diff options
| author | Andrew Geissler <geissonator@yahoo.com> | 2025-11-03 19:09:31 +0300 |
|---|---|---|
| committer | Andrew Geissler <geissonator@yahoo.com> | 2025-11-03 22:31:57 +0300 |
| commit | 6cb7f76381dbeb50bbf963f9192344f02d985637 (patch) | |
| tree | e194737ad2b6c562f463cc7a22116ef4aebd1232 /meta-openembedded/meta-python | |
| parent | 1f52643312f6f67537eb27bef9156e8b8bc66040 (diff) | |
| download | openbmc-scarthgap.tar.xz | |
subtree updates (scarthgap 11/3/2025)scarthgap
poky: ca27724b44..c4a4df3e72:
Adam Blank (3):
kernel-dev/common.rst: fix the in-tree defconfig description
ref-manual/variables.rst: fix the description of KBUILD_DEFCONFIG
ref-manual/variables.rst: fix the description of STAGING_DIR
Aditya Tayade (1):
e2fsprogs: removed 'sed -u' option
Adrian Freihofer (15):
kernel-fitimage: fix intentation
kernel-fitimage: fix external dtb check
devtool: modify support debug-builds
devtool: ide-sdk sort cmake preset
devtool: ide-sdk recommend DEBUG_BUILD
oe-selftest: devtool ide-sdk use modify debug-build
devtool: ide-sdk remove the plugin from eSDK installer
uboot-config: fix devtool modify with kernel-fitimage
sdk-manual: extensible.rst: devtool ide-sdk improve
sdk-manual: extensible.rst: update devtool ide-sdk
ref-manual: kernel-fitimage.bbclass does not use SPL_SIGN_KEYNAME
llvm: update from 18.1.6 to 18.1.8
llvm: fix build with gcc-15
expect: Revert "expect-native: fix do_compile failure with gcc-14"
expect: fix native build with GCC 15
Alban Bedel (1):
bind: Fix build with the `httpstats` package config enabled
Aleksandar Nikolic (12):
cve-check: Introduce CVE_CHECK_MANIFEST_JSON_SUFFIX
install-buildtools: remove md5 checksum validation
install-buildtools: fix "test installation" step
install-buildtools: update base-url, release and installer version
ref-manual: introduce CVE_CHECK_REPORT_PATCHED variable
scripts/install-buildtools: Update to 5.0.5
scripts/install-buildtools: Update to 5.0.6
scripts/install-buildtools: Update to 5.0.7
scripts/install-buildtools: Update to 5.0.9
scripts/install-buildtools: Update to 5.0.10
scripts/install-buildtools: Update to 5.0.11
scripts/install-buildtools: Update to 5.0.12
Alessio Cascone (1):
tzcode-native: Fix compiler setting from 2023d version
Alexander Kanavin (29):
mesa: remove obsolete 0001-meson.build-check-for-all-linux-host_os-combinations.patch
kexec-tools: submit 0003-kexec-ARM-Fix-add_buffer_phys_virt-align-issue.patch upstream
vorbis: mark patch as Inactive-Upstream
grub: mark grub-module-explicitly-keeps-symbole-.module_license.patch as a workaround
perl: submit the rest of determinism.patch upstream
iptables: submit 0001-configure-Add-option-to-enable-disable-libnfnetlink.patch upstream
xserver-xorg: upgrade 21.1.12 -> 21.1.13
mobile-broadband-provider-info: upgrade 20230416 -> 20240407
python3: submit deterministic_imports.patch upstream as a ticket
glib-networking: submit eagain.patch upstream
glslang: mark 0001-generate-glslang-pkg-config.patch as Inappropriate
tcp-wrappers: mark all patches as inactive-upstream
automake: mark new_rt_path_for_test-driver.patch as Inappropriate
settings-daemon: submit addsoundkeys.patch upstream and update to a revision that has it
dpkg: mark patches adding custom non-debian architectures as inappropriate for upstream
libacpi: mark patches as inactive-upstream
apr: drop 0007-explicitly-link-libapr-against-phtread-to-make-gold-.patch
pulseaudio, desktop-file-utils: correct freedesktop.org -> www.freedesktop.org SRC_URI
sysvinit: take release tarballs from github
package_rpm: use zstd's default compression level
package_rpm: restrict rpm to 4 threads
rust: add reproducibility patch to eliminate host leakage
rust: build the default set of tools
rust: use rust-snapshot binaries only in rust-native
rust: correctly link rust-snapshot into build/stage0
pkg-config-native: pick additional search paths from $EXTRA_NATIVE_PKGCONFIG_PATH
selftest/rust: correctly form the PATH environment variable
perlcross: update 1.5.2 -> 1.6
mtools: upgrade 4.0.43 -> 4.0.44
Alexis Cellier (1):
systemd: add libpcre2 as RRECOMMENDS if pcre2 is enabled
Alexis Lothoré (3):
oeqa/utils/postactions: transfer whole archive over ssh instead of doing individual copies
oeqa/postactions: fix exception handling
oeqa/ssh: allow to retrieve raw, unformatted ouput
Alon Bar-Lev (1):
module.bbclass: add KBUILD_EXTRA_SYMBOLS to install
Alper Ak (2):
ref-manual/variables.rst: document INHIBIT_DEFAULT_RUST_DEPS
ref-manual/variables.rst: document INHIBIT_UPDATERCD_BBCLASS
Anders Heimer (1):
libpam: mark CVE-2025-6018 as not applicable
Andrew Fernandes (1):
gtk+: add missing libdrm dependency
Andrew Kreimer (1):
manuals: remove repeated word
Antonin Godard (77):
ref-manual: add missing CVE_CHECK manifest variables
ref-manual: add missing TESTIMAGE_FAILED_QA_ARTIFACTS
ref-manual: add missing EXTERNAL_KERNEL_DEVICETREE variable
ref-manual: add missing OPKGBUILDCMD variable
ref-manual: merge patch-status-* to patch-status
ref-manual: structure.rst: document missing tmp/ dirs
overview-manual: concepts: add details on package splitting
ref-manual: faq: add q&a on class appends
ref-manual: release-process: update releases.svg
ref-manual: release-process: refresh the current LTS releases
ref-manual: release-process: update releases.svg with month after "Current"
ref-manual: release-process: add a reference to the doc's release
ref-manual: devtool-reference: refresh example outputs
ref-manual: devtool-reference: document missing commands
conf.py: rename :cve: role to :cve_nist:
doc: Makefile: remove inkscape, replace by rsvg-convert
doc: Makefile: add support for xelatex
doc: add a download page for epub and pdf
sphinx-static/switchers.js.in: do not refer to URL_ROOT anymore
conf.py: add a bitbake_git extlink
dev-manual: document how to provide confs from layer.conf
dev-manual: bblock: use warning block instead of attention
standards.md: add a section on admonitions
ref-manual: classes: fix bin_package description
Gather dependencies in poky.yaml.in
poky.yaml.in: add missing locales dependency
poky.yaml.in: replace inkscape dependency by librsvg2-bin
system-requirements: add fedora 39 to supported distros
system-requirements: update list of supported distros
system-requirements.rst: add dependencies for pdf builds
Update the documentation for SRCPV
poky.conf: add new tested distros
ref-manual/qa-checks: remove patch-status-core/patch-status-noncore
contributor-guide/submit-changes.rst: suggest to remove the git signature
ref-manual/devtool-reference: add warning note on deploy-target and shared objects
SSTATE_MIRRORS/SOURCE_MIRROR_URL: add instructions for mirror authentication
ref-manual/packages: move ptest section to the test-manual
ref-manual: move runtime-testing section to the test-manual
Update autobuilder URLs to valkyrie
test-manual/reproducible-builds: fix reproducible links
test-manual/ptest: link to common framework ptest classes
dev-manual/building: document the initramfs-framework recipe
ref-manual/faq: add q&a on systemd as default
contributor-guide/submit-changes: add policy on AI generated code
Add favicon for the documentation html
overview-manual/concepts: remove PR from the build dir list
ref-manual/variables.rst: WATCHDOG_TIMEOUT: fix recipe name
ref-manual/variables.rst: document autotools class related variables
documentation/conf.py: define a manpage url
ref-manual/variables.rst: add manpage links for toolchain variables
ref-manual/variables.rst: add missing documentation for BUILD_* variables
ref-manual/variables.rst: document missing SDK_*_ARCH variables
ref-manual/variables.rst: document HOST_*_ARCH variables
ref-manual/variables.rst: HOST_CC_ARCH: fix wrong SDK reference
ref-manual/variables.rst: improve the PKGV documentation
poky.yaml: introduce DISTRO_LATEST_TAG
Fix dead links that use the DISTRO macro
dev-manual/sbom.rst: fix wrong build outputs
test-manual/intro: remove Buildbot version used
ref-manual/release-process: update releases.svg
overview-manual/concepts.rst: fix sayhello hardcoded bindir
ref-manual/system-requirements.rst: update supported distributions
ref-manual/variables.rst: document the FIT_CONF_PREFIX variable
ref-manual/variables.rst: document SPL_DTB_BINARY
ref-manual/classes.rst: document the testexport class
dev-manual/security-subjects.rst: update mailing lists
test-manual/yocto-project-compatible.rst: fix a typo
ref-manual/structure: document the auto.conf file
ref-manual/variables.rst: document UNINATIVE_URL/CHECKSUM
ref-manual/classes.rst: extend the uninative class documentation
ref-manual/classes,variables: document the CCACHE_DISABLE variable
ref-manual/variables.rst: document the REQUIRED_MACHINE_FEATURES variable
ref-manual/variables.rst: document the REQUIRED_COMBINED_FEATURES variable
ref-manual/variables.rst: document the REQUIRED_IMAGE_FEATURES variable
ref-manual/variables.rst: document the USE_NLS variable
ref-manual/classes.rst: gettext: extend the documentation of the class
ref-manual/classes.rst: document the relative_symlinks class
Anuj Mittal (1):
sqlite3: upgrade 3.45.1 -> 3.45.3
Archana Polampalli (51):
less: fix CVE-2024-32487
ofono: fix CVE-2023-2794
ffmpeg: fix CVE-2023-49502
ffmpeg: fix CVE-2024-31578
ffmpeg: fix CVE-2024-31582
ffmpeg: fix CVE-2023-50008
ffmpeg: fix CVE-2024-32230
qemu: fix CVE-2024-7409
ffmpeg: fix CVE-2023-49501
ffmpeg: fix CVE-2024-28661
ffmpeg: fix CVE-2023-50007
ffmpeg: fix CVE-2023-49528
ffmpeg: fix CVE-2024-7055
ffmpeg: fix CVE-2024-35366
ffmpeg: fix CVE-2024-35367
ffmpeg: fix CVE-2024-35368
rsync: fix CVE-2024-12084
rsync: fix CVE-2024-12085
rsync: fix CVE-2024-12086
rsync: fix CVE-2024-12087
rsync: fix CVE-2024-12088
rsync: fix CVE-2024-12747
ffmpeg: fix CVE-2024-35365
ffmpeg: fix CVE-2024-36613
ffmpeg: fix CVE-2024-36616
ffmpeg: fix CVE-2024-36617
ffmpeg: fix CVE-2024-36618
ffmpeg: fix CVE-2024-36619
ffmpeg: fix CVE-2024-35369
gstreamer1.0-rtsp-server: fix CVE-2024-44331
ffmpeg: fix CVE-2025-25473
ffmpeg: fix CVE-2025-25471
ffmpeg: fix CVE-2025-22921
ffmpeg: fix CVE-2025-0518
ffmpeg: Correct the CVE ID to fix CVE-2025-22919
openssh: fix CVE-2025-26465
go: fix CVE-2025-22870
ghostscript: upgrade 10.04.0 -> 10.05.0
perlcross: 1.6 -> 1.6.2
perl: upgrade 5.38.2 -> 5.38.4
xwayland: fix CVE-2025-49175
xwayland: fix CVE-2025-49176
xwayland: fix CVE-2025-49177
xwayland: fix CVE-2025-49178
xwayland: fix CVE-2025-49179
xwayland: fix CVE-2025-49180
gdk-pixbuf: fix CVE-2025-7345
go: fix CVE-2025-4674
ffmpeg: upgrade 6.1.2 -> 6.1.3
ffmpeg: fix CVE-2025-1594
go: fix CVE-2025-47906
Ashish Sharma (11):
bind: Upgrade 9.18.25 -> 9.18.28
ruby: Backport fix for CVE-2024-27282
ruby: Fix CVE-2025-27219
binutils: Fix CVE-2025-1176
binutils: patch CVE-2025-1178 & CVE-2024-57360
binutils: patch CVE-2025-1181
binutils: patch CVE-2025-1182
libsoup: patch CVE-2025-46420
libsoup-2.4: Fix CVE-2025-46420
libsoup: patch CVE-2025-4476
screen: patch CVE-2025-46805
AshishKumar Mishra (2):
systemd: backport fix for handle USE_NLS from master
p11-kit: backport fix for handle USE_NLS from master
Barne Carstensen (1):
test-manual: update runtime-testing Exporting Tests section
Bartosz Golaszewski (1):
linux-firmware: add a package for ath12k firmware
Benjamin Szőke (2):
archiver.bbclass: Fix work-shared checking for kernel recipes
mc: fix source URL
Bin Lan (1):
lttng-ust: backport patch to fix cmake-multiple-shared-libraries build error
Bruce Ashfield (54):
linux-yocto/6.6: update to v6.6.36
linux-yocto/6.6: update to v6.6.38
linux-yocto/6.6: update to v6.6.40
linux-yocto/6.6: update to v6.6.43
kernel-devsrc: remove 64 bit vdso cmd files
linux-yocto/6.6: update to v6.6.44
linux-yocto/6.6: update to v6.6.45
linux-yocto/6.6: fix genericarm64 config warning
linux-yocto/6.6: update to v6.6.47
linux-yocto/6.6: update to v6.6.49
linux-yocto/6.6: update to v6.6.50
linux-yocto/6.6: update to v6.6.52
linux-yocto/6.6: update to v6.6.54
linux-yocto/6.6: update to v6.6.56
linux-yocto/6.6: update to v6.6.58
linux-yocto/6.6: genericarm64.cfg: enable CONFIG_DMA_CMA
linux-yocto/6.6: update to v6.6.59
linux-yocto/6.6: update to v6.6.60
linux-yocto/6.6: update to v6.6.62
linux-yocto/6.6: bsp/genericarm64: disable ARM64_SME
linux-yocto/6.6: update to v6.6.63
linux-yocto/6.6: update to v6.6.64
linux-yocto/6.6: update to v6.6.66
linux-yocto/6.6: update to v6.6.69
linux-yocto/6.6: update to v6.6.75
linux-yocto/6.6: update to v6.6.77
linux-yocto/6.6: update to v6.6.78
linux-yocto/6.6: update to v6.6.80
linux-yocto/6.6: update to v6.6.82
linux-yocto/6.6: update to v6.6.83
linux-yocto/6.6: update to v6.6.84
linux-yocto/6.6: update to v6.6.85
linux-yocto/6.6: fix beaglebone ethernet
linux-yocto/6.6: update to v6.6.86
linux-yocto/6.6: update to v6.6.87
linux-yocto/6.6: update to v6.6.88
linux-yocto/6.6: update to v6.6.89
linux-yocto/6.6: update to v6.6.91
linux-yocto/6.6: update to v6.6.92
linux-yocto/6.6: update to v6.6.93
linux-yocto/6.6: update to v6.6.94
linux-yocto/6.6: update to v6.6.96
linux-yocto/6.6: update to v6.6.98
linux-yocto/6.6: update to v6.6.99
linux-yocto/6.6: update to v6.6.100
linux-yocto/6.6: update to v6.6.101
linux-yocto/6.6: update to v6.6.102
linux-yocto/6.6: update to v6.6.103
linux-yocto/6.6: update to v6.6.106
linux-yocto/6.6: update to v6.6.107
linux-yocto/6.6: update to v6.6.108
linux-yocto/6.6: update to v6.6.109
linux-yocto/6.6: update to v6.6.110
linux-yocto/6.6: update to v6.6.111
Carlos Alberto Lopez Perez (1):
icu: Backport patch to fix build issues with long paths (>512 chars)
Carlos Sánchez de La Lama (1):
ref-manual: clarify KCONFIG_MODE default behaviour
Catalin Popescu (1):
Revert "bluez5: remove configuration files from install task"
Changqing Li (48):
apt-native: don't let dpkg overwrite files by default
apt: runtime error: filename too long (tmpdir length)
webkitgtk: fix do_configure error on beaglebone-yocto
webkitgtk: fix do_compile errors on beaglebone-yocto
vulkan-samples: fix do_compile error when -Og enabled
multilib.conf: remove appending to PKG_CONFIG_PATH
gettext: fix a parallel build issue
pixman: fixing inline failure with -Og
rt-tests: rt_bmark.py: fix TypeError
curl: correct the PACKAGECONFIG for native/nativesdk
libpng: update SRC_URI
expect-native: fix do_compile failure with gcc-14
libcap-ng: update SRC_URI
sysvinit: backport patch for fixing one issue of pidof
acpica: fix CVE-2024-24856
libsoup: fix CVE-2024-52530, CVE-2024-52531
rxvt-unicode.inc: disable the terminfo installation by setting TIC to :
sanity.bbclass: skip check_userns for non-local uid
systemd: enable create-log-dirs
babeltrace: extend to nativesdk
babeltrace2: extend to nativesdk
patch.py: set commituser and commitemail for addNote
initscripts: add function log_success_msg/log_failure_msg/log_warning_msg
buildtools-tarball: move setting of envvars to respective envfile
buildtools-tarball: add envvars into BB_ENV_PASSTHROUGH_ADDITIONS
buildtools-tarball: Make buildtools respects host CA certificates
libsoup: fix CVE-2025-32908
libsoup: fix CVE-2025-32907
libsoup-2.4: fix CVE-2025-32907
libsoup-2.4: fix do_compile failure
libsoup-2.4: fix CVE-2025-32053
libsoup: fix CVE-2025-32053
libsoup-2.4: fix CVE-2025-32052
libsoup: fix CVE-2025-32052
libsoup: fix CVE-2025-32051
libsoup-2.4: fix CVE-2025-32050
libsoup: fix CVE-2025-32050
libsoup-2.4: fix CVE-2025-46421
libsoup: fix CVE-2025-46421
libsoup-2.4: fix CVE-2025-4948
libsoup: fix CVE-2025-4948
libsoup-2.4: fix CVE-2025-4476
libsoup-2.4: fix CVE-2025-2784
libsoup: fix CVE-2025-2784
icu: fix CVE-2025-5222
libsoup-2.4: refresh CVE-2025-4969.patch
libsoup-2.4: fix CVE-2025-4945
libsoup: fix CVE-2025-4945
Chen Qi (8):
libnl: change HOMEPAGE
qemu: back port patches to fix riscv64 build failure
toolchain-shar-extract.sh: exit when post-relocate-setup.sh fails
libgfortran: fix buildpath QA issue
bitbake: data_smart.py: remove unnecessary ? from __expand_var_regexp__
bitbake: data_smart.py: simple clean up
bitbake: data_smart.py: clear expand_cache in _setvar_update_overridevars
coreutils: fix CVE-2025-5278
Chris Laplante (6):
bitbake: persist_data: close connection in SQLTable __exit__
bitbake: fetch2: use persist_data context managers
bitbake: ui/knotty: print log paths for failed tasks in summary
bitbake: ui/knotty: respect NO_COLOR & check for tty; rename print_hyperlink => format_hyperlink
bitbake: cooker: Make cooker 'skiplist' per-multiconfig/mc
util-linux: use ${B} instead of ${WORKDIR}/build, to fix building under devtool
Christian Taedcke (1):
iptables: fix memory corruption when parsing nft rules
Christos Gavros (2):
ref-manual/variables.rst: document the IMAGE_ROOTFS_MAXSIZE variable
ref-manual/variables.rst: document the INITRAMFS_MAXSIZE variable
Claus Stovgaard (1):
lib/oe/package-manager: skip processing installed-pkgs with empty globs
Clayton Casciato (1):
uboot-sign: fix concat_dtb arguments
Colin McAllister (2):
udev-extraconf: Add collect flag to mount
busybox: Fix cut with "-s" flag
Colin Pinnell McAllister (1):
ffmpeg: fix CVE-2025-1373
Daniel Semkowicz (2):
os-release: Fix VERSION_CODENAME in case it is empty
gstreamer1.0-plugins-bad: fix buffer allocation fail for v4l2codecs
Daniel Turull (4):
package: export debugsources in PKGDESTWORK as json
spdx: add option to include only compiled sources
xz: ignore CVE-2024-47611
libxml2: ignore CVE-2025-8732
David Nyström (3):
openssh: fix CVE-2025-61985
openssh: fix CVE-2025-61984
lz4: fix CVE-2025-62813
Deepak Rathore (1):
default-distrovars.inc: Fix CONNECTIVITY_CHECK_URIS redirect issue
Deepesh Varatharajan (13):
binutils: stable 2.42 branch updates
glibc: stable 2.39 branch updates.
binutils: stable 2.42 branch update
binutils: Fix CVE-2025-0840
glibc: stable 2.39 branch updates
binutils: stable 2.42 branch updates
binutils: Fix CVE-2025-5245
binutils: Fix CVE-2025-5244
gcc: Upgrade to GCC 13.4
binutils: stable 2.42 branch updates
binutils: Fix CVE-2025-7545
glibc: stable 2.39 branch updates
glibc: stable 2.39 branch updates
Deepthi Hemraj (5):
binutils: stable 2.42 branch updates
glibc: stable 2.39 branch updates
rust-llvm: Fix CVE-2024-0151
binutils: stable 2.42 branch update
glibc: stable 2.39 branch updates
Denys Dmytriyenko (3):
weston: upgrade 13.0.0 -> 13.0.1
gcc: unify cleanup of include-fixed, apply to cross-canadian
nativesdk-libtool: sanitize the script, remove buildpaths
Divya Chellam (16):
libpam: fix CVE-2024-10041
libxml2: Upgrade 2.12.8 -> 2.12.9
wget: fix CVE-2024-10524
vim: Upgrade 9.1.0764 -> 9.1.1043
vim: Upgrade 9.1.1043 -> 9.1.1115
ruby: fix CVE-2025-27220
ruby: fix CVE-2025-27221
screen: fix CVE-2025-46802
screen: fix CVE-2025-46804
libarchive: fix CVE-2025-5914
libarchive: fix CVE-2025-5915
libarchive: fix CVE-2025-5916
libarchive: fix CVE-2025-5917
libarchive: fix CVE-2025-5918
wpa-supplicant: fix CVE-2022-37660
vim: upgrade 9.1.1652 -> 9.1.1683
Divyanshu Rathore (1):
ffmpeg: upgrade 6.1.1 -> 6.1.2
Dixit Parmar (1):
ref-manual: document KERNEL_SPLIT_MODULES variable
Dmitry Baryshkov (1):
xserver-xorg: fix CVE-2023-5574 status
Emil Kronborg (3):
insane.bbclass: remove skipping of cross-compiled packages
insane.bbclass: fix HOST_ variable names
insane.bbclass: remove leftover variables and comment
Enrico Jörns (6):
wic: engine.py: use raw string for escape sequence
wic: bootimg-efi: fix error handling
bitbake: bitbake-diffsigs: fix handling when finding only a single sigfile
ref-manual/variables.rst: update ROOT_HOME documentation
conf.py: tweak SearchEnglish to be hyphen-friendly
conf.py: improve SearchEnglish to handle terms with dots
Erik Lindsten (1):
overview-manual/yp-intro.rst: fix broken link to article
Esben Haabendal (3):
pulseaudio: fix webrtc audio depdency
files: Amend overlayfs unit descriptions with path information
files: overlayfs-create-dirs: Improve mount unit dependency
Etienne Cordonnier (6):
oeqa/runtime: fix regression in minidebuginfo test
oeqa/runtime: make minidebuginfo test work with coreutils
oeqa/runtime: fix race-condition in minidebuginfo test
python3-setuptools-scm: respect GIT_CEILING_DIRECTORIES
ref-manual/variables.rst: document SSTATE_SKIP_CREATION
bitbake: gcp.py: remove slow calls to gsutil stat
Fabio Berton (2):
ccache.conf: Add include_file_ctime to sloppiness
linux-libc-headers: Fix invalid conversion in cn_proc.h
Florian Kreutzer (1):
dropbear: backport fix for concurrent channel open/close
Gassner, Tobias.ext (1):
rootfs: Ensure run-postinsts is not uninstalled for read-only-rootfs-delayed-postinsts
Gauthier HADERER (1):
populate_sdk_ext.bclass: make sure OECORE_NATIVE_SYSROOT is exported.
