diff options
| author | Andrew Geissler <geissonator@yahoo.com> | 2025-11-03 19:09:31 +0300 |
|---|---|---|
| committer | Andrew Geissler <geissonator@yahoo.com> | 2025-11-03 22:31:57 +0300 |
| commit | 6cb7f76381dbeb50bbf963f9192344f02d985637 (patch) | |
| tree | e194737ad2b6c562f463cc7a22116ef4aebd1232 /poky/meta/recipes-devtools/python | |
| parent | 1f52643312f6f67537eb27bef9156e8b8bc66040 (diff) | |
| download | openbmc-scarthgap.tar.xz | |
subtree updates (scarthgap 11/3/2025)scarthgap
poky: ca27724b44..c4a4df3e72:
Adam Blank (3):
kernel-dev/common.rst: fix the in-tree defconfig description
ref-manual/variables.rst: fix the description of KBUILD_DEFCONFIG
ref-manual/variables.rst: fix the description of STAGING_DIR
Aditya Tayade (1):
e2fsprogs: removed 'sed -u' option
Adrian Freihofer (15):
kernel-fitimage: fix intentation
kernel-fitimage: fix external dtb check
devtool: modify support debug-builds
devtool: ide-sdk sort cmake preset
devtool: ide-sdk recommend DEBUG_BUILD
oe-selftest: devtool ide-sdk use modify debug-build
devtool: ide-sdk remove the plugin from eSDK installer
uboot-config: fix devtool modify with kernel-fitimage
sdk-manual: extensible.rst: devtool ide-sdk improve
sdk-manual: extensible.rst: update devtool ide-sdk
ref-manual: kernel-fitimage.bbclass does not use SPL_SIGN_KEYNAME
llvm: update from 18.1.6 to 18.1.8
llvm: fix build with gcc-15
expect: Revert "expect-native: fix do_compile failure with gcc-14"
expect: fix native build with GCC 15
Alban Bedel (1):
bind: Fix build with the `httpstats` package config enabled
Aleksandar Nikolic (12):
cve-check: Introduce CVE_CHECK_MANIFEST_JSON_SUFFIX
install-buildtools: remove md5 checksum validation
install-buildtools: fix "test installation" step
install-buildtools: update base-url, release and installer version
ref-manual: introduce CVE_CHECK_REPORT_PATCHED variable
scripts/install-buildtools: Update to 5.0.5
scripts/install-buildtools: Update to 5.0.6
scripts/install-buildtools: Update to 5.0.7
scripts/install-buildtools: Update to 5.0.9
scripts/install-buildtools: Update to 5.0.10
scripts/install-buildtools: Update to 5.0.11
scripts/install-buildtools: Update to 5.0.12
Alessio Cascone (1):
tzcode-native: Fix compiler setting from 2023d version
Alexander Kanavin (29):
mesa: remove obsolete 0001-meson.build-check-for-all-linux-host_os-combinations.patch
kexec-tools: submit 0003-kexec-ARM-Fix-add_buffer_phys_virt-align-issue.patch upstream
vorbis: mark patch as Inactive-Upstream
grub: mark grub-module-explicitly-keeps-symbole-.module_license.patch as a workaround
perl: submit the rest of determinism.patch upstream
iptables: submit 0001-configure-Add-option-to-enable-disable-libnfnetlink.patch upstream
xserver-xorg: upgrade 21.1.12 -> 21.1.13
mobile-broadband-provider-info: upgrade 20230416 -> 20240407
python3: submit deterministic_imports.patch upstream as a ticket
glib-networking: submit eagain.patch upstream
glslang: mark 0001-generate-glslang-pkg-config.patch as Inappropriate
tcp-wrappers: mark all patches as inactive-upstream
automake: mark new_rt_path_for_test-driver.patch as Inappropriate
settings-daemon: submit addsoundkeys.patch upstream and update to a revision that has it
dpkg: mark patches adding custom non-debian architectures as inappropriate for upstream
libacpi: mark patches as inactive-upstream
apr: drop 0007-explicitly-link-libapr-against-phtread-to-make-gold-.patch
pulseaudio, desktop-file-utils: correct freedesktop.org -> www.freedesktop.org SRC_URI
sysvinit: take release tarballs from github
package_rpm: use zstd's default compression level
package_rpm: restrict rpm to 4 threads
rust: add reproducibility patch to eliminate host leakage
rust: build the default set of tools
rust: use rust-snapshot binaries only in rust-native
rust: correctly link rust-snapshot into build/stage0
pkg-config-native: pick additional search paths from $EXTRA_NATIVE_PKGCONFIG_PATH
selftest/rust: correctly form the PATH environment variable
perlcross: update 1.5.2 -> 1.6
mtools: upgrade 4.0.43 -> 4.0.44
Alexis Cellier (1):
systemd: add libpcre2 as RRECOMMENDS if pcre2 is enabled
Alexis Lothoré (3):
oeqa/utils/postactions: transfer whole archive over ssh instead of doing individual copies
oeqa/postactions: fix exception handling
oeqa/ssh: allow to retrieve raw, unformatted ouput
Alon Bar-Lev (1):
module.bbclass: add KBUILD_EXTRA_SYMBOLS to install
Alper Ak (2):
ref-manual/variables.rst: document INHIBIT_DEFAULT_RUST_DEPS
ref-manual/variables.rst: document INHIBIT_UPDATERCD_BBCLASS
Anders Heimer (1):
libpam: mark CVE-2025-6018 as not applicable
Andrew Fernandes (1):
gtk+: add missing libdrm dependency
Andrew Kreimer (1):
manuals: remove repeated word
Antonin Godard (77):
ref-manual: add missing CVE_CHECK manifest variables
ref-manual: add missing TESTIMAGE_FAILED_QA_ARTIFACTS
ref-manual: add missing EXTERNAL_KERNEL_DEVICETREE variable
ref-manual: add missing OPKGBUILDCMD variable
ref-manual: merge patch-status-* to patch-status
ref-manual: structure.rst: document missing tmp/ dirs
overview-manual: concepts: add details on package splitting
ref-manual: faq: add q&a on class appends
ref-manual: release-process: update releases.svg
ref-manual: release-process: refresh the current LTS releases
ref-manual: release-process: update releases.svg with month after "Current"
ref-manual: release-process: add a reference to the doc's release
ref-manual: devtool-reference: refresh example outputs
ref-manual: devtool-reference: document missing commands
conf.py: rename :cve: role to :cve_nist:
doc: Makefile: remove inkscape, replace by rsvg-convert
doc: Makefile: add support for xelatex
doc: add a download page for epub and pdf
sphinx-static/switchers.js.in: do not refer to URL_ROOT anymore
conf.py: add a bitbake_git extlink
dev-manual: document how to provide confs from layer.conf
dev-manual: bblock: use warning block instead of attention
standards.md: add a section on admonitions
ref-manual: classes: fix bin_package description
Gather dependencies in poky.yaml.in
poky.yaml.in: add missing locales dependency
poky.yaml.in: replace inkscape dependency by librsvg2-bin
system-requirements: add fedora 39 to supported distros
system-requirements: update list of supported distros
system-requirements.rst: add dependencies for pdf builds
Update the documentation for SRCPV
poky.conf: add new tested distros
ref-manual/qa-checks: remove patch-status-core/patch-status-noncore
contributor-guide/submit-changes.rst: suggest to remove the git signature
ref-manual/devtool-reference: add warning note on deploy-target and shared objects
SSTATE_MIRRORS/SOURCE_MIRROR_URL: add instructions for mirror authentication
ref-manual/packages: move ptest section to the test-manual
ref-manual: move runtime-testing section to the test-manual
Update autobuilder URLs to valkyrie
test-manual/reproducible-builds: fix reproducible links
test-manual/ptest: link to common framework ptest classes
dev-manual/building: document the initramfs-framework recipe
ref-manual/faq: add q&a on systemd as default
contributor-guide/submit-changes: add policy on AI generated code
Add favicon for the documentation html
overview-manual/concepts: remove PR from the build dir list
ref-manual/variables.rst: WATCHDOG_TIMEOUT: fix recipe name
ref-manual/variables.rst: document autotools class related variables
documentation/conf.py: define a manpage url
ref-manual/variables.rst: add manpage links for toolchain variables
ref-manual/variables.rst: add missing documentation for BUILD_* variables
ref-manual/variables.rst: document missing SDK_*_ARCH variables
ref-manual/variables.rst: document HOST_*_ARCH variables
ref-manual/variables.rst: HOST_CC_ARCH: fix wrong SDK reference
ref-manual/variables.rst: improve the PKGV documentation
poky.yaml: introduce DISTRO_LATEST_TAG
Fix dead links that use the DISTRO macro
dev-manual/sbom.rst: fix wrong build outputs
test-manual/intro: remove Buildbot version used
ref-manual/release-process: update releases.svg
overview-manual/concepts.rst: fix sayhello hardcoded bindir
ref-manual/system-requirements.rst: update supported distributions
ref-manual/variables.rst: document the FIT_CONF_PREFIX variable
ref-manual/variables.rst: document SPL_DTB_BINARY
ref-manual/classes.rst: document the testexport class
dev-manual/security-subjects.rst: update mailing lists
test-manual/yocto-project-compatible.rst: fix a typo
ref-manual/structure: document the auto.conf file
ref-manual/variables.rst: document UNINATIVE_URL/CHECKSUM
ref-manual/classes.rst: extend the uninative class documentation
ref-manual/classes,variables: document the CCACHE_DISABLE variable
ref-manual/variables.rst: document the REQUIRED_MACHINE_FEATURES variable
ref-manual/variables.rst: document the REQUIRED_COMBINED_FEATURES variable
ref-manual/variables.rst: document the REQUIRED_IMAGE_FEATURES variable
ref-manual/variables.rst: document the USE_NLS variable
ref-manual/classes.rst: gettext: extend the documentation of the class
ref-manual/classes.rst: document the relative_symlinks class
Anuj Mittal (1):
sqlite3: upgrade 3.45.1 -> 3.45.3
Archana Polampalli (51):
less: fix CVE-2024-32487
ofono: fix CVE-2023-2794
ffmpeg: fix CVE-2023-49502
ffmpeg: fix CVE-2024-31578
ffmpeg: fix CVE-2024-31582
ffmpeg: fix CVE-2023-50008
ffmpeg: fix CVE-2024-32230
qemu: fix CVE-2024-7409
ffmpeg: fix CVE-2023-49501
ffmpeg: fix CVE-2024-28661
ffmpeg: fix CVE-2023-50007
ffmpeg: fix CVE-2023-49528
ffmpeg: fix CVE-2024-7055
ffmpeg: fix CVE-2024-35366
ffmpeg: fix CVE-2024-35367
ffmpeg: fix CVE-2024-35368
rsync: fix CVE-2024-12084
rsync: fix CVE-2024-12085
rsync: fix CVE-2024-12086
rsync: fix CVE-2024-12087
rsync: fix CVE-2024-12088
rsync: fix CVE-2024-12747
ffmpeg: fix CVE-2024-35365
ffmpeg: fix CVE-2024-36613
ffmpeg: fix CVE-2024-36616
ffmpeg: fix CVE-2024-36617
ffmpeg: fix CVE-2024-36618
ffmpeg: fix CVE-2024-36619
ffmpeg: fix CVE-2024-35369
gstreamer1.0-rtsp-server: fix CVE-2024-44331
ffmpeg: fix CVE-2025-25473
ffmpeg: fix CVE-2025-25471
ffmpeg: fix CVE-2025-22921
ffmpeg: fix CVE-2025-0518
ffmpeg: Correct the CVE ID to fix CVE-2025-22919
openssh: fix CVE-2025-26465
go: fix CVE-2025-22870
ghostscript: upgrade 10.04.0 -> 10.05.0
perlcross: 1.6 -> 1.6.2
perl: upgrade 5.38.2 -> 5.38.4
xwayland: fix CVE-2025-49175
xwayland: fix CVE-2025-49176
xwayland: fix CVE-2025-49177
xwayland: fix CVE-2025-49178
xwayland: fix CVE-2025-49179
xwayland: fix CVE-2025-49180
gdk-pixbuf: fix CVE-2025-7345
go: fix CVE-2025-4674
ffmpeg: upgrade 6.1.2 -> 6.1.3
ffmpeg: fix CVE-2025-1594
go: fix CVE-2025-47906
Ashish Sharma (11):
bind: Upgrade 9.18.25 -> 9.18.28
ruby: Backport fix for CVE-2024-27282
ruby: Fix CVE-2025-27219
binutils: Fix CVE-2025-1176
binutils: patch CVE-2025-1178 & CVE-2024-57360
binutils: patch CVE-2025-1181
binutils: patch CVE-2025-1182
libsoup: patch CVE-2025-46420
libsoup-2.4: Fix CVE-2025-46420
libsoup: patch CVE-2025-4476
screen: patch CVE-2025-46805
AshishKumar Mishra (2):
systemd: backport fix for handle USE_NLS from master
p11-kit: backport fix for handle USE_NLS from master
Barne Carstensen (1):
test-manual: update runtime-testing Exporting Tests section
Bartosz Golaszewski (1):
linux-firmware: add a package for ath12k firmware
Benjamin Szőke (2):
archiver.bbclass: Fix work-shared checking for kernel recipes
mc: fix source URL
Bin Lan (1):
lttng-ust: backport patch to fix cmake-multiple-shared-libraries build error
Bruce Ashfield (54):
linux-yocto/6.6: update to v6.6.36
linux-yocto/6.6: update to v6.6.38
linux-yocto/6.6: update to v6.6.40
linux-yocto/6.6: update to v6.6.43
kernel-devsrc: remove 64 bit vdso cmd files
linux-yocto/6.6: update to v6.6.44
linux-yocto/6.6: update to v6.6.45
linux-yocto/6.6: fix genericarm64 config warning
linux-yocto/6.6: update to v6.6.47
linux-yocto/6.6: update to v6.6.49
linux-yocto/6.6: update to v6.6.50
linux-yocto/6.6: update to v6.6.52
linux-yocto/6.6: update to v6.6.54
linux-yocto/6.6: update to v6.6.56
linux-yocto/6.6: update to v6.6.58
linux-yocto/6.6: genericarm64.cfg: enable CONFIG_DMA_CMA
linux-yocto/6.6: update to v6.6.59
linux-yocto/6.6: update to v6.6.60
linux-yocto/6.6: update to v6.6.62
linux-yocto/6.6: bsp/genericarm64: disable ARM64_SME
linux-yocto/6.6: update to v6.6.63
linux-yocto/6.6: update to v6.6.64
linux-yocto/6.6: update to v6.6.66
linux-yocto/6.6: update to v6.6.69
linux-yocto/6.6: update to v6.6.75
linux-yocto/6.6: update to v6.6.77
linux-yocto/6.6: update to v6.6.78
linux-yocto/6.6: update to v6.6.80
linux-yocto/6.6: update to v6.6.82
linux-yocto/6.6: update to v6.6.83
linux-yocto/6.6: update to v6.6.84
linux-yocto/6.6: update to v6.6.85
linux-yocto/6.6: fix beaglebone ethernet
linux-yocto/6.6: update to v6.6.86
linux-yocto/6.6: update to v6.6.87
linux-yocto/6.6: update to v6.6.88
linux-yocto/6.6: update to v6.6.89
linux-yocto/6.6: update to v6.6.91
linux-yocto/6.6: update to v6.6.92
linux-yocto/6.6: update to v6.6.93
linux-yocto/6.6: update to v6.6.94
linux-yocto/6.6: update to v6.6.96
linux-yocto/6.6: update to v6.6.98
linux-yocto/6.6: update to v6.6.99
linux-yocto/6.6: update to v6.6.100
linux-yocto/6.6: update to v6.6.101
linux-yocto/6.6: update to v6.6.102
linux-yocto/6.6: update to v6.6.103
linux-yocto/6.6: update to v6.6.106
linux-yocto/6.6: update to v6.6.107
linux-yocto/6.6: update to v6.6.108
linux-yocto/6.6: update to v6.6.109
linux-yocto/6.6: update to v6.6.110
linux-yocto/6.6: update to v6.6.111
Carlos Alberto Lopez Perez (1):
icu: Backport patch to fix build issues with long paths (>512 chars)
Carlos Sánchez de La Lama (1):
ref-manual: clarify KCONFIG_MODE default behaviour
Catalin Popescu (1):
Revert "bluez5: remove configuration files from install task"
Changqing Li (48):
apt-native: don't let dpkg overwrite files by default
apt: runtime error: filename too long (tmpdir length)
webkitgtk: fix do_configure error on beaglebone-yocto
webkitgtk: fix do_compile errors on beaglebone-yocto
vulkan-samples: fix do_compile error when -Og enabled
multilib.conf: remove appending to PKG_CONFIG_PATH
gettext: fix a parallel build issue
pixman: fixing inline failure with -Og
rt-tests: rt_bmark.py: fix TypeError
curl: correct the PACKAGECONFIG for native/nativesdk
libpng: update SRC_URI
expect-native: fix do_compile failure with gcc-14
libcap-ng: update SRC_URI
sysvinit: backport patch for fixing one issue of pidof
acpica: fix CVE-2024-24856
libsoup: fix CVE-2024-52530, CVE-2024-52531
rxvt-unicode.inc: disable the terminfo installation by setting TIC to :
sanity.bbclass: skip check_userns for non-local uid
systemd: enable create-log-dirs
babeltrace: extend to nativesdk
babeltrace2: extend to nativesdk
patch.py: set commituser and commitemail for addNote
initscripts: add function log_success_msg/log_failure_msg/log_warning_msg
buildtools-tarball: move setting of envvars to respective envfile
buildtools-tarball: add envvars into BB_ENV_PASSTHROUGH_ADDITIONS
buildtools-tarball: Make buildtools respects host CA certificates
libsoup: fix CVE-2025-32908
libsoup: fix CVE-2025-32907
libsoup-2.4: fix CVE-2025-32907
libsoup-2.4: fix do_compile failure
libsoup-2.4: fix CVE-2025-32053
libsoup: fix CVE-2025-32053
libsoup-2.4: fix CVE-2025-32052
libsoup: fix CVE-2025-32052
libsoup: fix CVE-2025-32051
libsoup-2.4: fix CVE-2025-32050
libsoup: fix CVE-2025-32050
libsoup-2.4: fix CVE-2025-46421
libsoup: fix CVE-2025-46421
libsoup-2.4: fix CVE-2025-4948
libsoup: fix CVE-2025-4948
libsoup-2.4: fix CVE-2025-4476
libsoup-2.4: fix CVE-2025-2784
libsoup: fix CVE-2025-2784
icu: fix CVE-2025-5222
libsoup-2.4: refresh CVE-2025-4969.patch
libsoup-2.4: fix CVE-2025-4945
libsoup: fix CVE-2025-4945
Chen Qi (8):
libnl: change HOMEPAGE
qemu: back port patches to fix riscv64 build failure
toolchain-shar-extract.sh: exit when post-relocate-setup.sh fails
libgfortran: fix buildpath QA issue
bitbake: data_smart.py: remove unnecessary ? from __expand_var_regexp__
bitbake: data_smart.py: simple clean up
bitbake: data_smart.py: clear expand_cache in _setvar_update_overridevars
coreutils: fix CVE-2025-5278
Chris Laplante (6):
bitbake: persist_data: close connection in SQLTable __exit__
bitbake: fetch2: use persist_data context managers
bitbake: ui/knotty: print log paths for failed tasks in summary
bitbake: ui/knotty: respect NO_COLOR & check for tty; rename print_hyperlink => format_hyperlink
bitbake: cooker: Make cooker 'skiplist' per-multiconfig/mc
util-linux: use ${B} instead of ${WORKDIR}/build, to fix building under devtool
Christian Taedcke (1):
iptables: fix memory corruption when parsing nft rules
Christos Gavros (2):
ref-manual/variables.rst: document the IMAGE_ROOTFS_MAXSIZE variable
ref-manual/variables.rst: document the INITRAMFS_MAXSIZE variable
Claus Stovgaard (1):
lib/oe/package-manager: skip processing installed-pkgs with empty globs
Clayton Casciato (1):
uboot-sign: fix concat_dtb arguments
Colin McAllister (2):
udev-extraconf: Add collect flag to mount
busybox: Fix cut with "-s" flag
Colin Pinnell McAllister (1):
ffmpeg: fix CVE-2025-1373
Daniel Semkowicz (2):
os-release: Fix VERSION_CODENAME in case it is empty
gstreamer1.0-plugins-bad: fix buffer allocation fail for v4l2codecs
Daniel Turull (4):
package: export debugsources in PKGDESTWORK as json
spdx: add option to include only compiled sources
xz: ignore CVE-2024-47611
libxml2: ignore CVE-2025-8732
David Nyström (3):
openssh: fix CVE-2025-61985
openssh: fix CVE-2025-61984
lz4: fix CVE-2025-62813
Deepak Rathore (1):
default-distrovars.inc: Fix CONNECTIVITY_CHECK_URIS redirect issue
Deepesh Varatharajan (13):
binutils: stable 2.42 branch updates
glibc: stable 2.39 branch updates.
binutils: stable 2.42 branch update
binutils: Fix CVE-2025-0840
glibc: stable 2.39 branch updates
binutils: stable 2.42 branch updates
binutils: Fix CVE-2025-5245
binutils: Fix CVE-2025-5244
gcc: Upgrade to GCC 13.4
binutils: stable 2.42 branch updates
binutils: Fix CVE-2025-7545
glibc: stable 2.39 branch updates
glibc: stable 2.39 branch updates
Deepthi Hemraj (5):
binutils: stable 2.42 branch updates
glibc: stable 2.39 branch updates
rust-llvm: Fix CVE-2024-0151
binutils: stable 2.42 branch update
glibc: stable 2.39 branch updates
Denys Dmytriyenko (3):
weston: upgrade 13.0.0 -> 13.0.1
gcc: unify cleanup of include-fixed, apply to cross-canadian
nativesdk-libtool: sanitize the script, remove buildpaths
Divya Chellam (16):
libpam: fix CVE-2024-10041
libxml2: Upgrade 2.12.8 -> 2.12.9
wget: fix CVE-2024-10524
vim: Upgrade 9.1.0764 -> 9.1.1043
vim: Upgrade 9.1.1043 -> 9.1.1115
ruby: fix CVE-2025-27220
ruby: fix CVE-2025-27221
screen: fix CVE-2025-46802
screen: fix CVE-2025-46804
libarchive: fix CVE-2025-5914
libarchive: fix CVE-2025-5915
libarchive: fix CVE-2025-5916
libarchive: fix CVE-2025-5917
libarchive: fix CVE-2025-5918
wpa-supplicant: fix CVE-2022-37660
vim: upgrade 9.1.1652 -> 9.1.1683
Divyanshu Rathore (1):
ffmpeg: upgrade 6.1.1 -> 6.1.2
Dixit Parmar (1):
ref-manual: document KERNEL_SPLIT_MODULES variable
Dmitry Baryshkov (1):
xserver-xorg: fix CVE-2023-5574 status
Emil Kronborg (3):
insane.bbclass: remove skipping of cross-compiled packages
insane.bbclass: fix HOST_ variable names
insane.bbclass: remove leftover variables and comment
Enrico Jörns (6):
wic: engine.py: use raw string for escape sequence
wic: bootimg-efi: fix error handling
bitbake: bitbake-diffsigs: fix handling when finding only a single sigfile
ref-manual/variables.rst: update ROOT_HOME documentation
conf.py: tweak SearchEnglish to be hyphen-friendly
conf.py: improve SearchEnglish to handle terms with dots
Erik Lindsten (1):
overview-manual/yp-intro.rst: fix broken link to article
Esben Haabendal (3):
pulseaudio: fix webrtc audio depdency
files: Amend overlayfs unit descriptions with path information
files: overlayfs-create-dirs: Improve mount unit dependency
Etienne Cordonnier (6):
oeqa/runtime: fix regression in minidebuginfo test
oeqa/runtime: make minidebuginfo test work with coreutils
oeqa/runtime: fix race-condition in minidebuginfo test
python3-setuptools-scm: respect GIT_CEILING_DIRECTORIES
ref-manual/variables.rst: document SSTATE_SKIP_CREATION
bitbake: gcp.py: remove slow calls to gsutil stat
Fabio Berton (2):
ccache.conf: Add include_file_ctime to sloppiness
linux-libc-headers: Fix invalid conversion in cn_proc.h
Florian Kreutzer (1):
dropbear: backport fix for concurrent channel open/close
Gassner, Tobias.ext (1):
rootfs: Ensure run-postinsts is not uninstalled for read-only-rootfs-delayed-postinsts
Gauthier HADERER (1):
populate_sdk_ext.bclass: make sure OECORE_NATIVE_SYSROOT is exported.
