patch 9.2.0843: [security]: popup: opacity mask indexed out of bounds
Problem: [security]: A "clipwindow" popup with "opacity" anchored to a
text property can keep a negative window row when the anchor
scrolls above the top of the host window. The opacity mask
loop then indexes the screen array before its start, causing
an out-of-bounds read and a conditional out-of-bounds write
(tdjackey).
Solution: Keep the popup window row at the first visible row and record
the clipped-off top rows only in the top offset, so no
consumer has to clamp the row and the opacity mask loop stays
in bounds (Hirohito Higashi).
patch 9.2.0841: [security]: heap overflow when adding > 65535 text properties
Problem: [security]: heap overflow when adding > 65535 text properties
(Wang1rrr).
Solution: Verify that the number of text properties falls within the
limit (Yasuhiro Matsumoto).
patch 9.2.0840: [security]: code injection in netrw via bookmarks
Problem: [security]: code injection in netrw via bookmarks and history
(David Carliez)
Solution: Escape the '|' explicitly (Yasuhiro Matsumoto)
The bookmark and history menu builders interpolate paths into :execute'd
:menu commands using g:netrw_menu_escape, which did not escape the Ex
command separator '|'. A crafted path could break out of the :menu command
and run arbitrary Ex/shell commands when the menu was built or triggered.
Add '|' to g:netrw_menu_escape for the menu names, escape the :e right-hand
side with fnameescape(), and quote the netrw#MakeTgt() argument with
string() instead of raw single-quote interpolation.
patch 9.2.0839: [security]: arbitrary code execution via keyword lookup
Problem: [security]: arbitrary code execution via keyword lookup in
sh.vim, zsh.vim and ps1.vim filetype plugin
(manus-use)
Solution: For powershell, quote the commands using single quotes, for
sh/zsh pass the argument as a separate list item to term_start()/system()
(Yasuhiro Matsumoto).
patch 9.2.0836: filetype: .git-blame-ignore-revs file is not recognized
Problem: filetype: .git-blame-ignore-revs file is not recognized
Solution: Detect .git-blame-ignore-revs file as gitrevlist filetype,
include syntax and filetype plugins (Fionn Fitzmaurice)
A Git revision list is
> a list of object names (i.e. one unabbreviated SHA-1 per line)...,
> comments (#), empty lines, and any leading and trailing whitespace are
> ignored.
(from Git's fsck.skipList documentation).
The default output of git rev-list will match this. It is also suitable
as input to git blame --ignore-revs-file.
This adds filetype detection matching .git-blame-ignore-revs files,
syntax highlighting and basic filetype settings.
closes: #20702
Signed-off-by: Fionn Fitzmaurice <fionn@github.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0834: cleared last search pattern is restored from viminfo
Problem: cleared last search pattern is restored from viminfo
Solution: Do not apply the search pattern and 'hlsearch' state read
from viminfo while writing (Barrett Ruth).
fixes: #20718
closes: #20720
Signed-off-by: Barrett Ruth <br@barrettruth.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0833: GTK4: menu mnemonics do not work properly
Problem: GTK4: menu mnemonics do not work properly
Solution: Force "mnemonics-visible" back on via a notify handler and
set the active item on "mnemonic-activate" (Foxe Chen).
closes: #20722
Signed-off-by: Foxe Chen <chen.foxe@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
runtime(netrw): fix E471 in Neovim when g:netrw_chgwin is one past the last window
Problem: Opening a file from a netrw listing throws
"E471: Argument required: keepj keepalt 2wincmd 1" when
g:netrw_chgwin equals winnr('$')+1, e.g. after opening
:Lexplore (which sets g:netrw_chgwin=2) and closing the
sidebar, then browsing with :Explore in the remaining window.
s:NetrwBrowseChgDir builds the window jump as
"g:netrw_chgwin wincmd curwin", passing the saved window
NUMBER where wincmd expects its single-letter argument.
