summaryrefslogtreecommitdiff
path: root/meta-openembedded
diff options
context:
space:
mode:
authorAndrew Geissler <geissonator@yahoo.com>2025-11-03 19:09:31 +0300
committerAndrew Geissler <geissonator@yahoo.com>2025-11-03 22:31:57 +0300
commit6cb7f76381dbeb50bbf963f9192344f02d985637 (patch)
treee194737ad2b6c562f463cc7a22116ef4aebd1232 /meta-openembedded
parent1f52643312f6f67537eb27bef9156e8b8bc66040 (diff)
downloadopenbmc-scarthgap.tar.xz
subtree updates (scarthgap 11/3/2025)scarthgap
poky: ca27724b44..c4a4df3e72: Adam Blank (3): kernel-dev/common.rst: fix the in-tree defconfig description ref-manual/variables.rst: fix the description of KBUILD_DEFCONFIG ref-manual/variables.rst: fix the description of STAGING_DIR Aditya Tayade (1): e2fsprogs: removed 'sed -u' option Adrian Freihofer (15): kernel-fitimage: fix intentation kernel-fitimage: fix external dtb check devtool: modify support debug-builds devtool: ide-sdk sort cmake preset devtool: ide-sdk recommend DEBUG_BUILD oe-selftest: devtool ide-sdk use modify debug-build devtool: ide-sdk remove the plugin from eSDK installer uboot-config: fix devtool modify with kernel-fitimage sdk-manual: extensible.rst: devtool ide-sdk improve sdk-manual: extensible.rst: update devtool ide-sdk ref-manual: kernel-fitimage.bbclass does not use SPL_SIGN_KEYNAME llvm: update from 18.1.6 to 18.1.8 llvm: fix build with gcc-15 expect: Revert "expect-native: fix do_compile failure with gcc-14" expect: fix native build with GCC 15 Alban Bedel (1): bind: Fix build with the `httpstats` package config enabled Aleksandar Nikolic (12): cve-check: Introduce CVE_CHECK_MANIFEST_JSON_SUFFIX install-buildtools: remove md5 checksum validation install-buildtools: fix "test installation" step install-buildtools: update base-url, release and installer version ref-manual: introduce CVE_CHECK_REPORT_PATCHED variable scripts/install-buildtools: Update to 5.0.5 scripts/install-buildtools: Update to 5.0.6 scripts/install-buildtools: Update to 5.0.7 scripts/install-buildtools: Update to 5.0.9 scripts/install-buildtools: Update to 5.0.10 scripts/install-buildtools: Update to 5.0.11 scripts/install-buildtools: Update to 5.0.12 Alessio Cascone (1): tzcode-native: Fix compiler setting from 2023d version Alexander Kanavin (29): mesa: remove obsolete 0001-meson.build-check-for-all-linux-host_os-combinations.patch kexec-tools: submit 0003-kexec-ARM-Fix-add_buffer_phys_virt-align-issue.patch upstream vorbis: mark patch as Inactive-Upstream grub: mark grub-module-explicitly-keeps-symbole-.module_license.patch as a workaround perl: submit the rest of determinism.patch upstream iptables: submit 0001-configure-Add-option-to-enable-disable-libnfnetlink.patch upstream xserver-xorg: upgrade 21.1.12 -> 21.1.13 mobile-broadband-provider-info: upgrade 20230416 -> 20240407 python3: submit deterministic_imports.patch upstream as a ticket glib-networking: submit eagain.patch upstream glslang: mark 0001-generate-glslang-pkg-config.patch as Inappropriate tcp-wrappers: mark all patches as inactive-upstream automake: mark new_rt_path_for_test-driver.patch as Inappropriate settings-daemon: submit addsoundkeys.patch upstream and update to a revision that has it dpkg: mark patches adding custom non-debian architectures as inappropriate for upstream libacpi: mark patches as inactive-upstream apr: drop 0007-explicitly-link-libapr-against-phtread-to-make-gold-.patch pulseaudio, desktop-file-utils: correct freedesktop.org -> www.freedesktop.org SRC_URI sysvinit: take release tarballs from github package_rpm: use zstd's default compression level package_rpm: restrict rpm to 4 threads rust: add reproducibility patch to eliminate host leakage rust: build the default set of tools rust: use rust-snapshot binaries only in rust-native rust: correctly link rust-snapshot into build/stage0 pkg-config-native: pick additional search paths from $EXTRA_NATIVE_PKGCONFIG_PATH selftest/rust: correctly form the PATH environment variable perlcross: update 1.5.2 -> 1.6 mtools: upgrade 4.0.43 -> 4.0.44 Alexis Cellier (1): systemd: add libpcre2 as RRECOMMENDS if pcre2 is enabled Alexis Lothoré (3): oeqa/utils/postactions: transfer whole archive over ssh instead of doing individual copies oeqa/postactions: fix exception handling oeqa/ssh: allow to retrieve raw, unformatted ouput Alon Bar-Lev (1): module.bbclass: add KBUILD_EXTRA_SYMBOLS to install Alper Ak (2): ref-manual/variables.rst: document INHIBIT_DEFAULT_RUST_DEPS ref-manual/variables.rst: document INHIBIT_UPDATERCD_BBCLASS Anders Heimer (1): libpam: mark CVE-2025-6018 as not applicable Andrew Fernandes (1): gtk+: add missing libdrm dependency Andrew Kreimer (1): manuals: remove repeated word Antonin Godard (77): ref-manual: add missing CVE_CHECK manifest variables ref-manual: add missing TESTIMAGE_FAILED_QA_ARTIFACTS ref-manual: add missing EXTERNAL_KERNEL_DEVICETREE variable ref-manual: add missing OPKGBUILDCMD variable ref-manual: merge patch-status-* to patch-status ref-manual: structure.rst: document missing tmp/ dirs overview-manual: concepts: add details on package splitting ref-manual: faq: add q&a on class appends ref-manual: release-process: update releases.svg ref-manual: release-process: refresh the current LTS releases ref-manual: release-process: update releases.svg with month after "Current" ref-manual: release-process: add a reference to the doc's release ref-manual: devtool-reference: refresh example outputs ref-manual: devtool-reference: document missing commands conf.py: rename :cve: role to :cve_nist: doc: Makefile: remove inkscape, replace by rsvg-convert doc: Makefile: add support for xelatex doc: add a download page for epub and pdf sphinx-static/switchers.js.in: do not refer to URL_ROOT anymore conf.py: add a bitbake_git extlink dev-manual: document how to provide confs from layer.conf dev-manual: bblock: use warning block instead of attention standards.md: add a section on admonitions ref-manual: classes: fix bin_package description Gather dependencies in poky.yaml.in poky.yaml.in: add missing locales dependency poky.yaml.in: replace inkscape dependency by librsvg2-bin system-requirements: add fedora 39 to supported distros system-requirements: update list of supported distros system-requirements.rst: add dependencies for pdf builds Update the documentation for SRCPV poky.conf: add new tested distros ref-manual/qa-checks: remove patch-status-core/patch-status-noncore contributor-guide/submit-changes.rst: suggest to remove the git signature ref-manual/devtool-reference: add warning note on deploy-target and shared objects SSTATE_MIRRORS/SOURCE_MIRROR_URL: add instructions for mirror authentication ref-manual/packages: move ptest section to the test-manual ref-manual: move runtime-testing section to the test-manual Update autobuilder URLs to valkyrie test-manual/reproducible-builds: fix reproducible links test-manual/ptest: link to common framework ptest classes dev-manual/building: document the initramfs-framework recipe ref-manual/faq: add q&a on systemd as default contributor-guide/submit-changes: add policy on AI generated code Add favicon for the documentation html overview-manual/concepts: remove PR from the build dir list ref-manual/variables.rst: WATCHDOG_TIMEOUT: fix recipe name ref-manual/variables.rst: document autotools class related variables documentation/conf.py: define a manpage url ref-manual/variables.rst: add manpage links for toolchain variables ref-manual/variables.rst: add missing documentation for BUILD_* variables ref-manual/variables.rst: document missing SDK_*_ARCH variables ref-manual/variables.rst: document HOST_*_ARCH variables ref-manual/variables.rst: HOST_CC_ARCH: fix wrong SDK reference ref-manual/variables.rst: improve the PKGV documentation poky.yaml: introduce DISTRO_LATEST_TAG Fix dead links that use the DISTRO macro dev-manual/sbom.rst: fix wrong build outputs test-manual/intro: remove Buildbot version used ref-manual/release-process: update releases.svg overview-manual/concepts.rst: fix sayhello hardcoded bindir ref-manual/system-requirements.rst: update supported distributions ref-manual/variables.rst: document the FIT_CONF_PREFIX variable ref-manual/variables.rst: document SPL_DTB_BINARY ref-manual/classes.rst: document the testexport class dev-manual/security-subjects.rst: update mailing lists test-manual/yocto-project-compatible.rst: fix a typo ref-manual/structure: document the auto.conf file ref-manual/variables.rst: document UNINATIVE_URL/CHECKSUM ref-manual/classes.rst: extend the uninative class documentation ref-manual/classes,variables: document the CCACHE_DISABLE variable ref-manual/variables.rst: document the REQUIRED_MACHINE_FEATURES variable ref-manual/variables.rst: document the REQUIRED_COMBINED_FEATURES variable ref-manual/variables.rst: document the REQUIRED_IMAGE_FEATURES variable ref-manual/variables.rst: document the USE_NLS variable ref-manual/classes.rst: gettext: extend the documentation of the class ref-manual/classes.rst: document the relative_symlinks class Anuj Mittal (1): sqlite3: upgrade 3.45.1 -> 3.45.3 Archana Polampalli (51): less: fix CVE-2024-32487 ofono: fix CVE-2023-2794 ffmpeg: fix CVE-2023-49502 ffmpeg: fix CVE-2024-31578 ffmpeg: fix CVE-2024-31582 ffmpeg: fix CVE-2023-50008 ffmpeg: fix CVE-2024-32230 qemu: fix CVE-2024-7409 ffmpeg: fix CVE-2023-49501 ffmpeg: fix CVE-2024-28661 ffmpeg: fix CVE-2023-50007 ffmpeg: fix CVE-2023-49528 ffmpeg: fix CVE-2024-7055 ffmpeg: fix CVE-2024-35366 ffmpeg: fix CVE-2024-35367 ffmpeg: fix CVE-2024-35368 rsync: fix CVE-2024-12084 rsync: fix CVE-2024-12085 rsync: fix CVE-2024-12086 rsync: fix CVE-2024-12087 rsync: fix CVE-2024-12088 rsync: fix CVE-2024-12747 ffmpeg: fix CVE-2024-35365 ffmpeg: fix CVE-2024-36613 ffmpeg: fix CVE-2024-36616 ffmpeg: fix CVE-2024-36617 ffmpeg: fix CVE-2024-36618 ffmpeg: fix CVE-2024-36619 ffmpeg: fix CVE-2024-35369 gstreamer1.0-rtsp-server: fix CVE-2024-44331 ffmpeg: fix CVE-2025-25473 ffmpeg: fix CVE-2025-25471 ffmpeg: fix CVE-2025-22921 ffmpeg: fix CVE-2025-0518 ffmpeg: Correct the CVE ID to fix CVE-2025-22919 openssh: fix CVE-2025-26465 go: fix CVE-2025-22870 ghostscript: upgrade 10.04.0 -> 10.05.0 perlcross: 1.6 -> 1.6.2 perl: upgrade 5.38.2 -> 5.38.4 xwayland: fix CVE-2025-49175 xwayland: fix CVE-2025-49176 xwayland: fix CVE-2025-49177 xwayland: fix CVE-2025-49178 xwayland: fix CVE-2025-49179 xwayland: fix CVE-2025-49180 gdk-pixbuf: fix CVE-2025-7345 go: fix CVE-2025-4674 ffmpeg: upgrade 6.1.2 -> 6.1.3 ffmpeg: fix CVE-2025-1594 go: fix CVE-2025-47906 Ashish Sharma (11): bind: Upgrade 9.18.25 -> 9.18.28 ruby: Backport fix for CVE-2024-27282 ruby: Fix CVE-2025-27219 binutils: Fix CVE-2025-1176 binutils: patch CVE-2025-1178 & CVE-2024-57360 binutils: patch CVE-2025-1181 binutils: patch CVE-2025-1182 libsoup: patch CVE-2025-46420 libsoup-2.4: Fix CVE-2025-46420 libsoup: patch CVE-2025-4476 screen: patch CVE-2025-46805 AshishKumar Mishra (2): systemd: backport fix for handle USE_NLS from master p11-kit: backport fix for handle USE_NLS from master Barne Carstensen (1): test-manual: update runtime-testing Exporting Tests section Bartosz Golaszewski (1): linux-firmware: add a package for ath12k firmware Benjamin Szőke (2): archiver.bbclass: Fix work-shared checking for kernel recipes mc: fix source URL Bin Lan (1): lttng-ust: backport patch to fix cmake-multiple-shared-libraries build error Bruce Ashfield (54): linux-yocto/6.6: update to v6.6.36 linux-yocto/6.6: update to v6.6.38 linux-yocto/6.6: update to v6.6.40 linux-yocto/6.6: update to v6.6.43 kernel-devsrc: remove 64 bit vdso cmd files linux-yocto/6.6: update to v6.6.44 linux-yocto/6.6: update to v6.6.45 linux-yocto/6.6: fix genericarm64 config warning linux-yocto/6.6: update to v6.6.47 linux-yocto/6.6: update to v6.6.49 linux-yocto/6.6: update to v6.6.50 linux-yocto/6.6: update to v6.6.52 linux-yocto/6.6: update to v6.6.54 linux-yocto/6.6: update to v6.6.56 linux-yocto/6.6: update to v6.6.58 linux-yocto/6.6: genericarm64.cfg: enable CONFIG_DMA_CMA linux-yocto/6.6: update to v6.6.59 linux-yocto/6.6: update to v6.6.60 linux-yocto/6.6: update to v6.6.62 linux-yocto/6.6: bsp/genericarm64: disable ARM64_SME linux-yocto/6.6: update to v6.6.63 linux-yocto/6.6: update to v6.6.64 linux-yocto/6.6: update to v6.6.66 linux-yocto/6.6: update to v6.6.69 linux-yocto/6.6: update to v6.6.75 linux-yocto/6.6: update to v6.6.77 linux-yocto/6.6: update to v6.6.78 linux-yocto/6.6: update to v6.6.80 linux-yocto/6.6: update to v6.6.82 linux-yocto/6.6: update to v6.6.83 linux-yocto/6.6: update to v6.6.84 linux-yocto/6.6: update to v6.6.85 linux-yocto/6.6: fix beaglebone ethernet linux-yocto/6.6: update to v6.6.86 linux-yocto/6.6: update to v6.6.87 linux-yocto/6.6: update to v6.6.88 linux-yocto/6.6: update to v6.6.89 linux-yocto/6.6: update to v6.6.91 linux-yocto/6.6: update to v6.6.92 linux-yocto/6.6: update to v6.6.93 linux-yocto/6.6: update to v6.6.94 linux-yocto/6.6: update to v6.6.96 linux-yocto/6.6: update to v6.6.98 linux-yocto/6.6: update to v6.6.99 linux-yocto/6.6: update to v6.6.100 linux-yocto/6.6: update to v6.6.101 linux-yocto/6.6: update to v6.6.102 linux-yocto/6.6: update to v6.6.103 linux-yocto/6.6: update to v6.6.106 linux-yocto/6.6: update to v6.6.107 linux-yocto/6.6: update to v6.6.108 linux-yocto/6.6: update to v6.6.109 linux-yocto/6.6: update to v6.6.110 linux-yocto/6.6: update to v6.6.111 Carlos Alberto Lopez Perez (1): icu: Backport patch to fix build issues with long paths (>512 chars) Carlos Sánchez de La Lama (1): ref-manual: clarify KCONFIG_MODE default behaviour Catalin Popescu (1): Revert "bluez5: remove configuration files from install task" Changqing Li (48): apt-native: don't let dpkg overwrite files by default apt: runtime error: filename too long (tmpdir length) webkitgtk: fix do_configure error on beaglebone-yocto webkitgtk: fix do_compile errors on beaglebone-yocto vulkan-samples: fix do_compile error when -Og enabled multilib.conf: remove appending to PKG_CONFIG_PATH gettext: fix a parallel build issue pixman: fixing inline failure with -Og rt-tests: rt_bmark.py: fix TypeError curl: correct the PACKAGECONFIG for native/nativesdk libpng: update SRC_URI expect-native: fix do_compile failure with gcc-14 libcap-ng: update SRC_URI sysvinit: backport patch for fixing one issue of pidof acpica: fix CVE-2024-24856 libsoup: fix CVE-2024-52530, CVE-2024-52531 rxvt-unicode.inc: disable the terminfo installation by setting TIC to : sanity.bbclass: skip check_userns for non-local uid systemd: enable create-log-dirs babeltrace: extend to nativesdk babeltrace2: extend to nativesdk patch.py: set commituser and commitemail for addNote initscripts: add function log_success_msg/log_failure_msg/log_warning_msg buildtools-tarball: move setting of envvars to respective envfile buildtools-tarball: add envvars into BB_ENV_PASSTHROUGH_ADDITIONS buildtools-tarball: Make buildtools respects host CA certificates libsoup: fix CVE-2025-32908 libsoup: fix CVE-2025-32907 libsoup-2.4: fix CVE-2025-32907 libsoup-2.4: fix do_compile failure libsoup-2.4: fix CVE-2025-32053 libsoup: fix CVE-2025-32053 libsoup-2.4: fix CVE-2025-32052 libsoup: fix CVE-2025-32052 libsoup: fix CVE-2025-32051 libsoup-2.4: fix CVE-2025-32050 libsoup: fix CVE-2025-32050 libsoup-2.4: fix CVE-2025-46421 libsoup: fix CVE-2025-46421 libsoup-2.4: fix CVE-2025-4948 libsoup: fix CVE-2025-4948 libsoup-2.4: fix CVE-2025-4476 libsoup-2.4: fix CVE-2025-2784 libsoup: fix CVE-2025-2784 icu: fix CVE-2025-5222 libsoup-2.4: refresh CVE-2025-4969.patch libsoup-2.4: fix CVE-2025-4945 libsoup: fix CVE-2025-4945 Chen Qi (8): libnl: change HOMEPAGE qemu: back port patches to fix riscv64 build failure toolchain-shar-extract.sh: exit when post-relocate-setup.sh fails libgfortran: fix buildpath QA issue bitbake: data_smart.py: remove unnecessary ? from __expand_var_regexp__ bitbake: data_smart.py: simple clean up bitbake: data_smart.py: clear expand_cache in _setvar_update_overridevars coreutils: fix CVE-2025-5278 Chris Laplante (6): bitbake: persist_data: close connection in SQLTable __exit__ bitbake: fetch2: use persist_data context managers bitbake: ui/knotty: print log paths for failed tasks in summary bitbake: ui/knotty: respect NO_COLOR & check for tty; rename print_hyperlink => format_hyperlink bitbake: cooker: Make cooker 'skiplist' per-multiconfig/mc util-linux: use ${B} instead of ${WORKDIR}/build, to fix building under devtool Christian Taedcke (1): iptables: fix memory corruption when parsing nft rules Christos Gavros (2): ref-manual/variables.rst: document the IMAGE_ROOTFS_MAXSIZE variable ref-manual/variables.rst: document the INITRAMFS_MAXSIZE variable Claus Stovgaard (1): lib/oe/package-manager: skip processing installed-pkgs with empty globs Clayton Casciato (1): uboot-sign: fix concat_dtb arguments Colin McAllister (2): udev-extraconf: Add collect flag to mount busybox: Fix cut with "-s" flag Colin Pinnell McAllister (1): ffmpeg: fix CVE-2025-1373 Daniel Semkowicz (2): os-release: Fix VERSION_CODENAME in case it is empty gstreamer1.0-plugins-bad: fix buffer allocation fail for v4l2codecs Daniel Turull (4): package: export debugsources in PKGDESTWORK as json spdx: add option to include only compiled sources xz: ignore CVE-2024-47611 libxml2: ignore CVE-2025-8732 David Nyström (3): openssh: fix CVE-2025-61985 openssh: fix CVE-2025-61984 lz4: fix CVE-2025-62813 Deepak Rathore (1): default-distrovars.inc: Fix CONNECTIVITY_CHECK_URIS redirect issue Deepesh Varatharajan (13): binutils: stable 2.42 branch updates glibc: stable 2.39 branch updates. binutils: stable 2.42 branch update binutils: Fix CVE-2025-0840 glibc: stable 2.39 branch updates binutils: stable 2.42 branch updates binutils: Fix CVE-2025-5245 binutils: Fix CVE-2025-5244 gcc: Upgrade to GCC 13.4 binutils: stable 2.42 branch updates binutils: Fix CVE-2025-7545 glibc: stable 2.39 branch updates glibc: stable 2.39 branch updates Deepthi Hemraj (5): binutils: stable 2.42 branch updates glibc: stable 2.39 branch updates rust-llvm: Fix CVE-2024-0151 binutils: stable 2.42 branch update glibc: stable 2.39 branch updates Denys Dmytriyenko (3): weston: upgrade 13.0.0 -> 13.0.1 gcc: unify cleanup of include-fixed, apply to cross-canadian nativesdk-libtool: sanitize the script, remove buildpaths Divya Chellam (16): libpam: fix CVE-2024-10041 libxml2: Upgrade 2.12.8 -> 2.12.9 wget: fix CVE-2024-10524 vim: Upgrade 9.1.0764 -> 9.1.1043 vim: Upgrade 9.1.1043 -> 9.1.1115 ruby: fix CVE-2025-27220 ruby: fix CVE-2025-27221 screen: fix CVE-2025-46802 screen: fix CVE-2025-46804 libarchive: fix CVE-2025-5914 libarchive: fix CVE-2025-5915 libarchive: fix CVE-2025-5916 libarchive: fix CVE-2025-5917 libarchive: fix CVE-2025-5918 wpa-supplicant: fix CVE-2022-37660 vim: upgrade 9.1.1652 -> 9.1.1683 Divyanshu Rathore (1): ffmpeg: upgrade 6.1.1 -> 6.1.2 Dixit Parmar (1): ref-manual: document KERNEL_SPLIT_MODULES variable Dmitry Baryshkov (1): xserver-xorg: fix CVE-2023-5574 status Emil Kronborg (3): insane.bbclass: remove skipping of cross-compiled packages insane.bbclass: fix HOST_ variable names insane.bbclass: remove leftover variables and comment Enrico Jörns (6): wic: engine.py: use raw string for escape sequence wic: bootimg-efi: fix error handling bitbake: bitbake-diffsigs: fix handling when finding only a single sigfile ref-manual/variables.rst: update ROOT_HOME documentation conf.py: tweak SearchEnglish to be hyphen-friendly conf.py: improve SearchEnglish to handle terms with dots Erik Lindsten (1): overview-manual/yp-intro.rst: fix broken link to article Esben Haabendal (3): pulseaudio: fix webrtc audio depdency files: Amend overlayfs unit descriptions with path information files: overlayfs-create-dirs: Improve mount unit dependency Etienne Cordonnier (6): oeqa/runtime: fix regression in minidebuginfo test oeqa/runtime: make minidebuginfo test work with coreutils oeqa/runtime: fix race-condition in minidebuginfo test python3-setuptools-scm: respect GIT_CEILING_DIRECTORIES ref-manual/variables.rst: document SSTATE_SKIP_CREATION bitbake: gcp.py: remove slow calls to gsutil stat Fabio Berton (2): ccache.conf: Add include_file_ctime to sloppiness linux-libc-headers: Fix invalid conversion in cn_proc.h Florian Kreutzer (1): dropbear: backport fix for concurrent channel open/close Gassner, Tobias.ext (1): rootfs: Ensure run-postinsts is not uninstalled for read-only-rootfs-delayed-postinsts Gauthier HADERER (1): populate_sdk_ext.bclass: make sure OECORE_NATIVE_SYSROOT is exported. Guocai He (2): tcf-agent: correct the SRC_URI minicom: correct the SRC_URI Guénaël Muller (1): ref-manual: use standardized method accross both ubuntu and debian for locale install Guðni Már Gilbert (15): pam: Fix for CVE-2024-22365 python3-attrs: drop python3-ctypes from RDEPENDS bluez5: remove redundant patch for MAX_INPUT shared-mime-info: drop itstool-native from DEPENDS libpam: drop cracklib from DEPENDS systemd: drop intltool-native from DEPENDS systemd-boot: drop intltool-native from DEPENDS python3-poetry-core: drop python3-six from RDEPENDS dnf: drop python3-iniparse from DEPENDS and RDEPENDS python3: upgrade 3.12.6 -> 3.12.7 python3: upgrade 3.12.7 -> 3.12.8 systemd: upgrade 255.13 -> 255.17 systemd: upgrade 255.17 -> 255.18 bluez5: add missing tools to noinst-tools package systemd: upgrade 255.18 -> 255.21 Gyorgy Sarvari (1): conf/bitbake.conf: use gnu mirror instead of main server Haixiao Yan (2): glibc: Add single-threaded fast path to rand() buildtools-tarball: fix unbound variable issues under 'set -u' Harish Sadineni (7): binutils: Add missing perl modules to RDEPENDS for nativesdk variant rust-target-config: Fix TARGET_C_INT_WIDTH with correct size rust: fix for rust multilib sdk configuration rust: remove redundant cargo config file oeqa/sdk/context: fix for gtk3 test failure during do_testsdk binutils: Fix CVE-2025-1179 binutils: set CVE_STATUS for CVE-2025-1180 Hiago De Franco (2): weston: backport patch to allow neatvnc < v0.9.0 bluez5: backport patch to fix address type when loading keys Hitendra Prajapati (24): ghostscript: upgrade 10.02.1 -> 10.03.1 ruby: fix CVE-2024-27281 vte: fix CVE-2024-37535 curl: fix CVE-2024-8096 webkitgtk: upgrade 2.44.1 -> 2.44.3 cups: Backport fix for CVE-2024-47175 libarchive: fix CVE-2024-48957 & CVE-2024-48958 libsoup: fix CVE-2024-52532 ghostscript: upgrade 10.03.1 -> 10.04.0 libsndfile: fix CVE-2024-50612 ofono: Fix multiple CVEs libcap: fix CVE-2025-1390 elfutils: Fix multiple CVEs go: fix CVE-2025-22871 libsoup-3.4.4: Fix CVE-2025-4969 libsoup-2.4: Fix CVE-2025-4969 libxml2: fix CVE-2025-6021 libxml2: fix CVE-2025-49794 & CVE-2025-49796 libpam: fix CVE-2025-6020 gstreamer1.0-plugins-base: fix CVE-2025-47808 gstreamer1.0-plugins-base: fix CVE-2025-47806 gstreamer1.0-plugins-good: fix multiple CVEs gstreamer1.0-plugins-base: fix CVE-2025-47807 grub2: mark CVE-2024-2312 as not applicable Hongxu Jia (10): ovmf: fix CVE-2024-38796 ovmf: fix CVE-2024-1298 u-boot: fix CVE-2024-57254 u-boot: fix CVE-2024-57255 u-boot: fix CVE-2024-57256 u-boot: fix CVE-2024-57257 u-boot: fix CVE-2024-57258 u-boot: fix CVE-2024-57259 rpm: keep leading `/' from sed operation u-boot: fix CVE-2024-42040 Igor Opaniuk (1): wic: bootimg-efi: Support + symbol in filenames Jaeyoon Jung (2): makedevs: Fix issue when rootdir of / is given makedevs: Fix matching uid/gid Jagadeesh Krishnanjanappa (1): tune-cortexa32: set tune feature as armv8a Jan Vermaete (1): sdk: The main in the C example should return an int Jeroen Hofstee (2): bluez5: make media control a PACKAGECONFIG option bluez5: backport a patch to fix btmgmt -i Jiaying Song (9): liba52: fix do_fetch error enchant2: fix do_fetch error libxml-parser-perl: fix do_fetch error python3-zipp: fix CVE-2024-5569 subversion: fix CVE-2024-46901 boost: fix do_fetch error binutils: File name too long causing failure to open temporary head file in dlltool python3-requests: upgrade 2.32.3 -> 2.32.4 ruby-ptest : some ptest fixes Jinfeng Wang (3): tzdata&tzcode-native: upgrade 2024a -> 2024b mtools: upgrade 4.0.48 -> 4.0.49 systemtap: Fix task_work_cancel build Joao Marcos Costa (1): ref-manual/variables.rst: expand IMAGE_OVERHEAD_FACTOR glossary entry Joe Slater (1): oe-debuginfod: add option for data storage Joerg Schmidt (1): bitbake: bblayers/query: Fix using "removeprefix" string method Johannes Schneider (1): ppp: Revert lock path to /var/lock Jon Mason (4): oeqa/runtime/ssh: add retry logic and sleeps to allow for slower systems oeqa/runtime/ssh: check for all errors at the end oeqa/runtime/ssh: increase the number of attempts openssh: add backported header file include Jonas Gorski (1): rootfs-postcommands.bbclass: make opkg status reproducible Jookia (1): populate_sdk_ext.bbclass: Fix undefined variable error Jose Quaresma (7): go: upgrade 1.22.4 -> 1.22.5 oeqa/runtime/scp: requires openssh-sftp-server openssh: drop rejected patch fixed in 8.6p1 release openssh: systemd sd-notify patch was rejected upstream openssh: systemd notification was implemented upstream go: upgrade 1.22.5 -> 1.22.6 bitbake: bitbake: doc/user-manual: Update the BB_HASHSERVE_UPSTREAM Joshua Watt (3): bitbake: asyncrpc: Use client timeout for websocket open timeout bitbake: Remove custom exception backtrace formatting bitbake: Use a "fork" multiprocessing context João Marcos Costa (1): variables.rst: fix LAYERDEPENDS description Julien Stephan (5): README: add instruction to run Vale on a subset documentation: Makefile: add SPHINXLINTDOCS to specify subset to sphinx-lint styles: vocabularies: Yocto: add sstate ref-manual: variables: add SIGGEN_LOCKEDSIGS* variables dev-manual: add bblock documentation Jörg Sommer (5): classes/kernel: No symlink in postinst without KERNEL_IMAGETYPE_SYMLINK doc/features: remove duplicate word in distribution feature ext2 doc/features: describe distribution feature pni-name ptest-runner: Update 2.4.4 -> 2.4.5 runqemu: Fix detection of -serial parameter Kai Kang (3): multilib.bbclass: replace deprecated e.data with d cmake-qemu.bbclass: fix if criterion glibc: fix fortran header file conflict for arm Khem Raj (26): linux-yocto: Enable team net driver systemd.bbclass: Clarify error message grub,grub-efi: Remove -mfpmath=sse on x86 python3: Treat UID/GID overflow as failure gawk: Remove References to /usr/local/bin/gawk busybox: CVE-2023-42364 and CVE-2023-42365 fixes busybox: Add fix for CVE-2023-42366 gcc: Fix spurious '/' in GLIBC_DYNAMIC_LINKER on microblaze gnupg: Document CVE-2022-3219 and mark wontfix openssh: Mark CVE-2023-51767 as wont-fix libpcre2: Update base uri PhilipHazel -> PCRE2Project python3: Drop empty patch qemu: Do not define sched_attr with glibc >= 2.41 e2fsprogs: Fix build failure with gcc 15 parted: Fix build with GCC 15 bash: Stick to C17 std ncurses: Pin to C17 standard unzip: Fix build with GCC-15 m4: Stick to C17 standard gmp: Fix build with GCC15/C23 gmp: Fix build with older gcc versions gdbm: Use C11 standard unifdef: Don't use C23 constexpr keyword libtirpc: Fix build with gcc-15/C23 cpio: Pin to use C17 std expect: Fix build with GCC 15 Kirill Yatsenko (1): iptables: fix save/restore symlinks with libnftnl PACKAGECONFIG enabled Konrad Weihmann (3): runqemu: keep generating tap devices testimage: fallback for empty IMAGE_LINK_NAME testexport: fallback for empty IMAGE_LINK_NAME Kyungjik Min (1): pulseaudio: Add audio group explicitly Lee Chee Yang (24): migration-notes: add release notes for 5.0.1 migration-guides: add release notes for 4.0.19 migration-guides: add release notes for 5.0.2 migration-guide: add release notes for 4.0.20 migration-guides: add release notes for 5.0.3 migration-guide: add release notes for 4.0.21 migration-guides: add release notes for 5.0.4 migration-guide: add release notes for 4.0.22 migration-guides: add release notes for 5.0.5 migration-guides: add release notes for 4.0.23 migration-guides: add release notes for 5.0.6 migration-guides: add release notes for 4.0.24 migration-guides: add release notes for 5.0.7 migration-guides: add release notes for 4.0.25 migration-guides: add release notes for 5.0.8 migration-guides: add release notes for 4.0.26 migration-guides: add release notes for 5.0.9 migration-guides: add release notes for 4.0.27 migration-guide: add release notes for 5.0.10 migration-guides: add release notes for 4.0.28 migration-guides: add release notes for 5.0.11 migration-guides: add release notes for 4.0.29 migration-guides: add release notes for 5.0.12 migration-guides: add release notes for 4.0.30 Libo Chen (1): runqemu: fix special characters bug Louis Rannou (1): image_qa: fix error handling Macpaul Lin (1): linux-firmware: upgrade 20240312 -> 20240909 Madhu Marri (1): qemu 8.2.7: ignore CVE-2023-1386 Makarios Christakis (1): icu: Adjust ICU_DATA_DIR path on big endian targets Marco Cavallini (1): dev-manual/start.rst: added missing command in Optimize your VHDX file using DiskPart Marek Vasut (3): u-boot: kernel-fitimage: Fix dependency loop if UBOOT_SIGN_ENABLE and UBOOT_ENV enabled base-files: Drop /bin/sh dependency u-boot: kernel-fitimage: Restore FIT_SIGN_INDIVIDUAL="1" behavior Mark Hatle (9): package.py: Fix static debuginfo split package.py: Fix static library processing selftest-hardlink: Add additional test cases create-spdx-*: Support multilibs via SPDX_MULTILIB_SSTATE_ARCHS oeqa sdk cases: Skip SDK test cases when TCLIBC is newlib create-sdpx-2.2.bbclass: Switch from exists to isfile checking debugsrc populate_sdk_ext: write_local_conf add shutil import cve-update-nvd2-native: Handle BB_NO_NETWORK and missing db bitbake: bitbake: runqueue: Verify mcdepends are valid Markus Volk (3): libadwaita: update 1.5.0 -> 1.5.1 gcc: add a backport patch to fix an issue with tzdata 2024b ninja: fix build with python 3.13 Marta Rybczynska (1): vulnerabilities/classes: remove references to cve-check text format Martin Jansa (22): selftest: add Upstream-Status to .patch files libgfortran.inc: fix nativesdk-libgfortran dependencies populate_sdk_base: inherit nopackages meta-world-pkgdata: Inherit nopackages python3-lxml=v5.0.2 mc: set ac_cv_path_ZIP to avoid buildpaths QA issues libpam: re-add missing libgen include cairo: fix build with gcc-15 on host bash: use -std=gnu17 also for native CFLAGS cmake: fix build with gcc-15 on host git: fix build with gcc-15 on host pkgconfig: fix build with gcc-15 libgpg-error: fix build with gcc-15 rust-llvm: fix build with gcc-15 elfutils: fix build with gcc-15 binutils: fix build with gcc-15 dbus-glib: fix build with gcc-15 bitbake: bitbake: Bump version to 2.8.1 license.py: avoid deprecated ast.Str sanity.conf: Update minimum bitbake version to 2.8.1 lib/oe/utils: use multiprocessing from bb flex: fix build with gcc-15 on host Matthias Pritschet (1): ref-manual: fix typo and move SYSROOT_DIRS example Matthias Schiffer (1): curl: only set CA bundle in target build Michael Haener (1): oeqa/runtime/ping: don't bother trying to ping localhost Michael Halstead (4): yocto-uninative: Update to 4.6 for glibc 2.40 yocto-uninative: Update to 4.7 for glibc 2.41 yocto-uninative: Update to 4.8 for GCC 15.1 yocto-uninative: Update to 4.9 for glibc 2.42 Michael Opdenacker (5): maintainers.inc: update self e-mail address doc: Makefile: publish pdf and epub versions too dev-manual: fix styling of references to bmaptool dev-manual/bmaptool.rst: correct command for bmaptool-native dev-manual/bmaptool.rst: simplify and fix instructions Michal Seben (1): timedated: wait for jobs before SetNTP response Mikko Rapeli (1): ovmf-native: remove .pyc files from install Mingli Yu (1): llvm: Enable libllvm for native build Moritz Haase (2): meta: Enable '-o pipefail' for the SDK installer cmake: Correctly handle cost data of tests with arbitrary chars in name NeilBrown (1): nfs-utils: don't use signals to shut down nfs server. Nguyen Dat Tho (1): libatomic-ops: Update GITHUB_BASE_URI Nikhil R (1): cmake: Add PACKAGECONFIG option for debugger support Niko Mauno (15): dnf/mesa: Fix missing leading whitespace with ':append' libyaml: Fix warning regarding unpatched CVE systemd: Mitigate /var/log type mismatch issue systemd: Mitigate /var/tmp type mismatch issue image_types.bbclass: Use --force also with lz4,lzop util-linux: Add PACKAGECONFIG option to mitigate rootfs remount error iw: Fix LICENSE dejagnu: Fix LICENSE unzip: Fix LICENSE zip: Fix LICENSE tiff: Fix LICENSE gcr: Fix LICENSE python3-maturin: Fix cross compilation issue for armv7l, mips64, ppc cve-check.bbclass: Mitigate symlink related error cve-check.bbclass: Fix symlink handling also for text files Nitin Wankhade (1): examples: genl: fix wrong attribute size Oleksandr Hnatiuk (2): icu: remove host references in nativesdk to fix reproducibility gcc: remove paths to sysroot from configargs.h and checksum-options for gcc-cross-canadian Patrick Wicki (1): gpgme: move gpgme-tool to own sub-package Paul Barker (2): meta-ide-support: Mark recipe as MACHINE-specific dev-manual, test-manual: Update autobuilder output links Paul Gerber (1): uboot-sign: fix counters in do_uboot_assemble_fitimage Pavel Zhukov (1): package_rpm: Check if file exists before open() Pedro Ferreira (3): buildhistory: Fix intermittent package file list creation buildhistory: Restoring files from preserve list rust-common.bbclass: soft assignment for RUSTLIB path Peter Kjellerstedt (1): image.bbclass: Drop support for ImageQAFailed exceptions in image_qa Peter Marko (144): flac: fix buildpaths warnings cargo: remove True option to getVar calls ncurses: switch to new mirror busybox: Patch CVE-2021-42380 busybox: Patch CVE-2023-42363 libstd-rs,rust-cross-canadian: set CVE_PRODUCT to rust curl: Patch CVE-2024-6197 glibc: cleanup old cve status qemu: set cve status for CVE-2023-6683 libmnl: explicitly disable doxygen libyaml: ignore CVE-2024-35326 libyaml: Ignore CVE-2024-35325 curl: Patch CVE-2024-7264 python3: Upgrade 3.12.5 -> 3.12.6 wpa-supplicant: Ignore CVE-2024-5290 wpa-supplicant: Patch CVE-2024-3596 wpa-supplicant: Patch security advisory 2024-2 rust: ignore CVE-2024-43402 openssl: patch CVE-2024-9143 cve-check: add support for cvss v4.0 go: upgrade 1.22.6 -> 1.22.7 go: upgrade 1.22.7 -> 1.22.8 dropbear: backport patch for CVE-2023-48795 curl: patch CVE-2024-9681 gstreamer1.0: set status for CVE-2024-0444 expat: upgrade 2.6.3 -> 2.6.4 builder: set CVE_PRODUCT qemu: set CVE-2024-6505 to fixed gstreamer1.0-plugins-good: fix several CVEs gstreamer1.0-plugins-base: patch CVE-2024-47538 gstreamer1.0-plugins-base: patch CVE-2024-47607 gstreamer1.0-plugins-base: patch CVE-2024-47615 gstreamer1.0-plugins-good: patch CVE-2024-47613 gstreamer1.0-plugins-good: patch several CVEs gstreamer1.0-plugins-base: patch CVE-2024-47541 gstreamer1.0-plugins-base: patch CVE-2024-47542 gstreamer1.0-plugins-good: patch CVE-2024-47599 gstreamer1.0-plugins-base: patch CVE-2024-47600 gstreamer1.0-plugins-good: patch CVE-2024-47606 gstreamer1.0-plugins-good: patch CVE-2024-47606 gstreamer1.0-plugins-good: patch CVE-2024-47774 gstreamer1.0-plugins-good: patch several CVEs gstreamer1.0-plugins-base: patch CVE-2024-47835 gstreamer1.0: ignore CVEs fixed in plugins recipes socat: patch CVE-2024-54661 ofono: patch CVE-2024-7540, CVE-2024-7541, CVE-2024-7542 ofono: patch CVE-2023-4232 ofono: patch CVE-2023-4235 openssl: patch CVE-2024-13176 go: upgrade 1.22.8 -> 1.22.9 go: upgrade 1.22.9 -> 1.22.10 go: upgrade 1.22.10 -> 1.22.11 glibc: stable 2.39 branch updates python3: upgrade 3.12.8 -> 3.12.9 go: upgrade 1.22.11 -> 1.22.12 cmake: apply parallel build settings to ptest tasks subversion: ignore CVE-2024-45720 gnutls: patch CVE-2024-12243 openssl: upgrade 3.2.3 -> 3.2.4 libxml2: upgrade 2.12.9 -> 2.12.10 grub: drop obsolete CVE statuses grub: backport strlcpy function grup: patch CVE-2024-45781 grub: patch CVE-2024-45782 and CVE-2024-56737 grub: patch CVE-2024-45780 grub: patch CVE-2024-45783 grub: patch CVE-2025-0624 grub: patch CVE-2024-45774 grub: patch CVE-2024-45775 grub: patch CVE-2025-0622 grub: patch CVE-2024-45776 grub: patch CVE-2024-45777 grub: patch CVE-2025-0690 grub: patch CVE-2025-1118 grub: patch CVE-2024-45778 and CVE-2024-45779 grub: patch CVE-2025-0677, CVE-2025-0684, CVE-2025-0685, CVE-2025-0686 and CVE-2025-0689 grub: patch CVE-2025-0678 and CVE-2025-1125 libarchive: patch CVE-2025-1632 and CVE-2025-25724 xserver-xorg: mark CVEs fixed in 21.1.16 as fixed cve-update-nvd2-native: handle missing vulnStatus expat: patch CVE-2024-8176 freetype: follow-up patch for CVE-2025-27363 ofono: patch CVE-2024-7537 cve-update-nvd2-native: add workaround for json5 style list xz: upgrade 5.4.6 -> 5.4.7 xz: patch CVE-2025-31115 libarchive: upgrade 3.7.4 -> 3.7.9 sqlite3: patch CVE-2025-3277 sqlite3: patch CVE-2025-29088 ppp: patch CVE-2024-58250 libxml2: patch CVE-2025-32414 libxml2: patch CVE-2025-32415 glib-2.0: patch CVE-2025-3360 Revert "cve-update-nvd2-native: Tweak to work better with NFS DL_DIR" sqlite3: mark CVE-2025-29087 as patched python3: upgrade 3.12.9 -> 3.12.11 testimage: get real os-release file net-tools: patch CVE-2025-46836 go: set status of CVE-2024-3566 glibc: stable 2.39 branch updates python3: update CVE product busybox: apply patch for CVE-2023-39810 iputils: patch CVE-2025-48964 orc: set CVE_PRODUCT openssl: CVE-2024-41996 openssl: patch CVE-2025-27587 gnutls: patch CVE-2025-32989 gnutls: patch read buffer overrun in the "pre_shared_key" extension gnutls: patch reject zero-length version in certificate request gnutls: patch CVE-2025-32988 gnutls: patch CVE-2025-32990 gnutls: patch CVE-2025-6395 ncurses: patch CVE-2025-6141 libxml2: patch CVE-2025-6170 glibc: fix CVE-2025-8058 python3: patch CVE-2025-8194 go: ignore CVE-2025-0913 dropbear: patch CVE-2025-47203 glib-2.0: ignore CVE-2025-4056 qemu: set status of CVE-2024-7730 to fixed go-binary-native: ignore CVE-2025-0913 glib-2.0: patch CVE-2025-7039 glib-2.0: patch CVE-2025-6052 dpkg: patch CVE-2025-6297 libarchive: patch regression of patch for CVE-2025-5918 vim: upgrade 9.1.1198 -> 9.1.1652 sudo: remove devtool FIXME comment busybox: patch CVE-2025-46394 gstreamer1.0: ignore CVEs fixed in plugins gstreamer1.0: ignore CVE-2025-2759 ghostscript: patch CVE-2025-59798 ghostscript: patch CVE-2025-59799 ghostscript: patch CVE-2025-59800 expat: follow-up for CVE-2024-8176 tiff: ignore 5 CVEs ffmpeg: ignore 8 CVEs fixed in 6.1.1 and 6.1.3 releases openssl: upgrade 3.2.4 -> 3.2.6 qemu: patch CVE-2024-8354 binutils: patch CVE-2025-11082 binutils: patch CVE-2025-11083 gnupg: mark CVE-2025-30258 as patched python3: upgrade 3.12.11 -> 3.12.12 vulnerabilities: update nvdcve file name expat: patch CVE-2025-59375 Philip Lorenz (3): cmake: Fix sporadic issues when determining compiler internals cve-check: Add missing call to exit_if_errors shared-mime-info: Handle USE_NLS Poonam Jadhav (2): curl: ignore CVE-2025-0725 libpng: Add ptest Praveen Kumar (7): connman :fix CVE-2025-32743 connman :fix CVE-2025-32366 glib-2.0: fix CVE-2025-4373 go: fix CVE-2025-4673 sudo: upgrade 1.9.15p5 -> 1.9.17p1 go: fix CVE-2025-47907 bind: upgrade 9.18.33 -> 9.18.41 Preeti Sachan (1): ltp: backport patch to fix compilation error for x86_64 Priyal Doshi (2): tzdata/tzcode-native: upgrade 2024b -> 2025a tzdata/tzcode-native: upgrade 2025a -> 2025b Purushottam Choudhary (1): virglrenderer: Add patch to fix -int-conversion build issue Quentin Schulz (14): mmc-utils: fix URL weston-init: fix weston not starting when xwayland is enabled docs: README: specify how to contribute instead of pointing at another file docs: conf.py: silence SyntaxWarning on js_splitter_code ref-manual: classes: reword to clarify that native/nativesdk options are exclusive ref-manual: classes: nativesdk: move note to appropriate section go-helloworld: fix license contributor-guide: submit-changes: fix improper bold string contributor-guide: submit-changes: clarify example with Yocto bug ID contributor-guide: submit-changes: align CC tag description contributor-guide: submit-changes: make the Cc tag follow kernel guidelines contributor-guide: submit-changes: reword commit message instructions contributor-guide: submit-changes: number instruction list in commit your changes contributor-guide: submit-changes: make "Crediting contributors" part of "Commit your changes" Rajeshkumar Ramasamy (2): glib-networking: fix CVE-2025-60018 glib-networking: fix CVE-2025-60019 Randy MacLeod (1): systemd: stable update 255.4 -> 255.13 Ranjitsinh Rathod (1): rust: Add new varaible RUST_ENABLE_EXTRA_TOOLS Rasmus Villemoes (1): iptables: remove /etc/ethertypes Regis Dargent (1): udev-extraconf: fix network.sh script did not configure hotplugged interfaces Richard Purdie (60): selftest/cases/runtime_test: Exclude centos-9 from virgl tests cve-exclusion: Drop the version comparision/warning bitbake: codeparser/data: Ensure module function contents changing is accounted for bitbake: codeparser: Skip non-local functions for module dependencies pseudo: Update to pull in python 3.12+ fix layer.conf: Add os-release to SIGGEN_EXCLUDERECIPES_ABISAFE oeqa/sdk/case: Ensure DL_DIR is populated with artefacts if used create-spdx-3.0/populate_sdk_base: Add SDK_CLASSES inherit mechanism to fix tarball SPDX manifests pseudo: Fix to work with glibc 2.40 pseudo: Update to include open symlink handling bugfix nasm: Upgrade 2.16.01 -> 2.16.03 oeqa/runtime/ssh: In case of failure, show exit code and handle -15 (SIGTERM) oeqa/selftest/reproducibile: Explicitly list virtual targets expat: 2.6.2 -> 2.6.3 ruby: Make docs generation deterministic libedit: Make docs generation deterministic buildhistory: Simplify intercept call sites and drop SSTATEPOSTINSTFUNC usage scripts/install-buildtools: Update to 5.0.3 bitbake.conf: Add truncate to HOSTTOOLS license: Fix directory layout issues libsdl2: Fix non-deterministic configure option for libsamplerate bitbake: tests/fetch: Use our own mirror of sysprof to decouple from gnome gitlab bitbake: tests/fetch: Use our own mirror of mobile-broadband-provider to decouple from gnome gitlab cve_check: Use a local copy of the database during builds pseudo: Fix envp bug and add posix_spawn wrapper oeqa/runtime/ssh: Rework ssh timeout oeqa/runtime/ssh: Fix incorrect timeout fix qemurunner: Clean up serial_lock handling bitbake: fetch2/git: Use quote from shlex, not pipes bitbake: fetch/wget: Increase timeout to 100s from 30s bitbake: runqueue: Fix performance of multiconfigs with large overlap bitbake: runqueue: Optimise setscene loop processing bitbake: runqueue: Fix scenetask processing performance issue do_package/sstate/sstatesig: Change timestamp clamping to hash output only selftest/reproducible: Drop rawlogs selftest/reproducible: Clean up pathnames resulttool: Allow store to filter to specific revisions resulttool: Use single space indentation in json output oeqa/utils/gitarchive: Return tag name and improve exclude handling resulttool: Fix passthrough of --all files in store mode resulttool: Add --logfile-archive option to store mode resulttool: Handle ltp rawlogs as well as ptest resulttool: Clean up repoducible build logs resulttool: Trim the precision of duration information resulttool: Improve repo layout for oeselftest results cve-update-nvd2-native: Tweak to work better with NFS DL_DIR bitbake: tests/fetch: Fix git shallow test failure with git >= 2.48 bitbake: utils: Print information about lock issue before exiting bitbake: utils: Tweak lock_timeout logic bitbake: utils: Add signal blocking for lock_timeout bitbake: event/utils: Avoid deadlock from lock_timeout() and recursive events bitbake: toaster/tests/buildtest: Switch to new CDN bitbake: fetch2: Avoid deprecation warning sstatetests: Switch to new CDN local.conf.sample: Switch to new CDN bitbake: ast: Change deferred inherits to happen per recipe brief-yoctoprojectqs/ref-manual: Switch to new CDN bitbake: test/fetch: Switch u-boot based test to use our own mirror mtools: upgrade 4.0.46 -> 4.0.47 bitbake: utils: Optimise signal/sigmask performance Robert Kovacsics (1): sdk: Fix path length limit to match reserved size Robert P. J. Day (7): Clean up explanation of minimum required version numbers overview-manual: small number of pedantic cleanups bsp guide: update kernel version example to 6.12 bsp-guide: update lonely "4.12" kernel reference to "6.12" bsp-guide: update all of section 1.8.2 to reflect current beaglebone conf file variables.rst: remove references to obsolete tar packaging overview-manual/yp-intro.rst: update on-target packaging info Robert Yang (7): bitbake: data_smart: Improve performance for VariableHistory release-notes-5.0.rst: NO_OUTPUT -> NO_COLOR bitbake: gitsm: Add call_process_submodules() to remove duplicated code bitbake: gitsm: Remove downloads/tmpdir when failed cml1.bbclass: do_diffconfig: Don't override .config with .config.orig libgcrypt: Fix building error with '-O2' in sysroot path groff: Fix race issues for parallel build Rogerio Guerra Borin (1): u-boot: ensure keys are generated before assembling U-Boot FIT image Rohini Sangam (1): vim: Upgrade 9.1.0698 -> 9.1.0764 Roland Kovacs (3): gnupg: update 2.4.5 -> 2.4.8 libxml2: fix CVE-2025-49795 sqlite3: fix CVE-2025-6965 Ross Burton (31): cpio: mark CVE-2023-7216 as disputed fribidi: upgrade 1.0.13 -> 1.0.14 gstreamer1.0: skip another known flaky test libportal: fix rare build race meson: don't use deprecated pkgconfig variable curl: skip FTP tests in run-ptest gawk: update patch status python3-pycryptodome(x): use python_setuptools_build_meta build class gstreamer1.0: disable flaky baseparser tests librsvg: don't try to run target code at build time icu: update patch Upstream-Status strace: download release tarballs from GitHub tcl: skip io-13.6 test case groff: fix rare build race in hdtbl sanity: check for working user namespaces python3: add dependency on -compression to -core classes/nativesdk: also override TUNE_PKGARCH classes/qemu: use tune to select QEMU_EXTRAOPTIONS, not package architecture oeqa/selftest/rust: skip on all MIPS platforms Remove all mention of core-image-lsb ref-manual: don't refer to poky-lsb ref-manual: remove OE_IMPORTS puzzles: ignore three new CVEs for a different puzzles xserver-xf86-config: add a configuration fragment to disable screen blanking xserver-xf86-config: remove obsolete configuration files grub2: fix CVE-2024-56738 libxslt: apply patch for CVE-2025-7424 expect: update code for Tcl channel implementation expect: don't run aclocal in do_configure expect: cleanup do_install pulseaudio: ignore CVE-2024-11586 Ryan Eatmon (2): u-boot.inc: Refactor do_* steps into functions that can be overridden uboot: Allow for customizing installed/deployed file names Sana Kazi (1): gcc-cross-canadian.inc: Fix buildpaths error for pthread.h Sandeep Gundlupet Raju (1): tune-cortexr52: Remove aarch64 for ARM Cortex-R52 Saravanan (2): python3-xmltodict: fix CVE-2025-9375 cmake: fix CVE-2025-9301 Savvas Etairidis (1): systemd: Rename systemd_v255.21 to systemd_255.21 Sergei Zhmylev (1): lsb-release: fix Distro Codename shell escaping Shubham Kulkarni (1): libpam: Update fix for CVE-2024-10041 Shunsuke Tokumoto (1): python3-setuptools: Add "python:setuptools" to CVE_PRODUCT Siddharth Doshi (5): Tiff: Security fix for CVE-2024-7006 vim: Upgrade 9.1.0114 -> 9.1.0682 wpa-supplicant: Upgrade 2.10 -> 2.11 vim: Upgrade 9.1.0682 -> 9.1.0698 openssl: Upgrade 3.2.2 -> 3.2.3 Simon A. Eugster (1): documentation: Fix typo in standards.md Simone Weiß (3): tzdata: Add tzdata.zi to tzdata-core package sanity: Check if tar is gnutar curl: Ignore CVE-2024-32928 Soumya Sambu (12): python3-idna: upgrade 3.6 -> 3.7 python3-certifi: Fix CVE-2024-39689 python3-setuptools: Fix CVE-2024-6345 python3: Fix CVE-2024-7592 python3: Fix CVE-2024-8088 python3-requests: upgrade 2.32.1 -> 2.32.2 python3-requests: upgrade 2.32.0 -> 2.32.3 python3-jinja2: upgrade 3.1.4 -> 3.1.6 git: Upgrade 2.44.1 -> 2.44.3 elfutils: Fix CVE-2025-1371 elfutils: Fix CVE-2025-1376 elfutils: Fix CVE-2025-1377 Stanislav Vovk (1): libpam: fix CVE-2024-10963 Stefan Mueller-Klieser (1): kernel-arch: add macro-prefix-map in KERNEL_CC Steve Sakoman (35): Revert "apt: runtime error: filename too long (tmpdir length)" poky.conf: bump version for 5.0.3 build-appliance-image: Update to scarthgap head revision Revert "wpa-supplicant: Upgrade 2.10 -> 2.11" poky.conf: bump version for 5.0.4 build-appliance-image: Update to scarthgap head revision build-appliance-image: Update to scarthgap head revision release-notes-4.0: update BB_HASHSERVE_UPSTREAM for new infrastructure poky.conf: bump version for 5.0.5 build-appliance-image: Update to scarthgap head revision webkitgtk: fix erroneous use of unsuported DEBUG_LEVELFLAG variable llvm: reduce size of -dbg package poky.conf: bump version for 5.0.6 build-appliance-image: Update to scarthgap head revision poky.conf: bump version for 5.0.7 build-appliance-image: Update to scarthgap head revision Revert "rust: Add new varaible RUST_ENABLE_EXTRA_TOOLS" build-appliance-image: Update to scarthgap head revision poky.conf: add ubuntu2404 to SANITY_TESTED_DISTROS poky.conf: bump version for 5.0.8 build-appliance-image: Update to scarthgap head revision Revert "gcc-cross-canadian.inc: Fix buildpaths error for pthread.h" poky.conf: bump version for 5.0.9 build-appliance-image: Update to scarthgap head revision poky.conf: bump version for 5.0.10 build-appliance-image: Update to scarthgap head revision poky.conf: bump version for 5.0.11 build-appliance-image: Update to scarthgap head revision Revert "sudo: Fix CVE-2025-32462" poky.conf: bump version for 5.0.12 build-appliance-image: Update to scarthgap head revision selftest/cases/meta_ide.py: use use gnu mirror instead of main server oeqa/sdk/cases/buildcpio.py: use gnu mirror instead of main server poky.conf: bump version for 5.0.13 build-appliance-image: Update to scarthgap head revision Sunil Dora (2): gcc: Fix c++: tweak for Wrange-loop-construct binutils: Fix CVE-2025-1153 Talel BELHAJ SALEM (1): dev-manual/building.rst: add note about externalsrc variables absolute paths Talel BELHAJSALEM (1): contributor-guide: Remove duplicated words Teresa Remmet (1): recipes-bsp: usbutils: Fix usb-devices command using busybox Trevor Gamblin (7): python3: skip test_concurrent_futures/test_deadlock python3: skip test_multiprocessing/test_active_children test maintainers.inc: add self for unassigned python recipes python3: upgrade 3.12.4 -> 3.12.5 python3: skip readline limited history tests python3-urllib3: upgrade 2.2.1 -> 2.2.2 reproducible-builds.rst: show how to build a single package Trevor Woerner (5): contributor-guide/submit-changes: encourage patch version changelogs ref-manual/variables.rst: document WIC_CREATE_EXTRA_ARGS sphinx-lint: trailing whitespace sphinx-lint: missing space after literal sphinx-lint: unbalanced inline literal markup Ulrich Ölmann (1): initramfs-framework: fix typos Victor Giraud (1): busybox: fix CVE-2022-48174 Victor Kamensky (1): systemtap: fix systemtap-native build error on Fedora 40 Vijay Anusuri (44): openssh: fix CVE-2024-39894 apr: upgrade 1.7.4 -> 1.7.5 libpcap: Security fix for CVE-2023-7256 & CVE-2024-8006 xserver-xorg: upgrade 21.1.13 -> 21.1.14 glib-2.0: Backport fix for CVE-2024-52533 bind: Upgrade 9.18.28 -> 9.18.33 openssh: Fix CVE-2025-26466 xwayland: Fix CVE-2024-9632 xwayland: Fix CVE-2025-26594 xwayland: Fix CVE-2025-26595 xwayland: Fix CVE-2025-26596 xwayland: Fix CVE-2025-26597 xwayland: Fix CVE-2025-26598 xwayland: Fix CVE-2025-26599 xwayland: Fix CVE-2025-26600 xwayland: Fix CVE-2025-26601 libtasn1: upgrade 4.19.0 -> 4.20.0 xserver-xorg: upgrade 21.1.15 -> 21.1.16 libxslt: upgrade 1.1.39 -> 1.1.43 vim: Upgrade 9.1.1115 -> 9.1.1198 libsoup: Fix CVE-2025-32910 libsoup: Fix CVE-2025-32909 libsoup: Fix CVE-2025-32911 & CVE-2025-32913 libsoup: Fix CVE-2025-32912 libsoup: Fix CVE-2025-32906 libsoup-2.4: Fix CVE-2024-52530 libsoup-2.4: Fix CVE-2024-52531 libsoup-2.4: Fix CVE-2024-52532 libsoup-2.4: Fix CVE-2025-32906 libsoup-2.4: Fix CVE-2025-32909 libsoup: Fix CVE-2025-32914 openssh: Fix for CVE-2025-32728 libsoup-2.4: Fix CVE-2025-32910 libsoup-2.4: Fix CVE-2025-32911 & CVE-2025-32913 libsoup-2.4: Fix CVE-2025-32912 libsoup-2.4: Fix CVE-2025-32914 python3-setuptools: Fix CVE-2025-47273 kea: upgrade 2.4.1 -> 2.4.2 sudo: Fix CVE-2025-32462 git: Upgrade 2.44.3 -> 2.44.4 xserver-xorg: upgrade 21.1.6 -> 21.1.18 cups: upgrade 2.4.10 -> 2.4.11 cups: Fix for CVE-2025-58060 and CVE-2025-58364 gstreamer1.0-plugins-bad: Fix CVE-2025-3887 Virendra Thakur (3): rust-cross-canadian: Set CVE_STATUS ignore for CVE-2024-43402 util-linux: Add fix to isolate test fstab entries using CUSTOM_FSTAB curl: set conditional CVE_STATUS for CVE-2025-5025 Vishwas Udupa (1): openssl: rewrite ptest installation Vrushti Dabhi (1): curl: update CVE_STATUS for CVE-2025-5025 Vyacheslav Yurkov (1): systemd: Password agents shouldn't be optional Wadim Egorov (1): watchdog: Set watchdog_module in default config Wang Mingyu (18): ed: upgrade 1.20.1 -> 1.20.2 llvm: upgrade 18.1.5 -> 18.1.6 mesa: upgrade 24.0.5 -> 24.0.7 wireless-regdb: upgrade 2024.01.23 -> 2024.05.08 orc: upgrade 0.4.38 -> 0.4.39 cups: upgrade 2.4.9 -> 2.4.10 libadwaita: upgrade 1.5.1 -> 1.5.2 libdnf: upgrade 0.73.1 -> 0.73.2 wireless-regdb: upgrade 2024.05.08 -> 2024.07.04 cryptodev: upgrade 1.13 -> 1.14 orc: upgrade 0.4.39 -> 0.4.40 wireless-regdb: upgrade 2024.07.04 -> 2024.10.07 gnupg: upgrade 2.4.4 -> 2.4.5 xserver-xorg: upgrade 21.1.14 -> 21.1.15 ghostscript: upgrade 10.05.0 -> 10.05.1 mtools: upgrade 4.0.44 -> 4.0.45 mtools: upgrade 4.0.45 -> 4.0.46 mtools: upgrade 4.0.47 -> 4.0.48 Weisser, Pascal (1): ref-manual: Add missing variable IMAGE_ROOTFS_MAXSIZE Weisser, Pascal.ext (1): qemuboot: Trigger write_qemuboot_conf task on changes of kernel image realpath Xiangyu Chen (2): qemu: Upgrade 8.2.1 -> 8.2.2 lttng-modules: fix sched_stat_runtime changed in Linux 6.6.66 Yash Shinde (4): binutils: Fix CVE-2024-53589 binutils: Fix CVE-2025-7546 binutils: fix CVE-2025-11081 binutils: fix CVE-2025-8225 Yi Zhao (5): libcap-ng: upgrade 0.8.4 -> 0.8.5 libcap-ng-python: upgrade 0.8.4 -> 0.8.5 rpm: fix expansion of %_libdir in macros iputils: Security fix for CVE-2025-47268 kea: set correct permissions for /var/run/kea Yogita Urade (10): qemu: upgrade 8.2.2 -> 8.2.3 qemu: fix CVE-2024-4467 ruby: upgrade 3.2.2 -> 3.3.5 qemu: upgrade 8.2.3 -> 8.2.7 curl: fix CVE-2024-11053 curl: fix CVE-2025-0167 python3-urllib3: fix CVE-2025-50181 curl: fix CVE-2025-9086 tiff: fix CVE-2025-9900 tiff: ignore CVE-2025-8961 Zhang Peng (3): avahi: fix CVE-2024-52616 mpg123: upgrade 1.32.6 -> 1.32.10 avahi: fix CVE-2024-52615 aszh07 (3): xz: Update LICENSE variable for xz packages ffmpeg: Add "libswresample libavcodec" to CVE_PRODUCT libarchive: Fix CVE-2024-20696 rajmohan r (1): glibc-y2038-tests: remove glibc-y2038-tests_2.39.bb recipe meta-openembedded: 78a14731cf..15e18246dd: Adrian Freihofer (2): networkmanager: remove modemmanager rdepends thrift: fix build with gcc 15 Alexandre Truong (4): source-han-sans-*-fonts: Switch away from SVN fetcher in SRC_URI lcov: include UPSTREAM_CHECK_* to fix UNKNOWN_BROKEN status hunspell-dictionaries: switch branch from master to main evince: Update status for CVE-2011-0433 and CVE-2011-5244 Alexandre Videgrain (1): openbox: fix crash on alt+tab with fullscreen app AmateurECE (1): pipewire: Add glib-2.0-native dep for bluez5 Andrej Valek (1): externalsrc: fix support in various components Anil Dongare (1): libssh 0.10.6: Fix CVE-2025-8114 Ankur Tyagi (25): tinyproxy: patch CVE-2023-49606 frr: patch CVE-2024-44070 libavif: ignore CVE-2025-48175 libconfuse: patch CVE-2022-40320 hdf5: patch CVE-2025-2913 hdf5: patch CVE-2025-2914 hdf5: patch CVE-2025-2915 hdf5: patch CVE-2025-2923, CVE-2025-6816, CVE-2025-6856 hdf5: patch CVE-2025-2924 hdf5: patch CVE-2025-2925 hdf5: patch CVE-2025-6269, CVE-2025-6270, CVE-2025-6516 libppd: patch CVE-2024-47175 libcupsfilters: patch CVE-2024-47076 libraw: patch CVE-2025-43961 CVE-2025-43962 libraw: patch CVE-2025-43963 libraw: patch CVE-2025-43964 zlog: fix CVE-2024-22857 memcached: patch CVE-2023-46852 memcached: patch CVE-2023-46853 ndpi: ignore CVE-2025-25066 libiec61850: patch CVE-2024-26529 libiec61850: patch CVE-2024-45970 libiec61850: patch CVE-2024-45971 mbedtls: upgrade 3.6.4 -> 3.6.5 hostapd: patch CVE-2025-24912 Archana Polampalli (4): modejs: upgrade 20.18.0 -> 20.18.2 tftpy: fix CVE-2023-46566 tcpreplay: fix CVE-2024-22654 apache2: upgrade 2.4.64 - 2.4.65 Ariel D'Alessandro (1): pipewire: Install missing ALSA config files Armin Kuster (1): Revert "mariadb: fix runtime failure on riscv" Ashish Sharma (2): nginx: Backport fix for CVE-2024-7347 postgresql: Backport fix for CVE-2024-7348 AshishKumar Mishra (1): meta-oe: image: optionally remove RAW image after sparse image creation Awais Belal (2): mongodb: fix build with python 3.12 mongodb: update to 4.4.29 BINDU (1): flatbuffers: adapt for cross-compilation environments Barry Grussling (1): postgresql: Break perl RDEPENDS Bastian Krause (2): libsocketcan: use https instead of git protocol canutils: use https instead of git protocol Benjamin Szőke (1): tree: fix broken links Changqing Li (11): pavucontrol: update SRC_URI libatasmart: Update SRC_URI mariadb: fix runtime failure on riscv dlt-daemon: make DLT_WatchdogSec configurable abseil-cpp: upgrade 20240116.2 -> 20240116.3 nginx: fix CVE-2025-23419 libblockdev: fix CVE-2025-6019 udisks2: Hardening measure of CVE-2025-6019 phpmyadmin: upgrade 5.2.1 -> 5.2.2 luajit: fix several CVEs mariadb: correct STACK_DIRECTION setting Chen Qi (6): libdbd-mysql-perl: avoid invoking assert_lib at do_configure stage python3-protobuf: remove useless and problematic .pth file graphviz: remove obsolete and problematic patch protobuf: fix CVE-2024-7254 protobuf: upgrade from 4.25.3 to 4.25.8 python3-protobuf: upgrade from 4.25.3 to 4.25.8 Chris Laplante (1): poco: fix branch: master => poco-1.12.5 Christos Gavros (1): corosync: reproducibility issue Claus Stovgaard (2): lcov: sort RDEPENDS alphabetical lcov: Add missing RDEPENDS Clayton Casciato (1): chrony: use inherit_defer for conditional inherit of useradd Deepak Rathore (1): protobuf 4.25.8: Mark CVE-2024-7254 as patched Divya Chellam (7): nginx: upgrade 1.25.3 -> 1.25.4 redis: upgrade 7.2.6 -> 7.2.7 krb5: fix CVE-2025-24528 openvpn: upgrade 2.6.12 -> 2.6.14 libssh: fix CVE-2025-4878 libssh: fix CVE-2025-5987 jq: fix CVE-2025-9403 Dmitry Baryshkov (1): android-tools: Create flag file /etc/usb-debugging-enabled Esben Haabendal (1): netplan: add missing runtime dependencies Etienne Cordonnier (3): uutils-coreutils: upgrade 0.0.25 -> 0.0.26 uutils-coreutils: upgrade 0.0.26 -> 0.0.27 uutils-coreutils: fix compilation with selinux Fabrice Aeschbacher (1): mosquitto: upgrade 2.0.18 -> 2.0.19 Fathi Boudra (2): python3-django: upgrade 4.2.11 -> 4.2.16 python3-django: upgrade 5.0.4 -> 5.0.9 Frank de Brabander (3): python3-pydantic-core: fix incompatible version python3-pydantic-core: fix TMPDIR path reference python3-pydantic-core: add missing RDEPENDS for ptest Grygorii Tertychnyi (1): libusbgx: fix gadget-stop install Guocai He (6): python3-pylint: correct the SRC_URI libconfig: correct the SRC_URI logcheck: correct the SRC_URI thrift: correct the SRC_URI softhsm: correct the SRC_URI mariadb: File conflicts for multilib Guðni Már Gilbert (1): mbedtls: upgrade 3.6.3.1 -> 3.6.4 Gyorgy Sarvari (35): poppler: fix typos in CVE-2025-52886-0001.patch mod-dnssd: update SRC_URI mosh: set working SRC_URI psqlodbc: set valid SRC_URI collectd: set working SRC_URI apache2: ignore irrelevant CVEs civetweb: patch CVE-2025-55763 dovecot: patch CVE-2022-30550 pm-qa: update git fetch protocol tokyocabinet: switch to working SRC_URI tokyocabinet: fix license iperf2: ignore irrelevant CVEs jasper: patch CVE-2025-8835 jasper: patch CVE-2025-8836 jasper: patch CVE-2025-8837 etcd: patch CVE-2023-32082 freerdp3: patch CVE-2024-32039 and CVE-2024-32041 freerdp3: patch CVE-2024-32040 freerdp3: patch CVE-2024-32458 freerdp3: patch CVE-2024-32459 freerdp3: patch CVE-2024-32460 freerdp3: patch CVE-2024-32658 freerdp3: patch CVE-2025-32659 freerdp3: patch CVE-2024-32660 freerdp3: patch CVE-2024-32661 freerdp3: patch CVE-2024-32662 exiv2: patch CVE-2025-26623 exiv2: patch CVE-2025-54080 exiv2: patch CVE-2025-55304 redis: upgrade 6.2.18 -> 6.2.20 emacs: patch CVE-2024-30202 emacs: patch CVE-2024-30203 emacs: patch CVE-2024-30204 emacs: patch CVE-2024-30205 emacs: patch CVE-2024-39331 Haixiao Yan (4): openvpn: fix CVE-2024-28882 openvpn: upgrade 2.6.10 -> 2.6.12 lmsensors: Clean stale files for sensord to avoid incorrect GCC header dependencies python3-posix-ipc: fix runtime error Harish Sadineni (1): bpftool: Add support for riscv64 Hieu Van Nguyen (1): gphoto2: Fix contains reference to TMPDIR [buildpaths] warning Hitendra Prajapati (8): tgt: fix CVE-2024-45751 libssh: fix CVE-2025-5318 redis: fix CVE-2025-32023 libssh: fix CVE-2025-5351 & CVE-2025-5372 open-vm-tools: fix CVE-2025-22247 libssh: fix CVE-2025-4877 openjpeg: fix for CVE-2025-54874 libjxl: fix CVE-2024-11403 & CVE-2024-11498 Hongxu Jia (1): nodejs: support cross compile without qemu user conditionally J. S (2): nodejs: upgrade 20.16.0 -> 20.17.0 nodejs: upgrade 20.17.0 -> 20.18.0 J. S. (3): znc: Fix buildpaths QA errors nodejs: cleanup xfce4 update HOMEPAGEs Jan Vermaete (1): python3-werkzeug: added python3-difflib as RDEPENDS Jason Schonberg (1): nodejs: upgrade 20.13.0 -> 20.16.0 Jef Driesen (2): nginx: fix the tarball and license checksums lcov: Add missing RDEPENDS for nativesdk Jeroen Hofstee (5): nodejs: backport a patch to prevent brotli crashing nodejs can-utils: fix printing / reading timestamps can-utils: handle CAN_ERR_CNT correctly php: ignore CVE-2024-3566 nodejs: ignore CVE-2024-3566 Jeroen Knoops (1): nng: Rename default branch of github.com:nanomsg/nng.git Jiaying Song (15): rrdtool: Fix do_populate_sysroot QA issues nftables: change ptest output format debootstrap: fix do_fetch error wireguard-tools: fix do_fetch error vlock: fix do_fetch error openipmi: upgrade 2.0.34->2.0.36 tcpreplay: fix CVE-2023-43279 xfce-dusk-gtk3: fix do_fetch error eject: fix do_fetch error libdev-checklib-perl: fix do_fetch error xmlsec1: Switch SRC_URI to use github release chrony: fix do_fetch error v4l-utils: Fix QA and build errors related to _TIME_BITS on 32-bit webkitgtk3: update 2.44.1 -> 2.44.3 webkitgtk3: fix do_configure error on beaglebone-yocto Jinfeng Wang (2): netplan: Fix CVE-2022-4968 postfix: fix rootfs file difference Justin Bronder (1): python3-xmodem: replace hardcoded /usr with ${prefix} Khem Raj (32): python3-pydantic-core: Fix build with python 3.12.4 log4cpp: Fix buildpaths QA error python3-pydantic: Upgrade to 2.7.3 mariadb: Upgrade to 10.11.9 release ndisc: Remove buildpaths from binaries ndisc6: Fix reproducible build ghex,gnome-chess,gnome-photos: Add missing dep on itstool-native nodejs: Upgrade to 20.13.0 release nodejs: Fix build with libc++ 19 wolfssl: Add packageconfig for reproducible build blueman: Fix buildpathe issue with cython generated code botan: Make it reproducible keepalived: Make build reproducible ldns: Fix buildpaths QA issues python3-kivy: Remove buildpaths from comments in generated C sources python3-pyproj: Fix buildpaths QA Error python3-pyproj: Remove absolute paths from cython generated .c files python3-pycocotools: Remove absolute paths from comments lprng: Specify target paths for needed utilities fwknop: Specify target locations of gpg and wget e2tools: Fix buildpaths QA warning in config.status in ptest sharutils: Let POSIX_SHELL be overridable from environment python3-posix-ipc: switch to PEP-517 build backend gtkwave: Add libtirpc to depends ssmping: Use debian mirror for SRC_URI enca: Fix cross builds ckermit: Define return type for main ckermit: Fix build with GCC-15 procmail: Fix build with GCC-14 uim: Stick to C17 freerdp: Upgrade 2.11.2 -> 2.11.7 influxdb: Do not remove non-existing files Leon Anavi (2): sip: Upgrade 6.8.3 -> 6.8.6 sip: Fix homepage and license Leonard Anderweit (1): lmsensors: Fix build without sensord Libo Chen (3): thin-provisioning-tools: install missed thin_shrink and era_repair grpc: Fix CVE-2024-7246 libgpiod: fix gpiod-cxx-test failed test case Marc Ferland (2): polkit: update SRC_URI libvncserver: fix generated LibVNCServerTargets.cmake Markus Volk (4): exiv2: update 0.28.0 -> 0.28.2 gnome-remote-desktop: update 46.1 -> 46.2 geary: add itstool-native dependency eog: add itstool-native dependency Martin Jansa (13): bolt: package systemd_system_unitdir correctly giflib: fix build with gold and avoid imagemagick-native dependency Revert "gcab: ignore buildpaths error from sources" gpm: fix buildpaths QA issue xerces-c: fix buildpaths QA issue xmlrpc-c: update SRCREV lapack: add PACKAGECONFIG for cblas lapack: fix buildpaths in ptest also when CBLAS is enabled gcab: fix buildpaths QA issue python3-posix-ipc: improve build_support python3-h5py: backport fixes for incompatible-pointer-types issues abseil-cpp: fix build with gcc-15 on host nodejs: fix build with gcc-15 on host Martin Schwan (1): linuxptp: Add systemd instance specifier for ptp4l dependency Michael Olbrich (1): nftables: avoid python dependencies when building without python Michael Opdenacker (1): kernel-hardening-checker: backport recipe Mikko Rapeli (3): fwupd: skip buildpaths errors gcab: ignore buildpaths error from sources libjcat: skip buildpaths check Mingli Yu (2): asio: Add ptest support ptest-packagelists-meta-oe.inc: Add asio Neel Gandhi (1): v4l-utils: Install media ctrl header and library files Nikhil R (2): nftables: Conditionally add ${PN}-python as RDEPENDS for ptest rocksdb: Add an option to set static library Niko Mauno (16): python3-xlsxwriter: Fix LICENSE python3-cbor2: Fix LICENSE and LIC_FILES_CHKSUM python3-crc32c: Amend LICENSE declaration python3-email-validator: Fix LICENSE python3-lru-dict: Fix LICENSE and change SUMMARY to DESCRIPTION python3-mock: Fix LICENSE python3-parse-type: Fix LICENSE python3-pillow: Fix LICENSE and change SUMMARY to DESCRIPTION python3-platformdirs: Fix LICENSE python3-colorama: Fix LICENSE python3-fann2: Fix LICENSE python3-nmap: Fix LICENSE and LIC_FILES_CHKSUM python3-pycurl: Fix LICENSE python3-googleapis-common-protos: Fix LIC_FILES_CHKSUM python3-haversine: Fix LIC_FILES_CHKSUM python3-libevdev: Fix LIC_FILES_CHKSUM Ninette Adhikari (6): imagemagick: Update status for CVE imagemagick: Update status for CVE imagemagick: Update status for CVE xsp: CVE status update for CVE-2006-2658 influxdb: Update CVE status for CVE-2019-10329 monkey: Update status for CVE-2013-2183 Peter Kjellerstedt (6): hostapd: Support running "devtool modify hostapd" hostapd: Only include the relevant parts from README in LIC_FILES_CHKSUM libjs-jquery-icheck: Correct LIC_FILES_CHKSUM libdevmapper: Inherit nopackages ebtables: Remove the dependecy on bash libeigen: Remove LGPL code Peter Marko (41): libndp: Patch CVE-2024-5564 squid: patch CVE-2024-37894 hostapd: Patch CVE-2024-3596 hostapd: Patch security advisory 2024-2 nss: patch CVE-2024-6602 nss: patch CVE-2024-6609 squid: conditionally set status of CVE-2024-45802 thrift: fix c++ generated code compilation with clang grpc: patch CVE-2024-11407 python3-grpcio: patch CVE-2024-11407 python3-grpcio(-tools): fix build concurrency issue libmodbus: patch CVE-2024-10918 libmodbus: ignore CVE-2023-26793 and CVE-2024-34244 libcoap: patch CVE-2024-31031 spdlog: patch CVE-2025-6140 minifi-cpp: patch spdlog CVE-2025-6140 poco: ignore additional failing tests poco: patch CVE-2025-6375 nginx: patch CVE-2025-53859 fontforge: patch CVE-2024-25081 and CVE-2024-25082 fcgi: patch CVE-2025-23016 procmail: patch CVE-2014-3618 procmail: patch CVE-2017-16844. ace: ignore CVE-2009-1147 audiofile: fix multiple CVEs audiofile: patch CVE-2017-6829 audiofile: fix multiple CVEs audiofile: patch CVE-2017-6831 audiofile: patch CVE-2017-6839 emlog: set CVE_PRODUCT freerdp: patch CVE-2024-32661 freerdp: mark CVE-2024-32662 as fixed freerdp3: set CVE_PRODUCT corosync: fix upstream version check corosync: upgrade 3.1.6 -> 3.1.9 corosync: patch CVE-2025-30472 dash: set CVE_PRODUCT gattlib: mark CVE-2019-6498 as fixed memcached: ignore disputed CVE-2022-26635 monkey: ignore CVE-2013-1771 squid: patch CVE-2025-59362 Poonam Jadhav (1): tcpreplay: Fix CVE-2023-4256 Praveen Kumar (4): php: upgrade 8.2.28 -> 8.2.29 polkit: fix CVE-2025-7519 yasm: fix CVE-2024-22653 cjson: upgrade 1.7.18 -> 1.7.19 Preeti Sachan (1): bpftool: fix libelf.h not found error Raghuvarya S (2): android-tools-adbd.service: Update ConditionPathExists to /etc android-toold-adbd: Fix inconsistency between selinux configurations Rajeshkumar Ramasamy (1): open-vm-tools: fix CVE-2025-41244 Randolph Sapp (2): opencl-clhpp: add native and nativesdk vulkan-cts: allow vulkan versions > 1.3 Randy MacLeod (1): python3-pyyaml-include: support native and nativesdk build Robert Yang (1): hostapd: Add CVE id to CVE-2024-3596_00.patch Roland Kovacs (2): jq-1.7.1: Backport multiple CVE fixes jq: add Upstream-Status and CVE tags into .patch files Ryan Eatmon (1): kernel-selftest: Update to allow for turning on all tests Sana Kazi (2): libp11: Treat all openssl-3.x releases the same imagemagick: guard sed operations in do_install for optional files Saravanan (2): udisks2: upgrade 2.10.1 -> 2.10.2 fio: fix CVE-2025-10823 Scott Murray (2): python3-grpcio: Fix build with gcc-14 python3-grpcio: backport abseil-cpp RISC-V fix Shubham Pushpkar (2): wireshark 4.2.7: Fix CVE-2024-9781 cjson 1.7.18: Fix CVE-2025-57052 Siddharth Doshi (2): apache2: Upgrade 2.4.59 -> 2.4.60 apache2: Upgrade 2.4.60 -> 2.4.62 Sofiane HAMAM (2): Wolfssl: add ptest wolfssl: Upgrade 5.7.0 -> 5.7.2 Soumya Sambu (14): python3-sqlparse: Fix CVE-2024-4340 python3-werkzeug: upgrade 3.0.1 -> 3.0.3 gtk+: Fix CVE-2024-6655 python3-twisted: Fix CVE-2024-41671 python3-flask-cors: Fix CVE-2024-6221 python3-werkzeug: upgrade 3.0.3 -> 3.0.6 python3-tornado: Upgrade 6.4 -> 6.4.2 python3-django: upgrade 4.2.16 -> 4.2.17 python3-django: upgrade 5.0.9 -> 5.0.10 python3-django: upgrade 5.0.10 -> 5.0.11 python3-django: upgrade 4.2.17 -> 4.2.18 php: Upgrade 8.2.26 -> 8.2.28 iniparser: Fix CVE-2025-0633 python3-django: upgrade 4.2.18 -> 4.2.20 Sunil Dora (1): layer.conf: add bpftrace to NON_MULTILIB_RECIPES Swamil Jain (1): kmsxx: Revert to using original name for kmstest Thomas Roos (1): libcamera: backport 0.4.0 from master-next Tim Orling (1): python3-pydantic: upgrade 2.7.3 -> 2.7.4 Trevor Woerner (2): apache2: use update-alternatives for httpd iperf3: throughput fix Vijay Anusuri (16): krb5: upgrade 1.21.2 -> 1.21.3 wireshark: upgrade 4.2.4 -> 4.2.5 wireshark: upgrade 4.2.5 -> 4.2.7 php: upgrade 8.2.24 -> 8.2.26 openjpeg: upgrade 2.5.0 -> 2.5.3 postgresql: upgrade 16.5 -> 16.8 wireshark: upgrade 4.2.7 -> 4.2.9 proftpd: Fix CVE-2024-57392 redis: upgrade 7.2.7 -> 7.2.8 wireshark: upgrade 4.2.9 -> 4.2.12 proftpd: Fix CVE-2023-51713 apache2: Upgrade 2.4.62 -> 2.4.64 poppler: Fix CVE-2025-43718 redis: upgrade 7.2.8 -> 7.2.11 redis: upgrade 6.2.16 -> 6.2.18 vorbis-tools: Fix CVE-2023-43361 Virendra Thakur (2): opensc: Fix multiple cve CVE-2024-45615-45616-45617-45618-45619-45620 unbound: Fix CVE-2024-8508 Wang Mingyu (18): python3-email-validator: upgrade 2.1.0 -> 2.1.1 python3-pydantic: upgrade 2.7.0 -> 2.7.1 cjson: upgrade 1.7.17 -> 1.7.18 samba: upgrade 4.19.7 -> 4.19.8 postgresql: upgrade 16.3 -> 16.4 redis: upgrade 7.2.4 -> 7.2.5 mosquitto: upgrade 2.0.19 -> 2.0.20 uutils-coreutils: upgrade 0.0.27 -> 0.0.28 nana: Fix buildpaths warning. fetchmail: Fix buildpaths warning. fetchmail: disable rpath to fix buildpaths warning. python3-posix-ipc: upgrade 1.1.1 -> 1.2.0 mbedtls: upgrade 3.6.3 -> 3.6.3.1 geoip: fix do_fetch error rp-pppoe: update SRC_URI procmail: fix build failure with gcc-14 procmail: Add -Wno-implicit-int to fix error of do_compile libiec61850: upgrade 1.5.1 -> 1.5.3 Wentao Zhang (1): meta-oe/conf/layer.conf: remove libbpf from NON_MULTILIB_RECIPES for x86 and x86-64 Xiangyu Chen (1): crash: fix crash cannot work with kaslr Yi Zhao (12): samba: upgrade 4.19.6 -> 4.19.7 mbedtls: upgrade 3.6.0 -> 3.6.1 mbedtls: upgrade 2.28.8 -> 2.28.9 libldb: upgrade 2.8.0 -> 2.8.1 mbedtls: upgrade 3.6.1 -> 3.6.2 freeradius: upgrade 3.2.3 -> 3.2.5 hostapd: Security fix for CVE-2023-52160 redis: upgrade 7.2.5 -> 7.2.6 mbedtls: upgrade 2.28.9 -> 2.28.10 mbedtls: 3.6.2 -> 3.6.3 wxwidgets: upgrade 3.2.1 -> 3.2.6 redis: upgrade 6.2.14 -> 6.2.16 Yoann Congal (3): packagegroup-meta-oe: fix lvgl inclusion mdio-tools: fix mdio-netlink kernel module reproducibility gutenprint: fix a build race-condition Yogesh Tyagi (1): tbb-native: Fix build with gcc-13 Yogita Urade (18): graphviz: fix CVE-2023-46045 hdf5: upgrade to 1.14.4 poppler: CVE-2024-6239 krb5: fix CVE-2024-26458 and CVE-2024-26461 php: upgrade 8.2.20 -> 8.2.24 postgresql: upgrade 16.4 -> 16.5 poppler: fix CVE-2024-56378 poppler: fix CVE-2025-32364 poppler: fix CVE-2025-32365 poppler: fix CVE-2025-43903 syslog-ng: fix CVE-2024-47619 postgresql: upgrade 16.8 -> 16.9 mariadb: upgrade 10.11.9 -> 10.11.12 poppler: fix CVE-2025-52886 poppler: fix CVE-2025-50420 postgresql: upgrade 16.9 -> 16.10 indent: fix CVE-2023-40305 poppler: fix CVE-2025-52885 Zhang Peng (21): hiredis: remove ANSI color from ptest result frr: fix CVE-2024-34088 frr: fix CVE-2024-31950 frr: fix CVE-2024-31951 frr: fix CVE-2024-31948 frr: fix CVE-2024-31949 libgsf: upgrade 1.14.52 -> 1.14.53 glade: fix CVE-2020-36774 opensc: fix CVE-2024-8443 lapack: fix TMPDIR reference in do_package_qa iperf3: upgrade 3.16 -> 3.18 gnuplot: fix CVE-2025-3359 gnuplot: fix CVE-2025-31176 gnuplot: fix CVE-2025-31177 gnuplot: fix CVE-2025-31178 gnuplot: fix CVE-2025-31179 gnuplot: fix CVE-2025-31180 gnuplot: fix CVE-2025-31181 iperf3: fix CVE-2025-54349 iperf3: fix CVE-2025-54350 wxwidgets: fix CVE-2024-58249 Zoltán Böszörményi (1): gutenprint: 5.3.5 akash hadke (1): python3-flatbuffers: provide nativesdk support alperak (8): tayga: Fix contains reference to TMPDIR [buildpaths] warning etcd-cpp-apiv3: Fix contains reference to TMPDIR [buildpaths] warning exiv2: Upgrade 0.28.2 to 0.28.3 for CVE fix jsonrpc: Fix contains reference to TMPDIR [buildpaths] warning rdist: Fix contains reference to TMPDIR [buildpaths] warning perfetto: Fix contains reference to TMPDIR [buildpaths] warning hplip: Fix contains reference to TMPDIR [buildpaths] warning boinc-client: Fix contains reference to TMPDIR [buildpaths] warning gudnimar (1): pipewire: upgrade 1.0.5 -> 1.0.9 hongxu (2): p7zip: fix CVE-2023-52169 and CVE-2023-52168 indent: fix CVE-2024-0911 kjlau0112 (1): mbedtls: drop tag parameter from SRC_URI. mark.yang (1): srecord: fix build failure with gcc-15 meta-raspberrypi: 1918a27419..8767e2ff80: Adam Schafer (1): add raspi-utils recipe to scarthgap branch Andrei Gherzan (1): docs: Fix ReadTheDocs sphinx.configuration requirement Ayoub Zaki (1): raspberrypi5: add bcm2712d0 overlay required for booting up correctly Bassem Nomany (1): mesa: update to 24.3.1 Damiano Ferrari (2): rpi-eeprom: Update to latest release rpi-bootfiles: Update to latest release Florin Sarbu (1): linux-raspberrypi.inc: Change defconfig for RPi3 64 bits Garrett Brown (1): linux: Enable CONFIG_I2C_BRCMSTB for proper HDMI I2C support Gijs Peskens (1): raspberrypi5.conf: Add CM5 dtb's Jaeyoon Jung (1): linux-raspberrypi: Drop deprecated configs from android-driver.cfg Joshua Watt (1): linux-firmware-rpidistro: Fix WiFi on Raspberry Pi 5 Khem Raj (2): linux-raspberrypi-6.6: Upgrade to 6.6.63 rpi-base: Remove bcm2712-rpi-5-b.dtb from RPI_KERNEL_DEVICETREE target Leon Anavi (11): yocto-builder/Dockerfile: Ubuntu 22.04 rpi-base.inc: vc4-kms-dsi-ili9881-7inch.dtbo u-boot_%.bbappend: Increase CONFIG_SYS_BOOTM_LEN wayland-protocols: Upgrade 1.38 -> 1.45 mesa: Upgrade 24.3.1 -> 25.1.3 mesa: Upgrade 25.1.3 -> 25.1.6 mesa_%.bbappend: DISTRO_FEATURES for wayland mesa: wayland-protocols: Fix signatures linux-firmware-rpidistro: Update and stabilize rpi-base.inc: Add w1-gpio-pi5.dtbo rpi-base.inc: Add rpi-backlight.dtbo Markus Volk (4): linux-raspberrypi: add recipe for 6.12 linux-raspberrypi: update 6.12.2 -> 6.12.25 rpi-default-versions: Switch default kernel to 6.12 rpi-bootfiles: update to latest release Martin Jansa (3): docker-build: use --no-cache Revert "rpi-default-versions: Switch default kernel to 6.12" mesa, wayland-protocols: use separate recipe instead of bbappend Matthias Klein (1): linux-firmware-rpidistro: Upgrade to bookworm/20230625-2+rpt3 Omri Sarig (1): linux-firmware-rpidistro: Fix wireless error message on RPi Pierrick Curt (1): rpi-base: build uart dts overlays by default Thomas Roos (1): Moving bcm2712d0.dtbo into rpi-base.inc meta-arm: 58268ddccb..0f1e7bf92c: Amr Mohamed (5): kas: Update kas configuration for fvp-base.yml file arm-systemready/linux-distros: new inc file for unattended installation arm-systemready/linux-distros: Add kickstart file for Fedora unattended arm-systemready/oeqa: Add new test for Fedora unattended installation kas: Add new yml file for Distros unattended installation Ben (3): arm-systemready/linux-distros: Implement unattended openSUSE arm-systemready/oeqa: Add unattended installation testcase kas: Include unattended openSUSE test Bence Balogh (1): arm-bsp/trusted-firmware-m: corstone1000: Fix MPU configuration Harsimran Singh Tungal (1): arm-bsp,kas: corstone1000: enable External System based on new yml file Hugues KAMBA MPIANA (1): arm-bsp/documentation: corstone1000: Add SystemReady IR v2.0 certification Jon Mason (4): arm-toolchain: remove libmount-mountfd-support when using binary toolchain arm-bsp/fvp-base: Get 6.10 kernel working arm/linux-yocto: disable CONFIG_MTD_NAND_FSL_IFC arm-systemready/ir-acs: Update URL Jose Quaresma (1): bsp: optee-client: cleanup old tee-supplicant Luca Fancellu (2): arm/oeqa: Introduce retry mechanism for fvp_devices run_cmd arm/lib: Handle timeout for spawn object on stop() Romain Naour (4): external-arm-toolchain: remove old sed fixup for libc.so external-arm-toolchain: wrap symlink handling under usrmerge check external-arm-toolchain: override dynamic loader path with usrmerge enabled external-arm-toolchain: rebuild libmvec.so symlink if any Ross Burton (5): arm-base/linux-yocto: revert interim 6.10 patch for fvp-base arm-system-ready/arm-systemready-ir-acs: add version to download filename CI: use canonical git.yoctoproject.org URLs arm/execstack-native: add new recipe arm/fvp-base-a-aem: remove spurious executable stack from one library Vasyl Vavrychuk (3): external-arm-toolchain: wrap base_libdir vs libdir manipulations under usrmerge check external-arm-toolchain: in libc.so GNU ld script use base_libdir external-arm-toolchain: remove ${base_libdir}/libpthread*.so from FILES:${PN} meta-security: 11ea91192d..bc865c5276: Hitendra Prajapati (2): clamav: fix CVE-2024-20505 & CVE-2024-20506 libhtp: fix CVE-2024-45797 Vijay Anusuri (2): tpm2-tools: Upgrade 5.5 -> 5.7 tpm2-tss: upgrade 4.0.1 -> 4.0.2 Change-Id: Ief5b086436b2f3a4e819546fcd1bb9a5b1f608dd Signed-off-by: Andrew Geissler <geissonator@yahoo.com>
Diffstat (limited to 'meta-openembedded')
-rw-r--r--meta-openembedded/meta-filesystems/recipes-utils/e2tools/e2tools_git.bb2
-rw-r--r--meta-openembedded/meta-gnome/dynamic-layers/meta-security/recipes-gnome/gnome-remote-desktop/gnome-remote-desktop_46.2.bb (renamed from meta-openembedded/meta-gnome/dynamic-layers/meta-security/recipes-gnome/gnome-remote-desktop/gnome-remote-desktop_46.1.bb)16
-rw-r--r--meta-openembedded/meta-gnome/recipes-connectivity/geary/geary_44.1.bb1
-rw-r--r--meta-openembedded/meta-gnome/recipes-gnome/eog/eog_45.3.bb1
-rw-r--r--meta-openembedded/meta-gnome/recipes-gnome/evince/evince_46.0.bb4
-rw-r--r--meta-openembedded/meta-gnome/recipes-gnome/ghex/ghex_46.0.bb1
-rw-r--r--meta-openembedded/meta-gnome/recipes-gnome/gnome-chess/gnome-chess_46.0.bb2
-rw-r--r--meta-openembedded/meta-gnome/recipes-gnome/gnome-photos/gnome-photos_44.0.bb1
-rw-r--r--meta-openembedded/meta-gnome/recipes-gnome/libgsf/libgsf_1.14.53.bb (renamed from meta-openembedded/meta-gnome/recipes-gnome/libgsf/libgsf_1.14.52.bb)4
-rw-r--r--meta-openembedded/meta-multimedia/recipes-multimedia/libavif/libavif_1.0.1.bb2
-rw-r--r--meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera/0001-ipu3-Use-posix-basename.patch71
-rw-r--r--meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera/0001-rpi-Use-alloca-instead-of-variable-length-arrays.patch43
-rw-r--r--meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera/0002-options-Replace-use-of-VLAs-in-C.patch128
-rw-r--r--meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera_0.4.0.bb (renamed from meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera_0.2.0.bb)11
-rw-r--r--meta-openembedded/meta-multimedia/recipes-multimedia/pipewire/pipewire_1.0.9.bb (renamed from meta-openembedded/meta-multimedia/recipes-multimedia/pipewire/pipewire_1.0.5.bb)14
-rw-r--r--meta-openembedded/meta-multimedia/recipes-multimedia/vorbis-tools/vorbis-tools/CVE-2023-43361.patch57
-rw-r--r--meta-openembedded/meta-multimedia/recipes-multimedia/vorbis-tools/vorbis-tools_1.4.2.bb1
-rwxr-xr-xmeta-openembedded/meta-networking/conf/include/non-repro-meta-networking.inc2
-rw-r--r--meta-openembedded/meta-networking/conf/include/ptest-packagelists-meta-networking.inc1
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/blueman/blueman/0001-meson-DO-not-emit-absolute-path-when-S-B.patch38
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/blueman/blueman_2.3.5.bb1
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/civetweb/civetweb/0001-Fix-heap-overflow-in-directory-URI-slash-redirection.patch57
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/civetweb/civetweb_1.16.bb1
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/freeradius/freeradius_3.2.5.bb (renamed from meta-openembedded/meta-networking/recipes-connectivity/freeradius/freeradius_3.2.3.bb)2
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/libiec61850/files/CVE-2024-26529.patch33
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/libiec61850/files/CVE-2024-45970.patch74
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/libiec61850/files/CVE-2024-45971.patch218
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.5.3.bb (renamed from meta-openembedded/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.5.1.bb)5
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/mbedtls/mbedtls_2.28.10.bb (renamed from meta-openembedded/meta-networking/recipes-connectivity/mbedtls/mbedtls_2.28.8.bb)2
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/mbedtls/mbedtls_3.6.5.bb (renamed from meta-openembedded/meta-networking/recipes-connectivity/mbedtls/mbedtls_3.6.0.bb)13
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/mosquitto/files/1571.patch22
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/mosquitto/files/2894.patch25
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/mosquitto/mosquitto_2.0.20.bb (renamed from meta-openembedded/meta-networking/recipes-connectivity/mosquitto/mosquitto_2.0.18.bb)4
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/nanomsg/nng_1.7.3.bb2
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/networkmanager/networkmanager_1.46.0.bb2
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/rdist/rdist_6.1.5.bb2
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/samba/samba_4.19.8.bb (renamed from meta-openembedded/meta-networking/recipes-connectivity/samba/samba_4.19.6.bb)2
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/tayga/tayga_0.9.2.bb3
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/wolfssl/files/run-ptest24
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/wolfssl/wolfssl_5.7.0.bb22
-rw-r--r--meta-openembedded/meta-networking/recipes-connectivity/wolfssl/wolfssl_5.7.2.bb44
-rw-r--r--meta-openembedded/meta-networking/recipes-core/images/meta-networking-image-ptest.bb1
-rw-r--r--meta-openembedded/meta-networking/recipes-daemons/keepalived/keepalived/0001-configure.ac-Do-not-emit-compiler-flags-into-object-.patch29
-rw-r--r--meta-openembedded/meta-networking/recipes-daemons/keepalived/keepalived_2.2.8.bb5
-rw-r--r--meta-openembedded/meta-networking/recipes-daemons/postfix/files/0006-postfix-add-preliminary-setting.patch31
-rw-r--r--meta-openembedded/meta-networking/recipes-daemons/postfix/postfix_3.8.6.bb1
-rw-r--r--meta-openembedded/meta-networking/recipes-daemons/proftpd/files/CVE-2023-51713.patch278
-rw-r--r--meta-openembedded/meta-networking/recipes-daemons/proftpd/files/CVE-2024-57392.patch42
-rw-r--r--meta-openembedded/meta-networking/recipes-daemons/proftpd/proftpd_1.3.7c.bb2
-rw-r--r--meta-openembedded/meta-networking/recipes-daemons/squid/files/CVE-2024-37894.patch36
-rw-r--r--meta-openembedded/meta-networking/recipes-daemons/squid/files/CVE-2025-59362.patch52
-rw-r--r--meta-openembedded/meta-networking/recipes-daemons/squid/squid_6.9.bb8
-rw-r--r--meta-openembedded/meta-networking/recipes-devtools/libcoap/libcoap/CVE-2024-31031.patch82
-rw-r--r--meta-openembedded/meta-networking/recipes-devtools/libcoap/libcoap_4.3.4.bb1
-rw-r--r--meta-openembedded/meta-networking/recipes-extended/corosync/corosync/CVE-2025-30472.patch69
-rw-r--r--meta-openembedded/meta-networking/recipes-extended/corosync/corosync_3.1.9.bb (renamed from meta-openembedded/meta-networking/recipes-extended/corosync/corosync_3.1.6.bb)17
-rw-r--r--meta-openembedded/meta-networking/recipes-extended/tgt/files/CVE-2024-45751.patch71
-rw-r--r--meta-openembedded/meta-networking/recipes-extended/tgt/tgt_1.0.90.bb1
-rw-r--r--meta-openembedded/meta-networking/recipes-filter/ebtables/ebtables-2.0.11/ebtables-legacy-save19
-rw-r--r--meta-openembedded/meta-networking/recipes-filter/ebtables/ebtables_2.0.11.bb2
-rw-r--r--meta-openembedded/meta-networking/recipes-filter/nftables/nftables/run-ptest8
-rw-r--r--meta-openembedded/meta-networking/recipes-filter/nftables/nftables_1.0.9.bb9
-rw-r--r--meta-openembedded/meta-networking/recipes-irc/znc/znc_1.8.2.bb1
-rw-r--r--meta-openembedded/meta-networking/recipes-kernel/wireguard/wireguard-tools_1.0.20210914.bb2
-rw-r--r--meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-31948.patch130
-rw-r--r--meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-31949.patch163
-rw-r--r--meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-31950.patch68
-rw-r--r--meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-31951.patch110
-rw-r--r--meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-34088.patch83
-rw-r--r--meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-44070.patch54
-rw-r--r--meta-openembedded/meta-networking/recipes-protocols/frr/frr_9.1.bb6
-rw-r--r--meta-openembedded/meta-networking/recipes-protocols/net-snmp/net-snmp_5.9.4.bb3
-rw-r--r--meta-openembedded/meta-networking/recipes-protocols/rp-pppoe/rp-pppoe_3.15.bb2
-rw-r--r--meta-openembedded/meta-networking/recipes-support/chrony/chrony_4.5.bb4
-rw-r--r--meta-openembedded/meta-networking/recipes-support/dovecot/dovecot/0001-auth-Fix-handling-passdbs-with-identical-driver-args.patch137
-rw-r--r--meta-openembedded/meta-networking/recipes-support/dovecot/dovecot_2.3.21.bb1
-rw-r--r--meta-openembedded/meta-networking/recipes-support/fetchmail/fetchmail_6.4.38.bb2
-rw-r--r--meta-openembedded/meta-networking/recipes-support/fwknop/fwknop_2.6.10.bb4
-rw-r--r--meta-openembedded/meta-networking/recipes-support/geoip/geoip_1.6.12.bb8
-rwxr-xr-xmeta-openembedded/meta-networking/recipes-support/libconfuse/files/CVE-2022-40320.patch42
-rw-r--r--meta-openembedded/meta-networking/recipes-support/libconfuse/libconfuse_3.3.bb5
-rw-r--r--meta-openembedded/meta-networking/recipes-support/libldb/libldb_2.8.1.bb (renamed from meta-openembedded/meta-networking/recipes-support/libldb/libldb_2.8.0.bb)2
-rw-r--r--meta-openembedded/meta-networking/recipes-support/mdio-tools/mdio-netlink_1.3.1.bb5
-rw-r--r--meta-openembedded/meta-networking/recipes-support/memcached/memcached/CVE-2023-46852.patch71
-rw-r--r--meta-openembedded/meta-networking/recipes-support/memcached/memcached/CVE-2023-46853.patch117
-rw-r--r--meta-openembedded/meta-networking/recipes-support/memcached/memcached_1.6.17.bb4
-rw-r--r--meta-openembedded/meta-networking/recipes-support/ndisc6/ndisc6/0001-Remove-use-of-variables-indicating-buildtime-informa.patch85
-rw-r--r--meta-openembedded/meta-networking/recipes-support/ndisc6/ndisc6_1.0.8.bb5
-rw-r--r--meta-openembedded/meta-networking/recipes-support/ntopng/ndpi_4.2.bb2
-rw-r--r--meta-openembedded/meta-networking/recipes-support/open-vm-tools/open-vm-tools/CVE-2025-22247.patch378
-rw-r--r--meta-openembedded/meta-networking/recipes-support/open-vm-tools/open-vm-tools/CVE-2025-41244.patch123
-rw-r--r--meta-openembedded/meta-networking/recipes-support/open-vm-tools/open-vm-tools_12.3.5.bb2
-rw-r--r--meta-openembedded/meta-networking/recipes-support/openipmi/openipmi_2.0.36.bb (renamed from meta-openembedded/meta-networking/recipes-support/openipmi/openipmi_2.0.34.bb)2
-rw-r--r--meta-openembedded/meta-networking/recipes-support/openvpn/openvpn_2.6.14.bb (renamed from meta-openembedded/meta-networking/recipes-support/openvpn/openvpn_2.6.10.bb)2
-rw-r--r--meta-openembedded/meta-networking/recipes-support/ssmping/ssmping_0.9.1.bb3
-rw-r--r--meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay/CVE-2023-4256.patch27
-rw-r--r--meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay/CVE-2023-43279.patch39
-rw-r--r--meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay/CVE-2024-22654-0001.patch90
-rw-r--r--meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay/CVE-2024-22654-0002.patch35
-rw-r--r--meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay_4.4.4.bb4
-rw-r--r--meta-openembedded/meta-networking/recipes-support/tinyproxy/tinyproxy/0001-CVE-2023-49606.patch59
-rw-r--r--meta-openembedded/meta-networking/recipes-support/tinyproxy/tinyproxy_1.11.1.bb1
-rw-r--r--meta-openembedded/meta-networking/recipes-support/unbound/unbound/CVE-2024-8508.patch247
-rw-r--r--meta-openembedded/meta-networking/recipes-support/unbound/unbound_1.19.3.bb4
-rw-r--r--meta-openembedded/meta-networking/recipes-support/wireshark/wireshark_4.2.12.bb (renamed from meta-openembedded/meta-networking/recipes-support/wireshark/wireshark_4.2.4.bb)8
-rw-r--r--meta-openembedded/meta-oe/classes/image_types_sparse.bbclass6
-rw-r--r--meta-openembedded/meta-oe/conf/include/ptest-packagelists-meta-oe.inc1
-rw-r--r--meta-openembedded/meta-oe/conf/layer.conf5
-rw-r--r--meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-connectivity/netplan/netplan/CVE-2022-4968.patch452
-rw-r--r--meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-connectivity/netplan/netplan_1.0.bb2
-rw-r--r--meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-dbs/mongodb/mongodb/0001-free_mon-Include-missing-cstdint.patch28
-rw-r--r--meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-dbs/mongodb/mongodb/0001-moduleconfig.py-python-3.12-compatibility.patch57
-rw-r--r--meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-dbs/mongodb/mongodb_git.bb10
-rw-r--r--meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-multimedia/kmsxx/kmsxx_git.bb7
-rw-r--r--meta-openembedded/meta-oe/dynamic-layers/selinux/recipes-devtool/android-tools/android-tools/android-tools-adbd.service2
-rw-r--r--meta-openembedded/meta-oe/dynamic-layers/selinux/recipes-devtool/android-tools/android-tools_29.0.6.r14.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-benchmark/fio/fio/CVE-2025-10823.patch37
-rw-r--r--meta-openembedded/meta-oe/recipes-benchmark/fio/fio_3.36.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-benchmark/iperf2/iperf2_2.0.13.bb3
-rw-r--r--meta-openembedded/meta-oe/recipes-benchmark/iperf3/iperf3/CVE-2025-54349.patch97
-rw-r--r--meta-openembedded/meta-oe/recipes-benchmark/iperf3/iperf3/CVE-2025-54350.patch39
-rw-r--r--meta-openembedded/meta-oe/recipes-benchmark/iperf3/iperf3_3.18.bb (renamed from meta-openembedded/meta-oe/recipes-benchmark/iperf3/iperf3_3.16.bb)8
-rw-r--r--meta-openembedded/meta-oe/recipes-bsp/bolt/bolt_0.9.6.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-bsp/fwupd/fwupd_1.9.18.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-bsp/lm_sensors/lmsensors_3.6.0.bb10
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/ace/ace_6.5.19.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/gattlib/gattlib_git.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/0001-SAE-Check-for-invalid-Rejected-Groups-element-length.patch52
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/0003-SAE-Reject-invalid-Rejected-Groups-element-in-the-pa.patch38
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2023-52160.patch198
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_00.patch83
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_01.patch165
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_02.patch62
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_04.patch52
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_05.patch51
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_06.patch46
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_07.patch105
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_08.patch47
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2025-24912_01.patch80
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2025-24912_02.patch72
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd_2.10.bb28
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/krb5/krb5/CVE-2024-26458_CVE-2024-26461.patch207
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/krb5/krb5/CVE-2025-24528.patch68
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/krb5/krb5_1.21.3.bb (renamed from meta-openembedded/meta-oe/recipes-connectivity/krb5/krb5_1.21.2.bb)6
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/libndp/libndp/CVE-2024-5564.patch48
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/libndp/libndp_1.8.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/linuxptp/linuxptp/systemd/phc2sys@.service.in4
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/mosh/mosh_1.4.0.bb5
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/thrift/thrift/0001-THRIFT-5842-Add-missing-cstdint-include-for-int64_t-.patch51
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/thrift/thrift/0001-thrift-pr2755.patch599
-rw-r--r--meta-openembedded/meta-oe/recipes-connectivity/thrift/thrift_0.20.0.bb7
-rw-r--r--meta-openembedded/meta-oe/recipes-core/emlog/emlog.inc2
-rw-r--r--meta-openembedded/meta-oe/recipes-core/opencl/opencl-clhpp_git.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-core/packagegroups/packagegroup-meta-oe.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-core/uutils-coreutils/files/0001-Cargo.lock-revert-to-selinux-sys-0.6.9-and-fts-sys-0.patch178
-rw-r--r--meta-openembedded/meta-oe/recipes-core/uutils-coreutils/uutils-coreutils-crates.inc820
-rw-r--r--meta-openembedded/meta-oe/recipes-core/uutils-coreutils/uutils-coreutils_0.0.28.bb (renamed from meta-openembedded/meta-oe/recipes-core/uutils-coreutils/uutils-coreutils_0.0.25.bb)5
-rw-r--r--meta-openembedded/meta-oe/recipes-crypto/botan/botan_3.2.0.bb8
-rw-r--r--meta-openembedded/meta-oe/recipes-dbs/influxdb/influxdb_1.8.10.bb9
-rw-r--r--meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb-native_10.11.12.bb (renamed from meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb-native_10.11.7.bb)0
-rw-r--r--meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb.inc14
-rw-r--r--meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/0001-Add-missing-includes-cstdint-and-cstdio.patch43
-rw-r--r--meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/0001-MDEV-33439-Fix-build-with-libxml2-2.12.patch170
-rw-r--r--meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/0001-Remove-the-compile_time_assert-lines.patch43
-rw-r--r--meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/mm_malloc.patch13
-rw-r--r--meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/ppc-remove-glibc-dep.patch43
-rw-r--r--meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb_10.11.12.bb (renamed from meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb_10.11.7.bb)0
-rw-r--r--meta-openembedded/meta-oe/recipes-dbs/postgresql/files/0003-configure.ac-bypass-autoconf-2.69-version-check.patch6
-rw-r--r--meta-openembedded/meta-oe/recipes-dbs/postgresql/postgresql.inc10
-rw-r--r--meta-openembedded/meta-oe/recipes-dbs/postgresql/postgresql_16.10.bb (renamed from meta-openembedded/meta-oe/recipes-dbs/postgresql/postgresql_16.3.bb)4
-rw-r--r--meta-openembedded/meta-oe/recipes-dbs/psqlodbc/psqlodbc_16.00.0000.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-dbs/rocksdb/files/static_library_as_option.patch71
-rw-r--r--meta-openembedded/meta-oe/recipes-dbs/rocksdb/rocksdb_9.0.0.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/abseil-cpp/abseil-cpp/0001-PR-1739-container-internal-Explicitly-include-cstdin.patch34
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/abseil-cpp/abseil-cpp_20240116.3.bb (renamed from meta-openembedded/meta-oe/recipes-devtools/abseil-cpp/abseil-cpp_20240116.2.bb)3
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/android-tools/android-tools/android-tools-adbd.service2
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/android-tools/android-tools_5.1.1.r37.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/cjson/cjson_1.7.19.bb (renamed from meta-openembedded/meta-oe/recipes-devtools/cjson/cjson_1.7.17.bb)2
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/debootstrap/debootstrap_1.0.132.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/flatbuffers/flatbuffers.bb5
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/flatbuffers/python3-flatbuffers.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/giflib/files/add_suffix_to_convert_binary_used_in_Makefile.patch42
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/giflib/giflib/0001-Makefile-fix-typo-in-soname-argument.patch34
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/giflib/giflib_5.2.2.bb8
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/glade/glade/CVE-2020-36774.patch54
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/glade/glade_3.22.2.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/grpc/grpc/CVE-2024-11407.patch32
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/grpc/grpc/CVE-2024-7246.patch420
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/grpc/grpc_1.60.1.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/jq/jq/CVE-2024-23337.patch236
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/jq/jq/CVE-2024-53427.patch82
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/jq/jq/CVE-2025-48060.patch48
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/jq/jq/CVE-2025-9403.patch49
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/jq/jq_1.7.1.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/jsonrpc/jsonrpc_1.4.1.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/lapack/lapack_3.12.0.bb43
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/ldns/ldns_1.8.3.bb3
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/luajit/luajit/CVE-2024-25176.patch32
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/luajit/luajit/CVE-2024-25177.patch47
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/luajit/luajit/CVE-2024-25178.patch162
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/luajit/luajit_git.bb3
-rwxr-xr-xmeta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs-oe-cache-20.18/oe-npm-cache (renamed from meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs-oe-cache-20.12/oe-npm-cache)0
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs-oe-cache-native_20.18.bb (renamed from meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs-oe-cache-native_20.12.bb)0
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/0001-build-fix-build-with-Python-3.12.patch55
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/0001-gyp-resolve-python-3.12-issues.patch63
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/0001-src-fix-build-with-GCC-15.patch33
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/182d9c05e78.patch182
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/libatomic.patch85
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/zlib-fix-pointer-alignment.patch64
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs_20.18.2.bb (renamed from meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs_20.12.2.bb)88
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/perfetto/perfetto.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/perl/libdbd-mysql-perl/0001-Makefile.PL-avoid-running-assert_lib-at-configure.patch40
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/perl/libdbd-mysql-perl_4.050.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/perl/libdev-checklib-perl_1.16.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/php/php/0001-ext-opcache-config.m4-enable-opcache.patch15
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/php/php_8.2.29.bb (renamed from meta-openembedded/meta-oe/recipes-devtools/php/php_8.2.20.bb)3
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/protobuf/protobuf_4.25.8.bb (renamed from meta-openembedded/meta-oe/recipes-devtools/protobuf/protobuf_4.25.3.bb)4
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/sip/sip_6.8.6.bb (renamed from meta-openembedded/meta-oe/recipes-devtools/sip/sip_6.8.3.bb)12
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/xerces-c/xerces-c/0001-aclocal.m4-don-t-use-full-path-of-with_curl-in-xerce.patch58
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/xerces-c/xerces-c_3.2.5.bb8
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/xmlrpc-c/xmlrpc-c_1.59.01.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/yasm/yasm/CVE-2024-22653.patch32
-rw-r--r--meta-openembedded/meta-oe/recipes-devtools/yasm/yasm_git.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/boinc/boinc-client_7.20.5.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/collectd/collectd_5.12.0.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/dlt-daemon/dlt-daemon/0001-CMakeLists-txt-make-DLT_WatchdogSec-can-be-set-by-user.patch40
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/dlt-daemon/dlt-daemon_2.18.10.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/etcd/etcd-cpp-apiv3_0.15.3.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/etcd/etcd/CVE-2023-32082.patch86
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/etcd/etcd_3.5.7.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31176.patch86
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31177.patch40
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31178.patch95
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31179.patch35
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31180.patch43
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31181.patch43
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-3359.patch67
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot_5.4.3.bb7
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/hiredis/hiredis/run-ptest12
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/hplip/hplip_3.22.10.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/indent/indent/0001-Fix-a-heap-buffer-underread-in-set_buf_break.patch123
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/indent/indent/CVE-2023-40305_0001.patch4196
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/indent/indent/CVE-2023-40305_0002.patch4254
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/indent/indent_2.2.12.bb3
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/libblockdev/files/CVE-2025-6019.patch31
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/libblockdev/libblockdev_3.1.1.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/libconfig/libconfig_1.7.3.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus/CVE-2024-10918-01.patch177
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus/CVE-2024-10918-02.patch121
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus/CVE-2024-10918-03.patch84
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus/CVE-2024-10918-04.patch239
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus_3.1.10.bb11
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/lprng/lprng_3.8.C.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/minifi-cpp/files/CVE-2025-6140.patch35
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/minifi-cpp/minifi-cpp_0.15.0.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/nana/nana_git.bb6
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/p7zip/files/0001-Fix-two-buffer-overflow-vulnerabilities.patch455
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/p7zip/p7zip_16.02.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/polkit/files/CVE-2025-7519.patch34
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/polkit/polkit_124.bb8
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0001-hiredis-use-default-CC-if-it-is-set.patch (renamed from meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/hiredis-use-default-CC-if-it-is-set.patch)7
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0002-lua-update-Makefile-to-use-environment-build-setting.patch (renamed from meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/lua-update-Makefile-to-use-environment-build-setting.patch)6
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0003-hack-to-force-use-of-libc-malloc.patch (renamed from meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/oe-use-libc-malloc.patch)15
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0004-src-Do-not-reset-FINAL_LIBS.patch (renamed from meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/0001-src-Do-not-reset-FINAL_LIBS.patch)14
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0005-Define-_GNU_SOURCE-to-get-PTHREAD_MUTEX_INITIALIZER.patch (renamed from meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/GNU_SOURCE-7.patch)6
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0006-Define-correct-gregs-for-RISCV32.patch (renamed from meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/0006-Define-correct-gregs-for-RISCV32.patch)4
-rw-r--r--[-rwxr-xr-x]meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/init-redis-server (renamed from meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/init-redis-server)0
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/redis.conf (renamed from meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/redis.conf)0
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/redis.service (renamed from meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/redis.service)0
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/redis/redis/0001-hiredis-use-default-CC-if-it-is-set.patch (renamed from meta-openembedded/meta-oe/recipes-extended/redis/redis/hiredis-use-default-CC-if-it-is-set.patch)14
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/redis/redis/0002-lua-update-Makefile-to-use-environment-build-setting.patch (renamed from meta-openembedded/meta-oe/recipes-extended/redis/redis/lua-update-Makefile-to-use-environment-build-setting.patch)10
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/redis/redis/0003-hack-to-force-use-of-libc-malloc.patch (renamed from meta-openembedded/meta-oe/recipes-extended/redis/redis/oe-use-libc-malloc.patch)9
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/redis/redis/0004-src-Do-not-reset-FINAL_LIBS.patch (renamed from meta-openembedded/meta-oe/recipes-extended/redis/redis/0001-src-Do-not-reset-FINAL_LIBS.patch)8
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/redis/redis/0005-Define-_GNU_SOURCE-to-get-PTHREAD_MUTEX_INITIALIZER.patch (renamed from meta-openembedded/meta-oe/recipes-extended/redis/redis/GNU_SOURCE.patch)6
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/redis/redis/0006-Define-correct-gregs-for-RISCV32.patch12
-rw-r--r--[-rwxr-xr-x]meta-openembedded/meta-oe/recipes-extended/redis/redis/init-redis-server0
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/redis/redis_6.2.20.bb (renamed from meta-openembedded/meta-oe/recipes-extended/redis/redis_6.2.14.bb)17
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/redis/redis_7.2.11.bb (renamed from meta-openembedded/meta-oe/recipes-extended/redis/redis_7.2.4.bb)17
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/rrdtool/rrdtool_1.8.0.bb5
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/socketcan/can-utils/0001-lib-snprintf_can_error_frame-don-t-bail-out-if-CAN_E.patch70
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/socketcan/can-utils/0001-timestamp-formatting-always-use-64-bit-for-timestamp.patch422
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/socketcan/can-utils_2023.03.bb5
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/socketcan/canutils_4.0.6.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/socketcan/libsocketcan_0.0.12.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/vlock/vlock_2.2.3.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0001-locale-Avoid-using-glibc-specific-defines-on-musl.patch26
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0001-wx-config.in-Disable-cross-magic-it-does-not-work-fo.patch8
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0002-fix-libdir-for-multilib.patch (renamed from meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/fix-libdir-for-multilib.patch)35
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0003-create-links-with-relative-path.patch (renamed from meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/create-links-with-relative-path.patch)22
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0004-don-not-append-system-name-to-lib-name.patch (renamed from meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/not-append-system-name-to-lib-name.patch)12
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0005-wx-config-fix-libdir-for-multilib.patch (renamed from meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/wx-config-fix-libdir-for-multilib.patch)29
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0006-Fix-locale-on-musl.patch (renamed from meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/musl-locale-l.patch)18
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0007-Set-HAVE_LARGEFILE_SUPPORT-to-1-explicitly.patch (renamed from meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0001-Set-HAVE_LARGEFILE_SUPPORT-to-1-explicitly.patch)9
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/CVE-2024-58249.patch178
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets_3.2.6.bb (renamed from meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets_3.2.1.bb)18
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/zlog/zlog/0001-CVE-2024-22857-buffer-overflow-patched.patch31
-rw-r--r--meta-openembedded/meta-oe/recipes-extended/zlog/zlog_1.2.16.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-gnome/gcab/gcab/0001-gcab-enums.c.etemplate-include-basename-instead-of-f.patch37
-rw-r--r--meta-openembedded/meta-oe/recipes-gnome/gcab/gcab_1.6.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-gnome/gtk+/gtk+/CVE-2024-6655.patch40
-rw-r--r--meta-openembedded/meta-oe/recipes-gnome/gtk+/gtk+_2.24.33.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-gnome/libjcat/libjcat_0.2.1.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/fontforge/fontforge/CVE-2024-25081_CVE-2024-25082.patch181
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/fontforge/fontforge_20230101.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/gphoto2/gphoto2_2.5.28.bb3
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz/0001-Set-use_tcl-to-be-empty-string-if-tcl-is-disabled.patch33
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-0001.patch37
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-0002.patch38
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-0003.patch33
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz_8.1.0.bb7
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/gtkwave/gtkwave_3.3.119.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/jasper/jasper/0001-Fixes-400.patch171
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/jasper/jasper/0001-Fixes-401.patch78
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/jasper/jasper/0001-Fixes-402-403.patch62
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/jasper/jasper_4.1.1.bb6
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/libvncserver/libvncserver_0.9.14.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/openbox/files/0001-Fix-list-traversal-issue-in-client_calc_layer.patch56
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/openbox/openbox_3.6.1.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/openjpeg/openjpeg/0001-Do-not-ask-cmake-to-export-binaries-they-don-t-make-.patch (renamed from meta-openembedded/meta-oe/recipes-graphics/openjpeg/openjpeg/0002-Do-not-ask-cmake-to-export-binaries-they-don-t-make-.patch)10
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/openjpeg/openjpeg/CVE-2025-54874.patch44
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/openjpeg/openjpeg_2.5.3.bb (renamed from meta-openembedded/meta-oe/recipes-graphics/openjpeg/openjpeg_2.5.0.bb)5
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-cn-fonts_2.004.bb7
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-jp-fonts_2.004.bb7
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-kr-fonts_2.004.bb7
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-tw-fonts_2.004.bb7
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/vk-gl-cts/vulkan-cts/0001-Allow-running-the-CTS-with-unknown-versions-of-Vulka.patch41
-rw-r--r--meta-openembedded/meta-oe/recipes-graphics/vk-gl-cts/vulkan-cts_1.3.7.3.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-kernel/bpftool/bpftool.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-kernel/cpupower/cpupower.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-kernel/crash/crash.inc1
-rw-r--r--meta-openembedded/meta-oe/recipes-kernel/crash/crash/0001-symbol-fix-S-cannot-work-with-kaslr-detection.patch89
-rw-r--r--meta-openembedded/meta-oe/recipes-kernel/intel-speed-select/intel-speed-select.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-kernel/kernel-selftest/kernel-selftest.bb26
-rw-r--r--meta-openembedded/meta-oe/recipes-kernel/spidev-test/spidev-test.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-multimedia/audiofile/audiofile_0.3.6.bb5
-rw-r--r--meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0004-Always-check-the-number-of-coefficients.patch45
-rw-r--r--meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0005-clamp-index-values-to-fix-index-overflow-in-IMA.cpp.patch43
-rw-r--r--meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0006-Check-for-multiplication-overflow-in-sfconvert.patch79
-rw-r--r--meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0007-Actually-fail-when-error-occurs-in-parseFormat.patch46
-rw-r--r--meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0008-Check-for-multiplication-overflow-in-MSADPCM-decodeS.patch126
-rw-r--r--meta-openembedded/meta-oe/recipes-multimedia/libjxl/libjxl/CVE-2024-11403.patch70
-rw-r--r--meta-openembedded/meta-oe/recipes-multimedia/libjxl/libjxl/CVE-2024-11498.patch113
-rw-r--r--meta-openembedded/meta-oe/recipes-multimedia/libjxl/libjxl_0.10.2.bb6
-rw-r--r--meta-openembedded/meta-oe/recipes-multimedia/pulseaudio/pavucontrol_5.0.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-multimedia/v4l2apps/v4l-utils/0001-media-ctl-Install-media-ctl-header-and-library-files.patch78
-rw-r--r--meta-openembedded/meta-oe/recipes-multimedia/v4l2apps/v4l-utils/0003-meson.build-fix-arm-_TIME_BITS-64-error.patch38
-rw-r--r--meta-openembedded/meta-oe/recipes-multimedia/v4l2apps/v4l-utils_1.26.1.bb6
-rw-r--r--meta-openembedded/meta-oe/recipes-multimedia/xsp/xsp_1.0.0-8.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-printing/cups/libcupsfilters/0001-CVE-2024-47076.patch38
-rw-r--r--meta-openembedded/meta-oe/recipes-printing/cups/libcupsfilters_2.0.0.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-printing/cups/libppd/0001-CVE-2024-47175.patch600
-rw-r--r--meta-openembedded/meta-oe/recipes-printing/cups/libppd_2.0.0.bb5
-rw-r--r--meta-openembedded/meta-oe/recipes-printing/gutenprint/gutenprint/0001-cups-fix-a-build-race-condition-around-empty-directo.patch60
-rw-r--r--meta-openembedded/meta-oe/recipes-printing/gutenprint/gutenprint_5.3.5.bb (renamed from meta-openembedded/meta-oe/recipes-printing/gutenprint/gutenprint_5.3.4.bb)6
-rw-r--r--meta-openembedded/meta-oe/recipes-security/kernel-hardening-checker/files/0001-pyproject.toml-fix-up-license-information.patch31
-rw-r--r--meta-openembedded/meta-oe/recipes-security/kernel-hardening-checker/files/0002-pyproject.toml-relax-setuptool-version-requirement.patch29
-rw-r--r--meta-openembedded/meta-oe/recipes-security/kernel-hardening-checker/kernel-hardening-checker_0.6.10.2.bb41
-rw-r--r--meta-openembedded/meta-oe/recipes-security/softhsm/softhsm_2.6.1.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-shells/dash/dash_0.5.12.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-support/asio/asio/0001-tests-Remove-blocking_adaptation.cpp.patch37
-rw-r--r--meta-openembedded/meta-oe/recipes-support/asio/asio/run-ptest19
-rw-r--r--meta-openembedded/meta-oe/recipes-support/asio/asio_1.30.2.bb19
-rw-r--r--meta-openembedded/meta-oe/recipes-support/ckermit/ckermit_302.bb5
-rw-r--r--meta-openembedded/meta-oe/recipes-support/eject/eject_2.1.5.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-support/emacs/emacs_29.1.bb5
-rw-r--r--meta-openembedded/meta-oe/recipes-support/emacs/files/0001-lisp-gnus-mm-view.el-mm-display-inline-fontify-Mark-.patch27
-rw-r--r--meta-openembedded/meta-oe/recipes-support/emacs/files/0001-org-file-contents-Consider-all-remote-files-unsafe.patch38
-rw-r--r--meta-openembedded/meta-oe/recipes-support/emacs/files/0001-org-latex-preview-Add-protection-when-untrusted-cont.patch60
-rw-r--r--meta-openembedded/meta-oe/recipes-support/emacs/files/0001-org-link-expand-abbrev-Do-not-evaluate-arbitrary-uns.patch71
-rw-r--r--meta-openembedded/meta-oe/recipes-support/emacs/files/0001-org-macro-set-templates-Prevent-code-evaluation.patch47
-rw-r--r--meta-openembedded/meta-oe/recipes-support/enca/enca/cross.patch68
-rw-r--r--meta-openembedded/meta-oe/recipes-support/enca/enca/makefile-remove-tools.patch14
-rw-r--r--meta-openembedded/meta-oe/recipes-support/enca/enca_1.19.bb24
-rw-r--r--meta-openembedded/meta-oe/recipes-support/exiv2/exiv2/0001-Add-new-method-appendIccProfile-to-fix-quadratic-per.patch96
-rw-r--r--meta-openembedded/meta-oe/recipes-support/exiv2/exiv2/0001-CVE-2025-54080-fix.patch77
-rw-r--r--meta-openembedded/meta-oe/recipes-support/exiv2/exiv2/0001-Revert-fix-copy-constructors.patch82
-rw-r--r--meta-openembedded/meta-oe/recipes-support/exiv2/exiv2_0.28.0.bb19
-rw-r--r--meta-openembedded/meta-oe/recipes-support/exiv2/exiv2_0.28.3.bb15
-rw-r--r--meta-openembedded/meta-oe/recipes-support/freerdp/freerdp/0001-Fixed-compilation-warnings.patch27
-rw-r--r--meta-openembedded/meta-oe/recipes-support/freerdp/freerdp/CVE-2024-32661.patch27
-rw-r--r--meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32039.patch68
-rw-r--r--meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32040.patch29
-rw-r--r--meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32458.patch119
-rw-r--r--meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32459.patch30
-rw-r--r--meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32460.patch26
-rw-r--r--meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32658.patch35
-rw-r--r--meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32659.patch27
-rw-r--r--meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32660.patch151
-rw-r--r--meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32661.patch28
-rw-r--r--meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32662.patch28
-rw-r--r--meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3_3.4.0.bb15
-rw-r--r--meta-openembedded/meta-oe/recipes-support/freerdp/freerdp_2.11.7.bb (renamed from meta-openembedded/meta-oe/recipes-support/freerdp/freerdp_2.11.2.bb)6
-rw-r--r--meta-openembedded/meta-oe/recipes-support/gpm/gpm_git.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-support/hdf5/files/0001-cmake-remove-build-flags.patch41
-rw-r--r--meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2913.patch32
-rw-r--r--meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2914.patch47
-rw-r--r--meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2915.patch50
-rw-r--r--meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2923-CVE-2025-6816-CVE-2025-6856.patch65
-rw-r--r--meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2924.patch37
-rw-r--r--meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2925.patch53
-rw-r--r--meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-6269-CVE-2025-6270-CVE-2025-6516_01.patch65
-rw-r--r--meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-6269-CVE-2025-6270-CVE-2025-6516_02.patch252
-rw-r--r--meta-openembedded/meta-oe/recipes-support/hdf5/hdf5_1.14.4-3.bb (renamed from meta-openembedded/meta-oe/recipes-support/hdf5/hdf5_1.14.2.bb)21
-rw-r--r--meta-openembedded/meta-oe/recipes-support/hunspell/hunspell-dictionaries.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-support/imagemagick/imagemagick_7.1.1.bb93
-rw-r--r--meta-openembedded/meta-oe/recipes-support/iniparser/iniparser/CVE-2025-0633.patch37
-rw-r--r--meta-openembedded/meta-oe/recipes-support/iniparser/iniparser_4.1.bb1
-rwxr-xr-xmeta-openembedded/meta-oe/recipes-support/lcov/lcov_1.16.bb23
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libatasmart/libatasmart_0.19.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libeigen/libeigen/0002-Remove-LGPL-Code-and-references.patch1040
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libeigen/libeigen_3.4.0.bb9
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libgpiod/libgpiod-2.x/0001-bindings-cxx-tests-set-direction-when-reconfiguring-.patch38
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libgpiod/libgpiod_2.1.2.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libjs/libjs-jquery-icheck_1.0.3.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libp11/files/0001-detect-correct-openssl-3.x.patch28
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libp11/libp11_0.4.12.bb5
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libraw/libraw/0001-CVE-2025-43961-CVE-2025-43962.patch108
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libraw/libraw/0002-CVE-2025-43963.patch40
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libraw/libraw/0003-CVE-2025-43964.patch29
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libraw/libraw_0.21.2.bb7
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-4877.patch57
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-4878-0001.patch2552
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-4878-0002.patch34
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-5318.patch31
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-5351.patch38
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-5372.patch150
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-5987.patch37
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-8114.patch49
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libssh/libssh_0.10.6.bb8
-rw-r--r--meta-openembedded/meta-oe/recipes-support/libusbgx/libusbgx_git.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-support/log4cpp/log4cpp_1.1.4.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-support/lvm2/libdevmapper_2.03.22.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-support/nss/nss/CVE-2024-6602.patch65
-rw-r--r--meta-openembedded/meta-oe/recipes-support/nss/nss/CVE-2024-6609.patch30
-rw-r--r--meta-openembedded/meta-oe/recipes-support/nss/nss_3.98.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-support/opensc/files/0001-PR-Fixes-for-uninitialized-memory-issues.patch1268
-rw-r--r--meta-openembedded/meta-oe/recipes-support/opensc/files/CVE-2024-8443-0001.patch60
-rw-r--r--meta-openembedded/meta-oe/recipes-support/opensc/files/CVE-2024-8443-0002.patch55
-rw-r--r--meta-openembedded/meta-oe/recipes-support/opensc/opensc_0.25.1.bb6
-rw-r--r--meta-openembedded/meta-oe/recipes-support/poco/poco/0001-cppignore.lnx-Ignore-PKCS12-and-testLaunch-test.patch21
-rw-r--r--meta-openembedded/meta-oe/recipes-support/poco/poco/CVE-2025-6375.patch34
-rw-r--r--meta-openembedded/meta-oe/recipes-support/poco/poco_1.12.5p2.bb3
-rw-r--r--meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2024-56378.patch77
-rw-r--r--meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2024-6239-0001.patch1275
-rw-r--r--meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2024-6239-0002.patch111
-rw-r--r--meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-32364.patch28
-rw-r--r--meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-32365.patch41
-rw-r--r--meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-43718.patch31
-rw-r--r--meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-43903-0001.patch75
-rw-r--r--meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-43903-0002.patch49
-rw-r--r--meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-50420.patch38
-rw-r--r--meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-52885.patch30
-rw-r--r--meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-52886-0001.patch4319
-rw-r--r--meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-52886-0002.patch58
-rw-r--r--meta-openembedded/meta-oe/recipes-support/poppler/poppler_23.04.0.bb12
-rw-r--r--meta-openembedded/meta-oe/recipes-support/procmail/procmail/CVE-2014-3618.patch29
-rw-r--r--meta-openembedded/meta-oe/recipes-support/procmail/procmail/CVE-2017-16844.patch20
-rw-r--r--meta-openembedded/meta-oe/recipes-support/procmail/procmail/gcc14.patch127
-rw-r--r--meta-openembedded/meta-oe/recipes-support/procmail/procmail_3.22.bb9
-rw-r--r--meta-openembedded/meta-oe/recipes-support/sharutils/sharutils/0001-libopts.m4-accept-POSIX_SHELL-from-the-environment-d.patch47
-rw-r--r--meta-openembedded/meta-oe/recipes-support/sharutils/sharutils_4.15.2.bb3
-rw-r--r--meta-openembedded/meta-oe/recipes-support/spdlog/spdlog/CVE-2025-6140.patch35
-rw-r--r--meta-openembedded/meta-oe/recipes-support/spdlog/spdlog_1.13.0.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-support/srecord/files/0001-fix-build-failure-with-gcc-15-by-adding-cstdint-head.patch36
-rw-r--r--meta-openembedded/meta-oe/recipes-support/srecord/srecord_1.65.0.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-support/syslog-ng/files/CVE-2024-47619.patch292
-rw-r--r--meta-openembedded/meta-oe/recipes-support/syslog-ng/syslog-ng_4.6.0.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-support/tbb/tbb/0001-Fix-suppress-new-GCC-12-13-warnings-1192.patch57
-rw-r--r--meta-openembedded/meta-oe/recipes-support/tbb/tbb_2021.11.0.bb1
-rw-r--r--meta-openembedded/meta-oe/recipes-support/thin-provisioning-tools/thin-provisioning-tools_1.0.12.bb8
-rw-r--r--meta-openembedded/meta-oe/recipes-support/tokyocabinet/tokyocabinet_1.4.48.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-support/tree/tree_2.1.1.bb4
-rw-r--r--meta-openembedded/meta-oe/recipes-support/udisks/udisks2_2.10.2.bb (renamed from meta-openembedded/meta-oe/recipes-support/udisks/udisks2_2.10.1.bb)2
-rw-r--r--meta-openembedded/meta-oe/recipes-support/uim/uim_1.8.8.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-support/webkitgtk/webkitgtk3_2.44.3.bb (renamed from meta-openembedded/meta-oe/recipes-support/webkitgtk/webkitgtk3_2.44.1.bb)14
-rw-r--r--meta-openembedded/meta-oe/recipes-support/xmlsec1/xmlsec1_1.3.4.bb2
-rw-r--r--meta-openembedded/meta-oe/recipes-test/pm-qa/pm-qa_git.bb2
-rw-r--r--meta-openembedded/meta-perl/recipes-extended/logcheck/logcheck_1.4.3.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-cbor2_5.6.3.bb4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-colorama_0.4.6.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-crc32c_2.3.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-django_4.2.20.bb (renamed from meta-openembedded/meta-python/recipes-devtools/python/python3-django_4.2.11.bb)4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-django_5.0.11.bb (renamed from meta-openembedded/meta-python/recipes-devtools/python/python3-django_5.0.4.bb)2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-email-validator_2.1.1.bb (renamed from meta-openembedded/meta-python/recipes-devtools/python/python3-email-validator_2.1.0.bb)6
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-fann2_1.1.2.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors/CVE-2024-6221.patch110
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors_4.0.0.bb4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-googleapis-common-protos_1.63.0.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio-tools_1.62.2.bb4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-PR-1644-unscaledcycleclock-remove-RISC-V-support.patch82
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-crypto-use-_Generic-only-if-defined-__cplusplus.patch74
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/CVE-2024-11407.patch32
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio_1.62.2.bb7
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0001-Properly-cast-arguments-to-H5Lunpack_elink_val.patch25
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0002-Use-libc.stdint-instead-of-numpy.patch25
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-h5py_3.10.0.bb8
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-haversine_2.8.1.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-kivy_2.3.0.bb7
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-libevdev_0.11.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-lru-dict_1.3.0.bb4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-mock_5.1.0.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-nmap_1.6.0.bb4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-parse-type_0.6.2.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pillow_10.3.0.bb4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-platformdirs_4.2.0.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0001-build_support-use-source-filename-instead-of-foo-for.patch50
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0002-build_support-handle-empty-max_priority-value-as-Non.patch49
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0003-build_support-use-does_build_succeed-in-compile_and_.patch62
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0004-build_support-handle-runtime-errors-and-return-None-.patch47
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.1.1.bb11
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.2.0.bb17
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-protobuf_4.25.8.bb (renamed from meta-openembedded/meta-python/recipes-devtools/python/python3-protobuf_4.25.3.bb)10
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pycocotools_2.0.7.bb4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pycurl_7.45.2.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core-crates.inc88
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Bumps-pyo3-https-github.com-pyo3-pyo3-from-0.20.2-to.patch126
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Set-rust-version-from-1.76-to-1.75-in-Cargo.toml.patch29
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0002-Dont-embed-RUSTFLAGS-in-final-binary.patch47
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core_2.18.4.bb (renamed from meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core_2.16.3.bb)12
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic_2.7.4.bb (renamed from meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic_2.7.0.bb)2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pylint_3.1.0.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj/rpath.patch18
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj_3.6.1.bb10
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-pyyaml-include_1.3.2.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2024-4340.patch48
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse_0.4.4.bb1
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-tornado_6.4.2.bb (renamed from meta-openembedded/meta-python/recipes-devtools/python/python3-tornado_6.4.bb)4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0001.patch89
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0002.patch251
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-twisted_24.3.0.bb5
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-werkzeug_3.0.6.bb (renamed from meta-openembedded/meta-python/recipes-devtools/python/python3-werkzeug_3.0.1.bb)5
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-xlsxwriter_3.1.9.bb2
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/python3-xmodem_0.4.7.bb4
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/tftpy/CVE-2023-46566.patch26
-rw-r--r--meta-openembedded/meta-python/recipes-devtools/python/tftpy_0.8.2.bb2
-rw-r--r--meta-openembedded/meta-webserver/recipes-httpd/apache-mod/mod-dnssd_0.6.bb2
-rw-r--r--meta-openembedded/meta-webserver/recipes-httpd/apache2/apache2_2.4.65.bb (renamed from meta-openembedded/meta-webserver/recipes-httpd/apache2/apache2_2.4.59.bb)17
-rw-r--r--meta-openembedded/meta-webserver/recipes-httpd/monkey/monkey_1.6.9.bb2
-rw-r--r--meta-openembedded/meta-webserver/recipes-httpd/nginx/files/CVE-2024-7347-1.patch34
-rw-r--r--meta-openembedded/meta-webserver/recipes-httpd/nginx/files/CVE-2024-7347-2.patch52
-rw-r--r--meta-openembedded/meta-webserver/recipes-httpd/nginx/files/CVE-2025-23419.patch87
-rwxr-xr-xmeta-openembedded/meta-webserver/recipes-httpd/nginx/files/CVE-2025-53859.patch131
-rw-r--r--meta-openembedded/meta-webserver/recipes-httpd/nginx/nginx.inc3
-rw-r--r--meta-openembedded/meta-webserver/recipes-httpd/nginx/nginx_1.24.0.bb3
-rw-r--r--meta-openembedded/meta-webserver/recipes-httpd/nginx/nginx_1.25.4.bb (renamed from meta-openembedded/meta-webserver/recipes-httpd/nginx/nginx_1.25.3.bb)4
-rw-r--r--meta-openembedded/meta-webserver/recipes-php/phpmyadmin/phpmyadmin_5.2.2.bb (renamed from meta-openembedded/meta-webserver/recipes-php/phpmyadmin/phpmyadmin_5.2.1.bb)4
-rw-r--r--meta-openembedded/meta-webserver/recipes-support/fcgi/fcgi/CVE-2025-23016.patch40
-rw-r--r--meta-openembedded/meta-webserver/recipes-support/fcgi/fcgi_git.bb1
-rw-r--r--meta-openembedded/meta-xfce/recipes-art/xfce-dusk-gtk3/xfce-dusk-gtk3_1.3.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-multimedia/xfce4-mpc-plugin/xfce4-mpc-plugin_0.5.3.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/battery/xfce4-battery-plugin_1.1.5.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/calculator/xfce4-calculator-plugin_0.7.2.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/clipman/xfce4-clipman-plugin_1.6.2.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/cpufreq/xfce4-cpufreq-plugin_1.2.8.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/cpugraph/xfce4-cpugraph-plugin_1.2.8.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/datetime/xfce4-datetime-plugin_0.8.3.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/diskperf/xfce4-diskperf-plugin_2.7.0.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/eyes/xfce4-eyes-plugin_4.6.0.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/fsguard/xfce4-fsguard-plugin_1.1.3.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/genmon/xfce4-genmon-plugin_4.2.0.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/mailwatch/xfce4-mailwatch-plugin_1.3.1.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/mount/xfce4-mount-plugin_1.1.5.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/netload/xfce4-netload-plugin_1.4.1.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/notes/xfce4-notes-plugin_1.10.0.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/places/xfce4-places-plugin_1.8.3.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/sensors/xfce4-sensors-plugin_1.4.4.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/smartbookmark/xfce4-smartbookmark-plugin_0.5.2.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/systemload/xfce4-systemload-plugin_1.3.2.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/time-out/xfce4-time-out-plugin_1.1.3.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/timer/xfce4-timer-plugin_1.7.2.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/verve/xfce4-verve-plugin_2.0.3.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/wavelan/xfce4-wavelan-plugin_0.6.3.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/weather/xfce4-weather-plugin_0.11.1.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-panel-plugins/xkb/xfce4-xkb-plugin_0.8.2.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-thunar-plugins/archive/thunar-archive-plugin_0.5.2.bb2
-rw-r--r--meta-openembedded/meta-xfce/recipes-xfce/xfce4-power-manager/xfce4-power-manager_4.18.1.bb2
576 files changed, 38979 insertions, 1933 deletions
diff --git a/meta-openembedded/meta-filesystems/recipes-utils/e2tools/e2tools_git.bb b/meta-openembedded/meta-filesystems/recipes-utils/e2tools/e2tools_git.bb
index 1fa5e01874..a0d194cae0 100644
--- a/meta-openembedded/meta-filesystems/recipes-utils/e2tools/e2tools_git.bb
+++ b/meta-openembedded/meta-filesystems/recipes-utils/e2tools/e2tools_git.bb
@@ -67,7 +67,7 @@ do_install_ptest() {
cp -r "${S}" "${D}${PTEST_PATH}"
rm -rf ${D}${PTEST_PATH}/build/config.log ${D}${PTEST_PATH}/build/autom4te.cache \
${D}${PTEST_PATH}/git/.git ${D}${PTEST_PATH}/git/autom4te.cache
- sed -i -e 's;${RECIPE_SYSROOT};;g' ${D}${PTEST_PATH}/build/config.status
+ sed -i -e 's;${TMPDIR};;g' ${D}${PTEST_PATH}/build/config.status
}
RDEPENDS:${PN}-ptest += "bash coreutils e2fsprogs e2tools gawk make perl"
diff --git a/meta-openembedded/meta-gnome/dynamic-layers/meta-security/recipes-gnome/gnome-remote-desktop/gnome-remote-desktop_46.1.bb b/meta-openembedded/meta-gnome/dynamic-layers/meta-security/recipes-gnome/gnome-remote-desktop/gnome-remote-desktop_46.2.bb
index 634b37971e..59ae9383db 100644
--- a/meta-openembedded/meta-gnome/dynamic-layers/meta-security/recipes-gnome/gnome-remote-desktop/gnome-remote-desktop_46.1.bb
+++ b/meta-openembedded/meta-gnome/dynamic-layers/meta-security/recipes-gnome/gnome-remote-desktop/gnome-remote-desktop_46.2.bb
@@ -4,11 +4,11 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
GNOMEBASEBUILDCLASS = "meson"
-inherit gnomebase gettext gsettings features_check
+inherit gnomebase gettext gsettings features_check useradd
-REQUIRED_DISTRO_FEATURES = "opengl"
+REQUIRED_DISTRO_FEATURES = "opengl polkit"
-SRC_URI[archive.sha256sum] = "7c62a4281fdfa9522110affbf75d09973035f2adc7fa4577511d733186beb68f"
+SRC_URI[archive.sha256sum] = "97443eaffe4b1a69626886a41d25cbeb2c148d3fed43d92115c1b7d20d5238ab"
DEPENDS = " \
asciidoc-native \
@@ -36,5 +36,15 @@ PACKAGECONFIG[vnc] = "-Dvnc=true,-Dvnc=false,libvncserver"
PACKAGECONFIG[rdp] = "-Drdp=true,-Drdp=false,freerdp3 fuse3 libxkbcommon"
PACKAGECONFIG[systemd] = "-Dsystemd=true,-Dsystemd=false,systemd"
+USERADD_PACKAGES = "${PN}"
+USERADD_PARAM:${PN} = "--system --no-create-home --user-group --home-dir ${sysconfdir}/polkit-1 polkitd"
+
+do_install:append() {
+ if [ -d ${D}${datadir}/polkit-1/rules.d ]; then
+ chmod 700 ${D}${datadir}/polkit-1/rules.d
+ chown polkitd:root ${D}${datadir}/polkit-1/rules.d
+ fi
+}
+
PACKAGE_DEBUG_SPLIT_STYLE = "debug-without-src"
FILES:${PN} += "${systemd_user_unitdir} ${systemd_system_unitdir} ${datadir} ${libdir}/sysusers.d ${libdir}/tmpfiles.d"
diff --git a/meta-openembedded/meta-gnome/recipes-connectivity/geary/geary_44.1.bb b/meta-openembedded/meta-gnome/recipes-connectivity/geary/geary_44.1.bb
index decae6b2c7..93cad3fc88 100644
--- a/meta-openembedded/meta-gnome/recipes-connectivity/geary/geary_44.1.bb
+++ b/meta-openembedded/meta-gnome/recipes-connectivity/geary/geary_44.1.bb
@@ -18,6 +18,7 @@ DEPENDS = " \
gtk+3 \
icu \
iso-codes \
+ itstool-native \
json-glib \
libhandy \
libical \
diff --git a/meta-openembedded/meta-gnome/recipes-gnome/eog/eog_45.3.bb b/meta-openembedded/meta-gnome/recipes-gnome/eog/eog_45.3.bb
index 00fe266698..f3892f824d 100644
--- a/meta-openembedded/meta-gnome/recipes-gnome/eog/eog_45.3.bb
+++ b/meta-openembedded/meta-gnome/recipes-gnome/eog/eog_45.3.bb
@@ -3,6 +3,7 @@ LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
DEPENDS = " \
+ itstool-native \
librsvg \
gnome-desktop \
gsettings-desktop-schemas \
diff --git a/meta-openembedded/meta-gnome/recipes-gnome/evince/evince_46.0.bb b/meta-openembedded/meta-gnome/recipes-gnome/evince/evince_46.0.bb
index 57eb994e13..291d325848 100644
--- a/meta-openembedded/meta-gnome/recipes-gnome/evince/evince_46.0.bb
+++ b/meta-openembedded/meta-gnome/recipes-gnome/evince/evince_46.0.bb
@@ -56,3 +56,7 @@ FILES:${PN} += "${datadir}/dbus-1 \
${systemd_user_unitdir} \
"
FILES:${PN}-nautilus-extension = "${libdir}/nautilus/*/*so"
+
+CVE_PRODUCT = "evince"
+CVE_STATUS[CVE-2011-0433] = "fixed-version: No action required. The current version (46.0) is not affected by the CVE which has been patched since version 3.1.2"
+CVE_STATUS[CVE-2011-5244] = "fixed-version: No action required. The current version (46.0) is not affected by the CVE which has been patched since version 3.1.2"
diff --git a/meta-openembedded/meta-gnome/recipes-gnome/ghex/ghex_46.0.bb b/meta-openembedded/meta-gnome/recipes-gnome/ghex/ghex_46.0.bb
index 41d8391636..04b0f99532 100644
--- a/meta-openembedded/meta-gnome/recipes-gnome/ghex/ghex_46.0.bb
+++ b/meta-openembedded/meta-gnome/recipes-gnome/ghex/ghex_46.0.bb
@@ -7,6 +7,7 @@ DEPENDS = " \
desktop-file-utils-native \
glib-2.0-native \
gtk4 \
+ itstool-native \
libadwaita \
"
diff --git a/meta-openembedded/meta-gnome/recipes-gnome/gnome-chess/gnome-chess_46.0.bb b/meta-openembedded/meta-gnome/recipes-gnome/gnome-chess/gnome-chess_46.0.bb
index bb53b58df7..0b78a935f1 100644
--- a/meta-openembedded/meta-gnome/recipes-gnome/gnome-chess/gnome-chess_46.0.bb
+++ b/meta-openembedded/meta-gnome/recipes-gnome/gnome-chess/gnome-chess_46.0.bb
@@ -13,8 +13,8 @@ DEPENDS = " \
cairo \
desktop-file-utils-native \
glib-2.0 \
- glib-2.0 \
gtk4 \
+ itstool-native \
libadwaita \
librsvg \
pango \
diff --git a/meta-openembedded/meta-gnome/recipes-gnome/gnome-photos/gnome-photos_44.0.bb b/meta-openembedded/meta-gnome/recipes-gnome/gnome-photos/gnome-photos_44.0.bb
index 4b05e52ca0..e025b8b5a5 100644
--- a/meta-openembedded/meta-gnome/recipes-gnome/gnome-photos/gnome-photos_44.0.bb
+++ b/meta-openembedded/meta-gnome/recipes-gnome/gnome-photos/gnome-photos_44.0.bb
@@ -16,6 +16,7 @@ DEPENDS = " \
gexiv2 \
gnome-online-accounts \
gsettings-desktop-schemas \
+ itstool-native \
libdazzle \
tracker \
libhandy \
diff --git a/meta-openembedded/meta-gnome/recipes-gnome/libgsf/libgsf_1.14.52.bb b/meta-openembedded/meta-gnome/recipes-gnome/libgsf/libgsf_1.14.53.bb
index 7e1842b1ac..ffa24e8120 100644
--- a/meta-openembedded/meta-gnome/recipes-gnome/libgsf/libgsf_1.14.52.bb
+++ b/meta-openembedded/meta-gnome/recipes-gnome/libgsf/libgsf_1.14.53.bb
@@ -9,8 +9,8 @@ DEPENDS= "libxml2 bzip2 glib-2.0 zlib"
GNOMEBASEBUILDCLASS = "autotools"
inherit gnomebase gobject-introspection gettext gtk-doc
-SRC_URI[archive.sha256sum] = "9181c914b9fac0e05d6bcaa34c7b552fe5fc0961d3c9f8c01ccc381fb084bcf0"
-SRC_URI += "file://0001-configure.ac-drop-a-copy-paste-of-introspection.m4-m.patch"
+SRC_URI[archive.sha256sum] = "0eb59a86e0c50f97ac9cfe4d8cc1969f623f2ae8c5296f2414571ff0a9e8bcba"
+SRC_URI += " file://0001-configure.ac-drop-a-copy-paste-of-introspection.m4-m.patch"
PACKAGECONFIG ??= ""
PACKAGECONFIG[gdk-pixbuf] = "--with-gdk-pixbuf,--without-gdk-pixbuf,gdk-pixbuf"
diff --git a/meta-openembedded/meta-multimedia/recipes-multimedia/libavif/libavif_1.0.1.bb b/meta-openembedded/meta-multimedia/recipes-multimedia/libavif/libavif_1.0.1.bb
index 885758b6a4..8ddd16ee2a 100644
--- a/meta-openembedded/meta-multimedia/recipes-multimedia/libavif/libavif_1.0.1.bb
+++ b/meta-openembedded/meta-multimedia/recipes-multimedia/libavif/libavif_1.0.1.bb
@@ -14,3 +14,5 @@ DEPENDS = "dav1d"
inherit cmake
EXTRA_OECMAKE += "-DAVIF_CODEC_DAV1D=ON"
+
+CVE_STATUS[CVE-2025-48175] = "cpe-incorrect: The current version (1.0.1) is not affected by the CVE"
diff --git a/meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera/0001-ipu3-Use-posix-basename.patch b/meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera/0001-ipu3-Use-posix-basename.patch
deleted file mode 100644
index 9e4adf3d8d..0000000000
--- a/meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera/0001-ipu3-Use-posix-basename.patch
+++ /dev/null
@@ -1,71 +0,0 @@
-From 35d2acc61b1b27c0810a80cd21de65f29dc79df7 Mon Sep 17 00:00:00 2001
-From: Khem Raj <raj.khem@gmail.com>
-Date: Sun, 24 Mar 2024 11:27:21 -0700
-Subject: [PATCH] ipu3: Use posix basename
-
-musl does not implement GNU basename extention and with latest musl
-the prototype from string.h is also removed [1] which now results in
-compile errors e.g.
-
-../git/utils/ipu3/ipu3-pack.c:21:47: error: call to undeclared function 'basename'; ISO C99 and later do not support implicit function declarations [-Wimplicit-function-declaration]
-
-These utilities are using this function in usage() which is used just
-before program exit. Always use the basename APIs from libgen.h which is
-posix implementation
-
-[1] https://git.musl-libc.org/cgit/musl/commit/?id=725e17ed6dff4d0cd22487bb64470881e86a92e7
-
-Upstream-Status: Submitted [https://lists.libcamera.org/pipermail/libcamera-devel/2024-March/041180.html]
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
----
- utils/ipu3/ipu3-pack.c | 4 ++--
- utils/ipu3/ipu3-unpack.c | 3 ++-
- 2 files changed, 4 insertions(+), 3 deletions(-)
-
-diff --git a/utils/ipu3/ipu3-pack.c b/utils/ipu3/ipu3-pack.c
-index decbfc6c..23d2db8b 100644
---- a/utils/ipu3/ipu3-pack.c
-+++ b/utils/ipu3/ipu3-pack.c
-@@ -8,6 +8,7 @@
-
- #include <errno.h>
- #include <fcntl.h>
-+#include <libgen.h>
- #include <stdint.h>
- #include <stdio.h>
- #include <string.h>
-@@ -15,9 +16,8 @@
- #include <sys/types.h>
- #include <unistd.h>
-
--static void usage(const char *argv0)
-+static void usage(char *argv0)
- {
--
- printf("Usage: %s input-file output-file\n", basename(argv0));
- printf("Convert unpacked RAW10 Bayer data to the IPU3 packed Bayer formats\n");
- printf("If the output-file '-', output data will be written to standard output\n");
-diff --git a/utils/ipu3/ipu3-unpack.c b/utils/ipu3/ipu3-unpack.c
-index 9d2c1200..1505a970 100644
---- a/utils/ipu3/ipu3-unpack.c
-+++ b/utils/ipu3/ipu3-unpack.c
-@@ -8,6 +8,7 @@
-
- #include <errno.h>
- #include <fcntl.h>
-+#include <libgen.h>
- #include <stdint.h>
- #include <stdio.h>
- #include <string.h>
-@@ -15,7 +16,7 @@
- #include <sys/types.h>
- #include <unistd.h>
-
--static void usage(const char *argv0)
-+static void usage(char *argv0)
- {
- printf("Usage: %s input-file output-file\n", basename(argv0));
- printf("Unpack the IPU3 raw Bayer format to 16-bit Bayer\n");
---
-2.44.0
-
diff --git a/meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera/0001-rpi-Use-alloca-instead-of-variable-length-arrays.patch b/meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera/0001-rpi-Use-alloca-instead-of-variable-length-arrays.patch
deleted file mode 100644
index c336e92548..0000000000
--- a/meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera/0001-rpi-Use-alloca-instead-of-variable-length-arrays.patch
+++ /dev/null
@@ -1,43 +0,0 @@
-From 11cc6dbd45f0880beea64cdc514f57484b90bc39 Mon Sep 17 00:00:00 2001
-From: Khem Raj <raj.khem@gmail.com>
-Date: Tue, 20 Feb 2024 18:44:23 -0800
-Subject: [PATCH] rpi: Use malloc instead of variable length arrays
-
-Clang-18+ diagnoses this as error
-
-| ../git/src/ipa/rpi/controller/rpi/alsc.cpp:499:10: error: variable length arrays in C++ are a Clang extension [-Werror,-Wvla-cxx-extension] | 499 | int xLo[X], xHi[X];
-| | ^
-
-Upstream-Status: Submitted [https://lists.libcamera.org/pipermail/libcamera-devel/2024-February/040529.html]
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
-
-s
----
- src/ipa/rpi/controller/rpi/alsc.cpp | 7 +++++--
- 1 file changed, 5 insertions(+), 2 deletions(-)
-
-diff --git a/src/ipa/rpi/controller/rpi/alsc.cpp b/src/ipa/rpi/controller/rpi/alsc.cpp
-index 8a205c60..a7d42614 100644
---- a/src/ipa/rpi/controller/rpi/alsc.cpp
-+++ b/src/ipa/rpi/controller/rpi/alsc.cpp
-@@ -496,8 +496,8 @@ void resampleCalTable(const Array2D<double> &calTableIn,
- * Precalculate and cache the x sampling locations and phases to save
- * recomputing them on every row.
- */
-- int xLo[X], xHi[X];
-- double xf[X];
-+ int *xLo = (int*)malloc(X), *xHi = (int*)malloc(X);
-+ double *xf = (double*)malloc(X);
- double scaleX = cameraMode.sensorWidth /
- (cameraMode.width * cameraMode.scaleX);
- double xOff = cameraMode.cropX / (double)cameraMode.sensorWidth;
-@@ -539,6 +539,9 @@ void resampleCalTable(const Array2D<double> &calTableIn,
- *(out++) = above * (1 - yf) + below * yf;
- }
- }
-+ free(xf);
-+ free(xHi);
-+ free(xLo);
- }
-
- /* Calculate chrominance statistics (R/G and B/G) for each region. */
diff --git a/meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera/0002-options-Replace-use-of-VLAs-in-C.patch b/meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera/0002-options-Replace-use-of-VLAs-in-C.patch
deleted file mode 100644
index 473820653e..0000000000
--- a/meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera/0002-options-Replace-use-of-VLAs-in-C.patch
+++ /dev/null
@@ -1,128 +0,0 @@
-From 6e4736180fcaffdb06acf52fd3eb50ba5baa3d2a Mon Sep 17 00:00:00 2001
-From: Khem Raj <raj.khem@gmail.com>
-Date: Wed, 31 Jan 2024 21:04:28 -0800
-Subject: [PATCH] options: Replace use of VLAs in C++
-
-Clang++ 18 is fussy about this with new warning checks.
-
- ../git/src/apps/common/options.cpp:882:20: error: variable length arrays in C++ are a Clang extension [-Werror,-Wvla-cxx-extension]
- 882 | char shortOptions[optionsMap_.size() * 3 + 2];
- | ^~~~~~~~~~~~~~~~~~~~~~~~~~
-
-Therefore replace using VLAs with alloca and malloc/free
-
-Upstream-Status: Submitted [https://lists.libcamera.org/pipermail/libcamera-devel/2024-February/040381.html]
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
----
- src/apps/common/options.cpp | 12 ++++++++++--
- src/libcamera/ipc_unixsocket.cpp | 13 +++++++++----
- 2 files changed, 19 insertions(+), 6 deletions(-)
-
-diff --git a/src/apps/common/options.cpp b/src/apps/common/options.cpp
-index 4f7e8691..3656f3c1 100644
---- a/src/apps/common/options.cpp
-+++ b/src/apps/common/options.cpp
-@@ -879,8 +879,8 @@ OptionsParser::Options OptionsParser::parse(int argc, char **argv)
- * Allocate short and long options arrays large enough to contain all
- * options.
- */
-- char shortOptions[optionsMap_.size() * 3 + 2];
-- struct option longOptions[optionsMap_.size() + 1];
-+ char *shortOptions = (char*)malloc(optionsMap_.size() * 3 + 2);
-+ struct option *longOptions = (struct option*)malloc(sizeof(struct option) * (optionsMap_.size() + 1));
- unsigned int ids = 0;
- unsigned int idl = 0;
-
-@@ -935,12 +935,16 @@ OptionsParser::Options OptionsParser::parse(int argc, char **argv)
- std::cerr << argv[optind - 1] << std::endl;
-
- usage();
-+ free(shortOptions);
-+ free(longOptions);
- return options;
- }
-
- const Option &option = *optionsMap_[c];
- if (!parseValue(option, optarg, &options)) {
- usage();
-+ free(shortOptions);
-+ free(longOptions);
- return options;
- }
- }
-@@ -949,10 +953,14 @@ OptionsParser::Options OptionsParser::parse(int argc, char **argv)
- std::cerr << "Invalid non-option argument '" << argv[optind]
- << "'" << std::endl;
- usage();
-+ free(shortOptions);
-+ free(longOptions);
- return options;
- }
-
- options.valid_ = true;
-+ free(shortOptions);
-+ free(longOptions);
- return options;
- }
-
-diff --git a/src/libcamera/ipc_unixsocket.cpp b/src/libcamera/ipc_unixsocket.cpp
-index 1980d374..3bd861cb 100644
---- a/src/libcamera/ipc_unixsocket.cpp
-+++ b/src/libcamera/ipc_unixsocket.cpp
-@@ -8,6 +8,7 @@
- #include "libcamera/internal/ipc_unixsocket.h"
-
- #include <array>
-+#include <cstdint>
- #include <poll.h>
- #include <string.h>
- #include <sys/socket.h>
-@@ -247,8 +248,8 @@ int IPCUnixSocket::sendData(const void *buffer, size_t length,
- iov[0].iov_base = const_cast<void *>(buffer);
- iov[0].iov_len = length;
-
-- char buf[CMSG_SPACE(num * sizeof(uint32_t))];
-- memset(buf, 0, sizeof(buf));
-+ char *buf = (char*)malloc(CMSG_SPACE(num * sizeof(uint32_t)));
-+ memset((void*)buf, 0, sizeof(buf));
-
- struct cmsghdr *cmsg = (struct cmsghdr *)buf;
- cmsg->cmsg_len = CMSG_LEN(num * sizeof(uint32_t));
-@@ -270,9 +271,11 @@ int IPCUnixSocket::sendData(const void *buffer, size_t length,
- int ret = -errno;
- LOG(IPCUnixSocket, Error)
- << "Failed to sendmsg: " << strerror(-ret);
-+ free(buf);
- return ret;
- }
-
-+ free(buf);
- return 0;
- }
-
-@@ -283,8 +286,8 @@ int IPCUnixSocket::recvData(void *buffer, size_t length,
- iov[0].iov_base = buffer;
- iov[0].iov_len = length;
-
-- char buf[CMSG_SPACE(num * sizeof(uint32_t))];
-- memset(buf, 0, sizeof(buf));
-+ char *buf = (char*)malloc(CMSG_SPACE(num * sizeof(uint32_t)));
-+ memset((void*)buf, 0, sizeof(buf));
-
- struct cmsghdr *cmsg = (struct cmsghdr *)buf;
- cmsg->cmsg_len = CMSG_LEN(num * sizeof(uint32_t));
-@@ -305,12 +308,14 @@ int IPCUnixSocket::recvData(void *buffer, size_t length,
- if (ret != -EAGAIN)
- LOG(IPCUnixSocket, Error)
- << "Failed to recvmsg: " << strerror(-ret);
-+ free(buf);
- return ret;
- }
-
- if (fds)
- memcpy(fds, CMSG_DATA(cmsg), num * sizeof(uint32_t));
-
-+ free(buf);
- return 0;
- }
-
diff --git a/meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera_0.2.0.bb b/meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera_0.4.0.bb
index 45d6be31ec..682e56739f 100644
--- a/meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera_0.2.0.bb
+++ b/meta-openembedded/meta-multimedia/recipes-multimedia/libcamera/libcamera_0.4.0.bb
@@ -11,12 +11,9 @@ LIC_FILES_CHKSUM = "\
SRC_URI = " \
git://git.libcamera.org/libcamera/libcamera.git;protocol=https;branch=master \
file://0001-media_device-Add-bool-return-type-to-unlock.patch \
- file://0002-options-Replace-use-of-VLAs-in-C.patch \
- file://0001-rpi-Use-alloca-instead-of-variable-length-arrays.patch \
- file://0001-ipu3-Use-posix-basename.patch \
"
-SRCREV = "89227a428a82e724548399d35c98ea89566f9045"
+SRCREV = "35ed4b91291d9f3d08e4b51acfb51163e65df8f8"
PE = "1"
@@ -25,10 +22,11 @@ S = "${WORKDIR}/git"
DEPENDS = "python3-pyyaml-native python3-jinja2-native python3-ply-native python3-jinja2-native udev gnutls chrpath-native libevent libyaml"
DEPENDS += "${@bb.utils.contains('DISTRO_FEATURES', 'qt', 'qtbase qtbase-native', '', d)}"
-PACKAGES =+ "${PN}-gst"
+PACKAGES =+ "${PN}-gst ${PN}-pycamera"
PACKAGECONFIG ??= ""
PACKAGECONFIG[gst] = "-Dgstreamer=enabled,-Dgstreamer=disabled,gstreamer1.0 gstreamer1.0-plugins-base"
+PACKAGECONFIG[pycamera] = "-Dpycamera=enabled,-Dpycamera=disabled,python3 python3-pybind11"
LIBCAMERA_PIPELINES ??= "auto"
@@ -46,7 +44,7 @@ RDEPENDS:${PN} = "${@bb.utils.contains('DISTRO_FEATURES', 'wayland qt', 'qtwayla
inherit meson pkgconfig python3native
do_configure:prepend() {
- sed -i -e 's|py_compile=True,||' ${S}/utils/ipc/mojo/public/tools/mojom/mojom/generate/template_expander.py
+ sed -i -e 's|py_compile=True,||' ${S}/utils/codegen/ipc/mojo/public/tools/mojom/mojom/generate/template_expander.py
}
do_install:append() {
@@ -72,6 +70,7 @@ do_package_recalculate_ipa_signatures() {
FILES:${PN} += " ${libexecdir}/libcamera/v4l2-compat.so"
FILES:${PN}-gst = "${libdir}/gstreamer-1.0"
+FILES:${PN}-pycamera = "${PYTHON_SITEPACKAGES_DIR}/libcamera"
# libcamera-v4l2 explicitly sets _FILE_OFFSET_BITS=32 to get access to
# both 32 and 64 bit file APIs.
diff --git a/meta-openembedded/meta-multimedia/recipes-multimedia/pipewire/pipewire_1.0.5.bb b/meta-openembedded/meta-multimedia/recipes-multimedia/pipewire/pipewire_1.0.9.bb
index c8ac04d59a..c166725258 100644
--- a/meta-openembedded/meta-multimedia/recipes-multimedia/pipewire/pipewire_1.0.5.bb
+++ b/meta-openembedded/meta-multimedia/recipes-multimedia/pipewire/pipewire_1.0.9.bb
@@ -12,7 +12,7 @@ LIC_FILES_CHKSUM = " \
DEPENDS = "dbus ncurses"
-SRCREV = "a2287be601710eea0d073261223ec34b92384c8a"
+SRCREV = "467fd4a02e37f93a8d27448eef548e247f020466"
SRC_URI = "git://gitlab.freedesktop.org/pipewire/pipewire.git;branch=1.0;protocol=https"
S = "${WORKDIR}/git"
@@ -96,7 +96,7 @@ PACKAGECONFIG:class-target ??= " \
# as being in conflict.
PACKAGECONFIG[alsa] = "-Dalsa=enabled,-Dalsa=disabled,alsa-lib udev,,pipewire-alsa pipewire-alsa-card-profile"
PACKAGECONFIG[avahi] = "-Davahi=enabled,-Davahi=disabled,avahi"
-PACKAGECONFIG[bluez] = "-Dbluez5=enabled,-Dbluez5=disabled,bluez5 sbc"
+PACKAGECONFIG[bluez] = "-Dbluez5=enabled,-Dbluez5=disabled,bluez5 sbc glib-2.0-native"
PACKAGECONFIG[bluez-aac] = "-Dbluez5-codec-aac=enabled,-Dbluez5-codec-aac=disabled,fdk-aac"
PACKAGECONFIG[bluez-opus] = "-Dbluez5-codec-opus=enabled,-Dbluez5-codec-opus=disabled,libopus"
PACKAGECONFIG[bluez-lc3] = "-Dbluez5-codec-lc3=enabled,-Dbluez5-codec-lc3=disabled,liblc3"
@@ -157,6 +157,14 @@ remove_unused_installed_files() {
rm -f "${D}${datadir}/pipewire/minimal.conf"
}
+do_install:append() {
+ # The pipewire-alsa plugin needs the following files in /etc/alsa/conf.d/ to
+ # be picked up by alsa.
+ install -d ${D}${sysconfdir}/alsa/conf.d
+ ln -sf ${datadir}/alsa/alsa.conf.d/50-pipewire.conf ${D}${sysconfdir}/alsa/conf.d/50-pipewire.conf
+ ln -sf ${datadir}/alsa/alsa.conf.d/99-pipewire-default.conf ${D}${sysconfdir}/alsa/conf.d/99-pipewire-default.conf
+}
+
do_install[postfuncs] += "remove_unused_installed_files"
python split_dynamic_packages () {
@@ -328,6 +336,8 @@ RDEPENDS:${PN}-pulse += " \
FILES:${PN}-alsa = "\
${libdir}/alsa-lib/* \
${datadir}/alsa/alsa.conf.d/* \
+ ${sysconfdir}/alsa/conf.d/50-pipewire.conf \
+ ${sysconfdir}/alsa/conf.d/99-pipewire-default.conf \
"
# JACK drop-in libraries to redirect audio to pipewire.
diff --git a/meta-openembedded/meta-multimedia/recipes-multimedia/vorbis-tools/vorbis-tools/CVE-2023-43361.patch b/meta-openembedded/meta-multimedia/recipes-multimedia/vorbis-tools/vorbis-tools/CVE-2023-43361.patch
new file mode 100644
index 0000000000..69286907fa
--- /dev/null
+++ b/meta-openembedded/meta-multimedia/recipes-multimedia/vorbis-tools/vorbis-tools/CVE-2023-43361.patch
@@ -0,0 +1,57 @@
+From 5bb47f58582c15c2413564b741d1d95e7b566aa8 Mon Sep 17 00:00:00 2001
+From: Ralph Giles <giles@thaumas.net>
+Date: Sun, 17 Sep 2023 11:49:12 -0700
+Subject: [PATCH] oggenc: Don't assume the output path ends in a file name.
+
+oggenc attempts to create any specified directories in the output
+file path if they don't exist. The parser was assuming there was
+a final filename after the last directory separator, and so would
+try to read off the end of the argument if it was a bare directory
+such as `./` or `outdir/`. It also did not handle more than one
+consecutive separator. This corrects both issues.
+
+Thanks to Frank-Z7 (Zeng Yunxiang) at Huazhong University of Science
+and Technology (cse.hust.edu.cn) for the report.
+
+Fixes CVE-2023-43361.
+
+Upstream-Status: Backport [https://gitlab.xiph.org/xiph/vorbis-tools/-/commit/5bb47f58582c15c2413564b741d1d95e7b566aa8]
+CVE: CVE-2023-43361
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ oggenc/platform.c | 10 +++++++---
+ 1 file changed, 7 insertions(+), 3 deletions(-)
+
+diff --git a/oggenc/platform.c b/oggenc/platform.c
+index 6d9f4ef..d50ad99 100644
+--- a/oggenc/platform.c
++++ b/oggenc/platform.c
+@@ -136,18 +136,22 @@ int create_directories(char *fn, int isutf8)
+ {
+ char *end, *start;
+ struct stat statbuf;
+- char *segment = malloc(strlen(fn)+1);
++ const size_t fn_len = strlen(fn);
++ char *segment = malloc(fn_len+1);
+ #ifdef _WIN32
+ wchar_t seg[MAX_PATH+1];
+ #endif
+
+ start = fn;
+ #ifdef _WIN32
+- if(strlen(fn) >= 3 && isalpha(fn[0]) && fn[1]==':')
++ // Strip drive prefix
++ if(fn_len >= 3 && isalpha(fn[0]) && fn[1]==':') {
+ start = start+2;
++ }
+ #endif
+
+- while((end = strpbrk(start+1, PATH_SEPS)) != NULL)
++ // Loop through path segments, creating directories if necessary
++ while((end = strpbrk(start + strspn(start, PATH_SEPS), PATH_SEPS)) != NULL)
+ {
+ int rv;
+ memcpy(segment, fn, end-fn);
+--
+GitLab
+
diff --git a/meta-openembedded/meta-multimedia/recipes-multimedia/vorbis-tools/vorbis-tools_1.4.2.bb b/meta-openembedded/meta-multimedia/recipes-multimedia/vorbis-tools/vorbis-tools_1.4.2.bb
index 61a4aedb85..2cbd840138 100644
--- a/meta-openembedded/meta-multimedia/recipes-multimedia/vorbis-tools/vorbis-tools_1.4.2.bb
+++ b/meta-openembedded/meta-multimedia/recipes-multimedia/vorbis-tools/vorbis-tools_1.4.2.bb
@@ -13,6 +13,7 @@ DEPENDS = "libogg libvorbis"
SRC_URI = "http://downloads.xiph.org/releases/vorbis/${BP}.tar.gz \
file://gettext.patch \
file://0001-ogginfo-Include-utf8.h-for-missing-utf8_decode.patch \
+ file://CVE-2023-43361.patch \
"
SRC_URI[md5sum] = "998fca293bd4e4bdc2b96fb70f952f4e"
diff --git a/meta-openembedded/meta-networking/conf/include/non-repro-meta-networking.inc b/meta-openembedded/meta-networking/conf/include/non-repro-meta-networking.inc
index e0f448fe31..45eed5398e 100755
--- a/meta-openembedded/meta-networking/conf/include/non-repro-meta-networking.inc
+++ b/meta-openembedded/meta-networking/conf/include/non-repro-meta-networking.inc
@@ -15,7 +15,6 @@ KNOWN_NON_REPRO_META_NETWORKING = " \
htpdate-doc \
keepalived \
keepalived-dbg \
- kernel-module-mdio-netlink-6.6.17-yocto-standard \
libbearssl-staticdev \
libfko3 \
libfko-client \
@@ -25,7 +24,6 @@ KNOWN_NON_REPRO_META_NETWORKING = " \
libowfat-staticdev \
libruli-staticdev \
libsamba-util0 \
- mdio-netlink-dbg \
mosquitto \
mosquitto-dbg \
ncftp \
diff --git a/meta-openembedded/meta-networking/conf/include/ptest-packagelists-meta-networking.inc b/meta-openembedded/meta-networking/conf/include/ptest-packagelists-meta-networking.inc
index 7ec6f9063d..c3a2202de6 100644
--- a/meta-openembedded/meta-networking/conf/include/ptest-packagelists-meta-networking.inc
+++ b/meta-openembedded/meta-networking/conf/include/ptest-packagelists-meta-networking.inc
@@ -19,6 +19,7 @@ PTESTS_FAST_META_NETWORKING = "\
openhpi \
squid \
tcpdump \
+ wolfssl \
"
# firewalld currently hangs forever so disable it for now
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/blueman/blueman/0001-meson-DO-not-emit-absolute-path-when-S-B.patch b/meta-openembedded/meta-networking/recipes-connectivity/blueman/blueman/0001-meson-DO-not-emit-absolute-path-when-S-B.patch
new file mode 100644
index 0000000000..10f89a124c
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-connectivity/blueman/blueman/0001-meson-DO-not-emit-absolute-path-when-S-B.patch
@@ -0,0 +1,38 @@
+From 18af739fd96960bbc8c5db5dd290d2f9134cd347 Mon Sep 17 00:00:00 2001
+From: Khem Raj <raj.khem@gmail.com>
+Date: Wed, 14 Aug 2024 21:26:24 -0700
+Subject: [PATCH] meson: DO not emit absolute path when S != B
+
+build systems like OE build outside sourcetree in such cases it works
+ok but cython resolves the input file to absolute path and that gets
+emitted into genetate _blueman.c as module name, renders the build
+non-reproducible, wish cython had a better way to handle this but there
+is not, therefore tweak the meson build rule to account for specifying
+workdir to cython which will search the inputs correctly, and use
+meson's build_root to emit the output into build dir. This ensures that
+it becomes independent of source or build directories and cython does
+not generate the absolute paths into generate C code.
+
+See cython discussion on [1]
+
+[1] https://github.com/cython/cython/issues/5949
+
+Upstream-Status: Submitted [https://github.com/blueman-project/blueman/pull/2461]
+Signed-off-by: Khem Raj <raj.khem@gmail.com>
+---
+ module/meson.build | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/module/meson.build b/module/meson.build
+index 096ad7c8..e3d96f17 100644
+--- a/module/meson.build
++++ b/module/meson.build
+@@ -4,7 +4,7 @@ blueman_c = custom_target(
+ 'blueman_c',
+ output: '_blueman.c',
+ input: '_blueman.pyx',
+- command: [cython, '--output-file', '@OUTPUT@', '@INPUT@'])
++ command: [cython, '-w', meson.source_root(), '--output-file', meson.build_root() + '/' + '@OUTPUT@', '@INPUT@'])
+
+ sources = [
+ blueman_c,
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/blueman/blueman_2.3.5.bb b/meta-openembedded/meta-networking/recipes-connectivity/blueman/blueman_2.3.5.bb
index 0374d23f0c..4174da721d 100644
--- a/meta-openembedded/meta-networking/recipes-connectivity/blueman/blueman_2.3.5.bb
+++ b/meta-openembedded/meta-networking/recipes-connectivity/blueman/blueman_2.3.5.bb
@@ -13,6 +13,7 @@ SRC_URI = " \
file://0001-Search-for-cython3.patch \
file://0002-fix-fail-to-enable-bluetooth.patch \
file://0001-meson-add-pythoninstalldir-option.patch \
+ file://0001-meson-DO-not-emit-absolute-path-when-S-B.patch \
"
S = "${WORKDIR}/git"
SRCREV = "c85e7afb8d6547d4c35b7b639124de8e999c3650"
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/civetweb/civetweb/0001-Fix-heap-overflow-in-directory-URI-slash-redirection.patch b/meta-openembedded/meta-networking/recipes-connectivity/civetweb/civetweb/0001-Fix-heap-overflow-in-directory-URI-slash-redirection.patch
new file mode 100644
index 0000000000..667cb9c2f0
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-connectivity/civetweb/civetweb/0001-Fix-heap-overflow-in-directory-URI-slash-redirection.patch
@@ -0,0 +1,57 @@
+From e5e639d42a94b2585fe5123cb123963c6f04c3f5 Mon Sep 17 00:00:00 2001
+From: krispybyte <krispybyte@proton.me>
+Date: Sat, 21 Jun 2025 23:33:50 +0300
+Subject: [PATCH] Fix heap overflow in directory URI slash redirection
+
+CVE: CVE-2025-55763
+
+Upstream-Status: Backport [https://github.com/civetweb/civetweb/pull/1347/commits/76e222bcb77ba8452e5da4e82ae6cecd499c25e0]
+
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ src/civetweb.c | 23 ++++++++++++++++++-----
+ 1 file changed, 18 insertions(+), 5 deletions(-)
+
+diff --git a/src/civetweb.c b/src/civetweb.c
+index 9e321edf..5452b36d 100644
+--- a/src/civetweb.c
++++ b/src/civetweb.c
+@@ -15242,7 +15242,6 @@ handle_request(struct mg_connection *conn)
+ /* 12. Directory uris should end with a slash */
+ if (file.stat.is_directory && ((uri_len = (int)strlen(ri->local_uri)) > 0)
+ && (ri->local_uri[uri_len - 1] != '/')) {
+-
+ /* Path + server root */
+ size_t buflen = UTF8_PATH_MAX * 2 + 2;
+ char *new_path;
+@@ -15255,12 +15254,26 @@ handle_request(struct mg_connection *conn)
+ mg_send_http_error(conn, 500, "out or memory");
+ } else {
+ mg_get_request_link(conn, new_path, buflen - 1);
+- strcat(new_path, "/");
++
++ size_t len = strlen(new_path);
++ if (len + 1 < buflen) {
++ new_path[len] = '/';
++ new_path[len + 1] = '\0';
++ len += 1;
++ }
++
+ if (ri->query_string) {
+- /* Append ? and query string */
+- strcat(new_path, "?");
+- strcat(new_path, ri->query_string);
++ if (len + 1 < buflen) {
++ new_path[len] = '?';
++ new_path[len + 1] = '\0';
++ len += 1;
++ }
++
++ /* Append with size of space left for query string + null terminator */
++ size_t max_append = buflen - len - 1;
++ strncat(new_path, ri->query_string, max_append);
+ }
++
+ mg_send_http_redirect(conn, new_path, 301);
+ mg_free(new_path);
+ }
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/civetweb/civetweb_1.16.bb b/meta-openembedded/meta-networking/recipes-connectivity/civetweb/civetweb_1.16.bb
index f5a699d5be..a546efca7b 100644
--- a/meta-openembedded/meta-networking/recipes-connectivity/civetweb/civetweb_1.16.bb
+++ b/meta-openembedded/meta-networking/recipes-connectivity/civetweb/civetweb_1.16.bb
@@ -8,6 +8,7 @@ SRCREV = "d7ba35bbb649209c66e582d5a0244ba988a15159"
SRC_URI = "git://github.com/civetweb/civetweb.git;branch=master;protocol=https \
file://0001-Unittest-Link-librt-and-libm-using-l-option.patch \
+ file://0001-Fix-heap-overflow-in-directory-URI-slash-redirection.patch \
"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/freeradius/freeradius_3.2.3.bb b/meta-openembedded/meta-networking/recipes-connectivity/freeradius/freeradius_3.2.5.bb
index 7ea63a65d3..70f2496170 100644
--- a/meta-openembedded/meta-networking/recipes-connectivity/freeradius/freeradius_3.2.3.bb
+++ b/meta-openembedded/meta-networking/recipes-connectivity/freeradius/freeradius_3.2.5.bb
@@ -39,7 +39,7 @@ SRC_URI = "git://github.com/FreeRADIUS/freeradius-server.git;branch=v3.2.x;lfs=0
raddbdir = "${sysconfdir}/${MLPREFIX}raddb"
-SRCREV = "db3d1924d9a2e8d37c43872932621f69cfdbb099"
+SRCREV = "a7acce80f5ba2271d9aeb737a4a91a5bf8317f31"
UPSTREAM_CHECK_GITTAGREGEX = "release_(?P<pver>\d+(\_\d+)+)"
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/libiec61850/files/CVE-2024-26529.patch b/meta-openembedded/meta-networking/recipes-connectivity/libiec61850/files/CVE-2024-26529.patch
new file mode 100644
index 0000000000..ea3f472f30
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-connectivity/libiec61850/files/CVE-2024-26529.patch
@@ -0,0 +1,33 @@
+From e29799cba6f1d08cf6463a2b190c0e6502b885df Mon Sep 17 00:00:00 2001
+From: Michael Zillgith <michael.zillgith@mz-automation.de>
+Date: Fri, 2 Feb 2024 06:44:47 +0000
+Subject: [PATCH] CVE-2024-26529
+
+fixed - null pointer dereference in mmsServer_handleDeleteNamedVariableListRequest when receiving malformed message (LIB61850-430)
+
+CVE: CVE-2024-26529
+Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/cf94d64206cf53298edf4799a75b31657bb7cbb3]
+
+(cherry picked from commit cf94d64206cf53298edf4799a75b31657bb7cbb3)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/mms/iso_mms/server/mms_named_variable_list_service.c | 6 ++++++
+ 1 file changed, 6 insertions(+)
+
+diff --git a/src/mms/iso_mms/server/mms_named_variable_list_service.c b/src/mms/iso_mms/server/mms_named_variable_list_service.c
+index 3a27061c..3365f771 100644
+--- a/src/mms/iso_mms/server/mms_named_variable_list_service.c
++++ b/src/mms/iso_mms/server/mms_named_variable_list_service.c
+@@ -140,6 +140,12 @@ mmsServer_handleDeleteNamedVariableListRequest(MmsServerConnection connection,
+ mmsMsg_createMmsRejectPdu(&invokeId, MMS_ERROR_REJECT_INVALID_PDU, response);
+ goto exit_function;
+ }
++
++ if (request->listOfVariableListName == NULL)
++ {
++ mmsMsg_createMmsRejectPdu(&invokeId, MMS_ERROR_REJECT_INVALID_PDU, response);
++ goto exit_function;
++ }
+
+ long scopeOfDelete = DeleteNamedVariableListRequest__scopeOfDelete_specific;
+
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/libiec61850/files/CVE-2024-45970.patch b/meta-openembedded/meta-networking/recipes-connectivity/libiec61850/files/CVE-2024-45970.patch
new file mode 100644
index 0000000000..d0f10287ba
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-connectivity/libiec61850/files/CVE-2024-45970.patch
@@ -0,0 +1,74 @@
+From d5bd7cbf26b0254ce068ba7d940c26adbf9ce8e8 Mon Sep 17 00:00:00 2001
+From: Michael Zillgith <michael.zillgith@mz-automation.de>
+Date: Tue, 23 Jul 2024 18:50:15 +0100
+Subject: [PATCH] CVE-2024-45970
+
+fixed potential buffer overflows in MMS client file service handling (LIB61850-449)
+
+CVE: CVE-2024-45970
+Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/ac925fae8e281ac6defcd630e9dd756264e9c5bc]
+
+(cherry picked from commit ac925fae8e281ac6defcd630e9dd756264e9c5bc)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/mms/iso_mms/client/mms_client_files.c | 23 +++++++++++++++++++----
+ 1 file changed, 19 insertions(+), 4 deletions(-)
+
+diff --git a/src/mms/iso_mms/client/mms_client_files.c b/src/mms/iso_mms/client/mms_client_files.c
+index 4fca418e..935ba1a4 100644
+--- a/src/mms/iso_mms/client/mms_client_files.c
++++ b/src/mms/iso_mms/client/mms_client_files.c
+@@ -487,8 +487,13 @@ parseFileAttributes(uint8_t* buffer, int bufPos, int maxBufPos, uint32_t* fileSi
+ break;
+ case 0x81: /* lastModified */
+ {
+- if (lastModified != NULL) {
++ if (lastModified != NULL)
++ {
+ char gtString[40];
++
++ if (length > sizeof(gtString) - 1)
++ return false; /* lastModified string too long */
++
+ memcpy(gtString, buffer + bufPos, length);
+ gtString[length] = 0;
+ *lastModified = Conversions_generalizedTimeToMsTime(gtString);
+@@ -515,12 +520,14 @@ parseDirectoryEntry(uint8_t* buffer, int bufPos, int maxBufPos, uint32_t invokeI
+ uint32_t fileSize = 0;
+ uint64_t lastModified = 0;
+
+- while (bufPos < maxBufPos) {
++ while (bufPos < maxBufPos)
++ {
+ uint8_t tag = buffer[bufPos++];
+ int length;
+
+ bufPos = BerDecoder_decodeLength(buffer, &length, bufPos, maxBufPos);
+- if (bufPos < 0) {
++ if (bufPos < 0)
++ {
+ if (DEBUG_MMS_CLIENT)
+ printf("MMS_CLIENT: invalid length field\n");
+ return false;
+@@ -534,12 +541,20 @@ parseDirectoryEntry(uint8_t* buffer, int bufPos, int maxBufPos, uint32_t invokeI
+ tag = buffer[bufPos++];
+
+ bufPos = BerDecoder_decodeLength(buffer, &length, bufPos, maxBufPos);
+- if (bufPos < 0) {
++ if (bufPos < 0)
++ {
+ if (DEBUG_MMS_CLIENT)
+ printf("MMS_CLIENT: invalid length field\n");
+ return false;
+ }
+
++ if (length > (sizeof(fileNameMemory) - 1))
++ {
++ if (DEBUG_MMS_CLIENT)
++ printf("MMS_CLIENT: filename too long\n");
++ return false;
++ }
++
+ memcpy(filename, buffer + bufPos, length);
+ filename[length] = 0;
+
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/libiec61850/files/CVE-2024-45971.patch b/meta-openembedded/meta-networking/recipes-connectivity/libiec61850/files/CVE-2024-45971.patch
new file mode 100644
index 0000000000..bc71261f3c
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-connectivity/libiec61850/files/CVE-2024-45971.patch
@@ -0,0 +1,218 @@
+From b9bebc0d74998195422d104e4d430e2511d6c40f Mon Sep 17 00:00:00 2001
+From: Michael Zillgith <michael.zillgith@mz-automation.de>
+Date: Mon, 22 Jul 2024 16:34:03 +0100
+Subject: [PATCH] CVE-2024-45971
+
+LIB61850-447: replaced unsafe function StringUtils_createStringFromBufferInBuffer with function with length check to not exceed target buffer
+
+CVE: CVE-2024-45971
+Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0]
+
+(cherry picked from commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/common/inc/string_utilities.h | 3 ++
+ src/common/string_utilities.c | 12 +++++
+ src/iec61850/server/mms_mapping/mms_mapping.c | 6 ++-
+ src/mms/iso_mms/client/mms_client_identify.c | 6 +--
+ .../server/mms_named_variable_list_service.c | 52 +++++++++----------
+ 5 files changed, 48 insertions(+), 31 deletions(-)
+
+diff --git a/src/common/inc/string_utilities.h b/src/common/inc/string_utilities.h
+index b6b238ff..9a5d868a 100644
+--- a/src/common/inc/string_utilities.h
++++ b/src/common/inc/string_utilities.h
+@@ -63,6 +63,9 @@ StringUtils_createStringFromBuffer(const uint8_t* buf, int size);
+ LIB61850_INTERNAL char*
+ StringUtils_createStringFromBufferInBuffer(char* newString, const uint8_t* buf, int size);
+
++LIB61850_INTERNAL char*
++StringUtils_createStringFromBufferInBufferMax(char* newString, const uint8_t* buf, int size, int maxBufSize);
++
+ LIB61850_INTERNAL void
+ StringUtils_replace(char* string, char oldChar, char newChar);
+
+diff --git a/src/common/string_utilities.c b/src/common/string_utilities.c
+index 37e62ad7..378acbde 100644
+--- a/src/common/string_utilities.c
++++ b/src/common/string_utilities.c
+@@ -85,6 +85,18 @@ StringUtils_createStringFromBufferInBuffer(char* newString, const uint8_t* buf,
+ return newString;
+ }
+
++char*
++StringUtils_createStringFromBufferInBufferMax(char* newString, const uint8_t* buf, int size, int maxBufSize)
++{
++ if (size >= maxBufSize)
++ size = maxBufSize - 1;
++
++ memcpy(newString, buf, size);
++ newString[size] = 0;
++
++ return newString;
++}
++
+ char*
+ StringUtils_createStringInBuffer(char* newStr, int bufSize, int count, ...)
+ {
+diff --git a/src/iec61850/server/mms_mapping/mms_mapping.c b/src/iec61850/server/mms_mapping/mms_mapping.c
+index 707e8b57..4a700a27 100644
+--- a/src/iec61850/server/mms_mapping/mms_mapping.c
++++ b/src/iec61850/server/mms_mapping/mms_mapping.c
+@@ -3268,7 +3268,9 @@ mmsReadAccessHandler (void* parameter, MmsDomain* domain, char* variableId, MmsS
+ }
+ else
+ {
+- StringUtils_createStringFromBufferInBuffer(str, (uint8_t*) variableId, separator - variableId);
++ char str[65];
++
++ StringUtils_createStringFromBufferInBufferMax(str, (uint8_t*) variableId, separator - variableId, sizeof(str));
+
+ LogicalNode* ln = LogicalDevice_getLogicalNode(ld, str);
+
+@@ -3286,7 +3288,7 @@ mmsReadAccessHandler (void* parameter, MmsDomain* domain, char* variableId, MmsS
+ else {
+ doEnd--;
+
+- StringUtils_createStringFromBufferInBuffer(str, (uint8_t*) (doStart + 1), doEnd - doStart);
++ StringUtils_createStringFromBufferInBufferMax(str, (uint8_t*) (doStart + 1), doEnd - doStart, sizeof(str));
+ }
+
+ if (fc == IEC61850_FC_SP) {
+diff --git a/src/mms/iso_mms/client/mms_client_identify.c b/src/mms/iso_mms/client/mms_client_identify.c
+index 831b439d..c679a423 100644
+--- a/src/mms/iso_mms/client/mms_client_identify.c
++++ b/src/mms/iso_mms/client/mms_client_identify.c
+@@ -84,15 +84,15 @@ mmsClient_parseIdentifyResponse(MmsConnection self, ByteBuffer* response, uint32
+
+ switch (tag) {
+ case 0x80: /* vendorName */
+- vendorName = StringUtils_createStringFromBufferInBuffer(vendorNameBuf, buffer + bufPos, length);
++ vendorName = StringUtils_createStringFromBufferInBufferMax(vendorNameBuf, buffer + bufPos, length, sizeof(vendorNameBuf));
+ bufPos += length;
+ break;
+ case 0x81: /* modelName */
+- modelName = StringUtils_createStringFromBufferInBuffer(modelNameBuf, buffer + bufPos, length);
++ modelName = StringUtils_createStringFromBufferInBufferMax(modelNameBuf, buffer + bufPos, length, sizeof(modelNameBuf));
+ bufPos += length;
+ break;
+ case 0x82: /* revision */
+- revision = StringUtils_createStringFromBufferInBuffer(revisionBuf, buffer + bufPos, length);
++ revision = StringUtils_createStringFromBufferInBufferMax(revisionBuf, buffer + bufPos, length, sizeof (revisionBuf));
+ bufPos += length;
+ break;
+ case 0x83: /* list of abstract syntaxes */
+diff --git a/src/mms/iso_mms/server/mms_named_variable_list_service.c b/src/mms/iso_mms/server/mms_named_variable_list_service.c
+index 3365f771..757d0ed3 100644
+--- a/src/mms/iso_mms/server/mms_named_variable_list_service.c
++++ b/src/mms/iso_mms/server/mms_named_variable_list_service.c
+@@ -401,13 +401,13 @@ createNamedVariableList(MmsServer server, MmsDomain* domain, MmsDevice* device,
+ char variableName[65];
+ char domainId[65];
+
+- StringUtils_createStringFromBufferInBuffer(variableName,
+- varSpec->choice.name.choice.domainspecific.itemId.buf,
+- varSpec->choice.name.choice.domainspecific.itemId.size);
++ StringUtils_createStringFromBufferInBufferMax(variableName,
++ varSpec->choice.name.choice.domainspecific.itemId.buf,
++ varSpec->choice.name.choice.domainspecific.itemId.size, sizeof(variableName));
+
+- StringUtils_createStringFromBufferInBuffer(domainId,
+- varSpec->choice.name.choice.domainspecific.domainId.buf,
+- varSpec->choice.name.choice.domainspecific.domainId.size);
++ StringUtils_createStringFromBufferInBufferMax(domainId,
++ varSpec->choice.name.choice.domainspecific.domainId.buf,
++ varSpec->choice.name.choice.domainspecific.domainId.size, sizeof(domainId));
+
+ MmsDomain* elementDomain = MmsDevice_getDomain(device, domainId);
+
+@@ -494,9 +494,9 @@ mmsServer_handleDefineNamedVariableListRequest(
+ goto exit_free_struct;
+ }
+
+- StringUtils_createStringFromBufferInBuffer(domainName,
+- request->variableListName.choice.domainspecific.domainId.buf,
+- request->variableListName.choice.domainspecific.domainId.size);
++ StringUtils_createStringFromBufferInBufferMax(domainName,
++ request->variableListName.choice.domainspecific.domainId.buf,
++ request->variableListName.choice.domainspecific.domainId.size, sizeof(domainName));
+
+ MmsDomain* domain = MmsDevice_getDomain(device, domainName);
+
+@@ -517,9 +517,9 @@ mmsServer_handleDefineNamedVariableListRequest(
+ goto exit_free_struct;
+ }
+
+- StringUtils_createStringFromBufferInBuffer(variableListName,
+- request->variableListName.choice.domainspecific.itemId.buf,
+- request->variableListName.choice.domainspecific.itemId.size);
++ StringUtils_createStringFromBufferInBufferMax(variableListName,
++ request->variableListName.choice.domainspecific.itemId.buf,
++ request->variableListName.choice.domainspecific.itemId.size, sizeof(variableListName));
+
+ if (MmsDomain_getNamedVariableList(domain, variableListName) != NULL) {
+ mmsMsg_createServiceErrorPdu(invokeId, response, MMS_ERROR_DEFINITION_OBJECT_EXISTS);
+@@ -567,9 +567,9 @@ mmsServer_handleDefineNamedVariableListRequest(
+ goto exit_free_struct;
+ }
+
+- StringUtils_createStringFromBufferInBuffer(variableListName,
+- request->variableListName.choice.aaspecific.buf,
+- request->variableListName.choice.aaspecific.size);
++ StringUtils_createStringFromBufferInBufferMax(variableListName,
++ request->variableListName.choice.aaspecific.buf,
++ request->variableListName.choice.aaspecific.size, sizeof(variableListName));
+
+ if (MmsServerConnection_getNamedVariableList(connection, variableListName) != NULL) {
+ mmsMsg_createServiceErrorPdu(invokeId, response, MMS_ERROR_DEFINITION_OBJECT_EXISTS);
+@@ -611,9 +611,9 @@ mmsServer_handleDefineNamedVariableListRequest(
+ goto exit_free_struct;
+ }
+
+- StringUtils_createStringFromBufferInBuffer(variableListName,
+- request->variableListName.choice.vmdspecific.buf,
+- request->variableListName.choice.vmdspecific.size);
++ StringUtils_createStringFromBufferInBufferMax(variableListName,
++ request->variableListName.choice.vmdspecific.buf,
++ request->variableListName.choice.vmdspecific.size, sizeof(variableListName));
+
+ if (mmsServer_getNamedVariableListWithName(MmsDevice_getNamedVariableLists(connection->server->device), variableListName) != NULL) {
+ mmsMsg_createServiceErrorPdu(invokeId, response, MMS_ERROR_DEFINITION_OBJECT_EXISTS);
+@@ -757,11 +757,11 @@ mmsServer_handleGetNamedVariableListAttributesRequest(
+ goto exit_function;
+ }
+
+- StringUtils_createStringFromBufferInBuffer(domainName, request->choice.domainspecific.domainId.buf,
+- request->choice.domainspecific.domainId.size);
++ StringUtils_createStringFromBufferInBufferMax(domainName, request->choice.domainspecific.domainId.buf,
++ request->choice.domainspecific.domainId.size, sizeof(domainName));
+
+- StringUtils_createStringFromBufferInBuffer(itemName, request->choice.domainspecific.itemId.buf,
+- request->choice.domainspecific.itemId.size);
++ StringUtils_createStringFromBufferInBufferMax(itemName, request->choice.domainspecific.itemId.buf,
++ request->choice.domainspecific.itemId.size, sizeof(itemName));
+
+ MmsDevice* mmsDevice = MmsServer_getDevice(connection->server);
+
+@@ -798,8 +798,8 @@ mmsServer_handleGetNamedVariableListAttributesRequest(
+ goto exit_function;
+ }
+
+- StringUtils_createStringFromBufferInBuffer(listName, request->choice.aaspecific.buf,
+- request->choice.aaspecific.size);
++ StringUtils_createStringFromBufferInBufferMax(listName, request->choice.aaspecific.buf,
++ request->choice.aaspecific.size, sizeof(listName));
+
+ MmsNamedVariableList varList = MmsServerConnection_getNamedVariableList(connection, listName);
+
+@@ -817,8 +817,8 @@ mmsServer_handleGetNamedVariableListAttributesRequest(
+ goto exit_function;
+ }
+
+- StringUtils_createStringFromBufferInBuffer(listName, request->choice.vmdspecific.buf,
+- request->choice.vmdspecific.size);
++ StringUtils_createStringFromBufferInBufferMax(listName, request->choice.vmdspecific.buf,
++ request->choice.vmdspecific.size, sizeof(listName));
+
+ MmsDevice* mmsDevice = MmsServer_getDevice(connection->server);
+
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.5.1.bb b/meta-openembedded/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.5.3.bb
index 63476d3495..20dd447c7e 100644
--- a/meta-openembedded/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.5.1.bb
+++ b/meta-openembedded/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.5.3.bb
@@ -13,11 +13,14 @@ SECTION = "console/network"
LICENSE = "GPL-3.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=d32239bcb673463ab874e80d47fae504"
DEPENDS = "swig-native python3"
-SRCREV = "210cf30897631fe2006ac50483caf8fd616622a2"
+SRCREV = "6f557c490f0b46ab5d7ef1b01bb3bc9fab3f442f"
SRC_URI = "git://github.com/mz-automation/${BPN}.git;branch=v1.5;protocol=https \
file://0001-pyiec61850-don-t-break-CMAKE_INSTALL_PATH-by-trying-.patch \
file://0001-pyiec61850-Use-CMAKE_INSTALL_LIBDIR-from-GNUInstallD.patch \
+ file://CVE-2024-26529.patch \
+ file://CVE-2024-45970.patch \
+ file://CVE-2024-45971.patch \
"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/mbedtls/mbedtls_2.28.8.bb b/meta-openembedded/meta-networking/recipes-connectivity/mbedtls/mbedtls_2.28.10.bb
index 301e655989..610fd0af5e 100644
--- a/meta-openembedded/meta-networking/recipes-connectivity/mbedtls/mbedtls_2.28.8.bb
+++ b/meta-openembedded/meta-networking/recipes-connectivity/mbedtls/mbedtls_2.28.10.bb
@@ -23,7 +23,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=379d5819937a6c2f1ef1630d341e026d"
SECTION = "libs"
S = "${WORKDIR}/git"
-SRCREV = "5a764e5555c64337ed17444410269ff21cb617b1"
+SRCREV = "2fc8413bfcb51354c8e679141b17b3f1a5942561"
SRC_URI = "git://github.com/Mbed-TLS/mbedtls.git;protocol=https;branch=mbedtls-2.28 \
file://run-ptest \
"
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/mbedtls/mbedtls_3.6.0.bb b/meta-openembedded/meta-networking/recipes-connectivity/mbedtls/mbedtls_3.6.5.bb
index 92a2de82a3..3e46d16ce5 100644
--- a/meta-openembedded/meta-networking/recipes-connectivity/mbedtls/mbedtls_3.6.0.bb
+++ b/meta-openembedded/meta-networking/recipes-connectivity/mbedtls/mbedtls_3.6.5.bb
@@ -23,13 +23,11 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=379d5819937a6c2f1ef1630d341e026d"
SECTION = "libs"
S = "${WORKDIR}/git"
-SRC_URI = "git://github.com/Mbed-TLS/mbedtls.git;protocol=https;branch=master \
- git://github.com/Mbed-TLS/mbedtls-framework.git;protocol=https;branch=main;destsuffix=git/framework;name=framework \
- file://run-ptest"
+SRC_URI = "gitsm://github.com/Mbed-TLS/mbedtls.git;protocol=https;branch=mbedtls-3.6 \
+ file://run-ptest \
+ "
-SRCREV = "2ca6c285a0dd3f33982dd57299012dacab1ff206"
-SRCREV_framework = "750634d3a51eb9d61b59fd5d801546927c946588"
-SRCREV_FORMAT .= "_framework"
+SRCREV = "e185d7fd85499c8ce5ca2a54f5cf8fe7dbe3f8df"
UPSTREAM_CHECK_GITTAGREGEX = "v(?P<pver>\d+(\.\d+)+)"
@@ -76,7 +74,8 @@ sysroot_stage_all:append() {
do_install_ptest () {
install -d ${D}${PTEST_PATH}/tests
+ install -d ${D}${PTEST_PATH}/framework
cp -f ${B}/tests/test_suite_* ${D}${PTEST_PATH}/tests/
find ${D}${PTEST_PATH}/tests/ -type f -name "*.c" -delete
- cp -fR ${S}/tests/data_files ${D}${PTEST_PATH}/tests/
+ cp -fR ${S}/framework/data_files ${D}${PTEST_PATH}/framework/
}
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/mosquitto/files/1571.patch b/meta-openembedded/meta-networking/recipes-connectivity/mosquitto/files/1571.patch
deleted file mode 100644
index 627638ec89..0000000000
--- a/meta-openembedded/meta-networking/recipes-connectivity/mosquitto/files/1571.patch
+++ /dev/null
@@ -1,22 +0,0 @@
-Upstream-Status: Submitted [https://github.com/eclipse/mosquitto/pull/1571]
-From 3fe5468f1bdca1bff1d18cf43c9e338f41aa9e32 Mon Sep 17 00:00:00 2001
-From: Gianfranco Costamagna <costamagnagianfranco@yahoo.it>
-Date: Wed, 22 Jan 2020 12:39:49 +0100
-Subject: [PATCH] Add dynamic symbols linking with cmake too
-
-Signed-off-by: Gianfranco Costamagna <costamagnagianfranco@yahoo.it>
----
- lib/CMakeLists.txt | 2 ++
- 1 file changed, 2 insertions(+)
-
---- a/lib/CMakeLists.txt
-+++ b/lib/CMakeLists.txt
-@@ -94,6 +94,8 @@
- OUTPUT_NAME mosquitto
- VERSION ${VERSION}
- SOVERSION 1
-+ LINK_DEPENDS ${CMAKE_CURRENT_SOURCE_DIR}/linker.version
-+ LINK_FLAGS "-Wl,--version-script=${CMAKE_CURRENT_SOURCE_DIR}/linker.version"
- )
-
- install(TARGETS libmosquitto
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/mosquitto/files/2894.patch b/meta-openembedded/meta-networking/recipes-connectivity/mosquitto/files/2894.patch
deleted file mode 100644
index 7374cbd26f..0000000000
--- a/meta-openembedded/meta-networking/recipes-connectivity/mosquitto/files/2894.patch
+++ /dev/null
@@ -1,25 +0,0 @@
-From: Joachim Zobel <jz-2017@heute-morgen.de>
-Date: Wed, 13 Sep 2023 09:55:34 +0200
-Subject: [PATCH] Link correctly with shared websockets library if needed see:
- https://github.com/eclipse/mosquitto/pull/2751
-
-Patch contributed by Joachim Zobel <jz-2017@heute-morgen.de> and Daniel Engberg <daniel.engberg.lists@pyret.net>
----
-Upstream-Status: Pending
-
- src/CMakeLists.txt | 2 +-
- 1 file changed, 1 insertion(+), 1 deletion(-)
-
-diff --git a/src/CMakeLists.txt b/src/CMakeLists.txt
-index 9380a04..dce8313 100644
---- a/src/CMakeLists.txt
-+++ b/src/CMakeLists.txt
-@@ -200,7 +200,7 @@ if (WITH_WEBSOCKETS)
- link_directories(${mosquitto_SOURCE_DIR})
- endif (WIN32)
- else (STATIC_WEBSOCKETS)
-- set (MOSQ_LIBS ${MOSQ_LIBS} websockets)
-+ set (MOSQ_LIBS ${MOSQ_LIBS} websockets_shared)
- endif (STATIC_WEBSOCKETS)
- endif (WITH_WEBSOCKETS)
-
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/mosquitto/mosquitto_2.0.18.bb b/meta-openembedded/meta-networking/recipes-connectivity/mosquitto/mosquitto_2.0.20.bb
index ea9eb4857b..2bc1303185 100644
--- a/meta-openembedded/meta-networking/recipes-connectivity/mosquitto/mosquitto_2.0.18.bb
+++ b/meta-openembedded/meta-networking/recipes-connectivity/mosquitto/mosquitto_2.0.20.bb
@@ -16,12 +16,10 @@ DEPENDS = "uthash cjson"
SRC_URI = "http://mosquitto.org/files/source/mosquitto-${PV}.tar.gz \
file://mosquitto.init \
- file://1571.patch \
- file://2894.patch \
file://2895.patch \
"
-SRC_URI[sha256sum] = "d665fe7d0032881b1371a47f34169ee4edab67903b2cd2b4c083822823f4448a"
+SRC_URI[sha256sum] = "ebd07d89d2a446a7f74100ad51272e4a8bf300b61634a7812e19f068f2759de8"
inherit systemd update-rc.d useradd cmake pkgconfig
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/nanomsg/nng_1.7.3.bb b/meta-openembedded/meta-networking/recipes-connectivity/nanomsg/nng_1.7.3.bb
index a6556249b7..9ae3b89371 100644
--- a/meta-openembedded/meta-networking/recipes-connectivity/nanomsg/nng_1.7.3.bb
+++ b/meta-openembedded/meta-networking/recipes-connectivity/nanomsg/nng_1.7.3.bb
@@ -5,7 +5,7 @@ SECTION = "libs/networking"
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=a41e579bb4326c21c774f8e51e41d8a3"
-SRC_URI = "git://github.com/nanomsg/nng.git;branch=master;protocol=https"
+SRC_URI = "git://github.com/nanomsg/nng.git;branch=main;protocol=https"
SRCREV = "85fbe7f9e4642b554d0d97f2e3ff2aa12978691a"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/networkmanager/networkmanager_1.46.0.bb b/meta-openembedded/meta-networking/recipes-connectivity/networkmanager/networkmanager_1.46.0.bb
index 8184fcf1a1..1b4003df18 100644
--- a/meta-openembedded/meta-networking/recipes-connectivity/networkmanager/networkmanager_1.46.0.bb
+++ b/meta-openembedded/meta-networking/recipes-connectivity/networkmanager/networkmanager_1.46.0.bb
@@ -99,7 +99,7 @@ PACKAGECONFIG[polkit] = "-Dpolkit=true,-Dpolkit=false,polkit"
PACKAGECONFIG[bluez5] = "-Dbluez5_dun=true,-Dbluez5_dun=false,bluez5"
# consolekit is not picked by shlibs, so add it to RDEPENDS too
PACKAGECONFIG[consolekit] = "-Dsession_tracking_consolekit=true,-Dsession_tracking_consolekit=false,consolekit,consolekit"
-PACKAGECONFIG[modemmanager] = "-Dmodem_manager=true,-Dmodem_manager=false,modemmanager mobile-broadband-provider-info,modemmanager mobile-broadband-provider-info"
+PACKAGECONFIG[modemmanager] = "-Dmodem_manager=true,-Dmodem_manager=false,modemmanager mobile-broadband-provider-info"
PACKAGECONFIG[ppp] = "-Dppp=true -Dpppd=${sbindir}/pppd,-Dppp=false,ppp"
PACKAGECONFIG[dnsmasq] = "-Ddnsmasq=${bindir}/dnsmasq"
PACKAGECONFIG[nss] = "-Dcrypto=nss,,nss"
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/rdist/rdist_6.1.5.bb b/meta-openembedded/meta-networking/recipes-connectivity/rdist/rdist_6.1.5.bb
index d81cc9a3d1..e6d99431be 100644
--- a/meta-openembedded/meta-networking/recipes-connectivity/rdist/rdist_6.1.5.bb
+++ b/meta-openembedded/meta-networking/recipes-connectivity/rdist/rdist_6.1.5.bb
@@ -38,7 +38,7 @@ DEPENDS = "bison-native"
inherit autotools-brokensep
-EXTRA_OEMAKE = "BIN_GROUP=root MAN_GROUP=root RDIST_MODE=755 RDISTD_MODE=755 MAN_MODE=644"
+EXTRA_OEMAKE = "CPPFLAGS='${CFLAGS}' BIN_GROUP=root MAN_GROUP=root RDIST_MODE=755 RDISTD_MODE=755 MAN_MODE=644"
# http://errors.yoctoproject.org/Errors/Details/186972/
COMPATIBLE_HOST:libc-musl = 'null'
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/samba/samba_4.19.6.bb b/meta-openembedded/meta-networking/recipes-connectivity/samba/samba_4.19.8.bb
index bd0309934b..429f983c93 100644
--- a/meta-openembedded/meta-networking/recipes-connectivity/samba/samba_4.19.6.bb
+++ b/meta-openembedded/meta-networking/recipes-connectivity/samba/samba_4.19.8.bb
@@ -31,7 +31,7 @@ SRC_URI:append:libc-musl = " \
file://samba-4.3.9-remove-getpwent_r.patch \
"
-SRC_URI[sha256sum] = "653b52095554dbc223c63b96af5cdf9e98c3e048549c5f56143d3b33dce1cef1"
+SRC_URI[sha256sum] = "1aeff76c207f383477ce4badebd154691c408d2e15b01b333c85eb775468ddf6"
UPSTREAM_CHECK_REGEX = "samba\-(?P<pver>4\.19(\.\d+)+).tar.gz"
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/tayga/tayga_0.9.2.bb b/meta-openembedded/meta-networking/recipes-connectivity/tayga/tayga_0.9.2.bb
index 36d35e6dee..40dbccb840 100644
--- a/meta-openembedded/meta-networking/recipes-connectivity/tayga/tayga_0.9.2.bb
+++ b/meta-openembedded/meta-networking/recipes-connectivity/tayga/tayga_0.9.2.bb
@@ -12,6 +12,8 @@ SRC_URI[sha256sum] = "2b1f7927a9d2dcff9095aff3c271924b052ccfd2faca9588b277431a44
SYSTEMD_PACKAGES = "${PN}"
SYSTEMD_SERVICE:${PN} = "tayga.service"
+EXTRA_OEMAKE += "CFLAGS='${CFLAGS}'"
+
do_install:append() {
install -m 0644 ${WORKDIR}/tayga.conf ${D}${sysconfdir}/tayga.conf
install -d ${D}${systemd_unitdir}/system/
@@ -19,3 +21,4 @@ do_install:append() {
}
inherit autotools systemd
+
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/wolfssl/files/run-ptest b/meta-openembedded/meta-networking/recipes-connectivity/wolfssl/files/run-ptest
new file mode 100644
index 0000000000..ff66f4ef6c
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-connectivity/wolfssl/files/run-ptest
@@ -0,0 +1,24 @@
+#!/bin/sh
+
+echo "############ Running Wolfssl Ptest ##########"
+
+log_file=ptest.log
+temp_dir=$(mktemp -d /tmp/wolfss_temp.XXXXXX)
+echo "Wolfssl ptest logs are stored in ${temp_dir}/${log_file}"
+
+./test/unit.test > "$temp_dir/$log_file" 2>&1
+
+echo "Test script returned: $?"
+
+MAGIC_SENTENCE=$(grep "unit_test: Success for all configured tests." $temp_dir/$log_file)
+
+if [ -n "$MAGIC_SENTENCE" ]; then
+ echo "$MAGIC_SENTENCE"
+ echo "PASS: Wolfssl"
+else
+ echo "#### Issue with at least one test !####"
+ echo "FAIL: Wolfssl"
+fi
+NUM_FAILS=$(grep -c "Failed" $temp_dir/$log_file)
+
+exit $NUM_FAILS
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/wolfssl/wolfssl_5.7.0.bb b/meta-openembedded/meta-networking/recipes-connectivity/wolfssl/wolfssl_5.7.0.bb
deleted file mode 100644
index 47c14dd1a1..0000000000
--- a/meta-openembedded/meta-networking/recipes-connectivity/wolfssl/wolfssl_5.7.0.bb
+++ /dev/null
@@ -1,22 +0,0 @@
-SUMMARY = "wolfSSL Lightweight Embedded SSL/TLS Library"
-DESCRIPTION = "wolfSSL, formerly CyaSSL, is a lightweight SSL library written \
- in C and optimized for embedded and RTOS environments. It can \
- be up to 20 times smaller than OpenSSL while still supporting \
- a full TLS client and server, up to TLS 1.3"
-HOMEPAGE = "https://www.wolfssl.com/products/wolfssl"
-BUGTRACKER = "https://github.com/wolfssl/wolfssl/issues"
-SECTION = "libs"
-LICENSE = "GPL-2.0-only"
-LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
-
-PROVIDES += "cyassl"
-RPROVIDES:${PN} = "cyassl"
-
-SRC_URI = "git://github.com/wolfSSL/wolfssl.git;protocol=https;branch=master"
-SRCREV = "8970ff4c34034dbb3594943d11f8c9d4c5512bd5"
-
-S = "${WORKDIR}/git"
-
-inherit autotools
-
-BBCLASSEXTEND += "native nativesdk"
diff --git a/meta-openembedded/meta-networking/recipes-connectivity/wolfssl/wolfssl_5.7.2.bb b/meta-openembedded/meta-networking/recipes-connectivity/wolfssl/wolfssl_5.7.2.bb
new file mode 100644
index 0000000000..8f484d6098
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-connectivity/wolfssl/wolfssl_5.7.2.bb
@@ -0,0 +1,44 @@
+SUMMARY = "wolfSSL Lightweight Embedded SSL/TLS Library"
+DESCRIPTION = "wolfSSL, formerly CyaSSL, is a lightweight SSL library written \
+ in C and optimized for embedded and RTOS environments. It can \
+ be up to 20 times smaller than OpenSSL while still supporting \
+ a full TLS client and server, up to TLS 1.3"
+HOMEPAGE = "https://www.wolfssl.com/products/wolfssl"
+BUGTRACKER = "https://github.com/wolfssl/wolfssl/issues"
+SECTION = "libs"
+LICENSE = "GPL-2.0-only"
+LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
+
+PROVIDES += "cyassl"
+RPROVIDES:${PN} = "cyassl"
+
+SRC_URI = " \
+ git://github.com/wolfSSL/wolfssl.git;protocol=https;branch=master \
+ file://run-ptest \
+"
+SRCREV = "00e42151ca061463ba6a95adb2290f678cbca472"
+
+S = "${WORKDIR}/git"
+
+inherit autotools ptest
+
+PACKAGECONFIG ?= "reproducible-build"
+
+PACKAGECONFIG[reproducible-build] = "--enable-reproducible-build,--disable-reproducible-build,"
+BBCLASSEXTEND += "native nativesdk"
+
+RDEPENDS:${PN}-ptest += " bash"
+
+do_install_ptest() {
+ # Prevent QA Error "package contains reference to TMPDIR [buildpaths]" for unit.test script
+ # Replace the occurences of ${B}/src with '${PTEST_PATH}'
+ sed -i 's|${B}/src|${PTEST_PATH}|g' ${B}/tests/unit.test
+
+ install -d ${D}${PTEST_PATH}/test
+
+ # create an empty folder examples, needed in wolfssl's tests/api.c to "Test loading path with no files"
+ install -d ${D}${PTEST_PATH}/examples
+ cp -rf ${B}/tests/. ${D}${PTEST_PATH}/test
+ cp -rf ${S}/certs ${D}${PTEST_PATH}
+ cp -rf ${S}/tests ${D}${PTEST_PATH}
+}
diff --git a/meta-openembedded/meta-networking/recipes-core/images/meta-networking-image-ptest.bb b/meta-openembedded/meta-networking/recipes-core/images/meta-networking-image-ptest.bb
index 295da982ec..b6238d6100 100644
--- a/meta-openembedded/meta-networking/recipes-core/images/meta-networking-image-ptest.bb
+++ b/meta-openembedded/meta-networking/recipes-core/images/meta-networking-image-ptest.bb
@@ -20,6 +20,7 @@ BBCLASSEXTEND = "${@' '.join(['mcextend:'+x for x in d.getVar('PTESTS_META_NETWO
# box) and explicitly add up to 1500MB.
IMAGE_OVERHEAD_FACTOR = "1.0"
IMAGE_ROOTFS_EXTRA_SPACE = "324288"
+IMAGE_ROOTFS_EXTRA_SPACE:virtclass-mcextend-wolfssl = "714288"
# If a particular ptest needs more space, it can be customized:
#IMAGE_ROOTFS_EXTRA_SPACE:virtclass-mcextend-<pn> = "1024288"
diff --git a/meta-openembedded/meta-networking/recipes-daemons/keepalived/keepalived/0001-configure.ac-Do-not-emit-compiler-flags-into-object-.patch b/meta-openembedded/meta-networking/recipes-daemons/keepalived/keepalived/0001-configure.ac-Do-not-emit-compiler-flags-into-object-.patch
new file mode 100644
index 0000000000..1f9f8b30b1
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-daemons/keepalived/keepalived/0001-configure.ac-Do-not-emit-compiler-flags-into-object-.patch
@@ -0,0 +1,29 @@
+From 5b1b04356f3efc08ae279cafc6ee86df11f10c9a Mon Sep 17 00:00:00 2001
+From: Khem Raj <raj.khem@gmail.com>
+Date: Thu, 15 Aug 2024 23:13:02 -0700
+Subject: [PATCH] configure.ac: Do not emit compiler flags into object files
+
+They contain options which have absolute paths in them e.g. --sysroot
+therefore do not record them and make build reproducible
+
+Upstream-Status: Inappropriate [OE-Specific]
+
+Signed-off-by: Khem Raj <raj.khem@gmail.com>
+---
+ configure.ac | 3 +--
+ 1 file changed, 1 insertion(+), 2 deletions(-)
+
+diff --git a/configure.ac b/configure.ac
+index fae16f1..677b94a 100644
+--- a/configure.ac
++++ b/configure.ac
+@@ -904,8 +904,7 @@ if test "$enable_hardening" != no; then
+ "-Wp,-D_FORTIFY_SOURCE=2" \
+ "-fexceptions" \
+ "-fstack-protector-strong" \
+- "--param=ssp-buffer-size=4" \
+- "-grecord-gcc-switches"
++ "--param=ssp-buffer-size=4"
+ do
+ AC_MSG_CHECKING([for $FLAG support])
+ CFLAGS="$CFLAGS $FLAG"
diff --git a/meta-openembedded/meta-networking/recipes-daemons/keepalived/keepalived_2.2.8.bb b/meta-openembedded/meta-networking/recipes-daemons/keepalived/keepalived_2.2.8.bb
index 85f4a6aa59..c4d59d3caa 100644
--- a/meta-openembedded/meta-networking/recipes-daemons/keepalived/keepalived_2.2.8.bb
+++ b/meta-openembedded/meta-networking/recipes-daemons/keepalived/keepalived_2.2.8.bb
@@ -11,6 +11,7 @@ LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
SRC_URI = "http://www.keepalived.org/software/${BP}.tar.gz \
+ file://0001-configure.ac-Do-not-emit-compiler-flags-into-object-.patch \
"
SRC_URI[sha256sum] = "85882eb62974f395d4c631be990a41a839594a7e62fbfebcb5649a937a7a1bb6"
UPSTREAM_CHECK_URI = "https://github.com/acassen/keepalived/releases"
@@ -30,6 +31,10 @@ EXTRA_OEMAKE = "initdir=${sysconfdir}/init.d"
export EXTRA_CFLAGS = "${CFLAGS}"
+do_configure:append() {
+ sed -i -e 's|${WORKDIR}|<scrubbed>|g' ${B}/lib/config.h
+}
+
do_install:append() {
if [ -f ${D}${sysconfdir}/init.d/${BPN} ]; then
chmod 0755 ${D}${sysconfdir}/init.d/${BPN}
diff --git a/meta-openembedded/meta-networking/recipes-daemons/postfix/files/0006-postfix-add-preliminary-setting.patch b/meta-openembedded/meta-networking/recipes-daemons/postfix/files/0006-postfix-add-preliminary-setting.patch
new file mode 100644
index 0000000000..50d0073262
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-daemons/postfix/files/0006-postfix-add-preliminary-setting.patch
@@ -0,0 +1,31 @@
+From c09d377cd3b91c4c4360ebfab5be37f6296ff26a Mon Sep 17 00:00:00 2001
+From: Jinfeng Wang <jinfeng.wang.cn@windriver.com>
+Date: Wed, 16 Jul 2025 02:54:28 +0000
+Subject: [PATCH] postfix: add preliminary setting
+
+post-install call postconf commands to modify main.cf. When multiple
+parameters to postconf, the order of those parameters in main.cf is random.
+Then it will reproduce random results in rootfs file(sample-main.cf). To
+fix this, add preliminary setting in main.cf.
+
+Upstream-Status: Inappropriate [this is the use of post-install,
+upstream is not affected]
+
+Signed-off-by: Jinfeng Wang <jinfeng.wang.cn@windriver.com>
+---
+ conf/main.cf | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/conf/main.cf b/conf/main.cf
+index 2ee7996..0c208e6 100644
+--- a/conf/main.cf
++++ b/conf/main.cf
+@@ -683,3 +683,5 @@ sample_directory =
+ #
+ readme_directory =
+ inet_protocols = ipv4
++shlib_directory =
++meta_directory =
+--
+2.31.3
+
diff --git a/meta-openembedded/meta-networking/recipes-daemons/postfix/postfix_3.8.6.bb b/meta-openembedded/meta-networking/recipes-daemons/postfix/postfix_3.8.6.bb
index 3ec7f22ad3..b0ac51a9dd 100644
--- a/meta-openembedded/meta-networking/recipes-daemons/postfix/postfix_3.8.6.bb
+++ b/meta-openembedded/meta-networking/recipes-daemons/postfix/postfix_3.8.6.bb
@@ -26,6 +26,7 @@ SRC_URI = "http://ftp.porcupine.org/mirrors/postfix-release/official/postfix-${P
file://0003-makedefs-Use-native-compiler-to-build-makedefs.test.patch \
file://0004-Fix-icu-config.patch \
file://0005-makedefs-add-lnsl-and-lresolv-to-SYSLIBS-by-default.patch \
+ file://0006-postfix-add-preliminary-setting.patch \
"
SRC_URI[sha256sum] = "4b6e17c826cc438cc3016a9c0a55ea7e77c6cbafba7dd57241d81b690b0e9774"
diff --git a/meta-openembedded/meta-networking/recipes-daemons/proftpd/files/CVE-2023-51713.patch b/meta-openembedded/meta-networking/recipes-daemons/proftpd/files/CVE-2023-51713.patch
new file mode 100644
index 0000000000..377d8a74ec
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-daemons/proftpd/files/CVE-2023-51713.patch
@@ -0,0 +1,278 @@
+From 97bbe68363ccf2de0c07f67170ec64a8b4d62592 Mon Sep 17 00:00:00 2001
+From: TJ Saunders <tj@castaglia.org>
+Date: Sun, 6 Aug 2023 13:16:26 -0700
+Subject: [PATCH] Issue #1683: Avoid an edge case when handling unexpectedly
+ formatted input text from client, caused by quote/backslash semantics, by
+ skipping those semantics.
+
+Upstream-Status: Backport [https://github.com/proftpd/proftpd/commit/97bbe68363ccf2de0c07f67170ec64a8b4d62592]
+CVE: CVE-2023-51713
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ include/str.h | 3 ++-
+ src/main.c | 34 +++++++++++++++++++++++++++++----
+ src/str.c | 22 +++++++++++++---------
+ tests/api/str.c | 50 ++++++++++++++++++++++++++++++++++++++++++++++++-
+ 4 files changed, 94 insertions(+), 15 deletions(-)
+
+diff --git a/include/str.h b/include/str.h
+index f08398017..1261ae2c2 100644
+--- a/include/str.h
++++ b/include/str.h
+@@ -1,6 +1,6 @@
+ /*
+ * ProFTPD - FTP server daemon
+- * Copyright (c) 2008-2020 The ProFTPD Project team
++ * Copyright (c) 2008-2023 The ProFTPD Project team
+ *
+ * This program is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+@@ -131,6 +131,7 @@ const char *pr_gid2str(pool *, gid_t);
+ #define PR_STR_FL_PRESERVE_COMMENTS 0x0001
+ #define PR_STR_FL_PRESERVE_WHITESPACE 0x0002
+ #define PR_STR_FL_IGNORE_CASE 0x0004
++#define PR_STR_FL_IGNORE_QUOTES 0x0008
+
+ char *pr_str_get_token(char **, char *);
+ char *pr_str_get_token2(char **, char *, size_t *);
+diff --git a/src/main.c b/src/main.c
+index ee9c1eecb..e6b70731d 100644
+--- a/src/main.c
++++ b/src/main.c
+@@ -811,8 +811,24 @@ static cmd_rec *make_ftp_cmd(pool *p, char *buf, size_t buflen, int flags) {
+ return NULL;
+ }
+
++ /* By default, pr_str_get_word will handle quotes and backslashes for
++ * escaping characters. This can produce words which are shorter, use
++ * fewer bytes than the corresponding input buffer.
++ *
++ * In this particular situation, we use the length of this initial word
++ * for determining the length of the remaining buffer bytes, assumed to
++ * contain the FTP command arguments. If this initial word is thus
++ * unexpectedly "shorter", due to nonconformant FTP text, it can lead
++ * the subsequent buffer scan, looking for CRNUL sequencees, to access
++ * unexpected memory addresses (Issue #1683).
++ *
++ * Thus for this particular situation, we tell the function to ignore/skip
++ * such quote/backslash semantics, and treat them as any other character
++ * using the IGNORE_QUOTES flag.
++ */
++
+ ptr = buf;
+- wrd = pr_str_get_word(&ptr, str_flags);
++ wrd = pr_str_get_word(&ptr, str_flags|PR_STR_FL_IGNORE_QUOTES);
+ if (wrd == NULL) {
+ /* Nothing there...bail out. */
+ pr_trace_msg("ctrl", 5, "command '%s' is empty, ignoring", buf);
+@@ -820,6 +836,11 @@ static cmd_rec *make_ftp_cmd(pool *p, char *buf, size_t buflen, int flags) {
+ return NULL;
+ }
+
++ /* Note that this first word is the FTP command. This is why we make
++ * use of the ptr buffer, which advances through the input buffer as
++ * we read words from the buffer.
++ */
++
+ subpool = make_sub_pool(p);
+ pr_pool_tag(subpool, "make_ftp_cmd pool");
+ cmd = pcalloc(subpool, sizeof(cmd_rec));
+@@ -846,6 +867,7 @@ static cmd_rec *make_ftp_cmd(pool *p, char *buf, size_t buflen, int flags) {
+ arg_len = buflen - strlen(wrd);
+ arg = pcalloc(cmd->pool, arg_len + 1);
+
++ /* Remember that ptr here is advanced past the first word. */
+ for (i = 0, j = 0; i < arg_len; i++) {
+ pr_signals_handle();
+ if (i > 1 &&
+@@ -854,14 +876,13 @@ static cmd_rec *make_ftp_cmd(pool *p, char *buf, size_t buflen, int flags) {
+
+ /* Strip out the NUL by simply not copying it into the new buffer. */
+ have_crnul = TRUE;
++
+ } else {
+ arg[j++] = ptr[i];
+ }
+ }
+
+- cmd->arg = arg;
+-
+- if (have_crnul) {
++ if (have_crnul == TRUE) {
+ char *dup_arg;
+
+ /* Now make a copy of the stripped argument; this is what we need to
+@@ -871,6 +892,11 @@ static cmd_rec *make_ftp_cmd(pool *p, char *buf, size_t buflen, int flags) {
+ ptr = dup_arg;
+ }
+
++ cmd->arg = arg;
++
++ /* Now we can read the remamining words, as command arguments, from the
++ * input buffer.
++ */
+ while ((wrd = pr_str_get_word(&ptr, str_flags)) != NULL) {
+ pr_signals_handle();
+ *((char **) push_array(tarr)) = pstrdup(cmd->pool, wrd);
+diff --git a/src/str.c b/src/str.c
+index bcca4ae4d..a2ff74daf 100644
+--- a/src/str.c
++++ b/src/str.c
+@@ -1,6 +1,6 @@
+ /*
+ * ProFTPD - FTP server daemon
+- * Copyright (c) 2008-2017 The ProFTPD Project team
++ * Copyright (c) 2008-2023 The ProFTPD Project team
+ *
+ * This program is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+@@ -1209,7 +1209,7 @@ int pr_str_get_nbytes(const char *str, const char *units, off_t *nbytes) {
+
+ char *pr_str_get_word(char **cp, int flags) {
+ char *res, *dst;
+- char quote_mode = 0;
++ int quote_mode = FALSE;
+
+ if (cp == NULL ||
+ !*cp ||
+@@ -1238,24 +1238,28 @@ char *pr_str_get_word(char **cp, int flags) {
+ }
+ }
+
+- if (**cp == '\"') {
+- quote_mode++;
+- (*cp)++;
++ if (!(flags & PR_STR_FL_IGNORE_QUOTES)) {
++ if (**cp == '\"') {
++ quote_mode = TRUE;
++ (*cp)++;
++ }
+ }
+
+ while (**cp && (quote_mode ? (**cp != '\"') : !PR_ISSPACE(**cp))) {
+ pr_signals_handle();
+
+- if (**cp == '\\' && quote_mode) {
+-
++ if (**cp == '\\' &&
++ quote_mode == TRUE) {
+ /* Escaped char */
+ if (*((*cp)+1)) {
+- *dst = *(++(*cp));
++ *dst++ = *(++(*cp));
++ (*cp)++;
++ continue;
+ }
+ }
+
+ *dst++ = **cp;
+- ++(*cp);
++ (*cp)++;
+ }
+
+ if (**cp) {
+diff --git a/tests/api/str.c b/tests/api/str.c
+index 050f5c563..bc64f0fb0 100644
+--- a/tests/api/str.c
++++ b/tests/api/str.c
+@@ -1,6 +1,6 @@
+ /*
+ * ProFTPD - FTP server testsuite
+- * Copyright (c) 2008-2017 The ProFTPD Project team
++ * Copyright (c) 2008-2023 The ProFTPD Project team
+ *
+ * This program is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+@@ -695,19 +695,23 @@ END_TEST
+ START_TEST (get_word_test) {
+ char *ok, *res, *str;
+
++ mark_point();
+ res = pr_str_get_word(NULL, 0);
+ fail_unless(res == NULL, "Failed to handle null arguments");
+ fail_unless(errno == EINVAL, "Failed to set errno to EINVAL");
+
++ mark_point();
+ str = NULL;
+ res = pr_str_get_word(&str, 0);
+ fail_unless(res == NULL, "Failed to handle null str argument");
+ fail_unless(errno == EINVAL, "Failed to set errno to EINVAL");
+
++ mark_point();
+ str = pstrdup(p, " ");
+ res = pr_str_get_word(&str, 0);
+ fail_unless(res == NULL, "Failed to handle whitespace argument");
+
++ mark_point();
+ str = pstrdup(p, " foo");
+ res = pr_str_get_word(&str, PR_STR_FL_PRESERVE_WHITESPACE);
+ fail_unless(res != NULL, "Failed to handle whitespace argument: %s",
+@@ -723,6 +727,7 @@ START_TEST (get_word_test) {
+ ok = "foo";
+ fail_unless(strcmp(res, ok) == 0, "Expected '%s', got '%s'", ok, res);
+
++ mark_point();
+ str = pstrdup(p, " # foo");
+ res = pr_str_get_word(&str, 0);
+ fail_unless(res == NULL, "Failed to handle commented argument");
+@@ -742,6 +747,8 @@ START_TEST (get_word_test) {
+ fail_unless(strcmp(res, ok) == 0, "Expected '%s', got '%s'", ok, res);
+
+ /* Test multiple embedded quotes. */
++
++ mark_point();
+ str = pstrdup(p, "foo \"bar baz\" qux \"quz norf\"");
+ res = pr_str_get_word(&str, 0);
+ fail_unless(res != NULL, "Failed to handle quoted argument: %s",
+@@ -770,6 +777,47 @@ START_TEST (get_word_test) {
+
+ ok = "quz norf";
+ fail_unless(strcmp(res, ok) == 0, "Expected '%s', got '%s'", ok, res);
++
++
++ /* Test embedded quotes with backslashes (Issue #1683). */
++ mark_point();
++
++ str = pstrdup(p, "\"\\\\SYST\"");
++ res = pr_str_get_word(&str, 0);
++ fail_unless(res != NULL, "Failed to handle quoted argument: %s",
++ strerror(errno));
++
++ ok = "\\SYST";
++ fail_unless(strcmp(res, ok) == 0, "Expected '%s', got '%s'", ok, res);
++
++ mark_point();
++ str = pstrdup(p, "\"\"\\\\SYST");
++ res = pr_str_get_word(&str, 0);
++ fail_unless(res != NULL, "Failed to handle quoted argument: %s",
++ strerror(errno));
++
++ /* Note that pr_str_get_word() is intended to be called multiple times
++ * on an advancing buffer, effectively tokenizing the buffer. This is
++ * why the function does NOT decrement its quote mode.
++ */
++ ok = "";
++ fail_unless(strcmp(res, ok) == 0, "Expected '%s', got '%s'", ok, res);
++
++ /* Now do the same tests with the IGNORE_QUOTES flag */
++ mark_point();
++
++ str = ok = pstrdup(p, "\"\\\\SYST\"");
++ res = pr_str_get_word(&str, PR_STR_FL_IGNORE_QUOTES);
++ fail_unless(res != NULL, "Failed to handle quoted argument: %s",
++ strerror(errno));
++ fail_unless(strcmp(res, ok) == 0, "Expected '%s', got '%s'", ok, res);
++
++ mark_point();
++ str = ok = pstrdup(p, "\"\"\\\\SYST");
++ res = pr_str_get_word(&str, PR_STR_FL_IGNORE_QUOTES);
++ fail_unless(res != NULL, "Failed to handle quoted argument: %s",
++ strerror(errno));
++ fail_unless(strcmp(res, ok) == 0, "Expected '%s', got '%s'", ok, res);
+ }
+ END_TEST
+
+--
+2.25.1
+
diff --git a/meta-openembedded/meta-networking/recipes-daemons/proftpd/files/CVE-2024-57392.patch b/meta-openembedded/meta-networking/recipes-daemons/proftpd/files/CVE-2024-57392.patch
new file mode 100644
index 0000000000..0b50175a55
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-daemons/proftpd/files/CVE-2024-57392.patch
@@ -0,0 +1,42 @@
+From 981a37916fdb7b73435c6d5cdb01428b2269427d Mon Sep 17 00:00:00 2001
+From: TJ Saunders <tj@castaglia.org>
+Date: Sun, 9 Feb 2025 12:14:25 -0800
+Subject: [PATCH] Issue #1866: Some of the fuzzing tests submitted in the
+ advisory ran into existing null pointer dereferences (not buffer overflows);
+ let's correct them. (#1867)
+
+Upstream-Status: Backport [https://github.com/proftpd/proftpd/commit/981a37916fdb7b73435c6d5cdb01428b2269427d]
+CVE: CVE-2024-57392
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ modules/mod_ls.c | 7 +++++--
+ 1 file changed, 5 insertions(+), 2 deletions(-)
+
+diff --git a/modules/mod_ls.c b/modules/mod_ls.c
+index 45a3187bd..f7abfe540 100644
+--- a/modules/mod_ls.c
++++ b/modules/mod_ls.c
+@@ -349,7 +349,8 @@ static int sendline(int flags, char *fmt, ...) {
+ errno != 0) {
+ int xerrno = errno;
+
+- if (session.d != NULL) {
++ if (session.d != NULL &&
++ session.d->outstrm != NULL) {
+ xerrno = PR_NETIO_ERRNO(session.d->outstrm);
+ }
+
+@@ -1039,7 +1040,9 @@ static int outputfiles(cmd_rec *cmd) {
+ return res;
+ }
+
+- tail->down = NULL;
++ if (tail != NULL) {
++ tail->down = NULL;
++ }
+ tail = NULL;
+ colwidth = (colwidth | 7) + 1;
+ if (opt_l || !opt_C) {
+--
+2.25.1
+
diff --git a/meta-openembedded/meta-networking/recipes-daemons/proftpd/proftpd_1.3.7c.bb b/meta-openembedded/meta-networking/recipes-daemons/proftpd/proftpd_1.3.7c.bb
index ecd2777247..ec38fb54e1 100644
--- a/meta-openembedded/meta-networking/recipes-daemons/proftpd/proftpd_1.3.7c.bb
+++ b/meta-openembedded/meta-networking/recipes-daemons/proftpd/proftpd_1.3.7c.bb
@@ -15,6 +15,8 @@ SRC_URI = "git://github.com/proftpd/proftpd.git;branch=${BRANCH};protocol=https
file://contrib.patch \
file://build_fixup.patch \
file://proftpd.service \
+ file://CVE-2023-51713.patch \
+ file://CVE-2024-57392.patch \
"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-networking/recipes-daemons/squid/files/CVE-2024-37894.patch b/meta-openembedded/meta-networking/recipes-daemons/squid/files/CVE-2024-37894.patch
new file mode 100644
index 0000000000..ba12b71d6f
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-daemons/squid/files/CVE-2024-37894.patch
@@ -0,0 +1,36 @@
+From 920563e7a080155fae3ced73d6198781e8b0ff04 Mon Sep 17 00:00:00 2001
+From: Francesco Chemolli <5175948+kinkie@users.noreply.github.com>
+Date: Sun, 2 Jun 2024 14:41:16 +0000
+Subject: [PATCH] Bug 5378: type mismatch in libTrie (#1830)
+
+TrieNode::add() incorrectly computed an offset of an internal data
+structure, resulting in out-of-bounds memory accesses that could cause
+corruption or crashes.
+
+This bug was discovered and detailed by Joshua Rogers at
+https://megamansec.github.io/Squid-Security-Audit/esi-underflow.html
+where it was filed as "Buffer Underflow in ESI".
+
+CVE: CVE-2024-37894
+Upstream-Status: Backport [https://github.com/squid-cache/squid/commit/920563e7a080155fae3ced73d6198781e8b0ff04]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ lib/libTrie/TrieNode.cc | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/lib/libTrie/TrieNode.cc b/lib/libTrie/TrieNode.cc
+index 0f991a06d..d417e0f54 100644
+--- a/lib/libTrie/TrieNode.cc
++++ b/lib/libTrie/TrieNode.cc
+@@ -32,7 +32,7 @@ TrieNode::add(char const *aString, size_t theLength, void *privatedata, TrieChar
+ /* We trust that privatedata and existent keys have already been checked */
+
+ if (theLength) {
+- int index = transform ? (*transform)(*aString): *aString;
++ const unsigned char index = transform ? (*transform)(*aString): *aString;
+
+ if (!internal[index])
+ internal[index] = new TrieNode;
+--
+2.30.2
+
diff --git a/meta-openembedded/meta-networking/recipes-daemons/squid/files/CVE-2025-59362.patch b/meta-openembedded/meta-networking/recipes-daemons/squid/files/CVE-2025-59362.patch
new file mode 100644
index 0000000000..26a3896625
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-daemons/squid/files/CVE-2025-59362.patch
@@ -0,0 +1,52 @@
+From 0d89165ee6da10e6fa50c44998b3cd16d59400e9 Mon Sep 17 00:00:00 2001
+From: Alex Rousskov <rousskov@measurement-factory.com>
+Date: Sat, 30 Aug 2025 06:49:36 +0000
+Subject: [PATCH] Fix ASN.1 encoding of long SNMP OIDs (#2149)
+
+CVE: CVE-2025-59362
+Upstream-Status: Backport [https://github.com/squid-cache/squid/commit/0d89165ee6da10e6fa50c44998b3cd16d59400e9]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ lib/snmplib/asn1.c | 13 +++++++++++++
+ 1 file changed, 13 insertions(+)
+
+diff --git a/lib/snmplib/asn1.c b/lib/snmplib/asn1.c
+index 81f2051fb..2852c26b2 100644
+--- a/lib/snmplib/asn1.c
++++ b/lib/snmplib/asn1.c
+@@ -735,6 +735,7 @@ asn_build_objid(u_char * data, int *datalength,
+ * lastbyte ::= 0 7bitvalue
+ */
+ u_char buf[MAX_OID_LEN];
++ u_char *bufEnd = buf + sizeof(buf);
+ u_char *bp = buf;
+ oid *op = objid;
+ int asnlength;
+@@ -753,6 +754,10 @@ asn_build_objid(u_char * data, int *datalength,
+ while (objidlength-- > 0) {
+ subid = *op++;
+ if (subid < 127) { /* off by one? */
++ if (bp >= bufEnd) {
++ snmp_set_api_error(SNMPERR_ASN_ENCODE);
++ return (NULL);
++ }
+ *bp++ = subid;
+ } else {
+ mask = 0x7F; /* handle subid == 0 case */
+@@ -770,8 +775,16 @@ asn_build_objid(u_char * data, int *datalength,
+ /* fix a mask that got truncated above */
+ if (mask == 0x1E00000)
+ mask = 0xFE00000;
++ if (bp >= bufEnd) {
++ snmp_set_api_error(SNMPERR_ASN_ENCODE);
++ return (NULL);
++ }
+ *bp++ = (u_char) (((subid & mask) >> bits) | ASN_BIT8);
+ }
++ if (bp >= bufEnd) {
++ snmp_set_api_error(SNMPERR_ASN_ENCODE);
++ return (NULL);
++ }
+ *bp++ = (u_char) (subid & mask);
+ }
+ }
diff --git a/meta-openembedded/meta-networking/recipes-daemons/squid/squid_6.9.bb b/meta-openembedded/meta-networking/recipes-daemons/squid/squid_6.9.bb
index 33d286e122..490a5401c3 100644
--- a/meta-openembedded/meta-networking/recipes-daemons/squid/squid_6.9.bb
+++ b/meta-openembedded/meta-networking/recipes-daemons/squid/squid_6.9.bb
@@ -20,6 +20,8 @@ SRC_URI = "http://www.squid-cache.org/Versions/v${MAJ_VER}/${BPN}-${PV}.tar.xz \
file://volatiles.03_squid \
file://0002-squid-make-squid-conf-tests-run-on-target-device.patch \
file://squid.nm \
+ file://CVE-2024-37894.patch \
+ file://CVE-2025-59362.patch \
"
SRC_URI[sha256sum] = "1ad72d46e1cb556e9561214f0fb181adb87c7c47927ef69bc8acd68a03f61882"
@@ -146,3 +148,9 @@ FILES:${PN}-networkmanager = "${libdir}/NetworkManager/dispatcher.d"
RDEPENDS:${PN} += "perl ${PN}-conf"
RDEPENDS:${PN}-ptest += "perl make bash"
+
+python() {
+ # Only ESI feature is vulnerable
+ if not bb.utils.filter('PACKAGECONFIG', 'esi', d):
+ d.setVarFlag("CVE_STATUS", "CVE-2024-45802", "not-applicable-config: esi is disabled")
+}
diff --git a/meta-openembedded/meta-networking/recipes-devtools/libcoap/libcoap/CVE-2024-31031.patch b/meta-openembedded/meta-networking/recipes-devtools/libcoap/libcoap/CVE-2024-31031.patch
new file mode 100644
index 0000000000..bd1a88c87a
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-devtools/libcoap/libcoap/CVE-2024-31031.patch
@@ -0,0 +1,82 @@
+From 214665ac4b44b1b6a7e38d4d6907ee835a174928 Mon Sep 17 00:00:00 2001
+From: Jon Shallow <supjps-libcoap@jpshallow.com>
+Date: Mon, 25 Mar 2024 20:44:48 +0000
+Subject: [PATCH] coap_pdu.c: Fix UndefinedBehaviorSanitizer:
+ undefined-behavior
+
+This fixes a reported error in coap_update_token() where a size_t
+calculation is overflowed (but all ends up with the correct value).
+
+Instead of adding an overflowed size_t, now subtract the reversed
+size_t calculation as appropriate.
+
+coap_update_option() and coap_insert_option() similarily updated.
+
+CVE: CVE-2024-31031
+Upstream-Status: Backport [https://github.com/obgm/libcoap/commit/214665ac4b44b1b6a7e38d4d6907ee835a174928]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/coap_pdu.c | 33 ++++++++++++++++++++++++---------
+ 1 file changed, 24 insertions(+), 9 deletions(-)
+
+diff --git a/src/coap_pdu.c b/src/coap_pdu.c
+index afe445c8..e3be3f02 100644
+--- a/src/coap_pdu.c
++++ b/src/coap_pdu.c
+@@ -389,12 +389,15 @@ coap_update_token(coap_pdu_t *pdu, size_t len, const uint8_t *data) {
+ memmove(&pdu->token[(len + bias) - pdu->e_token_length],
+ pdu->token, pdu->used_size);
+ pdu->used_size += len + bias - pdu->e_token_length;
++ if (pdu->data) {
++ pdu->data += (len + bias) - pdu->e_token_length;
++ }
+ } else {
+ pdu->used_size -= pdu->e_token_length - (len + bias);
+ memmove(pdu->token, &pdu->token[pdu->e_token_length - (len + bias)], pdu->used_size);
+- }
+- if (pdu->data) {
+- pdu->data += (len + bias) - pdu->e_token_length;
++ if (pdu->data) {
++ pdu->data -= pdu->e_token_length - (len + bias);
++ }
+ }
+
+ pdu->actual_token.length = len;
+@@ -641,9 +644,15 @@ coap_insert_option(coap_pdu_t *pdu, coap_option_num_t number, size_t len,
+ number - prev_number, data, len))
+ return 0;
+
+- pdu->used_size += shift - shrink;
+- if (pdu->data)
+- pdu->data += shift - shrink;
++ if (shift >= shrink) {
++ pdu->used_size += shift - shrink;
++ if (pdu->data)
++ pdu->data += shift - shrink;
++ } else {
++ pdu->used_size -= shrink - shift;
++ if (pdu->data)
++ pdu->data -= shrink - shift;
++ }
+ return shift;
+ }
+
+@@ -681,9 +690,15 @@ coap_update_option(coap_pdu_t *pdu, coap_option_num_t number, size_t len,
+ decode.delta, data, len))
+ return 0;
+
+- pdu->used_size += new_length - old_length;
+- if (pdu->data)
+- pdu->data += new_length - old_length;
++ if (new_length >= old_length) {
++ pdu->used_size += new_length - old_length;
++ if (pdu->data)
++ pdu->data += new_length - old_length;
++ } else {
++ pdu->used_size -= old_length - new_length;
++ if (pdu->data)
++ pdu->data -= old_length - new_length;
++ }
+ return 1;
+ }
+
diff --git a/meta-openembedded/meta-networking/recipes-devtools/libcoap/libcoap_4.3.4.bb b/meta-openembedded/meta-networking/recipes-devtools/libcoap/libcoap_4.3.4.bb
index 98f0f02fb8..65bf455d9b 100644
--- a/meta-openembedded/meta-networking/recipes-devtools/libcoap/libcoap_4.3.4.bb
+++ b/meta-openembedded/meta-networking/recipes-devtools/libcoap/libcoap_4.3.4.bb
@@ -10,6 +10,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=1978dbc41673ab1c20e64b287c8317bc"
SRC_URI = "git://github.com/obgm/libcoap.git;branch=main;protocol=https \
file://run-ptest \
file://CVE-2024-0962.patch \
+ file://CVE-2024-31031.patch \
"
SRCREV = "5fd2f89ef068214130e5d60b7087ef48711fa615"
diff --git a/meta-openembedded/meta-networking/recipes-extended/corosync/corosync/CVE-2025-30472.patch b/meta-openembedded/meta-networking/recipes-extended/corosync/corosync/CVE-2025-30472.patch
new file mode 100644
index 0000000000..9b36dbe3fb
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-extended/corosync/corosync/CVE-2025-30472.patch
@@ -0,0 +1,69 @@
+From 7839990f9cdf34e55435ed90109e82709032466a Mon Sep 17 00:00:00 2001
+From: Jan Friesse <jfriesse@redhat.com>
+Date: Mon, 24 Mar 2025 12:05:08 +0100
+Subject: [PATCH] totemsrp: Check size of orf_token msg
+
+orf_token message is stored into preallocated array on endian convert
+so carefully crafted malicious message can lead to crash of corosync.
+
+Solution is to check message size beforehand.
+
+Signed-off-by: Jan Friesse <jfriesse@redhat.com>
+Reviewed-by: Christine Caulfield <ccaulfie@redhat.com>
+
+CVE: CVE-2025-30472
+Upstream-Status: Backport [https://github.com/corosync/corosync/commits/7839990f9cdf34e55435ed90109e82709032466a]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ exec/totemsrp.c | 18 +++++++++++++++++-
+ 1 file changed, 17 insertions(+), 1 deletion(-)
+
+diff --git a/exec/totemsrp.c b/exec/totemsrp.c
+index 962d0e2a..364528ce 100644
+--- a/exec/totemsrp.c
++++ b/exec/totemsrp.c
+@@ -3679,12 +3679,20 @@ static int check_orf_token_sanity(
+ const struct totemsrp_instance *instance,
+ const void *msg,
+ size_t msg_len,
++ size_t max_msg_len,
+ int endian_conversion_needed)
+ {
+ int rtr_entries;
+ const struct orf_token *token = (const struct orf_token *)msg;
+ size_t required_len;
+
++ if (msg_len > max_msg_len) {
++ log_printf (instance->totemsrp_log_level_security,
++ "Received orf_token message is too long... ignoring.");
++
++ return (-1);
++ }
++
+ if (msg_len < sizeof(struct orf_token)) {
+ log_printf (instance->totemsrp_log_level_security,
+ "Received orf_token message is too short... ignoring.");
+@@ -3698,6 +3706,13 @@ static int check_orf_token_sanity(
+ rtr_entries = token->rtr_list_entries;
+ }
+
++ if (rtr_entries > RETRANSMIT_ENTRIES_MAX) {
++ log_printf (instance->totemsrp_log_level_security,
++ "Received orf_token message rtr_entries is corrupted... ignoring.");
++
++ return (-1);
++ }
++
+ required_len = sizeof(struct orf_token) + rtr_entries * sizeof(struct rtr_item);
+ if (msg_len < required_len) {
+ log_printf (instance->totemsrp_log_level_security,
+@@ -3868,7 +3883,8 @@ static int message_handler_orf_token (
+ "Time since last token %0.4f ms", tv_diff / (float)QB_TIME_NS_IN_MSEC);
+ #endif
+
+- if (check_orf_token_sanity(instance, msg, msg_len, endian_conversion_needed) == -1) {
++ if (check_orf_token_sanity(instance, msg, msg_len, sizeof(token_storage),
++ endian_conversion_needed) == -1) {
+ return (0);
+ }
+
diff --git a/meta-openembedded/meta-networking/recipes-extended/corosync/corosync_3.1.6.bb b/meta-openembedded/meta-networking/recipes-extended/corosync/corosync_3.1.9.bb
index 8fca576614..cd9feb5da5 100644
--- a/meta-openembedded/meta-networking/recipes-extended/corosync/corosync_3.1.6.bb
+++ b/meta-openembedded/meta-networking/recipes-extended/corosync/corosync_3.1.9.bb
@@ -5,16 +5,17 @@ HOMEPAGE = "http://corosync.github.io/corosync/"
SECTION = "base"
-inherit autotools pkgconfig systemd
+inherit autotools pkgconfig systemd github-releases
-SRC_URI = "https://github.com/${BPN}/${BPN}/releases/download/v${PV}/${BP}.tar.gz \
+SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/${BP}.tar.gz \
file://corosync.conf \
+ file://CVE-2025-30472.patch \
"
-SRC_URI[sha256sum] = "ca6ed32b4d7f33ed614afce8760fe58d0de92c68b575d4969ebacd892f3d1e27"
-UPSTREAM_CHECK_REGEX = "(?P<pver>\d+\.(?!99)\d+(\.\d+)+)"
+SRC_URI[sha256sum] = "203354bbddee1a97b3c50a076eae89c635f406dd674ccaefc94bb9092acd9535"
+UPSTREAM_CHECK_GITTAGREGEX = "v(?P<pver>\d+(\.\d+)+)"
LICENSE = "BSD-3-Clause"
-LIC_FILES_CHKSUM = "file://LICENSE;md5=a85eb4ce24033adb6088dd1d6ffc5e5d"
+LIC_FILES_CHKSUM = "file://LICENSE;md5=d9c2cca5d3448c43e52a399ad611658a"
DEPENDS = "groff-native nss libqb kronosnet"
@@ -34,11 +35,6 @@ PACKAGECONFIG[systemd] = "--enable-systemd --with-systemddir=${systemd_system_un
EXTRA_OECONF = "ac_cv_path_BASHPATH=${base_bindir}/bash ap_cv_cc_pie=no"
EXTRA_OEMAKE = "tmpfilesdir_DATA="
-#do_configure:prepend() {
-# ( cd ${S}
-# ${S}/autogen.sh )
-#}
-
do_install:append() {
install -D -m 0644 ${WORKDIR}/corosync.conf ${D}${sysconfdir}/corosync/corosync.conf.example
install -d ${D}${sysconfdir}/sysconfig/
@@ -59,5 +55,6 @@ do_install:append() {
RDEPENDS:${PN} += "bash ${@bb.utils.contains('DISTRO_FEATURES', 'sysvinit', 'sysvinit-pidof', 'procps', d)}"
+FILES:${PN} += "${datadir}/dbus-1"
FILES:${PN}-dbg += "${libexecdir}/lcrso/.debug"
FILES:${PN}-doc += "${datadir}/snmp/mibs/COROSYNC-MIB.txt"
diff --git a/meta-openembedded/meta-networking/recipes-extended/tgt/files/CVE-2024-45751.patch b/meta-openembedded/meta-networking/recipes-extended/tgt/files/CVE-2024-45751.patch
new file mode 100644
index 0000000000..2de9ae9b28
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-extended/tgt/files/CVE-2024-45751.patch
@@ -0,0 +1,71 @@
+From abd8e0d987ab56013d360077202bf2aca20a42dd Mon Sep 17 00:00:00 2001
+From: Richard Weinberger <richard@nod.at>
+Date: Tue, 3 Sep 2024 16:14:58 +0200
+Subject: [PATCH] chap: Use proper entropy source
+
+The challenge sent to the initiator is based on a poor
+source of randomness, it uses rand() without seeding it by srand().
+So the glibc PRNG is always seeded with 1 and as a consequence the
+sequence of challenges is always the same.
+
+An attacker which is able to monitor network traffic can apply a replay
+attack to bypass the CHAP authentication. All the attacker has to do
+is waiting for the server or the service to restart and replay with a
+previously record CHAP session which fits into the sequence.
+
+To overcome the issue, use getrandom() to query the kernel random
+number generator.
+Also always send a challenge of length CHAP_CHALLENGE_MAX, there is no
+benefit in sending a variable length challenge.
+
+Signed-off-by: Richard Weinberger <richard@nod.at>
+
+Upstream-Status: Backport [https://github.com/fujita/tgt/commit/abd8e0d987ab56013d360077202bf2aca20a42dd]
+CVE: CVE-2024-45751
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ usr/iscsi/chap.c | 12 +++++-------
+ 1 file changed, 5 insertions(+), 7 deletions(-)
+
+diff --git a/usr/iscsi/chap.c b/usr/iscsi/chap.c
+index aa0fc67..b89ecab 100644
+--- a/usr/iscsi/chap.c
++++ b/usr/iscsi/chap.c
+@@ -28,6 +28,7 @@
+ #include <stdio.h>
+ #include <stdlib.h>
+ #include <string.h>
++#include <sys/random.h>
+
+ #include "iscsid.h"
+ #include "tgtd.h"
+@@ -359,22 +360,19 @@ static int chap_initiator_auth_create_challenge(struct iscsi_connection *conn)
+ sprintf(text, "%u", (unsigned char)conn->auth.chap.id);
+ text_key_add(conn, "CHAP_I", text);
+
+- /*
+- * FIXME: does a random challenge length provide any benefits security-
+- * wise, or should we rather always use the max. allowed length of
+- * 1024 for the (unencoded) challenge?