Guocai He (2):
tcf-agent: correct the SRC_URI
minicom: correct the SRC_URI
Guénaël Muller (1):
ref-manual: use standardized method accross both ubuntu and debian for locale install
Guðni Már Gilbert (15):
pam: Fix for CVE-2024-22365
python3-attrs: drop python3-ctypes from RDEPENDS
bluez5: remove redundant patch for MAX_INPUT
shared-mime-info: drop itstool-native from DEPENDS
libpam: drop cracklib from DEPENDS
systemd: drop intltool-native from DEPENDS
systemd-boot: drop intltool-native from DEPENDS
python3-poetry-core: drop python3-six from RDEPENDS
dnf: drop python3-iniparse from DEPENDS and RDEPENDS
python3: upgrade 3.12.6 -> 3.12.7
python3: upgrade 3.12.7 -> 3.12.8
systemd: upgrade 255.13 -> 255.17
systemd: upgrade 255.17 -> 255.18
bluez5: add missing tools to noinst-tools package
systemd: upgrade 255.18 -> 255.21
Gyorgy Sarvari (1):
conf/bitbake.conf: use gnu mirror instead of main server
Haixiao Yan (2):
glibc: Add single-threaded fast path to rand()
buildtools-tarball: fix unbound variable issues under 'set -u'
Harish Sadineni (7):
binutils: Add missing perl modules to RDEPENDS for nativesdk variant
rust-target-config: Fix TARGET_C_INT_WIDTH with correct size
rust: fix for rust multilib sdk configuration
rust: remove redundant cargo config file
oeqa/sdk/context: fix for gtk3 test failure during do_testsdk
binutils: Fix CVE-2025-1179
binutils: set CVE_STATUS for CVE-2025-1180
Hiago De Franco (2):
weston: backport patch to allow neatvnc < v0.9.0
bluez5: backport patch to fix address type when loading keys
Hitendra Prajapati (24):
ghostscript: upgrade 10.02.1 -> 10.03.1
ruby: fix CVE-2024-27281
vte: fix CVE-2024-37535
curl: fix CVE-2024-8096
webkitgtk: upgrade 2.44.1 -> 2.44.3
cups: Backport fix for CVE-2024-47175
libarchive: fix CVE-2024-48957 & CVE-2024-48958
libsoup: fix CVE-2024-52532
ghostscript: upgrade 10.03.1 -> 10.04.0
libsndfile: fix CVE-2024-50612
ofono: Fix multiple CVEs
libcap: fix CVE-2025-1390
elfutils: Fix multiple CVEs
go: fix CVE-2025-22871
libsoup-3.4.4: Fix CVE-2025-4969
libsoup-2.4: Fix CVE-2025-4969
libxml2: fix CVE-2025-6021
libxml2: fix CVE-2025-49794 & CVE-2025-49796
libpam: fix CVE-2025-6020
gstreamer1.0-plugins-base: fix CVE-2025-47808
gstreamer1.0-plugins-base: fix CVE-2025-47806
gstreamer1.0-plugins-good: fix multiple CVEs
gstreamer1.0-plugins-base: fix CVE-2025-47807
grub2: mark CVE-2024-2312 as not applicable
Hongxu Jia (10):
ovmf: fix CVE-2024-38796
ovmf: fix CVE-2024-1298
u-boot: fix CVE-2024-57254
u-boot: fix CVE-2024-57255
u-boot: fix CVE-2024-57256
u-boot: fix CVE-2024-57257
u-boot: fix CVE-2024-57258
u-boot: fix CVE-2024-57259
rpm: keep leading `/' from sed operation
u-boot: fix CVE-2024-42040
Igor Opaniuk (1):
wic: bootimg-efi: Support + symbol in filenames
Jaeyoon Jung (2):
makedevs: Fix issue when rootdir of / is given
makedevs: Fix matching uid/gid
Jagadeesh Krishnanjanappa (1):
tune-cortexa32: set tune feature as armv8a
Jan Vermaete (1):
sdk: The main in the C example should return an int
Jeroen Hofstee (2):
bluez5: make media control a PACKAGECONFIG option
bluez5: backport a patch to fix btmgmt -i
Jiaying Song (9):
liba52: fix do_fetch error
enchant2: fix do_fetch error
libxml-parser-perl: fix do_fetch error
python3-zipp: fix CVE-2024-5569
subversion: fix CVE-2024-46901
boost: fix do_fetch error
binutils: File name too long causing failure to open temporary head file in dlltool
python3-requests: upgrade 2.32.3 -> 2.32.4
ruby-ptest : some ptest fixes
Jinfeng Wang (3):
tzdata&tzcode-native: upgrade 2024a -> 2024b
mtools: upgrade 4.0.48 -> 4.0.49
systemtap: Fix task_work_cancel build
Joao Marcos Costa (1):
ref-manual/variables.rst: expand IMAGE_OVERHEAD_FACTOR glossary entry
Joe Slater (1):
oe-debuginfod: add option for data storage
Joerg Schmidt (1):
bitbake: bblayers/query: Fix using "removeprefix" string method
Johannes Schneider (1):
ppp: Revert lock path to /var/lock
Jon Mason (4):
oeqa/runtime/ssh: add retry logic and sleeps to allow for slower systems
oeqa/runtime/ssh: check for all errors at the end
oeqa/runtime/ssh: increase the number of attempts
openssh: add backported header file include
Jonas Gorski (1):
rootfs-postcommands.bbclass: make opkg status reproducible
Jookia (1):
populate_sdk_ext.bbclass: Fix undefined variable error
Jose Quaresma (7):
go: upgrade 1.22.4 -> 1.22.5
oeqa/runtime/scp: requires openssh-sftp-server
openssh: drop rejected patch fixed in 8.6p1 release
openssh: systemd sd-notify patch was rejected upstream
openssh: systemd notification was implemented upstream
go: upgrade 1.22.5 -> 1.22.6
bitbake: bitbake: doc/user-manual: Update the BB_HASHSERVE_UPSTREAM
Joshua Watt (3):
bitbake: asyncrpc: Use client timeout for websocket open timeout
bitbake: Remove custom exception backtrace formatting
bitbake: Use a "fork" multiprocessing context
João Marcos Costa (1):
variables.rst: fix LAYERDEPENDS description
Julien Stephan (5):
README: add instruction to run Vale on a subset
documentation: Makefile: add SPHINXLINTDOCS to specify subset to sphinx-lint
styles: vocabularies: Yocto: add sstate
ref-manual: variables: add SIGGEN_LOCKEDSIGS* variables
dev-manual: add bblock documentation
Jörg Sommer (5):
classes/kernel: No symlink in postinst without KERNEL_IMAGETYPE_SYMLINK
doc/features: remove duplicate word in distribution feature ext2
doc/features: describe distribution feature pni-name
ptest-runner: Update 2.4.4 -> 2.4.5
runqemu: Fix detection of -serial parameter
Kai Kang (3):
multilib.bbclass: replace deprecated e.data with d
cmake-qemu.bbclass: fix if criterion
glibc: fix fortran header file conflict for arm
Khem Raj (26):
linux-yocto: Enable team net driver
systemd.bbclass: Clarify error message
grub,grub-efi: Remove -mfpmath=sse on x86
python3: Treat UID/GID overflow as failure
gawk: Remove References to /usr/local/bin/gawk
busybox: CVE-2023-42364 and CVE-2023-42365 fixes
busybox: Add fix for CVE-2023-42366
gcc: Fix spurious '/' in GLIBC_DYNAMIC_LINKER on microblaze
gnupg: Document CVE-2022-3219 and mark wontfix
openssh: Mark CVE-2023-51767 as wont-fix
libpcre2: Update base uri PhilipHazel -> PCRE2Project
python3: Drop empty patch
qemu: Do not define sched_attr with glibc >= 2.41
e2fsprogs: Fix build failure with gcc 15
parted: Fix build with GCC 15
bash: Stick to C17 std
ncurses: Pin to C17 standard
unzip: Fix build with GCC-15
m4: Stick to C17 standard
gmp: Fix build with GCC15/C23
gmp: Fix build with older gcc versions
gdbm: Use C11 standard
unifdef: Don't use C23 constexpr keyword
libtirpc: Fix build with gcc-15/C23
cpio: Pin to use C17 std
expect: Fix build with GCC 15
Kirill Yatsenko (1):
iptables: fix save/restore symlinks with libnftnl PACKAGECONFIG enabled
Konrad Weihmann (3):
runqemu: keep generating tap devices
testimage: fallback for empty IMAGE_LINK_NAME
testexport: fallback for empty IMAGE_LINK_NAME
Kyungjik Min (1):
pulseaudio: Add audio group explicitly
Lee Chee Yang (24):
migration-notes: add release notes for 5.0.1
migration-guides: add release notes for 4.0.19
migration-guides: add release notes for 5.0.2
migration-guide: add release notes for 4.0.20
migration-guides: add release notes for 5.0.3
migration-guide: add release notes for 4.0.21
migration-guides: add release notes for 5.0.4
migration-guide: add release notes for 4.0.22
migration-guides: add release notes for 5.0.5
migration-guides: add release notes for 4.0.23
migration-guides: add release notes for 5.0.6
migration-guides: add release notes for 4.0.24
migration-guides: add release notes for 5.0.7
migration-guides: add release notes for 4.0.25
migration-guides: add release notes for 5.0.8
migration-guides: add release notes for 4.0.26
migration-guides: add release notes for 5.0.9
migration-guides: add release notes for 4.0.27
migration-guide: add release notes for 5.0.10
migration-guides: add release notes for 4.0.28
migration-guides: add release notes for 5.0.11
migration-guides: add release notes for 4.0.29
migration-guides: add release notes for 5.0.12
migration-guides: add release notes for 4.0.30
Libo Chen (1):
runqemu: fix special characters bug
Louis Rannou (1):
image_qa: fix error handling
Macpaul Lin (1):
linux-firmware: upgrade 20240312 -> 20240909
Madhu Marri (1):
qemu 8.2.7: ignore CVE-2023-1386
Makarios Christakis (1):
icu: Adjust ICU_DATA_DIR path on big endian targets
Marco Cavallini (1):
dev-manual/start.rst: added missing command in Optimize your VHDX file using DiskPart
Marek Vasut (3):
u-boot: kernel-fitimage: Fix dependency loop if UBOOT_SIGN_ENABLE and UBOOT_ENV enabled
base-files: Drop /bin/sh dependency
u-boot: kernel-fitimage: Restore FIT_SIGN_INDIVIDUAL="1" behavior
Mark Hatle (9):
package.py: Fix static debuginfo split
package.py: Fix static library processing
selftest-hardlink: Add additional test cases
create-spdx-*: Support multilibs via SPDX_MULTILIB_SSTATE_ARCHS
oeqa sdk cases: Skip SDK test cases when TCLIBC is newlib
create-sdpx-2.2.bbclass: Switch from exists to isfile checking debugsrc
populate_sdk_ext: write_local_conf add shutil import
cve-update-nvd2-native: Handle BB_NO_NETWORK and missing db
bitbake: bitbake: runqueue: Verify mcdepends are valid
Markus Volk (3):
libadwaita: update 1.5.0 -> 1.5.1
gcc: add a backport patch to fix an issue with tzdata 2024b
ninja: fix build with python 3.13
Marta Rybczynska (1):
vulnerabilities/classes: remove references to cve-check text format
Martin Jansa (22):
selftest: add Upstream-Status to .patch files
libgfortran.inc: fix nativesdk-libgfortran dependencies
populate_sdk_base: inherit nopackages
meta-world-pkgdata: Inherit nopackages
python3-lxml=v5.0.2
mc: set ac_cv_path_ZIP to avoid buildpaths QA issues
libpam: re-add missing libgen include
cairo: fix build with gcc-15 on host
bash: use -std=gnu17 also for native CFLAGS
cmake: fix build with gcc-15 on host
git: fix build with gcc-15 on host
pkgconfig: fix build with gcc-15
libgpg-error: fix build with gcc-15
rust-llvm: fix build with gcc-15
elfutils: fix build with gcc-15
binutils: fix build with gcc-15
dbus-glib: fix build with gcc-15
bitbake: bitbake: Bump version to 2.8.1
license.py: avoid deprecated ast.Str
sanity.conf: Update minimum bitbake version to 2.8.1
lib/oe/utils: use multiprocessing from bb
flex: fix build with gcc-15 on host
Matthias Pritschet (1):
ref-manual: fix typo and move SYSROOT_DIRS example
Matthias Schiffer (1):
curl: only set CA bundle in target build
Michael Haener (1):
oeqa/runtime/ping: don't bother trying to ping localhost
Michael Halstead (4):
yocto-uninative: Update to 4.6 for glibc 2.40
yocto-uninative: Update to 4.7 for glibc 2.41
yocto-uninative: Update to 4.8 for GCC 15.1
yocto-uninative: Update to 4.9 for glibc 2.42
Michael Opdenacker (5):
maintainers.inc: update self e-mail address
doc: Makefile: publish pdf and epub versions too
dev-manual: fix styling of references to bmaptool
dev-manual/bmaptool.rst: correct command for bmaptool-native
dev-manual/bmaptool.rst: simplify and fix instructions
Michal Seben (1):
timedated: wait for jobs before SetNTP response
Mikko Rapeli (1):
ovmf-native: remove .pyc files from install
Mingli Yu (1):
llvm: Enable libllvm for native build
Moritz Haase (2):
meta: Enable '-o pipefail' for the SDK installer
cmake: Correctly handle cost data of tests with arbitrary chars in name
NeilBrown (1):
nfs-utils: don't use signals to shut down nfs server.
Nguyen Dat Tho (1):
libatomic-ops: Update GITHUB_BASE_URI
Nikhil R (1):
cmake: Add PACKAGECONFIG option for debugger support
Niko Mauno (15):
dnf/mesa: Fix missing leading whitespace with ':append'
libyaml: Fix warning regarding unpatched CVE
systemd: Mitigate /var/log type mismatch issue
systemd: Mitigate /var/tmp type mismatch issue
image_types.bbclass: Use --force also with lz4,lzop
util-linux: Add PACKAGECONFIG option to mitigate rootfs remount error
iw: Fix LICENSE
dejagnu: Fix LICENSE
unzip: Fix LICENSE
zip: Fix LICENSE
tiff: Fix LICENSE
gcr: Fix LICENSE
python3-maturin: Fix cross compilation issue for armv7l, mips64, ppc
cve-check.bbclass: Mitigate symlink related error
cve-check.bbclass: Fix symlink handling also for text files
Nitin Wankhade (1):
examples: genl: fix wrong attribute size
Oleksandr Hnatiuk (2):
icu: remove host references in nativesdk to fix reproducibility
gcc: remove paths to sysroot from configargs.h and checksum-options for gcc-cross-canadian
Patrick Wicki (1):
gpgme: move gpgme-tool to own sub-package
Paul Barker (2):
meta-ide-support: Mark recipe as MACHINE-specific
dev-manual, test-manual: Update autobuilder output links
Paul Gerber (1):
uboot-sign: fix counters in do_uboot_assemble_fitimage
Pavel Zhukov (1):
package_rpm: Check if file exists before open()
Pedro Ferreira (3):
buildhistory: Fix intermittent package file list creation
buildhistory: Restoring files from preserve list
rust-common.bbclass: soft assignment for RUSTLIB path
Peter Kjellerstedt (1):
image.bbclass: Drop support for ImageQAFailed exceptions in image_qa
Peter Marko (144):
flac: fix buildpaths warnings
cargo: remove True option to getVar calls
ncurses: switch to new mirror
busybox: Patch CVE-2021-42380
busybox: Patch CVE-2023-42363
libstd-rs,rust-cross-canadian: set CVE_PRODUCT to rust
curl: Patch CVE-2024-6197
glibc: cleanup old cve status
qemu: set cve status for CVE-2023-6683
libmnl: explicitly disable doxygen
libyaml: ignore CVE-2024-35326
libyaml: Ignore CVE-2024-35325
curl: Patch CVE-2024-7264
python3: Upgrade 3.12.5 -> 3.12.6
wpa-supplicant: Ignore CVE-2024-5290
wpa-supplicant: Patch CVE-2024-3596
wpa-supplicant: Patch security advisory 2024-2
rust: ignore CVE-2024-43402
openssl: patch CVE-2024-9143
cve-check: add support for cvss v4.0
go: upgrade 1.22.6 -> 1.22.7
go: upgrade 1.22.7 -> 1.22.8
dropbear: backport patch for CVE-2023-48795
curl: patch CVE-2024-9681
gstreamer1.0: set status for CVE-2024-0444
expat: upgrade 2.6.3 -> 2.6.4
builder: set CVE_PRODUCT
qemu: set CVE-2024-6505 to fixed
gstreamer1.0-plugins-good: fix several CVEs
gstreamer1.0-plugins-base: patch CVE-2024-47538
gstreamer1.0-plugins-base: patch CVE-2024-47607
gstreamer1.0-plugins-base: patch CVE-2024-47615
gstreamer1.0-plugins-good: patch CVE-2024-47613
gstreamer1.0-plugins-good: patch several CVEs
gstreamer1.0-plugins-base: patch CVE-2024-47541
gstreamer1.0-plugins-base: patch CVE-2024-47542
gstreamer1.0-plugins-good: patch CVE-2024-47599
gstreamer1.0-plugins-base: patch CVE-2024-47600
gstreamer1.0-plugins-good: patch CVE-2024-47606
gstreamer1.0-plugins-good: patch CVE-2024-47606
gstreamer1.0-plugins-good: patch CVE-2024-47774
gstreamer1.0-plugins-good: patch several CVEs
gstreamer1.0-plugins-base: patch CVE-2024-47835
gstreamer1.0: ignore CVEs fixed in plugins recipes
socat: patch CVE-2024-54661
ofono: patch CVE-2024-7540, CVE-2024-7541, CVE-2024-7542
ofono: patch CVE-2023-4232
ofono: patch CVE-2023-4235
openssl: patch CVE-2024-13176
go: upgrade 1.22.8 -> 1.22.9
go: upgrade 1.22.9 -> 1.22.10
go: upgrade 1.22.10 -> 1.22.11
glibc: stable 2.39 branch updates
python3: upgrade 3.12.8 -> 3.12.9
go: upgrade 1.22.11 -> 1.22.12
cmake: apply parallel build settings to ptest tasks
subversion: ignore CVE-2024-45720
gnutls: patch CVE-2024-12243
openssl: upgrade 3.2.3 -> 3.2.4
libxml2: upgrade 2.12.9 -> 2.12.10
grub: drop obsolete CVE statuses
grub: backport strlcpy function
grup: patch CVE-2024-45781
grub: patch CVE-2024-45782 and CVE-2024-56737
grub: patch CVE-2024-45780
grub: patch CVE-2024-45783
grub: patch CVE-2025-0624
grub: patch CVE-2024-45774
grub: patch CVE-2024-45775
grub: patch CVE-2025-0622
grub: patch CVE-2024-45776
grub: patch CVE-2024-45777
grub: patch CVE-2025-0690
grub: patch CVE-2025-1118
grub: patch CVE-2024-45778 and CVE-2024-45779
grub: patch CVE-2025-0677, CVE-2025-0684, CVE-2025-0685, CVE-2025-0686 and CVE-2025-0689
grub: patch CVE-2025-0678 and CVE-2025-1125
libarchive: patch CVE-2025-1632 and CVE-2025-25724
xserver-xorg: mark CVEs fixed in 21.1.16 as fixed
cve-update-nvd2-native: handle missing vulnStatus
expat: patch CVE-2024-8176
freetype: follow-up patch for CVE-2025-27363
ofono: patch CVE-2024-7537
cve-update-nvd2-native: add workaround for json5 style list
xz: upgrade 5.4.6 -> 5.4.7
xz: patch CVE-2025-31115
libarchive: upgrade 3.7.4 -> 3.7.9
sqlite3: patch CVE-2025-3277
sqlite3: patch CVE-2025-29088
ppp: patch CVE-2024-58250
libxml2: patch CVE-2025-32414
libxml2: patch CVE-2025-32415
glib-2.0: patch CVE-2025-3360
Revert "cve-update-nvd2-native: Tweak to work better with NFS DL_DIR"
sqlite3: mark CVE-2025-29087 as patched
python3: upgrade 3.12.9 -> 3.12.11
testimage: get real os-release file
net-tools: patch CVE-2025-46836
go: set status of CVE-2024-3566
glibc: stable 2.39 branch updates
python3: update CVE product
busybox: apply patch for CVE-2023-39810
iputils: patch CVE-2025-48964
orc: set CVE_PRODUCT
openssl: CVE-2024-41996
openssl: patch CVE-2025-27587
gnutls: patch CVE-2025-32989
gnutls: patch read buffer overrun in the "pre_shared_key" extension
gnutls: patch reject zero-length version in certificate request
gnutls: patch CVE-2025-32988
gnutls: patch CVE-2025-32990
gnutls: patch CVE-2025-6395
ncurses: patch CVE-2025-6141
libxml2: patch CVE-2025-6170
glibc: fix CVE-2025-8058
python3: patch CVE-2025-8194
go: ignore CVE-2025-0913
dropbear: patch CVE-2025-47203
glib-2.0: ignore CVE-2025-4056
qemu: set status of CVE-2024-7730 to fixed
go-binary-native: ignore CVE-2025-0913
glib-2.0: patch CVE-2025-7039
glib-2.0: patch CVE-2025-6052
dpkg: patch CVE-2025-6297
libarchive: patch regression of patch for CVE-2025-5918
vim: upgrade 9.1.1198 -> 9.1.1652
sudo: remove devtool FIXME comment
busybox: patch CVE-2025-46394
gstreamer1.0: ignore CVEs fixed in plugins
gstreamer1.0: ignore CVE-2025-2759
ghostscript: patch CVE-2025-59798
ghostscript: patch CVE-2025-59799
ghostscript: patch CVE-2025-59800
expat: follow-up for CVE-2024-8176
tiff: ignore 5 CVEs
ffmpeg: ignore 8 CVEs fixed in 6.1.1 and 6.1.3 releases
openssl: upgrade 3.2.4 -> 3.2.6
qemu: patch CVE-2024-8354
binutils: patch CVE-2025-11082
binutils: patch CVE-2025-11083
gnupg: mark CVE-2025-30258 as patched
python3: upgrade 3.12.11 -> 3.12.12
vulnerabilities: update nvdcve file name
expat: patch CVE-2025-59375
Philip Lorenz (3):
cmake: Fix sporadic issues when determining compiler internals
cve-check: Add missing call to exit_if_errors
shared-mime-info: Handle USE_NLS
Poonam Jadhav (2):
curl: ignore CVE-2025-0725
libpng: Add ptest
Praveen Kumar (7):
connman :fix CVE-2025-32743
connman :fix CVE-2025-32366
glib-2.0: fix CVE-2025-4373
go: fix CVE-2025-4673
sudo: upgrade 1.9.15p5 -> 1.9.17p1
go: fix CVE-2025-47907
bind: upgrade 9.18.33 -> 9.18.41
Preeti Sachan (1):
ltp: backport patch to fix compilation error for x86_64
Priyal Doshi (2):
tzdata/tzcode-native: upgrade 2024b -> 2025a
tzdata/tzcode-native: upgrade 2025a -> 2025b
Purushottam Choudhary (1):
virglrenderer: Add patch to fix -int-conversion build issue
Quentin Schulz (14):
mmc-utils: fix URL
weston-init: fix weston not starting when xwayland is enabled
docs: README: specify how to contribute instead of pointing at another file
docs: conf.py: silence SyntaxWarning on js_splitter_code
ref-manual: classes: reword to clarify that native/nativesdk options are exclusive
ref-manual: classes: nativesdk: move note to appropriate section
go-helloworld: fix license
contributor-guide: submit-changes: fix improper bold string
contributor-guide: submit-changes: clarify example with Yocto bug ID
contributor-guide: submit-changes: align CC tag description
contributor-guide: submit-changes: make the Cc tag follow kernel guidelines
contributor-guide: submit-changes: reword commit message instructions
contributor-guide: submit-changes: number instruction list in commit your changes
contributor-guide: submit-changes: make "Crediting contributors" part of "Commit your changes"
Rajeshkumar Ramasamy (2):
glib-networking: fix CVE-2025-60018
glib-networking: fix CVE-2025-60019
Randy MacLeod (1):
systemd: stable update 255.4 -> 255.13
Ranjitsinh Rathod (1):
rust: Add new varaible RUST_ENABLE_EXTRA_TOOLS
Rasmus Villemoes (1):
iptables: remove /etc/ethertypes
Regis Dargent (1):
udev-extraconf: fix network.sh script did not configure hotplugged interfaces
Richard Purdie (60):
selftest/cases/runtime_test: Exclude centos-9 from virgl tests
cve-exclusion: Drop the version comparision/warning
bitbake: codeparser/data: Ensure module function contents changing is accounted for
bitbake: codeparser: Skip non-local functions for module dependencies
pseudo: Update to pull in python 3.12+ fix
layer.conf: Add os-release to SIGGEN_EXCLUDERECIPES_ABISAFE
oeqa/sdk/case: Ensure DL_DIR is populated with artefacts if used
create-spdx-3.0/populate_sdk_base: Add SDK_CLASSES inherit mechanism to fix tarball SPDX manifests
pseudo: Fix to work with glibc 2.40
pseudo: Update to include open symlink handling bugfix
nasm: Upgrade 2.16.01 -> 2.16.03
oeqa/runtime/ssh: In case of failure, show exit code and handle -15 (SIGTERM)
oeqa/selftest/reproducibile: Explicitly list virtual targets
expat: 2.6.2 -> 2.6.3
ruby: Make docs generation deterministic
libedit: Make docs generation deterministic
buildhistory: Simplify intercept call sites and drop SSTATEPOSTINSTFUNC usage
scripts/install-buildtools: Update to 5.0.3
bitbake.conf: Add truncate to HOSTTOOLS
license: Fix directory layout issues
libsdl2: Fix non-deterministic configure option for libsamplerate
bitbake: tests/fetch: Use our own mirror of sysprof to decouple from gnome gitlab
bitbake: tests/fetch: Use our own mirror of mobile-broadband-provider to decouple from gnome gitlab
cve_check: Use a local copy of the database during builds
pseudo: Fix envp bug and add posix_spawn wrapper
oeqa/runtime/ssh: Rework ssh timeout
oeqa/runtime/ssh: Fix incorrect timeout fix
qemurunner: Clean up serial_lock handling
bitbake: fetch2/git: Use quote from shlex, not pipes
bitbake: fetch/wget: Increase timeout to 100s from 30s
bitbake: runqueue: Fix performance of multiconfigs with large overlap
bitbake: runqueue: Optimise setscene loop processing
bitbake: runqueue: Fix scenetask processing performance issue
do_package/sstate/sstatesig: Change timestamp clamping to hash output only
selftest/reproducible: Drop rawlogs
selftest/reproducible: Clean up pathnames
resulttool: Allow store to filter to specific revisions
resulttool: Use single space indentation in json output
oeqa/utils/gitarchive: Return tag name and improve exclude handling
resulttool: Fix passthrough of --all files in store mode
resulttool: Add --logfile-archive option to store mode
resulttool: Handle ltp rawlogs as well as ptest
resulttool: Clean up repoducible build logs
resulttool: Trim the precision of duration information
resulttool: Improve repo layout for oeselftest results
cve-update-nvd2-native: Tweak to work better with NFS DL_DIR
bitbake: tests/fetch: Fix git shallow test failure with git >= 2.48
bitbake: utils: Print information about lock issue before exiting
bitbake: utils: Tweak lock_timeout logic
bitbake: utils: Add signal blocking for lock_timeout
bitbake: event/utils: Avoid deadlock from lock_timeout() and recursive events
bitbake: toaster/tests/buildtest: Switch to new CDN
bitbake: fetch2: Avoid deprecation warning
sstatetests: Switch to new CDN
local.conf.sample: Switch to new CDN
bitbake: ast: Change deferred inherits to happen per recipe
brief-yoctoprojectqs/ref-manual: Switch to new CDN
bitbake: test/fetch: Switch u-boot based test to use our own mirror
mtools: upgrade 4.0.46 -> 4.0.47
bitbake: utils: Optimise signal/sigmask performance
Robert Kovacsics (1):
sdk: Fix path length limit to match reserved size
Robert P. J. Day (7):
Clean up explanation of minimum required version numbers