Guocai He (2):
tcf-agent: correct the SRC_URI
minicom: correct the SRC_URI
Guénaël Muller (1):
ref-manual: use standardized method accross both ubuntu and debian for locale install
Guðni Már Gilbert (15):
pam: Fix for CVE-2024-22365
python3-attrs: drop python3-ctypes from RDEPENDS
bluez5: remove redundant patch for MAX_INPUT
shared-mime-info: drop itstool-native from DEPENDS
libpam: drop cracklib from DEPENDS
systemd: drop intltool-native from DEPENDS
systemd-boot: drop intltool-native from DEPENDS
python3-poetry-core: drop python3-six from RDEPENDS
dnf: drop python3-iniparse from DEPENDS and RDEPENDS
python3: upgrade 3.12.6 -> 3.12.7
python3: upgrade 3.12.7 -> 3.12.8
systemd: upgrade 255.13 -> 255.17
systemd: upgrade 255.17 -> 255.18
bluez5: add missing tools to noinst-tools package
systemd: upgrade 255.18 -> 255.21
Gyorgy Sarvari (1):
conf/bitbake.conf: use gnu mirror instead of main server
Haixiao Yan (2):
glibc: Add single-threaded fast path to rand()
buildtools-tarball: fix unbound variable issues under 'set -u'
Harish Sadineni (7):
binutils: Add missing perl modules to RDEPENDS for nativesdk variant
rust-target-config: Fix TARGET_C_INT_WIDTH with correct size
rust: fix for rust multilib sdk configuration
rust: remove redundant cargo config file
oeqa/sdk/context: fix for gtk3 test failure during do_testsdk
binutils: Fix CVE-2025-1179
binutils: set CVE_STATUS for CVE-2025-1180
Hiago De Franco (2):
weston: backport patch to allow neatvnc < v0.9.0
bluez5: backport patch to fix address type when loading keys
Hitendra Prajapati (24):
ghostscript: upgrade 10.02.1 -> 10.03.1
ruby: fix CVE-2024-27281
vte: fix CVE-2024-37535
curl: fix CVE-2024-8096
webkitgtk: upgrade 2.44.1 -> 2.44.3
cups: Backport fix for CVE-2024-47175
libarchive: fix CVE-2024-48957 & CVE-2024-48958
libsoup: fix CVE-2024-52532
ghostscript: upgrade 10.03.1 -> 10.04.0
libsndfile: fix CVE-2024-50612
ofono: Fix multiple CVEs
libcap: fix CVE-2025-1390
elfutils: Fix multiple CVEs
go: fix CVE-2025-22871
libsoup-3.4.4: Fix CVE-2025-4969
libsoup-2.4: Fix CVE-2025-4969
libxml2: fix CVE-2025-6021
libxml2: fix CVE-2025-49794 & CVE-2025-49796
libpam: fix CVE-2025-6020
gstreamer1.0-plugins-base: fix CVE-2025-47808
gstreamer1.0-plugins-base: fix CVE-2025-47806
gstreamer1.0-plugins-good: fix multiple CVEs
gstreamer1.0-plugins-base: fix CVE-2025-47807
grub2: mark CVE-2024-2312 as not applicable
Hongxu Jia (10):
ovmf: fix CVE-2024-38796
ovmf: fix CVE-2024-1298
u-boot: fix CVE-2024-57254
u-boot: fix CVE-2024-57255
u-boot: fix CVE-2024-57256
u-boot: fix CVE-2024-57257
u-boot: fix CVE-2024-57258
u-boot: fix CVE-2024-57259
rpm: keep leading `/' from sed operation
u-boot: fix CVE-2024-42040
Igor Opaniuk (1):
wic: bootimg-efi: Support + symbol in filenames
Jaeyoon Jung (2):
makedevs: Fix issue when rootdir of / is given
makedevs: Fix matching uid/gid
Jagadeesh Krishnanjanappa (1):
tune-cortexa32: set tune feature as armv8a
Jan Vermaete (1):
sdk: The main in the C example should return an int
Jeroen Hofstee (2):
bluez5: make media control a PACKAGECONFIG option
bluez5: backport a patch to fix btmgmt -i
Jiaying Song (9):
liba52: fix do_fetch error
enchant2: fix do_fetch error
libxml-parser-perl: fix do_fetch error
python3-zipp: fix CVE-2024-5569
subversion: fix CVE-2024-46901
boost: fix do_fetch error
binutils: File name too long causing failure to open temporary head file in dlltool
python3-requests: upgrade 2.32.3 -> 2.32.4
ruby-ptest : some ptest fixes
Jinfeng Wang (3):
tzdata&tzcode-native: upgrade 2024a -> 2024b
mtools: upgrade 4.0.48 -> 4.0.49
systemtap: Fix task_work_cancel build
Joao Marcos Costa (1):
ref-manual/variables.rst: expand IMAGE_OVERHEAD_FACTOR glossary entry
Joe Slater (1):
oe-debuginfod: add option for data storage
Joerg Schmidt (1):
bitbake: bblayers/query: Fix using "removeprefix" string method
Johannes Schneider (1):
ppp: Revert lock path to /var/lock
Jon Mason (4):
oeqa/runtime/ssh: add retry logic and sleeps to allow for slower systems
oeqa/runtime/ssh: check for all errors at the end
oeqa/runtime/ssh: increase the number of attempts
openssh: add backported header file include
Jonas Gorski (1):
rootfs-postcommands.bbclass: make opkg status reproducible
Jookia (1):
populate_sdk_ext.bbclass: Fix undefined variable error
Jose Quaresma (7):
go: upgrade 1.22.4 -> 1.22.5
oeqa/runtime/scp: requires openssh-sftp-server
openssh: drop rejected patch fixed in 8.6p1 release
openssh: systemd sd-notify patch was rejected upstream
openssh: systemd notification was implemented upstream
go: upgrade 1.22.5 -> 1.22.6
bitbake: bitbake: doc/user-manual: Update the BB_HASHSERVE_UPSTREAM
Joshua Watt (3):
bitbake: asyncrpc: Use client timeout for websocket open timeout
bitbake: Remove custom exception backtrace formatting
bitbake: Use a "fork" multiprocessing context
João Marcos Costa (1):
variables.rst: fix LAYERDEPENDS description
Julien Stephan (5):
README: add instruction to run Vale on a subset
documentation: Makefile: add SPHINXLINTDOCS to specify subset to sphinx-lint
styles: vocabularies: Yocto: add sstate
ref-manual: variables: add SIGGEN_LOCKEDSIGS* variables
dev-manual: add bblock documentation
Jörg Sommer (5):
classes/kernel: No symlink in postinst without KERNEL_IMAGETYPE_SYMLINK
doc/features: remove duplicate word in distribution feature ext2
doc/features: describe distribution feature pni-name
ptest-runner: Update 2.4.4 -> 2.4.5
runqemu: Fix detection of -serial parameter
Kai Kang (3):
multilib.bbclass: replace deprecated e.data with d
cmake-qemu.bbclass: fix if criterion
glibc: fix fortran header file conflict for arm
Khem Raj (26):
linux-yocto: Enable team net driver
systemd.bbclass: Clarify error message
grub,grub-efi: Remove -mfpmath=sse on x86
python3: Treat UID/GID overflow as failure
gawk: Remove References to /usr/local/bin/gawk
busybox: CVE-2023-42364 and CVE-2023-42365 fixes
busybox: Add fix for CVE-2023-42366
gcc: Fix spurious '/' in GLIBC_DYNAMIC_LINKER on microblaze
gnupg: Document CVE-2022-3219 and mark wontfix
openssh: Mark CVE-2023-51767 as wont-fix
libpcre2: Update base uri PhilipHazel -> PCRE2Project
python3: Drop empty patch
qemu: Do not define sched_attr with glibc >= 2.41
e2fsprogs: Fix build failure with gcc 15
parted: Fix build with GCC 15
bash: Stick to C17 std
ncurses: Pin to C17 standard
unzip: Fix build with GCC-15
m4: Stick to C17 standard
gmp: Fix build with GCC15/C23
gmp: Fix build with older gcc versions
gdbm: Use C11 standard
unifdef: Don't use C23 constexpr keyword
libtirpc: Fix build with gcc-15/C23
cpio: Pin to use C17 std
expect: Fix build with GCC 15
Kirill Yatsenko (1):
iptables: fix save/restore symlinks with libnftnl PACKAGECONFIG enabled
Konrad Weihmann (3):
runqemu: keep generating tap devices
testimage: fallback for empty IMAGE_LINK_NAME
testexport: fallback for empty IMAGE_LINK_NAME
Kyungjik Min (1):
pulseaudio: Add audio group explicitly
Lee Chee Yang (24):
migration-notes: add release notes for 5.0.1
migration-guides: add release notes for 4.0.19
migration-guides: add release notes for 5.0.2
migration-guide: add release notes for 4.0.20
migration-guides: add release notes for 5.0.3
migration-guide: add release notes for 4.0.21
migration-guides: add release notes for 5.0.4
migration-guide: add release notes for 4.0.22
migration-guides: add release notes for 5.0.5
migration-guides: add release notes for 4.0.23
migration-guides: add release notes for 5.0.6
migration-guides: add release notes for 4.0.24
migration-guides: add release notes for 5.0.7
migration-guides: add release notes for 4.0.25
migration-guides: add release notes for 5.0.8
migration-guides: add release notes for 4.0.26
migration-guides: add release notes for 5.0.9
migration-guides: add release notes for 4.0.27
migration-guide: add release notes for 5.0.10
migration-guides: add release notes for 4.0.28
migration-guides: add release notes for 5.0.11
migration-guides: add release notes for 4.0.29
migration-guides: add release notes for 5.0.12
migration-guides: add release notes for 4.0.30
Libo Chen (1):
runqemu: fix special characters bug
Louis Rannou (1):
image_qa: fix error handling
Macpaul Lin (1):
linux-firmware: upgrade 20240312 -> 20240909
Madhu Marri (1):
qemu 8.2.7: ignore CVE-2023-1386
Makarios Christakis (1):
icu: Adjust ICU_DATA_DIR path on big endian targets
Marco Cavallini (1):
dev-manual/start.rst: added missing command in Optimize your VHDX file using DiskPart
Marek Vasut (3):
u-boot: kernel-fitimage: Fix dependency loop if UBOOT_SIGN_ENABLE and UBOOT_ENV enabled
base-files: Drop /bin/sh dependency
u-boot: kernel-fitimage: Restore FIT_SIGN_INDIVIDUAL="1" behavior
Mark Hatle (9):
package.py: Fix static debuginfo split
package.py: Fix static library processing
selftest-hardlink: Add additional test cases
create-spdx-*: Support multilibs via SPDX_MULTILIB_SSTATE_ARCHS
oeqa sdk cases: Skip SDK test cases when TCLIBC is newlib
create-sdpx-2.2.bbclass: Switch from exists to isfile checking debugsrc
populate_sdk_ext: write_local_conf add shutil import
cve-update-nvd2-native: Handle BB_NO_NETWORK and missing db
bitbake: bitbake: runqueue: Verify mcdepends are valid
Markus Volk (3):
libadwaita: update 1.5.0 -> 1.5.1
gcc: add a backport patch to fix an issue with tzdata 2024b
ninja: fix build with python 3.13
Marta Rybczynska (1):
vulnerabilities/classes: remove references to cve-check text format
Martin Jansa (22):
selftest: add Upstream-Status to .patch files
libgfortran.inc: fix nativesdk-libgfortran dependencies
populate_sdk_base: inherit nopackages
meta-world-pkgdata: Inherit nopackages
python3-lxml=v5.0.2
mc: set ac_cv_path_ZIP to avoid buildpaths QA issues
libpam: re-add missing libgen include
cairo: fix build with gcc-15 on host
bash: use -std=gnu17 also for native CFLAGS
cmake: fix build with gcc-15 on host
git: fix build with gcc-15 on host
pkgconfig: fix build with gcc-15
libgpg-error: fix build with gcc-15
rust-llvm: fix build with gcc-15
elfutils: fix build with gcc-15
binutils: fix build with gcc-15
dbus-glib: fix build with gcc-15
bitbake: bitbake: Bump version to 2.8.1
license.py: avoid deprecated ast.Str
sanity.conf: Update minimum bitbake version to 2.8.1
lib/oe/utils: use multiprocessing from bb
flex: fix build with gcc-15 on host
Matthias Pritschet (1):
ref-manual: fix typo and move SYSROOT_DIRS example
Matthias Schiffer (1):
curl: only set CA bundle in target build
Michael Haener (1):
oeqa/runtime/ping: don't bother trying to ping localhost
Michael Halstead (4):
yocto-uninative: Update to 4.6 for glibc 2.40
yocto-uninative: Update to 4.7 for glibc 2.41
yocto-uninative: Update to 4.8 for GCC 15.1
yocto-uninative: Update to 4.9 for glibc 2.42
Michael Opdenacker (5):
maintainers.inc: update self e-mail address
doc: Makefile: publish pdf and epub versions too
dev-manual: fix styling of references to bmaptool
dev-manual/bmaptool.rst: correct command for bmaptool-native
dev-manual/bmaptool.rst: simplify and fix instructions
Michal Seben (1):
timedated: wait for jobs before SetNTP response
Mikko Rapeli (1):
ovmf-native: remove .pyc files from install
Mingli Yu (1):
llvm: Enable libllvm for native build
Moritz Haase (2):
meta: Enable '-o pipefail' for the SDK installer
cmake: Correctly handle cost data of tests with arbitrary chars in name
NeilBrown (1):
nfs-utils: don't use signals to shut down nfs server.
Nguyen Dat Tho (1):
libatomic-ops: Update GITHUB_BASE_URI
Nikhil R (1):
cmake: Add PACKAGECONFIG option for debugger support
Niko Mauno (15):
dnf/mesa: Fix missing leading whitespace with ':append'
libyaml: Fix warning regarding unpatched CVE
systemd: Mitigate /var/log type mismatch issue
systemd: Mitigate /var/tmp type mismatch issue
image_types.bbclass: Use --force also with lz4,lzop
util-linux: Add PACKAGECONFIG option to mitigate rootfs remount error
iw: Fix LICENSE
dejagnu: Fix LICENSE
unzip: Fix LICENSE
zip: Fix LICENSE
tiff: Fix LICENSE
gcr: Fix LICENSE
python3-maturin: Fix cross compilation issue for armv7l, mips64, ppc
cve-check.bbclass: Mitigate symlink related error
cve-check.bbclass: Fix symlink handling also for text files
Nitin Wankhade (1):
examples: genl: fix wrong attribute size
Oleksandr Hnatiuk (2):
icu: remove host references in nativesdk to fix reproducibility
gcc: remove paths to sysroot from configargs.h and checksum-options for gcc-cross-canadian
Patrick Wicki (1):
gpgme: move gpgme-tool to own sub-package
Paul Barker (2):
meta-ide-support: Mark recipe as MACHINE-specific
dev-manual, test-manual: Update autobuilder output links
Paul Gerber (1):
uboot-sign: fix counters in do_uboot_assemble_fitimage
Pavel Zhukov (1):
package_rpm: Check if file exists before open()
Pedro Ferreira (3):
buildhistory: Fix intermittent package file list creation
buildhistory: Restoring files from preserve list
rust-common.bbclass: soft assignment for RUSTLIB path
Peter Kjellerstedt (1):
image.bbclass: Drop support for ImageQAFailed exceptions in image_qa
Peter Marko (144):
flac: fix buildpaths warnings
cargo: remove True option to getVar calls
ncurses: switch to new mirror
busybox: Patch CVE-2021-42380
busybox: Patch CVE-2023-42363
libstd-rs,rust-cross-canadian: set CVE_PRODUCT to rust
curl: Patch CVE-2024-6197
glibc: cleanup old cve status
qemu: set cve status for CVE-2023-6683
libmnl: explicitly disable doxygen
libyaml: ignore CVE-2024-35326
libyaml: Ignore CVE-2024-35325
curl: Patch CVE-2024-7264
python3: Upgrade 3.12.5 -> 3.12.6
wpa-supplicant: Ignore CVE-2024-5290
wpa-supplicant: Patch CVE-2024-3596
wpa-supplicant: Patch security advisory 2024-2
rust: ignore CVE-2024-43402
openssl: patch CVE-2024-9143
cve-check: add support for cvss v4.0
go: upgrade 1.22.6 -> 1.22.7
go: upgrade 1.22.7 -> 1.22.8
dropbear: backport patch for CVE-2023-48795
curl: patch CVE-2024-9681
gstreamer1.0: set status for CVE-2024-0444
expat: upgrade 2.6.3 -> 2.6.4
builder: set CVE_PRODUCT
qemu: set CVE-2024-6505 to fixed
gstreamer1.0-plugins-good: fix several CVEs
gstreamer1.0-plugins-base: patch CVE-2024-47538
gstreamer1.0-plugins-base: patch CVE-2024-47607
gstreamer1.0-plugins-base: patch CVE-2024-47615
gstreamer1.0-plugins-good: patch CVE-2024-47613
gstreamer1.0-plugins-good: patch several CVEs
gstreamer1.0-plugins-base: patch CVE-2024-47541
gstreamer1.0-plugins-base: patch CVE-2024-47542
gstreamer1.0-plugins-good: patch CVE-2024-47599
gstreamer1.0-plugins-base: patch CVE-2024-47600
gstreamer1.0-plugins-good: patch CVE-2024-47606
gstreamer1.0-plugins-good: patch CVE-2024-47606
gstreamer1.0-plugins-good: patch CVE-2024-47774
gstreamer1.0-plugins-good: patch several CVEs
gstreamer1.0-plugins-base: patch CVE-2024-47835
gstreamer1.0: ignore CVEs fixed in plugins recipes
socat: patch CVE-2024-54661
ofono: patch CVE-2024-7540, CVE-2024-7541, CVE-2024-7542
ofono: patch CVE-2023-4232
ofono: patch CVE-2023-4235
openssl: patch CVE-2024-13176
go: upgrade 1.22.8 -> 1.22.9
go: upgrade 1.22.9 -> 1.22.10
go: upgrade 1.22.10 -> 1.22.11
glibc: stable 2.39 branch updates
python3: upgrade 3.12.8 -> 3.12.9
go: upgrade 1.22.11 -> 1.22.12
cmake: apply parallel build settings to ptest tasks
subversion: ignore CVE-2024-45720
gnutls: patch CVE-2024-12243
openssl: upgrade 3.2.3 -> 3.2.4
libxml2: upgrade 2.12.9 -> 2.12.10
grub: drop obsolete CVE statuses
grub: backport strlcpy function
grup: patch CVE-2024-45781
grub: patch CVE-2024-45782 and CVE-2024-56737
grub: patch CVE-2024-45780
grub: patch CVE-2024-45783
grub: patch CVE-2025-0624
grub: patch CVE-2024-45774
grub: patch CVE-2024-45775
grub: patch CVE-2025-0622
grub: patch CVE-2024-45776
grub: patch CVE-2024-45777
grub: patch CVE-2025-0690
grub: patch CVE-2025-1118
grub: patch CVE-2024-45778 and CVE-2024-45779
grub: patch CVE-2025-0677, CVE-2025-0684, CVE-2025-0685, CVE-2025-0686 and CVE-2025-0689
grub: patch CVE-2025-0678 and CVE-2025-1125
libarchive: patch CVE-2025-1632 and CVE-2025-25724
xserver-xorg: mark CVEs fixed in 21.1.16 as fixed
cve-update-nvd2-native: handle missing vulnStatus
expat: patch CVE-2024-8176
freetype: follow-up patch for CVE-2025-27363
ofono: patch CVE-2024-7537
cve-update-nvd2-native: add workaround for json5 style list
xz: upgrade 5.4.6 -> 5.4.7
xz: patch CVE-2025-31115
libarchive: upgrade 3.7.4 -> 3.7.9
sqlite3: patch CVE-2025-3277
sqlite3: patch CVE-2025-29088
ppp: patch CVE-2024-58250
libxml2: patch CVE-2025-32414
libxml2: patch CVE-2025-32415
glib-2.0: patch CVE-2025-3360
Revert "cve-update-nvd2-native: Tweak to work better with NFS DL_DIR"
sqlite3: mark CVE-2025-29087 as patched
python3: upgrade 3.12.9 -> 3.12.11
testimage: get real os-release file
net-tools: patch CVE-2025-46836
go: set status of CVE-2024-3566
glibc: stable 2.39 branch updates
python3: update CVE product
busybox: apply patch for CVE-2023-39810
iputils: patch CVE-2025-48964
orc: set CVE_PRODUCT
openssl: CVE-2024-41996
openssl: patch CVE-2025-27587
gnutls: patch CVE-2025-32989
gnutls: patch read buffer overrun in the "pre_shared_key" extension
gnutls: patch reject zero-length version in certificate request
gnutls: patch CVE-2025-32988
gnutls: patch CVE-2025-32990
gnutls: patch CVE-2025-6395
ncurses: patch CVE-2025-6141
libxml2: patch CVE-2025-6170
glibc: fix CVE-2025-8058
python3: patch CVE-2025-8194
go: ignore CVE-2025-0913
dropbear: patch CVE-2025-47203
glib-2.0: ignore CVE-2025-4056
qemu: set status of CVE-2024-7730 to fixed
go-binary-native: ignore CVE-2025-0913
glib-2.0: patch CVE-2025-7039
glib-2.0: patch CVE-2025-6052
dpkg: patch CVE-2025-6297
libarchive: patch regression of patch for CVE-2025-5918
vim: upgrade 9.1.1198 -> 9.1.1652
sudo: remove devtool FIXME comment
busybox: patch CVE-2025-46394
gstreamer1.0: ignore CVEs fixed in plugins
gstreamer1.0: ignore CVE-2025-2759
ghostscript: patch CVE-2025-59798
ghostscript: patch CVE-2025-59799
ghostscript: patch CVE-2025-59800
expat: follow-up for CVE-2024-8176
tiff: ignore 5 CVEs
ffmpeg: ignore 8 CVEs fixed in 6.1.1 and 6.1.3 releases
openssl: upgrade 3.2.4 -> 3.2.6
qemu: patch CVE-2024-8354
binutils: patch CVE-2025-11082
binutils: patch CVE-2025-11083
gnupg: mark CVE-2025-30258 as patched
python3: upgrade 3.12.11 -> 3.12.12
vulnerabilities: update nvdcve file name
expat: patch CVE-2025-59375
Philip Lorenz (3):
cmake: Fix sporadic issues when determining compiler internals
cve-check: Add missing call to exit_if_errors
shared-mime-info: Handle USE_NLS
Poonam Jadhav (2):
curl: ignore CVE-2025-0725
libpng: Add ptest
Praveen Kumar (7):
connman :fix CVE-2025-32743
connman :fix CVE-2025-32366
glib-2.0: fix CVE-2025-4373
go: fix CVE-2025-4673
sudo: upgrade 1.9.15p5 -> 1.9.17p1
go: fix CVE-2025-47907
bind: upgrade 9.18.33 -> 9.18.41
Preeti Sachan (1):
ltp: backport patch to fix compilation error for x86_64
Priyal Doshi (2):
tzdata/tzcode-native: upgrade 2024b -> 2025a
tzdata/tzcode-native: upgrade 2025a -> 2025b
Purushottam Choudhary (1):
virglrenderer: Add patch to fix -int-conversion build issue
Quentin Schulz (14):
mmc-utils: fix URL
weston-init: fix weston not starting when xwayland is enabled
docs: README: specify how to contribute instead of pointing at another file
docs: conf.py: silence SyntaxWarning on js_splitter_code
ref-manual: classes: reword to clarify that native/nativesdk options are exclusive
ref-manual: classes: nativesdk: move note to appropriate section
go-helloworld: fix license
contributor-guide: submit-changes: fix improper bold string
contributor-guide: submit-changes: clarify example with Yocto bug ID
contributor-guide: submit-changes: align CC tag description
contributor-guide: submit-changes: make the Cc tag follow kernel guidelines
contributor-guide: submit-changes: reword commit message instructions
contributor-guide: submit-changes: number instruction list in commit your changes
contributor-guide: submit-changes: make "Crediting contributors" part of "Commit your changes"
Rajeshkumar Ramasamy (2):
glib-networking: fix CVE-2025-60018
glib-networking: fix CVE-2025-60019
Randy MacLeod (1):
systemd: stable update 255.4 -> 255.13
Ranjitsinh Rathod (1):
rust: Add new varaible RUST_ENABLE_EXTRA_TOOLS
Rasmus Villemoes (1):
iptables: remove /etc/ethertypes
Regis Dargent (1):
udev-extraconf: fix network.sh script did not configure hotplugged interfaces
Richard Purdie (60):
selftest/cases/runtime_test: Exclude centos-9 from virgl tests
cve-exclusion: Drop the version comparision/warning
bitbake: codeparser/data: Ensure module function contents changing is accounted for
bitbake: codeparser: Skip non-local functions for module dependencies
pseudo: Update to pull in python 3.12+ fix
layer.conf: Add os-release to SIGGEN_EXCLUDERECIPES_ABISAFE
oeqa/sdk/case: Ensure DL_DIR is populated with artefacts if used
create-spdx-3.0/populate_sdk_base: Add SDK_CLASSES inherit mechanism to fix tarball SPDX manifests
pseudo: Fix to work with glibc 2.40
pseudo: Update to include open symlink handling bugfix
nasm: Upgrade 2.16.01 -> 2.16.03
oeqa/runtime/ssh: In case of failure, show exit code and handle -15 (SIGTERM)
oeqa/selftest/reproducibile: Explicitly list virtual targets
expat: 2.6.2 -> 2.6.3
ruby: Make docs generation deterministic
libedit: Make docs generation deterministic
buildhistory: Simplify intercept call sites and drop SSTATEPOSTINSTFUNC usage
scripts/install-buildtools: Update to 5.0.3
bitbake.conf: Add truncate to HOSTTOOLS
license: Fix directory layout issues
libsdl2: Fix non-deterministic configure option for libsamplerate
bitbake: tests/fetch: Use our own mirror of sysprof to decouple from gnome gitlab
bitbake: tests/fetch: Use our own mirror of mobile-broadband-provider to decouple from gnome gitlab
cve_check: Use a local copy of the database during builds
pseudo: Fix envp bug and add posix_spawn wrapper
oeqa/runtime/ssh: Rework ssh timeout
oeqa/runtime/ssh: Fix incorrect timeout fix
qemurunner: Clean up serial_lock handling
bitbake: fetch2/git: Use quote from shlex, not pipes
bitbake: fetch/wget: Increase timeout to 100s from 30s
bitbake: runqueue: Fix performance of multiconfigs with large overlap
bitbake: runqueue: Optimise setscene loop processing
bitbake: runqueue: Fix scenetask processing performance issue
do_package/sstate/sstatesig: Change timestamp clamping to hash output only
selftest/reproducible: Drop rawlogs
selftest/reproducible: Clean up pathnames
resulttool: Allow store to filter to specific revisions
resulttool: Use single space indentation in json output
oeqa/utils/gitarchive: Return tag name and improve exclude handling
resulttool: Fix passthrough of --all files in store mode
resulttool: Add --logfile-archive option to store mode
resulttool: Handle ltp rawlogs as well as ptest
resulttool: Clean up repoducible build logs
resulttool: Trim the precision of duration information
resulttool: Improve repo layout for oeselftest results
cve-update-nvd2-native: Tweak to work better with NFS DL_DIR
bitbake: tests/fetch: Fix git shallow test failure with git >= 2.48
bitbake: utils: Print information about lock issue before exiting
bitbake: utils: Tweak lock_timeout logic
bitbake: utils: Add signal blocking for lock_timeout
bitbake: event/utils: Avoid deadlock from lock_timeout() and recursive events
bitbake: toaster/tests/buildtest: Switch to new CDN
bitbake: fetch2: Avoid deprecation warning
sstatetests: Switch to new CDN
local.conf.sample: Switch to new CDN
bitbake: ast: Change deferred inherits to happen per recipe
brief-yoctoprojectqs/ref-manual: Switch to new CDN
bitbake: test/fetch: Switch u-boot based test to use our own mirror
mtools: upgrade 4.0.46 -> 4.0.47
bitbake: utils: Optimise signal/sigmask performance
Robert Kovacsics (1):
sdk: Fix path length limit to match reserved size
Robert P. J. Day (7):
Clean up explanation of minimum required version numbers
