98c3d6664f1f2d8ddab17b096e647986
Author: Christian Brabandt <cb@256bit.org>
Date: Sat May 23 19:05:28 2026 +0000
patch 9.2.0523: tests: no test for using shellescape() in combination with :!
Problem: tests: no test for using shellescape() in combination with :!
Solution: Add a test that checks runtime files for using wrong
combination of shellescape() with ! ex command
This has lead to a few security relevant issues, so add a test that
checks all runtime files for any ! followed by a shellescape() that does
not use the {special} arg.
related: Commit: 3fb5e58fbc63d86a3e65f1a141b0d67af2 (patch 9.2.0479:
[security]: runtime(tar): command injection in tar plugin)
closes: #20286
Supported by AI
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit da1f41d5d33152d7ab90a817bd99803c5727b937
Author: John Marriott <basilisk@internode.on.net>
Date: Sat May 23 19:00:12 2026 +0000
patch 9.2.0522: event_nr2name() in autocmd.c can be improved
Problem: event_nr2name() in autocmd.c can be improved
Solution: Refactor it so that event_nr2name() returns a string_T type
(John Marriott).
Additionally:
- change the define to an enum.
- in function auto_next_pat(), move some variables closer to where they
are used; rename s to fmt along the way.
closes: #20272
Signed-off-by: John Marriott <basilisk@internode.on.net>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit b34fa59abbd4f70b595ccab435446744443914d6
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Sat May 23 18:49:43 2026 +0000
patch 9.2.0521: GTK4: cannot resize shell after the window is shown
Problem: GTK4: cannot resize shell after the window is shown
(Maxim Kim, after v9.2.0501)
Solution: Always apply the requested size with
gtk_window_set_default_size(), regardless of realized state
(Yasuhiro Matsumoto).
fixes: #20264
closes: #20269
Co-Authored-by: Claude <noreply@anthropic.com>
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit d7e6ce7a767209ed046c8cb04091b47128892954
Author: Shad <shadow.walker@free.fr>
Date: Sat May 23 18:43:09 2026 +0000
patch 9.2.0520: Reversed text opacity in popup when termguicolor is set
Problem: When termguicolor is set, popup opacity seems reversed
for the underlying text: when opacity go from 1 to 99,
the greater opacity is, the more underlying text is readable.
Solution: Invert popup_color and base_fg when calling blend_colors
(Shad).
fixes: #20283
closes: #20284
Signed-off-by: Shad <shadow.walker@free.fr>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 3a54de8f441730dfe617892c7a08817252618a1c
Author: Foxe Chen <chen.foxe@gmail.com>
Date: Sat May 23 18:35:07 2026 +0000
patch 9.2.0519: GTK4: GUI tabline is not displayed correctly
Problem: GTK4: GUI tabline is not displayed correctly, and double
increments the index in the for() loop
Solution: Drop the additional increment (Foxe Chen)
closes: #20299
Co-Authored-by: Hirohito Higashi <h.east.727@gmail.com>
Signed-off-by: Foxe Chen <chen.foxe@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit f42ce78f770a68a8bb15209cc6def9b7763062f6
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Sat May 23 18:25:16 2026 +0000
patch 9.2.0518: GTK4: input method cannot compose text
Problem: GTK4: input method cannot compose text
(lilydjwg, after v9.2.0501)
Solution: Render the over-the-spot preedit with a GtkPopover instead of
a separate toplevel, so the compositor keeps
keyboard focus on the drawing area and does not disable
text-input-v3; attach the key controller to gui.drawarea and
filter key events manually with gtk_im_context_filter_keypress()
(Yasuhiro Matsumoto)
fixes: #20257
closes: #20266
Co-Authored-by: lilydjwg <lilydjwg@gmail.com>
Co-authored-by: Claude <noreply@anthropic.com>
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit cb8510d4703c13b34e178067ffe48a24c9a3ad32
Author: Yegappan Lakshmanan <yegappan@yahoo.com>
Date: Sat May 23 18:16:22 2026 +0000
patch 9.2.0517: quickfix: can set quickfixtextfunc in restricted/sandbox mode
Problem: quickfix: can set quickfixtextfunc in restricted/sandbox mode
(tacdm)
Solution: Disallow setting the quickfixtextfunc option from a sandbox
and restricted mode (Yegappan Lakshmanan).
closes: #20305
Co-Authored-by: tacdm
Signed-off-by: Yegappan Lakshmanan <yegappan@yahoo.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit ecba601e3f10fc046829877a0a4682a54cc27da0
Author: zeertzjq <zeertzjq@outlook.com>
Date: Sat May 23 16:07:16 2026 +0000
runtime(doc): fix a few small problems
closes: #20287
Signed-off-by: zeertzjq <zeertzjq@outlook.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit e3cb9655d7b0fbd4c2a14f7e300fafae374e3be2
Author: Foxe Chen <chen.foxe@gmail.com>
Date: Sat May 23 15:55:28 2026 +0000
patch 9.2.0516: socketserver: spurious error when servername is taken
Problem: socketserver: when searching for a free socket path,
socketserver_get_path() emits an error for each name that is
already in use (after v9.2.0512).
Solution: Add an "ignore" argument to socketserver_get_path() to
suppress the error (Foxe Chen).
Signed-off-by: Foxe Chen <chen.foxe@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
Signed-off-by: Foxe Chen <chen.foxe@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 6574102fb4a4b31c0988ea1c1de0ec4a665cc1c8
Author: Hirohito Higashi <h.east.727@gmail.com>
Date: Sat May 23 15:47:32 2026 +0000
runtime(doc): Tweak documentation style
closes: #20296
Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 37223f47b178d7e66173271e65d84de4413af6e2
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Date: Fri May 22 23:12:27 2026 +0000
CI: Bump github/codeql-action
Bumps the github-actions group with 1 update in the / directory: [github/codeql-action](https://github.com/github/codeql-action).