overview-manual: small number of pedantic cleanups
bsp guide: update kernel version example to 6.12
bsp-guide: update lonely "4.12" kernel reference to "6.12"
bsp-guide: update all of section 1.8.2 to reflect current beaglebone conf file
variables.rst: remove references to obsolete tar packaging
overview-manual/yp-intro.rst: update on-target packaging info
Robert Yang (7):
bitbake: data_smart: Improve performance for VariableHistory
release-notes-5.0.rst: NO_OUTPUT -> NO_COLOR
bitbake: gitsm: Add call_process_submodules() to remove duplicated code
bitbake: gitsm: Remove downloads/tmpdir when failed
cml1.bbclass: do_diffconfig: Don't override .config with .config.orig
libgcrypt: Fix building error with '-O2' in sysroot path
groff: Fix race issues for parallel build
Rogerio Guerra Borin (1):
u-boot: ensure keys are generated before assembling U-Boot FIT image
Rohini Sangam (1):
vim: Upgrade 9.1.0698 -> 9.1.0764
Roland Kovacs (3):
gnupg: update 2.4.5 -> 2.4.8
libxml2: fix CVE-2025-49795
sqlite3: fix CVE-2025-6965
Ross Burton (31):
cpio: mark CVE-2023-7216 as disputed
fribidi: upgrade 1.0.13 -> 1.0.14
gstreamer1.0: skip another known flaky test
libportal: fix rare build race
meson: don't use deprecated pkgconfig variable
curl: skip FTP tests in run-ptest
gawk: update patch status
python3-pycryptodome(x): use python_setuptools_build_meta build class
gstreamer1.0: disable flaky baseparser tests
librsvg: don't try to run target code at build time
icu: update patch Upstream-Status
strace: download release tarballs from GitHub
tcl: skip io-13.6 test case
groff: fix rare build race in hdtbl
sanity: check for working user namespaces
python3: add dependency on -compression to -core
classes/nativesdk: also override TUNE_PKGARCH
classes/qemu: use tune to select QEMU_EXTRAOPTIONS, not package architecture
oeqa/selftest/rust: skip on all MIPS platforms
Remove all mention of core-image-lsb
ref-manual: don't refer to poky-lsb
ref-manual: remove OE_IMPORTS
puzzles: ignore three new CVEs for a different puzzles
xserver-xf86-config: add a configuration fragment to disable screen blanking
xserver-xf86-config: remove obsolete configuration files
grub2: fix CVE-2024-56738
libxslt: apply patch for CVE-2025-7424
expect: update code for Tcl channel implementation
expect: don't run aclocal in do_configure
expect: cleanup do_install
pulseaudio: ignore CVE-2024-11586
Ryan Eatmon (2):
u-boot.inc: Refactor do_* steps into functions that can be overridden
uboot: Allow for customizing installed/deployed file names
Sana Kazi (1):
gcc-cross-canadian.inc: Fix buildpaths error for pthread.h
Sandeep Gundlupet Raju (1):
tune-cortexr52: Remove aarch64 for ARM Cortex-R52
Saravanan (2):
python3-xmltodict: fix CVE-2025-9375
cmake: fix CVE-2025-9301
Savvas Etairidis (1):
systemd: Rename systemd_v255.21 to systemd_255.21
Sergei Zhmylev (1):
lsb-release: fix Distro Codename shell escaping
Shubham Kulkarni (1):
libpam: Update fix for CVE-2024-10041
Shunsuke Tokumoto (1):
python3-setuptools: Add "python:setuptools" to CVE_PRODUCT
Siddharth Doshi (5):
Tiff: Security fix for CVE-2024-7006
vim: Upgrade 9.1.0114 -> 9.1.0682
wpa-supplicant: Upgrade 2.10 -> 2.11
vim: Upgrade 9.1.0682 -> 9.1.0698
openssl: Upgrade 3.2.2 -> 3.2.3
Simon A. Eugster (1):
documentation: Fix typo in standards.md
Simone Weiß (3):
tzdata: Add tzdata.zi to tzdata-core package
sanity: Check if tar is gnutar
curl: Ignore CVE-2024-32928
Soumya Sambu (12):
python3-idna: upgrade 3.6 -> 3.7
python3-certifi: Fix CVE-2024-39689
python3-setuptools: Fix CVE-2024-6345
python3: Fix CVE-2024-7592
python3: Fix CVE-2024-8088
python3-requests: upgrade 2.32.1 -> 2.32.2
python3-requests: upgrade 2.32.0 -> 2.32.3
python3-jinja2: upgrade 3.1.4 -> 3.1.6
git: Upgrade 2.44.1 -> 2.44.3
elfutils: Fix CVE-2025-1371
elfutils: Fix CVE-2025-1376
elfutils: Fix CVE-2025-1377
Stanislav Vovk (1):
libpam: fix CVE-2024-10963
Stefan Mueller-Klieser (1):
kernel-arch: add macro-prefix-map in KERNEL_CC
Steve Sakoman (35):
Revert "apt: runtime error: filename too long (tmpdir length)"
poky.conf: bump version for 5.0.3
build-appliance-image: Update to scarthgap head revision
Revert "wpa-supplicant: Upgrade 2.10 -> 2.11"
poky.conf: bump version for 5.0.4
build-appliance-image: Update to scarthgap head revision
build-appliance-image: Update to scarthgap head revision
release-notes-4.0: update BB_HASHSERVE_UPSTREAM for new infrastructure
poky.conf: bump version for 5.0.5
build-appliance-image: Update to scarthgap head revision
webkitgtk: fix erroneous use of unsuported DEBUG_LEVELFLAG variable
llvm: reduce size of -dbg package
poky.conf: bump version for 5.0.6
build-appliance-image: Update to scarthgap head revision
poky.conf: bump version for 5.0.7
build-appliance-image: Update to scarthgap head revision
Revert "rust: Add new varaible RUST_ENABLE_EXTRA_TOOLS"
build-appliance-image: Update to scarthgap head revision
poky.conf: add ubuntu2404 to SANITY_TESTED_DISTROS
poky.conf: bump version for 5.0.8
build-appliance-image: Update to scarthgap head revision
Revert "gcc-cross-canadian.inc: Fix buildpaths error for pthread.h"
poky.conf: bump version for 5.0.9
build-appliance-image: Update to scarthgap head revision
poky.conf: bump version for 5.0.10
build-appliance-image: Update to scarthgap head revision
poky.conf: bump version for 5.0.11
build-appliance-image: Update to scarthgap head revision
Revert "sudo: Fix CVE-2025-32462"
poky.conf: bump version for 5.0.12
build-appliance-image: Update to scarthgap head revision
selftest/cases/meta_ide.py: use use gnu mirror instead of main server
oeqa/sdk/cases/buildcpio.py: use gnu mirror instead of main server
poky.conf: bump version for 5.0.13
build-appliance-image: Update to scarthgap head revision
Sunil Dora (2):
gcc: Fix c++: tweak for Wrange-loop-construct
binutils: Fix CVE-2025-1153
Talel BELHAJ SALEM (1):
dev-manual/building.rst: add note about externalsrc variables absolute paths
Talel BELHAJSALEM (1):
contributor-guide: Remove duplicated words
Teresa Remmet (1):
recipes-bsp: usbutils: Fix usb-devices command using busybox
Trevor Gamblin (7):
python3: skip test_concurrent_futures/test_deadlock
python3: skip test_multiprocessing/test_active_children test
maintainers.inc: add self for unassigned python recipes
python3: upgrade 3.12.4 -> 3.12.5
python3: skip readline limited history tests
python3-urllib3: upgrade 2.2.1 -> 2.2.2
reproducible-builds.rst: show how to build a single package
Trevor Woerner (5):
contributor-guide/submit-changes: encourage patch version changelogs
ref-manual/variables.rst: document WIC_CREATE_EXTRA_ARGS
sphinx-lint: trailing whitespace
sphinx-lint: missing space after literal
sphinx-lint: unbalanced inline literal markup
Ulrich Ölmann (1):
initramfs-framework: fix typos
Victor Giraud (1):
busybox: fix CVE-2022-48174
Victor Kamensky (1):
systemtap: fix systemtap-native build error on Fedora 40
Vijay Anusuri (44):
openssh: fix CVE-2024-39894
apr: upgrade 1.7.4 -> 1.7.5
libpcap: Security fix for CVE-2023-7256 & CVE-2024-8006
xserver-xorg: upgrade 21.1.13 -> 21.1.14
glib-2.0: Backport fix for CVE-2024-52533
bind: Upgrade 9.18.28 -> 9.18.33
openssh: Fix CVE-2025-26466
xwayland: Fix CVE-2024-9632
xwayland: Fix CVE-2025-26594
xwayland: Fix CVE-2025-26595
xwayland: Fix CVE-2025-26596
xwayland: Fix CVE-2025-26597
xwayland: Fix CVE-2025-26598
xwayland: Fix CVE-2025-26599
xwayland: Fix CVE-2025-26600
xwayland: Fix CVE-2025-26601
libtasn1: upgrade 4.19.0 -> 4.20.0
xserver-xorg: upgrade 21.1.15 -> 21.1.16
libxslt: upgrade 1.1.39 -> 1.1.43
vim: Upgrade 9.1.1115 -> 9.1.1198
libsoup: Fix CVE-2025-32910
libsoup: Fix CVE-2025-32909
libsoup: Fix CVE-2025-32911 & CVE-2025-32913
libsoup: Fix CVE-2025-32912
libsoup: Fix CVE-2025-32906
libsoup-2.4: Fix CVE-2024-52530
libsoup-2.4: Fix CVE-2024-52531
libsoup-2.4: Fix CVE-2024-52532
libsoup-2.4: Fix CVE-2025-32906
libsoup-2.4: Fix CVE-2025-32909
libsoup: Fix CVE-2025-32914
openssh: Fix for CVE-2025-32728
libsoup-2.4: Fix CVE-2025-32910
libsoup-2.4: Fix CVE-2025-32911 & CVE-2025-32913
libsoup-2.4: Fix CVE-2025-32912
libsoup-2.4: Fix CVE-2025-32914
python3-setuptools: Fix CVE-2025-47273
kea: upgrade 2.4.1 -> 2.4.2
sudo: Fix CVE-2025-32462
git: Upgrade 2.44.3 -> 2.44.4
xserver-xorg: upgrade 21.1.6 -> 21.1.18
cups: upgrade 2.4.10 -> 2.4.11
cups: Fix for CVE-2025-58060 and CVE-2025-58364
gstreamer1.0-plugins-bad: Fix CVE-2025-3887
Virendra Thakur (3):
rust-cross-canadian: Set CVE_STATUS ignore for CVE-2024-43402
util-linux: Add fix to isolate test fstab entries using CUSTOM_FSTAB
curl: set conditional CVE_STATUS for CVE-2025-5025
Vishwas Udupa (1):
openssl: rewrite ptest installation
Vrushti Dabhi (1):
curl: update CVE_STATUS for CVE-2025-5025
Vyacheslav Yurkov (1):
systemd: Password agents shouldn't be optional
Wadim Egorov (1):
watchdog: Set watchdog_module in default config
Wang Mingyu (18):
ed: upgrade 1.20.1 -> 1.20.2
llvm: upgrade 18.1.5 -> 18.1.6
mesa: upgrade 24.0.5 -> 24.0.7
wireless-regdb: upgrade 2024.01.23 -> 2024.05.08
orc: upgrade 0.4.38 -> 0.4.39
cups: upgrade 2.4.9 -> 2.4.10
libadwaita: upgrade 1.5.1 -> 1.5.2
libdnf: upgrade 0.73.1 -> 0.73.2
wireless-regdb: upgrade 2024.05.08 -> 2024.07.04
cryptodev: upgrade 1.13 -> 1.14
orc: upgrade 0.4.39 -> 0.4.40
wireless-regdb: upgrade 2024.07.04 -> 2024.10.07
gnupg: upgrade 2.4.4 -> 2.4.5
xserver-xorg: upgrade 21.1.14 -> 21.1.15
ghostscript: upgrade 10.05.0 -> 10.05.1
mtools: upgrade 4.0.44 -> 4.0.45
mtools: upgrade 4.0.45 -> 4.0.46
mtools: upgrade 4.0.47 -> 4.0.48
Weisser, Pascal (1):
ref-manual: Add missing variable IMAGE_ROOTFS_MAXSIZE
Weisser, Pascal.ext (1):
qemuboot: Trigger write_qemuboot_conf task on changes of kernel image realpath
Xiangyu Chen (2):
qemu: Upgrade 8.2.1 -> 8.2.2
lttng-modules: fix sched_stat_runtime changed in Linux 6.6.66
Yash Shinde (4):
binutils: Fix CVE-2024-53589
binutils: Fix CVE-2025-7546
binutils: fix CVE-2025-11081
binutils: fix CVE-2025-8225
Yi Zhao (5):
libcap-ng: upgrade 0.8.4 -> 0.8.5
libcap-ng-python: upgrade 0.8.4 -> 0.8.5
rpm: fix expansion of %_libdir in macros
iputils: Security fix for CVE-2025-47268
kea: set correct permissions for /var/run/kea
Yogita Urade (10):
qemu: upgrade 8.2.2 -> 8.2.3
qemu: fix CVE-2024-4467
ruby: upgrade 3.2.2 -> 3.3.5
qemu: upgrade 8.2.3 -> 8.2.7
curl: fix CVE-2024-11053
curl: fix CVE-2025-0167
python3-urllib3: fix CVE-2025-50181
curl: fix CVE-2025-9086
tiff: fix CVE-2025-9900
tiff: ignore CVE-2025-8961
Zhang Peng (3):
avahi: fix CVE-2024-52616
mpg123: upgrade 1.32.6 -> 1.32.10
avahi: fix CVE-2024-52615
aszh07 (3):
xz: Update LICENSE variable for xz packages
ffmpeg: Add "libswresample libavcodec" to CVE_PRODUCT
libarchive: Fix CVE-2024-20696
rajmohan r (1):
glibc-y2038-tests: remove glibc-y2038-tests_2.39.bb recipe
meta-openembedded: 78a14731cf..15e18246dd:
Adrian Freihofer (2):
networkmanager: remove modemmanager rdepends
thrift: fix build with gcc 15
Alexandre Truong (4):
source-han-sans-*-fonts: Switch away from SVN fetcher in SRC_URI
lcov: include UPSTREAM_CHECK_* to fix UNKNOWN_BROKEN status
hunspell-dictionaries: switch branch from master to main
evince: Update status for CVE-2011-0433 and CVE-2011-5244
Alexandre Videgrain (1):
openbox: fix crash on alt+tab with fullscreen app
AmateurECE (1):
pipewire: Add glib-2.0-native dep for bluez5
Andrej Valek (1):
externalsrc: fix support in various components
Anil Dongare (1):
libssh 0.10.6: Fix CVE-2025-8114
Ankur Tyagi (25):
tinyproxy: patch CVE-2023-49606
frr: patch CVE-2024-44070
libavif: ignore CVE-2025-48175
libconfuse: patch CVE-2022-40320
hdf5: patch CVE-2025-2913
hdf5: patch CVE-2025-2914
hdf5: patch CVE-2025-2915
hdf5: patch CVE-2025-2923, CVE-2025-6816, CVE-2025-6856
hdf5: patch CVE-2025-2924
hdf5: patch CVE-2025-2925
hdf5: patch CVE-2025-6269, CVE-2025-6270, CVE-2025-6516
libppd: patch CVE-2024-47175
libcupsfilters: patch CVE-2024-47076
libraw: patch CVE-2025-43961 CVE-2025-43962
libraw: patch CVE-2025-43963
libraw: patch CVE-2025-43964
zlog: fix CVE-2024-22857
memcached: patch CVE-2023-46852
memcached: patch CVE-2023-46853
ndpi: ignore CVE-2025-25066
libiec61850: patch CVE-2024-26529
libiec61850: patch CVE-2024-45970
libiec61850: patch CVE-2024-45971
mbedtls: upgrade 3.6.4 -> 3.6.5
hostapd: patch CVE-2025-24912
Archana Polampalli (4):
modejs: upgrade 20.18.0 -> 20.18.2
tftpy: fix CVE-2023-46566
tcpreplay: fix CVE-2024-22654
apache2: upgrade 2.4.64 - 2.4.65
Ariel D'Alessandro (1):
pipewire: Install missing ALSA config files
Armin Kuster (1):
Revert "mariadb: fix runtime failure on riscv"
Ashish Sharma (2):
nginx: Backport fix for CVE-2024-7347
postgresql: Backport fix for CVE-2024-7348
AshishKumar Mishra (1):
meta-oe: image: optionally remove RAW image after sparse image creation
Awais Belal (2):
mongodb: fix build with python 3.12
mongodb: update to 4.4.29
BINDU (1):
flatbuffers: adapt for cross-compilation environments
Barry Grussling (1):
postgresql: Break perl RDEPENDS
Bastian Krause (2):
libsocketcan: use https instead of git protocol
canutils: use https instead of git protocol
Benjamin Szőke (1):
tree: fix broken links
Changqing Li (11):
pavucontrol: update SRC_URI
libatasmart: Update SRC_URI
mariadb: fix runtime failure on riscv
dlt-daemon: make DLT_WatchdogSec configurable
abseil-cpp: upgrade 20240116.2 -> 20240116.3
nginx: fix CVE-2025-23419
libblockdev: fix CVE-2025-6019
udisks2: Hardening measure of CVE-2025-6019
phpmyadmin: upgrade 5.2.1 -> 5.2.2
luajit: fix several CVEs
mariadb: correct STACK_DIRECTION setting
Chen Qi (6):
libdbd-mysql-perl: avoid invoking assert_lib at do_configure stage
python3-protobuf: remove useless and problematic .pth file
graphviz: remove obsolete and problematic patch
protobuf: fix CVE-2024-7254
protobuf: upgrade from 4.25.3 to 4.25.8
python3-protobuf: upgrade from 4.25.3 to 4.25.8
Chris Laplante (1):
poco: fix branch: master => poco-1.12.5
Christos Gavros (1):
corosync: reproducibility issue
Claus Stovgaard (2):
lcov: sort RDEPENDS alphabetical
lcov: Add missing RDEPENDS
Clayton Casciato (1):
chrony: use inherit_defer for conditional inherit of useradd
Deepak Rathore (1):
protobuf 4.25.8: Mark CVE-2024-7254 as patched
Divya Chellam (7):
nginx: upgrade 1.25.3 -> 1.25.4
redis: upgrade 7.2.6 -> 7.2.7
krb5: fix CVE-2025-24528
openvpn: upgrade 2.6.12 -> 2.6.14
libssh: fix CVE-2025-4878
libssh: fix CVE-2025-5987
jq: fix CVE-2025-9403
Dmitry Baryshkov (1):
android-tools: Create flag file /etc/usb-debugging-enabled
Esben Haabendal (1):
netplan: add missing runtime dependencies
Etienne Cordonnier (3):
uutils-coreutils: upgrade 0.0.25 -> 0.0.26
uutils-coreutils: upgrade 0.0.26 -> 0.0.27
uutils-coreutils: fix compilation with selinux
Fabrice Aeschbacher (1):
mosquitto: upgrade 2.0.18 -> 2.0.19
Fathi Boudra (2):
python3-django: upgrade 4.2.11 -> 4.2.16
python3-django: upgrade 5.0.4 -> 5.0.9
Frank de Brabander (3):
python3-pydantic-core: fix incompatible version
python3-pydantic-core: fix TMPDIR path reference
python3-pydantic-core: add missing RDEPENDS for ptest
Grygorii Tertychnyi (1):
libusbgx: fix gadget-stop install
Guocai He (6):
python3-pylint: correct the SRC_URI
libconfig: correct the SRC_URI
logcheck: correct the SRC_URI
thrift: correct the SRC_URI
softhsm: correct the SRC_URI
mariadb: File conflicts for multilib
Guðni Már Gilbert (1):
mbedtls: upgrade 3.6.3.1 -> 3.6.4
Gyorgy Sarvari (35):
poppler: fix typos in CVE-2025-52886-0001.patch
mod-dnssd: update SRC_URI
mosh: set working SRC_URI
psqlodbc: set valid SRC_URI
collectd: set working SRC_URI
apache2: ignore irrelevant CVEs
civetweb: patch CVE-2025-55763
dovecot: patch CVE-2022-30550
pm-qa: update git fetch protocol
tokyocabinet: switch to working SRC_URI
tokyocabinet: fix license
iperf2: ignore irrelevant CVEs
jasper: patch CVE-2025-8835
jasper: patch CVE-2025-8836
jasper: patch CVE-2025-8837
etcd: patch CVE-2023-32082
freerdp3: patch CVE-2024-32039 and CVE-2024-32041
freerdp3: patch CVE-2024-32040
freerdp3: patch CVE-2024-32458
freerdp3: patch CVE-2024-32459
freerdp3: patch CVE-2024-32460
freerdp3: patch CVE-2024-32658
freerdp3: patch CVE-2025-32659
freerdp3: patch CVE-2024-32660
freerdp3: patch CVE-2024-32661
freerdp3: patch CVE-2024-32662
exiv2: patch CVE-2025-26623
exiv2: patch CVE-2025-54080
exiv2: patch CVE-2025-55304
redis: upgrade 6.2.18 -> 6.2.20
emacs: patch CVE-2024-30202
emacs: patch CVE-2024-30203
emacs: patch CVE-2024-30204
emacs: patch CVE-2024-30205
emacs: patch CVE-2024-39331
Haixiao Yan (4):
openvpn: fix CVE-2024-28882
openvpn: upgrade 2.6.10 -> 2.6.12
lmsensors: Clean stale files for sensord to avoid incorrect GCC header dependencies
python3-posix-ipc: fix runtime error
Harish Sadineni (1):
bpftool: Add support for riscv64
Hieu Van Nguyen (1):
gphoto2: Fix contains reference to TMPDIR [buildpaths] warning
Hitendra Prajapati (8):
tgt: fix CVE-2024-45751
libssh: fix CVE-2025-5318
redis: fix CVE-2025-32023
libssh: fix CVE-2025-5351 & CVE-2025-5372
open-vm-tools: fix CVE-2025-22247
libssh: fix CVE-2025-4877
openjpeg: fix for CVE-2025-54874
libjxl: fix CVE-2024-11403 & CVE-2024-11498
Hongxu Jia (1):
nodejs: support cross compile without qemu user conditionally
J. S (2):
nodejs: upgrade 20.16.0 -> 20.17.0
nodejs: upgrade 20.17.0 -> 20.18.0
J. S. (3):
znc: Fix buildpaths QA errors
nodejs: cleanup
xfce4 update HOMEPAGEs
Jan Vermaete (1):
python3-werkzeug: added python3-difflib as RDEPENDS
Jason Schonberg (1):
nodejs: upgrade 20.13.0 -> 20.16.0
Jef Driesen (2):
nginx: fix the tarball and license checksums
lcov: Add missing RDEPENDS for nativesdk
Jeroen Hofstee (5):
nodejs: backport a patch to prevent brotli crashing nodejs
can-utils: fix printing / reading timestamps
can-utils: handle CAN_ERR_CNT correctly
php: ignore CVE-2024-3566
nodejs: ignore CVE-2024-3566
Jeroen Knoops (1):
nng: Rename default branch of github.com:nanomsg/nng.git
Jiaying Song (15):
rrdtool: Fix do_populate_sysroot QA issues
nftables: change ptest output format
debootstrap: fix do_fetch error
wireguard-tools: fix do_fetch error
vlock: fix do_fetch error
openipmi: upgrade 2.0.34->2.0.36
tcpreplay: fix CVE-2023-43279
xfce-dusk-gtk3: fix do_fetch error
eject: fix do_fetch error
libdev-checklib-perl: fix do_fetch error
xmlsec1: Switch SRC_URI to use github release
chrony: fix do_fetch error
v4l-utils: Fix QA and build errors related to _TIME_BITS on 32-bit
webkitgtk3: update 2.44.1 -> 2.44.3
webkitgtk3: fix do_configure error on beaglebone-yocto
Jinfeng Wang (2):
netplan: Fix CVE-2022-4968
postfix: fix rootfs file difference
Justin Bronder (1):
python3-xmodem: replace hardcoded /usr with ${prefix}
Khem Raj (32):
python3-pydantic-core: Fix build with python 3.12.4
log4cpp: Fix buildpaths QA error
python3-pydantic: Upgrade to 2.7.3
mariadb: Upgrade to 10.11.9 release
ndisc: Remove buildpaths from binaries
ndisc6: Fix reproducible build
ghex,gnome-chess,gnome-photos: Add missing dep on itstool-native
nodejs: Upgrade to 20.13.0 release
nodejs: Fix build with libc++ 19
wolfssl: Add packageconfig for reproducible build
blueman: Fix buildpathe issue with cython generated code
botan: Make it reproducible
keepalived: Make build reproducible
ldns: Fix buildpaths QA issues
python3-kivy: Remove buildpaths from comments in generated C sources
python3-pyproj: Fix buildpaths QA Error
python3-pyproj: Remove absolute paths from cython generated .c files
python3-pycocotools: Remove absolute paths from comments
lprng: Specify target paths for needed utilities
fwknop: Specify target locations of gpg and wget
e2tools: Fix buildpaths QA warning in config.status in ptest
sharutils: Let POSIX_SHELL be overridable from environment
python3-posix-ipc: switch to PEP-517 build backend
gtkwave: Add libtirpc to depends
ssmping: Use debian mirror for SRC_URI
enca: Fix cross builds
ckermit: Define return type for main
ckermit: Fix build with GCC-15
procmail: Fix build with GCC-14
uim: Stick to C17
freerdp: Upgrade 2.11.2 -> 2.11.7
influxdb: Do not remove non-existing files
Leon Anavi (2):
sip: Upgrade 6.8.3 -> 6.8.6
sip: Fix homepage and license
Leonard Anderweit (1):
lmsensors: Fix build without sensord
Libo Chen (3):
thin-provisioning-tools: install missed thin_shrink and era_repair
grpc: Fix CVE-2024-7246
libgpiod: fix gpiod-cxx-test failed test case
Marc Ferland (2):
polkit: update SRC_URI
libvncserver: fix generated LibVNCServerTargets.cmake
Markus Volk (4):
exiv2: update 0.28.0 -> 0.28.2
gnome-remote-desktop: update 46.1 -> 46.2
geary: add itstool-native dependency
eog: add itstool-native dependency
Martin Jansa (13):
bolt: package systemd_system_unitdir correctly
giflib: fix build with gold and avoid imagemagick-native dependency
Revert "gcab: ignore buildpaths error from sources"
gpm: fix buildpaths QA issue
xerces-c: fix buildpaths QA issue
xmlrpc-c: update SRCREV
lapack: add PACKAGECONFIG for cblas
lapack: fix buildpaths in ptest also when CBLAS is enabled
gcab: fix buildpaths QA issue
python3-posix-ipc: improve build_support
python3-h5py: backport fixes for incompatible-pointer-types issues
abseil-cpp: fix build with gcc-15 on host
nodejs: fix build with gcc-15 on host
Martin Schwan (1):
linuxptp: Add systemd instance specifier for ptp4l dependency
Michael Olbrich (1):
nftables: avoid python dependencies when building without python
Michael Opdenacker (1):
kernel-hardening-checker: backport recipe
Mikko Rapeli (3):
fwupd: skip buildpaths errors
gcab: ignore buildpaths error from sources
libjcat: skip buildpaths check
Mingli Yu (2):
asio: Add ptest support
ptest-packagelists-meta-oe.inc: Add asio
Neel Gandhi (1):
v4l-utils: Install media ctrl header and library files
Nikhil R (2):
nftables: Conditionally add ${PN}-python as RDEPENDS for ptest
rocksdb: Add an option to set static library
Niko Mauno (16):
python3-xlsxwriter: Fix LICENSE
python3-cbor2: Fix LICENSE and LIC_FILES_CHKSUM
python3-crc32c: Amend LICENSE declaration
python3-email-validator: Fix LICENSE
python3-lru-dict: Fix LICENSE and change SUMMARY to DESCRIPTION
python3-mock: Fix LICENSE
python3-parse-type: Fix LICENSE
python3-pillow: Fix LICENSE and change SUMMARY to DESCRIPTION
python3-platformdirs: Fix LICENSE
python3-colorama: Fix LICENSE
python3-fann2: Fix LICENSE
python3-nmap: Fix LICENSE and LIC_FILES_CHKSUM
python3-pycurl: Fix LICENSE
python3-googleapis-common-protos: Fix LIC_FILES_CHKSUM
python3-haversine: Fix LIC_FILES_CHKSUM
python3-libevdev: Fix LIC_FILES_CHKSUM
Ninette Adhikari (6):
imagemagick: Update status for CVE
imagemagick: Update status for CVE
imagemagick: Update status for CVE
xsp: CVE status update for CVE-2006-2658
influxdb: Update CVE status for CVE-2019-10329
monkey: Update status for CVE-2013-2183
Peter Kjellerstedt (6):
hostapd: Support running "devtool modify hostapd"
hostapd: Only include the relevant parts from README in LIC_FILES_CHKSUM
libjs-jquery-icheck: Correct LIC_FILES_CHKSUM
libdevmapper: Inherit nopackages
ebtables: Remove the dependecy on bash
libeigen: Remove LGPL code
Peter Marko (41):
libndp: Patch CVE-2024-5564
squid: patch CVE-2024-37894
hostapd: Patch CVE-2024-3596
hostapd: Patch security advisory 2024-2
nss: patch CVE-2024-6602
nss: patch CVE-2024-6609
squid: conditionally set status of CVE-2024-45802
thrift: fix c++ generated code compilation with clang
grpc: patch CVE-2024-11407
python3-grpcio: patch CVE-2024-11407
python3-grpcio(-tools): fix build concurrency issue
libmodbus: patch CVE-2024-10918
libmodbus: ignore CVE-2023-26793 and CVE-2024-34244
libcoap: patch CVE-2024-31031
spdlog: patch CVE-2025-6140
minifi-cpp: patch spdlog CVE-2025-6140
poco: ignore additional failing tests
poco: patch CVE-2025-6375
nginx: patch CVE-2025-53859
fontforge: patch CVE-2024-25081 and CVE-2024-25082
fcgi: patch CVE-2025-23016
procmail: patch CVE-2014-3618
procmail: patch CVE-2017-16844.
