From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Authentication-Results: plum.tunbury.org; dkim=pass (1024-bit key; unprotected) header.d=inria.fr header.i=@inria.fr header.a=rsa-sha256 header.s=dc header.b=nhlh6iIZ; dkim-atps=neutral Received-SPF: Pass (mailfrom) identity=mailfrom; client-ip=192.134.164.83; helo=mail2-relais-roc.national.inria.fr; envelope-from=caml-list-owner@inria.fr; receiver=tunbury.org Received: from mail2-relais-roc.national.inria.fr (mail2-relais-roc.national.inria.fr [192.134.164.83]) by plum.tunbury.org (Postfix) with ESMTP id 8A3F54009A for ; Tue, 21 Jul 2026 16:03:10 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=inria.fr; s=dc; h=from:to:date:message-id:mime-version:subject:reply-to: sender:list-id:list-help:list-subscribe:list-unsubscribe: list-post:list-owner:list-archive; bh=2fCL6WMp6vr7C8Uo0dWxzwCuPIvw1jAWZ5XadeV2tUg=; b=nhlh6iIZSJKBGtuiGvO1A0oZKZlpdhNOp5mgOBy8fZa5NR9JEljg6wzP dCVUAG56AqPpxtvzMfUSBrXO/W0EUu/gYP5UZZE3i6MIKH2GQNIMeynz1 SRFiQ8SwkYuiuzfkWaO6YHs2jgzyOoZ7NtZIXErPbj9ucmb+yrNOaOMpp Y=; X-CSE-ConnectionGUID: W58XDIGNRVa6GHczKiGcnw== X-CSE-MsgGUID: xCClf20WRtOOI8f5RARQHA== Authentication-Results: mail2-relais-roc.national.inria.fr; dkim=none (message not signed) header.i=none; spf=SoftFail smtp.mailfrom=caml-list-owner@inria.fr; spf=None smtp.helo=postmaster@prod-sympa-app.inria.fr Received-SPF: SoftFail (mail2-relais-roc.national.inria.fr: domain of caml-list-owner@inria.fr is inclined to not designate 128.93.162.27 as permitted sender) identity=mailfrom; client-ip=128.93.162.27; receiver=mail2-relais-roc.national.inria.fr; envelope-from="caml-list-owner@inria.fr"; x-sender="caml-list-owner@inria.fr"; x-conformance=spf_only; x-record-type="v=spf1"; x-record-text="v=spf1 ip4:128.93.142.0/24 ip4:192.134.164.0/24 ip4:128.93.162.160 ip4:128.93.162.3 ip4:128.93.162.88 ip4:89.107.174.7 mx ~all" Received-SPF: None (mail2-relais-roc.national.inria.fr: no sender authenticity information available from domain of postmaster@prod-sympa-app.inria.fr) identity=helo; client-ip=128.93.162.27; receiver=mail2-relais-roc.national.inria.fr; envelope-from="caml-list-owner@inria.fr"; x-sender="postmaster@prod-sympa-app.inria.fr"; x-conformance=spf_only X-IronPort-AV: E=Sophos;i="6.25,177,1779141600"; d="asc'?scan'208,217";a="287311859" Received: from prod-sympa-app.inria.fr ([128.93.162.27]) by mail2-relais-roc.national.inria.fr with ESMTP; 21 Jul 2026 18:03:08 +0200 Received: by prod-sympa-app.inria.fr (Postfix, from userid 990) id 54D0981EB4; Tue, 21 Jul 2026 18:03:07 +0200 (CEST) Received: from mail2-relais-roc.national.inria.fr (mail2-relais-roc.national.inria.fr [192.134.164.83]) by prod-sympa-app.inria.fr (Postfix) with ESMTP id DCC1581CFF for ; Tue, 21 Jul 2026 18:02:54 +0200 (CEST) X-CSE-ConnectionGUID: uMGA+oTeScGg42i4U2GT3A== X-CSE-MsgGUID: B9WWWEYMT6ORkTP7TW7Bhw== IronPort-SDR: 6a5f982c_6AkAUD9DUUcfVrHpInWzfVpLhxsaGxmuKpgfaVR3YqBbvJ8 RUkjdPdLxGgHzA26A0MdOfuReQbykxwurj/0XEg== X-ThreatScanner-Verdict: Negative X-IPAS-Result: =?us-ascii?q?A0EHAwC8ll9qjyIeaIFahBZbKRsBbl8zBwhJA4QZPINPh?= =?us-ascii?q?SuIeYEWkguJKIFpgUEFHAIOBwEDAQgFLgEbBAECBAEBAQIBAgGCCwqCI0YCj?= =?us-ascii?q?VgCHwYBBDQTAQIEAwIDAQEBAQEBAQEBAQELAQEBBAEBAQIBAQIEAwEBAQECE?= =?us-ascii?q?AEBAQEBATkFSYZPDYJFUVMedAEBAQEBAQEBAQEBAQEBIgEBAQEBAQEBAQEBA?= =?us-ascii?q?QEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQECBAQEATNdDgECBgQGE?= =?us-ascii?q?wEBLAYGGCMDEAQBBgMCEQE1AwETARIagmgBgiICUAMEAQwGpRKbDTd6fzOBA?= =?us-ascii?q?YIMAQEGgQg+AwIQAQ4J2j6BYAYDCYFNgViEGYJPDw0BKklqAgEChFAJhDgnD?= =?us-ascii?q?4FVRIEVgnMHb4JhAgEBGIEHAQgBARECAQgJCQ8kCYMlgmqCERWBDIF4BUtiB?= =?us-ascii?q?RkmLIE1gx4ugQqHYIFmA1ksAVUTFwsHBV6BCAMqLy1uMh2BIz4XNFgbBwWBH?= =?us-ascii?q?YEugQKEbiMfAzl/gS91SnctahIXgSaCFIE6Ak4DC209NxQZjDEQIQ2BNikgG?= =?us-ascii?q?SOBTSYOCy0FAQEBPBALCwEeAgUFAQcDCRYBAQQcAi4IDgoLCgQIBwMVBCYFC?= =?us-ascii?q?QURBwEPARYGCQIHBAIeD5JaGg4qAgGHTogNjhmTWR1tNAeEIIFgBgyJCYEmh?= =?us-ascii?q?yeOYIQEgVeLPYcDklEimGYjiV6BJgmBbx9MhxCOFDYGBASFUYF/IzwNIz8eD?= =?us-ascii?q?AczGjBDgjMBMwkWMRwPiACHVwEHgkQQMX2BJoF0O8ZuQjUCAQEKBSwHAgcBD?= =?us-ascii?q?ASFTh0BAYwIMoFMAQE?= IronPort-PHdr: A9a23:xoICbRzqy04lfsXXCzJZxVBlVkEcU1XcAAcZ59Idhq5Udez7ptK+Z xKZvawm0ASYDM2bs6sC17GK9fi4GCQp2tWojjMrSNR0TRgLiMEbzUQLIfWuLgnWCsCvRAEBW Pp4aVl+4nugOlJUEsutL3fbo3m18CJAUk6nbVk9Kev6AJPdgNqq3O6u5ZLTfx9IhD2gar9uM Rm6twrcu8cXjId4Nqo91xTFr3RGdulSwW5jOFafkwrh6suq85Nu/Stdt+g9+8JcVKnxYrg1Q 6FfADk6PG8549HmuwPeRgWV/HscVWsWkhtMAwfb6RzxQ4n8vCjnuOdjwSeWJcL4Q6g7Vji78 aplRwLmhD8IODAl/m7XjNdwjL9ArxK6uxN/2Y/Ub5qLO/d4Y6jQYMkVRWtFXsZWSixBHoaxZ JYBAuYdIepVqZT2qFwToxujHgmsHP3gxSNUhnH42q061v4uEQDA3Ac9G94Dv3DZoNDzOawPU +660bPIwC3DYf1IxDnz5ovGfR89rvyXUrJ8bdDcxFMzGw/ZjFidr5HuMTOP1uQKtmiW9/ZtV ea1hG4htgp/vySgxscpionImoIV1k3P+CJjz4YxP9K4TlR3YcW4H5tQsiGaNpd2Qt85TmFwv yY6zr0HuYKlcycWyJQnwR/fa+Wac4eW+B7jU/yRIThhiX9jZbmwiAq8/1K6xe3gSsm7zkxKr ixdn9XRq30A2Rzd58uFR/dh8Ums1yqD2gHP5+1ZI004ibbWJp4hzLM/iJcevkTNECD4lkv2g 6GbdEoq9+qo5uj5YrjroIKXOYFzigH7KKsum8q/DPwgMgcQQ2ib+Pi826P7/U3+RbVKi+M5n rPfsJ/EOcQXvqm5DBNP3YYm7xazFTCm0M4XnXUfI1JFeQ6Hj4j0O17VOvz3EfC/g1G0nDdv2 f/HMbzhApvMLnTZjLjherN951ZGxwo10dBf5o5UCrEfL/LoW0/xr8bUAQM+Mwyx2+rnB9R91 p8eWWKSGaCVKqLSsViQ6uIoOOmMepUZtyvjJPg7//LhkGU2mUMHcqWzwZQXb3e4Hux+L0WYZ 3rsmNYBHn0QsgowVuzmkEGNUTlVZ3auRaI85yo0CJ+6DYfCQICtj6aN3CKmEZFOZ2BGDEuME WvyeIWAX/cAcjmSIs95njMeVbihUZEu1R+1tAPg17VnKe/U9ysFvpzgzNh4//DfmQ82+DBuE siRz26AQ3t6k28UXTM70q9yrVR+x1ufy6R0nvNVGcZO6/5LXAo2L5zRwuN8BtvvQAzOZM2JR 0yjQti+ATE+UNYxw9gWbkZ4FNSukwrP3zKtA78Rl72LGII7/b7c33j3JsZ90mvG27c7g1khW MtPOnWqhq959wfNG47Ei1iVm7iueKgGwSLB6GiOwXCAsU1ESgJ9X6rIUWgaZkTMrNT54k3CT 6WpCbQiKgZP1NKMJLZWZtDxl1VIWffuNcnGbmyxgWm9HQ6IxrSIbIvqZ2USwjnSCEgCkwAS5 HaGKBYxCj2mo2LEAzxjDUjgY0f2/ul4sn+7VVM7zwGPb01gy7q15gUYiuebS/MO2LILpDkuq y5uEFa40N/XBMCMpw17fKVTed89+ktI1XrFtwxhOZytN7xtiUQbcwRzpk/u0xR3Cp5ckcUxt 3MrzA9yKbqC319bdjOY24rwOrzNJWXo8hCvcbba2lfF39mO4KcA9Ow4q0n/vAGuDkcu7m1r0 9ZL3Hub5ZvEFhIfX5LtXEov7Rh1ua/abCon6Y7M0H1tPrS4viXa29IuAOskygqgcMlDP6OEE g/yEtQaB9WwJ+AwnFipdB0EMPhP+643PsOmcuOL1rakMulugjyokXhK7oZl3k2R8ipzUPTI0 Iodzv+AxwWJTzjygE+6ssDvl4BJfSscE3aixyb5HIJRfbVyfYgTBmeuPcK3wtJ+iob3VXNE6 VCtGgBO5Mj8Mx6NaRa1iQlP02wTvnrhnyakmXg8mDgsqu+b3TfS6+XkbhsOfGBRF0d4ilK5C Iy9iZghV0itbhQ13E+s4U/8gbNQpKF+M3X7WUBMbjT7JGFkU7Ktu/yFecEZu8BgijleTOnpO QPScbX6uRZPj3KL9wp2wTk6c2vvoZDlh1lgj2nbKn9vrX3fcMU2xBHF5dWaS+QCliEeSnxej j/aTkO5I8Hv5c+dwp7Hu+b4TGmhU5xPbQHzyoeRqCaw5WtrGACy2feplY6vChA0hBfyzMIiT iDUtFD5a4jv2b69NLdcRHIwUUXHtuAvNLkriow0lY0d0ngch4yI8DwAi2imONFS3+TlZ3oIR CIX69TS/Q7u1VYlKy6ZgYXjWSbV2dNvMuGzeXhewSch94ZKBaOTuaRDhjdwq0GkoBj5ZOgk2 C8azeoy5XUaheAQpQdryT+SalwLNW9fOyGk1xGB7tTk6b5SeH7qa7+7kkx3gdGmCriG5ABaQ nfwPJk4T2d26Y1kPVTA3WeWiMmsccTMbd8VqhyfkgvRx+lTJpUrk/MWhC1hcWvjtHwhwuQ/g