Solution: Jump back to the saved window with "curwin wincmd w", as the
surrounding comment intends; the following statement then
performs the actual jump to g:netrw_chgwin.
The faulty line dates back to at least Vim 9.0
(runtime/autoload/netrw.vim:4976 at v9.0.0000).
Reported (against the since-archived netrw repo) in
saccarosium/netrw.vim#98 and neovim/neovim#34169.
Note: no test, because the error reproduces only in Neovim.
closes: #20741
Signed-off-by: erdivartanovich <erdivartanovich@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0832: socketserver: remote commands can be processed in reverse order
Problem: When several clients send a command in quick succession, e.g.
":drop" from repeated "--remote-tab", the commands can be
processed in reverse order, so the files open in the wrong
order.
Solution: The server inserts a newly accepted client at the head of the
client list, so pending clients are handled newest-first.
Append the client to the end of the list instead, so they are
handled in the order they were accepted (Hirohito Higashi).
closes: #20813
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Hirohito Higashi <h.east.727@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
Maxim Kim [Wed, 22 Jul 2026 17:22:44 +0000 (17:22 +0000)]
patch 9.2.0831: diff highlighting hard to read with syntax enabled
Problem: diff highlighting hard to read with syntax enabled and
terminals having 256 or less colors (Andrey Butirsky)
Solution: Set a cterm foreground color (Maxim Kim)
fixes: #4071
closes: #20711
Signed-off-by: Maxim Kim <habamax@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0830: the completion menu is not used on terminals without colors
Problem: When the terminal reports no colors ("t_Co" is 0 or 1) the
insert mode completion popup menu is not shown at all, while
the command line completion popup menu ('wildoptions' contains
"pum") is shown. In 'wildmenu' completion the current match
cannot be told apart from the other matches (Maxim Kim)
Solution: Show the insert mode completion popup menu regardless of the
number of colors and add "term" attributes to the default
highlighting of Pmenu, PmenuSel and PmenuThumb. The wildmenu
is drawn with the attributes of the status line, which is
reversed, and on most terminals the standout mode is the same
as the reverse mode, thus use the underline mode for the
default highlighting of WildMenu (Hirohito Higashi).
fixes: #20800
closes: #20803
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Hirohito Higashi <h.east.727@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0829: Sessions do not preserve script version for expression options
Problem: Sessions do not preserve script version for option holding
expressions
Solution: Remember script version for string options, and add a
":legacy" prefix for ":set"/":setlocal" calls when necessary
Since patch v9.2.0579 (":mksession, :mkview and :mkvimrc emit legacy Vim
script") session files are marked as Vim9 script. A few options have
Vim expressions as their values. When inserted their values literally
into a Vim9 script, these expressions are now evaluated as Vim9
expressions. But the original value might have been set by a legacy
script.
In order to be backward compatible and not break most of the existing
file type plugin scripts, we need to consider the script version of the
option value. If an option was set in a legacy script, or via "legacy
set"/"legacy setlocal", we need to restore it using the "legacy" prefix
as well.
Options are not marked as expression options, vs string options, vs bool
options. We only know if an option is a bool, number or a string
option. It seems safe to set bool and number options using Vim9
semantics. But for string options we do not know if an option value is
a Vim expression. And so, if it was set by a legacy script we just
use a conservative approach and prefix the "set" or "setlocal" command
with "legacy" for all string options set in a legacy context.
related: #20152
closes: #20696
Signed-off-by: Illia Bobyr <illia.bobyr@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0828: GTK4: hardware rendering can be improved
Problem: GTK4: hardware rendering can be improved
Solution: Refactor code (Foxe Chen)
This change does the following:
- Make each cell have its own array of glyphs, that represent it. Before
glyphs were stored per span of drawn text.
- Background color, invert blend is now stored as a single row pixel
buffer, that is scaled up to size when rendering. No need to have logic
for merging visual attributes together.