Updates `github/codeql-action` from 4.35.4 to 4.35.5
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/v4.35.4...v4.35.5)
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 4.35.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
...
closes: #20297
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 3d0a6073e560dd3b06a2f05ae01f0e9c59e68224
Author: zeertzjq <zeertzjq@outlook.com>
Date: Fri May 22 23:08:29 2026 +0000
patch 9.2.0515: virtualedit=insert doesn't work during change operation
Problem: virtualedit=insert doesn't work during change operation
(after 6.1.014).
Solution: Make virtual_op only affect virtualedit=block (zeertzjq).
related: neovim/neovim#35391
closes: #20298
Signed-off-by: zeertzjq <zeertzjq@outlook.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit ea71d5bb01ead1f982148771799462e91136107f
Author: Foxe Chen <chen.foxe@gmail.com>
Date: Fri May 22 22:18:03 2026 +0000
patch 9.2.0514: GTK4: build errors when socketserver is enabled
Problem: GTK4: build errors when socketserver is enabled
(after v9.2.0512)
Solution: Drop unused functions (Foxe Chen)
closes: #20293
Signed-off-by: Foxe Chen <chen.foxe@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 25e4e46c584840806b45da20edf8219cf19801a2
Author: Christian Brabandt <cb@256bit.org>
Date: Fri May 22 21:46:57 2026 +0000
patch 9.2.0513: [security]: memory safety issues in spellfile.c
Problem: [security]: memory safety issues in spellfile.c
(tacdm)
Solution: Add recursion limit to read_tree_node(), add length limit
check in tree_count_words(), use alloc_clear() in
spell_read_tree().
Github Security Advisory:
https://github.com/vim/vim/security/advisories/GHSA-3h95-3962-mmvf
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit e9c793bebcad2b585b3f5d25ca6108bcb48772fe
Author: Foxe Chen <chen.foxe@gmail.com>
Date: Fri May 22 18:30:52 2026 +0000
patch 9.2.0512: clientserver uses binary protocol
Problem: clientserver feature uses binary protocol and is hard
to understand
Solution: Rewrite the code based on channels and JSON messages
(Foxe Chen).
closes: #19782
Signed-off-by: Foxe Chen <chen.foxe@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 1d727b6f74896915a94f7d0e134d64cb0eac8045
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Fri May 22 18:09:33 2026 +0000
patch 9.2.0511: configure: when GTK4 is used also links in X11 libs
Problem: configure: when GTK4 is used also links in X11 libs
(Reilly Brogan)
Solution: Disable linking against X11 libraries when GTK4 GUI is to be
used (Yasuhiro Matsumoto)
GTK4 does not use any X11 APIs directly; the X11 backend is loaded by
GTK4 at runtime. Force with_x=no when --enable-gui=gtk4 so configure
does not probe for libICE/libSM/libX11/libXt/libXdmcp/libXpm, and so
packagers do not pull those into build dependencies. Also skip the
XSMP X11/SM/SMlib.h header check when X11 is disabled, since USE_XSMP
itself requires HAVE_X11.
fixes: #20268
closes: #20289
Co-authored-by: Claude <noreply@anthropic.com>
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit e3dedac77b2076210e7027b14a5927622434f014
Author: glepnir <glephunter@gmail.com>
Date: Fri May 22 17:59:23 2026 +0000
patch 9.2.0510: setline() mapping may trigger autoindent
Problem: setline() insert mode mapping may trigger autoindent,
corrupting the newly inserted line content (Evgeni Chasnovski)
Solution: Only strip autoindent whitespace when the rest of the line is
all whitespace (glepnir).
fixes: #19363
closes: #20290
Signed-off-by: glepnir <glephunter@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit c7645fcda50f95cc098545b70ce937a986b997d1
Author: Christian Brabandt <cb@256bit.org>
Date: Fri May 22 17:44:50 2026 +0000
runtime(doc): add a few references to mouse behaviour
fixes: #20281
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 44a1a6a33171ee34dddccf5236c38791fb489dfc
Author: Christian Brabandt <cb@256bit.org>
Date: Thu May 21 20:15:59 2026 +0000
runtime(doc): Update wrong shellescape() example
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 0b14d6de60dba104b3ff91461982072b5bbe95a5
Author: Antonio Giovanni Colombo <azc100@gmail.com>
Date: Thu May 21 20:13:42 2026 +0000
translation(it): Update Italian translation
Signed-off-by: Antonio Giovanni Colombo <azc100@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit daad5ea9058fae5c5c0014a0b49963d12caea9f8
Author: Muraoka Taro <koron.kaoriya@gmail.com>
Date: Thu May 21 20:05:14 2026 +0000
patch 9.2.0509: term.c: compile error when LOG_TRN is enabled
Problem: compile error when LOG_TRN is enabled
Solution: Use valid arguments (Muraoka Taro)
closes: #20278
Signed-off-by: Muraoka Taro <koron.kaoriya@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit b54e57ee54f0a4e6eac74b071071a9d85326de3a
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Thu May 21 19:57:06 2026 +0000
patch 9.2.0508: completion: cannot complete user cmd :K with 'ignorecase'
Problem: completion: cannot complete user cmd :K with 'ignorecase'
(rendcrx)
Solution: Skip the short-circuit when 'ignorecase' is set
(Yasuhiro Matsumoto)
The set_cmd_index() short-circuit for the :k command treats ":k<X>" as
":k {X}" (mark argument), which makes ":kz<Tab>" never reach the
command-name expansion path. With 'ignorecase' the same prefix on other
letters (":gz<Tab>") completes a user command like :Gz, so the result is
inconsistent. Skip the short-circuit when 'ignorecase' is set; default
behaviour is preserved so the existing :k tests still pass.
fixes: #20241
closes: #20275
Co-authored-by: zeertzjq <zeertzjq@outlook.com>
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 6845c7a63d573682b82d03d4ad606d27547f9498
Author: nyngwang <nyngwang@gmail.com>
Date: Thu May 21 19:54:22 2026 +0000
runtime(doc): fix a typo in :map-local
closes: #20276
Signed-off-by: nyngwang <nyngwang@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 1dfaeb4fa358586c3fa111c5d3fea34eb4278bc9
Author: Christian Brabandt <cb@256bit.org>
Date: Thu May 21 19:52:00 2026 +0000
runtime(doc): re-generate vim.man
related: #20186
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 06a2c7105c3d678cd0c04b934d26810af15b7470
Author: Hirohito Higashi <h.east.727@gmail.com>
Date: Thu May 21 19:45:59 2026 +0000
patch 9.2.0507: Vim9 class: public/protected member name clash uses same error
Problem: When a public member and a protected member in a Vim9
class have the same name (differing only in the leading '_'),
Vim reports E1369 "Duplicate variable", which is also used for
plain duplicate definitions. Users cannot tell from the
message whether the conflict is the public/protected naming
rule or a real duplicate.
