cherry-pick security from upstream