ace: ignore CVE-2009-1147
audiofile: fix multiple CVEs
audiofile: patch CVE-2017-6829
audiofile: fix multiple CVEs
audiofile: patch CVE-2017-6831
audiofile: patch CVE-2017-6839
emlog: set CVE_PRODUCT
freerdp: patch CVE-2024-32661
freerdp: mark CVE-2024-32662 as fixed
freerdp3: set CVE_PRODUCT
corosync: fix upstream version check
corosync: upgrade 3.1.6 -> 3.1.9
corosync: patch CVE-2025-30472
dash: set CVE_PRODUCT
gattlib: mark CVE-2019-6498 as fixed
memcached: ignore disputed CVE-2022-26635
monkey: ignore CVE-2013-1771
squid: patch CVE-2025-59362
Poonam Jadhav (1):
tcpreplay: Fix CVE-2023-4256
Praveen Kumar (4):
php: upgrade 8.2.28 -> 8.2.29
polkit: fix CVE-2025-7519
yasm: fix CVE-2024-22653
cjson: upgrade 1.7.18 -> 1.7.19
Preeti Sachan (1):
bpftool: fix libelf.h not found error
Raghuvarya S (2):
android-tools-adbd.service: Update ConditionPathExists to /etc
android-toold-adbd: Fix inconsistency between selinux configurations
Rajeshkumar Ramasamy (1):
open-vm-tools: fix CVE-2025-41244
Randolph Sapp (2):
opencl-clhpp: add native and nativesdk
vulkan-cts: allow vulkan versions > 1.3
Randy MacLeod (1):
python3-pyyaml-include: support native and nativesdk build
Robert Yang (1):
hostapd: Add CVE id to CVE-2024-3596_00.patch
Roland Kovacs (2):
jq-1.7.1: Backport multiple CVE fixes
jq: add Upstream-Status and CVE tags into .patch files
Ryan Eatmon (1):
kernel-selftest: Update to allow for turning on all tests
Sana Kazi (2):
libp11: Treat all openssl-3.x releases the same
imagemagick: guard sed operations in do_install for optional files
Saravanan (2):
udisks2: upgrade 2.10.1 -> 2.10.2
fio: fix CVE-2025-10823
Scott Murray (2):
python3-grpcio: Fix build with gcc-14
python3-grpcio: backport abseil-cpp RISC-V fix
Shubham Pushpkar (2):
wireshark 4.2.7: Fix CVE-2024-9781
cjson 1.7.18: Fix CVE-2025-57052
Siddharth Doshi (2):
apache2: Upgrade 2.4.59 -> 2.4.60
apache2: Upgrade 2.4.60 -> 2.4.62
Sofiane HAMAM (2):
Wolfssl: add ptest
wolfssl: Upgrade 5.7.0 -> 5.7.2
Soumya Sambu (14):
python3-sqlparse: Fix CVE-2024-4340
python3-werkzeug: upgrade 3.0.1 -> 3.0.3
gtk+: Fix CVE-2024-6655
python3-twisted: Fix CVE-2024-41671
python3-flask-cors: Fix CVE-2024-6221
python3-werkzeug: upgrade 3.0.3 -> 3.0.6
python3-tornado: Upgrade 6.4 -> 6.4.2
python3-django: upgrade 4.2.16 -> 4.2.17
python3-django: upgrade 5.0.9 -> 5.0.10
python3-django: upgrade 5.0.10 -> 5.0.11
python3-django: upgrade 4.2.17 -> 4.2.18
php: Upgrade 8.2.26 -> 8.2.28
iniparser: Fix CVE-2025-0633
python3-django: upgrade 4.2.18 -> 4.2.20
Sunil Dora (1):
layer.conf: add bpftrace to NON_MULTILIB_RECIPES
Swamil Jain (1):
kmsxx: Revert to using original name for kmstest
Thomas Roos (1):
libcamera: backport 0.4.0 from master-next
Tim Orling (1):
python3-pydantic: upgrade 2.7.3 -> 2.7.4
Trevor Woerner (2):
apache2: use update-alternatives for httpd
iperf3: throughput fix
Vijay Anusuri (16):
krb5: upgrade 1.21.2 -> 1.21.3
wireshark: upgrade 4.2.4 -> 4.2.5
wireshark: upgrade 4.2.5 -> 4.2.7
php: upgrade 8.2.24 -> 8.2.26
openjpeg: upgrade 2.5.0 -> 2.5.3
postgresql: upgrade 16.5 -> 16.8
wireshark: upgrade 4.2.7 -> 4.2.9
proftpd: Fix CVE-2024-57392
redis: upgrade 7.2.7 -> 7.2.8
wireshark: upgrade 4.2.9 -> 4.2.12
proftpd: Fix CVE-2023-51713
apache2: Upgrade 2.4.62 -> 2.4.64
poppler: Fix CVE-2025-43718
redis: upgrade 7.2.8 -> 7.2.11
redis: upgrade 6.2.16 -> 6.2.18
vorbis-tools: Fix CVE-2023-43361
Virendra Thakur (2):
opensc: Fix multiple cve CVE-2024-45615-45616-45617-45618-45619-45620
unbound: Fix CVE-2024-8508
Wang Mingyu (18):
python3-email-validator: upgrade 2.1.0 -> 2.1.1
python3-pydantic: upgrade 2.7.0 -> 2.7.1
cjson: upgrade 1.7.17 -> 1.7.18
samba: upgrade 4.19.7 -> 4.19.8
postgresql: upgrade 16.3 -> 16.4
redis: upgrade 7.2.4 -> 7.2.5
mosquitto: upgrade 2.0.19 -> 2.0.20
uutils-coreutils: upgrade 0.0.27 -> 0.0.28
nana: Fix buildpaths warning.
fetchmail: Fix buildpaths warning.
fetchmail: disable rpath to fix buildpaths warning.
python3-posix-ipc: upgrade 1.1.1 -> 1.2.0
mbedtls: upgrade 3.6.3 -> 3.6.3.1
geoip: fix do_fetch error
rp-pppoe: update SRC_URI
procmail: fix build failure with gcc-14
procmail: Add -Wno-implicit-int to fix error of do_compile
libiec61850: upgrade 1.5.1 -> 1.5.3
Wentao Zhang (1):
meta-oe/conf/layer.conf: remove libbpf from NON_MULTILIB_RECIPES for x86 and x86-64
Xiangyu Chen (1):
crash: fix crash cannot work with kaslr
Yi Zhao (12):
samba: upgrade 4.19.6 -> 4.19.7
mbedtls: upgrade 3.6.0 -> 3.6.1
mbedtls: upgrade 2.28.8 -> 2.28.9
libldb: upgrade 2.8.0 -> 2.8.1
mbedtls: upgrade 3.6.1 -> 3.6.2
freeradius: upgrade 3.2.3 -> 3.2.5
hostapd: Security fix for CVE-2023-52160
redis: upgrade 7.2.5 -> 7.2.6
mbedtls: upgrade 2.28.9 -> 2.28.10
mbedtls: 3.6.2 -> 3.6.3
wxwidgets: upgrade 3.2.1 -> 3.2.6
redis: upgrade 6.2.14 -> 6.2.16
Yoann Congal (3):
packagegroup-meta-oe: fix lvgl inclusion
mdio-tools: fix mdio-netlink kernel module reproducibility
gutenprint: fix a build race-condition
Yogesh Tyagi (1):
tbb-native: Fix build with gcc-13
Yogita Urade (18):
graphviz: fix CVE-2023-46045
hdf5: upgrade to 1.14.4
poppler: CVE-2024-6239
krb5: fix CVE-2024-26458 and CVE-2024-26461
php: upgrade 8.2.20 -> 8.2.24
postgresql: upgrade 16.4 -> 16.5
poppler: fix CVE-2024-56378
poppler: fix CVE-2025-32364
poppler: fix CVE-2025-32365
poppler: fix CVE-2025-43903
syslog-ng: fix CVE-2024-47619
postgresql: upgrade 16.8 -> 16.9
mariadb: upgrade 10.11.9 -> 10.11.12
poppler: fix CVE-2025-52886
poppler: fix CVE-2025-50420
postgresql: upgrade 16.9 -> 16.10
indent: fix CVE-2023-40305
poppler: fix CVE-2025-52885
Zhang Peng (21):
hiredis: remove ANSI color from ptest result
frr: fix CVE-2024-34088
frr: fix CVE-2024-31950
frr: fix CVE-2024-31951
frr: fix CVE-2024-31948
frr: fix CVE-2024-31949
libgsf: upgrade 1.14.52 -> 1.14.53
glade: fix CVE-2020-36774
opensc: fix CVE-2024-8443
lapack: fix TMPDIR reference in do_package_qa
iperf3: upgrade 3.16 -> 3.18
gnuplot: fix CVE-2025-3359
gnuplot: fix CVE-2025-31176
gnuplot: fix CVE-2025-31177
gnuplot: fix CVE-2025-31178
gnuplot: fix CVE-2025-31179
gnuplot: fix CVE-2025-31180
gnuplot: fix CVE-2025-31181
iperf3: fix CVE-2025-54349
iperf3: fix CVE-2025-54350
wxwidgets: fix CVE-2024-58249
Zoltán Böszörményi (1):
gutenprint: 5.3.5
akash hadke (1):
python3-flatbuffers: provide nativesdk support
alperak (8):
tayga: Fix contains reference to TMPDIR [buildpaths] warning
etcd-cpp-apiv3: Fix contains reference to TMPDIR [buildpaths] warning
exiv2: Upgrade 0.28.2 to 0.28.3 for CVE fix
jsonrpc: Fix contains reference to TMPDIR [buildpaths] warning
rdist: Fix contains reference to TMPDIR [buildpaths] warning
perfetto: Fix contains reference to TMPDIR [buildpaths] warning
hplip: Fix contains reference to TMPDIR [buildpaths] warning
boinc-client: Fix contains reference to TMPDIR [buildpaths] warning
gudnimar (1):
pipewire: upgrade 1.0.5 -> 1.0.9
hongxu (2):
p7zip: fix CVE-2023-52169 and CVE-2023-52168
indent: fix CVE-2024-0911
kjlau0112 (1):
mbedtls: drop tag parameter from SRC_URI.
mark.yang (1):
srecord: fix build failure with gcc-15
meta-raspberrypi: 1918a27419..8767e2ff80:
Adam Schafer (1):
add raspi-utils recipe to scarthgap branch
Andrei Gherzan (1):
docs: Fix ReadTheDocs sphinx.configuration requirement
Ayoub Zaki (1):
raspberrypi5: add bcm2712d0 overlay required for booting up correctly
Bassem Nomany (1):
mesa: update to 24.3.1
Damiano Ferrari (2):
rpi-eeprom: Update to latest release
rpi-bootfiles: Update to latest release
Florin Sarbu (1):
linux-raspberrypi.inc: Change defconfig for RPi3 64 bits
Garrett Brown (1):
linux: Enable CONFIG_I2C_BRCMSTB for proper HDMI I2C support
Gijs Peskens (1):
raspberrypi5.conf: Add CM5 dtb's
Jaeyoon Jung (1):
linux-raspberrypi: Drop deprecated configs from android-driver.cfg
Joshua Watt (1):
linux-firmware-rpidistro: Fix WiFi on Raspberry Pi 5
Khem Raj (2):
linux-raspberrypi-6.6: Upgrade to 6.6.63
rpi-base: Remove bcm2712-rpi-5-b.dtb from RPI_KERNEL_DEVICETREE target
Leon Anavi (11):
yocto-builder/Dockerfile: Ubuntu 22.04
rpi-base.inc: vc4-kms-dsi-ili9881-7inch.dtbo
u-boot_%.bbappend: Increase CONFIG_SYS_BOOTM_LEN
wayland-protocols: Upgrade 1.38 -> 1.45
mesa: Upgrade 24.3.1 -> 25.1.3
mesa: Upgrade 25.1.3 -> 25.1.6
mesa_%.bbappend: DISTRO_FEATURES for wayland
mesa: wayland-protocols: Fix signatures
linux-firmware-rpidistro: Update and stabilize
rpi-base.inc: Add w1-gpio-pi5.dtbo
rpi-base.inc: Add rpi-backlight.dtbo
Markus Volk (4):
linux-raspberrypi: add recipe for 6.12
linux-raspberrypi: update 6.12.2 -> 6.12.25
rpi-default-versions: Switch default kernel to 6.12
rpi-bootfiles: update to latest release
Martin Jansa (3):
docker-build: use --no-cache
Revert "rpi-default-versions: Switch default kernel to 6.12"
mesa, wayland-protocols: use separate recipe instead of bbappend
Matthias Klein (1):
linux-firmware-rpidistro: Upgrade to bookworm/20230625-2+rpt3
Omri Sarig (1):
linux-firmware-rpidistro: Fix wireless error message on RPi
Pierrick Curt (1):
rpi-base: build uart dts overlays by default
Thomas Roos (1):
Moving bcm2712d0.dtbo into rpi-base.inc
meta-arm: 58268ddccb..0f1e7bf92c:
Amr Mohamed (5):
kas: Update kas configuration for fvp-base.yml file
arm-systemready/linux-distros: new inc file for unattended installation
arm-systemready/linux-distros: Add kickstart file for Fedora unattended
arm-systemready/oeqa: Add new test for Fedora unattended installation
kas: Add new yml file for Distros unattended installation
Ben (3):
arm-systemready/linux-distros: Implement unattended openSUSE
arm-systemready/oeqa: Add unattended installation testcase
kas: Include unattended openSUSE test
Bence Balogh (1):
arm-bsp/trusted-firmware-m: corstone1000: Fix MPU configuration
Harsimran Singh Tungal (1):
arm-bsp,kas: corstone1000: enable External System based on new yml file
Hugues KAMBA MPIANA (1):
arm-bsp/documentation: corstone1000: Add SystemReady IR v2.0 certification
Jon Mason (4):
arm-toolchain: remove libmount-mountfd-support when using binary toolchain
arm-bsp/fvp-base: Get 6.10 kernel working
arm/linux-yocto: disable CONFIG_MTD_NAND_FSL_IFC
arm-systemready/ir-acs: Update URL
Jose Quaresma (1):
bsp: optee-client: cleanup old tee-supplicant
Luca Fancellu (2):
arm/oeqa: Introduce retry mechanism for fvp_devices run_cmd
arm/lib: Handle timeout for spawn object on stop()
Romain Naour (4):
external-arm-toolchain: remove old sed fixup for libc.so
external-arm-toolchain: wrap symlink handling under usrmerge check
external-arm-toolchain: override dynamic loader path with usrmerge enabled
external-arm-toolchain: rebuild libmvec.so symlink if any
Ross Burton (5):
arm-base/linux-yocto: revert interim 6.10 patch for fvp-base
arm-system-ready/arm-systemready-ir-acs: add version to download filename
CI: use canonical git.yoctoproject.org URLs
arm/execstack-native: add new recipe
arm/fvp-base-a-aem: remove spurious executable stack from one library
Vasyl Vavrychuk (3):
external-arm-toolchain: wrap base_libdir vs libdir manipulations under usrmerge check
external-arm-toolchain: in libc.so GNU ld script use base_libdir
external-arm-toolchain: remove ${base_libdir}/libpthread*.so from FILES:${PN}
meta-security: 11ea91192d..bc865c5276:
Hitendra Prajapati (2):
clamav: fix CVE-2024-20505 & CVE-2024-20506
libhtp: fix CVE-2024-45797
Vijay Anusuri (2):
tpm2-tools: Upgrade 5.5 -> 5.7
tpm2-tss: upgrade 4.0.1 -> 4.0.2
Change-Id: Ief5b086436b2f3a4e819546fcd1bb9a5b1f608dd
Signed-off-by: Andrew Geissler <geissonator@yahoo.com>
Diffstat (limited to 'poky/meta/recipes-devtools/python')
56 files changed, 1950 insertions, 142 deletions
diff --git a/poky/meta/recipes-devtools/python/python3-attrs_23.2.0.bb b/poky/meta/recipes-devtools/python/python3-attrs_23.2.0.bb index a638097988..e39b64306c 100644 --- a/poky/meta/recipes-devtools/python/python3-attrs_23.2.0.bb +++ b/poky/meta/recipes-devtools/python/python3-attrs_23.2.0.bb @@ -20,7 +20,6 @@ DEPENDS += " \ RDEPENDS:${PN}+= " \ python3-compression \ - python3-ctypes \ python3-crypt \ " diff --git a/poky/meta/recipes-devtools/python/python3-certifi/CVE-2024-39689.patch b/poky/meta/recipes-devtools/python/python3-certifi/CVE-2024-39689.patch new file mode 100644 index 0000000000..a2ecc15d2c --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3-certifi/CVE-2024-39689.patch @@ -0,0 +1,69 @@ +From bd8153872e9c6fc98f4023df9c2deaffea2fa463 Mon Sep 17 00:00:00 2001 +From: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> +Date: Wed, 3 Jul 2024 21:34:29 -0400 +Subject: [PATCH] 2024.07.04 (#295) + +Co-authored-by: alex <772+alex@users.noreply.github.com> + +CVE: CVE-2024-39689 + +Upstream-Status: Backport [https://github.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463] + +Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com> +--- + certifi/cacert.pem | 40 ---------------------------------------- + 1 file changed, 40 deletions(-) + +diff --git a/certifi/cacert.pem b/certifi/cacert.pem +index 1bec256..6bb8cf8 100644 +--- a/certifi/cacert.pem ++++ b/certifi/cacert.pem +@@ -3857,46 +3857,6 @@ DgQWBBQxCpCPtsad0kRLgLWi5h+xEk8blTAKBggqhkjOPQQDAwNoADBlAjEA31SQ + +RHUjE7AwWHCFUyqqx0LMV87HOIAl0Qx5v5zli/altP+CAezNIm8BZ/3Hobui3A= + -----END CERTIFICATE----- + +-# Issuer: CN=GLOBALTRUST 2020 O=e-commerce monitoring GmbH +-# Subject: CN=GLOBALTRUST 2020 O=e-commerce monitoring GmbH +-# Label: "GLOBALTRUST 2020" +-# Serial: 109160994242082918454945253 +-# MD5 Fingerprint: 8a:c7:6f:cb:6d:e3:cc:a2:f1:7c:83:fa:0e:78:d7:e8 +-# SHA1 Fingerprint: d0:67:c1:13:51:01:0c:aa:d0:c7:6a:65:37:31:16:26:4f:53:71:a2 +-# SHA256 Fingerprint: 9a:29:6a:51:82:d1:d4:51:a2:e3:7f:43:9b:74:da:af:a2:67:52:33:29:f9:0f:9a:0d:20:07:c3:34:e2:3c:9a +------BEGIN CERTIFICATE----- +-MIIFgjCCA2qgAwIBAgILWku9WvtPilv6ZeUwDQYJKoZIhvcNAQELBQAwTTELMAkG +-A1UEBhMCQVQxIzAhBgNVBAoTGmUtY29tbWVyY2UgbW9uaXRvcmluZyBHbWJIMRkw +-FwYDVQQDExBHTE9CQUxUUlVTVCAyMDIwMB4XDTIwMDIxMDAwMDAwMFoXDTQwMDYx +-MDAwMDAwMFowTTELMAkGA1UEBhMCQVQxIzAhBgNVBAoTGmUtY29tbWVyY2UgbW9u +-aXRvcmluZyBHbWJIMRkwFwYDVQQDExBHTE9CQUxUUlVTVCAyMDIwMIICIjANBgkq +-hkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAri5WrRsc7/aVj6B3GyvTY4+ETUWiD59b +-RatZe1E0+eyLinjF3WuvvcTfk0Uev5E4C64OFudBc/jbu9G4UeDLgztzOG53ig9Z +-YybNpyrOVPu44sB8R85gfD+yc/LAGbaKkoc1DZAoouQVBGM+uq/ufF7MpotQsjj3 +-QWPKzv9pj2gOlTblzLmMCcpL3TGQlsjMH/1WljTbjhzqLL6FLmPdqqmV0/0plRPw +-yJiT2S0WR5ARg6I6IqIoV6Lr/sCMKKCmfecqQjuCgGOlYx8ZzHyyZqjC0203b+J+ +-BlHZRYQfEs4kUmSFC0iAToexIiIwquuuvuAC4EDosEKAA1GqtH6qRNdDYfOiaxaJ +-SaSjpCuKAsR49GiKweR6NrFvG5Ybd0mN1MkGco/PU+PcF4UgStyYJ9ORJitHHmkH +-r96i5OTUawuzXnzUJIBHKWk7buis/UDr2O1xcSvy6Fgd60GXIsUf1DnQJ4+H4xj0 +-4KlGDfV0OoIu0G4skaMxXDtG6nsEEFZegB31pWXogvziB4xiRfUg3kZwhqG8k9Me +-dKZssCz3AwyIDMvUclOGvGBG85hqwvG/Q/lwIHfKN0F5VVJjjVsSn8VoxIidrPIw +-q7ejMZdnrY8XD2zHc+0klGvIg5rQmjdJBKuxFshsSUktq6HQjJLyQUp5ISXbY9e2 +-nKd+Qmn7OmMCAwEAAaNjMGEwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMC +-AQYwHQYDVR0OBBYEFNwuH9FhN3nkq9XVsxJxaD1qaJwiMB8GA1UdIwQYMBaAFNwu +-H9FhN3nkq9XVsxJxaD1qaJwiMA0GCSqGSIb3DQEBCwUAA4ICAQCR8EICaEDuw2jA +-VC/f7GLDw56KoDEoqoOOpFaWEhCGVrqXctJUMHytGdUdaG/7FELYjQ7ztdGl4wJC +-XtzoRlgHNQIw4Lx0SsFDKv/bGtCwr2zD/cuz9X9tAy5ZVp0tLTWMstZDFyySCstd +-6IwPS3BD0IL/qMy/pJTAvoe9iuOTe8aPmxadJ2W8esVCgmxcB9CpwYhgROmYhRZf +-+I/KARDOJcP5YBugxZfD0yyIMaK9MOzQ0MAS8cE54+X1+NZK3TTN+2/BT+MAi1bi +-kvcoskJ3ciNnxz8RFbLEAwW+uxF7Cr+obuf/WEPPm2eggAe2HcqtbepBEX4tdJP7 +-wry+UUTF72glJ4DjyKDUEuzZpTcdN3y0kcra1LGWge9oXHYQSa9+pTeAsRxSvTOB +-TI/53WXZFM2KJVj04sWDpQmQ1GwUY7VA3+vA/MRYfg0UFodUJ25W5HCEuGwyEn6C +-MUO+1918oa2u1qsgEu8KwxCMSZY13At1XrFP1U80DhEgB3VDRemjEdqso5nCtnkn +-4rnvyOL2NSl6dPrFf4IFYqYK6miyeUcGbvJXqBUzxvd4Sj1Ce2t+/vdG6tHrju+I +-aFvowdlxfv1k7/9nR4hYJS8+hge9+6jlgqispdNpQ80xiEmEU5LAsTkbOYMBMMTy +-qfrQA71yN2BWHzZ8vTmR9W0Nv3vXkg== +------END CERTIFICATE----- +- + # Issuer: CN=ANF Secure Server Root CA O=ANF Autoridad de Certificacion OU=ANF CA Raiz + # Subject: CN=ANF Secure Server Root CA O=ANF Autoridad de Certificacion OU=ANF CA Raiz + # Label: "ANF Secure Server Root CA" +-- +2.40.0 diff --git a/poky/meta/recipes-devtools/python/python3-certifi_2024.2.2.bb b/poky/meta/recipes-devtools/python/python3-certifi_2024.2.2.bb index 4e61b8d9d4..116add2079 100644 --- a/poky/meta/recipes-devtools/python/python3-certifi_2024.2.2.bb +++ b/poky/meta/recipes-devtools/python/python3-certifi_2024.2.2.bb @@ -7,6 +7,9 @@ HOMEPAGE = " http://certifi.io/" LICENSE = "ISC" LIC_FILES_CHKSUM = "file://LICENSE;md5=11618cb6a975948679286b1211bd573c" +SRC_URI += "file://CVE-2024-39689.patch \ + " + SRC_URI[sha256sum] = "0569859f95fc761b18b45ef421b1290a0f65f147e92a1e5eb3e635f9a5e4e66f" inherit pypi setuptools3 diff --git a/poky/meta/recipes-devtools/python/python3-idna_3.6.bb b/poky/meta/recipes-devtools/python/python3-idna_3.7.bb index 47c080cdf8..729aff1c46 100644 --- a/poky/meta/recipes-devtools/python/python3-idna_3.6.bb +++ b/poky/meta/recipes-devtools/python/python3-idna_3.7.bb @@ -1,9 +1,9 @@ SUMMARY = "Internationalised Domain Names in Applications" HOMEPAGE = "https://github.com/kjd/idna" LICENSE = "BSD-3-Clause & Python-2.0 & Unicode-TOU" -LIC_FILES_CHKSUM = "file://LICENSE.md;md5=dbec47b98e1469f6a104c82ff9698cee" +LIC_FILES_CHKSUM = "file://LICENSE.md;md5=204c0612e40a4dd46012a78d02c80fb1" -SRC_URI[sha256sum] = "9ecdbbd083b06798ae1e86adcbfe8ab1479cf864e4ee30fe4e46a003d12491ca" +SRC_URI[sha256sum] = "028ff3aadf0609c1fd278d8ea3089299412a7a8b9bd005dd08b9f8285bcb5cfc" inherit pypi python_flit_core diff --git a/poky/meta/recipes-devtools/python/python3-jinja2_3.1.4.bb b/poky/meta/recipes-devtools/python/python3-jinja2_3.1.6.bb index 2c02037011..de2b251049 100644 --- a/poky/meta/recipes-devtools/python/python3-jinja2_3.1.4.bb +++ b/poky/meta/recipes-devtools/python/python3-jinja2_3.1.6.bb @@ -4,7 +4,7 @@ HOMEPAGE = "https://pypi.org/project/Jinja2/" LICENSE = "BSD-3-Clause" LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=5dc88300786f1c214c1e9827a5229462" -SRC_URI[sha256sum] = "4a3aee7acbbe7303aede8e9648d13b8bf88a429282aa6122a993f0ac800cb369" +SRC_URI[sha256sum] = "0137fb05990d35f1275a587e9aee6d56da821fc83491a0fb838183be43f66d6d" PYPI_PACKAGE = "jinja2" @@ -21,6 +21,9 @@ SRC_URI += " \ do_install_ptest() { install -d ${D}${PTEST_PATH}/tests cp -rf ${S}/tests/* ${D}${PTEST_PATH}/tests/ + + # test_async items require trio module + rm -f ${D}${PTEST_PATH}/tests/test_async.py ${D}${PTEST_PATH}/tests/test_async_filters.py } RDEPENDS:${PN}-ptest += " \ diff --git a/poky/meta/recipes-devtools/python/python3-lxml_5.0.0.bb b/poky/meta/recipes-devtools/python/python3-lxml_5.0.2.bb index 66cb8b0938..c0b385c7ea 100644 --- a/poky/meta/recipes-devtools/python/python3-lxml_5.0.0.bb +++ b/poky/meta/recipes-devtools/python/python3-lxml_5.0.2.bb @@ -18,11 +18,10 @@ LIC_FILES_CHKSUM = "file://LICENSES.txt;md5=e4c045ebad958ead4b48008f70838403 \ DEPENDS += "libxml2 libxslt" -SRC_URI[sha256sum] = "2219cbf790e701acf9a21a31ead75f983e73daf0eceb9da6990212e4d20ebefe" +SRC_URI[sha256sum] = "6399703c40ba53e2c3b72fdb56cb908d2b83c08082ecf17de839b27e68d1e598" SRC_URI += "${PYPI_SRC_URI}" inherit pkgconfig pypi setuptools3 -PYPI_PACKAGE_EXT = "zip" # {standard input}: Assembler messages: # {standard input}:1488805: Error: branch out of range diff --git a/poky/meta/recipes-devtools/python/python3-maturin/0001-Extract-extension-architecture-name-resolvation-code.patch b/poky/meta/recipes-devtools/python/python3-maturin/0001-Extract-extension-architecture-name-resolvation-code.patch new file mode 100644 index 0000000000..f75d5a1ba8 --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3-maturin/0001-Extract-extension-architecture-name-resolvation-code.patch @@ -0,0 +1,107 @@ +From 42a97ee7100ad158d4b1ba6133ea13cc864a567f Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Vesa=20J=C3=A4=C3=A4skel=C3=A4inen?= + <vesa.jaaskelainen@vaisala.com> +Date: Sun, 1 Sep 2024 09:23:10 +0300 +Subject: [PATCH 1/5] Extract extension architecture name resolvation code as + helper +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +This commit introduces helper InterpreterConfig.get_python_ext_arch() that +can be used to determine the extension architecture name python uses in +`ext_suffix` for this architecture. + +Upstream-Status: Backport [https://github.com/PyO3/maturin/commit/42a97ee7100ad158d4b1ba6133ea13cc864a567f] + +Signed-off-by: Vesa Jääskeläinen <vesa.jaaskelainen@vaisala.com> +--- + src/python_interpreter/config.rs | 18 ++++++------------ + src/target.rs | 16 ++++++++++++++++ + 2 files changed, 22 insertions(+), 12 deletions(-) + +diff --git a/src/python_interpreter/config.rs b/src/python_interpreter/config.rs +index 912f9218..d76606f2 100644 +--- a/src/python_interpreter/config.rs ++++ b/src/python_interpreter/config.rs +@@ -47,15 +47,7 @@ impl InterpreterConfig { + // Python 2 is not supported + return None; + } +- let python_arch = if matches!(target.target_arch(), Arch::Armv6L | Arch::Armv7L) { +- "arm" +- } else if matches!