summaryrefslogtreecommitdiff
path: root/meta-openembedded/meta-python/recipes-devtools
diff options
context:
space:
mode:
authorAndrew Geissler <geissonator@yahoo.com>2025-11-03 19:09:31 +0300
committerAndrew Geissler <geissonator@yahoo.com>2025-11-03 22:31:57 +0300
commit6cb7f76381dbeb50bbf963f9192344f02d985637 (patch)
treee194737ad2b6c562f463cc7a22116ef4aebd1232 /meta-openembedded/meta-python/recipes-devtools
parent1f52643312f6f67537eb27bef9156e8b8bc66040 (diff)
downloadopenbmc-scarthgap.tar.xz
subtree updates (scarthgap 11/3/2025)scarthgap
poky: ca27724b44..c4a4df3e72: Adam Blank (3): kernel-dev/common.rst: fix the in-tree defconfig description ref-manual/variables.rst: fix the description of KBUILD_DEFCONFIG ref-manual/variables.rst: fix the description of STAGING_DIR Aditya Tayade (1): e2fsprogs: removed 'sed -u' option Adrian Freihofer (15): kernel-fitimage: fix intentation kernel-fitimage: fix external dtb check devtool: modify support debug-builds devtool: ide-sdk sort cmake preset devtool: ide-sdk recommend DEBUG_BUILD oe-selftest: devtool ide-sdk use modify debug-build devtool: ide-sdk remove the plugin from eSDK installer uboot-config: fix devtool modify with kernel-fitimage sdk-manual: extensible.rst: devtool ide-sdk improve sdk-manual: extensible.rst: update devtool ide-sdk ref-manual: kernel-fitimage.bbclass does not use SPL_SIGN_KEYNAME llvm: update from 18.1.6 to 18.1.8 llvm: fix build with gcc-15 expect: Revert "expect-native: fix do_compile failure with gcc-14" expect: fix native build with GCC 15 Alban Bedel (1): bind: Fix build with the `httpstats` package config enabled Aleksandar Nikolic (12): cve-check: Introduce CVE_CHECK_MANIFEST_JSON_SUFFIX install-buildtools: remove md5 checksum validation install-buildtools: fix "test installation" step install-buildtools: update base-url, release and installer version ref-manual: introduce CVE_CHECK_REPORT_PATCHED variable scripts/install-buildtools: Update to 5.0.5 scripts/install-buildtools: Update to 5.0.6 scripts/install-buildtools: Update to 5.0.7 scripts/install-buildtools: Update to 5.0.9 scripts/install-buildtools: Update to 5.0.10 scripts/install-buildtools: Update to 5.0.11 scripts/install-buildtools: Update to 5.0.12 Alessio Cascone (1): tzcode-native: Fix compiler setting from 2023d version Alexander Kanavin (29): mesa: remove obsolete 0001-meson.build-check-for-all-linux-host_os-combinations.patch kexec-tools: submit 0003-kexec-ARM-Fix-add_buffer_phys_virt-align-issue.patch upstream vorbis: mark patch as Inactive-Upstream grub: mark grub-module-explicitly-keeps-symbole-.module_license.patch as a workaround perl: submit the rest of determinism.patch upstream iptables: submit 0001-configure-Add-option-to-enable-disable-libnfnetlink.patch upstream xserver-xorg: upgrade 21.1.12 -> 21.1.13 mobile-broadband-provider-info: upgrade 20230416 -> 20240407 python3: submit deterministic_imports.patch upstream as a ticket glib-networking: submit eagain.patch upstream glslang: mark 0001-generate-glslang-pkg-config.patch as Inappropriate tcp-wrappers: mark all patches as inactive-upstream automake: mark new_rt_path_for_test-driver.patch as Inappropriate settings-daemon: submit addsoundkeys.patch upstream and update to a revision that has it dpkg: mark patches adding custom non-debian architectures as inappropriate for upstream libacpi: mark patches as inactive-upstream apr: drop 0007-explicitly-link-libapr-against-phtread-to-make-gold-.patch pulseaudio, desktop-file-utils: correct freedesktop.org -> www.freedesktop.org SRC_URI sysvinit: take release tarballs from github package_rpm: use zstd's default compression level package_rpm: restrict rpm to 4 threads rust: add reproducibility patch to eliminate host leakage rust: build the default set of tools rust: use rust-snapshot binaries only in rust-native rust: correctly link rust-snapshot into build/stage0 pkg-config-native: pick additional search paths from $EXTRA_NATIVE_PKGCONFIG_PATH selftest/rust: correctly form the PATH environment variable perlcross: update 1.5.2 -> 1.6 mtools: upgrade 4.0.43 -> 4.0.44 Alexis Cellier (1): systemd: add libpcre2 as RRECOMMENDS if pcre2 is enabled Alexis Lothoré (3): oeqa/utils/postactions: transfer whole archive over ssh instead of doing individual copies oeqa/postactions: fix exception handling oeqa/ssh: allow to retrieve raw, unformatted ouput Alon Bar-Lev (1): module.bbclass: add KBUILD_EXTRA_SYMBOLS to install Alper Ak (2): ref-manual/variables.rst: document INHIBIT_DEFAULT_RUST_DEPS ref-manual/variables.rst: document INHIBIT_UPDATERCD_BBCLASS Anders Heimer (1): libpam: mark CVE-2025-6018 as not applicable Andrew Fernandes (1): gtk+: add missing libdrm dependency Andrew Kreimer (1): manuals: remove repeated word Antonin Godard (77): ref-manual: add missing CVE_CHECK manifest variables ref-manual: add missing TESTIMAGE_FAILED_QA_ARTIFACTS ref-manual: add missing EXTERNAL_KERNEL_DEVICETREE variable ref-manual: add missing OPKGBUILDCMD variable ref-manual: merge patch-status-* to patch-status ref-manual: structure.rst: document missing tmp/ dirs overview-manual: concepts: add details on package splitting ref-manual: faq: add q&a on class appends ref-manual: release-process: update releases.svg ref-manual: release-process: refresh the current LTS releases ref-manual: release-process: update releases.svg with month after "Current" ref-manual: release-process: add a reference to the doc's release ref-manual: devtool-reference: refresh example outputs ref-manual: devtool-reference: document missing commands conf.py: rename :cve: role to :cve_nist: doc: Makefile: remove inkscape, replace by rsvg-convert doc: Makefile: add support for xelatex doc: add a download page for epub and pdf sphinx-static/switchers.js.in: do not refer to URL_ROOT anymore conf.py: add a bitbake_git extlink dev-manual: document how to provide confs from layer.conf dev-manual: bblock: use warning block instead of attention standards.md: add a section on admonitions ref-manual: classes: fix bin_package description Gather dependencies in poky.yaml.in poky.yaml.in: add missing locales dependency poky.yaml.in: replace inkscape dependency by librsvg2-bin system-requirements: add fedora 39 to supported distros system-requirements: update list of supported distros system-requirements.rst: add dependencies for pdf builds Update the documentation for SRCPV poky.conf: add new tested distros ref-manual/qa-checks: remove patch-status-core/patch-status-noncore contributor-guide/submit-changes.rst: suggest to remove the git signature ref-manual/devtool-reference: add warning note on deploy-target and shared objects SSTATE_MIRRORS/SOURCE_MIRROR_URL: add instructions for mirror authentication ref-manual/packages: move ptest section to the test-manual ref-manual: move runtime-testing section to the test-manual Update autobuilder URLs to valkyrie test-manual/reproducible-builds: fix reproducible links test-manual/ptest: link to common framework ptest classes dev-manual/building: document the initramfs-framework recipe ref-manual/faq: add q&a on systemd as default contributor-guide/submit-changes: add policy on AI generated code Add favicon for the documentation html overview-manual/concepts: remove PR from the build dir list ref-manual/variables.rst: WATCHDOG_TIMEOUT: fix recipe name ref-manual/variables.rst: document autotools class related variables documentation/conf.py: define a manpage url ref-manual/variables.rst: add manpage links for toolchain variables ref-manual/variables.rst: add missing documentation for BUILD_* variables ref-manual/variables.rst: document missing SDK_*_ARCH variables ref-manual/variables.rst: document HOST_*_ARCH variables ref-manual/variables.rst: HOST_CC_ARCH: fix wrong SDK reference ref-manual/variables.rst: improve the PKGV documentation poky.yaml: introduce DISTRO_LATEST_TAG Fix dead links that use the DISTRO macro dev-manual/sbom.rst: fix wrong build outputs test-manual/intro: remove Buildbot version used ref-manual/release-process: update releases.svg overview-manual/concepts.rst: fix sayhello hardcoded bindir ref-manual/system-requirements.rst: update supported distributions ref-manual/variables.rst: document the FIT_CONF_PREFIX variable ref-manual/variables.rst: document SPL_DTB_BINARY ref-manual/classes.rst: document the testexport class dev-manual/security-subjects.rst: update mailing lists test-manual/yocto-project-compatible.rst: fix a typo ref-manual/structure: document the auto.conf file ref-manual/variables.rst: document UNINATIVE_URL/CHECKSUM ref-manual/classes.rst: extend the uninative class documentation ref-manual/classes,variables: document the CCACHE_DISABLE variable ref-manual/variables.rst: document the REQUIRED_MACHINE_FEATURES variable ref-manual/variables.rst: document the REQUIRED_COMBINED_FEATURES variable ref-manual/variables.rst: document the REQUIRED_IMAGE_FEATURES variable ref-manual/variables.rst: document the USE_NLS variable ref-manual/classes.rst: gettext: extend the documentation of the class ref-manual/classes.rst: document the relative_symlinks class Anuj Mittal (1): sqlite3: upgrade 3.45.1 -> 3.45.3 Archana Polampalli (51): less: fix CVE-2024-32487 ofono: fix CVE-2023-2794 ffmpeg: fix CVE-2023-49502 ffmpeg: fix CVE-2024-31578 ffmpeg: fix CVE-2024-31582 ffmpeg: fix CVE-2023-50008 ffmpeg: fix CVE-2024-32230 qemu: fix CVE-2024-7409 ffmpeg: fix CVE-2023-49501 ffmpeg: fix CVE-2024-28661 ffmpeg: fix CVE-2023-50007 ffmpeg: fix CVE-2023-49528 ffmpeg: fix CVE-2024-7055 ffmpeg: fix CVE-2024-35366 ffmpeg: fix CVE-2024-35367 ffmpeg: fix CVE-2024-35368 rsync: fix CVE-2024-12084 rsync: fix CVE-2024-12085 rsync: fix CVE-2024-12086 rsync: fix CVE-2024-12087 rsync: fix CVE-2024-12088 rsync: fix CVE-2024-12747 ffmpeg: fix CVE-2024-35365 ffmpeg: fix CVE-2024-36613 ffmpeg: fix CVE-2024-36616 ffmpeg: fix CVE-2024-36617 ffmpeg: fix CVE-2024-36618 ffmpeg: fix CVE-2024-36619 ffmpeg: fix CVE-2024-35369 gstreamer1.0-rtsp-server: fix CVE-2024-44331 ffmpeg: fix CVE-2025-25473 ffmpeg: fix CVE-2025-25471 ffmpeg: fix CVE-2025-22921 ffmpeg: fix CVE-2025-0518 ffmpeg: Correct the CVE ID to fix CVE-2025-22919 openssh: fix CVE-2025-26465 go: fix CVE-2025-22870 ghostscript: upgrade 10.04.0 -> 10.05.0 perlcross: 1.6 -> 1.6.2 perl: upgrade 5.38.2 -> 5.38.4 xwayland: fix CVE-2025-49175 xwayland: fix CVE-2025-49176 xwayland: fix CVE-2025-49177 xwayland: fix CVE-2025-49178 xwayland: fix CVE-2025-49179 xwayland: fix CVE-2025-49180 gdk-pixbuf: fix CVE-2025-7345 go: fix CVE-2025-4674 ffmpeg: upgrade 6.1.2 -> 6.1.3 ffmpeg: fix CVE-2025-1594 go: fix CVE-2025-47906 Ashish Sharma (11): bind: Upgrade 9.18.25 -> 9.18.28 ruby: Backport fix for CVE-2024-27282 ruby: Fix CVE-2025-27219 binutils: Fix CVE-2025-1176 binutils: patch CVE-2025-1178 & CVE-2024-57360 binutils: patch CVE-2025-1181 binutils: patch CVE-2025-1182 libsoup: patch CVE-2025-46420 libsoup-2.4: Fix CVE-2025-46420 libsoup: patch CVE-2025-4476 screen: patch CVE-2025-46805 AshishKumar Mishra (2): systemd: backport fix for handle USE_NLS from master p11-kit: backport fix for handle USE_NLS from master Barne Carstensen (1): test-manual: update runtime-testing Exporting Tests section Bartosz Golaszewski (1): linux-firmware: add a package for ath12k firmware Benjamin Szőke (2): archiver.bbclass: Fix work-shared checking for kernel recipes mc: fix source URL Bin Lan (1): lttng-ust: backport patch to fix cmake-multiple-shared-libraries build error Bruce Ashfield (54): linux-yocto/6.6: update to v6.6.36 linux-yocto/6.6: update to v6.6.38 linux-yocto/6.6: update to v6.6.40 linux-yocto/6.6: update to v6.6.43 kernel-devsrc: remove 64 bit vdso cmd files linux-yocto/6.6: update to v6.6.44 linux-yocto/6.6: update to v6.6.45 linux-yocto/6.6: fix genericarm64 config warning linux-yocto/6.6: update to v6.6.47 linux-yocto/6.6: update to v6.6.49 linux-yocto/6.6: update to v6.6.50 linux-yocto/6.6: update to v6.6.52 linux-yocto/6.6: update to v6.6.54 linux-yocto/6.6: update to v6.6.56 linux-yocto/6.6: update to v6.6.58 linux-yocto/6.6: genericarm64.cfg: enable CONFIG_DMA_CMA linux-yocto/6.6: update to v6.6.59 linux-yocto/6.6: update to v6.6.60 linux-yocto/6.6: update to v6.6.62 linux-yocto/6.6: bsp/genericarm64: disable ARM64_SME linux-yocto/6.6: update to v6.6.63 linux-yocto/6.6: update to v6.6.64 linux-yocto/6.6: update to v6.6.66 linux-yocto/6.6: update to v6.6.69 linux-yocto/6.6: update to v6.6.75 linux-yocto/6.6: update to v6.6.77 linux-yocto/6.6: update to v6.6.78 linux-yocto/6.6: update to v6.6.80 linux-yocto/6.6: update to v6.6.82 linux-yocto/6.6: update to v6.6.83 linux-yocto/6.6: update to v6.6.84 linux-yocto/6.6: update to v6.6.85 linux-yocto/6.6: fix beaglebone ethernet linux-yocto/6.6: update to v6.6.86 linux-yocto/6.6: update to v6.6.87 linux-yocto/6.6: update to v6.6.88 linux-yocto/6.6: update to v6.6.89 linux-yocto/6.6: update to v6.6.91 linux-yocto/6.6: update to v6.6.92 linux-yocto/6.6: update to v6.6.93 linux-yocto/6.6: update to v6.6.94 linux-yocto/6.6: update to v6.6.96 linux-yocto/6.6: update to v6.6.98 linux-yocto/6.6: update to v6.6.99 linux-yocto/6.6: update to v6.6.100 linux-yocto/6.6: update to v6.6.101 linux-yocto/6.6: update to v6.6.102 linux-yocto/6.6: update to v6.6.103 linux-yocto/6.6: update to v6.6.106 linux-yocto/6.6: update to v6.6.107 linux-yocto/6.6: update to v6.6.108 linux-yocto/6.6: update to v6.6.109 linux-yocto/6.6: update to v6.6.110 linux-yocto/6.6: update to v6.6.111 Carlos Alberto Lopez Perez (1): icu: Backport patch to fix build issues with long paths (>512 chars) Carlos Sánchez de La Lama (1): ref-manual: clarify KCONFIG_MODE default behaviour Catalin Popescu (1): Revert "bluez5: remove configuration files from install task" Changqing Li (48): apt-native: don't let dpkg overwrite files by default apt: runtime error: filename too long (tmpdir length) webkitgtk: fix do_configure error on beaglebone-yocto webkitgtk: fix do_compile errors on beaglebone-yocto vulkan-samples: fix do_compile error when -Og enabled multilib.conf: remove appending to PKG_CONFIG_PATH gettext: fix a parallel build issue pixman: fixing inline failure with -Og rt-tests: rt_bmark.py: fix TypeError curl: correct the PACKAGECONFIG for native/nativesdk libpng: update SRC_URI expect-native: fix do_compile failure with gcc-14 libcap-ng: update SRC_URI sysvinit: backport patch for fixing one issue of pidof acpica: fix CVE-2024-24856 libsoup: fix CVE-2024-52530, CVE-2024-52531 rxvt-unicode.inc: disable the terminfo installation by setting TIC to : sanity.bbclass: skip check_userns for non-local uid systemd: enable create-log-dirs babeltrace: extend to nativesdk babeltrace2: extend to nativesdk patch.py: set commituser and commitemail for addNote initscripts: add function log_success_msg/log_failure_msg/log_warning_msg buildtools-tarball: move setting of envvars to respective envfile buildtools-tarball: add envvars into BB_ENV_PASSTHROUGH_ADDITIONS buildtools-tarball: Make buildtools respects host CA certificates libsoup: fix CVE-2025-32908 libsoup: fix CVE-2025-32907 libsoup-2.4: fix CVE-2025-32907 libsoup-2.4: fix do_compile failure libsoup-2.4: fix CVE-2025-32053 libsoup: fix CVE-2025-32053 libsoup-2.4: fix CVE-2025-32052 libsoup: fix CVE-2025-32052 libsoup: fix CVE-2025-32051 libsoup-2.4: fix CVE-2025-32050 libsoup: fix CVE-2025-32050 libsoup-2.4: fix CVE-2025-46421 libsoup: fix CVE-2025-46421 libsoup-2.4: fix CVE-2025-4948 libsoup: fix CVE-2025-4948 libsoup-2.4: fix CVE-2025-4476 libsoup-2.4: fix CVE-2025-2784 libsoup: fix CVE-2025-2784 icu: fix CVE-2025-5222 libsoup-2.4: refresh CVE-2025-4969.patch libsoup-2.4: fix CVE-2025-4945 libsoup: fix CVE-2025-4945 Chen Qi (8): libnl: change HOMEPAGE qemu: back port patches to fix riscv64 build failure toolchain-shar-extract.sh: exit when post-relocate-setup.sh fails libgfortran: fix buildpath QA issue bitbake: data_smart.py: remove unnecessary ? from __expand_var_regexp__ bitbake: data_smart.py: simple clean up bitbake: data_smart.py: clear expand_cache in _setvar_update_overridevars coreutils: fix CVE-2025-5278 Chris Laplante (6): bitbake: persist_data: close connection in SQLTable __exit__ bitbake: fetch2: use persist_data context managers bitbake: ui/knotty: print log paths for failed tasks in summary bitbake: ui/knotty: respect NO_COLOR & check for tty; rename print_hyperlink => format_hyperlink bitbake: cooker: Make cooker 'skiplist' per-multiconfig/mc util-linux: use ${B} instead of ${WORKDIR}/build, to fix building under devtool Christian Taedcke (1): iptables: fix memory corruption when parsing nft rules Christos Gavros (2): ref-manual/variables.rst: document the IMAGE_ROOTFS_MAXSIZE variable ref-manual/variables.rst: document the INITRAMFS_MAXSIZE variable Claus Stovgaard (1): lib/oe/package-manager: skip processing installed-pkgs with empty globs Clayton Casciato (1): uboot-sign: fix concat_dtb arguments Colin McAllister (2): udev-extraconf: Add collect flag to mount busybox: Fix cut with "-s" flag Colin Pinnell McAllister (1): ffmpeg: fix CVE-2025-1373 Daniel Semkowicz (2): os-release: Fix VERSION_CODENAME in case it is empty gstreamer1.0-plugins-bad: fix buffer allocation fail for v4l2codecs Daniel Turull (4): package: export debugsources in PKGDESTWORK as json spdx: add option to include only compiled sources xz: ignore CVE-2024-47611 libxml2: ignore CVE-2025-8732 David Nyström (3): openssh: fix CVE-2025-61985 openssh: fix CVE-2025-61984 lz4: fix CVE-2025-62813 Deepak Rathore (1): default-distrovars.inc: Fix CONNECTIVITY_CHECK_URIS redirect issue Deepesh Varatharajan (13): binutils: stable 2.42 branch updates glibc: stable 2.39 branch updates. binutils: stable 2.42 branch update binutils: Fix CVE-2025-0840 glibc: stable 2.39 branch updates binutils: stable 2.42 branch updates binutils: Fix CVE-2025-5245 binutils: Fix CVE-2025-5244 gcc: Upgrade to GCC 13.4 binutils: stable 2.42 branch updates binutils: Fix CVE-2025-7545 glibc: stable 2.39 branch updates glibc: stable 2.39 branch updates Deepthi Hemraj (5): binutils: stable 2.42 branch updates glibc: stable 2.39 branch updates rust-llvm: Fix CVE-2024-0151 binutils: stable 2.42 branch update glibc: stable 2.39 branch updates Denys Dmytriyenko (3): weston: upgrade 13.0.0 -> 13.0.1 gcc: unify cleanup of include-fixed, apply to cross-canadian nativesdk-libtool: sanitize the script, remove buildpaths Divya Chellam (16): libpam: fix CVE-2024-10041 libxml2: Upgrade 2.12.8 -> 2.12.9 wget: fix CVE-2024-10524 vim: Upgrade 9.1.0764 -> 9.1.1043 vim: Upgrade 9.1.1043 -> 9.1.1115 ruby: fix CVE-2025-27220 ruby: fix CVE-2025-27221 screen: fix CVE-2025-46802 screen: fix CVE-2025-46804 libarchive: fix CVE-2025-5914 libarchive: fix CVE-2025-5915 libarchive: fix CVE-2025-5916 libarchive: fix CVE-2025-5917 libarchive: fix CVE-2025-5918 wpa-supplicant: fix CVE-2022-37660 vim: upgrade 9.1.1652 -> 9.1.1683 Divyanshu Rathore (1): ffmpeg: upgrade 6.1.1 -> 6.1.2 Dixit Parmar (1): ref-manual: document KERNEL_SPLIT_MODULES variable Dmitry Baryshkov (1): xserver-xorg: fix CVE-2023-5574 status Emil Kronborg (3): insane.bbclass: remove skipping of cross-compiled packages insane.bbclass: fix HOST_ variable names insane.bbclass: remove leftover variables and comment Enrico Jörns (6): wic: engine.py: use raw string for escape sequence wic: bootimg-efi: fix error handling bitbake: bitbake-diffsigs: fix handling when finding only a single sigfile ref-manual/variables.rst: update ROOT_HOME documentation conf.py: tweak SearchEnglish to be hyphen-friendly conf.py: improve SearchEnglish to handle terms with dots Erik Lindsten (1): overview-manual/yp-intro.rst: fix broken link to article Esben Haabendal (3): pulseaudio: fix webrtc audio depdency files: Amend overlayfs unit descriptions with path information files: overlayfs-create-dirs: Improve mount unit dependency Etienne Cordonnier (6): oeqa/runtime: fix regression in minidebuginfo test oeqa/runtime: make minidebuginfo test work with coreutils oeqa/runtime: fix race-condition in minidebuginfo test python3-setuptools-scm: respect GIT_CEILING_DIRECTORIES ref-manual/variables.rst: document SSTATE_SKIP_CREATION bitbake: gcp.py: remove slow calls to gsutil stat Fabio Berton (2): ccache.conf: Add include_file_ctime to sloppiness linux-libc-headers: Fix invalid conversion in cn_proc.h Florian Kreutzer (1): dropbear: backport fix for concurrent channel open/close Gassner, Tobias.ext (1): rootfs: Ensure run-postinsts is not uninstalled for read-only-rootfs-delayed-postinsts Gauthier HADERER (1): populate_sdk_ext.bclass: make sure OECORE_NATIVE_SYSROOT is exported. Guocai He (2): tcf-agent: correct the SRC_URI minicom: correct the SRC_URI Guénaël Muller (1): ref-manual: use standardized method accross both ubuntu and debian for locale install Guðni Már Gilbert (15): pam: Fix for CVE-2024-22365 python3-attrs: drop python3-ctypes from RDEPENDS bluez5: remove redundant patch for MAX_INPUT shared-mime-info: drop itstool-native from DEPENDS libpam: drop cracklib from DEPENDS systemd: drop intltool-native from DEPENDS systemd-boot: drop intltool-native from DEPENDS python3-poetry-core: drop python3-six from RDEPENDS dnf: drop python3-iniparse from DEPENDS and RDEPENDS python3: upgrade 3.12.6 -> 3.12.7 python3: upgrade 3.12.7 -> 3.12.8 systemd: upgrade 255.13 -> 255.17 systemd: upgrade 255.17 -> 255.18 bluez5: add missing tools to noinst-tools package systemd: upgrade 255.18 -> 255.21 Gyorgy Sarvari (1): conf/bitbake.conf: use gnu mirror instead of main server Haixiao Yan (2): glibc: Add single-threaded fast path to rand() buildtools-tarball: fix unbound variable issues under 'set -u' Harish Sadineni (7): binutils: Add missing perl modules to RDEPENDS for nativesdk variant rust-target-config: Fix TARGET_C_INT_WIDTH with correct size rust: fix for rust multilib sdk configuration rust: remove redundant cargo config file oeqa/sdk/context: fix for gtk3 test failure during do_testsdk binutils: Fix CVE-2025-1179 binutils: set CVE_STATUS for CVE-2025-1180 Hiago De Franco (2): weston: backport patch to allow neatvnc < v0.9.0 bluez5: backport patch to fix address type when loading keys Hitendra Prajapati (24): ghostscript: upgrade 