summaryrefslogtreecommitdiff
path: root/poky/meta/recipes-devtools/python
diff options
context:
space:
mode:
authorAndrew Geissler <geissonator@yahoo.com>2025-11-03 19:09:31 +0300
committerAndrew Geissler <geissonator@yahoo.com>2025-11-03 22:31:57 +0300
commit6cb7f76381dbeb50bbf963f9192344f02d985637 (patch)
treee194737ad2b6c562f463cc7a22116ef4aebd1232 /poky/meta/recipes-devtools/python
parent1f52643312f6f67537eb27bef9156e8b8bc66040 (diff)
downloadopenbmc-scarthgap.tar.xz
subtree updates (scarthgap 11/3/2025)scarthgap
poky: ca27724b44..c4a4df3e72: Adam Blank (3): kernel-dev/common.rst: fix the in-tree defconfig description ref-manual/variables.rst: fix the description of KBUILD_DEFCONFIG ref-manual/variables.rst: fix the description of STAGING_DIR Aditya Tayade (1): e2fsprogs: removed 'sed -u' option Adrian Freihofer (15): kernel-fitimage: fix intentation kernel-fitimage: fix external dtb check devtool: modify support debug-builds devtool: ide-sdk sort cmake preset devtool: ide-sdk recommend DEBUG_BUILD oe-selftest: devtool ide-sdk use modify debug-build devtool: ide-sdk remove the plugin from eSDK installer uboot-config: fix devtool modify with kernel-fitimage sdk-manual: extensible.rst: devtool ide-sdk improve sdk-manual: extensible.rst: update devtool ide-sdk ref-manual: kernel-fitimage.bbclass does not use SPL_SIGN_KEYNAME llvm: update from 18.1.6 to 18.1.8 llvm: fix build with gcc-15 expect: Revert "expect-native: fix do_compile failure with gcc-14" expect: fix native build with GCC 15 Alban Bedel (1): bind: Fix build with the `httpstats` package config enabled Aleksandar Nikolic (12): cve-check: Introduce CVE_CHECK_MANIFEST_JSON_SUFFIX install-buildtools: remove md5 checksum validation install-buildtools: fix "test installation" step install-buildtools: update base-url, release and installer version ref-manual: introduce CVE_CHECK_REPORT_PATCHED variable scripts/install-buildtools: Update to 5.0.5 scripts/install-buildtools: Update to 5.0.6 scripts/install-buildtools: Update to 5.0.7 scripts/install-buildtools: Update to 5.0.9 scripts/install-buildtools: Update to 5.0.10 scripts/install-buildtools: Update to 5.0.11 scripts/install-buildtools: Update to 5.0.12 Alessio Cascone (1): tzcode-native: Fix compiler setting from 2023d version Alexander Kanavin (29): mesa: remove obsolete 0001-meson.build-check-for-all-linux-host_os-combinations.patch kexec-tools: submit 0003-kexec-ARM-Fix-add_buffer_phys_virt-align-issue.patch upstream vorbis: mark patch as Inactive-Upstream grub: mark grub-module-explicitly-keeps-symbole-.module_license.patch as a workaround perl: submit the rest of determinism.patch upstream iptables: submit 0001-configure-Add-option-to-enable-disable-libnfnetlink.patch upstream xserver-xorg: upgrade 21.1.12 -> 21.1.13 mobile-broadband-provider-info: upgrade 20230416 -> 20240407 python3: submit deterministic_imports.patch upstream as a ticket glib-networking: submit eagain.patch upstream glslang: mark 0001-generate-glslang-pkg-config.patch as Inappropriate tcp-wrappers: mark all patches as inactive-upstream automake: mark new_rt_path_for_test-driver.patch as Inappropriate settings-daemon: submit addsoundkeys.patch upstream and update to a revision that has it dpkg: mark patches adding custom non-debian architectures as inappropriate for upstream libacpi: mark patches as inactive-upstream apr: drop 0007-explicitly-link-libapr-against-phtread-to-make-gold-.patch pulseaudio, desktop-file-utils: correct freedesktop.org -> www.freedesktop.org SRC_URI sysvinit: take release tarballs from github package_rpm: use zstd's default compression level package_rpm: restrict rpm to 4 threads rust: add reproducibility patch to eliminate host leakage rust: build the default set of tools rust: use rust-snapshot binaries only in rust-native rust: correctly link rust-snapshot into build/stage0 pkg-config-native: pick additional search paths from $EXTRA_NATIVE_PKGCONFIG_PATH selftest/rust: correctly form the PATH environment variable perlcross: update 1.5.2 -> 1.6 mtools: upgrade 4.0.43 -> 4.0.44 Alexis Cellier (1): systemd: add libpcre2 as RRECOMMENDS if pcre2 is enabled Alexis Lothoré (3): oeqa/utils/postactions: transfer whole archive over ssh instead of doing individual copies oeqa/postactions: fix exception handling oeqa/ssh: allow to retrieve raw, unformatted ouput Alon Bar-Lev (1): module.bbclass: add KBUILD_EXTRA_SYMBOLS to install Alper Ak (2): ref-manual/variables.rst: document INHIBIT_DEFAULT_RUST_DEPS ref-manual/variables.rst: document INHIBIT_UPDATERCD_BBCLASS Anders Heimer (1): libpam: mark CVE-2025-6018 as not applicable Andrew Fernandes (1): gtk+: add missing libdrm dependency Andrew Kreimer (1): manuals: remove repeated word Antonin Godard (77): ref-manual: add missing CVE_CHECK manifest variables ref-manual: add missing TESTIMAGE_FAILED_QA_ARTIFACTS ref-manual: add missing EXTERNAL_KERNEL_DEVICETREE variable ref-manual: add missing OPKGBUILDCMD variable ref-manual: merge patch-status-* to patch-status ref-manual: structure.rst: document missing tmp/ dirs overview-manual: concepts: add details on package splitting ref-manual: faq: add q&a on class appends ref-manual: release-process: update releases.svg ref-manual: release-process: refresh the current LTS releases ref-manual: release-process: update releases.svg with month after "Current" ref-manual: release-process: add a reference to the doc's release ref-manual: devtool-reference: refresh example outputs ref-manual: devtool-reference: document missing commands conf.py: rename :cve: role to :cve_nist: doc: Makefile: remove inkscape, replace by rsvg-convert doc: Makefile: add support for xelatex doc: add a download page for epub and pdf sphinx-static/switchers.js.in: do not refer to URL_ROOT anymore conf.py: add a bitbake_git extlink dev-manual: document how to provide confs from layer.conf dev-manual: bblock: use warning block instead of attention standards.md: add a section on admonitions ref-manual: classes: fix bin_package description Gather dependencies in poky.yaml.in poky.yaml.in: add missing locales dependency poky.yaml.in: replace inkscape dependency by librsvg2-bin system-requirements: add fedora 39 to supported distros system-requirements: update list of supported distros system-requirements.rst: add dependencies for pdf builds Update the documentation for SRCPV poky.conf: add new tested distros ref-manual/qa-checks: remove patch-status-core/patch-status-noncore contributor-guide/submit-changes.rst: suggest to remove the git signature ref-manual/devtool-reference: add warning note on deploy-target and shared objects SSTATE_MIRRORS/SOURCE_MIRROR_URL: add instructions for mirror authentication ref-manual/packages: move ptest section to the test-manual ref-manual: move runtime-testing section to the test-manual Update autobuilder URLs to valkyrie test-manual/reproducible-builds: fix reproducible links test-manual/ptest: link to common framework ptest classes dev-manual/building: document the initramfs-framework recipe ref-manual/faq: add q&a on systemd as default contributor-guide/submit-changes: add policy on AI generated code Add favicon for the documentation html overview-manual/concepts: remove PR from the build dir list ref-manual/variables.rst: WATCHDOG_TIMEOUT: fix recipe name ref-manual/variables.rst: document autotools class related variables documentation/conf.py: define a manpage url ref-manual/variables.rst: add manpage links for toolchain variables ref-manual/variables.rst: add missing documentation for BUILD_* variables ref-manual/variables.rst: document missing SDK_*_ARCH variables ref-manual/variables.rst: document HOST_*_ARCH variables ref-manual/variables.rst: HOST_CC_ARCH: fix wrong SDK reference ref-manual/variables.rst: improve the PKGV documentation poky.yaml: introduce DISTRO_LATEST_TAG Fix dead links that use the DISTRO macro dev-manual/sbom.rst: fix wrong build outputs test-manual/intro: remove Buildbot version used ref-manual/release-process: update releases.svg overview-manual/concepts.rst: fix sayhello hardcoded bindir ref-manual/system-requirements.rst: update supported distributions ref-manual/variables.rst: document the FIT_CONF_PREFIX variable ref-manual/variables.rst: document SPL_DTB_BINARY ref-manual/classes.rst: document the testexport class dev-manual/security-subjects.rst: update mailing lists test-manual/yocto-project-compatible.rst: fix a typo ref-manual/structure: document the auto.conf file ref-manual/variables.rst: document UNINATIVE_URL/CHECKSUM ref-manual/classes.rst: extend the uninative class documentation ref-manual/classes,variables: document the CCACHE_DISABLE variable ref-manual/variables.rst: document the REQUIRED_MACHINE_FEATURES variable ref-manual/variables.rst: document the REQUIRED_COMBINED_FEATURES variable ref-manual/variables.rst: document the REQUIRED_IMAGE_FEATURES variable ref-manual/variables.rst: document the USE_NLS variable ref-manual/classes.rst: gettext: extend the documentation of the class ref-manual/classes.rst: document the relative_symlinks class Anuj Mittal (1): sqlite3: upgrade 3.45.1 -> 3.45.3 Archana Polampalli (51): less: fix CVE-2024-32487 ofono: fix CVE-2023-2794 ffmpeg: fix CVE-2023-49502 ffmpeg: fix CVE-2024-31578 ffmpeg: fix CVE-2024-31582 ffmpeg: fix CVE-2023-50008 ffmpeg: fix CVE-2024-32230 qemu: fix CVE-2024-7409 ffmpeg: fix CVE-2023-49501 ffmpeg: fix CVE-2024-28661 ffmpeg: fix CVE-2023-50007 ffmpeg: fix CVE-2023-49528 ffmpeg: fix CVE-2024-7055 ffmpeg: fix CVE-2024-35366 ffmpeg: fix CVE-2024-35367 ffmpeg: fix CVE-2024-35368 rsync: fix CVE-2024-12084 rsync: fix CVE-2024-12085 rsync: fix CVE-2024-12086 rsync: fix CVE-2024-12087 rsync: fix CVE-2024-12088 rsync: fix CVE-2024-12747 ffmpeg: fix CVE-2024-35365 ffmpeg: fix CVE-2024-36613 ffmpeg: fix CVE-2024-36616 ffmpeg: fix CVE-2024-36617 ffmpeg: fix CVE-2024-36618 ffmpeg: fix CVE-2024-36619 ffmpeg: fix CVE-2024-35369 gstreamer1.0-rtsp-server: fix CVE-2024-44331 ffmpeg: fix CVE-2025-25473 ffmpeg: fix CVE-2025-25471 ffmpeg: fix CVE-2025-22921 ffmpeg: fix CVE-2025-0518 ffmpeg: Correct the CVE ID to fix CVE-2025-22919 openssh: fix CVE-2025-26465 go: fix CVE-2025-22870 ghostscript: upgrade 10.04.0 -> 10.05.0 perlcross: 1.6 -> 1.6.2 perl: upgrade 5.38.2 -> 5.38.4 xwayland: fix CVE-2025-49175 xwayland: fix CVE-2025-49176 xwayland: fix CVE-2025-49177 xwayland: fix CVE-2025-49178 xwayland: fix CVE-2025-49179 xwayland: fix CVE-2025-49180 gdk-pixbuf: fix CVE-2025-7345 go: fix CVE-2025-4674 ffmpeg: upgrade 6.1.2 -> 6.1.3 ffmpeg: fix CVE-2025-1594 go: fix CVE-2025-47906 Ashish Sharma (11): bind: Upgrade 9.18.25 -> 9.18.28 ruby: Backport fix for CVE-2024-27282 ruby: Fix CVE-2025-27219 binutils: Fix CVE-2025-1176 binutils: patch CVE-2025-1178 & CVE-2024-57360 binutils: patch CVE-2025-1181 binutils: patch CVE-2025-1182 libsoup: patch CVE-2025-46420 libsoup-2.4: Fix CVE-2025-46420 libsoup: patch CVE-2025-4476 screen: patch CVE-2025-46805 AshishKumar Mishra (2): systemd: backport fix for handle USE_NLS from master p11-kit: backport fix for handle USE_NLS from master Barne Carstensen (1): test-manual: update runtime-testing Exporting Tests section Bartosz Golaszewski (1): linux-firmware: add a package for ath12k firmware Benjamin Szőke (2): archiver.bbclass: Fix work-shared checking for kernel recipes mc: fix source URL Bin Lan (1): lttng-ust: backport patch to fix cmake-multiple-shared-libraries build error Bruce Ashfield (54): linux-yocto/6.6: update to v6.6.36 linux-yocto/6.6: update to v6.6.38 linux-yocto/6.6: update to v6.6.40 linux-yocto/6.6: update to v6.6.43 kernel-devsrc: remove 64 bit vdso cmd files linux-yocto/6.6: update to v6.6.44 linux-yocto/6.6: update to v6.6.45 linux-yocto/6.6: fix genericarm64 config warning linux-yocto/6.6: update to v6.6.47 linux-yocto/6.6: update to v6.6.49 linux-yocto/6.6: update to v6.6.50 linux-yocto/6.6: update to v6.6.52 linux-yocto/6.6: update to v6.6.54 linux-yocto/6.6: update to v6.6.56 linux-yocto/6.6: update to v6.6.58 linux-yocto/6.6: genericarm64.cfg: enable CONFIG_DMA_CMA linux-yocto/6.6: update to v6.6.59 linux-yocto/6.6: update to v6.6.60 linux-yocto/6.6: update to v6.6.62 linux-yocto/6.6: bsp/genericarm64: disable ARM64_SME linux-yocto/6.6: update to v6.6.63 linux-yocto/6.6: update to v6.6.64 linux-yocto/6.6: update to v6.6.66 linux-yocto/6.6: update to v6.6.69 linux-yocto/6.6: update to v6.6.75 linux-yocto/6.6: update to v6.6.77 linux-yocto/6.6: update to v6.6.78 linux-yocto/6.6: update to v6.6.80 linux-yocto/6.6: update to v6.6.82 linux-yocto/6.6: update to v6.6.83 linux-yocto/6.6: update to v6.6.84 linux-yocto/6.6: update to v6.6.85 linux-yocto/6.6: fix beaglebone ethernet linux-yocto/6.6: update to v6.6.86 linux-yocto/6.6: update to v6.6.87 linux-yocto/6.6: update to v6.6.88 linux-yocto/6.6: update to v6.6.89 linux-yocto/6.6: update to v6.6.91 linux-yocto/6.6: update to v6.6.92 linux-yocto/6.6: update to v6.6.93 linux-yocto/6.6: update to v6.6.94 linux-yocto/6.6: update to v6.6.96 linux-yocto/6.6: update to v6.6.98 linux-yocto/6.6: update to v6.6.99 linux-yocto/6.6: update to v6.6.100 linux-yocto/6.6: update to v6.6.101 linux-yocto/6.6: update to v6.6.102 linux-yocto/6.6: update to v6.6.103 linux-yocto/6.6: update to v6.6.106 linux-yocto/6.6: update to v6.6.107 linux-yocto/6.6: update to v6.6.108 linux-yocto/6.6: update to v6.6.109 linux-yocto/6.6: update to v6.6.110 linux-yocto/6.6: update to v6.6.111 Carlos Alberto Lopez Perez (1): icu: Backport patch to fix build issues with long paths (>512 chars) Carlos Sánchez de La Lama (1): ref-manual: clarify KCONFIG_MODE default behaviour Catalin Popescu (1): Revert "bluez5: remove configuration files from install task" Changqing Li (48): apt-native: don't let dpkg overwrite files by default apt: runtime error: filename too long (tmpdir length) webkitgtk: fix do_configure error on beaglebone-yocto webkitgtk: fix do_compile errors on beaglebone-yocto vulkan-samples: fix do_compile error when -Og enabled multilib.conf: remove appending to PKG_CONFIG_PATH gettext: fix a parallel build issue pixman: fixing inline failure with -Og rt-tests: rt_bmark.py: fix TypeError curl: correct the PACKAGECONFIG for native/nativesdk libpng: update SRC_URI expect-native: fix do_compile failure with gcc-14 libcap-ng: update SRC_URI sysvinit: backport patch for fixing one issue of pidof acpica: fix CVE-2024-24856 libsoup: fix CVE-2024-52530, CVE-2024-52531 rxvt-unicode.inc: disable the terminfo installation by setting TIC to : sanity.bbclass: skip check_userns for non-local uid systemd: enable create-log-dirs babeltrace: extend to nativesdk babeltrace2: extend to nativesdk patch.py: set commituser and commitemail for addNote initscripts: add function log_success_msg/log_failure_msg/log_warning_msg buildtools-tarball: move setting of envvars to respective envfile buildtools-tarball: add envvars into BB_ENV_PASSTHROUGH_ADDITIONS buildtools-tarball: Make buildtools respects host CA certificates libsoup: fix CVE-2025-32908 libsoup: fix CVE-2025-32907 libsoup-2.4: fix CVE-2025-32907 libsoup-2.4: fix do_compile failure libsoup-2.4: fix CVE-2025-32053 libsoup: fix CVE-2025-32053 libsoup-2.4: fix CVE-2025-32052 libsoup: fix CVE-2025-32052 libsoup: fix CVE-2025-32051 libsoup-2.4: fix CVE-2025-32050 libsoup: fix CVE-2025-32050 libsoup-2.4: fix CVE-2025-46421 libsoup: fix CVE-2025-46421 libsoup-2.4: fix CVE-2025-4948 libsoup: fix CVE-2025-4948 libsoup-2.4: fix CVE-2025-4476 libsoup-2.4: fix CVE-2025-2784 libsoup: fix CVE-2025-2784 icu: fix CVE-2025-5222 libsoup-2.4: refresh CVE-2025-4969.patch libsoup-2.4: fix CVE-2025-4945 libsoup: fix CVE-2025-4945 Chen Qi (8): libnl: change HOMEPAGE qemu: back port patches to fix riscv64 build failure toolchain-shar-extract.sh: exit when post-relocate-setup.sh fails libgfortran: fix buildpath QA issue bitbake: data_smart.py: remove unnecessary ? from __expand_var_regexp__ bitbake: data_smart.py: simple clean up bitbake: data_smart.py: clear expand_cache in _setvar_update_overridevars coreutils: fix CVE-2025-5278 Chris Laplante (6): bitbake: persist_data: close connection in SQLTable __exit__ bitbake: fetch2: use persist_data context managers bitbake: ui/knotty: print log paths for failed tasks in summary bitbake: ui/knotty: respect NO_COLOR & check for tty; rename print_hyperlink => format_hyperlink bitbake: cooker: Make cooker 'skiplist' per-multiconfig/mc util-linux: use ${B} instead of ${WORKDIR}/build, to fix building under devtool Christian Taedcke (1): iptables: fix memory corruption when parsing nft rules Christos Gavros (2): ref-manual/variables.rst: document the IMAGE_ROOTFS_MAXSIZE variable ref-manual/variables.rst: document the INITRAMFS_MAXSIZE variable Claus Stovgaard (1): lib/oe/package-manager: skip processing installed-pkgs with empty globs Clayton Casciato (1): uboot-sign: fix concat_dtb arguments Colin McAllister (2): udev-extraconf: Add collect flag to mount busybox: Fix cut with "-s" flag Colin Pinnell McAllister (1): ffmpeg: fix CVE-2025-1373 Daniel Semkowicz (2): os-release: Fix VERSION_CODENAME in case it is empty gstreamer1.0-plugins-bad: fix buffer allocation fail for v4l2codecs Daniel Turull (4): package: export debugsources in PKGDESTWORK as json spdx: add option to include only compiled sources xz: ignore CVE-2024-47611 libxml2: ignore CVE-2025-8732 David Nyström (3): openssh: fix CVE-2025-61985 openssh: fix CVE-2025-61984 lz4: fix CVE-2025-62813 Deepak Rathore (1): default-distrovars.inc: Fix CONNECTIVITY_CHECK_URIS redirect issue Deepesh Varatharajan (13): binutils: stable 2.42 branch updates glibc: stable 2.39 branch updates. binutils: stable 2.42 branch update binutils: Fix CVE-2025-0840 glibc: stable 2.39 branch updates binutils: stable 2.42 branch updates binutils: Fix CVE-2025-5245 binutils: Fix CVE-2025-5244 gcc: Upgrade to GCC 13.4 binutils: stable 2.42 branch updates binutils: Fix CVE-2025-7545 glibc: stable 2.39 branch updates glibc: stable 2.39 branch updates Deepthi Hemraj (5): binutils: stable 2.42 branch updates glibc: stable 2.39 branch updates rust-llvm: Fix CVE-2024-0151 binutils: stable 2.42 branch update glibc: stable 2.39 branch updates Denys Dmytriyenko (3): weston: upgrade 13.0.0 -> 13.0.1 gcc: unify cleanup of include-fixed, apply to cross-canadian nativesdk-libtool: sanitize the script, remove buildpaths Divya Chellam (16): libpam: fix CVE-2024-10041 libxml2: Upgrade 2.12.8 -> 2.12.9 wget: fix CVE-2024-10524 vim: Upgrade 9.1.0764 -> 9.1.1043 vim: Upgrade 9.1.1043 -> 9.1.1115 ruby: fix CVE-2025-27220 ruby: fix CVE-2025-27221 screen: fix CVE-2025-46802 screen: fix CVE-2025-46804 libarchive: fix CVE-2025-5914 libarchive: fix CVE-2025-5915 libarchive: fix CVE-2025-5916 libarchive: fix CVE-2025-5917 libarchive: fix CVE-2025-5918 wpa-supplicant: fix CVE-2022-37660 vim: upgrade 9.1.1652 -> 9.1.1683 Divyanshu Rathore (1): ffmpeg: upgrade 6.1.1 -> 6.1.2 Dixit Parmar (1): ref-manual: document KERNEL_SPLIT_MODULES variable Dmitry Baryshkov (1): xserver-xorg: fix CVE-2023-5574 status Emil Kronborg (3): insane.bbclass: remove skipping of cross-compiled packages insane.bbclass: fix HOST_ variable names insane.bbclass: remove leftover variables and comment Enrico Jörns (6): wic: engine.py: use raw string for escape sequence wic: bootimg-efi: fix error handling bitbake: bitbake-diffsigs: fix handling when finding only a single sigfile ref-manual/variables.rst: update ROOT_HOME documentation conf.py: tweak SearchEnglish to be hyphen-friendly conf.py: improve SearchEnglish to handle terms with dots Erik Lindsten (1): overview-manual/yp-intro.rst: fix broken link to article Esben Haabendal (3): pulseaudio: fix webrtc audio depdency files: Amend overlayfs unit descriptions with path information files: overlayfs-create-dirs: Improve mount unit dependency Etienne Cordonnier (6): oeqa/runtime: fix regression in minidebuginfo test oeqa/runtime: make minidebuginfo test work with coreutils oeqa/runtime: fix race-condition in minidebuginfo test python3-setuptools-scm: respect GIT_CEILING_DIRECTORIES ref-manual/variables.rst: document SSTATE_SKIP_CREATION bitbake: gcp.py: remove slow calls to gsutil stat Fabio Berton (2): ccache.conf: Add include_file_ctime to sloppiness linux-libc-headers: Fix invalid conversion in cn_proc.h Florian Kreutzer (1): dropbear: backport fix for concurrent channel open/close Gassner, Tobias.ext (1): rootfs: Ensure run-postinsts is not uninstalled for read-only-rootfs-delayed-postinsts Gauthier HADERER (1): populate_sdk_ext.bclass: make sure OECORE_NATIVE_SYSROOT is exported. Guocai He (2): tcf-agent: correct the SRC_URI minicom: correct the SRC_URI Guénaël Muller (1): ref-manual: use standardized method accross both ubuntu and debian for locale install Guðni Már Gilbert (15): pam: Fix for CVE-2024-22365 python3-attrs: drop python3-ctypes from RDEPENDS bluez5: remove redundant patch for MAX_INPUT shared-mime-info: drop itstool-native from DEPENDS libpam: drop cracklib from DEPENDS systemd: drop intltool-native from DEPENDS systemd-boot: drop intltool-native from DEPENDS python3-poetry-core: drop python3-six from RDEPENDS dnf: drop python3-iniparse from DEPENDS and RDEPENDS python3: upgrade 3.12.6 -> 3.12.7 python3: upgrade 3.12.7 -> 3.12.8 systemd: upgrade 255.13 -> 255.17 systemd: upgrade 255.17 -> 255.18 bluez5: add missing tools to noinst-tools package systemd: upgrade 255.18 -> 255.21 Gyorgy Sarvari (1): conf/bitbake.conf: use gnu mirror instead of main server Haixiao Yan (2): glibc: Add single-threaded fast path to rand() buildtools-tarball: fix unbound variable issues under 'set -u' Harish Sadineni (7): binutils: Add missing perl modules to RDEPENDS for nativesdk variant rust-target-config: Fix TARGET_C_INT_WIDTH with correct size rust: fix for rust multilib sdk configuration rust: remove redundant cargo config file oeqa/sdk/context: fix for gtk3 test failure during do_testsdk binutils: Fix CVE-2025-1179 binutils: set CVE_STATUS for CVE-2025-1180 Hiago De Franco (2): weston: backport patch to allow neatvnc < v0.9.0 bluez5: backport patch to fix address type when loading keys Hitendra Prajapati (24): ghostscript: upgrade 10.02.1 -> 10.03.1 ruby: fix CVE-2024-27281 vte: fix CVE-2024-37535 curl: fix CVE-2024-8096 webkitgtk: upgrade 2.44.1 -> 2.44.3 cups: Backport fix for CVE-2024-47175 libarchive: fix CVE-2024-48957 & CVE-2024-48958 libsoup: fix CVE-2024-52532 ghostscript: upgrade 10.03.1 -> 10.04.0 libsndfile: fix CVE-2024-50612 ofono: Fix multiple CVEs libcap: fix CVE-2025-1390 elfutils: Fix multiple CVEs go: fix CVE-2025-22871 libsoup-3.4.4: Fix CVE-2025-4969 libsoup-2.4: Fix CVE-2025-4969 libxml2: fix CVE-2025-6021 libxml2: fix CVE-2025-49794 & CVE-2025-49796 libpam: fix CVE-2025-6020 gstreamer1.0-plugins-base: fix CVE-2025-47808 gstreamer1.0-plugins-base: fix CVE-2025-47806 gstreamer1.0-plugins-good: fix multiple CVEs gstreamer1.0-plugins-base: fix CVE-2025-47807 grub2: mark CVE-2024-2312 as not applicable Hongxu Jia (10): ovmf: fix CVE-2024-38796 ovmf: fix CVE-2024-1298 u-boot: fix CVE-2024-57254 u-boot: fix CVE-2024-57255 u-boot: fix CVE-2024-57256 u-boot: fix CVE-2024-57257 u-boot: fix CVE-2024-57258 u-boot: fix CVE-2024-57259 rpm: keep leading `/' from sed operation u-boot: fix CVE-2024-42040 Igor Opaniuk (1): wic: bootimg-efi: Support + symbol in filenames Jaeyoon Jung (2): makedevs: Fix issue when rootdir of / is given makedevs: Fix matching uid/gid Jagadeesh Krishnanjanappa (1): tune-cortexa32: set tune feature as armv8a Jan Vermaete (1): sdk: The main in the C example should return an int Jeroen Hofstee (2): bluez5: make media control a PACKAGECONFIG option bluez5: backport a patch to fix btmgmt -i Jiaying Song (9): liba52: fix do_fetch error enchant2: fix do_fetch error libxml-parser-perl: fix do_fetch error python3-zipp: fix CVE-2024-5569 subversion: fix CVE-2024-46901 boost: fix do_fetch error binutils: File name too long causing failure to open temporary head file in dlltool python3-requests: upgrade 2.32.3 -> 2.32.4 ruby-ptest : some ptest fixes Jinfeng Wang (3): tzdata&tzcode-native: upgrade 2024a -> 2024b mtools: upgrade 4.0.48 -> 4.0.49 systemtap: Fix task_work_cancel build Joao Marcos Costa (1): ref-manual/variables.rst: expand IMAGE_OVERHEAD_FACTOR glossary entry Joe Slater (1): oe-debuginfod: add option for data storage Joerg Schmidt (1): bitbake: bblayers/query: Fix using "removeprefix" string method Johannes Schneider (1): ppp: Revert lock path to /var/lock Jon Mason (4): oeqa/runtime/ssh: add retry logic and sleeps to allow for slower systems oeqa/runtime/ssh: check for all errors at the end oeqa/runtime/ssh: increase the number of attempts openssh: add backported header file include Jonas Gorski (1): rootfs-postcommands.bbclass: make opkg status reproducible Jookia (1): populate_sdk_ext.bbclass: Fix undefined variable error Jose Quaresma (7): go: upgrade 1.22.4 -> 1.22.5 oeqa/runtime/scp: requires openssh-sftp-server