(target.target_arch(), Arch::Powerpc64Le) && python_impl == PyPy { +- "ppc_64" +- } else if matches!(target.target_arch(), Arch::X86) && python_impl == PyPy { +- "x86" +- } else { +- target.get_python_arch() +- }; ++ let python_ext_arch = target.get_python_ext_arch(python_impl); + // See https://github.com/pypa/auditwheel/issues/349 + let target_env = match python_impl { + CPython => { +@@ -77,7 +69,7 @@ impl InterpreterConfig { + let ldversion = format!("{}{}{}", major, minor, abiflags); + let ext_suffix = format!( + ".cpython-{}-{}-linux-{}.so", +- ldversion, python_arch, target_env ++ ldversion, python_ext_arch, target_env + ); + Some(Self { + major, +@@ -90,7 +82,8 @@ impl InterpreterConfig { + } + (Os::Linux, PyPy) => { + let abi_tag = format!("pypy{}{}-{}", major, minor, PYPY_ABI_TAG); +- let ext_suffix = format!(".{}-{}-linux-{}.so", abi_tag, python_arch, target_env); ++ let ext_suffix = ++ format!(".{}-{}-linux-{}.so", abi_tag, python_ext_arch, target_env); + Some(Self { + major, + minor, +@@ -204,7 +197,8 @@ impl InterpreterConfig { + } + (Os::Emscripten, CPython) => { + let ldversion = format!("{}{}", major, minor); +- let ext_suffix = format!(".cpython-{}-{}-emscripten.so", ldversion, python_arch); ++ let ext_suffix = ++ format!(".cpython-{}-{}-emscripten.so", ldversion, python_ext_arch); + Some(Self { + major, + minor, +diff --git a/src/target.rs b/src/target.rs +index dc7df0cf..84bae559 100644 +--- a/src/target.rs ++++ b/src/target.rs +@@ -1,4 +1,5 @@ + use crate::cross_compile::is_cross_compiling; ++use crate::python_interpreter::InterpreterKind; + use crate::PlatformTag; + use anyhow::{anyhow, bail, format_err, Result}; + use platform_info::*; +@@ -368,6 +369,21 @@ impl Target { + } + } + ++ /// Returns the extension architecture name python uses in `ext_suffix` for this architecture. ++ pub fn get_python_ext_arch(&self, python_impl: InterpreterKind) -> &str { ++ if matches!(self.target_arch(), Arch::Armv6L | Arch::Armv7L) { ++ "arm" ++ } else if matches!(self.target_arch(), Arch::Powerpc64Le) ++ && python_impl == InterpreterKind::PyPy ++ { ++ "ppc_64" ++ } else if matches!(self.target_arch(), Arch::X86) && python_impl == InterpreterKind::PyPy { ++ "x86" ++ } else { ++ self.get_python_arch() ++ } ++ } ++ + /// Returns the name python uses in `sys.platform` for this os + pub fn get_python_os(&self) -> &str { + match self.os { +-- +2.34.1 + diff --git a/poky/meta/recipes-devtools/python/python3-maturin/0002-Fix-cross-compilation-issue-with-linux-armv7l-archit.patch b/poky/meta/recipes-devtools/python/python3-maturin/0002-Fix-cross-compilation-issue-with-linux-armv7l-archit.patch new file mode 100644 index 0000000000..4366dde111 --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3-maturin/0002-Fix-cross-compilation-issue-with-linux-armv7l-archit.patch @@ -0,0 +1,76 @@ +From 0c6b8cc84eff72ed21098029aaba079b899dbee2 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Vesa=20J=C3=A4=C3=A4skel=C3=A4inen?= + <vesa.jaaskelainen@vaisala.com> +Date: Sun, 1 Sep 2024 09:23:40 +0300 +Subject: [PATCH 2/5] Fix cross compilation issue with linux-armv7l + architecture +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +When compiling under Yocto project for linux-armv7l target architecture +.so files were generated incorrectly as: + + rpds.cpython-312-armv7l-linux-gnueabihf.so + +Where as platform and EXT_SUFFIX are defined as: + + >>> sysconfig.get_platform() + 'linux-armv7l' + >>> sysconfig.get_config_vars()['EXT_SUFFIX'] + '.cpython-312-arm-linux-gnueabihf.so' + +Which should have caused the .so files as: + + rpds.cpython-312-arm-linux-gnueabihf.so + +Upstream-Status: Backport [https://github.com/PyO3/maturin/commit/0c6b8cc84eff72ed21098029aaba079b899dbee2] + +Signed-off-by: Vesa Jääskeläinen <vesa.jaaskelainen@vaisala.com> +--- + src/python_interpreter/config.rs | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/src/python_interpreter/config.rs b/src/python_interpreter/config.rs +index d76606f2..5736aedc 100644 +--- a/src/python_interpreter/config.rs ++++ b/src/python_interpreter/config.rs +@@ -306,7 +306,7 @@ impl InterpreterConfig { + format!( + ".cpython-{}-{}-{}-{}.{}", + abi_tag, +- target.get_python_arch(), ++ target.get_python_ext_arch(interpreter_kind), + target.get_python_os(), + target_env, + file_ext, +@@ -319,7 +319,7 @@ impl InterpreterConfig { + major, + minor, + abi_tag, +- target.get_python_arch(), ++ target.get_python_ext_arch(interpreter_kind), + target.get_python_os(), + target_env, + file_ext, +@@ -330,7 +330,7 @@ impl InterpreterConfig { + format!( + ".{}-{}-{}.{}", + abi_tag.replace('_', "-"), +- target.get_python_arch(), ++ target.get_python_ext_arch(interpreter_kind), + target.get_python_os(), + file_ext, + ) +@@ -341,7 +341,7 @@ impl InterpreterConfig { + format!( + ".cpython-{}-{}-{}.{}", + abi_tag, +- target.get_python_arch(), ++ target.get_python_ext_arch(interpreter_kind), + target.get_python_os(), + file_ext + ) +-- +2.34.1 + diff --git a/poky/meta/recipes-devtools/python/python3-maturin/0003-Extract-extension-ABI-name-resolvation-code-as-helpe.patch b/poky/meta/recipes-devtools/python/python3-maturin/0003-Extract-extension-ABI-name-resolvation-code-as-helpe.patch new file mode 100644 index 0000000000..b4a7f69492 --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3-maturin/0003-Extract-extension-ABI-name-resolvation-code-as-helpe.patch @@ -0,0 +1,98 @@ +From fa64426f3a98a0455721c23ec86bd2240708b45e Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Vesa=20J=C3=A4=C3=A4skel=C3=A4inen?= + <vesa.jaaskelainen@vaisala.com> +Date: Sun, 1 Sep 2024 15:55:07 +0300 +Subject: [PATCH 3/5] Extract extension ABI name resolvation code as helper +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +This commit introduces helper InterpreterConfig.get_python_target_env() +that can be used to determine the extension ABI python uses in +`ext_suffix` for this architecture. + +Upstream-Status: Backport [https://github.com/PyO3/maturin/commit/fa64426f3a98a0455721c23ec86bd2240708b45e] + +Signed-off-by: Vesa Jääskeläinen <vesa.jaaskelainen@vaisala.com> +--- + src/python_interpreter/config.rs | 19 ++----------------- + src/target.rs | 20 ++++++++++++++++++++ + 2 files changed, 22 insertions(+), 17 deletions(-) + +diff --git a/src/python_interpreter/config.rs b/src/python_interpreter/config.rs +index 5736aedc..938e9955 100644 +--- a/src/python_interpreter/config.rs ++++ b/src/python_interpreter/config.rs +@@ -48,17 +48,7 @@ impl InterpreterConfig { + return None; + } + let python_ext_arch = target.get_python_ext_arch(python_impl); +- // See https://github.com/pypa/auditwheel/issues/349 +- let target_env = match python_impl { +- CPython => { +- if python_version >= (3, 11) { +- target.target_env().to_string() +- } else { +- target.target_env().to_string().replace("musl", "gnu") +- } +- } +- PyPy | GraalPy => "gnu".to_string(), +- }; ++ let target_env = target.get_python_target_env(python_impl, python_version); + match (target.target_os(), python_impl) { + (Os::Linux, CPython) => { + let abiflags = if python_version < (3, 8) { +@@ -294,12 +284,7 @@ impl InterpreterConfig { + }; + let file_ext = if target.is_windows() { "pyd" } else { "so" }; + let ext_suffix = if target.is_linux() || target.is_macos() { +- // See https://github.com/pypa/auditwheel/issues/349 +- let target_env = if (major, minor) >= (3, 11) { +- target.target_env().to_string() +- } else { +- target.target_env().to_string().replace("musl", "gnu") +- }; ++ let target_env = target.get_python_target_env(interpreter_kind, (major, minor)); + match interpreter_kind { + InterpreterKind::CPython => ext_suffix.unwrap_or_else(|| { + // Eg: .cpython-38-x86_64-linux-gnu.so +diff --git a/src/target.rs b/src/target.rs +index 84bae559..ad8ebaba 100644 +--- a/src/target.rs ++++ b/src/target.rs +@@ -1,5 +1,6 @@ + use crate::cross_compile::is_cross_compiling; + use crate::python_interpreter::InterpreterKind; ++use crate::python_interpreter::InterpreterKind::{CPython, GraalPy, PyPy}; + use crate::PlatformTag; + use anyhow::{anyhow, bail, format_err, Result}; + use platform_info::*; +@@ -384,6 +385,25 @@ impl Target { + } + } + ++ /// Returns the environment python uses in `ext_suffix` for this architecture. ++ pub fn get_python_target_env( ++ &self, ++ python_impl: InterpreterKind, ++ python_version: (usize, usize), ++ ) -> String { ++ match python_impl { ++ CPython => { ++ // For musl handling see https://github.com/pypa/auditwheel/issues/349 ++ if python_version >= (3, 11) { ++ self.target_env().to_string() ++ } else { ++ self.target_env().to_string().replace("musl", "gnu") ++ } ++ } ++ PyPy | GraalPy => "gnu".to_string(), ++ } ++ } ++ + /// Returns the name python uses in `sys.platform` for this os + pub fn get_python_os(&self) -> &str { + match self.os { +-- +2.34.1 + diff --git a/poky/meta/recipes-devtools/python/python3-maturin/0004-Fix-cross-compilation-issue-with-linux-ppc-architect.patch b/poky/meta/recipes-devtools/python/python3-maturin/0004-Fix-cross-compilation-issue-with-linux-ppc-architect.patch new file mode 100644 index 0000000000..bda5dca8f6 --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3-maturin/0004-Fix-cross-compilation-issue-with-linux-ppc-architect.patch @@ -0,0 +1,68 @@ +From f2c892109a05db144e8b18bcbcf9c24fe8d977c4 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Vesa=20J=C3=A4=C3=A4skel=C3=A4inen?= + <vesa.jaaskelainen@vaisala.com> +Date: Sun, 1 Sep 2024 15:55:16 +0300 +Subject: [PATCH 4/5] Fix cross compilation issue with linux-ppc architecture +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +When compiling under Yocto project for linux-ppc target architecture +.so files were generated incorrectly as: + + rpds.cpython-312-ppc-linux-gnu.so + +Where as platform and EXT_SUFFIX are defined as: + + >>> sysconfig.get_platform() + 'linux-ppc' + >>> sysconfig.get_config_vars()['EXT_SUFFIX'] + '.cpython-312-powerpc-linux-gnu.so' + +Which should have caused the .so files as: + + rpds.cpython-312-powerpc-linux-gnu.so + +Upstream-Status: Backport [https://github.com/PyO3/maturin/commit/f2c892109a05db144e8b18bcbcf9c24fe8d977c4] + +Signed-off-by: Vesa Jääskeläinen <vesa.jaaskelainen@vaisala.com> +--- + src/python_interpreter/config.rs | 8 ++++++++ + src/target.rs | 2 ++ + 2 files changed, 10 insertions(+) + +diff --git a/src/python_interpreter/config.rs b/src/python_interpreter/config.rs +index 938e9955..8f883887 100644 +--- a/src/python_interpreter/config.rs ++++ b/src/python_interpreter/config.rs +@@ -424,6 +424,14 @@ mod test { + ".cpython-310-powerpc64le-linux-gnu.so" + ); + ++ let sysconfig = InterpreterConfig::lookup_one( ++ &Target::from_target_triple(Some("powerpc-unknown-linux-gnu".to_string())).unwrap(), ++ InterpreterKind::CPython, ++ (3, 10), ++ ) ++ .unwrap(); ++ assert_eq!(sysconfig.ext_suffix, ".cpython-310-powerpc-linux-gnu.so"); ++ + let sysconfig = InterpreterConfig::lookup_one( + &Target::from_target_triple(Some("s390x-unknown-linux-gnu".to_string())).unwrap(), + InterpreterKind::CPython, +diff --git a/src/target.rs b/src/target.rs +index ad8ebaba..93afd9bb 100644 +--- a/src/target.rs ++++ b/src/target.rs +@@ -380,6 +380,8 @@ impl Target { + "ppc_64" + } else if matches!(self.target_arch(), Arch::X86) && python_impl == InterpreterKind::PyPy { + "x86" ++ } else if matches!(self.target_arch(), Arch::Powerpc) { ++ "powerpc" + } else { + self.get_python_arch() + } +-- +2.34.1 + diff --git a/poky/meta/recipes-devtools/python/python3-maturin/0005-Fix-cross-compilation-issue-with-linux-mips64-archit.patch b/poky/meta/recipes-devtools/python/python3-maturin/0005-Fix-cross-compilation-issue-with-linux-mips64-archit.patch new file mode 100644 index 0000000000..b24196d5dd --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3-maturin/0005-Fix-cross-compilation-issue-with-linux-mips64-archit.patch @@ -0,0 +1,82 @@ +From 5fe643579bcc63d824f6a0f0936fff451c622903 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Vesa=20J=C3=A4=C3=A4skel=C3=A4inen?= + <vesa.jaaskelainen@vaisala.com> +Date: Sun, 1 Sep 2024 15:55:54 +0300 +Subject: [PATCH 5/5] Fix cross compilation issue with linux-mips64 + architecture +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +When compiling under Yocto project for linux-mips64 target architecture +.so files were generated incorrectly as: + + rpds.cpython-312-mips64-linux-gnu.so + +Where as platform and EXT_SUFFIX are defined as: + + >>> sysconfig.get_platform() + 'linux-mips64' + >>> sysconfig.get_config_vars()['EXT_SUFFIX'] + '.cpython-312-mips64-linux-gnuabi64.so' + +Which should have caused the .so files as: + + rpds.cpython-312-mips64-linux-gnuabi64.so + +Upstream-Status: Backport [https://github.com/PyO3/maturin/commit/5fe643579bcc63d824f6a0f0936fff451c622903] + +Signed-off-by: Vesa Jääskeläinen <vesa.jaaskelainen@vaisala.com> +--- + src/python_interpreter/config.rs | 19 +++++++++++++++++++ + src/target.rs | 4 +++- + 2 files changed, 22 insertions(+), 1 deletion(-) + +diff --git a/src/python_interpreter/config.rs b/src/python_interpreter/config.rs +index 8f883887..ef656010 100644 +--- a/src/python_interpreter/config.rs ++++ b/src/python_interpreter/config.rs +@@ -432,6 +432,25 @@ mod test { + .unwrap(); + assert_eq!(sysconfig.ext_suffix, ".cpython-310-powerpc-linux-gnu.so"); + ++ let sysconfig = InterpreterConfig::lookup_one( ++ &Target::from_target_triple(Some("mips64-unknown-linux-gnu".to_string())).unwrap(), ++ InterpreterKind::CPython, ++ (3, 10), ++ ) ++ .unwrap(); ++ assert_eq!( ++ sysconfig.ext_suffix, ++ ".cpython-310-mips64-linux-gnuabi64.so" ++ ); ++ ++ let sysconfig = InterpreterConfig::lookup_one( ++ &Target::from_target_triple(Some("mips-unknown-linux-gnu".to_string())).unwrap(), ++ InterpreterKind::CPython, ++ (3, 10), ++ ) ++ .unwrap(); ++ assert_eq!(sysconfig.ext_suffix, ".cpython-310-mips-linux-gnu.so"); ++ + let sysconfig = InterpreterConfig::lookup_one( + &Target::from_target_triple(Some("s390x-unknown-linux-gnu".to_string())).unwrap(), + InterpreterKind::CPython, +diff --git a/src/target.rs b/src/target.rs +index 93afd9bb..25fc6c07 100644 +--- a/src/target.rs ++++ b/src/target.rs +@@ -396,7 +396,9 @@ impl Target { + match python_impl { + CPython => { + // For musl handling see https://github.com/pypa/auditwheel/issues/349 +- if python_version >= (3, 11) { ++ if matches!(self.target_arch(), Arch::Mips64 | Arch::Mips64el) && self.is_linux() { ++ "gnuabi64".to_string() ++ } else if python_version >= (3, 11) { + self.target_env().to_string() + } else { + self.target_env().to_string().replace("musl", "gnu") +-- +2.34.1 + diff --git a/poky/meta/recipes-devtools/python/python3-maturin_1.4.0.bb b/poky/meta/recipes-devtools/python/python3-maturin_1.4.0.bb index ed19ee647a..7322de0d08 100644 --- a/poky/meta/recipes-devtools/python/python3-maturin_1.4.0.bb +++ b/poky/meta/recipes-devtools/python/python3-maturin_1.4.0.bb @@ -7,6 +7,13 @@ LIC_FILES_CHKSUM = "file://license-apache;md5=1836efb2eb779966696f473ee8540542 \ SRC_URI += "file://0001-Add-32-bit-RISC-V-support.patch" SRC_URI[sha256sum] = "ed12e1768094a7adeafc3a74ebdb8dc2201fa64c4e7e31f14cfc70378bf93790" +SRC_URI:append = "\ + file://0001-Extract-extension-architecture-name-resolvation-code.patch \ + file://0002-Fix-cross-compilation-issue-with-linux-armv7l-archit.patch \ + file://0003-Extract-extension-ABI-name-resolvation-code-as-helpe.patch \ + file://0004-Fix-cross-compilation-issue-with-linux-ppc-architect.patch \ + file://0005-Fix-cross-compilation-issue-with-linux-mips64-archit.patch \ +" S = "${WORKDIR}/maturin-${PV}" diff --git a/poky/meta/recipes-devtools/python/python3-poetry-core_1.9.0.bb b/poky/meta/recipes-devtools/python/python3-poetry-core_1.9.0.bb index 540fdffaed..d1a8b939c0 100644 --- a/poky/meta/recipes-devtools/python/python3-poetry-core_1.9.0.bb +++ b/poky/meta/recipes-devtools/python/python3-poetry-core_1.9.0.bb @@ -36,7 +36,6 @@ RDEPENDS:${PN}:append:class-target = "\ RDEPENDS:${PN} += "\ python3-pip \ - python3-six \ " BBCLASSEXTEND = "native nativesdk" diff --git a/poky/meta/recipes-devtools/python/python3-pycryptodome_3.20.0.bb b/poky/meta/recipes-devtools/python/python3-pycryptodome_3.20.0.bb index d24fa58d43..6c93c205ac 100644 --- a/poky/meta/recipes-devtools/python/python3-pycryptodome_3.20.0.bb +++ b/poky/meta/recipes-devtools/python/python3-pycryptodome_3.20.0.bb @@ -1,5 +1,5 @@ require python-pycryptodome.inc -inherit setuptools3 +inherit python_setuptools_build_meta SRC_URI[sha256sum] = "09609209ed7de61c2b560cc5c8c4fbf892f8b15b1faf7e4cbffac97db1fffda7" diff --git a/poky/meta/recipes-devtools/python/python3-pycryptodomex_3.20.0.bb b/poky/meta/recipes-devtools/python/python3-pycryptodomex_3.20.0.bb index 2673ea8326..54578d2850 100644 --- a/poky/meta/recipes-devtools/python/python3-pycryptodomex_3.20.0.bb +++ b/poky/meta/recipes-devtools/python/python3-pycryptodomex_3.20.0.bb @@ -1,5 +1,5 @@ require python-pycryptodome.inc -inherit setuptools3 +inherit python_setuptools_build_meta SRC_URI[sha256sum] = "7a710b79baddd65b806402e14766c721aee8fb83381769c27920f26476276c1e" diff --git a/poky/meta/recipes-devtools/python/python3-requests/environment.d-python3-requests.sh b/poky/meta/recipes-devtools/python/python3-requests/environment.d-python3-requests.sh new file mode 100644 index 0000000000..400972814b --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3-requests/environment.d-python3-requests.sh @@ -0,0 +1,11 @@ +# Respect host env REQUESTS_CA_BUNDLE first, then auto-detected host cert, then cert in buildtools +# CAFILE/CAPATH is auto-deteced when source buildtools +if [ -z "${REQUESTS_CA_BUNDLE:-}" ]; then + if [ -n "${CAFILE:-}" ];then + export REQUESTS_CA_BUNDLE="$CAFILE" + elif [ -e "${OECORE_NATIVE_SYSROOT}/etc/ssl/certs/ca-certificates.crt" ];then + export REQUESTS_CA_BUNDLE="${OECORE_NATIVE_SYSROOT}/etc/ssl/certs/ca-certificates.crt" + fi +fi + +export BB_ENV_PASSTHROUGH_ADDITIONS="${BB_ENV_PASSTHROUGH_ADDITIONS:-} REQUESTS_CA_BUNDLE" diff --git a/poky/meta/recipes-devtools/python/python3-requests_2.31.0.bb b/poky/meta/recipes-devtools/python/python3-requests_2.31.0.bb deleted file mode 100644 index 287b4f8eee..0000000000 --- a/poky/meta/recipes-devtools/python/python3-requests_2.31.0.bb +++ /dev/null @@ -1,24 +0,0 @@ -SUMMARY = "Python HTTP for Humans." -HOMEPAGE = "https://requests.readthedocs.io" -LICENSE = "Apache-2.0" -LIC_FILES_CHKSUM = "file://LICENSE;md5=34400b68072d710fecd0a2940a0d1658" - -SRC_URI[sha256sum] = "942c5a758f98d790eaed1a29cb6eefc7ffb0d1cf7af05c3d2791656dbd6ad1e1" - -inherit pypi setuptools3 - -RDEPENDS:${PN} += " \ - python3-certifi \ - python3-email \ - python3-json \ - python3-netserver \ - python3-pysocks \ - python3-urllib3 \ - python3-chardet \ - python3-idna \ - python3-compression \ -" - -CVE_PRODUCT = "requests" - -BBCLASSEXTEND = "native nativesdk" diff --git a/poky/meta/recipes-devtools/python/python3-requests_2.32.4.bb b/poky/meta/recipes-devtools/python/python3-requests_2.32.4.bb new file mode 100644 index 0000000000..b86ecfba52 --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3-requests_2.32.4.bb @@ -0,0 +1,35 @@ +SUMMARY = "Python HTTP for Humans." +HOMEPAGE = "https://requests.readthedocs.io" +LICENSE = "Apache-2.0" +LIC_FILES_CHKSUM = "file://LICENSE;md5=34400b68072d710fecd0a2940a0d1658" + +SRC_URI:append:class-nativesdk = " \ + file://environment.d-python3-requests.sh \ +" + +SRC_URI[sha256sum] = "27d0316682c8a29834d3264820024b62a36942083d52caf2f14c0591336d3422" + +inherit pypi python_setuptools_build_meta + +do_install:append:class-nativesdk() { + mkdir -p ${D}${SDKPATHNATIVE}/environment-setup.d + install -m 644 ${WORKDIR}/environment.d-python3-requests.sh ${D}${SDKPATHNATIVE}/environment-setup.d/python3-requests.sh +} + +RDEPENDS:${PN} += " \ + python3-certifi \ + python3-email \ + python3-json \ + python3-netserver \ + python3-pysocks \ + python3-urllib3 \ + python3-chardet \ + python3-idna \ + python3-compression \ +" + +FILES:${PN}:append:class-nativesdk = " ${SDKPATHNATIVE}/environment-setup.d/python3-requests.sh" + +CVE_PRODUCT = "requests" + +BBCLASSEXTEND = "native nativesdk" diff --git a/poky/meta/recipes-devtools/python/python3-setuptools-scm/0001-respect-GIT_CEILING_DIRECTORIES.patch b/poky/meta/recipes-devtools/python/python3-setuptools-scm/0001-respect-GIT_CEILING_DIRECTORIES.patch new file mode 100644 index 0000000000..7d2808cc0c --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3-setuptools-scm/0001-respect-GIT_CEILING_DIRECTORIES.patch @@ -0,0 +1,36 @@ +From a1cc419a118560d63e1ab8838c256a3622185750 Mon Sep 17 00:00:00 2001 +From: Etienne Cordonnier <ecordonnier@snap.com> +Date: Thu, 13 Feb 2025 15:44:40 +0100 +Subject: [PATCH] respect GIT_CEILING_DIRECTORIES + +Fix for https://github.com/pypa/setuptools-scm/issues/1103 + +When searching for the root-directory of the git repository e.g. with git rev-parse --show-toplevel, +git stops the search when reaching $GIT_CEILING_DIRECTORIES. By ignoring this variable, the function +_git_toplevel can go above the real git repository (e.g. when packaging a tarball without .git repository), +and then runs "git archive" on an unrelated git repository. + +Upstream-Status: Pending + +Signed-off-by: Ross Burton <ross.burton@arm.com> +Signed-off-by: Etienne Cordonnier <ecordonnier@snap.com> +--- + src/setuptools_scm/_run_cmd.py | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/setuptools_scm/_run_cmd.py b/src/setuptools_scm/_run_cmd.py +index f2a8285..7e13d9f 100644 +--- a/src/setuptools_scm/_run_cmd.py ++++ b/src/setuptools_scm/_run_cmd.py +@@ -98,7 +98,7 @@ def no_git_env(env: Mapping[str, str]) -> dict[str, str]: + k: v + for k, v in env.items() + if not k.startswith("GIT_") +- or k in ("GIT_EXEC_PATH", "GIT_SSH", "GIT_SSH_COMMAND") ++ or k in ("GIT_CEILING_DIRECTORIES", "GIT_EXEC_PATH", "GIT_SSH", "GIT_SSH_COMMAND") + } + + +-- +2.43.0 + diff --git a/poky/meta/recipes-devtools/python/python3-setuptools-scm_8.0.4.bb b/poky/meta/recipes-devtools/python/python3-setuptools-scm_8.0.4.bb index 64b5050c3b..d5f8358a61 100644 --- a/poky/meta/recipes-devtools/python/python3-setuptools-scm_8.0.4.bb +++ b/poky/meta/recipes-devtools/python/python3-setuptools-scm_8.0.4.bb @@ -6,6 +6,7 @@ argument or in a SCM managed file." LICENSE = "MIT" LIC_FILES_CHKSUM = "file://LICENSE;md5=838c366f69b72c5df05c96dff79b35f2" +SRC_URI += "file://0001-respect-GIT_CEILING_DIRECTORIES.patch" SRC_URI[sha256sum] = "b5f43ff6800669595193fd09891564ee9d1d7dcb196cab4b2506d53a2e1c95c7" inherit pypi python_setuptools_build_meta diff --git a/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2024-6345.patch b/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2024-6345.patch new file mode 100644 index 0000000000..ac520be74a --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2024-6345.patch @@ -0,0 +1,312 @@ +From 88807c7062788254f654ea8c03427adc859321f0 Mon Sep 17 00:00:00 2001 +From: Jason R. Coombs <jaraco@jaraco.com> +Date: Mon Apr 29 20:01:38 2024 -0400 +Subject: [PATCH] Merge pull request #4332 from pypa/debt/package-index-vcs + +Modernize package_index VCS handling + +CVE: CVE-2024-6345 + +Upstream-Status: Backport [https://github.com/pypa/setuptools/commit/88807c7062788254f654ea8c03427adc859321f0] + +Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com> +--- + setup.cfg | 1 + + setuptools/package_index.py | 145 ++++++++++++++------------ + setuptools/tests/test_packageindex.py | 56 +++++----- + 3 files changed, 106 insertions(+), 96 deletions(-) + +diff --git a/setup.cfg b/setup.cfg +index edf9798..238d00a 100644 +--- a/setup.cfg ++++ b/setup.cfg +@@ -65,6 +65,7 @@ testing = + sys_platform != "cygwin" + jaraco.develop >= 7.21; python_version >= "3.9" and sys_platform != "cygwin" + pytest-home >= 0.5 ++ pytest-subprocess + testing-integration = + pytest + pytest-xdist +diff --git a/setuptools/package_index.py b/setuptools/package_index.py +index 271aa97..00a972d 100644 +--- a/setuptools/package_index.py ++++ b/setuptools/package_index.py +@@ -1,6 +1,7 @@ + """PyPI and direct package downloading.""" + + import sys ++import subprocess + import os + import re + import io +@@ -585,7 +586,7 @@ class PackageIndex(Environment): + scheme = URL_SCHEME(spec) + if scheme: + # It's a url, download it to tmpdir +- found = self._download_url(scheme.group(1), spec, tmpdir) ++ found = self._download_url(spec, tmpdir) + base, fragment = egg_info_for_url(spec) + if base.endswith('.py'): + found = self.gen_setup(found, fragment, tmpdir) +@@ -814,7 +815,7 @@ class PackageIndex(Environment): + else: + raise DistutilsError("Download error for %s: %s" % (url, v)) from v + +- def _download_url(self, scheme, url, tmpdir): ++ def _download_url(self, url, tmpdir): + # Determine download filename + # + name, fragment = egg_info_for_url(url) +@@ -829,19 +830,59 @@ class PackageIndex(Environment): + + filename = os.path.join(tmpdir, name) + +- # Download the file +- # +- if scheme == 'svn' or scheme.startswith('svn+'): +- return self._download_svn(url, filename) +- elif scheme == 'git' or scheme.startswith('git+'): +- return self._download_git(url, filename) +- elif scheme.startswith('hg+'): +- return self._download_hg(url, filename) +- elif scheme == 'file': +- return urllib.request.url2pathname(urllib.parse.urlparse(url)[2]) +- else: +- self.url_ok(url, True) # raises error if not allowed +- return self._attempt_download(url, filename) ++ return self._download_vcs(url, filename) or self._download_other(url, filename) ++ ++ @staticmethod ++ def _resolve_vcs(url): ++ """ ++ >>> rvcs = PackageIndex._resolve_vcs ++ >>> rvcs('git+http://foo/bar') ++ 'git' ++ >>> rvcs('hg+https://foo/bar') ++ 'hg' ++ >>> rvcs('git:myhost') ++ 'git' ++ >>> rvcs('hg:myhost') ++ >>> rvcs('http://foo/bar') ++ """ ++ scheme = urllib.parse.urlsplit(url).scheme ++ pre, sep, post = scheme.partition('+') ++ # svn and git have their own protocol; hg does not ++ allowed = set(['svn', 'git'] + ['hg'] * bool(sep)) ++ return next(iter({pre} & allowed), None) ++ ++ def _download_vcs(self, url, spec_filename): ++ vcs = self._resolve_vcs(url) ++ if not vcs: ++ return ++ if vcs == 'svn': ++ raise DistutilsError( ++ f"Invalid config, SVN download is not supported: {url}" ++ ) ++ ++ filename, _, _ = spec_filename.partition('#') ++ url, rev = self._vcs_split_rev_from_url(url) ++ ++ self.info(f"Doing {vcs} clone from {url} to {filename}") ++ subprocess.check_call([vcs, 'clone', '--quiet', url, filename]) ++ ++ co_commands = dict( ++ git=[vcs, '-C', filename, 'checkout', '--quiet', rev], ++ hg=[vcs, '--cwd', filename, 'up', '-C', '-r', rev, '-q'], ++ ) ++ if rev is not None: ++ self.info(f"Checking out {rev}") ++ subprocess.check_call(co_commands[vcs]) ++ ++ return filename ++ ++ def _download_other(self, url, filename): ++ scheme = urllib.parse.urlsplit(url).scheme ++ if scheme == 'file': # pragma: no cover ++ return urllib.request.url2pathname(urllib.parse.urlparse(url).path) ++ # raise error if not allowed ++ self.url_ok(url, True) ++ return self._attempt_download(url, filename) + + def scan_url(self, url): + self.process_url(url, True) +@@ -857,64 +898,36 @@ class PackageIndex(Environment): + os.unlink(filename) + raise DistutilsError(f"Unexpected HTML page found at {url}") + +- def _download_svn(self, url, _filename): +- raise DistutilsError(f"Invalid config, SVN download is not supported: {url}") +- + @staticmethod +- def _vcs_split_rev_from_url(url, pop_prefix=False): +- scheme, netloc, path, query, frag = urllib.parse.urlsplit(url) ++ def _vcs_split_rev_from_url(url): ++ """ ++ Given a possible VCS URL, return a clean URL and resolved revision if any. ++ >>> vsrfu = PackageIndex._vcs_split_rev_from_url ++ >>> vsrfu('git+https://github.com/pypa/setuptools@v69.0.0#egg-info=setuptools') ++ ('https://github.com/pypa/setuptools', 'v69.0.0') ++ >>> vsrfu('git+https://github.com/pypa/setuptools#egg-info=setuptools') ++ ('https://github.com/pypa/setuptools', None) ++ >>> vsrfu('http://foo/bar') ++ ('http://foo/bar', None) ++ """ ++ parts = urllib.parse.urlsplit(url) + +- scheme = scheme.split('+', 1)[-1] ++ clean_scheme = parts.scheme.split('+', 1)[-1] + + # Some fragment identification fails +- path = path.split('#', 1)[0] +- +- rev = None +- if '@' in path: +- path, rev = path.rsplit('@', 1) +- +- # Also, discard fragment +- url = urllib.parse.urlunsplit((scheme, netloc, path, query, '')) +- +- return url, rev +- +- def _download_git(self, url, filename): +- filename = filename.split('#', 1)[0] +- url, rev = self._vcs_split_rev_from_url(url, pop_prefix=True) +- +- self.info("Doing git clone from %s to %s", url, filename) +- os.system("git clone --quiet %s %s" % (url, filename)) +- +- if rev is not None: +- self.info("Checking out %s", rev) +- os.system( +- "git -C %s checkout --quiet %s" +- % ( +- filename, +- rev, +- ) +- ) ++ no_fragment_path, _, _ = parts.path.partition('#') + +- return filename ++ pre, sep, post = no_fragment_path.rpartition('@') ++ clean_path, rev = (pre, post) if sep else (post, None) + +- def _download_hg(self, url, filename): +- filename = filename.split('#', 1)[0] +- url, rev = self._vcs_split_rev_from_url(url, pop_prefix=True) ++ resolved = parts._replace( ++ scheme=clean_scheme, ++ path=clean_path, ++ # discard the fragment ++ fragment='', ++ ).geturl() + +- self.info("Doing hg clone from %s to %s", url, filename) +- os.system("hg clone --quiet %s %s" % (url, filename)) +- +- if rev is not None: +- self.info("Updating to %s", rev) +- os.system( +- "hg --cwd %s up -C -r %s -q" +- % ( +- filename, +- rev, +- ) +- ) +- +- return filename ++ return resolved, rev + + def debug(self, msg, *args): + log.debug(msg, *args) +diff --git a/setuptools/tests/test_packageindex.py b/setuptools/tests/test_packageindex.py +index 41b9661..e4cd91a 100644 +--- a/setuptools/tests/test_packageindex.py ++++ b/setuptools/tests/test_packageindex.py +@@ -2,7 +2,6 @@ import distutils.errors + import urllib.request + import urllib.error + import http.client +-from unittest import mock + + import pytest + +@@ -171,49 +170,46 @@ class TestPackageIndex: + assert dists[0].version == '' + assert dists[1].version == vc + +- def test_download_git_with_rev(self, tmpdir): ++ def test_download_git_with_rev(self, tmp_path, fp): + url = 'git+https://github.example/group/project@master#egg=foo' + index = setuptools.package_index.PackageIndex() + +- with mock.patch("os.system") as os_system_mock: +- result = index.download(url, str(tmpdir)) ++ expected_dir = tmp_path / 'project@master' ++ fp.register([ ++ 'git', ++ 'clone', ++ '--quiet', ++ 'https://github.example/group/project', ++ expected_dir, ++ ]) ++ fp.register(['git', '-C', expected_dir, 'checkout', '--quiet', 'master']) + +- os_system_mock.assert_called() ++ result = index.download(url, tmp_path) + +- expected_dir = str(tmpdir / 'project@master') +- expected = ( +- 'git clone --quiet ' 'https://github.example/group/project {expected_dir}' +- ).format(**locals()) +- first_call_args = os_system_mock.call_args_list[0][0] +- assert first_call_args == (expected,) ++ assert result == str(expected_dir) ++ assert len(fp.calls) == 2 + +- tmpl = 'git -C {expected_dir} checkout --quiet master' +- expected = tmpl.format(**locals()) +- assert os_system_mock.call_args_list[1][0] == (expected,) +- assert result == expected_dir +- +- def test_download_git_no_rev(self, tmpdir): ++ def test_download_git_no_rev(self, tmp_path, fp): + url = 'git+https://github.example/group/project#egg=foo' + index = setuptools.package_index.PackageIndex() + +- with mock.patch("os.system") as os_system_mock: +- result = index.download(url, str(tmpdir)) +- +- os_system_mock.assert_called() +- +- expected_dir = str(tmpdir / 'project') +- expected = ( +- 'git clone --quiet ' 'https://github.example/group/project {expected_dir}' +- ).format(**locals()) +- os_system_mock.assert_called_once_with(expected) +- +- def test_download_svn(self, tmpdir): ++ expected_dir = tmp_path / 'project' ++ fp.register([ ++ 'git', ++ 'clone', ++ '--quiet', ++ 'https://github.example/group/project', ++ expected_dir, ++ ]) ++ index.download(url, tmp_path) ++ ++ def test_download_svn(self, tmp_path): + url = 'svn+https://svn.example/project#egg=foo' + index = setuptools.package_index.PackageIndex() + + msg = r".*SVN download is not supported.*" + with pytest.raises(distutils.errors.DistutilsError, match=msg): +- index.download(url, str(tmpdir)) ++ index.download(url, tmp_path) + + + class TestContentCheckers: +-- +2.40.0 + diff --git a/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2025-47273-pre1.patch b/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2025-47273-pre1.patch new file mode 100644 index 0000000000..72bcaea435 --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2025-47273-pre1.patch @@ -0,0 +1,54 @@ +From d8390feaa99091d1ba9626bec0e4ba7072fc507a Mon Sep 17 00:00:00 2001 +From: "Jason R. Coombs" <jaraco@jaraco.com> +Date: Sat, 19 Apr 2025 12:49:55 -0400 +Subject: [PATCH] Extract _resolve_download_filename with test. + +Upstream-Status: Backport [https://github.com/pypa/setuptools/commit/d8390feaa99091d1ba9626bec0e4ba7072fc507a] +CVE: CVE-2025-47273 #Dependency Patch +Signed-off-by: Vijay Anusuri <vanusuri@mvista.com> +--- + setuptools/package_index.py | 20 ++++++++++++++++---- + 1 file changed, 16 insertions(+), 4 deletions(-) + +diff --git a/setuptools/package_index.py b/setuptools/package_index.py +index 00a972d..d460fcb 100644 +--- a/setuptools/package_index.py ++++ b/setuptools/package_index.py +@@ -815,9 +815,16 @@ class PackageIndex(Environment): + else: + raise DistutilsError("Download error for %s: %s" % (url, v)) from v + +- def _download_url(self, url, tmpdir): +- # Determine download filename +- # ++ @staticmethod ++ def _resolve_download_filename(url, tmpdir): ++ """ ++ >>> du = PackageIndex._resolve_download_filename ++ >>> root = getfixture('tmp_path') ++ >>> url = 'https://files.pythonhosted.org/packages/a9/5a/0db.../setuptools-78.1.0.tar.gz' ++ >>> import pathlib ++ >>> str(pathlib.Path(du(url, root)).relative_to(root)) ++ 'setuptools-78.1.0.tar.gz' ++ """ + name, fragment = egg_info_for_url(url) + if name: + while '..' in name: +@@ -828,8 +835,13 @@ class PackageIndex(Environment): + if name.endswith('.egg.zip'): + name = name[:-4] # strip the extra .zip before download + +- filename = os.path.join(tmpdir, name) ++ return os.path.join(tmpdir, name) + ++ def _download_url(self, url, tmpdir): ++ """ ++ Determine the download filename. ++ """ ++ filename = self._resolve_download_filename(url, tmpdir) + return self._download_vcs(url, filename) or self._download_other(url, filename) + + @staticmethod +-- +2.25.1 + diff --git a/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2025-47273.patch b/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2025-47273.patch new file mode 100644 index 0000000000..be6617e0f6 --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3-setuptools/CVE-2025-47273.patch @@ -0,0 +1,59 @@ +From 250a6d17978f9f6ac3ac887091f2d32886fbbb0b Mon Sep 17 00:00:00 2001 +From: "Jason R. Coombs" <jaraco@jaraco.com> +Date: Sat, 19 Apr 2025 13:03:47 -0400 +Subject: [PATCH] Add a check to ensure the name resolves relative to the + tmpdir. + +Closes #4946 + +Upstream-Status: Backport [https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b] +CVE: CVE-2025-47273 +Signed-off-by: Vijay Anusuri <vanusuri@mvista.com> +--- + setuptools/package_index.py | 18 ++++++++++++++++-- + 1 file changed, 16 insertions(+), 2 deletions(-) + +diff --git a/setuptools/package_index.py b/setuptools/package_index.py +index d460fcb..6c7874d 100644 +--- a/setuptools/package_index.py ++++ b/setuptools/package_index.py +@@ -818,12 +818,20 @@ class PackageIndex(Environment): + @staticmethod + def _resolve_download_filename(url, tmpdir): + """ ++ >>> import pathlib + >>> du = PackageIndex._resolve_download_filename + >>> root = getfixture('tmp_path') + >>> url = 'https://files.pythonhosted.org/packages/a9/5a/0db.../setuptools-78.1.0.tar.gz' +- >>> import pathlib + >>> str(pathlib.Path(du(url, root)).relative_to(root)) + 'setuptools-78.1.0.tar.gz' ++ ++ Ensures the target is always in tmpdir. ++ ++ >>> url = 'https://anyhost/%2fhome%2fuser%2f.ssh%2fauthorized_keys' ++ >>> du(url, root) ++ Traceback (most recent call last): ++ ... ++ ValueError: Invalid filename... + """ + name, fragment = egg_info_for_url(url) + if name: +@@ -835,7 +843,13 @@ class PackageIndex(Environment): + if name.endswith('.egg.zip'): + name = name[:-4] # strip the extra .zip before download + +- return os.path.join(tmpdir, name) ++ filename = os.path.join(tmpdir, name) ++ ++ # ensure path resolves within the tmpdir ++ if not filename.startswith(str(tmpdir)): ++ raise ValueError(f"Invalid filename {filename}") ++ ++ return filename + + def _download_url(self, url, tmpdir): + """ +-- +2.25.1 + diff --git a/poky/meta/recipes-devtools/python/python3-setuptools_69.1.1.bb b/poky/meta/recipes-devtools/python/python3-setuptools_69.1.1.bb index 67475b68eb..46b2f0ab00 100644 --- a/poky/meta/recipes-devtools/python/python3-setuptools_69.1.1.bb +++ b/poky/meta/recipes-devtools/python/python3-setuptools_69.1.1.bb @@ -6,10 +6,16 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=141643e11c48898150daa83802dbc65f" inherit pypi python_setuptools_build_meta +CVE_PRODUCT = "python3-setuptools python:setuptools" + SRC_URI:append:class-native = " file://0001-conditionally-do-not-fetch-code-by-easy_install.patch" SRC_URI += " \ - file://0001-_distutils-sysconfig.py-make-it-possible-to-substite.patch" + file://0001-_distutils-sysconfig.py-make-it-possible-to-substite.patch \ + file://CVE-2024-6345.patch \ + file://CVE-2025-47273-pre1.patch \ + file://CVE-2025-47273.patch \ +" SRC_URI[sha256sum] = "5c0806c7d9af348e6dd3777b4f4dbb42c7ad85b190104837488eab9a7c945cf8" diff --git a/poky/meta/recipes-devtools/python/python3-urllib3/CVE-2025-50181.patch b/poky/meta/recipes-devtools/python/python3-urllib3/CVE-2025-50181.patch new file mode 100644 index 0000000000..d4f6e98cc1 --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3-urllib3/CVE-2025-50181.patch @@ -0,0 +1,283 @@ +From f05b1329126d5be6de501f9d1e3e36738bc08857 Mon Sep 17 00:00:00 2001 +From: Illia Volochii <illia.volochii@gmail.com> +Date: Wed, 18 Jun 2025 16:25:01 +0300 +Subject: [PATCH] Merge commit from fork + +* Apply Quentin's suggestion + +Co-authored-by: Quentin Pradet <quentin.pradet@gmail.com> + +* Add tests for disabled redirects in the pool manager + +* Add a possible fix for the issue with not raised `MaxRetryError` + +* Make urllib3 handle redirects instead of JS when JSPI is used + +* Fix info in the new comment + +* State that redirects with XHR are not controlled by urllib3 + +* Remove excessive params from new test requests + +* Add tests reaching max non-0 redirects + +* Test redirects with Emscripten + +* Fix `test_merge_pool_kwargs` + +* Add a changelog entry + +* Parametrize tests + +* Drop a fix for Emscripten + +* Apply Seth's suggestion to docs + +Co-authored-by: Seth Michael Larson <sethmichaellarson@gmail.com> + +* Use a minor release instead of the patch one + +--------- + +Co-authored-by: Quentin Pradet <quentin.pradet@gmail.com> +Co-authored-by: Seth Michael Larson <sethmichaellarson@gmail.com> + +CVE: CVE-2025-50181 +Upstream-Status: Backport [https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857] + +Signed-off-by: Yogita Urade <yogita.urade@windriver.com> +--- + docs/reference/contrib/emscripten.rst | 2 +- + dummyserver/app.py | 1 + + src/urllib3/poolmanager.py | 18 +++- + test/contrib/emscripten/test_emscripten.py | 16 ++++ + test/test_poolmanager.py | 5 +- + test/with_dummyserver/test_poolmanager.py | 101 +++++++++++++++++++++ + 6 files changed, 139 insertions(+), 4 deletions(-) + +diff --git a/docs/reference/contrib/emscripten.rst b/docs/reference/contrib/emscripten.rst +index 9e85629..c88e422 100644 +--- a/docs/reference/contrib/emscripten.rst ++++ b/docs/reference/contrib/emscripten.rst +@@ -68,7 +68,7 @@ Features which are usable with Emscripten support are: + * Timeouts + * Retries + * Streaming (with Web Workers and Cross-Origin Isolation) +-* Redirects ++* Redirects (determined by browser/runtime, not restrictable with urllib3) + * Decompressing response bodies + + Features which don't work with Emscripten: +diff --git a/dummyserver/app.py b/dummyserver/app.py +index 9fc9d1b..96e0dab 100644 +--- a/dummyserver/app.py ++++ b/dummyserver/app.py +@@ -228,6 +228,7 @@ async def encodingrequest() -> ResponseReturnValue: + + + @hypercorn_app.route("/redirect", methods=["GET", "POST", "PUT"]) ++@pyodide_testing_app.route("/redirect", methods=["GET", "POST", "PUT"]) + async def redirect() -> ResponseReturnValue: + "Perform a redirect to ``target``" + values = await request.values +diff --git a/src/urllib3/poolmanager.py b/src/urllib3/poolmanager.py +index 085d1db..5763fea 100644 +--- a/src/urllib3/poolmanager.py ++++ b/src/urllib3/poolmanager.py +@@ -203,6 +203,22 @@ class PoolManager(RequestMethods): + **connection_pool_kw: typing.Any, + ) -> None: + super().