FRgx5a/9ISALmxs+uq+DHs6fnX8Y8oVvCrmjaNfgtq+x4erD4lsETUNXYL1QLSvCj1T/fXrO gCSESEt/2+BEOm6f0fX40NnonTTVpGzYijNdT9AlYkkH0HbfxAM5WJcFC83lZM4CA2wkcnoc UMjoysU+ka9sBxHjORhKxj4VG7b4gaucDY9DpaFf380pklP4VnYNcuG46d9BSZdq9ealjfVf 3agOi4dI1lcQkuAFkzuNbmo5MDd/q6fHOXrJv/HZ/OVouxbVuuU7Zioz41t8i3KM5mfeH54A LdovygLFWA8AMnflzgVHmYekyvLKdWQpBK95jFftse74ejmUwLp5JKSBv1VK9olqHXUye+Tc uWXgih+MzNR0JgBkGTJxLYo11kXkyhydjOpHNzsrAb1RbnL0u9SBh8fMWZoMddQqrg71U9LM NLajdX80vh5iOQ0AhFLTw6plsasbM0Ma2azUTGPTH2xD+zTPwaW6ZTZWfakTrlBkOhftxuxo CuWVUj5MWGKkzDvEQukMeRNkD2zNhtDvoqwaVBoVXilS8jpD3/zeNN6ljw5x7Qoi2iCbDRNd 2EkLwUW9vvLsWtRmb1nFnZE72Z5IOXMgCuf4+TCa/N0+bNqDilyi+NG8SE/wrpR4jtDQa89k y/To9hy5lC+x7DVm3w+CEYI8W4N397Y2Ccqcb/U/ZRBR3veqRcE7GHKTg8Pu8MgENrk/aZZ1 tnIkqv3bjZE6dPdu8UGVK22YIqKNmQsNR3xFXvaFgwAGHSQD1qH0lZmzdvH2EXAtp8+u4Thk 5oIS6ZGWRoyDPxPA0BsGpoZK5dyXy84ubSckcgD6GH4qUXBAsJAsdqUM5DaSeWqMzufgbReM lEz+4igeJ4oa6eu9XQ3cl5+jZjHEErWXMlQr2tmdABhqUFE9j5lRW022l75Qgmq/XkYGOXym 0ImzAxkbq5+kVWkq0dyLV3MqiwqlUA3ktiwmjGdfgn6K6KoVJ1XAS755AAhd4n2SAFvYUiuj FRpYX3aEqlJgeIqJgUJwEfM/IFCEvlGQehYbQ8MkLuJMu4w3w0U6SS/mR0ev7qDUMM+0lByN 8Xw5zFBw14xNYRkY/WIeOwSlh4L28fs9mfr1/htkl5HYR9XqSXMImhR4BNAdbg+eXjyprQ1u 1Dbl2MRcTpTXvd38KA0+hxtab/bqkCom/1CMh7jbbTHdvHF4mSYx5faEw882xFayBIb8eopj Zh7Ow+dU0RlpFeIPywALtGKaQRcbs4IsWPWYT7Lq+LGh5R8I4S6EOnsC+6IrqcdxEy+Tk4lG IEF78JJGZfJsgmQNcD8MLsM0gkg/izuNAzDFPNNaQ6GmzcBotiiwdlwx4YVKjwGAGp7ODm6/ f6O/F5s2aLfGoxuJCxGFoIfUxB+ENW3gStYo2hNAHGs3+QVxRLDpz7wqyLMDSXtOtpuYPDHL RhoCdyw5XA+6/3v0w+Rq82CYTqic48+6bqtoasAqp2KCu1ZV+x4ukbYwcxDQmCyFnTIGpizL oTxbI8laZr1DGy7WxqxkWFQLY+5MdCzI6yPmQytS5xTtdzR5woYbZqnLWw0TjlI8vkE4LNga AYDZZsifBOusB4xYqW7KQHeyd6uRmexNRNcSORZxuihIbkL32wrdODwmx5CBtkqivK690IAX sRAlhbF2fOqfJVTSwD2CiUbYwLLtDY0nGhnN/8vz6E42hyC4jx+e3ibMedubmJDpdQ1A1ifd G53BmQPTFiZlYPf4wSo0uNa725Hkt1Ty+EArGnms8qVfme3QKLy48aw0WJofZ08rqZ2K4CmP saWqMaUgGnEVJeJ+gTNFSe+E7Aycj14OCVcUeVFkmEjONUbtMxG80VjDq/WyJRFD7Qqrb2xL z84HWgV1yBLDutoPRQHkr76w7zehwude5QkMQUZvdNFmNRPCkZL IronPort-Data: A9a23:s+VlXqp8+ud3k1+9DgCScI9YEY9eBmIqbhIvgKrLsJaIsI4StFGz/ 9cnaN20SrzTNTykP5w0PZPnthk2DaWlyYVhHQI4qS03Fi1G8JqeCY6VdU2oNSjPf5CZFRM64 Z8UMYXMc55oES/XrBn9bbXo8nQt3qvTGLTwUbfPYXAhSGeIJMtZZTdLwobV1aY134jR73qxh O7PT+3j1H6NijJ5bDxLu/na9Rpmsaz44T5H7gIzP/0a41PXySlNUctDfPHgJHbRfNVoE7/hT Y4v7pnppzKDp09F5vCNy+ugLBVSGtY+GSDU1xK6joD72kAqShQai/h9bLxALx8O1V1lpvgpo P1Vr5u8VAw1CaPFneUZQnFwHjp3VUF80OavzUOX74rJkiUqT1O2m68wVB5sZNVCkgpKKTgmG cIweGhlgi+r3LreLIKTEoFEmsklJc/3C4IT0lkI5S3ZF/svXafYSKzM49JCtB9o7iyZNau2i 2IxMFKDXTyYC/F9Eg5/5KEWxY9EskLCnwhw9Dp5k4JnujmJlFQZPI/Fa7I5cvTSLSlcc93xS mjupwwVCTlDXDCTJKbsHttBSYYjkAuiML/+GoFU+dZ3pXK6hWsvBSYdelTn+/jltxSRZ4l2f hl8FioG9cDe9WSuXoC7Rxq8sWKJtR4aWsNNHqs98g7lJqj8ulzIQDFcEngaMJp96KfaRhRyv rONt+jTPmQ6qobIYyezzuKMqjejJSUeLWkDfDIJCwwf7IzqpIg1yAnETtNiDLKdhNroHzr92 HaP8Dh4gK8c5SIO///rogue2m3w9vAlSCYftzroYU+Uyz8nQ7SmW7T31WeEx/ZfedPxol6p5 yVYxZPBtIjiF6qlnyWIRKAJHaq1z+2UNSXVx19pBZgosTq3k0NPZqhV8Gg4PEBtI9oJcj/vY VbOtEVW/pA70GaWgbFffqeeIoct8aXbHvvqCqrVMucUTaQqXVrSlM1xXnJ8yVwBh2ACq8kC1 XqzdNb1S24dDbV7wTG2QeYEzLJtwToxrY8yeXwZ50r6uVZ9TCfLIVvgDLdoRrtghE9jiF6Jm +uzz+PQl31ivBTWO0E7C7L/0mzm3VBgWMyo8JMPHgJyCgdtH2UsQ+fWxaI9dodlmaVMi+qA8 2mmUVcw9WcTcUbvcF3QAlg6MeuHdc8m/RoTY3d2VX72gCdLXGpaxPtEH3fBVeV8rLQ7pRO1J tFZE/i97gNnFWuXp2tEMsKhxGGgHTzy7T+z0+OeSGBXV/Zdq8bhoLcIpyO2rHlUXBmk/9Azu aOh3Q79SJ8ODVYqRsXPZf7lixv7sXEBkaggFwHFM/tCSnXKqYJKEi3WiuNoAscuLR6Y+CCW+ TzLCjglpM7MgbQPzv/3uY6+obyELc5CD2tBPmyC7b+JJSjQpWWi5olbUde3RzPWVUKq2aD7O cBuku72au1akHl0sYNTTq5g/Zw6w96+to1L7x9FGU/TZA+BEYJQIXih3OhOuJZSx7RfhxCEZ 0KX9vReOpSLIMnAAndIACYEN8Otjeo1nBvW5tQLeHTK3jd9pue7YB8DLiuyhzx4B5orFoEcm MMKmtMcsi67gToUaue2tDherTmwHyZRQpccl88oBaHwgVAW0XBEW5vXDxH27Lypa9lhNkoLI CeetJHdhoZzl1bzTH4uKUfjheZtp4wCmBRv/m8wI16kntnkhPhu+DZz9T8xbBpezzQZ8uZVF 1VoCXZIJvS1z281vPRAYmGiIBEeJRu7/keq9UAFuleERGaVV0vMDlYHB8CzwG4j/VhhIwdrp IOj9D69UBLBXt3A4S8paEs0993hVYNQ8yPBquCGHuOEPaUHZR/6up+MWUw1ikrdBepgj2KWv uRaxuJBM63mPB4++p8AVpeR0L9BeS+UJGZDHONQpqMVFFHmIAid+yaCFB2zSPNoOvb2yxOcD p1/FNNuTDW77j6F9RoANJ4PIph1vf8n38UDcbXVPlw7s6OTgz5qkZDI/A38uTMbeMpvmsMDN Y/hTTKOPWiOj39ymWWWjs17FkenQNsDPivQ4fuU9bgXKpc9r+1cS0E+/b+qtXGzMgE83Ra1v hvGVpDG3d5Z1oVgsIv9IJptXzzuB4vIa92J1wSvv/BlT9DFa57OvjxIjGjXBV1dOL9JVulnk biIjsXM43rEm7QLSEHcpYiKEvhYxMe1XdcPCPnNElthoXKgVvPvsjw5wELpDbxSkdhY2Nure BvgVuu0auwueol8wF97VnFgNigzWoXNQIXunyefl8i3KwM81FXHJey39HWyYmB8cDQJCqLEC QT1mqiP4/5DnbsQGRReIfZsPJsgLHLJRqF8Z4D9mgeaB0b1mliyhL/GkEsx2yDqEViBKt7xu rjedyj9dTOzmovC4/9EkqJUvBQ4VW5xodAxcHkC+tVwtSuIMW4eIckZMrQEEptxkBGu5KrnZ TrIUnQuOR/9URtAbx/4xtbpBSWbOcAjJfb7IWYP036PSiLrGr6FPqRtxh1g71hyZDHn6uOtc vMa23/oOymO0oNbfvkS6tO7kNVY6KvjnFxQwn/Ekuv2Hxo6KpcJ3iY4HANyCAr2I/uUn0DPf WUIVWRIRX+gcnHIEOFiRmV0HS8Itza+3hQqaiaymOzkgbu599EZ6vPDOLDU6IYhPfQ6fOtEA Tu9QmaW+GmZ10ACoaZj6ZpjnaZwDunNBcSgarPqQQoJhayr92A7JIU4kDESSN05shtqe78He uJAP1BlbKhEFKxQ5FFS4QAZotRpVXYdEzzCjAj+vCLL1xsjwLA1vjC0mRnjJ8iYR7fL5i1lr PU6NS59YGF6cBPuoiR4vfkA4FnbEYcWD3asvuUAUMbpihn1IINCPOkJ7qz5vu69NFVcwYFFa Kua09M84Z+qGCSV0GgIWTvfjqdP9988J+jIt1MlEN+H2Dd9OEMXvutV8oqHczs= IronPort-HdrOrdr: A9a23:CTMelKAJgTlUrgblHej8sseALOsnbusQ8zAXPh9KJiC9I/b1qy nxppkmPEfP+UsssHFJo6HkBEDyewKhyXcV2/hdAV7GZmfbUQSTXfhfBOfZsl7d8mjFh5RgPM RbAuRD4b/LfCBHZK/BiWHSebdB/DDEytHSuQ639QY1cegAUdAF0+4NMHf8LqQAfnggOXNWLu v/2uN34xawc3Ueacq2QkICQ/XCoNPzkpfnaw4tBhIs6gWC5AnYp4LSIly95FMzQjlPybAt/S zuiAri/JiutPm911v1y3LTx44+oqqu9vJzQOi3zuQFIDTljQilIK57XaeZgTwzqOazrH43jd j3pQs6Ncgb0QKRQoj1m2qs5+DT6kdt15bQ8y7cvZIlm728eNsOMbsDuWueSGqf16NvhqA77E sB5RPni3MeN2K/oM263amRa/girDvFnZIv/NRj/kB3QM8QbqRcopcY+14QGJAcHDji4IRiC+ V2CtrAjcwmOW9yQkqpyFWH+ubcF0gbD1ODWAwPq8aV2z9ZkDRwyFYZ3tUWmjMF+IgmQ5dJ6u zYOuAw/Ys+BPM+fOZ4HqMMUMG3AmvCTVbFN3+TO03uEOUCN2jWo5D67b0p7KWheYAOzpE1hJ PdOWko/lIaagbrE4mDzZdL+hfCTCG0Wins0NhX49xjtrj1VNPQQFq+oZAV4r+dStkkc7jmsq yISeFr6tfYXBnTJbo= X-Talos-CUID: 9a23:YemOmG/DRLYLEqpQfCaVv1MxNelmdUHQ93z/LBPiCDpUEpKpEnbFrQ== X-Talos-MUID: =?us-ascii?q?9a23=3AUBuSdw2OPjdDASDGvPtS8dRx9zUjyfWRN38goLA?= =?us-ascii?q?65e6+NhBIZAui0x63Xdpy?= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,177,1779141600"; d="asc'?scan'208,217";a="287311748" X-IronPort-Outbreak-Status: No, level 0, Unknown - Unknown X-MGA-submission: =?us-ascii?q?MDEXzZu23MI5fS5U8Wo3+FRaGBO8tLAPwKxpwC?= =?us-ascii?q?0VvNuKs52bBu0uhEVejzNrnj2Mzw5Ug6Vtkc1j27x6+BMguJ36awAG9W?= =?us-ascii?q?TDTmNWpvycPADcEsdpkw0KTOPKGP1jyVaoWvrpjeC0YbykJmDFlbQ3Xw?= =?us-ascii?q?uhIfb4dBUJphdmi8enkHjHqA=3D=3D?