+- */
+- conn->auth.chap.challenge_size = (rand() % (CHAP_CHALLENGE_MAX / 2)) + CHAP_CHALLENGE_MAX / 2;
++ conn->auth.chap.challenge_size = CHAP_CHALLENGE_MAX;
+
+ conn->auth.chap.challenge = malloc(conn->auth.chap.challenge_size);
+ if (!conn->auth.chap.challenge)
+ return CHAP_TARGET_ERROR;
+
++ if (getrandom(conn->auth.chap.challenge, conn->auth.chap.challenge_size, 0) != conn->auth.chap.challenge_size)
++ return CHAP_TARGET_ERROR;
++
+ p = text;
+ strcpy(p, "0x");
+ p += 2;
+ for (i = 0; i < conn->auth.chap.challenge_size; i++) {
+- conn->auth.chap.challenge[i] = rand();
+ sprintf(p, "%.2hhx", conn->auth.chap.challenge[i]);
+ p += 2;
+ }
+--
+2.25.1
+
diff --git a/meta-openembedded/meta-networking/recipes-extended/tgt/tgt_1.0.90.bb b/meta-openembedded/meta-networking/recipes-extended/tgt/tgt_1.0.90.bb
index 35995f7876..f70f77f540 100644
--- a/meta-openembedded/meta-networking/recipes-extended/tgt/tgt_1.0.90.bb
+++ b/meta-openembedded/meta-networking/recipes-extended/tgt/tgt_1.0.90.bb
@@ -11,6 +11,7 @@ SRC_URI = "git://github.com/fujita/tgt.git;branch=master;protocol=https \
file://0001-usr-Makefile-WARNING-fix.patch \
file://usr-Makefile-apply-LDFLAGS-to-all-executables.patch \
file://musl-__wordsize.patch \
+ file://CVE-2024-45751.patch \
"
SRC_URI += "file://tgtd.init \
file://tgtd.service \
diff --git a/meta-openembedded/meta-networking/recipes-filter/ebtables/ebtables-2.0.11/ebtables-legacy-save b/meta-openembedded/meta-networking/recipes-filter/ebtables/ebtables-2.0.11/ebtables-legacy-save
index 2133600f77..0b39c23deb 100644
--- a/meta-openembedded/meta-networking/recipes-filter/ebtables/ebtables-2.0.11/ebtables-legacy-save
+++ b/meta-openembedded/meta-networking/recipes-filter/ebtables/ebtables-2.0.11/ebtables-legacy-save
@@ -1,4 +1,4 @@
-#!/bin/bash
+#!/bin/sh
EBTABLES="/usr/sbin/ebtables-legacy"
@@ -11,7 +11,7 @@ cnt=""
for table_name in $(grep -E '^ebtable_' /proc/modules | cut -f1 -d' ' | sed s/ebtable_//); do
table=$($EBTABLES -t $table_name -L $cnt)
- [ $? -eq 0 ] || { echo "$table"; exit -1; }
+ [ $? -eq 0 ] || { echo "$table"; exit 1; }
chain=""
rules=""
@@ -20,24 +20,23 @@ for table_name in $(grep -E '^ebtable_' /proc/modules | cut -f1 -d' ' | sed s/eb
case "$line" in
Bridge\ table:\ *)
- echo "*${line:14}"
+ echo "*${line#Bridge table: }"
;;
Bridge\ chain:\ *)
- chain="${line:14}"
+ chain="${line#Bridge chain: }"
chain="${chain%%,*}"
policy="${line##*policy: }"
echo ":$chain $policy"
;;
*)
- if [ "$cnt" = "--Lc" ]; then
- line=${line/, pcnt \=/ -c}
- line=${line/-- bcnt \=/}
- fi
- rules="$rules-A $chain $line\n"
+ [ "$cnt" != "--Lc" ] ||
+ line=$(echo "$line" | sed -e 's/, pcnt =/-c/' -e 's/ -- bcnt =//')
+ rules="$rules-A $chain $line
+"
;;
esac
done <<EOF
$table
EOF
- echo -e $rules
+ echo "$rules"
done
diff --git a/meta-openembedded/meta-networking/recipes-filter/ebtables/ebtables_2.0.11.bb b/meta-openembedded/meta-networking/recipes-filter/ebtables/ebtables_2.0.11.bb
index d522b514f6..30a4c79477 100644
--- a/meta-openembedded/meta-networking/recipes-filter/ebtables/ebtables_2.0.11.bb
+++ b/meta-openembedded/meta-networking/recipes-filter/ebtables/ebtables_2.0.11.bb
@@ -6,8 +6,6 @@ LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=53b4a999993871a28ab1488fdbd2e73e"
SECTION = "net"
-RDEPENDS:${PN} += "bash"
-
RRECOMMENDS:${PN} += "kernel-module-ebtables \
"
diff --git a/meta-openembedded/meta-networking/recipes-filter/nftables/nftables/run-ptest b/meta-openembedded/meta-networking/recipes-filter/nftables/nftables/run-ptest
index 32ddf9f455..55e801f67c 100644
--- a/meta-openembedded/meta-networking/recipes-filter/nftables/nftables/run-ptest
+++ b/meta-openembedded/meta-networking/recipes-filter/nftables/nftables/run-ptest
@@ -5,14 +5,18 @@ cd ${NFTABLESLIB}/ptest || exit 1
LOG="${NFTABLESLIB}/ptest/nftables_ptest_$(date +%Y%m%d-%H%M%S).log"
NFT=nft
-tests/shell/run-tests.sh -v | sed -E '/I: \[OK\]/ s/^/PASS: / ; /W: \[(CHK DUMP|VALGRIND|TAINTED|DUMP FAIL|FAILED)\]/ s/^/FAIL: /' | sed "s,\x1B\[[0-9;]*[a-zA-Z],,g" | tee -a "${LOG}"
+tests/shell/run-tests.sh -v | sed -E '/I: \[OK\]/ s/^/PASS: / ; /W: \[(CHK DUMP|VALGRIND|TAINTED|DUMP FAIL|FAILED)\]/ s/^/FAIL: / ; /I: \[SKIPPED\]/ s/^/SKIP: /' | sed "s,\x1B\[[0-9;]*[a-zA-Z],,g" | tee -a "${LOG}"
passed=$(grep -c PASS: "${LOG}")
failed=$(grep -c FAIL: "${LOG}")
-all=$((passed + failed))
+skiped=$(grep -c SKIP: "${LOG}")
+
+all=$((passed + failed + skiped))
( echo "=== Test Summary ==="
echo "TOTAL: ${all}"
echo "PASSED: ${passed}"
echo "FAILED: ${failed}"
+ echo "SKIPED: ${skiped}"
+ echo "===================="
) | tee -a "${LOG}"
diff --git a/meta-openembedded/meta-networking/recipes-filter/nftables/nftables_1.0.9.bb b/meta-openembedded/meta-networking/recipes-filter/nftables/nftables_1.0.9.bb
index 7718922742..569ab6f6af 100644
--- a/meta-openembedded/meta-networking/recipes-filter/nftables/nftables_1.0.9.bb
+++ b/meta-openembedded/meta-networking/recipes-filter/nftables/nftables_1.0.9.bb
@@ -35,9 +35,9 @@ EXTRA_OECONF = " \
SETUPTOOLS_SETUP_PATH = "${S}/py"
-inherit ${@bb.utils.contains('PACKAGECONFIG', 'python', 'setuptools3', '', d)}
+inherit_defer ${@bb.utils.contains('PACKAGECONFIG', 'python', 'setuptools3', '', d)}
-PACKAGES =+ "${PN}-python"
+PACKAGES =+ "${@bb.utils.contains('PACKAGECONFIG', 'python', '${PN}-python', '', d)}"
FILES:${PN}-python = "${PYTHON_SITEPACKAGES_DIR}"
RDEPENDS:${PN}-python = "python3-core python3-json ${PN}"
@@ -64,7 +64,10 @@ do_install() {
fi
}
-RDEPENDS:${PN}-ptest += " ${PN}-python bash coreutils make iproute2 iputils-ping procps python3-core python3-ctypes python3-json python3-misc sed util-linux"
+RDEPENDS:${PN}-ptest += " \
+ bash coreutils make iproute2 iputils-ping procps python3-core python3-ctypes python3-json python3-misc sed util-linux \
+ ${@bb.utils.contains('PACKAGECONFIG', 'python', '${PN}-python', '', d)} \
+"
RRECOMMENDS:${PN}-ptest += "\
kernel-module-nft-chain-nat kernel-module-nft-queue \
diff --git a/meta-openembedded/meta-networking/recipes-irc/znc/znc_1.8.2.bb b/meta-openembedded/meta-networking/recipes-irc/znc/znc_1.8.2.bb
index 1517384eca..68dd0702f7 100644
--- a/meta-openembedded/meta-networking/recipes-irc/znc/znc_1.8.2.bb
+++ b/meta-openembedded/meta-networking/recipes-irc/znc/znc_1.8.2.bb
@@ -29,4 +29,5 @@ do_configure:prepend() {
do_install:append() {
sed -i -e 's|${DEBUG_PREFIX_MAP}||g; s|--sysroot=${STAGING_DIR_TARGET}||g' ${D}${libdir}/pkgconfig/*.pc
+ sed -i -e 's|${DEBUG_PREFIX_MAP}||g; s|--sysroot=${STAGING_DIR_TARGET}||g' ${D}${bindir}/znc-buildmod
}
diff --git a/meta-openembedded/meta-networking/recipes-kernel/wireguard/wireguard-tools_1.0.20210914.bb b/meta-openembedded/meta-networking/recipes-kernel/wireguard/wireguard-tools_1.0.20210914.bb
index 8def54ece6..c12b8abd5d 100644
--- a/meta-openembedded/meta-networking/recipes-kernel/wireguard/wireguard-tools_1.0.20210914.bb
+++ b/meta-openembedded/meta-networking/recipes-kernel/wireguard/wireguard-tools_1.0.20210914.bb
@@ -1,7 +1,7 @@
require wireguard.inc
SRCREV = "3ba6527130c502144e7388b900138bca6260f4e8"
-SRC_URI = "git://git.zx2c4.com/wireguard-tools;branch=master"
+SRC_URI = "git://github.com/WireGuard/wireguard-tools.git;branch=master;protocol=https"
inherit bash-completion systemd pkgconfig
diff --git a/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-31948.patch b/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-31948.patch
new file mode 100644
index 0000000000..bc1f2edc7d
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-31948.patch
@@ -0,0 +1,130 @@
+From a11446687169c679b5e51b57f151a6f6c119656c Mon Sep 17 00:00:00 2001
+From: Donatas Abraitis <donatas@opensourcerouting.org>
+Date: Wed, 27 Mar 2024 18:42:56 +0200
+Subject: [PATCH 1/2] bgpd: Fix error handling when receiving BGP Prefix SID
+ attribute
+
+Without this patch, we always set the BGP Prefix SID attribute flag without
+checking if it's malformed or not. RFC8669 says that this attribute MUST be discarded.
+
+Also, this fixes the bgpd crash when a malformed Prefix SID attribute is received,
+with malformed transitive flags and/or TLVs.
+
+Reported-by: Iggy Frankovic <iggyfran@amazon.com>
+Signed-off-by: Donatas Abraitis <donatas@opensourcerouting.org>
+
+CVE: CVE-2024-31948
+Upstream-Status: Backport [https://github.com/FRRouting/frr/commit/ba6a8f1a31e1a88df2de69ea46068e8bd9b97138]
+
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ bgpd/bgp_attr.c | 5 +++--
+ 1 file changed, 3 insertions(+), 2 deletions(-)
+
+diff --git a/bgpd/bgp_attr.c b/bgpd/bgp_attr.c
+index 56e77eb3a..2639ff864 100644
+--- a/bgpd/bgp_attr.c
++++ b/bgpd/bgp_attr.c
+@@ -1390,6 +1390,7 @@ bgp_attr_malformed(struct bgp_attr_parser_args *args, uint8_t subcode,
+ case BGP_ATTR_AS4_AGGREGATOR:
+ case BGP_ATTR_AGGREGATOR:
+ case BGP_ATTR_ATOMIC_AGGREGATE:
++ case BGP_ATTR_PREFIX_SID:
+ return BGP_ATTR_PARSE_PROCEED;
+
+ /* Core attributes, particularly ones which may influence route
+@@ -3144,8 +3145,6 @@ enum bgp_attr_parse_ret bgp_attr_prefix_sid(struct bgp_attr_parser_args *args)
+ struct attr *const attr = args->attr;
+ enum bgp_attr_parse_ret ret;
+
+- attr->flag |= ATTR_FLAG_BIT(BGP_ATTR_PREFIX_SID);
+-
+ uint8_t type;
+ uint16_t length;
+ size_t headersz = sizeof(type) + sizeof(length);
+@@ -3195,6 +3194,8 @@ enum bgp_attr_parse_ret bgp_attr_prefix_sid(struct bgp_attr_parser_args *args)
+ }
+ }
+
++ SET_FLAG(attr->flag, ATTR_FLAG_BIT(BGP_ATTR_PREFIX_SID));
++
+ return BGP_ATTR_PARSE_PROCEED;
+ }
+
+--
+2.34.1
+
+From 70555e1c0927b84f3aae9406379b00c976b2fa0c Mon Sep 17 00:00:00 2001
+From: Donatas Abraitis <donatas@opensourcerouting.org>
+Date: Wed, 27 Mar 2024 19:08:38 +0200
+Subject: [PATCH 2/2] bgpd: Prevent from one more CVE triggering this place
+
+If we receive an attribute that is handled by bgp_attr_malformed(), use
+treat-as-withdraw behavior for unknown (or missing to add - if new) attributes.
+
+Signed-off-by: Donatas Abraitis <donatas@opensourcerouting.org>
+
+CVE: CVE-2024-31948
+Upstream-Status: Backport [https://github.com/FRRouting/frr/commit/babb23b74855e23c987a63f8256d24e28c044d07]
+
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ bgpd/bgp_attr.c | 33 ++++++++++++++++++++++-----------
+ 1 file changed, 22 insertions(+), 11 deletions(-)
+
+diff --git a/bgpd/bgp_attr.c b/bgpd/bgp_attr.c
+index 2639ff864..797f05d60 100644
+--- a/bgpd/bgp_attr.c
++++ b/bgpd/bgp_attr.c
+@@ -1381,6 +1381,15 @@ bgp_attr_malformed(struct bgp_attr_parser_args *args, uint8_t subcode,
+ (args->startp - STREAM_DATA(BGP_INPUT(peer)))
+ + args->total);
+
++ /* Partial optional attributes that are malformed should not cause
++ * the whole session to be reset. Instead treat it as a withdrawal
++ * of the routes, if possible.
++ */
++ if (CHECK_FLAG(flags, BGP_ATTR_FLAG_TRANS) &&
++ CHECK_FLAG(flags, BGP_ATTR_FLAG_OPTIONAL) &&
++ CHECK_FLAG(flags, BGP_ATTR_FLAG_PARTIAL))
++ return BGP_ATTR_PARSE_WITHDRAW;
++
+ switch (args->type) {
+ /* where an attribute is relatively inconsequential, e.g. it does not
+ * affect route selection, and can be safely ignored, then any such
+@@ -1418,19 +1427,21 @@ bgp_attr_malformed(struct bgp_attr_parser_args *args, uint8_t subcode,
+ BGP_NOTIFY_UPDATE_ERR, subcode,
+ notify_datap, length);
+ return BGP_ATTR_PARSE_ERROR;
++ default:
++ /* Unknown attributes, that are handled by this function
++ * should be treated as withdraw, to prevent one more CVE
++ * from being introduced.
++ * RFC 7606 says:
++ * The "treat-as-withdraw" approach is generally preferred
++ * and the "session reset" approach is discouraged.
++ */
++ flog_err(EC_BGP_ATTR_FLAG,
++ "%s(%u) attribute received, while it is not known how to handle it, treating as withdraw",
++ lookup_msg(attr_str, args->type, NULL), args->type);
++ break;
+ }
+
+- /* Partial optional attributes that are malformed should not cause
+- * the whole session to be reset. Instead treat it as a withdrawal
+- * of the routes, if possible.
+- */
+- if (CHECK_FLAG(flags, BGP_ATTR_FLAG_TRANS)
+- && CHECK_FLAG(flags, BGP_ATTR_FLAG_OPTIONAL)
+- && CHECK_FLAG(flags, BGP_ATTR_FLAG_PARTIAL))
+- return BGP_ATTR_PARSE_WITHDRAW;
+-
+- /* default to reset */
+- return BGP_ATTR_PARSE_ERROR_NOTIFYPLS;
++ return BGP_ATTR_PARSE_WITHDRAW;
+ }
+
+ /* Find out what is wrong with the path attribute flag bits and log the error.
+--
+2.34.1
+
diff --git a/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-31949.patch b/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-31949.patch
new file mode 100644
index 0000000000..dad0255ead
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-31949.patch
@@ -0,0 +1,163 @@
+From 2779d7d7c4f465f8e117aa4c47982dd60d620bc9 Mon Sep 17 00:00:00 2001
+From: Donatas Abraitis <donatas@opensourcerouting.org>
+Date: Sat, 30 Mar 2024 15:35:18 +0200
+Subject: [PATCH] bgpd: Fix errors handling for MP/GR capabilities as dynamic
+ capability
+
+When receiving a MP/GR capability as dynamic capability, but malformed, do not
+forget to advance the pointer to avoid hitting infinity loop.
+
+After:
+```
+Mar 29 11:15:28 donatas-laptop bgpd[353550]: [GS0AQ-HKY0X] 127.0.0.1 rcv CAPABILITY
+Mar 29 11:15:28 donatas-laptop bgpd[353550]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 5, length 0
+Mar 29 11:15:28 donatas-laptop bgpd[353550]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 0, length 0
+Mar 29 11:15:28 donatas-laptop bgpd[353550]: [HFHDS-QT71N][EC 33554494] 127.0.0.1(donatas-pc): unrecognized capability code: 0 - ignored
+Mar 29 11:15:28 donatas-laptop bgpd[353550]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 0, code: 0, length 0
+Mar 29 11:15:28 donatas-laptop bgpd[353550]: [HFHDS-QT71N][EC 33554494] 127.0.0.1(donatas-pc): unrecognized capability code: 0 - ignored
+Mar 29 11:15:28 donatas-laptop bgpd[353550]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 0, code: 0, length 0
+Mar 29 11:15:28 donatas-laptop bgpd[353550]: [HFHDS-QT71N][EC 33554494] 127.0.0.1(donatas-pc): unrecognized capability code: 0 - ignored
+Mar 29 11:15:28 donatas-laptop bgpd[353550]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 0, code: 0, length 1
+Mar 29 11:15:28 donatas-laptop bgpd[353550]: [HFHDS-QT71N][EC 33554494] 127.0.0.1(donatas-pc): unrecognized capability code: 0 - ignored
+Mar 29 11:15:28 donatas-laptop bgpd[353550]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+Mar 29 11:15:28 donatas-laptop bgpd[353550]: [Z1DRQ-N6Z5F] 127.0.0.1(donatas-pc): Dynamic Capability MultiProtocol Extensions afi/safi invalid (bad-value/unicast)
+```
+
+Before:
+```
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [Z1DRQ-N6Z5F] 127.0.0.1(donatas-pc): Dynamic Capability MultiProtocol Extensions afi/safi invalid (bad-value/unicast)
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [Z1DRQ-N6Z5F] 127.0.0.1(donatas-pc): Dynamic Capability MultiProtocol Extensions afi/safi invalid (bad-value/unicast)
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [Z1DRQ-N6Z5F] 127.0.0.1(donatas-pc): Dynamic Capability MultiProtocol Extensions afi/safi invalid (bad-value/unicast)
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [Z1DRQ-N6Z5F] 127.0.0.1(donatas-pc): Dynamic Capability MultiProtocol Extensions afi/safi invalid (bad-value/unicast)
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [Z1DRQ-N6Z5F] 127.0.0.1(donatas-pc): Dynamic Capability MultiProtocol Extensions afi/safi invalid (bad-value/unicast)
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [Z1DRQ-N6Z5F] 127.0.0.1(donatas-pc): Dynamic Capability MultiProtocol Extensions afi/safi invalid (bad-value/unicast)
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [Z1DRQ-N6Z5F] 127.0.0.1(donatas-pc): Dynamic Capability MultiProtocol Extensions afi/safi invalid (bad-value/unicast)
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [Z1DRQ-N6Z5F] 127.0.0.1(donatas-pc): Dynamic Capability MultiProtocol Extensions afi/safi invalid (bad-value/unicast)
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [Z1DRQ-N6Z5F] 127.0.0.1(donatas-pc): Dynamic Capability MultiProtocol Extensions afi/safi invalid (bad-value/unicast)
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [Z1DRQ-N6Z5F] 127.0.0.1(donatas-pc): Dynamic Capability MultiProtocol Extensions afi/safi invalid (bad-value/unicast)
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [Z1DRQ-N6Z5F] 127.0.0.1(donatas-pc): Dynamic Capability MultiProtocol Extensions afi/safi invalid (bad-value/unicast)
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [Z1DRQ-N6Z5F] 127.0.0.1(donatas-pc): Dynamic Capability MultiProtocol Extensions afi/safi invalid (bad-value/unicast)
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [Z1DRQ-N6Z5F] 127.0.0.1(donatas-pc): Dynamic Capability MultiProtocol Extensions afi/safi invalid (bad-value/unicast)
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [Z1DRQ-N6Z5F] 127.0.0.1(donatas-pc): Dynamic Capability MultiProtocol Extensions afi/safi invalid (bad-value/unicast)
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [Z1DRQ-N6Z5F] 127.0.0.1(donatas-pc): Dynamic Capability MultiProtocol Extensions afi/safi invalid (bad-value/unicast)
+Mar 29 11:14:54 donatas-laptop bgpd[347675]: [JTVED-VGTQQ] 127.0.0.1(donatas-pc): CAPABILITY has action: 1, code: 1, length 10
+```
+
+Reported-by: Iggy Frankovic <iggyfran@amazon.com>
+Signed-off-by: Donatas Abraitis <donatas@opensourcerouting.org>
+
+CVE: CVE-2024-31949
+Upstream-Status: Backport [https://github.com/FRRouting/frr/commit/30a332dad86fafd2b0b6c61d23de59ed969a219b]
+
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ bgpd/bgp_packet.c | 17 ++++++++++-------
+ 1 file changed, 10 insertions(+), 7 deletions(-)
+
+diff --git a/bgpd/bgp_packet.c b/bgpd/bgp_packet.c
+index cae82cbbb..50e5b54ab 100644
+--- a/bgpd/bgp_packet.c
++++ b/bgpd/bgp_packet.c
+@@ -3121,6 +3121,7 @@ static int bgp_capability_msg_parse(struct peer *peer, uint8_t *pnt,
+ zlog_err("%pBP: Capability length error", peer);
+ bgp_notify_send(peer->connection, BGP_NOTIFY_CEASE,
+ BGP_NOTIFY_SUBCODE_UNSPECIFIC);
++ pnt += length;
+ return BGP_Stop;
+ }
+ action = *pnt;
+@@ -3133,7 +3134,7 @@ static int bgp_capability_msg_parse(struct peer *peer, uint8_t *pnt,
+ action);
+ bgp_notify_send(peer->connection, BGP_NOTIFY_CEASE,
+ BGP_NOTIFY_SUBCODE_UNSPECIFIC);
+- return BGP_Stop;
++ goto done;
+ }
+
+ if (bgp_debug_neighbor_events(peer))
+@@ -3145,12 +3146,13 @@ static int bgp_capability_msg_parse(struct peer *peer, uint8_t *pnt,
+ zlog_err("%pBP: Capability length error", peer);
+ bgp_notify_send(peer->connection, BGP_NOTIFY_CEASE,
+ BGP_NOTIFY_SUBCODE_UNSPECIFIC);
++ pnt += length;
+ return BGP_Stop;
+ }
+
+ /* Ignore capability when override-capability is set. */
+ if (CHECK_FLAG(peer->flags, PEER_FLAG_OVERRIDE_CAPABILITY))
+- continue;
++ goto done;
+
+ capability = lookup_msg(capcode_str, hdr->code, "Unknown");
+
+@@ -3165,7 +3167,7 @@ static int bgp_capability_msg_parse(struct peer *peer, uint8_t *pnt,
+ peer, capability,
+ sizeof(struct capability_mp_data),
+ hdr->length);
+- return BGP_Stop;
++ goto done;
+ }
+
+ memcpy(&mpc, pnt + 3, sizeof(struct capability_mp_data));
+@@ -3180,7 +3182,7 @@ static int bgp_capability_msg_parse(struct peer *peer, uint8_t *pnt,
+ peer, capability,
+ iana_afi2str(pkt_afi),
+ iana_safi2str(pkt_safi));
+- continue;
++ goto done;
+ }
+
+ /* Address family check. */
+@@ -3207,7 +3209,7 @@ static int bgp_capability_msg_parse(struct peer *peer, uint8_t *pnt,
+ if (peer_active_nego(peer))
+ bgp_clear_route(peer, afi, safi);
+ else
+- return BGP_Stop;
++ goto done;
+ }
+ break;
+ case CAPABILITY_CODE_RESTART:
+@@ -3217,7 +3219,7 @@ static int bgp_capability_msg_parse(struct peer *peer, uint8_t *pnt,
+ bgp_notify_send(peer->connection,
+ BGP_NOTIFY_CEASE,
+ BGP_NOTIFY_SUBCODE_UNSPECIFIC);
+- return BGP_Stop;
++ goto done;
+ }
+
+ bgp_dynamic_capability_graceful_restart(pnt, action,
+@@ -3243,7 +3245,7 @@ static int bgp_capability_msg_parse(struct peer *peer, uint8_t *pnt,
+ bgp_notify_send(peer->connection,
+ BGP_NOTIFY_CEASE,
+ BGP_NOTIFY_SUBCODE_UNSPECIFIC);
+- return BGP_Stop;
++ goto done;
+ }
+
+ uint8_t role;
+@@ -3265,6 +3267,7 @@ static int bgp_capability_msg_parse(struct peer *peer, uint8_t *pnt,
+ break;
+ }
+
++done:
+ pnt += hdr->length + 3;
+ }
+
+--
+2.34.1
+
diff --git a/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-31950.patch b/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-31950.patch
new file mode 100644
index 0000000000..c579ec283e
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-31950.patch
@@ -0,0 +1,68 @@
+From f69d1313b19047d3d83fc2b36a518355b861dfc4 Mon Sep 17 00:00:00 2001
+From: Olivier Dugeon <olivier.dugeon@orange.com>
+Date: Wed, 3 Apr 2024 16:28:23 +0200
+Subject: [PATCH] ospfd: Solved crash in RI parsing with OSPF TE
+
+Iggy Frankovic discovered another ospfd crash when performing fuzzing of OSPF
+LSA packets. The crash occurs in ospf_te_parse_ri() function when attemping to
+read Segment Routing subTLVs. The original code doesn't check if the size of
+the SR subTLVs have the correct length. In presence of erronous LSA, this will
+cause a buffer overflow and ospfd crash.
+
+This patch introduces new verification of the subTLVs size for Router
+Information TLV.
+
+Co-authored-by: Iggy Frankovic <iggyfran@amazon.com>
+Signed-off-by: Olivier Dugeon <olivier.dugeon@orange.com>
+
+CVE: CVE-2024-31950
+Upstream-Status: Backport [https://github.com/FRRouting/frr/commit/f69d1313b19047d3d83fc2b36a518355b861dfc4]
+
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ ospfd/ospf_te.c | 9 +++++++++
+ 1 file changed, 9 insertions(+)
+
+diff --git a/ospfd/ospf_te.c b/ospfd/ospf_te.c
+index 359dc1f5d4b8..091669d8ed36 100644
+--- a/ospfd/ospf_te.c
++++ b/ospfd/ospf_te.c
+@@ -2456,6 +2456,9 @@ static int ospf_te_parse_ri(struct ls_ted *ted, struct ospf_lsa *lsa)
+
+ switch (ntohs(tlvh->type)) {
+ case RI_SR_TLV_SR_ALGORITHM:
++ if (TLV_BODY_SIZE(tlvh) < 1 ||
++ TLV_BODY_SIZE(tlvh) > ALGORITHM_COUNT)
++ break;
+ algo = (struct ri_sr_tlv_sr_algorithm *)tlvh;
+
+ for (int i = 0; i < ntohs(algo->header.length); i++) {
+@@ -2480,6 +2483,8 @@ static int ospf_te_parse_ri(struct ls_ted *ted, struct ospf_lsa *lsa)
+ break;
+
+ case RI_SR_TLV_SRGB_LABEL_RANGE:
++ if (TLV_BODY_SIZE(tlvh) != RI_SR_TLV_LABEL_RANGE_SIZE)
++ break;
+ range = (struct ri_sr_tlv_sid_label_range *)tlvh;
+ size = GET_RANGE_SIZE(ntohl(range->size));
+ lower = GET_LABEL(ntohl(range->lower.value));
+@@ -2497,6 +2502,8 @@ static int ospf_te_parse_ri(struct ls_ted *ted, struct ospf_lsa *lsa)
+ break;
+
+ case RI_SR_TLV_SRLB_LABEL_RANGE:
++ if (TLV_BODY_SIZE(tlvh) != RI_SR_TLV_LABEL_RANGE_SIZE)
++ break;
+ range = (struct ri_sr_tlv_sid_label_range *)tlvh;
+ size = GET_RANGE_SIZE(ntohl(range->size));
+ lower = GET_LABEL(ntohl(range->lower.value));
+@@ -2514,6 +2521,8 @@ static int ospf_te_parse_ri(struct ls_ted *ted, struct ospf_lsa *lsa)
+ break;
+
+ case RI_SR_TLV_NODE_MSD:
++ if (TLV_BODY_SIZE(tlvh) < RI_SR_TLV_NODE_MSD_SIZE)
++ break;
+ msd = (struct ri_sr_tlv_node_msd *)tlvh;
+ if ((CHECK_FLAG(node->flags, LS_NODE_MSD))
+ && (node->msd == msd->value))
+--
+2.34.1 \ No newline at end of file
diff --git a/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-31951.patch b/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-31951.patch
new file mode 100644
index 0000000000..7f19b0312a
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-31951.patch
@@ -0,0 +1,110 @@
+From 5557a289acdaeec8cc63ffc97b5c2abf6dee7b3a Mon Sep 17 00:00:00 2001
+From: Olivier Dugeon <olivier.dugeon@orange.com>
+Date: Fri, 5 Apr 2024 12:57:11 +0200
+Subject: [PATCH] ospfd: Correct Opaque LSA Extended parser
+
+Iggy Frankovic discovered another ospfd crash when performing fuzzing of OSPF
+LSA packets. The crash occurs in ospf_te_parse_ext_link() function when
+attemping to read Segment Routing Adjacency SID subTLVs. The original code
+doesn't check if the size of the Extended Link TLVs and subTLVs have the correct
+length. In presence of erronous LSA, this will cause a buffer overflow and ospfd
+crashes.
+
+This patch introduces new verification of the subTLVs size for Extended Link
+TLVs and subTLVs. Similar check has been also introduced for the Extended
+Prefix TLV.
+
+Co-authored-by: Iggy Frankovic <iggyfran@amazon.com>
+Signed-off-by: Olivier Dugeon <olivier.dugeon@orange.com>
+
+CVE: CVE-2024-31951
+Upstream-Status: Backport [https://github.com/FRRouting/frr/commit/5557a289acdaeec8cc63ffc97b5c2abf6dee7b3a]
+
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ ospfd/ospf_te.c | 35 +++++++++++++++++++++++++++++++++--
+ 1 file changed, 33 insertions(+), 2 deletions(-)
+
+diff --git a/ospfd/ospf_te.c b/ospfd/ospf_te.c
+index 091669d8ed36..e68f9444f512 100644
+--- a/ospfd/ospf_te.c
++++ b/ospfd/ospf_te.c
+@@ -2620,6 +2620,7 @@ static int ospf_te_parse_ext_pref(struct ls_ted *ted, struct ospf_lsa *lsa)
+ struct ext_tlv_prefix *ext;
+ struct ext_subtlv_prefix_sid *pref_sid;
+ uint32_t label;
++ uint16_t len, size;
+
+ /* Get corresponding Subnet from Link State Data Base */
+ ext = (struct ext_tlv_prefix *)TLV_HDR_TOP(lsa->data);
+@@ -2641,6 +2642,18 @@ static int ospf_te_parse_ext_pref(struct ls_ted *ted, struct ospf_lsa *lsa)
+ ote_debug(" |- Process Extended Prefix LSA %pI4 for subnet %pFX",
+ &lsa->data->id, &pref);
+
++ /*
++ * Check Extended Prefix TLV size against LSA size
++ * as only one TLV is allowed per LSA
++ */
++ len = TLV_BODY_SIZE(&ext->header);
++ size = lsa->size - (OSPF_LSA_HEADER_SIZE + TLV_HDR_SIZE);
++ if (len != size || len <= 0) {
++ ote_debug(" |- Wrong TLV size: %u instead of %u",
++ (uint32_t)len, (uint32_t)size);
++ return -1;
++ }
++
+ /* Initialize TLV browsing */
+ ls_pref = subnet->ls_pref;
+ pref_sid = (struct ext_subtlv_prefix_sid *)((char *)(ext) + TLV_HDR_SIZE
+@@ -2751,8 +2764,20 @@ static int ospf_te_parse_ext_link(struct ls_ted *ted, struct ospf_lsa *lsa)
+ ote_debug(" |- Process Extended Link LSA %pI4 for edge %pI4",
+ &lsa->data->id, &edge->attributes->standard.local);
+
+- /* Initialize TLV browsing */
+- len = TLV_BODY_SIZE(&ext->header) - EXT_TLV_LINK_SIZE;
++ /*
++ * Check Extended Link TLV size against LSA size
++ * as only one TLV is allowed per LSA
++ */
++ len = TLV_BODY_SIZE(&ext->header);
++ i = lsa->size - (OSPF_LSA_HEADER_SIZE + TLV_HDR_SIZE);
++ if (len != i || len <= 0) {
++ ote_debug(" |- Wrong TLV size: %u instead of %u",
++ (uint32_t)len, (uint32_t)i);
++ return -1;
++ }
++
++ /* Initialize subTLVs browsing */
++ len -= EXT_TLV_LINK_SIZE;
+ tlvh = (struct tlv_header *)((char *)(ext) + TLV_HDR_SIZE
+ + EXT_TLV_LINK_SIZE);
+ for (; sum < len; tlvh = TLV_HDR_NEXT(tlvh)) {
+@@ -2762,6 +2787,8 @@ static int ospf_te_parse_ext_link(struct ls_ted *ted, struct ospf_lsa *lsa)
+
+ switch (ntohs(tlvh->type)) {
+ case EXT_SUBTLV_ADJ_SID:
++ if (TLV_BODY_SIZE(tlvh) != EXT_SUBTLV_ADJ_SID_SIZE)
++ break;
+ adj = (struct ext_subtlv_adj_sid *)tlvh;
+ label = CHECK_FLAG(adj->flags,
+ EXT_SUBTLV_LINK_ADJ_SID_VFLG)
+@@ -2788,6 +2815,8 @@ static int ospf_te_parse_ext_link(struct ls_ted *ted, struct ospf_lsa *lsa)
+
+ break;
+ case EXT_SUBTLV_LAN_ADJ_SID:
++ if (TLV_BODY_SIZE(tlvh) != EXT_SUBTLV_LAN_ADJ_SID_SIZE)
++ break;
+ ladj = (struct ext_subtlv_lan_adj_sid *)tlvh;
+ label = CHECK_FLAG(ladj->flags,
+ EXT_SUBTLV_LINK_ADJ_SID_VFLG)
+@@ -2817,6 +2846,8 @@ static int ospf_te_parse_ext_link(struct ls_ted *ted, struct ospf_lsa *lsa)
+
+ break;
+ case EXT_SUBTLV_RMT_ITF_ADDR:
++ if (TLV_BODY_SIZE(tlvh) != EXT_SUBTLV_RMT_ITF_ADDR_SIZE)
++ break;
+ rmt = (struct ext_subtlv_rmt_itf_addr *)tlvh;
+ if (CHECK_FLAG(atr->flags, LS_ATTR_NEIGH_ADDR)
+ && IPV4_ADDR_SAME(&atr->standard.remote,
+--
+2.34.1 \ No newline at end of file
diff --git a/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-34088.patch b/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-34088.patch
new file mode 100644
index 0000000000..72dffb1328
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-34088.patch
@@ -0,0 +1,83 @@
+From 8c177d69e32b91b45bda5fc5da6511fa03dc11ca Mon Sep 17 00:00:00 2001
+From: Olivier Dugeon <olivier.dugeon@orange.com>
+Date: Tue, 16 Apr 2024 16:42:06 +0200
+Subject: [PATCH] ospfd: protect call to get_edge() in ospf_te.c
+
+During fuzzing, Iggy Frankovic discovered that get_edge() function in ospf_te.c
+could return null pointer, in particular when the link_id or advertised router
+IP addresses are fuzzed. As the null pointer returned by get_edge() function is
+not handlei by calling functions, this could cause ospfd crash.
+
+This patch introduces new verification of returned pointer by get_edge()
+function and stop the processing in case of null pointer. In addition, link ID
+and advertiser router ID are validated before calling ls_find_edge_by_key() to
+avoid the creation of a new edge with an invalid key.
+
+CVE-2024-34088
+
+Co-authored-by: Iggy Frankovic <iggyfran@amazon.com>
+Signed-off-by: Olivier Dugeon <olivier.dugeon@orange.com>
+
+CVE: CVE-2024-34088
+Upstream-Status: Backport [https://github.com/FRRouting/frr/commit/8c177d69e32b91b45bda5fc5da6511fa03dc11ca]
+
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ ospfd/ospf_te.c | 19 ++++++++++++++++---
+ 1 file changed, 16 insertions(+), 3 deletions(-)
+
+diff --git a/ospfd/ospf_te.c b/ospfd/ospf_te.c
+index e68f9444f512..d57990e1a174 100644
+--- a/ospfd/ospf_te.c
++++ b/ospfd/ospf_te.c
+@@ -1670,6 +1670,11 @@ static struct ls_edge *get_edge(struct ls_ted *ted, struct ls_node_id adv,
+ struct ls_edge *edge;
+ struct ls_attributes *attr;
+
++ /* Check that Link ID and Node ID are valid */
++ if (IPV4_NET0(link_id.s_addr) || IPV4_NET0(adv.id.ip.addr.s_addr) ||
++ adv.origin != OSPFv2)
++ return NULL;
++
+ /* Search Edge that corresponds to the Link ID */
+ key.family = AF_INET;
+ IPV4_ADDR_COPY(&key.k.addr, &link_id);
+@@ -1743,6 +1748,10 @@ static void ospf_te_update_link(struct ls_ted *ted, struct ls_vertex *vertex,
+
+ /* Get Corresponding Edge from Link State Data Base */
+ edge = get_edge(ted, vertex->node->adv, link_data);
++ if (!edge) {
++ ote_debug(" |- Found no edge from Link Data. Abort!");
++ return;
++ }
+ attr = edge->attributes;
+
+ /* re-attached edge to vertex if needed */
+@@ -2246,11 +2255,11 @@ static int ospf_te_parse_te(struct ls_ted *ted, struct ospf_lsa *lsa)
+ }
+
+ /* Get corresponding Edge from Link State Data Base */
+- if (IPV4_NET0(attr.standard.local.s_addr) && !attr.standard.local_id) {
+- ote_debug(" |- Found no TE Link local address/ID. Abort!");
++ edge = get_edge(ted, attr.adv, attr.standard.local);
++ if (!edge) {
++ ote_debug(" |- Found no edge from Link local add./ID. Abort!");
+ return -1;
+ }
+- edge = get_edge(ted, attr.adv, attr.standard.local);
+ old = edge->attributes;
+
+ ote_debug(" |- Process Traffic Engineering LSA %pI4 for Edge %pI4",
+@@ -2759,6 +2768,10 @@ static int ospf_te_parse_ext_link(struct ls_ted *ted, struct ospf_lsa *lsa)
+ lnid.id.ip.area_id = lsa->area->area_id;
+ ext = (struct ext_tlv_link *)TLV_HDR_TOP(lsa->data);
+ edge = get_edge(ted, lnid, ext->link_data);
++ if (!edge) {
++ ote_debug(" |- Found no edge from Extended Link Data. Abort!");
++ return -1;
++ }
+ atr = edge->attributes;
+
+ ote_debug(" |- Process Extended Link LSA %pI4 for edge %pI4",
+--
+2.34.1 \ No newline at end of file
diff --git a/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-44070.patch b/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-44070.patch
new file mode 100644
index 0000000000..87bd16efa6
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-protocols/frr/frr/CVE-2024-44070.patch
@@ -0,0 +1,54 @@
+From 335dc7f0421dc5b59a50795f21f28bd92ed4ef12 Mon Sep 17 00:00:00 2001
+From: Donatas Abraitis <donatas@opensourcerouting.org>
+Date: Wed, 31 Jul 2024 08:35:14 +0300
+Subject: [PATCH] bgpd: Check the actual remaining stream length before taking
+ TLV value
+
+```
+ 0 0xb50b9f898028 in __sanitizer_print_stack_trace (/home/ubuntu/frr-public/frr_public_private-libfuzzer/bgpd/.libs/bgpd+0x368028) (BuildId: 3292703ed7958b20076550c967f879db8dc27ca7)
+ 1 0xb50b9f7ed8e4 in fuzzer::PrintStackTrace() (/home/ubuntu/frr-public/frr_public_private-libfuzzer/bgpd/.libs/bgpd+0x2bd8e4) (BuildId: 3292703ed7958b20076550c967f879db8dc27ca7)
+ 2 0xb50b9f7d4d9c in fuzzer::Fuzzer::CrashCallback() (/home/ubuntu/frr-public/frr_public_private-libfuzzer/bgpd/.libs/bgpd+0x2a4d9c) (BuildId: 3292703ed7958b20076550c967f879db8dc27ca7)
+ 3 0xe0d12d7469cc (linux-vdso.so.1+0x9cc) (BuildId: 1a77697e9d723fe22246cfd7641b140c427b7e11)
+ 4 0xe0d12c88f1fc in __pthread_kill_implementation nptl/pthread_kill.c:43:17
+ 5 0xe0d12c84a678 in gsignal signal/../sysdeps/posix/raise.c:26:13
+ 6 0xe0d12c83712c in abort stdlib/abort.c:79:7
+ 7 0xe0d12d214724 in _zlog_assert_failed /home/ubuntu/frr-public/frr_public_private-libfuzzer/lib/zlog.c:789:2
+ 8 0xe0d12d1285e4 in stream_get /home/ubuntu/frr-public/frr_public_private-libfuzzer/lib/stream.c:324:3
+ 9 0xb50b9f8e47c4 in bgp_attr_encap /home/ubuntu/frr-public/frr_public_private-libfuzzer/bgpd/bgp_attr.c:2758:3
+ 10 0xb50b9f8dcd38 in bgp_attr_parse /home/ubuntu/frr-public/frr_public_private-libfuzzer/bgpd/bgp_attr.c:3783:10
+ 11 0xb50b9faf74b4 in bgp_update_receive /home/ubuntu/frr-public/frr_public_private-libfuzzer/bgpd/bgp_packet.c:2383:20
+ 12 0xb50b9faf1dcc in bgp_process_packet /home/ubuntu/frr-public/frr_public_private-libfuzzer/bgpd/bgp_packet.c:4075:11
+ 13 0xb50b9f8c90d0 in LLVMFuzzerTestOneInput /home/ubuntu/frr-public/frr_public_private-libfuzzer/bgpd/bgp_main.c:582:3
+```
+
+CVE: CVE-2024-44070
+Upstream-Status: Backport [https://github.com/FRRouting/frr/commit/21cd931a5f9303e12104c72ce31ca383c0c57514]
+
+Reported-by: Iggy Frankovic <iggyfran@amazon.com>
+Signed-off-by: Donatas Abraitis <donatas@opensourcerouting.org>
+(cherry picked from commit 0998b38e4d61179441f90dd7e7fd6a3a8b7bd8c5)
+(cherry picked from commit 21cd931a5f9303e12104c72ce31ca383c0c57514)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ bgpd/bgp_attr.c | 8 ++++++++
+ 1 file changed, 8 insertions(+)
+
+diff --git a/bgpd/bgp_attr.c b/bgpd/bgp_attr.c
+index 797f05d606..cc63251cc8 100644
+--- a/bgpd/bgp_attr.c
++++ b/bgpd/bgp_attr.c
+@@ -2718,6 +2718,14 @@ static int bgp_attr_encap(struct bgp_attr_parser_args *args)
+ args->total);
+ }
+
++ if (STREAM_READABLE(BGP_INPUT(peer)) < sublength) {
++ zlog_err("Tunnel Encap attribute sub-tlv length %d exceeds remaining stream length %zu",
++ sublength, STREAM_READABLE(BGP_INPUT(peer)));
++ return bgp_attr_malformed(args,
++ BGP_NOTIFY_UPDATE_OPT_ATTR_ERR,
++ args->total);
++ }
++
+ /* alloc and copy sub-tlv */
+ /* TBD make sure these are freed when attributes are released */
+ tlv = XCALLOC(MTYPE_ENCAP_TLV,
diff --git a/meta-openembedded/meta-networking/recipes-protocols/frr/frr_9.1.bb b/meta-openembedded/meta-networking/recipes-protocols/frr/frr_9.1.bb
index eea6d62f5f..ce9876c79f 100644
--- a/meta-openembedded/meta-networking/recipes-protocols/frr/frr_9.1.bb
+++ b/meta-openembedded/meta-networking/recipes-protocols/frr/frr_9.1.bb
@@ -13,6 +13,12 @@ LIC_FILES_CHKSUM = "file://doc/licenses/GPL-2.0;md5=b234ee4d69f5fce4486a80fdaf4a
SRC_URI = "git://github.com/FRRouting/frr.git;protocol=https;branch=stable/9.1 \
file://frr.pam \
file://0001-zebra-Mimic-GNU-basename-API-for-non-glibc-library-e.patch \
+ file://CVE-2024-34088.patch \
+ file://CVE-2024-31950.patch \
+ file://CVE-2024-31951.patch \
+ file://CVE-2024-31948.patch \
+ file://CVE-2024-31949.patch \
+ file://CVE-2024-44070.patch \
"
SRCREV = "ca2d6f0f1e000951224a18973cc1827f7f5215b5"
diff --git a/meta-openembedded/meta-networking/recipes-protocols/net-snmp/net-snmp_5.9.4.bb b/meta-openembedded/meta-networking/recipes-protocols/net-snmp/net-snmp_5.9.4.bb
index 395b02df00..f9572a1869 100644
--- a/meta-openembedded/meta-networking/recipes-protocols/net-snmp/net-snmp_5.9.4.bb
+++ b/meta-openembedded/meta-networking/recipes-protocols/net-snmp/net-snmp_5.9.4.bb
@@ -53,6 +53,8 @@ PACKAGECONFIG[perl] = "--enable-embedded-perl --with-perl-modules=yes, --disable
PACKAGECONFIG[smux] = ""
PACKAGECONFIG[systemd] = "--with-systemd, --without-systemd"
+SYSCONTACT_DISTRO ?= "no-contact-set@example.com"
+
EXTRA_OECONF = " \
--enable-shared \
--disable-manuals \
@@ -61,6 +63,7 @@ EXTRA_OECONF = " \
--with-persistent-directory=${localstatedir}/lib/net-snmp \
--with-endianness=${@oe.utils.conditional('SITEINFO_ENDIANNESS', 'le', 'little', 'big', d)} \
--with-mib-modules='${MIB_MODULES}' \
+ --with-sys-contact='${SYSCONTACT_DISTRO}' \
"
MIB_MODULES = ""
diff --git a/meta-openembedded/meta-networking/recipes-protocols/rp-pppoe/rp-pppoe_3.15.bb b/meta-openembedded/meta-networking/recipes-protocols/rp-pppoe/rp-pppoe_3.15.bb
index 4dfdb8fc21..1bfa4d1e2c 100644
--- a/meta-openembedded/meta-networking/recipes-protocols/rp-pppoe/rp-pppoe_3.15.bb
+++ b/meta-openembedded/meta-networking/recipes-protocols/rp-pppoe/rp-pppoe_3.15.bb
@@ -5,7 +5,7 @@ LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://doc/LICENSE;md5=a194eaefae2be54ee3221339b10d0581"
-SRC_URI = "https://dianne.skoll.ca/projects/rp-pppoe/download/OLD/rp-pppoe-${PV}.tar.gz \
+SRC_URI = "https://downloads.uls.co.za/rp-pppoe/rp-pppoe-${PV}.tar.gz \
file://top-autoconf.patch \
file://configure_in_cross.patch \
file://update-config.patch \
diff --git a/meta-openembedded/meta-networking/recipes-support/chrony/chrony_4.5.bb b/meta-openembedded/meta-networking/recipes-support/chrony/chrony_4.5.bb
index ed26e59879..dbea406233 100644
--- a/meta-openembedded/meta-networking/recipes-support/chrony/chrony_4.5.bb
+++ b/meta-openembedded/meta-networking/recipes-support/chrony/chrony_4.5.bb
@@ -30,7 +30,7 @@ SECTION = "net"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=751419260aa954499f7abaabaa882bbe"
-SRC_URI = "https://download.tuxfamily.org/chrony/chrony-${PV}.tar.gz \
+SRC_URI = "https://chrony-project.org/releases/chrony-${PV}.tar.gz \
file://chrony.conf \
file://chronyd \
file://arm_eabi.patch \
@@ -48,7 +48,7 @@ DEPENDS = "pps-tools"
inherit update-rc.d systemd pkgconfig
# Add chronyd user if privdrop packageconfig is selected
-inherit ${@bb.utils.contains('PACKAGECONFIG', 'privdrop', 'useradd', '', d)}
+inherit_defer ${@bb.utils.contains('PACKAGECONFIG', 'privdrop', 'useradd', '', d)}
USERADD_PACKAGES = "${@bb.utils.contains('PACKAGECONFIG', 'privdrop', '${PN}', '', d)}"
USERADD_PARAM:${PN} += "${@bb.utils.contains('PACKAGECONFIG', 'privdrop', '--system -d / -M --shell /bin/nologin chronyd;', '', d)}"
diff --git a/meta-openembedded/meta-networking/recipes-support/dovecot/dovecot/0001-auth-Fix-handling-passdbs-with-identical-driver-args.patch b/meta-openembedded/meta-networking/recipes-support/dovecot/dovecot/0001-auth-Fix-handling-passdbs-with-identical-driver-args.patch
new file mode 100644
index 0000000000..2adbee491e
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-support/dovecot/dovecot/0001-auth-Fix-handling-passdbs-with-identical-driver-args.patch
@@ -0,0 +1,137 @@
+From 30be738858f6e0b314717ea7ceb24fee165ce642 Mon Sep 17 00:00:00 2001
+From: Timo Sirainen <timo.sirainen@open-xchange.com>
+Date: Mon, 9 May 2022 15:23:33 +0300
+Subject: [PATCH] auth: Fix handling passdbs with identical driver/args but
+ different mechanisms/username_filter
+
+The passdb was wrongly deduplicated in this situation, causing wrong
+mechanisms or username_filter setting to be used. This would be a rather
+unlikely configuration though.
+
+Fixed by moving mechanisms and username_filter from struct passdb_module
+to struct auth_passdb, which is where they should have been in the first
+place.
+
+CVE: CVE-2022-30550
+
+Upstream-Status: Backport [https://github.com/dovecot/core/commit/7bad6a24160e34bce8f10e73dbbf9e5fbbcd1904]
+
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ src/auth/auth-request.c | 6 +++---
+ src/auth/auth.c | 18 ++++++++++++++++++
+ src/auth/auth.h | 5 +++++
+ src/auth/passdb.c | 15 ++-------------
+ src/auth/passdb.h | 4 ----
+ 5 files changed, 28 insertions(+), 20 deletions(-)
+
+diff --git a/src/auth/auth-request.c b/src/auth/auth-request.c
+index 635ee20..fab655e 100644
+--- a/src/auth/auth-request.c
++++ b/src/auth/auth-request.c
+@@ -560,8 +560,8 @@ auth_request_want_skip_passdb(struct auth_request *request,
+ struct auth_passdb *passdb)
+ {
+ /* if mechanism is not supported, skip */
+- const char *const *mechs = passdb->passdb->mechanisms;
+- const char *const *username_filter = passdb->passdb->username_filter;
++ const char *const *mechs = passdb->mechanisms;
++ const char *const *username_filter = passdb->username_filter;
+ const char *username;
+
+ username = request->fields.user;
+@@ -574,7 +574,7 @@ auth_request_want_skip_passdb(struct auth_request *request,
+ return TRUE;
+ }
+
+- if (passdb->passdb->username_filter != NULL &&
++ if (passdb->username_filter != NULL &&
+ !auth_request_username_accepted(username_filter, username)) {
+ auth_request_log_debug(request,
+ request->mech != NULL ? AUTH_SUBSYS_MECH
+diff --git a/src/auth/auth.c b/src/auth/auth.c
+index 845c43c..a5a4c81 100644
+--- a/src/auth/auth.c
++++ b/src/auth/auth.c
+@@ -93,6 +93,24 @@ auth_passdb_preinit(struct auth *auth, const struct auth_passdb_settings *set,
+ auth_passdb->override_fields_tmpl =
+ passdb_template_build(auth->pool, set->override_fields);
+
++ if (*set->mechanisms == '\0') {
++ auth_passdb->mechanisms = NULL;
++ } else if (strcasecmp(set->mechanisms, "none") == 0) {
++ auth_passdb->mechanisms = (const char *const[]){ NULL };
++ } else {
++ auth_passdb->mechanisms =
++ (const char *const *)p_strsplit_spaces(auth->pool,
++ set->mechanisms, " ,");
++ }
++
++ if (*set->username_filter == '\0') {
++ auth_passdb->username_filter = NULL;
++ } else {
++ auth_passdb->username_filter =
++ (const char *const *)p_strsplit_spaces(auth->pool,
++ set->username_filter, " ,");
++ }
++
+ /* for backwards compatibility: */
+ if (set->pass)
+ auth_passdb->result_success = AUTH_DB_RULE_CONTINUE;
+diff --git a/src/auth/auth.h b/src/auth/auth.h
+index 3ca5a9b..6208e4d 100644
+--- a/src/auth/auth.h
++++ b/src/auth/auth.h
+@@ -41,6 +41,11 @@ struct auth_passdb {
+ struct passdb_template *default_fields_tmpl;
+ struct passdb_template *override_fields_tmpl;
+
++ /* Supported authentication mechanisms, NULL is all, {NULL} is none */
++ const char *const *mechanisms;
++ /* Username filter, NULL is no filter */
++ const char *const *username_filter;
++
+ enum auth_passdb_skip skip;
+ enum auth_db_rule result_success;
+ enum auth_db_rule result_failure;
+diff --git a/src/auth/passdb.c b/src/auth/passdb.c
+index 9bc2b87..d3c61cc 100644
+--- a/src/auth/passdb.c
++++ b/src/auth/passdb.c
+@@ -224,19 +224,8 @@ passdb_preinit(pool_t pool, const struct auth_passdb_settings *set)
+ passdb->id = ++auth_passdb_id;
+ passdb->iface = *iface;
+ passdb->args = p_strdup(pool, set->args);
+- if (*set->mechanisms == '\0') {
+- passdb->mechanisms = NULL;
+- } else if (strcasecmp(set->mechanisms, "none") == 0) {
+- passdb->mechanisms = (const char *const[]){NULL};
+- } else {
+- passdb->mechanisms = (const char* const*)p_strsplit_spaces(pool, set->mechanisms, " ,");
+- }
+-
+- if (*set->username_filter == '\0') {
+- passdb->username_filter = NULL;
+- } else {
+- passdb->username_filter = (const char* const*)p_strsplit_spaces(pool, set->username_filter, " ,");
+- }
++ /* NOTE: if anything else than driver & args are added here,
++ passdb_find() also needs to be updated. */
+ array_push_back(&passdb_modules, &passdb);
+ return passdb;
+ }
+diff --git a/src/auth/passdb.h b/src/auth/passdb.h
+index f9b33ea..f515b1d 100644
+--- a/src/auth/passdb.h
++++ b/src/auth/passdb.h
+@@ -63,10 +63,6 @@ struct passdb_module {
+ /* Default password scheme for this module.
+ If default_cache_key is set, must not be NULL. */
+ const char *default_pass_scheme;
+- /* Supported authentication mechanisms, NULL is all, [NULL] is none*/
+- const char *const *mechanisms;
+- /* Username filter, NULL is no filter */
+- const char *const *username_filter;
+
+ /* If blocking is set to TRUE, use child processes to access
+ this passdb. */
diff --git a/meta-openembedded/meta-networking/recipes-support/dovecot/dovecot_2.3.21.bb b/meta-openembedded/meta-networking/recipes-support/dovecot/dovecot_2.3.21.bb
index 17fbd789b6..c626f26457 100644
--- a/meta-openembedded/meta-networking/recipes-support/dovecot/dovecot_2.3.21.bb
+++ b/meta-openembedded/meta-networking/recipes-support/dovecot/dovecot_2.3.21.bb
@@ -11,6 +11,7 @@ SRC_URI = "http://dovecot.org/releases/2.3/dovecot-${PV}.tar.gz \
file://dovecot.socket \
file://0001-not-check-pandoc.patch \
file://0001-m4-Check-for-libunwind-instead-of-libunwind-generic.patch \
+ file://0001-auth-Fix-handling-passdbs-with-identical-driver-args.patch \
"
SRC_URI[sha256sum] = "05b11093a71c237c2ef309ad587510721cc93bbee6828251549fc1586c36502d"
diff --git a/meta-openembedded/meta-networking/recipes-support/fetchmail/fetchmail_6.4.38.bb b/meta-openembedded/meta-networking/recipes-support/fetchmail/fetchmail_6.4.38.bb
index 587a479497..cc23d5a34e 100644
--- a/meta-openembedded/meta-networking/recipes-support/fetchmail/fetchmail_6.4.38.bb
+++ b/meta-openembedded/meta-networking/recipes-support/fetchmail/fetchmail_6.4.38.bb
@@ -16,7 +16,7 @@ SRC_URI[sha256sum] = "a6cb4ea863ac61d242ffb2db564a39123761578d3e40d71ce7b6f2905b
inherit autotools gettext pkgconfig python3-dir python3native
-EXTRA_OECONF = "--with-ssl=${STAGING_DIR_HOST}${prefix}"
+EXTRA_OECONF = "--with-ssl=${STAGING_DIR_HOST}${prefix} --disable-rpath "
do_install:append() {
sed -i 's,${RECIPE_SYSROOT_NATIVE},,g' ${D}${bindir}/fetchmailconf
diff --git a/meta-openembedded/meta-networking/recipes-support/fwknop/fwknop_2.6.10.bb b/meta-openembedded/meta-networking/recipes-support/fwknop/fwknop_2.6.10.bb
index a1f56cdf16..7a8cfe192a 100644
--- a/meta-openembedded/meta-networking/recipes-support/fwknop/fwknop_2.6.10.bb
+++ b/meta-openembedded/meta-networking/recipes-support/fwknop/fwknop_2.6.10.bb
@@ -14,7 +14,9 @@ SRC_URI[sha256sum] = "f6c09bec97ed8e474a98ae14f9f53e1bcdda33393f20667b6af3fb6bb8
DEPENDS = "libpcap gpgme"
-EXTRA_OECONF = " --with-iptables=${sbindir}/iptables"
+EXTRA_OECONF = "--with-iptables=${sbindir}/iptables \
+ --with-gpg=${bindir}/gpg \
+ --with-wget=${base_bindir}/wget"
do_configure:prepend () {
install -m 0755 ${STAGING_DATADIR_NATIVE}/gnu-config/config.guess ${S}/config
diff --git a/meta-openembedded/meta-networking/recipes-support/geoip/geoip_1.6.12.bb b/meta-openembedded/meta-networking/recipes-support/geoip/geoip_1.6.12.bb
index 429cd69d6d..12599f97de 100644
--- a/meta-openembedded/meta-networking/recipes-support/geoip/geoip_1.6.12.bb
+++ b/meta-openembedded/meta-networking/recipes-support/geoip/geoip_1.6.12.bb
@@ -11,10 +11,10 @@ SECTION = "libdevel"
GEOIP_DATABASE_VERSION = "20181205"
SRC_URI = "git://github.com/maxmind/geoip-api-c.git;branch=main;protocol=https \
- http://sources.openembedded.org/GeoIP.dat.${GEOIP_DATABASE_VERSION}.gz;apply=no;name=GeoIP-dat; \
- http://sources.openembedded.org/GeoIPv6.dat.${GEOIP_DATABASE_VERSION}.gz;apply=no;name=GeoIPv6-dat; \
- http://sources.openembedded.org/GeoLiteCity.dat.${GEOIP_DATABASE_VERSION}.gz;apply=no;name=GeoLiteCity-dat; \
- http://sources.openembedded.org/GeoLiteCityv6.dat.${GEOIP_DATABASE_VERSION}.gz;apply=no;name=GeoLiteCityv6-dat; \
+ https://downloads.yoctoproject.org/mirror/sources/GeoIP.dat.${GEOIP_DATABASE_VERSION}.gz;apply=no;name=GeoIP-dat; \
+ https://downloads.yoctoproject.org/mirror/sources/GeoIPv6.dat.${GEOIP_DATABASE_VERSION}.gz;apply=no;name=GeoIPv6-dat; \
+ https://downloads.yoctoproject.org/mirror/sources/GeoLiteCity.dat.${GEOIP_DATABASE_VERSION}.gz;apply=no;name=GeoLiteCity-dat; \
+ https://downloads.yoctoproject.org/mirror/sources/GeoLiteCityv6.dat.${GEOIP_DATABASE_VERSION}.gz;apply=no;name=GeoLiteCityv6-dat; \
file://run-ptest \
"
SRCREV = "4b526e7331ca1d692b74a0509ddcc725622ed31a"
diff --git a/meta-openembedded/meta-networking/recipes-support/libconfuse/files/CVE-2022-40320.patch b/meta-openembedded/meta-networking/recipes-support/libconfuse/files/CVE-2022-40320.patch
new file mode 100755
index 0000000000..52296b9c0f
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-support/libconfuse/files/CVE-2022-40320.patch
@@ -0,0 +1,42 @@
+From d73777c2c3566fb2647727bb56d9a2295b81669b Mon Sep 17 00:00:00 2001
+From: Joachim Wiberg <troglobit@gmail.com>
+Date: Fri, 2 Sep 2022 16:12:46 +0200
+Subject: [PATCH] Fix #163: unterminated username used with getpwnam()
+
+Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
+
+CVE: CVE-2022-40320
+Upstream-Status: Backport [https://github.com/libconfuse/libconfuse/commit/d73777c2c3566fb2647727bb56d9a2295b81669b]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/confuse.c | 9 ++++++---
+ 1 file changed, 6 insertions(+), 3 deletions(-)
+
+diff --git a/src/confuse.c b/src/confuse.c
+index 6d1fdbd..05566b5 100644
+--- a/src/confuse.c
++++ b/src/confuse.c
+@@ -1872,17 +1872,20 @@ DLLIMPORT char *cfg_tilde_expand(const char *filename)
+ file = filename + 1;
+ } else {
+ /* ~user or ~user/path */
+- char *user;
++ char *user; /* ~user or ~user/path */
++ size_t len;
+
+ file = strchr(filename, '/');
+ if (file == 0)
+ file = filename + strlen(filename);
+
+- user = malloc(file - filename);
++ len = file - filename - 1;
++ user = malloc(len + 1);
+ if (!user)
+ return NULL;
+
+- strncpy(user, filename + 1, file - filename - 1);
++ strncpy(user, &filename[1], len);
++ user[len] = 0;
+ passwd = getpwnam(user);
+ free(user);
+ }
diff --git a/meta-openembedded/meta-networking/recipes-support/libconfuse/libconfuse_3.3.bb b/meta-openembedded/meta-networking/recipes-support/libconfuse/libconfuse_3.3.bb
index b8d0536eb3..9a339326ca 100644
--- a/meta-openembedded/meta-networking/recipes-support/libconfuse/libconfuse_3.3.bb
+++ b/meta-openembedded/meta-networking/recipes-support/libconfuse/libconfuse_3.3.bb
@@ -3,7 +3,10 @@ LICENSE = "ISC"
LIC_FILES_CHKSUM = "file://LICENSE;md5=42fa47330d4051cd219f7d99d023de3a"
SRCREV = "a42aebf13db33afd575da6e63f55163d371f776d"
-SRC_URI = "git://github.com/libconfuse/libconfuse.git;branch=master;protocol=https"
+SRC_URI = " \
+ git://github.com/libconfuse/libconfuse.git;branch=master;protocol=https \
+ file://CVE-2022-40320.patch \
+"
inherit autotools-brokensep pkgconfig gettext
diff --git a/meta-openembedded/meta-networking/recipes-support/libldb/libldb_2.8.0.bb b/meta-openembedded/meta-networking/recipes-support/libldb/libldb_2.8.1.bb
index bdd87993d7..29ff2cf6f2 100644
--- a/meta-openembedded/meta-networking/recipes-support/libldb/libldb_2.8.0.bb
+++ b/meta-openembedded/meta-networking/recipes-support/libldb/libldb_2.8.1.bb
@@ -34,7 +34,7 @@ LIC_FILES_CHKSUM = "file://pyldb.h;endline=24;md5=dfbd238cecad76957f7f860fbe9ada
file://man/ldb.3.xml;beginline=261;endline=262;md5=137f9fd61040c1505d1aa1019663fd08 \
file://tools/ldbdump.c;endline=19;md5=a7d4fc5d1f75676b49df491575a86a42"
-SRC_URI[sha256sum] = "358dca10fcd27207ac857a0d7f435a46dbc6cd1f7c10dbb840c1931bf1965f08"
+SRC_URI[sha256sum] = "b68ce6eb0ccd2870fa3c8c334f2028b5d16606fd41308696c17b71959f7bf59f"
inherit pkgconfig waf-samba ptest
diff --git a/meta-openembedded/meta-networking/recipes-support/mdio-tools/mdio-netlink_1.3.1.bb b/meta-openembedded/meta-networking/recipes-support/mdio-tools/mdio-netlink_1.3.1.bb
index b50d33f908..3867b89052 100644
--- a/meta-openembedded/meta-networking/recipes-support/mdio-tools/mdio-netlink_1.3.1.bb
+++ b/meta-openembedded/meta-networking/recipes-support/mdio-tools/mdio-netlink_1.3.1.bb
@@ -3,11 +3,12 @@ require mdio-tools.inc
DEPENDS += "virtual/kernel libmnl"
# This module requires Linux 5.6 higher
-S = "${WORKDIR}/git/kernel"
+S = "${WORKDIR}/git"
inherit module
-EXTRA_OEMAKE = "KDIR=${STAGING_KERNEL_DIR}"
+EXTRA_OEMAKE = "-C kernel/ KDIR=${STAGING_KERNEL_DIR}"
+MODULES_MODULE_SYMVERS_LOCATION="kernel"
MODULES_INSTALL_TARGET = "install"
RPROVIDES:${PN} += "kernel-module-mdio-netlink"
diff --git a/meta-openembedded/meta-networking/recipes-support/memcached/memcached/CVE-2023-46852.patch b/meta-openembedded/meta-networking/recipes-support/memcached/memcached/CVE-2023-46852.patch
new file mode 100644
index 0000000000..2bb34af97a
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-support/memcached/memcached/CVE-2023-46852.patch
@@ -0,0 +1,71 @@
+From 44d8cfad2500881447cbfe2089bfd80b85ffcd7e Mon Sep 17 00:00:00 2001
+From: dormando <dormando@rydia.net>
+Date: Fri, 28 Jul 2023 10:32:16 -0700
+Subject: [PATCH] CVE-2023-46852
+
+proxy: fix buffer overflow with multiget syntax
+
+"get[200 spaces]key1 key2\r\n" would overflow a temporary buffer used to
+process multiget syntax.
+
+To exploit this you must first pass the check in try_read_command_proxy:
+- The request before the first newline must be less than 1024 bytes.
+- If it is more than 1024 bytes there is a limit of 100 spaces.
+- The key length is still checked at 250 bytes
+- Meaning you have up to 772 spaces and then the key to create stack
+ corruption.
+
+So the amount of data you can shove in here isn't unlimited.
+
+The fix caps the amount of data pre-key to be reasonable. Something like
+GAT needs space for a 32bit TTL which is at most going to be 15 bytes +
+spaces, so we limit it to 20 bytes.
+
+I hate hate hate hate hate the multiget syntax. hate it.
+
+CVE: CVE-2023-46852
+Upstream-Status: Backport [https://github.com/memcached/memcached/commit/76a6c363c18cfe7b6a1524ae64202ac9db330767]
+(cherry picked from commit 76a6c363c18cfe7b6a1524ae64202ac9db330767)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ proto_proxy.c | 16 ++++++++++++++--
+ 1 file changed, 14 insertions(+), 2 deletions(-)
+
+diff --git a/proto_proxy.c b/proto_proxy.c
+index 3ee8c07..9bef26d 100644
+--- a/proto_proxy.c
++++ b/proto_proxy.c
+@@ -616,6 +616,12 @@ int proxy_run_coroutine(lua_State *Lc, mc_resp *resp, io_pending_proxy_t *p, con
+ return 0;
+ }
+
++// basically any data before the first key.
++// max is like 15ish plus spaces. we can be more strict about how many spaces
++// to expect because any client spamming space is being deliberately stupid
++// anyway.
++#define MAX_CMD_PREFIX 20
++
+ static void proxy_process_command(conn *c, char *command, size_t cmdlen, bool multiget) {
+ assert(c != NULL);
+ LIBEVENT_THREAD *thr = c->thread;
+@@ -687,12 +693,18 @@ static void proxy_process_command(conn *c, char *command, size_t cmdlen, bool mu
+ if (!multiget && pr.cmd_type == CMD_TYPE_GET && pr.has_space) {
+ uint32_t keyoff = pr.tokens[pr.keytoken];
+ while (pr.klen != 0) {
+- char temp[KEY_MAX_LENGTH + 30];
++ char temp[KEY_MAX_LENGTH + MAX_CMD_PREFIX + 30];
+ char *cur = temp;
+ // Core daemon can abort the entire command if one key is bad, but
+ // we cannot from the proxy. Instead we have to inject errors into
+ // the stream. This should, thankfully, be rare at least.
+- if (pr.klen > KEY_MAX_LENGTH) {
++ if (pr.tokens[pr.keytoken] > MAX_CMD_PREFIX) {
++ if (!resp_start(c)) {
++ conn_set_state(c, conn_closing);
++ return;
++ }
++ proxy_out_errstring(c->resp, PROXY_CLIENT_ERROR, "malformed request");
++ } else if (pr.klen > KEY_MAX_LENGTH) {
+ if (!resp_start(c)) {
+ conn_set_state(c, conn_closing);
+ return;
diff --git a/meta-openembedded/meta-networking/recipes-support/memcached/memcached/CVE-2023-46853.patch b/meta-openembedded/meta-networking/recipes-support/memcached/memcached/CVE-2023-46853.patch
new file mode 100644
index 0000000000..cf8aaf467b
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-support/memcached/memcached/CVE-2023-46853.patch
@@ -0,0 +1,117 @@
+From 51c1f144d57379bd77f5b04c462171d26ebc5514 Mon Sep 17 00:00:00 2001
+From: dormando <dormando@rydia.net>
+Date: Wed, 2 Aug 2023 15:45:56 -0700
+Subject: [PATCH] CVE-2023-46853
+
+proxy: fix off-by-one if \r is missing
+
+A bunch of the parser assumed we only had \r\n, but I didn't actually
+have that strictness set. Some commands worked and some broke in subtle
+ways when just "\n" was being submitted.
+
+I'm not 100% confident in this change yet so I'm opening a PR to stage
+it while I run some more thorough tests.
+
+CVE: CVE-2023-46853
+Upstream-Status: Backport [https://github.com/memcached/memcached/commit/6987918e9a3094ec4fc8976f01f769f624d790fa]
+(cherry picked from commit 6987918e9a3094ec4fc8976f01f769f624d790fa)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ proxy.h | 1 +
+ proxy_request.c | 22 ++++++++++++++++------
+ t/proxy.t | 5 +++--
+ 3 files changed, 20 insertions(+), 8 deletions(-)
+
+diff --git a/proxy.h b/proxy.h
+index 015c093..29e5175 100644
+--- a/proxy.h
++++ b/proxy.h
+@@ -271,6 +271,7 @@ struct mcp_parser_s {
+ uint8_t keytoken; // because GAT. sigh. also cmds without a key.
+ uint32_t parsed; // how far into the request we parsed already
+ uint32_t reqlen; // full length of request buffer.
++ uint32_t endlen; // index to the start of \r\n or \n
+ int vlen;
+ uint32_t klen; // length of key.
+ uint16_t tokens[PARSER_MAX_TOKENS]; // offsets for start of each token
+diff --git a/proxy_request.c b/proxy_request.c
+index 457e9a1..6351d02 100644
+--- a/proxy_request.c
++++ b/proxy_request.c
+@@ -9,7 +9,7 @@
+ // where we later scan or directly feed data into API's.
+ static int _process_tokenize(mcp_parser_t *pr, const size_t max) {
+ const char *s = pr->request;
+- int len = pr->reqlen - 2;
++ int len = pr->endlen;
+
+ // since multigets can be huge, we can't purely judge reqlen against this
+ // limit, but we also can't index past it since the tokens are shorts.
+@@ -93,7 +93,7 @@ static int _process_request_key(mcp_parser_t *pr) {
+ // Returns the offset for the next key.
+ size_t _process_request_next_key(mcp_parser_t *pr) {
+ const char *cur = pr->request + pr->parsed;
+- int remain = pr->reqlen - pr->parsed - 2;
++ int remain = pr->endlen - pr->parsed;
+
+ // chew off any leading whitespace.
+ while (remain) {
+@@ -126,7 +126,7 @@ static int _process_request_metaflags(mcp_parser_t *pr, int token) {
+ return 0;
+ }
+ const char *cur = pr->request + pr->tokens[token];
+- const char *end = pr->request + pr->reqlen - 2;
++ const char *end = pr->request + pr->endlen;
+
+ // We blindly convert flags into bits, since the range of possible
+ // flags is deliberately < 64.
+@@ -290,15 +290,25 @@ int process_request(mcp_parser_t *pr, const char *command, size_t cmdlen) {
+ return -1;
+ }
+
+- const char *s = memchr(command, ' ', cmdlen-2);
++ // Commands can end with bare '\n's. Depressingly I intended to be strict
++ // with a \r\n requirement but never did this and need backcompat.
++ // In this case we _know_ \n is at cmdlen because we can't enter this
++ // function otherwise.
++ if (cm[cmdlen-2] == '\r') {
++ pr->endlen = cmdlen - 2;
++ } else {
++ pr->endlen = cmdlen - 1;
++ }
++
++ const char *s = memchr(command, ' ', pr->endlen);
+ if (s != NULL) {
+ cl = s - command;
+ } else {
+- cl = cmdlen - 2;
++ cl = pr->endlen;
+ }
+ pr->keytoken = 0;
+ pr->has_space = false;
+- pr->parsed = cl + 1;
++ pr->parsed = cl;
+ pr->request = command;
+ pr->reqlen = cmdlen;
+ int token_max = PARSER_MAX_TOKENS;
+diff --git a/t/proxy.t b/t/proxy.t
+index 37caa27..af6213a 100644
+--- a/t/proxy.t
++++ b/t/proxy.t
+@@ -151,13 +151,14 @@ my $p_sock = $p_srv->sock;
+ # NOTE: memcached always allowed [\r]\n for single command lines, but payloads
+ # (set/etc) require exactly \r\n as termination.
+ # doc/protocol.txt has always specified \r\n for command/response.
+-# Proxy is more strict than normal server in this case.
++# Note a bug lead me to believe that the proxy was more strict, we accept any
++# \n or \r\n terminated commands.
+ {
+ my $s = $srv[0]->sock;
+ print $s "version\n";
+ like(<$s>, qr/VERSION/, "direct server version cmd with just newline");
+ print $p_sock "version\n";
+- like(<$p_sock>, qr/SERVER_ERROR/, "proxy version cmd with just newline");
++ like(<$p_sock>, qr/VERSION/, "proxy version cmd with just newline");
+ print $p_sock "version\r\n";
+ like(<$p_sock>, qr/VERSION/, "proxy version cmd with full CRLF");
+ }
diff --git a/meta-openembedded/meta-networking/recipes-support/memcached/memcached_1.6.17.bb b/meta-openembedded/meta-networking/recipes-support/memcached/memcached_1.6.17.bb
index 270ad5486d..bfa1450368 100644
--- a/meta-openembedded/meta-networking/recipes-support/memcached/memcached_1.6.17.bb
+++ b/meta-openembedded/meta-networking/recipes-support/memcached/memcached_1.6.17.bb
@@ -22,9 +22,13 @@ RDEPENDS:${PN} += "perl perl-module-posix perl-module-autoloader \
SRC_URI = "http://www.memcached.org/files/${BP}.tar.gz \
file://memcached-add-hugetlbfs-check.patch \
file://0001-Fix-function-protypes.patch \
+ file://CVE-2023-46852.patch \
+ file://CVE-2023-46853.patch \
"
SRC_URI[sha256sum] = "2055e373613d8fc21529aff9f0adce3e23b9ce01ba0478d30e7941d9f2bd1224"
+CVE_STATUS[CVE-2022-26635] = "disputed: this is a problem of applications using php-memcached inproperly"
+
# set the same COMPATIBLE_HOST as libhugetlbfs
COMPATIBLE_HOST = "(i.86|x86_64|powerpc|powerpc64|aarch64|arm).*-linux*"
diff --git a/meta-openembedded/meta-networking/recipes-support/ndisc6/ndisc6/0001-Remove-use-of-variables-indicating-buildtime-informa.patch b/meta-openembedded/meta-networking/recipes-support/ndisc6/ndisc6/0001-Remove-use-of-variables-indicating-buildtime-informa.patch
new file mode 100644
index 0000000000..7bfb17bf08
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-support/ndisc6/ndisc6/0001-Remove-use-of-variables-indicating-buildtime-informa.patch
@@ -0,0 +1,85 @@
+From 7b3e78cf0348ea737609a2ace07c7c55aae36bcb Mon Sep 17 00:00:00 2001
+From: Santiago Vila <sanvila@debian.org>
+Date: Wed, 9 Oct 2024 22:05:09 -0700
+Subject: [PATCH] Remove use of variables indicating buildtime information
+
+We should not really care about the build date or the build host
+
+Sourced From: https://salsa.debian.org/debian/ndisc6/-/blob/master/debian/patches/reproducible-build.patch?ref_type=heads
+
+Upstream-Status: Pending
+Signed-off-by: Khem Raj <raj.khem@gmail.com>
+---
+ rdnss/rdnssd.c | 2 --
+ src/addrinfo.c | 2 --
+ src/ndisc.c | 2 --
+ src/tcpspray.c | 2 --
+ src/traceroute.c | 2 --
+ 5 files changed, 10 deletions(-)
+
+diff --git a/rdnss/rdnssd.c b/rdnss/rdnssd.c
+index b87edb2..7201525 100644
+--- a/rdnss/rdnssd.c
++++ b/rdnss/rdnssd.c
+@@ -741,8 +741,6 @@ version (void)
+ {
+ printf (_("rdnssd: IPv6 Recursive DNS Server discovery Daemon %s (%s)\n"),
+ VERSION, "$Rev$");
+- printf (_(" built %s on %s\n"), __DATE__, PACKAGE_BUILD_HOSTNAME);
+- printf (_("Configured with: %s\n"), PACKAGE_CONFIGURE_INVOCATION);
+ puts (_("Written by Pierre Ynard and Remi Denis-Courmont\n"));
+
+ printf (_("Copyright (C) %u-%u Pierre Ynard, Remi Denis-Courmont\n"),
+diff --git a/src/addrinfo.c b/src/addrinfo.c
+index cd73722..6316abd 100644
+--- a/src/addrinfo.c
++++ b/src/addrinfo.c
+@@ -148,8 +148,6 @@ static int quick_usage (const char *path)
+ static int version (void)
+ {
+ printf (_("addrinfo %s (%s)\n"), VERSION, "$Rev$");
+- printf (_(" built %s on %s\n"), __DATE__, PACKAGE_BUILD_HOSTNAME);
+- printf (_("Configured with: %s\n"), PACKAGE_CONFIGURE_INVOCATION);
+ puts (_("Written by Remi Denis-Courmont\n"));
+
+ printf (_("Copyright (C) %u-%u Remi Denis-Courmont\n"), 2002, 2007);
+diff --git a/src/ndisc.c b/src/ndisc.c
+index b190b18..6e222a0 100644
+--- a/src/ndisc.c
++++ b/src/ndisc.c
+@@ -920,9 +920,7 @@ version (void)
+ {
+ printf (_(
+ "ndisc6: IPv6 Neighbor/Router Discovery userland tool %s (%s)\n"), VERSION, "$Rev$");
+- printf (_(" built %s on %s\n"), __DATE__, PACKAGE_BUILD_HOSTNAME);
+
+- printf (_("Configured with: %s\n"), PACKAGE_CONFIGURE_INVOCATION);
+ puts (_("Written by Remi Denis-Courmont\n"));
+
+ printf (_("Copyright (C) %u-%u Remi Denis-Courmont\n"), 2004, 2007);
+diff --git a/src/tcpspray.c b/src/tcpspray.c
+index 39d8939..6347795 100644
+--- a/src/tcpspray.c
++++ b/src/tcpspray.c
+@@ -302,8 +302,6 @@ version (void)
+ {
+ printf (_(
+ "tcpspray6: TCP/IP bandwidth tester %s (%s)\n"), VERSION, "$Rev$");
+- printf (_(" built %s on %s\n"), __DATE__, PACKAGE_BUILD_HOSTNAME);
+- printf (_("Configured with: %s\n"), PACKAGE_CONFIGURE_INVOCATION);
+ puts (_("Written by Remi Denis-Courmont\n"));
+
+ printf (_("Copyright (C) %u-%u Remi Denis-Courmont\n"), 2005, 2007);
+diff --git a/src/traceroute.c b/src/traceroute.c
+index 489bc55..604b6af 100644
+--- a/src/traceroute.c
++++ b/src/traceroute.c
+@@ -1251,8 +1251,6 @@ version (void)
+ {
+ printf (_(
+ "traceroute6: TCP & UDP IPv6 traceroute tool %s (%s)\n"), VERSION, "$Rev$");
+- printf (_(" built %s on %s\n"), __DATE__, PACKAGE_BUILD_HOSTNAME);
+- printf (_("Configured with: %s\n"), PACKAGE_CONFIGURE_INVOCATION);
+ puts (_("Written by Remi Denis-Courmont\n"));
+
+ printf (_("Copyright (C) %u-%u Remi Denis-Courmont\n"), 2005, 2007);
diff --git a/meta-openembedded/meta-networking/recipes-support/ndisc6/ndisc6_1.0.8.bb b/meta-openembedded/meta-networking/recipes-support/ndisc6/ndisc6_1.0.8.bb
index a827e7f42a..21579d64c1 100644
--- a/meta-openembedded/meta-networking/recipes-support/ndisc6/ndisc6_1.0.8.bb
+++ b/meta-openembedded/meta-networking/recipes-support/ndisc6/ndisc6_1.0.8.bb
@@ -8,6 +8,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=751419260aa954499f7abaabaa882bbe"
SRCREV = "92e5d1cf6547fe40316b2a6ca2f7b8195ae0cbe5"
SRC_URI = "git://git.remlab.net/git/ndisc6.git;protocol=http;branch=master \
file://0001-autogen-Do-not-symlink-gettext.h-from-build-host.patch \
+ file://0001-Remove-use-of-variables-indicating-buildtime-informa.patch \
"
S = "${WORKDIR}/git"
@@ -27,6 +28,10 @@ do_configure:prepend() {
${S}/autogen.sh
}
+do_configure:append() {
+ sed -i -e 's|${WORKDIR}|<scrubbed>|g' ${B}/config.h
+}
+
do_install:append () {
rm -rf ${D}${localstatedir}
# Enable SUID bit for applications that need it
diff --git a/meta-openembedded/meta-networking/recipes-support/ntopng/ndpi_4.2.bb b/meta-openembedded/meta-networking/recipes-support/ntopng/ndpi_4.2.bb
index 13c3398c2b..d768f85d31 100644
--- a/meta-openembedded/meta-networking/recipes-support/ntopng/ndpi_4.2.bb
+++ b/meta-openembedded/meta-networking/recipes-support/ntopng/ndpi_4.2.bb
@@ -26,3 +26,5 @@ do_configure:prepend() {
EXTRA_OEMAKE = " \
libdir=${libdir} \
"
+
+CVE_STATUS[CVE-2025-25066] = "cpe-incorrect: Current version (4.2) is not affected."
diff --git a/meta-openembedded/meta-networking/recipes-support/open-vm-tools/open-vm-tools/CVE-2025-22247.patch b/meta-openembedded/meta-networking/recipes-support/open-vm-tools/open-vm-tools/CVE-2025-22247.patch
new file mode 100644
index 0000000000..4db79ef96d
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-support/open-vm-tools/open-vm-tools/CVE-2025-22247.patch
@@ -0,0 +1,378 @@
+From 7874e572b5aac5a418551dc5e3935c1e74bf6f1f Mon Sep 17 00:00:00 2001
+From: John Wolfe <john.wolfe@broadcom.com>
+Date: Mon, 5 May 2025 15:58:03 -0700
+Subject: [PATCH] Validate user names and file paths
+
+Prevent usage of illegal characters in user names and file paths.
+Also, disallow unexpected symlinks in file paths.
+
+This patch contains changes to common source files not applicable
+to open-vm-tools.
+
+All files being updated should be consider to have the copyright to
+be updated to:
+
+ * Copyright (c) XXXX-2025 Broadcom. All Rights Reserved.
+ * The term "Broadcom" refers to Broadcom Inc. and/or its subsidiaries.
+
+The 2025 Broadcom copyright information update is not part of this
+patch set to allow the patch to be easily applied to previous
+open-vm-tools source releases.
+
+Upstream-Status: Backport [https://github.com/vmware/open-vm-tools/blob/CVE-2025-22247.patch/CVE-2025-22247-1230-1250-VGAuth-updates.patch]
+CVE: CVE-2025-22247
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ open-vm-tools/vgauth/common/VGAuthUtil.c | 33 +++++++++
+ open-vm-tools/vgauth/common/VGAuthUtil.h | 2 +
+ open-vm-tools/vgauth/common/prefs.h | 3 +
+ open-vm-tools/vgauth/common/usercheck.c | 23 +++++-
+ open-vm-tools/vgauth/serviceImpl/alias.c | 74 ++++++++++++++++++-
+ open-vm-tools/vgauth/serviceImpl/service.c | 27 +++++++
+ open-vm-tools/vgauth/serviceImpl/serviceInt.h | 1 +
+ 7 files changed, 160 insertions(+), 3 deletions(-)
+
+diff --git a/open-vm-tools/vgauth/common/VGAuthUtil.c b/open-vm-tools/vgauth/common/VGAuthUtil.c
+index 76383c462..9c2adb8d0 100644
+--- a/open-vm-tools/vgauth/common/VGAuthUtil.c
++++ b/open-vm-tools/vgauth/common/VGAuthUtil.c
+@@ -309,3 +309,36 @@ Util_Assert(const char *cond,
+ #endif
+ g_assert(0);
+ }
++
++
++/*
++ ******************************************************************************
++ * Util_Utf8CaseCmp -- */ /**
++ *
++ * Case insensitive comparison for utf8 strings which can have non-ascii
++ * characters.
++ *
++ * @param[in] str1 Null terminated utf8 string.
++ * @param[in] str2 Null terminated utf8 string.
++ *
++ ******************************************************************************
++ */
++
++int
++Util_Utf8CaseCmp(const gchar *str1,
++ const gchar *str2)
++{
++ int ret;
++ gchar *str1Case;
++ gchar *str2Case;
++
++ str1Case = g_utf8_casefold(str1, -1);
++ str2Case = g_utf8_casefold(str2, -1);
++
++ ret = g_strcmp0(str1Case, str2Case);
++
++ g_free(str1Case);
++ g_free(str2Case);
++
++ return ret;
++}
+diff --git a/open-vm-tools/vgauth/common/VGAuthUtil.h b/open-vm-tools/vgauth/common/VGAuthUtil.h
+index f7f3aa216..ef32a91da 100644
+--- a/open-vm-tools/vgauth/common/VGAuthUtil.h
++++ b/open-vm-tools/vgauth/common/VGAuthUtil.h
+@@ -105,4 +105,6 @@ gboolean Util_CheckExpiration(const GTimeVal *start, unsigned int duration);
+
+ void Util_Assert(const char *cond, const char *file, int lineNum);
+
++int Util_Utf8CaseCmp(const gchar *str1, const gchar *str2);
++
+ #endif
+diff --git a/open-vm-tools/vgauth/common/prefs.h b/open-vm-tools/vgauth/common/prefs.h
+index 6c58f3f4b..3299eb26c 100644
+--- a/open-vm-tools/vgauth/common/prefs.h
++++ b/open-vm-tools/vgauth/common/prefs.h
+@@ -167,6 +167,9 @@ msgCatalog = /etc/vmware-tools/vgauth/messages
+ /** Where the localized version of the messages were installed. */
+ #define VGAUTH_PREF_LOCALIZATION_DIR "msgCatalog"
+
++/** If symlinks or junctions are allowed in alias store file path */
++#define VGAUTH_PREF_ALLOW_SYMLINKS "allowSymlinks"
++
+ /*
+ * Pref values
+ */
+diff --git a/open-vm-tools/vgauth/common/usercheck.c b/open-vm-tools/vgauth/common/usercheck.c
+index 3beede2e8..340aa0411 100644
+--- a/open-vm-tools/vgauth/common/usercheck.c
++++ b/open-vm-tools/vgauth/common/usercheck.c
+@@ -78,6 +78,8 @@
+ * Solaris as well, but that path is untested.
+ */
+
++#define MAX_USER_NAME_LEN 256
++
+ /*
+ * A single retry works for the LDAP case, but try more often in case NIS
+ * or something else has a related issue. Note that a bad username/uid won't
+@@ -354,12 +356,29 @@ Usercheck_UsernameIsLegal(const gchar *userName)
+ * restricted list for local usernames.
+ */
+ size_t len;
+- char *illegalChars = "<>/";
++ size_t i = 0;
++ int backSlashCnt = 0;
++ /*
++ * As user names are used to generate its alias store file name/path, it
++ * should not contain path traversal characters ('/' and '\').
++ */
++ char *illegalChars = "<>/\\";
+
+ len = strlen(userName);
+- if (strcspn(userName, illegalChars) != len) {
++ if (len > MAX_USER_NAME_LEN) {
+ return FALSE;
+ }
++
++ while ((i += strcspn(userName + i, illegalChars)) < len) {
++ /*
++ * One backward slash is allowed for domain\username separator.
++ */
++ if (userName[i] != '\\' || ++backSlashCnt > 1) {
++ return FALSE;
++ }
++ ++i;
++ }
++
+ return TRUE;
+ }
+
+diff --git a/open-vm-tools/vgauth/serviceImpl/alias.c b/open-vm-tools/vgauth/serviceImpl/alias.c
+index 4e170202c..c7040ebff 100644
+--- a/open-vm-tools/vgauth/serviceImpl/alias.c
++++ b/open-vm-tools/vgauth/serviceImpl/alias.c
+@@ -41,6 +41,7 @@
+ #include "certverify.h"
+ #include "VGAuthProto.h"
+ #include "vmxlog.h"
++#include "VGAuthUtil.h"
+
+ // puts the identity store in an easy to find place
+ #undef WIN_TEST_MODE
+@@ -66,6 +67,7 @@
+ #define ALIASSTORE_FILE_PREFIX "user-"
+ #define ALIASSTORE_FILE_SUFFIX ".xml"
+
++static gboolean allowSymlinks = FALSE;
+ static gchar *aliasStoreRootDir = DEFAULT_ALIASSTORE_ROOT_DIR;
+
+ #ifdef _WIN32
+@@ -252,6 +254,12 @@ mapping file layout:
+
+ */
+
++#ifdef _WIN32
++#define ISPATHSEP(c) ((c) == '\\' || (c) == '/')
++#else
++#define ISPATHSEP(c) ((c) == '/')
++#endif
++
+
+ /*
+ ******************************************************************************
+@@ -466,6 +474,7 @@ ServiceLoadFileContentsWin(const gchar *fileName,
+ gunichar2 *fileNameW = NULL;
+ BOOL ok;
+ DWORD bytesRead;
++ gchar *realPath = NULL;
+
+ *fileSize = 0;
+ *contents = NULL;
+@@ -622,6 +631,22 @@ ServiceLoadFileContentsWin(const gchar *fileName,
+ goto done;
+ }
+
++ if (!allowSymlinks) {
++ /*
++ * Check if fileName is real path.
++ */
++ if ((realPath = ServiceFileGetPathByHandle(hFile)) == NULL) {
++ err = VGAUTH_E_FAIL;
++ goto done;
++ }
++ if (Util_Utf8CaseCmp(realPath, fileName) != 0) {
++ Warning("%s: Real path (%s) is not same as file path (%s)\n",
++ __FUNCTION__, realPath, fileName);
++ err = VGAUTH_E_FAIL;
++ goto done;
++ }
++ }
++
+ /*
+ * Now finally read the contents.
+ */
+@@ -650,6 +675,7 @@ done:
+ CloseHandle(hFile);
+ }
+ g_free(fileNameW);
++ g_free(realPath);
+
+ return err;
+ }
+@@ -672,6 +698,7 @@ ServiceLoadFileContentsPosix(const gchar *fileName,
+ gchar *buf;
+ gchar *bp;
+ int fd = -1;
++ gchar realPath[PATH_MAX] = { 0 };
+
+ *fileSize = 0;
+ *contents = NULL;
+@@ -817,6 +844,23 @@ ServiceLoadFileContentsPosix(const gchar *fileName,
+ goto done;
+ }
+
++ if (!allowSymlinks) {
++ /*
++ * Check if fileName is real path.
++ */
++ if (realpath(fileName, realPath) == NULL) {
++ Warning("%s: realpath() failed. errno (%d)\n", __FUNCTION__, errno);
++ err = VGAUTH_E_FAIL;
++ goto done;
++ }
++ if (g_strcmp0(realPath, fileName) != 0) {
++ Warning("%s: Real path (%s) is not same as file path (%s)\n",
++ __FUNCTION__, realPath, fileName);
++ err = VGAUTH_E_FAIL;
++ goto done;
++ }
++ }
++
+ /*
+ * All confidence checks passed; read the bits.
+ */
+@@ -2803,8 +2847,13 @@ ServiceAliasRemoveAlias(const gchar *reqUserName,
+
+ /*
+ * We don't verify the user exists in a Remove operation, to allow
+- * cleanup of deleted user's stores.
++ * cleanup of deleted user's stores, but we do check whether the
++ * user name is legal or not.
+ */
++ if (!Usercheck_UsernameIsLegal(userName)) {
++ Warning("%s: Illegal user name '%s'\n", __FUNCTION__, userName);
++ return VGAUTH_E_FAIL;
++ }
+
+ if (!CertVerify_IsWellFormedPEMCert(pemCert)) {
+ return VGAUTH_E_INVALID_CERTIFICATE;
+@@ -3036,6 +3085,16 @@ ServiceAliasQueryAliases(const gchar *userName,
+ }
+ #endif
+
++ /*
++ * We don't verify the user exists in a Query operation to allow
++ * cleaning up after a deleted user, but we do check whether the
++ * user name is legal or not.
++ */
++ if (!Usercheck_UsernameIsLegal(userName)) {
++ Warning("%s: Illegal user name '%s'\n", __FUNCTION__, userName);
++ return VGAUTH_E_FAIL;
++ }
++
+ err = AliasLoadAliases(userName, num, aList);
+ if (VGAUTH_E_OK != err) {
+ Warning("%s: failed to load Aliases for '%s'\n", __FUNCTION__, userName);
+@@ -3294,6 +3353,7 @@ ServiceAliasInitAliasStore(void)
+ VGAuthError err = VGAUTH_E_OK;
+ gboolean saveBadDir = FALSE;
+ char *defaultDir = NULL;
++ size_t len;
+
+ #ifdef _WIN32
+ {
+@@ -3324,6 +3384,10 @@ ServiceAliasInitAliasStore(void)
+ defaultDir = g_strdup(DEFAULT_ALIASSTORE_ROOT_DIR);
+ #endif
+
++ allowSymlinks = Pref_GetBool(gPrefs,
++ VGAUTH_PREF_ALLOW_SYMLINKS,
++ VGAUTH_PREF_GROUP_NAME_SERVICE,
++ FALSE);
+ /*
+ * Find the alias store directory. This allows an installer to put
+ * it somewhere else if necessary.
+@@ -3337,6 +3401,14 @@ ServiceAliasInitAliasStore(void)
+ VGAUTH_PREF_GROUP_NAME_SERVICE,
+ defaultDir);
+
++ /*
++ * Remove the trailing separator if any from aliasStoreRootDir path.
++ */
++ len = strlen(aliasStoreRootDir);
++ if (ISPATHSEP(aliasStoreRootDir[len - 1])) {
++ aliasStoreRootDir[len - 1] = '\0';
++ }
++
+ Log("Using '%s' for alias store root directory\n", aliasStoreRootDir);
+
+ g_free(defaultDir);
+diff --git a/open-vm-tools/vgauth/serviceImpl/service.c b/open-vm-tools/vgauth/serviceImpl/service.c
+index d4716526c..e053ed0fa 100644
+--- a/open-vm-tools/vgauth/serviceImpl/service.c
++++ b/open-vm-tools/vgauth/serviceImpl/service.c
+@@ -28,6 +28,7 @@
+ #include "VGAuthUtil.h"
+ #ifdef _WIN32
+ #include "winUtil.h"
++#include <glib.h>
+ #endif
+
+ static ServiceStartListeningForIOFunc startListeningIOFunc = NULL;
+@@ -283,9 +284,35 @@ static gchar *
+ ServiceUserNameToPipeName(const char *userName)
+ {
+ gchar *escapedName = ServiceEncodeUserName(userName);
++#ifdef _WIN32
++ /*
++ * Adding below pragma only in windows to suppress the compile time warning
++ * about unavailability of g_uuid_string_random() since compiler flag
++ * GLIB_VERSION_MAX_ALLOWED is defined to GLIB_VERSION_2_34.
++ * TODO: Remove below pragma when GLIB_VERSION_MAX_ALLOWED is bumped up to
++ * or greater than GLIB_VERSION_2_52.
++ */
++#pragma warning(suppress : 4996)
++ gchar *uuidStr = g_uuid_string_random();
++ /*
++ * Add a unique suffix to avoid a name collision with an existing named pipe
++ * created by someone else (intentionally or by accident).
++ * This is not needed for Linux; name collisions on sockets are already
++ * avoided there since (1) file system paths to VGAuthService sockets are in
++ * a directory that is writable only by root and (2) VGAuthService unlinks a
++ * socket path before binding it to a newly created socket.
++ */
++ gchar *pipeName = g_strdup_printf("%s-%s-%s",
++ SERVICE_PUBLIC_PIPE_NAME,
++ escapedName,
++ uuidStr);
++
++ g_free(uuidStr);
++#else
+ gchar *pipeName = g_strdup_printf("%s-%s",
+ SERVICE_PUBLIC_PIPE_NAME,
+ escapedName);
++#endif
+
+ g_free(escapedName);
+ return pipeName;
+diff --git a/open-vm-tools/vgauth/serviceImpl/serviceInt.h b/open-vm-tools/vgauth/serviceImpl/serviceInt.h
+index 5f420192b..f4f88547d 100644
+--- a/open-vm-tools/vgauth/serviceImpl/serviceInt.h
++++ b/open-vm-tools/vgauth/serviceImpl/serviceInt.h
+@@ -441,6 +441,7 @@ VGAuthError ServiceFileVerifyAdminGroupOwnedByHandle(const HANDLE hFile);
+ VGAuthError ServiceFileVerifyEveryoneReadableByHandle(const HANDLE hFile);
+ VGAuthError ServiceFileVerifyUserAccessByHandle(const HANDLE hFile,
+ const char *userName);
++gchar *ServiceFileGetPathByHandle(HANDLE hFile);
+ #else
+ VGAuthError ServiceFileVerifyFileOwnerAndPerms(const char *fileName,
+ const char *userName,
+--
+2.49.0
+
diff --git a/meta-openembedded/meta-networking/recipes-support/open-vm-tools/open-vm-tools/CVE-2025-41244.patch b/meta-openembedded/meta-networking/recipes-support/open-vm-tools/open-vm-tools/CVE-2025-41244.patch
new file mode 100644
index 0000000000..4d3f80f3d7
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-support/open-vm-tools/open-vm-tools/CVE-2025-41244.patch
@@ -0,0 +1,123 @@
+From 7ed196cf01f8acd09011815a605b6733894b8aab Mon Sep 17 00:00:00 2001
+From: Kruti Pendharkar <kp025370@broadcom.com>
+Date: Mon, 29 Sep 2025 01:02:40 -0700
+Subject: [PATCH] Address CVE-2025-41244 - Disable (default) the execution of
+ the SDMP get-versions.sh script.
+
+With the Linux SDMP get-versions.sh script disabled, version information
+of installed services will not be made available to VMware Aria
+
+CVE: CVE-2025-41244
+
+Upstream-Status: Backport [https://github.com/vmware/open-vm-tools/commit/7ed196cf01f8acd09011815a605b6733894b8aab]
+
+Signed-off-by: Rajeshkumar Ramasamy <rajeshkumar.ramasamy@windriver.com>
+---
+ .../serviceDiscovery/serviceDiscovery.c | 37 ++++++++++++++++---
+ 1 file changed, 32 insertions(+), 5 deletions(-)
+
+diff --git a/open-vm-tools/services/plugins/serviceDiscovery/serviceDiscovery.c b/open-vm-tools/services/plugins/serviceDiscovery/serviceDiscovery.c
+index 103cf14..bf928c8 100644
+--- a/open-vm-tools/services/plugins/serviceDiscovery/serviceDiscovery.c
++++ b/open-vm-tools/services/plugins/serviceDiscovery/serviceDiscovery.c
+@@ -1,5 +1,6 @@
+ /*********************************************************
+- * Copyright (C) 2020-2021,2023 VMware, Inc. All rights reserved.
++ * Copyright (c) 2020-2025 Broadcom. All Rights Reserved.
++ * The term "Broadcom" refers to Broadcom Inc. and/or its subsidiaries.
+ *
+ * This program is free software; you can redistribute it and/or modify it
+ * under the terms of the GNU Lesser General Public License as published
+@@ -115,6 +116,12 @@ static gchar* scriptInstallDir = NULL;
+ */
+ #define SERVICE_DISCOVERY_RPC_WAIT_TIME 100
+
++/*
++ * Defines the configuration to enable/disable version obtaining logic
++ */
++#define CONFNAME_SERVICEDISCOVERY_VERSION_CHECK "version-check-enabled"
++#define SERVICE_DISCOVERY_CONF_DEFAULT_VERSION_CHECK FALSE
++
+ /*
+ * Defines the configuration to cache data in gdp plugin
+ */
+@@ -1239,23 +1246,27 @@ ServiceDiscoveryServerShutdown(gpointer src,
+ *
+ * Construct final paths of the scripts that will be used for execution.
+ *
++ * @param[in] versionCheckEnabled TRUE to include the SERVICE_DISCOVERY_KEY_VERSIONS
++ * entry; FALSE to skip it (derived from config).
++ *
+ *****************************************************************************
+ */
+
+ static void
+-ConstructScriptPaths(void)
++ConstructScriptPaths(Bool versionCheckEnabled)
+ {
+ int i;
+ #if !defined(OPEN_VM_TOOLS)
+ gchar *toolsInstallDir;
+ #endif
++ int insertIndex = 0;
+
+ if (gFullPaths != NULL) {
+ return;
+ }
+
+ gFullPaths = g_array_sized_new(FALSE, TRUE, sizeof(KeyNameValue),
+- ARRAYSIZE(gKeyScripts));
++ ARRAYSIZE(gKeyScripts) - (versionCheckEnabled ? 0u : 1u));
+ if (scriptInstallDir == NULL) {
+ #if defined(OPEN_VM_TOOLS)
+ scriptInstallDir = Util_SafeStrdup(VMTOOLS_SERVICE_DISCOVERY_SCRIPTS);
+@@ -1267,6 +1278,15 @@ ConstructScriptPaths(void)
+ #endif
+ }
+ for (i = 0; i < ARRAYSIZE(gKeyScripts); ++i) {
++ /*
++ * Skip adding if:
++ * 1. Version check is disabled, AND
++ * 2. The keyName matches SERVICE_DISCOVERY_KEY_VERSIONS
++ */
++ if (!versionCheckEnabled &&
++ g_strcmp0(gKeyScripts[i].keyName, SERVICE_DISCOVERY_KEY_VERSIONS) == 0) {
++ continue;
++ }
+ KeyNameValue tmp;
+ tmp.keyName = g_strdup_printf("%s", gKeyScripts[i].keyName);
+ #if defined(_WIN32)
+@@ -1274,7 +1294,8 @@ ConstructScriptPaths(void)
+ #else
+ tmp.val = g_strdup_printf("%s%s%s", scriptInstallDir, DIRSEPS, gKeyScripts[i].val);
+ #endif
+- g_array_insert_val(gFullPaths, i, tmp);
++ g_array_insert_val(gFullPaths, insertIndex, tmp);
++ insertIndex++;
+ }
+ }
+
+@@ -1340,14 +1361,20 @@ ToolsOnLoad(ToolsAppCtx *ctx)
+ }
+ };
+ gboolean disabled;
++ Bool versionCheckEnabled;
+
+ regData.regs = VMTools_WrapArray(regs,
+ sizeof *regs,
+ ARRAYSIZE(regs));
++ versionCheckEnabled = VMTools_ConfigGetBoolean(
++ ctx->config,
++ CONFGROUPNAME_SERVICEDISCOVERY,
++ CONFNAME_SERVICEDISCOVERY_VERSION_CHECK,
++ SERVICE_DISCOVERY_CONF_DEFAULT_VERSION_CHECK);
+ /*
+ * Append scripts execution command line
+ */
+- ConstructScriptPaths();
++ ConstructScriptPaths(versionCheckEnabled);
+
+ disabled =
+ VMTools_ConfigGetBoolean(ctx->config,
+--
+2.40.0
diff --git a/meta-openembedded/meta-networking/recipes-support/open-vm-tools/open-vm-tools_12.3.5.bb b/meta-openembedded/meta-networking/recipes-support/open-vm-tools/open-vm-tools_12.3.5.bb
index 82aab051f1..1ef2781d6a 100644
--- a/meta-openembedded/meta-networking/recipes-support/open-vm-tools/open-vm-tools_12.3.5.bb
+++ b/meta-openembedded/meta-networking/recipes-support/open-vm-tools/open-vm-tools_12.3.5.bb
@@ -43,6 +43,8 @@ SRC_URI = "git://github.com/vmware/open-vm-tools.git;protocol=https;branch=stabl
file://0012-hgfsServerLinux-Consider-64bit-time_t-possibility.patch;patchdir=.. \
file://0013-open-vm-tools-Correct-include-path-for-poll.h.patch;patchdir=.. \
file://0014-timeSync-Portable-way-to-print-64bit-time_t.patch;patchdir=.. \
+ file://CVE-2025-22247.patch;patchdir=.. \
+ file://CVE-2025-41244.patch;patchdir=.. \
"
UPSTREAM_CHECK_GITTAGREGEX = "stable-(?P<pver>\d+(\.\d+)+)"
diff --git a/meta-openembedded/meta-networking/recipes-support/openipmi/openipmi_2.0.34.bb b/meta-openembedded/meta-networking/recipes-support/openipmi/openipmi_2.0.36.bb
index eacbe5ce96..583b64c7de 100644
--- a/meta-openembedded/meta-networking/recipes-support/openipmi/openipmi_2.0.34.bb
+++ b/meta-openembedded/meta-networking/recipes-support/openipmi/openipmi_2.0.36.bb
@@ -34,7 +34,7 @@ SRC_URI = "${SOURCEFORGE_MIRROR}/openipmi/OpenIPMI-${PV}.tar.gz \
S = "${WORKDIR}/OpenIPMI-${PV}"
-SRC_URI[sha256sum] = "93227e43c72b5c3bd5949323e0669aa5527d1a971473a3a365af03fb8284a95f"
+SRC_URI[sha256sum] = "a0403148fa5f7bed930c958a4d1c558047e273763a408b3a0368edc137cc55d9"
inherit autotools-brokensep pkgconfig perlnative update-rc.d systemd cpan-base python3targetconfig
diff --git a/meta-openembedded/meta-networking/recipes-support/openvpn/openvpn_2.6.10.bb b/meta-openembedded/meta-networking/recipes-support/openvpn/openvpn_2.6.14.bb
index f8de78ff74..5361709f0c 100644
--- a/meta-openembedded/meta-networking/recipes-support/openvpn/openvpn_2.6.10.bb
+++ b/meta-openembedded/meta-networking/recipes-support/openvpn/openvpn_2.6.14.bb
@@ -14,7 +14,7 @@ SRC_URI = "http://swupdate.openvpn.org/community/releases/${BP}.tar.gz \
UPSTREAM_CHECK_URI = "https://openvpn.net/community-downloads"
-SRC_URI[sha256sum] = "1993bbb7b9edb430626eaa24573f881fd3df642f427fcb824b1aed1fca1bcc9b"
+SRC_URI[sha256sum] = "9eb6a6618352f9e7b771a9d38ae1631b5edfeed6d40233e243e602ddf2195e7a"
CVE_STATUS[CVE-2020-27569] = "not-applicable-config: Applies only Aviatrix OpenVPN client, not openvpn"
diff --git a/meta-openembedded/meta-networking/recipes-support/ssmping/ssmping_0.9.1.bb b/meta-openembedded/meta-networking/recipes-support/ssmping/ssmping_0.9.1.bb
index 0531ffe640..307120dc75 100644
--- a/meta-openembedded/meta-networking/recipes-support/ssmping/ssmping_0.9.1.bb
+++ b/meta-openembedded/meta-networking/recipes-support/ssmping/ssmping_0.9.1.bb
@@ -4,10 +4,9 @@ SECTION = "net"
LICENSE = "ISC"
LIC_FILES_CHKSUM = "file://asmping.c;beginline=2;endline=11;md5=1ca8d1a1ca931e5cfe604ebf20a78b71"
-SRC_URI = "http://www.venaas.no/multicast/ssmping/${BP}.tar.gz \
+SRC_URI = "${DEBIAN_MIRROR}/main/s/${BPN}/${BPN}_${PV}.orig.tar.gz;downloadfilename=${BP}.tar.gz \
file://0001-Makefile-tweak-install-dir.patch \
"
-SRC_URI[md5sum] = "ad8e3d13f6d72918f73be7e7975d7fad"
SRC_URI[sha256sum] = "22103a37eaa28489169a0927bc01e0596c3485fc4d29fc8456c07fd2c70fca6d"
CFLAGS += "-D_GNU_SOURCE "
diff --git a/meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay/CVE-2023-4256.patch b/meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay/CVE-2023-4256.patch
new file mode 100644
index 0000000000..2e4eee025b
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay/CVE-2023-4256.patch
@@ -0,0 +1,27 @@
+From 62bc10d4f1d2c9e2833ef2898fb0170e9300a9dd Mon Sep 17 00:00:00 2001
+From: Marsman1996 <lqliuyuwei@outlook.com>
+Date: Tue, 2 Apr 2024 17:29:21 +0800
+Subject: [PATCH] dlt_jnpr_ether_cleanup: check config before cleanup
+
+CVE: CVE-2023-4256
+Upstream-Status: Backport [https://github.com/appneta/tcpreplay/pull/851]
+Signed-off-by: Poonam Jadhav <poonam.jadhav@kpit.com>
+---
+ src/tcpedit/plugins/dlt_jnpr_ether/jnpr_ether.c | 3 ++-
+ 1 file changed, 2 insertions(+), 1 deletion(-)
+
+diff --git a/src/tcpedit/plugins/dlt_jnpr_ether/jnpr_ether.c b/src/tcpedit/plugins/dlt_jnpr_ether/jnpr_ether.c
+index c53ec297..9642a2c2 100644
+--- a/src/tcpedit/plugins/dlt_jnpr_ether/jnpr_ether.c
++++ b/src/tcpedit/plugins/dlt_jnpr_ether/jnpr_ether.c
+@@ -164,8 +164,9 @@ dlt_jnpr_ether_cleanup(tcpeditdlt_t *ctx)
+ jnpr_ether_config_t *config;
+
+ config = (jnpr_ether_config_t *)ctx->encoder->config;
+- if (config->subctx != NULL)
++ if (config != NULL && config->subctx != NULL) {
+ tcpedit_dlt_cleanup(config->subctx);
++ }
+ safe_free(plugin->config);
+ plugin->config = NULL;
+ plugin->config_size = 0;
diff --git a/meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay/CVE-2023-43279.patch b/meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay/CVE-2023-43279.patch
new file mode 100644
index 0000000000..45581268c0
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay/CVE-2023-43279.patch
@@ -0,0 +1,39 @@
+From 3164a75f2660a5c3537feff9fd8751346cf5ca57 Mon Sep 17 00:00:00 2001
+From: Gabriel Ganne <gabriel.ganne@gmail.com>
+Date: Sun, 21 Jan 2024 09:16:38 +0100
+Subject: [PATCH] add check for empty cidr
+
+This causes tcprewrite to exit with an error instead of crashing.
+
+Fixes: #824
+
+Upstream-Status: Backport
+CVE: CVE-2023-43279
+
+Reference to upstream patch:
+https://github.com/appneta/tcpreplay/pull/860/commits/963842ceca79e97ac3242448a0de94fb901d3560
+
+Signed-off-by: Gabriel Ganne <gabriel.ganne@gmail.com>
+Signed-off-by: Jiaying Song <jiaying.song.cn@windriver.com>
+---
+ src/common/cidr.c | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/src/common/cidr.c b/src/common/cidr.c
+index 687fd04..9afbfec 100644
+--- a/src/common/cidr.c
++++ b/src/common/cidr.c
+@@ -249,6 +249,10 @@ parse_cidr(tcpr_cidr_t **cidrdata, char *cidrin, char *delim)
+ char *network;
+ char *token = NULL;
+
++ if (cidrin == NULL) {
++ errx(-1, "%s", "Unable to parse empty CIDR");
++ }
++
+ mask_cidr6(&cidrin, delim);
+
+ /* first iteration of input using strtok */
+--
+2.25.1
+
diff --git a/meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay/CVE-2024-22654-0001.patch b/meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay/CVE-2024-22654-0001.patch
new file mode 100644
index 0000000000..26dedba8d4
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay/CVE-2024-22654-0001.patch
@@ -0,0 +1,90 @@
+From 5b5644356693f5c68dd4295e86f24f1d0a515d60 Mon Sep 17 00:00:00 2001
+From: Fred Klassen <fred.klassen@broadcom.com>
+Date: Sat, 1 Jun 2024 11:46:10 -0700
+Subject: [PATCH 1/2] Bug #827 PR# 842: add check for IPv6 extension header
+ length
+
+CVE: CVE-2024-22654
+
+Upstream-Status: Backport [https://github.com/appneta/tcpreplay/commit/5b5644356693f5c68dd4295e86f24f1d0a515d60]
+
+Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
+---
+ src/common/get.c | 29 +++++++++++++++++++++--------
+ 1 file changed, 21 insertions(+), 8 deletions(-)
+
+diff --git a/src/common/get.c b/src/common/get.c
+index 2d91116..89fe95b 100644
+--- a/src/common/get.c
++++ b/src/common/get.c
+@@ -41,8 +41,8 @@ extern const char pcap_version[];
+ static void *get_ipv6_next(struct tcpr_ipv6_ext_hdr_base *exthdr, const u_char *end_ptr);
+
+ /**
+- * Depending on what version of libpcap/WinPcap there are different ways to get
+- * the version of the libpcap/WinPcap library. This presents a unified way to
++ * Depending on what version of libpcap there are different ways to get
++ * the version of the libpcap library. This presents a unified way to
+ * get that information.
+ */
+ const char *
+@@ -196,8 +196,15 @@ parse_metadata(const u_char *pktdata,
+ uint32_t *vlan_offset)
+ {
+ bool done = false;
+- int res = 0;
+- while (!done && res == 0) {
++ assert(next_protocol);
++ assert(l2len);
++ assert(l2offset);
++ assert(vlan_offset);
++
++ if (!pktdata || !datalen)
++ errx(-1, "parse_metadata: invalid L2 parameters: pktdata=0x%p len=%d", pktdata, datalen);
++
++ while (!done) {
+ switch (*next_protocol) {
+ case ETHERTYPE_VLAN:
+ case ETHERTYPE_Q_IN_Q:
+@@ -205,18 +212,22 @@ parse_metadata(const u_char *pktdata,
+ if (*vlan_offset == 0)
+ *vlan_offset = *l2len;
+
+- res = parse_vlan(pktdata, datalen, next_protocol, l2len);
++ if (parse_vlan(pktdata, datalen, next_protocol, l2len))
++ return -1;
++
+ break;
+ case ETHERTYPE_MPLS:
+ case ETHERTYPE_MPLS_MULTI:
+- res = parse_mpls(pktdata, datalen, next_protocol, l2len, l2offset);
++ if (parse_mpls(pktdata, datalen, next_protocol, l2len, l2offset))
++ return -1;
++
+ break;
+ default:
+ done = true;
+ }
+ }
+
+- return res;
++ return 0;
+ }
+
+ /*
+@@ -605,9 +616,11 @@ get_layer4_v6(const ipv6_hdr_t *ip6_hdr, const u_char *end_ptr)
+ * no further processing, either TCP, UDP, ICMP, etc...
+ */
+ default:
+- if (proto != ip6_hdr->ip_nh) {
++ if (proto != ip6_hdr->ip_nh && next) {
+ dbgx(3, "Returning byte offset of this ext header: %u", IPV6_EXTLEN_TO_BYTES(next->ip_len));
+ next = (void *)((u_char *)next + IPV6_EXTLEN_TO_BYTES(next->ip_len));
++ if ((u_char*)next > end_ptr)
++ return NULL;
+ } else {
+ dbgx(3, "%s", "Returning end of IPv6 Header");
+ }
+--
+2.40.0
+
diff --git a/meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay/CVE-2024-22654-0002.patch b/meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay/CVE-2024-22654-0002.patch
new file mode 100644
index 0000000000..bcf560c0e5
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay/CVE-2024-22654-0002.patch
@@ -0,0 +1,35 @@
+From 52ed63329b37ae83cb86504db2c9deb6a91e2fe9 Mon Sep 17 00:00:00 2001
+From: Gabriel Ganne <gabriel.ganne@gmail.com>
+Date: Sun, 21 Jan 2024 08:59:10 +0100
+Subject: [PATCH 2/2] ipv6 - add check for extension header length
+
+Fixes #827
+
+Signed-off-by: Gabriel Ganne <gabriel.ganne@gmail.com>
+
+CVE: CVE-2024-22654
+
+Upstream-Status: Backport [https://github.com/appneta/tcpreplay/commit/52ed63329b37ae83cb86504db2c9deb6a91e2fe9]
+
+Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
+---
+ src/common/get.c | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/src/common/get.c b/src/common/get.c
+index 89fe95b..c31de5d 100644
+--- a/src/common/get.c
++++ b/src/common/get.c
+@@ -676,6 +676,10 @@ get_ipv6_next(struct tcpr_ipv6_ext_hdr_base *exthdr, const u_char *end_ptr)
+ case TCPR_IPV6_NH_HBH:
+ case TCPR_IPV6_NH_AH:
+ extlen = IPV6_EXTLEN_TO_BYTES(exthdr->ip_len);
++ if (extlen == 0) {
++ dbg(3, "Malformed IPv6 extension header...");
++ return NULL;
++ }
+ dbgx(3,
+ "Looks like we're an ext header (0x%hhx). Jumping %u bytes"
+ " to the next",
+--
+2.40.0
diff --git a/meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay_4.4.4.bb b/meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay_4.4.4.bb
index 26de40a65a..a784190868 100644
--- a/meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay_4.4.4.bb
+++ b/meta-openembedded/meta-networking/recipes-support/tcpreplay/tcpreplay_4.4.4.bb
@@ -11,6 +11,10 @@ SRC_URI = "https://github.com/appneta/${BPN}/releases/download/v${PV}/${BP}.tar.
file://0001-libopts.m4-set-POSIX_SHELL-to-bin-sh.patch \
file://0001-configure.ac-unify-search-dirs-for-pcap-and-add-lib3.patch \
file://0001-configure.ac-do-not-run-conftest-in-case-of-cross-co.patch \
+ file://CVE-2023-4256.patch \
+ file://CVE-2023-43279.patch \
+ file://CVE-2024-22654-0001.patch \
+ file://CVE-2024-22654-0002.patch \
"
SRC_URI[sha256sum] = "44f18fb6d3470ecaf77a51b901a119dae16da5be4d4140ffbb2785e37ad6d4bf"
diff --git a/meta-openembedded/meta-networking/recipes-support/tinyproxy/tinyproxy/0001-CVE-2023-49606.patch b/meta-openembedded/meta-networking/recipes-support/tinyproxy/tinyproxy/0001-CVE-2023-49606.patch
new file mode 100644
index 0000000000..dd10d2cd33
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-support/tinyproxy/tinyproxy/0001-CVE-2023-49606.patch
@@ -0,0 +1,59 @@
+From 982a46347c5939e08ad659858b1ac32361d7ffb8 Mon Sep 17 00:00:00 2001
+From: rofl0r <rofl0r@users.noreply.github.com>
+Date: Sun, 5 May 2024 10:37:29 +0000
+Subject: [PATCH] CVE-2023-49606
+
+fix potential UAF in header handling
+
+https://talosintelligence.com/vulnerability_reports/TALOS-2023-1889
+
+this bug was brought to my attention today by the debian tinyproxy
+package maintainer. the above link states that the issue was known
+since last year and that maintainers have been contacted, but if
+that is even true then it probably was done via a private email
+to a potentially outdated email address of one of the maintainers,
+not through the channels described clearly on the tinyproxy homepage:
+
+> Feel free to report a new bug or suggest features via github issues.
+> Tinyproxy developers hang out in #tinyproxy on irc.libera.chat.
+
+no github issue was filed, and nobody mentioned a vulnerability on
+the mentioned IRC chat. if the issue had been reported on github or
+IRC, the bug would have been fixed within a day.
+
+CVE: CVE-2023-49606
+Upstream-Status: Backport [https://github.com/tinyproxy/tinyproxy/commit/12a8484265f7b00591293da492bb3c9987001956]
+
+(cherry picked from commit 12a8484265f7b00591293da492bb3c9987001956)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/reqs.c | 9 +++++++--
+ 1 file changed, 7 insertions(+), 2 deletions(-)
+
+diff --git a/src/reqs.c b/src/reqs.c
+index b865190..705ce11 100644
+--- a/src/reqs.c
++++ b/src/reqs.c
+@@ -779,7 +779,7 @@ static int remove_connection_headers (orderedmap hashofheaders)
+ char *data;
+ char *ptr;
+ ssize_t len;
+- int i;
++ int i,j,df;
+
+ for (i = 0; i != (sizeof (headers) / sizeof (char *)); ++i) {
+ /* Look for the connection header. If it's not found, return. */
+@@ -804,7 +804,12 @@ static int remove_connection_headers (orderedmap hashofheaders)
+ */
+ ptr = data;
+ while (ptr < data + len) {
+- orderedmap_remove (hashofheaders, ptr);
++ df = 0;
++ /* check that ptr isn't one of headers to prevent
++ double-free (CVE-2023-49606) */
++ for (j = 0; j != (sizeof (headers) / sizeof (char *)); ++j)
++ if(!strcasecmp(ptr, headers[j])) df = 1;
++ if (!df) orderedmap_remove (hashofheaders, ptr);
+
+ /* Advance ptr to the next token */
+ ptr += strlen (ptr) + 1;
diff --git a/meta-openembedded/meta-networking/recipes-support/tinyproxy/tinyproxy_1.11.1.bb b/meta-openembedded/meta-networking/recipes-support/tinyproxy/tinyproxy_1.11.1.bb
index 999deff4de..8aff50fac8 100644
--- a/meta-openembedded/meta-networking/recipes-support/tinyproxy/tinyproxy_1.11.1.bb
+++ b/meta-openembedded/meta-networking/recipes-support/tinyproxy/tinyproxy_1.11.1.bb
@@ -8,6 +8,7 @@ SRC_URI = "https://github.com/${BPN}/${BPN}/releases/download/${PV}/${BP}.tar.gz
file://tinyproxy.service \
file://tinyproxy.conf \
file://CVE-2022-40468.patch \
+ file://0001-CVE-2023-49606.patch \
"
SRC_URI[sha256sum] = "1574acf7ba83c703a89e98bb2758a4ed9fda456f092624b33cfcf0ce2d3b2047"
diff --git a/meta-openembedded/meta-networking/recipes-support/unbound/unbound/CVE-2024-8508.patch b/meta-openembedded/meta-networking/recipes-support/unbound/unbound/CVE-2024-8508.patch
new file mode 100644
index 0000000000..65219fc98c
--- /dev/null
+++ b/meta-openembedded/meta-networking/recipes-support/unbound/unbound/CVE-2024-8508.patch
@@ -0,0 +1,247 @@
+Description: Limit name compression calculations to avoid DoS
+ Introduces a hard limit on the number of name compression calculations
+ per packet to prevent CPU lockup from maliciously crafted large RRsets.
+ This mitigates potential denial of service attacks.
+Author: Yorgos Thessalonikefs <yorgos@nlnetlabs.nl>
+Fixes: CVE-2024-8508
+CVE: CVE-2024-8508
+Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/b7c61d7cc256d6a174e6179622c7fa968272c259]
+Signed-off-by: Virendra Thakur <virendrak@kpit.com>
+---
+
+Index: unbound-1.19.3/util/data/msgencode.c
+===================================================================
+--- unbound-1.19.3.orig/util/data/msgencode.c
++++ unbound-1.19.3/util/data/msgencode.c
+@@ -62,6 +62,10 @@
+ #define RETVAL_TRUNC -4
+ /** return code that means all is peachy keen. Equal to DNS rcode NOERROR */
+ #define RETVAL_OK 0
++/** Max compressions we are willing to perform; more than that will result
++ * in semi-compressed messages, or truncated even on TCP for huge messages, to
++ * avoid locking the CPU for long */
++#define MAX_COMPRESSION_PER_MESSAGE 120
+
+ /**
+ * Data structure to help domain name compression in outgoing messages.
+@@ -284,15 +288,17 @@ write_compressed_dname(sldns_buffer* pkt
+
+ /** compress owner name of RR, return RETVAL_OUTMEM RETVAL_TRUNC */
+ static int
+-compress_owner(struct ub_packed_rrset_key* key, sldns_buffer* pkt,
+- struct regional* region, struct compress_tree_node** tree,
+- size_t owner_pos, uint16_t* owner_ptr, int owner_labs)
++compress_owner(struct ub_packed_rrset_key* key, sldns_buffer* pkt,
++ struct regional* region, struct compress_tree_node** tree,
++ size_t owner_pos, uint16_t* owner_ptr, int owner_labs,
++ size_t* compress_count)
+ {
+ struct compress_tree_node* p;
+ struct compress_tree_node** insertpt = NULL;
+ if(!*owner_ptr) {
+ /* compress first time dname */
+- if((p = compress_tree_lookup(tree, key->rk.dname,
++ if(*compress_count < MAX_COMPRESSION_PER_MESSAGE &&
++ (p = compress_tree_lookup(tree, key->rk.dname,
+ owner_labs, &insertpt))) {
+ if(p->labs == owner_labs)
+ /* avoid ptr chains, since some software is
+@@ -301,6 +307,7 @@ compress_owner(struct ub_packed_rrset_ke
+ if(!write_compressed_dname(pkt, key->rk.dname,
+ owner_labs, p))
+ return RETVAL_TRUNC;
++ (*compress_count)++;
+ /* check if typeclass+4 ttl + rdatalen is available */
+ if(sldns_buffer_remaining(pkt) < 4+4+2)
+ return RETVAL_TRUNC;
+@@ -313,7 +320,8 @@ compress_owner(struct ub_packed_rrset_ke
+ if(owner_pos <= PTR_MAX_OFFSET)
+ *owner_ptr = htons(PTR_CREATE(owner_pos));
+ }
+- if(!compress_tree_store(key->rk.dname, owner_labs,
++ if(*compress_count < MAX_COMPRESSION_PER_MESSAGE &&
++ !compress_tree_store(key->rk.dname, owner_labs,
+ owner_pos, region, p, insertpt))
+ return RETVAL_OUTMEM;
+ } else {
+@@ -333,20 +341,24 @@ compress_owner(struct ub_packed_rrset_ke
+
+ /** compress any domain name to the packet, return RETVAL_* */
+ static int
+-compress_any_dname(uint8_t* dname, sldns_buffer* pkt, int labs,
+- struct regional* region, struct compress_tree_node** tree)
++compress_any_dname(uint8_t* dname, sldns_buffer* pkt, int labs,
++ struct regional* region, struct compress_tree_node** tree,
++ size_t* compress_count)
+ {
+ struct compress_tree_node* p;
+ struct compress_tree_node** insertpt = NULL;
+ size_t pos = sldns_buffer_position(pkt);
+- if((p = compress_tree_lookup(tree, dname, labs, &insertpt))) {
++ if(*compress_count < MAX_COMPRESSION_PER_MESSAGE &&
++ (p = compress_tree_lookup(tree, dname, labs, &insertpt))) {
+ if(!write_compressed_dname(pkt, dname, labs, p))
+ return RETVAL_TRUNC;
++ (*compress_count)++;
+ } else {
+ if(!dname_buffer_write(pkt, dname))
+ return RETVAL_TRUNC;
+ }
+- if(!compress_tree_store(dname, labs, pos, region, p, insertpt))
++ if(*compress_count < MAX_COMPRESSION_PER_MESSAGE &&
++ !compress_tree_store(dname, labs, pos, region, p, insertpt))
+ return RETVAL_OUTMEM;
+ return RETVAL_OK;
+ }
+@@ -364,9 +376,9 @@ type_rdata_compressable(struct ub_packed
+
+ /** compress domain names in rdata, return RETVAL_* */
+ static int
+-compress_rdata(sldns_buffer* pkt, uint8_t* rdata, size_t todolen,
+- struct regional* region, struct compress_tree_node** tree,
+- const sldns_rr_descriptor* desc)
++compress_rdata(sldns_buffer* pkt, uint8_t* rdata, size_t todolen,
++ struct regional* region, struct compress_tree_node** tree,
++ const sldns_rr_descriptor* desc, size_t* compress_count)
+ {
+ int labs, r, rdf = 0;
+ size_t dname_len, len, pos = sldns_buffer_position(pkt);
+@@ -380,8 +392,8 @@ compress_rdata(sldns_buffer* pkt, uint8_
+ switch(desc->_wireformat[rdf]) {
+ case LDNS_RDF_TYPE_DNAME:
+ labs = dname_count_size_labels(rdata, &dname_len);
+- if((r=compress_any_dname(rdata, pkt, labs, region,
+- tree)) != RETVAL_OK)
++ if((r=compress_any_dname(rdata, pkt, labs, region,
++ tree, compress_count)) != RETVAL_OK)
+ return r;
+ rdata += dname_len;
+ todolen -= dname_len;
+@@ -449,7 +461,8 @@ static int
+ packed_rrset_encode(struct ub_packed_rrset_key* key, sldns_buffer* pkt,
+ uint16_t* num_rrs, time_t timenow, struct regional* region,
+ int do_data, int do_sig, struct compress_tree_node** tree,
+- sldns_pkt_section s, uint16_t qtype, int dnssec, size_t rr_offset)
++ sldns_pkt_section s, uint16_t qtype, int dnssec, size_t rr_offset,
++ size_t* compress_count)
+ {
+ size_t i, j, owner_pos;
+ int r, owner_labs;
+@@ -477,9 +490,9 @@ packed_rrset_encode(struct ub_packed_rrs
+ for(i=0; i<data->count; i++) {
+ /* rrset roundrobin */
+ j = (i + rr_offset) % data->count;
+- if((r=compress_owner(key, pkt, region, tree,
+- owner_pos, &owner_ptr, owner_labs))
+- != RETVAL_OK)
++ if((r=compress_owner(key, pkt, region, tree,
++ owner_pos, &owner_ptr, owner_labs,
++ compress_count)) != RETVAL_OK)
+ return r;
+ sldns_buffer_write(pkt, &key->rk.type, 2);
+ sldns_buffer_write(pkt, &key->rk.rrset_class, 2);
+@@ -489,8 +502,8 @@ packed_rrset_encode(struct ub_packed_rrs
+ else sldns_buffer_write_u32(pkt, data->rr_ttl[j]-adjust);
+ if(c) {
+ if((r=compress_rdata(pkt, data->rr_data[j],
+- data->rr_len[j], region, tree, c))
+- != RETVAL_OK)
++ data->rr_len[j], region, tree, c,
++ compress_count)) != RETVAL_OK)
+ return r;
+ } else {
+ if(sldns_buffer_remaining(pkt) < data->rr_len[j])
+@@ -510,9 +523,9 @@ packed_rrset_encode(struct ub_packed_rrs
+ return RETVAL_TRUNC;
+ sldns_buffer_write(pkt, &owner_ptr, 2);
+ } else {
+- if((r=compress_any_dname(key->rk.dname,
+- pkt, owner_labs, region, tree))
+- != RETVAL_OK)
++ if((r=compress_any_dname(key->rk.dname,
++ pkt, owner_labs, region, tree,
++ compress_count)) != RETVAL_OK)
+ return r;
+ if(sldns_buffer_remaining(pkt) <
+ 4+4+data->rr_len[i])
+@@ -544,7 +557,8 @@ static int
+ insert_section(struct reply_info* rep, size_t num_rrsets, uint16_t* num_rrs,
+ sldns_buffer* pkt, size_t rrsets_before, time_t timenow,
+ struct regional* region, struct compress_tree_node** tree,
+- sldns_pkt_section s, uint16_t qtype, int dnssec, size_t rr_offset)
++ sldns_pkt_section s, uint16_t qtype, int dnssec, size_t rr_offset,
++ size_t* compress_count)
+ {
+ int r;
+ size_t i, setstart;
+@@ -560,7 +574,7 @@ insert_section(struct reply_info* rep, s
+ setstart = sldns_buffer_position(pkt);
+ if((r=packed_rrset_encode(rep->rrsets[rrsets_before+i],
+ pkt, num_rrs, timenow, region, 1, 1, tree,
+- s, qtype, dnssec, rr_offset))
++ s, qtype, dnssec, rr_offset, compress_count))
+ != RETVAL_OK) {
+ /* Bad, but if due to size must set TC bit */
+ /* trim off the rrset neatly. */
+@@ -573,7 +587,7 @@ insert_section(struct reply_info* rep, s
+ setstart = sldns_buffer_position(pkt);
+ if((r=packed_rrset_encode(rep->rrsets[rrsets_before+i],
+ pkt, num_rrs, timenow, region, 1, 0, tree,
+- s, qtype, dnssec, rr_offset))
++ s, qtype, dnssec, rr_offset, compress_count))
+ != RETVAL_OK) {
+ sldns_buffer_set_position(pkt, setstart);
+ return r;
+@@ -584,7 +598,7 @@ insert_section(struct reply_info* rep, s
+ setstart = sldns_buffer_position(pkt);
+ if((r=packed_rrset_encode(rep->rrsets[rrsets_before+i],
+ pkt, num_rrs, timenow, region, 0, 1, tree,
+- s, qtype, dnssec, rr_offset))
++ s, qtype, dnssec, rr_offset, compress_count))
+ != RETVAL_OK) {
+ sldns_buffer_set_position(pkt, setstart);
+ return r;
+@@ -677,6 +691,7 @@ reply_info_encode(struct query_info* qin
+ struct compress_tree_node* tree = 0;
+ int r;
+ size_t rr_offset;
++ size_t compress_count=0;
+
+ sldns_buffer_clear(buffer);
+ if(udpsize < sldns_buffer_limit(buffer))
+@@ -723,7 +738,7 @@ reply_info_encode(struct query_info* qin
+ arep.rrsets = &qinfo->local_alias->rrset;
+ if((r=insert_section(&arep, 1, &ancount, buffer, 0,
+ timezero, region, &tree, LDNS_SECTION_ANSWER,
+- qinfo->qtype, dnssec, rr_offset)) != RETVAL_OK) {
++ qinfo->qtype, dnssec, rr_offset, &compress_count)) != RETVAL_OK) {
+ if(r == RETVAL_TRUNC) {
+ /* create truncated message */
+ sldns_buffer_write_u16_at(buffer, 6, ancount);
+@@ -738,7 +753,7 @@ reply_info_encode(struct query_info* qin
+ /* insert answer section */
+ if((r=insert_section(rep, rep->an_numrrsets, &ancount, buffer,
+ 0, timenow, region, &tree, LDNS_SECTION_ANSWER, qinfo->qtype,
+- dnssec, rr_offset)) != RETVAL_OK) {
++ dnssec, rr_offset, &compress_count)) != RETVAL_OK) {
+ if(r == RETVAL_TRUNC) {
+ /* create truncated message */
+ sldns_buffer_write_u16_at(buffer, 6, ancount);
+@@ -756,7 +771,7 @@ reply_info_encode(struct query_info* qin
+ if((r=insert_section(rep, rep->ns_numrrsets, &nscount, buffer,
+ rep->an_numrrsets, timenow, region, &tree,
+ LDNS_SECTION_AUTHORITY, qinfo->qtype,
+- dnssec, rr_offset)) != RETVAL_OK) {
++ dnssec, rr_offset, &compress_count)) != RETVAL_OK) {
+ if(r == RETVAL_TRUNC) {
+ /* create truncated message */
+ sldns_buffer_write_u16_at(buffer, 8, nscount);
+@@ -773,7 +788,7 @@ reply_info_encode(struct query_info* qin
+ if((r=insert_section(rep, rep->ar_numrrsets, &arcount, buffer,
+ rep->an_numrrsets + rep->ns_numrrsets, timenow, region,
+ &tree, LDNS_SECTION_ADDITIONAL, qinfo->qtype,
+- dnssec, rr_offset)) != RETVAL_OK) {
++ dnssec, rr_offset, &compress_count)) != RETVAL_OK) {
+ if(r == RETVAL_TRUNC) {
+ /* no need to set TC bit, this is the additional */
+ sldns_buffer_write_u16_at(buffer, 10, arcount);
diff --git a/meta-openembedded/meta-networking/recipes-support/unbound/unbound_1.19.3.bb b/meta-openembedded/meta-networking/recipes-support/unbound/unbound_1.19.3.bb
index ffdc78e9d6..6f54038c6c 100644
--- a/meta-openembedded/meta-networking/recipes-support/unbound/unbound_1.19.3.bb
+++ b/meta-openembedded/meta-networking/recipes-support/unbound/unbound_1.19.3.bb
@@ -9,7 +9,9 @@ SECTION = "net"
LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://LICENSE;md5=5308494bc0590c0cb036afd781d78f06"
-SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=branch-1.19.3"
+SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=branch-1.19.3 \
+ file://CVE-2024-8508.patch \
+ "
SRCREV = "48b6c60a24e9a5d6d369a7a37c9fe2a767f26abd"
inherit autotools pkgconfig systemd update-rc.d
diff --git a/meta-openembedded/meta-networking/recipes-support/wireshark/wireshark_4.2.4.bb b/meta-openembedded/meta-networking/recipes-support/wireshark/wireshark_4.2.12.bb
index 95db2efc4c..ab6160b767 100644
--- a/meta-openembedded/meta-networking/recipes-support/wireshark/wireshark_4.2.4.bb
+++ b/meta-openembedded/meta-networking/recipes-support/wireshark/wireshark_4.2.12.bb
@@ -2,22 +2,22 @@ DESCRIPTION = "wireshark - a popular network protocol analyzer"
HOMEPAGE = "http://www.wireshark.org"
SECTION = "net"
LICENSE = "GPL-2.0-only"
-LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
+LIC_FILES_CHKSUM = "file://COPYING;md5=570a9b3749dd0463a1778803b12a6dce"
DEPENDS = "pcre2 expat glib-2.0 glib-2.0-native libgcrypt libgpg-error libxml2 bison-native c-ares speexdsp"
DEPENDS:append:class-target = " wireshark-native chrpath-replacement-native "
-SRC_URI = "https://1.eu.dl.wireshark.org/src/wireshark-${PV}.tar.xz \
+SRC_URI = "https://1.eu.dl.wireshark.org/src/all-versions/wireshark-${PV}.tar.xz \
file://0001-wireshark-src-improve-reproducibility.patch \
file://0002-flex-Remove-line-directives.patch \
file://0004-lemon-Remove-line-directives.patch \
file://0001-UseLemon.cmake-do-not-use-lemon-data-from-the-host.patch \
"
-UPSTREAM_CHECK_URI = "https://1.as.dl.wireshark.org/src"
+UPSTREAM_CHECK_URI = "https://1.as.dl.wireshark.org/src/all-versions"
-SRC_URI[sha256sum] = "46bd0f4474337144b30816fb2d8f14e72a26d0391f24fe0b7b619acdcdad8c0c"
+SRC_URI[sha256sum] = "6ed51da5f6638aba609be8d1d64a7a85312749a49261146c391fea391a3e5f06"
PE = "1"
diff --git a/meta-openembedded/meta-oe/classes/image_types_sparse.bbclass b/meta-openembedded/meta-oe/classes/image_types_sparse.bbclass
index d6ea68968e..5416c2a019 100644
--- a/meta-openembedded/meta-oe/classes/image_types_sparse.bbclass
+++ b/meta-openembedded/meta-oe/classes/image_types_sparse.bbclass
@@ -9,9 +9,15 @@ SPARSE_BLOCK_SIZE ??= "4096"
CONVERSIONTYPES += "sparse"
+DELETE_RAWIMAGE_AFTER_SPARSE_CMD ??= "0"
+
CONVERSION_CMD:sparse = " \
truncate --no-create --size=%${SPARSE_BLOCK_SIZE} "${IMAGE_NAME}.${type}"; \
img2simg -s "${IMAGE_NAME}.${type}" "${IMAGE_NAME}.${type}.sparse" ${SPARSE_BLOCK_SIZE}; \
+ if [ "${DELETE_RAWIMAGE_AFTER_SPARSE_CMD}" = "1" ]; then \
+ rm -f ${IMAGE_NAME}.${type};\
+ bbwarn "Raw file ${IMAGE_NAME}.${type} removed" ;\
+ fi;\
"
CONVERSION_DEPENDS_sparse = "android-tools-native"
diff --git a/meta-openembedded/meta-oe/conf/include/ptest-packagelists-meta-oe.inc b/meta-openembedded/meta-oe/conf/include/ptest-packagelists-meta-oe.inc
index a29408a822..639daec992 100644
--- a/meta-openembedded/meta-oe/conf/include/ptest-packagelists-meta-oe.inc
+++ b/meta-openembedded/meta-oe/conf/include/ptest-packagelists-meta-oe.inc
@@ -7,6 +7,7 @@
#
# ptests which take less than ~30s each
PTESTS_FAST_META_OE = "\
+ asio \
cmocka \
cunit \
duktape \
diff --git a/meta-openembedded/meta-oe/conf/layer.conf b/meta-openembedded/meta-oe/conf/layer.conf
index 4d9acb8cc8..463d063f0a 100644
--- a/meta-openembedded/meta-oe/conf/layer.conf
+++ b/meta-openembedded/meta-oe/conf/layer.conf
@@ -114,4 +114,7 @@ SIGGEN_EXCLUDE_SAFE_RECIPE_DEPS += " \
DEFAULT_TEST_SUITES:pn-meta-oe-ptest-image = " ${PTESTTESTSUITE}"
-NON_MULTILIB_RECIPES:append = " crash pahole libbpf"
+NON_MULTILIB_RECIPES:append = " crash pahole libbpf bpftrace"
+
+NON_MULTILIB_RECIPES:remove:x86 = "libbpf"
+NON_MULTILIB_RECIPES:remove:x86-64 = "libbpf"
diff --git a/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-connectivity/netplan/netplan/CVE-2022-4968.patch b/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-connectivity/netplan/netplan/CVE-2022-4968.patch
new file mode 100644
index 0000000000..a7a3c28f3f
--- /dev/null
+++ b/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-connectivity/netplan/netplan/CVE-2022-4968.patch
@@ -0,0 +1,452 @@
+From 9d9a67b00b18708ce190b806686065a6c7b73527 Mon Sep 17 00:00:00 2001
+From: Danilo Egea Gondolfo <danilogondolfo@gmail.com>
+Date: Wed, 22 May 2024 15:44:16 +0100
+Subject: [PATCH] libnetplan: use more restrictive file permissions
+
+A new util.c:_netplan_g_string_free_to_file_with_permissions() was added
+and accepts the owner, group and file mode as arguments. When these
+properties can't be set, when the generator is called by a non-root user
+for example, it will not hard-fail. This function is called by unit
+tests where we can't set the owner to a privileged account for example.
+
+When generating backend files, use more restrictive permissions:
+
+networkd related files will be owned by root:systemd-network and have
+mode 0640.
+
+service unit files will be owned by root:root and have mode 0640.
+udevd files will be owned by root:root with mode 0640.
+
+wpa_supplicant and Network Manager files will continue with the existing
+permissions.
+
+Autopkgtests will check if the permissions are set as expected when
+calling the generator.
+
+CVE: CVE-2022-4968
+
+Upstream-Status: Backport [https://github.com/canonical/netplan/commit/4c39b75b5c6ae7d976bda6da68da60d9a7f085ee]
+
+Signed-off-by: Jinfeng Wang <jinfeng.wang.cn@windriver.com>
+---
+ src/networkd.c | 36 +++------------
+ src/networkd.h | 2 +
+ src/nm.c | 4 +-
+ src/openvswitch.c | 2 +-
+ src/sriov.c | 4 +-
+ src/util-internal.h | 3 ++
+ src/util.c | 46 +++++++++++++++++++
+ tests/generator/test_auth.py | 2 +-
+ tests/generator/test_wifis.py | 2 +-
+ tests/integration/base.py | 85 +++++++++++++++++++++++++++++++++++
+ 10 files changed, 150 insertions(+), 36 deletions(-)
+
+diff --git a/src/networkd.c b/src/networkd.c
+index 25121c4..a051c6f 100644
+--- a/src/networkd.c
++++ b/src/networkd.c
+@@ -221,7 +221,6 @@ STATIC void
+ write_link_file(const NetplanNetDefinition* def, const char* rootdir, const char* path)
+ {
+ GString* s = NULL;
+- mode_t orig_umask;
+
+ /* Don't write .link files for virtual devices; they use .netdev instead.
+ * Don't write .link files for MODEM devices, as they aren't supported by networkd.
+@@ -293,9 +292,7 @@ write_link_file(const NetplanNetDefinition* def, const char* rootdir, const char
+ g_string_append_printf(s, "LargeReceiveOffload=%s\n",
+ (def->large_receive_offload ? "true" : "false"));
+
+- orig_umask = umask(022);
+- _netplan_g_string_free_to_file(s, rootdir, path, ".link");
+- umask(orig_umask);
++ _netplan_g_string_free_to_file_with_permissions(s, rootdir, path, ".link", "root", "root", 0640);
+ }
+
+ STATIC gboolean
+@@ -313,7 +310,7 @@ write_regdom(const NetplanNetDefinition* def, const char* rootdir, GError** erro
+ g_string_append(s, "\n[Service]\nType=oneshot\n");
+ g_string_append_printf(s, "ExecStart="SBINDIR"/iw reg set %s\n", def->regulatory_domain);
+
+- _netplan_g_string_free_to_file(s, rootdir, path, NULL);
++ _netplan_g_string_free_to_file_with_permissions(s, rootdir, path, NULL, "root", "root", 0640);
+ _netplan_safe_mkdir_p_dir(link);
+ if (symlink(path, link) < 0 && errno != EEXIST) {
+ // LCOV_EXCL_START
+@@ -493,7 +490,6 @@ STATIC void
+ write_netdev_file(const NetplanNetDefinition* def, const char* rootdir, const char* path)
+ {
+ GString* s = NULL;
+- mode_t orig_umask;
+
+ g_assert(def->type >= NETPLAN_DEF_TYPE_VIRTUAL);
+
+@@ -589,11 +585,7 @@ write_netdev_file(const NetplanNetDefinition* def, const char* rootdir, const ch
+ default: g_assert_not_reached(); // LCOV_EXCL_LINE
+ }
+
+- /* these do not contain secrets and need to be readable by
+- * systemd-networkd - LP: #1736965 */
+- orig_umask = umask(022);
+- _netplan_g_string_free_to_file(s, rootdir, path, ".netdev");
+- umask(orig_umask);
++ _netplan_g_string_free_to_file_with_permissions(s, rootdir, path, ".netdev", "root", NETWORKD_GROUP, 0640);
+ }
+
+ STATIC void
+@@ -737,7 +729,6 @@ _netplan_netdef_write_network_file(
+ g_autoptr(GString) network = NULL;
+ g_autoptr(GString) link = NULL;
+ GString* s = NULL;
+- mode_t orig_umask;
+ gboolean is_optional = def->optional;
+
+ SET_OPT_OUT_PTR(has_been_written, FALSE);
+@@ -993,11 +984,7 @@ _netplan_netdef_write_network_file(
+ if (network->len > 0)
+ g_string_append_printf(s, "\n[Network]\n%s", network->str);
+
+- /* these do not contain secrets and need to be readable by
+- * systemd-networkd - LP: #1736965 */
+- orig_umask = umask(022);
+- _netplan_g_string_free_to_file(s, rootdir, path, ".network");
+- umask(orig_umask);
++ _netplan_g_string_free_to_file_with_permissions(s, rootdir, path, ".network", "root", NETWORKD_GROUP, 0640);
+ }
+
+ SET_OPT_OUT_PTR(has_been_written, TRUE);
+@@ -1009,7 +996,6 @@ write_rules_file(const NetplanNetDefinition* def, const char* rootdir)
+ {
+ GString* s = NULL;
+ g_autofree char* path = g_strjoin(NULL, "run/udev/rules.d/99-netplan-", def->id, ".rules", NULL);
+- mode_t orig_umask;
+
+ /* do we need to write a .rules file?
+ * It's only required for reliably setting the name of a physical device
+@@ -1043,9 +1029,7 @@ write_rules_file(const NetplanNetDefinition* def, const char* rootdir)
+
+ g_string_append_printf(s, "NAME=\"%s\"\n", def->set_name);
+
+- orig_umask = umask(022);
+- _netplan_g_string_free_to_file(s, rootdir, path, NULL);
+- umask(orig_umask);
++ _netplan_g_string_free_to_file_with_permissions(s, rootdir, path, NULL, "root", "root", 0640);
+ }
+
+ STATIC gboolean
+@@ -1194,7 +1178,6 @@ STATIC void
+ write_wpa_unit(const NetplanNetDefinition* def, const char* rootdir)
+ {
+ g_autofree gchar *stdouth = NULL;
+- mode_t orig_umask;
+
+ stdouth = systemd_escape(def->id);
+
+@@ -1213,9 +1196,7 @@ write_wpa_unit(const NetplanNetDefinition* def, const char* rootdir)
+ } else {
+ g_string_append(s, " -Dnl80211,wext\n");
+ }
+- orig_umask = umask(022);
+- _netplan_g_string_free_to_file(s, rootdir, path, NULL);
+- umask(orig_umask);
++ _netplan_g_string_free_to_file_with_permissions(s, rootdir, path, NULL, "root", "root", 0640);
+ }
+
+ STATIC gboolean
+@@ -1224,7 +1205,6 @@ write_wpa_conf(const NetplanNetDefinition* def, const char* rootdir, GError** er
+ GHashTableIter iter;
+ GString* s = g_string_new("ctrl_interface=/run/wpa_supplicant\n\n");
+ g_autofree char* path = g_strjoin(NULL, "run/netplan/wpa-", def->id, ".conf", NULL);
+- mode_t orig_umask;
+
+ g_debug("%s: Creating wpa_supplicant configuration file %s", def->id, path);
+ if (def->type == NETPLAN_DEF_TYPE_WIFI) {
+@@ -1313,9 +1293,7 @@ write_wpa_conf(const NetplanNetDefinition* def, const char* rootdir, GError** er
+ }
+
+ /* use tight permissions as this contains secrets */
+- orig_umask = umask(077);
+- _netplan_g_string_free_to_file(s, rootdir, path, NULL);
+- umask(orig_umask);
++ _netplan_g_string_free_to_file_with_permissions(s, rootdir, path, NULL, "root", "root", 0600);
+ return TRUE;
+ }
+
+diff --git a/src/networkd.h b/src/networkd.h
+index 2bd0848..36c34b3 100644
+--- a/src/networkd.h
++++ b/src/networkd.h
+@@ -20,6 +20,8 @@
+ #include "netplan.h"
+ #include <glib.h>
+
++#define NETWORKD_GROUP "systemd-network"
++
+ NETPLAN_INTERNAL gboolean
+ _netplan_netdef_write_networkd(
+ const NetplanState* np_state,
+diff --git a/src/nm.c b/src/nm.c
+index 2b850af..8f1bf05 100644
+--- a/src/nm.c
++++ b/src/nm.c
+@@ -1150,13 +1150,13 @@ netplan_state_finish_nm_write(
+
+ /* write generated NetworkManager drop-in config */
+ if (nm_conf->len > 0)
+- _netplan_g_string_free_to_file(nm_conf, rootdir, "run/NetworkManager/conf.d/netplan.conf", NULL);
++ _netplan_g_string_free_to_file_with_permissions(nm_conf, rootdir, "run/NetworkManager/conf.d/netplan.conf", NULL, "root", "root", 0640);
+ else
+ g_string_free(nm_conf, TRUE);
+
+ /* write generated udev rules */
+ if (udev_rules->len > 0)
+- _netplan_g_string_free_to_file(udev_rules, rootdir, "run/udev/rules.d/90-netplan.rules", NULL);
++ _netplan_g_string_free_to_file_with_permissions(udev_rules, rootdir, "run/udev/rules.d/90-netplan.rules", NULL, "root", "root", 0640);
+ else
+ g_string_free(udev_rules, TRUE);
+
+diff --git a/src/openvswitch.c b/src/openvswitch.c
+index 6eb0688..2ab77e7 100644
+--- a/src/openvswitch.c
++++ b/src/openvswitch.c
+@@ -66,7 +66,7 @@ write_ovs_systemd_unit(const char* id, const GString* cmds, const char* rootdir,
+ g_string_append(s, "StartLimitBurst=0\n");
+ g_string_append(s, cmds->str);
+
+- _netplan_g_string_free_to_file(s, rootdir, path, NULL);
++ _netplan_g_string_free_to_file_with_permissions(s, rootdir, path, NULL, "root", "root", 0640);
+
+ _netplan_safe_mkdir_p_dir(link);
+ if (symlink(path, link) < 0 && errno != EEXIST) {
+diff --git a/src/sriov.c b/src/sriov.c
+index 1534c94..213f124 100644
+--- a/src/sriov.c
++++ b/src/sriov.c
+@@ -54,7 +54,7 @@ write_sriov_rebind_systemd_unit(GHashTable* pfs, const char* rootdir, GError** e
+ g_string_truncate(interfaces, interfaces->len-1); /* cut trailing whitespace */
+ g_string_append_printf(s, "ExecStart=" SBINDIR "/netplan rebind --debug %s\n", interfaces->str);
+
+- _netplan_g_string_free_to_file(s, rootdir, path, NULL);
++ _netplan_g_string_free_to_file_with_permissions(s, rootdir, path, NULL, "root", "root", 0640);
+ g_string_free(interfaces, TRUE);
+
+ _netplan_safe_mkdir_p_dir(link);
+@@ -90,7 +90,7 @@ write_sriov_apply_systemd_unit(GHashTable* pfs, const char* rootdir, GError** er
+ g_string_append(s, "\n[Service]\nType=oneshot\n");
+ g_string_append_printf(s, "ExecStart=" SBINDIR "/netplan apply --sriov-only\n");
+
+- _netplan_g_string_free_to_file(s, rootdir, path, NULL);
++ _netplan_g_string_free_to_file_with_permissions(s, rootdir, path, NULL, "root", "root", 0640);
+
+ _netplan_safe_mkdir_p_dir(link);
+ if (symlink(path, link) < 0 && errno != EEXIST) {
+diff --git a/src/util-internal.h b/src/util-internal.h
+index 86bd1b7..7454e77 100644
+--- a/src/util-internal.h
++++ b/src/util-internal.h
+@@ -40,6 +40,9 @@ _netplan_safe_mkdir_p_dir(const char* file_path);
+ NETPLAN_INTERNAL void
+ _netplan_g_string_free_to_file(GString* s, const char* rootdir, const char* path, const char* suffix);
+
++void
++_netplan_g_string_free_to_file_with_permissions(GString* s, const char* rootdir, const char* path, const char* suffix, const char* owner, const char* group, mode_t mode);
++
+ NETPLAN_INTERNAL void
+ _netplan_unlink_glob(const char* rootdir, const char* _glob);
+
+diff --git a/src/util.c b/src/util.c
+index 36eb896..c2f9494 100644
+--- a/src/util.c
++++ b/src/util.c
+@@ -23,6 +23,9 @@
+ #include <regex.h>
+ #include <string.h>
+ #include <sys/mman.h>
++#include <sys/types.h>
++#include <pwd.h>
++#include <grp.h>
+
+ #include <glib.h>
+ #include <glib/gprintf.h>
+@@ -87,6 +90,49 @@ void _netplan_g_string_free_to_file(GString* s, const char* rootdir, const char*
+ }
+ }
+
++void _netplan_g_string_free_to_file_with_permissions(GString* s, const char* rootdir, const char* path, const char* suffix, const char* owner, const char* group, mode_t mode)
++{
++ g_autofree char* full_path = NULL;
++ g_autofree char* path_suffix = NULL;
++ g_autofree char* contents = g_string_free(s, FALSE);
++ GError* error = NULL;
++ struct passwd* pw = NULL;
++ struct group* gr = NULL;
++ int ret = 0;
++
++ path_suffix = g_strjoin(NULL, path, suffix, NULL);
++ full_path = g_build_path(G_DIR_SEPARATOR_S, rootdir ?: G_DIR_SEPARATOR_S, path_suffix, NULL);
++ _netplan_safe_mkdir_p_dir(full_path);
++ if (!g_file_set_contents_full(full_path, contents, -1, G_FILE_SET_CONTENTS_CONSISTENT | G_FILE_SET_CONTENTS_ONLY_EXISTING, mode, &error)) {
++ /* the mkdir() just succeeded, there is no sensible
++ * method to test this without root privileges, bind mounts, and
++ * simulating ENOSPC */
++ // LCOV_EXCL_START
++ g_fprintf(stderr, "ERROR: cannot create file %s: %s\n", path, error->message);
++ exit(1);
++ // LCOV_EXCL_STOP
++ }
++
++ /* Here we take the owner and group names and look up for their IDs in the passwd and group files.
++ * It's OK to fail to set the owners and mode as this code will be called from unit tests.
++ * The autopkgtests will check if the owner/group and mode are correctly set.
++ */
++ pw = getpwnam(owner);
++ if (!pw) {
++ g_debug("Failed to determine the UID of user %s: %s", owner, strerror(errno)); // LCOV_EXCL_LINE
++ }
++ gr = getgrnam(group);
++ if (!gr) {
++ g_debug("Failed to determine the GID of group %s: %s", group, strerror(errno)); // LCOV_EXCL_LINE
++ }
++ if (pw && gr) {
++ ret = chown(full_path, pw->pw_uid, gr->gr_gid);
++ if (ret != 0) {
++ g_debug("Failed to set owner and group for file %s: %s", full_path, strerror(errno));
++ }
++ }
++}
++
+ /**
+ * Remove all files matching given glob.
+ */
+diff --git a/tests/generator/test_auth.py b/tests/generator/test_auth.py
+index de23adb..d3d886c 100644
+--- a/tests/generator/test_auth.py
++++ b/tests/generator/test_auth.py
+@@ -226,7 +226,7 @@ network={
+
+ with open(os.path.join(self.workdir.name, 'run/systemd/system/netplan-wpa-eth0.service')) as f:
+ self.assertEqual(f.read(), SD_WPA % {'iface': 'eth0', 'drivers': 'wired'})
+- self.assertEqual(stat.S_IMODE(os.fstat(f.fileno()).st_mode), 0o644)
++ self.assertEqual(stat.S_IMODE(os.fstat(f.fileno()).st_mode), 0o640)
+ self.assertTrue(os.path.islink(os.path.join(
+ self.workdir.name, 'run/systemd/system/systemd-networkd.service.wants/netplan-wpa-eth0.service')))
+
+diff --git a/tests/generator/test_wifis.py b/tests/generator/test_wifis.py
+index b875172..610782a 100644
+--- a/tests/generator/test_wifis.py
++++ b/tests/generator/test_wifis.py
+@@ -140,7 +140,7 @@ network={
+ self.workdir.name, 'run/systemd/system/netplan-wpa-wl0.service')))
+ with open(os.path.join(self.workdir.name, 'run/systemd/system/netplan-wpa-wl0.service')) as f:
+ self.assertEqual(f.read(), SD_WPA % {'iface': 'wl0', 'drivers': 'nl80211,wext'})
+- self.assertEqual(stat.S_IMODE(os.fstat(f.fileno()).st_mode), 0o644)
++ self.assertEqual(stat.S_IMODE(os.fstat(f.fileno()).st_mode), 0o640)
+ self.assertTrue(os.path.islink(os.path.join(
+ self.workdir.name, 'run/systemd/system/systemd-networkd.service.wants/netplan-wpa-wl0.service')))
+
+diff --git a/tests/integration/base.py b/tests/integration/base.py
+index e9c366c..74f0682 100644
+--- a/tests/integration/base.py
++++ b/tests/integration/base.py
+@@ -32,6 +32,8 @@ import shutil
+ import gi
+ import glob
+ import json
++import pwd
++import grp
+
+ # make sure we point to libnetplan properly.
+ os.environ.update({'LD_LIBRARY_PATH': '.:{}'.format(os.environ.get('LD_LIBRARY_PATH'))})
+@@ -367,6 +369,89 @@ class IntegrationTestsBase(unittest.TestCase):
+ if state:
+ self.wait_output(['ip', 'addr', 'show', iface], state, 30)
+
++ # Assert file permissions
++ self.assert_file_permissions()
++
++ def assert_file_permissions(self):
++ """ Check if the generated files have the expected permissions """
++
++ nd_expected_mode = 0o100640
++ nd_expected_owner = 'root'
++ nd_expected_group = 'systemd-network'
++
++ sd_expected_mode = 0o100640
++ sd_expected_owner = 'root'
++ sd_expected_group = 'root'
++
++ udev_expected_mode = 0o100640
++ udev_expected_owner = 'root'
++ udev_expected_group = 'root'
++
++ nm_expected_mode = 0o100600
++ nm_expected_owner = 'root'
++ nm_expected_group = 'root'
++
++ wpa_expected_mode = 0o100600
++ wpa_expected_owner = 'root'
++ wpa_expected_group = 'root'
++
++ # Check systemd-networkd files
++ base_path = '/run/systemd/network'
++ files = glob.glob(f'{base_path}/*.network') + glob.glob(f'{base_path}/*.netdev')
++ for file in files:
++ res = os.stat(file)
++ user = pwd.getpwuid(res.st_uid)
++ group = grp.getgrgid(res.st_gid)
++ self.assertEqual(res.st_mode, nd_expected_mode, f'file {file}')
++ self.assertEqual(user.pw_name, nd_expected_owner, f'file {file}')
++ self.assertEqual(group.gr_name, nd_expected_group, f'file {file}')
++
++ # Check Network Manager files
++ base_path = '/run/NetworkManager/system-connections'
++ files = glob.glob(f'{base_path}/*.nmconnection')
++ for file in files:
++ res = os.stat(file)
++ user = pwd.getpwuid(res.st_uid)
++ group = grp.getgrgid(res.st_gid)
++ self.assertEqual(res.st_mode, nm_expected_mode, f'file {file}')
++ self.assertEqual(user.pw_name, nm_expected_owner, f'file {file}')
++ self.assertEqual(group.gr_name, nm_expected_group, f'file {file}')
++
++ # Check wpa_supplicant configuration files
++ base_path = '/run/netplan'
++ files = glob.glob(f'{base_path}/wpa-*.conf')
++ for file in files:
++ res = os.stat(file)
++ user = pwd.getpwuid(res.st_uid)
++ group = grp.getgrgid(res.st_gid)
++ self.assertEqual(res.st_mode, wpa_expected_mode, f'file {file}')
++ self.assertEqual(user.pw_name, wpa_expected_owner, f'file {file}')
++ self.assertEqual(group.gr_name, wpa_expected_group, f'file {file}')
++
++ # Check systemd service unit files
++ base_path = '/run/systemd/system/'
++ files = glob.glob(f'{base_path}/netplan-*.service')
++ files += glob.glob(f'{base_path}/systemd-networkd-wait-online.service.d/*.conf')
++ for file in files:
++ res = os.stat(file)
++ user = pwd.getpwuid(res.st_uid)
++ group = grp.getgrgid(res.st_gid)
++ self.assertEqual(res.st_mode, sd_expected_mode, f'file {file}')
++ self.assertEqual(user.pw_name, sd_expected_owner, f'file {file}')
++ self.assertEqual(group.gr_name, sd_expected_group, f'file {file}')
++
++ # Check systemd-udevd files
++ udev_path = '/run/udev/rules.d'
++ link_path = '/run/systemd/network'
++ files = glob.glob(f'{udev_path}/*-netplan*.rules') + glob.glob(f'{link_path}/*.link')
++ for file in files:
++ res = os.stat(file)
++ user = pwd.getpwuid(res.st_uid)
++ group = grp.getgrgid(res.st_gid)
++ self.assertEqual(res.st_mode, udev_expected_mode, f'file {file}')
++ self.assertEqual(user.pw_name, udev_expected_owner, f'file {file}')
++ self.assertEqual(group.gr_name, udev_expected_group, f'file {file}')
++
+ def state(self, iface, state):
+ '''Tell generate_and_settle() to wait for a specific state'''
+ return iface + '/' + state
+--
+2.44.1
+
diff --git a/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-connectivity/netplan/netplan_1.0.bb b/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-connectivity/netplan/netplan_1.0.bb
index 229414718c..752acc23c3 100644
--- a/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-connectivity/netplan/netplan_1.0.bb
+++ b/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-connectivity/netplan/netplan_1.0.bb
@@ -17,6 +17,7 @@ REQUIRED_DISTRO_FEATURES = "systemd"
SRC_URI = "git://github.com/CanonicalLtd/netplan.git;branch=main;protocol=https \
file://0001-meson.build-drop-unnecessary-build-dependencies.patch \
file://0002-meson.build-do-not-use-Werror.patch \
+ file://CVE-2022-4968.patch \
"
SRC_URI:append:libc-musl = " file://0001-don-t-fail-if-GLOB_BRACE-is-not-defined.patch"
@@ -34,6 +35,7 @@ EXTRA_OEMESON = "-Dunit_testing=false"
RDEPENDS:${PN} = "python3-core python3-netifaces python3-pyyaml \
python3-dbus python3-rich python3-cffi \
+ python3-json python3-fcntl \
util-linux-libuuid libnetplan \
"
diff --git a/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-dbs/mongodb/mongodb/0001-free_mon-Include-missing-cstdint.patch b/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-dbs/mongodb/mongodb/0001-free_mon-Include-missing-cstdint.patch
deleted file mode 100644
index 8cee14889f..0000000000
--- a/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-dbs/mongodb/mongodb/0001-free_mon-Include-missing-cstdint.patch
+++ /dev/null
@@ -1,28 +0,0 @@
-From 5d8218b8a1b5bc71e2a0cf543a000e194daba599 Mon Sep 17 00:00:00 2001
-From: Khem Raj <raj.khem@gmail.com>
-Date: Sun, 29 Jan 2023 17:15:30 -0800
-Subject: [PATCH] free_mon: Include missing <cstdint>
-
-gcc 13 moved some includes around and as a result <cstdint> is no
-longer transitively included [1]. Explicitly include it
-for uintXX_t.
-
-[1] https://gcc.gnu.org/gcc-13/porting_to.html#header-dep-changes
-
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
-
-Upstream-Status: Pending
----
- src/mongo/db/free_mon/free_mon_options.h | 1 +
- 1 file changed, 1 insertion(+)
-
---- a/src/mongo/db/free_mon/free_mon_options.h
-+++ b/src/mongo/db/free_mon/free_mon_options.h
-@@ -29,6 +29,7 @@
-
- #pragma once
-
-+#include <cstdint>
- #include <string>
- #include <vector>
-
diff --git a/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-dbs/mongodb/mongodb/0001-moduleconfig.py-python-3.12-compatibility.patch b/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-dbs/mongodb/mongodb/0001-moduleconfig.py-python-3.12-compatibility.patch
new file mode 100644
index 0000000000..51926b9d2e
--- /dev/null
+++ b/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-dbs/mongodb/mongodb/0001-moduleconfig.py-python-3.12-compatibility.patch
@@ -0,0 +1,57 @@
+From 37580777bc5294d606584f3731d9f5f5425bb587 Mon Sep 17 00:00:00 2001
+From: Awais B <awais.b@rufilla.com>
+Date: Tue, 4 Mar 2025 11:27:10 +0000
+Subject: [PATCH] moduleconfig.py: python 3.12 compatibility
+
+The imp module was deprecated in python 3.4 and is dropped
+with python 3.12. We now need to use importlib for the
+purpose of manipulating/loading modules.
+
+Upstream-Status: Pending
+Signed-off-by: Awais B <awais.b@rufilla.com>
+---
+ buildscripts/moduleconfig.py | 21 ++++++++++++++-------
+ 1 file changed, 14 insertions(+), 7 deletions(-)
+
+diff --git a/buildscripts/moduleconfig.py b/buildscripts/moduleconfig.py
+index b4d0bba0490..69dd91ab30d 100644
+--- a/buildscripts/moduleconfig.py
++++ b/buildscripts/moduleconfig.py
+@@ -27,7 +27,8 @@ MongoDB SConscript files do.
+ __all__ = ('discover_modules', 'discover_module_directories', 'configure_modules',
+ 'register_module_test') # pylint: disable=undefined-all-variable
+
+-import imp
++import importlib
++import sys
+ import inspect
+ import os
+
+@@ -71,12 +72,18 @@ def discover_modules(module_root, allowed_modules):
+ print("adding module: %s" % (name))
+ fp = open(build_py, "r")
+ try:
+- module = imp.load_module("module_" + name, fp, build_py,
+- (".py", "r", imp.PY_SOURCE))
+- if getattr(module, "name", None) is None:
+- module.name = name
+- found_modules.append(module)
+- found_module_names.append(name)
++ module_name = "module_" + name
++ module_spec = importlib.util.spec_from_file_location(module_name, build_py)
++
++ if module_spec is not None:
++ module = importlib.util.module_from_spec(module_spec)
++ sys.modules[module_name] = module
++ module_spec.loader.exec_module(module)
++
++ if not hasattr(module, "name"):
++ module.name = name
++ found_modules.append(module)
++ found_module_names.append(name)
+ finally:
+ fp.close()
+ except (FileNotFoundError, IOError):
+--
+2.34.1
+
diff --git a/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-dbs/mongodb/mongodb_git.bb b/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-dbs/mongodb/mongodb_git.bb
index ee5c77a85d..5d904dd4f9 100644
--- a/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-dbs/mongodb/mongodb_git.bb
+++ b/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-dbs/mongodb/mongodb_git.bb
@@ -11,9 +11,9 @@ DEPENDS = "openssl libpcap zlib boost curl python3 \
inherit scons dos2unix siteinfo python3native systemd useradd
-PV = "4.4.24"
-#v4.4.24
-SRCREV = "0b86b9b7b42ad9970c5f818c527dd86c0634243a"
+PV = "4.4.29"
+#v4.4.29
+SRCREV = "89d6ffe6fc67b36fd47aff6425087003966588e3"
SRC_URI = "git://github.com/mongodb/mongo.git;branch=v4.4;protocol=https \
file://0001-Tell-scons-to-use-build-settings-from-environment-va.patch \
file://0001-Use-long-long-instead-of-int64_t.patch \
@@ -32,10 +32,10 @@ SRC_URI = "git://github.com/mongodb/mongo.git;branch=v4.4;protocol=https \
file://0001-add-explict-static_cast-size_t-to-maxMemoryUsageByte.patch \
file://0001-server-Adjust-the-cache-alignment-assumptions.patch \
file://0001-The-std-lib-unary-binary_function-base-classes-are-d.patch \
- file://0001-free_mon-Include-missing-cstdint.patch \
file://0001-apply-msvc-workaround-for-clang-16.patch \
file://0001-Fix-type-mismatch-on-32bit-arches.patch \
file://0001-Fix-build-on-32bit.patch \
+ file://0001-moduleconfig.py-python-3.12-compatibility.patch \
"
SRC_URI:append:libc-musl ="\
file://0001-Mark-one-of-strerror_r-implementation-glibc-specific.patch \
@@ -145,5 +145,3 @@ SYSTEMD_SERVICE:${PN} = "mongod.service"
FILES:${PN} += "${nonarch_libdir}/tmpfiles.d"
RDEPENDS:${PN} += "tzdata-core"
-
-SKIP_RECIPE[mongodb] ?= "Needs porting to python 3.12"
diff --git a/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-multimedia/kmsxx/kmsxx_git.bb b/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-multimedia/kmsxx/kmsxx_git.bb
index cdba1a24d1..8fb93ae7aa 100644
--- a/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-multimedia/kmsxx/kmsxx_git.bb
+++ b/meta-openembedded/meta-oe/dynamic-layers/meta-python/recipes-multimedia/kmsxx/kmsxx_git.bb
@@ -24,12 +24,5 @@ S = "${WORKDIR}/git"
inherit meson pkgconfig
-do_install:append() {
- if ${@bb.utils.contains('PACKAGECONFIG', 'utils', 'true', 'false', d)}; then
- # kmstest already provided by libdrm-tests
- mv ${D}${bindir}/kmstest ${D}${bindir}/kmsxxtest
- fi
-}
-
FILES:${PN} ="${bindir} ${libdir}"
FILES:${PN}-python += "${PYTHON_SITEPACKAGES_DIR}/*"
diff --git a/meta-openembedded/meta-oe/dynamic-layers/selinux/recipes-devtool/android-tools/android-tools/android-tools-adbd.service b/meta-openembedded/meta-oe/dynamic-layers/selinux/recipes-devtool/android-tools/android-tools/android-tools-adbd.service
index ddf8d7f74e..b6661f2e39 100644
--- a/meta-openembedded/meta-oe/dynamic-layers/selinux/recipes-devtool/android-tools/android-tools/android-tools-adbd.service
+++ b/meta-openembedded/meta-oe/dynamic-layers/selinux/recipes-devtool/android-tools/android-tools/android-tools-adbd.service
@@ -1,6 +1,6 @@
[Unit]
Description=Android Debug Bridge
-ConditionPathExists=/var/usb-debugging-enabled
+ConditionPathExists=/etc/usb-debugging-enabled
Before=android-system.service
[Service]
diff --git a/meta-openembedded/meta-oe/dynamic-layers/selinux/recipes-devtool/android-tools/android-tools_29.0.6.r14.bb b/meta-openembedded/meta-oe/dynamic-layers/selinux/recipes-devtool/android-tools/android-tools_29.0.6.r14.bb
index fbad5e1368..e9b0c97e96 100644
--- a/meta-openembedded/meta-oe/dynamic-layers/selinux/recipes-devtool/android-tools/android-tools_29.0.6.r14.bb
+++ b/meta-openembedded/meta-oe/dynamic-layers/selinux/recipes-devtool/android-tools/android-tools_29.0.6.r14.bb
@@ -188,7 +188,7 @@ FILES:${PN} += "${libdir}/android ${libdir}/android/*"
BBCLASSEXTEND = "native"
android_tools_enable_devmode() {
- touch ${IMAGE_ROOTFS}/var/usb-debugging-enabled
+ touch ${IMAGE_ROOTFS}/etc/usb-debugging-enabled
}
ROOTFS_POSTPROCESS_COMMAND_${PN}-adbd += "${@bb.utils.contains("USB_DEBUGGING_ENABLED", "1", "android_tools_enable_devmode;", "", d)}"
diff --git a/meta-openembedded/meta-oe/recipes-benchmark/fio/fio/CVE-2025-10823.patch b/meta-openembedded/meta-oe/recipes-benchmark/fio/fio/CVE-2025-10823.patch
new file mode 100644
index 0000000000..f5523f83e4
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-benchmark/fio/fio/CVE-2025-10823.patch
@@ -0,0 +1,37 @@
+From 6a39dfaffdb8a6c2080eec0dc7fb1ee532d54025 Mon Sep 17 00:00:00 2001
+From: Jens Axboe <axboe@kernel.dk>
+Date: Tue, 23 Sep 2025 11:50:46 -0600
+Subject: [PATCH] options: check for NULL input string and fail
+
+Waste of time busy work.
+
+Link: https://github.com/axboe/fio/issues/1982
+
+CVE: CVE-2025-10823
+
+Upstream-Status: Backport
+https://github.com/axboe/fio/commit/6a39dfaffdb8a6c2080eec0dc7fb1ee532d54025
+
+Signed-off-by: Jens Axboe <axboe@kernel.dk>
+Signed-off-by: Saravanan <saravanan.kadambathursubramaniyam@windriver.com>
+---
+ options.c | 3 +++
+ 1 file changed, 3 insertions(+)
+
+diff --git a/options.c b/options.c
+index de935ef..b38441e 100644
+--- a/options.c
++++ b/options.c
+@@ -1535,6 +1535,9 @@ static int str_buffer_pattern_cb(void *data, const char *input)
+ struct thread_data *td = cb_data_to_td(data);
+ int ret;
+
++ if (!input)
++ return 1;
++
+ /* FIXME: for now buffer pattern does not support formats */
+ ret = parse_and_fill_pattern_alloc(input, strlen(input),
+ &td->o.buffer_pattern, NULL, NULL, NULL);
+--
+2.44.3
+
diff --git a/meta-openembedded/meta-oe/recipes-benchmark/fio/fio_3.36.bb b/meta-openembedded/meta-oe/recipes-benchmark/fio/fio_3.36.bb
index a871ed8fe5..917a6e1456 100644
--- a/meta-openembedded/meta-oe/recipes-benchmark/fio/fio_3.36.bb
+++ b/meta-openembedded/meta-oe/recipes-benchmark/fio/fio_3.36.bb
@@ -28,6 +28,8 @@ SRC_URI = "git://git.kernel.dk/fio.git;branch=master"
S = "${WORKDIR}/git"
+SRC_URI += "file://CVE-2025-10823.patch"
+
# avoids build breaks when using no-static-libs.inc
DISABLE_STATIC = ""
diff --git a/meta-openembedded/meta-oe/recipes-benchmark/iperf2/iperf2_2.0.13.bb b/meta-openembedded/meta-oe/recipes-benchmark/iperf2/iperf2_2.0.13.bb
index 86e5fef530..05a905b98f 100644
--- a/meta-openembedded/meta-oe/recipes-benchmark/iperf2/iperf2_2.0.13.bb
+++ b/meta-openembedded/meta-oe/recipes-benchmark/iperf2/iperf2_2.0.13.bb
@@ -21,3 +21,6 @@ PACKAGECONFIG ??= "${@bb.utils.contains('DISTRO_FEATURES', 'ipv6', 'ipv6', '', d
PACKAGECONFIG[ipv6] = "--enable-ipv6,--disable-ipv6,"
CVE_PRODUCT = "iperf_project:iperf"
+CVE_STATUS[CVE-2025-54349] = "cpe-incorrect: the vulnerability is in iperf3, which is a different project"
+CVE_STATUS[CVE-2025-54350] = "cpe-incorrect: the vulnerability is in iperf3, which is a different project"
+CVE_STATUS[CVE-2025-54351] = "cpe-incorrect: the vulnerability is in iperf3, which is a different project"
diff --git a/meta-openembedded/meta-oe/recipes-benchmark/iperf3/iperf3/CVE-2025-54349.patch b/meta-openembedded/meta-oe/recipes-benchmark/iperf3/iperf3/CVE-2025-54349.patch
new file mode 100644
index 0000000000..d21d635afe
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-benchmark/iperf3/iperf3/CVE-2025-54349.patch
@@ -0,0 +1,97 @@
+From 0ea4200f04ab2a823a718f48b8f853328858fcc9 Mon Sep 17 00:00:00 2001
+From: Sarah Larsen <swlarsen@es.net>
+Date: Wed, 25 Jun 2025 15:11:03 +0000
+Subject: [PATCH] Fix off-by-one heap overflow in auth.
+
+Reported by Han Lee (Apple Information Security)
+CVE-2025-54349
+
+CVE: CVE-2025-54349
+Upstream-Status: Backport [https://github.com/esnet/iperf/commit/4e5313bab0b9b3fe03513ab54f722c8a3e4b7bdf]
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ src/iperf_auth.c | 18 +++++++++++++-----
+ 1 file changed, 13 insertions(+), 5 deletions(-)
+
+diff --git a/src/iperf_auth.c b/src/iperf_auth.c
+index 72e85fc..86b4eba 100644
+--- a/src/iperf_auth.c
++++ b/src/iperf_auth.c
+@@ -288,6 +288,7 @@ int encrypt_rsa_message(const char *plaintext, EVP_PKEY *public_key, unsigned ch
+ }
+
+ int decrypt_rsa_message(const unsigned char *encryptedtext, const int encryptedtext_len, EVP_PKEY *private_key, unsigned char **plaintext, int use_pkcs1_padding) {
++ int ret =0;
+ #if OPENSSL_VERSION_MAJOR >= 3
+ EVP_PKEY_CTX *ctx;
+ #else
+@@ -310,7 +311,8 @@ int decrypt_rsa_message(const unsigned char *encryptedtext, const int encryptedt
+ keysize = RSA_size(rsa);
+ #endif
+ rsa_buffer = OPENSSL_malloc(keysize * 2);
+- *plaintext = (unsigned char*)OPENSSL_malloc(keysize);
++ // Note: +1 for NULL
++ *plaintext = (unsigned char*)OPENSSL_malloc(keysize + 1);
+
+ BIO *bioBuff = BIO_new_mem_buf((void*)encryptedtext, encryptedtext_len);
+ rsa_buffer_len = BIO_read(bioBuff, rsa_buffer, keysize * 2);
+@@ -320,13 +322,15 @@ int decrypt_rsa_message(const unsigned char *encryptedtext, const int encryptedt
+ padding = RSA_PKCS1_PADDING;
+ }
+ #if OPENSSL_VERSION_MAJOR >= 3
++
+ plaintext_len = keysize;
+ EVP_PKEY_decrypt_init(ctx);
+- int ret = EVP_PKEY_CTX_set_rsa_padding(ctx, padding);
++
++ ret = EVP_PKEY_CTX_set_rsa_padding(ctx, padding);
+ if (ret < 0){
+ goto errreturn;
+ }
+- EVP_PKEY_decrypt(ctx, *plaintext, &plaintext_len, rsa_buffer, rsa_buffer_len);
++ ret = EVP_PKEY_decrypt(ctx, *plaintext, &plaintext_len, rsa_buffer, rsa_buffer_len);
+ EVP_PKEY_CTX_free(ctx);
+ #else
+ plaintext_len = RSA_private_decrypt(rsa_buffer_len, rsa_buffer, *plaintext, rsa, padding);
+@@ -337,7 +341,7 @@ int decrypt_rsa_message(const unsigned char *encryptedtext, const int encryptedt
+ BIO_free(bioBuff);
+
+ /* Treat a decryption error as an empty string. */
+- if (plaintext_len < 0) {
++ if (plaintext_len <= 0) {
+ plaintext_len = 0;
+ }
+
+@@ -386,24 +390,28 @@ int decode_auth_setting(int enable_debug, const char *authtoken, EVP_PKEY *priva
+ int plaintext_len;
+ plaintext_len = decrypt_rsa_message(encrypted_b64, encrypted_len_b64, private_key, &plaintext, use_pkcs1_padding);
+ free(encrypted_b64);
+- if (plaintext_len < 0) {
++ if (plaintext_len <= 0) {
+ return -1;
+ }
++
+ plaintext[plaintext_len] = '\0';
+
+ char *s_username, *s_password;
+ s_username = (char *) calloc(plaintext_len, sizeof(char));
+ if (s_username == NULL) {
++ OPENSSL_free(plaintext);
+ return -1;
+ }
+ s_password = (char *) calloc(plaintext_len, sizeof(char));
+ if (s_password == NULL) {
++ OPENSSL_free(plaintext);
+ free(s_username);
+ return -1;
+ }
+
+ int rc = sscanf((char *) plaintext, auth_text_format, s_username, s_password, &utc_seconds);
+ if (rc != 3) {
++ OPENSSL_free(plaintext);
+ free(s_password);
+ free(s_username);
+ return -1;
+--
+2.50.0
+
diff --git a/meta-openembedded/meta-oe/recipes-benchmark/iperf3/iperf3/CVE-2025-54350.patch b/meta-openembedded/meta-oe/recipes-benchmark/iperf3/iperf3/CVE-2025-54350.patch
new file mode 100644
index 0000000000..e6de0e810c
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-benchmark/iperf3/iperf3/CVE-2025-54350.patch
@@ -0,0 +1,39 @@
+From 4cd6c8e85376a33bddd01fac143e27436d41f2b9 Mon Sep 17 00:00:00 2001
+From: "Bruce A. Mah" <bmah@es.net>
+Date: Tue, 24 Jun 2025 15:58:21 -0700
+Subject: [PATCH] Prevent crash due to assertion failures on malformed
+ authentication attempt.
+
+Reported by Han Lee (Apple Information Security)
+CVE-2025-54350
+
+CVE: CVE-2025-54350
+Upstream-Status: Backport [https://github.com/esnet/iperf/commit/4eab661da0bbaac04493fa40164e928c6df7934a]
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ src/iperf_auth.c | 2 --
+ 1 file changed, 2 deletions(-)
+
+diff --git a/src/iperf_auth.c b/src/iperf_auth.c
+index 86b4eba..632f03d 100644
+--- a/src/iperf_auth.c
++++ b/src/iperf_auth.c
+@@ -28,7 +28,6 @@
+ #include "iperf_config.h"
+
+ #include <string.h>
+-#include <assert.h>
+ #include <time.h>
+ #include <sys/types.h>
+ /* FreeBSD needs _WITH_GETLINE to enable the getline() declaration */
+@@ -152,7 +151,6 @@ int Base64Decode(const char* b64message, unsigned char** buffer, size_t* length)
+
+ BIO_set_flags(bio, BIO_FLAGS_BASE64_NO_NL); //Do not use newlines to flush buffer
+ *length = BIO_read(bio, *buffer, strlen(b64message));
+- assert(*length == decodeLen); //length should equal decodeLen, else something went horribly wrong
+ BIO_free_all(bio);
+
+ return (0); //success
+--
+2.50.0
+
diff --git a/meta-openembedded/meta-oe/recipes-benchmark/iperf3/iperf3_3.16.bb b/meta-openembedded/meta-oe/recipes-benchmark/iperf3/iperf3_3.18.bb
index 5cec4c6874..7fb2c52d08 100644
--- a/meta-openembedded/meta-oe/recipes-benchmark/iperf3/iperf3_3.16.bb
+++ b/meta-openembedded/meta-oe/recipes-benchmark/iperf3/iperf3_3.18.bb
@@ -10,14 +10,16 @@ SECTION = "console/network"
BUGTRACKER = "https://github.com/esnet/iperf/issues"
LICENSE = "BSD-3-Clause"
-LIC_FILES_CHKSUM = "file://LICENSE;md5=dc6301c8256ceb8f71c9e3c2ae9096b9"
+LIC_FILES_CHKSUM = "file://LICENSE;md5=f9873a72f714e240530e759e103ac7b2"
SRC_URI = "git://github.com/esnet/iperf.git;branch=master;protocol=https \
file://0002-Remove-pg-from-profile_CFLAGS.patch \
file://0001-configure.ac-check-for-CPP-prog.patch \
- "
+ file://CVE-2025-54349.patch \
+ file://CVE-2025-54350.patch \
+ "
-SRCREV = "f9481e1cd35159929458513692e4a8f9fdd1bd6f"
+SRCREV = "2a2984488d6de8f7a2d1f5938e03ca7be57e227c"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-oe/recipes-bsp/bolt/bolt_0.9.6.bb b/meta-openembedded/meta-oe/recipes-bsp/bolt/bolt_0.9.6.bb
index 4688ae860b..c278a0982a 100644
--- a/meta-openembedded/meta-oe/recipes-bsp/bolt/bolt_0.9.6.bb
+++ b/meta-openembedded/meta-oe/recipes-bsp/bolt/bolt_0.9.6.bb
@@ -18,5 +18,5 @@ inherit cmake pkgconfig meson features_check
FILES:${PN} += "${datadir}/dbus-1/* \
${datadir}/polkit-1/* \
- ${libdir}/systemd/* \
- "
+ ${systemd_system_unitdir} \
+"
diff --git a/meta-openembedded/meta-oe/recipes-bsp/fwupd/fwupd_1.9.18.bb b/meta-openembedded/meta-oe/recipes-bsp/fwupd/fwupd_1.9.18.bb
index e6c276ba4e..a98ed67f76 100644
--- a/meta-openembedded/meta-oe/recipes-bsp/fwupd/fwupd_1.9.18.bb
+++ b/meta-openembedded/meta-oe/recipes-bsp/fwupd/fwupd_1.9.18.bb
@@ -140,3 +140,5 @@ FILES:${PN} += "${libdir}/fwupd-plugins-* \
FILES:${PN}-ptest += "${libexecdir}/installed-tests/ \
${datadir}/installed-tests/"
RDEPENDS:${PN}-ptest += "gnome-desktop-testing"
+
+INSANE_SKIP:${PN}-ptest += "buildpaths"
diff --git a/meta-openembedded/meta-oe/recipes-bsp/lm_sensors/lmsensors_3.6.0.bb b/meta-openembedded/meta-oe/recipes-bsp/lm_sensors/lmsensors_3.6.0.bb
index aba5ab5878..6e4cf29f47 100644
--- a/meta-openembedded/meta-oe/recipes-bsp/lm_sensors/lmsensors_3.6.0.bb
+++ b/meta-openembedded/meta-oe/recipes-bsp/lm_sensors/lmsensors_3.6.0.bb
@@ -48,15 +48,19 @@ S = "${WORKDIR}/git"
EXTRA_OEMAKE = 'EXLDFLAGS="${LDFLAGS}" \
MACHINE=${TARGET_ARCH} PREFIX=${prefix} MANDIR=${mandir} \
LIBDIR=${libdir} \
- CC="${CC}" AR="${AR}"'
+ CC="${CC}" AR="${AR}" \
+ PROG_EXTRA="sensors ${PACKAGECONFIG_CONFARGS}"'
+
+do_configure:prepend() {
+ sed -i -e 's:^#\(PROG_EXTRA\):\1:' ${S}/Makefile
+}
do_compile() {
- sed -i -e 's:^# \(PROG_EXTRA\):\1:' ${S}/Makefile
# Respect LDFLAGS
sed -i -e 's/\$(LIBDIR)$/\$(LIBDIR) \$(LDFLAGS)/g' ${S}/Makefile
sed -i -e 's/\$(LIBSHSONAME) -o/$(LIBSHSONAME) \$(LDFLAGS) -o/g' \
${S}/lib/Module.mk
- oe_runmake user PROG_EXTRA="sensors ${PACKAGECONFIG_CONFARGS}"
+ oe_runmake user
}
do_install() {
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/ace/ace_6.5.19.bb b/meta-openembedded/meta-oe/recipes-connectivity/ace/ace_6.5.19.bb
index af4f2c54bb..911c1f69ab 100644
--- a/meta-openembedded/meta-oe/recipes-connectivity/ace/ace_6.5.19.bb
+++ b/meta-openembedded/meta-oe/recipes-connectivity/ace/ace_6.5.19.bb
@@ -13,6 +13,8 @@ SRC_URI = "https://github.com/DOCGroup/ACE_TAO/releases/download/ACE%2BTAO-6_5_1
"
SRC_URI[sha256sum] = "739be290a38229aaa5b5150e6ea55ce427e80970f0ace4c5040ac46644526f41"
+CVE_STATUS[CVE-2009-1147] = "cpe-incorrect: this CVE is for vmware ace"
+
COMPATIBLE_HOST:libc-musl = "null"
S = "${WORKDIR}/ACE_wrappers"
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/gattlib/gattlib_git.bb b/meta-openembedded/meta-oe/recipes-connectivity/gattlib/gattlib_git.bb
index 7ad28d594d..0841dc2596 100644
--- a/meta-openembedded/meta-oe/recipes-connectivity/gattlib/gattlib_git.bb
+++ b/meta-openembedded/meta-oe/recipes-connectivity/gattlib/gattlib_git.bb
@@ -17,6 +17,8 @@ SRCREV = "33a8a275928b186381bb0aea0f9778e330e57ec3"
S = "${WORKDIR}/git"
+CVE_STATUS[CVE-2019-6498] = "fixed-version: patch is already included in sources"
+
PACKAGECONFIG[examples] = "-DGATTLIB_BUILD_EXAMPLES=ON,-DGATTLIB_BUILD_EXAMPLES=OFF"
# Set this to force use of DBus API if Bluez version is older than 5.42
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/0001-SAE-Check-for-invalid-Rejected-Groups-element-length.patch b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/0001-SAE-Check-for-invalid-Rejected-Groups-element-length.patch
new file mode 100644
index 0000000000..5780f27f8b
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/0001-SAE-Check-for-invalid-Rejected-Groups-element-length.patch
@@ -0,0 +1,52 @@
+From 364c2da8741f0979dae497551e70b94c0e6c8636 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <j@w1.fi>
+Date: Sun, 7 Jul 2024 11:46:49 +0300
+Subject: [PATCH 1/3] SAE: Check for invalid Rejected Groups element length
+ explicitly
+
+Instead of practically ignoring an odd octet at the end of the element,
+check for such invalid case explicitly. This is needed to avoid a
+potential group downgrade attack.
+
+Signed-off-by: Jouni Malinen <j@w1.fi>
+
+CVE: CVE-2024-3596
+Upstream-Status: Backport [https://w1.fi/cgit/hostap/commit/?id=364c2da8741f0979dae497551e70b94c0e6c8636]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/ap/ieee802_11.c | 12 ++++++++++--
+ 1 file changed, 10 insertions(+), 2 deletions(-)
+
+diff --git a/src/ap/ieee802_11.c b/src/ap/ieee802_11.c
+index db4104928..1a62e30cc 100644
+--- a/src/ap/ieee802_11.c
++++ b/src/ap/ieee802_11.c
+@@ -1258,7 +1258,7 @@ static int check_sae_rejected_groups(struct hostapd_data *hapd,
+ struct sae_data *sae)
+ {
+ const struct wpabuf *groups;
+- size_t i, count;
++ size_t i, count, len;
+ const u8 *pos;
+
+ if (!sae->tmp)
+@@ -1268,7 +1268,15 @@ static int check_sae_rejected_groups(struct hostapd_data *hapd,
+ return 0;
+
+ pos = wpabuf_head(groups);
+- count = wpabuf_len(groups) / 2;
++ len = wpabuf_len(groups);
++ if (len & 1) {
++ wpa_printf(MSG_DEBUG,
++ "SAE: Invalid length of the Rejected Groups element payload: %zu",
++ len);
++ return 1;
++ }
++
++ count = len / 2;
+ for (i = 0; i < count; i++) {
+ int enabled;
+ u16 group;
+--
+2.30.2
+
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/0003-SAE-Reject-invalid-Rejected-Groups-element-in-the-pa.patch b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/0003-SAE-Reject-invalid-Rejected-Groups-element-in-the-pa.patch
new file mode 100644
index 0000000000..5e9e8bc01d
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/0003-SAE-Reject-invalid-Rejected-Groups-element-in-the-pa.patch
@@ -0,0 +1,38 @@
+From 9716bf1160beb677e965d9e6475d6c9e162e8374 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <j@w1.fi>
+Date: Tue, 9 Jul 2024 23:34:34 +0300
+Subject: [PATCH 3/3] SAE: Reject invalid Rejected Groups element in the parser
+
+There is no need to depend on all uses (i.e., both hostapd and
+wpa_supplicant) to verify that the length of the Rejected Groups field
+in the Rejected Groups element is valid (i.e., a multiple of two octets)
+since the common parser can reject the message when detecting this.
+
+Signed-off-by: Jouni Malinen <j@w1.fi>
+
+Upstream-Status: Backport [https://w1.fi/cgit/hostap/commit/?id=9716bf1160beb677e965d9e6475d6c9e162e8374]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/common/sae.c | 6 ++++++
+ 1 file changed, 6 insertions(+)
+
+diff --git a/src/common/sae.c b/src/common/sae.c
+index c0f154e91..620bdf753 100644
+--- a/src/common/sae.c
++++ b/src/common/sae.c
+@@ -2076,6 +2076,12 @@ static int sae_parse_rejected_groups(struct sae_data *sae,
+ return WLAN_STATUS_UNSPECIFIED_FAILURE;
+ epos++; /* skip ext ID */
+ len--;
++ if (len & 1) {
++ wpa_printf(MSG_DEBUG,
++ "SAE: Invalid length of the Rejected Groups element payload: %u",
++ len);
++ return WLAN_STATUS_UNSPECIFIED_FAILURE;
++ }
+
+ wpabuf_free(sae->tmp->peer_rejected_groups);
+ sae->tmp->peer_rejected_groups = wpabuf_alloc(len);
+--
+2.30.2
+
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2023-52160.patch b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2023-52160.patch
new file mode 100644
index 0000000000..7f46ea84c6
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2023-52160.patch
@@ -0,0 +1,198 @@
+From 6c81c2d98dc5a8a6296820bd9f083faae2c788c3 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <j@w1.fi>
+Date: Sat, 8 Jul 2023 19:55:32 +0300
+Subject: [PATCH] PEAP client: Update Phase 2 authentication requirements
+
+The previous PEAP client behavior allowed the server to skip Phase 2
+authentication with the expectation that the server was authenticated
+during Phase 1 through TLS server certificate validation. Various PEAP
+specifications are not exactly clear on what the behavior on this front
+is supposed to be and as such, this ended up being more flexible than
+the TTLS/FAST/TEAP cases. However, this is not really ideal when
+unfortunately common misconfiguration of PEAP is used in deployed
+devices where the server trust root (ca_cert) is not configured or the
+user has an easy option for allowing this validation step to be skipped.
+
+Change the default PEAP client behavior to be to require Phase 2
+authentication to be successfully completed for cases where TLS session
+resumption is not used and the client certificate has not been
+configured. Those two exceptions are the main cases where a deployed
+authentication server might skip Phase 2 and as such, where a more
+strict default behavior could result in undesired interoperability
+issues. Requiring Phase 2 authentication will end up disabling TLS
+session resumption automatically to avoid interoperability issues.
+
+Allow Phase 2 authentication behavior to be configured with a new phase1
+configuration parameter option:
+'phase2_auth' option can be used to control Phase 2 (i.e., within TLS
+tunnel) behavior for PEAP:
+ * 0 = do not require Phase 2 authentication
+ * 1 = require Phase 2 authentication when client certificate
+ (private_key/client_cert) is no used and TLS session resumption was
+ not used (default)
+ * 2 = require Phase 2 authentication in all cases
+
+Signed-off-by: Jouni Malinen <j@w1.fi>
+
+CVE: CVE-2023-52160
+
+Upstream-Status: Backport
+[https://w1.fi/cgit/hostap/commit/?id=8e6485a1bcb0baffdea9e55255a81270b768439c]
+
+Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
+---
+ src/eap_peer/eap_config.h | 8 +++++++
+ src/eap_peer/eap_peap.c | 40 ++++++++++++++++++++++++++++++++---
+ src/eap_peer/eap_tls_common.c | 6 ++++++
+ src/eap_peer/eap_tls_common.h | 5 +++++
+ 4 files changed, 56 insertions(+), 3 deletions(-)
+
+diff --git a/src/eap_peer/eap_config.h b/src/eap_peer/eap_config.h
+index 3238f74..047eec2 100644
+--- a/src/eap_peer/eap_config.h
++++ b/src/eap_peer/eap_config.h
+@@ -469,6 +469,14 @@ struct eap_peer_config {
+ * 1 = use cryptobinding if server supports it
+ * 2 = require cryptobinding
+ *
++ * phase2_auth option can be used to control Phase 2 (i.e., within TLS
++ * tunnel) behavior for PEAP:
++ * 0 = do not require Phase 2 authentication
++ * 1 = require Phase 2 authentication when client certificate
++ * (private_key/client_cert) is no used and TLS session resumption was
++ * not used (default)
++ * 2 = require Phase 2 authentication in all cases
++ *
+ * EAP-WSC (WPS) uses following options: pin=Device_Password and
+ * uuid=Device_UUID
+ *
+diff --git a/src/eap_peer/eap_peap.c b/src/eap_peer/eap_peap.c
+index 12e30df..6080697 100644
+--- a/src/eap_peer/eap_peap.c
++++ b/src/eap_peer/eap_peap.c
+@@ -67,6 +67,7 @@ struct eap_peap_data {
+ u8 cmk[20];
+ int soh; /* Whether IF-TNCCS-SOH (Statement of Health; Microsoft NAP)
+ * is enabled. */
++ enum { NO_AUTH, FOR_INITIAL, ALWAYS } phase2_auth;
+ };
+
+
+@@ -114,6 +115,19 @@ static void eap_peap_parse_phase1(struct eap_peap_data *data,
+ wpa_printf(MSG_DEBUG, "EAP-PEAP: Require cryptobinding");
+ }
+
++ if (os_strstr(phase1, "phase2_auth=0")) {
++ data->phase2_auth = NO_AUTH;
++ wpa_printf(MSG_DEBUG,
++ "EAP-PEAP: Do not require Phase 2 authentication");
++ } else if (os_strstr(phase1, "phase2_auth=1")) {
++ data->phase2_auth = FOR_INITIAL;
++ wpa_printf(MSG_DEBUG,
++ "EAP-PEAP: Require Phase 2 authentication for initial connection");
++ } else if (os_strstr(phase1, "phase2_auth=2")) {
++ data->phase2_auth = ALWAYS;
++ wpa_printf(MSG_DEBUG,
++ "EAP-PEAP: Require Phase 2 authentication for all cases");
++ }
+ #ifdef EAP_TNC
+ if (os_strstr(phase1, "tnc=soh2")) {
+ data->soh = 2;
+@@ -142,6 +156,7 @@ static void * eap_peap_init(struct eap_sm *sm)
+ data->force_peap_version = -1;
+ data->peap_outer_success = 2;
+ data->crypto_binding = OPTIONAL_BINDING;
++ data->phase2_auth = FOR_INITIAL;
+
+ if (config && config->phase1)
+ eap_peap_parse_phase1(data, config->phase1);
+@@ -454,6 +469,20 @@ static int eap_tlv_validate_cryptobinding(struct eap_sm *sm,
+ }
+
+
++static bool peap_phase2_sufficient(struct eap_sm *sm,
++ struct eap_peap_data *data)
++{
++ if ((data->phase2_auth == ALWAYS ||
++ (data->phase2_auth == FOR_INITIAL &&
++ !tls_connection_resumed(sm->ssl_ctx, data->ssl.conn) &&
++ !data->ssl.client_cert_conf) ||
++ data->phase2_eap_started) &&
++ !data->phase2_eap_success)
++ return false;
++ return true;
++}
++
++
+ /**
+ * eap_tlv_process - Process a received EAP-TLV message and generate a response
+ * @sm: Pointer to EAP state machine allocated with eap_peer_sm_init()
+@@ -568,6 +597,11 @@ static int eap_tlv_process(struct eap_sm *sm, struct eap_peap_data *data,
+ " - force failed Phase 2");
+ resp_status = EAP_TLV_RESULT_FAILURE;
+ ret->decision = DECISION_FAIL;
++ } else if (!peap_phase2_sufficient(sm, data)) {
++ wpa_printf(MSG_INFO,
++ "EAP-PEAP: Server indicated Phase 2 success, but sufficient Phase 2 authentication has not been completed");
++ resp_status = EAP_TLV_RESULT_FAILURE;
++ ret->decision = DECISION_FAIL;
+ } else {
+ resp_status = EAP_TLV_RESULT_SUCCESS;
+ ret->decision = DECISION_UNCOND_SUCC;
+@@ -887,8 +921,7 @@ continue_req:
+ /* EAP-Success within TLS tunnel is used to indicate
+ * shutdown of the TLS channel. The authentication has
+ * been completed. */
+- if (data->phase2_eap_started &&
+- !data->phase2_eap_success) {
++ if (!peap_phase2_sufficient(sm, data)) {
+ wpa_printf(MSG_DEBUG, "EAP-PEAP: Phase 2 "
+ "Success used to indicate success, "
+ "but Phase 2 EAP was not yet "
+@@ -1199,8 +1232,9 @@ static struct wpabuf * eap_peap_process(struct eap_sm *sm, void *priv,
+ static bool eap_peap_has_reauth_data(struct eap_sm *sm, void *priv)
+ {
+ struct eap_peap_data *data = priv;
++
+ return tls_connection_established(sm->ssl_ctx, data->ssl.conn) &&
+- data->phase2_success;
++ data->phase2_success && data->phase2_auth != ALWAYS;
+ }
+
+
+diff --git a/src/eap_peer/eap_tls_common.c b/src/eap_peer/eap_tls_common.c
+index c1837db..a53eeb1 100644
+--- a/src/eap_peer/eap_tls_common.c
++++ b/src/eap_peer/eap_tls_common.c
+@@ -239,6 +239,12 @@ static int eap_tls_params_from_conf(struct eap_sm *sm,
+
+ sm->ext_cert_check = !!(params->flags & TLS_CONN_EXT_CERT_CHECK);
+
++ if (!phase2)
++ data->client_cert_conf = params->client_cert ||
++ params->client_cert_blob ||
++ params->private_key ||
++ params->private_key_blob;
++
+ return 0;
+ }
+
+diff --git a/src/eap_peer/eap_tls_common.h b/src/eap_peer/eap_tls_common.h
+index 9ac0012..3348634 100644
+--- a/src/eap_peer/eap_tls_common.h
++++ b/src/eap_peer/eap_tls_common.h
+@@ -79,6 +79,11 @@ struct eap_ssl_data {
+ * tls_v13 - Whether TLS v1.3 or newer is used
+ */
+ int tls_v13;
++
++ /**
++ * client_cert_conf: Whether client certificate has been configured
++ */
++ bool client_cert_conf;
+ };
+
+
+--
+2.25.1
+
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_00.patch b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_00.patch
new file mode 100644
index 0000000000..58e1327f2b
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_00.patch
@@ -0,0 +1,83 @@
+From 945acf3ef06a6c312927da4fa055693dbac432d1 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <j@w1.fi>
+Date: Sat, 2 Apr 2022 16:28:12 +0300
+Subject: [PATCH 1/9] ieee802_11_auth: Coding style cleanup - no string
+ constant splitting
+
+Signed-off-by: Jouni Malinen <j@w1.fi>
+
+CVE: CVE-2024-3596
+Upstream-Status: Backport [https://w1.fi/cgit/hostap/commit/?id=945acf3ef06a6c312927da4fa055693dbac432d1]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/ap/ieee802_11_auth.c | 27 +++++++++++++++------------
+ 1 file changed, 15 insertions(+), 12 deletions(-)
+
+diff --git a/src/ap/ieee802_11_auth.c b/src/ap/ieee802_11_auth.c
+index 783ee6dea..47cc625be 100644
+--- a/src/ap/ieee802_11_auth.c
++++ b/src/ap/ieee802_11_auth.c
+@@ -267,16 +267,16 @@ int hostapd_allowed_address(struct hostapd_data *hapd, const u8 *addr,
+ os_get_reltime(&query->timestamp);
+ os_memcpy(query->addr, addr, ETH_ALEN);
+ if (hostapd_radius_acl_query(hapd, addr, query)) {
+- wpa_printf(MSG_DEBUG, "Failed to send Access-Request "
+- "for ACL query.");
++ wpa_printf(MSG_DEBUG,
++ "Failed to send Access-Request for ACL query.");
+ hostapd_acl_query_free(query);
+ return HOSTAPD_ACL_REJECT;
+ }
+
+ query->auth_msg = os_memdup(msg, len);
+ if (query->auth_msg == NULL) {
+- wpa_printf(MSG_ERROR, "Failed to allocate memory for "
+- "auth frame.");
++ wpa_printf(MSG_ERROR,
++ "Failed to allocate memory for auth frame.");
+ hostapd_acl_query_free(query);
+ return HOSTAPD_ACL_REJECT;
+ }
+@@ -467,19 +467,21 @@ hostapd_acl_recv_radius(struct radius_msg *msg, struct radius_msg *req,
+ if (query == NULL)
+ return RADIUS_RX_UNKNOWN;
+
+- wpa_printf(MSG_DEBUG, "Found matching Access-Request for RADIUS "
+- "message (id=%d)", query->radius_id);
++ wpa_printf(MSG_DEBUG,
++ "Found matching Access-Request for RADIUS message (id=%d)",
++ query->radius_id);
+
+ if (radius_msg_verify(msg, shared_secret, shared_secret_len, req, 0)) {
+- wpa_printf(MSG_INFO, "Incoming RADIUS packet did not have "
+- "correct authenticator - dropped\n");
++ wpa_printf(MSG_INFO,
++ "Incoming RADIUS packet did not have correct authenticator - dropped");
+ return RADIUS_RX_INVALID_AUTHENTICATOR;
+ }
+
+ if (hdr->code != RADIUS_CODE_ACCESS_ACCEPT &&
+ hdr->code != RADIUS_CODE_ACCESS_REJECT) {
+- wpa_printf(MSG_DEBUG, "Unknown RADIUS message code %d to ACL "
+- "query", hdr->code);
++ wpa_printf(MSG_DEBUG,
++ "Unknown RADIUS message code %d to ACL query",
++ hdr->code);
+ return RADIUS_RX_UNKNOWN;
+ }
+
+@@ -506,8 +508,9 @@ hostapd_acl_recv_radius(struct radius_msg *msg, struct radius_msg *req,
+ msg, RADIUS_ATTR_ACCT_INTERIM_INTERVAL,
+ &info->acct_interim_interval) == 0 &&
+ info->acct_interim_interval < 60) {
+- wpa_printf(MSG_DEBUG, "Ignored too small "
+- "Acct-Interim-Interval %d for STA " MACSTR,
++ wpa_printf(MSG_DEBUG,
++ "Ignored too small Acct-Interim-Interval %d for STA "
++ MACSTR,
+ info->acct_interim_interval,
+ MAC2STR(query->addr));
+ info->acct_interim_interval = 0;
+--
+2.30.2
+
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_01.patch b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_01.patch
new file mode 100644
index 0000000000..dab2eedd6a
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_01.patch
@@ -0,0 +1,165 @@
+From adac846bd0e258a0aa50750bbd2b411fa0085c46 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <j@w1.fi>
+Date: Sat, 16 Mar 2024 11:11:44 +0200
+Subject: [PATCH 2/9] RADIUS: Allow Message-Authenticator attribute as the
+ first attribute
+
+If a Message-Authenticator attribute was already added to a RADIUS
+message, use that attribute instead of adding a new one when finishing
+message building. This allows the Message-Authenticator attribute to be
+placed as the first attribute in the message.
+
+Signed-off-by: Jouni Malinen <j@w1.fi>
+
+CVE: CVE-2024-3596
+Upstream-Status: Backport [https://w1.fi/cgit/hostap/commit/?id=adac846bd0e258a0aa50750bbd2b411fa0085c46]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/radius/radius.c | 85 ++++++++++++++++++++++++++++-----------------
+ src/radius/radius.h | 1 +
+ 2 files changed, 54 insertions(+), 32 deletions(-)
+
+diff --git a/src/radius/radius.c b/src/radius/radius.c
+index be16e27b9..2d2e00b5c 100644
+--- a/src/radius/radius.c
++++ b/src/radius/radius.c
+@@ -364,25 +364,54 @@ void radius_msg_dump(struct radius_msg *msg)
+ }
+
+
++u8 * radius_msg_add_msg_auth(struct radius_msg *msg)
++{
++ u8 auth[MD5_MAC_LEN];
++ struct radius_attr_hdr *attr;
++
++ os_memset(auth, 0, MD5_MAC_LEN);
++ attr = radius_msg_add_attr(msg, RADIUS_ATTR_MESSAGE_AUTHENTICATOR,
++ auth, MD5_MAC_LEN);
++ if (!attr) {
++ wpa_printf(MSG_ERROR,
++ "WARNING: Could not add Message-Authenticator");
++ return NULL;
++ }
++
++ return (u8 *) (attr + 1);
++}
++
++
++static u8 * radius_msg_auth_pos(struct radius_msg *msg)
++{
++ u8 *pos;
++ size_t alen;
++
++ if (radius_msg_get_attr_ptr(msg, RADIUS_ATTR_MESSAGE_AUTHENTICATOR,
++ &pos, &alen, NULL) == 0 &&
++ alen == MD5_MAC_LEN) {
++ /* Use already added Message-Authenticator attribute */
++ return pos;
++ }
++
++ /* Add a Message-Authenticator attribute */
++ return radius_msg_add_msg_auth(msg);
++}
++
++
+ int radius_msg_finish(struct radius_msg *msg, const u8 *secret,
+ size_t secret_len)
+ {
+ if (secret) {
+- u8 auth[MD5_MAC_LEN];
+- struct radius_attr_hdr *attr;
++ u8 *pos;
+
+- os_memset(auth, 0, MD5_MAC_LEN);
+- attr = radius_msg_add_attr(msg,
+- RADIUS_ATTR_MESSAGE_AUTHENTICATOR,
+- auth, MD5_MAC_LEN);
+- if (attr == NULL) {
+- wpa_printf(MSG_WARNING, "RADIUS: Could not add "
+- "Message-Authenticator");
++ pos = radius_msg_auth_pos(msg);
++ if (!pos)
+ return -1;
+- }
+ msg->hdr->length = host_to_be16(wpabuf_len(msg->buf));
+- hmac_md5(secret, secret_len, wpabuf_head(msg->buf),
+- wpabuf_len(msg->buf), (u8 *) (attr + 1));
++ if (hmac_md5(secret, secret_len, wpabuf_head(msg->buf),
++ wpabuf_len(msg->buf), pos) < 0)
++ return -1;
+ } else
+ msg->hdr->length = host_to_be16(wpabuf_len(msg->buf));
+
+@@ -398,23 +427,19 @@ int radius_msg_finish(struct radius_msg *msg, const u8 *secret,
+ int radius_msg_finish_srv(struct radius_msg *msg, const u8 *secret,
+ size_t secret_len, const u8 *req_authenticator)
+ {
+- u8 auth[MD5_MAC_LEN];
+- struct radius_attr_hdr *attr;
+ const u8 *addr[4];
+ size_t len[4];
++ u8 *pos;
+
+- os_memset(auth, 0, MD5_MAC_LEN);
+- attr = radius_msg_add_attr(msg, RADIUS_ATTR_MESSAGE_AUTHENTICATOR,
+- auth, MD5_MAC_LEN);
+- if (attr == NULL) {
+- wpa_printf(MSG_ERROR, "WARNING: Could not add Message-Authenticator");
++ pos = radius_msg_auth_pos(msg);
++ if (!pos)
+ return -1;
+- }
+ msg->hdr->length = host_to_be16(wpabuf_len(msg->buf));
+ os_memcpy(msg->hdr->authenticator, req_authenticator,
+ sizeof(msg->hdr->authenticator));
+- hmac_md5(secret, secret_len, wpabuf_head(msg->buf),
+- wpabuf_len(msg->buf), (u8 *) (attr + 1));
++ if (hmac_md5(secret, secret_len, wpabuf_head(msg->buf),
++ wpabuf_len(msg->buf), pos) < 0)
++ return -1;
+
+ /* ResponseAuth = MD5(Code+ID+Length+RequestAuth+Attributes+Secret) */
+ addr[0] = (u8 *) msg->hdr;
+@@ -442,21 +467,17 @@ int radius_msg_finish_das_resp(struct radius_msg *msg, const u8 *secret,
+ {
+ const u8 *addr[2];
+ size_t len[2];
+- u8 auth[MD5_MAC_LEN];
+- struct radius_attr_hdr *attr;
++ u8 *pos;
+
+- os_memset(auth, 0, MD5_MAC_LEN);
+- attr = radius_msg_add_attr(msg, RADIUS_ATTR_MESSAGE_AUTHENTICATOR,
+- auth, MD5_MAC_LEN);
+- if (attr == NULL) {
+- wpa_printf(MSG_WARNING, "Could not add Message-Authenticator");
++ pos = radius_msg_auth_pos(msg);
++ if (!pos)
+ return -1;
+- }
+
+ msg->hdr->length = host_to_be16(wpabuf_len(msg->buf));
+ os_memcpy(msg->hdr->authenticator, req_hdr->authenticator, 16);
+- hmac_md5(secret, secret_len, wpabuf_head(msg->buf),
+- wpabuf_len(msg->buf), (u8 *) (attr + 1));
++ if (hmac_md5(secret, secret_len, wpabuf_head(msg->buf),
++ wpabuf_len(msg->buf), pos) < 0)
++ return -1;
+
+ /* ResponseAuth = MD5(Code+ID+Length+RequestAuth+Attributes+Secret) */
+ addr[0] = wpabuf_head_u8(msg->buf);
+diff --git a/src/radius/radius.h b/src/radius/radius.h
+index fb8148180..6b9dfbca2 100644
+--- a/src/radius/radius.h
++++ b/src/radius/radius.h
+@@ -240,6 +240,7 @@ struct wpabuf * radius_msg_get_buf(struct radius_msg *msg);
+ struct radius_msg * radius_msg_new(u8 code, u8 identifier);
+ void radius_msg_free(struct radius_msg *msg);
+ void radius_msg_dump(struct radius_msg *msg);
++u8 * radius_msg_add_msg_auth(struct radius_msg *msg);
+ int radius_msg_finish(struct radius_msg *msg, const u8 *secret,
+ size_t secret_len);
+ int radius_msg_finish_srv(struct radius_msg *msg, const u8 *secret,
+--
+2.30.2
+
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_02.patch b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_02.patch
new file mode 100644
index 0000000000..02e35bd6de
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_02.patch
@@ -0,0 +1,62 @@
+From 54abb0d3cf35894e7d86e3f7555e95b106306803 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <j@w1.fi>
+Date: Sat, 16 Mar 2024 11:13:32 +0200
+Subject: [PATCH 3/9] RADIUS server: Place Message-Authenticator attribute as
+ the first one
+
+Move the Message-Authenticator attribute to be the first attribute in
+the RADIUS messages. This mitigates certain MD5 attacks against
+RADIUS/UDP.
+
+Signed-off-by: Jouni Malinen <j@w1.fi>
+
+CVE: CVE-2024-3596
+Upstream-Status: Backport [https://w1.fi/cgit/hostap/commit/?id=54abb0d3cf35894e7d86e3f7555e95b106306803]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/radius/radius_server.c | 15 +++++++++++++++
+ 1 file changed, 15 insertions(+)
+
+diff --git a/src/radius/radius_server.c b/src/radius/radius_server.c
+index e02c21540..fa3691548 100644
+--- a/src/radius/radius_server.c
++++ b/src/radius/radius_server.c
+@@ -920,6 +920,11 @@ radius_server_encapsulate_eap(struct radius_server_data *data,
+ return NULL;
+ }
+
++ if (!radius_msg_add_msg_auth(msg)) {
++ radius_msg_free(msg);
++ return NULL;
++ }
++
+ sess_id = htonl(sess->sess_id);
+ if (code == RADIUS_CODE_ACCESS_CHALLENGE &&
+ !radius_msg_add_attr(msg, RADIUS_ATTR_STATE,
+@@ -1204,6 +1209,11 @@ radius_server_macacl(struct radius_server_data *data,
+ return NULL;
+ }
+
++ if (!radius_msg_add_msg_auth(msg)) {
++ radius_msg_free(msg);
++ return NULL;
++ }
++
+ if (radius_msg_copy_attr(msg, request, RADIUS_ATTR_PROXY_STATE) < 0) {
+ RADIUS_DEBUG("Failed to copy Proxy-State attribute(s)");
+ radius_msg_free(msg);
+@@ -1253,6 +1263,11 @@ static int radius_server_reject(struct radius_server_data *data,
+ return -1;
+ }
+
++ if (!radius_msg_add_msg_auth(msg)) {
++ radius_msg_free(msg);
++ return -1;
++ }
++
+ os_memset(&eapfail, 0, sizeof(eapfail));
+ eapfail.code = EAP_CODE_FAILURE;
+ eapfail.identifier = 0;
+--
+2.30.2
+
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_04.patch b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_04.patch
new file mode 100644
index 0000000000..ce499ce8b6
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_04.patch
@@ -0,0 +1,52 @@
+From 37fe8e48ab44d44fe3cf5dd8f52cb0a10be0cd17 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <j@w1.fi>
+Date: Sat, 16 Mar 2024 11:22:43 +0200
+Subject: [PATCH 5/9] hostapd: Move Message-Authenticator attribute to be the
+ first one in req
+
+Even if this is not strictly speaking necessary for mitigating certain
+RADIUS protocol attacks, be consistent with the RADIUS server behavior
+and move the Message-Authenticator attribute to be the first attribute
+in the message from RADIUS client in hostapd.
+
+Signed-off-by: Jouni Malinen <j@w1.fi>
+
+CVE: CVE-2024-3596
+Upstream-Status: Backport [https://w1.fi/cgit/hostap/commit/?id=37fe8e48ab44d44fe3cf5dd8f52cb0a10be0cd17]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/ap/ieee802_11_auth.c | 3 +++
+ src/ap/ieee802_1x.c | 3 +++
+ 2 files changed, 6 insertions(+)
+
+diff --git a/src/ap/ieee802_11_auth.c b/src/ap/ieee802_11_auth.c
+index 47cc625be..2a950cf7f 100644
+--- a/src/ap/ieee802_11_auth.c
++++ b/src/ap/ieee802_11_auth.c
+@@ -119,6 +119,9 @@ static int hostapd_radius_acl_query(struct hostapd_data *hapd, const u8 *addr,
+ goto fail;
+ }
+
++ if (!radius_msg_add_msg_auth(msg))
++ goto fail;
++
+ os_snprintf(buf, sizeof(buf), RADIUS_ADDR_FORMAT, MAC2STR(addr));
+ if (!radius_msg_add_attr(msg, RADIUS_ATTR_USER_NAME, (u8 *) buf,
+ os_strlen(buf))) {
+diff --git a/src/ap/ieee802_1x.c b/src/ap/ieee802_1x.c
+index 753c88335..89e3dd30e 100644
+--- a/src/ap/ieee802_1x.c
++++ b/src/ap/ieee802_1x.c
+@@ -702,6 +702,9 @@ void ieee802_1x_encapsulate_radius(struct hostapd_data *hapd,
+ goto fail;
+ }
+
++ if (!radius_msg_add_msg_auth(msg))
++ goto fail;
++
+ if (sm->identity &&
+ !radius_msg_add_attr(msg, RADIUS_ATTR_USER_NAME,
+ sm->identity, sm->identity_len)) {
+--
+2.30.2
+
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_05.patch b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_05.patch
new file mode 100644
index 0000000000..44113afd4a
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_05.patch
@@ -0,0 +1,51 @@
+From f54157077f799d84ce26bed6ad6b01c4a16e31cf Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <j@w1.fi>
+Date: Sat, 16 Mar 2024 11:26:58 +0200
+Subject: [PATCH 6/9] RADIUS DAS: Move Message-Authenticator attribute to be
+ the first one
+
+Even if this might not be strictly speaking necessary for mitigating
+certain RADIUS protocol attacks, be consistent with the RADIUS server
+behavior and move the Message-Authenticator attribute to be the first
+attribute in the RADIUS DAS responses from hostapd.
+
+Signed-off-by: Jouni Malinen <j@w1.fi>
+
+CVE: CVE-2024-3596
+Upstream-Status: Backport [https://w1.fi/cgit/hostap/commit/?id=f54157077f799d84ce26bed6ad6b01c4a16e31cf]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/radius/radius_das.c | 10 ++++++++++
+ 1 file changed, 10 insertions(+)
+
+diff --git a/src/radius/radius_das.c b/src/radius/radius_das.c
+index aaa3fc267..8d7c9b4c4 100644
+--- a/src/radius/radius_das.c
++++ b/src/radius/radius_das.c
+@@ -177,6 +177,11 @@ fail:
+ if (reply == NULL)
+ return NULL;
+
++ if (!radius_msg_add_msg_auth(reply)) {
++ radius_msg_free(reply);
++ return NULL;
++ }
++
+ if (error) {
+ if (!radius_msg_add_attr_int32(reply, RADIUS_ATTR_ERROR_CAUSE,
+ error)) {
+@@ -368,6 +373,11 @@ fail:
+ if (!reply)
+ return NULL;
+
++ if (!radius_msg_add_msg_auth(reply)) {
++ radius_msg_free(reply);
++ return NULL;
++ }
++
+ if (error &&
+ !radius_msg_add_attr_int32(reply, RADIUS_ATTR_ERROR_CAUSE, error)) {
+ radius_msg_free(reply);
+--
+2.30.2
+
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_06.patch b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_06.patch
new file mode 100644
index 0000000000..9a284b5261
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_06.patch
@@ -0,0 +1,46 @@
+From 934b0c3a45ce0726560ccefbd992a9d385c36385 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <j@w1.fi>
+Date: Sat, 16 Mar 2024 11:31:37 +0200
+Subject: [PATCH 7/9] Require Message-Authenticator in Access-Reject even
+ without EAP-Message
+
+Do not allow the exception for missing Message-Authenticator in
+Access-Reject without EAP-Message. While such exception is allowed in
+RADIUS definition, there is no strong reason to maintain this since
+Access-Reject is supposed to include EAP-Message and even if it doesn't,
+discarding Access-Reject will result in the connection not completing.
+
+Signed-off-by: Jouni Malinen <j@w1.fi>
+
+CVE: CVE-2024-3596
+Upstream-Status: Backport [https://w1.fi/cgit/hostap/commit/?id=934b0c3a45ce0726560ccefbd992a9d385c36385]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/ap/ieee802_1x.c | 11 +----------
+ 1 file changed, 1 insertion(+), 10 deletions(-)
+
+diff --git a/src/ap/ieee802_1x.c b/src/ap/ieee802_1x.c
+index 89e3dd30e..6e7b75128 100644
+--- a/src/ap/ieee802_1x.c
++++ b/src/ap/ieee802_1x.c
+@@ -1939,16 +1939,7 @@ ieee802_1x_receive_auth(struct radius_msg *msg, struct radius_msg *req,
+ }
+ sta = sm->sta;
+
+- /* RFC 2869, Ch. 5.13: valid Message-Authenticator attribute MUST be
+- * present when packet contains an EAP-Message attribute */
+- if (hdr->code == RADIUS_CODE_ACCESS_REJECT &&
+- radius_msg_get_attr(msg, RADIUS_ATTR_MESSAGE_AUTHENTICATOR, NULL,
+- 0) < 0 &&
+- radius_msg_get_attr(msg, RADIUS_ATTR_EAP_MESSAGE, NULL, 0) < 0) {
+- wpa_printf(MSG_DEBUG,
+- "Allowing RADIUS Access-Reject without Message-Authenticator since it does not include EAP-Message");
+- } else if (radius_msg_verify(msg, shared_secret, shared_secret_len,
+- req, 1)) {
++ if (radius_msg_verify(msg, shared_secret, shared_secret_len, req, 1)) {
+ wpa_printf(MSG_INFO,
+ "Incoming RADIUS packet did not have correct Message-Authenticator - dropped");
+ return RADIUS_RX_INVALID_AUTHENTICATOR;
+--
+2.30.2
+
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_07.patch b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_07.patch
new file mode 100644
index 0000000000..78d3f5d591
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_07.patch
@@ -0,0 +1,105 @@
+From 58097123ec5ea6f8276b38cb9b07669ec368a6c1 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <j@w1.fi>
+Date: Sun, 17 Mar 2024 10:42:56 +0200
+Subject: [PATCH 8/9] RADIUS: Require Message-Authenticator attribute in MAC
+ ACL cases
+
+hostapd required Message-Authenticator attribute to be included in EAP
+authentication cases, but that requirement was not in place for MAC ACL
+cases. Start requiring Message-Authenticator attribute for MAC ACL by
+default. Unlike the EAP case, this can still be disabled with
+radius_require_message_authenticator=1 to maintain compatibility with
+some RADIUS servers when used in a network where the connection to such
+a server is secure.
+
+Signed-off-by: Jouni Malinen <j@w1.fi>
+
+CVE: CVE-2024-3596
+Upstream-Status: Backport [https://w1.fi/cgit/hostap/commit/?id=58097123ec5ea6f8276b38cb9b07669ec368a6c1]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ hostapd/config_file.c | 3 +++
+ hostapd/hostapd.conf | 11 +++++++++++
+ src/ap/ap_config.c | 1 +
+ src/ap/ap_config.h | 1 +
+ src/ap/ieee802_11_auth.c | 4 +++-
+ 5 files changed, 19 insertions(+), 1 deletion(-)
+
+diff --git a/hostapd/config_file.c b/hostapd/config_file.c
+index b14728d1b..af1e81d1d 100644
+--- a/hostapd/config_file.c
++++ b/hostapd/config_file.c
+@@ -2806,6 +2806,9 @@ static int hostapd_config_fill(struct hostapd_config *conf,
+ bss->radius->acct_server->shared_secret_len = len;
+ } else if (os_strcmp(buf, "radius_retry_primary_interval") == 0) {
+ bss->radius->retry_primary_interval = atoi(pos);
++ } else if (os_strcmp(buf,
++ "radius_require_message_authenticator") == 0) {
++ bss->radius_require_message_authenticator = atoi(pos);
+ } else if (os_strcmp(buf, "radius_acct_interim_interval") == 0) {
+ bss->acct_interim_interval = atoi(pos);
+ } else if (os_strcmp(buf, "radius_request_cui") == 0) {
+diff --git a/hostapd/hostapd.conf b/hostapd/hostapd.conf
+index 3c2019f73..c055946a6 100644
+--- a/hostapd/hostapd.conf
++++ b/hostapd/hostapd.conf
+@@ -1447,6 +1447,17 @@ own_ip_addr=127.0.0.1
+ # currently used secondary server is still working.
+ #radius_retry_primary_interval=600
+
++# Message-Authenticator attribute requirement for non-EAP cases
++# hostapd requires Message-Authenticator attribute to be included in all cases
++# where RADIUS is used for EAP authentication. This is also required for cases
++# where RADIUS is used for MAC ACL (macaddr_acl=2) by default, but that case
++# can be configured to not require this for compatibility with RADIUS servers
++# that do not include the attribute. This is not recommended due to potential
++# security concerns, but can be used as a temporary workaround in networks where
++# the connection to the RADIUS server is secure.
++# 0 = Do not require Message-Authenticator in MAC ACL response
++# 1 = Require Message-Authenticator in all authentication cases (default)
++#radius_require_message_authenticator=1
+
+ # Interim accounting update interval
+ # If this is set (larger than 0) and acct_server is configured, hostapd will
+diff --git a/src/ap/ap_config.c b/src/ap/ap_config.c
+index 86b6e097c..cf497a180 100644
+--- a/src/ap/ap_config.c
++++ b/src/ap/ap_config.c
+@@ -120,6 +120,7 @@ void hostapd_config_defaults_bss(struct hostapd_bss_config *bss)
+ #endif /* CONFIG_IEEE80211R_AP */
+
+ bss->radius_das_time_window = 300;
++ bss->radius_require_message_authenticator = 1;
+
+ bss->anti_clogging_threshold = 5;
+ bss->sae_sync = 5;
+diff --git a/src/ap/ap_config.h b/src/ap/ap_config.h
+index 49cd3168a..22ad617f4 100644
+--- a/src/ap/ap_config.h
++++ b/src/ap/ap_config.h
+@@ -302,6 +302,7 @@ struct hostapd_bss_config {
+ struct hostapd_ip_addr own_ip_addr;
+ char *nas_identifier;
+ struct hostapd_radius_servers *radius;
++ int radius_require_message_authenticator;
+ int acct_interim_interval;
+ int radius_request_cui;
+ struct hostapd_radius_attr *radius_auth_req_attr;
+diff --git a/src/ap/ieee802_11_auth.c b/src/ap/ieee802_11_auth.c
+index 2a950cf7f..dab9bcde3 100644
+--- a/src/ap/ieee802_11_auth.c
++++ b/src/ap/ieee802_11_auth.c
+@@ -474,7 +474,9 @@ hostapd_acl_recv_radius(struct radius_msg *msg, struct radius_msg *req,
+ "Found matching Access-Request for RADIUS message (id=%d)",
+ query->radius_id);
+
+- if (radius_msg_verify(msg, shared_secret, shared_secret_len, req, 0)) {
++ if (radius_msg_verify(
++ msg, shared_secret, shared_secret_len, req,
++ hapd->conf->radius_require_message_authenticator)) {
+ wpa_printf(MSG_INFO,
+ "Incoming RADIUS packet did not have correct authenticator - dropped");
+ return RADIUS_RX_INVALID_AUTHENTICATOR;
+--
+2.30.2
+
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_08.patch b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_08.patch
new file mode 100644
index 0000000000..e23d1e0047
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2024-3596_08.patch
@@ -0,0 +1,47 @@
+From f302d9f9646704cce745734af21d540baa0da65f Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <j@w1.fi>
+Date: Sun, 17 Mar 2024 10:47:58 +0200
+Subject: [PATCH 9/9] RADIUS: Check Message-Authenticator if it is present even
+ if not required
+
+Always check the Message-Authenticator attribute in a received RADIUS
+message if it is present. Previously, this would have been skipped if
+the attribute was not required to be present.
+
+Signed-off-by: Jouni Malinen <j@w1.fi>
+
+CVE: CVE-2024-3596
+Upstream-Status: Backport [https://w1.fi/cgit/hostap/commit/?id=f302d9f9646704cce745734af21d540baa0da65f]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/radius/radius.c | 14 ++++++++++++++
+ 1 file changed, 14 insertions(+)
+
+diff --git a/src/radius/radius.c b/src/radius/radius.c
+index 2d2e00b5c..a0e3ce399 100644
+--- a/src/radius/radius.c
++++ b/src/radius/radius.c
+@@ -879,6 +879,20 @@ int radius_msg_verify(struct radius_msg *msg, const u8 *secret,
+ return 1;
+ }
+
++ if (!auth) {
++ u8 *pos;
++ size_t alen;
++
++ if (radius_msg_get_attr_ptr(msg,
++ RADIUS_ATTR_MESSAGE_AUTHENTICATOR,
++ &pos, &alen, NULL) == 0) {
++ /* Check the Message-Authenticator attribute since it
++ * was included even if we are configured to not
++ * require it. */
++ auth = 1;
++ }
++ }
++
+ if (auth &&
+ radius_msg_verify_msg_auth(msg, secret, secret_len,
+ sent_msg->hdr->authenticator)) {
+--
+2.30.2
+
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2025-24912_01.patch b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2025-24912_01.patch
new file mode 100644
index 0000000000..5ba3308139
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2025-24912_01.patch
@@ -0,0 +1,80 @@
+From c77bc3f388b81fabc9fa6233caa618c724de8a28 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <j@w1.fi>
+Date: Sat, 25 Jan 2025 11:21:16 +0200
+Subject: [PATCH] RADIUS: Drop pending request only when accepting the response
+
+The case of an invalid authenticator in a RADIUS response could imply
+that the response is not from the correct RADIUS server and as such,
+such a response should be discarded without changing internal state for
+the pending request. The case of an unknown response (RADIUS_RX_UNKNOWN)
+is somewhat more complex since it could have been indicated before
+validating the authenticator. In any case, it seems better to change the
+state for the pending request only when we have fully accepted the
+response.
+
+Allowing the internal state of pending RADIUS request to change based on
+responses that are not fully validation could have allow at least a
+theoretical DoS attack if an attacker were to have means for injecting
+RADIUS messages to the network using the IP address of the real RADIUS
+server and being able to do so more quickly than the real server and
+with the matching identifier from the request header (i.e., either by
+flooding 256 responses quickly or by having means to capture the RADIUS
+request). These should not really be realistic options in a properly
+protected deployment, but nevertheless it is good to be more careful in
+processing RADIUS responses.
+
+Remove a pending RADIUS request from the internal list only when having
+fully accepted a matching RADIUS response, i.e., after one of the
+registered handlers has confirmed that the authenticator is valid and
+processing of the response has succeeded.
+
+CVE: CVE-2025-24912
+Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=726432d7622cc0088ac353d073b59628b590ea44]
+
+Signed-off-by: Jouni Malinen <j@w1.fi>
+(cherry picked from commit 726432d7622cc0088ac353d073b59628b590ea44)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/radius/radius_client.c | 15 +++++++--------
+ 1 file changed, 7 insertions(+), 8 deletions(-)
+
+diff --git a/src/radius/radius_client.c b/src/radius/radius_client.c
+index ee9e46d2a..8f9332583 100644
+--- a/src/radius/radius_client.c
++++ b/src/radius/radius_client.c
+@@ -922,13 +922,6 @@ static void radius_client_receive(int sock, void *eloop_ctx, void *sock_ctx)
+ roundtrip / 100, roundtrip % 100);
+ rconf->round_trip_time = roundtrip;
+
+- /* Remove ACKed RADIUS packet from retransmit list */
+- if (prev_req)
+- prev_req->next = req->next;
+- else
+- radius->msgs = req->next;
+- radius->num_msgs--;
+-
+ for (i = 0; i < num_handlers; i++) {
+ RadiusRxResult res;
+ res = handlers[i].handler(msg, req->msg, req->shared_secret,
+@@ -939,6 +932,13 @@ static void radius_client_receive(int sock, void *eloop_ctx, void *sock_ctx)
+ radius_msg_free(msg);
+ /* fall through */
+ case RADIUS_RX_QUEUED:
++ /* Remove ACKed RADIUS packet from retransmit list */
++ if (prev_req)
++ prev_req->next = req->next;
++ else
++ radius->msgs = req->next;
++ radius->num_msgs--;
++
+ radius_client_msg_free(req);
+ return;
+ case RADIUS_RX_INVALID_AUTHENTICATOR:
+@@ -960,7 +960,6 @@ static void radius_client_receive(int sock, void *eloop_ctx, void *sock_ctx)
+ msg_type, hdr->code, hdr->identifier,
+ invalid_authenticator ? " [INVALID AUTHENTICATOR]" :
+ "");
+- radius_client_msg_free(req);
+
+ fail:
+ radius_msg_free(msg);
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2025-24912_02.patch b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2025-24912_02.patch
new file mode 100644
index 0000000000..28c0fa61ea
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2025-24912_02.patch
@@ -0,0 +1,72 @@
+From fe4d203a300e1eaa1ad7c7bc49e01b9490ab03d8 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <quic_jouni@quicinc.com>
+Date: Wed, 5 Feb 2025 19:23:39 +0200
+Subject: [PATCH] RADIUS: Fix pending request dropping
+
+A recent change to this moved the place where the processed RADIUS
+request was removed from the pending list to happen after the message
+handler had been called. This did not take into account possibility of
+the handler adding a new pending request in the list and the prev_req
+pointer not necessarily pointing to the correct entry anymore. As such,
+some of the pending requests could have been lost and that would result
+in not being able to process responses to those requests and also, to a
+memory leak.
+
+Fix this by determining prev_req at the point when the pending request
+is being removed, i.e., after the handler function has already added a
+new entry.
+
+Fixes: 726432d7622c ("RADIUS: Drop pending request only when accepting the response")
+
+CVE: CVE-2025-24912
+Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=339a334551ca911187cc870f4f97ef08e11db109]
+
+Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
+(cherry picked from commit 339a334551ca911187cc870f4f97ef08e11db109)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/radius/radius_client.c | 10 +++++++---
+ 1 file changed, 7 insertions(+), 3 deletions(-)
+
+diff --git a/src/radius/radius_client.c b/src/radius/radius_client.c
+index 8f9332583..a5a6cdfae 100644
+--- a/src/radius/radius_client.c
++++ b/src/radius/radius_client.c
+@@ -824,7 +824,7 @@ static void radius_client_receive(int sock, void *eloop_ctx, void *sock_ctx)
+ struct radius_hdr *hdr;
+ struct radius_rx_handler *handlers;
+ size_t num_handlers, i;
+- struct radius_msg_list *req, *prev_req;
++ struct radius_msg_list *req, *prev_req, *r;
+ struct os_reltime now;
+ struct hostapd_radius_server *rconf;
+ int invalid_authenticator = 0;
+@@ -887,7 +887,6 @@ static void radius_client_receive(int sock, void *eloop_ctx, void *sock_ctx)
+ break;
+ }
+
+- prev_req = NULL;
+ req = radius->msgs;
+ while (req) {
+ /* TODO: also match by src addr:port of the packet when using
+@@ -899,7 +898,6 @@ static void radius_client_receive(int sock, void *eloop_ctx, void *sock_ctx)
+ hdr->identifier)
+ break;
+
+- prev_req = req;
+ req = req->next;
+ }
+
+@@ -933,6 +931,12 @@ static void radius_client_receive(int sock, void *eloop_ctx, void *sock_ctx)
+ /* fall through */
+ case RADIUS_RX_QUEUED:
+ /* Remove ACKed RADIUS packet from retransmit list */
++ prev_req = NULL;
++ for (r = radius->msgs; r; r = r->next) {
++ if (r == req)
++ break;
++ prev_req = r;
++ }
+ if (prev_req)
+ prev_req->next = req->next;
+ else
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd_2.10.bb b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd_2.10.bb
index dbdc5c1bdf..0e241e48b0 100644
--- a/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd_2.10.bb
+++ b/meta-openembedded/meta-oe/recipes-connectivity/hostapd/hostapd_2.10.bb
@@ -2,7 +2,7 @@ SUMMARY = "User space daemon for extended IEEE 802.11 management"
HOMEPAGE = "http://w1.fi/hostapd/"
SECTION = "kernel/userland"
LICENSE = "BSD-3-Clause"
-LIC_FILES_CHKSUM = "file://hostapd/README;md5=c905478466c90f1cefc0df987c40e172"
+LIC_FILES_CHKSUM = "file://hostapd/README;beginline=5;endline=47;md5=aa03b8bd6216d1a7ca01fd4b89863073"
DEPENDS = "libnl openssl"
@@ -11,14 +11,24 @@ SRC_URI = " \
file://defconfig \
file://init \
file://hostapd.service \
+ file://CVE-2024-3596_00.patch \
+ file://CVE-2024-3596_01.patch \
+ file://CVE-2024-3596_02.patch \
+ file://CVE-2024-3596_04.patch \
+ file://CVE-2024-3596_05.patch \
+ file://CVE-2024-3596_06.patch \
+ file://CVE-2024-3596_07.patch \
+ file://CVE-2024-3596_08.patch \
+ file://0001-SAE-Check-for-invalid-Rejected-Groups-element-length.patch \
+ file://0003-SAE-Reject-invalid-Rejected-Groups-element-in-the-pa.patch \
+ file://CVE-2023-52160.patch \
+ file://CVE-2025-24912_01.patch \
+ file://CVE-2025-24912_02.patch \
"
SRC_URI[sha256sum] = "206e7c799b678572c2e3d12030238784bc4a9f82323b0156b4c9466f1498915d"
-S = "${WORKDIR}/hostapd-${PV}"
-B = "${WORKDIR}/hostapd-${PV}/hostapd"
-
inherit update-rc.d systemd pkgconfig features_check
CONFLICT_DISTRO_FEATURES = "openssl-no-weak-ciphers"
@@ -29,20 +39,20 @@ SYSTEMD_SERVICE:${PN} = "hostapd.service"
SYSTEMD_AUTO_ENABLE:${PN} = "disable"
do_configure:append() {
- install -m 0644 ${WORKDIR}/defconfig ${B}/.config
+ install -m 0644 ${WORKDIR}/defconfig ${B}/hostapd/.config
}
do_compile() {
export CFLAGS="-MMD -O2 -Wall -g"
export EXTRA_CFLAGS="${CFLAGS}"
- make V=1
+ make -C hostapd V=1
}
do_install() {
install -d ${D}${sbindir} ${D}${sysconfdir}/init.d ${D}${systemd_unitdir}/system/
- install -m 0644 ${B}/hostapd.conf ${D}${sysconfdir}
- install -m 0755 ${B}/hostapd ${D}${sbindir}
- install -m 0755 ${B}/hostapd_cli ${D}${sbindir}
+ install -m 0644 ${B}/hostapd/hostapd.conf ${D}${sysconfdir}
+ install -m 0755 ${B}/hostapd/hostapd ${D}${sbindir}
+ install -m 0755 ${B}/hostapd/hostapd_cli ${D}${sbindir}
install -m 755 ${WORKDIR}/init ${D}${sysconfdir}/init.d/hostapd
install -m 0644 ${WORKDIR}/hostapd.service ${D}${systemd_unitdir}/system/
sed -i -e 's,@SBINDIR@,${sbindir},g' -e 's,@SYSCONFDIR@,${sysconfdir},g' ${D}${systemd_unitdir}/system/hostapd.service
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/krb5/krb5/CVE-2024-26458_CVE-2024-26461.patch b/meta-openembedded/meta-oe/recipes-connectivity/krb5/krb5/CVE-2024-26458_CVE-2024-26461.patch
new file mode 100644
index 0000000000..46eb6aa96c
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/krb5/krb5/CVE-2024-26458_CVE-2024-26461.patch
@@ -0,0 +1,207 @@
+From c5f9c816107f70139de11b38aa02db2f1774ee0d Mon Sep 17 00:00:00 2001
+From: Greg Hudson <ghudson@mit.edu>
+Date: Tue, 5 Mar 2024 19:53:07 -0500
+Subject: [PATCH] Fix two unlikely memory leaks
+
+In gss_krb5int_make_seal_token_v3(), one of the bounds checks (which
+could probably never be triggered) leaks plain.data. Fix this leak
+and use current practices for cleanup throughout the function.
+
+In xmt_rmtcallres() (unused within the tree and likely elsewhere),
+store port_ptr into crp->port_ptr as soon as it is allocated;
+otherwise it could leak if the subsequent xdr_u_int32() operation
+fails.
+
+CVE: CVE-2024-26458 CVE-2024-26461
+Upstream-Status: Backport [https://github.com/krb5/krb5/commit/c5f9c816107f70139de11b38aa02db2f1774ee0d]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ src/lib/gssapi/krb5/k5sealv3.c | 56 +++++++++++++++-------------------
+ src/lib/rpc/pmap_rmt.c | 9 +++---
+ 2 files changed, 29 insertions(+), 36 deletions(-)
+
+diff --git a/src/lib/gssapi/krb5/k5sealv3.c b/src/lib/gssapi/krb5/k5sealv3.c
+index 1fcbdfb..d3210c1 100644
+--- a/src/lib/gssapi/krb5/k5sealv3.c
++++ b/src/lib/gssapi/krb5/k5sealv3.c
+@@ -65,7 +65,7 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
+ int conf_req_flag, int toktype)
+ {
+ size_t bufsize = 16;
+- unsigned char *outbuf = 0;
++ unsigned char *outbuf = NULL;
+ krb5_error_code err;
+ int key_usage;
+ unsigned char acceptor_flag;
+@@ -75,9 +75,13 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
+ #endif
+ size_t ec;
+ unsigned short tok_id;
+- krb5_checksum sum;
++ krb5_checksum sum = { 0 };
+ krb5_key key;
+ krb5_cksumtype cksumtype;
++ krb5_data plain = empty_data();
++
++ token->value = NULL;
++ token->length = 0;
+
+ acceptor_flag = ctx->initiate ? 0 : FLAG_SENDER_IS_ACCEPTOR;
+ key_usage = (toktype == KG_TOK_WRAP_MSG
+@@ -107,14 +111,15 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
+ #endif
+
+ if (toktype == KG_TOK_WRAP_MSG && conf_req_flag) {
+- krb5_data plain;
+ krb5_enc_data cipher;
+ size_t ec_max;
+ size_t encrypt_size;
+
+ /* 300: Adds some slop. */
+- if (SIZE_MAX - 300 < message->length)
+- return ENOMEM;
++ if (SIZE_MAX - 300 < message->length) {
++ err = ENOMEM;
++ goto cleanup;
++ }
+ ec_max = SIZE_MAX - message->length - 300;
+ if (ec_max > 0xffff)
+ ec_max = 0xffff;
+@@ -126,20 +131,20 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
+ #endif
+ err = alloc_data(&plain, message->length + 16 + ec);
+ if (err)
+- return err;
++ goto cleanup;
+
+ /* Get size of ciphertext. */
+ encrypt_size = krb5_encrypt_size(plain.length, key->keyblock.enctype);
+ if (encrypt_size > SIZE_MAX / 2) {
+ err = ENOMEM;
+- goto error;
++ goto cleanup;
+ }
+ bufsize = 16 + encrypt_size;
+ /* Allocate space for header plus encrypted data. */
+ outbuf = gssalloc_malloc(bufsize);
+ if (outbuf == NULL) {
+- free(plain.data);
+- return ENOMEM;
++ err = ENOMEM;
++ goto cleanup;
+ }
+
+ /* TOK_ID */
+@@ -164,11 +169,8 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
+ cipher.ciphertext.length = bufsize - 16;
+ cipher.enctype = key->keyblock.enctype;
+ err = krb5_k_encrypt(context, key, key_usage, 0, &plain, &cipher);
+- zap(plain.data, plain.length);
+- free(plain.data);
+- plain.data = 0;
+ if (err)
+- goto error;
++ goto cleanup;
+
+ /* Now that we know we're returning a valid token.... */
+ ctx->seq_send++;
+@@ -181,7 +183,6 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
+ /* If the rotate fails, don't worry about it. */
+ #endif
+ } else if (toktype == KG_TOK_WRAP_MSG && !conf_req_flag) {
+- krb5_data plain;
+ size_t cksumsize;
+
+ /* Here, message is the application-supplied data; message2 is
+@@ -193,21 +194,19 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
+ wrap_with_checksum:
+ err = alloc_data(&plain, message->length + 16);
+ if (err)
+- return err;
++ goto cleanup;
+
+ err = krb5_c_checksum_length(context, cksumtype, &cksumsize);
+ if (err)
+- goto error;
++ goto cleanup;
+
+ assert(cksumsize <= 0xffff);
+
+ bufsize = 16 + message2->length + cksumsize;
+ outbuf = gssalloc_malloc(bufsize);
+ if (outbuf == NULL) {
+- free(plain.data);
+- plain.data = 0;
+ err = ENOMEM;
+- goto error;
++ goto cleanup;
+ }
+
+ /* TOK_ID */
+@@ -239,23 +238,15 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
+ if (message2->length)
+ memcpy(outbuf + 16, message2->value, message2->length);
+
+- sum.contents = outbuf + 16 + message2->length;
+- sum.length = cksumsize;
+-
+ err = krb5_k_make_checksum(context, cksumtype, key,
+ key_usage, &plain, &sum);
+- zap(plain.data, plain.length);
+- free(plain.data);
+- plain.data = 0;
+ if (err) {
+ zap(outbuf,bufsize);
+- goto error;
++ goto cleanup;
+ }
+ if (sum.length != cksumsize)
+ abort();
+ memcpy(outbuf + 16 + message2->length, sum.contents, cksumsize);
+- krb5_free_checksum_contents(context, &sum);
+- sum.contents = 0;
+ /* Now that we know we're actually generating the token... */
+ ctx->seq_send++;
+
+@@ -285,12 +276,13 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
+
+ token->value = outbuf;
+ token->length = bufsize;
+- return 0;
++ outbuf = NULL;
++ err = 0;
+
+-error:
++cleanup:
++ krb5_free_checksum_contents(context, &sum);
++ zapfree(plain.data, plain.length);
+ gssalloc_free(outbuf);
+- token->value = NULL;
+- token->length = 0;
+ return err;
+ }
+
+diff --git a/src/lib/rpc/pmap_rmt.c b/src/lib/rpc/pmap_rmt.c
+index 8c7e30c..522cb20 100644
+--- a/src/lib/rpc/pmap_rmt.c
++++ b/src/lib/rpc/pmap_rmt.c
+@@ -160,11 +160,12 @@ xdr_rmtcallres(
+ caddr_t port_ptr;
+
+ port_ptr = (caddr_t)(void *)crp->port_ptr;
+- if (xdr_reference(xdrs, &port_ptr, sizeof (uint32_t),
+- xdr_u_int32) && xdr_u_int32(xdrs, &crp->resultslen)) {
+- crp->port_ptr = (uint32_t *)(void *)port_ptr;
++ if (!xdr_reference(xdrs, &port_ptr, sizeof (uint32_t),
++ (xdrproc_t)xdr_u_int32))
++ return (FALSE);
++ crp->port_ptr = (uint32_t *)(void *)port_ptr;
++ if (xdr_u_int32(xdrs, &crp->resultslen))
+ return ((*(crp->xdr_results))(xdrs, crp->results_ptr));
+- }
+ return (FALSE);
+ }
+
+--
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/krb5/krb5/CVE-2025-24528.patch b/meta-openembedded/meta-oe/recipes-connectivity/krb5/krb5/CVE-2025-24528.patch
new file mode 100644
index 0000000000..ac6039edf1
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/krb5/krb5/CVE-2025-24528.patch
@@ -0,0 +1,68 @@
+From 78ceba024b64d49612375be4a12d1c066b0bfbd0 Mon Sep 17 00:00:00 2001
+From: Zoltan Borbely <Zoltan.Borbely@morganstanley.com>
+Date: Tue, 28 Jan 2025 16:39:25 -0500
+Subject: [PATCH] Prevent overflow when calculating ulog block size
+
+In kdb_log.c:resize(), log an error and fail if the update size is
+larger than the largest possible block size (2^16-1).
+
+CVE-2025-24528:
+
+In MIT krb5 release 1.7 and later with incremental propagation
+enabled, an authenticated attacker can cause kadmind to write beyond
+the end of the mapped region for the iprop log file, likely causing a
+process crash.
+
+[ghudson@mit.edu: edited commit message and added CVE description]
+
+ticket: 9159 (new)
+tags: pullup
+target_version: 1.21-next
+
+CVE: CVE-2025-24528
+
+Upstream-Status: Backport [https://github.com/krb5/krb5/commit/78ceba024b64d49612375be4a12d1c066b0bfbd0]
+
+Signed-off-by: Divya Chellam <divya.chellam@windriver.com>
+---
+ src/lib/kdb/kdb_log.c | 10 ++++++++--
+ 1 file changed, 8 insertions(+), 2 deletions(-)
+
+diff --git a/src/lib/kdb/kdb_log.c b/src/lib/kdb/kdb_log.c
+index 2659a25..68fae91 100644
+--- a/src/lib/kdb/kdb_log.c
++++ b/src/lib/kdb/kdb_log.c
+@@ -183,7 +183,7 @@ extend_file_to(int fd, unsigned int new_size)
+ */
+ static krb5_error_code
+ resize(kdb_hlog_t *ulog, uint32_t ulogentries, int ulogfd,
+- unsigned int recsize)
++ unsigned int recsize, const kdb_incr_update_t *upd)
+ {
+ unsigned int new_block, new_size;
+
+@@ -195,6 +195,12 @@ resize(kdb_hlog_t *ulog, uint32_t ulogentries, int ulogfd,
+ new_block *= ULOG_BLOCK;
+ new_size += ulogentries * new_block;
+
++ if (new_block > UINT16_MAX) {
++ syslog(LOG_ERR, _("ulog overflow caused by principal %.*s"),
++ upd->kdb_princ_name.utf8str_t_len,
++ upd->kdb_princ_name.utf8str_t_val);
++ return KRB5_LOG_ERROR;
++ }
+ if (new_size > MAXLOGLEN)
+ return KRB5_LOG_ERROR;
+
+@@ -291,7 +297,7 @@ store_update(kdb_log_context *log_ctx, kdb_incr_update_t *upd)
+ recsize = sizeof(kdb_ent_header_t) + upd_size;
+
+ if (recsize > ulog->kdb_block) {
+- retval = resize(ulog, ulogentries, log_ctx->ulogfd, recsize);
++ retval = resize(ulog, ulogentries, log_ctx->ulogfd, recsize, upd);
+ if (retval)
+ return retval;
+ }
+--
+2.40.0
+
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/krb5/krb5_1.21.2.bb b/meta-openembedded/meta-oe/recipes-connectivity/krb5/krb5_1.21.3.bb
index 7af33e4e7e..4742fe47b2 100644
--- a/meta-openembedded/meta-oe/recipes-connectivity/krb5/krb5_1.21.2.bb
+++ b/meta-openembedded/meta-oe/recipes-connectivity/krb5/krb5_1.21.3.bb
@@ -14,7 +14,7 @@ DESCRIPTION = "Kerberos is a system for authenticating users and services on a n
HOMEPAGE = "http://web.mit.edu/Kerberos/"
SECTION = "console/network"
LICENSE = "MIT"
-LIC_FILES_CHKSUM = "file://${S}/../NOTICE;md5=32cb3a99207053d9f5c1ef177c4d6e34"
+LIC_FILES_CHKSUM = "file://${S}/../NOTICE;md5=71c06694263581762668e88b7b77a1a5"
inherit autotools-brokensep binconfig perlnative systemd update-rc.d pkgconfig
@@ -28,9 +28,11 @@ SRC_URI = "http://web.mit.edu/kerberos/dist/${BPN}/${SHRT_VER}/${BP}.tar.gz \
file://etc/default/krb5-admin-server \
file://krb5-kdc.service \
file://krb5-admin-server.service \
+ file://CVE-2024-26458_CVE-2024-26461.patch;striplevel=2 \
+ file://CVE-2025-24528.patch;striplevel=2 \
"
-SRC_URI[sha256sum] = "9560941a9d843c0243a71b17a7ac6fe31c7cebb5bce3983db79e52ae7e850491"
+SRC_URI[sha256sum] = "b7a4cd5ead67fb08b980b21abd150ff7217e85ea320c9ed0c6dadd304840ad35"
CVE_PRODUCT = "kerberos"
CVE_VERSION = "5-${PV}"
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/libndp/libndp/CVE-2024-5564.patch b/meta-openembedded/meta-oe/recipes-connectivity/libndp/libndp/CVE-2024-5564.patch
new file mode 100644
index 0000000000..fe7ce41b87
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/libndp/libndp/CVE-2024-5564.patch
@@ -0,0 +1,48 @@
+From 05e4ba7b0d126eea4c04387dcf40596059ee24af Mon Sep 17 00:00:00 2001
+From: Hangbin Liu <liuhangbin@gmail.com>
+Date: Wed, 5 Jun 2024 11:57:43 +0800
+Subject: [PATCH] libndp: valid route information option length
+
+RFC 4191 specifies that the Route Information Option Length should be 1, 2,
+or 3, depending on the Prefix Length. A malicious node could potentially
+trigger a buffer overflow and crash the tool by sending an IPv6 router
+advertisement message containing the "Route Information" option with a
+"Length" field larger than 3.
+
+To address this, add a check on the length field.
+
+Fixes: 8296a5bf0755 ("add support for Route Information Option (rfc4191)")
+Reported-by: Evgeny Vereshchagin <evverx@gmail.com>
+Suggested-by: Felix Maurer <fmaurer@redhat.com>
+Signed-off-by: Hangbin Liu <liuhangbin@gmail.com>
+Signed-off-by: Jiri Pirko <jiri@nvidia.com>
+
+CVE: CVE-2024-5564
+Upstream-Status: Backport [https://github.com/jpirko/libndp/commit/05e4ba7b0d126eea4c04387dcf40596059ee24af]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ libndp/libndp.c | 11 +++++++++++
+ 1 file changed, 11 insertions(+)
+
+diff --git a/libndp/libndp.c b/libndp/libndp.c
+index 6314717..72ec92e 100644
+--- a/libndp/libndp.c
++++ b/libndp/libndp.c
+@@ -1231,6 +1231,17 @@ static bool ndp_msg_opt_route_check_valid(void *opt_data)
+ */
+ if (((ri->nd_opt_ri_prf_reserved >> 3) & 3) == 2)
+ return false;
++
++ /* The Length field is 1, 2, or 3 depending on the Prefix Length.
++ * If Prefix Length is greater than 64, then Length must be 3.
++ * If Prefix Length is greater than 0, then Length must be 2 or 3.
++ * If Prefix Length is zero, then Length must be 1, 2, or 3.