overview-manual: small number of pedantic cleanups
bsp guide: update kernel version example to 6.12
bsp-guide: update lonely "4.12" kernel reference to "6.12"
bsp-guide: update all of section 1.8.2 to reflect current beaglebone conf file
variables.rst: remove references to obsolete tar packaging
overview-manual/yp-intro.rst: update on-target packaging info
Robert Yang (7):
bitbake: data_smart: Improve performance for VariableHistory
release-notes-5.0.rst: NO_OUTPUT -> NO_COLOR
bitbake: gitsm: Add call_process_submodules() to remove duplicated code
bitbake: gitsm: Remove downloads/tmpdir when failed
cml1.bbclass: do_diffconfig: Don't override .config with .config.orig
libgcrypt: Fix building error with '-O2' in sysroot path
groff: Fix race issues for parallel build
Rogerio Guerra Borin (1):
u-boot: ensure keys are generated before assembling U-Boot FIT image
Rohini Sangam (1):
vim: Upgrade 9.1.0698 -> 9.1.0764
Roland Kovacs (3):
gnupg: update 2.4.5 -> 2.4.8
libxml2: fix CVE-2025-49795
sqlite3: fix CVE-2025-6965
Ross Burton (31):
cpio: mark CVE-2023-7216 as disputed
fribidi: upgrade 1.0.13 -> 1.0.14
gstreamer1.0: skip another known flaky test
libportal: fix rare build race
meson: don't use deprecated pkgconfig variable
curl: skip FTP tests in run-ptest
gawk: update patch status
python3-pycryptodome(x): use python_setuptools_build_meta build class
gstreamer1.0: disable flaky baseparser tests
librsvg: don't try to run target code at build time
icu: update patch Upstream-Status
strace: download release tarballs from GitHub
tcl: skip io-13.6 test case
groff: fix rare build race in hdtbl
sanity: check for working user namespaces
python3: add dependency on -compression to -core
classes/nativesdk: also override TUNE_PKGARCH
classes/qemu: use tune to select QEMU_EXTRAOPTIONS, not package architecture
oeqa/selftest/rust: skip on all MIPS platforms
Remove all mention of core-image-lsb
ref-manual: don't refer to poky-lsb
ref-manual: remove OE_IMPORTS
puzzles: ignore three new CVEs for a different puzzles
xserver-xf86-config: add a configuration fragment to disable screen blanking
xserver-xf86-config: remove obsolete configuration files
grub2: fix CVE-2024-56738
libxslt: apply patch for CVE-2025-7424
expect: update code for Tcl channel implementation
expect: don't run aclocal in do_configure
expect: cleanup do_install
pulseaudio: ignore CVE-2024-11586
Ryan Eatmon (2):
u-boot.inc: Refactor do_* steps into functions that can be overridden
uboot: Allow for customizing installed/deployed file names
Sana Kazi (1):
gcc-cross-canadian.inc: Fix buildpaths error for pthread.h
Sandeep Gundlupet Raju (1):
tune-cortexr52: Remove aarch64 for ARM Cortex-R52
Saravanan (2):
python3-xmltodict: fix CVE-2025-9375
cmake: fix CVE-2025-9301
Savvas Etairidis (1):
systemd: Rename systemd_v255.21 to systemd_255.21
Sergei Zhmylev (1):
lsb-release: fix Distro Codename shell escaping
Shubham Kulkarni (1):
libpam: Update fix for CVE-2024-10041
Shunsuke Tokumoto (1):
python3-setuptools: Add "python:setuptools" to CVE_PRODUCT
Siddharth Doshi (5):
Tiff: Security fix for CVE-2024-7006
vim: Upgrade 9.1.0114 -> 9.1.0682
wpa-supplicant: Upgrade 2.10 -> 2.11
vim: Upgrade 9.1.0682 -> 9.1.0698
openssl: Upgrade 3.2.2 -> 3.2.3
Simon A. Eugster (1):
documentation: Fix typo in standards.md
Simone Weiß (3):
tzdata: Add tzdata.zi to tzdata-core package
sanity: Check if tar is gnutar
curl: Ignore CVE-2024-32928
Soumya Sambu (12):
python3-idna: upgrade 3.6 -> 3.7
python3-certifi: Fix CVE-2024-39689
python3-setuptools: Fix CVE-2024-6345
python3: Fix CVE-2024-7592
python3: Fix CVE-2024-8088
python3-requests: upgrade 2.32.1 -> 2.32.2
python3-requests: upgrade 2.32.0 -> 2.32.3
python3-jinja2: upgrade 3.1.4 -> 3.1.6
git: Upgrade 2.44.1 -> 2.44.3
elfutils: Fix CVE-2025-1371
elfutils: Fix CVE-2025-1376
elfutils: Fix CVE-2025-1377
Stanislav Vovk (1):
libpam: fix CVE-2024-10963
Stefan Mueller-Klieser (1):
kernel-arch: add macro-prefix-map in KERNEL_CC
Steve Sakoman (35):
Revert "apt: runtime error: filename too long (tmpdir length)"
poky.conf: bump version for 5.0.3
build-appliance-image: Update to scarthgap head revision
Revert "wpa-supplicant: Upgrade 2.10 -> 2.11"
poky.conf: bump version for 5.0.4
build-appliance-image: Update to scarthgap head revision
build-appliance-image: Update to scarthgap head revision
release-notes-4.0: update BB_HASHSERVE_UPSTREAM for new infrastructure
poky.conf: bump version for 5.0.5
build-appliance-image: Update to scarthgap head revision
webkitgtk: fix erroneous use of unsuported DEBUG_LEVELFLAG variable
llvm: reduce size of -dbg package
poky.conf: bump version for 5.0.6
build-appliance-image: Update to scarthgap head revision
poky.conf: bump version for 5.0.7
build-appliance-image: Update to scarthgap head revision
Revert "rust: Add new varaible RUST_ENABLE_EXTRA_TOOLS"
build-appliance-image: Update to scarthgap head revision
poky.conf: add ubuntu2404 to SANITY_TESTED_DISTROS
poky.conf: bump version for 5.0.8
build-appliance-image: Update to scarthgap head revision
Revert "gcc-cross-canadian.inc: Fix buildpaths error for pthread.h"
poky.conf: bump version for 5.0.9
build-appliance-image: Update to scarthgap head revision
poky.conf: bump version for 5.0.10
build-appliance-image: Update to scarthgap head revision
poky.conf: bump version for 5.0.11
build-appliance-image: Update to scarthgap head revision
Revert "sudo: Fix CVE-2025-32462"
poky.conf: bump version for 5.0.12
build-appliance-image: Update to scarthgap head revision
selftest/cases/meta_ide.py: use use gnu mirror instead of main server
oeqa/sdk/cases/buildcpio.py: use gnu mirror instead of main server
poky.conf: bump version for 5.0.13
build-appliance-image: Update to scarthgap head revision
Sunil Dora (2):
gcc: Fix c++: tweak for Wrange-loop-construct
binutils: Fix CVE-2025-1153
Talel BELHAJ SALEM (1):
dev-manual/building.rst: add note about externalsrc variables absolute paths
Talel BELHAJSALEM (1):
contributor-guide: Remove duplicated words
Teresa Remmet (1):
recipes-bsp: usbutils: Fix usb-devices command using busybox
Trevor Gamblin (7):
python3: skip test_concurrent_futures/test_deadlock
python3: skip test_multiprocessing/test_active_children test
maintainers.inc: add self for unassigned python recipes
python3: upgrade 3.12.4 -> 3.12.5
python3: skip readline limited history tests
python3-urllib3: upgrade 2.2.1 -> 2.2.2
reproducible-builds.rst: show how to build a single package
Trevor Woerner (5):
contributor-guide/submit-changes: encourage patch version changelogs
ref-manual/variables.rst: document WIC_CREATE_EXTRA_ARGS
sphinx-lint: trailing whitespace
sphinx-lint: missing space after literal
sphinx-lint: unbalanced inline literal markup
Ulrich Ölmann (1):
initramfs-framework: fix typos
Victor Giraud (1):
busybox: fix CVE-2022-48174
Victor Kamensky (1):
systemtap: fix systemtap-native build error on Fedora 40
Vijay Anusuri (44):
openssh: fix CVE-2024-39894
apr: upgrade 1.7.4 -> 1.7.5
libpcap: Security fix for CVE-2023-7256 & CVE-2024-8006
xserver-xorg: upgrade 21.1.13 -> 21.1.14
glib-2.0: Backport fix for CVE-2024-52533
bind: Upgrade 9.18.28 -> 9.18.33
openssh: Fix CVE-2025-26466
xwayland: Fix CVE-2024-9632
xwayland: Fix CVE-2025-26594
xwayland: Fix CVE-2025-26595
xwayland: Fix CVE-2025-26596
xwayland: Fix CVE-2025-26597
xwayland: Fix CVE-2025-26598
xwayland: Fix CVE-2025-26599
xwayland: Fix CVE-2025-26600
xwayland: Fix CVE-2025-26601
libtasn1: upgrade 4.19.0 -> 4.20.0
xserver-xorg: upgrade 21.1.15 -> 21.1.16
libxslt: upgrade 1.1.39 -> 1.1.43
vim: Upgrade 9.1.1115 -> 9.1.1198
libsoup: Fix CVE-2025-32910
libsoup: Fix CVE-2025-32909
libsoup: Fix CVE-2025-32911 & CVE-2025-32913
libsoup: Fix CVE-2025-32912
libsoup: Fix CVE-2025-32906
libsoup-2.4: Fix CVE-2024-52530
libsoup-2.4: Fix CVE-2024-52531
libsoup-2.4: Fix CVE-2024-52532
libsoup-2.4: Fix CVE-2025-32906
libsoup-2.4: Fix CVE-2025-32909
libsoup: Fix CVE-2025-32914
openssh: Fix for CVE-2025-32728
libsoup-2.4: Fix CVE-2025-32910
libsoup-2.4: Fix CVE-2025-32911 & CVE-2025-32913
libsoup-2.4: Fix CVE-2025-32912
libsoup-2.4: Fix CVE-2025-32914
python3-setuptools: Fix CVE-2025-47273
kea: upgrade 2.4.1 -> 2.4.2
sudo: Fix CVE-2025-32462
git: Upgrade 2.44.3 -> 2.44.4
xserver-xorg: upgrade 21.1.6 -> 21.1.18
cups: upgrade 2.4.10 -> 2.4.11
cups: Fix for CVE-2025-58060 and CVE-2025-58364
gstreamer1.0-plugins-bad: Fix CVE-2025-3887
Virendra Thakur (3):
rust-cross-canadian: Set CVE_STATUS ignore for CVE-2024-43402
util-linux: Add fix to isolate test fstab entries using CUSTOM_FSTAB
curl: set conditional CVE_STATUS for CVE-2025-5025
Vishwas Udupa (1):
openssl: rewrite ptest installation
Vrushti Dabhi (1):
curl: update CVE_STATUS for CVE-2025-5025
Vyacheslav Yurkov (1):
systemd: Password agents shouldn't be optional
Wadim Egorov (1):
watchdog: Set watchdog_module in default config
Wang Mingyu (18):
ed: upgrade 1.20.1 -> 1.20.2
llvm: upgrade 18.1.5 -> 18.1.6
mesa: upgrade 24.0.5 -> 24.0.7
wireless-regdb: upgrade 2024.01.23 -> 2024.05.08
orc: upgrade 0.4.38 -> 0.4.39
cups: upgrade 2.4.9 -> 2.4.10
libadwaita: upgrade 1.5.1 -> 1.5.2
libdnf: upgrade 0.73.1 -> 0.73.2
wireless-regdb: upgrade 2024.05.08 -> 2024.07.04
cryptodev: upgrade 1.13 -> 1.14
orc: upgrade 0.4.39 -> 0.4.40
wireless-regdb: upgrade 2024.07.04 -> 2024.10.07
gnupg: upgrade 2.4.4 -> 2.4.5
xserver-xorg: upgrade 21.1.14 -> 21.1.15
ghostscript: upgrade 10.05.0 -> 10.05.1
mtools: upgrade 4.0.44 -> 4.0.45
mtools: upgrade 4.0.45 -> 4.0.46
mtools: upgrade 4.0.47 -> 4.0.48
Weisser, Pascal (1):
ref-manual: Add missing variable IMAGE_ROOTFS_MAXSIZE
Weisser, Pascal.ext (1):
qemuboot: Trigger write_qemuboot_conf task on changes of kernel image realpath
Xiangyu Chen (2):
qemu: Upgrade 8.2.1 -> 8.2.2
lttng-modules: fix sched_stat_runtime changed in Linux 6.6.66
Yash Shinde (4):
binutils: Fix CVE-2024-53589
binutils: Fix CVE-2025-7546
binutils: fix CVE-2025-11081
binutils: fix CVE-2025-8225
Yi Zhao (5):
libcap-ng: upgrade 0.8.4 -> 0.8.5
libcap-ng-python: upgrade 0.8.4 -> 0.8.5
rpm: fix expansion of %_libdir in macros
iputils: Security fix for CVE-2025-47268
kea: set correct permissions for /var/run/kea
Yogita Urade (10):
qemu: upgrade 8.2.2 -> 8.2.3
qemu: fix CVE-2024-4467
ruby: upgrade 3.2.2 -> 3.3.5
qemu: upgrade 8.2.3 -> 8.2.7
curl: fix CVE-2024-11053
curl: fix CVE-2025-0167
python3-urllib3: fix CVE-2025-50181
curl: fix CVE-2025-9086
tiff: fix CVE-2025-9900
tiff: ignore CVE-2025-8961
Zhang Peng (3):
avahi: fix CVE-2024-52616
mpg123: upgrade 1.32.6 -> 1.32.10
avahi: fix CVE-2024-52615
aszh07 (3):
xz: Update LICENSE variable for xz packages
ffmpeg: Add "libswresample libavcodec" to CVE_PRODUCT
libarchive: Fix CVE-2024-20696
rajmohan r (1):
glibc-y2038-tests: remove glibc-y2038-tests_2.39.bb recipe
meta-openembedded: 78a14731cf..15e18246dd:
Adrian Freihofer (2):
networkmanager: remove modemmanager rdepends
thrift: fix build with gcc 15
Alexandre Truong (4):
source-han-sans-*-fonts: Switch away from SVN fetcher in SRC_URI
lcov: include UPSTREAM_CHECK_* to fix UNKNOWN_BROKEN status
hunspell-dictionaries: switch branch from master to main
evince: Update status for CVE-2011-0433 and CVE-2011-5244
Alexandre Videgrain (1):
openbox: fix crash on alt+tab with fullscreen app
AmateurECE (1):
pipewire: Add glib-2.0-native dep for bluez5
Andrej Valek (1):
externalsrc: fix support in various components
Anil Dongare (1):
libssh 0.10.6: Fix CVE-2025-8114
Ankur Tyagi (25):
tinyproxy: patch CVE-2023-49606
frr: patch CVE-2024-44070
libavif: ignore CVE-2025-48175
libconfuse: patch CVE-2022-40320
hdf5: patch CVE-2025-2913
hdf5: patch CVE-2025-2914
hdf5: patch CVE-2025-2915
hdf5: patch CVE-2025-2923, CVE-2025-6816, CVE-2025-6856
hdf5: patch CVE-2025-2924
hdf5: patch CVE-2025-2925
hdf5: patch CVE-2025-6269, CVE-2025-6270, CVE-2025-6516
libppd: patch CVE-2024-47175
libcupsfilters: patch CVE-2024-47076
libraw: patch CVE-2025-43961 CVE-2025-43962
libraw: patch CVE-2025-43963
libraw: patch CVE-2025-43964
zlog: fix CVE-2024-22857
memcached: patch CVE-2023-46852
memcached: patch CVE-2023-46853
ndpi: ignore CVE-2025-25066
libiec61850: patch CVE-2024-26529
libiec61850: patch CVE-2024-45970
libiec61850: patch CVE-2024-45971
mbedtls: upgrade 3.6.4 -> 3.6.5
hostapd: patch CVE-2025-24912
Archana Polampalli (4):
modejs: upgrade 20.18.0 -> 20.18.2
tftpy: fix CVE-2023-46566
tcpreplay: fix CVE-2024-22654
apache2: upgrade 2.4.64 - 2.4.65
Ariel D'Alessandro (1):
pipewire: Install missing ALSA config files
Armin Kuster (1):
Revert "mariadb: fix runtime failure on riscv"
Ashish Sharma (2):
nginx: Backport fix for CVE-2024-7347
postgresql: Backport fix for CVE-2024-7348
AshishKumar Mishra (1):
meta-oe: image: optionally remove RAW image after sparse image creation
Awais Belal (2):
mongodb: fix build with python 3.12
mongodb: update to 4.4.29
BINDU (1):
flatbuffers: adapt for cross-compilation environments
Barry Grussling (1):
postgresql: Break perl RDEPENDS
Bastian Krause (2):
libsocketcan: use https instead of git protocol
canutils: use https instead of git protocol
Benjamin Szőke (1):
tree: fix broken links
Changqing Li (11):
pavucontrol: update SRC_URI
libatasmart: Update SRC_URI
mariadb: fix runtime failure on riscv
dlt-daemon: make DLT_WatchdogSec configurable
abseil-cpp: upgrade 20240116.2 -> 20240116.3
nginx: fix CVE-2025-23419
libblockdev: fix CVE-2025-6019
udisks2: Hardening measure of CVE-2025-6019
phpmyadmin: upgrade 5.2.1 -> 5.2.2
luajit: fix several CVEs
mariadb: correct STACK_DIRECTION setting
Chen Qi (6):
libdbd-mysql-perl: avoid invoking assert_lib at do_configure stage
python3-protobuf: remove useless and problematic .pth file
graphviz: remove obsolete and problematic patch
protobuf: fix CVE-2024-7254
protobuf: upgrade from 4.25.3 to 4.25.8
python3-protobuf: upgrade from 4.25.3 to 4.25.8
Chris Laplante (1):
poco: fix branch: master => poco-1.12.5
Christos Gavros (1):
corosync: reproducibility issue
Claus Stovgaard (2):
lcov: sort RDEPENDS alphabetical
lcov: Add missing RDEPENDS
Clayton Casciato (1):
chrony: use inherit_defer for conditional inherit of useradd
Deepak Rathore (1):
protobuf 4.25.8: Mark CVE-2024-7254 as patched
Divya Chellam (7):
nginx: upgrade 1.25.3 -> 1.25.4
redis: upgrade 7.2.6 -> 7.2.7
krb5: fix CVE-2025-24528
openvpn: upgrade 2.6.12 -> 2.6.14
libssh: fix CVE-2025-4878
libssh: fix CVE-2025-5987
jq: fix CVE-2025-9403
Dmitry Baryshkov (1):
android-tools: Create flag file /etc/usb-debugging-enabled
Esben Haabendal (1):
netplan: add missing runtime dependencies
Etienne Cordonnier (3):
uutils-coreutils: upgrade 0.0.25 -> 0.0.26
uutils-coreutils: upgrade 0.0.26 -> 0.0.27
uutils-coreutils: fix compilation with selinux
Fabrice Aeschbacher (1):
mosquitto: upgrade 2.0.18 -> 2.0.19
Fathi Boudra (2):
python3-django: upgrade 4.2.11 -> 4.2.16
python3-django: upgrade 5.0.4 -> 5.0.9
Frank de Brabander (3):
python3-pydantic-core: fix incompatible version
python3-pydantic-core: fix TMPDIR path reference
python3-pydantic-core: add missing RDEPENDS for ptest
Grygorii Tertychnyi (1):
libusbgx: fix gadget-stop install
Guocai He (6):
python3-pylint: correct the SRC_URI
libconfig: correct the SRC_URI
logcheck: correct the SRC_URI
thrift: correct the SRC_URI
softhsm: correct the SRC_URI
mariadb: File conflicts for multilib
Guðni Már Gilbert (1):
mbedtls: upgrade 3.6.3.1 -> 3.6.4
Gyorgy Sarvari (35):
poppler: fix typos in CVE-2025-52886-0001.patch
mod-dnssd: update SRC_URI
mosh: set working SRC_URI
psqlodbc: set valid SRC_URI
collectd: set working SRC_URI
apache2: ignore irrelevant CVEs
civetweb: patch CVE-2025-55763
dovecot: patch CVE-2022-30550
pm-qa: update git fetch protocol
tokyocabinet: switch to working SRC_URI
tokyocabinet: fix license
iperf2: ignore irrelevant CVEs
jasper: patch CVE-2025-8835
jasper: patch CVE-2025-8836
jasper: patch CVE-2025-8837
etcd: patch CVE-2023-32082
freerdp3: patch CVE-2024-32039 and CVE-2024-32041
freerdp3: patch CVE-2024-32040
freerdp3: patch CVE-2024-32458
freerdp3: patch CVE-2024-32459
freerdp3: patch CVE-2024-32460
freerdp3: patch CVE-2024-32658
freerdp3: patch CVE-2025-32659
freerdp3: patch CVE-2024-32660
freerdp3: patch CVE-2024-32661
freerdp3: patch CVE-2024-32662
exiv2: patch CVE-2025-26623
exiv2: patch CVE-2025-54080
exiv2: patch CVE-2025-55304
redis: upgrade 6.2.18 -> 6.2.20
emacs: patch CVE-2024-30202
emacs: patch CVE-2024-30203
emacs: patch CVE-2024-30204
emacs: patch CVE-2024-30205
emacs: patch CVE-2024-39331
Haixiao Yan (4):
openvpn: fix CVE-2024-28882
openvpn: upgrade 2.6.10 -> 2.6.12
lmsensors: Clean stale files for sensord to avoid incorrect GCC header dependencies
python3-posix-ipc: fix runtime error
Harish Sadineni (1):
bpftool: Add support for riscv64
Hieu Van Nguyen (1):
gphoto2: Fix contains reference to TMPDIR [buildpaths] warning
Hitendra Prajapati (8):
tgt: fix CVE-2024-45751
libssh: fix CVE-2025-5318
redis: fix CVE-2025-32023
libssh: fix CVE-2025-5351 & CVE-2025-5372
open-vm-tools: fix CVE-2025-22247
libssh: fix CVE-2025-4877
openjpeg: fix for CVE-2025-54874
libjxl: fix CVE-2024-11403 & CVE-2024-11498
Hongxu Jia (1):
nodejs: support cross compile without qemu user conditionally
J. S (2):
nodejs: upgrade 20.16.0 -> 20.17.0
nodejs: upgrade 20.17.0 -> 20.18.0
J. S. (3):
znc: Fix buildpaths QA errors
nodejs: cleanup
xfce4 update HOMEPAGEs
Jan Vermaete (1):
python3-werkzeug: added python3-difflib as RDEPENDS
Jason Schonberg (1):
nodejs: upgrade 20.13.0 -> 20.16.0
Jef Driesen (2):
nginx: fix the tarball and license checksums
lcov: Add missing RDEPENDS for nativesdk
Jeroen Hofstee (5):
nodejs: backport a patch to prevent brotli crashing nodejs
can-utils: fix printing / reading timestamps
can-utils: handle CAN_ERR_CNT correctly
php: ignore CVE-2024-3566
nodejs: ignore CVE-2024-3566
Jeroen Knoops (1):
nng: Rename default branch of github.com:nanomsg/nng.git
Jiaying Song (15):
rrdtool: Fix do_populate_sysroot QA issues
nftables: change ptest output format
debootstrap: fix do_fetch error
wireguard-tools: fix do_fetch error
vlock: fix do_fetch error
openipmi: upgrade 2.0.34->2.0.36
tcpreplay: fix CVE-2023-43279
xfce-dusk-gtk3: fix do_fetch error
eject: fix do_fetch error
libdev-checklib-perl: fix do_fetch error
xmlsec1: Switch SRC_URI to use github release
chrony: fix do_fetch error
v4l-utils: Fix QA and build errors related to _TIME_BITS on 32-bit
webkitgtk3: update 2.44.1 -> 2.44.3
webkitgtk3: fix do_configure error on beaglebone-yocto
Jinfeng Wang (2):
netplan: Fix CVE-2022-4968
postfix: fix rootfs file difference
Justin Bronder (1):
python3-xmodem: replace hardcoded /usr with ${prefix}
Khem Raj (32):
python3-pydantic-core: Fix build with python 3.12.4
log4cpp: Fix buildpaths QA error
python3-pydantic: Upgrade to 2.7.3
mariadb: Upgrade to 10.11.9 release
ndisc: Remove buildpaths from binaries
ndisc6: Fix reproducible build
ghex,gnome-chess,gnome-photos: Add missing dep on itstool-native
nodejs: Upgrade to 20.13.0 release
nodejs: Fix build with libc++ 19
wolfssl: Add packageconfig for reproducible build
blueman: Fix buildpathe issue with cython generated code
botan: Make it reproducible
keepalived: Make build reproducible
ldns: Fix buildpaths QA issues
python3-kivy: Remove buildpaths from comments in generated C sources
python3-pyproj: Fix buildpaths QA Error
python3-pyproj: Remove absolute paths from cython generated .c files
python3-pycocotools: Remove absolute paths from comments
lprng: Specify target paths for needed utilities
fwknop: Specify target locations of gpg and wget
e2tools: Fix buildpaths QA warning in config.status in ptest
sharutils: Let POSIX_SHELL be overridable from environment
python3-posix-ipc: switch to PEP-517 build backend
gtkwave: Add libtirpc to depends
ssmping: Use debian mirror for SRC_URI
enca: Fix cross builds
ckermit: Define return type for main
ckermit: Fix build with GCC-15
procmail: Fix build with GCC-14
uim: Stick to C17
freerdp: Upgrade 2.11.2 -> 2.11.7
influxdb: Do not remove non-existing files
Leon Anavi (2):
sip: Upgrade 6.8.3 -> 6.8.6
sip: Fix homepage and license
Leonard Anderweit (1):
lmsensors: Fix build without sensord
Libo Chen (3):
thin-provisioning-tools: install missed thin_shrink and era_repair
grpc: Fix CVE-2024-7246
libgpiod: fix gpiod-cxx-test failed test case
Marc Ferland (2):
polkit: update SRC_URI
libvncserver: fix generated LibVNCServerTargets.cmake
Markus Volk (4):
exiv2: update 0.28.0 -> 0.28.2
gnome-remote-desktop: update 46.1 -> 46.2
geary: add itstool-native dependency
eog: add itstool-native dependency
Martin Jansa (13):
bolt: package systemd_system_unitdir correctly
giflib: fix build with gold and avoid imagemagick-native dependency
Revert "gcab: ignore buildpaths error from sources"
gpm: fix buildpaths QA issue
xerces-c: fix buildpaths QA issue
xmlrpc-c: update SRCREV
lapack: add PACKAGECONFIG for cblas
lapack: fix buildpaths in ptest also when CBLAS is enabled
gcab: fix buildpaths QA issue
python3-posix-ipc: improve build_support
python3-h5py: backport fixes for incompatible-pointer-types issues
abseil-cpp: fix build with gcc-15 on host
nodejs: fix build with gcc-15 on host
Martin Schwan (1):
linuxptp: Add systemd instance specifier for ptp4l dependency
Michael Olbrich (1):
nftables: avoid python dependencies when building without python
Michael Opdenacker (1):
kernel-hardening-checker: backport recipe
Mikko Rapeli (3):
fwupd: skip buildpaths errors
gcab: ignore buildpaths error from sources
libjcat: skip buildpaths check
Mingli Yu (2):
asio: Add ptest support
ptest-packagelists-meta-oe.inc: Add asio
Neel Gandhi (1):
v4l-utils: Install media ctrl header and library files
Nikhil R (2):
nftables: Conditionally add ${PN}-python as RDEPENDS for ptest
rocksdb: Add an option to set static library
Niko Mauno (16):
python3-xlsxwriter: Fix LICENSE
python3-cbor2: Fix LICENSE and LIC_FILES_CHKSUM
python3-crc32c: Amend LICENSE declaration
python3-email-validator: Fix LICENSE
python3-lru-dict: Fix LICENSE and change SUMMARY to DESCRIPTION
python3-mock: Fix LICENSE
python3-parse-type: Fix LICENSE
python3-pillow: Fix LICENSE and change SUMMARY to DESCRIPTION
python3-platformdirs: Fix LICENSE
python3-colorama: Fix LICENSE
python3-fann2: Fix LICENSE
python3-nmap: Fix LICENSE and LIC_FILES_CHKSUM
python3-pycurl: Fix LICENSE
python3-googleapis-common-protos: Fix LIC_FILES_CHKSUM
python3-haversine: Fix LIC_FILES_CHKSUM
python3-libevdev: Fix LIC_FILES_CHKSUM
Ninette Adhikari (6):
imagemagick: Update status for CVE
imagemagick: Update status for CVE
imagemagick: Update status for CVE
xsp: CVE status update for CVE-2006-2658
influxdb: Update CVE status for CVE-2019-10329
monkey: Update status for CVE-2013-2183
Peter Kjellerstedt (6):
hostapd: Support running "devtool modify hostapd"
hostapd: Only include the relevant parts from README in LIC_FILES_CHKSUM
libjs-jquery-icheck: Correct LIC_FILES_CHKSUM
libdevmapper: Inherit nopackages
ebtables: Remove the dependecy on bash
libeigen: Remove LGPL code
Peter Marko (41):
libndp: Patch CVE-2024-5564
squid: patch CVE-2024-37894
hostapd: Patch CVE-2024-3596
hostapd: Patch security advisory 2024-2
nss: patch CVE-2024-6602
nss: patch CVE-2024-6609
squid: conditionally set status of CVE-2024-45802
thrift: fix c++ generated code compilation with clang
grpc: patch CVE-2024-11407
python3-grpcio: patch CVE-2024-11407
python3-grpcio(-tools): fix build concurrency issue
libmodbus: patch CVE-2024-10918
libmodbus: ignore CVE-2023-26793 and CVE-2024-34244
libcoap: patch CVE-2024-31031
spdlog: patch CVE-2025-6140
minifi-cpp: patch spdlog CVE-2025-6140
poco: ignore additional failing tests
poco: patch CVE-2025-6375
nginx: patch CVE-2025-53859
fontforge: patch CVE-2024-25081 and CVE-2024-25082
fcgi: patch CVE-2025-23016
procmail: patch CVE-2014-3618
procmail: patch CVE-2017-16844.
