diff --git a/LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md b/LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md
index 00165b945c9..35ab272d4d2 100644
--- a/LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md
+++ b/LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md
@@ -9,7 +9,7 @@ The Azure Linux SPEC files originated from a variety of sources with varying lic
| Fedora (Copyright Remi Collet) | [CC-BY-SA 4.0](https://creativecommons.org/licenses/by-sa/4.0/legalcode) | libmemcached-awesome
librabbitmq |
| Fedora (ISC) | [ISC License](https://github.com/sarugaku/resolvelib/blob/main/LICENSE) | python-requests-gssapi
python-resolvelib |
| Magnus Edenhill Open Source | [Magnus Edenhill Open Source BSD License](https://github.com/jemalloc/jemalloc/blob/dev/COPYING) | librdkafka |
-| Microsoft | [Microsoft MIT License](/LICENSES-AND-NOTICES/LICENSE.md) | application-gateway-kubernetes-ingress
asc
azcopy
azl-otel-collector
azure-iot-sdk-c
azure-nvme-utils
azure-storage-cpp
azurelinux-image-tools
azurelinux-release
azurelinux-repos
azurelinux-rpm-macros
azurelinux-sysinfo
bazel
bmon
bpftrace
ccache
cert-manager
cf-cli
check-restart
clamav
cloud-hypervisor
cloud-provider-kubevirt
cmake-fedora
containerd2
coredns
dasel
dcos-cli
debugedit
dejavu-fonts
distroless-packages
docker-buildx
docker-cli
docker-compose
doxygen
dtc
edk2-hvloader-signed
elixir
espeak-ng
espeakup
flannel
fluent-bit
freefont
gflags
gh
go-md2man
grpc
grub2-efi-binary-signed
GSL
gtk-update-icon-cache
intel-pf-bb-config
ivykis
jsonbuilder
jx
kata-containers-cc
kata-packages-uvm
keda
keras
kernel-64k-signed
kernel-hwe-signed
kernel-mshv-signed
kernel-signed
kernel-uki
kernel-uki-signed
kpatch
kube-vip-cloud-provider
kubernetes
libacvp
libconfini
libconfuse
libgdiplus
libimobiledevice-glue
libmaxminddb
libmetalink
libsafec
libuv
libxml++
lld
lsb-release
ltp
lttng-consume
mm-common
moby-containerd-cc
moby-engine
msgpack
ncompress
networkd-dispatcher
nlohmann-json
nmap
ntopng
opentelemetry-cpp
packer
pcaudiolib
pcre2
perl-Test-Warnings
perl-Text-Template
pigz
prebuilt-ca-certificates
prebuilt-ca-certificates-base
prometheus-adapter
python-cachetools
python-cherrypy
python-cstruct
python-execnet
python-google-pasta
python-libclang
python-libevdev
python-logutils
python-ml-dtypes
python-namex
python-nocasedict
python-omegaconf
python-opt-einsum
python-optree
python-pecan
python-pip
python-pyrpm
python-remoto
python-repoze-lru
python-routes
python-rsa
python-setuptools
python-sphinxcontrib-websupport
python-tensorboard
python-tensorboard-plugin-wit
python-yamlloader
R
rabbitmq-server
rocksdb
rubygem-addressable
rubygem-asciidoctor
rubygem-bindata
rubygem-concurrent-ruby
rubygem-connection_pool
rubygem-cool.io
rubygem-deep_merge
rubygem-digest-crc
rubygem-elastic-transport
rubygem-elasticsearch
rubygem-elasticsearch-api
rubygem-eventmachine
rubygem-excon
rubygem-faraday
rubygem-faraday-em_http
rubygem-faraday-em_synchrony
rubygem-faraday-excon
rubygem-faraday-httpclient
rubygem-faraday-multipart
rubygem-faraday-net_http
rubygem-faraday-net_http_persistent
rubygem-faraday-rack
rubygem-faraday-retry
rubygem-ffi
rubygem-fiber-local
rubygem-hirb
rubygem-hocon
rubygem-hoe
rubygem-http_parser
rubygem-httpclient
rubygem-io-event
rubygem-jmespath
rubygem-ltsv
rubygem-mini_portile2
rubygem-minitest
rubygem-mocha
rubygem-msgpack
rubygem-multi_json
rubygem-multipart-post
rubygem-net-http-persistent
rubygem-nio4r
rubygem-nokogiri
rubygem-oj
rubygem-parallel
rubygem-power_assert
rubygem-prometheus-client
rubygem-protocol-hpack
rubygem-protocol-http
rubygem-protocol-http1
rubygem-protocol-http2
rubygem-public_suffix
rubygem-puppet-resource_api
rubygem-rdiscount