= Received: from mx1.polytechnique.org ([129.104.30.34]) by mail2-smtp-roc.national.inria.fr with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 21 Jul 2026 18:02:53 +0200 Received: from TM.local (lstlambert-656-1-123-74.w80-14.abo.wanadoo.fr [80.14.173.74]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ssl.polytechnique.org (Postfix) with ESMTPSA id 7778B1A3AA; Tue, 21 Jul 2026 18:02:52 +0200 (CEST) From: Alan Schmitt To: "lwn" , caml-list@inria.fr Date: Tue, 21 Jul 2026 18:02:49 +0200 Message-ID: MIME-Version: 1.0 Content-Type: multipart/signed; boundary="===-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" X-AV-Checked: ClamAV using ClamSMTP at svoboda.polytechnique.org (Tue Jul 21 18:02:52 2026 +0200 (CEST)) X-Spam-Flag: Unsure, tests=bogofilter, spamicity=0.499585, queueID=BF9D71A3EF X-Org-Mail: alan.schmitt.1995@polytechnique.org Subject: [Caml-list] Attn: Development Editor, Latest OCaml Weekly News Reply-To: Alan Schmitt X-Loop: caml-list@inria.fr X-Sequence: 19553 Errors-To: caml-list-owner@inria.fr Precedence: list Precedence: bulk Sender: caml-list-request@inria.fr X-no-archive: yes List-Id: List-Help: , List-Subscribe: , List-Unsubscribe: , List-Post: List-Owner: List-Archive: Archived-At: --===-=-= Content-Type: multipart/mixed; boundary="=-=-=" --=-=-= Content-Type: multipart/alternative; boundary="==-=-=" --==-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Hello Here is the latest OCaml Weekly News, for the week of July 14 to 21, 2026. Table of Contents =E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2= =94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94= =80 ocamlgrep 0.1.1 MirageOS on Unikraft ppx_deriving_melange 0.1.0 - eq, ord, show, map, iter derivers for Melange hegel 0.12.1 A small extension of Bigarray.Genarray adding iteration, mapping and folding OCaml Security Team, report for first half of 2026 Dune Package Management Updates opam 2.6.0~alpha1 The little type that could too much Old CWN ocamlgrep 0.1.1 =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2= =95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90 Archive: Nicolas Ojeda Bar announced =E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2= =94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94= =80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80= =E2=94=80=E2=94=80 We are happy to announce the first public release of `ocamlgrep', a tool for structural grepping of OCaml code. This tool has existed within the walls of LexiFi for a long time and we were keen on open-sourcing it, but it was not in a form that could be used by the wider public. Now, thanks to the work of @mjambon, we are able to to finally do so. To install: =E2=94=8C=E2=94=80=E2=94=80=E2=94=80=E2=94=80 =E2=94=82 $ opam install ocamlgrep =E2=94=94=E2=94=80=E2=94=80=E2=94=80=E2=94=80 The idea behind the tool is simple: you call it from within your Dune project[^1] with a query (after having built all `.cmt~/'.cmti~ artifacts, eg by doing `dune build @check'), and the tool returns the list of matches it can find in the source tree. A _query_ is syntactically an OCaml expression, possibly with _holes_ `__' in it. Some examples follow to give an idea of how the tool is used in practice. The following query searches for the anti-pattern `List.rev e1 @ e2' (where `e1' and `e2' are arbitrary expressions. =E2=94=8C=E2=94=80=E2=94=80=E2=94=80=E2=94=80 =E2=94=82 $ ocamlgrep 'List.rev __ @ __` =E2=94=94=E2=94=80=E2=94=80=E2=94=80=E2=94=80 NoteNote that as the tool works at the level of the OCaml AST, it will also match expressions of the form `(@) (e1 |> List.rev) e2', since they produce the same AST. The syntax of type constraints `(e : ty)' is overloaded to impose a type condition on the search term. For example, the following search query looks for function calls where the first argument is an `int' and the second one a `string'. =E2=94=8C=E2=94=80=E2=94=80=E2=94=80=E2=94=80 =E2=94=82 $ ocamlgrep '__ (__ : int) (__ : string)' =E2=94=94=E2=94=80=E2=94=80=E2=94=80=E2=94=80 The _holes_ can be numbered, `__1', `__2', etc, to express repetitions of the same term. For example, the following query searches for a pattern matching on an option that sends `Some x' to `Some x' (ie reconstructing the same value): =E2=94=8C=E2=94=80=E2=94=80=E2=94=80=E2=94=80 =E2=94=82 $ ocamlgrep 'match __ with Some __1 -> Some __1 | None -> __' =E2=94=94=E2=94=80=E2=94=80=E2=94=80=E2=94=80 We can also look for applications of the polymorphic operator `=3D' applied to `float' arguments: =E2=94=8C=E2=94=80=E2=94=80=E2=94=80=E2=94=80 =E2=94=82 $ ocamlgrep '(__ : float) =3D __' =E2=94=94=E2=94=80=E2=94=80=E2=94=80=E2=94=80 Historically, this tool has been useful for large-scale refactorings and linting of our codebase. Nowadays, such refactorings can often be done using AI agents. However, the tool is still able to do things that seem a bit beyond of what AI agents can do today, eg to look for applications of polymorphic functions where one of the arguments is of a specific type. This was for example useful when [migrating] our codebase to `no-flat-float-array' mode, where we wanted to make sure that polymorphic array operations were not being applied to `float array' values. Happy grepping! Cheers, Nicolas [^1]: Only Dune projects are supported for now. Adding support for other build systems should not be very hard, issues and/or PRs are welcome. [migrating] MirageOS on Unikraft =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2= =95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95= =90=E2=95=90=E2=95=90=E2=95=90 Archive: Continuing this thread, shym announced =E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2= =94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94= =80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80= =E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2= =94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80 I=E2=80=99m happy to announce that OCaml/Unikraft 1.2.0 [has been release= d] with: =E2=80=A2 support for OCaml 5.4.1 and 5.5.0, =E2=80=A2 a way to use fine-tuned Unikraft configurations when that=E2=80= =99s needed, =E2=80=A2 a new version number scheme for some of the packages, to combin= e the OCaml/Unikraft version with the underlying Unikraft version. Happy unikerneling! [has been released] ppx_deriving_melange 0.1.0 - eq, ord, show, map, iter derivers for Melange =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2= =95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95= =90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90= =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2= =95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95= =90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90= =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2= =95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95= =90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90 Archive: Atlas07 announced =E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2= =94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94= =80 Hi everyone, I'm happy to