ace: ignore CVE-2009-1147
audiofile: fix multiple CVEs
audiofile: patch CVE-2017-6829
audiofile: fix multiple CVEs
audiofile: patch CVE-2017-6831
audiofile: patch CVE-2017-6839
emlog: set CVE_PRODUCT
freerdp: patch CVE-2024-32661
freerdp: mark CVE-2024-32662 as fixed
freerdp3: set CVE_PRODUCT
corosync: fix upstream version check
corosync: upgrade 3.1.6 -> 3.1.9
corosync: patch CVE-2025-30472
dash: set CVE_PRODUCT
gattlib: mark CVE-2019-6498 as fixed
memcached: ignore disputed CVE-2022-26635
monkey: ignore CVE-2013-1771
squid: patch CVE-2025-59362
Poonam Jadhav (1):
tcpreplay: Fix CVE-2023-4256
Praveen Kumar (4):
php: upgrade 8.2.28 -> 8.2.29
polkit: fix CVE-2025-7519
yasm: fix CVE-2024-22653
cjson: upgrade 1.7.18 -> 1.7.19
Preeti Sachan (1):
bpftool: fix libelf.h not found error
Raghuvarya S (2):
android-tools-adbd.service: Update ConditionPathExists to /etc
android-toold-adbd: Fix inconsistency between selinux configurations
Rajeshkumar Ramasamy (1):
open-vm-tools: fix CVE-2025-41244
Randolph Sapp (2):
opencl-clhpp: add native and nativesdk
vulkan-cts: allow vulkan versions > 1.3
Randy MacLeod (1):
python3-pyyaml-include: support native and nativesdk build
Robert Yang (1):
hostapd: Add CVE id to CVE-2024-3596_00.patch
Roland Kovacs (2):
jq-1.7.1: Backport multiple CVE fixes
jq: add Upstream-Status and CVE tags into .patch files
Ryan Eatmon (1):
kernel-selftest: Update to allow for turning on all tests
Sana Kazi (2):
libp11: Treat all openssl-3.x releases the same
imagemagick: guard sed operations in do_install for optional files
Saravanan (2):
udisks2: upgrade 2.10.1 -> 2.10.2
fio: fix CVE-2025-10823
Scott Murray (2):
python3-grpcio: Fix build with gcc-14
python3-grpcio: backport abseil-cpp RISC-V fix
Shubham Pushpkar (2):
wireshark 4.2.7: Fix CVE-2024-9781
cjson 1.7.18: Fix CVE-2025-57052
Siddharth Doshi (2):
apache2: Upgrade 2.4.59 -> 2.4.60
apache2: Upgrade 2.4.60 -> 2.4.62
Sofiane HAMAM (2):
Wolfssl: add ptest
wolfssl: Upgrade 5.7.0 -> 5.7.2
Soumya Sambu (14):
python3-sqlparse: Fix CVE-2024-4340
python3-werkzeug: upgrade 3.0.1 -> 3.0.3
gtk+: Fix CVE-2024-6655
python3-twisted: Fix CVE-2024-41671
python3-flask-cors: Fix CVE-2024-6221
python3-werkzeug: upgrade 3.0.3 -> 3.0.6
python3-tornado: Upgrade 6.4 -> 6.4.2
python3-django: upgrade 4.2.16 -> 4.2.17
python3-django: upgrade 5.0.9 -> 5.0.10
python3-django: upgrade 5.0.10 -> 5.0.11
python3-django: upgrade 4.2.17 -> 4.2.18
php: Upgrade 8.2.26 -> 8.2.28
iniparser: Fix CVE-2025-0633
python3-django: upgrade 4.2.18 -> 4.2.20
Sunil Dora (1):
layer.conf: add bpftrace to NON_MULTILIB_RECIPES
Swamil Jain (1):
kmsxx: Revert to using original name for kmstest
Thomas Roos (1):
libcamera: backport 0.4.0 from master-next
Tim Orling (1):
python3-pydantic: upgrade 2.7.3 -> 2.7.4
Trevor Woerner (2):
apache2: use update-alternatives for httpd
iperf3: throughput fix
Vijay Anusuri (16):
krb5: upgrade 1.21.2 -> 1.21.3
wireshark: upgrade 4.2.4 -> 4.2.5
wireshark: upgrade 4.2.5 -> 4.2.7
php: upgrade 8.2.24 -> 8.2.26
openjpeg: upgrade 2.5.0 -> 2.5.3
postgresql: upgrade 16.5 -> 16.8
wireshark: upgrade 4.2.7 -> 4.2.9
proftpd: Fix CVE-2024-57392
redis: upgrade 7.2.7 -> 7.2.8
wireshark: upgrade 4.2.9 -> 4.2.12
proftpd: Fix CVE-2023-51713
apache2: Upgrade 2.4.62 -> 2.4.64
poppler: Fix CVE-2025-43718
redis: upgrade 7.2.8 -> 7.2.11
redis: upgrade 6.2.16 -> 6.2.18
vorbis-tools: Fix CVE-2023-43361
Virendra Thakur (2):
opensc: Fix multiple cve CVE-2024-45615-45616-45617-45618-45619-45620
unbound: Fix CVE-2024-8508
Wang Mingyu (18):
python3-email-validator: upgrade 2.1.0 -> 2.1.1
python3-pydantic: upgrade 2.7.0 -> 2.7.1
cjson: upgrade 1.7.17 -> 1.7.18
samba: upgrade 4.19.7 -> 4.19.8
postgresql: upgrade 16.3 -> 16.4
redis: upgrade 7.2.4 -> 7.2.5
mosquitto: upgrade 2.0.19 -> 2.0.20
uutils-coreutils: upgrade 0.0.27 -> 0.0.28
nana: Fix buildpaths warning.
fetchmail: Fix buildpaths warning.
fetchmail: disable rpath to fix buildpaths warning.
python3-posix-ipc: upgrade 1.1.1 -> 1.2.0
mbedtls: upgrade 3.6.3 -> 3.6.3.1
geoip: fix do_fetch error
rp-pppoe: update SRC_URI
procmail: fix build failure with gcc-14
procmail: Add -Wno-implicit-int to fix error of do_compile
libiec61850: upgrade 1.5.1 -> 1.5.3
Wentao Zhang (1):
meta-oe/conf/layer.conf: remove libbpf from NON_MULTILIB_RECIPES for x86 and x86-64
Xiangyu Chen (1):
crash: fix crash cannot work with kaslr
Yi Zhao (12):
samba: upgrade 4.19.6 -> 4.19.7
mbedtls: upgrade 3.6.0 -> 3.6.1
mbedtls: upgrade 2.28.8 -> 2.28.9
libldb: upgrade 2.8.0 -> 2.8.1
mbedtls: upgrade 3.6.1 -> 3.6.2
freeradius: upgrade 3.2.3 -> 3.2.5
hostapd: Security fix for CVE-2023-52160
redis: upgrade 7.2.5 -> 7.2.6
mbedtls: upgrade 2.28.9 -> 2.28.10
mbedtls: 3.6.2 -> 3.6.3
wxwidgets: upgrade 3.2.1 -> 3.2.6
redis: upgrade 6.2.14 -> 6.2.16
Yoann Congal (3):
packagegroup-meta-oe: fix lvgl inclusion
mdio-tools: fix mdio-netlink kernel module reproducibility
gutenprint: fix a build race-condition
Yogesh Tyagi (1):
tbb-native: Fix build with gcc-13
Yogita Urade (18):
graphviz: fix CVE-2023-46045
hdf5: upgrade to 1.14.4
poppler: CVE-2024-6239
krb5: fix CVE-2024-26458 and CVE-2024-26461
php: upgrade 8.2.20 -> 8.2.24
postgresql: upgrade 16.4 -> 16.5
poppler: fix CVE-2024-56378
poppler: fix CVE-2025-32364
poppler: fix CVE-2025-32365
poppler: fix CVE-2025-43903
syslog-ng: fix CVE-2024-47619
postgresql: upgrade 16.8 -> 16.9
mariadb: upgrade 10.11.9 -> 10.11.12
poppler: fix CVE-2025-52886
poppler: fix CVE-2025-50420
postgresql: upgrade 16.9 -> 16.10
indent: fix CVE-2023-40305
poppler: fix CVE-2025-52885
Zhang Peng (21):
hiredis: remove ANSI color from ptest result
frr: fix CVE-2024-34088
frr: fix CVE-2024-31950
frr: fix CVE-2024-31951
frr: fix CVE-2024-31948
frr: fix CVE-2024-31949
libgsf: upgrade 1.14.52 -> 1.14.53
glade: fix CVE-2020-36774
opensc: fix CVE-2024-8443
lapack: fix TMPDIR reference in do_package_qa
iperf3: upgrade 3.16 -> 3.18
gnuplot: fix CVE-2025-3359
gnuplot: fix CVE-2025-31176
gnuplot: fix CVE-2025-31177
gnuplot: fix CVE-2025-31178
gnuplot: fix CVE-2025-31179
gnuplot: fix CVE-2025-31180
gnuplot: fix CVE-2025-31181
iperf3: fix CVE-2025-54349
iperf3: fix CVE-2025-54350
wxwidgets: fix CVE-2024-58249
Zoltán Böszörményi (1):
gutenprint: 5.3.5
akash hadke (1):
python3-flatbuffers: provide nativesdk support
alperak (8):
tayga: Fix contains reference to TMPDIR [buildpaths] warning
etcd-cpp-apiv3: Fix contains reference to TMPDIR [buildpaths] warning
exiv2: Upgrade 0.28.2 to 0.28.3 for CVE fix
jsonrpc: Fix contains reference to TMPDIR [buildpaths] warning
rdist: Fix contains reference to TMPDIR [buildpaths] warning
perfetto: Fix contains reference to TMPDIR [buildpaths] warning
hplip: Fix contains reference to TMPDIR [buildpaths] warning
boinc-client: Fix contains reference to TMPDIR [buildpaths] warning
gudnimar (1):
pipewire: upgrade 1.0.5 -> 1.0.9
hongxu (2):
p7zip: fix CVE-2023-52169 and CVE-2023-52168
indent: fix CVE-2024-0911
kjlau0112 (1):
mbedtls: drop tag parameter from SRC_URI.
mark.yang (1):
srecord: fix build failure with gcc-15
meta-raspberrypi: 1918a27419..8767e2ff80:
Adam Schafer (1):
add raspi-utils recipe to scarthgap branch
Andrei Gherzan (1):
docs: Fix ReadTheDocs sphinx.configuration requirement
Ayoub Zaki (1):
raspberrypi5: add bcm2712d0 overlay required for booting up correctly
Bassem Nomany (1):
mesa: update to 24.3.1
Damiano Ferrari (2):
rpi-eeprom: Update to latest release
rpi-bootfiles: Update to latest release
Florin Sarbu (1):
linux-raspberrypi.inc: Change defconfig for RPi3 64 bits
Garrett Brown (1):
linux: Enable CONFIG_I2C_BRCMSTB for proper HDMI I2C support
Gijs Peskens (1):
raspberrypi5.conf: Add CM5 dtb's
Jaeyoon Jung (1):
linux-raspberrypi: Drop deprecated configs from android-driver.cfg
Joshua Watt (1):
linux-firmware-rpidistro: Fix WiFi on Raspberry Pi 5
Khem Raj (2):
linux-raspberrypi-6.6: Upgrade to 6.6.63
rpi-base: Remove bcm2712-rpi-5-b.dtb from RPI_KERNEL_DEVICETREE target
Leon Anavi (11):
yocto-builder/Dockerfile: Ubuntu 22.04
rpi-base.inc: vc4-kms-dsi-ili9881-7inch.dtbo
u-boot_%.bbappend: Increase CONFIG_SYS_BOOTM_LEN
wayland-protocols: Upgrade 1.38 -> 1.45
mesa: Upgrade 24.3.1 -> 25.1.3
mesa: Upgrade 25.1.3 -> 25.1.6
mesa_%.bbappend: DISTRO_FEATURES for wayland
mesa: wayland-protocols: Fix signatures
linux-firmware-rpidistro: Update and stabilize
rpi-base.inc: Add w1-gpio-pi5.dtbo
rpi-base.inc: Add rpi-backlight.dtbo
Markus Volk (4):
linux-raspberrypi: add recipe for 6.12
linux-raspberrypi: update 6.12.2 -> 6.12.25
rpi-default-versions: Switch default kernel to 6.12
rpi-bootfiles: update to latest release
Martin Jansa (3):
docker-build: use --no-cache
Revert "rpi-default-versions: Switch default kernel to 6.12"
mesa, wayland-protocols: use separate recipe instead of bbappend
Matthias Klein (1):
linux-firmware-rpidistro: Upgrade to bookworm/20230625-2+rpt3
Omri Sarig (1):
linux-firmware-rpidistro: Fix wireless error message on RPi
Pierrick Curt (1):
rpi-base: build uart dts overlays by default
Thomas Roos (1):
Moving bcm2712d0.dtbo into rpi-base.inc
meta-arm: 58268ddccb..0f1e7bf92c:
Amr Mohamed (5):
kas: Update kas configuration for fvp-base.yml file
arm-systemready/linux-distros: new inc file for unattended installation
arm-systemready/linux-distros: Add kickstart file for Fedora unattended
arm-systemready/oeqa: Add new test for Fedora unattended installation
kas: Add new yml file for Distros unattended installation
Ben (3):
arm-systemready/linux-distros: Implement unattended openSUSE
arm-systemready/oeqa: Add unattended installation testcase
kas: Include unattended openSUSE test
Bence Balogh (1):
arm-bsp/trusted-firmware-m: corstone1000: Fix MPU configuration
Harsimran Singh Tungal (1):
arm-bsp,kas: corstone1000: enable External System based on new yml file
Hugues KAMBA MPIANA (1):
arm-bsp/documentation: corstone1000: Add SystemReady IR v2.0 certification
Jon Mason (4):
arm-toolchain: remove libmount-mountfd-support when using binary toolchain
arm-bsp/fvp-base: Get 6.10 kernel working
arm/linux-yocto: disable CONFIG_MTD_NAND_FSL_IFC
arm-systemready/ir-acs: Update URL
Jose Quaresma (1):
bsp: optee-client: cleanup old tee-supplicant
Luca Fancellu (2):
arm/oeqa: Introduce retry mechanism for fvp_devices run_cmd
arm/lib: Handle timeout for spawn object on stop()
Romain Naour (4):
external-arm-toolchain: remove old sed fixup for libc.so
external-arm-toolchain: wrap symlink handling under usrmerge check
external-arm-toolchain: override dynamic loader path with usrmerge enabled
external-arm-toolchain: rebuild libmvec.so symlink if any
Ross Burton (5):
arm-base/linux-yocto: revert interim 6.10 patch for fvp-base
arm-system-ready/arm-systemready-ir-acs: add version to download filename
CI: use canonical git.yoctoproject.org URLs
arm/execstack-native: add new recipe
arm/fvp-base-a-aem: remove spurious executable stack from one library
Vasyl Vavrychuk (3):
external-arm-toolchain: wrap base_libdir vs libdir manipulations under usrmerge check
external-arm-toolchain: in libc.so GNU ld script use base_libdir
external-arm-toolchain: remove ${base_libdir}/libpthread*.so from FILES:${PN}
meta-security: 11ea91192d..bc865c5276:
Hitendra Prajapati (2):
clamav: fix CVE-2024-20505 & CVE-2024-20506
libhtp: fix CVE-2024-45797
Vijay Anusuri (2):
tpm2-tools: Upgrade 5.5 -> 5.7
tpm2-tss: upgrade 4.0.1 -> 4.0.2
Change-Id: Ief5b086436b2f3a4e819546fcd1bb9a5b1f608dd
Signed-off-by: Andrew Geissler <geissonator@yahoo.com>
Diffstat (limited to 'meta-openembedded/meta-python')
57 files changed, 1230 insertions, 219 deletions
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-cbor2_5.6.3.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-cbor2_5.6.3.bb index c9c98b6fb5..69573064bc 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-cbor2_5.6.3.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-cbor2_5.6.3.bb @@ -1,8 +1,8 @@ DESCRIPTION = "An implementation of RFC 7049 - Concise Binary Object Representation (CBOR)." DEPENDS +="python3-setuptools-scm-native" -LICENSE = "Apache-2.0" -LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/Apache-2.0;md5=89aea4e17d99a7cacdbeed46a0096b10" +LICENSE = "MIT" +LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=a79e64179819c7ce293372c059f1dbd8" SRC_URI[sha256sum] = "e6f0ae2751c2d333a960e0807c0611494eb1245631a167965acbc100509455d3" diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-colorama_0.4.6.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-colorama_0.4.6.bb index 0f364c424d..3871244031 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-colorama_0.4.6.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-colorama_0.4.6.bb @@ -1,6 +1,6 @@ SUMMARY = "Cross-platform colored terminal text." HOMEPAGE = "https://github.com/tartley/colorama" -LICENSE = "BSD-2-Clause" +LICENSE = "BSD-3-Clause" LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=b4936429a56a652b84c5c01280dcaa26" inherit pypi python_setuptools_build_meta diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-crc32c_2.3.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-crc32c_2.3.bb index da756ea074..125a7ad877 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-crc32c_2.3.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-crc32c_2.3.bb @@ -1,7 +1,7 @@ SUMMARY = "A python package implementing the crc32c algorithmin hardware and software" HOMEPAGE = "https://github.com/ICRAR/crc32c" -LICENSE = "BSD-2-Clause & BSD-3-Clause & CRC32C-ADLER & LGPL-2.0-or-later" +LICENSE = "BSD-2-Clause & BSD-3-Clause & CRC32C-ADLER & LGPL-2.1-or-later" LIC_FILES_CHKSUM = " \ file://LICENSE;md5=4fbd65380cdd255951079008b364516c \ file://LICENSE.google-crc32c;md5=e9ed01b5e5ac9eae23fc2bb33701220c \ diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-django_4.2.11.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-django_4.2.20.bb index 0642b7e7c3..3fb8b03224 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-django_4.2.11.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-django_4.2.20.bb @@ -1,7 +1,7 @@ require python-django.inc inherit setuptools3 -SRC_URI[sha256sum] = "6e6ff3db2d8dd0c986b4eec8554c8e4f919b5c1ff62a5b4390c17aff2ed6e5c4" +SRC_URI[sha256sum] = "92bac5b4432a64532abb73b2ac27203f485e40225d2640a7fbef2b62b876e789" RDEPENDS:${PN} += "\ python3-sqlparse \ @@ -10,5 +10,5 @@ RDEPENDS:${PN} += "\ # Set DEFAULT_PREFERENCE so that the LTS version of django is built by # default. To build the 4.x branch, -# PREFERRED_VERSION_python3-django = "4.2.11" can be added to local.conf +# PREFERRED_VERSION_python3-django = "4.2.20" can be added to local.conf DEFAULT_PREFERENCE = "-1" diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-django_5.0.4.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-django_5.0.11.bb index 3139ed4682..5060f3c9ad 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-django_5.0.4.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-django_5.0.11.bb @@ -1,7 +1,7 @@ require python-django.inc inherit setuptools3 -SRC_URI[sha256sum] = "4bd01a8c830bb77a8a3b0e7d8b25b887e536ad17a81ba2dce5476135c73312bd" +SRC_URI[sha256sum] = "e7d98fa05ce09cb3e8d5ad6472fb602322acd1740bfdadc29c8404182d664f65" RDEPENDS:${PN} += "\ python3-sqlparse \ diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-email-validator_2.1.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-email-validator_2.1.1.bb index 7daf548cb1..746d56d18e 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-email-validator_2.1.0.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-email-validator_2.1.1.bb @@ -1,9 +1,9 @@ SUMMARY = "A robust email address syntax and deliverability validation library." SECTION = "devel/python" -LICENSE = "CC0-1.0" -LIC_FILES_CHKSUM = "file://LICENSE;md5=65d3616852dbf7b1a6d4b53b00626032" +LICENSE = "Unlicense" +LIC_FILES_CHKSUM = "file://LICENSE;md5=2890aee62bd2a4c3197e2059016a397e" -SRC_URI[sha256sum] = "5f511cca8856bb03251d6292ba59e7f98978aae13fa5823ddd8bf885c56a6260" +SRC_URI[sha256sum] = "200a70680ba08904be6d1eef729205cc0d687634399a5924d842533efb824b84" PYPI_PACKAGE = "email_validator" diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-fann2_1.1.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-fann2_1.1.2.bb index 2fbc277139..2099d791dd 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-fann2_1.1.2.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-fann2_1.1.2.bb @@ -1,6 +1,6 @@ SUMMARY = "Python bindings for Fast Artificial Neural Networks 2.2.0 (FANN >= 2.2.0)" SECTION = "devel/python" -LICENSE = "LGPL-2.0-only" +LICENSE = "LGPL-2.1-only" LIC_FILES_CHKSUM = "file://LICENSE;md5=c73b943dc75f6f65e007c56ac6515c8f" SRC_URI[md5sum] = "0b85b418018746d63ed66b55465697a9" diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors/CVE-2024-6221.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors/CVE-2024-6221.patch new file mode 100644 index 0000000000..9049b2ffe6 --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors/CVE-2024-6221.patch @@ -0,0 +1,110 @@ +From 7ae310c56ac30e0b94fb42129aa377bf633256ec Mon Sep 17 00:00:00 2001 +From: Adriano Sela Aviles <adriano.selaviles@gmail.com> +Date: Fri, 30 Aug 2024 12:14:31 -0400 +Subject: [PATCH] Backwards Compatible Fix for CVE-2024-6221 (#363) + +CVE: CVE-2024-6221 + +Upstream-Status: Backport [https://github.com/corydolphin/flask-cors/commit/7ae310c56ac30e0b94fb42129aa377bf633256ec] + +Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com> +--- + docs/configuration.rst | 14 ++++++++++++++ + flask_cors/core.py | 8 +++++--- + flask_cors/extension.py | 16 ++++++++++++++++ + 3 files changed, 35 insertions(+), 3 deletions(-) + +diff --git a/docs/configuration.rst b/docs/configuration.rst +index 91282d3..c750cf4 100644 +--- a/docs/configuration.rst ++++ b/docs/configuration.rst +@@ -23,6 +23,19 @@ CORS_ALLOW_HEADERS (:py:class:`~typing.List` or :py:class:`str`) + Headers to accept from the client. + Headers in the :http:header:`Access-Control-Request-Headers` request header (usually part of the preflight OPTIONS request) matching headers in this list will be included in the :http:header:`Access-Control-Allow-Headers` response header. + ++CORS_ALLOW_PRIVATE_NETWORK (:py:class:`bool`) ++ If True, the response header :http:header:`Access-Control-Allow-Private-Network` ++ will be set with the value 'true' whenever the request header ++ :http:header:`Access-Control-Request-Private-Network` has a value 'true'. ++ ++ If False, the reponse header :http:header:`Access-Control-Allow-Private-Network` ++ will be set with the value 'false' whenever the request header ++ :http:header:`Access-Control-Request-Private-Network` has a value of 'true'. ++ ++ If the request header :http:header:`Access-Control-Request-Private-Network` is ++ not present or has a value other than 'true', the response header ++ :http:header:`Access-Control-Allow-Private-Network` will not be set. ++ + CORS_ALWAYS_SEND (:py:class:`bool`) + Usually, if a request doesn't include an :http:header:`Origin` header, the client did not request CORS. + This means we can ignore this request. +@@ -83,6 +96,7 @@ Default values + ~~~~~~~~~~~~~~ + + * CORS_ALLOW_HEADERS: "*" ++* CORS_ALLOW_PRIVATE_NETWORK: True + * CORS_ALWAYS_SEND: True + * CORS_AUTOMATIC_OPTIONS: True + * CORS_EXPOSE_HEADERS: None +diff --git a/flask_cors/core.py b/flask_cors/core.py +index 5358036..bd011f4 100644 +--- a/flask_cors/core.py ++++ b/flask_cors/core.py +@@ -36,7 +36,7 @@ CONFIG_OPTIONS = ['CORS_ORIGINS', 'CORS_METHODS', 'CORS_ALLOW_HEADERS', + 'CORS_MAX_AGE', 'CORS_SEND_WILDCARD', + 'CORS_AUTOMATIC_OPTIONS', 'CORS_VARY_HEADER', + 'CORS_RESOURCES', 'CORS_INTERCEPT_EXCEPTIONS', +- 'CORS_ALWAYS_SEND'] ++ 'CORS_ALWAYS_SEND', 'CORS_ALLOW_PRIVATE_NETWORK'] + # Attribute added to request object by decorator to indicate that CORS + # was evaluated, in case the decorator and extension are both applied + # to a view. +@@ -56,7 +56,8 @@ DEFAULT_OPTIONS = dict(origins='*', + vary_header=True, + resources=r'/*', + intercept_exceptions=True, +- always_send=True) ++ always_send=True, ++ allow_private_network=True) + + + def parse_resources(resources): +@@ -186,7 +187,8 @@ def get_cors_headers(options, request_headers, request_method): + + if ACL_REQUEST_HEADER_PRIVATE_NETWORK in request_headers \ + and request_headers.get(ACL_REQUEST_HEADER_PRIVATE_NETWORK) == 'true': +- headers[ACL_RESPONSE_PRIVATE_NETWORK] = 'true' ++ allow_private_network = 'true' if options.get('allow_private_network') else 'false' ++ headers[ACL_RESPONSE_PRIVATE_NETWORK] = allow_private_network + + # This is a preflight request + # http://www.w3.org/TR/cors/#resource-preflight-requests +diff --git a/flask_cors/extension.py b/flask_cors/extension.py +index c00cbff..694953f 100644 +--- a/flask_cors/extension.py ++++ b/flask_cors/extension.py +@@ -136,6 +136,22 @@ class CORS(object): + + Default : True + :type vary_header: bool ++ ++ :param allow_private_network: ++ If True, the response header `Access-Control-Allow-Private-Network` ++ will be set with the value 'true' whenever the request header ++ `Access-Control-Request-Private-Network` has a value 'true'. ++ ++ If False, the reponse header `Access-Control-Allow-Private-Network` ++ will be set with the value 'false' whenever the request header ++ `Access-Control-Request-Private-Network` has a value of 'true'. ++ ++ If the request header `Access-Control-Request-Private-Network` is ++ not present or has a value other than 'true', the response header ++ `Access-Control-Allow-Private-Network` will not be set. ++ ++ Default : True ++ :type allow_private_network: bool + """ + + def __init__(self, app=None, **kwargs): +-- +2.40.0 diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors_4.0.