openssh: drop rejected patch fixed in 8.6p1 release openssh: systemd sd-notify patch was rejected upstream openssh: systemd notification was implemented upstream go: upgrade 1.22.5 -> 1.22.6 bitbake: bitbake: doc/user-manual: Update the BB_HASHSERVE_UPSTREAM Joshua Watt (3): bitbake: asyncrpc: Use client timeout for websocket open timeout bitbake: Remove custom exception backtrace formatting bitbake: Use a "fork" multiprocessing context João Marcos Costa (1): variables.rst: fix LAYERDEPENDS description Julien Stephan (5): README: add instruction to run Vale on a subset documentation: Makefile: add SPHINXLINTDOCS to specify subset to sphinx-lint styles: vocabularies: Yocto: add sstate ref-manual: variables: add SIGGEN_LOCKEDSIGS* variables dev-manual: add bblock documentation Jörg Sommer (5): classes/kernel: No symlink in postinst without KERNEL_IMAGETYPE_SYMLINK doc/features: remove duplicate word in distribution feature ext2 doc/features: describe distribution feature pni-name ptest-runner: Update 2.4.4 -> 2.4.5 runqemu: Fix detection of -serial parameter Kai Kang (3): multilib.bbclass: replace deprecated e.data with d cmake-qemu.bbclass: fix if criterion glibc: fix fortran header file conflict for arm Khem Raj (26): linux-yocto: Enable team net driver systemd.bbclass: Clarify error message grub,grub-efi: Remove -mfpmath=sse on x86 python3: Treat UID/GID overflow as failure gawk: Remove References to /usr/local/bin/gawk busybox: CVE-2023-42364 and CVE-2023-42365 fixes busybox: Add fix for CVE-2023-42366 gcc: Fix spurious '/' in GLIBC_DYNAMIC_LINKER on microblaze gnupg: Document CVE-2022-3219 and mark wontfix openssh: Mark CVE-2023-51767 as wont-fix libpcre2: Update base uri PhilipHazel -> PCRE2Project python3: Drop empty patch qemu: Do not define sched_attr with glibc >= 2.41 e2fsprogs: Fix build failure with gcc 15 parted: Fix build with GCC 15 bash: Stick to C17 std ncurses: Pin to C17 standard unzip: Fix build with GCC-15 m4: Stick to C17 standard gmp: Fix build with GCC15/C23 gmp: Fix build with older gcc versions gdbm: Use C11 standard unifdef: Don't use C23 constexpr keyword libtirpc: Fix build with gcc-15/C23 cpio: Pin to use C17 std expect: Fix build with GCC 15 Kirill Yatsenko (1): iptables: fix save/restore symlinks with libnftnl PACKAGECONFIG enabled Konrad Weihmann (3): runqemu: keep generating tap devices testimage: fallback for empty IMAGE_LINK_NAME testexport: fallback for empty IMAGE_LINK_NAME Kyungjik Min (1): pulseaudio: Add audio group explicitly Lee Chee Yang (24): migration-notes: add release notes for 5.0.1 migration-guides: add release notes for 4.0.19 migration-guides: add release notes for 5.0.2 migration-guide: add release notes for 4.0.20 migration-guides: add release notes for 5.0.3 migration-guide: add release notes for 4.0.21 migration-guides: add release notes for 5.0.4 migration-guide: add release notes for 4.0.22 migration-guides: add release notes for 5.0.5 migration-guides: add release notes for 4.0.23 migration-guides: add release notes for 5.0.6 migration-guides: add release notes for 4.0.24 migration-guides: add release notes for 5.0.7 migration-guides: add release notes for 4.0.25 migration-guides: add release notes for 5.0.8 migration-guides: add release notes for 4.0.26 migration-guides: add release notes for 5.0.9 migration-guides: add release notes for 4.0.27 migration-guide: add release notes for 5.0.10 migration-guides: add release notes for 4.0.28 migration-guides: add release notes for 5.0.11 migration-guides: add release notes for 4.0.29 migration-guides: add release notes for 5.0.12 migration-guides: add release notes for 4.0.30 Libo Chen (1): runqemu: fix special characters bug Louis Rannou (1): image_qa: fix error handling Macpaul Lin (1): linux-firmware: upgrade 20240312 -> 20240909 Madhu Marri (1): qemu 8.2.7: ignore CVE-2023-1386 Makarios Christakis (1): icu: Adjust ICU_DATA_DIR path on big endian targets Marco Cavallini (1): dev-manual/start.rst: added missing command in Optimize your VHDX file using DiskPart Marek Vasut (3): u-boot: kernel-fitimage: Fix dependency loop if UBOOT_SIGN_ENABLE and UBOOT_ENV enabled base-files: Drop /bin/sh dependency u-boot: kernel-fitimage: Restore FIT_SIGN_INDIVIDUAL="1" behavior Mark Hatle (9): package.py: Fix static debuginfo split package.py: Fix static library processing selftest-hardlink: Add additional test cases create-spdx-*: Support multilibs via SPDX_MULTILIB_SSTATE_ARCHS oeqa sdk cases: Skip SDK test cases when TCLIBC is newlib create-sdpx-2.2.bbclass: Switch from exists to isfile checking debugsrc populate_sdk_ext: write_local_conf add shutil import cve-update-nvd2-native: Handle BB_NO_NETWORK and missing db bitbake: bitbake: runqueue: Verify mcdepends are valid Markus Volk (3): libadwaita: update 1.5.0 -> 1.5.1 gcc: add a backport patch to fix an issue with tzdata 2024b ninja: fix build with python 3.13 Marta Rybczynska (1): vulnerabilities/classes: remove references to cve-check text format Martin Jansa (22): selftest: add Upstream-Status to .patch files libgfortran.inc: fix nativesdk-libgfortran dependencies populate_sdk_base: inherit nopackages meta-world-pkgdata: Inherit nopackages python3-lxml=v5.0.2 mc: set ac_cv_path_ZIP to avoid buildpaths QA issues libpam: re-add missing libgen include cairo: fix build with gcc-15 on host bash: use -std=gnu17 also for native CFLAGS cmake: fix build with gcc-15 on host git: fix build with gcc-15 on host pkgconfig: fix build with gcc-15 libgpg-error: fix build with gcc-15 rust-llvm: fix build with gcc-15 elfutils: fix build with gcc-15 binutils: fix build with gcc-15 dbus-glib: fix build with gcc-15 bitbake: bitbake: Bump version to 2.8.1 license.py: avoid deprecated ast.Str sanity.conf: Update minimum bitbake version to 2.8.1 lib/oe/utils: use multiprocessing from bb flex: fix build with gcc-15 on host Matthias Pritschet (1): ref-manual: fix typo and move SYSROOT_DIRS example Matthias Schiffer (1): curl: only set CA bundle in target build Michael Haener (1): oeqa/runtime/ping: don't bother trying to ping localhost Michael Halstead (4): yocto-uninative: Update to 4.6 for glibc 2.40 yocto-uninative: Update to 4.7 for glibc 2.41 yocto-uninative: Update to 4.8 for GCC 15.1 yocto-uninative: Update to 4.9 for glibc 2.42 Michael Opdenacker (5): maintainers.inc: update self e-mail address doc: Makefile: publish pdf and epub versions too dev-manual: fix styling of references to bmaptool dev-manual/bmaptool.rst: correct command for bmaptool-native dev-manual/bmaptool.rst: simplify and fix instructions Michal Seben (1): timedated: wait for jobs before SetNTP response Mikko Rapeli (1): ovmf-native: remove .pyc files from install Mingli Yu (1): llvm: Enable libllvm for native build Moritz Haase (2): meta: Enable '-o pipefail' for the SDK installer cmake: Correctly handle cost data of tests with arbitrary chars in name NeilBrown (1): nfs-utils: don't use signals to shut down nfs server. Nguyen Dat Tho (1): libatomic-ops: Update GITHUB_BASE_URI Nikhil R (1): cmake: Add PACKAGECONFIG option for debugger support Niko Mauno (15): dnf/mesa: Fix missing leading whitespace with ':append' libyaml: Fix warning regarding unpatched CVE systemd: Mitigate /var/log type mismatch issue systemd: Mitigate /var/tmp type mismatch issue image_types.bbclass: Use --force also with lz4,lzop util-linux: Add PACKAGECONFIG option to mitigate rootfs remount error iw: Fix LICENSE dejagnu: Fix LICENSE unzip: Fix LICENSE zip: Fix LICENSE tiff: Fix LICENSE gcr: Fix LICENSE python3-maturin: Fix cross compilation issue for armv7l, mips64, ppc cve-check.bbclass: Mitigate symlink related error cve-check.bbclass: Fix symlink handling also for text files Nitin Wankhade (1): examples: genl: fix wrong attribute size Oleksandr Hnatiuk (2): icu: remove host references in nativesdk to fix reproducibility gcc: remove paths to sysroot from configargs.h and checksum-options for gcc-cross-canadian Patrick Wicki (1): gpgme: move gpgme-tool to own sub-package Paul Barker (2): meta-ide-support: Mark recipe as MACHINE-specific dev-manual, test-manual: Update autobuilder output links Paul Gerber (1): uboot-sign: fix counters in do_uboot_assemble_fitimage Pavel Zhukov (1): package_rpm: Check if file exists before open() Pedro Ferreira (3): buildhistory: Fix intermittent package file list creation buildhistory: Restoring files from preserve list rust-common.bbclass: soft assignment for RUSTLIB path Peter Kjellerstedt (1): image.bbclass: Drop support for ImageQAFailed exceptions in image_qa Peter Marko (144): flac: fix buildpaths warnings cargo: remove True option to getVar calls ncurses: switch to new mirror busybox: Patch CVE-2021-42380 busybox: Patch CVE-2023-42363 libstd-rs,rust-cross-canadian: set CVE_PRODUCT to rust curl: Patch CVE-2024-6197 glibc: cleanup old cve status qemu: set cve status for CVE-2023-6683 libmnl: explicitly disable doxygen libyaml: ignore CVE-2024-35326 libyaml: Ignore CVE-2024-35325 curl: Patch CVE-2024-7264 python3: Upgrade 3.12.5 -> 3.12.6 wpa-supplicant: Ignore CVE-2024-5290 wpa-supplicant: Patch CVE-2024-3596 wpa-supplicant: Patch security advisory 2024-2 rust: ignore CVE-2024-43402 openssl: patch CVE-2024-9143 cve-check: add support for cvss v4.0 go: upgrade 1.22.6 -> 1.22.7 go: upgrade 1.22.7 -> 1.22.8 dropbear: backport patch for CVE-2023-48795 curl: patch CVE-2024-9681 gstreamer1.0: set status for CVE-2024-0444 expat: upgrade 2.6.3 -> 2.6.4 builder: set CVE_PRODUCT qemu: set CVE-2024-6505 to fixed gstreamer1.0-plugins-good: fix several CVEs gstreamer1.0-plugins-base: patch CVE-2024-47538 gstreamer1.0-plugins-base: patch CVE-2024-47607 gstreamer1.0-plugins-base: patch CVE-2024-47615 gstreamer1.0-plugins-good: patch CVE-2024-47613 gstreamer1.0-plugins-good: patch several CVEs gstreamer1.0-plugins-base: patch CVE-2024-47541 gstreamer1.0-plugins-base: patch CVE-2024-47542 gstreamer1.0-plugins-good: patch CVE-2024-47599 gstreamer1.0-plugins-base: patch CVE-2024-47600 gstreamer1.0-plugins-good: patch CVE-2024-47606 gstreamer1.0-plugins-good: patch CVE-2024-47606 gstreamer1.0-plugins-good: patch CVE-2024-47774 gstreamer1.0-plugins-good: patch several CVEs gstreamer1.0-plugins-base: patch CVE-2024-47835 gstreamer1.0: ignore CVEs fixed in plugins recipes socat: patch CVE-2024-54661 ofono: patch CVE-2024-7540, CVE-2024-7541, CVE-2024-7542 ofono: patch CVE-2023-4232 ofono: patch CVE-2023-4235 openssl: patch CVE-2024-13176 go: upgrade 1.22.8 -> 1.22.9 go: upgrade 1.22.9 -> 1.22.10 go: upgrade 1.22.10 -> 1.22.11 glibc: stable 2.39 branch updates python3: upgrade 3.12.8 -> 3.12.9 go: upgrade 1.22.11 -> 1.22.12 cmake: apply parallel build settings to ptest tasks subversion: ignore CVE-2024-45720 gnutls: patch CVE-2024-12243 openssl: upgrade 3.2.3 -> 3.2.4 libxml2: upgrade 2.12.9 -> 2.12.10 grub: drop obsolete CVE statuses grub: backport strlcpy function grup: patch CVE-2024-45781 grub: patch CVE-2024-45782 and CVE-2024-56737 grub: patch CVE-2024-45780 grub: patch CVE-2024-45783 grub: patch CVE-2025-0624 grub: patch CVE-2024-45774 grub: patch CVE-2024-45775 grub: patch CVE-2025-0622 grub: patch CVE-2024-45776 grub: patch CVE-2024-45777 grub: patch CVE-2025-0690 grub: patch CVE-2025-1118 grub: patch CVE-2024-45778 and CVE-2024-45779 grub: patch CVE-2025-0677, CVE-2025-0684, CVE-2025-0685, CVE-2025-0686 and CVE-2025-0689 grub: patch CVE-2025-0678 and CVE-2025-1125 libarchive: patch CVE-2025-1632 and CVE-2025-25724 xserver-xorg: mark CVEs fixed in 21.1.16 as fixed cve-update-nvd2-native: handle missing vulnStatus expat: patch CVE-2024-8176 freetype: follow-up patch for CVE-2025-27363 ofono: patch CVE-2024-7537 cve-update-nvd2-native: add workaround for json5 style list xz: upgrade 5.4.6 -> 5.4.7 xz: patch CVE-2025-31115 libarchive: upgrade 3.7.4 -> 3.7.9 sqlite3: patch CVE-2025-3277 sqlite3: patch CVE-2025-29088 ppp: patch CVE-2024-58250 libxml2: patch CVE-2025-32414 libxml2: patch CVE-2025-32415 glib-2.0: patch CVE-2025-3360 Revert "cve-update-nvd2-native: Tweak to work better with NFS DL_DIR" sqlite3: mark CVE-2025-29087 as patched python3: upgrade 3.12.9 -> 3.12.11 testimage: get real os-release file net-tools: patch CVE-2025-46836 go: set status of CVE-2024-3566 glibc: stable 2.39 branch updates python3: update CVE product busybox: apply patch for CVE-2023-39810 iputils: patch CVE-2025-48964 orc: set CVE_PRODUCT openssl: CVE-2024-41996 openssl: patch CVE-2025-27587 gnutls: patch CVE-2025-32989 gnutls: patch read buffer overrun in the "pre_shared_key" extension gnutls: patch reject zero-length version in certificate request gnutls: patch CVE-2025-32988 gnutls: patch CVE-2025-32990 gnutls: patch CVE-2025-6395 ncurses: patch CVE-2025-6141 libxml2: patch CVE-2025-6170 glibc: fix CVE-2025-8058 python3: patch CVE-2025-8194 go: ignore CVE-2025-0913 dropbear: patch CVE-2025-47203 glib-2.0: ignore CVE-2025-4056 qemu: set status of CVE-2024-7730 to fixed go-binary-native: ignore CVE-2025-0913 glib-2.0: patch CVE-2025-7039 glib-2.0: patch CVE-2025-6052 dpkg: patch CVE-2025-6297 libarchive: patch regression of patch for CVE-2025-5918 vim: upgrade 9.1.1198 -> 9.1.1652 sudo: remove devtool FIXME comment busybox: patch CVE-2025-46394 gstreamer1.0: ignore CVEs fixed in plugins gstreamer1.0: ignore CVE-2025-2759 ghostscript: patch CVE-2025-59798 ghostscript: patch CVE-2025-59799 ghostscript: patch CVE-2025-59800 expat: follow-up for CVE-2024-8176 tiff: ignore 5 CVEs ffmpeg: ignore 8 CVEs fixed in 6.1.1 and 6.1.3 releases openssl: upgrade 3.2.4 -> 3.2.6 qemu: patch CVE-2024-8354 binutils: patch CVE-2025-11082 binutils: patch CVE-2025-11083 gnupg: mark CVE-2025-30258 as patched python3: upgrade 3.12.11 -> 3.12.12 vulnerabilities: update nvdcve file name expat: patch CVE-2025-59375 Philip Lorenz (3): cmake: Fix sporadic issues when determining compiler internals cve-check: Add missing call to exit_if_errors shared-mime-info: Handle USE_NLS Poonam Jadhav (2): curl: ignore CVE-2025-0725 libpng: Add ptest Praveen Kumar (7): connman :fix CVE-2025-32743 connman :fix CVE-2025-32366 glib-2.0: fix CVE-2025-4373 go: fix CVE-2025-4673 sudo: upgrade 1.9.15p5 -> 1.9.17p1 go: fix CVE-2025-47907 bind: upgrade 9.18.33 -> 9.18.41 Preeti Sachan (1): ltp: backport patch to fix compilation error for x86_64 Priyal Doshi (2): tzdata/tzcode-native: upgrade 2024b -> 2025a tzdata/tzcode-native: upgrade 2025a -> 2025b Purushottam Choudhary (1): virglrenderer: Add patch to fix -int-conversion build issue Quentin Schulz (14): mmc-utils: fix URL weston-init: fix weston not starting when xwayland is enabled docs: README: specify how to contribute instead of pointing at another file docs: conf.py: silence SyntaxWarning on js_splitter_code ref-manual: classes: reword to clarify that native/nativesdk options are exclusive ref-manual: classes: nativesdk: move note to appropriate section go-helloworld: fix license contributor-guide: submit-changes: fix improper bold string contributor-guide: submit-changes: clarify example with Yocto bug ID contributor-guide: submit-changes: align CC tag description contributor-guide: submit-changes: make the Cc tag follow kernel guidelines contributor-guide: submit-changes: reword commit message instructions contributor-guide: submit-changes: number instruction list in commit your changes contributor-guide: submit-changes: make "Crediting contributors" part of "Commit your changes" Rajeshkumar Ramasamy (2): glib-networking: fix CVE-2025-60018 glib-networking: fix CVE-2025-60019 Randy MacLeod (1): systemd: stable update 255.4 -> 255.13 Ranjitsinh Rathod (1): rust: Add new varaible RUST_ENABLE_EXTRA_TOOLS Rasmus Villemoes (1): iptables: remove /etc/ethertypes Regis Dargent (1): udev-extraconf: fix network.sh script did not configure hotplugged interfaces Richard Purdie (60): selftest/cases/runtime_test: Exclude centos-9 from virgl tests cve-exclusion: Drop the version comparision/warning bitbake: codeparser/data: Ensure module function contents changing is accounted for bitbake: codeparser: Skip non-local functions for module dependencies pseudo: Update to pull in python 3.12+ fix layer.conf: Add os-release to SIGGEN_EXCLUDERECIPES_ABISAFE oeqa/sdk/case: Ensure DL_DIR is populated with artefacts if used create-spdx-3.0/populate_sdk_base: Add SDK_CLASSES inherit mechanism to fix tarball SPDX manifests pseudo: Fix to work with glibc 2.40 pseudo: Update to include open symlink handling bugfix nasm: Upgrade 2.16.01 -> 2.16.03 oeqa/runtime/ssh: In case of failure, show exit code and handle -15 (SIGTERM) oeqa/selftest/reproducibile: Explicitly list virtual targets expat: 2.6.2 -> 2.6.3 ruby: Make docs generation deterministic libedit: Make docs generation deterministic buildhistory: Simplify intercept call sites and drop SSTATEPOSTINSTFUNC usage scripts/install-buildtools: Update to 5.0.3 bitbake.conf: Add truncate to HOSTTOOLS license: Fix directory layout issues libsdl2: Fix non-deterministic configure option for libsamplerate bitbake: tests/fetch: Use our own mirror of sysprof to decouple from gnome gitlab bitbake: tests/fetch: Use our own mirror of mobile-broadband-provider to decouple from gnome gitlab cve_check: Use a local copy of the database during builds pseudo: Fix envp bug and add posix_spawn wrapper oeqa/runtime/ssh: Rework ssh timeout oeqa/runtime/ssh: Fix incorrect timeout fix qemurunner: Clean up serial_lock handling bitbake: fetch2/git: Use quote from shlex, not pipes bitbake: fetch/wget: Increase timeout to 100s from 30s bitbake: runqueue: Fix performance of multiconfigs with large overlap bitbake: runqueue: Optimise setscene loop processing bitbake: runqueue: Fix scenetask processing performance issue do_package/sstate/sstatesig: Change timestamp clamping to hash output only selftest/reproducible: Drop rawlogs selftest/reproducible: Clean up pathnames resulttool: Allow store to filter to specific revisions resulttool: Use single space indentation in json output oeqa/utils/gitarchive: Return tag name and improve exclude handling resulttool: Fix passthrough of --all files in store mode resulttool: Add --logfile-archive option to store mode resulttool: Handle ltp rawlogs as well as ptest resulttool: Clean up repoducible build logs resulttool: Trim the precision of duration information resulttool: Improve repo layout for oeselftest results cve-update-nvd2-native: Tweak to work better with NFS DL_DIR bitbake: tests/fetch: Fix git shallow test failure with git >= 2.48 bitbake: utils: Print information about lock issue before exiting bitbake: utils: Tweak lock_timeout logic bitbake: utils: Add signal blocking for lock_timeout bitbake: event/utils: Avoid deadlock from lock_timeout() and recursive events bitbake: toaster/tests/buildtest: Switch to new CDN bitbake: fetch2: Avoid deprecation warning sstatetests: Switch to new CDN local.conf.sample: Switch to new CDN bitbake: ast: Change deferred inherits to happen per recipe brief-yoctoprojectqs/ref-manual: Switch to new CDN bitbake: test/fetch: Switch u-boot based test to use our own mirror mtools: upgrade 4.0.46 -> 4.0.47 bitbake: utils: Optimise signal/sigmask performance Robert Kovacsics (1): sdk: Fix path length limit to match reserved size Robert P. J. Day (7): Clean up explanation of minimum required version numbers overview-manual: small number of pedantic cleanups bsp guide: update kernel version example to 6.12 bsp-guide: update lonely "4.12" kernel reference to "6.12" bsp-guide: update all of section 1.8.2 to reflect current beaglebone conf file variables.rst: remove references to obsolete tar packaging overview-manual/yp-intro.rst: update on-target packaging info Robert Yang (7): bitbake: data_smart: Improve performance for VariableHistory release-notes-5.0.rst: NO_OUTPUT -> NO_COLOR bitbake: gitsm: Add call_process_submodules() to remove duplicated code bitbake: gitsm: Remove downloads/tmpdir when failed cml1.bbclass: do_diffconfig: Don't override .config with .config.orig libgcrypt: Fix building error with '-O2' in sysroot path groff: Fix race issues for parallel build Rogerio Guerra Borin (1): u-boot: ensure keys are generated before assembling U-Boot FIT image Rohini Sangam (1): vim: Upgrade 9.1.0698 -> 9.1.0764 Roland Kovacs (3): gnupg: update 2.4.5 -> 2.4.8 libxml2: fix CVE-2025-49795 sqlite3: fix CVE-2025-6965 Ross Burton (31): cpio: mark CVE-2023-7216 as disputed fribidi: upgrade 1.0.13 -> 1.0.14 gstreamer1.0: skip another known flaky test libportal: fix rare build race meson: don't use deprecated pkgconfig variable curl: skip FTP tests in run-ptest gawk: update patch status python3-pycryptodome(x): use python_setuptools_build_meta build class gstreamer1.0: disable flaky baseparser tests librsvg: don't try to run target code at build time icu: update patch Upstream-Status strace: download release tarballs from GitHub tcl: skip io-13.6 test case groff: fix rare build race in hdtbl sanity: check for working user namespaces python3: add dependency on -compression to -core classes/nativesdk: also override TUNE_PKGARCH classes/qemu: use tune to select QEMU_EXTRAOPTIONS, not package architecture oeqa/selftest/rust: skip on all MIPS platforms Remove all mention of core-image-lsb ref-manual: don't refer to poky-lsb ref-manual: remove OE_IMPORTS puzzles: ignore three new CVEs for a different puzzles xserver-xf86-config: add a configuration fragment to disable screen blanking xserver-xf86-config: remove obsolete configuration files grub2: fix CVE-2024-56738 libxslt: apply patch for CVE-2025-7424 expect: update code for Tcl channel implementation expect: don't run aclocal in do_configure expect: cleanup do_install pulseaudio: ignore CVE-2024-11586 Ryan Eatmon (2): u-boot.inc: Refactor do_* steps into functions that can be overridden uboot: Allow for customizing installed/deployed file names Sana Kazi (1): gcc-cross-canadian.inc: Fix buildpaths error for pthread.h Sandeep Gundlupet Raju (1): tune-cortexr52: Remove aarch64 for ARM Cortex-R52 Saravanan (2): python3-xmltodict: fix CVE-2025-9375 cmake: fix CVE-2025-9301 Savvas Etairidis (1): systemd: Rename systemd_v255.21 to systemd_255.21 Sergei Zhmylev (1): lsb-release: fix Distro Codename shell escaping Shubham Kulkarni (1): libpam: Update fix for CVE-2024-10041 Shunsuke Tokumoto (1): python3-setuptools: Add "python:setuptools" to CVE_PRODUCT Siddharth Doshi (5): Tiff: Security fix for CVE-2024-7006 vim: Upgrade 9.1.0114 -> 9.1.0682 wpa-supplicant: Upgrade 2.10 -> 2.11 vim: Upgrade 9.1.0682 -> 9.1.0698 openssl: Upgrade 3.2.2 -> 3.2.3 Simon A. Eugster (1): documentation: Fix typo in standards.md Simone Weiß (3): tzdata: Add tzdata.zi to tzdata-core package sanity: Check if tar is gnutar curl: Ignore CVE-2024-32928 Soumya Sambu (12): python3-idna: upgrade 3.6 -> 3.7 python3-certifi: Fix CVE-2024-39689 python3-setuptools: Fix CVE-2024-6345 python3: Fix CVE-2024-7592 python3: Fix CVE-2024-8088 python3-requests: upgrade 2.32.1 -> 2.32.2 python3-requests: upgrade 2.32.0 -> 2.32.3 python3-jinja2: upgrade 3.1.4 -> 3.1.6 git: Upgrade 2.44.1 -> 2.44.3 elfutils: Fix CVE-2025-1371 elfutils: Fix CVE-2025-1376 elfutils: Fix CVE-2025-1377 Stanislav Vovk (1): libpam: fix CVE-2024-10963 Stefan Mueller-Klieser (1): kernel-arch: add macro-prefix-map in KERNEL_CC Steve Sakoman (35): Revert "apt: runtime error: filename too long (tmpdir length)" poky.conf: bump version for 5.0.3 build-appliance-image: Update to scarthgap head revision Revert "wpa-supplicant: Upgrade 2.10 -> 2.11" poky.conf: bump version for 5.0.4 build-appliance-image: Update to scarthgap head revision build-appliance-image: Update to scarthgap head revision release-notes-4.0: update BB_HASHSERVE_UPSTREAM for new infrastructure poky.conf: bump version for 5.0.5 build-appliance-image: Update to scarthgap head revision webkitgtk: fix erroneous use of unsuported DEBUG_LEVELFLAG variable llvm: reduce size of -dbg package poky.conf: bump version for 5.0.6 build-appliance-image: Update to scarthgap head revision poky.conf: bump version for 5.0.7 build-appliance-image: Update to scarthgap head revision Revert "rust: Add new varaible RUST_ENABLE_EXTRA_TOOLS" build-appliance-image: Update to scarthgap head revision poky.conf: add ubuntu2404 to SANITY_TESTED_DISTROS poky.conf: bump version for 5.0.8 build-appliance-image: Update to scarthgap head revision Revert "gcc-cross-canadian.inc: Fix buildpaths error for pthread.h" poky.conf: bump version for 5.0.9 build-appliance-image: Update to scarthgap head revision poky.conf: bump version for 5.0.10 build-appliance-image: Update to scarthgap head revision poky.conf: bump version for 5.0.11 build-appliance-image: Update to scarthgap head revision Revert "sudo: Fix CVE-2025-32462" poky.conf: bump version for 5.0.12 build-appliance-image: Update to scarthgap head revision selftest/cases/meta_ide.py: use use gnu mirror instead of main server oeqa/sdk/cases/buildcpio.py: use gnu mirror instead of main server poky.conf: bump version for 5.0.13 build-appliance-image: Update to scarthgap head revision Sunil Dora (2): gcc: Fix c++: tweak for Wrange-loop-construct binutils: Fix CVE-2025-1153 Talel BELHAJ SALEM (1): dev-manual/building.rst: add note about externalsrc variables absolute paths Talel BELHAJSALEM (1): contributor-guide: Remove duplicated words Teresa Remmet (1): recipes-bsp: usbutils: Fix usb-devices command using busybox Trevor Gamblin (7): python3: skip test_concurrent_futures/test_deadlock python3: skip test_multiprocessing/test_active_children test maintainers.inc: add self for unassigned python recipes python3: upgrade 3.12.4 -> 3.12.5 python3: skip readline limited history tests python3-urllib3: upgrade 2.2.1 -> 2.2.2 reproducible-builds.rst: show how to build a single package Trevor Woerner (5): contributor-guide/submit-changes: encourage patch version changelogs ref-manual/variables.rst: document WIC_CREATE_EXTRA_ARGS sphinx-lint: trailing whitespace sphinx-lint: missing space after literal sphinx-lint: unbalanced inline literal markup Ulrich Ölmann (1): initramfs-framework: fix typos Victor Giraud (1): busybox: fix CVE-2022-48174 Victor Kamensky (1): systemtap: fix systemtap-native build error on Fedora 40 Vijay Anusuri (44): openssh: fix CVE-2024-39894 apr: upgrade 1.7.4 -> 1.7.5 libpcap: Security fix for CVE-2023-7256 & CVE-2024-8006 xserver-xorg: upgrade 21.1.13 -> 21.1.14 glib-2.0: Backport fix for CVE-2024-52533 bind: Upgrade 9.18.28 -> 9.18.33 openssh: Fix CVE-2025-26466 xwayland: Fix CVE-2024-9632 xwayland: Fix CVE-2025-26594 xwayland: Fix CVE-2025-26595 xwayland: Fix CVE-2025-26596 xwayland: Fix CVE-2025-26597 xwayland: Fix CVE-2025-26598 xwayland: Fix CVE-2025-26599 xwayland: Fix CVE-2025-26600 xwayland: Fix CVE-2025-26601 libtasn1: upgrade 4.19.0 -> 4.20.0 xserver-xorg: upgrade 21.1.15 -> 21.1.16 libxslt: upgrade 1.1.39 -> 1.1.43 vim: Upgrade 9.1.1115 -> 9.1.1198 libsoup: Fix CVE-2025-32910 libsoup: Fix CVE-2025-32909 libsoup: Fix CVE-2025-32911 & CVE-2025-32913 libsoup: Fix CVE-2025-32912 libsoup: Fix CVE-2025-32906 libsoup-2.4: Fix CVE-2024-52530 libsoup-2.4: Fix CVE-2024-52531 libsoup-2.4: Fix CVE-2024-52532 libsoup-2.4: Fix CVE-2025-32906 libsoup-2.4: Fix CVE-2025-32909 libsoup: Fix CVE-2025-32914 openssh: Fix for CVE-2025-32728 libsoup-2.4: Fix CVE-2025-32910 libsoup-2.4: Fix CVE-2025-32911 & CVE-2025-32913 libsoup-2.4: Fix CVE-2025-32912 libsoup-2.4: Fix CVE-2025-32914 python3-setuptools: Fix CVE-2025-47273 kea: upgrade 2.4.1 -> 2.4.2 sudo: Fix CVE-2025-32462 git: Upgrade 2.44.3 -> 2.44.4 xserver-xorg: upgrade 21.1.6 -> 21.1.18 cups: upgrade 2.4.10 -> 2.4.11 cups: Fix for CVE-2025-58060 and CVE-2025-58364 gstreamer1.0-plugins-bad: Fix CVE-2025-3887 Virendra Thakur (3): rust-cross-canadian: Set CVE_STATUS ignore for CVE-2024-43402 util-linux: Add fix to isolate test fstab entries using CUSTOM_FSTAB curl: set conditional CVE_STATUS for CVE-2025-5025 Vishwas Udupa (1): openssl: rewrite ptest installation Vrushti Dabhi (1): curl: update CVE_STATUS for CVE-2025-5025 Vyacheslav Yurkov (1): systemd: Password agents shouldn't be optional Wadim Egorov (1): watchdog: Set watchdog_module in default config Wang Mingyu (18): ed: upgrade 1.20.1 -> 1.20.2 llvm: upgrade 18.1.5 -> 18.1.6 mesa: upgrade 24.0.5 -> 24.0.7 wireless-regdb: upgrade 2024.01.23 -> 2024.05.08 orc: upgrade 0.4.38 -> 0.4.39 cups: upgrade 2.4.9 -> 2.4.10 libadwaita: upgrade 1.5.1 -> 1.5.2 libdnf: upgrade 0.73.1 -> 0.73.2 wireless-regdb: upgrade 2024.05.08 -> 2024.07.04 cryptodev: upgrade 1.13 -> 1.14 orc: upgrade 0.4.39 -> 0.4.40 wireless-regdb: upgrade 2024.07.04 -> 2024.10.07 gnupg: upgrade 2.4.4 -> 2.4.5 xserver-xorg: upgrade 21.1.14 -> 21.1.15 ghostscript: upgrade 10.05.0 -> 10.05.1 mtools: upgrade 4.0.44 -> 4.0.45 mtools: upgrade 4.0.45 -> 4.0.46 mtools: upgrade 4.0.47 -> 4.0.48 Weisser, Pascal (1): ref-manual: Add missing variable IMAGE_ROOTFS_MAXSIZE Weisser, Pascal.ext (1): qemuboot: Trigger write_qemuboot_conf task on changes of kernel image realpath Xiangyu Chen (2): qemu: Upgrade 8.2.1 -> 8.2.2 lttng-modules: fix sched_stat_runtime changed in Linux 6.6.66 Yash Shinde (4): binutils: Fix CVE-2024-53589 binutils: Fix CVE-2025-7546 binutils: fix CVE-2025-11081 binutils: fix CVE-2025-8225 Yi Zhao (5): libcap-ng: upgrade 0.8.4 -> 0.8.5 libcap-ng-python: upgrade 0.8.4 -> 0.8.5 rpm: fix expansion of %_libdir in macros iputils: Security fix for CVE-2025-47268 kea: set correct permissions for /var/run/kea Yogita Urade (10): qemu: upgrade 8.2.2 -> 8.2.3 qemu: fix CVE-2024-4467 ruby: upgrade 3.2.2 -> 3.3.5 qemu: upgrade 8.2.3 -> 8.2.7 curl: fix CVE-2024-11053 curl: fix CVE-2025-0167 python3-urllib3: fix CVE-2025-50181 curl: fix CVE-2025-9086 tiff: fix CVE-2025-9900 tiff: ignore CVE-2025-8961 Zhang Peng (3): avahi: fix CVE-2024-52616 mpg123: upgrade 1.32.6 -> 1.32.10 avahi: fix CVE-2024-52615 aszh07 (3): xz: Update LICENSE variable for xz packages ffmpeg: Add "libswresample libavcodec" to CVE_PRODUCT libarchive: Fix CVE-2024-20696 rajmohan r (1): glibc-y2038-tests: remove glibc-y2038-tests_2.39.bb recipe meta-openembedded: 78a14731cf..15e18246dd: Adrian Freihofer (2): networkmanager: remove modemmanager rdepends thrift: fix build with gcc 15 Alexandre Truong (4): source-han-sans-*-fonts: Switch away from SVN fetcher in SRC_URI lcov: include UPSTREAM_CHECK_* to fix UNKNOWN_BROKEN status hunspell-dictionaries: switch branch from master to main evince: Update status for CVE-2011-0433 and CVE-2011-5244 Alexandre Videgrain (1): openbox: fix crash on alt+tab with fullscreen app AmateurECE (1): pipewire: Add glib-2.0-native dep for bluez5 Andrej Valek (1): externalsrc: fix support in various components Anil Dongare (1): libssh 0.10.6: Fix CVE-2025-8114 Ankur Tyagi (25): tinyproxy: patch CVE-2023-49606 frr: patch CVE-2024-44070 libavif: ignore CVE-2025-48175 libconfuse: patch CVE-2022-40320 hdf5: patch CVE-2025-2913 hdf5: patch CVE-2025-2914 hdf5: patch CVE-2025-2915 hdf5: patch CVE-2025-2923, CVE-2025-6816, CVE-2025-6856 hdf5: patch CVE-2025-2924 hdf5: patch CVE-2025-2925 hdf5: patch CVE-2025-6269, CVE-2025-6270, CVE-2025-6516 libppd: patch CVE-2024-47175 libcupsfilters: patch CVE-2024-47076 libraw: patch CVE-2025-43961 CVE-2025-43962 libraw: patch CVE-2025-43963 libraw: patch CVE-2025-43964 zlog: fix CVE-2024-22857 memcached: patch CVE-2023-46852 memcached: patch CVE-2023-46853 ndpi: ignore CVE-2025-25066 libiec61850: patch CVE-2024-26529 libiec61850: patch CVE-2024-45970 libiec61850: patch CVE-2024-45971 mbedtls: upgrade 3.6.4 -> 3.6.5 hostapd: patch CVE-2025-24912 Archana Polampalli (4): modejs: upgrade 20.18.0 -> 20.18.2 tftpy: fix CVE-2023-46566 tcpreplay: fix CVE-2024-22654 apache2: upgrade 2.4.64 - 2.4.65 Ariel D'Alessandro (1): pipewire: Install missing ALSA config files Armin Kuster (1): Revert "mariadb: fix runtime failure on riscv" Ashish Sharma (2): nginx: Backport fix for CVE-2024-7347 postgresql: Backport fix for CVE-2024-7348 AshishKumar Mishra (1): meta-oe: image: optionally remove RAW image after sparse image creation Awais Belal (2): mongodb: fix build with python 3.12 mongodb: update to 4.4.29 BINDU (1): flatbuffers: adapt for cross-compilation environments Barry Grussling (1): postgresql: Break perl RDEPENDS Bastian Krause (2): libsocketcan: use https instead of git protocol canutils: use https instead of git protocol Benjamin Szőke (1): tree: fix broken links Changqing Li (11): pavucontrol: update SRC_URI libatasmart: Update SRC_URI mariadb: fix runtime failure on riscv dlt-daemon: make DLT_WatchdogSec configurable abseil-cpp: upgrade 20240116.2 -> 20240116.3 nginx: fix CVE-2025-23419 libblockdev: fix CVE-2025-6019 udisks2: Hardening measure of CVE-2025-6019 phpmyadmin: upgrade 5.2.1 -> 5.2.2 luajit: fix several CVEs mariadb: correct STACK_DIRECTION setting Chen Qi (6): libdbd-mysql-perl: avoid invoking assert_lib at do_configure stage python3-protobuf: remove useless and problematic .pth file graphviz: remove obsolete and problematic patch protobuf: fix CVE-2024-7254 protobuf: upgrade from 4.25.3 to 4.25.8 python3-protobuf: upgrade from 4.25.3 to 4.25.8 Chris Laplante (1): poco: fix branch: master => poco-1.12.5 Christos Gavros (1): corosync: reproducibility issue Claus Stovgaard (2): lcov: sort RDEPENDS alphabetical lcov: Add missing RDEPENDS Clayton Casciato (1): chrony: use inherit_defer for conditional inherit of useradd Deepak Rathore (1): protobuf 4.25.8: Mark CVE-2024-7254 as patched Divya Chellam (7): nginx: upgrade 1.25.3 -> 1.25.4 redis: upgrade 7.2.6 -> 7.2.7 krb5: fix CVE-2025-24528 openvpn: upgrade 2.6.12 -> 2.6.14 libssh: fix CVE-2025-4878 libssh: fix CVE-2025-5987 jq: fix CVE-2025-9403 Dmitry Baryshkov (1): android-tools: Create flag file /etc/usb-debugging-enabled Esben Haabendal (1): netplan: add missing runtime dependencies Etienne Cordonnier (3): uutils-coreutils: upgrade 0.0.25 -> 0.0.26 uutils-coreutils: upgrade 0.0.26 -> 0.0.27 uutils-coreutils: fix compilation with selinux Fabrice Aeschbacher (1): mosquitto: upgrade 2.0.18 -> 2.0.19 Fathi Boudra (2): python3-django: upgrade 4.2.11 -> 4.2.16 python3-django: upgrade 5.0.4 -> 5.0.9 Frank de Brabander (3): python3-pydantic-core: fix incompatible version python3-pydantic-core: fix TMPDIR path reference python3-pydantic-core: add missing RDEPENDS for ptest Grygorii Tertychnyi (1): libusbgx: fix gadget-stop install Guocai He (6): python3-pylint: correct the SRC_URI libconfig: correct the SRC_URI logcheck: correct the SRC_URI thrift: correct the SRC_URI softhsm: correct the SRC_URI mariadb: File conflicts for multilib Guðni Már Gilbert (1): mbedtls: upgrade 3.6.3.1 -> 3.6.4 Gyorgy Sarvari (35): poppler: fix typos in CVE-2025-52886-0001.patch mod-dnssd: update SRC_URI mosh: set working SRC_URI psqlodbc: set valid SRC_URI collectd: set working SRC_URI apache2: ignore irrelevant CVEs civetweb: patch CVE-2025-55763 dovecot: patch CVE-2022-30550 pm-qa: update git fetch protocol tokyocabinet: switch to working SRC_URI tokyocabinet: fix license iperf2: ignore irrelevant CVEs jasper: patch CVE-2025-8835 jasper: patch CVE-2025-8836 jasper: patch CVE-2025-8837 etcd: patch CVE-2023-32082 freerdp3: patch CVE-2024-32039 and CVE-2024-32041 freerdp3: patch CVE-2024-32040 freerdp3: patch CVE-2024-32458 freerdp3: patch CVE-2024-32459 freerdp3: patch CVE-2024-32460 freerdp3: patch CVE-2024-32658 freerdp3: patch CVE-2025-32659 freerdp3: patch CVE-2024-32660 freerdp3: patch CVE-2024-32661 freerdp3: patch CVE-2024-32662 exiv2: patch CVE-2025-26623 exiv2: patch CVE-2025-54080 exiv2: patch CVE-2025-55304 redis: upgrade 6.2.18 -> 6.2.20 emacs: patch CVE-2024-30202 emacs: patch CVE-2024-30203 emacs: patch CVE-2024-30204 emacs: patch CVE-2024-30205 emacs: patch CVE-2024-39331 Haixiao Yan (4): openvpn: fix CVE-2024-28882 openvpn: upgrade 2.6.10 -> 2.6.12 lmsensors: Clean stale files for sensord to avoid incorrect GCC header dependencies python3-posix-ipc: fix runtime error Harish Sadineni (1): bpftool: Add support for riscv64 Hieu Van Nguyen (1): gphoto2: Fix contains reference to TMPDIR [buildpaths] warning Hitendra Prajapati (8): tgt: fix CVE-2024-45751 libssh: fix CVE-2025-5318 redis: fix CVE-2025-32023 libssh: fix CVE-2025-5351 & CVE-2025-5372 open-vm-tools: fix CVE-2025-22247 libssh: fix CVE-2025-4877 openjpeg: fix for CVE-2025-54874 libjxl: fix CVE-2024-11403 & CVE-2024-11498 Hongxu Jia (1): nodejs: support cross compile without qemu user conditionally J. S (2): nodejs: upgrade 20.16.0 -> 20.17.0 nodejs: upgrade 20.17.0 -> 20.18.0 J. S. (3): znc: Fix buildpaths QA errors nodejs: cleanup xfce4 update HOMEPAGEs Jan Vermaete (1): python3-werkzeug: added python3-difflib as RDEPENDS Jason Schonberg (1): nodejs: upgrade 20.13.0 -> 20.16.0 Jef Driesen (2): nginx: fix the tarball and license checksums lcov: Add missing RDEPENDS for nativesdk Jeroen Hofstee (5): nodejs: backport a patch to prevent brotli crashing nodejs can-utils: fix printing / reading timestamps can-utils: handle CAN_ERR_CNT correctly php: ignore CVE-2024-3566 nodejs: ignore CVE-2024-3566 Jeroen Knoops (1): nng: Rename default branch of github.com:nanomsg/nng.git Jiaying Song (15): rrdtool: Fix do_populate_sysroot QA issues nftables: change ptest output format debootstrap: fix do_fetch error wireguard-tools: fix do_fetch error vlock: fix do_fetch error openipmi: upgrade 2.0.34->2.0.36 tcpreplay: fix CVE-2023-43279 xfce-dusk-gtk3: fix do_fetch error eject: fix do_fetch error libdev-checklib-perl: fix do_fetch error xmlsec1: Switch SRC_URI to use github release chrony: fix do_fetch error v4l-utils: Fix QA and build errors related to _TIME_BITS on 32-bit webkitgtk3: update 2.44.1 -> 2.44.3 webkitgtk3: fix do_configure error on beaglebone-yocto Jinfeng Wang (2): netplan: Fix CVE-2022-4968 postfix: fix rootfs file difference Justin Bronder (1): python3-xmodem: replace hardcoded /usr with ${prefix} Khem Raj (32): python3-pydantic-core: Fix build with python 3.12.4 log4cpp: Fix buildpaths QA error python3-pydantic: Upgrade to 2.7.3 mariadb: Upgrade to 10.11.9 release ndisc: Remove buildpaths from binaries ndisc6: Fix reproducible build ghex,gnome-chess,gnome-photos: Add missing dep on itstool-native nodejs: Upgrade to 20.13.0 release nodejs: Fix build with libc++ 19 wolfssl: Add packageconfig for reproducible build blueman: Fix buildpathe issue with cython generated code botan: Make it reproducible keepalived: Make build reproducible ldns: Fix buildpaths QA issues python3-kivy: Remove buildpaths from comments in generated C sources python3-pyproj: Fix buildpaths QA Error python3-pyproj: Remove absolute paths from cython generated .c files python3-pycocotools: Remove absolute paths from comments lprng: Specify target paths for needed utilities fwknop: Specify target locations of gpg and wget e2tools: Fix buildpaths QA warning in config.status in ptest sharutils: Let POSIX_SHELL be overridable from environment python3-posix-ipc: switch to PEP-517 build backend gtkwave: Add libtirpc to depends ssmping: Use debian mirror for SRC_URI enca: Fix cross builds ckermit: Define return type for main ckermit: Fix build with GCC-15 procmail: Fix build with GCC-14 uim: Stick to C17 freerdp: Upgrade 2.11.2 -> 2.11.7 influxdb: Do not remove non-existing files Leon Anavi (2): sip: Upgrade 6.8.3 -> 6.8.6 sip: Fix homepage and license Leonard Anderweit (1): lmsensors: Fix build without sensord Libo Chen (3): thin-provisioning-tools: install missed thin_shrink and era_repair grpc: Fix CVE-2024-7246 libgpiod: fix gpiod-cxx-test failed test case Marc Ferland (2): polkit: update SRC_URI libvncserver: fix generated LibVNCServerTargets.cmake Markus Volk (4): exiv2: update 0.28.0 -> 0.28.2 gnome-remote-desktop: update 46.1 -> 46.2 geary: add itstool-native dependency eog: add itstool-native dependency Martin Jansa (13): bolt: package systemd_system_unitdir correctly giflib: fix build with gold and avoid imagemagick-native dependency Revert "gcab: ignore buildpaths error from sources" gpm: fix buildpaths QA issue xerces-c: fix buildpaths QA issue xmlrpc-c: update SRCREV lapack: add PACKAGECONFIG for cblas lapack: fix buildpaths in ptest also when CBLAS is enabled gcab: fix buildpaths QA issue python3-posix-ipc: improve build_support python3-h5py: backport fixes for incompatible-pointer-types issues abseil-cpp: fix build with gcc-15 on host nodejs: fix build with gcc-15 on host Martin Schwan (1): linuxptp: Add systemd instance specifier for ptp4l dependency Michael Olbrich (1): nftables: avoid python dependencies when building without python Michael Opdenacker (1): kernel-hardening-checker: backport recipe Mikko Rapeli (3): fwupd: skip buildpaths errors gcab: ignore buildpaths error from sources libjcat: skip buildpaths check Mingli Yu (2): asio: Add ptest support ptest-packagelists-meta-oe.inc: Add asio Neel Gandhi (1): v4l-utils: Install media ctrl header and library files Nikhil R (2): nftables: Conditionally add ${PN}-python as RDEPENDS for ptest rocksdb: Add an option to set static library Niko Mauno (16): python3-xlsxwriter: Fix LICENSE python3-cbor2: Fix LICENSE and LIC_FILES_CHKSUM python3-crc32c: Amend LICENSE declaration python3-email-validator: Fix LICENSE python3-lru-dict: Fix LICENSE and change SUMMARY to DESCRIPTION python3-mock: Fix LICENSE python3-parse-type: Fix LICENSE python3-pillow: Fix LICENSE and change SUMMARY to DESCRIPTION python3-platformdirs: Fix LICENSE python3-colorama: Fix LICENSE python3-fann2: Fix LICENSE python3-nmap: Fix LICENSE and LIC_FILES_CHKSUM python3-pycurl: Fix LICENSE python3-googleapis-common-protos: Fix LIC_FILES_CHKSUM python3-haversine: Fix LIC_FILES_CHKSUM python3-libevdev: Fix LIC_FILES_CHKSUM Ninette Adhikari (6): imagemagick: Update status for CVE imagemagick: Update status for CVE imagemagick: Update status for CVE xsp: CVE status update for CVE-2006-2658 influxdb: Update CVE status for CVE-2019-10329 monkey: Update status for CVE-2013-2183 Peter Kjellerstedt (6): hostapd: Support running "devtool modify hostapd" hostapd: Only include the relevant parts from README in LIC_FILES_CHKSUM libjs-jquery-icheck: Correct LIC_FILES_CHKSUM libdevmapper: Inherit nopackages ebtables: Remove the dependecy on bash libeigen: Remove LGPL code Peter Marko (41): libndp: Patch CVE-2024-5564 squid: patch CVE-2024-37894 hostapd: Patch CVE-2024-3596 hostapd: Patch security advisory 2024-2 nss: patch CVE-2024-6602 nss: patch CVE-2024-6609 squid: conditionally set status of CVE-2024-45802 thrift: fix c++ generated code compilation with clang grpc: patch CVE-2024-11407 python3-grpcio: patch CVE-2024-11407 python3-grpcio(-tools): fix build concurrency issue libmodbus: patch CVE-2024-10918 libmodbus: ignore CVE-2023-26793 and CVE-2024-34244 libcoap: patch CVE-2024-31031 spdlog: patch CVE-2025-6140 minifi-cpp: patch spdlog CVE-2025-6140 poco: ignore additional failing tests poco: patch CVE-2025-6375 nginx: patch CVE-2025-53859 fontforge: patch CVE-2024-25081 and CVE-2024-25082 fcgi: patch CVE-2025-23016 procmail: patch CVE-2014-3618 procmail: patch CVE-2017-16844. ace: ignore CVE-2009-1147 audiofile: fix multiple CVEs audiofile: patch CVE-2017-6829 audiofile: fix multiple CVEs audiofile: patch CVE-2017-6831 audiofile: patch CVE-2017-6839 emlog: set CVE_PRODUCT freerdp: patch CVE-2024-32661 freerdp: mark CVE-2024-32662 as fixed freerdp3: set CVE_PRODUCT corosync: fix upstream version check corosync: upgrade 3.1.6 -> 3.1.9 corosync: patch CVE-2025-30472 dash: set CVE_PRODUCT gattlib: mark CVE-2019-6498 as fixed memcached: ignore disputed CVE-2022-26635 monkey: ignore CVE-2013-1771 squid: patch CVE-2025-59362 Poonam Jadhav (1): tcpreplay: Fix CVE-2023-4256 Praveen Kumar (4): php: upgrade 8.2.28 -> 8.2.29 polkit: fix CVE-2025-7519 yasm: fix CVE-2024-22653 cjson: upgrade 1.7.18 -> 1.7.19 Preeti Sachan (1): bpftool: fix libelf.h not found error Raghuvarya S (2): android-tools-adbd.service: Update ConditionPathExists to /etc android-toold-adbd: Fix inconsistency between selinux configurations Rajeshkumar Ramasamy (1): open-vm-tools: fix CVE-2025-41244 Randolph Sapp (2): opencl-clhpp: add native and nativesdk vulkan-cts: allow vulkan versions > 1.3 Randy MacLeod (1): python3-pyyaml-include: support native and nativesdk build Robert Yang (1): hostapd: Add CVE id to CVE-2024-3596_00.patch Roland Kovacs (2): jq-1.7.1: Backport multiple CVE fixes jq: add Upstream-Status and CVE tags into .patch files Ryan Eatmon (1): kernel-selftest: Update to allow for turning on all tests Sana Kazi (2): libp11: Treat all openssl-3.x releases the same imagemagick: guard sed operations in do_install for optional files Saravanan (2): udisks2: upgrade 2.10.1 -> 2.10.2 fio: fix CVE-2025-10823 Scott Murray (2): python3-grpcio: Fix build with gcc-14 python3-grpcio: backport abseil-cpp RISC-V fix Shubham Pushpkar (2): wireshark 4.2.7: Fix CVE-2024-9781 cjson 1.7.18: Fix CVE-2025-57052 Siddharth Doshi (2): apache2: Upgrade 2.4.59 -> 2.4.60 apache2: Upgrade 2.4.60 -> 2.4.62 Sofiane HAMAM (2): Wolfssl: add ptest wolfssl: Upgrade 5.7.0 -> 5.7.2 Soumya Sambu (14): python3-sqlparse: Fix CVE-2024-4340 python3-werkzeug: upgrade 3.0.1 -> 3.0.3 gtk+: Fix CVE-2024-6655 python3-twisted: Fix CVE-2024-41671 python3-flask-cors: Fix CVE-2024-6221 python3-werkzeug: upgrade 3.0.3 -> 3.0.6 python3-tornado: Upgrade 6.4 -> 6.4.2 python3-django: upgrade 4.2.16 -> 4.2.17 python3-django: upgrade 5.0.9 -> 5.0.10 python3-django: upgrade 5.0.10 -> 5.0.11 python3-django: upgrade 4.2.17 -> 4.2.18 php: Upgrade 8.2.26 -> 8.2.28 iniparser: Fix CVE-2025-0633 python3-django: upgrade 4.2.18 -> 4.2.20 Sunil Dora (1): layer.conf: add bpftrace to NON_MULTILIB_RECIPES Swamil Jain (1): kmsxx: Revert to using original name for kmstest Thomas Roos (1): libcamera: backport 0.4.0 from master-next Tim Orling (1): python3-pydantic: upgrade 2.7.3 -> 2.7.4 Trevor Woerner (2): apache2: use update-alternatives for httpd iperf3: throughput fix Vijay Anusuri (16): krb5: upgrade 1.21.2 -> 1.21.3 wireshark: upgrade 4.2.4 -> 4.2.5 wireshark: upgrade 4.2.5 -> 4.2.7 php: upgrade 8.2.24 -> 8.2.26 openjpeg: upgrade 2.5.0 -> 2.5.3 postgresql: upgrade 16.5 -> 16.8 wireshark: upgrade 4.2.7 -> 4.2.9 proftpd: Fix CVE-2024-57392 redis: upgrade 7.2.7 -> 7.2.8 wireshark: upgrade 4.2.9 -> 4.2.12 proftpd: Fix CVE-2023-51713 apache2: Upgrade 2.4.62 -> 2.4.64 poppler: Fix CVE-2025-43718 redis: upgrade 7.2.8 -> 7.2.11 redis: upgrade 6.2.16 -> 6.2.18 vorbis-tools: Fix CVE-2023-43361 Virendra Thakur (2): opensc: Fix multiple cve CVE-2024-45615-45616-45617-45618-45619-45620 unbound: Fix CVE-2024-8508 Wang Mingyu (18): python3-email-validator: upgrade 2.1.0 -> 2.1.1 python3-pydantic: upgrade 2.7.0 -> 2.7.1 cjson: upgrade 1.7.17 -> 1.7.18 samba: upgrade 4.19.7 -> 4.19.8 postgresql: upgrade 16.3 -> 16.4 redis: upgrade 7.2.4 -> 7.2.5 mosquitto: upgrade 2.0.19 -> 2.0.20 uutils-coreutils: upgrade 0.0.27 -> 0.0.28 nana: Fix buildpaths warning. fetchmail: Fix buildpaths warning. fetchmail: disable rpath to fix buildpaths warning. python3-posix-ipc: upgrade 1.1.1 -> 1.2.0 mbedtls: upgrade 3.6.3 -> 3.6.3.1 geoip: fix do_fetch error rp-pppoe: update SRC_URI procmail: fix build failure with gcc-14 procmail: Add -Wno-implicit-int to fix error of do_compile libiec61850: upgrade 1.5.1 -> 1.5.3 Wentao Zhang (1): meta-oe/conf/layer.conf: remove libbpf from NON_MULTILIB_RECIPES for x86 and x86-64 Xiangyu Chen (1): crash: fix crash cannot work with kaslr Yi Zhao (12): samba: upgrade 4.19.6 -> 4.19.7 mbedtls: upgrade 3.6.0 -> 3.6.1 mbedtls: upgrade 2.28.8 -> 2.28.9 libldb: upgrade 2.8.0 -> 2.8.1 mbedtls: upgrade 3.6.1 -> 3.6.2 freeradius: upgrade 3.2.3 -> 3.2.5 hostapd: Security fix for CVE-2023-52160 redis: upgrade 7.2.5 -> 7.2.6 mbedtls: upgrade 2.28.9 -> 2.28.10 mbedtls: 3.6.2 -> 3.6.3 wxwidgets: upgrade 3.2.1 -> 3.2.6 redis: upgrade 6.2.14 -> 6.2.16 Yoann Congal (3): packagegroup-meta-oe: fix lvgl inclusion mdio-tools: fix mdio-netlink kernel module reproducibility gutenprint: fix a build race-condition Yogesh Tyagi (1): tbb-native: Fix build with gcc-13 Yogita Urade (18): graphviz: fix CVE-2023-46045 hdf5: upgrade to 1.14.4 poppler: CVE-2024-6239 krb5: fix CVE-2024-26458 and CVE-2024-26461 php: upgrade 8.2.20 -> 8.2.24 postgresql: upgrade 16.4 -> 16.5 poppler: fix CVE-2024-56378 poppler: fix CVE-2025-32364 poppler: fix CVE-2025-32365 poppler: fix CVE-2025-43903 syslog-ng: fix CVE-2024-47619 postgresql: upgrade 16.8 -> 16.9 mariadb: upgrade 10.11.9 -> 10.11.12 poppler: fix CVE-2025-52886 poppler: fix CVE-2025-50420 postgresql: upgrade 16.9 -> 16.10 indent: fix CVE-2023-40305 poppler: fix CVE-2025-52885 Zhang Peng (21): hiredis: remove ANSI color from ptest result frr: fix CVE-2024-34088 frr: fix CVE-2024-31950 frr: fix CVE-2024-31951 frr: fix CVE-2024-31948 frr: fix CVE-2024-31949 libgsf: upgrade 1.14.52 -> 1.14.53 glade: fix CVE-2020-36774 opensc: fix CVE-2024-8443 lapack: fix TMPDIR reference in do_package_qa iperf3: upgrade 3.16 -> 3.18 gnuplot: fix CVE-2025-3359 gnuplot: fix CVE-2025-31176 gnuplot: fix CVE-2025-31177 gnuplot: fix CVE-2025-31178 gnuplot: fix CVE-2025-31179 gnuplot: fix CVE-2025-31180 gnuplot: fix CVE-2025-31181 iperf3: fix CVE-2025-54349 iperf3: fix CVE-2025-54350 wxwidgets: fix CVE-2024-58249 Zoltán Böszörményi (1): gutenprint: 5.3.5 akash hadke (1): python3-flatbuffers: provide nativesdk support alperak (8): tayga: Fix contains reference to TMPDIR [buildpaths] warning etcd-cpp-apiv3: Fix contains reference to TMPDIR [buildpaths] warning exiv2: Upgrade 0.28.2 to 0.28.3 for CVE fix jsonrpc: Fix contains reference to TMPDIR [buildpaths] warning rdist: Fix contains reference to TMPDIR [buildpaths] warning perfetto: Fix contains reference to TMPDIR [buildpaths] warning hplip: Fix contains reference to TMPDIR [buildpaths] warning boinc-client: Fix contains reference to TMPDIR [buildpaths] warning gudnimar (1): pipewire: upgrade 1.0.5 -> 1.0.9 hongxu (2): p7zip: fix CVE-2023-52169 and CVE-2023-52168 indent: fix