10.02.1 -> 10.03.1 ruby: fix CVE-2024-27281 vte: fix CVE-2024-37535 curl: fix CVE-2024-8096 webkitgtk: upgrade 2.44.1 -> 2.44.3 cups: Backport fix for CVE-2024-47175 libarchive: fix CVE-2024-48957 & CVE-2024-48958 libsoup: fix CVE-2024-52532 ghostscript: upgrade 10.03.1 -> 10.04.0 libsndfile: fix CVE-2024-50612 ofono: Fix multiple CVEs libcap: fix CVE-2025-1390 elfutils: Fix multiple CVEs go: fix CVE-2025-22871 libsoup-3.4.4: Fix CVE-2025-4969 libsoup-2.4: Fix CVE-2025-4969 libxml2: fix CVE-2025-6021 libxml2: fix CVE-2025-49794 & CVE-2025-49796 libpam: fix CVE-2025-6020 gstreamer1.0-plugins-base: fix CVE-2025-47808 gstreamer1.0-plugins-base: fix CVE-2025-47806 gstreamer1.0-plugins-good: fix multiple CVEs gstreamer1.0-plugins-base: fix CVE-2025-47807 grub2: mark CVE-2024-2312 as not applicable Hongxu Jia (10): ovmf: fix CVE-2024-38796 ovmf: fix CVE-2024-1298 u-boot: fix CVE-2024-57254 u-boot: fix CVE-2024-57255 u-boot: fix CVE-2024-57256 u-boot: fix CVE-2024-57257 u-boot: fix CVE-2024-57258 u-boot: fix CVE-2024-57259 rpm: keep leading `/' from sed operation u-boot: fix CVE-2024-42040 Igor Opaniuk (1): wic: bootimg-efi: Support + symbol in filenames Jaeyoon Jung (2): makedevs: Fix issue when rootdir of / is given makedevs: Fix matching uid/gid Jagadeesh Krishnanjanappa (1): tune-cortexa32: set tune feature as armv8a Jan Vermaete (1): sdk: The main in the C example should return an int Jeroen Hofstee (2): bluez5: make media control a PACKAGECONFIG option bluez5: backport a patch to fix btmgmt -i Jiaying Song (9): liba52: fix do_fetch error enchant2: fix do_fetch error libxml-parser-perl: fix do_fetch error python3-zipp: fix CVE-2024-5569 subversion: fix CVE-2024-46901 boost: fix do_fetch error binutils: File name too long causing failure to open temporary head file in dlltool python3-requests: upgrade 2.32.3 -> 2.32.4 ruby-ptest : some ptest fixes Jinfeng Wang (3): tzdata&tzcode-native: upgrade 2024a -> 2024b mtools: upgrade 4.0.48 -> 4.0.49 systemtap: Fix task_work_cancel build Joao Marcos Costa (1): ref-manual/variables.rst: expand IMAGE_OVERHEAD_FACTOR glossary entry Joe Slater (1): oe-debuginfod: add option for data storage Joerg Schmidt (1): bitbake: bblayers/query: Fix using "removeprefix" string method Johannes Schneider (1): ppp: Revert lock path to /var/lock Jon Mason (4): oeqa/runtime/ssh: add retry logic and sleeps to allow for slower systems oeqa/runtime/ssh: check for all errors at the end oeqa/runtime/ssh: increase the number of attempts openssh: add backported header file include Jonas Gorski (1): rootfs-postcommands.bbclass: make opkg status reproducible Jookia (1): populate_sdk_ext.bbclass: Fix undefined variable error Jose Quaresma (7): go: upgrade 1.22.4 -> 1.22.5 oeqa/runtime/scp: requires openssh-sftp-server openssh: drop rejected patch fixed in 8.6p1 release openssh: systemd sd-notify patch was rejected upstream openssh: systemd notification was implemented upstream go: upgrade 1.22.5 -> 1.22.6 bitbake: bitbake: doc/user-manual: Update the BB_HASHSERVE_UPSTREAM Joshua Watt (3): bitbake: asyncrpc: Use client timeout for websocket open timeout bitbake: Remove custom exception backtrace formatting bitbake: Use a "fork" multiprocessing context João Marcos Costa (1): variables.rst: fix LAYERDEPENDS description Julien Stephan (5): README: add instruction to run Vale on a subset documentation: Makefile: add SPHINXLINTDOCS to specify subset to sphinx-lint styles: vocabularies: Yocto: add sstate ref-manual: variables: add SIGGEN_LOCKEDSIGS* variables dev-manual: add bblock documentation Jörg Sommer (5): classes/kernel: No symlink in postinst without KERNEL_IMAGETYPE_SYMLINK doc/features: remove duplicate word in distribution feature ext2 doc/features: describe distribution feature pni-name ptest-runner: Update 2.4.4 -> 2.4.5 runqemu: Fix detection of -serial parameter Kai Kang (3): multilib.bbclass: replace deprecated e.data with d cmake-qemu.bbclass: fix if criterion glibc: fix fortran header file conflict for arm Khem Raj (26): linux-yocto: Enable team net driver systemd.bbclass: Clarify error message grub,grub-efi: Remove -mfpmath=sse on x86 python3: Treat UID/GID overflow as failure gawk: Remove References to /usr/local/bin/gawk busybox: CVE-2023-42364 and CVE-2023-42365 fixes busybox: Add fix for CVE-2023-42366 gcc: Fix spurious '/' in GLIBC_DYNAMIC_LINKER on microblaze gnupg: Document CVE-2022-3219 and mark wontfix openssh: Mark CVE-2023-51767 as wont-fix libpcre2: Update base uri PhilipHazel -> PCRE2Project python3: Drop empty patch qemu: Do not define sched_attr with glibc >= 2.41 e2fsprogs: Fix build failure with gcc 15 parted: Fix build with GCC 15 bash: Stick to C17 std ncurses: Pin to C17 standard unzip: Fix build with GCC-15 m4: Stick to C17 standard gmp: Fix build with GCC15/C23 gmp: Fix build with older gcc versions gdbm: Use C11 standard unifdef: Don't use C23 constexpr keyword libtirpc: Fix build with gcc-15/C23 cpio: Pin to use C17 std expect: Fix build with GCC 15 Kirill Yatsenko (1): iptables: fix save/restore symlinks with libnftnl PACKAGECONFIG enabled Konrad Weihmann (3): runqemu: keep generating tap devices testimage: fallback for empty IMAGE_LINK_NAME testexport: fallback for empty IMAGE_LINK_NAME Kyungjik Min (1): pulseaudio: Add audio group explicitly Lee Chee Yang (24): migration-notes: add release notes for 5.0.1 migration-guides: add release notes for 4.0.19 migration-guides: add release notes for 5.0.2 migration-guide: add release notes for 4.0.20 migration-guides: add release notes for 5.0.3 migration-guide: add release notes for 4.0.21 migration-guides: add release notes for 5.0.4 migration-guide: add release notes for 4.0.22 migration-guides: add release notes for 5.0.5 migration-guides: add release notes for 4.0.23 migration-guides: add release notes for 5.0.6 migration-guides: add release notes for 4.0.24 migration-guides: add release notes for 5.0.7 migration-guides: add release notes for 4.0.25 migration-guides: add release notes for 5.0.8 migration-guides: add release notes for 4.0.26 migration-guides: add release notes for 5.0.9 migration-guides: add release notes for 4.0.27 migration-guide: add release notes for 5.0.10 migration-guides: add release notes for 4.0.28 migration-guides: add release notes for 5.0.11 migration-guides: add release notes for 4.0.29 migration-guides: add release notes for 5.0.12 migration-guides: add release notes for 4.0.30 Libo Chen (1): runqemu: fix special characters bug Louis Rannou (1): image_qa: fix error handling Macpaul Lin (1): linux-firmware: upgrade 20240312 -> 20240909 Madhu Marri (1): qemu 8.2.7: ignore CVE-2023-1386 Makarios Christakis (1): icu: Adjust ICU_DATA_DIR path on big endian targets Marco Cavallini (1): dev-manual/start.rst: added missing command in Optimize your VHDX file using DiskPart Marek Vasut (3): u-boot: kernel-fitimage: Fix dependency loop if UBOOT_SIGN_ENABLE and UBOOT_ENV enabled base-files: Drop /bin/sh dependency u-boot: kernel-fitimage: Restore FIT_SIGN_INDIVIDUAL="1" behavior Mark Hatle (9): package.py: Fix static debuginfo split package.py: Fix static library processing selftest-hardlink: Add additional test cases create-spdx-*: Support multilibs via SPDX_MULTILIB_SSTATE_ARCHS oeqa sdk cases: Skip SDK test cases when TCLIBC is newlib create-sdpx-2.2.bbclass: Switch from exists to isfile checking debugsrc populate_sdk_ext: write_local_conf add shutil import cve-update-nvd2-native: Handle BB_NO_NETWORK and missing db bitbake: bitbake: runqueue: Verify mcdepends are valid Markus Volk (3): libadwaita: update 1.5.0 -> 1.5.1 gcc: add a backport patch to fix an issue with tzdata 2024b ninja: fix build with python 3.13 Marta Rybczynska (1): vulnerabilities/classes: remove references to cve-check text format Martin Jansa (22): selftest: add Upstream-Status to .patch files libgfortran.inc: fix nativesdk-libgfortran dependencies populate_sdk_base: inherit nopackages meta-world-pkgdata: Inherit nopackages python3-lxml=v5.0.2 mc: set ac_cv_path_ZIP to avoid buildpaths QA issues libpam: re-add missing libgen include cairo: fix build with gcc-15 on host bash: use -std=gnu17 also for native CFLAGS cmake: fix build with gcc-15 on host git: fix build with gcc-15 on host pkgconfig: fix build with gcc-15 libgpg-error: fix build with gcc-15 rust-llvm: fix build with gcc-15 elfutils: fix build with gcc-15 binutils: fix build with gcc-15 dbus-glib: fix build with gcc-15 bitbake: bitbake: Bump version to 2.8.1 license.py: avoid deprecated ast.Str sanity.conf: Update minimum bitbake version to 2.8.1 lib/oe/utils: use multiprocessing from bb flex: fix build with gcc-15 on host Matthias Pritschet (1): ref-manual: fix typo and move SYSROOT_DIRS example Matthias Schiffer (1): curl: only set CA bundle in target build Michael Haener (1): oeqa/runtime/ping: don't bother trying to ping localhost Michael Halstead (4): yocto-uninative: Update to 4.6 for glibc 2.40 yocto-uninative: Update to 4.7 for glibc 2.41 yocto-uninative: Update to 4.8 for GCC 15.1 yocto-uninative: Update to 4.9 for glibc 2.42 Michael Opdenacker (5): maintainers.inc: update self e-mail address doc: Makefile: publish pdf and epub versions too dev-manual: fix styling of references to bmaptool dev-manual/bmaptool.rst: correct command for bmaptool-native dev-manual/bmaptool.rst: simplify and fix instructions Michal Seben (1): timedated: wait for jobs before SetNTP response Mikko Rapeli (1): ovmf-native: remove .pyc files from install Mingli Yu (1): llvm: Enable libllvm for native build Moritz Haase (2): meta: Enable '-o pipefail' for the SDK installer cmake: Correctly handle cost data of tests with arbitrary chars in name NeilBrown (1): nfs-utils: don't use signals to shut down nfs server. Nguyen Dat Tho (1): libatomic-ops: Update GITHUB_BASE_URI Nikhil R (1): cmake: Add PACKAGECONFIG option for debugger support Niko Mauno (15): dnf/mesa: Fix missing leading whitespace with ':append' libyaml: Fix warning regarding unpatched CVE systemd: Mitigate /var/log type mismatch issue systemd: Mitigate /var/tmp type mismatch issue image_types.bbclass: Use --force also with lz4,lzop util-linux: Add PACKAGECONFIG option to mitigate rootfs remount error iw: Fix LICENSE dejagnu: Fix LICENSE unzip: Fix LICENSE zip: Fix LICENSE tiff: Fix LICENSE gcr: Fix LICENSE python3-maturin: Fix cross compilation issue for armv7l, mips64, ppc cve-check.bbclass: Mitigate symlink related error cve-check.bbclass: Fix symlink handling also for text files Nitin Wankhade (1): examples: genl: fix wrong attribute size Oleksandr Hnatiuk (2): icu: remove host references in nativesdk to fix reproducibility gcc: remove paths to sysroot from configargs.h and checksum-options for gcc-cross-canadian Patrick Wicki (1): gpgme: move gpgme-tool to own sub-package Paul Barker (2): meta-ide-support: Mark recipe as MACHINE-specific dev-manual, test-manual: Update autobuilder output links Paul Gerber (1): uboot-sign: fix counters in do_uboot_assemble_fitimage Pavel Zhukov (1): package_rpm: Check if file exists before open() Pedro Ferreira (3): buildhistory: Fix intermittent package file list creation buildhistory: Restoring files from preserve list rust-common.bbclass: soft assignment for RUSTLIB path Peter Kjellerstedt (1): image.bbclass: Drop support for ImageQAFailed exceptions in image_qa Peter Marko (144): flac: fix buildpaths warnings cargo: remove True option to getVar calls ncurses: switch to new mirror busybox: Patch CVE-2021-42380 busybox: Patch CVE-2023-42363 libstd-rs,rust-cross-canadian: set CVE_PRODUCT to rust curl: Patch CVE-2024-6197 glibc: cleanup old cve status qemu: set cve status for CVE-2023-6683 libmnl: explicitly disable doxygen libyaml: ignore CVE-2024-35326 libyaml: Ignore CVE-2024-35325 curl: Patch CVE-2024-7264 python3: Upgrade 3.12.5 -> 3.12.6 wpa-supplicant: Ignore CVE-2024-5290 wpa-supplicant: Patch CVE-2024-3596 wpa-supplicant: Patch security advisory 2024-2 rust: ignore CVE-2024-43402 openssl: patch CVE-2024-9143 cve-check: add support for cvss v4.0 go: upgrade 1.22.6 -> 1.22.7 go: upgrade 1.22.7 -> 1.22.8 dropbear: backport patch for CVE-2023-48795 curl: patch CVE-2024-9681 gstreamer1.0: set status for CVE-2024-0444 expat: upgrade 2.6.3 -> 2.6.4 builder: set CVE_PRODUCT qemu: set CVE-2024-6505 to fixed gstreamer1.0-plugins-good: fix several CVEs gstreamer1.0-plugins-base: patch CVE-2024-47538 gstreamer1.0-plugins-base: patch CVE-2024-47607 gstreamer1.0-plugins-base: patch CVE-2024-47615 gstreamer1.0-plugins-good: patch CVE-2024-47613 gstreamer1.0-plugins-good: patch several CVEs gstreamer1.0-plugins-base: patch CVE-2024-47541 gstreamer1.0-plugins-base: patch CVE-2024-47542 gstreamer1.0-plugins-good: patch CVE-2024-47599 gstreamer1.0-plugins-base: patch CVE-2024-47600 gstreamer1.0-plugins-good: patch CVE-2024-47606 gstreamer1.0-plugins-good: patch CVE-2024-47606 gstreamer1.0-plugins-good: patch CVE-2024-47774 gstreamer1.0-plugins-good: patch several CVEs gstreamer1.0-plugins-base: patch CVE-2024-47835 gstreamer1.0: ignore CVEs fixed in plugins recipes socat: patch CVE-2024-54661 ofono: patch CVE-2024-7540, CVE-2024-7541, CVE-2024-7542 ofono: patch CVE-2023-4232 ofono: patch CVE-2023-4235 openssl: patch CVE-2024-13176 go: upgrade 1.22.8 -> 1.22.9 go: upgrade 1.22.9 -> 1.22.10 go: upgrade 1.22.10 -> 1.22.11 glibc: stable 2.39 branch updates python3: upgrade 3.12.8 -> 3.12.9 go: upgrade 1.22.11 -> 1.22.12 cmake: apply parallel build settings to ptest tasks subversion: ignore CVE-2024-45720 gnutls: patch CVE-2024-12243 openssl: upgrade 3.2.3 -> 3.2.4 libxml2: upgrade 2.12.9 -> 2.12.10 grub: drop obsolete CVE statuses grub: backport strlcpy function grup: patch CVE-2024-45781 grub: patch CVE-2024-45782 and CVE-2024-56737 grub: patch CVE-2024-45780 grub: patch CVE-2024-45783 grub: patch CVE-2025-0624 grub: patch CVE-2024-45774 grub: patch CVE-2024-45775 grub: patch CVE-2025-0622 grub: patch CVE-2024-45776 grub: patch CVE-2024-45777 grub: patch CVE-2025-0690 grub: patch CVE-2025-1118 grub: patch CVE-2024-45778 and CVE-2024-45779 grub: patch CVE-2025-0677, CVE-2025-0684, CVE-2025-0685, CVE-2025-0686 and CVE-2025-0689 grub: patch CVE-2025-0678 and CVE-2025-1125 libarchive: patch CVE-2025-1632 and CVE-2025-25724 xserver-xorg: mark CVEs fixed in 21.1.16 as fixed cve-update-nvd2-native: handle missing vulnStatus expat: patch CVE-2024-8176 freetype: follow-up patch for CVE-2025-27363 ofono: patch CVE-2024-7537 cve-update-nvd2-native: add workaround for json5 style list xz: upgrade 5.4.6 -> 5.4.7 xz: patch CVE-2025-31115 libarchive: upgrade 3.7.4 -> 3.7.9 sqlite3: patch CVE-2025-3277 sqlite3: patch CVE-2025-29088 ppp: patch CVE-2024-58250 libxml2: patch CVE-2025-32414 libxml2: patch CVE-2025-32415 glib-2.0: patch CVE-2025-3360 Revert "cve-update-nvd2-native: Tweak to work better with NFS DL_DIR" sqlite3: mark CVE-2025-29087 as patched python3: upgrade 3.12.9 -> 3.12.11 testimage: get real os-release file net-tools: patch CVE-2025-46836 go: set status of CVE-2024-3566 glibc: stable 2.39 branch updates python3: update CVE product busybox: apply patch for CVE-2023-39810 iputils: patch CVE-2025-48964 orc: set CVE_PRODUCT openssl: CVE-2024-41996 openssl: patch CVE-2025-27587 gnutls: patch CVE-2025-32989 gnutls: patch read buffer overrun in the "pre_shared_key" extension gnutls: patch reject zero-length version in certificate request gnutls: patch CVE-2025-32988 gnutls: patch CVE-2025-32990 gnutls: patch CVE-2025-6395 ncurses: patch CVE-2025-6141 libxml2: patch CVE-2025-6170 glibc: fix CVE-2025-8058 python3: patch CVE-2025-8194 go: ignore CVE-2025-0913 dropbear: patch CVE-2025-47203 glib-2.0: ignore CVE-2025-4056 qemu: set status of CVE-2024-7730 to fixed go-binary-native: ignore CVE-2025-0913 glib-2.0: patch CVE-2025-7039 glib-2.0: patch CVE-2025-6052 dpkg: patch CVE-2025-6297 libarchive: patch regression of patch for CVE-2025-5918 vim: upgrade 9.1.1198 -> 9.1.1652 sudo: remove devtool FIXME comment busybox: patch CVE-2025-46394 gstreamer1.0: ignore CVEs fixed in plugins gstreamer1.0: ignore CVE-2025-2759 ghostscript: patch CVE-2025-59798 ghostscript: patch CVE-2025-59799 ghostscript: patch CVE-2025-59800 expat: follow-up for CVE-2024-8176 tiff: ignore 5 CVEs ffmpeg: ignore 8 CVEs fixed in 6.1.1 and 6.1.3 releases openssl: upgrade 3.2.4 -> 3.2.6 qemu: patch CVE-2024-8354 binutils: patch CVE-2025-11082 binutils: patch CVE-2025-11083 gnupg: mark CVE-2025-30258 as patched python3: upgrade 3.12.11 -> 3.12.12 vulnerabilities: update nvdcve file name expat: patch CVE-2025-59375 Philip Lorenz (3): cmake: Fix sporadic issues when determining compiler internals cve-check: Add missing call to exit_if_errors shared-mime-info: Handle USE_NLS Poonam Jadhav (2): curl: ignore CVE-2025-0725 libpng: Add ptest Praveen Kumar (7): connman :fix CVE-2025-32743 connman :fix CVE-2025-32366 glib-2.0: fix CVE-2025-4373 go: fix CVE-2025-4673 sudo: upgrade 1.9.15p5 -> 1.9.17p1 go: fix CVE-2025-47907 bind: upgrade 9.18.33 -> 9.18.41 Preeti Sachan (1): ltp: backport patch to fix compilation error for x86_64 Priyal Doshi (2): tzdata/tzcode-native: upgrade 2024b -> 2025a tzdata/tzcode-native: upgrade 2025a -> 2025b Purushottam Choudhary (1): virglrenderer: Add patch to fix -int-conversion build issue Quentin Schulz (14): mmc-utils: fix URL weston-init: fix weston not starting when xwayland is enabled docs: README: specify how to contribute instead of pointing at another file docs: conf.py: silence SyntaxWarning on js_splitter_code ref-manual: classes: reword to clarify that native/nativesdk options are exclusive ref-manual: classes: nativesdk: move note to appropriate section go-helloworld: fix license contributor-guide: submit-changes: fix improper bold string contributor-guide: submit-changes: clarify example with Yocto bug ID contributor-guide: submit-changes: align CC tag description contributor-guide: submit-changes: make the Cc tag follow kernel guidelines contributor-guide: submit-changes: reword commit message instructions contributor-guide: submit-changes: number instruction list in commit your changes contributor-guide: submit-changes: make "Crediting contributors" part of "Commit your changes" Rajeshkumar Ramasamy (2): glib-networking: fix CVE-2025-60018 glib-networking: fix CVE-2025-60019 Randy MacLeod (1): systemd: stable update 255.4 -> 255.13 Ranjitsinh Rathod (1): rust: Add new varaible RUST_ENABLE_EXTRA_TOOLS Rasmus Villemoes (1): iptables: remove /etc/ethertypes Regis Dargent (1): udev-extraconf: fix network.sh script did not configure hotplugged interfaces Richard Purdie (60): selftest/cases/runtime_test: Exclude centos-9 from virgl tests cve-exclusion: Drop the version comparision/warning bitbake: codeparser/data: Ensure module function contents changing is accounted for bitbake: codeparser: Skip non-local functions for module dependencies pseudo: Update to pull in python 3.12+ fix layer.conf: Add os-release to SIGGEN_EXCLUDERECIPES_ABISAFE oeqa/sdk/case: Ensure DL_DIR is populated with artefacts if used create-spdx-3.0/populate_sdk_base: Add SDK_CLASSES inherit mechanism to fix tarball SPDX manifests pseudo: Fix to work with glibc 2.40 pseudo: Update to include open symlink handling bugfix nasm: Upgrade 2.16.01 -> 2.16.03 oeqa/runtime/ssh: In case of failure, show exit code and handle -15 (SIGTERM) oeqa/selftest/reproducibile: Explicitly list virtual targets expat: 2.6.2 -> 2.6.3 ruby: Make docs generation deterministic libedit: Make docs generation deterministic buildhistory: Simplify intercept call sites and drop SSTATEPOSTINSTFUNC usage scripts/install-buildtools: Update to 5.0.3 bitbake.conf: Add truncate to HOSTTOOLS license: Fix directory layout issues libsdl2: Fix non-deterministic configure option for libsamplerate bitbake: tests/fetch: Use our own mirror of sysprof to decouple from gnome gitlab bitbake: tests/fetch: Use our own mirror of mobile-broadband-provider to decouple from gnome gitlab cve_check: Use a local copy of the database during builds pseudo: Fix envp bug and add posix_spawn wrapper oeqa/runtime/ssh: Rework ssh timeout oeqa/runtime/ssh: Fix incorrect timeout fix qemurunner: Clean up serial_lock handling bitbake: fetch2/git: Use quote from shlex, not pipes bitbake: fetch/wget: Increase timeout to 100s from 30s bitbake: runqueue: Fix performance of multiconfigs with large overlap bitbake: runqueue: Optimise setscene loop processing bitbake: runqueue: Fix scenetask processing performance issue do_package/sstate/sstatesig: Change timestamp clamping to hash output only selftest/reproducible: Drop rawlogs selftest/reproducible: Clean up pathnames resulttool: Allow store to filter to specific revisions resulttool: Use single space indentation in json output oeqa/utils/gitarchive: Return tag name and improve exclude handling resulttool: Fix passthrough of --all files in store mode resulttool: Add --logfile-archive option to store mode resulttool: Handle ltp rawlogs as well as ptest resulttool: Clean up repoducible build logs resulttool: Trim the precision of duration information resulttool: Improve repo layout for oeselftest results cve-update-nvd2-native: Tweak to work better with NFS DL_DIR bitbake: tests/fetch: Fix git shallow test failure with git >= 2.48 bitbake: utils: Print information about lock issue before exiting bitbake: utils: Tweak lock_timeout logic bitbake: utils: Add signal blocking for lock_timeout bitbake: event/utils: Avoid deadlock from lock_timeout() and recursive events bitbake: toaster/tests/buildtest: Switch to new CDN bitbake: fetch2: Avoid deprecation warning sstatetests: Switch to new CDN local.conf.sample: Switch to new CDN bitbake: ast: Change deferred inherits to happen per recipe brief-yoctoprojectqs/ref-manual: Switch to new CDN bitbake: test/fetch: Switch u-boot based test to use our own mirror mtools: upgrade 4.0.46 -> 4.0.47 bitbake: utils: Optimise signal/sigmask performance Robert Kovacsics (1): sdk: Fix path length limit to match reserved size Robert P. J. Day (7): Clean up explanation of minimum required version numbers overview-manual: small number of pedantic cleanups bsp guide: update kernel version example to 6.12 bsp-guide: update lonely "4.12" kernel reference to "6.12" bsp-guide: update all of section 1.8.2 to reflect current beaglebone conf file variables.rst: remove references to obsolete tar packaging overview-manual/yp-intro.rst: update on-target packaging info Robert Yang (7): bitbake: data_smart: Improve performance for VariableHistory release-notes-5.0.rst: NO_OUTPUT -> NO_COLOR bitbake: gitsm: Add call_process_submodules() to remove duplicated code bitbake: gitsm: Remove downloads/tmpdir when failed cml1.bbclass: do_diffconfig: Don't override .config with .config.orig libgcrypt: Fix building error with '-O2' in sysroot path groff: Fix race issues for parallel build Rogerio Guerra Borin (1): u-boot: ensure keys are generated before assembling U-Boot FIT image Rohini Sangam (1): vim: Upgrade 9.1.0698 -> 9.1.0764 Roland Kovacs (3): gnupg: update 2.4.5 -> 2.4.8 libxml2: fix CVE-2025-49795 sqlite3: fix CVE-2025-6965 Ross Burton (31): cpio: mark CVE-2023-7216 as disputed fribidi: upgrade 1.0.13 -> 1.0.14 gstreamer1.0: skip another known flaky test libportal: fix rare build race meson: don't use deprecated pkgconfig variable curl: skip FTP tests in run-ptest gawk: update patch status python3-pycryptodome(x): use python_setuptools_build_meta build class gstreamer1.0: disable flaky baseparser tests librsvg: don't try to run target code at build time icu: update patch Upstream-Status strace: download release tarballs from GitHub tcl: skip io-13.6 test case groff: fix rare build race in hdtbl sanity: check for working user namespaces python3: add dependency on -compression to -core classes/nativesdk: also override TUNE_PKGARCH classes/qemu: use tune to select QEMU_EXTRAOPTIONS, not package architecture oeqa/selftest/rust: skip on all MIPS platforms Remove all mention of core-image-lsb ref-manual: don't refer to poky-lsb ref-manual: remove OE_IMPORTS puzzles: ignore three new CVEs for a different puzzles xserver-xf86-config: add a configuration fragment to disable screen blanking xserver-xf86-config: remove obsolete configuration files grub2: fix CVE-2024-56738 libxslt: apply patch for CVE-2025-7424 expect: update code for Tcl channel implementation expect: don't run aclocal in do_configure expect: cleanup do_install pulseaudio: ignore CVE-2024-11586 Ryan Eatmon (2): u-boot.inc: Refactor do_* steps into functions that can be overridden uboot: Allow for customizing installed/deployed file names Sana Kazi (1): gcc-cross-canadian.inc: Fix buildpaths error for pthread.h Sandeep Gundlupet Raju (1): tune-cortexr52: Remove aarch64 for ARM Cortex-R52 Saravanan (2): python3-xmltodict: fix CVE-2025-9375 cmake: fix CVE-2025-9301 Savvas Etairidis (1): systemd: Rename systemd_v255.21 to systemd_255.21 Sergei Zhmylev (1): lsb-release: fix Distro Codename shell escaping Shubham Kulkarni (1): libpam: Update fix for CVE-2024-10041 Shunsuke Tokumoto (1): python3-setuptools: Add "python:setuptools" to CVE_PRODUCT Siddharth Doshi (5): Tiff: Security fix for CVE-2024-7006 vim: Upgrade 9.1.0114 -> 9.1.0682 wpa-supplicant: Upgrade 2.10 -> 2.11 vim: Upgrade 9.1.0682 -> 9.1.0698 openssl: Upgrade 3.2.2 -> 3.2.3 Simon A. Eugster (1): documentation: Fix typo in standards.md Simone Weiß (3): tzdata: Add tzdata.zi to tzdata-core package sanity: Check if tar is gnutar curl: Ignore CVE-2024-32928 Soumya Sambu (12): python3-idna: upgrade 3.6 -> 3.7 python3-certifi: Fix CVE-2024-39689 python3-setuptools: Fix CVE-2024-6345 python3: Fix CVE-2024-7592 python3: Fix CVE-2024-8088 python3-requests: upgrade 2.32.1 -> 2.32.2 python3-requests: upgrade 2.32.0 -> 2.32.3 python3-jinja2: upgrade 3.1.4 -> 3.1.6 git: Upgrade 2.44.1 -> 2.44.3 elfutils: Fix CVE-2025-1371 elfutils: Fix CVE-2025-1376 elfutils: Fix CVE-2025-1377 Stanislav Vovk (1): libpam: fix CVE-2024-10963 Stefan Mueller-Klieser (1): kernel-arch: add macro-prefix-map in KERNEL_CC Steve Sakoman (35): Revert "apt: runtime error: filename too long (tmpdir length)" poky.conf: bump version for 5.0.3 build-appliance-image: Update to scarthgap head revision Revert "wpa-supplicant: Upgrade 2.10 -> 2.11" poky.conf: bump version for 5.0.4 build-appliance-image: Update to scarthgap head revision build-appliance-image: Update to scarthgap head revision release-notes-4.0: update BB_HASHSERVE_UPSTREAM for new infrastructure poky.conf: bump version for 5.0.5 build-appliance-image: Update to scarthgap head revision webkitgtk: fix erroneous use of unsuported DEBUG_LEVELFLAG variable llvm: reduce size of -dbg package poky.conf: bump version for 5.0.6 build-appliance-image: Update to scarthgap head revision poky.conf: bump version for 5.0.7 build-appliance-image: Update to scarthgap head revision Revert "rust: Add new varaible RUST_ENABLE_EXTRA_TOOLS" build-appliance-image: Update to scarthgap head revision poky.conf: add ubuntu2404 to SANITY_TESTED_DISTROS poky.conf: bump version for 5.0.8 build-appliance-image: Update to scarthgap head revision Revert "gcc-cross-canadian.inc: Fix buildpaths error for pthread.h" poky.conf: bump version for 5.0.9 build-appliance-image: Update to scarthgap head revision poky.conf: bump version for 5.0.10 build-appliance-image: Update to scarthgap head revision poky.conf: bump version for 5.0.11 build-appliance-image: Update to scarthgap head revision Revert "sudo: Fix CVE-2025-32462" poky.conf: bump version for 5.0.12 build-appliance-image: Update to scarthgap head revision selftest/cases/meta_ide.py: use use gnu mirror instead of main server oeqa/sdk/cases/buildcpio.py: use gnu mirror instead of main server poky.conf: bump version for 5.0.13 build-appliance-image: Update to scarthgap head revision Sunil Dora (2): gcc: Fix c++: tweak for Wrange-loop-construct binutils: Fix CVE-2025-1153 Talel BELHAJ SALEM (1): dev-manual/building.rst: add note about externalsrc variables absolute paths Talel BELHAJSALEM (1): contributor-guide: Remove duplicated words Teresa Remmet (1): recipes-bsp: usbutils: Fix usb-devices command using busybox Trevor Gamblin (7): python3: skip test_concurrent_futures/test_deadlock python3: skip test_multiprocessing/test_active_children test maintainers.inc: add self for unassigned python recipes python3: upgrade 3.12.4 -> 3.12.5 python3: skip readline limited history tests python3-urllib3: upgrade 2.2.1 -> 2.2.2 reproducible-builds.rst: show how to build a single package Trevor Woerner (5): contributor-guide/submit-changes: encourage patch version changelogs ref-manual/variables.rst: document WIC_CREATE_EXTRA_ARGS sphinx-lint: trailing whitespace sphinx-lint: missing space after literal sphinx-lint: unbalanced inline literal markup Ulrich Ölmann (1): initramfs-framework: fix typos Victor Giraud (1): busybox: fix CVE-2022-48174 Victor Kamensky (1): systemtap: fix systemtap-native build error on Fedora 40 Vijay Anusuri (44): openssh: fix CVE-2024-39894 apr: upgrade 1.7.4 -> 1.7.5 libpcap: Security fix for CVE-2023-7256 & CVE-2024-8006 xserver-xorg: upgrade 21.1.13 -> 21.1.14 glib-2.0: Backport fix for CVE-2024-52533 bind: Upgrade 9.18.28 -> 9.18.33 openssh: Fix CVE-2025-26466 xwayland: Fix CVE-2024-9632 xwayland: Fix CVE-2025-26594 xwayland: Fix CVE-2025-26595 xwayland: Fix CVE-2025-26596 xwayland: Fix CVE-2025-26597 xwayland: Fix CVE-2025-26598 xwayland: Fix CVE-2025-26599 xwayland: Fix CVE-2025-26600 xwayland: Fix CVE-2025-26601 libtasn1: upgrade 4.19.0 -> 4.20.0 xserver-xorg: upgrade 21.1.15 -> 21.1.16 libxslt: upgrade 1.1.39 -> 1.1.43 vim: Upgrade 9.1.1115 -> 9.1.1198 libsoup: Fix CVE-2025-32910 libsoup: Fix CVE-2025-32909 libsoup: Fix CVE-2025-32911 & CVE-2025-32913 libsoup: Fix CVE-2025-32912 libsoup: Fix CVE-2025-32906 libsoup-2.4: Fix CVE-2024-52530 libsoup-2.4: Fix CVE-2024-52531 libsoup-2.4: Fix CVE-2024-52532 libsoup-2.4: Fix CVE-2025-32906 libsoup-2.4: Fix CVE-2025-32909 libsoup: Fix CVE-2025-32914 openssh: Fix for CVE-2025-32728 libsoup-2.4: Fix CVE-2025-32910 libsoup-2.4: Fix CVE-2025-32911 & CVE-2025-32913 libsoup-2.4: Fix CVE-2025-32912 libsoup-2.4: Fix CVE-2025-32914 python3-setuptools: Fix CVE-2025-47273 kea: upgrade 2.4.1 -> 2.4.2 sudo: Fix CVE-2025-32462 git: Upgrade 2.44.3 -> 2.44.4 xserver-xorg: upgrade 21.1.6 -> 21.1.18 cups: upgrade 2.4.10 -> 2.4.11 cups: Fix for CVE-2025-58060 and CVE-2025-58364 gstreamer1.0-plugins-bad: Fix CVE-2025-3887 Virendra Thakur (3): rust-cross-canadian: Set CVE_STATUS ignore for CVE-2024-43402 util-linux: Add fix to isolate test fstab entries using CUSTOM_FSTAB curl: set conditional CVE_STATUS for CVE-2025-5025 Vishwas Udupa (1): openssl: rewrite ptest installation Vrushti Dabhi (1): curl: update CVE_STATUS for CVE-2025-5025 Vyacheslav Yurkov (1): systemd: Password agents shouldn't be optional Wadim Egorov (1): watchdog: Set watchdog_module in default config Wang Mingyu (18): ed: upgrade 1.20.1 -> 1.20.2 llvm: upgrade 18.1.5 -> 18.1.6 mesa: upgrade 24.0.5 -> 24.0.7 wireless-regdb: upgrade 2024.01.23 -> 2024.05.08 orc: upgrade 0.4.38 -> 0.4.39 cups: upgrade 2.4.9 -> 2.4.10 libadwaita: upgrade 1.5.1 -> 1.5.2 libdnf: upgrade 0.73.1 -> 0.73.2 wireless-regdb: upgrade 2024.05.08 -> 2024.07.04 cryptodev: upgrade 1.13 -> 1.14 orc: upgrade 0.4.39 -> 0.4.40 wireless-regdb: upgrade 2024.07.04 -> 2024.10.07 gnupg: upgrade 2.4.4 -> 2.4.5 xserver-xorg: upgrade 21.1.14 -> 21.1.15 ghostscript: upgrade 10.05.0 -> 10.05.1 mtools: upgrade 4.0.44 -> 4.0.45 mtools: upgrade 4.0.45 -> 4.0.46 mtools: upgrade 4.0.47 -> 4.0.48 Weisser, Pascal (1): ref-manual: Add missing variable IMAGE_ROOTFS_MAXSIZE Weisser, Pascal.ext (1): qemuboot: Trigger write_qemuboot_conf task on changes of kernel image realpath Xiangyu Chen (2): qemu: Upgrade 8.2.1 -> 8.2.2 lttng-modules: fix sched_stat_runtime changed in Linux 6.6.66 Yash Shinde (4): binutils: Fix CVE-2024-53589 binutils: Fix CVE-2025-7546 binutils: fix CVE-2025-11081 binutils: fix CVE-2025-8225 Yi Zhao (5): libcap-ng: upgrade 0.8.4 -> 0.8.5 libcap-ng-python: upgrade 0.8.4 -> 0.8.5 rpm: fix expansion of %_libdir in macros iputils: Security fix for CVE-2025-47268 kea: set correct permissions for /var/run/kea Yogita Urade (10): qemu: upgrade 8.2.2 -> 8.2.3 qemu: fix CVE-2024-4467 ruby: upgrade 3.2.2 -> 3.3.5 qemu: upgrade 8.2.3 -> 8.2.7 curl: fix CVE-2024-11053 curl: fix CVE-2025-0167 python3-urllib3: fix CVE-2025-50181 curl: fix CVE-2025-9086 tiff: fix CVE-2025-9900 tiff: ignore CVE-2025-8961 Zhang Peng (3): avahi: fix CVE-2024-52616 mpg123: upgrade 1.32.6 -> 1.32.10 avahi: fix CVE-2024-52615 aszh07 (3): xz: Update LICENSE variable for xz packages ffmpeg: Add "libswresample libavcodec" to CVE_PRODUCT libarchive: Fix CVE-2024-20696 rajmohan r (1): glibc-y2038-tests: remove glibc-y2038-tests_2.39.bb recipe meta-openembedded: 78a14731cf..15e18246dd: Adrian Freihofer (2): networkmanager: remove modemmanager rdepends thrift: fix build with gcc 15 Alexandre Truong (4): source-han-sans-*-fonts: Switch away from SVN fetcher in SRC_URI lcov: include UPSTREAM_CHECK_* to fix UNKNOWN_BROKEN status hunspell-dictionaries: switch branch from master to main evince: Update status for CVE-2011-0433 and CVE-2011-5244 Alexandre Videgrain (1): openbox: fix crash on alt+tab with fullscreen app AmateurECE (1): pipewire: Add glib-2.0-native dep for bluez5 Andrej Valek (1): externalsrc: fix support in various components Anil Dongare (1): libssh 0.10.6: Fix CVE-2025-8114 Ankur Tyagi (25): tinyproxy: patch CVE-2023-49606 frr: patch CVE-2024-44070 libavif: ignore CVE-2025-48175 libconfuse: patch CVE-2022-40320 hdf5: patch CVE-2025-2913 hdf5: patch CVE-2025-2914 hdf5: patch CVE-2025-2915 hdf5: patch CVE-2025-2923, CVE-2025-6816, CVE-2025-6856 hdf5: patch CVE-2025-2924 hdf5: patch CVE-2025-2925 hdf5: patch CVE-2025-6269, CVE-2025-6270, CVE-2025-6516 libppd: patch CVE-2024-47175 libcupsfilters: patch CVE-2024-47076 libraw: patch CVE-2025-43961 CVE-2025-43962 libraw: patch CVE-2025-43963 libraw: patch CVE-2025-43964 zlog: fix CVE-2024-22857 memcached: patch CVE-2023-46852 memcached: patch CVE-2023-46853 ndpi: ignore CVE-2025-25066 libiec61850: patch CVE-2024-26529 libiec61850: patch CVE-2024-45970 libiec61850: patch CVE-2024-45971 mbedtls: upgrade 3.6.4 -> 3.6.5 hostapd: patch CVE-2025-24912 Archana Polampalli (4): modejs: upgrade 20.18.0 -> 20.18.2 tftpy: fix CVE-2023-46566 tcpreplay: fix CVE-2024-22654 apache2: upgrade 2.4.64 - 2.4.65 Ariel D'Alessandro (1): pipewire: Install missing ALSA config files Armin Kuster (1): Revert "mariadb: fix runtime failure on riscv" Ashish Sharma (2): nginx: Backport fix for CVE-2024-7347 postgresql: Backport fix for CVE-2024-7348 AshishKumar Mishra (1): meta-oe: image: optionally remove RAW image after sparse image creation Awais Belal (2): mongodb: fix build with python 3.12 mongodb: update to 4.4.29 BINDU (1): flatbuffers: adapt for cross-compilation environments Barry Grussling (1): postgresql: Break perl RDEPENDS Bastian Krause (2): libsocketcan: use https instead of git protocol canutils: use https instead of git protocol Benjamin Szőke (1): tree: fix broken links Changqing Li (11): pavucontrol: update SRC_URI libatasmart: Update SRC_URI mariadb: fix runtime failure on riscv dlt-daemon: make DLT_WatchdogSec configurable abseil-cpp: upgrade 20240116.2 -> 20240116.3 nginx: fix CVE-2025-23419 libblockdev: fix CVE-2025-6019 udisks2: Hardening measure of CVE-2025-6019 phpmyadmin: upgrade 5.2.1 -> 5.2.2 luajit: fix several CVEs mariadb: correct STACK_DIRECTION setting Chen Qi (6): libdbd-mysql-perl: avoid invoking assert_lib at do_configure stage python3-protobuf: remove useless and problematic .pth file graphviz: remove obsolete and problematic patch protobuf: fix CVE-2024-7254 protobuf: upgrade from 4.25.3 to 4.25.8 python3-protobuf: upgrade from 4.25.3 to 4.25.8 Chris Laplante (1): poco: fix branch: master => poco-1.12.5 Christos Gavros (1): corosync: reproducibility issue Claus Stovgaard (2): lcov: sort RDEPENDS alphabetical lcov: Add missing RDEPENDS Clayton Casciato (1): chrony: use inherit_defer for conditional inherit of useradd Deepak Rathore (1): protobuf 4.25.8: Mark CVE-2024-7254 as patched Divya Chellam (7): nginx: upgrade 1.25.3 -> 1.25.4 redis: upgrade 7.2.6 -> 7.2.7 krb5: fix CVE-2025-24528 openvpn: upgrade 2.6.12 -> 2.6.14 libssh: fix CVE-2025-4878 libssh: fix CVE-2025-5987 jq: fix CVE-2025-9403 Dmitry Baryshkov (1): android-tools: Create flag file /etc/usb-debugging-enabled Esben Haabendal (1): netplan: add missing runtime dependencies Etienne Cordonnier (3): uutils-coreutils: upgrade 0.0.25 -> 0.0.26 uutils-coreutils: upgrade 0.0.26 -> 0.0.27 uutils-coreutils: fix compilation with selinux Fabrice Aeschbacher (1): mosquitto: upgrade 2.0.18 -> 2.0.19 Fathi Boudra (2): python3-django: upgrade 4.2.11 -> 4.2.16 python3-django: upgrade 5.0.4 -> 5.0.9 Frank de Brabander (3): python3-pydantic-core: fix incompatible version python3-pydantic-core: fix TMPDIR path reference python3-pydantic-core: add missing RDEPENDS for ptest Grygorii Tertychnyi (1): libusbgx: fix gadget-stop install Guocai He (6): python3-pylint: correct the SRC_URI libconfig: correct the SRC_URI logcheck: correct the SRC_URI thrift: correct the SRC_URI softhsm: correct the SRC_URI mariadb: File conflicts for multilib Guðni Már Gilbert (1): mbedtls: upgrade 3.6.3.1 -> 3.6.4 Gyorgy Sarvari (35): poppler: fix typos in CVE-2025-52886-0001.patch mod-dnssd: update SRC_URI mosh: set working SRC_URI psqlodbc: set valid SRC_URI collectd: set working SRC_URI apache2: ignore irrelevant CVEs civetweb: patch CVE-2025-55763 dovecot: patch CVE-2022-30550 pm-qa: update git fetch protocol tokyocabinet: switch to working SRC_URI tokyocabinet: fix license iperf2: ignore irrelevant CVEs jasper: patch CVE-2025-8835 jasper: patch CVE-2025-8836 jasper: patch CVE-2025-8837 etcd: patch CVE-2023-32082 freerdp3: patch CVE-2024-32039 and CVE-2024-32041 freerdp3: patch CVE-2024-32040 freerdp3: patch CVE-2024-32458 freerdp3: patch CVE-2024-32459 freerdp3: patch CVE-2024-32460 freerdp3: patch CVE-2024-32658 freerdp3: patch CVE-2025-32659 freerdp3: patch CVE-2024-32660 freerdp3: patch CVE-2024-32661 freerdp3: patch CVE-2024-32662 exiv2: patch CVE-2025-26623 exiv2: patch CVE-2025-54080 exiv2: patch CVE-2025-55304 redis: upgrade 6.2.18 -> 6.2.20 emacs: patch CVE-2024-30202 emacs: patch CVE-2024-30203 emacs: patch CVE-2024-30204 emacs: patch CVE-2024-30205 emacs: patch CVE-2024-39331 Haixiao Yan (4): openvpn: fix CVE-2024-28882 openvpn: upgrade 2.6.10 -> 2.6.12 lmsensors: Clean stale files for sensord to avoid incorrect GCC header dependencies python3-posix-ipc: fix runtime error Harish Sadineni (1): bpftool: Add support for riscv64 Hieu Van Nguyen (1): gphoto2: Fix contains reference to TMPDIR [buildpaths] warning Hitendra Prajapati (8): tgt: fix CVE-2024-45751 libssh: fix CVE-2025-5318 redis: fix CVE-2025-32023 libssh: fix CVE-2025-5351 & CVE-2025-5372 open-vm-tools: fix CVE-2025-22247 libssh: fix CVE-2025-4877 openjpeg: fix for CVE-2025-54874 libjxl: fix CVE-2024-11403 & CVE-2024-11498 Hongxu Jia (1): nodejs: support cross compile without qemu user conditionally J. S (2): nodejs: upgrade 20.16.0 -> 20.17.0 nodejs: upgrade 20.17.0 -> 20.18.0 J. S. (3): znc: Fix buildpaths QA errors nodejs: cleanup xfce4 update HOMEPAGEs Jan Vermaete (1): python3-werkzeug: added python3-difflib as RDEPENDS Jason Schonberg (1): nodejs: upgrade 20.13.0 -> 20.16.0 Jef Driesen (2): nginx: fix the tarball and license checksums lcov: Add missing RDEPENDS for nativesdk Jeroen Hofstee (5): nodejs: backport a patch to prevent brotli crashing nodejs can-utils: fix printing / reading timestamps can-utils: handle CAN_ERR_CNT correctly php: ignore CVE-2024-3566 nodejs: ignore CVE-2024-3566 Jeroen Knoops (1): nng: Rename default branch of github.com:nanomsg/nng.git Jiaying Song (15): rrdtool: Fix do_populate_sysroot QA issues nftables: change ptest output format debootstrap: fix do_fetch error wireguard-tools: fix do_fetch error vlock: fix do_fetch error openipmi: upgrade 2.0.34->2.0.36 tcpreplay: fix CVE-2023-43279 xfce-dusk-gtk3: fix do_fetch error eject: fix do_fetch error libdev-checklib-perl: fix do_fetch error xmlsec1: Switch SRC_URI to use github release chrony: fix do_fetch error v4l-utils: Fix QA and build errors related to _TIME_BITS on 32-bit webkitgtk3: update 2.44.1 -> 2.44.3 webkitgtk3: fix do_configure error on beaglebone-yocto Jinfeng Wang (2): netplan: Fix CVE-2022-4968 postfix: fix rootfs file difference Justin Bronder (1): python3-xmodem: replace hardcoded /usr with ${prefix} Khem Raj (32): python3-pydantic-core: Fix build with python 3.12.4 log4cpp: Fix buildpaths QA error python3-pydantic: Upgrade to 2.7.3 mariadb: Upgrade to 10.11.9 release ndisc: Remove buildpaths from binaries ndisc6: Fix reproducible build ghex,gnome-chess,gnome-photos: Add missing dep on itstool-native nodejs: Upgrade to 20.13.0 release nodejs: Fix build with libc++ 19 wolfssl: Add packageconfig for reproducible build blueman: Fix buildpathe issue with cython generated code botan: Make it reproducible keepalived: Make build reproducible ldns: Fix buildpaths QA issues python3-kivy: Remove buildpaths from comments in generated C sources python3-pyproj: Fix buildpaths QA Error python3-pyproj: Remove absolute paths from cython generated .c files python3-pycocotools: Remove absolute paths from comments lprng: Specify target paths for needed utilities fwknop: Specify target locations of gpg and wget e2tools: Fix buildpaths QA warning in config.status in ptest sharutils: Let POSIX_SHELL be overridable from environment python3-posix-ipc: switch to PEP-517 build backend gtkwave: Add libtirpc to depends ssmping: Use debian mirror for SRC_URI enca: Fix cross builds ckermit: Define return type for main ckermit: Fix build with GCC-15 procmail: Fix build with GCC-14 uim: Stick to C17 freerdp: Upgrade 2.11.2 -> 2.11.7 influxdb: Do not remove non-existing files Leon Anavi (2): sip: Upgrade 6.8.3 -> 6.8.6 sip: Fix homepage and license Leonard Anderweit (1): lmsensors: Fix build without sensord Libo Chen (3): thin-provisioning-tools: install missed thin_shrink and era_repair grpc: Fix CVE-2024-7246 libgpiod: fix gpiod-cxx-test failed test case Marc Ferland (2): polkit: update SRC_URI libvncserver: fix generated LibVNCServerTargets.cmake Markus Volk (4): exiv2: update 0.28.0 -> 0.28.2 gnome-remote-desktop: update 46.1 -> 46.2 geary: add itstool-native dependency eog: add itstool-native dependency Martin Jansa (13): bolt: package systemd_system_unitdir correctly giflib: fix build with gold and avoid imagemagick-native dependency Revert "gcab: ignore buildpaths error from sources" gpm: fix buildpaths QA issue xerces-c: fix buildpaths QA issue xmlrpc-c: update SRCREV lapack: add PACKAGECONFIG for cblas lapack: fix buildpaths in ptest also when CBLAS is enabled gcab: fix buildpaths QA issue python3-posix-ipc: improve build_support python3-h5py: backport fixes for incompatible-pointer-types issues abseil-cpp: fix build with gcc-15 on host nodejs: fix build with gcc-15 on host Martin Schwan (1): linuxptp: Add systemd instance specifier for ptp4l dependency Michael Olbrich (1): nftables: avoid python dependencies when building without python Michael Opdenacker (1): kernel-hardening-checker: backport recipe Mikko Rapeli (3): fwupd: skip buildpaths errors gcab: ignore buildpaths error from sources libjcat: skip buildpaths check Mingli Yu (2): asio: Add ptest support ptest-packagelists-meta-oe.inc: Add asio Neel Gandhi (1): v4l-utils: Install media ctrl header and library files Nikhil R (2): nftables: Conditionally add ${PN}-python as RDEPENDS for ptest rocksdb: Add an option to set static library Niko Mauno (16): python3-xlsxwriter: Fix LICENSE python3-cbor2: Fix LICENSE and LIC_FILES_CHKSUM python3-crc32c: Amend LICENSE declaration python3-email-validator: Fix LICENSE python3-lru-dict: Fix LICENSE and change SUMMARY to DESCRIPTION python3-mock: Fix LICENSE python3-parse-type: Fix LICENSE python3-pillow: Fix LICENSE and change SUMMARY to DESCRIPTION python3-platformdirs: Fix LICENSE python3-colorama: Fix LICENSE python3-fann2: Fix LICENSE python3-nmap: Fix LICENSE and LIC_FILES_CHKSUM python3-pycurl: Fix LICENSE python3-googleapis-common-protos: Fix LIC_FILES_CHKSUM python3-haversine: Fix LIC_FILES_CHKSUM python3-libevdev: Fix