rubygem-rdkafka
rubygem-rexml
rubygem-ruby-kafka
rubygem-ruby-progressbar
rubygem-rubyzip
rubygem-semantic_puppet
rubygem-serverengine
rubygem-sigdump
rubygem-strptime
rubygem-systemd-journal
rubygem-test-unit
rubygem-thor
rubygem-timers
rubygem-tzinfo
rubygem-tzinfo-data
rubygem-webhdfs
rubygem-webrick
rubygem-yajl-ruby
rubygem-zip-zip
runc
sdbus-cpp
sgx-backwards-compatibility
shim
skopeo
span-lite
sriov-network-device-plugin
SymCrypt
SymCrypt-OpenSSL
systemd-boot-signed
tardev-snapshotter
tensorflow
tinyxml2
toml11
tracelogging
trident
umoci
usrsctp
vala
valkey
vnstat
walinuxagent-acl-config
zstd |
+| Microsoft | [Microsoft MIT License](/LICENSES-AND-NOTICES/LICENSE.md) | application-gateway-kubernetes-ingress
asc
azcopy
azl-otel-collector
azure-iot-sdk-c
azure-nvme-utils
azure-storage-cpp
azurelinux-image-tools
azurelinux-release
azurelinux-repos
azurelinux-rpm-macros
azurelinux-sysinfo
bazel
bmon
bpftrace
ccache
cert-manager
cf-cli
check-restart
clamav
cloud-hypervisor
cloud-provider-kubevirt
cmake-fedora
containerd2
coredns
dasel
dcos-cli
debugedit
dejavu-fonts
distroless-packages
docker-buildx
docker-cli
docker-compose
doxygen
dtc
edk2-hvloader-signed
elixir
espeak-ng
espeakup
flannel
fluent-bit
freefont
gflags
gh
go-md2man
grpc
grub2-efi-binary-signed
GSL
gtk-update-icon-cache
intel-pf-bb-config
ivykis
jsonbuilder
jx
kata-containers-cc
kata-packages-uvm
keda
keras
kernel-64k-signed
kernel-hwe-signed
kernel-mshv-signed
kernel-signed
kernel-uki
kernel-uki-signed
kpatch
kube-vip-cloud-provider
kubernetes
libacvp
libconfini
libconfuse
libgdiplus
libimobiledevice-glue
libmaxminddb
libmetalink
libsafec
libuv
libxml++
lld
lsb-release
ltp
lttng-consume
mm-common
moby-containerd-cc
moby-engine
msgpack
ncompress
networkd-dispatcher
nlohmann-json
nmap
ntopng
opentelemetry-cpp
packer
pcaudiolib
pcre2
perl-Test-Warnings
perl-Text-Template
pigz
prebuilt-ca-certificates
prebuilt-ca-certificates-base
prometheus-adapter
python-cachetools
python-cherrypy
python-cstruct
python-execnet
python-google-pasta
python-libclang
python-libevdev
python-logutils
python-ml-dtypes
python-namex
python-nocasedict
python-omegaconf
python-opt-einsum
python-optree
python-pecan
python-pip
python-pyrpm
python-remoto
python-repoze-lru
python-routes
python-rsa
python-setuptools
python-sphinxcontrib-websupport
python-tensorboard
python-tensorboard-plugin-wit
python-yamlloader
R
rabbitmq-server
rocksdb
rubygem-addressable
rubygem-asciidoctor
rubygem-bindata
rubygem-concurrent-ruby
rubygem-connection_pool
rubygem-cool.io
rubygem-deep_merge
rubygem-digest-crc
rubygem-elastic-transport
rubygem-elasticsearch
rubygem-elasticsearch-api
rubygem-eventmachine
rubygem-excon
rubygem-faraday
rubygem-faraday-em_http
rubygem-faraday-em_synchrony
rubygem-faraday-excon
rubygem-faraday-httpclient
rubygem-faraday-multipart
rubygem-faraday-net_http
rubygem-faraday-net_http_persistent
rubygem-faraday-rack
rubygem-faraday-retry
rubygem-ffi
rubygem-fiber-local
rubygem-hirb
rubygem-hocon
rubygem-hoe
rubygem-http_parser
rubygem-httpclient
rubygem-io-event
rubygem-jmespath
rubygem-ltsv
rubygem-mini_portile2
rubygem-minitest
rubygem-mocha
rubygem-msgpack
rubygem-multi_json
rubygem-multipart-post
rubygem-net-http-persistent
rubygem-nio4r
rubygem-nokogiri
rubygem-oj
rubygem-parallel
rubygem-power_assert
rubygem-prometheus-client
rubygem-protocol-hpack
rubygem-protocol-http
rubygem-protocol-http1
rubygem-protocol-http2
rubygem-public_suffix
rubygem-puppet-resource_api
rubygem-rdiscount
rubygem-rdkafka
rubygem-rexml
rubygem-ruby-kafka
rubygem-ruby-progressbar
rubygem-rubyzip
rubygem-semantic_puppet
rubygem-serverengine
rubygem-sigdump
rubygem-strptime
rubygem-systemd-journal
rubygem-test-unit