++ */
++ if (ri->nd_opt_ri_len > 3 ||
++ (ri->nd_opt_ri_prefix_len > 64 && ri->nd_opt_ri_len != 3) ||
++ (ri->nd_opt_ri_prefix_len > 0 && ri->nd_opt_ri_len == 1))
++ return false;
++
+ return true;
+ }
+
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/libndp/libndp_1.8.bb b/meta-openembedded/meta-oe/recipes-connectivity/libndp/libndp_1.8.bb
index 4d4d3e51cd..70d6abec1b 100644
--- a/meta-openembedded/meta-oe/recipes-connectivity/libndp/libndp_1.8.bb
+++ b/meta-openembedded/meta-oe/recipes-connectivity/libndp/libndp_1.8.bb
@@ -4,6 +4,7 @@ LICENSE = "LGPL-2.1-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=4fbd65380cdd255951079008b364516c"
SRC_URI = "git://github.com/jpirko/libndp;branch=master;protocol=https \
+ file://CVE-2024-5564.patch \
"
# tag for v1.8
SRCREV = "009ce9cd9b950ffa1f4f94c9436027b936850d0c"
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/linuxptp/linuxptp/systemd/phc2sys@.service.in b/meta-openembedded/meta-oe/recipes-connectivity/linuxptp/linuxptp/systemd/phc2sys@.service.in
index f66dd2d010..7d1d975ea3 100644
--- a/meta-openembedded/meta-oe/recipes-connectivity/linuxptp/linuxptp/systemd/phc2sys@.service.in
+++ b/meta-openembedded/meta-oe/recipes-connectivity/linuxptp/linuxptp/systemd/phc2sys@.service.in
@@ -1,8 +1,8 @@
[Unit]
Description=Synchronize system clock or PTP hardware clock (PHC)
Documentation=man:phc2sys
-Requires=ptp4l.service
-After=ptp4l.service
+Requires=ptp4l@%i.service
+After=ptp4l@%i.service
Before=time-sync.target
[Service]
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/mosh/mosh_1.4.0.bb b/meta-openembedded/meta-oe/recipes-connectivity/mosh/mosh_1.4.0.bb
index 693ec12d3c..62fb5444a4 100644
--- a/meta-openembedded/meta-oe/recipes-connectivity/mosh/mosh_1.4.0.bb
+++ b/meta-openembedded/meta-oe/recipes-connectivity/mosh/mosh_1.4.0.bb
@@ -14,13 +14,14 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=d32239bcb673463ab874e80d47fae504"
DEPENDS = "protobuf-native protobuf ncurses zlib libio-pty-perl openssl libutempter abseil-cpp"
-SRC_URI = "https://mosh.org/${BP}.tar.gz \
+GITHUB_BASE_URI = "https://github.com/mobile-shell/${BPN}/releases/"
+SRC_URI = "${GITHUB_BASE_URI}download/${BP}/${BP}.tar.gz \
file://0001-configure.ac-add-support-of-protobuf-4.22.x.patch \
"
SRC_URI[sha256sum] = "872e4b134e5df29c8933dff12350785054d2fd2839b5ae6b5587b14db1465ddd"
-inherit autotools pkgconfig
+inherit autotools pkgconfig github-releases
PACKAGE_BEFORE_PN += "${PN}-server"
FILES:${PN}-server = "${bindir}/mosh-server"
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/thrift/thrift/0001-THRIFT-5842-Add-missing-cstdint-include-for-int64_t-.patch b/meta-openembedded/meta-oe/recipes-connectivity/thrift/thrift/0001-THRIFT-5842-Add-missing-cstdint-include-for-int64_t-.patch
new file mode 100644
index 0000000000..c5a56338a3
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/thrift/thrift/0001-THRIFT-5842-Add-missing-cstdint-include-for-int64_t-.patch
@@ -0,0 +1,51 @@
+From 949cf4dc8973b39138cf89ce817b714d3bcce6eb Mon Sep 17 00:00:00 2001
+From: Sutou Kouhei <kou@clear-code.com>
+Date: Mon, 23 Dec 2024 12:33:22 +0900
+Subject: [PATCH] THRIFT-5842: Add missing cstdint include for int64_t in
+ Mutex.h
+
+Client: cpp
+
+GCC 15 (not released yet) requires `#include <cstdint>` for `int64_t`
+but `lib/cpp/src/thrift/concurrency/Mutex.h` doesn't have it. So we
+can't build Thrift with GCC 15:
+
+ [80/359] Building CXX object lib/cpp/CMakeFiles/thrift.dir/src/thrift/transport/TSSLServerSocket.cpp.o
+ FAILED: lib/cpp/CMakeFiles/thrift.dir/src/thrift/transport/TSSLServerSocket.cpp.o
+ /bin/g++-15 -DBOOST_ALL_DYN_LINK -DBOOST_TEST_DYN_LINK -DTHRIFT_STATIC_DEFINE -D__STDC_FORMAT_MACROS -D__STDC_LIMIT_MACROS -I/home/kou/work/cpp/thrift.kou.build/lib/cpp -I/home/kou/work/cpp/thrift.kou/lib/cpp -I/home/kou/work/cpp/thrift.kou.build -I/home/kou/work/cpp/thrift.kou/lib/cpp/src -g -std=c++11 -MD -MT lib/cpp/CMakeFiles/thrift.dir/src/thrift/transport/TSSLServerSocket.cpp.o -MF lib/cpp/CMakeFiles/thrift.dir/src/thrift/transport/TSSLServerSocket.cpp.o.d -o lib/cpp/CMakeFiles/thrift.dir/src/thrift/transport/TSSLServerSocket.cpp.o -c /home/kou/work/cpp/thrift.kou/lib/cpp/src/thrift/transport/TSSLServerSocket.cpp
+ In file included from /home/kou/work/cpp/thrift.kou/lib/cpp/src/thrift/transport/TServerSocket.h:25,
+ from /home/kou/work/cpp/thrift.kou/lib/cpp/src/thrift/transport/TSSLServerSocket.h:23,
+ from /home/kou/work/cpp/thrift.kou/lib/cpp/src/thrift/transport/TSSLServerSocket.cpp:21:
+ /home/kou/work/cpp/thrift.kou/lib/cpp/src/thrift/concurrency/Mutex.h:47:26: error: 'int64_t' has not been declared
+ 47 | virtual bool timedlock(int64_t milliseconds) const;
+ | ^~~~~~~
+ /home/kou/work/cpp/thrift.kou/lib/cpp/src/thrift/concurrency/Mutex.h:25:1: note: 'int64_t' is defined in header '<cstdint>'; this is probably fixable by adding '#include <cstdint>'
+ 24 | #include <thrift/TNonCopyable.h>
+ +++ |+#include <cstdint>
+ 25 |
+ /home/kou/work/cpp/thrift.kou/lib/cpp/src/thrift/concurrency/Mutex.h:60:29: error: 'int64_t' has not been declared
+ 60 | Guard(const Mutex& value, int64_t timeout = 0) : mutex_(&value) {
+ | ^~~~~~~
+ /home/kou/work/cpp/thrift.kou/lib/cpp/src/thrift/concurrency/Mutex.h:60:29: note: 'int64_t' is defined in header '<cstdint>'; this is probably fixable by adding '#include <cstdint>'
+
+See also: https://github.com/apache/arrow/issues/45096
+
+Upstream-Status: Backport [https://github.com/apache/thrift/pull/3078]
+
+Signed-off-by: Adrian Freihofer <adrian.freihofer@siemens.com>
+---
+ lib/cpp/src/thrift/concurrency/Mutex.h | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/lib/cpp/src/thrift/concurrency/Mutex.h b/lib/cpp/src/thrift/concurrency/Mutex.h
+index 1e5c3fba3..12f1729d6 100644
+--- a/lib/cpp/src/thrift/concurrency/Mutex.h
++++ b/lib/cpp/src/thrift/concurrency/Mutex.h
+@@ -20,6 +20,7 @@
+ #ifndef _THRIFT_CONCURRENCY_MUTEX_H_
+ #define _THRIFT_CONCURRENCY_MUTEX_H_ 1
+
++#include <cstdint>
+ #include <memory>
+ #include <thrift/TNonCopyable.h>
+
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/thrift/thrift/0001-thrift-pr2755.patch b/meta-openembedded/meta-oe/recipes-connectivity/thrift/thrift/0001-thrift-pr2755.patch
new file mode 100644
index 0000000000..b685d42728
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-connectivity/thrift/thrift/0001-thrift-pr2755.patch
@@ -0,0 +1,599 @@
+From f02ac2fb573bed72e9a2d1875807c6ff7ac19ec8 Mon Sep 17 00:00:00 2001
+From: Lukas Barth <mail@tinloaf.de>
+Date: Wed, 8 Feb 2023 09:33:03 +0100
+Subject: [PATCH 1/5] Move default constructor and operator== implementation to
+ CPP file
+
+Both the default constructor and operator== implementations reference
+certain member functions of the class' members. As an example, the default
+constructor references (i.e., "uses") the default constructors of its
+members.
+
+If a class contains a std::vector<Foo>, and Foo has only been *forward*-
+declared (which happens often in Thrift-generated code), this creates
+undefined behavior: The std::vector specification states that as long as
+Foo is an incomplete type, it is fine to reference std::vector<Foo>, but
+not any members (such as its default constructor).
+
+Thus, we must defer our default constructor's implementation (which references
+the default constructor of std::vector<Foo>) to a point where Foo is a
+complete type. That is the case in the .cpp file.
+
+The same holds for operator==.
+
+Upstream-Status: Backport [https://github.com/apache/thrift/pull/2755]
+
+Signed-off-by: Stanislav Angelovic <stanislav.angelovic.ext@siemens.com>
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ .../src/thrift/generate/t_cpp_generator.cc | 187 +++++++++++-------
+ 1 file changed, 121 insertions(+), 66 deletions(-)
+
+diff --git a/compiler/cpp/src/thrift/generate/t_cpp_generator.cc b/compiler/cpp/src/thrift/generate/t_cpp_generator.cc
+index 9724fae80..fecfa4bb5 100644
+--- a/compiler/cpp/src/thrift/generate/t_cpp_generator.cc
++++ b/compiler/cpp/src/thrift/generate/t_cpp_generator.cc
+@@ -146,11 +146,13 @@ public:
+ bool is_user_struct = false);
+ void generate_copy_constructor(std::ostream& out, t_struct* tstruct, bool is_exception);
+ void generate_move_constructor(std::ostream& out, t_struct* tstruct, bool is_exception);
++ void generate_default_constructor(std::ostream& out, t_struct* tstruct, bool is_exception);
+ void generate_constructor_helper(std::ostream& out,
+ t_struct* tstruct,
+ bool is_excpetion,
+ bool is_move);
+ void generate_assignment_operator(std::ostream& out, t_struct* tstruct);
++ void generate_equality_operator(std::ostream& out, t_struct* tstruct);
+ void generate_move_assignment_operator(std::ostream& out, t_struct* tstruct);
+ void generate_assignment_helper(std::ostream& out, t_struct* tstruct, bool is_move);
+ void generate_struct_reader(std::ostream& out, t_struct* tstruct, bool pointers = false);
+@@ -914,6 +916,10 @@ void t_cpp_generator::generate_cpp_struct(t_struct* tstruct, bool is_exception)
+ generate_struct_reader(out, tstruct);
+ generate_struct_writer(out, tstruct);
+ generate_struct_swap(f_types_impl_, tstruct);
++ if (!gen_no_default_operators_) {
++ generate_equality_operator(f_types_impl_, tstruct);
++ }
++ generate_default_constructor(f_types_impl_, tstruct, is_exception);
+ generate_copy_constructor(f_types_impl_, tstruct, is_exception);
+ if (gen_moveable_) {
+ generate_move_constructor(f_types_impl_, tstruct, is_exception);
+@@ -934,6 +940,117 @@ void t_cpp_generator::generate_cpp_struct(t_struct* tstruct, bool is_exception)
+ has_members_ = true;
+ }
+
++void t_cpp_generator::generate_equality_operator(std::ostream& out, t_struct* tstruct) {
++ // Get members
++ vector<t_field*>::const_iterator m_iter;
++ const vector<t_field*>& members = tstruct->get_members();
++
++ out << indent() << "bool " << tstruct->get_name()
++ << "::operator==(const " << tstruct->get_name() << " & "
++ << (members.size() > 0 ? "rhs" : "/* rhs */") << ") const" << endl;
++ scope_up(out);
++ for (m_iter = members.begin(); m_iter != members.end(); ++m_iter) {
++ // Most existing Thrift code does not use isset or optional/required,
++ // so we treat "default" fields as required.
++ if ((*m_iter)->get_req() != t_field::T_OPTIONAL) {
++ out << indent() << "if (!(" << (*m_iter)->get_name() << " == rhs."
++ << (*m_iter)->get_name() << "))" << endl << indent() << " return false;" << endl;
++ } else {
++ out << indent() << "if (__isset." << (*m_iter)->get_name() << " != rhs.__isset."
++ << (*m_iter)->get_name() << ")" << endl << indent() << " return false;" << endl
++ << indent() << "else if (__isset." << (*m_iter)->get_name() << " && !("
++ << (*m_iter)->get_name() << " == rhs." << (*m_iter)->get_name() << "))" << endl
++ << indent() << " return false;" << endl;
++ }
++ }
++ indent(out) << "return true;" << endl;
++ scope_down(out);
++ out << "\n";
++}
++
++void t_cpp_generator::generate_default_constructor(ostream& out,
++ t_struct* tstruct,
++ bool is_exception) {
++ // Get members
++ vector<t_field*>::const_iterator m_iter;
++ const vector<t_field*>& members = tstruct->get_members();
++
++ // TODO(barth) this is duplicated from generate_struct_declaration
++ bool has_default_value = false;
++ for (m_iter = members.begin(); m_iter != members.end(); ++m_iter) {
++ t_type* t = get_true_type((*m_iter)->get_type());
++ if (is_reference(*m_iter) || t->is_string()) {
++ t_const_value* cv = (*m_iter)->get_value();
++ if (cv != nullptr) {
++ has_default_value = true;
++ break;
++ }
++ }
++ }
++
++ std::string clsname_ctor = tstruct->get_name() + "::" + tstruct->get_name() + "()";
++ indent(out) << clsname_ctor << (has_default_value ? "" : " noexcept");
++
++ if (has_default_value || is_exception) {
++ // We need an initializer block
++
++ bool init_ctor = false;
++ std::string args_indent(" ");
++
++ // Default-initialize TException, if it is our base type
++ if (is_exception)
++ {
++ out << "\n";
++ indent(out) << " : ";
++ out << "TException()";
++ init_ctor = true;
++ }
++
++ // Default-initialize all members that should be initialized in
++ // the initializer block
++ for (m_iter = members.begin(); m_iter != members.end(); ++m_iter) {
++ t_type* t = get_true_type((*m_iter)->get_type());
++ if (t->is_base_type() || t->is_enum() || is_reference(*m_iter)) {
++ string dval;
++ t_const_value* cv = (*m_iter)->get_value();
++ if (cv != nullptr) {
++ dval += render_const_value(out, (*m_iter)->get_name(), t, cv);
++ } else if (t->is_enum()) {
++ dval += "static_cast<" + type_name(t) + ">(0)";
++ } else {
++ dval += (t->is_string() || is_reference(*m_iter)) ? "" : "0";
++ }
++ if (!init_ctor) {
++ out << "\n";
++ indent(out) << " : ";
++ init_ctor = true;
++ } else {
++ out << ",\n";
++ indent(out) << args_indent;
++ }
++
++ out << (*m_iter)->get_name() << "(" << dval << ")";
++ }
++ }
++ out << " {" << endl;
++ indent_up();
++ // TODO(dreiss): When everything else in Thrift is perfect,
++ // do more of these in the initializer list.
++ for (m_iter = members.begin(); m_iter != members.end(); ++m_iter) {
++ t_type* t = get_true_type((*m_iter)->get_type());
++ if (!t->is_base_type() && !t->is_enum() && !is_reference(*m_iter)) {
++ t_const_value* cv = (*m_iter)->get_value();
++ if (cv != nullptr) {
++ print_const_value(out, (*m_iter)->get_name(), t, cv);
++ }
++ }
++ }
++ scope_down(out);
++ } else {
++ out << " {}\n";
++ }
++}
++
+ void t_cpp_generator::generate_copy_constructor(ostream& out,
+ t_struct* tstruct,
+ bool is_exception) {
+@@ -1168,52 +1285,7 @@ void t_cpp_generator::generate_struct_declaration(ostream& out,
+
+ // Default constructor
+ std::string clsname_ctor = tstruct->get_name() + "()";
+- indent(out) << clsname_ctor << (has_default_value ? "" : " noexcept");
+-
+- bool init_ctor = false;
+- std::string args_indent(
+- indent().size() + clsname_ctor.size() + (has_default_value ? 3 : -1), ' ');
+-
+- for (m_iter = members.begin(); m_iter != members.end(); ++m_iter) {
+- t_type* t = get_true_type((*m_iter)->get_type());
+- if (t->is_base_type() || t->is_enum() || is_reference(*m_iter)) {
+- string dval;
+- t_const_value* cv = (*m_iter)->get_value();
+- if (cv != nullptr) {
+- dval += render_const_value(out, (*m_iter)->get_name(), t, cv);
+- } else if (t->is_enum()) {
+- dval += "static_cast<" + type_name(t) + ">(0)";
+- } else {
+- dval += (t->is_string() || is_reference(*m_iter)) ? "" : "0";
+- }
+- if (!init_ctor) {
+- init_ctor = true;
+- if(has_default_value) {
+- out << " : ";
+- } else {
+- out << '\n' << args_indent << ": ";
+- args_indent.append(" ");
+- }
+- } else {
+- out << ",\n" << args_indent;
+- }
+- out << (*m_iter)->get_name() << "(" << dval << ")";
+- }
+- }
+- out << " {" << endl;
+- indent_up();
+- // TODO(dreiss): When everything else in Thrift is perfect,
+- // do more of these in the initializer list.
+- for (m_iter = members.begin(); m_iter != members.end(); ++m_iter) {
+- t_type* t = get_true_type((*m_iter)->get_type());
+- if (!t->is_base_type() && !t->is_enum() && !is_reference(*m_iter)) {
+- t_const_value* cv = (*m_iter)->get_value();
+- if (cv != nullptr) {
+- print_const_value(out, (*m_iter)->get_name(), t, cv);
+- }
+- }
+- }
+- scope_down(out);
++ indent(out) << clsname_ctor << (has_default_value ? "" : " noexcept") << ";" << endl;
+ }
+
+ if (tstruct->annotations_.find("final") == tstruct->annotations_.end()) {
+@@ -1254,27 +1326,10 @@ void t_cpp_generator::generate_struct_declaration(ostream& out,
+ if (!pointers) {
+ // Should we generate default operators?
+ if (!gen_no_default_operators_) {
+- // Generate an equality testing operator. Make it inline since the compiler
+- // will do a better job than we would when deciding whether to inline it.
++ // Generate an equality testing operator.
+ out << indent() << "bool operator == (const " << tstruct->get_name() << " & "
+- << (members.size() > 0 ? "rhs" : "/* rhs */") << ") const" << endl;
+- scope_up(out);
+- for (m_iter = members.begin(); m_iter != members.end(); ++m_iter) {
+- // Most existing Thrift code does not use isset or optional/required,
+- // so we treat "default" fields as required.
+- if ((*m_iter)->get_req() != t_field::T_OPTIONAL) {
+- out << indent() << "if (!(" << (*m_iter)->get_name() << " == rhs."
+- << (*m_iter)->get_name() << "))" << endl << indent() << " return false;" << endl;
+- } else {
+- out << indent() << "if (__isset." << (*m_iter)->get_name() << " != rhs.__isset."
+- << (*m_iter)->get_name() << ")" << endl << indent() << " return false;" << endl
+- << indent() << "else if (__isset." << (*m_iter)->get_name() << " && !("
+- << (*m_iter)->get_name() << " == rhs." << (*m_iter)->get_name() << "))" << endl
+- << indent() << " return false;" << endl;
+- }
+- }
+- indent(out) << "return true;" << endl;
+- scope_down(out);
++ << (members.size() > 0 ? "rhs" : "/* rhs */") << ") const;" << endl;
++
+ out << indent() << "bool operator != (const " << tstruct->get_name() << " &rhs) const {"
+ << endl << indent() << " return !(*this == rhs);" << endl << indent() << "}" << endl
+ << endl;
+
+From cedcd0e6424a08dd6feeb2533810054c9aca2a9e Mon Sep 17 00:00:00 2001
+From: Lukas Barth <mail@tinloaf.de>
+Date: Wed, 8 Feb 2023 10:11:48 +0100
+Subject: [PATCH 2/5] Factor out duplicated code into helper function
+
+---
+ .../src/thrift/generate/t_cpp_generator.cc | 43 ++++++++++---------
+ 1 file changed, 23 insertions(+), 20 deletions(-)
+
+diff --git a/compiler/cpp/src/thrift/generate/t_cpp_generator.cc b/compiler/cpp/src/thrift/generate/t_cpp_generator.cc
+index fecfa4bb5..a77982f61 100644
+--- a/compiler/cpp/src/thrift/generate/t_cpp_generator.cc
++++ b/compiler/cpp/src/thrift/generate/t_cpp_generator.cc
+@@ -302,6 +302,12 @@ public:
+ */
+ bool is_struct_storage_not_throwing(t_struct* tstruct) const;
+
++ /**
++ * Helper function to determine whether any of the members of our struct
++ * has a default value.
++ */
++ bool has_field_with_default_value(t_struct* tstruct);
++
+ private:
+ /**
+ * Returns the include prefix to use for a file generated by program, or the
+@@ -968,26 +974,33 @@ void t_cpp_generator::generate_equality_operator(std::ostream& out, t_struct* ts
+ out << "\n";
+ }
+
+-void t_cpp_generator::generate_default_constructor(ostream& out,
+- t_struct* tstruct,
+- bool is_exception) {
+- // Get members
++bool t_cpp_generator::has_field_with_default_value(t_struct* tstruct)
++{
+ vector<t_field*>::const_iterator m_iter;
+ const vector<t_field*>& members = tstruct->get_members();
+
+- // TODO(barth) this is duplicated from generate_struct_declaration
+- bool has_default_value = false;
+ for (m_iter = members.begin(); m_iter != members.end(); ++m_iter) {
+ t_type* t = get_true_type((*m_iter)->get_type());
+ if (is_reference(*m_iter) || t->is_string()) {
+ t_const_value* cv = (*m_iter)->get_value();
+ if (cv != nullptr) {
+- has_default_value = true;
+- break;
++ return true;
+ }
+ }
+ }
+
++ return false;
++}
++
++void t_cpp_generator::generate_default_constructor(ostream& out,
++ t_struct* tstruct,
++ bool is_exception) {
++ // Get members
++ vector<t_field*>::const_iterator m_iter;
++ const vector<t_field*>& members = tstruct->get_members();
++
++ bool has_default_value = has_field_with_default_value(tstruct);
++
+ std::string clsname_ctor = tstruct->get_name() + "::" + tstruct->get_name() + "()";
+ indent(out) << clsname_ctor << (has_default_value ? "" : " noexcept");
+
+@@ -1271,18 +1284,8 @@ void t_cpp_generator::generate_struct_declaration(ostream& out,
+ << endl;
+ }
+
+- bool has_default_value = false;
+- for (m_iter = members.begin(); m_iter != members.end(); ++m_iter) {
+- t_type* t = get_true_type((*m_iter)->get_type());
+- if (is_reference(*m_iter) || t->is_string()) {
+- t_const_value* cv = (*m_iter)->get_value();
+- if (cv != nullptr) {
+- has_default_value = true;
+- break;
+- }
+- }
+- }
+-
++ bool has_default_value = has_field_with_default_value(tstruct);
++
+ // Default constructor
+ std::string clsname_ctor = tstruct->get_name() + "()";
+ indent(out) << clsname_ctor << (has_default_value ? "" : " noexcept") << ";" << endl;
+
+From 16105fa1a1bb9ae633b805fcb7af3c7757beb6e0 Mon Sep 17 00:00:00 2001
+From: Lukas Barth <mail@tinloaf.de>
+Date: Fri, 24 Feb 2023 13:46:58 +0100
+Subject: [PATCH 3/5] Move generate_default_constructor call into
+ generate_struct_definition
+
+This makes sure that helper structs like _args and _result also have
+their default constructors defined.
+---
+ .../src/thrift/generate/t_cpp_generator.cc | 19 +++++++++++++------
+ 1 file changed, 13 insertions(+), 6 deletions(-)
+
+diff --git a/compiler/cpp/src/thrift/generate/t_cpp_generator.cc b/compiler/cpp/src/thrift/generate/t_cpp_generator.cc
+index a77982f61..ccb79bc48 100644
+--- a/compiler/cpp/src/thrift/generate/t_cpp_generator.cc
++++ b/compiler/cpp/src/thrift/generate/t_cpp_generator.cc
+@@ -143,7 +143,8 @@ public:
+ std::ostream& force_cpp_out,
+ t_struct* tstruct,
+ bool setters = true,
+- bool is_user_struct = false);
++ bool is_user_struct = false,
++ bool pointers = false);
+ void generate_copy_constructor(std::ostream& out, t_struct* tstruct, bool is_exception);
+ void generate_move_constructor(std::ostream& out, t_struct* tstruct, bool is_exception);
+ void generate_default_constructor(std::ostream& out, t_struct* tstruct, bool is_exception);
+@@ -916,7 +917,7 @@ void t_cpp_generator::generate_forward_declaration(t_struct* tstruct) {
+ */
+ void t_cpp_generator::generate_cpp_struct(t_struct* tstruct, bool is_exception) {
+ generate_struct_declaration(f_types_, tstruct, is_exception, false, true, true, true, true);
+- generate_struct_definition(f_types_impl_, f_types_impl_, tstruct, true, true);
++ generate_struct_definition(f_types_impl_, f_types_impl_, tstruct, true, true, false);
+
+ std::ostream& out = (gen_templates_ ? f_types_tcc_ : f_types_impl_);
+ generate_struct_reader(out, tstruct);
+@@ -925,7 +926,6 @@ void t_cpp_generator::generate_cpp_struct(t_struct* tstruct, bool is_exception)
+ if (!gen_no_default_operators_) {
+ generate_equality_operator(f_types_impl_, tstruct);
+ }
+- generate_default_constructor(f_types_impl_, tstruct, is_exception);
+ generate_copy_constructor(f_types_impl_, tstruct, is_exception);
+ if (gen_moveable_) {
+ generate_move_constructor(f_types_impl_, tstruct, is_exception);
+@@ -1408,7 +1408,8 @@ void t_cpp_generator::generate_struct_definition(ostream& out,
+ ostream& force_cpp_out,
+ t_struct* tstruct,
+ bool setters,
+- bool is_user_struct) {
++ bool is_user_struct,
++ bool pointers) {
+ // Get members
+ vector<t_field*>::const_iterator m_iter;
+ const vector<t_field*>& members = tstruct->get_members();
+@@ -1423,6 +1424,11 @@ void t_cpp_generator::generate_struct_definition(ostream& out,
+ force_cpp_out << indent() << "}" << endl << endl;
+ }
+
++ if (!pointers)
++ {
++ generate_default_constructor(out, tstruct, false);
++ }
++
+ // Create a setter function for each field
+ if (setters) {
+ for (m_iter = members.begin(); m_iter != members.end(); ++m_iter) {
+@@ -2058,9 +2064,10 @@ void t_cpp_generator::generate_service_helpers(t_service* tservice) {
+ generate_struct_definition(out, f_service_, ts, false);
+ generate_struct_reader(out, ts);
+ generate_struct_writer(out, ts);
++
+ ts->set_name(tservice->get_name() + "_" + (*f_iter)->get_name() + "_pargs");
+ generate_struct_declaration(f_header_, ts, false, true, false, true);
+- generate_struct_definition(out, f_service_, ts, false);
++ generate_struct_definition(out, f_service_, ts, false, false, true);
+ generate_struct_writer(out, ts, true);
+ ts->set_name(name_orig);
+
+@@ -3508,7 +3515,7 @@ void t_cpp_generator::generate_function_helpers(t_service* tservice, t_function*
+
+ result.set_name(tservice->get_name() + "_" + tfunction->get_name() + "_presult");
+ generate_struct_declaration(f_header_, &result, false, true, true, gen_cob_style_);
+- generate_struct_definition(out, f_service_, &result, false);
++ generate_struct_definition(out, f_service_, &result, false, false, true);
+ generate_struct_reader(out, &result, true);
+ if (gen_cob_style_) {
+ generate_struct_writer(out, &result, true);
+
+From 4f56007baf46d4aa87eb7f8e5e34b773235c729a Mon Sep 17 00:00:00 2001
+From: Lukas Barth <mail@tinloaf.de>
+Date: Mon, 6 Mar 2023 11:37:09 +0100
+Subject: [PATCH 4/5] Always generate an initializer list
+
+---
+ .../src/thrift/generate/t_cpp_generator.cc | 102 +++++++++---------
+ 1 file changed, 54 insertions(+), 48 deletions(-)
+
+diff --git a/compiler/cpp/src/thrift/generate/t_cpp_generator.cc b/compiler/cpp/src/thrift/generate/t_cpp_generator.cc
+index ccb79bc48..2a65bfb96 100644
+--- a/compiler/cpp/src/thrift/generate/t_cpp_generator.cc
++++ b/compiler/cpp/src/thrift/generate/t_cpp_generator.cc
+@@ -1004,64 +1004,70 @@ void t_cpp_generator::generate_default_constructor(ostream& out,
+ std::string clsname_ctor = tstruct->get_name() + "::" + tstruct->get_name() + "()";
+ indent(out) << clsname_ctor << (has_default_value ? "" : " noexcept");
+
+- if (has_default_value || is_exception) {
+- // We need an initializer block
++ //
++ // Start generating initializer list
++ //
+
+- bool init_ctor = false;
+- std::string args_indent(" ");
++ bool init_ctor = false;
++ std::string args_indent(" ");
+
+- // Default-initialize TException, if it is our base type
+- if (is_exception)
+- {
+- out << "\n";
+- indent(out) << " : ";
+- out << "TException()";
+- init_ctor = true;
+- }
++ // Default-initialize TException, if it is our base type
++ if (is_exception)
++ {
++ out << "\n";
++ indent(out) << " : ";
++ out << "TException()";
++ init_ctor = true;
++ }
+
+- // Default-initialize all members that should be initialized in
+- // the initializer block
+- for (m_iter = members.begin(); m_iter != members.end(); ++m_iter) {
+- t_type* t = get_true_type((*m_iter)->get_type());
+- if (t->is_base_type() || t->is_enum() || is_reference(*m_iter)) {
+- string dval;
+- t_const_value* cv = (*m_iter)->get_value();
+- if (cv != nullptr) {
+- dval += render_const_value(out, (*m_iter)->get_name(), t, cv);
+- } else if (t->is_enum()) {
+- dval += "static_cast<" + type_name(t) + ">(0)";
+- } else {
+- dval += (t->is_string() || is_reference(*m_iter)) ? "" : "0";
+- }
+- if (!init_ctor) {
+- out << "\n";
+- indent(out) << " : ";
+- init_ctor = true;
++ // Default-initialize all members that should be initialized in
++ // the initializer block
++ for (m_iter = members.begin(); m_iter != members.end(); ++m_iter) {
++ t_type* t = get_true_type((*m_iter)->get_type());
++ if (t->is_base_type() || t->is_enum() || is_reference(*m_iter)) {
++ string dval;
++ t_const_value* cv = (*m_iter)->get_value();
++ if (cv != nullptr) {
++ dval += render_const_value(out, (*m_iter)->get_name(), t, cv);
++ } else if (t->is_enum()) {
++ dval += "static_cast<" + type_name(t) + ">(0)";
++ } else {
++ dval += (t->is_string() || is_reference(*m_iter)) ? "" : "0";
++ }
++ if (!init_ctor) {
++ init_ctor = true;
++ if(has_default_value) {
++ out << " : ";
+ } else {
+- out << ",\n";
+- indent(out) << args_indent;
++ out << '\n' << args_indent << ": ";
++ args_indent.append(" ");
+ }
+-
+- out << (*m_iter)->get_name() << "(" << dval << ")";
++ } else {
++ out << ",\n" << args_indent;
+ }
++
++ out << (*m_iter)->get_name() << "(" << dval << ")";
+ }
+- out << " {" << endl;
+- indent_up();
+- // TODO(dreiss): When everything else in Thrift is perfect,
+- // do more of these in the initializer list.
+- for (m_iter = members.begin(); m_iter != members.end(); ++m_iter) {
+- t_type* t = get_true_type((*m_iter)->get_type());
+- if (!t->is_base_type() && !t->is_enum() && !is_reference(*m_iter)) {
+- t_const_value* cv = (*m_iter)->get_value();
+- if (cv != nullptr) {
+- print_const_value(out, (*m_iter)->get_name(), t, cv);
+- }
++ }
++
++ //
++ // Start generating body
++ //
++
++ out << " {" << endl;
++ indent_up();
++ // TODO(dreiss): When everything else in Thrift is perfect,
++ // do more of these in the initializer list.
++ for (m_iter = members.begin(); m_iter != members.end(); ++m_iter) {
++ t_type* t = get_true_type((*m_iter)->get_type());
++ if (!t->is_base_type() && !t->is_enum() && !is_reference(*m_iter)) {
++ t_const_value* cv = (*m_iter)->get_value();
++ if (cv != nullptr) {
++ print_const_value(out, (*m_iter)->get_name(), t, cv);
+ }
+ }
+- scope_down(out);
+- } else {
+- out << " {}\n";
+ }
++ scope_down(out);
+ }
+
+ void t_cpp_generator::generate_copy_constructor(ostream& out,
+
+From 9bd8f1e1acb23cb3ef134291e56b2605a7356b04 Mon Sep 17 00:00:00 2001
+From: Lukas Barth <mail@tinloaf.de>
+Date: Tue, 4 Apr 2023 16:25:06 +0200
+Subject: [PATCH 5/5] Fix ODR violations in cases where templates are involved
+
+---
+ compiler/cpp/src/thrift/generate/t_cpp_generator.cc | 5 ++++-
+ 1 file changed, 4 insertions(+), 1 deletion(-)
+
+diff --git a/compiler/cpp/src/thrift/generate/t_cpp_generator.cc b/compiler/cpp/src/thrift/generate/t_cpp_generator.cc
+index 2a65bfb96..a085ada0e 100644
+--- a/compiler/cpp/src/thrift/generate/t_cpp_generator.cc
++++ b/compiler/cpp/src/thrift/generate/t_cpp_generator.cc
+@@ -1432,7 +1432,10 @@ void t_cpp_generator::generate_struct_definition(ostream& out,
+
+ if (!pointers)
+ {
+- generate_default_constructor(out, tstruct, false);
++ // 'force_cpp_out' always goes into the .cpp file, and never into a .tcc
++ // file in case templates are involved. Since the constructor is not templated,
++ // putting it into the (later included) .tcc file would cause ODR violations.
++ generate_default_constructor(force_cpp_out, tstruct, false);
+ }
+
+ // Create a setter function for each field
diff --git a/meta-openembedded/meta-oe/recipes-connectivity/thrift/thrift_0.20.0.bb b/meta-openembedded/meta-oe/recipes-connectivity/thrift/thrift_0.20.0.bb
index 23db052b9e..e4fd07198c 100644
--- a/meta-openembedded/meta-oe/recipes-connectivity/thrift/thrift_0.20.0.bb
+++ b/meta-openembedded/meta-oe/recipes-connectivity/thrift/thrift_0.20.0.bb
@@ -8,8 +8,11 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=c40a383cb3f747e0c7abbf1482f194f0 \
DEPENDS = "thrift-native boost flex-native bison-native openssl zlib"
-SRC_URI = "https://downloads.apache.org/${BPN}/${PV}/${BP}.tar.gz \
- file://0001-DefineInstallationPaths.cmake-Define-libdir-in-terms.patch"
+SRC_URI = "https://archive.apache.org/dist/${BPN}/${PV}/${BP}.tar.gz \
+ file://0001-DefineInstallationPaths.cmake-Define-libdir-in-terms.patch \
+ file://0001-thrift-pr2755.patch \
+ file://0001-THRIFT-5842-Add-missing-cstdint-include-for-int64_t-.patch \
+ "
SRC_URI[sha256sum] = "b5d8311a779470e1502c027f428a1db542f5c051c8e1280ccd2163fa935ff2d6"
BBCLASSEXTEND = "native nativesdk"
diff --git a/meta-openembedded/meta-oe/recipes-core/emlog/emlog.inc b/meta-openembedded/meta-oe/recipes-core/emlog/emlog.inc
index 631e52f388..ec78a11086 100644
--- a/meta-openembedded/meta-oe/recipes-core/emlog/emlog.inc
+++ b/meta-openembedded/meta-oe/recipes-core/emlog/emlog.inc
@@ -8,6 +8,8 @@ SRCREV = "a9bbf324fde131ff4cf064e32674086c4ced4dca"
PV = "0.70+git"
S = "${WORKDIR}/git"
+CVE_PRODUCT = "nicupavel:emlog"
+
EXTRA_OEMAKE += " \
CFLAGS='${TARGET_CFLAGS}' \
"
diff --git a/meta-openembedded/meta-oe/recipes-core/opencl/opencl-clhpp_git.bb b/meta-openembedded/meta-oe/recipes-core/opencl/opencl-clhpp_git.bb
index 7ae0362d37..23007d7cca 100644
--- a/meta-openembedded/meta-oe/recipes-core/opencl/opencl-clhpp_git.bb
+++ b/meta-openembedded/meta-oe/recipes-core/opencl/opencl-clhpp_git.bb
@@ -21,3 +21,5 @@ EXTRA_OECMAKE = " \
# Headers only so PN is empty
RDEPENDS:${PN}-dev = ""
+
+BBCLASSEXTEND += "native nativesdk"
diff --git a/meta-openembedded/meta-oe/recipes-core/packagegroups/packagegroup-meta-oe.bb b/meta-openembedded/meta-oe/recipes-core/packagegroups/packagegroup-meta-oe.bb
index 7544a9fbfa..71f74287c7 100644
--- a/meta-openembedded/meta-oe/recipes-core/packagegroups/packagegroup-meta-oe.bb
+++ b/meta-openembedded/meta-oe/recipes-core/packagegroups/packagegroup-meta-oe.bb
@@ -511,7 +511,7 @@ RDEPENDS:packagegroup-meta-oe-graphics ="\
libsdl2-net \
${@bb.utils.contains("DISTRO_FEATURES", "opengl", "libsdl2-ttf", "", d)} \
libsdl \
- ${@bb.utils.contains("DISTRO_FEATURES", "wayland", "lv-drivers lvgl lv-lib-png", "", d)} \
+ lvgl \
ttf-arphic-uming \
ttf-droid-sans ttf-droid-sans-mono ttf-droid-sans-fallback ttf-droid-sans-japanese ttf-droid-serif \
ttf-abyssinica \
diff --git a/meta-openembedded/meta-oe/recipes-core/uutils-coreutils/files/0001-Cargo.lock-revert-to-selinux-sys-0.6.9-and-fts-sys-0.patch b/meta-openembedded/meta-oe/recipes-core/uutils-coreutils/files/0001-Cargo.lock-revert-to-selinux-sys-0.6.9-and-fts-sys-0.patch
new file mode 100644
index 0000000000..d91c368891
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-core/uutils-coreutils/files/0001-Cargo.lock-revert-to-selinux-sys-0.6.9-and-fts-sys-0.patch
@@ -0,0 +1,178 @@
+From 2b578f1c2eee4e3552300d672eceea0804118896 Mon Sep 17 00:00:00 2001
+From: Etienne Cordonnier <ecordonnier@snap.com>
+Date: Mon, 10 Feb 2025 14:43:54 +0100
+Subject: [PATCH] Cargo.lock: revert to selinux-sys 0.6.9 and fts-sys 0.2.9
+
+selinux-sys 0.6.12 and fts-sys 0.2.11 uses offset_of which requires Rust 1.77.
+selinux 0.6.9 and fts-sys 0.2.9 compile with Rust 1.70.
+
+This fixes the compilation of uutils-coreutils when meta-selinux is included.
+
+This reverts https://github.com/uutils/coreutils/commit/10d3e98eda9342cf8d5f56d5082e38096743eb80
+
+Upstream-Status: Inappropriate [OE Specific]
+
+Signed-off-by: Etienne Cordonnier <ecordonnier@snap.com>
+---
+ Cargo.lock | 61 ++++++++++++++++++++++++++++++++++++++++++++----------
+ 1 file changed, 50 insertions(+), 11 deletions(-)
+
+diff --git a/Cargo.lock b/Cargo.lock
+index b59405071..5f7b420fc 100644
+--- a/Cargo.lock
++++ b/Cargo.lock
+@@ -167,14 +167,16 @@ dependencies = [
+
+ [[package]]
+ name = "bindgen"
+-version = "0.70.1"
++version = "0.69.5"
+ source = "registry+https://github.com/rust-lang/crates.io-index"
+-checksum = "f49d8fed880d473ea71efb9bf597651e77201bdd4893efe54c9e5d65ae04ce6f"
++checksum = "271383c67ccabffb7381723dea0672a673f292304fcb45c01cc648c7a8d58088"
+ dependencies = [
+ "bitflags 2.6.0",
+ "cexpr",
+ "clang-sys",
+- "itertools",
++ "itertools 0.12.1",
++ "lazy_static",
++ "lazycell",
+ "log",
+ "prettyplease",
+ "proc-macro2",
+@@ -183,6 +185,7 @@ dependencies = [
+ "rustc-hash",
+ "shlex",
+ "syn 2.0.86",
++ "which",
+ ]
+
+ [[package]]
+@@ -961,9 +964,9 @@ dependencies = [
+
+ [[package]]
+ name = "fts-sys"
+-version = "0.2.11"
++version = "0.2.9"
+ source = "registry+https://github.com/rust-lang/crates.io-index"
+-checksum = "28ab6a6dfd9184fe8a5097924dea6e7648f499121b3e933bb8486a17f817122e"
++checksum = "4e184d5f593d19793f26afb6f9a58d25f0bc755c4e48890ffcba6db416153ebb"
+ dependencies = [
+ "bindgen",
+ "libc",
+@@ -1156,6 +1159,15 @@ version = "0.4.1"
+ source = "registry+https://github.com/rust-lang/crates.io-index"
+ checksum = "6fe2267d4ed49bc07b63801559be28c718ea06c4738b7a03c94df7386d2cde46"
+
++[[package]]
++name = "home"
++version = "0.5.9"
++source = "registry+https://github.com/rust-lang/crates.io-index"
++checksum = "e3d1354bf6b7235cb4a0576c2619fd4ed18183f689b12b006a0ee7329eeff9a5"
++dependencies = [
++ "windows-sys 0.52.0",
++]
++
+ [[package]]
+ name = "hostname"
+ version = "0.4.0"
+@@ -1244,6 +1256,15 @@ dependencies = [
+ "windows-sys 0.48.0",
+ ]
+
++[[package]]
++name = "itertools"
++version = "0.12.1"
++source = "registry+https://github.com/rust-lang/crates.io-index"
++checksum = "ba291022dbbd398a455acf126c1e341954079855bc60dfdda641363bd6922569"
++dependencies = [
++ "either",
++]
++
+ [[package]]
+ name = "itertools"
+ version = "0.13.0"
+@@ -1303,6 +1324,12 @@ version = "1.4.0"
+ source = "registry+https://github.com/rust-lang/crates.io-index"
+ checksum = "e2abad23fbc42b3700f2f279844dc832adb2b2eb069b2df918f455c4e18cc646"
+
++[[package]]
++name = "lazycell"
++version = "1.3.0"
++source = "registry+https://github.com/rust-lang/crates.io-index"
++checksum = "830d08ce1d1d941e6b30645f1a0eb5643013d835ce3779a5fc208261dbe10f55"
++
+ [[package]]
+ name = "libc"
+ version = "0.2.161"
+@@ -2120,9 +2147,9 @@ dependencies = [
+
+ [[package]]
+ name = "selinux-sys"
+-version = "0.6.12"
++version = "0.6.9"
+ source = "registry+https://github.com/rust-lang/crates.io-index"
+-checksum = "8d557667087c5b4791e180b80979cd1a92fdb9bfd92cfd4b9ab199c4d7402423"
++checksum = "89d45498373dc17ec8ebb72e1fd320c015647b0157fc81dddf678e2e00205fec"
+ dependencies = [
+ "bindgen",
+ "cc",
+@@ -3100,7 +3127,7 @@ version = "0.0.28"
+ dependencies = [
+ "chrono",
+ "clap",
+- "itertools",
++ "itertools 0.13.0",
+ "quick-error 2.0.1",
+ "regex",
+ "uucore",
+@@ -3236,7 +3263,7 @@ dependencies = [
+ "compare",
+ "ctrlc",
+ "fnv",
+- "itertools",
++ "itertools 0.13.0",
+ "memchr",
+ "nix",
+ "rand",
+@@ -3520,7 +3547,7 @@ name = "uu_yes"
+ version = "0.0.28"
+ dependencies = [
+ "clap",
+- "itertools",
++ "itertools 0.13.0",
+ "nix",
+ "uucore",
+ ]
+@@ -3539,7 +3566,7 @@ dependencies = [
+ "dunce",
+ "glob",
+ "hex",
+- "itertools",
++ "itertools 0.13.0",
+ "libc",
+ "md-5",
+ "memchr",
+@@ -3687,6 +3714,18 @@ dependencies = [
+ "wasm-bindgen",
+ ]
+
++[[package]]
++name = "which"
++version = "4.4.2"
++source = "registry+https://github.com/rust-lang/crates.io-index"
++checksum = "87ba24419a2078cd2b0f2ede2691b6c66d8e47836da3b6db8265ebad47afbfc7"
++dependencies = [
++ "either",
++ "home",
++ "once_cell",
++ "rustix 0.38.37",
++]
++
+ [[package]]
+ name = "wild"
+ version = "2.2.1"
+--
+2.43.0
+
diff --git a/meta-openembedded/meta-oe/recipes-core/uutils-coreutils/uutils-coreutils-crates.inc b/meta-openembedded/meta-oe/recipes-core/uutils-coreutils/uutils-coreutils-crates.inc
index 58d8325628..f2b00f27bd 100644
--- a/meta-openembedded/meta-oe/recipes-core/uutils-coreutils/uutils-coreutils-crates.inc
+++ b/meta-openembedded/meta-oe/recipes-core/uutils-coreutils/uutils-coreutils-crates.inc
@@ -3,34 +3,42 @@
# from Cargo.lock
SRC_URI += " \
crate://crates.io/adler/1.0.2 \
- crate://crates.io/aho-corasick/1.0.4 \
+ crate://crates.io/ahash/0.8.11 \
+ crate://crates.io/aho-corasick/1.1.3 \
+ crate://crates.io/allocator-api2/0.2.18 \
crate://crates.io/android-tzdata/0.1.1 \
crate://crates.io/android_system_properties/0.1.5 \
+ crate://crates.io/ansi-width/0.1.0 \
crate://crates.io/anstream/0.5.0 \
crate://crates.io/anstyle/1.0.0 \
crate://crates.io/anstyle-parse/0.2.0 \
crate://crates.io/anstyle-query/1.0.0 \
crate://crates.io/anstyle-wincon/2.1.0 \
+ crate://crates.io/arbitrary/1.3.2 \
crate://crates.io/arrayref/0.3.6 \
crate://crates.io/arrayvec/0.7.4 \
crate://crates.io/autocfg/1.1.0 \
- crate://crates.io/bigdecimal/0.4.0 \
+ crate://crates.io/bigdecimal/0.4.6 \
crate://crates.io/binary-heap-plus/0.5.0 \
- crate://crates.io/bindgen/0.63.0 \
+ crate://crates.io/bincode/1.3.3 \
+ crate://crates.io/bindgen/0.69.5 \
+ crate://crates.io/bit-set/0.5.3 \
+ crate://crates.io/bit-vec/0.6.3 \
crate://crates.io/bitflags/1.3.2 \
- crate://crates.io/bitflags/2.4.2 \
+ crate://crates.io/bitflags/2.6.0 \
+ crate://crates.io/bitvec/1.0.1 \
crate://crates.io/blake2b_simd/1.0.2 \
- crate://crates.io/blake3/1.5.1 \
+ crate://crates.io/blake3/1.5.4 \
crate://crates.io/block-buffer/0.10.3 \
- crate://crates.io/bstr/1.9.1 \
+ crate://crates.io/bstr/1.10.0 \
crate://crates.io/bumpalo/3.11.1 \
- crate://crates.io/bytecount/0.6.7 \
+ crate://crates.io/bytecount/0.6.8 \
crate://crates.io/byteorder/1.5.0 \
- crate://crates.io/cc/1.0.79 \
+ crate://crates.io/cc/1.1.13 \
crate://crates.io/cexpr/0.6.0 \
crate://crates.io/cfg-if/1.0.0 \
- crate://crates.io/cfg_aliases/0.1.1 \
- crate://crates.io/chrono/0.4.35 \
+ crate://crates.io/cfg_aliases/0.2.1 \
+ crate://crates.io/chrono/0.4.38 \
crate://crates.io/clang-sys/1.4.0 \
crate://crates.io/clap/4.4.2 \
crate://crates.io/clap_builder/4.4.2 \
@@ -43,7 +51,6 @@ SRC_URI += " \
crate://crates.io/const-random/0.1.16 \
crate://crates.io/const-random-macro/0.1.16 \
crate://crates.io/constant_time_eq/0.3.0 \
- crate://crates.io/conv/0.3.3 \
crate://crates.io/core-foundation-sys/0.8.3 \
crate://crates.io/coz/0.1.3 \
crate://crates.io/cpp/0.5.9 \
@@ -51,67 +58,74 @@ SRC_URI += " \
crate://crates.io/cpp_common/0.5.9 \
crate://crates.io/cpp_macros/0.5.9 \
crate://crates.io/cpufeatures/0.2.5 \
- crate://crates.io/crc32fast/1.3.2 \
+ crate://crates.io/crc32fast/1.4.0 \
crate://crates.io/crossbeam-channel/0.5.10 \
crate://crates.io/crossbeam-deque/0.8.4 \
crate://crates.io/crossbeam-epoch/0.9.17 \
- crate://crates.io/crossbeam-utils/0.8.18 \
+ crate://crates.io/crossbeam-utils/0.8.19 \
crate://crates.io/crossterm/0.27.0 \
crate://crates.io/crossterm_winapi/0.9.1 \
crate://crates.io/crunchy/0.2.2 \
crate://crates.io/crypto-common/0.1.6 \
- crate://crates.io/ctrlc/3.4.4 \
- crate://crates.io/custom_derive/0.1.7 \
- crate://crates.io/data-encoding/2.5.0 \
- crate://crates.io/data-encoding-macro/0.1.14 \
- crate://crates.io/data-encoding-macro-internal/0.1.12 \
+ crate://crates.io/ctrlc/3.4.5 \
+ crate://crates.io/data-encoding/2.6.0 \
+ crate://crates.io/data-encoding-macro/0.1.15 \
+ crate://crates.io/data-encoding-macro-internal/0.1.13 \
+ crate://crates.io/deranged/0.3.11 \
+ crate://crates.io/derive_arbitrary/1.3.2 \
crate://crates.io/diff/0.1.13 \
crate://crates.io/digest/0.10.7 \
+ crate://crates.io/displaydoc/0.2.4 \
crate://crates.io/dlv-list/0.5.0 \
crate://crates.io/dns-lookup/2.0.4 \
- crate://crates.io/dunce/1.0.4 \
+ crate://crates.io/dunce/1.0.5 \
crate://crates.io/either/1.8.0 \
crate://crates.io/encode_unicode/0.3.6 \
- crate://crates.io/env_logger/0.8.4 \
+ crate://crates.io/equivalent/1.0.1 \
crate://crates.io/errno/0.3.8 \
crate://crates.io/exacl/0.12.0 \
- crate://crates.io/fastrand/2.0.1 \
+ crate://crates.io/fastrand/2.1.1 \
crate://crates.io/file_diff/1.0.0 \
- crate://crates.io/filetime/0.2.23 \
- crate://crates.io/flate2/1.0.24 \
+ crate://crates.io/filedescriptor/0.8.2 \
+ crate://crates.io/filetime/0.2.25 \
+ crate://crates.io/flate2/1.0.28 \
crate://crates.io/fnv/1.0.7 \
crate://crates.io/fs_extra/1.3.0 \
crate://crates.io/fsevent-sys/4.1.0 \
- crate://crates.io/fts-sys/0.2.4 \
- crate://crates.io/fundu/2.0.0 \
- crate://crates.io/fundu-core/0.3.0 \
- crate://crates.io/futures/0.3.28 \
- crate://crates.io/futures-channel/0.3.28 \
- crate://crates.io/futures-core/0.3.28 \
- crate://crates.io/futures-executor/0.3.28 \
- crate://crates.io/futures-io/0.3.28 \
- crate://crates.io/futures-macro/0.3.28 \
- crate://crates.io/futures-sink/0.3.28 \
- crate://crates.io/futures-task/0.3.28 \
- crate://crates.io/futures-timer/3.0.2 \
- crate://crates.io/futures-util/0.3.28 \
+ crate://crates.io/fts-sys/0.2.9 \
+ crate://crates.io/fundu/2.0.1 \
+ crate://crates.io/fundu-core/0.3.1 \
+ crate://crates.io/funty/2.0.0 \
+ crate://crates.io/futures/0.3.30 \
+ crate://crates.io/futures-channel/0.3.31 \
+ crate://crates.io/futures-core/0.3.31 \
+ crate://crates.io/futures-executor/0.3.30 \
+ crate://crates.io/futures-io/0.3.31 \
+ crate://crates.io/futures-macro/0.3.31 \
+ crate://crates.io/futures-sink/0.3.31 \
+ crate://crates.io/futures-task/0.3.31 \
+ crate://crates.io/futures-timer/3.0.3 \
+ crate://crates.io/futures-util/0.3.31 \
crate://crates.io/gcd/2.3.0 \
crate://crates.io/generic-array/0.14.6 \
crate://crates.io/getrandom/0.2.9 \
crate://crates.io/glob/0.3.1 \
- crate://crates.io/half/2.4.0 \
- crate://crates.io/hashbrown/0.13.2 \
+ crate://crates.io/half/2.4.1 \
+ crate://crates.io/hashbrown/0.14.3 \
crate://crates.io/hermit-abi/0.3.2 \
crate://crates.io/hex/0.4.3 \
crate://crates.io/hex-literal/0.4.1 \
- crate://crates.io/hostname/0.3.1 \
+ crate://crates.io/home/0.5.9 \
+ crate://crates.io/hostname/0.4.0 \
crate://crates.io/iana-time-zone/0.1.53 \
crate://crates.io/iana-time-zone-haiku/0.1.2 \
- crate://crates.io/indicatif/0.17.3 \
+ crate://crates.io/indexmap/2.5.0 \
+ crate://crates.io/indicatif/0.17.9 \
crate://crates.io/inotify/0.9.6 \
crate://crates.io/inotify-sys/0.1.5 \
crate://crates.io/io-lifetimes/1.0.11 \
crate://crates.io/itertools/0.12.1 \
+ crate://crates.io/itertools/0.13.0 \
crate://crates.io/itoa/1.0.4 \
crate://crates.io/js-sys/0.3.64 \
crate://crates.io/keccak/0.1.4 \
@@ -119,39 +133,44 @@ SRC_URI += " \
crate://crates.io/kqueue-sys/1.0.3 \
crate://crates.io/lazy_static/1.4.0 \
crate://crates.io/lazycell/1.3.0 \
- crate://crates.io/libc/0.2.153 \
+ crate://crates.io/libc/0.2.161 \
crate://crates.io/libloading/0.7.4 \
crate://crates.io/libm/0.2.7 \
+ crate://crates.io/libredox/0.1.3 \
crate://crates.io/linux-raw-sys/0.3.8 \
- crate://crates.io/linux-raw-sys/0.4.12 \
+ crate://crates.io/linux-raw-sys/0.4.14 \
crate://crates.io/lock_api/0.4.9 \
crate://crates.io/log/0.4.20 \
- crate://crates.io/lscolors/0.16.0 \
- crate://crates.io/match_cfg/0.1.0 \
+ crate://crates.io/lru/0.12.3 \
+ crate://crates.io/lscolors/0.20.0 \
crate://crates.io/md-5/0.10.6 \
- crate://crates.io/memchr/2.7.1 \
- crate://crates.io/memmap2/0.9.0 \
+ crate://crates.io/memchr/2.7.4 \
+ crate://crates.io/memmap2/0.9.5 \
crate://crates.io/minimal-lexical/0.2.1 \
- crate://crates.io/miniz_oxide/0.5.4 \
+ crate://crates.io/miniz_oxide/0.7.2 \
crate://crates.io/mio/0.8.11 \
- crate://crates.io/nix/0.28.0 \
+ crate://crates.io/nix/0.29.0 \
crate://crates.io/nom/7.1.3 \
crate://crates.io/notify/6.0.1 \
- crate://crates.io/nu-ansi-term/0.49.0 \
- crate://crates.io/num-bigint/0.4.4 \
- crate://crates.io/num-integer/0.1.45 \
- crate://crates.io/num-traits/0.2.18 \
+ crate://crates.io/nu-ansi-term/0.50.0 \
+ crate://crates.io/num-bigint/0.4.6 \
+ crate://crates.io/num-conv/0.1.0 \
+ crate://crates.io/num-integer/0.1.46 \
+ crate://crates.io/num-modular/0.5.1 \
+ crate://crates.io/num-prime/0.4.4 \
+ crate://crates.io/num-traits/0.2.19 \
+ crate://crates.io/num_enum/0.7.3 \
+ crate://crates.io/num_enum_derive/0.7.3 \
crate://crates.io/num_threads/0.1.6 \
crate://crates.io/number_prefix/0.4.0 \
- crate://crates.io/once_cell/1.19.0 \
+ crate://crates.io/once_cell/1.20.2 \
crate://crates.io/onig/6.4.0 \
crate://crates.io/onig_sys/69.8.1 \
- crate://crates.io/ordered-multimap/0.6.0 \
+ crate://crates.io/ordered-multimap/0.7.3 \
crate://crates.io/os_display/0.1.3 \
crate://crates.io/parking_lot/0.12.1 \
- crate://crates.io/parking_lot_core/0.9.9 \
- crate://crates.io/parse_datetime/0.5.0 \
- crate://crates.io/peeking_take_while/0.1.2 \
+ crate://crates.io/parking_lot_core/0.9.10 \
+ crate://crates.io/parse_datetime/0.6.0 \
crate://crates.io/phf/0.11.2 \
crate://crates.io/phf_codegen/0.11.2 \
crate://crates.io/phf_generator/0.11.1 \
@@ -159,83 +178,99 @@ SRC_URI += " \
crate://crates.io/pin-project-lite/0.2.9 \
crate://crates.io/pin-utils/0.1.0 \
crate://crates.io/pkg-config/0.3.26 \
- crate://crates.io/platform-info/2.0.2 \
- crate://crates.io/portable-atomic/0.3.15 \
+ crate://crates.io/platform-info/2.0.4 \
+ crate://crates.io/portable-atomic/1.6.0 \
+ crate://crates.io/powerfmt/0.2.0 \
crate://crates.io/ppv-lite86/0.2.17 \
- crate://crates.io/pretty_assertions/1.4.0 \
- crate://crates.io/proc-macro2/1.0.63 \
- crate://crates.io/procfs/0.16.0 \
- crate://crates.io/procfs-core/0.16.0 \
+ crate://crates.io/pretty_assertions/1.4.1 \
+ crate://crates.io/prettyplease/0.2.19 \
+ crate://crates.io/proc-macro-crate/3.2.0 \
+ crate://crates.io/proc-macro2/1.0.89 \
+ crate://crates.io/procfs/0.17.0 \
+ crate://crates.io/procfs-core/0.17.0 \
+ crate://crates.io/proptest/1.5.0 \
+ crate://crates.io/quick-error/1.2.3 \
crate://crates.io/quick-error/2.0.1 \
- crate://crates.io/quickcheck/1.0.3 \
- crate://crates.io/quote/1.0.29 \
+ crate://crates.io/quote/1.0.37 \
+ crate://crates.io/radium/0.7.0 \
crate://crates.io/rand/0.8.5 \
crate://crates.io/rand_chacha/0.3.1 \
crate://crates.io/rand_core/0.6.4 \
crate://crates.io/rand_pcg/0.3.1 \
- crate://crates.io/rayon/1.9.0 \
+ crate://crates.io/rand_xorshift/0.3.0 \
+ crate://crates.io/rayon/1.10.0 \
crate://crates.io/rayon-core/1.12.1 \
- crate://crates.io/redox_syscall/0.4.1 \
- crate://crates.io/redox_syscall/0.5.0 \
+ crate://crates.io/redox_syscall/0.5.7 \
crate://crates.io/reference-counted-singleton/0.1.2 \
- crate://crates.io/regex/1.10.4 \
- crate://crates.io/regex-automata/0.4.4 \
- crate://crates.io/regex-syntax/0.8.2 \
- crate://crates.io/relative-path/1.8.0 \
- crate://crates.io/rlimit/0.10.1 \
+ crate://crates.io/regex/1.11.1 \
+ crate://crates.io/regex-automata/0.4.8 \
+ crate://crates.io/regex-syntax/0.8.5 \
+ crate://crates.io/relative-path/1.9.3 \
+ crate://crates.io/rlimit/0.10.2 \
crate://crates.io/roff/0.2.1 \
- crate://crates.io/rstest/0.18.2 \
- crate://crates.io/rstest_macros/0.18.2 \
- crate://crates.io/rust-ini/0.19.0 \
+ crate://crates.io/rstest/0.23.0 \
+ crate://crates.io/rstest_macros/0.23.0 \
+ crate://crates.io/rust-ini/0.21.1 \
crate://crates.io/rustc-hash/1.1.0 \
- crate://crates.io/rustc_version/0.4.0 \
+ crate://crates.io/rustc_version/0.4.1 \
crate://crates.io/rustix/0.37.26 \
- crate://crates.io/rustix/0.38.31 \
+ crate://crates.io/rustix/0.38.37 \
+ crate://crates.io/rusty-fork/0.3.0 \
crate://crates.io/same-file/1.0.6 \
crate://crates.io/scopeguard/1.2.0 \
- crate://crates.io/self_cell/1.0.3 \
- crate://crates.io/selinux/0.4.0 \
- crate://crates.io/selinux-sys/0.6.2 \
+ crate://crates.io/self_cell/1.0.4 \
+ crate://crates.io/selinux/0.4.6 \
+ crate://crates.io/selinux-sys/0.6.9 \
crate://crates.io/semver/1.0.14 \
- crate://crates.io/serde/1.0.193 \
- crate://crates.io/serde_derive/1.0.193 \
+ crate://crates.io/serde/1.0.214 \
+ crate://crates.io/serde-big-array/0.5.1 \
+ crate://crates.io/serde_derive/1.0.214 \
crate://crates.io/sha1/0.10.6 \
crate://crates.io/sha2/0.10.8 \
crate://crates.io/sha3/0.10.8 \
crate://crates.io/shlex/1.3.0 \
crate://crates.io/signal-hook/0.3.17 \
crate://crates.io/signal-hook-mio/0.2.3 \
- crate://crates.io/signal-hook-registry/1.4.0 \
+ crate://crates.io/signal-hook-registry/1.4.1 \
crate://crates.io/siphasher/0.3.10 \
crate://crates.io/slab/0.4.7 \
crate://crates.io/sm3/0.4.2 \
- crate://crates.io/smallvec/1.13.1 \
+ crate://crates.io/smallvec/1.13.2 \
crate://crates.io/smawk/0.3.1 \
crate://crates.io/socket2/0.5.3 \
crate://crates.io/strsim/0.10.0 \
crate://crates.io/syn/1.0.109 \
- crate://crates.io/syn/2.0.32 \
- crate://crates.io/tempfile/3.10.1 \
+ crate://crates.io/syn/2.0.86 \
+ crate://crates.io/tap/1.0.1 \
+ crate://crates.io/tempfile/3.13.0 \
crate://crates.io/terminal_size/0.2.6 \
- crate://crates.io/terminal_size/0.3.0 \
+ crate://crates.io/terminal_size/0.4.0 \
crate://crates.io/textwrap/0.16.1 \
- crate://crates.io/thiserror/1.0.37 \
- crate://crates.io/thiserror-impl/1.0.37 \
- crate://crates.io/time/0.3.20 \
- crate://crates.io/time-core/0.1.0 \
- crate://crates.io/time-macros/0.2.8 \
+ crate://crates.io/thiserror/1.0.66 \
+ crate://crates.io/thiserror-impl/1.0.66 \
+ crate://crates.io/time/0.3.36 \
+ crate://crates.io/time-core/0.1.2 \
+ crate://crates.io/time-macros/0.2.18 \
crate://crates.io/tiny-keccak/2.0.2 \
+ crate://crates.io/toml_datetime/0.6.8 \
+ crate://crates.io/toml_edit/0.22.22 \
+ crate://crates.io/trim-in-place/0.1.7 \
crate://crates.io/typenum/1.15.0 \
- crate://crates.io/unicode-ident/1.0.5 \
+ crate://crates.io/unarray/0.1.4 \
+ crate://crates.io/unicode-ident/1.0.13 \
crate://crates.io/unicode-linebreak/0.1.5 \
- crate://crates.io/unicode-segmentation/1.11.0 \
- crate://crates.io/unicode-width/0.1.11 \
+ crate://crates.io/unicode-segmentation/1.12.0 \
+ crate://crates.io/unicode-width/0.1.13 \
+ crate://crates.io/unicode-width/0.2.0 \
crate://crates.io/unicode-xid/0.2.4 \
- crate://crates.io/unindent/0.2.1 \
+ crate://crates.io/unindent/0.2.3 \
crate://crates.io/utf8parse/0.2.1 \
+ crate://crates.io/utmp-classic/0.1.6 \
+ crate://crates.io/utmp-classic-raw/0.1.3 \
crate://crates.io/uuid/1.7.0 \
- crate://crates.io/uutils_term_grid/0.3.0 \
+ crate://crates.io/uutils_term_grid/0.6.0 \
crate://crates.io/version_check/0.9.4 \
+ crate://crates.io/wait-timeout/0.2.0 \
crate://crates.io/walkdir/2.5.0 \
crate://crates.io/wasi/0.11.0+wasi-snapshot-preview1 \
crate://crates.io/wasm-bindgen/0.2.87 \
@@ -243,74 +278,91 @@ SRC_URI += " \
crate://crates.io/wasm-bindgen-macro/0.2.87 \
crate://crates.io/wasm-bindgen-macro-support/0.2.87 \
crate://crates.io/wasm-bindgen-shared/0.2.87 \
- crate://crates.io/which/4.3.0 \
+ crate://crates.io/web-time/1.1.0 \
+ crate://crates.io/which/4.4.2 \
crate://crates.io/wild/2.2.1 \
crate://crates.io/winapi/0.3.9 \
crate://crates.io/winapi-i686-pc-windows-gnu/0.4.0 \
- crate://crates.io/winapi-util/0.1.6 \
+ crate://crates.io/winapi-util/0.1.9 \
crate://crates.io/winapi-x86_64-pc-windows-gnu/0.4.0 \
+ crate://crates.io/windows/0.52.0 \
+ crate://crates.io/windows-core/0.52.0 \
crate://crates.io/windows-sys/0.45.0 \
crate://crates.io/windows-sys/0.48.0 \
crate://crates.io/windows-sys/0.52.0 \
+ crate://crates.io/windows-sys/0.59.0 \
crate://crates.io/windows-targets/0.42.2 \
- crate://crates.io/windows-targets/0.48.0 \
- crate://crates.io/windows-targets/0.52.0 \
+ crate://crates.io/windows-targets/0.48.5 \
+ crate://crates.io/windows-targets/0.52.6 \
crate://crates.io/windows_aarch64_gnullvm/0.42.2 \
- crate://crates.io/windows_aarch64_gnullvm/0.48.0 \
- crate://crates.io/windows_aarch64_gnullvm/0.52.0 \
+ crate://crates.io/windows_aarch64_gnullvm/0.48.5 \
+ crate://crates.io/windows_aarch64_gnullvm/0.52.6 \
crate://crates.io/windows_aarch64_msvc/0.42.2 \
- crate://crates.io/windows_aarch64_msvc/0.48.0 \
- crate://crates.io/windows_aarch64_msvc/0.52.0 \
+ crate://crates.io/windows_aarch64_msvc/0.48.5 \
+ crate://crates.io/windows_aarch64_msvc/0.52.6 \
crate://crates.io/windows_i686_gnu/0.42.2 \
- crate://crates.io/windows_i686_gnu/0.48.0 \
- crate://crates.io/windows_i686_gnu/0.52.0 \
+ crate://crates.io/windows_i686_gnu/0.48.5 \
+ crate://crates.io/windows_i686_gnu/0.52.6 \
+ crate://crates.io/windows_i686_gnullvm/0.52.6 \
crate://crates.io/windows_i686_msvc/0.42.2 \
- crate://crates.io/windows_i686_msvc/0.48.0 \
- crate://crates.io/windows_i686_msvc/0.52.0 \
+ crate://crates.io/windows_i686_msvc/0.48.5 \
+ crate://crates.io/windows_i686_msvc/0.52.6 \
crate://crates.io/windows_x86_64_gnu/0.42.2 \
- crate://crates.io/windows_x86_64_gnu/0.48.0 \
- crate://crates.io/windows_x86_64_gnu/0.52.0 \
+ crate://crates.io/windows_x86_64_gnu/0.48.5 \
+ crate://crates.io/windows_x86_64_gnu/0.52.6 \
crate://crates.io/windows_x86_64_gnullvm/0.42.2 \
- crate://crates.io/windows_x86_64_gnullvm/0.48.0 \
- crate://crates.io/windows_x86_64_gnullvm/0.52.0 \
+ crate://crates.io/windows_x86_64_gnullvm/0.48.5 \
+ crate://crates.io/windows_x86_64_gnullvm/0.52.6 \
crate://crates.io/windows_x86_64_msvc/0.42.2 \
- crate://crates.io/windows_x86_64_msvc/0.48.0 \
- crate://crates.io/windows_x86_64_msvc/0.52.0 \
+ crate://crates.io/windows_x86_64_msvc/0.48.5 \
+ crate://crates.io/windows_x86_64_msvc/0.52.6 \
+ crate://crates.io/winnow/0.6.20 \
+ crate://crates.io/wyz/0.5.1 \
crate://crates.io/xattr/1.3.1 \
- crate://crates.io/yansi/0.5.1 \
+ crate://crates.io/yansi/1.0.1 \
crate://crates.io/z85/3.0.5 \
- crate://crates.io/zip/0.6.6 \
+ crate://crates.io/zerocopy/0.7.34 \
+ crate://crates.io/zerocopy-derive/0.7.34 \
+ crate://crates.io/zip/1.1.4 \
"
SRC_URI[adler-1.0.2.sha256sum] = "f26201604c87b1e01bd3d98f8d5d9a8fcbb815e8cedb41ffccbeb4bf593a35fe"
-SRC_URI[aho-corasick-1.0.4.sha256sum] = "6748e8def348ed4d14996fa801f4122cd763fff530258cdc03f64b25f89d3a5a"
+SRC_URI[ahash-0.8.11.sha256sum] = "e89da841a80418a9b391ebaea17f5c112ffaaa96f621d2c285b5174da76b9011"
+SRC_URI[aho-corasick-1.1.3.sha256sum] = "8e60d3430d3a69478ad0993f19238d2df97c507009a52b3c10addcd7f6bcb916"
+SRC_URI[allocator-api2-0.2.18.sha256sum] = "5c6cb57a04249c6480766f7f7cef5467412af1490f8d1e243141daddada3264f"
SRC_URI[android-tzdata-0.1.1.sha256sum] = "e999941b234f3131b00bc13c22d06e8c5ff726d1b6318ac7eb276997bbb4fef0"
SRC_URI[android_system_properties-0.1.5.sha256sum] = "819e7219dbd41043ac279b19830f2efc897156490d7fd6ea916720117ee66311"
+SRC_URI[ansi-width-0.1.0.sha256sum] = "219e3ce6f2611d83b51ec2098a12702112c29e57203a6b0a0929b2cddb486608"
SRC_URI[anstream-0.5.0.sha256sum] = "b1f58811cfac344940f1a400b6e6231ce35171f614f26439e80f8c1465c5cc0c"
SRC_URI[anstyle-1.0.0.sha256sum] = "41ed9a86bf92ae6580e0a31281f65a1b1d867c0cc68d5346e2ae128dddfa6a7d"
SRC_URI[anstyle-parse-0.2.0.sha256sum] = "e765fd216e48e067936442276d1d57399e37bce53c264d6fefbe298080cb57ee"
SRC_URI[anstyle-query-1.0.0.sha256sum] = "5ca11d4be1bab0c8bc8734a9aa7bf4ee8316d462a08c6ac5052f888fef5b494b"
SRC_URI[anstyle-wincon-2.1.0.sha256sum] = "58f54d10c6dfa51283a066ceab3ec1ab78d13fae00aa49243a45e4571fb79dfd"
+SRC_URI[arbitrary-1.3.2.sha256sum] = "7d5a26814d8dcb93b0e5a0ff3c6d80a8843bafb21b39e8e18a6f05471870e110"
SRC_URI[arrayref-0.3.6.sha256sum] = "a4c527152e37cf757a3f78aae5a06fbeefdb07ccc535c980a3208ee3060dd544"
SRC_URI[arrayvec-0.7.4.sha256sum] = "96d30a06541fbafbc7f82ed10c06164cfbd2c401138f6addd8404629c4b16711"
SRC_URI[autocfg-1.1.0.sha256sum] = "d468802bab17cbc0cc575e9b053f41e72aa36bfa6b7f55e3529ffa43161b97fa"
-SRC_URI[bigdecimal-0.4.0.sha256sum] = "5274a6b6e0ee020148397245b973e30163b7bffbc6d473613f850cb99888581e"
+SRC_URI[bigdecimal-0.4.6.sha256sum] = "8f850665a0385e070b64c38d2354e6c104c8479c59868d1e48a0c13ee2c7a1c1"
SRC_URI[binary-heap-plus-0.5.0.sha256sum] = "e4551d8382e911ecc0d0f0ffb602777988669be09447d536ff4388d1def11296"
-SRC_URI[bindgen-0.63.0.sha256sum] = "36d860121800b2a9a94f9b5604b332d5cffb234ce17609ea479d723dbc9d3885"
+SRC_URI[bincode-1.3.3.sha256sum] = "b1f45e9417d87227c7a56d22e471c6206462cba514c7590c09aff4cf6d1ddcad"
+SRC_URI[bindgen-0.69.5.sha256sum] = "271383c67ccabffb7381723dea0672a673f292304fcb45c01cc648c7a8d58088"
+SRC_URI[bit-set-0.5.3.sha256sum] = "0700ddab506f33b20a03b13996eccd309a48e5ff77d0d95926aa0210fb4e95f1"
+SRC_URI[bit-vec-0.6.3.sha256sum] = "349f9b6a179ed607305526ca489b34ad0a41aed5f7980fa90eb03160b69598fb"
SRC_URI[bitflags-1.3.2.sha256sum] = "bef38d45163c2f1dde094a7dfd33ccf595c92905c8f8f4fdc18d06fb1037718a"
-SRC_URI[bitflags-2.4.2.sha256sum] = "ed570934406eb16438a4e976b1b4500774099c13b8cb96eec99f620f05090ddf"
+SRC_URI[bitflags-2.6.0.sha256sum] = "b048fb63fd8b5923fc5aa7b340d8e156aec7ec02f0c78fa8a6ddc2613f6f71de"
+SRC_URI[bitvec-1.0.1.sha256sum] = "1bc2832c24239b0141d5674bb9174f9d68a8b5b3f2753311927c172ca46f7e9c"
SRC_URI[blake2b_simd-1.0.2.sha256sum] = "23285ad32269793932e830392f2fe2f83e26488fd3ec778883a93c8323735780"
-SRC_URI[blake3-1.5.1.sha256sum] = "30cca6d3674597c30ddf2c587bf8d9d65c9a84d2326d941cc79c9842dfe0ef52"
+SRC_URI[blake3-1.5.4.sha256sum] = "d82033247fd8e890df8f740e407ad4d038debb9eb1f40533fffb32e7d17dc6f7"
SRC_URI[block-buffer-0.10.3.sha256sum] = "69cce20737498f97b993470a6e536b8523f0af7892a4f928cceb1ac5e52ebe7e"
-SRC_URI[bstr-1.9.1.sha256sum] = "05efc5cfd9110c8416e471df0e96702d58690178e206e61b7173706673c93706"
+SRC_URI[bstr-1.10.0.sha256sum] = "40723b8fb387abc38f4f4a37c09073622e41dd12327033091ef8950659e6dc0c"
SRC_URI[bumpalo-3.11.1.sha256sum] = "572f695136211188308f16ad2ca5c851a712c464060ae6974944458eb83880ba"
-SRC_URI[bytecount-0.6.7.sha256sum] = "e1e5f035d16fc623ae5f74981db80a439803888314e3a555fd6f04acd51a3205"
+SRC_URI[bytecount-0.6.8.sha256sum] = "5ce89b21cab1437276d2650d57e971f9d548a2d9037cc231abdc0562b97498ce"
SRC_URI[byteorder-1.5.0.sha256sum] = "1fd0f2584146f6f2ef48085050886acf353beff7305ebd1ae69500e27c67f64b"
-SRC_URI[cc-1.0.79.sha256sum] = "50d30906286121d95be3d479533b458f87493b30a4b5f79a607db8f5d11aa91f"
+SRC_URI[cc-1.1.13.sha256sum] = "72db2f7947ecee9b03b510377e8bb9077afa27176fdbff55c51027e976fdcc48"
SRC_URI[cexpr-0.6.0.sha256sum] = "6fac387a98bb7c37292057cffc56d62ecb629900026402633ae9160df93a8766"
SRC_URI[cfg-if-1.0.0.sha256sum] = "baf1de4339761588bc0619e3cbc0120ee582ebb74b53b4efbf79117bd2da40fd"
-SRC_URI[cfg_aliases-0.1.1.sha256sum] = "fd16c4719339c4530435d38e511904438d07cce7950afa3718a84ac36c10e89e"
-SRC_URI[chrono-0.4.35.sha256sum] = "8eaf5903dcbc0a39312feb77df2ff4c76387d591b9fc7b04a238dcf8bb62639a"
+SRC_URI[cfg_aliases-0.2.1.sha256sum] = "613afe47fcd5fac7ccf1db93babcb082c5994d996f20b8b159f2ad1658eb5724"
+SRC_URI[chrono-0.4.38.sha256sum] = "a21f936df1771bf62b77f047b726c4625ff2e8aa607c01ec06e5a05bd8463401"
SRC_URI[clang-sys-1.4.0.sha256sum] = "fa2e27ae6ab525c3d369ded447057bca5438d86dc3a68f6faafb8269ba82ebf3"
SRC_URI[clap-4.4.2.sha256sum] = "6a13b88d2c62ff462f88e4a121f17a82c1af05693a2f192b5c38d14de73c19f6"
SRC_URI[clap_builder-4.4.2.sha256sum] = "2bb9faaa7c2ef94b2743a21f5a29e6f0010dff4caa69ac8e9d6cf8b6fa74da08"
@@ -323,7 +375,6 @@ SRC_URI[console-0.15.8.sha256sum] = "0e1f83fc076bd6dd27517eacdf25fef6c4dfe5f1d74
SRC_URI[const-random-0.1.16.sha256sum] = "11df32a13d7892ec42d51d3d175faba5211ffe13ed25d4fb348ac9e9ce835593"
SRC_URI[const-random-macro-0.1.16.sha256sum] = "f9d839f2a20b0aee515dc581a6172f2321f96cab76c1a38a4c584a194955390e"
SRC_URI[constant_time_eq-0.3.0.sha256sum] = "f7144d30dcf0fafbce74250a3963025d8d52177934239851c917d29f1df280c2"
-SRC_URI[conv-0.3.3.sha256sum] = "78ff10625fd0ac447827aa30ea8b861fead473bb60aeb73af6c1c58caf0d1299"
SRC_URI[core-foundation-sys-0.8.3.sha256sum] = "5827cebf4670468b8772dd191856768aedcb1b0278a04f989f7766351917b9dc"
SRC_URI[coz-0.1.3.sha256sum] = "cef55b3fe2f5477d59e12bc792e8b3c95a25bd099eadcfae006ecea136de76e2"
SRC_URI[cpp-0.5.9.sha256sum] = "bfa65869ef853e45c60e9828aa08cdd1398cb6e13f3911d9cb2a079b144fcd64"
@@ -331,67 +382,74 @@ SRC_URI[cpp_build-0.5.9.sha256sum] = "0e361fae2caf9758164b24da3eedd7f7d7451be30d
SRC_URI[cpp_common-0.5.9.sha256sum] = "3e1a2532e4ed4ea13031c13bc7bc0dbca4aae32df48e9d77f0d1e743179f2ea1"
SRC_URI[cpp_macros-0.5.9.sha256sum] = "47ec9cc90633446f779ef481a9ce5a0077107dd5b87016440448d908625a83fd"
SRC_URI[cpufeatures-0.2.5.sha256sum] = "28d997bd5e24a5928dd43e46dc529867e207907fe0b239c3477d924f7f2ca320"
-SRC_URI[crc32fast-1.3.2.sha256sum] = "b540bd8bc810d3885c6ea91e2018302f68baba2129ab3e88f32389ee9370880d"
+SRC_URI[crc32fast-1.4.0.sha256sum] = "b3855a8a784b474f333699ef2bbca9db2c4a1f6d9088a90a2d25b1eb53111eaa"
SRC_URI[crossbeam-channel-0.5.10.sha256sum] = "82a9b73a36529d9c47029b9fb3a6f0ea3cc916a261195352ba19e770fc1748b2"
SRC_URI[crossbeam-deque-0.8.4.sha256sum] = "fca89a0e215bab21874660c67903c5f143333cab1da83d041c7ded6053774751"
SRC_URI[crossbeam-epoch-0.9.17.sha256sum] = "0e3681d554572a651dda4186cd47240627c3d0114d45a95f6ad27f2f22e7548d"
-SRC_URI[crossbeam-utils-0.8.18.sha256sum] = "c3a430a770ebd84726f584a90ee7f020d28db52c6d02138900f22341f866d39c"
+SRC_URI[crossbeam-utils-0.8.19.sha256sum] = "248e3bacc7dc6baa3b21e405ee045c3047101a49145e7e9eca583ab4c2ca5345"
SRC_URI[crossterm-0.27.0.sha256sum] = "f476fe445d41c9e991fd07515a6f463074b782242ccf4a5b7b1d1012e70824df"
SRC_URI[crossterm_winapi-0.9.1.sha256sum] = "acdd7c62a3665c7f6830a51635d9ac9b23ed385797f70a83bb8bafe9c572ab2b"
SRC_URI[crunchy-0.2.2.sha256sum] = "7a81dae078cea95a014a339291cec439d2f232ebe854a9d672b796c6afafa9b7"
SRC_URI[crypto-common-0.1.6.sha256sum] = "1bfb12502f3fc46cca1bb51ac28df9d618d813cdc3d2f25b9fe775a34af26bb3"
-SRC_URI[ctrlc-3.4.4.sha256sum] = "672465ae37dc1bc6380a6547a8883d5dd397b0f1faaad4f265726cc7042a5345"
-SRC_URI[custom_derive-0.1.7.sha256sum] = "ef8ae57c4978a2acd8b869ce6b9ca1dfe817bff704c220209fdef2c0b75a01b9"
-SRC_URI[data-encoding-2.5.0.sha256sum] = "7e962a19be5cfc3f3bf6dd8f61eb50107f356ad6270fbb3ed41476571db78be5"
-SRC_URI[data-encoding-macro-0.1.14.sha256sum] = "20c01c06f5f429efdf2bae21eb67c28b3df3cf85b7dd2d8ef09c0838dac5d33e"
-SRC_URI[data-encoding-macro-internal-0.1.12.sha256sum] = "0047d07f2c89b17dd631c80450d69841a6b5d7fb17278cbc43d7e4cfcf2576f3"
+SRC_URI[ctrlc-3.4.5.sha256sum] = "90eeab0aa92f3f9b4e87f258c72b139c207d251f9cbc1080a0086b86a8870dd3"
+SRC_URI[data-encoding-2.6.0.sha256sum] = "e8566979429cf69b49a5c740c60791108e86440e8be149bbea4fe54d2c32d6e2"
+SRC_URI[data-encoding-macro-0.1.15.sha256sum] = "f1559b6cba622276d6d63706db152618eeb15b89b3e4041446b05876e352e639"
+SRC_URI[data-encoding-macro-internal-0.1.13.sha256sum] = "332d754c0af53bc87c108fed664d121ecf59207ec4196041f04d6ab9002ad33f"
+SRC_URI[deranged-0.3.11.sha256sum] = "b42b6fa04a440b495c8b04d0e71b707c585f83cb9cb28cf8cd0d976c315e31b4"
+SRC_URI[derive_arbitrary-1.3.2.sha256sum] = "67e77553c4162a157adbf834ebae5b415acbecbeafc7a74b0e886657506a7611"
SRC_URI[diff-0.1.13.sha256sum] = "56254986775e3233ffa9c4d7d3faaf6d36a2c09d30b20687e9f88bc8bafc16c8"
SRC_URI[digest-0.10.7.sha256sum] = "9ed9a281f7bc9b7576e61468ba615a66a5c8cfdff42420a70aa82701a3b1e292"
+SRC_URI[displaydoc-0.2.4.sha256sum] = "487585f4d0c6655fe74905e2504d8ad6908e4db67f744eb140876906c2f3175d"
SRC_URI[dlv-list-0.5.0.sha256sum] = "d529fd73d344663edfd598ccb3f344e46034db51ebd103518eae34338248ad73"
SRC_URI[dns-lookup-2.0.4.sha256sum] = "e5766087c2235fec47fafa4cfecc81e494ee679d0fd4a59887ea0919bfb0e4fc"
-SRC_URI[dunce-1.0.4.sha256sum] = "56ce8c6da7551ec6c462cbaf3bfbc75131ebbfa1c944aeaa9dab51ca1c5f0c3b"
+SRC_URI[dunce-1.0.5.sha256sum] = "92773504d58c093f6de2459af4af33faa518c13451eb8f2b5698ed3d36e7c813"
SRC_URI[either-1.8.0.sha256sum] = "90e5c1c8368803113bf0c9584fc495a58b86dc8a29edbf8fe877d21d9507e797"
SRC_URI[encode_unicode-0.3.6.sha256sum] = "a357d28ed41a50f9c765dbfe56cbc04a64e53e5fc58ba79fbc34c10ef3df831f"
-SRC_URI[env_logger-0.8.4.sha256sum] = "a19187fea3ac7e84da7dacf48de0c45d63c6a76f9490dae389aead16c243fce3"
+SRC_URI[equivalent-1.0.1.sha256sum] = "5443807d6dff69373d433ab9ef5378ad8df50ca6298caf15de6e52e24aaf54d5"
SRC_URI[errno-0.3.8.sha256sum] = "a258e46cdc063eb8519c00b9fc845fc47bcfca4130e2f08e88665ceda8474245"
SRC_URI[exacl-0.12.0.sha256sum] = "22be12de19decddab85d09f251ec8363f060ccb22ec9c81bc157c0c8433946d8"
-SRC_URI[fastrand-2.0.1.sha256sum] = "25cbce373ec4653f1a01a31e8a5e5ec0c622dc27ff9c4e6606eefef5cbbed4a5"
+SRC_URI[fastrand-2.1.1.sha256sum] = "e8c02a5121d4ea3eb16a80748c74f5549a5665e4c21333c6098f283870fbdea6"
SRC_URI[file_diff-1.0.0.sha256sum] = "31a7a908b8f32538a2143e59a6e4e2508988832d5d4d6f7c156b3cbc762643a5"
-SRC_URI[filetime-0.2.23.sha256sum] = "1ee447700ac8aa0b2f2bd7bc4462ad686ba06baa6727ac149a2d6277f0d240fd"
-SRC_URI[flate2-1.0.24.sha256sum] = "f82b0f4c27ad9f8bfd1f3208d882da2b09c301bc1c828fd3a00d0216d2fbbff6"
+SRC_URI[filedescriptor-0.8.2.sha256sum] = "7199d965852c3bac31f779ef99cbb4537f80e952e2d6aa0ffeb30cce00f4f46e"
+SRC_URI[filetime-0.2.25.sha256sum] = "35c0522e981e68cbfa8c3f978441a5f34b30b96e146b33cd3359176b50fe8586"
+SRC_URI[flate2-1.0.28.sha256sum] = "46303f565772937ffe1d394a4fac6f411c6013172fadde9dcdb1e147a086940e"
SRC_URI[fnv-1.0.7.sha256sum] = "3f9eec918d3f24069decb9af1554cad7c880e2da24a9afd88aca000531ab82c1"
SRC_URI[fs_extra-1.3.0.sha256sum] = "42703706b716c37f96a77aea830392ad231f44c9e9a67872fa5548707e11b11c"
SRC_URI[fsevent-sys-4.1.0.sha256sum] = "76ee7a02da4d231650c7cea31349b889be2f45ddb3ef3032d2ec8185f6313fd2"
-SRC_URI[fts-sys-0.2.4.sha256sum] = "9a66c0a21e344f20c87b4ca12643cf4f40a7018f132c98d344e989b959f49dd1"
-SRC_URI[fundu-2.0.0.sha256sum] = "6c04cb831a8dccadfe3774b07cba4574a1ec24974d761510e65d8a543c2d7cb4"
-SRC_URI[fundu-core-0.3.0.sha256sum] = "76a889e633afd839fb5b04fe53adfd588cefe518e71ec8d3c929698c6daf2acd"
-SRC_URI[futures-0.3.28.sha256sum] = "23342abe12aba583913b2e62f22225ff9c950774065e4bfb61a19cd9770fec40"
-SRC_URI[futures-channel-0.3.28.sha256sum] = "955518d47e09b25bbebc7a18df10b81f0c766eaf4c4f1cccef2fca5f2a4fb5f2"
-SRC_URI[futures-core-0.3.28.sha256sum] = "4bca583b7e26f571124fe5b7561d49cb2868d79116cfa0eefce955557c6fee8c"
-SRC_URI[futures-executor-0.3.28.sha256sum] = "ccecee823288125bd88b4d7f565c9e58e41858e47ab72e8ea2d64e93624386e0"
-SRC_URI[futures-io-0.3.28.sha256sum] = "4fff74096e71ed47f8e023204cfd0aa1289cd54ae5430a9523be060cdb849964"
-SRC_URI[futures-macro-0.3.28.sha256sum] = "89ca545a94061b6365f2c7355b4b32bd20df3ff95f02da9329b34ccc3bd6ee72"
-SRC_URI[futures-sink-0.3.28.sha256sum] = "f43be4fe21a13b9781a69afa4985b0f6ee0e1afab2c6f454a8cf30e2b2237b6e"
-SRC_URI[futures-task-0.3.28.sha256sum] = "76d3d132be6c0e6aa1534069c705a74a5997a356c0dc2f86a47765e5617c5b65"
-SRC_URI[futures-timer-3.0.2.sha256sum] = "e64b03909df88034c26dc1547e8970b91f98bdb65165d6a4e9110d94263dbb2c"
-SRC_URI[futures-util-0.3.28.sha256sum] = "26b01e40b772d54cf6c6d721c1d1abd0647a0106a12ecaa1c186273392a69533"
+SRC_URI[fts-sys-0.2.9.sha256sum] = "4e184d5f593d19793f26afb6f9a58d25f0bc755c4e48890ffcba6db416153ebb"
+SRC_URI[fundu-2.0.1.sha256sum] = "2ce12752fc64f35be3d53e0a57017cd30970f0cffd73f62c791837d8845badbd"
+SRC_URI[fundu-core-0.3.1.sha256sum] = "e463452e2d8b7600d38dcea1ed819773a57f0d710691bfc78db3961bd3f4c3ba"
+SRC_URI[funty-2.0.0.sha256sum] = "e6d5a32815ae3f33302d95fdcb2ce17862f8c65363dcfd29360480ba1001fc9c"
+SRC_URI[futures-0.3.30.sha256sum] = "645c6916888f6cb6350d2550b80fb63e734897a8498abe35cfb732b6487804b0"
+SRC_URI[futures-channel-0.3.31.sha256sum] = "2dff15bf788c671c1934e366d07e30c1814a8ef514e1af724a602e8a2fbe1b10"
+SRC_URI[futures-core-0.3.31.sha256sum] = "05f29059c0c2090612e8d742178b0580d2dc940c837851ad723096f87af6663e"
+SRC_URI[futures-executor-0.3.30.sha256sum] = "a576fc72ae164fca6b9db127eaa9a9dda0d61316034f33a0a0d4eda41f02b01d"
+SRC_URI[futures-io-0.3.31.sha256sum] = "9e5c1b78ca4aae1ac06c48a526a655760685149f0d465d21f37abfe57ce075c6"
+SRC_URI[futures-macro-0.3.31.sha256sum] = "162ee34ebcb7c64a8abebc059ce0fee27c2262618d7b60ed8faf72fef13c3650"
+SRC_URI[futures-sink-0.3.31.sha256sum] = "e575fab7d1e0dcb8d0c7bcf9a63ee213816ab51902e6d244a95819acacf1d4f7"
+SRC_URI[futures-task-0.3.31.sha256sum] = "f90f7dce0722e95104fcb095585910c0977252f286e354b5e3bd38902cd99988"
+SRC_URI[futures-timer-3.0.3.sha256sum] = "f288b0a4f20f9a56b5d1da57e2227c661b7b16168e2f72365f57b63326e29b24"
+SRC_URI[futures-util-0.3.31.sha256sum] = "9fa08315bb612088cc391249efdc3bc77536f16c91f6cf495e6fbe85b20a4a81"
SRC_URI[gcd-2.3.0.sha256sum] = "1d758ba1b47b00caf47f24925c0074ecb20d6dfcffe7f6d53395c0465674841a"
SRC_URI[generic-array-0.14.6.sha256sum] = "bff49e947297f3312447abdca79f45f4738097cc82b06e72054d2223f601f1b9"
SRC_URI[getrandom-0.2.9.sha256sum] = "c85e1d9ab2eadba7e5040d4e09cbd6d072b76a557ad64e797c2cb9d4da21d7e4"
SRC_URI[glob-0.3.1.sha256sum] = "d2fabcfbdc87f4758337ca535fb41a6d701b65693ce38287d856d1674551ec9b"
-SRC_URI[half-2.4.0.sha256sum] = "b5eceaaeec696539ddaf7b333340f1af35a5aa87ae3e4f3ead0532f72affab2e"
-SRC_URI[hashbrown-0.13.2.sha256sum] = "43a3c133739dddd0d2990f9a4bdf8eb4b21ef50e4851ca85ab661199821d510e"
+SRC_URI[half-2.4.1.sha256sum] = "6dd08c532ae367adf81c312a4580bc67f1d0fe8bc9c460520283f4c0ff277888"
+SRC_URI[hashbrown-0.14.3.sha256sum] = "290f1a1d9242c78d09ce40a5e87e7554ee637af1351968159f4952f028f75604"
SRC_URI[hermit-abi-0.3.2.sha256sum] = "443144c8cdadd93ebf52ddb4056d257f5b52c04d3c804e657d19eb73fc33668b"
SRC_URI[hex-0.4.3.sha256sum] = "7f24254aa9a54b5c858eaee2f5bccdb46aaf0e486a595ed5fd8f86ba55232a70"
SRC_URI[hex-literal-0.4.1.sha256sum] = "6fe2267d4ed49bc07b63801559be28c718ea06c4738b7a03c94df7386d2cde46"
-SRC_URI[hostname-0.3.1.sha256sum] = "3c731c3e10504cc8ed35cfe2f1db4c9274c3d35fa486e3b31df46f068ef3e867"
+SRC_URI[home-0.5.9.sha256sum] = "e3d1354bf6b7235cb4a0576c2619fd4ed18183f689b12b006a0ee7329eeff9a5"
+SRC_URI[hostname-0.4.0.sha256sum] = "f9c7c7c8ac16c798734b8a24560c1362120597c40d5e1459f09498f8f6c8f2ba"
SRC_URI[iana-time-zone-0.1.53.sha256sum] = "64c122667b287044802d6ce17ee2ddf13207ed924c712de9a66a5814d5b64765"
SRC_URI[iana-time-zone-haiku-0.1.2.sha256sum] = "f31827a206f56af32e590ba56d5d2d085f558508192593743f16b2306495269f"
-SRC_URI[indicatif-0.17.3.sha256sum] = "cef509aa9bc73864d6756f0d34d35504af3cf0844373afe9b8669a5b8005a729"
+SRC_URI[indexmap-2.5.0.sha256sum] = "68b900aa2f7301e21c36462b170ee99994de34dff39a4a6a528e80e7376d07e5"
+SRC_URI[indicatif-0.17.9.sha256sum] = "cbf675b85ed934d3c67b5c5469701eec7db22689d0a2139d856e0925fa28b281"
SRC_URI[inotify-0.9.6.sha256sum] = "f8069d3ec154eb856955c1c0fbffefbf5f3c40a104ec912d4797314c1801abff"
SRC_URI[inotify-sys-0.1.5.sha256sum] = "e05c02b5e89bff3b946cedeca278abc628fe811e604f027c45a8aa3cf793d0eb"
SRC_URI[io-lifetimes-1.0.11.sha256sum] = "eae7b9aee968036d54dce06cebaefd919e4472e753296daccd6d344e3e2df0c2"
SRC_URI[itertools-0.12.1.sha256sum] = "ba291022dbbd398a455acf126c1e341954079855bc60dfdda641363bd6922569"
+SRC_URI[itertools-0.13.0.sha256sum] = "413ee7dfc52ee1a4949ceeb7dbc8a33f2d6c088194d9f922fb8318faf1f01186"
SRC_URI[itoa-1.0.4.sha256sum] = "4217ad341ebadf8d8e724e264f13e593e0648f5b3e94b3896a5df283be015ecc"
SRC_URI[js-sys-0.3.64.sha256sum] = "c5f195fe497f702db0f318b07fdd68edb16955aed830df8363d837542f8f935a"
SRC_URI[keccak-0.1.4.sha256sum] = "8f6d5ed8676d904364de097082f4e7d240b571b67989ced0240f08b7f966f940"
@@ -399,39 +457,44 @@ SRC_URI[kqueue-1.0.7.sha256sum] = "2c8fc60ba15bf51257aa9807a48a61013db043fcf3a78
SRC_URI[kqueue-sys-1.0.3.sha256sum] = "8367585489f01bc55dd27404dcf56b95e6da061a256a666ab23be9ba96a2e587"
SRC_URI[lazy_static-1.4.0.sha256sum] = "e2abad23fbc42b3700f2f279844dc832adb2b2eb069b2df918f455c4e18cc646"
SRC_URI[lazycell-1.3.0.sha256sum] = "830d08ce1d1d941e6b30645f1a0eb5643013d835ce3779a5fc208261dbe10f55"
-SRC_URI[libc-0.2.153.sha256sum] = "9c198f91728a82281a64e1f4f9eeb25d82cb32a5de251c6bd1b5154d63a8e7bd"
+SRC_URI[libc-0.2.161.sha256sum] = "8e9489c2807c139ffd9c1794f4af0ebe86a828db53ecdc7fea2111d0fed085d1"
SRC_URI[libloading-0.7.4.sha256sum] = "b67380fd3b2fbe7527a606e18729d21c6f3951633d0500574c4dc22d2d638b9f"
SRC_URI[libm-0.2.7.sha256sum] = "f7012b1bbb0719e1097c47611d3898568c546d597c2e74d66f6087edd5233ff4"
+SRC_URI[libredox-0.1.3.sha256sum] = "c0ff37bd590ca25063e35af745c343cb7a0271906fb7b37e4813e8f79f00268d"
SRC_URI[linux-raw-sys-0.3.8.sha256sum] = "ef53942eb7bf7ff43a617b3e2c1c4a5ecf5944a7c1bc12d7ee39bbb15e5c1519"
-SRC_URI[linux-raw-sys-0.4.12.sha256sum] = "c4cd1a83af159aa67994778be9070f0ae1bd732942279cabb14f86f986a21456"
+SRC_URI[linux-raw-sys-0.4.14.sha256sum] = "78b3ae25bc7c8c38cec158d1f2757ee79e9b3740fbc7ccf0e59e4b08d793fa89"
SRC_URI[lock_api-0.4.9.sha256sum] = "435011366fe56583b16cf956f9df0095b405b82d76425bc8981c0e22e60ec4df"
SRC_URI[log-0.4.20.sha256sum] = "b5e6163cb8c49088c2c36f57875e58ccd8c87c7427f7fbd50ea6710b2f3f2e8f"
-SRC_URI[lscolors-0.16.0.sha256sum] = "ab0b209ec3976527806024406fe765474b9a1750a0ed4b8f0372364741f50e7b"
-SRC_URI[match_cfg-0.1.0.sha256sum] = "ffbee8634e0d45d258acb448e7eaab3fce7a0a467395d4d9f228e3c1f01fb2e4"
+SRC_URI[lru-0.12.3.sha256sum] = "d3262e75e648fce39813cb56ac41f3c3e3f65217ebf3844d818d1f9398cfb0dc"
+SRC_URI[lscolors-0.20.0.sha256sum] = "61183da5de8ba09a58e330d55e5ea796539d8443bd00fdeb863eac39724aa4ab"
SRC_URI[md-5-0.10.6.sha256sum] = "d89e7ee0cfbedfc4da3340218492196241d89eefb6dab27de5df917a6d2e78cf"
-SRC_URI[memchr-2.7.1.sha256sum] = "523dc4f511e55ab87b694dc30d0f820d60906ef06413f93d4d7a1385599cc149"
-SRC_URI[memmap2-0.9.0.sha256sum] = "deaba38d7abf1d4cca21cc89e932e542ba2b9258664d2a9ef0e61512039c9375"
+SRC_URI[memchr-2.7.4.sha256sum] = "78ca9ab1a0babb1e7d5695e3530886289c18cf2f87ec19a575a0abdce112e3a3"
+SRC_URI[memmap2-0.9.5.sha256sum] = "fd3f7eed9d3848f8b98834af67102b720745c4ec028fcd0aa0239277e7de374f"
SRC_URI[minimal-lexical-0.2.1.sha256sum] = "68354c5c6bd36d73ff3feceb05efa59b6acb7626617f4962be322a825e61f79a"
-SRC_URI[miniz_oxide-0.5.4.sha256sum] = "96590ba8f175222643a85693f33d26e9c8a015f599c216509b1a6894af675d34"
+SRC_URI[miniz_oxide-0.7.2.sha256sum] = "9d811f3e15f28568be3407c8e7fdb6514c1cda3cb30683f15b6a1a1dc4ea14a7"
SRC_URI[mio-0.8.11.sha256sum] = "a4a650543ca06a924e8b371db273b2756685faae30f8487da1b56505a8f78b0c"
-SRC_URI[nix-0.28.0.sha256sum] = "ab2156c4fce2f8df6c499cc1c763e4394b7482525bf2a9701c9d79d215f519e4"
+SRC_URI[nix-0.29.0.sha256sum] = "71e2746dc3a24dd78b3cfcb7be93368c6de9963d30f43a6a73998a9cf4b17b46"
SRC_URI[nom-7.1.3.sha256sum] = "d273983c5a657a70a3e8f2a01329822f3b8c8172b73826411a55751e404a0a4a"
SRC_URI[notify-6.0.1.sha256sum] = "5738a2795d57ea20abec2d6d76c6081186709c0024187cd5977265eda6598b51"
-SRC_URI[nu-ansi-term-0.49.0.sha256sum] = "c073d3c1930d0751774acf49e66653acecb416c3a54c6ec095a9b11caddb5a68"
-SRC_URI[num-bigint-0.4.4.sha256sum] = "608e7659b5c3d7cba262d894801b9ec9d00de989e8a82bd4bef91d08da45cdc0"
-SRC_URI[num-integer-0.1.45.sha256sum] = "225d3389fb3509a24c93f5c29eb6bde2586b98d9f016636dff58d7c6f7569cd9"
-SRC_URI[num-traits-0.2.18.sha256sum] = "da0df0e5185db44f69b44f26786fe401b6c293d1907744beaa7fa62b2e5a517a"
+SRC_URI[nu-ansi-term-0.50.0.sha256sum] = "dd2800e1520bdc966782168a627aa5d1ad92e33b984bf7c7615d31280c83ff14"
+SRC_URI[num-bigint-0.4.6.sha256sum] = "a5e44f723f1133c9deac646763579fdb3ac745e418f2a7af9cd0c431da1f20b9"
+SRC_URI[num-conv-0.1.0.sha256sum] = "51d515d32fb182ee37cda2ccdcb92950d6a3c2893aa280e540671c2cd0f3b1d9"
+SRC_URI[num-integer-0.1.46.sha256sum] = "7969661fd2958a5cb096e56c8e1ad0444ac2bbcd0061bd28660485a44879858f"
+SRC_URI[num-modular-0.5.1.sha256sum] = "64a5fe11d4135c3bcdf3a95b18b194afa9608a5f6ff034f5d857bc9a27fb0119"
+SRC_URI[num-prime-0.4.4.sha256sum] = "e238432a7881ec7164503ccc516c014bf009be7984cde1ba56837862543bdec3"
+SRC_URI[num-traits-0.2.19.sha256sum] = "071dfc062690e90b734c0b2273ce72ad0ffa95f0c74596bc250dcfd960262841"
+SRC_URI[num_enum-0.7.3.sha256sum] = "4e613fc340b2220f734a8595782c551f1250e969d87d3be1ae0579e8d4065179"
+SRC_URI[num_enum_derive-0.7.3.sha256sum] = "af1844ef2428cc3e1cb900be36181049ef3d3193c63e43026cfe202983b27a56"
SRC_URI[num_threads-0.1.6.sha256sum] = "2819ce041d2ee131036f4fc9d6ae7ae125a3a40e97ba64d04fe799ad9dabbb44"
SRC_URI[number_prefix-0.4.0.sha256sum] = "830b246a0e5f20af87141b25c173cd1b609bd7779a4617d6ec582abaf90870f3"
-SRC_URI[once_cell-1.19.0.sha256sum] = "3fdb12b2476b595f9358c5161aa467c2438859caa136dec86c26fdd2efe17b92"
+SRC_URI[once_cell-1.20.2.sha256sum] = "1261fe7e33c73b354eab43b1273a57c8f967d0391e80353e51f764ac02cf6775"
SRC_URI[onig-6.4.0.sha256sum] = "8c4b31c8722ad9171c6d77d3557db078cab2bd50afcc9d09c8b315c59df8ca4f"
SRC_URI[onig_sys-69.8.1.sha256sum] = "7b829e3d7e9cc74c7e315ee8edb185bf4190da5acde74afd7fc59c35b1f086e7"
-SRC_URI[ordered-multimap-0.6.0.sha256sum] = "4ed8acf08e98e744e5384c8bc63ceb0364e68a6854187221c18df61c4797690e"
+SRC_URI[ordered-multimap-0.7.3.sha256sum] = "49203cdcae0030493bad186b28da2fa25645fa276a51b6fec8010d281e02ef79"
SRC_URI[os_display-0.1.3.sha256sum] = "7a6229bad892b46b0dcfaaeb18ad0d2e56400f5aaea05b768bde96e73676cf75"
SRC_URI[parking_lot-0.12.1.sha256sum] = "3742b2c103b9f06bc9fff0a37ff4912935851bee6d36f3c02bcc755bcfec228f"
-SRC_URI[parking_lot_core-0.9.9.sha256sum] = "4c42a9226546d68acdd9c0a280d17ce19bfe27a46bf68784e4066115788d008e"
-SRC_URI[parse_datetime-0.5.0.sha256sum] = "3bbf4e25b13841080e018a1e666358adfe5e39b6d353f986ca5091c210b586a1"
-SRC_URI[peeking_take_while-0.1.2.sha256sum] = "19b17cddbe7ec3f8bc800887bab5e717348c95ea2ca0b1bf0837fb964dc67099"
+SRC_URI[parking_lot_core-0.9.10.sha256sum] = "1e401f977ab385c9e4e3ab30627d6f26d00e2c73eef317493c4ec6d468726cf8"
+SRC_URI[parse_datetime-0.6.0.sha256sum] = "a8720474e3dd4af20cea8716703498b9f3b690f318fa9d9d9e2e38eaf44b96d0"
SRC_URI[phf-0.11.2.sha256sum] = "ade2d8b8f33c7333b51bcf0428d37e217e9f32192ae4772156f65063b8ce03dc"
SRC_URI[phf_codegen-0.11.2.sha256sum] = "e8d39688d359e6b34654d328e262234662d16cc0f60ec8dcbe5e718709342a5a"
SRC_URI[phf_generator-0.11.1.sha256sum] = "b1181c94580fa345f50f19d738aaa39c0ed30a600d95cb2d3e23f94266f14fbf"
@@ -439,83 +502,99 @@ SRC_URI[phf_shared-0.11.2.sha256sum] = "90fcb95eef784c2ac79119d1dd819e162b5da872
SRC_URI[pin-project-lite-0.2.9.sha256sum] = "e0a7ae3ac2f1173085d398531c705756c94a4c56843785df85a60c1a0afac116"
SRC_URI[pin-utils-0.1.0.sha256sum] = "8b870d8c151b6f2fb93e84a13146138f05d02ed11c7e7c54f8826aaaf7c9f184"
SRC_URI[pkg-config-0.3.26.sha256sum] = "6ac9a59f73473f1b8d852421e59e64809f025994837ef743615c6d0c5b305160"
-SRC_URI[platform-info-2.0.2.sha256sum] = "d6259c4860e53bf665016f1b2f46a8859cadfa717581dc9d597ae4069de6300f"
-SRC_URI[portable-atomic-0.3.15.sha256sum] = "15eb2c6e362923af47e13c23ca5afb859e83d54452c55b0b9ac763b8f7c1ac16"
+SRC_URI[platform-info-2.0.4.sha256sum] = "91077ffd05d058d70d79eefcd7d7f6aac34980860a7519960f7913b6563a8c3a"
+SRC_URI[portable-atomic-1.6.0.sha256sum] = "7170ef9988bc169ba16dd36a7fa041e5c4cbeb6a35b76d4c03daded371eae7c0"
+SRC_URI[powerfmt-0.2.0.sha256sum] = "439ee305def115ba05938db6eb1644ff94165c5ab5e9420d1c1bcedbba909391"
SRC_URI[ppv-lite86-0.2.17.sha256sum] = "5b40af805b3121feab8a3c29f04d8ad262fa8e0561883e7653e024ae4479e6de"
-SRC_URI[pretty_assertions-1.4.0.sha256sum] = "af7cee1a6c8a5b9208b3cb1061f10c0cb689087b3d8ce85fb9d2dd7a29b6ba66"
-SRC_URI[proc-macro2-1.0.63.sha256sum] = "7b368fba921b0dce7e60f5e04ec15e565b3303972b42bcfde1d0713b881959eb"
-SRC_URI[procfs-0.16.0.sha256sum] = "731e0d9356b0c25f16f33b5be79b1c57b562f141ebfcdb0ad8ac2c13a24293b4"
-SRC_URI[procfs-core-0.16.0.sha256sum] = "2d3554923a69f4ce04c4a754260c338f505ce22642d3830e049a399fc2059a29"
+SRC_URI[pretty_assertions-1.4.1.sha256sum] = "3ae130e2f271fbc2ac3a40fb1d07180839cdbbe443c7a27e1e3c13c5cac0116d"
+SRC_URI[prettyplease-0.2.19.sha256sum] = "5ac2cf0f2e4f42b49f5ffd07dae8d746508ef7526c13940e5f524012ae6c6550"
+SRC_URI[proc-macro-crate-3.2.0.sha256sum] = "8ecf48c7ca261d60b74ab1a7b20da18bede46776b2e55535cb958eb595c5fa7b"
+SRC_URI[proc-macro2-1.0.89.sha256sum] = "f139b0662de085916d1fb67d2b4169d1addddda1919e696f3252b740b629986e"
+SRC_URI[procfs-0.17.0.sha256sum] = "cc5b72d8145275d844d4b5f6d4e1eef00c8cd889edb6035c21675d1bb1f45c9f"
+SRC_URI[procfs-core-0.17.0.sha256sum] = "239df02d8349b06fc07398a3a1697b06418223b1c7725085e801e7c0fc6a12ec"
+SRC_URI[proptest-1.5.0.sha256sum] = "b4c2511913b88df1637da85cc8d96ec8e43a3f8bb8ccb71ee1ac240d6f3df58d"
+SRC_URI[quick-error-1.2.3.sha256sum] = "a1d01941d82fa2ab50be1e79e6714289dd7cde78eba4c074bc5a4374f650dfe0"
SRC_URI[quick-error-2.0.1.sha256sum] = "a993555f31e5a609f617c12db6250dedcac1b0a85076912c436e6fc9b2c8e6a3"
-SRC_URI[quickcheck-1.0.3.sha256sum] = "588f6378e4dd99458b60ec275b4477add41ce4fa9f64dcba6f15adccb19b50d6"
-SRC_URI[quote-1.0.29.sha256sum] = "573015e8ab27661678357f27dc26460738fd2b6c86e46f386fde94cb5d913105"
+SRC_URI[quote-1.0.37.sha256sum] = "b5b9d34b8991d19d98081b46eacdd8eb58c6f2b201139f7c5f643cc155a633af"
+SRC_URI[radium-0.7.0.sha256sum] = "dc33ff2d4973d518d823d61aa239014831e521c75da58e3df4840d3f47749d09"
SRC_URI[rand-0.8.5.sha256sum] = "34af8d1a0e25924bc5b7c43c079c942339d8f0a8b57c39049bef581b46327404"
SRC_URI[rand_chacha-0.3.1.sha256sum] = "e6c10a63a0fa32252be49d21e7709d4d4baf8d231c2dbce1eaa8141b9b127d88"
SRC_URI[rand_core-0.6.4.sha256sum] = "ec0be4795e2f6a28069bec0b5ff3e2ac9bafc99e6a9a7dc3547996c5c816922c"
SRC_URI[rand_pcg-0.3.1.sha256sum] = "59cad018caf63deb318e5a4586d99a24424a364f40f1e5778c29aca23f4fc73e"
-SRC_URI[rayon-1.9.0.sha256sum] = "e4963ed1bc86e4f3ee217022bd855b297cef07fb9eac5dfa1f788b220b49b3bd"
+SRC_URI[rand_xorshift-0.3.0.sha256sum] = "d25bf25ec5ae4a3f1b92f929810509a2f53d7dca2f50b794ff57e3face536c8f"
+SRC_URI[rayon-1.10.0.sha256sum] = "b418a60154510ca1a002a752ca9714984e21e4241e804d32555251faf8b78ffa"
SRC_URI[rayon-core-1.12.1.sha256sum] = "1465873a3dfdaa8ae7cb14b4383657caab0b3e8a0aa9ae8e04b044854c8dfce2"
-SRC_URI[redox_syscall-0.4.1.sha256sum] = "4722d768eff46b75989dd134e5c353f0d6296e5aaa3132e776cbdb56be7731aa"
-SRC_URI[redox_syscall-0.5.0.sha256sum] = "13c178f952cc7eac391f3124bd9851d1ac0bdbc4c9de2d892ccd5f0d8b160e96"
+SRC_URI[redox_syscall-0.5.7.sha256sum] = "9b6dfecf2c74bce2466cabf93f6664d6998a69eb21e39f4207930065b27b771f"
SRC_URI[reference-counted-singleton-0.1.2.sha256sum] = "f1bfbf25d7eb88ddcbb1ec3d755d0634da8f7657b2cb8b74089121409ab8228f"
-SRC_URI[regex-1.10.4.sha256sum] = "c117dbdfde9c8308975b6a18d71f3f385c89461f7b3fb054288ecf2a2058ba4c"
-SRC_URI[regex-automata-0.4.4.sha256sum] = "3b7fa1134405e2ec9353fd416b17f8dacd46c473d7d3fd1cf202706a14eb792a"
-SRC_URI[regex-syntax-0.8.2.sha256sum] = "c08c74e62047bb2de4ff487b251e4a92e24f48745648451635cec7d591162d9f"
-SRC_URI[relative-path-1.8.0.sha256sum] = "4bf2521270932c3c7bed1a59151222bd7643c79310f2916f01925e1e16255698"
-SRC_URI[rlimit-0.10.1.sha256sum] = "3560f70f30a0f16d11d01ed078a07740fe6b489667abc7c7b029155d9f21c3d8"
+SRC_URI[regex-1.11.1.sha256sum] = "b544ef1b4eac5dc2db33ea63606ae9ffcfac26c1416a2806ae0bf5f56b201191"
+SRC_URI[regex-automata-0.4.8.sha256sum] = "368758f23274712b504848e9d5a6f010445cc8b87a7cdb4d7cbee666c1288da3"
+SRC_URI[regex-syntax-0.8.5.sha256sum] = "2b15c43186be67a4fd63bee50d0303afffcef381492ebe2c5d87f324e1b8815c"
+SRC_URI[relative-path-1.9.3.sha256sum] = "ba39f3699c378cd8970968dcbff9c43159ea4cfbd88d43c00b22f2ef10a435d2"
+SRC_URI[rlimit-0.10.2.sha256sum] = "7043b63bd0cd1aaa628e476b80e6d4023a3b50eb32789f2728908107bd0c793a"
SRC_URI[roff-0.2.1.sha256sum] = "b833d8d034ea094b1ea68aa6d5c740e0d04bad9d16568d08ba6f76823a114316"
-SRC_URI[rstest-0.18.2.sha256sum] = "97eeab2f3c0a199bc4be135c36c924b6590b88c377d416494288c14f2db30199"
-SRC_URI[rstest_macros-0.18.2.sha256sum] = "d428f8247852f894ee1be110b375111b586d4fa431f6c46e64ba5a0dcccbe605"
-SRC_URI[rust-ini-0.19.0.sha256sum] = "7e2a3bcec1f113553ef1c88aae6c020a369d03d55b58de9869a0908930385091"
+SRC_URI[rstest-0.23.0.sha256sum] = "0a2c585be59b6b5dd66a9d2084aa1d8bd52fbdb806eafdeffb52791147862035"
+SRC_URI[rstest_macros-0.23.0.sha256sum] = "825ea780781b15345a146be27eaefb05085e337e869bff01b4306a4fd4a9ad5a"
+SRC_URI[rust-ini-0.21.1.sha256sum] = "4e310ef0e1b6eeb79169a1171daf9abcb87a2e17c03bee2c4bb100b55c75409f"
SRC_URI[rustc-hash-1.1.0.sha256sum] = "08d43f7aa6b08d49f382cde6a7982047c3426db949b1424bc4b7ec9ae12c6ce2"
-SRC_URI[rustc_version-0.4.0.sha256sum] = "bfa0f585226d2e68097d4f95d113b15b83a82e819ab25717ec0590d9584ef366"
+SRC_URI[rustc_version-0.4.1.sha256sum] = "cfcb3a22ef46e85b45de6ee7e79d063319ebb6594faafcf1c225ea92ab6e9b92"
SRC_URI[rustix-0.37.26.sha256sum] = "84f3f8f960ed3b5a59055428714943298bf3fa2d4a1d53135084e0544829d995"
-SRC_URI[rustix-0.38.31.sha256sum] = "6ea3e1a662af26cd7a3ba09c0297a31af215563ecf42817c98df621387f4e949"
+SRC_URI[rustix-0.38.37.sha256sum] = "8acb788b847c24f28525660c4d7758620a7210875711f79e7f663cc152726811"
+SRC_URI[rusty-fork-0.3.0.sha256sum] = "cb3dcc6e454c328bb824492db107ab7c0ae8fcffe4ad210136ef014458c1bc4f"
SRC_URI[same-file-1.0.6.sha256sum] = "93fc1dc3aaa9bfed95e02e6eadabb4baf7e3078b0bd1b4d7b6b0b68378900502"
SRC_URI[scopeguard-1.2.0.sha256sum] = "94143f37725109f92c262ed2cf5e59bce7498c01bcc1502d7b9afe439a4e9f49"
-SRC_URI[self_cell-1.0.3.sha256sum] = "58bf37232d3bb9a2c4e641ca2a11d83b5062066f88df7fed36c28772046d65ba"
-SRC_URI[selinux-0.4.0.sha256sum] = "a00576725d21b588213fbd4af84cd7e4cc4304e8e9bd6c0f5a1498a3e2ca6a51"
-SRC_URI[selinux-sys-0.6.2.sha256sum] = "806d381649bb85347189d2350728817418138d11d738e2482cb644ec7f3c755d"
+SRC_URI[self_cell-1.0.4.sha256sum] = "d369a96f978623eb3dc28807c4852d6cc617fed53da5d3c400feff1ef34a714a"
+SRC_URI[selinux-0.4.6.sha256sum] = "0139b2436c81305eb6bda33af151851f75bd62783817b25f44daa371119c30b5"
+SRC_URI[selinux-sys-0.6.9.sha256sum] = "89d45498373dc17ec8ebb72e1fd320c015647b0157fc81dddf678e2e00205fec"
SRC_URI[semver-1.0.14.sha256sum] = "e25dfac463d778e353db5be2449d1cce89bd6fd23c9f1ea21310ce6e5a1b29c4"
-SRC_URI[serde-1.0.193.sha256sum] = "25dd9975e68d0cb5aa1120c288333fc98731bd1dd12f561e468ea4728c042b89"
-SRC_URI[serde_derive-1.0.193.sha256sum] = "43576ca501357b9b071ac53cdc7da8ef0cbd9493d8df094cd821777ea6e894d3"
+SRC_URI[serde-1.0.214.sha256sum] = "f55c3193aca71c12ad7890f1785d2b73e1b9f63a0bbc353c08ef26fe03fc56b5"
+SRC_URI[serde-big-array-0.5.1.sha256sum] = "11fc7cc2c76d73e0f27ee52abbd64eec84d46f370c88371120433196934e4b7f"
+SRC_URI[serde_derive-1.0.214.sha256sum] = "de523f781f095e28fa605cdce0f8307e451cc0fd14e2eb4cd2e98a355b147766"
SRC_URI[sha1-0.10.6.sha256sum] = "e3bf829a2d51ab4a5ddf1352d8470c140cadc8301b2ae1789db023f01cedd6ba"
SRC_URI[sha2-0.10.8.sha256sum] = "793db75ad2bcafc3ffa7c68b215fee268f537982cd901d132f89c6343f3a3dc8"
SRC_URI[sha3-0.10.8.sha256sum] = "75872d278a8f37ef87fa0ddbda7802605cb18344497949862c0d4dcb291eba60"
SRC_URI[shlex-1.3.0.sha256sum] = "0fda2ff0d084019ba4d7c6f371c95d8fd75ce3524c3cb8fb653a3023f6323e64"
SRC_URI[signal-hook-0.3.17.sha256sum] = "8621587d4798caf8eb44879d42e56b9a93ea5dcd315a6487c357130095b62801"
SRC_URI[signal-hook-mio-0.2.3.sha256sum] = "29ad2e15f37ec9a6cc544097b78a1ec90001e9f71b81338ca39f430adaca99af"
-SRC_URI[signal-hook-registry-1.4.0.sha256sum] = "e51e73328dc4ac0c7ccbda3a494dfa03df1de2f46018127f60c693f2648455b0"
+SRC_URI[signal-hook-registry-1.4.1.sha256sum] = "d8229b473baa5980ac72ef434c4415e70c4b5e71b423043adb4ba059f89c99a1"
SRC_URI[siphasher-0.3.10.sha256sum] = "7bd3e3206899af3f8b12af284fafc038cc1dc2b41d1b89dd17297221c5d225de"
SRC_URI[slab-0.4.7.sha256sum] = "4614a76b2a8be0058caa9dbbaf66d988527d86d003c11a94fbd335d7661edcef"
SRC_URI[sm3-0.4.2.sha256sum] = "ebb9a3b702d0a7e33bc4d85a14456633d2b165c2ad839c5fd9a8417c1ab15860"
-SRC_URI[smallvec-1.13.1.sha256sum] = "e6ecd384b10a64542d77071bd64bd7b231f4ed5940fba55e98c3de13824cf3d7"
+SRC_URI[smallvec-1.13.2.sha256sum] = "3c5e1a9a646d36c3599cd173a41282daf47c44583ad367b8e6837255952e5c67"
SRC_URI[smawk-0.3.1.sha256sum] = "f67ad224767faa3c7d8b6d91985b78e70a1324408abcb1cfcc2be4c06bc06043"
SRC_URI[socket2-0.5.3.sha256sum] = "2538b18701741680e0322a2302176d3253a35388e2e62f172f64f4f16605f877"
SRC_URI[strsim-0.10.0.sha256sum] = "73473c0e59e6d5812c5dfe2a064a6444949f089e20eec9a2e5506596494e4623"
SRC_URI[syn-1.0.109.sha256sum] = "72b64191b275b66ffe2469e8af2c1cfe3bafa67b529ead792a6d0160888b4237"
-SRC_URI[syn-2.0.32.sha256sum] = "239814284fd6f1a4ffe4ca893952cdd93c224b6a1571c9a9eadd670295c0c9e2"
-SRC_URI[tempfile-3.10.1.sha256sum] = "85b77fafb263dd9d05cbeac119526425676db3784113aa9295c88498cbf8bff1"
+SRC_URI[syn-2.0.86.sha256sum] = "e89275301d38033efb81a6e60e3497e734dfcc62571f2854bf4b16690398824c"
+SRC_URI[tap-1.0.1.sha256sum] = "55937e1799185b12863d447f42597ed69d9928686b8d88a1df17376a097d8369"
+SRC_URI[tempfile-3.13.0.sha256sum] = "f0f2c9fc62d0beef6951ccffd757e241266a2c833136efbe35af6cd2567dca5b"
SRC_URI[terminal_size-0.2.6.sha256sum] = "8e6bf6f19e9f8ed8d4048dc22981458ebcf406d67e94cd422e5ecd73d63b3237"
-SRC_URI[terminal_size-0.3.0.sha256sum] = "21bebf2b7c9e0a515f6e0f8c51dc0f8e4696391e6f1ff30379559f8365fb0df7"
+SRC_URI[terminal_size-0.4.0.sha256sum] = "4f599bd7ca042cfdf8f4512b277c02ba102247820f9d9d4a9f521f496751a6ef"
SRC_URI[textwrap-0.16.1.sha256sum] = "23d434d3f8967a09480fb04132ebe0a3e088c173e6d0ee7897abbdf4eab0f8b9"
-SRC_URI[thiserror-1.0.37.sha256sum] = "10deb33631e3c9018b9baf9dcbbc4f737320d2b576bac10f6aefa048fa407e3e"
-SRC_URI[thiserror-impl-1.0.37.sha256sum] = "982d17546b47146b28f7c22e3d08465f6b8903d0ea13c1660d9d84a6e7adcdbb"
-SRC_URI[time-0.3.20.sha256sum] = "cd0cbfecb4d19b5ea75bb31ad904eb5b9fa13f21079c3b92017ebdf4999a5890"
-SRC_URI[time-core-0.1.0.sha256sum] = "2e153e1f1acaef8acc537e68b44906d2db6436e2b35ac2c6b42640fff91f00fd"
-SRC_URI[time-macros-0.2.8.sha256sum] = "fd80a657e71da814b8e5d60d3374fc6d35045062245d80224748ae522dd76f36"
+SRC_URI[thiserror-1.0.66.sha256sum] = "5d171f59dbaa811dbbb1aee1e73db92ec2b122911a48e1390dfe327a821ddede"
+SRC_URI[thiserror-impl-1.0.66.sha256sum] = "b08be0f17bd307950653ce45db00cd31200d82b624b36e181337d9c7d92765b5"
+SRC_URI[time-0.3.36.sha256sum] = "5dfd88e563464686c916c7e46e623e520ddc6d79fa6641390f2e3fa86e83e885"
+SRC_URI[time-core-0.1.2.sha256sum] = "ef927ca75afb808a4d64dd374f00a2adf8d0fcff8e7b184af886c3c87ec4a3f3"
+SRC_URI[time-macros-0.2.18.sha256sum] = "3f252a68540fde3a3877aeea552b832b40ab9a69e318efd078774a01ddee1ccf"
SRC_URI[tiny-keccak-2.0.2.sha256sum] = "2c9d3793400a45f954c52e73d068316d76b6f4e36977e3fcebb13a2721e80237"
+SRC_URI[toml_datetime-0.6.8.sha256sum] = "0dd7358ecb8fc2f8d014bf86f6f638ce72ba252a2c3a2572f2a795f1d23efb41"
+SRC_URI[toml_edit-0.22.22.sha256sum] = "4ae48d6208a266e853d946088ed816055e556cc6028c5e8e2b84d9fa5dd7c7f5"
+SRC_URI[trim-in-place-0.1.7.sha256sum] = "343e926fc669bc8cde4fa3129ab681c63671bae288b1f1081ceee6d9d37904fc"
SRC_URI[typenum-1.15.0.sha256sum] = "dcf81ac59edc17cc8697ff311e8f5ef2d99fcbd9817b34cec66f90b6c3dfd987"
-SRC_URI[unicode-ident-1.0.5.sha256sum] = "6ceab39d59e4c9499d4e5a8ee0e2735b891bb7308ac83dfb4e80cad195c9f6f3"
+SRC_URI[unarray-0.1.4.sha256sum] = "eaea85b334db583fe3274d12b4cd1880032beab409c0d774be044d4480ab9a94"
+SRC_URI[unicode-ident-1.0.13.sha256sum] = "e91b56cd4cadaeb79bbf1a5645f6b4f8dc5bde8834ad5894a8db35fda9efa1fe"
SRC_URI[unicode-linebreak-0.1.5.sha256sum] = "3b09c83c3c29d37506a3e260c08c03743a6bb66a9cd432c6934ab501a190571f"
-SRC_URI[unicode-segmentation-1.11.0.sha256sum] = "d4c87d22b6e3f4a18d4d40ef354e97c90fcb14dd91d7dc0aa9d8a1172ebf7202"
-SRC_URI[unicode-width-0.1.11.sha256sum] = "e51733f11c9c4f72aa0c160008246859e340b00807569a0da0e7a1079b27ba85"
+SRC_URI[unicode-segmentation-1.12.0.sha256sum] = "f6ccf251212114b54433ec949fd6a7841275f9ada20dddd2f29e9ceea4501493"
+SRC_URI[unicode-width-0.1.13.sha256sum] = "0336d538f7abc86d282a4189614dfaa90810dfc2c6f6427eaf88e16311dd225d"
+SRC_URI[unicode-width-0.2.0.sha256sum] = "1fc81956842c57dac11422a97c3b8195a1ff727f06e85c84ed2e8aa277c9a0fd"
SRC_URI[unicode-xid-0.2.4.sha256sum] = "f962df74c8c05a667b5ee8bcf162993134c104e96440b663c8daa176dc772d8c"
-SRC_URI[unindent-0.2.1.sha256sum] = "5aa30f5ea51ff7edfc797c6d3f9ec8cbd8cfedef5371766b7181d33977f4814f"
+SRC_URI[unindent-0.2.3.sha256sum] = "c7de7d73e1754487cb58364ee906a499937a0dfabd86bcb980fa99ec8c8fa2ce"
SRC_URI[utf8parse-0.2.1.sha256sum] = "711b9620af191e0cdc7468a8d14e709c3dcdb115b36f838e601583af800a370a"
+SRC_URI[utmp-classic-0.1.6.sha256sum] = "e24c654e19afaa6b8f3877ece5d3bed849c2719c56f6752b18ca7da4fcc6e85a"
+SRC_URI[utmp-classic-raw-0.1.3.sha256sum] = "22c226537a3d6e01c440c1926ca0256dbee2d19b2229ede6fc4863a6493dd831"
SRC_URI[uuid-1.7.0.sha256sum] = "f00cc9702ca12d3c81455259621e676d0f7251cec66a21e98fe2e9a37db93b2a"
-SRC_URI[uutils_term_grid-0.3.0.sha256sum] = "b389452a568698688dda38802068378a16c15c4af9b153cdd99b65391292bbc7"
+SRC_URI[uutils_term_grid-0.6.0.sha256sum] = "f89defb4adb4ba5703a57abc879f96ddd6263a444cacc446db90bf2617f141fb"
SRC_URI[version_check-0.9.4.sha256sum] = "49874b5167b65d7193b8aba1567f5c7d93d001cafc34600cee003eda787e483f"
+SRC_URI[wait-timeout-0.2.0.sha256sum] = "9f200f5b12eb75f8c1ed65abd4b2db8a6e1b138a20de009dacee265a2498f3f6"
SRC_URI[walkdir-2.5.0.sha256sum] = "29790946404f91d9c5d06f9874efddea1dc06c5efe94541a7d6863108e3a5e4b"
SRC_URI[wasi-0.11.0+wasi-snapshot-preview1.sha256sum] = "9c8d87e72b64a3b4db28d11ce29237c246188f4f51057d65a7eab63b7987e423"
SRC_URI[wasm-bindgen-0.2.87.sha256sum] = "7706a72ab36d8cb1f80ffbf0e071533974a60d0a308d01a5d0375bf60499a342"
@@ -523,40 +602,309 @@ SRC_URI[wasm-bindgen-backend-0.2.87.sha256sum] = "5ef2b6d3c510e9625e5fe6f509ab07
SRC_URI[wasm-bindgen-macro-0.2.87.sha256sum] = "dee495e55982a3bd48105a7b947fd2a9b4a8ae3010041b9e0faab3f9cd028f1d"
SRC_URI[wasm-bindgen-macro-support-0.2.87.sha256sum] = "54681b18a46765f095758388f2d0cf16eb8d4169b639ab575a8f5693af210c7b"
SRC_URI[wasm-bindgen-shared-0.2.87.sha256sum] = "ca6ad05a4870b2bf5fe995117d3728437bd27d7cd5f06f13c17443ef369775a1"
-SRC_URI[which-4.3.0.sha256sum] = "1c831fbbee9e129a8cf93e7747a82da9d95ba8e16621cae60ec2cdc849bacb7b"
+SRC_URI[web-time-1.1.0.sha256sum] = "5a6580f308b1fad9207618087a65c04e7a10bc77e02c8e84e9b00dd4b12fa0bb"
+SRC_URI[which-4.4.2.sha256sum] = "87ba24419a2078cd2b0f2ede2691b6c66d8e47836da3b6db8265ebad47afbfc7"
SRC_URI[wild-2.2.1.sha256sum] = "a3131afc8c575281e1e80f36ed6a092aa502c08b18ed7524e86fbbb12bb410e1"
SRC_URI[winapi-0.3.9.sha256sum] = "5c839a674fcd7a98952e593242ea400abe93992746761e38641405d28b00f419"
SRC_URI[winapi-i686-pc-windows-gnu-0.4.0.sha256sum] = "ac3b87c63620426dd9b991e5ce0329eff545bccbbb34f3be09ff6fb6ab51b7b6"
-SRC_URI[winapi-util-0.1.6.sha256sum] = "f29e6f9198ba0d26b4c9f07dbe6f9ed633e1f3d5b8b414090084349e46a52596"
+SRC_URI[winapi-util-0.1.9.sha256sum] = "cf221c93e13a30d793f7645a0e7762c55d169dbb0a49671918a2319d289b10bb"
SRC_URI[winapi-x86_64-pc-windows-gnu-0.4.0.sha256sum] = "712e227841d057c1ee1cd2fb22fa7e5a5461ae8e48fa2ca79ec42cfc1931183f"
+SRC_URI[windows-0.52.0.sha256sum] = "e48a53791691ab099e5e2ad123536d0fff50652600abaf43bbf952894110d0be"
+SRC_URI[windows-core-0.52.0.sha256sum] = "33ab640c8d7e35bf8ba19b884ba838ceb4fba93a4e8c65a9059d08afcfc683d9"
SRC_URI[windows-sys-0.45.0.sha256sum] = "75283be5efb2831d37ea142365f009c02ec203cd29a3ebecbc093d52315b66d0"
SRC_URI[windows-sys-0.48.0.sha256sum] = "677d2418bec65e3338edb076e806bc1ec15693c5d0104683f2efe857f61056a9"
SRC_URI[windows-sys-0.52.0.sha256sum] = "282be5f36a8ce781fad8c8ae18fa3f9beff57ec1b52cb3de0789201425d9a33d"
+SRC_URI[windows-sys-0.59.0.sha256sum] = "1e38bc4d79ed67fd075bcc251a1c39b32a1776bbe92e5bef1f0bf1f8c531853b"
SRC_URI[windows-targets-0.42.2.sha256sum] = "8e5180c00cd44c9b1c88adb3693291f1cd93605ded80c250a75d472756b4d071"
-SRC_URI[windows-targets-0.48.0.sha256sum] = "7b1eb6f0cd7c80c79759c929114ef071b87354ce476d9d94271031c0497adfd5"
-SRC_URI[windows-targets-0.52.0.sha256sum] = "8a18201040b24831fbb9e4eb208f8892e1f50a37feb53cc7ff887feb8f50e7cd"
+SRC_URI[windows-targets-0.48.5.sha256sum] = "9a2fa6e2155d7247be68c096456083145c183cbbbc2764150dda45a87197940c"
+SRC_URI[windows-targets-0.52.6.sha256sum] = "9b724f72796e036ab90c1021d4780d4d3d648aca59e491e6b98e725b84e99973"
SRC_URI[windows_aarch64_gnullvm-0.42.2.sha256sum] = "597a5118570b68bc08d8d59125332c54f1ba9d9adeedeef5b99b02ba2b0698f8"
-SRC_URI[windows_aarch64_gnullvm-0.48.0.sha256sum] = "91ae572e1b79dba883e0d315474df7305d12f569b400fcf90581b06062f7e1bc"
-SRC_URI[windows_aarch64_gnullvm-0.52.0.sha256sum] = "cb7764e35d4db8a7921e09562a0304bf2f93e0a51bfccee0bd0bb0b666b015ea"
+SRC_URI[windows_aarch64_gnullvm-0.48.5.sha256sum] = "2b38e32f0abccf9987a4e3079dfb67dcd799fb61361e53e2882c3cbaf0d905d8"
+SRC_URI[windows_aarch64_gnullvm-0.52.6.sha256sum] = "32a4622180e7a0ec044bb555404c800bc9fd9ec262ec147edd5989ccd0c02cd3"
SRC_URI[windows_aarch64_msvc-0.42.2.sha256sum] = "e08e8864a60f06ef0d0ff4ba04124db8b0fb3be5776a5cd47641e942e58c4d43"
-SRC_URI[windows_aarch64_msvc-0.48.0.sha256sum] = "b2ef27e0d7bdfcfc7b868b317c1d32c641a6fe4629c171b8928c7b08d98d7cf3"
-SRC_URI[windows_aarch64_msvc-0.52.0.sha256sum] = "bbaa0368d4f1d2aaefc55b6fcfee13f41544ddf36801e793edbbfd7d7df075ef"
+SRC_URI[windows_aarch64_msvc-0.48.5.sha256sum] = "dc35310971f3b2dbbf3f0690a219f40e2d9afcf64f9ab7cc1be722937c26b4bc"
+SRC_URI[windows_aarch64_msvc-0.52.6.sha256sum] = "09ec2a7bb152e2252b53fa7803150007879548bc709c039df7627cabbd05d469"
SRC_URI[windows_i686_gnu-0.42.2.sha256sum] = "c61d927d8da41da96a81f029489353e68739737d3beca43145c8afec9a31a84f"
-SRC_URI[windows_i686_gnu-0.48.0.sha256sum] = "622a1962a7db830d6fd0a69683c80a18fda201879f0f447f065a3b7467daa241"
-SRC_URI[windows_i686_gnu-0.52.0.sha256sum] = "a28637cb1fa3560a16915793afb20081aba2c92ee8af57b4d5f28e4b3e7df313"
+SRC_URI[windows_i686_gnu-0.48.5.sha256sum] = "a75915e7def60c94dcef72200b9a8e58e5091744960da64ec734a6c6e9b3743e"
+SRC_URI[windows_i686_gnu-0.52.6.sha256sum] = "8e9b5ad5ab802e97eb8e295ac6720e509ee4c243f69d781394014ebfe8bbfa0b"
+SRC_URI[windows_i686_gnullvm-0.52.6.sha256sum] = "0eee52d38c090b3caa76c563b86c3a4bd71ef1a819287c19d586d7334ae8ed66"
SRC_URI[windows_i686_msvc-0.42.2.sha256sum] = "44d840b6ec649f480a41c8d80f9c65108b92d89345dd94027bfe06ac444d1060"
-SRC_URI[windows_i686_msvc-0.48.0.sha256sum] = "4542c6e364ce21bf45d69fdd2a8e455fa38d316158cfd43b3ac1c5b1b19f8e00"
-SRC_URI[windows_i686_msvc-0.52.0.sha256sum] = "ffe5e8e31046ce6230cc7215707b816e339ff4d4d67c65dffa206fd0f7aa7b9a"
+SRC_URI[windows_i686_msvc-0.48.5.sha256sum] = "8f55c233f70c4b27f66c523580f78f1004e8b5a8b659e05a4eb49d4166cca406"
+SRC_URI[windows_i686_msvc-0.52.6.sha256sum] = "240948bc05c5e7c6dabba28bf89d89ffce3e303022809e73deaefe4f6ec56c66"
SRC_URI[windows_x86_64_gnu-0.42.2.sha256sum] = "8de912b8b8feb55c064867cf047dda097f92d51efad5b491dfb98f6bbb70cb36"
-SRC_URI[windows_x86_64_gnu-0.48.0.sha256sum] = "ca2b8a661f7628cbd23440e50b05d705db3686f894fc9580820623656af974b1"
-SRC_URI[windows_x86_64_gnu-0.52.0.sha256sum] = "3d6fa32db2bc4a2f5abeacf2b69f7992cd09dca97498da74a151a3132c26befd"
+SRC_URI[windows_x86_64_gnu-0.48.5.sha256sum] = "53d40abd2583d23e4718fddf1ebec84dbff8381c07cae67ff7768bbf19c6718e"
+SRC_URI[windows_x86_64_gnu-0.52.6.sha256sum] = "147a5c80aabfbf0c7d901cb5895d1de30ef2907eb21fbbab29ca94c5b08b1a78"
SRC_URI[windows_x86_64_gnullvm-0.42.2.sha256sum] = "26d41b46a36d453748aedef1486d5c7a85db22e56aff34643984ea85514e94a3"
-SRC_URI[windows_x86_64_gnullvm-0.48.0.sha256sum] = "7896dbc1f41e08872e9d5e8f8baa8fdd2677f29468c4e156210174edc7f7b953"
-SRC_URI[windows_x86_64_gnullvm-0.52.0.sha256sum] = "1a657e1e9d3f514745a572a6846d3c7aa7dbe1658c056ed9c3344c4109a6949e"
+SRC_URI[windows_x86_64_gnullvm-0.48.5.sha256sum] = "0b7b52767868a23d5bab768e390dc5f5c55825b6d30b86c844ff2dc7414044cc"
+SRC_URI[windows_x86_64_gnullvm-0.52.6.sha256sum] = "24d5b23dc417412679681396f2b49f3de8c1473deb516bd34410872eff51ed0d"
SRC_URI[windows_x86_64_msvc-0.42.2.sha256sum] = "9aec5da331524158c6d1a4ac0ab1541149c0b9505fde06423b02f5ef0106b9f0"
-SRC_URI[windows_x86_64_msvc-0.48.0.sha256sum] = "1a515f5799fe4961cb532f983ce2b23082366b898e52ffbce459c86f67c8378a"
-SRC_URI[windows_x86_64_msvc-0.52.0.sha256sum] = "dff9641d1cd4be8d1a070daf9e3773c5f67e78b4d9d42263020c057706765c04"
+SRC_URI[windows_x86_64_msvc-0.48.5.sha256sum] = "ed94fce61571a4006852b7389a063ab983c02eb1bb37b47f8272ce92d06d9538"
+SRC_URI[windows_x86_64_msvc-0.52.6.sha256sum] = "589f6da84c646204747d1270a2a5661ea66ed1cced2631d546fdfb155959f9ec"
+SRC_URI[winnow-0.6.20.sha256sum] = "36c1fec1a2bb5866f07c25f68c26e565c4c200aebb96d7e55710c19d3e8ac49b"
+SRC_URI[wyz-0.5.1.sha256sum] = "05f360fc0b24296329c78fda852a1e9ae82de9cf7b27dae4b7f62f118f77b9ed"
SRC_URI[xattr-1.3.1.sha256sum] = "8da84f1a25939b27f6820d92aed108f83ff920fdf11a7b19366c27c4cda81d4f"
-SRC_URI[yansi-0.5.1.sha256sum] = "09041cd90cf85f7f8b2df60c646f853b7f535ce68f85244eb6731cf89fa498ec"
+SRC_URI[yansi-1.0.1.sha256sum] = "cfe53a6657fd280eaa890a3bc59152892ffa3e30101319d168b781ed6529b049"
SRC_URI[z85-3.0.5.sha256sum] = "2a599daf1b507819c1121f0bf87fa37eb19daac6aff3aefefd4e6e2e0f2020fc"
-SRC_URI[zip-0.6.6.sha256sum] = "760394e246e4c28189f19d488c058bf16f564016aefac5d32bb1f3b51d5e9261"
+SRC_URI[zerocopy-0.7.34.sha256sum] = "ae87e3fcd617500e5d106f0380cf7b77f3c6092aae37191433159dda23cfb087"
+SRC_URI[zerocopy-derive-0.7.34.sha256sum] = "15e934569e47891f7d9411f1a451d947a60e000ab3bd24fbb970f000387d1b3b"
+SRC_URI[zip-1.1.4.sha256sum] = "9cc23c04387f4da0374be4533ad1208cbb091d5c11d070dfef13676ad6497164"
+# from fuzz/Cargo.lock
+SRC_URI += " \
+ crate://crates.io/aho-corasick/1.1.3 \
+ crate://crates.io/android-tzdata/0.1.1 \
+ crate://crates.io/android_system_properties/0.1.5 \
+ crate://crates.io/anstream/0.6.14 \
+ crate://crates.io/anstyle/1.0.7 \
+ crate://crates.io/anstyle-parse/0.2.4 \
+ crate://crates.io/anstyle-query/1.0.3 \
+ crate://crates.io/anstyle-wincon/3.0.3 \
+ crate://crates.io/arbitrary/1.3.2 \
+ crate://crates.io/autocfg/1.3.0 \
+ crate://crates.io/bigdecimal/0.4.3 \
+ crate://crates.io/binary-heap-plus/0.5.0 \
+ crate://crates.io/bitflags/1.3.2 \
+ crate://crates.io/bitflags/2.5.0 \
+ crate://crates.io/bstr/1.9.1 \
+ crate://crates.io/bumpalo/3.16.0 \
+ crate://crates.io/bytecount/0.6.8 \
+ crate://crates.io/cc/1.0.98 \
+ crate://crates.io/cfg-if/1.0.0 \
+ crate://crates.io/cfg_aliases/0.1.1 \
+ crate://crates.io/cfg_aliases/0.2.1 \
+ crate://crates.io/chrono/0.4.38 \
+ crate://crates.io/clap/4.5.4 \
+ crate://crates.io/clap_builder/4.5.2 \
+ crate://crates.io/clap_lex/0.7.0 \
+ crate://crates.io/colorchoice/1.0.1 \
+ crate://crates.io/compare/0.1.0 \
+ crate://crates.io/const-random/0.1.18 \
+ crate://crates.io/const-random-macro/0.1.16 \
+ crate://crates.io/core-foundation-sys/0.8.6 \
+ crate://crates.io/crossbeam-deque/0.8.5 \
+ crate://crates.io/crossbeam-epoch/0.9.18 \
+ crate://crates.io/crossbeam-utils/0.8.20 \
+ crate://crates.io/crunchy/0.2.2 \
+ crate://crates.io/ctrlc/3.4.4 \
+ crate://crates.io/dlv-list/0.5.2 \
+ crate://crates.io/dunce/1.0.4 \
+ crate://crates.io/either/1.12.0 \
+ crate://crates.io/errno/0.3.9 \
+ crate://crates.io/fastrand/2.1.1 \
+ crate://crates.io/fnv/1.0.7 \
+ crate://crates.io/getrandom/0.2.15 \
+ crate://crates.io/glob/0.3.1 \
+ crate://crates.io/hashbrown/0.14.5 \
+ crate://crates.io/iana-time-zone/0.1.60 \
+ crate://crates.io/iana-time-zone-haiku/0.1.2 \
+ crate://crates.io/is_terminal_polyfill/1.70.0 \
+ crate://crates.io/itertools/0.13.0 \
+ crate://crates.io/jobserver/0.1.31 \
+ crate://crates.io/js-sys/0.3.69 \
+ crate://crates.io/libc/0.2.161 \
+ crate://crates.io/libfuzzer-sys/0.4.7 \
+ crate://crates.io/libm/0.2.8 \
+ crate://crates.io/linux-raw-sys/0.4.14 \
+ crate://crates.io/log/0.4.21 \
+ crate://crates.io/memchr/2.7.2 \
+ crate://crates.io/minimal-lexical/0.2.1 \
+ crate://crates.io/nix/0.28.0 \
+ crate://crates.io/nix/0.29.0 \
+ crate://crates.io/nom/7.1.3 \
+ crate://crates.io/num-bigint/0.4.5 \
+ crate://crates.io/num-integer/0.1.46 \
+ crate://crates.io/num-traits/0.2.19 \
+ crate://crates.io/number_prefix/0.4.0 \
+ crate://crates.io/once_cell/1.19.0 \
+ crate://crates.io/onig/6.4.0 \
+ crate://crates.io/onig_sys/69.8.1 \
+ crate://crates.io/ordered-multimap/0.7.3 \
+ crate://crates.io/os_display/0.1.3 \
+ crate://crates.io/parse_datetime/0.6.0 \
+ crate://crates.io/pkg-config/0.3.30 \
+ crate://crates.io/ppv-lite86/0.2.17 \
+ crate://crates.io/proc-macro2/1.0.83 \
+ crate://crates.io/quote/1.0.36 \
+ crate://crates.io/rand/0.8.5 \
+ crate://crates.io/rand_chacha/0.3.1 \
+ crate://crates.io/rand_core/0.6.4 \
+ crate://crates.io/rayon/1.10.0 \
+ crate://crates.io/rayon-core/1.12.1 \
+ crate://crates.io/regex/1.10.4 \
+ crate://crates.io/regex-automata/0.4.6 \
+ crate://crates.io/regex-syntax/0.8.3 \
+ crate://crates.io/rust-ini/0.21.0 \
+ crate://crates.io/rustix/0.38.37 \
+ crate://crates.io/self_cell/1.0.4 \
+ crate://crates.io/serde/1.0.202 \
+ crate://crates.io/serde_derive/1.0.202 \
+ crate://crates.io/similar/2.6.0 \
+ crate://crates.io/strsim/0.11.1 \
+ crate://crates.io/syn/2.0.65 \
+ crate://crates.io/tempfile/3.13.0 \
+ crate://crates.io/terminal_size/0.3.0 \
+ crate://crates.io/thiserror/1.0.61 \
+ crate://crates.io/thiserror-impl/1.0.61 \
+ crate://crates.io/tiny-keccak/2.0.2 \
+ crate://crates.io/trim-in-place/0.1.7 \
+ crate://crates.io/unicode-ident/1.0.12 \
+ crate://crates.io/unicode-width/0.1.12 \
+ crate://crates.io/utf8parse/0.2.1 \
+ crate://crates.io/wasi/0.11.0+wasi-snapshot-preview1 \
+ crate://crates.io/wasm-bindgen/0.2.92 \
+ crate://crates.io/wasm-bindgen-backend/0.2.92 \
+ crate://crates.io/wasm-bindgen-macro/0.2.92 \
+ crate://crates.io/wasm-bindgen-macro-support/0.2.92 \
+ crate://crates.io/wasm-bindgen-shared/0.2.92 \
+ crate://crates.io/wild/2.2.1 \
+ crate://crates.io/winapi-util/0.1.8 \
+ crate://crates.io/windows-core/0.52.0 \
+ crate://crates.io/windows-sys/0.48.0 \
+ crate://crates.io/windows-sys/0.52.0 \
+ crate://crates.io/windows-sys/0.59.0 \
+ crate://crates.io/windows-targets/0.48.5 \
+ crate://crates.io/windows-targets/0.52.6 \
+ crate://crates.io/windows_aarch64_gnullvm/0.48.5 \
+ crate://crates.io/windows_aarch64_gnullvm/0.52.6 \
+ crate://crates.io/windows_aarch64_msvc/0.48.5 \
+ crate://crates.io/windows_aarch64_msvc/0.52.6 \
+ crate://crates.io/windows_i686_gnu/0.48.5 \
+ crate://crates.io/windows_i686_gnu/0.52.6 \
+ crate://crates.io/windows_i686_gnullvm/0.52.6 \
+ crate://crates.io/windows_i686_msvc/0.48.5 \
+ crate://crates.io/windows_i686_msvc/0.52.6 \
+ crate://crates.io/windows_x86_64_gnu/0.48.5 \
+ crate://crates.io/windows_x86_64_gnu/0.52.6 \
+ crate://crates.io/windows_x86_64_gnullvm/0.48.5 \
+ crate://crates.io/windows_x86_64_gnullvm/0.52.6 \
+ crate://crates.io/windows_x86_64_msvc/0.48.5 \
+ crate://crates.io/windows_x86_64_msvc/0.52.6 \
+"
+
+SRC_URI[aho-corasick-1.1.3.sha256sum] = "8e60d3430d3a69478ad0993f19238d2df97c507009a52b3c10addcd7f6bcb916"
+SRC_URI[android-tzdata-0.1.1.sha256sum] = "e999941b234f3131b00bc13c22d06e8c5ff726d1b6318ac7eb276997bbb4fef0"
+SRC_URI[android_system_properties-0.1.5.sha256sum] = "819e7219dbd41043ac279b19830f2efc897156490d7fd6ea916720117ee66311"
+SRC_URI[anstream-0.6.14.sha256sum] = "418c75fa768af9c03be99d17643f93f79bbba589895012a80e3452a19ddda15b"
+SRC_URI[anstyle-1.0.7.sha256sum] = "038dfcf04a5feb68e9c60b21c9625a54c2c0616e79b72b0fd87075a056ae1d1b"
+SRC_URI[anstyle-parse-0.2.4.sha256sum] = "c03a11a9034d92058ceb6ee011ce58af4a9bf61491aa7e1e59ecd24bd40d22d4"
+SRC_URI[anstyle-query-1.0.3.sha256sum] = "a64c907d4e79225ac72e2a354c9ce84d50ebb4586dee56c82b3ee73004f537f5"
+SRC_URI[anstyle-wincon-3.0.3.sha256sum] = "61a38449feb7068f52bb06c12759005cf459ee52bb4adc1d5a7c4322d716fb19"
+SRC_URI[arbitrary-1.3.2.sha256sum] = "7d5a26814d8dcb93b0e5a0ff3c6d80a8843bafb21b39e8e18a6f05471870e110"
+SRC_URI[autocfg-1.3.0.sha256sum] = "0c4b4d0bd25bd0b74681c0ad21497610ce1b7c91b1022cd21c80c6fbdd9476b0"
+SRC_URI[bigdecimal-0.4.3.sha256sum] = "9324c8014cd04590682b34f1e9448d38f0674d0f7b2dc553331016ef0e4e9ebc"
+SRC_URI[binary-heap-plus-0.5.0.sha256sum] = "e4551d8382e911ecc0d0f0ffb602777988669be09447d536ff4388d1def11296"
+SRC_URI[bitflags-1.3.2.sha256sum] = "bef38d45163c2f1dde094a7dfd33ccf595c92905c8f8f4fdc18d06fb1037718a"
+SRC_URI[bitflags-2.5.0.sha256sum] = "cf4b9d6a944f767f8e5e0db018570623c85f3d925ac718db4e06d0187adb21c1"
+SRC_URI[bstr-1.9.1.sha256sum] = "05efc5cfd9110c8416e471df0e96702d58690178e206e61b7173706673c93706"
+SRC_URI[bumpalo-3.16.0.sha256sum] = "79296716171880943b8470b5f8d03aa55eb2e645a4874bdbb28adb49162e012c"
+SRC_URI[bytecount-0.6.8.sha256sum] = "5ce89b21cab1437276d2650d57e971f9d548a2d9037cc231abdc0562b97498ce"
+SRC_URI[cc-1.0.98.sha256sum] = "41c270e7540d725e65ac7f1b212ac8ce349719624d7bcff99f8e2e488e8cf03f"
+SRC_URI[cfg-if-1.0.0.sha256sum] = "baf1de4339761588bc0619e3cbc0120ee582ebb74b53b4efbf79117bd2da40fd"
+SRC_URI[cfg_aliases-0.1.1.sha256sum] = "fd16c4719339c4530435d38e511904438d07cce7950afa3718a84ac36c10e89e"
+SRC_URI[cfg_aliases-0.2.1.sha256sum] = "613afe47fcd5fac7ccf1db93babcb082c5994d996f20b8b159f2ad1658eb5724"
+SRC_URI[chrono-0.4.38.sha256sum] = "a21f936df1771bf62b77f047b726c4625ff2e8aa607c01ec06e5a05bd8463401"
+SRC_URI[clap-4.5.4.sha256sum] = "90bc066a67923782aa8515dbaea16946c5bcc5addbd668bb80af688e53e548a0"
+SRC_URI[clap_builder-4.5.2.sha256sum] = "ae129e2e766ae0ec03484e609954119f123cc1fe650337e155d03b022f24f7b4"
+SRC_URI[clap_lex-0.7.0.sha256sum] = "98cc8fbded0c607b7ba9dd60cd98df59af97e84d24e49c8557331cfc26d301ce"
+SRC_URI[colorchoice-1.0.1.sha256sum] = "0b6a852b24ab71dffc585bcb46eaf7959d175cb865a7152e35b348d1b2960422"
+SRC_URI[compare-0.1.0.sha256sum] = "120133d4db2ec47efe2e26502ee984747630c67f51974fca0b6c1340cf2368d3"
+SRC_URI[const-random-0.1.18.sha256sum] = "87e00182fe74b066627d63b85fd550ac2998d4b0bd86bfed477a0ae4c7c71359"
+SRC_URI[const-random-macro-0.1.16.sha256sum] = "f9d839f2a20b0aee515dc581a6172f2321f96cab76c1a38a4c584a194955390e"
+SRC_URI[core-foundation-sys-0.8.6.sha256sum] = "06ea2b9bc92be3c2baa9334a323ebca2d6f074ff852cd1d7b11064035cd3868f"
+SRC_URI[crossbeam-deque-0.8.5.sha256sum] = "613f8cc01fe9cf1a3eb3d7f488fd2fa8388403e97039e2f73692932e291a770d"
+SRC_URI[crossbeam-epoch-0.9.18.sha256sum] = "5b82ac4a3c2ca9c3460964f020e1402edd5753411d7737aa39c3714ad1b5420e"
+SRC_URI[crossbeam-utils-0.8.20.sha256sum] = "22ec99545bb0ed0ea7bb9b8e1e9122ea386ff8a48c0922e43f36d45ab09e0e80"
+SRC_URI[crunchy-0.2.2.sha256sum] = "7a81dae078cea95a014a339291cec439d2f232ebe854a9d672b796c6afafa9b7"
+SRC_URI[ctrlc-3.4.4.sha256sum] = "672465ae37dc1bc6380a6547a8883d5dd397b0f1faaad4f265726cc7042a5345"
+SRC_URI[dlv-list-0.5.2.sha256sum] = "442039f5147480ba31067cb00ada1adae6892028e40e45fc5de7b7df6dcc1b5f"
+SRC_URI[dunce-1.0.4.sha256sum] = "56ce8c6da7551ec6c462cbaf3bfbc75131ebbfa1c944aeaa9dab51ca1c5f0c3b"
+SRC_URI[either-1.12.0.sha256sum] = "3dca9240753cf90908d7e4aac30f630662b02aebaa1b58a3cadabdb23385b58b"
+SRC_URI[errno-0.3.9.sha256sum] = "534c5cf6194dfab3db3242765c03bbe257cf92f22b38f6bc0c58d59108a820ba"
+SRC_URI[fastrand-2.1.1.sha256sum] = "e8c02a5121d4ea3eb16a80748c74f5549a5665e4c21333c6098f283870fbdea6"
+SRC_URI[fnv-1.0.7.sha256sum] = "3f9eec918d3f24069decb9af1554cad7c880e2da24a9afd88aca000531ab82c1"
+SRC_URI[getrandom-0.2.15.sha256sum] = "c4567c8db10ae91089c99af84c68c38da3ec2f087c3f82960bcdbf3656b6f4d7"
+SRC_URI[glob-0.3.1.sha256sum] = "d2fabcfbdc87f4758337ca535fb41a6d701b65693ce38287d856d1674551ec9b"
+SRC_URI[hashbrown-0.14.5.sha256sum] = "e5274423e17b7c9fc20b6e7e208532f9b19825d82dfd615708b70edd83df41f1"
+SRC_URI[iana-time-zone-0.1.60.sha256sum] = "e7ffbb5a1b541ea2561f8c41c087286cc091e21e556a4f09a8f6cbf17b69b141"
+SRC_URI[iana-time-zone-haiku-0.1.2.sha256sum] = "f31827a206f56af32e590ba56d5d2d085f558508192593743f16b2306495269f"
+SRC_URI[is_terminal_polyfill-1.70.0.sha256sum] = "f8478577c03552c21db0e2724ffb8986a5ce7af88107e6be5d2ee6e158c12800"
+SRC_URI[itertools-0.13.0.sha256sum] = "413ee7dfc52ee1a4949ceeb7dbc8a33f2d6c088194d9f922fb8318faf1f01186"
+SRC_URI[jobserver-0.1.31.sha256sum] = "d2b099aaa34a9751c5bf0878add70444e1ed2dd73f347be99003d4577277de6e"
+SRC_URI[js-sys-0.3.69.sha256sum] = "29c15563dc2726973df627357ce0c9ddddbea194836909d655df6a75d2cf296d"
+SRC_URI[libc-0.2.161.sha256sum] = "8e9489c2807c139ffd9c1794f4af0ebe86a828db53ecdc7fea2111d0fed085d1"
+SRC_URI[libfuzzer-sys-0.4.7.sha256sum] = "a96cfd5557eb82f2b83fed4955246c988d331975a002961b07c81584d107e7f7"
+SRC_URI[libm-0.2.8.sha256sum] = "4ec2a862134d2a7d32d7983ddcdd1c4923530833c9f2ea1a44fc5fa473989058"
+SRC_URI[linux-raw-sys-0.4.14.sha256sum] = "78b3ae25bc7c8c38cec158d1f2757ee79e9b3740fbc7ccf0e59e4b08d793fa89"
+SRC_URI[log-0.4.21.sha256sum] = "90ed8c1e510134f979dbc4f070f87d4313098b704861a105fe34231c70a3901c"
+SRC_URI[memchr-2.7.2.sha256sum] = "6c8640c5d730cb13ebd907d8d04b52f55ac9a2eec55b440c8892f40d56c76c1d"
+SRC_URI[minimal-lexical-0.2.1.sha256sum] = "68354c5c6bd36d73ff3feceb05efa59b6acb7626617f4962be322a825e61f79a"
+SRC_URI[nix-0.28.0.sha256sum] = "ab2156c4fce2f8df6c499cc1c763e4394b7482525bf2a9701c9d79d215f519e4"
+SRC_URI[nix-0.29.0.sha256sum] = "71e2746dc3a24dd78b3cfcb7be93368c6de9963d30f43a6a73998a9cf4b17b46"
+SRC_URI[nom-7.1.3.sha256sum] = "d273983c5a657a70a3e8f2a01329822f3b8c8172b73826411a55751e404a0a4a"
+SRC_URI[num-bigint-0.4.5.sha256sum] = "c165a9ab64cf766f73521c0dd2cfdff64f488b8f0b3e621face3462d3db536d7"
+SRC_URI[num-integer-0.1.46.sha256sum] = "7969661fd2958a5cb096e56c8e1ad0444ac2bbcd0061bd28660485a44879858f"
+SRC_URI[num-traits-0.2.19.sha256sum] = "071dfc062690e90b734c0b2273ce72ad0ffa95f0c74596bc250dcfd960262841"
+SRC_URI[number_prefix-0.4.0.sha256sum] = "830b246a0e5f20af87141b25c173cd1b609bd7779a4617d6ec582abaf90870f3"
+SRC_URI[once_cell-1.19.0.sha256sum] = "3fdb12b2476b595f9358c5161aa467c2438859caa136dec86c26fdd2efe17b92"
+SRC_URI[onig-6.4.0.sha256sum] = "8c4b31c8722ad9171c6d77d3557db078cab2bd50afcc9d09c8b315c59df8ca4f"
+SRC_URI[onig_sys-69.8.1.sha256sum] = "7b829e3d7e9cc74c7e315ee8edb185bf4190da5acde74afd7fc59c35b1f086e7"
+SRC_URI[ordered-multimap-0.7.3.sha256sum] = "49203cdcae0030493bad186b28da2fa25645fa276a51b6fec8010d281e02ef79"
+SRC_URI[os_display-0.1.3.sha256sum] = "7a6229bad892b46b0dcfaaeb18ad0d2e56400f5aaea05b768bde96e73676cf75"
+SRC_URI[parse_datetime-0.6.0.sha256sum] = "a8720474e3dd4af20cea8716703498b9f3b690f318fa9d9d9e2e38eaf44b96d0"
+SRC_URI[pkg-config-0.3.30.sha256sum] = "d231b230927b5e4ad203db57bbcbee2802f6bce620b1e4a9024a07d94e2907ec"
+SRC_URI[ppv-lite86-0.2.17.sha256sum] = "5b40af805b3121feab8a3c29f04d8ad262fa8e0561883e7653e024ae4479e6de"
+SRC_URI[proc-macro2-1.0.83.sha256sum] = "0b33eb56c327dec362a9e55b3ad14f9d2f0904fb5a5b03b513ab5465399e9f43"
+SRC_URI[quote-1.0.36.sha256sum] = "0fa76aaf39101c457836aec0ce2316dbdc3ab723cdda1c6bd4e6ad4208acaca7"
+SRC_URI[rand-0.8.5.sha256sum] = "34af8d1a0e25924bc5b7c43c079c942339d8f0a8b57c39049bef581b46327404"
+SRC_URI[rand_chacha-0.3.1.sha256sum] = "e6c10a63a0fa32252be49d21e7709d4d4baf8d231c2dbce1eaa8141b9b127d88"
+SRC_URI[rand_core-0.6.4.sha256sum] = "ec0be4795e2f6a28069bec0b5ff3e2ac9bafc99e6a9a7dc3547996c5c816922c"
+SRC_URI[rayon-1.10.0.sha256sum] = "b418a60154510ca1a002a752ca9714984e21e4241e804d32555251faf8b78ffa"
+SRC_URI[rayon-core-1.12.1.sha256sum] = "1465873a3dfdaa8ae7cb14b4383657caab0b3e8a0aa9ae8e04b044854c8dfce2"
+SRC_URI[regex-1.10.4.sha256sum] = "c117dbdfde9c8308975b6a18d71f3f385c89461f7b3fb054288ecf2a2058ba4c"
+SRC_URI[regex-automata-0.4.6.sha256sum] = "86b83b8b9847f9bf95ef68afb0b8e6cdb80f498442f5179a29fad448fcc1eaea"
+SRC_URI[regex-syntax-0.8.3.sha256sum] = "adad44e29e4c806119491a7f06f03de4d1af22c3a680dd47f1e6e179439d1f56"
+SRC_URI[rust-ini-0.21.0.sha256sum] = "0d625ed57d8f49af6cfa514c42e1a71fadcff60eb0b1c517ff82fe41aa025b41"
+SRC_URI[rustix-0.38.37.sha256sum] = "8acb788b847c24f28525660c4d7758620a7210875711f79e7f663cc152726811"
+SRC_URI[self_cell-1.0.4.sha256sum] = "d369a96f978623eb3dc28807c4852d6cc617fed53da5d3c400feff1ef34a714a"
+SRC_URI[serde-1.0.202.sha256sum] = "226b61a0d411b2ba5ff6d7f73a476ac4f8bb900373459cd00fab8512828ba395"
+SRC_URI[serde_derive-1.0.202.sha256sum] = "6048858004bcff69094cd972ed40a32500f153bd3be9f716b2eed2e8217c4838"
+SRC_URI[similar-2.6.0.sha256sum] = "1de1d4f81173b03af4c0cbed3c898f6bff5b870e4a7f5d6f4057d62a7a4b686e"
+SRC_URI[strsim-0.11.1.sha256sum] = "7da8b5736845d9f2fcb837ea5d9e2628564b3b043a70948a3f0b778838c5fb4f"
+SRC_URI[syn-2.0.65.sha256sum] = "d2863d96a84c6439701d7a38f9de935ec562c8832cc55d1dde0f513b52fad106"
+SRC_URI[tempfile-3.13.0.sha256sum] = "f0f2c9fc62d0beef6951ccffd757e241266a2c833136efbe35af6cd2567dca5b"
+SRC_URI[terminal_size-0.3.0.sha256sum] = "21bebf2b7c9e0a515f6e0f8c51dc0f8e4696391e6f1ff30379559f8365fb0df7"
+SRC_URI[thiserror-1.0.61.sha256sum] = "c546c80d6be4bc6a00c0f01730c08df82eaa7a7a61f11d656526506112cc1709"
+SRC_URI[thiserror-impl-1.0.61.sha256sum] = "46c3384250002a6d5af4d114f2845d37b57521033f30d5c3f46c4d70e1197533"
+SRC_URI[tiny-keccak-2.0.2.sha256sum] = "2c9d3793400a45f954c52e73d068316d76b6f4e36977e3fcebb13a2721e80237"
+SRC_URI[trim-in-place-0.1.7.sha256sum] = "343e926fc669bc8cde4fa3129ab681c63671bae288b1f1081ceee6d9d37904fc"
+SRC_URI[unicode-ident-1.0.12.sha256sum] = "3354b9ac3fae1ff6755cb6db53683adb661634f67557942dea4facebec0fee4b"
+SRC_URI[unicode-width-0.1.12.sha256sum] = "68f5e5f3158ecfd4b8ff6fe086db7c8467a2dfdac97fe420f2b7c4aa97af66d6"
+SRC_URI[utf8parse-0.2.1.sha256sum] = "711b9620af191e0cdc7468a8d14e709c3dcdb115b36f838e601583af800a370a"
+SRC_URI[wasi-0.11.0+wasi-snapshot-preview1.sha256sum] = "9c8d87e72b64a3b4db28d11ce29237c246188f4f51057d65a7eab63b7987e423"
+SRC_URI[wasm-bindgen-0.2.92.sha256sum] = "4be2531df63900aeb2bca0daaaddec08491ee64ceecbee5076636a3b026795a8"
+SRC_URI[wasm-bindgen-backend-0.2.92.sha256sum] = "614d787b966d3989fa7bb98a654e369c762374fd3213d212cfc0251257e747da"
+SRC_URI[wasm-bindgen-macro-0.2.92.sha256sum] = "a1f8823de937b71b9460c0c34e25f3da88250760bec0ebac694b49997550d726"
+SRC_URI[wasm-bindgen-macro-support-0.2.92.sha256sum] = "e94f17b526d0a461a191c78ea52bbce64071ed5c04c9ffe424dcb38f74171bb7"
+SRC_URI[wasm-bindgen-shared-0.2.92.sha256sum] = "af190c94f2773fdb3729c55b007a722abb5384da03bc0986df4c289bf5567e96"
+SRC_URI[wild-2.2.1.sha256sum] = "a3131afc8c575281e1e80f36ed6a092aa502c08b18ed7524e86fbbb12bb410e1"
+SRC_URI[winapi-util-0.1.8.sha256sum] = "4d4cc384e1e73b93bafa6fb4f1df8c41695c8a91cf9c4c64358067d15a7b6c6b"
+SRC_URI[windows-core-0.52.0.sha256sum] = "33ab640c8d7e35bf8ba19b884ba838ceb4fba93a4e8c65a9059d08afcfc683d9"
+SRC_URI[windows-sys-0.48.0.sha256sum] = "677d2418bec65e3338edb076e806bc1ec15693c5d0104683f2efe857f61056a9"
+SRC_URI[windows-sys-0.52.0.sha256sum] = "282be5f36a8ce781fad8c8ae18fa3f9beff57ec1b52cb3de0789201425d9a33d"
+SRC_URI[windows-sys-0.59.0.sha256sum] = "1e38bc4d79ed67fd075bcc251a1c39b32a1776bbe92e5bef1f0bf1f8c531853b"
+SRC_URI[windows-targets-0.48.5.sha256sum] = "9a2fa6e2155d7247be68c096456083145c183cbbbc2764150dda45a87197940c"
+SRC_URI[windows-targets-0.52.6.sha256sum] = "9b724f72796e036ab90c1021d4780d4d3d648aca59e491e6b98e725b84e99973"
+SRC_URI[windows_aarch64_gnullvm-0.48.5.sha256sum] = "2b38e32f0abccf9987a4e3079dfb67dcd799fb61361e53e2882c3cbaf0d905d8"
+SRC_URI[windows_aarch64_gnullvm-0.52.6.sha256sum] = "32a4622180e7a0ec044bb555404c800bc9fd9ec262ec147edd5989ccd0c02cd3"
+SRC_URI[windows_aarch64_msvc-0.48.5.sha256sum] = "dc35310971f3b2dbbf3f0690a219f40e2d9afcf64f9ab7cc1be722937c26b4bc"
+SRC_URI[windows_aarch64_msvc-0.52.6.sha256sum] = "09ec2a7bb152e2252b53fa7803150007879548bc709c039df7627cabbd05d469"
+SRC_URI[windows_i686_gnu-0.48.5.sha256sum] = "a75915e7def60c94dcef72200b9a8e58e5091744960da64ec734a6c6e9b3743e"
+SRC_URI[windows_i686_gnu-0.52.6.sha256sum] = "8e9b5ad5ab802e97eb8e295ac6720e509ee4c243f69d781394014ebfe8bbfa0b"
+SRC_URI[windows_i686_gnullvm-0.52.6.sha256sum] = "0eee52d38c090b3caa76c563b86c3a4bd71ef1a819287c19d586d7334ae8ed66"
+SRC_URI[windows_i686_msvc-0.48.5.sha256sum] = "8f55c233f70c4b27f66c523580f78f1004e8b5a8b659e05a4eb49d4166cca406"
+SRC_URI[windows_i686_msvc-0.52.6.sha256sum] = "240948bc05c5e7c6dabba28bf89d89ffce3e303022809e73deaefe4f6ec56c66"
+SRC_URI[windows_x86_64_gnu-0.48.5.sha256sum] = "53d40abd2583d23e4718fddf1ebec84dbff8381c07cae67ff7768bbf19c6718e"
+SRC_URI[windows_x86_64_gnu-0.52.6.sha256sum] = "147a5c80aabfbf0c7d901cb5895d1de30ef2907eb21fbbab29ca94c5b08b1a78"
+SRC_URI[windows_x86_64_gnullvm-0.48.5.sha256sum] = "0b7b52767868a23d5bab768e390dc5f5c55825b6d30b86c844ff2dc7414044cc"
+SRC_URI[windows_x86_64_gnullvm-0.52.6.sha256sum] = "24d5b23dc417412679681396f2b49f3de8c1473deb516bd34410872eff51ed0d"
+SRC_URI[windows_x86_64_msvc-0.48.5.sha256sum] = "ed94fce61571a4006852b7389a063ab983c02eb1bb37b47f8272ce92d06d9538"
+SRC_URI[windows_x86_64_msvc-0.52.6.sha256sum] = "589f6da84c646204747d1270a2a5661ea66ed1cced2631d546fdfb155959f9ec"
diff --git a/meta-openembedded/meta-oe/recipes-core/uutils-coreutils/uutils-coreutils_0.0.25.bb b/meta-openembedded/meta-oe/recipes-core/uutils-coreutils/uutils-coreutils_0.0.28.bb
index 61f2dc2987..76cecac5a6 100644
--- a/meta-openembedded/meta-oe/recipes-core/uutils-coreutils/uutils-coreutils_0.0.25.bb
+++ b/meta-openembedded/meta-oe/recipes-core/uutils-coreutils/uutils-coreutils_0.0.28.bb
@@ -7,13 +7,14 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=e74349878141b240070458d414ab3b64"
inherit cargo cargo-update-recipe-crates
-SRC_URI += "git://github.com/uutils/coreutils.git;protocol=https;branch=main"
+SRC_URI += "git://github.com/uutils/coreutils.git;protocol=https;branch=main \
+ file://0001-Cargo.lock-revert-to-selinux-sys-0.6.9-and-fts-sys-0.patch"
# musl not supported because the libc crate does not support functions like "endutxent" at the moment,
# so src/uucore/src/lib/features.rs disables utmpx when targetting musl.
COMPATIBLE_HOST:libc-musl = "null"
-SRCREV = "68c77b4bd129bdc12d03cc74fe0f817d2df75894"
+SRCREV = "1d9e1626377cbaea3b21842a3525a62ba60f905f"
S = "${WORKDIR}/git"
require ${BPN}-crates.inc
diff --git a/meta-openembedded/meta-oe/recipes-crypto/botan/botan_3.2.0.bb b/meta-openembedded/meta-oe/recipes-crypto/botan/botan_3.2.0.bb
index 5eff2d383e..1fdda65a05 100644
--- a/meta-openembedded/meta-oe/recipes-crypto/botan/botan_3.2.0.bb
+++ b/meta-openembedded/meta-oe/recipes-crypto/botan/botan_3.2.0.bb
@@ -18,8 +18,8 @@ CPU:armv7ve = "armv7"
do_configure() {
python3 ${S}/configure.py \
- --prefix="${D}${exec_prefix}" \
- --libdir="${D}${libdir}" \
+ --prefix="${exec_prefix}" \
+ --libdir="${libdir}" \
--cpu="${CPU}" \
--cc-bin="${CXX}" \
--cxxflags="${CXXFLAGS}" \
@@ -39,8 +39,8 @@ do_compile() {
oe_runmake
}
do_install() {
- oe_runmake install
- sed -i -e "s|${D}||g" ${D}${libdir}/pkgconfig/botan-3.pc
+ oe_runmake DESTDIR=${D} install
+ sed -i -e 's|${WORKDIR}|<scrubbed>|g' ${D}${includedir}/botan-3/botan/build.h
}
PACKAGES += "${PN}-python3"
diff --git a/meta-openembedded/meta-oe/recipes-dbs/influxdb/influxdb_1.8.10.bb b/meta-openembedded/meta-oe/recipes-dbs/influxdb/influxdb_1.8.10.bb
index 5301071516..397b225ccb 100644
--- a/meta-openembedded/meta-oe/recipes-dbs/influxdb/influxdb_1.8.10.bb
+++ b/meta-openembedded/meta-oe/recipes-dbs/influxdb/influxdb_1.8.10.bb
@@ -38,9 +38,10 @@ USERADD_PACKAGES = "${PN}"
USERADD_PARAM:${PN} = "--system -d /var/lib/influxdb -m -s /bin/nologin influxdb"
do_install:prepend() {
- rm ${B}/src/${GO_IMPORT}/build.py
- rm ${B}/src/${GO_IMPORT}/build.sh
- rm ${B}/src/${GO_IMPORT}/Dockerfile*
+ test -e ${B}/src/${GO_IMPORT}/build.py && rm ${B}/src/${GO_IMPORT}/build.py
+ test -e ${B}/src/${GO_IMPORT}/build.sh && rm ${B}/src/${GO_IMPORT}/build.sh
+ rm -rf ${B}/src/${GO_IMPORT}/Dockerfile*
+
sed -i -e "s#usr/bin/sh#bin/sh#g" ${B}/src/${GO_IMPORT}/scripts/ci/run_perftest.sh
}
@@ -74,3 +75,5 @@ INITSCRIPT_NAME = "influxdb"
INITSCRIPT_PARAMS = "defaults"
SYSTEMD_SERVICE:${PN} = "influxdb.service"
+
+CVE_STATUS[CVE-2019-10329] = "cpe-incorrect: Version does not match and only the Jenkins plugin is affected."
diff --git a/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb-native_10.11.7.bb b/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb-native_10.11.12.bb
index 578357b480..578357b480 100644
--- a/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb-native_10.11.7.bb
+++ b/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb-native_10.11.12.bb
diff --git a/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb.inc b/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb.inc
index 33da32fb28..f0cec75568 100644
--- a/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb.inc
+++ b/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb.inc
@@ -17,17 +17,13 @@ SRC_URI = "https://archive.mariadb.org/${BP}/source/${BP}.tar.gz \
file://0001-innobase-Define-__NR_futex-if-it-does-not-exist.patch \
file://0001-aio_linux-Check-if-syscall-exists-before-using-it.patch \
file://ssize_t.patch \
- file://mm_malloc.patch \
file://sys_futex.patch \
file://cross-compiling.patch \
file://0001-sql-CMakeLists.txt-fix-gen_lex_hash-not-found.patch \
file://lfs64.patch \
file://0001-Add-missing-includes-cstdint-and-cstdio.patch \
- file://0001-Remove-the-compile_time_assert-lines.patch \
- file://0001-MDEV-33439-Fix-build-with-libxml2-2.12.patch \
"
-SRC_URI:append:libc-musl = " file://ppc-remove-glibc-dep.patch"
-SRC_URI[sha256sum] = "5239a245ed90517e96396605cd01ccd8f73cd7442d1b3076b6ffe258110e5157"
+SRC_URI[sha256sum] = "d61f23090cfc14f43e8a27c2d3ce7f80247e74481bb26a2d3a6308b8d194e167"
UPSTREAM_CHECK_URI = "https://github.com/MariaDB/server/releases"
@@ -35,10 +31,12 @@ S = "${WORKDIR}/mariadb-${PV}"
BINCONFIG_GLOB = "mysql_config"
-inherit cmake gettext binconfig update-rc.d systemd multilib_script pkgconfig
+inherit cmake gettext binconfig update-rc.d systemd multilib_script multilib_header pkgconfig
MULTILIB_SCRIPTS = "${PN}-server:${bindir}/mariadbd-safe \
- ${PN}-setupdb:${bindir}/mariadb-install-db"
+ ${PN}-setupdb:${bindir}/mariadb-install-db \
+ libmysqlclient-dev:${bindir}/mysql_config \
+ "
INITSCRIPT_PACKAGES = "${PN}-server ${PN}-setupdb"
INITSCRIPT_NAME:${PN}-server = "mysqld"
@@ -97,7 +95,6 @@ EXTRA_OECMAKE = "-DWITH_EMBEDDED_SERVER=ON \
-DINSTALL_SYSCONFDIR:PATH=${sysconfdir} \
-DMYSQL_DATADIR:PATH=/var/mysql \
-DCAT_EXECUTABLE=`which cat` \
- -DSTACK_DIRECTION=1 \
-DHAVE_SYSTEM_LIBFMT_EXITCODE=0 \
-DCMAKE_AR:FILEPATH=${AR}"
@@ -161,6 +158,7 @@ mariadb_sysroot_preprocess () {
do_install() {
oe_runmake 'DESTDIR=${D}' install
+ oe_multilib_header mysql/mariadb_version.h mysql/server/my_config.h mysql/server/private/config.h
install -d ${D}/${sysconfdir}/init.d
install -m 0644 ${WORKDIR}/my.cnf ${D}/${sysconfdir}/
diff --git a/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/0001-Add-missing-includes-cstdint-and-cstdio.patch b/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/0001-Add-missing-includes-cstdint-and-cstdio.patch
index f8ccb998be..fa580d039a 100644
--- a/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/0001-Add-missing-includes-cstdint-and-cstdio.patch
+++ b/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/0001-Add-missing-includes-cstdint-and-cstdio.patch
@@ -11,27 +11,14 @@ Upstream-Status: Pending
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Signed-off-by: Mingli Yu <mingli.yu@windriver.com>
---
- .../rocksdb/rocksdb/db/compaction/compaction_iteration_stats.h | 1 +
- storage/rocksdb/rocksdb/include/rocksdb/utilities/checkpoint.h | 1 +
- .../rocksdb/rocksdb/table/block_based/data_block_hash_index.h | 1 +
- storage/rocksdb/rocksdb/util/slice.cc | 1 +
- storage/rocksdb/rocksdb/util/string_util.h | 1 +
- 5 files changed, 5 insertions(+)
+ storage/rocksdb/rocksdb/include/rocksdb/utilities/checkpoint.h | 1 +
+ .../rocksdb/rocksdb/table/block_based/data_block_hash_index.h | 1 +
+ storage/rocksdb/rocksdb/util/slice.cc | 2 +-
+ storage/rocksdb/rocksdb/util/string_util.h | 1 +
+ 4 files changed, 4 insertions(+), 1 deletion(-)
-diff --git a/storage/rocksdb/rocksdb/db/compaction/compaction_iteration_stats.h b/storage/rocksdb/rocksdb/db/compaction/compaction_iteration_stats.h
-index 963c1d8e..73487edd 100644
---- a/storage/rocksdb/rocksdb/db/compaction/compaction_iteration_stats.h
-+++ b/storage/rocksdb/rocksdb/db/compaction/compaction_iteration_stats.h
-@@ -5,6 +5,7 @@
-
- #pragma once
-
-+#include <cstdint>
- #include "rocksdb/rocksdb_namespace.h"
-
- struct CompactionIterationStats {
diff --git a/storage/rocksdb/rocksdb/include/rocksdb/utilities/checkpoint.h b/storage/rocksdb/rocksdb/include/rocksdb/utilities/checkpoint.h
-index c7f93b4c..3c2ab805 100644
+index 7fb9d489..f7b4e6f0 100644
--- a/storage/rocksdb/rocksdb/include/rocksdb/utilities/checkpoint.h
+++ b/storage/rocksdb/rocksdb/include/rocksdb/utilities/checkpoint.h
@@ -8,6 +8,7 @@
@@ -55,20 +42,20 @@ index f356395f..32152217 100644
#include <vector>
diff --git a/storage/rocksdb/rocksdb/util/slice.cc b/storage/rocksdb/rocksdb/util/slice.cc
-index 6db11cc9..c26b6a21 100644
+index 3c3656de..b18d7f5d 100644
--- a/storage/rocksdb/rocksdb/util/slice.cc
+++ b/storage/rocksdb/rocksdb/util/slice.cc
-@@ -8,6 +8,7 @@
- // found in the LICENSE file. See the AUTHORS file for names of contributors.
+@@ -12,7 +12,7 @@
+ #include <stdio.h>
#include <algorithm>
+-
+#include <cstdint>
+ #include "rocksdb/convenience.h"
#include "rocksdb/slice_transform.h"
- #include "rocksdb/slice.h"
- #include "util/string_util.h"
-
-diff --git a/util/string_util.h b/util/string_util.h
-index 55d106fff02..11178fd1d7b 100644
+ #include "rocksdb/utilities/object_registry.h"
+diff --git a/storage/rocksdb/rocksdb/util/string_util.h b/storage/rocksdb/rocksdb/util/string_util.h
+index 7794dbb0..b480177e 100644
--- a/storage/rocksdb/rocksdb/util/string_util.h
+++ b/storage/rocksdb/rocksdb/util/string_util.h
@@ -6,6 +6,7 @@
@@ -80,5 +67,5 @@ index 55d106fff02..11178fd1d7b 100644
#include <string>
#include <unordered_map>
--
-2.25.1
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/0001-MDEV-33439-Fix-build-with-libxml2-2.12.patch b/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/0001-MDEV-33439-Fix-build-with-libxml2-2.12.patch
deleted file mode 100644
index 3e42535dad..0000000000
--- a/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/0001-MDEV-33439-Fix-build-with-libxml2-2.12.patch
+++ /dev/null
@@ -1,170 +0,0 @@
-From dae52f5916ef59434c93f0b716270f59dd0c3a94 Mon Sep 17 00:00:00 2001
-From: Jan Tojnar <jtojnar@gmail.com>
-Date: Sun, 7 Jan 2024 10:19:54 +0100
-Subject: [PATCH] MDEV-33439 Fix build with libxml2 2.12
-MIME-Version: 1.0
-Content-Type: text/plain; charset=UTF-8
-Content-Transfer-Encoding: 8bit
-
-libxml2 2.12.0 made `xmlGetLastError()` return `const` pointer:
-
-https://gitlab.gnome.org/GNOME/libxml2/-/commit/61034116d0a3c8b295c6137956adc3ae55720711
-
-Clang 16 does not like this:
-
- error: assigning to 'xmlErrorPtr' (aka '_xmlError *') from 'const xmlError *' (aka 'const _xmlError *') discards qualifiers
- error: cannot initialize a variable of type 'xmlErrorPtr' (aka '_xmlError *') with an rvalue of type 'const xmlError *' (aka 'const _xmlError *')
-
-Let’s update the variables to `const`.
-For older versions, it will be automatically converted.
-
-But then `xmlResetError(xmlError*)` will not like the `const` pointer:
-
- error: no matching function for call to 'xmlResetError'
- note: candidate function not viable: 1st argument ('const xmlError *' (aka 'const _xmlError *')) would lose const qualifier
-
-Let’s replace it with `xmlResetLastError()`.
-
-ALso remove `LIBXMLDOC::Xerr` protected member property.
-It was introduced in 65b0e5455b547a3d574fa77b34cce23ae3bea0a0
-along with the `xmlResetError` calls.
-It does not appear to be used for anything.
-
-Upstream-Status: Backport [https://github.com/MariaDB/server/pull/2983]
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
----
- storage/connect/libdoc.cpp | 39 +++++++++++++++++++-------------------
- 1 file changed, 19 insertions(+), 20 deletions(-)
-
-diff --git a/storage/connect/libdoc.cpp b/storage/connect/libdoc.cpp
-index 67f22ce2..ab588dd4 100644
---- a/storage/connect/libdoc.cpp
-+++ b/storage/connect/libdoc.cpp
-@@ -93,7 +93,6 @@ class LIBXMLDOC : public XMLDOCUMENT {
- xmlXPathContextPtr Ctxp;
- xmlXPathObjectPtr Xop;
- xmlXPathObjectPtr NlXop;
-- xmlErrorPtr Xerr;
- char *Buf; // Temporary
- bool Nofreelist;
- }; // end of class LIBXMLDOC
-@@ -327,7 +326,6 @@ LIBXMLDOC::LIBXMLDOC(char *nsl, char *nsdf, char *enc, PFBLOCK fp)
- Ctxp = NULL;
- Xop = NULL;
- NlXop = NULL;
-- Xerr = NULL;
- Buf = NULL;
- Nofreelist = false;
- } // end of LIBXMLDOC constructor
-@@ -365,8 +363,8 @@ bool LIBXMLDOC::ParseFile(PGLOBAL g, char *fn)
- Encoding = (char*)Docp->encoding;
-
- return false;
-- } else if ((Xerr = xmlGetLastError()))
-- xmlResetError(Xerr);
-+ } else if (xmlGetLastError())
-+ xmlResetLastError();
-
- return true;
- } // end of ParseFile
-@@ -505,9 +503,9 @@ int LIBXMLDOC::DumpDoc(PGLOBAL g, char *ofn)
- #if 1
- // This function does not crash (
- if (xmlSaveFormatFileEnc((const char *)ofn, Docp, Encoding, 0) < 0) {
-- xmlErrorPtr err = xmlGetLastError();
-+ const xmlError *err = xmlGetLastError();
- strcpy(g->Message, (err) ? err->message : "Error saving XML doc");
-- xmlResetError(Xerr);
-+ xmlResetLastError();
- rc = -1;
- } // endif Save
- // rc = xmlDocDump(of, Docp);
-@@ -546,8 +544,8 @@ void LIBXMLDOC::CloseDoc(PGLOBAL g, PFBLOCK xp)
- if (Nlist) {
- xmlXPathFreeNodeSet(Nlist);
-
-- if ((Xerr = xmlGetLastError()))
-- xmlResetError(Xerr);
-+ if (xmlGetLastError())
-+ xmlResetLastError();
-
- Nlist = NULL;
- } // endif Nlist
-@@ -555,8 +553,8 @@ void LIBXMLDOC::CloseDoc(PGLOBAL g, PFBLOCK xp)
- if (Xop) {
- xmlXPathFreeObject(Xop);
-
-- if ((Xerr = xmlGetLastError()))
-- xmlResetError(Xerr);
-+ if (xmlGetLastError())
-+ xmlResetLastError();
-
- Xop = NULL;
- } // endif Xop
-@@ -564,8 +562,8 @@ void LIBXMLDOC::CloseDoc(PGLOBAL g, PFBLOCK xp)
- if (NlXop) {
- xmlXPathFreeObject(NlXop);
-
-- if ((Xerr = xmlGetLastError()))
-- xmlResetError(Xerr);
-+ if (xmlGetLastError())
-+ xmlResetLastError();
-
- NlXop = NULL;
- } // endif NlXop
-@@ -573,8 +571,8 @@ void LIBXMLDOC::CloseDoc(PGLOBAL g, PFBLOCK xp)
- if (Ctxp) {
- xmlXPathFreeContext(Ctxp);
-
-- if ((Xerr = xmlGetLastError()))
-- xmlResetError(Xerr);
-+ if (xmlGetLastError())
-+ xmlResetLastError();
-
- Ctxp = NULL;
- } // endif Ctxp
-@@ -590,6 +588,7 @@ void LIBXMLDOC::CloseDoc(PGLOBAL g, PFBLOCK xp)
- /******************************************************************/
- xmlNodeSetPtr LIBXMLDOC::GetNodeList(PGLOBAL g, xmlNodePtr np, char *xp)
- {
-+ const xmlError *xerr;
- xmlNodeSetPtr nl;
-
- if (trace(1))
-@@ -649,11 +648,11 @@ xmlNodeSetPtr LIBXMLDOC::GetNodeList(PGLOBAL g, xmlNodePtr np, char *xp)
- } else
- xmlXPathFreeObject(Xop); // Caused node not found
-
-- if ((Xerr = xmlGetLastError())) {
-- strcpy(g->Message, Xerr->message);
-- xmlResetError(Xerr);
-+ if ((xerr = xmlGetLastError())) {
-+ strcpy(g->Message, xerr->message);
-+ xmlResetLastError();
- return NULL;
-- } // endif Xerr
-+ } // endif xerr
-
- } // endif Xop
-
-@@ -1079,7 +1078,7 @@ void XML2NODE::AddText(PGLOBAL g, PCSZ txtp)
- /******************************************************************/
- void XML2NODE::DeleteChild(PGLOBAL g, PXNODE dnp)
- {
-- xmlErrorPtr xerr;
-+ const xmlError *xerr;
-
- if (trace(1))
- htrc("DeleteChild: node=%p\n", dnp);
-@@ -1122,7 +1121,7 @@ void XML2NODE::DeleteChild(PGLOBAL g, PXNODE dnp)
- if (trace(1))
- htrc("DeleteChild: errmsg=%-.256s\n", xerr->message);
-
-- xmlResetError(xerr);
-+ xmlResetLastError();
- } // end of DeleteChild
-
- /* -------------------- class XML2NODELIST ---------------------- */
---
-2.44.0
-
diff --git a/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/0001-Remove-the-compile_time_assert-lines.patch b/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/0001-Remove-the-compile_time_assert-lines.patch
deleted file mode 100644
index 9a6e28297b..0000000000
--- a/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/0001-Remove-the-compile_time_assert-lines.patch
+++ /dev/null
@@ -1,43 +0,0 @@
-From cc5f1d0759b367265a1a000287e2ec15c31eb518 Mon Sep 17 00:00:00 2001
-From: Mingli Yu <mingli.yu@windriver.com>
-Date: Mon, 26 Feb 2024 14:56:02 +0800
-Subject: [PATCH] Remove the compile_time_assert lines
-
-Remove the problematic compile_time_assert lines to fix the below build
-failure on 32-bit arm.
- In file included from TOPDIR/build/tmp/work/cortexa15t2hf-neon-yoe-linux-gnueabi/mariadb/10.11.7/mariadb-10.11.7/tests/mysql_client_test.c:38:
- TOPDIR/build/tmp/work/cortexa15t2hf-neon-yoe-linux-gnueabi/mariadb/10.11.7/mariadb-10.11.7/tests/mysql_client_fw.c:1438:3: error: 'compile_time_assert' declared as an array with a negative size
- 1438 | compile_time_assert(sizeof(MYSQL) == 77*sizeof(void*)+656);
- | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
-
-Upstream-Status: Inappropriate [Upstream will bring the asset back
- in a new way [1]]
-[1] https://jira.mariadb.org/browse/MDEV-33429
-
-Signed-off-by: Mingli Yu <mingli.yu@windriver.com>
----
- tests/mysql_client_fw.c | 8 --------
- 1 file changed, 8 deletions(-)
-
-diff --git a/tests/mysql_client_fw.c b/tests/mysql_client_fw.c
-index c9e64678..5c0c7ce2 100644
---- a/tests/mysql_client_fw.c
-+++ b/tests/mysql_client_fw.c
-@@ -1430,14 +1430,6 @@ int main(int argc, char **argv)
- tests_to_run[i]= NULL;
- }
-
--#ifdef _WIN32
-- /* must be the same in C/C and embedded, 1208 on 64bit, 968 on 32bit */
-- compile_time_assert(sizeof(MYSQL) == 60*sizeof(void*)+728);
--#else
-- /* must be the same in C/C and embedded, 1272 on 64bit, 964 on 32bit */
-- compile_time_assert(sizeof(MYSQL) == 77*sizeof(void*)+656);
--#endif
--
- if (mysql_server_init(embedded_server_arg_count,
- embedded_server_args,
- (char**) embedded_server_groups))
---
-2.25.1
-
diff --git a/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/mm_malloc.patch b/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/mm_malloc.patch
deleted file mode 100644
index 6aa6c84882..0000000000
--- a/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/mm_malloc.patch
+++ /dev/null
@@ -1,13 +0,0 @@
-Upstream-Status: Pending
-
---- a/storage/rocksdb/rocksdb/port/jemalloc_helper.h
-+++ b/storage/rocksdb/rocksdb/port/jemalloc_helper.h
-@@ -5,7 +5,7 @@
-
- #pragma once
-
--#if defined(__clang__)
-+#if defined(__clang__) && defined(__GLIBC__)
- // glibc's `posix_memalign()` declaration specifies `throw()` while clang's
- // declaration does not. There is a hack in clang to make its re-declaration
- // compatible with glibc's if they are declared consecutively. That hack breaks
diff --git a/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/ppc-remove-glibc-dep.patch b/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/ppc-remove-glibc-dep.patch
deleted file mode 100644
index 3787b74ad1..0000000000
--- a/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb/ppc-remove-glibc-dep.patch
+++ /dev/null
@@ -1,43 +0,0 @@
-Upstream-Status: Pending
-
-Remove glibc specific function dependencies
-
-Sourced from: https://git.alpinelinux.org/aports/tree/main/mariadb/ppc-remove-glibc-dep.patch
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
-
-diff --git a/include/my_cpu.h b/include/my_cpu.h
-index f2e26fca..94599b74 100644
---- a/include/my_cpu.h
-+++ b/include/my_cpu.h
-@@ -24,17 +24,16 @@
- */
-
- #ifdef _ARCH_PWR8
--#include <sys/platform/ppc.h>
- /* Very low priority */
--#define HMT_very_low() __ppc_set_ppr_very_low()
-+#define HMT_very_low() asm volatile("or 31,31,31")
- /* Low priority */
--#define HMT_low() __ppc_set_ppr_low()
-+#define HMT_low() asm volatile ("or 1,1,1")
- /* Medium low priority */
--#define HMT_medium_low() __ppc_set_ppr_med_low()
-+#define HMT_medium_low() asm volatile ("or 6,6,6")
- /* Medium priority */
--#define HMT_medium() __ppc_set_ppr_med()
-+#define HMT_medium() asm volatile ("or 2,2,2")
- /* Medium high priority */
--#define HMT_medium_high() __ppc_set_ppr_med_high()
-+#define HMT_medium_high() asm volatile("or 5,5,5")
- /* High priority */
- #define HMT_high() asm volatile("or 3,3,3")
- #else
-@@ -72,7 +71,7 @@ static inline void MY_RELAX_CPU(void)
- __asm__ __volatile__ ("pause");
- #endif
- #elif defined(_ARCH_PWR8)
-- __ppc_get_timebase();
-+ __builtin_ppc_get_timebase();
- #elif defined __GNUC__ && (defined __arm__ || defined __aarch64__)
- /* Mainly, prevent the compiler from optimizing away delay loops */
- __asm__ __volatile__ ("":::"memory");
diff --git a/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb_10.11.7.bb b/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb_10.11.12.bb
index b1d1355e2b..b1d1355e2b 100644
--- a/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb_10.11.7.bb
+++ b/meta-openembedded/meta-oe/recipes-dbs/mysql/mariadb_10.11.12.bb
diff --git a/meta-openembedded/meta-oe/recipes-dbs/postgresql/files/0003-configure.ac-bypass-autoconf-2.69-version-check.patch b/meta-openembedded/meta-oe/recipes-dbs/postgresql/files/0003-configure.ac-bypass-autoconf-2.69-version-check.patch
index 9df4d073ff..7707d238e7 100644
--- a/meta-openembedded/meta-oe/recipes-dbs/postgresql/files/0003-configure.ac-bypass-autoconf-2.69-version-check.patch
+++ b/meta-openembedded/meta-oe/recipes-dbs/postgresql/files/0003-configure.ac-bypass-autoconf-2.69-version-check.patch
@@ -13,12 +13,12 @@ Signed-off-by: Yi Fan Yu <yifan.yu@windriver.com>
1 file changed, 4 deletions(-)
diff --git a/configure.ac b/configure.ac
-index 401ce30..27f382d 100644
+index 4f25567..b6b1eff 100644
--- a/configure.ac
+++ b/configure.ac
@@ -19,10 +19,6 @@ m4_pattern_forbid(^PGAC_)dnl to catch undefined macros
- AC_INIT([PostgreSQL], [16.3], [pgsql-bugs@lists.postgresql.org], [], [https://www.postgresql.org/])
+ AC_INIT([PostgreSQL], [16.10], [pgsql-bugs@lists.postgresql.org], [], [https://www.postgresql.org/])
-m4_if(m4_defn([m4_PACKAGE_VERSION]), [2.69], [], [m4_fatal([Autoconf version 2.69 is required.
-Untested combinations of 'autoconf' and PostgreSQL versions are not
@@ -28,5 +28,5 @@ index 401ce30..27f382d 100644
AC_CONFIG_SRCDIR([src/backend/access/common/heaptuple.c])
AC_CONFIG_AUX_DIR(config)
--
-2.25.1
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-dbs/postgresql/postgresql.inc b/meta-openembedded/meta-oe/recipes-dbs/postgresql/postgresql.inc
index e29a5bef77..5e0c0edf5e 100644
--- a/meta-openembedded/meta-oe/recipes-dbs/postgresql/postgresql.inc
+++ b/meta-openembedded/meta-oe/recipes-dbs/postgresql/postgresql.inc
@@ -19,7 +19,7 @@ DESCRIPTION = "\
"
HOMEPAGE = "http://www.postgresql.com"
LICENSE = "0BSD"
-DEPENDS = "libnsl2 readline tzcode-native"
+DEPENDS = "libnsl2 readline tzcode-native perl"
ARM_INSTRUCTION_SET = "arm"
@@ -37,7 +37,7 @@ LEAD_SONAME = "libpq.so"
export LDFLAGS_SL = "${LDFLAGS}"
export LDFLAGS_EX_BE = "-Wl,--export-dynamic"
-inherit autotools pkgconfig perlnative python3native python3targetconfig useradd update-rc.d systemd gettext cpan-base multilib_header
+inherit autotools pkgconfig perlnative python3native python3targetconfig useradd update-rc.d systemd gettext perl-version multilib_header
CFLAGS += "-I${STAGING_INCDIR}/${PYTHON_DIR} -I${STAGING_INCDIR}/tcl8.6"
@@ -122,6 +122,12 @@ python populate_packages:prepend() {
}
+# Same as the function in cpan-base.bbclass (but without the perl RDEPENDS)
+def is_target(d):
+ if not bb.data.inherits_class('native', d):
+ return "yes"
+ return "no"
+
# This will make native perl use target settings (for include dirs etc.)
export PERLCONFIGTARGET = "${@is_target(d)}"
export PERL_ARCHLIB = "${STAGING_LIBDIR}${PERL_OWN_DIR}/perl5/${@get_perl_version(d)}/${@get_perl_arch(d)}"
diff --git a/meta-openembedded/meta-oe/recipes-dbs/postgresql/postgresql_16.3.bb b/meta-openembedded/meta-oe/recipes-dbs/postgresql/postgresql_16.10.bb
index 6df719cd98..b1b8411dc7 100644
--- a/meta-openembedded/meta-oe/recipes-dbs/postgresql/postgresql_16.3.bb
+++ b/meta-openembedded/meta-oe/recipes-dbs/postgresql/postgresql_16.10.bb
@@ -1,6 +1,6 @@
require postgresql.inc
-LIC_FILES_CHKSUM = "file://COPYRIGHT;md5=89afbb2d7716371015101c2b2cb4297a"
+LIC_FILES_CHKSUM = "file://COPYRIGHT;md5=08b6032a749e67f6e3de84ea8e466933"
SRC_URI += "\
file://not-check-libperl.patch \
@@ -11,6 +11,6 @@ SRC_URI += "\
file://0005-postgresql-fix-ptest-failure-of-sysviews.patch \
"
-SRC_URI[sha256sum] = "331963d5d3dc4caf4216a049fa40b66d6bcb8c730615859411b9518764e60585"
+SRC_URI[sha256sum] = "de8485f4ce9c32e3ddfeef0b7c261eed1cecb54c9bcd170e437ff454cb292b42"
CVE_STATUS[CVE-2017-8806] = "not-applicable-config: Ddoesn't apply to out configuration of postgresql so we can safely ignore it."
diff --git a/meta-openembedded/meta-oe/recipes-dbs/psqlodbc/psqlodbc_16.00.0000.bb b/meta-openembedded/meta-oe/recipes-dbs/psqlodbc/psqlodbc_16.00.0000.bb
index a1ef8e75e9..d3b3ea5109 100644
--- a/meta-openembedded/meta-oe/recipes-dbs/psqlodbc/psqlodbc_16.00.0000.bb
+++ b/meta-openembedded/meta-oe/recipes-dbs/psqlodbc/psqlodbc_16.00.0000.bb
@@ -19,7 +19,7 @@ HOMEPAGE = "https://odbc.postgresql.org/"
LICENSE = "LGPL-2.0-only"
LIC_FILES_CHKSUM = "file://license.txt;md5=6db3822fc7512e83087ba798da013692"
-SRC_URI = "http://ftp.postgresql.org/pub/odbc/versions/src/${BPN}-${PV}.tar.gz \
+SRC_URI = "http://ftp.postgresql.org/pub/odbc/versions.old/src/${BPN}-${PV}.tar.gz \
file://psqlodbc-remove-some-checks-for-cross-compiling.patch \
file://psqlodbc-donot-use-the-hardcode-libdir.patch \
file://psqlodbc-fix-for-ptest-support.patch \
diff --git a/meta-openembedded/meta-oe/recipes-dbs/rocksdb/files/static_library_as_option.patch b/meta-openembedded/meta-oe/recipes-dbs/rocksdb/files/static_library_as_option.patch
new file mode 100644
index 0000000000..9a85e8db45
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-dbs/rocksdb/files/static_library_as_option.patch
@@ -0,0 +1,71 @@
+From 285d306494bde3e9c24c8cd6fea1eb380a304d03 Mon Sep 17 00:00:00 2001
+From: Bindu-Bhabu <bindudaniel1996@gmail.com>
+Date: Fri, 26 Jul 2024 15:14:45 +0530
+Subject: Add option to CMake for building static libraries
+
+ROCKSDB creates a STATIC library target reference by default.
+Modify the cmake so that the STATIC library is also an option
+just like creating a SHARED library and set default to ON.
+
+Upstream-Status: Submitted [https://github.com/facebook/rocksdb/pull/12890]
+
+Signed-off-by: Nisha Parrakat <nisha.m.parrakat@bmw.de>
+Signed-off-by: Bindu Bhabu <bhabu.bindu@kpit.com>
+---
+ CMakeLists.txt | 29 +++++++++++++++++------------
+ 1 file changed, 17 insertions(+), 12 deletions(-)
+
+diff --git a/CMakeLists.txt b/CMakeLists.txt
+index 93b884dd9c1..2ca925d505c 100644
+--- a/CMakeLists.txt
++++ b/CMakeLists.txt
+@@ -98,6 +98,7 @@ if (WITH_WINDOWS_UTF8_FILENAMES)
+ add_definitions(-DROCKSDB_WINDOWS_UTF8_FILENAMES)
+ endif()
+ option(ROCKSDB_BUILD_SHARED "Build shared versions of the RocksDB libraries" ON)
++option(ROCKSDB_BUILD_STATIC "Build static versions of the RocksDB libraries" ON)
+
+ if( NOT DEFINED CMAKE_CXX_STANDARD )
+ set(CMAKE_CXX_STANDARD 17)
+@@ -1139,11 +1140,13 @@ string(REGEX REPLACE "[^0-9: /-]+" "" GIT_DATE "${GIT_DATE}")
+ set(BUILD_VERSION_CC ${CMAKE_BINARY_DIR}/build_version.cc)
+ configure_file(util/build_version.cc.in ${BUILD_VERSION_CC} @ONLY)
+
+-add_library(${ROCKSDB_STATIC_LIB} STATIC ${SOURCES} ${BUILD_VERSION_CC})
+-target_include_directories(${ROCKSDB_STATIC_LIB} PUBLIC
+- $<BUILD_INTERFACE:${PROJECT_SOURCE_DIR}/include>)
+-target_link_libraries(${ROCKSDB_STATIC_LIB} PRIVATE
+- ${THIRDPARTY_LIBS} ${SYSTEM_LIBS})
++if(ROCKSDB_BUILD_STATIC)
++ add_library(${ROCKSDB_STATIC_LIB} STATIC ${SOURCES} ${BUILD_VERSION_CC})
++ target_include_directories(${ROCKSDB_STATIC_LIB} PUBLIC
++ $<BUILD_INTERFACE:${PROJECT_SOURCE_DIR}/include>)
++ target_link_libraries(${ROCKSDB_STATIC_LIB} PRIVATE
++ ${THIRDPARTY_LIBS} ${SYSTEM_LIBS})
++endif()
+
+ if(ROCKSDB_BUILD_SHARED)
+ add_library(${ROCKSDB_SHARED_LIB} SHARED ${SOURCES} ${BUILD_VERSION_CC})
+@@ -1238,13 +1241,15 @@ if(NOT WIN32 OR ROCKSDB_INSTALL_ON_WINDOWS)
+
+ install(DIRECTORY "${PROJECT_SOURCE_DIR}/cmake/modules" COMPONENT devel DESTINATION ${package_config_destination})
+
+- install(
+- TARGETS ${ROCKSDB_STATIC_LIB}
+- EXPORT RocksDBTargets
+- COMPONENT devel
+- ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}"
+- INCLUDES DESTINATION "${CMAKE_INSTALL_INCLUDEDIR}"
+- )
++ if(ROCKSDB_BUILD_STATIC)
++ install(
++ TARGETS ${ROCKSDB_STATIC_LIB}
++ EXPORT RocksDBTargets
++ COMPONENT devel
++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}"
++ INCLUDES DESTINATION "${CMAKE_INSTALL_INCLUDEDIR}"
++ )
++ endif()
+
+ if(ROCKSDB_BUILD_SHARED)
+ install(
diff --git a/meta-openembedded/meta-oe/recipes-dbs/rocksdb/rocksdb_9.0.0.bb b/meta-openembedded/meta-oe/recipes-dbs/rocksdb/rocksdb_9.0.0.bb
index 444351dbb4..fae54fdba4 100644
--- a/meta-openembedded/meta-oe/recipes-dbs/rocksdb/rocksdb_9.0.0.bb
+++ b/meta-openembedded/meta-oe/recipes-dbs/rocksdb/rocksdb_9.0.0.bb
@@ -17,6 +17,7 @@ SRC_URI = "git://github.com/facebook/${BPN}.git;branch=${SRCBRANCH};protocol=htt
file://0005-Implement-timer-implementation-for-mips-platform.patch \
file://0006-Implement-timer-for-arm-v6.patch \
file://0007-Fix-declaration-scope-of-LE_LOAD32-in-crc32c.patch \
+ file://static_library_as_option.patch \
"
SRC_URI:append:riscv32 = " file://0001-replace-old-sync-with-new-atomic-builtin-equivalents.patch"
@@ -43,6 +44,7 @@ EXTRA_OECMAKE = "\
-DWITH_BENCHMARK_TOOLS=OFF \
-DWITH_TOOLS=OFF \
-DFAIL_ON_WARNINGS=OFF \
+ -DROCKSDB_BUILD_STATIC=OFF \
"
CXXFLAGS += "${@bb.utils.contains('SELECTED_OPTIMIZATION', '-Og', '-DXXH_NO_INLINE_HINTS', '', d)}"
diff --git a/meta-openembedded/meta-oe/recipes-devtools/abseil-cpp/abseil-cpp/0001-PR-1739-container-internal-Explicitly-include-cstdin.patch b/meta-openembedded/meta-oe/recipes-devtools/abseil-cpp/abseil-cpp/0001-PR-1739-container-internal-Explicitly-include-cstdin.patch
new file mode 100644
index 0000000000..bb7afec2b5
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/abseil-cpp/abseil-cpp/0001-PR-1739-container-internal-Explicitly-include-cstdin.patch
@@ -0,0 +1,34 @@
+From af8424e2788446224a8b790d4a87aa06f4193320 Mon Sep 17 00:00:00 2001
+From: Christopher Fore <csfore@posteo.net>
+Date: Mon, 5 Aug 2024 12:09:18 -0700
+Subject: [PATCH] PR #1739: container/internal: Explicitly include <cstdint>
+
+Imported from GitHub PR https://github.com/abseil/abseil-cpp/pull/1739
+
+GCC 15 will no longer include <cstdint> by default, resulting in build failures in projects that do not explicitly include it.
+
+Merge faf1b03a591f06933da02976119da5743f428e4f into 9cb5e5d15c142e5cc43a2c1db87c8e4e5b6d38a5
+
+Merging this change closes #1739
+
+COPYBARA_INTEGRATE_REVIEW=https://github.com/abseil/abseil-cpp/pull/1739 from csfore:gcc-15-fix faf1b03a591f06933da02976119da5743f428e4f
+PiperOrigin-RevId: 659637669
+Change-Id: If14cb0e3522774cb700bd5a74abffb75feb7a0f5
+
+Upstream-Status: Backport [20250127.0 809e5de7b92950849289236a5a09e9cb4f32c7b9]
+---
+ absl/container/internal/container_memory.h | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/absl/container/internal/container_memory.h b/absl/container/internal/container_memory.h
+index 3262d4eb..ac01989d 100644
+--- a/absl/container/internal/container_memory.h
++++ b/absl/container/internal/container_memory.h
+@@ -17,6 +17,7 @@
+
+ #include <cassert>
+ #include <cstddef>
++#include <cstdint>
+ #include <cstring>
+ #include <memory>
+ #include <new>
diff --git a/meta-openembedded/meta-oe/recipes-devtools/abseil-cpp/abseil-cpp_20240116.2.bb b/meta-openembedded/meta-oe/recipes-devtools/abseil-cpp/abseil-cpp_20240116.3.bb
index 87ab239311..a11b5cbb53 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/abseil-cpp/abseil-cpp_20240116.2.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/abseil-cpp/abseil-cpp_20240116.3.bb
@@ -7,7 +7,7 @@ SECTION = "libs"
LICENSE = "Apache-2.0"
LIC_FILES_CHKSUM = "file://LICENSE;md5=df52c6edb7adc22e533b2bacc3bd3915"
-SRCREV = "d7aaad83b488fd62bd51c81ecf16cd938532cc0a"
+SRCREV = "54fac219c4ef0bc379dfffb0b8098725d77ac81b"
BRANCH = "lts_2024_01_16"
SRC_URI = "git://github.com/abseil/abseil-cpp;branch=${BRANCH};protocol=https \
file://0001-absl-always-use-asm-sgidefs.h.patch \
@@ -15,6 +15,7 @@ SRC_URI = "git://github.com/abseil/abseil-cpp;branch=${BRANCH};protocol=https \
file://abseil-ppc-fixes.patch \
file://0003-Remove-neon-option-from-cross-compilation.patch \
file://0004-PR-1644-unscaledcycleclock-remove-RISC-V-support.patch \
+ file://0001-PR-1739-container-internal-Explicitly-include-cstdin.patch \
"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-oe/recipes-devtools/android-tools/android-tools/android-tools-adbd.service b/meta-openembedded/meta-oe/recipes-devtools/android-tools/android-tools/android-tools-adbd.service
index ddf8d7f74e..b6661f2e39 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/android-tools/android-tools/android-tools-adbd.service
+++ b/meta-openembedded/meta-oe/recipes-devtools/android-tools/android-tools/android-tools-adbd.service
@@ -1,6 +1,6 @@
[Unit]
Description=Android Debug Bridge
-ConditionPathExists=/var/usb-debugging-enabled
+ConditionPathExists=/etc/usb-debugging-enabled
Before=android-system.service
[Service]
diff --git a/meta-openembedded/meta-oe/recipes-devtools/android-tools/android-tools_5.1.1.r37.bb b/meta-openembedded/meta-oe/recipes-devtools/android-tools/android-tools_5.1.1.r37.bb
index 1c66ea4997..9f02d703ba 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/android-tools/android-tools_5.1.1.r37.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/android-tools/android-tools_5.1.1.r37.bb
@@ -189,7 +189,7 @@ FILES:${PN}-fstools = "\
BBCLASSEXTEND = "native"
android_tools_enable_devmode() {
- touch ${IMAGE_ROOTFS}/var/usb-debugging-enabled
+ touch ${IMAGE_ROOTFS}/etc/usb-debugging-enabled
}
ROOTFS_POSTPROCESS_COMMAND_${PN}-adbd += "${@bb.utils.contains("USB_DEBUGGING_ENABLED", "1", "android_tools_enable_devmode;", "", d)}"
diff --git a/meta-openembedded/meta-oe/recipes-devtools/cjson/cjson_1.7.17.bb b/meta-openembedded/meta-oe/recipes-devtools/cjson/cjson_1.7.19.bb
index ea74f1d680..799eb119d6 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/cjson/cjson_1.7.17.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/cjson/cjson_1.7.19.bb
@@ -7,7 +7,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=218947f77e8cb8e2fa02918dc41c50d0"
SRC_URI = "git://github.com/DaveGamble/cJSON.git;branch=master;protocol=https \
file://run-ptest \
"
-SRCREV = "87d8f0961a01bf09bef98ff89bae9fdec42181ee"
+SRCREV = "c859b25da02955fef659d658b8f324b5cde87be3"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-oe/recipes-devtools/debootstrap/debootstrap_1.0.132.bb b/meta-openembedded/meta-oe/recipes-devtools/debootstrap/debootstrap_1.0.132.bb
index c28a51749c..94c112d395 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/debootstrap/debootstrap_1.0.132.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/debootstrap/debootstrap_1.0.132.bb
@@ -5,7 +5,7 @@ LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://debian/copyright;md5=1e68ced6e1689d4cd9dac75ff5225608"
SRC_URI = "\
- ${DEBIAN_MIRROR}/main/d/debootstrap/debootstrap_${PV}.tar.gz \
+ https://salsa.debian.org/installer-team/debootstrap/-/archive/${PV}/debootstrap_${PV}.tar.gz \
file://0001-support-to-override-usr-sbin-and-usr-share.patch \
file://0002-support-to-override-usr-bin-arch-test.patch \
file://0001-do-not-hardcode-the-full-path-of-dpkg.patch \
diff --git a/meta-openembedded/meta-oe/recipes-devtools/flatbuffers/flatbuffers.bb b/meta-openembedded/meta-oe/recipes-devtools/flatbuffers/flatbuffers.bb
index 183554e2c8..3103fd0091 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/flatbuffers/flatbuffers.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/flatbuffers/flatbuffers.bb
@@ -23,6 +23,11 @@ EXTRA_OECMAKE:append:class-target = " -DFLATBUFFERS_FLATC_EXECUTABLE=${STAGING_B
inherit cmake python3native
+rm_flatc_cmaketarget_for_target() {
+ rm -f "${SYSROOT_DESTDIR}/${libdir}/cmake/flatbuffers/FlatcTargets.cmake"
+}
+SYSROOT_PREPROCESS_FUNCS:class-target += "rm_flatc_cmaketarget_for_target"
+
FILES:${PN}-compiler = "${bindir}"
BBCLASSEXTEND = "native nativesdk"
diff --git a/meta-openembedded/meta-oe/recipes-devtools/flatbuffers/python3-flatbuffers.bb b/meta-openembedded/meta-oe/recipes-devtools/flatbuffers/python3-flatbuffers.bb
index 5d3c73fd9a..1fab013580 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/flatbuffers/python3-flatbuffers.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/flatbuffers/python3-flatbuffers.bb
@@ -12,4 +12,4 @@ RDEPENDS:${PN} = "flatbuffers"
inherit setuptools3
-BBCLASSEXTEND = "native"
+BBCLASSEXTEND = "native nativesdk"
diff --git a/meta-openembedded/meta-oe/recipes-devtools/giflib/files/add_suffix_to_convert_binary_used_in_Makefile.patch b/meta-openembedded/meta-oe/recipes-devtools/giflib/files/add_suffix_to_convert_binary_used_in_Makefile.patch
deleted file mode 100644
index a01b28ac6d..0000000000
--- a/meta-openembedded/meta-oe/recipes-devtools/giflib/files/add_suffix_to_convert_binary_used_in_Makefile.patch
+++ /dev/null
@@ -1,42 +0,0 @@
-Subject: Modify binary name "convert" to "convert.im7"
-
-The change is needed to resolve the below compilation error
-after giflib version upgrade. Log data follows:
-| DEBUG: Executing shell function do_compile
-| NOTE: make -j 8
-| make -C doc
-| make[1]: Entering directory '../giflib/5.2.2/giflib-5.2.2/doc'
-| convert ../pic/gifgrid.gif -resize 50x50 giflib-logo.gif
-| make[1]: convert: No such file or directory
-| make[1]: *** [Makefile:46: giflib-logo.gif] Error 127
-| make[1]: Leaving directory '../giflib/5.2.2/giflib-5.2.2/doc'
-| make: *** [Makefile:93: all] Error 2
-| ERROR: oe_runmake failed
-
-Added dependency on ImageMagick which includes "convert" utility,
-to ensure availability of required tool during compilation process.
-
-This patch updates the binary name used in Makefile from
-"convert" to "convert.im7" for resizing the logo image used in HTML
-documentation as Imagemagick installs binary in this format.
-
-Below commits justify the cause of adding the suffix to binaries
-provided by ImageMagic package:
-https://git.openembedded.org/meta-openembedded/commit/meta-oe/recipes-support/imagemagick?id=dcbb49f707e7ad9bf755dd3275ffc442154b8144
-https://git.openembedded.org/meta-openembedded/commit/meta-oe/recipes-support/imagemagick?id=6e0c24e9b3f9d430dec57f61f8c12c74bca5375d
-
-Signed-off-by: Bhabu Bindu <bhabubindu@kpit.com>
-Upstream-Status: Inappropriate [OE specific]
-
-===================================================================
---- a/doc/Makefile
-+++ b/doc/Makefile
-@@ -43,7 +43,7 @@
-
- # Logo image file for HTML docs
- giflib-logo.gif: ../pic/gifgrid.gif
-- convert $^ -resize 50x50 $@
-+ convert.im7 $^ -resize 50x50 $@
-
- # Philosophical choice: the website gets the internal manual pages
- allhtml: $(XMLALL:.xml=.html) giflib-logo.gif
diff --git a/meta-openembedded/meta-oe/recipes-devtools/giflib/giflib/0001-Makefile-fix-typo-in-soname-argument.patch b/meta-openembedded/meta-oe/recipes-devtools/giflib/giflib/0001-Makefile-fix-typo-in-soname-argument.patch
new file mode 100644
index 0000000000..dc87ed60b9
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/giflib/giflib/0001-Makefile-fix-typo-in-soname-argument.patch
@@ -0,0 +1,34 @@
+From 7f0cd4b6b56183b0afbefd01425e5ebd2b8733b4 Mon Sep 17 00:00:00 2001
+From: Martin Jansa <martin.jansa@gmail.com>
+Date: Mon, 8 Jul 2024 13:18:11 +0200
+Subject: [PATCH] Makefile: fix typo in soname argument
+
+* introduced in:
+ https://sourceforge.net/p/giflib/code/ci/b65c7ac2905c0842e7977a7b51d83af4486ca7b8/
+ there is no LIBUTILMAJOR variable only LIBUTILSOMAJOR leading to:
+
+ ld: fatal error: -soname: must take a non-empty argument
+ collect2: error: ld returned 1 exit status
+
+ with some linkers like GOLD
+
+Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
+---
+Upstream-Status: Submitted [https://sourceforge.net/p/giflib/code/merge-requests/17/]
+
+ Makefile | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/Makefile b/Makefile
+index 87966a9..41b149e 100644
+--- a/Makefile
++++ b/Makefile
+@@ -109,7 +109,7 @@ $(LIBUTILSO): $(UOBJECTS) $(UHEADERS)
+ ifeq ($(UNAME), Darwin)
+ $(CC) $(CFLAGS) -dynamiclib -current_version $(LIBVER) $(OBJECTS) -o $(LIBUTILSO)
+ else
+- $(CC) $(CFLAGS) -shared $(LDFLAGS) -Wl,-soname -Wl,$(LIBUTILMAJOR) -o $(LIBUTILSO) $(UOBJECTS)
++ $(CC) $(CFLAGS) -shared $(LDFLAGS) -Wl,-soname -Wl,$(LIBUTILSOMAJOR) -o $(LIBUTILSO) $(UOBJECTS)
+ endif
+
+ libutil.a: $(UOBJECTS) $(UHEADERS)
diff --git a/meta-openembedded/meta-oe/recipes-devtools/giflib/giflib_5.2.2.bb b/meta-openembedded/meta-oe/recipes-devtools/giflib/giflib_5.2.2.bb
index 7d8a175fe3..aa47f93095 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/giflib/giflib_5.2.2.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/giflib/giflib_5.2.2.bb
@@ -5,14 +5,16 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=ae11c61b04b2917be39b11f78d71519a"
CVE_PRODUCT = "giflib_project:giflib"
-DEPENDS = "xmlto-native imagemagick-native"
+DEPENDS = "xmlto-native"
SRC_URI = "${SOURCEFORGE_MIRROR}/giflib/${BP}.tar.gz \
- file://add_suffix_to_convert_binary_used_in_Makefile.patch"
+ https://sourceforge.net/p/giflib/code/ci/d54b45b0240d455bbaedee4be5203d2703e59967/tree/doc/giflib-logo.gif?format=raw;subdir=${BP}/doc;name=logo;downloadfilename=giflib-logo.gif \
+ file://0001-Makefile-fix-typo-in-soname-argument.patch \
+"
+SRC_URI[logo.sha256sum] = "1a54383986adad1521d00e003b4c482c27e8bc60690be944a1f3319c75abc2c9"
SRC_URI[sha256sum] = "be7ffbd057cadebe2aa144542fd90c6838c6a083b5e8a9048b8ee3b66b29d5fb"
-
do_install() {
# using autotools's default will end up in /usr/local
oe_runmake DESTDIR=${D} PREFIX=${prefix} LIBDIR=${libdir} install
diff --git a/meta-openembedded/meta-oe/recipes-devtools/glade/glade/CVE-2020-36774.patch b/meta-openembedded/meta-oe/recipes-devtools/glade/glade/CVE-2020-36774.patch
new file mode 100644
index 0000000000..5049b44e55
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/glade/glade/CVE-2020-36774.patch
@@ -0,0 +1,54 @@
+From 7acdd3c6f6934f47b8974ebc2190a59ea5d2ed17 Mon Sep 17 00:00:00 2001
+From: Juan Pablo Ugarte <juanpablougarte@gmail.com>
+Date: Fri, 2 Oct 2020 16:08:23 -0300
+Subject: [PATCH] GladeGtkBox: fix glade_gtk_box_post_create
+
+Some widgets with contruct properties like GtkMessageDialog get
+rebuilt right after they are created on project loading so we need
+to check glade_project_is_loading() intead of GLADE_CREATE_LOAD
+and use the object ad the connect data to make sure it gets disconected
+if it was the object being rebuilt
+
+Fix issue #479 "Glade 3.36.0 segfaults when opening a file"
+
+CVE: CVE-2020-36774
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glade/-/commit/7acdd3c6f6934f47b8974ebc2190a59ea5d2ed17]
+
+Signed-off-by: Peng Zhang <peng.zhang1.cn@windriver.com>
+---
+ plugins/gtk+/glade-gtk-box.c | 8 ++++----
+ 1 file changed, 4 insertions(+), 4 deletions(-)
+
+diff --git a/plugins/gtk+/glade-gtk-box.c b/plugins/gtk+/glade-gtk-box.c
+index 0c157a6d..a0252b6a 100644
+--- a/plugins/gtk+/glade-gtk-box.c
++++ b/plugins/gtk+/glade-gtk-box.c
+@@ -58,9 +58,9 @@ glade_gtk_box_create_editable (GladeWidgetAdaptor *adaptor,
+ }
+
+ static void
+-glade_gtk_box_parse_finished (GladeProject * project, GladeWidget *gbox)
++glade_gtk_box_parse_finished (GladeProject *project, GObject *box)
+ {
+- GObject *box = glade_widget_get_object (gbox);
++ GladeWidget *gbox = glade_widget_get_from_gobject (box);
+
+ glade_widget_property_set (gbox, "use-center-child",
+ gtk_box_get_center_widget (GTK_BOX (box)) != NULL);
+@@ -87,11 +87,11 @@ glade_gtk_box_post_create (GladeWidgetAdaptor *adaptor,
+ g_signal_connect (G_OBJECT (gwidget), "configure-end",
+ G_CALLBACK (glade_gtk_box_configure_end), container);
+
+- if (reason == GLADE_CREATE_LOAD)
++ if (glade_project_is_loading (project))
+ {
+ g_signal_connect_object (project, "parse-finished",
+ G_CALLBACK (glade_gtk_box_parse_finished),
+- gwidget, 0);
++ container, 0);
+ }
+ }
+
+--
+GitLab
+
diff --git a/meta-openembedded/meta-oe/recipes-devtools/glade/glade_3.22.2.bb b/meta-openembedded/meta-oe/recipes-devtools/glade/glade_3.22.2.bb
index d11751a4b2..4a1c5fc8a5 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/glade/glade_3.22.2.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/glade/glade_3.22.2.bb
@@ -17,6 +17,7 @@ ANY_OF_DISTRO_FEATURES = "${GTK3DISTROFEATURES}"
SRC_URI = "http://ftp.gnome.org/pub/GNOME/sources/glade/3.22/glade-${PV}.tar.xz \
file://remove-yelp-help-rules-var.patch \
+ file://CVE-2020-36774.patch \
"
SRC_URI[md5sum] = "c074fa378c8f1ad80d20133c4ae6f42d"
SRC_URI[sha256sum] = "edefa6eb24b4d15bd52589121dc109bc08c286157c41288deb74dd9cc3f26a21"
diff --git a/meta-openembedded/meta-oe/recipes-devtools/grpc/grpc/CVE-2024-11407.patch b/meta-openembedded/meta-oe/recipes-devtools/grpc/grpc/CVE-2024-11407.patch
new file mode 100644
index 0000000000..beaff6a423
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/grpc/grpc/CVE-2024-11407.patch
@@ -0,0 +1,32 @@
+From e9046b2bbebc0cb7f5dc42008f807f6c7e98e791 Mon Sep 17 00:00:00 2001
+From: Vignesh Babu <vigneshbabu@google.com>
+Date: Thu, 12 Sep 2024 11:13:45 -0700
+Subject: [PATCH] [EventEngine] Fix bug in Tx0cp code path in posix endpoint.
+
+This fix ensures that the iov_base pointers point to the right address.
+
+PiperOrigin-RevId: 673923651
+
+CVE: CVE-2024-11407
+Upstream-Status: Backport [https://github.com/grpc/grpc/commit/e9046b2bbebc0cb7f5dc42008f807f6c7e98e791]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/core/lib/event_engine/posix_engine/posix_endpoint.cc | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/core/lib/event_engine/posix_engine/posix_endpoint.cc b/src/core/lib/event_engine/posix_engine/posix_endpoint.cc
+index 7634bb1334b..c5708db02c5 100644
+--- a/src/core/lib/event_engine/posix_engine/posix_endpoint.cc
++++ b/src/core/lib/event_engine/posix_engine/posix_endpoint.cc
+@@ -239,7 +239,7 @@ msg_iovlen_type TcpZerocopySendRecord::PopulateIovs(size_t* unwind_slice_idx,
+ iov_size++) {
+ MutableSlice& slice = internal::SliceCast<MutableSlice>(
+ buf_.MutableSliceAt(out_offset_.slice_idx));
+- iov[iov_size].iov_base = slice.begin();
++ iov[iov_size].iov_base = slice.begin() + out_offset_.byte_idx;
+ iov[iov_size].iov_len = slice.length() - out_offset_.byte_idx;
+ *sending_length += iov[iov_size].iov_len;
+ ++(out_offset_.slice_idx);
+--
+2.30.2
+
diff --git a/meta-openembedded/meta-oe/recipes-devtools/grpc/grpc/CVE-2024-7246.patch b/meta-openembedded/meta-oe/recipes-devtools/grpc/grpc/CVE-2024-7246.patch
new file mode 100644
index 0000000000..a690b49c67
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/grpc/grpc/CVE-2024-7246.patch
@@ -0,0 +1,420 @@
+From ac0948e39eb19c3325a576e152709d4cc915a7e4 Mon Sep 17 00:00:00 2001
+From: Craig Tiller <ctiller@google.com>
+Date: Thu, 1 Aug 2024 13:02:27 -0700
+Subject: [PATCH] [v1.60] [chttp2] Fix a bug in hpack error handling (#37361)
+
+PiperOrigin-RevId: 657234128
+PiperOrigin-RevId: 658458047
+
+Craig Tiller <ctiller@google.com>
+
+CVE: CVE-2024-7246
+
+Upstream-Status: Backport
+[https://github.com/grpc/grpc/pull/37361/files]
+
+Signed-off-by: Libo Chen <libo.chen.cn@windriver.com>
+---
+ .../chttp2/transport/hpack_parser.cc | 63 +++++++------
+ .../transport/chttp2/transport/hpack_parser.h | 2 +
+ .../transport/chttp2/hpack_parser_test.cc | 89 ++++++++++++++++---
+ .../transport/chttp2/hpack_sync_fuzzer.cc | 62 +++++++++++++
+ .../transport/chttp2/hpack_sync_fuzzer.proto | 3 +
+ 5 files changed, 179 insertions(+), 40 deletions(-)
+
+diff --git a/src/core/ext/transport/chttp2/transport/hpack_parser.cc b/src/core/ext/transport/chttp2/transport/hpack_parser.cc
+index 31bf464..f2fe80c 100644
+--- a/src/core/ext/transport/chttp2/transport/hpack_parser.cc
++++ b/src/core/ext/transport/chttp2/transport/hpack_parser.cc
+@@ -91,12 +91,14 @@ constexpr Base64InverseTable kBase64InverseTable;
+ class HPackParser::Input {
+ public:
+ Input(grpc_slice_refcount* current_slice_refcount, const uint8_t* begin,
+- const uint8_t* end, absl::BitGenRef bitsrc, HpackParseResult& error)
++ const uint8_t* end, absl::BitGenRef bitsrc,
++ HpackParseResult& frame_error, HpackParseResult& field_error)
+ : current_slice_refcount_(current_slice_refcount),
+ begin_(begin),
+ end_(end),
+ frontier_(begin),
+- error_(error),
++ frame_error_(frame_error),
++ field_error_(field_error),
+ bitsrc_(bitsrc) {}
+
+ // If input is backed by a slice, retrieve its refcount. If not, return
+@@ -215,14 +217,18 @@ class HPackParser::Input {
+
+ // Check if we saw an EOF
+ bool eof_error() const {
+- return min_progress_size_ != 0 || error_.connection_error();
++ return min_progress_size_ != 0 || frame_error_.connection_error();
++ }
++
++ // Reset the field error to be ok
++ void ClearFieldError() {
++ if (field_error_.ok()) return;
++ field_error_ = HpackParseResult();
+ }
+
+ // Minimum number of bytes to unstuck the current parse
+ size_t min_progress_size() const { return min_progress_size_; }
+
+- bool has_error() const { return !error_.ok(); }
+-
+ // Set the current error - tweaks the error to include a stream id so that
+ // chttp2 does not close the connection.
+ // Intended for errors that are specific to a stream and recoverable.
+@@ -246,10 +252,7 @@ class HPackParser::Input {
+ // read prior to being able to get further in this parse.
+ void UnexpectedEOF(size_t min_progress_size) {
+ GPR_ASSERT(min_progress_size > 0);
+- if (min_progress_size_ != 0 || error_.connection_error()) {
+- GPR_DEBUG_ASSERT(eof_error());
+- return;
+- }
++ if (eof_error()) return;
+ // Set min progress size, taking into account bytes parsed already but not
+ // consumed.
+ min_progress_size_ = min_progress_size + (begin_ - frontier_);
+@@ -302,13 +305,18 @@ class HPackParser::Input {
+ // Do not use this directly, instead use SetErrorAndContinueParsing or
+ // SetErrorAndStopParsing.
+ void SetError(HpackParseResult error) {
+- if (!error_.ok() || min_progress_size_ > 0) {
+- if (error.connection_error() && !error_.connection_error()) {
+- error_ = std::move(error); // connection errors dominate
++ SetErrorFor(frame_error_, error);
++ SetErrorFor(field_error_, std::move(error));
++ }
++
++ void SetErrorFor(HpackParseResult& error, HpackParseResult new_error) {
++ if (!error.ok() || min_progress_size_ > 0) {
++ if (new_error.connection_error() && !error.connection_error()) {
++ error = std::move(new_error); // connection errors dominate
+ }
+ return;
+ }
+- error_ = std::move(error);
++ error = std::move(new_error);
+ }
+
+ // Refcount if we are backed by a slice
+@@ -320,7 +328,8 @@ class HPackParser::Input {
+ // Frontier denotes the first byte past successfully processed input
+ const uint8_t* frontier_;
+ // Current error
+- HpackParseResult& error_;
++ HpackParseResult& frame_error_;
++ HpackParseResult& field_error_;
+ // If the error was EOF, we flag it here by noting how many more bytes would
+ // be needed to make progress
+ size_t min_progress_size_ = 0;
+@@ -597,6 +606,7 @@ class HPackParser::Parser {
+ bool ParseTop() {
+ GPR_DEBUG_ASSERT(state_.parse_state == ParseState::kTop);
+ auto cur = *input_->Next();
++ input_->ClearFieldError();
+ switch (cur >> 4) {
+ // Literal header not indexed - First byte format: 0000xxxx
+ // Literal header never indexed - First byte format: 0001xxxx
+@@ -702,7 +712,7 @@ class HPackParser::Parser {
+ break;
+ }
+ gpr_log(
+- GPR_DEBUG, "HTTP:%d:%s:%s: %s%s", log_info_.stream_id, type,
++ GPR_INFO, "HTTP:%d:%s:%s: %s%s", log_info_.stream_id, type,
+ log_info_.is_client ? "CLI" : "SVR", memento.md.DebugString().c_str(),
+ memento.parse_status == nullptr
+ ? ""
+@@ -951,11 +961,10 @@ class HPackParser::Parser {
+ state_.string_length)
+ : String::Parse(input_, state_.is_string_huff_compressed,
+ state_.string_length);
+- HpackParseResult& status = state_.frame_error;
+ absl::string_view key_string;
+ if (auto* s = absl::get_if<Slice>(&state_.key)) {
+ key_string = s->as_string_view();
+- if (status.ok()) {
++ if (state_.field_error.ok()) {
+ auto r = ValidateKey(key_string);
+ if (r != ValidateMetadataResult::kOk) {
+ input_->SetErrorAndContinueParsing(
+@@ -965,7 +974,7 @@ class HPackParser::Parser {
+ } else {
+ const auto* memento = absl::get<const HPackTable::Memento*>(state_.key);
+ key_string = memento->md.key();
+- if (status.ok() && memento->parse_status != nullptr) {
++ if (state_.field_error.ok() && memento->parse_status != nullptr) {
+ input_->SetErrorAndContinueParsing(*memento->parse_status);
+ }
+ }
+@@ -992,16 +1001,16 @@ class HPackParser::Parser {
+ key_string.size() + value.wire_size + hpack_constants::kEntryOverhead;
+ auto md = grpc_metadata_batch::Parse(
+ key_string, std::move(value_slice), state_.add_to_table, transport_size,
+- [key_string, &status, this](absl::string_view message, const Slice&) {
+- if (!status.ok()) return;
++ [key_string, this](absl::string_view message, const Slice&) {
++ if (!state_.field_error.ok()) return;
+ input_->SetErrorAndContinueParsing(
+ HpackParseResult::MetadataParseError(key_string));
+ gpr_log(GPR_ERROR, "Error parsing '%s' metadata: %s",
+ std::string(key_string).c_str(),
+ std::string(message).c_str());
+ });
+- HPackTable::Memento memento{std::move(md),
+- status.PersistentStreamErrorOrNullptr()};
++ HPackTable::Memento memento{
++ std::move(md), state_.field_error.PersistentStreamErrorOrNullptr()};
+ input_->UpdateFrontier();
+ state_.parse_state = ParseState::kTop;
+ if (state_.add_to_table) {
+@@ -1163,13 +1172,13 @@ grpc_error_handle HPackParser::Parse(
+ std::vector<uint8_t> buffer = std::move(unparsed_bytes_);
+ return ParseInput(
+ Input(nullptr, buffer.data(), buffer.data() + buffer.size(), bitsrc,
+- state_.frame_error),
++ state_.frame_error, state_.field_error),
+ is_last, call_tracer);
+ }
+- return ParseInput(
+- Input(slice.refcount, GRPC_SLICE_START_PTR(slice),
+- GRPC_SLICE_END_PTR(slice), bitsrc, state_.frame_error),
+- is_last, call_tracer);
++ return ParseInput(Input(slice.refcount, GRPC_SLICE_START_PTR(slice),
++ GRPC_SLICE_END_PTR(slice), bitsrc, state_.frame_error,
++ state_.field_error),
++ is_last, call_tracer);
+ }
+
+ grpc_error_handle HPackParser::ParseInput(
+diff --git a/src/core/ext/transport/chttp2/transport/hpack_parser.h b/src/core/ext/transport/chttp2/transport/hpack_parser.h
+index 3745668..55842e4 100644
+--- a/src/core/ext/transport/chttp2/transport/hpack_parser.h
++++ b/src/core/ext/transport/chttp2/transport/hpack_parser.h
+@@ -236,6 +236,8 @@ class HPackParser {
+ HPackTable hpack_table;
+ // Error so far for this frame (set by class Input)
+ HpackParseResult frame_error;
++ // Error so far for this field (set by class Input)
++ HpackParseResult field_error;
+ // Length of frame so far.
+ uint32_t frame_length = 0;
+ // Length of the string being parsed
+diff --git a/test/core/transport/chttp2/hpack_parser_test.cc b/test/core/transport/chttp2/hpack_parser_test.cc
+index 3772d90..d5b9c6c 100644
+--- a/test/core/transport/chttp2/hpack_parser_test.cc
++++ b/test/core/transport/chttp2/hpack_parser_test.cc
+@@ -440,19 +440,82 @@ INSTANTIATE_TEST_SUITE_P(
+ Test{"Base64LegalEncoding",
+ {},
+ {},
+- {// Binary metadata: created using:
+- // tools/codegen/core/gen_header_frame.py
+- // --compression inc --no_framing --output hexstr
+- // < test/core/transport/chttp2/bad-base64.headers
+- {"4009612e622e632d62696e1c6c75636b696c7920666f722075732c206974"
+- "27732074756573646179",
+- absl::InternalError("Error parsing 'a.b.c-bin' metadata: "
+- "illegal base64 encoding"),
+- 0},
+- {"be",
+- absl::InternalError("Error parsing 'a.b.c-bin' metadata: "
+- "illegal base64 encoding"),
+- 0}}},
++ {
++ // Binary metadata: created using:
++ // tools/codegen/core/gen_header_frame.py
++ // --compression inc --no_framing --output hexstr
++ // < test/core/transport/chttp2/bad-base64.headers
++ {"4009612e622e632d62696e1c6c75636b696c7920666f722075732c206974"
++ "27732074756573646179",
++ absl::InternalError("Error parsing 'a.b.c-bin' metadata: "
++ "illegal base64 encoding"),
++ 0},
++ {"be",
++ absl::InternalError("Error parsing 'a.b.c-bin' metadata: "
++ "illegal base64 encoding"),
++ kEndOfHeaders},
++ {"82", ":method: GET\n", 0},
++ }},
++ Test{"Base64LegalEncodingWorksAfterFailure",
++ {},
++ {},
++ {
++ // Binary metadata: created using:
++ // tools/codegen/core/gen_header_frame.py
++ // --compression inc --no_framing --output hexstr
++ // < test/core/transport/chttp2/bad-base64.headers
++ {"4009612e622e632d62696e1c6c75636b696c7920666f722075732c206974"
++ "27732074756573646179",
++ absl::InternalError("Error parsing 'a.b.c-bin' metadata: "
++ "illegal base64 encoding"),
++ 0},
++ {"be",
++ absl::InternalError("Error parsing 'a.b.c-bin' metadata: "
++ "illegal base64 encoding"),
++ 0},
++ {"400e636f6e74656e742d6c656e6774680135",
++ absl::InternalError("Error parsing 'a.b.c-bin' metadata: "
++ "illegal base64 encoding"),
++ kEndOfHeaders},
++ {"be", "content-length: 5\n", 0},
++ }},
++ Test{"Base64LegalEncodingWorksAfterFailure2",
++ {},
++ {},
++ {
++ {// Generated with: tools/codegen/core/gen_header_frame.py
++ // --compression inc --output hexstr --no_framing <
++ // test/core/transport/chttp2/MiXeD-CaSe.headers
++ "400a4d695865442d436153651073686f756c64206e6f74207061727365",
++ absl::InternalError("Illegal header key: MiXeD-CaSe"), 0},
++ // Binary metadata: created using:
++ // tools/codegen/core/gen_header_frame.py
++ // --compression inc --no_framing --output hexstr
++ // < test/core/transport/chttp2/bad-base64.headers
++ {"4009612e622e632d62696e1c6c75636b696c7920666f722075732c206974"
++ "27732074756573646179",
++ absl::InternalError("Illegal header key: MiXeD-CaSe"), 0},
++ {"be", absl::InternalError("Illegal header key: MiXeD-CaSe"),
++ 0},
++ {"400e636f6e74656e742d6c656e6774680135",
++ absl::InternalError("Illegal header key: MiXeD-CaSe"),
++ kEndOfHeaders},
++ {"be", "content-length: 5\n", 0},
++ {"bf",
++ absl::InternalError("Error parsing 'a.b.c-bin' metadata: "
++ "illegal base64 encoding"),
++ 0},
++ // Only the first error in each frame is reported, so we should
++ // still see the same error here...
++ {"c0",
++ absl::InternalError("Error parsing 'a.b.c-bin' metadata: "
++ "illegal base64 encoding"),
++ kEndOfHeaders},
++ // ... but if we look at the next frame we should see the
++ // stored error
++ {"c0", absl::InternalError("Illegal header key: MiXeD-CaSe"),
++ kEndOfHeaders},
++ }},
+ Test{"TeIsTrailers",
+ {},
+ {},
+diff --git a/test/core/transport/chttp2/hpack_sync_fuzzer.cc b/test/core/transport/chttp2/hpack_sync_fuzzer.cc
+index 47e4265..9afa41f 100644
+--- a/test/core/transport/chttp2/hpack_sync_fuzzer.cc
++++ b/test/core/transport/chttp2/hpack_sync_fuzzer.cc
+@@ -85,6 +85,10 @@ void FuzzOneInput(const hpack_sync_fuzzer::Msg& msg) {
+ // Not an interesting case to fuzz
+ continue;
+ }
++ if (msg.check_ab_preservation() &&
++ header.literal_inc_idx().key() == "a") {
++ continue;
++ }
+ if (absl::EndsWith(header.literal_inc_idx().value(), "-bin")) {
+ std::ignore = encoder.EmitLitHdrWithBinaryStringKeyIncIdx(
+ Slice::FromCopiedString(header.literal_inc_idx().key()),
+@@ -96,6 +100,10 @@ void FuzzOneInput(const hpack_sync_fuzzer::Msg& msg) {
+ }
+ break;
+ case hpack_sync_fuzzer::Header::kLiteralNotIdx:
++ if (msg.check_ab_preservation() &&
++ header.literal_not_idx().key() == "a") {
++ continue;
++ }
+ if (absl::EndsWith(header.literal_not_idx().value(), "-bin")) {
+ encoder.EmitLitHdrWithBinaryStringKeyNotIdx(
+ Slice::FromCopiedString(header.literal_not_idx().key()),
+@@ -114,6 +122,10 @@ void FuzzOneInput(const hpack_sync_fuzzer::Msg& msg) {
+ break;
+ }
+ }
++ if (msg.check_ab_preservation()) {
++ std::ignore = encoder.EmitLitHdrWithNonBinaryStringKeyIncIdx(
++ Slice::FromCopiedString("a"), Slice::FromCopiedString("b"));
++ }
+
+ // STAGE 2: Decode the buffer (encode_output) into a list of headers
+ HPackParser parser;
+@@ -140,6 +152,21 @@ void FuzzOneInput(const hpack_sync_fuzzer::Msg& msg) {
+ }
+ }
+
++ if (seen_errors.empty() && msg.check_ab_preservation()) {
++ std::string backing;
++ auto a_value = read_metadata.GetStringValue("a", &backing);
++ if (!a_value.has_value()) {
++ fprintf(stderr, "Expected 'a' header to be present: %s\n",
++ read_metadata.DebugString().c_str());
++ abort();
++ }
++ if (a_value != "b") {
++ fprintf(stderr, "Expected 'a' header to be 'b', got '%s'\n",
++ std::string(*a_value).c_str());
++ abort();
++ }
++ }
++
+ // STAGE 3: If we reached here we either had a stream error or no error
+ // parsing.
+ // Either way, the hpack tables should be of the same size between client and
+@@ -168,6 +195,41 @@ void FuzzOneInput(const hpack_sync_fuzzer::Msg& msg) {
+ }
+ abort();
+ }
++
++ if (msg.check_ab_preservation()) {
++ SliceBuffer encode_output_2;
++ hpack_encoder_detail::Encoder encoder_2(
++ &compressor, msg.use_true_binary_metadata(), encode_output_2);
++ encoder_2.EmitIndexed(62);
++ GPR_ASSERT(encode_output_2.Count() == 1);
++ grpc_metadata_batch read_metadata_2(arena.get());
++ parser.BeginFrame(
++ &read_metadata_2, 1024, 1024, HPackParser::Boundary::EndOfHeaders,
++ HPackParser::Priority::None,
++ HPackParser::LogInfo{3, HPackParser::LogInfo::kHeaders, false});
++ auto err = parser.Parse(encode_output_2.c_slice_at(0), true,
++ absl::BitGenRef(proto_bit_src),
++ /*call_tracer=*/nullptr);
++ if (!err.ok()) {
++ fprintf(stderr, "Error parsing preservation encoded data: %s\n",
++ err.ToString().c_str());
++ abort();
++ }
++ std::string backing;
++ auto a_value = read_metadata_2.GetStringValue("a", &backing);
++ if (!a_value.has_value()) {
++ fprintf(stderr,
++ "Expected 'a' header to be present: %s\nfirst metadata: %s\n",
++ read_metadata_2.DebugString().c_str(),
++ read_metadata.DebugString().c_str());
++ abort();
++ }
++ if (a_value != "b") {
++ fprintf(stderr, "Expected 'a' header to be 'b', got '%s'\n",
++ std::string(*a_value).c_str());
++ abort();
++ }
++ }
+ }
+
+ } // namespace
+diff --git a/test/core/transport/chttp2/hpack_sync_fuzzer.proto b/test/core/transport/chttp2/hpack_sync_fuzzer.proto
+index 72792b6..2c075a6 100644
+--- a/test/core/transport/chttp2/hpack_sync_fuzzer.proto
++++ b/test/core/transport/chttp2/hpack_sync_fuzzer.proto
+@@ -44,4 +44,7 @@ message Msg {
+ repeated Header headers = 2;
+ grpc.testing.FuzzConfigVars config_vars = 3;
+ repeated uint64 random_numbers = 4;
++ // Ensure that a header "a: b" appended to headers with hpack incremental
++ // indexing is correctly added to the hpack table.
++ bool check_ab_preservation = 5;
+ }
+--
+2.44.1
+
diff --git a/meta-openembedded/meta-oe/recipes-devtools/grpc/grpc_1.60.1.bb b/meta-openembedded/meta-oe/recipes-devtools/grpc/grpc_1.60.1.bb
index 63c696a623..1594353ef5 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/grpc/grpc_1.60.1.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/grpc/grpc_1.60.1.bb
@@ -24,6 +24,8 @@ SRCREV_grpc = "e5ae3b6b44bf3b64d24bfb4b4f82556239b986db"
BRANCH = "v1.60.x"
SRC_URI = "gitsm://github.com/grpc/grpc.git;protocol=https;name=grpc;branch=${BRANCH} \
file://0001-cmake-Link-with-libatomic-on-rv32-rv64.patch \
+ file://CVE-2024-7246.patch \
+ file://CVE-2024-11407.patch \
"
# Fixes build with older compilers 4.8 especially on ubuntu 14.04
CXXFLAGS:append:class-native = " -Wl,--no-as-needed"
diff --git a/meta-openembedded/meta-oe/recipes-devtools/jq/jq/CVE-2024-23337.patch b/meta-openembedded/meta-oe/recipes-devtools/jq/jq/CVE-2024-23337.patch
new file mode 100644
index 0000000000..8b8243b752
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/jq/jq/CVE-2024-23337.patch
@@ -0,0 +1,236 @@
+From d9237e3d607f946fe74540efa42a2eacca2a6fbd Mon Sep 17 00:00:00 2001
+From: itchyny <itchyny@cybozu.co.jp>
+Date: Wed, 21 May 2025 07:45:00 +0900
+Subject: [PATCH] Fix signed integer overflow in jvp_array_write and
+ jvp_object_rehash
+
+This commit fixes signed integer overflow and SEGV issues on growing
+arrays and objects. The size of arrays and objects is now limited to
+`536870912` (`0x20000000`). This fixes CVE-2024-23337 and fixes #3262.
+
+Upstream-Status: Backport [https://github.com/jqlang/jq.git/commit/de21386681c0df0104a99d9d09db23a9b2a78b1e]
+CVE: CVE-2024-23337
+
+(cherry picked from commit de21386681c0df0104a99d9d09db23a9b2a78b1e)
+Signed-off-by: Roland Kovacs <roland.kovacs@est.tech>
+---
+ src/jv.c | 57 ++++++++++++++++++++++++++++++++++++++++-----------
+ src/jv_aux.c | 9 ++++----
+ tests/jq.test | 4 ++++
+ 3 files changed, 54 insertions(+), 16 deletions(-)
+
+diff --git a/src/jv.c b/src/jv.c
+index 34573b8..15990f1 100644
+--- a/src/jv.c
++++ b/src/jv.c
+@@ -1001,6 +1001,11 @@ jv jv_array_set(jv j, int idx, jv val) {
+ jv_free(val);
+ return jv_invalid_with_msg(jv_string("Out of bounds negative array index"));
+ }
++ if (idx > (INT_MAX >> 2) - jvp_array_offset(j)) {
++ jv_free(j);
++ jv_free(val);
++ return jv_invalid_with_msg(jv_string("Array index too large"));
++ }
+ // copy/free of val,j coalesced
+ jv* slot = jvp_array_write(&j, idx);
+ jv_free(*slot);
+@@ -1020,6 +1025,7 @@ jv jv_array_concat(jv a, jv b) {
+ // FIXME: could be faster
+ jv_array_foreach(b, i, elem) {
+ a = jv_array_append(a, elem);
++ if (!jv_is_valid(a)) break;
+ }
+ jv_free(b);
+ return a;
+@@ -1283,15 +1289,22 @@ jv jv_string_indexes(jv j, jv k) {
+ assert(JVP_HAS_KIND(k, JV_KIND_STRING));
+ const char *jstr = jv_string_value(j);
+ const char *idxstr = jv_string_value(k);
+- const char *p;
++ const char *p, *lp;
+ int jlen = jv_string_length_bytes(jv_copy(j));
+ int idxlen = jv_string_length_bytes(jv_copy(k));
+ jv a = jv_array();
+
+ if (idxlen != 0) {
+- p = jstr;
++ int n = 0;
++ p = lp = jstr;
+ while ((p = _jq_memmem(p, (jstr + jlen) - p, idxstr, idxlen)) != NULL) {
+- a = jv_array_append(a, jv_number(p - jstr));
++ while (lp < p) {
++ lp += jvp_utf8_decode_length(*lp);
++ n++;
++ }
++
++ a = jv_array_append(a, jv_number(n));
++ if (!jv_is_valid(a)) break;
+ p++;
+ }
+ }
+@@ -1314,14 +1327,17 @@ jv jv_string_split(jv j, jv sep) {
+
+ if (seplen == 0) {
+ int c;
+- while ((jstr = jvp_utf8_next(jstr, jend, &c)))
++ while ((jstr = jvp_utf8_next(jstr, jend, &c))) {
+ a = jv_array_append(a, jv_string_append_codepoint(jv_string(""), c));
++ if (!jv_is_valid(a)) break;
++ }
+ } else {
+ for (p = jstr; p < jend; p = s + seplen) {
+ s = _jq_memmem(p, jend - p, sepstr, seplen);
+ if (s == NULL)
+ s = jend;
+ a = jv_array_append(a, jv_string_sized(p, s - p));
++ if (!jv_is_valid(a)) break;
+ // Add an empty string to denote that j ends on a sep
+ if (s + seplen == jend && seplen != 0)
+ a = jv_array_append(a, jv_string(""));
+@@ -1339,8 +1355,10 @@ jv jv_string_explode(jv j) {
+ const char* end = i + len;
+ jv a = jv_array_sized(len);
+ int c;
+- while ((i = jvp_utf8_next(i, end, &c)))
++ while ((i = jvp_utf8_next(i, end, &c))) {
+ a = jv_array_append(a, jv_number(c));
++ if (!jv_is_valid(a)) break;
++ }
+ jv_free(j);
+ return a;
+ }
+@@ -1614,10 +1632,13 @@ static void jvp_object_free(jv o) {
+ }
+ }
+
+-static jv jvp_object_rehash(jv object) {
++static int jvp_object_rehash(jv *objectp) {
++ jv object = *objectp;
+ assert(JVP_HAS_KIND(object, JV_KIND_OBJECT));
+ assert(jvp_refcnt_unshared(object.u.ptr));
+ int size = jvp_object_size(object);
++ if (size > INT_MAX >> 2)
++ return 0;
+ jv new_object = jvp_object_new(size * 2);
+ for (int i=0; i<size; i++) {
+ struct object_slot* slot = jvp_object_get_slot(object, i);
+@@ -1630,7 +1651,8 @@ static jv jvp_object_rehash(jv object) {
+ }
+ // references are transported, just drop the old table
+ jv_mem_free(jvp_object_ptr(object));
+- return new_object;
++ *objectp = new_object;
++ return 1;
+ }
+
+ static jv jvp_object_unshare(jv object) {
+@@ -1659,27 +1681,32 @@ static jv jvp_object_unshare(jv object) {
+ return new_object;
+ }
+
+-static jv* jvp_object_write(jv* object, jv key) {
++static int jvp_object_write(jv* object, jv key, jv **valpp) {
+ *object = jvp_object_unshare(*object);
+ int* bucket = jvp_object_find_bucket(*object, key);
+ struct object_slot* slot = jvp_object_find_slot(*object, key, bucket);
+ if (slot) {
+ // already has the key
+ jvp_string_free(key);
+- return &slot->value;
++ *valpp = &slot->value;
++ return 1;
+ }
+ slot = jvp_object_add_slot(*object, key, bucket);
+ if (slot) {
+ slot->value = jv_invalid();
+ } else {
+- *object = jvp_object_rehash(*object);
++ if (!jvp_object_rehash(object)) {
++ *valpp = NULL;
++ return 0;
++ }
+ bucket = jvp_object_find_bucket(*object, key);
+ assert(!jvp_object_find_slot(*object, key, bucket));
+ slot = jvp_object_add_slot(*object, key, bucket);
+ assert(slot);
+ slot->value = jv_invalid();
+ }
+- return &slot->value;
++ *valpp = &slot->value;
++ return 1;
+ }
+
+ static int jvp_object_delete(jv* object, jv key) {
+@@ -1779,7 +1806,11 @@ jv jv_object_set(jv object, jv key, jv value) {
+ assert(JVP_HAS_KIND(object, JV_KIND_OBJECT));
+ assert(JVP_HAS_KIND(key, JV_KIND_STRING));
+ // copy/free of object, key, value coalesced
+- jv* slot = jvp_object_write(&object, key);
++ jv* slot;
++ if (!jvp_object_write(&object, key, &slot)) {
++ jv_free(object);
++ return jv_invalid_with_msg(jv_string("Object too big"));
++ }
+ jv_free(*slot);
+ *slot = value;
+ return object;
+@@ -1804,6 +1835,7 @@ jv jv_object_merge(jv a, jv b) {
+ assert(JVP_HAS_KIND(a, JV_KIND_OBJECT));
+ jv_object_foreach(b, k, v) {
+ a = jv_object_set(a, k, v);
++ if (!jv_is_valid(a)) break;
+ }
+ jv_free(b);
+ return a;
+@@ -1823,6 +1855,7 @@ jv jv_object_merge_recursive(jv a, jv b) {
+ jv_free(elem);
+ a = jv_object_set(a, k, v);
+ }
++ if (!jv_is_valid(a)) break;
+ }
+ jv_free(b);
+ return a;
+diff --git a/src/jv_aux.c b/src/jv_aux.c
+index 6004799..bbe1c0d 100644
+--- a/src/jv_aux.c
++++ b/src/jv_aux.c
+@@ -193,18 +193,19 @@ jv jv_set(jv t, jv k, jv v) {
+ if (slice_len < insert_len) {
+ // array is growing
+ int shift = insert_len - slice_len;
+- for (int i = array_len - 1; i >= end; i--) {
++ for (int i = array_len - 1; i >= end && jv_is_valid(t); i--) {
+ t = jv_array_set(t, i + shift, jv_array_get(jv_copy(t), i));
+ }
+ } else if (slice_len > insert_len) {
+ // array is shrinking
+ int shift = slice_len - insert_len;
+- for (int i = end; i < array_len; i++) {
++ for (int i = end; i < array_len && jv_is_valid(t); i++) {
+ t = jv_array_set(t, i - shift, jv_array_get(jv_copy(t), i));
+ }
+- t = jv_array_slice(t, 0, array_len - shift);
++ if (jv_is_valid(t))
++ t = jv_array_slice(t, 0, array_len - shift);
+ }
+- for (int i=0; i < insert_len; i++) {
++ for (int i = 0; i < insert_len && jv_is_valid(t); i++) {
+ t = jv_array_set(t, start + i, jv_array_get(jv_copy(v), i));
+ }
+ jv_free(v);
+diff --git a/tests/jq.test b/tests/jq.test
+index d052b22..22bfd3a 100644
+--- a/tests/jq.test
++++ b/tests/jq.test
+@@ -198,6 +198,10 @@ null
+ [0,1,2]
+ [0,5,2]
+
++try (.[999999999] = 0) catch .