LIC_FILES_CHKSUM Ninette Adhikari (6): imagemagick: Update status for CVE imagemagick: Update status for CVE imagemagick: Update status for CVE xsp: CVE status update for CVE-2006-2658 influxdb: Update CVE status for CVE-2019-10329 monkey: Update status for CVE-2013-2183 Peter Kjellerstedt (6): hostapd: Support running "devtool modify hostapd" hostapd: Only include the relevant parts from README in LIC_FILES_CHKSUM libjs-jquery-icheck: Correct LIC_FILES_CHKSUM libdevmapper: Inherit nopackages ebtables: Remove the dependecy on bash libeigen: Remove LGPL code Peter Marko (41): libndp: Patch CVE-2024-5564 squid: patch CVE-2024-37894 hostapd: Patch CVE-2024-3596 hostapd: Patch security advisory 2024-2 nss: patch CVE-2024-6602 nss: patch CVE-2024-6609 squid: conditionally set status of CVE-2024-45802 thrift: fix c++ generated code compilation with clang grpc: patch CVE-2024-11407 python3-grpcio: patch CVE-2024-11407 python3-grpcio(-tools): fix build concurrency issue libmodbus: patch CVE-2024-10918 libmodbus: ignore CVE-2023-26793 and CVE-2024-34244 libcoap: patch CVE-2024-31031 spdlog: patch CVE-2025-6140 minifi-cpp: patch spdlog CVE-2025-6140 poco: ignore additional failing tests poco: patch CVE-2025-6375 nginx: patch CVE-2025-53859 fontforge: patch CVE-2024-25081 and CVE-2024-25082 fcgi: patch CVE-2025-23016 procmail: patch CVE-2014-3618 procmail: patch CVE-2017-16844. ace: ignore CVE-2009-1147 audiofile: fix multiple CVEs audiofile: patch CVE-2017-6829 audiofile: fix multiple CVEs audiofile: patch CVE-2017-6831 audiofile: patch CVE-2017-6839 emlog: set CVE_PRODUCT freerdp: patch CVE-2024-32661 freerdp: mark CVE-2024-32662 as fixed freerdp3: set CVE_PRODUCT corosync: fix upstream version check corosync: upgrade 3.1.6 -> 3.1.9 corosync: patch CVE-2025-30472 dash: set CVE_PRODUCT gattlib: mark CVE-2019-6498 as fixed memcached: ignore disputed CVE-2022-26635 monkey: ignore CVE-2013-1771 squid: patch CVE-2025-59362 Poonam Jadhav (1): tcpreplay: Fix CVE-2023-4256 Praveen Kumar (4): php: upgrade 8.2.28 -> 8.2.29 polkit: fix CVE-2025-7519 yasm: fix CVE-2024-22653 cjson: upgrade 1.7.18 -> 1.7.19 Preeti Sachan (1): bpftool: fix libelf.h not found error Raghuvarya S (2): android-tools-adbd.service: Update ConditionPathExists to /etc android-toold-adbd: Fix inconsistency between selinux configurations Rajeshkumar Ramasamy (1): open-vm-tools: fix CVE-2025-41244 Randolph Sapp (2): opencl-clhpp: add native and nativesdk vulkan-cts: allow vulkan versions > 1.3 Randy MacLeod (1): python3-pyyaml-include: support native and nativesdk build Robert Yang (1): hostapd: Add CVE id to CVE-2024-3596_00.patch Roland Kovacs (2): jq-1.7.1: Backport multiple CVE fixes jq: add Upstream-Status and CVE tags into .patch files Ryan Eatmon (1): kernel-selftest: Update to allow for turning on all tests Sana Kazi (2): libp11: Treat all openssl-3.x releases the same imagemagick: guard sed operations in do_install for optional files Saravanan (2): udisks2: upgrade 2.10.1 -> 2.10.2 fio: fix CVE-2025-10823 Scott Murray (2): python3-grpcio: Fix build with gcc-14 python3-grpcio: backport abseil-cpp RISC-V fix Shubham Pushpkar (2): wireshark 4.2.7: Fix CVE-2024-9781 cjson 1.7.18: Fix CVE-2025-57052 Siddharth Doshi (2): apache2: Upgrade 2.4.59 -> 2.4.60 apache2: Upgrade 2.4.60 -> 2.4.62 Sofiane HAMAM (2): Wolfssl: add ptest wolfssl: Upgrade 5.7.0 -> 5.7.2 Soumya Sambu (14): python3-sqlparse: Fix CVE-2024-4340 python3-werkzeug: upgrade 3.0.1 -> 3.0.3 gtk+: Fix CVE-2024-6655 python3-twisted: Fix CVE-2024-41671 python3-flask-cors: Fix CVE-2024-6221 python3-werkzeug: upgrade 3.0.3 -> 3.0.6 python3-tornado: Upgrade 6.4 -> 6.4.2 python3-django: upgrade 4.2.16 -> 4.2.17 python3-django: upgrade 5.0.9 -> 5.0.10 python3-django: upgrade 5.0.10 -> 5.0.11 python3-django: upgrade 4.2.17 -> 4.2.18 php: Upgrade 8.2.26 -> 8.2.28 iniparser: Fix CVE-2025-0633 python3-django: upgrade 4.2.18 -> 4.2.20 Sunil Dora (1): layer.conf: add bpftrace to NON_MULTILIB_RECIPES Swamil Jain (1): kmsxx: Revert to using original name for kmstest Thomas Roos (1): libcamera: backport 0.4.0 from master-next Tim Orling (1): python3-pydantic: upgrade 2.7.3 -> 2.7.4 Trevor Woerner (2): apache2: use update-alternatives for httpd iperf3: throughput fix Vijay Anusuri (16): krb5: upgrade 1.21.2 -> 1.21.3 wireshark: upgrade 4.2.4 -> 4.2.5 wireshark: upgrade 4.2.5 -> 4.2.7 php: upgrade 8.2.24 -> 8.2.26 openjpeg: upgrade 2.5.0 -> 2.5.3 postgresql: upgrade 16.5 -> 16.8 wireshark: upgrade 4.2.7 -> 4.2.9 proftpd: Fix CVE-2024-57392 redis: upgrade 7.2.7 -> 7.2.8 wireshark: upgrade 4.2.9 -> 4.2.12 proftpd: Fix CVE-2023-51713 apache2: Upgrade 2.4.62 -> 2.4.64 poppler: Fix CVE-2025-43718 redis: upgrade 7.2.8 -> 7.2.11 redis: upgrade 6.2.16 -> 6.2.18 vorbis-tools: Fix CVE-2023-43361 Virendra Thakur (2): opensc: Fix multiple cve CVE-2024-45615-45616-45617-45618-45619-45620 unbound: Fix CVE-2024-8508 Wang Mingyu (18): python3-email-validator: upgrade 2.1.0 -> 2.1.1 python3-pydantic: upgrade 2.7.0 -> 2.7.1 cjson: upgrade 1.7.17 -> 1.7.18 samba: upgrade 4.19.7 -> 4.19.8 postgresql: upgrade 16.3 -> 16.4 redis: upgrade 7.2.4 -> 7.2.5 mosquitto: upgrade 2.0.19 -> 2.0.20 uutils-coreutils: upgrade 0.0.27 -> 0.0.28 nana: Fix buildpaths warning. fetchmail: Fix buildpaths warning. fetchmail: disable rpath to fix buildpaths warning. python3-posix-ipc: upgrade 1.1.1 -> 1.2.0 mbedtls: upgrade 3.6.3 -> 3.6.3.1 geoip: fix do_fetch error rp-pppoe: update SRC_URI procmail: fix build failure with gcc-14 procmail: Add -Wno-implicit-int to fix error of do_compile libiec61850: upgrade 1.5.1 -> 1.5.3 Wentao Zhang (1): meta-oe/conf/layer.conf: remove libbpf from NON_MULTILIB_RECIPES for x86 and x86-64 Xiangyu Chen (1): crash: fix crash cannot work with kaslr Yi Zhao (12): samba: upgrade 4.19.6 -> 4.19.7 mbedtls: upgrade 3.6.0 -> 3.6.1 mbedtls: upgrade 2.28.8 -> 2.28.9 libldb: upgrade 2.8.0 -> 2.8.1 mbedtls: upgrade 3.6.1 -> 3.6.2 freeradius: upgrade 3.2.3 -> 3.2.5 hostapd: Security fix for CVE-2023-52160 redis: upgrade 7.2.5 -> 7.2.6 mbedtls: upgrade 2.28.9 -> 2.28.10 mbedtls: 3.6.2 -> 3.6.3 wxwidgets: upgrade 3.2.1 -> 3.2.6 redis: upgrade 6.2.14 -> 6.2.16 Yoann Congal (3): packagegroup-meta-oe: fix lvgl inclusion mdio-tools: fix mdio-netlink kernel module reproducibility gutenprint: fix a build race-condition Yogesh Tyagi (1): tbb-native: Fix build with gcc-13 Yogita Urade (18): graphviz: fix CVE-2023-46045 hdf5: upgrade to 1.14.4 poppler: CVE-2024-6239 krb5: fix CVE-2024-26458 and CVE-2024-26461 php: upgrade 8.2.20 -> 8.2.24 postgresql: upgrade 16.4 -> 16.5 poppler: fix CVE-2024-56378 poppler: fix CVE-2025-32364 poppler: fix CVE-2025-32365 poppler: fix CVE-2025-43903 syslog-ng: fix CVE-2024-47619 postgresql: upgrade 16.8 -> 16.9 mariadb: upgrade 10.11.9 -> 10.11.12 poppler: fix CVE-2025-52886 poppler: fix CVE-2025-50420 postgresql: upgrade 16.9 -> 16.10 indent: fix CVE-2023-40305 poppler: fix CVE-2025-52885 Zhang Peng (21): hiredis: remove ANSI color from ptest result frr: fix CVE-2024-34088 frr: fix CVE-2024-31950 frr: fix CVE-2024-31951 frr: fix CVE-2024-31948 frr: fix CVE-2024-31949 libgsf: upgrade 1.14.52 -> 1.14.53 glade: fix CVE-2020-36774 opensc: fix CVE-2024-8443 lapack: fix TMPDIR reference in do_package_qa iperf3: upgrade 3.16 -> 3.18 gnuplot: fix CVE-2025-3359 gnuplot: fix CVE-2025-31176 gnuplot: fix CVE-2025-31177 gnuplot: fix CVE-2025-31178 gnuplot: fix CVE-2025-31179 gnuplot: fix CVE-2025-31180 gnuplot: fix CVE-2025-31181 iperf3: fix CVE-2025-54349 iperf3: fix CVE-2025-54350 wxwidgets: fix CVE-2024-58249 Zoltán Böszörményi (1): gutenprint: 5.3.5 akash hadke (1): python3-flatbuffers: provide nativesdk support alperak (8): tayga: Fix contains reference to TMPDIR [buildpaths] warning etcd-cpp-apiv3: Fix contains reference to TMPDIR [buildpaths] warning exiv2: Upgrade 0.28.2 to 0.28.3 for CVE fix jsonrpc: Fix contains reference to TMPDIR [buildpaths] warning rdist: Fix contains reference to TMPDIR [buildpaths] warning perfetto: Fix contains reference to TMPDIR [buildpaths] warning hplip: Fix contains reference to TMPDIR [buildpaths] warning boinc-client: Fix contains reference to TMPDIR [buildpaths] warning gudnimar (1): pipewire: upgrade 1.0.5 -> 1.0.9 hongxu (2): p7zip: fix CVE-2023-52169 and CVE-2023-52168 indent: fix CVE-2024-0911 kjlau0112 (1): mbedtls: drop tag parameter from SRC_URI. mark.yang (1): srecord: fix build failure with gcc-15 meta-raspberrypi: 1918a27419..8767e2ff80: Adam Schafer (1): add raspi-utils recipe to scarthgap branch Andrei Gherzan (1): docs: Fix ReadTheDocs sphinx.configuration requirement Ayoub Zaki (1): raspberrypi5: add bcm2712d0 overlay required for booting up correctly Bassem Nomany (1): mesa: update to 24.3.1 Damiano Ferrari (2): rpi-eeprom: Update to latest release rpi-bootfiles: Update to latest release Florin Sarbu (1): linux-raspberrypi.inc: Change defconfig for RPi3 64 bits Garrett Brown (1): linux: Enable CONFIG_I2C_BRCMSTB for proper HDMI I2C support Gijs Peskens (1): raspberrypi5.conf: Add CM5 dtb's Jaeyoon Jung (1): linux-raspberrypi: Drop deprecated configs from android-driver.cfg Joshua Watt (1): linux-firmware-rpidistro: Fix WiFi on Raspberry Pi 5 Khem Raj (2): linux-raspberrypi-6.6: Upgrade to 6.6.63 rpi-base: Remove bcm2712-rpi-5-b.dtb from RPI_KERNEL_DEVICETREE target Leon Anavi (11): yocto-builder/Dockerfile: Ubuntu 22.04 rpi-base.inc: vc4-kms-dsi-ili9881-7inch.dtbo u-boot_%.bbappend: Increase CONFIG_SYS_BOOTM_LEN wayland-protocols: Upgrade 1.38 -> 1.45 mesa: Upgrade 24.3.1 -> 25.1.3 mesa: Upgrade 25.1.3 -> 25.1.6 mesa_%.bbappend: DISTRO_FEATURES for wayland mesa: wayland-protocols: Fix signatures linux-firmware-rpidistro: Update and stabilize rpi-base.inc: Add w1-gpio-pi5.dtbo rpi-base.inc: Add rpi-backlight.dtbo Markus Volk (4): linux-raspberrypi: add recipe for 6.12 linux-raspberrypi: update 6.12.2 -> 6.12.25 rpi-default-versions: Switch default kernel to 6.12 rpi-bootfiles: update to latest release Martin Jansa (3): docker-build: use --no-cache Revert "rpi-default-versions: Switch default kernel to 6.12" mesa, wayland-protocols: use separate recipe instead of bbappend Matthias Klein (1): linux-firmware-rpidistro: Upgrade to bookworm/20230625-2+rpt3 Omri Sarig (1): linux-firmware-rpidistro: Fix wireless error message on RPi Pierrick Curt (1): rpi-base: build uart dts overlays by default Thomas Roos (1): Moving bcm2712d0.dtbo into rpi-base.inc meta-arm: 58268ddccb..0f1e7bf92c: Amr Mohamed (5): kas: Update kas configuration for fvp-base.yml file arm-systemready/linux-distros: new inc file for unattended installation arm-systemready/linux-distros: Add kickstart file for Fedora unattended arm-systemready/oeqa: Add new test for Fedora unattended installation kas: Add new yml file for Distros unattended installation Ben (3): arm-systemready/linux-distros: Implement unattended openSUSE arm-systemready/oeqa: Add unattended installation testcase kas: Include unattended openSUSE test Bence Balogh (1): arm-bsp/trusted-firmware-m: corstone1000: Fix MPU configuration Harsimran Singh Tungal (1): arm-bsp,kas: corstone1000: enable External System based on new yml file Hugues KAMBA MPIANA (1): arm-bsp/documentation: corstone1000: Add SystemReady IR v2.0 certification Jon Mason (4): arm-toolchain: remove libmount-mountfd-support when using binary toolchain arm-bsp/fvp-base: Get 6.10 kernel working arm/linux-yocto: disable CONFIG_MTD_NAND_FSL_IFC arm-systemready/ir-acs: Update URL Jose Quaresma (1): bsp: optee-client: cleanup old tee-supplicant Luca Fancellu (2): arm/oeqa: Introduce retry mechanism for fvp_devices run_cmd arm/lib: Handle timeout for spawn object on stop() Romain Naour (4): external-arm-toolchain: remove old sed fixup for libc.so external-arm-toolchain: wrap symlink handling under usrmerge check external-arm-toolchain: override dynamic loader path with usrmerge enabled external-arm-toolchain: rebuild libmvec.so symlink if any Ross Burton (5): arm-base/linux-yocto: revert interim 6.10 patch for fvp-base arm-system-ready/arm-systemready-ir-acs: add version to download filename CI: use canonical git.yoctoproject.org URLs arm/execstack-native: add new recipe arm/fvp-base-a-aem: remove spurious executable stack from one library Vasyl Vavrychuk (3): external-arm-toolchain: wrap base_libdir vs libdir manipulations under usrmerge check external-arm-toolchain: in libc.so GNU ld script use base_libdir external-arm-toolchain: remove ${base_libdir}/libpthread*.so from FILES:${PN} meta-security: 11ea91192d..bc865c5276: Hitendra Prajapati (2): clamav: fix CVE-2024-20505 & CVE-2024-20506 libhtp: fix CVE-2024-45797 Vijay Anusuri (2): tpm2-tools: Upgrade 5.5 -> 5.7 tpm2-tss: upgrade 4.0.1 -> 4.0.2 Change-Id: Ief5b086436b2f3a4e819546fcd1bb9a5b1f608dd Signed-off-by: Andrew Geissler <geissonator@yahoo.com>
Diffstat (limited to 'meta-openembedded/meta-python/recipes-devtools')
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-cbor2_5.6.3.bb4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-colorama_0.4.6.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-crc32c_2.3.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-django_4.2.20.bb (renamed from meta-openembedded/meta-python/recipes-devtools/python/python3-django_4.2.11.bb)4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-django_5.0.11.bb (renamed from meta-openembedded/meta-python/recipes-devtools/python/python3-django_5.0.4.bb)2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-email-validator_2.1.1.bb (renamed from meta-openembedded/meta-python/recipes-devtools/python/python3-email-validator_2.1.0.bb)6
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-fann2_1.1.2.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors/CVE-2024-6221.patch110
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors_4.0.0.bb4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-googleapis-common-protos_1.63.0.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio-tools_1.62.2.bb4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-PR-1644-unscaledcycleclock-remove-RISC-V-support.patch82
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-crypto-use-_Generic-only-if-defined-__cplusplus.patch74
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/CVE-2024-11407.patch32
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio_1.62.2.bb7
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0001-Properly-cast-arguments-to-H5Lunpack_elink_val.patch25
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0002-Use-libc.stdint-instead-of-numpy.patch25
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-h5py_3.10.0.bb8
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-haversine_2.8.1.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-kivy_2.3.0.bb7
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-libevdev_0.11.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-lru-dict_1.3.0.bb4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-mock_5.1.0.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-nmap_1.6.0.bb4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-parse-type_0.6.2.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pillow_10.3.0.bb4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-platformdirs_4.2.0.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0001-build_support-use-source-filename-instead-of-foo-for.patch50
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0002-build_support-handle-empty-max_priority-value-as-Non.patch49
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0003-build_support-use-does_build_succeed-in-compile_and_.patch62
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0004-build_support-handle-runtime-errors-and-return-None-.patch47
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.1.1.bb11
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.2.0.bb17
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-protobuf_4.25.8.bb (renamed from meta-openembedded/meta-python/recipes-devtools/python/python3-protobuf_4.25.3.bb)10
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pycocotools_2.0.7.bb4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pycurl_7.45.2.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core-crates.inc88
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Bumps-pyo3-https-github.com-pyo3-pyo3-from-0.20.2-to.patch126
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Set-rust-version-from-1.76-to-1.75-in-Cargo.toml.patch29
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0002-Dont-embed-RUSTFLAGS-in-final-binary.patch47
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core_2.18.4.bb (renamed from meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core_2.16.3.bb)12
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic_2.7.4.bb (renamed from meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic_2.7.0.bb)2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pylint_3.1.0.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj/rpath.patch18
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj_3.6.1.bb10
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pyyaml-include_1.3.2.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2024-4340.patch48
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse_0.4.4.bb1
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-tornado_6.4.2.bb (renamed from meta-openembedded/meta-python/recipes-devtools/python/python3-tornado_6.4.bb)4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0001.patch89
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0002.patch251
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-twisted_24.3.0.bb5
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-werkzeug_3.0.6.bb (renamed from meta-openembedded/meta-python/recipes-devtools/python/python3-werkzeug_3.0.1.bb)5
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-xlsxwriter_3.1.9.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-xmodem_0.4.7.bb4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/tftpy/CVE-2023-46566.patch26
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/tftpy_0.8.2.bb2
57 files changed, 1230 insertions, 219 deletions
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-cbor2_5.6.3.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-cbor2_5.6.3.bb
index c9c98b6fb5..69573064bc 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-cbor2_5.6.3.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-cbor2_5.6.3.bb
@@ -1,8 +1,8 @@
DESCRIPTION = "An implementation of RFC 7049 - Concise Binary Object Representation (CBOR)."
DEPENDS +="python3-setuptools-scm-native"
-LICENSE = "Apache-2.0"
-LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/Apache-2.0;md5=89aea4e17d99a7cacdbeed46a0096b10"
+LICENSE = "MIT"
+LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=a79e64179819c7ce293372c059f1dbd8"
SRC_URI[sha256sum] = "e6f0ae2751c2d333a960e0807c0611494eb1245631a167965acbc100509455d3"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-colorama_0.4.6.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-colorama_0.4.6.bb
index 0f364c424d..3871244031 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-colorama_0.4.6.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-colorama_0.4.6.bb
@@ -1,6 +1,6 @@
SUMMARY = "Cross-platform colored terminal text."
HOMEPAGE = "https://github.com/tartley/colorama"
-LICENSE = "BSD-2-Clause"
+LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=b4936429a56a652b84c5c01280dcaa26"
inherit pypi python_setuptools_build_meta
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-crc32c_2.3.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-crc32c_2.3.bb
index da756ea074..125a7ad877 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-crc32c_2.3.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-crc32c_2.3.bb
@@ -1,7 +1,7 @@
SUMMARY = "A python package implementing the crc32c algorithmin hardware and software"
HOMEPAGE = "https://github.com/ICRAR/crc32c"
-LICENSE = "BSD-2-Clause & BSD-3-Clause & CRC32C-ADLER & LGPL-2.0-or-later"
+LICENSE = "BSD-2-Clause & BSD-3-Clause & CRC32C-ADLER & LGPL-2.1-or-later"
LIC_FILES_CHKSUM = " \
file://LICENSE;md5=4fbd65380cdd255951079008b364516c \
file://LICENSE.google-crc32c;md5=e9ed01b5e5ac9eae23fc2bb33701220c \
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-django_4.2.11.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-django_4.2.20.bb
index 0642b7e7c3..3fb8b03224 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-django_4.2.11.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-django_4.2.20.bb
@@ -1,7 +1,7 @@
require python-django.inc
inherit setuptools3
-SRC_URI[sha256sum] = "6e6ff3db2d8dd0c986b4eec8554c8e4f919b5c1ff62a5b4390c17aff2ed6e5c4"
+SRC_URI[sha256sum] = "92bac5b4432a64532abb73b2ac27203f485e40225d2640a7fbef2b62b876e789"
RDEPENDS:${PN} += "\
python3-sqlparse \
@@ -10,5 +10,5 @@ RDEPENDS:${PN} += "\
# Set DEFAULT_PREFERENCE so that the LTS version of django is built by
# default. To build the 4.x branch,
-# PREFERRED_VERSION_python3-django = "4.2.11" can be added to local.conf
+# PREFERRED_VERSION_python3-django = "4.2.20" can be added to local.conf
DEFAULT_PREFERENCE = "-1"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-django_5.0.4.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-django_5.0.11.bb
index 3139ed4682..5060f3c9ad 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-django_5.0.4.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-django_5.0.11.bb
@@ -1,7 +1,7 @@
require python-django.inc
inherit setuptools3
-SRC_URI[sha256sum] = "4bd01a8c830bb77a8a3b0e7d8b25b887e536ad17a81ba2dce5476135c73312bd"
+SRC_URI[sha256sum] = "e7d98fa05ce09cb3e8d5ad6472fb602322acd1740bfdadc29c8404182d664f65"
RDEPENDS:${PN} += "\
python3-sqlparse \
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-email-validator_2.1.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-email-validator_2.1.1.bb
index 7daf548cb1..746d56d18e 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-email-validator_2.1.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-email-validator_2.1.1.bb
@@ -1,9 +1,9 @@
SUMMARY = "A robust email address syntax and deliverability validation library."