announce the first release of *ppx_deriving_melange*, a Melange-compatible subset of `ppx_deriving': Why =E2=95=8C=E2=95=8C=E2=95=8C The original `ppx_deriving' can't support Melange: it predates dune's Melange integration =E2=80=94 it is distributed through findlib META file= s, and its generated code depends on a runtime library that isn't built in Melange mode. Melange can only link libraries that dune builds for it, so common patterns like `\[@@deriving eq, show\]' were off the table when writing frontend OCaml. `ppx_deriving_melange' fills that gap: same derivers, same naming conventions and attributes, implemented on ppxlib and tested against Melange =E2=80=94 and its generated code is self-contained, so nothing ex= tra needs to link into your bundle. A key use case is *universal code* =E2=80=94 libraries compiled both nati= vely and to JavaScript. Put your shared types in a library with `(modes :standard melange)', derive once, and the exact same `equal~/~compare~/~show' functions run on the server and in the browser. (This is how the project tests itself: one test-case library exercised by OUnit natively and by node on the Melange side.) What you get =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C =E2=94=8C=E2=94=80=E2=94=80=E2=94=80=E2=94=80 =E2=94=82 type user =3D { =E2=94=82=20 =E2=94=82 name : string; =E2=94=82=20 =E2=94=82 roles : string list; =E2=94=82=20 =E2=94=82 } =E2=94=82=20 =E2=94=82 [@@deriving eq, ord, show] =E2=94=82=20 =E2=94=82=20 =E2=94=82=20 =E2=94=82 (* generates: =E2=94=82=20 =E2=94=82 val equal_user : user -> user -> bool =E2=94=82=20 =E2=94=82 val compare_user : user -> user -> int =E2=94=82=20 =E2=94=82 val pp_user : Format.formatter -> user -> unit =E2=94=82=20 =E2=94=82 val show_user : user -> string *) =E2=94=94=E2=94=80=E2=94=80=E2=94=80=E2=94=80 Supported derivers in 0.1.0: `eq', `iter', `map', `ord', and `show', following the native `ppx_deriving' conventions =E2=80=94 including the `equal', `compare', and `printer' attribute overrides, the `with_path' option for `show', tuples, records, (polymorphic) variants, options, lists, arrays, results, type parameters, and recursive type groups. The README documents the exact supported scope of each deriver. Two design points worth calling out: =E2=80=A2 *Self-contained generated code.* There is no runtime library: t= he generated functions only use the stdlib, so the ppx is a build-time dependency only. =E2=80=A2 *Bundle-size-aware `show'.* Melange compiles `Stdlib.Format' in= to a lot of JavaScript, so `show' builds its string directly and only falls back to `Format' where the type requires it (custom printers, etc.). Code that only calls `show' doesn't pull Format into your bundle; `pp' stays fully Format-based and native-compatible. What's not there (yet) =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95= =8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C Some `ppx_deriving' derivers aren't implemented yet (`enum', `fold', `make', =E2=80=A6), and a few type shapes are out of scope for now (`ref', `lazy_t', `nativeint', functor-applied types). If you need one of these =E2=80=94 or hit anything that behaves differently from native `ppx_deriving' =E2=80=94 please open an issue; that's exactly the feedback that will drive what gets built next. Using it =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C =E2=94=8C=E2=94=80=E2=94=80=E2=94=80=E2=94=80 =E2=94=82 opam install ppx_deriving_melange =E2=94=94=E2=94=80=E2=94=80=E2=94=80=E2=94=80 =E2=94=8C=E2=94=80=E2=94=80=E2=94=80=E2=94=80 =E2=94=82 (library =E2=94=82=20 =E2=94=82 (name my_frontend_lib) =E2=94=82=20 =E2=94=82 (modes melange) =E2=94=82=20 =E2=94=82 (preprocess =E2=94=82=20 =E2=94=82 (pps ppx_deriving_melange))) =E2=94=94=E2=94=80=E2=94=80=E2=94=80=E2=94=80 Thanks to the `ppx_deriving' authors =E2=80=94 this project follows their design and behavior closely, and includes their license attribution =E2= =80=94 and to [davesnx] for reviews and encouragement along the way. Feedback, issues, and deriver requests very welcome! [davesnx] hegel 0.12.1 =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2= =95=90=E2=95=90=E2=95=90=E2=95=90 Archive: Ethan Chou announced =E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2= =94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94= =80=E2=94=80=E2=94=80=E2=94=80 Hello! I work at [Antithesis], a deterministic simulation testing startup. Recently, we released Hegel for OCaml. Hegel is a family of PBT libraries based on Hypothesis, providing powerful, ergonomic property-based testing for many different languages. Hegel lets you declare data generation inline with your test code, and provides native support for stateful testing. The installation instructions can be found at the Github repository [here]. Click on the link in the about section in the repository to see the documentation sorry, I can't post more than two links yet). We encourage people to contribute! Here's an example Hegel test: =E2=94=8C=E2=94=80=E2=94=80=E2=94=80=E2=94=80 =E2=94=82 let bad_map _ xs =3D xs =E2=94=82=20 =E2=94=82 let%hegel_test bad_map_vs_map tc =3D =E2=94=82 let int_gen =3D integers () in =E2=94=82 let int_fn_gen =3D functions ~sexp_of_arg:Core.Int.sexp_of_t = ~returns:int_gen () in =E2=94=82 let f =3D draw_silent tc int_fn_gen =E2=94=82 and xs =3D draw tc (lists int_gen ()) in =E2=94=82 require_equal =E2=94=82 tc =E2=94=82 (Core.List.sexp_of_t Core.Int.sexp_of_t) =E2=94=82 (bad_map f xs) (List.map f xs) =E2=94=94=E2=94=80=E2=94=80=E2=94=80=E2=94=80 prints (with colors in the terminal): =E2=94=8C=E2=94=80=E2=94=80=E2=94=80=E2=94=80 =E2=94=82 --- Failure: bad_map_vs_map (examples/higher_order.ml:20) -----= --------- =E2=94=82 Falsified after 2 test cases (0 discarded): =E2=94=82=20 =E2=94=82 xs =3D (0) =E2=94=82 f 0 =3D 1 =E2=94=82 require_equal: values differ (- lhs / + rhs): =E2=94=82 (0) (1) =E2=94=82=20 =E2=94=82 Exception: Failure("require_equal: values differ") =E2=94=82 rerun with: [@@failure_blobs [ "AAQAAAABAQAKAQAAAAABAAAKAQAAAAE= =3D" ]] =E2=94=94=E2=94=80=E2=94=80=E2=94=80=E2=94=80 Happy testing! [Antithesis] [here] A small extension of Bigarray.Genarray adding iteration, mapping and folding =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2= =95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95= =90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90= =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2= =95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95= =90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90= =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2= =95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95= =90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90= =E2=95=90 