++null
++"Array index too large"
++
+ #
+ # Multiple outputs, iteration
+ #
diff --git a/meta-openembedded/meta-oe/recipes-devtools/jq/jq/CVE-2024-53427.patch b/meta-openembedded/meta-oe/recipes-devtools/jq/jq/CVE-2024-53427.patch
new file mode 100644
index 0000000000..64a44a1307
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/jq/jq/CVE-2024-53427.patch
@@ -0,0 +1,82 @@
+From fa6131eb6e9d43e88e35982fa5f6049da2a77a87 Mon Sep 17 00:00:00 2001
+From: itchyny <itchyny@cybozu.co.jp>
+Date: Wed, 5 Mar 2025 07:43:54 +0900
+Subject: [PATCH] Reject NaN with payload while parsing JSON
+
+This commit drops support for parsing NaN with payload in JSON like
+`NaN123` and fixes CVE-2024-53427. Other JSON extensions like `NaN` and
+`Infinity` are still supported. Fixes #3023, fixes #3196, fixes #3246.
+
+Upstream-Status: Backport [https://github.com/jqlang/jq.git/commit/a09a4dfd55e6c24d04b35062ccfe4509748b1dd3]
+CVE: CVE-2024-53427
+
+(cherry picked from commit a09a4dfd55e6c24d04b35062ccfe4509748b1dd3)
+Signed-off-by: Roland Kovacs <roland.kovacs@est.tech>
+---
+ src/jv.c | 9 +++++++++
+ tests/jq.test | 14 ++++++++++----
+ tests/shtest | 5 -----
+ 3 files changed, 19 insertions(+), 9 deletions(-)
+
+diff --git a/src/jv.c b/src/jv.c
+index e23d8ec..34573b8 100644
+--- a/src/jv.c
++++ b/src/jv.c
+@@ -589,6 +589,15 @@ static jv jvp_literal_number_new(const char * literal) {
+ jv_mem_free(n);
+ return JV_INVALID;
+ }
++ if (decNumberIsNaN(&n->num_decimal)) {
++ // Reject NaN with payload.
++ if (n->num_decimal.digits > 1 || *n->num_decimal.lsu != 0) {
++ jv_mem_free(n);
++ return JV_INVALID;
++ }
++ jv_mem_free(n);
++ return jv_number(NAN);
++ }
+
+ jv r = {JVP_FLAGS_NUMBER_LITERAL, 0, 0, JV_NUMBER_SIZE_INIT, {&n->refcnt}};
+ return r;
+diff --git a/tests/jq.test b/tests/jq.test
+index 7036df2..d052b22 100644
+--- a/tests/jq.test
++++ b/tests/jq.test
+@@ -1938,11 +1938,17 @@ tojson | fromjson
+ {"a":nan}
+ {"a":null}
+
+-# also "nan with payload" #2985
+-fromjson | isnan
+-"nan1234"
++# NaN with payload is not parsed
++.[] | try (fromjson | isnan) catch .
++["NaN","-NaN","NaN1","NaN10","NaN100","NaN1000","NaN10000","NaN100000"]
+ true
+-
++true
++"Invalid numeric literal at EOF at line 1, column 4 (while parsing 'NaN1')"
++"Invalid numeric literal at EOF at line 1, column 5 (while parsing 'NaN10')"
++"Invalid numeric literal at EOF at line 1, column 6 (while parsing 'NaN100')"
++"Invalid numeric literal at EOF at line 1, column 7 (while parsing 'NaN1000')"
++"Invalid numeric literal at EOF at line 1, column 8 (while parsing 'NaN10000')"
++"Invalid numeric literal at EOF at line 1, column 9 (while parsing 'NaN100000')"
+
+ # calling input/0, or debug/0 in a test doesn't crash jq
+
+diff --git a/tests/shtest b/tests/shtest
+index 14aafbf..a471889 100755
+--- a/tests/shtest
++++ b/tests/shtest
+@@ -594,11 +594,6 @@ if ! x=$($JQ -n "1 # foo$cr + 2") || [ "$x" != 1 ]; then
+ exit 1
+ fi
+
+-# CVE-2023-50268: No stack overflow comparing a nan with a large payload
+-$VALGRIND $Q $JQ '1 != .' <<\EOF >/dev/null
+-Nan4000
+-EOF
+-
+ # Allow passing the inline jq script before -- #2919
+ if ! r=$($JQ --args -rn -- '$ARGS.positional[0]' bar) || [ "$r" != bar ]; then
+ echo "passing the inline script after -- didn't work"
diff --git a/meta-openembedded/meta-oe/recipes-devtools/jq/jq/CVE-2025-48060.patch b/meta-openembedded/meta-oe/recipes-devtools/jq/jq/CVE-2025-48060.patch
new file mode 100644
index 0000000000..c3dfd8ce21
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/jq/jq/CVE-2025-48060.patch
@@ -0,0 +1,48 @@
+From 35c08446e4bcd89e0e87e7750c68306d6c0e9ec5 Mon Sep 17 00:00:00 2001
+From: itchyny <itchyny@cybozu.co.jp>
+Date: Sat, 31 May 2025 11:46:40 +0900
+Subject: [PATCH] Fix heap buffer overflow when formatting an empty string
+
+The `jv_string_empty` did not properly null-terminate the string data,
+which could lead to a heap buffer overflow. The test case of
+GHSA-p7rr-28xf-3m5w (`0[""*0]`) was fixed by the commit dc849e9bb74a,
+but another case (`0[[]|implode]`) was still vulnerable. This commit
+ensures string data is properly null-terminated, and fixes CVE-2025-48060.
+
+Upstream-Status: Backport [https://github.com/jqlang/jq.git/commit/c6e041699d8cd31b97375a2596217aff2cfca85b]
+CVE: CVE-2025-48060
+
+(cherry picked from commit c6e041699d8cd31b97375a2596217aff2cfca85b)
+Signed-off-by: Roland Kovacs <roland.kovacs@est.tech>
+---
+ src/jv.c | 1 +
+ tests/jq.test | 4 ++++
+ 2 files changed, 5 insertions(+)
+
+diff --git a/src/jv.c b/src/jv.c
+index 15990f1..18dbb54 100644
+--- a/src/jv.c
++++ b/src/jv.c
+@@ -1125,6 +1125,7 @@ static jv jvp_string_empty_new(uint32_t length) {
+ jvp_string* s = jvp_string_alloc(length);
+ s->length_hashed = 0;
+ memset(s->data, 0, length);
++ s->data[length] = 0;
+ jv r = {JVP_FLAGS_STRING, 0, 0, 0, {&s->refcnt}};
+ return r;
+ }
+diff --git a/tests/jq.test b/tests/jq.test
+index 22bfd3a..ecb9116 100644
+--- a/tests/jq.test
++++ b/tests/jq.test
+@@ -2030,6 +2030,10 @@ map(try implode catch .)
+ [123,["a"],[nan]]
+ ["implode input must be an array","string (\"a\") can't be imploded, unicode codepoint needs to be numeric","number (null) can't be imploded, unicode codepoint needs to be numeric"]
+
++try 0[implode] catch .
++[]
++"Cannot index number with string \"\""
++
+ # walk
+ walk(.)
+ {"x":0}
diff --git a/meta-openembedded/meta-oe/recipes-devtools/jq/jq/CVE-2025-9403.patch b/meta-openembedded/meta-oe/recipes-devtools/jq/jq/CVE-2025-9403.patch
new file mode 100644
index 0000000000..19d769a6f5
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/jq/jq/CVE-2025-9403.patch
@@ -0,0 +1,49 @@
+From a4d9d540103ff9a262e304329c277ec89b27e5f9 Mon Sep 17 00:00:00 2001
+From: itchyny <itchyny@cybozu.co.jp>
+Date: Mon, 15 Sep 2025 07:47:51 +0900
+Subject: [PATCH] Fix expected value assertion for NaN value (fix #3393)
+ (#3408)
+
+CVE: CVE-2025-9403
+
+Upstream-Status: Backport [https://github.com/jqlang/jq/commit/a4d9d540103ff9a262e304329c277ec89b27e5f9]
+
+Signed-off-by: Divya Chellam <divya.chellam@windriver.com>
+---
+ src/jq_test.c | 13 ++++++++-----
+ 1 file changed, 8 insertions(+), 5 deletions(-)
+
+diff --git a/src/jq_test.c b/src/jq_test.c
+index 3945686..f42b05c 100644
+--- a/src/jq_test.c
++++ b/src/jq_test.c
+@@ -2,6 +2,7 @@
+ #include <stdio.h>
+ #include <string.h>
+ #include <stdlib.h>
++#include <math.h>
+ #ifdef HAVE_PTHREAD
+ #include <pthread.h>
+ #endif
+@@ -208,11 +209,13 @@ static void run_jq_tests(jv lib_dirs, int verbose, FILE *testdata, int skip, int
+ printf(" for test at line number %u: %s\n", lineno, prog);
+ pass = 0;
+ }
+- jv as_string = jv_dump_string(jv_copy(expected), rand() & ~(JV_PRINT_COLOR|JV_PRINT_REFCOUNT));
+- jv reparsed = jv_parse_sized(jv_string_value(as_string), jv_string_length_bytes(jv_copy(as_string)));
+- assert(jv_equal(jv_copy(expected), jv_copy(reparsed)));
+- jv_free(as_string);
+- jv_free(reparsed);
++ if (!(jv_get_kind(expected) == JV_KIND_NUMBER && isnan(jv_number_value(expected)))) {
++ jv as_string = jv_dump_string(jv_copy(expected), rand() & ~(JV_PRINT_COLOR|JV_PRINT_REFCOUNT));
++ jv reparsed = jv_parse_sized(jv_string_value(as_string), jv_string_length_bytes(jv_copy(as_string)));
++ assert(jv_equal(jv_copy(expected), jv_copy(reparsed)));
++ jv_free(as_string);
++ jv_free(reparsed);
++ }
+ jv_free(expected);
+ jv_free(actual);
+ }
+--
+2.40.0
+
diff --git a/meta-openembedded/meta-oe/recipes-devtools/jq/jq_1.7.1.bb b/meta-openembedded/meta-oe/recipes-devtools/jq/jq_1.7.1.bb
index 6b12335513..dfc8dda7ee 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/jq/jq_1.7.1.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/jq/jq_1.7.1.bb
@@ -11,6 +11,10 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=488f4e0b04c0456337fb70d1ac1758ba"
GITHUB_BASE_URI = "https://github.com/jqlang/${BPN}/releases/"
SRC_URI = "${GITHUB_BASE_URI}/download/${BPN}-${PV}/${BPN}-${PV}.tar.gz \
file://run-ptest \
+ file://CVE-2024-23337.patch \
+ file://CVE-2024-53427.patch \
+ file://CVE-2025-48060.patch \
+ file://CVE-2025-9403.patch \
"
SRC_URI[sha256sum] = "478c9ca129fd2e3443fe27314b455e211e0d8c60bc8ff7df703873deeee580c2"
diff --git a/meta-openembedded/meta-oe/recipes-devtools/jsonrpc/jsonrpc_1.4.1.bb b/meta-openembedded/meta-oe/recipes-devtools/jsonrpc/jsonrpc_1.4.1.bb
index 544922f05d..f0c60e5a86 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/jsonrpc/jsonrpc_1.4.1.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/jsonrpc/jsonrpc_1.4.1.bb
@@ -25,4 +25,8 @@ EXTRA_OECMAKE += "-DCOMPILE_TESTS=NO -DCOMPILE_STUBGEN=NO -DCOMPILE_EXAMPLES=NO
-DCMAKE_LIBRARY_PATH=${libdir} \
"
+do_install:append() {
+ sed -i -e 's#${RECIPE_SYSROOT}##g' ${D}${libdir}/libjson-rpc-cpp/cmake/libjson-rpc-cppTargets.cmake
+}
+
FILES:${PN}-dev += "${libdir}/libjson-rpc-cpp/cmake"
diff --git a/meta-openembedded/meta-oe/recipes-devtools/lapack/lapack_3.12.0.bb b/meta-openembedded/meta-oe/recipes-devtools/lapack/lapack_3.12.0.bb
index fef9d3a80e..4845d34106 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/lapack/lapack_3.12.0.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/lapack/lapack_3.12.0.bb
@@ -24,6 +24,7 @@ S = "${WORKDIR}/git"
PACKAGECONFIG ?= ""
PACKAGECONFIG[lapacke] = "-DLAPACKE=ON,-DLAPACKE=OFF"
+PACKAGECONFIG[cblas] = "-DCBLAS=ON,-DCBLAS=OFF"
EXTRA_OECMAKE = " -DBUILD_SHARED_LIBS=ON \
${@bb.utils.contains('PTEST_ENABLED', '1', ' -DBUILD_TESTING=ON', '', d)} \
@@ -33,6 +34,48 @@ OECMAKE_GENERATOR = "Unix Makefiles"
inherit cmake pkgconfig ptest
EXCLUDE_FROM_WORLD = "1"
+# The `xerbla.o` file contains an absolute path in `xerbla.f.o`, but the options
+# `-fdebug-prefix-map` and `-ffile-prefix-map` cannot be used because gfortran does
+# not support them. And we cannot easily change CMake to use relative paths, because
+# it will convert them to absolute paths when generating Unix Makefiles or Ninja:
+# https://gitlab.kitware.com/cmake/community/-/wikis/FAQ#why-does-cmake-use-full-paths-or-can-i-copy-my-build-tree
+# https://gitlab.kitware.com/cmake/cmake/-/issues/13894
+#
+# To address this issue, we manually replace the absolute path with a relative path
+# in the generated `build.make` file.
+#
+# An issue has been reported: https://github.com/Reference-LAPACK/lapack/issues/1087,
+# requesting a fix in the source code.
+#
+# This workaround resolves the TMPDIR [buildpaths] issue by converting the absolute path
+# of `xerbla.f` to a relative path. The steps are as follows:
+#
+# 1. Locate all `build.make` files after the `do_configure` step is completed.
+# 2. Compute the relative path for various `*.f` files based on the current build directory.
+# 3. Replace the absolute path with the calculated relative path in the `build.make` files
+#
+# Additionally, when ptests are enabled, apply a simpler workaround for ptest code:
+# - Replace occurrences of `${WORKDIR}` in all `build.make` files under the TESTING directory, excluding
+# the MATGEN subdirectory, with a relative path prefix of `"../../.."`.
+do_configure:append(){
+ for file in `find ${B} -name build.make`; do
+ # Replacing all .f files found with:
+ # for f in $(find ${S} -name \*.f -printf " %f" | sort -u); do
+ # would be more reliable with other optional PACKAGECONFIGs, but also very slow as there are
+ # ~ 3500 of them and this loop takes around 20 minutes
+ for f in xerbla c_cblat1 c_cblat2 c_cblat3 c_dblat1 c_dblat2 c_dblat3 c_sblat1 c_sblat2 c_sblat3 c_zblat1 c_zblat2 c_zblat3; do
+ sed -i -e "s#\(.*-c \).*\(/$f\.f \)#\1$(grep "\-c .*$f\.f" $file | awk -F'cd ' '{print $2}'| \
+ awk "{src=\$1; sub(/.*-c /, \"\"); sub(/$f\.f.*/, \"\"); obj=\$0; print src, obj}" | \
+ while read src obj; do echo "$(realpath --relative-to="$src" "$obj")"; done)\2#g" $file
+ done
+ done
+ if ${@bb.utils.contains('PTEST_ENABLED', '1', 'true', 'false', d)} ; then
+ for file in `find . -name build.make -path '*TESTING*' -not -path '*MATGEN*'`; do
+ sed -i -e "s#\(.*-c \)\(${WORKDIR}\)\(.*.[f|F] \)#\1../../..\3#g" $file
+ done
+ fi
+}
+
do_install_ptest () {
rsync -a ${B}/TESTING ${D}${PTEST_PATH} \
--exclude CMakeFiles \
diff --git a/meta-openembedded/meta-oe/recipes-devtools/ldns/ldns_1.8.3.bb b/meta-openembedded/meta-oe/recipes-devtools/ldns/ldns_1.8.3.bb
index 16816e62d8..80e5571954 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/ldns/ldns_1.8.3.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/ldns/ldns_1.8.3.bb
@@ -19,5 +19,6 @@ do_install:append() {
sed -e 's@[^ ]*-ffile-prefix-map=[^ "]*@@g' \
-e 's@[^ ]*-fdebug-prefix-map=[^ "]*@@g' \
-e 's@[^ ]*-fmacro-prefix-map=[^ "]*@@g' \
- -i ${D}${libdir}/pkgconfig/*.pc
+ -e 's@${RECIPE_SYSROOT}@@g' \
+ -i ${D}${libdir}/pkgconfig/*.pc ${D}${bindir}/ldns-config
}
diff --git a/meta-openembedded/meta-oe/recipes-devtools/luajit/luajit/CVE-2024-25176.patch b/meta-openembedded/meta-oe/recipes-devtools/luajit/luajit/CVE-2024-25176.patch
new file mode 100644
index 0000000000..5d3048e05f
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/luajit/luajit/CVE-2024-25176.patch
@@ -0,0 +1,32 @@
+From fd92fb62201b3980af8e538452102e9f21426ec6 Mon Sep 17 00:00:00 2001
+From: Mike Pall <mike>
+Date: Thu, 25 Jan 2024 13:23:48 +0100
+Subject: [PATCH] Fix zero stripping in %g number formatting.
+
+Reported by pwnhacker0x18. #1149
+
+CVE: CVE-2024-25176
+Upstream-Status: Backport [https://github.com/LuaJIT/LuaJIT/commit/343ce0edaf3906a62022936175b2f5410024cbfc]
+
+Signed-off-by: Changqing Li <changqing.li@windriver.com>
+---
+ src/lj_strfmt_num.c | 3 ++-
+ 1 file changed, 2 insertions(+), 1 deletion(-)
+
+diff --git a/src/lj_strfmt_num.c b/src/lj_strfmt_num.c
+index 79ec0263..c6e776aa 100644
+--- a/src/lj_strfmt_num.c
++++ b/src/lj_strfmt_num.c
+@@ -454,7 +454,8 @@ static char *lj_strfmt_wfnum(SBuf *sb, SFormat sf, lua_Number n, char *p)
+ prec--;
+ if (!i) {
+ if (ndlo == ndhi) { prec = 0; break; }
+- lj_strfmt_wuint9(tail, nd[++ndlo]);
++ ndlo = (ndlo + 1) & 0x3f;
++ lj_strfmt_wuint9(tail, nd[ndlo]);
+ i = 9;
+ }
+ }
+--
+2.34.1
+
diff --git a/meta-openembedded/meta-oe/recipes-devtools/luajit/luajit/CVE-2024-25177.patch b/meta-openembedded/meta-oe/recipes-devtools/luajit/luajit/CVE-2024-25177.patch
new file mode 100644
index 0000000000..f02749498c
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/luajit/luajit/CVE-2024-25177.patch
@@ -0,0 +1,47 @@
+From e27aa9c2fe7e7744b517ff0811defc11a81aa454 Mon Sep 17 00:00:00 2001
+From: Changqing Li <changqing.li@windriver.com>
+Date: Mon, 4 Aug 2025 16:47:31 +0800
+Subject: [PATCH] Fix unsinking of IR_FSTORE for NULL metatable.
+
+Reported by pwnhacker0x18. #1147
+
+CVE: CVE-2024-25177
+Upstream-Status: Backport [https://github.com/openresty/luajit2/commit/85b4fed0b0353dd78c8c875c2f562d522a2b310f]
+
+Signed-off-by: Changqing Li <changqing.li@windriver.com>
+---
+ src/lj_snap.c | 11 ++++++++---
+ 1 file changed, 8 insertions(+), 3 deletions(-)
+
+diff --git a/src/lj_snap.c b/src/lj_snap.c
+index 7d7347a1..f3645e87 100644
+--- a/src/lj_snap.c
++++ b/src/lj_snap.c
+@@ -453,6 +453,7 @@ static TRef snap_replay_const(jit_State *J, IRIns *ir)
+ case IR_KNUM: case IR_KINT64:
+ return lj_ir_k64(J, (IROp)ir->o, ir_k64(ir)->u64);
+ case IR_KPTR: return lj_ir_kptr(J, ir_kptr(ir)); /* Continuation. */
++ case IR_KNULL: return lj_ir_knull(J, irt_type(ir->t));
+ default: lj_assertJ(0, "bad IR constant op %d", ir->o); return TREF_NIL;
+ }
+ }
+@@ -902,9 +903,13 @@ static void snap_unsink(jit_State *J, GCtrace *T, ExitState *ex,
+ if (irk->o == IR_FREF) {
+ switch (irk->op2) {
+ case IRFL_TAB_META:
+- snap_restoreval(J, T, ex, snapno, rfilt, irs->op2, &tmp);
+- /* NOBARRIER: The table is new (marked white). */
+- setgcref(t->metatable, obj2gco(tabV(&tmp)));
++ if (T->ir[irs->op2].o == IR_KNULL) {
++ setgcrefnull(t->metatable);
++ } else {
++ snap_restoreval(J, T, ex, snapno, rfilt, irs->op2, &tmp);
++ /* NOBARRIER: The table is new (marked white). */
++ setgcref(t->metatable, obj2gco(tabV(&tmp)));
++ }
+ break;
+ case IRFL_TAB_NOMM:
+ /* Negative metamethod cache invalidated by lj_tab_set() below. */
+--
+2.34.1
+
diff --git a/meta-openembedded/meta-oe/recipes-devtools/luajit/luajit/CVE-2024-25178.patch b/meta-openembedded/meta-oe/recipes-devtools/luajit/luajit/CVE-2024-25178.patch
new file mode 100644
index 0000000000..485cffff31
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/luajit/luajit/CVE-2024-25178.patch
@@ -0,0 +1,162 @@
+From f57533a41640087904ecbd5ca6946656078e6014 Mon Sep 17 00:00:00 2001
+From: Mike Pall <mike>
+Date: Sun, 4 Feb 2024 16:34:30 +0100
+Subject: [PATCH] Rework stack overflow handling.
+
+Reported by pwnhacker0x18. Fixed by Peter Cawley. #1152
+
+CVE: CVE-2024-25178
+Upstream-Status: Backport [https://github.com/LuaJIT/LuaJIT/commit/defe61a56751a0db5f00ff3ab7b8f45436ba74c8
+https://github.com/LuaJIT/LuaJIT/commit/0d313b243194a0b8d2399d8b549ca5a0ff234db5]
+
+Signed-off-by: Changqing Li <changqing.li@windriver.com>
+---
+ src/lj_debug.c | 1 +
+ src/lj_err.c | 22 +++++++++++++++++---
+ src/lj_err.h | 1 +
+ src/lj_state.c | 54 +++++++++++++++++++++++++++++++++-----------------
+ 4 files changed, 57 insertions(+), 21 deletions(-)
+
+diff --git a/src/lj_debug.c b/src/lj_debug.c
+index fa189b6e..8d8b9eb5 100644
+--- a/src/lj_debug.c
++++ b/src/lj_debug.c
+@@ -64,6 +64,7 @@ static BCPos debug_framepc(lua_State *L, GCfunc *fn, cTValue *nextframe)
+ if (cf == NULL || (char *)cframe_pc(cf) == (char *)cframe_L(cf))
+ return NO_BCPOS;
+ ins = cframe_pc(cf); /* Only happens during error/hook handling. */
++ if (!ins) return NO_BCPOS;
+ } else {
+ if (frame_islua(nextframe)) {
+ ins = frame_pc(nextframe);
+diff --git a/src/lj_err.c b/src/lj_err.c
+index 7b11e4d0..6b752728 100644
+--- a/src/lj_err.c
++++ b/src/lj_err.c
+@@ -818,7 +818,14 @@ LJ_NOINLINE void lj_err_mem(lua_State *L)
+ TValue *base = tvref(G(L)->jit_base);
+ if (base) L->base = base;
+ }
+- if (curr_funcisL(L)) L->top = curr_topL(L);
++ if (curr_funcisL(L)) {
++ L->top = curr_topL(L);
++ if (LJ_UNLIKELY(L->top > tvref(L->maxstack))) {
++ /* The current Lua frame violates the stack. Replace it with a dummy. */
++ L->top = L->base;
++ setframe_gc(L->base - 1 - LJ_FR2, obj2gco(L), LJ_TTHREAD);
++ }
++ }
+ setstrV(L, L->top++, lj_err_str(L, LJ_ERR_ERRMEM));
+ lj_err_throw(L, LUA_ERRMEM);
+ }
+@@ -879,9 +886,11 @@ LJ_NOINLINE void LJ_FASTCALL lj_err_run(lua_State *L)
+ {
+ ptrdiff_t ef = (LJ_HASJIT && tvref(G(L)->jit_base)) ? 0 : finderrfunc(L);
+ if (ef) {
+- TValue *errfunc = restorestack(L, ef);
+- TValue *top = L->top;
++ TValue *errfunc, *top;
++ lj_state_checkstack(L, LUA_MINSTACK * 2); /* Might raise new error. */
+ lj_trace_abort(G(L));
++ errfunc = restorestack(L, ef);
++ top = L->top;
+ if (!tvisfunc(errfunc) || L->status == LUA_ERRERR) {
+ setstrV(L, top-1, lj_err_str(L, LJ_ERR_ERRERR));
+ lj_err_throw(L, LUA_ERRERR);
+@@ -906,6 +915,13 @@ LJ_NOINLINE void LJ_FASTCALL lj_err_trace(lua_State *L, int errcode)
+ }
+ #endif
+
++/* Stack overflow error. */
++void LJ_FASTCALL lj_err_stkov(lua_State *L)
++{
++ lj_debug_addloc(L, err2msg(LJ_ERR_STKOV), L->base-1, NULL);
++ lj_err_run(L);
++}
++
+ /* Formatted runtime error message. */
+ LJ_NORET LJ_NOINLINE static void err_msgv(lua_State *L, ErrMsg em, ...)
+ {
+diff --git a/src/lj_err.h b/src/lj_err.h
+index 8768fefd..67686cb7 100644
+--- a/src/lj_err.h
++++ b/src/lj_err.h
+@@ -23,6 +23,7 @@ LJ_DATA const char *lj_err_allmsg;
+ LJ_FUNC GCstr *lj_err_str(lua_State *L, ErrMsg em);
+ LJ_FUNCA_NORET void LJ_FASTCALL lj_err_throw(lua_State *L, int errcode);
+ LJ_FUNC_NORET void lj_err_mem(lua_State *L);
++LJ_FUNC_NORET void LJ_FASTCALL lj_err_stkov(lua_State *L);
+ LJ_FUNC_NORET void LJ_FASTCALL lj_err_run(lua_State *L);
+ #if LJ_HASJIT
+ LJ_FUNCA_NORET void LJ_FASTCALL lj_err_trace(lua_State *L, int errcode);
+diff --git a/src/lj_state.c b/src/lj_state.c
+index 7e4961bd..02cc4440 100644
+--- a/src/lj_state.c
++++ b/src/lj_state.c
+@@ -102,27 +102,45 @@ void lj_state_shrinkstack(lua_State *L, MSize used)
+ /* Try to grow stack. */
+ void LJ_FASTCALL lj_state_growstack(lua_State *L, MSize need)
+ {
+- MSize n;
+- if (L->stacksize >= LJ_STACK_MAXEX) {
+- /* 4. Throw 'error in error handling' when we are _over_ the limit. */
+- if (L->stacksize > LJ_STACK_MAXEX)
++ MSize n = L->stacksize + need;
++ if (LJ_LIKELY(n < LJ_STACK_MAX)) { /* The stack can grow as requested. */
++ if (n < 2 * L->stacksize) { /* Try to double the size. */
++ n = 2 * L->stacksize;
++ if (n > LJ_STACK_MAX)
++ n = LJ_STACK_MAX;
++ }
++ resizestack(L, n);
++ } else { /* Request would overflow. Raise a stack overflow error. */
++ if (curr_funcisL(L)) {
++ L->top = curr_topL(L);
++ if (L->top > tvref(L->maxstack)) {
++ /* The current Lua frame violates the stack, so replace it with a
++ ** dummy. This can happen when BC_IFUNCF is trying to grow the stack.
++ */
++ L->top = L->base;
++ setframe_gc(L->base - 1 - LJ_FR2, obj2gco(L), LJ_TTHREAD);
++ }
++ }
++ if (L->stacksize <= LJ_STACK_MAXEX) {
++ /* An error handler might want to inspect the stack overflow error, but
++ ** will need some stack space to run in. We give it a stack size beyond
++ ** the normal limit in order to do so, then rely on lj_state_relimitstack
++ ** calls during unwinding to bring us back to a convential stack size.
++ ** The + 1 is space for the error message, and 2 * LUA_MINSTACK is for
++ ** the lj_state_checkstack() call in lj_err_run().
++ */
++ resizestack(L, LJ_STACK_MAX + 1 + 2 * LUA_MINSTACK);
++ lj_err_stkov(L); /* May invoke an error handler. */
++ } else {
++ /* If we're here, then the stack overflow error handler is requesting
++ ** to grow the stack even further. We have no choice but to abort the
++ ** error handler.
++ */
++ GCstr *em = lj_err_str(L, LJ_ERR_STKOV); /* Might OOM. */
++ setstrV(L, L->top++, em); /* There is always space to push an error. */
+ lj_err_throw(L, LUA_ERRERR); /* Does not invoke an error handler. */
+- /* 1. We are _at_ the limit after the last growth. */
+- if (L->status < LUA_ERRRUN) { /* 2. Throw 'stack overflow'. */
+- L->status = LUA_ERRRUN; /* Prevent ending here again for pushed msg. */
+- lj_err_msg(L, LJ_ERR_STKOV); /* May invoke an error handler. */
+ }
+- /* 3. Add space (over the limit) for pushed message and error handler. */
+- }
+- n = L->stacksize + need;
+- if (n > LJ_STACK_MAX) {
+- n += 2*LUA_MINSTACK;
+- } else if (n < 2*L->stacksize) {
+- n = 2*L->stacksize;
+- if (n >= LJ_STACK_MAX)
+- n = LJ_STACK_MAX;
+ }
+- resizestack(L, n);
+ }
+
+ void LJ_FASTCALL lj_state_growstack1(lua_State *L)
+--
+2.34.1
+
diff --git a/meta-openembedded/meta-oe/recipes-devtools/luajit/luajit_git.bb b/meta-openembedded/meta-oe/recipes-devtools/luajit/luajit_git.bb
index 240271d410..507d254556 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/luajit/luajit_git.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/luajit/luajit_git.bb
@@ -6,6 +6,9 @@ HOMEPAGE = "http://luajit.org"
SRC_URI = "git://luajit.org/git/luajit-2.0.git;protocol=http;branch=v2.1 \
file://0001-Do-not-strip-automatically-this-leaves-the-stripping.patch \
file://0001-Use-builtin-for-clear_cache.patch \
+ file://CVE-2024-25177.patch \
+ file://CVE-2024-25176.patch \
+ file://CVE-2024-25178.patch \
"
PV = "2.1"
diff --git a/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs-oe-cache-20.12/oe-npm-cache b/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs-oe-cache-20.18/oe-npm-cache
index eb0f143eae..eb0f143eae 100755
--- a/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs-oe-cache-20.12/oe-npm-cache
+++ b/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs-oe-cache-20.18/oe-npm-cache
diff --git a/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs-oe-cache-native_20.12.bb b/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs-oe-cache-native_20.18.bb
index a61dd5018f..a61dd5018f 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs-oe-cache-native_20.12.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs-oe-cache-native_20.18.bb
diff --git a/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/0001-build-fix-build-with-Python-3.12.patch b/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/0001-build-fix-build-with-Python-3.12.patch
deleted file mode 100644
index 39026d0742..0000000000
--- a/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/0001-build-fix-build-with-Python-3.12.patch
+++ /dev/null
@@ -1,55 +0,0 @@
-From 656f6c91f1da7f1e1ffb01e2de7d9026a84958b5 Mon Sep 17 00:00:00 2001
-From: Luigi Pinca <luigipinca@gmail.com>
-Date: Wed, 8 Nov 2023 21:20:53 +0100
-Subject: [PATCH] build: fix build with Python 3.12
-
-Replace `distutils.version.StrictVersion` with
-`packaging.version.Version`.
-
-Refs: https://github.com/nodejs/node/pull/50209#issuecomment-1795852539
-PR-URL: https://github.com/nodejs/node/pull/50582
-Reviewed-By: Richard Lau <rlau@redhat.com>
-Reviewed-By: Chengzhong Wu <legendecas@gmail.com>
-
-Upstream-Status: Backport [https://github.com/nodejs/node/commit/95534ad82f4e33f53fd50efe633d43f8da70cba6]
-Signed-off-by: Alexander Kanavin <alex@linutronix.de>
----
- configure.py | 11 +++++------
- 1 file changed, 5 insertions(+), 6 deletions(-)
-
-diff --git a/configure.py b/configure.py
-index 62f041ce..18fe7c14 100755
---- a/configure.py
-+++ b/configure.py
-@@ -14,8 +14,6 @@ import bz2
- import io
- from pathlib import Path
-
--from distutils.version import StrictVersion
--
- # If not run from node/, cd to node/.
- os.chdir(Path(__file__).parent)
-
-@@ -30,6 +28,7 @@ tools_path = Path('tools')
-
- sys.path.insert(0, str(tools_path / 'gyp' / 'pylib'))
- from gyp.common import GetFlavor
-+from packaging.version import Version
-
- # imports in tools/configure.d
- sys.path.insert(0, str(tools_path / 'configure.d'))
-@@ -1565,10 +1564,10 @@ def configure_openssl(o):
- # supported asm compiler for AVX2. See https://github.com/openssl/openssl/
- # blob/OpenSSL_1_1_0-stable/crypto/modes/asm/aesni-gcm-x86_64.pl#L52-L69
- openssl110_asm_supported = \
-- ('gas_version' in variables and StrictVersion(variables['gas_version']) >= StrictVersion('2.23')) or \
-- ('xcode_version' in variables and StrictVersion(variables['xcode_version']) >= StrictVersion('5.0')) or \
-- ('llvm_version' in variables and StrictVersion(variables['llvm_version']) >= StrictVersion('3.3')) or \
-- ('nasm_version' in variables and StrictVersion(variables['nasm_version']) >= StrictVersion('2.10'))
-+ ('gas_version' in variables and Version(variables['gas_version']) >= Version('2.23')) or \
-+ ('xcode_version' in variables and Version(variables['xcode_version']) >= Version('5.0')) or \
-+ ('llvm_version' in variables and Version(variables['llvm_version']) >= Version('3.3')) or \
-+ ('nasm_version' in variables and Version(variables['nasm_version']) >= Version('2.10'))
-
- if is_x86 and not openssl110_asm_supported:
- error('''Did not find a new enough assembler, install one or build with
diff --git a/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/0001-gyp-resolve-python-3.12-issues.patch b/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/0001-gyp-resolve-python-3.12-issues.patch
deleted file mode 100644
index 9d878dfb8d..0000000000
--- a/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/0001-gyp-resolve-python-3.12-issues.patch
+++ /dev/null
@@ -1,63 +0,0 @@
-From bf8c96ba6936050ed4a0de5bc8aeeaf2b3c50dc1 Mon Sep 17 00:00:00 2001
-From: Alexander Kanavin <alex@linutronix.de>
-Date: Thu, 7 Dec 2023 12:54:30 +0100
-Subject: [PATCH] gyp: resolve python 3.12 issues
-
-Upstream has updated gyp wholesale in the main branch, so
-this patch can be dropped in due time.
-
-Upstream-Status: Inappropriate [issue will be fixed upstream with the next nodejs LTS update]
-
-Signed-off-by: Alexander Kanavin <alex@linutronix.de>
----
- deps/npm/node_modules/node-gyp/gyp/pylib/gyp/input.py | 4 ++--
- tools/gyp/pylib/gyp/input.py | 4 ++--
- 2 files changed, 4 insertions(+), 4 deletions(-)
-
-diff --git a/deps/npm/node_modules/node-gyp/gyp/pylib/gyp/input.py b/deps/npm/node_modules/node-gyp/gyp/pylib/gyp/input.py
-index d9699a0a..173e9465 100644
---- a/deps/npm/node_modules/node-gyp/gyp/pylib/gyp/input.py
-+++ b/deps/npm/node_modules/node-gyp/gyp/pylib/gyp/input.py
-@@ -16,7 +16,7 @@ import subprocess
- import sys
- import threading
- import traceback
--from distutils.version import StrictVersion
-+from packaging.version import Version
- from gyp.common import GypError
- from gyp.common import OrderedSet
-
-@@ -1183,7 +1183,7 @@ def EvalSingleCondition(cond_expr, true_dict, false_dict, phase, variables, buil
- else:
- ast_code = compile(cond_expr_expanded, "<string>", "eval")
- cached_conditions_asts[cond_expr_expanded] = ast_code
-- env = {"__builtins__": {}, "v": StrictVersion}
-+ env = {"__builtins__": {}, "v": Version}
- if eval(ast_code, env, variables):
- return true_dict
- return false_dict
-diff --git a/tools/gyp/pylib/gyp/input.py b/tools/gyp/pylib/gyp/input.py
-index 354958bf..ab6112e5 100644
---- a/tools/gyp/pylib/gyp/input.py
-+++ b/tools/gyp/pylib/gyp/input.py
-@@ -16,7 +16,7 @@ import subprocess
- import sys
- import threading
- import traceback
--from distutils.version import StrictVersion
-+from packaging.version import Version
- from gyp.common import GypError
- from gyp.common import OrderedSet
-
-@@ -1190,7 +1190,7 @@ def EvalSingleCondition(cond_expr, true_dict, false_dict, phase, variables, buil
- else:
- ast_code = compile(cond_expr_expanded, "<string>", "eval")
- cached_conditions_asts[cond_expr_expanded] = ast_code
-- env = {"__builtins__": {}, "v": StrictVersion}
-+ env = {"__builtins__": {}, "v": Version}
- if eval(ast_code, env, variables):
- return true_dict
- return false_dict
---
-2.39.2
-
diff --git a/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/0001-src-fix-build-with-GCC-15.patch b/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/0001-src-fix-build-with-GCC-15.patch
new file mode 100644
index 0000000000..9d09f4f482
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/0001-src-fix-build-with-GCC-15.patch
@@ -0,0 +1,33 @@
+From bade7a1866618b9e46358b839fe5fdf16b1db2be Mon Sep 17 00:00:00 2001
+From: tjuhaszrh <tjuhasz@redhat.com>
+Date: Sat, 25 Jan 2025 10:34:54 +0100
+Subject: [PATCH] src: fix build with GCC 15
+
+Added cstdint to worker_inspector as on more recent version of gcc
+the build was failing due to changes to libstdc++ and the removal
+of transitive includes.
+
+PR-URL: https://github.com/nodejs/node/pull/56740
+Fixes: https://github.com/nodejs/node/issues/56731
+Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
+Reviewed-By: Chengzhong Wu <legendecas@gmail.com>
+Reviewed-By: Richard Lau <rlau@redhat.com>
+Reviewed-By: James M Snell <jasnell@gmail.com>
+
+Upstream-Status: Backport [https://github.com/nodejs/node/commit/bade7a1866618b9e46358b839fe5fdf16b1db2be]
+---
+ src/inspector/worker_inspector.h | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/src/inspector/worker_inspector.h b/src/inspector/worker_inspector.h
+index d3254d5aa0ebe4..24403bb1704c40 100644
+--- a/src/inspector/worker_inspector.h
++++ b/src/inspector/worker_inspector.h
+@@ -5,6 +5,7 @@
+ #error("This header can only be used when inspector is enabled")
+ #endif
+
++#include <cstdint>
+ #include <memory>
+ #include <string>
+ #include <unordered_map>
diff --git a/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/182d9c05e78.patch b/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/182d9c05e78.patch
new file mode 100644
index 0000000000..9b3fc566c8
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/182d9c05e78.patch
@@ -0,0 +1,182 @@
+From 182d9c05e78b1ddb1cb8242cd3628a7855a0336f Mon Sep 17 00:00:00 2001
+From: Andrey Kosyakov <caseq@chromium.org>
+Date: Thu, 17 Aug 2023 13:50:11 -0700
+Subject: [PATCH] Define UChar as char16_t
+
+We used to have UChar defined as uint16_t which does not go along
+with STL these days if you try to have an std::basic_string<> of it,
+as there are no standard std::char_traits<> specialization for uint16_t.
+
+This switches UChar to char16_t where practical, introducing a few
+compatibility shims to keep CL size small, as (1) this would likely
+have to be back-ported and (2) crdtp extensively uses uint16_t for
+wide chars.
+
+Bug: b:296390693
+Change-Id: I66a32d8f0050915225b187de56896c26dd76163d
+Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/4789966
+Reviewed-by: Jaroslav Sevcik <jarin@chromium.org>
+Commit-Queue: Jaroslav Sevcik <jarin@chromium.org>
+Auto-Submit: Andrey Kosyakov <caseq@chromium.org>
+Cr-Commit-Position: refs/heads/main@{#89559}
+
+Upstream-Status: Backport [https://chromium-review.googlesource.com/c/v8/v8/+/4789966]
+Signed-off-by: Khem Raj <raj.khem@gmail.com>
+---
+ src/inspector/string-16.cc | 8 +++++++-
+ src/inspector/string-16.h | 10 ++++++++--
+ src/inspector/v8-string-conversions.cc | 6 +++---
+ src/inspector/v8-string-conversions.h | 6 ++++--
+ .../inspector_protocol/crdtp/test_platform_v8.cc | 9 ++++++---
+ 5 files changed, 28 insertions(+), 11 deletions(-)
+
+--- a/deps/v8/src/inspector/string-16.cc
++++ b/deps/v8/src/inspector/string-16.cc
+@@ -27,7 +27,7 @@ bool isSpaceOrNewLine(UChar c) {
+ return isASCII(c) && c <= ' ' && (c == ' ' || (c <= 0xD && c >= 0x9));
+ }
+
+-int64_t charactersToInteger(const UChar* characters, size_t length,
++int64_t charactersToInteger(const uint16_t* characters, size_t length,
+ bool* ok = nullptr) {
+ std::vector<char> buffer;
+ buffer.reserve(length + 1);
+@@ -50,6 +50,8 @@ int64_t charactersToInteger(const UChar*
+
+ String16::String16(const UChar* characters, size_t size)
+ : m_impl(characters, size) {}
++String16::String16(const uint16_t* characters, size_t size)
++ : m_impl(reinterpret_cast<const UChar*>(characters), size) {}
+
+ String16::String16(const UChar* characters) : m_impl(characters) {}
+
+@@ -241,6 +243,10 @@ String16 String16::fromUTF16LE(const UCh
+ #endif // V8_TARGET_BIG_ENDIAN
+ }
+
++String16 String16::fromUTF16LE(const uint16_t* stringStart, size_t length) {
++ return fromUTF16LE(reinterpret_cast<const UChar*>(stringStart), length);
++}
++
+ std::string String16::utf8() const {
+ return UTF16ToUTF8(m_impl.data(), m_impl.size());
+ }
+--- a/deps/v8/src/inspector/string-16.h
++++ b/deps/v8/src/inspector/string-16.h
+@@ -6,6 +6,7 @@
+ #define V8_INSPECTOR_STRING_16_H_
+
+ #include <stdint.h>
++#include <uchar.h>
+
+ #include <cctype>
+ #include <climits>
+@@ -17,7 +18,7 @@
+
+ namespace v8_inspector {
+
+-using UChar = uint16_t;
++using UChar = char16_t;
+
+ class String16 {
+ public:
+@@ -27,6 +28,7 @@ class String16 {
+ String16(const String16&) V8_NOEXCEPT = default;
+ String16(String16&&) V8_NOEXCEPT = default;
+ String16(const UChar* characters, size_t size);
++ String16(const uint16_t* characters, size_t size);
+ V8_EXPORT String16(const UChar* characters);
+ V8_EXPORT String16(const char* characters);
+ String16(const char* characters, size_t size);
+@@ -48,7 +50,9 @@ class String16 {
+ int toInteger(bool* ok = nullptr) const;
+ std::pair<size_t, size_t> getTrimmedOffsetAndLength() const;
+ String16 stripWhiteSpace() const;
+- const UChar* characters16() const { return m_impl.c_str(); }
++ const uint16_t* characters16() const {
++ return reinterpret_cast<const uint16_t*>(m_impl.c_str());
++ }
+ size_t length() const { return m_impl.length(); }
+ bool isEmpty() const { return !m_impl.length(); }
+ UChar operator[](size_t index) const { return m_impl[index]; }
+@@ -78,6 +82,8 @@ class String16 {
+ // On Big endian architectures, byte order needs to be flipped.
+ V8_EXPORT static String16 fromUTF16LE(const UChar* stringStart,
+ size_t length);
++ V8_EXPORT static String16 fromUTF16LE(const uint16_t* stringStart,
++ size_t length);
+
+ std::size_t hash() const {
+ if (!hash_code) {
+--- a/deps/v8/src/inspector/v8-string-conversions.cc
++++ b/deps/v8/src/inspector/v8-string-conversions.cc
+@@ -12,7 +12,7 @@
+
+ namespace v8_inspector {
+ namespace {
+-using UChar = uint16_t;
++using UChar = char16_t;
+ using UChar32 = uint32_t;
+
+ bool isASCII(UChar c) { return !(c & ~0x7F); }
+@@ -386,7 +386,7 @@ std::string UTF16ToUTF8(const UChar* str
+
+ std::basic_string<UChar> UTF8ToUTF16(const char* stringStart, size_t length) {
+ if (!stringStart || !length) return std::basic_string<UChar>();
+- std::vector<uint16_t> buffer(length);
++ std::vector<UChar> buffer(length);
+ UChar* bufferStart = buffer.data();
+
+ UChar* bufferCurrent = bufferStart;
+@@ -395,7 +395,7 @@ std::basic_string<UChar> UTF8ToUTF16(con
+ reinterpret_cast<const char*>(stringStart + length),
+ &bufferCurrent, bufferCurrent + buffer.size(), nullptr,
+ true) != conversionOK)
+- return std::basic_string<uint16_t>();
++ return std::basic_string<UChar>();
+ size_t utf16Length = bufferCurrent - bufferStart;
+ return std::basic_string<UChar>(bufferStart, bufferStart + utf16Length);
+ }
+--- a/deps/v8/src/inspector/v8-string-conversions.h
++++ b/deps/v8/src/inspector/v8-string-conversions.h
+@@ -5,14 +5,16 @@
+ #ifndef V8_INSPECTOR_V8_STRING_CONVERSIONS_H_
+ #define V8_INSPECTOR_V8_STRING_CONVERSIONS_H_
+
++#include <uchar.h>
++
+ #include <cstdint>
+ #include <string>
+
+ // Conversion routines between UT8 and UTF16, used by string-16.{h,cc}. You may
+ // want to use string-16.h directly rather than these.
+ namespace v8_inspector {
+-std::basic_string<uint16_t> UTF8ToUTF16(const char* stringStart, size_t length);
+-std::string UTF16ToUTF8(const uint16_t* stringStart, size_t length);
++std::basic_string<char16_t> UTF8ToUTF16(const char* stringStart, size_t length);
++std::string UTF16ToUTF8(const char16_t* stringStart, size_t length);
+ } // namespace v8_inspector
+
+ #endif // V8_INSPECTOR_V8_STRING_CONVERSIONS_H_
+--- a/deps/v8/third_party/inspector_protocol/crdtp/test_platform_v8.cc
++++ b/deps/v8/third_party/inspector_protocol/crdtp/test_platform_v8.cc
+@@ -11,13 +11,16 @@
+ namespace v8_crdtp {
+
+ std::string UTF16ToUTF8(span<uint16_t> in) {
+- return v8_inspector::UTF16ToUTF8(in.data(), in.size());
++ return v8_inspector::UTF16ToUTF8(reinterpret_cast<const char16_t*>(in.data()),
++ in.size());
+ }
+
+ std::vector<uint16_t> UTF8ToUTF16(span<uint8_t> in) {
+- std::basic_string<uint16_t> utf16 = v8_inspector::UTF8ToUTF16(
++ std::basic_string<char16_t> utf16 = v8_inspector::UTF8ToUTF16(
+ reinterpret_cast<const char*>(in.data()), in.size());
+- return std::vector<uint16_t>(utf16.begin(), utf16.end());
++ return std::vector<uint16_t>(
++ reinterpret_cast<const uint16_t*>(utf16.data()),
++ reinterpret_cast<const uint16_t*>(utf16.data()) + utf16.size());
+ }
+
+ } // namespace v8_crdtp
diff --git a/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/libatomic.patch b/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/libatomic.patch
index cb0237309e..22dc6c151f 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/libatomic.patch
+++ b/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/libatomic.patch
@@ -1,21 +1,76 @@
-Link mksnapshot with libatomic on x86
+From 15e751e4b79475fb34e4b32a3ca54119b20c564a Mon Sep 17 00:00:00 2001
+From: Hongxu Jia <hongxu.jia@windriver.com>
+Date: Sat, 17 Aug 2024 21:33:18 +0800
+Subject: [PATCH] link libatomic for clang conditionally
-Clang-12 on x86 emits atomic builtins
+Clang emits atomic builtin, explicitly link libatomic conditionally:
+- For target build, always link -latomic for clang as usual
+- For host build, if host and target have same bit width, cross compiling
+ is enabled, and host toolchain is gcc which does not link -latomic;
+ if host and target have different bit width, no cross compiling,
+ host build is the same with target build that requires to link
+ -latomic;
-Fixes
-| module-compiler.cc:(.text._ZN2v88internal4wasm12_GLOBAL__N_123ExecuteCompilationUnitsERKSt10shared_ptrINS2_22BackgroundCompileTokenEEPNS0_8CountersEiNS2_19CompileBaselineOnlyE+0x558): un
-defined reference to `__atomic_load'
+Fix:
+|tmp-glibc/work/core2-64-wrs-linux/nodejs/20.13.0/node-v20.13.0/out/Release/node_js2c: error while loading shared libraries: libatomic.so.1: cannot open shared object file: No such file or directory
-Upstream-Status: Pending
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
+Upstream-Status: Inappropriate [OE specific]
+Signed-off-by: Hongxu Jia <hongxu.jia@windriver.com>
+---
+ node.gyp | 13 ++++++++++++-
+ tools/v8_gypfiles/v8.gyp | 15 ++++++++++++---
+ 2 files changed, 24 insertions(+), 4 deletions(-)
+
+diff --git a/node.gyp b/node.gyp
+index b425f443..f296f35c 100644
+--- a/node.gyp
++++ b/node.gyp
+@@ -487,7 +487,18 @@
+ ],
+ }],
+ ['OS=="linux" and clang==1', {
+- 'libraries': ['-latomic'],
++ 'target_conditions': [
++ ['_toolset=="host"', {
++ 'conditions': [
++ ['"<!(echo $HOST_AND_TARGET_SAME_WIDTH)"=="0"', {
++ 'libraries': ['-latomic'],
++ }],
++ ],
++ }],
++ ['_toolset=="target"', {
++ 'libraries': ['-latomic'],
++ }],
++ ],
+ }],
+ ],
+ },
+diff --git a/tools/v8_gypfiles/v8.gyp b/tools/v8_gypfiles/v8.gyp
+index b23263cf..dcabf4ca 100644
--- a/tools/v8_gypfiles/v8.gyp
+++ b/tools/v8_gypfiles/v8.gyp
-@@ -1436,6 +1436,7 @@
- {
- 'target_name': 'mksnapshot',
- 'type': 'executable',
-+ 'libraries': [ '-latomic' ],
- 'dependencies': [
- 'v8_base_without_compiler',
- 'v8_compiler_for_mksnapshot',
+@@ -1100,9 +1100,18 @@
+ # Platforms that don't have Compare-And-Swap (CAS) support need to link atomic library
+ # to implement atomic memory access
+ ['v8_current_cpu in ["mips64", "mips64el", "ppc", "arm", "riscv64", "loong64"]', {
+- 'link_settings': {
+- 'libraries': ['-latomic', ],
+- },
++ 'target_conditions': [
++ ['_toolset=="host"', {
++ 'conditions': [
++ ['"<!(echo $HOST_AND_TARGET_SAME_WIDTH)"=="0"', {
++ 'libraries': ['-latomic'],
++ }],
++ ],
++ }],
++ ['_toolset=="target"', {
++ 'libraries': ['-latomic', ],
++ }],
++ ],
+ }],
+ ],
+ }, # v8_base_without_compiler
+--
+2.35.5
diff --git a/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/zlib-fix-pointer-alignment.patch b/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/zlib-fix-pointer-alignment.patch
new file mode 100644
index 0000000000..824ff678c6
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs/zlib-fix-pointer-alignment.patch
@@ -0,0 +1,64 @@
+From bbcd1f33161fd9874e8a61999d2739b177f99723 Mon Sep 17 00:00:00 2001
+From: Jeroen Hofstee <jhofstee@victronenergy.com>
+Date: Mon, 28 Apr 2025 14:21:44 +0000
+Subject: [PATCH] zlib: fix pointer alignment
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+The function AllocForBrotli prefixes the allocated memory with its
+size, and returns a pointer to the region after it. This pointer can
+however no longer be suitably aligned. Correct this by allocating
+the maximum of the the size of the size_t and the max alignment.
+
+On Arm 32bits the size_t is 4 bytes long, but the alignment is 8 for
+some NEON instructions. When Brotli is compiled with optimizations
+enabled newer GCC versions will use the NEON instructions and trigger
+a bus error killing node.
+
+see https://github.com/google/brotli/issues/1159
+
+PR-URL: https://github.com/nodejs/node/pull/57727
+Reviewed-By: Shelley Vohr <shelley.vohr@gmail.com>
+Reviewed-By: Tobias Nießen <tniessen@tnie.de>
+Reviewed-By: Daniel Lemire <daniel@lemire.me>
+Reviewed-By: Gerhard Stöbich <deb2001-github@yahoo.de>
+
+Upstream-Status: Backport [https://github.com/nodejs/node/commit/dc035bbc9b310ff8067bc0dad22230978489c061]
+---
+ src/node_zlib.cc | 8 +++++---
+ 1 file changed, 5 insertions(+), 3 deletions(-)
+
+diff --git a/src/node_zlib.cc b/src/node_zlib.cc
+index 66370e41..a537e766 100644
+--- a/src/node_zlib.cc
++++ b/src/node_zlib.cc
+@@ -493,20 +493,22 @@ class CompressionStream : public AsyncWrap, public ThreadPoolWork {
+ }
+
+ static void* AllocForBrotli(void* data, size_t size) {
+- size += sizeof(size_t);
++ constexpr size_t offset = std::max(sizeof(size_t), alignof(max_align_t));
++ size += offset;
+ CompressionStream* ctx = static_cast<CompressionStream*>(data);
+ char* memory = UncheckedMalloc(size);
+ if (UNLIKELY(memory == nullptr)) return nullptr;
+ *reinterpret_cast<size_t*>(memory) = size;
+ ctx->unreported_allocations_.fetch_add(size,
+ std::memory_order_relaxed);
+- return memory + sizeof(size_t);
++ return memory + offset;
+ }
+
+ static void FreeForZlib(void* data, void* pointer) {
+ if (UNLIKELY(pointer == nullptr)) return;
+ CompressionStream* ctx = static_cast<CompressionStream*>(data);
+- char* real_pointer = static_cast<char*>(pointer) - sizeof(size_t);
++ constexpr size_t offset = std::max(sizeof(size_t), alignof(max_align_t));
++ char* real_pointer = static_cast<char*>(pointer) - offset;
+ size_t real_size = *reinterpret_cast<size_t*>(real_pointer);
+ ctx->unreported_allocations_.fetch_sub(real_size,
+ std::memory_order_relaxed);
+--
+2.43.0
+
diff --git a/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs_20.12.2.bb b/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs_20.18.2.bb
index d86c38f2fc..d757a7395c 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs_20.12.2.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/nodejs/nodejs_20.18.2.bb
@@ -1,15 +1,15 @@
DESCRIPTION = "nodeJS Evented I/O for V8 JavaScript"
HOMEPAGE = "http://nodejs.org"
LICENSE = "MIT & ISC & BSD-2-Clause & BSD-3-Clause & Artistic-2.0 & Apache-2.0"
-LIC_FILES_CHKSUM = "file://LICENSE;md5=9a7fcce64128730251dbc58aa41b4674"
+LIC_FILES_CHKSUM = "file://LICENSE;md5=c83fcdcd43ab352be6429ee1fd8827a0"
CVE_PRODUCT = "nodejs node.js"
-DEPENDS = "openssl file-replacement-native python3-packaging-native"
+DEPENDS = "openssl openssl-native file-replacement-native python3-packaging-native"
DEPENDS:append:class-target = " qemu-native"
DEPENDS:append:class-native = " c-ares-native"
-inherit pkgconfig python3native qemu ptest
+inherit pkgconfig python3native qemu ptest siteinfo
COMPATIBLE_MACHINE:armv4 = "(!.*armv4).*"
COMPATIBLE_MACHINE:armv5 = "(!.*armv5).*"
@@ -24,23 +24,24 @@ SRC_URI = "http://nodejs.org/dist/v${PV}/node-v${PV}.tar.xz \
file://0004-v8-don-t-override-ARM-CFLAGS.patch \
file://system-c-ares.patch \
file://0001-liftoff-Correct-function-signatures.patch \
+ file://libatomic.patch \
+ file://182d9c05e78.patch \
+ file://zlib-fix-pointer-alignment.patch \
+ file://0001-src-fix-build-with-GCC-15.patch \
file://run-ptest \
"
-
SRC_URI:append:class-target = " \
file://0001-Using-native-binaries.patch \
"
-SRC_URI:append:toolchain-clang:x86 = " \
- file://libatomic.patch \
- "
SRC_URI:append:toolchain-clang:powerpc64le = " \
file://0001-ppc64-Do-not-use-mminimal-toc-with-clang.patch \
"
-SRC_URI[sha256sum] = "d7cbcc5fbfb31e9001f3f0150bbeda59abe5dd7137aaa6273958cd59ce35ced7"
+SRC_URI[sha256sum] = "69bf81b70f3a95ae0763459f02860c282d7e3a47567c8afaf126cc778176a882"
S = "${WORKDIR}/node-v${PV}"
CVE_PRODUCT += "node.js"
+CVE_STATUS[CVE-2024-3566] = "not-applicable-platform: Issue only applies on Windows"
# v8 errors out if you have set CCACHE
CCACHE = ""
@@ -66,28 +67,14 @@ ARCHFLAGS ?= ""
PACKAGECONFIG ??= "ares brotli icu zlib"
-PACKAGECONFIG[ares] = "--shared-cares,,c-ares"
-PACKAGECONFIG[brotli] = "--shared-brotli,,brotli"
-PACKAGECONFIG[icu] = "--with-intl=system-icu,--without-intl,icu"
+PACKAGECONFIG[ares] = "--shared-cares,,c-ares c-ares-native"
+PACKAGECONFIG[brotli] = "--shared-brotli,,brotli brotli-native"
+PACKAGECONFIG[icu] = "--with-intl=system-icu,--without-intl,icu icu-native"
PACKAGECONFIG[libuv] = "--shared-libuv,,libuv"
PACKAGECONFIG[nghttp2] = "--shared-nghttp2,,nghttp2"
PACKAGECONFIG[shared] = "--shared"
PACKAGECONFIG[zlib] = "--shared-zlib,,zlib"
-# We don't want to cross-compile during target compile,
-# and we need to use the right flags during host compile,
-# too.
-EXTRA_OEMAKE = "\
- CC.host='${CC} -pie -fPIE' \
- CFLAGS.host='${CPPFLAGS} ${CFLAGS}' \
- CXX.host='${CXX} -pie -fPIE' \
- CXXFLAGS.host='${CPPFLAGS} ${CXXFLAGS}' \
- LDFLAGS.host='${LDFLAGS}' \
- AR.host='${AR}' \
- \
- builddir_name=./ \
-"
-
EXTRANATIVEPATH += "file-native"
python prune_sources() {
@@ -110,9 +97,11 @@ do_unpack[postfuncs] += "prune_sources"
# V8's JIT infrastructure requires binaries such as mksnapshot and
# mkpeephole to be run in the host during the build. However, these
# binaries must have the same bit-width as the target (e.g. a x86_64
-# host targeting ARMv6 needs to produce a 32-bit binary). Instead of
-# depending on a third Yocto toolchain, we just build those binaries
-# for the target and run them on the host with QEMU.
+# host targeting ARMv6 needs to produce a 32-bit binary).
+# 1. If host and target have the different bit width, run those
+# binaries for the target and run them on the host with QEMU.
+# 2. If host and target have the same bit width, enable upstream
+# cross crompile support and no QEMU
python do_create_v8_qemu_wrapper () {
"""Creates a small wrapper that invokes QEMU to run some target V8 binaries
on the host."""
@@ -120,6 +109,10 @@ python do_create_v8_qemu_wrapper () {
d.expand('${STAGING_DIR_HOST}${base_libdir}')]
qemu_cmd = qemu_wrapper_cmdline(d, d.getVar('STAGING_DIR_HOST'),
qemu_libdirs)
+
+ if d.getVar("HOST_AND_TARGET_SAME_WIDTH") == "1":
+ qemu_cmd = ""
+
wrapper_path = d.expand('${B}/v8-qemu-wrapper.sh')
with open(wrapper_path, 'w') as wrapper_file:
wrapper_file.write("""#!/bin/sh
@@ -138,6 +131,14 @@ addtask create_v8_qemu_wrapper after do_configure before do_compile
LDFLAGS:append:x86 = " -latomic"
+export CC_host
+export CFLAGS_host
+export CXX_host
+export CXXFLAGS_host
+export LDFLAGS_host
+export AR_host
+export HOST_AND_TARGET_SAME_WIDTH
+
CROSS_FLAGS = "--cross-compiling"
CROSS_FLAGS:class-native = "--no-cross-compiling"
@@ -179,4 +180,35 @@ RDEPENDS:${PN}-npm = "bash python3-core python3-shell python3-datetime \
PACKAGES =+ "${PN}-systemtap"
FILES:${PN}-systemtap = "${datadir}/systemtap"
+do_configure[prefuncs] += "set_gyp_variables"
+do_compile[prefuncs] += "set_gyp_variables"
+do_install[prefuncs] += "set_gyp_variables"
+python set_gyp_variables () {
+ if d.getVar("HOST_AND_TARGET_SAME_WIDTH") == "0":
+ # We don't want to cross-compile during target compile,
+ # and we need to use the right flags during host compile,
+ # too.
+ d.setVar("CC_host", d.getVar("CC") + " -pie -fPIE")
+ d.setVar("CFLAGS_host", d.getVar("CFLAGS"))
+ d.setVar("CXX_host", d.getVar("CXX") + " -pie -fPIE")
+ d.setVar("CXXFLAGS_host", d.getVar("CXXFLAGS"))
+ d.setVar("LDFLAGS_host", d.getVar("LDFLAGS"))
+ d.setVar("AR_host", d.getVar("AR"))
+ elif d.getVar("HOST_AND_TARGET_SAME_WIDTH") == "1":
+ # Enable upstream cross crompile support
+ d.setVar("CC_host", d.getVar("BUILD_CC"))
+ d.setVar("CFLAGS_host", d.getVar("BUILD_CFLAGS"))
+ d.setVar("CXX_host", d.getVar("BUILD_CXX"))
+ d.setVar("CXXFLAGS_host", d.getVar("BUILD_CXXFLAGS"))
+ d.setVar("LDFLAGS_host", d.getVar("BUILD_LDFLAGS"))
+ d.setVar("AR_host", d.getVar("BUILD_AR"))
+}
+python __anonymous () {
+ # 32 bit target and 64 bit host (x86-64 or aarch64) have different bit width
+ if d.getVar("SITEINFO_BITS") == "32" and "64" in d.getVar("BUILD_ARCH"):
+ d.setVar("HOST_AND_TARGET_SAME_WIDTH", "0")
+ else:
+ d.setVar("HOST_AND_TARGET_SAME_WIDTH", "1")
+}
+
BBCLASSEXTEND = "native"
diff --git a/meta-openembedded/meta-oe/recipes-devtools/perfetto/perfetto.bb b/meta-openembedded/meta-oe/recipes-devtools/perfetto/perfetto.bb
index 7e9408b0b2..884e0a024b 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/perfetto/perfetto.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/perfetto/perfetto.bb
@@ -96,8 +96,8 @@ do_configure () {
ARGS=$ARGS" target_os=\"linux\""
ARGS=$ARGS" target_cpu=\"$arch\""
- ARGS=$ARGS" target_cc=\"$CC_BIN ${TUNE_CCARGS}\""
- ARGS=$ARGS" target_cxx=\"$CXX_BIN -std=c++11 ${TUNE_CCARGS}\""
+ ARGS=$ARGS" target_cc=\"$CC_BIN ${TUNE_CCARGS} ${DEBUG_PREFIX_MAP}\""
+ ARGS=$ARGS" target_cxx=\"$CXX_BIN -std=c++11 ${TUNE_CCARGS} ${DEBUG_PREFIX_MAP}\""
ARGS=$ARGS" target_strip=\"$STRIP_BIN\"" #
ARGS=$ARGS" target_sysroot=\"${RECIPE_SYSROOT}\""
ARGS=$ARGS" target_linker=\"$CC_BIN ${TUNE_CCARGS} ${LDFLAGS}\""
diff --git a/meta-openembedded/meta-oe/recipes-devtools/perl/libdbd-mysql-perl/0001-Makefile.PL-avoid-running-assert_lib-at-configure.patch b/meta-openembedded/meta-oe/recipes-devtools/perl/libdbd-mysql-perl/0001-Makefile.PL-avoid-running-assert_lib-at-configure.patch
new file mode 100644
index 0000000000..2e010931d6
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/perl/libdbd-mysql-perl/0001-Makefile.PL-avoid-running-assert_lib-at-configure.patch
@@ -0,0 +1,40 @@
+From 577cdd6a571cfed506ec902b9021e60a2b854e4a Mon Sep 17 00:00:00 2001
+From: Chen Qi <Qi.Chen@windriver.com>
+Date: Sun, 7 Jul 2024 22:32:30 -0700
+Subject: [PATCH] Makefile.PL: avoid running assert_lib at configure
+
+The assert_lib will run the generated binary. When cross compiling,
+e.g., for qemuarm64, we'll see error like below:
+
+ /usr/lib64/ld-linux-aarch64.so.1: No such file or directory
+
+We should just skip library checking, because in OE, if these libs are
+not available, the do_compile process will fail anyway.
+
+Upstream-Status: Inappropriate [OE Specific]
+
+Signed-off-by: Chen Qi <Qi.Chen@windriver.com>
+---
+ Makefile.PL | 6 +-----
+ 1 file changed, 1 insertion(+), 5 deletions(-)
+
+diff --git a/Makefile.PL b/Makefile.PL
+index a1b38f6..939cadc 100644
+--- a/Makefile.PL
++++ b/Makefile.PL
+@@ -206,11 +206,7 @@ To change these settings, see 'perl Makefile.PL --help' and
+ MSG
+
+ print "Checking if libs are available for compiling...\n";
+-
+-assert_lib(
+- LIBS => ($opt->{'embedded'} ? $opt->{'embedded'} : $opt->{libs}),
+-);
+-
++print "Skip checking libs at configure stage as we are cross compiling.\n";
+ print "Looks good.\n\n";
+
+ sleep 1;
+--
+2.25.1
+
diff --git a/meta-openembedded/meta-oe/recipes-devtools/perl/libdbd-mysql-perl_4.050.bb b/meta-openembedded/meta-oe/recipes-devtools/perl/libdbd-mysql-perl_4.050.bb
index fc505fe1e8..99a9fcf628 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/perl/libdbd-mysql-perl_4.050.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/perl/libdbd-mysql-perl_4.050.bb
@@ -15,7 +15,9 @@ DEPENDS += "libdev-checklib-perl-native libdbi-perl-native libmysqlclient"
LIC_FILES_CHKSUM = "file://LICENSE;md5=d0a06964340e5c0cde88b7af611f755c"
SRCREV = "9b5b70ea372f49fe9bc9e592dae3870596d1e3d6"
-SRC_URI = "git://github.com/perl5-dbi/DBD-mysql.git;protocol=https;branch=master"
+SRC_URI = "git://github.com/perl5-dbi/DBD-mysql.git;protocol=https;branch=master \
+ file://0001-Makefile.PL-avoid-running-assert_lib-at-configure.patch \
+ "
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-oe/recipes-devtools/perl/libdev-checklib-perl_1.16.bb b/meta-openembedded/meta-oe/recipes-devtools/perl/libdev-checklib-perl_1.16.bb
index 74a09e7bf8..bda1771ca7 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/perl/libdev-checklib-perl_1.16.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/perl/libdev-checklib-perl_1.16.bb
@@ -8,7 +8,7 @@ LICENSE = "Artistic-1.0 | GPL-1.0-or-later"
LIC_FILES_CHKSUM = "file://README;md5=7911cdbb572d25c5f2e2ea17f669efc2"
-SRC_URI = "https://cpan.metacpan.org/modules/by-module/Devel/Devel-CheckLib-${PV}.tar.gz \
+SRC_URI = "https://cpan.metacpan.org/authors/id/M/MA/MATTN/Devel-CheckLib-${PV}.tar.gz \
file://0001-CheckLib.pm-don-t-execute-the-binary.patch \
"
SRC_URI[sha256sum] = "869d38c258e646dcef676609f0dd7ca90f085f56cf6fd7001b019a5d5b831fca"
diff --git a/meta-openembedded/meta-oe/recipes-devtools/php/php/0001-ext-opcache-config.m4-enable-opcache.patch b/meta-openembedded/meta-oe/recipes-devtools/php/php/0001-ext-opcache-config.m4-enable-opcache.patch
index c743697469..496213540b 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/php/php/0001-ext-opcache-config.m4-enable-opcache.patch
+++ b/meta-openembedded/meta-oe/recipes-devtools/php/php/0001-ext-opcache-config.m4-enable-opcache.patch
@@ -1,6 +1,6 @@
-From 889583912ddd7abc628f2703892ec4884db6419a Mon Sep 17 00:00:00 2001
-From: Soumya Sambu <soumya.sambu@windriver.com>
-Date: Tue, 7 May 2024 08:39:16 +0000
+From aa99f9db92817358d6b91040cc555f5ca31b727c Mon Sep 17 00:00:00 2001
+From: Yogita Urade <yogita.urade@windriver.com>
+Date: Mon, 25 Nov 2024 07:07:38 +0000
Subject: [PATCH 01/11] ext/opcache/config.m4: enable opcache
We can't use AC_TRY_RUN to run programs in a cross compile
@@ -23,12 +23,15 @@ Signed-off-by: Mingli Yu <mingli.yu@windriver.com>
update patch to version 8.2.18
Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
+
+update patch to version 8.2.24
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
---
ext/opcache/config.m4 | 204 ++----------------------------------------
1 file changed, 8 insertions(+), 196 deletions(-)
diff --git a/ext/opcache/config.m4 b/ext/opcache/config.m4
-index 6bf07ad3..5d645b86 100644
+index b3929382..ba1a9aff 100644
--- a/ext/opcache/config.m4
+++ b/ext/opcache/config.m4
@@ -113,209 +113,21 @@ if test "$PHP_OPCACHE" != "no"; then
@@ -247,8 +250,8 @@ index 6bf07ad3..5d645b86 100644
+ have_shm_mmap_posix=yes
+ PHP_CHECK_LIBRARY(rt, shm_unlink, [PHP_ADD_LIBRARY(rt,1,OPCACHE_SHARED_LIBADD)])
- PHP_NEW_EXTENSION(opcache,
- ZendAccelerator.c \
+ AX_CHECK_COMPILE_FLAG([-Wno-implicit-fallthrough],
+ [PHP_OPCACHE_CFLAGS="$PHP_OPCACHE_CFLAGS -Wno-implicit-fallthrough"],,
--
2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-devtools/php/php_8.2.20.bb b/meta-openembedded/meta-oe/recipes-devtools/php/php_8.2.29.bb
index f807f67a23..08cece1c17 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/php/php_8.2.20.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/php/php_8.2.29.bb
@@ -34,7 +34,7 @@ SRC_URI:append:class-target = " \
"
S = "${WORKDIR}/php-${PV}"
-SRC_URI[sha256sum] = "5dec6fa61c7b9c47aa1d76666be651f2642ed2bcf6cd8638c57e3571ce2aac61"
+SRC_URI[sha256sum] = "51979e8d198cbade2aad4ffe9f53dd3f04f9602d3089e5979985e058ade4267c"
CVE_STATUS_GROUPS += "CVE_STATUS_PHP"
CVE_STATUS_PHP[status] = "fixed-version: The name of this product is exactly the same as github.com/emlog/emlog. CVE can be safely ignored."
@@ -43,6 +43,7 @@ CVE_STATUS_PHP = " \
CVE-2007-3205 \
CVE-2007-4596 \
"
+CVE_STATUS[CVE-2024-3566] = "not-applicable-platform: Issue only applies on Windows"
inherit autotools pkgconfig python3native gettext multilib_header multilib_script systemd
diff --git a/meta-openembedded/meta-oe/recipes-devtools/protobuf/protobuf_4.25.3.bb b/meta-openembedded/meta-oe/recipes-devtools/protobuf/protobuf_4.25.8.bb
index 3241345963..e54dffd2cd 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/protobuf/protobuf_4.25.3.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/protobuf/protobuf_4.25.8.bb
@@ -10,7 +10,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=37b5762e07f0af8c74ce80a8bda4266b"
DEPENDS = "zlib abseil-cpp"
DEPENDS:append:class-target = " protobuf-native"
-SRCREV = "4a2aef570deb2bfb8927426558701e8bfc26f2a4"
+SRCREV = "a4cbdd3ed0042e8f9b9c30e8b0634096d9532809"
SRC_URI = "gitsm://github.com/protocolbuffers/protobuf.git;branch=25.x;protocol=https \
file://run-ptest \
@@ -21,6 +21,8 @@ SRC_URI:append:mipsel:toolchain-clang = " file://0001-Fix-build-on-mips-clang.pa
S = "${WORKDIR}/git"
+CVE_STATUS[CVE-2024-7254] = "fixed-version: The vulnerability has been addressed and the fix is included in version v4.25.8"
+
inherit cmake pkgconfig ptest
PACKAGECONFIG ??= ""
diff --git a/meta-openembedded/meta-oe/recipes-devtools/sip/sip_6.8.3.bb b/meta-openembedded/meta-oe/recipes-devtools/sip/sip_6.8.6.bb
index d12130af43..1defe29b08 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/sip/sip_6.8.3.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/sip/sip_6.8.6.bb
@@ -3,15 +3,17 @@
SUMMARY = "A Python bindings generator for C/C++ libraries"
-HOMEPAGE = "https://www.riverbankcomputing.com/software/sip/"
-LICENSE = "GPL-2.0-or-later"
+HOMEPAGE = "https://github.com/Python-SIP/sip"
+LICENSE = "BSD-2-Clause"
SECTION = "devel"
-LIC_FILES_CHKSUM = "file://LICENSE-GPL2;md5=e91355d8a6f8bd8f7c699d62863c7303"
+LIC_FILES_CHKSUM = "file://LICENSE;md5=ed1d69a33480ebf4ff8a7a760826d84e"
-inherit pypi setuptools3 python3native
+inherit pypi python_setuptools_build_meta python3native
PYPI_PACKAGE = "sip"
-SRC_URI[sha256sum] = "888547b018bb24c36aded519e93d3e513d4c6aa0ba55b7cc1affbd45cf10762c"
+SRC_URI[sha256sum] = "7fc959e48e6ec5d5af8bd026f69f5e24d08b3cb8abb342176f5ab8030cc07d7a"
+
+DEPENDS += "python3-setuptools-scm-native"
RDEPENDS:${PN} = " \
python3-core \
diff --git a/meta-openembedded/meta-oe/recipes-devtools/xerces-c/xerces-c/0001-aclocal.m4-don-t-use-full-path-of-with_curl-in-xerce.patch b/meta-openembedded/meta-oe/recipes-devtools/xerces-c/xerces-c/0001-aclocal.m4-don-t-use-full-path-of-with_curl-in-xerce.patch
new file mode 100644
index 0000000000..2ad7beb51c
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/xerces-c/xerces-c/0001-aclocal.m4-don-t-use-full-path-of-with_curl-in-xerce.patch
@@ -0,0 +1,58 @@
+From d001f12d428f7adaeaadee5263a22c797c99d67b Mon Sep 17 00:00:00 2001
+From: Martin Jansa <martin.jansa@gmail.com>
+Date: Fri, 30 Aug 2024 11:42:27 +0200
+Subject: [PATCH] aclocal.m4: don't use full path of $with_curl in xerces-c.pc
+
+* fixes:
+ ERROR: QA Issue: File /usr/lib32/pkgconfig/xerces-c.pc in package lib32-libxerces-c-dev contains reference to TMPDIR [buildpaths]
+
+* xerces-c was blacklisted due to tmpdir since 2016:
+ https://git.openembedded.org/meta-openembedded/commit/?id=1af196e42c811947bb483df30bfce758adee83d1
+
+* then sed call:
+ sed -i -e 's:-L${STAGING_DIR}/lib:-L\$\{libdir\}:g' ${B}/xerces-c.pc
+ was added to do_install:append and blacklist dropped in:
+ https://git.openembedded.org/meta-openembedded/commit/?id=87b9efff79e62f569525e4760adc594d0d9ac476
+
+* sed call was adjusted in:
+ https://git.openembedded.org/meta-openembedded/commit/?id=87c9e9537dc43468a6aaf706853b784ce6de14e0
+ sed -i s:-L${STAGING_LIBDIR}::g ${B}/xerces-c.pc
+
+* but it was still failing in some cases, e.g. with multilib where libdir is /usr/lib64, so the sed call is:
+ sed -i s:-L{WORKDIR}/recipe-sysroot/usr/lib64::g ${WORKDIR}/build/xerces-c.pc
+ but the actual xerces-c.pc file still has:
+
+ Libs: -L${libdir} -lxerces-c
+ Libs.private: -L${WORKDIR}/recipe-sysroot/usr/lib -lcurl
+
+ because this aclocal was always hardcoding "lib" (appended to --with-curl
+ value which is passed together with ${prefix}) and not respecting the libdir value:
+ PACKAGECONFIG[curl] = "--with-curl=${STAGING_DIR_TARGET}${prefix},--with-curl=no,curl"
+ PACKAGECONFIG[icu] = "--with-icu=${STAGING_DIR_TARGET}${prefix},--with-icu=no,icu"
+
+* xerces-c supports CMake since 2017:
+ https://github.com/apache/xerces-c/commit/2606b2924c3e2bf0cf50f72b79378721b6bcf04e
+ switching from autotools to CMake would probably resolve some of this as well
+
+Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
+---
+Upstream-Status: Pending [It would be better to just switch to CMake]
+
+ m4/xerces_curl_prefix.m4 | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/m4/xerces_curl_prefix.m4 b/m4/xerces_curl_prefix.m4
+index d1d015c..7928bdc 100644
+--- a/m4/xerces_curl_prefix.m4
++++ b/m4/xerces_curl_prefix.m4
+@@ -39,8 +39,8 @@ AC_DEFUN([XERCES_CURL_PREFIX],
+ curl_libs=`$curl_config --libs`
+ else
+ if test -n "$with_curl"; then
+- curl_flags="-I$with_curl/include"
+- curl_libs="-L$with_curl/lib -lcurl"
++ curl_flags=""
++ curl_libs="-lcurl"
+ else
+ # Default compiler paths.
+ #
diff --git a/meta-openembedded/meta-oe/recipes-devtools/xerces-c/xerces-c_3.2.5.bb b/meta-openembedded/meta-oe/recipes-devtools/xerces-c/xerces-c_3.2.5.bb
index 1643af2546..9fd7e8fbab 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/xerces-c/xerces-c_3.2.5.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/xerces-c/xerces-c_3.2.5.bb
@@ -9,7 +9,9 @@ SECTION = "libs"
LICENSE = "Apache-2.0"
LIC_FILES_CHKSUM = "file://LICENSE;md5=3b83ef96387f14655fc854ddc3c6bd57"
-SRC_URI = "http://archive.apache.org/dist/xerces/c/3/sources/${BP}.tar.bz2"
+SRC_URI = "http://archive.apache.org/dist/xerces/c/3/sources/${BP}.tar.bz2 \
+ file://0001-aclocal.m4-don-t-use-full-path-of-with_curl-in-xerce.patch \
+"
SRC_URI[sha256sum] = "1db4028c9b7f1f778efbf4a9462d65e13f9938f2c22f9e9994e12c49ba97e252"
inherit autotools
@@ -18,10 +20,6 @@ PACKAGECONFIG ??= "curl icu"
PACKAGECONFIG[curl] = "--with-curl=${STAGING_DIR_TARGET}${prefix},--with-curl=no,curl"
PACKAGECONFIG[icu] = "--with-icu=${STAGING_DIR_TARGET}${prefix},--with-icu=no,icu"
-do_install:prepend () {
- sed -i s:-L${STAGING_LIBDIR}::g ${B}/xerces-c.pc
-}
-
PACKAGES = "libxerces-c \
libxerces-c-dev \
xerces-c-samples \
diff --git a/meta-openembedded/meta-oe/recipes-devtools/xmlrpc-c/xmlrpc-c_1.59.01.bb b/meta-openembedded/meta-oe/recipes-devtools/xmlrpc-c/xmlrpc-c_1.59.01.bb
index 5d5152b834..b667507ef9 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/xmlrpc-c/xmlrpc-c_1.59.01.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/xmlrpc-c/xmlrpc-c_1.59.01.bb
@@ -10,7 +10,7 @@ SRC_URI = "git://github.com/mirror/xmlrpc-c.git;branch=master;protocol=https \
file://0002-fix-formatting-issues.patch \
"
#Release 1.59.01
-SRCREV = "352aeaa9ae49e90e55187cbda839f2113df06278"
+SRCREV = "08b052692b70171a6fcb437d4f52a46977eda62e"
S = "${WORKDIR}/git/stable"
diff --git a/meta-openembedded/meta-oe/recipes-devtools/yasm/yasm/CVE-2024-22653.patch b/meta-openembedded/meta-oe/recipes-devtools/yasm/yasm/CVE-2024-22653.patch
new file mode 100644
index 0000000000..dbbd4b94ef
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-devtools/yasm/yasm/CVE-2024-22653.patch
@@ -0,0 +1,32 @@
+From 121ab150b3577b666c79a79f4a511798d7ad2432 Mon Sep 17 00:00:00 2001
+From: haruki3hhh <135201297+haruki3hhh@users.noreply.github.com>
+Date: Mon, 24 Jun 2024 18:08:27 -0500
+Subject: [PATCH] Fix null pointer dereference in yasm_section_bcs_append
+ (#263)
+
+CVE: CVE-2024-22653
+
+Upstream-Status: Backport [https://github.com/yasm/yasm/commit/121ab150b3577b666c79a79f4a511798d7ad2432]
+
+Signed-off-by: Praveen Kumar <praveen.kumar@windriver.com>
+---
+ libyasm/section.c | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/libyasm/section.c b/libyasm/section.c
+index ba582bfa..1c1ba710 100644
+--- a/libyasm/section.c
++++ b/libyasm/section.c
+@@ -611,6 +611,10 @@ yasm_bytecode *
+ yasm_section_bcs_append(yasm_section *sect, yasm_bytecode *bc)
+ {
+ if (bc) {
++ if (!sect) {
++ yasm_error_set(YASM_ERROR_VALUE, "Attempt to append bytecode to a NULL section or with a NULL bytecode");
++ return NULL;
++ }
+ if (bc->callback) {
+ bc->section = sect; /* record parent section */
+ STAILQ_INSERT_TAIL(&sect->bcs, bc, link);
+--
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-devtools/yasm/yasm_git.bb b/meta-openembedded/meta-oe/recipes-devtools/yasm/yasm_git.bb
index 216b777667..99717d3a32 100644
--- a/meta-openembedded/meta-oe/recipes-devtools/yasm/yasm_git.bb
+++ b/meta-openembedded/meta-oe/recipes-devtools/yasm/yasm_git.bb
@@ -16,6 +16,7 @@ SRC_URI = "git://github.com/yasm/yasm.git;branch=master;protocol=https \
file://CVE-2023-37732.patch \
file://0001-yasm-Set-build-date-to-SOURCE_DATE_EPOCH.patch \
file://0002-yasm-Use-BUILD_DATE-for-reproducibility.patch \
+ file://CVE-2024-22653.patch \
"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-oe/recipes-extended/boinc/boinc-client_7.20.5.bb b/meta-openembedded/meta-oe/recipes-extended/boinc/boinc-client_7.20.5.bb
index 4e35283dd2..cfd134dd4f 100644
--- a/meta-openembedded/meta-oe/recipes-extended/boinc/boinc-client_7.20.5.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/boinc/boinc-client_7.20.5.bb
@@ -77,6 +77,10 @@ do_install:prepend() {
mkdir -p ${D}${sysconfdir}/default
}
+do_install:append() {
+ sed -i -e 's#${S}##g' ${D}${includedir}/boinc/svn_version.h
+}
+
SYSTEMD_SERVICE:${PN} = "boinc-client.service"
FILES:${PN} += "${libdir}/systemd"
diff --git a/meta-openembedded/meta-oe/recipes-extended/collectd/collectd_5.12.0.bb b/meta-openembedded/meta-oe/recipes-extended/collectd/collectd_5.12.0.bb
index 02f1fcb420..b826934aa2 100644
--- a/meta-openembedded/meta-oe/recipes-extended/collectd/collectd_5.12.0.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/collectd/collectd_5.12.0.bb
@@ -6,7 +6,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=1bd21f19f7f0c61a7be8ecacb0e28854"
DEPENDS = "curl libpcap libxml2 yajl libgcrypt libtool lvm2"
-SRC_URI = "https://collectd.org/files/collectd-${PV}.tar.bz2 \
+SRC_URI = "${GITHUB_BASE_URI}download/${BP}/${BP}.tar.bz2 \
file://collectd.init \
file://collectd.service \
file://no-gcrypt-badpath.patch \
@@ -19,7 +19,7 @@ SRC_URI = "https://collectd.org/files/collectd-${PV}.tar.bz2 \
SRC_URI[md5sum] = "2b23a65960bc323d065234776a542e04"
SRC_URI[sha256sum] = "5bae043042c19c31f77eb8464e56a01a5454e0b39fa07cf7ad0f1bfc9c3a09d6"
-inherit autotools python3native update-rc.d pkgconfig systemd
+inherit autotools python3native update-rc.d pkgconfig systemd github-releases
SYSTEMD_SERVICE:${PN} = "collectd.service"
diff --git a/meta-openembedded/meta-oe/recipes-extended/dlt-daemon/dlt-daemon/0001-CMakeLists-txt-make-DLT_WatchdogSec-can-be-set-by-user.patch b/meta-openembedded/meta-oe/recipes-extended/dlt-daemon/dlt-daemon/0001-CMakeLists-txt-make-DLT_WatchdogSec-can-be-set-by-user.patch
new file mode 100644
index 0000000000..335872c40f
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/dlt-daemon/dlt-daemon/0001-CMakeLists-txt-make-DLT_WatchdogSec-can-be-set-by-user.patch
@@ -0,0 +1,40 @@
+From bc03f142507da92add8ba325fdf8187d47a7d719 Mon Sep 17 00:00:00 2001
+From: Changqing Li <changqing.li@windriver.com>
+Date: Fri, 13 Dec 2024 16:37:24 +0800
+Subject: [PATCH] CMakeLists.txt: make DLT_WatchdogSec can be set by user
+
+In my test env, WatchdogSec default value 2 is not enough, manually
+changed to 3 is ok. This makes dlt.service/dlt-system.service start
+failed during boot time. So, make DLT_WatchdogSec can be set by user, so
+user can set them to proper value at build time, then service can start
+successfully in boot time.
+
+Signed-off-by: Changqing Li <changqing.li@windriver.com>
+
+Upstream-Status: Backport [https://github.com/COVESA/dlt-daemon/pull/720/commits/bc03f142507da92add8ba325fdf8187d47a7d719]
+
+Signed-off-by: Changqing Li <changqing.li@windriver.com>
+---
+ systemd/CMakeLists.txt | 8 ++++++--
+ 1 file changed, 6 insertions(+), 2 deletions(-)
+
+diff --git a/systemd/CMakeLists.txt b/systemd/CMakeLists.txt
+index 16cbe86b5..659378d16 100644
+--- a/systemd/CMakeLists.txt
++++ b/systemd/CMakeLists.txt
+@@ -18,10 +18,14 @@ if(WITH_SYSTEMD)
+ set(SYSTEMD_CONFIGURATIONS_FILES_DIR ${SYSTEMD_UNITDIR} )
+
+ if(WITH_SYSTEMD_WATCHDOG)
+- set( DLT_WatchdogSec 2 )
++ if(NOT DEFINED DLT_WatchdogSec)
++ set(DLT_WatchdogSec 2 CACHE STRING "Watchdog timeout in seconds")
++ endif()
+ message( STATUS "The systemd watchdog is enabled - timeout is set to ${DLT_WatchdogSec} seconds")
+ else(WITH_SYSTEMD_WATCHDOG)
+- set( DLT_WatchdogSec 0 )
++ if(NOT DEFINED DLT_WatchdogSec)
++ set(DLT_WatchdogSec 0 CACHE STRING "Watchdog timeout in seconds")
++ endif()
+ message( STATUS "The systemd watchdog is disabled")
+ endif(WITH_SYSTEMD_WATCHDOG)
diff --git a/meta-openembedded/meta-oe/recipes-extended/dlt-daemon/dlt-daemon_2.18.10.bb b/meta-openembedded/meta-oe/recipes-extended/dlt-daemon/dlt-daemon_2.18.10.bb
index 3d2e4a73f1..888289b357 100644
--- a/meta-openembedded/meta-oe/recipes-extended/dlt-daemon/dlt-daemon_2.18.10.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/dlt-daemon/dlt-daemon_2.18.10.bb
@@ -19,6 +19,7 @@ SRC_URI = "git://github.com/COVESA/${BPN}.git;protocol=https;branch=master \
file://0004-Modify-systemd-config-directory.patch \
file://544.patch \
file://567.patch \
+ file://0001-CMakeLists-txt-make-DLT_WatchdogSec-can-be-set-by-user.patch \
"
SRCREV = "0f2d4cfffada6f8448a2cb27995b38eb4271044f"
diff --git a/meta-openembedded/meta-oe/recipes-extended/etcd/etcd-cpp-apiv3_0.15.3.bb b/meta-openembedded/meta-oe/recipes-extended/etcd/etcd-cpp-apiv3_0.15.3.bb
index 401d53c79c..e6fe8af890 100644
--- a/meta-openembedded/meta-oe/recipes-extended/etcd/etcd-cpp-apiv3_0.15.3.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/etcd/etcd-cpp-apiv3_0.15.3.bb
@@ -19,5 +19,9 @@ S = "${WORKDIR}/git"
EXTRA_OECONF += "-DCPPREST_EXCLUDE_WEBSOCKETS=ON"
+do_install:append() {
+ sed -i -e 's#${RECIPE_SYSROOT}##g' ${D}${libdir}/cmake/etcd-cpp-api/etcd-targets.cmake
+}
+
SOLIBS = ".so"
FILES_SOLIBSDEV = ""
diff --git a/meta-openembedded/meta-oe/recipes-extended/etcd/etcd/CVE-2023-32082.patch b/meta-openembedded/meta-oe/recipes-extended/etcd/etcd/CVE-2023-32082.patch
new file mode 100644
index 0000000000..fe350265a4
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/etcd/etcd/CVE-2023-32082.patch
@@ -0,0 +1,86 @@
+From 021ad998bed830f903b96ee9dcf87a35ca60c148 Mon Sep 17 00:00:00 2001
+From: Hitoshi Mitake <h.mitake@gmail.com>
+Date: Wed, 29 Mar 2023 20:46:32 +0900
+Subject: [PATCH] etcdserver: protect lease timetilive with auth
+
+CVE: CVE-2023-32082
+Upstream-Status: Backport [https://github.com/etcd-io/etcd/commit/d1b1aa9dbe8065fb2cb36fe035daf701ccabc4e0]
+
+Signed-off-by: Hitoshi Mitake <h.mitake@gmail.com>
+Co-authored-by: Benjamin Wang <wachao@vmware.com>
+(cherry picked from commit d1b1aa9dbe8065fb2cb36fe035daf701ccabc4e0)
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ server/etcdserver/v3_server.go | 52 +++++++++++++++++++++++++++++++++-
+ 1 file changed, 51 insertions(+), 1 deletion(-)
+
+diff --git a/server/etcdserver/v3_server.go b/server/etcdserver/v3_server.go
+index 0184b8d18..c8ce8c69c 100644
+--- a/server/etcdserver/v3_server.go
++++ b/server/etcdserver/v3_server.go
+@@ -336,7 +336,32 @@ func (s *EtcdServer) LeaseRenew(ctx context.Context, id lease.LeaseID) (int64, e
+ return -1, ErrCanceled
+ }
+
+-func (s *EtcdServer) LeaseTimeToLive(ctx context.Context, r *pb.LeaseTimeToLiveRequest) (*pb.LeaseTimeToLiveResponse, error) {
++func (s *EtcdServer) checkLeaseTimeToLive(ctx context.Context, leaseID lease.LeaseID) (uint64, error) {
++ rev := s.AuthStore().Revision()
++ if !s.AuthStore().IsAuthEnabled() {
++ return rev, nil
++ }
++ authInfo, err := s.AuthInfoFromCtx(ctx)
++ if err != nil {
++ return rev, err
++ }
++ if authInfo == nil {
++ return rev, auth.ErrUserEmpty
++ }
++
++ l := s.lessor.Lookup(leaseID)
++ if l != nil {
++ for _, key := range l.Keys() {
++ if err := s.AuthStore().IsRangePermitted(authInfo, []byte(key), []byte{}); err != nil {
++ return 0, err
++ }
++ }
++ }
++
++ return rev, nil
++}
++
++func (s *EtcdServer) leaseTimeToLive(ctx context.Context, r *pb.LeaseTimeToLiveRequest) (*pb.LeaseTimeToLiveResponse, error) {
+ if s.isLeader() {
+ if err := s.waitAppliedIndex(); err != nil {
+ return nil, err
+@@ -386,6 +411,31 @@ func (s *EtcdServer) LeaseTimeToLive(ctx context.Context, r *pb.LeaseTimeToLiveR
+ return nil, ErrCanceled
+ }
+
++func (s *EtcdServer) LeaseTimeToLive(ctx context.Context, r *pb.LeaseTimeToLiveRequest) (*pb.LeaseTimeToLiveResponse, error) {
++ var rev uint64
++ var err error
++ if r.Keys {
++ // check RBAC permission only if Keys is true
++ rev, err = s.checkLeaseTimeToLive(ctx, lease.LeaseID(r.ID))
++ if err != nil {
++ return nil, err
++ }
++ }
++
++ resp, err := s.leaseTimeToLive(ctx, r)
++ if err != nil {
++ return nil, err
++ }
++
++ if r.Keys {
++ if s.AuthStore().IsAuthEnabled() && rev != s.AuthStore().Revision() {
++ return nil, auth.ErrAuthOldRevision
++ }
++ }
++ return resp, nil
++}
++
++// LeaseLeases is really ListLeases !???
+ func (s *EtcdServer) LeaseLeases(ctx context.Context, r *pb.LeaseLeasesRequest) (*pb.LeaseLeasesResponse, error) {
+ ls := s.lessor.Leases()
+ lss := make([]*pb.LeaseStatus, len(ls))
diff --git a/meta-openembedded/meta-oe/recipes-extended/etcd/etcd_3.5.7.bb b/meta-openembedded/meta-oe/recipes-extended/etcd/etcd_3.5.7.bb
index 0794158a52..83847f871f 100644
--- a/meta-openembedded/meta-oe/recipes-extended/etcd/etcd_3.5.7.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/etcd/etcd_3.5.7.bb
@@ -8,6 +8,7 @@ SRC_URI = " \
git://github.com/etcd-io/etcd;branch=release-3.5;protocol=https \
file://0001-xxhash-bump-to-v2.1.2.patch;patchdir=src/${GO_IMPORT} \
file://0001-test_lib.sh-remove-gobin-requirement-during-build.patch;patchdir=src/${GO_IMPORT} \
+ file://CVE-2023-32082.patch;patchdir=src/${GO_IMPORT} \
file://etcd.service \
file://etcd-existing.conf \
file://etcd-new.service \
diff --git a/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31176.patch b/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31176.patch
new file mode 100644
index 0000000000..7fdabff476
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31176.patch
@@ -0,0 +1,86 @@
+From d0664704daa46d2e4440c0c50057d0dfa47467ea Mon Sep 17 00:00:00 2001
+From: Ethan A Merritt <merritt@u.washington.edu>
+Date: Tue, 11 Mar 2025 12:31:54 -0700
+Subject: [PATCH] guard against invalid read from plot->labels
+
+If a plot style uses points and the point chosen has PT_CHARACTER
+then the program looks for a possible font in plot->labels->font.
+These plot styles contain a flag bit HAS_POINT (gp_types.h).
+The program makes sure to initialize plot->labels for these styles.
+However a problem arises when a plot style that doesn't use points
+nevertheless triggers this same attempted font lookup by using a
+linetype that happens to use pointtype PT_CHARACTER.
+I think this is only possible with 'splot' but I added parallel
+checks for 'plot' as well.
+
+Bug 2776
+
+CVE: CVE-2025-31176
+Upstream-Status: Backport [https://sourceforge.net/p/gnuplot/gnuplot-main/ci/b456a3ef618f55a20b3071d336cb20514274f1d4/]
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ src/boundary.c | 2 +-
+ src/graph3d.c | 4 ++--
+ src/graphics.c | 4 ++--
+ 3 files changed, 5 insertions(+), 5 deletions(-)
+
+diff --git a/src/boundary.c b/src/boundary.c
+index fd2ac86f4..60dbce042 100644
+--- a/src/boundary.c
++++ b/src/boundary.c
+@@ -1440,7 +1440,7 @@ do_key_sample_point(
+ (*t->pointsize)(pointsize);
+ if (on_page(xl + key_point_offset, yl)) {
+ if (this_plot->lp_properties.p_type == PT_CHARACTER) {
+- if (this_plot->labels->textcolor.type != TC_DEFAULT)
++ if (this_plot->labels && this_plot->labels->textcolor.type != TC_DEFAULT)
+ apply_pm3dcolor(&(this_plot->labels->textcolor));
+ (*t->put_text) (xl + key_point_offset, yl,
+ this_plot->lp_properties.p_char);
+diff --git a/src/graph3d.c b/src/graph3d.c
+index 0d3ca7221..48b02f580 100644
+--- a/src/graph3d.c
++++ b/src/graph3d.c
+@@ -2016,7 +2016,7 @@ plot3d_points(struct surface_points *plot)
+ /* Set whatever we can that applies to every point in the loop */
+ if (plot->lp_properties.p_type == PT_CHARACTER) {
+ ignore_enhanced(TRUE);
+- if (plot->labels->font && plot->labels->font[0])
++ if (plot->labels && plot->labels->font && plot->labels->font[0])
+ (*t->set_font) (plot->labels->font);
+ (*t->justify_text) (CENTRE);
+ }
+@@ -2111,7 +2111,7 @@ plot3d_points(struct surface_points *plot)
+
+ /* Return to initial state */
+ if (plot->lp_properties.p_type == PT_CHARACTER) {
+- if (plot->labels->font && plot->labels->font[0])
++ if (plot->labels && plot->labels->font && plot->labels->font[0])
+ (*t->set_font) ("");
+ ignore_enhanced(FALSE);
+ }
+diff --git a/src/graphics.c b/src/graphics.c
+index bdbebe92a..2b500b12b 100644
+--- a/src/graphics.c
++++ b/src/graphics.c
+@@ -2353,7 +2353,7 @@ plot_points(struct curve_points *plot)
+ /* Set whatever we can that applies to every point in the loop */
+ if (plot->lp_properties.p_type == PT_CHARACTER) {
+ ignore_enhanced(TRUE);
+- if (plot->labels->font && plot->labels->font[0])
++ if (plot->labels && plot->labels->font && plot->labels->font[0])
+ (*t->set_font) (plot->labels->font);
+ (*t->justify_text) (CENTRE);
+ }
+@@ -2475,7 +2475,7 @@ plot_points(struct curve_points *plot)
+
+ /* Return to initial state */
+ if (plot->lp_properties.p_type == PT_CHARACTER) {
+- if (plot->labels->font && plot->labels->font[0])
++ if (plot->labels && plot->labels->font && plot->labels->font[0])
+ (*t->set_font) ("");
+ ignore_enhanced(FALSE);
+ }
+--
+2.43.0
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31177.patch b/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31177.patch
new file mode 100644
index 0000000000..dcacf538b2
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31177.patch
@@ -0,0 +1,40 @@
+From 36a4355010a81a78cf9df03d3c76dcd599ed994b Mon Sep 17 00:00:00 2001
+From: Ethan A Merritt <merritt@u.washington.edu>
+Date: Wed, 15 Jan 2025 11:56:13 -0800
+Subject: [PATCH] dumb: more stringent tests against y bound of dumb terminal
+ charcell array
+
+Bug 2756
+
+CVE: CVE-2025-31177
+Upstream-Status: Backport [https://sourceforge.net/p/gnuplot/gnuplot-main/ci/226809aebb345e74d371bb43a2b434b490be527a/]
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ term/dumb.trm | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/term/dumb.trm b/term/dumb.trm
+index c93afb94e..bb22ca25f 100644
+--- a/term/dumb.trm
++++ b/term/dumb.trm
+@@ -637,7 +637,7 @@ DUMB_put_text(unsigned int x, unsigned int y, const char *str)
+ {
+ int i, length;
+
+- if (y > dumb_ymax)
++ if (y < 0 || y > dumb_ymax)
+ return;
+
+ length = gp_strlen(str);
+@@ -784,7 +784,7 @@ ENHdumb_FLUSH()
+ y += i;
+
+ /* print the string fragment, perhaps invisibly */
+- if (ENHdumb_show && y < dumb_ymax) {
++ if (ENHdumb_show && (0 <= y && y < dumb_ymax)) {
+ #ifdef DUMB_UTF8
+ for (i = 0; i < len && x < dumb_xmax; i++, x++) {
+ utf8_copy_one( (char *)(&DUMB_PIXEL(x, y)), gp_strchrn(str,i));
+--
+2.43.0
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31178.patch b/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31178.patch
new file mode 100644
index 0000000000..c783d75180
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31178.patch
@@ -0,0 +1,95 @@
+From c625576a4e086f8e3ad6f23559052494465722c6 Mon Sep 17 00:00:00 2001
+From: Ethan A Merritt <merritt@u.washington.edu>
+Date: Tue, 14 Jan 2025 21:23:19 -0800
+Subject: [PATCH] use snprintf to protect against garbage user-supplied mouse
+ format
+
+Bug 2754
+
+CVE: CVE-2025-31178
+Upstream-Status: Backport [https://sourceforge.net/p/gnuplot/gnuplot-main/ci/b78cc829a18e9436daaa859c96f3970157f3171e/]
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ src/mouse.c | 19 +++++++++----------
+ 1 file changed, 9 insertions(+), 10 deletions(-)
+
+diff --git a/src/mouse.c b/src/mouse.c
+index ef8f14d71..1571144ce 100644
+--- a/src/mouse.c
++++ b/src/mouse.c
+@@ -168,7 +168,7 @@ static void alert(void);
+ static void MousePosToGraphPosReal(int xx, int yy, double *x, double *y, double *x2, double *y2);
+ static char *xy_format(void);
+ static char *zoombox_format(void);
+-static char *GetAnnotateString(char *s, double x, double y, int mode, char *fmt);
++static char *GetAnnotateString(char *s, size_t len, double x, double y, int mode, char *fmt);
+ static char *xDateTimeFormat(double x, char *b, int mode);
+ static void GetRulerString(char *p, double x, double y);
+ static void apply_zoom(struct t_zoom * z);
+@@ -418,7 +418,7 @@ zoombox_format()
+ /* formats the information for an annotation (middle mouse button clicked)
+ */
+ static char *
+-GetAnnotateString(char *s, double x, double y, int mode, char *fmt)
++GetAnnotateString(char *s, size_t len, double x, double y, int mode, char *fmt)
+ {
+ if (axis_array[FIRST_X_AXIS].datatype == DT_DMS
+ || axis_array[FIRST_Y_AXIS].datatype == DT_DMS) {
+@@ -473,11 +473,11 @@ GetAnnotateString(char *s, double x, double y, int mode, char *fmt)
+ r = rmin + x/cos(phi);
+
+ if (fmt)
+- sprintf(s, fmt, theta, r);
++ snprintf(s, len, fmt, theta, r);
+ else
+ sprintf(s, "theta: %.1f%s r: %g", theta, degree_sign, r);
+ } else if ((mode == MOUSE_COORDINATES_ALT) && fmt) {
+- sprintf(s, fmt, x, y); /* user defined format */
++ snprintf(s, len, fmt, x, y); /* user defined format */
+ } else if (mode == MOUSE_COORDINATES_FUNCTION) {
+ /* EXPERIMENTAL !!! */
+ t_value original_x, original_y;
+@@ -500,7 +500,7 @@ GetAnnotateString(char *s, double x, double y, int mode, char *fmt)
+ gpfree_string(&readout);
+ } else {
+ /* Default format ("set mouse mouseformat" is not active) */
+- sprintf(s, xy_format(), x, y); /* usual x,y values */
++ snprintf(s, len, xy_format(), x, y); /* usual x,y values */
+ }
+ return s + strlen(s);
+ }
+@@ -886,10 +886,10 @@ UpdateStatuslineWithMouseSetting(mouse_setting_t * ms)
+ strcat(format, ms->fmt);
+ strcat(format, ", ");
+ strcat(format, ms->fmt);
+- sprintf(s0, format, surface_rot_x, surface_rot_z, surface_scale, surface_zscale);
++ snprintf(s0, 255, format, surface_rot_x, surface_rot_z, surface_scale, surface_zscale);
+ } else if (!TICS_ON(axis_array[SECOND_X_AXIS].ticmode) && !TICS_ON(axis_array[SECOND_Y_AXIS].ticmode)) {
+ /* only first X and Y axis are in use */
+- sp = GetAnnotateString(s0, real_x, real_y, mouse_mode, mouse_alt_string);
++ sp = GetAnnotateString(s0, 255, real_x, real_y, mouse_mode, mouse_alt_string);
+ if (ruler.on)
+ GetRulerString(sp, real_x, real_y);
+ } else {
+@@ -2116,7 +2116,7 @@ event_buttonrelease(struct gp_event_t *ge)
+ * only place, if the user didn't drag (rotate) the plot */
+
+ if (!is_3d_plot || !motion) {
+- GetAnnotateString(s0, real_x, real_y, mouse_mode, mouse_alt_string);
++ GetAnnotateString(s0, 255, real_x, real_y, mouse_mode, mouse_alt_string);
+ term->set_clipboard(s0);
+ if (display_ipc_commands()) {
+ fprintf(stderr, "put `%s' to clipboard.\n", s0);
+@@ -2129,8 +2129,7 @@ event_buttonrelease(struct gp_event_t *ge)
+ * only done if the user didn't drag (scale) the plot */
+
+ if (!is_3d_plot || !motion) {
+-
+- GetAnnotateString(s0, real_x, real_y, mouse_mode, mouse_alt_string);
++ GetAnnotateString(s0, 255, real_x, real_y, mouse_mode, mouse_alt_string);
+ if (mouse_setting.label) {
+ if (modifier_mask & Mod_Ctrl) {
+ remove_label(mouse_x, mouse_y);
+--
+2.43.0
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31179.patch b/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31179.patch
new file mode 100644
index 0000000000..a7ec6e78f0
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31179.patch
@@ -0,0 +1,35 @@
+From 92c147cbcb8c28e4662963b378fc31e1d58c72f2 Mon Sep 17 00:00:00 2001
+From: Ethan A Merritt <merritt@u.washington.edu>
+Date: Tue, 11 Mar 2025 16:31:23 -0700
+Subject: [PATCH] guard against trying to format a huge number as a time
+
+The time formatting code does not handle time_in_seconds > 1.e12
+(sometime in the year 33658).
+
+Bug 2779
+CVE: CVE-2025-31179
+Upstream-Status: Backport [https://sourceforge.net/p/gnuplot/gnuplot-main/ci/ed647df512786b3c94429dd5c864715301e03ea5/]
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ src/mouse.c | 5 +++++
+ 1 file changed, 5 insertions(+)
+
+diff --git a/src/mouse.c b/src/mouse.c
+index 1571144ce..86dee805c 100644
+--- a/src/mouse.c
++++ b/src/mouse.c
+@@ -513,6 +513,11 @@ static char *
+ xDateTimeFormat(double x, char *b, int mode)
+ {
+ struct tm tm;
++ if (fabs(x) > 1.e12) { /* Some time in the year 33688 */
++ int_warn(NO_CARET, "time value out of range");
++ *b = '\0';
++ return b;
++ }
+
+ switch (mode) {
+ case MOUSE_COORDINATES_XDATE:
+--
+2.43.0
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31180.patch b/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31180.patch
new file mode 100644
index 0000000000..e444a87128
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31180.patch
@@ -0,0 +1,43 @@
+From ec0fa6117d8e98918a030e31c2e8df32ab6e4542 Mon Sep 17 00:00:00 2001
+From: Ethan A Merritt <merritt@u.washington.edu>
+Date: Tue, 14 Jan 2025 21:54:14 -0800
+Subject: [PATCH] canvas: handle nonlinear x2 or y2 axis with an incomplete
+ definition
+
+Actually "handle" means "ignore".
+But now it doesn't segfault trying to probe a non-existant link function.
+
+Bug 2755
+
+CVE: CVE-2025-31180
+Upstream-Status: Backport [https://sourceforge.net/p/gnuplot/gnuplot-main/ci/b2343fd02c4fff94957f0151b73daa0a1f7fec49/]
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ term/canvas.trm | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/term/canvas.trm b/term/canvas.trm
+index fee3e5dfa..e796cec0d 100644
+--- a/term/canvas.trm
++++ b/term/canvas.trm
+@@ -646,7 +646,7 @@ CANVAS_text()
+ } else
+ fprintf(gpoutfile, "gnuplot.plot_axis_x2min = \"none\"\n");
+ if (axis_array[SECOND_X_AXIS].linked_to_primary
+- && axis_array[FIRST_X_AXIS].link_udf->at) {
++ && axis_array[FIRST_X_AXIS].link_udf && axis_array[FIRST_X_AXIS].link_udf->at) {
+ fprintf(gpoutfile, "gnuplot.x2_mapping = function(x) { return x; };");
+ fprintf(gpoutfile, " // replace returned value with %s\n",
+ axis_array[FIRST_X_AXIS].link_udf->definition);
+@@ -657,7 +657,7 @@ CANVAS_text()
+ } else
+ fprintf(gpoutfile, "gnuplot.plot_axis_y2min = \"none\"\n");
+ if (axis_array[SECOND_Y_AXIS].linked_to_primary
+- && axis_array[FIRST_Y_AXIS].link_udf->at) {
++ && axis_array[FIRST_Y_AXIS].link_udf && axis_array[FIRST_Y_AXIS].link_udf->at) {
+ fprintf(gpoutfile, "gnuplot.y2_mapping = function(y) { return y; };");
+ fprintf(gpoutfile, " // replace returned value with %s\n",
+ axis_array[FIRST_Y_AXIS].link_udf->definition);
+--
+2.43.0
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31181.patch b/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31181.patch
new file mode 100644
index 0000000000..2de4617ff1
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-31181.patch
@@ -0,0 +1,43 @@
+From 2d9e68278aece7e971815d9c3ec297c5e9bc51bd Mon Sep 17 00:00:00 2001
+From: Ethan A Merritt <merritt@u.washington.edu>
+Date: Tue, 14 Jan 2025 20:56:37 -0800
+Subject: [PATCH] x11: protect against double fclose() if two errors in a row
+
+Bug 2753
+
+CVE: CVE-2025-31181
+Upstream-Status: Backport [https://sourceforge.net/p/gnuplot/gnuplot-main/ci/af96c2c1b20383684b1ec2084dab7936f7053031/]
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ term/x11.trm | 8 +++++---
+ 1 file changed, 5 insertions(+), 3 deletions(-)
+
+diff --git a/term/x11.trm b/term/x11.trm
+index 458fcf5f9..1b51a80c8 100644
+--- a/term/x11.trm
++++ b/term/x11.trm
+@@ -856,8 +856,9 @@ X11_atexit()
+ /* dont wait(), since they might be -persist */
+ X11_ipc = NULL;
+ #ifdef PIPE_IPC
+- close(ipc_back_fd);
+- ipc_back_fd = -1;
++ if (ipc_back_fd >= 0)
++ close(ipc_back_fd);
++ ipc_back_fd = IPC_BACK_CLOSED;
+ #endif
+ }
+ }
+@@ -1412,7 +1413,8 @@ X11_graphics()
+ #ifdef PIPE_IPC
+ /* if we know the outboard driver has stopped, restart it */
+ if (ipc_back_fd == IPC_BACK_CLOSED) {
+- fclose(X11_ipc);
++ if (X11_ipc > 0)
++ fclose(X11_ipc);
+ X11_ipc = NULL;
+ X11_init();
+ }
+--
+2.43.0
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-3359.patch b/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-3359.patch
new file mode 100644
index 0000000000..d2de00ec6d
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot/CVE-2025-3359.patch
@@ -0,0 +1,67 @@
+From 997b4ee68275664b94e0c881ace5121d79c0c29c Mon Sep 17 00:00:00 2001
+From: Ethan A Merritt <merritt@u.washington.edu>
+Date: Tue, 25 Mar 2025 22:51:54 -0700
+Subject: [PATCH] hpgl: font name parsing overruns the string by one char
+
+if no comma is present in the font name.
+E.g.
+ set term pcl
+ set title "Title" font "sans" # no comma in font name
+ plot x
+
+Bug 2781
+
+CVE: CVE-2025-3359
+Upstream-Status: Backport [https://sourceforge.net/p/gnuplot/gnuplot-main/ci/a5897feadc4be73b0ffd8458556c47117bd24d03/]
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ term/hpgl.trm | 28 +++++++++++-----------------
+ 1 file changed, 11 insertions(+), 17 deletions(-)
+
+diff --git a/term/hpgl.trm b/term/hpgl.trm
+index 04088977d..fdb4c7083 100644
+--- a/term/hpgl.trm
++++ b/term/hpgl.trm
+@@ -1650,28 +1650,22 @@ TERM_PUBLIC int
+ HPGL2_set_font(const char *font)
+ {
+ char name[MAX_ID_LEN + 1];
+- int sep;
+- int int_size;
+- double size;
++ char *sep;
++ double size = HPGL2_point_size;
+
+ if (font == NULL)
+ font = "";
+
+- sep = strcspn(font, ",");
+- strncpy(name, font, sizeof(name));
+-
+- if (sep < sizeof(name))
+- name[sep] = NUL;
+-
+-/* determine font size, use default from options if invalid */
+- int_size = 0;
+- /* FIXME: use strtod instead */
+- sscanf(&(font[sep + 1]), "%d", &int_size);
+- if (int_size > 0)
+- size = int_size;
+- else
+- size = HPGL2_point_size;
++ safe_strncpy(name, font, sizeof(name));
+
++ /* determine font size, use default from options if invalid */
++ sep = strchr(font, ',');
++ if (sep) {
++ double req_size = strtod(sep+1, NULL);
++ if (req_size > 0)
++ size = req_size;
++ *sep = '\0';
++ }
+ return HPGL2_set_font_size(name, size);
+ }
+
+--
+2.43.0
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot_5.4.3.bb b/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot_5.4.3.bb
index fe5e5c067d..b945cc318d 100644
--- a/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot_5.4.3.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/gnuplot/gnuplot_5.4.3.bb
@@ -15,6 +15,13 @@ SRC_URI = "${SOURCEFORGE_MIRROR}/project/${BPN}/${BPN}/${PV}/${BP}.tar.gz;name=a
http://www.mneuroth.de/privat/zaurus/qtplot-0.2.tar.gz;name=qtplot \
file://gnuplot.desktop \
file://gnuplot.png \
+ file://CVE-2025-3359.patch \
+ file://CVE-2025-31176.patch \
+ file://CVE-2025-31177.patch \
+ file://CVE-2025-31178.patch \
+ file://CVE-2025-31179.patch \
+ file://CVE-2025-31180.patch \
+ file://CVE-2025-31181.patch \
"
SRC_URI:append:class-target = " \
file://0002-do-not-build-demos.patch \
diff --git a/meta-openembedded/meta-oe/recipes-extended/hiredis/hiredis/run-ptest b/meta-openembedded/meta-oe/recipes-extended/hiredis/hiredis/run-ptest
index 8d450b881f..8b352c3401 100644
--- a/meta-openembedded/meta-oe/recipes-extended/hiredis/hiredis/run-ptest
+++ b/meta-openembedded/meta-oe/recipes-extended/hiredis/hiredis/run-ptest
@@ -2,17 +2,17 @@
TEST_SSL=0 TEST_ASYNC=0 ./test.sh | sed -e 's/PASSED/PASS/g' -e 's/FAILED/FAIL/g' -e 's/SKIPPED/SKIP/g' | awk '
{
- if ($NF == "\033[0;32mPASS\033[0;0m" || $NF == "\033[0;31mFAIL\033[0;0m" || $NF == "\033[01;33mSKIP\033[0;0m") {
+ gsub(/\x1B\[[0-9;]*m/, "")
+ if ($NF == "PASS" || $NF == "FAIL" || $NF == "SKIP") {
printf "%s: %s\n", $NF, $0
} else {
print
}
-}'| awk '{
- if ($NF == "\033[0;32mPASS\033[0;0m" || $NF == "\033[0;31mFAIL\033[0;0m" || $NF == "\033[01;33mSKIP\033[0;0m") {
+}' | awk '{
+ if ($NF == "PASS" || $NF == "FAIL" || $NF == "SKIP") {
$NF = ""
print $0
} else {
- print
- }
+ print
+ }
}' | awk '{gsub(/:/,"",$NF)}1'
-
diff --git a/meta-openembedded/meta-oe/recipes-extended/hplip/hplip_3.22.10.bb b/meta-openembedded/meta-oe/recipes-extended/hplip/hplip_3.22.10.bb
index be420b4837..991c695565 100644
--- a/meta-openembedded/meta-oe/recipes-extended/hplip/hplip_3.22.10.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/hplip/hplip_3.22.10.bb
@@ -49,7 +49,7 @@ EXTRA_OECONF += "\
--with-cupsfilterdir=${libexecdir}/cups/filter \
"
-EXTRA_OEMAKE = "rulessystemdir=${systemd_unitdir}/system/"
+EXTRA_OEMAKE = "CPPFLAGS='${CFLAGS}' rulessystemdir=${systemd_unitdir}/system/"
do_install:append() {
rm -rf ${D}${datadir}/hplip/upgrade.py
diff --git a/meta-openembedded/meta-oe/recipes-extended/indent/indent/0001-Fix-a-heap-buffer-underread-in-set_buf_break.patch b/meta-openembedded/meta-oe/recipes-extended/indent/indent/0001-Fix-a-heap-buffer-underread-in-set_buf_break.patch
new file mode 100644
index 0000000000..9938b6ebed
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/indent/indent/0001-Fix-a-heap-buffer-underread-in-set_buf_break.patch
@@ -0,0 +1,123 @@
+From ec3ce4dce7f0bc6f15e8a29eeb3776359e0750fb Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= <ppisar@redhat.com>
+Date: Fri, 22 Nov 2024 17:27:21 +0800
+Subject: [PATCH] Fix a heap buffer underread in set_buf_break()
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+If an opening parenthesis follows a comment with a text, a read from
+an invalid address happens in set_buf_break():
+
+ $ printf '/*a*/()' | valgrind -- ./src/indent - -o /dev/null
+ ==28887== Memcheck, a memory error detector
+ ==28887== Copyright (C) 2002-2022, and GNU GPL'd, by Julian Seward et al.
+ ==28887== Using Valgrind-3.22.0 and LibVEX; rerun with -h for copyright info
+ ==28887== Command: ./src/indent - -o /dev/null
+ ==28887==
+ ==28887== Invalid read of size 2
+ ==28887== at 0x409989: set_buf_break (output.c:319)
+ ==28887== by 0x401FE7: indent_main_loop (indent.c:640)
+ ==28887== by 0x4022A7: indent (indent.c:759)
+ ==28887== by 0x40294E: indent_single_file (indent.c:1004)
+ ==28887== by 0x402A1C: indent_all (indent.c:1042)
+ ==28887== by 0x402BD0: main (indent.c:1123)
+ ==28887== Address 0x4a5facc is 4 bytes before a block of size 16 alloc'd
+ ==28887== at 0x4849E60: calloc (vg_replace_malloc.c:1595)
+ ==28887== by 0x408B61: xmalloc (globs.c:42)
+ ==28887== by 0x40765E: init_parser (parse.c:73)
+ ==28887== by 0x402B1F: main (indent.c:1101)
+
+It happens when checking an indentation level of the outer scope by indexing
+parser_state_tos->paren_indents[]:
+
+ level = parser_state_tos->p_l_follow;
+ [...]
+ /* Did we just parse a bracket that will be put on the next line
+ * by this line break? */
+ if ((*token == '(') || (*token == '['))
+ --level; /* then don't take it into account */
+ [...]
+ if (level == 0) {
+ } else {
+→ if (parser_state_tos->paren_indents[level - 1] < 0) {...}
+ }
+
+The cause is a special case for moving opening parentheses and
+brackets to a next line. If parser_state_tos->p_l_follow is zero
+(like in the reproducer), the index evaluates to -2 and goes out of
+range of the paren_indents array.
+
+This patch simply prevents from decreasing the index under zero when
+formating the code. Maybe it leaves some piece of code unformated, but
+it's safe.
+
+I checked all places where p_l_follow is set (it is only in
+handletoken.c) and they corretly prevent from decrasing it under
+zero. That keeps set_buf_break() in output.c as the culprit.
+
+<https://lists.gnu.org/archive/html/bug-indent/2024-01/msg00000.html>
+
+Signed-off-by: Petr Písař <ppisar@redhat.com>
+
+CVE: CVE-2024-0911
+Upstream-Status: Backport [feb2b646e6c3a05018e132515c5eda98ca13d50d
+Signed-off-by: Hongxu Jia <hongxu.jia@windriver.com>
+---
+ regression/TEST | 2 +-
+ regression/input/comment-parent-heap-underread.c | 3 +++
+ regression/standard/comment-parent-heap-underread.c | 5 +++++
+ src/output.c | 2 +-
+ 4 files changed, 10 insertions(+), 2 deletions(-)
+ create mode 100644 regression/input/comment-parent-heap-underread.c
+ create mode 100644 regression/standard/comment-parent-heap-underread.c
+
+diff --git a/regression/TEST b/regression/TEST
+index a76c112..0888a18 100755
+--- a/regression/TEST
++++ b/regression/TEST
+@@ -38,7 +38,7 @@ BUGS="case-label.c one-line-1.c one-line-2.c one-line-3.c \
+ macro.c enum.c elif.c nested.c wrapped-string.c minus_predecrement.c \
+ bug-gnu-33364.c float-constant-suffix.c block-comments.c \
+ no-forced-nl-in-block-init.c hexadecimal_float.c \
+- comment-heap-overread.c"
++ comment-heap-overread.c comment-parent-heap-underread.c"
+
+ INDENTSRC="args.c backup.h backup.c dirent_def.h globs.c indent.h \
+ indent.c indent_globs.h io.c lexi.c memcpy.c parse.c pr_comment.c \
+diff --git a/regression/input/comment-parent-heap-underread.c b/regression/input/comment-parent-heap-underread.c
+new file mode 100644
+index 0000000..68e13cf
+--- /dev/null
++++ b/regression/input/comment-parent-heap-underread.c
+@@ -0,0 +1,3 @@
++void foo(void) {
++/*a*/(1);
++}
+diff --git a/regression/standard/comment-parent-heap-underread.c b/regression/standard/comment-parent-heap-underread.c
+new file mode 100644
+index 0000000..9a1c6e3
+--- /dev/null
++++ b/regression/standard/comment-parent-heap-underread.c
+@@ -0,0 +1,5 @@
++void
++foo (void)
++{
++/*a*/ (1);
++}
+diff --git a/src/output.c b/src/output.c
+index 5b92167..b8a4961 100644
+--- a/src/output.c
++++ b/src/output.c
+@@ -290,7 +290,7 @@ void set_buf_break (
+ /* Did we just parse a bracket that will be put on the next line
+ * by this line break? */
+
+- if ((*token == '(') || (*token == '['))
++ if (level > 0 && ((*token == '(') || (*token == '[')))
+ {
+ --level; /* then don't take it into account */
+ }
+--
+2.34.1
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/indent/indent/CVE-2023-40305_0001.patch b/meta-openembedded/meta-oe/recipes-extended/indent/indent/CVE-2023-40305_0001.patch
new file mode 100644
index 0000000000..367202e3c5
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/indent/indent/CVE-2023-40305_0001.patch
@@ -0,0 +1,4196 @@
+From df4ab2d19e247d059e0025789ba513418073ab6f Mon Sep 17 00:00:00 2001
+From: Petr Písař <ppisar@redhat.com>
+Date: Thu, 19 Oct 2023 07:36:32 +0000
+Subject: [PATCH] Fix an out-of-buffer read in search_brace()/lexi() on an
+ condition without parentheses followed with an overlong comment
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Reproducer:
+
+$ hexdump -C /tmp/short
+00000000 69 66 20 30 3b 65 6c 73 65 2f 2a 0a 0a 0a 0a 0a |if 0;else/*.....|
+00000010 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a |................|
+*
+00000800 0a 0a 2a 2f 78 0a |..*/x.|
+00000806
+
+$ valgrind -- ./indent -o /dev/null /tmp/short
+[...]
+==21830== Invalid read of size 1
+==21830== at 0x40586A: lexi (lexi.c:251)
+==21830== by 0x40198C: search_brace (indent.c:387)
+==21830== by 0x401CC2: indent_main_loop (indent.c:548)
+==21830== by 0x402298: indent (indent.c:758)
+==21830== by 0x402941: indent_single_file (indent.c:1003)
+==21830== by 0x402A0F: indent_all (indent.c:1041)
+==21830== by 0x402BC5: main (indent.c:1122)
+==21830== Address 0x4ab2210 is 0 bytes inside a block of size 2,048 free'd
+==21830== at 0x4847A40: realloc (vg_replace_malloc.c:1649)
+==21830== by 0x408BC0: xrealloc (globs.c:64)
+==21830== by 0x40BF03: need_chars (handletoken.c:89)
+==21830== by 0x401433: sw_buffer (indent.c:149)
+==21830== by 0x401973: search_brace (indent.c:380)
+==21830== by 0x401CC2: indent_main_loop (indent.c:548)
+==21830== by 0x402298: indent (indent.c:758)
+==21830== by 0x402941: indent_single_file (indent.c:1003)
+==21830== by 0x402A0F: indent_all (indent.c:1041)
+==21830== by 0x402BC5: main (indent.c:1122)
+==21830== Block was alloc'd at
+==21830== at 0x4847A40: realloc (vg_replace_malloc.c:1649)
+==21830== by 0x408BC0: xrealloc (globs.c:64)
+==21830== by 0x40BF03: need_chars (handletoken.c:89)
+==21830== by 0x401696: search_brace (indent.c:281)
+==21830== by 0x401CC2: indent_main_loop (indent.c:548)
+==21830== by 0x402298: indent (indent.c:758)
+==21830== by 0x402941: indent_single_file (indent.c:1003)
+==21830== by 0x402A0F: indent_all (indent.c:1041)
+==21830== by 0x402BC5: main (indent.c:1122)
+
+The cause was that need_chars(&save_com, ...) could reallocate save_com.ptr
+pointer keeping a dangling copy of that pointer saved to buf_ptr
+a line above.
+
+Related to CVE-2023-40305
+
+Signed-off-by: Petr Písař <ppisar@redhat.com>
+
+CVE: CVE-2023-40305
+
+Upstream-Status: Backport [https://git.savannah.gnu.org/cgit/indent.git/commit/?id=df4ab2d19e247d059e0025789ba513418073ab6f]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ regression/TEST | 3 +-
+ regression/input/comment-heap-overread.c | 2040 ++++++++++++++++++
+ regression/standard/comment-heap-overread.c | 2042 +++++++++++++++++++
+ src/indent.c | 2 +-
+ 4 files changed, 4085 insertions(+), 2 deletions(-)
+ create mode 100644 regression/input/comment-heap-overread.c
+ create mode 100644 regression/standard/comment-heap-overread.c
+
+diff --git a/regression/TEST b/regression/TEST
+index 56f41d9..a7a6747 100755
+--- a/regression/TEST
++++ b/regression/TEST
+@@ -37,7 +37,8 @@ BUGS="case-label.c one-line-1.c one-line-2.c one-line-3.c \
+ one-line-4.c struct-decl.c sizeof-in-while.c line-break-comment.c \
+ macro.c enum.c elif.c nested.c wrapped-string.c minus_predecrement.c \
+ bug-gnu-33364.c float-constant-suffix.c block-comments.c \
+- no-forced-nl-in-block-init.c hexadecimal_float.c"
++ no-forced-nl-in-block-init.c hexadecimal_float.c \
++ comment-heap-overread.c"
+
+ INDENTSRC="args.c backup.h backup.c dirent_def.h globs.c indent.h \
+ indent.c indent_globs.h io.c lexi.c memcpy.c parse.c pr_comment.c \
+diff --git a/regression/input/comment-heap-overread.c b/regression/input/comment-heap-overread.c
+new file mode 100644
+index 0000000..5b0b172
+--- /dev/null
++++ b/regression/input/comment-heap-overread.c
+@@ -0,0 +1,2040 @@
++if 0;else/*
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++*/x
+diff --git a/regression/standard/comment-heap-overread.c b/regression/standard/comment-heap-overread.c
+new file mode 100644
+index 0000000..e601fb4
+--- /dev/null
++++ b/regression/standard/comment-heap-overread.c
+@@ -0,0 +1,2042 @@
++if 0;
++else /*
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++ */
++ x
+diff --git a/src/indent.c b/src/indent.c
+index 0c2780b..208b48a 100644
+--- a/src/indent.c
++++ b/src/indent.c
+@@ -145,8 +145,8 @@ static void sw_buffer(void)
+ parser_state_tos->search_brace = false;
+ bp_save = buf_ptr;
+ be_save = buf_end;
+- buf_ptr = save_com.ptr;
+ need_chars (&save_com, 1);
++ buf_ptr = save_com.ptr;
+ buf_end = save_com.end;
+ save_com.end = save_com.ptr; /* make save_com empty */
+ }
+--
+2.35.5
diff --git a/meta-openembedded/meta-oe/recipes-extended/indent/indent/CVE-2023-40305_0002.patch b/meta-openembedded/meta-oe/recipes-extended/indent/indent/CVE-2023-40305_0002.patch
new file mode 100644
index 0000000000..d02521bb06
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/indent/indent/CVE-2023-40305_0002.patch
@@ -0,0 +1,4254 @@
+From 2685cc0bef0200733b634932ea7399b6cf91b6d7 Mon Sep 17 00:00:00 2001
+From: Petr Písař <ppisar@redhat.com>
+Date: Thu, 19 Oct 2023 08:42:59 +0000
+Subject: [PATCH] Fix a heap buffer overwrite in search_brace()
+ (CVE-2023-40305)
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+If there was a comment between if-condition and an statement opening
+bracket and the comment size aligned to an indent-internal 1024 B
+buffer for comments, indent attempted to write into a nonallocated
+memory on heap.
+
+$ hexdump -C /tmp/write1
+00000000 69 66 20 30 3b 65 6c 73 65 2f 2a 0a 0a 0a 0a 0a |if 0;else/*.....|
+00000010 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a |................|
+*
+00000800 0a 0a 0a 0a 2a 2f 7b 0a |....*/{.|
+00000808
+
+$ valgrind -- ./indent -o /dev/null /tmp/write1 2>&1 | head -n 23
+==26345== Memcheck, a memory error detector
+==26345== Copyright (C) 2002-2022, and GNU GPL'd, by Julian Seward et al.
+==26345== Using Valgrind-3.21.0 and LibVEX; rerun with -h for copyright info
+==26345== Command: ./indent -o /dev/null /tmp/write1
+==26345==
+==26345== Invalid write of size 1
+==26345== at 0x401558: search_brace (indent.c:232)
+==26345== by 0x401CB2: indent_main_loop (indent.c:548)
+==26345== by 0x402288: indent (indent.c:758)
+==26345== by 0x402931: indent_single_file (indent.c:1003)
+==26345== by 0x4029FF: indent_all (indent.c:1041)
+==26345== by 0x402BA6: main (indent.c:1122)
+==26345== Address 0x4aa7830 is 0 bytes after a block of size 2,048 alloc'd
+==26345== at 0x4847A40: realloc (vg_replace_malloc.c:1649)
+==26345== by 0x408BA1: xrealloc (globs.c:64)
+==26345== by 0x40BEE4: need_chars (handletoken.c:89)
+==26345== by 0x401686: search_brace (indent.c:281)
+==26345== by 0x401CB2: indent_main_loop (indent.c:548)
+==26345== by 0x402288: indent (indent.c:758)
+==26345== by 0x402931: indent_single_file (indent.c:1003)
+==26345== by 0x4029FF: indent_all (indent.c:1041)
+==26345== by 0x402BA6: main (indent.c:1122)
+
+The cause was that the buffer was exhausted by the comment text and no
+space left for the following new-line and curly bracket characters.
+
+This patch fixes it by enlarging the buffer two fit these two
+additional characters.
+
+<https://savannah.gnu.org/bugs/index.php?64503>
+
+Signed-off-by: Petr Písař <ppisar@redhat.com>
+
+CVE: CVE-2023-40305
+
+Upstream-Status: Backport [https://git.savannah.gnu.org/cgit/indent.git/commit/?id=2685cc0bef0200733b634932ea7399b6cf91b6d7]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ regression/TEST | 44 +-
+ regression/input/comment-heap-overwrite.c | 2042 ++++++++++++++++
+ regression/standard/comment-heap-overwrite.c | 2044 +++++++++++++++++
+ .../standard/comment-heap-overwrite.err | 1 +
+ src/indent.c | 1 +
+ 5 files changed, 4111 insertions(+), 21 deletions(-)
+ create mode 100644 regression/input/comment-heap-overwrite.c
+ create mode 100644 regression/standard/comment-heap-overwrite.c
+ create mode 100644 regression/standard/comment-heap-overwrite.err
+
+diff --git a/regression/TEST b/regression/TEST
+index a7a6747..a76c112 100755
+--- a/regression/TEST
++++ b/regression/TEST
+@@ -427,6 +427,7 @@ echo Testing new comment stuff...Done.
+
+
+ echo Testing bad code handling....
++ERR=output/errors
+
+ # print_comment() was reading past the end of the buffer...
+ echo -ne '/*' | $INDENT -npro -st > /dev/null 2>&1
+@@ -444,29 +445,30 @@ then
+ echo >> $ERR
+ fi
+
+-# This ends in a error from indent but it shouldn't coredump.
+-$INDENT -npro input/bug206785.c -o output/bug206785.c 2>output/bug206785.err
++# This ends in an error from indent but it shouldn't coredump.
++for TEST in bug206785 comment-heap-overwrite; do
++ $INDENT -npro input/"$TEST".c -o output/"$TEST".c 2>output/"$TEST".err
+
+-if [ $? -ne 2 ]
+-then
+- printf ERROR: bad return status from indent. | tee -a $ERR
+- echo >> $ERR
+-fi
+-cd output
++ if [ $? -ne 2 ]
++ then
++ printf "ERROR: bad return status from indent for %s.c" "$TEST" | tee -a $ERR
++ echo >> $ERR
++ fi
+
+-for i in bug206785.c bug206785.err
+-do
+- printf ...$i...
+- diff --initial-tab ../standard/$i $i > $i-diffs 2>&1
+- if [ -s $i-diffs ]
+- then
+- printf ERROR: $i failed | tee -a $ERR
+- echo >> $ERR
+- else
+- rm $i-diffs
+- rm $i
+- fi
+- echo
++ for i in "$TEST".c "$TEST".err
++ do
++ printf "...%s..." "$i"
++ diff --initial-tab standard/"$i" output/"$i" > output/"$i"-diffs 2>&1
++ if [ -s output/"$i"-diffs ]
++ then
++ printf "ERROR: %s failed" "$i" | tee -a $ERR
++ echo >> $ERR
++ else
++ rm output/"$i"-diffs
++ rm output/"$i"
++ fi
++ echo
++ done
+ done
+
+ echo Testing bad code handling...Done.
+diff --git a/regression/input/comment-heap-overwrite.c b/regression/input/comment-heap-overwrite.c
+new file mode 100644
+index 0000000..5b1ca6a
+--- /dev/null
++++ b/regression/input/comment-heap-overwrite.c
+@@ -0,0 +1,2042 @@
++if 0;else/*
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++*/{
+diff --git a/regression/standard/comment-heap-overwrite.c b/regression/standard/comment-heap-overwrite.c
+new file mode 100644
+index 0000000..8650d51
+--- /dev/null
++++ b/regression/standard/comment-heap-overwrite.c
+@@ -0,0 +1,2044 @@
++if 0;
++else /*
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++
++ */
++ {
+diff --git a/regression/standard/comment-heap-overwrite.err b/regression/standard/comment-heap-overwrite.err
+new file mode 100644
+index 0000000..fa571c8
+--- /dev/null
++++ b/regression/standard/comment-heap-overwrite.err
+@@ -0,0 +1 @@
++indent: input/comment-heap-overwrite.c:2044: Error:Unexpected end of file
+diff --git a/src/indent.c b/src/indent.c
+index 208b48a..a9f88a2 100644
+--- a/src/indent.c
++++ b/src/indent.c
+@@ -228,6 +228,7 @@ static BOOLEAN search_brace(
+ * a `dump_line' call, thus ensuring that the brace
+ * will go into the right column. */
+
++ need_chars (&save_com, 2);
+ *save_com.end++ = EOL;
+ *save_com.end++ = '{';
+ save_com.len += 2;
+--
+2.35.5
diff --git a/meta-openembedded/meta-oe/recipes-extended/indent/indent_2.2.12.bb b/meta-openembedded/meta-oe/recipes-extended/indent/indent_2.2.12.bb
index 1a7d61abc0..7bf8e406fb 100644
--- a/meta-openembedded/meta-oe/recipes-extended/indent/indent_2.2.12.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/indent/indent_2.2.12.bb
@@ -17,6 +17,9 @@ SRC_URI = "${GNU_MIRROR}/${BPN}/${BP}.tar.gz \
file://0001-Makefile.am-remove-regression-dir.patch \
file://0001-Fix-builds-with-recent-gettext.patch \
file://0001-Remove-dead-paren_level-code.patch \
+ file://CVE-2023-40305_0001.patch \
+ file://CVE-2023-40305_0002.patch \
+ file://0001-Fix-a-heap-buffer-underread-in-set_buf_break.patch \
"
SRC_URI[md5sum] = "4764b6ac98f6654a35da117b8e5e8e14"
SRC_URI[sha256sum] = "e77d68c0211515459b8812118d606812e300097cfac0b4e9fb3472664263bb8b"
diff --git a/meta-openembedded/meta-oe/recipes-extended/libblockdev/files/CVE-2025-6019.patch b/meta-openembedded/meta-oe/recipes-extended/libblockdev/files/CVE-2025-6019.patch
new file mode 100644
index 0000000000..2575578e77
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/libblockdev/files/CVE-2025-6019.patch
@@ -0,0 +1,31 @@
+From b2e9c16c726f62e500241617f8f3a03aa658fbe3 Mon Sep 17 00:00:00 2001
+From: Thomas Blume <Thomas.Blume@suse.com>
+Date: Fri, 16 May 2025 14:27:10 +0200
+Subject: [PATCH] Don't allow suid and dev set on fs resize
+
+Fixes: CVE-2025-6019
+
+CVE: CVE-2025-6019
+Upstream-Status: Backport [ https://github.com/storaged-project/libblockdev/commit/46b54414f66e965e3c37f8f51e621f96258ae22e ]
+
+Signed-off-by: Changqing Li <changqing.li@windriver.com>
+---
+ src/plugins/fs/generic.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/plugins/fs/generic.c b/src/plugins/fs/generic.c
+index 2b2180aa..60f7d75e 100644
+--- a/src/plugins/fs/generic.c
++++ b/src/plugins/fs/generic.c
+@@ -661,7 +661,7 @@ static gchar* fs_mount (const gchar *device, gchar *fstype, gboolean read_only,
+ "Failed to create temporary directory for mounting '%s'.", device);
+ return NULL;
+ }
+- ret = bd_fs_mount (device, mountpoint, fstype, read_only ? "ro" : NULL, NULL, &l_error);
++ ret = bd_fs_mount (device, mountpoint, fstype, read_only ? "nosuid,nodev,ro" : "nosuid,nodev", NULL, &l_error);
+ if (!ret) {
+ g_propagate_prefixed_error (error, l_error, "Failed to mount '%s': ", device);
+ g_rmdir (mountpoint);
+--
+2.34.1
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/libblockdev/libblockdev_3.1.1.bb b/meta-openembedded/meta-oe/recipes-extended/libblockdev/libblockdev_3.1.1.bb
index 1ad8036d7b..a7e7162c30 100644
--- a/meta-openembedded/meta-oe/recipes-extended/libblockdev/libblockdev_3.1.1.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/libblockdev/libblockdev_3.1.1.bb
@@ -14,6 +14,7 @@ DEPENDS = "autoconf-archive-native glib-2.0 kmod udev libnvme"
SRC_URI = "git://github.com/storaged-project/libblockdev;branch=3.1.x-devel;protocol=https \
file://0001-fix-pythondir-for-multilib-when-cross-compiling.patch \
+ file://CVE-2025-6019.patch \
"
SRCREV = "68aaff5556afe26be749c29a2b7cbd714dce3050"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-oe/recipes-extended/libconfig/libconfig_1.7.3.bb b/meta-openembedded/meta-oe/recipes-extended/libconfig/libconfig_1.7.3.bb
index 6382569923..6509271076 100644
--- a/meta-openembedded/meta-oe/recipes-extended/libconfig/libconfig_1.7.3.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/libconfig/libconfig_1.7.3.bb
@@ -7,7 +7,7 @@ SECTION = "libs"
LICENSE = "LGPL-2.1-only"
LIC_FILES_CHKSUM = "file://COPYING.LIB;md5=fad9b3332be894bab9bc501572864b29"
-SRC_URI = "https://hyperrealm.github.io/libconfig/dist/libconfig-${PV}.tar.gz"
+SRC_URI = "https://github.com/hyperrealm/libconfig/releases/download/v${PV}/libconfig-${PV}.tar.gz"
UPSTREAM_CHECK_URI = "https://github.com/hyperrealm/libconfig/releases"
UPSTREAM_CHECK_REGEX = "Version (?P<pver>\d+(\.\d+)+)"
diff --git a/meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus/CVE-2024-10918-01.patch b/meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus/CVE-2024-10918-01.patch
new file mode 100644
index 0000000000..f50bee68e8
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus/CVE-2024-10918-01.patch
@@ -0,0 +1,177 @@
+From df79a02feb253c0a9a009bcdbb21e47581315111 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?St=C3=A9phane=20Raimbault?= <stephane.raimbault@gmail.com>
+Date: Fri, 18 Oct 2024 10:47:14 +0200
+Subject: [PATCH] Check length passed to modbus_reply (write_bit)
+
+The modbus_reply function is designed to receive arguments
+from modbus_receive. This patch avoid a wrong use of memcpy if
+the user chooses to inject a bad length argument.
+
+Thank you Nozomi Networks Labs Advisory for the report.
+
+CVE: CVE-2024-10918
+Upstream-Status: Backport [https://github.com/stephane/libmodbus/commit/df79a02feb253c0a9a009bcdbb21e47581315111]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/modbus.c | 54 +++++++++++++++++++++++++---------------
+ tests/unit-test-client.c | 9 +++++--
+ tests/unit-test-server.c | 16 +++++++++---
+ tests/unit-test.h.in | 1 +
+ 4 files changed, 55 insertions(+), 25 deletions(-)
+
+diff --git a/src/modbus.c b/src/modbus.c
+index 5a9b867..33086ec 100644
+--- a/src/modbus.c
++++ b/src/modbus.c
+@@ -897,24 +897,37 @@ int modbus_reply(modbus_t *ctx,
+ FALSE,
+ "Illegal data address 0x%0X in write_bit\n",
+ address);
++ break;
++ }
++
++ /* This check is only done here to ensure using memcpy is safe. */
++ rsp_length = compute_response_length_from_request(ctx, (uint8_t *) req);
++ if (rsp_length != req_length) {
++ /* Bad use of modbus_reply */
++ rsp_length = response_exception(ctx,
++ &sft,
++ MODBUS_EXCEPTION_ILLEGAL_DATA_VALUE,
++ rsp,
++ FALSE,
++ "Invalid request length (%d)\n",
++ req_length);
++ break;
++ }
++
++ int data = (req[offset + 3] << 8) + req[offset + 4];
++ if (data == 0xFF00 || data == 0x0) {
++ mb_mapping->tab_bits[mapping_address] = data ? ON : OFF;
++ memcpy(rsp, req, rsp_length);
+ } else {
+- int data = (req[offset + 3] << 8) + req[offset + 4];
+-
+- if (data == 0xFF00 || data == 0x0) {
+- mb_mapping->tab_bits[mapping_address] = data ? ON : OFF;
+- memcpy(rsp, req, req_length);
+- rsp_length = req_length;
+- } else {
+- rsp_length = response_exception(
+- ctx,
+- &sft,
+- MODBUS_EXCEPTION_ILLEGAL_DATA_VALUE,
+- rsp,
+- FALSE,
+- "Illegal data value 0x%0X in write_bit request at address %0X\n",
+- data,
+- address);
+- }
++ rsp_length = response_exception(
++ ctx,
++ &sft,
++ MODBUS_EXCEPTION_ILLEGAL_DATA_VALUE,
++ rsp,
++ FALSE,
++ "Illegal data value 0x%0X in write_bit request at address %0X\n",
++ data,
++ address);
+ }
+ } break;
+ case MODBUS_FC_WRITE_SINGLE_REGISTER: {
+@@ -1127,8 +1140,8 @@ int modbus_reply(modbus_t *ctx,
+ break;
+ }
+
+- /* Suppress any responses in RTU when the request was a broadcast, excepted when quirk
+- * is enabled. */
++ /* Suppress any responses in RTU when the request was a broadcast, excepted when
++ * quirk is enabled. */
+ if (ctx->backend->backend_type == _MODBUS_BACKEND_TYPE_RTU &&
+ slave == MODBUS_BROADCAST_ADDRESS &&
+ !(ctx->quirks & MODBUS_QUIRK_REPLY_TO_BROADCAST)) {
+@@ -1821,7 +1834,8 @@ int modbus_set_byte_timeout(modbus_t *ctx, uint32_t to_sec, uint32_t to_usec)
+ return 0;
+ }
+
+-/* Get the timeout interval used by the server to wait for an indication from a client */
++/* Get the timeout interval used by the server to wait for an indication from a client
++ */
+ int modbus_get_indication_timeout(modbus_t *ctx, uint32_t *to_sec, uint32_t *to_usec)
+ {
+ if (ctx == NULL) {
+diff --git a/tests/unit-test-client.c b/tests/unit-test-client.c
+index a441766..50859f8 100644
+--- a/tests/unit-test-client.c
++++ b/tests/unit-test-client.c
+@@ -400,11 +400,11 @@ int main(int argc, char *argv[])
+ ASSERT_TRUE(rc == -1 && errno == EMBXILADD, "");
+
+ rc = modbus_write_bits(ctx, 0, 1, tab_rp_bits);
+- printf("* modbus_write_coils (0): ");
++ printf("* modbus_write_bits (0): ");
+ ASSERT_TRUE(rc == -1 && errno == EMBXILADD, "");
+
+ rc = modbus_write_bits(ctx, UT_BITS_ADDRESS + UT_BITS_NB, UT_BITS_NB, tab_rp_bits);
+- printf("* modbus_write_coils (max): ");
++ printf("* modbus_write_bits (max): ");
+ ASSERT_TRUE(rc == -1 && errno == EMBXILADD, "");
+
+ rc = modbus_write_register(ctx, 0, tab_rp_registers[0]);
+@@ -500,6 +500,11 @@ int main(int argc, char *argv[])
+ rc = modbus_set_slave(ctx, old_slave);
+ ASSERT_TRUE(rc == 0, "Uanble to restore slave value")
+
++ /** BAD USE OF REPLY FUNCTION **/
++ rc = modbus_write_bit(ctx, UT_BITS_ADDRESS_INVALID_REQUEST_LENGTH, ON);
++ printf("* modbus_write_bit (triggers invalid reply): ");
++ ASSERT_TRUE(rc == -1 && errno == EMBXILVAL, "");
++
+ /** SLAVE REPLY **/
+
+ printf("\nTEST SLAVE REPLY:\n");
+diff --git a/tests/unit-test-server.c b/tests/unit-test-server.c
+index 561d64d..8e28124 100644
+--- a/tests/unit-test-server.c
++++ b/tests/unit-test-server.c
+@@ -150,9 +150,8 @@ int main(int argc, char *argv[])
+ break;
+ }
+
+- /* Special server behavior to test client */
+- if (query[header_length] == 0x03) {
+- /* Read holding registers */
++ /** Special server behavior to test client **/
++ if (query[header_length] == MODBUS_FC_READ_HOLDING_REGISTERS) {
+
+ if (MODBUS_GET_INT16_FROM_INT8(query, header_length + 3) ==
+ UT_REGISTERS_NB_SPECIAL) {
+@@ -204,6 +203,17 @@ int main(int argc, char *argv[])
+ }
+ continue;
+ }
++
++ } else if (query[header_length] == MODBUS_FC_WRITE_SINGLE_COIL) {
++ if (MODBUS_GET_INT16_FROM_INT8(query, header_length + 1) ==
++ UT_BITS_ADDRESS_INVALID_REQUEST_LENGTH) {
++ // The valid length is lengths of header + checkum + FC + address + value
++ // (max 12)
++ rc = 34;
++ printf("Special modbus_write_bit detected. Inject a wrong rc value (%d) "
++ "in modbus_reply\n",
++ rc);
++ }
+ }
+
+ rc = modbus_reply(ctx, query, rc, mb_mapping);
+diff --git a/tests/unit-test.h.in b/tests/unit-test.h.in
+index 5e379bb..21d09e3 100644
+--- a/tests/unit-test.h.in
++++ b/tests/unit-test.h.in
+@@ -30,6 +30,7 @@
+ const uint16_t UT_BITS_ADDRESS = 0x130;
+ const uint16_t UT_BITS_NB = 0x25;
+ const uint8_t UT_BITS_TAB[] = { 0xCD, 0x6B, 0xB2, 0x0E, 0x1B };
++const uint16_t UT_BITS_ADDRESS_INVALID_REQUEST_LENGTH = UT_BITS_ADDRESS + 2;
+
+ const uint16_t UT_INPUT_BITS_ADDRESS = 0x1C4;
+ const uint16_t UT_INPUT_BITS_NB = 0x16;
diff --git a/meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus/CVE-2024-10918-02.patch b/meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus/CVE-2024-10918-02.patch
new file mode 100644
index 0000000000..16b9ba72c5
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus/CVE-2024-10918-02.patch
@@ -0,0 +1,121 @@
+From d8a971e04d52be16bf405b51d934a30b8aa3f2c3 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?St=C3=A9phane=20Raimbault?= <stephane.raimbault@gmail.com>
+Date: Sun, 20 Oct 2024 18:02:22 +0200
+Subject: [PATCH] Check length passed to modbus_reply (write_register)
+
+Related to df79a02feb253c.
+
+CVE: CVE-2024-10918
+Upstream-Status: Backport [https://github.com/stephane/libmodbus/commit/d8a971e04d52be16bf405b51d934a30b8aa3f2c3]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/modbus.c | 38 ++++++++++++++++++++++++++------------
+ tests/unit-test-client.c | 6 +++++-
+ tests/unit-test-server.c | 13 +++++++++++--
+ 3 files changed, 42 insertions(+), 15 deletions(-)
+
+diff --git a/src/modbus.c b/src/modbus.c
+index 33086ec..fe192a7 100644
+--- a/src/modbus.c
++++ b/src/modbus.c
+@@ -904,13 +904,14 @@ int modbus_reply(modbus_t *ctx,
+ rsp_length = compute_response_length_from_request(ctx, (uint8_t *) req);
+ if (rsp_length != req_length) {
+ /* Bad use of modbus_reply */
+- rsp_length = response_exception(ctx,
+- &sft,
+- MODBUS_EXCEPTION_ILLEGAL_DATA_VALUE,
+- rsp,
+- FALSE,
+- "Invalid request length (%d)\n",
+- req_length);
++ rsp_length =
++ response_exception(ctx,
++ &sft,
++ MODBUS_EXCEPTION_ILLEGAL_DATA_VALUE,
++ rsp,
++ FALSE,
++ "Invalid request length used in modbus_reply (%d)\n",
++ req_length);
+ break;
+ }
+
+@@ -942,13 +943,26 @@ int modbus_reply(modbus_t *ctx,
+ FALSE,
+ "Illegal data address 0x%0X in write_register\n",
+ address);
+- } else {
+- int data = (req[offset + 3] << 8) + req[offset + 4];
++ break;
++ }
+
+- mb_mapping->tab_registers[mapping_address] = data;
+- memcpy(rsp, req, req_length);
+- rsp_length = req_length;
++ rsp_length = compute_response_length_from_request(ctx, (uint8_t *) req);
++ if (rsp_length != req_length) {
++ /* Bad use of modbus_reply */
++ rsp_length =
++ response_exception(ctx,
++ &sft,
++ MODBUS_EXCEPTION_ILLEGAL_DATA_VALUE,
++ rsp,
++ FALSE,
++ "Invalid request length used in modbus_reply (%d)\n",
++ req_length);
++ break;
+ }
++ int data = (req[offset + 3] << 8) + req[offset + 4];
++
++ mb_mapping->tab_registers[mapping_address] = data;
++ memcpy(rsp, req, rsp_length);
+ } break;
+ case MODBUS_FC_WRITE_MULTIPLE_COILS: {
+ int nb = (req[offset + 3] << 8) + req[offset + 4];
+diff --git a/tests/unit-test-client.c b/tests/unit-test-client.c
+index 50859f8..84d5840 100644
+--- a/tests/unit-test-client.c
++++ b/tests/unit-test-client.c
+@@ -498,13 +498,17 @@ int main(int argc, char *argv[])
+
+ modbus_disable_quirks(ctx, MODBUS_QUIRK_MAX_SLAVE);
+ rc = modbus_set_slave(ctx, old_slave);
+- ASSERT_TRUE(rc == 0, "Uanble to restore slave value")
++ ASSERT_TRUE(rc == 0, "Unable to restore slave value")
+
+ /** BAD USE OF REPLY FUNCTION **/
+ rc = modbus_write_bit(ctx, UT_BITS_ADDRESS_INVALID_REQUEST_LENGTH, ON);
+ printf("* modbus_write_bit (triggers invalid reply): ");
+ ASSERT_TRUE(rc == -1 && errno == EMBXILVAL, "");
+
++ rc = modbus_write_register(ctx, UT_REGISTERS_ADDRESS_SPECIAL, 0x42);
++ printf("* modbus_write_register (triggers invalid reply): ");
++ ASSERT_TRUE(rc == -1 && errno == EMBXILVAL, "");
++
+ /** SLAVE REPLY **/
+
+ printf("\nTEST SLAVE REPLY:\n");
+diff --git a/tests/unit-test-server.c b/tests/unit-test-server.c
+index 8e28124..fc7ceb3 100644
+--- a/tests/unit-test-server.c
++++ b/tests/unit-test-server.c
+@@ -210,8 +210,17 @@ int main(int argc, char *argv[])
+ // The valid length is lengths of header + checkum + FC + address + value
+ // (max 12)
+ rc = 34;
+- printf("Special modbus_write_bit detected. Inject a wrong rc value (%d) "
+- "in modbus_reply\n",
++ printf(
++ "Special modbus_write_bit detected. Inject a wrong length value (%d) "
++ "in modbus_reply\n",
++ rc);
++ }
++ } else if (query[header_length] == MODBUS_FC_WRITE_SINGLE_REGISTER) {
++ if (MODBUS_GET_INT16_FROM_INT8(query, header_length + 1) ==
++ UT_REGISTERS_ADDRESS_SPECIAL) {
++ rc = 45;
++ printf("Special modbus_write_register detected. Inject a wrong length "
++ "value (%d) in modbus_reply\n",
+ rc);
+ }
+ }
diff --git a/meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus/CVE-2024-10918-03.patch b/meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus/CVE-2024-10918-03.patch
new file mode 100644
index 0000000000..6ae9305b33
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus/CVE-2024-10918-03.patch
@@ -0,0 +1,84 @@
+From 7ea85f1b41f7066849f4bde7c0a3549b1e087bbf Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?St=C3=A9phane=20Raimbault?= <stephane.raimbault@gmail.com>
+Date: Sun, 20 Oct 2024 18:23:26 +0200
+Subject: [PATCH] Small cleanups of unit test server
+
+CVE: CVE-2024-10918
+Upstream-Status: Backport [https://github.com/stephane/libmodbus/commit/7ea85f1b41f7066849f4bde7c0a3549b1e087bbf]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ tests/unit-test-server.c | 29 ++++++++++++-----------------
+ 1 file changed, 12 insertions(+), 17 deletions(-)
+
+diff --git a/tests/unit-test-server.c b/tests/unit-test-server.c
+index fc7ceb3..bb25ba4 100644
+--- a/tests/unit-test-server.c
++++ b/tests/unit-test-server.c
+@@ -150,21 +150,21 @@ int main(int argc, char *argv[])
+ break;
+ }
+
++ uint8_t function = query[header_length];
++ uint16_t address = MODBUS_GET_INT16_FROM_INT8(query, header_length + 1);
++
+ /** Special server behavior to test client **/
+- if (query[header_length] == MODBUS_FC_READ_HOLDING_REGISTERS) {
+-
++ if (function == MODBUS_FC_READ_HOLDING_REGISTERS) {
+ if (MODBUS_GET_INT16_FROM_INT8(query, header_length + 3) ==
+ UT_REGISTERS_NB_SPECIAL) {
+ printf("Set an incorrect number of values\n");
+ MODBUS_SET_INT16_TO_INT8(
+ query, header_length + 3, UT_REGISTERS_NB_SPECIAL - 1);
+- } else if (MODBUS_GET_INT16_FROM_INT8(query, header_length + 1) ==
+- UT_REGISTERS_ADDRESS_SPECIAL) {
++ } else if (address == UT_REGISTERS_ADDRESS_SPECIAL) {
+ printf("Reply to this special register address by an exception\n");
+ modbus_reply_exception(ctx, query, MODBUS_EXCEPTION_SLAVE_OR_SERVER_BUSY);
+ continue;
+- } else if (MODBUS_GET_INT16_FROM_INT8(query, header_length + 1) ==
+- UT_REGISTERS_ADDRESS_INVALID_TID_OR_SLAVE) {
++ } else if (address == UT_REGISTERS_ADDRESS_INVALID_TID_OR_SLAVE) {
+ const int RAW_REQ_LENGTH = 5;
+ uint8_t raw_req[] = {(use_backend == RTU) ? INVALID_SERVER_ID : 0xFF,
+ 0x03,
+@@ -175,12 +175,10 @@ int main(int argc, char *argv[])
+ printf("Reply with an invalid TID or slave\n");
+ modbus_send_raw_request(ctx, raw_req, RAW_REQ_LENGTH * sizeof(uint8_t));
+ continue;
+- } else if (MODBUS_GET_INT16_FROM_INT8(query, header_length + 1) ==
+- UT_REGISTERS_ADDRESS_SLEEP_500_MS) {
++ } else if (address == UT_REGISTERS_ADDRESS_SLEEP_500_MS) {
+ printf("Sleep 0.5 s before replying\n");
+ usleep(500000);
+- } else if (MODBUS_GET_INT16_FROM_INT8(query, header_length + 1) ==
+- UT_REGISTERS_ADDRESS_BYTE_SLEEP_5_MS) {
++ } else if (address == UT_REGISTERS_ADDRESS_BYTE_SLEEP_5_MS) {
+ /* Test low level only available in TCP mode */
+ /* Catch the reply and send reply byte a byte */
+ uint8_t req[] = "\x00\x1C\x00\x00\x00\x05\xFF\x03\x02\x00\x00";
+@@ -203,10 +201,8 @@ int main(int argc, char *argv[])
+ }
+ continue;
+ }
+-
+- } else if (query[header_length] == MODBUS_FC_WRITE_SINGLE_COIL) {
+- if (MODBUS_GET_INT16_FROM_INT8(query, header_length + 1) ==
+- UT_BITS_ADDRESS_INVALID_REQUEST_LENGTH) {
++ } else if (function == MODBUS_FC_WRITE_SINGLE_COIL) {
++ if (address == UT_BITS_ADDRESS_INVALID_REQUEST_LENGTH) {
+ // The valid length is lengths of header + checkum + FC + address + value
+ // (max 12)
+ rc = 34;
+@@ -215,9 +211,8 @@ int main(int argc, char *argv[])
+ "in modbus_reply\n",
+ rc);
+ }
+- } else if (query[header_length] == MODBUS_FC_WRITE_SINGLE_REGISTER) {
+- if (MODBUS_GET_INT16_FROM_INT8(query, header_length + 1) ==
+- UT_REGISTERS_ADDRESS_SPECIAL) {
++ } else if (function == MODBUS_FC_WRITE_SINGLE_REGISTER) {
++ if (address == UT_REGISTERS_ADDRESS_SPECIAL) {
+ rc = 45;
+ printf("Special modbus_write_register detected. Inject a wrong length "
+ "value (%d) in modbus_reply\n",
diff --git a/meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus/CVE-2024-10918-04.patch b/meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus/CVE-2024-10918-04.patch
new file mode 100644
index 0000000000..4538054193
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus/CVE-2024-10918-04.patch
@@ -0,0 +1,239 @@
+From 81bf713cf029bfa5b5da87b945c1e8817b4398f9 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?St=C3=A9phane=20Raimbault?= <stephane.raimbault@gmail.com>
+Date: Mon, 21 Oct 2024 17:32:39 +0200
+Subject: [PATCH] Fix request length check in modbus_reply in RTU
+
+- rename internal *_prepare_response_tid to *_get_response_tid
+- change signature, don't need req length anymore
+- remove misleading modification of req_length
+- check of req length before use in memcpy for mask write register
+
+Related to df79a02feb253c0a9a009bcdbb21e47581315111
+
+CVE: CVE-2024-10918
+Upstream-Status: Backport [https://github.com/stephane/libmodbus/commit/81bf713cf029bfa5b5da87b945c1e8817b4398f9]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/modbus-private.h | 2 +-
+ src/modbus-rtu.c | 5 ++--
+ src/modbus-tcp.c | 6 ++--
+ src/modbus.c | 71 ++++++++++++++++++++++++++++----------------
+ 4 files changed, 52 insertions(+), 32 deletions(-)
+
+diff --git a/src/modbus-private.h b/src/modbus-private.h
+index 6cd3424..ea83187 100644
+--- a/src/modbus-private.h
++++ b/src/modbus-private.h
+@@ -75,7 +75,7 @@ typedef struct _modbus_backend {
+ int (*build_request_basis)(
+ modbus_t *ctx, int function, int addr, int nb, uint8_t *req);
+ int (*build_response_basis)(sft_t *sft, uint8_t *rsp);
+- int (*prepare_response_tid)(const uint8_t *req, int *req_length);
++ int (*get_response_tid)(const uint8_t *req);
+ int (*send_msg_pre)(uint8_t *req, int req_length);
+ ssize_t (*send)(modbus_t *ctx, const uint8_t *req, int req_length);
+ int (*receive)(modbus_t *ctx, uint8_t *req);
+diff --git a/src/modbus-rtu.c b/src/modbus-rtu.c
+index b774923..8b5ee08 100644
+--- a/src/modbus-rtu.c
++++ b/src/modbus-rtu.c
+@@ -129,9 +129,8 @@ static uint16_t crc16(uint8_t *buffer, uint16_t buffer_length)
+ return (crc_hi << 8 | crc_lo);
+ }
+
+-static int _modbus_rtu_prepare_response_tid(const uint8_t *req, int *req_length)
++static int _modbus_rtu_get_response_tid(const uint8_t *req)
+ {
+- (*req_length) -= _MODBUS_RTU_CHECKSUM_LENGTH;
+ /* No TID */
+ return 0;
+ }
+@@ -1187,7 +1186,7 @@ const modbus_backend_t _modbus_rtu_backend = {
+ _modbus_set_slave,
+ _modbus_rtu_build_request_basis,
+ _modbus_rtu_build_response_basis,
+- _modbus_rtu_prepare_response_tid,
++ _modbus_rtu_get_response_tid,
+ _modbus_rtu_send_msg_pre,
+ _modbus_rtu_send,
+ _modbus_rtu_receive,
+diff --git a/src/modbus-tcp.c b/src/modbus-tcp.c
+index 733a4a9..60ac6b4 100644
+--- a/src/modbus-tcp.c
++++ b/src/modbus-tcp.c
+@@ -151,7 +151,7 @@ static int _modbus_tcp_build_response_basis(sft_t *sft, uint8_t *rsp)
+ return _MODBUS_TCP_PRESET_RSP_LENGTH;
+ }
+
+-static int _modbus_tcp_prepare_response_tid(const uint8_t *req, int *req_length)
++static int _modbus_tcp_get_response_tid(const uint8_t *req)
+ {
+ return (req[0] << 8) + req[1];
+ }
+@@ -812,7 +812,7 @@ const modbus_backend_t _modbus_tcp_backend = {
+ _modbus_set_slave,
+ _modbus_tcp_build_request_basis,
+ _modbus_tcp_build_response_basis,
+- _modbus_tcp_prepare_response_tid,
++ _modbus_tcp_get_response_tid,
+ _modbus_tcp_send_msg_pre,
+ _modbus_tcp_send,
+ _modbus_tcp_receive,
+@@ -835,7 +835,7 @@ const modbus_backend_t _modbus_tcp_pi_backend = {
+ _modbus_set_slave,
+ _modbus_tcp_build_request_basis,
+ _modbus_tcp_build_response_basis,
+- _modbus_tcp_prepare_response_tid,
++ _modbus_tcp_get_response_tid,
+ _modbus_tcp_send_msg_pre,
+ _modbus_tcp_send,
+ _modbus_tcp_receive,
+diff --git a/src/modbus.c b/src/modbus.c
+index fe192a7..e3737bb 100644
+--- a/src/modbus.c
++++ b/src/modbus.c
+@@ -125,7 +125,7 @@ int modbus_flush(modbus_t *ctx)
+ return rc;
+ }
+
+-/* Computes the length of the expected response */
++/* Computes the length of the expected response including checksum */
+ static unsigned int compute_response_length_from_request(modbus_t *ctx, uint8_t *req)
+ {
+ int length;
+@@ -386,8 +386,7 @@ int _modbus_receive_msg(modbus_t *ctx, uint8_t *msg, msg_type_t msg_type)
+ length_to_read = ctx->backend->header_length + 1;
+
+ if (msg_type == MSG_INDICATION) {
+- /* Wait for a message, we don't know when the message will be
+- * received */
++ /* Wait for a message, we don't know when the message will be received */
+ if (ctx->indication_timeout.tv_sec == 0 && ctx->indication_timeout.tv_usec == 0) {
+ /* By default, the indication timeout isn't set */
+ p_tv = NULL;
+@@ -799,7 +798,7 @@ int modbus_reply(modbus_t *ctx,
+
+ sft.slave = slave;
+ sft.function = function;
+- sft.t_id = ctx->backend->prepare_response_tid(req, &req_length);
++ sft.t_id = ctx->backend->get_response_tid(req);
+
+ /* Data are flushed on illegal number of values errors. */
+ switch (function) {
+@@ -895,7 +894,7 @@ int modbus_reply(modbus_t *ctx,
+ MODBUS_EXCEPTION_ILLEGAL_DATA_ADDRESS,
+ rsp,
+ FALSE,
+- "Illegal data address 0x%0X in write_bit\n",
++ "Illegal data address 0x%0X in write bit\n",
+ address);
+ break;
+ }
+@@ -904,20 +903,26 @@ int modbus_reply(modbus_t *ctx,
+ rsp_length = compute_response_length_from_request(ctx, (uint8_t *) req);
+ if (rsp_length != req_length) {
+ /* Bad use of modbus_reply */
+- rsp_length =
+- response_exception(ctx,
+- &sft,
+- MODBUS_EXCEPTION_ILLEGAL_DATA_VALUE,
+- rsp,
+- FALSE,
+- "Invalid request length used in modbus_reply (%d)\n",
+- req_length);
++ rsp_length = response_exception(
++ ctx,
++ &sft,
++ MODBUS_EXCEPTION_ILLEGAL_DATA_VALUE,
++ rsp,
++ FALSE,
++ "Invalid request length in modbus_reply to write bit (%d)\n",
++ req_length);
+ break;
+ }
+
++ /* Don't copy the CRC, if any, it will be computed later (even if identical to the
++ * request) */
++ rsp_length -= ctx->backend->checksum_length;
++
+ int data = (req[offset + 3] << 8) + req[offset + 4];
+ if (data == 0xFF00 || data == 0x0) {
++ /* Apply the change to mapping */
+ mb_mapping->tab_bits[mapping_address] = data ? ON : OFF;
++ /* Prepare response */
+ memcpy(rsp, req, rsp_length);
+ } else {
+ rsp_length = response_exception(
+@@ -949,19 +954,21 @@ int modbus_reply(modbus_t *ctx,
+ rsp_length = compute_response_length_from_request(ctx, (uint8_t *) req);
+ if (rsp_length != req_length) {
+ /* Bad use of modbus_reply */
+- rsp_length =
+- response_exception(ctx,
+- &sft,
+- MODBUS_EXCEPTION_ILLEGAL_DATA_VALUE,
+- rsp,
+- FALSE,
+- "Invalid request length used in modbus_reply (%d)\n",
+- req_length);
++ rsp_length = response_exception(
++ ctx,
++ &sft,
++ MODBUS_EXCEPTION_ILLEGAL_DATA_VALUE,
++ rsp,
++ FALSE,
++ "Invalid request length in modbus_reply to write register (%d)\n",
++ req_length);
+ break;
+ }
+ int data = (req[offset + 3] << 8) + req[offset + 4];
+
+ mb_mapping->tab_registers[mapping_address] = data;
++
++ rsp_length -= ctx->backend->checksum_length;
+ memcpy(rsp, req, rsp_length);
+ } break;
+ case MODBUS_FC_WRITE_MULTIPLE_COILS: {
+@@ -1082,8 +1089,23 @@ int modbus_reply(modbus_t *ctx,
+
+ data = (data & and) | (or &(~and));
+ mb_mapping->tab_registers[mapping_address] = data;
+- memcpy(rsp, req, req_length);
+- rsp_length = req_length;
++
++ rsp_length = compute_response_length_from_request(ctx, (uint8_t *) req);
++ if (rsp_length != req_length) {
++ /* Bad use of modbus_reply */
++ rsp_length = response_exception(ctx,
++ &sft,
++ MODBUS_EXCEPTION_ILLEGAL_DATA_VALUE,
++ rsp,
++ FALSE,
++ "Invalid request length in modbus_reply "
++ "to mask write register (%d)\n",
++ req_length);
++ break;
++ }
++
++ rsp_length -= ctx->backend->checksum_length;
++ memcpy(rsp, req, rsp_length);
+ }
+ } break;
+ case MODBUS_FC_WRITE_AND_READ_REGISTERS: {
+@@ -1171,7 +1193,6 @@ int modbus_reply_exception(modbus_t *ctx, const uint8_t *req, unsigned int excep
+ int function;
+ uint8_t rsp[MAX_MESSAGE_LENGTH];
+ int rsp_length;
+- int dummy_length = 99;
+ sft_t sft;
+
+ if (ctx == NULL) {
+@@ -1185,7 +1206,7 @@ int modbus_reply_exception(modbus_t *ctx, const uint8_t *req, unsigned int excep
+
+ sft.slave = slave;
+ sft.function = function + 0x80;
+- sft.t_id = ctx->backend->prepare_response_tid(req, &dummy_length);
++ sft.t_id = ctx->backend->get_response_tid(req);
+ rsp_length = ctx->backend->build_response_basis(&sft, rsp);
+
+ /* Positive exception code */
diff --git a/meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus_3.1.10.bb b/meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus_3.1.10.bb
index 9e17f91669..853abced29 100644
--- a/meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus_3.1.10.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/libmodbus/libmodbus_3.1.10.bb
@@ -6,7 +6,13 @@ SECTION = "libs"
LICENSE = "LGPL-2.1-or-later"
LIC_FILES_CHKSUM = "file://COPYING.LESSER;md5=4fbd65380cdd255951079008b364516c"
-SRC_URI = "git://github.com/stephane/libmodbus;branch=master;protocol=https"
+SRC_URI = " \
+ git://github.com/stephane/libmodbus;branch=master;protocol=https \
+ file://CVE-2024-10918-01.patch \
+ file://CVE-2024-10918-02.patch \
+ file://CVE-2024-10918-03.patch \
+ file://CVE-2024-10918-04.patch \
+"
SRCREV = "2cbafa3113e276c3697d297f68e88d112b53174d"
S = "${WORKDIR}/git"
@@ -15,3 +21,6 @@ inherit autotools pkgconfig
PACKAGECONFIG ??= ""
PACKAGECONFIG[test] = "--enable-tests,--disable-tests,,"
+
+CVE_STATUS[CVE-2023-26793] = "disputed: The buffer overflow concerns unit-test-client and it's intentional."
+CVE_STATUS[CVE-2024-34244] = "disputed: This issue is invalid and only found a bug in the fuzzing driver"
diff --git a/meta-openembedded/meta-oe/recipes-extended/lprng/lprng_3.8.C.bb b/meta-openembedded/meta-oe/recipes-extended/lprng/lprng_3.8.C.bb
index 73e4eac3dd..cd9d9e8a36 100644
--- a/meta-openembedded/meta-oe/recipes-extended/lprng/lprng_3.8.C.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/lprng/lprng_3.8.C.bb
@@ -11,7 +11,9 @@ SRC_URI[sha256sum] = "694a1747a96385b89e93f43343bf35cee5c8c73353a83814106911c99f
inherit autotools gettext
-EXTRA_OECONF = "--disable-ssl --disable-kerberos --enable-force_localhost"
+EXTRA_OECONF = "--disable-ssl --disable-kerberos --enable-force_localhost \
+ CHOWN=${base_bindir}/chown CHGRP=${base_bindir}/chgrp \
+ OPENSSL=${bindir}/openssl PRUTIL=${bindir}/pr"
FILES:${PN}-dbg += "${libdir}/lprng/filters/.debug"
# configure: WARNING: Program 'clear' is not found. Set environment CLEAR=no if you do not want to use it
diff --git a/meta-openembedded/meta-oe/recipes-extended/minifi-cpp/files/CVE-2025-6140.patch b/meta-openembedded/meta-oe/recipes-extended/minifi-cpp/files/CVE-2025-6140.patch
new file mode 100644
index 0000000000..3707d9e9c4
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/minifi-cpp/files/CVE-2025-6140.patch
@@ -0,0 +1,35 @@
+From 10320184df1eb4638e253a34b1eb44ce78954094 Mon Sep 17 00:00:00 2001
+From: Gabi Melman <gmelman1@gmail.com>
+Date: Mon, 17 Mar 2025 15:46:31 +0200
+Subject: [PATCH] Fixed issue #3360 (#3361)
+
+CVE: CVE-2025-6140
+Upstream-Status: Backport [https://github.com/gabime/spdlog/commit/10320184df1eb4638e253a34b1eb44ce78954094]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ include/spdlog/pattern_formatter-inl.h | 5 ++++-
+ 1 file changed, 4 insertions(+), 1 deletion(-)
+
+diff --git a/include/spdlog/pattern_formatter-inl.h b/include/spdlog/pattern_formatter-inl.h
+index b53d8051..fd408ed5 100644
+--- a/include/spdlog/pattern_formatter-inl.h
++++ b/include/spdlog/pattern_formatter-inl.h
+@@ -65,6 +65,9 @@ public:
+ pad_it(remaining_pad_);
+ } else if (padinfo_.truncate_) {
+ long new_size = static_cast<long>(dest_.size()) + remaining_pad_;
++ if (new_size < 0) {
++ new_size = 0;
++ }
+ dest_.resize(static_cast<size_t>(new_size));
+ }
+ }
+@@ -259,7 +262,7 @@ public:
+ : flag_formatter(padinfo) {}
+
+ void format(const details::log_msg &, const std::tm &tm_time, memory_buf_t &dest) override {
+- const size_t field_size = 10;
++ const size_t field_size = 8;
+ ScopedPadder p(field_size, padinfo_, dest);
+
+ fmt_helper::pad2(tm_time.tm_mon + 1, dest);
diff --git a/meta-openembedded/meta-oe/recipes-extended/minifi-cpp/minifi-cpp_0.15.0.bb b/meta-openembedded/meta-oe/recipes-extended/minifi-cpp/minifi-cpp_0.15.0.bb
index beb247c254..f84f018ea9 100644
--- a/meta-openembedded/meta-oe/recipes-extended/minifi-cpp/minifi-cpp_0.15.0.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/minifi-cpp/minifi-cpp_0.15.0.bb
@@ -29,6 +29,7 @@ SRC_URI = "git://github.com/apache/nifi-minifi-cpp.git;protocol=https;branch=mai
file://0008-libsodium-aarch64_crypto.patch \
file://systemd-volatile.conf \
file://sysvinit-volatile.conf \
+ file://CVE-2025-6140.patch;patchdir=${S}/thirdparty/spdlog-src \
"
SRCREV = "9b55dc0c0f17a190f3e9ade87070a28faf542c25"
diff --git a/meta-openembedded/meta-oe/recipes-extended/nana/nana_git.bb b/meta-openembedded/meta-oe/recipes-extended/nana/nana_git.bb
index 7c748bc49b..d292bb8827 100644
--- a/meta-openembedded/meta-oe/recipes-extended/nana/nana_git.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/nana/nana_git.bb
@@ -42,3 +42,9 @@ do_configure:prepend:class-nativesdk() {
}
BBCLASSEXTEND = "native nativesdk"
+
+do_install:append() {
+ sed -i -e 's,--sysroot=${STAGING_DIR_TARGET},,g' ${D}${bindir}/nana-c++lg
+ sed -i -e 's,--sysroot=${STAGING_DIR_TARGET},,g' ${D}${bindir}/nana-clg
+ sed -i -e 's,--sysroot=${STAGING_DIR_TARGET},,g' ${D}${bindir}/nana
+}
diff --git a/meta-openembedded/meta-oe/recipes-extended/p7zip/files/0001-Fix-two-buffer-overflow-vulnerabilities.patch b/meta-openembedded/meta-oe/recipes-extended/p7zip/files/0001-Fix-two-buffer-overflow-vulnerabilities.patch
new file mode 100644
index 0000000000..d149c34134
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/p7zip/files/0001-Fix-two-buffer-overflow-vulnerabilities.patch
@@ -0,0 +1,455 @@
+From 1f266347b154ed90b8262126f04e8cc8f59fa617 Mon Sep 17 00:00:00 2001
+From: Hongxu Jia <hongxu.jia@windriver.com>
+Date: Fri, 22 Nov 2024 21:25:21 +0800
+Subject: [PATCH] Fix two buffer overflow vulnerabilities
+
+According to [1][2], Igor Pavlov, the author of 7-Zip, refused to
+provide an advisory or any related change log entries. We have to
+backport a part of ./CPP/7zip/Archive/NtfsHandler.cpp from upstream
+big commit
+
+Upstream-Status: Backport [https://github.com/ip7z/7zip/commit/fc662341e6f85da78ada0e443f6116b978f79f22]
+
+[1] https://dfir.ru/2024/06/19/vulnerabilities-in-7-zip-and-ntfs3/
+[2] https://dfir.ru/wp-content/uploads/2024/07/screenshot-2024-07-03-at-02-13-40-7-zip-_-bugs-_-2402-two-vulnerabilities-in-the-ntfs-handler.png
+
+CVE: CVE-2023-52169
+CVE: CVE-2023-52168
+
+Signed-off-by: Hongxu Jia <hongxu.jia@windriver.com>
+---
+ CPP/7zip/Archive/NtfsHandler.cpp | 229 ++++++++++++++++++++-----------
+ 1 file changed, 151 insertions(+), 78 deletions(-)
+
+diff --git a/CPP/7zip/Archive/NtfsHandler.cpp b/CPP/7zip/Archive/NtfsHandler.cpp
+index 93e9f88..2701439 100644
+--- a/CPP/7zip/Archive/NtfsHandler.cpp
++++ b/CPP/7zip/Archive/NtfsHandler.cpp
+@@ -71,8 +71,9 @@ struct CHeader
+ {
+ unsigned SectorSizeLog;
+ unsigned ClusterSizeLog;
++ unsigned MftRecordSizeLog;
+ // Byte MediaType;
+- UInt32 NumHiddenSectors;
++ //UInt32 NumHiddenSectors;
+ UInt64 NumSectors;
+ UInt64 NumClusters;
+ UInt64 MftCluster;
+@@ -111,30 +112,42 @@ bool CHeader::Parse(const Byte *p)
+ if (memcmp(p + 3, "NTFS ", 8) != 0)
+ return false;
+ {
+- int t = GetLog(Get16(p + 11));
+- if (t < 9 || t > 12)
+- return false;
+- SectorSizeLog = t;
+- t = GetLog(p[13]);
+- if (t < 0)
+- return false;
+- sectorsPerClusterLog = t;
+- ClusterSizeLog = SectorSizeLog + sectorsPerClusterLog;
+- if (ClusterSizeLog > 30)
+- return false;
++ {
++ const int t = GetLog(Get16(p + 11));
++ if (t < 9 || t > 12)
++ return false;
++ SectorSizeLog = (unsigned)t;
++ }
++ {
++ const unsigned v = p[13];
++ if (v <= 0x80)
++ {
++ const int t = GetLog(v);
++ if (t < 0)
++ return false;
++ sectorsPerClusterLog = (unsigned)t;
++ }
++ else
++ sectorsPerClusterLog = 0x100 - v;
++ ClusterSizeLog = SectorSizeLog + sectorsPerClusterLog;
++ if (ClusterSizeLog > 30)
++ return false;
++ }
+ }
+
+ for (int i = 14; i < 21; i++)
+ if (p[i] != 0)
+ return false;
+
++ // F8 : a hard disk
++ // F0 : high-density 3.5-inch floppy disk
+ if (p[21] != 0xF8) // MediaType = Fixed_Disk
+ return false;
+ if (Get16(p + 22) != 0) // NumFatSectors
+ return false;
+- G16(p + 24, SectorsPerTrack); // 63 usually
+- G16(p + 26, NumHeads); // 255
+- G32(p + 28, NumHiddenSectors); // 63 (XP) / 2048 (Vista and win7) / (0 on media that are not partitioned ?)
++ // G16(p + 24, SectorsPerTrack); // 63 usually
++ // G16(p + 26, NumHeads); // 255
++ // G32(p + 28, NumHiddenSectors); // 63 (XP) / 2048 (Vista and win7) / (0 on media that are not partitioned ?)
+ if (Get32(p + 32) != 0) // NumSectors32
+ return false;
+
+@@ -156,14 +169,47 @@ bool CHeader::Parse(const Byte *p)
+
+ NumClusters = NumSectors >> sectorsPerClusterLog;
+
+- G64(p + 0x30, MftCluster);
++ G64(p + 0x30, MftCluster); // $MFT.
+ // G64(p + 0x38, Mft2Cluster);
+- G64(p + 0x48, SerialNumber);
+- UInt32 numClustersInMftRec;
+- UInt32 numClustersInIndexBlock;
+- G32(p + 0x40, numClustersInMftRec); // -10 means 2 ^10 = 1024 bytes.
+- G32(p + 0x44, numClustersInIndexBlock);
+- return (numClustersInMftRec < 256 && numClustersInIndexBlock < 256);
++ G64(p + 0x48, SerialNumber); // $MFTMirr
++
++ /*
++ numClusters_per_MftRecord:
++ numClusters_per_IndexBlock:
++ only low byte from 4 bytes is used. Another 3 high bytes are zeros.
++ If the number is positive (number < 0x80),
++ then it represents the number of clusters.
++ If the number is negative (number >= 0x80),
++ then the size of the file record is 2 raised to the absolute value of this number.
++ example: (0xF6 == -10) means 2^10 = 1024 bytes.
++ */
++ {
++ UInt32 numClusters_per_MftRecord;
++ G32(p + 0x40, numClusters_per_MftRecord);
++ if (numClusters_per_MftRecord >= 0x100 || numClusters_per_MftRecord == 0)
++ return false;
++ if (numClusters_per_MftRecord < 0x80)
++ {
++ const int t = GetLog(numClusters_per_MftRecord);
++ if (t < 0)
++ return false;
++ MftRecordSizeLog = (unsigned)t + ClusterSizeLog;
++ }
++ else
++ MftRecordSizeLog = 0x100 - numClusters_per_MftRecord;
++ // what exact MFT record sizes are possible and supported by Windows?
++ // do we need to change this limit here?
++ const unsigned k_MftRecordSizeLog_MAX = 12;
++ if (MftRecordSizeLog > k_MftRecordSizeLog_MAX)
++ return false;
++ if (MftRecordSizeLog < SectorSizeLog)
++ return false;
++ }
++ {
++ UInt32 numClusters_per_IndexBlock;
++ G32(p + 0x44, numClusters_per_IndexBlock);
++ return (numClusters_per_IndexBlock < 0x100);
++ }
+ }
+
+ struct CMftRef
+@@ -235,7 +281,7 @@ struct CFileNameAttr
+ bool Parse(const Byte *p, unsigned size);
+ };
+
+-static void GetString(const Byte *p, unsigned len, UString2 &res)
++static void GetString(const Byte *p, const unsigned len, UString2 &res)
+ {
+ if (len == 0 && res.IsEmpty())
+ return;
+@@ -266,8 +312,8 @@ bool CFileNameAttr::Parse(const Byte *p, unsigned size)
+ G32(p + 0x38, Attrib);
+ // G16(p + 0x3C, PackedEaSize);
+ NameType = p[0x41];
+- unsigned len = p[0x40];
+- if (0x42 + len > size)
++ const unsigned len = p[0x40];
++ if (0x42 + len * 2 > size)
+ return false;
+ if (len != 0)
+ GetString(p + 0x42, len, Name);
+@@ -954,6 +1000,14 @@ struct CDataRef
+ static const UInt32 kMagic_FILE = 0x454C4946;
+ static const UInt32 kMagic_BAAD = 0x44414142;
+
++// 22.02: we support some rare case magic values:
++static const UInt32 kMagic_INDX = 0x58444e49;
++static const UInt32 kMagic_HOLE = 0x454c4f48;
++static const UInt32 kMagic_RSTR = 0x52545352;
++static const UInt32 kMagic_RCRD = 0x44524352;
++static const UInt32 kMagic_CHKD = 0x444b4843;
++static const UInt32 kMagic_FFFFFFFF = 0xFFFFFFFF;
++
+ struct CMftRec
+ {
+ UInt32 Magic;
+@@ -1030,6 +1084,26 @@ struct CMftRec
+
+ bool Parse(Byte *p, unsigned sectorSizeLog, UInt32 numSectors, UInt32 recNumber, CObjectVector<CAttr> *attrs);
+
++ bool Is_Magic_Empty() const
++ {
++ // what exact Magic values are possible for empty and unused records?
++ const UInt32 k_Magic_Unused_MAX = 5; // 22.02
++ return (Magic <= k_Magic_Unused_MAX);
++ }
++ bool Is_Magic_FILE() const { return (Magic == kMagic_FILE); }
++ // bool Is_Magic_BAAD() const { return (Magic == kMagic_BAAD); }
++ bool Is_Magic_CanIgnore() const
++ {
++ return Is_Magic_Empty()
++ || Magic == kMagic_BAAD
++ || Magic == kMagic_INDX
++ || Magic == kMagic_HOLE
++ || Magic == kMagic_RSTR
++ || Magic == kMagic_RCRD
++ || Magic == kMagic_CHKD
++ || Magic == kMagic_FFFFFFFF;
++ }
++
+ bool IsEmpty() const { return (Magic <= 2); }
+ bool IsFILE() const { return (Magic == kMagic_FILE); }
+ bool IsBAAD() const { return (Magic == kMagic_BAAD); }
+@@ -1141,9 +1215,8 @@ bool CMftRec::Parse(Byte *p, unsigned sectorSizeLog, UInt32 numSectors, UInt32 r
+ CObjectVector<CAttr> *attrs)
+ {
+ G32(p, Magic);
+- if (!IsFILE())
+- return IsEmpty() || IsBAAD();
+-
++ if (!Is_Magic_FILE())
++ return Is_Magic_CanIgnore();
+
+ {
+ UInt32 usaOffset;
+@@ -1188,12 +1261,12 @@ bool CMftRec::Parse(Byte *p, unsigned sectorSizeLog, UInt32 numSectors, UInt32 r
+ G16(p + 0x10, SeqNumber);
+ // G16(p + 0x12, LinkCount);
+ // PRF(printf(" L=%d", LinkCount));
+- UInt32 attrOffs = Get16(p + 0x14);
++ const UInt32 attrOffs = Get16(p + 0x14);
+ G16(p + 0x16, Flags);
+ PRF(printf(" F=%4X", Flags));
+
+- UInt32 bytesInUse = Get32(p + 0x18);
+- UInt32 bytesAlloc = Get32(p + 0x1C);
++ const UInt32 bytesInUse = Get32(p + 0x18);
++ const UInt32 bytesAlloc = Get32(p + 0x1C);
+ G64(p + 0x20, BaseMftRef.Val);
+ if (BaseMftRef.Val != 0)
+ {
+@@ -1667,68 +1740,57 @@ HRESULT CDatabase::Open()
+
+ SeekToCluster(Header.MftCluster);
+
+- CMftRec mftRec;
+- UInt32 numSectorsInRec;
+-
++ // we use ByteBuf for records reading.
++ // so the size of ByteBuf must be >= mftRecordSize
++ const size_t recSize = (size_t)1 << Header.MftRecordSizeLog;
++ const size_t kBufSize = MyMax((size_t)(1 << 15), recSize);
++ ByteBuf.Alloc(kBufSize);
++ RINOK(ReadStream_FALSE(InStream, ByteBuf, recSize))
++ {
++ const UInt32 allocSize = Get32(ByteBuf + 0x1C);
++ if (allocSize != recSize)
++ return S_FALSE;
++ }
++ // MftRecordSizeLog >= SectorSizeLog
++ const UInt32 numSectorsInRec = 1u << (Header.MftRecordSizeLog - Header.SectorSizeLog);
+ CMyComPtr<IInStream> mftStream;
++ CMftRec mftRec;
+ {
+- UInt32 blockSize = 1 << 12;
+- ByteBuf.Alloc(blockSize);
+- RINOK(ReadStream_FALSE(InStream, ByteBuf, blockSize));
+-
+- {
+- UInt32 allocSize = Get32(ByteBuf + 0x1C);
+- int t = GetLog(allocSize);
+- if (t < (int)Header.SectorSizeLog)
+- return S_FALSE;
+- RecSizeLog = t;
+- if (RecSizeLog > 15)
+- return S_FALSE;
+- }
+-
+- numSectorsInRec = 1 << (RecSizeLog - Header.SectorSizeLog);
+ if (!mftRec.Parse(ByteBuf, Header.SectorSizeLog, numSectorsInRec, 0, NULL))
+ return S_FALSE;
+- if (!mftRec.IsFILE())
++ if (!mftRec.Is_Magic_FILE())
+ return S_FALSE;
+ mftRec.ParseDataNames();
+ if (mftRec.DataRefs.IsEmpty())
+ return S_FALSE;
+- RINOK(mftRec.GetStream(InStream, 0, Header.ClusterSizeLog, Header.NumClusters, &mftStream));
++ RINOK(mftRec.GetStream(InStream, 0, Header.ClusterSizeLog, Header.NumClusters, &mftStream))
+ if (!mftStream)
+ return S_FALSE;
+ }
+
+ // CObjectVector<CAttr> SecurityAttrs;
+
+- UInt64 mftSize = mftRec.DataAttrs[0].Size;
++ const UInt64 mftSize = mftRec.DataAttrs[0].Size;
+ if ((mftSize >> 4) > Header.GetPhySize_Clusters())
+ return S_FALSE;
+
+- const size_t kBufSize = (1 << 15);
+- const size_t recSize = ((size_t)1 << RecSizeLog);
+- if (kBufSize < recSize)
+- return S_FALSE;
+-
+ {
+- const UInt64 numFiles = mftSize >> RecSizeLog;
++ const UInt64 numFiles = mftSize >> Header.MftRecordSizeLog;
+ if (numFiles > (1 << 30))
+ return S_FALSE;
+ if (OpenCallback)
+ {
+ RINOK(OpenCallback->SetTotal(&numFiles, &mftSize));
+ }
+-
+- ByteBuf.Alloc(kBufSize);
+ Recs.ClearAndReserve((unsigned)numFiles);
+ }
+-
++
+ for (UInt64 pos64 = 0;;)
+ {
+ if (OpenCallback)
+ {
+ const UInt64 numFiles = Recs.Size();
+- if ((numFiles & 0x3FF) == 0)
++ if ((numFiles & 0x3FFF) == 0)
+ {
+ RINOK(OpenCallback->SetCompleted(&numFiles, &pos64));
+ }
+@@ -1817,12 +1879,18 @@ HRESULT CDatabase::Open()
+ for (i = 0; i < Recs.Size(); i++)
+ {
+ CMftRec &rec = Recs[i];
++ if (!rec.Is_Magic_FILE())
++ continue;
++
+ if (!rec.BaseMftRef.IsBaseItself())
+ {
+- UInt64 refIndex = rec.BaseMftRef.GetIndex();
+- if (refIndex > (UInt32)Recs.Size())
++ const UInt64 refIndex = rec.BaseMftRef.GetIndex();
++ if (refIndex >= Recs.Size())
+ return S_FALSE;
+ CMftRec &refRec = Recs[(unsigned)refIndex];
++ if (!refRec.Is_Magic_FILE())
++ continue;
++
+ bool moveAttrs = (refRec.SeqNumber == rec.BaseMftRef.GetNumber() && refRec.BaseMftRef.IsBaseItself());
+ if (rec.InUse() && refRec.InUse())
+ {
+@@ -1837,12 +1905,17 @@ HRESULT CDatabase::Open()
+ }
+
+ for (i = 0; i < Recs.Size(); i++)
+- Recs[i].ParseDataNames();
++ {
++ CMftRec &rec = Recs[i];
++ if (!rec.Is_Magic_FILE())
++ continue;
++ rec.ParseDataNames();
++ }
+
+ for (i = 0; i < Recs.Size(); i++)
+ {
+ CMftRec &rec = Recs[i];
+- if (!rec.IsFILE() || !rec.BaseMftRef.IsBaseItself())
++ if (!rec.Is_Magic_FILE() || !rec.BaseMftRef.IsBaseItself())
+ continue;
+ if (i < kNumSysRecs && !_showSystemFiles)
+ continue;
+@@ -1864,7 +1937,7 @@ HRESULT CDatabase::Open()
+ FOR_VECTOR (di, rec.DataRefs)
+ if (rec.DataAttrs[rec.DataRefs[di].Start].Name.IsEmpty())
+ {
+- indexOfUnnamedStream = di;
++ indexOfUnnamedStream = (int)di;
+ break;
+ }
+ }
+@@ -1922,14 +1995,14 @@ HRESULT CDatabase::Open()
+ indexOfUnnamedStream);
+
+ if (rec.MyItemIndex < 0)
+- rec.MyItemIndex = Items.Size();
+- item.ParentHost = Items.Add(item);
++ rec.MyItemIndex = (int)Items.Size();
++ item.ParentHost = (int)Items.Add(item);
+
+ /* we can use that code to reduce the number of alt streams:
+ it will not show how alt streams for hard links. */
+ // if (!isMainName) continue; isMainName = false;
+
+- unsigned numAltStreams = 0;
++ // unsigned numAltStreams = 0;
+
+ FOR_VECTOR (di, rec.DataRefs)
+ {
+@@ -1947,9 +2020,9 @@ HRESULT CDatabase::Open()
+ continue;
+ }
+
+- numAltStreams++;
++ // numAltStreams++;
+ ThereAreAltStreams = true;
+- item.DataIndex = di;
++ item.DataIndex = (int)di;
+ Items.Add(item);
+ }
+ }
+@@ -1964,10 +2037,10 @@ HRESULT CDatabase::Open()
+ if (attr.Name == L"$SDS")
+ {
+ CMyComPtr<IInStream> sdsStream;
+- RINOK(rec.GetStream(InStream, di, Header.ClusterSizeLog, Header.NumClusters, &sdsStream));
++ RINOK(rec.GetStream(InStream, (int)di, Header.ClusterSizeLog, Header.NumClusters, &sdsStream));
+ if (sdsStream)
+ {
+- UInt64 size64 = attr.GetSize();
++ const UInt64 size64 = attr.GetSize();
+ if (size64 < (UInt32)1 << 29)
+ {
+ size_t size = (size_t)size64;
+@@ -1997,7 +2070,7 @@ HRESULT CDatabase::Open()
+ const CMftRec &rec = Recs[item.RecIndex];
+ const CFileNameAttr &fn = rec.FileNames[item.NameIndex];
+ const CMftRef &parentDirRef = fn.ParentDirRef;
+- UInt64 refIndex = parentDirRef.GetIndex();
++ const UInt64 refIndex = parentDirRef.GetIndex();
+ if (refIndex == kRecIndex_RootDir)
+ item.ParentFolder = -1;
+ else
+@@ -2024,17 +2097,17 @@ HRESULT CDatabase::Open()
+ unsigned virtIndex = Items.Size();
+ if (_showSystemFiles)
+ {
+- _systemFolderIndex = virtIndex++;
++ _systemFolderIndex = (int)(virtIndex++);
+ VirtFolderNames.Add(kVirtualFolder_System);
+ }
+ if (thereAreUnknownFolders_Normal)
+ {
+- _lostFolderIndex_Normal = virtIndex++;
++ _lostFolderIndex_Normal = (int)(virtIndex++);
+ VirtFolderNames.Add(kVirtualFolder_Lost_Normal);
+ }
+ if (thereAreUnknownFolders_Deleted)
+ {
+- _lostFolderIndex_Deleted = virtIndex++;
++ _lostFolderIndex_Deleted = (int)(virtIndex++);
+ VirtFolderNames.Add(kVirtualFolder_Lost_Deleted);
+ }
+
+--
+2.34.1
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/p7zip/p7zip_16.02.bb b/meta-openembedded/meta-oe/recipes-extended/p7zip/p7zip_16.02.bb
index e795482eb6..31a12fdb04 100644
--- a/meta-openembedded/meta-oe/recipes-extended/p7zip/p7zip_16.02.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/p7zip/p7zip_16.02.bb
@@ -12,6 +12,7 @@ SRC_URI = "http://downloads.sourceforge.net/p7zip/p7zip/${PV}/p7zip_${PV}_src_al
file://change_numMethods_from_bool_to_unsigned.patch \
file://CVE-2018-5996.patch \
file://CVE-2016-9296.patch \
+ file://0001-Fix-two-buffer-overflow-vulnerabilities.patch \
"
SRC_URI[md5sum] = "a0128d661cfe7cc8c121e73519c54fbf"
diff --git a/meta-openembedded/meta-oe/recipes-extended/polkit/files/CVE-2025-7519.patch b/meta-openembedded/meta-oe/recipes-extended/polkit/files/CVE-2025-7519.patch
new file mode 100644
index 0000000000..78945a88fc
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/polkit/files/CVE-2025-7519.patch
@@ -0,0 +1,34 @@
+From 107d3801361b9f9084f78710178e683391f1d245 Mon Sep 17 00:00:00 2001
+From: Jan Rybar <jrybar@redhat.com>
+Date: Fri, 6 Jun 2025 13:25:55 +0200
+Subject: [PATCH] Nested .policy files cause xml parsing overflow leading to
+ crash
+
+CVE: CVE-2025-7519
+
+Upstream-Status: Backport [https://github.com/polkit-org/polkit/commit/107d3801361b9f9084f78710178e683391f1d245]
+
+Signed-off-by: Praveen Kumar <praveen.kumar@windriver.com>
+---
+ src/polkitbackend/polkitbackendactionpool.c | 6 ++++++
+ 1 file changed, 6 insertions(+)
+
+diff --git a/src/polkitbackend/polkitbackendactionpool.c b/src/polkitbackend/polkitbackendactionpool.c
+index 43f89cb..f4acca9 100644
+--- a/src/polkitbackend/polkitbackendactionpool.c
++++ b/src/polkitbackend/polkitbackendactionpool.c
+@@ -739,6 +739,12 @@ _start (void *data, const char *el, const char **attr)
+ guint num_attr;
+ ParserData *pd = data;
+
++ if (pd->stack_depth < 0 || pd->stack_depth >= PARSER_MAX_DEPTH)
++ {
++ g_warning ("XML parsing reached max depth?");
++ goto error;
++ }
++
+ for (num_attr = 0; attr[num_attr] != NULL; num_attr++)
+ ;
+
+--
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-extended/polkit/polkit_124.bb b/meta-openembedded/meta-oe/recipes-extended/polkit/polkit_124.bb
index 9e2eb05c62..3709aa0ef4 100644
--- a/meta-openembedded/meta-oe/recipes-extended/polkit/polkit_124.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/polkit/polkit_124.bb
@@ -1,10 +1,14 @@
-SUMMARY = "PolicyKit Authorization Framework"
+SUMMARY = "Polkit Authorization Framework"
DESCRIPTION = "The polkit package is an application-level toolkit for defining and handling the policy that allows unprivileged processes to speak to privileged processes."
HOMEPAGE = "http://www.freedesktop.org/wiki/Software/polkit"
LICENSE = "LGPL-2.0-or-later"
LIC_FILES_CHKSUM = "file://COPYING;md5=155db86cdbafa7532b41f390409283eb"
+BUGTRACKER = "https://github.com/polkit-org/polkit/issues"
-SRC_URI = "git://gitlab.freedesktop.org/polkit/polkit.git;protocol=https;branch=master"
+SRC_URI = "\
+ git://github.com/polkit-org/polkit.git;protocol=https;branch=main \
+ file://CVE-2025-7519.patch \
+"
S = "${WORKDIR}/git"
SRCREV = "82f0924dc0eb23b9df68e88dbaf9e07c81940a5a"
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/hiredis-use-default-CC-if-it-is-set.patch b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0001-hiredis-use-default-CC-if-it-is-set.patch
index 7785acca5c..63bf403412 100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/hiredis-use-default-CC-if-it-is-set.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0001-hiredis-use-default-CC-if-it-is-set.patch
@@ -1,4 +1,4 @@
-From 41efa2f0cf08c91ff935bbb2d16ab233df7f5811 Mon Sep 17 00:00:00 2001
+From af4fc632c03b2a68be4206b4896f27fc4bb865ae Mon Sep 17 00:00:00 2001
From: Venture Research <tech@ventureresearch.com>
Date: Fri, 8 Feb 2013 17:39:52 -0600
Subject: [PATCH] hiredis: use default CC if it is set
@@ -9,6 +9,8 @@ Content-Transfer-Encoding: 8bit
Instead of trying to automagically figure out CC, which breaks with OE
as CC has spaces in it, just skip it if one was already passed in.
+Upstream-Status: Pending
+
Signed-off-by: Venture Research <tech@ventureresearch.com>
Update to work with 4.0.8
@@ -16,10 +18,7 @@ Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
Reworked for 6.0.4
Signed-off-by: Andreas Müller <schnitzeltony@gmail.com>
-
---
-Upstream-Status: Pending
-
deps/hiredis/Makefile | 2 --
1 file changed, 2 deletions(-)
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/lua-update-Makefile-to-use-environment-build-setting.patch b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0002-lua-update-Makefile-to-use-environment-build-setting.patch
index 20708eda1e..46330f5064 100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/lua-update-Makefile-to-use-environment-build-setting.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0002-lua-update-Makefile-to-use-environment-build-setting.patch
@@ -1,4 +1,4 @@
-From aa3d31355f3cc140b1dc2f4fcff8e3c0aa261549 Mon Sep 17 00:00:00 2001
+From 45ae5eb5c3482054073e06ab1a78e0aa9b96447f Mon Sep 17 00:00:00 2001
From: Venture Research <tech@ventureresearch.com>
Date: Fri, 8 Feb 2013 20:22:19 -0600
Subject: [PATCH] lua: update Makefile to use environment build settings
@@ -6,6 +6,8 @@ Subject: [PATCH] lua: update Makefile to use environment build settings
OE-specific parameters, instead of overriding all of these simply use
the ones that are already passed in. Also configure for only Linux...
+Upstream-Status: Pending
+
Signed-off-by: Venture Research <tech@ventureresearch.com>
Updated to work with 3.0.x
@@ -14,8 +16,6 @@ Signed-off-by: Armin Kuster <akust808@gmail.com>
updated to work wtih 6.2.1
Signed-off-by: Yi Fan Yu <yifan.yu@windriver.com>
-
-Upstream-Status: Pending
---
deps/Makefile | 1 -
deps/lua/Makefile | 1 -
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/oe-use-libc-malloc.patch b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0003-hack-to-force-use-of-libc-malloc.patch
index 7b601e02a9..8991d2d9bc 100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/oe-use-libc-malloc.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0003-hack-to-force-use-of-libc-malloc.patch
@@ -1,4 +1,4 @@
-From 38a5f403b033d03cdac3ff814687d83f61527d8e Mon Sep 17 00:00:00 2001
+From 7a98e3ac480413ce7db3a5edd5dc70458b921b29 Mon Sep 17 00:00:00 2001
From: Venture Research <tech@ventureresearch.com>
Date: Wed, 6 Feb 2013 20:51:02 -0600
Subject: [PATCH] hack to force use of libc malloc
@@ -9,21 +9,20 @@ removed in favor of magic.
Note that this of course doesn't allow tcmalloc and jemalloc, however
jemalloc wasn't building correctly.
+Upstream-Status: Pending
+
Signed-off-by: Venture Research <tech@ventureresearch.com>
Update to work with 4.0.8
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
-
---
-Upstream-Status: Pending
-
src/Makefile | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
-diff --git a/src/Makefile b/src/Makefile
-index ecbd275..39decee 100644
---- a/src/Makefile
-+++ b/src/Makefile
+Index: redis-7.2.10/src/Makefile
+===================================================================
+--- redis-7.2.10.orig/src/Makefile
++++ redis-7.2.10/src/Makefile
@@ -13,7 +13,8 @@
# Just use 'make dep', but this is only needed by developers.
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/0001-src-Do-not-reset-FINAL_LIBS.patch b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0004-src-Do-not-reset-FINAL_LIBS.patch
index 01e53e3f21..0513138b4e 100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/0001-src-Do-not-reset-FINAL_LIBS.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0004-src-Do-not-reset-FINAL_LIBS.patch
@@ -1,4 +1,4 @@
-From d9d1f9a501ef7caa80d1e6595218898e9989ec2b Mon Sep 17 00:00:00 2001
+From 50fc46a12f6cf97e7b927d3ea29eecc9ebdea34d Mon Sep 17 00:00:00 2001
From: Khem Raj <raj.khem@gmail.com>
Date: Tue, 10 Sep 2019 20:04:26 -0700
Subject: [PATCH] src: Do not reset FINAL_LIBS
@@ -9,17 +9,17 @@ environment to get it going
e.g. -latomic is needed on clang/x86 to provide for 64bit atomics
Upstream-Status: Pending
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
+Signed-off-by: Khem Raj <raj.khem@gmail.com>
---
src/Makefile | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
-diff --git a/src/Makefile b/src/Makefile
-index 39decee..f5efe82 100644
---- a/src/Makefile
-+++ b/src/Makefile
-@@ -119,7 +119,7 @@ endif
+Index: redis-7.2.10/src/Makefile
+===================================================================
+--- redis-7.2.10.orig/src/Makefile
++++ redis-7.2.10/src/Makefile
+@@ -122,7 +122,7 @@ endif
FINAL_CFLAGS=$(STD) $(WARN) $(OPT) $(DEBUG) $(CFLAGS) $(REDIS_CFLAGS)
FINAL_LDFLAGS=$(LDFLAGS) $(REDIS_LDFLAGS) $(DEBUG)
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/GNU_SOURCE-7.patch b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0005-Define-_GNU_SOURCE-to-get-PTHREAD_MUTEX_INITIALIZER.patch
index 6e07c25c6a..8e5f30993b 100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/GNU_SOURCE-7.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0005-Define-_GNU_SOURCE-to-get-PTHREAD_MUTEX_INITIALIZER.patch
@@ -1,4 +1,4 @@
-From a22512ac1cbd6de1f5646219722e49752d1f60ac Mon Sep 17 00:00:00 2001
+From acd832d76002a1916b3128ac05bc0296425aea6d Mon Sep 17 00:00:00 2001
From: Khem Raj <raj.khem@gmail.com>
Date: Sat, 21 Dec 2019 12:09:51 -0800
Subject: [PATCH] Define _GNU_SOURCE to get PTHREAD_MUTEX_INITIALIZER
@@ -9,14 +9,14 @@ Fixes
| | ^~~~~~~~~~~~~~~~~~~~~~~~~
Upstream-Status: Pending
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
+Signed-off-by: Khem Raj <raj.khem@gmail.com>
---
src/zmalloc.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/src/zmalloc.c b/src/zmalloc.c
-index ba03685..322304f 100644
+index bbfa386..93e07ff 100644
--- a/src/zmalloc.c
+++ b/src/zmalloc.c
@@ -32,6 +32,7 @@
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/0006-Define-correct-gregs-for-RISCV32.patch b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0006-Define-correct-gregs-for-RISCV32.patch
index 93c3595261..7009048171 100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/0006-Define-correct-gregs-for-RISCV32.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/0006-Define-correct-gregs-for-RISCV32.patch
@@ -1,14 +1,14 @@
-From 634f62be6c135ece93cb4e44a69ce3cb66f394ca Mon Sep 17 00:00:00 2001
+From dd3ecb07bbf80b986b8f2c656ea11d1346e212f6 Mon Sep 17 00:00:00 2001
From: Khem Raj <raj.khem@gmail.com>
Date: Mon, 26 Oct 2020 21:32:22 -0700
Subject: [PATCH] Define correct gregs for RISCV32
Upstream-Status: Pending
+
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Updated patch for 6.2.8
Signed-off-by: Changqing Li <changqing.li@windriver.com>
-
---
src/debug.c | 26 ++++++++++++++++++++++++--
1 file changed, 24 insertions(+), 2 deletions(-)
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/init-redis-server b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/init-redis-server
index c5f335f57d..c5f335f57d 100755..100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/init-redis-server
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/init-redis-server
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/redis.conf b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/redis.conf
index 75037d6dc8..75037d6dc8 100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/redis.conf
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/redis.conf
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/redis.service b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/redis.service
index b7791d0df4..b7791d0df4 100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.4/redis.service
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis-7.2.11/redis.service
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis/hiredis-use-default-CC-if-it-is-set.patch b/meta-openembedded/meta-oe/recipes-extended/redis/redis/0001-hiredis-use-default-CC-if-it-is-set.patch
index d2a1b45e66..51a6e9c957 100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis/hiredis-use-default-CC-if-it-is-set.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis/0001-hiredis-use-default-CC-if-it-is-set.patch
@@ -1,11 +1,16 @@
-From dc745a33f3875cc72d41bd34ed490b352e546352 Mon Sep 17 00:00:00 2001
+From 67990f216f2fbbc8a6699c700dfc089aa617905f Mon Sep 17 00:00:00 2001
From: Venture Research <tech@ventureresearch.com>
Date: Fri, 8 Feb 2013 17:39:52 -0600
Subject: [PATCH] hiredis: use default CC if it is set
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
Instead of trying to automagically figure out CC, which breaks with OE
as CC has spaces in it, just skip it if one was already passed in.
+Upstream-Status: Pending
+
Signed-off-by: Venture Research <tech@ventureresearch.com>
Update to work with 4.0.8
@@ -14,13 +19,11 @@ Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
Reworked for 6.0.4
Signed-off-by: Andreas Müller <schnitzeltony@gmail.com>
---
-Upstream-Status: Pending
-
deps/hiredis/Makefile | 2 --
1 file changed, 2 deletions(-)
diff --git a/deps/hiredis/Makefile b/deps/hiredis/Makefile
-index 25ac154..569f82b 100644
+index 7e41c97..54717e3 100644
--- a/deps/hiredis/Makefile
+++ b/deps/hiredis/Makefile
@@ -42,8 +42,6 @@ endef
@@ -32,6 +35,3 @@ index 25ac154..569f82b 100644
OPTIMIZATION?=-O3
WARNINGS=-Wall -W -Wstrict-prototypes -Wwrite-strings -Wno-missing-field-initializers
DEBUG_FLAGS?= -g -ggdb
---
-2.21.3
-
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis/lua-update-Makefile-to-use-environment-build-setting.patch b/meta-openembedded/meta-oe/recipes-extended/redis/redis/0002-lua-update-Makefile-to-use-environment-build-setting.patch
index aade7afd06..17b533669b 100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis/lua-update-Makefile-to-use-environment-build-setting.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis/0002-lua-update-Makefile-to-use-environment-build-setting.patch
@@ -1,4 +1,4 @@
-From 097a2b259cb266c2c861dc74fa6f80712d6138c5 Mon Sep 17 00:00:00 2001
+From ef989aab052510bfda32b2b325a5f80b76c42677 Mon Sep 17 00:00:00 2001
From: Venture Research <tech@ventureresearch.com>
Date: Fri, 8 Feb 2013 20:22:19 -0600
Subject: [PATCH] lua: update Makefile to use environment build settings
@@ -6,6 +6,8 @@ Subject: [PATCH] lua: update Makefile to use environment build settings
OE-specific parameters, instead of overriding all of these simply use
the ones that are already passed in. Also configure for only Linux...
+Upstream-Status: Pending
+
Signed-off-by: Venture Research <tech@ventureresearch.com>
Updated to work with 3.0.x
@@ -15,18 +17,16 @@ Signed-off-by: Armin Kuster <akust808@gmail.com>
updated to work wtih 6.2.1
Signed-off-by: Yi Fan Yu <yifan.yu@windriver.com>
---
-Upstream-Status: Pending
-
deps/Makefile | 1 -
deps/lua/Makefile | 1 -
deps/lua/src/Makefile | 16 ++++++----------
3 files changed, 6 insertions(+), 12 deletions(-)
diff --git a/deps/Makefile b/deps/Makefile
-index ff16ee9..d8d64aa 100644
+index cbe3aef..76bc222 100644
--- a/deps/Makefile
+++ b/deps/Makefile
-@@ -74,7 +74,6 @@ LUA_LDFLAGS+= $(LDFLAGS)
+@@ -81,7 +81,6 @@ endif
# lua's Makefile defines AR="ar rcu", which is unusual, and makes it more
# challenging to cross-compile lua (and redis). These defines make it easier
# to fit redis into cross-compilation environments, which typically set AR.
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis/oe-use-libc-malloc.patch b/meta-openembedded/meta-oe/recipes-extended/redis/redis/0003-hack-to-force-use-of-libc-malloc.patch
index e76bdbc263..f1021eef6c 100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis/oe-use-libc-malloc.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis/0003-hack-to-force-use-of-libc-malloc.patch
@@ -1,4 +1,4 @@
-From 1fa047162983d4a7e0576f0837a73a6027a783bd Mon Sep 17 00:00:00 2001
+From b9586abcb803747301f6cc4ff93c7642bef693ea Mon Sep 17 00:00:00 2001
From: Venture Research <tech@ventureresearch.com>
Date: Wed, 6 Feb 2013 20:51:02 -0600
Subject: [PATCH] hack to force use of libc malloc
@@ -9,19 +9,18 @@ removed in favor of magic.
Note that this of course doesn't allow tcmalloc and jemalloc, however
jemalloc wasn't building correctly.
+Upstream-Status: Pending
+
Signed-off-by: Venture Research <tech@ventureresearch.com>
Update to work with 4.0.8
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
-
---
-Upstream-Status: Pending
-
src/Makefile | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/src/Makefile b/src/Makefile
-index ecd6929..c7f43c5 100644
+index 7d75c83..35dd314 100644
--- a/src/Makefile
+++ b/src/Makefile
@@ -13,7 +13,8 @@
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis/0001-src-Do-not-reset-FINAL_LIBS.patch b/meta-openembedded/meta-oe/recipes-extended/redis/redis/0004-src-Do-not-reset-FINAL_LIBS.patch
index 66ab0ee33c..958106e261 100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis/0001-src-Do-not-reset-FINAL_LIBS.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis/0004-src-Do-not-reset-FINAL_LIBS.patch
@@ -1,4 +1,4 @@
-From 97584e1eb78dc18599534b47b6670c20c63f5ee2 Mon Sep 17 00:00:00 2001
+From a4d87aca1c00c53b386ee7490223971e00873add Mon Sep 17 00:00:00 2001
From: Khem Raj <raj.khem@gmail.com>
Date: Tue, 10 Sep 2019 20:04:26 -0700
Subject: [PATCH] src: Do not reset FINAL_LIBS
@@ -9,17 +9,17 @@ environment to get it going
e.g. -latomic is needed on clang/x86 to provide for 64bit atomics
Upstream-Status: Pending
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
+Signed-off-by: Khem Raj <raj.khem@gmail.com>
---
src/Makefile | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/Makefile b/src/Makefile
-index 5564351..83ccd76 100644
+index 35dd314..3770f96 100644
--- a/src/Makefile
+++ b/src/Makefile
-@@ -91,7 +91,7 @@ endif
+@@ -93,7 +93,7 @@ endif
FINAL_CFLAGS=$(STD) $(WARN) $(OPT) $(DEBUG) $(CFLAGS) $(REDIS_CFLAGS)
FINAL_LDFLAGS=$(LDFLAGS) $(REDIS_LDFLAGS) $(DEBUG)
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis/GNU_SOURCE.patch b/meta-openembedded/meta-oe/recipes-extended/redis/redis/0005-Define-_GNU_SOURCE-to-get-PTHREAD_MUTEX_INITIALIZER.patch
index 20f689bd0b..d73c66c9d0 100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis/GNU_SOURCE.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis/0005-Define-_GNU_SOURCE-to-get-PTHREAD_MUTEX_INITIALIZER.patch
@@ -1,4 +1,4 @@
-From 98d526f76049be21bf3d77158236b2189419a78e Mon Sep 17 00:00:00 2001
+From 2e6311c9c7cd85bf63eab8fe92c08ec1ec01b6fc Mon Sep 17 00:00:00 2001
From: Khem Raj <raj.khem@gmail.com>
Date: Sat, 21 Dec 2019 12:09:51 -0800
Subject: [PATCH] Define _GNU_SOURCE to get PTHREAD_MUTEX_INITIALIZER
@@ -9,6 +9,7 @@ Fixes
| | ^~~~~~~~~~~~~~~~~~~~~~~~~
Upstream-Status: Pending
+
Signed-off-by: Khem Raj <raj.khem@gmail.com>
---
src/zmalloc.c | 1 +
@@ -26,6 +27,3 @@ index 1f33d09..5e182d1 100644
#include <stdio.h>
#include <stdlib.h>
#include <stdint.h>
---
-2.25.1
-
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis/0006-Define-correct-gregs-for-RISCV32.patch b/meta-openembedded/meta-oe/recipes-extended/redis/redis/0006-Define-correct-gregs-for-RISCV32.patch
index 9d7e502717..bb3f5c607e 100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis/0006-Define-correct-gregs-for-RISCV32.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis/0006-Define-correct-gregs-for-RISCV32.patch
@@ -1,9 +1,10 @@
-From 26bd72f3b8de22e5036d86e6c79f815853b83473 Mon Sep 17 00:00:00 2001
+From 6149911f7a6fbaef3ed418408e2b501fa9479ffa Mon Sep 17 00:00:00 2001
From: Khem Raj <raj.khem@gmail.com>
Date: Mon, 26 Oct 2020 21:32:22 -0700
Subject: [PATCH] Define correct gregs for RISCV32
Upstream-Status: Pending
+
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Updated patch for 6.2.1
@@ -13,10 +14,10 @@ Signed-off-by: Yi Fan Yu <yifan.yu@windriver.com>
1 file changed, 24 insertions(+), 2 deletions(-)
diff --git a/src/debug.c b/src/debug.c
-index 5318c14..8c21b47 100644
+index bb76c5d..55a0696 100644
--- a/src/debug.c
+++ b/src/debug.c
-@@ -1055,7 +1055,9 @@ static void* getAndSetMcontextEip(ucontext_t *uc, void *eip) {
+@@ -1067,7 +1067,9 @@ static void* getAndSetMcontextEip(ucontext_t *uc, void *eip) {
#endif
#elif defined(__linux__)
/* Linux */
@@ -27,7 +28,7 @@ index 5318c14..8c21b47 100644
GET_SET_RETURN(uc->uc_mcontext.gregs[14], eip);
#elif defined(__X86_64__) || defined(__x86_64__)
GET_SET_RETURN(uc->uc_mcontext.gregs[16], eip);
-@@ -1222,8 +1224,28 @@ void logRegisters(ucontext_t *uc) {
+@@ -1234,8 +1236,28 @@ void logRegisters(ucontext_t *uc) {
#endif
/* Linux */
#elif defined(__linux__)
@@ -57,6 +58,3 @@ index 5318c14..8c21b47 100644
serverLog(LL_WARNING,
"\n"
"EAX:%08lx EBX:%08lx ECX:%08lx EDX:%08lx\n"
---
-2.25.1
-
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis/init-redis-server b/meta-openembedded/meta-oe/recipes-extended/redis/redis/init-redis-server
index c5f335f57d..c5f335f57d 100755..100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis/init-redis-server
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis/init-redis-server
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis_6.2.14.bb b/meta-openembedded/meta-oe/recipes-extended/redis/redis_6.2.20.bb
index fa430ce402..6eaf885f2f 100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis_6.2.14.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis_6.2.20.bb
@@ -10,19 +10,20 @@ SRC_URI = "http://download.redis.io/releases/${BP}.tar.gz \
file://redis.conf \
file://init-redis-server \
file://redis.service \
- file://hiredis-use-default-CC-if-it-is-set.patch \
- file://lua-update-Makefile-to-use-environment-build-setting.patch \
- file://oe-use-libc-malloc.patch \
- file://0001-src-Do-not-reset-FINAL_LIBS.patch \
- file://GNU_SOURCE.patch \
+ file://0001-hiredis-use-default-CC-if-it-is-set.patch \
+ file://0002-lua-update-Makefile-to-use-environment-build-setting.patch \
+ file://0003-hack-to-force-use-of-libc-malloc.patch \
+ file://0004-src-Do-not-reset-FINAL_LIBS.patch \
+ file://0005-Define-_GNU_SOURCE-to-get-PTHREAD_MUTEX_INITIALIZER.patch \
file://0006-Define-correct-gregs-for-RISCV32.patch \
- "
-SRC_URI[sha256sum] = "34e74856cbd66fdb3a684fb349d93961d8c7aa668b06f81fd93ff267d09bc277"
+ "
+
+SRC_URI[sha256sum] = "7f8b8a7aed53c445a877adf9e3743cdd323518524170135a58c0702f2dba6ef4"
inherit autotools-brokensep update-rc.d systemd useradd
FINAL_LIBS:x86:toolchain-clang = "-latomic"
-FINAL_LIBS:riscv32:toolchain-clang = "-latomic"
+FINAL_LIBS:riscv32 = "-latomic"
FINAL_LIBS:mips = "-latomic"
FINAL_LIBS:arm = "-latomic"
FINAL_LIBS:powerpc = "-latomic"
diff --git a/meta-openembedded/meta-oe/recipes-extended/redis/redis_7.2.4.bb b/meta-openembedded/meta-oe/recipes-extended/redis/redis_7.2.11.bb
index 5d64e9ba78..5ccb1ac935 100644
--- a/meta-openembedded/meta-oe/recipes-extended/redis/redis_7.2.4.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/redis/redis_7.2.11.bb
@@ -10,19 +10,20 @@ SRC_URI = "http://download.redis.io/releases/${BP}.tar.gz \
file://redis.conf \
file://init-redis-server \
file://redis.service \
- file://hiredis-use-default-CC-if-it-is-set.patch \
- file://lua-update-Makefile-to-use-environment-build-setting.patch \
- file://oe-use-libc-malloc.patch \
- file://0001-src-Do-not-reset-FINAL_LIBS.patch \
- file://GNU_SOURCE-7.patch \
+ file://0001-hiredis-use-default-CC-if-it-is-set.patch \
+ file://0002-lua-update-Makefile-to-use-environment-build-setting.patch \
+ file://0003-hack-to-force-use-of-libc-malloc.patch \
+ file://0004-src-Do-not-reset-FINAL_LIBS.patch \
+ file://0005-Define-_GNU_SOURCE-to-get-PTHREAD_MUTEX_INITIALIZER.patch \
file://0006-Define-correct-gregs-for-RISCV32.patch \
- "
-SRC_URI[sha256sum] = "8d104c26a154b29fd67d6568b4f375212212ad41e0c2caa3d66480e78dbd3b59"
+ "
+
+SRC_URI[sha256sum] = "2f9886eca68d30114ad6a01da65631f8007d802fd3e6c9fac711251e6390323d"
inherit autotools-brokensep pkgconfig update-rc.d systemd useradd
FINAL_LIBS:x86:toolchain-clang = "-latomic"
-FINAL_LIBS:riscv32:toolchain-clang = "-latomic"
+FINAL_LIBS:riscv32 = "-latomic"
FINAL_LIBS:mips = "-latomic"
FINAL_LIBS:arm = "-latomic"
FINAL_LIBS:powerpc = "-latomic"
diff --git a/meta-openembedded/meta-oe/recipes-extended/rrdtool/rrdtool_1.8.0.bb b/meta-openembedded/meta-oe/recipes-extended/rrdtool/rrdtool_1.8.0.bb
index cbe1af2854..5afb3f2f44 100644
--- a/meta-openembedded/meta-oe/recipes-extended/rrdtool/rrdtool_1.8.0.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/rrdtool/rrdtool_1.8.0.bb
@@ -103,6 +103,11 @@ do_configure() {
${B}/examples/*.pl
}
+do_install:append:class-native() {
+ # Replace the shebang line in cgi-demo.cgi
+ sed -i '1s|^.*$|#!/usr/bin/env rrdcgi|' ${D}${datadir}/rrdtool/examples/cgi-demo.cgi
+}
+
PACKAGES =+ "${PN}-perl ${PN}-python"
PACKAGES =+ "rrdcached"
diff --git a/meta-openembedded/meta-oe/recipes-extended/socketcan/can-utils/0001-lib-snprintf_can_error_frame-don-t-bail-out-if-CAN_E.patch b/meta-openembedded/meta-oe/recipes-extended/socketcan/can-utils/0001-lib-snprintf_can_error_frame-don-t-bail-out-if-CAN_E.patch
new file mode 100644
index 0000000000..f393cce091
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/socketcan/can-utils/0001-lib-snprintf_can_error_frame-don-t-bail-out-if-CAN_E.patch
@@ -0,0 +1,70 @@
+From 7d59157d4d570ba994f7dd07243ac5fb1c541410 Mon Sep 17 00:00:00 2001
+From: Marc Kleine-Budde <mkl@pengutronix.de>
+Date: Wed, 27 Sep 2023 16:15:52 +0200
+Subject: [PATCH] lib: snprintf_can_error_frame(): don't bail out if
+ CAN_ERR_CNT is set
+
+If CAN_ERR_CNT is set, the snprintf_can_error_frame() bails out, as it
+cannot decode CAN_ERR_CNT.
+
+Fixes: 21fb43532e80 ("lib: snprintf_can_error_frame: print counter errors if CAN_ERR_CNT is set")
+
+Upstream-Status: Backport [https://github.com/linux-can/can-utils/commit/7d59157d4d570ba994f7dd07243ac5fb1c541410]
+---
+ lib.c | 23 +++++++++++++++++++----
+ 1 file changed, 19 insertions(+), 4 deletions(-)
+
+diff --git a/lib.c b/lib.c
+index d665c69..0201e94 100644
+--- a/lib.c
++++ b/lib.c
+@@ -499,6 +499,7 @@ static const char *error_classes[] = {
+ "bus-off",
+ "bus-error",
+ "restarted-after-bus-off",
++ "error-counter-tx-rx",
+ };
+
+ static const char *controller_problems[] = {
+@@ -636,6 +637,19 @@ static int snprintf_error_prot(char *buf, size_t len, const struct canfd_frame *
+ return n;
+ }
+
++static int snprintf_error_cnt(char *buf, size_t len, const struct canfd_frame *cf)
++{
++ int n = 0;
++
++ if (len <= 0)
++ return 0;
++
++ n += snprintf(buf + n, len - n, "{{%d}{%d}}",
++ cf->data[6], cf->data[7]);
++
++ return n;
++}
++
+ void snprintf_can_error_frame(char *buf, size_t len, const struct canfd_frame *cf,
+ const char* sep)
+ {
+@@ -679,13 +693,14 @@ void snprintf_can_error_frame(char *buf, size_t len, const struct canfd_frame *c
+ n += snprintf_error_ctrl(buf + n, len - n, cf);
+ if (mask == CAN_ERR_PROT)
+ n += snprintf_error_prot(buf + n, len - n, cf);
++ if (mask == CAN_ERR_CNT)
++ n += snprintf_error_cnt(buf + n, len - n, cf);
+ classes++;
+ }
+ }
+
+- if (cf->can_id & CAN_ERR_CNT || cf->data[6] || cf->data[7]) {
+- n += snprintf(buf + n, len - n, "%s", sep);
+- n += snprintf(buf + n, len - n, "error-counter-tx-rx{{%d}{%d}}",
+- cf->data[6], cf->data[7]);
++ if (!(cf->can_id & CAN_ERR_CNT) && (cf->data[6] || cf->data[7])) {
++ n += snprintf(buf + n, len - n, "%serror-counter-tx-rx", sep);
++ n += snprintf_error_cnt(buf + n, len - n, cf);
+ }
+ }
+--
+2.43.0
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/socketcan/can-utils/0001-timestamp-formatting-always-use-64-bit-for-timestamp.patch b/meta-openembedded/meta-oe/recipes-extended/socketcan/can-utils/0001-timestamp-formatting-always-use-64-bit-for-timestamp.patch
new file mode 100644
index 0000000000..47f3792c39
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/socketcan/can-utils/0001-timestamp-formatting-always-use-64-bit-for-timestamp.patch
@@ -0,0 +1,422 @@
+From 05eb82fc959328f851d4b939d394529ac377de19 Mon Sep 17 00:00:00 2001
+From: TyK <tisyang@gmail.com>
+Date: Mon, 27 Nov 2023 10:59:21 +0800
+Subject: [PATCH] timestamp formatting: always use 64-bit for timestamp
+ formatting.
+
+Using C99 `unsigned long long` to format `struct timeval`'s `tv_sec`
+and `tv_usec`, fix incorrect print on some 32bit platform which
+are using time64.
+
+Upstream-Status: Backport [https://github.com/linux-can/can-utils/commit/ceda93bd5c56927c72d48dcaa30e17d6ecea86b8]
+---
+ asc2log.c | 38 +++++++++++++++++++++++---------------
+ candump.c | 6 +++---
+ canlogserver.c | 4 ++--
+ canplayer.c | 11 +++++++----
+ isotpdump.c | 8 ++++----
+ isotpperf.c | 4 ++--
+ isotpsniffer.c | 6 +++---
+ j1939cat.c | 4 ++--
+ j1939spy.c | 6 +++---
+ log2asc.c | 11 +++++++----
+ slcanpty.c | 4 ++--
+ 11 files changed, 58 insertions(+), 44 deletions(-)
+
+diff --git a/asc2log.c b/asc2log.c
+index ea6b486..4eb3609 100644
+--- a/asc2log.c
++++ b/asc2log.c
+@@ -73,7 +73,7 @@ void print_usage(char *prg)
+
+ void prframe(FILE *file, struct timeval *tv, int dev, struct canfd_frame *cf, unsigned int max_dlen, char *extra_info) {
+
+- fprintf(file, "(%lu.%06lu) ", tv->tv_sec, tv->tv_usec);
++ fprintf(file, "(%llu.%06llu) ", (unsigned long long)tv->tv_sec, (unsigned long long)tv->tv_usec);
+
+ if (dev > 0)
+ fprintf(file, "can%d ", dev-1);
+@@ -141,11 +141,14 @@ void eval_can(char* buf, struct timeval *date_tvp, char timestamps, char base, i
+ char dir[3]; /* 'Rx' or 'Tx' plus terminating zero */
+ char *extra_info;
+ int i, items;
++ unsigned long long sec, usec;
+
+ /* check for ErrorFrames */
+- if (sscanf(buf, "%lu.%lu %d %s",
+- &read_tv.tv_sec, &read_tv.tv_usec,
++ if (sscanf(buf, "%llu.%llu %d %s",
++ &sec, &usec,
+ &interface, tmp1) == 4) {
++ read_tv.tv_sec = sec;
++ read_tv.tv_usec = usec;
+
+ if (!strncmp(tmp1, "ErrorFrame", strlen("ErrorFrame"))) {
+
+@@ -165,18 +168,20 @@ void eval_can(char* buf, struct timeval *date_tvp, char timestamps, char base, i
+
+ /* check for CAN frames with (hexa)decimal values */
+ if (base == 'h')
+- items = sscanf(buf, "%lu.%lu %d %s %2s %c %x %x %x %x %x %x %x %x %x",
+- &read_tv.tv_sec, &read_tv.tv_usec, &interface,
++ items = sscanf(buf, "%llu.%llu %d %s %2s %c %x %x %x %x %x %x %x %x %x",
++ &sec, &usec, &interface,
+ tmp1, dir, &rtr, &dlc,
+ &data[0], &data[1], &data[2], &data[3],
+ &data[4], &data[5], &data[6], &data[7]);
+ else
+- items = sscanf(buf, "%lu.%lu %d %s %2s %c %x %d %d %d %d %d %d %d %d",
+- &read_tv.tv_sec, &read_tv.tv_usec, &interface,
++ items = sscanf(buf, "%llu.%llu %d %s %2s %c %x %d %d %d %d %d %d %d %d",
++ &sec, &usec, &interface,
+ tmp1, dir, &rtr, &dlc,
+ &data[0], &data[1], &data[2], &data[3],
+ &data[4], &data[5], &data[6], &data[7]);
+
++ read_tv.tv_sec = sec;
++ read_tv.tv_usec = usec;
+ if (items < 7 ) /* make sure we've read the dlc */
+ return;
+
+@@ -246,6 +251,7 @@ void eval_canfd(char* buf, struct timeval *date_tvp, char timestamps, int dplace
+ char *extra_info;
+ char *ptr;
+ int i;
++ unsigned long long sec, usec;
+
+ /* The CANFD format is mainly in hex representation but <DataLength>
+ and probably some content we skip anyway. Don't trust the docs! */
+@@ -255,19 +261,21 @@ void eval_canfd(char* buf, struct timeval *date_tvp, char timestamps, int dplace
+ 100000 214 223040 80000000 46500250 460a0250 20011736 20010205 */
+
+ /* check for valid line without symbolic name */
+- if (sscanf(buf, "%lu.%lu %*s %d %2s %s %hhx %hhx %x %d ",
+- &read_tv.tv_sec, &read_tv.tv_usec, &interface,
++ if (sscanf(buf, "%llu.%llu %*s %d %2s %s %hhx %hhx %x %d ",
++ &sec, &usec, &interface,
+ dir, tmp1, &brs, &esi, &dlc, &dlen) != 9) {
+
+ /* check for valid line with a symbolic name */
+- if (sscanf(buf, "%lu.%lu %*s %d %2s %s %*s %hhx %hhx %x %d ",
+- &read_tv.tv_sec, &read_tv.tv_usec, &interface,
++ if (sscanf(buf, "%llu.%llu %*s %d %2s %s %*s %hhx %hhx %x %d ",
++ &sec, &usec, &interface,
+ dir, tmp1, &brs, &esi, &dlc, &dlen) != 9) {
+
+ /* no valid CANFD format pattern */
+ return;
+ }
+ }
++ read_tv.tv_sec = sec;
++ read_tv.tv_usec = usec;
+
+ /* check for allowed (unsigned) value ranges */
+ if ((dlen > CANFD_MAX_DLEN) || (dlc > CANFD_MAX_DLC) ||
+@@ -427,12 +435,12 @@ int main(int argc, char **argv)
+ FILE *infile = stdin;
+ FILE *outfile = stdout;
+ static int verbose;
+- static struct timeval tmp_tv; /* tmp frame timestamp from ASC file */
+ static struct timeval date_tv; /* date of the ASC file */
+ static int dplace; /* decimal place 4, 5 or 6 or uninitialized */
+ static char base; /* 'd'ec or 'h'ex */
+ static char timestamps; /* 'a'bsolute or 'r'elative */
+ int opt;
++ unsigned long long sec, usec;
+
+ while ((opt = getopt(argc, argv, "I:O:v?")) != -1) {
+ switch (opt) {
+@@ -505,12 +513,12 @@ int main(int argc, char **argv)
+ gettimeofday(&date_tv, NULL);
+ }
+ if (verbose)
+- printf("date %lu => %s", date_tv.tv_sec, ctime(&date_tv.tv_sec));
++ printf("date %llu => %s", (unsigned long long)date_tv.tv_sec, ctime(&date_tv.tv_sec));
+ continue;
+ }
+
+ /* check for decimal places length in valid CAN frames */
+- if (sscanf(buf, "%lu.%s %s ", &tmp_tv.tv_sec, tmp2,
++ if (sscanf(buf, "%llu.%s %s ", &sec, tmp2,
+ tmp1) != 3)
+ continue; /* dplace remains zero until first found CAN frame */
+
+@@ -529,7 +537,7 @@ int main(int argc, char **argv)
+ /* so try to get CAN frames and ErrorFrames and convert them */
+
+ /* check classic CAN format or the CANFD tag which can take both types */
+- if (sscanf(buf, "%lu.%lu %s ", &tmp_tv.tv_sec, &tmp_tv.tv_usec, tmp1) == 3){
++ if (sscanf(buf, "%llu.%llu %s ", &sec, &usec, tmp1) == 3){
+ if (!strncmp(tmp1, "CANFD", 5))
+ eval_canfd(buf, &date_tv, timestamps, dplace, outfile);
+ else
+diff --git a/candump.c b/candump.c
+index 82f75b1..4ae8864 100644
+--- a/candump.c
++++ b/candump.c
+@@ -224,7 +224,7 @@ static inline void sprint_timestamp(const char timestamp, const struct timeval *
+ {
+ switch (timestamp) {
+ case 'a': /* absolute with timestamp */
+- sprintf(ts_buffer, "(%010lu.%06lu) ", tv->tv_sec, tv->tv_usec);
++ sprintf(ts_buffer, "(%010llu.%06llu) ", (unsigned long long)tv->tv_sec, (unsigned long long)tv->tv_usec);
+ break;
+
+ case 'A': /* absolute with date */
+@@ -234,7 +234,7 @@ static inline void sprint_timestamp(const char timestamp, const struct timeval *
+
+ tm = *localtime(&tv->tv_sec);
+ strftime(timestring, 24, "%Y-%m-%d %H:%M:%S", &tm);
+- sprintf(ts_buffer, "(%s.%06lu) ", timestring, tv->tv_usec);
++ sprintf(ts_buffer, "(%s.%06llu) ", timestring, (unsigned long long)tv->tv_usec);
+ }
+ break;
+
+@@ -251,7 +251,7 @@ static inline void sprint_timestamp(const char timestamp, const struct timeval *
+ diff.tv_sec--, diff.tv_usec += 1000000;
+ if (diff.tv_sec < 0)
+ diff.tv_sec = diff.tv_usec = 0;
+- sprintf(ts_buffer, "(%03lu.%06lu) ", diff.tv_sec, diff.tv_usec);
++ sprintf(ts_buffer, "(%03llu.%06llu) ", (unsigned long long)diff.tv_sec, (unsigned long long)diff.tv_usec);
+
+ if (timestamp == 'd')
+ *last_tv = *tv; /* update for delta calculation */
+diff --git a/canlogserver.c b/canlogserver.c
+index 51d548f..349d64e 100644
+--- a/canlogserver.c
++++ b/canlogserver.c
+@@ -408,8 +408,8 @@ int main(int argc, char **argv)
+
+ idx = idx2dindex(addr.can_ifindex, s[i]);
+
+- sprintf(temp, "(%lu.%06lu) %*s ",
+- tv.tv_sec, tv.tv_usec, max_devname_len, devname[idx]);
++ sprintf(temp, "(%llu.%06llu) %*s ",
++ (unsigned long long)tv.tv_sec, (unsigned long long)tv.tv_usec, max_devname_len, devname[idx]);
+ sprint_canframe(temp+strlen(temp), &frame, 0, maxdlen);
+ strcat(temp, "\n");
+
+diff --git a/canplayer.c b/canplayer.c
+index 51adc77..96346ce 100644
+--- a/canplayer.c
++++ b/canplayer.c
+@@ -259,6 +259,7 @@ int main(int argc, char **argv)
+ int txidx; /* sendto() interface index */
+ int eof, txmtu, i, j;
+ char *fret;
++ unsigned long long sec, usec;
+
+ while ((opt = getopt(argc, argv, "I:l:tin:g:s:xv?")) != -1) {
+ switch (opt) {
+@@ -419,11 +420,12 @@ int main(int argc, char **argv)
+
+ eof = 0;
+
+- if (sscanf(buf, "(%lu.%lu) %s %s", &log_tv.tv_sec, &log_tv.tv_usec,
+- device, ascframe) != 4) {
++ if (sscanf(buf, "(%llu.%llu) %s %s", &sec, &usec, device, ascframe) != 4) {
+ fprintf(stderr, "incorrect line format in logfile\n");
+ return 1;
+ }
++ log_tv.tv_sec = sec;
++ log_tv.tv_usec = usec;
+
+ if (use_timestamps) { /* throttle sending due to logfile timestamps */
+
+@@ -505,11 +507,12 @@ int main(int argc, char **argv)
+ break;
+ }
+
+- if (sscanf(buf, "(%lu.%lu) %s %s", &log_tv.tv_sec, &log_tv.tv_usec,
+- device, ascframe) != 4) {
++ if (sscanf(buf, "(%llu.%llu) %s %s", &sec, &usec, device, ascframe) != 4) {
+ fprintf(stderr, "incorrect line format in logfile\n");
+ return 1;
+ }
++ log_tv.tv_sec = sec;
++ log_tv.tv_usec = usec;
+
+ /*
+ * ensure the fractions of seconds are 6 decimal places long to catch
+diff --git a/isotpdump.c b/isotpdump.c
+index d22725e..e9e96ce 100644
+--- a/isotpdump.c
++++ b/isotpdump.c
+@@ -361,7 +361,7 @@ int main(int argc, char **argv)
+
+ switch (timestamp) {
+ case 'a': /* absolute with timestamp */
+- printf("(%lu.%06lu) ", tv.tv_sec, tv.tv_usec);
++ printf("(%llu.%06llu) ", (unsigned long long)tv.tv_sec, (unsigned long long)tv.tv_usec);
+ break;
+
+ case 'A': /* absolute with date */
+@@ -372,7 +372,7 @@ int main(int argc, char **argv)
+ tm = *localtime(&tv.tv_sec);
+ strftime(timestring, 24, "%Y-%m-%d %H:%M:%S",
+ &tm);
+- printf("(%s.%06lu) ", timestring, tv.tv_usec);
++ printf("(%s.%06llu) ", timestring, (unsigned long long)tv.tv_usec);
+ } break;
+
+ case 'd': /* delta */
+@@ -388,8 +388,8 @@ int main(int argc, char **argv)
+ diff.tv_sec--, diff.tv_usec += 1000000;
+ if (diff.tv_sec < 0)
+ diff.tv_sec = diff.tv_usec = 0;
+- printf("(%lu.%06lu) ", diff.tv_sec,
+- diff.tv_usec);
++ printf("(%llu.%06llu) ", (unsigned long long)diff.tv_sec,
++ (unsigned long long)diff.tv_usec);
+
+ if (timestamp == 'd')
+ last_tv =
+diff --git a/isotpperf.c b/isotpperf.c
+index 154d5cd..ad0dc2a 100644
+--- a/isotpperf.c
++++ b/isotpperf.c
+@@ -403,9 +403,9 @@ int main(int argc, char **argv)
+
+ /* check devisor to be not zero */
+ if (diff_tv.tv_sec * 1000 + diff_tv.tv_usec / 1000){
+- printf("%lu.%06lus ", diff_tv.tv_sec, diff_tv.tv_usec);
++ printf("%llu.%06llus ", (unsigned long long)diff_tv.tv_sec, (unsigned long long)diff_tv.tv_usec);
+ printf("=> %lu byte/s", (fflen * 1000) /
+- (diff_tv.tv_sec * 1000 + diff_tv.tv_usec / 1000));
++ (unsigned long)(diff_tv.tv_sec * 1000 + diff_tv.tv_usec / 1000));
+ } else
+ printf("(no time available) ");
+
+diff --git a/isotpsniffer.c b/isotpsniffer.c
+index 2b6de40..f976149 100644
+--- a/isotpsniffer.c
++++ b/isotpsniffer.c
+@@ -101,7 +101,7 @@ void printbuf(unsigned char *buffer, int nbytes, int color, int timestamp,
+ switch (timestamp) {
+
+ case 'a': /* absolute with timestamp */
+- printf("(%lu.%06lu) ", tv->tv_sec, tv->tv_usec);
++ printf("(%llu.%06llu) ", (unsigned long long)tv->tv_sec, (unsigned long long)tv->tv_usec);
+ break;
+
+ case 'A': /* absolute with date */
+@@ -111,7 +111,7 @@ void printbuf(unsigned char *buffer, int nbytes, int color, int timestamp,
+
+ tm = *localtime(&tv->tv_sec);
+ strftime(timestring, 24, "%Y-%m-%d %H:%M:%S", &tm);
+- printf("(%s.%06lu) ", timestring, tv->tv_usec);
++ printf("(%s.%06llu) ", timestring, (unsigned long long)tv->tv_usec);
+ }
+ break;
+
+@@ -128,7 +128,7 @@ void printbuf(unsigned char *buffer, int nbytes, int color, int timestamp,
+ diff.tv_sec--, diff.tv_usec += 1000000;
+ if (diff.tv_sec < 0)
+ diff.tv_sec = diff.tv_usec = 0;
+- printf("(%lu.%06lu) ", diff.tv_sec, diff.tv_usec);
++ printf("(%llu.%06llu) ", (unsigned long long)diff.tv_sec, (unsigned long long)diff.tv_usec);
+
+ if (timestamp == 'd')
+ *last_tv = *tv; /* update for delta calculation */
+diff --git a/j1939cat.c b/j1939cat.c
+index 4234aad..238c4ff 100644
+--- a/j1939cat.c
++++ b/j1939cat.c
+@@ -148,8 +148,8 @@ static void j1939cat_print_timestamp(struct j1939cat_priv *priv, const char *nam
+ if (!(cur->tv_sec | cur->tv_nsec))
+ return;
+
+- fprintf(stderr, " %s: %lu s %lu us (seq=%03u, send=%07u)",
+- name, cur->tv_sec, cur->tv_nsec / 1000,
++ fprintf(stderr, " %s: %llu s %llu us (seq=%03u, send=%07u)",
++ name, (unsigned long long)cur->tv_sec, (unsigned long long)cur->tv_nsec / 1000,
+ stats->tskey, stats->send);
+
+ fprintf(stderr, "\n");
+diff --git a/j1939spy.c b/j1939spy.c
+index e49ed14..56950ea 100644
+--- a/j1939spy.c
++++ b/j1939spy.c
+@@ -268,14 +268,14 @@ int main(int argc, char **argv)
+ goto abs_time;
+ } else if ('a' == s.time) {
+ abs_time:
+- printf("(%lu.%04lu)", tdut.tv_sec, tdut.tv_usec / 100);
++ printf("(%llu.%04llu)", (unsigned long long)tdut.tv_sec, (unsigned long long)tdut.tv_usec / 100);
+ } else if ('A' == s.time) {
+ struct tm tm;
+ tm = *localtime(&tdut.tv_sec);
+- printf("(%04u%02u%02uT%02u%02u%02u.%04lu)",
++ printf("(%04u%02u%02uT%02u%02u%02u.%04llu)",
+ tm.tm_year + 1900, tm.tm_mon + 1, tm.tm_mday,
+ tm.tm_hour, tm.tm_min, tm.tm_sec,
+- tdut.tv_usec/100);
++ (unsigned long long)tdut.tv_usec/100);
+ }
+ }
+ printf(" %s ", libj1939_addr2str(&src));
+diff --git a/log2asc.c b/log2asc.c
+index a1cf364..85634f8 100644
+--- a/log2asc.c
++++ b/log2asc.c
+@@ -190,6 +190,7 @@ int main(int argc, char **argv)
+ FILE *infile = stdin;
+ FILE *outfile = stdout;
+ static int maxdev, devno, i, crlf, fdfmt, nortrdlc, d4, opt, mtu;
++ unsigned long long sec, usec;
+
+ while ((opt = getopt(argc, argv, "I:O:4nfr?")) != -1) {
+ switch (opt) {
+@@ -259,18 +260,20 @@ int main(int argc, char **argv)
+ if (buf[0] != '(')
+ continue;
+
+- if (sscanf(buf, "(%lu.%lu) %s %s %s", &tv.tv_sec, &tv.tv_usec,
++ if (sscanf(buf, "(%llu.%llu) %s %s %s", &sec, &usec,
+ device, ascframe, extra_info) != 5) {
+
+ /* do not evaluate the extra info */
+ extra_info[0] = 0;
+
+- if (sscanf(buf, "(%lu.%lu) %s %s", &tv.tv_sec, &tv.tv_usec,
++ if (sscanf(buf, "(%llu.%llu) %s %s", &sec, &usec,
+ device, ascframe) != 4) {
+ fprintf(stderr, "incorrect line format in logfile\n");
+ return 1;
+ }
+ }
++ tv.tv_sec = sec;
++ tv.tv_usec = usec;
+
+ if (!start_tv.tv_sec) { /* print banner */
+ start_tv = tv;
+@@ -305,9 +308,9 @@ int main(int argc, char **argv)
+ tv.tv_sec = tv.tv_usec = 0;
+
+ if (d4)
+- fprintf(outfile, "%4lu.%04lu ", tv.tv_sec, tv.tv_usec/100);
++ fprintf(outfile, "%4llu.%04llu ", (unsigned long long)tv.tv_sec, (unsigned long long)tv.tv_usec/100);
+ else
+- fprintf(outfile, "%4lu.%06lu ", tv.tv_sec, tv.tv_usec);
++ fprintf(outfile, "%4llu.%06llu ", (unsigned long long)tv.tv_sec, (unsigned long long)tv.tv_usec);
+
+ if ((mtu == CAN_MTU) && (fdfmt == 0))
+ can_asc(&cf, devno, nortrdlc, extra_info, outfile);
+diff --git a/slcanpty.c b/slcanpty.c
+index fa97cd6..fc86d4f 100644
+--- a/slcanpty.c
++++ b/slcanpty.c
+@@ -363,8 +363,8 @@ int can2pty(int pty, int socket, int *tstamp)
+ if (ioctl(socket, SIOCGSTAMP, &tv) < 0)
+ perror("SIOCGSTAMP");
+
+- sprintf(&buf[ptr + 2*frame.can_dlc], "%04lX",
+- (tv.tv_sec%60)*1000 + tv.tv_usec/1000);
++ sprintf(&buf[ptr + 2*frame.can_dlc], "%04llX",
++ (unsigned long long)(tv.tv_sec%60)*1000 + tv.tv_usec/1000);
+ }
+
+ strcat(buf, "\r"); /* add terminating character */
+--
+2.43.0
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/socketcan/can-utils_2023.03.bb b/meta-openembedded/meta-oe/recipes-extended/socketcan/can-utils_2023.03.bb
index ca6cb7db58..0804b514a9 100644
--- a/meta-openembedded/meta-oe/recipes-extended/socketcan/can-utils_2023.03.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/socketcan/can-utils_2023.03.bb
@@ -4,7 +4,10 @@ LIC_FILES_CHKSUM = "file://include/linux/can.h;endline=44;md5=a9e1169c6c9a114a61
DEPENDS = "libsocketcan"
-SRC_URI = "git://github.com/linux-can/${BPN}.git;protocol=https;branch=master"
+SRC_URI = "git://github.com/linux-can/${BPN}.git;protocol=https;branch=master \
+ file://0001-timestamp-formatting-always-use-64-bit-for-timestamp.patch \
+ file://0001-lib-snprintf_can_error_frame-don-t-bail-out-if-CAN_E.patch \
+"
SRCREV = "cfe41963f3425e9adb01a70cfaddedf5e5982720"
diff --git a/meta-openembedded/meta-oe/recipes-extended/socketcan/canutils_4.0.6.bb b/meta-openembedded/meta-oe/recipes-extended/socketcan/canutils_4.0.6.bb
index ab4710e81f..6989531c81 100644
--- a/meta-openembedded/meta-oe/recipes-extended/socketcan/canutils_4.0.6.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/socketcan/canutils_4.0.6.bb
@@ -8,7 +8,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=94d55d512a9ba36caa9b7df079bae19f"
DEPENDS = "libsocketcan"
SRCREV = "299dff7f5322bf0348dcdd60071958ebedf5f09d"
-SRC_URI = "git://git.pengutronix.de/git/tools/canutils.git;protocol=git;branch=master \
+SRC_URI = "git://git.pengutronix.de/git/tools/canutils.git;protocol=https;branch=master \
file://0001-canutils-candump-Add-error-frame-s-handling.patch \
"
diff --git a/meta-openembedded/meta-oe/recipes-extended/socketcan/libsocketcan_0.0.12.bb b/meta-openembedded/meta-oe/recipes-extended/socketcan/libsocketcan_0.0.12.bb
index 9f6ef85c87..f45c2d750d 100644
--- a/meta-openembedded/meta-oe/recipes-extended/socketcan/libsocketcan_0.0.12.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/socketcan/libsocketcan_0.0.12.bb
@@ -7,7 +7,7 @@ LIC_FILES_CHKSUM = "file://src/libsocketcan.c;beginline=3;endline=17;md5=97e38ad
SRCREV = "077def398ad303043d73339112968e5112d8d7c8"
-SRC_URI = "git://git.pengutronix.de/git/tools/libsocketcan.git;protocol=git;branch=master"
+SRC_URI = "git://git.pengutronix.de/git/tools/libsocketcan.git;protocol=https;branch=master"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-oe/recipes-extended/vlock/vlock_2.2.3.bb b/meta-openembedded/meta-oe/recipes-extended/vlock/vlock_2.2.3.bb
index 455bda1d76..84289515ef 100644
--- a/meta-openembedded/meta-oe/recipes-extended/vlock/vlock_2.2.3.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/vlock/vlock_2.2.3.bb
@@ -9,7 +9,7 @@ SECTION = "utils"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=a17cb0a873d252440acfdf9b3d0e7fbf"
-SRC_URI = "${GENTOO_MIRROR}/${BP}.tar.gz \
+SRC_URI = "${GENTOO_MIRROR}/37/${BP}.tar.gz \
file://disable_vlockrc.patch \
file://vlock_pam_tally2_reset.patch \
file://vlock-no_tally.patch \
diff --git a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0001-locale-Avoid-using-glibc-specific-defines-on-musl.patch b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0001-locale-Avoid-using-glibc-specific-defines-on-musl.patch
deleted file mode 100644
index 52f4449339..0000000000
--- a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0001-locale-Avoid-using-glibc-specific-defines-on-musl.patch
+++ /dev/null
@@ -1,26 +0,0 @@
-From 72c3b7324f00047e6dc5d8380ed2f6ff2494a6f9 Mon Sep 17 00:00:00 2001
-From: Khem Raj <raj.khem@gmail.com>
-Date: Sun, 18 Dec 2022 14:51:34 -0800
-Subject: [PATCH] locale: Avoid using glibc specific defines on musl
-
-musl does not provide some glibc-only enum members e.g. _NL_ADDRESS_LANG_NAME
-
-Upstream-Status: Submitted [https://github.com/wxWidgets/wxWidgets/pull/23050]
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
----
- src/unix/uilocale.cpp | 2 +-
- 1 file changed, 1 insertion(+), 1 deletion(-)
-
-diff --git a/src/unix/uilocale.cpp b/src/unix/uilocale.cpp
-index 57773e17f5..86816ba896 100644
---- a/src/unix/uilocale.cpp
-+++ b/src/unix/uilocale.cpp
-@@ -619,7 +619,7 @@ wxString
- wxUILocaleImplUnix::GetLocalizedName(wxLocaleName name, wxLocaleForm form) const
- {
- wxString str;
--#if defined(HAVE_LANGINFO_H) && defined(__LINUX__)
-+#if defined(HAVE_LANGINFO_H) && defined(__LINUX__) && defined(__GLIBC__)
- switch (name)
- {
- case wxLOCALE_NAME_LOCALE:
diff --git a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0001-wx-config.in-Disable-cross-magic-it-does-not-work-fo.patch b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0001-wx-config.in-Disable-cross-magic-it-does-not-work-fo.patch
index b3b9e79c53..a3b8d0c0ee 100644
--- a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0001-wx-config.in-Disable-cross-magic-it-does-not-work-fo.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0001-wx-config.in-Disable-cross-magic-it-does-not-work-fo.patch
@@ -1,4 +1,4 @@
-From a071243763f4b06fc7e71f541c49cecf380b6f27 Mon Sep 17 00:00:00 2001
+From 8f582c0ea40ccdb2d439b7614459d752f3606e15 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Andreas=20M=C3=BCller?= <schnitzeltony@gmail.com>
Date: Sun, 11 Oct 2020 22:16:55 +0200
Subject: [PATCH] wx-config.in: Disable cross magic - it does not work for us
@@ -18,10 +18,10 @@ Signed-off-by: Andreas Müller <schnitzeltony@gmail.com>
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/wx-config.in b/wx-config.in
-index d132e3182f..d0d162e8a3 100755
+index 4df8571d28..1173d89685 100755
--- a/wx-config.in
+++ b/wx-config.in
-@@ -396,7 +396,7 @@ get_mask()
+@@ -394,7 +394,7 @@ get_mask()
}
# Returns true if this script is for a cross compiled config.
@@ -31,5 +31,5 @@ index d132e3182f..d0d162e8a3 100755
# Determine the base directories we require.
--
-2.26.2
+2.25.1
diff --git a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/fix-libdir-for-multilib.patch b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0002-fix-libdir-for-multilib.patch
index ea204ed3b1..b599f38871 100644
--- a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/fix-libdir-for-multilib.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0002-fix-libdir-for-multilib.patch
@@ -1,12 +1,18 @@
-wxWidgets hardcodes libdir with 'lib' and does not support multilib which will
-change it. Respect variable wxPLATFORM_LIB_DIR to support libdir be configurable.
+From 9487fe5cd271a4bee96ab590509ef38f6972887a Mon Sep 17 00:00:00 2001
+From: Kai Kang <kai.kang@windriver.com>
+Date: Sat, 12 Oct 2024 18:43:25 +0800
+Subject: [PATCH] fix libdir for multilib
+
+wxWidgets hardcodes libdir with 'lib' and does not support multilib
+which will change it. Respect variable wxPLATFORM_LIB_DIR to support
+libdir be configurable.
Upstream-Status: Pending
Signed-off-by: Kai Kang <kai.kang@windriver.com>
-Rebase for wxWidgets 3.2.1. Replace wxPLATFORM_LIB_DIR with LIB_SUFFIX in this
-patch that LIB_SUFFIX has been passed to cmake in cmake.bbclass.
+Rebase for wxWidgets 3.2.1. Replace wxPLATFORM_LIB_DIR with LIB_SUFFIX
+in this patch that LIB_SUFFIX has been passed to cmake in cmake.bbclass.