- Underlines, undercurls, and strikethroughs use a mask outline, and a
pixel buffer (similar to the above) that is opaque at parts where there
are under decorations. This means having 100 individual undercurls that
are all separated by spaces in a row will only result in a single mask
node.
- Render nodes are cached per row, because creating render nodes are
cheap. The actual heavy stuff would be shaping text into glyphs, which
are cached per cell.
- Use PangoAttrFontFeatures to handle guiligatures option, instead of
manually splitting draw calls, which is buggy and complex (some complex
unicode characters are not rendered correctly).
- Render block cursor separately, this prevents a full redraw of the text
for the row the cursor is on (only if glyphs in cell underneath cursor
did not change).
Complex unicode characters that bleed outside of the cell should look
better, since the background is always rendered before all glyphs,
meaning they are not clipped off.
fixes: #13435
closes: #20674
Signed-off-by: Foxe Chen <chen.foxe@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0827: :startinsert enters Insert mode in a non-modifiable buffer
Problem: ":startinsert" enters Insert mode in a buffer where
'modifiable' is off, the error only appears when a character
is typed. Typing "i" gives the error right away (Barrett Ruth)
Solution: Give the error when the buffer is not modifiable, like "i"
does. Keep ignoring the command in a terminal window, where
":startinsert" is documented to be ineffective, and keep
accepting it when 'insertmode' is set, like "i" does
(Hirohito Higashi).
fixes: #20804
closes: #20806
Signed-off-by: Hirohito Higashi <h.east.727@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
Maxim Kim [Wed, 22 Jul 2026 09:16:53 +0000 (09:16 +0000)]
patch 9.2.0826: highlighting for broken terminals can be improved
Problem: highlighting for broken terminals can be improved
(Maxim Kim)
Solution: Make the highlighting work better when the terminal does not
support colors (Maxim Kim)
In a colorless or broken terminal emulator current syntax highlighting
is too intense with using bold and underline for various syntax
elements.
In this scenario, when the colors are not available at all, the most
important part of the syntax is the comments, something that is not
executed or compiled.
- Comments are highlighted as bold
- All other syntax elements are set to NONE
- LineNr is not highlighted (was underline)
- SpecialKey is not highlighted (was bold)
fixes: #20712
closes: #20799
Signed-off-by: Maxim Kim <habamax@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0825: regexp: submatch in a look-behind is empty with the NFA engine
Problem: With the NFA engine a sub-expression inside a variable width
look-behind, e.g. "\v(.)@<=", is empty for the first match on
every line except the first one. The old engine is correct
(Mukundan)
Solution: The look-behind is retried from the previous line, because the
width of "." is over-estimated. While scanning that line the
start state is added at the end of the line, where it gets the
position of the line break as its start position, even though
the match actually starts on the next line. Use the position
of the start of the next line in that case (Hirohito Higashi).
fixes: #20802
closes: #20805
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Hirohito Higashi <h.east.727@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
James McCoy [Tue, 21 Jul 2026 16:28:59 +0000 (16:28 +0000)]
patch 9.2.0823: tests: Test_clientserver_servlist_list may fail
Problem: tests: Test_clientserver_servlist_list may fail
Solution: Skip Test_clientserver_serverlist_list for non-gvim GUI builds
(James McCoy)
Running a GUI build that cannot access the GUI clientserver will fail
like below
command line..script /build/package/src/testdir/runtest.vim[636]..function RunTheTest[63]..Test_clientserver_serverlist_list[16]..WaitForAssert[2]..<SNR>4_WaitForCommon[11]..<lambda>23 line 1: Pattern 'XVIMTEST' does not match ''
command line..script /build/package/src/testdir/runtest.vim[636]..function RunTheTest[63]..Test_clientserver_serverlist_list line 18: Expected 'list<string>' but got 'string'
Caught exception in Test_clientserver_serverlist_list(): Vim(call):E897: List or Blob required @ command line..script /build/package/src/testdir/runtest.vim[636]..function RunTheTest[63]..Test_clientserver_serverlist_list, line 19
closes: #20719
Signed-off-by: James McCoy <jamessan@debian.org> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0820: GUI: hidden popup image is displayed and not erased
Problem: In the GUI a popup image is drawn even when the popup is
hidden, and hiding a popup leaves part of the image on the
screen (Bakudankun).