rubygem-thor
rubygem-timers
rubygem-tzinfo
rubygem-tzinfo-data
rubygem-webhdfs
rubygem-webrick
rubygem-yajl-ruby
rubygem-zip-zip
runc
rust-bootstrap
sdbus-cpp
sgx-backwards-compatibility
shim
skopeo
span-lite
sriov-network-device-plugin
SymCrypt
SymCrypt-OpenSSL
systemd-boot-signed
tardev-snapshotter
tensorflow
tinyxml2
toml11
tracelogging
trident
umoci
usrsctp
vala
valkey
vnstat
walinuxagent-acl-config
zstd |
| Netplan source | [GPLv3](https://github.com/canonical/netplan/blob/main/COPYING) | netplan |
| Numad source | [LGPLv2 License](https://www.gnu.org/licenses/old-licenses/lgpl-2.1.txt) | numad |
| NVIDIA | [ASL 2.0 License and spec specific licenses](http://www.apache.org/licenses/LICENSE-2.0) | ibarr
ibdump
ibsim
iser
iser-hwe
iser-hwe-signed
iser-signed
isert
isert-hwe
isert-hwe-signed
isert-signed
libnvidia-container
libvma
mft_kernel
mft_kernel-hwe
mft_kernel-hwe-signed
mft_kernel-signed
mlnx-ethtool
mlnx-iproute2
mlnx-nfsrdma
mlnx-nfsrdma-hwe
mlnx-nfsrdma-hwe-signed
mlnx-nfsrdma-signed
mlnx-ofa_kernel
mlnx-ofa_kernel-hwe
mlnx-ofa_kernel-hwe-modules-signed
mlnx-ofa_kernel-modules-signed
mlnx-tools
mlx-bootctl
mlx-steering-dump
multiperf
nvidia-container-toolkit
ofed-docs
ofed-scripts
perftest
rshim
sockperf
srp
srp-hwe
srp-hwe-signed
srp-signed
xpmem
xpmem-hwe
xpmem-hwe-modules-signed
xpmem-modules-signed |
diff --git a/LICENSES-AND-NOTICES/SPECS/data/licenses.json b/LICENSES-AND-NOTICES/SPECS/data/licenses.json
index 4e89ffd5cd9..3967b3c9a30 100644
--- a/LICENSES-AND-NOTICES/SPECS/data/licenses.json
+++ b/LICENSES-AND-NOTICES/SPECS/data/licenses.json
@@ -2456,6 +2456,7 @@
"rubygem-yajl-ruby",
"rubygem-zip-zip",
"runc",
+ "rust-bootstrap",
"sdbus-cpp",
"sgx-backwards-compatibility",
"shim",
diff --git a/SPECS-EXTENDED/389-ds-base/389-ds-base.spec b/SPECS-EXTENDED/389-ds-base/389-ds-base.spec
index 8f52fcb6743..067b8fbaab8 100644
--- a/SPECS-EXTENDED/389-ds-base/389-ds-base.spec
+++ b/SPECS-EXTENDED/389-ds-base/389-ds-base.spec
@@ -68,7 +68,7 @@ ExcludeArch: i686
Summary: 389 Directory Server (%{variant})
Name: 389-ds-base
Version: 3.1.1
-Release: 11%{?dist}
+Release: 12%{?dist}
License: GPL-3.0-or-later AND (0BSD OR Apache-2.0 OR MIT) AND (Apache-2.0 OR Apache-2.0 WITH LLVM-exception OR MIT) AND (Apache-2.0 OR BSL-1.0) AND (Apache-2.0 OR MIT OR Zlib) AND (Apache-2.0 OR MIT) AND (CC-BY-4.0 AND MIT) AND (MIT OR Apache-2.0) AND Unicode-DFS-2016 AND (MIT OR CC0-1.0) AND (MIT OR Unlicense) AND 0BSD AND Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND ISC AND MIT AND MIT AND ISC AND MPL-2.0 AND PSF-2.0
URL: https://www.port389.org
Vendor: Microsoft Corporation
@@ -733,13 +733,16 @@ exit 0
%endif
%changelog
+* Wed Aug 19 2026 Kavya Sree Kaitepalli - 3.1.1-12
+- Bump release to rebuild with rust
+
* Wed Feb 11 2026 BinduSri Adabala - 3.1.1-11
- Bump release to rebuild with rust
* Mon Feb 02 2026 Archana Shettigar - 3.1.1-10
- Bump release to rebuild with rust
-* Tue Jan 13 2025 Kavya Sree Kaitepalli - 3.1.1-9
+* Tue Jan 13 2026 Kavya Sree Kaitepalli - 3.1.1-9
- Bump release to rebuild with rust
- Add patch add explicit lifetime for ValueArrayRef iterator
diff --git a/SPECS-EXTENDED/kata-containers-preview/kata-containers-preview.spec b/SPECS-EXTENDED/kata-containers-preview/kata-containers-preview.spec
index 1a08ea365c3..8686155e4ff 100644
--- a/SPECS-EXTENDED/kata-containers-preview/kata-containers-preview.spec
+++ b/SPECS-EXTENDED/kata-containers-preview/kata-containers-preview.spec
@@ -5,7 +5,7 @@
Name: kata-containers-preview
Version: 3.27.0~preview2
-Release: 1%{?dist}
+Release: 2%{?dist}
Summary: Kata Containers preview package developed for Pod Sandboxing on AKS
License: ASL 2.0
@@ -14,6 +14,9 @@ Vendor: Microsoft Corporation