Solution: Add a dedicated error E1406 "Public and protected member
have the same name" and emit it only when the name clash is
between a public and a protected member. Keep E1369 for
genuine duplicate variable definitions (Hirohito Higashi).
fixes: #20240
closes: #20277
Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit ff9fd819aeca68b55c013af78edec6da7e269a8f
Author: Guilherme Puida Moreira <guilherme@puida.xyz>
Date: Thu May 21 19:34:20 2026 +0000
runtime(debversions): Add stonking (26.10) as Ubuntu release name
closes: #20282
Signed-off-by: Guilherme Puida Moreira <guilherme@puida.xyz>
Signed-off-by: James McCoy <jamessan@jamessan.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit d0af3bcee1d91514a33fbaf19ccc2aa2ab73ba40
Author: Hirohito Higashi <h.east.727@gmail.com>
Date: Thu May 21 19:03:50 2026 +0000
runtime(doc): fix help tags for removed/reused error codes
Problem: Several error codes (E614, E1319, E1321, E1323, E1400, E1401,
E1402, E1406) were removed from errors.h in v9.1.0600 but
their *Ennn* tags remained in the help files, so :help Ennn
jumps to obsolete locations. E1395 was later reused with a
new meaning ("Using a null class") in v9.1.1119, but its tag
is still placed in the type-alias section.
Solution: Remove the stale *Ennn* tags from the help files. Move
*E1395* to the vim9.txt null-values section to match its
current meaning. Also fix the indentation of *E1411*.
Regenerate runtime/doc/tags.
closes: #20279
Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 85eb099bf2210a3882005c0bf5d47306902c999e
Author: Cyril Roelandt <tipecaml@gmail.com>
Date: Wed May 20 21:15:33 2026 +0000
runtime(mbsync): Properly handle values for the "Sync" keyword
This has been manually tested with my personal mbsync configuration and
with the following test file:
$ cat test.mbsyncrc
Channel Foo
# None may not be combined with other operations
Sync None
Sync None New
# First form
Sync Pull
Sync Push
Sync New
Sync Old
Sync Upgrade
Sync ReNew
Sync Gone
Sync Delete
Sync Flags
Sync Invalid
# Second form
Sync PullNew
Sync PullOld
Sync PullUpgrade
Sync PullReNew
Sync PullGone
Sync PullDelete
Sync PullFlags
Sync PullFull
Sync PullAll
Sync PullInvalid
Sync PushNew
Sync PushOld
Sync PushUpgrade
Sync PushReNew
Sync PushGone
Sync PushDelete
Sync PushFlags
Sync PushFull
Sync PushAll
Sync PushInvalid
Sync NewInvalid
# Multiple operations
Sync New Upgrade Gone Flags
# Mix of the two styles (an example from the mbsync manpage)
Sync PullNew PullGone Push
# Syntaxically correct, though they will raise a warning in mbsync:
Sync PullNew Pull
Sync PullNew Gone Push
closes: #20243
Signed-off-by: Pierrick Guillaume <pguillaume@fymyte.com>
Signed-off-by: Cyril Roelandt <tipecaml@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit a0931a90eeee6692556f330b5ba1fb413f9ea85d
Author: John Marriott <basilisk@internode.on.net>
Date: Wed May 20 18:38:55 2026 +0000
patch 9.2.0506: home_replace() function can be improved
Problem: home_replace() function can be improved
Solution: Refactor home_replace() to return the length of the string
(John Marriott).
In addition:
- in function set_b0_fname() move ulen into the block where it is used.
- In function findswapname() rework logic around displaying "swap file
already exists" dialogue so that literal message text is set once.
closes: #20249
Signed-off-by: John Marriott <basilisk@internode.on.net>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit aee12156ee3018efcdae87a8c2c327db386f0a5d
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Wed May 20 18:36:11 2026 +0000
runtime(doc): fix GTK4 package name in src/INSTALL
The GTK4 section in src/INSTALL pointed at libgtk-3-dev. Use
libgtk-4-dev and note that GTK4 is not the default and requires
--enable-gui=gtk4.
closes: #20254
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit aed758986de7e677d63b1f6caa845938a2fabbdc
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Wed May 20 18:26:14 2026 +0000
patch 9.2.0505: GTK4: text looks blurry on HiDPI displays
Problem: GTK4: text looks blurry on HiDPI displays
(Foxe Chen, after v9.2.0501)
Solution: Allocate the cairo surface at physical resolution and set the
device scale, recreate it on scale-factor changes
(Yasuhiro Matsumoto).
The backing cairo image surface was created at logical pixel size, so
GTK4 upscaled it when blitting to the physical framebuffer. Allocate
the surface at width*scale x height*scale and apply
cairo_surface_set_device_scale() so drawing code keeps using logical
coordinates while the surface itself has full physical resolution.