SECTION = "devel/python"
-LICENSE = "CC0-1.0"
-LIC_FILES_CHKSUM = "file://LICENSE;md5=65d3616852dbf7b1a6d4b53b00626032"
+LICENSE = "Unlicense"
+LIC_FILES_CHKSUM = "file://LICENSE;md5=2890aee62bd2a4c3197e2059016a397e"
-SRC_URI[sha256sum] = "5f511cca8856bb03251d6292ba59e7f98978aae13fa5823ddd8bf885c56a6260"
+SRC_URI[sha256sum] = "200a70680ba08904be6d1eef729205cc0d687634399a5924d842533efb824b84"
PYPI_PACKAGE = "email_validator"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-fann2_1.1.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-fann2_1.1.2.bb
index 2fbc277139..2099d791dd 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-fann2_1.1.2.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-fann2_1.1.2.bb
@@ -1,6 +1,6 @@
SUMMARY = "Python bindings for Fast Artificial Neural Networks 2.2.0 (FANN >= 2.2.0)"
SECTION = "devel/python"
-LICENSE = "LGPL-2.0-only"
+LICENSE = "LGPL-2.1-only"
LIC_FILES_CHKSUM = "file://LICENSE;md5=c73b943dc75f6f65e007c56ac6515c8f"
SRC_URI[md5sum] = "0b85b418018746d63ed66b55465697a9"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors/CVE-2024-6221.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors/CVE-2024-6221.patch
new file mode 100644
index 0000000000..9049b2ffe6
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors/CVE-2024-6221.patch
@@ -0,0 +1,110 @@
+From 7ae310c56ac30e0b94fb42129aa377bf633256ec Mon Sep 17 00:00:00 2001
+From: Adriano Sela Aviles <adriano.selaviles@gmail.com>
+Date: Fri, 30 Aug 2024 12:14:31 -0400
+Subject: [PATCH] Backwards Compatible Fix for CVE-2024-6221 (#363)
+
+CVE: CVE-2024-6221
+
+Upstream-Status: Backport [https://github.com/corydolphin/flask-cors/commit/7ae310c56ac30e0b94fb42129aa377bf633256ec]
+
+Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
+---
+ docs/configuration.rst | 14 ++++++++++++++
+ flask_cors/core.py | 8 +++++---
+ flask_cors/extension.py | 16 ++++++++++++++++
+ 3 files changed, 35 insertions(+), 3 deletions(-)
+
+diff --git a/docs/configuration.rst b/docs/configuration.rst
+index 91282d3..c750cf4 100644
+--- a/docs/configuration.rst
++++ b/docs/configuration.rst
+@@ -23,6 +23,19 @@ CORS_ALLOW_HEADERS (:py:class:`~typing.List` or :py:class:`str`)
+ Headers to accept from the client.
+ Headers in the :http:header:`Access-Control-Request-Headers` request header (usually part of the preflight OPTIONS request) matching headers in this list will be included in the :http:header:`Access-Control-Allow-Headers` response header.
+
++CORS_ALLOW_PRIVATE_NETWORK (:py:class:`bool`)
++ If True, the response header :http:header:`Access-Control-Allow-Private-Network`
++ will be set with the value 'true' whenever the request header
++ :http:header:`Access-Control-Request-Private-Network` has a value 'true'.
++
++ If False, the reponse header :http:header:`Access-Control-Allow-Private-Network`
++ will be set with the value 'false' whenever the request header
++ :http:header:`Access-Control-Request-Private-Network` has a value of 'true'.
++
++ If the request header :http:header:`Access-Control-Request-Private-Network` is
++ not present or has a value other than 'true', the response header
++ :http:header:`Access-Control-Allow-Private-Network` will not be set.
++
+ CORS_ALWAYS_SEND (:py:class:`bool`)
+ Usually, if a request doesn't include an :http:header:`Origin` header, the client did not request CORS.
+ This means we can ignore this request.
+@@ -83,6 +96,7 @@ Default values
+ ~~~~~~~~~~~~~~
+
+ * CORS_ALLOW_HEADERS: "*"
++* CORS_ALLOW_PRIVATE_NETWORK: True
+ * CORS_ALWAYS_SEND: True
+ * CORS_AUTOMATIC_OPTIONS: True
+ * CORS_EXPOSE_HEADERS: None
+diff --git a/flask_cors/core.py b/flask_cors/core.py
+index 5358036..bd011f4 100644
+--- a/flask_cors/core.py
++++ b/flask_cors/core.py
+@@ -36,7 +36,7 @@ CONFIG_OPTIONS = ['CORS_ORIGINS', 'CORS_METHODS', 'CORS_ALLOW_HEADERS',
+ 'CORS_MAX_AGE', 'CORS_SEND_WILDCARD',
+ 'CORS_AUTOMATIC_OPTIONS', 'CORS_VARY_HEADER',
+ 'CORS_RESOURCES', 'CORS_INTERCEPT_EXCEPTIONS',
+- 'CORS_ALWAYS_SEND']
++ 'CORS_ALWAYS_SEND', 'CORS_ALLOW_PRIVATE_NETWORK']
+ # Attribute added to request object by decorator to indicate that CORS
+ # was evaluated, in case the decorator and extension are both applied
+ # to a view.
+@@ -56,7 +56,8 @@ DEFAULT_OPTIONS = dict(origins='*',
+ vary_header=True,
+ resources=r'/*',
+ intercept_exceptions=True,
+- always_send=True)
++ always_send=True,
++ allow_private_network=True)
+
+
+ def parse_resources(resources):
+@@ -186,7 +187,8 @@ def get_cors_headers(options, request_headers, request_method):
+
+ if ACL_REQUEST_HEADER_PRIVATE_NETWORK in request_headers \
+ and request_headers.get(ACL_REQUEST_HEADER_PRIVATE_NETWORK) == 'true':
+- headers[ACL_RESPONSE_PRIVATE_NETWORK] = 'true'
++ allow_private_network = 'true' if options.get('allow_private_network') else 'false'
++ headers[ACL_RESPONSE_PRIVATE_NETWORK] = allow_private_network
+
+ # This is a preflight request
+ # http://www.w3.org/TR/cors/#resource-preflight-requests
+diff --git a/flask_cors/extension.py b/flask_cors/extension.py
+index c00cbff..694953f 100644
+--- a/flask_cors/extension.py
++++ b/flask_cors/extension.py
+@@ -136,6 +136,22 @@ class CORS(object):
+
+ Default : True
+ :type vary_header: bool
++
++ :param allow_private_network:
++ If True, the response header `Access-Control-Allow-Private-Network`
++ will be set with the value 'true' whenever the request header
++ `Access-Control-Request-Private-Network` has a value 'true'.
++
++ If False, the reponse header `Access-Control-Allow-Private-Network`
++ will be set with the value 'false' whenever the request header
++ `Access-Control-Request-Private-Network` has a value of 'true'.
++
++ If the request header `Access-Control-Request-Private-Network` is
++ not present or has a value other than 'true', the response header
++ `Access-Control-Allow-Private-Network` will not be set.
++
++ Default : True
++ :type allow_private_network: bool
+ """
+
+ def __init__(self, app=None, **kwargs):
+--
+2.40.0
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors_4.0.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors_4.0.0.bb
index 1d0d86b4e7..77b51c5515 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors_4.0.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors_4.0.0.bb
@@ -9,6 +9,10 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=118fecaa576ab51c1520f95e98db61ce"
PYPI_PACKAGE = "Flask-Cors"
+SRC_URI += " \
+ file://CVE-2024-6221.patch \
+"
+
SRC_URI[sha256sum] = "f268522fcb2f73e2ecdde1ef45e2fd5c71cc48fe03cffb4b441c6d1b40684eb0"
inherit pypi setuptools3
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-googleapis-common-protos_1.63.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-googleapis-common-protos_1.63.0.bb
index aee2337267..3c55294498 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-googleapis-common-protos_1.63.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-googleapis-common-protos_1.63.0.bb
@@ -1,7 +1,7 @@
DESCRIPTION = "Common protobufs used in Google APIs"
HOMEPAGE = "https://github.com/googleapis/python-api-common-protos"
LICENSE = "Apache-2.0"
-LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/Apache-2.0;md5=89aea4e17d99a7cacdbeed46a0096b10"
+LIC_FILES_CHKSUM = "file://LICENSE;md5=3b83ef96387f14655fc854ddc3c6bd57"
inherit pypi setuptools3
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio-tools_1.62.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio-tools_1.62.2.bb
index e05b8734d6..5b8bbe681a 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio-tools_1.62.2.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio-tools_1.62.2.bb
@@ -16,4 +16,8 @@ SRC_URI[sha256sum] = "5fd5e1582b678e6b941ee5f5809340be5e0724691df5299aae8226640f
RDEPENDS:${PN} = "python3-grpcio"
+do_compile:prepend() {
+ export GRPC_PYTHON_BUILD_EXT_COMPILER_JOBS="${@oe.utils.parallel_make(d, False)}"
+}
+
BBCLASSEXTEND = "native nativesdk"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-PR-1644-unscaledcycleclock-remove-RISC-V-support.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-PR-1644-unscaledcycleclock-remove-RISC-V-support.patch
new file mode 100644
index 0000000000..82f15f88cd
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-PR-1644-unscaledcycleclock-remove-RISC-V-support.patch
@@ -0,0 +1,82 @@
+From 7335a36d0b5c1c597566f9aa3f458a5b6817c3b4 Mon Sep 17 00:00:00 2001
+From: aurel32 <aurelien@aurel32.net>
+Date: Fri, 22 Mar 2024 14:21:13 -0700
+Subject: [PATCH] PR #1644: unscaledcycleclock: remove RISC-V support
+
+Imported from GitHub PR https://github.com/abseil/abseil-cpp/pull/1644
+
+Starting with Linux 6.6 [1], RDCYCLE is a privileged instruction on RISC-V and can't be used directly from userland. There is a sysctl option to change that as a transition period, but it will eventually disappear.
+
+The RDTIME instruction is another less accurate alternative, however its frequency varies from board to board, and there is currently now way to get its frequency from userland [2].
+
+Therefore this patch just removes the code for unscaledcycleclock on RISC-V. Without processor specific implementation, abseil relies on std::chrono::steady_clock::now().time_since_epoch() which is basically a wrapper around clock_gettime (CLOCK_MONOTONIC), which in turns use __vdso_clock_gettime(). On RISC-V this VDSO is just a wrapper around RDTIME correctly scaled to use nanoseconds units.
+
+This fixes the testsuite on riscv64, tested on a VisionFive 2 board.
+
+[1] https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cc4c07c89aada16229084eeb93895c95b7eabaa3
+[2] https://github.com/abseil/abseil-cpp/pull/1631
+Merge 43356a2548cfde76e164d446cb69004b488c6a71 into 76f8011beabdaee872b5fde7546e02407b220cb1
+
+Merging this change closes #1644
+
+COPYBARA_INTEGRATE_REVIEW=https://github.com/abseil/abseil-cpp/pull/1644 from aurel32:rv64-no-unscaledcycleclock 43356a2548cfde76e164d446cb69004b488c6a71
+PiperOrigin-RevId: 618286262
+Change-Id: Ie4120a727e7d0bb185df6e06ea145c780ebe6652
+
+Upstream-Status: Backport [https://github.com/abseil/abseil-cpp/commit/7335a36d]
+[Adapted to apply on top of meta-oe's patch stack]
+Signed-off-by: Scott Murray <scott.murray@konsulko.com>
+---
+ .../absl/base/internal/unscaledcycleclock.cc | 12 ------------
+ .../absl/base/internal/unscaledcycleclock_config.h | 5 ++---
+ 2 files changed, 2 insertions(+), 15 deletions(-)
+
+diff --git a/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock.cc b/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock.cc
+index f11fecb..103b4f6 100644
+--- a/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock.cc
++++ b/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock.cc
+@@ -121,18 +121,6 @@ double UnscaledCycleClock::Frequency() {
+ return aarch64_timer_frequency;
+ }
+
+-#elif defined(__riscv)
+-
+-int64_t UnscaledCycleClock::Now() {
+- int64_t virtual_timer_value;
+- asm volatile("rdcycle %0" : "=r"(virtual_timer_value));
+- return virtual_timer_value;
+-}
+-
+-double UnscaledCycleClock::Frequency() {
+- return base_internal::NominalCPUFrequency();
+-}
+-
+ #elif defined(_M_IX86) || defined(_M_X64)
+
+ #pragma intrinsic(__rdtsc)
+diff --git a/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock_config.h b/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock_config.h
+index 5e232c1..83552fc 100644
+--- a/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock_config.h
++++ b/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock_config.h
+@@ -22,7 +22,6 @@
+ // The following platforms have an implementation of a hardware counter.
+ #if defined(__i386__) || defined(__x86_64__) || defined(__aarch64__) || \
+ ((defined(__powerpc__) || defined(__ppc__)) && defined(__GLIBC__)) || \
+- defined(__riscv) || \
+ defined(_M_IX86) || (defined(_M_X64) && !defined(_M_ARM64EC))
+ #define ABSL_HAVE_UNSCALED_CYCLECLOCK_IMPLEMENTATION 1
+ #else
+@@ -54,8 +53,8 @@
+ #if ABSL_USE_UNSCALED_CYCLECLOCK
+ // This macro can be used to test if UnscaledCycleClock::Frequency()
+ // is NominalCPUFrequency() on a particular platform.
+-#if (defined(__i386__) || defined(__x86_64__) || defined(__riscv) || \
+- defined(_M_IX86) || defined(_M_X64))
++#if (defined(__i386__) || defined(__x86_64__) || defined(_M_IX86) || \
++ defined(_M_X64))
+ #define ABSL_INTERNAL_UNSCALED_CYCLECLOCK_FREQUENCY_IS_CPU_FREQUENCY
+ #endif
+ #endif
+--
+2.44.0
+
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-crypto-use-_Generic-only-if-defined-__cplusplus.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-crypto-use-_Generic-only-if-defined-__cplusplus.patch
new file mode 100644
index 0000000000..d830d92284
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-crypto-use-_Generic-only-if-defined-__cplusplus.patch
@@ -0,0 +1,74 @@
+From 3359a87a71307336100b84e66b69bad385cd3cfc Mon Sep 17 00:00:00 2001
+From: Martin Jansa <martin.jansa@gmail.com>
+Date: Mon, 6 May 2024 01:36:39 +0200
+Subject: [PATCH] crypto: use _Generic only if !defined(__cplusplus)
+
+* fixes build with gcc-14 which has __builtin_addc and __builtin_subc
+ with gcc-13 it was already using the #else branch because of missing builtins
+
+* fixes
+ https://github.com/grpc/grpc/issues/35945
+
+* _Generic was introduced in boringssl with:
+ https://boringssl.googlesource.com/boringssl/+/70ca6bc24be103dabd68e448cd3af29b929b771d%5E%21/#F4
+
+* but e.g. third_party/boringssl-with-bazel/src/ssl/d1_both.cc includes
+ this internal.h and from the .cc extension gcc will process it as C++
+ where _Generic isn't available, causing:
+
+In file included from third_party/boringssl-with-bazel/src/ssl/d1_both.cc:125:
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h: In function 'uint32_t CRYPTO_addc_u32(uint32_t, uint32_t, uint32_t, uint32_t*)':
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1159:7: error: expected primary-expression before 'unsigned'
+ 1159 | unsigned: __builtin_addc, \
+ | ^~~~~~~~
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1166:10: note: in expansion of macro 'CRYPTO_GENERIC_ADDC'
+ 1166 | return CRYPTO_GENERIC_ADDC(x, y, carry, out_carry);
+ | ^~~~~~~~~~~~~~~~~~~
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1160:7: error: expected primary-expression before 'unsigned'
+ 1160 | unsigned long: __builtin_addcl, \
+ | ^~~~~~~~
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1166:10: note: in expansion of macro 'CRYPTO_GENERIC_ADDC'
+ 1166 | return CRYPTO_GENERIC_ADDC(x, y, carry, out_carry);
+ | ^~~~~~~~~~~~~~~~~~~
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1161:7: error: expected primary-expression before 'unsigned'
+ 1161 | unsigned long long: __builtin_addcll))((x), (y), (carry), (out_carry))
+ | ^~~~~~~~
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1166:10: note: in expansion of macro 'CRYPTO_GENERIC_ADDC'
+ 1166 | return CRYPTO_GENERIC_ADDC(x, y, carry, out_carry);
+ | ^~~~~~~~~~~~~~~~~~~
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1158:4: error: '_Generic' was not declared in this scope
+ 1158 | (_Generic((x), \
+ | ^~~~~~~~
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1166:10: note: in expansion of macro 'CRYPTO_GENERIC_ADDC'
+ 1166 | return CRYPTO_GENERIC_ADDC(x, y, carry, out_carry);
+ | ^~~~~~~~~~~~~~~~~~~
+
+Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
+---
+Upstream-Status: Submitted [https://boringssl-review.googlesource.com/c/boringssl/+/68227 crypto: use _Generic only if !defined(__cplusplus)]
+
+ crypto/internal.h | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/crypto/internal.h b/crypto/internal.h
+index a77102d76..30d6826dd 100644
+--- a/crypto/internal.h
++++ b/crypto/internal.h
+@@ -1176,7 +1176,7 @@ static inline uint64_t CRYPTO_rotr_u64(uint64_t value, int shift) {
+
+ // CRYPTO_addc_* returns |x + y + carry|, and sets |*out_carry| to the carry
+ // bit. |carry| must be zero or one.
+-#if OPENSSL_HAS_BUILTIN(__builtin_addc)
++#if OPENSSL_HAS_BUILTIN(__builtin_addc) && !defined(__cplusplus)
+
+ #define CRYPTO_GENERIC_ADDC(x, y, carry, out_carry) \
+ (_Generic((x), \
+@@ -1228,7 +1228,7 @@ static inline uint64_t CRYPTO_addc_u64(uint64_t x, uint64_t y, uint64_t carry,
+
+ // CRYPTO_subc_* returns |x - y - borrow|, and sets |*out_borrow| to the borrow
+ // bit. |borrow| must be zero or one.
+-#if OPENSSL_HAS_BUILTIN(__builtin_subc)
++#if OPENSSL_HAS_BUILTIN(__builtin_subc) && !defined(__cplusplus)
+
+ #define CRYPTO_GENERIC_SUBC(x, y, borrow, out_borrow) \
+ (_Generic((x), \
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/CVE-2024-11407.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/CVE-2024-11407.patch
new file mode 100644
index 0000000000..eef5e7239e
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/CVE-2024-11407.patch
@@ -0,0 +1,32 @@
+From e9046b2bbebc0cb7f5dc42008f807f6c7e98e791 Mon Sep 17 00:00:00 2001
+From: Vignesh Babu <vigneshbabu@google.com>
+Date: Thu, 12 Sep 2024 11:13:45 -0700
+Subject: [PATCH] [EventEngine] Fix bug in Tx0cp code path in posix endpoint.
+
+This fix ensures that the iov_base pointers point to the right address.
+
+PiperOrigin-RevId: 673923651
+
+CVE: CVE-2024-11407
+Upstream-Status: Backport [https://github.com/grpc/grpc/commit/e9046b2bbebc0cb7f5dc42008f807f6c7e98e791]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/core/lib/event_engine/posix_engine/posix_endpoint.cc | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/core/lib/event_engine/posix_engine/posix_endpoint.cc b/src/core/lib/event_engine/posix_engine/posix_endpoint.cc
+index 7634bb1334b..c5708db02c5 100644
+--- a/src/core/lib/event_engine/posix_engine/posix_endpoint.cc
++++ b/src/core/lib/event_engine/posix_engine/posix_endpoint.cc
+@@ -240,7 +240,7 @@ msg_iovlen_type TcpZerocopySendRecord::PopulateIovs(size_t* unwind_slice_idx,
+ iov_size++) {
+ MutableSlice& slice = internal::SliceCast<MutableSlice>(
+ buf_.MutableSliceAt(out_offset_.slice_idx));
+- iov[iov_size].iov_base = slice.begin();
++ iov[iov_size].iov_base = slice.begin() + out_offset_.byte_idx;
+ iov[iov_size].iov_len = slice.length() - out_offset_.byte_idx;
+ *sending_length += iov[iov_size].iov_len;
+ ++(out_offset_.slice_idx);
+--
+2.30.2
+
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio_1.62.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio_1.62.2.bb
index 80a4d04e67..3581991a56 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio_1.62.2.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio_1.62.2.bb
@@ -9,7 +9,10 @@ DEPENDS += "python3-protobuf"
SRC_URI += "file://0001-Include-missing-cstdint-header.patch \
file://abseil-ppc-fixes.patch \
file://0001-zlib-Include-unistd.h-for-open-close-C-APIs.patch \
+ file://0001-crypto-use-_Generic-only-if-defined-__cplusplus.patch;patchdir=third_party/boringssl-with-bazel/src/ \
file://0001-target.h-define-proper-macro-for-ppc-ppc64.patch \
+ file://0001-PR-1644-unscaledcycleclock-remove-RISC-V-support.patch \
+ file://CVE-2024-11407.patch \
"
SRC_URI[sha256sum] = "c77618071d96b7a8be2c10701a98537823b9c65ba256c0b9067e0594cdbd954d"
@@ -35,6 +38,10 @@ BORING_SSL:aarch64 = "1"
BORING_SSL ?= "0"
export GRPC_BUILD_WITH_BORING_SSL_ASM = "${BORING_SSL}"
+do_compile:prepend() {
+ export GRPC_PYTHON_BUILD_EXT_COMPILER_JOBS="${@oe.utils.parallel_make(d, False)}"
+}
+
GRPC_CFLAGS ?= ""
GRPC_CFLAGS:append:toolchain-clang = " -fvisibility=hidden -fno-wrapv -fno-exceptions"
export GRPC_PYTHON_CFLAGS = "${GRPC_CFLAGS}"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0001-Properly-cast-arguments-to-H5Lunpack_elink_val.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0001-Properly-cast-arguments-to-H5Lunpack_elink_val.patch
new file mode 100644
index 0000000000..c39d9b1950
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0001-Properly-cast-arguments-to-H5Lunpack_elink_val.patch
@@ -0,0 +1,25 @@
+From 30a59c233fbe149109f378837642dc02b2caf3f5 Mon Sep 17 00:00:00 2001
+From: Orion Poplawski <orion@nwra.com>
+Date: Thu, 15 Feb 2024 20:47:50 -0700
+Subject: [PATCH] Properly cast arguments to H5Lunpack_elink_val
+
+Upstream-Status: Backport [https://github.com/h5py/h5py/pull/2380/commits/704e13ac83b42898514610c4df9f32f367e767e4]
+
+Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
+---
+ h5py/h5l.pyx | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/h5py/h5l.pyx b/h5py/h5l.pyx
+index 60b252f..af725bd 100644
+--- a/h5py/h5l.pyx
++++ b/h5py/h5l.pyx
+@@ -184,7 +184,7 @@ cdef class LinkProxy:
+ if info.type == H5L_TYPE_SOFT:
+ py_retval = buf
+ else:
+- H5Lunpack_elink_val(buf, buf_size, &wtf, &ext_file_name, &ext_obj_name)
++ H5Lunpack_elink_val(buf, buf_size, &wtf, <const char **>&ext_file_name, <const char **>&ext_obj_name)
+ py_retval = (bytes(ext_file_name), bytes(ext_obj_name))
+ finally:
+ efree(buf)
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0002-Use-libc.stdint-instead-of-numpy.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0002-Use-libc.stdint-instead-of-numpy.patch
new file mode 100644
index 0000000000..35263d8315
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0002-Use-libc.stdint-instead-of-numpy.patch
@@ -0,0 +1,25 @@
+From 8b4de2f6946b1c1f68279ecadc05c2817ae82189 Mon Sep 17 00:00:00 2001
+From: Orion Poplawski <orion@nwra.com>
+Date: Thu, 22 Feb 2024 08:41:17 -0700
+Subject: [PATCH] Use libc.stdint instead of numpy
+
+Upstream-Status: Backport [https://github.com/h5py/h5py/pull/2382/commits/387a22b8c1513800c0401f496b4ed512c1639798]
+
+Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
+---
+ h5py/api_types_ext.pxd | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/h5py/api_types_ext.pxd b/h5py/api_types_ext.pxd
+index 91acb12..55a239f 100644
+--- a/h5py/api_types_ext.pxd
++++ b/h5py/api_types_ext.pxd
+@@ -20,7 +20,7 @@ from libc.string cimport strlen, strchr, strcpy, strncpy, strcmp,\
+ ctypedef long size_t
+ from libc.time cimport time_t
+
+-from numpy cimport int8_t, uint8_t, int16_t, uint16_t, int32_t, uint32_t, int64_t, uint64_t
++from libc.stdint cimport int8_t, uint8_t, int16_t, uint16_t, int32_t, uint32_t, int64_t, uint64_t
+
+ IF UNAME_SYSNAME != "Windows":
+ cdef extern from "unistd.h":
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py_3.10.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py_3.10.0.bb
index 8a9158525e..3ba5ea7396 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py_3.10.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py_3.10.0.bb
@@ -6,8 +6,12 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=113251d71fb0384712c719b567261c5c"
SRC_URI[sha256sum] = "d93adc48ceeb33347eb24a634fb787efc7ae4644e6ea4ba733d099605045c049"
-SRC_URI += "file://0001-setup_build.py-avoid-absolute-path.patch \
- file://0001-Fix-Cython-3-compatibility.patch"
+SRC_URI += " \
+ file://0001-setup_build.py-avoid-absolute-path.patch \
+ file://0001-Fix-Cython-3-compatibility.patch \
+ file://0001-Properly-cast-arguments-to-H5Lunpack_elink_val.patch \
+ file://0002-Use-libc.stdint-instead-of-numpy.patch \
+"
inherit pkgconfig pypi setuptools3
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-haversine_2.8.1.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-haversine_2.8.1.bb
index e45ae79860..5fd5ddd71c 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-haversine_2.8.1.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-haversine_2.8.1.bb
@@ -1,6 +1,6 @@
SUMMARY = "Calculate the distance between 2 points on Earth"
LICENSE = "MIT"
-LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302"
+LIC_FILES_CHKSUM = "file://LICENSE;md5=20a52d2c688975e989fcbee3e6c8d1a1"
SRC_URI[sha256sum] = "ab750caa0c8f2168bd7b00a429757a83a8393be1aa30f91c2becf6b523189e2a"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-kivy_2.3.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-kivy_2.3.0.bb
index 991aa0f7d8..2c66db188b 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-kivy_2.3.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-kivy_2.3.0.bb
@@ -70,3 +70,10 @@ RDEPENDS:${PN} = " \
python3-pillow \
python3-pygments \
"
+
+do_compile:append() {
+ for f in `find ${B} -name *.c`
+ do
+ sed -i -e "/BEGIN: Cython Metadata/,/END: Cython Metadata/d" $f
+ done
+}
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-libevdev_0.11.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-libevdev_0.11.bb
index 27e336710c..5ad2a59951 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-libevdev_0.11.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-libevdev_0.11.bb
@@ -3,7 +3,7 @@ HOMEPAGE = "https://gitlab.freedesktop.org/libevdev/python-libevdev"
SECTION = "devel/python"
LICENSE = "MIT"
-LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302"
+LIC_FILES_CHKSUM = "file://COPYING;md5=d94c10c546b419eddc6296157ec40747"
SRC_URI[md5sum] = "34b48098c1fba26de79a0d67a17a588a"
SRC_URI[sha256sum] = "e9ca006a4df2488a60bd9a740011ee948d81904be2364f017e560169508f560f"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-lru-dict_1.3.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-lru-dict_1.3.0.bb
index e9535fa6f1..51f3860b07 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-lru-dict_1.3.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-lru-dict_1.3.0.bb
@@ -1,7 +1,7 @@
-SUMMARY = "A fixed size dict like container which evicts Least Recently Used (LRU) items once size limit is exceeded."