Archive: Continuing this thread, NAlec announced =E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2= =94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94= =80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80= =E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2= =94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80 Just to let you know, it is now available as [GenArrayIter] opam package. PR welcome of course. Documentation [here] [GenArrayIter] [here] OCaml Security Team, report for first half of 2026 =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2= =95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95= =90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90= =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2= =95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95= =90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90 Archive: Hannes Mehnert announced =E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2= =94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94= =80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80 Throughout the first half of 2026, the security team has worked on security advisories: the publishing pipeline (from report over communication and fixes, to the security vulnerability database - these days osv.dev and CVE). The team consists of: =E2=80=A2 Hannes Mehnert - @hannesm - individual, robur.coop =E2=80=A2 Mindy Preston - @yomimono - individual =E2=80=A2 Joe - @cfcs - individual =E2=80=A2 Edwin T=C3=B6r=C3=B6k - @edwintorok - individual, Tarides =E2=80=A2 Nicol=C3=A1s Ojeda B=C3=A4r - @nojb - LexiFi =E2=80=A2 Louis Roch=C3=A9 - @Khady - ahrefs =E2=80=A2 Boning Dong - @bn-d - Bloomberg Vulnerability Database =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95= =8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C The public vulnerability database () is established, and filled as well with old security advisories (from the MirageOS project, etc.). There is tooling via CI which generates a branch "generated-osv", which is a source for the Open Source Vulnerability database (), run by Google. The direct link for all security advisories of the OCaml Security team is [here]. The tooling is available from . [here] Audit Tooling =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C Another utility to check your "opam switch" for installed vulnerable packages (using the above mentioned vulnerability database), has been developed - available at . Public Meetings =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C On March 19th a public OCaml security meeting took place with 10 attendees. The meeting notes are available at Modification Policy of the opam-repository =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95= =8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C= =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95= =8C The Security Team proposed to make the immutability policy stricter (see ) - which has been merged. So, any published opam package must not modify its sources (change tarball, add patches, modify build instructions, =E2=80=A6). Instead, a new version must be published. This makes the pack= age URL () sensible and point to a precise source. Grant Proposals =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C A call for contributions was opened until end of March 2026. The Security Team is impressed by the amount and quality of the proposals. Evaluation and finding funding for proposals is still ongoing. We have some preliminary decisions and will reach out to the applicants by the end of July 2026. Advisories =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C So far, there have been 10 advisories (OSEC-2026-01 until OSEC-2026-10) published, and some more are worked on. Our primary communication channel is email, and we reach out to reports that we received GitHub by email. A [public mailing list] is available where security advisories are announced. They range from issues in the OCaml runtime (Marshal buffer over-read OSEC-2026-01 CVE-2026-28364, Bigarray.reshape interger overflow OSEC-2026-04 CVE-2026-34353, command injection on Windows via filename OSEC-2026-05 CVE-2026-41083), opam sandbox escape (OSEC-2026-03 CVE-2026-41082, OSEC-2026-10 CVE-2026-57825), insufficient certificate property checks (in tls, OSEC-2026-06 CVE-2026-45388, OSEC-2026-07 CVE-2026-45389), path traversal (in tar, OSEC-2026-08 CVE-2026-45390), memory exhaustion (unbounded memory usage in arp, OSEC-2026-02, infinite loop in albatross-console, OSEC-2026-09). The variety of reporters - 8 different people in 10 reports - is amazing. Thanks to all reporters, as well as the upstream developers. It has been a pleasure to coordinate the vulnerabilities. [public mailing list] Future Plans =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C The Security Team also hopes to publish security guides for OCaml programmers and project maintainers. Acknowledgements =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C The Security Team is an initiative of the OCaml Software Foundation and is grateful to the OCSF and its sponsors for their support. Dune Package Management Updates =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2= =95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95= =90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90= =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90 Archive: Continuing this thread, Shon announced =E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2= =94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94= =80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80= =E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2= =94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80 Hello! We have just made our roadmap for dune package management available on the wiki for dune: . About the roadmap =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95= =8C This living document aims to set out and explain the current status and the planned trajectory of our ongoing work. It should help to convey both what what we are working on and why we think it is important. It is not heavy on technical details, but aims to give a high level view of the project trajectory. For technical details, please click thru to the tracking issues: they are are in varying stages of discovery, but some are very well developed or provide a view into the history of completed work on the milestone. We will keep this document up to date and it will be revised as needed, to keep our projections in line with our emerging understanding, and to incorporate feedback and guidance from interested stakeholders. Support