Also recreate the surface on notify::scale-factor when the window
moves between monitors with different scales.
fixes: #20252
closes: #20258
Co-authored-by: Claude <noreply@anthropic.com>
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 146f46e26446f75a25457d8b00065f7057352d8e
Author: Lifepillar <lifepillar@lifepillar.me>
Date: Wed May 20 18:20:04 2026 +0000
runtime(context,typeset): Correct whitespace error in Log()'s 'edit' command
Also drop Last Change headers as this commit comes from the plugin's
maintainer.
related: #20242
related: #20244
closes: #20263
Signed-off-by: Lifepillar <lifepillar@lifepillar.me>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 8cbc77e957106160cfc9c46215cee1db54c3fe6b
Author: James McCoy <jamessan@debian.org>
Date: Sat May 9 19:41:47 2026 -0400
release package vim version 2:9.2.0461-1
Signed-off-by: James McCoy <jamessan@debian.org>
commit e3fc7d5e56b1d773ad1819a89a4dd3c23302ca2f
Author: James McCoy <jamessan@debian.org>
Date: Sat May 9 16:45:07 2026 -0400
Update changelog for 9.2.0461
Signed-off-by: James McCoy <jamessan@debian.org>
commit 060d57f64709906a8266c8465f7de1accebdea43
Merge: 503107706 4f610f07b
Author: James McCoy <jamessan@debian.org>
Date: Sat May 9 16:31:44 2026 -0400
Merge tag 'v9.2.0461' into debian/sid
v9.2.0461
commit 4f610f07b76b4f34d011179c2531ab4517ac11e8
Author: Christian Brabandt <cb@256bit.org>
Date: Sat May 9 14:41:37 2026 +0000
patch 9.2.0461: Corrupted undofile causes use-after-free
Problem: The four pointer-resolution loops in u_read_undo() lack
an i != j guard, so a header whose uh_next.seq equals
its own uh_seq resolves uh_next.ptr to itself. On
buffer close, u_freeheader() sees uhp->uh_next.ptr !=
NULL and skips updating b_u_oldhead, so u_blockfree()
dereferences the freed header on the next iteration.
The same pattern applies to uh_prev, uh_alt_next and
uh_alt_prev. A crafted .un~ file in the same directory
as a text file can trigger the use-after-free and
subsequent double-free when the buffer is closed.
(Daniel Cervera)
Solution: Add an i != j guard to each of the four resolution
loops, matching the guard already present in the
duplicate-detection loop above.
closes: #20168
Supported by AI
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit abd74fa122451882b3b4e7b83813cf3b17e8109a
Author: zeertzjq <zeertzjq@outlook.com>
Date: Sat May 9 14:18:53 2026 +0000
patch 9.2.0460: did_set_shellpipe_redir() in wrong file
Problem: did_set_shellpipe_redir() is a callback for a string option,
but is not in optionstr.c (after 9.2.0458).
Solution: Move it to optionstr.c. Also add missing change from patch
9.2.0455 (zeertzjq).
related: #20159
related: #20164
closes: #20170
Signed-off-by: zeertzjq <zeertzjq@outlook.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 124f8bececb1a50e85965d12ccd52c6c25a73122
Author: Christian Brabandt <cb@256bit.org>
Date: Sat May 9 14:13:52 2026 +0000
patch 9.2.0459: tests: test_termcodes fails (after v9.2.0456)
Problem: tests: test_termcodes fails, because it disabled DECRQM, but
did not adjust the expected values in the test (after v9.2.0456)
Solution: Update the test
related: #20161
closes: #20173
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit fbec828c7e3144aad2c9b9a207773ad0a4a46b9a
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Date: Sat May 9 13:49:43 2026 +0000
CI: Bump the github-actions group across 1 directory with 2 updates
Bumps the github-actions group with 2 updates in the / directory: [github/codeql-action](https://github.com/github/codeql-action) and [actions/labeler](https://github.com/actions/labeler).
Updates `github/codeql-action` from 4.35.2 to 4.35.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/v4.35.2...v4.35.3)
Updates `actions/labeler` from 6 to 6.0.1
- [Release notes](https://github.com/actions/labeler/releases)
- [Commits](https://github.com/actions/labeler/compare/v6...v6.0.1)
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 4.35.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: actions/labeler
dependency-version: 6.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
...
closes: #20171
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 84ae09dd79b9888ba71dc2a28f9afcac3e7b8901
Author: Christian Brabandt <cb@256bit.org>
Date: Fri May 8 21:29:21 2026 +0000
patch 9.2.0458: Crash with invalid shellredir/shellpipe value
Problem: Crash with invalid shellredir/shellpipe value
(bfredl)
Solution: Validate the option and allow only a single "%s".
fixes: #20157
closes: #20159
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 2f00656b3480ed5384ce0513402025de9643462c
Author: Christian Brabandt <cb@256bit.org>
Date: Fri May 8 21:22:28 2026 +0000
patch 9.2.0457: Compile warning about unused variable
Problem: Compile warning about unused variable
(Tony Mechelynck, after v9.2.0452)
Solution: Initialize the variable
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 7644d9d6114d0b17bfaebb069dd68ae0d7d907fb
Author: Foxe Chen <chen.foxe@gmail.com>
Date: Fri May 8 21:14:52 2026 +0000
patch 9.2.0456: stray p character displayed on some terms
Problem: stray p character displayed on some terms
Solution: Make sending DECRQM more strict and disable it for a few more
terminals (Foxe Chen)
fixes: #20156
fixes: #20140
closes: #20161
Signed-off-by: Foxe Chen <chen.foxe@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 9694ff58fe510bf3906a7b6817429e29d5975987
Author: zeertzjq <zeertzjq@outlook.com>
Date: Fri May 8 21:09:48 2026 +0000
patch 9.2.0455: 'findfunc' only allows extra info for cmdline completion
Problem: 'findfunc' only allows extra info for cmdline completion, not
for actually finding files (Maxim Kim, after 9.2.0451).
Solution: Handle returning a list of dicts when actually finding files.
Also fix crash on NULL string (zeertzjq).
fixes: #20163
closes: #20164
Signed-off-by: zeertzjq <zeertzjq@outlook.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit b207b5a2a38dd8f45417e69c2e659c4c05ad3c1e
Author: zeertzjq <zeertzjq@outlook.com>
Date: Fri May 8 21:06:08 2026 +0000
patch 9.2.0454: tests: no test that "abbr" in customlist completion is shown
Problem: No test that "abbr" in customlist completion is shown in pum.