CVE-2024-0911 kjlau0112 (1): mbedtls: drop tag parameter from SRC_URI. mark.yang (1): srecord: fix build failure with gcc-15 meta-raspberrypi: 1918a27419..8767e2ff80: Adam Schafer (1): add raspi-utils recipe to scarthgap branch Andrei Gherzan (1): docs: Fix ReadTheDocs sphinx.configuration requirement Ayoub Zaki (1): raspberrypi5: add bcm2712d0 overlay required for booting up correctly Bassem Nomany (1): mesa: update to 24.3.1 Damiano Ferrari (2): rpi-eeprom: Update to latest release rpi-bootfiles: Update to latest release Florin Sarbu (1): linux-raspberrypi.inc: Change defconfig for RPi3 64 bits Garrett Brown (1): linux: Enable CONFIG_I2C_BRCMSTB for proper HDMI I2C support Gijs Peskens (1): raspberrypi5.conf: Add CM5 dtb's Jaeyoon Jung (1): linux-raspberrypi: Drop deprecated configs from android-driver.cfg Joshua Watt (1): linux-firmware-rpidistro: Fix WiFi on Raspberry Pi 5 Khem Raj (2): linux-raspberrypi-6.6: Upgrade to 6.6.63 rpi-base: Remove bcm2712-rpi-5-b.dtb from RPI_KERNEL_DEVICETREE target Leon Anavi (11): yocto-builder/Dockerfile: Ubuntu 22.04 rpi-base.inc: vc4-kms-dsi-ili9881-7inch.dtbo u-boot_%.bbappend: Increase CONFIG_SYS_BOOTM_LEN wayland-protocols: Upgrade 1.38 -> 1.45 mesa: Upgrade 24.3.1 -> 25.1.3 mesa: Upgrade 25.1.3 -> 25.1.6 mesa_%.bbappend: DISTRO_FEATURES for wayland mesa: wayland-protocols: Fix signatures linux-firmware-rpidistro: Update and stabilize rpi-base.inc: Add w1-gpio-pi5.dtbo rpi-base.inc: Add rpi-backlight.dtbo Markus Volk (4): linux-raspberrypi: add recipe for 6.12 linux-raspberrypi: update 6.12.2 -> 6.12.25 rpi-default-versions: Switch default kernel to 6.12 rpi-bootfiles: update to latest release Martin Jansa (3): docker-build: use --no-cache Revert "rpi-default-versions: Switch default kernel to 6.12" mesa, wayland-protocols: use separate recipe instead of bbappend Matthias Klein (1): linux-firmware-rpidistro: Upgrade to bookworm/20230625-2+rpt3 Omri Sarig (1): linux-firmware-rpidistro: Fix wireless error message on RPi Pierrick Curt (1): rpi-base: build uart dts overlays by default Thomas Roos (1): Moving bcm2712d0.dtbo into rpi-base.inc meta-arm: 58268ddccb..0f1e7bf92c: Amr Mohamed (5): kas: Update kas configuration for fvp-base.yml file arm-systemready/linux-distros: new inc file for unattended installation arm-systemready/linux-distros: Add kickstart file for Fedora unattended arm-systemready/oeqa: Add new test for Fedora unattended installation kas: Add new yml file for Distros unattended installation Ben (3): arm-systemready/linux-distros: Implement unattended openSUSE arm-systemready/oeqa: Add unattended installation testcase kas: Include unattended openSUSE test Bence Balogh (1): arm-bsp/trusted-firmware-m: corstone1000: Fix MPU configuration Harsimran Singh Tungal (1): arm-bsp,kas: corstone1000: enable External System based on new yml file Hugues KAMBA MPIANA (1): arm-bsp/documentation: corstone1000: Add SystemReady IR v2.0 certification Jon Mason (4): arm-toolchain: remove libmount-mountfd-support when using binary toolchain arm-bsp/fvp-base: Get 6.10 kernel working arm/linux-yocto: disable CONFIG_MTD_NAND_FSL_IFC arm-systemready/ir-acs: Update URL Jose Quaresma (1): bsp: optee-client: cleanup old tee-supplicant Luca Fancellu (2): arm/oeqa: Introduce retry mechanism for fvp_devices run_cmd arm/lib: Handle timeout for spawn object on stop() Romain Naour (4): external-arm-toolchain: remove old sed fixup for libc.so external-arm-toolchain: wrap symlink handling under usrmerge check external-arm-toolchain: override dynamic loader path with usrmerge enabled external-arm-toolchain: rebuild libmvec.so symlink if any Ross Burton (5): arm-base/linux-yocto: revert interim 6.10 patch for fvp-base arm-system-ready/arm-systemready-ir-acs: add version to download filename CI: use canonical git.yoctoproject.org URLs arm/execstack-native: add new recipe arm/fvp-base-a-aem: remove spurious executable stack from one library Vasyl Vavrychuk (3): external-arm-toolchain: wrap base_libdir vs libdir manipulations under usrmerge check external-arm-toolchain: in libc.so GNU ld script use base_libdir external-arm-toolchain: remove ${base_libdir}/libpthread*.so from FILES:${PN} meta-security: 11ea91192d..bc865c5276: Hitendra Prajapati (2): clamav: fix CVE-2024-20505 & CVE-2024-20506 libhtp: fix CVE-2024-45797 Vijay Anusuri (2): tpm2-tools: Upgrade 5.5 -> 5.7 tpm2-tss: upgrade 4.0.1 -> 4.0.2 Change-Id: Ief5b086436b2f3a4e819546fcd1bb9a5b1f608dd Signed-off-by: Andrew Geissler <geissonator@yahoo.com>
Diffstat (limited to 'poky/meta/recipes-devtools/python')
-rw-r--r--poky/meta/recipes-devtools/python/python3-attrs_23.2.0.bb1
-rw-r--r--poky/meta/recipes-devtools/python/python3-certifi/CVE-2024-39689.patch69
-rw-r--r--poky/meta/recipes-devtools/python/python3-certifi_2024.2.2.bb3
-rw-r--r--poky/meta/recipes-devtools/python/python3-idna_3.7.bb (renamed from poky/meta/recipes-devtools/python/python3-idna_3.6.bb)4
-rw-r--r--poky/meta/recipes-devtools/python/python3-jinja2_3.1.6.bb (renamed from poky/meta/recipes-devtools/python/python3-jinja2_3.1.4.bb)5
-rw-r--r--poky/meta/recipes-devtools/python/python3-lxml_5.0.2.bb (renamed from poky/meta/recipes-devtools/python/python3-lxml_5.0.0.bb)3
-rw-r--r--poky/meta/recipes-devtools/python/python3-maturin/0001-Extract-extension-architecture-name-resolvation-code.patch107
-rw-r--r--poky/meta/recipes-devtools/python/python3-maturin/0002-Fix-cross-compilation-issue-with-linux-armv7l-archit.patch76
-rw-r--r--poky/meta/recipes-devtools/python/python3-maturin/0003-Extract-extension-ABI-name-resolvation-code-as-helpe.patch98
-rw-r--r--poky/meta/recipes-devtools/python/python3-maturin/0004-Fix-cross-compilation-issue-with-linux-ppc-architect.patch68
-rw-r--r--poky/meta/recipes-devtools/python/python3-maturin/0005-Fix-cross-compilation-issue-with-linux-mips64-archit.patch82
-rw-r--r--poky/meta/recipes-devtools/python/python3-maturin_1.4.0.bb7
-rw-r--r--poky/meta/recipes-devtools/python/python3-poetry-core_1.9.0.bb1
-rw-r--r--poky/meta/recipes-devtools/python/python3-pycryptodome_3.20.0.bb2
-rw-r--r--poky/meta/recipes-devtools/python/python3-pycryptodomex_3.20.0.bb2
-rw-r--r--poky/meta/recipes-devtools/python/python3-requests/environment.d-python3-requests.sh11
-rw-r--r--poky/meta/recipes-devtools/python/python3-requests_2.31.0.bb24
-rw-r--r--poky/meta/recipes-devtools/python/python3-requests_2.32.4.bb35
-rw-r--r--poky/meta/recipes-devtools/python/python3-setuptools-scm/0001-respect-GIT_CEILING_DIRECTORIES.patch36
-rw-r--r--poky/meta/recipes-devtools/python/python3-setuptools-scm_8.0.4.bb1
-rw-r--r--poky/meta/recipes-devtools/python/python3-setuptools/CVE-2024-6345.patch312
-rw-r--r--poky/meta/recipes-devtools/python/python3-setuptools/CVE-2025-47273-pre1.patch54
-rw-r--r--poky/meta/recipes-devtools/python/python3-setuptools/CVE-2025-47273.patch59
-rw-r--r--poky/meta/recipes-devtools/python/python3-setuptools_69.1.1.bb8
-rw-r--r--poky/meta/recipes-devtools/python/python3-urllib3/CVE-2025-50181.patch283
-rw-r--r--poky/meta/recipes-devtools/python/python3-urllib3_2.2.2.bb (renamed from poky/meta/recipes-devtools/python/python3-urllib3_2.2.1.bb)6
-rw-r--r--poky/meta/recipes-devtools/python/python3-xmltodict/CVE-2025-9375-1.patch111
-rw-r--r--poky/meta/recipes-devtools/python/python3-xmltodict/CVE-2025-9375-2.patch176
-rw-r--r--poky/meta/recipes-devtools/python/python3-xmltodict_0.13.0.bb2
-rw-r--r--poky/meta/recipes-devtools/python/python3-zipp/CVE-2024-5569.patch138
-rw-r--r--poky/meta/recipes-devtools/python/python3-zipp_3.17.0.bb1
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch6
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch3
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch7
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch6
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-Skip-failing-tests-due-to-load-variability-on-YP-AB.patch16
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch7
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch37
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-gh-114492-Initialize-struct-termios-before-calling-t.patch26
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-python3-use-cc_basename-to-replace-CC-for-checking-c.patch20
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-skip-no_stdout_fileno-test-due-to-load-variability.patch6
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch5
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-test_active_children-skip-problematic-test.patch27
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-test_ctypes.test_find-skip-without-tools-sdk.patch5
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-test_deadlock-skip-problematic-test.patch27
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch7
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-test_readline-skip-limited-history-test.patch38
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-test_shutdown-skip-problematic-test.patch11
-rw-r--r--poky/meta/recipes-devtools/python/python3/0001-test_storlines-skip-due-to-load-variability.patch7
-rw-r--r--poky/meta/recipes-devtools/python/python3/0020-configure.ac-setup.py-do-not-add-a-curses-include-pa.patch6
-rw-r--r--poky/meta/recipes-devtools/python/python3/cgi_py.patch3
-rw-r--r--poky/meta/recipes-devtools/python/python3/crosspythonpath.patch5
-rw-r--r--poky/meta/recipes-devtools/python/python3/deterministic_imports.patch7
-rw-r--r--poky/meta/recipes-devtools/python/python3/makerace.patch6
-rw-r--r--poky/meta/recipes-devtools/python/python3/python3-manifest.json2
-rw-r--r--poky/meta/recipes-devtools/python/python3_3.12.12.bb (renamed from poky/meta/recipes-devtools/python/python3_3.12.4.bb)17
56 files changed, 1950 insertions, 142 deletions
diff --git a/poky/meta/recipes-devtools/python/python3-attrs_23.2.0.bb b/poky/meta/recipes-devtools/python/python3-attrs_23.2.0.bb
index a638097988..e39b64306c 100644
--- a/poky/meta/recipes-devtools/python/python3-attrs_23.2.0.bb
+++ b/poky/meta/recipes-devtools/python/python3-attrs_23.2.0.bb
@@ -20,7 +20,6 @@ DEPENDS += " \
RDEPENDS:${PN}+= " \
python3-compression \
- python3-ctypes \
python3-crypt \
"
diff --git a/poky/meta/recipes-devtools/python/python3-certifi/CVE-2024-39689.patch b/poky/meta/recipes-devtools/python/python3-certifi/CVE-2024-39689.patch
new file mode 100644
index 0000000000..a2ecc15d2c
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3-certifi/CVE-2024-39689.patch
@@ -0,0 +1,69 @@
+From bd8153872e9c6fc98f4023df9c2deaffea2fa463 Mon Sep 17 00:00:00 2001
+From: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
+Date: Wed, 3 Jul 2024 21:34:29 -0400
+Subject: [PATCH] 2024.07.04 (#295)
+
+Co-authored-by: alex <772+alex@users.noreply.github.com>
+
+CVE: CVE-2024-39689
+
+Upstream-Status: Backport [https://github.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463]
+
+Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
+---
+ certifi/cacert.pem | 40 ----------------------------------------
+ 1 file changed, 40 deletions(-)
+
+diff --git a/certifi/cacert.pem b/certifi/cacert.pem
+index 1bec256..6bb8cf8 100644
+--- a/certifi/cacert.pem
++++ b/certifi/cacert.pem
+@@ -3857,46 +3857,6 @@ DgQWBBQxCpCPtsad0kRLgLWi5h+xEk8blTAKBggqhkjOPQQDAwNoADBlAjEA31SQ
+ +RHUjE7AwWHCFUyqqx0LMV87HOIAl0Qx5v5zli/altP+CAezNIm8BZ/3Hobui3A=
+ -----END CERTIFICATE-----
+
+-# Issuer: CN=GLOBALTRUST 2020 O=e-commerce monitoring GmbH
+-# Subject: CN=GLOBALTRUST 2020 O=e-commerce monitoring GmbH
+-# Label: "GLOBALTRUST 2020"
+-# Serial: 109160994242082918454945253
+-# MD5 Fingerprint: 8a:c7:6f:cb:6d:e3:cc:a2:f1:7c:83:fa:0e:78:d7:e8
+-# SHA1 Fingerprint: d0:67:c1:13:51:01:0c:aa:d0:c7:6a:65:37:31:16:26:4f:53:71:a2
+-# SHA256 Fingerprint: 9a:29:6a:51:82:d1:d4:51:a2:e3:7f:43:9b:74:da:af:a2:67:52:33:29:f9:0f:9a:0d:20:07:c3:34:e2:3c:9a
+------BEGIN CERTIFICATE-----
+-MIIFgjCCA2qgAwIBAgILWku9WvtPilv6ZeUwDQYJKoZIhvcNAQELBQAwTTELMAkG
+-A1UEBhMCQVQxIzAhBgNVBAoTGmUtY29tbWVyY2UgbW9uaXRvcmluZyBHbWJIMRkw
+-FwYDVQQDExBHTE9CQUxUUlVTVCAyMDIwMB4XDTIwMDIxMDAwMDAwMFoXDTQwMDYx
+-MDAwMDAwMFowTTELMAkGA1UEBhMCQVQxIzAhBgNVBAoTGmUtY29tbWVyY2UgbW9u
+-aXRvcmluZyBHbWJIMRkwFwYDVQQDExBHTE9CQUxUUlVTVCAyMDIwMIICIjANBgkq
+-hkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAri5WrRsc7/aVj6B3GyvTY4+ETUWiD59b
+-RatZe1E0+eyLinjF3WuvvcTfk0Uev5E4C64OFudBc/jbu9G4UeDLgztzOG53ig9Z
+-YybNpyrOVPu44sB8R85gfD+yc/LAGbaKkoc1DZAoouQVBGM+uq/ufF7MpotQsjj3
+-QWPKzv9pj2gOlTblzLmMCcpL3TGQlsjMH/1WljTbjhzqLL6FLmPdqqmV0/0plRPw
+-yJiT2S0WR5ARg6I6IqIoV6Lr/sCMKKCmfecqQjuCgGOlYx8ZzHyyZqjC0203b+J+
+-BlHZRYQfEs4kUmSFC0iAToexIiIwquuuvuAC4EDosEKAA1GqtH6qRNdDYfOiaxaJ
+-SaSjpCuKAsR49GiKweR6NrFvG5Ybd0mN1MkGco/PU+PcF4UgStyYJ9ORJitHHmkH
+-r96i5OTUawuzXnzUJIBHKWk7buis/UDr2O1xcSvy6Fgd60GXIsUf1DnQJ4+H4xj0
+-4KlGDfV0OoIu0G4skaMxXDtG6nsEEFZegB31pWXogvziB4xiRfUg3kZwhqG8k9Me
+-dKZssCz3AwyIDMvUclOGvGBG85hqwvG/Q/lwIHfKN0F5VVJjjVsSn8VoxIidrPIw
+-q7ejMZdnrY8XD2zHc+0klGvIg5rQmjdJBKuxFshsSUktq6HQjJLyQUp5ISXbY9e2
+-nKd+Qmn7OmMCAwEAAaNjMGEwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMC
+-AQYwHQYDVR0OBBYEFNwuH9FhN3nkq9XVsxJxaD1qaJwiMB8GA1UdIwQYMBaAFNwu
+-H9FhN3nkq9XVsxJxaD1qaJwiMA0GCSqGSIb3DQEBCwUAA4ICAQCR8EICaEDuw2jA
+-VC/f7GLDw56KoDEoqoOOpFaWEhCGVrqXctJUMHytGdUdaG/7FELYjQ7ztdGl4wJC
+-XtzoRlgHNQIw4Lx0SsFDKv/bGtCwr2zD/cuz9X9tAy5ZVp0tLTWMstZDFyySCstd
+-6IwPS3BD0IL/qMy/pJTAvoe9iuOTe8aPmxadJ2W8esVCgmxcB9CpwYhgROmYhRZf
+-+I/KARDOJcP5YBugxZfD0yyIMaK9MOzQ0MAS8cE54+X1+NZK3TTN+2/BT+MAi1bi
+-kvcoskJ3ciNnxz8RFbLEAwW+uxF7Cr+obuf/WEPPm2eggAe2HcqtbepBEX4tdJP7
+-wry+UUTF72glJ4DjyKDUEuzZpTcdN3y0kcra1LGWge9oXHYQSa9+pTeAsRxSvTOB
+-TI/53WXZFM2KJVj04sWDpQmQ1GwUY7VA3+vA/MRYfg0UFodUJ25W5HCEuGwyEn6C
+-MUO+1918oa2u1qsgEu8KwxCMSZY13At1XrFP1U80DhEgB3VDRemjEdqso5nCtnkn
+-4rnvyOL2NSl6dPrFf4IFYqYK6miyeUcGbvJXqBUzxvd4Sj1Ce2t+/vdG6tHrju+I
+-aFvowdlxfv1k7/9nR4hYJS8+hge9+6jlgqispdNpQ80xiEmEU5LAsTkbOYMBMMTy
+-qfrQA71yN2BWHzZ8vTmR9W0Nv3vXkg==
+------END CERTIFICATE-----
+-
+ # Issuer: CN=ANF Secure Server Root CA O=ANF Autoridad de Certificacion OU=ANF CA Raiz
+ # Subject: CN=ANF Secure Server Root CA O=ANF Autoridad de Certificacion OU=ANF CA Raiz
+ # Label: "ANF Secure Server Root CA"
+--
+2.40.0
diff --git a/poky/meta/recipes-devtools/python/python3-certifi_2024.2.2.bb b/poky/meta/recipes-devtools/python/python3-certifi_2024.2.2.bb
index 4e61b8d9d4..116add2079 100644
--- a/poky/meta/recipes-devtools/python/python3-certifi_2024.2.2.bb
+++ b/poky/meta/recipes-devtools/python/python3-certifi_2024.2.2.bb
@@ -7,6 +7,9 @@ HOMEPAGE = " http://certifi.io/"
LICENSE = "ISC"
LIC_FILES_CHKSUM = "file://LICENSE;md5=11618cb6a975948679286b1211bd573c"
+SRC_URI += "file://CVE-2024-39689.patch \
+ "
+
SRC_URI[sha256sum] = "0569859f95fc761b18b45ef421b1290a0f65f147e92a1e5eb3e635f9a5e4e66f"
inherit pypi setuptools3
diff --git a/poky/meta/recipes-devtools/python/python3-idna_3.6.bb b/poky/meta/recipes-devtools/python/python3-idna_3.7.bb
index 47c080cdf8..729aff1c46 100644
--- a/poky/meta/recipes-devtools/python/python3-idna_3.6.bb
+++ b/poky/meta/recipes-devtools/python/python3-idna_3.7.bb
@@ -1,9 +1,9 @@
SUMMARY = "Internationalised Domain Names in Applications"
HOMEPAGE = "https://github.com/kjd/idna"
LICENSE = "BSD-3-Clause & Python-2.0 & Unicode-TOU"
-LIC_FILES_CHKSUM = "file://LICENSE.md;md5=dbec47b98e1469f6a104c82ff9698cee"
+LIC_FILES_CHKSUM = "file://LICENSE.md;md5=204c0612e40a4dd46012a78d02c80fb1"
-SRC_URI[sha256sum] = "9ecdbbd083b06798ae1e86adcbfe8ab1479cf864e4ee30fe4e46a003d12491ca"
+SRC_URI[sha256sum] = "028ff3aadf0609c1fd278d8ea3089299412a7a8b9bd005dd08b9f8285bcb5cfc"
inherit pypi python_flit_core
diff --git a/poky/meta/recipes-devtools/python/python3-jinja2_3.1.4.bb b/poky/meta/recipes-devtools/python/python3-jinja2_3.1.6.bb
index 2c02037011..de2b251049 100644
--- a/poky/meta/recipes-devtools/python/python3-jinja2_3.1.4.bb
+++ b/poky/meta/recipes-devtools/python/python3-jinja2_3.1.6.bb
@@ -4,7 +4,7 @@ HOMEPAGE = "https://pypi.org/project/Jinja2/"
LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=5dc88300786f1c214c1e9827a5229462"
-SRC_URI[sha256sum] = "4a3aee7acbbe7303aede8e9648d13b8bf88a429282aa6122a993f0ac800cb369"
+SRC_URI[sha256sum] = "0137fb05990d35f1275a587e9aee6d56da821fc83491a0fb838183be43f66d6d"
PYPI_PACKAGE = "jinja2"
@@ -21,6 +21,9 @@ SRC_URI += " \
do_install_ptest() {
install -d ${D}${PTEST_PATH}/tests
cp -rf ${S}/tests/* ${D}${PTEST_PATH}/tests/
+
+ # test_async items require trio module
+ rm -f ${D}${PTEST_PATH}/tests/test_async.py ${D}${PTEST_PATH}/tests/test_async_filters.py
}
RDEPENDS:${PN}-ptest += " \
diff --git a/poky/meta/recipes-devtools/python/python3-lxml_5.0.0.bb b/poky/meta/recipes-devtools/python/python3-lxml_5.0.2.bb
index 66cb8b0938..c0b385c7ea 100644
--- a/poky/meta/recipes-devtools/python/python3-lxml_5.0.0.bb
+++ b/poky/meta/recipes-devtools/python/python3-lxml_5.0.2.bb
@@ -18,11 +18,10 @@ LIC_FILES_CHKSUM = "file://LICENSES.txt;md5=e4c045ebad958ead4b48008f70838403 \
DEPENDS += "libxml2 libxslt"
-SRC_URI[sha256sum] = "2219cbf790e701acf9a21a31ead75f983e73daf0eceb9da6990212e4d20ebefe"
+SRC_URI[sha256sum] = "6399703c40ba53e2c3b72fdb56cb908d2b83c08082ecf17de839b27e68d1e598"
SRC_URI += "${PYPI_SRC_URI}"
inherit pkgconfig pypi setuptools3
-PYPI_PACKAGE_EXT = "zip"
# {standard input}: Assembler messages:
# {standard input}:1488805: Error: branch out of range
diff --git a/poky/meta/recipes-devtools/python/python3-maturin/0001-Extract-extension-architecture-name-resolvation-code.patch b/poky/meta/recipes-devtools/python/python3-maturin/0001-Extract-extension-architecture-name-resolvation-code.patch
new file mode 100644
index 0000000000..f75d5a1ba8
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3-maturin/0001-Extract-extension-architecture-name-resolvation-code.patch
@@ -0,0 +1,107 @@
+From 42a97ee7100ad158d4b1ba6133ea13cc864a567f Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Vesa=20J=C3=A4=C3=A4skel=C3=A4inen?=
+ <vesa.jaaskelainen@vaisala.com>
+Date: Sun, 1 Sep 2024 09:23:10 +0300
+Subject: [PATCH 1/5] Extract extension architecture name resolvation code as
+ helper
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+This commit introduces helper InterpreterConfig.get_python_ext_arch() that
+can be used to determine the extension architecture name python uses in
+`ext_suffix` for this architecture.
+
+Upstream-Status: Backport [https://github.com/PyO3/maturin/commit/42a97ee7100ad158d4b1ba6133ea13cc864a567f]
+
+Signed-off-by: Vesa Jääskeläinen <vesa.jaaskelainen@vaisala.com>
+---
+ src/python_interpreter/config.rs | 18 ++++++------------
+ src/target.rs | 16 ++++++++++++++++
+ 2 files changed, 22 insertions(+), 12 deletions(-)
+
+diff --git a/src/python_interpreter/config.rs b/src/python_interpreter/config.rs
+index 912f9218..d76606f2 100644
+--- a/src/python_interpreter/config.rs
++++ b/src/python_interpreter/config.rs
+@@ -47,15 +47,7 @@ impl InterpreterConfig {
+ // Python 2 is not supported
+ return None;
+ }
+- let python_arch = if matches!(target.target_arch(), Arch::Armv6L | Arch::Armv7L) {
+- "arm"
+- } else if matches!(target.target_arch(), Arch::Powerpc64Le) && python_impl == PyPy {
+- "ppc_64"
+- } else if matches!(target.target_arch(), Arch::X86) && python_impl == PyPy {
+- "x86"
+- } else {
+- target.get_python_arch()
+- };
++ let python_ext_arch = target.get_python_ext_arch(python_impl);
+ // See https://github.com/pypa/auditwheel/issues/349
+ let target_env = match python_impl {
+ CPython => {
+@@ -77,7 +69,7 @@ impl InterpreterConfig {
+ let ldversion = format!("{}{}{}", major, minor, abiflags);
+ let ext_suffix = format!(
+ ".cpython-{}-{}-linux-{}.so",
+- ldversion, python_arch, target_env
++ ldversion, python_ext_arch, target_env
+ );
+ Some(Self {
+ major,
+@@ -90,7 +82,8 @@ impl InterpreterConfig {
+ }
+ (Os::Linux, PyPy) => {
+ let abi_tag = format!("pypy{}{}-{}", major, minor, PYPY_ABI_TAG);
+- let ext_suffix = format!(".{}-{}-linux-{}.so", abi_tag, python_arch, target_env);
++ let ext_suffix =
++ format!(".{}-{}-linux-{}.so", abi_tag, python_ext_arch, target_env);
+ Some(Self {
+ major,
+ minor,
+@@ -204,7 +197,8 @@ impl InterpreterConfig {
+ }
+ (Os::Emscripten, CPython) => {
+ let ldversion = format!("{}{}", major, minor);
+- let ext_suffix = format!(".cpython-{}-{}-emscripten.so", ldversion, python_arch);
++ let ext_suffix =
++ format!(".cpython-{}-{}-emscripten.so", ldversion, python_ext_arch);
+ Some(Self {
+ major,
+ minor,
+diff --git a/src/target.rs b/src/target.rs
+index dc7df0cf..84bae559 100644
+--- a/src/target.rs
++++ b/src/target.rs
+@@ -1,4 +1,5 @@
+ use crate::cross_compile::is_cross_compiling;
++use crate::python_interpreter::InterpreterKind;
+ use crate::PlatformTag;
+ use anyhow::{anyhow, bail, format_err, Result};
+ use platform_info::*;
+@@ -368,6 +369,21 @@ impl Target {
+ }
+ }
+
++ /// Returns the extension architecture name python uses in `ext_suffix` for this architecture.
++ pub fn get_python_ext_arch(&self, python_impl: InterpreterKind) -> &str {
++ if matches!(self.target_arch(), Arch::Armv6L | Arch::Armv7L) {
++ "arm"
++ } else if matches!(self.target_arch(), Arch::Powerpc64Le)
++ && python_impl == InterpreterKind::PyPy
++ {
++ "ppc_64"
++ } else if matches!(self.target_arch(), Arch::X86) && python_impl == InterpreterKind::PyPy {
++ "x86"
++ } else {
++ self.get_python_arch()
++ }
++ }
++
+ /// Returns the name python uses in `sys.platform` for this os
+ pub fn get_python_os(&self) -> &str {
+ match self.os {
+--
+2.34.1
+
diff --git a/poky/meta/recipes-devtools/python/python3-maturin/0002-Fix-cross-compilation-issue-with-linux-armv7l-archit.patch b/poky/meta/recipes-devtools/python/python3-maturin/0002-Fix-cross-compilation-issue-with-linux-armv7l-archit.patch
new file mode 100644
index 0000000000..4366dde111
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3-maturin/0002-Fix-cross-compilation-issue-with-linux-armv7l-archit.patch
@@ -0,0 +1,76 @@
+From 0c6b8cc84eff72ed21098029aaba079b899dbee2 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Vesa=20J=C3=A4=C3=A4skel=C3=A4inen?=
+ <vesa.jaaskelainen@vaisala.com>
+Date: Sun, 1 Sep 2024 09:23:40 +0300
+Subject: [PATCH 2/5] Fix cross compilation issue with linux-armv7l
+ architecture
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+When compiling under Yocto project for linux-armv7l target architecture
+.so files were generated incorrectly as:
+
+ rpds.cpython-312-armv7l-linux-gnueabihf.so
+
+Where as platform and EXT_SUFFIX are defined as:
+
+ >>> sysconfig.get_platform()
+ 'linux-armv7l'
+ >>> sysconfig.get_config_vars()['EXT_SUFFIX']
+ '.cpython-312-arm-linux-gnueabihf.so'
+
+Which should have caused the .so files as:
+
+ rpds.cpython-312-arm-linux-gnueabihf.so
+
+Upstream-Status: Backport [https://github.com/PyO3/maturin/commit/0c6b8cc84eff72ed21098029aaba079b899dbee2]
+
+Signed-off-by: Vesa Jääskeläinen <vesa.jaaskelainen@vaisala.com>
+---
+ src/python_interpreter/config.rs | 8 ++++----
+ 1 file changed, 4 insertions(+), 4 deletions(-)
+
+diff --git a/src/python_interpreter/config.rs b/src/python_interpreter/config.rs
+index d76606f2..5736aedc 100644
+--- a/src/python_interpreter/config.rs
++++ b/src/python_interpreter/config.rs
+@@ -306,7 +306,7 @@ impl InterpreterConfig {
+ format!(
+ ".cpython-{}-{}-{}-{}.{}",
+ abi_tag,
+- target.get_python_arch(),
++ target.get_python_ext_arch(interpreter_kind),
+ target.get_python_os(),
+ target_env,
+ file_ext,
+@@ -319,7 +319,7 @@ impl InterpreterConfig {
+ major,
+ minor,
+ abi_tag,
+- target.get_python_arch(),
++ target.get_python_ext_arch(interpreter_kind),
+ target.get_python_os(),
+ target_env,
+ file_ext,
+@@ -330,7 +330,7 @@ impl InterpreterConfig {
+ format!(
+ ".{}-{}-{}.{}",
+ abi_tag.replace('_', "-"),
+- target.get_python_arch(),
++ target.get_python_ext_arch(interpreter_kind),
+ target.get_python_os(),
+ file_ext,
+ )
+@@ -341,7 +341,7 @@ impl InterpreterConfig {
+ format!(
+ ".cpython-{}-{}-{}.{}",
+ abi_tag,
+- target.get_python_arch(),
++ target.get_python_ext_arch(interpreter_kind),
+ target.get_python_os(),
+ file_ext
+ )
+--
+2.34.1
+
diff --git a/poky/meta/recipes-devtools/python/python3-maturin/0003-Extract-extension-ABI-name-resolvation-code-as-helpe.patch b/poky/meta/recipes-devtools/python/python3-maturin/0003-Extract-extension-ABI-name-resolvation-code-as-helpe.patch
new file mode 100644
index 0000000000..b4a7f69492
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3-maturin/0003-Extract-extension-ABI-name-resolvation-code-as-helpe.patch
@@ -0,0 +1,98 @@
+From fa64426f3a98a0455721c23ec86bd2240708b45e Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Vesa=20J=C3=A4=C3=A4skel=C3=A4inen?=
+ <vesa.jaaskelainen@vaisala.com>
+Date: Sun, 1 Sep 2024 15:55:07 +0300
+Subject: [PATCH 3/5] Extract extension ABI name resolvation code as helper
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+This commit introduces helper InterpreterConfig.get_python_target_env()
+that can be used to determine the extension ABI python uses in
+`ext_suffix` for this architecture.