for the relocatable compiler in dune package management is now avai= lable in dune 3.24 =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95= =8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C= =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95= =8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C= =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95= =8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C= =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95= =8C=E2=95=8C As you will see on the roadmap, a substantial course of work led by @Alizter, and supported by @ElectreAAS (among others), has made the relocatable compiler available by default in dune package management, building on even more substantial prior work by @dra27's. This makes use of David's overlay compiler packages to provide relocatability for previous recent compiler versions. In my personal experience, this has made a decisive improvement in the the UX of setting up projects with dune package management, and came along with many additional fixes improving opam package compatibility. As a very welcome bonus, dune package management now supports the installation of packages that use symlinks in their sources! Input and contributions =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95= =8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C Please feel free to share any input or raise any questions! Input can be shared in this thread, or through our [documented channels for feedback]. [documented channels for feedback] opam 2.6.0~alpha1 =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2= =95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95= =90 Archive: Kate announced =E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2= =94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80 Hi everyone, We are happy to announce the first alpha release of opam 2.6.0. This is the culmination of 2 years of team work requiring large internal changes, we hope you'll enjoy it. This version is an alpha, we invite users to test it to spot previously unnoticed bugs as we head towards the stable release. What=E2=80=99s new? Some highlights: =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2= =95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95= =8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C= =E2=95=8C=E2=95=8C=E2=95=8C =E2=80=A2 :money_bag: For people using the shell hooks, this release chan= ged the way `PATH' is kept up-to-date from opam taking priority over any other elements of `PATH' by making sure to always be in front, to replacing the directory managed by opam in-place, keeping the order asked by the user. To benefit from this, make sure `opam init --reinit -ni' was ran once after upgrading to this version (automatically done by our install script if it detects an existing opam installation). ([#6859], [#6815]). /Thanks to [@gridbugs] for this contribution./ =E2=80=A2 :wastebasket: Reduce the disk space usage of opam by removing t= he `build' directory as soon as possible and removing redundant archive caches. While the disk usage used by opam can be reduced over time while simply reinstalling packages, you can liberate some free GB in one go using `opam clean --all-switches'. ([#6440], [#4056], [#5448]) =E2=80=A2 :high_speed_train: Improve performance drastically on certain file-systems (e.g. NTFS on Windows or IO constrained machines) by changing the format HTTP repositories such as opam.ocaml.org are stored in internally. ([#6625], [#5346], [#5741], [#5648], [#5484], [#5559], [#3050], [#6974]). =E2=80=A2 :envelope_with_arrow: Add `root' and `rootexec' sections to `.install' files to install files from the root prefix ([#6938], [#6919]). *Thanks to [@WardBrian] for this contribution.* =E2=80=A2 :woman_technologist: Add a new `--ignore-available-on' argument= to allow ignoring the `available:' field of certain packages ([#6836], [#5283]). *Thanks once-again to [@WardBrian] for this contribution.* =E2=80=A2 :ocean: Many more UI additions and improvements, bug fixes, =E2= =80=A6 :open_book: You can read our [blog post] for more information about these changes and more, and for even more details you can take a look at the [release note] or the [changelog]. [#6859] [#6815] [@gridbugs] [#6440] [#4056] [#5448] [#6625] [#5346] [#5741] [#5648] [#5484] [#5559] [#3050] [#6974] [#6938] [#6919] [@WardBrian] [#6836] [#5283] [blog post] [release note] [changelog] Try it! =E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C=E2=95=8C The upgrade instructions are unchanged: For Unix systems =E2=94=8C=E2=94=80=E2=94=80=E2=94=80=E2=94=80 =E2=94=82 bash -c "sh <(curl -fsSL https://opam.ocaml.org/install.sh) --v= ersion 2.6.0~alpha1" =E2=94=94=E2=94=80=E2=94=80=E2=94=80=E2=94=80 or from PowerShell for Windows systems =E2=94=8C=E2=94=80=E2=94=80=E2=94=80=E2=94=80 =E2=94=82 Invoke-Expression "& { $(Invoke-RestMethod https://opam.ocaml.o= rg/install.ps1) } -Version 2.6.0~alpha1" =E2=94=94=E2=94=80=E2=94=80=E2=94=80=E2=94=80 Please report any issues to the [bug-tracker]. Happy hacking, <> <> The opam team <> <> :camel: =E2=80=94 /Special thanks to the Haematology department and Bone Marrow Transplant Unit of the NHS Greater Glasgow for making this release possible <3/ [bug-tracker] The little type that could too much =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2= =95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95= =90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90= =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2= =95=90=E2=95=90 Archive: Rapha=C3=ABl Proust announced =E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2= =94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94= =80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80=E2=94=80 I wrote a small blog post about how some types are intended for multiple use cases and it's not always grerat. It uses the Stdlib as a small example in the intro, but the real focus is on Lwt. Feedback (on the post or on the points of Lwt that are discussed) is very welcome. I'll probably start working on improving the Lwt bits soon so let me know what you think. Old CWN =E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90=E2=95=90 If you happen to miss a CWN, you can [send me a message] and I'll mail it to you, or go take a look at [the archive] or the [RSS feed of the archives]. If you also wish to receive it every week by mail, you may subscribe to the [caml-list]. [Alan Schmitt] [send me a message] [the archive] [RSS feed of the archives] [caml-list] [Alan Schmitt] --==-=-= Content-Type: text/html; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable OCaml Weekly News

