Commit 1ae30c2812 for bind

commit 1ae30c2812fc7a9afc0d69c386de657b04fa798b
Author: Michal Nowak <mnowak@isc.org>
Date:   Fri Sep 25 05:28:34 2026 +0000

    Test BIND 9 with TSAN against libuv git

    The libuv-git jobs build libuv without a sanitizer, so they missed the
    uv_async_send() vs uv_loop_close() data race that libuv git had for
    four months before it was released in 1.53.0 and the TSAN jobs caught
    it.

    Move the libuv-git build, unit, and system test jobs from the
    tumbleweed image to the tsan-fedora-44 one, build libuv git with
    -fsanitize=thread, and link BIND 9 against it instead of the libuv
    release in /opt/tsan.

    Assisted-by: Claude:claude-opus-5-5[1m]

diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml
index ddb3782520..33a31deab2 100644
--- a/.gitlab-ci.yml
+++ b/.gitlab-ci.yml
@@ -1803,45 +1803,48 @@ unit:clang:freebsd15:amd64:
   <<: *unit_test_job
   <<: *freebsd_autoscaler_15_amd64_tags

-# Build and run tests against the latest git version of libuv
+# Build and run tests with TSAN against the latest git version of libuv

-gcc:tumbleweed:libuv-git:amd64:
-  <<: *tumbleweed_latest_amd64_image
+gcc:tsan:libuv-git:amd64:
+  <<: *tsan_fedora_44_amd64_image
   <<: *build_job
   variables:
-    EXTRA_SETUP_FILES: "--native-file ci/tumbleweed.ini"
+    EXTRA_SETUP_FILES: "--native-file ci/tsan.ini --native-file ci/tsan-gcc.ini --native-file ci/libuv-git.ini"
   before_script:
     - *list_installed_package_versions
-    - zypper --non-interactive rm --clean-deps libuv-devel
     - git clone --depth 1 https://github.com/libuv/libuv.git /tmp/libuv
     - cd /tmp/libuv
     - sh autogen.sh
-    - ./configure --prefix="$CI_PROJECT_DIR/libuv"
-    - make -j"$BUILD_PARALLEL_JOBS" CFLAGS=""
+    # Same flags as the libuv build in the tsan-fedora-44 image.
+    - CFLAGS="-rdynamic -ggdb -O2 -Wno-deprecated-declarations -fno-omit-frame-pointer -fno-optimize-sibling-calls -fPIC -fsanitize=thread -Wl,-rpath=/opt/tsan/lib -Wl,--enable-new-dtags" LDFLAGS="-fPIE -fsanitize=thread -Wl,-rpath=/opt/tsan/lib -Wl,--disable-new-dtags" ./configure --prefix="$CI_PROJECT_DIR/libuv"
+    - make -j"$BUILD_PARALLEL_JOBS"
     - make install
     - cd "$CI_PROJECT_DIR"
-    - export PKG_CONFIG_PATH="$CI_PROJECT_DIR/libuv/lib/pkgconfig:${PKG_CONFIG_PATH:-}"
   rules:
     - *rule_source_other_than_mr

-system:gcc:tumbleweed:libuv-git:amd64:
-  <<: *tumbleweed_latest_amd64_image
-  <<: *system_test_job
+system:gcc:tsan:libuv-git:amd64:
+  variables:
+    TSAN_SYMBOLIZER_PATH: "${TSAN_SYMBOLIZER_PATH_FEDORA}"
+  <<: *tsan_fedora_44_amd64_image
+  <<: *system_test_tsan_job
   needs:
-    - job: gcc:tumbleweed:libuv-git:amd64
+    - job: gcc:tsan:libuv-git:amd64
       artifacts: true
   rules:
     - *rule_source_other_than_mr

-unit:gcc:tumbleweed:libuv-git:amd64:
-  <<: *tumbleweed_latest_amd64_image
-  <<: *unit_test_job
+unit:gcc:tsan:libuv-git:amd64:
+  variables:
+    TSAN_SYMBOLIZER_PATH: "${TSAN_SYMBOLIZER_PATH_FEDORA}"
+  <<: *tsan_fedora_44_amd64_image
+  <<: *unit_test_tsan_job
   before_script:
     - build/named -V > named.version
     - "grep -E '^compiled with libuv version: [0-9]+\\.[0-9]+\\.[0-9]+$' named.version"
     - "grep -E '^linked to libuv version: [0-9]+\\.[0-9]+\\.[0-9]+-dev$' named.version"
   needs:
-    - job: gcc:tumbleweed:libuv-git:amd64
+    - job: gcc:tsan:libuv-git:amd64
       artifacts: true
   rules:
     - *rule_source_other_than_mr
diff --git a/ci/libuv-git.ini b/ci/libuv-git.ini
new file mode 100644
index 0000000000..989340ea50
--- /dev/null
+++ b/ci/libuv-git.ini
@@ -0,0 +1,10 @@
+# The libuv-git jobs install libuv git into the source tree.  /opt/tsan in the
+# tsan images also has a libuv release, so list libuv git first in
+# pkg_config_path and pass its include directory with the compiler, ahead of
+# the -I/opt/tsan/include added by liburcu and OpenSSL.
+
+[binaries]
+c = ['gcc', '-I@GLOBAL_SOURCE_ROOT@/libuv/include']
+
+[built-in options]
+pkg_config_path = ['@GLOBAL_SOURCE_ROOT@/libuv/lib/pkgconfig', '/opt/tsan/lib/pkgconfig']