__init__(headers) ++ if "retries" in connection_pool_kw: ++ retries = connection_pool_kw["retries"] ++ if not isinstance(retries, Retry): ++ # When Retry is initialized, raise_on_redirect is based ++ # on a redirect boolean value. ++ # But requests made via a pool manager always set ++ # redirect to False, and raise_on_redirect always ends ++ # up being False consequently. ++ # Here we fix the issue by setting raise_on_redirect to ++ # a value needed by the pool manager without considering ++ # the redirect boolean. ++ raise_on_redirect = retries is not False ++ retries = Retry.from_int(retries, redirect=False) ++ retries.raise_on_redirect = raise_on_redirect ++ connection_pool_kw = connection_pool_kw.copy() ++ connection_pool_kw["retries"] = retries + self.connection_pool_kw = connection_pool_kw + + self.pools: RecentlyUsedContainer[PoolKey, HTTPConnectionPool] +@@ -456,7 +472,7 @@ class PoolManager(RequestMethods): + kw["body"] = None + kw["headers"] = HTTPHeaderDict(kw["headers"])._prepare_for_method_change() + +- retries = kw.get("retries") ++ retries = kw.get("retries", response.retries) + if not isinstance(retries, Retry): + retries = Retry.from_int(retries, redirect=redirect) + +diff --git a/test/contrib/emscripten/test_emscripten.py b/test/contrib/emscripten/test_emscripten.py +index 17264d8..0e107fa 100644 +--- a/test/contrib/emscripten/test_emscripten.py ++++ b/test/contrib/emscripten/test_emscripten.py +@@ -949,6 +949,22 @@ def test_retries( + pyodide_test(selenium_coverage, testserver_http.http_host, find_unused_port()) + + ++def test_redirects( ++ selenium_coverage: typing.Any, testserver_http: PyodideServerInfo ++) -> None: ++ @run_in_pyodide # type: ignore[misc] ++ def pyodide_test(selenium_coverage: typing.Any, host: str, port: int) -> None: ++ from urllib3 import request ++ ++ redirect_url = f"http://{host}:{port}/redirect" ++ response = request("GET", redirect_url) ++ assert response.status == 200 ++ ++ pyodide_test( ++ selenium_coverage, testserver_http.http_host, testserver_http.http_port ++ ) ++ ++ + @install_urllib3_wheel() + def test_insecure_requests_warning( + selenium_coverage: typing.Any, testserver_http: PyodideServerInfo +diff --git a/test/test_poolmanager.py b/test/test_poolmanager.py +index ab5f203..b481a19 100644 +--- a/test/test_poolmanager.py ++++ b/test/test_poolmanager.py +@@ -379,9 +379,10 @@ class TestPoolManager: + + def test_merge_pool_kwargs(self) -> None: + """Assert _merge_pool_kwargs works in the happy case""" +- p = PoolManager(retries=100) ++ retries = retry.Retry(total=100) ++ p = PoolManager(retries=retries) + merged = p._merge_pool_kwargs({"new_key": "value"}) +- assert {"retries": 100, "new_key": "value"} == merged ++ assert {"retries": retries, "new_key": "value"} == merged + + def test_merge_pool_kwargs_none(self) -> None: + """Assert false-y values to _merge_pool_kwargs result in defaults""" +diff --git a/test/with_dummyserver/test_poolmanager.py b/test/with_dummyserver/test_poolmanager.py +index af77241..7f163ab 100644 +--- a/test/with_dummyserver/test_poolmanager.py ++++ b/test/with_dummyserver/test_poolmanager.py +@@ -84,6 +84,89 @@ class TestPoolManager(HypercornDummyServerTestCase): + assert r.status == 200 + assert r.data == b"Dummy server!" + ++ @pytest.mark.parametrize( ++ "retries", ++ (0, Retry(total=0), Retry(redirect=0), Retry(total=0, redirect=0)), ++ ) ++ def test_redirects_disabled_for_pool_manager_with_0( ++ self, retries: typing.Literal[0] | Retry ++ ) -> None: ++ """ ++ Check handling redirects when retries is set to 0 on the pool ++ manager. ++ """ ++ with PoolManager(retries=retries) as http: ++ with pytest.raises(MaxRetryError): ++ http.request("GET", f"{self.base_url}/redirect") ++ ++ # Setting redirect=True should not change the behavior. ++ with pytest.raises(MaxRetryError): ++ http.request("GET", f"{self.base_url}/redirect", redirect=True) ++ ++ # Setting redirect=False should not make it follow the redirect, ++ # but MaxRetryError should not be raised. ++ response = http.request("GET", f"{self.base_url}/redirect", redirect=False) ++ assert response.status == 303 ++ ++ @pytest.mark.parametrize( ++ "retries", ++ ( ++ False, ++ Retry(total=False), ++ Retry(redirect=False), ++ Retry(total=False, redirect=False), ++ ), ++ ) ++ def test_redirects_disabled_for_pool_manager_with_false( ++ self, retries: typing.Literal[False] | Retry ++ ) -> None: ++ """ ++ Check that setting retries set to False on the pool manager disables ++ raising MaxRetryError and redirect=True does not change the ++ behavior. ++ """ ++ with PoolManager(retries=retries) as http: ++ response = http.request("GET", f"{self.base_url}/redirect") ++ assert response.status == 303 ++ ++ response = http.request("GET", f"{self.base_url}/redirect", redirect=True) ++ assert response.status == 303 ++ ++ response = http.request("GET", f"{self.base_url}/redirect", redirect=False) ++ assert response.status == 303 ++ ++ def test_redirects_disabled_for_individual_request(self) -> None: ++ """ ++ Check handling redirects when they are meant to be disabled ++ on the request level. ++ """ ++ with PoolManager() as http: ++ # Check when redirect is not passed. ++ with pytest.raises(MaxRetryError): ++ http.request("GET", f"{self.base_url}/redirect", retries=0) ++ response = http.request("GET", f"{self.base_url}/redirect", retries=False) ++ assert response.status == 303 ++ ++ # Check when redirect=True. ++ with pytest.raises(MaxRetryError): ++ http.request( ++ "GET", f"{self.base_url}/redirect", retries=0, redirect=True ++ ) ++ response = http.request( ++ "GET", f"{self.base_url}/redirect", retries=False, redirect=True ++ ) ++ assert response.status == 303 ++ ++ # Check when redirect=False. ++ response = http.request( ++ "GET", f"{self.base_url}/redirect", retries=0, redirect=False ++ ) ++ assert response.status == 303 ++ response = http.request( ++ "GET", f"{self.base_url}/redirect", retries=False, redirect=False ++ ) ++ assert response.status == 303 ++ + def test_cross_host_redirect(self) -> None: + with PoolManager() as http: + cross_host_location = f"{self.base_url_alt}/echo?a=b" +@@ -138,6 +221,24 @@ class TestPoolManager(HypercornDummyServerTestCase): + pool = http.connection_from_host(self.host, self.port) + assert pool.num_connections == 1 + ++ # Check when retries are configured for the pool manager. ++ with PoolManager(retries=1) as http: ++ with pytest.raises(MaxRetryError): ++ http.request( ++ "GET", ++ f"{self.base_url}/redirect", ++ fields={"target": f"/redirect?target={self.base_url}/"}, ++ ) ++ ++ # Here we allow more retries for the request. ++ response = http.request( ++ "GET", ++ f"{self.base_url}/redirect", ++ fields={"target": f"/redirect?target={self.base_url}/"}, ++ retries=2, ++ ) ++ assert response.status == 200 ++ + def test_redirect_cross_host_remove_headers(self) -> None: + with PoolManager() as http: + r = http.request( +-- +2.40.0 diff --git a/poky/meta/recipes-devtools/python/python3-urllib3_2.2.1.bb b/poky/meta/recipes-devtools/python/python3-urllib3_2.2.2.bb index fc1828b4ee..bdb1c7ca8d 100644 --- a/poky/meta/recipes-devtools/python/python3-urllib3_2.2.1.bb +++ b/poky/meta/recipes-devtools/python/python3-urllib3_2.2.2.bb @@ -3,10 +3,14 @@ HOMEPAGE = "https://github.com/shazow/urllib3" LICENSE = "MIT" LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=52d273a3054ced561275d4d15260ecda" -SRC_URI[sha256sum] = "d0570876c61ab9e520d776c38acbbb5b05a776d3f9ff98a5c8fd5162a444cf19" +SRC_URI[sha256sum] = "dd505485549a7a552833da5e6063639d0d177c04f23bc3864e41e5dc5f612168" inherit pypi python_hatchling +SRC_URI += " \ + file://CVE-2025-50181.patch \ +" + RDEPENDS:${PN} += "\ python3-certifi \ python3-cryptography \ diff --git a/poky/meta/recipes-devtools/python/python3-xmltodict/CVE-2025-9375-1.patch b/poky/meta/recipes-devtools/python/python3-xmltodict/CVE-2025-9375-1.patch new file mode 100644 index 0000000000..e8977dd2ea --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3-xmltodict/CVE-2025-9375-1.patch @@ -0,0 +1,111 @@ +From ecd456ab88d379514b116ef9293318b74e5ed3ee Mon Sep 17 00:00:00 2001 +From: Martin Blech <78768+martinblech@users.noreply.github.com> +Date: Thu, 4 Sep 2025 17:25:39 -0700 +Subject: [PATCH] Prevent XML injection: reject '<'/'>' in element/attr names + (incl. @xmlns) + +* Add tests for tag names, attribute names, and @xmlns prefixes; confirm attr values are escaped. + +CVE: CVE-2025-9375 + +Upstream-Status: Backport +https://github.com/martinblech/xmltodict/commit/ecd456ab88d379514b116ef9293318b74e5ed3ee +https://git.launchpad.net/ubuntu/+source/python-xmltodict/commit/?id=e8110a20e00d80db31d5fc9f8f4577328385d6b6 + +Signed-off-by: Saravanan <saravanan.kadambathursubramaniyam@windriver.com> + +--- + tests/test_dicttoxml.py | 32 ++++++++++++++++++++++++++++++++ + xmltodict.py | 20 +++++++++++++++++++- + 2 files changed, 51 insertions(+), 1 deletion(-) + +Index: python-xmltodict-0.13.0/tests/test_dicttoxml.py +=================================================================== +--- python-xmltodict-0.13.0.orig/tests/test_dicttoxml.py ++++ python-xmltodict-0.13.0/tests/test_dicttoxml.py +@@ -213,3 +213,35 @@ xmlns:b="http://b.com/"><x a:attr="val"> + expected_xml = '<?xml version="1.0" encoding="utf-8"?>\n<x>false</x>' + xml = unparse(dict(x=False)) + self.assertEqual(xml, expected_xml) ++ ++ def test_rejects_tag_name_with_angle_brackets(self): ++ # Minimal guard: disallow '<' or '>' to prevent breaking tag context ++ with self.assertRaises(ValueError): ++ unparse({"m><tag>content</tag": "unsafe"}, full_document=False) ++ ++ def test_rejects_attribute_name_with_angle_brackets(self): ++ # Now we expect bad attribute names to be rejected ++ with self.assertRaises(ValueError): ++ unparse( ++ {"a": {"@m><tag>content</tag": "unsafe", "#text": "x"}}, ++ full_document=False, ++ ) ++ ++ def test_rejects_malicious_xmlns_prefix(self): ++ # xmlns prefixes go under @xmlns mapping; reject angle brackets in prefix ++ with self.assertRaises(ValueError): ++ unparse( ++ { ++ "a": { ++ "@xmlns": {"m><bad": "http://example.com/"}, ++ "#text": "x", ++ } ++ }, ++ full_document=False, ++ ) ++ ++ def test_attribute_values_with_angle_brackets_are_escaped(self): ++ # Attribute values should be escaped by XMLGenerator ++ xml = unparse({"a": {"@attr": "1<middle>2", "#text": "x"}}, full_document=False) ++ # The generated XML should contain escaped '<' and '>' within the attribute value ++ self.assertIn('attr="1<middle>2"', xml) +Index: python-xmltodict-0.13.0/xmltodict.py +=================================================================== +--- python-xmltodict-0.13.0.orig/xmltodict.py ++++ python-xmltodict-0.13.0/xmltodict.py +@@ -379,6 +379,14 @@ def parse(xml_input, encoding=None, expa + return handler.item + + ++def _has_angle_brackets(value): ++ """Return True if value (a str) contains '<' or '>'. ++ ++ Non-string values return False. Uses fast substring checks implemented in C. ++ """ ++ return isinstance(value, str) and ("<" in value or ">" in value) ++ ++ + def _process_namespace(name, namespaces, ns_sep=':', attr_prefix='@'): + if not namespaces: + return name +@@ -412,6 +420,9 @@ def _emit(key, value, content_handler, + if result is None: + return + key, value = result ++ # Minimal validation to avoid breaking out of tag context ++ if _has_angle_brackets(key): ++ raise ValueError('Invalid element name: "<" or ">" not allowed') + if (not hasattr(value, '__iter__') + or isinstance(value, _basestring) + or isinstance(value, dict)): +@@ -445,12 +456,19 @@ def _emit(key, value, content_handler, + attr_prefix) + if ik == '@xmlns' and isinstance(iv, dict): + for k, v in iv.items(): ++ if _has_angle_brackets(k): ++ raise ValueError( ++ 'Invalid attribute name: "<" or ">" not allowed' ++ ) + attr = 'xmlns{}'.format(':{}'.format(k) if k else '') + attrs[attr] = _unicode(v) + continue + if not isinstance(iv, _unicode): + iv = _unicode(iv) +- attrs[ik[len(attr_prefix):]] = iv ++ attr_name = ik[len(attr_prefix) :] ++ if _has_angle_brackets(attr_name): ++ raise ValueError('Invalid attribute name: "<" or ">" not allowed') ++ attrs[attr_name] = iv + continue + children.append((ik, iv)) + if pretty: diff --git a/poky/meta/recipes-devtools/python/python3-xmltodict/CVE-2025-9375-2.patch b/poky/meta/recipes-devtools/python/python3-xmltodict/CVE-2025-9375-2.patch new file mode 100644 index 0000000000..1be22cff6e --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3-xmltodict/CVE-2025-9375-2.patch @@ -0,0 +1,176 @@ +From f98c90f071228ed73df997807298e1df4f790c33 Mon Sep 17 00:00:00 2001 +From: Martin Blech <78768+martinblech@users.noreply.github.com> +Date: Mon, 8 Sep 2025 11:18:33 -0700 +Subject: [PATCH] Enhance unparse() XML name validation with stricter rules and + tests + +Extend existing validation (previously only for "<" and ">") to also +reject element, attribute, and xmlns prefix names that are non-string, +start with "?" or "!", or contain "/", spaces, tabs, or newlines. +Update _emit and namespace handling to use _validate_name. Add tests +covering these new invalid name cases. + +CVE: CVE-2025-9375 + +Upstream-Status: Backport +https://github.com/martinblech/xmltodict/commit/f98c90f071228ed73df997807298e1df4f790c33 +https://git.launchpad.net/ubuntu/+source/python-xmltodict/commit/?id=e8110a20e00d80db31d5fc9f8f4577328385d6b6 + +Signed-off-by: Saravanan <saravanan.kadambathursubramaniyam@windriver.com +--- + tests/test_dicttoxml.py | 60 +++++++++++++++++++++++++++++++++++++++++ + xmltodict.py | 48 ++++++++++++++++++++++++++------- + 2 files changed, 99 insertions(+), 9 deletions(-) + +Index: python-xmltodict-0.13.0/tests/test_dicttoxml.py +=================================================================== +--- python-xmltodict-0.13.0.orig/tests/test_dicttoxml.py ++++ python-xmltodict-0.13.0/tests/test_dicttoxml.py +@@ -245,3 +245,63 @@ xmlns:b="http://b.com/"><x a:attr="val"> + xml = unparse({"a": {"@attr": "1<middle>2", "#text": "x"}}, full_document=False) + # The generated XML should contain escaped '<' and '>' within the attribute value + self.assertIn('attr="1<middle>2"', xml) ++ ++ def test_rejects_tag_name_starting_with_question(self): ++ with self.assertRaises(ValueError): ++ unparse({"?pi": "data"}, full_document=False) ++ ++ def test_rejects_tag_name_starting_with_bang(self): ++ with self.assertRaises(ValueError): ++ unparse({"!decl": "data"}, full_document=False) ++ ++ def test_rejects_attribute_name_starting_with_question(self): ++ with self.assertRaises(ValueError): ++ unparse({"a": {"@?weird": "x"}}, full_document=False) ++ ++ def test_rejects_attribute_name_starting_with_bang(self): ++ with self.assertRaises(ValueError): ++ unparse({"a": {"@!weird": "x"}}, full_document=False) ++ ++ def test_rejects_xmlns_prefix_starting_with_question_or_bang(self): ++ with self.assertRaises(ValueError): ++ unparse({"a": {"@xmlns": {"?p": "http://e/"}}}, full_document=False) ++ with self.assertRaises(ValueError): ++ unparse({"a": {"@xmlns": {"!p": "http://e/"}}}, full_document=False) ++ ++ def test_rejects_non_string_names(self): ++ class Weird: ++ def __str__(self): ++ return "bad>name" ++ ++ # Non-string element key ++ with self.assertRaises(ValueError): ++ unparse({Weird(): "x"}, full_document=False) ++ # Non-string attribute key ++ with self.assertRaises(ValueError): ++ unparse({"a": {Weird(): "x"}}, full_document=False) ++ ++ def test_rejects_tag_name_with_slash(self): ++ with self.assertRaises(ValueError): ++ unparse({"bad/name": "x"}, full_document=False) ++ ++ def test_rejects_tag_name_with_whitespace(self): ++ for name in ["bad name", "bad\tname", "bad\nname"]: ++ with self.assertRaises(ValueError): ++ unparse({name: "x"}, full_document=False) ++ ++ def test_rejects_attribute_name_with_slash(self): ++ with self.assertRaises(ValueError): ++ unparse({"a": {"@bad/name": "x"}}, full_document=False) ++ ++ def test_rejects_attribute_name_with_whitespace(self): ++ for name in ["@bad name", "@bad\tname", "@bad\nname"]: ++ with self.assertRaises(ValueError): ++ unparse({"a": {name: "x"}}, full_document=False) ++ ++ def test_rejects_xmlns_prefix_with_slash_or_whitespace(self): ++ # Slash ++ with self.assertRaises(ValueError): ++ unparse({"a": {"@xmlns": {"bad/prefix": "http://e/"}}}, full_document=False) ++ # Whitespace ++ with self.assertRaises(ValueError): ++ unparse({"a": {"@xmlns": {"bad prefix": "http://e/"}}}, full_document=False) +Index: python-xmltodict-0.13.0/xmltodict.py +=================================================================== +--- python-xmltodict-0.13.0.orig/xmltodict.py ++++ python-xmltodict-0.13.0/xmltodict.py +@@ -387,7 +387,42 @@ def _has_angle_brackets(value): + return isinstance(value, str) and ("<" in value or ">" in value) + + ++def _has_invalid_name_chars(value): ++ """Return True if value (a str) contains any disallowed name characters. ++ ++ Disallowed: '<', '>', '/', or any whitespace character. ++ Non-string values return False. ++ """ ++ if not isinstance(value, str): ++ return False ++ if "<" in value or ">" in value or "/" in value: ++ return True ++ # Check for any whitespace (spaces, tabs, newlines, etc.) ++ return any(ch.isspace() for ch in value) ++ ++ ++def _validate_name(value, kind): ++ """Validate an element/attribute name for XML safety. ++ ++ Raises ValueError with a specific reason when invalid. ++ ++ kind: 'element' or 'attribute' (used in error messages) ++ """ ++ if not isinstance(value, str): ++ raise ValueError(f"{kind} name must be a string") ++ if value.startswith("?") or value.startswith("!"): ++ raise ValueError(f'Invalid {kind} name: cannot start with "?" or "!"') ++ if "<" in value or ">" in value: ++ raise ValueError(f'Invalid {kind} name: "<" or ">" not allowed') ++ if "/" in value: ++ raise ValueError(f'Invalid {kind} name: "/" not allowed') ++ if any(ch.isspace() for ch in value): ++ raise ValueError(f"Invalid {kind} name: whitespace not allowed") ++ ++ + def _process_namespace(name, namespaces, ns_sep=':', attr_prefix='@'): ++ if not isinstance(name, str): ++ return name + if not namespaces: + return name + try: +@@ -421,8 +456,7 @@ def _emit(key, value, content_handler, + return + key, value = result + # Minimal validation to avoid breaking out of tag context +- if _has_angle_brackets(key): +- raise ValueError('Invalid element name: "<" or ">" not allowed') ++ _validate_name(key, "element") + if (not hasattr(value, '__iter__') + or isinstance(value, _basestring) + or isinstance(value, dict)): +@@ -451,23 +485,19 @@ def _emit(key, value, content_handler, + if ik == cdata_key: + cdata = iv + continue +- if ik.startswith(attr_prefix): ++ if isinstance(ik, str) and ik.startswith(attr_prefix): + ik = _process_namespace(ik, namespaces, namespace_separator, + attr_prefix) + if ik == '@xmlns' and isinstance(iv, dict): + for k, v in iv.items(): +- if _has_angle_brackets(k): +- raise ValueError( +- 'Invalid attribute name: "<" or ">" not allowed' +- ) ++ _validate_name(k, "attribute") + attr = 'xmlns{}'.format(':{}'.format(k) if k else '') + attrs[attr] = _unicode(v) + continue + if not isinstance(iv, _unicode): + iv = _unicode(iv) + attr_name = ik[len(attr_prefix) :] +- if _has_angle_brackets(attr_name): +- raise ValueError('Invalid attribute name: "<" or ">" not allowed') ++ _validate_name(attr_name, "attribute") + attrs[attr_name] = iv + continue + children.append((ik, iv)) diff --git a/poky/meta/recipes-devtools/python/python3-xmltodict_0.13.0.bb b/poky/meta/recipes-devtools/python/python3-xmltodict_0.13.0.bb index e8e275647c..9a308a29d2 100644 --- a/poky/meta/recipes-devtools/python/python3-xmltodict_0.13.0.bb +++ b/poky/meta/recipes-devtools/python/python3-xmltodict_0.13.0.bb @@ -13,6 +13,8 @@ inherit pypi setuptools3 ptest SRC_URI += " \ file://run-ptest \ + file://CVE-2025-9375-1.patch \ + file://CVE-2025-9375-2.patch \ " RDEPENDS:${PN} += " \ diff --git a/poky/meta/recipes-devtools/python/python3-zipp/CVE-2024-5569.patch b/poky/meta/recipes-devtools/python/python3-zipp/CVE-2024-5569.patch new file mode 100644 index 0000000000..1cc43243bf --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3-zipp/CVE-2024-5569.patch @@ -0,0 +1,138 @@ +From b1804347ec2db16452a7bff2b469d2c66776b904 Mon Sep 17 00:00:00 2001 +From: "Jason R. Coombs" <jaraco@jaraco.com> +Date: Fri, 31 May 2024 11:20:57 -0400 +Subject: [PATCH] fix CVE-2024-5569 + +The patch includes the following changes: +c18417e Add news fragment. +58115d2 Employ SanitizedNames in CompleteDirs. Fixes broken test. +564fcc1 Add SanitizedNames mixin. +79a309f Add some assertions about malformed paths. + +Upstream-Status: Backport +[https://github.com/jaraco/zipp/pull/120/commits/79a309fe54dc6b7934fb72e9f31bcb58f2e9f547] +[https://github.com/jaraco/zipp/pull/120/commits/564fcc10cdbfdaecdb33688e149827465931c9e0] +[https://github.com/jaraco/zipp/pull/120/commits/58115d2be968644ce71ce6bcc9b79826c82a1806] +[https://github.com/jaraco/zipp/pull/120/commits/c18417ed2953e181728a7dac07bff88a2190abf7] + +CVE: CVE-2024-5569 + +Signed-off-by: Jiaying Song <jiaying.song.cn@windriver.com> +--- + newsfragments/119.bugfix.rst | 1 + + tests/test_path.py | 17 ++++++++++ + zipp/__init__.py | 64 +++++++++++++++++++++++++++++++++++- + 3 files changed, 81 insertions(+), 1 deletion(-) + create mode 100644 newsfragments/119.bugfix.rst + +diff --git a/newsfragments/119.bugfix.rst b/newsfragments/119.bugfix.rst +new file mode 100644 +index 0000000..6c72e2d +--- /dev/null ++++ b/newsfragments/119.bugfix.rst +@@ -0,0 +1 @@ ++Improved handling of malformed zip files. +\ No newline at end of file +diff --git a/tests/test_path.py b/tests/test_path.py +index a77a5de..3752243 100644 +--- a/tests/test_path.py ++++ b/tests/test_path.py +@@ -575,3 +575,20 @@ class TestPath(unittest.TestCase): + zipp.Path(alpharep) + with self.assertRaises(KeyError): + alpharep.getinfo('does-not-exist') ++ ++ def test_malformed_paths(self): ++ """ ++ Path should handle malformed paths. ++ """ ++ data = io.BytesIO() ++ zf = zipfile.ZipFile(data, "w") ++ zf.writestr("/one-slash.txt", b"content") ++ zf.writestr("//two-slash.txt", b"content") ++ zf.writestr("../parent.txt", b"content") ++ zf.filename = '' ++ root = zipfile.Path(zf) ++ assert list(map(str, root.iterdir())) == [ ++ 'one-slash.txt', ++ 'two-slash.txt', ++ 'parent.txt', ++ ] +diff --git a/zipp/__init__.py b/zipp/__init__.py +index becd010..e980e9b 100644 +--- a/zipp/__init__.py ++++ b/zipp/__init__.py +@@ -84,7 +84,69 @@ class InitializedState: + super().