+
+Upstream-Status: Backport [https://github.com/PyO3/maturin/commit/fa64426f3a98a0455721c23ec86bd2240708b45e]
+
+Signed-off-by: Vesa Jääskeläinen <vesa.jaaskelainen@vaisala.com>
+---
+ src/python_interpreter/config.rs | 19 ++-----------------
+ src/target.rs | 20 ++++++++++++++++++++
+ 2 files changed, 22 insertions(+), 17 deletions(-)
+
+diff --git a/src/python_interpreter/config.rs b/src/python_interpreter/config.rs
+index 5736aedc..938e9955 100644
+--- a/src/python_interpreter/config.rs
++++ b/src/python_interpreter/config.rs
+@@ -48,17 +48,7 @@ impl InterpreterConfig {
+ return None;
+ }
+ let python_ext_arch = target.get_python_ext_arch(python_impl);
+- // See https://github.com/pypa/auditwheel/issues/349
+- let target_env = match python_impl {
+- CPython => {
+- if python_version >= (3, 11) {
+- target.target_env().to_string()
+- } else {
+- target.target_env().to_string().replace("musl", "gnu")
+- }
+- }
+- PyPy | GraalPy => "gnu".to_string(),
+- };
++ let target_env = target.get_python_target_env(python_impl, python_version);
+ match (target.target_os(), python_impl) {
+ (Os::Linux, CPython) => {
+ let abiflags = if python_version < (3, 8) {
+@@ -294,12 +284,7 @@ impl InterpreterConfig {
+ };
+ let file_ext = if target.is_windows() { "pyd" } else { "so" };
+ let ext_suffix = if target.is_linux() || target.is_macos() {
+- // See https://github.com/pypa/auditwheel/issues/349
+- let target_env = if (major, minor) >= (3, 11) {
+- target.target_env().to_string()
+- } else {
+- target.target_env().to_string().replace("musl", "gnu")
+- };
++ let target_env = target.get_python_target_env(interpreter_kind, (major, minor));
+ match interpreter_kind {
+ InterpreterKind::CPython => ext_suffix.unwrap_or_else(|| {
+ // Eg: .cpython-38-x86_64-linux-gnu.so
+diff --git a/src/target.rs b/src/target.rs
+index 84bae559..ad8ebaba 100644
+--- a/src/target.rs
++++ b/src/target.rs
+@@ -1,5 +1,6 @@
+ use crate::cross_compile::is_cross_compiling;
+ use crate::python_interpreter::InterpreterKind;
++use crate::python_interpreter::InterpreterKind::{CPython, GraalPy, PyPy};
+ use crate::PlatformTag;
+ use anyhow::{anyhow, bail, format_err, Result};
+ use platform_info::*;
+@@ -384,6 +385,25 @@ impl Target {
+ }
+ }
+
++ /// Returns the environment python uses in `ext_suffix` for this architecture.
++ pub fn get_python_target_env(
++ &self,
++ python_impl: InterpreterKind,
++ python_version: (usize, usize),
++ ) -> String {
++ match python_impl {
++ CPython => {
++ // For musl handling see https://github.com/pypa/auditwheel/issues/349
++ if python_version >= (3, 11) {
++ self.target_env().to_string()
++ } else {
++ self.target_env().to_string().replace("musl", "gnu")
++ }
++ }
++ PyPy | GraalPy => "gnu".to_string(),
++ }
++ }
++
+ /// Returns the name python uses in `sys.platform` for this os
+ pub fn get_python_os(&self) -> &str {
+ match self.os {
+--
+2.34.1
+
diff --git a/poky/meta/recipes-devtools/python/python3-maturin/0004-Fix-cross-compilation-issue-with-linux-ppc-architect.patch b/poky/meta/recipes-devtools/python/python3-maturin/0004-Fix-cross-compilation-issue-with-linux-ppc-architect.patch
new file mode 100644
index 0000000000..bda5dca8f6
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3-maturin/0004-Fix-cross-compilation-issue-with-linux-ppc-architect.patch
@@ -0,0 +1,68 @@
+From f2c892109a05db144e8b18bcbcf9c24fe8d977c4 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Vesa=20J=C3=A4=C3=A4skel=C3=A4inen?=
+ <vesa.jaaskelainen@vaisala.com>
+Date: Sun, 1 Sep 2024 15:55:16 +0300
+Subject: [PATCH 4/5] Fix cross compilation issue with linux-ppc architecture
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+When compiling under Yocto project for linux-ppc target architecture
+.so files were generated incorrectly as:
+
+ rpds.cpython-312-ppc-linux-gnu.so
+
+Where as platform and EXT_SUFFIX are defined as:
+
+ >>> sysconfig.get_platform()
+ 'linux-ppc'
+ >>> sysconfig.get_config_vars()['EXT_SUFFIX']
+ '.cpython-312-powerpc-linux-gnu.so'
+
+Which should have caused the .so files as:
+
+ rpds.cpython-312-powerpc-linux-gnu.so
+
+Upstream-Status: Backport [https://github.com/PyO3/maturin/commit/f2c892109a05db144e8b18bcbcf9c24fe8d977c4]
+
+Signed-off-by: Vesa Jääskeläinen <vesa.jaaskelainen@vaisala.com>
+---
+ src/python_interpreter/config.rs | 8 ++++++++
+ src/target.rs | 2 ++
+ 2 files changed, 10 insertions(+)
+
+diff --git a/src/python_interpreter/config.rs b/src/python_interpreter/config.rs
+index 938e9955..8f883887 100644
+--- a/src/python_interpreter/config.rs
++++ b/src/python_interpreter/config.rs
+@@ -424,6 +424,14 @@ mod test {
+ ".cpython-310-powerpc64le-linux-gnu.so"
+ );
+
++ let sysconfig = InterpreterConfig::lookup_one(
++ &Target::from_target_triple(Some("powerpc-unknown-linux-gnu".to_string())).unwrap(),
++ InterpreterKind::CPython,
++ (3, 10),
++ )
++ .unwrap();
++ assert_eq!(sysconfig.ext_suffix, ".cpython-310-powerpc-linux-gnu.so");
++
+ let sysconfig = InterpreterConfig::lookup_one(
+ &Target::from_target_triple(Some("s390x-unknown-linux-gnu".to_string())).unwrap(),
+ InterpreterKind::CPython,
+diff --git a/src/target.rs b/src/target.rs
+index ad8ebaba..93afd9bb 100644
+--- a/src/target.rs
++++ b/src/target.rs
+@@ -380,6 +380,8 @@ impl Target {
+ "ppc_64"
+ } else if matches!(self.target_arch(), Arch::X86) && python_impl == InterpreterKind::PyPy {
+ "x86"
++ } else if matches!(self.target_arch(), Arch::Powerpc) {
++ "powerpc"
+ } else {
+ self.get_python_arch()
+ }
+--
+2.34.1
+
diff --git a/poky/meta/recipes-devtools/python/python3-maturin/0005-Fix-cross-compilation-issue-with-linux-mips64-archit.patch b/poky/meta/recipes-devtools/python/python3-maturin/0005-Fix-cross-compilation-issue-with-linux-mips64-archit.patch
new file mode 100644
index 0000000000..b24196d5dd
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3-maturin/0005-Fix-cross-compilation-issue-with-linux-mips64-archit.patch
@@ -0,0 +1,82 @@
+From 5fe643579bcc63d824f6a0f0936fff451c622903 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Vesa=20J=C3=A4=C3=A4skel=C3=A4inen?=
+ <vesa.jaaskelainen@vaisala.com>
+Date: Sun, 1 Sep 2024 15:55:54 +0300
+Subject: [PATCH 5/5] Fix cross compilation issue with linux-mips64
+ architecture
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+When compiling under Yocto project for linux-mips64 target architecture
+.so files were generated incorrectly as:
+
+ rpds.cpython-312-mips64-linux-gnu.so
+
+Where as platform and EXT_SUFFIX are defined as:
+
+ >>> sysconfig.get_platform()
+ 'linux-mips64'
+ >>> sysconfig.get_config_vars()['EXT_SUFFIX']
+ '.cpython-312-mips64-linux-gnuabi64.so'
+
+Which should have caused the .so files as:
+
+ rpds.cpython-312-mips64-linux-gnuabi64.so
+
+Upstream-Status: Backport [https://github.com/PyO3/maturin/commit/5fe643579bcc63d824f6a0f0936fff451c622903]
+
+Signed-off-by: Vesa Jääskeläinen <vesa.jaaskelainen@vaisala.com>
+---
+ src/python_interpreter/config.rs | 19 +++++++++++++++++++
+ src/target.rs | 4 +++-
+ 2 files changed, 22 insertions(+), 1 deletion(-)
+
+diff --git a/src/python_interpreter/config.rs b/src/python_interpreter/config.rs
+index 8f883887..ef656010 100644
+--- a/src/python_interpreter/config.rs
++++ b/src/python_interpreter/config.rs
+@@ -432,6 +432,25 @@ mod test {
+ .unwrap();
+ assert_eq!(sysconfig.ext_suffix, ".cpython-310-powerpc-linux-gnu.so");
+
++ let sysconfig = InterpreterConfig::lookup_one(
++ &Target::from_target_triple(Some("mips64-unknown-linux-gnu".to_string())).unwrap(),
++ InterpreterKind::CPython,
++ (3, 10),
++ )
++ .unwrap();
++ assert_eq!(
++ sysconfig.ext_suffix,
++ ".cpython-310-mips64-linux-gnuabi64.so"
++ );
++
++ let sysconfig = InterpreterConfig::lookup_one(
++ &Target::from_target_triple(Some("mips-unknown-linux-gnu".to_string())).unwrap(),
++ InterpreterKind::CPython,
++ (3, 10),
++ )
++ .unwrap();
++ assert_eq!(sysconfig.ext_suffix, ".cpython-310-mips-linux-gnu.so");
++
+ let sysconfig = InterpreterConfig::lookup_one(
+ &Target::from_target_triple(Some("s390x-unknown-linux-gnu".to_string())).unwrap(),
+ InterpreterKind::CPython,
+diff --git a/src/target.rs b/src/target.rs
+index 93afd9bb..25fc6c07 100644
+--- a/src/target.rs
++++ b/src/target.rs
+@@ -396,7 +396,9 @@ impl Target {
+ match python_impl {
+ CPython => {
+ // For musl handling see https://github.com/pypa/auditwheel/issues/349
+- if python_version >= (3, 11) {
++ if matches!(self.target_arch(), Arch::Mips64 | Arch::Mips64el) && self.is_linux() {
++ "gnuabi64".to_string()
++ } else if python_version >= (3, 11) {
+ self.target_env().to_string()
+ } else {
+ self.target_env().to_string().replace("musl", "gnu")
+--
+2.34.1
+
diff --git a/poky/meta/recipes-devtools/python/python3-maturin_1.4.0.bb b/poky/meta/recipes-devtools/python/python3-maturin_1.4.0.bb
index ed19ee647a..7322de0d08 100644
--- a/poky/meta/recipes-devtools/python/python3-maturin_1.4.0.bb
+++ b/poky/meta/recipes-devtools/python/python3-maturin_1.4.0.bb
@@ -7,6 +7,13 @@ LIC_FILES_CHKSUM = "file://license-apache;md5=1836efb2eb779966696f473ee8540542 \
SRC_URI += "file://0001-Add-32-bit-RISC-V-support.patch"
SRC_URI[sha256sum] = "ed12e1768094a7adeafc3a74ebdb8dc2201fa64c4e7e31f14cfc70378bf93790"
+SRC_URI:append = "\
+ file://0001-Extract-extension-architecture-name-resolvation-code.patch \
+ file://0002-Fix-cross-compilation-issue-with-linux-armv7l-archit.patch \
+ file://0003-Extract-extension-ABI-name-resolvation-code-as-helpe.patch \
+ file://0004-Fix-cross-compilation-issue-with-linux-ppc-architect.patch \
+ file://0005-Fix-cross-compilation-issue-with-linux-mips64-archit.patch \
+"
S = "${WORKDIR}/maturin-${PV}"
diff --git a/poky/meta/recipes-devtools/python/python3-poetry-core_1.9.0.bb b/poky/meta/recipes-devtools/python/python3-poetry-core_1.9.0.bb
index 540fdffaed..d1a8b939c0 100644
--- a/poky/meta/recipes-devtools/python/python3-poetry-core_1.9.0.bb
+++ b/poky/meta/recipes-devtools/python/python3-poetry-core_1.9.0.bb
@@ -36,7 +36,6 @@ RDEPENDS:${PN}:append:class-target = "\
RDEPENDS:${PN} += "\
python3-pip \
- python3-six \
"
BBCLASSEXTEND = "native nativesdk"
diff --git a/poky/meta/recipes-devtools/python/python3-pycryptodome_3.20.0.bb b/poky/meta/recipes-devtools/python/python3-pycryptodome_3.20.0.bb
index d24fa58d43..6c93c205ac 100644
--- a/poky/meta/recipes-devtools/python/python3-pycryptodome_3.20.0.bb
+++ b/poky/meta/recipes-devtools/python/python3-pycryptodome_3.20.0.bb
@@ -1,5 +1,5 @@
require python-pycryptodome.inc
-inherit setuptools3
+inherit python_setuptools_build_meta
SRC_URI[sha256sum] = "09609209ed7de61c2b560cc5c8c4fbf892f8b15b1faf7e4cbffac97db1fffda7"
diff --git a/poky/meta/recipes-devtools/python/python3-pycryptodomex_3.20.0.bb b/poky/meta/recipes-devtools/python/python3-pycryptodomex_3.20.0.bb
index 2673ea8326..54578d2850 100644
--- a/poky/meta/recipes-devtools/python/python3-pycryptodomex_3.20.0.bb
+++ b/poky/meta/recipes-devtools/python/python3-pycryptodomex_3.20.0.bb
@@ -1,5 +1,5 @@
require python-pycryptodome.inc
-inherit setuptools3
+inherit python_setuptools_build_meta
SRC_URI[sha256sum] = "7a710b79baddd65b806402e14766c721aee8fb83381769c27920f26476276c1e"
diff --git a/poky/meta/recipes-devtools/python/python3-requests/environment.d-python3-requests.sh b/poky/meta/recipes-devtools/python/python3-requests/environment.d-python3-requests.sh
new file mode 100644
index 0000000000..400972814b
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3-requests/environment.d-python3-requests.sh
@@ -0,0 +1,11 @@
+# Respect host env REQUESTS_CA_BUNDLE first, then auto-detected host cert, then cert in buildtools
+# CAFILE/CAPATH is auto-deteced when source buildtools
+if [ -z "${REQUESTS_CA_BUNDLE:-}" ]; then
+ if [ -n "${CAFILE:-}" ];then
+ export REQUESTS_CA_BUNDLE="$CAFILE"
+ elif [ -e "${OECORE_NATIVE_SYSROOT}/etc/ssl/certs/ca-certificates.crt" ];then
+ export REQUESTS_CA_BUNDLE="${OECORE_NATIVE_SYSROOT}/etc/ssl/certs/ca-certificates.crt"
+ fi
+fi
+
+export BB_ENV_PASSTHROUGH_ADDITIONS="${BB_ENV_PASSTHROUGH_ADDITIONS:-} REQUESTS_CA_BUNDLE"
diff --git a/poky/meta/recipes-devtools/python/python3-requests_2.31.0.bb b/poky/meta/recipes-devtools/python/python3-requests_2.31.0.bb
deleted file mode 100644
index 287b4f8eee..0000000000
--- a/poky/meta/recipes-devtools/python/python3-requests_2.31.0.bb
+++ /dev/null
@@ -1,24 +0,0 @@
-SUMMARY = "Python HTTP for Humans."
-HOMEPAGE = "https://requests.readthedocs.io"
-LICENSE = "Apache-2.0"
-LIC_FILES_CHKSUM = "file://LICENSE;md5=34400b68072d710fecd0a2940a0d1658"
-
-SRC_URI[sha256sum] = "942c5a758f98d790eaed1a29cb6eefc7ffb0d1cf7af05c3d2791656dbd6ad1e1"
-
-inherit pypi setuptools3
-
-RDEPENDS:${PN} += " \
- python3-certifi \
- python3-email \
- python3-json \
- python3-netserver \
- python3-pysocks \
- python3-urllib3 \
- python3-chardet \
- python3-idna \
- python3-compression \
-"
-
-CVE_PRODUCT = "requests"
-
-BBCLASSEXTEND = "native nativesdk"
diff --git a/poky/meta/recipes-devtools/python/python3-requests_2.32.4.bb b/poky/meta/recipes-devtools/python/python3-requests_2.32.4.bb
new file mode 100644
index 0000000000..b86ecfba52
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3-requests_2.32.4.bb
@@ -0,0 +1,35 @@
+SUMMARY = "Python HTTP for Humans."
+HOMEPAGE = "https://requests.readthedocs.io"
+LICENSE = "Apache-2.0"
+LIC_FILES_CHKSUM = "file://LICENSE;md5=34400b68072d710fecd0a2940a0d1658"
+
+SRC_URI:append:class-nativesdk = " \
+ file://environment.d-python3-requests.sh \
+"
+
+SRC_URI[sha256sum] = "27d0316682c8a29834d3264820024b62a36942083d52caf2f14c0591336d3422"
+
+inherit pypi python_setuptools_build_meta
+
+do_install:append:class-nativesdk() {
+ mkdir -p ${D}${SDKPATHNATIVE}/environment-setup.d
+ install -m 644 ${WORKDIR}/environment.d-python3-requests.sh ${D}${SDKPATHNATIVE}/environment-setup.d/python3-requests.sh
+}
+
+RDEPENDS:${PN} += " \
+ python3-certifi \
+ python3-email \
+ python3-json \
+ python3-netserver \
+ python3-pysocks \
+ python3-urllib3 \
+ python3-chardet \
+ python3-idna \
+ python3-compression \
+"
+
+FILES:${PN}:append:class-nativesdk = " ${SDKPATHNATIVE}/environment-setup.d/python3-requests.sh"
+
+CVE_PRODUCT = "requests"
+
+BBCLASSEXTEND = "native nativesdk"
diff --git a/poky/meta/recipes-devtools/python/python3-setuptools-scm/0001-respect-GIT_CEILING_DIRECTORIES.patch b/poky/meta/recipes-devtools/python/python3-setuptools-scm/0001-respect-GIT_CEILING_DIRECTORIES.patch
new file mode 100644
index 0000000000..7d2808cc0c
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3-setuptools-scm/0001-respect-GIT_CEILING_DIRECTORIES.patch
@@ -0,0 +1,36 @@
+From a1cc419a118560d63e1ab8838c256a3622185750 Mon Sep 17 00:00:00 2001
+From: Etienne Cordonnier <ecordonnier@snap.com>
+Date: Thu, 13 Feb 2025 15:44:40 +0100
+Subject: [PATCH] respect GIT_CEILING_DIRECTORIES
+
+Fix for https://github.com/pypa/setuptools-scm/issues/1103
+
+When searching for the root-directory of the git repository e.g. with git rev-parse --show-toplevel,
+git stops the search when reaching $GIT_CEILING_DIRECTORIES. By ignoring this variable, the function
+_git_toplevel can go above the real git repository (e.g. when packaging a tarball without .git repository),
+and then runs "git archive" on an unrelated git repository.
+
+Upstream-Status: Pending
+
+Signed-off-by: Ross Burton <ross.burton@arm.com>
+Signed-off-by: Etienne Cordonnier <ecordonnier@snap.com>
+---
+ src/setuptools_scm/_run_cmd.py | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/setuptools_scm/_run_cmd.py b/src/setuptools_scm/_run_cmd.py
+index f2a8285..7e13d9f 100644
+--- a/src/setuptools_scm/_run_cmd.py
++++ b/src/setuptools_scm/_run_cmd.py
+@@ -98,7 +98,7 @@ def no_git_env(env: Mapping[str, str]) -> dict[str, str]:
+ k: v
+ for k, v in env.items()
+ if not k.startswith("GIT_")
+- or k in ("GIT_EXEC_PATH", "GIT_SSH", "GIT_SSH_COMMAND")
++ or k in ("GIT_CEILING_DIRECTORIES", "GIT_EXEC_PATH", "GIT_SSH", "GIT_SSH_COMMAND")
+ }
+
+
+--
+2.43.0
+
diff --git a/poky/meta/recipes-devtools/python/python3-setuptools-scm_8.0.4.bb b/poky/meta/recipes-devtools/python/python3-setuptools-scm_8.0.4.bb
index 64b5050c3b..d5f8358a61 100644
--- a/poky/meta/recipes-devtools/python/python3-setuptools-scm_8.0.4.bb
+++ b/poky/meta/recipes-devtools/python/python3-setuptools-scm_8.0.4.bb
@@ -6,6 +6,7 @@ argument or in a SCM managed file."
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=838c366f69b72c5df05c96dff79b35f2"
+SRC_URI += "file://0001-respect-GIT_CEILING_DIRECTORIES.patch"
SRC_URI[sha256sum] = "b5f43ff6800669595193fd09891564ee9d1d7dcb196cab4b2506d53a2e1c95c7"
inherit pypi python_setuptools_build_meta
diff --git a/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2024-6345.patch b/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2024-6345.patch
new file mode 100644
index 0000000000..ac520be74a
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2024-6345.patch
@@ -0,0 +1,312 @@
+From 88807c7062788254f654ea8c03427adc859321f0 Mon Sep 17 00:00:00 2001
+From: Jason R. Coombs <jaraco@jaraco.com>
+Date: Mon Apr 29 20:01:38 2024 -0400
+Subject: [PATCH] Merge pull request #4332 from pypa/debt/package-index-vcs
+
+Modernize package_index VCS handling
+
+CVE: CVE-2024-6345
+
+Upstream-Status: Backport [https://github.com/pypa/setuptools/commit/88807c7062788254f654ea8c03427adc859321f0]
+
+Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
+---
+ setup.cfg | 1 +
+ setuptools/package_index.py | 145 ++++++++++++++------------
+ setuptools/tests/test_packageindex.py | 56 +++++-----
+ 3 files changed, 106 insertions(+), 96 deletions(-)
+
+diff --git a/setup.cfg b/setup.cfg
+index edf9798..238d00a 100644
+--- a/setup.cfg
++++ b/setup.cfg
+@@ -65,6 +65,7 @@ testing =
+ sys_platform != "cygwin"
+ jaraco.develop >= 7.21; python_version >= "3.9" and sys_platform != "cygwin"
+ pytest-home >= 0.5
++ pytest-subprocess
+ testing-integration =
+ pytest
+ pytest-xdist
+diff --git a/setuptools/package_index.py b/setuptools/package_index.py
+index 271aa97..00a972d 100644
+--- a/setuptools/package_index.py
++++ b/setuptools/package_index.py
+@@ -1,6 +1,7 @@
+ """PyPI and direct package downloading."""
+
+ import sys
++import subprocess
+ import os
+ import re
+ import io
+@@ -585,7 +586,7 @@ class PackageIndex(Environment):
+ scheme = URL_SCHEME(spec)
+ if scheme:
+ # It's a url, download it to tmpdir
+- found = self._download_url(scheme.group(1), spec, tmpdir)
++ found = self._download_url(spec, tmpdir)
+ base, fragment = egg_info_for_url(spec)
+ if base.endswith('.py'):
+ found = self.gen_setup(found, fragment, tmpdir)
+@@ -814,7 +815,7 @@ class PackageIndex(Environment):
+ else:
+ raise DistutilsError("Download error for %s: %s" % (url, v)) from v
+
+- def _download_url(self, scheme, url, tmpdir):
++ def _download_url(self, url, tmpdir):
+ # Determine download filename
+ #
+ name, fragment = egg_info_for_url(url)
+@@ -829,19 +830,59 @@ class PackageIndex(Environment):
+
+ filename = os.path.join(tmpdir, name)
+
+- # Download the file
+- #
+- if scheme == 'svn' or scheme.startswith('svn+'):
+- return self._download_svn(url, filename)
+- elif scheme == 'git' or scheme.startswith('git+'):
+- return self._download_git(url, filename)
+- elif scheme.startswith('hg+'):
+- return self._download_hg(url, filename)
+- elif scheme == 'file':
+- return urllib.request.url2pathname(urllib.parse.urlparse(url)[2])
+- else:
+- self.url_ok(url, True) # raises error if not allowed
+- return self._attempt_download(url, filename)
++ return self._download_vcs(url, filename) or self._download_other(url, filename)
++
++ @staticmethod
++ def _resolve_vcs(url):
++ """
++ >>> rvcs = PackageIndex._resolve_vcs
++ >>> rvcs('git+http://foo/bar')
++ 'git'
++ >>> rvcs('hg+https://foo/bar')
++ 'hg'
++ >>> rvcs('git:myhost')
++ 'git'
++ >>> rvcs('hg:myhost')
++ >>> rvcs('http://foo/bar')
++ """
++ scheme = urllib.parse.urlsplit(url).scheme
++ pre, sep, post = scheme.partition('+')
++ # svn and git have their own protocol; hg does not
++ allowed = set(['svn', 'git'] + ['hg'] * bool(sep))
++ return next(iter({pre} & allowed), None)
++
++ def _download_vcs(self, url, spec_filename):
++ vcs = self._resolve_vcs(url)
++ if not vcs:
++ return
++ if vcs == 'svn':
++ raise DistutilsError(
++ f"Invalid config, SVN download is not supported: {url}"
++ )
++
++ filename, _, _ = spec_filename.partition('#')
++ url, rev = self._vcs_split_rev_from_url(url)
++
++ self.info(f"Doing {vcs} clone from {url} to {filename}")
++ subprocess.check_call([vcs, 'clone', '--quiet', url, filename])
++
++ co_commands = dict(
++ git=[vcs, '-C', filename, 'checkout', '--quiet', rev],
++ hg=[vcs, '--cwd', filename, 'up', '-C', '-r', rev, '-q'],
++ )
++ if rev is not None:
++ self.info(f"Checking out {rev}")
++ subprocess.check_call(co_commands[vcs])
++
++ return filename
++
++ def _download_other(self, url, filename):
++ scheme = urllib.parse.urlsplit(url).scheme
++ if scheme == 'file': # pragma: no cover
++ return urllib.request.url2pathname(urllib.parse.urlparse(url).path)
++ # raise error if not allowed
++ self.url_ok(url, True)
++ return self._attempt_download(url, filename)
+
+ def scan_url(self, url):
+ self.process_url(url, True)
+@@ -857,64 +898,36 @@ class PackageIndex(Environment):
+ os.unlink(filename)
+ raise DistutilsError(f"Unexpected HTML page found at {url}")
+
+- def _download_svn(self, url, _filename):
+- raise DistutilsError(f"Invalid config, SVN download is not supported: {url}")
+-
+ @staticmethod
+- def _vcs_split_rev_from_url(url, pop_prefix=False):
+- scheme, netloc, path, query, frag = urllib.parse.urlsplit(url)
++ def _vcs_split_rev_from_url(url):
++ """
++ Given a possible VCS URL, return a clean URL and resolved revision if any.