Solution: Skip hidden popups when repainting images after the cursor is
undrawn or the window is exposed. Redraw the area the image
covered when the popup is hidden or closed, also for the GDI
backend (Hirohito Higashi).
fixes: #20796
closes: #20798
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Hirohito Higashi <h.east.727@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0819: MS-Windows: sixel image shown as raw text in the console
Problem: On the MS-Windows console a popup image is displayed as the raw
sixel escape sequence instead of the image, unless
'termguicolors' is set (Bakudankun).
Solution: Write a DCS sequence with the console API that lets the console
parse it, no matter which write path the current colors select.
Keep track of the terminator across writes, since a long
sequence is split up (Hirohito Higashi).
fixes: #20795
closes: #20797
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Hirohito Higashi <h.east.727@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0818: tests: client-server test fails without X11 server
Problem: When unable to connect to X11, serverlist({'list':1}) returns
a string instead of a list. This causes Test_remote_serverlist() in
test_vim9_builtin.vim to fail.
Solution: Raise E240 (No connection to the X server)
Additionally, This fix `Test_clientserver_env_method()` keeping
`VIM_CLIENTSERVER` environment variable instead of deleting it. This
allows certain `+clientserver` tests to pass, even in environments where
the X11 server is unavailable, provided that `VIM_CLIENTSERVER=socket`
is set.
closes: #20716
Co-Authored-By: James McCoy <jamessan@jamessan.com> Signed-off-by: Muraoka Taro <koron.kaoriya@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0817: crash when building a stacktrace during an autocommand
Problem: Vim can crash while building a stack trace when an autocommand
is being triggered but has not matched a pattern yet, for
example at the more prompt with 'verbose' set (stefanos82).
Solution: Handle the autocommand entry on the execution stack that does
not have a script context yet (Hirohito Higashi).
fixes: #20730
closes: #20732
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Hirohito Higashi <h.east.727@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0815: deeply nested regexp patterns may cause stack overflow
Problem: Deeply nested regexp groups can cause uncontrolled recursion
in the regexp compiler and exhaust the C stack.
Solution: Limit recursive regexp parsing depth in both the backtracking
and NFA compilers (lipengyu)
closes: #20731
Signed-off-by: lipengyu <lipengyu@kylinos.cn> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0814: Vim9: E1041 when reloading an autoload script with exported variables
Problem: Sourcing a Vim9 autoload script more than once fails with E1041
for its exported variables and constants, while exported functions
reload without error (ubaldot)
Solution: Give exported variables and constants the same clean slate as
functions on reload by removing them from the global namespace, so
the script body can define them again. Keep classes and enums:
objects created from the previous definition still refer to it, so
they are not redefined this way (Hirohito Higashi)
fixes: #19205
closes: #20726
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Hirohito Higashi <h.east.727@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0813: dict_add_func() may corrupt funcref count on failure
Problem: dict_add_func() references the function only after a
successful dict_add(), on failure dictitem_free()
calls func_unref() without a matching func_ref(), corrupting
the reference count of a lambda or numbered function.
Solution: Take the reference before dict_add() so the unref on the
failure path is balanced (Yasuhiro Matsumoto).
related: #20668
closes: #20742
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0812: :argdelete with pattern leads to wrong argidx()
Problem: :argdelete with pattern leads to wrong argidx().
Solution: Correct argidx() in both branches of ex_argdelete(). Also use
ARGCOUNT macro in two more places (zeertzjq).
patch 9.2.0810: add_llist_tags() uses wrong function to free dict
Problem: add_llist_tags() uses wrong function to free dict on alloc
failure
Solution: Use dict_unref() (Yasuhiro Matsumoto).
add_llist_tags() released a dict_alloc()'d dict with vim_free() when
list_append_dict() failed, leaving a dangling pointer in the dict
garbage-collection chain. Use dict_unref().
related: #20668
closes: #20743
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0809: getframelayout() uses wrong function to free lists
Problem: getframelayout() uses wrong function to free lists on alloc
failure.