Signed-off-by: Kai Kang <kai.kang@windriver.com>
---
@@ -17,36 +23,36 @@ Signed-off-by: Kai Kang <kai.kang@windriver.com>
4 files changed, 10 insertions(+), 10 deletions(-)
diff --git a/CMakeLists.txt b/CMakeLists.txt
-index a49ecd3883..d469471f38 100644
+index f6ae7f6210..2a13e448db 100644
--- a/CMakeLists.txt
+++ b/CMakeLists.txt
@@ -45,7 +45,7 @@ include(build/cmake/policies.cmake NO_POLICY_SCOPE)
# Initialize variables for quick access to wx root dir in sub dirs
set(wxSOURCE_DIR ${CMAKE_CURRENT_SOURCE_DIR})
- set(wxBINARY_DIR ${CMAKE_BINARY_DIR})
+ set(wxBINARY_DIR ${CMAKE_CURRENT_BINARY_DIR})
-set(wxOUTPUT_DIR ${wxBINARY_DIR}/lib)
+set(wxOUTPUT_DIR ${wxBINARY_DIR}/lib${LIB_SUFFIX})
# parse the version number from wx/version.h and include in wxMAJOR_VERSION and wxMINOR_VERSION
file(READ "${wxSOURCE_DIR}/include/wx/version.h" WX_VERSION_H_CONTENTS)
diff --git a/build/cmake/config.cmake b/build/cmake/config.cmake
-index b359560bc0..c59ea60923 100644
+index addd8d6b81..9ec677534b 100644
--- a/build/cmake/config.cmake
+++ b/build/cmake/config.cmake
-@@ -76,7 +76,7 @@ function(wx_write_config_inplace)
+@@ -100,7 +100,7 @@ function(wx_write_config_inplace)
execute_process(
COMMAND
"${CMAKE_COMMAND}" -E ${COPY_CMD}
-- "${CMAKE_CURRENT_BINARY_DIR}/lib/wx/config/inplace-${TOOLCHAIN_FULLNAME}"
-+ "${CMAKE_CURRENT_BINARY_DIR}/lib${LIB_SUFFIX}/wx/config/inplace-${TOOLCHAIN_FULLNAME}"
- "${CMAKE_CURRENT_BINARY_DIR}/wx-config"
+- "${wxBINARY_DIR}/lib/wx/config/inplace-${TOOLCHAIN_FULLNAME}"
++ "${wxBINARY_DIR}/lib${LIB_SUFFIX}/wx/config/inplace-${TOOLCHAIN_FULLNAME}"
+ "${wxBINARY_DIR}/wx-config"
)
endfunction()
diff --git a/build/cmake/functions.cmake b/build/cmake/functions.cmake
-index 7182364e5e..55fbebc7ee 100644
+index 72a34f0b4f..81ede7d8ae 100644
--- a/build/cmake/functions.cmake
+++ b/build/cmake/functions.cmake
-@@ -435,8 +435,8 @@ macro(wx_add_library name)
+@@ -462,8 +462,8 @@ macro(wx_add_library name)
endif()
wx_install(TARGETS ${name}
EXPORT wxWidgetsTargets
@@ -105,3 +111,6 @@ index 384c6837b8..d3303faabb 100644
)
# uninstall target
+--
+2.25.1
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/create-links-with-relative-path.patch b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0003-create-links-with-relative-path.patch
index 6eef0b6790..dbede0304f 100644
--- a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/create-links-with-relative-path.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0003-create-links-with-relative-path.patch
@@ -1,18 +1,23 @@
+From b86806ef34d4c9171165c1533064bf34ad822e20 Mon Sep 17 00:00:00 2001
+From: Kai Kang <kai.kang@windriver.com>
+Date: Sat, 12 Oct 2024 18:43:25 +0800
+Subject: [PATCH] create links with relative path
+
It fails to build python3-wxgtk4 which depends on wxwidgets:
| ERROR: wxwidgets-native-3.2.1-r0 do_populate_sysroot: sstate found an
absolute path symlink /path/to/build/tmp-glibc/work/x86_64-linux
- /wxwidgets-native/3.2.1-r0/sysroot-destdir/path/to/build/tmp-glibc/work
- /x86_64-linux/wxwidgets-native/3.2.1-r0/recipe-sysroot-native/usr/bin/wx-config
+ /wxwidgets-native/3.2.1-r0/sysroot-destdir/path/to/build/tmp-glibc/work
+ /x86_64-linux/wxwidgets-native/3.2.1-r0/recipe-sysroot-native/usr/bin/wx-config
pointing at /path/to/build/tmp-glibc/work/x86_64-linux/wxwidgets-native/3.2.1-r0
- /recipe-sysroot-native/usr/lib/wx/config/gtk3-unicode-3.2.
+ /recipe-sysroot-native/usr/lib/wx/config/gtk3-unicode-3.2.
Please replace this with a relative link.
| ERROR: wxwidgets-native-3.2.1-r0 do_populate_sysroot: sstate found an
absolute path symlink /path/to/build/tmp-glibc/work/x86_64-linux/wxwidgets-native
- /3.2.1-r0/sysroot-destdir/path/to/build/tmp-glibc/work/x86_64-linux/wxwidgets-native
- /3.2.1-r0/recipe-sysroot-native/usr/bin/wxrc pointing at /path/to/build/tmp-glibc
- /work/x86_64-linux/wxwidgets-native/3.2.1-r0/recipe-sysroot-native/usr/bin/wxrc-3.2.
- Please replace this with a relative link.
+ /3.2.1-r0/sysroot-destdir/path/to/build/tmp-glibc/work/x86_64-linux/wxwidgets-native
+ /3.2.1-r0/recipe-sysroot-native/usr/bin/wxrc pointing at /path/to/build/tmp-glibc
+ /work/x86_64-linux/wxwidgets-native/3.2.1-r0/recipe-sysroot-native/usr/bin/wxrc-3.2.
+ Please replace this with a relative link.
Create symlink with relative path to fix the issues.
@@ -50,3 +55,6 @@ index dbed8cc9b3..1dbc3261d3 100644
\"\$ENV{DESTDIR}${CMAKE_INSTALL_PREFIX}/bin/wxrc${EXE_SUFFIX}\" \
)"
)
+--
+2.25.1
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/not-append-system-name-to-lib-name.patch b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0004-don-not-append-system-name-to-lib-name.patch
index 6329256b0c..e3463ba170 100644
--- a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/not-append-system-name-to-lib-name.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0004-don-not-append-system-name-to-lib-name.patch
@@ -1,3 +1,8 @@
+From 5e9725c1151e2b029066d61ef5dccf1f3e6cb323 Mon Sep 17 00:00:00 2001
+From: Kai Kang <kai.kang@windriver.com>
+Date: Sat, 12 Oct 2024 18:43:25 +0800
+Subject: [PATCH] don not append system name to lib name
+
It appends system name to library names for cross compile. For example, the
library name is libwx_baseu-3.1-Linux.so rather than libwx_baseu-3.1.so. It is
not appropriate for oe.
@@ -14,10 +19,10 @@ Signed-off-by: Kai Kang <kai.kang@windriver.com>
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/build/cmake/functions.cmake b/build/cmake/functions.cmake
-index e374d9a273..c6b1908bd6 100644
+index 81ede7d8ae..23eebeb914 100644
--- a/build/cmake/functions.cmake
+++ b/build/cmake/functions.cmake
-@@ -219,9 +219,9 @@ function(wx_set_target_properties target_name)
+@@ -243,9 +243,9 @@ function(wx_set_target_properties target_name)
endif()
set(cross_target)
@@ -30,3 +35,6 @@ index e374d9a273..c6b1908bd6 100644
set(lib_prefix "lib")
if(MSVC OR (WIN32 AND wxBUILD_SHARED))
+--
+2.25.1
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/wx-config-fix-libdir-for-multilib.patch b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0005-wx-config-fix-libdir-for-multilib.patch
index 628f8dee56..b650c50386 100644
--- a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/wx-config-fix-libdir-for-multilib.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0005-wx-config-fix-libdir-for-multilib.patch
@@ -1,8 +1,14 @@
-It sets 'libdir' with path element 'lib' directly which is not suitable for
-multilib. Add an option '--baselib' for wx-config to support multilib when
-cross compile. And set default value of baselib with "lib${wxPLATFORM_LIB_DIR}".
+From 4230cd84f156f9eb5c9b80ffbc69dd55fa7c7ca7 Mon Sep 17 00:00:00 2001
+From: Kai Kang <kai.kang@windriver.com>
+Date: Sat, 12 Oct 2024 18:43:25 +0800
+Subject: [PATCH] wx-config: fix libdir for multilib
-Upstream-Status: Pending [oe specific]
+It sets 'libdir' with path element 'lib' directly which is not suitable
+for multilib. Add an option '--baselib' for wx-config to support
+multilib when cross compile. And set default value of baselib with
+"lib${wxPLATFORM_LIB_DIR}".
+
+Upstream-Status: Inappropriate [oe specific]
Signed-off-by: Kai Kang <kai.kang@windriver.com>
@@ -15,10 +21,10 @@ Signed-off-by: Kai Kang <kai.kang@windriver.com>
2 files changed, 5 insertions(+), 3 deletions(-)
diff --git a/build/cmake/config.cmake b/build/cmake/config.cmake
-index 52ae69d3f6..28aa733eb0 100644
+index 9ec677534b..ee61cf7572 100644
--- a/build/cmake/config.cmake
+++ b/build/cmake/config.cmake
-@@ -86,7 +86,7 @@ function(wx_write_config)
+@@ -110,7 +110,7 @@ function(wx_write_config)
set(prefix ${CMAKE_INSTALL_PREFIX})
set(exec_prefix "\${prefix}")
set(includedir "\${prefix}/include")
@@ -26,9 +32,9 @@ index 52ae69d3f6..28aa733eb0 100644
+ set(libdir "\${exec_prefix}/\${baselib}")
set(bindir "\${exec_prefix}/bin")
- find_program(EGREP egrep)
+ if(wxBUILD_MONOLITHIC)
diff --git a/wx-config.in b/wx-config.in
-index e3f7d115bb..0e78af03c7 100755
+index 1173d89685..8364a33e9d 100755
--- a/wx-config.in
+++ b/wx-config.in
@@ -42,7 +42,8 @@ usage()
@@ -41,7 +47,7 @@ index e3f7d115bb..0e78af03c7 100755
[--list] [--selected-config] [--host=HOST] [--toolkit=TOOLKIT]
[--universal[=yes|no]] [--unicode[=yes|no]] [--static[=yes|no]]
[--debug[=yes|no]] [--version[=VERSION]] [--flavour=FLAVOUR]
-@@ -137,7 +138,7 @@ wxconfig_output_options="prefix exec_prefix
+@@ -133,7 +134,7 @@ wxconfig_output_options="prefix exec_prefix
# Options that permit the user to supply hints that may affect the output.
# These options all accept arbitrary values, to interpret as they please.
@@ -50,7 +56,7 @@ index e3f7d115bb..0e78af03c7 100755
# Input options that accept only a yes or no argument.
#
-@@ -404,6 +405,7 @@ is_cross() { [ "x@cross_compiling@" = "xyes" ]; }
+@@ -400,6 +401,7 @@ is_cross() { [ "xno" = "xyes" ]; }
# Determine the base directories we require.
prefix=${input_option_prefix-${this_prefix:-@prefix@}}
exec_prefix=${input_option_exec_prefix-${input_option_prefix-${this_exec_prefix:-@exec_prefix@}}}
@@ -58,3 +64,6 @@ index e3f7d115bb..0e78af03c7 100755
wxconfdir="@libdir@/wx/config"
installed_configs=`cd "$wxconfdir" 2> /dev/null && ls | grep -v "^inplace-"`
+--
+2.25.1
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/musl-locale-l.patch b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0006-Fix-locale-on-musl.patch
index e4ca6579f8..37d61dcb3f 100644
--- a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/musl-locale-l.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0006-Fix-locale-on-musl.patch
@@ -1,8 +1,19 @@
-Upstream-Status: Pending
+From 64d5d7f68cde208c6f8a5e0b71da93f98e4720f7 Mon Sep 17 00:00:00 2001
+From: Khem Raj <raj.khem@gmail.com>
+Date: Sat, 12 Oct 2024 20:30:16 +0800
+Subject: [PATCH] Fix locale on musl
these macro'd away functions don't exist in musl (yet)
+
+Upstream-Status: Pending
+
+Signed-off-by: Khem Raj <raj.khem@gmail.com>
+---
+ include/wx/xlocale.h | 20 ++++++++++++++++++++
+ 1 file changed, 20 insertions(+)
+
diff --git a/include/wx/xlocale.h b/include/wx/xlocale.h
-index c433d25..3ab9d84 100644
+index c433d25d05..794cf0b66b 100644
--- a/include/wx/xlocale.h
+++ b/include/wx/xlocale.h
@@ -33,6 +33,26 @@
@@ -32,3 +43,6 @@ index c433d25..3ab9d84 100644
// The platform-specific locale type
// If wxXLocale_t is not defined, then only "C" locale support is provided
#ifdef wxHAS_XLOCALE_SUPPORT
+--
+2.25.1
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0001-Set-HAVE_LARGEFILE_SUPPORT-to-1-explicitly.patch b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0007-Set-HAVE_LARGEFILE_SUPPORT-to-1-explicitly.patch
index 5160f2e1fe..ef94e3551b 100644
--- a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0001-Set-HAVE_LARGEFILE_SUPPORT-to-1-explicitly.patch
+++ b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/0007-Set-HAVE_LARGEFILE_SUPPORT-to-1-explicitly.patch
@@ -1,4 +1,4 @@
-From e108aff9d6dae613f486c1b1681f4a3cdf17b845 Mon Sep 17 00:00:00 2001
+From 22f70d5bd039b20bfdad522341412ca001c639db Mon Sep 17 00:00:00 2001
From: Khem Raj <raj.khem@gmail.com>
Date: Mon, 19 Dec 2022 15:07:55 -0800
Subject: [PATCH] Set HAVE_LARGEFILE_SUPPORT to 1 explicitly
@@ -6,16 +6,17 @@ Subject: [PATCH] Set HAVE_LARGEFILE_SUPPORT to 1 explicitly
nothing sets this to 0, but for some reason it gets undef'd
Upstream-Status: Pending
+
Signed-off-by: Khem Raj <raj.khem@gmail.com>
---
build/cmake/setup.h.in | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/build/cmake/setup.h.in b/build/cmake/setup.h.in
-index bce33a73f3..22afb4cfa0 100644
+index fcc282980d..767adbf658 100644
--- a/build/cmake/setup.h.in
+++ b/build/cmake/setup.h.in
-@@ -869,8 +869,7 @@
+@@ -867,8 +867,7 @@
/*
* Define if large (64 bit file offsets) files are supported.
*/
@@ -26,5 +27,5 @@ index bce33a73f3..22afb4cfa0 100644
* Use OpenGL
*/
--
-2.39.0
+2.25.1
diff --git a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/CVE-2024-58249.patch b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/CVE-2024-58249.patch
new file mode 100644
index 0000000000..8ba9cc1b04
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets/CVE-2024-58249.patch
@@ -0,0 +1,178 @@
+From e440b3a6097546a8aca66bd4c7a21be25e89d340 Mon Sep 17 00:00:00 2001
+From: Vadim Zeitlin <vadim@wxwidgets.org>
+Date: Sun, 27 Oct 2024 00:56:21 +0200
+Subject: [PATCH] Fix crash when connection is refused in wxWebRequestCURL
+
+Avoid deleting wxEventLoopSourceHandler which may be still in use, as is
+the case when we get write IO notification just before an error one: if
+we delete the handler while handling the former, we crash when getting
+the latter one.
+
+Use a hack to avoid deleting the handlers for which write notification
+is being processed and delete them later, when we get the error one.
+
+See #24885.
+
+(cherry picked from commit 4e0fca8ab9756989598d07b41e672af86eac7092)
+
+CVE: CVE-2024-58249
+Upstream-Status: Backport [https://github.com/wxWidgets/wxWidgets/commit/f2918a9ac823074901ce27de939baa57788beb3d]
+
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ src/common/webrequest_curl.cpp | 80 +++++++++++++++++++++++++---------
+ 1 file changed, 60 insertions(+), 20 deletions(-)
+
+diff --git a/src/common/webrequest_curl.cpp b/src/common/webrequest_curl.cpp
+index f50acf4f8d..64650ab6b4 100644
+--- a/src/common/webrequest_curl.cpp
++++ b/src/common/webrequest_curl.cpp
+@@ -704,10 +704,13 @@ SocketPollerImpl* SocketPollerImpl::Create(wxEvtHandler* hndlr)
+
+ // SocketPollerSourceHandler - a source handler used by the SocketPoller class.
+
++class SourceSocketPoller;
++
+ class SocketPollerSourceHandler: public wxEventLoopSourceHandler
+ {
+ public:
+- SocketPollerSourceHandler(curl_socket_t, wxEvtHandler*);
++ SocketPollerSourceHandler(curl_socket_t sock, SourceSocketPoller* poller)
++ : m_socket(sock), m_poller(poller) {}
+
+ void OnReadWaiting() wxOVERRIDE;
+ void OnWriteWaiting() wxOVERRIDE;
+@@ -716,16 +719,9 @@ public:
+ private:
+ void SendEvent(int);
+ curl_socket_t m_socket;
+- wxEvtHandler* m_handler;
++ SourceSocketPoller* const m_poller;
+ };
+
+-SocketPollerSourceHandler::SocketPollerSourceHandler(curl_socket_t sock,
+- wxEvtHandler* hndlr)
+-{
+- m_socket = sock;
+- m_handler = hndlr;
+-}
+-
+ void SocketPollerSourceHandler::OnReadWaiting()
+ {
+ SendEvent(SocketPoller::READY_FOR_READ);
+@@ -741,14 +737,6 @@ void SocketPollerSourceHandler::OnExceptionWaiting()
+ SendEvent(SocketPoller::HAS_ERROR);
+ }
+
+-void SocketPollerSourceHandler::SendEvent(int result)
+-{
+- wxThreadEvent event(wxEVT_SOCKET_POLLER_RESULT);
+- event.SetPayload<curl_socket_t>(m_socket);
+- event.SetInt(result);
+- m_handler->ProcessEvent(event);
+-}
+-
+ // SourceSocketPoller - a SocketPollerImpl based on event loop sources.
+
+ class SourceSocketPoller: public SocketPollerImpl
+@@ -760,6 +748,8 @@ public:
+ void StopPolling(curl_socket_t) wxOVERRIDE;
+ void ResumePolling(curl_socket_t) wxOVERRIDE;
+
++ void SendEvent(curl_socket_t sock, int result);
++
+ private:
+ WX_DECLARE_HASH_MAP(curl_socket_t, wxEventLoopSource*, wxIntegerHash,\
+ wxIntegerEqual, SocketDataMap);
+@@ -768,11 +758,25 @@ private:
+
+ SocketDataMap m_socketData;
+ wxEvtHandler* m_handler;
++
++ // The socket for which we're currently processing a write IO notification.
++ curl_socket_t m_activeWriteSocket;
++
++ // The sockets that we couldn't clean up yet but should do if/when we get
++ // an error notification for them.
++ wxVector<curl_socket_t> m_socketsToCleanUp;
+ };
+
++// This function must be implemented after full SourceSocketPoller declaration.
++void SocketPollerSourceHandler::SendEvent(int result)
++{
++ m_poller->SendEvent(m_socket, result);
++}
++
+ SourceSocketPoller::SourceSocketPoller(wxEvtHandler* hndlr)
+ {
+ m_handler = hndlr;
++ m_activeWriteSocket = 0;
+ }
+
+ SourceSocketPoller::~SourceSocketPoller()
+@@ -822,9 +826,7 @@ bool SourceSocketPoller::StartPolling(curl_socket_t sock, int pollAction)
+ }
+ else
+ {
+- // Otherwise create a new source handler.
+- srcHandler =
+- new SocketPollerSourceHandler(sock, m_handler);
++ srcHandler = new SocketPollerSourceHandler(sock, this);
+ }
+
+ // Get a new source object for these polling checks.
+@@ -858,6 +860,15 @@ bool SourceSocketPoller::StartPolling(curl_socket_t sock, int pollAction)
+
+ void SourceSocketPoller::StopPolling(curl_socket_t sock)
+ {
++ if ( sock == m_activeWriteSocket )
++ {
++ // We can't clean up the socket while we're inside OnWriteWaiting() for
++ // it because it could be followed by OnExceptionWaiting() and we'd
++ // crash if we deleted it already.
++ m_socketsToCleanUp.push_back(sock);
++ return;
++ }
++
+ SocketDataMap::iterator it = m_socketData.find(sock);
+
+ if ( it != m_socketData.end() )
+@@ -871,6 +882,35 @@ void SourceSocketPoller::ResumePolling(curl_socket_t WXUNUSED(sock))
+ {
+ }
+
++void SourceSocketPoller::SendEvent(curl_socket_t sock, int result)
++{
++ if ( result == SocketPoller::READY_FOR_WRITE )
++ {
++ // Prevent the handler from this socket from being deleted in case we
++ // get a HAS_ERROR event for it immediately after this one.
++ m_activeWriteSocket = sock;
++ }
++
++ wxThreadEvent event(wxEVT_SOCKET_POLLER_RESULT);
++ event.SetPayload<curl_socket_t>(sock);
++ event.SetInt(result);
++ m_handler->ProcessEvent(event);
++
++ m_activeWriteSocket = 0;
++
++ if ( result == SocketPoller::HAS_ERROR )
++ {
++ // Check if we have any sockets to clean up and do it now, it should be
++ // safe.
++ for ( size_t n = 0; n < m_socketsToCleanUp.size(); ++n )
++ {
++ StopPolling(m_socketsToCleanUp[n]);
++ }
++
++ m_socketsToCleanUp.clear();
++ }
++}
++
+ void SourceSocketPoller::CleanUpSocketSource(wxEventLoopSource* source)
+ {
+ wxEventLoopSourceHandler* srcHandler = source->GetHandler();
+--
+2.50.0
+
diff --git a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets_3.2.1.bb b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets_3.2.6.bb
index 91653e2852..1cf44bbfa3 100644
--- a/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets_3.2.1.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/wxwidgets/wxwidgets_3.2.6.bb
@@ -20,17 +20,19 @@ DEPENDS += " \
SRC_URI = "gitsm://github.com/wxWidgets/wxWidgets.git;branch=3.2;protocol=https \
file://0001-wx-config.in-Disable-cross-magic-it-does-not-work-fo.patch \
- file://fix-libdir-for-multilib.patch \
- file://create-links-with-relative-path.patch \
- file://not-append-system-name-to-lib-name.patch \
- file://wx-config-fix-libdir-for-multilib.patch \
- file://0001-locale-Avoid-using-glibc-specific-defines-on-musl.patch \
- file://musl-locale-l.patch \
- file://0001-Set-HAVE_LARGEFILE_SUPPORT-to-1-explicitly.patch \
+ file://0002-fix-libdir-for-multilib.patch \
+ file://0003-create-links-with-relative-path.patch \
+ file://0004-don-not-append-system-name-to-lib-name.patch \
+ file://0005-wx-config-fix-libdir-for-multilib.patch \
+ file://0006-Fix-locale-on-musl.patch \
+ file://0007-Set-HAVE_LARGEFILE_SUPPORT-to-1-explicitly.patch \
+ file://CVE-2024-58249.patch \
"
-SRCREV= "97e99707c5d2271a70cb686720b48dbf34ced496"
+SRCREV = "5ff25322553c1870cf20a2e1ba6f20ed50d9fe9a"
S = "${WORKDIR}/git"
+UPSTREAM_CHECK_GITTAGREGEX = "v(?P<pver>\d+(\.\d+)+)"
+
# These can be either 'builtin' or 'sys' and builtin means cloned soures are
# build. So these cannot be PACKAGECONFIGs and let's use libs where we can (see
# DEPENDS)
diff --git a/meta-openembedded/meta-oe/recipes-extended/zlog/zlog/0001-CVE-2024-22857-buffer-overflow-patched.patch b/meta-openembedded/meta-oe/recipes-extended/zlog/zlog/0001-CVE-2024-22857-buffer-overflow-patched.patch
new file mode 100644
index 0000000000..1f11b07216
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-extended/zlog/zlog/0001-CVE-2024-22857-buffer-overflow-patched.patch
@@ -0,0 +1,31 @@
+From bffbd94a0807efbab0f449b13d622d3cffa224a4 Mon Sep 17 00:00:00 2001
+From: Ali Raza <elirazamumtaz@gmail.com>
+Date: Thu, 29 Feb 2024 11:36:25 +0500
+Subject: [PATCH] CVE-2024-22857: buffer overflow patched
+
+CVE: CVE-2024-22857
+Upstream-Status: Backport [https://github.com/HardySimpson/zlog/commit/c47f781a9f1e9604f5201e27d046d925d0d48ac4]
+
+(cherry picked from commit c47f781a9f1e9604f5201e27d046d925d0d48ac4)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/rule.c | 6 ++++--
+ 1 file changed, 4 insertions(+), 2 deletions(-)
+
+diff --git a/src/rule.c b/src/rule.c
+index ae3d74f..38d3fdc 100644
+--- a/src/rule.c
++++ b/src/rule.c
+@@ -866,8 +866,10 @@ zlog_rule_t *zlog_rule_new(char *line,
+ }
+ break;
+ case '$' :
+- sscanf(file_path + 1, "%s", a_rule->record_name);
+-
++ // read only MAXLEN_PATH characters from the file_path + 1
++ strncpy(a_rule->record_name, file_path + 1, MAXLEN_PATH);
++ a_rule->record_name[MAXLEN_PATH] = '\0';
++
+ if (file_limit) { /* record path exists */
+ p = strchr(file_limit, '"');
+ if (!p) {
diff --git a/meta-openembedded/meta-oe/recipes-extended/zlog/zlog_1.2.16.bb b/meta-openembedded/meta-oe/recipes-extended/zlog/zlog_1.2.16.bb
index b75802f09f..86a465d285 100644
--- a/meta-openembedded/meta-oe/recipes-extended/zlog/zlog_1.2.16.bb
+++ b/meta-openembedded/meta-oe/recipes-extended/zlog/zlog_1.2.16.bb
@@ -4,7 +4,9 @@ LICENSE = "LGPL-2.1-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=4fbd65380cdd255951079008b364516c"
SRCREV = "dc2c284664757fce6ef8f96f8b3ab667a53ef489"
-SRC_URI = "git://github.com/HardySimpson/zlog;branch=master;protocol=https"
+SRC_URI = "git://github.com/HardySimpson/zlog;branch=master;protocol=https \
+ file://0001-CVE-2024-22857-buffer-overflow-patched.patch \
+ "
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-oe/recipes-gnome/gcab/gcab/0001-gcab-enums.c.etemplate-include-basename-instead-of-f.patch b/meta-openembedded/meta-oe/recipes-gnome/gcab/gcab/0001-gcab-enums.c.etemplate-include-basename-instead-of-f.patch
new file mode 100644
index 0000000000..dd6ae1b427
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-gnome/gcab/gcab/0001-gcab-enums.c.etemplate-include-basename-instead-of-f.patch
@@ -0,0 +1,37 @@
+From 6fa1b6d3f72caf6d0cf61752b522dc19fb9933b7 Mon Sep 17 00:00:00 2001
+From: Martin Jansa <martin.jansa@gmail.com>
+Date: Fri, 30 Aug 2024 10:44:17 +0200
+Subject: [PATCH] gcab-enums.c.etemplate: include @basename@ instead of full
+ path from @filename@
+
+* fixes:
+ ERROR: QA Issue: File /usr/src/debug/gcab/1.6/libgcab/gcab-enums.c in package gcab-src contains reference to TMPDIR [buildpaths]
+
+lib32-gcab/1.6/package $ grep -R styhead .
+./usr/src/debug/lib32-gcab/1.6/libgcab/gcab-enums.c:#include "WORKDIR/build/../gcab-1.6/libgcab/gcab-file.h"
+./usr/src/debug/lib32-gcab/1.6/libgcab/gcab-enums.c:#include "WORKDIR/build/../gcab-1.6/libgcab/gcab-folder.h"
+
+glib-mkenum supports also @basename@ since 2.22 which would avoid this QA issue
+ @filename@ name of current input file
+ @basename@ base name of the current input file (Since: 2.22)
+
+Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
+---
+Upstream-Status: Pending
+
+ libgcab/gcab-enums.c.etemplate | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/libgcab/gcab-enums.c.etemplate b/libgcab/gcab-enums.c.etemplate
+index 194b1e0..2e85824 100644
+--- a/libgcab/gcab-enums.c.etemplate
++++ b/libgcab/gcab-enums.c.etemplate
+@@ -21,7 +21,7 @@
+ /*** END file-header ***/
+
+ /*** BEGIN file-production ***/
+-#include "@filename@"
++#include "@basename@"
+ /*** END file-production ***/
+
+
diff --git a/meta-openembedded/meta-oe/recipes-gnome/gcab/gcab_1.6.bb b/meta-openembedded/meta-oe/recipes-gnome/gcab/gcab_1.6.bb
index 4278fc9453..503d25271f 100644
--- a/meta-openembedded/meta-oe/recipes-gnome/gcab/gcab_1.6.bb
+++ b/meta-openembedded/meta-oe/recipes-gnome/gcab/gcab_1.6.bb
@@ -7,6 +7,7 @@ DEPENDS = "glib-2.0"
SRC_URI = "\
${GNOME_MIRROR}/gcab/${PV}/gcab-${PV}.tar.xz \
+ file://0001-gcab-enums.c.etemplate-include-basename-instead-of-f.patch \
file://run-ptest \
"
SRC_URI[sha256sum] = "2f0c9615577c4126909e251f9de0626c3ee7a152376c15b5544df10fc87e560b"
diff --git a/meta-openembedded/meta-oe/recipes-gnome/gtk+/gtk+/CVE-2024-6655.patch b/meta-openembedded/meta-oe/recipes-gnome/gtk+/gtk+/CVE-2024-6655.patch
new file mode 100644
index 0000000000..dfa54f2f31
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-gnome/gtk+/gtk+/CVE-2024-6655.patch
@@ -0,0 +1,40 @@
+From 3bbf0b6176d42836d23c36a6ac410e807ec0a7a7 Mon Sep 17 00:00:00 2001
+From: Matthias Clasen <mclasen@redhat.com>
+Date: Sat, 15 Jun 2024 14:18:01 -0400
+Subject: [PATCH] Stop looking for modules in cwd
+
+This is just not a good idea. It is surprising, and can be misused.
+
+Fixes: #6786
+
+CVE: CVE-2024-6655
+
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/gtk/-/commit/3bbf0b6176d42836d23c36a6ac410e807ec0a7a7]
+
+Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
+---
+ gtk/gtkmodules.c | 9 ++-------
+ 1 file changed, 2 insertions(+), 7 deletions(-)
+
+diff --git a/gtk/gtkmodules.c b/gtk/gtkmodules.c
+index e09b583..e75810c 100644
+--- a/gtk/gtkmodules.c
++++ b/gtk/gtkmodules.c
+@@ -225,13 +225,8 @@ find_module (const gchar *name)
+ gchar *module_name;
+
+ module_name = _gtk_find_module (name, "modules");
+- if (!module_name)
+- {
+- /* As last resort, try loading without an absolute path (using system
+- * library path)
+- */
+- module_name = g_module_build_path (NULL, name);
+- }
++ if (module_name == NULL)
++ return NULL;
+
+ module = g_module_open (module_name, G_MODULE_BIND_LOCAL | G_MODULE_BIND_LAZY);
+
+--
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-gnome/gtk+/gtk+_2.24.33.bb b/meta-openembedded/meta-oe/recipes-gnome/gtk+/gtk+_2.24.33.bb
index 5eac641cf3..8b9f6723dd 100644
--- a/meta-openembedded/meta-oe/recipes-gnome/gtk+/gtk+_2.24.33.bb
+++ b/meta-openembedded/meta-oe/recipes-gnome/gtk+/gtk+_2.24.33.bb
@@ -11,6 +11,7 @@ SRC_URI = "http://ftp.gnome.org/pub/gnome/sources/gtk+/2.24/gtk+-${PV}.tar.xz \
file://strict-prototypes.patch \
file://0001-Do-not-look-into-HOME-when-looking-for-gtk-modules.patch \
file://0001-Fix-signature-of-create_menu-function.patch \
+ file://CVE-2024-6655.patch \
"
SRC_URI[sha256sum] = "ac2ac757f5942d318a311a54b0c80b5ef295f299c2a73c632f6bfb1ff49cc6da"
diff --git a/meta-openembedded/meta-oe/recipes-gnome/libjcat/libjcat_0.2.1.bb b/meta-openembedded/meta-oe/recipes-gnome/libjcat/libjcat_0.2.1.bb
index 2d95e14447..7dc88d7279 100644
--- a/meta-openembedded/meta-oe/recipes-gnome/libjcat/libjcat_0.2.1.bb
+++ b/meta-openembedded/meta-oe/recipes-gnome/libjcat/libjcat_0.2.1.bb
@@ -32,3 +32,5 @@ GTKDOC_MESON_OPTION = "gtkdoc"
RDEPENDS:${PN}:class-target = "\
${@bb.utils.contains('PACKAGECONFIG', 'gpg', 'gnupg', '', d)} \
"
+
+INSANE_SKIP:${PN}-ptest += "buildpaths"
diff --git a/meta-openembedded/meta-oe/recipes-graphics/fontforge/fontforge/CVE-2024-25081_CVE-2024-25082.patch b/meta-openembedded/meta-oe/recipes-graphics/fontforge/fontforge/CVE-2024-25081_CVE-2024-25082.patch
new file mode 100644
index 0000000000..40f85e9f33
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-graphics/fontforge/fontforge/CVE-2024-25081_CVE-2024-25082.patch
@@ -0,0 +1,181 @@
+From 216eb14b558df344b206bf82e2bdaf03a1f2f429 Mon Sep 17 00:00:00 2001
+From: Peter Kydas <pk@canva.com>
+Date: Tue, 6 Feb 2024 20:03:04 +1100
+Subject: [PATCH] fix splinefont shell command injection (#5367)
+
+CVE: CVE-2024-25081
+CVE: CVE-2024-25082
+Upstream-Status: Backport [https://github.com/fontforge/fontforge/commit/216eb14b558df344b206bf82e2bdaf03a1f2f429]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ fontforge/splinefont.c | 123 +++++++++++++++++++++++++++++------------
+ 1 file changed, 89 insertions(+), 34 deletions(-)
+
+diff --git a/fontforge/splinefont.c b/fontforge/splinefont.c
+index 239fdc035..647daee10 100644
+--- a/fontforge/splinefont.c
++++ b/fontforge/splinefont.c
+@@ -788,11 +788,14 @@ return( name );
+
+ char *Unarchive(char *name, char **_archivedir) {
+ char *dir = getenv("TMPDIR");
+- char *pt, *archivedir, *listfile, *listcommand, *unarchivecmd, *desiredfile;
++ char *pt, *archivedir, *listfile, *desiredfile;
+ char *finalfile;
+ int i;
+ int doall=false;
+ static int cnt=0;
++ gchar *command[5];
++ gchar *stdoutresponse = NULL;
++ gchar *stderrresponse = NULL;
+
+ *_archivedir = NULL;
+
+@@ -827,18 +830,30 @@ return( NULL );
+ listfile = malloc(strlen(archivedir)+strlen("/" TOC_NAME)+1);
+ sprintf( listfile, "%s/" TOC_NAME, archivedir );
+
+- listcommand = malloc( strlen(archivers[i].unarchive) + 1 +
+- strlen( archivers[i].listargs) + 1 +
+- strlen( name ) + 3 +
+- strlen( listfile ) +4 );
+- sprintf( listcommand, "%s %s %s > %s", archivers[i].unarchive,
+- archivers[i].listargs, name, listfile );
+- if ( system(listcommand)!=0 ) {
+- free(listcommand); free(listfile);
+- ArchiveCleanup(archivedir);
+-return( NULL );
++ command[0] = archivers[i].unarchive;
++ command[1] = archivers[i].listargs;
++ command[2] = name;
++ command[3] = NULL; // command args need to be NULL-terminated
++
++ if ( g_spawn_sync(
++ NULL,
++ command,
++ NULL,
++ G_SPAWN_SEARCH_PATH,
++ NULL,
++ NULL,
++ &stdoutresponse,
++ &stderrresponse,
++ NULL,
++ NULL
++ ) == FALSE) { // did not successfully execute
++ ArchiveCleanup(archivedir);
++ return( NULL );
+ }
+- free(listcommand);
++ // Write out the listfile to be read in later
++ FILE *fp = fopen(listfile, "wb");
++ fwrite(stdoutresponse, strlen(stdoutresponse), 1, fp);
++ fclose(fp);
+
+ desiredfile = ArchiveParseTOC(listfile, archivers[i].ars, &doall);
+ free(listfile);
+@@ -847,22 +862,28 @@ return( NULL );
+ return( NULL );
+ }
+
+- /* I tried sending everything to stdout, but that doesn't work if the */
+- /* output is a directory file (ufo, sfdir) */
+- unarchivecmd = malloc( strlen(archivers[i].unarchive) + 1 +
+- strlen( archivers[i].listargs) + 1 +
+- strlen( name ) + 1 +
+- strlen( desiredfile ) + 3 +
+- strlen( archivedir ) + 30 );
+- sprintf( unarchivecmd, "( cd %s ; %s %s %s %s ) > /dev/null", archivedir,
+- archivers[i].unarchive,
+- archivers[i].extractargs, name, doall ? "" : desiredfile );
+- if ( system(unarchivecmd)!=0 ) {
+- free(unarchivecmd); free(desiredfile);
+- ArchiveCleanup(archivedir);
+-return( NULL );
++ command[0] = archivers[i].unarchive;
++ command[1] = archivers[i].extractargs;
++ command[2] = name;
++ command[3] = doall ? "" : desiredfile;
++ command[4] = NULL;
++
++ if ( g_spawn_sync(
++ (gchar*)archivedir,
++ command,
++ NULL,
++ G_SPAWN_SEARCH_PATH,
++ NULL,
++ NULL,
++ &stdoutresponse,
++ &stderrresponse,
++ NULL,
++ NULL
++ ) == FALSE) { // did not successfully execute
++ free(desiredfile);
++ ArchiveCleanup(archivedir);
++ return( NULL );
+ }
+- free(unarchivecmd);
+
+ finalfile = malloc( strlen(archivedir) + 1 + strlen(desiredfile) + 1);
+ sprintf( finalfile, "%s/%s", archivedir, desiredfile );
+@@ -885,20 +906,54 @@ struct compressors compressors[] = {
+
+ char *Decompress(char *name, int compression) {
+ char *dir = getenv("TMPDIR");
+- char buf[1500];
+ char *tmpfn;
+-
++ gchar *command[4];
++ gint stdout_pipe;
++ gchar buffer[4096];
++ gssize bytes_read;
++ GByteArray *binary_data = g_byte_array_new();
++
+ if ( dir==NULL ) dir = P_tmpdir;
+ tmpfn = malloc(strlen(dir)+strlen(GFileNameTail(name))+2);
+ strcpy(tmpfn,dir);
+ strcat(tmpfn,"/");
+ strcat(tmpfn,GFileNameTail(name));
+ *strrchr(tmpfn,'.') = '\0';
+- snprintf( buf, sizeof(buf), "%s < %s > %s", compressors[compression].decomp, name, tmpfn );
+- if ( system(buf)==0 )
+-return( tmpfn );
+- free(tmpfn);
+-return( NULL );
++
++ command[0] = compressors[compression].decomp;
++ command[1] = "-c";
++ command[2] = name;
++ command[3] = NULL;
++
++ // Have to use async because g_spawn_sync doesn't handle nul-bytes in the output (which happens with binary data)
++ if (g_spawn_async_with_pipes(
++ NULL,
++ command,
++ NULL,
++ G_SPAWN_DO_NOT_REAP_CHILD | G_SPAWN_SEARCH_PATH,
++ NULL,
++ NULL,
++ NULL,
++ NULL,
++ &stdout_pipe,
++ NULL,
++ NULL) == FALSE) {
++ //command has failed
++ return( NULL );
++ }
++
++ // Read binary data from pipe and output to file
++ while ((bytes_read = read(stdout_pipe, buffer, sizeof(buffer))) > 0) {
++ g_byte_array_append(binary_data, (guint8 *)buffer, bytes_read);
++ }
++ close(stdout_pipe);
++
++ FILE *fp = fopen(tmpfn, "wb");
++ fwrite(binary_data->data, sizeof(gchar), binary_data->len, fp);
++ fclose(fp);
++ g_byte_array_free(binary_data, TRUE);
++
++ return(tmpfn);
+ }
+
+ static char *ForceFileToHaveName(FILE *file, char *exten) {
diff --git a/meta-openembedded/meta-oe/recipes-graphics/fontforge/fontforge_20230101.bb b/meta-openembedded/meta-oe/recipes-graphics/fontforge/fontforge_20230101.bb
index 31dd495fd7..d470ff12d4 100644
--- a/meta-openembedded/meta-oe/recipes-graphics/fontforge/fontforge_20230101.bb
+++ b/meta-openembedded/meta-oe/recipes-graphics/fontforge/fontforge_20230101.bb
@@ -20,6 +20,7 @@ SRC_URI = "git://github.com/${BPN}/${BPN}.git;branch=master;protocol=https \
file://0001-fontforgeexe-Use-env-to-find-fontforge.patch \
file://0001-cmake-Use-alternate-way-to-detect-libm.patch \
file://0001-Fix-Translations-containing-invalid-directives-hs.patch \
+ file://CVE-2024-25081_CVE-2024-25082.patch \
"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-oe/recipes-graphics/gphoto2/gphoto2_2.5.28.bb b/meta-openembedded/meta-oe/recipes-graphics/gphoto2/gphoto2_2.5.28.bb
index 513845194d..1dc2a1fc34 100644
--- a/meta-openembedded/meta-oe/recipes-graphics/gphoto2/gphoto2_2.5.28.bb
+++ b/meta-openembedded/meta-oe/recipes-graphics/gphoto2/gphoto2_2.5.28.bb
@@ -19,3 +19,6 @@ EXTRA_OECONF += "--with-jpeg-prefix=${STAGING_INCDIR} \
--without-cdk \
"
+do_configure:append() {
+ sed -i -e 's#${RECIPE_SYSROOT}##g' ${B}/config.h
+}
diff --git a/meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz/0001-Set-use_tcl-to-be-empty-string-if-tcl-is-disabled.patch b/meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz/0001-Set-use_tcl-to-be-empty-string-if-tcl-is-disabled.patch
deleted file mode 100644
index 99b53e2e12..0000000000
--- a/meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz/0001-Set-use_tcl-to-be-empty-string-if-tcl-is-disabled.patch
+++ /dev/null
@@ -1,33 +0,0 @@
-From 564901ab78da2b2b1bed92351dc3c102dc0a8154 Mon Sep 17 00:00:00 2001
-From: Khem Raj <raj.khem@gmail.com>
-Date: Tue, 6 Aug 2019 17:51:39 -0700
-Subject: [PATCH] Set use_tcl to be empty string if tcl is disabled
-
-Upstream-Status: Inappropriate [Cross-compile specific]
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
----
- configure.ac | 2 +-
- 1 file changed, 1 insertion(+), 1 deletion(-)
-
---- a/configure.ac
-+++ b/configure.ac
-@@ -1225,7 +1225,7 @@ AC_ARG_ENABLE(tcl,
- [], [enable_tcl=yes])
-
- if test "x$enable_tcl" != "xyes"; then
-- use_tcl="No (disabled)"
-+ use_tcl=""
- fi
-
- if test "x$use_tcl" = "x"; then
---- a/Makefile.am
-+++ b/Makefile.am
-@@ -11,7 +11,7 @@ pkginclude_HEADERS = $(top_builddir)/gra
- dist_man_MANS = graphviz.7
-
- # $(subdirs) contains the list from: AC_CONFIG_SUBDIRS
--SUBDIRS = $(subdirs) lib plugin cmd tclpkg doc contrib share graphs tests
-+SUBDIRS = $(subdirs) lib plugin cmd doc contrib share graphs tests
-
- .PHONY: doxygen
- doxygen:
diff --git a/meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-0001.patch b/meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-0001.patch
new file mode 100644
index 0000000000..7b177370df
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-0001.patch
@@ -0,0 +1,37 @@
+From 361f274ca901c3c476697a6404662d95f4dd43cb Mon Sep 17 00:00:00 2001
+From: Matthew Fernandez <matthew.fernandez@gmail.com>
+Date: Wed, 24 Jul 2024 13:19:03 +0800
+Subject: [PATCH] gvc gvconfig_plugin_install_from_config: more tightly scope
+ 'gv_api'
+
+CVE: CVE-2023-46045
+Upstream-Status: Backport [https://gitlab.com/graphviz/graphviz/-/commit/361f274ca901c3c476697a6404662d95f4dd43cb]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ lib/gvc/gvconfig.c | 3 +--
+ 1 file changed, 1 insertion(+), 2 deletions(-)
+
+diff --git a/lib/gvc/gvconfig.c b/lib/gvc/gvconfig.c
+index d03de09..2f31b98 100644
+--- a/lib/gvc/gvconfig.c
++++ b/lib/gvc/gvconfig.c
+@@ -174,7 +174,6 @@ static int gvconfig_plugin_install_from_config(GVC_t * gvc, char *s)
+ {
+ char *package_path, *name, *api;
+ const char *type;
+- api_t gv_api;
+ int quality;
+ int nest = 0;
+ gvplugin_package_t *package;
+@@ -189,7 +188,7 @@ static int gvconfig_plugin_install_from_config(GVC_t * gvc, char *s)
+ package = gvplugin_package_record(gvc, package_path, name);
+ do {
+ api = token(&nest, &s);
+- gv_api = gvplugin_api(api);
++ const api_t gv_api = gvplugin_api(api);
+ do {
+ if (nest == 2) {
+ type = token(&nest, &s);
+--
+2.25.1
diff --git a/meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-0002.patch b/meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-0002.patch
new file mode 100644
index 0000000000..fbab10bb31
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-0002.patch
@@ -0,0 +1,38 @@
+From 3f31704cafd7da3e86bb2861accf5e90c973e62a Mon Sep 17 00:00:00 2001
+From: Matthew Fernandez <matthew.fernandez@gmail.com>
+Date: Wed, 24 Jul 2024 13:39:39 +0800
+Subject: [PATCH] gvc gvconfig_plugin_install_from_config: more tightly scope
+ 'api'
+
+CVE: CVE-2023-46045
+Upstream-Status: Backport [https://gitlab.com/graphviz/graphviz/-/commit/3f31704cafd7da3e86bb2861accf5e90c973e62a]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ lib/gvc/gvconfig.c | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/lib/gvc/gvconfig.c b/lib/gvc/gvconfig.c
+index 2f31b98..ea0d81b 100644
+--- a/lib/gvc/gvconfig.c
++++ b/lib/gvc/gvconfig.c
+@@ -172,7 +172,7 @@ static char *token(int *nest, char **tokens)
+
+ static int gvconfig_plugin_install_from_config(GVC_t * gvc, char *s)
+ {
+- char *package_path, *name, *api;
++ char *package_path, *name;
+ const char *type;
+ int quality;
+ int nest = 0;
+@@ -187,7 +187,7 @@ static int gvconfig_plugin_install_from_config(GVC_t * gvc, char *s)
+ name = "x";
+ package = gvplugin_package_record(gvc, package_path, name);
+ do {
+- api = token(&nest, &s);
++ const char *api = token(&nest, &s);
+ const api_t gv_api = gvplugin_api(api);
+ do {
+ if (nest == 2) {
+--
+2.25.1
diff --git a/meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-0003.patch b/meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-0003.patch
new file mode 100644
index 0000000000..372f44efee
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-0003.patch
@@ -0,0 +1,33 @@
+From a95f977f5d809915ec4b14836d2b5b7f5e74881e Mon Sep 17 00:00:00 2001
+From: Matthew Fernandez <matthew.fernandez@gmail.com>
+Date: Wed, 24 Jul 2024 15:02:06 +0800
+Subject: [PATCH] gvc: detect plugin installation failure and display an error
+
+Gitlab: fixes #2441
+Reported-by: GJDuck
+
+CVE: CVE-2023-46045
+Upstream-Status: Backport [https://gitlab.com/graphviz/graphviz/-/commit/a95f977f5d809915ec4b14836d2b5b7f5e74881e]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ lib/gvc/gvconfig.c | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/lib/gvc/gvconfig.c b/lib/gvc/gvconfig.c
+index ea0d81b..1eccc70 100644
+--- a/lib/gvc/gvconfig.c
++++ b/lib/gvc/gvconfig.c
+@@ -189,6 +189,10 @@ static int gvconfig_plugin_install_from_config(GVC_t * gvc, char *s)
+ do {
+ const char *api = token(&nest, &s);
+ const api_t gv_api = gvplugin_api(api);
++ if (gv_api == (api_t)-1) {
++ agerr(AGERR, "config error: %s %s not found\n", package_path, api);
++ return 0;
++ }
+ do {
+ if (nest == 2) {
+ type = token(&nest, &s);
+--
+2.25.1
diff --git a/meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz_8.1.0.bb b/meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz_8.1.0.bb
index 2700142e5d..5108f03233 100644
--- a/meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz_8.1.0.bb
+++ b/meta-openembedded/meta-oe/recipes-graphics/graphviz/graphviz_8.1.0.bb
@@ -20,11 +20,10 @@ inherit autotools-brokensep pkgconfig gettext qemu
SRC_URI = "https://gitlab.com/api/v4/projects/4207231/packages/generic/${BPN}-releases/${PV}/${BP}.tar.xz \
file://0001-Autotools-fix-do-not-put-prefix-based-paths-in-compi.patch \
+ file://CVE-2023-46045-0001.patch \
+ file://CVE-2023-46045-0002.patch \
+ file://CVE-2023-46045-0003.patch \
"
-# Use native mkdefs
-SRC_URI:append:class-target = "\
- file://0001-Set-use_tcl-to-be-empty-string-if-tcl-is-disabled.patch \
-"
SRC_URI:append:class-nativesdk = "\
file://graphviz-setup.sh \
"
diff --git a/meta-openembedded/meta-oe/recipes-graphics/gtkwave/gtkwave_3.3.119.bb b/meta-openembedded/meta-oe/recipes-graphics/gtkwave/gtkwave_3.3.119.bb
index 0b1b054041..1b16a22a44 100644
--- a/meta-openembedded/meta-oe/recipes-graphics/gtkwave/gtkwave_3.3.119.bb
+++ b/meta-openembedded/meta-oe/recipes-graphics/gtkwave/gtkwave_3.3.119.bb
@@ -13,6 +13,7 @@ DEPENDS = " \
gperf-native \
gtk+3 \
gdk-pixbuf \
+ libtirpc \
tcl \
tk \
bzip2 \
diff --git a/meta-openembedded/meta-oe/recipes-graphics/jasper/jasper/0001-Fixes-400.patch b/meta-openembedded/meta-oe/recipes-graphics/jasper/jasper/0001-Fixes-400.patch
new file mode 100644
index 0000000000..217eb29179
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-graphics/jasper/jasper/0001-Fixes-400.patch
@@ -0,0 +1,171 @@
+From ad08c18022f730937ccf9e9feb2a5236146afec5 Mon Sep 17 00:00:00 2001
+From: Michael Adams <mdadams@ece.uvic.ca>
+Date: Tue, 29 Jul 2025 20:16:35 -0700
+Subject: [PATCH] Fixes #400.
+
+Added a check for a missing color component in the jas_image_chclrspc
+function.
+
+CVE: CVE-2025-8835
+Upstream-Status: Backport [https://github.com/jasper-software/jasper/commit/bb7d62bd0a2a8e0e1fdb4d603f3305f955158c52]
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ src/libjasper/base/jas_image.c | 72 ++++++++++++++++++++++++++++------
+ 1 file changed, 61 insertions(+), 11 deletions(-)
+
+diff --git a/src/libjasper/base/jas_image.c b/src/libjasper/base/jas_image.c
+index 1ed0905..c8aa42b 100644
+--- a/src/libjasper/base/jas_image.c
++++ b/src/libjasper/base/jas_image.c
+@@ -118,6 +118,8 @@ static void jas_image_calcbbox2(const jas_image_t *image,
+ jas_image_coord_t *bry);
+ static void jas_image_fmtinfo_init(jas_image_fmtinfo_t *fmtinfo);
+ static void jas_image_fmtinfo_cleanup(jas_image_fmtinfo_t *fmtinfo);
++static jas_cmcmptfmt_t* jas_cmcmptfmt_array_create(int n);
++static void jas_cmcmptfmt_array_destroy(jas_cmcmptfmt_t* cmptfmts, int n);
+
+ /******************************************************************************\
+ * Create and destroy operations.
+@@ -413,6 +415,36 @@ static void jas_image_cmpt_destroy(jas_image_cmpt_t *cmpt)
+ jas_free(cmpt);
+ }
+
++static jas_cmcmptfmt_t* jas_cmcmptfmt_array_create(int n)
++{
++ jas_cmcmptfmt_t* cmptfmts;
++ JAS_LOGDEBUGF(10, "jas_cmcmptfmt_array_create(%d)\n", n);
++ if (!(cmptfmts = jas_alloc2(n, sizeof(jas_cmcmptfmt_t)))) {
++ return 0;
++ }
++ for (int i = 0; i < n; ++i) {
++ cmptfmts[i].buf = 0;
++ }
++ JAS_LOGDEBUGF(10, "jas_cmcmptfmt_array_create(%d) returning %p\n", n,
++ JAS_CAST(void *, cmptfmts));
++ return cmptfmts;
++}
++
++static void jas_cmcmptfmt_array_destroy(jas_cmcmptfmt_t* cmptfmts, int n)
++{
++ assert(cmptfmts);
++ assert(n > 0);
++ JAS_LOGDEBUGF(10, "jas_cmcmptfmt_array_destroy(%p, %d)\n",
++ JAS_CAST(void *, cmptfmts), n);
++ for (int i = 0; i < n; ++i) {
++ if (cmptfmts[i].buf) {
++ jas_free(cmptfmts[i].buf);
++ }
++ cmptfmts[i].buf = 0;
++ }
++ jas_free(cmptfmts);
++}
++
+ /******************************************************************************\
+ * Load and save operations.
+ \******************************************************************************/
+@@ -1588,12 +1620,15 @@ jas_image_t *jas_image_chclrspc(jas_image_t *image,
+ jas_cmcmptfmt_t *incmptfmts;
+ jas_cmcmptfmt_t *outcmptfmts;
+
++ assert(image);
++ assert(outprof);
++
+ #if 0
+ jas_eprintf("IMAGE\n");
+ jas_image_dump(image, stderr);
+ #endif
+
+- if (image->numcmpts_ == 0) {
++ if (!jas_image_numcmpts(image)) {
+ /*
+ can't work with a file with no components;
+ continuing would crash because we'd attempt to
+@@ -1604,6 +1639,8 @@ jas_image_t *jas_image_chclrspc(jas_image_t *image,
+
+ outimage = 0;
+ xform = 0;
++ incmptfmts = 0;
++ outcmptfmts = 0;
+ if (!(inimage = jas_image_copy(image))) {
+ goto error;
+ }
+@@ -1694,16 +1731,22 @@ jas_image_t *jas_image_chclrspc(jas_image_t *image,
+ }
+
+ inpixmap.numcmpts = numinclrchans;
+- if (!(incmptfmts = jas_alloc2(numinclrchans, sizeof(jas_cmcmptfmt_t)))) {
++ assert(numinclrchans != 0);
++ if (!(incmptfmts = jas_cmcmptfmt_array_create(numinclrchans))) {
+ // formerly call to abort()
+ goto error;
+ }
+ inpixmap.cmptfmts = incmptfmts;
+ for (unsigned i = 0; i < numinclrchans; ++i) {
+ const int j = jas_image_getcmptbytype(inimage, JAS_IMAGE_CT_COLOR(i));
++ if (j < 0) {
++ jas_logerrorf("missing color component %d\n", i);
++ goto error;
++ }
+ if (!(incmptfmts[i].buf = jas_alloc2(width, sizeof(long)))) {
+ goto error;
+ }
++ assert(j >= 0 && j < jas_image_numcmpts(inimage));
+ incmptfmts[i].prec = jas_image_cmptprec(inimage, j);
+ incmptfmts[i].sgnd = jas_image_cmptsgnd(inimage, j);
+ incmptfmts[i].width = width;
+@@ -1711,7 +1754,7 @@ jas_image_t *jas_image_chclrspc(jas_image_t *image,
+ }
+
+ outpixmap.numcmpts = numoutclrchans;
+- if (!(outcmptfmts = jas_alloc2(numoutclrchans, sizeof(jas_cmcmptfmt_t)))) {
++ if (!(outcmptfmts = jas_cmcmptfmt_array_create(numoutclrchans))) {
+ // formerly call to abort()
+ goto error;
+ }
+@@ -1719,9 +1762,14 @@ jas_image_t *jas_image_chclrspc(jas_image_t *image,
+
+ for (unsigned i = 0; i < numoutclrchans; ++i) {
+ const int j = jas_image_getcmptbytype(outimage, JAS_IMAGE_CT_COLOR(i));
++ if (j < 0) {
++ jas_logerrorf("missing color component %d\n", i);
++ goto error;
++ }
+ if (!(outcmptfmts[i].buf = jas_alloc2(width, sizeof(long)))) {
+ goto error;
+ }
++ assert(j >= 0 && j < jas_image_numcmpts(outimage));
+ outcmptfmts[i].prec = jas_image_cmptprec(outimage, j);
+ outcmptfmts[i].sgnd = jas_image_cmptsgnd(outimage, j);
+ outcmptfmts[i].width = width;
+@@ -1746,14 +1794,8 @@ jas_image_t *jas_image_chclrspc(jas_image_t *image,
+ }
+ }
+
+- for (unsigned i = 0; i < numoutclrchans; ++i) {
+- jas_free(outcmptfmts[i].buf);
+- }
+- jas_free(outcmptfmts);
+- for (unsigned i = 0; i < numinclrchans; ++i) {
+- jas_free(incmptfmts[i].buf);
+- }
+- jas_free(incmptfmts);
++ jas_cmcmptfmt_array_destroy(outcmptfmts, numoutclrchans);
++ jas_cmcmptfmt_array_destroy(incmptfmts, numinclrchans);
+ jas_cmxform_destroy(xform);
+ jas_image_destroy(inimage);
+
+@@ -1765,6 +1807,14 @@ jas_image_t *jas_image_chclrspc(jas_image_t *image,
+ #endif
+ return outimage;
+ error:
++ if (incmptfmts) {
++ assert(numinclrchans);
++ jas_cmcmptfmt_array_destroy(incmptfmts, numinclrchans);
++ }
++ if (outcmptfmts) {
++ assert(numoutclrchans);
++ jas_cmcmptfmt_array_destroy(outcmptfmts, numoutclrchans);
++ }
+ if (xform) {
+ jas_cmxform_destroy(xform);
+ }
diff --git a/meta-openembedded/meta-oe/recipes-graphics/jasper/jasper/0001-Fixes-401.patch b/meta-openembedded/meta-oe/recipes-graphics/jasper/jasper/0001-Fixes-401.patch
new file mode 100644
index 0000000000..d7e40c8493
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-graphics/jasper/jasper/0001-Fixes-401.patch
@@ -0,0 +1,78 @@
+From 823034b2b47be037278e612177180783b04fb687 Mon Sep 17 00:00:00 2001
+From: Michael Adams <mdadams@ece.uvic.ca>
+Date: Sat, 2 Aug 2025 18:00:39 -0700
+Subject: [PATCH] Fixes #401.
+
+JPEG-2000 (JPC) Encoder:
+- Added some missing range checking on several coding parameters
+ (e.g., precint width/height and codeblock width/height).
+
+CVE: CVE-2025-8836
+Upstream-Status: Backport [https://github.com/jasper-software/jasper/commit/79185d32d7a444abae441935b20ae4676b3513d4]
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ src/libjasper/jpc/jpc_enc.c | 30 ++++++++++++++++++++++++------
+ src/libjasper/jpc/jpc_t2dec.c | 3 ++-
+ 2 files changed, 26 insertions(+), 7 deletions(-)
+
+diff --git a/src/libjasper/jpc/jpc_enc.c b/src/libjasper/jpc/jpc_enc.c
+index 64f8aa5..4fb23d4 100644
+--- a/src/libjasper/jpc/jpc_enc.c
++++ b/src/libjasper/jpc/jpc_enc.c
+@@ -484,18 +484,36 @@ static jpc_enc_cp_t *cp_create(const char *optstr, jas_image_t *image)
+ cp->tileheight = atoi(jas_tvparser_getval(tvp));
+ break;
+ case OPT_PRCWIDTH:
+- prcwidthexpn = jpc_floorlog2(atoi(jas_tvparser_getval(tvp)));
++ i = atoi(jas_tvparser_getval(tvp));
++ if (i <= 0) {
++ jas_logerrorf("invalid precinct width (%d)\n", i);
++ goto error;
++ }
++ prcwidthexpn = jpc_floorlog2(i);
+ break;
+ case OPT_PRCHEIGHT:
+- prcheightexpn = jpc_floorlog2(atoi(jas_tvparser_getval(tvp)));
++ i = atoi(jas_tvparser_getval(tvp));
++ if (i <= 0) {
++ jas_logerrorf("invalid precinct height (%d)\n", i);
++ goto error;
++ }
++ prcheightexpn = jpc_floorlog2(i);
+ break;
+ case OPT_CBLKWIDTH:
+- tccp->cblkwidthexpn =
+- jpc_floorlog2(atoi(jas_tvparser_getval(tvp)));
++ i = atoi(jas_tvparser_getval(tvp));
++ if (i <= 0) {
++ jas_logerrorf("invalid code block width (%d)\n", i);
++ goto error;
++ }
++ tccp->cblkwidthexpn = jpc_floorlog2(i);
+ break;
+ case OPT_CBLKHEIGHT:
+- tccp->cblkheightexpn =
+- jpc_floorlog2(atoi(jas_tvparser_getval(tvp)));
++ i = atoi(jas_tvparser_getval(tvp));
++ if (i <= 0) {
++ jas_logerrorf("invalid code block height (%d)\n", i);
++ goto error;
++ }
++ tccp->cblkheightexpn = jpc_floorlog2(i);
+ break;
+ case OPT_MODE:
+ if ((tagid = jas_taginfo_nonull(jas_taginfos_lookup(modetab,
+diff --git a/src/libjasper/jpc/jpc_t2dec.c b/src/libjasper/jpc/jpc_t2dec.c
+index de77623..1eff88a 100644
+--- a/src/libjasper/jpc/jpc_t2dec.c
++++ b/src/libjasper/jpc/jpc_t2dec.c
+@@ -348,7 +348,8 @@ static int jpc_dec_decodepkt(jpc_dec_t *dec, jas_stream_t *pkthdrstream, jas_str
+ const unsigned n = JAS_MIN((unsigned)numnewpasses, maxpasses);
+ mycounter += n;
+ numnewpasses -= n;
+- if ((len = jpc_bitstream_getbits(inb, cblk->numlenbits + jpc_floorlog2(n))) < 0) {
++ if ((len = jpc_bitstream_getbits(inb,
++ cblk->numlenbits + jpc_floorlog2(n))) < 0) {
+ jpc_bitstream_close(inb);
+ jas_logerrorf("cannot get bits\n");
+ return -1;
diff --git a/meta-openembedded/meta-oe/recipes-graphics/jasper/jasper/0001-Fixes-402-403.patch b/meta-openembedded/meta-oe/recipes-graphics/jasper/jasper/0001-Fixes-402-403.patch
new file mode 100644
index 0000000000..b8d78c698e
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-graphics/jasper/jasper/0001-Fixes-402-403.patch
@@ -0,0 +1,62 @@
+From d3f6b098f83326222a2576f938ddff93338c60be Mon Sep 17 00:00:00 2001
+From: Michael Adams <mdadams@ece.uvic.ca>
+Date: Tue, 5 Aug 2025 20:46:48 -0700
+Subject: [PATCH] Fixes #402, #403.
+
+JPEG-2000 (JPC) Decoder:
+- Added the setting of several pointers to null in some cleanup code
+ after the pointed-to memory was freed. This pointer nulling is not
+ needed normally, but it is needed when certain debugging logs are
+ enabled (so that the debug code understands that the memory associated
+ with the aforementioned pointers has been freed).
+
+CVE: CVE-2025-8837
+Upstream-Status: Backport [https://github.com/jasper-software/jasper/commit/8308060d3fbc1da10353ac8a95c8ea60eba9c25a]
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ src/libjasper/jpc/jpc_dec.c | 13 ++++++++-----
+ 1 file changed, 8 insertions(+), 5 deletions(-)
+
+diff --git a/src/libjasper/jpc/jpc_dec.c b/src/libjasper/jpc/jpc_dec.c
+index e76aa40..929f7ae 100644
+--- a/src/libjasper/jpc/jpc_dec.c
++++ b/src/libjasper/jpc/jpc_dec.c
+@@ -1134,23 +1134,23 @@ static int jpc_dec_tilefini(jpc_dec_t *dec, jpc_dec_tile_t *tile)
+
+ if (tile->cp) {
+ jpc_dec_cp_destroy(tile->cp);
+- //tile->cp = 0;
++ tile->cp = 0;
+ }
+ if (tile->tcomps) {
+ jas_free(tile->tcomps);
+- //tile->tcomps = 0;
++ tile->tcomps = 0;
+ }
+ if (tile->pi) {
+ jpc_pi_destroy(tile->pi);
+- //tile->pi = 0;
++ tile->pi = 0;
+ }
+ if (tile->pkthdrstream) {
+ jas_stream_close(tile->pkthdrstream);
+- //tile->pkthdrstream = 0;
++ tile->pkthdrstream = 0;
+ }
+ if (tile->pptstab) {
+ jpc_ppxstab_destroy(tile->pptstab);
+- //tile->pptstab = 0;
++ tile->pptstab = 0;
+ }
+
+ tile->state = JPC_TILE_DONE;
+@@ -2286,6 +2286,9 @@ static int jpc_dec_dump(const jpc_dec_t *dec)
+ const jpc_dec_tile_t *tile;
+ for (tileno = 0, tile = dec->tiles; tileno < dec->numtiles;
+ ++tileno, ++tile) {
++ if (!tile->tcomps) {
++ continue;
++ }
+ assert(!dec->numcomps || tile->tcomps);
+ unsigned compno;
+ const jpc_dec_tcomp_t *tcomp;
diff --git a/meta-openembedded/meta-oe/recipes-graphics/jasper/jasper_4.1.1.bb b/meta-openembedded/meta-oe/recipes-graphics/jasper/jasper_4.1.1.bb
index 5281980ecb..393539e227 100644
--- a/meta-openembedded/meta-oe/recipes-graphics/jasper/jasper_4.1.1.bb
+++ b/meta-openembedded/meta-oe/recipes-graphics/jasper/jasper_4.1.1.bb
@@ -3,7 +3,11 @@ HOMEPAGE = "https://jasper-software.github.io/jasper/"
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=a80440d1d8f17d041c71c7271d6e06eb"
-SRC_URI = "git://github.com/jasper-software/jasper.git;protocol=https;branch=master"
+SRC_URI = "git://github.com/jasper-software/jasper.git;protocol=https;branch=master \
+ file://0001-Fixes-400.patch \
+ file://0001-Fixes-401.patch \
+ file://0001-Fixes-402-403.patch \
+ "
SRCREV = "917f7708b755d8434f70618108c1a76f1b6a0a82"
CVE_STATUS[CVE-2015-8751] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions."
diff --git a/meta-openembedded/meta-oe/recipes-graphics/libvncserver/libvncserver_0.9.14.bb b/meta-openembedded/meta-oe/recipes-graphics/libvncserver/libvncserver_0.9.14.bb
index ce01593b8b..6f271ee0d3 100644
--- a/meta-openembedded/meta-oe/recipes-graphics/libvncserver/libvncserver_0.9.14.bb
+++ b/meta-openembedded/meta-oe/recipes-graphics/libvncserver/libvncserver_0.9.14.bb
@@ -42,7 +42,7 @@ PACKAGECONFIG[zlib] = "-DWITH_ZLIB=ON,-DWITH_ZLIB=OFF,zlib"
PACKAGE_BEFORE_PN = "libvncclient"
FILES:libvncclient = "${libdir}/libvncclient.*"
-inherit cmake
+inherit cmake pkgconfig
SRC_URI = "git://github.com/LibVNC/libvncserver;branch=master;protocol=https"
SRCREV = "10e9eb75f73e973725dc75c373de5d89807af028"
@@ -52,5 +52,5 @@ S = "${WORKDIR}/git"
EXTRA_OECMAKE = "-DMAKE_INSTALL_LIBDIR=${libdir}"
do_install:append() {
- sed -i -e 's|${STAGING_DIR_HOST}||g' ${D}${libdir}/cmake/LibVNCServer/LibVNCServerTargets.cmake
+ sed -i -e 's|${STAGING_DIR_HOST}${libdir}/||g' ${D}${libdir}/cmake/LibVNCServer/LibVNCServerTargets.cmake
}
diff --git a/meta-openembedded/meta-oe/recipes-graphics/openbox/files/0001-Fix-list-traversal-issue-in-client_calc_layer.patch b/meta-openembedded/meta-oe/recipes-graphics/openbox/files/0001-Fix-list-traversal-issue-in-client_calc_layer.patch
new file mode 100644
index 0000000000..8bc2b80f68
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-graphics/openbox/files/0001-Fix-list-traversal-issue-in-client_calc_layer.patch
@@ -0,0 +1,56 @@
+From d41128e5a1002af41c976c8860f8299cfcd3cd72 Mon Sep 17 00:00:00 2001
+From: pldubouilh <pldubouilh@gmail.com>
+Date: Fri, 17 Mar 2023 18:23:47 +0100
+Subject: [PATCH] Fix list traversal issue in client_calc_layer
+
+The calls to client_calc_layer_internal can modify stacking_list, which
+can cause us to follow dangling ->next pointers (either by the pointer
+itself already being freed, or it pointing to a freed area). Avoid this
+by copying the list first, the goal is to visit every client in the list
+once so this should be fine.
+
+Upstream-Status: Backport [http://git.openbox.org/?p=mikachu/openbox.git;a=commit;h=d41128e5a1002af41c976c8860f8299cfcd3cd72]
+Signed-off-by: Alexandre Videgrain <alexandre.videgrain@smile.fr>
+---
+ openbox/client.c | 9 +++++++--
+ 1 file changed, 7 insertions(+), 2 deletions(-)
+
+diff --git a/openbox/client.c b/openbox/client.c
+index 7168b240..b8264587 100644
+--- a/openbox/client.c
++++ b/openbox/client.c
+@@ -2742,9 +2742,12 @@ static void client_calc_layer_internal(ObClient *self)
+ void client_calc_layer(ObClient *self)
+ {
+ GList *it;
++ /* the client_calc_layer_internal calls below modify stacking_list,
++ so we have to make a copy to iterate over */
++ GList *list = g_list_copy(stacking_list);
+
+ /* skip over stuff above fullscreen layer */
+- for (it = stacking_list; it; it = g_list_next(it))
++ for (it = list; it; it = g_list_next(it))
+ if (window_layer(it->data) <= OB_STACKING_LAYER_FULLSCREEN) break;
+
+ /* find the windows in the fullscreen layer, and mark them not-visited */
+@@ -2757,7 +2760,7 @@ void client_calc_layer(ObClient *self)
+ client_calc_layer_internal(self);
+
+ /* skip over stuff above fullscreen layer */
+- for (it = stacking_list; it; it = g_list_next(it))
++ for (it = list; it; it = g_list_next(it))
+ if (window_layer(it->data) <= OB_STACKING_LAYER_FULLSCREEN) break;
+
+ /* now recalc any windows in the fullscreen layer which have not
+@@ -2768,6 +2771,8 @@ void client_calc_layer(ObClient *self)
+ !WINDOW_AS_CLIENT(it->data)->visited)
+ client_calc_layer_internal(it->data);
+ }
++
++ g_list_free(it);
+ }
+
+ gboolean client_should_show(ObClient *self)
+--
+2.34.1
+
diff --git a/meta-openembedded/meta-oe/recipes-graphics/openbox/openbox_3.6.1.bb b/meta-openembedded/meta-oe/recipes-graphics/openbox/openbox_3.6.1.bb
index 9a15077316..1851a84b97 100644
--- a/meta-openembedded/meta-oe/recipes-graphics/openbox/openbox_3.6.1.bb
+++ b/meta-openembedded/meta-oe/recipes-graphics/openbox/openbox_3.6.1.bb
@@ -8,6 +8,7 @@ SRC_URI = " \
http://icculus.org/openbox/releases/openbox-${PV}.tar.gz \
file://0001-Makefile.am-avoid-race-when-creating-autostart-direc.patch \
file://0001-openbox-xdg-autostart-convert-to-python3.patch \
+ file://0001-Fix-list-traversal-issue-in-client_calc_layer.patch \
"
SRC_URI[md5sum] = "b72794996c6a3ad94634727b95f9d204"
diff --git a/meta-openembedded/meta-oe/recipes-graphics/openjpeg/openjpeg/0002-Do-not-ask-cmake-to-export-binaries-they-don-t-make-.patch b/meta-openembedded/meta-oe/recipes-graphics/openjpeg/openjpeg/0001-Do-not-ask-cmake-to-export-binaries-they-don-t-make-.patch
index 0ba13cf88f..2e25ecc7ef 100644
--- a/meta-openembedded/meta-oe/recipes-graphics/openjpeg/openjpeg/0002-Do-not-ask-cmake-to-export-binaries-they-don-t-make-.patch
+++ b/meta-openembedded/meta-oe/recipes-graphics/openjpeg/openjpeg/0001-Do-not-ask-cmake-to-export-binaries-they-don-t-make-.patch
@@ -1,4 +1,4 @@
-From 4681de07e21f17aa28710d3a51fabe7da60463f9 Mon Sep 17 00:00:00 2001
+From 805ce4d40c5aaae12aa73452ff07babe8eb43a62 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Andreas=20M=C3=BCller?= <schnitzeltony@gmail.com>
Date: Fri, 28 Sep 2018 00:38:50 +0200
Subject: [PATCH] Do not ask cmake to export binaries - they don't make it
@@ -15,17 +15,17 @@ Signed-off-by: Andreas Müller <schnitzeltony@gmail.com>
1 file changed, 1 deletion(-)
diff --git a/src/bin/jp2/CMakeLists.txt b/src/bin/jp2/CMakeLists.txt
-index 4324c36d..2c11fe02 100644
+index 26156bcb..9eff04aa 100644
--- a/src/bin/jp2/CMakeLists.txt
+++ b/src/bin/jp2/CMakeLists.txt
-@@ -66,7 +66,6 @@ foreach(exe opj_decompress opj_compress opj_dump)
+@@ -64,7 +64,6 @@ foreach(exe opj_decompress opj_compress opj_dump)
endif()
# Install exe
install(TARGETS ${exe}
- EXPORT OpenJPEGTargets
- DESTINATION ${OPENJPEG_INSTALL_BIN_DIR} COMPONENT Applications
+ DESTINATION ${CMAKE_INSTALL_BINDIR} COMPONENT Applications
)
if(OPJ_USE_DSYMUTIL)
--
-2.14.4
+2.25.1
diff --git a/meta-openembedded/meta-oe/recipes-graphics/openjpeg/openjpeg/CVE-2025-54874.patch b/meta-openembedded/meta-oe/recipes-graphics/openjpeg/openjpeg/CVE-2025-54874.patch
new file mode 100644
index 0000000000..187557a35c
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-graphics/openjpeg/openjpeg/CVE-2025-54874.patch
@@ -0,0 +1,44 @@
+From f809b80c67717c152a5ad30bf06774f00da4fd2d Mon Sep 17 00:00:00 2001
+From: Sebastian Rasmussen <sebras@gmail.com>
+Date: Thu, 16 Jan 2025 02:13:43 +0100
+Subject: [PATCH] opj_jp2_read_header: Check for error after parsing header.
+
+Consider the case where the caller has not set the p_image
+pointer to NULL before calling opj_read_header().
+
+If opj_j2k_read_header_procedure() fails while obtaining the rest
+of the marker segment when calling opj_stream_read_data() because
+the data stream is too short, then opj_j2k_read_header() will
+never have the chance to initialize p_image, leaving it
+uninitialized.
+
+opj_jp2_read_header() will check the p_image value whether
+opj_j2k_read_header() suceeded or failed. This may be detected as
+an error in valgrind or ASAN.
+
+The fix is to check whether opj_j2k_read_header() suceeded before
+using the output argument p_image.
+
+CVE: CVE-2025-54874
+Upstream-Status: Backport [https://github.com/uclouvain/openjpeg/commit/f809b80c67717c152a5ad30bf06774f00da4fd2d]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ src/lib/openjp2/jp2.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/lib/openjp2/jp2.c b/src/lib/openjp2/jp2.c
+index 4df055a5..da506318 100644
+--- a/src/lib/openjp2/jp2.c
++++ b/src/lib/openjp2/jp2.c
+@@ -2873,7 +2873,7 @@ OPJ_BOOL opj_jp2_read_header(opj_stream_private_t *p_stream,
+ p_image,
+ p_manager);
+
+- if (p_image && *p_image) {
++ if (ret && p_image && *p_image) {
+ /* Set Image Color Space */
+ if (jp2->enumcs == 16) {
+ (*p_image)->color_space = OPJ_CLRSPC_SRGB;
+--
+2.50.1
+
diff --git a/meta-openembedded/meta-oe/recipes-graphics/openjpeg/openjpeg_2.5.0.bb b/meta-openembedded/meta-oe/recipes-graphics/openjpeg/openjpeg_2.5.3.bb
index f2d74078e8..586bfeaf1f 100644
--- a/meta-openembedded/meta-oe/recipes-graphics/openjpeg/openjpeg_2.5.0.bb
+++ b/meta-openembedded/meta-oe/recipes-graphics/openjpeg/openjpeg_2.5.3.bb
@@ -6,9 +6,10 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=c648878b4840d7babaade1303e7f108c"
DEPENDS = "libpng tiff lcms zlib"
SRC_URI = "git://github.com/uclouvain/openjpeg.git;branch=master;protocol=https \
- file://0002-Do-not-ask-cmake-to-export-binaries-they-don-t-make-.patch \
+ file://0001-Do-not-ask-cmake-to-export-binaries-they-don-t-make-.patch \
+ file://CVE-2025-54874.patch \
"
-SRCREV = "a5891555eb49ed7cc26b2901ea680acda136d811"
+SRCREV = "210a8a5690d0da66f02d49420d7176a21ef409dc"
S = "${WORKDIR}/git"
inherit cmake
diff --git a/meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-cn-fonts_2.004.bb b/meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-cn-fonts_2.004.bb
index b4a598527e..391d465571 100644
--- a/meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-cn-fonts_2.004.bb
+++ b/meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-cn-fonts_2.004.bb
@@ -11,13 +11,10 @@ inherit allarch fontcache
#EXCLUDE_FROM_WORLD = "1"
SRC_URI = " \
- svn://github.com/adobe-fonts/source-han-sans;module=branches/release/SubsetOTF/CN;protocol=http;rev=82 \
+ https://github.com/adobe-fonts/source-han-sans/releases/download/2.004R/SourceHanSansCN.zip;subdir=${BP} \
file://44-source-han-sans-cn.conf \
"
-SRC_URI[md5sum] = "d16abc21f6575bb08894efedbed484a2"
-SRC_URI[sha256sum] = "0a0e1d8e52833bc352d454d8242da03b82c0efc41323fb66f7435e5b39734a4f"
-
-S = "${WORKDIR}/SourceHanSansCN"
+SRC_URI[sha256sum] = "6841fc13f1c0d255cfeb33d2a2c68d24bbebd94ae2c070347a2b2b200a1db4d6"
do_install() {
install -d ${D}${sysconfdir}/fonts/conf.d/
diff --git a/meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-jp-fonts_2.004.bb b/meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-jp-fonts_2.004.bb
index 6a4509048f..f940478a80 100644
--- a/meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-jp-fonts_2.004.bb
+++ b/meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-jp-fonts_2.004.bb
@@ -11,13 +11,10 @@ inherit allarch fontcache
#EXCLUDE_FROM_WORLD = "1"
SRC_URI = " \
- svn://github.com/adobe-fonts/source-han-sans;module=branches/release/SubsetOTF/JP;protocol=http;rev=82 \
+ https://github.com/adobe-fonts/source-han-sans/releases/download/2.004R/SourceHanSansJP.zip;subdir=${BP} \
file://44-source-han-sans-jp.conf \
"
-SRC_URI[md5sum] = "908fbf97f3df04a6838708c093f1e900"
-SRC_URI[sha256sum] = "dc6dbae3fba35f220bac88ba7130b826c7efe1282f472788fae3628b79be3f54"
-
-S = "${WORKDIR}/SourceHanSansJP"
+SRC_URI[sha256sum] = "1ae9f62ad620d686c4a049ce25cf54e3afd8fefc954a678c644cf9802750c17e"
do_install() {
install -d ${D}${sysconfdir}/fonts/conf.d/
diff --git a/meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-kr-fonts_2.004.bb b/meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-kr-fonts_2.004.bb
index 5ab5057d86..f536d1b61e 100644
--- a/meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-kr-fonts_2.004.bb
+++ b/meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-kr-fonts_2.004.bb
@@ -11,13 +11,10 @@ inherit allarch fontcache
#EXCLUDE_FROM_WORLD = "1"
SRC_URI = " \
- svn://github.com/adobe-fonts/source-han-sans;module=branches/release/SubsetOTF/TW;protocol=http;rev=82 \
+ https://github.com/adobe-fonts/source-han-sans/releases/download/2.004R/SourceHanSansKR.zip;subdir=${BP} \
file://44-source-han-sans-kr.conf \
"
-SRC_URI[md5sum] = "f8d1bd6c87d8575afdb25e2f46bd81d4"
-SRC_URI[sha256sum] = "38fd15c80f9980492faaa1af39ff873d8a38e45027023fb17d5b10d4b4b0e6af"
-
-S = "${WORKDIR}/SourceHanSansKR"
+SRC_URI[sha256sum] = "02fe28a48c6381c49d61c27a1b173c77f0e6f2b9f2b68e79f076f10a6a8f4bfe"
do_install() {
install -d ${D}${sysconfdir}/fonts/conf.d/
diff --git a/meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-tw-fonts_2.004.bb b/meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-tw-fonts_2.004.bb
index a2b3fff079..0a4aff5e31 100644
--- a/meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-tw-fonts_2.004.bb
+++ b/meta-openembedded/meta-oe/recipes-graphics/ttf-fonts/source-han-sans-tw-fonts_2.004.bb
@@ -11,13 +11,10 @@ inherit allarch fontcache
#EXCLUDE_FROM_WORLD = "1"
SRC_URI = " \
- svn://github.com/adobe-fonts/source-han-sans;module=branches/release/SubsetOTF/TW;protocol=http;rev=82 \
+ https://github.com/adobe-fonts/source-han-sans/releases/download/2.004R/SourceHanSansTW.zip;subdir=${BP} \
file://44-source-han-sans-tw.conf \
"
-SRC_URI[md5sum] = "6533b71b31c19e548768f0fc963202f3"
-SRC_URI[sha256sum] = "92ba161921c5cdec5a8f8d5711676f0865b50cee071c25eb4bd4125b5af59fd0"
-
-S = "${WORKDIR}/SourceHanSansTW"
+SRC_URI[sha256sum] = "11d78c8fbc1a4bb04a453cdd65c99db8d41ec5cd6ba6d68c8638e6ba170de806"
do_install() {
install -d ${D}${sysconfdir}/fonts/conf.d/
diff --git a/meta-openembedded/meta-oe/recipes-graphics/vk-gl-cts/vulkan-cts/0001-Allow-running-the-CTS-with-unknown-versions-of-Vulka.patch b/meta-openembedded/meta-oe/recipes-graphics/vk-gl-cts/vulkan-cts/0001-Allow-running-the-CTS-with-unknown-versions-of-Vulka.patch
new file mode 100644
index 0000000000..2797acf416
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-graphics/vk-gl-cts/vulkan-cts/0001-Allow-running-the-CTS-with-unknown-versions-of-Vulka.patch
@@ -0,0 +1,41 @@
+From 954b523a998933b1edbe9af3fe7b1c74595cf148 Mon Sep 17 00:00:00 2001
+From: Lorenzo Dal Col <lorenzo@khronosgroup.org>
+Date: Tue, 17 Sep 2024 17:18:20 +0200
+Subject: [PATCH] Allow running the CTS with unknown versions of Vulkan in the
+ driver
+
+This will default to VK_API_MAX_FRAMEWORK_VERSION, which at this time is 1.3.x.
+VK-GL-CTS issue: 5165
+Components: Framework, Vulkan
+Affects: None
+
+Change-Id: I954d0144db9ff5f3848c81df61dd263505b17ac2
+Upstream-Status: Backport [https://github.com/KhronosGroup/VK-GL-CTS/commit/609c09b3163d86d7e4819fbfc00a616e364f14f0]
+Signed-off-by: Randolph Sapp <rs@ti.com>
+---
+ external/vulkancts/framework/vulkan/vkApiVersion.cpp | 9 ++++++++-
+ 1 file changed, 8 insertions(+), 1 deletion(-)
+
+diff --git a/external/vulkancts/framework/vulkan/vkApiVersion.cpp b/external/vulkancts/framework/vulkan/vkApiVersion.cpp
+index d996cb0e6..8720df52a 100644
+--- a/external/vulkancts/framework/vulkan/vkApiVersion.cpp
++++ b/external/vulkancts/framework/vulkan/vkApiVersion.cpp
+@@ -134,7 +134,14 @@ deUint32 minVulkanAPIVersion(deUint32 lhs, deUint32 rhs)
+ for (auto it = begin(commonPredecessors); it != end(commonPredecessors); ++it)
+ if (isApiVersionPredecessor(rhs, *it) && isApiVersionPredecessor(lhs, *it))
+ return *it;
+- return 0;
++
++#ifndef CTS_USES_VULKANSC
++ // If we got to this point, it means we are dealing with an unknown version.
++ // We assume it to be valid, and we default to VK_API_MAX_FRAMEWORK_VERSION which is generated from the spec.
++ return VK_API_MAX_FRAMEWORK_VERSION;
++#else
++ return VKSC_API_MAX_FRAMEWORK_VERSION;
++#endif
+ }
+
+ } // vk
+--
+2.50.1
+
diff --git a/meta-openembedded/meta-oe/recipes-graphics/vk-gl-cts/vulkan-cts_1.3.7.3.bb b/meta-openembedded/meta-oe/recipes-graphics/vk-gl-cts/vulkan-cts_1.3.7.3.bb
index 7492fe9aa4..cc80549eeb 100644
--- a/meta-openembedded/meta-oe/recipes-graphics/vk-gl-cts/vulkan-cts_1.3.7.3.bb
+++ b/meta-openembedded/meta-oe/recipes-graphics/vk-gl-cts/vulkan-cts_1.3.7.3.bb
@@ -19,6 +19,7 @@ SRCREV_video-parser = "138bbe048221d315962ddf8413aa6a08cc62a381"
SRC_URI += "file://0001-cmake-Define-WAYLAND_SCANNER-and-WAYLAND_PROTOCOLS_D.patch \
file://0001-vulkan-cts-include-missing-cstdint.patch \
+ file://0001-Allow-running-the-CTS-with-unknown-versions-of-Vulka.patch \
"
TOOLCHAIN = "gcc"
diff --git a/meta-openembedded/meta-oe/recipes-kernel/bpftool/bpftool.bb b/meta-openembedded/meta-oe/recipes-kernel/bpftool/bpftool.bb
index b22334fe90..ec778c6e76 100644
--- a/meta-openembedded/meta-oe/recipes-kernel/bpftool/bpftool.bb
+++ b/meta-openembedded/meta-oe/recipes-kernel/bpftool/bpftool.bb
@@ -14,7 +14,7 @@ EXTRA_OEMAKE = "\
-C ${S}/tools/bpf/bpftool \
O=${B} \
CROSS=${TARGET_PREFIX} \
- CC="${CC} ${DEBUG_PREFIX_MAP} -fdebug-prefix-map=${STAGING_KERNEL_DIR}=${KERNEL_SRC_PATH}" \
+ CC="${CC} ${DEBUG_PREFIX_MAP} -fdebug-prefix-map=${STAGING_KERNEL_DIR}=${KERNEL_SRC_PATH} ${CFLAGS}" \
HOSTCC="${BUILD_CC} ${BUILD_CFLAGS}" \
LD="${LD}" \
AR=${AR} \
@@ -26,7 +26,7 @@ SECURITY_CFLAGS = ""
do_configure[depends] += "virtual/kernel:do_shared_workdir"
-COMPATIBLE_HOST = "(x86_64|aarch64).*-linux"
+COMPATIBLE_HOST = "(x86_64|aarch64|riscv64).*-linux"
COMPATIBLE_HOST:libc-musl = 'null'
do_compile() {
diff --git a/meta-openembedded/meta-oe/recipes-kernel/cpupower/cpupower.bb b/meta-openembedded/meta-oe/recipes-kernel/cpupower/cpupower.bb
index 18e3638052..453ebe8c7f 100644
--- a/meta-openembedded/meta-oe/recipes-kernel/cpupower/cpupower.bb
+++ b/meta-openembedded/meta-oe/recipes-kernel/cpupower/cpupower.bb
@@ -7,7 +7,7 @@ PROVIDES = "virtual/cpupower"
inherit kernelsrc kernel-arch bash-completion
-do_populate_lic[depends] += "virtual/kernel:do_patch"
+do_populate_lic[depends] += "virtual/kernel:do_shared_workdir"
EXTRA_OEMAKE = "-C ${S}/tools/power/cpupower O=${B} CROSS=${TARGET_PREFIX} CC="${CC}" LD="${LD}" AR=${AR} ARCH=${ARCH}"
diff --git a/meta-openembedded/meta-oe/recipes-kernel/crash/crash.inc b/meta-openembedded/meta-oe/recipes-kernel/crash/crash.inc
index 04318b1505..c8c8518394 100644
--- a/meta-openembedded/meta-oe/recipes-kernel/crash/crash.inc
+++ b/meta-openembedded/meta-oe/recipes-kernel/crash/crash.inc
@@ -22,6 +22,7 @@ SRC_URI = "git://github.com/crash-utility/${BPN}.git;branch=master;protocol=http
file://0001-cross_add_configure_option.patch \
file://donnot-extract-gdb-during-do-compile.patch \
file://gdb_build_jobs_and_not_write_crash_target.patch \
+ file://0001-symbol-fix-S-cannot-work-with-kaslr-detection.patch \
"
SRCREV = "a6832f608cb5d473739cf33bbf84ab1df8d98fd5"
diff --git a/meta-openembedded/meta-oe/recipes-kernel/crash/crash/0001-symbol-fix-S-cannot-work-with-kaslr-detection.patch b/meta-openembedded/meta-oe/recipes-kernel/crash/crash/0001-symbol-fix-S-cannot-work-with-kaslr-detection.patch
new file mode 100644
index 0000000000..47182f8b6c
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-kernel/crash/crash/0001-symbol-fix-S-cannot-work-with-kaslr-detection.patch
@@ -0,0 +1,89 @@
+From 329bd56da28fc1b5b53a60ca2172643d2090435d Mon Sep 17 00:00:00 2001
+From: Tao Liu <ltao@redhat.com>
+Date: Fri, 13 Dec 2024 08:36:03 +0000
+Subject: [PATCH] symbol: fix -S cannot work with kaslr detection
+
+When kernel enabled the CONFIG_RANDOMIZE_BASE, crash needs to add "kaslr=auto"
+in crash command line to tell crash to decode the random address.
+But when with "-S" in command line, crash would bypass the kaslr option
+that cause symbol from kernel image is mismatch with ram on a live system.
+
+The fix is provided by Tao Liu <ltao@redhat.com> from crash-utility upstream,
+and not merged to crash master yet.
+
+Upstream-Status: Pending
+[https://lists.crash-utility.osci.io/archives/list/devel@lists.crash-utility.osci.io/thread/5OXNYPPU6GLLQKCWH7WBNBJXLNZ4EBZD/]
+
+Signed-off-by: Xiangyu Chen <xiangyu.chen@windriver.com>
+---
+ symbols.c | 18 ++++++++++--------
+ 1 file changed, 10 insertions(+), 8 deletions(-)
+
+diff --git a/symbols.c b/symbols.c
+index a3cd0f3..6062d21 100644
+--- a/symbols.c
++++ b/symbols.c
+@@ -25,7 +25,7 @@
+
+ static void store_symbols(bfd *, int, void *, long, unsigned int);
+ static void store_sysmap_symbols(void);
+-static ulong relocate(ulong, char *, int);
++static ulong relocate(ulong, char *, int *);
+ static int relocate_force(ulong, char *);
+ static void kaslr_init(void);
+ static void strip_module_symbol_end(char *s);
+@@ -230,6 +230,7 @@ symtab_init(void)
+ DEBUGINFO_ERROR_MESSAGE1 :
+ DEBUGINFO_ERROR_MESSAGE2);
+ }
++ kt->flags |= RELOC_FORCE;
+ store_sysmap_symbols();
+ return;
+ } else if (LKCD_KERNTYPES())
+@@ -817,7 +818,7 @@ store_symbols(bfd *abfd, int dynamic, void *minisyms, long symcount,
+ syminfo.type)) {
+ if (kt->flags & (RELOC_SET|RELOC_FORCE))
+ sp->value = relocate(syminfo.value,
+- (char *)syminfo.name, !(first++));
++ (char *)syminfo.name, &first);
+ else
+ sp->value = syminfo.value;
+ sp->type = syminfo.type;
+@@ -893,9 +894,9 @@ store_sysmap_symbols(void)
+
+ if (machdep->verify_symbol(name, syment.value,
+ syment.type)) {
+- if (kt->flags & RELOC_SET)
++ if (kt->flags & (RELOC_SET|RELOC_FORCE))
+ sp->value = relocate(syment.value,
+- syment.name, !(first++));
++ syment.name, &first);
+ else
+ sp->value = syment.value;
+ sp->type = syment.type;
+@@ -924,7 +925,7 @@ store_sysmap_symbols(void)
+ * are not as loaded into the kernel (not unity-mapped).
+ */
+ static ulong
+-relocate(ulong symval, char *symname, int first_symbol)
++relocate(ulong symval, char *symname, int *first_symbol)
+ {
+ if (XEN_HYPER_MODE()) {
+ kt->flags &= ~(RELOC_SET|RELOC_FORCE);
+@@ -937,9 +938,10 @@ relocate(ulong symval, char *symname, int first_symbol)
+ break;
+
+ case RELOC_FORCE:
+- if (first_symbol && !relocate_force(symval, symname))
+- kt->flags &= ~RELOC_FORCE;
+- break;
++ if (!(*first_symbol) && relocate_force(symval, symname)) {
++ *first_symbol += 1;
++ }
++ return symval - kt->relocate;
+ }
+
+ if (machine_type("X86_64")) {
+--
+2.35.5
+
diff --git a/meta-openembedded/meta-oe/recipes-kernel/intel-speed-select/intel-speed-select.bb b/meta-openembedded/meta-oe/recipes-kernel/intel-speed-select/intel-speed-select.bb
index 23ea0d8aae..3b5866180d 100644
--- a/meta-openembedded/meta-oe/recipes-kernel/intel-speed-select/intel-speed-select.bb
+++ b/meta-openembedded/meta-oe/recipes-kernel/intel-speed-select/intel-speed-select.bb
@@ -13,7 +13,7 @@ COMPATIBLE_HOST:libc-musl = 'null'
DEPENDS = "libnl"
-do_populate_lic[depends] += "virtual/kernel:do_patch"
+do_populate_lic[depends] += "virtual/kernel:do_shared_workdir"
B = "${WORKDIR}/${BPN}-${PV}"
diff --git a/meta-openembedded/meta-oe/recipes-kernel/kernel-selftest/kernel-selftest.bb b/meta-openembedded/meta-oe/recipes-kernel/kernel-selftest/kernel-selftest.bb
index 01f185adba..a070ceab55 100644
--- a/meta-openembedded/meta-oe/recipes-kernel/kernel-selftest/kernel-selftest.bb
+++ b/meta-openembedded/meta-oe/recipes-kernel/kernel-selftest/kernel-selftest.bb
@@ -55,7 +55,7 @@ TEST_LIST = "\
EXTRA_OEMAKE = '\
CROSS_COMPILE=${TARGET_PREFIX} \
ARCH=${ARCH} \
- CC="${CC}" \
+ CC="${CC} ${DEBUG_PREFIX_MAP}" \
AR="${AR}" \
LD="${LD}" \
CLANG="clang -fno-stack-protector -target ${TARGET_ARCH} ${TOOLCHAIN_OPTIONS} -isystem ${S} -D__WORDSIZE=\'64\' -Wno-error=unused-command-line-argument" \
@@ -96,25 +96,13 @@ either install it and add it to HOSTTOOLS, or add clang-native from meta-clang t
sed -i -e '/mrecord-mcount/d' ${S}/Makefile
sed -i -e '/Wno-alloc-size-larger-than/d' ${S}/Makefile
sed -i -e '/Wno-alloc-size-larger-than/d' ${S}/scripts/Makefile.*
- for i in ${TEST_LIST}
- do
- oe_runmake -C ${S}/tools/testing/selftests/${i}
- done
+ oe_runmake -C ${S}/tools/testing/selftests TARGETS="${TEST_LIST}"
}
do_install() {
- for i in ${TEST_LIST}
- do
- oe_runmake -C ${S}/tools/testing/selftests/${i} INSTALL_PATH=${D}/usr/kernel-selftest/${i} install
- # Install kselftest-list.txt that required by kselftest runner.
- oe_runmake -s --no-print-directory COLLECTION=${i} -C ${S}/tools/testing/selftests/${i} emit_tests \
- >> ${D}/usr/kernel-selftest/kselftest-list.txt
- done
- # Install kselftest runner.
- install -m 0755 ${S}/tools/testing/selftests/run_kselftest.sh ${D}/usr/kernel-selftest/
- cp -R --no-dereference --preserve=mode,links -v ${S}/tools/testing/selftests/kselftest ${D}/usr/kernel-selftest/
+ oe_runmake -C ${S}/tools/testing/selftests INSTALL_PATH=${D}/usr/kernel-selftest TARGETS="${TEST_LIST}" install
if [ -e ${D}/usr/kernel-selftest/bpf/test_offload.py ]; then
- sed -i -e '1s,#!.*python3,#! /usr/bin/env python3,' ${D}/usr/kernel-selftest/bpf/test_offload.py
+ sed -i -e '1s,#!.*python3,#! /usr/bin/env python3,' ${D}/usr/kernel-selftest/bpf/test_offload.py
fi
chown root:root -R ${D}/usr/kernel-selftest
}
@@ -158,6 +146,12 @@ RDEPENDS:${PN} += "python3 perl perl-module-io-handle"
INSANE_SKIP:${PN} += "libdir"
+# A few of the selftests set compile flags that trip up the "ldflags" and
+# "already-stripped" QA checks. As this is mainly a testing package and
+# not really meant for user level execution, disable these two checks.
+INSANE_SKIP:${PN} += "ldflags"
+INSANE_SKIP:${PN} += "already-stripped"
+
SECURITY_CFLAGS = ""
COMPATIBLE_HOST:libc-musl = 'null'
diff --git a/meta-openembedded/meta-oe/recipes-kernel/spidev-test/spidev-test.bb b/meta-openembedded/meta-oe/recipes-kernel/spidev-test/spidev-test.bb
index 2e8c5cbb8d..7b87dd28df 100644
--- a/meta-openembedded/meta-oe/recipes-kernel/spidev-test/spidev-test.bb
+++ b/meta-openembedded/meta-oe/recipes-kernel/spidev-test/spidev-test.bb
@@ -6,7 +6,7 @@ PROVIDES = "virtual/spidev-test"
inherit bash-completion kernelsrc kernel-arch
-do_populate_lic[depends] += "virtual/kernel:do_patch"
+do_populate_lic[depends] += "virtual/kernel:do_shared_workdir"
EXTRA_OEMAKE = "-C ${S}/tools/spi O=${B} CROSS=${TARGET_PREFIX} CC="${CC}" LD="${LD}" AR=${AR} ARCH=${ARCH}"
diff --git a/meta-openembedded/meta-oe/recipes-multimedia/audiofile/audiofile_0.3.6.bb b/meta-openembedded/meta-oe/recipes-multimedia/audiofile/audiofile_0.3.6.bb
index a09f84381e..d10c7a8b49 100644
--- a/meta-openembedded/meta-oe/recipes-multimedia/audiofile/audiofile_0.3.6.bb
+++ b/meta-openembedded/meta-oe/recipes-multimedia/audiofile/audiofile_0.3.6.bb
@@ -13,6 +13,11 @@ SRC_URI = " \
file://0001-fix-negative-shift-constants.patch \
file://0002-fix-build-on-gcc6.patch \
file://0003-fix-CVE-2015-7747.patch \
+ file://0004-Always-check-the-number-of-coefficients.patch \
+ file://0005-clamp-index-values-to-fix-index-overflow-in-IMA.cpp.patch \
+ file://0006-Check-for-multiplication-overflow-in-sfconvert.patch \
+ file://0007-Actually-fail-when-error-occurs-in-parseFormat.patch \
+ file://0008-Check-for-multiplication-overflow-in-MSADPCM-decodeS.patch \
"
SRC_URI[md5sum] = "235dde14742317328f0109e9866a8008"
SRC_URI[sha256sum] = "ea2449ad3f201ec590d811db9da6d02ffc5e87a677d06b92ab15363d8cb59782"
diff --git a/meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0004-Always-check-the-number-of-coefficients.patch b/meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0004-Always-check-the-number-of-coefficients.patch
new file mode 100644
index 0000000000..282f4c01b9
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0004-Always-check-the-number-of-coefficients.patch
@@ -0,0 +1,45 @@
+From c48e4c6503f7dabd41f11d4c9c7b7f8960e7f2c0 Mon Sep 17 00:00:00 2001
+From: Antonio Larrosa <larrosa@kde.org>
+Date: Mon, 6 Mar 2017 12:51:22 +0100
+Subject: [PATCH] Always check the number of coefficients
+
+When building the library with NDEBUG, asserts are eliminated
+so it's better to always check that the number of coefficients
+is inside the array range.
+
+This fixes the 00191-audiofile-indexoob issue in #41
+
+Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
+
+CVE: CVE-2017-6827
+CVE: CVE-2017-6828
+CVE: CVE-2017-6832
+CVE: CVE-2017-6833
+CVE: CVE-2017-6835
+CVE: CVE-2017-6837
+Upstream-Status: Inactive-Upstream [lastrelease: 2013]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ libaudiofile/WAVE.cpp | 6 ++++++
+ 1 file changed, 6 insertions(+)
+
+diff --git a/libaudiofile/WAVE.cpp b/libaudiofile/WAVE.cpp
+index 0e81cf7..61f9541 100644
+--- a/libaudiofile/WAVE.cpp
++++ b/libaudiofile/WAVE.cpp
+@@ -281,6 +281,12 @@ status WAVEFile::parseFormat(const Tag &id, uint32_t size)
+
+ /* numCoefficients should be at least 7. */
+ assert(numCoefficients >= 7 && numCoefficients <= 255);
++ if (numCoefficients < 7 || numCoefficients > 255)
++ {
++ _af_error(AF_BAD_HEADER,
++ "Bad number of coefficients");
++ return AF_FAIL;
++ }
+
+ m_msadpcmNumCoefficients = numCoefficients;
+
+--
+2.11.0
+
diff --git a/meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0005-clamp-index-values-to-fix-index-overflow-in-IMA.cpp.patch b/meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0005-clamp-index-values-to-fix-index-overflow-in-IMA.cpp.patch
new file mode 100644
index 0000000000..00bb7e597e
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0005-clamp-index-values-to-fix-index-overflow-in-IMA.cpp.patch
@@ -0,0 +1,43 @@
+From 25eb00ce913452c2e614548d7df93070bf0d066f Mon Sep 17 00:00:00 2001
+From: Antonio Larrosa <larrosa@kde.org>
+Date: Mon, 6 Mar 2017 18:02:31 +0100
+Subject: [PATCH] clamp index values to fix index overflow in IMA.cpp
+
+This fixes #33
+(also reported at https://bugzilla.opensuse.org/show_bug.cgi?id=1026981
+and https://blogs.gentoo.org/ago/2017/02/20/audiofile-global-buffer-overflow-in-decodesample-ima-cpp/)
+
+Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
+
+CVE: CVE-2017-6829
+Upstream-Status: Inactive-Upstream [lastrelease: 2013]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ libaudiofile/modules/IMA.cpp | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/libaudiofile/modules/IMA.cpp b/libaudiofile/modules/IMA.cpp
+index 7476d44..df4aad6 100644
+--- a/libaudiofile/modules/IMA.cpp
++++ b/libaudiofile/modules/IMA.cpp
+@@ -169,7 +169,7 @@ int IMA::decodeBlockWAVE(const uint8_t *encoded, int16_t *decoded)
+ if (encoded[1] & 0x80)
+ m_adpcmState[c].previousValue -= 0x10000;
+
+- m_adpcmState[c].index = encoded[2];
++ m_adpcmState[c].index = clamp(encoded[2], 0, 88);
+
+ *decoded++ = m_adpcmState[c].previousValue;
+
+@@ -210,7 +210,7 @@ int IMA::decodeBlockQT(const uint8_t *encoded, int16_t *decoded)
+ predictor -= 0x10000;
+
+ state.previousValue = clamp(predictor, MIN_INT16, MAX_INT16);
+- state.index = encoded[1] & 0x7f;
++ state.index = clamp(encoded[1] & 0x7f, 0, 88);
+ encoded += 2;
+
+ for (int n=0; n<m_framesPerPacket; n+=2)
+--
+2.11.0
+
diff --git a/meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0006-Check-for-multiplication-overflow-in-sfconvert.patch b/meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0006-Check-for-multiplication-overflow-in-sfconvert.patch
new file mode 100644
index 0000000000..ec21b09f30
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0006-Check-for-multiplication-overflow-in-sfconvert.patch
@@ -0,0 +1,79 @@
+From 7d65f89defb092b63bcbc5d98349fb222ca73b3c Mon Sep 17 00:00:00 2001
+From: Antonio Larrosa <larrosa@kde.org>
+Date: Mon, 6 Mar 2017 13:54:52 +0100
+Subject: [PATCH] Check for multiplication overflow in sfconvert
+
+Checks that a multiplication doesn't overflow when
+calculating the buffer size, and if it overflows,
+reduce the buffer size instead of failing.
+
+This fixes the 00192-audiofile-signintoverflow-sfconvert case
+in #41
+
+Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
+
+CVE: CVE-2017-6830
+CVE: CVE-2017-6834
+CVE: CVE-2017-6836
+CVE: CVE-2017-6838
+Upstream-Status: Inactive-Upstream [lastrelease: 2013]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ sfcommands/sfconvert.c | 34 ++++++++++++++++++++++++++++++++--
+ 1 file changed, 32 insertions(+), 2 deletions(-)
+
+diff --git a/sfcommands/sfconvert.c b/sfcommands/sfconvert.c
+index 80a1bc4..970a3e4 100644
+--- a/sfcommands/sfconvert.c
++++ b/sfcommands/sfconvert.c
+@@ -45,6 +45,33 @@ void printusage (void);
+ void usageerror (void);
+ bool copyaudiodata (AFfilehandle infile, AFfilehandle outfile, int trackid);
+
++int firstBitSet(int x)
++{
++ int position=0;
++ while (x!=0)
++ {
++ x>>=1;
++ ++position;
++ }
++ return position;
++}
++
++#ifndef __has_builtin
++#define __has_builtin(x) 0
++#endif
++
++int multiplyCheckOverflow(int a, int b, int *result)
++{
++#if (defined __GNUC__ && __GNUC__ >= 5) || ( __clang__ && __has_builtin(__builtin_mul_overflow))
++ return __builtin_mul_overflow(a, b, result);
++#else
++ if (firstBitSet(a)+firstBitSet(b)>31) // int is signed, so we can't use 32 bits
++ return true;
++ *result = a * b;
++ return false;
++#endif
++}
++
+ int main (int argc, char **argv)
+ {
+ if (argc == 2)
+@@ -323,8 +350,11 @@ bool copyaudiodata (AFfilehandle infile, AFfilehandle outfile, int trackid)
+ {
+ int frameSize = afGetVirtualFrameSize(infile, trackid, 1);
+
+- const int kBufferFrameCount = 65536;
+- void *buffer = malloc(kBufferFrameCount * frameSize);
++ int kBufferFrameCount = 65536;
++ int bufferSize;
++ while (multiplyCheckOverflow(kBufferFrameCount, frameSize, &bufferSize))
++ kBufferFrameCount /= 2;
++ void *buffer = malloc(bufferSize);
+
+ AFframecount totalFrames = afGetFrameCount(infile, AF_DEFAULT_TRACK);
+ AFframecount totalFramesWritten = 0;
+--
+2.11.0
+
diff --git a/meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0007-Actually-fail-when-error-occurs-in-parseFormat.patch b/meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0007-Actually-fail-when-error-occurs-in-parseFormat.patch
new file mode 100644
index 0000000000..38294ca200
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0007-Actually-fail-when-error-occurs-in-parseFormat.patch
@@ -0,0 +1,46 @@
+From a2e9eab8ea87c4ffc494d839ebb4ea145eb9f2e6 Mon Sep 17 00:00:00 2001
+From: Antonio Larrosa <larrosa@kde.org>
+Date: Mon, 6 Mar 2017 18:59:26 +0100
+Subject: [PATCH] Actually fail when error occurs in parseFormat
+
+When there's an unsupported number of bits per sample or an invalid
+number of samples per block, don't only print an error message using
+the error handler, but actually stop parsing the file.
+
+This fixes #35 (also reported at
+https://bugzilla.opensuse.org/show_bug.cgi?id=1026983 and
+https://blogs.gentoo.org/ago/2017/02/20/audiofile-heap-based-buffer-overflow-in-imadecodeblockwave-ima-cpp/
+)
+
+Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
+
+CVE: CVE-2017-6831
+Upstream-Status: Inactive-Upstream [lastrelease: 2013]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ libaudiofile/WAVE.cpp | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/libaudiofile/WAVE.cpp b/libaudiofile/WAVE.cpp
+index 0e81cf7..d762249 100644
+--- a/libaudiofile/WAVE.cpp
++++ b/libaudiofile/WAVE.cpp
+@@ -326,6 +326,7 @@ status WAVEFile::parseFormat(const Tag &id, uint32_t size)
+ {
+ _af_error(AF_BAD_NOT_IMPLEMENTED,
+ "IMA ADPCM compression supports only 4 bits per sample");
++ return AF_FAIL;
+ }
+
+ int bytesPerBlock = (samplesPerBlock + 14) / 8 * 4 * channelCount;
+@@ -333,6 +334,7 @@ status WAVEFile::parseFormat(const Tag &id, uint32_t size)
+ {
+ _af_error(AF_BAD_CODEC_CONFIG,
+ "Invalid samples per block for IMA ADPCM compression");
++ return AF_FAIL;
+ }
+
+ track->f.sampleWidth = 16;
+--
+2.11.0
+
diff --git a/meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0008-Check-for-multiplication-overflow-in-MSADPCM-decodeS.patch b/meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0008-Check-for-multiplication-overflow-in-MSADPCM-decodeS.patch
new file mode 100644
index 0000000000..857ed78c59
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-multimedia/audiofile/files/0008-Check-for-multiplication-overflow-in-MSADPCM-decodeS.patch
@@ -0,0 +1,126 @@
+From beacc44eb8cdf6d58717ec1a5103c5141f1b37f9 Mon Sep 17 00:00:00 2001
+From: Antonio Larrosa <larrosa@kde.org>
+Date: Mon, 6 Mar 2017 13:43:53 +0100
+Subject: [PATCH] Check for multiplication overflow in MSADPCM decodeSample
+
+Check for multiplication overflow (using __builtin_mul_overflow
+if available) in MSADPCM.cpp decodeSample and return an empty
+decoded block if an error occurs.
+
+This fixes the 00193-audiofile-signintoverflow-MSADPCM case of #41
+
+Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
+
+CVE: CVE-2017-6839
+Upstream-Status: Inactive-Upstream [lastrelease: 2013]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ libaudiofile/modules/BlockCodec.cpp | 5 ++--
+ libaudiofile/modules/MSADPCM.cpp | 47 +++++++++++++++++++++++++++++++++----
+ 2 files changed, 46 insertions(+), 6 deletions(-)
+
+diff --git a/libaudiofile/modules/BlockCodec.cpp b/libaudiofile/modules/BlockCodec.cpp
+index 45925e8..4731be1 100644
+--- a/libaudiofile/modules/BlockCodec.cpp
++++ b/libaudiofile/modules/BlockCodec.cpp
+@@ -52,8 +52,9 @@ void BlockCodec::runPull()
+ // Decompress into m_outChunk.
+ for (int i=0; i<blocksRead; i++)
+ {
+- decodeBlock(static_cast<const uint8_t *>(m_inChunk->buffer) + i * m_bytesPerPacket,
+- static_cast<int16_t *>(m_outChunk->buffer) + i * m_framesPerPacket * m_track->f.channelCount);
++ if (decodeBlock(static_cast<const uint8_t *>(m_inChunk->buffer) + i * m_bytesPerPacket,
++ static_cast<int16_t *>(m_outChunk->buffer) + i * m_framesPerPacket * m_track->f.channelCount)==0)
++ break;
+
+ framesRead += m_framesPerPacket;
+ }
+diff --git a/libaudiofile/modules/MSADPCM.cpp b/libaudiofile/modules/MSADPCM.cpp
+index 8ea3c85..ef9c38c 100644
+--- a/libaudiofile/modules/MSADPCM.cpp
++++ b/libaudiofile/modules/MSADPCM.cpp
+@@ -101,24 +101,60 @@ static const int16_t adaptationTable[] =
+ 768, 614, 512, 409, 307, 230, 230, 230
+ };
+
++int firstBitSet(int x)
++{
++ int position=0;
++ while (x!=0)
++ {
++ x>>=1;
++ ++position;
++ }
++ return position;
++}
++
++#ifndef __has_builtin
++#define __has_builtin(x) 0
++#endif
++
++int multiplyCheckOverflow(int a, int b, int *result)
++{
++#if (defined __GNUC__ && __GNUC__ >= 5) || ( __clang__ && __has_builtin(__builtin_mul_overflow))
++ return __builtin_mul_overflow(a, b, result);
++#else
++ if (firstBitSet(a)+firstBitSet(b)>31) // int is signed, so we can't use 32 bits
++ return true;
++ *result = a * b;
++ return false;
++#endif
++}
++
++
+ // Compute a linear PCM value from the given differential coded value.
+ static int16_t decodeSample(ms_adpcm_state &state,
+- uint8_t code, const int16_t *coefficient)
++ uint8_t code, const int16_t *coefficient, bool *ok=NULL)
+ {
+ int linearSample = (state.sample1 * coefficient[0] +
+ state.sample2 * coefficient[1]) >> 8;
++ int delta;
+
+ linearSample += ((code & 0x08) ? (code - 0x10) : code) * state.delta;
+
+ linearSample = clamp(linearSample, MIN_INT16, MAX_INT16);
+
+- int delta = (state.delta * adaptationTable[code]) >> 8;
++ if (multiplyCheckOverflow(state.delta, adaptationTable[code], &delta))
++ {
++ if (ok) *ok=false;
++ _af_error(AF_BAD_COMPRESSION, "Error decoding sample");
++ return 0;
++ }
++ delta >>= 8;
+ if (delta < 16)
+ delta = 16;
+
+ state.delta = delta;
+ state.sample2 = state.sample1;
+ state.sample1 = linearSample;
++ if (ok) *ok=true;
+
+ return static_cast<int16_t>(linearSample);
+ }
+@@ -212,13 +248,16 @@ int MSADPCM::decodeBlock(const uint8_t *encoded, int16_t *decoded)
+ {
+ uint8_t code;
+ int16_t newSample;
++ bool ok;
+
+ code = *encoded >> 4;
+- newSample = decodeSample(*state[0], code, coefficient[0]);
++ newSample = decodeSample(*state[0], code, coefficient[0], &ok);
++ if (!ok) return 0;
+ *decoded++ = newSample;
+
+ code = *encoded & 0x0f;
+- newSample = decodeSample(*state[1], code, coefficient[1]);
++ newSample = decodeSample(*state[1], code, coefficient[1], &ok);
++ if (!ok) return 0;
+ *decoded++ = newSample;
+
+ encoded++;
+--
+2.11.0
+
diff --git a/meta-openembedded/meta-oe/recipes-multimedia/libjxl/libjxl/CVE-2024-11403.patch b/meta-openembedded/meta-oe/recipes-multimedia/libjxl/libjxl/CVE-2024-11403.patch
new file mode 100644
index 0000000000..625218c2d3
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-multimedia/libjxl/libjxl/CVE-2024-11403.patch
@@ -0,0 +1,70 @@
+From 9cc451b91b74ba470fd72bd48c121e9f33d24c99 Mon Sep 17 00:00:00 2001
+From: szabadka <9074039+szabadka@users.noreply.github.com>
+Date: Thu, 3 Oct 2024 18:07:38 +0200
+Subject: [PATCH] Port the Huffman lookup table size fix from brunsli. (#3871)
+
+CVE: CVE-2024-11403
+Upstream-Status: Backport [https://github.com/libjxl/libjxl/commit/9cc451b91b74ba470fd72bd48c121e9f33d24c99]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ lib/jpegli/huffman.h | 16 ++++++++++++----
+ lib/jxl/jpeg/enc_jpeg_huffman_decode.h | 16 ++++++++++++----
+ 2 files changed, 24 insertions(+), 8 deletions(-)
+
+diff --git a/lib/jpegli/huffman.h b/lib/jpegli/huffman.h
+index f0e5e1de..99549668 100644
+--- a/lib/jpegli/huffman.h
++++ b/lib/jpegli/huffman.h
+@@ -15,10 +15,18 @@ namespace jpegli {
+
+ constexpr int kJpegHuffmanRootTableBits = 8;
+ // Maximum huffman lookup table size.
+-// According to zlib/examples/enough.c, 758 entries are always enough for
+-// an alphabet of 257 symbols (256 + 1 special symbol for the all 1s code) and
+-// max bit length 16 if the root table has 8 bits.
+-constexpr int kJpegHuffmanLutSize = 758;
++// Requirements: alphabet of 257 symbols (256 + 1 special symbol for the all 1s
++// code) and max bit length 16, the root table has 8 bits.
++// zlib/examples/enough.c works with an assumption that Huffman code is
++// "complete". Input JPEGs might have this assumption broken, hence the
++// following sum is used as estimate:
++// + number of 1-st level cells
++// + number of symbols
++// + asymptotic amount of repeated 2nd level cells
++// The third number is 1 + 3 + ... + 255 i.e. it is assumed that sub-table of
++// each "size" might be almost completely be filled with repetitions.
++// Total sum is slightly less than 1024,...
++constexpr int kJpegHuffmanLutSize = 1024;
+
+ struct HuffmanTableEntry {
+ uint8_t bits; // number of bits used for this symbol
+diff --git a/lib/jxl/jpeg/enc_jpeg_huffman_decode.h b/lib/jxl/jpeg/enc_jpeg_huffman_decode.h
+index b8a60e41..fc9bd17b 100644
+--- a/lib/jxl/jpeg/enc_jpeg_huffman_decode.h
++++ b/lib/jxl/jpeg/enc_jpeg_huffman_decode.h
+@@ -15,10 +15,18 @@ namespace jpeg {
+
+ constexpr int kJpegHuffmanRootTableBits = 8;
+ // Maximum huffman lookup table size.
+-// According to zlib/examples/enough.c, 758 entries are always enough for
+-// an alphabet of 257 symbols (256 + 1 special symbol for the all 1s code) and
+-// max bit length 16 if the root table has 8 bits.
+-constexpr int kJpegHuffmanLutSize = 758;
++// Requirements: alphabet of 257 symbols (256 + 1 special symbol for the all 1s
++// code) and max bit length 16, the root table has 8 bits.
++// zlib/examples/enough.c works with an assumption that Huffman code is
++// "complete". Input JPEGs might have this assumption broken, hence the
++// following sum is used as estimate:
++// + number of 1-st level cells
++// + number of symbols
++// + asymptotic amount of repeated 2nd level cells
++// The third number is 1 + 3 + ... + 255 i.e. it is assumed that sub-table of
++// each "size" might be almost completely be filled with repetitions.
++// Total sum is slightly less than 1024,...
++constexpr int kJpegHuffmanLutSize = 1024;
+
+ struct HuffmanTableEntry {
+ // Initialize the value to an invalid symbol so that we can recognize it
+--
+2.50.1
+
diff --git a/meta-openembedded/meta-oe/recipes-multimedia/libjxl/libjxl/CVE-2024-11498.patch b/meta-openembedded/meta-oe/recipes-multimedia/libjxl/libjxl/CVE-2024-11498.patch
new file mode 100644
index 0000000000..25f85e1527
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-multimedia/libjxl/libjxl/CVE-2024-11498.patch
@@ -0,0 +1,113 @@
+From bf4781a2eed2eef664790170977d1d3d8347efb9 Mon Sep 17 00:00:00 2001
+From: Luca Versari <veluca@google.com>
+Date: Thu, 21 Nov 2024 16:33:08 +0100
+Subject: [PATCH] Check height limit in modular trees. (#3943)
+
+Also rewrite the implementation to use iterative checking instead of
+recursive checking of tree property values, to ensure stack usage is
+low.
+
+Before, it was possible for appropriately-crafted files to use a
+significant amount of stack (in the order of hundreds of MB).
+
+CVE: CVE-2024-11498
+Upstream-Status: Backport [https://github.com/libjxl/libjxl/commit/bf4781a2eed2eef664790170977d1d3d8347efb9]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ lib/jxl/modular/encoding/dec_ma.cc | 66 ++++++++++++++++++++----------
+ 1 file changed, 45 insertions(+), 21 deletions(-)
+
+diff --git a/lib/jxl/modular/encoding/dec_ma.cc b/lib/jxl/modular/encoding/dec_ma.cc
+index b53b9a91..df2948d8 100644
+--- a/lib/jxl/modular/encoding/dec_ma.cc
++++ b/lib/jxl/modular/encoding/dec_ma.cc
+@@ -6,6 +6,7 @@
+ #include "lib/jxl/modular/encoding/dec_ma.h"
+
+ #include <limits>
++#include <vector>
+
+ #include "lib/jxl/base/printf_macros.h"
+ #include "lib/jxl/dec_ans.h"
+@@ -17,23 +18,49 @@ namespace jxl {
+
+ namespace {
+
+-Status ValidateTree(
+- const Tree &tree,
+- const std::vector<std::pair<pixel_type, pixel_type>> &prop_bounds,
+- size_t root) {
+- if (tree[root].property == -1) return true;
+- size_t p = tree[root].property;
+- int val = tree[root].splitval;
+- if (prop_bounds[p].first > val) return JXL_FAILURE("Invalid tree");
+- // Splitting at max value makes no sense: left range will be exactly same
+- // as parent, right range will be invalid (min > max).
+- if (prop_bounds[p].second <= val) return JXL_FAILURE("Invalid tree");
+- auto new_bounds = prop_bounds;
+- new_bounds[p].first = val + 1;
+- JXL_RETURN_IF_ERROR(ValidateTree(tree, new_bounds, tree[root].lchild));
+- new_bounds[p] = prop_bounds[p];
+- new_bounds[p].second = val;
+- return ValidateTree(tree, new_bounds, tree[root].rchild);
++Status ValidateTree(const Tree &tree) {
++ int num_properties = 0;
++ for (auto node : tree) {
++ if (node.property >= num_properties) {
++ num_properties = node.property + 1;
++ }
++ }
++ std::vector<int> height(tree.size());
++ std::vector<std::pair<pixel_type, pixel_type>> property_ranges(
++ num_properties * tree.size());
++ for (int i = 0; i < num_properties; i++) {
++ property_ranges[i].first = std::numeric_limits<pixel_type>::min();
++ property_ranges[i].second = std::numeric_limits<pixel_type>::max();
++ }
++ const int kHeightLimit = 2048;
++ for (size_t i = 0; i < tree.size(); i++) {
++ if (height[i] > kHeightLimit) {
++ return JXL_FAILURE("Tree too tall: %d", height[i]);
++ }
++ if (tree[i].property == -1) continue;
++ height[tree[i].lchild] = height[i] + 1;
++ height[tree[i].rchild] = height[i] + 1;
++ for (size_t p = 0; p < static_cast<size_t>(num_properties); p++) {
++ if (p == static_cast<size_t>(tree[i].property)) {
++ pixel_type l = property_ranges[i * num_properties + p].first;
++ pixel_type u = property_ranges[i * num_properties + p].second;
++ pixel_type val = tree[i].splitval;
++ if (l > val || u <= val) {
++ return JXL_FAILURE("Invalid tree");
++ }
++ property_ranges[tree[i].lchild * num_properties + p] =
++ std::make_pair(val + 1, u);
++ property_ranges[tree[i].rchild * num_properties + p] =
++ std::make_pair(l, val);
++ } else {
++ property_ranges[tree[i].lchild * num_properties + p] =
++ property_ranges[i * num_properties + p];
++ property_ranges[tree[i].rchild * num_properties + p] =
++ property_ranges[i * num_properties + p];
++ }
++ }
++ }
++ return true;
+ }
+
+ Status DecodeTree(BitReader *br, ANSSymbolReader *reader,
+@@ -82,10 +109,7 @@ Status DecodeTree(BitReader *br, ANSSymbolReader *reader,
+ tree->size() + to_decode + 2, Predictor::Zero, 0, 1);
+ to_decode += 2;
+ }
+- std::vector<std::pair<pixel_type, pixel_type>> prop_bounds;
+- prop_bounds.resize(256, {std::numeric_limits<pixel_type>::min(),
+- std::numeric_limits<pixel_type>::max()});
+- return ValidateTree(*tree, prop_bounds, 0);
++ return ValidateTree(*tree);
+ }
+ } // namespace
+
+--
+2.50.1
+
diff --git a/meta-openembedded/meta-oe/recipes-multimedia/libjxl/libjxl_0.10.2.bb b/meta-openembedded/meta-oe/recipes-multimedia/libjxl/libjxl_0.10.2.bb
index eced6c7726..2bf0f126b0 100644
--- a/meta-openembedded/meta-oe/recipes-multimedia/libjxl/libjxl_0.10.2.bb
+++ b/meta-openembedded/meta-oe/recipes-multimedia/libjxl/libjxl_0.10.2.bb
@@ -8,8 +8,10 @@ inherit cmake pkgconfig mime
DEPENDS = "highway brotli"
-SRC_URI = "gitsm://github.com/libjxl/libjxl.git;protocol=https;nobranch=1"
-
+SRC_URI = "gitsm://github.com/libjxl/libjxl.git;protocol=https;nobranch=1 \
+ file://CVE-2024-11403.patch \
+ file://CVE-2024-11498.patch \
+ "
SRCREV = "e1489592a770b989303b0edc5cc1dc447bbe0515"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-oe/recipes-multimedia/pulseaudio/pavucontrol_5.0.bb b/meta-openembedded/meta-oe/recipes-multimedia/pulseaudio/pavucontrol_5.0.bb
index 012fc3a94d..29500bdb94 100644
--- a/meta-openembedded/meta-oe/recipes-multimedia/pulseaudio/pavucontrol_5.0.bb
+++ b/meta-openembedded/meta-oe/recipes-multimedia/pulseaudio/pavucontrol_5.0.bb
@@ -14,7 +14,7 @@ inherit autotools features_check perlnative pkgconfig
ANY_OF_DISTRO_FEATURES = "${GTK3DISTROFEATURES}"
-SRC_URI = "http://freedesktop.org/software/pulseaudio/${BPN}/${BP}.tar.xz"
+SRC_URI = "http://www.freedesktop.org/software/pulseaudio/${BPN}/${BP}.tar.xz"
SRC_URI:append = " ${@bb.utils.contains('DISTRO_FEATURES', 'wayland', 'file://0001-pavucontrol-remove-canberra-gtk-support.patch', '', d)}"
SRC_URI[sha256sum] = "ce2b72c3b5f1a70ad0df19dd81750f9455bd20870d1d3a36d20536af2e8f4e7a"
diff --git a/meta-openembedded/meta-oe/recipes-multimedia/v4l2apps/v4l-utils/0001-media-ctl-Install-media-ctl-header-and-library-files.patch b/meta-openembedded/meta-oe/recipes-multimedia/v4l2apps/v4l-utils/0001-media-ctl-Install-media-ctl-header-and-library-files.patch
new file mode 100644
index 0000000000..6c946d8c48
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-multimedia/v4l2apps/v4l-utils/0001-media-ctl-Install-media-ctl-header-and-library-files.patch
@@ -0,0 +1,78 @@
+From 3867fcfa4389c7fa271705f1fd1d4bfb74bc1bd1 Mon Sep 17 00:00:00 2001
+From: Neel Gandhi <neel.gandhi@amd.com>
+Date: Wed, 5 Jun 2024 13:51:36 +0530
+Subject: [PATCH] media-ctl: Install media-ctl header and library files
+
+Install mediactl and v4l2subdev header and library
+files, which may be required by 3rd party applications
+to populate and control v4l2subdev device node tree
+
+Install of these files was removed in upstream commit
+0911dce53b08b0df3066be2c75f67e8a314d8729.
+
+Upstream-Status: Denied
+
+v4l-utils maintainers do not promise a stable API for this library, and
+do not currently have the time to do so. So exporting the API in this
+way is fine, as long as we understand that it will change and users of
+the API will need to adapt over time.
+
+Signed-off-by: Neel Gandhi <neel.gandhi@amd.com>
+Signed-off-by: Mark Hatle <mark.hatle@amd.com>
+---
+ utils/media-ctl/meson.build | 28 +++++++++++++++++++++-------
+ 1 file changed, 21 insertions(+), 7 deletions(-)
+
+diff --git a/utils/media-ctl/meson.build b/utils/media-ctl/meson.build
+index 3a7b0c9a..40669b4c 100644
+--- a/utils/media-ctl/meson.build
++++ b/utils/media-ctl/meson.build
+@@ -3,14 +3,24 @@ libmediactl_sources = files(
+ 'mediactl-priv.h',
+ )
+
++libmediactl_api = files(
++ 'mediactl.h',
++ 'v4l2subdev.h',
++)
++
++install_headers(libmediactl_api, subdir: 'mediactl')
++
+ libmediactl_deps = [
+ dep_libudev,
+ ]
+
+-libmediactl = static_library('mediactl',
+- libmediactl_sources,
+- dependencies : libmediactl_deps,
+- include_directories : v4l2_utils_incdir)
++libmediactl = library('mediactl',
++ libmediactl_sources,
++ soversion: '0',
++ version: '0.0.0',
++ install : true,
++ dependencies : libmediactl_deps,
++ include_directories : v4l2_utils_incdir)
+
+ dep_libmediactl = declare_dependency(link_with : libmediactl)
+
+@@ -18,9 +28,13 @@ libv4l2subdev_sources = files('libv4l2subdev.c')
+ libv4l2subdev_sources += media_bus_format_names_h
+ libv4l2subdev_sources += media_bus_format_codes_h
+
+-libv4l2subdev = static_library('v4l2subdev',
+- libv4l2subdev_sources,
+- include_directories : v4l2_utils_incdir)
++libv4l2subdev = library('v4l2subdev',
++ libv4l2subdev_sources,
++ soversion: '0',
++ version: '0.0.0',
++ install : true,
++ dependencies : dep_libmediactl,
++ include_directories : v4l2_utils_incdir)
+
+ dep_libv4l2subdev = declare_dependency(link_with : libv4l2subdev)
+
+--
+2.34.1
+
diff --git a/meta-openembedded/meta-oe/recipes-multimedia/v4l2apps/v4l-utils/0003-meson.build-fix-arm-_TIME_BITS-64-error.patch b/meta-openembedded/meta-oe/recipes-multimedia/v4l2apps/v4l-utils/0003-meson.build-fix-arm-_TIME_BITS-64-error.patch
new file mode 100644
index 0000000000..f41dde0e16
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-multimedia/v4l2apps/v4l-utils/0003-meson.build-fix-arm-_TIME_BITS-64-error.patch
@@ -0,0 +1,38 @@
+From 5aabd01e415374fc97eebe80d4635c3bae728f81 Mon Sep 17 00:00:00 2001
+From: Hans Verkuil <hverkuil@xs4all.nl>
+Date: Sat, 12 Apr 2025 12:30:13 +0200
+Subject: [PATCH] meson.build: fix arm _TIME_BITS=64 error
+
+Undefine _TIME_BITS to avoid this error on 32-bit arm:
+
+/usr/include/features-time64.h:26:5: error: #error "_TIME_BITS=64 is allowed only with _FILE_OFFSET_BITS=64"
+
+Upstream-Status: Backport [https://github.com/gjasny/v4l-utils/commit/d517cfdcdc16533ab7e06e97c07ca089cf261aef]
+
+Signed-off-by: Hans Verkuil <hverkuil@xs4all.nl>
+Signed-off-by: Jiaying Song <jiaying.song.cn@windriver.com>
+---
+ meson.build | 6 +++++-
+ 1 file changed, 5 insertions(+), 1 deletion(-)
+
+diff --git a/meson.build b/meson.build
+index 269a9da7..31927cda 100644
+--- a/meson.build
++++ b/meson.build
+@@ -53,8 +53,12 @@ v4l2_wrapper_args = [
+ # As the library needs to provide both 32-bit and 64-bit versions
+ # of file operations, disable transparent large file support (fixes
+ # 'Error: symbol `open64/mmap64' is already defined' compile failure
+- # otherwise)
++ # otherwise).
++ #
++ # Also disable _TIME_BITS=64 since this is allowed only with
++ # _FILE_OFFSET_BITS=64, which is now 32.
+ '-U_FILE_OFFSET_BITS',
++ '-U_TIME_BITS',
+ '-D_FILE_OFFSET_BITS=32',
+ '-D_LARGEFILE64_SOURCE',
+ ]
+--
+2.34.1
+
diff --git a/meta-openembedded/meta-oe/recipes-multimedia/v4l2apps/v4l-utils_1.26.1.bb b/meta-openembedded/meta-oe/recipes-multimedia/v4l2apps/v4l-utils_1.26.1.bb
index 52759ef18e..97271908b5 100644
--- a/meta-openembedded/meta-oe/recipes-multimedia/v4l2apps/v4l-utils_1.26.1.bb
+++ b/meta-openembedded/meta-oe/recipes-multimedia/v4l2apps/v4l-utils_1.26.1.bb
@@ -13,10 +13,6 @@ DEPENDS = "jpeg \
DEPENDS:append:libc-musl = " argp-standalone"
DEPENDS:append:class-target = " udev"
LDFLAGS:append = " -pthread"
-# v4l2 explicitly sets _FILE_OFFSET_BITS=32 to get access to
-# both 32 and 64 bit file APIs. But it does not handle the time side?
-# Needs further investigation
-GLIBC_64BIT_TIME_FLAGS = ""
inherit meson gettext pkgconfig
@@ -28,6 +24,8 @@ PACKAGECONFIG[v4l2-tracer] = ",-Dv4l2-tracer=disabled,json-c"
SRC_URI = "\
git://git.linuxtv.org/v4l-utils.git;protocol=https;branch=stable-1.26 \
file://0001-keytable-meson-Restrict-the-installation-of-50-rc_ke.patch \
+ file://0001-media-ctl-Install-media-ctl-header-and-library-files.patch \
+ file://0003-meson.build-fix-arm-_TIME_BITS-64-error.patch \
"
SRCREV = "4aee01a027923cab1e40969f56f8ba58d3e6c0d1"
diff --git a/meta-openembedded/meta-oe/recipes-multimedia/xsp/xsp_1.0.0-8.bb b/meta-openembedded/meta-oe/recipes-multimedia/xsp/xsp_1.0.0-8.bb
index c611da48c0..32f7bae0dc 100644
--- a/meta-openembedded/meta-oe/recipes-multimedia/xsp/xsp_1.0.0-8.bb
+++ b/meta-openembedded/meta-oe/recipes-multimedia/xsp/xsp_1.0.0-8.bb
@@ -13,3 +13,5 @@ REQUIRED_DISTRO_FEATURES = "x11"
SRC_URI[md5sum] = "2a0d8d02228d4cbd28b6e07bb7c17cf5"
SRC_URI[sha256sum] = "8b722b952b64841d996c70c3278499886c81bb5012991beed5f66f4158418f59"
+
+CVE_STATUS[CVE-2006-2658] = "cpe-incorrect: The recipe used in the `meta-openembedded` is a different xsp package compared to the one which has the CVE issue."
diff --git a/meta-openembedded/meta-oe/recipes-printing/cups/libcupsfilters/0001-CVE-2024-47076.patch b/meta-openembedded/meta-oe/recipes-printing/cups/libcupsfilters/0001-CVE-2024-47076.patch
new file mode 100644
index 0000000000..5fdf2bd444
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-printing/cups/libcupsfilters/0001-CVE-2024-47076.patch
@@ -0,0 +1,38 @@
+From 5f950f6a52c7453d76fb30dbc8d66bbc1cc682a3 Mon Sep 17 00:00:00 2001
+From: Zdenek Dohnal <zdohnal@redhat.com>
+Date: Thu, 26 Sep 2024 23:09:29 +0200
+Subject: [PATCH] CVE-2024-47076
+
+cfGetPrinterAttributes5(): Validate response attributes before return
+
+The destination can be corrupted or forged, so validate the response
+to strenghten security measures.
+
+CVE: CVE-2024-47076
+Upstream-Status: Backport [https://github.com/OpenPrinting/libcupsfilters/commit/95576ec3d20c109332d14672a807353cdc551018]
+
+(cherry picked from commit 95576ec3d20c109332d14672a807353cdc551018)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ cupsfilters/ipp.c | 8 ++++++++
+ 1 file changed, 8 insertions(+)
+
+diff --git a/cupsfilters/ipp.c b/cupsfilters/ipp.c
+index a0814ae5..994c8dac 100644
+--- a/cupsfilters/ipp.c
++++ b/cupsfilters/ipp.c
+@@ -452,6 +452,14 @@ cfGetPrinterAttributes5(http_t *http_printer,
+ ippDelete(response2);
+ }
+ }
++
++ // Check if the response is valid
++ if (!ippValidateAttributes(response))
++ {
++ ippDelete(response);
++ response = NULL;
++ }
++
+ if (have_http == 0) httpClose(http_printer);
+ if (uri) free(uri);
+ return (response);
diff --git a/meta-openembedded/meta-oe/recipes-printing/cups/libcupsfilters_2.0.0.bb b/meta-openembedded/meta-oe/recipes-printing/cups/libcupsfilters_2.0.0.bb
index 7f7174d940..827172a6a1 100644
--- a/meta-openembedded/meta-oe/recipes-printing/cups/libcupsfilters_2.0.0.bb
+++ b/meta-openembedded/meta-oe/recipes-printing/cups/libcupsfilters_2.0.0.bb
@@ -8,6 +8,7 @@ DEPENDS = "cups fontconfig libexif dbus lcms qpdf poppler libpng jpeg tiff"
SRC_URI = " \
https://github.com/OpenPrinting/${BPN}/releases/download/${PV}/${BP}.tar.xz \
file://0001-use-noexcept-false-instead-of-throw-from-c-17-onward.patch \
+ file://0001-CVE-2024-47076.patch \
"
SRC_URI[sha256sum] = "542f2bfbc58136a4743c11dc8c86cee03c9aca705612654e36ac34aa0d9aa601"
diff --git a/meta-openembedded/meta-oe/recipes-printing/cups/libppd/0001-CVE-2024-47175.patch b/meta-openembedded/meta-oe/recipes-printing/cups/libppd/0001-CVE-2024-47175.patch
new file mode 100644
index 0000000000..ba9cc683af
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-printing/cups/libppd/0001-CVE-2024-47175.patch
@@ -0,0 +1,600 @@
+From 67a96c1e81bf219a5eefb81b513cf1f44d1a3700 Mon Sep 17 00:00:00 2001
+From: Zdenek Dohnal <zdohnal@redhat.com>
+Date: Thu, 26 Sep 2024 23:12:14 +0200
+Subject: [PATCH] CVE-2024-47175
+
+Prevent PPD generation based on invalid IPP response
+
+Author: Mike Sweet
+Minor fixes: Zdenek Dohnal
+
+CVE: CVE-2024-47175
+Upstream-Status: Backport [https://github.com/OpenPrinting/libppd/commit/d681747ebf12602cb426725eb8ce2753211e2477]
+
+(cherry picked from commit d681747ebf12602cb426725eb8ce2753211e2477)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ ppd/ppd-cache.c | 17 ++-
+ ppd/ppd-generator.c | 257 ++++++++++++++++++++++++++++----------------
+ 2 files changed, 176 insertions(+), 98 deletions(-)
+
+diff --git a/ppd/ppd-cache.c b/ppd/ppd-cache.c
+index 5aa617c1..747c9ad5 100644
+--- a/ppd/ppd-cache.c
++++ b/ppd/ppd-cache.c
+@@ -1,6 +1,7 @@
+ //
+ // PPD cache implementation for libppd.
+ //
++// Copyright © 2024 by OpenPrinting
+ // Copyright © 2010-2019 by Apple Inc.
+ //
+ // Licensed under Apache License v2.0. See the file "LICENSE" for more
+@@ -3413,7 +3414,7 @@ ppdCacheGetBin(
+
+ //
+ // Range check input...
+-
++
+
+ if (!pc || !output_bin)
+ return (NULL);
+@@ -3914,7 +3915,7 @@ ppdCacheGetPageSize(
+ {
+ //
+ // Check not only the base size (like "A4") but also variants (like
+- // "A4.Borderless"). We check only the margins and orientation but do
++ // "A4.Borderless"). We check only the margins and orientation but do
+ // not re-check the size.
+ //
+
+@@ -4711,7 +4712,7 @@ ppdPwgPpdizeName(const char *ipp, // I - IPP keyword
+ *end; // End of name buffer
+
+
+- if (!ipp)
++ if (!ipp || !_ppd_isalnum(*ipp))
+ {
+ *name = '\0';
+ return;
+@@ -4721,13 +4722,19 @@ ppdPwgPpdizeName(const char *ipp, // I - IPP keyword
+
+ for (ptr = name + 1, end = name + namesize - 1; *ipp && ptr < end;)
+ {
+- if (*ipp == '-' && _ppd_isalnum(ipp[1]))
++ if (*ipp == '-' && isalnum(ipp[1]))
+ {
+ ipp ++;
+ *ptr++ = (char)toupper(*ipp++ & 255);
+ }
+- else
++ else if (*ipp == '_' || *ipp == '.' || *ipp == '-' || isalnum(*ipp))
++ {
+ *ptr++ = *ipp++;
++ }
++ else
++ {
++ ipp ++;
++ }
+ }
+
+ *ptr = '\0';
+diff --git a/ppd/ppd-generator.c b/ppd/ppd-generator.c
+index a815030b..011e086e 100644
+--- a/ppd/ppd-generator.c
++++ b/ppd/ppd-generator.c
+@@ -1,15 +1,16 @@
+ //
+ // PWG Raster/Apple Raster/PCLm/PDF/IPP legacy PPD generator for libppd.
+ //
+-// Copyright 2016-2019 by Till Kamppeter.
+-// Copyright 2017-2019 by Sahil Arora.
+-// Copyright 2018-2019 by Deepak Patankar.
++// Copyright © 2024 by OpenPrinting
++// Copyright © 2016-2019 by Till Kamppeter.
++// Copyright © 2017-2019 by Sahil Arora.
++// Copyright © 2018-2019 by Deepak Patankar.
+ //
+ // The PPD generator is based on the PPD generator for the CUPS
+ // "lpadmin -m everywhere" functionality in the cups/ppd-cache.c
+ // file. The copyright of this file is:
+ //
+-// Copyright 2010-2016 by Apple Inc.
++// Copyright © 2010-2016 by Apple Inc.
+ //
+ // Licensed under Apache License v2.0. See the file "LICENSE" for more
+ // information.
+@@ -51,6 +52,7 @@
+
+ static int http_connect(http_t **http, const char *url, char *resource,
+ size_t ressize);
++static void ppd_put_string(cups_file_t *fp, cups_lang_t *lang, const char *ppd_option, const char *ppd_choice, const char *pwg_msgid);
+
+
+ //
+@@ -60,7 +62,7 @@ static int http_connect(http_t **http, const char *url, char *resource,
+ // than CUPS 2.2.x. We have also an additional test and development
+ // platform for this code. Taken from cups/ppd-cache.c,
+ // cups/string-private.h, cups/string.c.
+-//
++//
+ // The advantage of PPD generation instead of working with System V
+ // interface scripts is that the print dialogs of the clients do not
+ // need to ask the printer for its options via IPP. So we have access
+@@ -124,7 +126,7 @@ char ppdgenerator_msg[1024];
+ // IPP 1.x legacy)
+ //
+
+-char * // O - PPD filename or NULL
++char * // O - PPD filename or NULL
+ // on error
+ ppdCreatePPDFromIPP(char *buffer, // I - Filename buffer
+ size_t bufsize, // I - Size of filename
+@@ -175,7 +177,7 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ cups_array_t *conflicts, // I - Array of
+ // constraints
+ cups_array_t *sizes, // I - Media sizes we've
+- // added
++ // added
+ char* default_pagesize, // I - Default page size
+ const char *default_cluster_color, // I - cluster def
+ // color (if cluster's
+@@ -187,6 +189,7 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ size_t status_msg_size) // I - Size of status
+ // message buffer
+ {
++ cups_lang_t *lang; // Localization language
+ cups_file_t *fp; // PPD file
+ cups_array_t *printer_sizes; // Media sizes we've added
+ cups_size_t *size; // Current media size
+@@ -199,9 +202,10 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ ipp_t *media_col, // Media collection
+ *media_size; // Media size collection
+ char make[256], // Make and model
+- *model, // Model name
++ *mptr, // Pointer into make and model
+ ppdname[PPD_MAX_NAME];
+ // PPD keyword
++ const char *model; // Model name
+ int i, j, // Looping vars
+ count = 0, // Number of values
+ bottom, // Largest bottom margin
+@@ -283,6 +287,68 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ return (NULL);
+ }
+
++ //
++ // Get a sanitized make and model...
++ //
++
++ if ((attr = ippFindAttribute(supported, "printer-make-and-model", IPP_TAG_TEXT)) != NULL && ippValidateAttribute(attr))
++ {
++ // Sanitize the model name to only contain PPD-safe characters.
++ strlcpy(make, ippGetString(attr, 0, NULL), sizeof(make));
++
++ for (mptr = make; *mptr; mptr ++)
++ {
++ if (*mptr < ' ' || *mptr >= 127 || *mptr == '\"')
++ {
++ // Truncate the make and model on the first bad character...
++ *mptr = '\0';
++ break;
++ }
++ }
++
++ while (mptr > make)
++ {
++ // Strip trailing whitespace...
++ mptr --;
++ if (*mptr == ' ')
++ *mptr = '\0';
++ }
++
++ if (!make[0])
++ {
++ // Use a default make and model if nothing remains...
++ strlcpy(make, "Unknown", sizeof(make));
++ }
++ }
++ else
++ {
++ // Use a default make and model...
++ strlcpy(make, "Unknown", sizeof(make));
++ }
++
++ if (!strncasecmp(make, "Hewlett Packard ", 16) || !strncasecmp(make, "Hewlett-Packard ", 16))
++ {
++ // Normalize HP printer make and model...
++ model = make + 16;
++ strlcpy(make, "HP", sizeof(make));
++
++ if (!strncasecmp(model, "HP ", 3))
++ model += 3;
++ }
++ else if ((mptr = strchr(make, ' ')) != NULL)
++ {
++ // Separate "MAKE MODEL"...
++ while (*mptr && *mptr == ' ')
++ *mptr++ = '\0';
++
++ model = mptr;
++ }
++ else
++ {
++ // No separate model name...
++ model = "Printer";
++ }
++
+ //
+ // Standard stuff for PPD file...
+ //
+@@ -311,25 +377,6 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ }
+ }
+
+- if ((attr = ippFindAttribute(supported, "printer-make-and-model",
+- IPP_TAG_TEXT)) != NULL)
+- strlcpy(make, ippGetString(attr, 0, NULL), sizeof(make));
+- else if (make_model && make_model[0] != '\0')
+- strlcpy(make, make_model, sizeof(make));
+- else
+- strlcpy(make, "Unknown Printer", sizeof(make));
+-
+- if (!strncasecmp(make, "Hewlett Packard ", 16) ||
+- !strncasecmp(make, "Hewlett-Packard ", 16))
+- {
+- model = make + 16;
+- strlcpy(make, "HP", sizeof(make));
+- }
+- else if ((model = strchr(make, ' ')) != NULL)
+- *model++ = '\0';
+- else
+- model = make;
+-
+ cupsFilePrintf(fp, "*Manufacturer: \"%s\"\n", make);
+ cupsFilePrintf(fp, "*ModelName: \"%s %s\"\n", make, model);
+ cupsFilePrintf(fp, "*Product: \"(%s %s)\"\n", make, model);
+@@ -425,21 +472,19 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ }
+ cupsFilePuts(fp, "\"\n");
+
+- if ((attr = ippFindAttribute(supported, "printer-more-info", IPP_TAG_URI)) !=
+- NULL)
++ if ((attr = ippFindAttribute(supported, "printer-more-info", IPP_TAG_URI)) != NULL && ippValidateAttribute(attr))
+ cupsFilePrintf(fp, "*APSupplies: \"%s\"\n", ippGetString(attr, 0, NULL));
+
+- if ((attr = ippFindAttribute(supported, "printer-charge-info-uri",
+- IPP_TAG_URI)) != NULL)
+- cupsFilePrintf(fp, "*cupsChargeInfoURI: \"%s\"\n", ippGetString(attr, 0,
+- NULL));
++ if ((attr = ippFindAttribute(supported, "printer-charge-info-uri", IPP_TAG_URI)) != NULL && ippValidateAttribute(attr))
++ cupsFilePrintf(fp, "*cupsChargeInfoURI: \"%s\"\n", ippGetString(attr, 0, NULL));
+
+ // Message catalogs for UI strings
++ lang = cupsLangDefault();
+ opt_strings_catalog = cfCatalogOptionArrayNew();
+ cfCatalogLoad(NULL, NULL, opt_strings_catalog);
+
+ if ((attr = ippFindAttribute(supported, "printer-strings-uri",
+- IPP_TAG_URI)) != NULL)
++ IPP_TAG_URI)) != NULL && ippValidateAttribute(attr))
+ {
+ printer_opt_strings_catalog = cfCatalogOptionArrayNew();
+ cfCatalogLoad(ippGetString(attr, 0, NULL), NULL,
+@@ -492,7 +537,7 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ response = cupsDoRequest(http, request, resource);
+
+ if ((attr = ippFindAttribute(response, "printer-strings-uri",
+- IPP_TAG_URI)) != NULL)
++ IPP_TAG_URI)) != NULL && ippValidateAttribute(attr))
+ cupsFilePrintf(fp, "*cupsStringsURI %s: \"%s\"\n", keyword,
+ ippGetString(attr, 0, NULL));
+
+@@ -518,13 +563,10 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ IPP_TAG_BOOLEAN), 0))
+ cupsFilePuts(fp, "*cupsJobAccountingUserId: True\n");
+
+- if ((attr = ippFindAttribute(supported, "printer-privacy-policy-uri",
+- IPP_TAG_URI)) != NULL)
+- cupsFilePrintf(fp, "*cupsPrivacyURI: \"%s\"\n",
+- ippGetString(attr, 0, NULL));
++ if ((attr = ippFindAttribute(supported, "printer-privacy-policy-uri", IPP_TAG_URI)) != NULL && ippValidateAttribute(attr))
++ cupsFilePrintf(fp, "*cupsPrivacyURI: \"%s\"\n", ippGetString(attr, 0, NULL));
+
+- if ((attr = ippFindAttribute(supported, "printer-mandatory-job-attributes",
+- IPP_TAG_KEYWORD)) != NULL)
++ if ((attr = ippFindAttribute(supported, "printer-mandatory-job-attributes", IPP_TAG_KEYWORD)) != NULL && ippValidateAttribute(attr))
+ {
+ char prefix = '\"'; // Prefix for string
+
+@@ -544,8 +586,7 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ cupsFilePuts(fp, "\"\n");
+ }
+
+- if ((attr = ippFindAttribute(supported, "printer-requested-job-attributes",
+- IPP_TAG_KEYWORD)) != NULL)
++ if ((attr = ippFindAttribute(supported, "printer-requested-job-attributes", IPP_TAG_KEYWORD)) != NULL && ippValidateAttribute(attr))
+ {
+ char prefix = '\"'; // Prefix for string
+
+@@ -664,7 +705,7 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ }
+
+ //
+- // Fax
++ // Fax
+ //
+
+ if (is_fax)
+@@ -705,21 +746,21 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ #ifdef CUPS_RASTER_HAVE_APPLERASTER
+ else if (cupsArrayFind(pdl_list, "image/urf"))
+ {
+- int resStore = 0; // Variable for storing the no. of resolutions in the resolution array
++ int resStore = 0; // Variable for storing the no. of resolutions in the resolution array
+ int resArray[__INT16_MAX__]; // Creating a resolution array supporting a maximum of 32767 resolutions.
+ int lowdpi = 0, middpi = 0, hidpi = 0; // Lower , middle and higher resolution
+ if ((attr = ippFindAttribute(supported, "urf-supported",
+ IPP_TAG_KEYWORD)) != NULL)
+ {
+ for (int i = 0, count = ippGetCount(attr); i < count; i ++)
+- {
++ {
+ const char *rs = ippGetString(attr, i, NULL); // RS values
+- const char *rsCopy = ippGetString(attr, i, NULL); // RS values(copy)
++ const char *rsCopy = ippGetString(attr, i, NULL); // RS values(copy)
+ if (strncasecmp(rs, "RS", 2)) // Comparing attributes to have RS in
+ // the beginning to indicate the
+ // resolution feature
+ continue;
+- int resCount = 0; // Using a count variable which can be reset
++ int resCount = 0; // Using a count variable which can be reset
+ while (*rsCopy != '\0') // Parsing through the copy pointer to
+ // determine the no. of resolutions
+ {
+@@ -817,7 +858,7 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ formatfound = 1;
+ is_apple = 1;
+ }
+- }
++ }
+ }
+ }
+ }
+@@ -909,7 +950,7 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ if (manual_copies == 1)
+ cupsFilePuts(fp, "*cupsManualCopies: True\n");
+
+- // No resolution requirements by any of the supported PDLs?
++ // No resolution requirements by any of the supported PDLs?
+ // Use "printer-resolution-supported" attribute
+ if (common_res == NULL)
+ {
+@@ -1027,7 +1068,7 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ //
+ // PageSize/PageRegion/ImageableArea/PaperDimension
+ //
+-
++
+ cfGenerateSizes(supported, CF_GEN_SIZES_DEFAULT, &printer_sizes, &defattr,
+ NULL, NULL, NULL, NULL, NULL, NULL,
+ &min_width, &min_length,
+@@ -1406,15 +1447,15 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ if (!strcmp(sources[j], keyword))
+ break;
+ if (j >= 0)
+- cupsFilePrintf(fp, "*InputSlot %s%s%s: \"<</MediaPosition %d>>setpagedevice\"\n",
+- ppdname,
+- (human_readable ? "/" : ""),
+- (human_readable ? human_readable : ""), j);
++ {
++ cupsFilePrintf(fp, "*InputSlot %s: \"<</MediaPosition %d>>setpagedevice\"\n", ppdname, j);
++ ppd_put_string(fp, lang, "InputSlot", ppdname, human_readable);
++ }
+ else
+- cupsFilePrintf(fp, "*InputSlot %s%s%s: \"\"\n",
+- ppdname,
+- (human_readable ? "/" : ""),
+- (human_readable ? human_readable : ""));
++ {
++ cupsFilePrintf(fp, "*InputSlot %s%s%s:\"\"\n", ppdname, human_readable ? "/" : "", human_readable ? human_readable : "");
++ ppd_put_string(fp, lang, "InputSlot", ppdname, human_readable);
++ }
+ }
+ cupsFilePuts(fp, "*CloseUI: *InputSlot\n");
+ }
+@@ -1449,11 +1490,8 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ human_readable = cfCatalogLookUpChoice((char *)keyword, "media-type",
+ opt_strings_catalog,
+ printer_opt_strings_catalog);
+- cupsFilePrintf(fp, "*MediaType %s%s%s: \"<</MediaType(%s)>>setpagedevice\"\n",
+- ppdname,
+- (human_readable ? "/" : ""),
+- (human_readable ? human_readable : ""),
+- ppdname);
++ cupsFilePrintf(fp, "*MediaType %s: \"<</MediaType(%s)>>setpagedevice\"\n", ppdname, ppdname);
++ ppd_put_string(fp, lang, "MediaType", ppdname, human_readable);
+ }
+ cupsFilePuts(fp, "*CloseUI: *MediaType\n");
+ }
+@@ -1776,10 +1814,8 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ human_readable = cfCatalogLookUpChoice((char *)keyword, "output-bin",
+ opt_strings_catalog,
+ printer_opt_strings_catalog);
+- cupsFilePrintf(fp, "*OutputBin %s%s%s: \"\"\n",
+- ppdname,
+- (human_readable ? "/" : ""),
+- (human_readable ? human_readable : ""));
++ cupsFilePrintf(fp, "*OutputBin %s: \"\"\n", ppdname);
++ ppd_put_string(fp, lang, "OutputBin", ppdname, human_readable);
+ outputorderinfofound = 0;
+ faceupdown = 1;
+ firsttolast = 1;
+@@ -1833,7 +1869,7 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+
+ //
+ // Finishing options...
+- //
++ //
+
+ if ((attr = ippFindAttribute(supported, "finishings-supported",
+ IPP_TAG_ENUM)) != NULL)
+@@ -1958,9 +1994,8 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ human_readable = cfCatalogLookUpChoice(buf, "finishings",
+ opt_strings_catalog,
+ printer_opt_strings_catalog);
+- cupsFilePrintf(fp, "*StapleLocation %s%s%s: \"\"\n", ppd_keyword,
+- (human_readable ? "/" : ""),
+- (human_readable ? human_readable : ""));
++ cupsFilePrintf(fp, "*StapleLocation %s: \"\"\n", ppd_keyword);
++ ppd_put_string(fp, lang, "StapleLocation", ppd_keyword, human_readable);
+ cupsFilePrintf(fp, "*cupsIPPFinishings %d/%s: \"*StapleLocation %s\"\n",
+ value, keyword, ppd_keyword);
+ }
+@@ -2050,9 +2085,8 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ human_readable = cfCatalogLookUpChoice(buf, "finishings",
+ opt_strings_catalog,
+ printer_opt_strings_catalog);
+- cupsFilePrintf(fp, "*FoldType %s%s%s: \"\"\n", ppd_keyword,
+- (human_readable ? "/" : ""),
+- (human_readable ? human_readable : ""));
++ cupsFilePrintf(fp, "*FoldType %s: \"\"\n", ppd_keyword);
++ ppd_put_string(fp, lang, "FoldType", ppd_keyword, human_readable);
+ cupsFilePrintf(fp, "*cupsIPPFinishings %d/%s: \"*FoldType %s\"\n",
+ value, keyword, ppd_keyword);
+ }
+@@ -2149,9 +2183,8 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ human_readable = cfCatalogLookUpChoice(buf, "finishings",
+ opt_strings_catalog,
+ printer_opt_strings_catalog);
+- cupsFilePrintf(fp, "*PunchMedia %s%s%s: \"\"\n", ppd_keyword,
+- (human_readable ? "/" : ""),
+- (human_readable ? human_readable : ""));
++ cupsFilePrintf(fp, "*PunchMedia %s: \"\"\n", ppd_keyword);
++ ppd_put_string(fp, lang, "PunchMedia", ppd_keyword, human_readable);
+ cupsFilePrintf(fp, "*cupsIPPFinishings %d/%s: \"*PunchMedia %s\"\n",
+ value, keyword, ppd_keyword);
+ }
+@@ -2242,9 +2275,8 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ human_readable = cfCatalogLookUpChoice(buf, "finishings",
+ opt_strings_catalog,
+ printer_opt_strings_catalog);
+- cupsFilePrintf(fp, "*CutMedia %s%s%s: \"\"\n", ppd_keyword,
+- (human_readable ? "/" : ""),
+- (human_readable ? human_readable : ""));
++ cupsFilePrintf(fp, "*CutMedia %s: \"\"\n", ppd_keyword);
++ ppd_put_string(fp, lang, "CutMedia", ppd_keyword, human_readable);
+ cupsFilePrintf(fp, "*cupsIPPFinishings %d/%s: \"*CutMedia %s\"\n",
+ value, keyword, ppd_keyword);
+ }
+@@ -2268,7 +2300,7 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ cupsFilePrintf(fp, "*OpenUI *cupsFinishingTemplate/%s: PickOne\n",
+ (human_readable ? human_readable : "Finishing Template"));
+ cupsFilePuts(fp, "*OrderDependency: 10 AnySetup *cupsFinishingTemplate\n");
+- cupsFilePuts(fp, "*DefaultcupsFinishingTemplate: none\n");
++ cupsFilePuts(fp, "*DefaultcupsFinishingTemplate: None\n");
+ human_readable = cfCatalogLookUpChoice("3", "finishings",
+ opt_strings_catalog,
+ printer_opt_strings_catalog);
+@@ -2299,8 +2331,9 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ printer_opt_strings_catalog);
+ if (human_readable == NULL)
+ human_readable = (char *)keyword;
+- cupsFilePrintf(fp, "*cupsFinishingTemplate %s/%s: \"\n", keyword,
+- human_readable);
++ ppdPwgPpdizeName(keyword, ppdname, sizeof(ppdname));
++ cupsFilePrintf(fp, "*cupsFinishingTemplate %s: \"\n", ppdname);
++ ppd_put_string(fp, lang, "cupsFinishingTemplate", ppdname, human_readable);
+ for (finishing_attr = ippFirstAttribute(finishing_col); finishing_attr;
+ finishing_attr = ippNextAttribute(finishing_col)) {
+ if (ippGetValueTag(finishing_attr) == IPP_TAG_BEGIN_COLLECTION) {
+@@ -2564,14 +2597,14 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ if (!preset || !preset_name)
+ continue;
+
+- if ((localized_name =
++ ppdPwgPpdizeName(preset_name, ppdname, sizeof(ppdname));
++
++ localized_name =
+ cfCatalogLookUpOption((char *)preset_name,
+ opt_strings_catalog,
+- printer_opt_strings_catalog)) == NULL)
+- cupsFilePrintf(fp, "*APPrinterPreset %s: \"\n", preset_name);
+- else
+- cupsFilePrintf(fp, "*APPrinterPreset %s/%s: \"\n", preset_name,
+- localized_name);
++ printer_opt_strings_catalog);
++ cupsFilePrintf(fp, "*APPrinterPreset %s: \"\n", ppdname);
++ ppd_put_string(fp, lang, "APPrinterPreset", ppdname, localized_name);
+
+ for (member = ippFirstAttribute(preset); member;
+ member = ippNextAttribute(preset))
+@@ -2620,7 +2653,10 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ ippGetString(ippFindAttribute(fin_col,
+ "finishing-template",
+ IPP_TAG_ZERO), 0, NULL)) != NULL)
+- cupsFilePrintf(fp, "*cupsFinishingTemplate %s\n", keyword);
++ {
++ ppdPwgPpdizeName(keyword, ppdname, sizeof(ppdname));
++ cupsFilePrintf(fp, "*cupsFinishingTemplate %s\n", ppdname);
++ }
+ }
+ }
+ else if (!strcmp(member_name, "media"))
+@@ -2659,7 +2695,7 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ NULL)) != NULL)
+ {
+ ppdPwgPpdizeName(keyword, ppdname, sizeof(ppdname));
+- cupsFilePrintf(fp, "*InputSlot %s\n", keyword);
++ cupsFilePrintf(fp, "*InputSlot %s\n", ppdname);
+ }
+
+ if ((keyword = ippGetString(ippFindAttribute(media_col, "media-type",
+@@ -2667,7 +2703,7 @@ ppdCreatePPDFromIPP2(char *buffer, // I - Filename buffer
+ NULL)) != NULL)
+ {
+ ppdPwgPpdizeName(keyword, ppdname, sizeof(ppdname));
+- cupsFilePrintf(fp, "*MediaType %s\n", keyword);
++ cupsFilePrintf(fp, "*MediaType %s\n", ppdname);
+ }
+ }
+ else if (!strcmp(member_name, "print-quality"))
+@@ -2817,3 +2853,38 @@ http_connect(http_t **http, // IO - Current HTTP connection
+
+ return (*http != NULL);
+ }
++
++
++/*
++ * 'ppd_put_strings()' - Write localization attributes to a PPD file.
++ */
++
++static void
++ppd_put_string(cups_file_t *fp, /* I - PPD file */
++ cups_lang_t *lang, /* I - Language */
++ const char *ppd_option,/* I - PPD option */
++ const char *ppd_choice,/* I - PPD choice */
++ const char *text) /* I - Localized text */
++{
++ if (!text)
++ return;
++
++ // Add the first line of localized text...
++#if CUPS_VERSION_MAJOR > 2
++ cupsFilePrintf(fp, "*%s.%s %s/", cupsLangGetName(lang), ppd_option, ppd_choice);
++#else
++ cupsFilePrintf(fp, "*%s.%s %s/", lang->language, ppd_option, ppd_choice);
++#endif // CUPS_VERSION_MAJOR > 2
++
++ while (*text && *text != '\n')
++ {
++ // Escape ":" and "<"...
++ if (*text == ':' || *text == '<')
++ cupsFilePrintf(fp, "<%02X>", *text);
++ else
++ cupsFilePutChar(fp, *text);
++
++ text ++;
++ }
++ cupsFilePuts(fp, ": \"\"\n");
++}
diff --git a/meta-openembedded/meta-oe/recipes-printing/cups/libppd_2.0.0.bb b/meta-openembedded/meta-oe/recipes-printing/cups/libppd_2.0.0.bb
index 99b1f6e730..f1cf25901e 100644
--- a/meta-openembedded/meta-oe/recipes-printing/cups/libppd_2.0.0.bb
+++ b/meta-openembedded/meta-oe/recipes-printing/cups/libppd_2.0.0.bb
@@ -5,7 +5,10 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=c1fca671047153ce6825c4ab06f2ab49"
DEPENDS = "libcupsfilters"
-SRC_URI = "https://github.com/OpenPrinting/${BPN}/releases/download/${PV}/${BP}.tar.xz"
+SRC_URI = " \
+ https://github.com/OpenPrinting/${BPN}/releases/download/${PV}/${BP}.tar.xz \
+ file://0001-CVE-2024-47175.patch \
+"
SRC_URI[sha256sum] = "882d3c659a336e91559de8f3c76fc26197fe6e5539d9b484a596e29a5a4e0bc8"
inherit autotools gettext pkgconfig github-releases
diff --git a/meta-openembedded/meta-oe/recipes-printing/gutenprint/gutenprint/0001-cups-fix-a-build-race-condition-around-empty-directo.patch b/meta-openembedded/meta-oe/recipes-printing/gutenprint/gutenprint/0001-cups-fix-a-build-race-condition-around-empty-directo.patch
new file mode 100644
index 0000000000..758acfe6be
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-printing/gutenprint/gutenprint/0001-cups-fix-a-build-race-condition-around-empty-directo.patch
@@ -0,0 +1,60 @@
+From e3b0952fe936f90cfda9cbed368fae2143b72089 Mon Sep 17 00:00:00 2001
+From: Yoann Congal <yoann.congal@smile.fr>
+Date: Thu, 3 Jul 2025 15:27:04 +0200
+Subject: [PATCH] cups: fix a build race-condition around empty directories
+ removal
+
+In automake, install-exec and install-data happen in parallel.
+install-exec installs executables and install-data finishes with
+install-data-hook that removes empty directories. If install-data-hook
+happen before install-exec finishes, it might remove a directory while
+it is used by the install process and make it fail.
+
+Fix this by adding an explicit dependency between install-data-hook and
+install-exec.
+
+For example, here is the log of such a failure:
+| make install-data-hook
+| hosttools/mkdir -p 'image/usr/libexec/cups/backend'
+| make[5]: Entering directory '$WORKDIR/build/src/cups'
+| Expect a number of "rmdir: Directory not empty" warnings
+| /bin/bash ../../libtool --mode=install $HOSTTOOLS/install -c backend_gutenprint '$WORKDIR/image/usr/libexec/cups/backend'
+ # Start of the install process (from install-exec)
+| These messages are harmless and should be ignored.
+...
+| rmdir $WORKDIR/image/usr/libexec/cups/backend
+ # empty /usr/libexec/cups/backend is removed (from install-data-hook)
+...
+| libtool: install: $HOSTTOOLS/install -c backend_gutenprint $WORKDIR/image/usr/libexec/cups/backend
+ # install in a non-existing directory: backend_gutenprint is installed
+ # as /usr/libexec/cups/backend (this is now a file instead of a
+ # directory)
+| make install-exec-hook
+| make[5]: Entering directory '$WORKDIR/build/src/cups'
+| chmod 700 $WORKDIR/image/usr/libexec/cups/backend/backend_gutenprint
+| chmod: cannot access '$WORKDIR/image/usr/libexec/cups/backend/backend_gutenprint': Not a directory
+ # chmod fails because /usr/libexec/cups/backend is a file and not a
+ # directory
+| make[5]: *** [Makefile:2166: install-exec-hook] Error 1
+
+Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
+Upstream-Status: Submitted [https://sourceforge.net/p/gimp-print/mailman/gimp-print-devel/thread/20250703164244.1120340-1-yoann.congal%40smile.fr/#msg59202153]
+---
+ src/cups/Makefile.am | 3 ++-
+ 1 file changed, 2 insertions(+), 1 deletion(-)
+
+diff --git a/src/cups/Makefile.am b/src/cups/Makefile.am
+index 7928ee3..fe45c92 100644
+--- a/src/cups/Makefile.am
++++ b/src/cups/Makefile.am
+@@ -206,8 +206,9 @@ uninstall-local: $(INSTALL_DATA_LOCAL_DEPS) $(INSTALL_BLACKLIST)
+ $(RM) -f "$(DESTDIR)$(cupsdata_blacklistdir)/net.sf.gimp-print.usb-quirks"
+ $(RM) -f "$(DESTDIR)$(pkglibdir)/backend/gutenprint$(GUTENPRINT_MAJOR_VERSION)$(GUTENPRINT_MINOR_VERSION)+usb"
+
+-install-data-hook:
++install-data-hook: install-exec
+ # Remove unused directories in install tree
++# Note: it removes "exec" directories, so it must happen after install-exec.
+ -@echo 'Expect a number of "rmdir: Directory not empty" warnings'
+ -@echo 'These messages are harmless and should be ignored.'
+ -rmdir $(DESTDIR)$(cups_modeldir)
diff --git a/meta-openembedded/meta-oe/recipes-printing/gutenprint/gutenprint_5.3.4.bb b/meta-openembedded/meta-oe/recipes-printing/gutenprint/gutenprint_5.3.5.bb
index 5263890239..82953b798c 100644
--- a/meta-openembedded/meta-oe/recipes-printing/gutenprint/gutenprint_5.3.4.bb
+++ b/meta-openembedded/meta-oe/recipes-printing/gutenprint/gutenprint_5.3.5.bb
@@ -14,8 +14,10 @@ HOMEPAGE = "http://gimp-print.sourceforge.net/"
LICENSE = "GPL-2.0-or-later"
LIC_FILES_CHKSUM = "file://COPYING;md5=59530bdf33659b29e73d4adb9f9f6552"
-SRC_URI = "https://downloads.sourceforge.net/gimp-print/${BP}.tar.xz"
-SRC_URI[sha256sum] = "db44a701d2b8e6a8931c83cec06c91226be266d23e5c189d20a39dd175f2023b"
+SRC_URI = "https://downloads.sourceforge.net/gimp-print/${BP}.tar.xz \
+ file://0001-cups-fix-a-build-race-condition-around-empty-directo.patch \
+ "
+SRC_URI[sha256sum] = "f5a9f47de28530b1ae2069cfbc647a9a641baeeabe809bb0ef2b3ec5b9668d70"
inherit autotools gettext pkgconfig
diff --git a/meta-openembedded/meta-oe/recipes-security/kernel-hardening-checker/files/0001-pyproject.toml-fix-up-license-information.patch b/meta-openembedded/meta-oe/recipes-security/kernel-hardening-checker/files/0001-pyproject.toml-fix-up-license-information.patch
new file mode 100644
index 0000000000..4460146722
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-security/kernel-hardening-checker/files/0001-pyproject.toml-fix-up-license-information.patch
@@ -0,0 +1,31 @@
+From e94c486c6c3473979ce5be627f030cc95ce165e6 Mon Sep 17 00:00:00 2001
+From: Michael Opdenacker <michael.opdenacker@rootcommit.com>
+Date: Sun, 17 Aug 2025 17:27:21 +0200
+Subject: [PATCH 1/2] pyproject.toml: fix up license information
+
+Without this change, the Python tooling complains that you
+can't have both "license" and "license-files" settings in pyproject.toml.
+
+This issue doesn't happen any more with the Python tooling
+in master (as of August 2025), so it's irrelevant for upstream.
+
+Signed-off-by: Michael Opdenacker <michael.opdenacker@rootcommit.com>
+Upstream-Status: Inappropriate [oe specific]
+---
+ pyproject.toml | 3 +--
+ 1 file changed, 1 insertion(+), 2 deletions(-)
+
+diff --git a/pyproject.toml b/pyproject.toml
+index a0b75c3..79e710b 100644
+--- a/pyproject.toml
++++ b/pyproject.toml
+@@ -20,8 +20,7 @@ authors = [
+ maintainers = [
+ {name = "Alexander Popov", email = "alex.popov@linux.com"}
+ ]
+-license = "GPL-3.0-only"
+-license-files = ["LICENSE.txt"]
++license = { text = "GPL-3.0-only" }
+ classifiers = [
+ "Development Status :: 5 - Production/Stable",
+ "Topic :: Security",
diff --git a/meta-openembedded/meta-oe/recipes-security/kernel-hardening-checker/files/0002-pyproject.toml-relax-setuptool-version-requirement.patch b/meta-openembedded/meta-oe/recipes-security/kernel-hardening-checker/files/0002-pyproject.toml-relax-setuptool-version-requirement.patch
new file mode 100644
index 0000000000..05a8126c4e
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-security/kernel-hardening-checker/files/0002-pyproject.toml-relax-setuptool-version-requirement.patch
@@ -0,0 +1,29 @@
+From 7c64511d2dcb58bc4d83dd41667c1f9295ca9712 Mon Sep 17 00:00:00 2001
+From: Michael Opdenacker <michael.opdenacker@rootcommit.com>
+Date: Tue, 19 Aug 2025 21:47:05 +0200
+Subject: [PATCH 2/2] pyproject.toml: relax setuptool version requirement
+
+To match with what's available in Scarthgap
+It turns out that setuptools 69 is sufficient for building this tool.
+The developer may have aligned the version with his testing environment.
+
+This patch is not needed on meta-openembedded master which has a recent enough
+version.
+
+Signed-off-by: Michael Opdenacker <michael.opdenacker@rootcommit.com>
+Upstream-Status: Inappropriate [oe specific]
+---
+ pyproject.toml | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/pyproject.toml b/pyproject.toml
+index 79e710b..a8b59d8 100644
+--- a/pyproject.toml
++++ b/pyproject.toml
+@@ -1,5 +1,5 @@
+ [build-system]
+-requires = ["setuptools >= 77.0.3"]
++requires = ["setuptools >= 69"]
+ build-backend = "setuptools.build_meta"
+
+ [tool.setuptools.packages.find]
diff --git a/meta-openembedded/meta-oe/recipes-security/kernel-hardening-checker/kernel-hardening-checker_0.6.10.2.bb b/meta-openembedded/meta-oe/recipes-security/kernel-hardening-checker/kernel-hardening-checker_0.6.10.2.bb
new file mode 100644
index 0000000000..c0ae0f0d3c
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-security/kernel-hardening-checker/kernel-hardening-checker_0.6.10.2.bb
@@ -0,0 +1,41 @@
+SUMMARY = "A tool for checking the security hardening options of the Linux kernel"
+DESCRIPTION = "\
+ There are plenty of security hardening options for the Linux kernel; Kconfig \
+ options (compile-time); Kernel cmdline arguments (boot-time); Sysctl \
+ parameters (runtime). A lot of them have to be enabled manually to make the \
+ system more secure which is difficult to track. This tool helps with this \
+ task by checking and reporting about the settings compared to a list of \
+ recommendation. \
+"
+HOMEPAGE = "https://github.com/a13xp0p0v/kernel-hardening-checker"
+BUGTRACKER = "https://github.com/a13xp0p0v/kernel-hardening-checker/issues"
+LICENSE = "GPL-3.0-only"
+LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=d32239bcb673463ab874e80d47fae504"
+
+SRC_URI = "git://github.com/a13xp0p0v/kernel-hardening-checker;protocol=https;branch=master \
+ file://0001-pyproject.toml-fix-up-license-information.patch \
+ file://0002-pyproject.toml-relax-setuptool-version-requirement.patch"
+
+SRCREV = "0ebece346f187e7d3589883cc1d194fcd1c3cda8"
+
+S = "${WORKDIR}/git"
+
+PACKAGE_ARCH = "${MACHINE_ARCH}"
+
+RDEPENDS:${PN} = "\
+ python3-json \
+ python3-misc \
+ python3-compression \
+ bash \
+"
+
+# /boot/config is required for the analysis
+RRECOMMENDS:${PN}:class-target = "\
+ kernel-dev \
+"
+
+inherit python_setuptools_build_meta
+
+# allow to run on build host, if you don't want it in the image
+# oe-run-native kernel-hardening-checker-native kernel-hardening-checker ...
+BBCLASSEXTEND = "native"
diff --git a/meta-openembedded/meta-oe/recipes-security/softhsm/softhsm_2.6.1.bb b/meta-openembedded/meta-oe/recipes-security/softhsm/softhsm_2.6.1.bb
index 930bca96ff..12c6947a21 100644
--- a/meta-openembedded/meta-oe/recipes-security/softhsm/softhsm_2.6.1.bb
+++ b/meta-openembedded/meta-oe/recipes-security/softhsm/softhsm_2.6.1.bb
@@ -5,7 +5,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=ef3f77a3507c3d91e75b9f2bdaee4210"
DEPENDS = "sqlite3"
-SRC_URI = "https://dist.opendnssec.org/source/softhsm-2.6.1.tar.gz \
+SRC_URI = "https://github.com/opendnssec/opendnssec/releases/download/2.1.14/softhsm-2.6.1.tar.gz \
file://0001-avoid-unnecessary-check-for-sqlite3-binary.patch \
"
SRC_URI[sha256sum] = "61249473054bcd1811519ef9a989a880a7bdcc36d317c9c25457fc614df475f2"
diff --git a/meta-openembedded/meta-oe/recipes-shells/dash/dash_0.5.12.bb b/meta-openembedded/meta-oe/recipes-shells/dash/dash_0.5.12.bb
index 947ef702d7..1bf3625760 100644
--- a/meta-openembedded/meta-oe/recipes-shells/dash/dash_0.5.12.bb
+++ b/meta-openembedded/meta-oe/recipes-shells/dash/dash_0.5.12.bb
@@ -10,6 +10,8 @@ inherit autotools update-alternatives
SRC_URI = "http://gondor.apana.org.au/~herbert/${BPN}/files/${BP}.tar.gz"
SRC_URI[sha256sum] = "6a474ac46e8b0b32916c4c60df694c82058d3297d8b385b74508030ca4a8f28a"
+CVE_PRODUCT = "dash:dash"
+
EXTRA_OECONF += "--bindir=${base_bindir}"
ALTERNATIVE:${PN} = "sh"
diff --git a/meta-openembedded/meta-oe/recipes-support/asio/asio/0001-tests-Remove-blocking_adaptation.cpp.patch b/meta-openembedded/meta-oe/recipes-support/asio/asio/0001-tests-Remove-blocking_adaptation.cpp.patch
new file mode 100644
index 0000000000..5aa502916d
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/asio/asio/0001-tests-Remove-blocking_adaptation.cpp.patch
@@ -0,0 +1,37 @@
+From 7d76513b82a67e117d195a1b5a0d6c2e8591488b Mon Sep 17 00:00:00 2001
+From: Mingli Yu <mingli.yu@windriver.com>
+Date: Thu, 10 Oct 2024 13:58:38 +0800
+Subject: [PATCH] tests: Remove blocking_adaptation.cpp
+
+The test failed to build with clang as below.
+../../../asio-1.30.2/src/tests/../../include/asio/execution/blocking_adaptation.hpp:216:13: error: call to 'query' is ambiguous
+ 216 | conditional_t<true, T, P>::query(static_cast<P&&>(p))
+ | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+../../../asio-1.30.2/src/tests/../../include/asio/execution/blocking_adaptation.hpp:213:29: note: in instantiation of exception specification for 'query<asio::execution::detail::blocking_adaptation::allowed_t<>>' requested here
+ 213 | static constexpr auto query(P&& p)
+ |
+
+We can add the case back once the above build failure resolved then.
+
+Upstream-Status: Pending
+
+Signed-off-by: Mingli Yu <mingli.yu@windriver.com>
+---
+ src/tests/Makefile.am | 1 -
+ 1 file changed, 1 deletion(-)
+
+diff --git a/src/tests/Makefile.am b/src/tests/Makefile.am
+index 04f8a03..eab2d56 100644
+--- a/src/tests/Makefile.am
++++ b/src/tests/Makefile.am
+@@ -68,7 +68,6 @@ check_PROGRAMS = \
+ unit/error \
+ unit/execution/any_executor \
+ unit/execution/blocking \
+- unit/execution/blocking_adaptation \
+ unit/execution/context_as \
+ unit/execution/executor \
+ unit/execution/invocable_archetype \
+--
+2.34.1
+
diff --git a/meta-openembedded/meta-oe/recipes-support/asio/asio/run-ptest b/meta-openembedded/meta-oe/recipes-support/asio/asio/run-ptest
new file mode 100644
index 0000000000..d37db0b315
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/asio/asio/run-ptest
@@ -0,0 +1,19 @@
+#!/bin/sh
+
+ptestdir=$(dirname "$(readlink -f "$0")")
+cd "$ptestdir"/tests || exit
+
+tests=$(find * -type f -executable)
+
+rm -rf test.log
+
+for f in $tests
+do
+ if test -x ./"$f"; then
+ if ./"$f" > test.log 2>&1; then
+ echo "PASS: $f"
+ else
+ echo "FAIL: $f"
+ fi
+ fi
+done
diff --git a/meta-openembedded/meta-oe/recipes-support/asio/asio_1.30.2.bb b/meta-openembedded/meta-oe/recipes-support/asio/asio_1.30.2.bb
index 6930381ecd..1f492b71eb 100644
--- a/meta-openembedded/meta-oe/recipes-support/asio/asio_1.30.2.bb
+++ b/meta-openembedded/meta-oe/recipes-support/asio/asio_1.30.2.bb
@@ -8,9 +8,12 @@ LICENSE = "BSL-1.0"
DEPENDS = "openssl"
-SRC_URI = "${SOURCEFORGE_MIRROR}/asio/${BP}.tar.bz2"
+SRC_URI = "${SOURCEFORGE_MIRROR}/asio/${BP}.tar.bz2 \
+ file://0001-tests-Remove-blocking_adaptation.cpp.patch \
+ file://run-ptest \
+"
-inherit autotools
+inherit autotools ptest
ALLOW_EMPTY:${PN} = "1"
@@ -22,4 +25,16 @@ PACKAGECONFIG ??= "boost"
PACKAGECONFIG[boost] = "--with-boost=${STAGING_LIBDIR},--without-boost,boost"
+TESTDIR = "src/tests"
+do_compile_ptest() {
+ echo 'buildtest-TESTS: $(check_PROGRAMS)' >> ${TESTDIR}/Makefile
+ oe_runmake -C ${TESTDIR} buildtest-TESTS
+}
+
+do_install_ptest() {
+ install -d ${D}${PTEST_PATH}/tests
+ # copy executables
+ find ${B}/${TESTDIR}/unit -type f -executable -exec cp {} ${D}${PTEST_PATH}/tests/ \;
+}
+
BBCLASSEXTEND = "native nativesdk"
diff --git a/meta-openembedded/meta-oe/recipes-support/ckermit/ckermit_302.bb b/meta-openembedded/meta-oe/recipes-support/ckermit/ckermit_302.bb
index 53f2b9d2c5..e9c3a53e38 100644
--- a/meta-openembedded/meta-oe/recipes-support/ckermit/ckermit_302.bb
+++ b/meta-openembedded/meta-oe/recipes-support/ckermit/ckermit_302.bb
@@ -28,7 +28,7 @@ do_compile () {
# The original makefile doesn't differentiate between CC and CC_FOR_BUILD,
# so we build wart manually. Note that you need a ckwart.o with the proper
# timestamp to make this hack work:
- ${BUILD_CC} -c ckwart.c
+ ${BUILD_CC} -DMAINTYPE=int -c -o ckwart.o ckwart.c
${BUILD_CC} -o wart ckwart.o
./wart ckcpro.w ckcpro.c
@@ -45,7 +45,8 @@ do_compile () {
-DNORESEND -DNOAUTODL -DNOSTREAMING -DNOHINTS -DNOCKXYZ -DNOLEARN \
-DNOMKDIR -DNOPERMS -DNOCKTIMERS -DNOCKREGEX -DNOREALPATH \
-DCK_SMALL -DNOLOGDIAL -DNORENAME -DNOWHATAMI \
- -DNOARROWKEYS"
+ -DNOARROWKEYS -DMAINTYPE=int \
+ -D_DEFAULT_SOURCE -ansi"
}
do_install () {
diff --git a/meta-openembedded/meta-oe/recipes-support/eject/eject_2.1.5.bb b/meta-openembedded/meta-oe/recipes-support/eject/eject_2.1.5.bb
index dd5489e7db..953c2e541c 100644
--- a/meta-openembedded/meta-oe/recipes-support/eject/eject_2.1.5.bb
+++ b/meta-openembedded/meta-oe/recipes-support/eject/eject_2.1.5.bb
@@ -5,7 +5,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=8ca43cbc842c2336e835926c2166c28b"
inherit autotools gettext update-alternatives
-SRC_URI = "http://sources.openembedded.org/${BP}.tar.gz \
+SRC_URI = "https://downloads.yoctoproject.org/mirror/sources/${BP}.tar.gz \
file://eject-2.1.5-error-return.patch \
file://eject-2.1.1-verbose.patch \
file://eject-2.1.5-spaces.patch \
diff --git a/meta-openembedded/meta-oe/recipes-support/emacs/emacs_29.1.bb b/meta-openembedded/meta-oe/recipes-support/emacs/emacs_29.1.bb
index 5cbe4551c0..23388f309b 100644
--- a/meta-openembedded/meta-oe/recipes-support/emacs/emacs_29.1.bb
+++ b/meta-openembedded/meta-oe/recipes-support/emacs/emacs_29.1.bb
@@ -5,6 +5,11 @@ LICENSE = "GPL-3.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=1ebbd3e34237af26da5dc08a4e440464"
SRC_URI = "https://ftp.gnu.org/pub/gnu/emacs/emacs-${PV}.tar.xz \
+ file://0001-org-macro-set-templates-Prevent-code-evaluation.patch \
+ file://0001-lisp-gnus-mm-view.el-mm-display-inline-fontify-Mark-.patch \
+ file://0001-org-latex-preview-Add-protection-when-untrusted-cont.patch \
+ file://0001-org-file-contents-Consider-all-remote-files-unsafe.patch \
+ file://0001-org-link-expand-abbrev-Do-not-evaluate-arbitrary-uns.patch \
"
SRC_URI:append:class-target = " \
file://use-emacs-native-tools-for-cross-compiling.patch \
diff --git a/meta-openembedded/meta-oe/recipes-support/emacs/files/0001-lisp-gnus-mm-view.el-mm-display-inline-fontify-Mark-.patch b/meta-openembedded/meta-oe/recipes-support/emacs/files/0001-lisp-gnus-mm-view.el-mm-display-inline-fontify-Mark-.patch
new file mode 100644
index 0000000000..d951bf4205
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/emacs/files/0001-lisp-gnus-mm-view.el-mm-display-inline-fontify-Mark-.patch
@@ -0,0 +1,27 @@
+From 0e7fe7809daa123921faa0bd088931cf8ddfd705 Mon Sep 17 00:00:00 2001
+From: Ihor Radchenko <yantar92@posteo.net>
+Date: Tue, 20 Feb 2024 12:44:30 +0300
+Subject: [PATCH] * lisp/gnus/mm-view.el (mm-display-inline-fontify): Mark
+ contents untrusted.
+
+CVE: CVE-2024-30203
+
+Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=937b9042ad7426acdcca33e3d931d8f495bdd804]
+
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ lisp/gnus/mm-view.el | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/lisp/gnus/mm-view.el b/lisp/gnus/mm-view.el
+index 2c40735..e24f3f3 100644
+--- a/lisp/gnus/mm-view.el
++++ b/lisp/gnus/mm-view.el
+@@ -504,6 +504,7 @@ If MODE is not set, try to find mode automatically."
+ (setq coding-system (mm-find-buffer-file-coding-system)))
+ (setq text (buffer-string))))
+ (with-temp-buffer
++ (setq untrusted-content t)
+ (insert (cond ((eq charset 'gnus-decoded)
+ (with-current-buffer (mm-handle-buffer handle)
+ (buffer-string)))
diff --git a/meta-openembedded/meta-oe/recipes-support/emacs/files/0001-org-file-contents-Consider-all-remote-files-unsafe.patch b/meta-openembedded/meta-oe/recipes-support/emacs/files/0001-org-file-contents-Consider-all-remote-files-unsafe.patch
new file mode 100644
index 0000000000..7408f0e404
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/emacs/files/0001-org-file-contents-Consider-all-remote-files-unsafe.patch
@@ -0,0 +1,38 @@
+From 3a3bc6df4295ff7d5ea7193dfe0492cd858e1664 Mon Sep 17 00:00:00 2001
+From: Ihor Radchenko <yantar92@posteo.net>
+Date: Tue, 20 Feb 2024 14:59:20 +0300
+Subject: [PATCH] org-file-contents: Consider all remote files unsafe
+
+* lisp/org/org.el (org-file-contents): When loading files, consider all
+remote files (like TRAMP-fetched files) unsafe, in addition to URLs.
+
+CVE: CVE-2024-30205
+Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=2bc865ace050ff118db43f01457f95f95112b877]
+
+Signed-off-by: Gyorgy Sarvari
+---
+ lisp/org/org.el | 6 +++++-
+ 1 file changed, 5 insertions(+), 1 deletion(-)
+
+diff --git a/lisp/org/org.el b/lisp/org/org.el
+index ab58978..03140bd 100644
+--- a/lisp/org/org.el
++++ b/lisp/org/org.el
+@@ -4576,12 +4576,16 @@ from file or URL, and return nil.
+ If NOCACHE is non-nil, do a fresh fetch of FILE even if cached version
+ is available. This option applies only if FILE is a URL."
+ (let* ((is-url (org-url-p file))
++ (is-remote (condition-case nil
++ (file-remote-p file)
++ ;; In case of error, be safe.
++ (t t)))
+ (cache (and is-url
+ (not nocache)
+ (gethash file org--file-cache))))
+ (cond
+ (cache)
+- (is-url
++ ((or is-url is-remote)
+ (if (org--should-fetch-remote-resource-p file)
+ (condition-case error
+ (with-current-buffer (url-retrieve-synchronously file)
diff --git a/meta-openembedded/meta-oe/recipes-support/emacs/files/0001-org-latex-preview-Add-protection-when-untrusted-cont.patch b/meta-openembedded/meta-oe/recipes-support/emacs/files/0001-org-latex-preview-Add-protection-when-untrusted-cont.patch
new file mode 100644
index 0000000000..085bc31c17
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/emacs/files/0001-org-latex-preview-Add-protection-when-untrusted-cont.patch
@@ -0,0 +1,60 @@
+From c5cc03c196306372e53700553e0fb5135f6105e6 Mon Sep 17 00:00:00 2001
+From: Ihor Radchenko <yantar92@posteo.net>
+Date: Tue, 20 Feb 2024 12:47:24 +0300
+Subject: [PATCH] org-latex-preview: Add protection when `untrusted-content' is
+ non-nil
+
+* lisp/org/org.el (org--latex-preview-when-risky): New variable
+controlling how to handle LaTeX previews in Org files from untrusted
+origin.
+(org-latex-preview): Consult `org--latex-preview-when-risky' before
+generating previews.
+
+This patch adds a layer of protection when LaTeX preview is requested
+for an email attachment, where `untrusted-content' is set to non-nil.
+
+CVE: CVE-2024-30204
+
+Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=6f9ea396f49cbe38c2173e0a72ba6af3e03b271c]
+Signed-off-by: Gyorgy Sarvari
+---
+ lisp/org/org.el | 19 +++++++++++++++++++
+ 1 file changed, 19 insertions(+)
+
+diff --git a/lisp/org/org.el b/lisp/org/org.el
+index d3e14fe..ab58978 100644
+--- a/lisp/org/org.el
++++ b/lisp/org/org.el
+@@ -1140,6 +1140,24 @@ the following lines anywhere in the buffer:
+ :package-version '(Org . "8.0")
+ :type 'boolean)
+
++(defvar untrusted-content) ; defined in files.el
++(defvar org--latex-preview-when-risky nil
++ "If non-nil, enable LaTeX preview in Org buffers from unsafe source.
++
++Some specially designed LaTeX code may generate huge pdf or log files
++that may exhaust disk space.
++
++This variable controls how to handle LaTeX preview when rendering LaTeX
++fragments that originate from incoming email messages. It has no effect
++when Org mode is unable to determine the origin of the Org buffer.
++
++An Org buffer is considered to be from unsafe source when the
++variable `untrusted-content' has a non-nil value in the buffer.
++
++If this variable is non-nil, LaTeX previews are rendered unconditionally.
++
++This variable may be renamed or changed in the future.")
++
+ (defcustom org-insert-mode-line-in-empty-file nil
+ "Non-nil means insert the first line setting Org mode in empty files.
+ When the function `org-mode' is called interactively in an empty file, this
+@@ -15687,6 +15705,7 @@ fragments in the buffer."
+ (interactive "P")
+ (cond
+ ((not (display-graphic-p)) nil)
++ ((and untrusted-content (not org--latex-preview-when-risky)) nil)
+ ;; Clear whole buffer.
+ ((equal arg '(64))
+ (org-clear-latex-preview (point-min) (point-max))
diff --git a/meta-openembedded/meta-oe/recipes-support/emacs/files/0001-org-link-expand-abbrev-Do-not-evaluate-arbitrary-uns.patch b/meta-openembedded/meta-oe/recipes-support/emacs/files/0001-org-link-expand-abbrev-Do-not-evaluate-arbitrary-uns.patch
new file mode 100644
index 0000000000..88fdaaf22d
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/emacs/files/0001-org-link-expand-abbrev-Do-not-evaluate-arbitrary-uns.patch
@@ -0,0 +1,71 @@
+From 8b8866eb94c7b7140ba94eb2b4e6ead14c0d986d Mon Sep 17 00:00:00 2001
+From: Ihor Radchenko <yantar92@posteo.net>
+Date: Fri, 21 Jun 2024 15:45:25 +0200
+Subject: [PATCH] org-link-expand-abbrev: Do not evaluate arbitrary unsafe
+ Elisp code
+
+* lisp/org/ol.el (org-link-expand-abbrev): Refuse expanding %(...)
+link abbrevs that specify unsafe function. Instead, display a
+warning, and do not expand the abbrev. Clear all the text properties
+from the returned link, to avoid any potential vulnerabilities caused
+by properties that may contain arbitrary Elisp.
+
+CVE: CVE-2024-39331
+Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=c645e1d8205f0f0663ec4a2d27575b238c646c7c]
+
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ lisp/org/ol.el | 40 +++++++++++++++++++++++++++++-----------
+ 1 file changed, 29 insertions(+), 11 deletions(-)
+
+diff --git a/lisp/org/ol.el b/lisp/org/ol.el
+index 9ad191c..c15128f 100644
+--- a/lisp/org/ol.el
++++ b/lisp/org/ol.el
+@@ -1063,17 +1063,35 @@ Abbreviations are defined in `org-link-abbrev-alist'."
+ (if (not as)
+ link
+ (setq rpl (cdr as))
+- (cond
+- ((symbolp rpl) (funcall rpl tag))
+- ((string-match "%(\\([^)]+\\))" rpl)
+- (replace-match
+- (save-match-data
+- (funcall (intern-soft (match-string 1 rpl)) tag))
+- t t rpl))
+- ((string-match "%s" rpl) (replace-match (or tag "") t t rpl))
+- ((string-match "%h" rpl)
+- (replace-match (url-hexify-string (or tag "")) t t rpl))
+- (t (concat rpl tag)))))))
++ ;; Drop any potentially dangerous text properties like
++ ;; `modification-hooks' that may be used as an attack vector.
++ (substring-no-properties
++ (cond
++ ((symbolp rpl) (funcall rpl tag))
++ ((string-match "%(\\([^)]+\\))" rpl)
++ (let ((rpl-fun-symbol (intern-soft (match-string 1 rpl))))
++ ;; Using `unsafep-function' is not quite enough because
++ ;; Emacs considers functions like `genenv' safe, while
++ ;; they can potentially be used to expose private system
++ ;; data to attacker if abbreviated link is clicked.
++ (if (or (eq t (get rpl-fun-symbol 'org-link-abbrev-safe))
++ (eq t (get rpl-fun-symbol 'pure)))
++ (replace-match
++ (save-match-data
++ (funcall (intern-soft (match-string 1 rpl)) tag))
++ t t rpl)
++ (org-display-warning
++ (format "Disabling unsafe link abbrev: %s
++You may mark function safe via (put '%s 'org-link-abbrev-safe t)"
++ rpl (match-string 1 rpl)))
++ (setq org-link-abbrev-alist-local (delete as org-link-abbrev-alist-local)
++ org-link-abbrev-alist (delete as org-link-abbrev-alist))
++ link
++ )))
++ ((string-match "%s" rpl) (replace-match (or tag "") t t rpl))
++ ((string-match "%h" rpl)
++ (replace-match (url-hexify-string (or tag "")) t t rpl))
++ (t (concat rpl tag))))))))
+
+ (defun org-link-open (link &optional arg)
+ "Open a link object LINK.
diff --git a/meta-openembedded/meta-oe/recipes-support/emacs/files/0001-org-macro-set-templates-Prevent-code-evaluation.patch b/meta-openembedded/meta-oe/recipes-support/emacs/files/0001-org-macro-set-templates-Prevent-code-evaluation.patch
new file mode 100644
index 0000000000..c88843da59
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/emacs/files/0001-org-macro-set-templates-Prevent-code-evaluation.patch
@@ -0,0 +1,47 @@
+From 7b1f10c152e69a32155c0291b9c8e83a8e28ebff Mon Sep 17 00:00:00 2001
+From: Ihor Radchenko <yantar92@posteo.net>
+Date: Tue, 20 Feb 2024 12:19:46 +0300
+Subject: [PATCH] org-macro--set-templates: Prevent code evaluation
+
+* lisp/org/org-macro.el (org-macro--set-templates): Get rid of any
+risk to evaluate code when `org-macro--set-templates' is called as a
+part of major mode initialization. This way, no code evaluation is
+ever triggered when user merely opens the file or when
+`mm-display-org-inline' invokes Org major mode to fontify mime part
+preview in email messages.
+
+CVE: CVE-2024-30202
+
+Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=befa9fcaae29a6c9a283ba371c3c5234c7f644eb]
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ lisp/org/org-macro.el | 9 ++++++++-
+ 1 file changed, 8 insertions(+), 1 deletion(-)
+
+diff --git a/lisp/org/org-macro.el b/lisp/org/org-macro.el
+index 481e431..a3b5c6e 100644
+--- a/lisp/org/org-macro.el
++++ b/lisp/org/org-macro.el
+@@ -109,6 +109,13 @@ previous one, unless VALUE is nil. Return the updated list."
+ (let ((new-templates nil))
+ (pcase-dolist (`(,name . ,value) templates)
+ (let ((old-definition (assoc name new-templates)))
++ ;; This code can be evaluated unconditionally, as a part of
++ ;; loading Org mode. We *must not* evaluate any code present
++ ;; inside the Org buffer while loading. Org buffers may come
++ ;; from various sources, like received email messages from
++ ;; potentially malicious senders. Org mode might be used to
++ ;; preview such messages and no code evaluation from inside the
++ ;; received Org text should ever happen without user consent.
+ (when (and (stringp value) (string-match-p "\\`(eval\\>" value))
+ ;; Pre-process the evaluation form for faster macro expansion.
+ (let* ((args (org-macro--makeargs value))
+@@ -121,7 +128,7 @@ previous one, unless VALUE is nil. Return the updated list."
+ (cadr (read value))
+ (error
+ (user-error "Invalid definition for macro %S" name)))))
+- (setq value (eval (macroexpand-all `(lambda ,args ,body)) t))))
++ (setq value `(lambda ,args ,body))))
+ (cond ((and value old-definition) (setcdr old-definition value))
+ (old-definition)
+ (t (push (cons name (or value "")) new-templates)))))
diff --git a/meta-openembedded/meta-oe/recipes-support/enca/enca/cross.patch b/meta-openembedded/meta-oe/recipes-support/enca/enca/cross.patch
new file mode 100644
index 0000000000..7749dee088
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/enca/enca/cross.patch
@@ -0,0 +1,68 @@
+From: Helmut Grohne <helmut@subdivi.de>
+Subject: build make_hash with the build arch compiler
+
+Also note that we cannot include config.h in make_hash.c, because it is
+specific to the host architecture.
+
+Sourced from debian - https://salsa.debian.org/debian/enca/-/blob/master/debian/patches/cross.patch?ref_type=heads
+
+Upstream-Status: Pending
+Signed-off-by: Khem Raj <raj.khem@gmail.com>
+
+Index: enca-1.19/configure.ac
+===================================================================
+--- enca-1.19.orig/configure.ac
++++ enca-1.19/configure.ac
+@@ -35,6 +35,7 @@
+ dnl Checks for programs.
+ AC_PROG_AWK
+ AC_PROG_CC
++AX_PROG_CC_FOR_BUILD
+ AC_GNU_SOURCE
+ AC_AIX
+ AC_ISC_POSIX
+Index: enca-1.19/tools/Makefile.am
+===================================================================
+--- enca-1.19.orig/tools/Makefile.am
++++ enca-1.19/tools/Makefile.am
+@@ -2,7 +2,8 @@
+ noinst_HEADERS = encodings.h
+ noinst_SCRIPTS = expand_table.pl
+
+-make_hash_SOURCES = make_hash.c
++make_hash$(EXEEXT): make_hash.c
++ $(CC_FOR_BUILD) $(CFLAGS_FOR_BUILD) -o $@ $<
+
+ BUILT_SOURCES = $(noinst_HEADERS)
+
+Index: enca-1.19/tools/make_hash.c
+===================================================================
+--- enca-1.19.orig/tools/make_hash.c
++++ enca-1.19/tools/make_hash.c
+@@ -17,25 +17,9 @@
+ with this program; if not, write to the Free Software Foundation, Inc.,
+ 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA.
+ */
+-#ifdef HAVE_CONFIG_H
+-# include "config.h"
+-#endif /* HAVE_CONFIG_H */
+-
+ #include <stdlib.h>
+ #include <stdio.h>
+-
+-#ifdef HAVE_STRING_H
+-# include <string.h>
+-#else /* HAVE_STRING_H */
+-# ifdef HAVE_STRINGS_H
+-# include <strings.h>
+-# endif /* HAVE_STRINGS_H */
+-#endif /* HAVE_STRING_H */
+-
+-#ifdef HAVE_MEMORY_H
+-# include <memory.h>
+-#endif /* HAVE_MEMORY_H */
+-
++#include <string.h>
+ #include <unistd.h>
+ #include <ctype.h>
+
diff --git a/meta-openembedded/meta-oe/recipes-support/enca/enca/makefile-remove-tools.patch b/meta-openembedded/meta-oe/recipes-support/enca/enca/makefile-remove-tools.patch
deleted file mode 100644
index 756745d839..0000000000
--- a/meta-openembedded/meta-oe/recipes-support/enca/enca/makefile-remove-tools.patch
+++ /dev/null
@@ -1,14 +0,0 @@
-Upstream-Status: Pending
-
---- enca-1.19/Makefile.am.orig 2006-06-29 15:34:55.000000000 +0100
-+++ enca-1.19/Makefile.am 2006-06-29 15:35:20.000000000 +0100
-@@ -1,7 +1,7 @@
- if MAINTAINER_MODE
--SUBDIRS = tools data script lib src devel-docs test
-+SUBDIRS = data script lib src devel-docs test
- else
--SUBDIRS = tools script lib src devel-docs
-+SUBDIRS = script lib src devel-docs
- endif
- man_MANS = man/enca.1
-
diff --git a/meta-openembedded/meta-oe/recipes-support/enca/enca_1.19.bb b/meta-openembedded/meta-oe/recipes-support/enca/enca_1.19.bb
index 774f05f7c4..61da50ba52 100644
--- a/meta-openembedded/meta-oe/recipes-support/enca/enca_1.19.bb
+++ b/meta-openembedded/meta-oe/recipes-support/enca/enca_1.19.bb
@@ -2,33 +2,19 @@ SUMMARY = "Enca is an Extremely Naive Charset Analyser"
SECTION = "libs"
HOMEPAGE = "https://cihar.com/software/enca/"
-DEPENDS += "gettext-native"
+DEPENDS += "gettext-native autoconf-archive-native"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=24b9569831c46d4818450b55282476b4"
SRC_URI = "https://dl.cihar.com/enca/enca-${PV}.tar.gz \
+ file://cross.patch \
file://dont-run-tests.patch \
- file://makefile-remove-tools.patch \
file://libenca-003-iconv.patch \
- file://0001-Do-not-use-MKTEMP_PROG-in-cross-build.patch"
+ file://0001-Do-not-use-MKTEMP_PROG-in-cross-build.patch \
+ "
SRC_URI[sha256sum] = "4c305cc59f3e57f2cfc150a6ac511690f43633595760e1cb266bf23362d72f8a"
inherit autotools
-do_configure:prepend() {
- # remove failing test which checks for something that isn't even used
- sed -i -e '/ye_FUNC_SCANF_MODIF_SIZE_T/d' ${S}/configure.ac
-}
-
-do_configure:append() {
- sed -i s:-I/usr/include::g ${B}/Makefile
- sed -i s:-I/usr/include::g ${B}/*/Makefile
-}
-
-do_compile() {
- cd ${S}/tools && ${BUILD_CC} -o make_hash make_hash.c
- cd ${B}
- oe_runmake
-}
-
+EXTRA_OECONF += "MKTEMP_PROG=mktemp"
diff --git a/meta-openembedded/meta-oe/recipes-support/exiv2/exiv2/0001-Add-new-method-appendIccProfile-to-fix-quadratic-per.patch b/meta-openembedded/meta-oe/recipes-support/exiv2/exiv2/0001-Add-new-method-appendIccProfile-to-fix-quadratic-per.patch
new file mode 100644
index 0000000000..a0399c539b
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/exiv2/exiv2/0001-Add-new-method-appendIccProfile-to-fix-quadratic-per.patch
@@ -0,0 +1,96 @@
+From 14a862213873b3f81941721a5972853fd269ca63 Mon Sep 17 00:00:00 2001
+From: Kevin Backhouse <kevinbackhouse@github.com>
+Date: Fri, 15 Aug 2025 12:08:49 +0100
+Subject: [PATCH] Add new method appendIccProfile to fix quadratic performance
+ issue.
+
+Upstream-Status: Backport [https://github.com/Exiv2/exiv2/pull/3345/commits/e5bf22e0cebeabeb2ffd40678344467a271be12d]
+CVE: CVE-2025-55304
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ include/exiv2/image.hpp | 10 ++++++++++
+ src/image.cpp | 29 +++++++++++++++++++++--------
+ src/jpgimage.cpp | 7 +------
+ 3 files changed, 32 insertions(+), 14 deletions(-)
+
+diff --git a/include/exiv2/image.hpp b/include/exiv2/image.hpp
+index 629a8a4fd..072016013 100644
+--- a/include/exiv2/image.hpp
++++ b/include/exiv2/image.hpp
+@@ -191,6 +191,16 @@ class EXIV2API Image {
+ @param bTestValid - tests that iccProfile contains credible data
+ */
+ virtual void setIccProfile(DataBuf&& iccProfile, bool bTestValid = true);
++ /*!
++ @brief Append more bytes to the iccProfile.
++ @param iccProfile DataBuf containing profile (binary)
++ @param bTestValid - tests that iccProfile contains credible data
++ */
++ virtual void appendIccProfile(const uint8_t* bytes, size_t size, bool bTestValid);
++ /*!
++ @brief Throw an exception if the size at the beginning of the iccProfile isn't correct.
++ */
++ virtual void checkIccProfile();
+ /*!
+ @brief Erase iccProfile. the profile is not removed from
+ the actual image until the writeMetadata() method is called.
+diff --git a/src/image.cpp b/src/image.cpp
+index f06660cf7..eb6b3eb0a 100644
+--- a/src/image.cpp
++++ b/src/image.cpp
+@@ -625,16 +625,29 @@ void Image::setComment(const std::string& comment) {
+ }
+
+ void Image::setIccProfile(Exiv2::DataBuf&& iccProfile, bool bTestValid) {
++ iccProfile_ = std::move(iccProfile);
+ if (bTestValid) {
+- if (iccProfile.size() < sizeof(long)) {
+- throw Error(ErrorCode::kerInvalidIccProfile);
+- }
+- const size_t size = iccProfile.read_uint32(0, bigEndian);
+- if (size != iccProfile.size()) {
+- throw Error(ErrorCode::kerInvalidIccProfile);
+- }
++ checkIccProfile();
++ }
++}
++
++void Image::appendIccProfile(const uint8_t* bytes, size_t size, bool bTestValid) {
++ const size_t start = iccProfile_.size();
++ iccProfile_.resize(Safe::add(start, size));
++ memcpy(iccProfile_.data(start), bytes, size);
++ if (bTestValid) {
++ checkIccProfile();
++ }
++}
++
++void Image::checkIccProfile() {
++ if (iccProfile_.size() < sizeof(long)) {
++ throw Error(ErrorCode::kerInvalidIccProfile);
++ }
++ const size_t size = iccProfile_.read_uint32(0, bigEndian);
++ if (size != iccProfile_.size()) {
++ throw Error(ErrorCode::kerInvalidIccProfile);
+ }
+- iccProfile_ = std::move(iccProfile);
+ }
+
+ void Image::clearIccProfile() {
+diff --git a/src/jpgimage.cpp b/src/jpgimage.cpp
+index 34187dc63..2c29135ae 100644
+--- a/src/jpgimage.cpp
++++ b/src/jpgimage.cpp
+@@ -268,12 +268,7 @@ void JpegBase::readMetadata() {
+ icc_size = s;
+ }
+
+- DataBuf profile(Safe::add(iccProfile_.size(), icc_size));
+- if (!iccProfile_.empty()) {
+- std::copy(iccProfile_.begin(), iccProfile_.end(), profile.begin());
+- }
+- std::copy_n(buf.c_data(2 + 14), icc_size, profile.data() + iccProfile_.size());
+- setIccProfile(std::move(profile), chunk == chunks);
++ appendIccProfile(buf.c_data(2 + 14), icc_size, chunk == chunks);
+ } else if (pixelHeight_ == 0 && inRange2(marker, sof0_, sof3_, sof5_, sof15_)) {
+ // We hit a SOFn (start-of-frame) marker
+ if (size < 8) {
diff --git a/meta-openembedded/meta-oe/recipes-support/exiv2/exiv2/0001-CVE-2025-54080-fix.patch b/meta-openembedded/meta-oe/recipes-support/exiv2/exiv2/0001-CVE-2025-54080-fix.patch
new file mode 100644
index 0000000000..6a4c80f8a8
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/exiv2/exiv2/0001-CVE-2025-54080-fix.patch
@@ -0,0 +1,77 @@
+From 6a0c63f1362dac8badfad5d2dcc55fb4ff04fc60 Mon Sep 17 00:00:00 2001
+From: Kevin Backhouse <kevinbackhouse@github.com>
+Date: Tue, 29 Jul 2025 18:58:46 +0100
+Subject: [PATCH] CVE-2025-54080 fix
+
+Upstream-Status: Backport [https://github.com/Exiv2/exiv2/commit/e737332427711f15bcdc4e903203d6b7493eaec0]
+CVE: CVE-2025-54080
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ src/epsimage.cpp | 40 +++++++++++-----------------------------
+ 1 file changed, 11 insertions(+), 29 deletions(-)
+
+diff --git a/src/epsimage.cpp b/src/epsimage.cpp
+index 2e2241b69..bb4aa3303 100644
+--- a/src/epsimage.cpp
++++ b/src/epsimage.cpp
+@@ -241,6 +241,8 @@ void readWriteEpsMetadata(BasicIo& io, std::string& xmpPacket, NativePreviewList
+ uint32_t posTiff = 0;
+ uint32_t sizeTiff = 0;
+
++ ErrorCode errcode = write ? ErrorCode::kerImageWriteFailed : ErrorCode::kerFailedToReadImageData;
++
+ // check for DOS EPS
+ const bool dosEps =
+ (size >= dosEpsSignature.size() && memcmp(data, dosEpsSignature.data(), dosEpsSignature.size()) == 0);
+@@ -248,12 +250,8 @@ void readWriteEpsMetadata(BasicIo& io, std::string& xmpPacket, NativePreviewList
+ #ifdef DEBUG
+ EXV_DEBUG << "readWriteEpsMetadata: Found DOS EPS signature\n";
+ #endif
+- if (size < 30) {
+-#ifndef SUPPRESS_WARNINGS
+- EXV_WARNING << "Premature end of file after DOS EPS signature.\n";
+-#endif
+- throw Error(write ? ErrorCode::kerImageWriteFailed : ErrorCode::kerFailedToReadImageData);
+- }
++
++ enforce(size >= 30, errcode);
+ posEps = getULong(data + 4, littleEndian);
+ posEndEps = getULong(data + 8, littleEndian) + posEps;
+ posWmf = getULong(data + 12, littleEndian);
+@@ -285,29 +283,13 @@ void readWriteEpsMetadata(BasicIo& io, std::string& xmpPacket, NativePreviewList
+ if (write)
+ throw Error(ErrorCode::kerImageWriteFailed);
+ }
+- if (posEps < 30 || posEndEps > size) {
+-#ifndef SUPPRESS_WARNINGS
+- EXV_WARNING << "DOS EPS file has invalid position (" << posEps << ") or size (" << (posEndEps - posEps)
+- << ") for EPS section.\n";
+-#endif
+- throw Error(write ? ErrorCode::kerImageWriteFailed : ErrorCode::kerFailedToReadImageData);
+- }
+- if (sizeWmf != 0 && (posWmf < 30 || posWmf + sizeWmf > size)) {
+-#ifndef SUPPRESS_WARNINGS
+- EXV_WARNING << "DOS EPS file has invalid position (" << posWmf << ") or size (" << sizeWmf
+- << ") for WMF section.\n";
+-#endif
+- if (write)
+- throw Error(ErrorCode::kerImageWriteFailed);
+- }
+- if (sizeTiff != 0 && (posTiff < 30 || posTiff + sizeTiff > size)) {
+-#ifndef SUPPRESS_WARNINGS
+- EXV_WARNING << "DOS EPS file has invalid position (" << posTiff << ") or size (" << sizeTiff
+- << ") for TIFF section.\n";
+-#endif
+- if (write)
+- throw Error(ErrorCode::kerImageWriteFailed);
+- }
++ enforce(30 <= posEps, errcode);
++ enforce(sizeWmf == 0 || 30 <= posWmf, errcode);
++ enforce(sizeTiff == 0 || 30 <= posTiff, errcode);
++
++ enforce(posEps <= posEndEps && posEndEps <= size, errcode);
++ enforce(posWmf <= size && sizeWmf <= size - posWmf, errcode);
++ enforce(posTiff <= size && sizeTiff <= size - posTiff, errcode);
+ }
+
+ // check first line
diff --git a/meta-openembedded/meta-oe/recipes-support/exiv2/exiv2/0001-Revert-fix-copy-constructors.patch b/meta-openembedded/meta-oe/recipes-support/exiv2/exiv2/0001-Revert-fix-copy-constructors.patch
new file mode 100644
index 0000000000..b3074e2823
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/exiv2/exiv2/0001-Revert-fix-copy-constructors.patch
@@ -0,0 +1,82 @@
+From f338465efb49166c543dcc2fc52810370ea90475 Mon Sep 17 00:00:00 2001
+From: Rosen Penev <rosenp@gmail.com>
+Date: Mon, 17 Feb 2025 16:34:40 -0800
+Subject: [PATCH] Revert "fix copy constructors"
+
+This reverts commit afb2d998fe62f7e829e93e62506bf9968117c9c5.
+
+This commit is wrong and ends up resulting in use after frees because of
+C pointers. The proper solution is shared_ptr instead of C pointers but
+that's a lot more involved than reverting this.
+
+Signed-off-by: Rosen Penev <rosenp@gmail.com>
+
+CVE: CVE-2025-26623
+Upstream-Status: Backport [https://github.com/Exiv2/exiv2/pull/3174/commits/638ff11ce7480000974b5c619eafcb8618e3b586]
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ src/tiffcomposite_int.cpp | 19 +++++++++++++++++++
+ src/tiffcomposite_int.hpp | 6 +++---
+ 2 files changed, 22 insertions(+), 3 deletions(-)
+
+diff --git a/src/tiffcomposite_int.cpp b/src/tiffcomposite_int.cpp
+index 95ce450c7..3e6e93d5c 100644
+--- a/src/tiffcomposite_int.cpp
++++ b/src/tiffcomposite_int.cpp
+@@ -127,6 +127,25 @@ TiffEntryBase::TiffEntryBase(const TiffEntryBase& rhs) :
+ storage_(rhs.storage_) {
+ }
+
++TiffDirectory::TiffDirectory(const TiffDirectory& rhs) : TiffComponent(rhs), hasNext_(rhs.hasNext_) {
++}
++
++TiffSubIfd::TiffSubIfd(const TiffSubIfd& rhs) : TiffEntryBase(rhs), newGroup_(rhs.newGroup_) {
++}
++
++TiffBinaryArray::TiffBinaryArray(const TiffBinaryArray& rhs) :
++ TiffEntryBase(rhs),
++ cfgSelFct_(rhs.cfgSelFct_),
++ arraySet_(rhs.arraySet_),
++ arrayCfg_(rhs.arrayCfg_),
++ arrayDef_(rhs.arrayDef_),
++ defSize_(rhs.defSize_),
++ setSize_(rhs.setSize_),
++ origData_(rhs.origData_),
++ origSize_(rhs.origSize_),
++ pRoot_(rhs.pRoot_) {
++}
++
+ TiffComponent::UniquePtr TiffComponent::clone() const {
+ return UniquePtr(doClone());
+ }
+diff --git a/src/tiffcomposite_int.hpp b/src/tiffcomposite_int.hpp
+index 4506a4dca..307e0bd9e 100644
+--- a/src/tiffcomposite_int.hpp
++++ b/src/tiffcomposite_int.hpp
+@@ -851,7 +851,7 @@ class TiffDirectory : public TiffComponent {
+ //! @name Protected Creators
+ //@{
+ //! Copy constructor (used to implement clone()).
+- TiffDirectory(const TiffDirectory&) = default;
++ TiffDirectory(const TiffDirectory& rhs);
+ //@}
+
+ //! @name Protected Manipulators
+@@ -944,7 +944,7 @@ class TiffSubIfd : public TiffEntryBase {
+ //! @name Protected Creators
+ //@{
+ //! Copy constructor (used to implement clone()).
+- TiffSubIfd(const TiffSubIfd&) = default;
++ TiffSubIfd(const TiffSubIfd& rhs);
+ TiffSubIfd& operator=(const TiffSubIfd&) = delete;
+ //@}
+
+@@ -1346,7 +1346,7 @@ class TiffBinaryArray : public TiffEntryBase {
+ //! @name Protected Creators
+ //@{
+ //! Copy constructor (used to implement clone()).
+- TiffBinaryArray(const TiffBinaryArray&) = default;
++ TiffBinaryArray(const TiffBinaryArray& rhs);
+ //@}
+
+ //! @name Protected Manipulators
diff --git a/meta-openembedded/meta-oe/recipes-support/exiv2/exiv2_0.28.0.bb b/meta-openembedded/meta-oe/recipes-support/exiv2/exiv2_0.28.0.bb
deleted file mode 100644
index 958810cf7a..0000000000
--- a/meta-openembedded/meta-oe/recipes-support/exiv2/exiv2_0.28.0.bb
+++ /dev/null
@@ -1,19 +0,0 @@
-SUMMARY = "Exif, Iptc and XMP metadata manipulation library and tools"
-LICENSE = "GPL-2.0-only"
-LIC_FILES_CHKSUM = "file://COPYING;md5=625f055f41728f84a8d7938acc35bdc2"
-
-DEPENDS = "zlib expat brotli libinih"
-
-SRC_URI = "https://github.com/Exiv2/${BPN}/releases/download/v${PV}/${BP}-Source.tar.gz"
-SRC_URI[sha256sum] = "89af3b5ef7277753ef7a7b5374ae017c6b9e304db3b688f1948e73e103491f3d"
-# Once patch is obsolete (project should be aware due to PRs), dos2unix can be removed either
-# inherit dos2unix
-S = "${WORKDIR}/${BP}-Source"
-
-inherit cmake gettext
-
-do_install:append:class-target() {
- # reproducibility: remove build host path
- sed -i ${D}${libdir}/cmake/exiv2/exiv2Config.cmake \
- -e 's:${STAGING_DIR_HOST}::g'
-}
diff --git a/meta-openembedded/meta-oe/recipes-support/exiv2/exiv2_0.28.3.bb b/meta-openembedded/meta-oe/recipes-support/exiv2/exiv2_0.28.3.bb
new file mode 100644
index 0000000000..db32398b4f
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/exiv2/exiv2_0.28.3.bb
@@ -0,0 +1,15 @@
+SUMMARY = "Exif, Iptc and XMP metadata manipulation library and tools"
+LICENSE = "GPL-2.0-only"
+LIC_FILES_CHKSUM = "file://COPYING;md5=625f055f41728f84a8d7938acc35bdc2"
+
+DEPENDS = "zlib expat brotli libinih"
+
+SRC_URI = "git://github.com/Exiv2/exiv2.git;protocol=https;branch=0.28.x \
+ file://0001-Revert-fix-copy-constructors.patch \
+ file://0001-CVE-2025-54080-fix.patch \
+ file://0001-Add-new-method-appendIccProfile-to-fix-quadratic-per.patch \
+ "
+SRCREV = "a6a79ef064f131ffd03c110acce2d3edb84ffa2e"
+S = "${WORKDIR}/git"
+
+inherit cmake gettext
diff --git a/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp/0001-Fixed-compilation-warnings.patch b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp/0001-Fixed-compilation-warnings.patch
new file mode 100644
index 0000000000..7fae2703f8
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp/0001-Fixed-compilation-warnings.patch
@@ -0,0 +1,27 @@
+From 75fa1fa5bd5ef2350390564245fd0984209ac092 Mon Sep 17 00:00:00 2001
+From: akallabeth <akallabeth@posteo.net>
+Date: Mon, 4 Jul 2022 14:34:46 +0200
+Subject: [PATCH] Fixed compilation warnings
+
+Upstream-Status: Backport [https://github.com/FreeRDP/FreeRDP/commit/2da280b8a1748052b70b3f5a1ef0d8e932c33adc]
+Signed-off-by: Khem Raj <raj.khem@gmail.com>
+---
+ client/X11/xf_graphics.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/client/X11/xf_graphics.c b/client/X11/xf_graphics.c
+index 5aa1fd48b..fe81e0ed9 100644
+--- a/client/X11/xf_graphics.c
++++ b/client/X11/xf_graphics.c
+@@ -438,7 +438,7 @@ static BOOL xf_Pointer_New(rdpContext* context, rdpPointer* pointer)
+
+ #endif
+ fail:
+- WLog_DBG(TAG, "%s: %ld", __func__, rc ? pointer : -1);
++ WLog_DBG(TAG, "%s: %p", __func__, rc ? pointer : NULL);
+ return rc;
+ }
+
+--
+2.45.0
+
diff --git a/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp/CVE-2024-32661.patch b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp/CVE-2024-32661.patch
new file mode 100644
index 0000000000..002135b5e4
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp/CVE-2024-32661.patch
@@ -0,0 +1,27 @@
+From 71e463e31b4d69f4022d36bfc814592f56600793 Mon Sep 17 00:00:00 2001
+From: akallabeth <akallabeth@posteo.net>
+Date: Sun, 21 Apr 2024 13:56:13 +0200
+Subject: [PATCH] [core,info] fix missing check in rdp_write_logon_info_v1
+
+CVE: CVE-2024-32661
+Upstream-Status: Backport [https://github.com/FreeRDP/FreeRDP/commit/71e463e31b4d69f4022d36bfc814592f56600793]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ libfreerdp/core/info.c | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/libfreerdp/core/info.c b/libfreerdp/core/info.c
+index 7d6eec137..3395e4d2e 100644
+--- a/libfreerdp/core/info.c
++++ b/libfreerdp/core/info.c
+@@ -1322,6 +1322,10 @@ static BOOL rdp_write_logon_info_v1(wStream* s, logon_info* info)
+ return FALSE;
+
+ /* domain */
++ WINPR_ASSERT(info);
++ if (!info->domain || !info->username)
++ return FALSE;
++
+ ilen = ConvertToUnicode(CP_UTF8, 0, info->domain, -1, &wString, 0);
+
+ if (ilen < 0)
diff --git a/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32039.patch b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32039.patch
new file mode 100644
index 0000000000..f553228350
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32039.patch
@@ -0,0 +1,68 @@
+From bcaac313a07865cf05176c9d07ec1ca0670b2b61 Mon Sep 17 00:00:00 2001
+From: akallabeth <akallabeth@posteo.net>
+Date: Tue, 16 Apr 2024 08:35:05 +0200
+Subject: [PATCH] fix integer overflow
+
+reorder check to prevent possible integer overflow
+
+CVE: CVE-2024-32039 CVE-2024-32041
+Upstream-Status: Backport [https://github.com/FreeRDP/FreeRDP/commit/1208f23bc967be01cae42ca448a36f4f3d0cb7d8]
+
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ libfreerdp/codec/clear.c | 2 +-
+ libfreerdp/codec/zgfx.c | 14 +++++++++-----
+ 2 files changed, 10 insertions(+), 6 deletions(-)
+
+diff --git a/libfreerdp/codec/clear.c b/libfreerdp/codec/clear.c
+index 5c009d8e9..512aeae20 100644
+--- a/libfreerdp/codec/clear.c
++++ b/libfreerdp/codec/clear.c
+@@ -409,7 +409,7 @@ static BOOL clear_decompress_residual_data(CLEAR_CONTEXT* clear, wStream* s,
+ }
+ }
+
+- if ((pixelIndex + runLengthFactor) > pixelCount)
++ if ((pixelIndex >= pixelCount) || (runLengthFactor > (pixelCount - pixelIndex)))
+ {
+ WLog_ERR(TAG,
+ "pixelIndex %" PRIu32 " + runLengthFactor %" PRIu32 " > pixelCount %" PRIu32
+diff --git a/libfreerdp/codec/zgfx.c b/libfreerdp/codec/zgfx.c
+index 881823ab3..b7ee27511 100644
+--- a/libfreerdp/codec/zgfx.c
++++ b/libfreerdp/codec/zgfx.c
+@@ -227,7 +227,10 @@ static BOOL zgfx_decompress_segment(ZGFX_CONTEXT* zgfx, wStream* stream, size_t
+ BYTE* pbSegment = NULL;
+ size_t cbSegment = 0;
+
+- if (!zgfx || !stream || (segmentSize < 2))
++ WINPR_ASSERT(zgfx);
++ WINPR_ASSERT(stream);
++
++ if (segmentSize < 2)
+ return FALSE;
+
+ cbSegment = segmentSize - 1;
+@@ -346,8 +349,9 @@ static BOOL zgfx_decompress_segment(ZGFX_CONTEXT* zgfx, wStream* stream, size_t
+
+ if (count > sizeof(zgfx->OutputBuffer) - zgfx->OutputCount)
+ return FALSE;
+-
+- if (count > zgfx->cBitsRemaining / 8)
++ else if (count > zgfx->cBitsRemaining / 8)
++ return FALSE;
++ else if (zgfx->pbInputCurrent + count > zgfx->pbInputEnd)
+ return FALSE;
+
+ CopyMemory(&(zgfx->OutputBuffer[zgfx->OutputCount]), zgfx->pbInputCurrent,
+@@ -386,8 +390,8 @@ int zgfx_decompress(ZGFX_CONTEXT* zgfx, const BYTE* pSrcData, UINT32 SrcSize, BY
+ wStream sbuffer = { 0 };
+ wStream* stream = Stream_StaticConstInit(&sbuffer, pSrcData, SrcSize);
+
+- if (!stream)
+- return -1;
++ WINPR_ASSERT(zgfx);
++ WINPR_ASSERT(stream);
+
+ if (!Stream_CheckAndLogRequiredLength(TAG, stream, 1))
+ goto fail;
diff --git a/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32040.patch b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32040.patch
new file mode 100644
index 0000000000..10b89e577f
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32040.patch
@@ -0,0 +1,29 @@
+From f29088d17903aa8e58073b9811dc8a72f94cf4fb Mon Sep 17 00:00:00 2001
+From: akallabeth <akallabeth@posteo.net>
+Date: Tue, 16 Apr 2024 08:26:37 +0200
+Subject: [PATCH] fix missing check
+
+in nsc_rle_decode abort if there are more bytes to be read then there
+are left.
+
+CVE: CVE-2024-32040
+Upstream-Status: Backport [https://github.com/FreeRDP/FreeRDP/commit/d58cbc96aced4d082abf92b41a415a891c7ea309]
+
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ libfreerdp/codec/nsc.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/libfreerdp/codec/nsc.c b/libfreerdp/codec/nsc.c
+index 049b541f1..c2d92e48c 100644
+--- a/libfreerdp/codec/nsc.c
++++ b/libfreerdp/codec/nsc.c
+@@ -160,7 +160,7 @@ static BOOL nsc_rle_decode(const BYTE* in, size_t inSize, BYTE* out, UINT32 outS
+ len |= ((UINT32)(*in++)) << 24U;
+ }
+
+- if (outSize < len)
++ if ((outSize < len) || (left < len))
+ return FALSE;
+
+ outSize -= len;
diff --git a/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32458.patch b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32458.patch
new file mode 100644
index 0000000000..a9b51221d4
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32458.patch
@@ -0,0 +1,119 @@
+From 3033c4d69afbb23f577cf6962314613ef96782fd Mon Sep 17 00:00:00 2001
+From: akallabeth <akallabeth@posteo.net>
+Date: Tue, 16 Apr 2024 08:42:52 +0200
+Subject: [PATCH] fix missing input length checks
+
+CVE: CVE-2024-32458
+Upstream-Status: Backport [https://github.com/FreeRDP/FreeRDP/commit/9da3f236985207378abe64bc401cecd8566e4542]
+
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ libfreerdp/codec/planar.c | 54 +++++++++++++++++++++++++++++----------
+ 1 file changed, 40 insertions(+), 14 deletions(-)
+
+diff --git a/libfreerdp/codec/planar.c b/libfreerdp/codec/planar.c
+index 0ec086269..4b51a023e 100644
+--- a/libfreerdp/codec/planar.c
++++ b/libfreerdp/codec/planar.c
+@@ -788,18 +788,26 @@ BOOL planar_decompress(BITMAP_PLANAR_CONTEXT* planar, const BYTE* pSrcData, UINT
+ rawHeights[3] = nSrcHeight;
+ }
+
++ const size_t diff = srcp - pSrcData;
++ if (SrcSize < diff)
++ {
++ WLog_ERR(TAG, "Size mismatch %" PRIu32 " < %" PRIuz, SrcSize, diff);
++ return FALSE;
++ }
++
+ if (!rle) /* RAW */
+ {
++
+ UINT32 base = planeSize * 3;
+ if (cs)
+ base = planeSize + planeSize / 2;
+
+ if (alpha)
+ {
+- if ((SrcSize - (srcp - pSrcData)) < (planeSize + base))
++ if ((SrcSize - diff) < (planeSize + base))
+ {
+- WLog_ERR(TAG, "Alpha plane size mismatch %" PRIu32 " < %" PRIu32,
+- SrcSize - (srcp - pSrcData), (planeSize + base));
++ WLog_ERR(TAG, "Alpha plane size mismatch %" PRIuz " < %" PRIu32, SrcSize - diff,
++ (planeSize + base));
+ return FALSE;
+ }
+
+@@ -817,10 +825,9 @@ BOOL planar_decompress(BITMAP_PLANAR_CONTEXT* planar, const BYTE* pSrcData, UINT
+ }
+ else
+ {
+- if ((SrcSize - (srcp - pSrcData)) < base)
++ if ((SrcSize - diff) < base)
+ {
+- WLog_ERR(TAG, "plane size mismatch %" PRIu32 " < %" PRIu32,
+- SrcSize - (srcp - pSrcData), base);
++ WLog_ERR(TAG, "plane size mismatch %" PRIu32 " < %" PRIu32, SrcSize - diff, base);
+ return FALSE;
+ }
+
+@@ -841,8 +848,8 @@ BOOL planar_decompress(BITMAP_PLANAR_CONTEXT* planar, const BYTE* pSrcData, UINT
+ if (alpha)
+ {
+ planes[3] = srcp;
+- rleSizes[3] = planar_skip_plane_rle(planes[3], SrcSize - (planes[3] - pSrcData),
+- rawWidths[3], rawHeights[3]); /* AlphaPlane */
++ rleSizes[3] = planar_skip_plane_rle(planes[3], SrcSize - diff, rawWidths[3],
++ rawHeights[3]); /* AlphaPlane */
+
+ if (rleSizes[3] < 0)
+ return FALSE;
+@@ -852,22 +859,41 @@ BOOL planar_decompress(BITMAP_PLANAR_CONTEXT* planar, const BYTE* pSrcData, UINT
+ else
+ planes[0] = srcp;
+
+- rleSizes[0] = planar_skip_plane_rle(planes[0], SrcSize - (planes[0] - pSrcData),
+- rawWidths[0], rawHeights[0]); /* RedPlane */
++ const size_t diff0 = (planes[0] - pSrcData);
++ if (SrcSize < diff0)
++ {
++ WLog_ERR(TAG, "Size mismatch %" PRIu32 " < %" PRIuz, SrcSize, diff0);
++ return FALSE;
++ }
++ rleSizes[0] = planar_skip_plane_rle(planes[0], SrcSize - diff0, rawWidths[0],
++ rawHeights[0]); /* RedPlane */
+
+ if (rleSizes[0] < 0)
+ return FALSE;
+
+ planes[1] = planes[0] + rleSizes[0];
+- rleSizes[1] = planar_skip_plane_rle(planes[1], SrcSize - (planes[1] - pSrcData),
+- rawWidths[1], rawHeights[1]); /* GreenPlane */
++
++ const size_t diff1 = (planes[1] - pSrcData);
++ if (SrcSize < diff1)
++ {
++ WLog_ERR(TAG, "Size mismatch %" PRIu32 " < %" PRIuz, SrcSize, diff1);
++ return FALSE;
++ }
++ rleSizes[1] = planar_skip_plane_rle(planes[1], SrcSize - diff1, rawWidths[1],
++ rawHeights[1]); /* GreenPlane */
+
+ if (rleSizes[1] < 1)
+ return FALSE;
+
+ planes[2] = planes[1] + rleSizes[1];
+- rleSizes[2] = planar_skip_plane_rle(planes[2], SrcSize - (planes[2] - pSrcData),
+- rawWidths[2], rawHeights[2]); /* BluePlane */
++ const size_t diff2 = (planes[2] - pSrcData);
++ if (SrcSize < diff2)
++ {
++ WLog_ERR(TAG, "Size mismatch %" PRIu32 " < %" PRIuz, SrcSize, diff);
++ return FALSE;
++ }
++ rleSizes[2] = planar_skip_plane_rle(planes[2], SrcSize - diff2, rawWidths[2],
++ rawHeights[2]); /* BluePlane */
+
+ if (rleSizes[2] < 1)
+ return FALSE;
diff --git a/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32459.patch b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32459.patch
new file mode 100644
index 0000000000..8370f055a5
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32459.patch
@@ -0,0 +1,30 @@
+From 8e385887fb3ffe0ec50f8c2cbdcbc66b5ff1569e Mon Sep 17 00:00:00 2001
+From: akallabeth <akallabeth@posteo.net>
+Date: Tue, 16 Apr 2024 08:45:03 +0200
+Subject: [PATCH] fix missing input length check
+
+CVE: CVE-2024-32459
+Upstream-Status: Backport [https://github.com/FreeRDP/FreeRDP/commit/91a1535f88a00bbb2b212b6a808a021aa4f486f8]
+
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ libfreerdp/codec/ncrush.c | 6 ++++++
+ 1 file changed, 6 insertions(+)
+
+diff --git a/libfreerdp/codec/ncrush.c b/libfreerdp/codec/ncrush.c
+index 4a7162c89..69921853b 100644
+--- a/libfreerdp/codec/ncrush.c
++++ b/libfreerdp/codec/ncrush.c
+@@ -2068,6 +2068,12 @@ int ncrush_decompress(NCRUSH_CONTEXT* ncrush, const BYTE* pSrcData, UINT32 SrcSi
+ return 1;
+ }
+
++ if (SrcSize < 4)
++ {
++ WLog_ERR(TAG, "Input size short: SrcSize %" PRIu32 " < 4", SrcSize);
++ return -1;
++ }
++
+ const BYTE* SrcEnd = &pSrcData[SrcSize];
+ const BYTE* SrcPtr = pSrcData + 4;
+
diff --git a/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32460.patch b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32460.patch
new file mode 100644
index 0000000000..95eb8cd076
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32460.patch
@@ -0,0 +1,26 @@
+From 4e64b3356b155835d991bcb70a9aa914252fece7 Mon Sep 17 00:00:00 2001
+From: akallabeth <akallabeth@posteo.net>
+Date: Tue, 16 Apr 2024 08:47:31 +0200
+Subject: [PATCH] fix off by one length check
+
+CVE: CVE-2024-32460
+Upstream-Status: Backport [https://github.com/FreeRDP/FreeRDP/commit/ecfafe4ad054435d84cb7b111ea73ebd46832fb6]
+
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ libfreerdp/codec/interleaved.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/libfreerdp/codec/interleaved.c b/libfreerdp/codec/interleaved.c
+index 75b2e2775..df148b667 100644
+--- a/libfreerdp/codec/interleaved.c
++++ b/libfreerdp/codec/interleaved.c
+@@ -237,7 +237,7 @@ static UINT ExtractRunLengthLiteFgBg(const BYTE* pbOrderHdr, const BYTE* pbEnd,
+ runLength = *pbOrderHdr & g_MaskLiteRunLength;
+ if (runLength == 0)
+ {
+- if (!buffer_within_range(pbOrderHdr, 1, pbEnd))
++ if (!buffer_within_range(pbOrderHdr, 2, pbEnd))
+ {
+ *advance = 0;
+ return 0;
diff --git a/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32658.patch b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32658.patch
new file mode 100644
index 0000000000..6af8867a6c
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32658.patch
@@ -0,0 +1,35 @@
+From f489a734d2c06eb4adee654919455799e4cb8c01 Mon Sep 17 00:00:00 2001
+From: akallabeth <akallabeth@posteo.net>
+Date: Sat, 20 Apr 2024 17:59:49 +0200
+Subject: [PATCH] fix offset error
+
+CVE: CVE-2024-32658
+Upstream-Status: Backport [https://github.com/FreeRDP/FreeRDP/commit/1a755d898ddc028cc818d0dd9d49d5acff4c44bf]
+
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ libfreerdp/codec/interleaved.c | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/libfreerdp/codec/interleaved.c b/libfreerdp/codec/interleaved.c
+index df148b667..08520e55e 100644
+--- a/libfreerdp/codec/interleaved.c
++++ b/libfreerdp/codec/interleaved.c
+@@ -212,7 +212,7 @@ static UINT ExtractRunLengthRegularFgBg(const BYTE* pbOrderHdr, const BYTE* pbEn
+ runLength = (*pbOrderHdr) & g_MaskRegularRunLength;
+ if (runLength == 0)
+ {
+- if (!buffer_within_range(pbOrderHdr, 1, pbEnd))
++ if (!buffer_within_range(pbOrderHdr, 2, pbEnd))
+ {
+ *advance = 0;
+ return 0;
+@@ -282,7 +282,7 @@ static UINT ExtractRunLengthMegaMega(const BYTE* pbOrderHdr, const BYTE* pbEnd,
+ WINPR_ASSERT(pbEnd);
+ WINPR_ASSERT(advance);
+
+- if (!buffer_within_range(pbOrderHdr, 2, pbEnd))
++ if (!buffer_within_range(pbOrderHdr, 3, pbEnd))
+ {
+ *advance = 0;
+ return 0;
diff --git a/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32659.patch b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32659.patch
new file mode 100644
index 0000000000..25d2613cda
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32659.patch
@@ -0,0 +1,27 @@
+From 47d18566159cefd714187e9b143a6ecbd1b13781 Mon Sep 17 00:00:00 2001
+From: akallabeth <akallabeth@posteo.net>
+Date: Sun, 21 Apr 2024 10:18:43 +0200
+Subject: [PATCH] fix out of bound read
+
+CVE: CVE-2024-32659
+Upstream-Status: Backport [https://github.com/FreeRDP/FreeRDP/commit/6430945ce003a5e24d454d8566f54aae1b6b617b]
+
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ libfreerdp/codec/color.c | 3 +++
+ 1 file changed, 3 insertions(+)
+
+diff --git a/libfreerdp/codec/color.c b/libfreerdp/codec/color.c
+index 186d477c8..9aba6df65 100644
+--- a/libfreerdp/codec/color.c
++++ b/libfreerdp/codec/color.c
+@@ -847,6 +847,9 @@ BOOL freerdp_image_copy(BYTE* pDstData, DWORD DstFormat, UINT32 nDstStep, UINT32
+ if (!pDstData || !pSrcData)
+ return FALSE;
+
++ if ((nWidth == 0) || (nHeight == 0))
++ return TRUE;
++
+ if (nDstStep == 0)
+ nDstStep = nWidth * FreeRDPGetBytesPerPixel(DstFormat);
+
diff --git a/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32660.patch b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32660.patch
new file mode 100644
index 0000000000..5e0d679467
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32660.patch
@@ -0,0 +1,151 @@
+From 466ffba85665107f23cbc25ee4563e5638dcc4cd Mon Sep 17 00:00:00 2001
+From: akallabeth <akallabeth@posteo.net>
+Date: Sat, 20 Apr 2024 19:59:48 +0200
+Subject: [PATCH] allocate in segment steps
+
+do not trust the uncompressedSize of a ZGFX_SEGMENTED_MULTIPART and
+allocate the output buffer in steps after decoding a segment.
+
+CVE: CVE-2024-32660
+Upstream-Status: Backport [https://github.com/FreeRDP/FreeRDP/commit/5e5d27cf310e4c10b854be7667bfb7a5d774eb47]
+
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ libfreerdp/codec/zgfx.c | 75 +++++++++++++++++++++++++----------------
+ 1 file changed, 46 insertions(+), 29 deletions(-)
+
+diff --git a/libfreerdp/codec/zgfx.c b/libfreerdp/codec/zgfx.c
+index b7ee27511..3a9d2e526 100644
+--- a/libfreerdp/codec/zgfx.c
++++ b/libfreerdp/codec/zgfx.c
+@@ -382,16 +382,46 @@ static BYTE* aligned_zgfx_malloc(size_t size)
+ return malloc(size + 64);
+ }
+
++static BOOL zgfx_append(ZGFX_CONTEXT* zgfx, BYTE** ppConcatenated, size_t uncompressedSize,
++ size_t* pUsed)
++{
++ WINPR_ASSERT(zgfx);
++ WINPR_ASSERT(ppConcatenated);
++ WINPR_ASSERT(pUsed);
++
++ const size_t used = *pUsed;
++ if (zgfx->OutputCount > UINT32_MAX - used)
++ return FALSE;
++
++ if (used + zgfx->OutputCount > uncompressedSize)
++ return FALSE;
++
++ BYTE* tmp = realloc(*ppConcatenated, used + zgfx->OutputCount + 64ull);
++ if (!tmp)
++ return FALSE;
++ *ppConcatenated = tmp;
++ CopyMemory(&tmp[used], zgfx->OutputBuffer, zgfx->OutputCount);
++ *pUsed = used + zgfx->OutputCount;
++ return TRUE;
++}
++
+ int zgfx_decompress(ZGFX_CONTEXT* zgfx, const BYTE* pSrcData, UINT32 SrcSize, BYTE** ppDstData,
+ UINT32* pDstSize, UINT32 flags)
+ {
+ int status = -1;
+ BYTE descriptor = 0;
+ wStream sbuffer = { 0 };
++ size_t used = 0;
++ BYTE* pConcatenated = NULL;
+ wStream* stream = Stream_StaticConstInit(&sbuffer, pSrcData, SrcSize);
+
+ WINPR_ASSERT(zgfx);
+ WINPR_ASSERT(stream);
++ WINPR_ASSERT(ppDstData);
++ WINPR_ASSERT(pDstSize);
++
++ *ppDstData = NULL;
++ *pDstSize = 0;
+
+ if (!Stream_CheckAndLogRequiredLength(TAG, stream, 1))
+ goto fail;
+@@ -403,16 +433,15 @@ int zgfx_decompress(ZGFX_CONTEXT* zgfx, const BYTE* pSrcData, UINT32 SrcSize, BY
+ if (!zgfx_decompress_segment(zgfx, stream, Stream_GetRemainingLength(stream)))
+ goto fail;
+
+- *ppDstData = NULL;
+-
+ if (zgfx->OutputCount > 0)
+- *ppDstData = aligned_zgfx_malloc(zgfx->OutputCount);
+-
+- if (!*ppDstData)
+- goto fail;
+-
+- *pDstSize = zgfx->OutputCount;
+- CopyMemory(*ppDstData, zgfx->OutputBuffer, zgfx->OutputCount);
++ {
++ if (!zgfx_append(zgfx, &pConcatenated, zgfx->OutputCount, &used))
++ goto fail;
++ if (used != zgfx->OutputCount)
++ goto fail;
++ *ppDstData = pConcatenated;
++ *pDstSize = zgfx->OutputCount;
++ }
+ }
+ else if (descriptor == ZGFX_SEGMENTED_MULTIPART)
+ {
+@@ -420,8 +449,6 @@ int zgfx_decompress(ZGFX_CONTEXT* zgfx, const BYTE* pSrcData, UINT32 SrcSize, BY
+ UINT16 segmentNumber = 0;
+ UINT16 segmentCount = 0;
+ UINT32 uncompressedSize = 0;
+- BYTE* pConcatenated = NULL;
+- size_t used = 0;
+
+ if (!Stream_CheckAndLogRequiredLength(TAG, stream, 6))
+ goto fail;
+@@ -429,17 +456,6 @@ int zgfx_decompress(ZGFX_CONTEXT* zgfx, const BYTE* pSrcData, UINT32 SrcSize, BY
+ Stream_Read_UINT16(stream, segmentCount); /* segmentCount (2 bytes) */
+ Stream_Read_UINT32(stream, uncompressedSize); /* uncompressedSize (4 bytes) */
+
+- if (!Stream_CheckAndLogRequiredLengthOfSize(TAG, stream, segmentCount, sizeof(UINT32)))
+- goto fail;
+-
+- pConcatenated = aligned_zgfx_malloc(uncompressedSize);
+-
+- if (!pConcatenated)
+- goto fail;
+-
+- *ppDstData = pConcatenated;
+- *pDstSize = uncompressedSize;
+-
+ for (segmentNumber = 0; segmentNumber < segmentCount; segmentNumber++)
+ {
+ if (!Stream_CheckAndLogRequiredLength(TAG, stream, sizeof(UINT32)))
+@@ -450,16 +466,15 @@ int zgfx_decompress(ZGFX_CONTEXT* zgfx, const BYTE* pSrcData, UINT32 SrcSize, BY
+ if (!zgfx_decompress_segment(zgfx, stream, segmentSize))
+ goto fail;
+
+- if (zgfx->OutputCount > UINT32_MAX - used)
++ if (!zgfx_append(zgfx, &pConcatenated, uncompressedSize, &used))
+ goto fail;
++ }
+
+- if (used + zgfx->OutputCount > uncompressedSize)
+- goto fail;
++ if (used != uncompressedSize)
++ goto fail;
+
+- CopyMemory(pConcatenated, zgfx->OutputBuffer, zgfx->OutputCount);
+- pConcatenated += zgfx->OutputCount;
+- used += zgfx->OutputCount;
+- }
++ *ppDstData = pConcatenated;
++ *pDstSize = uncompressedSize;
+ }
+ else
+ {
+@@ -468,6 +483,8 @@ int zgfx_decompress(ZGFX_CONTEXT* zgfx, const BYTE* pSrcData, UINT32 SrcSize, BY
+
+ status = 1;
+ fail:
++ if (status < 0)
++ free(pConcatenated);
+ return status;
+ }
+
diff --git a/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32661.patch b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32661.patch
new file mode 100644
index 0000000000..5b3fa07a3c
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32661.patch
@@ -0,0 +1,28 @@
+From baf5543fe8f2db56edc26c8ad93e20696b905da8 Mon Sep 17 00:00:00 2001
+From: akallabeth <akallabeth@posteo.net>
+Date: Sun, 21 Apr 2024 13:56:13 +0200
+Subject: [PATCH] fix missing check in rdp_write_logon_info_v1
+
+CVE: CVE-2024-32661
+Upstream-Status: Backport [https://github.com/FreeRDP/FreeRDP/commit/71e463e31b4d69f4022d36bfc814592f56600793]
+
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ libfreerdp/core/info.c | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/libfreerdp/core/info.c b/libfreerdp/core/info.c
+index 7d6eec137..3395e4d2e 100644
+--- a/libfreerdp/core/info.c
++++ b/libfreerdp/core/info.c
+@@ -1398,6 +1398,10 @@ static BOOL rdp_write_logon_info_v1(wStream* s, logon_info* info)
+ return FALSE;
+
+ /* domain */
++ WINPR_ASSERT(info);
++ if (!info->domain || !info->username)
++ return FALSE;
++
+ len = strnlen(info->domain, charLen + 1);
+ if (len > charLen)
+ return FALSE;
diff --git a/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32662.patch b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32662.patch
new file mode 100644
index 0000000000..adf7d9e175
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3/CVE-2024-32662.patch
@@ -0,0 +1,28 @@
+From 950d2f039021c6fd8d476c08f10269c61bd1701e Mon Sep 17 00:00:00 2001
+From: akallabeth <akallabeth@posteo.net>
+Date: Mon, 22 Apr 2024 09:27:27 +0200
+Subject: [PATCH] fix length of redirection strings
+
+length field is in bytes, when converting from UCS-2 use size in WCHAR
+
+CVE: CVE-2024-32662
+Upstream-Status: Backport [https://github.com/FreeRDP/FreeRDP/commit/626d10a94a88565d957ddc30768ed08b320049a7]
+
+Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
+---
+ libfreerdp/core/redirection.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/libfreerdp/core/redirection.c b/libfreerdp/core/redirection.c
+index 8538a9056..5343a071c 100644
+--- a/libfreerdp/core/redirection.c
++++ b/libfreerdp/core/redirection.c
+@@ -243,7 +243,7 @@ static BOOL rdp_redirection_read_base64_wchar(UINT32 flag, wStream* s, UINT32* p
+ const WCHAR* wchar = (const WCHAR*)ptr;
+
+ size_t utf8_len = 0;
+- char* utf8 = ConvertWCharNToUtf8Alloc(wchar, *pLength, &utf8_len);
++ char* utf8 = ConvertWCharNToUtf8Alloc(wchar, *pLength / sizeof(WCHAR), &utf8_len);
+ if (!utf8)
+ goto fail;
+
diff --git a/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3_3.4.0.bb b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3_3.4.0.bb
index 537d19263d..a272ba0ecb 100644
--- a/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3_3.4.0.bb
+++ b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp3_3.4.0.bb
@@ -8,10 +8,23 @@ DEPENDS = "openssl libusb1 uriparser cairo icu pkcs11-helper zlib jpeg"
inherit pkgconfig cmake
SRCREV = "708f3764897e06297469a7b0507b3c9ecc041ad7"
-SRC_URI = "git://github.com/FreeRDP/FreeRDP.git;branch=master;protocol=https"
+SRC_URI = "git://github.com/FreeRDP/FreeRDP.git;branch=master;protocol=https \
+ file://CVE-2024-32039.patch \
+ file://CVE-2024-32040.patch \
+ file://CVE-2024-32458.patch \
+ file://CVE-2024-32459.patch \
+ file://CVE-2024-32460.patch \
+ file://CVE-2024-32658.patch \
+ file://CVE-2024-32659.patch \
+ file://CVE-2024-32660.patch \
+ file://CVE-2024-32661.patch \
+ file://CVE-2024-32662.patch \
+ "
S = "${WORKDIR}/git"
+CVE_PRODUCT = "freerdp"
+
PACKAGECONFIG ??= " \
${@bb.utils.filter('DISTRO_FEATURES', 'pam pulseaudio wayland x11', d)} \
${@bb.utils.contains('LICENSE_FLAGS_ACCEPTED', 'commercial', 'ffmpeg', '', d)} \
diff --git a/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp_2.11.2.bb b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp_2.11.7.bb
index 8de0e39ad7..d0d7d28b55 100644
--- a/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp_2.11.2.bb
+++ b/meta-openembedded/meta-oe/recipes-support/freerdp/freerdp_2.11.7.bb
@@ -13,11 +13,13 @@ inherit pkgconfig cmake gitpkgv
PE = "1"
PKGV = "${GITPKGVTAG}"
-SRCREV = "a38c1be9eee39a9bc22b511fffe96e63fdf8ebe7"
+SRCREV = "7f6cc93c21d7f0faad6daacca06f494f29ce882c"
SRC_URI = "git://github.com/FreeRDP/FreeRDP.git;branch=stable-2.0;protocol=https \
file://winpr-makecert-Build-with-install-RPATH.patch \
+ file://0001-Fixed-compilation-warnings.patch \
file://0001-Fix-const-qualifier-error.patch \
file://0002-Do-not-install-tools-a-CMake-targets.patch \
+ file://CVE-2024-32661.patch \
"
S = "${WORKDIR}/git"
@@ -90,3 +92,5 @@ python populate_packages:prepend () {
description='FreeRDP plugin %s',
prepend=True, extra_depends='')
}
+
+CVE_STATUS[CVE-2024-32662] = "fixed-version: 2.x is not affected, bug was introduced in 3.0.0"
diff --git a/meta-openembedded/meta-oe/recipes-support/gpm/gpm_git.bb b/meta-openembedded/meta-oe/recipes-support/gpm/gpm_git.bb
index 31503e9c62..1a96bea099 100644
--- a/meta-openembedded/meta-oe/recipes-support/gpm/gpm_git.bb
+++ b/meta-openembedded/meta-oe/recipes-support/gpm/gpm_git.bb
@@ -24,6 +24,10 @@ inherit autotools-brokensep update-rc.d systemd texinfo
INITSCRIPT_NAME = "gpm"
INITSCRIPT_PARAMS = "defaults"
+# Avoid line statements with bison/yacc
+# ERROR: lib32-gpm-1.99.7+gite82d1a653ca94aa4ed12441424da6ce780b1e530-r0 do_package_qa: QA Issue: File /usr/src/debug/lib32-gpm/1.99.7+gite82d1a653ca94aa4ed12441424da6ce780b1e530/src/prog/gpm-root.c in package lib32-gpm-src contains reference to TMPDIR [buildpaths]
+EXTRA_OEMAKE = "YFLAGS='-l'"
+
do_configure:prepend() {
(cd ${S};./autogen.sh;cd -)
}
diff --git a/meta-openembedded/meta-oe/recipes-support/hdf5/files/0001-cmake-remove-build-flags.patch b/meta-openembedded/meta-oe/recipes-support/hdf5/files/0001-cmake-remove-build-flags.patch
index 68d9c3a3cf..0d016ccb4c 100644
--- a/meta-openembedded/meta-oe/recipes-support/hdf5/files/0001-cmake-remove-build-flags.patch
+++ b/meta-openembedded/meta-oe/recipes-support/hdf5/files/0001-cmake-remove-build-flags.patch
@@ -1,6 +1,6 @@
-From 4fa437782261c0da785d4574ad3a03700f624e66 Mon Sep 17 00:00:00 2001
+From 9f5afd99cce93e68996deb2b5fa7c32737d279fe Mon Sep 17 00:00:00 2001
From: Mingli Yu <mingli.yu@windriver.com>
-Date: Tue, 19 Sep 2023 02:56:09 +0000
+Date: Tue, 16 Jul 2024 17:54:29 +0800
Subject: [PATCH] cmake: remove build flags
Don't generate the build host related info and reemove the build flags
@@ -11,11 +11,10 @@ Upstream-Status: Inappropriate [oe specific]
Signed-off-by: Mingli Yu <mingli.yu@windriver.com>
---
config/cmake/libhdf5.settings.cmake.in | 18 +++++++++---------
- src/H5make_libsettings.c | 17 -----------------
- 2 files changed, 9 insertions(+), 26 deletions(-)
+ 1 file changed, 9 insertions(+), 9 deletions(-)
diff --git a/config/cmake/libhdf5.settings.cmake.in b/config/cmake/libhdf5.settings.cmake.in
-index f60f0de..f4433c0 100644
+index deb07ed..6f255c4 100644
--- a/config/cmake/libhdf5.settings.cmake.in
+++ b/config/cmake/libhdf5.settings.cmake.in
@@ -23,23 +23,23 @@ Linking Options:
@@ -28,7 +27,7 @@ index f60f0de..f4433c0 100644
AM_LDFLAGS: @AM_LDFLAGS@
Extra libraries: @LINK_LIBS@
- Archiver: @CMAKE_AR@
-- AR_FLAGS:
+- AR_FLAGS:
- Ranlib: @CMAKE_RANLIB@
+ Archiver:
+ AR_FLAGS:
@@ -63,34 +62,6 @@ index f60f0de..f4433c0 100644
H5 C++ Flags: @HDF5_CMAKE_CXX_FLAGS@
AM C++ Flags: @AM_CXXFLAGS@
Shared C++ Library: @H5_ENABLE_SHARED_LIB@
-diff --git a/src/H5make_libsettings.c b/src/H5make_libsettings.c
-index 2661288..7c0f84f 100644
---- a/src/H5make_libsettings.c
-+++ b/src/H5make_libsettings.c
-@@ -205,23 +205,6 @@ information about the library build configuration\n";
- fprintf(rawoutstream, "/* Generated automatically by H5make_libsettings -- do not edit */\n\n\n");
- fputs(FileHeader, rawoutstream); /*the copyright notice--see top of this file */
-
-- fprintf(rawoutstream, " *\n * Created:\t\t%s %2d, %4d\n", month_name[tm->tm_mon], tm->tm_mday,
-- 1900 + tm->tm_year);
-- if (pwd || real_name[0] || host_name[0]) {
-- fprintf(rawoutstream, " *\t\t\t");
-- if (real_name[0])
-- fprintf(rawoutstream, "%s <", real_name);
--#ifdef H5_HAVE_GETPWUID
-- if (pwd)
-- fputs(pwd->pw_name, rawoutstream);
--#endif
-- if (host_name[0])
-- fprintf(rawoutstream, "@%s", host_name);
-- if (real_name[0])
-- fprintf(rawoutstream, ">");
-- fputc('\n', rawoutstream);
-- }
--
- fprintf(rawoutstream, " *\n * Purpose:\t\t");
-
- for (s = purpose; *s; s++) {
--
-2.35.5
+2.25.1
diff --git a/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2913.patch b/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2913.patch
new file mode 100644
index 0000000000..e1614bee9b
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2913.patch
@@ -0,0 +1,32 @@
+From 538a14fc5a1ed393495029d5054d934bc09844ee Mon Sep 17 00:00:00 2001
+From: bmribler <39579120+bmribler@users.noreply.github.com>
+Date: Tue, 5 Aug 2025 09:12:33 -0400
+Subject: [PATCH] Fix reading bad size in the raw header continuation message
+ (#5710)
+
+This issue was reported in GH-5376 as a heap-use-after-free vulnerability in
+one of the free lists. It appeared that the library came to this vulnerability
+after it encountered an undetected reading of a bad value. The fuzzer now failed
+with an appropriate error message.
+
+CVE: CVE-2025-2913
+Upstream-Status: Backport [https://github.com/HDFGroup/hdf5/commit/7cc8b5e1010a09c892bc97ac32d9515c3777ce07]
+(cherry picked from commit 7cc8b5e1010a09c892bc97ac32d9515c3777ce07)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/H5Ocont.c | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/src/H5Ocont.c b/src/H5Ocont.c
+index 621095a198..c03f4dd1e9 100644
+--- a/src/H5Ocont.c
++++ b/src/H5Ocont.c
+@@ -100,6 +100,8 @@ H5O__cont_decode(H5F_t *f, H5O_t H5_ATTR_UNUSED *open_oh, unsigned H5_ATTR_UNUSE
+ if (H5_IS_BUFFER_OVERFLOW(p, H5F_sizeof_size(f), p_end))
+ HGOTO_ERROR(H5E_OHDR, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
+ H5F_DECODE_LENGTH(f, p, cont->size);
++ if (cont->size == 0)
++ HGOTO_ERROR(H5E_OHDR, H5E_BADVALUE, NULL, "invalid continuation chunk size (0)");
+
+ cont->chunkno = 0;
+
diff --git a/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2914.patch b/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2914.patch
new file mode 100644
index 0000000000..c999e39d7e
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2914.patch
@@ -0,0 +1,47 @@
+From 20a34d68dd837f83d90df45ead054bbeda999830 Mon Sep 17 00:00:00 2001
+From: bmribler <39579120+bmribler@users.noreply.github.com>
+Date: Wed, 13 Aug 2025 14:45:41 -0400
+Subject: [PATCH] Refix of the attempts in PR-5209 (#5722)
+
+This PR addresses the root cause of the issue by adding a sanity-check immediately
+after reading the file space page size from the file.
+
+The same fuzzer in GH-5376 was used to verify that the assert before the vulnerability
+had occurred and that an error indicating a corrupted file space page size replaced it.