++ >>> vsrfu = PackageIndex._vcs_split_rev_from_url
++ >>> vsrfu('git+https://github.com/pypa/setuptools@v69.0.0#egg-info=setuptools')
++ ('https://github.com/pypa/setuptools', 'v69.0.0')
++ >>> vsrfu('git+https://github.com/pypa/setuptools#egg-info=setuptools')
++ ('https://github.com/pypa/setuptools', None)
++ >>> vsrfu('http://foo/bar')
++ ('http://foo/bar', None)
++ """
++ parts = urllib.parse.urlsplit(url)
+
+- scheme = scheme.split('+', 1)[-1]
++ clean_scheme = parts.scheme.split('+', 1)[-1]
+
+ # Some fragment identification fails
+- path = path.split('#', 1)[0]
+-
+- rev = None
+- if '@' in path:
+- path, rev = path.rsplit('@', 1)
+-
+- # Also, discard fragment
+- url = urllib.parse.urlunsplit((scheme, netloc, path, query, ''))
+-
+- return url, rev
+-
+- def _download_git(self, url, filename):
+- filename = filename.split('#', 1)[0]
+- url, rev = self._vcs_split_rev_from_url(url, pop_prefix=True)
+-
+- self.info("Doing git clone from %s to %s", url, filename)
+- os.system("git clone --quiet %s %s" % (url, filename))
+-
+- if rev is not None:
+- self.info("Checking out %s", rev)
+- os.system(
+- "git -C %s checkout --quiet %s"
+- % (
+- filename,
+- rev,
+- )
+- )
++ no_fragment_path, _, _ = parts.path.partition('#')
+
+- return filename
++ pre, sep, post = no_fragment_path.rpartition('@')
++ clean_path, rev = (pre, post) if sep else (post, None)
+
+- def _download_hg(self, url, filename):
+- filename = filename.split('#', 1)[0]
+- url, rev = self._vcs_split_rev_from_url(url, pop_prefix=True)
++ resolved = parts._replace(
++ scheme=clean_scheme,
++ path=clean_path,
++ # discard the fragment
++ fragment='',
++ ).geturl()
+
+- self.info("Doing hg clone from %s to %s", url, filename)
+- os.system("hg clone --quiet %s %s" % (url, filename))
+-
+- if rev is not None:
+- self.info("Updating to %s", rev)
+- os.system(
+- "hg --cwd %s up -C -r %s -q"
+- % (
+- filename,
+- rev,
+- )
+- )
+-
+- return filename
++ return resolved, rev
+
+ def debug(self, msg, *args):
+ log.debug(msg, *args)
+diff --git a/setuptools/tests/test_packageindex.py b/setuptools/tests/test_packageindex.py
+index 41b9661..e4cd91a 100644
+--- a/setuptools/tests/test_packageindex.py
++++ b/setuptools/tests/test_packageindex.py
+@@ -2,7 +2,6 @@ import distutils.errors
+ import urllib.request
+ import urllib.error
+ import http.client
+-from unittest import mock
+
+ import pytest
+
+@@ -171,49 +170,46 @@ class TestPackageIndex:
+ assert dists[0].version == ''
+ assert dists[1].version == vc
+
+- def test_download_git_with_rev(self, tmpdir):
++ def test_download_git_with_rev(self, tmp_path, fp):
+ url = 'git+https://github.example/group/project@master#egg=foo'
+ index = setuptools.package_index.PackageIndex()
+
+- with mock.patch("os.system") as os_system_mock:
+- result = index.download(url, str(tmpdir))
++ expected_dir = tmp_path / 'project@master'
++ fp.register([
++ 'git',
++ 'clone',
++ '--quiet',
++ 'https://github.example/group/project',
++ expected_dir,
++ ])
++ fp.register(['git', '-C', expected_dir, 'checkout', '--quiet', 'master'])
+
+- os_system_mock.assert_called()
++ result = index.download(url, tmp_path)
+
+- expected_dir = str(tmpdir / 'project@master')
+- expected = (
+- 'git clone --quiet ' 'https://github.example/group/project {expected_dir}'
+- ).format(**locals())
+- first_call_args = os_system_mock.call_args_list[0][0]
+- assert first_call_args == (expected,)
++ assert result == str(expected_dir)
++ assert len(fp.calls) == 2
+
+- tmpl = 'git -C {expected_dir} checkout --quiet master'
+- expected = tmpl.format(**locals())
+- assert os_system_mock.call_args_list[1][0] == (expected,)
+- assert result == expected_dir
+-
+- def test_download_git_no_rev(self, tmpdir):
++ def test_download_git_no_rev(self, tmp_path, fp):
+ url = 'git+https://github.example/group/project#egg=foo'
+ index = setuptools.package_index.PackageIndex()
+
+- with mock.patch("os.system") as os_system_mock:
+- result = index.download(url, str(tmpdir))
+-
+- os_system_mock.assert_called()
+-
+- expected_dir = str(tmpdir / 'project')
+- expected = (
+- 'git clone --quiet ' 'https://github.example/group/project {expected_dir}'
+- ).format(**locals())
+- os_system_mock.assert_called_once_with(expected)
+-
+- def test_download_svn(self, tmpdir):
++ expected_dir = tmp_path / 'project'
++ fp.register([
++ 'git',
++ 'clone',
++ '--quiet',
++ 'https://github.example/group/project',
++ expected_dir,
++ ])
++ index.download(url, tmp_path)
++
++ def test_download_svn(self, tmp_path):
+ url = 'svn+https://svn.example/project#egg=foo'
+ index = setuptools.package_index.PackageIndex()
+
+ msg = r".*SVN download is not supported.*"
+ with pytest.raises(distutils.errors.DistutilsError, match=msg):
+- index.download(url, str(tmpdir))
++ index.download(url, tmp_path)
+
+
+ class TestContentCheckers:
+--
+2.40.0
+
diff --git a/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2025-47273-pre1.patch b/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2025-47273-pre1.patch
new file mode 100644
index 0000000000..72bcaea435
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2025-47273-pre1.patch
@@ -0,0 +1,54 @@
+From d8390feaa99091d1ba9626bec0e4ba7072fc507a Mon Sep 17 00:00:00 2001
+From: "Jason R. Coombs" <jaraco@jaraco.com>
+Date: Sat, 19 Apr 2025 12:49:55 -0400
+Subject: [PATCH] Extract _resolve_download_filename with test.
+
+Upstream-Status: Backport [https://github.com/pypa/setuptools/commit/d8390feaa99091d1ba9626bec0e4ba7072fc507a]
+CVE: CVE-2025-47273 #Dependency Patch
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ setuptools/package_index.py | 20 ++++++++++++++++----
+ 1 file changed, 16 insertions(+), 4 deletions(-)
+
+diff --git a/setuptools/package_index.py b/setuptools/package_index.py
+index 00a972d..d460fcb 100644
+--- a/setuptools/package_index.py
++++ b/setuptools/package_index.py
+@@ -815,9 +815,16 @@ class PackageIndex(Environment):
+ else:
+ raise DistutilsError("Download error for %s: %s" % (url, v)) from v
+
+- def _download_url(self, url, tmpdir):
+- # Determine download filename
+- #
++ @staticmethod
++ def _resolve_download_filename(url, tmpdir):
++ """
++ >>> du = PackageIndex._resolve_download_filename
++ >>> root = getfixture('tmp_path')
++ >>> url = 'https://files.pythonhosted.org/packages/a9/5a/0db.../setuptools-78.1.0.tar.gz'
++ >>> import pathlib
++ >>> str(pathlib.Path(du(url, root)).relative_to(root))
++ 'setuptools-78.1.0.tar.gz'
++ """
+ name, fragment = egg_info_for_url(url)
+ if name:
+ while '..' in name:
+@@ -828,8 +835,13 @@ class PackageIndex(Environment):
+ if name.endswith('.egg.zip'):
+ name = name[:-4] # strip the extra .zip before download
+
+- filename = os.path.join(tmpdir, name)
++ return os.path.join(tmpdir, name)
+
++ def _download_url(self, url, tmpdir):
++ """
++ Determine the download filename.
++ """
++ filename = self._resolve_download_filename(url, tmpdir)
+ return self._download_vcs(url, filename) or self._download_other(url, filename)
+
+ @staticmethod
+--
+2.25.1
+
diff --git a/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2025-47273.patch b/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2025-47273.patch
new file mode 100644
index 0000000000..be6617e0f6
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2025-47273.patch
@@ -0,0 +1,59 @@
+From 250a6d17978f9f6ac3ac887091f2d32886fbbb0b Mon Sep 17 00:00:00 2001
+From: "Jason R. Coombs" <jaraco@jaraco.com>
+Date: Sat, 19 Apr 2025 13:03:47 -0400
+Subject: [PATCH] Add a check to ensure the name resolves relative to the
+ tmpdir.
+
+Closes #4946
+
+Upstream-Status: Backport [https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b]
+CVE: CVE-2025-47273
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ setuptools/package_index.py | 18 ++++++++++++++++--
+ 1 file changed, 16 insertions(+), 2 deletions(-)
+
+diff --git a/setuptools/package_index.py b/setuptools/package_index.py
+index d460fcb..6c7874d 100644
+--- a/setuptools/package_index.py
++++ b/setuptools/package_index.py
+@@ -818,12 +818,20 @@ class PackageIndex(Environment):
+ @staticmethod
+ def _resolve_download_filename(url, tmpdir):
+ """
++ >>> import pathlib
+ >>> du = PackageIndex._resolve_download_filename
+ >>> root = getfixture('tmp_path')
+ >>> url = 'https://files.pythonhosted.org/packages/a9/5a/0db.../setuptools-78.1.0.tar.gz'
+- >>> import pathlib
+ >>> str(pathlib.Path(du(url, root)).relative_to(root))
+ 'setuptools-78.1.0.tar.gz'
++
++ Ensures the target is always in tmpdir.
++
++ >>> url = 'https://anyhost/%2fhome%2fuser%2f.ssh%2fauthorized_keys'
++ >>> du(url, root)
++ Traceback (most recent call last):
++ ...
++ ValueError: Invalid filename...
+ """
+ name, fragment = egg_info_for_url(url)
+ if name:
+@@ -835,7 +843,13 @@ class PackageIndex(Environment):
+ if name.endswith('.egg.zip'):
+ name = name[:-4] # strip the extra .zip before download
+
+- return os.path.join(tmpdir, name)
++ filename = os.path.join(tmpdir, name)
++
++ # ensure path resolves within the tmpdir
++ if not filename.startswith(str(tmpdir)):
++ raise ValueError(f"Invalid filename {filename}")
++
++ return filename
+
+ def _download_url(self, url, tmpdir):
+ """
+--
+2.25.1
+
diff --git a/poky/meta/recipes-devtools/python/python3-setuptools_69.1.1.bb b/poky/meta/recipes-devtools/python/python3-setuptools_69.1.1.bb
index 67475b68eb..46b2f0ab00 100644
--- a/poky/meta/recipes-devtools/python/python3-setuptools_69.1.1.bb
+++ b/poky/meta/recipes-devtools/python/python3-setuptools_69.1.1.bb
@@ -6,10 +6,16 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=141643e11c48898150daa83802dbc65f"
inherit pypi python_setuptools_build_meta
+CVE_PRODUCT = "python3-setuptools python:setuptools"
+
SRC_URI:append:class-native = " file://0001-conditionally-do-not-fetch-code-by-easy_install.patch"
SRC_URI += " \
- file://0001-_distutils-sysconfig.py-make-it-possible-to-substite.patch"
+ file://0001-_distutils-sysconfig.py-make-it-possible-to-substite.patch \
+ file://CVE-2024-6345.patch \
+ file://CVE-2025-47273-pre1.patch \
+ file://CVE-2025-47273.patch \
+"
SRC_URI[sha256sum] = "5c0806c7d9af348e6dd3777b4f4dbb42c7ad85b190104837488eab9a7c945cf8"
diff --git a/poky/meta/recipes-devtools/python/python3-urllib3/CVE-2025-50181.patch b/poky/meta/recipes-devtools/python/python3-urllib3/CVE-2025-50181.patch
new file mode 100644
index 0000000000..d4f6e98cc1
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3-urllib3/CVE-2025-50181.patch
@@ -0,0 +1,283 @@
+From f05b1329126d5be6de501f9d1e3e36738bc08857 Mon Sep 17 00:00:00 2001
+From: Illia Volochii <illia.volochii@gmail.com>
+Date: Wed, 18 Jun 2025 16:25:01 +0300
+Subject: [PATCH] Merge commit from fork
+
+* Apply Quentin's suggestion
+
+Co-authored-by: Quentin Pradet <quentin.pradet@gmail.com>
+
+* Add tests for disabled redirects in the pool manager
+
+* Add a possible fix for the issue with not raised `MaxRetryError`
+
+* Make urllib3 handle redirects instead of JS when JSPI is used
+
+* Fix info in the new comment
+
+* State that redirects with XHR are not controlled by urllib3
+
+* Remove excessive params from new test requests
+
+* Add tests reaching max non-0 redirects
+
+* Test redirects with Emscripten
+
+* Fix `test_merge_pool_kwargs`
+
+* Add a changelog entry
+
+* Parametrize tests
+
+* Drop a fix for Emscripten
+
+* Apply Seth's suggestion to docs
+
+Co-authored-by: Seth Michael Larson <sethmichaellarson@gmail.com>
+
+* Use a minor release instead of the patch one
+
+---------
+
+Co-authored-by: Quentin Pradet <quentin.pradet@gmail.com>
+Co-authored-by: Seth Michael Larson <sethmichaellarson@gmail.com>
+
+CVE: CVE-2025-50181
+Upstream-Status: Backport [https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857]
+
+Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
+---
+ docs/reference/contrib/emscripten.rst | 2 +-
+ dummyserver/app.py | 1 +
+ src/urllib3/poolmanager.py | 18 +++-
+ test/contrib/emscripten/test_emscripten.py | 16 ++++
+ test/test_poolmanager.py | 5 +-
+ test/with_dummyserver/test_poolmanager.py | 101 +++++++++++++++++++++
+ 6 files changed, 139 insertions(+), 4 deletions(-)
+
+diff --git a/docs/reference/contrib/emscripten.rst b/docs/reference/contrib/emscripten.rst
+index 9e85629..c88e422 100644
+--- a/docs/reference/contrib/emscripten.rst
++++ b/docs/reference/contrib/emscripten.rst
+@@ -68,7 +68,7 @@ Features which are usable with Emscripten support are:
+ * Timeouts
+ * Retries
+ * Streaming (with Web Workers and Cross-Origin Isolation)
+-* Redirects
++* Redirects (determined by browser/runtime, not restrictable with urllib3)
+ * Decompressing response bodies
+
+ Features which don't work with Emscripten:
+diff --git a/dummyserver/app.py b/dummyserver/app.py
+index 9fc9d1b..96e0dab 100644
+--- a/dummyserver/app.py
++++ b/dummyserver/app.py
+@@ -228,6 +228,7 @@ async def encodingrequest() -> ResponseReturnValue:
+
+
+ @hypercorn_app.route("/redirect", methods=["GET", "POST", "PUT"])
++@pyodide_testing_app.route("/redirect", methods=["GET", "POST", "PUT"])
+ async def redirect() -> ResponseReturnValue:
+ "Perform a redirect to ``target``"
+ values = await request.values
+diff --git a/src/urllib3/poolmanager.py b/src/urllib3/poolmanager.py
+index 085d1db..5763fea 100644
+--- a/src/urllib3/poolmanager.py
++++ b/src/urllib3/poolmanager.py
+@@ -203,6 +203,22 @@ class PoolManager(RequestMethods):
+ **connection_pool_kw: typing.Any,
+ ) -> None:
+ super().__init__(headers)
++ if "retries" in connection_pool_kw:
++ retries = connection_pool_kw["retries"]
++ if not isinstance(retries, Retry):
++ # When Retry is initialized, raise_on_redirect is based
++ # on a redirect boolean value.
++ # But requests made via a pool manager always set
++ # redirect to False, and raise_on_redirect always ends
++ # up being False consequently.
++ # Here we fix the issue by setting raise_on_redirect to
++ # a value needed by the pool manager without considering
++ # the redirect boolean.
++ raise_on_redirect = retries is not False
++ retries = Retry.from_int(retries, redirect=False)
++ retries.raise_on_redirect = raise_on_redirect
++ connection_pool_kw = connection_pool_kw.copy()
++ connection_pool_kw["retries"] = retries
+ self.connection_pool_kw = connection_pool_kw
+
+ self.pools: RecentlyUsedContainer[PoolKey, HTTPConnectionPool]
+@@ -456,7 +472,7 @@ class PoolManager(RequestMethods):
+ kw["body"] = None
+ kw["headers"] = HTTPHeaderDict(kw["headers"])._prepare_for_method_change()
+
+- retries = kw.get("retries")
++ retries = kw.get("retries", response.retries)
+ if not isinstance(retries, Retry):
+ retries = Retry.from_int(retries, redirect=redirect)
+
+diff --git a/test/contrib/emscripten/test_emscripten.py b/test/contrib/emscripten/test_emscripten.py
+index 17264d8..0e107fa 100644
+--- a/test/contrib/emscripten/test_emscripten.py
++++ b/test/contrib/emscripten/test_emscripten.py
+@@ -949,6 +949,22 @@ def test_retries(
+ pyodide_test(selenium_coverage, testserver_http.http_host, find_unused_port())
+
+
++def test_redirects(
++ selenium_coverage: typing.Any, testserver_http: PyodideServerInfo
++) -> None:
++ @run_in_pyodide # type: ignore[misc]
++ def pyodide_test(selenium_coverage: typing.Any, host: str, port: int) -> None:
++ from urllib3 import request
++
++ redirect_url = f"http://{host}:{port}/redirect"
++ response = request("GET", redirect_url)
++ assert response.status == 200
++
++ pyodide_test(
++ selenium_coverage, testserver_http.http_host, testserver_http.http_port
++ )
++
++
+ @install_urllib3_wheel()
+ def test_insecure_requests_warning(
+ selenium_coverage: typing.Any, testserver_http: PyodideServerInfo
+diff --git a/test/test_poolmanager.py b/test/test_poolmanager.py
+index ab5f203..b481a19 100644
+--- a/test/test_poolmanager.py
++++ b/test/test_poolmanager.py
+@@ -379,9 +379,10 @@ class TestPoolManager:
+
+ def test_merge_pool_kwargs(self) -> None:
+ """Assert _merge_pool_kwargs works in the happy case"""
+- p = PoolManager(retries=100)
++ retries = retry.Retry(total=100)
++ p = PoolManager(retries=retries)
+ merged = p._merge_pool_kwargs({"new_key": "value"})
+- assert {"retries": 100, "new_key": "value"} == merged
++ assert {"retries": retries, "new_key": "value"} == merged
+
+ def test_merge_pool_kwargs_none(self) -> None:
+ """Assert false-y values to _merge_pool_kwargs result in defaults"""
+diff --git a/test/with_dummyserver/test_poolmanager.py b/test/with_dummyserver/test_poolmanager.py
+index af77241..7f163ab 100644
+--- a/test/with_dummyserver/test_poolmanager.py
++++ b/test/with_dummyserver/test_poolmanager.py
+@@ -84,6 +84,89 @@ class TestPoolManager(HypercornDummyServerTestCase):
+ assert r.status == 200
+ assert r.data == b"Dummy server!"
+
++ @pytest.mark.parametrize(
++ "retries",
++ (0, Retry(total=0), Retry(redirect=0), Retry(total=0, redirect=0)),
++ )
++ def test_redirects_disabled_for_pool_manager_with_0(
++ self, retries: typing.Literal[0] | Retry
++ ) -> None:
++ """
++ Check handling redirects when retries is set to 0 on the pool
++ manager.
++ """
++ with PoolManager(retries=retries) as http:
++ with pytest.raises(MaxRetryError):
++ http.request("GET", f"{self.base_url}/redirect")
++
++ # Setting redirect=True should not change the behavior.
++ with pytest.raises(MaxRetryError):
++ http.request("GET", f"{self.base_url}/redirect", redirect=True)
++
++ # Setting redirect=False should not make it follow the redirect,
++ # but MaxRetryError should not be raised.
++ response = http.request("GET", f"{self.base_url}/redirect", redirect=False)
++ assert response.status == 303
++
++ @pytest.mark.parametrize(
++ "retries",
++ (
++ False,
++ Retry(total=False),
++ Retry(redirect=False),
++ Retry(total=False, redirect=False),
++ ),
++ )
++ def test_redirects_disabled_for_pool_manager_with_false(
++ self, retries: typing.Literal[False] | Retry
++ ) -> None:
++ """
++ Check that setting retries set to False on the pool manager disables
++ raising MaxRetryError and redirect=True does not change the
++ behavior.
++ """
++ with PoolManager(retries=retries) as http:
++ response = http.request("GET", f"{self.base_url}/redirect")
++ assert response.status == 303
++
++ response = http.request("GET", f"{self.base_url}/redirect", redirect=True)
++ assert response.status == 303
++
++ response = http.request("GET", f"{self.base_url}/redirect", redirect=False)
++ assert response.status == 303
++
++ def test_redirects_disabled_for_individual_request(self) -> None:
++ """
++ Check handling redirects when they are meant to be disabled
++ on the request level.
++ """
++ with PoolManager() as http:
++ # Check when redirect is not passed.
++ with pytest.raises(MaxRetryError):
++ http.request("GET", f"{self.base_url}/redirect", retries=0)
++ response = http.request("GET", f"{self.base_url}/redirect", retries=False)
++ assert response.status == 303
++
++ # Check when redirect=True.
++ with pytest.raises(MaxRetryError):
++ http.request(
++ "GET", f"{self.base_url}/redirect", retries=0, redirect=True
++ )
++ response = http.request(
++ "GET", f"{self.base_url}/redirect", retries=False, redirect=True
++ )
++ assert response.status == 303
++
++ # Check when redirect=False.
++ response = http.request(
++ "GET", f"{self.base_url}/redirect", retries=0, redirect=False
++ )
++ assert response.status == 303
++ response = http.request(
++ "GET", f"{self.base_url}/redirect", retries=False, redirect=False
++ )
++ assert response.status == 303
++
+ def test_cross_host_redirect(self) -> None:
+ with PoolManager() as http:
+ cross_host_location = f"{self.base_url_alt}/echo?a=b"
+@@ -138,6 +221,24 @@ class TestPoolManager(HypercornDummyServerTestCase):
+ pool = http.connection_from_host(self.host, self.port)
+ assert pool.num_connections == 1
+
++ # Check when retries are configured for the pool manager.
++ with PoolManager(retries=1) as http:
++ with pytest.raises(MaxRetryError):
++ http.request(
++ "GET",
++ f"{self.base_url}/redirect",
++ fields={"target": f"/redirect?target={self.base_url}/"},
++ )
++
++ # Here we allow more retries for the request.
++ response = http.request(
++ "GET",
++ f"{self.base_url}/redirect",
++ fields={"target": f"/redirect?target={self.base_url}/"},
++ retries=2,
++ )
++ assert response.status == 200
++
+ def test_redirect_cross_host_remove_headers(self) -> None:
+ with PoolManager() as http:
+ r = http.request(
+--
+2.40.0
diff --git a/poky/meta/recipes-devtools/python/python3-urllib3_2.2.1.bb b/poky/meta/recipes-devtools/python/python3-urllib3_2.2.2.bb
index fc1828b4ee..bdb1c7ca8d 100644
--- a/poky/meta/recipes-devtools/python/python3-urllib3_2.2.1.bb
+++ b/poky/meta/recipes-devtools/python/python3-urllib3_2.2.2.bb
@@ -3,10 +3,14 @@ HOMEPAGE = "https://github.com/shazow/urllib3"
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=52d273a3054ced561275d4d15260ecda"
-SRC_URI[sha256sum] = "d0570876c61ab9e520d776c38acbbb5b05a776d3f9ff98a5c8fd5162a444cf19"
+SRC_URI[sha256sum] = "dd505485549a7a552833da5e6063639d0d177c04f23bc3864e41e5dc5f612168"
inherit pypi python_hatchling
+SRC_URI += " \
+ file://CVE-2025-50181.patch \
+"
+
RDEPENDS:${PN} += "\
python3-certifi \
python3-cryptography \
diff --git a/poky/meta/recipes-devtools/python/python3-xmltodict/CVE-2025-9375-1.patch b/poky/meta/recipes-devtools/python/python3-xmltodict/CVE-2025-9375-1.patch
new file mode 100644
index 0000000000..e8977dd2ea
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3-xmltodict/CVE-2025-9375-1.patch
@@ -0,0 +1,111 @@
+From ecd456ab88d379514b116ef9293318b74e5ed3ee Mon Sep 17 00:00:00 2001
+From: Martin Blech <78768+martinblech@users.noreply.github.com>
+Date: Thu, 4 Sep 2025 17:25:39 -0700
+Subject: [PATCH] Prevent XML injection: reject '<'/'>' in element/attr names
+ (incl. @xmlns)
+
+* Add tests for tag names, attribute names, and @xmlns prefixes; confirm attr values are escaped.
+
+CVE: CVE-2025-9375
+
+Upstream-Status: Backport
+https://github.com/martinblech/xmltodict/commit/ecd456ab88d379514b116ef9293318b74e5ed3ee
+https://git.launchpad.net/ubuntu/+source/python-xmltodict/commit/?id=e8110a20e00d80db31d5fc9f8f4577328385d6b6
+
+Signed-off-by: Saravanan <saravanan.kadambathursubramaniyam@windriver.com>
+
+---
+ tests/test_dicttoxml.py | 32 ++++++++++++++++++++++++++++++++
+ xmltodict.py | 20 +++++++++++++++++++-
+ 2 files changed, 51 insertions(+), 1 deletion(-)
+
+Index: python-xmltodict-0.13.0/tests/test_dicttoxml.py
+===================================================================
+--- python-xmltodict-0.13.0.orig/tests/test_dicttoxml.py
++++ python-xmltodict-0.13.0/tests/test_dicttoxml.py
+@@ -213,3 +213,35 @@ xmlns:b="http://b.com/"><x a:attr="val">
+ expected_xml = '<?xml version="1.0" encoding="utf-8"?>\n<x>false</x>'
+ xml = unparse(dict(x=False))
+ self.assertEqual(xml, expected_xml)
++
++ def test_rejects_tag_name_with_angle_brackets(self):
++ # Minimal guard: disallow '<' or '>' to prevent breaking tag context
++ with self.assertRaises(ValueError):
++ unparse({"m><tag>content</tag": "unsafe"}, full_document=False)
++
++ def test_rejects_attribute_name_with_angle_brackets(self):
++ # Now we expect bad attribute names to be rejected
++ with self.assertRaises(ValueError):
++ unparse(
++ {"a": {"@m><tag>content</tag": "unsafe", "#text": "x"}},
++ full_document=False,
++ )
++
++ def test_rejects_malicious_xmlns_prefix(self):
++ # xmlns prefixes go under @xmlns mapping; reject angle brackets in prefix
++ with self.assertRaises(ValueError):
++ unparse(
++ {
++ "a": {
++ "@xmlns": {"m><bad": "http://example.com/"},
++ "#text": "x",
++ }
++ },
++ full_document=False,
++ )
++
++ def test_attribute_values_with_angle_brackets_are_escaped(self):
++ # Attribute values should be escaped by XMLGenerator
++ xml = unparse({"a": {"@attr": "1<middle>2", "#text": "x"}}, full_document=False)
++ # The generated XML should contain escaped '<' and '>' within the attribute value
++ self.assertIn('attr="1&lt;middle&gt;2"', xml)
+Index: python-xmltodict-0.13.0/xmltodict.py
+===================================================================
+--- python-xmltodict-0.13.0.orig/xmltodict.py
++++ python-xmltodict-0.13.0/xmltodict.py
+@@ -379,6 +379,14 @@ def parse(xml_input, encoding=None, expa
+ return handler.item
+
+
++def _has_angle_brackets(value):
++ """Return True if value (a str) contains '<' or '>'.
++
++ Non-string values return False. Uses fast substring checks implemented in C.
++ """
++ return isinstance(value, str) and ("<" in value or ">" in value)
++
++
+ def _process_namespace(name, namespaces, ns_sep=':', attr_prefix='@'):
+ if not namespaces:
+ return name
+@@ -412,6 +420,9 @@ def _emit(key, value, content_handler,
+ if result is None:
+ return
+ key, value = result
++ # Minimal validation to avoid breaking out of tag context
++ if _has_angle_brackets(key):
++ raise ValueError('Invalid element name: "<" or ">" not allowed')
+ if (not hasattr(value, '__iter__')
+ or isinstance(value, _basestring)
+ or isinstance(value, dict)):
+@@ -445,12 +456,19 @@ def _emit(key, value, content_handler,
+ attr_prefix)
+ if ik == '@xmlns' and isinstance(iv, dict):
+ for k, v in iv.items():
++ if _has_angle_brackets(k):
++ raise ValueError(
++ 'Invalid attribute name: "<" or ">" not allowed'
++ )
+ attr = 'xmlns{}'.format(':{}'.format(k) if k else '')
+ attrs[attr] = _unicode(v)
+ continue
+ if not isinstance(iv, _unicode):
+ iv = _unicode(iv)
+- attrs[ik[len(attr_prefix):]] = iv
++ attr_name = ik[len(attr_prefix) :]
++ if _has_angle_brackets(attr_name):
++ raise ValueError('Invalid attribute name: "<" or ">" not allowed')
++ attrs[attr_name] = iv
+ continue
+ children.append((ik, iv))
+ if pretty:
diff --git a/poky/meta/recipes-devtools/python/python3-xmltodict/CVE-2025-9375-2.patch b/poky/meta/recipes-devtools/python/python3-xmltodict/CVE-2025-9375-2.patch
new file mode 100644
index 0000000000..1be22cff6e
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3-xmltodict/CVE-2025-9375-2.patch
@@ -0,0 +1,176 @@
+From f98c90f071228ed73df997807298e1df4f790c33 Mon Sep 17 00:00:00 2001
+From: Martin Blech <78768+martinblech@users.noreply.github.com>
+Date: Mon, 8 Sep 2025 11:18:33 -0700
+Subject: [PATCH] Enhance unparse() XML name validation with stricter rules and
+ tests
+
+Extend existing validation (previously only for "<" and ">") to also
+reject element, attribute, and xmlns prefix names that are non-string,
+start with "?" or "!", or contain "/", spaces, tabs, or newlines.
+Update _emit and namespace handling to use _validate_name. Add tests
+covering these new invalid name cases.