Solution: Use list_free() on alloc failure (Yasuhiro Matsumoto).
get_framelayout() released a list_alloc()'d list with vim_free() when
list_append_list() failed, leaving a dangling pointer in the list
garbage-collection chain. Use list_free() so it is unlinked.
related: #20668
related: #20743
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0808: getregionpos: double-free on alloc failure
Problem: getregionpos: double-free on alloc failure
Solution: Only free lists that were not appended (Yasuhiro Matsumoto).
add_regionpos_range() freed lists already linked into the result tree when
a later list_alloc()/list_append_list() failed, causing a double-free and
use-after-free. Only free lists that were not appended, and free them with
list_free() so they are unlinked from the garbage-collection chain.
related: #20668
closes: #20744
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0807: MS-Windows: ellipsis character is garbled
Problem: Source code is not treated as utf-8 by MSVC, so '…'
character in string literal is interpreted wrong.
Solution: Set utf-8 for both source and execution charsets.
patch 9.2.0806: 'showcmd' may show internal command keys
Problem: The `showcmd` statusline item may show internal command keys when a
`<Cmd>` or `<ScriptCmd>` mapping redraws the statusline, and may
leave stale text behind when `%S` is rendered directly.
Solution: Do not add these internal mapping dispatch keys to the `showcmd`
buffer, and keep the clear state in sync when `%S` renders it
(Barrett Ruth)
patch 9.2.0805: screenpos() "curscol" is wrong with 'rightleft'
Problem: With 'rightleft' set, the "curscol" value of screenpos() does not
point to the screen column where the cursor is placed.
Solution: Count "curscol" from the left side of the window, leaving "col"
and "endcol" as reading-order columns (Hirohito Higashi)
related: #20763
closes: #20786
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Hirohito Higashi <h.east.727@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0804: wincol() is wrong for a double-wide character with 'rightleft'
Problem: With 'rightleft' set and the cursor on a double-wide character,
wincol() returns the column one to the right of where the cursor
actually is (after v9.2.0791)
Solution: Take the width of the character under the cursor into account,
like the cursor positioning already does.
related: #20763
closes: #20785
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Hirohito Higashi <h.east.727@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0802: Memory leak with list_append_dict/dict_add_list on alloc failure
Problem: Memory leak with list_append_dict()/dict_add_list() on alloc
failure
Solution: Free the list/dict when dict_add_list()/list_append_dict()
failed (Yasuhiro Matsumoto)
Various getinfo-style builtins ignored the return of list_append_dict()/
dict_add_list() and leaked the freshly allocated, GC-linked dict or list on
allocation failure. Check the return and unref on failure. Affects
getreginfo/setreg event (register.c), hlget (highlight.c), prop_list
(textprop.c), getmatches (match.c), menu_getinfo (menu.c),
popup_getoptions (popupwin.c), sign_getplaced (sign.c), job_info (job.c),
term_getcursor/term_scrape (terminal.c), diff() (diff.c), complete_info
(insexpand.c), cmdcomplete_info (cmdexpand.c).
related: #20668
related: #20745
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0796: Visual block reselection wrong with 'virtualedit'
Problem: Visual block reselection wrong with 'virtualedit' when line
lengths are different (Alex Yang, after 8.2.3494).