OCaml Weekly News

Previous Week<= /a> Up Next Week

Hello

Here is the latest OCaml Weekly News, for the week of July 14 to 21, 2026.

ocamlgrep 0.1.1

Nicolas Ojeda Bar announced

We are happy to announce the first public release of ocamlgrep= , a tool for structural grepping of OCaml code.

This tool has existed within the walls of LexiFi for a long time and we wer= e keen on open-sourcing it, but it was not in a form that could be used by = the wider public. Now, thanks to the work of @mjambon, we are able to to fi= nally do so.

https://= github.com/LexiFi/ocamlgrep/releases/tag/0.1.1

To install:

$ opam install ocamlgrep

The idea behind the tool is simple: you call it from within your Dune proje= ct[^1] with a query (after having built all .cmt~/.cmti~ artif= acts, eg by doing dune build @check), and the tool returns the= list of matches it can find in the source tree. A query is syntactically an OCaml expression, possibly with holes __ in it. Some examples follow = to give an idea of how the tool is used in practice.

The following query searches for the anti-pattern List.rev e1 @ e2 (where e1 and e2 are arbitrary expressions.

$ ocamlgrep 'List.rev __ @ __`

NoteNote that as the tool works at the level of the OCaml AST, it will also= match expressions of the form (@) (e1 |> List.rev) e2, sin= ce they produce the same AST.

The syntax of type constraints (e : ty) is overloaded to impos= e a type condition on the search term. For example, the following search qu= ery looks for function calls where the first argument is an int and the second one a string.

$ ocamlgrep '__ (__ : int) (__ : string)'

The holes can be numbered, __1, __2, etc, to express repetitions of the same term. For exam= ple, the following query searches for a pattern matching on an option that = sends Some x to Some x (ie reconstructing the sam= e value):

$ ocamlgrep 'match __ with Some __1 -> Some __1 | None -> __'

We can also look for applications of the polymorphic operator =3D applied to float arguments:

$ ocamlgrep '(__ : float) =3D __'

Historically, this tool has been useful for large-scale refactorings and li= nting of our codebase. Nowadays, such refactorings can often be done using = AI agents. However, the tool is still able to do things that seem a bit bey= ond of what AI agents can do today, eg to look for applications of polymorp= hic functions where one of the arguments is of a specific type. This was fo= r example useful when migrating our codebase to no-flat-float-array mode, where we wanted to make sure that polymorphic array operations wer= e not being applied to float array values.

Happy grepping!

Cheers, Nicolas

[^1]: Only Dune projects are supported for now. Adding support for other bu= ild systems should not be very hard, issues and/or PRs are welcome.

MirageOS on Unikraft

Continuing this thread, shym announced

I=E2=80=99m happy to announce that OCaml/Unikraft 1.2.0 has been released with:

  • support for OCaml 5.4.1 and 5.5.0,
  • a way to use fine-tuned Unikraft configurations when that=E2=80=99s nee= ded,
  • a new version number scheme for some of the packages, to combine the OC= aml/Unikraft version with the underlying Unikraft version.

Happy unikerneling!

ppx_deriving_melange 0.1.0 - eq, ord, show, map, iter derivers= for Melange

Atlas07 announced

Hi everyone,

I'm happy to announce the first release of ppx_deriving_melange, a M= elange-compatible subset of ppx_deriving: https://github.com/ahrefs/ppx_derivi= ng_melange

Why

The original ppx_deriving can't support Melange: it predates d= une's Melange integration =E2=80=94 it is distributed through findlib META = files, and its generated code depends on a runtime library that isn't built= in Melange mode. Melange can only link libraries that dune builds for it, = so common patterns like \[@@deriving eq, show\] were off the t= able when writing frontend OCaml.

ppx_deriving_melange fills that gap: same derivers, same namin= g conventions and attributes, implemented on ppxlib and tested against Mela= nge =E2=80=94 and its generated code is self-contained, so nothing extra ne= eds to link into your bundle.

A key use case is universal code =E2=80=94 libraries compiled both n= atively and to JavaScript. Put your shared types in a library with (m= odes :standard melange), derive once, and the exact same equal= ~/~compare~/~show functions run on the server and in the browser. (T= his is how the project tests itself: one test-case library exercised by OUn= it natively and by node on the Melange side.)

What you get

type u=
ser =3D {

  name : string;

  roles : string list;

}

[@@deriving eq, ord, show]



(* generates:

   val equal_user : use=
r -> user -> bool

   val compare_user : u=
ser -> user -> int

   val pp_user : Format=
.formatter -> user -> unit

   val show_user : user=
 -> string *)=

Supported derivers in 0.1.0: eq, iter, map<= /code>, ord, and show, following the native ppx_deriving conventions =E2=80=94 including the equal= , compare, and printer attribute overrides, the <= code>with_path option for show, tuples, records, (polym= orphic) variants, options, lists, arrays, results, type parameters, and rec= ursive type groups. The README documents the exact supported scope of each = deriver.

Two design points worth calling out:

  • Self-contained generated code. There is no runtime library: the = generated functions only use the stdlib, so the ppx is a build-time depende= ncy only.
  • Bundle-size-aware show. Melange compiles Stdl= ib.Format into a lot of JavaScript, so show builds its = string directly and only falls back to Format where the type r= equires it (custom printers, etc.). Code that only calls show = doesn't pull Format into your bundle; pp stays fully Format-ba= sed and native-compatible.

What's not there (yet)

Some ppx_deriving derivers aren't implemented yet (enum<= /code>, fold, make, …), and a few type sha= pes are out of scope for now (ref, lazy_t, = nativeint, functor-applied types). If you need one of these =E2=80= =94 or hit anything that behaves differently from native ppx_deriving= =E2=80=94 please open an issue; that's exactly the feedback that wi= ll drive what gets built next.

Using it

opam install ppx_deriving_melange
(library

 (name my_frontend_lib)

 (modes melange)

 (preprocess

  (pps ppx_deriving_melange)))

Thanks to the ppx_deriving authors =E2=80=94 this project foll= ows their design and behavior closely, and includes their license attributi= on =E2=80=94 and to davesnx for = reviews and encouragement along the way.

Feedback, issues, and deriver requests very welcome!

hegel 0.12.1

Ethan Chou announced

Hello! I work at Antithesis, a deter= ministic simulation testing startup.

Recently, we released Hegel for OCaml.

Hegel is a family of PBT libraries based on Hypothesis, providing powerful,= ergonomic property-based testing for many different languages. Hegel lets = you declare data generation inline with your test code, and provides native= support for stateful testing.

The installation instructions can be found at the Github repository here. Click on the link in= the about section in the repository to see the documentation sorry, I can'= t post more than two links yet). We encourage people to contribute!

Here's an example Hegel test:

let bad_map _ xs =3D xs

let%hegel_test bad_ma=
p_vs_map tc =3D
  let int_gen =3D integers () in
  let int_fn_gen =3D functions ~sexp_of_arg:Core.Int.sexp_of_t ~returns:int_gen () in
  let f =3D draw_silent tc int_fn_gen
  and xs =3D draw tc (lists int_gen ()) in
  require_equal
    tc
    (Core.List.se=
xp_of_t Core.Int.=
sexp_of_t)
    (bad_map f xs) (List=
.map f xs)

prints (with colors in the terminal):

=2D-- Failure: bad_map_vs_map (examples/higher_order.ml:20) --------------
Falsified after 2 test cases (0 discarded):

xs =3D (0)
f 0 =3D 1
require_equal: values differ (- lhs / + rhs):
(0)  (1)

Exception: Failure("require_equal: values differ")
rerun with: [@@failure_blobs [ "AAQAAAABAQAKAQAAAAABAAAKAQAAAAE=3D" ]]

Happy testing!

A small extension of Bigarray.Genarray adding iteration, mappi= ng and folding

Continuing this thread, NAlec announced

Just to let you know, it is now available as GenArrayIter opam package. PR welcome of course.= =20 Documentation here

OCaml Security Team, report for first half of 2026

Hannes Mehnert announced

Throughout the first half of 2026, the security team has worked on security= advisories: the publishing pipeline (from report over communication and fi= xes, to the security vulnerability database - these days osv.dev and CVE).

The team consists of:

  • Hannes Mehnert - @hannesm - individual, robur.coop
  • Mindy Preston - @yomimono - individual
  • Joe - @cfcs - individual
  • Edwin T=C3=B6r=C3=B6k - @edwintorok - individual, Tarides
  • Nicol=C3=A1s Ojeda B=C3=A4r - @nojb - LexiFi
  • Louis Roch=C3=A9 - @Khady - ahrefs
  • Boning Dong - @bn-d - Bloomberg

Vulnerability Database

The public vulnerability database (https://github.com/ocaml/security-advisories) is estab= lished, and filled as well with old security advisories (from the MirageOS = project, etc.). There is tooling via CI which generates a branch "generated= -osv", which is a source for the Open Source Vulnerability database (https://osv.dev), run by Google. The direct link = for all security advisories of the OCaml Security team is here.

The tooling is available from https://github.com/hannesm/advisories.