Distribution: Azure Linux
Source0: https://github.com/microsoft/kata-containers/archive/refs/tags/%{upstream_ver}.tar.gz#/kata-containers-%{upstream_ver}.tar.gz
Source1: kata-containers-%{upstream_ver}-cargo.tar.gz
+Patch0: rust-fix-unstable-name-collisions.patch
+# This patch can be removed when this package is upgraded to v3.32.0
+Patch1: rust-1.96-protection-cpuid.patch
BuildRequires: azurelinux-release
BuildRequires: golang
BuildRequires: protobuf-compiler
@@ -115,6 +118,9 @@ popd
%{tools_pkg}/tools/osbuilder/node-builder/azure-linux/agent-install/usr/lib/systemd/system/kata-agent.service
%changelog
+* Wed Aug 19 2026 Kavya Sree Kaitepalli - 3.27.0~preview2-2
+- Bump release to rebuild with rust
+
* Mon Apr 13 2026 CBL-Mariner Servicing Account - 3.27.0.preview2-1
- Auto-upgrade to 3.27.0.preview2
diff --git a/SPECS-EXTENDED/kata-containers-preview/rust-1.96-protection-cpuid.patch b/SPECS-EXTENDED/kata-containers-preview/rust-1.96-protection-cpuid.patch
new file mode 100644
index 00000000000..bdf1b7b0879
--- /dev/null
+++ b/SPECS-EXTENDED/kata-containers-preview/rust-1.96-protection-cpuid.patch
@@ -0,0 +1,44 @@
+From a63a948b4afcc266a06ef18f2cb46440c48e8bb6 Mon Sep 17 00:00:00 2001
+From: stevenhorsman
+Date: Mon, 1 Jun 2026 17:04:43 +0100
+Subject: [PATCH] libs: Remove unnecessary unsafe blocks in protection.rs
+
+Rust 1.94 now warns about unnecessary unsafe blocks around
+x86_64::__cpuid() calls. Remove the unsafe blocks as they are
+no longer needed.
+
+This fixes the following clippy warnings:
+- warning: unnecessary `unsafe` block at line 129
+- warning: unnecessary `unsafe` block at line 142
+
+Signed-off-by: stevenhorsman
+Generated-By: IBM Bob
+
+Upstream-Commit: https://github.com/kata-containers/kata-containers/commit/a63a948b4afcc266a06ef18f2cb46440c48e8bb6
+Upstream-Status: Backport
+---
+ src/libs/kata-sys-util/src/protection.rs | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/src/libs/kata-sys-util/src/protection.rs b/src/libs/kata-sys-util/src/protection.rs
+index 77d2698d0de5..38a38009a501 100644
+--- a/src/libs/kata-sys-util/src/protection.rs
++++ b/src/libs/kata-sys-util/src/protection.rs
+@@ -126,7 +126,7 @@ pub fn arch_guest_protection(
+ // shouldn't hurt to double-check and have better logging if anything
+ // goes wrong.
+
+- let fn0 = unsafe { x86_64::__cpuid(0) };
++ let fn0 = x86_64::__cpuid(0);
+ // The values in [ ebx, edx, ecx ] spell out "AuthenticAMD" when
+ // interpreted byte-wise as ASCII. No need to bother here with an
+ // actual conversion to string though.
+@@ -139,7 +139,7 @@ pub fn arch_guest_protection(
+ }
+
+ // AMD64 Architecture Prgrammer's Manual Fn8000_001f docs on pg. 640
+- let fn8000_001f = unsafe { x86_64::__cpuid(0x8000_001f) };
++ let fn8000_001f = x86_64::__cpuid(0x8000_001f);
+ if fn8000_001f.eax & 0x10 == 0 {
+ return Err(ProtectionError::CheckFailed("SEV not supported".to_owned()));
+ }
diff --git a/SPECS-EXTENDED/kata-containers-preview/rust-fix-unstable-name-collisions.patch b/SPECS-EXTENDED/kata-containers-preview/rust-fix-unstable-name-collisions.patch
new file mode 100644
index 00000000000..09063b33b24
--- /dev/null
+++ b/SPECS-EXTENDED/kata-containers-preview/rust-fix-unstable-name-collisions.patch
@@ -0,0 +1,65 @@
+From 56d44062ea37b36e902fd89e91b09a897876d806 Mon Sep 17 00:00:00 2001
+From: stevenhorsman
+Date: Fri, 17 Apr 2026 14:42:50 +0100
+Subject: [PATCH] libs: Fix unstable_name_collisions warnings
+
+Remove NixPath's is_empty() to avoid ambiguity with the future
+std::path::Path::is_empty() method and switch to
+path.as_os_str().is_empty as recommended by @burgerdev.
+
+This addresses unstable_name_collisions warnings in Rust 1.93.