Solution: Set the entire cursor position to old position when computing
target curswant, since the check_cursor() added in 8.2.3494
may change cursor column as well (zeertzjq).
fixes: #20746
closes: #20748
Signed-off-by: zeertzjq <zeertzjq@outlook.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0795: popup menu shadow is not cleared when the menu shrinks
Problem: When the popup menu shrinks its shadow is not cleared: a stale
shadow cell is left on the empty (~) lines near the menu, and when
the menu also gets narrower the border and text of the larger menu
show through the shadow (Maxim Kim)
Solution: Exclude the shadow corner cells that are never drawn, and when the
menu is redrawn redraw the background under the shadow first, so
content left by a larger menu is cleared instead of showing through
(Hirohito Higashi).
fixes: #20740
closes: #20750
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Hirohito Higashi <h.east.727@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0793: If session restored a tiny window, restore fails
Problem: If session restored a tiny window, restore fails
Solution: Extend window sizes to be at least the minimum size during
session restore (Illia Bobyr)
If session contains a window that is shorter/narrower than the current
`&winminheight` and `&winminwidth`, respectively, Vim will fail when
assigning original values to the `&winminheight`/`&winminwidth` and the
session restore will be slightly incomplete.
It seems reasonable to assume that if the user have selected certain
values for these minimum size settings, it is safe to just make the
restored windows big enough to match the minimums and continue without
producing an error.
This fix allows `Test_mksession_winminheight()` to start with the
default values of `&winheight`/`&winwidth` and only change them after
the session restore.
closes: #20692
Supported by AI.
Signed-off-by: Illia Bobyr <illia.bobyr@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
Mark Woods [Sat, 18 Jul 2026 13:25:17 +0000 (13:25 +0000)]
patch 9.2.0792: runtime(netrw): Explore without optional dir broken
Problem: runtime(netrw): Explore without optional [dir] argument should
open directory of the current file
Solution: Make it work as documented (Mark Woods)
Broken by fix for #20636 in PR #20663
related: #20663
closes: #20761
Signed-off-by: Mark Woods <mwoods.online.ie@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0791: wincol() counts from right side for 'rightleft'
Problem: wincol() counts cells from right side of the window if
'rightleft' is enabled.
Solution: Fix wincol() to count from left side of the window
as documented (Sergey Vlasov).
closes: #20763
Signed-off-by: Sergey Vlasov <sergey@vlasov.me> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0790: 'completeslash' breaks :find completion with 'findfunc'
Problem: On MS-Windows with 'completeslash' set, an item completed by
'findfunc' cannot be opened with :find, E345 is given (Mao-Yining)
Solution: Do not apply 'completeslash' to matches returned by 'findfunc',
they are opaque strings that are passed back to the function
unchanged (glepnir)
fixes: #20770
closes: #20771
Signed-off-by: glepnir <glephunter@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0789: 'statuslineopt' status line too high after a window is minimized
Problem: With a global 'statuslineopt' maxheight, the status line height is
not reduced to what every window can afford. After a window is put
at its minimum height (e.g. CTRL-W_), setting 'statuslineopt' still
gives a status line taller than the small window can display,
instead of the best-effort height that fits all windows.
Solution: Let every window using the global 'statuslineopt' constrain the
best-effort height, including windows at their minimum height.
Correct a misleading test comment and add a test (Hirohito Higashi).
closes: #20772
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Hirohito Higashi <h.east.727@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
Young [Sat, 18 Jul 2026 09:39:58 +0000 (09:39 +0000)]
patch 9.2.0788: filetype: hip files are not recognized
Problem: filetype: hip files are not recognized
Solution: Detect *.hip files as hip filetype, include filetype, syntax
and indent plugins, update makemenu.vim and synmenu.vim (Young)
Round out HIP (Heterogeneous-compute Interface for Portability) support
to mirror the existing CUDA files:
- autoload/dist/ft.vim: detect the ".hip" extension as filetype "hip"
- ftplugin/hip.vim: behave like C++ by sourcing ftplugin/cpp.vim
- indent/hip.vim: use cindent, like indent/cuda.vim
- makemenu.vim / synmenu.vim: add a Syntax menu entry
The syntax/hip.vim file already sources syntax/cpp.vim and adds the
HIP-specific keywords, matching syntax/cuda.vim.
closes: #20773
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Signed-off-by: Young <young20050727@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
CI: Bump the github-actions group across 1 directory with 2 updates
Bumps the github-actions group with 2 updates in the / directory: [github/codeql-action](https://github.com/github/codeql-action) and [actions/labeler](https://github.com/actions/labeler).