Solution: Add some "abbr" fields to the existing test (zeertzjq).
closes: #20165
Signed-off-by: zeertzjq <zeertzjq@outlook.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit c895390e58fb080f94dcc1c60757a3d697698515
Author: Hirohito Higashi <h.east.727@gmail.com>
Date: Fri May 8 20:57:34 2026 +0000
patch 9.2.0453: vertical separator of statusline blend into active statusline
Problem: Since v9.2.0349, the vertical separator cell at status line
rows is drawn as a space with StatusLine highlight, hiding the
user's 'fillchars' "vert" or "stl"/"stlnc" character at that
cell (after v9.2.0349)
Solution: Drop the status line blend. At status line rows the separator
cell goes back to using the status fillchar when adjacent
status lines are connected, or the vsep character otherwise.
(Same as before v9.2.0348)
Keep the VertSplitNC highlight group introduced in v9.2.0349. The
highlight (VertSplit vs VertSplitNC) is selected based on whether the
current window is adjacent to the separator at the row.
Vertical separators are redrawn on current-window changes and on
:redrawstatus[!] so the VertSplit/VertSplitNC highlight is updated
immediately.
fixes: #20089
related: #19951
closes: #20167
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit b9871cef1073dfbcb74b73d9b939b374d6bd50e5
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Thu May 7 19:40:16 2026 +0000
patch 9.2.0452: screen.c popup opacity blend logic is duplicated
Problem: screen_line() has four near-identical blocks computing
the popup_attr, the combined attr, the blend value and
the underlying base attr in sequence when handling popups
with opacity. The duplication makes the function long
and hard to follow, and changes have to be applied to all
four sites.
Solution: Extract the shared computation into popup_blend_with_base()
and popup_base_attr_or() helpers, and cache per-popup
attrs once via popup_opacity_T. No behavior change
(Yasuhiro Matsumoto).
closes: #20154
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 58124789aaf98fd96cd94a738633fd652a5e079a
Author: zeertzjq <zeertzjq@outlook.com>
Date: Thu May 7 19:29:06 2026 +0000
patch 9.2.0451: 'findfunc' can't return extra info for cmdline completion
Problem: 'findfunc' can't return extra info for cmdline completion
(Maxim Kim).
Solution: Handle 'findfunc' return value in cmdline completion like that
of "customlist" functions (zeertzjq).
fixes: #20155
closes: #20158
Signed-off-by: zeertzjq <zeertzjq@outlook.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 92993329178cb1f72d700fff45ca86e1c2d369f8
Author: Christian Brabandt <cb@256bit.org>
Date: Wed May 6 20:50:00 2026 +0200
patch 9.2.0450: [security]: heap buffer overflow in spellfile.c read_compound()
Problem: read_compound() in spellfile.c computes the size of the regex
pattern buffer using signed-int arithmetic on the attacker
controlled SN_COMPOUND sectionlen. With sectionlen=0x40000008
and UTF-8 encoding active the multiplication wraps to 27 while
the per-byte loop writes up to ~1B bytes, overflowing the heap.
Reachable when loading a crafted .spl file (e.g. via 'set spell'
after a modeline sets 'spelllang'). The cp/ap/crp allocations
have the same int + 1 overflow class (Daniel Cervera)
Solution: Use type size_t as buffer size and reject values larger than
COMPOUND_MAX_LEN (100000). Apply the same size_t treatment to
the cp/ap/crp allocations.
Github Advisory:
https://github.com/vim/vim/security/advisories/GHSA-q4jv-r9gj-6cwv
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 4cbdef8e30cd5da5d3a0941ab88bf082b0b1e164
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Wed May 6 18:24:51 2026 +0000
runtime(vim9): Check cmd.exe on WSL is executable
closes: #20150
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 0ab4316fced588dd8d5aba1284c0ada14aa8eb7a
Author: Christian Brabandt <cb@256bit.org>
Date: Wed May 6 18:17:00 2026 +0000
patch 9.2.0449: Make proto fails in non GTK builds
Problem: Make proto fails when not building the GTK gui
Solution: Test for $GLIB_COMPILE_RESOURCES as done elsewhere
closes: #20145
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 4bcc8ba93d4d7b6b216dc6a0365e21676b70c715
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Wed May 6 18:02:09 2026 +0000
patch 9.2.0448: Vim9: dangling cmdline pointer after skip_expr_cctx()
Problem: Vim9: dangling cmdline pointer after skip_expr_cctx()
(Foxe Chen)
Solution: Extract the cmdline restoration logic from compile_lambda into
a helper restore_cmdline_arg() and call it from
skip_expr_cctx() too, so a skipped lambda inside an "else"
branch does not leave "*arg" pointing into freed evalarg
memory (Yasuhiro Matsumoto).
fixes: #20147
closes: #20148
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit c06002f3cb07c374bfc1a1310cf13ee1914e86da
Author: magnus-rattlehead <magnus-rattlehead@users.noreply.github.com>
Date: Tue May 5 20:35:32 2026 +0000
patch 9.2.0447: cindent does not ignore comments
Problem: When find_start_brace() scans backwards for the enclosing
block, '{' and '}' inside // and /* */ comments are counted,
producing wrong indent for code following such comments
(rendcrx).
Solution: Implement FM_SKIPCOMM in findmatchlimit() to track block-
comment state and skip matches inside comments. Pass
FM_SKIPCOMM from cindent's call sites
(find_start_brace, find_match_char, cin_iswhileofdo,
get_c_indent).
fixes: #4
fixes: #648
fixes: #19578
closes: #19581
closes: #20111
Signed-off-by: magnus-rattlehead <guranjakustivi@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 7ccc273a4cb6012e5afbdb94d0f2597bc01fe2fd
Author: J. Paulo Seibt <jpseibt@gmail.com>
Date: Tue May 5 20:06:15 2026 +0000
patch 9.2.0446: runtime(netrw): off-by-one bug in s:NetrwUnMarkFile()
Problem: off-by-one bug in s:NetrwUnMarkFile()
Solution: Correctly loop through all buffers to unlet all variables
(J. Paulo Seibt)
When the function loops through buffers to clear s:netrwmarkfilelist_#
and s:netrwmarkfilemtch_#, it skips the last one at bufnr('$'), messing
up mark highlights and causing other functions that operate on those
arrays (like delete or rename) to target stale marked files.