+
+Fixes: #12835
+
+Upstream-Reference: https://github.com/kata-containers/kata-containers/commit/56d44062ea37b36e902fd89e91b09a897876d806
+
+Co-authored-by: Markus Rudy
+Signed-off-by: stevenhorsman
+---
+ src/libs/kata-sys-util/src/mount.rs | 10 +++++-----
+ 1 file changed, 5 insertions(+), 5 deletions(-)
+
+diff --git a/src/libs/kata-sys-util/src/mount.rs b/src/libs/kata-sys-util/src/mount.rs
+index 892e95639b93..ce9f807fcecb 100644
+--- a/src/libs/kata-sys-util/src/mount.rs
++++ b/src/libs/kata-sys-util/src/mount.rs
+@@ -52,7 +52,7 @@ use std::time::Instant;
+
+ use lazy_static::lazy_static;
+ use nix::mount::{mount, MntFlags, MsFlags};
+-use nix::{unistd, NixPath};
++use nix::unistd;
+ use oci_spec::runtime as oci;
+
+ use crate::fs::is_symlink;
+@@ -225,7 +225,7 @@ pub fn create_mount_destination, D: AsRef, R: AsRef>(
+ /// Caller needs to ensure safety of the `dst` to avoid possible file path based attacks.
+ pub fn bind_remount>(dst: P, readonly: bool) -> Result<()> {
+ let dst = dst.as_ref();
+- if dst.is_empty() {
++ if dst.as_os_str().is_empty() {
+ return Err(Error::NullMountPointPath);
+ }
+ let dst = dst
+@@ -262,10 +262,10 @@ pub fn bind_mount_unchecked, D: AsRef>(
+
+ let src = src.as_ref();
+ let dst = dst.as_ref();
+- if src.is_empty() {
++ if src.as_os_str().is_empty() {
+ return Err(Error::NullMountPointPath);
+ }
+- if dst.is_empty() {
++ if dst.as_os_str().is_empty() {
+ return Err(Error::NullMountPointPath);
+ }
+ let abs_src = src
+@@ -760,7 +760,7 @@ pub fn umount_timeout>(path: P, timeout: u64) -> Result<()> {
+ /// # Safety
+ /// Caller needs to ensure safety of the `path` to avoid possible file path based attacks.
+ pub fn umount_all>(mountpoint: P, lazy_umount: bool) -> Result<()> {
+- if mountpoint.as_ref().is_empty() || !mountpoint.as_ref().exists() {
++ if mountpoint.as_ref().as_os_str().is_empty() || !mountpoint.as_ref().exists() {
+ return Ok(());
+ }
+
diff --git a/SPECS-EXTENDED/ripgrep/ripgrep.spec b/SPECS-EXTENDED/ripgrep/ripgrep.spec
index 2cd01621c80..567fb2d306a 100644
--- a/SPECS-EXTENDED/ripgrep/ripgrep.spec
+++ b/SPECS-EXTENDED/ripgrep/ripgrep.spec
@@ -20,7 +20,7 @@
Name: ripgrep
Version: 13.0.0
-Release: 13%{?dist}
+Release: 14%{?dist}
Summary: A search tool that combines ag with grep
License: MIT AND Unlicense
Vendor: Microsoft Corporation
@@ -104,6 +104,9 @@ install -Dm 644 complete/_rg %{buildroot}%{_datadir}/zsh/site-functions/_rg
%{_datadir}/zsh
%changelog
+* Wed Aug 19 2026 Kavya Sree Kaitepalli - 13.0.0-14
+- Bump release to rebuild with rust
+
* Wed Feb 11 2026 BinduSri Adabala - 13.0.0-13
- Bump release to rebuild with rust
diff --git a/SPECS-EXTENDED/rust-cbindgen/rust-cbindgen.spec b/SPECS-EXTENDED/rust-cbindgen/rust-cbindgen.spec
index 39db2476345..b61681c8b71 100644
--- a/SPECS-EXTENDED/rust-cbindgen/rust-cbindgen.spec
+++ b/SPECS-EXTENDED/rust-cbindgen/rust-cbindgen.spec
@@ -2,7 +2,7 @@
Summary: Tool for generating C bindings to Rust code
Name: rust-cbindgen
Version: 0.24.3
-Release: 11%{?dist}
+Release: 12%{?dist}
License: MIT
Vendor: Microsoft Corporation
Distribution: Azure Linux
@@ -96,6 +96,9 @@ RUSTFLAGS=%{rustflags} cargo test --release
%endif
%changelog
+* Wed Aug 19 2026 Kavya Sree Kaitepalli - 0.24.3-12
+- Bump release to rebuild with rust
+
* Fri Jun 05 2026 BinduSri Adabala - 0.24.3-11
- Bump release to rebuild with rust
diff --git a/SPECS-EXTENDED/tardev-snapshotter/tardev-snapshotter.spec b/SPECS-EXTENDED/tardev-snapshotter/tardev-snapshotter.spec
index a09545fbdc8..9e7cdbb866f 100644
--- a/SPECS-EXTENDED/tardev-snapshotter/tardev-snapshotter.spec
+++ b/SPECS-EXTENDED/tardev-snapshotter/tardev-snapshotter.spec
@@ -3,7 +3,7 @@
Summary: Tardev Snapshotter for containerd
Name: tardev-snapshotter
Version: 3.2.0.tardev1
-Release: 9%{?dist}
+Release: 10%{?dist}
License: ASL 2.0
Group: Tools/Container