Updates `github/codeql-action` from 4.36.3 to 4.37.0
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/v4.36.3...v4.37.0)
Updates `actions/labeler` from 6.1.0 to 6.2.0
- [Release notes](https://github.com/actions/labeler/releases)
- [Commits](https://github.com/actions/labeler/compare/v6.1.0...v6.2.0)
patch 9.2.0785: WinResized not triggered when the whole Vim is resized
Problem: When the whole Vim (terminal or GUI) is resized, VimResized fires
right away but WinResized does not: it only triggers on the next
typed command, even though the windows already changed size
(Mao-Yining).
Solution: Trigger the WinResized (and WinScrolled) check right after firing
VimResized on a shell resize, so window size changes are reported
immediately instead of waiting for the next command
(Hirohito Higashi).
fixes: #20774
closes: #20775
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Hirohito Higashi <h.east.727@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0784: crash when borrowing statusline highlight in silent Ex mode
Problem: Vim crashes with a NULL pointer dereference when a status line is
redrawn next to a vertical separator in silent Ex mode, where the
screen cell arrays are not allocated (tdjackey).
Solution: Skip borrowing the vertical separator highlight when the screen is
not allocated (Hirohito Higashi).
closes: #20776
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Hirohito Higashi <h.east.727@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
CI: Bump the github-actions group across 1 directory with 2 updates
Bumps the github-actions group with 2 updates in the / directory: [actions/cache](https://github.com/actions/cache) and [github/codeql-action](https://github.com/github/codeql-action).
Updates `actions/cache` from 5.0.5 to 6.1.0
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](https://github.com/actions/cache/compare/v5.0.5...v6.1.0)
Updates `github/codeql-action` from 4.36.2 to 4.36.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/v4.36.2...v4.36.3)
patch 9.2.0783: tests: personal spell files leak into later tests
Problem: Test_spelldump_prefixtree_overflow() resets 'runtimepath' to
defaults, which can expose personal spell files to later tests
(Jun-ichi Takimoto, after v9.2.0662)
Solution: Save and restore the test runner's 'runtimepath' value (coyaSONG).
As in
```
TEST_FILTER=winminheight make test_mksession
```
Yet, when ran as part of the whole test suite they succeeded.
This was due to some state leaking from one test into another.
I think this is bad, as it can confuse someone making changes in the
relevant area.
`Test_mksession_winminheight` is actually still broken a bit, and
requires `winheight` and `winwidth` set at the beginning of the test,
rather than later, when it actually matters. This exposes a subtle bug
in the session restore script. I have a patch in a separate commit.
closes: #20691
Signed-off-by: Illia Bobyr <illia.bobyr@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
runtime(doc): clarify behaviour of 'title' and 'iconstring'
Document that some terminals sets the 'icon' as window title. Just like
'title' would. Which can be confusing and need to be documented for
both options.
closes: #20553
Signed-off-by: Celelibi <celelibi@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0781: tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir
Problem: tests: Test_fuzzy_completion_bufname_fullpath() creates an
unnecessary directory with the name of a file.
Solution: Only create the parent directory of the file (zeertzjq).
closes: #20695
Signed-off-by: zeertzjq <zeertzjq@outlook.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0777: Memory leak in add_defer() on alloc failure
Problem: Memory leak in add_defer() on allocation failure (Ao Xijie)
Solution: Free saved_name when ga_grow() fails, propagate failure from
add_defer_function() to the caller, add a test for alloc
failure
patch 9.2.0774: Memory leak in f_getscriptinfo() on alloc failure
Problem: Memory leak in the script info code on allocation failure
Solution: Route the failures through the existing cleanup with "goto
theend", and unref var_dict and the functions list when
dict_add_dict()/dict_add_list() fail.