+DESCRIPTION = "A fixed size dict like container which evicts Least Recently Used (LRU) items once size limit is exceeded."
HOMEPAGE = "https://github.com/amitdev/lru-dict"
SECTION = "devel/python"
-LICENSE = "BSD-3-Clause"
+LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=9d10a486ee04034fdef5162fd791f153"
SRC_URI[sha256sum] = "54fd1966d6bd1fcde781596cb86068214edeebff1db13a2cea11079e3fd07b6b"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-mock_5.1.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-mock_5.1.0.bb
index d9ecb9d4c8..1b89260e1b 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-mock_5.1.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-mock_5.1.0.bb
@@ -1,7 +1,7 @@
DESCRIPTION = "A Python Mocking and Patching Library for Testing"
HOMEPAGE = "https://pypi.python.org/pypi/mock"
SECTION = "devel/python"
-LICENSE = "Apache-2.0"
+LICENSE = "BSD-2-Clause"
LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=de9dfbf780446b18aab11f00baaf5b7e"
inherit pypi setuptools3
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-nmap_1.6.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-nmap_1.6.0.bb
index 5fe9ab4e39..2293e3ddf8 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-nmap_1.6.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-nmap_1.6.0.bb
@@ -1,8 +1,8 @@
DESCRIPTION = "python-nmap is a python library which helps in using nmap port scanner"
HOMEPAGE = "https://www.nmmapper.com/"
SECTION = "devel/python"
-LICENSE = "MIT"
-LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302"
+LICENSE = "GPL-3.0-only"
+LIC_FILES_CHKSUM = "file://LICENSE;md5=1ebbd3e34237af26da5dc08a4e440464"
DEPENDS += "python3-wheel-native"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-parse-type_0.6.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-parse-type_0.6.2.bb
index a7d8cd86ce..57dfc5a508 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-parse-type_0.6.2.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-parse-type_0.6.2.bb
@@ -1,6 +1,6 @@
SUMMARY = "Simplifies building parse types based on the parse module"
HOMEPAGE = "https://github.com/jenisys/parse_type"
-LICENSE = "BSD-3-Clause"
+LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=2e469278ace89c246d52505acc39c3da"
SRC_URI[sha256sum] = "79b1f2497060d0928bc46016793f1fca1057c4aacdf15ef876aa48d75a73a355"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pillow_10.3.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pillow_10.3.0.bb
index debf488154..8b0bcf55dd 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pillow_10.3.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pillow_10.3.0.bb
@@ -1,8 +1,8 @@
-SUMMARY = "Python Imaging Library (Fork). Pillow is the friendly PIL fork by Alex \
+DESCRIPTION = "Python Imaging Library (Fork). Pillow is the friendly PIL fork by Alex \
Clark and Contributors. PIL is the Python Imaging Library by Fredrik Lundh and \
Contributors."
HOMEPAGE = "https://pillow.readthedocs.io"
-LICENSE = "MIT"
+LICENSE = "HPND"
LIC_FILES_CHKSUM = "file://LICENSE;md5=c349a4b4b9ec2377a8fd6a7df87dbffe"
SRC_URI = "git://github.com/python-pillow/Pillow.git;branch=main;protocol=https \
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-platformdirs_4.2.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-platformdirs_4.2.0.bb
index 19c95b374a..c69c390b80 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-platformdirs_4.2.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-platformdirs_4.2.0.bb
@@ -1,6 +1,6 @@
SUMMARY = "A small Python module for determining appropriate platform-specific dirs"
HOMEPAGE = "https://github.com/platformdirs/platformdirs"
-LICENSE = "BSD-3-Clause"
+LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=ea4f5a41454746a9ed111e3d8723d17a"
SRC_URI += " \
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0001-build_support-use-source-filename-instead-of-foo-for.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0001-build_support-use-source-filename-instead-of-foo-for.patch
new file mode 100644
index 0000000000..8bb7267086
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0001-build_support-use-source-filename-instead-of-foo-for.patch
@@ -0,0 +1,50 @@
+From 09cfcf7de2aab873a13949d5a128ccfb9e54732d Mon Sep 17 00:00:00 2001
+From: Martin Jansa <martin.jansa@gmail.com>
+Date: Mon, 5 May 2025 08:15:37 +0200
+Subject: [PATCH] build_support: use source filename instead of 'foo' for
+ discover tests
+
+* helps when debugging the issues
+* use the same order of CC arguments in compile_and_run and
+ does_build_succeed just for consistency
+* use pthread in both compile_and_run and does_build_succeed functions
+ it was added only to does_build_succeed in 5ec39f7af8cfd8525d225b1302fa93f7133b3849
+ not sure if it was intentional
+
+Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
+Upstream-Status: Submitted [https://github.com/osvenskan/posix_ipc/pull/77]
+---
+ build_support/discover_system_info.py | 6 +++---
+ 1 file changed, 3 insertions(+), 3 deletions(-)
+
+diff --git a/build_support/discover_system_info.py b/build_support/discover_system_info.py
+index bc4d174..6d059d9 100644
+--- a/build_support/discover_system_info.py
++++ b/build_support/discover_system_info.py
+@@ -60,7 +60,7 @@ def does_build_succeed(filename, linker_options=""):
+ # Rather than testing whether or not it's needed, I just specify it
+ # everywhere since it's harmless to specify it when it's not needed.
+ cc = os.getenv("CC", "cc")
+- cmd = "%s -Wall -o ./build_support/src/foo ./build_support/src/%s %s -lpthread" % (cc, filename, linker_options)
++ cmd = "%s -Wall -o ./build_support/src/%s ./build_support/src/%s %s -lpthread" % (cc, filename[:-2], filename, linker_options)
+
+ p = subprocess.Popen(cmd, shell=True, stdout=STDOUT, stderr=STDERR)
+
+@@ -73,7 +73,7 @@ def compile_and_run(filename, linker_options=""):
+ # Utility function that returns the stdout output from running the
+ # compiled source file; None if the compile fails.
+ cc = os.getenv("CC", "cc")
+- cmd = "%s -Wall -o ./build_support/src/foo %s ./build_support/src/%s" % (cc, linker_options, filename)
++ cmd = "%s -Wall -o ./build_support/src/%s ./build_support/src/%s %s -lpthread" % (cc, filename[:-2], filename, linker_options)
+
+ p = subprocess.Popen(cmd, shell=True, stdout=STDOUT, stderr=STDERR)
+
+@@ -82,7 +82,7 @@ def compile_and_run(filename, linker_options=""):
+ return None
+
+ try:
+- s = subprocess.Popen(["./build_support/src/foo"],
++ s = subprocess.Popen(["./build_support/src/%s" % filename[:-2]],
+ stdout=subprocess.PIPE).communicate()[0]
+ return s.strip().decode()
+ except Exception:
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0002-build_support-handle-empty-max_priority-value-as-Non.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0002-build_support-handle-empty-max_priority-value-as-Non.patch
new file mode 100644
index 0000000000..54c8ddaba7
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0002-build_support-handle-empty-max_priority-value-as-Non.patch
@@ -0,0 +1,49 @@
+From 8fc46d871639dbe799f6ff0a61b046412ef5dcc6 Mon Sep 17 00:00:00 2001
+From: Martin Jansa <martin.jansa@gmail.com>
+Date: Mon, 5 May 2025 08:16:30 +0200
+Subject: [PATCH] build_support: handle empty max_priority value as None
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+When cross-compiling these tests they fail when the host cannot execute
+the binaries built for target.
+
+On my local ubuntu-22.04 docker container running
+build_support/src/sniff_mq_prio_max results in:
+posix_ipc-1.2.0 $ ./build_support/src/foo
+bash: ./build_support/src/foo: cannot execute binary file: Exec format error
+which triggers the Exception in compile_and_run and returns None
+
+While on some other ubuntu-22.04 containers I see:
+posix_ipc-1.2.0$ ./build_support/src/sniff_mq_prio_max
+/usr/lib/ld-linux-aarch64.so.1: No such file or directory
+
+and the compile_and_run returns
+b''
+which then causes
+posix_ipc-1.2.0/build_support/discover_system_info.py", line 244, in sniff_mq_prio_max
+    if max_priority < 0:
+       ^^^^^^^^^^^^^^^^
+
+Handle the empty value the same as None to avoid this.
+
+Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
+Upstream-Status: Submitted [https://github.com/osvenskan/posix_ipc/pull/77]
+---
+ build_support/discover_system_info.py | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/build_support/discover_system_info.py b/build_support/discover_system_info.py
+index 6d059d9..f8a3c83 100644
+--- a/build_support/discover_system_info.py
++++ b/build_support/discover_system_info.py
+@@ -223,7 +223,7 @@ def sniff_mq_prio_max():
+ except ValueError:
+ max_priority = None
+
+- if max_priority is None:
++ if not max_priority:
+ # Looking for a #define didn't work; ask sysconf() instead.
+ # Note that sys.sysconf_names doesn't exist under Cygwin.
+ if hasattr(os, "sysconf_names") and \
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0003-build_support-use-does_build_succeed-in-compile_and_.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0003-build_support-use-does_build_succeed-in-compile_and_.patch
new file mode 100644
index 0000000000..b36d1cdb3a
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0003-build_support-use-does_build_succeed-in-compile_and_.patch
@@ -0,0 +1,62 @@
+From 760374e778fc28193cfea1416a739e206f9201c6 Mon Sep 17 00:00:00 2001
+From: Martin Jansa <martin.jansa@gmail.com>
+Date: Mon, 5 May 2025 08:28:56 +0200
+Subject: [PATCH] build_support: use does_build_succeed in compile_and_run
+
+* avoid the duplication and building the sniff_mq_prio_max.c twice
+
+Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
+Upstream-Status: Submitted [https://github.com/osvenskan/posix_ipc/pull/77]
+---
+ build_support/discover_system_info.py | 27 ++++++++++-----------------
+ 1 file changed, 10 insertions(+), 17 deletions(-)
+
+diff --git a/build_support/discover_system_info.py b/build_support/discover_system_info.py
+index f8a3c83..f6e6c8c 100644
+--- a/build_support/discover_system_info.py
++++ b/build_support/discover_system_info.py
+@@ -72,22 +72,17 @@ def does_build_succeed(filename, linker_options=""):
+ def compile_and_run(filename, linker_options=""):
+ # Utility function that returns the stdout output from running the
+ # compiled source file; None if the compile fails.
+- cc = os.getenv("CC", "cc")
+- cmd = "%s -Wall -o ./build_support/src/%s ./build_support/src/%s %s -lpthread" % (cc, filename[:-2], filename, linker_options)
+-
+- p = subprocess.Popen(cmd, shell=True, stdout=STDOUT, stderr=STDERR)
+-
+- if p.wait():
++ if does_build_succeed(filename, linker_options=""):
++ try:
++ s = subprocess.Popen(["./build_support/src/%s" % filename[:-2]],
++ stdout=subprocess.PIPE).communicate()[0]
++ return s.strip().decode()
++ except Exception:
++ # execution resulted in an error
++ return None
++ else:
+ # uh-oh, compile failed
+ return None
+-
+- try:
+- s = subprocess.Popen(["./build_support/src/%s" % filename[:-2]],
+- stdout=subprocess.PIPE).communicate()[0]
+- return s.strip().decode()
+- except Exception:
+- # execution resulted in an error
+- return None
+
+
+ def get_sysctl_value(name):
+@@ -211,11 +206,9 @@ def sniff_mq_prio_max():
+ # ref: http://www.opengroup.org/onlinepubs/009695399/basedefs/limits.h.html
+ DEFAULT_PRIORITY_MAX = 32
+
+- max_priority = None
+ # OS X up to and including 10.8 doesn't support POSIX messages queues and
+ # doesn't define MQ_PRIO_MAX. Maybe this aggravation will cease in 10.9?
+- if does_build_succeed("sniff_mq_prio_max.c"):
+- max_priority = compile_and_run("sniff_mq_prio_max.c")
++ max_priority = compile_and_run("sniff_mq_prio_max.c")
+
+ if max_priority:
+ try:
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0004-build_support-handle-runtime-errors-and-return-None-.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0004-build_support-handle-runtime-errors-and-return-None-.patch
new file mode 100644
index 0000000000..e84345a397
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0004-build_support-handle-runtime-errors-and-return-None-.patch
@@ -0,0 +1,47 @@
+From b079074048bc33b206b21f73fecb8173cf8adaf0 Mon Sep 17 00:00:00 2001
+From: Haixiao Yan <haixiao.yan.cn@windriver.com>
+Date: Mon, 15 Sep 2025 21:15:45 +0800
+Subject: [PATCH] build_support: handle runtime errors and return None for
+ invalid max_priority
+
+When cross-compiling, test binaries may fail to execute on the host system if
+the target toolchain was built against a newer glibc version than what is
+available on the host.
+
+For example, on Ubuntu 20.04 the following error occurs:
+
+./build_support/src/sniff_mq_prio_max: /lib/x86_64-linux-gnu/libc.so.6: version
+`GLIBC_2.34' not found (required by ./build_support/src/sniff_mq_prio_max)
+
+This change ensures that such runtime errors are gracefully handled, and
+max_priority is set to None when the test binary cannot be executed.
+
+Upstream-Status: Pending
+
+Signed-off-by: Haixiao Yan <haixiao.yan.cn@windriver.com>
+---
+ build_support/discover_system_info.py | 8 ++++++--
+ 1 file changed, 6 insertions(+), 2 deletions(-)
+
+diff --git a/build_support/discover_system_info.py b/build_support/discover_system_info.py
+index f6e6c8cbe6ba..4fec48b5529d 100644
+--- a/build_support/discover_system_info.py
++++ b/build_support/discover_system_info.py
+@@ -75,8 +75,12 @@ def compile_and_run(filename, linker_options=""):
+ if does_build_succeed(filename, linker_options=""):
+ try:
+ s = subprocess.Popen(["./build_support/src/%s" % filename[:-2]],
+- stdout=subprocess.PIPE).communicate()[0]
+- return s.strip().decode()
++ stdout=subprocess.PIPE, stderr=subprocess.PIPE)
++ stdout, stderr = s.communicate()
++ if s.returncode != 0:
++ # runtime error
++ return None
++ return stdout.strip().decode()
+ except Exception:
+ # execution resulted in an error
+ return None
+--
+2.25.1
+
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.1.1.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.1.1.bb
deleted file mode 100644
index a71187399b..0000000000
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.1.1.bb
+++ /dev/null
@@ -1,11 +0,0 @@
-DESCRIPTION = "POSIX IPC primitives (semaphores, shared memory and message queues) for Python"
-HOMEPAGE = "http://semanchuk.com/philip/posix_ipc/"
-SECTION = "devel/python"
-LICENSE = "BSD-3-Clause"
-LIC_FILES_CHKSUM = "file://LICENSE;md5=513d94a7390d4d72f3475e2d45c739b5"
-
-PYPI_PACKAGE = "posix_ipc"
-
-SRC_URI[sha256sum] = "e2456ba0cfb2ee5ba14121450e8d825b3c4a1461fca0761220aab66d4111cbb7"
-
-inherit setuptools3 pypi
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.2.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.2.0.bb
new file mode 100644
index 0000000000..cad1403813
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.2.0.bb
@@ -0,0 +1,17 @@
+DESCRIPTION = "POSIX IPC primitives (semaphores, shared memory and message queues) for Python"
+HOMEPAGE = "http://semanchuk.com/philip/posix_ipc/"
+SECTION = "devel/python"
+LICENSE = "BSD-3-Clause"
+LIC_FILES_CHKSUM = "file://LICENSE;md5=1a4f3bd729df04bf68f66ef877e9c7c9"
+
+PYPI_PACKAGE = "posix_ipc"
+
+SRC_URI[sha256sum] = "b7444e2703c156b3cb9fcb568e85d716232f3e78f04529ebc881cfb2aedb3838"
+
+SRC_URI += " \
+ file://0001-build_support-use-source-filename-instead-of-foo-for.patch \
+ file://0002-build_support-handle-empty-max_priority-value-as-Non.patch \
+ file://0003-build_support-use-does_build_succeed-in-compile_and_.patch \
+ file://0004-build_support-handle-runtime-errors-and-return-None-.patch \
+"
+inherit pypi python_setuptools_build_meta
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-protobuf_4.25.3.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-protobuf_4.25.8.bb
index b9b03badd0..aca30efdee 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-protobuf_4.25.3.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-protobuf_4.25.8.bb
@@ -6,7 +6,7 @@ LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://PKG-INFO;beginline=8;endline=8;md5=53dbfa56f61b90215a9f8f0d527c043d"
inherit pypi setuptools3
-SRC_URI[sha256sum] = "25b5d0b42fd000320bd7830b349e3b696435f3b329810427a6bcce6a5492cc5c"
+SRC_URI[sha256sum] = "6135cf8affe1fc6f76cced2641e4ea8d3e59518d1f24ae41ba97bcad82d397cd"
# http://errors.yoctoproject.org/Errors/Details/184715/
# Can't find required file: ../src/google/protobuf/descriptor.proto
@@ -35,3 +35,11 @@ DISTUTILS_INSTALL_ARGS += "--cpp_implementation"
do_compile:prepend:class-native () {
export KOKORO_BUILD_NUMBER="1"
}
+
+do_install:append () {
+ # Remove useless and problematic .pth file. python3-protobuf is installed in the standard
+ # location of site packages. No need for such .pth file.