+
+CVE: CVE-2025-9375
+
+Upstream-Status: Backport
+https://github.com/martinblech/xmltodict/commit/f98c90f071228ed73df997807298e1df4f790c33
+https://git.launchpad.net/ubuntu/+source/python-xmltodict/commit/?id=e8110a20e00d80db31d5fc9f8f4577328385d6b6
+
+Signed-off-by: Saravanan <saravanan.kadambathursubramaniyam@windriver.com
+---
+ tests/test_dicttoxml.py | 60 +++++++++++++++++++++++++++++++++++++++++
+ xmltodict.py | 48 ++++++++++++++++++++++++++-------
+ 2 files changed, 99 insertions(+), 9 deletions(-)
+
+Index: python-xmltodict-0.13.0/tests/test_dicttoxml.py
+===================================================================
+--- python-xmltodict-0.13.0.orig/tests/test_dicttoxml.py
++++ python-xmltodict-0.13.0/tests/test_dicttoxml.py
+@@ -245,3 +245,63 @@ xmlns:b="http://b.com/"><x a:attr="val">
+ xml = unparse({"a": {"@attr": "1<middle>2", "#text": "x"}}, full_document=False)
+ # The generated XML should contain escaped '<' and '>' within the attribute value
+ self.assertIn('attr="1&lt;middle&gt;2"', xml)
++
++ def test_rejects_tag_name_starting_with_question(self):
++ with self.assertRaises(ValueError):
++ unparse({"?pi": "data"}, full_document=False)
++
++ def test_rejects_tag_name_starting_with_bang(self):
++ with self.assertRaises(ValueError):
++ unparse({"!decl": "data"}, full_document=False)
++
++ def test_rejects_attribute_name_starting_with_question(self):
++ with self.assertRaises(ValueError):
++ unparse({"a": {"@?weird": "x"}}, full_document=False)
++
++ def test_rejects_attribute_name_starting_with_bang(self):
++ with self.assertRaises(ValueError):
++ unparse({"a": {"@!weird": "x"}}, full_document=False)
++
++ def test_rejects_xmlns_prefix_starting_with_question_or_bang(self):
++ with self.assertRaises(ValueError):
++ unparse({"a": {"@xmlns": {"?p": "http://e/"}}}, full_document=False)
++ with self.assertRaises(ValueError):
++ unparse({"a": {"@xmlns": {"!p": "http://e/"}}}, full_document=False)
++
++ def test_rejects_non_string_names(self):
++ class Weird:
++ def __str__(self):
++ return "bad>name"
++
++ # Non-string element key
++ with self.assertRaises(ValueError):
++ unparse({Weird(): "x"}, full_document=False)
++ # Non-string attribute key
++ with self.assertRaises(ValueError):
++ unparse({"a": {Weird(): "x"}}, full_document=False)
++
++ def test_rejects_tag_name_with_slash(self):
++ with self.assertRaises(ValueError):
++ unparse({"bad/name": "x"}, full_document=False)
++
++ def test_rejects_tag_name_with_whitespace(self):
++ for name in ["bad name", "bad\tname", "bad\nname"]:
++ with self.assertRaises(ValueError):
++ unparse({name: "x"}, full_document=False)
++
++ def test_rejects_attribute_name_with_slash(self):
++ with self.assertRaises(ValueError):
++ unparse({"a": {"@bad/name": "x"}}, full_document=False)
++
++ def test_rejects_attribute_name_with_whitespace(self):
++ for name in ["@bad name", "@bad\tname", "@bad\nname"]:
++ with self.assertRaises(ValueError):
++ unparse({"a": {name: "x"}}, full_document=False)
++
++ def test_rejects_xmlns_prefix_with_slash_or_whitespace(self):
++ # Slash
++ with self.assertRaises(ValueError):
++ unparse({"a": {"@xmlns": {"bad/prefix": "http://e/"}}}, full_document=False)
++ # Whitespace
++ with self.assertRaises(ValueError):
++ unparse({"a": {"@xmlns": {"bad prefix": "http://e/"}}}, full_document=False)
+Index: python-xmltodict-0.13.0/xmltodict.py
+===================================================================
+--- python-xmltodict-0.13.0.orig/xmltodict.py
++++ python-xmltodict-0.13.0/xmltodict.py
+@@ -387,7 +387,42 @@ def _has_angle_brackets(value):
+ return isinstance(value, str) and ("<" in value or ">" in value)
+
+
++def _has_invalid_name_chars(value):
++ """Return True if value (a str) contains any disallowed name characters.
++
++ Disallowed: '<', '>', '/', or any whitespace character.
++ Non-string values return False.
++ """
++ if not isinstance(value, str):
++ return False
++ if "<" in value or ">" in value or "/" in value:
++ return True
++ # Check for any whitespace (spaces, tabs, newlines, etc.)
++ return any(ch.isspace() for ch in value)
++
++
++def _validate_name(value, kind):
++ """Validate an element/attribute name for XML safety.
++
++ Raises ValueError with a specific reason when invalid.
++
++ kind: 'element' or 'attribute' (used in error messages)
++ """
++ if not isinstance(value, str):
++ raise ValueError(f"{kind} name must be a string")
++ if value.startswith("?") or value.startswith("!"):
++ raise ValueError(f'Invalid {kind} name: cannot start with "?" or "!"')
++ if "<" in value or ">" in value:
++ raise ValueError(f'Invalid {kind} name: "<" or ">" not allowed')
++ if "/" in value:
++ raise ValueError(f'Invalid {kind} name: "/" not allowed')
++ if any(ch.isspace() for ch in value):
++ raise ValueError(f"Invalid {kind} name: whitespace not allowed")
++
++
+ def _process_namespace(name, namespaces, ns_sep=':', attr_prefix='@'):
++ if not isinstance(name, str):
++ return name
+ if not namespaces:
+ return name
+ try:
+@@ -421,8 +456,7 @@ def _emit(key, value, content_handler,
+ return
+ key, value = result
+ # Minimal validation to avoid breaking out of tag context
+- if _has_angle_brackets(key):
+- raise ValueError('Invalid element name: "<" or ">" not allowed')
++ _validate_name(key, "element")
+ if (not hasattr(value, '__iter__')
+ or isinstance(value, _basestring)
+ or isinstance(value, dict)):
+@@ -451,23 +485,19 @@ def _emit(key, value, content_handler,
+ if ik == cdata_key:
+ cdata = iv
+ continue
+- if ik.startswith(attr_prefix):
++ if isinstance(ik, str) and ik.startswith(attr_prefix):
+ ik = _process_namespace(ik, namespaces, namespace_separator,
+ attr_prefix)
+ if ik == '@xmlns' and isinstance(iv, dict):
+ for k, v in iv.items():
+- if _has_angle_brackets(k):
+- raise ValueError(
+- 'Invalid attribute name: "<" or ">" not allowed'
+- )
++ _validate_name(k, "attribute")
+ attr = 'xmlns{}'.format(':{}'.format(k) if k else '')
+ attrs[attr] = _unicode(v)
+ continue
+ if not isinstance(iv, _unicode):
+ iv = _unicode(iv)
+ attr_name = ik[len(attr_prefix) :]
+- if _has_angle_brackets(attr_name):
+- raise ValueError('Invalid attribute name: "<" or ">" not allowed')
++ _validate_name(attr_name, "attribute")
+ attrs[attr_name] = iv
+ continue
+ children.append((ik, iv))
diff --git a/poky/meta/recipes-devtools/python/python3-xmltodict_0.13.0.bb b/poky/meta/recipes-devtools/python/python3-xmltodict_0.13.0.bb
index e8e275647c..9a308a29d2 100644
--- a/poky/meta/recipes-devtools/python/python3-xmltodict_0.13.0.bb
+++ b/poky/meta/recipes-devtools/python/python3-xmltodict_0.13.0.bb
@@ -13,6 +13,8 @@ inherit pypi setuptools3 ptest
SRC_URI += " \
file://run-ptest \
+ file://CVE-2025-9375-1.patch \
+ file://CVE-2025-9375-2.patch \
"
RDEPENDS:${PN} += " \
diff --git a/poky/meta/recipes-devtools/python/python3-zipp/CVE-2024-5569.patch b/poky/meta/recipes-devtools/python/python3-zipp/CVE-2024-5569.patch
new file mode 100644
index 0000000000..1cc43243bf
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3-zipp/CVE-2024-5569.patch
@@ -0,0 +1,138 @@
+From b1804347ec2db16452a7bff2b469d2c66776b904 Mon Sep 17 00:00:00 2001
+From: "Jason R. Coombs" <jaraco@jaraco.com>
+Date: Fri, 31 May 2024 11:20:57 -0400
+Subject: [PATCH] fix CVE-2024-5569
+
+The patch includes the following changes:
+c18417e Add news fragment.
+58115d2 Employ SanitizedNames in CompleteDirs. Fixes broken test.
+564fcc1 Add SanitizedNames mixin.
+79a309f Add some assertions about malformed paths.
+
+Upstream-Status: Backport
+[https://github.com/jaraco/zipp/pull/120/commits/79a309fe54dc6b7934fb72e9f31bcb58f2e9f547]
+[https://github.com/jaraco/zipp/pull/120/commits/564fcc10cdbfdaecdb33688e149827465931c9e0]
+[https://github.com/jaraco/zipp/pull/120/commits/58115d2be968644ce71ce6bcc9b79826c82a1806]
+[https://github.com/jaraco/zipp/pull/120/commits/c18417ed2953e181728a7dac07bff88a2190abf7]
+
+CVE: CVE-2024-5569
+
+Signed-off-by: Jiaying Song <jiaying.song.cn@windriver.com>
+---
+ newsfragments/119.bugfix.rst | 1 +
+ tests/test_path.py | 17 ++++++++++
+ zipp/__init__.py | 64 +++++++++++++++++++++++++++++++++++-
+ 3 files changed, 81 insertions(+), 1 deletion(-)
+ create mode 100644 newsfragments/119.bugfix.rst
+
+diff --git a/newsfragments/119.bugfix.rst b/newsfragments/119.bugfix.rst
+new file mode 100644
+index 0000000..6c72e2d
+--- /dev/null
++++ b/newsfragments/119.bugfix.rst
+@@ -0,0 +1 @@
++Improved handling of malformed zip files.
+\ No newline at end of file
+diff --git a/tests/test_path.py b/tests/test_path.py
+index a77a5de..3752243 100644
+--- a/tests/test_path.py
++++ b/tests/test_path.py
+@@ -575,3 +575,20 @@ class TestPath(unittest.TestCase):
+ zipp.Path(alpharep)
+ with self.assertRaises(KeyError):
+ alpharep.getinfo('does-not-exist')
++
++ def test_malformed_paths(self):
++ """
++ Path should handle malformed paths.
++ """
++ data = io.BytesIO()
++ zf = zipfile.ZipFile(data, "w")
++ zf.writestr("/one-slash.txt", b"content")
++ zf.writestr("//two-slash.txt", b"content")
++ zf.writestr("../parent.txt", b"content")
++ zf.filename = ''
++ root = zipfile.Path(zf)
++ assert list(map(str, root.iterdir())) == [
++ 'one-slash.txt',
++ 'two-slash.txt',
++ 'parent.txt',
++ ]
+diff --git a/zipp/__init__.py b/zipp/__init__.py
+index becd010..e980e9b 100644
+--- a/zipp/__init__.py
++++ b/zipp/__init__.py
+@@ -84,7 +84,69 @@ class InitializedState:
+ super().__init__(*args, **kwargs)
+
+
+-class CompleteDirs(InitializedState, zipfile.ZipFile):
++class SanitizedNames:
++ """
++ ZipFile mix-in to ensure names are sanitized.
++ """
++
++ def namelist(self):
++ return list(map(self._sanitize, super().namelist()))
++
++ @staticmethod
++ def _sanitize(name):
++ r"""
++ Ensure a relative path with posix separators and no dot names.
++
++ Modeled after
++ https://github.com/python/cpython/blob/bcc1be39cb1d04ad9fc0bd1b9193d3972835a57c/Lib/zipfile/__init__.py#L1799-L1813
++ but provides consistent cross-platform behavior.
++
++ >>> san = SanitizedNames._sanitize
++ >>> san('/foo/bar')
++ 'foo/bar'
++ >>> san('//foo.txt')
++ 'foo.txt'
++ >>> san('foo/.././bar.txt')
++ 'foo/bar.txt'
++ >>> san('foo../.bar.txt')
++ 'foo../.bar.txt'
++ >>> san('\\foo\\bar.txt')
++ 'foo/bar.txt'
++ >>> san('D:\\foo.txt')
++ 'D/foo.txt'
++ >>> san('\\\\server\\share\\file.txt')
++ 'server/share/file.txt'
++ >>> san('\\\\?\\GLOBALROOT\\Volume3')
++ '?/GLOBALROOT/Volume3'
++ >>> san('\\\\.\\PhysicalDrive1\\root')
++ 'PhysicalDrive1/root'
++
++ Retain any trailing slash.
++ >>> san('abc/')
++ 'abc/'
++
++ Raises a ValueError if the result is empty.
++ >>> san('../..')
++ Traceback (most recent call last):
++ ...
++ ValueError: Empty filename
++ """
++
++ def allowed(part):
++ return part and part not in {'..', '.'}
++
++ # Remove the drive letter.
++ # Don't use ntpath.splitdrive, because that also strips UNC paths
++ bare = re.sub('^([A-Z]):', r'\1', name, flags=re.IGNORECASE)
++ clean = bare.replace('\\', '/')
++ parts = clean.split('/')
++ joined = '/'.join(filter(allowed, parts))
++ if not joined:
++ raise ValueError("Empty filename")
++ return joined + '/' * name.endswith('/')
++
++
++class CompleteDirs(InitializedState, SanitizedNames, zipfile.ZipFile):
+ """
+ A ZipFile subclass that ensures that implied directories
+ are always included in the namelist.
+--
+2.25.1
+
diff --git a/poky/meta/recipes-devtools/python/python3-zipp_3.17.0.bb b/poky/meta/recipes-devtools/python/python3-zipp_3.17.0.bb
index e9e220e315..9f756887b5 100644
--- a/poky/meta/recipes-devtools/python/python3-zipp_3.17.0.bb
+++ b/poky/meta/recipes-devtools/python/python3-zipp_3.17.0.bb
@@ -3,6 +3,7 @@ HOMEPAGE = "https://github.com/jaraco/zipp"
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=141643e11c48898150daa83802dbc65f"
+SRC_URI += "file://CVE-2024-5569.patch"
SRC_URI[sha256sum] = "84e64a1c28cf7e91ed2078bb8cc8c259cb19b76942096c8d7b84947690cabaf0"
DEPENDS += "python3-setuptools-scm-native"
diff --git a/poky/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch b/poky/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch
index 0d807db39f..a8f98d873e 100644
--- a/poky/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch
+++ b/poky/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch
@@ -1,4 +1,4 @@
-From 365399f17d35719d828ddd49182dcb401fb7791c Mon Sep 17 00:00:00 2001
+From e8bd4f8ee56cbb12a61c1dcabf35a1835a863132 Mon Sep 17 00:00:00 2001
From: Paulo Neves <ptsneves@gmail.com>
Date: Tue, 7 Jun 2022 16:16:41 +0200
Subject: [PATCH] Avoid shebang overflow on python-config.py
@@ -16,10 +16,10 @@ Upstream-Status: Denied [distribution]
1 file changed, 2 insertions(+)
diff --git a/Makefile.pre.in b/Makefile.pre.in
-index 77bf09a..6353c57 100644
+index 2d235d2..1ac2263 100644
--- a/Makefile.pre.in
+++ b/Makefile.pre.in
-@@ -2339,6 +2339,8 @@ python-config: $(srcdir)/Misc/python-config.in Misc/python-config.sh
+@@ -2356,6 +2356,8 @@ python-config: $(srcdir)/Misc/python-config.in Misc/python-config.sh
@ # Substitution happens here, as the completely-expanded BINDIR
@ # is not available in configure
sed -e "s,@EXENAME@,$(EXENAME)," < $(srcdir)/Misc/python-config.in >python-config.py
diff --git a/poky/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch b/poky/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch
index 026150f0e2..5ca09c6f3c 100644
--- a/poky/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch
+++ b/poky/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch
@@ -1,4 +1,4 @@
-From f8a664cf1fc73e381d57d6927207286059744837 Mon Sep 17 00:00:00 2001
+From bbfb7fdf01f0502c7bf3d418f3a912ea76c93f24 Mon Sep 17 00:00:00 2001
From: Alexander Kanavin <alex@linutronix.de>
Date: Thu, 16 Sep 2021 16:35:37 +0200
Subject: [PATCH] Lib/pty.py: handle stdin I/O errors same way as master I/O
@@ -24,7 +24,6 @@ So let's treat both channels the same.
Upstream-Status: Submitted [https://github.com/python/cpython/pull/28388]
Signed-off-by: Alexander Kanavin <alex@linutronix.de>
-
---
Lib/pty.py | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/poky/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch b/poky/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch
index 680254fab9..c42a56bcb3 100644
--- a/poky/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch
+++ b/poky/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch
@@ -1,4 +1,4 @@
-From 71c194077bb907bfe423d3f3275f33a6c8ca0e74 Mon Sep 17 00:00:00 2001
+From c739bf214b9dd6060db216b79077806fccb582ae Mon Sep 17 00:00:00 2001
From: Alexander Kanavin <alex@linutronix.de>
Date: Fri, 17 Nov 2023 14:26:32 +0100
Subject: [PATCH] Lib/sysconfig.py: use prefix value from build configuration
@@ -9,16 +9,15 @@ native python.
Upstream-Status: Inappropriate [oe-core cross builds]
Signed-off-by: Alexander Kanavin <alex@linutronix.de>
-
---
Lib/sysconfig.py | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/Lib/sysconfig.py b/Lib/sysconfig.py
-index 79c0510..91ebcb6 100644
+index 6258b68..d59ec6e 100644
--- a/Lib/sysconfig.py
+++ b/Lib/sysconfig.py
-@@ -668,6 +668,11 @@ def _init_config_vars():
+@@ -675,6 +675,11 @@ def _init_config_vars():
_CONFIG_VARS['VPATH'] = sys._vpath
if os.name == 'posix':
_init_posix(_CONFIG_VARS)
diff --git a/poky/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch b/poky/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch
index ee33128fa1..b78f619958 100644
--- a/poky/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch
+++ b/poky/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch
@@ -1,4 +1,4 @@
-From 38278339832a57dbf5fa3ef21accaa03e2c814d7 Mon Sep 17 00:00:00 2001
+From b9081b2e21983f2a828bc40a47ab278ef69f4dfe Mon Sep 17 00:00:00 2001
From: Alexander Kanavin <alex.kanavin@gmail.com>
Date: Wed, 30 Jan 2019 12:41:04 +0100
Subject: [PATCH] Makefile.pre: use qemu wrapper when gathering profile data
@@ -10,10 +10,10 @@ Signed-off-by: Alexander Kanavin <alex.kanavin@gmail.com>
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/Makefile.pre.in b/Makefile.pre.in
-index dd5e69f..381feb0 100644
+index 083f4c7..dce36a5 100644
--- a/Makefile.pre.in
+++ b/Makefile.pre.in
-@@ -658,8 +658,7 @@ profile-run-stamp:
+@@ -660,8 +660,7 @@ profile-run-stamp:
# enabled.
$(MAKE) profile-gen-stamp
# Next, run the profile task to generate the profile information.
diff --git a/poky/meta/recipes-devtools/python/python3/0001-Skip-failing-tests-due-to-load-variability-on-YP-AB.patch b/poky/meta/recipes-devtools/python/python3/0001-Skip-failing-tests-due-to-load-variability-on-YP-AB.patch
index 197daa71a5..051ec2c635 100644
--- a/poky/meta/recipes-devtools/python/python3/0001-Skip-failing-tests-due-to-load-variability-on-YP-AB.patch
+++ b/poky/meta/recipes-devtools/python/python3/0001-Skip-failing-tests-due-to-load-variability-on-YP-AB.patch
@@ -1,4 +1,4 @@
-From 3471e3478e0760c42e04f8046cee2367ab5706d2 Mon Sep 17 00:00:00 2001
+From b4014e3d1d9e38b25f2840e65e2acd757f3e5d41 Mon Sep 17 00:00:00 2001
From: Yi Fan Yu <yifan.yu@windriver.com>
Date: Thu, 1 Apr 2021 13:08:37 -0700
Subject: [PATCH] Skip failing tests due to load variability on YP AB
@@ -23,10 +23,10 @@ Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
2 files changed, 5 insertions(+)
diff --git a/Lib/test/_test_multiprocessing.py b/Lib/test/_test_multiprocessing.py
-index e42c7ab..dff5227 100644
+index 3b4415b..1f94dec 100644
--- a/Lib/test/_test_multiprocessing.py
+++ b/Lib/test/_test_multiprocessing.py
-@@ -682,6 +682,7 @@ class _TestProcess(BaseTestCase):
+@@ -692,6 +692,7 @@ class _TestProcess(BaseTestCase):
close_queue(q)
@support.requires_resource('walltime')
@@ -34,7 +34,7 @@ index e42c7ab..dff5227 100644
def test_many_processes(self):
if self.TYPE == 'threads':
self.skipTest('test not appropriate for {}'.format(self.TYPE))
-@@ -2066,6 +2067,7 @@ class _TestBarrier(BaseTestCase):
+@@ -2223,6 +2224,7 @@ class _TestBarrier(BaseTestCase):
except threading.BrokenBarrierError:
results.append(True)
@@ -42,7 +42,7 @@ index e42c7ab..dff5227 100644
def test_timeout(self):
"""
Test wait(timeout)
-@@ -5024,6 +5026,7 @@ class TestWait(unittest.TestCase):
+@@ -5220,6 +5222,7 @@ class TestWait(unittest.TestCase):
time.sleep(period)
@support.requires_resource('walltime')
@@ -51,10 +51,10 @@ index e42c7ab..dff5227 100644
from multiprocessing.connection import wait
diff --git a/Lib/test/test_time.py b/Lib/test/test_time.py
-index 02cc3f4..51a4548 100644
+index 9463add..4e0f39d 100644
--- a/Lib/test/test_time.py
+++ b/Lib/test/test_time.py
-@@ -492,6 +492,7 @@ class TimeTestCase(unittest.TestCase):
+@@ -536,6 +536,7 @@ class TimeTestCase(unittest.TestCase):
@unittest.skipIf(
support.is_wasi, "process_time not available on WASI"
)
@@ -62,7 +62,7 @@ index 02cc3f4..51a4548 100644
def test_process_time(self):
# process_time() should not include time spend during a sleep
start = time.process_time()
-@@ -505,6 +506,7 @@ class TimeTestCase(unittest.TestCase):
+@@ -549,6 +550,7 @@ class TimeTestCase(unittest.TestCase):
self.assertTrue(info.monotonic)
self.assertFalse(info.adjustable)
diff --git a/poky/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch b/poky/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch
index b6c6ac5a28..08142617c0 100644
--- a/poky/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch
+++ b/poky/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch
@@ -1,4 +1,4 @@
-From 37d058e841ba3bd89b5746cc5381afb014b11581 Mon Sep 17 00:00:00 2001
+From 5224cc0ac21f4c2574c24e0fee38b145ca15175b Mon Sep 17 00:00:00 2001
From: Wentao Zhang <wentao.zhang@windriver.com>
Date: Mon, 20 Mar 2023 13:39:52 +0800
Subject: [PATCH] Update test_sysconfig for posix_user purelib
@@ -17,16 +17,15 @@ Update test_sysconfig.test_user_similar() for the posix_user scheme:
Upstream-Status: Inappropriate [oe-core specific]
Signed-off-by: Wentao Zhang <wentao.zhang@windriver.com>
-
---
Lib/test/test_sysconfig.py | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Lib/test/test_sysconfig.py b/Lib/test/test_sysconfig.py
-index b6dbf3d..5672590 100644
+index 3468d0c..9ff174c 100644
--- a/Lib/test/test_sysconfig.py
+++ b/Lib/test/test_sysconfig.py
-@@ -372,7 +372,7 @@ class TestSysConfig(unittest.TestCase):
+@@ -390,7 +390,7 @@ class TestSysConfig(unittest.TestCase):
expected = os.path.normpath(global_path.replace(base, user, 1))
# bpo-44860: platlib of posix_user doesn't use sys.platlibdir,
# whereas posix_prefix does.
diff --git a/poky/meta/recipes-devtools/python/python3/0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch b/poky/meta/recipes-devtools/python/python3/0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch
new file mode 100644
index 0000000000..98b3aa42d2
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3/0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch
@@ -0,0 +1,37 @@
+From 6e3868c8c330f997bc242a8d51d742baac449ecc Mon Sep 17 00:00:00 2001
+From: Petr Viktorin <encukou@gmail.com>
+Date: Wed, 23 Aug 2023 20:00:07 +0200
+Subject: [PATCH] gh-107811: tarfile: treat overflow in UID/GID as failure to
+ set it (#108369)
+
+Upstream-Status: Backport [https://github.com/python/cpython/pull/108369]
+Signed-off-by: Khem Raj <raj.khem@gmail.com>
+---
+ Lib/tarfile.py | 3 ++-
+ .../Library/2023-08-23-17-34-39.gh-issue-107811.3Fng72.rst | 3 +++
+ 2 files changed, 5 insertions(+), 1 deletion(-)
+ create mode 100644 Misc/NEWS.d/next/Library/2023-08-23-17-34-39.gh-issue-107811.3Fng72.rst
+
+diff --git a/Lib/tarfile.py b/Lib/tarfile.py
+index 0a0f31e..4dfb67d 100755
+--- a/Lib/tarfile.py
++++ b/Lib/tarfile.py
+@@ -2688,7 +2688,8 @@ class TarFile(object):
+ os.lchown(targetpath, u, g)
+ else:
+ os.chown(targetpath, u, g)
+- except OSError as e:
++ except (OSError, OverflowError) as e:
++ # OverflowError can be raised if an ID doesn't fit in `id_t`
+ raise ExtractError("could not change owner") from e
+
+ def chmod(self, tarinfo, targetpath):
+diff --git a/Misc/NEWS.d/next/Library/2023-08-23-17-34-39.gh-issue-107811.3Fng72.rst b/Misc/NEWS.d/next/Library/2023-08-23-17-34-39.gh-issue-107811.3Fng72.rst
+new file mode 100644
+index 0000000..ffca413
+--- /dev/null
++++ b/Misc/NEWS.d/next/Library/2023-08-23-17-34-39.gh-issue-107811.3Fng72.rst
+@@ -0,0 +1,3 @@
++:mod:`tarfile`: extraction of members with overly large UID or GID (e.g. on
++an OS with 32-bit :c:type:`!id_t`) now fails in the same way as failing to
++set the ID.
diff --git a/poky/meta/recipes-devtools/python/python3/0001-gh-114492-Initialize-struct-termios-before-calling-t.patch b/poky/meta/recipes-devtools/python/python3/0001-gh-114492-Initialize-struct-termios-before-calling-t.patch
deleted file mode 100644
index 8406ef30a2..0000000000
--- a/poky/meta/recipes-devtools/python/python3/0001-gh-114492-Initialize-struct-termios-before-calling-t.patch
+++ /dev/null
@@ -1,26 +0,0 @@
-From 439aa02f42d6e6715c172076261757fcb89a936a Mon Sep 17 00:00:00 2001
-From: "Miss Islington (bot)"
- <31488909+miss-islington@users.noreply.github.com>
-Date: Tue, 23 Jan 2024 23:02:02 +0100
-Subject: [PATCH] gh-114492: Initialize struct termios before calling
- tcgetattr() (GH-114495) (GH-114502)
-
-On Alpine Linux it could leave some field non-initialized.
-(cherry picked from commit d22c066b802592932f9eb18434782299e80ca42e)
-
-Upstream-Status: Backport [https://github.com/python/cpython/commit/386c72d9928c51aa2c855ce592bd8022da3b407f]
-Co-authored-by: Serhiy Storchaka <storchaka@gmail.com>
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
----
- .../next/Library/2024-01-23-21-20-40.gh-issue-114492.vKxl5o.rst | 2 ++
- 1 file changed, 2 insertions(+)
- create mode 100644 Misc/NEWS.d/next/Library/2024-01-23-21-20-40.gh-issue-114492.vKxl5o.rst
-
-diff --git a/Misc/NEWS.d/next/Library/2024-01-23-21-20-40.gh-issue-114492.vKxl5o.rst b/Misc/NEWS.d/next/Library/2024-01-23-21-20-40.gh-issue-114492.vKxl5o.rst
-new file mode 100644
-index 0000000..8df8299
---- /dev/null
-+++ b/Misc/NEWS.d/next/Library/2024-01-23-21-20-40.gh-issue-114492.vKxl5o.rst
-@@ -0,0 +1,2 @@
-+Make the result of :func:`termios.tcgetattr` reproducible on Alpine Linux.
-+Previously it could leave a random garbage in some fields.
diff --git a/poky/meta/recipes-devtools/python/python3/0001-python3-use-cc_basename-to-replace-CC-for-checking-c.patch b/poky/meta/recipes-devtools/python/python3/0001-python3-use-cc_basename-to-replace-CC-for-checking-c.patch
index bbeabe4389..5a1f9ffccf 100644
--- a/poky/meta/recipes-devtools/python/python3/0001-python3-use-cc_basename-to-replace-CC-for-checking-c.patch
+++ b/poky/meta/recipes-devtools/python/python3/0001-python3-use-cc_basename-to-replace-CC-for-checking-c.patch
@@ -1,4 +1,4 @@
-From ababc7b1db8c406910766e11cdd04cbef7a706c9 Mon Sep 17 00:00:00 2001
+From 82576cdb9d6d9736ba122592974b0e7727216a3f Mon Sep 17 00:00:00 2001
From: Changqing Li <changqing.li@windriver.com>
Date: Mon, 22 Oct 2018 15:19:51 +0800
Subject: [PATCH] python3: use cc_basename to replace CC for checking compiler
@@ -26,7 +26,7 @@ Signed-off-by: Changqing Li <changqing.li@windriver.com>
1 file changed, 10 insertions(+), 9 deletions(-)
diff --git a/configure.ac b/configure.ac
-index 384718d..5a1d58b 100644
+index 9270b5f..955daad 100644
--- a/configure.ac
+++ b/configure.ac
@@ -137,6 +137,7 @@ AC_CONFIG_HEADERS([pyconfig.h])
@@ -46,7 +46,7 @@ index 384718d..5a1d58b 100644
gcc) AC_PATH_TOOL([CXX], [g++], [g++], [notfound]) ;;
cc) AC_PATH_TOOL([CXX], [c++], [c++], [notfound]) ;;
clang|*/clang) AC_PATH_TOOL([CXX], [clang++], [clang++], [notfound]) ;;
-@@ -1328,7 +1329,7 @@ rmdir CaseSensitiveTestDir
+@@ -1331,7 +1332,7 @@ rmdir CaseSensitiveTestDir
case $ac_sys_system in
hp*|HP*)
@@ -55,7 +55,7 @@ index 384718d..5a1d58b 100644
cc|*/cc) CC="$CC -Ae";;
esac;;
esac
-@@ -1854,7 +1855,7 @@ esac
+@@ -1857,7 +1858,7 @@ esac
],
[AC_MSG_RESULT([no])])
if test "$Py_LTO" = 'true' ; then
@@ -64,7 +64,7 @@ index 384718d..5a1d58b 100644
*clang*)
LDFLAGS_NOLTO="-fno-lto"
dnl Clang linker requires -flto in order to link objects with LTO information.