The bufnr() help page says that bufnr("$") returns the highest buffer
number of existing buffers, so while ibuf < bufnr("$") does not clear
the last buffer-local arrays.
To reproduce:
Just opening a fresh Vim and running :Ex opens a netrw buffer at the
highest number. Then, typing mu after marking some files triggers the
mark highlight bug, and finally typing D would act like calling the
delete function against the previous marked files, as the buffer-local
arrays where not touched by s:NetrwUnMarkFile.
closes: #20129
Signed-off-by: J. Paulo Seibt <jpseibt@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 40fc78f0a185f003844334e7c9dd217d6d993143
Author: Jesse Rosenstock <jmr@google.com>
Date: Tue May 5 19:50:46 2026 +0000
patch 9.2.0445: win_fix_scroll() called before win_comp_pos() in command_height()
Problem: win_fix_scroll(true) is called before win_comp_pos() in
command_height().
Solution: Move win_fix_scroll(true) after win_comp_pos(), matching the
ordering used in win_drag_status_line() (Jesse Rosenstock).
Patch 9.2.0413 added win_fix_scroll(true) to command_height() to handle
splitkeep when cmdheight changes, but placed the call before win_comp_pos().
win_fix_scroll() reads w_winrow to detect window movement
(https://github.com/vim/vim/blob/620557bd48865fa3d927901764d2747bf68597b5/src/window.c#L7266),
but w_winrow is not recomputed until win_comp_pos() runs
(https://github.com/vim/vim/blob/620557bd48865fa3d927901764d2747bf68597b5/src/window.c#L6516).
This causes incorrect scroll adjustments and was breaking
Test_smoothscroll_incsearch on macOS CI.
closes: #20138
Co-authored-by: Gemini
Signed-off-by: Jesse Rosenstock <jmr@google.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 88fb739918a0d2ca4277e1e79b4fd5799e9b0128
Author: Christian Brabandt <cb@256bit.org>
Date: Tue May 5 19:47:19 2026 +0000
patch 9.2.0444: Cannot set 'path' option via modeline
Problem: Cannot set 'path' option via modeline (zeertzjq, after v9.2.0435)
Solution: Revert the part that disallows setting 'path' via modeline.
closes: #20137
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit cf947e7ef09fc8a63f447b54b107585b8f3b7abe
Author: Hirohito Higashi <h.east.727@gmail.com>
Date: Tue May 5 19:02:59 2026 +0000
patch 9.2.0443: GUI: cancelling save dialog overwrites or discards unnamed buffer
Problem: When closing gvim with an unsaved unnamed buffer, choosing
"Yes" in the "Save changes?" dialog and then "Cancel" in the
file selection dialog either silently writes the buffer to a
file named "Untitled" (overwriting any existing file with
that name) or discards the buffer altogether
(vibs29, after v9.1.0265).
Solution: In dialog_changed(), if browse_save_fname() leaves the buffer
without a file name, treat it as a cancel and return without
saving. Also stop clearing the modified flag in the restore
path on write failure, so the unsaved changes are kept and
the caller (e.g. gui_shell_closed()) can also cancel the
close. Pre-fill the file dialog with "Untitled" to match
the preceding "Save changes to ..." prompt. Add a test for
the write-failure path (Hirohito Higashi).
fixes: #20132
closes: #20143
Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 2bfddbea47e1afa79ecd094040418abdba88bc83
Author: zeertzjq <zeertzjq@outlook.com>
Date: Tue May 5 18:56:56 2026 +0000
patch 9.2.0442: completion: i_CTRL-X_CTRL-V doesn't use dict from customlist
Problem: Completion with i_CTRL-X_CTRL-V doesn't use dict from cmdline
"customlist" completion.
Solution: Include abbr/kind/menu/info in the completion items
(zeertzjq).
closes: #20139
Signed-off-by: zeertzjq <zeertzjq@outlook.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 1903020b82eb49c26c8f83ad29f7f2d1d317a81e
Author: Arnaud Rebillout <elboulangero@gmail.com>
Date: Mon May 4 20:31:51 2026 +0000
runtime(autopkgtest): update syntax script
Fix some typos, and move a deprecated keyword where it belongs
closes: #20141
Signed-off-by: Arnaud Rebillout <arnaudr@debian.org>
Signed-off-by: James McCoy <jamessan@jamessan.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit b10159bcc22aa1c976234a6b2677f11438bef953
Author: mityu <mityu.mail@gmail.com>
Date: Mon May 4 20:24:07 2026 +0000
Fix wrong comment in getchar.c
The comment for `do_key_input_pre()` function says that it handles the
InsertCharPre autocommand, but what the function actually handles is the
KeyInputPre autocommand.
closes: #20142
Signed-off-by: mityu <mityu.mail@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 8c7d824b73ff939890f13c3792e45833a651a840
Author: Hirohito Higashi <h.east.727@gmail.com>
Date: Mon May 4 20:03:46 2026 +0000
patch 9.2.0441: statusline: click handler not called on multi-line statusline
Problem: With a multi-line statusline clicking on a "%[FuncName]...%[]"
or "%@FuncName@..." region defined on a row other than the
last drawn row does not invoke the handler (Christian
Robinson, after v9.2.0338)
Solution: In win_redr_custom() the click region table reflects only the
last iteration of the per-row draw loop, so click regions are
recorded only for the last row. Move the click-region
resolution inside the loop and append regions for each row
using vim_realloc(). This also fixes a leak of
clicktab[].funcname for non-last rows (Hirohito Higashi).
fixes: #20116
closes: #20120
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 0c998003bc6ae20e10a6a7362edf52da2eb12019
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Mon May 4 19:58:27 2026 +0000
patch 9.2.0440: MS-Windows: cursor flicker during update_screen()
Problem: MS-Windows: cursor flicker during update_screen()
Solution: Hide the cursor during update_screen() to avoid Windows ConPTY
flicker (Yasuhiro Matsumoto).