Problem: Vim9: Null dereference inside alloc_type(),
Missing NULL check after ALLOC_ONE() (Ao Xijie)
Solution: Check that the returned value from ALLOC_ONE() is not NULL
patch 9.2.0771: dict_add_list() has inconsistent ownership on failure
Problem: dict_add_list() frees the passed list on failure path
(when dict_add() fails) but not on the other (when
dictitem_alloc() fails), so a caller cannot tell whether it
still owns the list after a failure.
Solution: On failure leave the passed list untouched and owned by the
caller; only take a reference on success.
patch 9.2.0770: dict_add_dict() has inconsistent ownership on failure
Problem: dict_add_dict() frees the passed dict on one failure path
(when dict_add() fails) but not on the other (when
dictitem_alloc() fails), so a caller cannot tell whether it
still owns the dict after a failure. Callers that unref the
dict on failure (e.g. in window.c) then double-free it when
dict_add() fails.
Solution: Make the failure contract consistent: on failure leave the
passed dict untouched and owned by the caller; only take a
reference on success.
Manoj Panda [Thu, 2 Jul 2026 19:10:36 +0000 (19:10 +0000)]
patch 9.2.0769: conversion to utf-16be using iconv is inconsistent
Problem: enc_canonize function changes utf-16be to utf-16 but in linux
type utf-16 defaults to utf-16le.
Solution: Creating a separate entry for utf-16be in enc_canon_table.
Note: the effect is only visible on iconv implementations that
treat "utf-16" and "utf-16be" differently, so the test does
not necessarily fail on an unpatched Vim (Manoj Panda)
closes: #20681
Signed-off-by: Manoj Panda <manojpandawork@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0768: legacy/vim9cmd modifiers are not exclusive
Problem: legacy/vim9cmd modifiers are not exclusive
Solution: when parsing command modifiers clear the other flag
(Illia Bobyr)
When one of the ":legacy" or ":vim9cmd" prefixes is used, it sets a
flag. As the rest of the code might check either of the flags, setting
both could produce confusing results. It does not make a lot of sense
to use both prefixes in the same command. But just in case it is used,
selecting the last prefix seems reasonable.
closes: #20682
Signed-off-by: Illia Bobyr <illia.bobyr@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0767: legacy/vim9cmd modifiers do not set script version for options values
Problem: legacy/vim9cmd modifiers do not set script version for options
values
Solution: Set the correct script version depending on command modifier
flags (Illia Bobyr)
When remembering script context for an option value we should consider
flags "CMOD_LEGACY" and "CMOD_VIM9CMD" set in "cmdmod.cmd_flags" by the
":legacy" and ":vim9cmd" command prefixes. Otherwise, if an option
value is an expression, it might be evaluated in an incorrect context.
closes: #20683
Signed-off-by: Illia Bobyr <illia.bobyr@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0766: quick_tab entries for empty letters point to the wrong index
Problem: Letters with no options (like "y" and "z") have their
quick_tab entry left at 0, so lookups for those letters start
scanning at options[0] instead of failing fast.
Solution: Set entries for letters with no option names to the last-option
index, so such lookups stop immediately (Illia Bobyr)
closes: #20684
Signed-off-by: Illia Bobyr <illia.bobyr@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
patch 9.2.0765: popup: opacity popup over a terminal is not cleared when moved
Problem: A semi-transparent (opacity) popup shown over a terminal window
leaves its old cells on screen when it is moved or its text
changes, and typing in the terminal makes them accumulate. Only
a full redraw (CTRL-L) clears them.
Solution: When redrawing the background under an opacity popup, force a full
repaint of an underlying terminal window so the blend uses the
terminal's true background instead of stale, already-blended
cells.
fixes: #20679
closes: #20688
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Hirohito Higashi <h.east.727@gmail.com> Signed-off-by: Christian Brabandt <cb@256bit.org>