Audit Tooling

Another utility to check your "opam switch" for installed vulnerable packag= es (using the above mentioned vulnerability database), has been developed -= available at https://git= hub.com/hannesm/opam-audit.

Public Meetings

On March 19th a public OCaml security meeting took place with 10 attendees.= The meeting notes are available at https://pad.data.coop/7-Ic5rG6ToynsW02hJsndg

Modification Policy of the opam-repository

The Security Team proposed to make the immutability policy stricter (see https://githu= b.com/ocaml/opam-repository/pull/29072) - which has been merged. So, an= y published opam package must not modify its sources (change tarball, add p= atches, modify build instructions, …). Instead, a new version must b= e published. This makes the package URL (https://github.com/package-url/purl-spec) sensible a= nd point to a precise source.

Grant Proposals

A call for contributions was opened until end of March 2026. The Security T= eam is impressed by the amount and quality of the proposals. Evaluation and= finding funding for proposals is still ongoing. We have some preliminary d= ecisions and will reach out to the applicants by the end of July 2026.

Advisories

So far, there have been 10 advisories (OSEC-2026-01 until OSEC-2026-10) pub= lished, and some more are worked on. Our primary communication channel is e= mail, and we reach out to reports that we received GitHub by email. A = public mailing list is available where security advisories are announce= d.

They range from issues in the OCaml runtime (Marshal buffer over-read OSEC-= 2026-01 CVE-2026-28364, Bigarray.reshape interger overflow OSEC-2026-04 CVE= -2026-34353, command injection on Windows via filename OSEC-2026-05 CVE-202= 6-41083), opam sandbox escape (OSEC-2026-03 CVE-2026-41082, OSEC-2026-10 CV= E-2026-57825), insufficient certificate property checks (in tls, OSEC-2026-= 06 CVE-2026-45388, OSEC-2026-07 CVE-2026-45389), path traversal (in tar, OS= EC-2026-08 CVE-2026-45390), memory exhaustion (unbounded memory usage in ar= p, OSEC-2026-02, infinite loop in albatross-console, OSEC-2026-09).

The variety of reporters - 8 different people in 10 reports - is amazing. T= hanks to all reporters, as well as the upstream developers. It has been a p= leasure to coordinate the vulnerabilities.

Future Plans

The Security Team also hopes to publish security guides for OCaml programme= rs and project maintainers.

Acknowledgements

The Security Team is an initiative of the OCaml Software Foundation and is = grateful to the OCSF and its sponsors for their support.

Dune Package Management Updates

Continuing this thread, Shon announced

Hello! We have just made our roadmap for dune package management available = on the wiki for dune: https://github.com/ocaml/dune/wiki/Dune-Pkg-Roadmap.

About the roadmap

This living document aims to set out and explain the current status and the= planned trajectory of our ongoing work. It should help to convey both what= what we are working on and why we think it is important. It is not heavy o= n technical details, but aims to give a high level view of the project traj= ectory. For technical details, please click thru to the tracking issues: th= ey are are in varying stages of discovery, but some are very well developed= or provide a view into the history of completed work on the milestone.

We will keep this document up to date and it will be revised as needed, to = keep our projections in line with our emerging understanding, and to incorp= orate feedback and guidance from interested stakeholders.

Support for the relocatable compiler in dune package = management is now available in dune 3.24

As you will see on the roadmap, a substantial course of work led by @Alizte= r, and supported by @ElectreAAS (among others), has made the relocatable co= mpiler available by default in dune package management, building on even mo= re substantial prior work by @dra27's. This makes use of David's overlay c= ompiler packages to provide relocatability for previous recent compiler ver= sions.=20

In my personal experience, this has made a decisive improvement in the the = UX of setting up projects with dune package management, and came along with= many additional fixes improving opam package compatibility.

As a very welcome bonus, dune package management now supports the installat= ion of packages that use symlinks in their sources!

Input and contributions

Please feel free to share any input or raise any questions! Input can be sh= ared in this thread, or through our documented channels for feedb= ack.

opam 2.6.0~alpha1

Kate announced

Hi everyone,

We are happy to announce the first alpha release of opam 2.6.0. This is the= culmination of 2 years of team work requiring large internal changes, we h= ope you'll enjoy it.

This version is an alpha, we invite users to test it to spot previously unn= oticed bugs as we head towards the stable release.

What=E2=80=99s new? Some highlights:

  • :money_bag: For people using the shell hooks, this release changed the = way PATH is kept up-to-date from opam taking priority over any= other elements of PATH by making sure to always be in front, = to replacing the directory managed by opam in-place, keeping the order aske= d by the user. To benefit from this, make sure opam init --reinit -ni= was ran once after upgrading to this version (automatically done by= our install script if it detects an existing opam installation). (#6859, #6815). Thanks to @gridbugs for this contribution.
  • :wastebasket: Reduce the disk space usage of opam by removing the build directory as soon as possible and removing redundant archive = caches. While the disk usage used by opam can be reduced over time while si= mply reinstalling packages, you can liberate some free GB in one go using <= code>opam clean --all-switches. (#6440, #4056, #54= 48)
  • :high_speed_train: Improve performance drastically on certain file-syst= ems (e.g. NTFS on Windows or IO constrained machines) by changing the forma= t HTTP repositories such as opam.ocaml.org are stored in internally. (#6625, #5346, #5741, #5648, #5484, #55= 59, #3050, #6974).
  • :envelope_with_arrow: Add root and rootexec s= ections to .install files to install files from the root prefi= x (#6938, #6919). Thanks to @WardBrian for this contribution.=
  • :woman_technologist: Add a new --ignore-available-on argum= ent to allow ignoring the available: field of certain packages= (#6836, #5283). Thanks once-agai= n to @WardBrian for this contr= ibution.
  • :ocean: Many more UI additions and improvements, bug fixes, =E2=80=A6

:open_book: You can read our blog post for more information about these changes and mor= e, and for even more details you can take a look at the release note or the changelog= .

Try it!

The upgrade instructions are unchanged:

For Unix systems

bash -c "sh <(curl -fsSL https://opam.ocaml.org/install.sh) --version 2.=
6.0~alpha1"

or from PowerShell for Windows systems

Invoke-Expression "& { $(Invoke-RestMethod https://opam.ocaml.org/insta=
ll.ps1) } -Version 2.6.0~alpha1"

Please report any issues to the bug-tracker.

Happy hacking, <> <> The opam team <> <> :camel:

Special thanks to the Haematology department and Bone Marrow Transplant = Unit of the NHS Greater Glasgow for making this release possible <3

The little type that could too much

Rapha=C3=ABl Proust announced

I wrote a small blog post about how some types are intended for multiple us= e cases and it's not always grerat. It uses the Stdlib as a small example i= n the intro, but the real focus is on Lwt.

https://tech.ahrefs.com/the-little-type-that-could-too-much-3f21c= 2e80430

Feedback (on the post or on the points of Lwt that are discussed) is very w= elcome. I'll probably start working on improving the Lwt bits soon so let m= e know what you think.

Old CWN

If you happen to miss a CWN, you can send me a message and I'll mail it to you, or go take a loo= k at the archive or the <= a href=3D"https://alan.petitepomme.net/cwn/cwn.rss">RSS feed of the archive= s.

If you also wish to receive it every week by mail, you may subscribe to the= caml-list.

--==-=-=-- --=-=-=-- --===-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQFvBAEBCABZFiEE6lXof/BsSVW56ZmGBA0KO07S5ccFAmpfmCkbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMCwzHxxhbGFuLnNjaG1pdHRAcG9seXRlY2huaXF1ZS5v cmcACgkQBA0KO07S5ccQ5Af7BX+Z0CxLAFCGhsk2OjdvePowFMhnGEUdHbLEPyls D1VakbOaHuIUIXfoDVLJ8uBqzXbeBboKWFPom4VkQxpQ7uGqbQIiCL+gmXe6CHZb fYpAeQCwxM6fjKz4QsBpbzagQDtPpaysl8KNMhdCGDBa9skDRSNWKTVFrtdY4eas xlCbLHaHQJqaV+sh8ANyLKWIJc3JRKuuqjQyU1VoOJh6FTakIYvApVfsL+7ngibn opwkg3K0AglATPH95n5orBQh4stsZgzv7o3nnhsqxMWpzfzpYA+kRYdv2OCE02AG miB/NgWG1iWfOv5/N3TsG5B4t0sOodXiyLoCrjXUSOa/Vg== =nl9F -----END PGP SIGNATURE----- --===-=-=--