+
+CVE: CVE-2025-2914
+Upstream-Status: Backport [https://github.com/HDFGroup/hdf5/commit/804f3bace997e416917b235dbd3beac3652a8a05]
+(cherry picked from commit 804f3bace997e416917b235dbd3beac3652a8a05)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/H5Fsuper.c | 2 ++
+ src/H5Ofsinfo.c | 3 +++
+ 2 files changed, 5 insertions(+)
+
+diff --git a/src/H5Fsuper.c b/src/H5Fsuper.c
+index 3e5bc9a3a2..4de4c1feb0 100644
+--- a/src/H5Fsuper.c
++++ b/src/H5Fsuper.c
+@@ -756,6 +756,8 @@ H5F__super_read(H5F_t *f, H5P_genplist_t *fa_plist, bool initial_read)
+ if (!(flags & H5O_MSG_FLAG_WAS_UNKNOWN)) {
+ H5O_fsinfo_t fsinfo; /* File space info message from superblock extension */
+
++ memset(&fsinfo, 0, sizeof(H5O_fsinfo_t));
++
+ /* f->shared->null_fsm_addr: Whether to drop free-space to the floor */
+ /* The h5clear tool uses this property to tell the library
+ * to drop free-space to the floor
+diff --git a/src/H5Ofsinfo.c b/src/H5Ofsinfo.c
+index 5b692357fc..2bb6ea6119 100644
+--- a/src/H5Ofsinfo.c
++++ b/src/H5Ofsinfo.c
+@@ -182,6 +182,9 @@ H5O__fsinfo_decode(H5F_t *f, H5O_t H5_ATTR_UNUSED *open_oh, unsigned H5_ATTR_UNU
+ if (H5_IS_BUFFER_OVERFLOW(p, H5F_sizeof_size(f), p_end))
+ HGOTO_ERROR(H5E_OHDR, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
+ H5F_DECODE_LENGTH(f, p, fsinfo->page_size); /* File space page size */
++ /* Basic sanity check */
++ if (fsinfo->page_size == 0 || fsinfo->page_size > H5F_FILE_SPACE_PAGE_SIZE_MAX)
++ HGOTO_ERROR(H5E_OHDR, H5E_BADVALUE, NULL, "invalid page size in file space info");
+
+ if (H5_IS_BUFFER_OVERFLOW(p, 2, p_end))
+ HGOTO_ERROR(H5E_OHDR, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
diff --git a/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2915.patch b/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2915.patch
new file mode 100644
index 0000000000..83eb8ff504
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2915.patch
@@ -0,0 +1,50 @@
+From 2bab8a1ffae567d35effa777dda82d423a80bccd Mon Sep 17 00:00:00 2001
+From: Glenn Song <43005495+glennsong09@users.noreply.github.com>
+Date: Mon, 20 Oct 2025 07:47:28 -0500
+Subject: [PATCH] Fix CVE-2025-2915 (#5746)
+
+This PR fixes issue #5380, which has a heap based buffer overflow after H5MF_xfree is called on an address of 0 (file superblock). This PR changes an assert making sure addr isn't 0 to an if check.
+
+The bug was first reproduced using the fuzzer and the POC file from #5380. With this change, the heap based buffer overflow no longer occurs.
+
+CVE: CVE-2025-2915
+Upstream-Status: Backport [https://github.com/HDFGroup/hdf5/commit/26a76bafdef3a0950d348a08667de161a19b7c2c]
+(cherry picked from commit 26a76bafdef3a0950d348a08667de161a19b7c2c)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/H5Faccum.c | 3 +++
+ src/H5Ocache_image.c | 7 +++++++
+ 2 files changed, 10 insertions(+)
+
+diff --git a/src/H5Faccum.c b/src/H5Faccum.c
+index 9c4c8cdbbd..145abd1cbd 100644
+--- a/src/H5Faccum.c
++++ b/src/H5Faccum.c
+@@ -879,6 +879,9 @@ H5F__accum_free(H5F_shared_t *f_sh, H5FD_mem_t H5_ATTR_UNUSED type, haddr_t addr
+
+ /* Calculate the size of the overlap with the accumulator, etc. */
+ H5_CHECKED_ASSIGN(overlap_size, size_t, (addr + size) - accum->loc, haddr_t);
++ /* Sanity check */
++ /* Overlap size should not result in "negative" value after subtraction */
++ assert(overlap_size < accum->size);
+ new_accum_size = accum->size - overlap_size;
+
+ /* Move the accumulator buffer information to eliminate the freed block */
+diff --git a/src/H5Ocache_image.c b/src/H5Ocache_image.c
+index d91b46341c..c0ab004ec7 100644
+--- a/src/H5Ocache_image.c
++++ b/src/H5Ocache_image.c
+@@ -116,6 +116,13 @@ H5O__mdci_decode(H5F_t *f, H5O_t H5_ATTR_UNUSED *open_oh, unsigned H5_ATTR_UNUSE
+ HGOTO_ERROR(H5E_OHDR, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
+ H5F_DECODE_LENGTH(f, p, mesg->size);
+
++ if (mesg->addr >= (HADDR_UNDEF - mesg->size))
++ HGOTO_ERROR(H5E_OHDR, H5E_OVERFLOW, NULL, "address plus size overflows");
++ if (mesg->addr == HADDR_UNDEF)
++ HGOTO_ERROR(H5E_OHDR, H5E_OVERFLOW, NULL, "address is undefined");
++ if ((mesg->addr + mesg->size) > H5F_get_eoa(f, H5FD_MEM_SUPER))
++ HGOTO_ERROR(H5E_OHDR, H5E_OVERFLOW, NULL, "address plus size exceeds file eoa");
++
+ /* Set return value */
+ ret_value = (void *)mesg;
+
diff --git a/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2923-CVE-2025-6816-CVE-2025-6856.patch b/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2923-CVE-2025-6816-CVE-2025-6856.patch
new file mode 100644
index 0000000000..47dc6b1ac7
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2923-CVE-2025-6816-CVE-2025-6856.patch
@@ -0,0 +1,65 @@
+From 951ebdce0098dac1042d5e9650e655c6c1f92904 Mon Sep 17 00:00:00 2001
+From: jhendersonHDF <jhenderson@hdfgroup.org>
+Date: Fri, 26 Sep 2025 13:13:10 -0500
+Subject: [PATCH] Fix issue with handling of corrupted object header continuation messages (#5829)
+
+An HDF5 file could be specifically constructed such that an object
+header contained a corrupted continuation message which pointed
+back to itself. This eventually resulted in an internal buffer being
+allocated with too small of a size, leading to a heap buffer overflow
+when encoding an object header message into it. This has been fixed
+by checking the expected number of deserialized object header chunks
+against the actual value as chunks are being deserialized.
+
+Fixes CVE-2025-6816, CVE-2025-6856, CVE-2025-2923
+
+CVE: CVE-2025-2923, CVE-2025-6816, CVE-2025-6856
+Upstream-Status: Backport [https://github.com/HDFGroup/hdf5/commit/29c847a43db0cdc85b01cafa5a7613ea73932675]
+
+(cherry picked from commit 29c847a43db0cdc85b01cafa5a7613ea73932675)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/H5Oint.c | 17 +++++++++++------
+ 1 file changed, 11 insertions(+), 6 deletions(-)
+
+diff --git a/src/H5Oint.c b/src/H5Oint.c
+index 022ee43..a5e0072 100644
+--- a/src/H5Oint.c
++++ b/src/H5Oint.c
+@@ -1013,10 +1013,9 @@ H5O_protect(const H5O_loc_t *loc, unsigned prot_flags, bool pin_all_chunks)
+ */
+ curr_msg = 0;
+ while (curr_msg < cont_msg_info.nmsgs) {
+- H5O_chunk_proxy_t *chk_proxy; /* Proxy for chunk, to bring it into memory */
+-#ifndef NDEBUG
+- size_t chkcnt = oh->nchunks; /* Count of chunks (for sanity checking) */
+-#endif /* NDEBUG */
++ H5O_chunk_proxy_t *chk_proxy; /* Proxy for chunk, to bring it into memory */
++ unsigned chunkno; /* Chunk number for chunk proxy */
++ size_t chkcnt = oh->nchunks; /* Count of chunks (for sanity checking) */
+
+ /* Bring the chunk into the cache */
+ /* (which adds to the object header) */
+@@ -1029,14 +1028,20 @@ H5O_protect(const H5O_loc_t *loc, unsigned prot_flags, bool pin_all_chunks)
+
+ /* Sanity check */
+ assert(chk_proxy->oh == oh);
+- assert(chk_proxy->chunkno == chkcnt);
+- assert(oh->nchunks == (chkcnt + 1));
++
++ chunkno = chk_proxy->chunkno;
+
+ /* Release the chunk from the cache */
+ if (H5AC_unprotect(loc->file, H5AC_OHDR_CHK, cont_msg_info.msgs[curr_msg].addr, chk_proxy,
+ H5AC__NO_FLAGS_SET) < 0)
+ HGOTO_ERROR(H5E_OHDR, H5E_CANTUNPROTECT, NULL, "unable to release object header chunk");
+
++ if (chunkno != chkcnt)
++ HGOTO_ERROR(H5E_OHDR, H5E_BADVALUE, NULL, "incorrect chunk number for object header chunk");
++ if (oh->nchunks != (chkcnt + 1))
++ HGOTO_ERROR(H5E_OHDR, H5E_BADVALUE, NULL,
++ "incorrect number of chunks after deserializing object header chunk");
++
+ /* Advance to next continuation message */
+ curr_msg++;
+ } /* end while */
diff --git a/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2924.patch b/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2924.patch
new file mode 100644
index 0000000000..1a9185dd66
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2924.patch
@@ -0,0 +1,37 @@
+From 3a6f6c1f57c09281d4a9d11a1ae809fd21b666dd Mon Sep 17 00:00:00 2001
+From: Glenn Song <43005495+glennsong09@users.noreply.github.com>
+Date: Mon, 15 Sep 2025 07:56:54 -0500
+Subject: [PATCH] Fixes heap-based buffer overflow in H5HL__fl_deserialize by adding an overflow check.
+
+CVE: CVE-2025-2924
+Upstream-Status: Backport [https://github.com/HDFGroup/hdf5/commit/0a57195ca67d278f1cf7d01566c121048e337a59]
+
+(cherry picked from commit 0a57195ca67d278f1cf7d01566c121048e337a59)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/H5HLcache.c | 5 +++++
+ 1 file changed, 5 insertions(+)
+
+diff --git a/src/H5HLcache.c b/src/H5HLcache.c
+index d0836fe..7f412d2 100644
+--- a/src/H5HLcache.c
++++ b/src/H5HLcache.c
+@@ -225,6 +225,7 @@ H5HL__fl_deserialize(H5HL_t *heap)
+ /* check arguments */
+ assert(heap);
+ assert(!heap->freelist);
++ HDcompile_assert(sizeof(hsize_t) == sizeof(uint64_t));
+
+ /* Build free list */
+ free_block = heap->free_block;
+@@ -232,6 +233,10 @@ H5HL__fl_deserialize(H5HL_t *heap)
+ const uint8_t *image; /* Pointer into image buffer */
+
+ /* Sanity check */
++
++ if (free_block > UINT64_MAX - (2 * heap->sizeof_size))
++ HGOTO_ERROR(H5E_HEAP, H5E_BADRANGE, FAIL, "decoded heap block address overflow");
++
+ if ((free_block + (2 * heap->sizeof_size)) > heap->dblk_size)
+ HGOTO_ERROR(H5E_HEAP, H5E_BADRANGE, FAIL, "bad heap free list");
+
diff --git a/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2925.patch b/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2925.patch
new file mode 100644
index 0000000000..23bc4e5577
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-2925.patch
@@ -0,0 +1,53 @@
+From 57a511958842f50cbf07b05262f2fe95e70c141b Mon Sep 17 00:00:00 2001
+From: Glenn Song <43005495+glennsong09@users.noreply.github.com>
+Date: Thu, 9 Oct 2025 14:48:55 -0500
+Subject: [PATCH] Fix CVE-2025-2925 (#5739)
+
+This PR fixes issue #5383, which was occurring due to actual_len + H5C_IMAGE_EXTRA_SPACE being 0. When realloc was called, it freed image, but gets sent to done before new_image can be assigned to image. Because the pointer for image isn't null, it attempts to free it here again, causing the double free to occur. This PR addresses Quincey's concern and fixes the issue while preserving new_image and image.
+
+The bug was first reproduced using the fuzzer and the POC file from #5383. With this change, the double free no longer occurs.
+
+CVE: CVE-2025-2925
+Upstream-Status: Backport [https://github.com/HDFGroup/hdf5/commit/4310c19608455c17a213383d07715efb2918defc]
+
+(cherry picked from commit 4310c19608455c17a213383d07715efb2918defc)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/H5Centry.c | 10 ++++++++++
+ 1 file changed, 10 insertions(+)
+
+diff --git a/src/H5Centry.c b/src/H5Centry.c
+index 6883e89..bef93d8 100644
+--- a/src/H5Centry.c
++++ b/src/H5Centry.c
+@@ -1051,9 +1051,14 @@ H5C__load_entry(H5F_t *f,
+ */
+ do {
+ if (actual_len != len) {
++ /* Verify that the length isn't a bad value */
++ if (len == 0)
++ HGOTO_ERROR(H5E_CACHE, H5E_BADVALUE, NULL, "len is a bad value");
++
+ if (NULL == (new_image = H5MM_realloc(image, len + H5C_IMAGE_EXTRA_SPACE)))
+ HGOTO_ERROR(H5E_CACHE, H5E_CANTALLOC, NULL, "image null after H5MM_realloc()");
+ image = (uint8_t *)new_image;
++
+ #if H5C_DO_MEMORY_SANITY_CHECKS
+ H5MM_memcpy(image + len, H5C_IMAGE_SANITY_VALUE, H5C_IMAGE_EXTRA_SPACE);
+ #endif /* H5C_DO_MEMORY_SANITY_CHECKS */
+@@ -1104,10 +1109,15 @@ H5C__load_entry(H5F_t *f,
+ if (H5C__verify_len_eoa(f, type, addr, &actual_len, true) < 0)
+ HGOTO_ERROR(H5E_CACHE, H5E_BADVALUE, NULL, "actual_len exceeds EOA");
+
++ /* Verify that the length isn't 0 */
++ if (actual_len == 0)
++ HGOTO_ERROR(H5E_CACHE, H5E_BADVALUE, NULL, "actual_len is a bad value");
++
+ /* Expand buffer to new size */
+ if (NULL == (new_image = H5MM_realloc(image, actual_len + H5C_IMAGE_EXTRA_SPACE)))
+ HGOTO_ERROR(H5E_CACHE, H5E_CANTALLOC, NULL, "image null after H5MM_realloc()");
+ image = (uint8_t *)new_image;
++
+ #if H5C_DO_MEMORY_SANITY_CHECKS
+ H5MM_memcpy(image + actual_len, H5C_IMAGE_SANITY_VALUE, H5C_IMAGE_EXTRA_SPACE);
+ #endif /* H5C_DO_MEMORY_SANITY_CHECKS */
diff --git a/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-6269-CVE-2025-6270-CVE-2025-6516_01.patch b/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-6269-CVE-2025-6270-CVE-2025-6516_01.patch
new file mode 100644
index 0000000000..c09ade1c4c
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-6269-CVE-2025-6270-CVE-2025-6516_01.patch
@@ -0,0 +1,65 @@
+From ac57aaf0186ba175947d370496934fd399fbc225 Mon Sep 17 00:00:00 2001
+From: aled-ua <bugbuster.cc@gmail.com>
+Date: Wed, 15 Jan 2025 15:02:25 -0600
+Subject: [PATCH] Fix vuln OSV-2023-77 (#5210)
+
+CVE: CVE-2025-6269, CVE-2025-6270, CVE-2025-6516
+Upstream-Status: Backport [https://github.com/HDFGroup/hdf5/commit/7f27ba8c3a8483c3d7e5e2cb21fefb2c7563422d]
+(cherry picked from commit 7f27ba8c3a8483c3d7e5e2cb21fefb2c7563422d)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/H5Cimage.c | 13 +++++++++----
+ 1 file changed, 9 insertions(+), 4 deletions(-)
+
+diff --git a/src/H5Cimage.c b/src/H5Cimage.c
+index ec1af787d5..72dc52dafb 100644
+--- a/src/H5Cimage.c
++++ b/src/H5Cimage.c
+@@ -118,7 +118,8 @@ do { \
+ /* Helper routines */
+ static size_t H5C__cache_image_block_entry_header_size(const H5F_t *f);
+ static size_t H5C__cache_image_block_header_size(const H5F_t *f);
+-static herr_t H5C__decode_cache_image_header(const H5F_t *f, H5C_t *cache_ptr, const uint8_t **buf);
++static herr_t H5C__decode_cache_image_header(const H5F_t *f, H5C_t *cache_ptr, const uint8_t **buf,
++ size_t buf_size);
+ #ifndef NDEBUG /* only used in assertions */
+ static herr_t H5C__decode_cache_image_entry(const H5F_t *f, const H5C_t *cache_ptr, const uint8_t **buf,
+ unsigned entry_num);
+@@ -299,7 +300,7 @@ H5C__construct_cache_image_buffer(H5F_t *f, H5C_t *cache_ptr)
+ /* needed for sanity checks */
+ fake_cache_ptr->image_len = cache_ptr->image_len;
+ q = (const uint8_t *)cache_ptr->image_buffer;
+- status = H5C__decode_cache_image_header(f, fake_cache_ptr, &q);
++ status = H5C__decode_cache_image_header(f, fake_cache_ptr, &q, cache_ptr->image_len + 1);
+ assert(status >= 0);
+
+ assert(NULL != p);
+@@ -1269,7 +1270,7 @@ H5C__cache_image_block_header_size(const H5F_t *f)
+ *-------------------------------------------------------------------------
+ */
+ static herr_t
+-H5C__decode_cache_image_header(const H5F_t *f, H5C_t *cache_ptr, const uint8_t **buf)
++H5C__decode_cache_image_header(const H5F_t *f, H5C_t *cache_ptr, const uint8_t **buf, size_t buf_size)
+ {
+ uint8_t version;
+ uint8_t flags;
+@@ -1289,6 +1290,10 @@ H5C__decode_cache_image_header(const H5F_t *f, H5C_t *cache_ptr, const uint8_t *
+ /* Point to buffer to decode */
+ p = *buf;
+
++ /* Ensure buffer has enough data for signature comparison */
++ if (H5_IS_BUFFER_OVERFLOW(p, H5C__MDCI_BLOCK_SIGNATURE_LEN, *buf + buf_size - 1))
++ HGOTO_ERROR(H5E_CACHE, H5E_OVERFLOW, FAIL, "Insufficient buffer size for signature");
++
+ /* Check signature */
+ if (memcmp(p, H5C__MDCI_BLOCK_SIGNATURE, (size_t)H5C__MDCI_BLOCK_SIGNATURE_LEN) != 0)
+ HGOTO_ERROR(H5E_CACHE, H5E_BADVALUE, FAIL, "Bad metadata cache image header signature");
+@@ -2388,7 +2393,7 @@ H5C__reconstruct_cache_contents(H5F_t *f, H5C_t *cache_ptr)
+
+ /* Decode metadata cache image header */
+ p = (uint8_t *)cache_ptr->image_buffer;
+- if (H5C__decode_cache_image_header(f, cache_ptr, &p) < 0)
++ if (H5C__decode_cache_image_header(f, cache_ptr, &p, cache_ptr->image_len + 1) < 0)
+ HGOTO_ERROR(H5E_CACHE, H5E_CANTDECODE, FAIL, "cache image header decode failed");
+ assert((size_t)(p - (uint8_t *)cache_ptr->image_buffer) < cache_ptr->image_len);
+
diff --git a/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-6269-CVE-2025-6270-CVE-2025-6516_02.patch b/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-6269-CVE-2025-6270-CVE-2025-6516_02.patch
new file mode 100644
index 0000000000..f7324f58c1
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/hdf5/files/CVE-2025-6269-CVE-2025-6270-CVE-2025-6516_02.patch
@@ -0,0 +1,252 @@
+From 89e3e43aa0f64a3bbd253bef658846d9ff030bdd Mon Sep 17 00:00:00 2001
+From: bmribler <39579120+bmribler@users.noreply.github.com>
+Date: Thu, 25 Sep 2025 22:17:14 -0400
+Subject: [PATCH] Fixed CVE-2025-6269 (#5850)
+
+The GitHub issue #5579 included several security vulnerabilities in function
+H5C__reconstruct_cache_entry().
+
+This PR addressed them by:
+- adding buffer size argument to the function
+- adding buffer overflow checks
+- adding input validations
+- releasing allocated resource on failure
+
+These changes addressed the crashes reported. However, there is a skiplist
+crash during the unwinding process that has to be investigated.
+
+CVE: CVE-2025-6269, CVE-2025-6270, CVE-2025-6516
+Upstream-Status: Backport [https://github.com/HDFGroup/hdf5/commit/3914bb7f7ec7105d8bfbeb3aebd92e867cff5b70]
+(cherry picked from commit 3914bb7f7ec7105d8bfbeb3aebd92e867cff5b70)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/H5Cimage.c | 84 ++++++++++++++++++++++++++++++++++++++------------
+ src/H5Ocont.c | 5 +--
+ 2 files changed, 68 insertions(+), 21 deletions(-)
+
+diff --git a/src/H5Cimage.c b/src/H5Cimage.c
+index 72dc52dafb..b97be228ed 100644
+--- a/src/H5Cimage.c
++++ b/src/H5Cimage.c
+@@ -132,7 +132,8 @@ static void H5C__prep_for_file_close__compute_fd_heights_real(H5C_cache_entry_
+ static herr_t H5C__prep_for_file_close__setup_image_entries_array(H5C_t *cache_ptr);
+ static herr_t H5C__prep_for_file_close__scan_entries(const H5F_t *f, H5C_t *cache_ptr);
+ static herr_t H5C__reconstruct_cache_contents(H5F_t *f, H5C_t *cache_ptr);
+-static H5C_cache_entry_t *H5C__reconstruct_cache_entry(const H5F_t *f, H5C_t *cache_ptr, const uint8_t **buf);
++static H5C_cache_entry_t *H5C__reconstruct_cache_entry(const H5F_t *f, H5C_t *cache_ptr, hsize_t *buf_size,
++ const uint8_t **buf);
+ static herr_t H5C__write_cache_image_superblock_msg(H5F_t *f, bool create);
+ static herr_t H5C__read_cache_image(H5F_t *f, H5C_t *cache_ptr);
+ static herr_t H5C__write_cache_image(H5F_t *f, const H5C_t *cache_ptr);
+@@ -2377,6 +2378,7 @@ H5C__reconstruct_cache_contents(H5F_t *f, H5C_t *cache_ptr)
+ {
+ H5C_cache_entry_t *pf_entry_ptr; /* Pointer to prefetched entry */
+ H5C_cache_entry_t *parent_ptr; /* Pointer to parent of prefetched entry */
++ hsize_t image_len; /* Image length */
+ const uint8_t *p; /* Pointer into image buffer */
+ unsigned u, v; /* Local index variable */
+ herr_t ret_value = SUCCEED; /* Return value */
+@@ -2392,10 +2394,11 @@ H5C__reconstruct_cache_contents(H5F_t *f, H5C_t *cache_ptr)
+ assert(cache_ptr->image_len > 0);
+
+ /* Decode metadata cache image header */
+- p = (uint8_t *)cache_ptr->image_buffer;
+- if (H5C__decode_cache_image_header(f, cache_ptr, &p, cache_ptr->image_len + 1) < 0)
++ p = (uint8_t *)cache_ptr->image_buffer;
++ image_len = cache_ptr->image_len;
++ if (H5C__decode_cache_image_header(f, cache_ptr, &p, image_len + 1) < 0)
+ HGOTO_ERROR(H5E_CACHE, H5E_CANTDECODE, FAIL, "cache image header decode failed");
+- assert((size_t)(p - (uint8_t *)cache_ptr->image_buffer) < cache_ptr->image_len);
++ assert((size_t)(p - (uint8_t *)cache_ptr->image_buffer) < image_len);
+
+ /* The image_data_len and # of entries should be defined now */
+ assert(cache_ptr->image_data_len > 0);
+@@ -2407,7 +2410,7 @@ H5C__reconstruct_cache_contents(H5F_t *f, H5C_t *cache_ptr)
+ /* Create the prefetched entry described by the ith
+ * entry in cache_ptr->image_entrise.
+ */
+- if (NULL == (pf_entry_ptr = H5C__reconstruct_cache_entry(f, cache_ptr, &p)))
++ if (NULL == (pf_entry_ptr = H5C__reconstruct_cache_entry(f, cache_ptr, &image_len, &p)))
+ HGOTO_ERROR(H5E_CACHE, H5E_SYSTEM, FAIL, "reconstruction of cache entry failed");
+
+ /* Note that we make no checks on available cache space before
+@@ -2563,19 +2566,21 @@ done:
+ *-------------------------------------------------------------------------
+ */
+ static H5C_cache_entry_t *
+-H5C__reconstruct_cache_entry(const H5F_t *f, H5C_t *cache_ptr, const uint8_t **buf)
++H5C__reconstruct_cache_entry(const H5F_t *f, H5C_t *cache_ptr, hsize_t *buf_size, const uint8_t **buf)
+ {
+ H5C_cache_entry_t *pf_entry_ptr = NULL; /* Reconstructed cache entry */
+ uint8_t flags = 0;
+ bool is_dirty = false;
++ haddr_t eoa;
++ bool is_fd_parent = false;
+ #ifndef NDEBUG /* only used in assertions */
+- bool in_lru = false;
+- bool is_fd_parent = false;
+- bool is_fd_child = false;
++ bool in_lru = false;
++ bool is_fd_child = false;
+ #endif
+- const uint8_t *p;
+ bool file_is_rw;
+- H5C_cache_entry_t *ret_value = NULL; /* Return value */
++ const uint8_t *p;
++ const uint8_t *p_end = *buf + *buf_size - 1; /* Pointer to last valid byte in buffer */
++ H5C_cache_entry_t *ret_value = NULL; /* Return value */
+
+ FUNC_ENTER_PACKAGE
+
+@@ -2595,9 +2600,15 @@ H5C__reconstruct_cache_entry(const H5F_t *f, H5C_t *cache_ptr, const uint8_t **b
+ p = *buf;
+
+ /* Decode type id */
++ if (H5_IS_BUFFER_OVERFLOW(p, 1, p_end))
++ HGOTO_ERROR(H5E_CACHE, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
+ pf_entry_ptr->prefetch_type_id = *p++;
++ if (pf_entry_ptr->prefetch_type_id < H5AC_BT_ID || pf_entry_ptr->prefetch_type_id >= H5AC_NTYPES)
++ HGOTO_ERROR(H5E_CACHE, H5E_BADVALUE, NULL, "type id is out of valid range");
+
+ /* Decode flags */
++ if (H5_IS_BUFFER_OVERFLOW(p, 1, p_end))
++ HGOTO_ERROR(H5E_CACHE, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
+ flags = *p++;
+ if (flags & H5C__MDCI_ENTRY_DIRTY_FLAG)
+ is_dirty = true;
+@@ -2625,19 +2636,31 @@ H5C__reconstruct_cache_entry(const H5F_t *f, H5C_t *cache_ptr, const uint8_t **b
+ pf_entry_ptr->is_dirty = (is_dirty && file_is_rw);
+
+ /* Decode ring */
++ if (H5_IS_BUFFER_OVERFLOW(p, 1, p_end))
++ HGOTO_ERROR(H5E_CACHE, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
+ pf_entry_ptr->ring = *p++;
+- assert(pf_entry_ptr->ring > (uint8_t)(H5C_RING_UNDEFINED));
+- assert(pf_entry_ptr->ring < (uint8_t)(H5C_RING_NTYPES));
++ if (pf_entry_ptr->ring >= (uint8_t)(H5C_RING_NTYPES))
++ HGOTO_ERROR(H5E_CACHE, H5E_BADVALUE, NULL, "ring is out of valid range");
+
+ /* Decode age */
++ if (H5_IS_BUFFER_OVERFLOW(p, 1, p_end))
++ HGOTO_ERROR(H5E_CACHE, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
+ pf_entry_ptr->age = *p++;
++ if (pf_entry_ptr->age > H5AC__CACHE_IMAGE__ENTRY_AGEOUT__MAX)
++ HGOTO_ERROR(H5E_CACHE, H5E_BADVALUE, NULL, "entry age is out of policy range");
+
+ /* Decode dependency child count */
++ if (H5_IS_BUFFER_OVERFLOW(p, 2, p_end))
++ HGOTO_ERROR(H5E_CACHE, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
+ UINT16DECODE(p, pf_entry_ptr->fd_child_count);
+- assert((is_fd_parent && pf_entry_ptr->fd_child_count > 0) ||
+- (!is_fd_parent && pf_entry_ptr->fd_child_count == 0));
++ if (is_fd_parent && pf_entry_ptr->fd_child_count <= 0)
++ HGOTO_ERROR(H5E_CACHE, H5E_BADVALUE, NULL, "parent entry has no children");
++ else if (!is_fd_parent && pf_entry_ptr->fd_child_count != 0)
++ HGOTO_ERROR(H5E_CACHE, H5E_BADVALUE, NULL, "non-parent entry has children");
+
+ /* Decode dirty dependency child count */
++ if (H5_IS_BUFFER_OVERFLOW(p, 2, p_end))
++ HGOTO_ERROR(H5E_CACHE, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
+ UINT16DECODE(p, pf_entry_ptr->fd_dirty_child_count);
+ if (!file_is_rw)
+ pf_entry_ptr->fd_dirty_child_count = 0;
+@@ -2645,20 +2668,32 @@ H5C__reconstruct_cache_entry(const H5F_t *f, H5C_t *cache_ptr, const uint8_t **b
+ HGOTO_ERROR(H5E_CACHE, H5E_BADVALUE, NULL, "invalid dirty flush dependency child count");
+
+ /* Decode dependency parent count */
++ if (H5_IS_BUFFER_OVERFLOW(p, 2, p_end))
++ HGOTO_ERROR(H5E_CACHE, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
+ UINT16DECODE(p, pf_entry_ptr->fd_parent_count);
+ assert((is_fd_child && pf_entry_ptr->fd_parent_count > 0) ||
+ (!is_fd_child && pf_entry_ptr->fd_parent_count == 0));
+
+ /* Decode index in LRU */
++ if (H5_IS_BUFFER_OVERFLOW(p, 4, p_end))
++ HGOTO_ERROR(H5E_CACHE, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
+ INT32DECODE(p, pf_entry_ptr->lru_rank);
+ assert((in_lru && pf_entry_ptr->lru_rank >= 0) || (!in_lru && pf_entry_ptr->lru_rank == -1));
+
+ /* Decode entry offset */
++ if (H5_IS_BUFFER_OVERFLOW(p, H5F_SIZEOF_ADDR(f), p_end))
++ HGOTO_ERROR(H5E_CACHE, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
+ H5F_addr_decode(f, &p, &pf_entry_ptr->addr);
+- if (!H5_addr_defined(pf_entry_ptr->addr))
+- HGOTO_ERROR(H5E_CACHE, H5E_BADVALUE, NULL, "invalid entry offset");
++
++ /* Validate address range */
++ eoa = H5F_get_eoa(f, H5FD_MEM_DEFAULT);
++ if (!H5_addr_defined(pf_entry_ptr->addr) || H5_addr_overflow(pf_entry_ptr->addr, pf_entry_ptr->size) ||
++ H5_addr_ge(pf_entry_ptr->addr + pf_entry_ptr->size, eoa))
++ HGOTO_ERROR(H5E_CACHE, H5E_BADVALUE, NULL, "invalid entry address range");
+
+ /* Decode entry length */
++ if (H5_IS_BUFFER_OVERFLOW(p, H5F_SIZEOF_SIZE(f), p_end))
++ HGOTO_ERROR(H5E_CACHE, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
+ H5F_DECODE_LENGTH(f, p, pf_entry_ptr->size);
+ if (pf_entry_ptr->size == 0)
+ HGOTO_ERROR(H5E_CACHE, H5E_BADVALUE, NULL, "invalid entry size");
+@@ -2679,6 +2714,9 @@ H5C__reconstruct_cache_entry(const H5F_t *f, H5C_t *cache_ptr, const uint8_t **b
+ "memory allocation failed for fd parent addrs buffer");
+
+ for (u = 0; u < pf_entry_ptr->fd_parent_count; u++) {
++
++ if (H5_IS_BUFFER_OVERFLOW(p, H5F_SIZEOF_ADDR(f), p_end))
++ HGOTO_ERROR(H5E_CACHE, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
+ H5F_addr_decode(f, &p, &(pf_entry_ptr->fd_parent_addrs[u]));
+ if (!H5_addr_defined(pf_entry_ptr->fd_parent_addrs[u]))
+ HGOTO_ERROR(H5E_CACHE, H5E_BADVALUE, NULL, "invalid flush dependency parent offset");
+@@ -2694,6 +2732,8 @@ H5C__reconstruct_cache_entry(const H5F_t *f, H5C_t *cache_ptr, const uint8_t **b
+ #endif /* H5C_DO_MEMORY_SANITY_CHECKS */
+
+ /* Copy the entry image from the cache image block */
++ if (H5_IS_BUFFER_OVERFLOW(p, pf_entry_ptr->size, p_end))
++ HGOTO_ERROR(H5E_CACHE, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
+ H5MM_memcpy(pf_entry_ptr->image_ptr, p, pf_entry_ptr->size);
+ p += pf_entry_ptr->size;
+
+@@ -2708,14 +2748,20 @@ H5C__reconstruct_cache_entry(const H5F_t *f, H5C_t *cache_ptr, const uint8_t **b
+ /* Sanity checks */
+ assert(pf_entry_ptr->size > 0 && pf_entry_ptr->size < H5C_MAX_ENTRY_SIZE);
+
+- /* Update buffer pointer */
++ /* Update buffer pointer and buffer len */
++ *buf_size -= (hsize_t)(p - *buf);
+ *buf = p;
+
+ ret_value = pf_entry_ptr;
+
+ done:
+- if (NULL == ret_value && pf_entry_ptr)
++ if (NULL == ret_value && pf_entry_ptr) {
++ if (pf_entry_ptr->image_ptr)
++ H5MM_xfree(pf_entry_ptr->image_ptr);
++ if (pf_entry_ptr->fd_parent_count > 0 && pf_entry_ptr->fd_parent_addrs)
++ H5MM_xfree(pf_entry_ptr->fd_parent_addrs);
+ pf_entry_ptr = H5FL_FREE(H5C_cache_entry_t, pf_entry_ptr);
++ }
+
+ FUNC_LEAVE_NOAPI(ret_value)
+ } /* H5C__reconstruct_cache_entry() */
+diff --git a/src/H5Ocont.c b/src/H5Ocont.c
+index c03f4dd1e9..4b1840448a 100644
+--- a/src/H5Ocont.c
++++ b/src/H5Ocont.c
+@@ -93,6 +93,9 @@ H5O__cont_decode(H5F_t *f, H5O_t H5_ATTR_UNUSED *open_oh, unsigned H5_ATTR_UNUSE
+ HGOTO_ERROR(H5E_OHDR, H5E_NOSPACE, NULL, "memory allocation failed");
+
+ /* Decode */
++
++ cont->chunkno = 0;
++
+ if (H5_IS_BUFFER_OVERFLOW(p, H5F_sizeof_addr(f), p_end))
+ HGOTO_ERROR(H5E_OHDR, H5E_OVERFLOW, NULL, "ran off end of input buffer while decoding");
+ H5F_addr_decode(f, &p, &(cont->addr));
+@@ -103,8 +106,6 @@ H5O__cont_decode(H5F_t *f, H5O_t H5_ATTR_UNUSED *open_oh, unsigned H5_ATTR_UNUSE
+ if (cont->size == 0)
+ HGOTO_ERROR(H5E_OHDR, H5E_BADVALUE, NULL, "invalid continuation chunk size (0)");
+
+- cont->chunkno = 0;
+-
+ /* Set return value */
+ ret_value = cont;
+
diff --git a/meta-openembedded/meta-oe/recipes-support/hdf5/hdf5_1.14.2.bb b/meta-openembedded/meta-oe/recipes-support/hdf5/hdf5_1.14.4-3.bb
index b8a81bb0b7..80828ad30c 100644
--- a/meta-openembedded/meta-oe/recipes-support/hdf5/hdf5_1.14.2.bb
+++ b/meta-openembedded/meta-oe/recipes-support/hdf5/hdf5_1.14.4-3.bb
@@ -5,18 +5,26 @@ HOMEPAGE = "https://www.hdfgroup.org/"
SECTION = "libs"
LICENSE = "HDF5"
-LIC_FILES_CHKSUM = "file://COPYING;md5=9ba0f3d878ab6c2403c86e9b0362d998"
+LIC_FILES_CHKSUM = "file://COPYING;md5=adebb1ecf1b3b80c13359e18ef67301e"
inherit cmake siteinfo qemu multilib_header multilib_script
DEPENDS += "qemu-native zlib"
SRC_URI = " \
- https://support.hdfgroup.org/ftp/HDF5/releases/hdf5-1.14/hdf5-${PV}/src/${BPN}-${PV}.tar.bz2 \
+ https://support.hdfgroup.org/ftp/HDF5/releases/hdf5-1.14/hdf5-1.14.4/src/${BPN}-${PV}.tar.gz \
file://0002-Remove-suffix-shared-from-shared-library-name.patch \
file://0001-cmake-remove-build-flags.patch \
+ file://CVE-2025-2913.patch \
+ file://CVE-2025-2914.patch \
+ file://CVE-2025-2915.patch \
+ file://CVE-2025-2923-CVE-2025-6816-CVE-2025-6856.patch \
+ file://CVE-2025-2924.patch \
+ file://CVE-2025-2925.patch \
+ file://CVE-2025-6269-CVE-2025-6270-CVE-2025-6516_01.patch \
+ file://CVE-2025-6269-CVE-2025-6270-CVE-2025-6516_02.patch \
"
-SRC_URI[sha256sum] = "ea3c5e257ef322af5e77fc1e52ead3ad6bf3bb4ac06480dd17ee3900d7a24cfb"
+SRC_URI[sha256sum] = "019ac451d9e1cf89c0482ba2a06f07a46166caf23f60fea5ef3c37724a318e03"
FILES:${PN} += "${libdir}/libhdf5.settings ${datadir}/*"
@@ -44,10 +52,13 @@ MULTILIB_SCRIPTS += "${PN}:${bindir}/h5cc \
${PN}:${bindir}/h5hlcc \
"
+do_configure:append() {
+ sed -i -e 's|${WORKDIR}||g' ${B}/src/libhdf5.settings
+ sed -i -e 's|${WORKDIR}||g' ${B}/src/H5build_settings.c
+}
+
do_install:append() {
# Used for generating config files on target
- install -m 755 ${B}/bin/H5detect ${D}${bindir}
- install -m 755 ${B}/bin/H5make_libsettings ${D}${bindir}
oe_multilib_header H5pubconf.h
# remove the buildpath
sed -i -e 's|${RECIPE_SYSROOT}||g' ${D}${libdir}/pkgconfig/hdf5.pc
diff --git a/meta-openembedded/meta-oe/recipes-support/hunspell/hunspell-dictionaries.bb b/meta-openembedded/meta-oe/recipes-support/hunspell/hunspell-dictionaries.bb
index 0ec426afb9..12231443a4 100644
--- a/meta-openembedded/meta-oe/recipes-support/hunspell/hunspell-dictionaries.bb
+++ b/meta-openembedded/meta-oe/recipes-support/hunspell/hunspell-dictionaries.bb
@@ -135,7 +135,7 @@ RDEPENDS:${PN} = "hunspell"
PV = "0.0.0+git"
SRCREV = "820a65e539e34a3a8c2a855d2450b84745c624ee"
-SRC_URI = "git://github.com/wooorm/dictionaries.git;branch=master;protocol=https"
+SRC_URI = "git://github.com/wooorm/dictionaries.git;branch=main;protocol=https"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-oe/recipes-support/imagemagick/imagemagick_7.1.1.bb b/meta-openembedded/meta-oe/recipes-support/imagemagick/imagemagick_7.1.1.bb
index 6ab8a61b9b..752fef303b 100644
--- a/meta-openembedded/meta-oe/recipes-support/imagemagick/imagemagick_7.1.1.bb
+++ b/meta-openembedded/meta-oe/recipes-support/imagemagick/imagemagick_7.1.1.bb
@@ -36,13 +36,24 @@ PACKAGECONFIG[x11] = "--with-x,--without-x,virtual/libx11 libxext libxt"
PACKAGECONFIG[xml] = "--with-xml,--without-xml,libxml2"
do_install:append:class-target() {
- for file in MagickCore-config.im7 MagickWand-config.im7 Magick++-config.im7; do
- sed -i 's,${STAGING_DIR_TARGET},,g' ${D}${bindir}/"$file"
+ for file in MagickCore-config.im7 MagickWand-config.im7; do
+ sed -i 's,${STAGING_DIR_TARGET},,g' "${D}${bindir}/$file"
done
- sed -i 's,${S},,g' ${D}${libdir}/ImageMagick-${BASE_PV}/config-Q16HDRI/configure.xml
- sed -i 's,${B},,g' ${D}${libdir}/ImageMagick-${BASE_PV}/config-Q16HDRI/configure.xml
- sed -i 's,${RECIPE_SYSROOT},,g' ${D}${libdir}/ImageMagick-${BASE_PV}/config-Q16HDRI/configure.xml
- sed -i 's,${HOSTTOOLS_DIR},${bindir},g' ${D}${sysconfdir}/ImageMagick-7/delegates.xml
+
+ if ${@bb.utils.contains('PACKAGECONFIG', 'cxx', 'true', 'false', d)}; then
+ sed -i 's,${STAGING_DIR_TARGET},,g' "${D}${bindir}/Magick++-config.im7"
+ fi
+
+ if ${@bb.utils.contains('PACKAGECONFIG', 'xml', 'true', 'false', d)}; then
+ xml_config="${D}${libdir}/ImageMagick-${BASE_PV}/config-Q16HDRI/configure.xml"
+ sed -i 's,${S},,g' "$xml_config"
+ sed -i 's,${B},,g' "$xml_config"
+ sed -i 's,${RECIPE_SYSROOT},,g' "$xml_config"
+ fi
+
+ if ${@bb.utils.contains_any('PACKAGECONFIG', 'webp openjpeg', 'true', 'false', d)}; then
+ sed -i 's,${HOSTTOOLS_DIR},${bindir},g' "${D}${sysconfdir}/ImageMagick-7/delegates.xml"
+ fi
}
FILES:${PN} += "${libdir}/ImageMagick-${BASE_PV}/config-Q16* \
@@ -99,3 +110,73 @@ ALTERNATIVE_LINK_NAME[montage.1] = "${mandir}/man1/montage.1"
ALTERNATIVE_TARGET[montage.1] = "${mandir}/man1/montage.im7.1"
ALTERNATIVE_LINK_NAME[stream.1] = "${mandir}/man1/stream.1"
ALTERNATIVE_TARGET[stream.1] = "${mandir}/man1/stream.im7.1"
+
+CVE_STATUS[CVE-2007-1667] = "cpe-incorrect: CVE should not include a CPE for imagemagick"
+CVE_STATUS[CVE-2014-9804] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9805] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9806] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9807] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9808] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9809] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9810] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9811] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9812] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9813] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9814] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9815] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9816] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9817] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9818] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9819] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9820] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9821] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9822] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9823] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9824] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9825] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9826] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9827] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9828] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9829] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9830] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9831] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9848] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9852] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9853] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9854] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2014-9907] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-10062] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 7.0.1-10"
+CVE_STATUS[CVE-2016-10144] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.7-1"
+CVE_STATUS[CVE-2016-10145] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.7-1"
+CVE_STATUS[CVE-2016-10146] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.6-8"
+CVE_STATUS[CVE-2016-5118] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 7.0.1-7"
+CVE_STATUS[CVE-2016-7513] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7514] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 7.0.1-0"
+CVE_STATUS[CVE-2016-7515] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7516] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7517] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7518] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7519] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7520] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7521] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7522] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7523] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7524] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7525] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7526] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7527] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7528] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7529] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7530] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7531] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 7.0.1-0"
+CVE_STATUS[CVE-2016-7532] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7533] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7534] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7535] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7536] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7537] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2016-7538] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 6.9.4-0"
+CVE_STATUS[CVE-2017-5506] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 7.0.4-4"
+CVE_STATUS[CVE-2017-5509] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 7.0.4-4"
+CVE_STATUS[CVE-2017-5510] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 7.0.4-4"
+CVE_STATUS[CVE-2017-5511] = "cpe-incorrect: The current version (7.1.1) is not affected by the CVE which affects versions at least earlier than 7.0.4-3"
diff --git a/meta-openembedded/meta-oe/recipes-support/iniparser/iniparser/CVE-2025-0633.patch b/meta-openembedded/meta-oe/recipes-support/iniparser/iniparser/CVE-2025-0633.patch
new file mode 100644
index 0000000000..a9d2a19b2c
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/iniparser/iniparser/CVE-2025-0633.patch
@@ -0,0 +1,37 @@
+From 072a39a772a38c475e35a1be311304ca99e9de7f Mon Sep 17 00:00:00 2001
+From: Lars Möllendorf <lars@moellendorf.eu>
+Date: Sun, 26 Jan 2025 08:48:23 +0100
+Subject: [PATCH] Fix heap overflow in `iniparser_dumpsection_ini()`
+
+...reported in #177
+
+As suggested by the issue reporter this is fixed by returning from
+`iniparser_dumpsection_ini()` in case the length of the passed section name
+of dictionary to dump was bigger than the size of the internal buffer used
+to copy this string to.
+
+Changelog: changed
+
+CVE: CVE-2025-0633
+
+Upstream-Status: Backport [https://gitlab.com/iniparser/iniparser/-/commit/072a39a772a38c475e35a1be311304ca99e9de7f]
+
+Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
+---
+ src/iniparser.c | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/src/iniparser.c b/src/iniparser.c
+index dbceb20..2aeecf4 100644
+--- a/src/iniparser.c
++++ b/src/iniparser.c
+@@ -301,6 +301,7 @@ void iniparser_dumpsection_ini(const dictionary * d, const char * s, FILE * f)
+
+ if (d==NULL || f==NULL) return ;
+ if (! iniparser_find_entry(d, s)) return ;
++ if (strlen(s) > sizeof(keym)) return;
+
+ seclen = (int)strlen(s);
+ fprintf(f, "\n[%s]\n", s);
+--
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-support/iniparser/iniparser_4.1.bb b/meta-openembedded/meta-oe/recipes-support/iniparser/iniparser_4.1.bb
index c80668d279..13a3a1f979 100644
--- a/meta-openembedded/meta-oe/recipes-support/iniparser/iniparser_4.1.bb
+++ b/meta-openembedded/meta-oe/recipes-support/iniparser/iniparser_4.1.bb
@@ -12,6 +12,7 @@ SRC_URI = "git://github.com/ndevilla/iniparser.git;protocol=https;branch=master
file://0001-iniparser.pc-Make-libpath-a-variable.patch \
file://Add-CMake-support.patch \
file://CVE-2023-33461.patch \
+ file://CVE-2025-0633.patch \
"
SRCREV= "deb85ad4936d4ca32cc2260ce43323d47936410d"
diff --git a/meta-openembedded/meta-oe/recipes-support/lcov/lcov_1.16.bb b/meta-openembedded/meta-oe/recipes-support/lcov/lcov_1.16.bb
index 22d68814ee..6b8c105d3e 100755
--- a/meta-openembedded/meta-oe/recipes-support/lcov/lcov_1.16.bb
+++ b/meta-openembedded/meta-oe/recipes-support/lcov/lcov_1.16.bb
@@ -9,13 +9,13 @@ LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=751419260aa954499f7abaabaa882bbe"
RDEPENDS:${PN} += " \
+ libjson-perl \
perl \
- perl-module-filehandle \
- perl-module-getopt-std \
- perl-module-digest-md5 \
- perl-module-digest-sha \
+ perl-module-compress-zlib \
perl-module-constant \
perl-module-cwd \
+ perl-module-digest-md5 \
+ perl-module-digest-sha \
perl-module-errno \
perl-module-file-basename \
perl-module-file-copy \
@@ -25,12 +25,16 @@ RDEPENDS:${PN} += " \
perl-module-file-spec-functions \
perl-module-file-spec-unix \
perl-module-file-temp \
+ perl-module-filehandle \
perl-module-getopt-long \
+ perl-module-getopt-std \
perl-module-list-util \
+ perl-module-load \
+ perl-module-metadata \
perl-module-mro \
perl-module-overload \
- perl-module-overloading \
perl-module-overload-numbers \
+ perl-module-overloading \
perl-module-parent \
perl-module-pod-usage \
perl-module-posix \
@@ -46,10 +50,19 @@ RDEPENDS:${PN}:append:class-target = " \
gcov \
gcov-symlinks \
"
+
+RDEPENDS:${PN}:append:class-nativesdk = " \
+ nativesdk-gcov \
+ nativesdk-gcov-symlinks \
+"
+
SRC_URI = "https://github.com/linux-test-project/lcov/releases/download/v${PV}/lcov-${PV}.tar.gz"
SRC_URI[md5sum] = "bfee0cef50d7b7bd1df03bfadf68dcef"
SRC_URI[sha256sum] = "987031ad5528c8a746d4b52b380bc1bffe412de1f2b9c2ba5224995668e3240b"
+UPSTREAM_CHECK_URI = "https://github.com/linux-test-project/lcov/releases"
+UPSTREAM_CHECK_REGEX = "(?P<pver>\d+(\.\d+)+)"
+
do_install() {
oe_runmake install PREFIX=${D}${prefix} CFG_DIR=${D}${sysconfdir} LCOV_PERL_PATH="/usr/bin/env perl"
}
diff --git a/meta-openembedded/meta-oe/recipes-support/libatasmart/libatasmart_0.19.bb b/meta-openembedded/meta-oe/recipes-support/libatasmart/libatasmart_0.19.bb
index f747ecbf72..59b26d821e 100644
--- a/meta-openembedded/meta-oe/recipes-support/libatasmart/libatasmart_0.19.bb
+++ b/meta-openembedded/meta-oe/recipes-support/libatasmart/libatasmart_0.19.bb
@@ -5,7 +5,7 @@ LIC_FILES_CHKSUM = "file://LGPL;md5=2d5025d4aa3495befef8f17206a5b0a1"
DEPENDS = "udev"
SRCREV = "de6258940960443038b4c1651dfda3620075e870"
-SRC_URI = "git://git.0pointer.de/libatasmart.git;branch=master \
+SRC_URI = "git://git.0pointer.net/libatasmart.git;protocol=https;branch=master \
file://0001-Makefile.am-add-CFLAGS-and-LDFLAGS-definiton.patch \
"
diff --git a/meta-openembedded/meta-oe/recipes-support/libeigen/libeigen/0002-Remove-LGPL-Code-and-references.patch b/meta-openembedded/meta-oe/recipes-support/libeigen/libeigen/0002-Remove-LGPL-Code-and-references.patch
new file mode 100644
index 0000000000..2d19bc23c8
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/libeigen/libeigen/0002-Remove-LGPL-Code-and-references.patch
@@ -0,0 +1,1040 @@
+From e63a6950dbebf4dd95e5c74c423c06fd65df5182 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Antonio=20S=C3=A1nchez?= <cantonios@google.com>
+Date: Wed, 8 Feb 2023 01:25:06 +0000
+Subject: [PATCH] Remove LGPL Code and references.
+
+Upstream-Status: Backport [https://gitlab.com/libeigen/eigen/-/commit/e256ad1823c2eddd6954241ddc99bfeb7bb29cb3]
+---
+ COPYING.LGPL | 502 ------------------
+ COPYING.README | 16 +-
+ Eigen/src/Core/util/NonMPL2.h | 3 -
+ .../IncompleteCholesky.h | 3 +-
+ bench/tensors/eigen_sycl_bench.sh | 1 -
+ bench/tensors/eigen_sycl_bench_contract.sh | 2 +-
+ doc/PreprocessorDirectives.dox | 3 -
+ test/CMakeLists.txt | 1 -
+ test/mpl2only.cpp | 24 -
+ unsupported/Eigen/IterativeSolvers | 6 -
+ .../IterativeSolvers/ConstrainedConjGrad.h | 187 -------
+ .../IterativeSolvers/IterationController.h | 154 ------
+ 12 files changed, 4 insertions(+), 898 deletions(-)
+ delete mode 100644 COPYING.LGPL
+ delete mode 100644 Eigen/src/Core/util/NonMPL2.h
+ delete mode 100644 test/mpl2only.cpp
+ delete mode 100644 unsupported/Eigen/src/IterativeSolvers/ConstrainedConjGrad.h
+ delete mode 100644 unsupported/Eigen/src/IterativeSolvers/IterationController.h
+
+diff --git a/COPYING.LGPL b/COPYING.LGPL
+deleted file mode 100644
+index 4362b4915..000000000
+--- a/COPYING.LGPL
++++ /dev/null
+@@ -1,502 +0,0 @@
+- GNU LESSER GENERAL PUBLIC LICENSE
+- Version 2.1, February 1999
+-
+- Copyright (C) 1991, 1999 Free Software Foundation, Inc.
+- 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
+- Everyone is permitted to copy and distribute verbatim copies
+- of this license document, but changing it is not allowed.
+-
+-[This is the first released version of the Lesser GPL. It also counts
+- as the successor of the GNU Library Public License, version 2, hence
+- the version number 2.1.]
+-
+- Preamble
+-
+- The licenses for most software are designed to take away your
+-freedom to share and change it. By contrast, the GNU General Public
+-Licenses are intended to guarantee your freedom to share and change
+-free software--to make sure the software is free for all its users.
+-
+- This license, the Lesser General Public License, applies to some
+-specially designated software packages--typically libraries--of the
+-Free Software Foundation and other authors who decide to use it. You
+-can use it too, but we suggest you first think carefully about whether
+-this license or the ordinary General Public License is the better
+-strategy to use in any particular case, based on the explanations below.
+-
+- When we speak of free software, we are referring to freedom of use,
+-not price. Our General Public Licenses are designed to make sure that
+-you have the freedom to distribute copies of free software (and charge
+-for this service if you wish); that you receive source code or can get
+-it if you want it; that you can change the software and use pieces of
+-it in new free programs; and that you are informed that you can do
+-these things.
+-
+- To protect your rights, we need to make restrictions that forbid
+-distributors to deny you these rights or to ask you to surrender these
+-rights. These restrictions translate to certain responsibilities for
+-you if you distribute copies of the library or if you modify it.
+-
+- For example, if you distribute copies of the library, whether gratis
+-or for a fee, you must give the recipients all the rights that we gave
+-you. You must make sure that they, too, receive or can get the source
+-code. If you link other code with the library, you must provide
+-complete object files to the recipients, so that they can relink them
+-with the library after making changes to the library and recompiling
+-it. And you must show them these terms so they know their rights.
+-
+- We protect your rights with a two-step method: (1) we copyright the
+-library, and (2) we offer you this license, which gives you legal
+-permission to copy, distribute and/or modify the library.
+-
+- To protect each distributor, we want to make it very clear that
+-there is no warranty for the free library. Also, if the library is
+-modified by someone else and passed on, the recipients should know
+-that what they have is not the original version, so that the original
+-author's reputation will not be affected by problems that might be
+-introduced by others.
+-
+- Finally, software patents pose a constant threat to the existence of
+-any free program. We wish to make sure that a company cannot
+-effectively restrict the users of a free program by obtaining a
+-restrictive license from a patent holder. Therefore, we insist that
+-any patent license obtained for a version of the library must be
+-consistent with the full freedom of use specified in this license.
+-
+- Most GNU software, including some libraries, is covered by the
+-ordinary GNU General Public License. This license, the GNU Lesser
+-General Public License, applies to certain designated libraries, and
+-is quite different from the ordinary General Public License. We use
+-this license for certain libraries in order to permit linking those
+-libraries into non-free programs.
+-
+- When a program is linked with a library, whether statically or using
+-a shared library, the combination of the two is legally speaking a
+-combined work, a derivative of the original library. The ordinary
+-General Public License therefore permits such linking only if the
+-entire combination fits its criteria of freedom. The Lesser General
+-Public License permits more lax criteria for linking other code with
+-the library.
+-
+- We call this license the "Lesser" General Public License because it
+-does Less to protect the user's freedom than the ordinary General
+-Public License. It also provides other free software developers Less
+-of an advantage over competing non-free programs. These disadvantages
+-are the reason we use the ordinary General Public License for many
+-libraries. However, the Lesser license provides advantages in certain
+-special circumstances.
+-
+- For example, on rare occasions, there may be a special need to
+-encourage the widest possible use of a certain library, so that it becomes
+-a de-facto standard. To achieve this, non-free programs must be
+-allowed to use the library. A more frequent case is that a free
+-library does the same job as widely used non-free libraries. In this
+-case, there is little to gain by limiting the free library to free
+-software only, so we use the Lesser General Public License.
+-
+- In other cases, permission to use a particular library in non-free
+-programs enables a greater number of people to use a large body of
+-free software. For example, permission to use the GNU C Library in
+-non-free programs enables many more people to use the whole GNU
+-operating system, as well as its variant, the GNU/Linux operating
+-system.
+-
+- Although the Lesser General Public License is Less protective of the
+-users' freedom, it does ensure that the user of a program that is
+-linked with the Library has the freedom and the wherewithal to run
+-that program using a modified version of the Library.
+-
+- The precise terms and conditions for copying, distribution and
+-modification follow. Pay close attention to the difference between a
+-"work based on the library" and a "work that uses the library". The
+-former contains code derived from the library, whereas the latter must
+-be combined with the library in order to run.
+-
+- GNU LESSER GENERAL PUBLIC LICENSE
+- TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION
+-
+- 0. This License Agreement applies to any software library or other
+-program which contains a notice placed by the copyright holder or
+-other authorized party saying it may be distributed under the terms of
+-this Lesser General Public License (also called "this License").
+-Each licensee is addressed as "you".
+-
+- A "library" means a collection of software functions and/or data
+-prepared so as to be conveniently linked with application programs
+-(which use some of those functions and data) to form executables.
+-
+- The "Library", below, refers to any such software library or work
+-which has been distributed under these terms. A "work based on the
+-Library" means either the Library or any derivative work under
+-copyright law: that is to say, a work containing the Library or a
+-portion of it, either verbatim or with modifications and/or translated
+-straightforwardly into another language. (Hereinafter, translation is
+-included without limitation in the term "modification".)
+-
+- "Source code" for a work means the preferred form of the work for
+-making modifications to it. For a library, complete source code means
+-all the source code for all modules it contains, plus any associated
+-interface definition files, plus the scripts used to control compilation
+-and installation of the library.
+-
+- Activities other than copying, distribution and modification are not
+-covered by this License; they are outside its scope. The act of
+-running a program using the Library is not restricted, and output from
+-such a program is covered only if its contents constitute a work based
+-on the Library (independent of the use of the Library in a tool for
+-writing it). Whether that is true depends on what the Library does
+-and what the program that uses the Library does.
+-
+- 1. You may copy and distribute verbatim copies of the Library's
+-complete source code as you receive it, in any medium, provided that
+-you conspicuously and appropriately publish on each copy an
+-appropriate copyright notice and disclaimer of warranty; keep intact
+-all the notices that refer to this License and to the absence of any
+-warranty; and distribute a copy of this License along with the
+-Library.
+-
+- You may charge a fee for the physical act of transferring a copy,
+-and you may at your option offer warranty protection in exchange for a
+-fee.
+-
+- 2. You may modify your copy or copies of the Library or any portion
+-of it, thus forming a work based on the Library, and copy and
+-distribute such modifications or work under the terms of Section 1
+-above, provided that you also meet all of these conditions:
+-
+- a) The modified work must itself be a software library.
+-
+- b) You must cause the files modified to carry prominent notices
+- stating that you changed the files and the date of any change.
+-
+- c) You must cause the whole of the work to be licensed at no
+- charge to all third parties under the terms of this License.
+-
+- d) If a facility in the modified Library refers to a function or a
+- table of data to be supplied by an application program that uses
+- the facility, other than as an argument passed when the facility
+- is invoked, then you must make a good faith effort to ensure that,
+- in the event an application does not supply such function or
+- table, the facility still operates, and performs whatever part of
+- its purpose remains meaningful.
+-
+- (For example, a function in a library to compute square roots has
+- a purpose that is entirely well-defined independent of the
+- application. Therefore, Subsection 2d requires that any
+- application-supplied function or table used by this function must
+- be optional: if the application does not supply it, the square
+- root function must still compute square roots.)
+-
+-These requirements apply to the modified work as a whole. If
+-identifiable sections of that work are not derived from the Library,
+-and can be reasonably considered independent and separate works in
+-themselves, then this License, and its terms, do not apply to those
+-sections when you distribute them as separate works. But when you
+-distribute the same sections as part of a whole which is a work based
+-on the Library, the distribution of the whole must be on the terms of
+-this License, whose permissions for other licensees extend to the
+-entire whole, and thus to each and every part regardless of who wrote
+-it.
+-
+-Thus, it is not the intent of this section to claim rights or contest
+-your rights to work written entirely by you; rather, the intent is to
+-exercise the right to control the distribution of derivative or
+-collective works based on the Library.
+-
+-In addition, mere aggregation of another work not based on the Library
+-with the Library (or with a work based on the Library) on a volume of
+-a storage or distribution medium does not bring the other work under
+-the scope of this License.
+-
+- 3. You may opt to apply the terms of the ordinary GNU General Public
+-License instead of this License to a given copy of the Library. To do
+-this, you must alter all the notices that refer to this License, so
+-that they refer to the ordinary GNU General Public License, version 2,
+-instead of to this License. (If a newer version than version 2 of the
+-ordinary GNU General Public License has appeared, then you can specify
+-that version instead if you wish.) Do not make any other change in
+-these notices.
+-
+- Once this change is made in a given copy, it is irreversible for
+-that copy, so the ordinary GNU General Public License applies to all
+-subsequent copies and derivative works made from that copy.
+-
+- This option is useful when you wish to copy part of the code of
+-the Library into a program that is not a library.
+-
+- 4. You may copy and distribute the Library (or a portion or
+-derivative of it, under Section 2) in object code or executable form
+-under the terms of Sections 1 and 2 above provided that you accompany
+-it with the complete corresponding machine-readable source code, which
+-must be distributed under the terms of Sections 1 and 2 above on a
+-medium customarily used for software interchange.
+-
+- If distribution of object code is made by offering access to copy
+-from a designated place, then offering equivalent access to copy the
+-source code from the same place satisfies the requirement to
+-distribute the source code, even though third parties are not
+-compelled to copy the source along with the object code.
+-
+- 5. A program that contains no derivative of any portion of the
+-Library, but is designed to work with the Library by being compiled or
+-linked with it, is called a "work that uses the Library". Such a
+-work, in isolation, is not a derivative work of the Library, and
+-therefore falls outside the scope of this License.
+-
+- However, linking a "work that uses the Library" with the Library
+-creates an executable that is a derivative of the Library (because it
+-contains portions of the Library), rather than a "work that uses the
+-library". The executable is therefore covered by this License.
+-Section 6 states terms for distribution of such executables.
+-
+- When a "work that uses the Library" uses material from a header file
+-that is part of the Library, the object code for the work may be a
+-derivative work of the Library even though the source code is not.
+-Whether this is true is especially significant if the work can be
+-linked without the Library, or if the work is itself a library. The
+-threshold for this to be true is not precisely defined by law.
+-
+- If such an object file uses only numerical parameters, data
+-structure layouts and accessors, and small macros and small inline
+-functions (ten lines or less in length), then the use of the object
+-file is unrestricted, regardless of whether it is legally a derivative
+-work. (Executables containing this object code plus portions of the
+-Library will still fall under Section 6.)
+-
+- Otherwise, if the work is a derivative of the Library, you may
+-distribute the object code for the work under the terms of Section 6.
+-Any executables containing that work also fall under Section 6,
+-whether or not they are linked directly with the Library itself.
+-
+- 6. As an exception to the Sections above, you may also combine or
+-link a "work that uses the Library" with the Library to produce a
+-work containing portions of the Library, and distribute that work
+-under terms of your choice, provided that the terms permit
+-modification of the work for the customer's own use and reverse
+-engineering for debugging such modifications.
+-
+- You must give prominent notice with each copy of the work that the
+-Library is used in it and that the Library and its use are covered by
+-this License. You must supply a copy of this License. If the work
+-during execution displays copyright notices, you must include the
+-copyright notice for the Library among them, as well as a reference
+-directing the user to the copy of this License. Also, you must do one
+-of these things:
+-
+- a) Accompany the work with the complete corresponding
+- machine-readable source code for the Library including whatever
+- changes were used in the work (which must be distributed under
+- Sections 1 and 2 above); and, if the work is an executable linked
+- with the Library, with the complete machine-readable "work that
+- uses the Library", as object code and/or source code, so that the
+- user can modify the Library and then relink to produce a modified
+- executable containing the modified Library. (It is understood
+- that the user who changes the contents of definitions files in the
+- Library will not necessarily be able to recompile the application
+- to use the modified definitions.)
+-
+- b) Use a suitable shared library mechanism for linking with the
+- Library. A suitable mechanism is one that (1) uses at run time a
+- copy of the library already present on the user's computer system,
+- rather than copying library functions into the executable, and (2)
+- will operate properly with a modified version of the library, if
+- the user installs one, as long as the modified version is
+- interface-compatible with the version that the work was made with.
+-
+- c) Accompany the work with a written offer, valid for at
+- least three years, to give the same user the materials
+- specified in Subsection 6a, above, for a charge no more
+- than the cost of performing this distribution.
+-
+- d) If distribution of the work is made by offering access to copy
+- from a designated place, offer equivalent access to copy the above
+- specified materials from the same place.
+-
+- e) Verify that the user has already received a copy of these
+- materials or that you have already sent this user a copy.
+-
+- For an executable, the required form of the "work that uses the
+-Library" must include any data and utility programs needed for
+-reproducing the executable from it. However, as a special exception,
+-the materials to be distributed need not include anything that is
+-normally distributed (in either source or binary form) with the major
+-components (compiler, kernel, and so on) of the operating system on
+-which the executable runs, unless that component itself accompanies
+-the executable.
+-
+- It may happen that this requirement contradicts the license
+-restrictions of other proprietary libraries that do not normally
+-accompany the operating system. Such a contradiction means you cannot
+-use both them and the Library together in an executable that you
+-distribute.
+-
+- 7. You may place library facilities that are a work based on the
+-Library side-by-side in a single library together with other library
+-facilities not covered by this License, and distribute such a combined
+-library, provided that the separate distribution of the work based on
+-the Library and of the other library facilities is otherwise
+-permitted, and provided that you do these two things:
+-
+- a) Accompany the combined library with a copy of the same work
+- based on the Library, uncombined with any other library
+- facilities. This must be distributed under the terms of the
+- Sections above.
+-
+- b) Give prominent notice with the combined library of the fact
+- that part of it is a work based on the Library, and explaining
+- where to find the accompanying uncombined form of the same work.
+-
+- 8. You may not copy, modify, sublicense, link with, or distribute
+-the Library except as expressly provided under this License. Any
+-attempt otherwise to copy, modify, sublicense, link with, or
+-distribute the Library is void, and will automatically terminate your
+-rights under this License. However, parties who have received copies,
+-or rights, from you under this License will not have their licenses
+-terminated so long as such parties remain in full compliance.
+-
+- 9. You are not required to accept this License, since you have not
+-signed it. However, nothing else grants you permission to modify or
+-distribute the Library or its derivative works. These actions are
+-prohibited by law if you do not accept this License. Therefore, by
+-modifying or distributing the Library (or any work based on the
+-Library), you indicate your acceptance of this License to do so, and
+-all its terms and conditions for copying, distributing or modifying
+-the Library or works based on it.
+-
+- 10. Each time you redistribute the Library (or any work based on the
+-Library), the recipient automatically receives a license from the
+-original licensor to copy, distribute, link with or modify the Library
+-subject to these terms and conditions. You may not impose any further
+-restrictions on the recipients' exercise of the rights granted herein.
+-You are not responsible for enforcing compliance by third parties with
+-this License.
+-
+- 11. If, as a consequence of a court judgment or allegation of patent
+-infringement or for any other reason (not limited to patent issues),
+-conditions are imposed on you (whether by court order, agreement or
+-otherwise) that contradict the conditions of this License, they do not
+-excuse you from the conditions of this License. If you cannot
+-distribute so as to satisfy simultaneously your obligations under this
+-License and any other pertinent obligations, then as a consequence you
+-may not distribute the Library at all. For example, if a patent
+-license would not permit royalty-free redistribution of the Library by
+-all those who receive copies directly or indirectly through you, then
+-the only way you could satisfy both it and this License would be to
+-refrain entirely from distribution of the Library.
+-
+-If any portion of this section is held invalid or unenforceable under any
+-particular circumstance, the balance of the section is intended to apply,
+-and the section as a whole is intended to apply in other circumstances.
+-
+-It is not the purpose of this section to induce you to infringe any
+-patents or other property right claims or to contest validity of any
+-such claims; this section has the sole purpose of protecting the
+-integrity of the free software distribution system which is
+-implemented by public license practices. Many people have made
+-generous contributions to the wide range of software distributed
+-through that system in reliance on consistent application of that
+-system; it is up to the author/donor to decide if he or she is willing
+-to distribute software through any other system and a licensee cannot
+-impose that choice.
+-
+-This section is intended to make thoroughly clear what is believed to
+-be a consequence of the rest of this License.
+-
+- 12. If the distribution and/or use of the Library is restricted in
+-certain countries either by patents or by copyrighted interfaces, the
+-original copyright holder who places the Library under this License may add
+-an explicit geographical distribution limitation excluding those countries,
+-so that distribution is permitted only in or among countries not thus
+-excluded. In such case, this License incorporates the limitation as if
+-written in the body of this License.
+-
+- 13. The Free Software Foundation may publish revised and/or new
+-versions of the Lesser General Public License from time to time.
+-Such new versions will be similar in spirit to the present version,
+-but may differ in detail to address new problems or concerns.
+-
+-Each version is given a distinguishing version number. If the Library
+-specifies a version number of this License which applies to it and
+-"any later version", you have the option of following the terms and
+-conditions either of that version or of any later version published by
+-the Free Software Foundation. If the Library does not specify a
+-license version number, you may choose any version ever published by
+-the Free Software Foundation.
+-
+- 14. If you wish to incorporate parts of the Library into other free
+-programs whose distribution conditions are incompatible with these,
+-write to the author to ask for permission. For software which is
+-copyrighted by the Free Software Foundation, write to the Free
+-Software Foundation; we sometimes make exceptions for this. Our
+-decision will be guided by the two goals of preserving the free status
+-of all derivatives of our free software and of promoting the sharing
+-and reuse of software generally.
+-
+- NO WARRANTY
+-
+- 15. BECAUSE THE LIBRARY IS LICENSED FREE OF CHARGE, THERE IS NO
+-WARRANTY FOR THE LIBRARY, TO THE EXTENT PERMITTED BY APPLICABLE LAW.
+-EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR
+-OTHER PARTIES PROVIDE THE LIBRARY "AS IS" WITHOUT WARRANTY OF ANY
+-KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE
+-IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
+-PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE
+-LIBRARY IS WITH YOU. SHOULD THE LIBRARY PROVE DEFECTIVE, YOU ASSUME
+-THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
+-
+- 16. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN
+-WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY
+-AND/OR REDISTRIBUTE THE LIBRARY AS PERMITTED ABOVE, BE LIABLE TO YOU
+-FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR
+-CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE
+-LIBRARY (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING
+-RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A
+-FAILURE OF THE LIBRARY TO OPERATE WITH ANY OTHER SOFTWARE), EVEN IF
+-SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH
+-DAMAGES.
+-
+- END OF TERMS AND CONDITIONS
+-
+- How to Apply These Terms to Your New Libraries
+-
+- If you develop a new library, and you want it to be of the greatest
+-possible use to the public, we recommend making it free software that
+-everyone can redistribute and change. You can do so by permitting
+-redistribution under these terms (or, alternatively, under the terms of the
+-ordinary General Public License).
+-
+- To apply these terms, attach the following notices to the library. It is
+-safest to attach them to the start of each source file to most effectively
+-convey the exclusion of warranty; and each file should have at least the
+-"copyright" line and a pointer to where the full notice is found.
+-
+- <one line to give the library's name and a brief idea of what it does.>
+- Copyright (C) <year> <name of author>
+-
+- This library is free software; you can redistribute it and/or
+- modify it under the terms of the GNU Lesser General Public
+- License as published by the Free Software Foundation; either
+- version 2.1 of the License, or (at your option) any later version.
+-
+- This library is distributed in the hope that it will be useful,
+- but WITHOUT ANY WARRANTY; without even the implied warranty of
+- MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+- Lesser General Public License for more details.
+-
+- You should have received a copy of the GNU Lesser General Public
+- License along with this library; if not, write to the Free Software
+- Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
+-
+-Also add information on how to contact you by electronic and paper mail.
+-
+-You should also get your employer (if you work as a programmer) or your
+-school, if any, to sign a "copyright disclaimer" for the library, if
+-necessary. Here is a sample; alter the names:
+-
+- Yoyodyne, Inc., hereby disclaims all copyright interest in the
+- library `Frob' (a library for tweaking knobs) written by James Random Hacker.
+-
+- <signature of Ty Coon>, 1 April 1990
+- Ty Coon, President of Vice
+-
+-That's all there is to it!
+diff --git a/COPYING.README b/COPYING.README
+index de5b63215..11af93ca7 100644
+--- a/COPYING.README
++++ b/COPYING.README
+@@ -2,17 +2,5 @@ Eigen is primarily MPL2 licensed. See COPYING.MPL2 and these links:
+ http://www.mozilla.org/MPL/2.0/
+ http://www.mozilla.org/MPL/2.0/FAQ.html
+
+-Some files contain third-party code under BSD or LGPL licenses, whence the other
+-COPYING.* files here.
+-
+-All the LGPL code is either LGPL 2.1-only, or LGPL 2.1-or-later.
+-For this reason, the COPYING.LGPL file contains the LGPL 2.1 text.
+-
+-If you want to guarantee that the Eigen code that you are #including is licensed
+-under the MPL2 and possibly more permissive licenses (like BSD), #define this
+-preprocessor symbol:
+- EIGEN_MPL2_ONLY
+-For example, with most compilers, you could add this to your project CXXFLAGS:
+- -DEIGEN_MPL2_ONLY
+-This will cause a compilation error to be generated if you #include any code that is
+-LGPL licensed.
++Some files contain third-party code under BSD or other MPL2-compatible licenses,
++whence the other COPYING.* files here.
+\ No newline at end of file
+diff --git a/Eigen/src/Core/util/NonMPL2.h b/Eigen/src/Core/util/NonMPL2.h
+deleted file mode 100644
+index 1af67cf18..000000000
+--- a/Eigen/src/Core/util/NonMPL2.h
++++ /dev/null
+@@ -1,3 +0,0 @@
+-#ifdef EIGEN_MPL2_ONLY
+-#error Including non-MPL2 code in EIGEN_MPL2_ONLY mode
+-#endif
+diff --git a/Eigen/src/IterativeLinearSolvers/IncompleteCholesky.h b/Eigen/src/IterativeLinearSolvers/IncompleteCholesky.h
+index 7803fd817..1a5d7faeb 100644
+--- a/Eigen/src/IterativeLinearSolvers/IncompleteCholesky.h
++++ b/Eigen/src/IterativeLinearSolvers/IncompleteCholesky.h
+@@ -24,8 +24,7 @@ namespace Eigen {
+ * \tparam Scalar the scalar type of the input matrices
+ * \tparam _UpLo The triangular part that will be used for the computations. It can be Lower
+ * or Upper. Default is Lower.
+- * \tparam _OrderingType The ordering method to use, either AMDOrdering<> or NaturalOrdering<>. Default is AMDOrdering<int>,
+- * unless EIGEN_MPL2_ONLY is defined, in which case the default is NaturalOrdering<int>.
++ * \tparam _OrderingType The ordering method to use, either AMDOrdering<> or NaturalOrdering<>. Default is AMDOrdering<int>.
+ *
+ * \implsparsesolverconcept
+ *
+diff --git a/bench/tensors/eigen_sycl_bench.sh b/bench/tensors/eigen_sycl_bench.sh
+index 3f67b3d86..4cb8f7be4 100755
+--- a/bench/tensors/eigen_sycl_bench.sh
++++ b/bench/tensors/eigen_sycl_bench.sh
+@@ -10,7 +10,6 @@ benchmark_main.cc \
+ -march=native \
+ -O3 \
+ -DNDEBUG \
+--DEIGEN_MPL2_ONLY \
+ -DEIGEN_USE_SYCL=1 \
+ -DEIGEN_SYCL_LOCAL_MEM=1 \
+ -no-serial-memop \
+diff --git a/bench/tensors/eigen_sycl_bench_contract.sh b/bench/tensors/eigen_sycl_bench_contract.sh
+index 73fd6c4a0..3ab0138a1 100644
+--- a/bench/tensors/eigen_sycl_bench_contract.sh
++++ b/bench/tensors/eigen_sycl_bench_contract.sh
+@@ -1,7 +1,7 @@
+ rm -f tensor_contract_sycl_bench
+ : "${COMPUTECPP_PACKAGE_ROOT_DIR:?Need to set COMPUTECPP_PACKAGE_ROOT_DIR}"
+ echo "COMPUTECPP_PACKAGE_ROOT_DIR is set to: "$COMPUTECPP_PACKAGE_ROOT_DIR
+-${COMPUTECPP_PACKAGE_ROOT_DIR}/bin/compute++ tensor_contract_sycl_bench.cc -I ../../ -I ${COMPUTECPP_PACKAGE_ROOT_DIR}/include/ -std=c++11 -O3 -DNDEBUG -DEIGEN_MPL2_ONLY -DEIGEN_USE_SYCL=1 -no-serial-memop -mllvm -inline-threshold=10000 -fsycl-ih-last -sycl-driver -Xclang -cl-mad-enable -lOpenCL -lComputeCpp -lpthread -o tensor_contract_sycl_bench ${@:1}
++${COMPUTECPP_PACKAGE_ROOT_DIR}/bin/compute++ tensor_contract_sycl_bench.cc -I ../../ -I ${COMPUTECPP_PACKAGE_ROOT_DIR}/include/ -std=c++11 -O3 -DNDEBUG -DEIGEN_USE_SYCL=1 -no-serial-memop -mllvm -inline-threshold=10000 -fsycl-ih-last -sycl-driver -Xclang -cl-mad-enable -lOpenCL -lComputeCpp -lpthread -o tensor_contract_sycl_bench ${@:1}
+ export LD_LIBRARY_PATH=${COMPUTECPP_PACKAGE_ROOT_DIR}/lib:$LD_LIBRARY_PATH
+ ./tensor_contract_sycl_bench
+
+diff --git a/doc/PreprocessorDirectives.dox b/doc/PreprocessorDirectives.dox
+index 0f545b086..b7d59ccbc 100644
+--- a/doc/PreprocessorDirectives.dox
++++ b/doc/PreprocessorDirectives.dox
+@@ -92,9 +92,6 @@ run time. However, these assertions do cost time and can thus be turned off.
+ - \b eigen_assert - macro with one argument that is used inside %Eigen for assertions. By default, it is
+ basically defined to be \c assert, which aborts the program if the assertion is violated. Redefine this
+ macro if you want to do something else, like throwing an exception.
+- - \b EIGEN_MPL2_ONLY - disable non MPL2 compatible features, or in other words disable the features which
+- are still under the LGPL.
+-
+
+ \section TopicPreprocessorDirectivesPerformance Alignment, vectorization and performance tweaking
+
+diff --git a/test/CMakeLists.txt b/test/CMakeLists.txt
+index 5136f82aa..9f557743a 100644
+--- a/test/CMakeLists.txt
++++ b/test/CMakeLists.txt
+@@ -277,7 +277,6 @@ ei_add_test(special_numbers)
+ ei_add_test(rvalue_types)
+ ei_add_test(dense_storage)
+ ei_add_test(ctorleak)
+-ei_add_test(mpl2only)
+ ei_add_test(inplace_decomposition)
+ ei_add_test(half_float)
+ ei_add_test(bfloat16_float)
+diff --git a/test/mpl2only.cpp b/test/mpl2only.cpp
+deleted file mode 100644
+index 296350d08..000000000
+--- a/test/mpl2only.cpp
++++ /dev/null
+@@ -1,24 +0,0 @@
+-// This file is part of Eigen, a lightweight C++ template library
+-// for linear algebra.
+-//
+-// Copyright (C) 2015 Gael Guennebaud <gael.guennebaud@inria.fr>
+-//
+-// This Source Code Form is subject to the terms of the Mozilla
+-// Public License v. 2.0. If a copy of the MPL was not distributed
+-// with this file, You can obtain one at http://mozilla.org/MPL/2.0/.
+-
+-#ifndef EIGEN_MPL2_ONLY
+-#define EIGEN_MPL2_ONLY
+-#endif
+-#include <Eigen/Dense>
+-#include <Eigen/SparseCore>
+-#include <Eigen/SparseLU>
+-#include <Eigen/SparseQR>
+-#include <Eigen/Sparse>
+-#include <Eigen/IterativeLinearSolvers>
+-#include <Eigen/Eigen>
+-
+-int main()
+-{
+- return 0;
+-}
+diff --git a/unsupported/Eigen/IterativeSolvers b/unsupported/Eigen/IterativeSolvers
+index a3f58d676..f045fb607 100644
+--- a/unsupported/Eigen/IterativeSolvers
++++ b/unsupported/Eigen/IterativeSolvers
+@@ -19,7 +19,6 @@
+ * \defgroup IterativeLinearSolvers_Module Iterative solvers module
+ * This module aims to provide various iterative linear and non linear solver algorithms.
+ * It currently provides:
+- * - a constrained conjugate gradient
+ * - a Householder GMRES implementation
+ * - an IDR(s) implementation
+ * - a DGMRES implementation
+@@ -33,11 +32,6 @@
+
+ #include "../../Eigen/src/Core/util/DisableStupidWarnings.h"
+
+-#ifndef EIGEN_MPL2_ONLY
+-#include "src/IterativeSolvers/IterationController.h"
+-#include "src/IterativeSolvers/ConstrainedConjGrad.h"
+-#endif
+-
+ #include "src/IterativeSolvers/IncompleteLU.h"
+ #include "src/IterativeSolvers/GMRES.h"
+ #include "src/IterativeSolvers/DGMRES.h"
+diff --git a/unsupported/Eigen/src/IterativeSolvers/ConstrainedConjGrad.h b/unsupported/Eigen/src/IterativeSolvers/ConstrainedConjGrad.h
+deleted file mode 100644
+index e7d70f39d..000000000
+--- a/unsupported/Eigen/src/IterativeSolvers/ConstrainedConjGrad.h
++++ /dev/null
+@@ -1,187 +0,0 @@
+-// This file is part of Eigen, a lightweight C++ template library
+-// for linear algebra.
+-//
+-// Copyright (C) 2008 Gael Guennebaud <gael.guennebaud@inria.fr>
+-
+-/* NOTE The functions of this file have been adapted from the GMM++ library */
+-
+-//========================================================================
+-//
+-// Copyright (C) 2002-2007 Yves Renard
+-//
+-// This file is a part of GETFEM++
+-//
+-// Getfem++ is free software; you can redistribute it and/or modify
+-// it under the terms of the GNU Lesser General Public License as
+-// published by the Free Software Foundation; version 2.1 of the License.
+-//
+-// This program is distributed in the hope that it will be useful,
+-// but WITHOUT ANY WARRANTY; without even the implied warranty of
+-// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+-// GNU Lesser General Public License for more details.
+-// You should have received a copy of the GNU Lesser General Public
+-// License along with this program; if not, write to the Free Software
+-// Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301,
+-// USA.
+-//
+-//========================================================================
+-
+-#include "../../../../Eigen/src/Core/util/NonMPL2.h"
+-
+-#ifndef EIGEN_CONSTRAINEDCG_H
+-#define EIGEN_CONSTRAINEDCG_H
+-
+-#include "../../../../Eigen/Core"
+-
+-namespace Eigen {
+-
+-namespace internal {
+-
+-/** \ingroup IterativeLinearSolvers_Module
+- * Compute the pseudo inverse of the non-square matrix C such that
+- * \f$ CINV = (C * C^T)^{-1} * C \f$ based on a conjugate gradient method.
+- *
+- * This function is internally used by constrained_cg.
+- */
+-template <typename CMatrix, typename CINVMatrix>
+-void pseudo_inverse(const CMatrix &C, CINVMatrix &CINV)
+-{
+- // optimisable : copie de la ligne, precalcul de C * trans(C).
+- typedef typename CMatrix::Scalar Scalar;
+- typedef typename CMatrix::Index Index;
+- // FIXME use sparse vectors ?
+- typedef Matrix<Scalar,Dynamic,1> TmpVec;
+-
+- Index rows = C.rows(), cols = C.cols();
+-
+- TmpVec d(rows), e(rows), l(cols), p(rows), q(rows), r(rows);
+- Scalar rho, rho_1, alpha;
+- d.setZero();
+-
+- typedef Triplet<double> T;
+- std::vector<T> tripletList;
+-
+- for (Index i = 0; i < rows; ++i)
+- {
+- d[i] = 1.0;
+- rho = 1.0;
+- e.setZero();
+- r = d;
+- p = d;
+-
+- while (rho >= 1e-38)
+- { /* conjugate gradient to compute e */
+- /* which is the i-th row of inv(C * trans(C)) */
+- l = C.transpose() * p;
+- q = C * l;
+- alpha = rho / p.dot(q);
+- e += alpha * p;
+- r += -alpha * q;
+- rho_1 = rho;
+- rho = r.dot(r);
+- p = (rho/rho_1) * p + r;
+- }
+-
+- l = C.transpose() * e; // l is the i-th row of CINV
+- // FIXME add a generic "prune/filter" expression for both dense and sparse object to sparse
+- for (Index j=0; j<l.size(); ++j)
+- if (l[j]<1e-15)
+- tripletList.push_back(T(i,j,l(j)));
+-
+-
+- d[i] = 0.0;
+- }
+- CINV.setFromTriplets(tripletList.begin(), tripletList.end());
+-}
+-
+-
+-
+-/** \ingroup IterativeLinearSolvers_Module
+- * Constrained conjugate gradient
+- *
+- * Computes the minimum of \f$ 1/2((Ax).x) - bx \f$ under the constraint \f$ Cx \le f \f$
+- */
+-template<typename TMatrix, typename CMatrix,
+- typename VectorX, typename VectorB, typename VectorF>
+-void constrained_cg(const TMatrix& A, const CMatrix& C, VectorX& x,
+- const VectorB& b, const VectorF& f, IterationController &iter)
+-{
+- using std::sqrt;
+- typedef typename TMatrix::Scalar Scalar;
+- typedef typename TMatrix::Index Index;
+- typedef Matrix<Scalar,Dynamic,1> TmpVec;
+-
+- Scalar rho = 1.0, rho_1, lambda, gamma;
+- Index xSize = x.size();
+- TmpVec p(xSize), q(xSize), q2(xSize),
+- r(xSize), old_z(xSize), z(xSize),
+- memox(xSize);
+- std::vector<bool> satured(C.rows());
+- p.setZero();
+- iter.setRhsNorm(sqrt(b.dot(b))); // gael vect_sp(PS, b, b)
+- if (iter.rhsNorm() == 0.0) iter.setRhsNorm(1.0);
+-
+- SparseMatrix<Scalar,RowMajor> CINV(C.rows(), C.cols());
+- pseudo_inverse(C, CINV);
+-
+- while(true)
+- {
+- // computation of residual
+- old_z = z;
+- memox = x;
+- r = b;
+- r += A * -x;
+- z = r;
+- bool transition = false;
+- for (Index i = 0; i < C.rows(); ++i)
+- {
+- Scalar al = C.row(i).dot(x) - f.coeff(i);
+- if (al >= -1.0E-15)
+- {
+- if (!satured[i])
+- {
+- satured[i] = true;
+- transition = true;
+- }
+- Scalar bb = CINV.row(i).dot(z);
+- if (bb > 0.0)
+- // FIXME: we should allow that: z += -bb * C.row(i);
+- for (typename CMatrix::InnerIterator it(C,i); it; ++it)
+- z.coeffRef(it.index()) -= bb*it.value();
+- }
+- else
+- satured[i] = false;
+- }
+-
+- // descent direction
+- rho_1 = rho;
+- rho = r.dot(z);
+-
+- if (iter.finished(rho)) break;
+- if (transition || iter.first()) gamma = 0.0;
+- else gamma = (std::max)(0.0, (rho - old_z.dot(z)) / rho_1);
+- p = z + gamma*p;
+-
+- ++iter;
+- // one dimensionnal optimization
+- q = A * p;
+- lambda = rho / q.dot(p);
+- for (Index i = 0; i < C.rows(); ++i)
+- {
+- if (!satured[i])
+- {
+- Scalar bb = C.row(i).dot(p) - f[i];
+- if (bb > 0.0)
+- lambda = (std::min)(lambda, (f.coeff(i)-C.row(i).dot(x)) / bb);
+- }
+- }
+- x += lambda * p;
+- memox -= x;
+- }
+-}
+-
+-} // end namespace internal
+-
+-} // end namespace Eigen
+-
+-#endif // EIGEN_CONSTRAINEDCG_H
+diff --git a/unsupported/Eigen/src/IterativeSolvers/IterationController.h b/unsupported/Eigen/src/IterativeSolvers/IterationController.h
+deleted file mode 100644
+index a116e09e2..000000000
+--- a/unsupported/Eigen/src/IterativeSolvers/IterationController.h
++++ /dev/null
+@@ -1,154 +0,0 @@
+-// This file is part of Eigen, a lightweight C++ template library
+-// for linear algebra.
+-//
+-// Copyright (C) 2008-2009 Gael Guennebaud <gael.guennebaud@inria.fr>
+-
+-/* NOTE The class IterationController has been adapted from the iteration
+- * class of the GMM++ and ITL libraries.
+- */
+-
+-//=======================================================================
+-// Copyright (C) 1997-2001
+-// Authors: Andrew Lumsdaine <lums@osl.iu.edu>
+-// Lie-Quan Lee <llee@osl.iu.edu>
+-//
+-// This file is part of the Iterative Template Library
+-//
+-// You should have received a copy of the License Agreement for the
+-// Iterative Template Library along with the software; see the
+-// file LICENSE.
+-//
+-// Permission to modify the code and to distribute modified code is
+-// granted, provided the text of this NOTICE is retained, a notice that
+-// the code was modified is included with the above COPYRIGHT NOTICE and
+-// with the COPYRIGHT NOTICE in the LICENSE file, and that the LICENSE
+-// file is distributed with the modified code.
+-//
+-// LICENSOR MAKES NO REPRESENTATIONS OR WARRANTIES, EXPRESS OR IMPLIED.
+-// By way of example, but not limitation, Licensor MAKES NO
+-// REPRESENTATIONS OR WARRANTIES OF MERCHANTABILITY OR FITNESS FOR ANY
+-// PARTICULAR PURPOSE OR THAT THE USE OF THE LICENSED SOFTWARE COMPONENTS
+-// OR DOCUMENTATION WILL NOT INFRINGE ANY PATENTS, COPYRIGHTS, TRADEMARKS
+-// OR OTHER RIGHTS.
+-//=======================================================================
+-
+-//========================================================================
+-//
+-// Copyright (C) 2002-2007 Yves Renard
+-//
+-// This file is a part of GETFEM++
+-//
+-// Getfem++ is free software; you can redistribute it and/or modify
+-// it under the terms of the GNU Lesser General Public License as
+-// published by the Free Software Foundation; version 2.1 of the License.
+-//
+-// This program is distributed in the hope that it will be useful,
+-// but WITHOUT ANY WARRANTY; without even the implied warranty of
+-// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+-// GNU Lesser General Public License for more details.
+-// You should have received a copy of the GNU Lesser General Public
+-// License along with this program; if not, write to the Free Software
+-// Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301,
+-// USA.
+-//
+-//========================================================================
+-
+-#include "../../../../Eigen/src/Core/util/NonMPL2.h"
+-
+-#ifndef EIGEN_ITERATION_CONTROLLER_H
+-#define EIGEN_ITERATION_CONTROLLER_H
+-
+-namespace Eigen {
+-
+-/** \ingroup IterativeLinearSolvers_Module
+- * \class IterationController
+- *
+- * \brief Controls the iterations of the iterative solvers
+- *
+- * This class has been adapted from the iteration class of GMM++ and ITL libraries.
+- *
+- */
+-class IterationController
+-{
+- protected :
+- double m_rhsn; ///< Right hand side norm
+- size_t m_maxiter; ///< Max. number of iterations
+- int m_noise; ///< if noise > 0 iterations are printed
+- double m_resmax; ///< maximum residual
+- double m_resminreach, m_resadd;
+- size_t m_nit; ///< iteration number
+- double m_res; ///< last computed residual
+- bool m_written;
+- void (*m_callback)(const IterationController&);
+- public :
+-
+- void init()
+- {
+- m_nit = 0; m_res = 0.0; m_written = false;
+- m_resminreach = 1E50; m_resadd = 0.0;
+- m_callback = 0;
+- }
+-
+- IterationController(double r = 1.0E-8, int noi = 0, size_t mit = size_t(-1))
+- : m_rhsn(1.0), m_maxiter(mit), m_noise(noi), m_resmax(r) { init(); }
+-
+- void operator ++(int) { m_nit++; m_written = false; m_resadd += m_res; }
+- void operator ++() { (*this)++; }
+-
+- bool first() { return m_nit == 0; }
+-
+- /* get/set the "noisyness" (verbosity) of the solvers */
+- int noiseLevel() const { return m_noise; }
+- void setNoiseLevel(int n) { m_noise = n; }
+- void reduceNoiseLevel() { if (m_noise > 0) m_noise--; }
+-
+- double maxResidual() const { return m_resmax; }
+- void setMaxResidual(double r) { m_resmax = r; }
+-
+- double residual() const { return m_res; }
+-
+- /* change the user-definable callback, called after each iteration */
+- void setCallback(void (*t)(const IterationController&))
+- {
+- m_callback = t;
+- }
+-
+- size_t iteration() const { return m_nit; }
+- void setIteration(size_t i) { m_nit = i; }
+-
+- size_t maxIterarions() const { return m_maxiter; }
+- void setMaxIterations(size_t i) { m_maxiter = i; }
+-
+- double rhsNorm() const { return m_rhsn; }
+- void setRhsNorm(double r) { m_rhsn = r; }
+-
+- bool converged() const { return m_res <= m_rhsn * m_resmax; }
+- bool converged(double nr)
+- {
+- using std::abs;
+- m_res = abs(nr);
+- m_resminreach = (std::min)(m_resminreach, m_res);
+- return converged();
+- }
+- template<typename VectorType> bool converged(const VectorType &v)
+- { return converged(v.squaredNorm()); }
+-
+- bool finished(double nr)
+- {
+- if (m_callback) m_callback(*this);
+- if (m_noise > 0 && !m_written)
+- {
+- converged(nr);
+- m_written = true;
+- }
+- return (m_nit >= m_maxiter || converged(nr));
+- }
+- template <typename VectorType>
+- bool finished(const MatrixBase<VectorType> &v)
+- { return finished(double(v.squaredNorm())); }
+-
+-};
+-
+-} // end namespace Eigen
+-
+-#endif // EIGEN_ITERATION_CONTROLLER_H
diff --git a/meta-openembedded/meta-oe/recipes-support/libeigen/libeigen_3.4.0.bb b/meta-openembedded/meta-oe/recipes-support/libeigen/libeigen_3.4.0.bb
index 72044427dd..d7c117120b 100644
--- a/meta-openembedded/meta-oe/recipes-support/libeigen/libeigen_3.4.0.bb
+++ b/meta-openembedded/meta-oe/recipes-support/libeigen/libeigen_3.4.0.bb
@@ -1,15 +1,20 @@
DESCRIPTION = "Eigen is a C++ template library for linear algebra: matrices, vectors, numerical solvers, and related algorithms."
HOMEPAGE = "http://eigen.tuxfamily.org/"
-LICENSE = "MPL-2.0 & Apache-2.0 & BSD-3-Clause & GPL-2.0-only & LGPL-2.1-only & MINPACK"
+LICENSE = "MPL-2.0 & Apache-2.0 & BSD-3-Clause & GPL-2.0-only & MINPACK"
+# The GPL code is only used for benchmark tests and does not affect what is installed.
+LICENSE:${PN} = "MPL-2.0 & Apache-2.0 & BSD-3-Clause & MINPACK"
+LICENSE:${PN}-dbg = "MPL-2.0 & Apache-2.0 & BSD-3-Clause & MINPACK"
+LICENSE:${PN}-dev = "MPL-2.0 & Apache-2.0 & BSD-3-Clause & MINPACK"
LIC_FILES_CHKSUM = "file://COPYING.MPL2;md5=815ca599c9df247a0c7f619bab123dad \
+ file://COPYING.APACHE;md5=8de23b8e93c63005353056b2475e9aa5 \
file://COPYING.BSD;md5=2dd0510ee95e59ca28834b875bc96596 \
file://COPYING.GPL;md5=d32239bcb673463ab874e80d47fae504 \
- file://COPYING.LGPL;md5=4fbd65380cdd255951079008b364516c \
file://COPYING.MINPACK;md5=71d91b0f75ce79a75d3108a72bef8116 \
"
SRC_URI = "git://gitlab.com/libeigen/eigen.git;protocol=http;branch=3.4 \
file://0001-Default-eigen_packet_wrapper-constructor.patch \
+ file://0002-Remove-LGPL-Code-and-references.patch \
"
SRCREV = "3147391d946bb4b6c68edd901f2add6ac1f31f8c"
diff --git a/meta-openembedded/meta-oe/recipes-support/libgpiod/libgpiod-2.x/0001-bindings-cxx-tests-set-direction-when-reconfiguring-.patch b/meta-openembedded/meta-oe/recipes-support/libgpiod/libgpiod-2.x/0001-bindings-cxx-tests-set-direction-when-reconfiguring-.patch
new file mode 100644
index 0000000000..f8b94f0b99
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/libgpiod/libgpiod-2.x/0001-bindings-cxx-tests-set-direction-when-reconfiguring-.patch
@@ -0,0 +1,38 @@
+From 8c7126b7b5dee0ed5433cf9265ccc79095d53939 Mon Sep 17 00:00:00 2001
+From: Bartosz Golaszewski <bartosz.golaszewski@linaro.org>
+Date: Mon, 8 Jul 2024 11:48:27 +0200
+Subject: [PATCH] bindings: cxx: tests: set direction when reconfiguring lines
+
+Linux kernel commit b44039638741 ("gpiolib: cdev: Ignore reconfiguration
+without direction") made the direction setting mandatory for line config
+passed to the kernel when reconfiguring requested lines. Fix the C++ test
+case which doesn't do it and now fails due to the rest of the settings
+being ignored.
+
+Reviewed-by: Kent Gibson <warthog618@gmail.com>
+Link: https://lore.kernel.org/r/20240708094827.84986-1-brgl@bgdev.pl
+Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@linaro.org>
+
+Upstream-Status: Backport
+[https://web.git.kernel.org/pub/scm/libs/libgpiod/libgpiod.git/commit/?id=3e224d885b1de54fe5510b9c5e7296260a1a4507]
+
+Signed-off-by: Libo Chen <libo.chen.cn@windriver.com>
+---
+ bindings/cxx/tests/tests-line-request.cpp | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/bindings/cxx/tests/tests-line-request.cpp b/bindings/cxx/tests/tests-line-request.cpp
+index 9632ae0..6e29532 100644
+--- a/bindings/cxx/tests/tests-line-request.cpp
++++ b/bindings/cxx/tests/tests-line-request.cpp
+@@ -208,6 +208,7 @@ TEST_CASE("values can be read", "[line-request]")
+ .add_line_settings(
+ offs,
+ ::gpiod::line_settings()
++ .set_direction(direction::INPUT)
+ .set_active_low(true))
+ );
+
+--
+2.44.1
+
diff --git a/meta-openembedded/meta-oe/recipes-support/libgpiod/libgpiod_2.1.2.bb b/meta-openembedded/meta-oe/recipes-support/libgpiod/libgpiod_2.1.2.bb
index 6e4fbd2a3b..edbde0f7a7 100644
--- a/meta-openembedded/meta-oe/recipes-support/libgpiod/libgpiod_2.1.2.bb
+++ b/meta-openembedded/meta-oe/recipes-support/libgpiod/libgpiod_2.1.2.bb
@@ -7,6 +7,8 @@ LIC_FILES_CHKSUM = " \
file://LICENSES/CC-BY-SA-4.0.txt;md5=fba3b94d88bfb9b81369b869a1e9a20f \
"
+SRC_URI += "file://0001-bindings-cxx-tests-set-direction-when-reconfiguring-.patch"
+
FILESEXTRAPATHS:prepend := "${THISDIR}/${PN}-2.x:"
SRC_URI[sha256sum] = "7a148a5a7d1c97a1abb40474b9a392b6edd7a42fe077dfd7ff42cfba24308548"
diff --git a/meta-openembedded/meta-oe/recipes-support/libjs/libjs-jquery-icheck_1.0.3.bb b/meta-openembedded/meta-oe/recipes-support/libjs/libjs-jquery-icheck_1.0.3.bb
index 31c3534b88..63dfc6fa78 100644
--- a/meta-openembedded/meta-oe/recipes-support/libjs/libjs-jquery-icheck_1.0.3.bb
+++ b/meta-openembedded/meta-oe/recipes-support/libjs/libjs-jquery-icheck_1.0.3.bb
@@ -3,7 +3,7 @@ SECTION = "console/network"
HOMEPAGE = "http://fronteed.com/iCheck"
LICENSE = "MIT"
-LIC_FILES_CHKSUM = "file://icheck.js;start_line=1;end_line=8;md5=404078d7de9f05ed64d364274f790055"
+LIC_FILES_CHKSUM = "file://icheck.js;beginline=6;endline=7;md5=ea25eee37fc3b14403e215bfe13564bc"
SRC_URI = "git://github.com/fronteed/icheck.git;protocol=https;branch=${PV}"
diff --git a/meta-openembedded/meta-oe/recipes-support/libp11/files/0001-detect-correct-openssl-3.x.patch b/meta-openembedded/meta-oe/recipes-support/libp11/files/0001-detect-correct-openssl-3.x.patch
new file mode 100644
index 0000000000..aa61e9d979
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/libp11/files/0001-detect-correct-openssl-3.x.patch
@@ -0,0 +1,28 @@
+From 74497e0fa5b69b15790d6697e1ebce13af842d4c Mon Sep 17 00:00:00 2001
+From: Mike Gilbert <floppym@gentoo.org>
+Date: Thu, 13 Jul 2023 13:52:54 -0400
+Subject: [PATCH] configure: treat all openssl-3.x releases the same
+
+OpenSSL's soversion will not change for any 3.x minor release.
+
+https://www.openssl.org/policies/general/versioning-policy.html
+---
+ configure.ac | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+Upstream-Status: Backport [https://github.com/OpenSC/libp11/commit/74497e0fa5b69b15790d6697e1ebce13af842d4c.patch]
+Signed-off-by: Sana Kazi <sanakazi720@gmail.com>
+
+diff --git a/configure.ac b/configure.ac
+index b96979d9..c344e84a 100644
+--- a/configure.ac
++++ b/configure.ac
+@@ -33,7 +33,7 @@ AC_C_BIGENDIAN
+ # issues with applications linking to new openssl, old libp11, and vice versa
+ case "`$PKG_CONFIG --modversion --silence-errors libcrypto || \
+ $PKG_CONFIG --modversion openssl`" in
+- 3.0.*) # Predicted engines directory prefix for OpenSSL 3.x
++ 3.*) # Predicted engines directory prefix for OpenSSL 3.x
+ LIBP11_LT_OLDEST="3"
+ debian_ssl_prefix="openssl-3.0.0";;
+ 1.1.*) # Predicted engines directory prefix for OpenSSL 1.1.x
diff --git a/meta-openembedded/meta-oe/recipes-support/libp11/libp11_0.4.12.bb b/meta-openembedded/meta-oe/recipes-support/libp11/libp11_0.4.12.bb
index 2237782009..cc4a138e2d 100644
--- a/meta-openembedded/meta-oe/recipes-support/libp11/libp11_0.4.12.bb
+++ b/meta-openembedded/meta-oe/recipes-support/libp11/libp11_0.4.12.bb
@@ -9,7 +9,10 @@ LICENSE = "LGPL-2.0-or-later"
LIC_FILES_CHKSUM = "file://COPYING;md5=fad9b3332be894bab9bc501572864b29"
DEPENDS = "libtool openssl"
-SRC_URI = "git://github.com/OpenSC/libp11.git;branch=master;protocol=https"
+SRC_URI = "git://github.com/OpenSC/libp11.git;branch=master;protocol=https \
+ file://0001-detect-correct-openssl-3.x.patch \
+"
+
SRCREV = "53d65dc48cf436694f7edcfc805414e608e8a2bf"
UPSTREAM_CHECK_GITTAGREGEX = "libp11-(?P<pver>\d+(\.\d+)+)"
diff --git a/meta-openembedded/meta-oe/recipes-support/libraw/libraw/0001-CVE-2025-43961-CVE-2025-43962.patch b/meta-openembedded/meta-oe/recipes-support/libraw/libraw/0001-CVE-2025-43961-CVE-2025-43962.patch
new file mode 100644
index 0000000000..1abd302caf
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/libraw/libraw/0001-CVE-2025-43961-CVE-2025-43962.patch
@@ -0,0 +1,108 @@
+From 880829f7ed206c21ce05d5772f0928629c7dd577 Mon Sep 17 00:00:00 2001
+From: Alex Tutubalin <lexa@lexa.ru>
+Date: Sat, 1 Feb 2025 15:32:39 +0300
+Subject: [PATCH] CVE-2025-43961 CVE-2025-43962
+
+Prevent out-of-bounds read in fuji 0xf00c tag parser
+
+prevent OOB reads in phase_one_correct
+
+CVE: CVE-2025-43961 CVE-2025-43962
+Upstream-Status: Backport [https://github.com/LibRaw/LibRaw/commit/66fe663e02a4dd610b4e832f5d9af326709336c2]
+
+(cherry picked from commit 66fe663e02a4dd610b4e832f5d9af326709336c2)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/decoders/load_mfbacks.cpp | 18 ++++++++++++++----
+ src/metadata/tiff.cpp | 28 +++++++++++++++++-----------
+ 2 files changed, 31 insertions(+), 15 deletions(-)
+
+diff --git a/src/decoders/load_mfbacks.cpp b/src/decoders/load_mfbacks.cpp
+index cddc33eb..1a1bdfb3 100644
+--- a/src/decoders/load_mfbacks.cpp
++++ b/src/decoders/load_mfbacks.cpp
+@@ -490,6 +490,9 @@ int LibRaw::phase_one_correct()
+ fseek(ifp, off_412, SEEK_SET);
+ for (i = 0; i < 9; i++)
+ head[i] = get4() & 0x7fff;
++ unsigned w0 = head[1] * head[3], w1 = head[2] * head[4];
++ if (w0 > 10240000 || w1 > 10240000)
++ throw LIBRAW_EXCEPTION_ALLOC;
+ yval[0] = (float *)calloc(head[1] * head[3] + head[2] * head[4], 6);
+ yval[1] = (float *)(yval[0] + head[1] * head[3]);
+ xval[0] = (ushort *)(yval[1] + head[2] * head[4]);
+@@ -514,10 +517,17 @@ int LibRaw::phase_one_correct()
+ for (k = j = 0; j < head[1]; j++)
+ if (num < xval[0][k = head[1] * i + j])
+ break;
+- frac = (j == 0 || j == head[1])
+- ? 0
+- : (xval[0][k] - num) / (xval[0][k] - xval[0][k - 1]);
+- mult[i - cip] = yval[0][k - 1] * frac + yval[0][k] * (1 - frac);
++ if (j == 0 || j == head[1] || k < 1 || k >= w0+w1)
++ frac = 0;
++ else
++ {
++ int xdiv = (xval[0][k] - xval[0][k - 1]);
++ frac = xdiv ? (xval[0][k] - num) / (xval[0][k] - xval[0][k - 1]) : 0;
++ }
++ if (k < w0 + w1)
++ mult[i - cip] = yval[0][k > 0 ? k - 1 : 0] * frac + yval[0][k] * (1 - frac);
++ else
++ mult[i - cip] = 0;
+ }
+ i = ((mult[0] * (1 - cfrac) + mult[1] * cfrac) * row + num) * 2;
+ RAW(row, col) = LIM(i, 0, 65535);
+diff --git a/src/metadata/tiff.cpp b/src/metadata/tiff.cpp
+index c34b8647..af664937 100644
+--- a/src/metadata/tiff.cpp
++++ b/src/metadata/tiff.cpp
+@@ -1032,31 +1032,37 @@ int LibRaw::parse_tiff_ifd(int base)
+ if ((fwb[0] == rafdata[fi]) && (fwb[1] == rafdata[fi + 1]) &&
+ (fwb[2] == rafdata[fi + 2])) // found Tungsten WB
+ {
+- if (rafdata[fi - 15] !=
++ if (fi > 14 && rafdata[fi - 15] !=
+ fwb[0]) // 15 is offset of Tungsten WB from the first
+ // preset, Fine Weather WB
+ continue;
+- for (int wb_ind = 0, ofst = fi - 15; wb_ind < (int)Fuji_wb_list1.size();
+- wb_ind++, ofst += 3)
+- {
+- icWBC[Fuji_wb_list1[wb_ind]][1] =
+- icWBC[Fuji_wb_list1[wb_ind]][3] = rafdata[ofst];
+- icWBC[Fuji_wb_list1[wb_ind]][0] = rafdata[ofst + 1];
+- icWBC[Fuji_wb_list1[wb_ind]][2] = rafdata[ofst + 2];
+- }
++ if (fi >= 15)
++ {
++ for (int wb_ind = 0, ofst = fi - 15; wb_ind < (int)Fuji_wb_list1.size();
++ wb_ind++, ofst += 3)
++ {
++ icWBC[Fuji_wb_list1[wb_ind]][1] =
++ icWBC[Fuji_wb_list1[wb_ind]][3] = rafdata[ofst];
++ icWBC[Fuji_wb_list1[wb_ind]][0] = rafdata[ofst + 1];
++ icWBC[Fuji_wb_list1[wb_ind]][2] = rafdata[ofst + 2];
++ }
++ }
+
+ if (is34)
+ fi += 24;
+ fi += 96;
+ for (fj = fi; fj < (fi + 15); fj += 3) // looking for the end of the WB table
+ {
++ if (fj > libraw_internal_data.unpacker_data.lenRAFData - 3)
++ break;
+ if (rafdata[fj] != rafdata[fi])
+ {
+ fj -= 93;
+ if (is34)
+ fj -= 9;
+-// printf ("wb start in DNG: 0x%04x\n", fj*2-0x4e);
+- for (int iCCT = 0, ofst = fj; iCCT < 31;
++//printf ("wb start in DNG: 0x%04x\n", fj*2-0x4e);
++ for (int iCCT = 0, ofst = fj; iCCT < 31
++ && ofst < libraw_internal_data.unpacker_data.lenRAFData - 3;
+ iCCT++, ofst += 3)
+ {
+ icWBCCTC[iCCT][0] = FujiCCT_K[iCCT];
diff --git a/meta-openembedded/meta-oe/recipes-support/libraw/libraw/0002-CVE-2025-43963.patch b/meta-openembedded/meta-oe/recipes-support/libraw/libraw/0002-CVE-2025-43963.patch
new file mode 100644
index 0000000000..d571164781
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/libraw/libraw/0002-CVE-2025-43963.patch
@@ -0,0 +1,40 @@
+From 975393c804bc321fd4bc709c3c221733dac2d80a Mon Sep 17 00:00:00 2001
+From: Alex Tutubalin <lexa@lexa.ru>
+Date: Thu, 6 Feb 2025 21:01:58 +0300
+Subject: [PATCH] CVE-2025-43963
+
+check split_col/split_row values in phase_one_correct
+
+CVE: CVE-2025-43963
+Upstream-Status: Backport [https://github.com/LibRaw/LibRaw/commit/be26e7639ecf8beb55f124ce780e99842de2e964]
+
+(cherry picked from commit be26e7639ecf8beb55f124ce780e99842de2e964)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/decoders/load_mfbacks.cpp | 6 ++++--
+ 1 file changed, 4 insertions(+), 2 deletions(-)
+
+diff --git a/src/decoders/load_mfbacks.cpp b/src/decoders/load_mfbacks.cpp
+index 1a1bdfb3..f89aecce 100644
+--- a/src/decoders/load_mfbacks.cpp
++++ b/src/decoders/load_mfbacks.cpp
+@@ -348,7 +348,8 @@ int LibRaw::phase_one_correct()
+ off_412 = ftell(ifp) - 38;
+ }
+ }
+- else if (tag == 0x041f && !qlin_applied)
++ else if (tag == 0x041f && !qlin_applied && ph1.split_col > 0 && ph1.split_col < raw_width
++ && ph1.split_row > 0 && ph1.split_row < raw_height)
+ { /* Quadrant linearization */
+ ushort lc[2][2][16], ref[16];
+ int qr, qc;
+@@ -432,7 +433,8 @@ int LibRaw::phase_one_correct()
+ }
+ qmult_applied = 1;
+ }
+- else if (tag == 0x0431 && !qmult_applied)
++ else if (tag == 0x0431 && !qmult_applied && ph1.split_col > 0 && ph1.split_col < raw_width
++ && ph1.split_row > 0 && ph1.split_row < raw_height)
+ { /* Quadrant combined - four tile gain calibration */
+ ushort lc[2][2][7], ref[7];
+ int qr, qc;
diff --git a/meta-openembedded/meta-oe/recipes-support/libraw/libraw/0003-CVE-2025-43964.patch b/meta-openembedded/meta-oe/recipes-support/libraw/libraw/0003-CVE-2025-43964.patch
new file mode 100644
index 0000000000..d7d7664da3
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/libraw/libraw/0003-CVE-2025-43964.patch
@@ -0,0 +1,29 @@
+From 0ecd9906f70114a974809bb35b4ec9fe7fed9011 Mon Sep 17 00:00:00 2001
+From: Alex Tutubalin <lexa@lexa.ru>
+Date: Sun, 2 Mar 2025 11:35:43 +0300
+Subject: [PATCH] CVE-2025-43964
+
+additional checks in PhaseOne correction tag 0x412 processing
+
+CVE: CVE-2025-43964
+Upstream-Status: Backport [https://github.com/LibRaw/LibRaw/commit/a50dc3f1127d2e37a9b39f57ad9bb2ebb60f18c0]
+
+(cherry picked from commit a50dc3f1127d2e37a9b39f57ad9bb2ebb60f18c0)
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/decoders/load_mfbacks.cpp | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/src/decoders/load_mfbacks.cpp b/src/decoders/load_mfbacks.cpp
+index f89aecce..95015d27 100644
+--- a/src/decoders/load_mfbacks.cpp
++++ b/src/decoders/load_mfbacks.cpp
+@@ -495,6 +495,8 @@ int LibRaw::phase_one_correct()
+ unsigned w0 = head[1] * head[3], w1 = head[2] * head[4];
+ if (w0 > 10240000 || w1 > 10240000)
+ throw LIBRAW_EXCEPTION_ALLOC;
++ if (w0 < 1 || w1 < 1)
++ throw LIBRAW_EXCEPTION_IO_CORRUPT;
+ yval[0] = (float *)calloc(head[1] * head[3] + head[2] * head[4], 6);
+ yval[1] = (float *)(yval[0] + head[1] * head[3]);
+ xval[0] = (ushort *)(yval[1] + head[2] * head[4]);
diff --git a/meta-openembedded/meta-oe/recipes-support/libraw/libraw_0.21.2.bb b/meta-openembedded/meta-oe/recipes-support/libraw/libraw_0.21.2.bb
index 4d089f3b79..1303c0e8ac 100644
--- a/meta-openembedded/meta-oe/recipes-support/libraw/libraw_0.21.2.bb
+++ b/meta-openembedded/meta-oe/recipes-support/libraw/libraw_0.21.2.bb
@@ -2,7 +2,12 @@ SUMMARY = "raw image decoder"
LICENSE = "LGPL-2.1-only | CDDL-1.0"
LIC_FILES_CHKSUM = "file://COPYRIGHT;md5=1501ae0aa3c8544e63f08d6f7bf88a6f"
-SRC_URI = "git://github.com/LibRaw/LibRaw.git;branch=0.21-stable;protocol=https"
+SRC_URI = " \
+ git://github.com/LibRaw/LibRaw.git;branch=0.21-stable;protocol=https \
+ file://0001-CVE-2025-43961-CVE-2025-43962.patch \
+ file://0002-CVE-2025-43963.patch \
+ file://0003-CVE-2025-43964.patch \
+"
SRCREV = "1ef70158d7fde1ced6aaddb0b9443c32a7121d3d"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-4877.patch b/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-4877.patch
new file mode 100644
index 0000000000..afea52c5b5
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-4877.patch
@@ -0,0 +1,57 @@
+From 6fd9cc8ce3958092a1aae11f1f2e911b2747732d Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Tue, 15 Apr 2025 11:41:24 +0200
+Subject: CVE-2025-4877 base64: Prevent integer overflow and potential OOB
+
+Set maximum input to 256MB to have safe margin to the 1GB trigger point
+for 32b arch.
+
+The OOB should not be reachable by any internal code paths as most of
+the buffers and strings we use as input for this operation already have
+similar limit and none really allows this much of data.
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+Reviewed-by: Andreas Schneider <asn@cryptomilk.org>
+(cherry picked from commit 00f09acbec55962839fc7837ef14c56fb8fbaf72)
+
+CVE: CVE-2025-4877
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=6fd9cc8ce3958092a1aae11f1f2e911b2747732d]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ src/base64.c | 13 ++++++++++++-
+ 1 file changed, 12 insertions(+), 1 deletion(-)
+
+diff --git a/src/base64.c b/src/base64.c
+index 4148f49c..f42e0e80 100644
+--- a/src/base64.c
++++ b/src/base64.c
+@@ -29,6 +29,9 @@
+ #include "libssh/priv.h"
+ #include "libssh/buffer.h"
+
++/* Do not allow encoding more than 256MB of data */
++#define BASE64_MAX_INPUT_LEN 256 * 1024 * 1024
++
+ static
+ const uint8_t alphabet[] = "ABCDEFGHIJKLMNOPQRSTUVWXYZ"
+ "abcdefghijklmnopqrstuvwxyz"
+@@ -274,7 +277,15 @@ uint8_t *bin_to_base64(const uint8_t *source, size_t len)
+ {
+ uint8_t *base64 = NULL;
+ uint8_t *ptr = NULL;
+- size_t flen = len + (3 - (len % 3)); /* round to upper 3 multiple */
++ size_t flen = 0;
++
++ /* Set the artificial upper limit for the input. Otherwise on 32b arch, the
++ * following line could overflow for sizes larger than SIZE_MAX / 4 */
++ if (len > BASE64_MAX_INPUT_LEN) {
++ return NULL;
++ }
++
++ flen = len + (3 - (len % 3)); /* round to upper 3 multiple */
+ flen = (4 * flen) / 3 + 1;
+
+ base64 = malloc(flen);
+--
+2.50.1
+
diff --git a/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-4878-0001.patch b/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-4878-0001.patch
new file mode 100644
index 0000000000..22f8733a69
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-4878-0001.patch
@@ -0,0 +1,2552 @@
+From 697650caa97eaf7623924c75f9fcfec6dd423cd1 Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Wed, 23 Apr 2025 17:57:11 +0200
+Subject: [PATCH] CVE-2025-4878 Initialize pointers where possible
+
+This is mostly mechanical change initializing all the pointers I was able to
+find with some grep and manual review of sources and examples.
+
+Used the following greps (which yield some false positives though):
+
+ git grep " \w* *\* *\w*;$"
+ git grep " ssh_session \w*;"
+ git grep " ssh_channel \w*;"
+ git grep " struct ssh_iterator \*\w*;"
+ git grep " ssh_bind \w*;"
+ git grep " ssh_key \w*;"
+ git grep " ssh_string \w*;"
+ git grep " ssh_buffer \w*;"
+ git grep " HMACCTX \w*;"
+ git grep " SHACTX \w*;"
+ grep -rinP '^(?!.*=)\s*(?:\w+\s+)*\w+\s*\*\s*\w+\s*;'
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+Reviewed-by: Andreas Schneider <asn@cryptomilk.org>
+
+CVE: CVE-2025-4878
+
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=697650caa97eaf7623924c75f9fcfec6dd423cd1]
+
+Signed-off-by: Divya Chellam <divya.chellam@windriver.com>
+---
+ doc/authentication.dox | 10 +++----
+ doc/command.dox | 2 +-
+ doc/forwarding.dox | 4 +--
+ doc/guided_tour.dox | 14 ++++-----
+ doc/shell.dox | 2 +-
+ examples/authentication.c | 12 ++++----
+ examples/connect_ssh.c | 2 +-
+ examples/exec.c | 4 +--
+ examples/knownhosts.c | 2 +-
+ examples/libssh_scp.c | 11 ++++----
+ examples/proxy.c | 18 ++++++------
+ examples/samplesshd-cb.c | 10 +++----
+ examples/samplesshd-kbdint.c | 16 +++++------
+ examples/scp_download.c | 4 +--
+ examples/senddata.c | 4 +--
+ examples/ssh_client.c | 8 +++---
+ examples/sshd_direct-tcpip.c | 14 ++++-----
+ examples/sshnetcat.c | 6 ++--
+ src/agent.c | 13 +++++----
+ src/auth.c | 7 +++--
+ src/bind.c | 11 ++++----
+ src/bind_config.c | 4 +--
+ src/buffer.c | 9 +++---
+ src/callbacks.c | 2 +-
+ src/chachapoly.c | 2 +-
+ src/channels.c | 55 ++++++++++++++++++------------------
+ src/client.c | 2 +-
+ src/config.c | 4 +--
+ src/config_parser.c | 12 ++++----
+ src/connect.c | 4 +--
+ src/connector.c | 5 ++--
+ src/dh_crypto.c | 2 +-
+ src/ecdh_gcrypt.c | 4 +--
+ src/gcrypt_missing.c | 2 +-
+ src/getpass.c | 4 +--
+ src/gssapi.c | 28 +++++++++---------
+ src/kex.c | 4 +--
+ src/known_hosts.c | 41 ++++++++++++++-------------
+ src/knownhosts.c | 18 ++++++------
+ src/legacy.c | 43 +++++++++++++++-------------
+ src/libmbedcrypto.c | 2 +-
+ src/log.c | 2 +-
+ src/messages.c | 18 ++++++------
+ src/misc.c | 24 ++++++++--------
+ src/options.c | 18 ++++++------
+ src/packet.c | 6 ++--
+ src/packet_crypt.c | 2 +-
+ src/pki.c | 50 ++++++++++++++++----------------
+ src/pki_container_openssh.c | 14 ++++-----
+ src/pki_crypto.c | 8 +++---
+ src/pki_ed25519.c | 6 ++--
+ src/pki_ed25519_common.c | 2 +-
+ src/pki_gcrypt.c | 12 ++++----
+ src/pki_mbedcrypto.c | 12 ++++----
+ src/poll.c | 10 +++----
+ src/server.c | 23 ++++++++-------
+ src/session.c | 14 ++++-----
+ src/sftpserver.c | 12 ++++----
+ src/string.c | 6 ++--
+ src/threads/winlocks.c | 2 +-
+ src/wrapper.c | 2 +-
+ 61 files changed, 340 insertions(+), 324 deletions(-)
+
+diff --git a/doc/authentication.dox b/doc/authentication.dox
+index 7d0ab81d..a0b2df84 100644
+--- a/doc/authentication.dox
++++ b/doc/authentication.dox
+@@ -105,7 +105,7 @@ Here is a small example of password authentication:
+ @code
+ int authenticate_password(ssh_session session)
+ {
+- char *password;
++ char *password = NULL;
+ int rc;
+
+ password = getpass("Enter your password: ");
+@@ -218,7 +218,7 @@ int authenticate_kbdint(ssh_session session)
+ rc = ssh_userauth_kbdint(session, NULL, NULL);
+ while (rc == SSH_AUTH_INFO)
+ {
+- const char *name, *instruction;
++ const char *name = NULL, *instruction = NULL;
+ int nprompts, iprompt;
+
+ name = ssh_userauth_kbdint_getname(session);
+@@ -231,7 +231,7 @@ int authenticate_kbdint(ssh_session session)
+ printf("%s\n", instruction);
+ for (iprompt = 0; iprompt < nprompts; iprompt++)
+ {
+- const char *prompt;
++ const char *prompt = NULL;
+ char echo;
+
+ prompt = ssh_userauth_kbdint_getprompt(session, iprompt, &echo);
+@@ -251,7 +251,7 @@ int authenticate_kbdint(ssh_session session)
+ }
+ else
+ {
+- char *ptr;
++ char *ptr = NULL;
+
+ ptr = getpass(prompt);
+ if (ssh_userauth_kbdint_setanswer(session, iprompt, ptr) < 0)
+@@ -354,7 +354,7 @@ The following example shows how to retrieve and dispose the issue banner:
+ int display_banner(ssh_session session)
+ {
+ int rc;
+- char *banner;
++ char *banner = NULL;
+
+ /*
+ *** Does not work without calling ssh_userauth_none() first ***
+diff --git a/doc/command.dox b/doc/command.dox
+index 588151c6..e82748ce 100644
+--- a/doc/command.dox
++++ b/doc/command.dox
+@@ -22,7 +22,7 @@ a SSH session that uses this channel:
+ @code
+ int show_remote_files(ssh_session session)
+ {
+- ssh_channel channel;
++ ssh_channel channel = NULL;
+ int rc;
+
+ channel = ssh_channel_new(session);
+diff --git a/doc/forwarding.dox b/doc/forwarding.dox
+index 2b202b4d..3ca3aa8a 100644
+--- a/doc/forwarding.dox
++++ b/doc/forwarding.dox
+@@ -100,7 +100,7 @@ used to retrieve google's home page from the remote SSH server.
+ @code
+ int direct_forwarding(ssh_session session)
+ {
+- ssh_channel forwarding_channel;
++ ssh_channel forwarding_channel = NULL;
+ int rc = SSH_ERROR;
+ char *http_get = "GET / HTTP/1.1\nHost: www.google.com\n\n";
+ int nbytes, nwritten;
+@@ -161,7 +161,7 @@ local libssh application, which handles them:
+ int web_server(ssh_session session)
+ {
+ int rc;
+- ssh_channel channel;
++ ssh_channel channel = NULL;
+ char buffer[256];
+ int nbytes, nwritten;
+ int port = 0;
+diff --git a/doc/guided_tour.dox b/doc/guided_tour.dox
+index 69576f18..60f4087e 100644
+--- a/doc/guided_tour.dox
++++ b/doc/guided_tour.dox
+@@ -79,7 +79,7 @@ Here is a small example of how to use it:
+
+ int main()
+ {
+- ssh_session my_ssh_session;
++ ssh_session my_ssh_session = NULL;
+ int verbosity = SSH_LOG_PROTOCOL;
+ int port = 22;
+
+@@ -126,7 +126,7 @@ Here's an example:
+
+ int main()
+ {
+- ssh_session my_ssh_session;
++ ssh_session my_ssh_session = NULL;
+ int rc;
+
+ my_ssh_session = ssh_new();
+@@ -190,8 +190,8 @@ int verify_knownhost(ssh_session session)
+ ssh_key srv_pubkey = NULL;
+ size_t hlen;
+ char buf[10];
+- char *hexa;
+- char *p;
++ char *hexa = NULL;
++ char *p = NULL;
+ int cmp;
+ int rc;
+
+@@ -317,9 +317,9 @@ The example below shows an authentication with password:
+
+ int main()
+ {
+- ssh_session my_ssh_session;
++ ssh_session my_ssh_session = NULL;
+ int rc;
+- char *password;
++ char *password = NULL;
+
+ // Open session and set options
+ my_ssh_session = ssh_new();
+@@ -380,7 +380,7 @@ The example below shows how to execute a remote command:
+ @code
+ int show_remote_processes(ssh_session session)
+ {
+- ssh_channel channel;
++ ssh_channel channel = NULL;
+ int rc;
+ char buffer[256];
+ int nbytes;
+diff --git a/doc/shell.dox b/doc/shell.dox
+index d770f27a..54d97888 100644
+--- a/doc/shell.dox
++++ b/doc/shell.dox
+@@ -26,7 +26,7 @@ The code sample below achieves these tasks:
+ @code
+ int shell_session(ssh_session session)
+ {
+- ssh_channel channel;
++ ssh_channel channel = NULL;
+ int rc;
+
+ channel = ssh_channel_new(session);
+diff --git a/examples/authentication.c b/examples/authentication.c
+index 7c47c8bd..31de7cfc 100644
+--- a/examples/authentication.c
++++ b/examples/authentication.c
+@@ -30,8 +30,8 @@ int authenticate_kbdint(ssh_session session, const char *password)
+
+ err = ssh_userauth_kbdint(session, NULL, NULL);
+ while (err == SSH_AUTH_INFO) {
+- const char *instruction;
+- const char *name;
++ const char *instruction = NULL;
++ const char *name = NULL;
+ char buffer[128];
+ int i, n;
+
+@@ -48,8 +48,8 @@ int authenticate_kbdint(ssh_session session, const char *password)
+ }
+
+ for (i = 0; i < n; i++) {
+- const char *answer;
+- const char *prompt;
++ const char *answer = NULL;
++ const char *prompt = NULL;
+ char echo;
+
+ prompt = ssh_userauth_kbdint_getprompt(session, i, &echo);
+@@ -58,7 +58,7 @@ int authenticate_kbdint(ssh_session session, const char *password)
+ }
+
+ if (echo) {
+- char *p;
++ char *p = NULL;
+
+ printf("%s", prompt);
+
+@@ -143,7 +143,7 @@ int authenticate_console(ssh_session session)
+ int rc;
+ int method;
+ char password[128] = {0};
+- char *banner;
++ char *banner = NULL;
+
+ // Try to authenticate
+ rc = ssh_userauth_none(session, NULL);
+diff --git a/examples/connect_ssh.c b/examples/connect_ssh.c
+index c9e4ef6e..06094272 100644
+--- a/examples/connect_ssh.c
++++ b/examples/connect_ssh.c
+@@ -22,7 +22,7 @@ clients must be made or how a client should react.
+ #include <stdio.h>
+
+ ssh_session connect_ssh(const char *host, const char *user,int verbosity){
+- ssh_session session;
++ ssh_session session = NULL;
+ int auth=0;
+
+ session=ssh_new();
+diff --git a/examples/exec.c b/examples/exec.c
+index 77d3be47..f90df364 100644
+--- a/examples/exec.c
++++ b/examples/exec.c
+@@ -5,8 +5,8 @@
+ #include "examples_common.h"
+
+ int main(void) {
+- ssh_session session;
+- ssh_channel channel;
++ ssh_session session = NULL;
++ ssh_channel channel = NULL;
+ char buffer[256];
+ int rbytes, wbytes, total = 0;
+ int rc;
+diff --git a/examples/knownhosts.c b/examples/knownhosts.c
+index 0726bfa8..2857a085 100644
+--- a/examples/knownhosts.c
++++ b/examples/knownhosts.c
+@@ -38,7 +38,7 @@ int verify_knownhost(ssh_session session)
+ char buf[10];
+ unsigned char *hash = NULL;
+ size_t hlen;
+- ssh_key srv_pubkey;
++ ssh_key srv_pubkey = NULL;
+ int rc;
+
+ rc = ssh_get_server_publickey(session, &srv_pubkey);
+diff --git a/examples/libssh_scp.c b/examples/libssh_scp.c
+index 6fdf8a4f..a332e0d2 100644
+--- a/examples/libssh_scp.c
++++ b/examples/libssh_scp.c
+@@ -26,9 +26,9 @@ program.
+ #define BUF_SIZE 16384
+ #endif
+
+-static char **sources;
++static char **sources = NULL;
+ static int nsources;
+-static char *destination;
++static char *destination = NULL;
+ static int verbosity = 0;
+
+ struct location {
+@@ -114,9 +114,10 @@ static void location_free(struct location *loc)
+ }
+ }
+
+-static struct location *parse_location(char *loc) {
+- struct location *location;
+- char *ptr;
++static struct location *parse_location(char *loc)
++{
++ struct location *location = NULL;
++ char *ptr = NULL;
+
+ location = malloc(sizeof(struct location));
+ if (location == NULL) {
+diff --git a/examples/proxy.c b/examples/proxy.c
+index 159a37e5..25451789 100644
+--- a/examples/proxy.c
++++ b/examples/proxy.c
+@@ -35,8 +35,8 @@ clients must be made or how a client should react.
+ static int authenticated=0;
+ static int tries = 0;
+ static int error = 0;
+-static ssh_channel chan=NULL;
+-static char *username;
++static ssh_channel chan = NULL;
++static char *username = NULL;
+ static ssh_gssapi_creds client_creds = NULL;
+
+ static int auth_password(ssh_session session, const char *user,
+@@ -216,11 +216,12 @@ static error_t parse_opt (int key, char *arg, struct argp_state *state) {
+ static struct argp argp = {options, parse_opt, args_doc, doc, NULL, NULL, NULL};
+ #endif /* HAVE_ARGP_H */
+
+-int main(int argc, char **argv){
+- ssh_session session;
+- ssh_bind sshbind;
+- ssh_event mainloop;
+- ssh_session client_session;
++int main(int argc, char **argv)
++{
++ ssh_session session = NULL;
++ ssh_bind sshbind = NULL;
++ ssh_event mainloop = NULL;
++ ssh_session client_session = NULL;
+
+ struct ssh_server_callbacks_struct cb = {
+ .userdata = NULL,
+@@ -231,7 +232,7 @@ int main(int argc, char **argv){
+
+ char buf[BUF_SIZE];
+ char host[128]="";
+- char *ptr;
++ char *ptr = NULL;
+ int i,r, rc;
+
+ sshbind=ssh_bind_new();
+@@ -348,4 +349,3 @@ int main(int argc, char **argv){
+ ssh_finalize();
+ return 0;
+ }
+-
+diff --git a/examples/samplesshd-cb.c b/examples/samplesshd-cb.c
+index e5b48994..693b040d 100644
+--- a/examples/samplesshd-cb.c
++++ b/examples/samplesshd-cb.c
+@@ -257,10 +257,11 @@ static error_t parse_opt (int key, char *arg, struct argp_state *state) {
+ static struct argp argp = {options, parse_opt, args_doc, doc, NULL, NULL, NULL};
+ #endif /* HAVE_ARGP_H */
+
+-int main(int argc, char **argv){
+- ssh_session session;
+- ssh_bind sshbind;
+- ssh_event mainloop;
++int main(int argc, char **argv)
++{
++ ssh_session session = NULL;
++ ssh_bind sshbind = NULL;
++ ssh_event mainloop = NULL;
+ struct ssh_server_callbacks_struct cb = {
+ .userdata = NULL,
+ .auth_none_function = auth_none,
+@@ -353,4 +354,3 @@ int main(int argc, char **argv){
+ ssh_finalize();
+ return 0;
+ }
+-
+diff --git a/examples/samplesshd-kbdint.c b/examples/samplesshd-kbdint.c
+index 6608306c..141088c2 100644
+--- a/examples/samplesshd-kbdint.c
++++ b/examples/samplesshd-kbdint.c
+@@ -187,8 +187,8 @@ static error_t parse_opt (int key, char *arg, struct argp_state *state) {
+ static struct argp argp = {options, parse_opt, args_doc, doc, NULL, NULL, NULL};
+ #endif /* HAVE_ARGP_H */
+
+-static const char *name;
+-static const char *instruction;
++static const char *name = NULL;
++static const char *instruction = NULL;
+ static const char *prompts[2];
+ static char echo[] = { 1, 0 };
+
+@@ -292,11 +292,12 @@ static int authenticate(ssh_session session) {
+ return 0;
+ }
+
+-int main(int argc, char **argv){
+- ssh_session session;
+- ssh_bind sshbind;
+- ssh_message message;
+- ssh_channel chan=0;
++int main(int argc, char **argv)
++{
++ ssh_session session = NULL;
++ ssh_bind sshbind = NULL;
++ ssh_message message = NULL;
++ ssh_channel chan = NULL;
+ char buf[BUF_SIZE];
+ int auth=0;
+ int shell=0;
+@@ -426,4 +427,3 @@ int main(int argc, char **argv){
+ ssh_finalize();
+ return 0;
+ }
+-
+diff --git a/examples/scp_download.c b/examples/scp_download.c
+index e6c1e796..dcaa2cb7 100644
+--- a/examples/scp_download.c
++++ b/examples/scp_download.c
+@@ -108,7 +108,7 @@ static int fetch_files(ssh_session session){
+ int size;
+ char buffer[BUF_SIZE];
+ int mode;
+- char *filename;
++ char *filename = NULL;
+ int r;
+ ssh_scp scp=ssh_scp_new(session, SSH_SCP_READ | SSH_SCP_RECURSIVE, "/tmp/libssh_tests/*");
+ if(ssh_scp_init(scp) != SSH_OK){
+@@ -167,7 +167,7 @@ static int fetch_files(ssh_session session){
+ }
+
+ int main(int argc, char **argv){
+- ssh_session session;
++ ssh_session session = NULL;
+ if(opts(argc,argv)<0)
+ return EXIT_FAILURE;
+ session=connect_ssh(host,NULL,verbosity);
+diff --git a/examples/senddata.c b/examples/senddata.c
+index 21181fb9..78383a2b 100644
+--- a/examples/senddata.c
++++ b/examples/senddata.c
+@@ -6,7 +6,7 @@
+ #define LIMIT 0x100000000UL
+
+ int main(void) {
+- ssh_session session;
++ ssh_session session = NULL;
+ ssh_channel channel;
+ char buffer[1024*1024];
+ int rc;
+@@ -47,7 +47,7 @@ int main(void) {
+ if(total > LIMIT)
+ break;
+ }
+-
++
+ if (rc < 0) {
+ printf("error : %s\n",ssh_get_error(session));
+ ssh_channel_close(channel);
+diff --git a/examples/ssh_client.c b/examples/ssh_client.c
+index aaf0cb5b..896890c3 100644
+--- a/examples/ssh_client.c
++++ b/examples/ssh_client.c
+@@ -53,7 +53,7 @@ static struct termios terminal;
+
+ static char *pcap_file = NULL;
+
+-static char *proxycommand;
++static char *proxycommand = NULL;
+
+ static int auth_callback(const char *prompt,
+ char *buf,
+@@ -252,7 +252,7 @@ static void select_loop(ssh_session session,ssh_channel channel)
+
+ static void shell(ssh_session session)
+ {
+- ssh_channel channel;
++ ssh_channel channel = NULL;
+ struct termios terminal_local;
+ int interactive=isatty(0);
+
+@@ -324,7 +324,7 @@ static void batch_shell(ssh_session session)
+ static int client(ssh_session session)
+ {
+ int auth = 0;
+- char *banner;
++ char *banner = NULL;
+ int state;
+
+ if (user) {
+@@ -408,7 +408,7 @@ static void cleanup_pcap(void)
+
+ int main(int argc, char **argv)
+ {
+- ssh_session session;
++ ssh_session session = NULL;
+
+ ssh_init();
+ session = ssh_new();
+diff --git a/examples/sshd_direct-tcpip.c b/examples/sshd_direct-tcpip.c
+index b0e29796..152377e9 100644
+--- a/examples/sshd_direct-tcpip.c
++++ b/examples/sshd_direct-tcpip.c
+@@ -358,7 +358,7 @@ my_fd_data_function(UNUSED_PARAM(socket_t fd),
+ {
+ struct event_fd_data_struct *event_fd_data = (struct event_fd_data_struct *)userdata;
+ ssh_channel channel = event_fd_data->channel;
+- ssh_session session;
++ ssh_session session = NULL;
+ int len, i, wr;
+ char buf[BUF_SIZE];
+ int blocking;
+@@ -452,8 +452,8 @@ open_tcp_socket(ssh_message msg)
+ {
+ struct sockaddr_in sin;
+ int forwardsock = -1;
+- struct hostent *host;
+- const char *dest_hostname;
++ struct hostent *host = NULL;
++ const char *dest_hostname = NULL;
+ int dest_port;
+
+ forwardsock = socket(AF_INET, SOCK_STREAM, 0);
+@@ -496,8 +496,8 @@ message_callback(UNUSED_PARAM(ssh_session session),
+ UNUSED_PARAM(void *userdata))
+ {
+ ssh_channel channel;
+- int socket_fd, *pFd;
+- struct ssh_channel_callbacks_struct *cb_chan;
++ int socket_fd, *pFd = NULL;
++ struct ssh_channel_callbacks_struct *cb_chan = NULL;
+ struct event_fd_data_struct *event_fd_data;
+
+ _ssh_log(SSH_LOG_PACKET, "=== message_callback", "Message type: %d",
+@@ -665,8 +665,8 @@ static struct argp argp = {options, parse_opt, args_doc, doc, NULL, NULL, NULL};
+ int
+ main(int argc, char **argv)
+ {
+- ssh_session session;
+- ssh_bind sshbind;
++ ssh_session session = NULL;
++ ssh_bind sshbind = NULL;
+ struct ssh_server_callbacks_struct cb = {
+ .userdata = NULL,
+ .auth_password_function = auth_password,
+diff --git a/examples/sshnetcat.c b/examples/sshnetcat.c
+index 59b0a289..8a1153a6 100644
+--- a/examples/sshnetcat.c
++++ b/examples/sshnetcat.c
+@@ -39,7 +39,7 @@ clients must be made or how a client should react.
+ #define BUF_SIZE 4096
+ #endif
+
+-char *host;
++char *host = NULL;
+ const char *desthost="localhost";
+ const char *port="22";
+
+@@ -193,7 +193,7 @@ static void forwarding(ssh_session session){
+
+ static int client(ssh_session session){
+ int auth=0;
+- char *banner;
++ char *banner = NULL;
+ int state;
+
+ if (ssh_options_set(session, SSH_OPTIONS_HOST ,host) < 0)
+@@ -246,7 +246,7 @@ void cleanup_pcap(void)
+ #endif
+
+ int main(int argc, char **argv){
+- ssh_session session;
++ ssh_session session = NULL;
+
+ session = ssh_new();
+
+diff --git a/src/agent.c b/src/agent.c
+index 6e3d7d79..c81b0805 100644
+--- a/src/agent.c
++++ b/src/agent.c
+@@ -424,8 +424,9 @@ ssh_key ssh_agent_get_first_ident(struct ssh_session_struct *session,
+
+ /* caller has to free comment */
+ ssh_key ssh_agent_get_next_ident(struct ssh_session_struct *session,
+- char **comment) {
+- struct ssh_key_struct *key;
++ char **comment)
++{
++ struct ssh_key_struct *key = NULL;
+ struct ssh_string_struct *blob = NULL;
+ struct ssh_string_struct *tmp = NULL;
+ int rc;
+@@ -494,10 +495,10 @@ ssh_string ssh_agent_sign_data(ssh_session session,
+ const ssh_key pubkey,
+ struct ssh_buffer_struct *data)
+ {
+- ssh_buffer request;
+- ssh_buffer reply;
+- ssh_string key_blob;
+- ssh_string sig_blob;
++ ssh_buffer request = NULL;
++ ssh_buffer reply = NULL;
++ ssh_string key_blob = NULL;
++ ssh_string sig_blob = NULL;
+ unsigned int type = 0;
+ unsigned int flags = 0;
+ uint32_t dlen;
+diff --git a/src/auth.c b/src/auth.c
+index 4feb6558..98022311 100644
+--- a/src/auth.c
++++ b/src/auth.c
+@@ -195,8 +195,9 @@ static int ssh_userauth_get_response(ssh_session session)
+ *
+ * This banner should be shown to user prior to authentication
+ */
+-SSH_PACKET_CALLBACK(ssh_packet_userauth_banner) {
+- ssh_string banner;
++SSH_PACKET_CALLBACK(ssh_packet_userauth_banner)
++{
++ ssh_string banner = NULL;
+ (void)type;
+ (void)user;
+
+@@ -1398,7 +1399,7 @@ int ssh_userauth_agent_pubkey(ssh_session session,
+ const char *username,
+ ssh_public_key publickey)
+ {
+- ssh_key key;
++ ssh_key key = NULL;
+ int rc;
+
+ key = ssh_key_new();
+diff --git a/src/bind.c b/src/bind.c
+index a91e6747..c331006a 100644
+--- a/src/bind.c
++++ b/src/bind.c
+@@ -74,7 +74,7 @@
+ static socket_t bind_socket(ssh_bind sshbind, const char *hostname,
+ int port) {
+ char port_c[6];
+- struct addrinfo *ai;
++ struct addrinfo *ai = NULL;
+ struct addrinfo hints;
+ int opt = 1;
+ socket_t s;
+@@ -132,8 +132,9 @@ static socket_t bind_socket(ssh_bind sshbind, const char *hostname,
+ return s;
+ }
+
+-ssh_bind ssh_bind_new(void) {
+- ssh_bind ptr;
++ssh_bind ssh_bind_new(void)
++{
++ ssh_bind ptr = NULL;
+
+ ptr = calloc(1, sizeof(struct ssh_bind_struct));
+ if (ptr == NULL) {
+@@ -251,7 +252,7 @@ static int ssh_bind_import_keys(ssh_bind sshbind) {
+ }
+
+ int ssh_bind_listen(ssh_bind sshbind) {
+- const char *host;
++ const char *host = NULL;
+ socket_t fd;
+ int rc;
+
+@@ -475,7 +476,7 @@ int ssh_bind_accept_fd(ssh_bind sshbind, ssh_session session, socket_t fd)
+ return SSH_ERROR;
+ }
+ } else {
+- char *p;
++ char *p = NULL;
+ /* If something was set to the session prior to calling this
+ * function, keep only what is allowed by the options set in
+ * sshbind */
+diff --git a/src/bind_config.c b/src/bind_config.c
+index 27c42c95..ed42cbe3 100644
+--- a/src/bind_config.c
++++ b/src/bind_config.c
+@@ -200,7 +200,7 @@ local_parse_file(ssh_bind bind,
+ uint8_t *seen,
+ unsigned int depth)
+ {
+- FILE *f;
++ FILE *f = NULL;
+ char line[MAX_LINE_SIZE] = {0};
+ unsigned int count = 0;
+ int rv;
+@@ -626,7 +626,7 @@ int ssh_bind_config_parse_file(ssh_bind bind, const char *filename)
+ {
+ char line[MAX_LINE_SIZE] = {0};
+ unsigned int count = 0;
+- FILE *f;
++ FILE *f = NULL;
+ uint32_t parser_flags;
+ int rv;
+
+diff --git a/src/buffer.c b/src/buffer.c
+index 8991e006..62fda334 100644
+--- a/src/buffer.c
++++ b/src/buffer.c
+@@ -371,7 +371,8 @@ int ssh_buffer_allocate_size(struct ssh_buffer_struct *buffer,
+ */
+ void *ssh_buffer_allocate(struct ssh_buffer_struct *buffer, uint32_t len)
+ {
+- void *ptr;
++ void *ptr = NULL;
++
+ buffer_verify(buffer);
+
+ if (buffer->used + len < len) {
+@@ -925,7 +926,7 @@ int ssh_buffer_pack_va(struct ssh_buffer_struct *buffer,
+ va_list ap)
+ {
+ int rc = SSH_ERROR;
+- const char *p;
++ const char *p = NULL;
+ union {
+ uint8_t byte;
+ uint16_t word;
+@@ -934,7 +935,7 @@ int ssh_buffer_pack_va(struct ssh_buffer_struct *buffer,
+ ssh_string string;
+ void *data;
+ } o;
+- char *cstring;
++ char *cstring = NULL;
+ bignum b;
+ size_t len;
+ size_t count;
+@@ -1093,7 +1094,7 @@ int ssh_buffer_unpack_va(struct ssh_buffer_struct *buffer,
+ va_list ap)
+ {
+ int rc = SSH_ERROR;
+- const char *p = format, *last;
++ const char *p = format, *last = NULL;
+ union {
+ uint8_t *byte;
+ uint16_t *word;
+diff --git a/src/callbacks.c b/src/callbacks.c
+index 3ed2f11c..6bfed62a 100644
+--- a/src/callbacks.c
++++ b/src/callbacks.c
+@@ -113,7 +113,7 @@ int ssh_add_channel_callbacks(ssh_channel channel, ssh_channel_callbacks cb)
+
+ int ssh_remove_channel_callbacks(ssh_channel channel, ssh_channel_callbacks cb)
+ {
+- struct ssh_iterator *it;
++ struct ssh_iterator *it = NULL;
+
+ if (channel == NULL || channel->callbacks == NULL){
+ return SSH_ERROR;
+diff --git a/src/chachapoly.c b/src/chachapoly.c
+index 2cd23854..354a0d26 100644
+--- a/src/chachapoly.c
++++ b/src/chachapoly.c
+@@ -42,7 +42,7 @@ static int chacha20_set_encrypt_key(struct ssh_cipher_struct *cipher,
+ void *key,
+ void *IV)
+ {
+- struct chacha20_poly1305_keysched *sched;
++ struct chacha20_poly1305_keysched *sched = NULL;
+ uint8_t *u8key = key;
+ (void)IV;
+
+diff --git a/src/channels.c b/src/channels.c
+index ab6915a2..8290dbd1 100644
+--- a/src/channels.c
++++ b/src/channels.c
+@@ -165,7 +165,7 @@ uint32_t ssh_channel_new_id(ssh_session session)
+ */
+ SSH_PACKET_CALLBACK(ssh_packet_channel_open_conf){
+ uint32_t channelid=0;
+- ssh_channel channel;
++ ssh_channel channel = NULL;
+ int rc;
+ (void)type;
+ (void)user;
+@@ -226,7 +226,7 @@ error:
+ */
+ SSH_PACKET_CALLBACK(ssh_packet_channel_open_fail){
+
+- ssh_channel channel;
++ ssh_channel channel = NULL;
+ char *error = NULL;
+ uint32_t code;
+ int rc;
+@@ -386,7 +386,7 @@ end:
+ /* return channel with corresponding local id, or NULL if not found */
+ ssh_channel ssh_channel_from_local(ssh_session session, uint32_t id) {
+ struct ssh_iterator *it;
+- ssh_channel channel;
++ ssh_channel channel = NULL;
+
+ for (it = ssh_list_get_iterator(session->channels); it != NULL ; it=it->next) {
+ channel = ssh_iterator_value(ssh_channel, it);
+@@ -471,7 +471,7 @@ error:
+ */
+ static ssh_channel channel_from_msg(ssh_session session, ssh_buffer packet)
+ {
+- ssh_channel channel;
++ ssh_channel channel = NULL;
+ uint32_t chan;
+ int rc;
+
+@@ -493,7 +493,7 @@ static ssh_channel channel_from_msg(ssh_session session, ssh_buffer packet)
+ }
+
+ SSH_PACKET_CALLBACK(channel_rcv_change_window) {
+- ssh_channel channel;
++ ssh_channel channel = NULL;
+ uint32_t bytes;
+ int rc;
+ (void)user;
+@@ -632,7 +632,7 @@ SSH_PACKET_CALLBACK(channel_rcv_data){
+ }
+
+ SSH_PACKET_CALLBACK(channel_rcv_eof) {
+- ssh_channel channel;
++ ssh_channel channel = NULL;
+ (void)user;
+ (void)type;
+
+@@ -676,8 +676,9 @@ static bool ssh_channel_has_unread_data(ssh_channel channel)
+ return false;
+ }
+
+-SSH_PACKET_CALLBACK(channel_rcv_close) {
+- ssh_channel channel;
++SSH_PACKET_CALLBACK(channel_rcv_close)
++{
++ ssh_channel channel = NULL;
+ (void)user;
+ (void)type;
+
+@@ -902,7 +903,7 @@ int channel_default_bufferize(ssh_channel channel,
+ void *data, uint32_t len,
+ bool is_stderr)
+ {
+- ssh_session session;
++ ssh_session session = NULL;
+
+ if(channel == NULL) {
+ return -1;
+@@ -1041,7 +1042,7 @@ int ssh_channel_open_auth_agent(ssh_channel channel)
+ int ssh_channel_open_forward(ssh_channel channel, const char *remotehost,
+ int remoteport, const char *sourcehost, int localport)
+ {
+- ssh_session session;
++ ssh_session session = NULL;
+ ssh_buffer payload = NULL;
+ ssh_string str = NULL;
+ int rc = SSH_ERROR;
+@@ -1179,7 +1180,7 @@ error:
+ */
+ void ssh_channel_free(ssh_channel channel)
+ {
+- ssh_session session;
++ ssh_session session = NULL;
+
+ if (channel == NULL) {
+ return;
+@@ -1280,7 +1281,7 @@ void ssh_channel_do_free(ssh_channel channel)
+ */
+ int ssh_channel_send_eof(ssh_channel channel)
+ {
+- ssh_session session;
++ ssh_session session = NULL;
+ int rc = SSH_ERROR;
+ int err;
+
+@@ -1341,7 +1342,7 @@ error:
+ */
+ int ssh_channel_close(ssh_channel channel)
+ {
+- ssh_session session;
++ ssh_session session = NULL;
+ int rc = 0;
+
+ if(channel == NULL) {
+@@ -1437,7 +1438,7 @@ static int channel_write_common(ssh_channel channel,
+ const void *data,
+ uint32_t len, int is_stderr)
+ {
+- ssh_session session;
++ ssh_session session = NULL;
+ uint32_t origlen = len;
+ size_t effectivelen;
+ size_t maxpacketlen;
+@@ -1694,7 +1695,7 @@ void ssh_channel_set_blocking(ssh_channel channel, int blocking)
+ * @brief handle a SSH_CHANNEL_SUCCESS packet and set the channel state.
+ */
+ SSH_PACKET_CALLBACK(ssh_packet_channel_success){
+- ssh_channel channel;
++ ssh_channel channel = NULL;
+ (void)type;
+ (void)user;
+
+@@ -1724,7 +1725,7 @@ SSH_PACKET_CALLBACK(ssh_packet_channel_success){
+ * @brief Handle a SSH_CHANNEL_FAILURE packet and set the channel state.
+ */
+ SSH_PACKET_CALLBACK(ssh_packet_channel_failure){
+- ssh_channel channel;
++ ssh_channel channel = NULL;
+ (void)type;
+ (void)user;
+
+@@ -1863,7 +1864,7 @@ error:
+ int ssh_channel_request_pty_size(ssh_channel channel, const char *terminal,
+ int col, int row)
+ {
+- ssh_session session;
++ ssh_session session = NULL;
+ ssh_buffer buffer = NULL;
+ int rc = SSH_ERROR;
+
+@@ -2174,7 +2175,7 @@ static ssh_channel ssh_channel_accept(ssh_session session, int channeltype,
+ #endif
+ ssh_message msg = NULL;
+ ssh_channel channel = NULL;
+- struct ssh_iterator *iterator;
++ struct ssh_iterator *iterator = NULL;
+ int t;
+
+ /*
+@@ -2838,7 +2839,7 @@ error:
+ int channel_read_buffer(ssh_channel channel, ssh_buffer buffer, uint32_t count,
+ int is_stderr)
+ {
+- ssh_session session;
++ ssh_session session = NULL;
+ char *buffer_tmp = NULL;
+ int r;
+ uint32_t total=0;
+@@ -2979,7 +2980,7 @@ int ssh_channel_read_timeout(ssh_channel channel,
+ int is_stderr,
+ int timeout_ms)
+ {
+- ssh_session session;
++ ssh_session session = NULL;
+ ssh_buffer stdbuf;
+ uint32_t len;
+ struct ssh_channel_read_termination_struct ctx;
+@@ -3103,7 +3104,7 @@ int ssh_channel_read_nonblocking(ssh_channel channel,
+ uint32_t count,
+ int is_stderr)
+ {
+- ssh_session session;
++ ssh_session session = NULL;
+ uint32_t to_read;
+ int rc;
+ int blocking;
+@@ -3213,8 +3214,8 @@ int ssh_channel_poll(ssh_channel channel, int is_stderr)
+ */
+ int ssh_channel_poll_timeout(ssh_channel channel, int timeout, int is_stderr)
+ {
+- ssh_session session;
+- ssh_buffer stdbuf;
++ ssh_session session = NULL;
++ ssh_buffer stdbuf = NULL;
+ struct ssh_channel_read_termination_struct ctx;
+ size_t len;
+ int rc;
+@@ -3341,7 +3342,7 @@ channel_protocol_select(ssh_channel *rchans, ssh_channel *wchans,
+ ssh_channel *echans, ssh_channel *rout,
+ ssh_channel *wout, ssh_channel *eout)
+ {
+- ssh_channel chan;
++ ssh_channel chan = NULL;
+ int i;
+ int j = 0;
+
+@@ -3422,7 +3423,7 @@ static size_t count_ptrs(ssh_channel *ptrs)
+ int ssh_channel_select(ssh_channel *readchans, ssh_channel *writechans,
+ ssh_channel *exceptchans, struct timeval * timeout)
+ {
+- ssh_channel *rchans, *wchans, *echans;
++ ssh_channel *rchans = NULL, *wchans = NULL, *echans = NULL;
+ ssh_channel dummy = NULL;
+ ssh_event event = NULL;
+ int rc;
+@@ -3615,7 +3616,7 @@ int ssh_channel_write_stderr(ssh_channel channel, const void *data, uint32_t len
+ int ssh_channel_open_reverse_forward(ssh_channel channel, const char *remotehost,
+ int remoteport, const char *sourcehost, int localport)
+ {
+- ssh_session session;
++ ssh_session session = NULL;
+ ssh_buffer payload = NULL;
+ int rc = SSH_ERROR;
+
+@@ -3679,7 +3680,7 @@ error:
+ int ssh_channel_open_x11(ssh_channel channel,
+ const char *orig_addr, int orig_port)
+ {
+- ssh_session session;
++ ssh_session session = NULL;
+ ssh_buffer payload = NULL;
+ int rc = SSH_ERROR;
+
+diff --git a/src/client.c b/src/client.c
+index e912090e..0cfca1c4 100644
+--- a/src/client.c
++++ b/src/client.c
+@@ -748,7 +748,7 @@ ssh_session_set_disconnect_message(ssh_session session, const char *message)
+ void
+ ssh_disconnect(ssh_session session)
+ {
+- struct ssh_iterator *it;
++ struct ssh_iterator *it = NULL;
+ int rc;
+
+ if (session == NULL) {
+diff --git a/src/config.c b/src/config.c
+index c5c40125..d4d8d419 100644
+--- a/src/config.c
++++ b/src/config.c
+@@ -203,7 +203,7 @@ local_parse_file(ssh_session session,
+ unsigned int depth,
+ bool global)
+ {
+- FILE *f;
++ FILE *f = NULL;
+ char line[MAX_LINE_SIZE] = {0};
+ unsigned int count = 0;
+ int rv;
+@@ -1201,7 +1201,7 @@ int ssh_config_parse_file(ssh_session session, const char *filename)
+ {
+ char line[MAX_LINE_SIZE] = {0};
+ unsigned int count = 0;
+- FILE *f;
++ FILE *f = NULL;
+ int parsing, rv;
+ bool global = 0;
+
+diff --git a/src/config_parser.c b/src/config_parser.c
+index b8b94611..e55c76d0 100644
+--- a/src/config_parser.c
++++ b/src/config_parser.c
+@@ -39,8 +39,8 @@
+ */
+ char *ssh_config_get_cmd(char **str)
+ {
+- register char *c;
+- char *r;
++ register char *c = NULL;
++ char *r = NULL;
+
+ /* Ignore leading spaces */
+ for (c = *str; *c; c++) {
+@@ -67,7 +67,7 @@ out:
+ */
+ char *ssh_config_get_token(char **str)
+ {
+- register char *c;
++ register char *c = NULL;
+ bool had_equal = false;
+ char *r = NULL;
+
+@@ -116,7 +116,7 @@ out:
+
+ long ssh_config_get_long(char **str, long notfound)
+ {
+- char *p, *endp;
++ char *p = NULL, *endp = NULL;
+ long i;
+
+ p = ssh_config_get_token(str);
+@@ -133,7 +133,7 @@ long ssh_config_get_long(char **str, long notfound)
+
+ const char *ssh_config_get_str_tok(char **str, const char *def)
+ {
+- char *p;
++ char *p = NULL;
+
+ p = ssh_config_get_token(str);
+ if (p && *p) {
+@@ -145,7 +145,7 @@ const char *ssh_config_get_str_tok(char **str, const char *def)
+
+ int ssh_config_get_yesno(char **str, int notfound)
+ {
+- const char *p;
++ const char *p = NULL;
+
+ p = ssh_config_get_str_tok(str, NULL);
+ if (p == NULL) {
+diff --git a/src/connect.c b/src/connect.c
+index 15cae644..2d09af5e 100644
+--- a/src/connect.c
++++ b/src/connect.c
+@@ -194,8 +194,8 @@ socket_t ssh_connect_host_nonblocking(ssh_session session, const char *host,
+ }
+
+ if (bind_addr) {
+- struct addrinfo *bind_ai;
+- struct addrinfo *bind_itr;
++ struct addrinfo *bind_ai = NULL;
++ struct addrinfo *bind_itr = NULL;
+
+ SSH_LOG(SSH_LOG_PACKET, "Resolving %s", bind_addr);
+
+diff --git a/src/connector.c b/src/connector.c
+index 56716749..6632cca1 100644
+--- a/src/connector.c
++++ b/src/connector.c
+@@ -637,8 +637,9 @@ error:
+ return rc;
+ }
+
+-int ssh_connector_remove_event(ssh_connector connector) {
+- ssh_session session;
++int ssh_connector_remove_event(ssh_connector connector)
++{
++ ssh_session session = NULL;
+
+ if (connector->in_poll != NULL) {
+ ssh_event_remove_poll(connector->event, connector->in_poll);
+diff --git a/src/dh_crypto.c b/src/dh_crypto.c
+index 9ff7ad3c..4dd9b507 100644
+--- a/src/dh_crypto.c
++++ b/src/dh_crypto.c
+@@ -404,7 +404,7 @@ done:
+ */
+ int ssh_dh_init_common(struct ssh_crypto_struct *crypto)
+ {
+- struct dh_ctx *ctx;
++ struct dh_ctx *ctx = NULL;
+ int rc;
+
+ ctx = calloc(1, sizeof(*ctx));
+diff --git a/src/ecdh_gcrypt.c b/src/ecdh_gcrypt.c
+index 3d9d426f..73fcd50f 100644
+--- a/src/ecdh_gcrypt.c
++++ b/src/ecdh_gcrypt.c
+@@ -132,9 +132,9 @@ int ecdh_build_k(ssh_session session)
+ #else
+ size_t k_len = 0;
+ enum ssh_key_exchange_e kex_type = session->next_crypto->kex_type;
+- ssh_string s;
++ ssh_string s = NULL;
+ #endif
+- ssh_string pubkey_raw;
++ ssh_string pubkey_raw = NULL;
+ gcry_sexp_t pubkey = NULL;
+ ssh_string privkey = NULL;
+ int rc = SSH_ERROR;
+diff --git a/src/gcrypt_missing.c b/src/gcrypt_missing.c
+index e931ec5b..56dcfb6d 100644
+--- a/src/gcrypt_missing.c
++++ b/src/gcrypt_missing.c
+@@ -47,7 +47,7 @@ int ssh_gcry_dec2bn(bignum *bn, const char *data) {
+
+ char *ssh_gcry_bn2dec(bignum bn) {
+ bignum bndup, num, ten;
+- char *ret;
++ char *ret = NULL;
+ int count, count2;
+ int size, rsize;
+ char decnum;
+diff --git a/src/getpass.c b/src/getpass.c
+index 6be33c77..c19c4bc0 100644
+--- a/src/getpass.c
++++ b/src/getpass.c
+@@ -46,7 +46,7 @@
+ */
+ static int ssh_gets(const char *prompt, char *buf, size_t len, int verify)
+ {
+- char *tmp;
++ char *tmp = NULL;
+ char *ptr = NULL;
+ int ok = 0;
+
+@@ -78,7 +78,7 @@ static int ssh_gets(const char *prompt, char *buf, size_t len, int verify)
+ }
+
+ if (verify) {
+- char *key_string;
++ char *key_string = NULL;
+
+ key_string = calloc(1, len);
+ if (key_string == NULL) {
+diff --git a/src/gssapi.c b/src/gssapi.c
+index 5325ac72..fd7b25af 100644
+--- a/src/gssapi.c
++++ b/src/gssapi.c
+@@ -196,7 +196,7 @@ ssh_gssapi_handle_userauth(ssh_session session, const char *user,
+ gss_name_t server_name; /* local server fqdn */
+ OM_uint32 maj_stat, min_stat;
+ size_t i;
+- char *ptr;
++ char *ptr = NULL;
+ gss_OID_set supported; /* oids supported by server */
+ gss_OID_set both_supported; /* oids supported by both client and server */
+ gss_OID_set selected; /* oid selected for authentication */
+@@ -341,7 +341,7 @@ static char *ssh_gssapi_name_to_char(gss_name_t name)
+ {
+ gss_buffer_desc buffer;
+ OM_uint32 maj_stat, min_stat;
+- char *ptr;
++ char *ptr = NULL;
+ maj_stat = gss_display_name(&min_stat, name, &buffer, NULL);
+ ssh_gssapi_log_error(SSH_LOG_WARNING,
+ "converting name",
+@@ -359,9 +359,10 @@ static char *ssh_gssapi_name_to_char(gss_name_t name)
+
+ }
+
+-SSH_PACKET_CALLBACK(ssh_packet_userauth_gssapi_token_server){
+- ssh_string token;
+- char *hexa;
++SSH_PACKET_CALLBACK(ssh_packet_userauth_gssapi_token_server)
++{
++ ssh_string token = NULL;
++ char *hexa = NULL;
+ OM_uint32 maj_stat, min_stat;
+ gss_buffer_desc input_token, output_token = GSS_C_EMPTY_BUFFER;
+ gss_name_t client_name = GSS_C_NO_NAME;
+@@ -385,7 +386,7 @@ SSH_PACKET_CALLBACK(ssh_packet_userauth_gssapi_token_server){
+ }
+
+ if (ssh_callbacks_exists(session->server_callbacks, gssapi_accept_sec_ctx_function)){
+- ssh_string out_token=NULL;
++ ssh_string out_token = NULL;
+ rc = session->server_callbacks->gssapi_accept_sec_ctx_function(session,
+ token, &out_token, session->server_callbacks->userdata);
+ if (rc == SSH_ERROR){
+@@ -507,7 +508,7 @@ static ssh_buffer ssh_gssapi_build_mic(ssh_session session)
+
+ SSH_PACKET_CALLBACK(ssh_packet_userauth_gssapi_mic)
+ {
+- ssh_string mic_token;
++ ssh_string mic_token = NULL;
+ OM_uint32 maj_stat, min_stat;
+ gss_buffer_desc mic_buf = GSS_C_EMPTY_BUFFER;
+ gss_buffer_desc mic_token_buf = GSS_C_EMPTY_BUFFER;
+@@ -670,7 +671,7 @@ static int ssh_gssapi_match(ssh_session session, gss_OID_set *valid_oids)
+ gss_name_t client_id = GSS_C_NO_NAME;
+ gss_OID oid;
+ unsigned int i;
+- char *ptr;
++ char *ptr = NULL;
+ int ret;
+
+ if (session->gssapi->client.client_deleg_creds == NULL) {
+@@ -866,11 +867,11 @@ static gss_OID ssh_gssapi_oid_from_string(ssh_string oid_s)
+
+ SSH_PACKET_CALLBACK(ssh_packet_userauth_gssapi_response){
+ int rc;
+- ssh_string oid_s;
++ ssh_string oid_s = NULL;
+ gss_uint32 maj_stat, min_stat;
+ gss_buffer_desc input_token = GSS_C_EMPTY_BUFFER;
+ gss_buffer_desc output_token = GSS_C_EMPTY_BUFFER;
+- char *hexa;
++ char *hexa = NULL;
+ (void)type;
+ (void)user;
+
+@@ -987,10 +988,11 @@ static int ssh_gssapi_send_mic(ssh_session session)
+ return ssh_packet_send(session);
+ }
+
+-SSH_PACKET_CALLBACK(ssh_packet_userauth_gssapi_token_client){
++SSH_PACKET_CALLBACK(ssh_packet_userauth_gssapi_token_client)
++{
+ int rc;
+- ssh_string token;
+- char *hexa;
++ ssh_string token = NULL;
++ char *hexa = NULL;
+ OM_uint32 maj_stat, min_stat;
+ gss_buffer_desc input_token, output_token = GSS_C_EMPTY_BUFFER;
+ (void)user;
+diff --git a/src/kex.c b/src/kex.c
+index fbc70cf4..ecfc0120 100644
+--- a/src/kex.c
++++ b/src/kex.c
+@@ -330,7 +330,7 @@ static int cmp_first_kex_algo(const char *client_str,
+ size_t client_kex_len;
+ size_t server_kex_len;
+
+- char *colon;
++ char *colon = NULL;
+
+ int is_wrong = 1;
+
+@@ -762,7 +762,7 @@ char *ssh_client_select_hostkeys(ssh_session session)
+ int ssh_set_client_kex(ssh_session session)
+ {
+ struct ssh_kex_struct *client = &session->next_crypto->client_kex;
+- const char *wanted;
++ const char *wanted = NULL;
+ int ok;
+ int i;
+
+diff --git a/src/known_hosts.c b/src/known_hosts.c
+index 84e15572..f660a6f3 100644
+--- a/src/known_hosts.c
++++ b/src/known_hosts.c
+@@ -79,8 +79,8 @@ static struct ssh_tokens_st *ssh_get_knownhost_line(FILE **file,
+ const char **found_type)
+ {
+ char buffer[MAX_LINE_SIZE] = {0};
+- char *ptr;
+- struct ssh_tokens_st *tokens;
++ char *ptr = NULL;
++ struct ssh_tokens_st *tokens = NULL;
+
+ if (*file == NULL) {
+ *file = fopen(filename,"r");
+@@ -149,7 +149,7 @@ static struct ssh_tokens_st *ssh_get_knownhost_line(FILE **file,
+ static int check_public_key(ssh_session session, char **tokens) {
+ ssh_string pubkey_blob = NULL;
+ ssh_buffer pubkey_buffer;
+- char *pubkey_64;
++ char *pubkey_64 = NULL;
+ int rc;
+
+ /* ssh-dss or ssh-rsa */
+@@ -205,11 +205,11 @@ static int match_hashed_host(const char *host, const char *sourcehash)
+ * hash := HMAC_SHA1(key=salt,data=host)
+ */
+ unsigned char buffer[256] = {0};
+- ssh_buffer salt;
+- ssh_buffer hash;
+- HMACCTX mac;
+- char *source;
+- char *b64hash;
++ ssh_buffer salt = NULL;
++ ssh_buffer hash = NULL;
++ HMACCTX mac = NULL;
++ char *source = NULL;
++ char *b64hash = NULL;
+ int match, rc;
+ size_t size;
+
+@@ -304,14 +304,14 @@ static int match_hashed_host(const char *host, const char *sourcehash)
+ int ssh_is_server_known(ssh_session session)
+ {
+ FILE *file = NULL;
+- char *host;
+- char *hostport;
+- const char *type;
++ char *host = NULL;
++ char *hostport = NULL;
++ const char *type = NULL;
+ int match;
+ int i = 0;
+- char *files[3];
++ char *files[3] = {0};
+
+- struct ssh_tokens_st *tokens;
++ struct ssh_tokens_st *tokens = NULL;
+
+ int ret = SSH_SERVER_NOT_KNOWN;
+
+@@ -443,12 +443,13 @@ int ssh_is_server_known(ssh_session session)
+ * @deprecated Please use ssh_session_export_known_hosts_entry()
+ * @brief This function is deprecated.
+ */
+-char * ssh_dump_knownhost(ssh_session session) {
++char *ssh_dump_knownhost(ssh_session session)
++{
+ ssh_key server_pubkey = NULL;
+- char *host;
+- char *hostport;
+- char *buffer;
+- char *b64_key;
++ char *host = NULL;
++ char *hostport = NULL;
++ char *buffer = NULL;
++ char *b64_key = NULL;
+ int rc;
+
+ if (session->opts.host == NULL) {
+@@ -513,9 +514,9 @@ char * ssh_dump_knownhost(ssh_session session) {
+ */
+ int ssh_write_knownhost(ssh_session session)
+ {
+- FILE *file;
++ FILE *file = NULL;
+ char *buffer = NULL;
+- char *dir;
++ char *dir = NULL;
+ int rc;
+
+ if (session->opts.knownhosts == NULL) {
+diff --git a/src/knownhosts.c b/src/knownhosts.c
+index 9f978096..109b4f06 100644
+--- a/src/knownhosts.c
++++ b/src/knownhosts.c
+@@ -61,7 +61,7 @@ static int hash_hostname(const char *name,
+ size_t *hash_size)
+ {
+ int rc;
+- HMACCTX mac_ctx;
++ HMACCTX mac_ctx = NULL;
+
+ mac_ctx = hmac_init(salt, salt_size, SSH_HMAC_SHA1);
+ if (mac_ctx == NULL) {
+@@ -81,8 +81,8 @@ static int hash_hostname(const char *name,
+
+ static int match_hashed_hostname(const char *host, const char *hashed_host)
+ {
+- char *hashed;
+- char *b64_hash;
++ char *hashed = NULL;
++ char *b64_hash = NULL;
+ ssh_buffer salt = NULL;
+ ssh_buffer hash = NULL;
+ unsigned char hashed_buf[256] = {0};
+@@ -229,7 +229,7 @@ static int ssh_known_hosts_read_entries(const char *match,
+ char line[MAX_LINE_SIZE];
+ size_t lineno = 0;
+ size_t len = 0;
+- FILE *fp;
++ FILE *fp = NULL;
+ int rc;
+
+ fp = fopen(filename, "r");
+@@ -288,7 +288,7 @@ static int ssh_known_hosts_read_entries(const char *match,
+ for (it = ssh_list_get_iterator(*entries);
+ it != NULL;
+ it = it->next) {
+- struct ssh_knownhosts_entry *entry2;
++ struct ssh_knownhosts_entry *entry2 = NULL;
+ int cmp;
+ entry2 = ssh_iterator_value(struct ssh_knownhosts_entry *, it);
+ cmp = ssh_known_hosts_entries_compare(entry, entry2);
+@@ -312,8 +312,8 @@ error:
+
+ static char *ssh_session_get_host_port(ssh_session session)
+ {
+- char *host_port;
+- char *host;
++ char *host_port = NULL;
++ char *host = NULL;
+
+ if (session->opts.host == NULL) {
+ ssh_set_error(session,
+@@ -537,7 +537,7 @@ char *ssh_known_hosts_get_algorithms_names(ssh_session session)
+ char *host_port = NULL;
+ size_t count;
+ bool needcomma = false;
+- char *names;
++ char *names = NULL;
+
+ int rc;
+
+@@ -645,7 +645,7 @@ int ssh_known_hosts_parse_line(const char *hostname,
+ {
+ struct ssh_knownhosts_entry *e = NULL;
+ char *known_host = NULL;
+- char *p;
++ char *p = NULL;
+ char *save_tok = NULL;
+ enum ssh_keytypes_e key_type;
+ int match = 0;
+diff --git a/src/legacy.c b/src/legacy.c
+index 7b165dbe..7359040c 100644
+--- a/src/legacy.c
++++ b/src/legacy.c
+@@ -48,7 +48,7 @@ int ssh_auth_list(ssh_session session) {
+ int ssh_userauth_offer_pubkey(ssh_session session, const char *username,
+ int type, ssh_string publickey)
+ {
+- ssh_key key;
++ ssh_key key = NULL;
+ int rc;
+
+ (void) type; /* unused */
+@@ -70,7 +70,7 @@ int ssh_userauth_pubkey(ssh_session session,
+ ssh_string publickey,
+ ssh_private_key privatekey)
+ {
+- ssh_key key;
++ ssh_key key = NULL;
+ int rc;
+
+ (void) publickey; /* unused */
+@@ -389,10 +389,11 @@ void publickey_free(ssh_public_key key) {
+ SAFE_FREE(key);
+ }
+
+-ssh_public_key publickey_from_privatekey(ssh_private_key prv) {
+- struct ssh_public_key_struct *p;
+- ssh_key privkey;
+- ssh_key pubkey;
++ssh_public_key publickey_from_privatekey(ssh_private_key prv)
++{
++ struct ssh_public_key_struct *p = NULL;
++ ssh_key privkey = NULL;
++ ssh_key pubkey = NULL;
+ int rc;
+
+ privkey = ssh_key_new();
+@@ -434,8 +435,8 @@ ssh_private_key privatekey_from_file(ssh_session session,
+ const char *passphrase) {
+ ssh_auth_callback auth_fn = NULL;
+ void *auth_data = NULL;
+- ssh_private_key privkey;
+- ssh_key key;
++ ssh_private_key privkey = NULL;
++ ssh_key key = NULL;
+ int rc;
+
+ (void) type; /* unused */
+@@ -510,7 +511,7 @@ void privatekey_free(ssh_private_key prv) {
+
+ ssh_string publickey_from_file(ssh_session session, const char *filename,
+ int *type) {
+- ssh_key key;
++ ssh_key key = NULL;
+ ssh_string key_str = NULL;
+ int rc;
+
+@@ -543,9 +544,10 @@ int ssh_type_from_name(const char *name) {
+ return ssh_key_type_from_name(name);
+ }
+
+-ssh_public_key publickey_from_string(ssh_session session, ssh_string pubkey_s) {
+- struct ssh_public_key_struct *pubkey;
+- ssh_key key;
++ssh_public_key publickey_from_string(ssh_session session, ssh_string pubkey_s)
++{
++ struct ssh_public_key_struct *pubkey = NULL;
++ ssh_key key = NULL;
+ int rc;
+
+ (void) session; /* unused */
+@@ -579,9 +581,10 @@ ssh_public_key publickey_from_string(ssh_session session, ssh_string pubkey_s) {
+ return pubkey;
+ }
+
+-ssh_string publickey_to_string(ssh_public_key pubkey) {
+- ssh_key key;
+- ssh_string key_blob;
++ssh_string publickey_to_string(ssh_public_key pubkey)
++{
++ ssh_key key = NULL;
++ ssh_string key_blob = NULL;
+ int rc;
+
+ if (pubkey == NULL) {
+@@ -624,11 +627,11 @@ int ssh_publickey_to_file(ssh_session session,
+ ssh_string pubkey,
+ int type)
+ {
+- FILE *fp;
+- char *user;
++ FILE *fp = NULL;
++ char *user = NULL;
+ char buffer[1024];
+ char host[256];
+- unsigned char *pubkey_64;
++ unsigned char *pubkey_64 = NULL;
+ size_t len;
+ int rc;
+ if(session==NULL)
+@@ -695,9 +698,9 @@ int ssh_try_publickey_from_file(ssh_session session,
+ const char *keyfile,
+ ssh_string *publickey,
+ int *type) {
+- char *pubkey_file;
++ char *pubkey_file = NULL;
+ size_t len;
+- ssh_string pubkey_string;
++ ssh_string pubkey_string = NULL;
+ int pubkey_type;
+
+ if (session == NULL || keyfile == NULL || publickey == NULL || type == NULL) {
+diff --git a/src/libmbedcrypto.c b/src/libmbedcrypto.c
+index caa3b6e9..422d5ae2 100644
+--- a/src/libmbedcrypto.c
++++ b/src/libmbedcrypto.c
+@@ -133,7 +133,7 @@ cipher_init(struct ssh_cipher_struct *cipher,
+ void *IV)
+ {
+ const mbedtls_cipher_info_t *cipher_info = NULL;
+- mbedtls_cipher_context_t *ctx;
++ mbedtls_cipher_context_t *ctx = NULL;
+ size_t key_bitlen = 0;
+ size_t iv_size = 0;
+ int rc;
+diff --git a/src/log.c b/src/log.c
+index 5bae18b8..fabbe945 100644
+--- a/src/log.c
++++ b/src/log.c
+@@ -44,7 +44,7 @@
+
+ static LIBSSH_THREAD int ssh_log_level;
+ static LIBSSH_THREAD ssh_logging_callback ssh_log_cb;
+-static LIBSSH_THREAD void *ssh_log_userdata;
++static LIBSSH_THREAD void *ssh_log_userdata = NULL;
+
+ /**
+ * @defgroup libssh_log The SSH logging functions
+diff --git a/src/messages.c b/src/messages.c
+index 3f969536..6dadabf0 100644
+--- a/src/messages.c
++++ b/src/messages.c
+@@ -479,7 +479,7 @@ static void ssh_message_queue(ssh_session session, ssh_message message)
+ */
+ ssh_message ssh_message_pop_head(ssh_session session){
+ ssh_message msg=NULL;
+- struct ssh_iterator *i;
++ struct ssh_iterator *i = NULL;
+ if(session->ssh_message_list == NULL)
+ return NULL;
+ i=ssh_list_get_iterator(session->ssh_message_list);
+@@ -493,7 +493,7 @@ ssh_message ssh_message_pop_head(ssh_session session){
+ /* Returns 1 if there is a message available */
+ static int ssh_message_termination(void *s){
+ ssh_session session = s;
+- struct ssh_iterator *it;
++ struct ssh_iterator *it = NULL;
+ if(session->session_state == SSH_SESSION_STATE_ERROR)
+ return 1;
+ it = ssh_list_get_iterator(session->ssh_message_list);
+@@ -694,7 +694,7 @@ static ssh_buffer ssh_msg_userauth_build_digest(ssh_session session,
+ ssh_string algo)
+ {
+ struct ssh_crypto_struct *crypto = NULL;
+- ssh_buffer buffer;
++ ssh_buffer buffer = NULL;
+ ssh_string str=NULL;
+ int rc;
+
+@@ -933,9 +933,9 @@ SSH_PACKET_CALLBACK(ssh_packet_userauth_request){
+ #ifdef WITH_GSSAPI
+ if (strcmp(method, "gssapi-with-mic") == 0) {
+ uint32_t n_oid;
+- ssh_string *oids;
+- ssh_string oid;
+- char *hexa;
++ ssh_string *oids = NULL;
++ ssh_string oid = NULL;
++ char *hexa = NULL;
+ int i;
+ ssh_buffer_get_u32(packet, &n_oid);
+ n_oid=ntohl(n_oid);
+@@ -1019,7 +1019,7 @@ SSH_PACKET_CALLBACK(ssh_packet_userauth_info_response){
+ SSH_PACKET_CALLBACK(ssh_packet_userauth_info_response){
+ uint32_t nanswers;
+ uint32_t i;
+- ssh_string tmp;
++ ssh_string tmp = NULL;
+ int rc;
+
+ ssh_message msg = NULL;
+@@ -1251,7 +1251,7 @@ end:
+ * @returns SSH_OK on success, SSH_ERROR if an error occurred.
+ */
+ int ssh_message_channel_request_open_reply_accept_channel(ssh_message msg, ssh_channel chan) {
+- ssh_session session;
++ ssh_session session = NULL;
+ int rc;
+
+ if (msg == NULL) {
+@@ -1302,7 +1302,7 @@ int ssh_message_channel_request_open_reply_accept_channel(ssh_message msg, ssh_c
+ * @returns NULL in case of error
+ */
+ ssh_channel ssh_message_channel_request_open_reply_accept(ssh_message msg) {
+- ssh_channel chan;
++ ssh_channel chan = NULL;
+ int rc;
+
+ if (msg == NULL) {
+diff --git a/src/misc.c b/src/misc.c
+index 7081f12a..f371f332 100644
+--- a/src/misc.c
++++ b/src/misc.c
+@@ -393,7 +393,7 @@ int ssh_is_ipaddr(const char *str)
+
+ char *ssh_lowercase(const char* str)
+ {
+- char *new, *p;
++ char *new = NULL, *p = NULL;
+
+ if (str == NULL) {
+ return NULL;
+@@ -447,7 +447,7 @@ char *ssh_hostport(const char *host, int port)
+ char *ssh_get_hexa(const unsigned char *what, size_t len)
+ {
+ const char h[] = "0123456789abcdef";
+- char *hexa;
++ char *hexa = NULL;
+ size_t i;
+ size_t hlen = len * 3;
+
+@@ -716,7 +716,7 @@ struct ssh_list *ssh_list_new(void)
+
+ void ssh_list_free(struct ssh_list *list)
+ {
+- struct ssh_iterator *ptr, *next;
++ struct ssh_iterator *ptr = NULL, *next = NULL;
+ if (!list)
+ return;
+ ptr = list->root;
+@@ -737,7 +737,7 @@ struct ssh_iterator *ssh_list_get_iterator(const struct ssh_list *list)
+
+ struct ssh_iterator *ssh_list_find(const struct ssh_list *list, void *value)
+ {
+- struct ssh_iterator *it;
++ struct ssh_iterator *it = NULL;
+
+ for (it = ssh_list_get_iterator(list); it != NULL ; it = it->next)
+ if (it->data == value)
+@@ -826,7 +826,7 @@ int ssh_list_prepend(struct ssh_list *list, const void *data)
+
+ void ssh_list_remove(struct ssh_list *list, struct ssh_iterator *iterator)
+ {
+- struct ssh_iterator *ptr, *prev;
++ struct ssh_iterator *ptr = NULL, *prev = NULL;
+
+ if (list == NULL) {
+ return;
+@@ -967,7 +967,7 @@ char *ssh_dirname (const char *path)
+ char *ssh_basename (const char *path)
+ {
+ char *new = NULL;
+- const char *s;
++ const char *s = NULL;
+ size_t len;
+
+ if (path == NULL || *path == '\0') {
+@@ -1105,8 +1105,8 @@ int ssh_mkdirs(const char *pathname, mode_t mode)
+ */
+ char *ssh_path_expand_tilde(const char *d)
+ {
+- char *h = NULL, *r;
+- const char *p;
++ char *h = NULL, *r = NULL;
++ const char *p = NULL;
+ size_t ld;
+ size_t lh = 0;
+
+@@ -1121,7 +1121,7 @@ char *ssh_path_expand_tilde(const char *d)
+ #ifdef _WIN32
+ return strdup(d);
+ #else
+- struct passwd *pw;
++ struct passwd *pw = NULL;
+ size_t s = p - d;
+ char u[128];
+
+@@ -1182,7 +1182,7 @@ char *ssh_path_expand_escape(ssh_session session, const char *s)
+ char *buf = NULL;
+ char *r = NULL;
+ char *x = NULL;
+- const char *p;
++ const char *p = NULL;
+ size_t i, l;
+
+ r = ssh_path_expand_tilde(s);
+@@ -1335,8 +1335,8 @@ char *ssh_path_expand_escape(ssh_session session, const char *s)
+ */
+ int ssh_analyze_banner(ssh_session session, int server)
+ {
+- const char *banner;
+- const char *openssh;
++ const char *banner = NULL;
++ const char *openssh = NULL;
+
+ if (server) {
+ banner = session->clientbanner;
+diff --git a/src/options.c b/src/options.c
+index 38511455..b641b34f 100644
+--- a/src/options.c
++++ b/src/options.c
+@@ -67,7 +67,7 @@
+ */
+ int ssh_options_copy(ssh_session src, ssh_session *dest)
+ {
+- ssh_session new;
++ ssh_session new = NULL;
+ struct ssh_iterator *it = NULL;
+ struct ssh_list *list = NULL;
+ char *id = NULL;
+@@ -499,8 +499,8 @@ int ssh_options_set_algo(ssh_session session,
+ int ssh_options_set(ssh_session session, enum ssh_options_e type,
+ const void *value)
+ {
+- const char *v;
+- char *p, *q;
++ const char *v = NULL;
++ char *p = NULL, *q = NULL;
+ long int i;
+ unsigned int u;
+ int rc;
+@@ -1170,7 +1170,7 @@ int ssh_options_get_port(ssh_session session, unsigned int* port_target) {
+ */
+ int ssh_options_get(ssh_session session, enum ssh_options_e type, char** value)
+ {
+- char* src = NULL;
++ char *src = NULL;
+
+ if (session == NULL) {
+ return SSH_ERROR;
+@@ -1192,7 +1192,7 @@ int ssh_options_get(ssh_session session, enum ssh_options_e type, char** value)
+ break;
+ }
+ case SSH_OPTIONS_IDENTITY: {
+- struct ssh_iterator *it;
++ struct ssh_iterator *it = NULL;
+ it = ssh_list_get_iterator(session->opts.identity);
+ if (it == NULL) {
+ it = ssh_list_get_iterator(session->opts.identity_non_exp);
+@@ -1445,7 +1445,7 @@ int ssh_options_getopt(ssh_session session, int *argcptr, char **argv)
+ */
+ int ssh_options_parse_config(ssh_session session, const char *filename)
+ {
+- char *expanded_filename;
++ char *expanded_filename = NULL;
+ int r;
+
+ if (session == NULL) {
+@@ -1491,7 +1491,7 @@ out:
+
+ int ssh_options_apply(ssh_session session)
+ {
+- char *tmp;
++ char *tmp = NULL;
+ int rc;
+
+ if (session->opts.sshdir == NULL) {
+@@ -2204,7 +2204,7 @@ static char *ssh_bind_options_expand_escape(ssh_bind sshbind, const char *s)
+ char *buf = NULL;
+ char *r = NULL;
+ char *x = NULL;
+- const char *p;
++ const char *p = NULL;
+ size_t i, l;
+
+ r = ssh_path_expand_tilde(s);
+@@ -2310,7 +2310,7 @@ static char *ssh_bind_options_expand_escape(ssh_bind sshbind, const char *s)
+ int ssh_bind_options_parse_config(ssh_bind sshbind, const char *filename)
+ {
+ int rc = 0;
+- char *expanded_filename;
++ char *expanded_filename = NULL;
+
+ if (sshbind == NULL) {
+ return -1;
+diff --git a/src/packet.c b/src/packet.c
+index ea73f9ad..4b4d0dc3 100644
+--- a/src/packet.c
++++ b/src/packet.c
+@@ -1430,8 +1430,8 @@ error:
+ static void ssh_packet_socket_controlflow_callback(int code, void *userdata)
+ {
+ ssh_session session = userdata;
+- struct ssh_iterator *it;
+- ssh_channel channel;
++ struct ssh_iterator *it = NULL;
++ ssh_channel channel = NULL;
+
+ if (code == SSH_SOCKET_FLOW_WRITEWONTBLOCK) {
+ SSH_LOG(SSH_LOG_TRACE, "sending channel_write_wontblock callback");
+@@ -1894,7 +1894,7 @@ int ssh_packet_send(ssh_session session)
+
+ /* We finished the key exchange so we can try to send our queue now */
+ if (rc == SSH_OK && type == SSH2_MSG_NEWKEYS) {
+- struct ssh_iterator *it;
++ struct ssh_iterator *it = NULL;
+
+ if (session->flags & SSH_SESSION_FLAG_KEX_STRICT) {
+ /* reset packet sequence number when running in strict kex mode */
+diff --git a/src/packet_crypt.c b/src/packet_crypt.c
+index fe3f489e..96e9586c 100644
+--- a/src/packet_crypt.c
++++ b/src/packet_crypt.c
+@@ -262,7 +262,7 @@ int ssh_packet_hmac_verify(ssh_session session,
+ {
+ struct ssh_crypto_struct *crypto = NULL;
+ unsigned char hmacbuf[DIGEST_MAX_LEN] = {0};
+- HMACCTX ctx;
++ HMACCTX ctx = NULL;
+ size_t hmaclen = DIGEST_MAX_LEN;
+ uint32_t seq;
+ int cmp;
+diff --git a/src/pki.c b/src/pki.c
+index a7c84c5e..cf4176fb 100644
+--- a/src/pki.c
++++ b/src/pki.c
+@@ -369,7 +369,7 @@ enum ssh_digest_e ssh_key_hash_from_name(const char *name)
+ */
+ int ssh_key_algorithm_allowed(ssh_session session, const char *type)
+ {
+- const char *allowed_list;
++ const char *allowed_list = NULL;
+
+ if (session->client) {
+ allowed_list = session->opts.pubkey_accepted_types;
+@@ -729,7 +729,7 @@ int ssh_key_cmp(const ssh_key k1,
+
+ ssh_signature ssh_signature_new(void)
+ {
+- struct ssh_signature_struct *sig;
++ struct ssh_signature_struct *sig = NULL;
+
+ sig = malloc(sizeof(struct ssh_signature_struct));
+ if (sig == NULL) {
+@@ -821,7 +821,7 @@ int ssh_pki_import_privkey_base64(const char *b64_key,
+ void *auth_data,
+ ssh_key *pkey)
+ {
+- ssh_key key;
++ ssh_key key = NULL;
+ char *openssh_header = NULL;
+
+ if (b64_key == NULL || pkey == NULL) {
+@@ -944,8 +944,8 @@ int ssh_pki_import_privkey_file(const char *filename,
+ void *auth_data,
+ ssh_key *pkey) {
+ struct stat sb;
+- char *key_buf;
+- FILE *file;
++ char *key_buf = NULL;
++ FILE *file = NULL;
+ off_t size;
+ int rc;
+ char err_msg[SSH_ERRNO_MSG_MAX] = {0};
+@@ -1046,7 +1046,7 @@ int ssh_pki_export_privkey_file(const ssh_key privkey,
+ void *auth_data,
+ const char *filename)
+ {
+- ssh_string blob;
++ ssh_string blob = NULL;
+ FILE *fp;
+ int rc;
+
+@@ -1093,8 +1093,8 @@ int ssh_pki_export_privkey_file(const ssh_key privkey,
+ /* temporary function to migrate seamlessly to ssh_key */
+ ssh_public_key ssh_pki_convert_key_to_publickey(const ssh_key key)
+ {
+- ssh_public_key pub;
+- ssh_key tmp;
++ ssh_public_key pub = NULL;
++ ssh_key tmp = NULL;
+
+ if (key == NULL) {
+ return NULL;
+@@ -1131,7 +1131,7 @@ ssh_public_key ssh_pki_convert_key_to_publickey(const ssh_key key)
+
+ ssh_private_key ssh_pki_convert_key_to_privatekey(const ssh_key key)
+ {
+- ssh_private_key privkey;
++ ssh_private_key privkey = NULL;
+
+ privkey = calloc(1, sizeof(struct ssh_private_key_struct));
+ if (privkey == NULL) {
+@@ -1521,9 +1521,9 @@ static int pki_import_cert_buffer(ssh_buffer buffer,
+ enum ssh_keytypes_e type,
+ ssh_key *pkey)
+ {
+- ssh_buffer cert;
+- ssh_string tmp_s;
+- const char *type_c;
++ ssh_buffer cert = NULL;
++ ssh_string tmp_s = NULL;
++ const char *type_c = NULL;
+ ssh_key key = NULL;
+ int rc;
+
+@@ -2067,7 +2067,7 @@ error:
+ int ssh_pki_export_privkey_to_pubkey(const ssh_key privkey,
+ ssh_key *pkey)
+ {
+- ssh_key pubkey;
++ ssh_key pubkey = NULL;
+
+ if (privkey == NULL || !ssh_key_is_private(privkey)) {
+ return SSH_ERROR;
+@@ -2105,7 +2105,7 @@ int ssh_pki_export_privkey_to_pubkey(const ssh_key privkey,
+ int ssh_pki_export_pubkey_blob(const ssh_key key,
+ ssh_string *pblob)
+ {
+- ssh_string blob;
++ ssh_string blob = NULL;
+
+ if (key == NULL) {
+ return SSH_OK;
+@@ -2135,8 +2135,8 @@ int ssh_pki_export_pubkey_blob(const ssh_key key,
+ int ssh_pki_export_pubkey_base64(const ssh_key key,
+ char **b64_key)
+ {
+- ssh_string key_blob;
+- unsigned char *b64;
++ ssh_string key_blob = NULL;
++ unsigned char *b64 = NULL;
+
+ if (key == NULL || b64_key == NULL) {
+ return SSH_ERROR;
+@@ -2175,9 +2175,9 @@ int ssh_pki_export_pubkey_file(const ssh_key key,
+ {
+ char key_buf[MAX_LINE_SIZE];
+ char host[256];
+- char *b64_key;
+- char *user;
+- FILE *fp;
++ char *b64_key = NULL;
++ char *user = NULL;
++ FILE *fp = NULL;
+ int rc;
+
+ if (key == NULL || filename == NULL || *filename == '\0') {
+@@ -2238,7 +2238,7 @@ int ssh_pki_export_pubkey_file(const ssh_key key,
+ * @returns SSH_OK on success, SSH_ERROR otherwise.
+ **/
+ int ssh_pki_copy_cert_to_privkey(const ssh_key certkey, ssh_key privkey) {
+- ssh_buffer cert_buffer;
++ ssh_buffer cert_buffer = NULL;
+ int rc;
+
+ if (certkey == NULL || privkey == NULL) {
+@@ -2273,7 +2273,7 @@ int ssh_pki_export_signature_blob(const ssh_signature sig,
+ ssh_string *sig_blob)
+ {
+ ssh_buffer buf = NULL;
+- ssh_string str;
++ ssh_string str = NULL;
+ int rc;
+
+ if (sig == NULL || sig_blob == NULL) {
+@@ -2337,7 +2337,7 @@ int ssh_pki_import_signature_blob(const ssh_string sig_blob,
+ enum ssh_keytypes_e type;
+ enum ssh_digest_e hash_type;
+ ssh_string algorithm = NULL, blob = NULL;
+- ssh_buffer buf;
++ ssh_buffer buf = NULL;
+ const char *alg = NULL;
+ uint8_t flags = 0;
+ uint32_t counter = 0;
+@@ -2697,9 +2697,9 @@ ssh_string ssh_pki_do_sign_agent(ssh_session session,
+ const ssh_key pubkey)
+ {
+ struct ssh_crypto_struct *crypto = NULL;
+- ssh_string session_id;
+- ssh_string sig_blob;
+- ssh_buffer sig_buf;
++ ssh_string session_id = NULL;
++ ssh_string sig_blob = NULL;
++ ssh_buffer sig_buf = NULL;
+ int rc;
+
+ crypto = ssh_packet_get_current_crypto(session, SSH_DIRECTION_BOTH);
+diff --git a/src/pki_container_openssh.c b/src/pki_container_openssh.c
+index 4314c5b7..f2776c2c 100644
+--- a/src/pki_container_openssh.c
++++ b/src/pki_container_openssh.c
+@@ -234,12 +234,12 @@ ssh_pki_openssh_import(const char *text_key,
+ bool private)
+ {
+ const char *ptr = text_key;
+- const char *end;
+- char *base64;
++ const char *end = NULL;
++ char *base64 = NULL;
+ int cmp;
+ int rc;
+ int i;
+- ssh_buffer buffer = NULL, privkey_buffer=NULL;
++ ssh_buffer buffer = NULL, privkey_buffer = NULL;
+ char *magic = NULL, *ciphername = NULL, *kdfname = NULL;
+ uint32_t nkeys = 0, checkint1 = 0, checkint2 = 0xFFFF;
+ ssh_string kdfoptions = NULL;
+@@ -538,14 +538,14 @@ ssh_string ssh_pki_openssh_privkey_export(const ssh_key privkey,
+ {
+ ssh_buffer buffer;
+ ssh_string str = NULL;
+- ssh_string pubkey_s=NULL;
++ ssh_string pubkey_s = NULL;
+ ssh_buffer privkey_buffer = NULL;
+ uint32_t rnd;
+ uint32_t rounds = 16;
+- ssh_string salt=NULL;
+- ssh_string kdf_options=NULL;
++ ssh_string salt = NULL;
++ ssh_string kdf_options = NULL;
+ int to_encrypt=0;
+- unsigned char *b64;
++ unsigned char *b64 = NULL;
+ uint32_t str_len, len;
+ uint8_t padding = 1;
+ int ok;
+diff --git a/src/pki_crypto.c b/src/pki_crypto.c
+index aec49544..0fc69121 100644
+--- a/src/pki_crypto.c
++++ b/src/pki_crypto.c
+@@ -382,7 +382,7 @@ int pki_pubkey_build_ecdsa(ssh_key key, int nid, ssh_string e)
+ #else
+ int rc;
+ const char *group_name = OSSL_EC_curve_nid2name(nid);
+- OSSL_PARAM_BLD *param_bld;
++ OSSL_PARAM_BLD *param_bld = NULL;
+ #endif /* OPENSSL_VERSION_NUMBER */
+
+ key->ecdsa_nid = nid;
+@@ -2299,7 +2299,7 @@ static ssh_string pki_ecdsa_signature_to_blob(const ssh_signature sig)
+ const unsigned char *raw_sig_data = NULL;
+ size_t raw_sig_len;
+
+- ECDSA_SIG *ecdsa_sig;
++ ECDSA_SIG *ecdsa_sig = NULL;
+
+ int rc;
+
+@@ -2616,8 +2616,8 @@ static int pki_signature_from_ecdsa_blob(UNUSED_PARAM(const ssh_key pubkey),
+ ECDSA_SIG *ecdsa_sig = NULL;
+ BIGNUM *pr = NULL, *ps = NULL;
+
+- ssh_string r;
+- ssh_string s;
++ ssh_string r = NULL;
++ ssh_string s = NULL;
+
+ ssh_buffer buf = NULL;
+ uint32_t rlen;
+diff --git a/src/pki_ed25519.c b/src/pki_ed25519.c
+index 6a5a4a8a..0674fb63 100644
+--- a/src/pki_ed25519.c
++++ b/src/pki_ed25519.c
+@@ -62,7 +62,7 @@ int pki_ed25519_sign(const ssh_key privkey,
+ size_t hlen)
+ {
+ int rc;
+- uint8_t *buffer;
++ uint8_t *buffer = NULL;
+ uint64_t dlen = 0;
+
+ buffer = malloc(hlen + ED25519_SIG_LEN);
+@@ -104,8 +104,8 @@ int pki_ed25519_verify(const ssh_key pubkey,
+ size_t hlen)
+ {
+ uint64_t mlen = 0;
+- uint8_t *buffer;
+- uint8_t *buffer2;
++ uint8_t *buffer = NULL;
++ uint8_t *buffer2 = NULL;
+ int rc;
+
+ if (pubkey == NULL || sig == NULL ||
+diff --git a/src/pki_ed25519_common.c b/src/pki_ed25519_common.c
+index bdc6f6bb..59a3b03c 100644
+--- a/src/pki_ed25519_common.c
++++ b/src/pki_ed25519_common.c
+@@ -213,7 +213,7 @@ int pki_ed25519_public_key_to_blob(ssh_buffer buffer, ssh_key key)
+ */
+ ssh_string pki_ed25519_signature_to_blob(ssh_signature sig)
+ {
+- ssh_string sig_blob;
++ ssh_string sig_blob = NULL;
+ int rc;
+
+ #ifdef HAVE_OPENSSL_ED25519
+diff --git a/src/pki_gcrypt.c b/src/pki_gcrypt.c
+index 418a46b3..cb4de325 100644
+--- a/src/pki_gcrypt.c
++++ b/src/pki_gcrypt.c
+@@ -152,7 +152,7 @@ static ssh_string asn1_get_int(ssh_buffer buffer) {
+
+ static ssh_string asn1_get_bit_string(ssh_buffer buffer)
+ {
+- ssh_string str;
++ ssh_string str = NULL;
+ unsigned char type;
+ uint32_t size;
+ unsigned char unused, last, *p;
+@@ -1882,9 +1882,9 @@ ssh_string pki_signature_to_blob(const ssh_signature sig)
+ case SSH_KEYTYPE_ECDSA_P521:
+ #ifdef HAVE_GCRYPT_ECC
+ {
+- ssh_string R;
+- ssh_string S;
+- ssh_buffer b;
++ ssh_string R = NULL;
++ ssh_string S = NULL;
++ ssh_buffer b = NULL;
+
+ b = ssh_buffer_new();
+ if (b == NULL) {
+@@ -2054,8 +2054,8 @@ ssh_signature pki_signature_from_blob(const ssh_key pubkey,
+ case SSH_KEYTYPE_SK_ECDSA:
+ #ifdef HAVE_GCRYPT_ECC
+ { /* build ecdsa siganature */
+- ssh_buffer b;
+- ssh_string r, s;
++ ssh_buffer b = NULL;
++ ssh_string r = NULL, s = NULL;
+ uint32_t rlen;
+
+ b = ssh_buffer_new();
+diff --git a/src/pki_mbedcrypto.c b/src/pki_mbedcrypto.c
+index cb9d3228..01813702 100644
+--- a/src/pki_mbedcrypto.c
++++ b/src/pki_mbedcrypto.c
+@@ -1078,9 +1078,9 @@ ssh_string pki_signature_to_blob(const ssh_signature sig)
+ case SSH_KEYTYPE_ECDSA_P256:
+ case SSH_KEYTYPE_ECDSA_P384:
+ case SSH_KEYTYPE_ECDSA_P521: {
+- ssh_string r;
+- ssh_string s;
+- ssh_buffer b;
++ ssh_string r = NULL;
++ ssh_string s = NULL;
++ ssh_buffer b = NULL;
+ int rc;
+
+ b = ssh_buffer_new();
+@@ -1234,9 +1234,9 @@ ssh_signature pki_signature_from_blob(const ssh_key pubkey,
+ case SSH_KEYTYPE_ECDSA_P384:
+ case SSH_KEYTYPE_ECDSA_P521:
+ case SSH_KEYTYPE_SK_ECDSA: {
+- ssh_buffer b;
+- ssh_string r;
+- ssh_string s;
++ ssh_buffer b = NULL;
++ ssh_string r = NULL;
++ ssh_string s = NULL;
+ size_t rlen;
+
+ b = ssh_buffer_new();
+diff --git a/src/poll.c b/src/poll.c
+index 8f81c11c..d0f9726d 100644
+--- a/src/poll.c
++++ b/src/poll.c
+@@ -560,8 +560,8 @@ void ssh_poll_ctx_free(ssh_poll_ctx ctx)
+
+ static int ssh_poll_ctx_resize(ssh_poll_ctx ctx, size_t new_size)
+ {
+- ssh_poll_handle *pollptrs;
+- ssh_pollfd_t *pollfds;
++ ssh_poll_handle *pollptrs = NULL;
++ ssh_pollfd_t *pollfds = NULL;
+
+ pollptrs = realloc(ctx->pollptrs, sizeof(ssh_poll_handle) * new_size);
+ if (pollptrs == NULL) {
+@@ -862,7 +862,7 @@ ssh_event_add_fd(ssh_event event, socket_t fd, short events,
+ ssh_event_callback cb, void *userdata)
+ {
+ ssh_poll_handle p;
+- struct ssh_event_fd_wrapper *pw;
++ struct ssh_event_fd_wrapper *pw = NULL;
+
+ if(event == NULL || event->ctx == NULL || cb == NULL
+ || fd == SSH_INVALID_SOCKET) {
+@@ -932,7 +932,7 @@ int ssh_event_add_session(ssh_event event, ssh_session session)
+ {
+ ssh_poll_handle p;
+ #ifdef WITH_SERVER
+- struct ssh_iterator *iterator;
++ struct ssh_iterator *iterator = NULL;
+ #endif
+
+ if(event == NULL || event->ctx == NULL || session == NULL) {
+@@ -1079,7 +1079,7 @@ int ssh_event_remove_session(ssh_event event, ssh_session session)
+ register size_t i, used;
+ int rc = SSH_ERROR;
+ #ifdef WITH_SERVER
+- struct ssh_iterator *iterator;
++ struct ssh_iterator *iterator = NULL;
+ #endif
+
+ if (event == NULL || event->ctx == NULL || session == NULL) {
+diff --git a/src/server.c b/src/server.c
+index 70b90899..89f8d8b0 100644
+--- a/src/server.c
++++ b/src/server.c
+@@ -85,8 +85,8 @@ int server_set_kex(ssh_session session)
+ {
+ struct ssh_kex_struct *server = &session->next_crypto->server_kex;
+ int i, j, rc;
+- const char *wanted, *allowed;
+- char *kept;
++ const char *wanted = NULL, *allowed = NULL;
++ char *kept = NULL;
+ char hostkeys[128] = {0};
+ enum ssh_keytypes_e keytype;
+ size_t len;
+@@ -219,9 +219,10 @@ int ssh_server_init_kex(ssh_session session) {
+ return server_set_kex(session);
+ }
+
+-static int ssh_server_send_extensions(ssh_session session) {
++static int ssh_server_send_extensions(ssh_session session)
++{
+ int rc;
+- const char *hostkey_algorithms;
++ const char *hostkey_algorithms = NULL;
+
+ SSH_LOG(SSH_LOG_PACKET, "Sending SSH_MSG_EXT_INFO");
+
+@@ -286,8 +287,8 @@ ssh_get_key_params(ssh_session session,
+ ssh_key *privkey,
+ enum ssh_digest_e *digest)
+ {
+- ssh_key pubkey;
+- ssh_string pubkey_blob;
++ ssh_key pubkey = NULL;
++ ssh_string pubkey_blob = NULL;
+ int rc;
+
+ switch(session->srv.hostkey) {
+@@ -723,8 +724,9 @@ static int ssh_message_service_request_reply_default(ssh_message msg) {
+ *
+ * @returns SSH_OK when success otherwise SSH_ERROR
+ */
+-int ssh_message_service_reply_success(ssh_message msg) {
+- ssh_session session;
++int ssh_message_service_reply_success(ssh_message msg)
++{
++ ssh_session session = NULL;
+ int rc;
+
+ if (msg == NULL) {
+@@ -1132,8 +1134,9 @@ int ssh_message_auth_reply_pk_ok(ssh_message msg, ssh_string algo, ssh_string pu
+ *
+ * @returns SSH_OK on success, otherwise SSH_ERROR
+ */
+-int ssh_message_auth_reply_pk_ok_simple(ssh_message msg) {
+- ssh_string algo;
++int ssh_message_auth_reply_pk_ok_simple(ssh_message msg)
++{
++ ssh_string algo = NULL;
+ ssh_string pubkey_blob = NULL;
+ int ret;
+
+diff --git a/src/session.c b/src/session.c
+index 8c509699..0e0f622b 100644
+--- a/src/session.c
++++ b/src/session.c
+@@ -58,7 +58,7 @@
+ */
+ ssh_session ssh_new(void)
+ {
+- ssh_session session;
++ ssh_session session = NULL;
+ char *id = NULL;
+ int rc;
+
+@@ -280,7 +280,7 @@ void ssh_free(ssh_session session)
+
+ /* options */
+ if (session->opts.identity) {
+- char *id;
++ char *id = NULL;
+
+ for (id = ssh_list_pop_head(char *, session->opts.identity);
+ id != NULL;
+@@ -291,7 +291,7 @@ void ssh_free(ssh_session session)
+ }
+
+ if (session->opts.identity_non_exp) {
+- char *id;
++ char *id = NULL;
+
+ for (id = ssh_list_pop_head(char *, session->opts.identity_non_exp);
+ id != NULL;
+@@ -1157,7 +1157,7 @@ int ssh_get_publickey_hash(const ssh_key key,
+ unsigned char **hash,
+ size_t *hlen)
+ {
+- ssh_string blob;
++ ssh_string blob = NULL;
+ unsigned char *h = NULL;
+ int rc;
+
+@@ -1169,7 +1169,7 @@ int ssh_get_publickey_hash(const ssh_key key,
+ switch (type) {
+ case SSH_PUBLICKEY_HASH_SHA1:
+ {
+- SHACTX ctx;
++ SHACTX ctx = NULL;
+
+ h = calloc(1, SHA_DIGEST_LEN);
+ if (h == NULL) {
+@@ -1201,7 +1201,7 @@ int ssh_get_publickey_hash(const ssh_key key,
+ break;
+ case SSH_PUBLICKEY_HASH_SHA256:
+ {
+- SHA256CTX ctx;
++ SHA256CTX ctx = NULL;
+
+ h = calloc(1, SHA256_DIGEST_LEN);
+ if (h == NULL) {
+@@ -1233,7 +1233,7 @@ int ssh_get_publickey_hash(const ssh_key key,
+ break;
+ case SSH_PUBLICKEY_HASH_MD5:
+ {
+- MD5CTX ctx;
++ MD5CTX ctx = NULL;
+
+ /* In FIPS mode, we cannot use MD5 */
+ if (ssh_fips_mode()) {
+diff --git a/src/sftpserver.c b/src/sftpserver.c
+index b3349e16..528ef6f9 100644
+--- a/src/sftpserver.c
++++ b/src/sftpserver.c
+@@ -299,8 +299,8 @@ void sftp_client_message_free(sftp_client_message msg) {
+
+ int sftp_reply_name(sftp_client_message msg, const char *name,
+ sftp_attributes attr) {
+- ssh_buffer out;
+- ssh_string file;
++ ssh_buffer out = NULL;
++ ssh_string file = NULL;
+
+ out = ssh_buffer_new();
+ if (out == NULL) {
+@@ -369,7 +369,7 @@ int sftp_reply_attr(sftp_client_message msg, sftp_attributes attr) {
+
+ int sftp_reply_names_add(sftp_client_message msg, const char *file,
+ const char *longname, sftp_attributes attr) {
+- ssh_string name;
++ ssh_string name = NULL;
+
+ name = ssh_string_from_char(file);
+ if (name == NULL) {
+@@ -435,8 +435,8 @@ int sftp_reply_names(sftp_client_message msg) {
+
+ int sftp_reply_status(sftp_client_message msg, uint32_t status,
+ const char *message) {
+- ssh_buffer out;
+- ssh_string s;
++ ssh_buffer out = NULL;
++ ssh_string s = NULL;
+
+ out = ssh_buffer_new();
+ if (out == NULL) {
+@@ -492,7 +492,7 @@ int sftp_reply_data(sftp_client_message msg, const void *data, int len) {
+ * valid info (or worse).
+ */
+ ssh_string sftp_handle_alloc(sftp_session sftp, void *info) {
+- ssh_string ret;
++ ssh_string ret = NULL;
+ uint32_t val;
+ uint32_t i;
+
+diff --git a/src/string.c b/src/string.c
+index 44403487..0ab9310c 100644
+--- a/src/string.c
++++ b/src/string.c
+@@ -106,7 +106,7 @@ int ssh_string_fill(struct ssh_string_struct *s, const void *data, size_t len) {
+ * @note The null byte is not copied nor counted in the output string.
+ */
+ struct ssh_string_struct *ssh_string_from_char(const char *what) {
+- struct ssh_string_struct *ptr;
++ struct ssh_string_struct *ptr = NULL;
+ size_t len;
+
+ if(what == NULL) {
+@@ -180,7 +180,7 @@ const char *ssh_string_get_char(struct ssh_string_struct *s)
+ */
+ char *ssh_string_to_char(struct ssh_string_struct *s) {
+ size_t len;
+- char *new;
++ char *new = NULL;
+
+ if (s == NULL) {
+ return NULL;
+@@ -219,7 +219,7 @@ void ssh_string_free_char(char *s) {
+ * @return Newly allocated copy of the string, NULL on error.
+ */
+ struct ssh_string_struct *ssh_string_copy(struct ssh_string_struct *s) {
+- struct ssh_string_struct *new;
++ struct ssh_string_struct *new = NULL;
+ size_t len;
+
+ if (s == NULL) {
+diff --git a/src/threads/winlocks.c b/src/threads/winlocks.c
+index da600418..e63635e7 100644
+--- a/src/threads/winlocks.c
++++ b/src/threads/winlocks.c
+@@ -82,7 +82,7 @@ static struct ssh_threads_callbacks_struct ssh_threads_winlock =
+
+ void ssh_mutex_lock(SSH_MUTEX *mutex)
+ {
+- void *rc;
++ void *rc = NULL;
+
+ CRITICAL_SECTION *mutex_tmp = NULL;
+
+diff --git a/src/wrapper.c b/src/wrapper.c
+index d317dc4c..43bf2137 100644
+--- a/src/wrapper.c
++++ b/src/wrapper.c
+@@ -152,7 +152,7 @@ static void cipher_free(struct ssh_cipher_struct *cipher) {
+
+ struct ssh_crypto_struct *crypto_new(void)
+ {
+- struct ssh_crypto_struct *crypto;
++ struct ssh_crypto_struct *crypto = NULL;
+
+ crypto = malloc(sizeof(struct ssh_crypto_struct));
+ if (crypto == NULL) {
+--
+2.40.0
+
diff --git a/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-4878-0002.patch b/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-4878-0002.patch
new file mode 100644
index 0000000000..2c280d258d
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-4878-0002.patch
@@ -0,0 +1,34 @@
+From b35ee876adc92a208d47194772e99f9c71e0bedb Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Mon, 28 Apr 2025 11:04:55 +0200
+Subject: [PATCH] CVE-2025-4878 legacy: Properly check return value to avoid
+ NULL pointer dereference
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+Reviewed-by: Andreas Schneider <asn@cryptomilk.org>
+
+CVE: CVE-2025-4878
+
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=b35ee876adc92a208d47194772e99f9c71e0bedb]
+
+Signed-off-by: Divya Chellam <divya.chellam@windriver.com>
+---
+ src/legacy.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/legacy.c b/src/legacy.c
+index 7359040c..f73ef6cc 100644
+--- a/src/legacy.c
++++ b/src/legacy.c
+@@ -452,7 +452,7 @@ ssh_private_key privatekey_from_file(ssh_session session,
+ auth_fn,
+ auth_data,
+ &key);
+- if (rc == SSH_ERROR) {
++ if (rc != SSH_OK) {
+ return NULL;
+ }
+
+--
+2.40.0
+
diff --git a/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-5318.patch b/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-5318.patch
new file mode 100644
index 0000000000..02efc7a8f3
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-5318.patch
@@ -0,0 +1,31 @@
+From 5f4ffda88770f95482fd0e66aa44106614dbf466 Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Tue, 22 Apr 2025 21:18:44 +0200
+Subject: CVE-2025-5318: sftpserver: Fix possible buffer overrun
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+Reviewed-by: Andreas Schneider <asn@cryptomilk.org>
+
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=5f4ffda88770f95482fd0e66aa44106614dbf466]
+CVE: CVE-2025-5318
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ src/sftpserver.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/sftpserver.c b/src/sftpserver.c
+index 9117f155..b3349e16 100644
+--- a/src/sftpserver.c
++++ b/src/sftpserver.c
+@@ -538,7 +538,7 @@ void *sftp_handle(sftp_session sftp, ssh_string handle){
+
+ memcpy(&val, ssh_string_data(handle), sizeof(uint32_t));
+
+- if (val > SFTP_HANDLES) {
++ if (val >= SFTP_HANDLES) {
+ return NULL;
+ }
+
+--
+2.49.0
+
diff --git a/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-5351.patch b/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-5351.patch
new file mode 100644
index 0000000000..09bf3d8bd5
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-5351.patch
@@ -0,0 +1,38 @@
+From 6ddb730a27338983851248af59b128b995aad256 Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Tue, 6 May 2025 22:43:31 +0200
+Subject: CVE-2025-5351 pki_crypto: Avoid double-free on low-memory conditions
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+Reviewed-by: Andreas Schneider <asn@cryptomilk.org>
+
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=6ddb730a27338983851248af59b128b995aad256]
+CVE: CVE-2025-5351
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ src/pki_crypto.c | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/src/pki_crypto.c b/src/pki_crypto.c
+index 5b0d7ded..aec49544 100644
+--- a/src/pki_crypto.c
++++ b/src/pki_crypto.c
+@@ -2023,6 +2023,7 @@ ssh_string pki_publickey_to_blob(const ssh_key key)
+ bignum_safe_free(bn);
+ bignum_safe_free(be);
+ OSSL_PARAM_free(params);
++ params = NULL;
+ #endif /* OPENSSL_VERSION_NUMBER */
+ break;
+ }
+@@ -2143,6 +2144,7 @@ ssh_string pki_publickey_to_blob(const ssh_key key)
+ */
+ #if 0
+ OSSL_PARAM_free(params);
++ params = NULL;
+ #endif /* OPENSSL_VERSION_NUMBER */
+
+ if (key->type == SSH_KEYTYPE_SK_ECDSA &&
+--
+2.49.0
+
diff --git a/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-5372.patch b/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-5372.patch
new file mode 100644
index 0000000000..c9c0cfe156
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-5372.patch
@@ -0,0 +1,150 @@
+From a9d8a3d44829cf9182b252bc951f35fb0d573972 Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Wed, 14 May 2025 14:07:58 +0200
+Subject: CVE-2025-5372 libgcrypto: Simplify error checking and handling of
+ return codes in ssh_kdf()
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+Reviewed-by: Andreas Schneider <asn@cryptomilk.org>
+
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=a9d8a3d44829cf9182b252bc951f35fb0d573972]
+CVE: CVE-2025-5372
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ src/libcrypto.c | 62 ++++++++++++++++++++++---------------------------
+ 1 file changed, 28 insertions(+), 34 deletions(-)
+
+diff --git a/src/libcrypto.c b/src/libcrypto.c
+index 4f945d90..76e067d3 100644
+--- a/src/libcrypto.c
++++ b/src/libcrypto.c
+@@ -163,7 +163,7 @@ int ssh_kdf(struct ssh_crypto_struct *crypto,
+ uint8_t key_type, unsigned char *output,
+ size_t requested_len)
+ {
+- int rc = -1;
++ int ret = SSH_ERROR, rv;
+ #if OPENSSL_VERSION_NUMBER < 0x30000000L
+ EVP_KDF_CTX *ctx = EVP_KDF_CTX_new_id(EVP_KDF_SSHKDF);
+ #else
+@@ -185,81 +185,75 @@ int ssh_kdf(struct ssh_crypto_struct *crypto,
+ }
+
+ #if OPENSSL_VERSION_NUMBER < 0x30000000L
+- rc = EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_MD,
++ rv = EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_MD,
+ sshkdf_digest_to_md(crypto->digest_type));
+- if (rc != 1) {
++ if (rv != 1) {
+ goto out;
+ }
+- rc = EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KEY, key, key_len);
+- if (rc != 1) {
++ rv = EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KEY, key, key_len);
++ if (rv != 1) {
+ goto out;
+ }
+- rc = EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_SSHKDF_XCGHASH,
++ rv = EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_SSHKDF_XCGHASH,
+ crypto->secret_hash, crypto->digest_len);
+- if (rc != 1) {
++ if (rv != 1) {
+ goto out;
+ }
+- rc = EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_SSHKDF_TYPE, key_type);
+- if (rc != 1) {
++ rv = EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_SSHKDF_TYPE, key_type);
++ if (rv != 1) {
+ goto out;
+ }
+- rc = EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_SSHKDF_SESSION_ID,
++ rv = EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_SSHKDF_SESSION_ID,
+ crypto->session_id, crypto->session_id_len);
+- if (rc != 1) {
++ if (rv != 1) {
+ goto out;
+ }
+- rc = EVP_KDF_derive(ctx, output, requested_len);
+- if (rc != 1) {
++ rv = EVP_KDF_derive(ctx, output, requested_len);
++ if (rv != 1) {
+ goto out;
+ }
+ #else
+- rc = OSSL_PARAM_BLD_push_utf8_string(param_bld, OSSL_KDF_PARAM_DIGEST,
++ rv = OSSL_PARAM_BLD_push_utf8_string(param_bld, OSSL_KDF_PARAM_DIGEST,
+ md, strlen(md));
+- if (rc != 1) {
+- rc = -1;
++ if (rv != 1) {
+ goto out;
+ }
+- rc = OSSL_PARAM_BLD_push_octet_string(param_bld, OSSL_KDF_PARAM_KEY,
++ rv = OSSL_PARAM_BLD_push_octet_string(param_bld, OSSL_KDF_PARAM_KEY,
+ key, key_len);
+- if (rc != 1) {
+- rc = -1;
++ if (rv != 1) {
+ goto out;
+ }
+- rc = OSSL_PARAM_BLD_push_octet_string(param_bld,
++ rv = OSSL_PARAM_BLD_push_octet_string(param_bld,
+ OSSL_KDF_PARAM_SSHKDF_XCGHASH,
+ crypto->secret_hash,
+ crypto->digest_len);
+- if (rc != 1) {
+- rc = -1;
++ if (rv != 1) {
+ goto out;
+ }
+- rc = OSSL_PARAM_BLD_push_octet_string(param_bld,
++ rv = OSSL_PARAM_BLD_push_octet_string(param_bld,
+ OSSL_KDF_PARAM_SSHKDF_SESSION_ID,
+ crypto->session_id,
+ crypto->session_id_len);
+- if (rc != 1) {
+- rc = -1;
++ if (rv != 1) {
+ goto out;
+ }
+- rc = OSSL_PARAM_BLD_push_utf8_string(param_bld, OSSL_KDF_PARAM_SSHKDF_TYPE,
++ rv = OSSL_PARAM_BLD_push_utf8_string(param_bld, OSSL_KDF_PARAM_SSHKDF_TYPE,
+ (const char*)&key_type, 1);
+- if (rc != 1) {
+- rc = -1;
++ if (rv != 1) {
+ goto out;
+ }
+
+ params = OSSL_PARAM_BLD_to_param(param_bld);
+ if (params == NULL) {
+- rc = -1;
+ goto out;
+ }
+
+- rc = EVP_KDF_derive(ctx, output, requested_len, params);
+- if (rc != 1) {
+- rc = -1;
++ rv = EVP_KDF_derive(ctx, output, requested_len, params);
++ if (rv != 1) {
+ goto out;
+ }
+ #endif /* OPENSSL_VERSION_NUMBER */
++ ret = SSH_OK;
+
+ out:
+ #if OPENSSL_VERSION_NUMBER >= 0x30000000L
+@@ -267,8 +261,8 @@ out:
+ OSSL_PARAM_free(params);
+ #endif
+ EVP_KDF_CTX_free(ctx);
+- if (rc < 0) {
+- return rc;
++ if (ret < 0) {
++ return ret;
+ }
+ return 0;
+ }
+--
+2.49.0
+
diff --git a/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-5987.patch b/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-5987.patch
new file mode 100644
index 0000000000..08395e0e7d
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-5987.patch
@@ -0,0 +1,37 @@
+From 90b4845e0c98574bbf7bea9e97796695f064bf57 Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Tue, 6 May 2025 22:51:41 +0200
+Subject: [PATCH] CVE-2025-5987 libcrypto: Correctly detect failures of chacha
+ initialization
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+Reviewed-by: Andreas Schneider <asn@cryptomilk.org>
+
+CVE: CVE-2025-5987
+
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=90b4845e0c98574bbf7bea9e97796695f064bf57]
+
+Signed-off-by: Divya Chellam <divya.chellam@windriver.com>
+---
+ src/libcrypto.c | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/src/libcrypto.c b/src/libcrypto.c
+index 76e067d3..69a850de 100644
+--- a/src/libcrypto.c
++++ b/src/libcrypto.c
+@@ -771,9 +771,9 @@ chacha20_poly1305_set_key(struct ssh_cipher_struct *cipher,
+ SSH_LOG(SSH_LOG_WARNING, "EVP_CIPHER_CTX_new failed");
+ goto out;
+ }
+- ret = EVP_EncryptInit_ex(ctx->header_evp, EVP_chacha20(), NULL,
++ rv = EVP_EncryptInit_ex(ctx->header_evp, EVP_chacha20(), NULL,
+ u8key + CHACHA20_KEYLEN, NULL);
+- if (ret != 1) {
++ if (rv != 1) {
+ SSH_LOG(SSH_LOG_WARNING, "EVP_CipherInit failed");
+ goto out;
+ }
+--
+2.40.0
+
diff --git a/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-8114.patch b/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-8114.patch
new file mode 100644
index 0000000000..10bbbcb114
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/libssh/libssh/CVE-2025-8114.patch
@@ -0,0 +1,49 @@
+From 5f4950367c027aa91fcea240df354a856a4a0025 Mon Sep 17 00:00:00 2001
+From: Andreas Schneider <asn@cryptomilk.org>
+Date: Wed, 6 Aug 2025 15:17:59 +0200
+Subject: [PATCH] CVE-2025-8114: Fix NULL pointer dereference after allocation
+ failure
+
+CVE: CVE-2025-8114
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=53ac23ded4cb]
+
+Signed-off-by: Andreas Schneider <asn@cryptomilk.org>
+Reviewed-by: Jakub Jelen <jjelen@redhat.com>
+(cherry picked from commit 53ac23ded4cb2c5463f6c4cd1525331bd578812d)
+Signed-off-by: Anil Dongare <adongare@cisco.com>
+---
+ src/kex.c | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/src/kex.c b/src/kex.c
+index fbc70cf4..b4bab277 100644
+--- a/src/kex.c
++++ b/src/kex.c
+@@ -1391,6 +1391,8 @@ int ssh_make_sessionid(ssh_session session)
+ ssh_log_hexdump("hash buffer", ssh_buffer_get(buf), ssh_buffer_get_len(buf));
+ #endif
+
++ /* Set rc for the following switch statement in case we goto error. */
++ rc = SSH_ERROR;
+ switch (session->next_crypto->kex_type) {
+ case SSH_KEX_DH_GROUP1_SHA1:
+ case SSH_KEX_DH_GROUP14_SHA1:
+@@ -1450,6 +1452,7 @@ int ssh_make_sessionid(ssh_session session)
+ session->next_crypto->secret_hash);
+ break;
+ }
++
+ /* During the first kex, secret hash and session ID are equal. However, after
+ * a key re-exchange, a new secret hash is calculated. This hash will not replace
+ * but complement existing session id.
+@@ -1458,6 +1461,7 @@ int ssh_make_sessionid(ssh_session session)
+ session->next_crypto->session_id = malloc(session->next_crypto->digest_len);
+ if (session->next_crypto->session_id == NULL) {
+ ssh_set_error_oom(session);
++ rc = SSH_ERROR;
+ goto error;
+ }
+ memcpy(session->next_crypto->session_id, session->next_crypto->secret_hash,
+--
+2.43.5
+
diff --git a/meta-openembedded/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-openembedded/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index 31f29c1b7d..602e01fce6 100644
--- a/meta-openembedded/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-openembedded/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -10,6 +10,14 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
file://0001-tests-CMakeLists.txt-do-not-search-ssh-sshd-commands.patch \
file://0001-libgcrypt.c-Fix-prototype-of-des3_encrypt-des3_decry.patch \
file://run-ptest \
+ file://CVE-2025-5318.patch \
+ file://CVE-2025-5351.patch \
+ file://CVE-2025-5372.patch \
+ file://CVE-2025-4877.patch \
+ file://CVE-2025-4878-0001.patch \
+ file://CVE-2025-4878-0002.patch \
+ file://CVE-2025-5987.patch \
+ file://CVE-2025-8114.patch \
"
SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
diff --git a/meta-openembedded/meta-oe/recipes-support/libusbgx/libusbgx_git.bb b/meta-openembedded/meta-oe/recipes-support/libusbgx/libusbgx_git.bb
index a20ff4eeab..7e88be00a4 100644
--- a/meta-openembedded/meta-oe/recipes-support/libusbgx/libusbgx_git.bb
+++ b/meta-openembedded/meta-oe/recipes-support/libusbgx/libusbgx_git.bb
@@ -40,7 +40,7 @@ INHIBIT_UPDATERCD_BBCLASS = "${@bb.utils.contains('PACKAGECONFIG', 'examples', '
do_install:append() {
install -Dm 0755 ${WORKDIR}/gadget-start ${D}${bindir}/gadget-start
sed -i -e 's,/usr/bin,${bindir},g' -e 's,/etc,${sysconfdir},g' ${D}${bindir}/gadget-start
- install -m 0755 ${WORKDIR}/gadget-start ${D}${bindir}/gadget-stop
+ install -m 0755 ${WORKDIR}/gadget-stop ${D}${bindir}/gadget-stop
sed -i -e 's,/usr/bin,${bindir},g' -e 's,/etc,${sysconfdir},g' ${D}${bindir}/gadget-stop
if ${@bb.utils.contains('DISTRO_FEATURES','systemd','true','false',d)}; then
diff --git a/meta-openembedded/meta-oe/recipes-support/log4cpp/log4cpp_1.1.4.bb b/meta-openembedded/meta-oe/recipes-support/log4cpp/log4cpp_1.1.4.bb
index 729857eb62..a8b9b9a019 100644
--- a/meta-openembedded/meta-oe/recipes-support/log4cpp/log4cpp_1.1.4.bb
+++ b/meta-openembedded/meta-oe/recipes-support/log4cpp/log4cpp_1.1.4.bb
@@ -20,3 +20,7 @@ EXTRA_OECONF = "\
"
CXXFLAGS += "-std=c++14"
+
+do_install:append() {
+ sed -i -e 's|${DEBUG_PREFIX_MAP}||g; s|--sysroot=${STAGING_DIR_TARGET}||g' ${D}${bindir}/log4cpp-config
+}
diff --git a/meta-openembedded/meta-oe/recipes-support/lvm2/libdevmapper_2.03.22.bb b/meta-openembedded/meta-oe/recipes-support/lvm2/libdevmapper_2.03.22.bb
index be558ce1d2..3b4439c3ae 100644
--- a/meta-openembedded/meta-oe/recipes-support/lvm2/libdevmapper_2.03.22.bb
+++ b/meta-openembedded/meta-oe/recipes-support/lvm2/libdevmapper_2.03.22.bb
@@ -5,6 +5,8 @@ require lvm2.inc
DEPENDS += "autoconf-archive-native"
+inherit nopackages
+
TARGET_CC_ARCH += "${LDFLAGS}"
do_install() {
diff --git a/meta-openembedded/meta-oe/recipes-support/nss/nss/CVE-2024-6602.patch b/meta-openembedded/meta-oe/recipes-support/nss/nss/CVE-2024-6602.patch
new file mode 100644
index 0000000000..f75d822d03
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/nss/nss/CVE-2024-6602.patch
@@ -0,0 +1,65 @@
+From 7804e99346339bb31f801a2fcba63b6fbd8bca4a Mon Sep 17 00:00:00 2001
+From: John Schanck <jschanck@mozilla.com>
+Date: Mon, 20 May 2024 18:46:14 +0000
+Subject: [PATCH] Bug 1895032 - remove redundant AllocItem implementation.
+ r=nss-reviewers,rrelyea
+
+Differential Revision: https://phabricator.services.mozilla.com/D209476
+
+--HG--
+extra : moz-landing-system : lando
+
+CVE: CVE-2024-6602
+Upstream-Status: Backport [https://hg.mozilla.org/projects/nss/rev/f9b22115dc97be76e388dc9d0dca946dde955e64]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ nss/lib/util/secitem.c | 23 ++++-------------------
+ 1 file changed, 4 insertions(+), 19 deletions(-)
+
+diff --git a/nss/lib/util/secitem.c b/nss/lib/util/secitem.c
+index cd6996178..6ba11a551 100644
+--- a/nss/lib/util/secitem.c
++++ b/nss/lib/util/secitem.c
+@@ -238,35 +238,20 @@ SECITEM_ArenaDupItem(PLArenaPool *arena, const SECItem *from)
+ SECItem *to;
+
+ if (from == NULL) {
+- return (NULL);
++ return NULL;
+ }
+
+- if (arena != NULL) {
+- to = (SECItem *)PORT_ArenaAlloc(arena, sizeof(SECItem));
+- } else {
+- to = (SECItem *)PORT_Alloc(sizeof(SECItem));
+- }
++ to = SECITEM_AllocItem(arena, NULL, from->len);
+ if (to == NULL) {
+- return (NULL);
++ return NULL;
+ }
+
+- if (arena != NULL) {
+- to->data = (unsigned char *)PORT_ArenaAlloc(arena, from->len);
+- } else {
+- to->data = (unsigned char *)PORT_Alloc(from->len);
+- }
+- if (to->data == NULL) {
+- PORT_Free(to);
+- return (NULL);
+- }
+-
+- to->len = from->len;
+ to->type = from->type;
+ if (to->len) {
+ PORT_Memcpy(to->data, from->data, to->len);
+ }
+
+- return (to);
++ return to;
+ }
+
+ SECStatus
+--
+2.30.2
+
diff --git a/meta-openembedded/meta-oe/recipes-support/nss/nss/CVE-2024-6609.patch b/meta-openembedded/meta-oe/recipes-support/nss/nss/CVE-2024-6609.patch
new file mode 100644
index 0000000000..38932cc237
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/nss/nss/CVE-2024-6609.patch
@@ -0,0 +1,30 @@
+From 41550b24b92c4a5971da9842e5e9f2b452aceca8 Tue Oct 29 22:44:57 2024
+From: Peter Marko <peter.marko@siemens.com>
+Date: Tue, 29 Oct 2024 22:44:57 +0100
+Subject: [PATCH] fix CVE-2024-6609
+
+CVE: CVE-2024-6609
+Upstream-Status: Inappropriate [upstream ticket: https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/t9JmsYkujWM/m/HjKuk-ngBAAJ]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ nss/lib/freebl/ec.c | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/nss/lib/freebl/ec.c b/nss/lib/freebl/ec.c
+index 73a625a..c9490da 100644
+--- a/nss/lib/freebl/ec.c
++++ b/nss/lib/freebl/ec.c
+@@ -302,6 +302,10 @@ done:
+
+ cleanup:
+ mp_clear(&k);
++ if (err < MP_OKAY) {
++ MP_TO_SEC_ERROR(err);
++ rv = SECFailure;
++ }
+ if (rv) {
+ PORT_FreeArena(arena, PR_TRUE);
+ }
+--
+2.30.2
+
diff --git a/meta-openembedded/meta-oe/recipes-support/nss/nss_3.98.bb b/meta-openembedded/meta-oe/recipes-support/nss/nss_3.98.bb
index 01501362e2..9218b4d30b 100644
--- a/meta-openembedded/meta-oe/recipes-support/nss/nss_3.98.bb
+++ b/meta-openembedded/meta-oe/recipes-support/nss/nss_3.98.bb
@@ -32,6 +32,8 @@ SRC_URI = "http://ftp.mozilla.org/pub/security/nss/releases/${VERSION_DIR}/src/$
file://system-pkcs11.txt \
file://nss-fix-nsinstall-build.patch \
file://0001-freebl-add-a-configure-option-to-disable-ARM-HW-cryp.patch \
+ file://CVE-2024-6602.patch \
+ file://CVE-2024-6609.patch \
"
SRC_URI[sha256sum] = "f549cc33d35c0601674bfacf7c6ad683c187595eb4125b423238d3e9aa4209ce"
diff --git a/meta-openembedded/meta-oe/recipes-support/opensc/files/0001-PR-Fixes-for-uninitialized-memory-issues.patch b/meta-openembedded/meta-oe/recipes-support/opensc/files/0001-PR-Fixes-for-uninitialized-memory-issues.patch
new file mode 100644
index 0000000000..1c45067e5e
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/opensc/files/0001-PR-Fixes-for-uninitialized-memory-issues.patch
@@ -0,0 +1,1268 @@
+From: Virendra Thakur <virendrak@kpit.com>
+Date: Tue, 15 Oct 2024 17:29:19 +0000 (-0600)
+Subject: Avoid using uninitialized memory
+
+Avoid using uninitialized memory
+
+37 new use-of-uninitialized-memory bugs were found while testing fuzzing harnesses. The bugs were found in these functions:
+
+cac_read_file()
+cardos_match_card()
+sc_bin_to_hex()
+strcmp(), from gids_get_identifiers()
+do_select()
+bcmp(), from cac_list_compare_path()
+insert_cert()
+cardos_lifecycle_get()
+gids_read_masterfile()
+sc_pkcs15init_parse_info()
+piv_get_challenge()
+asn1_decode()
+malloc(), from cac_read_file()
+sc_asn1_decode_object_id()
+sc_pkcs15emu_sc_hsm_decode_cvc()
+gemsafe_get_cert_len()
+process_fcp()
+dnie_process_fci()
+iso7816_process_fci()
+sc_pkcs15_read_file()
+strlen(), from set_string()
+asn1_encode_path()
+msc_extract_rsa_public_key()
+sc_build_pin()
+DES_set_key_unchecked(), from openssl_enc()
+starcos_write_pukey()
+iasecc_sdo_parse()
+setcos_generate_key()
+iasecc_parse_size()
+iasecc_se_parse()
+sc_hsm_determine_free_id()
+asn1_encode_entry()
+coolkey_rsa_op()
+sc_asn1_read_tag()
+do_init_app()
+sc_pkcs15init_create_pin()
+sc_asn1_clear_algorithm_id()
+Reported by Matteo Marini (@Heinzeen)
+
+Upstream-Status: Backport [https://github.com/OpenSC/OpenSC/pull/3225/files/ab476044a009003262991c065b792baa053c7be5]
+
+CVE: CVE-2024-45615 CVE-2024-45616 CVE-2024-45617 CVE-2024-45618 CVE-2024-45619 CVE-2024-45620
+Hunk present in card-entersafe.c and card-gids.c are refresehed base on codebase.
+
+From f25c61dae98ebfc7eb81b48f002621663cfcf9cb Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Mon, 20 May 2024 21:19:15 +0200
+Subject: [PATCH 01/30] gids: Avoid using uninitialized memory
+
+Thanks Matteo Marini for report
+
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-h5f7-rjr5-vx54
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+---
+ src/libopensc/card-gids.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/libopensc/card-gids.c b/src/libopensc/card-gids.c
+index aa63035097..90c98b557d 100644
+--- a/src/libopensc/card-gids.c
++++ b/src/libopensc/card-gids.c
+@@ -251,7 +251,7 @@ static int gids_get_DO(sc_card_t* card,
+ LOG_TEST_RET(card->ctx, r, "gids get data failed");
+ LOG_TEST_RET(card->ctx, sc_check_sw(card, apdu.sw1, apdu.sw2), "invalid return");
+
+- p = sc_asn1_find_tag(card->ctx, buffer, sizeof(buffer), dataObjectIdentifier, &datasize);
++ p = sc_asn1_find_tag(card->ctx, buffer, apdu.resplen, dataObjectIdentifier, &datasize);
+ if (!p) {
+ LOG_FUNC_RETURN(card->ctx, SC_ERROR_FILE_NOT_FOUND);
+ }
+
+From a905ad4600ab13f36ec1d0c909b18ca016d91a5a Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Mon, 20 May 2024 21:31:38 +0200
+Subject: [PATCH 02/30] pkcs15init: Avoid using uninitialized memory
+
+Thanks Matteo Marini for report
+
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-h5f7-rjr5-vx54
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+---
+ src/pkcs15init/profile.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/pkcs15init/profile.c b/src/pkcs15init/profile.c
+index 5113af6ef6..72963e2f9c 100644
+--- a/src/pkcs15init/profile.c
++++ b/src/pkcs15init/profile.c
+@@ -1809,7 +1809,7 @@ do_pin_storedlength(struct state *cur, int argc, char **argv)
+ static int
+ do_pin_flags(struct state *cur, int argc, char **argv)
+ {
+- unsigned int flags;
++ unsigned int flags = 0;
+ int i, r;
+
+ if (cur->pin->pin.auth_type != SC_PKCS15_PIN_AUTH_TYPE_PIN)
+
+From 4ca050b83c8f265280059697c3764460ad8aac9b Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Tue, 3 Sep 2024 09:15:22 +0200
+Subject: [PATCH 03/30] pkcs15init: Remove tab indentation
+
+---
+ src/pkcs15init/profile.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/pkcs15init/profile.c b/src/pkcs15init/profile.c
+index 72963e2f9c..4fbc3e7e1f 100644
+--- a/src/pkcs15init/profile.c
++++ b/src/pkcs15init/profile.c
+@@ -1809,7 +1809,7 @@ do_pin_storedlength(struct state *cur, int argc, char **argv)
+ static int
+ do_pin_flags(struct state *cur, int argc, char **argv)
+ {
+- unsigned int flags = 0;
++ unsigned int flags = 0;
+ int i, r;
+
+ if (cur->pin->pin.auth_type != SC_PKCS15_PIN_AUTH_TYPE_PIN)
+
+From 5580be58f2dc88f8b75a60d213a57014333c6b17 Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Mon, 20 May 2024 22:14:48 +0200
+Subject: [PATCH 04/30] cac: Correctly calculate certificate length based on
+ the resplen
+
+Thanks Matteo Marini for report
+
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-h5f7-rjr5-vx54
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+---
+ src/libopensc/card-cac1.c | 6 +++---
+ 1 file changed, 3 insertions(+), 3 deletions(-)
+
+diff --git a/src/libopensc/card-cac1.c b/src/libopensc/card-cac1.c
+index 5ddacc4565..06b2671f43 100644
+--- a/src/libopensc/card-cac1.c
++++ b/src/libopensc/card-cac1.c
+@@ -92,12 +92,12 @@ static int cac_cac1_get_certificate(sc_card_t *card, u8 **out_buf, size_t *out_l
+ if (apdu.sw1 != 0x63 || apdu.sw2 < 1) {
+ /* we've either finished reading, or hit an error, break */
+ r = sc_check_sw(card, apdu.sw1, apdu.sw2);
+- left -= len;
++ left -= apdu.resplen;
+ break;
+ }
+ /* Adjust the lengths */
+- left -= len;
+- out_ptr += len;
++ left -= apdu.resplen;
++ out_ptr += apdu.resplen;
+ len = MIN(left, apdu.sw2);
+ }
+ if (r < 0) {
+
+From 9da37a80ed3b3ceaf472e1a43a4672f4e30637d1 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Thu, 11 Jul 2024 14:58:25 +0200
+Subject: [PATCH 05/30] cac: Fix uninitialized values
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_card/1,fuzz_pkcs11/6
+---
+ src/libopensc/card-cac.c | 12 ++++++------
+ 1 file changed, 6 insertions(+), 6 deletions(-)
+
+diff --git a/src/libopensc/card-cac.c b/src/libopensc/card-cac.c
+index 898fce8aa5..412f22644d 100644
+--- a/src/libopensc/card-cac.c
++++ b/src/libopensc/card-cac.c
+@@ -252,7 +252,7 @@ static int cac_apdu_io(sc_card_t *card, int ins, int p1, int p2,
+ size_t * recvbuflen)
+ {
+ int r;
+- sc_apdu_t apdu;
++ sc_apdu_t apdu = {0};
+ u8 rbufinitbuf[CAC_MAX_SIZE];
+ u8 *rbuf;
+ size_t rbuflen;
+@@ -389,13 +389,13 @@ cac_get_acr(sc_card_t *card, int acr_type, u8 **out_buf, size_t *out_len)
+ static int cac_read_file(sc_card_t *card, int file_type, u8 **out_buf, size_t *out_len)
+ {
+ u8 params[2];
+- u8 count[2];
++ u8 count[2] = {0};
+ u8 *out = NULL;
+- u8 *out_ptr;
++ u8 *out_ptr = NULL;
+ size_t offset = 0;
+ size_t size = 0;
+ size_t left = 0;
+- size_t len;
++ size_t len = 0;
+ int r;
+
+ params[0] = file_type;
+@@ -458,7 +458,7 @@ static int cac_read_binary(sc_card_t *card, unsigned int idx,
+ const u8 *tl_ptr, *val_ptr, *tl_start;
+ u8 *tlv_ptr;
+ const u8 *cert_ptr;
+- size_t tl_len, val_len, tlv_len;
++ size_t tl_len = 0, val_len = 0, tlv_len;
+ size_t len, tl_head_len, cert_len;
+ u8 cert_type, tag;
+
+@@ -1519,7 +1519,7 @@ static int cac_parse_CCC(sc_card_t *card, cac_private_data_t *priv, const u8 *tl
+ static int cac_process_CCC(sc_card_t *card, cac_private_data_t *priv, int depth)
+ {
+ u8 *tl = NULL, *val = NULL;
+- size_t tl_len, val_len;
++ size_t tl_len = 0, val_len = 0;
+ int r;
+
+ if (depth > CAC_MAX_CCC_DEPTH) {
+
+From 39a55ef0a44cb34b22e585281b1e1eee30eb79a5 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Thu, 11 Jul 2024 15:27:19 +0200
+Subject: [PATCH 06/30] cardos: Fix uninitialized values
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_card/2
+---
+ src/libopensc/card-cardos.c | 8 ++++----
+ 1 file changed, 4 insertions(+), 4 deletions(-)
+
+diff --git a/src/libopensc/card-cardos.c b/src/libopensc/card-cardos.c
+index 2e2d524333..a0e2322478 100644
+--- a/src/libopensc/card-cardos.c
++++ b/src/libopensc/card-cardos.c
+@@ -94,14 +94,14 @@ static void fixup_transceive_length(const struct sc_card *card,
+
+ static int cardos_match_card(sc_card_t *card)
+ {
+- unsigned char atr[SC_MAX_ATR_SIZE];
++ unsigned char atr[SC_MAX_ATR_SIZE] = { 0 };
+ int i;
+
+ i = _sc_match_atr(card, cardos_atrs, &card->type);
+ if (i < 0)
+ return 0;
+
+- memcpy(atr, card->atr.value, sizeof(atr));
++ memcpy(atr, card->atr.value, card->atr.len);
+
+ /* Do not change card type for CIE! */
+ if (card->type == SC_CARD_TYPE_CARDOS_CIE_V1)
+@@ -114,8 +114,8 @@ static int cardos_match_card(sc_card_t *card)
+ return 1;
+ if (card->type == SC_CARD_TYPE_CARDOS_M4_2) {
+ int rv;
+- sc_apdu_t apdu;
+- u8 rbuf[SC_MAX_APDU_BUFFER_SIZE];
++ sc_apdu_t apdu = { 0 };
++ u8 rbuf[SC_MAX_APDU_BUFFER_SIZE] = { 0 };
+ /* first check some additional ATR bytes */
+ if ((atr[4] != 0xff && atr[4] != 0x02) ||
+ (atr[6] != 0x10 && atr[6] != 0x0a) ||
+
+From e66619fadb3fd666e3359886fe18e387de068799 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Fri, 12 Jul 2024 13:16:56 +0200
+Subject: [PATCH 07/30] card-dnie: Check APDU response length and ASN1 lengths
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs15_decode/10, fuzz_pkcs15_encode/12
+---
+ src/libopensc/asn1.c | 4 +++-
+ src/libopensc/card-dnie.c | 8 ++++++--
+ 2 files changed, 9 insertions(+), 3 deletions(-)
+
+diff --git a/src/libopensc/asn1.c b/src/libopensc/asn1.c
+index 08ef56149c..548263a2da 100644
+--- a/src/libopensc/asn1.c
++++ b/src/libopensc/asn1.c
+@@ -68,7 +68,7 @@ int sc_asn1_read_tag(const u8 ** buf, size_t buflen, unsigned int *cla_out,
+
+ *buf = NULL;
+
+- if (left == 0 || !p)
++ if (left == 0 || !p || buflen == 0)
+ return SC_ERROR_INVALID_ASN1_OBJECT;
+ if (*p == 0xff || *p == 0) {
+ /* end of data reached */
+@@ -83,6 +83,8 @@ int sc_asn1_read_tag(const u8 ** buf, size_t buflen, unsigned int *cla_out,
+ */
+ cla = (*p & SC_ASN1_TAG_CLASS) | (*p & SC_ASN1_TAG_CONSTRUCTED);
+ tag = *p & SC_ASN1_TAG_PRIMITIVE;
++ if (left < 1)
++ return SC_ERROR_INVALID_ASN1_OBJECT;
+ p++;
+ left--;
+ if (tag == SC_ASN1_TAG_PRIMITIVE) {
+diff --git a/src/libopensc/card-dnie.c b/src/libopensc/card-dnie.c
+index 464670f096..d8b90e8439 100644
+--- a/src/libopensc/card-dnie.c
++++ b/src/libopensc/card-dnie.c
+@@ -1172,12 +1172,16 @@ static int dnie_compose_and_send_apdu(sc_card_t *card, const u8 *path, size_t pa
+
+ if (file_out) {
+ /* finally process FCI response */
++ size_t len = apdu.resp[1];
+ sc_file_free(*file_out);
+ *file_out = sc_file_new();
+ if (*file_out == NULL) {
+ LOG_FUNC_RETURN(ctx, SC_ERROR_OUT_OF_MEMORY);
+ }
+- res = card->ops->process_fci(card, *file_out, apdu.resp + 2, apdu.resp[1]);
++ if (apdu.resplen - 2 < len || len < 1) {
++ LOG_FUNC_RETURN(ctx, SC_ERROR_UNKNOWN_DATA_RECEIVED);
++ }
++ res = card->ops->process_fci(card, *file_out, apdu.resp + 2, len);
+ }
+ LOG_FUNC_RETURN(ctx, res);
+ }
+@@ -1935,7 +1939,7 @@ static int dnie_process_fci(struct sc_card *card,
+ int *op = df_acl;
+ int n = 0;
+ sc_context_t *ctx = NULL;
+- if ((card == NULL) || (card->ctx == NULL) || (file == NULL))
++ if ((card == NULL) || (card->ctx == NULL) || (file == NULL) || buflen == 0)
+ return SC_ERROR_INVALID_ARGUMENTS;
+ ctx = card->ctx;
+ LOG_FUNC_CALLED(ctx);
+
+From 737931e6edaaa2142e1e71a2b76159f6ce458bb8 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Fri, 12 Jul 2024 14:03:59 +0200
+Subject: [PATCH 08/30] muscle: Report invalid SW when reading object
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs11/20, fuzz_pkcs15init/10
+---
+ src/libopensc/muscle.c | 19 ++++++++++---------
+ 1 file changed, 10 insertions(+), 9 deletions(-)
+
+diff --git a/src/libopensc/muscle.c b/src/libopensc/muscle.c
+index 46a9f66b88..89dfcbbcba 100644
+--- a/src/libopensc/muscle.c
++++ b/src/libopensc/muscle.c
+@@ -92,33 +92,34 @@ int msc_partial_read_object(sc_card_t *card, msc_id objectId, int offset, u8 *da
+ apdu.resp = data;
+ r = sc_transmit_apdu(card, &apdu);
+ LOG_TEST_RET(card->ctx, r, "APDU transmit failed");
+- if(apdu.sw1 == 0x90 && apdu.sw2 == 0x00)
++ if (apdu.sw1 == 0x90 && apdu.sw2 == 0x00 && dataLength <= apdu.resplen)
+ return (int)dataLength;
+- if(apdu.sw1 == 0x9C) {
+- if(apdu.sw2 == 0x07) {
++ if (apdu.sw1 == 0x9C) {
++ if (apdu.sw2 == 0x07) {
+ SC_FUNC_RETURN(card->ctx, SC_LOG_DEBUG_VERBOSE, SC_ERROR_FILE_NOT_FOUND);
+- } else if(apdu.sw2 == 0x06) {
++ } else if (apdu.sw2 == 0x06) {
+ SC_FUNC_RETURN(card->ctx, SC_LOG_DEBUG_VERBOSE, SC_ERROR_NOT_ALLOWED);
+- } else if(apdu.sw2 == 0x0F) {
++ } else if (apdu.sw2 == 0x0F) {
+ /* GUESSED */
+ SC_FUNC_RETURN(card->ctx, SC_LOG_DEBUG_VERBOSE, SC_ERROR_INVALID_ARGUMENTS);
+ }
+ }
+ sc_log(card->ctx,
+ "got strange SWs: 0x%02X 0x%02X\n", apdu.sw1, apdu.sw2);
+- return (int)dataLength;
+-
++ SC_FUNC_RETURN(card->ctx, SC_LOG_DEBUG_VERBOSE, SC_ERROR_UNKNOWN_DATA_RECEIVED);
+ }
+
+ int msc_read_object(sc_card_t *card, msc_id objectId, int offset, u8 *data, size_t dataLength)
+ {
+- int r;
++ int r = 0;
+ unsigned int i;
+ size_t max_read_unit = MSC_MAX_READ;
+
+- for(i = 0; i < dataLength; i += max_read_unit) {
++ for (i = 0; i < dataLength; i += r) {
+ r = msc_partial_read_object(card, objectId, offset + i, data + i, MIN(dataLength - i, max_read_unit));
+ LOG_TEST_RET(card->ctx, r, "Error in partial object read");
++ if (r == 0)
++ break;
+ }
+ return (int)dataLength;
+ }
+
+From e7f6a24b7e9ac849d0242ce9e183c8160e5e9e8c Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Fri, 12 Jul 2024 14:16:24 +0200
+Subject: [PATCH 09/30] card-mcrd: Check length of response buffer in select
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs11/5,12 fuzz_pkcs15_crypt/9
+---
+ src/libopensc/card-mcrd.c | 11 +++++++----
+ 1 file changed, 7 insertions(+), 4 deletions(-)
+
+diff --git a/src/libopensc/card-mcrd.c b/src/libopensc/card-mcrd.c
+index 3a549999eb..911e9f0a07 100644
+--- a/src/libopensc/card-mcrd.c
++++ b/src/libopensc/card-mcrd.c
+@@ -587,20 +587,23 @@ do_select(sc_card_t * card, u8 kind,
+ }
+ }
+
+- if (p2 == 0x04 && apdu.resp[0] == 0x62) {
++ if (p2 == 0x04 && apdu.resplen > 2 && apdu.resp[0] == 0x62) {
+ *file = sc_file_new();
+ if (!*file)
+ LOG_FUNC_RETURN(card->ctx, SC_ERROR_OUT_OF_MEMORY);
++ if (apdu.resp[1] > apdu.resplen - 2)
++ LOG_FUNC_RETURN(card->ctx, SC_ERROR_INVALID_DATA);
+ process_fcp(card, *file, apdu.resp + 2, apdu.resp[1]);
+ return SC_SUCCESS;
+ }
+
+- if (p2 != 0x0C && apdu.resp[0] == 0x6F) {
++ if (p2 != 0x0C && apdu.resplen > 2 && apdu.resp[0] == 0x6F) {
+ *file = sc_file_new();
+ if (!*file)
+ LOG_FUNC_RETURN(card->ctx, SC_ERROR_OUT_OF_MEMORY);
+- if (apdu.resp[1] <= apdu.resplen)
+- process_fcp(card, *file, apdu.resp + 2, apdu.resp[1]);
++ if (apdu.resp[1] > apdu.resplen - 2)
++ LOG_FUNC_RETURN(card->ctx, SC_ERROR_INVALID_DATA);
++ process_fcp(card, *file, apdu.resp + 2, apdu.resp[1]);
+ return SC_SUCCESS;
+ }
+ return SC_SUCCESS;
+
+From d18a07ea891c7bd7dff0d187fbb4df5169fd9698 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Fri, 12 Jul 2024 14:35:47 +0200
+Subject: [PATCH 10/30] pkcs15-cert.c: Initialize OID length
+
+In case it is not set later.
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs11/7
+---
+ src/libopensc/pkcs15-cert.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/libopensc/pkcs15-cert.c b/src/libopensc/pkcs15-cert.c
+index 1777a85835..5e2dbb89d0 100644
+--- a/src/libopensc/pkcs15-cert.c
++++ b/src/libopensc/pkcs15-cert.c
+@@ -169,7 +169,7 @@ sc_pkcs15_get_name_from_dn(struct sc_context *ctx, const u8 *dn, size_t dn_len,
+ for (next_ava = rdn, next_ava_len = rdn_len; next_ava_len; ) {
+ const u8 *ava, *dummy, *oidp;
+ struct sc_object_id oid;
+- size_t ava_len, dummy_len, oid_len;
++ size_t ava_len = 0, dummy_len, oid_len = 0;
+
+ /* unwrap the set and point to the next ava */
+ ava = sc_asn1_skip_tag(ctx, &next_ava, &next_ava_len, SC_ASN1_TAG_SET | SC_ASN1_CONS, &ava_len);
+
+From c65e6f004d99187d63d68e4a9a9d5ada770b7b8d Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Fri, 12 Jul 2024 15:04:19 +0200
+Subject: [PATCH 11/30] card-gids: Use actual length of reponse buffer
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs11/11
+---
+ src/libopensc/card-gids.c | 6 ++++--
+ 1 file changed, 4 insertions(+), 2 deletions(-)
+
+diff --git a/src/libopensc/card-gids.c b/src/libopensc/card-gids.c
+index 90c98b557d..5fb0d4acb4 100644
+--- a/src/libopensc/card-gids.c
++++ b/src/libopensc/card-gids.c
+@@ -231,6 +231,7 @@ static int gids_get_DO(sc_card_t* card,
+ size_t datasize = 0;
+ const u8* p;
+ u8 buffer[MAX_GIDS_FILE_SIZE];
++ size_t buffer_len = sizeof(buffer);
+
+ SC_FUNC_CALLED(card->ctx, SC_LOG_DEBUG_VERBOSE);
+ sc_log(card->ctx,
+@@ -244,14 +245,15 @@ static int gids_get_DO(sc_card_t* card,
+ apdu.data = data;
+ apdu.datalen = 04;
+ apdu.resp = buffer;
+- apdu.resplen = sizeof(buffer);
++ apdu.resplen = buffer_len;
+ apdu.le = 256;
+
+ r = sc_transmit_apdu(card, &apdu);
+ LOG_TEST_RET(card->ctx, r, "gids get data failed");
+ LOG_TEST_RET(card->ctx, sc_check_sw(card, apdu.sw1, apdu.sw2), "invalid return");
++ buffer_len = apdu.resplen;
+
+- p = sc_asn1_find_tag(card->ctx, buffer, apdu.resplen, dataObjectIdentifier, &datasize);
++ p = sc_asn1_find_tag(card->ctx, buffer, buffer_len, dataObjectIdentifier, &datasize);
+ if (!p) {
+ LOG_FUNC_RETURN(card->ctx, SC_ERROR_FILE_NOT_FOUND);
+ }
+
+From 3b242c5d7160a66fb94efabef9318ebf03ebc63f Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Tue, 16 Jul 2024 14:05:36 +0200
+Subject: [PATCH 12/30] cac: Check return value when selecting AID
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs11/14
+---
+ src/libopensc/card-cac.c | 6 +++---
+ 1 file changed, 3 insertions(+), 3 deletions(-)
+
+diff --git a/src/libopensc/card-cac.c b/src/libopensc/card-cac.c
+index 412f22644d..71ab7e482f 100644
+--- a/src/libopensc/card-cac.c
++++ b/src/libopensc/card-cac.c
+@@ -1293,10 +1293,10 @@ static int cac_parse_aid(sc_card_t *card, cac_private_data_t *priv, const u8 *ai
+ /* Call without OID set will just select the AID without subsequent
+ * OID selection, which we need to figure out just now
+ */
+- cac_select_file_by_type(card, &new_object.path, NULL);
++ r = cac_select_file_by_type(card, &new_object.path, NULL);
++ LOG_TEST_RET(card->ctx, r, "Cannot select AID");
+ r = cac_get_properties(card, &prop);
+- if (r < 0)
+- return SC_ERROR_INTERNAL;
++ LOG_TEST_RET(card->ctx, r, "Cannot get CAC properties");
+
+ for (i = 0; i < prop.num_objects; i++) {
+ /* don't fail just because we have more certs than we can support */
+
+From 19d55573fcb638d02acc378cf638da9b4e481cd7 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Tue, 16 Jul 2024 14:22:02 +0200
+Subject: [PATCH 13/30] pkcs15-tcos: Check number of read bytes for cert
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs11/15
+---
+ src/libopensc/pkcs15-tcos.c | 3 ++-
+ 1 file changed, 2 insertions(+), 1 deletion(-)
+
+diff --git a/src/libopensc/pkcs15-tcos.c b/src/libopensc/pkcs15-tcos.c
+index a84001e122..4d02a98ee1 100644
+--- a/src/libopensc/pkcs15-tcos.c
++++ b/src/libopensc/pkcs15-tcos.c
+@@ -62,7 +62,8 @@ static int insert_cert(
+ "Select(%s) failed\n", path);
+ return 1;
+ }
+- if(sc_read_binary(card, 0, cert, sizeof(cert), 0)<0){
++ r = sc_read_binary(card, 0, cert, sizeof(cert), 0);
++ if (r <= 0){
+ sc_log(ctx,
+ "ReadBinary(%s) failed\n", path);
+ return 2;
+
+From 74d42f32fd6f96f190ee7dd188f873115dcb5af2 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Tue, 16 Jul 2024 14:29:01 +0200
+Subject: [PATCH 14/30] cardos: Return error when response length is 0
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs11/18
+---
+ src/libopensc/card-cardos.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/libopensc/card-cardos.c b/src/libopensc/card-cardos.c
+index a0e2322478..124752d78b 100644
+--- a/src/libopensc/card-cardos.c
++++ b/src/libopensc/card-cardos.c
+@@ -1281,7 +1281,7 @@ cardos_lifecycle_get(sc_card_t *card, int *mode)
+ LOG_TEST_RET(card->ctx, r, "Card returned error");
+
+ if (apdu.resplen < 1) {
+- LOG_TEST_RET(card->ctx, r, "Lifecycle byte not in response");
++ LOG_TEST_RET(card->ctx, SC_ERROR_UNKNOWN_DATA_RECEIVED, "Lifecycle byte not in response");
+ }
+
+ r = SC_SUCCESS;
+
+From 2e6333f2024765bbd0e384cadce6d6c6496339a2 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Tue, 16 Jul 2024 15:51:51 +0200
+Subject: [PATCH 15/30] card-piv: Initialize variables for tag and CLA
+
+In case they are not later initialize later by
+sc_asn1_read_tag() function.