-@@ -1983,7 +1984,7 @@ then
+@@ -1986,7 +1987,7 @@ then
fi
fi
LLVM_PROF_ERR=no
@@ -73,7 +73,7 @@ index 384718d..5a1d58b 100644
*clang*)
# Any changes made here should be reflected in the GCC+Darwin case below
PGO_PROF_GEN_FLAG="-fprofile-instr-generate"
-@@ -2147,7 +2148,7 @@ AC_MSG_RESULT([$BOLT_APPLY_FLAGS])
+@@ -2179,7 +2180,7 @@ AC_MSG_RESULT([$BOLT_APPLY_FLAGS])
# compiler and platform. BASECFLAGS tweaks need to be made even if the
# user set OPT.
@@ -82,7 +82,7 @@ index 384718d..5a1d58b 100644
*clang*)
cc_is_clang=1
;;
-@@ -2419,7 +2420,7 @@ yes)
+@@ -2451,7 +2452,7 @@ yes)
# ICC doesn't recognize the option, but only emits a warning
## XXX does it emit an unused result warning and can it be disabled?
@@ -91,7 +91,7 @@ index 384718d..5a1d58b 100644
[*icc*], [ac_cv_disable_unused_result_warning=no]
[PY_CHECK_CC_WARNING([disable], [unused-result])])
AS_VAR_IF([ac_cv_disable_unused_result_warning], [yes],
-@@ -2665,7 +2666,7 @@ yes)
+@@ -2697,7 +2698,7 @@ yes)
;;
esac
@@ -100,7 +100,7 @@ index 384718d..5a1d58b 100644
*mpicc*)
CFLAGS_NODIST="$CFLAGS_NODIST"
;;
-@@ -3482,7 +3483,7 @@ then
+@@ -3532,7 +3533,7 @@ then
then
LINKFORSHARED="-Wl,--export-dynamic"
fi;;
@@ -109,7 +109,7 @@ index 384718d..5a1d58b 100644
*gcc*)
if $CC -Xlinker --help 2>&1 | grep export-dynamic >/dev/null
then
-@@ -6803,7 +6804,7 @@ if test "$ac_cv_gcc_asm_for_x87" = yes; then
+@@ -6853,7 +6854,7 @@ if test "$ac_cv_gcc_asm_for_x87" = yes; then
# Some versions of gcc miscompile inline asm:
# http://gcc.gnu.org/bugzilla/show_bug.cgi?id=46491
# http://gcc.gnu.org/ml/gcc/2010-11/msg00366.html
diff --git a/poky/meta/recipes-devtools/python/python3/0001-skip-no_stdout_fileno-test-due-to-load-variability.patch b/poky/meta/recipes-devtools/python/python3/0001-skip-no_stdout_fileno-test-due-to-load-variability.patch
index 2d7bca6a77..4920cb9ad9 100644
--- a/poky/meta/recipes-devtools/python/python3/0001-skip-no_stdout_fileno-test-due-to-load-variability.patch
+++ b/poky/meta/recipes-devtools/python/python3/0001-skip-no_stdout_fileno-test-due-to-load-variability.patch
@@ -1,4 +1,4 @@
-From 217cea231462e7703e8c9ea39c0a6833f799a420 Mon Sep 17 00:00:00 2001
+From 5944f707fc04fb65caec3f0e1ce3a42169426c47 Mon Sep 17 00:00:00 2001
From: Trevor Gamblin <tgamblin@baylibre.com>
Date: Fri, 15 Sep 2023 08:48:33 -0400
Subject: [PATCH] skip no_stdout_fileno test due to load variability
@@ -16,10 +16,10 @@ Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
1 file changed, 1 insertion(+)
diff --git a/Lib/test/test_builtin.py b/Lib/test/test_builtin.py
-index 4d03c46..b329b7a 100644
+index c71c568..e41ab5e 100644
--- a/Lib/test/test_builtin.py
+++ b/Lib/test/test_builtin.py
-@@ -2326,6 +2326,7 @@ class PtyTests(unittest.TestCase):
+@@ -2375,6 +2375,7 @@ class PtyTests(unittest.TestCase):
# Check stdin/stdout error handler is used when invoking PyOS_Readline()
self.check_input_tty("prompté", b"quux\xe9", "ascii")
diff --git a/poky/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch b/poky/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch
index fc52fdac26..c7ac43cc85 100644
--- a/poky/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch
+++ b/poky/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch
@@ -1,4 +1,4 @@
-From a5d429a0e1a4809c1ded7be7e45dcabeb82c53d8 Mon Sep 17 00:00:00 2001
+From 3aeeddb1325679d5c0471ad86806e92e72187138 Mon Sep 17 00:00:00 2001
From: Alexander Kanavin <alex@linutronix.de>
Date: Sun, 12 Sep 2021 21:44:36 +0200
Subject: [PATCH] sysconfig.py: use platlibdir also for purelib
@@ -8,13 +8,12 @@ is not correct.
Upstream-Status: Inappropriate [oe-core specific]
Signed-off-by: Alexander Kanavin <alex@linutronix.de>
-
---
Lib/sysconfig.py | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Lib/sysconfig.py b/Lib/sysconfig.py
-index 122d441..79c0510 100644
+index 517b13a..6258b68 100644
--- a/Lib/sysconfig.py
+++ b/Lib/sysconfig.py
@@ -28,7 +28,7 @@ _INSTALL_SCHEMES = {
diff --git a/poky/meta/recipes-devtools/python/python3/0001-test_active_children-skip-problematic-test.patch b/poky/meta/recipes-devtools/python/python3/0001-test_active_children-skip-problematic-test.patch
new file mode 100644
index 0000000000..164c8b5180
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3/0001-test_active_children-skip-problematic-test.patch
@@ -0,0 +1,27 @@
+From a83311a1030b816f422dbb4457fc38c1289c224d Mon Sep 17 00:00:00 2001
+From: Trevor Gamblin <tgamblin@baylibre.com>
+Date: Thu, 13 Jun 2024 10:54:31 -0400
+Subject: [PATCH] test_active_children: skip problematic test
+
+This test is failing in some tests on the Autobuilder. Since it's of a
+similar nature to other failing/hanging tests, disable it for now.
+
+Upstream-Status: Inappropriate [OE-Specific]
+
+Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
+---
+ Lib/test/_test_multiprocessing.py | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/Lib/test/_test_multiprocessing.py b/Lib/test/_test_multiprocessing.py
+index 1f94dec..3632219 100644
+--- a/Lib/test/_test_multiprocessing.py
++++ b/Lib/test/_test_multiprocessing.py
+@@ -585,6 +585,7 @@ class _TestProcess(BaseTestCase):
+ self.assertTrue(type(cpus) is int)
+ self.assertTrue(cpus >= 1)
+
++ @unittest.skip("skipping problematic test")
+ def test_active_children(self):
+ self.assertEqual(type(self.active_children()), list)
+
diff --git a/poky/meta/recipes-devtools/python/python3/0001-test_ctypes.test_find-skip-without-tools-sdk.patch b/poky/meta/recipes-devtools/python/python3/0001-test_ctypes.test_find-skip-without-tools-sdk.patch
index b4fe946cba..307e4bf306 100644
--- a/poky/meta/recipes-devtools/python/python3/0001-test_ctypes.test_find-skip-without-tools-sdk.patch
+++ b/poky/meta/recipes-devtools/python/python3/0001-test_ctypes.test_find-skip-without-tools-sdk.patch
@@ -1,4 +1,4 @@
-From b64c131a576a4b4f821514e711ab91b1394fb4ff Mon Sep 17 00:00:00 2001
+From fbbf04dbeae217b985073263499174960e5fd142 Mon Sep 17 00:00:00 2001
From: Tim Orling <timothy.t.orling@intel.com>
Date: Fri, 18 Jun 2021 11:56:50 -0700
Subject: [PATCH] test_ctypes.test_find: skip without tools-sdk
@@ -10,13 +10,12 @@ easiest way to dynamically check for that is looking for
Upstream-Status: Inappropriate [oe-specific]
Signed-off-by: Tim Orling <timothy.t.orling@intel.com>
-
---
Lib/test/test_ctypes/test_find.py | 2 ++
1 file changed, 2 insertions(+)
diff --git a/Lib/test/test_ctypes/test_find.py b/Lib/test/test_ctypes/test_find.py
-index 1ff9d01..59def26 100644
+index a41e949..eb5fe19 100644
--- a/Lib/test/test_ctypes/test_find.py
+++ b/Lib/test/test_ctypes/test_find.py
@@ -113,10 +113,12 @@ class FindLibraryLinux(unittest.TestCase):
diff --git a/poky/meta/recipes-devtools/python/python3/0001-test_deadlock-skip-problematic-test.patch b/poky/meta/recipes-devtools/python/python3/0001-test_deadlock-skip-problematic-test.patch
new file mode 100644
index 0000000000..e07f7392f6
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3/0001-test_deadlock-skip-problematic-test.patch
@@ -0,0 +1,27 @@
+From 9d658dd20f02edcf878b245d638c474c808ab8d1 Mon Sep 17 00:00:00 2001
+From: Trevor Gamblin <tgamblin@baylibre.com>
+Date: Wed, 12 Jun 2024 10:29:03 -0400
+Subject: [PATCH] test_deadlock: skip problematic test
+
+This test hangs frequently when run on the Autobuilder. Disable it in
+testing until the cause can be determined.
+
+Upstream-Status: Inappropriate [OE-Specific]
+
+Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
+---
+ Lib/test/test_concurrent_futures/test_deadlock.py | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/Lib/test/test_concurrent_futures/test_deadlock.py b/Lib/test/test_concurrent_futures/test_deadlock.py
+index e8cd8f6..021906b 100644
+--- a/Lib/test/test_concurrent_futures/test_deadlock.py
++++ b/Lib/test/test_concurrent_futures/test_deadlock.py
+@@ -90,6 +90,7 @@ class ErrorAtUnpickle(object):
+ return _raise_error_ignore_stderr, (UnpicklingError, )
+
+
++@unittest.skip("skipping problematic test")
+ class ExecutorDeadlockTest:
+ TIMEOUT = support.LONG_TIMEOUT
+
diff --git a/poky/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch b/poky/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch
index 410a9fc7f1..535c48c769 100644
--- a/poky/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch
+++ b/poky/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch
@@ -1,4 +1,4 @@
-From ef5728f0af14da5c9f80b0f038fe5bf6d44cb0e9 Mon Sep 17 00:00:00 2001
+From fcd5b7d30d3245ce92ea45dfbab3c7b7da690c20 Mon Sep 17 00:00:00 2001
From: Mingli Yu <mingli.yu@windriver.com>
Date: Mon, 5 Aug 2019 15:57:39 +0800
Subject: [PATCH] test_locale.py: correct the test output format
@@ -26,16 +26,15 @@ Upstream-Status: Submitted [https://github.com/python/cpython/pull/15132]
Rebased for 3.9.4, still not accepted upstream Signed-off-by: Alejandro Hernandez <alejandro@enedino.org>
Signed-off-by: Mingli Yu <mingli.yu@windriver.com>
-
---
Lib/test/test_locale.py | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Lib/test/test_locale.py b/Lib/test/test_locale.py
-index b0d7998..cb12153 100644
+index cde80a4..e8ffd71 100644
--- a/Lib/test/test_locale.py
+++ b/Lib/test/test_locale.py
-@@ -557,7 +557,7 @@ class TestMiscellaneous(unittest.TestCase):
+@@ -561,7 +561,7 @@ class TestMiscellaneous(unittest.TestCase):
self.skipTest('test needs Turkish locale')
loc = locale.getlocale(locale.LC_CTYPE)
if verbose:
diff --git a/poky/meta/recipes-devtools/python/python3/0001-test_readline-skip-limited-history-test.patch b/poky/meta/recipes-devtools/python/python3/0001-test_readline-skip-limited-history-test.patch
new file mode 100644
index 0000000000..f9dc0ddcda
--- /dev/null
+++ b/poky/meta/recipes-devtools/python/python3/0001-test_readline-skip-limited-history-test.patch
@@ -0,0 +1,38 @@
+From 34fd0bc8afc67a11eea5d73f9e0edf045c5ce541 Mon Sep 17 00:00:00 2001
+From: Trevor Gamblin <tgamblin@baylibre.com>
+Date: Tue, 13 Aug 2024 11:07:05 -0400
+Subject: [PATCH] test_readline: skip limited history test
+
+This test was added recently and is failing on the ptest image when
+using the default PACKAGECONFIG settings (i.e. with editline instead of
+readline).. Disable it until the proper fix is determined.
+
+A bug has been opened upstream: https://github.com/python/cpython/issues/123018
+
+Upstream-Status: Inappropriate [OE-specific]
+
+Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
+---
+ Lib/test/test_readline.py | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/Lib/test/test_readline.py b/Lib/test/test_readline.py
+index fab124a..291dd48 100644
+--- a/Lib/test/test_readline.py
++++ b/Lib/test/test_readline.py
+@@ -141,6 +141,7 @@ class TestHistoryManipulation (unittest.TestCase):
+ self.assertEqual(readline.get_history_item(1), "entrée 1")
+ self.assertEqual(readline.get_history_item(2), "entrée 22")
+
++ @unittest.skip("Skipping problematic test")
+ def test_write_read_limited_history(self):
+ previous_length = readline.get_history_length()
+ self.addCleanup(readline.set_history_length, previous_length)
+@@ -379,6 +380,7 @@ readline.write_history_file(history_file)
+ self.assertIn(b"done", output)
+
+
++ @unittest.skip("Skipping problematic test")
+ def test_write_read_limited_history(self):
+ previous_length = readline.get_history_length()
+ self.addCleanup(readline.set_history_length, previous_length)
diff --git a/poky/meta/recipes-devtools/python/python3/0001-test_shutdown-skip-problematic-test.patch b/poky/meta/recipes-devtools/python/python3/0001-test_shutdown-skip-problematic-test.patch
index 1d4cda18b1..61fe5e9ba1 100644
--- a/poky/meta/recipes-devtools/python/python3/0001-test_shutdown-skip-problematic-test.patch
+++ b/poky/meta/recipes-devtools/python/python3/0001-test_shutdown-skip-problematic-test.patch
@@ -1,4 +1,4 @@
-From 9d4cdbde100798ba9fa1cf3f82dbaf18fd10a543 Mon Sep 17 00:00:00 2001
+From d09a034acba8922158d38fd16be970b5a454428a Mon Sep 17 00:00:00 2001
From: Trevor Gamblin <tgamblin@baylibre.com>
Date: Wed, 8 May 2024 11:58:09 -0400
Subject: [PATCH] test_shutdown: skip problematic test
@@ -14,7 +14,7 @@ Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
1 file changed, 3 insertions(+)
diff --git a/Lib/test/test_concurrent_futures/test_shutdown.py b/Lib/test/test_concurrent_futures/test_shutdown.py
-index 7a4065afd4..6b878a48bf 100644
+index 7a4065a..6b878a4 100644
--- a/Lib/test/test_concurrent_futures/test_shutdown.py
+++ b/Lib/test/test_concurrent_futures/test_shutdown.py
@@ -20,6 +20,7 @@ def sleep_and_print(t, msg):
@@ -25,7 +25,7 @@ index 7a4065afd4..6b878a48bf 100644
class ExecutorShutdownTest:
def test_run_after_shutdown(self):
self.executor.shutdown()
-@@ -156,6 +157,7 @@ def timeout(_signum, _frame):
+@@ -156,6 +157,7 @@ class ExecutorShutdownTest:
signal.signal(signal.SIGALRM, old_handler)
@@ -33,7 +33,7 @@ index 7a4065afd4..6b878a48bf 100644
class ThreadPoolShutdownTest(ThreadPoolMixin, ExecutorShutdownTest, BaseTestCase):
def test_threads_terminate(self):
def acquire_lock(lock):
-@@ -252,6 +254,7 @@ def test_cancel_futures_wait_false(self):
+@@ -252,6 +254,7 @@ class ThreadPoolShutdownTest(ThreadPoolMixin, ExecutorShutdownTest, BaseTestCase
self.assertIn(out.strip(), [b"apple", b""])
@@ -41,6 +41,3 @@ index 7a4065afd4..6b878a48bf 100644
class ProcessPoolShutdownTest(ExecutorShutdownTest):
def test_processes_terminate(self):
def acquire_lock(lock):
---
-2.45.0
-
diff --git a/poky/meta/recipes-devtools/python/python3/0001-test_storlines-skip-due-to-load-variability.patch b/poky/meta/recipes-devtools/python/python3/0001-test_storlines-skip-due-to-load-variability.patch
index 0d0eb08459..88cd93a51f 100644
--- a/poky/meta/recipes-devtools/python/python3/0001-test_storlines-skip-due-to-load-variability.patch
+++ b/poky/meta/recipes-devtools/python/python3/0001-test_storlines-skip-due-to-load-variability.patch
@@ -1,4 +1,4 @@
-From dc69a1afdb3ba619705ff71e14f19ed3142e422f Mon Sep 17 00:00:00 2001
+From 6715560de4d622c2d72ee7b587c916ac647c54bb Mon Sep 17 00:00:00 2001
From: Trevor Gamblin <tgamblin@baylibre.com>
Date: Fri, 6 Oct 2023 10:59:44 -0400
Subject: [PATCH] test_storlines: skip due to load variability
@@ -11,16 +11,15 @@ Upstream-Status: Inappropriate [OE-Specific]
[YOCTO #14933]
Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
-
---
Lib/test/test_ftplib.py | 1 +
1 file changed, 1 insertion(+)
diff --git a/Lib/test/test_ftplib.py b/Lib/test/test_ftplib.py
-index 2f191ea..dc29346 100644
+index 4c4a449..b8c79a4 100644
--- a/Lib/test/test_ftplib.py
+++ b/Lib/test/test_ftplib.py
-@@ -626,6 +626,7 @@ class TestFTPClass(TestCase):
+@@ -629,6 +629,7 @@ class TestFTPClass(TestCase):
self.client.storbinary('stor', f, rest=r)
self.assertEqual(self.server.handler_instance.rest, str(r))
diff --git a/poky/meta/recipes-devtools/python/python3/0020-configure.ac-setup.py-do-not-add-a-curses-include-pa.patch b/poky/meta/recipes-devtools/python/python3/0020-configure.ac-setup.py-do-not-add-a-curses-include-pa.patch
index 0661249bfd..e917c8bdf0 100644
--- a/poky/meta/recipes-devtools/python/python3/0020-configure.ac-setup.py-do-not-add-a-curses-include-pa.patch
+++ b/poky/meta/recipes-devtools/python/python3/0020-configure.ac-setup.py-do-not-add-a-curses-include-pa.patch
@@ -1,4 +1,4 @@
-From d0205c60d08f51d84bd8ddc07a57e8c71710fdad Mon Sep 17 00:00:00 2001
+From 011b21dc9b090c0b97eaecbd80a9e0c1cd39b12d Mon Sep 17 00:00:00 2001
From: Alexander Kanavin <alex@linutronix.de>
Date: Fri, 17 Nov 2023 14:16:40 +0100
Subject: [PATCH] configure.ac: do not add a curses include path from the host
@@ -15,10 +15,10 @@ Signed-off-by: Alexander Kanavin <alex.kanavin@gmail.com>
1 file changed, 6 deletions(-)
diff --git a/configure.ac b/configure.ac
-index c49cd4f..affdedf 100644
+index 6e465a4..13c4835 100644
--- a/configure.ac
+++ b/configure.ac
-@@ -6508,12 +6508,6 @@ AS_VAR_IF([have_panel], [no], [
+@@ -6558,12 +6558,6 @@ AS_VAR_IF([have_panel], [no], [
AC_MSG_RESULT([$have_panel (CFLAGS: $PANEL_CFLAGS, LIBS: $PANEL_LIBS)])
])
diff --git a/poky/meta/recipes-devtools/python/python3/cgi_py.patch b/poky/meta/recipes-devtools/python/python3/cgi_py.patch
index 8262c88e73..880a463760 100644
--- a/poky/meta/recipes-devtools/python/python3/cgi_py.patch
+++ b/poky/meta/recipes-devtools/python/python3/cgi_py.patch
@@ -1,4 +1,4 @@
-From a56778372fe8dc7c42f5ffd911d89498c22dd064 Mon Sep 17 00:00:00 2001
+From 6ebd9de3505be0965cfc37e2e4d0d882d75f0ec2 Mon Sep 17 00:00:00 2001
From: Mark Hatle <mark.hatle@windriver.com>
Date: Wed, 21 Sep 2011 20:55:33 -0500
Subject: [PATCH] Lib/cgi.py: Update the script as mentioned in the comment
@@ -6,7 +6,6 @@ Subject: [PATCH] Lib/cgi.py: Update the script as mentioned in the comment
Upstream-Status: Inappropriate [distribution]
Signed-off-by: Mark Hatle <mark.hatle@windriver.com>
-
---
Lib/cgi.py | 11 +----------
1 file changed, 1 insertion(+), 10 deletions(-)
diff --git a/poky/meta/recipes-devtools/python/python3/crosspythonpath.patch b/poky/meta/recipes-devtools/python/python3/crosspythonpath.patch
index 2c4aef0511..24268fb91a 100644
--- a/poky/meta/recipes-devtools/python/python3/crosspythonpath.patch
+++ b/poky/meta/recipes-devtools/python/python3/crosspythonpath.patch
@@ -1,4 +1,4 @@
-From 5b66463c10fec1440e977d5a21a0167862d6d79c Mon Sep 17 00:00:00 2001
+From 0bcdb84db7801507b155a40db2228ba516edeb73 Mon Sep 17 00:00:00 2001
From: Ricardo Ribalda <ricardo@ribalda.com>
Date: Tue, 18 Nov 2014 03:35:33 -0500
Subject: [PATCH] configure.ac: add CROSSPYTHONPATH into PYTHONPATH for
@@ -14,13 +14,12 @@ Upstream-Status: Inappropriate [OE-Core integration specific]
Credits-to: Mark Hatle <mark.hatle@windriver.com>
Credits-to: Jackie Huang <jackie.huang@windriver.com>
Signed-off-by: Ricardo Ribalda <ricardo@ribalda.com>
-
---
configure.ac | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/configure.ac b/configure.ac
-index cb9e198..d81c19a 100644
+index 955daad..6e465a4 100644
--- a/configure.ac
+++ b/configure.ac
@@ -165,7 +165,7 @@ AC_ARG_WITH([build-python],
diff --git a/poky/meta/recipes-devtools/python/python3/deterministic_imports.patch b/poky/meta/recipes-devtools/python/python3/deterministic_imports.patch
index 104df94964..9bfdf5cd47 100644
--- a/poky/meta/recipes-devtools/python/python3/deterministic_imports.patch
+++ b/poky/meta/recipes-devtools/python/python3/deterministic_imports.patch
@@ -1,4 +1,4 @@
-From 039d5e652796b55f1132afa568c7432b6ed89afd Mon Sep 17 00:00:00 2001
+From 1d6f0f5f8a1279fc9bc06266caa3f3b6f234c4cb Mon Sep 17 00:00:00 2001
From: Richard Purdie <richard.purdie@linuxfoundation.org>
Date: Fri, 27 May 2022 17:05:44 +0100
Subject: [PATCH] python3: Ensure stale empty python module directories don't
@@ -11,15 +11,14 @@ has caused a long string of different issues for us.
As a result, patch this to a behaviour which works for us.
-Upstream-Status: Pending [need to talk to upstream to see if they'll take one or both fixes]
+Upstream-Status: Submitted [https://github.com/python/cpython/issues/120492; need to first talk to upstream to see if they'll take one or both fixes]
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
-
---
Lib/importlib/metadata/__init__.py | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/Lib/importlib/metadata/__init__.py b/Lib/importlib/metadata/__init__.py
-index 82e0ce1..969cac4 100644
+index e6ca178..ac5a75b 100644
--- a/Lib/importlib/metadata/__init__.py
+++ b/Lib/importlib/metadata/__init__.py
@@ -710,7 +710,14 @@ class Lookup:
diff --git a/poky/meta/recipes-devtools/python/python3/makerace.patch b/poky/meta/recipes-devtools/python/python3/makerace.patch
index c1b20703e6..fbe12a5fca 100644
--- a/poky/meta/recipes-devtools/python/python3/makerace.patch
+++ b/poky/meta/recipes-devtools/python/python3/makerace.patch
@@ -1,4 +1,4 @@
-From 9f827c29adbe656af3c8fc963fdd8f47aec0c442 Mon Sep 17 00:00:00 2001
+From be22dd9b091af8f971f924fdbce5b439d9b2e850 Mon Sep 17 00:00:00 2001
From: Richard Purdie <richard.purdie@linuxfoundation.org>
Date: Tue, 13 Jul 2021 23:19:29 +0100
Subject: [PATCH] python3: Fix make race
@@ -17,10 +17,10 @@ Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Makefile.pre.in b/Makefile.pre.in
-index 381feb0..77bf09a 100644
+index dce36a5..2d235d2 100644
--- a/Makefile.pre.in
+++ b/Makefile.pre.in
-@@ -2250,7 +2250,7 @@ COMPILEALL_OPTS=-j0
+@@ -2267,7 +2267,7 @@ COMPILEALL_OPTS=-j0
TEST_MODULES=@TEST_MODULES@
.PHONY: libinstall
diff --git a/poky/meta/recipes-devtools/python/python3/python3-manifest.json b/poky/meta/recipes-devtools/python/python3/python3-manifest.json
index 46092d4004..292c5bbc5d 100644
--- a/poky/meta/recipes-devtools/python/python3/python3-manifest.json
+++ b/poky/meta/recipes-devtools/python/python3/python3-manifest.json
@@ -216,7 +216,7 @@
},
"core": {
"summary": "Python interpreter and core modules",
- "rdepends": [],
+ "rdepends": ["compression"],
"files": [
"${bindir}/python${PYTHON_MAJMIN}",
"${bindir}/python${PYTHON_MAJMIN}.real",
diff --git a/poky/meta/recipes-devtools/python/python3_3.12.4.bb b/poky/meta/recipes-devtools/python/python3_3.12.12.bb
index 0cb84b91b4..9a957c59bc 100644
--- a/poky/meta/recipes-devtools/python/python3_3.12.4.bb
+++ b/poky/meta/recipes-devtools/python/python3_3.12.12.bb
@@ -29,20 +29,23 @@ SRC_URI = "http://www.python.org/ftp/python/${PV}/Python-${PV}.tar.xz \
file://0001-Update-test_sysconfig-for-posix_user-purelib.patch \
file://0001-skip-no_stdout_fileno-test-due-to-load-variability.patch \
file://0001-test_storlines-skip-due-to-load-variability.patch \
- file://0001-gh-114492-Initialize-struct-termios-before-calling-t.patch \
file://0001-test_shutdown-skip-problematic-test.patch \
+ file://0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch \
+ file://0001-test_deadlock-skip-problematic-test.patch \
+ file://0001-test_active_children-skip-problematic-test.patch \
+ file://0001-test_readline-skip-limited-history-test.patch \
"
SRC_URI:append:class-native = " \
file://0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch \
"
-SRC_URI[sha256sum] = "f6d419a6d8743ab26700801b4908d26d97e8b986e14f95de31b32de2b0e79554"
+SRC_URI[sha256sum] = "fb85a13414b028c49ba18bbd523c2d055a30b56b18b92ce454ea2c51edc656c4"
# exclude pre-releases for both python 2.x and 3.x
UPSTREAM_CHECK_REGEX = "[Pp]ython-(?P<pver>\d+(\.\d+)+).tar"
-CVE_PRODUCT = "python cpython"
+CVE_PRODUCT = "python:python python_software_foundation:python cpython"
CVE_STATUS[CVE-2007-4559] = "disputed: Upstream consider this expected behaviour"
CVE_STATUS[CVE-2019-18348] = "not-applicable-config: This is not exploitable when glibc has CVE-2016-10739 fixed"
@@ -181,14 +184,14 @@ do_install:append:class-native() {
# when they're only used for python called with -O or -OO.
#find ${D} -name *opt-*.pyc -delete
# Remove all pyc files. There are a ton of them and it is probably faster to let
- # python create the ones it wants at runtime rather than manage in the sstate
+ # python create the ones it wants at runtime rather than manage in the sstate
# tarballs and sysroot creation.
find ${D} -name *.pyc -delete
# Nothing should be looking into ${B} for python3-native
sed -i -e 's:${B}:/build/path/unavailable/:g' \
${D}/${libdir}/python${PYTHON_MAJMIN}/config-${PYTHON_MAJMIN}${PYTHON_ABI}*/Makefile
-
+
# disable the lookup in user's site-packages globally
sed -i 's#ENABLE_USER_SITE = None#ENABLE_USER_SITE = False#' ${D}${libdir}/python${PYTHON_MAJMIN}/site.py
@@ -223,7 +226,7 @@ do_install:append() {
rm -f ${D}${libdir}/python${PYTHON_MAJMIN}/test/__pycache__/test_range.cpython*
rm -f ${D}${libdir}/python${PYTHON_MAJMIN}/test/__pycache__/test_xml_etree.cpython*
- # Similar to the above, we're getting reproducibility issues with
+ # Similar to the above, we're getting reproducibility issues with
# /usr/lib/python3.10/__pycache__/traceback.cpython-310.pyc
# so remove it too
rm -f ${D}${libdir}/python${PYTHON_MAJMIN}/__pycache__/traceback.cpython*
@@ -300,7 +303,7 @@ py_package_preprocess () {
cd -
mv ${PKGD}/${bindir}/python${PYTHON_MAJMIN}-config ${PKGD}/${bindir}/python${PYTHON_MAJMIN}-config-${MULTILIB_SUFFIX}
-
+
#Remove the unneeded copy of target sysconfig data
rm -rf ${PKGD}/${libdir}/python-sysconfigdata
}