+ # NOTE: do not drop this removal until the following issue in upstream cpython is resolved:
+ # https://github.com/python/cpython/issues/122220
+ rm -f ${D}${PYTHON_SITEPACKAGES_DIR}/protobuf-*-nspkg.pth
+}
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pycocotools_2.0.7.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pycocotools_2.0.7.bb
index bebfb128f2..15fdbcf89c 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pycocotools_2.0.7.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pycocotools_2.0.7.bb
@@ -9,3 +9,7 @@ SRC_URI[sha256sum] = "da8b7815196eebf0adabf67fcc459126cbc6498bbc6ab1fd144c371465
DEPENDS = "python3-cython-native python3-numpy-native virtual/crypt"
RDEPENDS:${PN} = "python3-matplotlib python3-pillow python3-profile"
+
+do_compile:append() {
+ sed -i -e "/BEGIN: Cython Metadata/,/END: Cython Metadata/d" ${B}/pycocotools/_mask.c
+}
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pycurl_7.45.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pycurl_7.45.2.bb
index a6863e21ff..10d3cd1027 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pycurl_7.45.2.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pycurl_7.45.2.bb
@@ -7,7 +7,7 @@ be used to fetch objects identified by a URL from a Python program \
SECTION = "devel/python"
HOMEPAGE = "http://pycurl.io/"
-LICENSE = "LGPL-2.0-only | MIT"
+LICENSE = "LGPL-2.1-only | MIT"
LIC_FILES_CHKSUM = "file://COPYING-LGPL;md5=4fbd65380cdd255951079008b364516c \
file://COPYING-MIT;md5=be42e1b1e58c8d59c2901fd747bfc55d \
"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core-crates.inc b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core-crates.inc
index dd2027948c..c6b30bc677 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core-crates.inc
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core-crates.inc
@@ -2,31 +2,29 @@
# from Cargo.lock
SRC_URI += " \
- crate://crates.io/ahash/0.8.7 \
+ crate://crates.io/ahash/0.8.10 \
crate://crates.io/aho-corasick/1.0.2 \
- crate://crates.io/allocator-api2/0.2.16 \
crate://crates.io/autocfg/1.1.0 \
crate://crates.io/base64/0.21.7 \
crate://crates.io/bitflags/1.3.2 \
+ crate://crates.io/bitvec/1.0.1 \
crate://crates.io/cc/1.0.79 \
crate://crates.io/cfg-if/1.0.0 \
- crate://crates.io/enum_dispatch/0.3.12 \
+ crate://crates.io/enum_dispatch/0.3.13 \
crate://crates.io/equivalent/1.0.1 \
crate://crates.io/form_urlencoded/1.2.1 \
+ crate://crates.io/funty/2.0.0 \
crate://crates.io/getrandom/0.2.10 \
crate://crates.io/hashbrown/0.14.3 \
crate://crates.io/heck/0.4.1 \
crate://crates.io/idna/0.5.0 \
- crate://crates.io/indexmap/2.0.0 \
+ crate://crates.io/indexmap/2.2.2 \
crate://crates.io/indoc/2.0.4 \
crate://crates.io/itoa/1.0.8 \
- crate://crates.io/jiter/0.0.6 \
- crate://crates.io/lexical-core/0.8.5 \
+ crate://crates.io/jiter/0.4.1 \
crate://crates.io/lexical-parse-float/0.8.5 \
crate://crates.io/lexical-parse-integer/0.8.6 \
crate://crates.io/lexical-util/0.8.5 \
- crate://crates.io/lexical-write-float/0.8.5 \
- crate://crates.io/lexical-write-integer/0.8.5 \
crate://crates.io/libc/0.2.147 \
crate://crates.io/lock_api/0.4.10 \
crate://crates.io/memchr/2.6.3 \
@@ -40,29 +38,32 @@ SRC_URI += " \
crate://crates.io/percent-encoding/2.3.1 \
crate://crates.io/portable-atomic/1.6.0 \
crate://crates.io/proc-macro2/1.0.76 \
- crate://crates.io/pyo3/0.20.3 \
- crate://crates.io/pyo3-build-config/0.20.3 \
- crate://crates.io/pyo3-ffi/0.20.3 \
- crate://crates.io/pyo3-macros/0.20.3 \
- crate://crates.io/pyo3-macros-backend/0.20.3 \
+ crate://crates.io/pyo3/0.21.2 \
+ crate://crates.io/pyo3-build-config/0.21.2 \
+ crate://crates.io/pyo3-ffi/0.21.2 \
+ crate://crates.io/pyo3-macros/0.21.2 \
+ crate://crates.io/pyo3-macros-backend/0.21.2 \
crate://crates.io/python3-dll-a/0.2.9 \
crate://crates.io/quote/1.0.35 \
+ crate://crates.io/radium/0.7.0 \
crate://crates.io/redox_syscall/0.3.5 \
- crate://crates.io/regex/1.10.2 \
- crate://crates.io/regex-automata/0.4.3 \
+ crate://crates.io/regex/1.10.4 \
+ crate://crates.io/regex-automata/0.4.5 \
crate://crates.io/regex-syntax/0.8.2 \
crate://crates.io/rustversion/1.0.13 \
crate://crates.io/ryu/1.0.14 \
crate://crates.io/scopeguard/1.1.0 \
- crate://crates.io/serde/1.0.195 \
- crate://crates.io/serde_derive/1.0.195 \
- crate://crates.io/serde_json/1.0.109 \
- crate://crates.io/smallvec/1.11.2 \
- crate://crates.io/speedate/0.13.0 \
+ crate://crates.io/serde/1.0.203 \
+ crate://crates.io/serde_derive/1.0.203 \
+ crate://crates.io/serde_json/1.0.116 \
+ crate://crates.io/smallvec/1.13.2 \
+ crate://crates.io/speedate/0.14.0 \
crate://crates.io/static_assertions/1.1.0 \
crate://crates.io/strum/0.25.0 \
crate://crates.io/strum_macros/0.25.3 \
+ crate://crates.io/strum_macros/0.26.1 \
crate://crates.io/syn/2.0.48 \
+ crate://crates.io/tap/1.0.1 \
crate://crates.io/target-lexicon/0.12.9 \
crate://crates.io/tinyvec/1.6.0 \
crate://crates.io/tinyvec_macros/0.1.1 \
@@ -71,7 +72,7 @@ SRC_URI += " \
crate://crates.io/unicode-normalization/0.1.22 \
crate://crates.io/unindent/0.2.3 \
crate://crates.io/url/2.5.0 \
- crate://crates.io/uuid/1.6.1 \
+ crate://crates.io/uuid/1.8.0 \
crate://crates.io/version_check/0.9.4 \
crate://crates.io/wasi/0.11.0+wasi-snapshot-preview1 \
crate://crates.io/windows-targets/0.48.1 \
@@ -82,35 +83,34 @@ SRC_URI += " \
crate://crates.io/windows_x86_64_gnu/0.48.0 \
crate://crates.io/windows_x86_64_gnullvm/0.48.0 \
crate://crates.io/windows_x86_64_msvc/0.48.0 \
+ crate://crates.io/wyz/0.5.1 \
crate://crates.io/zerocopy/0.7.32 \
crate://crates.io/zerocopy-derive/0.7.32 \
"
-SRC_URI[ahash-0.8.7.sha256sum] = "77c3a9648d43b9cd48db467b3f87fdd6e146bcc88ab0180006cef2179fe11d01"
+SRC_URI[ahash-0.8.10.sha256sum] = "8b79b82693f705137f8fb9b37871d99e4f9a7df12b917eed79c3d3954830a60b"
SRC_URI[aho-corasick-1.0.2.sha256sum] = "43f6cb1bf222025340178f382c426f13757b2960e89779dfcb319c32542a5a41"
-SRC_URI[allocator-api2-0.2.16.sha256sum] = "0942ffc6dcaadf03badf6e6a2d0228460359d5e34b57ccdc720b7382dfbd5ec5"
SRC_URI[autocfg-1.1.0.sha256sum] = "d468802bab17cbc0cc575e9b053f41e72aa36bfa6b7f55e3529ffa43161b97fa"
SRC_URI[base64-0.21.7.sha256sum] = "9d297deb1925b89f2ccc13d7635fa0714f12c87adce1c75356b39ca9b7178567"
SRC_URI[bitflags-1.3.2.sha256sum] = "bef38d45163c2f1dde094a7dfd33ccf595c92905c8f8f4fdc18d06fb1037718a"
+SRC_URI[bitvec-1.0.1.sha256sum] = "1bc2832c24239b0141d5674bb9174f9d68a8b5b3f2753311927c172ca46f7e9c"
SRC_URI[cc-1.0.79.sha256sum] = "50d30906286121d95be3d479533b458f87493b30a4b5f79a607db8f5d11aa91f"
SRC_URI[cfg-if-1.0.0.sha256sum] = "baf1de4339761588bc0619e3cbc0120ee582ebb74b53b4efbf79117bd2da40fd"
-SRC_URI[enum_dispatch-0.3.12.sha256sum] = "8f33313078bb8d4d05a2733a94ac4c2d8a0df9a2b84424ebf4f33bfc224a890e"
+SRC_URI[enum_dispatch-0.3.13.sha256sum] = "aa18ce2bc66555b3218614519ac839ddb759a7d6720732f979ef8d13be147ecd"
SRC_URI[equivalent-1.0.1.sha256sum] = "5443807d6dff69373d433ab9ef5378ad8df50ca6298caf15de6e52e24aaf54d5"
SRC_URI[form_urlencoded-1.2.1.sha256sum] = "e13624c2627564efccf4934284bdd98cbaa14e79b0b5a141218e507b3a823456"
+SRC_URI[funty-2.0.0.sha256sum] = "e6d5a32815ae3f33302d95fdcb2ce17862f8c65363dcfd29360480ba1001fc9c"
SRC_URI[getrandom-0.2.10.sha256sum] = "be4136b2a15dd319360be1c07d9933517ccf0be8f16bf62a3bee4f0d618df427"
SRC_URI[hashbrown-0.14.3.sha256sum] = "290f1a1d9242c78d09ce40a5e87e7554ee637af1351968159f4952f028f75604"
SRC_URI[heck-0.4.1.sha256sum] = "95505c38b4572b2d910cecb0281560f54b440a19336cbbcb27bf6ce6adc6f5a8"
SRC_URI[idna-0.5.0.sha256sum] = "634d9b1461af396cad843f47fdba5597a4f9e6ddd4bfb6ff5d85028c25cb12f6"
-SRC_URI[indexmap-2.0.0.sha256sum] = "d5477fe2230a79769d8dc68e0eabf5437907c0457a5614a9e8dddb67f65eb65d"
+SRC_URI[indexmap-2.2.2.sha256sum] = "824b2ae422412366ba479e8111fd301f7b5faece8149317bb81925979a53f520"
SRC_URI[indoc-2.0.4.sha256sum] = "1e186cfbae8084e513daff4240b4797e342f988cecda4fb6c939150f96315fd8"
SRC_URI[itoa-1.0.8.sha256sum] = "62b02a5381cc465bd3041d84623d0fa3b66738b52b8e2fc3bab8ad63ab032f4a"
-SRC_URI[jiter-0.0.6.sha256sum] = "87db066a99f69382be06d02313f8ce989996b53a04a8a70cfd1a6483a56227f7"
-SRC_URI[lexical-core-0.8.5.sha256sum] = "2cde5de06e8d4c2faabc400238f9ae1c74d5412d03a7bd067645ccbc47070e46"
+SRC_URI[jiter-0.4.1.sha256sum] = "abbbbe1bad457e3cd5503af716aedc735e849505a0d2172c55a753ae1b127458"
SRC_URI[lexical-parse-float-0.8.5.sha256sum] = "683b3a5ebd0130b8fb52ba0bdc718cc56815b6a097e28ae5a6997d0ad17dc05f"
SRC_URI[lexical-parse-integer-0.8.6.sha256sum] = "6d0994485ed0c312f6d965766754ea177d07f9c00c9b82a5ee62ed5b47945ee9"
SRC_URI[lexical-util-0.8.5.sha256sum] = "5255b9ff16ff898710eb9eb63cb39248ea8a5bb036bea8085b1a767ff6c4e3fc"
-SRC_URI[lexical-write-float-0.8.5.sha256sum] = "accabaa1c4581f05a3923d1b4cfd124c329352288b7b9da09e766b0668116862"
-SRC_URI[lexical-write-integer-0.8.5.sha256sum] = "e1b6f3d1f4422866b68192d62f77bc5c700bee84f3069f2469d7bc8c77852446"
SRC_URI[libc-0.2.147.sha256sum] = "b4668fb0ea861c1df094127ac5f1da3409a82116a4ba74fca2e58ef927159bb3"
SRC_URI[lock_api-0.4.10.sha256sum] = "c1cc9717a20b1bb222f333e6a92fd32f7d8a18ddc5a3191a11af45dcbf4dcd16"
SRC_URI[memchr-2.6.3.sha256sum] = "8f232d6ef707e1956a43342693d2a31e72989554d58299d7a88738cc95b0d35c"
@@ -124,29 +124,32 @@ SRC_URI[parking_lot_core-0.9.8.sha256sum] = "93f00c865fe7cabf650081affecd3871070
SRC_URI[percent-encoding-2.3.1.sha256sum] = "e3148f5046208a5d56bcfc03053e3ca6334e51da8dfb19b6cdc8b306fae3283e"
SRC_URI[portable-atomic-1.6.0.sha256sum] = "7170ef9988bc169ba16dd36a7fa041e5c4cbeb6a35b76d4c03daded371eae7c0"
SRC_URI[proc-macro2-1.0.76.sha256sum] = "95fc56cda0b5c3325f5fbbd7ff9fda9e02bb00bb3dac51252d2f1bfa1cb8cc8c"
-SRC_URI[pyo3-0.20.3.sha256sum] = "53bdbb96d49157e65d45cc287af5f32ffadd5f4761438b527b055fb0d4bb8233"
-SRC_URI[pyo3-build-config-0.20.3.sha256sum] = "deaa5745de3f5231ce10517a1f5dd97d53e5a2fd77aa6b5842292085831d48d7"
-SRC_URI[pyo3-ffi-0.20.3.sha256sum] = "62b42531d03e08d4ef1f6e85a2ed422eb678b8cd62b762e53891c05faf0d4afa"
-SRC_URI[pyo3-macros-0.20.3.sha256sum] = "7305c720fa01b8055ec95e484a6eca7a83c841267f0dd5280f0c8b8551d2c158"
-SRC_URI[pyo3-macros-backend-0.20.3.sha256sum] = "7c7e9b68bb9c3149c5b0cade5d07f953d6d125eb4337723c4ccdb665f1f96185"
+SRC_URI[pyo3-0.21.2.sha256sum] = "a5e00b96a521718e08e03b1a622f01c8a8deb50719335de3f60b3b3950f069d8"
+SRC_URI[pyo3-build-config-0.21.2.sha256sum] = "7883df5835fafdad87c0d888b266c8ec0f4c9ca48a5bed6bbb592e8dedee1b50"
+SRC_URI[pyo3-ffi-0.21.2.sha256sum] = "01be5843dc60b916ab4dad1dca6d20b9b4e6ddc8e15f50c47fe6d85f1fb97403"
+SRC_URI[pyo3-macros-0.21.2.sha256sum] = "77b34069fc0682e11b31dbd10321cbf94808394c56fd996796ce45217dfac53c"
+SRC_URI[pyo3-macros-backend-0.21.2.sha256sum] = "08260721f32db5e1a5beae69a55553f56b99bd0e1c3e6e0a5e8851a9d0f5a85c"
SRC_URI[python3-dll-a-0.2.9.sha256sum] = "d5f07cd4412be8fa09a721d40007c483981bbe072cd6a21f2e83e04ec8f8343f"
SRC_URI[quote-1.0.35.sha256sum] = "291ec9ab5efd934aaf503a6466c5d5251535d108ee747472c3977cc5acc868ef"
+SRC_URI[radium-0.7.0.sha256sum] = "dc33ff2d4973d518d823d61aa239014831e521c75da58e3df4840d3f47749d09"
SRC_URI[redox_syscall-0.3.5.sha256sum] = "567664f262709473930a4bf9e51bf2ebf3348f2e748ccc50dea20646858f8f29"
-SRC_URI[regex-1.10.2.sha256sum] = "380b951a9c5e80ddfd6136919eef32310721aa4aacd4889a8d39124b026ab343"
-SRC_URI[regex-automata-0.4.3.sha256sum] = "5f804c7828047e88b2d32e2d7fe5a105da8ee3264f01902f796c8e067dc2483f"
+SRC_URI[regex-1.10.4.sha256sum] = "c117dbdfde9c8308975b6a18d71f3f385c89461f7b3fb054288ecf2a2058ba4c"
+SRC_URI[regex-automata-0.4.5.sha256sum] = "5bb987efffd3c6d0d8f5f89510bb458559eab11e4f869acb20bf845e016259cd"
SRC_URI[regex-syntax-0.8.2.sha256sum] = "c08c74e62047bb2de4ff487b251e4a92e24f48745648451635cec7d591162d9f"
SRC_URI[rustversion-1.0.13.sha256sum] = "dc31bd9b61a32c31f9650d18add92aa83a49ba979c143eefd27fe7177b05bd5f"
SRC_URI[ryu-1.0.14.sha256sum] = "fe232bdf6be8c8de797b22184ee71118d63780ea42ac85b61d1baa6d3b782ae9"
SRC_URI[scopeguard-1.1.0.sha256sum] = "d29ab0c6d3fc0ee92fe66e2d99f700eab17a8d57d1c1d3b748380fb20baa78cd"
-SRC_URI[serde-1.0.195.sha256sum] = "63261df402c67811e9ac6def069e4786148c4563f4b50fd4bf30aa370d626b02"
-SRC_URI[serde_derive-1.0.195.sha256sum] = "46fe8f8603d81ba86327b23a2e9cdf49e1255fb94a4c5f297f6ee0547178ea2c"
-SRC_URI[serde_json-1.0.109.sha256sum] = "cb0652c533506ad7a2e353cce269330d6afd8bdfb6d75e0ace5b35aacbd7b9e9"
-SRC_URI[smallvec-1.11.2.sha256sum] = "4dccd0940a2dcdf68d092b8cbab7dc0ad8fa938bf95787e1b916b0e3d0e8e970"
-SRC_URI[speedate-0.13.0.sha256sum] = "242f76c50fd18cbf098607090ade73a08d39cfd84ea835f3796a2c855223b19b"
+SRC_URI[serde-1.0.203.sha256sum] = "7253ab4de971e72fb7be983802300c30b5a7f0c2e56fab8abfc6a214307c0094"
+SRC_URI[serde_derive-1.0.203.sha256sum] = "500cbc0ebeb6f46627f50f3f5811ccf6bf00643be300b4c3eabc0ef55dc5b5ba"
+SRC_URI[serde_json-1.0.116.sha256sum] = "3e17db7126d17feb94eb3fad46bf1a96b034e8aacbc2e775fe81505f8b0b2813"
+SRC_URI[smallvec-1.13.2.sha256sum] = "3c5e1a9a646d36c3599cd173a41282daf47c44583ad367b8e6837255952e5c67"
+SRC_URI[speedate-0.14.0.sha256sum] = "c323c4e6fece5a5a1a2a7f726d243144cce9fbcfe3ce4d9f3c6ede726a2bc780"
SRC_URI[static_assertions-1.1.0.sha256sum] = "a2eb9349b6444b326872e140eb1cf5e7c522154d69e7a0ffb0fb81c06b37543f"
SRC_URI[strum-0.25.0.sha256sum] = "290d54ea6f91c969195bdbcd7442c8c2a2ba87da8bf60a7ee86a235d4bc1e125"
SRC_URI[strum_macros-0.25.3.sha256sum] = "23dc1fa9ac9c169a78ba62f0b841814b7abae11bdd047b9c58f893439e309ea0"
+SRC_URI[strum_macros-0.26.1.sha256sum] = "7a3417fc93d76740d974a01654a09777cb500428cc874ca9f45edfe0c4d4cd18"
SRC_URI[syn-2.0.48.sha256sum] = "0f3531638e407dfc0814761abb7c00a5b54992b849452a0646b7f65c9f770f3f"
+SRC_URI[tap-1.0.1.sha256sum] = "55937e1799185b12863d447f42597ed69d9928686b8d88a1df17376a097d8369"
SRC_URI[target-lexicon-0.12.9.sha256sum] = "df8e77cb757a61f51b947ec4a7e3646efd825b73561db1c232a8ccb639e611a0"
SRC_URI[tinyvec-1.6.0.sha256sum] = "87cc5ceb3875bb20c2890005a4e226a4651264a5c75edb2421b52861a0a0cb50"
SRC_URI[tinyvec_macros-0.1.1.sha256sum] = "1f3ccbac311fea05f86f61904b462b55fb3df8837a366dfc601a0161d0532f20"
@@ -155,7 +158,7 @@ SRC_URI[unicode-ident-1.0.10.sha256sum] = "22049a19f4a68748a168c0fc439f9516686aa
SRC_URI[unicode-normalization-0.1.22.sha256sum] = "5c5713f0fc4b5db668a2ac63cdb7bb4469d8c9fed047b1d0292cc7b0ce2ba921"
SRC_URI[unindent-0.2.3.sha256sum] = "c7de7d73e1754487cb58364ee906a499937a0dfabd86bcb980fa99ec8c8fa2ce"
SRC_URI[url-2.5.0.sha256sum] = "31e6302e3bb753d46e83516cae55ae196fc0c309407cf11ab35cc51a4c2a4633"
-SRC_URI[uuid-1.6.1.sha256sum] = "5e395fcf16a7a3d8127ec99782007af141946b4795001f876d54fb0d55978560"
+SRC_URI[uuid-1.8.0.sha256sum] = "a183cf7feeba97b4dd1c0d46788634f6221d87fa961b305bed08c851829efcc0"
SRC_URI[version_check-0.9.4.sha256sum] = "49874b5167b65d7193b8aba1567f5c7d93d001cafc34600cee003eda787e483f"
SRC_URI[wasi-0.11.0+wasi-snapshot-preview1.sha256sum] = "9c8d87e72b64a3b4db28d11ce29237c246188f4f51057d65a7eab63b7987e423"
SRC_URI[windows-targets-0.48.1.sha256sum] = "05d4b17490f70499f20b9e791dcf6a299785ce8af4d709018206dc5b4953e95f"
@@ -166,5 +169,6 @@ SRC_URI[windows_i686_msvc-0.48.0.sha256sum] = "4542c6e364ce21bf45d69fdd2a8e455fa
SRC_URI[windows_x86_64_gnu-0.48.0.sha256sum] = "ca2b8a661f7628cbd23440e50b05d705db3686f894fc9580820623656af974b1"
SRC_URI[windows_x86_64_gnullvm-0.48.0.sha256sum] = "7896dbc1f41e08872e9d5e8f8baa8fdd2677f29468c4e156210174edc7f7b953"
SRC_URI[windows_x86_64_msvc-0.48.0.sha256sum] = "1a515f5799fe4961cb532f983ce2b23082366b898e52ffbce459c86f67c8378a"
+SRC_URI[wyz-0.5.1.sha256sum] = "05f360fc0b24296329c78fda852a1e9ae82de9cf7b27dae4b7f62f118f77b9ed"
SRC_URI[zerocopy-0.7.32.sha256sum] = "74d4d3961e53fa4c9a25a8637fc2bfaf2595b3d3ae34875568a5cf64787716be"
SRC_URI[zerocopy-derive-0.7.32.sha256sum] = "9ce1b18ccd8e73a9321186f97e46f9f04b778851177567b1975109d26a08d2a6"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Bumps-pyo3-https-github.com-pyo3-pyo3-from-0.20.2-to.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Bumps-pyo3-https-github.com-pyo3-pyo3-from-0.20.2-to.patch
deleted file mode 100644
index 32777e1d03..0000000000
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Bumps-pyo3-https-github.com-pyo3-pyo3-from-0.20.2-to.patch
+++ /dev/null
@@ -1,126 +0,0 @@
-From a5690f973384bf8cbf4deb3b83d822b7aaefbdd8 Mon Sep 17 00:00:00 2001
-From: Khem Raj <raj.khem@gmail.com>
-Date: Tue, 27 Feb 2024 11:00:46 -0800
-Subject: [PATCH] Bumps [pyo3](https://github.com/pyo3/pyo3) from 0.20.2 to
- 0.20.3.
-
-Upstream-Status: Pending
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
----
- Cargo.lock | 26 +++++++++++++++++---------
- Cargo.toml | 2 +-
- 2 files changed, 18 insertions(+), 10 deletions(-)
-
---- a/Cargo.lock
-+++ b/Cargo.lock
-@@ -322,6 +322,12 @@ source = "registry+https://github.com/ru
- checksum = "e3148f5046208a5d56bcfc03053e3ca6334e51da8dfb19b6cdc8b306fae3283e"
-
- [[package]]
-+name = "portable-atomic"
-+version = "1.6.0"
-+source = "registry+https://github.com/rust-lang/crates.io-index"
-+checksum = "7170ef9988bc169ba16dd36a7fa041e5c4cbeb6a35b76d4c03daded371eae7c0"
-+
-+[[package]]
- name = "proc-macro2"
- version = "1.0.76"
- source = "registry+https://github.com/rust-lang/crates.io-index"
-@@ -357,9 +363,9 @@ dependencies = [
-
- [[package]]
- name = "pyo3"
--version = "0.20.2"
-+version = "0.20.3"
- source = "registry+https://github.com/rust-lang/crates.io-index"
--checksum = "9a89dc7a5850d0e983be1ec2a463a171d20990487c3cfcd68b5363f1ee3d6fe0"
-+checksum = "53bdbb96d49157e65d45cc287af5f32ffadd5f4761438b527b055fb0d4bb8233"
- dependencies = [
- "cfg-if",
- "indoc",
-@@ -367,6 +373,7 @@ dependencies = [
- "memoffset",
- "num-bigint",
- "parking_lot",
-+ "portable-atomic",
- "pyo3-build-config",
- "pyo3-ffi",
- "pyo3-macros",
-@@ -375,9 +382,9 @@ dependencies = [
-
- [[package]]
- name = "pyo3-build-config"
--version = "0.20.2"
-+version = "0.20.3"
- source = "registry+https://github.com/rust-lang/crates.io-index"
--checksum = "07426f0d8fe5a601f26293f300afd1a7b1ed5e78b2a705870c5f30893c5163be"
-+checksum = "deaa5745de3f5231ce10517a1f5dd97d53e5a2fd77aa6b5842292085831d48d7"
- dependencies = [
- "once_cell",
- "python3-dll-a",
-@@ -386,9 +393,9 @@ dependencies = [
-
- [[package]]
- name = "pyo3-ffi"
--version = "0.20.2"
-+version = "0.20.3"
- source = "registry+https://github.com/rust-lang/crates.io-index"
--checksum = "dbb7dec17e17766b46bca4f1a4215a85006b4c2ecde122076c562dd058da6cf1"
-+checksum = "62b42531d03e08d4ef1f6e85a2ed422eb678b8cd62b762e53891c05faf0d4afa"
- dependencies = [
- "libc",
- "pyo3-build-config",
-@@ -396,9 +403,9 @@ dependencies = [
-
- [[package]]
- name = "pyo3-macros"
--version = "0.20.2"
-+version = "0.20.3"
- source = "registry+https://github.com/rust-lang/crates.io-index"
--checksum = "05f738b4e40d50b5711957f142878cfa0f28e054aa0ebdfc3fd137a843f74ed3"
-+checksum = "7305c720fa01b8055ec95e484a6eca7a83c841267f0dd5280f0c8b8551d2c158"
- dependencies = [
- "proc-macro2",
- "pyo3-macros-backend",
-@@ -408,12 +415,13 @@ dependencies = [
-
- [[package]]
- name = "pyo3-macros-backend"
--version = "0.20.2"
-+version = "0.20.3"
- source = "registry+https://github.com/rust-lang/crates.io-index"
--checksum = "0fc910d4851847827daf9d6cdd4a823fbdaab5b8818325c5e97a86da79e8881f"
-+checksum = "7c7e9b68bb9c3149c5b0cade5d07f953d6d125eb4337723c4ccdb665f1f96185"
- dependencies = [
- "heck",
- "proc-macro2",
-+ "pyo3-build-config",
- "quote",
- "syn",
- ]
---- a/Cargo.toml
-+++ b/Cargo.toml
-@@ -26,7 +26,7 @@ include = [
- ]
-
- [dependencies]
--pyo3 = { version = "0.20.2", features = ["generate-import-lib", "num-bigint"] }
-+pyo3 = { version = "0.20.3", features = ["generate-import-lib", "num-bigint"] }
- regex = "1.10.2"
- strum = { version = "0.25.0", features = ["derive"] }
- strum_macros = "0.25.3"
-@@ -70,12 +70,12 @@ debug = true
- strip = false
-
- [dev-dependencies]
--pyo3 = { version = "0.20.2", features = ["auto-initialize"] }
-+pyo3 = { version = "0.20.3", features = ["auto-initialize"] }
-
- [build-dependencies]
- version_check = "0.9.4"
- # used where logic has to be version/distribution specific, e.g. pypy
--pyo3-build-config = { version = "0.20.2" }
-+pyo3-build-config = { version = "0.20.3" }
-
- [lints.clippy]
- dbg_macro = "warn"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Set-rust-version-from-1.76-to-1.75-in-Cargo.toml.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Set-rust-version-from-1.76-to-1.75-in-Cargo.toml.patch
new file mode 100644
index 0000000000..c4e6f2f6ab
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Set-rust-version-from-1.76-to-1.75-in-Cargo.toml.patch
@@ -0,0 +1,29 @@
+From 6e1852228a2aa38cc76b9a968bba6b603efa5b28 Mon Sep 17 00:00:00 2001
+From: Frank de Brabander <debrabander@gmail.com>
+Date: Thu, 25 Jul 2024 13:50:44 +0200
+Subject: [PATCH] Set rust version from 1.76 to 1.75 in Cargo.toml
+
+Current openembedded-core uses 1.75 and this packages doesn't actually
+require a newer version.
+
+Upstream-Status: Inappropriate
+---
+ Cargo.toml | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/Cargo.toml b/Cargo.toml
+index 8f0ea44..10b277c 100644
+--- a/Cargo.toml
++++ b/Cargo.toml
+@@ -24,7 +24,7 @@ include = [
+ "!tests/.pytest_cache",
+ "!*.so",
+ ]
+-rust-version = "1.76"
++rust-version = "1.75"
+
+ [dependencies]
+ pyo3 = { version = "0.21.2", features = ["generate-import-lib", "num-bigint"] }
+--
+2.39.2
+
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0002-Dont-embed-RUSTFLAGS-in-final-binary.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0002-Dont-embed-RUSTFLAGS-in-final-binary.patch
new file mode 100644
index 0000000000..1c195e294b
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0002-Dont-embed-RUSTFLAGS-in-final-binary.patch
@@ -0,0 +1,47 @@
+From b3282b301096253a11b1f887f915d0a2a2183597 Mon Sep 17 00:00:00 2001
+From: Frank de Brabander <debrabander@gmail.com>
+Date: Thu, 8 Aug 2024 08:04:48 +0200
+Subject: [PATCH] Dont embed RUSTFLAGS in final binary
+
+Upstream-Status: Backport [https://github.com/pydantic/pydantic-core/commit/e07c41b3bad75948201a2201387225694c2fb501]
+---
+ build.rs | 9 +++++++++
+ src/lib.rs | 5 ++++-
+ 2 files changed, 13 insertions(+), 1 deletion(-)
+
+diff --git a/build.rs b/build.rs
+index 7f59e1f..7fe6490 100644
+--- a/build.rs
++++ b/build.rs
+@@ -35,6 +35,15 @@ fn main() {
+ if let Some(true) = version_check::supports_feature("coverage_attribute") {
+ println!("cargo:rustc-cfg=has_coverage_attribute");
+ }
++
++ if std::env::var("RUSTFLAGS")
++ .unwrap_or_default()
++ .contains("-Cprofile-use=")
++ {
++ println!("cargo:rustc-cfg=specified_profile_use");
++ }
++ println!("cargo:rustc-check-cfg=cfg(specified_profile_use)");
++
+ generate_self_schema();
+ println!("cargo:rustc-env=PROFILE={}", std::env::var("PROFILE").unwrap());
+ }
+diff --git a/src/lib.rs b/src/lib.rs
+index d55e836..206a7a1 100644
+--- a/src/lib.rs
++++ b/src/lib.rs
+@@ -111,7 +111,10 @@ pub fn build_info() -> String {
+ format!(
+ "profile={} pgo={}",
+ env!("PROFILE"),
+- option_env!("RUSTFLAGS").unwrap_or("").contains("-Cprofile-use="),
++ // We use a `cfg!` here not `env!`/`option_env!` as those would
++ // embed `RUSTFLAGS` into the generated binary which causes problems
++ // with reproducable builds.