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors_4.0.0.bb index 1d0d86b4e7..77b51c5515 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors_4.0.0.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors_4.0.0.bb @@ -9,6 +9,10 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=118fecaa576ab51c1520f95e98db61ce" PYPI_PACKAGE = "Flask-Cors" +SRC_URI += " \ + file://CVE-2024-6221.patch \ +" + SRC_URI[sha256sum] = "f268522fcb2f73e2ecdde1ef45e2fd5c71cc48fe03cffb4b441c6d1b40684eb0" inherit pypi setuptools3 diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-googleapis-common-protos_1.63.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-googleapis-common-protos_1.63.0.bb index aee2337267..3c55294498 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-googleapis-common-protos_1.63.0.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-googleapis-common-protos_1.63.0.bb @@ -1,7 +1,7 @@ DESCRIPTION = "Common protobufs used in Google APIs" HOMEPAGE = "https://github.com/googleapis/python-api-common-protos" LICENSE = "Apache-2.0" -LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/Apache-2.0;md5=89aea4e17d99a7cacdbeed46a0096b10" +LIC_FILES_CHKSUM = "file://LICENSE;md5=3b83ef96387f14655fc854ddc3c6bd57" inherit pypi setuptools3 diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio-tools_1.62.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio-tools_1.62.2.bb index e05b8734d6..5b8bbe681a 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio-tools_1.62.2.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio-tools_1.62.2.bb @@ -16,4 +16,8 @@ SRC_URI[sha256sum] = "5fd5e1582b678e6b941ee5f5809340be5e0724691df5299aae8226640f RDEPENDS:${PN} = "python3-grpcio" +do_compile:prepend() { + export GRPC_PYTHON_BUILD_EXT_COMPILER_JOBS="${@oe.utils.parallel_make(d, False)}" +} + BBCLASSEXTEND = "native nativesdk" diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-PR-1644-unscaledcycleclock-remove-RISC-V-support.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-PR-1644-unscaledcycleclock-remove-RISC-V-support.patch new file mode 100644 index 0000000000..82f15f88cd --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-PR-1644-unscaledcycleclock-remove-RISC-V-support.patch @@ -0,0 +1,82 @@ +From 7335a36d0b5c1c597566f9aa3f458a5b6817c3b4 Mon Sep 17 00:00:00 2001 +From: aurel32 <aurelien@aurel32.net> +Date: Fri, 22 Mar 2024 14:21:13 -0700 +Subject: [PATCH] PR #1644: unscaledcycleclock: remove RISC-V support + +Imported from GitHub PR https://github.com/abseil/abseil-cpp/pull/1644 + +Starting with Linux 6.6 [1], RDCYCLE is a privileged instruction on RISC-V and can't be used directly from userland. There is a sysctl option to change that as a transition period, but it will eventually disappear. + +The RDTIME instruction is another less accurate alternative, however its frequency varies from board to board, and there is currently now way to get its frequency from userland [2]. + +Therefore this patch just removes the code for unscaledcycleclock on RISC-V. Without processor specific implementation, abseil relies on std::chrono::steady_clock::now().time_since_epoch() which is basically a wrapper around clock_gettime (CLOCK_MONOTONIC), which in turns use __vdso_clock_gettime(). On RISC-V this VDSO is just a wrapper around RDTIME correctly scaled to use nanoseconds units. + +This fixes the testsuite on riscv64, tested on a VisionFive 2 board. + +[1] https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cc4c07c89aada16229084eeb93895c95b7eabaa3 +[2] https://github.com/abseil/abseil-cpp/pull/1631 +Merge 43356a2548cfde76e164d446cb69004b488c6a71 into 76f8011beabdaee872b5fde7546e02407b220cb1 + +Merging this change closes #1644 + +COPYBARA_INTEGRATE_REVIEW=https://github.com/abseil/abseil-cpp/pull/1644 from aurel32:rv64-no-unscaledcycleclock 43356a2548cfde76e164d446cb69004b488c6a71 +PiperOrigin-RevId: 618286262 +Change-Id: Ie4120a727e7d0bb185df6e06ea145c780ebe6652 + +Upstream-Status: Backport [https://github.com/abseil/abseil-cpp/commit/7335a36d] +[Adapted to apply on top of meta-oe's patch stack] +Signed-off-by: Scott Murray <scott.murray@konsulko.com> +--- + .../absl/base/internal/unscaledcycleclock.cc | 12 ------------ + .../absl/base/internal/unscaledcycleclock_config.h | 5 ++--- + 2 files changed, 2 insertions(+), 15 deletions(-) + +diff --git a/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock.cc b/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock.cc +index f11fecb..103b4f6 100644 +--- a/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock.cc ++++ b/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock.cc +@@ -121,18 +121,6 @@ double UnscaledCycleClock::Frequency() { + return aarch64_timer_frequency; + } + +-#elif defined(__riscv) +- +-int64_t UnscaledCycleClock::Now() { +- int64_t virtual_timer_value; +- asm volatile("rdcycle %0" : "=r"(virtual_timer_value)); +- return virtual_timer_value; +-} +- +-double UnscaledCycleClock::Frequency() { +- return base_internal::NominalCPUFrequency(); +-} +- + #elif defined(_M_IX86) || defined(_M_X64) + + #pragma intrinsic(__rdtsc) +diff --git a/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock_config.h b/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock_config.h +index 5e232c1..83552fc 100644 +--- a/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock_config.h ++++ b/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock_config.h +@@ -22,7 +22,6 @@ + // The following platforms have an implementation of a hardware counter. + #if defined(__i386__) || defined(__x86_64__) || defined(__aarch64__) || \ + ((defined(__powerpc__) || defined(__ppc__)) && defined(__GLIBC__)) || \ +- defined(__riscv) || \ + defined(_M_IX86) || (defined(_M_X64) && !defined(_M_ARM64EC)) + #define ABSL_HAVE_UNSCALED_CYCLECLOCK_IMPLEMENTATION 1 + #else +@@ -54,8 +53,8 @@ + #if ABSL_USE_UNSCALED_CYCLECLOCK + // This macro can be used to test if UnscaledCycleClock::Frequency() + // is NominalCPUFrequency() on a particular platform. +-#if (defined(__i386__) || defined(__x86_64__) || defined(__riscv) || \ +- defined(_M_IX86) || defined(_M_X64)) ++#if (defined(__i386__) || defined(__x86_64__) || defined(_M_IX86) || \ ++ defined(_M_X64)) + #define ABSL_INTERNAL_UNSCALED_CYCLECLOCK_FREQUENCY_IS_CPU_FREQUENCY + #endif + #endif +-- +2.44.0 + diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-crypto-use-_Generic-only-if-defined-__cplusplus.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-crypto-use-_Generic-only-if-defined-__cplusplus.patch new file mode 100644 index 0000000000..d830d92284 --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-crypto-use-_Generic-only-if-defined-__cplusplus.patch @@ -0,0 +1,74 @@ +From 3359a87a71307336100b84e66b69bad385cd3cfc Mon Sep 17 00:00:00 2001 +From: Martin Jansa <martin.jansa@gmail.com> +Date: Mon, 6 May 2024 01:36:39 +0200 +Subject: [PATCH] crypto: use _Generic only if !defined(__cplusplus) + +* fixes build with gcc-14 which has __builtin_addc and __builtin_subc + with gcc-13 it was already using the #else branch because of missing builtins + +* fixes + https://github.com/grpc/grpc/issues/35945 + +* _Generic was introduced in boringssl with: + https://boringssl.googlesource.com/boringssl/+/70ca6bc24be103dabd68e448cd3af29b929b771d%5E%21/#F4 + +* but e.g. third_party/boringssl-with-bazel/src/ssl/d1_both.cc includes + this internal.h and from the .cc extension gcc will process it as C++ + where _Generic isn't available, causing: + +In file included from third_party/boringssl-with-bazel/src/ssl/d1_both.cc:125: +third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h: In function 'uint32_t CRYPTO_addc_u32(uint32_t, uint32_t, uint32_t, uint32_t*)': +third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1159:7: error: expected primary-expression before 'unsigned' + 1159 | unsigned: __builtin_addc, \ + | ^~~~~~~~ +third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1166:10: note: in expansion of macro 'CRYPTO_GENERIC_ADDC' + 1166 | return CRYPTO_GENERIC_ADDC(x, y, carry, out_carry); + | ^~~~~~~~~~~~~~~~~~~ +third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1160:7: error: expected primary-expression before 'unsigned' + 1160 | unsigned long: __builtin_addcl, \ + | ^~~~~~~~ +third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1166:10: note: in expansion of macro 'CRYPTO_GENERIC_ADDC' + 1166 | return CRYPTO_GENERIC_ADDC(x, y, carry, out_carry); + | ^~~~~~~~~~~~~~~~~~~ +third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1161:7: error: expected primary-expression before 'unsigned' + 1161 | unsigned long long: __builtin_addcll))((x), (y), (carry), (out_carry)) + | ^~~~~~~~ +third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1166:10: note: in expansion of macro 'CRYPTO_GENERIC_ADDC' + 1166 | return CRYPTO_GENERIC_ADDC(x, y, carry, out_carry); + | ^~~~~~~~~~~~~~~~~~~ +third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1158:4: error: '_Generic' was not declared in this scope + 1158 | (_Generic((x), \ + | ^~~~~~~~ +third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1166:10: note: in expansion of macro 'CRYPTO_GENERIC_ADDC' + 1166 | return CRYPTO_GENERIC_ADDC(x, y, carry, out_carry); + | ^~~~~~~~~~~~~~~~~~~ + +Signed-off-by: Martin Jansa <martin.jansa@gmail.com> +--- +Upstream-Status: Submitted [https://boringssl-review.googlesource.com/c/boringssl/+/68227 crypto: use _Generic only if !defined(__cplusplus)] + + crypto/internal.h | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/crypto/internal.h b/crypto/internal.h +index a77102d76..30d6826dd 100644 +--- a/crypto/internal.h ++++ b/crypto/internal.h +@@ -1176,7 +1176,7 @@ static inline uint64_t CRYPTO_rotr_u64(uint64_t value, int shift) { + + // CRYPTO_addc_* returns |x + y + carry|, and sets |*out_carry| to the carry + // bit. |carry| must be zero or one. +-#if OPENSSL_HAS_BUILTIN(__builtin_addc) ++#if OPENSSL_HAS_BUILTIN(__builtin_addc) && !defined(__cplusplus) + + #define CRYPTO_GENERIC_ADDC(x, y, carry, out_carry) \ + (_Generic((x), \ +@@ -1228,7 +1228,7 @@ static inline uint64_t CRYPTO_addc_u64(uint64_t x, uint64_t y, uint64_t carry, + + // CRYPTO_subc_* returns |x - y - borrow|, and sets |*out_borrow| to the borrow + // bit. |borrow| must be zero or one. +-#if OPENSSL_HAS_BUILTIN(__builtin_subc) ++#if OPENSSL_HAS_BUILTIN(__builtin_subc) && !defined(__cplusplus) + + #define CRYPTO_GENERIC_SUBC(x, y, borrow, out_borrow) \ + (_Generic((x), \ diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/CVE-2024-11407.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/CVE-2024-11407.patch new file mode 100644 index 0000000000..eef5e7239e --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/CVE-2024-11407.patch @@ -0,0 +1,32 @@ +From e9046b2bbebc0cb7f5dc42008f807f6c7e98e791 Mon Sep 17 00:00:00 2001 +From: Vignesh Babu <vigneshbabu@google.com> +Date: Thu, 12 Sep 2024 11:13:45 -0700 +Subject: [PATCH] [EventEngine] Fix bug in Tx0cp code path in posix endpoint. + +This fix ensures that the iov_base pointers point to the right address. + +PiperOrigin-RevId: 673923651 + +CVE: CVE-2024-11407 +Upstream-Status: Backport [https://github.com/grpc/grpc/commit/e9046b2bbebc0cb7f5dc42008f807f6c7e98e791] +Signed-off-by: Peter Marko <peter.marko@siemens.com> +--- + src/core/lib/event_engine/posix_engine/posix_endpoint.cc | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/core/lib/event_engine/posix_engine/posix_endpoint.cc b/src/core/lib/event_engine/posix_engine/posix_endpoint.cc +index 7634bb1334b..c5708db02c5 100644 +--- a/src/core/lib/event_engine/posix_engine/posix_endpoint.cc ++++ b/src/core/lib/event_engine/posix_engine/posix_endpoint.cc +@@ -240,7 +240,7 @@ msg_iovlen_type TcpZerocopySendRecord::PopulateIovs(size_t* unwind_slice_idx, + iov_size++) { + MutableSlice& slice = internal::SliceCast<MutableSlice>( + buf_.MutableSliceAt(out_offset_.slice_idx)); +- iov[iov_size].iov_base = slice.begin(); ++ iov[iov_size].iov_base = slice.begin() + out_offset_.byte_idx; + iov[iov_size].iov_len = slice.length() - out_offset_.byte_idx; + *sending_length += iov[iov_size].iov_len; + ++(out_offset_.slice_idx); +-- +2.30.2 + diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio_1.62.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio_1.62.2.bb index 80a4d04e67..3581991a56 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio_1.62.2.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio_1.62.2.bb @@ -9,7 +9,10 @@ DEPENDS += "python3-protobuf" SRC_URI += "file://0001-Include-missing-cstdint-header.patch \ file://abseil-ppc-fixes.patch \ file://0001-zlib-Include-unistd.h-for-open-close-C-APIs.patch \ + file://0001-crypto-use-_Generic-only-if-defined-__cplusplus.patch;patchdir=third_party/boringssl-with-bazel/src/ \ file://0001-target.h-define-proper-macro-for-ppc-ppc64.patch \ + file://0001-PR-1644-unscaledcycleclock-remove-RISC-V-support.patch \ + file://CVE-2024-11407.patch \ " SRC_URI[sha256sum] = "c77618071d96b7a8be2c10701a98537823b9c65ba256c0b9067e0594cdbd954d" @@ -35,6 +38,10 @@ BORING_SSL:aarch64 = "1" BORING_SSL ?= "0" export GRPC_BUILD_WITH_BORING_SSL_ASM = "${BORING_SSL}" +do_compile:prepend() { + export GRPC_PYTHON_BUILD_EXT_COMPILER_JOBS="${@oe.utils.parallel_make(d, False)}" +} + GRPC_CFLAGS ?= "" GRPC_CFLAGS:append:toolchain-clang = " -fvisibility=hidden -fno-wrapv -fno-exceptions" export GRPC_PYTHON_CFLAGS = "${GRPC_CFLAGS}" diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0001-Properly-cast-arguments-to-H5Lunpack_elink_val.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0001-Properly-cast-arguments-to-H5Lunpack_elink_val.patch new file mode 100644 index 0000000000..c39d9b1950 --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0001-Properly-cast-arguments-to-H5Lunpack_elink_val.patch @@ -0,0 +1,25 @@ +From 30a59c233fbe149109f378837642dc02b2caf3f5 Mon Sep 17 00:00:00 2001 +From: Orion Poplawski <orion@nwra.com> +Date: Thu, 15 Feb 2024 20:47:50 -0700 +Subject: [PATCH] Properly cast arguments to H5Lunpack_elink_val + +Upstream-Status: Backport [https://github.com/h5py/h5py/pull/2380/commits/704e13ac83b42898514610c4df9f32f367e767e4] + +Signed-off-by: Martin Jansa <martin.jansa@gmail.com> +--- + h5py/h5l.pyx | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/h5py/h5l.pyx b/h5py/h5l.pyx +index 60b252f..af725bd 100644 +--- a/h5py/h5l.pyx ++++ b/h5py/h5l.pyx +@@ -184,7 +184,7 @@ cdef class LinkProxy: + if info.type == H5L_TYPE_SOFT: + py_retval = buf + else: +- H5Lunpack_elink_val(buf, buf_size, &wtf, &ext_file_name, &ext_obj_name) ++ H5Lunpack_elink_val(buf, buf_size, &wtf, <const char **>&ext_file_name, <const char **>&ext_obj_name) + py_retval = (bytes(ext_file_name), bytes(ext_obj_name)) + finally: + efree(buf) diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0002-Use-libc.stdint-instead-of-numpy.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0002-Use-libc.stdint-instead-of-numpy.patch new file mode 100644 index 0000000000..35263d8315 --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0002-Use-libc.stdint-instead-of-numpy.patch @@ -0,0 +1,25 @@ +From 8b4de2f6946b1c1f68279ecadc05c2817ae82189 Mon Sep 17 00:00:00 2001 +From: Orion Poplawski <orion@nwra.com> +Date: Thu, 22 Feb 2024 08:41:17 -0700 +Subject: [PATCH] Use libc.stdint instead of numpy + +Upstream-Status: Backport [https://github.com/h5py/h5py/pull/2382/commits/387a22b8c1513800c0401f496b4ed512c1639798] + +Signed-off-by: Martin Jansa <martin.jansa@gmail.com> +--- + h5py/api_types_ext.pxd | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/h5py/api_types_ext.pxd b/h5py/api_types_ext.pxd +index 91acb12..55a239f 100644 +--- a/h5py/api_types_ext.pxd ++++ b/h5py/api_types_ext.pxd +@@ -20,7 +20,7 @@ from libc.string cimport strlen, strchr, strcpy, strncpy, strcmp,\ + ctypedef long size_t + from libc.time cimport time_t + +-from numpy cimport int8_t, uint8_t, int16_t, uint16_t, int32_t, uint32_t, int64_t, uint64_t ++from libc.stdint cimport int8_t, uint8_t, int16_t, uint16_t, int32_t, uint32_t, int64_t, uint64_t + + IF UNAME_SYSNAME != "Windows": + cdef extern from "unistd.h": diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py_3.10.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py_3.10.0.bb index 8a9158525e..3ba5ea7396 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py_3.10.0.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py_3.10.0.bb @@ -6,8 +6,12 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=113251d71fb0384712c719b567261c5c" SRC_URI[sha256sum] = "d93adc48ceeb33347eb24a634fb787efc7ae4644e6ea4ba733d099605045c049" -SRC_URI += "file://0001-setup_build.py-avoid-absolute-path.patch \ - file://0001-Fix-Cython-3-compatibility.patch" +SRC_URI += " \ + file://0001-setup_build.py-avoid-absolute-path.patch \ + file://0001-Fix-Cython-3-compatibility.patch \ + file://0001-Properly-cast-arguments-to-H5Lunpack_elink_val.patch \ + file://0002-Use-libc.stdint-instead-of-numpy.patch \ +" inherit pkgconfig pypi setuptools3 diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-haversine_2.8.1.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-haversine_2.8.1.bb index e45ae79860..5fd5ddd71c 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-haversine_2.8.1.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-haversine_2.8.1.bb @@ -1,6 +1,6 @@ SUMMARY = "Calculate the distance between 2 points on Earth" LICENSE = "MIT" -LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302" +LIC_FILES_CHKSUM = "file://LICENSE;md5=20a52d2c688975e989fcbee3e6c8d1a1" SRC_URI[sha256sum] = "ab750caa0c8f2168bd7b00a429757a83a8393be1aa30f91c2becf6b523189e2a" diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-kivy_2.3.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-kivy_2.3.0.bb index 991aa0f7d8..2c66db188b 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-kivy_2.3.0.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-kivy_2.3.0.bb @@ -70,3 +70,10 @@ RDEPENDS:${PN} = " \ python3-pillow \ python3-pygments \ " + +do_compile:append() { + for f in `find ${B} -name *.c` + do + sed -i -e "/BEGIN: Cython Metadata/,/END: Cython Metadata/d" $f + done +} diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-libevdev_0.11.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-libevdev_0.11.bb index 27e336710c..5ad2a59951 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-libevdev_0.11.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-libevdev_0.11.bb @@ -3,7 +3,7 @@ HOMEPAGE = "https://gitlab.freedesktop.org/libevdev/python-libevdev" SECTION = "devel/python" LICENSE = "MIT" -LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302" +LIC_FILES_CHKSUM = "file://COPYING;md5=d94c10c546b419eddc6296157ec40747" SRC_URI[md5sum] = "34b48098c1fba26de79a0d67a17a588a" SRC_URI[sha256sum] = "e9ca006a4df2488a60bd9a740011ee948d81904be2364f017e560169508f560f" diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-lru-dict_1.3.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-lru-dict_1.3.0.bb index e9535fa6f1..51f3860b07 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-lru-dict_1.3.0.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-lru-dict_1.3.0.bb @@ -1,7 +1,7 @@ -SUMMARY = "A fixed size dict like container which evicts Least Recently Used (LRU) items once size limit is exceeded." +DESCRIPTION = "A fixed size dict like container which evicts Least Recently Used (LRU) items once size limit is exceeded." HOMEPAGE = "https://github.com/amitdev/lru-dict" SECTION = "devel/python" -LICENSE = "BSD-3-Clause" +LICENSE = "MIT" LIC_FILES_CHKSUM = "file://LICENSE;md5=9d10a486ee04034fdef5162fd791f153" SRC_URI[sha256sum] = "54fd1966d6bd1fcde781596cb86068214edeebff1db13a2cea11079e3fd07b6b" diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-mock_5.1.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-mock_5.1.0.bb index d9ecb9d4c8..1b89260e1b 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-mock_5.1.0.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-mock_5.1.0.bb @@ -1,7 +1,7 @@ DESCRIPTION = "A Python Mocking and Patching Library for Testing" HOMEPAGE = "https://pypi.python.org/pypi/mock" SECTION = "devel/python" -LICENSE = "Apache-2.0" +LICENSE = "BSD-2-Clause" LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=de9dfbf780446b18aab11f00baaf5b7e" inherit pypi setuptools3 diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-nmap_1.6.