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs11/21
+---
+ src/libopensc/card-piv.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/libopensc/card-piv.c b/src/libopensc/card-piv.c
+index f4eafe47a4..034635d898 100644
+--- a/src/libopensc/card-piv.c
++++ b/src/libopensc/card-piv.c
+@@ -4428,7 +4428,7 @@ static int piv_get_challenge(sc_card_t *card, u8 *rnd, size_t len)
+ const u8 *p;
+ size_t out_len = 0;
+ int r;
+- unsigned int tag_out, cla_out;
++ unsigned int tag_out = 0, cla_out = 0;
+ piv_private_data_t * priv = PIV_DATA(card);
+
+ LOG_FUNC_CALLED(card->ctx);
+
+From 95815e45fb9f764d6e820a287ebc242e5a3155ec Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Tue, 16 Jul 2024 16:32:45 +0200
+Subject: [PATCH 16/30] pkcs15-sc-hsm: Initialize variables for tag and CLA
+
+In case they are not later initialize later by
+sc_asn1_read_tag() function.
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs15_crypt/12
+---
+ src/libopensc/pkcs15-sc-hsm.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/libopensc/pkcs15-sc-hsm.c b/src/libopensc/pkcs15-sc-hsm.c
+index 315cd74482..acdbee7054 100644
+--- a/src/libopensc/pkcs15-sc-hsm.c
++++ b/src/libopensc/pkcs15-sc-hsm.c
+@@ -386,7 +386,7 @@ int sc_pkcs15emu_sc_hsm_decode_cvc(sc_pkcs15_card_t * p15card,
+ struct sc_asn1_entry asn1_cvcert[C_ASN1_CVCERT_SIZE];
+ struct sc_asn1_entry asn1_cvc_body[C_ASN1_CVC_BODY_SIZE];
+ struct sc_asn1_entry asn1_cvc_pubkey[C_ASN1_CVC_PUBKEY_SIZE];
+- unsigned int cla,tag;
++ unsigned int cla = 0, tag = 0;
+ size_t taglen;
+ const u8 *tbuf;
+ int r;
+
+From 16e0af0a310e4f611b88ea29ec53e02928d5ba35 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Wed, 17 Jul 2024 09:15:43 +0200
+Subject: [PATCH 17/30] pkcs15-gemsafeV1: Check length of buffer for object
+
+Number of actually read bytes may differ from
+the stated object length.
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs15_crypt/15
+---
+ src/libopensc/pkcs15-gemsafeV1.c | 20 +++++++++++++++-----
+ 1 file changed, 15 insertions(+), 5 deletions(-)
+
+diff --git a/src/libopensc/pkcs15-gemsafeV1.c b/src/libopensc/pkcs15-gemsafeV1.c
+index 25140503fa..9fb8956fe9 100644
+--- a/src/libopensc/pkcs15-gemsafeV1.c
++++ b/src/libopensc/pkcs15-gemsafeV1.c
+@@ -169,6 +169,7 @@ static int gemsafe_get_cert_len(sc_card_t *card)
+ size_t objlen;
+ int certlen;
+ unsigned int ind, i=0;
++ int read_len;
+
+ sc_format_path(GEMSAFE_PATH, &path);
+ r = sc_select_file(card, &path, &file);
+@@ -177,9 +178,11 @@ static int gemsafe_get_cert_len(sc_card_t *card)
+ sc_file_free(file);
+
+ /* Initial read */
+- r = sc_read_binary(card, 0, ibuf, GEMSAFE_READ_QUANTUM, 0);
+- if (r < 0)
++ read_len = sc_read_binary(card, 0, ibuf, GEMSAFE_READ_QUANTUM, 0);
++ if (read_len <= 2) {
++ sc_log(card->ctx, "Invalid size of object data: %d", read_len);
+ return SC_ERROR_INTERNAL;
++ }
+
+ /* Actual stored object size is encoded in first 2 bytes
+ * (allocated EF space is much greater!)
+@@ -208,7 +211,7 @@ static int gemsafe_get_cert_len(sc_card_t *card)
+ * the private key.
+ */
+ ind = 2; /* skip length */
+- while (ibuf[ind] == 0x01 && i < gemsafe_cert_max) {
++ while (ind + 1 < (size_t)read_len && ibuf[ind] == 0x01 && i < gemsafe_cert_max) {
+ if (ibuf[ind+1] == 0xFE) {
+ gemsafe_prkeys[i].ref = ibuf[ind+4];
+ sc_log(card->ctx, "Key container %d is allocated and uses key_ref %d",
+@@ -235,7 +238,7 @@ static int gemsafe_get_cert_len(sc_card_t *card)
+ /* Read entire file, then dissect in memory.
+ * Gemalto ClassicClient seems to do it the same way.
+ */
+- iptr = ibuf + GEMSAFE_READ_QUANTUM;
++ iptr = ibuf + read_len;
+ while ((size_t)(iptr - ibuf) < objlen) {
+ r = sc_read_binary(card, (unsigned)(iptr - ibuf), iptr,
+ MIN(GEMSAFE_READ_QUANTUM, objlen - (iptr - ibuf)), 0);
+@@ -243,7 +246,14 @@ static int gemsafe_get_cert_len(sc_card_t *card)
+ sc_log(card->ctx, "Could not read cert object");
+ return SC_ERROR_INTERNAL;
+ }
+- iptr += GEMSAFE_READ_QUANTUM;
++ if (r == 0)
++ break;
++ read_len += r;
++ iptr += r;
++ }
++ if ((size_t)read_len < objlen) {
++ sc_log(card->ctx, "Could not read cert object");
++ return SC_ERROR_INTERNAL;
+ }
+
+ /* Search buffer for certificates, they start with 0x3082. */
+
+From 5aad7762d144a39ef11bd6f0881fc7e992161bb5 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Wed, 17 Jul 2024 10:39:52 +0200
+Subject: [PATCH 18/30] card-jpki: Check number of read bytes
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs15_encode/18
+---
+ src/libopensc/card-jpki.c | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/src/libopensc/card-jpki.c b/src/libopensc/card-jpki.c
+index 6e4d0f3165..71339491d1 100644
+--- a/src/libopensc/card-jpki.c
++++ b/src/libopensc/card-jpki.c
+@@ -195,6 +195,8 @@ jpki_select_file(struct sc_card *card,
+ u8 buf[4];
+ rc = sc_read_binary(card, 0, buf, 4, 0);
+ LOG_TEST_RET(card->ctx, rc, "SW Check failed");
++ if (rc < 4)
++ LOG_TEST_RET(card->ctx, SC_ERROR_UNKNOWN_DATA_RECEIVED, "Received data too short");
+ file = sc_file_new();
+ if (!file) {
+ LOG_FUNC_RETURN(card->ctx, SC_ERROR_OUT_OF_MEMORY);
+
+From 535e9d62f94b496bb5214edf0ee6f431ae6d94cb Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Wed, 17 Jul 2024 11:18:52 +0200
+Subject: [PATCH 19/30] pkcs15-tcos: Check return value of serial num
+ conversion
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs15_encode/21
+---
+ src/libopensc/pkcs15-tcos.c | 9 +++++++--
+ 1 file changed, 7 insertions(+), 2 deletions(-)
+
+diff --git a/src/libopensc/pkcs15-tcos.c b/src/libopensc/pkcs15-tcos.c
+index 4d02a98ee1..2bd275c4f4 100644
+--- a/src/libopensc/pkcs15-tcos.c
++++ b/src/libopensc/pkcs15-tcos.c
+@@ -531,10 +531,15 @@ int sc_pkcs15emu_tcos_init_ex(
+ /* get the card serial number */
+ r = sc_card_ctl(card, SC_CARDCTL_GET_SERIALNR, &serialnr);
+ if (r < 0) {
+- sc_log(ctx, "unable to get ICCSN\n");
++ sc_log(ctx, "unable to get ICCSN");
+ return SC_ERROR_WRONG_CARD;
+ }
+- sc_bin_to_hex(serialnr.value, serialnr.len , serial, sizeof(serial), 0);
++ r = sc_bin_to_hex(serialnr.value, serialnr.len, serial, sizeof(serial), 0);
++ if (r != SC_SUCCESS) {
++ sc_log(ctx, "serial number invalid");
++ return SC_ERROR_INTERNAL;
++ }
++
+ serial[19] = '\0';
+ set_string(&p15card->tokeninfo->serial_number, serial);
+
+
+From 230a783a0476ef1b387818ba5dd9c1c73978744f Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Wed, 17 Jul 2024 12:53:52 +0200
+Subject: [PATCH 20/30] pkcs15-tcos: Check certificate length before accessing
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs15_encode/8
+---
+ src/libopensc/pkcs15-tcos.c | 35 +++++++++++++++++++++--------------
+ 1 file changed, 21 insertions(+), 14 deletions(-)
+
+diff --git a/src/libopensc/pkcs15-tcos.c b/src/libopensc/pkcs15-tcos.c
+index 2bd275c4f4..ecaa66edf2 100644
+--- a/src/libopensc/pkcs15-tcos.c
++++ b/src/libopensc/pkcs15-tcos.c
+@@ -45,6 +45,7 @@ static int insert_cert(
+ struct sc_pkcs15_cert_info cert_info;
+ struct sc_pkcs15_object cert_obj;
+ unsigned char cert[20];
++ size_t cert_len = 0;
+ int r;
+
+ memset(&cert_info, 0, sizeof(cert_info));
+@@ -57,25 +58,31 @@ static int insert_cert(
+ strlcpy(cert_obj.label, label, sizeof(cert_obj.label));
+ cert_obj.flags = writable ? SC_PKCS15_CO_FLAG_MODIFIABLE : 0;
+
+- if(sc_select_file(card, &cert_info.path, NULL)!=SC_SUCCESS){
+- sc_log(ctx,
+- "Select(%s) failed\n", path);
++ if (sc_select_file(card, &cert_info.path, NULL) != SC_SUCCESS) {
++ sc_log(ctx, "Select(%s) failed", path);
+ return 1;
+ }
+ r = sc_read_binary(card, 0, cert, sizeof(cert), 0);
+- if (r <= 0){
+- sc_log(ctx,
+- "ReadBinary(%s) failed\n", path);
++ if (r <= 0) {
++ sc_log(ctx, "ReadBinary(%s) failed\n", path);
+ return 2;
+ }
+- if(cert[0]!=0x30 || cert[1]!=0x82){
+- sc_log(ctx,
+- "Invalid Cert: %02X:%02X:...\n", cert[0], cert[1]);
++ cert_len = r; /* actual number of read bytes */
++ if (cert_len < 7 || (size_t)(7 + cert[5]) > cert_len) {
++ sc_log(ctx, "Invalid certificate length");
++ return 3;
++ }
++ if (cert[0] != 0x30 || cert[1] != 0x82) {
++ sc_log(ctx, "Invalid Cert: %02X:%02X:...\n", cert[0], cert[1]);
+ return 3;
+ }
+
+ /* some certificates are prefixed by an OID */
+- if(cert[4]==0x06 && cert[5]<10 && cert[6+cert[5]]==0x30 && cert[7+cert[5]]==0x82){
++ if (cert[4] == 0x06 && cert[5] < 10 && cert[6 + cert[5]] == 0x30 && cert[7 + cert[5]] == 0x82) {
++ if ((size_t)(9 + cert[5]) > cert_len) {
++ sc_log(ctx, "Invalid certificate length");
++ return 3;
++ }
+ cert_info.path.index=6+cert[5];
+ cert_info.path.count=(cert[8+cert[5]]<<8) + cert[9+cert[5]] + 4;
+ } else {
+@@ -83,12 +90,12 @@ static int insert_cert(
+ cert_info.path.count=(cert[2]<<8) + cert[3] + 4;
+ }
+
+- r=sc_pkcs15emu_add_x509_cert(p15card, &cert_obj, &cert_info);
+- if(r!=SC_SUCCESS){
+- sc_log(ctx, "sc_pkcs15emu_add_x509_cert(%s) failed\n", path);
++ r = sc_pkcs15emu_add_x509_cert(p15card, &cert_obj, &cert_info);
++ if (r != SC_SUCCESS) {
++ sc_log(ctx, "sc_pkcs15emu_add_x509_cert(%s) failed", path);
+ return 4;
+ }
+- sc_log(ctx, "%s: OK, Index=%d, Count=%d\n", path, cert_info.path.index, cert_info.path.count);
++ sc_log(ctx, "%s: OK, Index=%d, Count=%d", path, cert_info.path.index, cert_info.path.count);
+ return 0;
+ }
+
+
+From afb1bba4f1966a5b78fdba44b6e7c4dd115cfb29 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Wed, 17 Jul 2024 14:56:22 +0200
+Subject: [PATCH 21/30] pkcs15-lib: Report transport key error
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs15init/17, fuzz_pkcs15init/18
+---
+ src/pkcs15init/pkcs15-lib.c | 6 ++++--
+ 1 file changed, 4 insertions(+), 2 deletions(-)
+
+diff --git a/src/pkcs15init/pkcs15-lib.c b/src/pkcs15init/pkcs15-lib.c
+index 6574e8025d..943d53e987 100644
+--- a/src/pkcs15init/pkcs15-lib.c
++++ b/src/pkcs15init/pkcs15-lib.c
+@@ -3831,13 +3831,15 @@ sc_pkcs15init_get_transport_key(struct sc_profile *profile, struct sc_pkcs15_car
+ if (callbacks.get_key) {
+ rv = callbacks.get_key(profile, type, reference, defbuf, defsize, pinbuf, pinsize);
+ LOG_TEST_RET(ctx, rv, "Cannot get key");
+- }
+- else if (rv >= 0) {
++ } else if (rv >= 0) {
+ if (*pinsize < defsize)
+ LOG_TEST_RET(ctx, SC_ERROR_BUFFER_TOO_SMALL, "Get transport key error");
+
+ memcpy(pinbuf, data.key_data, data.len);
+ *pinsize = data.len;
++ } else {
++ /* pinbuf and pinsize were not filled */
++ LOG_TEST_RET(ctx, SC_ERROR_INTERNAL, "Get transport key error");
+ }
+
+ memset(&auth_info, 0, sizeof(auth_info));
+
+From 60f08c6fca2f87f30480589d00922599c8189555 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Thu, 18 Jul 2024 09:23:20 +0200
+Subject: [PATCH 22/30] pkcs15-starcos: Check length of file to be non-zero
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs15init/20
+---
+ src/pkcs15init/pkcs15-starcos.c | 4 +++-
+ 1 file changed, 3 insertions(+), 1 deletion(-)
+
+diff --git a/src/pkcs15init/pkcs15-starcos.c b/src/pkcs15init/pkcs15-starcos.c
+index bde7413a46..267ad2b04a 100644
+--- a/src/pkcs15init/pkcs15-starcos.c
++++ b/src/pkcs15init/pkcs15-starcos.c
+@@ -670,6 +670,8 @@ static int starcos_write_pukey(sc_profile_t *profile, sc_card_t *card,
+ return r;
+ len = tfile->size;
+ sc_file_free(tfile);
++ if (len == 0)
++ return SC_ERROR_INTERNAL;
+ buf = malloc(len);
+ if (!buf)
+ return SC_ERROR_OUT_OF_MEMORY;
+@@ -684,7 +686,7 @@ static int starcos_write_pukey(sc_profile_t *profile, sc_card_t *card,
+ if (num_keys == 0xff)
+ num_keys = 0;
+ /* encode public key */
+- keylen = starcos_encode_pukey(rsa, NULL, kinfo);
++ keylen = starcos_encode_pukey(rsa, NULL, kinfo);
+ if (!keylen) {
+ free(buf);
+ return SC_ERROR_INTERNAL;
+
+From 513d3fdeed6b07f05c8d3bf9532d0b54dcbc3488 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Thu, 18 Jul 2024 09:35:23 +0200
+Subject: [PATCH 23/30] iasecc-sdo: Check length of data before dereferencing
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs15init/21
+---
+ src/libopensc/iasecc-sdo.c | 3 +++
+ 1 file changed, 3 insertions(+)
+
+diff --git a/src/libopensc/iasecc-sdo.c b/src/libopensc/iasecc-sdo.c
+index 417b6dd57d..98402a4e3f 100644
+--- a/src/libopensc/iasecc-sdo.c
++++ b/src/libopensc/iasecc-sdo.c
+@@ -760,6 +760,9 @@ iasecc_sdo_parse(struct sc_card *card, unsigned char *data, size_t data_len, str
+
+ LOG_FUNC_CALLED(ctx);
+
++ if (data == NULL || data_len < 2)
++ LOG_FUNC_RETURN(ctx, SC_ERROR_INVALID_DATA);
++
+ if (*data == IASECC_SDO_TEMPLATE_TAG) {
+ size_size = iasecc_parse_size(data + 1, data_len - 1, &size);
+ LOG_TEST_RET(ctx, size_size, "parse error: invalid size data of IASECC_SDO_TEMPLATE");
+
+From b1cdaf4b820d6ba6e3f42acd289ef3e6540bb9f3 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Thu, 18 Jul 2024 15:39:15 +0200
+Subject: [PATCH 24/30] card-oberthur: Check length of serial number
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs11/1, fuzz_pkcs15init/2
+---
+ src/libopensc/card-oberthur.c | 5 ++++-
+ 1 file changed, 4 insertions(+), 1 deletion(-)
+
+diff --git a/src/libopensc/card-oberthur.c b/src/libopensc/card-oberthur.c
+index f344d5901f..5920c2c417 100644
+--- a/src/libopensc/card-oberthur.c
++++ b/src/libopensc/card-oberthur.c
+@@ -145,7 +145,7 @@ auth_select_aid(struct sc_card *card)
+ {
+ struct sc_apdu apdu;
+ unsigned char apdu_resp[SC_MAX_APDU_BUFFER_SIZE];
+- struct auth_private_data *data = (struct auth_private_data *) card->drv_data;
++ struct auth_private_data *data = (struct auth_private_data *)card->drv_data;
+ int rv, ii;
+ struct sc_path tmp_path;
+
+@@ -162,6 +162,9 @@ auth_select_aid(struct sc_card *card)
+
+ rv = sc_transmit_apdu(card, &apdu);
+ LOG_TEST_RET(card->ctx, rv, "APDU transmit failed");
++ if (apdu.resplen < 20) {
++ LOG_TEST_RET(card->ctx, SC_ERROR_UNKNOWN_DATA_RECEIVED, "Serial number has incorrect length");
++ }
+ card->serialnr.len = 4;
+ memcpy(card->serialnr.value, apdu.resp+15, 4);
+
+
+From 67064f41b5dd0947a7fcbc78b7c46d35439c6458 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Thu, 18 Jul 2024 10:16:39 +0200
+Subject: [PATCH 25/30] pkcs15-setcos: Check length of generated key
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs15init/26
+---
+ src/pkcs15init/pkcs15-setcos.c | 5 ++++-
+ 1 file changed, 4 insertions(+), 1 deletion(-)
+
+diff --git a/src/pkcs15init/pkcs15-setcos.c b/src/pkcs15init/pkcs15-setcos.c
+index a445513901..6525541f5a 100644
+--- a/src/pkcs15init/pkcs15-setcos.c
++++ b/src/pkcs15init/pkcs15-setcos.c
+@@ -507,6 +507,9 @@ setcos_generate_key(struct sc_profile *profile, struct sc_pkcs15_card *p15card,
+ r = sc_card_ctl(p15card->card, SC_CARDCTL_SETCOS_GETDATA, &data_obj);
+ LOG_TEST_RET(ctx, r, "Cannot get key modulus: 'SETCOS_GETDATA' failed");
+
++ if (data_obj.DataLen < 3 || data_obj.DataLen < pubkey->u.rsa.modulus.len)
++ LOG_TEST_RET(ctx, SC_ERROR_UNKNOWN_DATA_RECEIVED, "Cannot get key modulus: wrong length of raw key");
++
+ keybits = ((raw_pubkey[0] * 256) + raw_pubkey[1]); /* modulus bit length */
+ if (keybits != key_info->modulus_length) {
+ sc_log(ctx,
+@@ -514,7 +517,7 @@ setcos_generate_key(struct sc_profile *profile, struct sc_pkcs15_card *p15card,
+ keybits, key_info->modulus_length);
+ LOG_TEST_RET(ctx, SC_ERROR_PKCS15INIT, "Failed to generate key");
+ }
+- memcpy (pubkey->u.rsa.modulus.data, &raw_pubkey[2], pubkey->u.rsa.modulus.len);
++ memcpy(pubkey->u.rsa.modulus.data, &raw_pubkey[2], pubkey->u.rsa.modulus.len);
+ } else {
+ sc_file_free(file);
+ }
+
+From c911e5fca9184b16f94669ca0fa5227aaf0b590e Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Thu, 18 Jul 2024 11:03:46 +0200
+Subject: [PATCH 26/30] iasecc-sdo: Check length of data when parsing
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs15init/27,29
+---
+ src/libopensc/iasecc-sdo.c | 9 +++++++++
+ 1 file changed, 9 insertions(+)
+
+diff --git a/src/libopensc/iasecc-sdo.c b/src/libopensc/iasecc-sdo.c
+index 98402a4e3f..dbd5b9f08c 100644
+--- a/src/libopensc/iasecc-sdo.c
++++ b/src/libopensc/iasecc-sdo.c
+@@ -318,16 +318,25 @@ iasecc_se_parse(struct sc_card *card, unsigned char *data, size_t data_len, stru
+
+ LOG_FUNC_CALLED(ctx);
+
++ if (data_len < 1)
++ LOG_FUNC_RETURN(ctx, SC_ERROR_INVALID_DATA);
++
+ if (*data == IASECC_SDO_TEMPLATE_TAG) {
+ size_size = iasecc_parse_size(data + 1, data_len - 1, &size);
+ LOG_TEST_RET(ctx, size_size, "parse error: invalid size data of IASECC_SDO_TEMPLATE");
+
++ if (data_len - 1 < size)
++ LOG_FUNC_RETURN(ctx, SC_ERROR_INVALID_DATA);
++
+ data += size_size + 1;
+ data_len = size;
+ sc_log(ctx,
+ "IASECC_SDO_TEMPLATE: size %"SC_FORMAT_LEN_SIZE_T"u, size_size %d",
+ size, size_size);
+
++ if (data_len < 3)
++ LOG_FUNC_RETURN(ctx, SC_ERROR_INVALID_DATA);
++
+ if (*data != IASECC_SDO_TAG_HEADER)
+ LOG_FUNC_RETURN(ctx, SC_ERROR_INVALID_DATA);
+
+
+From 755448b802a3631724eaf9a3cdece327afd127b7 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Thu, 18 Jul 2024 11:38:25 +0200
+Subject: [PATCH 27/30] pkcs15-sc-hsm: Properly check length of file list
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs15init/8
+---
+ src/pkcs15init/pkcs15-sc-hsm.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/pkcs15init/pkcs15-sc-hsm.c b/src/pkcs15init/pkcs15-sc-hsm.c
+index 71f96cfc56..db1a2b518f 100644
+--- a/src/pkcs15init/pkcs15-sc-hsm.c
++++ b/src/pkcs15init/pkcs15-sc-hsm.c
+@@ -140,7 +140,7 @@ static int sc_hsm_determine_free_id(struct sc_pkcs15_card *p15card, u8 range)
+ LOG_TEST_RET(card->ctx, filelistlength, "Could not enumerate file and key identifier");
+
+ for (j = 0; j < 256; j++) {
+- for (i = 0; i < filelistlength; i += 2) {
++ for (i = 0; i + 1 < filelistlength; i += 2) {
+ if ((filelist[i] == range) && (filelist[i + 1] == j)) {
+ break;
+ }
+
+From 9c8c25a82e1ef4b26a1828e430f6efe07f002b8c Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Thu, 18 Jul 2024 12:33:31 +0200
+Subject: [PATCH 28/30] card-coolkey: Check length of buffer before conversion
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs15_reader/3
+---
+ src/libopensc/card-coolkey.c | 11 ++++++++---
+ 1 file changed, 8 insertions(+), 3 deletions(-)
+
+diff --git a/src/libopensc/card-coolkey.c b/src/libopensc/card-coolkey.c
+index 9192aac092..5d547bc960 100644
+--- a/src/libopensc/card-coolkey.c
++++ b/src/libopensc/card-coolkey.c
+@@ -1688,6 +1688,7 @@ static int coolkey_rsa_op(sc_card_t *card, const u8 * data, size_t datalen,
+ u8 key_number;
+ size_t params_len;
+ u8 buf[MAX_COMPUTE_BUF + 2];
++ size_t buf_len;
+ u8 *buf_out;
+
+ SC_FUNC_CALLED(card->ctx, SC_LOG_DEBUG_VERBOSE);
+@@ -1728,8 +1729,6 @@ static int coolkey_rsa_op(sc_card_t *card, const u8 * data, size_t datalen,
+ ushort2bebytes(params.init.buf_len, 0);
+ } else {
+ /* The data fits in APDU. Copy it to the params object */
+- size_t buf_len;
+-
+ params.init.location = COOLKEY_CRYPT_LOCATION_APDU;
+
+ params_len = sizeof(params.init) + datalen;
+@@ -1749,6 +1748,7 @@ static int coolkey_rsa_op(sc_card_t *card, const u8 * data, size_t datalen,
+ if (r < 0) {
+ goto done;
+ }
++ buf_len = crypt_out_len_p;
+
+ if (datalen > MAX_COMPUTE_BUF) {
+ u8 len_buf[2];
+@@ -1767,7 +1767,12 @@ static int coolkey_rsa_op(sc_card_t *card, const u8 * data, size_t datalen,
+ priv->nonce, sizeof(priv->nonce));
+
+ } else {
+- size_t out_length = bebytes2ushort(buf);
++ size_t out_length;
++ if (buf_len < 2) {
++ r = SC_ERROR_WRONG_LENGTH;
++ goto done;
++ }
++ out_length = bebytes2ushort(buf);
+ if (out_length > sizeof buf - 2) {
+ r = SC_ERROR_WRONG_LENGTH;
+ goto done;
+
+From b6754eb3b279505c6d4f09cfa1c77dcad9420468 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Tue, 23 Jul 2024 10:48:32 +0200
+Subject: [PATCH 29/30] card-entersafe: Check length of serial number
+
+Thanks Matteo Marini for report
+https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
+
+fuzz_pkcs15_reader/5
+---
+ src/libopensc/card-entersafe.c | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/src/libopensc/card-entersafe.c b/src/libopensc/card-entersafe.c
+index 5f6d8a424d..025ebedc91 100644
+--- a/src/libopensc/card-entersafe.c
++++ b/src/libopensc/card-entersafe.c
+@@ -1479,6 +1479,8 @@ static int entersafe_get_serialnr(sc_car
+ r=entersafe_transmit_apdu(card, &apdu,0,0,0,0);
+ LOG_TEST_RET(card->ctx, r, "APDU transmit failed");
+ LOG_TEST_RET(card->ctx, sc_check_sw(card,apdu.sw1,apdu.sw2),"EnterSafe get SN failed");
++ if (apdu.resplen != 8)
++ LOG_TEST_RET(card->ctx, SC_ERROR_UNKNOWN_DATA_RECEIVED, "Invalid length of SN");
+
+ card->serialnr.len=serial->len=8;
+ memcpy(card->serialnr.value,rbuf,8);
+
+From ab476044a009003262991c065b792baa053c7be5 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
+Date: Thu, 1 Aug 2024 10:32:40 +0200
+Subject: [PATCH 30/30] card-cardos: Check length of APDU response
+
+---
+ src/libopensc/card-cardos.c | 8 ++++----
+ 1 file changed, 4 insertions(+), 4 deletions(-)
+
+diff --git a/src/libopensc/card-cardos.c b/src/libopensc/card-cardos.c
+index 124752d78b..595ec099e3 100644
+--- a/src/libopensc/card-cardos.c
++++ b/src/libopensc/card-cardos.c
+@@ -94,7 +94,7 @@ static void fixup_transceive_length(const struct sc_card *card,
+
+ static int cardos_match_card(sc_card_t *card)
+ {
+- unsigned char atr[SC_MAX_ATR_SIZE] = { 0 };
++ unsigned char atr[SC_MAX_ATR_SIZE] = {0};
+ int i;
+
+ i = _sc_match_atr(card, cardos_atrs, &card->type);
+@@ -114,8 +114,8 @@ static int cardos_match_card(sc_card_t *card)
+ return 1;
+ if (card->type == SC_CARD_TYPE_CARDOS_M4_2) {
+ int rv;
+- sc_apdu_t apdu = { 0 };
+- u8 rbuf[SC_MAX_APDU_BUFFER_SIZE] = { 0 };
++ sc_apdu_t apdu = {0};
++ u8 rbuf[SC_MAX_APDU_BUFFER_SIZE] = {0};
+ /* first check some additional ATR bytes */
+ if ((atr[4] != 0xff && atr[4] != 0x02) ||
+ (atr[6] != 0x10 && atr[6] != 0x0a) ||
+@@ -131,7 +131,7 @@ static int cardos_match_card(sc_card_t *card)
+ apdu.lc = 0;
+ rv = sc_transmit_apdu(card, &apdu);
+ LOG_TEST_RET(card->ctx, rv, "APDU transmit failed");
+- if (apdu.sw1 != 0x90 || apdu.sw2 != 0x00)
++ if (apdu.sw1 != 0x90 || apdu.sw2 != 0x00 || apdu.resplen < 2)
+ return 0;
+ if (apdu.resp[0] != atr[10] ||
+ apdu.resp[1] != atr[11])
diff --git a/meta-openembedded/meta-oe/recipes-support/opensc/files/CVE-2024-8443-0001.patch b/meta-openembedded/meta-oe/recipes-support/opensc/files/CVE-2024-8443-0001.patch
new file mode 100644
index 0000000000..7d80aba769
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/opensc/files/CVE-2024-8443-0001.patch
@@ -0,0 +1,60 @@
+From b28a3cef416fcfb92fbb9ea7fd3c71df52c6c9fc Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Mon, 12 Aug 2024 19:02:14 +0200
+Subject: [PATCH] openpgp: Do not accept non-matching key responses
+
+When generating RSA key pair using PKCS#15 init, the driver could accept
+responses relevant to ECC keys, which made further processing in the
+pkcs15-init failing/accessing invalid parts of structures.
+
+Thanks oss-fuzz!
+
+https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=71010
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+
+CVE: CVE-2024-8443
+Upstream-Status: Backport [https://github.com/OpenSC/OpenSC/commit/b28a3cef416fcfb92fbb9ea7fd3c71df52c6c9fc]
+
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ src/libopensc/card-openpgp.c | 10 ++++++++++
+ 1 file changed, 10 insertions(+)
+
+diff --git a/src/libopensc/card-openpgp.c b/src/libopensc/card-openpgp.c
+index fad32f0ce..f99ec0db9 100644
+--- a/src/libopensc/card-openpgp.c
++++ b/src/libopensc/card-openpgp.c
+@@ -2877,6 +2877,9 @@ pgp_parse_and_set_pubkey_output(sc_card_t *card, u8* data, size_t data_len,
+
+ /* RSA modulus */
+ if (tag == 0x0081) {
++ if (key_info->algorithm != SC_OPENPGP_KEYALGO_RSA) {
++ LOG_FUNC_RETURN(card->ctx, SC_ERROR_UNKNOWN_DATA_RECEIVED);
++ }
+ if ((BYTES4BITS(key_info->u.rsa.modulus_len) < len) /* modulus_len is in bits */
+ || key_info->u.rsa.modulus == NULL) {
+
+@@ -2892,6 +2895,9 @@ pgp_parse_and_set_pubkey_output(sc_card_t *card, u8* data, size_t data_len,
+ }
+ /* RSA public exponent */
+ else if (tag == 0x0082) {
++ if (key_info->algorithm != SC_OPENPGP_KEYALGO_RSA) {
++ LOG_FUNC_RETURN(card->ctx, SC_ERROR_UNKNOWN_DATA_RECEIVED);
++ }
+ if ((BYTES4BITS(key_info->u.rsa.exponent_len) < len) /* exponent_len is in bits */
+ || key_info->u.rsa.exponent == NULL) {
+
+@@ -2907,6 +2913,10 @@ pgp_parse_and_set_pubkey_output(sc_card_t *card, u8* data, size_t data_len,
+ }
+ /* ECC public key */
+ else if (tag == 0x0086) {
++ if (key_info->algorithm != SC_OPENPGP_KEYALGO_ECDSA &&
++ key_info->algorithm != SC_OPENPGP_KEYALGO_ECDH) {
++ LOG_FUNC_RETURN(card->ctx, SC_ERROR_UNKNOWN_DATA_RECEIVED);
++ }
+ /* set the output data */
+ /* len is ecpoint length + format byte
+ * see section 7.2.14 of 3.3.1 specs */
+--
+2.34.1
diff --git a/meta-openembedded/meta-oe/recipes-support/opensc/files/CVE-2024-8443-0002.patch b/meta-openembedded/meta-oe/recipes-support/opensc/files/CVE-2024-8443-0002.patch
new file mode 100644
index 0000000000..30a7e63a72
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/opensc/files/CVE-2024-8443-0002.patch
@@ -0,0 +1,55 @@
+From 02e847458369c08421fd2d5e9a16a5f272c2de9e Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Thu, 15 Aug 2024 11:13:47 +0200
+Subject: [PATCH] openpgp: Avoid buffer overflow when writing fingerprint
+
+Fix also surrounding code to return error (not just log it)
+when some step fails.
+
+Thanks oss-fuzz
+
+https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=70933
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+
+CVE: CVE-2024-8443
+Upstream-Status: Backport [https://github.com/OpenSC/OpenSC/commit/02e847458369c08421fd2d5e9a16a5f272c2de9e]
+
+Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
+---
+ src/libopensc/card-openpgp.c | 17 ++++++++++++-----
+ 1 file changed, 12 insertions(+), 5 deletions(-)
+
+diff --git a/src/libopensc/card-openpgp.c b/src/libopensc/card-openpgp.c
+index f99ec0db9..3957440de 100644
+--- a/src/libopensc/card-openpgp.c
++++ b/src/libopensc/card-openpgp.c
+@@ -2756,14 +2756,21 @@ pgp_calculate_and_store_fingerprint(sc_card_t *card, time_t ctime,
+ /* update the blob containing fingerprints (00C5) */
+ sc_log(card->ctx, "Updating fingerprint blob 00C5.");
+ fpseq_blob = pgp_find_blob(card, 0x00C5);
+- if (fpseq_blob == NULL)
+- LOG_TEST_GOTO_ERR(card->ctx, SC_ERROR_OUT_OF_MEMORY, "Cannot find blob 00C5");
++ if (fpseq_blob == NULL) {
++ r = SC_ERROR_OUT_OF_MEMORY;
++ LOG_TEST_GOTO_ERR(card->ctx, r, "Cannot find blob 00C5");
++ }
++ if (20 * key_info->key_id > fpseq_blob->len) {
++ r = SC_ERROR_OBJECT_NOT_VALID;
++ LOG_TEST_GOTO_ERR(card->ctx, r, "The 00C5 blob is not large enough");
++ }
+
+ /* save the fingerprints sequence */
+ newdata = malloc(fpseq_blob->len);
+- if (newdata == NULL)
+- LOG_TEST_GOTO_ERR(card->ctx, SC_ERROR_OUT_OF_MEMORY,
+- "Not enough memory to update fingerprint blob 00C5");
++ if (newdata == NULL) {
++ r = SC_ERROR_OUT_OF_MEMORY;
++ LOG_TEST_GOTO_ERR(card->ctx, r, "Not enough memory to update fingerprint blob 00C5");
++ }
+
+ memcpy(newdata, fpseq_blob->data, fpseq_blob->len);
+ /* move p to the portion holding the fingerprint of the current key */
+--
+2.34.1
diff --git a/meta-openembedded/meta-oe/recipes-support/opensc/opensc_0.25.1.bb b/meta-openembedded/meta-oe/recipes-support/opensc/opensc_0.25.1.bb
index 19fb78092e..e41c457fa8 100644
--- a/meta-openembedded/meta-oe/recipes-support/opensc/opensc_0.25.1.bb
+++ b/meta-openembedded/meta-oe/recipes-support/opensc/opensc_0.25.1.bb
@@ -13,7 +13,11 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=cb8aedd3bced19bd8026d96a8b6876d7"
#v0.21.0
SRCREV = "0a4b772d6fdab9bfaaa3123775a48a7cb6c5e7c6"
-SRC_URI = "git://github.com/OpenSC/OpenSC;branch=stable-0.25;protocol=https"
+SRC_URI = "git://github.com/OpenSC/OpenSC;branch=stable-0.25;protocol=https \
+ file://0001-PR-Fixes-for-uninitialized-memory-issues.patch \
+ file://CVE-2024-8443-0001.patch \
+ file://CVE-2024-8443-0002.patch \
+ "
DEPENDS = "virtual/libiconv openssl"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-oe/recipes-support/poco/poco/0001-cppignore.lnx-Ignore-PKCS12-and-testLaunch-test.patch b/meta-openembedded/meta-oe/recipes-support/poco/poco/0001-cppignore.lnx-Ignore-PKCS12-and-testLaunch-test.patch
index f70e8bcc74..5e588429fe 100644
--- a/meta-openembedded/meta-oe/recipes-support/poco/poco/0001-cppignore.lnx-Ignore-PKCS12-and-testLaunch-test.patch
+++ b/meta-openembedded/meta-oe/recipes-support/poco/poco/0001-cppignore.lnx-Ignore-PKCS12-and-testLaunch-test.patch
@@ -40,18 +40,31 @@ There were 4 failures:
Not found: POCO_BASE"
│ │ in "<unknown>", line -1
+There was 1 error:
+ 1: CppUnit::TestCaller<CryptoTest>.testEncryptDecryptGCM
+ "Poco::IOException:
+I/O error: error:1C800066:Provider routines::cipher operation failed"
+ in "<unknown>", line -1
+
+There was 1 error:
+ 1: CppUnit::TestCaller<HTTPSClientSessionTest>.testInterop
+ "Poco::Net::DNSException:
+DNS error: Temporary DNS error while resolving: secure.appinf.com"
+ in "<unknown>", line -1
+
Upstream-Status: Inappropriate [OE specific]
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Signed-off-by: Patrick Wicki <patrick.wicki@siemens.com>
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
---
- cppignore.lnx | 9 +++++++++
- 1 file changed, 9 insertions(+)
+ cppignore.lnx | 11 +++++++++++
+ 1 file changed, 11 insertions(+)
diff --git a/cppignore.lnx b/cppignore.lnx
index 2c2376526..65df4af08 100644
--- a/cppignore.lnx
+++ b/cppignore.lnx
-@@ -28,3 +28,12 @@ CppUnit::TestCaller<HTTPSClientSessionTest>.testProxy
+@@ -28,3 +28,14 @@ CppUnit::TestCaller<HTTPSClientSessionTest>.testProxy
CppUnit::TestCaller<HTTPSStreamFactoryTest>.testProxy
CppUnit::TestCaller<DNSTest>.testHostByAddress
CppUnit::TestCaller<DNSTest>.testHostByName
@@ -64,3 +77,5 @@ index 2c2376526..65df4af08 100644
+CppUnit::TestCaller<PKCS12ContainerTest>.testCertsOnlyPKCS12
+CppUnit::TestCaller<PKCS12ContainerTest>.testPEMReadWrite
+CppUnit::TestCaller<MongoDBTest>.testArray
++CppUnit::TestCaller<CryptoTest>.testEncryptDecryptGCM
++CppUnit::TestCaller<HTTPSClientSessionTest>.testInterop
diff --git a/meta-openembedded/meta-oe/recipes-support/poco/poco/CVE-2025-6375.patch b/meta-openembedded/meta-oe/recipes-support/poco/poco/CVE-2025-6375.patch
new file mode 100644
index 0000000000..2ec8f819f9
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/poco/poco/CVE-2025-6375.patch
@@ -0,0 +1,34 @@
+From 6f2f85913c191ab9ddfb8fae781f5d66afccf3bf Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?G=C3=BCnter=20Obiltschnig?= <guenter.obiltschnig@appinf.com>
+Date: Wed, 16 Apr 2025 09:15:33 +0200
+Subject: [PATCH] fix(Net): A SEGV at Net/src/MultipartReader.cpp:164:1 #4915
+ (move assertion out of ctor)
+
+CVE: CVE-2025-6375
+Upstream-Status: Backport [https://github.com/pocoproject/poco/commit/6f2f85913c191ab9ddfb8fae781f5d66afccf3bf]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ Net/src/MultipartReader.cpp | 3 +--
+ 1 file changed, 1 insertion(+), 2 deletions(-)
+
+diff --git a/Net/src/MultipartReader.cpp b/Net/src/MultipartReader.cpp
+index f3a2f2bba..f4aa27dd8 100644
+--- a/Net/src/MultipartReader.cpp
++++ b/Net/src/MultipartReader.cpp
+@@ -36,7 +36,6 @@ MultipartStreamBuf::MultipartStreamBuf(std::istream& istr, const std::string& bo
+ _boundary(boundary),
+ _lastPart(false)
+ {
+- poco_assert (!boundary.empty() && boundary.length() < STREAM_BUFFER_SIZE - 6);
+ }
+
+
+@@ -47,7 +46,7 @@ MultipartStreamBuf::~MultipartStreamBuf()
+
+ int MultipartStreamBuf::readFromDevice(char* buffer, std::streamsize length)
+ {
+- poco_assert_dbg (length >= _boundary.length() + 6);
++ poco_assert (!_boundary.empty() && _boundary.length() < length - 6);
+
+ static const int eof = std::char_traits<char>::eof();
+ std::streambuf& buf = *_istr.rdbuf();
diff --git a/meta-openembedded/meta-oe/recipes-support/poco/poco_1.12.5p2.bb b/meta-openembedded/meta-oe/recipes-support/poco/poco_1.12.5p2.bb
index a0bb0b5d96..86e0adf522 100644
--- a/meta-openembedded/meta-oe/recipes-support/poco/poco_1.12.5p2.bb
+++ b/meta-openembedded/meta-oe/recipes-support/poco/poco_1.12.5p2.bb
@@ -8,11 +8,12 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=4267f48fc738f50380cbeeb76f95cebc"
# These dependencies are required by Foundation
DEPENDS = "libpcre2 zlib"
-SRC_URI = "git://github.com/pocoproject/poco.git;branch=master;protocol=https \
+SRC_URI = "git://github.com/pocoproject/poco.git;branch=poco-1.12.5;protocol=https \
file://0001-Use-std-atomic-int-instead-of-std-atomic-bool.patch \
file://0001-cppignore.lnx-Ignore-PKCS12-and-testLaunch-test.patch \
file://run-ptest \
file://0002-fix-build-Install-cmake-files-with-resolved-ENABLE_J.patch \
+ file://CVE-2025-6375.patch \
"
SRCREV = "1d6fb3e1383e559cacbada5e3f861c0dafaf5d30"
diff --git a/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2024-56378.patch b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2024-56378.patch
new file mode 100644
index 0000000000..f94b8fed1f
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2024-56378.patch
@@ -0,0 +1,77 @@
+From ade9b5ebed44b0c15522c27669ef6cdf93eff84e Mon Sep 17 00:00:00 2001
+From: Albert Astals Cid <aacid@kde.org>
+Date: Tue, 17 Dec 2024 18:59:01 +0100
+Subject: [PATCH] JBIG2Bitmap::combine: Fix crash on malformed files
+
+Fixes #1553
+
+CVE: CVE-2024-56378
+Upstream-Status: Backport [https://gitlab.freedesktop.org/poppler/poppler/-/commit/ade9b5ebed44b0c15522c27669ef6cdf93eff84e]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ poppler/JBIG2Stream.cc | 15 +++++++++------
+ 1 file changed, 9 insertions(+), 6 deletions(-)
+
+diff --git a/poppler/JBIG2Stream.cc b/poppler/JBIG2Stream.cc
+index 77ffeb2..bdc51d0 100644
+--- a/poppler/JBIG2Stream.cc
++++ b/poppler/JBIG2Stream.cc
+@@ -765,7 +765,7 @@ void JBIG2Bitmap::duplicateRow(int yDest, int ySrc)
+
+ void JBIG2Bitmap::combine(JBIG2Bitmap *bitmap, int x, int y, unsigned int combOp)
+ {
+- int x0, x1, y0, y1, xx, yy;
++ int x0, x1, y0, y1, xx, yy, yyy;
+ unsigned char *srcPtr, *destPtr;
+ unsigned int src0, src1, src, dest, s1, s2, m1, m2, m3;
+ bool oneByte;
+@@ -812,14 +812,17 @@ void JBIG2Bitmap::combine(JBIG2Bitmap *bitmap, int x, int y, unsigned int combOp
+ oneByte = x0 == ((x1 - 1) & ~7);
+
+ for (yy = y0; yy < y1; ++yy) {
+- if (unlikely((y + yy >= h) || (y + yy < 0))) {
++ if (unlikely(checkedAdd(y, yy, &yyy))) {
++ continue;
++ }
++ if (unlikely((yyy >= h) || (yyy < 0))) {
+ continue;
+ }
+
+ // one byte per line -- need to mask both left and right side
+ if (oneByte) {
+ if (x >= 0) {
+- destPtr = data + (y + yy) * line + (x >> 3);
++ destPtr = data + yyy * line + (x >> 3);
+ srcPtr = bitmap->data + yy * bitmap->line;
+ dest = *destPtr;
+ src1 = *srcPtr;
+@@ -842,7 +845,7 @@ void JBIG2Bitmap::combine(JBIG2Bitmap *bitmap, int x, int y, unsigned int combOp
+ }
+ *destPtr = dest;
+ } else {
+- destPtr = data + (y + yy) * line;
++ destPtr = data + yyy * line;
+ srcPtr = bitmap->data + yy * bitmap->line + (-x >> 3);
+ dest = *destPtr;
+ src1 = *srcPtr;
+@@ -872,7 +875,7 @@ void JBIG2Bitmap::combine(JBIG2Bitmap *bitmap, int x, int y, unsigned int combOp
+
+ // left-most byte
+ if (x >= 0) {
+- destPtr = data + (y + yy) * line + (x >> 3);
++ destPtr = data + yyy * line + (x >> 3);
+ srcPtr = bitmap->data + yy * bitmap->line;
+ src1 = *srcPtr++;
+ dest = *destPtr;
+@@ -896,7 +899,7 @@ void JBIG2Bitmap::combine(JBIG2Bitmap *bitmap, int x, int y, unsigned int combOp
+ *destPtr++ = dest;
+ xx = x0 + 8;
+ } else {
+- destPtr = data + (y + yy) * line;
++ destPtr = data + yyy * line;
+ srcPtr = bitmap->data + yy * bitmap->line + (-x >> 3);
+ src1 = *srcPtr++;
+ xx = x0;
+--
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2024-6239-0001.patch b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2024-6239-0001.patch
new file mode 100644
index 0000000000..9994ce785b
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2024-6239-0001.patch
@@ -0,0 +1,1275 @@
+From fc1c711cb5f769546c6b31cc688bf0ee7f0c1dbc Mon Sep 17 00:00:00 2001
+From: Sune Vuorela <sune@vuorela.dk>
+Date: Thu, 1 Feb 2024 19:11:03 +0000
+Subject: [PATCH] More unicode vectors; fewer raw pointers
+
+CVE: CVE-2024-6239
+Upstream-Status: Backport [https://gitlab.freedesktop.org/poppler/poppler/-/commit/fc1c711cb5f769546c6b31cc688bf0ee7f0c1dbc]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ cpp/poppler-toc.cpp | 5 +-
+ glib/poppler-document.cc | 3 +-
+ poppler/CharCodeToUnicode.cc | 113 +++++++++------------------
+ poppler/CharCodeToUnicode.h | 12 ++-
+ poppler/DateInfo.cc | 10 +--
+ poppler/JSInfo.cc | 9 +--
+ poppler/Outline.cc | 12 +--
+ poppler/Outline.h | 7 +-
+ poppler/TextOutputDev.cc | 8 +-
+ poppler/UTF.cc | 78 ++++++++----------
+ poppler/UTF.h | 11 ++-
+ qt5/src/poppler-outline.cc | 2 +-
+ qt5/src/poppler-private.cc | 13 ++-
+ qt5/src/poppler-private.h | 1 +
+ qt5/tests/check_internal_outline.cpp | 6 +-
+ qt5/tests/check_utf_conversion.cpp | 24 +++---
+ qt6/src/poppler-outline.cc | 2 +-
+ qt6/src/poppler-private.cc | 5 ++
+ qt6/src/poppler-private.h | 1 +
+ qt6/tests/check_internal_outline.cpp | 6 +-
+ qt6/tests/check_utf_conversion.cpp | 24 +++---
+ utils/HtmlFonts.cc | 4 +-
+ utils/HtmlFonts.h | 2 +-
+ utils/HtmlOutputDev.cc | 38 ++++-----
+ utils/HtmlOutputDev.h | 2 +-
+ utils/pdfinfo.cc | 8 +-
+ utils/pdfsig.cc | 8 +-
+ utils/pdftohtml.cc | 25 +++---
+ 28 files changed, 183 insertions(+), 256 deletions(-)
+
+diff --git a/cpp/poppler-toc.cpp b/cpp/poppler-toc.cpp
+index c79abde..ed3a983 100644
+--- a/cpp/poppler-toc.cpp
++++ b/cpp/poppler-toc.cpp
+@@ -61,9 +61,8 @@ toc_item_private::~toc_item_private()
+
+ void toc_item_private::load(const OutlineItem *item)
+ {
+- const Unicode *title_unicode = item->getTitle();
+- const int title_length = item->getTitleLength();
+- title = detail::unicode_to_ustring(title_unicode, title_length);
++ const std::vector<Unicode> &title_unicode = item->getTitle();
++ title = detail::unicode_to_ustring(title_unicode.data(), title_unicode.size());
+ is_open = item->isOpen();
+ }
+
+diff --git a/glib/poppler-document.cc b/glib/poppler-document.cc
+index 7505a6f..fdfefdc 100644
+--- a/glib/poppler-document.cc
++++ b/glib/poppler-document.cc
+@@ -2772,7 +2772,8 @@ PopplerAction *poppler_index_iter_get_action(PopplerIndexIter *iter)
+ item = (*iter->items)[iter->index];
+ link_action = item->getAction();
+
+- title = unicode_to_char(item->getTitle(), item->getTitleLength());
++ const std::vector<Unicode> &itemTitle = item->getTitle();
++ title = unicode_to_char(itemTitle.data(), itemTitle.size());
+
+ action = _poppler_action_new(iter->document, link_action, title);
+ g_free(title);
+diff --git a/poppler/CharCodeToUnicode.cc b/poppler/CharCodeToUnicode.cc
+index cd00937..d9ef019 100644
+--- a/poppler/CharCodeToUnicode.cc
++++ b/poppler/CharCodeToUnicode.cc
+@@ -38,6 +38,7 @@
+
+ #include <cstdio>
+ #include <cstring>
++#include <functional>
+ #include "goo/glibc.h"
+ #include "goo/gmem.h"
+ #include "goo/gfile.h"
+@@ -51,13 +52,6 @@
+
+ //------------------------------------------------------------------------
+
+-struct CharCodeToUnicodeString
+-{
+- CharCode c;
+- Unicode *u;
+- int len;
+-};
+-
+ //------------------------------------------------------------------------
+
+ static int getCharFromString(void *data)
+@@ -162,7 +156,7 @@ CharCodeToUnicode *CharCodeToUnicode::parseCIDToUnicode(const char *fileName, co
+ }
+ fclose(f);
+
+- ctu = new CharCodeToUnicode(collection->toStr(), mapA, mapLenA, true, nullptr, 0, 0);
++ ctu = new CharCodeToUnicode(collection->toStr(), mapA, mapLenA, true, {});
+ gfree(mapA);
+ return ctu;
+ }
+@@ -171,8 +165,7 @@ CharCodeToUnicode *CharCodeToUnicode::parseUnicodeToUnicode(const GooString *fil
+ {
+ FILE *f;
+ Unicode *mapA;
+- CharCodeToUnicodeString *sMapA;
+- CharCode size, oldSize, len, sMapSizeA, sMapLenA;
++ CharCode size, oldSize, len;
+ char buf[256];
+ char *tok;
+ Unicode u0;
+@@ -192,8 +185,7 @@ CharCodeToUnicode *CharCodeToUnicode::parseUnicodeToUnicode(const GooString *fil
+ mapA = (Unicode *)gmallocn(size, sizeof(Unicode));
+ memset(mapA, 0, size * sizeof(Unicode));
+ len = 0;
+- sMapA = nullptr;
+- sMapSizeA = sMapLenA = 0;
++ std::vector<CharCodeToUnicodeString> sMapA;
+
+ line = 0;
+ while (getLine(buf, sizeof(buf), f)) {
+@@ -230,17 +222,12 @@ CharCodeToUnicode *CharCodeToUnicode::parseUnicodeToUnicode(const GooString *fil
+ mapA[u0] = uBuf[0];
+ } else {
+ mapA[u0] = 0;
+- if (sMapLenA == sMapSizeA) {
+- sMapSizeA += 16;
+- sMapA = (CharCodeToUnicodeString *)greallocn(sMapA, sMapSizeA, sizeof(CharCodeToUnicodeString));
+- }
+- sMapA[sMapLenA].c = u0;
+- sMapA[sMapLenA].u = (Unicode *)gmallocn(n, sizeof(Unicode));
++ std::vector<Unicode> u;
++ u.reserve(n);
+ for (i = 0; i < n; ++i) {
+- sMapA[sMapLenA].u[i] = uBuf[i];
++ u.push_back(uBuf[i]);
+ }
+- sMapA[sMapLenA].len = n;
+- ++sMapLenA;
++ sMapA.push_back({ u0, std::move(u) });
+ }
+ if (u0 >= len) {
+ len = u0 + 1;
+@@ -248,7 +235,7 @@ CharCodeToUnicode *CharCodeToUnicode::parseUnicodeToUnicode(const GooString *fil
+ }
+ fclose(f);
+
+- ctu = new CharCodeToUnicode(fileName->toStr(), mapA, len, true, sMapA, sMapLenA, sMapSizeA);
++ ctu = new CharCodeToUnicode(fileName->toStr(), mapA, len, true, std::move(sMapA));
+ gfree(mapA);
+ gfree(uBuf);
+ return ctu;
+@@ -256,7 +243,7 @@ CharCodeToUnicode *CharCodeToUnicode::parseUnicodeToUnicode(const GooString *fil
+
+ CharCodeToUnicode *CharCodeToUnicode::make8BitToUnicode(Unicode *toUnicode)
+ {
+- return new CharCodeToUnicode({}, toUnicode, 256, true, nullptr, 0, 0);
++ return new CharCodeToUnicode({}, toUnicode, 256, true, {});
+ }
+
+ CharCodeToUnicode *CharCodeToUnicode::parseCMap(const GooString *buf, int nBits)
+@@ -512,25 +499,18 @@ void CharCodeToUnicode::addMapping(CharCode code, char *uStr, int n, int offset)
+ map[code] = 0xfffd;
+ }
+ } else {
+- if (sMapLen >= sMapSize) {
+- sMapSize = sMapSize + 16;
+- sMap = (CharCodeToUnicodeString *)greallocn(sMap, sMapSize, sizeof(CharCodeToUnicodeString));
+- }
+ map[code] = 0;
+- sMap[sMapLen].c = code;
+ int utf16Len = n / 4;
+- Unicode *utf16 = (Unicode *)gmallocn(utf16Len, sizeof(Unicode));
++ std::vector<Unicode> utf16(utf16Len);
++ utf16.resize(utf16Len);
+ for (j = 0; j < utf16Len; ++j) {
+ if (!parseHex(uStr + j * 4, 4, &utf16[j])) {
+- gfree(utf16);
+ error(errSyntaxWarning, -1, "Illegal entry in ToUnicode CMap");
+ return;
+ }
+ }
+ utf16[utf16Len - 1] += offset;
+- sMap[sMapLen].len = UTF16toUCS4(utf16, utf16Len, &sMap[sMapLen].u);
+- gfree(utf16);
+- ++sMapLen;
++ sMap.push_back({ code, UTF16toUCS4(utf16.data(), utf16.size()) });
+ }
+ }
+
+@@ -561,8 +541,6 @@ CharCodeToUnicode::CharCodeToUnicode()
+ {
+ map = nullptr;
+ mapLen = 0;
+- sMap = nullptr;
+- sMapLen = sMapSize = 0;
+ refCnt = 1;
+ isIdentity = false;
+ }
+@@ -576,13 +554,11 @@ CharCodeToUnicode::CharCodeToUnicode(const std::optional<std::string> &tagA) : t
+ for (i = 0; i < mapLen; ++i) {
+ map[i] = 0;
+ }
+- sMap = nullptr;
+- sMapLen = sMapSize = 0;
+ refCnt = 1;
+ isIdentity = false;
+ }
+
+-CharCodeToUnicode::CharCodeToUnicode(const std::optional<std::string> &tagA, Unicode *mapA, CharCode mapLenA, bool copyMap, CharCodeToUnicodeString *sMapA, int sMapLenA, int sMapSizeA) : tag(tagA)
++CharCodeToUnicode::CharCodeToUnicode(const std::optional<std::string> &tagA, Unicode *mapA, CharCode mapLenA, bool copyMap, std::vector<CharCodeToUnicodeString> &&sMapA) : tag(tagA)
+ {
+ mapLen = mapLenA;
+ if (copyMap) {
+@@ -591,9 +567,7 @@ CharCodeToUnicode::CharCodeToUnicode(const std::optional<std::string> &tagA, Uni
+ } else {
+ map = mapA;
+ }
+- sMap = sMapA;
+- sMapLen = sMapLenA;
+- sMapSize = sMapSizeA;
++ sMap = std::move(sMapA);
+ refCnt = 1;
+ isIdentity = false;
+ }
+@@ -601,12 +575,6 @@ CharCodeToUnicode::CharCodeToUnicode(const std::optional<std::string> &tagA, Uni
+ CharCodeToUnicode::~CharCodeToUnicode()
+ {
+ gfree(map);
+- if (sMap) {
+- for (int i = 0; i < sMapLen; ++i) {
+- gfree(sMap[i].u);
+- }
+- gfree(sMap);
+- }
+ }
+
+ void CharCodeToUnicode::incRefCnt()
+@@ -628,7 +596,8 @@ bool CharCodeToUnicode::match(const GooString *tagA)
+
+ void CharCodeToUnicode::setMapping(CharCode c, Unicode *u, int len)
+ {
+- int i, j;
++ size_t i;
++ int j;
+
+ if (!map || isIdentity) {
+ return;
+@@ -636,28 +605,26 @@ void CharCodeToUnicode::setMapping(CharCode c, Unicode *u, int len)
+ if (len == 1) {
+ map[c] = u[0];
+ } else {
+- for (i = 0; i < sMapLen; ++i) {
++ std::optional<std::reference_wrapper<CharCodeToUnicodeString>> element;
++ for (i = 0; i < sMap.size(); ++i) {
+ if (sMap[i].c == c) {
+- gfree(sMap[i].u);
++ sMap[i].u.clear();
++ element = std::ref(sMap[i]);
+ break;
+ }
+ }
+- if (i == sMapLen) {
+- if (sMapLen == sMapSize) {
+- sMapSize += 8;
+- sMap = (CharCodeToUnicodeString *)greallocn(sMap, sMapSize, sizeof(CharCodeToUnicodeString));
+- }
+- ++sMapLen;
++ if (!element) {
++ sMap.emplace_back(CharCodeToUnicodeString { c, {} });
++ element = std::ref(sMap.back());
+ }
+ map[c] = 0;
+- sMap[i].c = c;
+- sMap[i].len = len;
+- sMap[i].u = (Unicode *)gmallocn(len, sizeof(Unicode));
++ element->get().c = c;
++ element->get().u.reserve(len);
+ for (j = 0; j < len; ++j) {
+ if (UnicodeIsValid(u[j])) {
+- sMap[i].u[j] = u[j];
++ element->get().u.push_back(u[j]);
+ } else {
+- sMap[i].u[j] = 0xfffd;
++ element->get().u.push_back(0xfffd);
+ }
+ }
+ }
+@@ -665,8 +632,6 @@ void CharCodeToUnicode::setMapping(CharCode c, Unicode *u, int len)
+
+ int CharCodeToUnicode::mapToUnicode(CharCode c, Unicode const **u) const
+ {
+- int i;
+-
+ if (isIdentity) {
+ map[0] = (Unicode)c;
+ *u = map;
+@@ -679,10 +644,10 @@ int CharCodeToUnicode::mapToUnicode(CharCode c, Unicode const **u) const
+ *u = &map[c];
+ return 1;
+ }
+- for (i = sMapLen - 1; i >= 0; --i) { // in reverse so CMap takes precedence
+- if (sMap[i].c == c) {
+- *u = sMap[i].u;
+- return sMap[i].len;
++ for (auto i = sMap.size(); i > 0; --i) { // in reverse so CMap takes precedence
++ if (sMap[i - 1].c == c) {
++ *u = sMap[i - 1].u.data();
++ return sMap[i - 1].u.size();
+ }
+ }
+ return 0;
+@@ -704,24 +669,24 @@ int CharCodeToUnicode::mapToCharCode(const Unicode *u, CharCode *c, int usize) c
+ }
+ *c = 'x';
+ } else {
+- int i, j;
++ size_t j;
+ // for each entry in the sMap
+- for (i = 0; i < sMapLen; i++) {
++ for (const auto &element : sMap) {
+ // if the entry's unicode length isn't the same are usize, the strings
+ // are obviously different
+- if (sMap[i].len != usize) {
++ if (element.u.size() != size_t(usize)) {
+ continue;
+ }
+ // compare the string char by char
+- for (j = 0; j < sMap[i].len; j++) {
+- if (sMap[i].u[j] != u[j]) {
++ for (j = 0; j < element.u.size(); j++) {
++ if (element.u[j] != u[j]) {
+ break;
+ }
+ }
+
+ // we have the same strings
+- if (j == sMap[i].len) {
+- *c = sMap[i].c;
++ if (j == element.u.size()) {
++ *c = element.c;
+ return 1;
+ }
+ }
+diff --git a/poppler/CharCodeToUnicode.h b/poppler/CharCodeToUnicode.h
+index 596d44d..9aa2571 100644
+--- a/poppler/CharCodeToUnicode.h
++++ b/poppler/CharCodeToUnicode.h
+@@ -33,11 +33,11 @@
+
+ #include <atomic>
+ #include <optional>
++#include <vector>
+
+ #include "poppler-config.h"
+ #include "CharTypes.h"
+
+-struct CharCodeToUnicodeString;
+ class GooString;
+
+ //------------------------------------------------------------------------
+@@ -100,18 +100,22 @@ public:
+ CharCode getLength() const { return mapLen; }
+
+ private:
++ struct CharCodeToUnicodeString
++ {
++ CharCode c;
++ std::vector<Unicode> u;
++ };
+ bool parseCMap1(int (*getCharFunc)(void *), void *data, int nBits);
+ void addMapping(CharCode code, char *uStr, int n, int offset);
+ void addMappingInt(CharCode code, Unicode u);
+ CharCodeToUnicode();
+ explicit CharCodeToUnicode(const std::optional<std::string> &tagA);
+- CharCodeToUnicode(const std::optional<std::string> &tagA, Unicode *mapA, CharCode mapLenA, bool copyMap, CharCodeToUnicodeString *sMapA, int sMapLenA, int sMapSizeA);
++ CharCodeToUnicode(const std::optional<std::string> &tagA, Unicode *mapA, CharCode mapLenA, bool copyMap, std::vector<CharCodeToUnicodeString> &&sMapA);
+
+ const std::optional<std::string> tag;
+ Unicode *map;
+ CharCode mapLen;
+- CharCodeToUnicodeString *sMap;
+- int sMapLen, sMapSize;
++ std::vector<CharCodeToUnicodeString> sMap;
+ std::atomic_int refCnt;
+ bool isIdentity;
+ };
+diff --git a/poppler/DateInfo.cc b/poppler/DateInfo.cc
+index cdba4ab..28474de 100644
+--- a/poppler/DateInfo.cc
++++ b/poppler/DateInfo.cc
+@@ -36,16 +36,14 @@
+ /* See PDF Reference 1.3, Section 3.8.2 for PDF Date representation */
+ bool parseDateString(const GooString *date, int *year, int *month, int *day, int *hour, int *minute, int *second, char *tz, int *tzHour, int *tzMinute)
+ {
+- Unicode *u;
+- int len = TextStringToUCS4(date->toStr(), &u);
++ std::vector<Unicode> u = TextStringToUCS4(date->toStr());
+ GooString s;
+- for (int i = 0; i < len; i++) {
++ for (auto &c : u) {
+ // Ignore any non ASCII characters
+- if (u[i] < 128) {
+- s.append(u[i]);
++ if (c < 128) {
++ s.append(c);
+ }
+ }
+- gfree(u);
+ const char *dateString = s.c_str();
+
+ if (strlen(dateString) < 2) {
+diff --git a/poppler/JSInfo.cc b/poppler/JSInfo.cc
+index 29fa707..eaef33e 100644
+--- a/poppler/JSInfo.cc
++++ b/poppler/JSInfo.cc
+@@ -38,20 +38,17 @@ JSInfo::~JSInfo() { }
+
+ void JSInfo::printJS(const GooString *js)
+ {
+- Unicode *u = nullptr;
+ char buf[8];
+- int i, n, len;
+
+ if (!js || !js->c_str()) {
+ return;
+ }
+
+- len = TextStringToUCS4(js->toStr(), &u);
+- for (i = 0; i < len; i++) {
+- n = uniMap->mapUnicode(u[i], buf, sizeof(buf));
++ std::vector<Unicode> u = TextStringToUCS4(js->toStr());
++ for (auto &c : u) {
++ int n = uniMap->mapUnicode(c, buf, sizeof(buf));
+ fwrite(buf, 1, n, file);
+ }
+- gfree(u);
+ }
+
+ void JSInfo::scanLinkAction(LinkAction *link, const char *action)
+diff --git a/poppler/Outline.cc b/poppler/Outline.cc
+index 4c68be9..086c104 100644
+--- a/poppler/Outline.cc
++++ b/poppler/Outline.cc
+@@ -407,15 +407,12 @@ OutlineItem::OutlineItem(const Dict *dict, Ref refA, OutlineItem *parentA, XRef
+ parent = parentA;
+ xref = xrefA;
+ doc = docA;
+- title = nullptr;
+ kids = nullptr;
+
+ obj1 = dict->lookup("Title");
+ if (obj1.isString()) {
+ const GooString *s = obj1.getString();
+- titleLen = TextStringToUCS4(s->toStr(), &title);
+- } else {
+- titleLen = 0;
++ title = TextStringToUCS4(s->toStr());
+ }
+
+ obj1 = dict->lookup("Dest");
+@@ -446,9 +443,6 @@ OutlineItem::~OutlineItem()
+ delete kids;
+ kids = nullptr;
+ }
+- if (title) {
+- gfree(title);
+- }
+ }
+
+ std::vector<OutlineItem *> *OutlineItem::readItemList(OutlineItem *parent, const Object *firstItemRef, XRef *xrefA, PDFDoc *docA)
+@@ -494,11 +488,9 @@ void OutlineItem::open()
+
+ void OutlineItem::setTitle(const std::string &titleA)
+ {
+- gfree(title);
+-
+ Object dict = xref->fetch(ref);
+ GooString *g = new GooString(titleA);
+- titleLen = TextStringToUCS4(g->toStr(), &title);
++ title = TextStringToUCS4(g->toStr());
+ dict.dictSet("Title", Object(g));
+ xref->setModifiedObject(&dict, ref);
+ }
+diff --git a/poppler/Outline.h b/poppler/Outline.h
+index a301604..af431f6 100644
+--- a/poppler/Outline.h
++++ b/poppler/Outline.h
+@@ -27,6 +27,7 @@
+ #define OUTLINE_H
+
+ #include <memory>
++#include <vector>
+ #include "Object.h"
+ #include "CharTypes.h"
+ #include "poppler_private_export.h"
+@@ -91,9 +92,8 @@ public:
+ OutlineItem(const OutlineItem &) = delete;
+ OutlineItem &operator=(const OutlineItem &) = delete;
+ static std::vector<OutlineItem *> *readItemList(OutlineItem *parent, const Object *firstItemRef, XRef *xrefA, PDFDoc *docA);
+- const Unicode *getTitle() const { return title; }
++ const std::vector<Unicode> &getTitle() const { return title; }
+ void setTitle(const std::string &titleA);
+- int getTitleLength() const { return titleLen; }
+ bool setPageDest(int i);
+ // OutlineItem keeps the ownership of the action
+ const LinkAction *getAction() const { return action.get(); }
+@@ -112,8 +112,7 @@ private:
+ OutlineItem *parent;
+ PDFDoc *doc;
+ XRef *xref;
+- Unicode *title;
+- int titleLen;
++ std::vector<Unicode> title;
+ std::unique_ptr<LinkAction> action;
+ bool startsOpen;
+ std::vector<OutlineItem *> *kids; // nullptr if this item is closed or has no kids
+diff --git a/poppler/TextOutputDev.cc b/poppler/TextOutputDev.cc
+index 06fc307..ee11fcb 100644
+--- a/poppler/TextOutputDev.cc
++++ b/poppler/TextOutputDev.cc
+@@ -5668,15 +5668,11 @@ void ActualText::end(const GfxState *state)
+ // extents of all the glyphs inside the span
+
+ if (actualTextNBytes) {
+- Unicode *uni = nullptr;
+- int length;
+-
+ // now that we have the position info for all of the text inside
+ // the marked content span, we feed the "ActualText" back through
+ // text->addChar()
+- length = TextStringToUCS4(actualText->toStr(), &uni);
+- text->addChar(state, actualTextX0, actualTextY0, actualTextX1 - actualTextX0, actualTextY1 - actualTextY0, 0, actualTextNBytes, uni, length);
+- gfree(uni);
++ std::vector<Unicode> uni = TextStringToUCS4(actualText->toStr());
++ text->addChar(state, actualTextX0, actualTextY0, actualTextX1 - actualTextX0, actualTextY1 - actualTextY0, 0, actualTextNBytes, uni.data(), uni.size());
+ }
+
+ delete actualText;
+diff --git a/poppler/UTF.cc b/poppler/UTF.cc
+index 9b1bf95..eb542eb 100644
+--- a/poppler/UTF.cc
++++ b/poppler/UTF.cc
+@@ -42,65 +42,52 @@ bool UnicodeIsValid(Unicode ucs4)
+ return (ucs4 < 0x110000) && ((ucs4 & 0xfffff800) != 0xd800) && (ucs4 < 0xfdd0 || ucs4 > 0xfdef) && ((ucs4 & 0xfffe) != 0xfffe);
+ }
+
+-int UTF16toUCS4(const Unicode *utf16, int utf16Len, Unicode **ucs4_out)
++std::vector<Unicode> UTF16toUCS4(const Unicode *utf16, int utf16Len)
+ {
+- int i, n, len;
+- Unicode *u;
+-
+ // count characters
+- len = 0;
+- for (i = 0; i < utf16Len; i++) {
++ int len = 0;
++ for (int i = 0; i < utf16Len; i++) {
+ if (utf16[i] >= 0xd800 && utf16[i] < 0xdc00 && i + 1 < utf16Len && utf16[i + 1] >= 0xdc00 && utf16[i + 1] < 0xe000) {
+ i++; /* surrogate pair */
+ }
+ len++;
+ }
+- if (ucs4_out == nullptr) {
+- return len;
+- }
+-
+- u = (Unicode *)gmallocn(len, sizeof(Unicode));
+- n = 0;
++ std::vector<Unicode> u;
++ u.reserve(len);
+ // convert string
+- for (i = 0; i < utf16Len; i++) {
++ for (int i = 0; i < utf16Len; i++) {
+ if (utf16[i] >= 0xd800 && utf16[i] < 0xdc00) { /* surrogate pair */
+ if (i + 1 < utf16Len && utf16[i + 1] >= 0xdc00 && utf16[i + 1] < 0xe000) {
+ /* next code is a low surrogate */
+- u[n] = (((utf16[i] & 0x3ff) << 10) | (utf16[i + 1] & 0x3ff)) + 0x10000;
++ u.push_back((((utf16[i] & 0x3ff) << 10) | (utf16[i + 1] & 0x3ff)) + 0x10000);
+ ++i;
+ } else {
+ /* missing low surrogate
+ replace it with REPLACEMENT CHARACTER (U+FFFD) */
+- u[n] = 0xfffd;
++ u.push_back(0xfffd);
+ }
+ } else if (utf16[i] >= 0xdc00 && utf16[i] < 0xe000) {
+ /* invalid low surrogate
+ replace it with REPLACEMENT CHARACTER (U+FFFD) */
+- u[n] = 0xfffd;
++ u.push_back(0xfffd);
+ } else {
+- u[n] = utf16[i];
++ u.push_back(utf16[i]);
+ }
+- if (!UnicodeIsValid(u[n])) {
+- u[n] = 0xfffd;
++ if (!UnicodeIsValid(u.back())) {
++ u.back() = 0xfffd;
+ }
+- n++;
+ }
+- *ucs4_out = u;
+- return len;
++ return u;
+ }
+
+-int TextStringToUCS4(const std::string &textStr, Unicode **ucs4)
++std::vector<Unicode> TextStringToUCS4(const std::string &textStr)
+ {
+- int i, len;
+- const char *s;
+- Unicode *u;
+ bool isUnicode, isUnicodeLE;
+
+- len = textStr.size();
+- s = textStr.c_str();
++ int len = textStr.size();
++ const std::string &s = textStr;
+ if (len == 0) {
+- *ucs4 = nullptr;
+- return 0;
++ return {};
+ }
+
+ if (GooString::hasUnicodeMarker(textStr)) {
+@@ -115,30 +102,30 @@ int TextStringToUCS4(const std::string &textStr, Unicode **ucs4)
+ }
+
+ if (isUnicode || isUnicodeLE) {
+- Unicode *utf16;
+ len = len / 2 - 1;
+ if (len > 0) {
+- utf16 = new Unicode[len];
+- for (i = 0; i < len; i++) {
++ std::vector<Unicode> utf16;
++ utf16.reserve(len);
++ for (int i = 0; i < len; i++) {
+ if (isUnicode) {
+- utf16[i] = (s[2 + i * 2] & 0xff) << 8 | (s[3 + i * 2] & 0xff);
++ utf16.push_back((s[2 + i * 2] & 0xff) << 8 | (s[3 + i * 2] & 0xff));
+ } else { // UnicodeLE
+- utf16[i] = (s[3 + i * 2] & 0xff) << 8 | (s[2 + i * 2] & 0xff);
++ utf16.push_back((s[3 + i * 2] & 0xff) << 8 | (s[2 + i * 2] & 0xff));
+ }
+ }
+- len = UTF16toUCS4(utf16, len, &u);
+- delete[] utf16;
++ return UTF16toUCS4(utf16.data(), utf16.size());
++
+ } else {
+- u = nullptr;
++ return {};
+ }
+ } else {
+- u = (Unicode *)gmallocn(len, sizeof(Unicode));
+- for (i = 0; i < len; i++) {
+- u[i] = pdfDocEncoding[s[i] & 0xff];
++ std::vector<Unicode> u;
++ u.reserve(len);
++ for (int i = 0; i < len; i++) {
++ u.push_back(pdfDocEncoding[s[i] & 0xff]);
+ }
++ return u;
+ }
+- *ucs4 = u;
+- return len;
+ }
+
+ bool UnicodeIsWhitespace(Unicode ucs4)
+@@ -549,7 +536,10 @@ void unicodeToAscii7(const Unicode *in, int len, Unicode **ucs4_out, int *out_le
+ }
+ }
+
+- *out_len = TextStringToUCS4(str, ucs4_out);
++ std::vector<Unicode> ucs4 = TextStringToUCS4(str);
++ *out_len = ucs4.size();
++ *ucs4_out = (Unicode *)gmallocn(ucs4.size(), sizeof(Unicode));
++ memcpy(*ucs4_out, ucs4.data(), ucs4.size() * sizeof(Unicode));
+
+ if (indices) {
+ idx[k] = in_idx[len];
+diff --git a/poppler/UTF.h b/poppler/UTF.h
+index 626c686..bfc5f65 100644
+--- a/poppler/UTF.h
++++ b/poppler/UTF.h
+@@ -19,6 +19,7 @@
+ #include <cstdint>
+ #include <climits>
+ #include <memory>
++#include <vector>
+
+ #include "goo/GooString.h"
+ #include "CharTypes.h"
+@@ -27,16 +28,14 @@
+ // Convert a UTF-16 string to a UCS-4
+ // utf16 - utf16 bytes
+ // utf16_len - number of UTF-16 characters
+-// ucs4_out - if not NULL, allocates and returns UCS-4 string. Free with gfree.
+ // returns number of UCS-4 characters
+-int UTF16toUCS4(const Unicode *utf16, int utf16Len, Unicode **ucs4_out);
++std::vector<Unicode> UTF16toUCS4(const Unicode *utf16, int utf16Len);
+
+ // Convert a PDF Text String to UCS-4
+ // s - PDF text string
+-// ucs4 - if the number of UCS-4 characters is > 0, allocates and
+-// returns UCS-4 string. Free with gfree.
+-// returns number of UCS-4 characters
+-int POPPLER_PRIVATE_EXPORT TextStringToUCS4(const std::string &textStr, Unicode **ucs4);
++// returns UCS-4 characters
++// Convert a PDF text string to UCS-4
++std::vector<Unicode> POPPLER_PRIVATE_EXPORT TextStringToUCS4(const std::string &textStr);
+
+ // check if UCS-4 character is valid
+ bool UnicodeIsValid(Unicode ucs4);
+diff --git a/qt5/src/poppler-outline.cc b/qt5/src/poppler-outline.cc
+index 5ff7e37..2f6ef2d 100644
+--- a/qt5/src/poppler-outline.cc
++++ b/qt5/src/poppler-outline.cc
+@@ -78,7 +78,7 @@ QString OutlineItem::name() const
+
+ if (name.isEmpty()) {
+ if (const ::OutlineItem *data = m_data->data) {
+- name = unicodeToQString(data->getTitle(), data->getTitleLength());
++ name = unicodeToQString(data->getTitle());
+ }
+ }
+
+diff --git a/qt5/src/poppler-private.cc b/qt5/src/poppler-private.cc
+index 228d8e8..54df79f 100644
+--- a/qt5/src/poppler-private.cc
++++ b/qt5/src/poppler-private.cc
+@@ -94,6 +94,11 @@ QString unicodeToQString(const Unicode *u, int len)
+ return QString::fromUtf8(convertedStr.c_str(), convertedStr.getLength());
+ }
+
++QString unicodeToQString(const std::vector<Unicode> &u)
++{
++ return unicodeToQString(u.data(), u.size());
++}
++
+ QString UnicodeParsedString(const GooString *s1)
+ {
+ return (s1) ? UnicodeParsedString(s1->toStr()) : QString();
+@@ -266,13 +271,7 @@ void DocumentData::addTocChildren(QDomDocument *docSyn, QDomNode *parent, const
+ // iterate over every object in 'items'
+
+ // 1. create element using outlineItem's title as tagName
+- QString name;
+- const Unicode *uniChar = outlineItem->getTitle();
+- int titleLength = outlineItem->getTitleLength();
+- name = unicodeToQString(uniChar, titleLength);
+- if (name.isEmpty()) {
+- continue;
+- }
++ QString name = unicodeToQString(outlineItem->getTitle());
+
+ QDomElement item = docSyn->createElement(name);
+ parent->appendChild(item);
+diff --git a/qt5/src/poppler-private.h b/qt5/src/poppler-private.h
+index 39dfb6b..bba5bd7 100644
+--- a/qt5/src/poppler-private.h
++++ b/qt5/src/poppler-private.h
+@@ -73,6 +73,7 @@ namespace Poppler {
+
+ /* borrowed from kpdf */
+ POPPLER_QT5_EXPORT QString unicodeToQString(const Unicode *u, int len);
++POPPLER_QT5_EXPORT QString unicodeToQString(const std::vector<Unicode> &u);
+
+ POPPLER_QT5_EXPORT QString UnicodeParsedString(const GooString *s1);
+
+diff --git a/qt5/tests/check_internal_outline.cpp b/qt5/tests/check_internal_outline.cpp
+index c12b604..5db6bf4 100644
+--- a/qt5/tests/check_internal_outline.cpp
++++ b/qt5/tests/check_internal_outline.cpp
+@@ -56,10 +56,10 @@ void TestInternalOutline::testCreateOutline()
+
+ static std::string getTitle(const OutlineItem *item)
+ {
+- const Unicode *u = item->getTitle();
++ std::vector<Unicode> u = item->getTitle();
+ std::string s;
+- for (int i = 0; i < item->getTitleLength(); i++) {
+- s.append(1, (char)u[i]);
++ for (auto &c : u) {
++ s.append(1, (char)(c));
+ }
+ return s;
+ }
+diff --git a/qt5/tests/check_utf_conversion.cpp b/qt5/tests/check_utf_conversion.cpp
+index 73c684e..b00f080 100644
+--- a/qt5/tests/check_utf_conversion.cpp
++++ b/qt5/tests/check_utf_conversion.cpp
+@@ -133,16 +133,13 @@ void TestUTFConversion::testUnicodeToAscii7()
+ // malloc() always returns 8-byte aligned memory addresses.
+ GooString *goo = Poppler::QStringToUnicodeGooString(QString::fromUtf8("®©©©©©©©©©©©©©©©©©©©©")); // clazy:exclude=qstring-allocations
+
+- Unicode *in;
+- const int in_len = TextStringToUCS4(goo->toStr(), &in);
++ const std::vector<Unicode> in = TextStringToUCS4(goo->toStr());
+
+ delete goo;
+
+ int in_norm_len;
+ int *in_norm_idx;
+- Unicode *in_norm = unicodeNormalizeNFKC(in, in_len, &in_norm_len, &in_norm_idx, true);
+-
+- free(in);
++ Unicode *in_norm = unicodeNormalizeNFKC(in.data(), in.size(), &in_norm_len, &in_norm_idx, true);
+
+ Unicode *out;
+ int out_len;
+@@ -174,25 +171,24 @@ void TestUTFConversion::testUnicodeLittleEndian()
+ // Let's assert both GooString's are different
+ QVERIFY(GooUTF16LE != GooUTF16BE);
+
+- Unicode *UCS4fromLE, *UCS4fromBE;
+- const int len1 = TextStringToUCS4(GooUTF16LE, &UCS4fromLE);
+- const int len2 = TextStringToUCS4(GooUTF16BE, &UCS4fromBE);
++ const std::vector<Unicode> UCS4fromLE = TextStringToUCS4(GooUTF16LE);
++ const std::vector<Unicode> UCS4fromBE = TextStringToUCS4(GooUTF16BE);
+
+ // len is 4 because TextStringToUCS4() removes the two leading Byte Order Mark (BOM) code points
+- QCOMPARE(len1, len2);
+- QCOMPARE(len1, 4);
++ QCOMPARE(UCS4fromLE.size(), UCS4fromBE.size());
++ QCOMPARE(UCS4fromLE.size(), 4);
+
+ // Check that now after conversion, UCS4fromLE and UCS4fromBE are now the same
+- for (int i = 0; i < len1; i++) {
++ for (size_t i = 0; i < UCS4fromLE.size(); i++) {
+ QCOMPARE(UCS4fromLE[i], UCS4fromBE[i]);
+ }
+
+ const QString expected = QString::fromUtf8("HI!☑"); // clazy:exclude=qstring-allocations
+
+ // Do some final verifications, checking the strings to be "HI!"
+- QVERIFY(*UCS4fromLE == *UCS4fromBE);
+- QVERIFY(compare(UCS4fromLE, expected.utf16(), len1));
+- QVERIFY(compare(UCS4fromBE, expected.utf16(), len1));
++ QVERIFY(UCS4fromLE == UCS4fromBE);
++ QVERIFY(compare(UCS4fromLE.data(), expected.utf16(), UCS4fromLE.size()));
++ QVERIFY(compare(UCS4fromBE.data(), expected.utf16(), UCS4fromLE.size()));
+ }
+
+ QTEST_GUILESS_MAIN(TestUTFConversion)
+diff --git a/qt6/src/poppler-outline.cc b/qt6/src/poppler-outline.cc
+index f5ba2a9..2bc0d30 100644
+--- a/qt6/src/poppler-outline.cc
++++ b/qt6/src/poppler-outline.cc
+@@ -78,7 +78,7 @@ QString OutlineItem::name() const
+
+ if (name.isEmpty()) {
+ if (const ::OutlineItem *data = m_data->data) {
+- name = unicodeToQString(data->getTitle(), data->getTitleLength());
++ name = unicodeToQString(data->getTitle());
+ }
+ }
+
+diff --git a/qt6/src/poppler-private.cc b/qt6/src/poppler-private.cc
+index 91d1725..2cb2396 100644
+--- a/qt6/src/poppler-private.cc
++++ b/qt6/src/poppler-private.cc
+@@ -94,6 +94,11 @@ QString unicodeToQString(const Unicode *u, int len)
+ return QString::fromUtf8(convertedStr.c_str(), convertedStr.getLength());
+ }
+
++QString unicodeToQString(const std::vector<Unicode> &u)
++{
++ return unicodeToQString(u.data(), u.size());
++}
++
+ QString UnicodeParsedString(const GooString *s1)
+ {
+ return (s1) ? UnicodeParsedString(s1->toStr()) : QString();
+diff --git a/qt6/src/poppler-private.h b/qt6/src/poppler-private.h
+index d1f7335..a3117a6 100644
+--- a/qt6/src/poppler-private.h
++++ b/qt6/src/poppler-private.h
+@@ -72,6 +72,7 @@ namespace Poppler {
+
+ /* borrowed from kpdf */
+ POPPLER_QT6_EXPORT QString unicodeToQString(const Unicode *u, int len);
++POPPLER_QT6_EXPORT QString unicodeToQString(const std::vector<Unicode> &u);
+
+ POPPLER_QT6_EXPORT QString UnicodeParsedString(const GooString *s1);
+
+diff --git a/qt6/tests/check_internal_outline.cpp b/qt6/tests/check_internal_outline.cpp
+index c12b604..d23e773 100644
+--- a/qt6/tests/check_internal_outline.cpp
++++ b/qt6/tests/check_internal_outline.cpp
+@@ -56,10 +56,10 @@ void TestInternalOutline::testCreateOutline()
+
+ static std::string getTitle(const OutlineItem *item)
+ {
+- const Unicode *u = item->getTitle();
++ const std::vector<Unicode> &u = item->getTitle();
+ std::string s;
+- for (int i = 0; i < item->getTitleLength(); i++) {
+- s.append(1, (char)u[i]);
++ for (const auto &c : u) {
++ s.append(1, (char)(c));
+ }
+ return s;
+ }
+diff --git a/qt6/tests/check_utf_conversion.cpp b/qt6/tests/check_utf_conversion.cpp
+index 2cac758..e7f35ea 100644
+--- a/qt6/tests/check_utf_conversion.cpp
++++ b/qt6/tests/check_utf_conversion.cpp
+@@ -131,16 +131,13 @@ void TestUTFConversion::testUnicodeToAscii7()
+ // malloc() always returns 8-byte aligned memory addresses.
+ GooString *goo = Poppler::QStringToUnicodeGooString(QString::fromUtf8("®©©©©©©©©©©©©©©©©©©©©")); // clazy:exclude=qstring-allocations
+
+- Unicode *in;
+- const int in_len = TextStringToUCS4(goo->toStr(), &in);
++ const std::vector<Unicode> in = TextStringToUCS4(goo->toStr());
+
+ delete goo;
+
+ int in_norm_len;
+ int *in_norm_idx;
+- Unicode *in_norm = unicodeNormalizeNFKC(in, in_len, &in_norm_len, &in_norm_idx, true);
+-
+- free(in);
++ Unicode *in_norm = unicodeNormalizeNFKC(in.data(), in.size(), &in_norm_len, &in_norm_idx, true);
+
+ Unicode *out;
+ int out_len;
+@@ -172,25 +169,24 @@ void TestUTFConversion::testUnicodeLittleEndian()
+ // Let's assert both GooString's are different
+ QVERIFY(GooUTF16LE != GooUTF16BE);
+
+- Unicode *UCS4fromLE, *UCS4fromBE;
+- const int len1 = TextStringToUCS4(GooUTF16LE, &UCS4fromLE);
+- const int len2 = TextStringToUCS4(GooUTF16BE, &UCS4fromBE);
++ const std::vector<Unicode> UCS4fromLE = TextStringToUCS4(GooUTF16LE);
++ const std::vector<Unicode> UCS4fromBE = TextStringToUCS4(GooUTF16BE);
+
+ // len is 4 because TextStringToUCS4() removes the two leading Byte Order Mark (BOM) code points
+- QCOMPARE(len1, len2);
+- QCOMPARE(len1, 4);
++ QCOMPARE(UCS4fromLE.size(), UCS4fromBE.size());
++ QCOMPARE(UCS4fromLE.size(), 4);
+
+ // Check that now after conversion, UCS4fromLE and UCS4fromBE are now the same
+- for (int i = 0; i < len1; i++) {
++ for (size_t i = 0; i < UCS4fromLE.size(); i++) {
+ QCOMPARE(UCS4fromLE[i], UCS4fromBE[i]);
+ }
+
+ const QString expected = QStringLiteral("HI!☑");
+
+ // Do some final verifications, checking the strings to be "HI!"
+- QVERIFY(*UCS4fromLE == *UCS4fromBE);
+- QVERIFY(compare(UCS4fromLE, expected.utf16(), len1));
+- QVERIFY(compare(UCS4fromBE, expected.utf16(), len1));
++ QVERIFY(UCS4fromLE == UCS4fromBE);
++ QVERIFY(compare(UCS4fromLE.data(), expected.utf16(), UCS4fromLE.size()));
++ QVERIFY(compare(UCS4fromBE.data(), expected.utf16(), UCS4fromBE.size()));
+ }
+
+ QTEST_GUILESS_MAIN(TestUTFConversion)
+diff --git a/utils/HtmlFonts.cc b/utils/HtmlFonts.cc
+index ca7d4a4..9f25621 100644
+--- a/utils/HtmlFonts.cc
++++ b/utils/HtmlFonts.cc
+@@ -230,9 +230,9 @@ GooString *HtmlFont::getFullName()
+ }
+
+ // this method if plain wrong todo
+-GooString *HtmlFont::HtmlFilter(const Unicode *u, int uLen)
++std::unique_ptr<GooString> HtmlFont::HtmlFilter(const Unicode *u, int uLen)
+ {
+- GooString *tmp = new GooString();
++ auto tmp = std::make_unique<GooString>();
+ const UnicodeMap *uMap;
+ char buf[8];
+ int n;
+diff --git a/utils/HtmlFonts.h b/utils/HtmlFonts.h
+index ca4ae54..74cdca0 100644
+--- a/utils/HtmlFonts.h
++++ b/utils/HtmlFonts.h
+@@ -104,7 +104,7 @@ public:
+ }
+ const double *getRotMat() const { return rotSkewMat; }
+ GooString *getFontName();
+- static GooString *HtmlFilter(const Unicode *u, int uLen); // char* s);
++ static std::unique_ptr<GooString> HtmlFilter(const Unicode *u, int uLen); // char* s);
+ bool isEqual(const HtmlFont &x) const;
+ bool isEqualIgnoreBold(const HtmlFont &x) const;
+ void print() const { printf("font: %s (%s) %d %s%s\n", FontName->c_str(), familyName.c_str(), size, bold ? "bold " : "", italic ? "italic " : ""); };
+diff --git a/utils/HtmlOutputDev.cc b/utils/HtmlOutputDev.cc
+index 2611e06..b45a5ff 100644
+--- a/utils/HtmlOutputDev.cc
++++ b/utils/HtmlOutputDev.cc
+@@ -124,11 +124,11 @@ static bool debug = false;
+
+ #if 0
+ static GooString* Dirname(GooString* str){
+-
++
+ char *p=str->c_str();
+ int len=str->getLength();
+ for (int i=len-1;i>=0;i--)
+- if (*(p+i)==SLASH)
++ if (*(p+i)==SLASH)
+ return new GooString(p,i+1);
+ return new GooString();
+ }
+@@ -219,14 +219,13 @@ HtmlString::HtmlString(GfxState *state, double fontSize, HtmlFontAccu *_fonts) :
+ len = size = 0;
+ yxNext = nullptr;
+ xyNext = nullptr;
+- htext = new GooString();
++ htext = std::make_unique<GooString>();
+ dir = textDirUnknown;
+ }
+
+ HtmlString::~HtmlString()
+ {
+ gfree(text);
+- delete htext;
+ gfree(xRight);
+ }
+
+@@ -345,7 +344,6 @@ void HtmlPage::beginString(GfxState *state, const GooString *s)
+ void HtmlPage::conv()
+ {
+ for (HtmlString *tmp = yxStrings; tmp; tmp = tmp->yxNext) {
+- delete tmp->htext;
+ tmp->htext = HtmlFont::HtmlFilter(tmp->text, tmp->len);
+
+ size_t linkIndex = 0;
+@@ -641,7 +639,7 @@ void HtmlPage::coalesce()
+ bool finish_a = switch_links && hlink1 != nullptr;
+ bool finish_italic = hfont1->isItalic() && (!hfont2->isItalic() || finish_a);
+ bool finish_bold = hfont1->isBold() && (!hfont2->isBold() || finish_a || finish_italic);
+- CloseTags(str1->htext, finish_a, finish_italic, finish_bold);
++ CloseTags(str1->htext.get(), finish_a, finish_italic, finish_bold);
+ if (switch_links && hlink2 != nullptr) {
+ GooString *ls = hlink2->getLinkStart();
+ str1->htext->append(ls);
+@@ -654,7 +652,7 @@ void HtmlPage::coalesce()
+ str1->htext->append("<b>", 3);
+ }
+
+- str1->htext->append(str2->htext);
++ str1->htext->append(str2->htext.get());
+ // str1 now contains href for link of str2 (if it is defined)
+ str1->link = str2->link;
+ hfont1 = hfont2;
+@@ -671,7 +669,7 @@ void HtmlPage::coalesce()
+ bool finish_a = str1->getLink() != nullptr;
+ bool finish_bold = hfont1->isBold();
+ bool finish_italic = hfont1->isItalic();
+- CloseTags(str1->htext, finish_a, finish_italic, finish_bold);
++ CloseTags(str1->htext.get(), finish_a, finish_italic, finish_bold);
+
+ str1->xMin = curX;
+ str1->yMin = curY;
+@@ -698,14 +696,14 @@ void HtmlPage::coalesce()
+ bool finish_bold = hfont1->isBold();
+ bool finish_italic = hfont1->isItalic();
+ bool finish_a = str1->getLink() != nullptr;
+- CloseTags(str1->htext, finish_a, finish_italic, finish_bold);
++ CloseTags(str1->htext.get(), finish_a, finish_italic, finish_bold);
+
+ #if 0 //~ for debugging
+ for (str1 = yxStrings; str1; str1 = str1->yxNext) {
+ printf("x=%3d..%3d y=%3d..%3d size=%2d ",
+ (int)str1->xMin, (int)str1->xMax, (int)str1->yMin, (int)str1->yMax,
+ (int)(str1->yMax - str1->yMin));
+- printf("'%s'\n", str1->htext->c_str());
++ printf("'%s'\n", str1->htext->c_str());
+ }
+ printf("\n------------------------------------------------------------\n\n");
+ #endif
+@@ -1225,10 +1223,10 @@ void HtmlOutputDev::startPage(int pageNumA, GfxState *state, XRef *xref)
+ exit(1);
+ }
+ delete fname;
+- // if(state->getRotation()!=0)
++ // if(state->getRotation()!=0)
+ // fprintf(tin,"ROTATE=%d rotate %d neg %d neg translate\n",state->getRotation(),state->getX1(),-state->getY1());
+- // else
+- fprintf(tin,"ROTATE=%d neg %d neg translate\n",state->getX1(),state->getY1());
++ // else
++ fprintf(tin,"ROTATE=%d neg %d neg translate\n",state->getX1(),state->getY1());
+ }
+ }
+ #endif
+@@ -1723,10 +1721,11 @@ bool HtmlOutputDev::newHtmlOutlineLevel(FILE *output, const std::vector<OutlineI
+ fputs("<ul>\n", output);
+
+ for (OutlineItem *item : *outlines) {
+- GooString *titleStr = HtmlFont::HtmlFilter(item->getTitle(), item->getTitleLength());
++ const auto &title = item->getTitle();
++ std::unique_ptr<GooString> titleStr = HtmlFont::HtmlFilter(title.data(), title.size());
+
+ GooString *linkName = nullptr;
+- ;
++
+ const int itemPage = getOutlinePageNum(item);
+ if (itemPage > 0) {
+ /* complex simple
+@@ -1753,12 +1752,13 @@ bool HtmlOutputDev::newHtmlOutlineLevel(FILE *output, const std::vector<OutlineI
+ if (linkName) {
+ fprintf(output, "<a href=\"%s\">", linkName->c_str());
+ }
+- fputs(titleStr->c_str(), output);
++ if (titleStr) {
++ fputs(titleStr->c_str(), output);
++ }
+ if (linkName) {
+ fputs("</a>", output);
+ delete linkName;
+ }
+- delete titleStr;
+ atLeastOne = true;
+
+ item->open();
+@@ -1778,14 +1778,14 @@ void HtmlOutputDev::newXmlOutlineLevel(FILE *output, const std::vector<OutlineIt
+ fputs("<outline>\n", output);
+
+ for (OutlineItem *item : *outlines) {
+- GooString *titleStr = HtmlFont::HtmlFilter(item->getTitle(), item->getTitleLength());
++ const std::vector<Unicode> &title = item->getTitle();
++ auto titleStr = HtmlFont::HtmlFilter(title.data(), title.size());
+ const int itemPage = getOutlinePageNum(item);
+ if (itemPage > 0) {
+ fprintf(output, "<item page=\"%d\">%s</item>\n", itemPage, titleStr->c_str());
+ } else {
+ fprintf(output, "<item>%s</item>\n", titleStr->c_str());
+ }
+- delete titleStr;
+
+ item->open();
+ if (item->hasKids() && item->getKids()) {
+diff --git a/utils/HtmlOutputDev.h b/utils/HtmlOutputDev.h
+index c7b08d1..e490eff 100644
+--- a/utils/HtmlOutputDev.h
++++ b/utils/HtmlOutputDev.h
+@@ -95,7 +95,7 @@ private:
+ HtmlString *yxNext; // next string in y-major order
+ HtmlString *xyNext; // next string in x-major order
+ int fontpos;
+- GooString *htext;
++ std::unique_ptr<GooString> htext;
+ int len; // length of text and xRight
+ int size; // size of text and xRight arrays
+ UnicodeTextDirection dir; // direction (left to right/right to left)
+diff --git a/utils/pdfinfo.cc b/utils/pdfinfo.cc
+index 1f4ca79..2057d22 100644
+--- a/utils/pdfinfo.cc
++++ b/utils/pdfinfo.cc
+@@ -114,14 +114,12 @@ static const ArgDesc argDesc[] = { { "-f", argInt, &firstPage, 0, "first page to
+
+ static void printTextString(const GooString *s, const UnicodeMap *uMap)
+ {
+- Unicode *u;
+ char buf[8];
+- int len = TextStringToUCS4(s->toStr(), &u);
+- for (int i = 0; i < len; i++) {
+- int n = uMap->mapUnicode(u[i], buf, sizeof(buf));
++ std::vector<Unicode> u = TextStringToUCS4(s->toStr());
++ for (const auto &c : u) {
++ int n = uMap->mapUnicode(c, buf, sizeof(buf));
+ fwrite(buf, 1, n, stdout);
+ }
+- gfree(u);
+ }
+
+ static void printUCS4String(const Unicode *u, int len, const UnicodeMap *uMap)
+diff --git a/utils/pdfsig.cc b/utils/pdfsig.cc
+index 490795f..e15a360 100644
+--- a/utils/pdfsig.cc
++++ b/utils/pdfsig.cc
+@@ -224,16 +224,14 @@ static std::string TextStringToUTF8(const std::string &str)
+ {
+ const UnicodeMap *utf8Map = globalParams->getUtf8Map();
+
+- Unicode *u;
+- const int len = TextStringToUCS4(str, &u);
++ std::vector<Unicode> u = TextStringToUCS4(str);
+
+ std::string convertedStr;
+- for (int i = 0; i < len; ++i) {
++ for (auto &c : u) {
+ char buf[8];
+- const int n = utf8Map->mapUnicode(u[i], buf, sizeof(buf));
++ const int n = utf8Map->mapUnicode(c, buf, sizeof(buf));
+ convertedStr.append(buf, n);
+ }
+- gfree(u);
+
+ return convertedStr;
+ }
+diff --git a/utils/pdftohtml.cc b/utils/pdftohtml.cc
+index 97b141a..d7c0889 100644
+--- a/utils/pdftohtml.cc
++++ b/utils/pdftohtml.cc
+@@ -99,7 +99,7 @@ static char ownerPassword[33] = "";
+ static char userPassword[33] = "";
+ static bool printVersion = false;
+
+-static GooString *getInfoString(Dict *infoDict, const char *key);
++static std::unique_ptr<GooString> getInfoString(Dict *infoDict, const char *key);
+ static GooString *getInfoDate(Dict *infoDict, const char *key);
+
+ static char textEncName[128] = "";
+@@ -158,8 +158,11 @@ int main(int argc, char *argv[])
+ {
+ std::unique_ptr<PDFDoc> doc;
+ GooString *fileName = nullptr;
+- GooString *docTitle = nullptr;
+- GooString *author = nullptr, *keywords = nullptr, *subject = nullptr, *date = nullptr;
++ std::unique_ptr<GooString> docTitle;
++ std::unique_ptr<GooString> author;
++ std::unique_ptr<GooString> keywords;
++ std::unique_ptr<GooString> subject;
++ GooString *date = nullptr;
+ GooString *htmlFileName = nullptr;
+ HtmlOutputDev *htmlOut = nullptr;
+ SplashOutputDev *splashOut = nullptr;
+@@ -317,7 +320,7 @@ int main(int argc, char *argv[])
+ }
+ }
+ if (!docTitle) {
+- docTitle = new GooString(htmlFileName);
++ docTitle = std::make_unique<GooString>(htmlFileName);
+ }
+
+ if (!singleHtml) {
+@@ -330,16 +333,6 @@ int main(int argc, char *argv[])
+ // write text file
+ htmlOut = new HtmlOutputDev(doc->getCatalog(), htmlFileName->c_str(), docTitle->c_str(), author ? author->c_str() : nullptr, keywords ? keywords->c_str() : nullptr, subject ? subject->c_str() : nullptr, date ? date->c_str() : nullptr,
+ rawOrder, firstPage, doOutline);
+- delete docTitle;
+- if (author) {
+- delete author;
+- }
+- if (keywords) {
+- delete keywords;
+- }
+- if (subject) {
+- delete subject;
+- }
+ if (date) {
+ delete date;
+ }
+@@ -397,7 +390,7 @@ error:
+ return exit_status;
+ }
+
+-static GooString *getInfoString(Dict *infoDict, const char *key)
++static std::unique_ptr<GooString> getInfoString(Dict *infoDict, const char *key)
+ {
+ Object obj;
+ // Raw value as read from PDF (may be in pdfDocEncoding or UCS2)
+@@ -406,7 +399,7 @@ static GooString *getInfoString(Dict *infoDict, const char *key)
+ Unicode *unicodeString;
+ int unicodeLength;
+ // Value HTML escaped and converted to desired encoding
+- GooString *encodedString = nullptr;
++ std::unique_ptr<GooString> encodedString;
+ // Is rawString UCS2 (as opposed to pdfDocEncoding)
+ bool isUnicode;
+
+--
+2.40.0
+
diff --git a/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2024-6239-0002.patch b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2024-6239-0002.patch
new file mode 100644
index 0000000000..cb9ef4237c
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2024-6239-0002.patch
@@ -0,0 +1,111 @@
+From 0554731052d1a97745cb179ab0d45620589dd9c4 Mon Sep 17 00:00:00 2001
+From: Albert Astals Cid <aacid@kde.org>
+Date: Fri, 17 Jun 2024 00:54:55 +0200
+Subject: [PATCH] pdfinfo: Fix crash in broken documents when using -dests
+
+CVE: CVE-2024-6239
+Upstream-Status: Backport [https://gitlab.freedesktop.org/poppler/poppler/-/commit/0554731052d1a97745cb179ab0d45620589dd9c4]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ utils/pdfinfo.cc | 35 +++++++++++++++--------------------
+ 1 file changed, 15 insertions(+), 20 deletions(-)
+
+diff --git a/utils/pdfinfo.cc b/utils/pdfinfo.cc
+index 2057d22..5f96b41 100644
+--- a/utils/pdfinfo.cc
++++ b/utils/pdfinfo.cc
+@@ -15,7 +15,7 @@
+ // under GPL version 2 or later
+ //
+ // Copyright (C) 2006 Dom Lachowicz <cinamod@hotmail.com>
+-// Copyright (C) 2007-2010, 2012, 2016-2022 Albert Astals Cid <aacid@kde.org>
++// Copyright (C) 2007-2010, 2012, 2016-2022, 2024 Albert Astals Cid <aacid@kde.org>
+ // Copyright (C) 2010 Hib Eris <hib@hiberis.nl>
+ // Copyright (C) 2011 Vittal Aithal <vittal.aithal@cognidox.com>
+ // Copyright (C) 2012, 2013, 2016-2018, 2021 Adrian Johnson <ajohnson@redneon.com>
+@@ -112,16 +112,21 @@ static const ArgDesc argDesc[] = { { "-f", argInt, &firstPage, 0, "first page to
+ { "-?", argFlag, &printHelp, 0, "print usage information" },
+ {} };
+
+-static void printTextString(const GooString *s, const UnicodeMap *uMap)
++static void printStdTextString(const std::string &s, const UnicodeMap *uMap)
+ {
+ char buf[8];
+- std::vector<Unicode> u = TextStringToUCS4(s->toStr());
++ const std::vector<Unicode> u = TextStringToUCS4(s);
+ for (const auto &c : u) {
+ int n = uMap->mapUnicode(c, buf, sizeof(buf));
+ fwrite(buf, 1, n, stdout);
+ }
+ }
+
++static void printTextString(const GooString *s, const UnicodeMap *uMap)
++{
++ printStdTextString(s->toStr(), uMap);
++}
++
+ static void printUCS4String(const Unicode *u, int len, const UnicodeMap *uMap)
+ {
+ char buf[8];
+@@ -293,11 +298,6 @@ static void printStruct(const StructElement *element, unsigned indent)
+ }
+ }
+
+-struct GooStringCompare
+-{
+- bool operator()(GooString *lhs, GooString *rhs) const { return lhs->cmp(const_cast<GooString *>(rhs)) < 0; }
+-};
+-
+ static void printLinkDest(const std::unique_ptr<LinkDest> &dest)
+ {
+ GooString s;
+@@ -368,29 +368,25 @@ static void printLinkDest(const std::unique_ptr<LinkDest> &dest)
+
+ static void printDestinations(PDFDoc *doc, const UnicodeMap *uMap)
+ {
+- std::map<Ref, std::map<GooString *, std::unique_ptr<LinkDest>, GooStringCompare>> map;
++ std::map<Ref, std::map<std::string, std::unique_ptr<LinkDest>>> map;
+
+ int numDests = doc->getCatalog()->numDestNameTree();
+ for (int i = 0; i < numDests; i++) {
+- GooString *name = new GooString(doc->getCatalog()->getDestNameTreeName(i));
++ const GooString *name = doc->getCatalog()->getDestNameTreeName(i);
+ std::unique_ptr<LinkDest> dest = doc->getCatalog()->getDestNameTreeDest(i);
+- if (dest && dest->isPageRef()) {
++ if (name && dest && dest->isPageRef()) {
+ Ref pageRef = dest->getPageRef();
+- map[pageRef].insert(std::make_pair(name, std::move(dest)));
+- } else {
+- delete name;
++ map[pageRef].insert(std::make_pair(name->toStr(), std::move(dest)));
+ }
+ }
+
+ numDests = doc->getCatalog()->numDests();
+ for (int i = 0; i < numDests; i++) {
+- GooString *name = new GooString(doc->getCatalog()->getDestsName(i));
++ const char *name = doc->getCatalog()->getDestsName(i);
+ std::unique_ptr<LinkDest> dest = doc->getCatalog()->getDestsDest(i);
+- if (dest && dest->isPageRef()) {
++ if (name && dest && dest->isPageRef()) {
+ Ref pageRef = dest->getPageRef();
+ map[pageRef].insert(std::make_pair(name, std::move(dest)));
+- } else {
+- delete name;
+ }
+ }
+
+@@ -404,9 +400,8 @@ static void printDestinations(PDFDoc *doc, const UnicodeMap *uMap)
+ printf("%4d ", i);
+ printLinkDest(it.second);
+ printf(" \"");
+- printTextString(it.first, uMap);
++ printStdTextString(it.first, uMap);
+ printf("\"\n");
+- delete it.first;
+ }
+ }
+ }
+--
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-32364.patch b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-32364.patch
new file mode 100644
index 0000000000..04af0278ce
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-32364.patch
@@ -0,0 +1,28 @@
+From d87bc726c7cc98f8c26b60ece5f20236e9de1bc3 Mon Sep 17 00:00:00 2001
+From: Albert Astals Cid <aacid@kde.org>
+Date: Mon, 24 Mar 2025 00:44:54 +0100
+Subject: [PATCH] PSStack::roll: Protect against doing int = -INT_MIN
+
+CVE: CVE-2025-32364
+Upstream-Status: Backport [https://gitlab.freedesktop.org/poppler/poppler/-/commit/d87bc726c7cc98f8c26b60ece5f20236e9de1bc3]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ poppler/Function.cc | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/poppler/Function.cc b/poppler/Function.cc
+index 043ae8e..65888a0 100644
+--- a/poppler/Function.cc
++++ b/poppler/Function.cc
+@@ -1066,7 +1066,7 @@ void PSStack::roll(int n, int j)
+ PSObject obj;
+ int i, k;
+
+- if (unlikely(n == 0)) {
++ if (unlikely(n == 0 || j == INT_MIN)) {
+ return;
+ }
+ if (j >= 0) {
+--
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-32365.patch b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-32365.patch
new file mode 100644
index 0000000000..703a69fc95
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-32365.patch
@@ -0,0 +1,41 @@
+From 1f151565bbca5be7449ba8eea6833051cc1baa41 Mon Sep 17 00:00:00 2001
+From: Albert Astals Cid <aacid@kde.org>
+Date: Mon, 31 Mar 2025 14:35:49 +0200
+Subject: [PATCH] Move isOk check to inside JBIG2Bitmap::combine
+
+CVE: CVE-2025-32365
+Upstream-Status: Backport [https://gitlab.freedesktop.org/poppler/poppler/-/commit/1f151565bbca5be7449ba8eea6833051cc1baa41]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ poppler/JBIG2Stream.cc | 8 +++++---
+ 1 file changed, 5 insertions(+), 3 deletions(-)
+
+diff --git a/poppler/JBIG2Stream.cc b/poppler/JBIG2Stream.cc
+index bdc51d0..2974493 100644
+--- a/poppler/JBIG2Stream.cc
++++ b/poppler/JBIG2Stream.cc
+@@ -770,6 +770,10 @@ void JBIG2Bitmap::combine(JBIG2Bitmap *bitmap, int x, int y, unsigned int combOp
+ unsigned int src0, src1, src, dest, s1, s2, m1, m2, m3;
+ bool oneByte;
+
++ if (unlikely(!isOk())) {
++ return;
++ }
++
+ // check for the pathological case where y = -2^31
+ if (y < -0x7fffffff) {
+ return;
+@@ -2200,9 +2204,7 @@ void JBIG2Stream::readTextRegionSeg(unsigned int segNum, bool imm, bool lossless
+ if (pageH == 0xffffffff && y + h > curPageH) {
+ pageBitmap->expand(y + h, pageDefPixel);
+ }
+- if (pageBitmap->isOk()) {
+- pageBitmap->combine(bitmap.get(), x, y, extCombOp);
+- }
++ pageBitmap->combine(bitmap.get(), x, y, extCombOp);
+
+ // store the region bitmap
+ } else {
+--
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-43718.patch b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-43718.patch
new file mode 100644
index 0000000000..dd3b9c8306
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-43718.patch
@@ -0,0 +1,31 @@
+From f54b815672117c250420787c8c006de98e8c7408 Mon Sep 17 00:00:00 2001
+From: Albert Astals Cid <aacid@kde.org>
+Date: Wed, 26 Mar 2025 11:26:32 +0100
+Subject: [PATCH] Make sure regex doesn't stack overflow by limiting it
+
+Happens with very long pdfsubver strings when compiled with
+-fno-omit-frame-pointer -mno-omit-leaf-frame-pointer -flto=auto
+
+Upstream-Status: Backport [https://gitlab.freedesktop.org/poppler/poppler/-/commit/f54b815672117c250420787c8c006de98e8c7408]
+CVE: CVE-2025-43718
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ poppler/PDFDoc.cc | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/poppler/PDFDoc.cc b/poppler/PDFDoc.cc
+index a7c2e24..a779def 100644
+--- a/poppler/PDFDoc.cc
++++ b/poppler/PDFDoc.cc
+@@ -482,7 +482,7 @@ static PDFSubtypePart pdfPartFromString(PDFSubtype subtype, const std::string &p
+
+ static PDFSubtypeConformance pdfConformanceFromString(const std::string &pdfsubver)
+ {
+- const std::regex regex("PDF/(?:A|X|VT|E|UA)-[[:digit:]]([[:alpha:]]+)");
++ const std::regex regex("PDF/(?:A|X|VT|E|UA)-[[:digit:]]([[:alpha:]]{1,3})");
+ std::smatch match;
+ PDFSubtypeConformance pdfConf = subtypeConfNone;
+
+--
+2.25.1
+
diff --git a/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-43903-0001.patch b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-43903-0001.patch
new file mode 100644
index 0000000000..d18ff08ea0
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-43903-0001.patch
@@ -0,0 +1,75 @@
+From 33672ca1b6670f7378e24f6d475438f7f5d86b05 Mon Sep 17 00:00:00 2001
+From: Sune Vuorela <sune@vuorela.dk>
+Date: Mon, 22 May 2023 19:53:08 +0000
+Subject: [PATCH] Fix crash with weird hashing used for signatures
+
+CVE: CVE-2025-43903
+Upstream-Status: Backport [https://gitlab.freedesktop.org/poppler/poppler/-/commit/33672ca1b6670f7378e24f6d475438f7f5d86b05]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ poppler/SignatureHandler.cc | 15 ++++++++++++---
+ poppler/SignatureHandler.h | 7 ++++++-
+ 2 files changed, 18 insertions(+), 4 deletions(-)
+
+diff --git a/poppler/SignatureHandler.cc b/poppler/SignatureHandler.cc
+index 9916300..f0b7006 100644
+--- a/poppler/SignatureHandler.cc
++++ b/poppler/SignatureHandler.cc
+@@ -768,11 +768,11 @@ SignatureVerificationHandler::SignatureVerificationHandler(std::vector<unsigned
+ SECItem usedAlgorithm = NSS_CMSSignedData_GetDigestAlgs(CMSSignedData)[0]->algorithm;
+ auto hashAlgorithm = SECOID_FindOIDTag(&usedAlgorithm);
+ HASH_HashType hashType = HASH_GetHashTypeByOidTag(hashAlgorithm);
+- hashContext = std::make_unique<HashContext>(ConvertHashTypeFromNss(hashType));
++ hashContext = HashContext::create(ConvertHashTypeFromNss(hashType));
+ }
+ }
+
+-SignatureSignHandler::SignatureSignHandler(const std::string &certNickname, HashAlgorithm digestAlgTag) : hashContext(std::make_unique<HashContext>(digestAlgTag)), signing_cert(nullptr)
++SignatureSignHandler::SignatureSignHandler(const std::string &certNickname, HashAlgorithm digestAlgTag) : hashContext(HashContext::create(digestAlgTag)), signing_cert(nullptr)
+ {
+ SignatureHandler::setNSSDir({});
+ signing_cert = CERT_FindCertByNickname(CERT_GetDefaultCertDB(), certNickname.c_str());
+@@ -1232,7 +1232,16 @@ std::vector<unsigned char> HashContext::endHash()
+ return digestBuffer;
+ }
+
+-HashContext::HashContext(HashAlgorithm algorithm) : hash_context { HASH_Create(HASH_GetHashTypeByOidTag(ConvertHashAlgorithmToNss(algorithm))) }, digest_alg_tag(algorithm) { }
++HashContext::HashContext(HashAlgorithm algorithm, private_tag) : hash_context { HASH_Create(HASH_GetHashTypeByOidTag(ConvertHashAlgorithmToNss(algorithm))) }, digest_alg_tag(algorithm) { }
++
++std::unique_ptr<HashContext> HashContext::create(HashAlgorithm algorithm)
++{
++ auto ctx = std::make_unique<HashContext>(algorithm, private_tag {});
++ if (ctx->hash_context) {
++ return ctx;
++ }
++ return {};
++}
+
+ HashAlgorithm HashContext::getHashAlgorithm() const
+ {
+diff --git a/poppler/SignatureHandler.h b/poppler/SignatureHandler.h
+index c9fb575..f1b319f 100644
+--- a/poppler/SignatureHandler.h
++++ b/poppler/SignatureHandler.h
+@@ -51,12 +51,17 @@ static const int maxSupportedSignatureSize = 10000;
+
+ class HashContext
+ {
++ class private_tag
++ {
++ };
++
+ public:
+- explicit HashContext(HashAlgorithm algorithm);
++ HashContext(HashAlgorithm algorithm, private_tag);
+ void updateHash(unsigned char *data_block, int data_len);
+ std::vector<unsigned char> endHash();
+ HashAlgorithm getHashAlgorithm() const;
+ ~HashContext() = default;
++ static std::unique_ptr<HashContext> create(HashAlgorithm algorithm);
+
+ private:
+ struct HashDestroyer
+--
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-43903-0002.patch b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-43903-0002.patch
new file mode 100644
index 0000000000..dc2d1e7e6d
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-43903-0002.patch
@@ -0,0 +1,49 @@
+From f1b9c830f145a0042e853d6462b2f9ca4016c669 Mon Sep 17 00:00:00 2001
+From: Juraj sarinay <juraj@sarinay.com>
+Date: Thu, 6 Mar 2025 02:02:56 +0100
+Subject: [PATCH] Properly verify adbe.pkcs7.sha1 signatures.
+
+For signatures with non-empty encapsulated content
+(typically adbe.pkcs7.sha1), we only compared hash values and
+never actually checked SignatureValue within SignerInfo.
+The bug introduced by c7c0207b1cfe49a4353d6cda93dbebef4508138f
+made trivial signature forgeries possible. Fix this by calling
+NSS_CMSSignerInfo_Verify() after the hash values compare equal.
+
+CVE: CVE-2025-43903
+Upstream-Status: Backport [https://gitlab.freedesktop.org/poppler/poppler/-/commit/f1b9c830f145a0042e853d6462b2f9ca4016c669]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ poppler/SignatureHandler.cc | 11 +++++++++--
+ 1 file changed, 9 insertions(+), 2 deletions(-)
+
+diff --git a/poppler/SignatureHandler.cc b/poppler/SignatureHandler.cc
+index 9916300..5c478bc 100644
+--- a/poppler/SignatureHandler.cc
++++ b/poppler/SignatureHandler.cc
+@@ -934,13 +934,20 @@ SignatureValidationStatus SignatureVerificationHandler::validateSignature()
+ This means it's not a detached type signature
+ so the digest is contained in SignedData->contentInfo
+ */
+- if (digest.len == content_info_data->len && memcmp(digest.data, content_info_data->data, digest.len) == 0) {
++ if (digest.len != content_info_data->len || memcmp(digest.data, content_info_data->data, digest.len) != 0) {
+ return SIGNATURE_VALID;
+ } else {
+ return SIGNATURE_DIGEST_MISMATCH;
+ }
+
+- } else if (NSS_CMSSignerInfo_Verify(CMSSignerInfo, &digest, nullptr) != SECSuccess) {
++ auto innerHashContext = HashContext::create(hashContext->getHashAlgorithm());
++ innerHashContext->updateHash(content_info_data->data, content_info_data->len);
++ digest_buffer = innerHashContext->endHash();
++ digest.data = digest_buffer.data();
++ digest.len = digest_buffer.size();
++ }
++
++ if (NSS_CMSSignerInfo_Verify(CMSSignerInfo, &digest, nullptr) != SECSuccess) {
+ return NSS_SigTranslate(CMSSignerInfo->verificationStatus);
+ } else {
+ return SIGNATURE_VALID;
+--
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-50420.patch b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-50420.patch
new file mode 100644
index 0000000000..a6396eeba2
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-50420.patch
@@ -0,0 +1,38 @@
+From a7025904e3330dd6cf95f3664ef6fc77034cc5e1 Mon Sep 17 00:00:00 2001
+From: Sune Vuorela <sune@vuorela.dk>
+Date: Tue, 29 Jul 2025 14:14:00 +0200
+Subject: [PATCH] Fix crash in pdfseparate
+
+Don't continue recursing in PDFDoc::mark* if things looks a bit weirder
+than expected
+
+CVE: CVE-2025-50420
+Upstream-Status: Backport [https://gitlab.freedesktop.org/poppler/poppler/-/commit/a7025904e3330dd6cf95f3664ef6fc77034cc5e1]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ poppler/PDFDoc.cc | 9 +++++++++
+ 1 file changed, 9 insertions(+)
+
+diff --git a/poppler/PDFDoc.cc b/poppler/PDFDoc.cc
+index 872841c..a7c2e24 100644
+--- a/poppler/PDFDoc.cc
++++ b/poppler/PDFDoc.cc
+@@ -1818,6 +1818,15 @@ bool PDFDoc::markAnnotations(Object *annotsObj, XRef *xRef, XRef *countRef, unsi
+ if (obj1.isDict()) {
+ Dict *dict = obj1.getDict();
+ Object type = dict->lookup("Type");
++ if (type.isNull()) {
++ Object subType = dict->lookup("SubType");
++ // Type is optional, subtype is required
++ // If neither of them exists, something is probably
++ // weird here, so let us just skip this entry
++ if (subType.isNull()) {
++ continue;
++ }
++ }
+ if (type.isName() && strcmp(type.getName(), "Annot") == 0) {
+ const Object &obj2 = dict->lookupNF("P");
+ if (obj2.isRef()) {
+--
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-52885.patch b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-52885.patch
new file mode 100644
index 0000000000..a48b2c01a6
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-52885.patch
@@ -0,0 +1,30 @@
+From 4ce27cc826bf90cc8dbbd8a8c87bd913cccd7ec0 Mon Sep 17 00:00:00 2001
+From: Kevin Backhouse <kevinbackhouse@github.com>
+Date: Wed, 3 Sep 2025 14:36:54 +0100
+Subject: [PATCH] Check for duplicate entries
+
+CVE: CVE-2025-52885
+Upstream-Status: Backport [https://gitlab.freedesktop.org/poppler/poppler/-/commit/4ce27cc826bf90cc8dbbd8a8c87bd913cccd7ec0]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ poppler/StructTreeRoot.cc | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/poppler/StructTreeRoot.cc b/poppler/StructTreeRoot.cc
+index 47adac9..10db9aa 100644
+--- a/poppler/StructTreeRoot.cc
++++ b/poppler/StructTreeRoot.cc
+@@ -137,6 +137,10 @@ void StructTreeRoot::parseNumberTreeNode(Dict *node)
+ }
+ int keyVal = key.getInt();
+ std::vector<Parent> &vec = parentTree[keyVal];
++ if (!vec.empty()) {
++ error(errSyntaxError, -1, "Nums item at position {0:d} is a duplicate entry for key {1:d}", i, keyVal);
++ continue;
++ }
+
+ Object valueArray = nums.arrayGet(i + 1);
+ if (valueArray.isArray()) {
+--
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-52886-0001.patch b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-52886-0001.patch
new file mode 100644
index 0000000000..4de3f8bcdc
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-52886-0001.patch
@@ -0,0 +1,4319 @@
+From f2f933100eb18ade38ece640343007290c609e21 Mon Sep 17 00:00:00 2001
+From: Sune Vuorela <sune@vuorela.dk>
+Date: Wed, 2 Apr 2025 16:19:28 +0200
+Subject: [PATCH] Annot: Do refcount with shared_ptr
+
+Manage annots by shared_ptr rather than the manual ref/deref usage.
+
+Also do a bit more documentation of ownerships with unique ptr's
+
+CVE: CVE-2025-52886
+Upstream-Status: Backport [https://gitlab.freedesktop.org/poppler/poppler/-/commit/3449a16d3b1389870eb3e20795e802c6ae8bc04f]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ glib/poppler-annot.cc | 158 +++++------
+ glib/poppler-page.cc | 8 +-
+ glib/poppler-private.h | 24 +-
+ poppler/Annot.cc | 143 ++++------
+ poppler/Annot.h | 34 +--
+ poppler/FontInfo.cc | 2 +-
+ poppler/Form.cc | 11 +-
+ poppler/Form.h | 6 +-
+ poppler/JSInfo.cc | 8 +-
+ poppler/Link.cc | 14 +-
+ poppler/Link.h | 4 +-
+ poppler/PDFDoc.cc | 2 +-
+ poppler/PSOutputDev.cc | 2 +-
+ poppler/Page.cc | 39 ++-
+ poppler/Page.h | 8 +-
+ qt5/src/poppler-annotation-private.h | 10 +-
+ qt5/src/poppler-annotation.cc | 393 +++++++++++++--------------
+ qt5/src/poppler-form.cc | 4 +-
+ qt6/src/poppler-annotation-private.h | 10 +-
+ qt6/src/poppler-annotation.cc | 393 +++++++++++++--------------
+ qt6/src/poppler-form.cc | 4 +-
+ utils/HtmlOutputDev.cc | 4 +-
+ utils/pdfdetach.cc | 4 +-
+ utils/pdfinfo.cc | 2 +-
+ 24 files changed, 582 insertions(+), 705 deletions(-)
+
+diff --git a/glib/poppler-annot.cc b/glib/poppler-annot.cc
+index b995f03..6fb7807 100644
+--- a/glib/poppler-annot.cc
++++ b/glib/poppler-annot.cc
+@@ -19,6 +19,7 @@
+ * Foundation, Inc., 51 Franklin Street - Fifth Floor, Boston, MA 02110-1301, USA.
+ */
+
++#include "AnnotStampImageHelper.h"
+ #include "config.h"
+ #include "poppler.h"
+ #include "poppler-private.h"
+@@ -26,7 +27,7 @@
+ #define ZERO_CROPBOX(c) (!(c && (c->x1 > 0.01 || c->y1 > 0.01)))
+
+ const PDFRectangle *_poppler_annot_get_cropbox_and_page(PopplerAnnot *poppler_annot, Page **page_out);
+-AnnotStampImageHelper *_poppler_convert_cairo_image_to_stamp_image_helper(cairo_surface_t *image, PDFDoc *doc, GError **error);
++std::unique_ptr<AnnotStampImageHelper> _poppler_convert_cairo_image_to_stamp_image_helper(cairo_surface_t *image, PDFDoc *doc, GError **error);
+
+ /**
+ * SECTION:poppler-annot
+@@ -177,13 +178,12 @@ G_DEFINE_TYPE(PopplerAnnotCircle, poppler_annot_circle, POPPLER_TYPE_ANNOT_MARKU
+ G_DEFINE_TYPE(PopplerAnnotSquare, poppler_annot_square, POPPLER_TYPE_ANNOT_MARKUP)
+ G_DEFINE_TYPE(PopplerAnnotStamp, poppler_annot_stamp, POPPLER_TYPE_ANNOT)
+
+-static PopplerAnnot *_poppler_create_annot(GType annot_type, Annot *annot)
++static PopplerAnnot *_poppler_create_annot(GType annot_type, std::shared_ptr<Annot> annot)
+ {
+ PopplerAnnot *poppler_annot;
+
+ poppler_annot = POPPLER_ANNOT(g_object_new(annot_type, nullptr));
+- poppler_annot->annot = annot;
+- annot->incRefCnt();
++ poppler_annot->annot = std::move(annot);
+
+ return poppler_annot;
+ }
+@@ -193,8 +193,7 @@ static void poppler_annot_finalize(GObject *object)
+ PopplerAnnot *poppler_annot = POPPLER_ANNOT(object);
+
+ if (poppler_annot->annot) {
+- poppler_annot->annot->decRefCnt();
+- poppler_annot->annot = nullptr;
++ poppler_annot->annot.reset();
+ }
+
+ G_OBJECT_CLASS(poppler_annot_parent_class)->finalize(object);
+@@ -209,7 +208,7 @@ static void poppler_annot_class_init(PopplerAnnotClass *klass)
+ gobject_class->finalize = poppler_annot_finalize;
+ }
+
+-PopplerAnnot *_poppler_annot_new(Annot *annot)
++PopplerAnnot *_poppler_annot_new(const std::shared_ptr<Annot> &annot)
+ {
+ return _poppler_create_annot(POPPLER_TYPE_ANNOT, annot);
+ }
+@@ -222,7 +221,7 @@ static void poppler_annot_text_init(PopplerAnnotText *poppler_annot) { }
+
+ static void poppler_annot_text_class_init(PopplerAnnotTextClass *klass) { }
+
+-PopplerAnnot *_poppler_annot_text_new(Annot *annot)
++PopplerAnnot *_poppler_annot_text_new(const std::shared_ptr<Annot> &annot)
+ {
+ return _poppler_create_annot(POPPLER_TYPE_ANNOT_TEXT, annot);
+ }
+@@ -242,15 +241,14 @@ PopplerAnnot *_poppler_annot_text_new(Annot *annot)
+ */
+ PopplerAnnot *poppler_annot_text_new(PopplerDocument *doc, PopplerRectangle *rect)
+ {
+- Annot *annot;
+ PDFRectangle pdf_rect(rect->x1, rect->y1, rect->x2, rect->y2);
+
+- annot = new AnnotText(doc->doc, &pdf_rect);
++ auto annot = std::make_shared<AnnotText>(doc->doc, &pdf_rect);
+
+ return _poppler_annot_text_new(annot);
+ }
+
+-PopplerAnnot *_poppler_annot_text_markup_new(Annot *annot)
++PopplerAnnot *_poppler_annot_text_markup_new(const std::shared_ptr<Annot> &annot)
+ {
+ return _poppler_create_annot(POPPLER_TYPE_ANNOT_TEXT_MARKUP, annot);
+ }
+@@ -323,10 +321,9 @@ static void poppler_annot_text_markup_class_init(PopplerAnnotTextMarkupClass *kl
+ PopplerAnnot *poppler_annot_text_markup_new_highlight(PopplerDocument *doc, PopplerRectangle *rect, GArray *quadrilaterals)
+ {
+ PopplerAnnot *poppler_annot;
+- AnnotTextMarkup *annot;
+ PDFRectangle pdf_rect(rect->x1, rect->y1, rect->x2, rect->y2);
+
+- annot = new AnnotTextMarkup(doc->doc, &pdf_rect, Annot::typeHighlight);
++ auto annot = std::make_shared<AnnotTextMarkup>(doc->doc, &pdf_rect, Annot::typeHighlight);
+
+ poppler_annot = _poppler_annot_text_markup_new(annot);
+ poppler_annot_text_markup_set_quadrilaterals(POPPLER_ANNOT_TEXT_MARKUP(poppler_annot), quadrilaterals);
+@@ -350,12 +347,11 @@ PopplerAnnot *poppler_annot_text_markup_new_highlight(PopplerDocument *doc, Popp
+ PopplerAnnot *poppler_annot_text_markup_new_squiggly(PopplerDocument *doc, PopplerRectangle *rect, GArray *quadrilaterals)
+ {
+ PopplerAnnot *poppler_annot;
+- AnnotTextMarkup *annot;
+ PDFRectangle pdf_rect(rect->x1, rect->y1, rect->x2, rect->y2);
+
+ g_return_val_if_fail(quadrilaterals != nullptr && quadrilaterals->len > 0, NULL);
+
+- annot = new AnnotTextMarkup(doc->doc, &pdf_rect, Annot::typeSquiggly);
++ auto annot = std::make_shared<AnnotTextMarkup>(doc->doc, &pdf_rect, Annot::typeSquiggly);
+
+ poppler_annot = _poppler_annot_text_markup_new(annot);
+ poppler_annot_text_markup_set_quadrilaterals(POPPLER_ANNOT_TEXT_MARKUP(poppler_annot), quadrilaterals);
+@@ -379,12 +375,11 @@ PopplerAnnot *poppler_annot_text_markup_new_squiggly(PopplerDocument *doc, Poppl
+ PopplerAnnot *poppler_annot_text_markup_new_strikeout(PopplerDocument *doc, PopplerRectangle *rect, GArray *quadrilaterals)
+ {
+ PopplerAnnot *poppler_annot;
+- AnnotTextMarkup *annot;
+ PDFRectangle pdf_rect(rect->x1, rect->y1, rect->x2, rect->y2);
+
+ g_return_val_if_fail(quadrilaterals != nullptr && quadrilaterals->len > 0, NULL);
+
+- annot = new AnnotTextMarkup(doc->doc, &pdf_rect, Annot::typeStrikeOut);
++ auto annot = std::make_shared<AnnotTextMarkup>(doc->doc, &pdf_rect, Annot::typeStrikeOut);
+
+ poppler_annot = _poppler_annot_text_markup_new(annot);
+ poppler_annot_text_markup_set_quadrilaterals(POPPLER_ANNOT_TEXT_MARKUP(poppler_annot), quadrilaterals);
+@@ -408,12 +403,11 @@ PopplerAnnot *poppler_annot_text_markup_new_strikeout(PopplerDocument *doc, Popp
+ PopplerAnnot *poppler_annot_text_markup_new_underline(PopplerDocument *doc, PopplerRectangle *rect, GArray *quadrilaterals)
+ {
+ PopplerAnnot *poppler_annot;
+- AnnotTextMarkup *annot;
+ PDFRectangle pdf_rect(rect->x1, rect->y1, rect->x2, rect->y2);
+
+ g_return_val_if_fail(quadrilaterals != nullptr && quadrilaterals->len > 0, NULL);
+
+- annot = new AnnotTextMarkup(doc->doc, &pdf_rect, Annot::typeUnderline);
++ auto annot = std::make_shared<AnnotTextMarkup>(doc->doc, &pdf_rect, Annot::typeUnderline);
+
+ poppler_annot = _poppler_annot_text_markup_new(annot);
+ poppler_annot_text_markup_set_quadrilaterals(POPPLER_ANNOT_TEXT_MARKUP(poppler_annot), quadrilaterals);
+@@ -424,7 +418,7 @@ static void poppler_annot_free_text_init(PopplerAnnotFreeText *poppler_annot) {
+
+ static void poppler_annot_free_text_class_init(PopplerAnnotFreeTextClass *klass) { }
+
+-PopplerAnnot *_poppler_annot_free_text_new(Annot *annot)
++PopplerAnnot *_poppler_annot_free_text_new(const std::shared_ptr<Annot> &annot)
+ {
+ return _poppler_create_annot(POPPLER_TYPE_ANNOT_FREE_TEXT, annot);
+ }
+@@ -433,7 +427,7 @@ static void poppler_annot_file_attachment_init(PopplerAnnotFileAttachment *poppl
+
+ static void poppler_annot_file_attachment_class_init(PopplerAnnotFileAttachmentClass *klass) { }
+
+-PopplerAnnot *_poppler_annot_file_attachment_new(Annot *annot)
++PopplerAnnot *_poppler_annot_file_attachment_new(const std::shared_ptr<Annot> &annot)
+ {
+ return _poppler_create_annot(POPPLER_TYPE_ANNOT_FILE_ATTACHMENT, annot);
+ }
+@@ -459,13 +453,13 @@ static void poppler_annot_movie_class_init(PopplerAnnotMovieClass *klass)
+ gobject_class->finalize = poppler_annot_movie_finalize;
+ }
+
+-PopplerAnnot *_poppler_annot_movie_new(Annot *annot)
++PopplerAnnot *_poppler_annot_movie_new(const std::shared_ptr<Annot> &annot)
+ {
+ PopplerAnnot *poppler_annot;
+ AnnotMovie *annot_movie;
+
+ poppler_annot = _poppler_create_annot(POPPLER_TYPE_ANNOT_MOVIE, annot);
+- annot_movie = static_cast<AnnotMovie *>(poppler_annot->annot);
++ annot_movie = static_cast<AnnotMovie *>(poppler_annot->annot.get());
+ POPPLER_ANNOT_MOVIE(poppler_annot)->movie = _poppler_movie_new(annot_movie->getMovie());
+
+ return poppler_annot;
+@@ -492,14 +486,14 @@ static void poppler_annot_screen_class_init(PopplerAnnotScreenClass *klass)
+ gobject_class->finalize = poppler_annot_screen_finalize;
+ }
+
+-PopplerAnnot *_poppler_annot_screen_new(PopplerDocument *doc, Annot *annot)
++PopplerAnnot *_poppler_annot_screen_new(PopplerDocument *doc, const std::shared_ptr<Annot> &annot)
+ {
+ PopplerAnnot *poppler_annot;
+ AnnotScreen *annot_screen;
+ LinkAction *action;
+
+ poppler_annot = _poppler_create_annot(POPPLER_TYPE_ANNOT_SCREEN, annot);
+- annot_screen = static_cast<AnnotScreen *>(poppler_annot->annot);
++ annot_screen = static_cast<AnnotScreen *>(poppler_annot->annot.get());
+ action = annot_screen->getAction();
+ if (action) {
+ POPPLER_ANNOT_SCREEN(poppler_annot)->action = _poppler_action_new(doc, action, nullptr);
+@@ -508,7 +502,7 @@ PopplerAnnot *_poppler_annot_screen_new(PopplerDocument *doc, Annot *annot)
+ return poppler_annot;
+ }
+
+-PopplerAnnot *_poppler_annot_line_new(Annot *annot)
++PopplerAnnot *_poppler_annot_line_new(const std::shared_ptr<Annot> &annot)
+ {
+ return _poppler_create_annot(POPPLER_TYPE_ANNOT_LINE, annot);
+ }
+@@ -535,17 +529,16 @@ static void poppler_annot_line_class_init(PopplerAnnotLineClass *klass) { }
+ PopplerAnnot *poppler_annot_line_new(PopplerDocument *doc, PopplerRectangle *rect, PopplerPoint *start, PopplerPoint *end)
+ {
+ PopplerAnnot *poppler_annot;
+- Annot *annot;
+ PDFRectangle pdf_rect(rect->x1, rect->y1, rect->x2, rect->y2);
+
+- annot = new AnnotLine(doc->doc, &pdf_rect);
++ auto annot = std::make_shared<AnnotLine>(doc->doc, &pdf_rect);
+
+ poppler_annot = _poppler_annot_line_new(annot);
+ poppler_annot_line_set_vertices(POPPLER_ANNOT_LINE(poppler_annot), start, end);
+ return poppler_annot;
+ }
+
+-PopplerAnnot *_poppler_annot_circle_new(Annot *annot)
++PopplerAnnot *_poppler_annot_circle_new(const std::shared_ptr<Annot> &annot)
+ {
+ return _poppler_create_annot(POPPLER_TYPE_ANNOT_CIRCLE, annot);
+ }
+@@ -569,15 +562,14 @@ static void poppler_annot_circle_class_init(PopplerAnnotCircleClass *klass) { }
+ **/
+ PopplerAnnot *poppler_annot_circle_new(PopplerDocument *doc, PopplerRectangle *rect)
+ {
+- Annot *annot;
+ PDFRectangle pdf_rect(rect->x1, rect->y1, rect->x2, rect->y2);
+
+- annot = new AnnotGeometry(doc->doc, &pdf_rect, Annot::typeCircle);
++ auto annot = std::make_shared<AnnotGeometry>(doc->doc, &pdf_rect, Annot::typeCircle);
+
+ return _poppler_annot_circle_new(annot);
+ }
+
+-PopplerAnnot *_poppler_annot_square_new(Annot *annot)
++PopplerAnnot *_poppler_annot_square_new(const std::shared_ptr<Annot> &annot)
+ {
+ return _poppler_create_annot(POPPLER_TYPE_ANNOT_SQUARE, annot);
+ }
+@@ -601,10 +593,9 @@ static void poppler_annot_square_class_init(PopplerAnnotSquareClass *klass) { }
+ **/
+ PopplerAnnot *poppler_annot_square_new(PopplerDocument *doc, PopplerRectangle *rect)
+ {
+- Annot *annot;
+ PDFRectangle pdf_rect(rect->x1, rect->y1, rect->x2, rect->y2);
+
+- annot = new AnnotGeometry(doc->doc, &pdf_rect, Annot::typeSquare);
++ auto annot = std::make_shared<AnnotGeometry>(doc->doc, &pdf_rect, Annot::typeSquare);
+
+ return _poppler_annot_square_new(annot);
+ }
+@@ -623,7 +614,7 @@ static void poppler_annot_stamp_class_init(PopplerAnnotStampClass *klass)
+ gobject_class->finalize = poppler_annot_stamp_finalize;
+ }
+
+-PopplerAnnot *_poppler_annot_stamp_new(Annot *annot)
++PopplerAnnot *_poppler_annot_stamp_new(const std::shared_ptr<Annot> &annot)
+ {
+ PopplerAnnot *poppler_annot;
+
+@@ -647,10 +638,9 @@ PopplerAnnot *_poppler_annot_stamp_new(Annot *annot)
+ **/
+ PopplerAnnot *poppler_annot_stamp_new(PopplerDocument *doc, PopplerRectangle *rect)
+ {
+- Annot *annot;
+ PDFRectangle pdf_rect(rect->x1, rect->y1, rect->x2, rect->y2);
+
+- annot = new AnnotStamp(doc->doc, &pdf_rect);
++ auto annot = std::make_shared<AnnotStamp>(doc->doc, &pdf_rect);
+
+ return _poppler_annot_stamp_new(annot);
+ }
+@@ -699,9 +689,9 @@ static gboolean get_raw_data_from_cairo_image(cairo_surface_t *image, cairo_form
+ return FALSE;
+ }
+
+-AnnotStampImageHelper *_poppler_convert_cairo_image_to_stamp_image_helper(cairo_surface_t *image, PDFDoc *doc, GError **error)
++std::unique_ptr<AnnotStampImageHelper> _poppler_convert_cairo_image_to_stamp_image_helper(cairo_surface_t *image, PDFDoc *doc, GError **error)
+ {
+- AnnotStampImageHelper *annotImg;
++ std::unique_ptr<AnnotStampImageHelper> annotImg;
+ GByteArray *data;
+ GByteArray *sMaskData;
+
+@@ -733,9 +723,9 @@ AnnotStampImageHelper *_poppler_convert_cairo_image_to_stamp_image_helper(cairo_
+
+ if (sMaskData->len > 0) {
+ AnnotStampImageHelper sMask(doc, width, height, ColorSpace::DeviceGray, 8, (char *)sMaskData->data, (int)sMaskData->len);
+- annotImg = new AnnotStampImageHelper(doc, width, height, colorSpace, bitsPerComponent, (char *)data->data, (int)data->len, sMask.getRef());
++ annotImg = std::make_unique<AnnotStampImageHelper>(doc, width, height, colorSpace, bitsPerComponent, (char *)data->data, (int)data->len, sMask.getRef());
+ } else {
+- annotImg = new AnnotStampImageHelper(doc, width, height, colorSpace, bitsPerComponent, (char *)data->data, (int)data->len);
++ annotImg = std::make_unique<AnnotStampImageHelper>(doc, width, height, colorSpace, bitsPerComponent, (char *)data->data, (int)data->len);
+ }
+
+ g_byte_array_unref(data);
+@@ -1128,7 +1118,7 @@ void poppler_annot_set_rectangle(PopplerAnnot *poppler_annot, PopplerRectangle *
+ if (page && SUPPORTED_ROTATION(page->getRotate())) {
+ /* annot is inside a rotated page, as core poppler rect must be saved
+ * un-rotated, let's proceed to un-rotate rect before saving */
+- _unrotate_rect_for_annot_and_page(page, poppler_annot->annot, &x1, &y1, &x2, &y2);
++ _unrotate_rect_for_annot_and_page(page, poppler_annot->annot.get(), &x1, &y1, &x2, &y2);
+ }
+
+ poppler_annot->annot->setRect(x1 + crop_box->x1, y1 + crop_box->y1, x2 + crop_box->x1, y2 + crop_box->y1);
+@@ -1150,7 +1140,7 @@ gchar *poppler_annot_markup_get_label(PopplerAnnotMarkup *poppler_annot)
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_MARKUP(poppler_annot), NULL);
+
+- annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ text = annot->getLabel();
+
+@@ -1174,7 +1164,7 @@ void poppler_annot_markup_set_label(PopplerAnnotMarkup *poppler_annot, const gch
+
+ g_return_if_fail(POPPLER_IS_ANNOT_MARKUP(poppler_annot));
+
+- annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ tmp = label ? g_convert(label, -1, "UTF-16BE", "UTF-8", nullptr, &length, nullptr) : nullptr;
+ annot->setLabel(std::make_unique<GooString>(tmp, length));
+@@ -1197,7 +1187,7 @@ gboolean poppler_annot_markup_has_popup(PopplerAnnotMarkup *poppler_annot)
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_MARKUP(poppler_annot), FALSE);
+
+- annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ return annot->getPopup() != nullptr;
+ }
+@@ -1219,8 +1209,8 @@ void poppler_annot_markup_set_popup(PopplerAnnotMarkup *poppler_annot, PopplerRe
+
+ g_return_if_fail(POPPLER_IS_ANNOT_MARKUP(poppler_annot));
+
+- annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot);
+- annot->setPopup(std::make_unique<AnnotPopup>(annot->getDoc(), &pdf_rect));
++ annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot.get());
++ annot->setPopup(std::make_shared<AnnotPopup>(annot->getDoc(), &pdf_rect));
+ }
+
+ /**
+@@ -1239,9 +1229,9 @@ gboolean poppler_annot_markup_get_popup_is_open(PopplerAnnotMarkup *poppler_anno
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_MARKUP(poppler_annot), FALSE);
+
+- annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+- if ((annot_popup = annot->getPopup())) {
++ if ((annot_popup = annot->getPopup().get())) {
+ return annot_popup->getOpen();
+ }
+
+@@ -1264,9 +1254,9 @@ void poppler_annot_markup_set_popup_is_open(PopplerAnnotMarkup *poppler_annot, g
+
+ g_return_if_fail(POPPLER_IS_ANNOT_MARKUP(poppler_annot));
+
+- annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+- annot_popup = annot->getPopup();
++ annot_popup = annot->getPopup().get();
+ if (!annot_popup) {
+ return;
+ }
+@@ -1295,8 +1285,8 @@ gboolean poppler_annot_markup_get_popup_rectangle(PopplerAnnotMarkup *poppler_an
+ g_return_val_if_fail(POPPLER_IS_ANNOT_MARKUP(poppler_annot), FALSE);
+ g_return_val_if_fail(poppler_rect != nullptr, FALSE);
+
+- annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot);
+- annot_popup = annot->getPopup();
++ annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot.get());
++ annot_popup = annot->getPopup().get();
+ if (!annot_popup) {
+ return FALSE;
+ }
+@@ -1330,8 +1320,8 @@ void poppler_annot_markup_set_popup_rectangle(PopplerAnnotMarkup *poppler_annot,
+ g_return_if_fail(POPPLER_IS_ANNOT_MARKUP(poppler_annot));
+ g_return_if_fail(poppler_rect != nullptr);
+
+- annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot);
+- annot_popup = annot->getPopup();
++ annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot.get());
++ annot_popup = annot->getPopup().get();
+ if (!annot_popup) {
+ return;
+ }
+@@ -1354,7 +1344,7 @@ gdouble poppler_annot_markup_get_opacity(PopplerAnnotMarkup *poppler_annot)
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_MARKUP(poppler_annot), 0);
+
+- annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ return annot->getOpacity();
+ }
+@@ -1376,7 +1366,7 @@ void poppler_annot_markup_set_opacity(PopplerAnnotMarkup *poppler_annot, gdouble
+
+ g_return_if_fail(POPPLER_IS_ANNOT_MARKUP(poppler_annot));
+
+- annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+ annot->setOpacity(opacity);
+ }
+
+@@ -1397,7 +1387,7 @@ GDate *poppler_annot_markup_get_date(PopplerAnnotMarkup *poppler_annot)
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_MARKUP(poppler_annot), NULL);
+
+- annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+ annot_date = annot->getDate();
+ if (!annot_date) {
+ return nullptr;
+@@ -1430,7 +1420,7 @@ gchar *poppler_annot_markup_get_subject(PopplerAnnotMarkup *poppler_annot)
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_MARKUP(poppler_annot), NULL);
+
+- annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ text = annot->getSubject();
+
+@@ -1451,7 +1441,7 @@ PopplerAnnotMarkupReplyType poppler_annot_markup_get_reply_to(PopplerAnnotMarkup
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_MARKUP(poppler_annot), POPPLER_ANNOT_MARKUP_REPLY_TYPE_R);
+
+- annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ switch (annot->getReplyTo()) {
+ case AnnotMarkup::replyTypeR:
+@@ -1479,7 +1469,7 @@ PopplerAnnotExternalDataType poppler_annot_markup_get_external_data(PopplerAnnot
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_MARKUP(poppler_annot), POPPLER_ANNOT_EXTERNAL_DATA_MARKUP_UNKNOWN);
+
+- annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotMarkup *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ switch (annot->getExData()) {
+ case annotExternalDataMarkup3D:
+@@ -1509,7 +1499,7 @@ gboolean poppler_annot_text_get_is_open(PopplerAnnotText *poppler_annot)
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_TEXT(poppler_annot), FALSE);
+
+- annot = static_cast<AnnotText *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotText *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ return annot->getOpen();
+ }
+@@ -1529,7 +1519,7 @@ void poppler_annot_text_set_is_open(PopplerAnnotText *poppler_annot, gboolean is
+
+ g_return_if_fail(POPPLER_IS_ANNOT_TEXT(poppler_annot));
+
+- annot = static_cast<AnnotText *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotText *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+ annot->setOpen(is_open);
+ }
+
+@@ -1548,7 +1538,7 @@ gchar *poppler_annot_text_get_icon(PopplerAnnotText *poppler_annot)
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_TEXT(poppler_annot), NULL);
+
+- annot = static_cast<AnnotText *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotText *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ text = annot->getIcon();
+
+@@ -1601,7 +1591,7 @@ void poppler_annot_text_set_icon(PopplerAnnotText *poppler_annot, const gchar *i
+
+ g_return_if_fail(POPPLER_IS_ANNOT_TEXT(poppler_annot));
+
+- annot = static_cast<AnnotText *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotText *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ text = new GooString(icon);
+ annot->setIcon(text);
+@@ -1622,7 +1612,7 @@ PopplerAnnotTextState poppler_annot_text_get_state(PopplerAnnotText *poppler_ann
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_TEXT(poppler_annot), POPPLER_ANNOT_TEXT_STATE_UNKNOWN);
+
+- annot = static_cast<AnnotText *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotText *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ switch (annot->getState()) {
+ case AnnotText::stateUnknown:
+@@ -1669,7 +1659,7 @@ void poppler_annot_text_markup_set_quadrilaterals(PopplerAnnotTextMarkup *popple
+ g_return_if_fail(POPPLER_IS_ANNOT_TEXT_MARKUP(poppler_annot));
+ g_return_if_fail(quadrilaterals != nullptr && quadrilaterals->len > 0);
+
+- annot = static_cast<AnnotTextMarkup *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotTextMarkup *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+ crop_box = _poppler_annot_get_cropbox_and_page(POPPLER_ANNOT(poppler_annot), &page);
+ quads = create_annot_quads_from_poppler_quads(quadrilaterals);
+
+@@ -1708,7 +1698,7 @@ GArray *poppler_annot_text_markup_get_quadrilaterals(PopplerAnnotTextMarkup *pop
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_TEXT_MARKUP(poppler_annot), NULL);
+
+- annot = static_cast<AnnotTextMarkup *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotTextMarkup *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+ crop_box = _poppler_annot_get_cropbox(POPPLER_ANNOT(poppler_annot));
+ AnnotQuadrilaterals *quads = annot->getQuadrilaterals();
+
+@@ -1730,7 +1720,7 @@ PopplerAnnotFreeTextQuadding poppler_annot_free_text_get_quadding(PopplerAnnotFr
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_FREE_TEXT(poppler_annot), POPPLER_ANNOT_FREE_TEXT_QUADDING_LEFT_JUSTIFIED);
+
+- annot = static_cast<AnnotFreeText *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotFreeText *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ switch (annot->getQuadding()) {
+ case VariableTextQuadding::leftJustified:
+@@ -1764,7 +1754,7 @@ PopplerAnnotCalloutLine *poppler_annot_free_text_get_callout_line(PopplerAnnotFr
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_FREE_TEXT(poppler_annot), NULL);
+
+- annot = static_cast<AnnotFreeText *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotFreeText *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ if ((line = annot->getCalloutLine())) {
+ AnnotCalloutMultiLine *multiline;
+@@ -1808,11 +1798,10 @@ PopplerAttachment *poppler_annot_file_attachment_get_attachment(PopplerAnnotFile
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_FILE_ATTACHMENT(poppler_annot), NULL);
+
+- annot = static_cast<AnnotFileAttachment *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotFileAttachment *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+- FileSpec *file = new FileSpec(annot->getFile());
+- attachment = _poppler_attachment_new(file);
+- delete file;
++ FileSpec file { annot->getFile() };
++ attachment = _poppler_attachment_new(&file);
+
+ return attachment;
+ }
+@@ -1834,7 +1823,7 @@ gchar *poppler_annot_file_attachment_get_name(PopplerAnnotFileAttachment *popple
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_FILE_ATTACHMENT(poppler_annot), NULL);
+
+- annot = static_cast<AnnotFileAttachment *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotFileAttachment *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+ name = annot->getName();
+
+ return name ? _poppler_goo_string_to_utf8(name) : nullptr;
+@@ -1906,7 +1895,7 @@ gchar *poppler_annot_movie_get_title(PopplerAnnotMovie *poppler_annot)
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_MOVIE(poppler_annot), NULL);
+
+- annot = static_cast<AnnotMovie *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotMovie *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ title = annot->getTitle();
+
+@@ -1965,7 +1954,7 @@ void poppler_annot_line_set_vertices(PopplerAnnotLine *poppler_annot, PopplerPoi
+ g_return_if_fail(start != nullptr);
+ g_return_if_fail(end != nullptr);
+
+- annot = static_cast<AnnotLine *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotLine *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+ annot->setVertices(start->x, start->y, end->x, end->y);
+ }
+
+@@ -1974,7 +1963,7 @@ static PopplerColor *poppler_annot_geometry_get_interior_color(PopplerAnnot *pop
+ {
+ AnnotGeometry *annot;
+
+- annot = static_cast<AnnotGeometry *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotGeometry *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ return create_poppler_color_from_annot_color(annot->getInteriorColor());
+ }
+@@ -1983,7 +1972,7 @@ static void poppler_annot_geometry_set_interior_color(PopplerAnnot *poppler_anno
+ {
+ AnnotGeometry *annot;
+
+- annot = static_cast<AnnotGeometry *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotGeometry *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ annot->setInteriorColor(create_annot_color_from_poppler_color(poppler_color));
+ }
+@@ -2073,7 +2062,7 @@ PopplerAnnotStampIcon poppler_annot_stamp_get_icon(PopplerAnnotStamp *poppler_an
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_STAMP(poppler_annot), POPPLER_ANNOT_STAMP_ICON_UNKNOWN);
+
+- annot = static_cast<AnnotStamp *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotStamp *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ text = annot->getIcon();
+
+@@ -2129,7 +2118,7 @@ void poppler_annot_stamp_set_icon(PopplerAnnotStamp *poppler_annot, PopplerAnnot
+
+ g_return_if_fail(POPPLER_IS_ANNOT_STAMP(poppler_annot));
+
+- annot = static_cast<AnnotStamp *>(POPPLER_ANNOT(poppler_annot)->annot);
++ annot = static_cast<AnnotStamp *>(POPPLER_ANNOT(poppler_annot)->annot.get());
+
+ if (icon == POPPLER_ANNOT_STAMP_ICON_NONE) {
+ annot->setIcon(nullptr);
+@@ -2186,16 +2175,15 @@ void poppler_annot_stamp_set_icon(PopplerAnnotStamp *poppler_annot, PopplerAnnot
+ gboolean poppler_annot_stamp_set_custom_image(PopplerAnnotStamp *poppler_annot, cairo_surface_t *image, GError **error)
+ {
+ AnnotStamp *annot;
+- AnnotStampImageHelper *annot_image_helper;
+
+ g_return_val_if_fail(POPPLER_IS_ANNOT_STAMP(poppler_annot), FALSE);
+
+- annot = static_cast<AnnotStamp *>(POPPLER_ANNOT(poppler_annot)->annot);
+- annot_image_helper = _poppler_convert_cairo_image_to_stamp_image_helper(image, annot->getDoc(), error);
++ annot = static_cast<AnnotStamp *>(POPPLER_ANNOT(poppler_annot)->annot.get());
++ std::unique_ptr<AnnotStampImageHelper> annot_image_helper = _poppler_convert_cairo_image_to_stamp_image_helper(image, annot->getDoc(), error);
+ if (!annot_image_helper) {
+ return FALSE;
+ }
+- annot->setCustomImage(annot_image_helper);
++ annot->setCustomImage(std::move(annot_image_helper));
+
+ return TRUE;
+ }
+diff --git a/glib/poppler-page.cc b/glib/poppler-page.cc
+index 7f47cd5..1ccc423 100644
+--- a/glib/poppler-page.cc
++++ b/glib/poppler-page.cc
+@@ -1132,7 +1132,7 @@ GList *poppler_page_get_link_mapping(PopplerPage *page)
+
+ poppler_page_get_size(page, &width, &height);
+
+- for (AnnotLink *link : links->getLinks()) {
++ for (const std::shared_ptr<AnnotLink> &link : links->getLinks()) {
+ PopplerLinkMapping *mapping;
+ PopplerRectangle rect;
+ LinkAction *link_action;
+@@ -1295,7 +1295,7 @@ GList *poppler_page_get_annot_mapping(PopplerPage *page)
+ poppler_page_get_size(page, &width, &height);
+ crop_box = page->page->getCropBox();
+
+- for (Annot *annot : annots->getAnnots()) {
++ for (const std::shared_ptr<Annot> &annot : annots->getAnnots()) {
+ PopplerAnnotMapping *mapping;
+ PopplerRectangle rect;
+ gboolean flag_no_rotate;
+@@ -1572,12 +1572,12 @@ void poppler_page_add_annot(PopplerPage *page, PopplerAnnot *annot)
+ if (page_is_rotated) {
+ /* annot is inside a rotated page, as core poppler rect must be saved
+ * un-rotated, let's proceed to un-rotate rect before saving */
+- _unrotate_rect_for_annot_and_page(page->page, annot->annot, &x1, &y1, &x2, &y2);
++ _unrotate_rect_for_annot_and_page(page->page, annot->annot.get(), &x1, &y1, &x2, &y2);
+ }
+
+ annot->annot->setRect(x1 + page_crop_box->x1, y1 + page_crop_box->y1, x2 + page_crop_box->x1, y2 + page_crop_box->y1);
+
+- AnnotTextMarkup *annot_markup = dynamic_cast<AnnotTextMarkup *>(annot->annot);
++ AnnotTextMarkup *annot_markup = dynamic_cast<AnnotTextMarkup *>(annot->annot.get());
+ if (annot_markup) {
+ AnnotQuadrilaterals *quads;
+ crop_box = _poppler_annot_get_cropbox(annot);
+diff --git a/glib/poppler-private.h b/glib/poppler-private.h
+index 758c702..1b51b76 100644
+--- a/glib/poppler-private.h
++++ b/glib/poppler-private.h
+@@ -85,7 +85,7 @@ struct _PopplerFormField
+ struct _PopplerAnnot
+ {
+ GObject parent_instance;
+- Annot *annot;
++ std::shared_ptr<Annot> annot;
+ };
+
+ typedef struct _Layer
+@@ -146,17 +146,17 @@ PopplerFormField *_poppler_form_field_new(PopplerDocument *document, FormWidget
+ PopplerAttachment *_poppler_attachment_new(FileSpec *file);
+ PopplerMovie *_poppler_movie_new(const Movie *movie);
+ PopplerMedia *_poppler_media_new(const MediaRendition *media);
+-PopplerAnnot *_poppler_annot_new(Annot *annot);
+-PopplerAnnot *_poppler_annot_text_new(Annot *annot);
+-PopplerAnnot *_poppler_annot_free_text_new(Annot *annot);
+-PopplerAnnot *_poppler_annot_text_markup_new(Annot *annot);
+-PopplerAnnot *_poppler_annot_file_attachment_new(Annot *annot);
+-PopplerAnnot *_poppler_annot_movie_new(Annot *annot);
+-PopplerAnnot *_poppler_annot_screen_new(PopplerDocument *doc, Annot *annot);
+-PopplerAnnot *_poppler_annot_line_new(Annot *annot);
+-PopplerAnnot *_poppler_annot_circle_new(Annot *annot);
+-PopplerAnnot *_poppler_annot_square_new(Annot *annot);
+-PopplerAnnot *_poppler_annot_stamp_new(Annot *annot);
++PopplerAnnot *_poppler_annot_new(const std::shared_ptr<Annot> &annot);
++PopplerAnnot *_poppler_annot_text_new(const std::shared_ptr<Annot> &annot);
++PopplerAnnot *_poppler_annot_free_text_new(const std::shared_ptr<Annot> &annot);
++PopplerAnnot *_poppler_annot_text_markup_new(const std::shared_ptr<Annot> &annot);
++PopplerAnnot *_poppler_annot_file_attachment_new(const std::shared_ptr<Annot> &annot);
++PopplerAnnot *_poppler_annot_movie_new(const std::shared_ptr<Annot> &annot);
++PopplerAnnot *_poppler_annot_screen_new(PopplerDocument *doc, const std::shared_ptr<Annot> &annot);
++PopplerAnnot *_poppler_annot_line_new(const std::shared_ptr<Annot> &annot);
++PopplerAnnot *_poppler_annot_circle_new(const std::shared_ptr<Annot> &annot);
++PopplerAnnot *_poppler_annot_square_new(const std::shared_ptr<Annot> &annot);
++PopplerAnnot *_poppler_annot_stamp_new(const std::shared_ptr<Annot> &annot);
+
+ const PDFRectangle *_poppler_annot_get_cropbox(PopplerAnnot *poppler_annot);
+
+diff --git a/poppler/Annot.cc b/poppler/Annot.cc
+index 5716ea5..b98df5d 100644
+--- a/poppler/Annot.cc
++++ b/poppler/Annot.cc
+@@ -1064,7 +1064,7 @@ void AnnotAppearance::removeStream(Ref refToStream)
+ continue;
+ }
+ Annots *annots = page->getAnnots();
+- for (Annot *annot : annots->getAnnots()) {
++ for (const std::shared_ptr<Annot> &annot : annots->getAnnots()) {
+ AnnotAppearance *annotAp = annot->getAppearStreams();
+ if (annotAp && annotAp != this && annotAp->referencesStream(refToStream)) {
+ return; // Another annotation points to the stream -> Don't delete it
+@@ -1263,7 +1263,6 @@ double AnnotAppearanceBBox::getPageYMax() const
+ Annot::Annot(PDFDoc *docA, PDFRectangle *rectA)
+ {
+
+- refCnt = 1;
+ flags = flagUnknown;
+ type = typeUnknown;
+
+@@ -1284,7 +1283,6 @@ Annot::Annot(PDFDoc *docA, PDFRectangle *rectA)
+
+ Annot::Annot(PDFDoc *docA, Object &&dictObject)
+ {
+- refCnt = 1;
+ hasRef = false;
+ flags = flagUnknown;
+ type = typeUnknown;
+@@ -1294,7 +1292,6 @@ Annot::Annot(PDFDoc *docA, Object &&dictObject)
+
+ Annot::Annot(PDFDoc *docA, Object &&dictObject, const Object *obj)
+ {
+- refCnt = 1;
+ if (obj->isRef()) {
+ hasRef = true;
+ ref = obj->getRef();
+@@ -1670,18 +1667,6 @@ void Annot::removeReferencedObjects()
+ invalidateAppearance();
+ }
+
+-void Annot::incRefCnt()
+-{
+- refCnt++;
+-}
+-
+-void Annot::decRefCnt()
+-{
+- if (--refCnt == 0) {
+- delete this;
+- }
+-}
+-
+ Annot::~Annot() { }
+
+ void AnnotAppearanceBuilder::setDrawColor(const AnnotColor *drawColor, bool fill)
+@@ -2218,7 +2203,7 @@ void AnnotMarkup::setLabel(std::unique_ptr<GooString> &&new_label)
+ update("T", Object(label->copy()));
+ }
+
+-void AnnotMarkup::setPopup(std::unique_ptr<AnnotPopup> &&new_popup)
++void AnnotMarkup::setPopup(std::shared_ptr<AnnotPopup> new_popup)
+ {
+ // If there exists an old popup annotation that is already
+ // associated with a page, then we need to remove that
+@@ -2227,7 +2212,7 @@ void AnnotMarkup::setPopup(std::unique_ptr<AnnotPopup> &&new_popup)
+ if (popup && popup->getPageNum() != 0) {
+ Page *pageobj = doc->getPage(popup->getPageNum());
+ if (pageobj) {
+- pageobj->removeAnnot(popup.get());
++ pageobj->removeAnnot(popup);
+ }
+ }
+
+@@ -2244,7 +2229,7 @@ void AnnotMarkup::setPopup(std::unique_ptr<AnnotPopup> &&new_popup)
+ Page *pageobj = doc->getPage(page);
+ assert(pageobj != nullptr); // pageobj should exist in doc (see setPage())
+
+- pageobj->addAnnot(popup.get());
++ pageobj->addAnnot(popup);
+ }
+ } else {
+ popup = nullptr;
+@@ -2276,7 +2261,7 @@ void AnnotMarkup::removeReferencedObjects()
+
+ // Remove popup
+ if (popup) {
+- pageobj->removeAnnot(popup.get());
++ pageobj->removeAnnot(popup);
+ }
+
+ Annot::removeReferencedObjects();
+@@ -2943,7 +2928,7 @@ void AnnotFreeText::setStyleString(GooString *new_string)
+ update("DS", Object(styleString->copy()));
+ }
+
+-void AnnotFreeText::setCalloutLine(AnnotCalloutLine *line)
++void AnnotFreeText::setCalloutLine(std::unique_ptr<AnnotCalloutLine> &&line)
+ {
+ Object obj1;
+ if (line == nullptr) {
+@@ -2958,15 +2943,13 @@ void AnnotFreeText::setCalloutLine(AnnotCalloutLine *line)
+ obj1.arrayAdd(Object(x2));
+ obj1.arrayAdd(Object(y2));
+
+- AnnotCalloutMultiLine *mline = dynamic_cast<AnnotCalloutMultiLine *>(line);
++ AnnotCalloutMultiLine *mline = dynamic_cast<AnnotCalloutMultiLine *>(line.get());
+ if (mline) {
+ double x3 = mline->getX3(), y3 = mline->getY3();
+ obj1.arrayAdd(Object(x3));
+ obj1.arrayAdd(Object(y3));
+- calloutLine = std::make_unique<AnnotCalloutMultiLine>(x1, y1, x2, y2, x3, y3);
+- } else {
+- calloutLine = std::make_unique<AnnotCalloutLine>(x1, y1, x2, y2);
+ }
++ calloutLine = std::move(line);
+ }
+
+ update("CL", std::move(obj1));
+@@ -5715,10 +5698,7 @@ AnnotStamp::AnnotStamp(PDFDoc *docA, Object &&dictObject, const Object *obj) : A
+ initialize(docA, annotObj.getDict());
+ }
+
+-AnnotStamp::~AnnotStamp()
+-{
+- delete stampImageHelper;
+-}
++AnnotStamp::~AnnotStamp() = default;
+
+ void AnnotStamp::initialize(PDFDoc *docA, Dict *dict)
+ {
+@@ -5729,7 +5709,6 @@ void AnnotStamp::initialize(PDFDoc *docA, Dict *dict)
+ icon = std::make_unique<GooString>("Draft");
+ }
+
+- stampImageHelper = nullptr;
+ updatedAppearanceStream = Ref::INVALID();
+ }
+
+@@ -5887,16 +5866,18 @@ void AnnotStamp::setIcon(GooString *new_icon)
+ invalidateAppearance();
+ }
+
+-void AnnotStamp::setCustomImage(AnnotStampImageHelper *stampImageHelperA)
++void AnnotStamp::setCustomImage(std::unique_ptr<AnnotStampImageHelper> &&stampImageHelperA)
+ {
+ if (!stampImageHelperA) {
+ return;
+ }
+
+ annotLocker();
+- clearCustomImage();
++ if (stampImageHelper) {
++ stampImageHelper->removeAnnotStampImageObject();
++ }
+
+- stampImageHelper = stampImageHelperA;
++ stampImageHelper = std::move(stampImageHelperA);
+ generateStampCustomAppearance();
+
+ if (updatedAppearanceStream == Ref::INVALID()) {
+@@ -5911,16 +5892,6 @@ void AnnotStamp::setCustomImage(AnnotStampImageHelper *stampImageHelperA)
+ update("AP", std::move(obj1));
+ }
+
+-void AnnotStamp::clearCustomImage()
+-{
+- if (stampImageHelper != nullptr) {
+- stampImageHelper->removeAnnotStampImageObject();
+- delete stampImageHelper;
+- stampImageHelper = nullptr;
+- invalidateAppearance();
+- }
+-}
+-
+ //------------------------------------------------------------------------
+ // AnnotGeometry
+ //------------------------------------------------------------------------
+@@ -7467,96 +7438,90 @@ const GooString *AnnotRichMedia::Params::getFlashVars() const
+
+ Annots::Annots(PDFDoc *docA, int page, Object *annotsObj)
+ {
+- Annot *annot;
+- int i;
+-
+ doc = docA;
+
+ if (annotsObj->isArray()) {
+- for (i = 0; i < annotsObj->arrayGetLength(); ++i) {
++ for (int i = 0; i < annotsObj->arrayGetLength(); ++i) {
+ // get the Ref to this annot and pass it to Annot constructor
+ // this way, it'll be possible for the annot to retrieve the corresponding
+ // form widget
+ Object obj1 = annotsObj->arrayGet(i);
+ if (obj1.isDict()) {
+ const Object &obj2 = annotsObj->arrayGetNF(i);
+- annot = createAnnot(std::move(obj1), &obj2);
++ std::shared_ptr<Annot> annot = createAnnot(std::move(obj1), &obj2);
+ if (annot) {
+ if (annot->isOk()) {
+ annot->setPage(page, false); // Don't change /P
+ appendAnnot(annot);
+ }
+- annot->decRefCnt();
+ }
+ }
+ }
+ }
+ }
+
+-void Annots::appendAnnot(Annot *annot)
++void Annots::appendAnnot(std::shared_ptr<Annot> annot)
+ {
+ if (annot && annot->isOk()) {
+- annots.push_back(annot);
+- annot->incRefCnt();
++ annots.push_back(std::move(annot));
+ }
+ }
+
+-bool Annots::removeAnnot(Annot *annot)
++bool Annots::removeAnnot(const std::shared_ptr<Annot> &annot)
+ {
+ auto idx = std::find(annots.begin(), annots.end(), annot);
+
+ if (idx == annots.end()) {
+ return false;
+ } else {
+- annot->decRefCnt();
+ annots.erase(idx);
+ return true;
+ }
+ }
+
+-Annot *Annots::createAnnot(Object &&dictObject, const Object *obj)
++std::shared_ptr<Annot> Annots::createAnnot(Object &&dictObject, const Object *obj)
+ {
+- Annot *annot = nullptr;
++ std::shared_ptr<Annot> annot = nullptr;
+ Object obj1 = dictObject.dictLookup("Subtype");
+ if (obj1.isName()) {
+ const char *typeName = obj1.getName();
+
+ if (!strcmp(typeName, "Text")) {
+- annot = new AnnotText(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotText>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "Link")) {
+- annot = new AnnotLink(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotLink>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "FreeText")) {
+- annot = new AnnotFreeText(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotFreeText>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "Line")) {
+- annot = new AnnotLine(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotLine>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "Square")) {
+- annot = new AnnotGeometry(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotGeometry>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "Circle")) {
+- annot = new AnnotGeometry(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotGeometry>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "Polygon")) {
+- annot = new AnnotPolygon(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotPolygon>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "PolyLine")) {
+- annot = new AnnotPolygon(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotPolygon>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "Highlight")) {
+- annot = new AnnotTextMarkup(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotTextMarkup>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "Underline")) {
+- annot = new AnnotTextMarkup(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotTextMarkup>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "Squiggly")) {
+- annot = new AnnotTextMarkup(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotTextMarkup>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "StrikeOut")) {
+- annot = new AnnotTextMarkup(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotTextMarkup>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "Stamp")) {
+- annot = new AnnotStamp(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotStamp>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "Caret")) {
+- annot = new AnnotCaret(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotCaret>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "Ink")) {
+- annot = new AnnotInk(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotInk>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "FileAttachment")) {
+- annot = new AnnotFileAttachment(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotFileAttachment>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "Sound")) {
+- annot = new AnnotSound(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotSound>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "Movie")) {
+- annot = new AnnotMovie(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotMovie>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "Widget")) {
+ // Find the annot in forms
+ if (obj->isRef()) {
+@@ -7565,25 +7530,24 @@ Annot *Annots::createAnnot(Object &&dictObject, const Object *obj)
+ FormWidget *widget = form->findWidgetByRef(obj->getRef());
+ if (widget) {
+ annot = widget->getWidgetAnnotation();
+- annot->incRefCnt();
+ }
+ }
+ }
+ if (!annot) {
+- annot = new AnnotWidget(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotWidget>(doc, std::move(dictObject), obj);
+ }
+ } else if (!strcmp(typeName, "Screen")) {
+- annot = new AnnotScreen(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotScreen>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "PrinterMark")) {
+- annot = new Annot(doc, std::move(dictObject), obj);
++ annot = std::make_shared<Annot>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "TrapNet")) {
+- annot = new Annot(doc, std::move(dictObject), obj);
++ annot = std::make_shared<Annot>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "Watermark")) {
+- annot = new Annot(doc, std::move(dictObject), obj);
++ annot = std::make_shared<Annot>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "3D")) {
+- annot = new Annot3D(doc, std::move(dictObject), obj);
++ annot = std::make_shared<Annot3D>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "RichMedia")) {
+- annot = new AnnotRichMedia(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotRichMedia>(doc, std::move(dictObject), obj);
+ } else if (!strcmp(typeName, "Popup")) {
+ /* Popup annots are already handled by markup annots
+ * Here we only care about popup annots without a
+@@ -7591,21 +7555,21 @@ Annot *Annots::createAnnot(Object &&dictObject, const Object *obj)
+ */
+ Object obj2 = dictObject.dictLookup("Parent");
+ if (obj2.isNull()) {
+- annot = new AnnotPopup(doc, std::move(dictObject), obj);
++ annot = std::make_shared<AnnotPopup>(doc, std::move(dictObject), obj);
+ } else {
+ annot = nullptr;
+ }
+ } else {
+- annot = new Annot(doc, std::move(dictObject), obj);
++ annot = std::make_shared<Annot>(doc, std::move(dictObject), obj);
+ }
+ }
+
+ return annot;
+ }
+
+-Annot *Annots::findAnnot(Ref *ref)
++std::shared_ptr<Annot> Annots::findAnnot(Ref *ref)
+ {
+- for (auto *annot : annots) {
++ for (const auto &annot : annots) {
+ if (annot->match(ref)) {
+ return annot;
+ }
+@@ -7613,12 +7577,7 @@ Annot *Annots::findAnnot(Ref *ref)
+ return nullptr;
+ }
+
+-Annots::~Annots()
+-{
+- for (auto *annot : annots) {
+- annot->decRefCnt();
+- }
+-}
++Annots::~Annots() = default;
+
+ //------------------------------------------------------------------------
+ // AnnotAppearanceBuilder
+diff --git a/poppler/Annot.h b/poppler/Annot.h
+index 819877d..ad40d5e 100644
+--- a/poppler/Annot.h
++++ b/poppler/Annot.h
+@@ -716,9 +716,6 @@ public:
+ Annot(PDFDoc *docA, Object &&dictObject, const Object *obj);
+ bool isOk() { return ok; }
+
+- void incRefCnt();
+- void decRefCnt();
+-
+ virtual void draw(Gfx *gfx, bool printing);
+ // Get the resource dict of the appearance stream
+ virtual Object getAppearanceResDict();
+@@ -774,6 +771,8 @@ public:
+ // If newFontNeeded is not null, it will contain whether the given font has glyphs to represent the needed text
+ static void layoutText(const GooString *text, GooString *outBuf, int *i, const GfxFont &font, double *width, double widthLimit, int *charCount, bool noReencode, bool *newFontNeeded = nullptr);
+
++ virtual ~Annot();
++
+ private:
+ void readArrayNum(Object *pdfArray, int key, double *value);
+ // write vStr[i:j[ in appearBuf
+@@ -782,7 +781,6 @@ private:
+ void setPage(int pageIndex, bool updateP); // Called by Page::addAnnot and Annots ctor
+
+ protected:
+- virtual ~Annot();
+ virtual void removeReferencedObjects(); // Called by Page::removeAnnot
+ Object createForm(const GooString *appearBuf, const double *bbox, bool transparencyGroup, Dict *resDict);
+ Object createForm(const GooString *appearBuf, const double *bbox, bool transparencyGroup, Object &&resDictObject); // overload to support incRef/decRef
+@@ -799,8 +797,6 @@ protected:
+
+ Object annotObj;
+
+- std::atomic_int refCnt;
+-
+ // required data
+ AnnotSubtype type; // Annotation type
+ std::unique_ptr<PDFRectangle> rect; // Rect
+@@ -873,7 +869,7 @@ public:
+
+ // getters
+ const GooString *getLabel() const { return label.get(); }
+- AnnotPopup *getPopup() const { return popup.get(); }
++ std::shared_ptr<AnnotPopup> getPopup() const { return popup; }
+ double getOpacity() const { return opacity; }
+ // getRC
+ const GooString *getDate() const { return date.get(); }
+@@ -884,7 +880,7 @@ public:
+ AnnotExternalDataType getExData() const { return exData; }
+
+ // The annotation takes the ownership of new_popup
+- void setPopup(std::unique_ptr<AnnotPopup> &&new_popup);
++ void setPopup(std::shared_ptr<AnnotPopup> new_popup);
+ void setLabel(std::unique_ptr<GooString> &&new_label);
+ void setOpacity(double opacityA);
+ void setDate(GooString *new_date);
+@@ -893,7 +889,7 @@ protected:
+ void removeReferencedObjects() override;
+
+ std::unique_ptr<GooString> label; // T (Default author)
+- std::unique_ptr<AnnotPopup> popup; // Popup
++ std::shared_ptr<AnnotPopup> popup; // Popup
+ double opacity; // CA (Default 1.0)
+ // RC
+ std::unique_ptr<GooString> date; // CreationDate
+@@ -1068,7 +1064,7 @@ public:
+ void setDefaultAppearance(const DefaultAppearance &da);
+ void setQuadding(VariableTextQuadding new_quadding);
+ void setStyleString(GooString *new_string);
+- void setCalloutLine(AnnotCalloutLine *line);
++ void setCalloutLine(std::unique_ptr<AnnotCalloutLine> &&line);
+ void setIntent(AnnotFreeTextIntent new_intent);
+
+ // getters
+@@ -1224,9 +1220,7 @@ public:
+
+ void setIcon(GooString *new_icon);
+
+- void setCustomImage(AnnotStampImageHelper *stampImageHelperA);
+-
+- void clearCustomImage();
++ void setCustomImage(std::unique_ptr<AnnotStampImageHelper> &&stampImageHelperA);
+
+ // getters
+ const GooString *getIcon() const { return icon.get(); }
+@@ -1237,7 +1231,7 @@ private:
+ void generateStampCustomAppearance();
+
+ std::unique_ptr<GooString> icon; // Name (Default Draft)
+- AnnotStampImageHelper *stampImageHelper;
++ std::unique_ptr<AnnotStampImageHelper> stampImageHelper;
+ Ref updatedAppearanceStream;
+ };
+
+@@ -1768,17 +1762,17 @@ public:
+ Annots(const Annots &) = delete;
+ Annots &operator=(const Annots &) = delete;
+
+- const std::vector<Annot *> &getAnnots() { return annots; }
++ const std::vector<std::shared_ptr<Annot>> &getAnnots() { return annots; }
+
+- void appendAnnot(Annot *annot);
+- bool removeAnnot(Annot *annot);
++ void appendAnnot(std::shared_ptr<Annot> annot);
++ bool removeAnnot(const std::shared_ptr<Annot> &annot);
+
+ private:
+- Annot *createAnnot(Object &&dictObject, const Object *obj);
+- Annot *findAnnot(Ref *ref);
++ std::shared_ptr<Annot> createAnnot(Object &&dictObject, const Object *obj);
++ std::shared_ptr<Annot> findAnnot(Ref *ref);
+
+ PDFDoc *doc;
+- std::vector<Annot *> annots;
++ std::vector<std::shared_ptr<Annot>> annots;
+ };
+
+ #endif
+diff --git a/poppler/FontInfo.cc b/poppler/FontInfo.cc
+index 309ec6d..c8c1bdf 100644
+--- a/poppler/FontInfo.cc
++++ b/poppler/FontInfo.cc
+@@ -82,7 +82,7 @@ std::vector<FontInfo *> FontInfoScanner::scan(int nPages)
+ delete resDict;
+ }
+ annots = page->getAnnots();
+- for (Annot *annot : annots->getAnnots()) {
++ for (const std::shared_ptr<Annot> &annot : annots->getAnnots()) {
+ Object obj1 = annot->getAppearanceResDict();
+ if (obj1.isDict()) {
+ scanFonts(xrefA.get(), obj1.getDict(), &result);
+diff --git a/poppler/Form.cc b/poppler/Form.cc
+index 2c0c35a..ca73a35 100644
+--- a/poppler/Form.cc
++++ b/poppler/Form.cc
+@@ -123,12 +123,7 @@ FormWidget::FormWidget(PDFDoc *docA, Object *aobj, unsigned num, Ref aref, FormF
+ widget = nullptr;
+ }
+
+-FormWidget::~FormWidget()
+-{
+- if (widget) {
+- widget->decRefCnt();
+- }
+-}
++FormWidget::~FormWidget() = default;
+
+ void FormWidget::print(int indent)
+ {
+@@ -142,7 +137,7 @@ void FormWidget::createWidgetAnnotation()
+ }
+
+ Object obj1(ref);
+- widget = new AnnotWidget(doc, &obj, &obj1, field);
++ widget = std::make_shared<AnnotWidget>(doc, &obj, &obj1, field);
+ }
+
+ bool FormWidget::inRect(double x, double y) const
+@@ -3114,7 +3109,7 @@ FormPageWidgets::FormPageWidgets(Annots *annots, unsigned int page, Form *form)
+
+ /* For each entry in the page 'Annots' dict, try to find
+ a matching form field */
+- for (Annot *annot : annots->getAnnots()) {
++ for (const std::shared_ptr<Annot> &annot : annots->getAnnots()) {
+
+ if (annot->getType() != Annot::typeWidget) {
+ continue;
+diff --git a/poppler/Form.h b/poppler/Form.h
+index 80be38e..5a0af10 100644
+--- a/poppler/Form.h
++++ b/poppler/Form.h
+@@ -146,8 +146,8 @@ public:
+ static void decodeID(unsigned id, unsigned *pageNum, unsigned *fieldNum);
+
+ void createWidgetAnnotation();
+- AnnotWidget *getWidgetAnnotation() const { return widget; }
+- void setWidgetAnnotation(AnnotWidget *_widget) { widget = _widget; }
++ std::shared_ptr<AnnotWidget> getWidgetAnnotation() const { return widget; }
++ void setWidgetAnnotation(std::shared_ptr<AnnotWidget> _widget) { widget = std::move(widget); }
+
+ virtual void updateWidgetAppearance() = 0;
+
+@@ -156,7 +156,7 @@ public:
+ protected:
+ FormWidget(PDFDoc *docA, Object *aobj, unsigned num, Ref aref, FormField *fieldA);
+
+- AnnotWidget *widget;
++ std::shared_ptr<AnnotWidget> widget;
+ FormField *field;
+ FormFieldType type;
+ Object obj;
+diff --git a/poppler/JSInfo.cc b/poppler/JSInfo.cc
+index eaef33e..e4c4f37 100644
+--- a/poppler/JSInfo.cc
++++ b/poppler/JSInfo.cc
+@@ -191,15 +191,15 @@ void JSInfo::scan(int nPages)
+ }
+ // annotation actions (links, screen, widget)
+ annots = page->getAnnots();
+- for (Annot *a : annots->getAnnots()) {
++ for (const std::shared_ptr<Annot> &a : annots->getAnnots()) {
+ if (a->getType() == Annot::typeLink) {
+- AnnotLink *annot = static_cast<AnnotLink *>(a);
++ AnnotLink *annot = static_cast<AnnotLink *>(a.get());
+ scanLinkAction(annot->getAction(), "Link Annotation Activated");
+ if (onlyFirstJS && hasJS) {
+ return;
+ }
+ } else if (a->getType() == Annot::typeScreen) {
+- AnnotScreen *annot = static_cast<AnnotScreen *>(a);
++ AnnotScreen *annot = static_cast<AnnotScreen *>(a.get());
+ scanLinkAction(annot->getAction(), "Screen Annotation Activated");
+ scanLinkAction(annot->getAdditionalAction(Annot::actionCursorEntering).get(), "Screen Annotation Cursor Enter");
+ scanLinkAction(annot->getAdditionalAction(Annot::actionCursorLeaving).get(), "Screen Annotation Cursor Leave");
+@@ -216,7 +216,7 @@ void JSInfo::scan(int nPages)
+ return;
+ }
+ } else if (a->getType() == Annot::typeWidget) {
+- AnnotWidget *annot = static_cast<AnnotWidget *>(a);
++ AnnotWidget *annot = static_cast<AnnotWidget *>(a.get());
+ scanLinkAction(annot->getAction(), "Widget Annotation Activated");
+ scanLinkAction(annot->getAdditionalAction(Annot::actionCursorEntering).get(), "Widget Annotation Cursor Enter");
+ scanLinkAction(annot->getAdditionalAction(Annot::actionCursorLeaving).get(), "Widget Annotation Cursor Leave");
+diff --git a/poppler/Link.cc b/poppler/Link.cc
+index 8aca0b9..c952887 100644
+--- a/poppler/Link.cc
++++ b/poppler/Link.cc
+@@ -35,6 +35,7 @@
+
+ #include <cstddef>
+ #include <cstring>
++#include <memory>
+ #include "goo/gmem.h"
+ #include "goo/GooString.h"
+ #include "Error.h"
+@@ -890,20 +891,13 @@ Links::Links(Annots *annots)
+ return;
+ }
+
+- for (Annot *annot : annots->getAnnots()) {
++ for (const std::shared_ptr<Annot> &annot : annots->getAnnots()) {
+
+ if (annot->getType() != Annot::typeLink) {
+ continue;
+ }
+-
+- annot->incRefCnt();
+- links.push_back(static_cast<AnnotLink *>(annot));
++ links.push_back(std::static_pointer_cast<AnnotLink>(annot));
+ }
+ }
+
+-Links::~Links()
+-{
+- for (AnnotLink *link : links) {
+- link->decRefCnt();
+- }
+-}
++Links::~Links() = default;
+diff --git a/poppler/Link.h b/poppler/Link.h
+index 204207b..9bd01f0 100644
+--- a/poppler/Link.h
++++ b/poppler/Link.h
+@@ -555,10 +555,10 @@ public:
+ Links(const Links &) = delete;
+ Links &operator=(const Links &) = delete;
+
+- const std::vector<AnnotLink *> &getLinks() const { return links; }
++ const std::vector<std::shared_ptr<AnnotLink>> &getLinks() const { return links; }
+
+ private:
+- std::vector<AnnotLink *> links;
++ std::vector<std::shared_ptr<AnnotLink>> links;
+ };
+
+ #endif
+diff --git a/poppler/PDFDoc.cc b/poppler/PDFDoc.cc
+index f1b9bfc..872841c 100644
+--- a/poppler/PDFDoc.cc
++++ b/poppler/PDFDoc.cc
+@@ -2225,7 +2225,7 @@ bool PDFDoc::sign(const std::string &saveFilename, const std::string &certNickna
+ field->setImageResource(imageResourceRef);
+
+ Object refObj(ref);
+- AnnotWidget *signatureAnnot = new AnnotWidget(this, field->getObj(), &refObj, field.get());
++ auto signatureAnnot = std::make_shared<AnnotWidget>(this, field->getObj(), &refObj, field.get());
+ signatureAnnot->setFlags(signatureAnnot->getFlags() | Annot::flagPrint | Annot::flagLocked | Annot::flagNoRotate);
+ Dict dummy(getXRef());
+ auto appearCharacs = std::make_unique<AnnotAppearanceCharacs>(&dummy);
+diff --git a/poppler/PSOutputDev.cc b/poppler/PSOutputDev.cc
+index 23e3dcf..ac03f27 100644
+--- a/poppler/PSOutputDev.cc
++++ b/poppler/PSOutputDev.cc
+@@ -1738,7 +1738,7 @@ void PSOutputDev::writeDocSetup(Catalog *catalog, const std::vector<int> &pageLi
+ setupResources(resDict);
+ }
+ annots = page->getAnnots();
+- for (Annot *annot : annots->getAnnots()) {
++ for (const std::shared_ptr<Annot> &annot : annots->getAnnots()) {
+ Object obj1 = annot->getAppearanceResDict();
+ if (obj1.isDict()) {
+ setupResources(obj1.getDict());
+diff --git a/poppler/Page.cc b/poppler/Page.cc
+index 9d5a4ff..234f124 100644
+--- a/poppler/Page.cc
++++ b/poppler/Page.cc
+@@ -318,14 +318,7 @@ err1:
+ ok = false;
+ }
+
+-Page::~Page()
+-{
+- delete attrs;
+- delete annots;
+- for (auto frmField : standaloneFields) {
+- delete frmField;
+- }
+-}
++Page::~Page() = default;
+
+ Dict *Page::getResourceDict()
+ {
+@@ -364,11 +357,11 @@ void Page::replaceXRef(XRef *xrefA)
+ }
+
+ /* Loads standalone fields into Page, should be called once per page only */
+-void Page::loadStandaloneFields(Annots *annotations, Form *form)
++void Page::loadStandaloneFields(Form *form)
+ {
+ /* Look for standalone annots, identified by being: 1) of type Widget
+ * 2) not referenced from the Catalog's Form Field array */
+- for (Annot *annot : annots->getAnnots()) {
++ for (const std::shared_ptr<Annot> &annot : annots->getAnnots()) {
+
+ if (annot->getType() != Annot::typeWidget || !annot->getHasRef()) {
+ continue;
+@@ -384,7 +377,7 @@ void Page::loadStandaloneFields(Annots *annotations, Form *form)
+
+ if (field && field->getNumWidgets() == 1) {
+
+- static_cast<AnnotWidget *>(annot)->setField(field);
++ std::static_pointer_cast<AnnotWidget>(annot)->setField(field);
+
+ field->setStandAlone(true);
+ FormWidget *formWidget = field->getWidget(0);
+@@ -405,15 +398,15 @@ Annots *Page::getAnnots(XRef *xrefA)
+ {
+ if (!annots) {
+ Object obj = getAnnotsObject(xrefA);
+- annots = new Annots(doc, num, &obj);
++ annots = std::make_unique<Annots>(doc, num, &obj);
+ // Load standalone fields once for the page
+- loadStandaloneFields(annots, doc->getCatalog()->getForm());
++ loadStandaloneFields(doc->getCatalog()->getForm());
+ }
+
+- return annots;
++ return annots.get();
+ }
+
+-bool Page::addAnnot(Annot *annot)
++bool Page::addAnnot(const std::shared_ptr<Annot> &annot)
+ {
+ if (unlikely(xref->getEntry(pageRef.num)->type == xrefEntryFree)) {
+ // something very wrong happened if we're here
+@@ -456,14 +449,14 @@ bool Page::addAnnot(Annot *annot)
+ // Popup annots are already handled by markup annots,
+ // so add to the list only Popup annots without a
+ // markup annotation associated.
+- if (annot->getType() != Annot::typePopup || !static_cast<AnnotPopup *>(annot)->hasParent()) {
++ if (annot->getType() != Annot::typePopup || !static_cast<AnnotPopup *>(annot.get())->hasParent()) {
+ annots->appendAnnot(annot);
+ }
+ annot->setPage(num, true);
+
+- AnnotMarkup *annotMarkup = dynamic_cast<AnnotMarkup *>(annot);
++ AnnotMarkup *annotMarkup = dynamic_cast<AnnotMarkup *>(annot.get());
+ if (annotMarkup) {
+- AnnotPopup *annotPopup = annotMarkup->getPopup();
++ std::shared_ptr<AnnotPopup> annotPopup = annotMarkup->getPopup();
+ if (annotPopup) {
+ addAnnot(annotPopup);
+ }
+@@ -472,7 +465,7 @@ bool Page::addAnnot(Annot *annot)
+ return true;
+ }
+
+-void Page::removeAnnot(Annot *annot)
++void Page::removeAnnot(const std::shared_ptr<Annot> &annot)
+ {
+ Ref annotRef = annot->getRef();
+
+@@ -596,8 +589,8 @@ void Page::displaySlice(OutputDev *out, double hDPI, double vDPI, int rotate, bo
+ if (globalParams->getPrintCommands()) {
+ printf("***** Annotations\n");
+ }
+- for (Annot *annot : annots->getAnnots()) {
+- if ((annotDisplayDecideCbk && (*annotDisplayDecideCbk)(annot, annotDisplayDecideCbkData)) || !annotDisplayDecideCbk) {
++ for (const std::shared_ptr<Annot> &annot : annots->getAnnots()) {
++ if ((annotDisplayDecideCbk && (*annotDisplayDecideCbk)(annot.get(), annotDisplayDecideCbkData)) || !annotDisplayDecideCbk) {
+ annot->draw(gfx, printing);
+ }
+ }
+@@ -787,8 +780,8 @@ void Page::makeBox(double hDPI, double vDPI, int rotate, bool useMediaBox, bool
+ void Page::processLinks(OutputDev *out)
+ {
+ std::unique_ptr<Links> links = getLinks();
+- for (AnnotLink *link : links->getLinks()) {
+- out->processLink(link);
++ for (const std::shared_ptr<AnnotLink> &link : links->getLinks()) {
++ out->processLink(link.get());
+ }
+ }
+
+diff --git a/poppler/Page.h b/poppler/Page.h
+index 3fe86be..56951a2 100644
+--- a/poppler/Page.h
++++ b/poppler/Page.h
+@@ -181,9 +181,9 @@ public:
+ // Get annotations array.
+ Object getAnnotsObject(XRef *xrefA = nullptr) { return annotsObj.fetch(xrefA ? xrefA : xref); }
+ // Add a new annotation to the page
+- bool addAnnot(Annot *annot);
++ bool addAnnot(const std::shared_ptr<Annot> &annot);
+ // Remove an existing annotation from the page
+- void removeAnnot(Annot *annot);
++ void removeAnnot(const std::shared_ptr<Annot> &annot);
+
+ // Return a list of links.
+ std::unique_ptr<Links> getLinks();
+@@ -252,7 +252,7 @@ private:
+ const Ref pageRef; // page reference
+ int num; // page number
+ PageAttrs *attrs; // page attributes
+- Annots *annots; // annotations
++ std::unique_ptr<Annots> annots; // annotations
+ Object annotsObj; // annotations array
+ Object contents; // page contents
+ Object thumb; // page thumbnail
+@@ -267,7 +267,7 @@ private:
+ // create standalone FormFields to contain those special FormWidgets, as
+ // they are 'de facto' being used to implement tooltips. See #34
+ std::vector<FormField *> standaloneFields;
+- void loadStandaloneFields(Annots *annotations, Form *form);
++ void loadStandaloneFields(Form *form);
+ };
+
+ #endif
+diff --git a/qt5/src/poppler-annotation-private.h b/qt5/src/poppler-annotation-private.h
+index 1f8d756..8970f49 100644
+--- a/qt5/src/poppler-annotation-private.h
++++ b/qt5/src/poppler-annotation-private.h
+@@ -57,7 +57,7 @@ public:
+
+ /* Returns an Annotation of the right subclass whose d_ptr points to
+ * this AnnotationPrivate */
+- virtual Annotation *makeAlias() = 0;
++ virtual std::unique_ptr<Annotation> makeAlias() = 0;
+
+ /* properties: contents related */
+ QString author;
+@@ -77,18 +77,18 @@ public:
+ /* revisions */
+ Annotation::RevScope revisionScope;
+ Annotation::RevType revisionType;
+- QList<Annotation *> revisions;
++ std::vector<std::unique_ptr<Annotation>> revisions;
+
+ /* After this call, the Annotation object will behave like a wrapper for
+ * the specified Annot object. All cached values are discarded */
+- void tieToNativeAnnot(Annot *ann, ::Page *page, DocumentData *doc);
++ void tieToNativeAnnot(std::shared_ptr<Annot> ann, ::Page *page, DocumentData *doc);
+
+ /* Creates a new Annot object on the specified page, flushes current
+ * values to that object and ties this Annotation to that object */
+- virtual Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) = 0;
++ virtual std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) = 0;
+
+ /* Inited to 0 (i.e. untied annotation) */
+- Annot *pdfAnnot;
++ std::shared_ptr<Annot> pdfAnnot;
+ ::Page *pdfPage;
+ DocumentData *parentDoc;
+
+diff --git a/qt5/src/poppler-annotation.cc b/qt5/src/poppler-annotation.cc
+index e15523c..4964563 100644
+--- a/qt5/src/poppler-annotation.cc
++++ b/qt5/src/poppler-annotation.cc
+@@ -65,6 +65,12 @@
+ * static data set at creation time by findAnnotations
+ */
+
++template<typename T, typename U>
++static std::unique_ptr<T> static_pointer_cast(std::unique_ptr<U> &&in)
++{
++ return std::unique_ptr<T>(static_cast<std::add_pointer_t<T>>(in.release()));
++}
++
+ namespace Poppler {
+
+ // BEGIN AnnotationUtils implementation
+@@ -199,36 +205,25 @@ void getRawDataFromQImage(const QImage &qimg, int bitsPerPixel, QByteArray *data
+ void AnnotationPrivate::addRevision(Annotation *ann, Annotation::RevScope scope, Annotation::RevType type)
+ {
+ /* Since ownership stays with the caller, create an alias of ann */
+- revisions.append(ann->d_ptr->makeAlias());
++ revisions.push_back(ann->d_ptr->makeAlias());
+
+ /* Set revision properties */
+ revisionScope = scope;
+ revisionType = type;
+ }
+
+-AnnotationPrivate::~AnnotationPrivate()
+-{
+- // Delete all children revisions
+- qDeleteAll(revisions);
+-
+- // Release Annot object
+- if (pdfAnnot) {
+- pdfAnnot->decRefCnt();
+- }
+-}
++AnnotationPrivate::~AnnotationPrivate() = default;
+
+-void AnnotationPrivate::tieToNativeAnnot(Annot *ann, ::Page *page, Poppler::DocumentData *doc)
++void AnnotationPrivate::tieToNativeAnnot(std::shared_ptr<Annot> ann, ::Page *page, Poppler::DocumentData *doc)
+ {
+ if (pdfAnnot) {
+ error(errIO, -1, "Annotation is already tied");
+ return;
+ }
+
+- pdfAnnot = ann;
++ pdfAnnot = std::move(ann);
+ pdfPage = page;
+ parentDoc = doc;
+-
+- pdfAnnot->incRefCnt();
+ }
+
+ /* This method is called when a new annotation is created, after pdfAnnot and
+@@ -237,7 +232,7 @@ void AnnotationPrivate::flushBaseAnnotationProperties()
+ {
+ Q_ASSERT(pdfPage);
+
+- Annotation *q = makeAlias(); // Setters are defined in the public class
++ std::unique_ptr<Annotation> q = makeAlias(); // Setters are defined in the public class
+
+ // Since pdfAnnot has been set, this calls will write in the Annot object
+ q->setAuthor(author);
+@@ -251,12 +246,7 @@ void AnnotationPrivate::flushBaseAnnotationProperties()
+ q->setPopup(popup);
+
+ // Flush revisions
+- foreach (Annotation *r, revisions) {
+- // TODO: Flush revision
+- delete r; // Object is no longer needed
+- }
+-
+- delete q;
++ revisions.clear();
+
+ // Clear some members to save memory
+ author.clear();
+@@ -455,14 +445,15 @@ QList<Annotation *> AnnotationPrivate::findAnnotations(::Page *pdfPage, Document
+
+ // Create Annotation objects and tie to their native Annot
+ QList<Annotation *> res;
+- for (Annot *ann : annots->getAnnots()) {
++ for (const std::shared_ptr<Annot> &ann : annots->getAnnots()) {
++
+ if (!ann) {
+ error(errInternal, -1, "Annot is null");
+ continue;
+ }
+
+ // Check parent annotation
+- AnnotMarkup *markupann = dynamic_cast<AnnotMarkup *>(ann);
++ AnnotMarkup *markupann = dynamic_cast<AnnotMarkup *>(ann.get());
+ if (!markupann) {
+ // Assume it's a root annotation, and skip if user didn't request it
+ if (parentID != -1) {
+@@ -536,7 +527,7 @@ QList<Annotation *> AnnotationPrivate::findAnnotations(::Page *pdfPage, Document
+ continue;
+ }
+ // parse Link params
+- AnnotLink *linkann = static_cast<AnnotLink *>(ann);
++ AnnotLink *linkann = static_cast<AnnotLink *>(ann.get());
+ LinkAnnotation *l = new LinkAnnotation();
+ annotation = l;
+
+@@ -566,7 +557,7 @@ QList<Annotation *> AnnotationPrivate::findAnnotations(::Page *pdfPage, Document
+ if (!wantFileAttachmentAnnotations) {
+ continue;
+ }
+- AnnotFileAttachment *attachann = static_cast<AnnotFileAttachment *>(ann);
++ AnnotFileAttachment *attachann = static_cast<AnnotFileAttachment *>(ann.get());
+ FileAttachmentAnnotation *f = new FileAttachmentAnnotation();
+ annotation = f;
+ // -> fileIcon
+@@ -581,7 +572,7 @@ QList<Annotation *> AnnotationPrivate::findAnnotations(::Page *pdfPage, Document
+ if (!wantSoundAnnotations) {
+ continue;
+ }
+- AnnotSound *soundann = static_cast<AnnotSound *>(ann);
++ AnnotSound *soundann = static_cast<AnnotSound *>(ann.get());
+ SoundAnnotation *s = new SoundAnnotation();
+ annotation = s;
+
+@@ -596,7 +587,7 @@ QList<Annotation *> AnnotationPrivate::findAnnotations(::Page *pdfPage, Document
+ if (!wantMovieAnnotations) {
+ continue;
+ }
+- AnnotMovie *movieann = static_cast<AnnotMovie *>(ann);
++ AnnotMovie *movieann = static_cast<AnnotMovie *>(ann.get());
+ MovieAnnotation *m = new MovieAnnotation();
+ annotation = m;
+
+@@ -614,7 +605,7 @@ QList<Annotation *> AnnotationPrivate::findAnnotations(::Page *pdfPage, Document
+ if (!wantScreenAnnotations) {
+ continue;
+ }
+- AnnotScreen *screenann = static_cast<AnnotScreen *>(ann);
++ AnnotScreen *screenann = static_cast<AnnotScreen *>(ann.get());
+ // TODO Support other link types than Link::Rendition in ScreenAnnotation
+ if (!screenann->getAction() || screenann->getAction()->getKind() != actionRendition) {
+ continue;
+@@ -644,7 +635,7 @@ QList<Annotation *> AnnotationPrivate::findAnnotations(::Page *pdfPage, Document
+ annotation = new WidgetAnnotation();
+ break;
+ case Annot::typeRichMedia: {
+- const AnnotRichMedia *annotRichMedia = static_cast<AnnotRichMedia *>(ann);
++ const AnnotRichMedia *annotRichMedia = static_cast<AnnotRichMedia *>(ann.get());
+
+ RichMediaAnnotation *richMediaAnnotation = new RichMediaAnnotation;
+
+@@ -852,9 +843,9 @@ Link *AnnotationPrivate::additionalAction(Annotation::AdditionalActionType type)
+
+ std::unique_ptr<::LinkAction> linkAction = nullptr;
+ if (pdfAnnot->getType() == Annot::typeScreen) {
+- linkAction = static_cast<AnnotScreen *>(pdfAnnot)->getAdditionalAction(actionType);
++ linkAction = static_cast<AnnotScreen *>(pdfAnnot.get())->getAdditionalAction(actionType);
+ } else {
+- linkAction = static_cast<AnnotWidget *>(pdfAnnot)->getAdditionalAction(actionType);
++ linkAction = static_cast<AnnotWidget *>(pdfAnnot.get())->getAdditionalAction(actionType);
+ }
+
+ Link *link = nullptr;
+@@ -875,7 +866,7 @@ void AnnotationPrivate::addAnnotationToPage(::Page *pdfPage, DocumentData *doc,
+
+ // Unimplemented annotations can't be created by the user because their ctor
+ // is private. Therefore, createNativeAnnot will never return 0
+- Annot *nativeAnnot = ann->d_ptr->createNativeAnnot(pdfPage, doc);
++ std::shared_ptr<Annot> nativeAnnot = ann->d_ptr->createNativeAnnot(pdfPage, doc);
+ Q_ASSERT(nativeAnnot);
+
+ if (ann->d_ptr->annotationAppearance.isStream()) {
+@@ -908,8 +899,8 @@ class TextAnnotationPrivate : public AnnotationPrivate
+ {
+ public:
+ TextAnnotationPrivate();
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+ void setDefaultAppearanceToNative();
+ std::unique_ptr<DefaultAppearance> getDefaultAppearanceFromNative() const;
+
+@@ -1419,7 +1410,7 @@ QString Annotation::author() const
+ return d->author;
+ }
+
+- const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot);
++ const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot.get());
+ return markupann ? UnicodeParsedString(markupann->getLabel()) : QString();
+ }
+
+@@ -1432,7 +1423,7 @@ void Annotation::setAuthor(const QString &author)
+ return;
+ }
+
+- AnnotMarkup *markupann = dynamic_cast<AnnotMarkup *>(d->pdfAnnot);
++ AnnotMarkup *markupann = dynamic_cast<AnnotMarkup *>(d->pdfAnnot.get());
+ if (markupann) {
+ markupann->setLabel(std::unique_ptr<GooString>(QStringToUnicodeGooString(author)));
+ }
+@@ -1535,7 +1526,7 @@ QDateTime Annotation::creationDate() const
+ return d->creationDate;
+ }
+
+- const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot);
++ const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot.get());
+
+ if (markupann && markupann->getDate()) {
+ return convertDate(markupann->getDate()->c_str());
+@@ -1553,7 +1544,7 @@ void Annotation::setCreationDate(const QDateTime &date)
+ return;
+ }
+
+- AnnotMarkup *markupann = dynamic_cast<AnnotMarkup *>(d->pdfAnnot);
++ AnnotMarkup *markupann = dynamic_cast<AnnotMarkup *>(d->pdfAnnot.get());
+ if (markupann) {
+ if (date.isValid()) {
+ const time_t t = date.toSecsSinceEpoch();
+@@ -1686,7 +1677,7 @@ Annotation::Style Annotation::style() const
+ Style s;
+ s.setColor(convertAnnotColor(d->pdfAnnot->getColor()));
+
+- const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot);
++ const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot.get());
+ if (markupann) {
+ s.setOpacity(markupann->getOpacity());
+ }
+@@ -1713,11 +1704,11 @@ Annotation::Style Annotation::style() const
+ AnnotBorderEffect *border_effect;
+ switch (d->pdfAnnot->getType()) {
+ case Annot::typeFreeText:
+- border_effect = static_cast<AnnotFreeText *>(d->pdfAnnot)->getBorderEffect();
++ border_effect = static_cast<AnnotFreeText *>(d->pdfAnnot.get())->getBorderEffect();
+ break;
+ case Annot::typeSquare:
+ case Annot::typeCircle:
+- border_effect = static_cast<AnnotGeometry *>(d->pdfAnnot)->getBorderEffect();
++ border_effect = static_cast<AnnotGeometry *>(d->pdfAnnot.get())->getBorderEffect();
+ break;
+ default:
+ border_effect = nullptr;
+@@ -1741,7 +1732,7 @@ void Annotation::setStyle(const Annotation::Style &style)
+
+ d->pdfAnnot->setColor(convertQColor(style.color()));
+
+- AnnotMarkup *markupann = dynamic_cast<AnnotMarkup *>(d->pdfAnnot);
++ AnnotMarkup *markupann = dynamic_cast<AnnotMarkup *>(d->pdfAnnot.get());
+ if (markupann) {
+ markupann->setOpacity(style.opacity());
+ }
+@@ -1765,9 +1756,9 @@ Annotation::Popup Annotation::popup() const
+ AnnotPopup *popup = nullptr;
+ int flags = -1; // Not initialized
+
+- const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot);
++ const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot.get());
+ if (markupann) {
+- popup = markupann->getPopup();
++ popup = markupann->getPopup().get();
+ w.setSummary(UnicodeParsedString(markupann->getSubject()));
+ }
+
+@@ -1783,7 +1774,7 @@ Annotation::Popup Annotation::popup() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeText) {
+- const AnnotText *textann = static_cast<const AnnotText *>(d->pdfAnnot);
++ const AnnotText *textann = static_cast<const AnnotText *>(d->pdfAnnot.get());
+
+ // Text annotations default to same rect as annotation
+ if (flags == -1) {
+@@ -1839,7 +1830,7 @@ Annotation::RevScope Annotation::revisionScope() const
+ return d->revisionScope;
+ }
+
+- const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot);
++ const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot.get());
+
+ if (markupann && markupann->isInReplyTo()) {
+ switch (markupann->getReplyTo()) {
+@@ -1861,7 +1852,7 @@ Annotation::RevType Annotation::revisionType() const
+ return d->revisionType;
+ }
+
+- const AnnotText *textann = dynamic_cast<const AnnotText *>(d->pdfAnnot);
++ const AnnotText *textann = dynamic_cast<const AnnotText *>(d->pdfAnnot.get());
+
+ if (textann && textann->isInReplyTo()) {
+ switch (textann->getState()) {
+@@ -1892,8 +1883,9 @@ QList<Annotation *> Annotation::revisions() const
+ if (!d->pdfAnnot) {
+ /* Return aliases, whose ownership goes to the caller */
+ QList<Annotation *> res;
+- foreach (Annotation *rev, d->revisions)
+- res.append(rev->d_ptr->makeAlias());
++ for (const std::unique_ptr<Annotation> &rev : d->revisions) {
++ res.append(rev->d_ptr->makeAlias().release());
++ }
+ return res;
+ }
+
+@@ -1910,7 +1902,7 @@ std::unique_ptr<AnnotationAppearance> Annotation::annotationAppearance() const
+ {
+ Q_D(const Annotation);
+
+- return std::make_unique<AnnotationAppearance>(new AnnotationAppearancePrivate(d->pdfAnnot));
++ return std::make_unique<AnnotationAppearance>(new AnnotationAppearancePrivate(d->pdfAnnot.get()));
+ }
+
+ void Annotation::setAnnotationAppearance(const AnnotationAppearance &annotationAppearance)
+@@ -1934,15 +1926,15 @@ void Annotation::setAnnotationAppearance(const AnnotationAppearance &annotationA
+
+ TextAnnotationPrivate::TextAnnotationPrivate() : AnnotationPrivate(), textType(TextAnnotation::Linked), textIcon(QStringLiteral("Note")), inplaceAlign(0), inplaceIntent(TextAnnotation::Unknown) { }
+
+-Annotation *TextAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> TextAnnotationPrivate::makeAlias()
+ {
+- return new TextAnnotation(*this);
++ return std::unique_ptr<Annotation>(new TextAnnotation(*this));
+ }
+
+-Annot *TextAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> TextAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ // Setters are defined in the public class
+- TextAnnotation *q = static_cast<TextAnnotation *>(makeAlias());
++ std::unique_ptr<TextAnnotation> q = static_pointer_cast<TextAnnotation>(makeAlias());
+
+ // Set page and contents
+ pdfPage = destPage;
+@@ -1951,13 +1943,13 @@ Annot *TextAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *
+ // Set pdfAnnot
+ PDFRectangle rect = boundaryToPdfRectangle(boundary, flags);
+ if (textType == TextAnnotation::Linked) {
+- pdfAnnot = new AnnotText { destPage->getDoc(), &rect };
++ pdfAnnot = std::make_shared<AnnotText>(destPage->getDoc(), &rect);
+ } else {
+ const double pointSize = textFont ? textFont->pointSizeF() : AnnotFreeText::undefinedFontPtSize;
+ if (pointSize < 0) {
+ qWarning() << "TextAnnotationPrivate::createNativeAnnot: font pointSize < 0";
+ }
+- pdfAnnot = new AnnotFreeText { destPage->getDoc(), &rect };
++ pdfAnnot = std::make_shared<AnnotFreeText>(destPage->getDoc(), &rect);
+ }
+
+ // Set properties
+@@ -1967,8 +1959,6 @@ Annot *TextAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *
+ q->setCalloutPoints(inplaceCallout);
+ q->setInplaceIntent(inplaceIntent);
+
+- delete q;
+-
+ inplaceCallout.clear(); // Free up memory
+
+ setDefaultAppearanceToNative();
+@@ -1979,7 +1969,7 @@ Annot *TextAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *
+ void TextAnnotationPrivate::setDefaultAppearanceToNative()
+ {
+ if (pdfAnnot && pdfAnnot->getType() == Annot::typeFreeText) {
+- AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(pdfAnnot);
++ AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(pdfAnnot.get());
+ const double pointSize = textFont ? textFont->pointSizeF() : AnnotFreeText::undefinedFontPtSize;
+ if (pointSize < 0) {
+ qWarning() << "TextAnnotationPrivate::createNativeAnnot: font pointSize < 0";
+@@ -2008,7 +1998,7 @@ void TextAnnotationPrivate::setDefaultAppearanceToNative()
+ std::unique_ptr<DefaultAppearance> TextAnnotationPrivate::getDefaultAppearanceFromNative() const
+ {
+ if (pdfAnnot && pdfAnnot->getType() == Annot::typeFreeText) {
+- AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(pdfAnnot);
++ AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(pdfAnnot.get());
+ return ftextann->getDefaultAppearance();
+ } else {
+ return {};
+@@ -2165,7 +2155,7 @@ QString TextAnnotation::textIcon() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeText) {
+- const AnnotText *textann = static_cast<const AnnotText *>(d->pdfAnnot);
++ const AnnotText *textann = static_cast<const AnnotText *>(d->pdfAnnot.get());
+ return QString::fromLatin1(textann->getIcon()->c_str());
+ }
+
+@@ -2182,7 +2172,7 @@ void TextAnnotation::setTextIcon(const QString &icon)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeText) {
+- AnnotText *textann = static_cast<AnnotText *>(d->pdfAnnot);
++ AnnotText *textann = static_cast<AnnotText *>(d->pdfAnnot.get());
+ QByteArray encoded = icon.toLatin1();
+ GooString s(encoded.constData());
+ textann->setIcon(&s);
+@@ -2256,7 +2246,7 @@ int TextAnnotation::inplaceAlign() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeFreeText) {
+- const AnnotFreeText *ftextann = static_cast<const AnnotFreeText *>(d->pdfAnnot);
++ const AnnotFreeText *ftextann = static_cast<const AnnotFreeText *>(d->pdfAnnot.get());
+ return static_cast<int>(ftextann->getQuadding());
+ }
+
+@@ -2273,7 +2263,7 @@ void TextAnnotation::setInplaceAlign(int align)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeFreeText) {
+- AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(d->pdfAnnot);
++ AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(d->pdfAnnot.get());
+ ftextann->setQuadding((VariableTextQuadding)align);
+ }
+ }
+@@ -2300,7 +2290,7 @@ QVector<QPointF> TextAnnotation::calloutPoints() const
+ return QVector<QPointF>();
+ }
+
+- const AnnotFreeText *ftextann = static_cast<const AnnotFreeText *>(d->pdfAnnot);
++ const AnnotFreeText *ftextann = static_cast<const AnnotFreeText *>(d->pdfAnnot.get());
+ const AnnotCalloutLine *callout = ftextann->getCalloutLine();
+
+ if (!callout) {
+@@ -2332,7 +2322,7 @@ void TextAnnotation::setCalloutPoints(const QVector<QPointF> &points)
+ return;
+ }
+
+- AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(d->pdfAnnot);
++ AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(d->pdfAnnot.get());
+ const int count = points.size();
+
+ if (count == 0) {
+@@ -2345,7 +2335,7 @@ void TextAnnotation::setCalloutPoints(const QVector<QPointF> &points)
+ return;
+ }
+
+- AnnotCalloutLine *callout;
++ std::unique_ptr<AnnotCalloutLine> callout;
+ double x1, y1, x2, y2;
+ double MTX[6];
+ d->fillTransformationMTX(MTX);
+@@ -2355,13 +2345,12 @@ void TextAnnotation::setCalloutPoints(const QVector<QPointF> &points)
+ if (count == 3) {
+ double x3, y3;
+ XPDFReader::invTransform(MTX, points[2], x3, y3);
+- callout = new AnnotCalloutMultiLine(x1, y1, x2, y2, x3, y3);
++ callout = std::make_unique<AnnotCalloutMultiLine>(x1, y1, x2, y2, x3, y3);
+ } else {
+- callout = new AnnotCalloutLine(x1, y1, x2, y2);
++ callout = std::make_unique<AnnotCalloutLine>(x1, y1, x2, y2);
+ }
+
+- ftextann->setCalloutLine(callout);
+- delete callout;
++ ftextann->setCalloutLine(std::move(callout));
+ }
+
+ TextAnnotation::InplaceIntent TextAnnotation::inplaceIntent() const
+@@ -2373,7 +2362,7 @@ TextAnnotation::InplaceIntent TextAnnotation::inplaceIntent() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeFreeText) {
+- const AnnotFreeText *ftextann = static_cast<const AnnotFreeText *>(d->pdfAnnot);
++ const AnnotFreeText *ftextann = static_cast<const AnnotFreeText *>(d->pdfAnnot.get());
+ return (TextAnnotation::InplaceIntent)ftextann->getIntent();
+ }
+
+@@ -2390,7 +2379,7 @@ void TextAnnotation::setInplaceIntent(TextAnnotation::InplaceIntent intent)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeFreeText) {
+- AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(d->pdfAnnot);
++ AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(d->pdfAnnot.get());
+ ftextann->setIntent((AnnotFreeText::AnnotFreeTextIntent)intent);
+ }
+ }
+@@ -2400,8 +2389,8 @@ class LineAnnotationPrivate : public AnnotationPrivate
+ {
+ public:
+ LineAnnotationPrivate();
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields (note uses border for rendering style)
+ QLinkedList<QPointF> linePoints;
+@@ -2421,15 +2410,15 @@ LineAnnotationPrivate::LineAnnotationPrivate()
+ {
+ }
+
+-Annotation *LineAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> LineAnnotationPrivate::makeAlias()
+ {
+- return new LineAnnotation(*this);
++ return std::unique_ptr<LineAnnotation>(new LineAnnotation(*this));
+ }
+
+-Annot *LineAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> LineAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ // Setters are defined in the public class
+- LineAnnotation *q = static_cast<LineAnnotation *>(makeAlias());
++ std::unique_ptr<LineAnnotation> q = static_pointer_cast<LineAnnotation>(makeAlias());
+
+ // Set page and document
+ pdfPage = destPage;
+@@ -2438,9 +2427,9 @@ Annot *LineAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *
+ // Set pdfAnnot
+ PDFRectangle rect = boundaryToPdfRectangle(boundary, flags);
+ if (lineType == LineAnnotation::StraightLine) {
+- pdfAnnot = new AnnotLine(doc->doc, &rect);
++ pdfAnnot = std::make_shared<AnnotLine>(doc->doc, &rect);
+ } else {
+- pdfAnnot = new AnnotPolygon(doc->doc, &rect, lineClosed ? Annot::typePolygon : Annot::typePolyLine);
++ pdfAnnot = std::make_shared<AnnotPolygon>(doc->doc, &rect, lineClosed ? Annot::typePolygon : Annot::typePolyLine);
+ }
+
+ // Set properties
+@@ -2454,8 +2443,6 @@ Annot *LineAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *
+ q->setLineShowCaption(lineShowCaption);
+ q->setLineIntent(lineIntent);
+
+- delete q;
+-
+ linePoints.clear(); // Free up memory
+
+ return pdfAnnot;
+@@ -2621,14 +2608,14 @@ QLinkedList<QPointF> LineAnnotation::linePoints() const
+
+ QLinkedList<QPointF> res;
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot);
++ const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot.get());
+ QPointF p;
+ XPDFReader::transform(MTX, lineann->getX1(), lineann->getY1(), p);
+ res.append(p);
+ XPDFReader::transform(MTX, lineann->getX2(), lineann->getY2(), p);
+ res.append(p);
+ } else {
+- const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot);
++ const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot.get());
+ const AnnotPath *vertices = polyann->getVertices();
+
+ for (int i = 0; i < vertices->getCoordsLength(); ++i) {
+@@ -2651,7 +2638,7 @@ void LineAnnotation::setLinePoints(const QLinkedList<QPointF> &points)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot);
++ AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot.get());
+ if (points.size() != 2) {
+ error(errSyntaxError, -1, "Expected two points for a straight line");
+ return;
+@@ -2663,7 +2650,7 @@ void LineAnnotation::setLinePoints(const QLinkedList<QPointF> &points)
+ XPDFReader::invTransform(MTX, points.last(), x2, y2);
+ lineann->setVertices(x1, y1, x2, y2);
+ } else {
+- AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot);
++ AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot.get());
+ AnnotPath *p = d->toAnnotPath(points);
+ polyann->setVertices(p);
+ delete p;
+@@ -2679,10 +2666,10 @@ LineAnnotation::TermStyle LineAnnotation::lineStartStyle() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot);
++ const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot.get());
+ return (LineAnnotation::TermStyle)lineann->getStartStyle();
+ } else {
+- const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot);
++ const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot.get());
+ return (LineAnnotation::TermStyle)polyann->getStartStyle();
+ }
+ }
+@@ -2697,10 +2684,10 @@ void LineAnnotation::setLineStartStyle(LineAnnotation::TermStyle style)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot);
++ AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot.get());
+ lineann->setStartEndStyle((AnnotLineEndingStyle)style, lineann->getEndStyle());
+ } else {
+- AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot);
++ AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot.get());
+ polyann->setStartEndStyle((AnnotLineEndingStyle)style, polyann->getEndStyle());
+ }
+ }
+@@ -2714,10 +2701,10 @@ LineAnnotation::TermStyle LineAnnotation::lineEndStyle() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot);
++ const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot.get());
+ return (LineAnnotation::TermStyle)lineann->getEndStyle();
+ } else {
+- const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot);
++ const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot.get());
+ return (LineAnnotation::TermStyle)polyann->getEndStyle();
+ }
+ }
+@@ -2732,10 +2719,10 @@ void LineAnnotation::setLineEndStyle(LineAnnotation::TermStyle style)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot);
++ AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot.get());
+ lineann->setStartEndStyle(lineann->getStartStyle(), (AnnotLineEndingStyle)style);
+ } else {
+- AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot);
++ AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot.get());
+ polyann->setStartEndStyle(polyann->getStartStyle(), (AnnotLineEndingStyle)style);
+ }
+ }
+@@ -2761,7 +2748,7 @@ void LineAnnotation::setLineClosed(bool closed)
+ }
+
+ if (d->pdfAnnot->getType() != Annot::typeLine) {
+- AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot);
++ AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot.get());
+
+ // Set new subtype and switch intent if necessary
+ if (closed) {
+@@ -2789,10 +2776,10 @@ QColor LineAnnotation::lineInnerColor() const
+ AnnotColor *c;
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot);
++ const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot.get());
+ c = lineann->getInteriorColor();
+ } else {
+- const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot);
++ const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot.get());
+ c = polyann->getInteriorColor();
+ }
+
+@@ -2811,10 +2798,10 @@ void LineAnnotation::setLineInnerColor(const QColor &color)
+ auto c = convertQColor(color);
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot);
++ AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot.get());
+ lineann->setInteriorColor(std::move(c));
+ } else {
+- AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot);
++ AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot.get());
+ polyann->setInteriorColor(std::move(c));
+ }
+ }
+@@ -2828,7 +2815,7 @@ double LineAnnotation::lineLeadingForwardPoint() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot);
++ const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot.get());
+ return lineann->getLeaderLineLength();
+ }
+
+@@ -2845,7 +2832,7 @@ void LineAnnotation::setLineLeadingForwardPoint(double point)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot);
++ AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot.get());
+ lineann->setLeaderLineLength(point);
+ }
+ }
+@@ -2859,7 +2846,7 @@ double LineAnnotation::lineLeadingBackPoint() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot);
++ const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot.get());
+ return lineann->getLeaderLineExtension();
+ }
+
+@@ -2876,7 +2863,7 @@ void LineAnnotation::setLineLeadingBackPoint(double point)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot);
++ AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot.get());
+ lineann->setLeaderLineExtension(point);
+ }
+ }
+@@ -2890,7 +2877,7 @@ bool LineAnnotation::lineShowCaption() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot);
++ const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot.get());
+ return lineann->getCaption();
+ }
+
+@@ -2907,7 +2894,7 @@ void LineAnnotation::setLineShowCaption(bool show)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot);
++ AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot.get());
+ lineann->setCaption(show);
+ }
+ }
+@@ -2921,10 +2908,10 @@ LineAnnotation::LineIntent LineAnnotation::lineIntent() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot);
++ const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot.get());
+ return (LineAnnotation::LineIntent)(lineann->getIntent() + 1);
+ } else {
+- const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot);
++ const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot.get());
+ if (polyann->getIntent() == AnnotPolygon::polygonCloud) {
+ return LineAnnotation::PolygonCloud;
+ } else { // AnnotPolygon::polylineDimension, AnnotPolygon::polygonDimension
+@@ -2947,10 +2934,10 @@ void LineAnnotation::setLineIntent(LineAnnotation::LineIntent intent)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot);
++ AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot.get());
+ lineann->setIntent((AnnotLine::AnnotLineIntent)(intent - 1));
+ } else {
+- AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot);
++ AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot.get());
+ if (intent == LineAnnotation::PolygonCloud) {
+ polyann->setIntent(AnnotPolygon::polygonCloud);
+ } else // LineAnnotation::Dimension
+@@ -2969,8 +2956,8 @@ class GeomAnnotationPrivate : public AnnotationPrivate
+ {
+ public:
+ GeomAnnotationPrivate();
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields (note uses border for rendering style)
+ GeomAnnotation::GeomType geomType;
+@@ -2979,15 +2966,15 @@ public:
+
+ GeomAnnotationPrivate::GeomAnnotationPrivate() : AnnotationPrivate(), geomType(GeomAnnotation::InscribedSquare) { }
+
+-Annotation *GeomAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> GeomAnnotationPrivate::makeAlias()
+ {
+- return new GeomAnnotation(*this);
++ return std::unique_ptr<GeomAnnotation>(new GeomAnnotation(*this));
+ }
+
+-Annot *GeomAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> GeomAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ // Setters are defined in the public class
+- GeomAnnotation *q = static_cast<GeomAnnotation *>(makeAlias());
++ std::unique_ptr<GeomAnnotation> q = static_pointer_cast<GeomAnnotation>(makeAlias());
+
+ // Set page and document
+ pdfPage = destPage;
+@@ -3002,13 +2989,12 @@ Annot *GeomAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *
+
+ // Set pdfAnnot
+ PDFRectangle rect = boundaryToPdfRectangle(boundary, flags);
+- pdfAnnot = new AnnotGeometry(destPage->getDoc(), &rect, type);
++ pdfAnnot = std::make_shared<AnnotGeometry>(destPage->getDoc(), &rect, type);
+
+ // Set properties
+ flushBaseAnnotationProperties();
+ q->setGeomInnerColor(geomInnerColor);
+
+- delete q;
+ return pdfAnnot;
+ }
+
+@@ -3089,7 +3075,7 @@ void GeomAnnotation::setGeomType(GeomAnnotation::GeomType type)
+ return;
+ }
+
+- AnnotGeometry *geomann = static_cast<AnnotGeometry *>(d->pdfAnnot);
++ AnnotGeometry *geomann = static_cast<AnnotGeometry *>(d->pdfAnnot.get());
+ if (type == GeomAnnotation::InscribedSquare) {
+ geomann->setType(Annot::typeSquare);
+ } else { // GeomAnnotation::InscribedCircle
+@@ -3105,7 +3091,7 @@ QColor GeomAnnotation::geomInnerColor() const
+ return d->geomInnerColor;
+ }
+
+- const AnnotGeometry *geomann = static_cast<const AnnotGeometry *>(d->pdfAnnot);
++ const AnnotGeometry *geomann = static_cast<const AnnotGeometry *>(d->pdfAnnot.get());
+ return convertAnnotColor(geomann->getInteriorColor());
+ }
+
+@@ -3118,7 +3104,7 @@ void GeomAnnotation::setGeomInnerColor(const QColor &color)
+ return;
+ }
+
+- AnnotGeometry *geomann = static_cast<AnnotGeometry *>(d->pdfAnnot);
++ AnnotGeometry *geomann = static_cast<AnnotGeometry *>(d->pdfAnnot.get());
+ geomann->setInteriorColor(convertQColor(color));
+ }
+
+@@ -3127,8 +3113,8 @@ class HighlightAnnotationPrivate : public AnnotationPrivate
+ {
+ public:
+ HighlightAnnotationPrivate();
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields
+ HighlightAnnotation::HighlightType highlightType;
+@@ -3142,9 +3128,9 @@ public:
+
+ HighlightAnnotationPrivate::HighlightAnnotationPrivate() : AnnotationPrivate(), highlightType(HighlightAnnotation::Highlight) { }
+
+-Annotation *HighlightAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> HighlightAnnotationPrivate::makeAlias()
+ {
+- return new HighlightAnnotation(*this);
++ return std::unique_ptr<HighlightAnnotation>(new HighlightAnnotation(*this));
+ }
+
+ Annot::AnnotSubtype HighlightAnnotationPrivate::toAnnotSubType(HighlightAnnotation::HighlightType type)
+@@ -3217,10 +3203,10 @@ AnnotQuadrilaterals *HighlightAnnotationPrivate::toQuadrilaterals(const QList<Hi
+ return new AnnotQuadrilaterals(std::move(ac), count);
+ }
+
+-Annot *HighlightAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> HighlightAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ // Setters are defined in the public class
+- HighlightAnnotation *q = static_cast<HighlightAnnotation *>(makeAlias());
++ std::unique_ptr<HighlightAnnotation> q = static_pointer_cast<HighlightAnnotation>(makeAlias());
+
+ // Set page and document
+ pdfPage = destPage;
+@@ -3228,7 +3214,7 @@ Annot *HighlightAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentD
+
+ // Set pdfAnnot
+ PDFRectangle rect = boundaryToPdfRectangle(boundary, flags);
+- pdfAnnot = new AnnotTextMarkup(destPage->getDoc(), &rect, toAnnotSubType(highlightType));
++ pdfAnnot = std::make_shared<AnnotTextMarkup>(destPage->getDoc(), &rect, toAnnotSubType(highlightType));
+
+ // Set properties
+ flushBaseAnnotationProperties();
+@@ -3236,8 +3222,6 @@ Annot *HighlightAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentD
+
+ highlightQuads.clear(); // Free up memory
+
+- delete q;
+-
+ return pdfAnnot;
+ }
+
+@@ -3370,7 +3354,7 @@ void HighlightAnnotation::setHighlightType(HighlightAnnotation::HighlightType ty
+ return;
+ }
+
+- AnnotTextMarkup *hlann = static_cast<AnnotTextMarkup *>(d->pdfAnnot);
++ AnnotTextMarkup *hlann = static_cast<AnnotTextMarkup *>(d->pdfAnnot.get());
+ hlann->setType(HighlightAnnotationPrivate::toAnnotSubType(type));
+ }
+
+@@ -3382,7 +3366,7 @@ QList<HighlightAnnotation::Quad> HighlightAnnotation::highlightQuads() const
+ return d->highlightQuads;
+ }
+
+- const AnnotTextMarkup *hlann = static_cast<AnnotTextMarkup *>(d->pdfAnnot);
++ const AnnotTextMarkup *hlann = static_cast<AnnotTextMarkup *>(d->pdfAnnot.get());
+ return d->fromQuadrilaterals(hlann->getQuadrilaterals());
+ }
+
+@@ -3395,7 +3379,7 @@ void HighlightAnnotation::setHighlightQuads(const QList<HighlightAnnotation::Qua
+ return;
+ }
+
+- AnnotTextMarkup *hlann = static_cast<AnnotTextMarkup *>(d->pdfAnnot);
++ AnnotTextMarkup *hlann = static_cast<AnnotTextMarkup *>(d->pdfAnnot.get());
+ AnnotQuadrilaterals *quadrilaterals = d->toQuadrilaterals(quads);
+ hlann->setQuadrilaterals(quadrilaterals);
+ delete quadrilaterals;
+@@ -3406,10 +3390,10 @@ class StampAnnotationPrivate : public AnnotationPrivate
+ {
+ public:
+ StampAnnotationPrivate();
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+- AnnotStampImageHelper *convertQImageToAnnotStampImageHelper(const QImage &qimg);
++ std::unique_ptr<AnnotStampImageHelper> convertQImageToAnnotStampImageHelper(const QImage &qimg);
+
+ // data fields
+ QString stampIconName;
+@@ -3418,14 +3402,14 @@ public:
+
+ StampAnnotationPrivate::StampAnnotationPrivate() : AnnotationPrivate(), stampIconName(QStringLiteral("Draft")) { }
+
+-Annotation *StampAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> StampAnnotationPrivate::makeAlias()
+ {
+- return new StampAnnotation(*this);
++ return std::unique_ptr<StampAnnotation>(new StampAnnotation(*this));
+ }
+
+-Annot *StampAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> StampAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+- StampAnnotation *q = static_cast<StampAnnotation *>(makeAlias());
++ std::unique_ptr<StampAnnotation> q = static_pointer_cast<StampAnnotation>(makeAlias());
+
+ // Set page and document
+ pdfPage = destPage;
+@@ -3433,21 +3417,19 @@ Annot *StampAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData
+
+ // Set pdfAnnot
+ PDFRectangle rect = boundaryToPdfRectangle(boundary, flags);
+- pdfAnnot = new AnnotStamp(destPage->getDoc(), &rect);
++ pdfAnnot = std::make_shared<AnnotStamp>(destPage->getDoc(), &rect);
+
+ // Set properties
+ flushBaseAnnotationProperties();
+ q->setStampIconName(stampIconName);
+ q->setStampCustomImage(stampCustomImage);
+
+- delete q;
+-
+ stampIconName.clear(); // Free up memory
+
+ return pdfAnnot;
+ }
+
+-AnnotStampImageHelper *StampAnnotationPrivate::convertQImageToAnnotStampImageHelper(const QImage &qimg)
++std::unique_ptr<AnnotStampImageHelper> StampAnnotationPrivate::convertQImageToAnnotStampImageHelper(const QImage &qimg)
+ {
+ QImage convertedQImage = qimg;
+
+@@ -3528,13 +3510,13 @@ AnnotStampImageHelper *StampAnnotationPrivate::convertQImageToAnnotStampImageHel
+
+ getRawDataFromQImage(convertedQImage, convertedQImage.depth(), &data, &sMaskData);
+
+- AnnotStampImageHelper *annotImg;
++ std::unique_ptr<AnnotStampImageHelper> annotImg;
+
+ if (sMaskData.count() > 0) {
+ AnnotStampImageHelper sMask(parentDoc->doc, width, height, ColorSpace::DeviceGray, 8, sMaskData.data(), sMaskData.count());
+- annotImg = new AnnotStampImageHelper(parentDoc->doc, width, height, colorSpace, bitsPerComponent, data.data(), data.count(), sMask.getRef());
++ annotImg = std::make_unique<AnnotStampImageHelper>(parentDoc->doc, width, height, colorSpace, bitsPerComponent, data.data(), data.count(), sMask.getRef());
+ } else {
+- annotImg = new AnnotStampImageHelper(parentDoc->doc, width, height, colorSpace, bitsPerComponent, data.data(), data.count());
++ annotImg = std::make_unique<AnnotStampImageHelper>(parentDoc->doc, width, height, colorSpace, bitsPerComponent, data.data(), data.count());
+ }
+
+ return annotImg;
+@@ -3595,7 +3577,7 @@ QString StampAnnotation::stampIconName() const
+ return d->stampIconName;
+ }
+
+- const AnnotStamp *stampann = static_cast<const AnnotStamp *>(d->pdfAnnot);
++ const AnnotStamp *stampann = static_cast<const AnnotStamp *>(d->pdfAnnot.get());
+ return QString::fromLatin1(stampann->getIcon()->c_str());
+ }
+
+@@ -3608,7 +3590,7 @@ void StampAnnotation::setStampIconName(const QString &name)
+ return;
+ }
+
+- AnnotStamp *stampann = static_cast<AnnotStamp *>(d->pdfAnnot);
++ AnnotStamp *stampann = static_cast<AnnotStamp *>(d->pdfAnnot.get());
+ QByteArray encoded = name.toLatin1();
+ GooString s(encoded.constData());
+ stampann->setIcon(&s);
+@@ -3627,9 +3609,9 @@ void StampAnnotation::setStampCustomImage(const QImage &image)
+ return;
+ }
+
+- AnnotStamp *stampann = static_cast<AnnotStamp *>(d->pdfAnnot);
+- AnnotStampImageHelper *annotCustomImage = d->convertQImageToAnnotStampImageHelper(image);
+- stampann->setCustomImage(annotCustomImage);
++ AnnotStamp *stampann = static_cast<AnnotStamp *>(d->pdfAnnot.get());
++ std::unique_ptr<AnnotStampImageHelper> annotCustomImage = d->convertQImageToAnnotStampImageHelper(image);
++ stampann->setCustomImage(std::move(annotCustomImage));
+ }
+
+ /** InkAnnotation [Annotation] */
+@@ -3637,8 +3619,8 @@ class InkAnnotationPrivate : public AnnotationPrivate
+ {
+ public:
+ InkAnnotationPrivate();
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields
+ QList<QLinkedList<QPointF>> inkPaths;
+@@ -3649,9 +3631,9 @@ public:
+
+ InkAnnotationPrivate::InkAnnotationPrivate() : AnnotationPrivate() { }
+
+-Annotation *InkAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> InkAnnotationPrivate::makeAlias()
+ {
+- return new InkAnnotation(*this);
++ return std::unique_ptr<InkAnnotation>(new InkAnnotation(*this));
+ }
+
+ // Note: Caller is required to delete array elements and the array itself after use
+@@ -3665,10 +3647,10 @@ AnnotPath **InkAnnotationPrivate::toAnnotPaths(const QList<QLinkedList<QPointF>>
+ return res;
+ }
+
+-Annot *InkAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> InkAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ // Setters are defined in the public class
+- InkAnnotation *q = static_cast<InkAnnotation *>(makeAlias());
++ std::unique_ptr<InkAnnotation> q = static_pointer_cast<InkAnnotation>(makeAlias());
+
+ // Set page and document
+ pdfPage = destPage;
+@@ -3676,7 +3658,7 @@ Annot *InkAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *d
+
+ // Set pdfAnnot
+ PDFRectangle rect = boundaryToPdfRectangle(boundary, flags);
+- pdfAnnot = new AnnotInk(destPage->getDoc(), &rect);
++ pdfAnnot = std::make_shared<AnnotInk>(destPage->getDoc(), &rect);
+
+ // Set properties
+ flushBaseAnnotationProperties();
+@@ -3684,8 +3666,6 @@ Annot *InkAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *d
+
+ inkPaths.clear(); // Free up memory
+
+- delete q;
+-
+ return pdfAnnot;
+ }
+
+@@ -3787,7 +3767,7 @@ QList<QLinkedList<QPointF>> InkAnnotation::inkPaths() const
+ return d->inkPaths;
+ }
+
+- const AnnotInk *inkann = static_cast<const AnnotInk *>(d->pdfAnnot);
++ const AnnotInk *inkann = static_cast<const AnnotInk *>(d->pdfAnnot.get());
+
+ const AnnotPath *const *paths = inkann->getInkList();
+ if (!paths || !inkann->getInkListLength()) {
+@@ -3825,7 +3805,7 @@ void InkAnnotation::setInkPaths(const QList<QLinkedList<QPointF>> &paths)
+ return;
+ }
+
+- AnnotInk *inkann = static_cast<AnnotInk *>(d->pdfAnnot);
++ AnnotInk *inkann = static_cast<AnnotInk *>(d->pdfAnnot.get());
+ AnnotPath **annotpaths = d->toAnnotPaths(paths);
+ const int pathsNumber = paths.size();
+ inkann->setInkList(annotpaths, pathsNumber);
+@@ -3842,8 +3822,8 @@ class LinkAnnotationPrivate : public AnnotationPrivate
+ public:
+ LinkAnnotationPrivate();
+ ~LinkAnnotationPrivate() override;
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields
+ Link *linkDestination;
+@@ -3858,12 +3838,12 @@ LinkAnnotationPrivate::~LinkAnnotationPrivate()
+ delete linkDestination;
+ }
+
+-Annotation *LinkAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> LinkAnnotationPrivate::makeAlias()
+ {
+- return new LinkAnnotation(*this);
++ return std::unique_ptr<LinkAnnotation>(new LinkAnnotation(*this));
+ }
+
+-Annot *LinkAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> LinkAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ return nullptr; // Not implemented
+ }
+@@ -4144,8 +4124,8 @@ class CaretAnnotationPrivate : public AnnotationPrivate
+ {
+ public:
+ CaretAnnotationPrivate();
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields
+ CaretAnnotation::CaretSymbol symbol;
+@@ -4174,15 +4154,15 @@ static CaretAnnotation::CaretSymbol caretSymbolFromString(const QString &symbol)
+
+ CaretAnnotationPrivate::CaretAnnotationPrivate() : AnnotationPrivate(), symbol(CaretAnnotation::None) { }
+
+-Annotation *CaretAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> CaretAnnotationPrivate::makeAlias()
+ {
+- return new CaretAnnotation(*this);
++ return std::unique_ptr<CaretAnnotation>(new CaretAnnotation(*this));
+ }
+
+-Annot *CaretAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> CaretAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ // Setters are defined in the public class
+- CaretAnnotation *q = static_cast<CaretAnnotation *>(makeAlias());
++ std::unique_ptr<CaretAnnotation> q = static_pointer_cast<CaretAnnotation>(makeAlias());
+
+ // Set page and document
+ pdfPage = destPage;
+@@ -4190,13 +4170,12 @@ Annot *CaretAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData
+
+ // Set pdfAnnot
+ PDFRectangle rect = boundaryToPdfRectangle(boundary, flags);
+- pdfAnnot = new AnnotCaret(destPage->getDoc(), &rect);
++ pdfAnnot = std::make_shared<AnnotCaret>(destPage->getDoc(), &rect);
+
+ // Set properties
+ flushBaseAnnotationProperties();
+ q->setCaretSymbol(symbol);
+
+- delete q;
+ return pdfAnnot;
+ }
+
+@@ -4255,7 +4234,7 @@ CaretAnnotation::CaretSymbol CaretAnnotation::caretSymbol() const
+ return d->symbol;
+ }
+
+- const AnnotCaret *caretann = static_cast<const AnnotCaret *>(d->pdfAnnot);
++ const AnnotCaret *caretann = static_cast<const AnnotCaret *>(d->pdfAnnot.get());
+ return (CaretAnnotation::CaretSymbol)caretann->getSymbol();
+ }
+
+@@ -4268,7 +4247,7 @@ void CaretAnnotation::setCaretSymbol(CaretAnnotation::CaretSymbol symbol)
+ return;
+ }
+
+- AnnotCaret *caretann = static_cast<AnnotCaret *>(d->pdfAnnot);
++ AnnotCaret *caretann = static_cast<AnnotCaret *>(d->pdfAnnot.get());
+ caretann->setSymbol((AnnotCaret::AnnotCaretSymbol)symbol);
+ }
+
+@@ -4278,8 +4257,8 @@ class FileAttachmentAnnotationPrivate : public AnnotationPrivate
+ public:
+ FileAttachmentAnnotationPrivate();
+ ~FileAttachmentAnnotationPrivate() override;
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields
+ QString icon;
+@@ -4293,12 +4272,12 @@ FileAttachmentAnnotationPrivate::~FileAttachmentAnnotationPrivate()
+ delete embfile;
+ }
+
+-Annotation *FileAttachmentAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> FileAttachmentAnnotationPrivate::makeAlias()
+ {
+- return new FileAttachmentAnnotation(*this);
++ return std::unique_ptr<FileAttachmentAnnotation>(new FileAttachmentAnnotation(*this));
+ }
+
+-Annot *FileAttachmentAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> FileAttachmentAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ return nullptr; // Not implemented
+ }
+@@ -4370,8 +4349,8 @@ class SoundAnnotationPrivate : public AnnotationPrivate
+ public:
+ SoundAnnotationPrivate();
+ ~SoundAnnotationPrivate() override;
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields
+ QString icon;
+@@ -4385,12 +4364,12 @@ SoundAnnotationPrivate::~SoundAnnotationPrivate()
+ delete sound;
+ }
+
+-Annotation *SoundAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> SoundAnnotationPrivate::makeAlias()
+ {
+- return new SoundAnnotation(*this);
++ return std::unique_ptr<SoundAnnotation>(new SoundAnnotation(*this));
+ }
+
+-Annot *SoundAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> SoundAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ return nullptr; // Not implemented
+ }
+@@ -4462,8 +4441,8 @@ class MovieAnnotationPrivate : public AnnotationPrivate
+ public:
+ MovieAnnotationPrivate();
+ ~MovieAnnotationPrivate() override;
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields
+ MovieObject *movie;
+@@ -4477,12 +4456,12 @@ MovieAnnotationPrivate::~MovieAnnotationPrivate()
+ delete movie;
+ }
+
+-Annotation *MovieAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> MovieAnnotationPrivate::makeAlias()
+ {
+- return new MovieAnnotation(*this);
++ return std::unique_ptr<Annotation>(new MovieAnnotation(*this));
+ }
+
+-Annot *MovieAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> MovieAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ return nullptr; // Not implemented
+ }
+@@ -4554,8 +4533,8 @@ class ScreenAnnotationPrivate : public AnnotationPrivate
+ public:
+ ScreenAnnotationPrivate();
+ ~ScreenAnnotationPrivate() override;
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields
+ LinkRendition *action;
+@@ -4571,12 +4550,12 @@ ScreenAnnotationPrivate::~ScreenAnnotationPrivate()
+
+ ScreenAnnotation::ScreenAnnotation(ScreenAnnotationPrivate &dd) : Annotation(dd) { }
+
+-Annotation *ScreenAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> ScreenAnnotationPrivate::makeAlias()
+ {
+- return new ScreenAnnotation(*this);
++ return std::unique_ptr<ScreenAnnotation>(new ScreenAnnotation(*this));
+ }
+
+-Annot *ScreenAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> ScreenAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ return nullptr; // Not implemented
+ }
+@@ -4634,16 +4613,16 @@ Link *ScreenAnnotation::additionalAction(AdditionalActionType type) const
+ class WidgetAnnotationPrivate : public AnnotationPrivate
+ {
+ public:
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+ };
+
+-Annotation *WidgetAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> WidgetAnnotationPrivate::makeAlias()
+ {
+- return new WidgetAnnotation(*this);
++ return std::unique_ptr<WidgetAnnotation>(new WidgetAnnotation(*this));
+ }
+
+-Annot *WidgetAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> WidgetAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ return nullptr; // Not implemented
+ }
+@@ -4967,9 +4946,9 @@ public:
+
+ ~RichMediaAnnotationPrivate() override;
+
+- Annotation *makeAlias() override { return new RichMediaAnnotation(*this); }
++ std::unique_ptr<Annotation> makeAlias() override { return std::unique_ptr<RichMediaAnnotation>(new RichMediaAnnotation(*this)); }
+
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override
+ {
+ Q_UNUSED(destPage);
+ Q_UNUSED(doc);
+
+diff --git a/qt5/src/poppler-form.cc b/qt5/src/poppler-form.cc
+index dfdcd39..760a891 100644
+--- a/qt5/src/poppler-form.cc
++++ b/qt5/src/poppler-form.cc
+@@ -269,7 +269,7 @@ Link *FormField::additionalAction(AdditionalActionType type) const
+
+ Link *FormField::additionalAction(Annotation::AdditionalActionType type) const
+ {
+- ::AnnotWidget *w = m_formData->fm->getWidgetAnnotation();
++ std::shared_ptr<AnnotWidget> w = m_formData->fm->getWidgetAnnotation();
+ if (!w) {
+ return nullptr;
+ }
+@@ -350,7 +350,7 @@ void FormFieldButton::setIcon(const FormFieldIcon &icon)
+
+ FormWidgetButton *fwb = static_cast<FormWidgetButton *>(m_formData->fm);
+ if (fwb->getButtonType() == formButtonPush) {
+- ::AnnotWidget *w = m_formData->fm->getWidgetAnnotation();
++ ::AnnotWidget *w = m_formData->fm->getWidgetAnnotation().get();
+ FormFieldIconData *data = FormFieldIconData::getData(icon);
+ if (data->icon != nullptr) {
+ w->setNewAppearance(data->icon->lookup("AP"));
+diff --git a/qt6/src/poppler-annotation-private.h b/qt6/src/poppler-annotation-private.h
+index 35e2676..11cda48 100644
+--- a/qt6/src/poppler-annotation-private.h
++++ b/qt6/src/poppler-annotation-private.h
+@@ -59,7 +59,7 @@ public:
+
+ /* Returns an Annotation of the right subclass whose d_ptr points to
+ * this AnnotationPrivate */
+- virtual Annotation *makeAlias() = 0;
++ virtual std::unique_ptr<Annotation> makeAlias() = 0;
+
+ /* properties: contents related */
+ QString author;
+@@ -79,18 +79,18 @@ public:
+ /* revisions */
+ Annotation::RevScope revisionScope;
+ Annotation::RevType revisionType;
+- QList<Annotation *> revisions;
++ std::vector<std::unique_ptr<Annotation>> revisions;
+
+ /* After this call, the Annotation object will behave like a wrapper for
+ * the specified Annot object. All cached values are discarded */
+- void tieToNativeAnnot(Annot *ann, ::Page *page, DocumentData *doc);
++ void tieToNativeAnnot(std::shared_ptr<Annot> ann, ::Page *page, DocumentData *doc);
+
+ /* Creates a new Annot object on the specified page, flushes current
+ * values to that object and ties this Annotation to that object */
+- virtual Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) = 0;
++ virtual std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) = 0;
+
+ /* Inited to 0 (i.e. untied annotation) */
+- Annot *pdfAnnot;
++ std::shared_ptr<Annot> pdfAnnot;
+ ::Page *pdfPage;
+ DocumentData *parentDoc;
+
+diff --git a/qt6/src/poppler-annotation.cc b/qt6/src/poppler-annotation.cc
+index 1a3c813..c1fcdb6 100644
+--- a/qt6/src/poppler-annotation.cc
++++ b/qt6/src/poppler-annotation.cc
+@@ -57,6 +57,12 @@
+ #include <Link.h>
+ #include <DateInfo.h>
+
++template<typename T, typename U>
++static std::unique_ptr<T> static_pointer_cast(std::unique_ptr<U> &&in)
++{
++ return std::unique_ptr<T>(static_cast<std::add_pointer_t<T>>(in.release()));
++}
++
+ /* Almost all getters directly query the underlying poppler annotation, with
+ * the exceptions of link, file attachment, sound, movie and screen annotations,
+ * Whose data retrieval logic has not been moved yet. Their getters return
+@@ -129,36 +135,25 @@ void getRawDataFromQImage(const QImage &qimg, int bitsPerPixel, QByteArray *data
+ void AnnotationPrivate::addRevision(Annotation *ann, Annotation::RevScope scope, Annotation::RevType type)
+ {
+ /* Since ownership stays with the caller, create an alias of ann */
+- revisions.append(ann->d_ptr->makeAlias());
++ revisions.push_back(ann->d_ptr->makeAlias());
+
+ /* Set revision properties */
+ revisionScope = scope;
+ revisionType = type;
+ }
+
+-AnnotationPrivate::~AnnotationPrivate()
+-{
+- // Delete all children revisions
+- qDeleteAll(revisions);
+-
+- // Release Annot object
+- if (pdfAnnot) {
+- pdfAnnot->decRefCnt();
+- }
+-}
++AnnotationPrivate::~AnnotationPrivate() = default;
+
+-void AnnotationPrivate::tieToNativeAnnot(Annot *ann, ::Page *page, Poppler::DocumentData *doc)
++void AnnotationPrivate::tieToNativeAnnot(std::shared_ptr<Annot> ann, ::Page *page, Poppler::DocumentData *doc)
+ {
+ if (pdfAnnot) {
+ error(errIO, -1, "Annotation is already tied");
+ return;
+ }
+
+- pdfAnnot = ann;
++ pdfAnnot = std::move(ann);
+ pdfPage = page;
+ parentDoc = doc;
+-
+- pdfAnnot->incRefCnt();
+ }
+
+ /* This method is called when a new annotation is created, after pdfAnnot and
+@@ -167,7 +162,7 @@ void AnnotationPrivate::flushBaseAnnotationProperties()
+ {
+ Q_ASSERT(pdfPage);
+
+- Annotation *q = makeAlias(); // Setters are defined in the public class
++ std::unique_ptr<Annotation> q = makeAlias(); // Setters are defined in the public class
+
+ // Since pdfAnnot has been set, this calls will write in the Annot object
+ q->setAuthor(author);
+@@ -180,14 +175,6 @@ void AnnotationPrivate::flushBaseAnnotationProperties()
+ q->setStyle(style);
+ q->setPopup(popup);
+
+- // Flush revisions
+- foreach (Annotation *r, revisions) {
+- // TODO: Flush revision
+- delete r; // Object is no longer needed
+- }
+-
+- delete q;
+-
+ // Clear some members to save memory
+ author.clear();
+ contents.clear();
+@@ -377,14 +364,14 @@ std::vector<std::unique_ptr<Annotation>> AnnotationPrivate::findAnnotations(::Pa
+
+ // Create Annotation objects and tie to their native Annot
+ std::vector<std::unique_ptr<Annotation>> res;
+- for (Annot *ann : annots->getAnnots()) {
++ for (const std::shared_ptr<Annot> &ann : annots->getAnnots()) {
+ if (!ann) {
+ error(errInternal, -1, "Annot is null");
+ continue;
+ }
+
+ // Check parent annotation
+- AnnotMarkup *markupann = dynamic_cast<AnnotMarkup *>(ann);
++ AnnotMarkup *markupann = dynamic_cast<AnnotMarkup *>(ann.get());
+ if (!markupann) {
+ // Assume it's a root annotation, and skip if user didn't request it
+ if (parentID != -1) {
+@@ -458,7 +445,7 @@ std::vector<std::unique_ptr<Annotation>> AnnotationPrivate::findAnnotations(::Pa
+ continue;
+ }
+ // parse Link params
+- AnnotLink *linkann = static_cast<AnnotLink *>(ann);
++ AnnotLink *linkann = static_cast<AnnotLink *>(ann.get());
+ LinkAnnotation *l = new LinkAnnotation();
+
+ // -> hlMode
+@@ -488,7 +475,7 @@ std::vector<std::unique_ptr<Annotation>> AnnotationPrivate::findAnnotations(::Pa
+ if (!wantFileAttachmentAnnotations) {
+ continue;
+ }
+- AnnotFileAttachment *attachann = static_cast<AnnotFileAttachment *>(ann);
++ AnnotFileAttachment *attachann = static_cast<AnnotFileAttachment *>(ann.get());
+ FileAttachmentAnnotation *f = new FileAttachmentAnnotation();
+ // -> fileIcon
+ f->setFileIconName(QString::fromLatin1(attachann->getName()->c_str()));
+@@ -503,7 +490,7 @@ std::vector<std::unique_ptr<Annotation>> AnnotationPrivate::findAnnotations(::Pa
+ if (!wantSoundAnnotations) {
+ continue;
+ }
+- AnnotSound *soundann = static_cast<AnnotSound *>(ann);
++ AnnotSound *soundann = static_cast<AnnotSound *>(ann.get());
+ SoundAnnotation *s = new SoundAnnotation();
+
+ // -> soundIcon
+@@ -518,7 +505,7 @@ std::vector<std::unique_ptr<Annotation>> AnnotationPrivate::findAnnotations(::Pa
+ if (!wantMovieAnnotations) {
+ continue;
+ }
+- AnnotMovie *movieann = static_cast<AnnotMovie *>(ann);
++ AnnotMovie *movieann = static_cast<AnnotMovie *>(ann.get());
+ MovieAnnotation *m = new MovieAnnotation();
+
+ // -> movie
+@@ -536,7 +523,7 @@ std::vector<std::unique_ptr<Annotation>> AnnotationPrivate::findAnnotations(::Pa
+ if (!wantScreenAnnotations) {
+ continue;
+ }
+- AnnotScreen *screenann = static_cast<AnnotScreen *>(ann);
++ AnnotScreen *screenann = static_cast<AnnotScreen *>(ann.get());
+ // TODO Support other link types than Link::Rendition in ScreenAnnotation
+ if (!screenann->getAction() || screenann->getAction()->getKind() != actionRendition) {
+ continue;
+@@ -566,7 +553,7 @@ std::vector<std::unique_ptr<Annotation>> AnnotationPrivate::findAnnotations(::Pa
+ annotation.reset(new WidgetAnnotation());
+ break;
+ case Annot::typeRichMedia: {
+- const AnnotRichMedia *annotRichMedia = static_cast<AnnotRichMedia *>(ann);
++ const AnnotRichMedia *annotRichMedia = static_cast<AnnotRichMedia *>(ann.get());
+
+ RichMediaAnnotation *richMediaAnnotation = new RichMediaAnnotation;
+
+@@ -774,9 +761,9 @@ std::unique_ptr<Link> AnnotationPrivate::additionalAction(Annotation::Additional
+
+ std::unique_ptr<::LinkAction> linkAction;
+ if (pdfAnnot->getType() == Annot::typeScreen) {
+- linkAction = static_cast<AnnotScreen *>(pdfAnnot)->getAdditionalAction(actionType);
++ linkAction = static_cast<AnnotScreen *>(pdfAnnot.get())->getAdditionalAction(actionType);
+ } else {
+- linkAction = static_cast<AnnotWidget *>(pdfAnnot)->getAdditionalAction(actionType);
++ linkAction = static_cast<AnnotWidget *>(pdfAnnot.get())->getAdditionalAction(actionType);
+ }
+
+ if (linkAction) {
+@@ -795,7 +782,7 @@ void AnnotationPrivate::addAnnotationToPage(::Page *pdfPage, DocumentData *doc,
+
+ // Unimplemented annotations can't be created by the user because their ctor
+ // is private. Therefore, createNativeAnnot will never return 0
+- Annot *nativeAnnot = ann->d_ptr->createNativeAnnot(pdfPage, doc);
++ std::shared_ptr<Annot> nativeAnnot = ann->d_ptr->createNativeAnnot(pdfPage, doc);
+ Q_ASSERT(nativeAnnot);
+
+ if (ann->d_ptr->annotationAppearance.isStream()) {
+@@ -828,8 +815,8 @@ class TextAnnotationPrivate : public AnnotationPrivate
+ {
+ public:
+ TextAnnotationPrivate();
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+ void setDefaultAppearanceToNative();
+ std::unique_ptr<DefaultAppearance> getDefaultAppearanceFromNative() const;
+
+@@ -1057,7 +1044,7 @@ QString Annotation::author() const
+ return d->author;
+ }
+
+- const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot);
++ const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot.get());
+ return markupann ? UnicodeParsedString(markupann->getLabel()) : QString();
+ }
+
+@@ -1070,7 +1057,7 @@ void Annotation::setAuthor(const QString &author)
+ return;
+ }
+
+- AnnotMarkup *markupann = dynamic_cast<AnnotMarkup *>(d->pdfAnnot);
++ AnnotMarkup *markupann = dynamic_cast<AnnotMarkup *>(d->pdfAnnot.get());
+ if (markupann) {
+ markupann->setLabel(std::unique_ptr<GooString>(QStringToUnicodeGooString(author)));
+ }
+@@ -1173,7 +1160,7 @@ QDateTime Annotation::creationDate() const
+ return d->creationDate;
+ }
+
+- const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot);
++ const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot.get());
+
+ if (markupann && markupann->getDate()) {
+ return convertDate(markupann->getDate()->c_str());
+@@ -1191,7 +1178,7 @@ void Annotation::setCreationDate(const QDateTime &date)
+ return;
+ }
+
+- AnnotMarkup *markupann = dynamic_cast<AnnotMarkup *>(d->pdfAnnot);
++ AnnotMarkup *markupann = dynamic_cast<AnnotMarkup *>(d->pdfAnnot.get());
+ if (markupann) {
+ if (date.isValid()) {
+ const time_t t = date.toSecsSinceEpoch();
+@@ -1325,7 +1312,7 @@ Annotation::Style Annotation::style() const
+ Style s;
+ s.setColor(convertAnnotColor(d->pdfAnnot->getColor()));
+
+- const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot);
++ const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot.get());
+ if (markupann) {
+ s.setOpacity(markupann->getOpacity());
+ }
+@@ -1348,11 +1335,11 @@ Annotation::Style Annotation::style() const
+ AnnotBorderEffect *border_effect;
+ switch (d->pdfAnnot->getType()) {
+ case Annot::typeFreeText:
+- border_effect = static_cast<AnnotFreeText *>(d->pdfAnnot)->getBorderEffect();
++ border_effect = static_cast<AnnotFreeText *>(d->pdfAnnot.get())->getBorderEffect();
+ break;
+ case Annot::typeSquare:
+ case Annot::typeCircle:
+- border_effect = static_cast<AnnotGeometry *>(d->pdfAnnot)->getBorderEffect();
++ border_effect = static_cast<AnnotGeometry *>(d->pdfAnnot.get())->getBorderEffect();
+ break;
+ default:
+ border_effect = nullptr;
+@@ -1376,7 +1363,7 @@ void Annotation::setStyle(const Annotation::Style &style)
+
+ d->pdfAnnot->setColor(convertQColor(style.color()));
+
+- AnnotMarkup *markupann = dynamic_cast<AnnotMarkup *>(d->pdfAnnot);
++ AnnotMarkup *markupann = dynamic_cast<AnnotMarkup *>(d->pdfAnnot.get());
+ if (markupann) {
+ markupann->setOpacity(style.opacity());
+ }
+@@ -1397,10 +1384,10 @@ Annotation::Popup Annotation::popup() const
+ }
+
+ Popup w;
+- AnnotPopup *popup = nullptr;
++ std::shared_ptr<AnnotPopup> popup = nullptr;
+ int flags = -1; // Not initialized
+
+- const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot);
++ const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot.get());
+ if (markupann) {
+ popup = markupann->getPopup();
+ w.setSummary(UnicodeParsedString(markupann->getSubject()));
+@@ -1418,7 +1405,7 @@ Annotation::Popup Annotation::popup() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeText) {
+- const AnnotText *textann = static_cast<const AnnotText *>(d->pdfAnnot);
++ const AnnotText *textann = static_cast<const AnnotText *>(d->pdfAnnot.get());
+
+ // Text annotations default to same rect as annotation
+ if (flags == -1) {
+@@ -1474,7 +1461,7 @@ Annotation::RevScope Annotation::revisionScope() const
+ return d->revisionScope;
+ }
+
+- const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot);
++ const AnnotMarkup *markupann = dynamic_cast<const AnnotMarkup *>(d->pdfAnnot.get());
+
+ if (markupann && markupann->isInReplyTo()) {
+ switch (markupann->getReplyTo()) {
+@@ -1496,7 +1483,7 @@ Annotation::RevType Annotation::revisionType() const
+ return d->revisionType;
+ }
+
+- const AnnotText *textann = dynamic_cast<const AnnotText *>(d->pdfAnnot);
++ const AnnotText *textann = dynamic_cast<const AnnotText *>(d->pdfAnnot.get());
+
+ if (textann && textann->isInReplyTo()) {
+ switch (textann->getState()) {
+@@ -1527,8 +1514,10 @@ std::vector<std::unique_ptr<Annotation>> Annotation::revisions() const
+ if (!d->pdfAnnot) {
+ /* Return aliases, whose ownership goes to the caller */
+ std::vector<std::unique_ptr<Annotation>> res;
+- foreach (Annotation *rev, d->revisions)
+- res.push_back(std::unique_ptr<Annotation>(rev->d_ptr->makeAlias()));
++ res.reserve(d->revisions.size());
++ for (const std::unique_ptr<Annotation> &rev : d->revisions) {
++ res.push_back(rev->d_ptr->makeAlias());
++ }
+ return res;
+ }
+
+@@ -1545,7 +1534,7 @@ std::unique_ptr<AnnotationAppearance> Annotation::annotationAppearance() const
+ {
+ Q_D(const Annotation);
+
+- return std::make_unique<AnnotationAppearance>(new AnnotationAppearancePrivate(d->pdfAnnot));
++ return std::make_unique<AnnotationAppearance>(new AnnotationAppearancePrivate(d->pdfAnnot.get()));
+ }
+
+ void Annotation::setAnnotationAppearance(const AnnotationAppearance &annotationAppearance)
+@@ -1568,15 +1557,15 @@ void Annotation::setAnnotationAppearance(const AnnotationAppearance &annotationA
+ /** TextAnnotation [Annotation] */
+ TextAnnotationPrivate::TextAnnotationPrivate() : AnnotationPrivate(), textType(TextAnnotation::Linked), textIcon(QStringLiteral("Note")), inplaceAlign(TextAnnotation::InplaceAlignLeft), inplaceIntent(TextAnnotation::Unknown) { }
+
+-Annotation *TextAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> TextAnnotationPrivate::makeAlias()
+ {
+- return new TextAnnotation(*this);
++ return std::unique_ptr<Annotation>(new TextAnnotation(*this));
+ }
+
+-Annot *TextAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> TextAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ // Setters are defined in the public class
+- TextAnnotation *q = static_cast<TextAnnotation *>(makeAlias());
++ std::unique_ptr<TextAnnotation> q = static_pointer_cast<TextAnnotation>(makeAlias());
+
+ // Set page and contents
+ pdfPage = destPage;
+@@ -1585,13 +1574,13 @@ Annot *TextAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *
+ // Set pdfAnnot
+ PDFRectangle rect = boundaryToPdfRectangle(boundary, flags);
+ if (textType == TextAnnotation::Linked) {
+- pdfAnnot = new AnnotText { destPage->getDoc(), &rect };
++ pdfAnnot = std::make_shared<AnnotText>(destPage->getDoc(), &rect);
+ } else {
+ const double pointSize = textFont ? textFont->pointSizeF() : AnnotFreeText::undefinedFontPtSize;
+ if (pointSize < 0) {
+ qWarning() << "TextAnnotationPrivate::createNativeAnnot: font pointSize < 0";
+ }
+- pdfAnnot = new AnnotFreeText { destPage->getDoc(), &rect };
++ pdfAnnot = std::make_shared<AnnotFreeText>(destPage->getDoc(), &rect);
+ }
+
+ // Set properties
+@@ -1601,8 +1590,6 @@ Annot *TextAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *
+ q->setCalloutPoints(inplaceCallout);
+ q->setInplaceIntent(inplaceIntent);
+
+- delete q;
+-
+ inplaceCallout.clear(); // Free up memory
+
+ setDefaultAppearanceToNative();
+@@ -1613,7 +1600,7 @@ Annot *TextAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *
+ void TextAnnotationPrivate::setDefaultAppearanceToNative()
+ {
+ if (pdfAnnot && pdfAnnot->getType() == Annot::typeFreeText) {
+- AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(pdfAnnot);
++ AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(pdfAnnot.get());
+ const double pointSize = textFont ? textFont->pointSizeF() : AnnotFreeText::undefinedFontPtSize;
+ if (pointSize < 0) {
+ qWarning() << "TextAnnotationPrivate::createNativeAnnot: font pointSize < 0";
+@@ -1642,7 +1629,7 @@ void TextAnnotationPrivate::setDefaultAppearanceToNative()
+ std::unique_ptr<DefaultAppearance> TextAnnotationPrivate::getDefaultAppearanceFromNative() const
+ {
+ if (pdfAnnot && pdfAnnot->getType() == Annot::typeFreeText) {
+- AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(pdfAnnot);
++ AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(pdfAnnot.get());
+ return ftextann->getDefaultAppearance();
+ } else {
+ return {};
+@@ -1696,7 +1683,7 @@ QString TextAnnotation::textIcon() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeText) {
+- const AnnotText *textann = static_cast<const AnnotText *>(d->pdfAnnot);
++ const AnnotText *textann = static_cast<const AnnotText *>(d->pdfAnnot.get());
+ return QString::fromLatin1(textann->getIcon()->c_str());
+ }
+
+@@ -1713,7 +1700,7 @@ void TextAnnotation::setTextIcon(const QString &icon)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeText) {
+- AnnotText *textann = static_cast<AnnotText *>(d->pdfAnnot);
++ AnnotText *textann = static_cast<AnnotText *>(d->pdfAnnot.get());
+ QByteArray encoded = icon.toLatin1();
+ GooString s(encoded.constData());
+ textann->setIcon(&s);
+@@ -1787,7 +1774,7 @@ TextAnnotation::InplaceAlignPosition TextAnnotation::inplaceAlign() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeFreeText) {
+- const AnnotFreeText *ftextann = static_cast<const AnnotFreeText *>(d->pdfAnnot);
++ const AnnotFreeText *ftextann = static_cast<const AnnotFreeText *>(d->pdfAnnot.get());
+ switch (ftextann->getQuadding()) {
+ case VariableTextQuadding::leftJustified:
+ return InplaceAlignLeft;
+@@ -1824,7 +1811,7 @@ void TextAnnotation::setInplaceAlign(InplaceAlignPosition align)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeFreeText) {
+- AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(d->pdfAnnot);
++ AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(d->pdfAnnot.get());
+ ftextann->setQuadding(alignToQuadding(align));
+ }
+ }
+@@ -1851,7 +1838,7 @@ QVector<QPointF> TextAnnotation::calloutPoints() const
+ return QVector<QPointF>();
+ }
+
+- const AnnotFreeText *ftextann = static_cast<const AnnotFreeText *>(d->pdfAnnot);
++ const AnnotFreeText *ftextann = static_cast<const AnnotFreeText *>(d->pdfAnnot.get());
+ const AnnotCalloutLine *callout = ftextann->getCalloutLine();
+
+ if (!callout) {
+@@ -1883,7 +1870,7 @@ void TextAnnotation::setCalloutPoints(const QVector<QPointF> &points)
+ return;
+ }
+
+- AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(d->pdfAnnot);
++ AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(d->pdfAnnot.get());
+ const int count = points.size();
+
+ if (count == 0) {
+@@ -1896,7 +1883,7 @@ void TextAnnotation::setCalloutPoints(const QVector<QPointF> &points)
+ return;
+ }
+
+- AnnotCalloutLine *callout;
++ std::unique_ptr<AnnotCalloutLine> *callout;
+ double x1, y1, x2, y2;
+ double MTX[6];
+ d->fillTransformationMTX(MTX);
+@@ -1906,13 +1893,12 @@ void TextAnnotation::setCalloutPoints(const QVector<QPointF> &points)
+ if (count == 3) {
+ double x3, y3;
+ XPDFReader::invTransform(MTX, points[2], x3, y3);
+- callout = new AnnotCalloutMultiLine(x1, y1, x2, y2, x3, y3);
++ callout = std::make_unique<AnnotCalloutMultiLine>(x1, y1, x2, y2, x3, y3);
+ } else {
+- callout = new AnnotCalloutLine(x1, y1, x2, y2);
++ callout = std::make_unique<AnnotCalloutLine>(x1, y1, x2, y2);
+ }
+
+- ftextann->setCalloutLine(callout);
+- delete callout;
++ ftextann->setCalloutLine(std::move(callout));
+ }
+
+ TextAnnotation::InplaceIntent TextAnnotation::inplaceIntent() const
+@@ -1924,7 +1910,7 @@ TextAnnotation::InplaceIntent TextAnnotation::inplaceIntent() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeFreeText) {
+- const AnnotFreeText *ftextann = static_cast<const AnnotFreeText *>(d->pdfAnnot);
++ const AnnotFreeText *ftextann = static_cast<const AnnotFreeText *>(d->pdfAnnot.get());
+ return (TextAnnotation::InplaceIntent)ftextann->getIntent();
+ }
+
+@@ -1941,7 +1927,7 @@ void TextAnnotation::setInplaceIntent(TextAnnotation::InplaceIntent intent)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeFreeText) {
+- AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(d->pdfAnnot);
++ AnnotFreeText *ftextann = static_cast<AnnotFreeText *>(d->pdfAnnot.get());
+ ftextann->setIntent((AnnotFreeText::AnnotFreeTextIntent)intent);
+ }
+ }
+@@ -1951,8 +1937,8 @@ class LineAnnotationPrivate : public AnnotationPrivate
+ {
+ public:
+ LineAnnotationPrivate();
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields (note uses border for rendering style)
+ QVector<QPointF> linePoints;
+@@ -1972,15 +1958,15 @@ LineAnnotationPrivate::LineAnnotationPrivate()
+ {
+ }
+
+-Annotation *LineAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> LineAnnotationPrivate::makeAlias()
+ {
+- return new LineAnnotation(*this);
++ return std::unique_ptr<Annotation>(new LineAnnotation(*this));
+ }
+
+-Annot *LineAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> LineAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ // Setters are defined in the public class
+- LineAnnotation *q = static_cast<LineAnnotation *>(makeAlias());
++ std::unique_ptr<LineAnnotation> q = static_pointer_cast<LineAnnotation *>(makeAlias());
+
+ // Set page and document
+ pdfPage = destPage;
+@@ -1989,9 +1975,9 @@ Annot *LineAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *
+ // Set pdfAnnot
+ PDFRectangle rect = boundaryToPdfRectangle(boundary, flags);
+ if (lineType == LineAnnotation::StraightLine) {
+- pdfAnnot = new AnnotLine(doc->doc, &rect);
++ pdfAnnot = std::make_shared<AnnotLine>(doc->doc, &rect);
+ } else {
+- pdfAnnot = new AnnotPolygon(doc->doc, &rect, lineClosed ? Annot::typePolygon : Annot::typePolyLine);
++ pdfAnnot = std::make_shared<AnnotPolygon>(doc->doc, &rect, lineClosed ? Annot::typePolygon : Annot::typePolyLine);
+ }
+
+ // Set properties
+@@ -2005,8 +1991,6 @@ Annot *LineAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *
+ q->setLineShowCaption(lineShowCaption);
+ q->setLineIntent(lineIntent);
+
+- delete q;
+-
+ linePoints.clear(); // Free up memory
+
+ return pdfAnnot;
+@@ -2063,14 +2047,14 @@ QVector<QPointF> LineAnnotation::linePoints() const
+
+ QVector<QPointF> res;
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot);
++ const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot.get());
+ QPointF p;
+ XPDFReader::transform(MTX, lineann->getX1(), lineann->getY1(), p);
+ res.append(p);
+ XPDFReader::transform(MTX, lineann->getX2(), lineann->getY2(), p);
+ res.append(p);
+ } else {
+- const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot);
++ const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot.get());
+ const AnnotPath *vertices = polyann->getVertices();
+
+ for (int i = 0; i < vertices->getCoordsLength(); ++i) {
+@@ -2093,7 +2077,7 @@ void LineAnnotation::setLinePoints(const QVector<QPointF> &points)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot);
++ AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot.get());
+ if (points.size() != 2) {
+ error(errSyntaxError, -1, "Expected two points for a straight line");
+ return;
+@@ -2105,7 +2089,7 @@ void LineAnnotation::setLinePoints(const QVector<QPointF> &points)
+ XPDFReader::invTransform(MTX, points.last(), x2, y2);
+ lineann->setVertices(x1, y1, x2, y2);
+ } else {
+- AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot);
++ AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot.get());
+ AnnotPath *p = d->toAnnotPath(points);
+ polyann->setVertices(p);
+ delete p;
+@@ -2121,10 +2105,10 @@ LineAnnotation::TermStyle LineAnnotation::lineStartStyle() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot);
++ const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot.get());
+ return (LineAnnotation::TermStyle)lineann->getStartStyle();
+ } else {
+- const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot);
++ const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot.get());
+ return (LineAnnotation::TermStyle)polyann->getStartStyle();
+ }
+ }
+@@ -2139,10 +2123,10 @@ void LineAnnotation::setLineStartStyle(LineAnnotation::TermStyle style)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot);
++ AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot.get());
+ lineann->setStartEndStyle((AnnotLineEndingStyle)style, lineann->getEndStyle());
+ } else {
+- AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot);
++ AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot.get());
+ polyann->setStartEndStyle((AnnotLineEndingStyle)style, polyann->getEndStyle());
+ }
+ }
+@@ -2156,10 +2140,10 @@ LineAnnotation::TermStyle LineAnnotation::lineEndStyle() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot);
++ const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot.get());
+ return (LineAnnotation::TermStyle)lineann->getEndStyle();
+ } else {
+- const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot);
++ const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot.get());
+ return (LineAnnotation::TermStyle)polyann->getEndStyle();
+ }
+ }
+@@ -2174,10 +2158,10 @@ void LineAnnotation::setLineEndStyle(LineAnnotation::TermStyle style)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot);
++ AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot.get());
+ lineann->setStartEndStyle(lineann->getStartStyle(), (AnnotLineEndingStyle)style);
+ } else {
+- AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot);
++ AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot.get());
+ polyann->setStartEndStyle(polyann->getStartStyle(), (AnnotLineEndingStyle)style);
+ }
+ }
+@@ -2203,7 +2187,7 @@ void LineAnnotation::setLineClosed(bool closed)
+ }
+
+ if (d->pdfAnnot->getType() != Annot::typeLine) {
+- AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot);
++ AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot.get());
+
+ // Set new subtype and switch intent if necessary
+ if (closed) {
+@@ -2231,10 +2215,10 @@ QColor LineAnnotation::lineInnerColor() const
+ AnnotColor *c;
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot);
++ const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot.get());
+ c = lineann->getInteriorColor();
+ } else {
+- const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot);
++ const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot.get());
+ c = polyann->getInteriorColor();
+ }
+
+@@ -2253,10 +2237,10 @@ void LineAnnotation::setLineInnerColor(const QColor &color)
+ auto c = convertQColor(color);
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot);
++ AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot.get());
+ lineann->setInteriorColor(std::move(c));
+ } else {
+- AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot);
++ AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot.get());
+ polyann->setInteriorColor(std::move(c));
+ }
+ }
+@@ -2270,7 +2254,7 @@ double LineAnnotation::lineLeadingForwardPoint() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot);
++ const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot.get());
+ return lineann->getLeaderLineLength();
+ }
+
+@@ -2287,7 +2271,7 @@ void LineAnnotation::setLineLeadingForwardPoint(double point)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot);
++ AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot.get());
+ lineann->setLeaderLineLength(point);
+ }
+ }
+@@ -2301,7 +2285,7 @@ double LineAnnotation::lineLeadingBackPoint() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot);
++ const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot.get());
+ return lineann->getLeaderLineExtension();
+ }
+
+@@ -2318,7 +2302,7 @@ void LineAnnotation::setLineLeadingBackPoint(double point)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot);
++ AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot.get());
+ lineann->setLeaderLineExtension(point);
+ }
+ }
+@@ -2332,7 +2316,7 @@ bool LineAnnotation::lineShowCaption() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot);
++ const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot.get());
+ return lineann->getCaption();
+ }
+
+@@ -2349,7 +2333,7 @@ void LineAnnotation::setLineShowCaption(bool show)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot);
++ AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot.get());
+ lineann->setCaption(show);
+ }
+ }
+@@ -2363,10 +2347,10 @@ LineAnnotation::LineIntent LineAnnotation::lineIntent() const
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot);
++ const AnnotLine *lineann = static_cast<const AnnotLine *>(d->pdfAnnot.get());
+ return (LineAnnotation::LineIntent)(lineann->getIntent() + 1);
+ } else {
+- const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot);
++ const AnnotPolygon *polyann = static_cast<const AnnotPolygon *>(d->pdfAnnot.get());
+ if (polyann->getIntent() == AnnotPolygon::polygonCloud) {
+ return LineAnnotation::PolygonCloud;
+ } else { // AnnotPolygon::polylineDimension, AnnotPolygon::polygonDimension
+@@ -2389,10 +2373,10 @@ void LineAnnotation::setLineIntent(LineAnnotation::LineIntent intent)
+ }
+
+ if (d->pdfAnnot->getType() == Annot::typeLine) {
+- AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot);
++ AnnotLine *lineann = static_cast<AnnotLine *>(d->pdfAnnot.get());
+ lineann->setIntent((AnnotLine::AnnotLineIntent)(intent - 1));
+ } else {
+- AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot);
++ AnnotPolygon *polyann = static_cast<AnnotPolygon *>(d->pdfAnnot.get());
+ if (intent == LineAnnotation::PolygonCloud) {
+ polyann->setIntent(AnnotPolygon::polygonCloud);
+ } else // LineAnnotation::Dimension
+@@ -2411,8 +2395,8 @@ class GeomAnnotationPrivate : public AnnotationPrivate
+ {
+ public:
+ GeomAnnotationPrivate();
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields (note uses border for rendering style)
+ GeomAnnotation::GeomType geomType;
+@@ -2421,15 +2405,15 @@ public:
+
+ GeomAnnotationPrivate::GeomAnnotationPrivate() : AnnotationPrivate(), geomType(GeomAnnotation::InscribedSquare) { }
+
+-Annotation *GeomAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> GeomAnnotationPrivate::makeAlias()
+ {
+- return new GeomAnnotation(*this);
++ return std::unique_ptr<Annotation>(new GeomAnnotation(*this));
+ }
+
+-Annot *GeomAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> GeomAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ // Setters are defined in the public class
+- GeomAnnotation *q = static_cast<GeomAnnotation *>(makeAlias());
++ std::unique_ptr<GeomAnnotation> q = static_pointer_cast<GeomAnnotation *>(makeAlias());
+
+ // Set page and document
+ pdfPage = destPage;
+@@ -2444,13 +2428,12 @@ Annot *GeomAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *
+
+ // Set pdfAnnot
+ PDFRectangle rect = boundaryToPdfRectangle(boundary, flags);
+- pdfAnnot = new AnnotGeometry(destPage->getDoc(), &rect, type);
++ pdfAnnot = std::make_shared<AnnotGeometry>(destPage->getDoc(), &rect, type);
+
+ // Set properties
+ flushBaseAnnotationProperties();
+ q->setGeomInnerColor(geomInnerColor);
+
+- delete q;
+ return pdfAnnot;
+ }
+
+@@ -2489,7 +2472,7 @@ void GeomAnnotation::setGeomType(GeomAnnotation::GeomType type)
+ return;
+ }
+
+- AnnotGeometry *geomann = static_cast<AnnotGeometry *>(d->pdfAnnot);
++ AnnotGeometry *geomann = static_cast<AnnotGeometry *>(d->pdfAnnot.get());
+ if (type == GeomAnnotation::InscribedSquare) {
+ geomann->setType(Annot::typeSquare);
+ } else { // GeomAnnotation::InscribedCircle
+@@ -2505,7 +2488,7 @@ QColor GeomAnnotation::geomInnerColor() const
+ return d->geomInnerColor;
+ }
+
+- const AnnotGeometry *geomann = static_cast<const AnnotGeometry *>(d->pdfAnnot);
++ const AnnotGeometry *geomann = static_cast<const AnnotGeometry *>(d->pdfAnnot.get());
+ return convertAnnotColor(geomann->getInteriorColor());
+ }
+
+@@ -2518,7 +2501,7 @@ void GeomAnnotation::setGeomInnerColor(const QColor &color)
+ return;
+ }
+
+- AnnotGeometry *geomann = static_cast<AnnotGeometry *>(d->pdfAnnot);
++ AnnotGeometry *geomann = static_cast<AnnotGeometry *>(d->pdfAnnot.get());
+ geomann->setInteriorColor(convertQColor(color));
+ }
+
+@@ -2527,8 +2510,8 @@ class HighlightAnnotationPrivate : public AnnotationPrivate
+ {
+ public:
+ HighlightAnnotationPrivate();
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields
+ HighlightAnnotation::HighlightType highlightType;
+@@ -2542,9 +2525,9 @@ public:
+
+ HighlightAnnotationPrivate::HighlightAnnotationPrivate() : AnnotationPrivate(), highlightType(HighlightAnnotation::Highlight) { }
+
+-Annotation *HighlightAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> HighlightAnnotationPrivate::makeAlias()
+ {
+- return new HighlightAnnotation(*this);
++ return std::unique_ptr<Annotation>(new HighlightAnnotation(*this));
+ }
+
+ Annot::AnnotSubtype HighlightAnnotationPrivate::toAnnotSubType(HighlightAnnotation::HighlightType type)
+@@ -2617,10 +2600,10 @@ AnnotQuadrilaterals *HighlightAnnotationPrivate::toQuadrilaterals(const QList<Hi
+ return new AnnotQuadrilaterals(std::move(ac), count);
+ }
+
+-Annot *HighlightAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> HighlightAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ // Setters are defined in the public class
+- HighlightAnnotation *q = static_cast<HighlightAnnotation *>(makeAlias());
++ std::unique_ptr<HighlightAnnotation> q = static_pointer_cast<HighlightAnnotation *>(makeAlias());
+
+ // Set page and document
+ pdfPage = destPage;
+@@ -2628,7 +2611,7 @@ Annot *HighlightAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentD
+
+ // Set pdfAnnot
+ PDFRectangle rect = boundaryToPdfRectangle(boundary, flags);
+- pdfAnnot = new AnnotTextMarkup(destPage->getDoc(), &rect, toAnnotSubType(highlightType));
++ pdfAnnot = std::make_shared<AnnotTextMarkup>(destPage->getDoc(), &rect, toAnnotSubType(highlightType));
+
+ // Set properties
+ flushBaseAnnotationProperties();
+@@ -2636,8 +2619,6 @@ Annot *HighlightAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentD
+
+ highlightQuads.clear(); // Free up memory
+
+- delete q;
+-
+ return pdfAnnot;
+ }
+
+@@ -2682,7 +2663,7 @@ void HighlightAnnotation::setHighlightType(HighlightAnnotation::HighlightType ty
+ return;
+ }
+
+- AnnotTextMarkup *hlann = static_cast<AnnotTextMarkup *>(d->pdfAnnot);
++ AnnotTextMarkup *hlann = static_cast<AnnotTextMarkup *>(d->pdfAnnot.get());
+ hlann->setType(HighlightAnnotationPrivate::toAnnotSubType(type));
+ }
+
+@@ -2694,7 +2675,7 @@ QList<HighlightAnnotation::Quad> HighlightAnnotation::highlightQuads() const
+ return d->highlightQuads;
+ }
+
+- const AnnotTextMarkup *hlann = static_cast<AnnotTextMarkup *>(d->pdfAnnot);
++ const AnnotTextMarkup *hlann = static_cast<AnnotTextMarkup *>(d->pdfAnnot.get());
+ return d->fromQuadrilaterals(hlann->getQuadrilaterals());
+ }
+
+@@ -2707,7 +2688,7 @@ void HighlightAnnotation::setHighlightQuads(const QList<HighlightAnnotation::Qua
+ return;
+ }
+
+- AnnotTextMarkup *hlann = static_cast<AnnotTextMarkup *>(d->pdfAnnot);
++ AnnotTextMarkup *hlann = static_cast<AnnotTextMarkup *>(d->pdfAnnot.get());
+ AnnotQuadrilaterals *quadrilaterals = d->toQuadrilaterals(quads);
+ hlann->setQuadrilaterals(quadrilaterals);
+ delete quadrilaterals;
+@@ -2718,10 +2699,10 @@ class StampAnnotationPrivate : public AnnotationPrivate
+ {
+ public:
+ StampAnnotationPrivate();
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+- AnnotStampImageHelper *convertQImageToAnnotStampImageHelper(const QImage &qimg);
++ std::unique_ptr<AnnotStampImageHelper> convertQImageToAnnotStampImageHelper(const QImage &qimg);
+
+ // data fields
+ QString stampIconName;
+@@ -2730,14 +2711,14 @@ public:
+
+ StampAnnotationPrivate::StampAnnotationPrivate() : AnnotationPrivate(), stampIconName(QStringLiteral("Draft")) { }
+
+-Annotation *StampAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> StampAnnotationPrivate::makeAlias()
+ {
+- return new StampAnnotation(*this);
++ return std::unique_ptr<Annotation>(new StampAnnotation(*this));
+ }
+
+-Annot *StampAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> StampAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+- StampAnnotation *q = static_cast<StampAnnotation *>(makeAlias());
++ std::shared_ptr<StampAnnotation> q = static_pointer_cast<StampAnnotation *>(makeAlias());
+
+ // Set page and document
+ pdfPage = destPage;
+@@ -2745,21 +2726,19 @@ Annot *StampAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData
+
+ // Set pdfAnnot
+ PDFRectangle rect = boundaryToPdfRectangle(boundary, flags);
+- pdfAnnot = new AnnotStamp(destPage->getDoc(), &rect);
++ pdfAnnot = std::make_shared<AnnotStamp>(destPage->getDoc(), &rect);
+
+ // Set properties
+ flushBaseAnnotationProperties();
+ q->setStampIconName(stampIconName);
+ q->setStampCustomImage(stampCustomImage);
+
+- delete q;
+-
+ stampIconName.clear(); // Free up memory
+
+ return pdfAnnot;
+ }
+
+-AnnotStampImageHelper *StampAnnotationPrivate::convertQImageToAnnotStampImageHelper(const QImage &qimg)
++std::unique_ptr<AnnotStampImageHelper> *StampAnnotationPrivate::convertQImageToAnnotStampImageHelper(const QImage &qimg)
+ {
+ QImage convertedQImage = qimg;
+
+@@ -2838,13 +2817,13 @@ AnnotStampImageHelper *StampAnnotationPrivate::convertQImageToAnnotStampImageHel
+
+ getRawDataFromQImage(convertedQImage, convertedQImage.depth(), &data, &sMaskData);
+
+- AnnotStampImageHelper *annotImg;
++ std::unique_ptr<AnnotStampImageHelper> annotImg;
+
+ if (sMaskData.size() > 0) {
+ AnnotStampImageHelper sMask(parentDoc->doc, width, height, ColorSpace::DeviceGray, 8, sMaskData.data(), sMaskData.size());
+- annotImg = new AnnotStampImageHelper(parentDoc->doc, width, height, colorSpace, bitsPerComponent, data.data(), data.size(), sMask.getRef());
++ annotImg = std::make_unique<AnnotStampImageHelper>(parentDoc->doc, width, height, colorSpace, bitsPerComponent, data.data(), data.size(), sMask.getRef());
+ } else {
+- annotImg = new AnnotStampImageHelper(parentDoc->doc, width, height, colorSpace, bitsPerComponent, data.data(), data.size());
++ annotImg = std::make_unique<AnnotStampImageHelper>(parentDoc->doc, width, height, colorSpace, bitsPerComponent, data.data(), data.size());
+ }
+
+ return annotImg;
+@@ -2869,7 +2848,7 @@ QString StampAnnotation::stampIconName() const
+ return d->stampIconName;
+ }
+
+- const AnnotStamp *stampann = static_cast<const AnnotStamp *>(d->pdfAnnot);
++ const AnnotStamp *stampann = static_cast<const AnnotStamp *>(d->pdfAnnot.get());
+ return QString::fromLatin1(stampann->getIcon()->c_str());
+ }
+
+@@ -2882,7 +2861,7 @@ void StampAnnotation::setStampIconName(const QString &name)
+ return;
+ }
+
+- AnnotStamp *stampann = static_cast<AnnotStamp *>(d->pdfAnnot);
++ AnnotStamp *stampann = static_cast<AnnotStamp *>(d->pdfAnnot.get());
+ QByteArray encoded = name.toLatin1();
+ GooString s(encoded.constData());
+ stampann->setIcon(&s);
+@@ -2901,9 +2880,9 @@ void StampAnnotation::setStampCustomImage(const QImage &image)
+ return;
+ }
+
+- AnnotStamp *stampann = static_cast<AnnotStamp *>(d->pdfAnnot);
+- AnnotStampImageHelper *annotCustomImage = d->convertQImageToAnnotStampImageHelper(image);
+- stampann->setCustomImage(annotCustomImage);
++ AnnotStamp *stampann = static_cast<AnnotStamp *>(d->pdfAnnot.get());
++ std::unique_ptr<AnnotStampImageHelper> annotCustomImage = d->convertQImageToAnnotStampImageHelper(image);
++ stampann->setCustomImage(std::move(annotCustomImage));
+ }
+
+ /** InkAnnotation [Annotation] */
+@@ -2911,8 +2890,8 @@ class InkAnnotationPrivate : public AnnotationPrivate
+ {
+ public:
+ InkAnnotationPrivate();
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields
+ QList<QVector<QPointF>> inkPaths;
+@@ -2923,9 +2902,9 @@ public:
+
+ InkAnnotationPrivate::InkAnnotationPrivate() : AnnotationPrivate() { }
+
+-Annotation *InkAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> *InkAnnotationPrivate::makeAlias()
+ {
+- return new InkAnnotation(*this);
++ return std::unique_ptr<Annotation>(new InkAnnotation(*this));
+ }
+
+ // Note: Caller is required to delete array elements and the array itself after use
+@@ -2939,10 +2918,10 @@ AnnotPath **InkAnnotationPrivate::toAnnotPaths(const QList<QVector<QPointF>> &pa
+ return res;
+ }
+
+-Annot *InkAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> InkAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ // Setters are defined in the public class
+- InkAnnotation *q = static_cast<InkAnnotation *>(makeAlias());
++ std::unique_ptr<InkAnnotation> q = static_pointer_cast<InkAnnotation *>(makeAlias());
+
+ // Set page and document
+ pdfPage = destPage;
+@@ -2950,7 +2929,7 @@ Annot *InkAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *d
+
+ // Set pdfAnnot
+ PDFRectangle rect = boundaryToPdfRectangle(boundary, flags);
+- pdfAnnot = new AnnotInk(destPage->getDoc(), &rect);
++ pdfAnnot = std::make_shared<AnnotInk>(destPage->getDoc(), &rect);
+
+ // Set properties
+ flushBaseAnnotationProperties();
+@@ -2958,8 +2937,6 @@ Annot *InkAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *d
+
+ inkPaths.clear(); // Free up memory
+
+- delete q;
+-
+ return pdfAnnot;
+ }
+
+@@ -2982,7 +2959,7 @@ QList<QVector<QPointF>> InkAnnotation::inkPaths() const
+ return d->inkPaths;
+ }
+
+- const AnnotInk *inkann = static_cast<const AnnotInk *>(d->pdfAnnot);
++ const AnnotInk *inkann = static_cast<const AnnotInk *>(d->pdfAnnot.get());
+
+ const AnnotPath *const *paths = inkann->getInkList();
+ if (!paths || !inkann->getInkListLength()) {
+@@ -3020,7 +2997,7 @@ void InkAnnotation::setInkPaths(const QList<QVector<QPointF>> &paths)
+ return;
+ }
+
+- AnnotInk *inkann = static_cast<AnnotInk *>(d->pdfAnnot);
++ AnnotInk *inkann = static_cast<AnnotInk *>(d->pdfAnnot.get());
+ AnnotPath **annotpaths = d->toAnnotPaths(paths);
+ const int pathsNumber = paths.size();
+ inkann->setInkList(annotpaths, pathsNumber);
+@@ -3037,8 +3014,8 @@ class LinkAnnotationPrivate : public AnnotationPrivate
+ public:
+ LinkAnnotationPrivate();
+ ~LinkAnnotationPrivate() override;
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields
+ std::unique_ptr<Link> linkDestination;
+@@ -3050,12 +3027,12 @@ LinkAnnotationPrivate::LinkAnnotationPrivate() : AnnotationPrivate(), linkHLMode
+
+ LinkAnnotationPrivate::~LinkAnnotationPrivate() { }
+
+-Annotation *LinkAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> LinkAnnotationPrivate::makeAlias()
+ {
+- return new LinkAnnotation(*this);
++ return std::unique_ptr<Annotation>(new LinkAnnotation(*this));
+ }
+
+-Annot *LinkAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::unique_ptr<Annot> *LinkAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ return nullptr; // Not implemented
+ }
+@@ -3076,7 +3053,6 @@ Link *LinkAnnotation::linkDestination() const
+ Q_D(const LinkAnnotation);
+ return d->linkDestination.get();
+ }
+-
+ void LinkAnnotation::setLinkDestination(std::unique_ptr<Link> &&link)
+ {
+ Q_D(LinkAnnotation);
+@@ -3120,8 +3096,8 @@ class CaretAnnotationPrivate : public AnnotationPrivate
+ {
+ public:
+ CaretAnnotationPrivate();
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields
+ CaretAnnotation::CaretSymbol symbol;
+@@ -3129,15 +3105,15 @@ public:
+
+ CaretAnnotationPrivate::CaretAnnotationPrivate() : AnnotationPrivate(), symbol(CaretAnnotation::None) { }
+
+-Annotation *CaretAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> CaretAnnotationPrivate::makeAlias()
+ {
+- return new CaretAnnotation(*this);
++ return std::unique_ptr<Annotation>(new CaretAnnotation(*this));
+ }
+
+-Annot *CaretAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> CaretAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ // Setters are defined in the public class
+- CaretAnnotation *q = static_cast<CaretAnnotation *>(makeAlias());
++ std::unique_ptr<CaretAnnotation> q = static_pointer_cast<CaretAnnotation *>(makeAlias());
+
+ // Set page and document
+ pdfPage = destPage;
+@@ -3145,13 +3121,12 @@ Annot *CaretAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData
+
+ // Set pdfAnnot
+ PDFRectangle rect = boundaryToPdfRectangle(boundary, flags);
+- pdfAnnot = new AnnotCaret(destPage->getDoc(), &rect);
++ pdfAnnot = std::make_shared<AnnotCaret>(destPage->getDoc(), &rect);
+
+ // Set properties
+ flushBaseAnnotationProperties();
+ q->setCaretSymbol(symbol);
+
+- delete q;
+ return pdfAnnot;
+ }
+
+@@ -3174,7 +3149,7 @@ CaretAnnotation::CaretSymbol CaretAnnotation::caretSymbol() const
+ return d->symbol;
+ }
+
+- const AnnotCaret *caretann = static_cast<const AnnotCaret *>(d->pdfAnnot);
++ const AnnotCaret *caretann = static_cast<const AnnotCaret *>(d->pdfAnnot.get());
+ return (CaretAnnotation::CaretSymbol)caretann->getSymbol();
+ }
+
+@@ -3187,7 +3162,7 @@ void CaretAnnotation::setCaretSymbol(CaretAnnotation::CaretSymbol symbol)
+ return;
+ }
+
+- AnnotCaret *caretann = static_cast<AnnotCaret *>(d->pdfAnnot);
++ AnnotCaret *caretann = static_cast<AnnotCaret *>(d->pdfAnnot.get());
+ caretann->setSymbol((AnnotCaret::AnnotCaretSymbol)symbol);
+ }
+
+@@ -3197,8 +3172,8 @@ class FileAttachmentAnnotationPrivate : public AnnotationPrivate
+ public:
+ FileAttachmentAnnotationPrivate();
+ ~FileAttachmentAnnotationPrivate() override;
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields
+ QString icon;
+@@ -3212,12 +3187,12 @@ FileAttachmentAnnotationPrivate::~FileAttachmentAnnotationPrivate()
+ delete embfile;
+ }
+
+-Annotation *FileAttachmentAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> FileAttachmentAnnotationPrivate::makeAlias()
+ {
+- return new FileAttachmentAnnotation(*this);
++ return std::unique_ptr<Annotation>(new FileAttachmentAnnotation(*this));
+ }
+
+-Annot *FileAttachmentAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> *FileAttachmentAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ return nullptr; // Not implemented
+ }
+@@ -3263,8 +3238,8 @@ class SoundAnnotationPrivate : public AnnotationPrivate
+ public:
+ SoundAnnotationPrivate();
+ ~SoundAnnotationPrivate() override;
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields
+ QString icon;
+@@ -3278,12 +3253,12 @@ SoundAnnotationPrivate::~SoundAnnotationPrivate()
+ delete sound;
+ }
+
+-Annotation *SoundAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> SoundAnnotationPrivate::makeAlias()
+ {
+- return new SoundAnnotation(*this);
++ return std::unique_ptr<Annotation>(new SoundAnnotation(*this));
+ }
+
+-Annot *SoundAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> SoundAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ return nullptr; // Not implemented
+ }
+@@ -3329,8 +3304,8 @@ class MovieAnnotationPrivate : public AnnotationPrivate
+ public:
+ MovieAnnotationPrivate();
+ ~MovieAnnotationPrivate() override;
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields
+ MovieObject *movie;
+@@ -3344,12 +3319,12 @@ MovieAnnotationPrivate::~MovieAnnotationPrivate()
+ delete movie;
+ }
+
+-Annotation *MovieAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> MovieAnnotationPrivate::makeAlias()
+ {
+- return new MovieAnnotation(*this);
++ return std::unique_ptr<Annotation>(new MovieAnnotation(*this));
+ }
+
+-Annot *MovieAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> MovieAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ return nullptr; // Not implemented
+ }
+@@ -3395,8 +3370,8 @@ class ScreenAnnotationPrivate : public AnnotationPrivate
+ public:
+ ScreenAnnotationPrivate();
+ ~ScreenAnnotationPrivate() override;
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+
+ // data fields
+ LinkRendition *action;
+@@ -3412,12 +3387,12 @@ ScreenAnnotationPrivate::~ScreenAnnotationPrivate()
+
+ ScreenAnnotation::ScreenAnnotation(ScreenAnnotationPrivate &dd) : Annotation(dd) { }
+
+-Annotation *ScreenAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> ScreenAnnotationPrivate::makeAlias()
+ {
+- return new ScreenAnnotation(*this);
++ return std::unique_ptr<Annotation>(new ScreenAnnotation(*this));
+ }
+
+-Annot *ScreenAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> ScreenAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ return nullptr; // Not implemented
+ }
+@@ -3465,16 +3440,16 @@ std::unique_ptr<Link> ScreenAnnotation::additionalAction(AdditionalActionType ty
+ class WidgetAnnotationPrivate : public AnnotationPrivate
+ {
+ public:
+- Annotation *makeAlias() override;
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override;
++ std::unique_ptr<Annotation> makeAlias() override;
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override;
+ };
+
+-Annotation *WidgetAnnotationPrivate::makeAlias()
++std::unique_ptr<Annotation> WidgetAnnotationPrivate::makeAlias()
+ {
+- return new WidgetAnnotation(*this);
++ return std::unique_ptr<Annotation>(new WidgetAnnotation(*this));
+ }
+
+-Annot *WidgetAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
++std::shared_ptr<Annot> WidgetAnnotationPrivate::createNativeAnnot(::Page *destPage, DocumentData *doc)
+ {
+ return nullptr; // Not implemented
+ }
+@@ -3788,9 +3763,9 @@ public:
+
+ ~RichMediaAnnotationPrivate() override;
+
+- Annotation *makeAlias() override { return new RichMediaAnnotation(*this); }
++ std::unique_ptr<Annotation> makeAlias() override { return std::unique_ptr<Annotation>(new RichMediaAnnotation(*this)); }
+
+- Annot *createNativeAnnot(::Page *destPage, DocumentData *doc) override
++ std::shared_ptr<Annot> createNativeAnnot(::Page *destPage, DocumentData *doc) override
+ {
+ Q_UNUSED(destPage);
+ Q_UNUSED(doc);
+diff --git a/qt6/src/poppler-form.cc b/qt6/src/poppler-form.cc
+index b415c08..74ba075 100644
+--- a/qt6/src/poppler-form.cc
++++ b/qt6/src/poppler-form.cc
+@@ -269,7 +269,7 @@ std::unique_ptr<Link> FormField::additionalAction(AdditionalActionType type) con
+
+ std::unique_ptr<Link> FormField::additionalAction(Annotation::AdditionalActionType type) const
+ {
+- ::AnnotWidget *w = m_formData->fm->getWidgetAnnotation();
++ ::AnnotWidget *w = m_formData->fm->getWidgetAnnotation().get();
+ if (!w) {
+ return {};
+ }
+@@ -350,7 +350,7 @@ void FormFieldButton::setIcon(const FormFieldIcon &icon)
+
+ FormWidgetButton *fwb = static_cast<FormWidgetButton *>(m_formData->fm);
+ if (fwb->getButtonType() == formButtonPush) {
+- ::AnnotWidget *w = m_formData->fm->getWidgetAnnotation();
++ std::shared_ptr<::AnnotWidget> w = m_formData->fm->getWidgetAnnotation();
+ FormFieldIconData *data = FormFieldIconData::getData(icon);
+ if (data->icon != nullptr) {
+ w->setNewAppearance(data->icon->lookup("AP"));
+diff --git a/utils/HtmlOutputDev.cc b/utils/HtmlOutputDev.cc
+index b45a5ff..ec51a24 100644
+--- a/utils/HtmlOutputDev.cc
++++ b/utils/HtmlOutputDev.cc
+@@ -1252,8 +1252,8 @@ void HtmlOutputDev::startPage(int pageNumA, GfxState *state, XRef *xref)
+ void HtmlOutputDev::endPage()
+ {
+ std::unique_ptr<Links> linksList = docPage->getLinks();
+- for (AnnotLink *link : linksList->getLinks()) {
+- doProcessLink(link);
++ for (const std::shared_ptr<AnnotLink> &link : linksList->getLinks()) {
++ doProcessLink(link.get());
+ }
+
+ pages->conv();
+diff --git a/utils/pdfdetach.cc b/utils/pdfdetach.cc
+index 247c2c1..cbb4f30 100644
+--- a/utils/pdfdetach.cc
++++ b/utils/pdfdetach.cc
+@@ -150,11 +150,11 @@ int main(int argc, char *argv[])
+ break;
+ }
+
+- for (Annot *annot : annots->getAnnots()) {
++ for (const std::shared_ptr<Annot> &annot : annots->getAnnots()) {
+ if (annot->getType() != Annot::typeFileAttachment) {
+ continue;
+ }
+- embeddedFiles.push_back(std::make_unique<FileSpec>(static_cast<AnnotFileAttachment *>(annot)->getFile()));
++ embeddedFiles.push_back(std::make_unique<FileSpec>(static_cast<AnnotFileAttachment *>(annot.get())->getFile()));
+ }
+ }
+
+diff --git a/utils/pdfinfo.cc b/utils/pdfinfo.cc
+index 5f96b41..7b3896e 100644
+--- a/utils/pdfinfo.cc
++++ b/utils/pdfinfo.cc
+@@ -415,7 +415,7 @@ static void printUrlList(PDFDoc *doc)
+ Page *page = doc->getPage(pg);
+ if (page) {
+ std::unique_ptr<Links> links = page->getLinks();
+- for (AnnotLink *annot : links->getLinks()) {
++ for (const std::shared_ptr<AnnotLink> &annot : links->getLinks()) {
+ LinkAction *action = annot->getAction();
+ if (action->getKind() == actionURI) {
+ LinkURI *linkUri = dynamic_cast<LinkURI *>(action);
+--
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-52886-0002.patch b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-52886-0002.patch
new file mode 100644
index 0000000000..d8668699c1
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/poppler/poppler/CVE-2025-52886-0002.patch
@@ -0,0 +1,58 @@
+From ac36affcc8486de38e8905a8d6547a3464ff46e5 Mon Sep 17 00:00:00 2001
+From: Sune Vuorela <sune@vuorela.dk>
+Date: Tue, 3 Jun 2025 00:35:19 +0200
+Subject: [PATCH] Limit ammount of annots per document/page
+
+CVE: CVE-2025-52886
+Upstream-Status: Backport [https://gitlab.freedesktop.org/poppler/poppler/-/commit/ac36affcc8486de38e8905a8d6547a3464ff46e5
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ poppler/Annot.cc | 4 ++++
+ poppler/Page.cc | 16 ++++++++++++++++
+ 2 files changed, 20 insertions(+)
+
+diff --git a/poppler/Annot.cc b/poppler/Annot.cc
+index b98df5d..3e9dfac 100644
+--- a/poppler/Annot.cc
++++ b/poppler/Annot.cc
+@@ -7450,6 +7450,10 @@ Annots::Annots(PDFDoc *docA, int page, Object *annotsObj)
+ const Object &obj2 = annotsObj->arrayGetNF(i);
+ std::shared_ptr<Annot> annot = createAnnot(std::move(obj1), &obj2);
+ if (annot) {
++ if (annot.use_count() > 100000) {
++ error(errSyntaxError, -1, "Annotations likely malformed. Too many references. Stopping processing annots on page {0:d}", page);
++ break;
++ }
+ if (annot->isOk()) {
+ annot->setPage(page, false); // Don't change /P
+ appendAnnot(annot);
+diff --git a/poppler/Page.cc b/poppler/Page.cc
+index 234f124..858b128 100644
+--- a/poppler/Page.cc
++++ b/poppler/Page.cc
+@@ -288,6 +288,22 @@ Page::Page(PDFDoc *docA, int numA, Object &&pageDict, Ref pageRefA, PageAttrs *a
+ goto err2;
+ }
+
++ if (annotsObj.isArray() && annotsObj.arrayGetLength() > 10000) {
++ error(errSyntaxError, -1, "Page annotations object (page {0:d}) is likely malformed. Too big: ({1:d})", num, annotsObj.arrayGetLength());
++ goto err2;
++ }
++ if (annotsObj.isRef()) {
++ auto resolvedObj = getAnnotsObject();
++ if (resolvedObj.isArray() && resolvedObj.arrayGetLength() > 10000) {
++ error(errSyntaxError, -1, "Page annotations object (page {0:d}) is likely malformed. Too big: ({1:d})", num, resolvedObj.arrayGetLength());
++ goto err2;
++ }
++ if (!resolvedObj.isArray() && !resolvedObj.isNull()) {
++ error(errSyntaxError, -1, "Page annotations object (page {0:d}) is wrong type ({1:s})", num, resolvedObj.getTypeName());
++ goto err2;
++ }
++ }
++
+ // contents
+ contents = pageObj.dictLookupNF("Contents").copy();
+ if (!(contents.isRef() || contents.isArray() || contents.isNull())) {
+--
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-support/poppler/poppler_23.04.0.bb b/meta-openembedded/meta-oe/recipes-support/poppler/poppler_23.04.0.bb
index f4411e1163..b56a4cf6b1 100644
--- a/meta-openembedded/meta-oe/recipes-support/poppler/poppler_23.04.0.bb
+++ b/meta-openembedded/meta-oe/recipes-support/poppler/poppler_23.04.0.bb
@@ -9,6 +9,18 @@ SRC_URI = "http://poppler.freedesktop.org/${BP}.tar.xz \
file://0001-cmake-Do-not-use-isystem.patch \
file://jpeg-stdio.patch \
file://CVE-2023-34872.patch \
+ file://CVE-2024-6239-0001.patch \
+ file://CVE-2024-6239-0002.patch \
+ file://CVE-2024-56378.patch \
+ file://CVE-2025-32364.patch \
+ file://CVE-2025-32365.patch \
+ file://CVE-2025-43903-0001.patch \
+ file://CVE-2025-43903-0002.patch \
+ file://CVE-2025-52886-0001.patch \
+ file://CVE-2025-52886-0002.patch \
+ file://CVE-2025-50420.patch \
+ file://CVE-2025-43718.patch \
+ file://CVE-2025-52885.patch \
"
SRC_URI[sha256sum] = "b6d893dc7dcd4138b9e9df59a13c59695e50e80dc5c2cacee0674670693951a1"
diff --git a/meta-openembedded/meta-oe/recipes-support/procmail/procmail/CVE-2014-3618.patch b/meta-openembedded/meta-oe/recipes-support/procmail/procmail/CVE-2014-3618.patch
new file mode 100644
index 0000000000..b041924361
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/procmail/procmail/CVE-2014-3618.patch
@@ -0,0 +1,29 @@
+Description: Fix heap-overflow in formail
+ CVE-2014-3618: Heap-overflow in formail when processing
+ specially-crafted email headers.