Vendor: Microsoft Corporation
@@ -67,6 +67,9 @@ fi
%config(noreplace) %{_unitdir}/%{name}.service
%changelog
+* Wed Aug 19 2026 Kavya Sree Kaitepalli - 3.2.0.tardev1-10
+- Bump release to rebuild with rust
+
* Fri Jun 05 2026 BinduSri Adabala - 3.2.0.tardev1-9
- Bump release to rebuild with rust
diff --git a/SPECS/clamav/clamav.spec b/SPECS/clamav/clamav.spec
index 47dc34ca309..eab551bdb51 100644
--- a/SPECS/clamav/clamav.spec
+++ b/SPECS/clamav/clamav.spec
@@ -1,7 +1,7 @@
Summary: Open source antivirus engine
Name: clamav
Version: 1.5.4
-Release: 1%{?dist}
+Release: 2%{?dist}
License: ASL 2.0 AND BSD AND bzip2-1.0.4 AND GPLv2 AND LGPLv2+ AND MIT AND Public Domain AND UnRar
Vendor: Microsoft Corporation
Distribution: Azure Linux
@@ -148,6 +148,9 @@ fi
%dir %attr(-,clamav,clamav) %{_sharedstatedir}/clamav
%changelog
+* Wed Aug 19 2026 Kavya Sree Kaitepalli - 1.5.4-2
+- Bump release to rebuild with rust
+
* Mon Aug 10 2026 CBL-Mariner Servicing Account - 1.5.4-1
- Auto-upgrade to 1.5.4 - CVE-2026-20348, CVE-2026-20345, CVE-2026-20347, CVE-2026-20346, CVE-2026-20339, CVE-2026-20337, CVE-2026-20338
diff --git a/SPECS/cloud-hypervisor/cloud-hypervisor.spec b/SPECS/cloud-hypervisor/cloud-hypervisor.spec
index 5ed75dc0203..2e7f541a344 100644
--- a/SPECS/cloud-hypervisor/cloud-hypervisor.spec
+++ b/SPECS/cloud-hypervisor/cloud-hypervisor.spec
@@ -5,7 +5,7 @@
Name: cloud-hypervisor
Summary: Cloud Hypervisor is an open source Virtual Machine Monitor (VMM) that runs on top of the KVM hypervisor and the Microsoft Hypervisor (MSHV).
Version: 51.1.101
-Release: 2%{?dist}
+Release: 3%{?dist}
License: ASL 2.0 OR BSD-3-clause
Vendor: Microsoft Corporation
Distribution: Azure Linux
@@ -137,6 +137,9 @@ cargo build --release --target=%{rust_musl_target} %{cargo_pkg_feature_opts} %{c
%license LICENSES/CC-BY-4.0.txt
%changelog
+* Wed Aug 19 2026 Kavya Sree Kaitepalli - 51.1.101-3
+- Bump release to rebuild with rust
+
* Fri Jun 05 2026 BinduSri Adabala - 51.1.101-2
- Bump release to rebuild with rust
diff --git a/SPECS/kata-containers-cc/kata-containers-cc.spec b/SPECS/kata-containers-cc/kata-containers-cc.spec
index 4179deb48af..102842cc921 100644
--- a/SPECS/kata-containers-cc/kata-containers-cc.spec
+++ b/SPECS/kata-containers-cc/kata-containers-cc.spec
@@ -3,7 +3,7 @@
Name: kata-containers-cc
Version: 3.15.0.aks0
-Release: 16%{?dist}
+Release: 17%{?dist}
Summary: Kata Confidential Containers package developed for Confidential Containers on AKS
License: ASL 2.0
URL: https://github.com/microsoft/kata-containers
@@ -19,6 +19,7 @@ Patch4: CVE-2025-5791.patch
Patch5: CVE-2025-4574.patch
Patch6: CVE-2026-42250.patch
Patch7: CVE-2026-56852.patch
+Patch8: rust-fix-unstable-name-collisions.patch
ExclusiveArch: x86_64
BuildRequires: azurelinux-release
@@ -154,6 +155,9 @@ fi
%{tools_pkg}/tools/osbuilder/node-builder/azure-linux/agent-install/usr/lib/systemd/system/kata-agent.service
%changelog
+* Wed Aug 19 2026 Kavya Sree Kaitepalli - 3.15.0.aks0-17
+- Fix unstable_name_collisions rust build errors in kata-sys-util mount.rs
+
* Mon Jul 27 2026 Azure Linux Security Servicing Account - 3.15.0.aks0-16
- Patch for CVE-2026-56852
diff --git a/SPECS/kata-containers-cc/rust-fix-unstable-name-collisions.patch b/SPECS/kata-containers-cc/rust-fix-unstable-name-collisions.patch
new file mode 100644
index 00000000000..09063b33b24
--- /dev/null
+++ b/SPECS/kata-containers-cc/rust-fix-unstable-name-collisions.patch
@@ -0,0 +1,65 @@
+From 56d44062ea37b36e902fd89e91b09a897876d806 Mon Sep 17 00:00:00 2001
+From: stevenhorsman
+Date: Fri, 17 Apr 2026 14:42:50 +0100
+Subject: [PATCH] libs: Fix unstable_name_collisions warnings
+
+Remove NixPath's is_empty() to avoid ambiguity with the future
+std::path::Path::is_empty() method and switch to
+path.as_os_str().is_empty as recommended by @burgerdev.