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-nmap_1.6.0.bb index 5fe9ab4e39..2293e3ddf8 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-nmap_1.6.0.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-nmap_1.6.0.bb @@ -1,8 +1,8 @@ DESCRIPTION = "python-nmap is a python library which helps in using nmap port scanner" HOMEPAGE = "https://www.nmmapper.com/" SECTION = "devel/python" -LICENSE = "MIT" -LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302" +LICENSE = "GPL-3.0-only" +LIC_FILES_CHKSUM = "file://LICENSE;md5=1ebbd3e34237af26da5dc08a4e440464" DEPENDS += "python3-wheel-native" diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-parse-type_0.6.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-parse-type_0.6.2.bb index a7d8cd86ce..57dfc5a508 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-parse-type_0.6.2.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-parse-type_0.6.2.bb @@ -1,6 +1,6 @@ SUMMARY = "Simplifies building parse types based on the parse module" HOMEPAGE = "https://github.com/jenisys/parse_type" -LICENSE = "BSD-3-Clause" +LICENSE = "MIT" LIC_FILES_CHKSUM = "file://LICENSE;md5=2e469278ace89c246d52505acc39c3da" SRC_URI[sha256sum] = "79b1f2497060d0928bc46016793f1fca1057c4aacdf15ef876aa48d75a73a355" diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pillow_10.3.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pillow_10.3.0.bb index debf488154..8b0bcf55dd 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pillow_10.3.0.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pillow_10.3.0.bb @@ -1,8 +1,8 @@ -SUMMARY = "Python Imaging Library (Fork). Pillow is the friendly PIL fork by Alex \ +DESCRIPTION = "Python Imaging Library (Fork). Pillow is the friendly PIL fork by Alex \ Clark and Contributors. PIL is the Python Imaging Library by Fredrik Lundh and \ Contributors." HOMEPAGE = "https://pillow.readthedocs.io" -LICENSE = "MIT" +LICENSE = "HPND" LIC_FILES_CHKSUM = "file://LICENSE;md5=c349a4b4b9ec2377a8fd6a7df87dbffe" SRC_URI = "git://github.com/python-pillow/Pillow.git;branch=main;protocol=https \ diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-platformdirs_4.2.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-platformdirs_4.2.0.bb index 19c95b374a..c69c390b80 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-platformdirs_4.2.0.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-platformdirs_4.2.0.bb @@ -1,6 +1,6 @@ SUMMARY = "A small Python module for determining appropriate platform-specific dirs" HOMEPAGE = "https://github.com/platformdirs/platformdirs" -LICENSE = "BSD-3-Clause" +LICENSE = "MIT" LIC_FILES_CHKSUM = "file://LICENSE;md5=ea4f5a41454746a9ed111e3d8723d17a" SRC_URI += " \ diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0001-build_support-use-source-filename-instead-of-foo-for.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0001-build_support-use-source-filename-instead-of-foo-for.patch new file mode 100644 index 0000000000..8bb7267086 --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0001-build_support-use-source-filename-instead-of-foo-for.patch @@ -0,0 +1,50 @@ +From 09cfcf7de2aab873a13949d5a128ccfb9e54732d Mon Sep 17 00:00:00 2001 +From: Martin Jansa <martin.jansa@gmail.com> +Date: Mon, 5 May 2025 08:15:37 +0200 +Subject: [PATCH] build_support: use source filename instead of 'foo' for + discover tests + +* helps when debugging the issues +* use the same order of CC arguments in compile_and_run and + does_build_succeed just for consistency +* use pthread in both compile_and_run and does_build_succeed functions + it was added only to does_build_succeed in 5ec39f7af8cfd8525d225b1302fa93f7133b3849 + not sure if it was intentional + +Signed-off-by: Martin Jansa <martin.jansa@gmail.com> +Upstream-Status: Submitted [https://github.com/osvenskan/posix_ipc/pull/77] +--- + build_support/discover_system_info.py | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/build_support/discover_system_info.py b/build_support/discover_system_info.py +index bc4d174..6d059d9 100644 +--- a/build_support/discover_system_info.py ++++ b/build_support/discover_system_info.py +@@ -60,7 +60,7 @@ def does_build_succeed(filename, linker_options=""): + # Rather than testing whether or not it's needed, I just specify it + # everywhere since it's harmless to specify it when it's not needed. + cc = os.getenv("CC", "cc") +- cmd = "%s -Wall -o ./build_support/src/foo ./build_support/src/%s %s -lpthread" % (cc, filename, linker_options) ++ cmd = "%s -Wall -o ./build_support/src/%s ./build_support/src/%s %s -lpthread" % (cc, filename[:-2], filename, linker_options) + + p = subprocess.Popen(cmd, shell=True, stdout=STDOUT, stderr=STDERR) + +@@ -73,7 +73,7 @@ def compile_and_run(filename, linker_options=""): + # Utility function that returns the stdout output from running the + # compiled source file; None if the compile fails. + cc = os.getenv("CC", "cc") +- cmd = "%s -Wall -o ./build_support/src/foo %s ./build_support/src/%s" % (cc, linker_options, filename) ++ cmd = "%s -Wall -o ./build_support/src/%s ./build_support/src/%s %s -lpthread" % (cc, filename[:-2], filename, linker_options) + + p = subprocess.Popen(cmd, shell=True, stdout=STDOUT, stderr=STDERR) + +@@ -82,7 +82,7 @@ def compile_and_run(filename, linker_options=""): + return None + + try: +- s = subprocess.Popen(["./build_support/src/foo"], ++ s = subprocess.Popen(["./build_support/src/%s" % filename[:-2]], + stdout=subprocess.PIPE).communicate()[0] + return s.strip().decode() + except Exception: diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0002-build_support-handle-empty-max_priority-value-as-Non.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0002-build_support-handle-empty-max_priority-value-as-Non.patch new file mode 100644 index 0000000000..54c8ddaba7 --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0002-build_support-handle-empty-max_priority-value-as-Non.patch @@ -0,0 +1,49 @@ +From 8fc46d871639dbe799f6ff0a61b046412ef5dcc6 Mon Sep 17 00:00:00 2001 +From: Martin Jansa <martin.jansa@gmail.com> +Date: Mon, 5 May 2025 08:16:30 +0200 +Subject: [PATCH] build_support: handle empty max_priority value as None +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +When cross-compiling these tests they fail when the host cannot execute +the binaries built for target. + +On my local ubuntu-22.04 docker container running +build_support/src/sniff_mq_prio_max results in: +posix_ipc-1.2.0 $ ./build_support/src/foo +bash: ./build_support/src/foo: cannot execute binary file: Exec format error +which triggers the Exception in compile_and_run and returns None + +While on some other ubuntu-22.04 containers I see: +posix_ipc-1.2.0$ ./build_support/src/sniff_mq_prio_max +/usr/lib/ld-linux-aarch64.so.1: No such file or directory + +and the compile_and_run returns +b'' +which then causes +posix_ipc-1.2.0/build_support/discover_system_info.py", line 244, in sniff_mq_prio_max + if max_priority < 0: + ^^^^^^^^^^^^^^^^ + +Handle the empty value the same as None to avoid this. + +Signed-off-by: Martin Jansa <martin.jansa@gmail.com> +Upstream-Status: Submitted [https://github.com/osvenskan/posix_ipc/pull/77] +--- + build_support/discover_system_info.py | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/build_support/discover_system_info.py b/build_support/discover_system_info.py +index 6d059d9..f8a3c83 100644 +--- a/build_support/discover_system_info.py ++++ b/build_support/discover_system_info.py +@@ -223,7 +223,7 @@ def sniff_mq_prio_max(): + except ValueError: + max_priority = None + +- if max_priority is None: ++ if not max_priority: + # Looking for a #define didn't work; ask sysconf() instead. + # Note that sys.sysconf_names doesn't exist under Cygwin. + if hasattr(os, "sysconf_names") and \ diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0003-build_support-use-does_build_succeed-in-compile_and_.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0003-build_support-use-does_build_succeed-in-compile_and_.patch new file mode 100644 index 0000000000..b36d1cdb3a --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0003-build_support-use-does_build_succeed-in-compile_and_.patch @@ -0,0 +1,62 @@ +From 760374e778fc28193cfea1416a739e206f9201c6 Mon Sep 17 00:00:00 2001 +From: Martin Jansa <martin.jansa@gmail.com> +Date: Mon, 5 May 2025 08:28:56 +0200 +Subject: [PATCH] build_support: use does_build_succeed in compile_and_run + +* avoid the duplication and building the sniff_mq_prio_max.c twice + +Signed-off-by: Martin Jansa <martin.jansa@gmail.com> +Upstream-Status: Submitted [https://github.com/osvenskan/posix_ipc/pull/77] +--- + build_support/discover_system_info.py | 27 ++++++++++----------------- + 1 file changed, 10 insertions(+), 17 deletions(-) + +diff --git a/build_support/discover_system_info.py b/build_support/discover_system_info.py +index f8a3c83..f6e6c8c 100644 +--- a/build_support/discover_system_info.py ++++ b/build_support/discover_system_info.py +@@ -72,22 +72,17 @@ def does_build_succeed(filename, linker_options=""): + def compile_and_run(filename, linker_options=""): + # Utility function that returns the stdout output from running the + # compiled source file; None if the compile fails. +- cc = os.getenv("CC", "cc") +- cmd = "%s -Wall -o ./build_support/src/%s ./build_support/src/%s %s -lpthread" % (cc, filename[:-2], filename, linker_options) +- +- p = subprocess.Popen(cmd, shell=True, stdout=STDOUT, stderr=STDERR) +- +- if p.wait(): ++ if does_build_succeed(filename, linker_options=""): ++ try: ++ s = subprocess.Popen(["./build_support/src/%s" % filename[:-2]], ++ stdout=subprocess.PIPE).communicate()[0] ++ return s.strip().decode() ++ except Exception: ++ # execution resulted in an error ++ return None ++ else: + # uh-oh, compile failed + return None +- +- try: +- s = subprocess.Popen(["./build_support/src/%s" % filename[:-2]], +- stdout=subprocess.PIPE).communicate()[0] +- return s.strip().decode() +- except Exception: +- # execution resulted in an error +- return None + + + def get_sysctl_value(name): +@@ -211,11 +206,9 @@ def sniff_mq_prio_max(): + # ref: http://www.opengroup.org/onlinepubs/009695399/basedefs/limits.h.html + DEFAULT_PRIORITY_MAX = 32 + +- max_priority = None + # OS X up to and including 10.8 doesn't support POSIX messages queues and + # doesn't define MQ_PRIO_MAX. Maybe this aggravation will cease in 10.9? +- if does_build_succeed("sniff_mq_prio_max.c"): +- max_priority = compile_and_run("sniff_mq_prio_max.c") ++ max_priority = compile_and_run("sniff_mq_prio_max.c") + + if max_priority: + try: diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0004-build_support-handle-runtime-errors-and-return-None-.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0004-build_support-handle-runtime-errors-and-return-None-.patch new file mode 100644 index 0000000000..e84345a397 --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0004-build_support-handle-runtime-errors-and-return-None-.patch @@ -0,0 +1,47 @@ +From b079074048bc33b206b21f73fecb8173cf8adaf0 Mon Sep 17 00:00:00 2001 +From: Haixiao Yan <haixiao.yan.cn@windriver.com> +Date: Mon, 15 Sep 2025 21:15:45 +0800 +Subject: [PATCH] build_support: handle runtime errors and return None for + invalid max_priority + +When cross-compiling, test binaries may fail to execute on the host system if +the target toolchain was built against a newer glibc version than what is +available on the host. + +For example, on Ubuntu 20.04 the following error occurs: + +./build_support/src/sniff_mq_prio_max: /lib/x86_64-linux-gnu/libc.so.6: version +`GLIBC_2.34' not found (required by ./build_support/src/sniff_mq_prio_max) + +This change ensures that such runtime errors are gracefully handled, and +max_priority is set to None when the test binary cannot be executed. + +Upstream-Status: Pending + +Signed-off-by: Haixiao Yan <haixiao.yan.cn@windriver.com> +--- + build_support/discover_system_info.py | 8 ++++++-- + 1 file changed, 6 insertions(+), 2 deletions(-) + +diff --git a/build_support/discover_system_info.py b/build_support/discover_system_info.py +index f6e6c8cbe6ba..4fec48b5529d 100644 +--- a/build_support/discover_system_info.py ++++ b/build_support/discover_system_info.py +@@ -75,8 +75,12 @@ def compile_and_run(filename, linker_options=""): + if does_build_succeed(filename, linker_options=""): + try: + s = subprocess.Popen(["./build_support/src/%s" % filename[:-2]], +- stdout=subprocess.PIPE).communicate()[0] +- return s.strip().decode() ++ stdout=subprocess.PIPE, stderr=subprocess.PIPE) ++ stdout, stderr = s.communicate() ++ if s.returncode != 0: ++ # runtime error ++ return None ++ return stdout.strip().decode() + except Exception: + # execution resulted in an error + return None +-- +2.25.1 + diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.1.1.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.1.1.bb deleted file mode 100644 index a71187399b..0000000000 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.1.1.bb +++ /dev/null @@ -1,11 +0,0 @@ -DESCRIPTION = "POSIX IPC primitives (semaphores, shared memory and message queues) for Python" -HOMEPAGE = "http://semanchuk.com/philip/posix_ipc/" -SECTION = "devel/python" -LICENSE = "BSD-3-Clause" -LIC_FILES_CHKSUM = "file://LICENSE;md5=513d94a7390d4d72f3475e2d45c739b5" - -PYPI_PACKAGE = "posix_ipc" - -SRC_URI[sha256sum] = "e2456ba0cfb2ee5ba14121450e8d825b3c4a1461fca0761220aab66d4111cbb7" - -inherit setuptools3 pypi diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.2.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.2.0.bb new file mode 100644 index 0000000000..cad1403813 --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.2.0.bb @@ -0,0 +1,17 @@ +DESCRIPTION = "POSIX IPC primitives (semaphores, shared memory and message queues) for Python" +HOMEPAGE = "http://semanchuk.com/philip/posix_ipc/" +SECTION = "devel/python" +LICENSE = "BSD-3-Clause" +LIC_FILES_CHKSUM = "file://LICENSE;md5=1a4f3bd729df04bf68f66ef877e9c7c9" + +PYPI_PACKAGE = "posix_ipc" + +SRC_URI[sha256sum] = "b7444e2703c156b3cb9fcb568e85d716232f3e78f04529ebc881cfb2aedb3838" + +SRC_URI += " \ + file://0001-build_support-use-source-filename-instead-of-foo-for.patch \ + file://0002-build_support-handle-empty-max_priority-value-as-Non.patch \ + file://0003-build_support-use-does_build_succeed-in-compile_and_.patch \ + file://0004-build_support-handle-runtime-errors-and-return-None-.patch \ +" +inherit pypi python_setuptools_build_meta diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-protobuf_4.25.3.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-protobuf_4.25.8.bb index b9b03badd0..aca30efdee 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-protobuf_4.25.3.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-protobuf_4.25.8.bb @@ -6,7 +6,7 @@ LICENSE = "BSD-3-Clause" LIC_FILES_CHKSUM = "file://PKG-INFO;beginline=8;endline=8;md5=53dbfa56f61b90215a9f8f0d527c043d" inherit pypi setuptools3 -SRC_URI[sha256sum] = "25b5d0b42fd000320bd7830b349e3b696435f3b329810427a6bcce6a5492cc5c" +SRC_URI[sha256sum] = "6135cf8affe1fc6f76cced2641e4ea8d3e59518d1f24ae41ba97bcad82d397cd" # http://errors.yoctoproject.org/Errors/Details/184715/ # Can't find required file: ../src/google/protobuf/descriptor.proto @@ -35,3 +35,11 @@ DISTUTILS_INSTALL_ARGS += "--cpp_implementation" do_compile:prepend:class-native () { export KOKORO_BUILD_NUMBER="1" } + +do_install:append () { + # Remove useless and problematic .pth file. python3-protobuf is installed in the standard + # location of site packages. No need for such .pth file. + # NOTE: do not drop this removal until the following issue in upstream cpython is resolved: + # https://github.com/python/cpython/issues/122220 + rm -f ${D}${PYTHON_SITEPACKAGES_DIR}/protobuf-*-nspkg.pth +} diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pycocotools_2.0.7.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pycocotools_2.0.7.bb index bebfb128f2..15fdbcf89c 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pycocotools_2.0.7.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pycocotools_2.0.7.bb @@ -9,3 +9,7 @@ SRC_URI[sha256sum] = "da8b7815196eebf0adabf67fcc459126cbc6498bbc6ab1fd144c371465 DEPENDS = "python3-cython-native python3-numpy-native virtual/crypt" RDEPENDS:${PN} = "python3-matplotlib python3-pillow python3-profile" + +do_compile:append() { + sed -i -e "/BEGIN: Cython Metadata/,/END: Cython Metadata/d" ${B}/pycocotools/_mask.c +} diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pycurl_7.45.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pycurl_7.45.2.bb index a6863e21ff..10d3cd1027 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pycurl_7.45.2.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pycurl_7.45.2.bb @@ -7,7 +7,7 @@ be used to fetch objects identified by a URL from a Python program \ SECTION = "devel/python" HOMEPAGE = "http://pycurl.io/" -LICENSE = "LGPL-2.0-only | MIT" +LICENSE = "LGPL-2.1-only | MIT" LIC_FILES_CHKSUM = "file://COPYING-LGPL;md5=4fbd65380cdd255951079008b364516c \ file://COPYING-MIT;md5=be42e1b1e58c8d59c2901fd747bfc55d \ " diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core-crates.inc b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core-crates.inc index dd2027948c..c6b30bc677 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core-crates.inc +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core-crates.inc @@ -2,31 +2,29 @@ # from Cargo.lock SRC_URI += " \ - crate://crates.io/ahash/0.8.7 \ + crate://crates.io/ahash/0.8.10 \ crate://crates.io/aho-corasick/1.0.2 \ - crate://crates.io/allocator-api2/0.2.16 \ crate://crates.io/autocfg/1.1.0 \ crate://crates.io/base64/0.21.7 \ crate://crates.io/bitflags/1.3.2 \ + crate://crates.io/bitvec/1.0.1 \ crate://crates.io/cc/1.0.79 \ crate://crates.io/cfg-if/1.0.0 \ - crate://crates.io/enum_dispatch/0.3.12 \ + crate://crates.io/enum_dispatch/0.3.13 \ crate://crates.io/equivalent/1.0.1 \ crate://crates.io/form_urlencoded/1.2.1 \ + crate://crates.io/funty/2.0.0 \ crate://crates.io/getrandom/0.2.10 \ crate://crates.io/hashbrown/0.14.3 \ crate://crates.io/heck/0.4.1 \ crate://crates.io/idna/0.5.0 \ - crate://crates.io/indexmap/2.0.0 \ + crate://crates.io/indexmap/2.2.2 \ crate://crates.io/indoc/2.0.4 \ crate://crates.io/itoa/1.0.8 \ - crate://crates.io/jiter/0.0.6 \ - crate://crates.io/lexical-core/0.8.5 \ + crate://crates.io/jiter/0.4.1 \ crate://crates.io/lexical-parse-float/0.8.5 \ crate://crates.io/lexical-parse-integer/0.8.6 \ crate://crates.io/lexical-util/0.8.5 \ - crate://crates.io/lexical-write-float/0.8.5 \ - crate://crates.io/lexical-write-integer/0.8.5 \ crate://crates.io/libc/0.2.147 \ crate://crates.io/lock_api/0.4.10 \ crate://crates.io/memchr/2.6.3 \ @@ -40,29 +38,32 @@ SRC_URI += " \ crate://crates.io/percent-encoding/2.3.1 \ crate://crates.io/portable-atomic/1.6.0 \ crate://crates.io/proc-macro2/1.0.76 \ - crate://crates.io/pyo3/0.20.3 \ - crate://crates.io/pyo3-build-config/0.20.3 \ - crate://crates.io/pyo3-ffi/0.20.3 \ - crate://crates.io/pyo3-macros/0.20.3 \ - crate://crates.io/pyo3-macros-backend/0.20.3 \ + crate://crates.io/pyo3/0.21.2 \ + crate://crates.io/pyo3-build-config/0.21.2 \ + crate://crates.io/pyo3-ffi/0.21.2 \ + crate://crates.io/pyo3-macros/0.21.2 \ + crate://crates.io/pyo3-macros-backend/0.21.2 \ crate://crates.io/python3-dll-a/0.2.9 \ crate://crates.io/quote/1.0.35 \ + crate://crates.io/radium/0.7.0 \ crate://crates.io/redox_syscall/0.3.5 \ - crate://crates.io/regex/1.10.2 \ - crate://crates.io/regex-automata/0.4.3 \ + crate://crates.io/regex/1.10.4 \ + crate://crates.io/regex-automata/0.4.5 \ crate://crates.io/regex-syntax/0.8.2 \ crate://crates.io/rustversion/1.0.13 \ crate://crates.io/ryu/1.0.14 \ crate://crates.io/scopeguard/1.1.0 \ - crate://crates.io/serde/1.0.195 \ - crate://crates.io/serde_derive/1.0.195 \ - crate://crates.io/serde_json/1.0.109 \ - crate://crates.io/smallvec/1.11.2 \ - crate://crates.io/speedate/0.13.0 \ + crate://crates.io/serde/1.0.203 \ + crate://crates.io/serde_derive/1.0.203 \ + crate://crates.io/serde_json/1.0.116 \ + crate://crates.io/smallvec/1.13.2 \ + crate://crates.io/speedate/0.14.0 \ crate://crates.io/static_assertions/1.1.0 \ crate://crates.io/strum/0.25.0 \ crate://crates.io/strum_macros/0.25.3 \ + crate://crates.io/strum_macros/0.26.1 \ crate://crates.io/syn/2.0.48 \ + crate://crates.io/tap/1.0.1 \ crate://crates.io/target-lexicon/0.12.9 \ crate://crates.io/tinyvec/1.6.0 \ crate://crates.io/tinyvec_macros/0.1.1 \ @@ -71,7 +72,7 @@ SRC_URI += " \ crate://crates.io/unicode-normalization/0.1.22 \ crate://crates.io/unindent/0.2.3 \ crate://crates.io/url/2.5.0 \ - crate://crates.io/uuid/1.6.1 \ + crate://crates.io/uuid/1.8.0 \ crate://crates.io/version_check/0.9.4 \ crate://crates.io/wasi/0.11.0+wasi-snapshot-preview1 \ crate://crates.io/windows-targets/0.48.1 \ @@ -82,35 +83,34 @@ SRC_URI += " \ crate://crates.io/windows_x86_64_gnu/0.48.0 \ crate://crates.io/windows_x86_64_gnullvm/0.48.0 \ crate://crates.io/windows_x86_64_msvc/0.48.0 \ + crate://crates.io/wyz/0.5.1 \ crate://crates.io/zerocopy/0.7.32 \ crate://crates.io/zerocopy-derive/0.7.32 \ " -SRC_URI[ahash-0.8.7.sha256sum] = "77c3a9648d43b9cd48db467b3f87fdd6e146bcc88ab0180006cef2179fe11d01" +SRC_URI[ahash-0.8.10.sha256sum] = "8b79b82693f705137f8fb9b37871d99e4f9a7df12b917eed79c3d3954830a60b" SRC_URI[aho-corasick-1.0.2.sha256sum] = "43f6cb1bf222025340178f382c426f13757b2960e89779dfcb319c32542a5a41" -SRC_URI[allocator-api2-0.2.16.sha256sum] = "0942ffc6dcaadf03badf6e6a2d0228460359d5e34b57ccdc720b7382dfbd5ec5" SRC_URI[autocfg-1.1.0.sha256sum] = "d468802bab17cbc0cc575e9b053f41e72aa36bfa6b7f55e3529ffa43161b97fa" SRC_URI[base64-0.21.7.sha256sum] = "9d297deb1925b89f2ccc13d7635fa0714f12c87adce1c75356b39ca9b7178567" SRC_URI[bitflags-1.3.2.sha256sum] = "bef38d45163c2f1dde094a7dfd33ccf595c92905c8f8f4fdc18d06fb1037718a" +SRC_URI[bitvec-1.0.1.sha256sum] = "1bc2832c24239b0141d5674bb9174f9d68a8b5b3f2753311927c172ca46f7e9c" SRC_URI[cc-1.0.79.sha256sum] = "50d30906286121d95be3d479533b458f87493b30a4b5f79a607db8f5d11aa91f" SRC_URI[cfg-if-1.0.0.sha256sum] = "baf1de4339761588bc0619e3cbc0120ee582ebb74b53b4efbf79117bd2da40fd" -SRC_URI[enum_dispatch-0.3.12.sha256sum] = "8f33313078bb8d4d05a2733a94ac4c2d8a0df9a2b84424ebf4f33bfc224a890e" +SRC_URI[enum_dispatch-0.3.13.sha256sum] = "aa18ce2bc66555b3218614519ac839ddb759a7d6720732f979ef8d13be147ecd" SRC_URI[equivalent-1.0.1.sha256sum] = "5443807d6dff69373d433ab9ef5378ad8df50ca6298caf15de6e52e24aaf54d5" SRC_URI[form_urlencoded-1.2.1.sha256sum] = "e13624c2627564efccf4934284bdd98cbaa14e79b0b5a141218e507b3a823456" +SRC_URI[funty-2.0.0.sha256sum] = "e6d5a32815ae3f33302d95fdcb2ce17862f8c65363dcfd29360480ba1001fc9c" SRC_URI[getrandom-0.2.10.sha256sum] = "be4136b2a15dd319360be1c07d9933517ccf0be8f16bf62a3bee4f0d618df427" SRC_URI[hashbrown-0.14.3.sha256sum] = "290f1a1d9242c78d09ce40a5e87e7554ee637af1351968159f4952f028f75604" SRC_URI[heck-0.4.1.sha256sum] = "95505c38b4572b2d910cecb0281560f54b440a19336cbbcb27bf6ce6adc6f5a8" SRC_URI[idna-0.5.0.sha256sum] = "634d9b1461af396cad843f47fdba5597a4f9e6ddd4bfb6ff5d85028c25cb12f6" -SRC_URI[indexmap-2.0.0.sha256sum] = "d5477fe2230a79769d8dc68e0eabf5437907c0457a5614a9e8dddb67f65eb65d" +SRC_URI[indexmap-2.2.2.sha256sum] = "824b2ae422412366ba479e8111fd301f7b5faece8149317bb81925979a53f520" SRC_URI[indoc-2.0.4.sha256sum] = "1e186cfbae8084e513daff4240b4797e342f988cecda4fb6c939150f96315fd8" SRC_URI[itoa-1.0.8.sha256sum] = "62b02a5381cc465bd3041d84623d0fa3b66738b52b8e2fc3bab8ad63ab032f4a" -SRC_URI[jiter-0.0.6.sha256sum] = "87db066a99f69382be06d02313f8ce989996b53a04a8a70cfd1a6483a56227f7" -SRC_URI[lexical-core-0.8.5.sha256sum] = "2cde5de06e8d4c2faabc400238f9ae1c74d5412d03a7bd067645ccbc47070e46" +SRC_URI[jiter-0.4.1.sha256sum] = "abbbbe1bad457e3cd5503af716aedc735e849505a0d2172c55a753ae1b127458" SRC_URI[lexical-parse-float-0.8.5.sha256sum] = "683b3a5ebd0130b8fb52ba0bdc718cc56815b6a097e28ae5a6997d0ad17dc05f" SRC_URI[lexical-parse-integer-0.8.6.sha256sum] = "6d0994485ed0c312f6d965766754ea177d07f9c00c9b82a5ee62ed5b47945ee9" SRC_URI[lexical-util-0.8.5.sha256sum] = "5255b9ff16ff898710eb9eb63cb39248ea8a5bb036bea8085b1a767ff6c4e3fc" -SRC_URI[lexical-write-float-0.8.5.sha256sum] = "accabaa1c4581f05a3923d1b4cfd124c329352288b7b9da09e766b0668116862" -SRC_URI[lexical-write-integer-0.8.5.sha256sum] = "e1b6f3d1f4422866b68192d62f77bc5c700bee84f3069f2469d7bc8c77852446" SRC_URI[libc-0.2.147.sha256sum] = "b4668fb0ea861c1df094127ac5f1da3409a82116a4ba74fca2e58ef927159bb3" SRC_URI[lock_api-0.4.10.sha256sum] = "c1cc9717a20b1bb222f333e6a92fd32f7d8a18ddc5a3191a11af45dcbf4dcd16" SRC_URI[memchr-2.6.3.sha256sum] = "8f232d6ef707e1956a43342693d2a31e72989554d58299d7a88738cc95b0d35c" @@ -124,29 +124,32 @@ SRC_URI[parking_lot_core-0.9.8.sha256sum] = "93f00c865fe7cabf650081affecd3871070 SRC_URI[percent-encoding-2.3.1.sha256sum] = "e3148f5046208a5d56bcfc03053e3ca6334e51da8dfb19b6cdc8b306fae3283e" SRC_URI[portable-atomic-1.6.0.sha256sum] = "7170ef9988bc169ba16dd36a7fa041e5c4cbeb6a35b76d4c03daded371eae7c0" SRC_URI[proc-macro2-1.0.76.sha256sum] = "95fc56cda0b5c3325f5fbbd7ff9fda9e02bb00bb3dac51252d2f1bfa1cb8cc8c" -SRC_URI[pyo3-0.20.3.sha256sum] = "53bdbb96d49157e65d45cc287af5f32ffadd5f4761438b527b055fb0d4bb8233" -SRC_URI[pyo3-build-config-0.20.3.sha256sum] = "deaa5745de3f5231ce10517a1f5dd97d53e5a2fd77aa6b5842292085831d48d7" -SRC_URI[pyo3-ffi-0.20.3.sha256sum] = "62b42531d03e08d4ef1f6e85a2ed422eb678b8cd62b762e53891c05faf0d4afa" -SRC_URI[pyo3-macros-0.20.3.sha256sum] = "7305c720fa01b8055ec95e484a6eca7a83c841267f0dd5280f0c8b8551d2c158" -SRC_URI[pyo3-macros-backend-0.20.3.sha256sum] = "7c7e9b68bb9c3149c5b0cade5d07f953d6d125eb4337723c4ccdb665f1f96185" +SRC_URI[pyo3-0.21.2.sha256sum] = "a5e00b96a521718e08e03b1a622f01c8a8deb50719335de3f60b3b3950f069d8" +SRC_URI[pyo3-build-config-0.21.2.sha256sum] = "7883df5835fafdad87c0d888b266c8ec0f4c9ca48a5bed6bbb592e8dedee1b50" +SRC_URI[pyo3-ffi-0.21.2.sha256sum] = "01be5843dc60b916ab4dad1dca6d20b9b4e6ddc8e15f50c47fe6d85f1fb97403" +SRC_URI[pyo3-macros-0.21.2.sha256sum] = "77b34069fc0682e11b31dbd10321cbf94808394c56fd996796ce45217dfac53c" +SRC_URI[pyo3-macros-backend-0.21.2.sha256sum] = "08260721f32db5e1a5beae69a55553f56b99bd0e1c3e6e0a5e8851a9d0f5a85c" SRC_URI[python3-dll-a-0.2.9.sha256sum] = "d5f07cd4412be8fa09a721d40007c483981bbe072cd6a21f2e83e04ec8f8343f" SRC_URI[quote-1.0.35.sha256sum] = "291ec9ab5efd934aaf503a6466c5d5251535d108ee747472c3977cc5acc868ef" +SRC_URI[radium-0.7.0.sha256sum] = "dc33ff2d4973d518d823d61aa239014831e521c75da58e3df4840d3f47749d09" SRC_URI[redox_syscall-0.3.5.sha256sum] = "567664f262709473930a4bf9e51bf2ebf3348f2e748ccc50dea20646858f8f29" -SRC_URI[regex-1.10.2.sha256sum] = "380b951a9c5e80ddfd6136919eef32310721aa4aacd4889a8d39124b026ab343" -SRC_URI[regex-automata-0.4.3.sha256sum] = "5f804c7828047e88b2d32e2d7fe5a105da8ee3264f01902f796c8e067dc2483f" +SRC_URI[regex-1.10.4.sha256sum] = "c117dbdfde9c8308975b6a18d71f3f385c89461f7b3fb054288ecf2a2058ba4c" +SRC_URI[regex-automata-0.4.5.sha256sum] = "5bb987efffd3c6d0d8f5f89510bb458559eab11e4f869acb20bf845e016259cd" SRC_URI[regex-syntax-0.8.2.sha256sum] = "c08c74e62047bb2de4ff487b251e4a92e24f48745648451635cec7d591162d9f" SRC_URI[rustversion-1.0.13.sha256sum] = "dc31bd9b61a32c31f9650d18add92aa83a49ba979c143eefd27fe7177b05bd5f" SRC_URI[ryu-1.0.14.sha256sum] = "fe232bdf6be8c8de797b22184ee71118d63780ea42ac85b61d1baa6d3b782ae9" SRC_URI[scopeguard-1.1.0.sha256sum] = "d29ab0c6d3fc0ee92fe66e2d99f700eab17a8d57d1c1d3b748380fb20baa78cd" -SRC_URI[serde-1.0.195.sha256sum] = "63261df402c67811e9ac6def069e4786148c4563f4b50fd4bf30aa370d626b02" -SRC_URI[serde_derive-1.0.195.sha256sum] = "46fe8f8603d81ba86327b23a2e9cdf49e1255fb94a4c5f297f6ee0547178ea2c" -SRC_URI[serde_json-1.0.109.sha256sum] = "cb0652c533506ad7a2e353cce269330d6afd8bdfb6d75e0ace5b35aacbd7b9e9" -SRC_URI[smallvec-1.11.2.sha256sum] = "4dccd0940a2dcdf68d092b8cbab7dc0ad8fa938bf95787e1b916b0e3d0e8e970" -SRC_URI[speedate-0.13.0.sha256sum] = "242f76c50fd18cbf098607090ade73a08d39cfd84ea835f3796a2c855223b19b" +SRC_URI[serde-1.0.203.sha256sum] = "7253ab4de971e72fb7be983802300c30b5a7f0c2e56fab8abfc6a214307c0094" +SRC_URI[serde_derive-1.0.203.sha256sum] = "500cbc0ebeb6f46627f50f3f5811ccf6bf00643be300b4c3eabc0ef55dc5b5ba" +SRC_URI[serde_json-1.0.116.sha256sum] = "3e17db7126d17feb94eb3fad46bf1a96b034e8aacbc2e775fe81505f8b0b2813" +SRC_URI[smallvec-1.13.2.sha256sum] = "3c5e1a9a646d36c3599cd173a41282daf47c44583ad367b8e6837255952e5c67" +SRC_URI[speedate-0.14.0.sha256sum] = "c323c4e6fece5a5a1a2a7f726d243144cce9fbcfe3ce4d9f3c6ede726a2bc780" SRC_URI[static_assertions-1.1.0.sha256sum] = "a2eb9349b6444b326872e140eb1cf5e7c522154d69e7a0ffb0fb81c06b37543f" SRC_URI[strum-0.25.0.sha256sum] = "290d54ea6f91c969195bdbcd7442c8c2a2ba87da8bf60a7ee86a235d4bc1e125" SRC_URI[strum_macros-0.25.3.sha256sum] = "23dc1fa9ac9c169a78ba62f0b841814b7abae11bdd047b9c58f893439e309ea0" +SRC_URI[strum_macros-0.26.1.sha256sum] = "7a3417fc93d76740d974a01654a09777cb500428cc874ca9f45edfe0c4d4cd18" SRC_URI[syn-2.0.48.sha256sum] = "0f3531638e407dfc0814761abb7c00a5b54992b849452a0646b7f65c9f770f3f" +SRC_URI[tap-1.0.1.sha256sum] = "55937e1799185b12863d447f42597ed69d9928686b8d88a1df17376a097d8369" SRC_URI[target-lexicon-0.12.9.sha256sum] = "df8e77cb757a61f51b947ec4a7e3646efd825b73561db1c232a8ccb639e611a0" SRC_URI[tinyvec-1.6.0.sha256sum] = "87cc5ceb3875bb20c2890005a4e226a4651264a5c75edb2421b52861a0a0cb50" SRC_URI[tinyvec_macros-0.1.1.sha256sum] = "1f3ccbac311fea05f86f61904b462b55fb3df8837a366dfc601a0161d0532f20" @@ -155,7 +158,7 @@ SRC_URI[unicode-ident-1.0.10.sha256sum] = "22049a19f4a68748a168c0fc439f9516686aa SRC_URI[unicode-normalization-0.1.22.sha256sum] = "5c5713f0fc4b5db668a2ac63cdb7bb4469d8c9fed047b1d0292cc7b0ce2ba921" SRC_URI[unindent-0.2.3.sha256sum] = "c7de7d73e1754487cb58364ee906a499937a0dfabd86bcb980fa99ec8c8fa2ce" SRC_URI[url-2.5.0.sha256sum] = "31e6302e3bb753d46e83516cae55ae196fc0c309407cf11ab35cc51a4c2a4633" -SRC_URI[uuid-1.6.1.sha256sum] = "5e395fcf16a7a3d8127ec99782007af141946b4795001f876d54fb0d55978560" +SRC_URI[uuid-1.8.0.sha256sum] = "a183cf7feeba97b4dd1c0d46788634f6221d87fa961b305bed08c851829efcc0" SRC_URI[version_check-0.9.4.sha256sum] = "49874b5167b65d7193b8aba1567f5c7d93d001cafc34600cee003eda787e483f" SRC_URI[wasi-0.11.0+wasi-snapshot-preview1.sha256sum] = "9c8d87e72b64a3b4db28d11ce29237c246188f4f51057d65a7eab63b7987e423" SRC_URI[windows-targets-0.48.1.sha256sum] = "05d4b17490f70499f20b9e791dcf6a299785ce8af4d709018206dc5b4953e95f" @@ -166,5 +169,6 @@ SRC_URI[windows_i686_msvc-0.48.0.sha256sum] = "4542c6e364ce21bf45d69fdd2a8e455fa SRC_URI[windows_x86_64_gnu-0.48.0.sha256sum] = "ca2b8a661f7628cbd23440e50b05d705db3686f894fc9580820623656af974b1" SRC_URI[windows_x86_64_gnullvm-0.48.0.sha256sum] = "7896dbc1f41e08872e9d5e8f8baa8fdd2677f29468c4e156210174edc7f7b953" SRC_URI[windows_x86_64_msvc-0.48.0.sha256sum] = "1a515f5799fe4961cb532f983ce2b23082366b898e52ffbce459c86f67c8378a" +SRC_URI[wyz-0.5.1.sha256sum] = "05f360fc0b24296329c78fda852a1e9ae82de9cf7b27dae4b7f62f118f77b9ed" SRC_URI[zerocopy-0.7.32.sha256sum] = "74d4d3961e53fa4c9a25a8637fc2bfaf2595b3d3ae34875568a5cf64787716be" SRC_URI[zerocopy-derive-0.7.32.sha256sum] = "9ce1b18ccd8e73a9321186f97e46f9f04b778851177567b1975109d26a08d2a6" diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Bumps-pyo3-https-github.com-pyo3-pyo3-from-0.20.2-to.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Bumps-pyo3-https-github.com-pyo3-pyo3-from-0.20.2-to.patch deleted file mode 100644 index 32777e1d03..0000000000 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Bumps-pyo3-https-github.com-pyo3-pyo3-from-0.20.2-to.patch +++ /dev/null @@ -1,126 +0,0 @@ -From a5690f973384bf8cbf4deb3b83d822b7aaefbdd8 Mon Sep 17 00:00:00 2001 -From: Khem Raj <raj.khem@gmail.com> -Date: Tue, 27 Feb 2024 11:00:46 -0800 -Subject: [PATCH] Bumps [pyo3](https://github.com/pyo3/pyo3) from 0.20.2 to - 0.20.3. - -Upstream-Status: Pending -Signed-off-by: Khem Raj <raj.khem@gmail.com> ---- - Cargo.lock | 26 +++++++++++++++++--------- - Cargo.toml | 2 +- - 2 files changed, 18 insertions(+), 10 deletions(-) - ---- a/Cargo.lock -+++ b/Cargo.lock -@@ -322,6 +322,12 @@ source = "registry+https://github.com/ru - checksum = "e3148f5046208a5d56bcfc03053e3ca6334e51da8dfb19b6cdc8b306fae3283e" - - [[package]] -+name = "portable-atomic" -+version = "1.6.0" -+source = "registry+https://github.com/rust-lang/crates.io-index" -+checksum = "7170ef9988bc169ba16dd36a7fa041e5c4cbeb6a35b76d4c03daded371eae7c0" -+ -+[[package]] - name = "proc-macro2" - version = "1.0.76" - source = "registry+https://github.com/rust-lang/crates.io-index" -@@ -357,9 +363,9 @@ dependencies = [ - - [[package]] - name = "pyo3" --version = "0.20.2" -+version = "0.20.3" - source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "9a89dc7a5850d0e983be1ec2a463a171d20990487c3cfcd68b5363f1ee3d6fe0" -+checksum = "53bdbb96d49157e65d45cc287af5f32ffadd5f4761438b527b055fb0d4bb8233" - dependencies = [ - "cfg-if", - "indoc", -@@ -367,6 +373,7 @@ dependencies = [ - "memoffset", - "num-bigint", - "parking_lot", -+ "portable-atomic", - "pyo3-build-config", - "pyo3-ffi", - "pyo3-macros", -@@ -375,9 +382,9 @@ dependencies = [ - - [[package]] - name = "pyo3-build-config" --version = "0.20.2" -+version = "0.20.3" - source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "07426f0d8fe5a601f26293f300afd1a7b1ed5e78b2a705870c5f30893c5163be" -+checksum = "deaa5745de3f5231ce10517a1f5dd97d53e5a2fd77aa6b5842292085831d48d7" - dependencies = [ - "once_cell", - "python3-dll-a", -@@ -386,9 +393,9 @@ dependencies = [ - - [[package]] - name = "pyo3-ffi" --version = "0.20.2" -+version = "0.20.3" - source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "dbb7dec17e17766b46bca4f1a4215a85006b4c2ecde122076c562dd058da6cf1" -+checksum = "62b42531d03e08d4ef1f6e85a2ed422eb678b8cd62b762e53891c05faf0d4afa" - dependencies = [ - "libc", - "pyo3-build-config", -@@ -396,9 +403,9 @@ dependencies = [ - - [[package]] - name = "pyo3-macros" --version = "0.20.2" -+version = "0.20.3" - source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "05f738b4e40d50b5711957f142878cfa0f28e054aa0ebdfc3fd137a843f74ed3" -+checksum = "7305c720fa01b8055ec95e484a6eca7a83c841267f0dd5280f0c8b8551d2c158" - dependencies = [ - "proc-macro2", - "pyo3-macros-backend", -@@ -408,12 +415,13 @@ dependencies = [ - - [[package]] - name = "pyo3-macros-backend" --version = "0.20.2" -+version = "0.20.3" - source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "0fc910d4851847827daf9d6cdd4a823fbdaab5b8818325c5e97a86da79e8881f" -+checksum = "7c7e9b68bb9c3149c5b0cade5d07f953d6d125eb4337723c4ccdb665f1f96185" - dependencies = [ - "heck", - "proc-macro2", -+ "pyo3-build-config", - "quote", - "syn", - ] ---- a/Cargo.toml -+++ b/Cargo.toml -@@ -26,7 +26,7 @@ include = [ - ] - - [dependencies] --pyo3 = { version = "0.20.2", features = ["generate-import-lib", "num-bigint"] } -+pyo3 = { version = "0.20.3", features = ["generate-import-lib", "num-bigint"] } - regex = "1.10.2" - strum = { version = "0.25.0", features = ["derive"] } - strum_macros = "0.25.3" -@@ -70,12 +70,12 @@ debug = true - strip = false - - [dev-dependencies] --pyo3 = { version = "0.20.2", features = ["auto-initialize"] } -+pyo3 = { version = "0.20.3", features = ["auto-initialize"] } - - [build-dependencies] - version_check = "0.9.4" - # used where logic has to be version/distribution specific, e.g. pypy --pyo3-build-config = { version = "0.20.2" } -+pyo3-build-config = { version = "0.20.3" } - - [lints.clippy] - dbg_macro = "warn" diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Set-rust-version-from-1.76-to-1.75-in-Cargo.toml.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Set-rust-version-from-1.76-to-1.75-in-Cargo.toml.patch new file mode 100644 index 0000000000..c4e6f2f6ab --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Set-rust-version-from-1.76-to-1.75-in-Cargo.toml.patch @@ -0,0 +1,29 @@ +From 6e1852228a2aa38cc76b9a968bba6b603efa5b28 Mon Sep 17 00:00:00 2001 +From: Frank de Brabander <debrabander@gmail.com> +Date: Thu, 25 Jul 2024 13:50:44 +0200 +Subject: [PATCH] Set rust version from 1.76 to 1.75 in Cargo.toml + +Current openembedded-core uses 1.75 and this packages doesn't actually +require a newer version. + +Upstream-Status: Inappropriate +--- + Cargo.toml | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/Cargo.toml b/Cargo.toml +index 8f0ea44..10b277c 100644 +--- a/Cargo.toml ++++ b/Cargo.toml +@@ -24,7 +24,7 @@ include = [ + "!tests/.pytest_cache", + "!*.so", + ] +-rust-version = "1.76" ++rust-version = "1.75" + + [dependencies] + pyo3 = { version = "0.21.2", features = ["generate-import-lib", "num-bigint"] } +-- +2.39.2 + diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0002-Dont-embed-RUSTFLAGS-in-final-binary.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0002-Dont-embed-RUSTFLAGS-in-final-binary.patch new file mode 100644 index 0000000000..1c195e294b --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0002-Dont-embed-RUSTFLAGS-in-final-binary.patch @@ -0,0 +1,47 @@ +From b3282b301096253a11b1f887f915d0a2a2183597 Mon Sep 17 00:00:00 2001 +From: Frank de Brabander <debrabander@gmail.com> +Date: Thu, 8 Aug 2024 08:04:48 +0200 +Subject: [PATCH] Dont embed RUSTFLAGS in final binary + +Upstream-Status: Backport [https://github.com/pydantic/pydantic-core/commit/e07c41b3bad75948201a2201387225694c2fb501] +--- + build.rs | 9 +++++++++ + src/lib.rs | 5 ++++- + 2 files changed, 13 insertions(+), 1 deletion(-) + +diff --git a/build.rs b/build.rs +index 7f59e1f..7fe6490 100644 +--- a/build.rs ++++ b/build.rs +@@ -35,6 +35,15 @@ fn main() { + if let Some(true) = version_check::supports_feature("coverage_attribute") { + println!("cargo:rustc-cfg=has_coverage_attribute"); + } ++ ++ if std::env::var("RUSTFLAGS") ++ .unwrap_or_default() ++ .contains("-Cprofile-use=") ++ { ++ println!("cargo:rustc-cfg=specified_profile_use"); ++ } ++ println!("cargo:rustc-check-cfg=cfg(specified_profile_use)"); ++ + generate_self_schema(); + println!("cargo:rustc-env=PROFILE={}", std::env::var("PROFILE").unwrap()); + } +diff --git a/src/lib.rs b/src/lib.rs +index d55e836..206a7a1 100644 +--- a/src/lib.rs ++++ b/src/lib.rs +@@ -111,7 +111,10 @@ pub fn build_info() -> String { + format!( + "profile={} pgo={}", + env!("PROFILE"), +- option_env!("RUSTFLAGS").unwrap_or("").contains("-Cprofile-use="), ++ // We use a `cfg!` here not `env!`/`option_env!` as those would ++ // embed `RUSTFLAGS` into the generated binary which causes problems ++ // with reproducable builds. ++ cfg!(specified_profile_use), + ) + } + diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core_2.16.3.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core_2.18.4.bb index faa291ea6d..adaf4a62cb 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core_2.16.3.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core_2.18.4.bb @@ -8,8 +8,9 @@ HOMEPAGE = "https://github.com/pydantic/pydantic-core" LICENSE = "MIT" LIC_FILES_CHKSUM = "file://LICENSE;md5=ab599c188b4a314d2856b3a55030c75c" -SRC_URI += "file://0001-Bumps-pyo3-https-github.com-pyo3-pyo3-from-0.20.2-to.patch" -SRC_URI[sha256sum] = "1cac689f80a3abab2d3c0048b29eea5751114054f032a941a32de4c852c59cad" +SRC_URI += "file://0001-Set-rust-version-from-1.76-to-1.75-in-Cargo.toml.patch \ + file://0002-Dont-embed-RUSTFLAGS-in-final-binary.patch" +SRC_URI[sha256sum] = "ec3beeada09ff865c344ff3bc2f427f5e6c26401cc6113d77e372c3fdac73864" DEPENDS = "python3-maturin-native python3-typing-extensions" @@ -19,7 +20,10 @@ inherit pypi cargo-update-recipe-crates python_maturin PYPI_PACKAGE = "pydantic_core" -RDEPENDS:${PN} += "python3-typing-extensions" +RDEPENDS:${PN} += " \ + python3-compression \ + python3-typing-extensions \ +" INSANE_SKIP:${PN} = "already-stripped" @@ -33,6 +37,8 @@ RDEPENDS:${PN}-ptest += "\ python3-pytest-timeout \ python3-pytest-benchmark \ python3-unittest-automake-output \ + python3-zoneinfo \ + tzdata \ " do_install:append() { diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic_2.7.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic_2.7.4.bb index 36ad83527d..04c9c91c0e 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic_2.7.0.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic_2.7.4.bb @@ -11,7 +11,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=09280955509d1c4ca14bae02f21d49a6" inherit pypi python_hatchling -SRC_URI[sha256sum] = "b5ecdd42262ca2462e2624793551e80911a1e989f462910bb81aef974b4bb383" +SRC_URI[sha256sum] = "0c84efd9548d545f63ac0060c1e4d39bb9b14db8b3c0652338aecc07b5adec52" DEPENDS += "python3-hatch-fancy-pypi-readme-native" diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pylint_3.1.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pylint_3.1.0.bb index 12f4f908af..4c49acaf1e 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pylint_3.1.0.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pylint_3.1.0.bb @@ -3,7 +3,7 @@ HOMEPAGE= "http://www.pylint.org/" LICENSE = "GPL-2.0-only" LIC_FILES_CHKSUM = "file://LICENSE;md5=c107cf754550e65755c42985a5d4e9c9" -SRC_URI += "git://github.com/pylint-dev/pylint;branch=maintenance/3.1.x;protocol=https \ +SRC_URI += "git://github.com/pylint-dev/pylint;branch=main;protocol=https \ file://0001-Adjust-test-expectations-for-ptest.patch \ file://run-ptest \ " diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj/rpath.