+Origin: http://www.openwall.com/lists/oss-security/2014/09/03/8
+Bug-Debian: https://bugs.debian.org/704675
+Bug-Debian: https://bugs.debian.org/760443
+Forwarded: not-needed
+Last-Update: 2014-09-04
+
+CVE: CVE-2014-3618
+Upstream-Status: Inactive-Upstream [lastrelease: 2001]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+
+--- a/src/formisc.c
++++ b/src/formisc.c
+@@ -84,12 +84,11 @@ normal: *target++= *start++;
+ case '"':*target++=delim='"';start++;
+ }
+ ;{ int i;
+- do
++ while(*start)
+ if((i= *target++= *start++)==delim) /* corresponding delimiter? */
+ break;
+ else if(i=='\\'&&*start) /* skip quoted character */
+ *target++= *start++;
+- while(*start); /* anything? */
+ }
+ hitspc=2;
+ }
diff --git a/meta-openembedded/meta-oe/recipes-support/procmail/procmail/CVE-2017-16844.patch b/meta-openembedded/meta-oe/recipes-support/procmail/procmail/CVE-2017-16844.patch
new file mode 100644
index 0000000000..6e04989c33
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/procmail/procmail/CVE-2017-16844.patch
@@ -0,0 +1,20 @@
+From: Santiago Vila <sanvila@debian.org>
+Subject: Fix heap-based buffer overflow in loadbuf()
+Bug-Debian: http://bugs.debian.org/876511
+X-Debian-version: 3.22-26
+
+CVE: CVE-2017-16844
+Upstream-Status: Inactive-Upstream [lastrelease: 2001]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+
+--- a/src/formisc.c
++++ b/src/formisc.c
+@@ -103,7 +103,7 @@
+ }
+ /* append to buf */
+ void loadbuf(text,len)const char*const text;const size_t len;
+-{ if(buffilled+len>buflen) /* buf can't hold the text */
++{ while(buffilled+len>buflen) /* buf can't hold the text */
+ buf=realloc(buf,buflen+=Bsize);
+ tmemmove(buf+buffilled,text,len);buffilled+=len;
+ }
diff --git a/meta-openembedded/meta-oe/recipes-support/procmail/procmail/gcc14.patch b/meta-openembedded/meta-oe/recipes-support/procmail/procmail/gcc14.patch
new file mode 100644
index 0000000000..5ca56fa006
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/procmail/procmail/gcc14.patch
@@ -0,0 +1,127 @@
+From: Santiago Vila <sanvila@debian.org>
+Subject: Fix build with gcc-14
+Bug-Debian: https://bugs.debian.org/1075398
+
+Upstream-Status: Pending
+Signed-off-by: Khem Raj <raj.khem@gmail.com>
+--- a/initmake
++++ b/initmake
+@@ -124,7 +124,7 @@ else
+ fi
+
+ cat >_autotst.c <<HERE
+-main()
++int main()
+ { return 0;
+ }
+ HERE
+@@ -200,7 +200,7 @@ cat >_autotst.c <<HERE
+ #include <sys/types.h>
+ #include <stdio.h>
+ #include <sys/stat.h>
+-main()
++int main()
+ { struct stat buf;return!&buf;
+ }
+ HERE
+--- a/src/autoconf
++++ b/src/autoconf
+@@ -414,6 +414,12 @@ cat >_autotst.c <<HERE
+ int dolock,child[NR_of_forks],timeout,fdcollect;
+ char dirlocktest[]="_locktest";
+
++#include <stdlib.h>
++int killchildren();
++int fdlock(int fd);
++int sfdlock(int fd);
++int fdunlock();
++
+ void stimeout()
+ { timeout=1;close(fdcollect);killchildren();
+ }
+@@ -435,7 +441,7 @@ unsigned sfork()
+ return pid;
+ }
+
+-int main(argc,argv)char*argv[];
++int main(int argc,char*argv[])
+ { int goodlock,testlock,i,pip[2],pipw[2];time_t otimet;unsigned dtimet;
+ static char filename[]="_locktst.l0";
+ close(0);goodlock=0;testlock=FIRST_lock;signal(SIGPIPE,SIG_DFL);
+@@ -585,13 +591,13 @@ int killchildren()
+ return 0;
+ }
+
+-int sfdlock(fd)
++int sfdlock(int fd)
+ { int i;unsigned gobble[GOBBLE>>2];
+ for(i=GOBBLE>>2;i;gobble[--i]=~(unsigned)0); /* SunOS crash test */
+ return fdlock(fd);
+ }
+
+-static oldfdlock;
++static int oldfdlock;
+ #ifdef F_SETLKW
+ static struct flock flck; /* why can't it be a local variable? */
+ #endif
+@@ -599,7 +605,7 @@ static struct flock flck; /* why can't
+ static off_t oldlockoffset;
+ #endif
+
+-int fdlock(fd)
++int fdlock(int fd)
+ { int i;unsigned gobble[GOBBLE>>2];
+ for(i=GOBBLE>>2;i;gobble[--i]=~(unsigned)0); /* SunOS crash test */
+ oldfdlock=fd;fd=0;
+@@ -993,11 +999,11 @@ int main(){int i;i=1;
+ i+=WIFEXITED(i);
+ i+=WIFSTOPPED(i);
+ i+=WEXITSTATUS(i);
+- i+=WSIGTERM(i);
++ i+=WTERMSIG(i);
+ return i;}
+ HERE
+
+-echo 'Testing for WIFEXITED(), WIFSTOPPED(), WEXITSTATUS() & WSIGTERM()'
++echo 'Testing for WIFEXITED(), WIFSTOPPED(), WEXITSTATUS() & WTERMSIG()'
+ if $MAKE _autotst.$O >_autotst.rrr 2>&1
+ then
+ $FGREP -v include/ <_autotst.rrr >_autotst.$O
+@@ -1029,6 +1035,8 @@ cat >_autotst.c <<HERE
+ #ifndef NO_COMSAT
+ #include "network.h"
+ #endif
++int setrgid();
++int setresgid();
+ int main(){char a[2];
+ endpwent();endgrent();memmove(a,"0",1);bcopy("0",a,1);strcspn(a,"0");
+ strtol("0",(char**)0,10);strchr("0",'0');strpbrk(a,"0");rename(a,"0");
+@@ -1059,7 +1067,7 @@ echo 'Testing for memmove, strchr, strpb
+ echo ' rename, setrgid, setegid, pow, opendir, mkdir, waitpid, fsync,'
+ echo ' ftruncate, strtod, strncasecmp, strerror, strlcat,'
+ echo ' memset, bzero, and _exit'
+-if $MAKE _autotst.$O >$DEVNULL 2>&1
++if $MAKE _autotst.$O >_autotst.rrr 2>&1
+ then
+ :
+ else
+@@ -1196,7 +1204,7 @@ unsigned long dobench(strstr,iter,haysta
+ return (unsigned long)clock()-to;
+ }
+ #endif
+-int main(argc,argv)int argc;const char*argv[];
++int main(int argc,const char*argv[])
+ { if(argc==1)
+ { char*haystack;
+ #ifdef BENCHSIZE
+--- a/src/mailfold.c
++++ b/src/mailfold.c
+@@ -378,7 +378,7 @@ void concon(ch)const int ch; /* flip b
+ }
+ }
+
+-void readmail(rhead,tobesent)const long tobesent;
++void readmail(int rhead,const long tobesent)
+ { char*chp,*pastend;static size_t contlengthoffset;
+ ;{ long dfilled;
+ if(rhead==2) /* already read, just examine what we have */
diff --git a/meta-openembedded/meta-oe/recipes-support/procmail/procmail_3.22.bb b/meta-openembedded/meta-oe/recipes-support/procmail/procmail_3.22.bb
index 16917666a4..5da6ce2603 100644
--- a/meta-openembedded/meta-oe/recipes-support/procmail/procmail_3.22.bb
+++ b/meta-openembedded/meta-oe/recipes-support/procmail/procmail_3.22.bb
@@ -12,7 +12,11 @@ SRC_URI = "http://www.ring.gr.jp/archives/net/mail/${BPN}/${BP}.tar.gz \
file://from-debian-to-fix-compile-errors.patch \
file://from-debian-to-modify-parameters.patch \
file://from-debian-to-fix-man-file.patch \
- file://man-file-mailstat.1-from-debian.patch"
+ file://man-file-mailstat.1-from-debian.patch \
+ file://CVE-2014-3618.patch \
+ file://CVE-2017-16844.patch \
+ file://gcc14.patch \
+"
SRC_URI[md5sum] = "1678ea99b973eb77eda4ecf6acae53f1"
SRC_URI[sha256sum] = "087c75b34dd33d8b9df5afe9e42801c9395f4bf373a784d9bc97153b0062e117"
@@ -22,6 +26,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=a71e50e197a992c862379e576e669757 \
DEPENDS = "libnet"
inherit autotools-brokensep
+
do_configure() {
find examples -type f | xargs chmod 644
export CC="${BUILD_CC}"
@@ -33,7 +38,7 @@ do_configure() {
}
do_compile() {
- oe_runmake -i TARGET_CFLAGS="$TARGET_CFLAGS -Wno-comments -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64" LDFLAGS0="${LDFLAGS}"
+ oe_runmake -i CFLAGS="$TARGET_CFLAGS -Wno-comments -Wno-implicit-int -Wno-implicit-function-declaration -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64" LDFLAGS0="${LDFLAGS}"
}
do_install() {
diff --git a/meta-openembedded/meta-oe/recipes-support/sharutils/sharutils/0001-libopts.m4-accept-POSIX_SHELL-from-the-environment-d.patch b/meta-openembedded/meta-oe/recipes-support/sharutils/sharutils/0001-libopts.m4-accept-POSIX_SHELL-from-the-environment-d.patch
new file mode 100644
index 0000000000..6d8a5e2128
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/sharutils/sharutils/0001-libopts.m4-accept-POSIX_SHELL-from-the-environment-d.patch
@@ -0,0 +1,47 @@
+From fb8bf1c1b1d0bf8e9bc637c0e67219fab1a9eb03 Mon Sep 17 00:00:00 2001
+From: Khem Raj <raj.khem@gmail.com>
+Date: Wed, 14 Aug 2024 15:24:57 -0700
+Subject: [PATCH] libopts.m4: accept POSIX_SHELL from the environment during
+ the configure step
+
+This lets us set it to the canonical path /bin/bash, even on systems
+where both /bin/bash and /usr/bin/bash are available, and therefore
+which(1) might return /usr/bin/bash (depending on PATH order).
+
+Both copies of libopts.m4 are marked as generated files, but the files
+from which they were generated do not seem to be present in the sharutils
+package. This change is equivalent to part of a 2016 autogen commit
+<https://git.savannah.gnu.org/cgit/autogen.git/commit/?id=db064b9a>.
+
+Upstream-Status: Backport [https://git.savannah.gnu.org/cgit/autogen.git/commit/?id=db064b9a]
+
+Signed-off-by: Khem Raj <raj.khem@gmail.com>
+---
+ libopts/m4/libopts.m4 | 1 +
+ m4/libopts.m4 | 1 +
+ 2 files changed, 2 insertions(+)
+
+diff --git a/libopts/m4/libopts.m4 b/libopts/m4/libopts.m4
+index 1a896d9..3b88426 100644
+--- a/libopts/m4/libopts.m4
++++ b/libopts/m4/libopts.m4
+@@ -114,6 +114,7 @@ AC_DEFUN([INVOKE_LIBOPTS_MACROS_FIRST],[
+ AC_PROG_SED
+ [while :
+ do
++ test -x "$POSIX_SHELL" && break
+ POSIX_SHELL=`which bash`
+ test -x "$POSIX_SHELL" && break
+ POSIX_SHELL=`which dash`
+diff --git a/m4/libopts.m4 b/m4/libopts.m4
+index c7ba4f3..a1127e1 100644
+--- a/m4/libopts.m4
++++ b/m4/libopts.m4
+@@ -114,6 +114,7 @@ AC_DEFUN([INVOKE_LIBOPTS_MACROS_FIRST],[
+ AC_PROG_SED
+ [while :
+ do
++ test -x "$POSIX_SHELL" && break
+ POSIX_SHELL=`which bash`
+ test -x "$POSIX_SHELL" && break
+ POSIX_SHELL=`which dash`
diff --git a/meta-openembedded/meta-oe/recipes-support/sharutils/sharutils_4.15.2.bb b/meta-openembedded/meta-oe/recipes-support/sharutils/sharutils_4.15.2.bb
index 2a16b18288..7a506d034d 100644
--- a/meta-openembedded/meta-oe/recipes-support/sharutils/sharutils_4.15.2.bb
+++ b/meta-openembedded/meta-oe/recipes-support/sharutils/sharutils_4.15.2.bb
@@ -13,10 +13,13 @@ SRC_URI = "${GNU_MIRROR}/${BPN}/${BP}.tar.gz \
file://0001-Fix-building-with-GCC-10.patch \
file://0002-Do-not-include-lib-md5.c-into-src-shar.c.patch \
file://0001-configure.ac-Check-and-define-intmax_t-type.patch \
+ file://0001-libopts.m4-accept-POSIX_SHELL-from-the-environment-d.patch \
"
SRC_URI[md5sum] = "32a51b23e25ad5e6af4b89f228be1800"
SRC_URI[sha256sum] = "ee336e68549664e7a19b117adf02edfdeac6307f22e5ba78baca457116914637"
+EXTRA_OECONF = "POSIX_SHELL=${base_bindir}/sh"
+
do_install:append() {
if [ -e ${D}${libdir}/charset.alias ]
then
diff --git a/meta-openembedded/meta-oe/recipes-support/spdlog/spdlog/CVE-2025-6140.patch b/meta-openembedded/meta-oe/recipes-support/spdlog/spdlog/CVE-2025-6140.patch
new file mode 100644
index 0000000000..3707d9e9c4
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/spdlog/spdlog/CVE-2025-6140.patch
@@ -0,0 +1,35 @@
+From 10320184df1eb4638e253a34b1eb44ce78954094 Mon Sep 17 00:00:00 2001
+From: Gabi Melman <gmelman1@gmail.com>
+Date: Mon, 17 Mar 2025 15:46:31 +0200
+Subject: [PATCH] Fixed issue #3360 (#3361)
+
+CVE: CVE-2025-6140
+Upstream-Status: Backport [https://github.com/gabime/spdlog/commit/10320184df1eb4638e253a34b1eb44ce78954094]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ include/spdlog/pattern_formatter-inl.h | 5 ++++-
+ 1 file changed, 4 insertions(+), 1 deletion(-)
+
+diff --git a/include/spdlog/pattern_formatter-inl.h b/include/spdlog/pattern_formatter-inl.h
+index b53d8051..fd408ed5 100644
+--- a/include/spdlog/pattern_formatter-inl.h
++++ b/include/spdlog/pattern_formatter-inl.h
+@@ -65,6 +65,9 @@ public:
+ pad_it(remaining_pad_);
+ } else if (padinfo_.truncate_) {
+ long new_size = static_cast<long>(dest_.size()) + remaining_pad_;
++ if (new_size < 0) {
++ new_size = 0;
++ }
+ dest_.resize(static_cast<size_t>(new_size));
+ }
+ }
+@@ -259,7 +262,7 @@ public:
+ : flag_formatter(padinfo) {}
+
+ void format(const details::log_msg &, const std::tm &tm_time, memory_buf_t &dest) override {
+- const size_t field_size = 10;
++ const size_t field_size = 8;
+ ScopedPadder p(field_size, padinfo_, dest);
+
+ fmt_helper::pad2(tm_time.tm_mon + 1, dest);
diff --git a/meta-openembedded/meta-oe/recipes-support/spdlog/spdlog_1.13.0.bb b/meta-openembedded/meta-oe/recipes-support/spdlog/spdlog_1.13.0.bb
index c6a0881db9..5761766ca8 100644
--- a/meta-openembedded/meta-oe/recipes-support/spdlog/spdlog_1.13.0.bb
+++ b/meta-openembedded/meta-oe/recipes-support/spdlog/spdlog_1.13.0.bb
@@ -4,7 +4,9 @@ LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=9573510928429ad0cbe5ba4de77546e9"
SRCREV = "7c02e204c92545f869e2f04edaab1f19fe8b19fd"
-SRC_URI = "git://github.com/gabime/spdlog.git;protocol=https;branch=v1.x"
+SRC_URI = "git://github.com/gabime/spdlog.git;protocol=https;branch=v1.x \
+ file://CVE-2025-6140.patch \
+"
DEPENDS = "fmt"
diff --git a/meta-openembedded/meta-oe/recipes-support/srecord/files/0001-fix-build-failure-with-gcc-15-by-adding-cstdint-head.patch b/meta-openembedded/meta-oe/recipes-support/srecord/files/0001-fix-build-failure-with-gcc-15-by-adding-cstdint-head.patch
new file mode 100644
index 0000000000..fe55fc5c87
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/srecord/files/0001-fix-build-failure-with-gcc-15-by-adding-cstdint-head.patch
@@ -0,0 +1,36 @@
+From 69290e4d727492a63a2a4424368a476b86ef8183 Mon Sep 17 00:00:00 2001
+From: "mark.yang" <mark.yang@lge.com>
+Date: Mon, 7 Apr 2025 17:18:34 +0900
+Subject: [PATCH] fix build failure with gcc 15 by adding cstdint header
+
+Fixes #79
+
+srecord/input/file/hp64k.h:82:21: error: ‘uint16_t’ has not been declared
+ 82 | bool read_u16be(uint16_t *dest);
+ | ^~~~~~~~
+/home/abuild/rpmbuild/BUILD/srecord-1.65.0-build/srecord-1.65.0-Source/./srecord/input/file/hp64k.h:1:1: note: ‘uint16_t’ is defined in header ‘<cstdint>’; this is probably fixable by adding ‘#include <cstdint>’
+ +++ |+#include <cstdint>
+ 1 | //
+make[2]: *** [srecord/CMakeFiles/lib_srecord.dir/build.make:222: srecord/CMakeFiles/lib_srecord.dir/arglex/tool/input.cc.o] Error 1
+
+ * From gcc 13, cstdint header must be explicitly included for uint_X data types.
+ * See also: https://gcc.gnu.org/gcc-13/porting_to.html#header-dep-changes
+
+Upstream-Status: Submitted [https://github.com/sierrafoxtrot/srecord/pull/80]
+Signed-off-by: mark.yang <mark.yang@lge.com>
+---
+ srecord/input/file/hp64k.h | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/srecord/input/file/hp64k.h b/srecord/input/file/hp64k.h
+index a3f8a6d..205e1e4 100644
+--- a/srecord/input/file/hp64k.h
++++ b/srecord/input/file/hp64k.h
+@@ -21,6 +21,7 @@
+ #define LIB_INPUT_FILE_HP64K
+
+ #include <srecord/input/file.h>
++#include <cstdint>
+
+ namespace srecord {
+
diff --git a/meta-openembedded/meta-oe/recipes-support/srecord/srecord_1.65.0.bb b/meta-openembedded/meta-oe/recipes-support/srecord/srecord_1.65.0.bb
index 3e8a87d07f..b4294975bd 100644
--- a/meta-openembedded/meta-oe/recipes-support/srecord/srecord_1.65.0.bb
+++ b/meta-openembedded/meta-oe/recipes-support/srecord/srecord_1.65.0.bb
@@ -7,7 +7,9 @@ SRC_URI = " \
https://sourceforge.net/projects/${BPN}/files/srecord/${@oe.utils.trim_version('${PV}', 2)}/${BP}-Source.tar.gz \
file://0001-Disable-doxygen.patch \
file://0001-cmake-Do-not-try-to-compute-library-dependencies-dur.patch \
- file://0001-cmake-respect-explicit-install-prefix.patch"
+ file://0001-cmake-respect-explicit-install-prefix.patch \
+ file://0001-fix-build-failure-with-gcc-15-by-adding-cstdint-head.patch \
+"
SRC_URI[sha256sum] = "81c3d07cf15ce50441f43a82cefd0ac32767c535b5291bcc41bd2311d1337644"
S = "${WORKDIR}/${BP}-Source"
diff --git a/meta-openembedded/meta-oe/recipes-support/syslog-ng/files/CVE-2024-47619.patch b/meta-openembedded/meta-oe/recipes-support/syslog-ng/files/CVE-2024-47619.patch
new file mode 100644
index 0000000000..725f471b3b
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/syslog-ng/files/CVE-2024-47619.patch
@@ -0,0 +1,292 @@
+From 12a0624e4c275f14cee9a6b4f36e714d2ced8544 Mon Sep 17 00:00:00 2001
+From: therandomstring <bal.horv.98@gmail.com>
+Date: Wed, 07 May 2025 09:30:36 +0530
+Subject: [PATCH] Merge commit from fork
+
+Fix transport accepting incorrect wildcards
+
+CVE: CVE-2024-47619
+Upstream-Status: Backport [https://github.com/syslog-ng/syslog-ng/commit/12a0624e4c275f14cee9a6b4f36e714d2ced8544]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ lib/transport/tests/CMakeLists.txt | 1 +
+ lib/transport/tests/Makefile.am | 9 +-
+ lib/transport/tests/test_tls_wildcard_match.c | 104 ++++++++++++++++++
+ lib/transport/tls-verifier.c | 86 +++++++++++++--
+ lib/transport/tls-verifier.h | 2 +
+ 5 files changed, 190 insertions(+), 12 deletions(-)
+ create mode 100644 lib/transport/tests/test_tls_wildcard_match.c
+
+diff --git a/lib/transport/tests/CMakeLists.txt b/lib/transport/tests/CMakeLists.txt
+index 834f456..ce1d033 100644
+--- a/lib/transport/tests/CMakeLists.txt
++++ b/lib/transport/tests/CMakeLists.txt
+@@ -3,3 +3,4 @@ add_unit_test(CRITERION TARGET test_transport_factory_id)
+ add_unit_test(CRITERION TARGET test_transport_factory)
+ add_unit_test(CRITERION TARGET test_transport_factory_registry)
+ add_unit_test(CRITERION TARGET test_multitransport)
++add_unit_test(CRITERION TARGET test_tls_wildcard_match)
+diff --git a/lib/transport/tests/Makefile.am b/lib/transport/tests/Makefile.am
+index 7eac994..ae2426c 100644
+--- a/lib/transport/tests/Makefile.am
++++ b/lib/transport/tests/Makefile.am
+@@ -3,7 +3,8 @@ lib_transport_tests_TESTS = \
+ lib/transport/tests/test_transport_factory_id \
+ lib/transport/tests/test_transport_factory \
+ lib/transport/tests/test_transport_factory_registry \
+- lib/transport/tests/test_multitransport
++ lib/transport/tests/test_multitransport \
++ lib/transport/tests/test_tls_wildcard_match
+
+ EXTRA_DIST += lib/transport/tests/CMakeLists.txt
+
+@@ -38,3 +39,9 @@ lib_transport_tests_test_multitransport_CFLAGS = $(TEST_CFLAGS) \
+ lib_transport_tests_test_multitransport_LDADD = $(TEST_LDADD)
+ lib_transport_tests_test_multitransport_SOURCES = \
+ lib/transport/tests/test_multitransport.c
++
++lib_transport_tests_test_tls_wildcard_match_CFLAGS = $(TEST_CFLAGS) \
++ -I${top_srcdir}/lib/transport/tests
++lib_transport_tests_test_tls_wildcard_match_LDADD = $(TEST_LDADD)
++lib_transport_tests_test_tls_wildcard_match_SOURCES = \
++ lib/transport/tests/test_tls_wildcard_match.c
+diff --git a/lib/transport/tests/test_tls_wildcard_match.c b/lib/transport/tests/test_tls_wildcard_match.c
+new file mode 100644
+index 0000000..90cecb0
+--- /dev/null
++++ b/lib/transport/tests/test_tls_wildcard_match.c
+@@ -0,0 +1,104 @@
++/*
++ * Copyright (c) 2024 One Identity LLC.
++ * Copyright (c) 2024 Franco Fichtner
++ *
++ * This library is free software; you can redistribute it and/or
++ * modify it under the terms of the GNU Lesser General Public
++ * License as published by the Free Software Foundation; either
++ * version 2.1 of the License, or (at your option) any later version.
++ *
++ * This library is distributed in the hope that it will be useful,
++ * but WITHOUT ANY WARRANTY; without even the implied warranty of
++ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
++ * Lesser General Public License for more details.
++ *
++ * You should have received a copy of the GNU Lesser General Public
++ * License along with this library; if not, write to the Free Software
++ * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
++ *
++ * As an additional exemption you are allowed to compile & link against the
++ * OpenSSL libraries as published by the OpenSSL project. See the file
++ * COPYING for details.
++ *
++ */
++
++
++#include <criterion/criterion.h>
++
++#include "transport/tls-verifier.h"
++
++TestSuite(tls_wildcard, .init = NULL, .fini = NULL);
++
++Test(tls_wildcard, test_wildcard_match_pattern_acceptance)
++{
++ cr_assert_eq(tls_wildcard_match("test", "test"), TRUE);
++ cr_assert_eq(tls_wildcard_match("test", "*"), TRUE);
++ cr_assert_eq(tls_wildcard_match("test", "t*t"), TRUE);
++ cr_assert_eq(tls_wildcard_match("test", "t*"), TRUE);
++ cr_assert_eq(tls_wildcard_match("", ""), TRUE);
++ cr_assert_eq(tls_wildcard_match("test.one", "test.one"), TRUE);
++ cr_assert_eq(tls_wildcard_match("test.one.two", "test.one.two"), TRUE);
++ cr_assert_eq(tls_wildcard_match("192.0.2.0", "192.0.2.0"), TRUE);
++ cr_assert_eq(tls_wildcard_match("2001:0000:130F:0000:0000:09C0:876A:130B", "2001:0000:130F:0000:0000:09C0:876A:130B"),
++ TRUE);
++ cr_assert_eq(tls_wildcard_match("2001:0000:130F:0000:0000:09C0:876A:130B", "2001:0:130F:0:0:9C0:876A:130B"), TRUE);
++ cr_assert_eq(tls_wildcard_match("2001:0:130F:0:0:9C0:876A:130B", "2001:0000:130F:0000:0000:09C0:876A:130B"), TRUE);
++ cr_assert_eq(tls_wildcard_match("2001:0000:130F::09C0:876A:130B", "2001:0000:130F:0000:0000:09C0:876A:130B"), TRUE);
++ cr_assert_eq(tls_wildcard_match("2001:0000:130F:0000:0000:09C0:876A:130B", "2001:0000:130F::09C0:876A:130B"), TRUE);
++ cr_assert_eq(tls_wildcard_match("2001:0000:130F:0000:0000:09C0:876A:130B", "2001:0:130F::9C0:876A:130B"), TRUE);
++ cr_assert_eq(tls_wildcard_match("2001:0:130F::9C0:876A:130B", "2001:0000:130F:0000:0000:09C0:876A:130B"), TRUE);
++}
++
++Test(tls_wildcard, test_wildcard_match_wildcard_rejection)
++{
++ cr_assert_eq(tls_wildcard_match("test", "**"), FALSE);
++ cr_assert_eq(tls_wildcard_match("test", "*es*"), FALSE);
++ cr_assert_eq(tls_wildcard_match("test", "t*?"), FALSE);
++}
++
++Test(tls_wildcard, test_wildcard_match_pattern_rejection)
++{
++ cr_assert_eq(tls_wildcard_match("test", "tset"), FALSE);
++ cr_assert_eq(tls_wildcard_match("test", "set"), FALSE);
++ cr_assert_eq(tls_wildcard_match("", "*"), FALSE);
++ cr_assert_eq(tls_wildcard_match("test", ""), FALSE);
++ cr_assert_eq(tls_wildcard_match("test.two", "test.one"), FALSE);
++}
++
++Test(tls_wildcard, test_wildcard_match_format_rejection)
++{
++ cr_assert_eq(tls_wildcard_match("test.two", "test.*"), FALSE);
++ cr_assert_eq(tls_wildcard_match("test.two", "test.t*o"), FALSE);
++ cr_assert_eq(tls_wildcard_match("test", "test.two"), FALSE);
++ cr_assert_eq(tls_wildcard_match("test.two", "test"), FALSE);
++ cr_assert_eq(tls_wildcard_match("test.one.two", "test.one"), FALSE);
++ cr_assert_eq(tls_wildcard_match("test.one", "test.one.two"), FALSE);
++ cr_assert_eq(tls_wildcard_match("test.three", "three.test"), FALSE);
++ cr_assert_eq(tls_wildcard_match("test.one.two", "test.one.*"), FALSE);
++}
++
++Test(tls_wildcard, test_wildcard_match_complex_rejection)
++{
++ cr_assert_eq(tls_wildcard_match("test.two", "test.???"), FALSE);
++ cr_assert_eq(tls_wildcard_match("test.one.two", "test.one.?wo"), FALSE);
++}
++
++Test(tls_wildcard, test_ip_wildcard_rejection)
++{
++ cr_assert_eq(tls_wildcard_match("192.0.2.0", "*.0.2.0"), FALSE);
++ cr_assert_eq(tls_wildcard_match("2001:0000:130F:0000:0000:09C0:876A:130B", "*:0000:130F:0000:0000:09C0:876A:130B"),
++ FALSE);
++ cr_assert_eq(tls_wildcard_match("2001:0:130F::9C0:876A:130B", "*:0000:130F:0000:0000:09C0:876A:130B"), FALSE);
++}
++
++Test(tls_wildcard, test_case_insensivity)
++{
++ cr_assert_eq(tls_wildcard_match("test", "TEST"), TRUE);
++ cr_assert_eq(tls_wildcard_match("TEST", "test"), TRUE);
++ cr_assert_eq(tls_wildcard_match("TeST", "TEst"), TRUE);
++ cr_assert_eq(tls_wildcard_match("test.one", "test.ONE"), TRUE);
++ cr_assert_eq(tls_wildcard_match("test.TWO", "test.two"), TRUE);
++ cr_assert_eq(tls_wildcard_match("test.three", "*T.three"), TRUE);
++ cr_assert_eq(tls_wildcard_match("2001:0000:130F:0000:0000:09C0:876A:130B", "2001:0000:130f:0000:0000:09c0:876a:130b"),
++ TRUE);
++}
+diff --git a/lib/transport/tls-verifier.c b/lib/transport/tls-verifier.c
+index 606ad02..dde00d9 100644
+--- a/lib/transport/tls-verifier.c
++++ b/lib/transport/tls-verifier.c
+@@ -1,4 +1,6 @@
+ /*
++ * Copyright (c) 2024 One Identity LLC.
++ * Copyright (c) 2024 Franco Fichtner
+ * Copyright (c) 2002-2011 Balabit
+ * Copyright (c) 1998-2011 Balázs Scheidler
+ *
+@@ -75,7 +77,7 @@ tls_verifier_unref(TLSVerifier *self)
+
+ /* helper functions */
+
+-static gboolean
++gboolean
+ tls_wildcard_match(const gchar *host_name, const gchar *pattern)
+ {
+ gchar **pattern_parts, **hostname_parts;
+@@ -86,22 +88,84 @@ tls_wildcard_match(const gchar *host_name, const gchar *pattern)
+
+ pattern_parts = g_strsplit(pattern, ".", 0);
+ hostname_parts = g_strsplit(host_name, ".", 0);
+- for (i = 0; pattern_parts[i]; i++)
++
++ if(g_strrstr(pattern, "\?"))
++ {
++ /* Glib would treat any question marks as jokers */
++ success = FALSE;
++ }
++ else if (g_hostname_is_ip_address(host_name))
++ {
++ /* no wildcards in IP */
++ if (g_strrstr(pattern, "*"))
++ {
++ success = FALSE;
++ }
++ else
++ {
++ struct in6_addr host_buffer, pattern_buffer;
++ gint INET_TYPE, INET_ADDRLEN;
++ if(strstr(host_name, ":"))
++ {
++ INET_TYPE = AF_INET6;
++ INET_ADDRLEN = INET6_ADDRSTRLEN;
++ }
++ else
++ {
++ INET_TYPE = AF_INET;
++ INET_ADDRLEN = INET_ADDRSTRLEN;
++ }
++ char host_ip[INET_ADDRLEN], pattern_ip[INET_ADDRLEN];
++ gint host_ip_ok = inet_pton(INET_TYPE, host_name, &host_buffer);
++ gint pattern_ip_ok = inet_pton(INET_TYPE, pattern, &pattern_buffer);
++ inet_ntop(INET_TYPE, &host_buffer, host_ip, INET_ADDRLEN);
++ inet_ntop(INET_TYPE, &pattern_buffer, pattern_ip, INET_ADDRLEN);
++ success = (host_ip_ok && pattern_ip_ok && strcmp(host_ip, pattern_ip) == 0);
++ }
++ }
++ else
+ {
+- if (!hostname_parts[i])
++ if (pattern_parts[0] == NULL)
+ {
+- /* number of dot separated entries is not the same in the hostname and the pattern spec */
+- goto exit;
++ if (hostname_parts[0] == NULL)
++ success = TRUE;
++ else
++ success = FALSE;
+ }
++ else
++ {
++ success = TRUE;
++ for (i = 0; pattern_parts[i]; i++)
++ {
++ if (hostname_parts[i] == NULL)
++ {
++ /* number of dot separated entries is not the same in the hostname and the pattern spec */
++ success = FALSE;
++ break;
++ }
++ char *wildcard_matched = g_strrstr(pattern_parts[i], "*");
++ if (wildcard_matched && (i != 0 || wildcard_matched != strstr(pattern_parts[i], "*")))
++ {
++ /* wildcard only on leftmost part and never as multiple wildcards as per both RFC 6125 and 9525 */
++ success = FALSE;
++ break;
++ }
+
+- lower_pattern = g_ascii_strdown(pattern_parts[i], -1);
+- lower_hostname = g_ascii_strdown(hostname_parts[i], -1);
++ lower_pattern = g_ascii_strdown(pattern_parts[i], -1);
++ lower_hostname = g_ascii_strdown(hostname_parts[i], -1);
+
+- if (!g_pattern_match_simple(lower_pattern, lower_hostname))
+- goto exit;
++ if (!g_pattern_match_simple(lower_pattern, lower_hostname))
++ {
++ success = FALSE;
++ break;
++ }
++ }
++ if (hostname_parts[i])
++ /* hostname has more parts than the pattern */
++ success = FALSE;
++ }
+ }
+- success = TRUE;
+-exit:
++
+ g_free(lower_pattern);
+ g_free(lower_hostname);
+ g_strfreev(pattern_parts);
+diff --git a/lib/transport/tls-verifier.h b/lib/transport/tls-verifier.h
+index 5642afa..98ab858 100644
+--- a/lib/transport/tls-verifier.h
++++ b/lib/transport/tls-verifier.h
+@@ -44,5 +44,7 @@ void tls_verifier_unref(TLSVerifier *self);
+
+ gboolean tls_verify_certificate_name(X509 *cert, const gchar *hostname);
+
++gboolean tls_wildcard_match(const gchar *host_name, const gchar *pattern);
++
+
+ #endif
+--
+2.40.0
diff --git a/meta-openembedded/meta-oe/recipes-support/syslog-ng/syslog-ng_4.6.0.bb b/meta-openembedded/meta-oe/recipes-support/syslog-ng/syslog-ng_4.6.0.bb
index 4584944150..e2ae40fd61 100644
--- a/meta-openembedded/meta-oe/recipes-support/syslog-ng/syslog-ng_4.6.0.bb
+++ b/meta-openembedded/meta-oe/recipes-support/syslog-ng/syslog-ng_4.6.0.bb
@@ -24,6 +24,7 @@ SRC_URI = "https://github.com/balabit/syslog-ng/releases/download/${BP}/${BP}.ta
file://syslog-ng.service-the-syslog-ng-service.patch \
file://0001-Fix-buildpaths-warning.patch \
file://0001-macros-guard-ipv6-code-with-SYSLOG_NG_ENABLE_IPV6.patch \
+ file://CVE-2024-47619.patch \
"
SRC_URI:append:powerpc64le = " file://0001-plugin.c-workaround-powerpc64le-segfaults-error.patch"
diff --git a/meta-openembedded/meta-oe/recipes-support/tbb/tbb/0001-Fix-suppress-new-GCC-12-13-warnings-1192.patch b/meta-openembedded/meta-oe/recipes-support/tbb/tbb/0001-Fix-suppress-new-GCC-12-13-warnings-1192.patch
new file mode 100644
index 0000000000..489f011b84
--- /dev/null
+++ b/meta-openembedded/meta-oe/recipes-support/tbb/tbb/0001-Fix-suppress-new-GCC-12-13-warnings-1192.patch
@@ -0,0 +1,57 @@
+From e131071769ee3df51b56b053ba6bfa06ae9eff25 Mon Sep 17 00:00:00 2001
+From: Dmitri Mokhov <dmitri.n.mokhov@intel.com>
+Date: Mon, 11 Sep 2023 10:35:07 -0500
+Subject: [PATCH] Fix/suppress new GCC 12/13 warnings (#1192)
+
+Upstream-Status: Backport [https://github.com/oneapi-src/oneTBB/commit/e131071769ee3df51b56b053ba6bfa06ae9eff25]
+Signed-off-by: Dmitri Mokhov <dmitri.n.mokhov@intel.com>
+---
+ .../oneapi/tbb/detail/_concurrent_unordered_base.h | 2 +-
+ src/tbb/concurrent_monitor.h | 12 +++++++++++-
+ 2 files changed, 12 insertions(+), 2 deletions(-)
+
+diff --git a/include/oneapi/tbb/detail/_concurrent_unordered_base.h b/include/oneapi/tbb/detail/_concurrent_unordered_base.h
+index ade91c33..40829208 100644
+--- a/include/oneapi/tbb/detail/_concurrent_unordered_base.h
++++ b/include/oneapi/tbb/detail/_concurrent_unordered_base.h
+@@ -921,7 +921,7 @@ private:
+ node_allocator_traits::deallocate(dummy_node_allocator, node, 1);
+ } else {
+ // GCC 11.1 issues a warning here that incorrect destructor might be called for dummy_nodes
+- #if (__TBB_GCC_VERSION >= 110100 && __TBB_GCC_VERSION < 130000 ) && !__clang__ && !__INTEL_COMPILER
++ #if (__TBB_GCC_VERSION >= 110100 && __TBB_GCC_VERSION < 140000 ) && !__clang__ && !__INTEL_COMPILER
+ volatile
+ #endif
+ value_node_ptr val_node = static_cast<value_node_ptr>(node);
+diff --git a/src/tbb/concurrent_monitor.h b/src/tbb/concurrent_monitor.h
+index 3d20ef5b..3e5c4beb 100644
+--- a/src/tbb/concurrent_monitor.h
++++ b/src/tbb/concurrent_monitor.h
+@@ -1,5 +1,5 @@
+ /*
+- Copyright (c) 2005-2021 Intel Corporation
++ Copyright (c) 2005-2023 Intel Corporation
+
+ Licensed under the Apache License, Version 2.0 (the "License");
+ you may not use this file except in compliance with the License.
+@@ -290,7 +290,17 @@ public:
+ n = my_waitset.front();
+ if (n != end) {
+ my_waitset.remove(*n);
++
++// GCC 12.x-13.x issues a warning here that to_wait_node(n)->my_is_in_list might have size 0, since n is
++// a base_node pointer. (This cannot happen, because only wait_node pointers are added to my_waitset.)
++#if (__TBB_GCC_VERSION >= 120100 && __TBB_GCC_VERSION < 140000 ) && !__clang__ && !__INTEL_COMPILER
++#pragma GCC diagnostic push
++#pragma GCC diagnostic ignored "-Wstringop-overflow"
++#endif
+ to_wait_node(n)->my_is_in_list.store(false, std::memory_order_relaxed);
++#if (__TBB_GCC_VERSION >= 120100 && __TBB_GCC_VERSION < 140000 ) && !__clang__ && !__INTEL_COMPILER
++#pragma GCC diagnostic pop
++#endif
+ }
+ }
+
+--
+2.43.0
+
diff --git a/meta-openembedded/meta-oe/recipes-support/tbb/tbb_2021.11.0.bb b/meta-openembedded/meta-oe/recipes-support/tbb/tbb_2021.11.0.bb
index f834726bd6..318cd87643 100644
--- a/meta-openembedded/meta-oe/recipes-support/tbb/tbb_2021.11.0.bb
+++ b/meta-openembedded/meta-oe/recipes-support/tbb/tbb_2021.11.0.bb
@@ -16,6 +16,7 @@ BRANCH = "onetbb_2021"
SRCREV = "8b829acc65569019edb896c5150d427f288e8aba"
SRC_URI = "git://github.com/oneapi-src/oneTBB.git;protocol=https;branch=${BRANCH} \
file://0001-hwloc_detection.cmake-remove-cross-compiation-check.patch \
+ file://0001-Fix-suppress-new-GCC-12-13-warnings-1192.patch \
"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-oe/recipes-support/thin-provisioning-tools/thin-provisioning-tools_1.0.12.bb b/meta-openembedded/meta-oe/recipes-support/thin-provisioning-tools/thin-provisioning-tools_1.0.12.bb
index 09b91f6b37..51b4b3dcc9 100644
--- a/meta-openembedded/meta-oe/recipes-support/thin-provisioning-tools/thin-provisioning-tools_1.0.12.bb
+++ b/meta-openembedded/meta-oe/recipes-support/thin-provisioning-tools/thin-provisioning-tools_1.0.12.bb
@@ -34,16 +34,18 @@ do_install:append() {
thin_delta \
thin_dump \
thin_ls \
- thin_repair \
- thin_restore \
- thin_rmap \
thin_metadata_size \
thin_metadata_pack \
thin_metadata_unpack \
+ thin_repair \
+ thin_restore \
+ thin_rmap \
+ thin_shrink \
thin_trim \
era_check \
era_dump \
era_invalidate \
+ era_repair \
era_restore; do
ln -sf pdata_tools ${D}${sbindir}/$tool
done
diff --git a/meta-openembedded/meta-oe/recipes-support/tokyocabinet/tokyocabinet_1.4.48.bb b/meta-openembedded/meta-oe/recipes-support/tokyocabinet/tokyocabinet_1.4.48.bb
index ae00ff4e55..335b71065b 100644
--- a/meta-openembedded/meta-oe/recipes-support/tokyocabinet/tokyocabinet_1.4.48.bb
+++ b/meta-openembedded/meta-oe/recipes-support/tokyocabinet/tokyocabinet_1.4.48.bb
@@ -12,10 +12,10 @@ Records are organized in hash table, B+ tree, or fixed-length array."
HOMEPAGE = "http://fallabs.com/tokyocabinet/"
-LICENSE = "GPL-2.0-only"
+LICENSE = "LGPL-2.1-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=7fbc338309ac38fefcd64b04bb903e34"
-SRC_URI = "http://fallabs.com/tokyocabinet/${BP}.tar.gz \
+SRC_URI = "${DEBIAN_MIRROR}/main/t/${BPN}/${BPN}_${PV}.orig.tar.gz \
file://remove-hard-coded-include-and-lib-paths.patch \
file://0001-configure-Fix-check-functions-for-AC_CHECK_LIB-test.patch \
"
diff --git a/meta-openembedded/meta-oe/recipes-support/tree/tree_2.1.1.bb b/meta-openembedded/meta-oe/recipes-support/tree/tree_2.1.1.bb
index 0b61149609..1eaea6a22b 100644
--- a/meta-openembedded/meta-oe/recipes-support/tree/tree_2.1.1.bb
+++ b/meta-openembedded/meta-oe/recipes-support/tree/tree_2.1.1.bb
@@ -1,10 +1,10 @@
SUMMARY = "A recursive directory listing command"
-HOMEPAGE = "http://mama.indstate.edu/users/ice/tree/"
+HOMEPAGE = "https://oldmanprogrammer.net/source.php?dir=projects/tree"
SECTION = "console/utils"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://LICENSE;md5=393a5ca445f6965873eca0259a17f833"
-SRC_URI = "http://mama.indstate.edu/users/ice/tree/src/${BP}.tgz"
+SRC_URI = "https://oldmanprogrammer.net/tar/tree/${BP}.tgz"
SRC_URI[sha256sum] = "d3c3d55f403af7c76556546325aa1eca90b918cbaaf6d3ab60a49d8367ab90d5"
# tree's default CFLAGS for Linux
diff --git a/meta-openembedded/meta-oe/recipes-support/udisks/udisks2_2.10.1.bb b/meta-openembedded/meta-oe/recipes-support/udisks/udisks2_2.10.2.bb
index cb1cbe670d..c7be69d269 100644
--- a/meta-openembedded/meta-oe/recipes-support/udisks/udisks2_2.10.1.bb
+++ b/meta-openembedded/meta-oe/recipes-support/udisks/udisks2_2.10.2.bb
@@ -21,7 +21,7 @@ SRC_URI = " \
git://github.com/storaged-project/udisks.git;branch=2.10.x-branch;protocol=https \
file://0001-Makefile.am-Dont-include-buildpath.patch \
"
-SRCREV = "18c9faf089e306ad6f3f51f5cb887a6b9aa08350"
+SRCREV = "bc623acf9e7488dc105e4b00069d57e303e2616b"
S = "${WORKDIR}/git"
CVE_PRODUCT = "udisks"
diff --git a/meta-openembedded/meta-oe/recipes-support/uim/uim_1.8.8.bb b/meta-openembedded/meta-oe/recipes-support/uim/uim_1.8.8.bb
index e0d9d05dce..0a3783e593 100644
--- a/meta-openembedded/meta-oe/recipes-support/uim/uim_1.8.8.bb
+++ b/meta-openembedded/meta-oe/recipes-support/uim/uim_1.8.8.bb
@@ -34,6 +34,8 @@ REQUIRED_DISTRO_FEATURES = "x11"
GTKIMMODULES_PACKAGES = "uim-gtk2.0 uim-gtk3"
+CFLAGS += "-std=gnu17"
+
EXTRA_OECONF += "--disable-emacs \
--with-libedit=${STAGING_EXECPREFIXDIR} \
--without-scim \
diff --git a/meta-openembedded/meta-oe/recipes-support/webkitgtk/webkitgtk3_2.44.1.bb b/meta-openembedded/meta-oe/recipes-support/webkitgtk/webkitgtk3_2.44.3.bb
index fc96d5dc3b..440cae62dd 100644
--- a/meta-openembedded/meta-oe/recipes-support/webkitgtk/webkitgtk3_2.44.1.bb
+++ b/meta-openembedded/meta-oe/recipes-support/webkitgtk/webkitgtk3_2.44.3.bb
@@ -16,7 +16,7 @@ SRC_URI = "https://www.webkitgtk.org/releases/webkitgtk-${PV}.tar.xz \
file://0001-LowLevelInterpreter.cpp-339-21-error-t6-was-not-decl.patch \
file://30e1d5e22213fdaca2a29ec3400c927d710a37a8.patch \
"
-SRC_URI[sha256sum] = "425b1459b0f04d0600c78d1abb5e7edfa3c060a420f8b231e9a6a2d5d29c5561"
+SRC_URI[sha256sum] = "dc82d042ecaca981a4852357c06e5235743319cf10a94cd36ad41b97883a0b54"
inherit cmake pkgconfig gobject-introspection perlnative features_check upstream-version-is-even gi-docgen
@@ -115,18 +115,6 @@ EXTRA_OECMAKE:append:armv4 = " -DENABLE_JIT=OFF "
EXTRA_OECMAKE:append:armv5 = " -DENABLE_JIT=OFF "
EXTRA_OECMAKE:append:armv6 = " -DENABLE_JIT=OFF "
-# And for armv7* don't enable it for softfp, because after:
-# https://github.com/WebKit/WebKit/commit/a2ec4ef1997d6fafa6ffc607bffb54e76168a918
-# https://bugs.webkit.org/show_bug.cgi?id=242172
-# softfp armv7* fails because WEBASSEMBLY is left enabled by default and JIT gets
-# explicitly disabled causing:
-# http://errors.yoctoproject.org/Errors/Details/734587/
-# PR was sent upstream, but the end result is the same both JIT and WEBASSEMBLY disabled
-# https://github.com/WebKit/WebKit/pull/17447
-EXTRA_OECMAKE:append:armv7a = " -DENABLE_JIT=${@bb.utils.contains('TUNE_FEATURES', 'callconvention-hard', 'ON', 'OFF', d)}"
-EXTRA_OECMAKE:append:armv7r = " -DENABLE_JIT=${@bb.utils.contains('TUNE_FEATURES', 'callconvention-hard', 'ON', 'OFF', d)}"
-EXTRA_OECMAKE:append:armv7ve = " -DENABLE_JIT=${@bb.utils.contains('TUNE_FEATURES', 'callconvention-hard', 'ON', 'OFF', d)}"
-
EXTRA_OECMAKE:append:mipsarch = " -DUSE_LD_GOLD=OFF "
EXTRA_OECMAKE:append:powerpc = " -DUSE_LD_GOLD=OFF "
diff --git a/meta-openembedded/meta-oe/recipes-support/xmlsec1/xmlsec1_1.3.4.bb b/meta-openembedded/meta-oe/recipes-support/xmlsec1/xmlsec1_1.3.4.bb
index 7639209e19..64912c3b03 100644
--- a/meta-openembedded/meta-oe/recipes-support/xmlsec1/xmlsec1_1.3.4.bb
+++ b/meta-openembedded/meta-oe/recipes-support/xmlsec1/xmlsec1_1.3.4.bb
@@ -12,7 +12,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=352791d62092ea8104f085042de7f4d0"
SECTION = "libs"
-SRC_URI = "http://www.aleksey.com/xmlsec/download/${BP}.tar.gz \
+SRC_URI = "https://github.com/lsh123/xmlsec/releases/download/${PR}/${BP}.tar.gz \
file://fix-ltmain.sh.patch \
file://change-finding-path-of-nss.patch \
file://makefile-ptest.patch \
diff --git a/meta-openembedded/meta-oe/recipes-test/pm-qa/pm-qa_git.bb b/meta-openembedded/meta-oe/recipes-test/pm-qa/pm-qa_git.bb
index fc21e6192e..7266e9ae32 100644
--- a/meta-openembedded/meta-oe/recipes-test/pm-qa/pm-qa_git.bb
+++ b/meta-openembedded/meta-oe/recipes-test/pm-qa/pm-qa_git.bb
@@ -10,7 +10,7 @@ BRANCH ?= "master"
SRCREV = "05710ec5032be4c8edafb4109d4d908d31243906"
-SRC_URI = "git://git.linaro.org/power/pm-qa.git;protocol=git;branch=${BRANCH}"
+SRC_URI = "git://git.linaro.org/power/pm-qa.git;protocol=https;branch=${BRANCH}"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-perl/recipes-extended/logcheck/logcheck_1.4.3.bb b/meta-openembedded/meta-perl/recipes-extended/logcheck/logcheck_1.4.3.bb
index c13bd940ea..3d17de6390 100644
--- a/meta-openembedded/meta-perl/recipes-extended/logcheck/logcheck_1.4.3.bb
+++ b/meta-openembedded/meta-perl/recipes-extended/logcheck/logcheck_1.4.3.bb
@@ -11,7 +11,7 @@ HOMEPAGE = "http://logcheck.org/"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://LICENSE;md5=c93c0550bd3173f4504b2cbd8991e50b"
-SRC_URI = "${DEBIAN_MIRROR}/main/l/${BPN}/${BPN}_${PV}.tar.xz \
+SRC_URI = "https://snapshot.debian.org/archive/debian/20230718T155737Z/pool/main/l/${BPN}/${BPN}_${PV}.tar.xz \
file://99_logcheck \
"
SRC_URI[sha256sum] = "ad83ae80bd780bdae5eefd40ad59a3e97b85ad3a4962aa7c00d98ed3bdffcdd0"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-cbor2_5.6.3.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-cbor2_5.6.3.bb
index c9c98b6fb5..69573064bc 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-cbor2_5.6.3.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-cbor2_5.6.3.bb
@@ -1,8 +1,8 @@
DESCRIPTION = "An implementation of RFC 7049 - Concise Binary Object Representation (CBOR)."
DEPENDS +="python3-setuptools-scm-native"
-LICENSE = "Apache-2.0"
-LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/Apache-2.0;md5=89aea4e17d99a7cacdbeed46a0096b10"
+LICENSE = "MIT"
+LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=a79e64179819c7ce293372c059f1dbd8"
SRC_URI[sha256sum] = "e6f0ae2751c2d333a960e0807c0611494eb1245631a167965acbc100509455d3"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-colorama_0.4.6.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-colorama_0.4.6.bb
index 0f364c424d..3871244031 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-colorama_0.4.6.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-colorama_0.4.6.bb
@@ -1,6 +1,6 @@
SUMMARY = "Cross-platform colored terminal text."
HOMEPAGE = "https://github.com/tartley/colorama"
-LICENSE = "BSD-2-Clause"
+LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=b4936429a56a652b84c5c01280dcaa26"
inherit pypi python_setuptools_build_meta
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-crc32c_2.3.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-crc32c_2.3.bb
index da756ea074..125a7ad877 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-crc32c_2.3.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-crc32c_2.3.bb
@@ -1,7 +1,7 @@
SUMMARY = "A python package implementing the crc32c algorithmin hardware and software"
HOMEPAGE = "https://github.com/ICRAR/crc32c"
-LICENSE = "BSD-2-Clause & BSD-3-Clause & CRC32C-ADLER & LGPL-2.0-or-later"
+LICENSE = "BSD-2-Clause & BSD-3-Clause & CRC32C-ADLER & LGPL-2.1-or-later"
LIC_FILES_CHKSUM = " \
file://LICENSE;md5=4fbd65380cdd255951079008b364516c \
file://LICENSE.google-crc32c;md5=e9ed01b5e5ac9eae23fc2bb33701220c \
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-django_4.2.11.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-django_4.2.20.bb
index 0642b7e7c3..3fb8b03224 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-django_4.2.11.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-django_4.2.20.bb
@@ -1,7 +1,7 @@
require python-django.inc
inherit setuptools3
-SRC_URI[sha256sum] = "6e6ff3db2d8dd0c986b4eec8554c8e4f919b5c1ff62a5b4390c17aff2ed6e5c4"
+SRC_URI[sha256sum] = "92bac5b4432a64532abb73b2ac27203f485e40225d2640a7fbef2b62b876e789"
RDEPENDS:${PN} += "\
python3-sqlparse \
@@ -10,5 +10,5 @@ RDEPENDS:${PN} += "\
# Set DEFAULT_PREFERENCE so that the LTS version of django is built by
# default. To build the 4.x branch,
-# PREFERRED_VERSION_python3-django = "4.2.11" can be added to local.conf
+# PREFERRED_VERSION_python3-django = "4.2.20" can be added to local.conf
DEFAULT_PREFERENCE = "-1"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-django_5.0.4.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-django_5.0.11.bb
index 3139ed4682..5060f3c9ad 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-django_5.0.4.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-django_5.0.11.bb
@@ -1,7 +1,7 @@
require python-django.inc
inherit setuptools3
-SRC_URI[sha256sum] = "4bd01a8c830bb77a8a3b0e7d8b25b887e536ad17a81ba2dce5476135c73312bd"
+SRC_URI[sha256sum] = "e7d98fa05ce09cb3e8d5ad6472fb602322acd1740bfdadc29c8404182d664f65"
RDEPENDS:${PN} += "\
python3-sqlparse \
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-email-validator_2.1.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-email-validator_2.1.1.bb
index 7daf548cb1..746d56d18e 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-email-validator_2.1.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-email-validator_2.1.1.bb
@@ -1,9 +1,9 @@
SUMMARY = "A robust email address syntax and deliverability validation library."
SECTION = "devel/python"
-LICENSE = "CC0-1.0"
-LIC_FILES_CHKSUM = "file://LICENSE;md5=65d3616852dbf7b1a6d4b53b00626032"
+LICENSE = "Unlicense"
+LIC_FILES_CHKSUM = "file://LICENSE;md5=2890aee62bd2a4c3197e2059016a397e"
-SRC_URI[sha256sum] = "5f511cca8856bb03251d6292ba59e7f98978aae13fa5823ddd8bf885c56a6260"
+SRC_URI[sha256sum] = "200a70680ba08904be6d1eef729205cc0d687634399a5924d842533efb824b84"
PYPI_PACKAGE = "email_validator"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-fann2_1.1.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-fann2_1.1.2.bb
index 2fbc277139..2099d791dd 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-fann2_1.1.2.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-fann2_1.1.2.bb
@@ -1,6 +1,6 @@
SUMMARY = "Python bindings for Fast Artificial Neural Networks 2.2.0 (FANN >= 2.2.0)"
SECTION = "devel/python"
-LICENSE = "LGPL-2.0-only"
+LICENSE = "LGPL-2.1-only"
LIC_FILES_CHKSUM = "file://LICENSE;md5=c73b943dc75f6f65e007c56ac6515c8f"
SRC_URI[md5sum] = "0b85b418018746d63ed66b55465697a9"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors/CVE-2024-6221.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors/CVE-2024-6221.patch
new file mode 100644
index 0000000000..9049b2ffe6
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors/CVE-2024-6221.patch
@@ -0,0 +1,110 @@
+From 7ae310c56ac30e0b94fb42129aa377bf633256ec Mon Sep 17 00:00:00 2001
+From: Adriano Sela Aviles <adriano.selaviles@gmail.com>
+Date: Fri, 30 Aug 2024 12:14:31 -0400
+Subject: [PATCH] Backwards Compatible Fix for CVE-2024-6221 (#363)
+
+CVE: CVE-2024-6221
+
+Upstream-Status: Backport [https://github.com/corydolphin/flask-cors/commit/7ae310c56ac30e0b94fb42129aa377bf633256ec]
+
+Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
+---
+ docs/configuration.rst | 14 ++++++++++++++
+ flask_cors/core.py | 8 +++++---
+ flask_cors/extension.py | 16 ++++++++++++++++
+ 3 files changed, 35 insertions(+), 3 deletions(-)
+
+diff --git a/docs/configuration.rst b/docs/configuration.rst
+index 91282d3..c750cf4 100644
+--- a/docs/configuration.rst
++++ b/docs/configuration.rst
+@@ -23,6 +23,19 @@ CORS_ALLOW_HEADERS (:py:class:`~typing.List` or :py:class:`str`)
+ Headers to accept from the client.
+ Headers in the :http:header:`Access-Control-Request-Headers` request header (usually part of the preflight OPTIONS request) matching headers in this list will be included in the :http:header:`Access-Control-Allow-Headers` response header.
+
++CORS_ALLOW_PRIVATE_NETWORK (:py:class:`bool`)
++ If True, the response header :http:header:`Access-Control-Allow-Private-Network`
++ will be set with the value 'true' whenever the request header
++ :http:header:`Access-Control-Request-Private-Network` has a value 'true'.
++
++ If False, the reponse header :http:header:`Access-Control-Allow-Private-Network`
++ will be set with the value 'false' whenever the request header
++ :http:header:`Access-Control-Request-Private-Network` has a value of 'true'.
++
++ If the request header :http:header:`Access-Control-Request-Private-Network` is
++ not present or has a value other than 'true', the response header
++ :http:header:`Access-Control-Allow-Private-Network` will not be set.
++
+ CORS_ALWAYS_SEND (:py:class:`bool`)
+ Usually, if a request doesn't include an :http:header:`Origin` header, the client did not request CORS.
+ This means we can ignore this request.
+@@ -83,6 +96,7 @@ Default values
+ ~~~~~~~~~~~~~~
+
+ * CORS_ALLOW_HEADERS: "*"
++* CORS_ALLOW_PRIVATE_NETWORK: True
+ * CORS_ALWAYS_SEND: True
+ * CORS_AUTOMATIC_OPTIONS: True
+ * CORS_EXPOSE_HEADERS: None
+diff --git a/flask_cors/core.py b/flask_cors/core.py
+index 5358036..bd011f4 100644
+--- a/flask_cors/core.py
++++ b/flask_cors/core.py
+@@ -36,7 +36,7 @@ CONFIG_OPTIONS = ['CORS_ORIGINS', 'CORS_METHODS', 'CORS_ALLOW_HEADERS',
+ 'CORS_MAX_AGE', 'CORS_SEND_WILDCARD',
+ 'CORS_AUTOMATIC_OPTIONS', 'CORS_VARY_HEADER',
+ 'CORS_RESOURCES', 'CORS_INTERCEPT_EXCEPTIONS',
+- 'CORS_ALWAYS_SEND']
++ 'CORS_ALWAYS_SEND', 'CORS_ALLOW_PRIVATE_NETWORK']
+ # Attribute added to request object by decorator to indicate that CORS
+ # was evaluated, in case the decorator and extension are both applied
+ # to a view.
+@@ -56,7 +56,8 @@ DEFAULT_OPTIONS = dict(origins='*',
+ vary_header=True,
+ resources=r'/*',
+ intercept_exceptions=True,
+- always_send=True)
++ always_send=True,
++ allow_private_network=True)
+
+
+ def parse_resources(resources):
+@@ -186,7 +187,8 @@ def get_cors_headers(options, request_headers, request_method):
+
+ if ACL_REQUEST_HEADER_PRIVATE_NETWORK in request_headers \
+ and request_headers.get(ACL_REQUEST_HEADER_PRIVATE_NETWORK) == 'true':
+- headers[ACL_RESPONSE_PRIVATE_NETWORK] = 'true'
++ allow_private_network = 'true' if options.get('allow_private_network') else 'false'
++ headers[ACL_RESPONSE_PRIVATE_NETWORK] = allow_private_network
+
+ # This is a preflight request
+ # http://www.w3.org/TR/cors/#resource-preflight-requests
+diff --git a/flask_cors/extension.py b/flask_cors/extension.py
+index c00cbff..694953f 100644
+--- a/flask_cors/extension.py
++++ b/flask_cors/extension.py
+@@ -136,6 +136,22 @@ class CORS(object):
+
+ Default : True
+ :type vary_header: bool
++
++ :param allow_private_network:
++ If True, the response header `Access-Control-Allow-Private-Network`
++ will be set with the value 'true' whenever the request header
++ `Access-Control-Request-Private-Network` has a value 'true'.
++
++ If False, the reponse header `Access-Control-Allow-Private-Network`
++ will be set with the value 'false' whenever the request header
++ `Access-Control-Request-Private-Network` has a value of 'true'.
++
++ If the request header `Access-Control-Request-Private-Network` is
++ not present or has a value other than 'true', the response header
++ `Access-Control-Allow-Private-Network` will not be set.
++
++ Default : True
++ :type allow_private_network: bool
+ """
+
+ def __init__(self, app=None, **kwargs):
+--
+2.40.0
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors_4.0.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors_4.0.0.bb
index 1d0d86b4e7..77b51c5515 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors_4.0.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-flask-cors_4.0.0.bb
@@ -9,6 +9,10 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=118fecaa576ab51c1520f95e98db61ce"
PYPI_PACKAGE = "Flask-Cors"
+SRC_URI += " \
+ file://CVE-2024-6221.patch \
+"
+
SRC_URI[sha256sum] = "f268522fcb2f73e2ecdde1ef45e2fd5c71cc48fe03cffb4b441c6d1b40684eb0"
inherit pypi setuptools3
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-googleapis-common-protos_1.63.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-googleapis-common-protos_1.63.0.bb
index aee2337267..3c55294498 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-googleapis-common-protos_1.63.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-googleapis-common-protos_1.63.0.bb
@@ -1,7 +1,7 @@
DESCRIPTION = "Common protobufs used in Google APIs"
HOMEPAGE = "https://github.com/googleapis/python-api-common-protos"
LICENSE = "Apache-2.0"
-LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/Apache-2.0;md5=89aea4e17d99a7cacdbeed46a0096b10"
+LIC_FILES_CHKSUM = "file://LICENSE;md5=3b83ef96387f14655fc854ddc3c6bd57"
inherit pypi setuptools3
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio-tools_1.62.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio-tools_1.62.2.bb
index e05b8734d6..5b8bbe681a 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio-tools_1.62.2.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio-tools_1.62.2.bb
@@ -16,4 +16,8 @@ SRC_URI[sha256sum] = "5fd5e1582b678e6b941ee5f5809340be5e0724691df5299aae8226640f
RDEPENDS:${PN} = "python3-grpcio"
+do_compile:prepend() {
+ export GRPC_PYTHON_BUILD_EXT_COMPILER_JOBS="${@oe.utils.parallel_make(d, False)}"
+}
+
BBCLASSEXTEND = "native nativesdk"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-PR-1644-unscaledcycleclock-remove-RISC-V-support.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-PR-1644-unscaledcycleclock-remove-RISC-V-support.patch
new file mode 100644
index 0000000000..82f15f88cd
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-PR-1644-unscaledcycleclock-remove-RISC-V-support.patch
@@ -0,0 +1,82 @@
+From 7335a36d0b5c1c597566f9aa3f458a5b6817c3b4 Mon Sep 17 00:00:00 2001
+From: aurel32 <aurelien@aurel32.net>
+Date: Fri, 22 Mar 2024 14:21:13 -0700
+Subject: [PATCH] PR #1644: unscaledcycleclock: remove RISC-V support
+
+Imported from GitHub PR https://github.com/abseil/abseil-cpp/pull/1644
+
+Starting with Linux 6.6 [1], RDCYCLE is a privileged instruction on RISC-V and can't be used directly from userland. There is a sysctl option to change that as a transition period, but it will eventually disappear.
+
+The RDTIME instruction is another less accurate alternative, however its frequency varies from board to board, and there is currently now way to get its frequency from userland [2].
+
+Therefore this patch just removes the code for unscaledcycleclock on RISC-V. Without processor specific implementation, abseil relies on std::chrono::steady_clock::now().time_since_epoch() which is basically a wrapper around clock_gettime (CLOCK_MONOTONIC), which in turns use __vdso_clock_gettime(). On RISC-V this VDSO is just a wrapper around RDTIME correctly scaled to use nanoseconds units.
+
+This fixes the testsuite on riscv64, tested on a VisionFive 2 board.
+
+[1] https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cc4c07c89aada16229084eeb93895c95b7eabaa3
+[2] https://github.com/abseil/abseil-cpp/pull/1631
+Merge 43356a2548cfde76e164d446cb69004b488c6a71 into 76f8011beabdaee872b5fde7546e02407b220cb1
+
+Merging this change closes #1644
+
+COPYBARA_INTEGRATE_REVIEW=https://github.com/abseil/abseil-cpp/pull/1644 from aurel32:rv64-no-unscaledcycleclock 43356a2548cfde76e164d446cb69004b488c6a71
+PiperOrigin-RevId: 618286262
+Change-Id: Ie4120a727e7d0bb185df6e06ea145c780ebe6652
+
+Upstream-Status: Backport [https://github.com/abseil/abseil-cpp/commit/7335a36d]
+[Adapted to apply on top of meta-oe's patch stack]
+Signed-off-by: Scott Murray <scott.murray@konsulko.com>
+---
+ .../absl/base/internal/unscaledcycleclock.cc | 12 ------------
+ .../absl/base/internal/unscaledcycleclock_config.h | 5 ++---
+ 2 files changed, 2 insertions(+), 15 deletions(-)
+
+diff --git a/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock.cc b/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock.cc
+index f11fecb..103b4f6 100644
+--- a/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock.cc
++++ b/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock.cc
+@@ -121,18 +121,6 @@ double UnscaledCycleClock::Frequency() {
+ return aarch64_timer_frequency;
+ }
+
+-#elif defined(__riscv)
+-
+-int64_t UnscaledCycleClock::Now() {
+- int64_t virtual_timer_value;
+- asm volatile("rdcycle %0" : "=r"(virtual_timer_value));
+- return virtual_timer_value;
+-}
+-
+-double UnscaledCycleClock::Frequency() {
+- return base_internal::NominalCPUFrequency();
+-}
+-
+ #elif defined(_M_IX86) || defined(_M_X64)
+
+ #pragma intrinsic(__rdtsc)
+diff --git a/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock_config.h b/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock_config.h
+index 5e232c1..83552fc 100644
+--- a/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock_config.h
++++ b/third_party/abseil-cpp/absl/base/internal/unscaledcycleclock_config.h
+@@ -22,7 +22,6 @@
+ // The following platforms have an implementation of a hardware counter.
+ #if defined(__i386__) || defined(__x86_64__) || defined(__aarch64__) || \
+ ((defined(__powerpc__) || defined(__ppc__)) && defined(__GLIBC__)) || \
+- defined(__riscv) || \
+ defined(_M_IX86) || (defined(_M_X64) && !defined(_M_ARM64EC))
+ #define ABSL_HAVE_UNSCALED_CYCLECLOCK_IMPLEMENTATION 1
+ #else
+@@ -54,8 +53,8 @@
+ #if ABSL_USE_UNSCALED_CYCLECLOCK
+ // This macro can be used to test if UnscaledCycleClock::Frequency()
+ // is NominalCPUFrequency() on a particular platform.
+-#if (defined(__i386__) || defined(__x86_64__) || defined(__riscv) || \
+- defined(_M_IX86) || defined(_M_X64))
++#if (defined(__i386__) || defined(__x86_64__) || defined(_M_IX86) || \
++ defined(_M_X64))
+ #define ABSL_INTERNAL_UNSCALED_CYCLECLOCK_FREQUENCY_IS_CPU_FREQUENCY
+ #endif
+ #endif
+--
+2.44.0
+
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-crypto-use-_Generic-only-if-defined-__cplusplus.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-crypto-use-_Generic-only-if-defined-__cplusplus.patch
new file mode 100644
index 0000000000..d830d92284
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/0001-crypto-use-_Generic-only-if-defined-__cplusplus.patch
@@ -0,0 +1,74 @@
+From 3359a87a71307336100b84e66b69bad385cd3cfc Mon Sep 17 00:00:00 2001
+From: Martin Jansa <martin.jansa@gmail.com>
+Date: Mon, 6 May 2024 01:36:39 +0200
+Subject: [PATCH] crypto: use _Generic only if !defined(__cplusplus)
+
+* fixes build with gcc-14 which has __builtin_addc and __builtin_subc
+ with gcc-13 it was already using the #else branch because of missing builtins
+
+* fixes
+ https://github.com/grpc/grpc/issues/35945
+
+* _Generic was introduced in boringssl with:
+ https://boringssl.googlesource.com/boringssl/+/70ca6bc24be103dabd68e448cd3af29b929b771d%5E%21/#F4
+
+* but e.g. third_party/boringssl-with-bazel/src/ssl/d1_both.cc includes
+ this internal.h and from the .cc extension gcc will process it as C++
+ where _Generic isn't available, causing:
+
+In file included from third_party/boringssl-with-bazel/src/ssl/d1_both.cc:125:
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h: In function 'uint32_t CRYPTO_addc_u32(uint32_t, uint32_t, uint32_t, uint32_t*)':
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1159:7: error: expected primary-expression before 'unsigned'
+ 1159 | unsigned: __builtin_addc, \
+ | ^~~~~~~~
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1166:10: note: in expansion of macro 'CRYPTO_GENERIC_ADDC'
+ 1166 | return CRYPTO_GENERIC_ADDC(x, y, carry, out_carry);
+ | ^~~~~~~~~~~~~~~~~~~
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1160:7: error: expected primary-expression before 'unsigned'
+ 1160 | unsigned long: __builtin_addcl, \
+ | ^~~~~~~~
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1166:10: note: in expansion of macro 'CRYPTO_GENERIC_ADDC'
+ 1166 | return CRYPTO_GENERIC_ADDC(x, y, carry, out_carry);
+ | ^~~~~~~~~~~~~~~~~~~
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1161:7: error: expected primary-expression before 'unsigned'
+ 1161 | unsigned long long: __builtin_addcll))((x), (y), (carry), (out_carry))
+ | ^~~~~~~~
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1166:10: note: in expansion of macro 'CRYPTO_GENERIC_ADDC'
+ 1166 | return CRYPTO_GENERIC_ADDC(x, y, carry, out_carry);
+ | ^~~~~~~~~~~~~~~~~~~
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1158:4: error: '_Generic' was not declared in this scope
+ 1158 | (_Generic((x), \
+ | ^~~~~~~~
+third_party/boringssl-with-bazel/src/ssl/../crypto/internal.h:1166:10: note: in expansion of macro 'CRYPTO_GENERIC_ADDC'
+ 1166 | return CRYPTO_GENERIC_ADDC(x, y, carry, out_carry);
+ | ^~~~~~~~~~~~~~~~~~~
+
+Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
+---
+Upstream-Status: Submitted [https://boringssl-review.googlesource.com/c/boringssl/+/68227 crypto: use _Generic only if !defined(__cplusplus)]
+
+ crypto/internal.h | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/crypto/internal.h b/crypto/internal.h
+index a77102d76..30d6826dd 100644
+--- a/crypto/internal.h
++++ b/crypto/internal.h
+@@ -1176,7 +1176,7 @@ static inline uint64_t CRYPTO_rotr_u64(uint64_t value, int shift) {
+
+ // CRYPTO_addc_* returns |x + y + carry|, and sets |*out_carry| to the carry
+ // bit. |carry| must be zero or one.
+-#if OPENSSL_HAS_BUILTIN(__builtin_addc)
++#if OPENSSL_HAS_BUILTIN(__builtin_addc) && !defined(__cplusplus)
+
+ #define CRYPTO_GENERIC_ADDC(x, y, carry, out_carry) \
+ (_Generic((x), \
+@@ -1228,7 +1228,7 @@ static inline uint64_t CRYPTO_addc_u64(uint64_t x, uint64_t y, uint64_t carry,
+
+ // CRYPTO_subc_* returns |x - y - borrow|, and sets |*out_borrow| to the borrow
+ // bit. |borrow| must be zero or one.
+-#if OPENSSL_HAS_BUILTIN(__builtin_subc)
++#if OPENSSL_HAS_BUILTIN(__builtin_subc) && !defined(__cplusplus)
+
+ #define CRYPTO_GENERIC_SUBC(x, y, borrow, out_borrow) \
+ (_Generic((x), \
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/CVE-2024-11407.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/CVE-2024-11407.patch
new file mode 100644
index 0000000000..eef5e7239e
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio/CVE-2024-11407.patch
@@ -0,0 +1,32 @@
+From e9046b2bbebc0cb7f5dc42008f807f6c7e98e791 Mon Sep 17 00:00:00 2001
+From: Vignesh Babu <vigneshbabu@google.com>
+Date: Thu, 12 Sep 2024 11:13:45 -0700
+Subject: [PATCH] [EventEngine] Fix bug in Tx0cp code path in posix endpoint.
+
+This fix ensures that the iov_base pointers point to the right address.
+
+PiperOrigin-RevId: 673923651
+
+CVE: CVE-2024-11407
+Upstream-Status: Backport [https://github.com/grpc/grpc/commit/e9046b2bbebc0cb7f5dc42008f807f6c7e98e791]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/core/lib/event_engine/posix_engine/posix_endpoint.cc | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/core/lib/event_engine/posix_engine/posix_endpoint.cc b/src/core/lib/event_engine/posix_engine/posix_endpoint.cc
+index 7634bb1334b..c5708db02c5 100644
+--- a/src/core/lib/event_engine/posix_engine/posix_endpoint.cc
++++ b/src/core/lib/event_engine/posix_engine/posix_endpoint.cc
+@@ -240,7 +240,7 @@ msg_iovlen_type TcpZerocopySendRecord::PopulateIovs(size_t* unwind_slice_idx,
+ iov_size++) {
+ MutableSlice& slice = internal::SliceCast<MutableSlice>(
+ buf_.MutableSliceAt(out_offset_.slice_idx));
+- iov[iov_size].iov_base = slice.begin();
++ iov[iov_size].iov_base = slice.begin() + out_offset_.byte_idx;
+ iov[iov_size].iov_len = slice.length() - out_offset_.byte_idx;
+ *sending_length += iov[iov_size].iov_len;
+ ++(out_offset_.slice_idx);
+--
+2.30.2
+
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio_1.62.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio_1.62.2.bb
index 80a4d04e67..3581991a56 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio_1.62.2.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-grpcio_1.62.2.bb
@@ -9,7 +9,10 @@ DEPENDS += "python3-protobuf"
SRC_URI += "file://0001-Include-missing-cstdint-header.patch \
file://abseil-ppc-fixes.patch \
file://0001-zlib-Include-unistd.h-for-open-close-C-APIs.patch \
+ file://0001-crypto-use-_Generic-only-if-defined-__cplusplus.patch;patchdir=third_party/boringssl-with-bazel/src/ \
file://0001-target.h-define-proper-macro-for-ppc-ppc64.patch \
+ file://0001-PR-1644-unscaledcycleclock-remove-RISC-V-support.patch \
+ file://CVE-2024-11407.patch \
"
SRC_URI[sha256sum] = "c77618071d96b7a8be2c10701a98537823b9c65ba256c0b9067e0594cdbd954d"
@@ -35,6 +38,10 @@ BORING_SSL:aarch64 = "1"
BORING_SSL ?= "0"
export GRPC_BUILD_WITH_BORING_SSL_ASM = "${BORING_SSL}"
+do_compile:prepend() {
+ export GRPC_PYTHON_BUILD_EXT_COMPILER_JOBS="${@oe.utils.parallel_make(d, False)}"
+}
+
GRPC_CFLAGS ?= ""
GRPC_CFLAGS:append:toolchain-clang = " -fvisibility=hidden -fno-wrapv -fno-exceptions"
export GRPC_PYTHON_CFLAGS = "${GRPC_CFLAGS}"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0001-Properly-cast-arguments-to-H5Lunpack_elink_val.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0001-Properly-cast-arguments-to-H5Lunpack_elink_val.patch
new file mode 100644
index 0000000000..c39d9b1950
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0001-Properly-cast-arguments-to-H5Lunpack_elink_val.patch
@@ -0,0 +1,25 @@
+From 30a59c233fbe149109f378837642dc02b2caf3f5 Mon Sep 17 00:00:00 2001
+From: Orion Poplawski <orion@nwra.com>
+Date: Thu, 15 Feb 2024 20:47:50 -0700
+Subject: [PATCH] Properly cast arguments to H5Lunpack_elink_val
+
+Upstream-Status: Backport [https://github.com/h5py/h5py/pull/2380/commits/704e13ac83b42898514610c4df9f32f367e767e4]
+
+Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
+---
+ h5py/h5l.pyx | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/h5py/h5l.pyx b/h5py/h5l.pyx
+index 60b252f..af725bd 100644
+--- a/h5py/h5l.pyx
++++ b/h5py/h5l.pyx
+@@ -184,7 +184,7 @@ cdef class LinkProxy:
+ if info.type == H5L_TYPE_SOFT:
+ py_retval = buf
+ else:
+- H5Lunpack_elink_val(buf, buf_size, &wtf, &ext_file_name, &ext_obj_name)
++ H5Lunpack_elink_val(buf, buf_size, &wtf, <const char **>&ext_file_name, <const char **>&ext_obj_name)
+ py_retval = (bytes(ext_file_name), bytes(ext_obj_name))
+ finally:
+ efree(buf)
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0002-Use-libc.stdint-instead-of-numpy.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0002-Use-libc.stdint-instead-of-numpy.patch
new file mode 100644
index 0000000000..35263d8315
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py/0002-Use-libc.stdint-instead-of-numpy.patch
@@ -0,0 +1,25 @@
+From 8b4de2f6946b1c1f68279ecadc05c2817ae82189 Mon Sep 17 00:00:00 2001
+From: Orion Poplawski <orion@nwra.com>
+Date: Thu, 22 Feb 2024 08:41:17 -0700
+Subject: [PATCH] Use libc.stdint instead of numpy
+
+Upstream-Status: Backport [https://github.com/h5py/h5py/pull/2382/commits/387a22b8c1513800c0401f496b4ed512c1639798]
+
+Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
+---
+ h5py/api_types_ext.pxd | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/h5py/api_types_ext.pxd b/h5py/api_types_ext.pxd
+index 91acb12..55a239f 100644
+--- a/h5py/api_types_ext.pxd
++++ b/h5py/api_types_ext.pxd
+@@ -20,7 +20,7 @@ from libc.string cimport strlen, strchr, strcpy, strncpy, strcmp,\
+ ctypedef long size_t
+ from libc.time cimport time_t
+
+-from numpy cimport int8_t, uint8_t, int16_t, uint16_t, int32_t, uint32_t, int64_t, uint64_t
++from libc.stdint cimport int8_t, uint8_t, int16_t, uint16_t, int32_t, uint32_t, int64_t, uint64_t
+
+ IF UNAME_SYSNAME != "Windows":
+ cdef extern from "unistd.h":
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py_3.10.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py_3.10.0.bb
index 8a9158525e..3ba5ea7396 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py_3.10.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-h5py_3.10.0.bb
@@ -6,8 +6,12 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=113251d71fb0384712c719b567261c5c"
SRC_URI[sha256sum] = "d93adc48ceeb33347eb24a634fb787efc7ae4644e6ea4ba733d099605045c049"
-SRC_URI += "file://0001-setup_build.py-avoid-absolute-path.patch \
- file://0001-Fix-Cython-3-compatibility.patch"
+SRC_URI += " \
+ file://0001-setup_build.py-avoid-absolute-path.patch \
+ file://0001-Fix-Cython-3-compatibility.patch \
+ file://0001-Properly-cast-arguments-to-H5Lunpack_elink_val.patch \
+ file://0002-Use-libc.stdint-instead-of-numpy.patch \
+"
inherit pkgconfig pypi setuptools3
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-haversine_2.8.1.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-haversine_2.8.1.bb
index e45ae79860..5fd5ddd71c 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-haversine_2.8.1.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-haversine_2.8.1.bb
@@ -1,6 +1,6 @@
SUMMARY = "Calculate the distance between 2 points on Earth"
LICENSE = "MIT"
-LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302"
+LIC_FILES_CHKSUM = "file://LICENSE;md5=20a52d2c688975e989fcbee3e6c8d1a1"
SRC_URI[sha256sum] = "ab750caa0c8f2168bd7b00a429757a83a8393be1aa30f91c2becf6b523189e2a"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-kivy_2.3.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-kivy_2.3.0.bb
index 991aa0f7d8..2c66db188b 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-kivy_2.3.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-kivy_2.3.0.bb
@@ -70,3 +70,10 @@ RDEPENDS:${PN} = " \
python3-pillow \
python3-pygments \
"
+
+do_compile:append() {
+ for f in `find ${B} -name *.c`
+ do
+ sed -i -e "/BEGIN: Cython Metadata/,/END: Cython Metadata/d" $f
+ done
+}
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-libevdev_0.11.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-libevdev_0.11.bb
index 27e336710c..5ad2a59951 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-libevdev_0.11.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-libevdev_0.11.bb
@@ -3,7 +3,7 @@ HOMEPAGE = "https://gitlab.freedesktop.org/libevdev/python-libevdev"
SECTION = "devel/python"
LICENSE = "MIT"
-LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302"
+LIC_FILES_CHKSUM = "file://COPYING;md5=d94c10c546b419eddc6296157ec40747"
SRC_URI[md5sum] = "34b48098c1fba26de79a0d67a17a588a"
SRC_URI[sha256sum] = "e9ca006a4df2488a60bd9a740011ee948d81904be2364f017e560169508f560f"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-lru-dict_1.3.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-lru-dict_1.3.0.bb
index e9535fa6f1..51f3860b07 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-lru-dict_1.3.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-lru-dict_1.3.0.bb
@@ -1,7 +1,7 @@
-SUMMARY = "A fixed size dict like container which evicts Least Recently Used (LRU) items once size limit is exceeded."
+DESCRIPTION = "A fixed size dict like container which evicts Least Recently Used (LRU) items once size limit is exceeded."
HOMEPAGE = "https://github.com/amitdev/lru-dict"
SECTION = "devel/python"
-LICENSE = "BSD-3-Clause"
+LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=9d10a486ee04034fdef5162fd791f153"
SRC_URI[sha256sum] = "54fd1966d6bd1fcde781596cb86068214edeebff1db13a2cea11079e3fd07b6b"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-mock_5.1.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-mock_5.1.0.bb
index d9ecb9d4c8..1b89260e1b 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-mock_5.1.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-mock_5.1.0.bb
@@ -1,7 +1,7 @@
DESCRIPTION = "A Python Mocking and Patching Library for Testing"
HOMEPAGE = "https://pypi.python.org/pypi/mock"
SECTION = "devel/python"
-LICENSE = "Apache-2.0"
+LICENSE = "BSD-2-Clause"
LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=de9dfbf780446b18aab11f00baaf5b7e"
inherit pypi setuptools3
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-nmap_1.6.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-nmap_1.6.0.bb
index 5fe9ab4e39..2293e3ddf8 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-nmap_1.6.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-nmap_1.6.0.bb
@@ -1,8 +1,8 @@
DESCRIPTION = "python-nmap is a python library which helps in using nmap port scanner"
HOMEPAGE = "https://www.nmmapper.com/"
SECTION = "devel/python"
-LICENSE = "MIT"
-LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302"
+LICENSE = "GPL-3.0-only"
+LIC_FILES_CHKSUM = "file://LICENSE;md5=1ebbd3e34237af26da5dc08a4e440464"
DEPENDS += "python3-wheel-native"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-parse-type_0.6.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-parse-type_0.6.2.bb
index a7d8cd86ce..57dfc5a508 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-parse-type_0.6.2.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-parse-type_0.6.2.bb
@@ -1,6 +1,6 @@
SUMMARY = "Simplifies building parse types based on the parse module"
HOMEPAGE = "https://github.com/jenisys/parse_type"
-LICENSE = "BSD-3-Clause"
+LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=2e469278ace89c246d52505acc39c3da"
SRC_URI[sha256sum] = "79b1f2497060d0928bc46016793f1fca1057c4aacdf15ef876aa48d75a73a355"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pillow_10.3.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pillow_10.3.0.bb
index debf488154..8b0bcf55dd 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pillow_10.3.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pillow_10.3.0.bb
@@ -1,8 +1,8 @@
-SUMMARY = "Python Imaging Library (Fork). Pillow is the friendly PIL fork by Alex \
+DESCRIPTION = "Python Imaging Library (Fork). Pillow is the friendly PIL fork by Alex \
Clark and Contributors. PIL is the Python Imaging Library by Fredrik Lundh and \
Contributors."
HOMEPAGE = "https://pillow.readthedocs.io"
-LICENSE = "MIT"
+LICENSE = "HPND"
LIC_FILES_CHKSUM = "file://LICENSE;md5=c349a4b4b9ec2377a8fd6a7df87dbffe"
SRC_URI = "git://github.com/python-pillow/Pillow.git;branch=main;protocol=https \
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-platformdirs_4.2.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-platformdirs_4.2.0.bb
index 19c95b374a..c69c390b80 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-platformdirs_4.2.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-platformdirs_4.2.0.bb
@@ -1,6 +1,6 @@
SUMMARY = "A small Python module for determining appropriate platform-specific dirs"
HOMEPAGE = "https://github.com/platformdirs/platformdirs"
-LICENSE = "BSD-3-Clause"
+LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=ea4f5a41454746a9ed111e3d8723d17a"
SRC_URI += " \
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0001-build_support-use-source-filename-instead-of-foo-for.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0001-build_support-use-source-filename-instead-of-foo-for.patch
new file mode 100644
index 0000000000..8bb7267086
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0001-build_support-use-source-filename-instead-of-foo-for.patch
@@ -0,0 +1,50 @@
+From 09cfcf7de2aab873a13949d5a128ccfb9e54732d Mon Sep 17 00:00:00 2001
+From: Martin Jansa <martin.jansa@gmail.com>
+Date: Mon, 5 May 2025 08:15:37 +0200
+Subject: [PATCH] build_support: use source filename instead of 'foo' for
+ discover tests
+
+* helps when debugging the issues
+* use the same order of CC arguments in compile_and_run and
+ does_build_succeed just for consistency
+* use pthread in both compile_and_run and does_build_succeed functions
+ it was added only to does_build_succeed in 5ec39f7af8cfd8525d225b1302fa93f7133b3849
+ not sure if it was intentional
+
+Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
+Upstream-Status: Submitted [https://github.com/osvenskan/posix_ipc/pull/77]
+---
+ build_support/discover_system_info.py | 6 +++---
+ 1 file changed, 3 insertions(+), 3 deletions(-)
+
+diff --git a/build_support/discover_system_info.py b/build_support/discover_system_info.py
+index bc4d174..6d059d9 100644
+--- a/build_support/discover_system_info.py
++++ b/build_support/discover_system_info.py
+@@ -60,7 +60,7 @@ def does_build_succeed(filename, linker_options=""):
+ # Rather than testing whether or not it's needed, I just specify it
+ # everywhere since it's harmless to specify it when it's not needed.
+ cc = os.getenv("CC", "cc")
+- cmd = "%s -Wall -o ./build_support/src/foo ./build_support/src/%s %s -lpthread" % (cc, filename, linker_options)
++ cmd = "%s -Wall -o ./build_support/src/%s ./build_support/src/%s %s -lpthread" % (cc, filename[:-2], filename, linker_options)
+
+ p = subprocess.Popen(cmd, shell=True, stdout=STDOUT, stderr=STDERR)
+
+@@ -73,7 +73,7 @@ def compile_and_run(filename, linker_options=""):
+ # Utility function that returns the stdout output from running the
+ # compiled source file; None if the compile fails.
+ cc = os.getenv("CC", "cc")
+- cmd = "%s -Wall -o ./build_support/src/foo %s ./build_support/src/%s" % (cc, linker_options, filename)
++ cmd = "%s -Wall -o ./build_support/src/%s ./build_support/src/%s %s -lpthread" % (cc, filename[:-2], filename, linker_options)
+
+ p = subprocess.Popen(cmd, shell=True, stdout=STDOUT, stderr=STDERR)
+
+@@ -82,7 +82,7 @@ def compile_and_run(filename, linker_options=""):
+ return None
+
+ try:
+- s = subprocess.Popen(["./build_support/src/foo"],
++ s = subprocess.Popen(["./build_support/src/%s" % filename[:-2]],
+ stdout=subprocess.PIPE).communicate()[0]
+ return s.strip().decode()
+ except Exception:
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0002-build_support-handle-empty-max_priority-value-as-Non.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0002-build_support-handle-empty-max_priority-value-as-Non.patch
new file mode 100644
index 0000000000..54c8ddaba7
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0002-build_support-handle-empty-max_priority-value-as-Non.patch
@@ -0,0 +1,49 @@
+From 8fc46d871639dbe799f6ff0a61b046412ef5dcc6 Mon Sep 17 00:00:00 2001
+From: Martin Jansa <martin.jansa@gmail.com>
+Date: Mon, 5 May 2025 08:16:30 +0200
+Subject: [PATCH] build_support: handle empty max_priority value as None
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+When cross-compiling these tests they fail when the host cannot execute
+the binaries built for target.
+
+On my local ubuntu-22.04 docker container running
+build_support/src/sniff_mq_prio_max results in:
+posix_ipc-1.2.0 $ ./build_support/src/foo
+bash: ./build_support/src/foo: cannot execute binary file: Exec format error
+which triggers the Exception in compile_and_run and returns None
+
+While on some other ubuntu-22.04 containers I see:
+posix_ipc-1.2.0$ ./build_support/src/sniff_mq_prio_max
+/usr/lib/ld-linux-aarch64.so.1: No such file or directory
+
+and the compile_and_run returns
+b''
+which then causes
+posix_ipc-1.2.0/build_support/discover_system_info.py", line 244, in sniff_mq_prio_max
+    if max_priority < 0:
+       ^^^^^^^^^^^^^^^^
+
+Handle the empty value the same as None to avoid this.
+
+Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
+Upstream-Status: Submitted [https://github.com/osvenskan/posix_ipc/pull/77]
+---
+ build_support/discover_system_info.py | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/build_support/discover_system_info.py b/build_support/discover_system_info.py
+index 6d059d9..f8a3c83 100644
+--- a/build_support/discover_system_info.py
++++ b/build_support/discover_system_info.py
+@@ -223,7 +223,7 @@ def sniff_mq_prio_max():
+ except ValueError:
+ max_priority = None
+
+- if max_priority is None:
++ if not max_priority:
+ # Looking for a #define didn't work; ask sysconf() instead.
+ # Note that sys.sysconf_names doesn't exist under Cygwin.
+ if hasattr(os, "sysconf_names") and \
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0003-build_support-use-does_build_succeed-in-compile_and_.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0003-build_support-use-does_build_succeed-in-compile_and_.patch
new file mode 100644
index 0000000000..b36d1cdb3a
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0003-build_support-use-does_build_succeed-in-compile_and_.patch
@@ -0,0 +1,62 @@
+From 760374e778fc28193cfea1416a739e206f9201c6 Mon Sep 17 00:00:00 2001
+From: Martin Jansa <martin.jansa@gmail.com>
+Date: Mon, 5 May 2025 08:28:56 +0200
+Subject: [PATCH] build_support: use does_build_succeed in compile_and_run
+
+* avoid the duplication and building the sniff_mq_prio_max.c twice
+
+Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
+Upstream-Status: Submitted [https://github.com/osvenskan/posix_ipc/pull/77]
+---
+ build_support/discover_system_info.py | 27 ++++++++++-----------------
+ 1 file changed, 10 insertions(+), 17 deletions(-)
+
+diff --git a/build_support/discover_system_info.py b/build_support/discover_system_info.py
+index f8a3c83..f6e6c8c 100644
+--- a/build_support/discover_system_info.py
++++ b/build_support/discover_system_info.py
+@@ -72,22 +72,17 @@ def does_build_succeed(filename, linker_options=""):
+ def compile_and_run(filename, linker_options=""):
+ # Utility function that returns the stdout output from running the
+ # compiled source file; None if the compile fails.
+- cc = os.getenv("CC", "cc")
+- cmd = "%s -Wall -o ./build_support/src/%s ./build_support/src/%s %s -lpthread" % (cc, filename[:-2], filename, linker_options)
+-
+- p = subprocess.Popen(cmd, shell=True, stdout=STDOUT, stderr=STDERR)
+-
+- if p.wait():
++ if does_build_succeed(filename, linker_options=""):
++ try:
++ s = subprocess.Popen(["./build_support/src/%s" % filename[:-2]],
++ stdout=subprocess.PIPE).communicate()[0]
++ return s.strip().decode()
++ except Exception:
++ # execution resulted in an error
++ return None
++ else:
+ # uh-oh, compile failed
+ return None
+-
+- try:
+- s = subprocess.Popen(["./build_support/src/%s" % filename[:-2]],
+- stdout=subprocess.PIPE).communicate()[0]
+- return s.strip().decode()
+- except Exception:
+- # execution resulted in an error
+- return None
+
+
+ def get_sysctl_value(name):
+@@ -211,11 +206,9 @@ def sniff_mq_prio_max():
+ # ref: http://www.opengroup.org/onlinepubs/009695399/basedefs/limits.h.html
+ DEFAULT_PRIORITY_MAX = 32
+
+- max_priority = None
+ # OS X up to and including 10.8 doesn't support POSIX messages queues and
+ # doesn't define MQ_PRIO_MAX. Maybe this aggravation will cease in 10.9?
+- if does_build_succeed("sniff_mq_prio_max.c"):
+- max_priority = compile_and_run("sniff_mq_prio_max.c")
++ max_priority = compile_and_run("sniff_mq_prio_max.c")
+
+ if max_priority:
+ try:
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0004-build_support-handle-runtime-errors-and-return-None-.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0004-build_support-handle-runtime-errors-and-return-None-.patch
new file mode 100644
index 0000000000..e84345a397
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc/0004-build_support-handle-runtime-errors-and-return-None-.patch
@@ -0,0 +1,47 @@
+From b079074048bc33b206b21f73fecb8173cf8adaf0 Mon Sep 17 00:00:00 2001
+From: Haixiao Yan <haixiao.yan.cn@windriver.com>
+Date: Mon, 15 Sep 2025 21:15:45 +0800
+Subject: [PATCH] build_support: handle runtime errors and return None for
+ invalid max_priority
+
+When cross-compiling, test binaries may fail to execute on the host system if
+the target toolchain was built against a newer glibc version than what is
+available on the host.
+
+For example, on Ubuntu 20.04 the following error occurs:
+
+./build_support/src/sniff_mq_prio_max: /lib/x86_64-linux-gnu/libc.so.6: version
+`GLIBC_2.34' not found (required by ./build_support/src/sniff_mq_prio_max)
+
+This change ensures that such runtime errors are gracefully handled, and
+max_priority is set to None when the test binary cannot be executed.
+
+Upstream-Status: Pending
+
+Signed-off-by: Haixiao Yan <haixiao.yan.cn@windriver.com>
+---
+ build_support/discover_system_info.py | 8 ++++++--
+ 1 file changed, 6 insertions(+), 2 deletions(-)
+
+diff --git a/build_support/discover_system_info.py b/build_support/discover_system_info.py
+index f6e6c8cbe6ba..4fec48b5529d 100644
+--- a/build_support/discover_system_info.py
++++ b/build_support/discover_system_info.py
+@@ -75,8 +75,12 @@ def compile_and_run(filename, linker_options=""):
+ if does_build_succeed(filename, linker_options=""):
+ try:
+ s = subprocess.Popen(["./build_support/src/%s" % filename[:-2]],
+- stdout=subprocess.PIPE).communicate()[0]
+- return s.strip().decode()
++ stdout=subprocess.PIPE, stderr=subprocess.PIPE)
++ stdout, stderr = s.communicate()
++ if s.returncode != 0:
++ # runtime error
++ return None
++ return stdout.strip().decode()
+ except Exception:
+ # execution resulted in an error
+ return None
+--
+2.25.1
+
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.1.1.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.1.1.bb
deleted file mode 100644
index a71187399b..0000000000
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.1.1.bb
+++ /dev/null
@@ -1,11 +0,0 @@
-DESCRIPTION = "POSIX IPC primitives (semaphores, shared memory and message queues) for Python"
-HOMEPAGE = "http://semanchuk.com/philip/posix_ipc/"
-SECTION = "devel/python"
-LICENSE = "BSD-3-Clause"
-LIC_FILES_CHKSUM = "file://LICENSE;md5=513d94a7390d4d72f3475e2d45c739b5"
-
-PYPI_PACKAGE = "posix_ipc"
-
-SRC_URI[sha256sum] = "e2456ba0cfb2ee5ba14121450e8d825b3c4a1461fca0761220aab66d4111cbb7"
-
-inherit setuptools3 pypi
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.2.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.2.0.bb
new file mode 100644
index 0000000000..cad1403813
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-posix-ipc_1.2.0.bb
@@ -0,0 +1,17 @@
+DESCRIPTION = "POSIX IPC primitives (semaphores, shared memory and message queues) for Python"
+HOMEPAGE = "http://semanchuk.com/philip/posix_ipc/"
+SECTION = "devel/python"
+LICENSE = "BSD-3-Clause"
+LIC_FILES_CHKSUM = "file://LICENSE;md5=1a4f3bd729df04bf68f66ef877e9c7c9"
+
+PYPI_PACKAGE = "posix_ipc"
+
+SRC_URI[sha256sum] = "b7444e2703c156b3cb9fcb568e85d716232f3e78f04529ebc881cfb2aedb3838"
+
+SRC_URI += " \
+ file://0001-build_support-use-source-filename-instead-of-foo-for.patch \
+ file://0002-build_support-handle-empty-max_priority-value-as-Non.patch \
+ file://0003-build_support-use-does_build_succeed-in-compile_and_.patch \
+ file://0004-build_support-handle-runtime-errors-and-return-None-.patch \
+"
+inherit pypi python_setuptools_build_meta
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-protobuf_4.25.3.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-protobuf_4.25.8.bb
index b9b03badd0..aca30efdee 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-protobuf_4.25.3.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-protobuf_4.25.8.bb
@@ -6,7 +6,7 @@ LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://PKG-INFO;beginline=8;endline=8;md5=53dbfa56f61b90215a9f8f0d527c043d"
inherit pypi setuptools3
-SRC_URI[sha256sum] = "25b5d0b42fd000320bd7830b349e3b696435f3b329810427a6bcce6a5492cc5c"
+SRC_URI[sha256sum] = "6135cf8affe1fc6f76cced2641e4ea8d3e59518d1f24ae41ba97bcad82d397cd"
# http://errors.yoctoproject.org/Errors/Details/184715/
# Can't find required file: ../src/google/protobuf/descriptor.proto
@@ -35,3 +35,11 @@ DISTUTILS_INSTALL_ARGS += "--cpp_implementation"
do_compile:prepend:class-native () {
export KOKORO_BUILD_NUMBER="1"
}
+
+do_install:append () {
+ # Remove useless and problematic .pth file. python3-protobuf is installed in the standard
+ # location of site packages. No need for such .pth file.
+ # NOTE: do not drop this removal until the following issue in upstream cpython is resolved:
+ # https://github.com/python/cpython/issues/122220
+ rm -f ${D}${PYTHON_SITEPACKAGES_DIR}/protobuf-*-nspkg.pth
+}
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pycocotools_2.0.7.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pycocotools_2.0.7.bb
index bebfb128f2..15fdbcf89c 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pycocotools_2.0.7.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pycocotools_2.0.7.bb
@@ -9,3 +9,7 @@ SRC_URI[sha256sum] = "da8b7815196eebf0adabf67fcc459126cbc6498bbc6ab1fd144c371465
DEPENDS = "python3-cython-native python3-numpy-native virtual/crypt"
RDEPENDS:${PN} = "python3-matplotlib python3-pillow python3-profile"
+
+do_compile:append() {
+ sed -i -e "/BEGIN: Cython Metadata/,/END: Cython Metadata/d" ${B}/pycocotools/_mask.c
+}
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pycurl_7.45.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pycurl_7.45.2.bb
index a6863e21ff..10d3cd1027 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pycurl_7.45.2.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pycurl_7.45.2.bb
@@ -7,7 +7,7 @@ be used to fetch objects identified by a URL from a Python program \
SECTION = "devel/python"
HOMEPAGE = "http://pycurl.io/"
-LICENSE = "LGPL-2.0-only | MIT"
+LICENSE = "LGPL-2.1-only | MIT"
LIC_FILES_CHKSUM = "file://COPYING-LGPL;md5=4fbd65380cdd255951079008b364516c \
file://COPYING-MIT;md5=be42e1b1e58c8d59c2901fd747bfc55d \
"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core-crates.inc b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core-crates.inc
index dd2027948c..c6b30bc677 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core-crates.inc
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core-crates.inc
@@ -2,31 +2,29 @@
# from Cargo.lock
SRC_URI += " \
- crate://crates.io/ahash/0.8.7 \
+ crate://crates.io/ahash/0.8.10 \
crate://crates.io/aho-corasick/1.0.2 \
- crate://crates.io/allocator-api2/0.2.16 \
crate://crates.io/autocfg/1.1.0 \
crate://crates.io/base64/0.21.7 \
crate://crates.io/bitflags/1.3.2 \
+ crate://crates.io/bitvec/1.0.1 \
crate://crates.io/cc/1.0.79 \
crate://crates.io/cfg-if/1.0.0 \
- crate://crates.io/enum_dispatch/0.3.12 \
+ crate://crates.io/enum_dispatch/0.3.13 \
crate://crates.io/equivalent/1.0.1 \
crate://crates.io/form_urlencoded/1.2.1 \
+ crate://crates.io/funty/2.0.0 \
crate://crates.io/getrandom/0.2.10 \
crate://crates.io/hashbrown/0.14.3 \
crate://crates.io/heck/0.4.1 \
crate://crates.io/idna/0.5.0 \
- crate://crates.io/indexmap/2.0.0 \
+ crate://crates.io/indexmap/2.2.2 \
crate://crates.io/indoc/2.0.4 \
crate://crates.io/itoa/1.0.8 \
- crate://crates.io/jiter/0.0.6 \
- crate://crates.io/lexical-core/0.8.5 \
+ crate://crates.io/jiter/0.4.1 \
crate://crates.io/lexical-parse-float/0.8.5 \
crate://crates.io/lexical-parse-integer/0.8.6 \
crate://crates.io/lexical-util/0.8.5 \
- crate://crates.io/lexical-write-float/0.8.5 \
- crate://crates.io/lexical-write-integer/0.8.5 \
crate://crates.io/libc/0.2.147 \
crate://crates.io/lock_api/0.4.10 \
crate://crates.io/memchr/2.6.3 \
@@ -40,29 +38,32 @@ SRC_URI += " \
crate://crates.io/percent-encoding/2.3.1 \
crate://crates.io/portable-atomic/1.6.0 \
crate://crates.io/proc-macro2/1.0.76 \
- crate://crates.io/pyo3/0.20.3 \
- crate://crates.io/pyo3-build-config/0.20.3 \
- crate://crates.io/pyo3-ffi/0.20.3 \
- crate://crates.io/pyo3-macros/0.20.3 \
- crate://crates.io/pyo3-macros-backend/0.20.3 \
+ crate://crates.io/pyo3/0.21.2 \
+ crate://crates.io/pyo3-build-config/0.21.2 \
+ crate://crates.io/pyo3-ffi/0.21.2 \
+ crate://crates.io/pyo3-macros/0.21.2 \
+ crate://crates.io/pyo3-macros-backend/0.21.2 \
crate://crates.io/python3-dll-a/0.2.9 \
crate://crates.io/quote/1.0.35 \
+ crate://crates.io/radium/0.7.0 \
crate://crates.io/redox_syscall/0.3.5 \
- crate://crates.io/regex/1.10.2 \
- crate://crates.io/regex-automata/0.4.3 \
+ crate://crates.io/regex/1.10.4 \
+ crate://crates.io/regex-automata/0.4.5 \
crate://crates.io/regex-syntax/0.8.2 \
crate://crates.io/rustversion/1.0.13 \
crate://crates.io/ryu/1.0.14 \
crate://crates.io/scopeguard/1.1.0 \
- crate://crates.io/serde/1.0.195 \
- crate://crates.io/serde_derive/1.0.195 \
- crate://crates.io/serde_json/1.0.109 \
- crate://crates.io/smallvec/1.11.2 \
- crate://crates.io/speedate/0.13.0 \
+ crate://crates.io/serde/1.0.203 \
+ crate://crates.io/serde_derive/1.0.203 \
+ crate://crates.io/serde_json/1.0.116 \
+ crate://crates.io/smallvec/1.13.2 \
+ crate://crates.io/speedate/0.14.0 \
crate://crates.io/static_assertions/1.1.0 \
crate://crates.io/strum/0.25.0 \
crate://crates.io/strum_macros/0.25.3 \
+ crate://crates.io/strum_macros/0.26.1 \
crate://crates.io/syn/2.0.48 \
+ crate://crates.io/tap/1.0.1 \
crate://crates.io/target-lexicon/0.12.9 \
crate://crates.io/tinyvec/1.6.0 \
crate://crates.io/tinyvec_macros/0.1.1 \
@@ -71,7 +72,7 @@ SRC_URI += " \
crate://crates.io/unicode-normalization/0.1.22 \
crate://crates.io/unindent/0.2.3 \
crate://crates.io/url/2.5.0 \
- crate://crates.io/uuid/1.6.1 \
+ crate://crates.io/uuid/1.8.0 \
crate://crates.io/version_check/0.9.4 \
crate://crates.io/wasi/0.11.0+wasi-snapshot-preview1 \
crate://crates.io/windows-targets/0.48.1 \
@@ -82,35 +83,34 @@ SRC_URI += " \
crate://crates.io/windows_x86_64_gnu/0.48.0 \
crate://crates.io/windows_x86_64_gnullvm/0.48.0 \
crate://crates.io/windows_x86_64_msvc/0.48.0 \
+ crate://crates.io/wyz/0.5.1 \
crate://crates.io/zerocopy/0.7.32 \
crate://crates.io/zerocopy-derive/0.7.32 \
"
-SRC_URI[ahash-0.8.7.sha256sum] = "77c3a9648d43b9cd48db467b3f87fdd6e146bcc88ab0180006cef2179fe11d01"
+SRC_URI[ahash-0.8.10.sha256sum] = "8b79b82693f705137f8fb9b37871d99e4f9a7df12b917eed79c3d3954830a60b"
SRC_URI[aho-corasick-1.0.2.sha256sum] = "43f6cb1bf222025340178f382c426f13757b2960e89779dfcb319c32542a5a41"
-SRC_URI[allocator-api2-0.2.16.sha256sum] = "0942ffc6dcaadf03badf6e6a2d0228460359d5e34b57ccdc720b7382dfbd5ec5"
SRC_URI[autocfg-1.1.0.sha256sum] = "d468802bab17cbc0cc575e9b053f41e72aa36bfa6b7f55e3529ffa43161b97fa"
SRC_URI[base64-0.21.7.sha256sum] = "9d297deb1925b89f2ccc13d7635fa0714f12c87adce1c75356b39ca9b7178567"
SRC_URI[bitflags-1.3.2.sha256sum] = "bef38d45163c2f1dde094a7dfd33ccf595c92905c8f8f4fdc18d06fb1037718a"
+SRC_URI[bitvec-1.0.1.sha256sum] = "1bc2832c24239b0141d5674bb9174f9d68a8b5b3f2753311927c172ca46f7e9c"
SRC_URI[cc-1.0.79.sha256sum] = "50d30906286121d95be3d479533b458f87493b30a4b5f79a607db8f5d11aa91f"
SRC_URI[cfg-if-1.0.0.sha256sum] = "baf1de4339761588bc0619e3cbc0120ee582ebb74b53b4efbf79117bd2da40fd"
-SRC_URI[enum_dispatch-0.3.12.sha256sum] = "8f33313078bb8d4d05a2733a94ac4c2d8a0df9a2b84424ebf4f33bfc224a890e"
+SRC_URI[enum_dispatch-0.3.13.sha256sum] = "aa18ce2bc66555b3218614519ac839ddb759a7d6720732f979ef8d13be147ecd"
SRC_URI[equivalent-1.0.1.sha256sum] = "5443807d6dff69373d433ab9ef5378ad8df50ca6298caf15de6e52e24aaf54d5"
SRC_URI[form_urlencoded-1.2.1.sha256sum] = "e13624c2627564efccf4934284bdd98cbaa14e79b0b5a141218e507b3a823456"
+SRC_URI[funty-2.0.0.sha256sum] = "e6d5a32815ae3f33302d95fdcb2ce17862f8c65363dcfd29360480ba1001fc9c"
SRC_URI[getrandom-0.2.10.sha256sum] = "be4136b2a15dd319360be1c07d9933517ccf0be8f16bf62a3bee4f0d618df427"
SRC_URI[hashbrown-0.14.3.sha256sum] = "290f1a1d9242c78d09ce40a5e87e7554ee637af1351968159f4952f028f75604"
SRC_URI[heck-0.4.1.sha256sum] = "95505c38b4572b2d910cecb0281560f54b440a19336cbbcb27bf6ce6adc6f5a8"
SRC_URI[idna-0.5.0.sha256sum] = "634d9b1461af396cad843f47fdba5597a4f9e6ddd4bfb6ff5d85028c25cb12f6"
-SRC_URI[indexmap-2.0.0.sha256sum] = "d5477fe2230a79769d8dc68e0eabf5437907c0457a5614a9e8dddb67f65eb65d"
+SRC_URI[indexmap-2.2.2.sha256sum] = "824b2ae422412366ba479e8111fd301f7b5faece8149317bb81925979a53f520"
SRC_URI[indoc-2.0.4.sha256sum] = "1e186cfbae8084e513daff4240b4797e342f988cecda4fb6c939150f96315fd8"
SRC_URI[itoa-1.0.8.sha256sum] = "62b02a5381cc465bd3041d84623d0fa3b66738b52b8e2fc3bab8ad63ab032f4a"
-SRC_URI[jiter-0.0.6.sha256sum] = "87db066a99f69382be06d02313f8ce989996b53a04a8a70cfd1a6483a56227f7"
-SRC_URI[lexical-core-0.8.5.sha256sum] = "2cde5de06e8d4c2faabc400238f9ae1c74d5412d03a7bd067645ccbc47070e46"
+SRC_URI[jiter-0.4.1.sha256sum] = "abbbbe1bad457e3cd5503af716aedc735e849505a0d2172c55a753ae1b127458"
SRC_URI[lexical-parse-float-0.8.5.sha256sum] = "683b3a5ebd0130b8fb52ba0bdc718cc56815b6a097e28ae5a6997d0ad17dc05f"
SRC_URI[lexical-parse-integer-0.8.6.sha256sum] = "6d0994485ed0c312f6d965766754ea177d07f9c00c9b82a5ee62ed5b47945ee9"
SRC_URI[lexical-util-0.8.5.sha256sum] = "5255b9ff16ff898710eb9eb63cb39248ea8a5bb036bea8085b1a767ff6c4e3fc"
-SRC_URI[lexical-write-float-0.8.5.sha256sum] = "accabaa1c4581f05a3923d1b4cfd124c329352288b7b9da09e766b0668116862"
-SRC_URI[lexical-write-integer-0.8.5.sha256sum] = "e1b6f3d1f4422866b68192d62f77bc5c700bee84f3069f2469d7bc8c77852446"
SRC_URI[libc-0.2.147.sha256sum] = "b4668fb0ea861c1df094127ac5f1da3409a82116a4ba74fca2e58ef927159bb3"
SRC_URI[lock_api-0.4.10.sha256sum] = "c1cc9717a20b1bb222f333e6a92fd32f7d8a18ddc5a3191a11af45dcbf4dcd16"
SRC_URI[memchr-2.6.3.sha256sum] = "8f232d6ef707e1956a43342693d2a31e72989554d58299d7a88738cc95b0d35c"
@@ -124,29 +124,32 @@ SRC_URI[parking_lot_core-0.9.8.sha256sum] = "93f00c865fe7cabf650081affecd3871070
SRC_URI[percent-encoding-2.3.1.sha256sum] = "e3148f5046208a5d56bcfc03053e3ca6334e51da8dfb19b6cdc8b306fae3283e"
SRC_URI[portable-atomic-1.6.0.sha256sum] = "7170ef9988bc169ba16dd36a7fa041e5c4cbeb6a35b76d4c03daded371eae7c0"
SRC_URI[proc-macro2-1.0.76.sha256sum] = "95fc56cda0b5c3325f5fbbd7ff9fda9e02bb00bb3dac51252d2f1bfa1cb8cc8c"
-SRC_URI[pyo3-0.20.3.sha256sum] = "53bdbb96d49157e65d45cc287af5f32ffadd5f4761438b527b055fb0d4bb8233"
-SRC_URI[pyo3-build-config-0.20.3.sha256sum] = "deaa5745de3f5231ce10517a1f5dd97d53e5a2fd77aa6b5842292085831d48d7"
-SRC_URI[pyo3-ffi-0.20.3.sha256sum] = "62b42531d03e08d4ef1f6e85a2ed422eb678b8cd62b762e53891c05faf0d4afa"
-SRC_URI[pyo3-macros-0.20.3.sha256sum] = "7305c720fa01b8055ec95e484a6eca7a83c841267f0dd5280f0c8b8551d2c158"
-SRC_URI[pyo3-macros-backend-0.20.3.sha256sum] = "7c7e9b68bb9c3149c5b0cade5d07f953d6d125eb4337723c4ccdb665f1f96185"
+SRC_URI[pyo3-0.21.2.sha256sum] = "a5e00b96a521718e08e03b1a622f01c8a8deb50719335de3f60b3b3950f069d8"
+SRC_URI[pyo3-build-config-0.21.2.sha256sum] = "7883df5835fafdad87c0d888b266c8ec0f4c9ca48a5bed6bbb592e8dedee1b50"
+SRC_URI[pyo3-ffi-0.21.2.sha256sum] = "01be5843dc60b916ab4dad1dca6d20b9b4e6ddc8e15f50c47fe6d85f1fb97403"
+SRC_URI[pyo3-macros-0.21.2.sha256sum] = "77b34069fc0682e11b31dbd10321cbf94808394c56fd996796ce45217dfac53c"
+SRC_URI[pyo3-macros-backend-0.21.2.sha256sum] = "08260721f32db5e1a5beae69a55553f56b99bd0e1c3e6e0a5e8851a9d0f5a85c"
SRC_URI[python3-dll-a-0.2.9.sha256sum] = "d5f07cd4412be8fa09a721d40007c483981bbe072cd6a21f2e83e04ec8f8343f"
SRC_URI[quote-1.0.35.sha256sum] = "291ec9ab5efd934aaf503a6466c5d5251535d108ee747472c3977cc5acc868ef"
+SRC_URI[radium-0.7.0.sha256sum] = "dc33ff2d4973d518d823d61aa239014831e521c75da58e3df4840d3f47749d09"
SRC_URI[redox_syscall-0.3.5.sha256sum] = "567664f262709473930a4bf9e51bf2ebf3348f2e748ccc50dea20646858f8f29"
-SRC_URI[regex-1.10.2.sha256sum] = "380b951a9c5e80ddfd6136919eef32310721aa4aacd4889a8d39124b026ab343"
-SRC_URI[regex-automata-0.4.3.sha256sum] = "5f804c7828047e88b2d32e2d7fe5a105da8ee3264f01902f796c8e067dc2483f"
+SRC_URI[regex-1.10.4.sha256sum] = "c117dbdfde9c8308975b6a18d71f3f385c89461f7b3fb054288ecf2a2058ba4c"
+SRC_URI[regex-automata-0.4.5.sha256sum] = "5bb987efffd3c6d0d8f5f89510bb458559eab11e4f869acb20bf845e016259cd"
SRC_URI[regex-syntax-0.8.2.sha256sum] = "c08c74e62047bb2de4ff487b251e4a92e24f48745648451635cec7d591162d9f"
SRC_URI[rustversion-1.0.13.sha256sum] = "dc31bd9b61a32c31f9650d18add92aa83a49ba979c143eefd27fe7177b05bd5f"
SRC_URI[ryu-1.0.14.sha256sum] = "fe232bdf6be8c8de797b22184ee71118d63780ea42ac85b61d1baa6d3b782ae9"
SRC_URI[scopeguard-1.1.0.sha256sum] = "d29ab0c6d3fc0ee92fe66e2d99f700eab17a8d57d1c1d3b748380fb20baa78cd"
-SRC_URI[serde-1.0.195.sha256sum] = "63261df402c67811e9ac6def069e4786148c4563f4b50fd4bf30aa370d626b02"
-SRC_URI[serde_derive-1.0.195.sha256sum] = "46fe8f8603d81ba86327b23a2e9cdf49e1255fb94a4c5f297f6ee0547178ea2c"
-SRC_URI[serde_json-1.0.109.sha256sum] = "cb0652c533506ad7a2e353cce269330d6afd8bdfb6d75e0ace5b35aacbd7b9e9"
-SRC_URI[smallvec-1.11.2.sha256sum] = "4dccd0940a2dcdf68d092b8cbab7dc0ad8fa938bf95787e1b916b0e3d0e8e970"
-SRC_URI[speedate-0.13.0.sha256sum] = "242f76c50fd18cbf098607090ade73a08d39cfd84ea835f3796a2c855223b19b"
+SRC_URI[serde-1.0.203.sha256sum] = "7253ab4de971e72fb7be983802300c30b5a7f0c2e56fab8abfc6a214307c0094"
+SRC_URI[serde_derive-1.0.203.sha256sum] = "500cbc0ebeb6f46627f50f3f5811ccf6bf00643be300b4c3eabc0ef55dc5b5ba"
+SRC_URI[serde_json-1.0.116.sha256sum] = "3e17db7126d17feb94eb3fad46bf1a96b034e8aacbc2e775fe81505f8b0b2813"
+SRC_URI[smallvec-1.13.2.sha256sum] = "3c5e1a9a646d36c3599cd173a41282daf47c44583ad367b8e6837255952e5c67"
+SRC_URI[speedate-0.14.0.sha256sum] = "c323c4e6fece5a5a1a2a7f726d243144cce9fbcfe3ce4d9f3c6ede726a2bc780"
SRC_URI[static_assertions-1.1.0.sha256sum] = "a2eb9349b6444b326872e140eb1cf5e7c522154d69e7a0ffb0fb81c06b37543f"
SRC_URI[strum-0.25.0.sha256sum] = "290d54ea6f91c969195bdbcd7442c8c2a2ba87da8bf60a7ee86a235d4bc1e125"
SRC_URI[strum_macros-0.25.3.sha256sum] = "23dc1fa9ac9c169a78ba62f0b841814b7abae11bdd047b9c58f893439e309ea0"
+SRC_URI[strum_macros-0.26.1.sha256sum] = "7a3417fc93d76740d974a01654a09777cb500428cc874ca9f45edfe0c4d4cd18"
SRC_URI[syn-2.0.48.sha256sum] = "0f3531638e407dfc0814761abb7c00a5b54992b849452a0646b7f65c9f770f3f"
+SRC_URI[tap-1.0.1.sha256sum] = "55937e1799185b12863d447f42597ed69d9928686b8d88a1df17376a097d8369"
SRC_URI[target-lexicon-0.12.9.sha256sum] = "df8e77cb757a61f51b947ec4a7e3646efd825b73561db1c232a8ccb639e611a0"
SRC_URI[tinyvec-1.6.0.sha256sum] = "87cc5ceb3875bb20c2890005a4e226a4651264a5c75edb2421b52861a0a0cb50"
SRC_URI[tinyvec_macros-0.1.1.sha256sum] = "1f3ccbac311fea05f86f61904b462b55fb3df8837a366dfc601a0161d0532f20"
@@ -155,7 +158,7 @@ SRC_URI[unicode-ident-1.0.10.sha256sum] = "22049a19f4a68748a168c0fc439f9516686aa
SRC_URI[unicode-normalization-0.1.22.sha256sum] = "5c5713f0fc4b5db668a2ac63cdb7bb4469d8c9fed047b1d0292cc7b0ce2ba921"
SRC_URI[unindent-0.2.3.sha256sum] = "c7de7d73e1754487cb58364ee906a499937a0dfabd86bcb980fa99ec8c8fa2ce"
SRC_URI[url-2.5.0.sha256sum] = "31e6302e3bb753d46e83516cae55ae196fc0c309407cf11ab35cc51a4c2a4633"
-SRC_URI[uuid-1.6.1.sha256sum] = "5e395fcf16a7a3d8127ec99782007af141946b4795001f876d54fb0d55978560"
+SRC_URI[uuid-1.8.0.sha256sum] = "a183cf7feeba97b4dd1c0d46788634f6221d87fa961b305bed08c851829efcc0"
SRC_URI[version_check-0.9.4.sha256sum] = "49874b5167b65d7193b8aba1567f5c7d93d001cafc34600cee003eda787e483f"
SRC_URI[wasi-0.11.0+wasi-snapshot-preview1.sha256sum] = "9c8d87e72b64a3b4db28d11ce29237c246188f4f51057d65a7eab63b7987e423"
SRC_URI[windows-targets-0.48.1.sha256sum] = "05d4b17490f70499f20b9e791dcf6a299785ce8af4d709018206dc5b4953e95f"
@@ -166,5 +169,6 @@ SRC_URI[windows_i686_msvc-0.48.0.sha256sum] = "4542c6e364ce21bf45d69fdd2a8e455fa
SRC_URI[windows_x86_64_gnu-0.48.0.sha256sum] = "ca2b8a661f7628cbd23440e50b05d705db3686f894fc9580820623656af974b1"
SRC_URI[windows_x86_64_gnullvm-0.48.0.sha256sum] = "7896dbc1f41e08872e9d5e8f8baa8fdd2677f29468c4e156210174edc7f7b953"
SRC_URI[windows_x86_64_msvc-0.48.0.sha256sum] = "1a515f5799fe4961cb532f983ce2b23082366b898e52ffbce459c86f67c8378a"
+SRC_URI[wyz-0.5.1.sha256sum] = "05f360fc0b24296329c78fda852a1e9ae82de9cf7b27dae4b7f62f118f77b9ed"
SRC_URI[zerocopy-0.7.32.sha256sum] = "74d4d3961e53fa4c9a25a8637fc2bfaf2595b3d3ae34875568a5cf64787716be"
SRC_URI[zerocopy-derive-0.7.32.sha256sum] = "9ce1b18ccd8e73a9321186f97e46f9f04b778851177567b1975109d26a08d2a6"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Bumps-pyo3-https-github.com-pyo3-pyo3-from-0.20.2-to.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Bumps-pyo3-https-github.com-pyo3-pyo3-from-0.20.2-to.patch
deleted file mode 100644
index 32777e1d03..0000000000
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Bumps-pyo3-https-github.com-pyo3-pyo3-from-0.20.2-to.patch
+++ /dev/null
@@ -1,126 +0,0 @@
-From a5690f973384bf8cbf4deb3b83d822b7aaefbdd8 Mon Sep 17 00:00:00 2001
-From: Khem Raj <raj.khem@gmail.com>
-Date: Tue, 27 Feb 2024 11:00:46 -0800
-Subject: [PATCH] Bumps [pyo3](https://github.com/pyo3/pyo3) from 0.20.2 to
- 0.20.3.
-
-Upstream-Status: Pending
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
----
- Cargo.lock | 26 +++++++++++++++++---------
- Cargo.toml | 2 +-
- 2 files changed, 18 insertions(+), 10 deletions(-)
-
---- a/Cargo.lock
-+++ b/Cargo.lock
-@@ -322,6 +322,12 @@ source = "registry+https://github.com/ru
- checksum = "e3148f5046208a5d56bcfc03053e3ca6334e51da8dfb19b6cdc8b306fae3283e"
-
- [[package]]
-+name = "portable-atomic"
-+version = "1.6.0"
-+source = "registry+https://github.com/rust-lang/crates.io-index"
-+checksum = "7170ef9988bc169ba16dd36a7fa041e5c4cbeb6a35b76d4c03daded371eae7c0"
-+
-+[[package]]
- name = "proc-macro2"
- version = "1.0.76"
- source = "registry+https://github.com/rust-lang/crates.io-index"
-@@ -357,9 +363,9 @@ dependencies = [
-
- [[package]]
- name = "pyo3"
--version = "0.20.2"
-+version = "0.20.3"
- source = "registry+https://github.com/rust-lang/crates.io-index"
--checksum = "9a89dc7a5850d0e983be1ec2a463a171d20990487c3cfcd68b5363f1ee3d6fe0"
-+checksum = "53bdbb96d49157e65d45cc287af5f32ffadd5f4761438b527b055fb0d4bb8233"
- dependencies = [
- "cfg-if",
- "indoc",
-@@ -367,6 +373,7 @@ dependencies = [
- "memoffset",
- "num-bigint",
- "parking_lot",
-+ "portable-atomic",
- "pyo3-build-config",
- "pyo3-ffi",
- "pyo3-macros",
-@@ -375,9 +382,9 @@ dependencies = [
-
- [[package]]
- name = "pyo3-build-config"
--version = "0.20.2"
-+version = "0.20.3"
- source = "registry+https://github.com/rust-lang/crates.io-index"
--checksum = "07426f0d8fe5a601f26293f300afd1a7b1ed5e78b2a705870c5f30893c5163be"
-+checksum = "deaa5745de3f5231ce10517a1f5dd97d53e5a2fd77aa6b5842292085831d48d7"
- dependencies = [
- "once_cell",
- "python3-dll-a",
-@@ -386,9 +393,9 @@ dependencies = [
-
- [[package]]
- name = "pyo3-ffi"
--version = "0.20.2"
-+version = "0.20.3"
- source = "registry+https://github.com/rust-lang/crates.io-index"
--checksum = "dbb7dec17e17766b46bca4f1a4215a85006b4c2ecde122076c562dd058da6cf1"
-+checksum = "62b42531d03e08d4ef1f6e85a2ed422eb678b8cd62b762e53891c05faf0d4afa"
- dependencies = [
- "libc",
- "pyo3-build-config",
-@@ -396,9 +403,9 @@ dependencies = [
-
- [[package]]
- name = "pyo3-macros"
--version = "0.20.2"
-+version = "0.20.3"
- source = "registry+https://github.com/rust-lang/crates.io-index"
--checksum = "05f738b4e40d50b5711957f142878cfa0f28e054aa0ebdfc3fd137a843f74ed3"
-+checksum = "7305c720fa01b8055ec95e484a6eca7a83c841267f0dd5280f0c8b8551d2c158"
- dependencies = [
- "proc-macro2",
- "pyo3-macros-backend",
-@@ -408,12 +415,13 @@ dependencies = [
-
- [[package]]
- name = "pyo3-macros-backend"
--version = "0.20.2"
-+version = "0.20.3"
- source = "registry+https://github.com/rust-lang/crates.io-index"
--checksum = "0fc910d4851847827daf9d6cdd4a823fbdaab5b8818325c5e97a86da79e8881f"
-+checksum = "7c7e9b68bb9c3149c5b0cade5d07f953d6d125eb4337723c4ccdb665f1f96185"
- dependencies = [
- "heck",
- "proc-macro2",
-+ "pyo3-build-config",
- "quote",
- "syn",
- ]
---- a/Cargo.toml
-+++ b/Cargo.toml
-@@ -26,7 +26,7 @@ include = [
- ]
-
- [dependencies]
--pyo3 = { version = "0.20.2", features = ["generate-import-lib", "num-bigint"] }
-+pyo3 = { version = "0.20.3", features = ["generate-import-lib", "num-bigint"] }
- regex = "1.10.2"
- strum = { version = "0.25.0", features = ["derive"] }
- strum_macros = "0.25.3"
-@@ -70,12 +70,12 @@ debug = true
- strip = false
-
- [dev-dependencies]
--pyo3 = { version = "0.20.2", features = ["auto-initialize"] }
-+pyo3 = { version = "0.20.3", features = ["auto-initialize"] }
-
- [build-dependencies]
- version_check = "0.9.4"
- # used where logic has to be version/distribution specific, e.g. pypy
--pyo3-build-config = { version = "0.20.2" }
-+pyo3-build-config = { version = "0.20.3" }
-
- [lints.clippy]
- dbg_macro = "warn"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Set-rust-version-from-1.76-to-1.75-in-Cargo.toml.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Set-rust-version-from-1.76-to-1.75-in-Cargo.toml.patch
new file mode 100644
index 0000000000..c4e6f2f6ab
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0001-Set-rust-version-from-1.76-to-1.75-in-Cargo.toml.patch
@@ -0,0 +1,29 @@
+From 6e1852228a2aa38cc76b9a968bba6b603efa5b28 Mon Sep 17 00:00:00 2001
+From: Frank de Brabander <debrabander@gmail.com>
+Date: Thu, 25 Jul 2024 13:50:44 +0200
+Subject: [PATCH] Set rust version from 1.76 to 1.75 in Cargo.toml
+
+Current openembedded-core uses 1.75 and this packages doesn't actually
+require a newer version.
+
+Upstream-Status: Inappropriate
+---
+ Cargo.toml | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/Cargo.toml b/Cargo.toml
+index 8f0ea44..10b277c 100644
+--- a/Cargo.toml
++++ b/Cargo.toml
+@@ -24,7 +24,7 @@ include = [
+ "!tests/.pytest_cache",
+ "!*.so",
+ ]
+-rust-version = "1.76"
++rust-version = "1.75"
+
+ [dependencies]
+ pyo3 = { version = "0.21.2", features = ["generate-import-lib", "num-bigint"] }
+--
+2.39.2
+
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0002-Dont-embed-RUSTFLAGS-in-final-binary.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0002-Dont-embed-RUSTFLAGS-in-final-binary.patch
new file mode 100644
index 0000000000..1c195e294b
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core/0002-Dont-embed-RUSTFLAGS-in-final-binary.patch
@@ -0,0 +1,47 @@
+From b3282b301096253a11b1f887f915d0a2a2183597 Mon Sep 17 00:00:00 2001
+From: Frank de Brabander <debrabander@gmail.com>
+Date: Thu, 8 Aug 2024 08:04:48 +0200
+Subject: [PATCH] Dont embed RUSTFLAGS in final binary
+
+Upstream-Status: Backport [https://github.com/pydantic/pydantic-core/commit/e07c41b3bad75948201a2201387225694c2fb501]
+---
+ build.rs | 9 +++++++++
+ src/lib.rs | 5 ++++-
+ 2 files changed, 13 insertions(+), 1 deletion(-)
+
+diff --git a/build.rs b/build.rs
+index 7f59e1f..7fe6490 100644
+--- a/build.rs
++++ b/build.rs
+@@ -35,6 +35,15 @@ fn main() {
+ if let Some(true) = version_check::supports_feature("coverage_attribute") {
+ println!("cargo:rustc-cfg=has_coverage_attribute");
+ }
++
++ if std::env::var("RUSTFLAGS")
++ .unwrap_or_default()
++ .contains("-Cprofile-use=")
++ {
++ println!("cargo:rustc-cfg=specified_profile_use");
++ }
++ println!("cargo:rustc-check-cfg=cfg(specified_profile_use)");
++
+ generate_self_schema();
+ println!("cargo:rustc-env=PROFILE={}", std::env::var("PROFILE").unwrap());
+ }
+diff --git a/src/lib.rs b/src/lib.rs
+index d55e836..206a7a1 100644
+--- a/src/lib.rs
++++ b/src/lib.rs
+@@ -111,7 +111,10 @@ pub fn build_info() -> String {
+ format!(
+ "profile={} pgo={}",
+ env!("PROFILE"),
+- option_env!("RUSTFLAGS").unwrap_or("").contains("-Cprofile-use="),
++ // We use a `cfg!` here not `env!`/`option_env!` as those would
++ // embed `RUSTFLAGS` into the generated binary which causes problems
++ // with reproducable builds.
++ cfg!(specified_profile_use),
+ )
+ }
+
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core_2.16.3.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core_2.18.4.bb
index faa291ea6d..adaf4a62cb 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core_2.16.3.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic-core_2.18.4.bb
@@ -8,8 +8,9 @@ HOMEPAGE = "https://github.com/pydantic/pydantic-core"
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=ab599c188b4a314d2856b3a55030c75c"
-SRC_URI += "file://0001-Bumps-pyo3-https-github.com-pyo3-pyo3-from-0.20.2-to.patch"
-SRC_URI[sha256sum] = "1cac689f80a3abab2d3c0048b29eea5751114054f032a941a32de4c852c59cad"
+SRC_URI += "file://0001-Set-rust-version-from-1.76-to-1.75-in-Cargo.toml.patch \
+ file://0002-Dont-embed-RUSTFLAGS-in-final-binary.patch"
+SRC_URI[sha256sum] = "ec3beeada09ff865c344ff3bc2f427f5e6c26401cc6113d77e372c3fdac73864"
DEPENDS = "python3-maturin-native python3-typing-extensions"
@@ -19,7 +20,10 @@ inherit pypi cargo-update-recipe-crates python_maturin
PYPI_PACKAGE = "pydantic_core"
-RDEPENDS:${PN} += "python3-typing-extensions"
+RDEPENDS:${PN} += " \
+ python3-compression \
+ python3-typing-extensions \
+"
INSANE_SKIP:${PN} = "already-stripped"
@@ -33,6 +37,8 @@ RDEPENDS:${PN}-ptest += "\
python3-pytest-timeout \
python3-pytest-benchmark \
python3-unittest-automake-output \
+ python3-zoneinfo \
+ tzdata \
"
do_install:append() {
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic_2.7.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic_2.7.4.bb
index 36ad83527d..04c9c91c0e 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic_2.7.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pydantic_2.7.4.bb
@@ -11,7 +11,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=09280955509d1c4ca14bae02f21d49a6"
inherit pypi python_hatchling
-SRC_URI[sha256sum] = "b5ecdd42262ca2462e2624793551e80911a1e989f462910bb81aef974b4bb383"
+SRC_URI[sha256sum] = "0c84efd9548d545f63ac0060c1e4d39bb9b14db8b3c0652338aecc07b5adec52"
DEPENDS += "python3-hatch-fancy-pypi-readme-native"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pylint_3.1.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pylint_3.1.0.bb
index 12f4f908af..4c49acaf1e 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pylint_3.1.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pylint_3.1.0.bb
@@ -3,7 +3,7 @@ HOMEPAGE= "http://www.pylint.org/"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://LICENSE;md5=c107cf754550e65755c42985a5d4e9c9"
-SRC_URI += "git://github.com/pylint-dev/pylint;branch=maintenance/3.1.x;protocol=https \
+SRC_URI += "git://github.com/pylint-dev/pylint;branch=main;protocol=https \
file://0001-Adjust-test-expectations-for-ptest.patch \
file://run-ptest \
"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj/rpath.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj/rpath.patch
new file mode 100644
index 0000000000..347996a808
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj/rpath.patch
@@ -0,0 +1,18 @@
+Description: Don't set RPATH in libraries.
+Author: Bas Couwenberg <sebastic@debian.org>
+Forwarded: not-needed
+
+Upstream-Status: Inappropriate [OE-Specific]
+Signed-off-by: Khem Raj <raj.khem@gmail.com>
+--- a/setup.py
++++ b/setup.py
+@@ -194,9 +194,6 @@ def get_extension_modules():
+ ext_options = {
+ "include_dirs": include_dirs,
+ "library_dirs": library_dirs,
+- "runtime_library_dirs": (
+- library_dirs if os.name != "nt" and sys.platform != "cygwin" else None
+- ),
+ "libraries": get_libraries(library_dirs),
+ }
+ # setup cythonized modules
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj_3.6.1.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj_3.6.1.bb
index a4121c3934..f6b6ee8a46 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj_3.6.1.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyproj_3.6.1.bb
@@ -8,6 +8,8 @@ PYPI_PACKAGE = "pyproj"
inherit pypi setuptools3
+SRC_URI += "file://rpath.patch"
+
SRC_URI[sha256sum] = "44aa7c704c2b7d8fb3d483bbf75af6cb2350d30a63b144279a09b75fead501bf"
RDEPENDS:${PN} = " \
@@ -21,3 +23,11 @@ RDEPENDS:${PN} = " \
export PROJ_INCDIR = "${STAGING_INCDIR}"
export PROJ_LIBDIR = "${STAGING_LIBDIR}"
export PROJ_DIR = "${STAGING_BINDIR_NATIVE}/.."
+
+do_compile:append() {
+ for f in `find ${B} -name *.c`
+ do
+ sed -i -e "/BEGIN: Cython Metadata/,/END: Cython Metadata/d" $f
+ done
+ python_pep517_do_compile
+}
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-pyyaml-include_1.3.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyyaml-include_1.3.2.bb
index 3a5bd99a78..309d0ac596 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-pyyaml-include_1.3.2.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-pyyaml-include_1.3.2.bb
@@ -26,4 +26,4 @@ RDEPENDS:${PN}-ptest += " \
python3-pytest \
python3-unittest-automake-output \
"
-
+BBCLASSEXTEND = "native nativesdk"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2024-4340.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2024-4340.patch
new file mode 100644
index 0000000000..670904071a
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse/CVE-2024-4340.patch
@@ -0,0 +1,48 @@
+From b4a39d9850969b4e1d6940d32094ee0b42a2cf03 Mon Sep 17 00:00:00 2001
+From: Andi Albrecht <albrecht.andi@gmail.com>
+Date: Sat, 13 Apr 2024 13:59:00 +0200
+Subject: [PATCH] Raise SQLParseError instead of RecursionError.
+
+CVE: CVE-2024-4340
+
+Upstream-Status: Backport [https://github.com/andialbrecht/sqlparse/commit/b4a39d9850969b4e1d6940d32094ee0b42a2cf03]
+
+Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
+---
+ sqlparse/sql.py | 14 +++++++++-----
+ 1 file changed, 9 insertions(+), 5 deletions(-)
+
+diff --git a/sqlparse/sql.py b/sqlparse/sql.py
+index 1ccfbdb..2090621 100644
+--- a/sqlparse/sql.py
++++ b/sqlparse/sql.py
+@@ -10,6 +10,7 @@
+ import re
+
+ from sqlparse import tokens as T
++from sqlparse.exceptions import SQLParseError
+ from sqlparse.utils import imt, remove_quotes
+
+
+@@ -209,11 +210,14 @@ class TokenList(Token):
+
+ This method is recursively called for all child tokens.
+ """
+- for token in self.tokens:
+- if token.is_group:
+- yield from token.flatten()
+- else:
+- yield token
++ try:
++ for token in self.tokens:
++ if token.is_group:
++ yield from token.flatten()
++ else:
++ yield token
++ except RecursionError as err:
++ raise SQLParseError('Maximum recursion depth exceeded') from err
+
+ def get_sublists(self):
+ for token in self.tokens:
+--
+2.25.1
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse_0.4.4.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse_0.4.4.bb
index c04971ee8f..fa633026c8 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse_0.4.4.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-sqlparse_0.4.4.bb
@@ -5,6 +5,7 @@ LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://LICENSE;md5=2b136f573f5386001ea3b7b9016222fc"
SRC_URI += "file://0001-sqlparse-change-shebang-to-python3.patch \
+ file://CVE-2024-4340.patch \
file://run-ptest \
"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-tornado_6.4.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-tornado_6.4.2.bb
index b01c1cec2a..751f32913a 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-tornado_6.4.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-tornado_6.4.2.bb
@@ -6,9 +6,9 @@ HOMEPAGE = "http://www.tornadoweb.org/en/stable/"
LICENSE = "Apache-2.0"
LIC_FILES_CHKSUM = "file://LICENSE;md5=3b83ef96387f14655fc854ddc3c6bd57"
-SRC_URI[sha256sum] = "72291fa6e6bc84e626589f1c29d90a5a6d593ef5ae68052ee2ef000dfd273dee"
+SRC_URI[sha256sum] = "92bad5b4746e9879fd7bf1eb21dce4e3fc5128d71601f80005afa39237ad620b"
-inherit pypi setuptools3
+inherit pypi python_setuptools_build_meta
# Requires _compression which is currently located in misc
RDEPENDS:${PN} += " \
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0001.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0001.patch
new file mode 100644
index 0000000000..1f6bf6bbfc
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0001.patch
@@ -0,0 +1,89 @@
+From 046a164f89a0f08d3239ecebd750360f8914df33 Mon Sep 17 00:00:00 2001
+From: Adi Roiban <adiroiban@gmail.com>
+Date: Mon Jul 29 14:28:03 2024 +0100
+Subject: [PATCH] Merge commit from fork
+
+Added HTML output encoding the "URL" parameter of the "redirectTo" function
+
+CVE: CVE-2024-41671
+
+Upstream-Status: Backport [https://github.com/twisted/twisted/commit/046a164f89a0f08d3239ecebd750360f8914df33]
+
+Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
+---
+ src/twisted/web/_template_util.py | 2 +-
+ src/twisted/web/test/test_util.py | 39 ++++++++++++++++++++++++++++++-
+ 2 files changed, 39 insertions(+), 2 deletions(-)
+
+diff --git a/src/twisted/web/_template_util.py b/src/twisted/web/_template_util.py
+index 230c33f..7266079 100644
+--- a/src/twisted/web/_template_util.py
++++ b/src/twisted/web/_template_util.py
+@@ -92,7 +92,7 @@ def redirectTo(URL: bytes, request: IRequest) -> bytes:
+ </body>
+ </html>
+ """ % {
+- b"url": URL
++ b"url": escape(URL.decode("utf-8")).encode("utf-8")
+ }
+ return content
+
+diff --git a/src/twisted/web/test/test_util.py b/src/twisted/web/test/test_util.py
+index 1e76300..9847dcb 100644
+--- a/src/twisted/web/test/test_util.py
++++ b/src/twisted/web/test/test_util.py
+@@ -5,7 +5,6 @@
+ Tests for L{twisted.web.util}.
+ """
+
+-
+ import gc
+
+ from twisted.internet import defer
+@@ -64,6 +63,44 @@ class RedirectToTests(TestCase):
+ targetURL = "http://target.example.com/4321"
+ self.assertRaises(TypeError, redirectTo, targetURL, request)
+
++ def test_legitimateRedirect(self):
++ """
++ Legitimate URLs are fully interpolated in the `redirectTo` response body without transformation
++ """
++ request = DummyRequest([b""])
++ html = redirectTo(b"https://twisted.org/", request)
++ expected = b"""
++<html>
++ <head>
++ <meta http-equiv=\"refresh\" content=\"0;URL=https://twisted.org/\">
++ </head>
++ <body bgcolor=\"#FFFFFF\" text=\"#000000\">
++ <a href=\"https://twisted.org/\">click here</a>
++ </body>
++</html>
++"""
++ self.assertEqual(html, expected)
++
++ def test_maliciousRedirect(self):
++ """
++ Malicious URLs are HTML-escaped before interpolating them in the `redirectTo` response body
++ """
++ request = DummyRequest([b""])
++ html = redirectTo(
++ b'https://twisted.org/"><script>alert(document.location)</script>', request
++ )
++ expected = b"""
++<html>
++ <head>
++ <meta http-equiv=\"refresh\" content=\"0;URL=https://twisted.org/&quot;&gt;&lt;script&gt;alert(document.location)&lt;/script&gt;\">
++ </head>
++ <body bgcolor=\"#FFFFFF\" text=\"#000000\">
++ <a href=\"https://twisted.org/&quot;&gt;&lt;script&gt;alert(document.location)&lt;/script&gt;\">click here</a>
++ </body>
++</html>
++"""
++ self.assertEqual(html, expected)
++
+
+ class ParentRedirectTests(SynchronousTestCase):
+ """
+--
+2.40.0
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0002.patch b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0002.patch
new file mode 100644
index 0000000000..147c21d73d
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0002.patch
@@ -0,0 +1,251 @@
+From 4a930de12fb67e88fefcb8822104152f42b27abc Mon Sep 17 00:00:00 2001
+From: Adi Roiban <adiroiban@gmail.com>
+Date: Mon Jul 29 14:27:23 2024 +0100
+Subject: [PATCH] Merge commit from fork
+
+Address GHSA-c8m8-j448-xjx7
+
+CVE: CVE-2024-41671
+
+Upstream-Status: Backport [https://github.com/twisted/twisted/commit/4a930de12fb67e88fefcb8822104152f42b27abc]
+
+Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
+---
+ src/twisted/web/http.py | 21 +++--
+ src/twisted/web/test/test_http.py | 122 ++++++++++++++++++++++++++----
+ 2 files changed, 122 insertions(+), 21 deletions(-)
+
+diff --git a/src/twisted/web/http.py b/src/twisted/web/http.py
+index 1c59838..3b784f5 100644
+--- a/src/twisted/web/http.py
++++ b/src/twisted/web/http.py
+@@ -2000,16 +2000,21 @@ class _ChunkedTransferDecoder:
+ @returns: C{False}, as there is either insufficient data to continue,
+ or no data remains.
+ """
+- if (
+- self._receivedTrailerHeadersSize + len(self._buffer)
+- > self._maxTrailerHeadersSize
+- ):
+- raise _MalformedChunkedDataError("Trailer headers data is too long.")
+-
+ eolIndex = self._buffer.find(b"\r\n", self._start)
+
+ if eolIndex == -1:
+ # Still no end of network line marker found.
++ #
++ # Check if we've run up against the trailer size limit: if the next
++ # read contains the terminating CRLF then we'll have this many bytes
++ # of trailers (including the CRLFs).
++ minTrailerSize = (
++ self._receivedTrailerHeadersSize
++ + len(self._buffer)
++ + (1 if self._buffer.endswith(b"\r") else 2)
++ )
++ if minTrailerSize > self._maxTrailerHeadersSize:
++ raise _MalformedChunkedDataError("Trailer headers data is too long.")
+ # Continue processing more data.
+ return False
+
+@@ -2019,6 +2024,8 @@ class _ChunkedTransferDecoder:
+ del self._buffer[0 : eolIndex + 2]
+ self._start = 0
+ self._receivedTrailerHeadersSize += eolIndex + 2
++ if self._receivedTrailerHeadersSize > self._maxTrailerHeadersSize:
++ raise _MalformedChunkedDataError("Trailer headers data is too long.")
+ return True
+
+ # eolIndex in this part of code is equal to 0
+@@ -2342,8 +2349,8 @@ class HTTPChannel(basic.LineReceiver, policies.TimeoutMixin):
+ self.__header = line
+
+ def _finishRequestBody(self, data):
+- self.allContentReceived()
+ self._dataBuffer.append(data)
++ self.allContentReceived()
+
+ def _maybeChooseTransferDecoder(self, header, data):
+ """
+diff --git a/src/twisted/web/test/test_http.py b/src/twisted/web/test/test_http.py
+index 33d0a49..1130d31 100644
+--- a/src/twisted/web/test/test_http.py
++++ b/src/twisted/web/test/test_http.py
+@@ -135,7 +135,7 @@ class DummyHTTPHandler(http.Request):
+ data = self.content.read()
+ length = self.getHeader(b"content-length")
+ if length is None:
+- length = networkString(str(length))
++ length = str(length).encode()
+ request = b"'''\n" + length + b"\n" + data + b"'''\n"
+ self.setResponseCode(200)
+ self.setHeader(b"Request", self.uri)
+@@ -563,17 +563,23 @@ class HTTP0_9Tests(HTTP1_0Tests):
+
+ class PipeliningBodyTests(unittest.TestCase, ResponseTestMixin):
+ """
+- Tests that multiple pipelined requests with bodies are correctly buffered.
++ Pipelined requests get buffered and executed in the order received,
++ not processed in parallel.
+ """
+
+ requests = (
+ b"POST / HTTP/1.1\r\n"
+ b"Content-Length: 10\r\n"
+ b"\r\n"
+- b"0123456789POST / HTTP/1.1\r\n"
+- b"Content-Length: 10\r\n"
+- b"\r\n"
+ b"0123456789"
++ # Chunk encoded request.
++ b"POST / HTTP/1.1\r\n"
++ b"Transfer-Encoding: chunked\r\n"
++ b"\r\n"
++ b"a\r\n"
++ b"0123456789\r\n"
++ b"0\r\n"
++ b"\r\n"
+ )
+
+ expectedResponses = [
+@@ -590,14 +596,16 @@ class PipeliningBodyTests(unittest.TestCase, ResponseTestMixin):
+ b"Request: /",
+ b"Command: POST",
+ b"Version: HTTP/1.1",
+- b"Content-Length: 21",
+- b"'''\n10\n0123456789'''\n",
++ b"Content-Length: 23",
++ b"'''\nNone\n0123456789'''\n",
+ ),
+ ]
+
+- def test_noPipelining(self):
++ def test_stepwiseTinyTube(self):
+ """
+- Test that pipelined requests get buffered, not processed in parallel.
++ Imitate a slow connection that delivers one byte at a time.
++ The request handler (L{DelayedHTTPHandler}) is puppeted to
++ step through the handling of each request.
+ """
+ b = StringTransport()
+ a = http.HTTPChannel()
+@@ -606,10 +614,9 @@ class PipeliningBodyTests(unittest.TestCase, ResponseTestMixin):
+ # one byte at a time, to stress it.
+ for byte in iterbytes(self.requests):
+ a.dataReceived(byte)
+- value = b.value()
+
+ # So far only one request should have been dispatched.
+- self.assertEqual(value, b"")
++ self.assertEqual(b.value(), b"")
+ self.assertEqual(1, len(a.requests))
+
+ # Now, process each request one at a time.
+@@ -618,8 +625,91 @@ class PipeliningBodyTests(unittest.TestCase, ResponseTestMixin):
+ request = a.requests[0].original
+ request.delayedProcess()
+
+- value = b.value()
+- self.assertResponseEquals(value, self.expectedResponses)
++ self.assertResponseEquals(b.value(), self.expectedResponses)
++
++ def test_stepwiseDumpTruck(self):
++ """
++ Imitate a fast connection where several pipelined
++ requests arrive in a single read. The request handler
++ (L{DelayedHTTPHandler}) is puppeted to step through the
++ handling of each request.
++ """
++ b = StringTransport()
++ a = http.HTTPChannel()
++ a.requestFactory = DelayedHTTPHandlerProxy
++ a.makeConnection(b)
++
++ a.dataReceived(self.requests)
++
++ # So far only one request should have been dispatched.
++ self.assertEqual(b.value(), b"")
++ self.assertEqual(1, len(a.requests))
++
++ # Now, process each request one at a time.
++ while a.requests:
++ self.assertEqual(1, len(a.requests))
++ request = a.requests[0].original
++ request.delayedProcess()
++
++ self.assertResponseEquals(b.value(), self.expectedResponses)
++
++ def test_immediateTinyTube(self):
++ """
++ Imitate a slow connection that delivers one byte at a time.
++ (L{DummyHTTPHandler}) immediately responds, but no more
++ than one
++ """
++ b = StringTransport()
++ a = http.HTTPChannel()
++ a.requestFactory = DummyHTTPHandlerProxy # "sync"
++ a.makeConnection(b)
++
++ # one byte at a time, to stress it.
++ for byte in iterbytes(self.requests):
++ a.dataReceived(byte)
++ # There is never more than one request dispatched at a time:
++ self.assertLessEqual(len(a.requests), 1)
++
++ self.assertResponseEquals(b.value(), self.expectedResponses)
++
++ def test_immediateDumpTruck(self):
++ """
++ Imitate a fast connection where several pipelined
++ requests arrive in a single read. The request handler
++ (L{DummyHTTPHandler}) immediately responds.
++ This doesn't check the at-most-one pending request
++ invariant but exercises otherwise uncovered code paths.
++ See GHSA-c8m8-j448-xjx7.
++ """
++ b = StringTransport()
++ a = http.HTTPChannel()
++ a.requestFactory = DummyHTTPHandlerProxy
++ a.makeConnection(b)
++
++ # All bytes at once to ensure there's stuff to buffer.
++ a.dataReceived(self.requests)
++
++ self.assertResponseEquals(b.value(), self.expectedResponses)
++
++ def test_immediateABiggerTruck(self):
++ """
++ Imitate a fast connection where a so many pipelined
++ requests arrive in a single read that backpressure is indicated.
++ The request handler (L{DummyHTTPHandler}) immediately responds.
++ This doesn't check the at-most-one pending request
++ invariant but exercises otherwise uncovered code paths.
++ See GHSA-c8m8-j448-xjx7.
++ @see: L{http.HTTPChannel._optimisticEagerReadSize}
++ """
++ b = StringTransport()
++ a = http.HTTPChannel()
++ a.requestFactory = DummyHTTPHandlerProxy
++ a.makeConnection(b)
++
++ overLimitCount = a._optimisticEagerReadSize // len(self.requests) * 10
++ a.dataReceived(self.requests * overLimitCount)
++
++ self.assertResponseEquals(b.value(), self.expectedResponses * overLimitCount)
+
+ def test_pipeliningReadLimit(self):
+ """
+@@ -1522,7 +1612,11 @@ class ChunkedTransferEncodingTests(unittest.TestCase):
+ lambda b: None, # pragma: nocov
+ )
+ p._maxTrailerHeadersSize = 10
+- p.dataReceived(b"3\r\nabc\r\n0\r\n0123456789")
++ # 9 bytes are received so far, in 2 packets.
++ # For now, all is ok.
++ p.dataReceived(b"3\r\nabc\r\n0\r\n01234567")
++ p.dataReceived(b"\r")
++ # Once the 10th byte is received, the processing fails.
+ self.assertRaises(
+ http._MalformedChunkedDataError,
+ p.dataReceived,
+--
+2.40.0
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted_24.3.0.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted_24.3.0.bb
index 336c173893..272aecb8b0 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted_24.3.0.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-twisted_24.3.0.bb
@@ -6,6 +6,11 @@ HOMEPAGE = "https://twisted.org"
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=c1c5d2c2493b848f83864bdedd67bbf5"
+SRC_URI += " \
+ file://CVE-2024-41671-0001.patch \
+ file://CVE-2024-41671-0002.patch \
+"
+
SRC_URI[sha256sum] = "6b38b6ece7296b5e122c9eb17da2eeab3d98a198f50ca9efd00fb03e5b4fd4ae"
inherit pypi python_hatchling
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-werkzeug_3.0.1.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-werkzeug_3.0.6.bb
index f8d2769b41..5758830cb9 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-werkzeug_3.0.1.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-werkzeug_3.0.6.bb
@@ -8,9 +8,9 @@ cookie handling, file uploads, a powerful URL routing system and a bunch \
of community contributed addon modules."
HOMEPAGE = "https://werkzeug.palletsprojects.com"
LICENSE = "BSD-3-Clause"
-LIC_FILES_CHKSUM = "file://LICENSE.rst;md5=5dc88300786f1c214c1e9827a5229462"
+LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=5dc88300786f1c214c1e9827a5229462"
-SRC_URI[sha256sum] = "507e811ecea72b18a404947aded4b3390e1db8f826b494d76550ef45bb3b1dcc"
+SRC_URI[sha256sum] = "a8dd59d4de28ca70471a34cba79bed5f7ef2e036a76b3ab0835474246eb41f8d"
inherit pypi python_flit_core
@@ -20,4 +20,5 @@ RDEPENDS:${PN} += " \
python3-profile \
python3-compression \
python3-json \
+ python3-difflib \
"
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-xlsxwriter_3.1.9.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-xlsxwriter_3.1.9.bb
index ee7dab35cb..4e23feebbb 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-xlsxwriter_3.1.9.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-xlsxwriter_3.1.9.bb
@@ -1,7 +1,7 @@
SUMMARY = "Python 2 and 3 compatibility library"
HOMEPAGE = "https://xlsxwriter.readthedocs.io"
SECTION = "devel/python"
-LICENSE = "MIT"
+LICENSE = "BSD-2-Clause"
LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=12d9fac1f0049be71ab5aa4a78da02b0"
inherit pypi setuptools3
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/python3-xmodem_0.4.7.bb b/meta-openembedded/meta-python/recipes-devtools/python/python3-xmodem_0.4.7.bb
index 482f0c641b..a5942e3d5c 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/python3-xmodem_0.4.7.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/python3-xmodem_0.4.7.bb
@@ -9,8 +9,8 @@ inherit pypi setuptools3
do_install:append() {
install -d ${D}${docdir}/${PN}
- mv ${D}/usr/doc/* ${D}${docdir}/${PN}/
- rmdir ${D}/usr/doc
+ mv ${D}${prefix}/doc/* ${D}${docdir}/${PN}/
+ rmdir ${D}${prefix}/doc
}
RDEPENDS:${PN} += " \
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/tftpy/CVE-2023-46566.patch b/meta-openembedded/meta-python/recipes-devtools/python/tftpy/CVE-2023-46566.patch
new file mode 100644
index 0000000000..0131dedb1c
--- /dev/null
+++ b/meta-openembedded/meta-python/recipes-devtools/python/tftpy/CVE-2023-46566.patch
@@ -0,0 +1,26 @@
+From 5b4dcbe1c8fb178e4d31b9a9e63e603b73e8fb2f Mon Sep 17 00:00:00 2001
+From: Dave Wapstra <dwapstra@cisco.com>
+Date: Wed, 3 Jul 2024 14:32:58 +1200
+Subject: [PATCH] Add packet size check
+
+CVE: CVE-2023-46566
+
+Upstream-Status: Backport [https://github.com/msoulier/tftpy/commit/5b4dcbe1c8fb178e4d31b9a9e63e603b73e8fb2f]
+---
+ tftpy/TftpPacketFactory.py | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/tftpy/TftpPacketFactory.py b/tftpy/TftpPacketFactory.py
+index 41f39a9..a8c9cd0 100644
+--- a/tftpy/TftpPacketFactory.py
++++ b/tftpy/TftpPacketFactory.py
+@@ -29,6 +29,7 @@ class TftpPacketFactory(object):
+ """This method is used to parse an existing datagram into its
+ corresponding TftpPacket object. The buffer is the raw bytes off of
+ the network."""
++ tftpassert(len(buffer) > 2, 'Invalid packet size')
+ log.debug("parsing a %d byte packet" % len(buffer))
+ (opcode,) = struct.unpack(str("!H"), buffer[:2])
+ log.debug("opcode is %d" % opcode)
+--
+2.40.0
diff --git a/meta-openembedded/meta-python/recipes-devtools/python/tftpy_0.8.2.bb b/meta-openembedded/meta-python/recipes-devtools/python/tftpy_0.8.2.bb
index c1b3234f72..c169916845 100644
--- a/meta-openembedded/meta-python/recipes-devtools/python/tftpy_0.8.2.bb
+++ b/meta-openembedded/meta-python/recipes-devtools/python/tftpy_0.8.2.bb
@@ -11,3 +11,5 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=22770e72ae03c61f5bcc4e333b61368d"
SRC_URI[sha256sum] = "e1d1a680efd88eba176b351175844253067392a9b0f8b81588e3ff2b9e7bbb5b"
inherit pypi setuptools3
+
+SRC_URI += "file://CVE-2023-46566.patch"
diff --git a/meta-openembedded/meta-webserver/recipes-httpd/apache-mod/mod-dnssd_0.6.bb b/meta-openembedded/meta-webserver/recipes-httpd/apache-mod/mod-dnssd_0.6.bb
index 5fac0a6ed4..6f2a2330ae 100644
--- a/meta-openembedded/meta-webserver/recipes-httpd/apache-mod/mod-dnssd_0.6.bb
+++ b/meta-openembedded/meta-webserver/recipes-httpd/apache-mod/mod-dnssd_0.6.bb
@@ -5,7 +5,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=3b83ef96387f14655fc854ddc3c6bd57"
DEPENDS = "apache2 avahi"
-SRC_URI = "git://git.0pointer.de/mod_dnssd;protocol=git;branch=master"
+SRC_URI = "git://git.0pointer.net/mod_dnssd.git;protocol=https;branch=master"
SRCREV = "be2fb9f6158f800685de7a1bc01c39b6cf1fa12c"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-webserver/recipes-httpd/apache2/apache2_2.4.59.bb b/meta-openembedded/meta-webserver/recipes-httpd/apache2/apache2_2.4.65.bb
index b96e8b4e17..dcba815831 100644
--- a/meta-openembedded/meta-webserver/recipes-httpd/apache2/apache2_2.4.59.bb
+++ b/meta-openembedded/meta-webserver/recipes-httpd/apache2/apache2_2.4.65.bb
@@ -27,7 +27,7 @@ SRC_URI:append:class-target = " \
"
LIC_FILES_CHKSUM = "file://LICENSE;md5=bddeddfac80b2c9a882241d008bb41c3"
-SRC_URI[sha256sum] = "ec51501ec480284ff52f637258135d333230a7d229c3afa6f6c2f9040e321323"
+SRC_URI[sha256sum] = "58b8be97d9940ec17f7656c0c6b9f41b618aac468b894b534148e3296c53b8b3"
S = "${WORKDIR}/httpd-${PV}"
@@ -37,6 +37,18 @@ DEPENDS = "openssl expat pcre apr apr-util apache2-native "
CVE_PRODUCT = "apache:http_server"
+CVE_STATUS[CVE-1999-0289] = "not-applicable-platform: The current version is not affected. It only applies for Windows"
+CVE_STATUS[CVE-1999-0678] = "not-applicable-platform: this CVE is for Debian packaging configuration"
+CVE_STATUS[CVE-1999-1237] = "cpe-incorrect: This is vulnerability of Apache AuthenSmb module, fixed in 0.9"
+CVE_STATUS[CVE-1999-1412] = "not-applicable-platform: this CVE is for MAC OS X specific problem"
+CVE_STATUS[CVE-2007-0086] = "disputed: this CVE is officially disputed by Redhat"
+CVE_STATUS[CVE-2007-0450] = "not-applicable-platform: The current version is not affected. It only applies for Windows."
+CVE_STATUS[CVE-2007-6421] = "cpe-incorrect: The current version is not affected by the CVE which affects versions from 2.2 (incl.) to 2.2.8 (excl.)"
+CVE_STATUS[CVE-2007-6422] = "cpe-incorrect: The current version is not affected by the CVE which affects versions from 2.2 (incl.) to 2.2.8 (excl.)"
+CVE_STATUS[CVE-2007-6423] = "cpe-incorrect: The current version is not affected by the CVE which affects versions from 2.2.x to 2.2.7-dev"
+CVE_STATUS[CVE-2008-2168] = "cpe-incorrect: The current version is not affected by the CVE which affects versions up to 2.2.6 (excl.)"
+CVE_STATUS[CVE-2010-0425] = "not-applicable-platform: The current version is not affected. It only applies for Windows."
+
SSTATE_SCAN_FILES += "apxs config_vars.mk config.nice"
PACKAGECONFIG ?= "${@bb.utils.filter('DISTRO_FEATURES', 'selinux', d)}"
@@ -175,6 +187,9 @@ INITSCRIPT_PARAMS = "defaults 91 20"
SYSTEMD_SERVICE:${PN} = "apache2.service"
SYSTEMD_AUTO_ENABLE:${PN} = "enable"
+ALTERNATIVE:${PN} = "httpd"
+ALTERNATIVE_LINK_NAME[httpd] = "${sbindir}/httpd"
+ALTERNATIVE_PRIORITY[httpd] = "60"
ALTERNATIVE:${PN}-doc = "htpasswd.1"
ALTERNATIVE_LINK_NAME[htpasswd.1] = "${mandir}/man1/htpasswd.1"
diff --git a/meta-openembedded/meta-webserver/recipes-httpd/monkey/monkey_1.6.9.bb b/meta-openembedded/meta-webserver/recipes-httpd/monkey/monkey_1.6.9.bb
index ee5dc16198..773e099198 100644
--- a/meta-openembedded/meta-webserver/recipes-httpd/monkey/monkey_1.6.9.bb
+++ b/meta-openembedded/meta-webserver/recipes-httpd/monkey/monkey_1.6.9.bb
@@ -90,3 +90,5 @@ CONFFILES:${PN} = "${sysconfdir}/monkey/monkey.conf \
${sysconfdir}/monkey/plugins/auth/monkey.users \
"
+CVE_STATUS[CVE-2013-2183] = "cpe-incorrect: Current version (1.6.9) is not affected. Issue was addressed in version 1.3.0"
+CVE_STATUS[CVE-2013-1771] = "not-applicable-platform: this is gentoo specific CVE"
diff --git a/meta-openembedded/meta-webserver/recipes-httpd/nginx/files/CVE-2024-7347-1.patch b/meta-openembedded/meta-webserver/recipes-httpd/nginx/files/CVE-2024-7347-1.patch
new file mode 100644
index 0000000000..23723d63d4
--- /dev/null
+++ b/meta-openembedded/meta-webserver/recipes-httpd/nginx/files/CVE-2024-7347-1.patch
@@ -0,0 +1,34 @@
+From 88955b1044ef38315b77ad1a509d63631a790a0f Mon Sep 17 00:00:00 2001
+From: Roman Arutyunyan <arut@nginx.com>
+Date: Mon, 12 Aug 2024 18:20:45 +0400
+Subject: [PATCH] Mp4: rejecting unordered chunks in stsc atom.
+
+Unordered chunks could result in trak->end_chunk smaller than trak->start_chunk
+in ngx_http_mp4_crop_stsc_data(). Later in ngx_http_mp4_update_stco_atom()
+this caused buffer overread while trying to calculate trak->end_offset.
+
+CVE: CVE-2024-7347
+Upstream-Status: Backport [https://github.com/nginx/nginx/commit/88955b1044ef38315b77ad1a509d63631a790a0f]
+Signed-off-by: Ashish Sharma <asharma@mvista.com>
+
+ src/http/modules/ngx_http_mp4_module.c | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+diff --git a/src/http/modules/ngx_http_mp4_module.c b/src/http/modules/ngx_http_mp4_module.c
+index 1cd017c274..041ad263b5 100644
+--- a/src/http/modules/ngx_http_mp4_module.c
++++ b/src/http/modules/ngx_http_mp4_module.c
+@@ -3156,6 +3156,13 @@ ngx_http_mp4_crop_stsc_data(ngx_http_mp4_file_t *mp4,
+
+ next_chunk = ngx_mp4_get_32value(entry->chunk);
+
++ if (next_chunk < chunk) {
++ ngx_log_error(NGX_LOG_ERR, mp4->file.log, 0,
++ "unordered mp4 stsc chunks in \"%s\"",
++ mp4->file.name.data);
++ return NGX_ERROR;
++ }
++
+ ngx_log_debug5(NGX_LOG_DEBUG_HTTP, mp4->file.log, 0,
+ "sample:%uD, chunk:%uD, chunks:%uD, "
+ "samples:%uD, id:%uD",
diff --git a/meta-openembedded/meta-webserver/recipes-httpd/nginx/files/CVE-2024-7347-2.patch b/meta-openembedded/meta-webserver/recipes-httpd/nginx/files/CVE-2024-7347-2.patch
new file mode 100644
index 0000000000..5b8d08a1e1
--- /dev/null
+++ b/meta-openembedded/meta-webserver/recipes-httpd/nginx/files/CVE-2024-7347-2.patch
@@ -0,0 +1,52 @@
+From 7362d01658b61184108c21278443910da68f93b4 Mon Sep 17 00:00:00 2001
+From: Roman Arutyunyan <arut@nginx.com>
+Date: Mon, 12 Aug 2024 18:20:43 +0400
+Subject: [PATCH] Mp4: fixed buffer underread while updating stsz atom.
+
+While cropping an stsc atom in ngx_http_mp4_crop_stsc_data(), a 32-bit integer
+overflow could happen, which could result in incorrect seeking and a very large
+value stored in "samples". This resulted in a large invalid value of
+trak->end_chunk_samples. This value is further used to calculate the value of
+trak->end_chunk_samples_size in ngx_http_mp4_update_stsz_atom(). While doing
+this, a large invalid value of trak->end_chunk_samples could result in reading
+memory before stsz atom start. This could potentially result in a segfault.
+
+CVE: CVE-2024-7347
+Upstream-Status: Backport [https://github.com/nginx/nginx/commit/7362d01658b61184108c21278443910da68f93b4]
+Signed-off-by: Ashish Sharma <asharma@mvista.com>
+
+ src/http/modules/ngx_http_mp4_module.c | 7 ++++---
+ 1 file changed, 4 insertions(+), 3 deletions(-)
+
+diff --git a/src/http/modules/ngx_http_mp4_module.c b/src/http/modules/ngx_http_mp4_module.c
+index 03175dea21..1cd017c274 100644
+--- a/src/http/modules/ngx_http_mp4_module.c
++++ b/src/http/modules/ngx_http_mp4_module.c
+@@ -3099,7 +3099,8 @@ static ngx_int_t
+ ngx_http_mp4_crop_stsc_data(ngx_http_mp4_file_t *mp4,
+ ngx_http_mp4_trak_t *trak, ngx_uint_t start)
+ {
+- uint32_t start_sample, chunk, samples, id, next_chunk, n,
++ uint64_t n;
++ uint32_t start_sample, chunk, samples, id, next_chunk,
+ prev_samples;
+ ngx_buf_t *data, *buf;
+ ngx_uint_t entries, target_chunk, chunk_samples;
+@@ -3160,7 +3161,7 @@ ngx_http_mp4_crop_stsc_data(ngx_http_mp4_file_t *mp4,
+ "samples:%uD, id:%uD",
+ start_sample, chunk, next_chunk - chunk, samples, id);
+
+- n = (next_chunk - chunk) * samples;
++ n = (uint64_t) (next_chunk - chunk) * samples;
+
+ if (start_sample < n) {
+ goto found;
+@@ -3182,7 +3183,7 @@ ngx_http_mp4_crop_stsc_data(ngx_http_mp4_file_t *mp4,
+ "sample:%uD, chunk:%uD, chunks:%uD, samples:%uD",
+ start_sample, chunk, next_chunk - chunk, samples);
+
+- n = (next_chunk - chunk) * samples;
++ n = (uint64_t) (next_chunk - chunk) * samples;
+
+ if (start_sample > n) {
+ ngx_log_error(NGX_LOG_ERR, mp4->file.log, 0,
diff --git a/meta-openembedded/meta-webserver/recipes-httpd/nginx/files/CVE-2025-23419.patch b/meta-openembedded/meta-webserver/recipes-httpd/nginx/files/CVE-2025-23419.patch
new file mode 100644
index 0000000000..e42664f11a
--- /dev/null
+++ b/meta-openembedded/meta-webserver/recipes-httpd/nginx/files/CVE-2025-23419.patch
@@ -0,0 +1,87 @@
+From bc23d3cdf98e855a5409d3584a241d4d773ab306 Mon Sep 17 00:00:00 2001
+From: Sergey Kandaurov <pluknet@nginx.com>
+Date: Wed, 22 Jan 2025 18:55:44 +0400
+Subject: [PATCH] SNI: added restriction for TLSv1.3 cross-SNI session
+ resumption.
+
+In OpenSSL, session resumption always happens in the default SSL context,
+prior to invoking the SNI callback. Further, unlike in TLSv1.2 and older
+protocols, SSL_get_servername() returns values received in the resumption
+handshake, which may be different from the value in the initial handshake.
+Notably, this makes the restriction added in b720f650b insufficient for
+sessions resumed with different SNI server name.
+
+Considering the example from b720f650b, previously, a client was able to
+request example.org by presenting a certificate for example.org, then to
+resume and request example.com.
+
+The fix is to reject handshakes resumed with a different server name, if
+verification of client certificates is enabled in a corresponding server
+configuration.
+
+CVE: CVE-2025-23419
+Upstream-Status: Backport [https://github.com/nginx/nginx/commit/13935cf9fdc3c8d8278c70716417d3b71c36140e]
+
+This patch is partially cherry picked from commit
+13935cf9fdc3c8d8278c70716417d3b71c36140e, the original patch had 2
+parts. One fixed problem in `http/ngx_http_request` module and the
+second fixed problem in `stream/ngx_stream_ssl_module` module. The fix
+for `stream/ngx_stream_ssl_module can't be aplied because, the 'stream
+virtual servers' funcionality was added later in this commit:
+https://github.com/nginx/nginx/commit/d21675228a0ba8d4331e05c60660228a5d3326de.
+Therefore only `http/ngx_http_request` part was backported.
+
+Signed-off-by: Changqing Li <changqing.li@windriver.com>
+
+---
+ src/http/ngx_http_request.c | 27 +++++++++++++++++++++++++--
+ 1 file changed, 25 insertions(+), 2 deletions(-)
+
+diff --git a/src/http/ngx_http_request.c b/src/http/ngx_http_request.c
+index 5e0340b..514c021 100644
+--- a/src/http/ngx_http_request.c
++++ b/src/http/ngx_http_request.c
+@@ -907,6 +907,31 @@ ngx_http_ssl_servername(ngx_ssl_conn_t *ssl_conn, int *ad, void *arg)
+ goto done;
+ }
+
++ sscf = ngx_http_get_module_srv_conf(cscf->ctx, ngx_http_ssl_module);
++
++#if (defined TLS1_3_VERSION \
++ && !defined LIBRESSL_VERSION_NUMBER && !defined OPENSSL_IS_BORINGSSL)
++
++ /*
++ * SSL_SESSION_get0_hostname() is only available in OpenSSL 1.1.1+,
++ * but servername being negotiated in every TLSv1.3 handshake
++ * is only returned in OpenSSL 1.1.1+ as well
++ */
++
++ if (sscf->verify) {
++ const char *hostname;
++
++ hostname = SSL_SESSION_get0_hostname(SSL_get0_session(ssl_conn));
++
++ if (hostname != NULL && ngx_strcmp(hostname, servername) != 0) {
++ c->ssl->handshake_rejected = 1;
++ *ad = SSL_AD_ACCESS_DENIED;
++ return SSL_TLSEXT_ERR_ALERT_FATAL;
++ }
++ }
++
++#endif
++
+ hc->ssl_servername = ngx_palloc(c->pool, sizeof(ngx_str_t));
+ if (hc->ssl_servername == NULL) {
+ goto error;
+@@ -920,8 +945,6 @@ ngx_http_ssl_servername(ngx_ssl_conn_t *ssl_conn, int *ad, void *arg)
+
+ ngx_set_connection_log(c, clcf->error_log);
+
+- sscf = ngx_http_get_module_srv_conf(hc->conf_ctx, ngx_http_ssl_module);
+-
+ c->ssl->buffer_size = sscf->buffer_size;
+
+ if (sscf->ssl.ctx) {
+--
+2.34.1
+
diff --git a/meta-openembedded/meta-webserver/recipes-httpd/nginx/files/CVE-2025-53859.patch b/meta-openembedded/meta-webserver/recipes-httpd/nginx/files/CVE-2025-53859.patch
new file mode 100755
index 0000000000..6f689938f4
--- /dev/null
+++ b/meta-openembedded/meta-webserver/recipes-httpd/nginx/files/CVE-2025-53859.patch
@@ -0,0 +1,131 @@
+CVE: CVE-2025-53859
+Upstream-Status: Backport [https://nginx.org/download/patch.2025.smtp.txt]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+
+diff --git a/src/mail/ngx_mail_handler.c b/src/mail/ngx_mail_handler.c
+index 1167df3fb..d3be7f3b3 100644
+--- a/src/mail/ngx_mail_handler.c
++++ b/src/mail/ngx_mail_handler.c
+@@ -523,7 +523,7 @@ ngx_mail_starttls_only(ngx_mail_session_t *s, ngx_connection_t *c)
+ ngx_int_t
+ ngx_mail_auth_plain(ngx_mail_session_t *s, ngx_connection_t *c, ngx_uint_t n)
+ {
+- u_char *p, *last;
++ u_char *p, *pos, *last;
+ ngx_str_t *arg, plain;
+
+ arg = s->args.elts;
+@@ -555,7 +555,7 @@ ngx_mail_auth_plain(ngx_mail_session_t *s, ngx_connection_t *c, ngx_uint_t n)
+ return NGX_MAIL_PARSE_INVALID_COMMAND;
+ }
+
+- s->login.data = p;
++ pos = p;
+
+ while (p < last && *p) { p++; }
+
+@@ -565,7 +565,8 @@ ngx_mail_auth_plain(ngx_mail_session_t *s, ngx_connection_t *c, ngx_uint_t n)
+ return NGX_MAIL_PARSE_INVALID_COMMAND;
+ }
+
+- s->login.len = p++ - s->login.data;
++ s->login.len = p++ - pos;
++ s->login.data = pos;
+
+ s->passwd.len = last - p;
+ s->passwd.data = p;
+@@ -583,24 +584,26 @@ ngx_int_t
+ ngx_mail_auth_login_username(ngx_mail_session_t *s, ngx_connection_t *c,
+ ngx_uint_t n)
+ {
+- ngx_str_t *arg;
++ ngx_str_t *arg, login;
+
+ arg = s->args.elts;
+
+ ngx_log_debug1(NGX_LOG_DEBUG_MAIL, c->log, 0,
+ "mail auth login username: \"%V\"", &arg[n]);
+
+- s->login.data = ngx_pnalloc(c->pool, ngx_base64_decoded_length(arg[n].len));
+- if (s->login.data == NULL) {
++ login.data = ngx_pnalloc(c->pool, ngx_base64_decoded_length(arg[n].len));
++ if (login.data == NULL) {
+ return NGX_ERROR;
+ }
+
+- if (ngx_decode_base64(&s->login, &arg[n]) != NGX_OK) {
++ if (ngx_decode_base64(&login, &arg[n]) != NGX_OK) {
+ ngx_log_error(NGX_LOG_INFO, c->log, 0,
+ "client sent invalid base64 encoding in AUTH LOGIN command");
+ return NGX_MAIL_PARSE_INVALID_COMMAND;
+ }
+
++ s->login = login;
++
+ ngx_log_debug1(NGX_LOG_DEBUG_MAIL, c->log, 0,
+ "mail auth login username: \"%V\"", &s->login);
+
+@@ -611,7 +614,7 @@ ngx_mail_auth_login_username(ngx_mail_session_t *s, ngx_connection_t *c,
+ ngx_int_t
+ ngx_mail_auth_login_password(ngx_mail_session_t *s, ngx_connection_t *c)
+ {
+- ngx_str_t *arg;
++ ngx_str_t *arg, passwd;
+
+ arg = s->args.elts;
+
+@@ -620,18 +623,19 @@ ngx_mail_auth_login_password(ngx_mail_session_t *s, ngx_connection_t *c)
+ "mail auth login password: \"%V\"", &arg[0]);
+ #endif
+
+- s->passwd.data = ngx_pnalloc(c->pool,
+- ngx_base64_decoded_length(arg[0].len));
+- if (s->passwd.data == NULL) {
++ passwd.data = ngx_pnalloc(c->pool, ngx_base64_decoded_length(arg[0].len));
++ if (passwd.data == NULL) {
+ return NGX_ERROR;
+ }
+
+- if (ngx_decode_base64(&s->passwd, &arg[0]) != NGX_OK) {
++ if (ngx_decode_base64(&passwd, &arg[0]) != NGX_OK) {
+ ngx_log_error(NGX_LOG_INFO, c->log, 0,
+ "client sent invalid base64 encoding in AUTH LOGIN command");
+ return NGX_MAIL_PARSE_INVALID_COMMAND;
+ }
+
++ s->passwd = passwd;
++
+ #if (NGX_DEBUG_MAIL_PASSWD)
+ ngx_log_debug1(NGX_LOG_DEBUG_MAIL, c->log, 0,
+ "mail auth login password: \"%V\"", &s->passwd);
+@@ -674,24 +678,26 @@ ngx_int_t
+ ngx_mail_auth_cram_md5(ngx_mail_session_t *s, ngx_connection_t *c)
+ {
+ u_char *p, *last;
+- ngx_str_t *arg;
++ ngx_str_t *arg, login;
+
+ arg = s->args.elts;
+
+ ngx_log_debug1(NGX_LOG_DEBUG_MAIL, c->log, 0,
+ "mail auth cram-md5: \"%V\"", &arg[0]);
+
+- s->login.data = ngx_pnalloc(c->pool, ngx_base64_decoded_length(arg[0].len));
+- if (s->login.data == NULL) {
++ login.data = ngx_pnalloc(c->pool, ngx_base64_decoded_length(arg[0].len));
++ if (login.data == NULL) {
+ return NGX_ERROR;
+ }
+
+- if (ngx_decode_base64(&s->login, &arg[0]) != NGX_OK) {
++ if (ngx_decode_base64(&login, &arg[0]) != NGX_OK) {
+ ngx_log_error(NGX_LOG_INFO, c->log, 0,
+ "client sent invalid base64 encoding in AUTH CRAM-MD5 command");
+ return NGX_MAIL_PARSE_INVALID_COMMAND;
+ }
+
++ s->login = login;
++
+ p = s->login.data;
+ last = p + s->login.len;
+
diff --git a/meta-openembedded/meta-webserver/recipes-httpd/nginx/nginx.inc b/meta-openembedded/meta-webserver/recipes-httpd/nginx/nginx.inc
index 83ae90c40c..945be05c6a 100644
--- a/meta-openembedded/meta-webserver/recipes-httpd/nginx/nginx.inc
+++ b/meta-openembedded/meta-webserver/recipes-httpd/nginx/nginx.inc
@@ -23,6 +23,9 @@ SRC_URI = " \
file://nginx.service \
file://nginx-fix-pidfile.patch \
file://0001-configure-libxslt-conf.patch \
+ file://CVE-2024-7347-1.patch \
+ file://CVE-2024-7347-2.patch \
+ file://CVE-2025-53859.patch \
"
inherit siteinfo update-rc.d useradd systemd
diff --git a/meta-openembedded/meta-webserver/recipes-httpd/nginx/nginx_1.24.0.bb b/meta-openembedded/meta-webserver/recipes-httpd/nginx/nginx_1.24.0.bb
index e5666f6fe6..ed18b6471d 100644
--- a/meta-openembedded/meta-webserver/recipes-httpd/nginx/nginx_1.24.0.bb
+++ b/meta-openembedded/meta-webserver/recipes-httpd/nginx/nginx_1.24.0.bb
@@ -2,7 +2,8 @@ require nginx.inc
LIC_FILES_CHKSUM = "file://LICENSE;md5=175abb631c799f54573dc481454c8632"
-SRC_URI:append = " file://CVE-2023-44487.patch"
+SRC_URI:append = " file://CVE-2023-44487.patch \
+ file://CVE-2025-23419.patch"
SRC_URI[sha256sum] = "77a2541637b92a621e3ee76776c8b7b40cf6d707e69ba53a940283e30ff2f55d"
diff --git a/meta-openembedded/meta-webserver/recipes-httpd/nginx/nginx_1.25.3.bb b/meta-openembedded/meta-webserver/recipes-httpd/nginx/nginx_1.25.4.bb
index d0371dd3cc..5ea2f5726e 100644
--- a/meta-openembedded/meta-webserver/recipes-httpd/nginx/nginx_1.25.3.bb
+++ b/meta-openembedded/meta-webserver/recipes-httpd/nginx/nginx_1.25.4.bb
@@ -4,7 +4,7 @@ require nginx.inc
# 1.25.x is the current mainline branches containing all new features
DEFAULT_PREFERENCE = "-1"
-LIC_FILES_CHKSUM = "file://LICENSE;md5=79ad2eb837299421c4435dedc8897b3d"
+LIC_FILES_CHKSUM = "file://LICENSE;md5=a6547d7e5628787ee2a9c5a3480eb628"
-SRC_URI[sha256sum] = "64c5b975ca287939e828303fa857d22f142b251f17808dfe41733512d9cded86"
+SRC_URI[sha256sum] = "760729901acbaa517996e681ee6ea259032985e37c2768beef80df3a877deed9"
diff --git a/meta-openembedded/meta-webserver/recipes-php/phpmyadmin/phpmyadmin_5.2.1.bb b/meta-openembedded/meta-webserver/recipes-php/phpmyadmin/phpmyadmin_5.2.2.bb
index 34b710e885..c98ce4585b 100644
--- a/meta-openembedded/meta-webserver/recipes-php/phpmyadmin/phpmyadmin_5.2.1.bb
+++ b/meta-openembedded/meta-webserver/recipes-php/phpmyadmin/phpmyadmin_5.2.2.bb
@@ -3,7 +3,7 @@ HOMEPAGE = "http://www.phpmyadmin.net"
# Main code is GPLv2, vendor/tecnickcom/tcpdf is under LGPLv3, js/jquery is under MIT
LICENSE = "GPL-2.0-only & LGPL-3.0-only & MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=b234ee4d69f5fce4486a80fdaf4a4263 \
- file://vendor/tecnickcom/tcpdf/LICENSE.TXT;md5=d0ff7e060074497f34481cf574e8a581 \
+ file://vendor/tecnickcom/tcpdf/LICENSE.TXT;md5=72bda492a00ee8c4121987c6afdefc07 \
file://js/vendor/jquery/MIT-LICENSE.txt;md5=de877aa6d744cc160ff41c26a8e4811f \
"
@@ -11,7 +11,7 @@ SRC_URI = "https://files.phpmyadmin.net/phpMyAdmin/${PV}/phpMyAdmin-${PV}-all-la
file://apache.conf \
"
-SRC_URI[sha256sum] = "373f9599dfbd96d6fe75316d5dad189e68c305f297edf42377db9dd6b41b2557"
+SRC_URI[sha256sum] = "f881819a3b11e653b0212afaf0cc105db85c767715cb3f5852670f7fc36c9669"
UPSTREAM_CHECK_URI = "https://www.phpmyadmin.net/downloads/"
UPSTREAM_CHECK_REGEX = "phpMyAdmin-(?P<pver>\d+(\.\d+)+)-all-languages.tar.xz"
diff --git a/meta-openembedded/meta-webserver/recipes-support/fcgi/fcgi/CVE-2025-23016.patch b/meta-openembedded/meta-webserver/recipes-support/fcgi/fcgi/CVE-2025-23016.patch
new file mode 100644
index 0000000000..b763d7651c
--- /dev/null
+++ b/meta-openembedded/meta-webserver/recipes-support/fcgi/fcgi/CVE-2025-23016.patch
@@ -0,0 +1,40 @@
+From b0eabcaf4d4f371514891a52115c746815c2ff15 Mon Sep 17 00:00:00 2001
+From: Pycatchown <39068868+Pycatchown@users.noreply.github.com>
+Date: Tue, 8 Apr 2025 17:39:30 +0200
+Subject: [PATCH] Update fcgiapp.c
+
+Fixing an integer overflow (CVE-2025-23016)
+
+CVE: CVE-2025-23016
+Upstream-Status: Backport [https://github.com/FastCGI-Archives/fcgi2/commit/b0eabcaf4d4f371514891a52115c746815c2ff15]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ libfcgi/fcgiapp.c | 8 ++++++++
+ 1 file changed, 8 insertions(+)
+
+diff --git a/libfcgi/fcgiapp.c b/libfcgi/fcgiapp.c
+index 4ffe318..99c3630 100644
+--- a/libfcgi/fcgiapp.c
++++ b/libfcgi/fcgiapp.c
+@@ -1173,6 +1173,10 @@ static int ReadParams(Params *paramsPtr, FCGX_Stream *stream)
+ }
+ nameLen = ((nameLen & 0x7f) << 24) + (lenBuff[0] << 16)
+ + (lenBuff[1] << 8) + lenBuff[2];
++ if (nameLen >= INT_MAX) {
++ SetError(stream, FCGX_PARAMS_ERROR);
++ return -1;
++ }
+ }
+ if((valueLen = FCGX_GetChar(stream)) == EOF) {
+ SetError(stream, FCGX_PARAMS_ERROR);
+@@ -1185,6 +1189,10 @@ static int ReadParams(Params *paramsPtr, FCGX_Stream *stream)
+ }
+ valueLen = ((valueLen & 0x7f) << 24) + (lenBuff[0] << 16)
+ + (lenBuff[1] << 8) + lenBuff[2];
++ if (valueLen >= INT_MAX) {
++ SetError(stream, FCGX_PARAMS_ERROR);
++ return -1;
++ }
+ }
+ /*
+ * nameLen and valueLen are now valid; read the name and value
diff --git a/meta-openembedded/meta-webserver/recipes-support/fcgi/fcgi_git.bb b/meta-openembedded/meta-webserver/recipes-support/fcgi/fcgi_git.bb
index 61ef6073e0..d327d435d5 100644
--- a/meta-openembedded/meta-webserver/recipes-support/fcgi/fcgi_git.bb
+++ b/meta-openembedded/meta-webserver/recipes-support/fcgi/fcgi_git.bb
@@ -7,6 +7,7 @@ SRCREV = "382aa2b0d53a87c27f2f647dfaf670375ba0b85f"
PV = "2.4.2"
SRC_URI = "git://github.com/FastCGI-Archives/fcgi2.git;protocol=https;branch=master \
+ file://CVE-2025-23016.patch \
"
S = "${WORKDIR}/git"
diff --git a/meta-openembedded/meta-xfce/recipes-art/xfce-dusk-gtk3/xfce-dusk-gtk3_1.3.bb b/meta-openembedded/meta-xfce/recipes-art/xfce-dusk-gtk3/xfce-dusk-gtk3_1.3.bb
index 4cbdb4e083..a6a1790c1a 100644
--- a/meta-openembedded/meta-xfce/recipes-art/xfce-dusk-gtk3/xfce-dusk-gtk3_1.3.bb
+++ b/meta-openembedded/meta-xfce/recipes-art/xfce-dusk-gtk3/xfce-dusk-gtk3_1.3.bb
@@ -4,7 +4,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=8f0e2cd40e05189ec81232da84bd6e1a"
inherit allarch
-SRC_URI = "http://sources.openembedded.org/141404-xfce_dusk_gtk3-1_3.tar.gz;subdir=${BPN}-${PV}"
+SRC_URI = "https://downloads.yoctoproject.org/mirror/sources/141404-xfce_dusk_gtk3-1_3.tar.gz;subdir=${BPN}-${PV}"
SRC_URI[md5sum] = "b3ad37ad8173b14ec090e60a80e65d8f"
SRC_URI[sha256sum] = "bfa8a88607d1a1da5bd0b9e4e075767c54400a3c5a0fae88b619ed71532f30b4"
diff --git a/meta-openembedded/meta-xfce/recipes-multimedia/xfce4-mpc-plugin/xfce4-mpc-plugin_0.5.3.bb b/meta-openembedded/meta-xfce/recipes-multimedia/xfce4-mpc-plugin/xfce4-mpc-plugin_0.5.3.bb
index cd868c243b..2d4cdfa498 100644
--- a/meta-openembedded/meta-xfce/recipes-multimedia/xfce4-mpc-plugin/xfce4-mpc-plugin_0.5.3.bb
+++ b/meta-openembedded/meta-xfce/recipes-multimedia/xfce4-mpc-plugin/xfce4-mpc-plugin_0.5.3.bb
@@ -1,5 +1,5 @@
SUMMARY = "Simple client plugin for Music Player Daemon"
-HOMEPAGE = "https://goodies.xfce.org/projects/panel-plugins/xfce4-mpc-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-mpc-plugin/start"
SECTION = "x11/application"
LICENSE = "0BSD"
LIC_FILES_CHKSUM = "file://COPYING;md5=3604d987e6dfdfc672c754d08953b0e0"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/battery/xfce4-battery-plugin_1.1.5.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/battery/xfce4-battery-plugin_1.1.5.bb
index ce119bb6da..16ebebf235 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/battery/xfce4-battery-plugin_1.1.5.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/battery/xfce4-battery-plugin_1.1.5.bb
@@ -1,5 +1,5 @@
SUMMARY = "A battery monitor panel plugin for Xfce4, compatible with APM and ACP"
-HOMEPAGE = "https://goodies.xfce.org/projects/panel-plugins/xfce4-battery-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-battery-plugin/start"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/calculator/xfce4-calculator-plugin_0.7.2.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/calculator/xfce4-calculator-plugin_0.7.2.bb
index 0c464930e1..d5ce9ad361 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/calculator/xfce4-calculator-plugin_0.7.2.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/calculator/xfce4-calculator-plugin_0.7.2.bb
@@ -1,5 +1,5 @@
SUMMARY = "A calculator plugin for the Xfce panel"
-HOMEPAGE = "http://goodies.xfce.org/projects/panel-plugins/xfce4-calculator-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-calculator-plugin/start"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=909430f63fddd63f120ba29e8979f65c"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/clipman/xfce4-clipman-plugin_1.6.2.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/clipman/xfce4-clipman-plugin_1.6.2.bb
index 39a8f2edfe..59fb8578c1 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/clipman/xfce4-clipman-plugin_1.6.2.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/clipman/xfce4-clipman-plugin_1.6.2.bb
@@ -1,5 +1,5 @@
SUMMARY = "Clipman is a clipboard manager for Xfce"
-HOMEPAGE = "http://goodies.xfce.org/projects/panel-plugins/xfce4-clipman-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-clipman-plugin/start"
SECTION = "x11/application"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=751419260aa954499f7abaabaa882bbe"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/cpufreq/xfce4-cpufreq-plugin_1.2.8.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/cpufreq/xfce4-cpufreq-plugin_1.2.8.bb
index 8ddf48d6ef..1a19f488c0 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/cpufreq/xfce4-cpufreq-plugin_1.2.8.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/cpufreq/xfce4-cpufreq-plugin_1.2.8.bb
@@ -1,5 +1,5 @@
SUMMARY = "Panel plugin to display frequency of all cpus"
-HOMEPAGE = "http://goodies.xfce.org/projects/panel-plugins/xfce4-cpufreq-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-cpufreq-plugin/start"
LICENSE = "GPL-2.0-or-later"
LIC_FILES_CHKSUM = "file://COPYING;md5=1f6f1c0be32491a0c8d2915607a28f36"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/cpugraph/xfce4-cpugraph-plugin_1.2.8.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/cpugraph/xfce4-cpugraph-plugin_1.2.8.bb
index 8e58175615..b240eaad5e 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/cpugraph/xfce4-cpugraph-plugin_1.2.8.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/cpugraph/xfce4-cpugraph-plugin_1.2.8.bb
@@ -1,5 +1,5 @@
SUMMARY = "Panel plugin with graphical representation of the cpu frequency"
-HOMEPAGE = "https://goodies.xfce.org/projects/panel-plugins/xfce4-cpugraph-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-cpugraph-plugin/start"
LICENSE = "GPL-2.0-or-later"
LIC_FILES_CHKSUM = "file://COPYING;md5=415654f59d8fa70fe4eac2c3f86c8f5e"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/datetime/xfce4-datetime-plugin_0.8.3.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/datetime/xfce4-datetime-plugin_0.8.3.bb
index f292a6deaf..f025edd4c5 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/datetime/xfce4-datetime-plugin_0.8.3.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/datetime/xfce4-datetime-plugin_0.8.3.bb
@@ -1,5 +1,5 @@
SUMMARY = "Panel plugin displaying date and time and a calendar when left-clicked"
-HOMEPAGE = "https://goodies.xfce.org/projects/panel-plugins/xfce4-datetime-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-datetime-plugin/start"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=59530bdf33659b29e73d4adb9f9f6552"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/diskperf/xfce4-diskperf-plugin_2.7.0.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/diskperf/xfce4-diskperf-plugin_2.7.0.bb
index 25a57f3233..583aa9a006 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/diskperf/xfce4-diskperf-plugin_2.7.0.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/diskperf/xfce4-diskperf-plugin_2.7.0.bb
@@ -1,5 +1,5 @@
SUMMARY = "Panel plugin displaying instant disk/partition performance"
-HOMEPAGE = "https://goodies.xfce.org/projects/panel-plugins/xfce4-diskperf-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-diskperf-plugin/start"
LICENSE = "BSD-2-Clause"
LIC_FILES_CHKSUM = "file://COPYING;md5=d3e627798d6a60bece47aa8b3532e1f1"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/eyes/xfce4-eyes-plugin_4.6.0.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/eyes/xfce4-eyes-plugin_4.6.0.bb
index 0c796534ab..6eaac70a09 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/eyes/xfce4-eyes-plugin_4.6.0.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/eyes/xfce4-eyes-plugin_4.6.0.bb
@@ -1,5 +1,5 @@
SUMMARY = "Panel plugin with graphical representation of the cpu frequency"
-HOMEPAGE = "http://goodies.xfce.org/projects/panel-plugins/xfce4-eyes-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-eyes-plugin/start"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/fsguard/xfce4-fsguard-plugin_1.1.3.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/fsguard/xfce4-fsguard-plugin_1.1.3.bb
index 380d2e19e3..de8d6786c2 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/fsguard/xfce4-fsguard-plugin_1.1.3.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/fsguard/xfce4-fsguard-plugin_1.1.3.bb
@@ -1,5 +1,5 @@
DESCRIPTION = "The FSGuard panel plugin checks free space on a chosen mount point frequently and displays a message when a limit is reached"
-HOMEPAGE = "https://goodies.xfce.org/projects/panel-plugins/xfce4-fsguard-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-fsguard-plugin/start"
LICENSE = "BSD-2-Clause"
LIC_FILES_CHKSUM = "file://COPYING;md5=3434d79d62df09abf5f78bb76d6cd21b"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/genmon/xfce4-genmon-plugin_4.2.0.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/genmon/xfce4-genmon-plugin_4.2.0.bb
index 31ad5e7ced..6558a1492d 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/genmon/xfce4-genmon-plugin_4.2.0.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/genmon/xfce4-genmon-plugin_4.2.0.bb
@@ -1,5 +1,5 @@
DESCRIPTION = "This plugin cyclically spawns the indicated script/program, captures its output (stdout) and displays the resulting string into the panel."
-HOMEPAGE = "http://goodies.xfce.org/projects/panel-plugins/xfce4-genmon-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-genmon-plugin/start"
LICENSE = "LGPL-2.1-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=4b54a1fd55a448865a0b32d41598759d"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/mailwatch/xfce4-mailwatch-plugin_1.3.1.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/mailwatch/xfce4-mailwatch-plugin_1.3.1.bb
index 6ea260765f..d6b367c0da 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/mailwatch/xfce4-mailwatch-plugin_1.3.1.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/mailwatch/xfce4-mailwatch-plugin_1.3.1.bb
@@ -1,5 +1,5 @@
SUMMARY = "Multi-protocol, multi-mailbox mail watcher for the Xfce4 panel"
-HOMEPAGE = "http://goodies.xfce.org/projects/panel-plugins/xfce4-mailwatch-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-mailwatch-plugin/start"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/mount/xfce4-mount-plugin_1.1.5.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/mount/xfce4-mount-plugin_1.1.5.bb
index 3a6baf21f9..f11e41f9bd 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/mount/xfce4-mount-plugin_1.1.5.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/mount/xfce4-mount-plugin_1.1.5.bb
@@ -1,5 +1,5 @@
SUMMARY = "Mount/umount utility for the xfce panel"
-HOMEPAGE = "http://goodies.xfce.org/projects/panel-plugins/xfce4-mount-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-mount-plugin/start"
SECTION = "x11/application"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=94d55d512a9ba36caa9b7df079bae19f"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/netload/xfce4-netload-plugin_1.4.1.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/netload/xfce4-netload-plugin_1.4.1.bb
index c30f17a7d4..6ed4747565 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/netload/xfce4-netload-plugin_1.4.1.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/netload/xfce4-netload-plugin_1.4.1.bb
@@ -1,5 +1,5 @@
SUMMARY = "Panel plugin displaying current load of the network interfaces"
-HOMEPAGE = "https://goodies.xfce.org/projects/panel-plugins/xfce4-netload-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-netload-plugin/start"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=2b6065ae7d3696cdad6869dd8627a9fe"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/notes/xfce4-notes-plugin_1.10.0.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/notes/xfce4-notes-plugin_1.10.0.bb
index 8c9768b1e3..3895cb9bce 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/notes/xfce4-notes-plugin_1.10.0.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/notes/xfce4-notes-plugin_1.10.0.bb
@@ -1,5 +1,5 @@
SUMMARY = "Notes plugin for the Xfce Panel"
-HOMEPAGE = "http://goodies.xfce.org/projects/panel-plugins/xfce4-notes-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-notes-plugin/start"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/places/xfce4-places-plugin_1.8.3.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/places/xfce4-places-plugin_1.8.3.bb
index 6400e0d3e4..753dcae91e 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/places/xfce4-places-plugin_1.8.3.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/places/xfce4-places-plugin_1.8.3.bb
@@ -1,6 +1,6 @@
SUMMARY = "Menu for quick access to folders, documents and removable media"
DESCRIPTION = "Panel plugin displaying menu with quick access to folders, documents and removable media"
-HOMEPAGE = "https://goodies.xfce.org/projects/panel-plugins/xfce4-places-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-places-plugin/start"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=b6952d9a47fc2ad0f315510e1290455f"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/sensors/xfce4-sensors-plugin_1.4.4.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/sensors/xfce4-sensors-plugin_1.4.4.bb
index eb1165c578..ba3c83a131 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/sensors/xfce4-sensors-plugin_1.4.4.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/sensors/xfce4-sensors-plugin_1.4.4.bb
@@ -1,5 +1,5 @@
SUMMARY = "Sensors plugin for the Xfce Panel"
-HOMEPAGE = "http://goodies.xfce.org/projects/panel-plugins/xfce4-sensors-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-sensors-plugin/start"
LICENSE = "GPL-2.0-or-later"
LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/smartbookmark/xfce4-smartbookmark-plugin_0.5.2.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/smartbookmark/xfce4-smartbookmark-plugin_0.5.2.bb
index fdec598190..68e9cbd3a3 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/smartbookmark/xfce4-smartbookmark-plugin_0.5.2.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/smartbookmark/xfce4-smartbookmark-plugin_0.5.2.bb
@@ -1,5 +1,5 @@
SUMMARY = "Panel plugin allowing to send requests directly to browser"
-HOMEPAGE = "https://goodies.xfce.org/projects/panel-plugins/xfce4-smartbookmark-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-smartbookmark-plugin/start"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/systemload/xfce4-systemload-plugin_1.3.2.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/systemload/xfce4-systemload-plugin_1.3.2.bb
index e7a3e9936e..0b07bda32b 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/systemload/xfce4-systemload-plugin_1.3.2.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/systemload/xfce4-systemload-plugin_1.3.2.bb
@@ -1,5 +1,5 @@
DESCRIPTION = "Panel plugin displaying current CPU load, the memory in use, the swap space and the system uptime"
-HOMEPAGE = "https://goodies.xfce.org/projects/panel-plugins/xfce4-systemload-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-systemload-plugin/start"
LICENSE = "BSD-2-Clause"
LIC_FILES_CHKSUM = "file://COPYING;md5=9acb172a93ff6c43cce2aff790a8aef8"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/time-out/xfce4-time-out-plugin_1.1.3.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/time-out/xfce4-time-out-plugin_1.1.3.bb
index 9fa287a1ca..1622cd4d2b 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/time-out/xfce4-time-out-plugin_1.1.3.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/time-out/xfce4-time-out-plugin_1.1.3.bb
@@ -1,5 +1,5 @@
SUMMARY = "This plugin makes it possible to take periodical breaks"
-HOMEPAGE = "https://goodies.xfce.org/projects/panel-plugins/xfce4-time-out-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-time-out-plugin/start"
SECTION = "x11/application"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=59530bdf33659b29e73d4adb9f9f6552"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/timer/xfce4-timer-plugin_1.7.2.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/timer/xfce4-timer-plugin_1.7.2.bb
index 33b60438d1..0f164b79c5 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/timer/xfce4-timer-plugin_1.7.2.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/timer/xfce4-timer-plugin_1.7.2.bb
@@ -1,6 +1,6 @@
SUMMARY = "XFCE panel plugin to generate alarm messages"
DESCRIPTION = "This is a simple plugin that lets the user run an alarm at a specified time or at the end of a specified countdown period"
-HOMEPAGE = "http://goodies.xfce.org/projects/panel-plugins/xfce4-timer-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-timer-plugin/start"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=f1c52159bdaebd029cb11927cbe709e4"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/verve/xfce4-verve-plugin_2.0.3.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/verve/xfce4-verve-plugin_2.0.3.bb
index 9dcaae8ceb..844d8caf17 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/verve/xfce4-verve-plugin_2.0.3.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/verve/xfce4-verve-plugin_2.0.3.bb
@@ -1,5 +1,5 @@
SUMMARY = "Verve panel plugin is a comfortable command line plugin for the Xfce panel"
-HOMEPAGE = "http://goodies.xfce.org/projects/panel-plugins/xfce4-verve-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-verve-plugin/start"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/wavelan/xfce4-wavelan-plugin_0.6.3.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/wavelan/xfce4-wavelan-plugin_0.6.3.bb
index 530f52425a..64e7ea6a18 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/wavelan/xfce4-wavelan-plugin_0.6.3.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/wavelan/xfce4-wavelan-plugin_0.6.3.bb
@@ -1,5 +1,5 @@
SUMMARY = "Panel plugin displaying stats from a wireless lan interface"
-HOMEPAGE = "https://goodies.xfce.org/projects/panel-plugins/xfce4-wavelan-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-wavelan-plugin/start"
LICENSE = "BSD-2-Clause"
LIC_FILES_CHKSUM = "file://COPYING;md5=e1e5872df9c5cf1a23f16493d9104920"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/weather/xfce4-weather-plugin_0.11.1.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/weather/xfce4-weather-plugin_0.11.1.bb
index 858bd5459b..87b826954c 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/weather/xfce4-weather-plugin_0.11.1.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/weather/xfce4-weather-plugin_0.11.1.bb
@@ -1,5 +1,5 @@
SUMMARY = "Panel plugin to display current temperature and weather condition"
-HOMEPAGE = "http://goodies.xfce.org/projects/panel-plugins/xfce4-weather-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-weather-plugin/start"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
diff --git a/meta-openembedded/meta-xfce/recipes-panel-plugins/xkb/xfce4-xkb-plugin_0.8.2.bb b/meta-openembedded/meta-xfce/recipes-panel-plugins/xkb/xfce4-xkb-plugin_0.8.2.bb
index 3d935a3d71..0e482af353 100644
--- a/meta-openembedded/meta-xfce/recipes-panel-plugins/xkb/xfce4-xkb-plugin_0.8.2.bb
+++ b/meta-openembedded/meta-xfce/recipes-panel-plugins/xkb/xfce4-xkb-plugin_0.8.2.bb
@@ -1,5 +1,5 @@
SUMMARY = "XKB layout switching panel plug-in for the Xfce desktop environment"
-HOMEPAGE = "http://goodies.xfce.org/projects/panel-plugins/xfce4-xkb-plugin"
+HOMEPAGE = "https://docs.xfce.org/panel-plugins/xfce4-xkb-plugin/start"
SECTION = "x11/application"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=496f09f084b0f7e6f02f769a84490c6b"
diff --git a/meta-openembedded/meta-xfce/recipes-thunar-plugins/archive/thunar-archive-plugin_0.5.2.bb b/meta-openembedded/meta-xfce/recipes-thunar-plugins/archive/thunar-archive-plugin_0.5.2.bb
index 91b3efa83e..0ba997b544 100644
--- a/meta-openembedded/meta-xfce/recipes-thunar-plugins/archive/thunar-archive-plugin_0.5.2.bb
+++ b/meta-openembedded/meta-xfce/recipes-thunar-plugins/archive/thunar-archive-plugin_0.5.2.bb
@@ -1,5 +1,5 @@
DESCRIPTION = "Thunar Archive Plugin allows you to create and extract archive files using file context menus in Thunar"
-HOMEPAGE = "http://goodies.xfce.org/projects/thunar-plugins/thunar-archive-plugin"
+HOMEPAGE = "https://docs.xfce.org/xfce/thunar/archive"
LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=4cf66a4984120007c9881cc871cf49db"
diff --git a/meta-openembedded/meta-xfce/recipes-xfce/xfce4-power-manager/xfce4-power-manager_4.18.1.bb b/meta-openembedded/meta-xfce/recipes-xfce/xfce4-power-manager/xfce4-power-manager_4.18.1.bb
index f7f72356d8..cfb7a26ab1 100644
--- a/meta-openembedded/meta-xfce/recipes-xfce/xfce4-power-manager/xfce4-power-manager_4.18.1.bb
+++ b/meta-openembedded/meta-xfce/recipes-xfce/xfce4-power-manager/xfce4-power-manager_4.18.1.bb
@@ -1,5 +1,5 @@
SUMMARY = "Power manager for the Xfce desktop environment"
-HOMEPAGE = "http://goodies.xfce.org/projects/applications/xfce4-power-manager"
+HOMEPAGE = "https://docs.xfce.org/xfce/xfce4-power-manager/start"
SECTION = "x11"
LICENSE = "GPL-2.0-or-later"