+
+This addresses unstable_name_collisions warnings in Rust 1.93.
+
+Fixes: #12835
+
+Upstream-Reference: https://github.com/kata-containers/kata-containers/commit/56d44062ea37b36e902fd89e91b09a897876d806
+
+Co-authored-by: Markus Rudy
+Signed-off-by: stevenhorsman
+---
+ src/libs/kata-sys-util/src/mount.rs | 10 +++++-----
+ 1 file changed, 5 insertions(+), 5 deletions(-)
+
+diff --git a/src/libs/kata-sys-util/src/mount.rs b/src/libs/kata-sys-util/src/mount.rs
+index 892e95639b93..ce9f807fcecb 100644
+--- a/src/libs/kata-sys-util/src/mount.rs
++++ b/src/libs/kata-sys-util/src/mount.rs
+@@ -52,7 +52,7 @@ use std::time::Instant;
+
+ use lazy_static::lazy_static;
+ use nix::mount::{mount, MntFlags, MsFlags};
+-use nix::{unistd, NixPath};
++use nix::unistd;
+ use oci_spec::runtime as oci;
+
+ use crate::fs::is_symlink;
+@@ -225,7 +225,7 @@ pub fn create_mount_destination, D: AsRef, R: AsRef>(
+ /// Caller needs to ensure safety of the `dst` to avoid possible file path based attacks.
+ pub fn bind_remount>(dst: P, readonly: bool) -> Result<()> {
+ let dst = dst.as_ref();
+- if dst.is_empty() {
++ if dst.as_os_str().is_empty() {
+ return Err(Error::NullMountPointPath);
+ }
+ let dst = dst
+@@ -262,10 +262,10 @@ pub fn bind_mount_unchecked, D: AsRef>(
+
+ let src = src.as_ref();
+ let dst = dst.as_ref();
+- if src.is_empty() {
++ if src.as_os_str().is_empty() {
+ return Err(Error::NullMountPointPath);
+ }
+- if dst.is_empty() {
++ if dst.as_os_str().is_empty() {
+ return Err(Error::NullMountPointPath);
+ }
+ let abs_src = src
+@@ -760,7 +760,7 @@ pub fn umount_timeout>(path: P, timeout: u64) -> Result<()> {
+ /// # Safety
+ /// Caller needs to ensure safety of the `path` to avoid possible file path based attacks.
+ pub fn umount_all>(mountpoint: P, lazy_umount: bool) -> Result<()> {
+- if mountpoint.as_ref().is_empty() || !mountpoint.as_ref().exists() {
++ if mountpoint.as_ref().as_os_str().is_empty() || !mountpoint.as_ref().exists() {
+ return Ok(());
+ }
+
diff --git a/SPECS/kata-containers/kata-containers.spec b/SPECS/kata-containers/kata-containers.spec
index 86135d6475a..e5d152970fa 100644
--- a/SPECS/kata-containers/kata-containers.spec
+++ b/SPECS/kata-containers/kata-containers.spec
@@ -2,7 +2,7 @@
Name: kata-containers
Version: 3.32.0.kata0
-Release: 3%{?dist}
+Release: 4%{?dist}
Summary: Kata Containers package developed for Pod Sandboxing on AKS
License: ASL 2.0
URL: https://github.com/microsoft/kata-containers
@@ -143,6 +143,9 @@ install -m 0644 \
%{tools_pkg}/tools/osbuilder/node-builder/azure-linux/agent-install/usr/lib/systemd/system/kata-agent.service
%changelog
+* Wed Aug 19 2026 Kavya Sree Kaitepalli - 3.32.0.kata0-4
+- Bump release to rebuild with rust
+
* Fri Aug 14 2026 Azure Linux Security Servicing Account - 3.32.0.kata0-3
- Patch for CVE-2026-50540
diff --git a/SPECS/rust-bootstrap/rust-bootstrap.signatures.json b/SPECS/rust-bootstrap/rust-bootstrap.signatures.json
new file mode 100644
index 00000000000..5af1a812dc1
--- /dev/null
+++ b/SPECS/rust-bootstrap/rust-bootstrap.signatures.json
@@ -0,0 +1,10 @@
+{
+ "Signatures": {
+ "cargo-1.95.0-x86_64-unknown-linux-gnu.tar.xz": "e74edd2cf7d0f1f1383b4f00eb90c843750bc489e2ccf7214e6476678a907425",
+ "rustc-1.95.0-x86_64-unknown-linux-gnu.tar.xz": "8426a3d170a5879f5682f5fbdd024a1779b3951e7baba685af2d6dc32a6dfc15",
+ "rust-std-1.95.0-x86_64-unknown-linux-gnu.tar.xz": "047ea7098803d3500fa1072e9cee5392697e21525559e4458128a2bf874aa382",
+ "cargo-1.95.0-aarch64-unknown-linux-gnu.tar.xz": "7c070aeba9bbf12073646995a03f36c346bb5f541d0078ba6d9dc2a7adaaf6af",