++ cfg!(specified_profile_use),
+ )
+ }
+
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core_2.16.3.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core_2.18.4.bb
index faa291ea6d..adaf4a62cb 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core_2.16.3.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core_2.18.4.bb
@@ -8,8 +8,9 @@ HOMEPAGE = "https://github.com/pydantic/pydantic-core"
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=ab599c188b4a314d2856b3a55030c75c"
-SRC_URI += "file://0001-Bumps-pyo3-https-github.com-pyo3-pyo3-from-0.20.2-to.patch"
-SRC_URI[sha256sum] = "1cac689f80a3abab2d3c0048b29eea5751114054f032a941a32de4c852c59cad"
+SRC_URI += "file://0001-Set-rust-version-from-1.76-to-1.75-in-Cargo.toml.patch \
+ file://0002-Dont-embed-RUSTFLAGS-in-final-binary.patch"
+SRC_URI[sha256sum] = "ec3beeada09ff865c344ff3bc2f427f5e6c26401cc6113d77e372c3fdac73864"
DEPENDS = "python3-maturin-native python3-typing-extensions"
@@ -19,7 +20,10 @@ inherit pypi cargo-update-recipe-crates python_maturin
PYPI_PACKAGE = "pydantic_core"
-RDEPENDS:${PN} += "python3-typing-extensions"
+RDEPENDS:${PN} += " \
+ python3-compression \
+ python3-typing-extensions \
+"
INSANE_SKIP:${PN} = "already-stripped"
@@ -33,6 +37,8 @@ RDEPENDS:${PN}-ptest += "\
python3-pytest-timeout \
python3-pytest-benchmark \
python3-unittest-automake-output \
+ python3-zoneinfo \
+ tzdata \
"
do_install:append() {
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic_2.7.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic_2.7.4.bb
index 36ad83527d..04c9c91c0e 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic_2.7.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic_2.7.4.bb
@@ -11,7 +11,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=09280955509d1c4ca14bae02f21d49a6"
inherit pypi python_hatchling
-SRC_URI[sha256sum] = "b5ecdd42262ca2462e2624793551e80911a1e989f462910bb81aef974b4bb383"
+SRC_URI[sha256sum] = "0c84efd9548d545f63ac0060c1e4d39bb9b14db8b3c0652338aecc07b5adec52"
DEPENDS += "python3-hatch-fancy-pypi-readme-native"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pylint_3.1.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pylint_3.1.0.bb
index 12f4f908af..4c49acaf1e 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pylint_3.1.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pylint_3.1.0.bb
@@ -3,7 +3,7 @@ HOMEPAGE= "http://www.pylint.org/"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://LICENSE;md5=c107cf754550e65755c42985a5d4e9c9"
-SRC_URI += "git://github.com/pylint-dev/pylint;branch=maintenance/3.1.x;protocol=https \
+SRC_URI += "git://github.com/pylint-dev/pylint;branch=main;protocol=https \
file://0001-Adjust-test-expectations-for-ptest.patch \
file://run-ptest \
"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj/rpath.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj/rpath.patch
new file mode 100644
index 0000000000..347996a808
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj/rpath.patch
@@ -0,0 +1,18 @@
+Description: Don't set RPATH in libraries.
+Author: Bas Couwenberg <sebastic@debian.org>
+Forwarded: not-needed
+
+Upstream-Status: Inappropriate [OE-Specific]
+Signed-off-by: Khem Raj <raj.khem@gmail.com>
+--- a/setup.py
++++ b/setup.py
+@@ -194,9 +194,6 @@ def get_extension_modules():
+ ext_options = {
+ "include_dirs": include_dirs,
+ "library_dirs": library_dirs,
+- "runtime_library_dirs": (
+- library_dirs if os.name != "nt" and sys.platform != "cygwin" else None
+- ),
+ "libraries": get_libraries(library_dirs),
+ }
+ # setup cythonized modules
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj_3.6.1.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj_3.6.1.bb
index a4121c3934..f6b6ee8a46 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj_3.6.1.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj_3.6.1.bb
@@ -8,6 +8,8 @@ PYPI_PACKAGE = "pyproj"
inherit pypi setuptools3
+SRC_URI += "file://rpath.patch"
+
SRC_URI[sha256sum] = "44aa7c704c2b7d8fb3d483bbf75af6cb2350d30a63b144279a09b75fead501bf"
RDEPENDS:${PN} = " \
@@ -21,3 +23,11 @@ RDEPENDS:${PN} = " \
export PROJ_INCDIR = "${STAGING_INCDIR}"
export PROJ_LIBDIR = "${STAGING_LIBDIR}"
export PROJ_DIR = "${STAGING_BINDIR_NATIVE}/.."
+
+do_compile:append() {
+ for f in `find ${B} -name *.c`
+ do
+ sed -i -e "/BEGIN: Cython Metadata/,/END: Cython Metadata/d" $f
+ done
+ python_pep517_do_compile
+}
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pyyaml-include_1.3.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyyaml-include_1.3.2.bb
index 3a5bd99a78..309d0ac596 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pyyaml-include_1.3.2.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyyaml-include_1.3.2.bb
@@ -26,4 +26,4 @@ RDEPENDS:${PN}-ptest += " \
python3-pytest \
python3-unittest-automake-output \
"
-
+BBCLASSEXTEND = "native nativesdk"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2024-4340.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2024-4340.patch
new file mode 100644
index 0000000000..670904071a
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2024-4340.patch
@@ -0,0 +1,48 @@
+From b4a39d9850969b4e1d6940d32094ee0b42a2cf03 Mon Sep 17 00:00:00 2001
+From: Andi Albrecht <albrecht.andi@gmail.com>
+Date: Sat, 13 Apr 2024 13:59:00 +0200
+Subject: [PATCH] Raise SQLParseError instead of RecursionError.
+
+CVE: CVE-2024-4340
+
+Upstream-Status: Backport [https://github.com/andialbrecht/sqlparse/commit/b4a39d9850969b4e1d6940d32094ee0b42a2cf03]
+
+Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
+---
+ sqlparse/sql.py | 14 +++++++++-----
+ 1 file changed, 9 insertions(+), 5 deletions(-)
+
+diff --git a/sqlparse/sql.py b/sqlparse/sql.py
+index 1ccfbdb..2090621 100644
+--- a/sqlparse/sql.py
++++ b/sqlparse/sql.py
+@@ -10,6 +10,7 @@
+ import re
+
+ from sqlparse import tokens as T
++from sqlparse.exceptions import SQLParseError
+ from sqlparse.utils import imt, remove_quotes
+
+
+@@ -209,11 +210,14 @@ class TokenList(Token):
+
+ This method is recursively called for all child tokens.
+ """
+- for token in self.tokens:
+- if token.is_group:
+- yield from token.flatten()
+- else:
+- yield token
++ try:
++ for token in self.tokens:
++ if token.is_group:
++ yield from token.flatten()
++ else:
++ yield token
++ except RecursionError as err:
++ raise SQLParseError('Maximum recursion depth exceeded') from err
+
+ def get_sublists(self):
+ for token in self.tokens:
+--
+2.25.1
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse_0.4.4.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse_0.4.4.bb
index c04971ee8f..fa633026c8 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse_0.4.4.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse_0.4.4.bb
@@ -5,6 +5,7 @@ LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://LICENSE;md5=2b136f573f5386001ea3b7b9016222fc"
SRC_URI += "file://0001-sqlparse-change-shebang-to-python3.patch \
+ file://CVE-2024-4340.patch \
file://run-ptest \
"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-tornado_6.4.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-tornado_6.4.2.bb
index b01c1cec2a..751f32913a 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-tornado_6.4.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-tornado_6.4.2.bb
@@ -6,9 +6,9 @@ HOMEPAGE = "http://www.tornadoweb.org/en/stable/"
LICENSE = "Apache-2.0"
LIC_FILES_CHKSUM = "file://LICENSE;md5=3b83ef96387f14655fc854ddc3c6bd57"
-SRC_URI[sha256sum] = "72291fa6e6bc84e626589f1c29d90a5a6d593ef5ae68052ee2ef000dfd273dee"
+SRC_URI[sha256sum] = "92bad5b4746e9879fd7bf1eb21dce4e3fc5128d71601f80005afa39237ad620b"
-inherit pypi setuptools3
+inherit pypi python_setuptools_build_meta
# Requires _compression which is currently located in misc
RDEPENDS:${PN} += " \
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0001.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0001.patch
new file mode 100644
index 0000000000..1f6bf6bbfc
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0001.patch
@@ -0,0 +1,89 @@
+From 046a164f89a0f08d3239ecebd750360f8914df33 Mon Sep 17 00:00:00 2001
+From: Adi Roiban <adiroiban@gmail.com>
+Date: Mon Jul 29 14:28:03 2024 +0100
+Subject: [PATCH] Merge commit from fork
+
+Added HTML output encoding the "URL" parameter of the "redirectTo" function
+
+CVE: CVE-2024-41671
+
+Upstream-Status: Backport [https://github.com/twisted/twisted/commit/046a164f89a0f08d3239ecebd750360f8914df33]
+
+Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
+---
+ src/twisted/web/_template_util.py | 2 +-
+ src/twisted/web/test/test_util.py | 39 ++++++++++++++++++++++++++++++-
+ 2 files changed, 39 insertions(+), 2 deletions(-)
+
+diff --git a/src/twisted/web/_template_util.py b/src/twisted/web/_template_util.py
+index 230c33f..7266079 100644
+--- a/src/twisted/web/_template_util.py
++++ b/src/twisted/web/_template_util.py
+@@ -92,7 +92,7 @@ def redirectTo(URL: bytes, request: IRequest) -> bytes:
+ </body>
+ </html>
+ """ % {
+- b"url": URL
++ b"url": escape(URL.decode("utf-8")).encode("utf-8")
+ }
+ return content
+
+diff --git a/src/twisted/web/test/test_util.py b/src/twisted/web/test/test_util.py
+index 1e76300..9847dcb 100644
+--- a/src/twisted/web/test/test_util.py
++++ b/src/twisted/web/test/test_util.py
+@@ -5,7 +5,6 @@
+ Tests for L{twisted.web.util}.
+ """
+
+-
+ import gc
+
+ from twisted.internet import defer
+@@ -64,6 +63,44 @@ class RedirectToTests(TestCase):
+ targetURL = "http://target.example.com/4321"
+ self.assertRaises(TypeError, redirectTo, targetURL, request)
+
++ def test_legitimateRedirect(self):
++ """
++ Legitimate URLs are fully interpolated in the `redirectTo` response body without transformation
++ """
++ request = DummyRequest([b""])
++ html = redirectTo(b"https://twisted.org/", request)
++ expected = b"""
++<html>
++ <head>
++ <meta http-equiv=\"refresh\" content=\"0;URL=https://twisted.org/\">
++ </head>
++ <body bgcolor=\"#FFFFFF\" text=\"#000000\">
++ <a href=\"https://twisted.org/\">click here</a>
++ </body>
++</html>
++"""
++ self.assertEqual(html, expected)
++
++ def test_maliciousRedirect(self):
++ """
++ Malicious URLs are HTML-escaped before interpolating them in the `redirectTo` response body
++ """
++ request = DummyRequest([b""])
++ html = redirectTo(
++ b'https://twisted.org/"><script>alert(document.location)</script>', request
++ )
++ expected = b"""
++<html>
++ <head>
++ <meta http-equiv=\"refresh\" content=\"0;URL=https://twisted.org/&quot;&gt;&lt;script&gt;alert(document.location)&lt;/script&gt;\">
++ </head>
++ <body bgcolor=\"#FFFFFF\" text=\"#000000\">
++ <a href=\"https://twisted.org/&quot;&gt;&lt;script&gt;alert(document.location)&lt;/script&gt;\">click here</a>
++ </body>
++</html>
++"""
++ self.assertEqual(html, expected)
++
+
+ class ParentRedirectTests(SynchronousTestCase):
+ """
+--
+2.40.0
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0002.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0002.patch
new file mode 100644
index 0000000000..147c21d73d
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0002.patch
@@ -0,0 +1,251 @@
+From 4a930de12fb67e88fefcb8822104152f42b27abc Mon Sep 17 00:00:00 2001
+From: Adi Roiban <adiroiban@gmail.com>
+Date: Mon Jul 29 14:27:23 2024 +0100
+Subject: [PATCH] Merge commit from fork
+
+Address GHSA-c8m8-j448-xjx7
+
+CVE: CVE-2024-41671
+
+Upstream-Status: Backport [https://github.com/twisted/twisted/commit/4a930de12fb67e88fefcb8822104152f42b27abc]
+
+Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
+---
+ src/twisted/web/http.py | 21 +++--
+ src/twisted/web/test/test_http.py | 122 ++++++++++++++++++++++++++----
+ 2 files changed, 122 insertions(+), 21 deletions(-)
+
+diff --git a/src/twisted/web/http.py b/src/twisted/web/http.py
+index 1c59838..3b784f5 100644
+--- a/src/twisted/web/http.py
++++ b/src/twisted/web/http.py
+@@ -2000,16 +2000,21 @@ class _ChunkedTransferDecoder:
+ @returns: C{False}, as there is either insufficient data to continue,
+ or no data remains.
+ """
+- if (
+- self._receivedTrailerHeadersSize + len(self._buffer)
+- > self._maxTrailerHeadersSize
+- ):
+- raise _MalformedChunkedDataError("Trailer headers data is too long.")
+-
+ eolIndex = self._buffer.find(b"\r\n", self._start)
+
+ if eolIndex == -1:
+ # Still no end of network line marker found.
++ #
++ # Check if we've run up against the trailer size limit: if the next
++ # read contains the terminating CRLF then we'll have this many bytes
++ # of trailers (including the CRLFs).
++ minTrailerSize = (
++ self._receivedTrailerHeadersSize
++ + len(self._buffer)
++ + (1 if self._buffer.endswith(b"\r") else 2)
++ )
++ if minTrailerSize > self._maxTrailerHeadersSize:
++ raise _MalformedChunkedDataError("Trailer headers data is too long.")
+ # Continue processing more data.
+ return False
+
+@@ -2019,6 +2024,8 @@ class _ChunkedTransferDecoder:
+ del self._buffer[0 : eolIndex + 2]
+ self._start = 0
+ self._receivedTrailerHeadersSize += eolIndex + 2
++ if self._receivedTrailerHeadersSize > self._maxTrailerHeadersSize:
++ raise _MalformedChunkedDataError("Trailer headers data is too long.")
+ return True
+
+ # eolIndex in this part of code is equal to 0
+@@ -2342,8 +2349,8 @@ class HTTPChannel(basic.LineReceiver, policies.TimeoutMixin):
+ self.__header = line
+
+ def _finishRequestBody(self, data):
+- self.allContentReceived()
+ self._dataBuffer.append(data)
++ self.allContentReceived()
+
+ def _maybeChooseTransferDecoder(self, header, data):
+ """
+diff --git a/src/twisted/web/test/test_http.py b/src/twisted/web/test/test_http.py
+index 33d0a49..1130d31 100644
+--- a/src/twisted/web/test/test_http.py
++++ b/src/twisted/web/test/test_http.py
+@@ -135,7 +135,7 @@ class DummyHTTPHandler(http.Request):
+ data = self.content.read()
+ length = self.getHeader(b"content-length")
+ if length is None:
+- length = networkString(str(length))
++ length = str(length).encode()
+ request = b"'''\n" + length + b"\n" + data + b"'''\n"
+ self.setResponseCode(200)
+ self.setHeader(b"Request", self.uri)
+@@ -563,17 +563,23 @@ class HTTP0_9Tests(HTTP1_0Tests):
+
+ class PipeliningBodyTests(unittest.TestCase, ResponseTestMixin):
+ """
+- Tests that multiple pipelined requests with bodies are correctly buffered.
++ Pipelined requests get buffered and executed in the order received,
++ not processed in parallel.
+ """
+
+ requests = (
+ b"POST / HTTP/1.1\r\n"
+ b"Content-Length: 10\r\n"
+ b"\r\n"
+- b"0123456789POST / HTTP/1.1\r\n"
+- b"Content-Length: 10\r\n"
+- b"\r\n"
+ b"0123456789"
++ # Chunk encoded request.
++ b"POST / HTTP/1.1\r\n"
++ b"Transfer-Encoding: chunked\r\n"
++ b"\r\n"
++ b"a\r\n"
++ b"0123456789\r\n"
++ b"0\r\n"
++ b"\r\n"
+ )
+
+ expectedResponses = [
+@@ -590,14 +596,16 @@ class PipeliningBodyTests(unittest.TestCase, ResponseTestMixin):
+ b"Request: /",
+ b"Command: POST",
+ b"Version: HTTP/1.1",
+- b"Content-Length: 21",
+- b"'''\n10\n0123456789'''\n",
++ b"Content-Length: 23",
++ b"'''\nNone\n0123456789'''\n",
+ ),
+ ]
+
+- def test_noPipelining(self):
++ def test_stepwiseTinyTube(self):
+ """
+- Test that pipelined requests get buffered, not processed in parallel.
++ Imitate a slow connection that delivers one byte at a time.
++ The request handler (L{DelayedHTTPHandler}) is puppeted to
++ step through the handling of each request.
+ """
+ b = StringTransport()
+ a = http.HTTPChannel()
+@@ -606,10 +614,9 @@ class PipeliningBodyTests(unittest.TestCase, ResponseTestMixin):
+ # one byte at a time, to stress it.
+ for byte in iterbytes(self.requests):
+ a.dataReceived(byte)
+- value = b.value()
+
+ # So far only one request should have been dispatched.
+- self.assertEqual(value, b"")
++ self.assertEqual(b.value(), b"")
+ self.assertEqual(1, len(a.requests))
+
+ # Now, process each request one at a time.
+@@ -618,8 +625,91 @@ class PipeliningBodyTests(unittest.TestCase, ResponseTestMixin):
+ request = a.requests[0].original
+ request.delayedProcess()
+
+- value = b.value()
+- self.assertResponseEquals(value, self.expectedResponses)
++ self.assertResponseEquals(b.value(), self.expectedResponses)
++
++ def test_stepwiseDumpTruck(self):
++ """
++ Imitate a fast connection where several pipelined
++ requests arrive in a single read. The request handler
++ (L{DelayedHTTPHandler}) is puppeted to step through the
++ handling of each request.
++ """
++ b = StringTransport()
++ a = http.HTTPChannel()
++ a.requestFactory = DelayedHTTPHandlerProxy
++ a.makeConnection(b)
++
++ a.dataReceived(self.requests)
++
++ # So far only one request should have been dispatched.
++ self.assertEqual(b.value(), b"")
++ self.assertEqual(1, len(a.requests))
++
++ # Now, process each request one at a time.
++ while a.requests:
++ self.assertEqual(1, len(a.requests))
++ request = a.requests[0].original
++ request.delayedProcess()
++
++ self.assertResponseEquals(b.value(), self.expectedResponses)
++
++ def test_immediateTinyTube(self):
++ """
++ Imitate a slow connection that delivers one byte at a time.
++ (L{DummyHTTPHandler}) immediately responds, but no more
++ than one
++ """
++ b = StringTransport()
++ a = http.HTTPChannel()
++ a.requestFactory = DummyHTTPHandlerProxy # "sync"
++ a.makeConnection(b)
++
++ # one byte at a time, to stress it.
++ for byte in iterbytes(self.requests):
++ a.dataReceived(byte)
++ # There is never more than one request dispatched at a time:
++ self.assertLessEqual(len(a.requests), 1)
++
++ self.assertResponseEquals(b.value(), self.expectedResponses)
++
++ def test_immediateDumpTruck(self):
++ """
++ Imitate a fast connection where several pipelined
++ requests arrive in a single read. The request handler
++ (L{DummyHTTPHandler}) immediately responds.
++ This doesn't check the at-most-one pending request
++ invariant but exercises otherwise uncovered code paths.
++ See GHSA-c8m8-j448-xjx7.
++ """
++ b = StringTransport()
++ a = http.HTTPChannel()
++ a.requestFactory = DummyHTTPHandlerProxy
++ a.makeConnection(b)
++
++ # All bytes at once to ensure there's stuff to buffer.
++ a.dataReceived(self.requests)
++
++ self.assertResponseEquals(b.value(), self.expectedResponses)
++
++ def test_immediateABiggerTruck(self):
++ """
++ Imitate a fast connection where a so many pipelined
++ requests arrive in a single read that backpressure is indicated.
++ The request handler (L{DummyHTTPHandler}) immediately responds.
++ This doesn't check the at-most-one pending request
++ invariant but exercises otherwise uncovered code paths.
++ See GHSA-c8m8-j448-xjx7.
++ @see: L{http.HTTPChannel._optimisticEagerReadSize}
++ """
++ b = StringTransport()
++ a = http.HTTPChannel()
++ a.requestFactory = DummyHTTPHandlerProxy
++ a.makeConnection(b)
++
++ overLimitCount = a._optimisticEagerReadSize // len(self.requests) * 10
++ a.dataReceived(self.requests * overLimitCount)
++
++ self.assertResponseEquals(b.value(), self.expectedResponses * overLimitCount)
+
+ def test_pipeliningReadLimit(self):
+ """
+@@ -1522,7 +1612,11 @@ class ChunkedTransferEncodingTests(unittest.TestCase):
+ lambda b: None, # pragma: nocov
+ )
+ p._maxTrailerHeadersSize = 10
+- p.dataReceived(b"3\r\nabc\r\n0\r\n0123456789")
++ # 9 bytes are received so far, in 2 packets.
++ # For now, all is ok.
++ p.dataReceived(b"3\r\nabc\r\n0\r\n01234567")
++ p.dataReceived(b"\r")
++ # Once the 10th byte is received, the processing fails.
+ self.assertRaises(
+ http._MalformedChunkedDataError,
+ p.dataReceived,
+--
+2.40.0
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted_24.3.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted_24.3.0.bb
index 336c173893..272aecb8b0 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted_24.3.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted_24.3.0.bb
@@ -6,6 +6,11 @@ HOMEPAGE = "https://twisted.org"
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=c1c5d2c2493b848f83864bdedd67bbf5"
+SRC_URI += " \
+ file://CVE-2024-41671-0001.patch \
+ file://CVE-2024-41671-0002.patch \
+"
+
SRC_URI[sha256sum] = "6b38b6ece7296b5e122c9eb17da2eeab3d98a198f50ca9efd00fb03e5b4fd4ae"
inherit pypi python_hatchling
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-werkzeug_3.0.1.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-werkzeug_3.0.6.bb
index f8d2769b41..5758830cb9 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-werkzeug_3.0.1.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-werkzeug_3.0.6.bb
@@ -8,9 +8,9 @@ cookie handling, file uploads, a powerful URL routing system and a bunch \
of community contributed addon modules."
HOMEPAGE = "https://werkzeug.palletsprojects.com"
LICENSE = "BSD-3-Clause"
-LIC_FILES_CHKSUM = "file://LICENSE.rst;md5=5dc88300786f1c214c1e9827a5229462"
+LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=5dc88300786f1c214c1e9827a5229462"
-SRC_URI[sha256sum] = "507e811ecea72b18a404947aded4b3390e1db8f826b494d76550ef45bb3b1dcc"
+SRC_URI[sha256sum] = "a8dd59d4de28ca70471a34cba79bed5f7ef2e036a76b3ab0835474246eb41f8d"
inherit pypi python_flit_core
@@ -20,4 +20,5 @@ RDEPENDS:${PN} += " \
python3-profile \
python3-compression \
python3-json \
+ python3-difflib \
"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-xlsxwriter_3.1.9.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-xlsxwriter_3.1.9.bb
index ee7dab35cb..4e23feebbb 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-xlsxwriter_3.1.9.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-xlsxwriter_3.1.9.bb
@@ -1,7 +1,7 @@
SUMMARY = "Python 2 and 3 compatibility library"
HOMEPAGE = "https://xlsxwriter.readthedocs.io"
SECTION = "devel/python"
-LICENSE = "MIT"
+LICENSE = "BSD-2-Clause"
LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=12d9fac1f0049be71ab5aa4a78da02b0"
inherit pypi setuptools3
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-xmodem_0.4.7.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-xmodem_0.4.7.bb
index 482f0c641b..a5942e3d5c 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-xmodem_0.4.7.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-xmodem_0.4.7.bb
@@ -9,8 +9,8 @@ inherit pypi setuptools3
do_install:append() {
install -d ${D}${docdir}/${PN}
- mv ${D}/usr/doc/* ${D}${docdir}/${PN}/
- rmdir ${D}/usr/doc
+ mv ${D}${prefix}/doc/* ${D}${docdir}/${PN}/
+ rmdir ${D}${prefix}/doc
}
RDEPENDS:${PN} += " \
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/tftpy/CVE-2023-46566.patch b/meta-openembedded/meta-python/recipes-devtools/python/tftpy/CVE-2023-46566.patch
new file mode 100644
index 0000000000..0131dedb1c
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/tftpy/CVE-2023-46566.patch
@@ -0,0 +1,26 @@
+From 5b4dcbe1c8fb178e4d31b9a9e63e603b73e8fb2f Mon Sep 17 00:00:00 2001
+From: Dave Wapstra <dwapstra@cisco.com>
+Date: Wed, 3 Jul 2024 14:32:58 +1200
+Subject: [PATCH] Add packet size check
+
+CVE: CVE-2023-46566
+
+Upstream-Status: Backport [https://github.com/msoulier/tftpy/commit/5b4dcbe1c8fb178e4d31b9a9e63e603b73e8fb2f]
+---
+ tftpy/TftpPacketFactory.py | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/tftpy/TftpPacketFactory.py b/tftpy/TftpPacketFactory.py
+index 41f39a9..a8c9cd0 100644
+--- a/tftpy/TftpPacketFactory.py
++++ b/tftpy/TftpPacketFactory.py
+@@ -29,6 +29,7 @@ class TftpPacketFactory(object):
+ """This method is used to parse an existing datagram into its
+ corresponding TftpPacket object. The buffer is the raw bytes off of
+ the network."""
++ tftpassert(len(buffer) > 2, 'Invalid packet size')
+ log.debug("parsing a %d byte packet" % len(buffer))
+ (opcode,) = struct.unpack(str("!H"), buffer[:2])
+ log.debug("opcode is %d" % opcode)
+--
+2.40.0
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/tftpy_0.8.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/tftpy_0.8.2.bb
index c1b3234f72..c169916845 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/tftpy_0.8.2.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/tftpy_0.8.2.bb
@@ -11,3 +11,5 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=22770e72ae03c61f5bcc4e333b61368d"
SRC_URI[sha256sum] = "e1d1a680efd88eba176b351175844253067392a9b0f8b81588e3ff2b9e7bbb5b"
inherit pypi setuptools3
+
+SRC_URI += "file://CVE-2023-46566.patch"