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj/rpath.patch new file mode 100644 index 0000000000..347996a808 --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj/rpath.patch @@ -0,0 +1,18 @@ +Description: Don't set RPATH in libraries. +Author: Bas Couwenberg <sebastic@debian.org> +Forwarded: not-needed + +Upstream-Status: Inappropriate [OE-Specific] +Signed-off-by: Khem Raj <raj.khem@gmail.com> +--- a/setup.py ++++ b/setup.py +@@ -194,9 +194,6 @@ def get_extension_modules(): + ext_options = { + "include_dirs": include_dirs, + "library_dirs": library_dirs, +- "runtime_library_dirs": ( +- library_dirs if os.name != "nt" and sys.platform != "cygwin" else None +- ), + "libraries": get_libraries(library_dirs), + } + # setup cythonized modules diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj_3.6.1.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj_3.6.1.bb index a4121c3934..f6b6ee8a46 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj_3.6.1.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj_3.6.1.bb @@ -8,6 +8,8 @@ PYPI_PACKAGE = "pyproj" inherit pypi setuptools3 +SRC_URI += "file://rpath.patch" + SRC_URI[sha256sum] = "44aa7c704c2b7d8fb3d483bbf75af6cb2350d30a63b144279a09b75fead501bf" RDEPENDS:${PN} = " \ @@ -21,3 +23,11 @@ RDEPENDS:${PN} = " \ export PROJ_INCDIR = "${STAGING_INCDIR}" export PROJ_LIBDIR = "${STAGING_LIBDIR}" export PROJ_DIR = "${STAGING_BINDIR_NATIVE}/.." + +do_compile:append() { + for f in `find ${B} -name *.c` + do + sed -i -e "/BEGIN: Cython Metadata/,/END: Cython Metadata/d" $f + done + python_pep517_do_compile +} diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pyyaml-include_1.3.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyyaml-include_1.3.2.bb index 3a5bd99a78..309d0ac596 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pyyaml-include_1.3.2.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyyaml-include_1.3.2.bb @@ -26,4 +26,4 @@ RDEPENDS:${PN}-ptest += " \ python3-pytest \ python3-unittest-automake-output \ " - +BBCLASSEXTEND = "native nativesdk" diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2024-4340.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2024-4340.patch new file mode 100644 index 0000000000..670904071a --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2024-4340.patch @@ -0,0 +1,48 @@ +From b4a39d9850969b4e1d6940d32094ee0b42a2cf03 Mon Sep 17 00:00:00 2001 +From: Andi Albrecht <albrecht.andi@gmail.com> +Date: Sat, 13 Apr 2024 13:59:00 +0200 +Subject: [PATCH] Raise SQLParseError instead of RecursionError. + +CVE: CVE-2024-4340 + +Upstream-Status: Backport [https://github.com/andialbrecht/sqlparse/commit/b4a39d9850969b4e1d6940d32094ee0b42a2cf03] + +Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com> +--- + sqlparse/sql.py | 14 +++++++++----- + 1 file changed, 9 insertions(+), 5 deletions(-) + +diff --git a/sqlparse/sql.py b/sqlparse/sql.py +index 1ccfbdb..2090621 100644 +--- a/sqlparse/sql.py ++++ b/sqlparse/sql.py +@@ -10,6 +10,7 @@ + import re + + from sqlparse import tokens as T ++from sqlparse.exceptions import SQLParseError + from sqlparse.utils import imt, remove_quotes + + +@@ -209,11 +210,14 @@ class TokenList(Token): + + This method is recursively called for all child tokens. + """ +- for token in self.tokens: +- if token.is_group: +- yield from token.flatten() +- else: +- yield token ++ try: ++ for token in self.tokens: ++ if token.is_group: ++ yield from token.flatten() ++ else: ++ yield token ++ except RecursionError as err: ++ raise SQLParseError('Maximum recursion depth exceeded') from err + + def get_sublists(self): + for token in self.tokens: +-- +2.25.1 diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse_0.4.4.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse_0.4.4.bb index c04971ee8f..fa633026c8 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse_0.4.4.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse_0.4.4.bb @@ -5,6 +5,7 @@ LICENSE = "BSD-3-Clause" LIC_FILES_CHKSUM = "file://LICENSE;md5=2b136f573f5386001ea3b7b9016222fc" SRC_URI += "file://0001-sqlparse-change-shebang-to-python3.patch \ + file://CVE-2024-4340.patch \ file://run-ptest \ " diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-tornado_6.4.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-tornado_6.4.2.bb index b01c1cec2a..751f32913a 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-tornado_6.4.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-tornado_6.4.2.bb @@ -6,9 +6,9 @@ HOMEPAGE = "http://www.tornadoweb.org/en/stable/" LICENSE = "Apache-2.0" LIC_FILES_CHKSUM = "file://LICENSE;md5=3b83ef96387f14655fc854ddc3c6bd57" -SRC_URI[sha256sum] = "72291fa6e6bc84e626589f1c29d90a5a6d593ef5ae68052ee2ef000dfd273dee" +SRC_URI[sha256sum] = "92bad5b4746e9879fd7bf1eb21dce4e3fc5128d71601f80005afa39237ad620b" -inherit pypi setuptools3 +inherit pypi python_setuptools_build_meta # Requires _compression which is currently located in misc RDEPENDS:${PN} += " \ diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0001.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0001.patch new file mode 100644 index 0000000000..1f6bf6bbfc --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0001.patch @@ -0,0 +1,89 @@ +From 046a164f89a0f08d3239ecebd750360f8914df33 Mon Sep 17 00:00:00 2001 +From: Adi Roiban <adiroiban@gmail.com> +Date: Mon Jul 29 14:28:03 2024 +0100 +Subject: [PATCH] Merge commit from fork + +Added HTML output encoding the "URL" parameter of the "redirectTo" function + +CVE: CVE-2024-41671 + +Upstream-Status: Backport [https://github.com/twisted/twisted/commit/046a164f89a0f08d3239ecebd750360f8914df33] + +Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com> +--- + src/twisted/web/_template_util.py | 2 +- + src/twisted/web/test/test_util.py | 39 ++++++++++++++++++++++++++++++- + 2 files changed, 39 insertions(+), 2 deletions(-) + +diff --git a/src/twisted/web/_template_util.py b/src/twisted/web/_template_util.py +index 230c33f..7266079 100644 +--- a/src/twisted/web/_template_util.py ++++ b/src/twisted/web/_template_util.py +@@ -92,7 +92,7 @@ def redirectTo(URL: bytes, request: IRequest) -> bytes: + </body> + </html> + """ % { +- b"url": URL ++ b"url": escape(URL.decode("utf-8")).encode("utf-8") + } + return content + +diff --git a/src/twisted/web/test/test_util.py b/src/twisted/web/test/test_util.py +index 1e76300..9847dcb 100644 +--- a/src/twisted/web/test/test_util.py ++++ b/src/twisted/web/test/test_util.py +@@ -5,7 +5,6 @@ + Tests for L{twisted.web.util}. + """ + +- + import gc + + from twisted.internet import defer +@@ -64,6 +63,44 @@ class RedirectToTests(TestCase): + targetURL = "http://target.example.com/4321" + self.assertRaises(TypeError, redirectTo, targetURL, request) + ++ def test_legitimateRedirect(self): ++ """ ++ Legitimate URLs are fully interpolated in the `redirectTo` response body without transformation ++ """ ++ request = DummyRequest([b""]) ++ html = redirectTo(b"https://twisted.org/", request) ++ expected = b""" ++<html> ++ <head> ++ <meta http-equiv=\"refresh\" content=\"0;URL=https://twisted.org/\"> ++ </head> ++ <body bgcolor=\"#FFFFFF\" text=\"#000000\"> ++ <a href=\"https://twisted.org/\">click here</a> ++ </body> ++</html> ++""" ++ self.assertEqual(html, expected) ++ ++ def test_maliciousRedirect(self): ++ """ ++ Malicious URLs are HTML-escaped before interpolating them in the `redirectTo` response body ++ """ ++ request = DummyRequest([b""]) ++ html = redirectTo( ++ b'https://twisted.org/"><script>alert(document.location)</script>', request ++ ) ++ expected = b""" ++<html> ++ <head> ++ <meta http-equiv=\"refresh\" content=\"0;URL=https://twisted.org/"><script>alert(document.location)</script>\"> ++ </head> ++ <body bgcolor=\"#FFFFFF\" text=\"#000000\"> ++ <a href=\"https://twisted.org/"><script>alert(document.location)</script>\">click here</a> ++ </body> ++</html> ++""" ++ self.assertEqual(html, expected) ++ + + class ParentRedirectTests(SynchronousTestCase): + """ +-- +2.40.0 diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0002.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0002.patch new file mode 100644 index 0000000000..147c21d73d --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0002.patch @@ -0,0 +1,251 @@ +From 4a930de12fb67e88fefcb8822104152f42b27abc Mon Sep 17 00:00:00 2001 +From: Adi Roiban <adiroiban@gmail.com> +Date: Mon Jul 29 14:27:23 2024 +0100 +Subject: [PATCH] Merge commit from fork + +Address GHSA-c8m8-j448-xjx7 + +CVE: CVE-2024-41671 + +Upstream-Status: Backport [https://github.com/twisted/twisted/commit/4a930de12fb67e88fefcb8822104152f42b27abc] + +Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com> +--- + src/twisted/web/http.py | 21 +++-- + src/twisted/web/test/test_http.py | 122 ++++++++++++++++++++++++++---- + 2 files changed, 122 insertions(+), 21 deletions(-) + +diff --git a/src/twisted/web/http.py b/src/twisted/web/http.py +index 1c59838..3b784f5 100644 +--- a/src/twisted/web/http.py ++++ b/src/twisted/web/http.py +@@ -2000,16 +2000,21 @@ class _ChunkedTransferDecoder: + @returns: C{False}, as there is either insufficient data to continue, + or no data remains. + """ +- if ( +- self._receivedTrailerHeadersSize + len(self._buffer) +- > self._maxTrailerHeadersSize +- ): +- raise _MalformedChunkedDataError("Trailer headers data is too long.") +- + eolIndex = self._buffer.find(b"\r\n", self._start) + + if eolIndex == -1: + # Still no end of network line marker found. ++ # ++ # Check if we've run up against the trailer size limit: if the next ++ # read contains the terminating CRLF then we'll have this many bytes ++ # of trailers (including the CRLFs). ++ minTrailerSize = ( ++ self._receivedTrailerHeadersSize ++ + len(self._buffer) ++ + (1 if self._buffer.endswith(b"\r") else 2) ++ ) ++ if minTrailerSize > self._maxTrailerHeadersSize: ++ raise _MalformedChunkedDataError("Trailer headers data is too long.") + # Continue processing more data. + return False + +@@ -2019,6 +2024,8 @@ class _ChunkedTransferDecoder: + del self._buffer[0 : eolIndex + 2] + self._start = 0 + self._receivedTrailerHeadersSize += eolIndex + 2 ++ if self._receivedTrailerHeadersSize > self._maxTrailerHeadersSize: ++ raise _MalformedChunkedDataError("Trailer headers data is too long.") + return True + + # eolIndex in this part of code is equal to 0 +@@ -2342,8 +2349,8 @@ class HTTPChannel(basic.LineReceiver, policies.TimeoutMixin): + self.__header = line + + def _finishRequestBody(self, data): +- self.allContentReceived() + self._dataBuffer.append(data) ++ self.allContentReceived() + + def _maybeChooseTransferDecoder(self, header, data): + """ +diff --git a/src/twisted/web/test/test_http.py b/src/twisted/web/test/test_http.py +index 33d0a49..1130d31 100644 +--- a/src/twisted/web/test/test_http.py ++++ b/src/twisted/web/test/test_http.py +@@ -135,7 +135,7 @@ class DummyHTTPHandler(http.Request): + data = self.content.read() + length = self.getHeader(b"content-length") + if length is None: +- length = networkString(str(length)) ++ length = str(length).encode() + request = b"'''\n" + length + b"\n" + data + b"'''\n" + self.setResponseCode(200) + self.setHeader(b"Request", self.uri) +@@ -563,17 +563,23 @@ class HTTP0_9Tests(HTTP1_0Tests): + + class PipeliningBodyTests(unittest.TestCase, ResponseTestMixin): + """ +- Tests that multiple pipelined requests with bodies are correctly buffered. ++ Pipelined requests get buffered and executed in the order received, ++ not processed in parallel. + """ + + requests = ( + b"POST / HTTP/1.1\r\n" + b"Content-Length: 10\r\n" + b"\r\n" +- b"0123456789POST / HTTP/1.1\r\n" +- b"Content-Length: 10\r\n" +- b"\r\n" + b"0123456789" ++ # Chunk encoded request. ++ b"POST / HTTP/1.1\r\n" ++ b"Transfer-Encoding: chunked\r\n" ++ b"\r\n" ++ b"a\r\n" ++ b"0123456789\r\n" ++ b"0\r\n" ++ b"\r\n" + ) + + expectedResponses = [ +@@ -590,14 +596,16 @@ class PipeliningBodyTests(unittest.TestCase, ResponseTestMixin): + b"Request: /", + b"Command: POST", + b"Version: HTTP/1.1", +- b"Content-Length: 21", +- b"'''\n10\n0123456789'''\n", ++ b"Content-Length: 23", ++ b"'''\nNone\n0123456789'''\n", + ), + ] + +- def test_noPipelining(self): ++ def test_stepwiseTinyTube(self): + """ +- Test that pipelined requests get buffered, not processed in parallel. ++ Imitate a slow connection that delivers one byte at a time. ++ The request handler (L{DelayedHTTPHandler}) is puppeted to ++ step through the handling of each request. + """ + b = StringTransport() + a = http.HTTPChannel() +@@ -606,10 +614,9 @@ class PipeliningBodyTests(unittest.TestCase, ResponseTestMixin): + # one byte at a time, to stress it. + for byte in iterbytes(self.requests): + a.dataReceived(byte) +- value = b.value() + + # So far only one request should have been dispatched. +- self.assertEqual(value, b"") ++ self.assertEqual(b.value(), b"") + self.assertEqual(1, len(a.requests)) + + # Now, process each request one at a time. +@@ -618,8 +625,91 @@ class PipeliningBodyTests(unittest.TestCase, ResponseTestMixin): + request = a.requests[0].original + request.delayedProcess() + +- value = b.value() +- self.assertResponseEquals(value, self.expectedResponses) ++ self.assertResponseEquals(b.value(), self.expectedResponses) ++ ++ def test_stepwiseDumpTruck(self): ++ """ ++ Imitate a fast connection where several pipelined ++ requests arrive in a single read. The request handler ++ (L{DelayedHTTPHandler}) is puppeted to step through the ++ handling of each request. ++ """ ++ b = StringTransport() ++ a = http.HTTPChannel() ++ a.requestFactory = DelayedHTTPHandlerProxy ++ a.makeConnection(b) ++ ++ a.dataReceived(self.requests) ++ ++ # So far only one request should have been dispatched. ++ self.assertEqual(b.value(), b"") ++ self.assertEqual(1, len(a.requests)) ++ ++ # Now, process each request one at a time. ++ while a.requests: ++ self.assertEqual(1, len(a.requests)) ++ request = a.requests[0].original ++ request.delayedProcess() ++ ++ self.assertResponseEquals(b.value(), self.expectedResponses) ++ ++ def test_immediateTinyTube(self): ++ """ ++ Imitate a slow connection that delivers one byte at a time. ++ (L{DummyHTTPHandler}) immediately responds, but no more ++ than one ++ """ ++ b = StringTransport() ++ a = http.HTTPChannel() ++ a.requestFactory = DummyHTTPHandlerProxy # "sync" ++ a.makeConnection(b) ++ ++ # one byte at a time, to stress it. ++ for byte in iterbytes(self.requests): ++ a.dataReceived(byte) ++ # There is never more than one request dispatched at a time: ++ self.assertLessEqual(len(a.requests), 1) ++ ++ self.assertResponseEquals(b.value(), self.expectedResponses) ++ ++ def test_immediateDumpTruck(self): ++ """ ++ Imitate a fast connection where several pipelined ++ requests arrive in a single read. The request handler ++ (L{DummyHTTPHandler}) immediately responds. ++ This doesn't check the at-most-one pending request ++ invariant but exercises otherwise uncovered code paths. ++ See GHSA-c8m8-j448-xjx7. ++ """ ++ b = StringTransport() ++ a = http.HTTPChannel() ++ a.requestFactory = DummyHTTPHandlerProxy ++ a.makeConnection(b) ++ ++ # All bytes at once to ensure there's stuff to buffer. ++ a.dataReceived(self.requests) ++ ++ self.assertResponseEquals(b.value(), self.expectedResponses) ++ ++ def test_immediateABiggerTruck(self): ++ """ ++ Imitate a fast connection where a so many pipelined ++ requests arrive in a single read that backpressure is indicated. ++ The request handler (L{DummyHTTPHandler}) immediately responds. ++ This doesn't check the at-most-one pending request ++ invariant but exercises otherwise uncovered code paths. ++ See GHSA-c8m8-j448-xjx7. ++ @see: L{http.HTTPChannel._optimisticEagerReadSize} ++ """ ++ b = StringTransport() ++ a = http.HTTPChannel() ++ a.requestFactory = DummyHTTPHandlerProxy ++ a.makeConnection(b) ++ ++ overLimitCount = a._optimisticEagerReadSize // len(self.requests) * 10 ++ a.dataReceived(self.requests * overLimitCount) ++ ++ self.assertResponseEquals(b.value(), self.expectedResponses * overLimitCount) + + def test_pipeliningReadLimit(self): + """ +@@ -1522,7 +1612,11 @@ class ChunkedTransferEncodingTests(unittest.TestCase): + lambda b: None, # pragma: nocov + ) + p._maxTrailerHeadersSize = 10 +- p.dataReceived(b"3\r\nabc\r\n0\r\n0123456789") ++ # 9 bytes are received so far, in 2 packets. ++ # For now, all is ok. ++ p.dataReceived(b"3\r\nabc\r\n0\r\n01234567") ++ p.dataReceived(b"\r") ++ # Once the 10th byte is received, the processing fails. + self.assertRaises( + http._MalformedChunkedDataError, + p.dataReceived, +-- +2.40.0 diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted_24.3.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted_24.3.0.bb index 336c173893..272aecb8b0 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted_24.3.0.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted_24.3.0.bb @@ -6,6 +6,11 @@ HOMEPAGE = "https://twisted.org" LICENSE = "MIT" LIC_FILES_CHKSUM = "file://LICENSE;md5=c1c5d2c2493b848f83864bdedd67bbf5" +SRC_URI += " \ + file://CVE-2024-41671-0001.patch \ + file://CVE-2024-41671-0002.patch \ +" + SRC_URI[sha256sum] = "6b38b6ece7296b5e122c9eb17da2eeab3d98a198f50ca9efd00fb03e5b4fd4ae" inherit pypi python_hatchling diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-werkzeug_3.0.1.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-werkzeug_3.0.6.bb index f8d2769b41..5758830cb9 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-werkzeug_3.0.1.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-werkzeug_3.0.6.bb @@ -8,9 +8,9 @@ cookie handling, file uploads, a powerful URL routing system and a bunch \ of community contributed addon modules." HOMEPAGE = "https://werkzeug.palletsprojects.com" LICENSE = "BSD-3-Clause" -LIC_FILES_CHKSUM = "file://LICENSE.rst;md5=5dc88300786f1c214c1e9827a5229462" +LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=5dc88300786f1c214c1e9827a5229462" -SRC_URI[sha256sum] = "507e811ecea72b18a404947aded4b3390e1db8f826b494d76550ef45bb3b1dcc" +SRC_URI[sha256sum] = "a8dd59d4de28ca70471a34cba79bed5f7ef2e036a76b3ab0835474246eb41f8d" inherit pypi python_flit_core @@ -20,4 +20,5 @@ RDEPENDS:${PN} += " \ python3-profile \ python3-compression \ python3-json \ + python3-difflib \ " diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-xlsxwriter_3.1.9.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-xlsxwriter_3.1.9.bb index ee7dab35cb..4e23feebbb 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-xlsxwriter_3.1.9.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-xlsxwriter_3.1.9.bb @@ -1,7 +1,7 @@ SUMMARY = "Python 2 and 3 compatibility library" HOMEPAGE = "https://xlsxwriter.readthedocs.io" SECTION = "devel/python" -LICENSE = "MIT" +LICENSE = "BSD-2-Clause" LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=12d9fac1f0049be71ab5aa4a78da02b0" inherit pypi setuptools3 diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-xmodem_0.4.7.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-xmodem_0.4.7.bb index 482f0c641b..a5942e3d5c 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/python3-xmodem_0.4.7.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-xmodem_0.4.7.bb @@ -9,8 +9,8 @@ inherit pypi setuptools3 do_install:append() { install -d ${D}${docdir}/${PN} - mv ${D}/usr/doc/* ${D}${docdir}/${PN}/ - rmdir ${D}/usr/doc + mv ${D}${prefix}/doc/* ${D}${docdir}/${PN}/ + rmdir ${D}${prefix}/doc } RDEPENDS:${PN} += " \ diff --git a/meta-openembedded/meta-python/recipes-devtools/python/tftpy/CVE-2023-46566.patch b/meta-openembedded/meta-python/recipes-devtools/python/tftpy/CVE-2023-46566.patch new file mode 100644 index 0000000000..0131dedb1c --- /dev/null +++ b/meta-openembedded/meta-python/recipes-devtools/python/tftpy/CVE-2023-46566.patch @@ -0,0 +1,26 @@ +From 5b4dcbe1c8fb178e4d31b9a9e63e603b73e8fb2f Mon Sep 17 00:00:00 2001 +From: Dave Wapstra <dwapstra@cisco.com> +Date: Wed, 3 Jul 2024 14:32:58 +1200 +Subject: [PATCH] Add packet size check + +CVE: CVE-2023-46566 + +Upstream-Status: Backport [https://github.com/msoulier/tftpy/commit/5b4dcbe1c8fb178e4d31b9a9e63e603b73e8fb2f] +--- + tftpy/TftpPacketFactory.py | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/tftpy/TftpPacketFactory.py b/tftpy/TftpPacketFactory.py +index 41f39a9..a8c9cd0 100644 +--- a/tftpy/TftpPacketFactory.py ++++ b/tftpy/TftpPacketFactory.py +@@ -29,6 +29,7 @@ class TftpPacketFactory(object): + """This method is used to parse an existing datagram into its + corresponding TftpPacket object. The buffer is the raw bytes off of + the network.""" ++ tftpassert(len(buffer) > 2, 'Invalid packet size') + log.debug("parsing a %d byte packet" % len(buffer)) + (opcode,) = struct.unpack(str("!H"), buffer[:2]) + log.debug("opcode is %d" % opcode) +-- +2.40.0 diff --git a/meta-openembedded/meta-python/recipes-devtools/python/tftpy_0.8.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/tftpy_0.8.2.bb index c1b3234f72..c169916845 100644 --- a/meta-openembedded/meta-python/recipes-devtools/python/tftpy_0.8.2.bb +++ b/meta-openembedded/meta-python/recipes-devtools/python/tftpy_0.8.2.bb @@ -11,3 +11,5 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=22770e72ae03c61f5bcc4e333b61368d" SRC_URI[sha256sum] = "e1d1a680efd88eba176b351175844253067392a9b0f8b81588e3ff2b9e7bbb5b" inherit pypi setuptools3 + +SRC_URI += "file://CVE-2023-46566.patch" |