+ "rustc-1.95.0-aarch64-unknown-linux-gnu.tar.xz": "0fe3689eeaed603e5ef24572d11597d3edadaefd2cb181674ad621260f2501d2",
+ "rust-std-1.95.0-aarch64-unknown-linux-gnu.tar.xz": "3a21b271b1ff973b94d69b25e7a39992f9fbcae1ab6d9475844a23e6ad3908ac"
+ }
+}
diff --git a/SPECS/rust-bootstrap/rust-bootstrap.spec b/SPECS/rust-bootstrap/rust-bootstrap.spec
new file mode 100644
index 00000000000..add368127e1
--- /dev/null
+++ b/SPECS/rust-bootstrap/rust-bootstrap.spec
@@ -0,0 +1,48 @@
+Summary: Prebuilt stage0 bootstrap toolchain used to build rust
+Name: rust-bootstrap
+Version: 1.95.0
+Release: 1%{?dist}
+License: (ASL 2.0 OR MIT) AND BSD AND CC-BY-3.0
+Vendor: Microsoft Corporation
+Distribution: Azure Linux
+Group: Development/Languages
+URL: https://www.rust-lang.org/
+BuildArch: noarch
+
+# Notes:
+# - These are the official upstream prebuilt cargo/rustc/rust-std tarballs
+# consumed by rust.spec to bootstrap-compile a new toolchain from source.
+# - When bumping "stage0_version"/"release_date" in rust.spec, bump the same
+# values here (Version and %{release_date}) and rebuild this package first.
+%define release_date 2026-04-16
+
+Source0: https://static.rust-lang.org/dist/%{release_date}/cargo-%{version}-x86_64-unknown-linux-gnu.tar.xz
+Source1: https://static.rust-lang.org/dist/%{release_date}/rustc-%{version}-x86_64-unknown-linux-gnu.tar.xz
+Source2: https://static.rust-lang.org/dist/%{release_date}/rust-std-%{version}-x86_64-unknown-linux-gnu.tar.xz
+Source3: https://static.rust-lang.org/dist/%{release_date}/cargo-%{version}-aarch64-unknown-linux-gnu.tar.xz
+Source4: https://static.rust-lang.org/dist/%{release_date}/rustc-%{version}-aarch64-unknown-linux-gnu.tar.xz
+Source5: https://static.rust-lang.org/dist/%{release_date}/rust-std-%{version}-aarch64-unknown-linux-gnu.tar.xz
+
+%description
+Prebuilt cargo/rustc/rust-std stage0 tarballs (x86_64 and aarch64) consumed
+by the rust package to bootstrap-compile a new toolchain. Not intended for
+direct/standalone use.
+
+%prep
+# Nothing to unpack, sources are installed as-is.
+
+%build
+# Nothing to build, sources are installed as-is.
+
+%install
+mkdir -p %{buildroot}%{_datadir}/rust-bootstrap/%{version}
+cp %{SOURCE0} %{SOURCE1} %{SOURCE2} %{SOURCE3} %{SOURCE4} %{SOURCE5} \
+ %{buildroot}%{_datadir}/rust-bootstrap/%{version}/
+
+%files
+%{_datadir}/rust-bootstrap/%{version}/
+
+%changelog
+* Wed Aug 19 2026 Kavya Sree Kaitepalli - 1.95.0-1
+- Original version for Azure Linux. Split out of rust.spec to keep its SRPM small.
+- License verified.
diff --git a/SPECS/rust/CVE-2024-11738.patch b/SPECS/rust/CVE-2024-11738.patch
deleted file mode 100644
index 22836637803..00000000000
--- a/SPECS/rust/CVE-2024-11738.patch
+++ /dev/null
@@ -1,35 +0,0 @@
-From 874dd834f5444394deda1f7fcc19cc09afebf6bd Mon Sep 17 00:00:00 2001
-From: Kevin Wang
-Date: Fri, 22 Nov 2024 20:48:01 +0800
-Subject: [PATCH] Record and restore the processed cursor in
- first_handshake_message
-
-Signed-off-by: Azure Linux Security Servicing Account
-Upstream-reference: https://github.com/rustls/rustls/pull/2231.patch
----
- vendor/rustls-0.23.13/src/conn.rs | 2 ++
- 1 file changed, 2 insertions(+)
-
-diff --git a/vendor/rustls-0.23.13/src/conn.rs b/vendor/rustls-0.23.13/src/conn.rs
-index 60b597ba5..d45d71fd0 100644
---- a/vendor/rustls-0.23.13/src/conn.rs
-+++ b/vendor/rustls-0.23.13/src/conn.rs
-@@ -655,6 +655,7 @@ impl ConnectionCommon {
- /// `process_handshake_messages()` path, specialized for the first handshake message.
- pub(crate) fn first_handshake_message(&mut self) -> Result