On terminals that do not honor synchronized output mode (e.g. Windows
ConPTY), update_screen() emits cell positioning and content as multiple
Win32 console writes through mch_write(), which the terminal renders as
separate frames. This shows up as the cursor briefly jumping to column
1 of rows being redrawn, especially during async redraws around the
popup completion menu.
Disable the cursor with cursor_off() at the start of update_screen()
and restore it with cursor_on() at the end, but only when synchronized
output mode is not active. When it is, the redraw is already atomic
from the terminal's view and hiding the cursor would only add visible
blink with no benefit.
closes: #20121
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 3bfffcc29054faff2dbec2d765317ee09e9ef827
Author: zeertzjq <zeertzjq@outlook.com>
Date: Mon May 4 19:53:10 2026 +0000
patch 9.2.0439: completion: info popup not removed in cmdline mode
Problem: Info popup isn't removed when selecting an item that doesn't
have "info" in cmdline completion, which is inconsistent with
Insert mode behavior.
Solution: Set pum_call_update_screen in cmdline mode (zeertzjq).
closes: #20128
Signed-off-by: zeertzjq <zeertzjq@outlook.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 20a124a6e0e2445c500ccc7c496a8fe5d334aed8
Author: Jesse Rosenstock <jmr@google.com>
Date: Mon May 4 19:22:25 2026 +0000
patch 9.2.0438: tests: test_plugin_termdebug is flaky
Problem: Test_termdebug_tbreak(), Test_termdebug_basic(), and
Test_termdebug_toggle_break() use synchronous assert_equal()
to check breakpoint signs immediately after sending commands
to gdb. On slow CI (ASAN, ARM64, macOS) gdb may not have
processed the response yet, causing the sign to be missing.
Solution: Wrap the three assertions in WaitForAssert() to poll until
the signs are placed, matching the pattern already used by
the other assertions in the same tests (Jesse Rosenstock).
closes: #20133
Co-authored-by: Gemini
Signed-off-by: Jesse Rosenstock <jmr@google.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit bb807ebc8a7a6ad3f3d330cf19ce775cb40a2811
Author: Hirohito Higashi <h.east.727@gmail.com>
Date: Mon May 4 19:17:52 2026 +0000
runtime(doc): Tweak documentation style
closes: #20134
Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit cb0b4cf45c627263c844348a0ec6388dcfef9fcb
Author: Felipe Matarazzo <felipemps@protonmail.com>
Date: Mon May 4 19:10:37 2026 +0000
Fix a few more typos
closes: #20135
Signed-off-by: Felipe Matarazzo <felipemps@protonmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 9d3019104c37bad56ff5bdc7614b26cb3fea7ce4
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Sun May 3 18:37:05 2026 +0000
patch 9.2.0437: MS-Windows: cursor flicker in vtp mode
Problem: MS-Windows: cursor flicker in vtp mode
Solution: Skip mch_update_cursor() in cursor_visible() when vtp is
active (Yasuhiro Matsumoto).
In vtp (ConPTY) mode the cursor visibility is controlled by DECTCEM
(\033[?25h / \033[?25l). The follow-up call to mch_update_cursor() then
re-emits DECSCUSR (\033[0 q etc.) on every visibility toggle even though
the cursor shape did not change. Some terminals briefly redisplay the
cursor when DECSCUSR arrives, so this can cause a visible flash at the
position the cursor will be moved to next (e.g. column 0 ahead of a line
redraw).
In non-vtp mode the call is still required because SetConsoleCursorInfo()
inside mch_set_cursor_shape() reads s_cursor_visible to apply the
visibility change, so keep that path unchanged.
closes: #20122
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 503107706dc699a52c3b399e67b1d163c600bc02
Author: James McCoy <jamessan@debian.org>
Date: Sat May 2 10:40:28 2026 -0400
release package vim version 2:9.2.0428-1
Signed-off-by: James McCoy <jamessan@debian.org>
commit 5007b15639fb465ead585ff986e772498a4bde40
Author: James McCoy <jamessan@debian.org>
Date: Fri May 1 20:44:15 2026 -0400
Bump changelog to 9.2.0428
Signed-off-by: James McCoy <jamessan@debian.org>
commit c772f6af820a72f78ea3dd018c059ce3ae72885a
Merge: 9cbb64573 59e59a62b
Author: James McCoy <jamessan@debian.org>
Date: Fri May 1 20:43:28 2026 -0400
Merge tag 'v9.2.0428' into debian/sid
v9.2.0428
commit 59e59a62b417c6cee7384718120a9378ee347064
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Fri May 1 16:28:51 2026 +0000
patch 9.2.0428: popup: no opacity support for completepopup/previewpopup
Problem: popup: no opacity support for completepopup/previewpopup
Solution: Add support opacity: suboption for the 'completeopt'.
Accepts opacity:0-100 with the same semantics as popup_create()'s
opacity option, allowing the info / preview popup to blend with
the background.
closes: #20099
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 7b218ae98c0f9a26ade91f0950e5c43d3c3c5b2b
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Fri May 1 16:10:21 2026 +0000
patch 9.2.0427: popup: opacity blend may leaks white bg color
Problem: popup: opacity blend may leaks white bg color
Solution: Add cterm color blending for 256 color terminals, use
COLOR_INVALID() macro to check for invalid color
(Yasuhiro Matsumoto)
When a textprop highlight only set gui=undercurl/guisp (no fg/bg), the
CTERMCOLOR sentinel was treated by hl_blend_attr() as a real near-white
color, leaking white bg onto textprop-covered cells under an opacity
popup or pum. Add a cterm color blending path that approximates blends
in the xterm 256-color palette using the gui RGB when available, so
opacity now has a visible effect even without 'termguicolors' (in
256-color terminals). Below 256 colors the blend is skipped.
Also document the requirement (GUI, 'termguicolors', or 256-color
terminal) and update existing pumopt/popupwin opacity screendumps to
reflect the new blended output.
closes: #20095
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit cf5d7102b9624f1bf230b6efad22f9bd0b39bd53
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Fri May 1 16:01:03 2026 +0000
patch 9.2.0426: tests: still some flaky screendump tests
Problem: tests: still some flaky screendump tests
(James McCoy)
Solution: Replace flaky VerifyScreenDump checks with assert_* assertions
for Test_visual_block_scroll and Test_scrolloffpad_with_folds,
and remove the now-unused dump files, mark those tests as
flaky (which happened previously for screendump tests
automatically) (Yasuhiro Matsumoto).
fixes: #20096
related: #20095
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit d25f8d1b2c6e0cbd390a36884c95edc88f1b3d69
Author: Shougo Matsushita <Shougo.Matsu@gmail.com>
Date: Fri May 1 14:54:56 2026 +0000
patch 9.2.0425: Cannot silence undo/redo messages
Problem: Cannot silence undo/redo messages
Solution: Add "u" flag to 'shortmess' option
(Shougo Matsushita).
fixes: #20049
closes: #20107
Signed-off-by: Shougo Matsushita <Shougo.Matsu@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit ec8b8bd82a905f0faf1a73bf57381597f0e25654
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Fri May 1 13:29:01 2026 +0000
patch 9.2.0424: popup: flicker when wildtrigger() refreshes the popup menu
Problem: popup: flicker when wildtrigger() refreshes the popup menu
Solution: Wrap the pum teardown and cmdline redraw in synchronized
terminal output (Yasuhiro Matsumoto).
Reduces flicker when wildtrigger() refreshes the popup on every
keystroke and the cmdline is wrapped: the un-scroll inside
update_screen() and the re-scroll inside redrawcmd() are emitted as
one atomic terminal update.
closes: #20081
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 587447ec64ffd9e6eaba329ffd9d778159ea6e32
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Fri May 1 13:25:31 2026 +0000
patch 9.2.0423: popup: wrapped cmdline truncated with wildoptions=pum
Problem: popup: wrapped cmdline truncated with wildoptions=pum
Solution: Call msg_starthere() in redrawcmd() to reset lines_left
before each redraw (Yasuhiro Matsumoto).
redrawcmd() leaves lines_left at its previous value, which decrements
across successive redraws (e.g. when wildtrigger() refreshes the popup
on every keystroke) until 0, after which msg_no_more aborts drawing
the wrapped cmdline. Call msg_starthere() to reset it.
related: #20081
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit ba85f88fe95db2daf3ea2542042af9e65308e2b8
Author: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Date: Fri May 1 13:12:11 2026 +0000
patch 9.2.0422: popup: leave stray char when scrollbar changes
Problem: popup: leave stray char when scrollbar changes
(Maxim Kim, after v9.2.0112)
Solution: refresh popup mask when scrollbar visibility changes
(Yasuhiro Matsumoto)
popup_adjust_position() set popup_mask_refresh only on geometry
changes, missing the case where w_has_scrollbar flips. After
popup_settext() shrinks the buffer enough that the scrollbar
disappears, the cell that held the old border / scrollbar was
never repainted, leaving stray characters.
fixes: #20092
closes: #20098
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 7f3243e3a8285badb0b2e34458cecaa9bfaadf49
Author: Ivan Pešić <27575106+eevan78@users.noreply.github.com>
Date: Thu Apr 30 18:06:46 2026 +0000
translation(sr): Update of Serbian translation
closes: #20105
Signed-off-by: Ivan Pešić <27575106+eevan78@users.noreply.github.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 7da90de1cb6df8f2dcbab97d3c7b8b83fa0de13d
Author: Léana 江 <leana.jiang+git@icloud.com>
Date: Thu Apr 30 18:00:28 2026 +0000
runtime(cabal): add missing haskell language editions
closes: #20097
Signed-off-by: Léana 江 <leana.jiang+git@icloud.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit f793e98068a3de540caf539ff0ecb35f06aa2a08
Author: Hirohito Higashi <h.east.727@gmail.com>
Date: Wed Apr 29 21:44:12 2026 +0000
runtime(doc): clarify separator cell on status line rows
- Expand hl-VertSplit / hl-VertSplitNC in syntax.txt to spell out which
character (space vs 'fillchars' "vert") and which highlight group
(StatusLine / StatusLineNC / VertSplit / VertSplitNC) are used at the
separator cell on each kind of screen row.
- Add cross references from hl-StatusLine and hl-StatusLineNC to
hl-VertSplit / hl-VertSplitNC.
The behavior itself is unchanged — see v9.2.0349 (c72196529) — but the
asymmetry reported in #20089 surprised users, so this aims to make the
spec discoverable from the highlight group docs.
closes: #20101
Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 620557bd48865fa3d927901764d2747bf68597b5
Author: Christian Brabandt <cb@256bit.org>
Date: Wed Apr 29 21:22:48 2026 +0000
runtime(doc): Update help tags file
forgotten from Commit e7e35b9e3866abcbb33e
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit e7e35b9e3866abcbb33eec789c85636671c86440
Author: Christian Brabandt <cb@256bit.org>
Date: Wed Apr 29 21:17:11 2026 +0000
runtime(doc): clarify that viminfo file should be trusted
Signed-off-by: Christian Brabandt <cb@256bit.org>
commit 77499e009af677720e747debebedb78d12a77cb6
Author: Christian Brabandt <cb@256bit.org>
Date: Wed Apr 29 20:36:14 2026 +0000
patch 9.2.0421: vimball: can smuggle Vimscript into VimballRecord file
Problem: vimball: can smuggle Vimscript into VimballRecord file
(Mayank Jangid and Kushal Khemka)
Solution: Disallow strange file names
Signed-off-by: Christian Brabandt <cb@256bit.org>
Among the 3 debian patches available in version 2:9.2.0782-1 of the package, we noticed the following issues:
Automatic checks made by the Debian l10n team found some issues with the translations contained in this package. You should check the l10n status report for more information.
Issues can be things such as missing translations, problematic translated strings, outdated PO files, unknown languages, etc.