__init__(*args, **kwargs) + + +-class CompleteDirs(InitializedState, zipfile.ZipFile): ++class SanitizedNames: ++ """ ++ ZipFile mix-in to ensure names are sanitized. ++ """ ++ ++ def namelist(self): ++ return list(map(self._sanitize, super().namelist())) ++ ++ @staticmethod ++ def _sanitize(name): ++ r""" ++ Ensure a relative path with posix separators and no dot names. ++ ++ Modeled after ++ https://github.com/python/cpython/blob/bcc1be39cb1d04ad9fc0bd1b9193d3972835a57c/Lib/zipfile/__init__.py#L1799-L1813 ++ but provides consistent cross-platform behavior. ++ ++ >>> san = SanitizedNames._sanitize ++ >>> san('/foo/bar') ++ 'foo/bar' ++ >>> san('//foo.txt') ++ 'foo.txt' ++ >>> san('foo/.././bar.txt') ++ 'foo/bar.txt' ++ >>> san('foo../.bar.txt') ++ 'foo../.bar.txt' ++ >>> san('\\foo\\bar.txt') ++ 'foo/bar.txt' ++ >>> san('D:\\foo.txt') ++ 'D/foo.txt' ++ >>> san('\\\\server\\share\\file.txt') ++ 'server/share/file.txt' ++ >>> san('\\\\?\\GLOBALROOT\\Volume3') ++ '?/GLOBALROOT/Volume3' ++ >>> san('\\\\.\\PhysicalDrive1\\root') ++ 'PhysicalDrive1/root' ++ ++ Retain any trailing slash. ++ >>> san('abc/') ++ 'abc/' ++ ++ Raises a ValueError if the result is empty. ++ >>> san('../..') ++ Traceback (most recent call last): ++ ... ++ ValueError: Empty filename ++ """ ++ ++ def allowed(part): ++ return part and part not in {'..', '.'} ++ ++ # Remove the drive letter. ++ # Don't use ntpath.splitdrive, because that also strips UNC paths ++ bare = re.sub('^([A-Z]):', r'\1', name, flags=re.IGNORECASE) ++ clean = bare.replace('\\', '/') ++ parts = clean.split('/') ++ joined = '/'.join(filter(allowed, parts)) ++ if not joined: ++ raise ValueError("Empty filename") ++ return joined + '/' * name.endswith('/') ++ ++ ++class CompleteDirs(InitializedState, SanitizedNames, zipfile.ZipFile): + """ + A ZipFile subclass that ensures that implied directories + are always included in the namelist. +-- +2.25.1 + diff --git a/poky/meta/recipes-devtools/python/python3-zipp_3.17.0.bb b/poky/meta/recipes-devtools/python/python3-zipp_3.17.0.bb index e9e220e315..9f756887b5 100644 --- a/poky/meta/recipes-devtools/python/python3-zipp_3.17.0.bb +++ b/poky/meta/recipes-devtools/python/python3-zipp_3.17.0.bb @@ -3,6 +3,7 @@ HOMEPAGE = "https://github.com/jaraco/zipp" LICENSE = "MIT" LIC_FILES_CHKSUM = "file://LICENSE;md5=141643e11c48898150daa83802dbc65f" +SRC_URI += "file://CVE-2024-5569.patch" SRC_URI[sha256sum] = "84e64a1c28cf7e91ed2078bb8cc8c259cb19b76942096c8d7b84947690cabaf0" DEPENDS += "python3-setuptools-scm-native" diff --git a/poky/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch b/poky/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch index 0d807db39f..a8f98d873e 100644 --- a/poky/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch +++ b/poky/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch @@ -1,4 +1,4 @@ -From 365399f17d35719d828ddd49182dcb401fb7791c Mon Sep 17 00:00:00 2001 +From e8bd4f8ee56cbb12a61c1dcabf35a1835a863132 Mon Sep 17 00:00:00 2001 From: Paulo Neves <ptsneves@gmail.com> Date: Tue, 7 Jun 2022 16:16:41 +0200 Subject: [PATCH] Avoid shebang overflow on python-config.py @@ -16,10 +16,10 @@ Upstream-Status: Denied [distribution] 1 file changed, 2 insertions(+) diff --git a/Makefile.pre.in b/Makefile.pre.in -index 77bf09a..6353c57 100644 +index 2d235d2..1ac2263 100644 --- a/Makefile.pre.in +++ b/Makefile.pre.in -@@ -2339,6 +2339,8 @@ python-config: $(srcdir)/Misc/python-config.in Misc/python-config.sh +@@ -2356,6 +2356,8 @@ python-config: $(srcdir)/Misc/python-config.in Misc/python-config.sh @ # Substitution happens here, as the completely-expanded BINDIR @ # is not available in configure sed -e "s,@EXENAME@,$(EXENAME)," < $(srcdir)/Misc/python-config.in >python-config.py diff --git a/poky/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch b/poky/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch index 026150f0e2..5ca09c6f3c 100644 --- a/poky/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch +++ b/poky/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch @@ -1,4 +1,4 @@ -From f8a664cf1fc73e381d57d6927207286059744837 Mon Sep 17 00:00:00 2001 +From bbfb7fdf01f0502c7bf3d418f3a912ea76c93f24 Mon Sep 17 00:00:00 2001 From: Alexander Kanavin <alex@linutronix.de> Date: Thu, 16 Sep 2021 16:35:37 +0200 Subject: [PATCH] Lib/pty.py: handle stdin I/O errors same way as master I/O @@ -24,7 +24,6 @@ So let's treat both channels the same. Upstream-Status: Submitted [https://github.com/python/cpython/pull/28388] Signed-off-by: Alexander Kanavin <alex@linutronix.de> - --- Lib/pty.py | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/poky/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch b/poky/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch index 680254fab9..c42a56bcb3 100644 --- a/poky/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch +++ b/poky/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch @@ -1,4 +1,4 @@ -From 71c194077bb907bfe423d3f3275f33a6c8ca0e74 Mon Sep 17 00:00:00 2001 +From c739bf214b9dd6060db216b79077806fccb582ae Mon Sep 17 00:00:00 2001 From: Alexander Kanavin <alex@linutronix.de> Date: Fri, 17 Nov 2023 14:26:32 +0100 Subject: [PATCH] Lib/sysconfig.py: use prefix value from build configuration @@ -9,16 +9,15 @@ native python. Upstream-Status: Inappropriate [oe-core cross builds] Signed-off-by: Alexander Kanavin <alex@linutronix.de> - --- Lib/sysconfig.py | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/Lib/sysconfig.py b/Lib/sysconfig.py -index 79c0510..91ebcb6 100644 +index 6258b68..d59ec6e 100644 --- a/Lib/sysconfig.py +++ b/Lib/sysconfig.py -@@ -668,6 +668,11 @@ def _init_config_vars(): +@@ -675,6 +675,11 @@ def _init_config_vars(): _CONFIG_VARS['VPATH'] = sys._vpath if os.name == 'posix': _init_posix(_CONFIG_VARS) diff --git a/poky/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch b/poky/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch index ee33128fa1..b78f619958 100644 --- a/poky/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch +++ b/poky/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch @@ -1,4 +1,4 @@ -From 38278339832a57dbf5fa3ef21accaa03e2c814d7 Mon Sep 17 00:00:00 2001 +From b9081b2e21983f2a828bc40a47ab278ef69f4dfe Mon Sep 17 00:00:00 2001 From: Alexander Kanavin <alex.kanavin@gmail.com> Date: Wed, 30 Jan 2019 12:41:04 +0100 Subject: [PATCH] Makefile.pre: use qemu wrapper when gathering profile data @@ -10,10 +10,10 @@ Signed-off-by: Alexander Kanavin <alex.kanavin@gmail.com> 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/Makefile.pre.in b/Makefile.pre.in -index dd5e69f..381feb0 100644 +index 083f4c7..dce36a5 100644 --- a/Makefile.pre.in +++ b/Makefile.pre.in -@@ -658,8 +658,7 @@ profile-run-stamp: +@@ -660,8 +660,7 @@ profile-run-stamp: # enabled. $(MAKE) profile-gen-stamp # Next, run the profile task to generate the profile information. diff --git a/poky/meta/recipes-devtools/python/python3/0001-Skip-failing-tests-due-to-load-variability-on-YP-AB.patch b/poky/meta/recipes-devtools/python/python3/0001-Skip-failing-tests-due-to-load-variability-on-YP-AB.patch index 197daa71a5..051ec2c635 100644 --- a/poky/meta/recipes-devtools/python/python3/0001-Skip-failing-tests-due-to-load-variability-on-YP-AB.patch +++ b/poky/meta/recipes-devtools/python/python3/0001-Skip-failing-tests-due-to-load-variability-on-YP-AB.patch @@ -1,4 +1,4 @@ -From 3471e3478e0760c42e04f8046cee2367ab5706d2 Mon Sep 17 00:00:00 2001 +From b4014e3d1d9e38b25f2840e65e2acd757f3e5d41 Mon Sep 17 00:00:00 2001 From: Yi Fan Yu <yifan.yu@windriver.com> Date: Thu, 1 Apr 2021 13:08:37 -0700 Subject: [PATCH] Skip failing tests due to load variability on YP AB @@ -23,10 +23,10 @@ Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com> 2 files changed, 5 insertions(+) diff --git a/Lib/test/_test_multiprocessing.py b/Lib/test/_test_multiprocessing.py -index e42c7ab..dff5227 100644 +index 3b4415b..1f94dec 100644 --- a/Lib/test/_test_multiprocessing.py +++ b/Lib/test/_test_multiprocessing.py -@@ -682,6 +682,7 @@ class _TestProcess(BaseTestCase): +@@ -692,6 +692,7 @@ class _TestProcess(BaseTestCase): close_queue(q) @support.requires_resource('walltime') @@ -34,7 +34,7 @@ index e42c7ab..dff5227 100644 def test_many_processes(self): if self.TYPE == 'threads': self.skipTest('test not appropriate for {}'.format(self.TYPE)) -@@ -2066,6 +2067,7 @@ class _TestBarrier(BaseTestCase): +@@ -2223,6 +2224,7 @@ class _TestBarrier(BaseTestCase): except threading.BrokenBarrierError: results.append(True) @@ -42,7 +42,7 @@ index e42c7ab..dff5227 100644 def test_timeout(self): """ Test wait(timeout) -@@ -5024,6 +5026,7 @@ class TestWait(unittest.TestCase): +@@ -5220,6 +5222,7 @@ class TestWait(unittest.TestCase): time.sleep(period) @support.requires_resource('walltime') @@ -51,10 +51,10 @@ index e42c7ab..dff5227 100644 from multiprocessing.connection import wait diff --git a/Lib/test/test_time.py b/Lib/test/test_time.py -index 02cc3f4..51a4548 100644 +index 9463add..4e0f39d 100644 --- a/Lib/test/test_time.py +++ b/Lib/test/test_time.py -@@ -492,6 +492,7 @@ class TimeTestCase(unittest.TestCase): +@@ -536,6 +536,7 @@ class TimeTestCase(unittest.TestCase): @unittest.skipIf( support.is_wasi, "process_time not available on WASI" ) @@ -62,7 +62,7 @@ index 02cc3f4..51a4548 100644 def test_process_time(self): # process_time() should not include time spend during a sleep start = time.process_time() -@@ -505,6 +506,7 @@ class TimeTestCase(unittest.TestCase): +@@ -549,6 +550,7 @@ class TimeTestCase(unittest.TestCase): self.assertTrue(info.monotonic) self.assertFalse(info.adjustable) diff --git a/poky/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch b/poky/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch index b6c6ac5a28..08142617c0 100644 --- a/poky/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch +++ b/poky/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch @@ -1,4 +1,4 @@ -From 37d058e841ba3bd89b5746cc5381afb014b11581 Mon Sep 17 00:00:00 2001 +From 5224cc0ac21f4c2574c24e0fee38b145ca15175b Mon Sep 17 00:00:00 2001 From: Wentao Zhang <wentao.zhang@windriver.com> Date: Mon, 20 Mar 2023 13:39:52 +0800 Subject: [PATCH] Update test_sysconfig for posix_user purelib @@ -17,16 +17,15 @@ Update test_sysconfig.test_user_similar() for the posix_user scheme: Upstream-Status: Inappropriate [oe-core specific] Signed-off-by: Wentao Zhang <wentao.zhang@windriver.com> - --- Lib/test/test_sysconfig.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Lib/test/test_sysconfig.py b/Lib/test/test_sysconfig.py -index b6dbf3d..5672590 100644 +index 3468d0c..9ff174c 100644 --- a/Lib/test/test_sysconfig.py +++ b/Lib/test/test_sysconfig.py -@@ -372,7 +372,7 @@ class TestSysConfig(unittest.TestCase): +@@ -390,7 +390,7 @@ class TestSysConfig(unittest.TestCase): expected = os.path.normpath(global_path.replace(base, user, 1)) # bpo-44860: platlib of posix_user doesn't use sys.platlibdir, # whereas posix_prefix does. diff --git a/poky/meta/recipes-devtools/python/python3/0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch b/poky/meta/recipes-devtools/python/python3/0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch new file mode 100644 index 0000000000..98b3aa42d2 --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3/0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch @@ -0,0 +1,37 @@ +From 6e3868c8c330f997bc242a8d51d742baac449ecc Mon Sep 17 00:00:00 2001 +From: Petr Viktorin <encukou@gmail.com> +Date: Wed, 23 Aug 2023 20:00:07 +0200 +Subject: [PATCH] gh-107811: tarfile: treat overflow in UID/GID as failure to + set it (#108369) + +Upstream-Status: Backport [https://github.com/python/cpython/pull/108369] +Signed-off-by: Khem Raj <raj.khem@gmail.com> +--- + Lib/tarfile.py | 3 ++- + .../Library/2023-08-23-17-34-39.gh-issue-107811.3Fng72.rst | 3 +++ + 2 files changed, 5 insertions(+), 1 deletion(-) + create mode 100644 Misc/NEWS.d/next/Library/2023-08-23-17-34-39.gh-issue-107811.3Fng72.rst + +diff --git a/Lib/tarfile.py b/Lib/tarfile.py +index 0a0f31e..4dfb67d 100755 +--- a/Lib/tarfile.py ++++ b/Lib/tarfile.py +@@ -2688,7 +2688,8 @@ class TarFile(object): + os.lchown(targetpath, u, g) + else: + os.chown(targetpath, u, g) +- except OSError as e: ++ except (OSError, OverflowError) as e: ++ # OverflowError can be raised if an ID doesn't fit in `id_t` + raise ExtractError("could not change owner") from e + + def chmod(self, tarinfo, targetpath): +diff --git a/Misc/NEWS.d/next/Library/2023-08-23-17-34-39.gh-issue-107811.3Fng72.rst b/Misc/NEWS.d/next/Library/2023-08-23-17-34-39.gh-issue-107811.3Fng72.rst +new file mode 100644 +index 0000000..ffca413 +--- /dev/null ++++ b/Misc/NEWS.d/next/Library/2023-08-23-17-34-39.gh-issue-107811.3Fng72.rst +@@ -0,0 +1,3 @@ ++:mod:`tarfile`: extraction of members with overly large UID or GID (e.g. on ++an OS with 32-bit :c:type:`!id_t`) now fails in the same way as failing to ++set the ID. diff --git a/poky/meta/recipes-devtools/python/python3/0001-gh-114492-Initialize-struct-termios-before-calling-t.patch b/poky/meta/recipes-devtools/python/python3/0001-gh-114492-Initialize-struct-termios-before-calling-t.patch deleted file mode 100644 index 8406ef30a2..0000000000 --- a/poky/meta/recipes-devtools/python/python3/0001-gh-114492-Initialize-struct-termios-before-calling-t.patch +++ /dev/null @@ -1,26 +0,0 @@ -From 439aa02f42d6e6715c172076261757fcb89a936a Mon Sep 17 00:00:00 2001 -From: "Miss Islington (bot)" - <31488909+miss-islington@users.noreply.github.com> -Date: Tue, 23 Jan 2024 23:02:02 +0100 -Subject: [PATCH] gh-114492: Initialize struct termios before calling - tcgetattr() (GH-114495) (GH-114502) - -On Alpine Linux it could leave some field non-initialized. -(cherry picked from commit d22c066b802592932f9eb18434782299e80ca42e) - -Upstream-Status: Backport [https://github.com/python/cpython/commit/386c72d9928c51aa2c855ce592bd8022da3b407f] -Co-authored-by: Serhiy Storchaka <storchaka@gmail.com> -Signed-off-by: Khem Raj <raj.khem@gmail.com> ---- - .../next/Library/2024-01-23-21-20-40.gh-issue-114492.vKxl5o.rst | 2 ++ - 1 file changed, 2 insertions(+) - create mode 100644 Misc/NEWS.d/next/Library/2024-01-23-21-20-40.gh-issue-114492.vKxl5o.rst - -diff --git a/Misc/NEWS.d/next/Library/2024-01-23-21-20-40.gh-issue-114492.vKxl5o.rst b/Misc/NEWS.d/next/Library/2024-01-23-21-20-40.gh-issue-114492.vKxl5o.rst -new file mode 100644 -index 0000000..8df8299 ---- /dev/null -+++ b/Misc/NEWS.d/next/Library/2024-01-23-21-20-40.gh-issue-114492.vKxl5o.rst -@@ -0,0 +1,2 @@ -+Make the result of :func:`termios.tcgetattr` reproducible on Alpine Linux. -+Previously it could leave a random garbage in some fields. diff --git a/poky/meta/recipes-devtools/python/python3/0001-python3-use-cc_basename-to-replace-CC-for-checking-c.patch b/poky/meta/recipes-devtools/python/python3/0001-python3-use-cc_basename-to-replace-CC-for-checking-c.patch index bbeabe4389..5a1f9ffccf 100644 --- a/poky/meta/recipes-devtools/python/python3/0001-python3-use-cc_basename-to-replace-CC-for-checking-c.patch +++ b/poky/meta/recipes-devtools/python/python3/0001-python3-use-cc_basename-to-replace-CC-for-checking-c.patch @@ -1,4 +1,4 @@ -From ababc7b1db8c406910766e11cdd04cbef7a706c9 Mon Sep 17 00:00:00 2001 +From 82576cdb9d6d9736ba122592974b0e7727216a3f Mon Sep 17 00:00:00 2001 From: Changqing Li <changqing.li@windriver.com> Date: Mon, 22 Oct 2018 15:19:51 +0800 Subject: [PATCH] python3: use cc_basename to replace CC for checking compiler @@ -26,7 +26,7 @@ Signed-off-by: Changqing Li <changqing.li@windriver.com> 1 file changed, 10 insertions(+), 9 deletions(-) diff --git a/configure.ac b/configure.ac -index 384718d..5a1d58b 100644 +index 9270b5f..955daad 100644 --- a/configure.ac +++ b/configure.ac @@ -137,6 +137,7 @@ AC_CONFIG_HEADERS([pyconfig.h]) @@ -46,7 +46,7 @@ index 384718d..5a1d58b 100644 gcc) AC_PATH_TOOL([CXX], [g++], [g++], [notfound]) ;; cc) AC_PATH_TOOL([CXX], [c++], [c++], [notfound]) ;; clang|*/clang) AC_PATH_TOOL([CXX], [clang++], [clang++], [notfound]) ;; -@@ -1328,7 +1329,7 @@ rmdir CaseSensitiveTestDir +@@ -1331,7 +1332,7 @@ rmdir CaseSensitiveTestDir case $ac_sys_system in hp*|HP*) @@ -55,7 +55,7 @@ index 384718d..5a1d58b 100644 cc|*/cc) CC="$CC -Ae";; esac;; esac -@@ -1854,7 +1855,7 @@ esac +@@ -1857,7 +1858,7 @@ esac ], [AC_MSG_RESULT([no])]) if test "$Py_LTO" = 'true' ; then @@ -64,7 +64,7 @@ index 384718d..5a1d58b 100644 *clang*) LDFLAGS_NOLTO="-fno-lto" dnl Clang linker requires -flto in order to link objects with LTO information. -@@ -1983,7 +1984,7 @@ then +@@ -1986,7 +1987,7 @@ then fi fi LLVM_PROF_ERR=no @@ -73,7 +73,7 @@ index 384718d..5a1d58b 100644 *clang*) # Any changes made here should be reflected in the GCC+Darwin case below PGO_PROF_GEN_FLAG="-fprofile-instr-generate" -@@ -2147,7 +2148,7 @@ AC_MSG_RESULT([$BOLT_APPLY_FLAGS]) +@@ -2179,7 +2180,7 @@ AC_MSG_RESULT([$BOLT_APPLY_FLAGS]) # compiler and platform. BASECFLAGS tweaks need to be made even if the # user set OPT. @@ -82,7 +82,7 @@ index 384718d..5a1d58b 100644 *clang*) cc_is_clang=1 ;; -@@ -2419,7 +2420,7 @@ yes) +@@ -2451,7 +2452,7 @@ yes) # ICC doesn't recognize the option, but only emits a warning ## XXX does it emit an unused result warning and can it be disabled? @@ -91,7 +91,7 @@ index 384718d..5a1d58b 100644 [*icc*], [ac_cv_disable_unused_result_warning=no] [PY_CHECK_CC_WARNING([disable], [unused-result])]) AS_VAR_IF([ac_cv_disable_unused_result_warning], [yes], -@@ -2665,7 +2666,7 @@ yes) +@@ -2697,7 +2698,7 @@ yes) ;; esac @@ -100,7 +100,7 @@ index 384718d..5a1d58b 100644 *mpicc*) CFLAGS_NODIST="$CFLAGS_NODIST" ;; -@@ -3482,7 +3483,7 @@ then +@@ -3532,7 +3533,7 @@ then then LINKFORSHARED="-Wl,--export-dynamic" fi;; @@ -109,7 +109,7 @@ index 384718d..5a1d58b 100644 *gcc*) if $CC -Xlinker --help 2>&1 | grep export-dynamic >/dev/null then -@@ -6803,7 +6804,7 @@ if test "$ac_cv_gcc_asm_for_x87" = yes; then +@@ -6853,7 +6854,7 @@ if test "$ac_cv_gcc_asm_for_x87" = yes; then # Some versions of gcc miscompile inline asm: # http://gcc.gnu.org/bugzilla/show_bug.cgi?id=46491 # http://gcc.gnu.org/ml/gcc/2010-11/msg00366.html diff --git a/poky/meta/recipes-devtools/python/python3/0001-skip-no_stdout_fileno-test-due-to-load-variability.patch b/poky/meta/recipes-devtools/python/python3/0001-skip-no_stdout_fileno-test-due-to-load-variability.patch index 2d7bca6a77..4920cb9ad9 100644 --- a/poky/meta/recipes-devtools/python/python3/0001-skip-no_stdout_fileno-test-due-to-load-variability.patch +++ b/poky/meta/recipes-devtools/python/python3/0001-skip-no_stdout_fileno-test-due-to-load-variability.patch @@ -1,4 +1,4 @@ -From 217cea231462e7703e8c9ea39c0a6833f799a420 Mon Sep 17 00:00:00 2001 +From 5944f707fc04fb65caec3f0e1ce3a42169426c47 Mon Sep 17 00:00:00 2001 From: Trevor Gamblin <tgamblin@baylibre.com> Date: Fri, 15 Sep 2023 08:48:33 -0400 Subject: [PATCH] skip no_stdout_fileno test due to load variability @@ -16,10 +16,10 @@ Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com> 1 file changed, 1 insertion(+) diff --git a/Lib/test/test_builtin.py b/Lib/test/test_builtin.py -index 4d03c46..b329b7a 100644 +index c71c568..e41ab5e 100644 --- a/Lib/test/test_builtin.py +++ b/Lib/test/test_builtin.py -@@ -2326,6 +2326,7 @@ class PtyTests(unittest.TestCase): +@@ -2375,6 +2375,7 @@ class PtyTests(unittest.TestCase): # Check stdin/stdout error handler is used when invoking PyOS_Readline() self.check_input_tty("prompté", b"quux\xe9", "ascii") diff --git a/poky/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch b/poky/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch index fc52fdac26..c7ac43cc85 100644 --- a/poky/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch +++ b/poky/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch @@ -1,4 +1,4 @@ -From a5d429a0e1a4809c1ded7be7e45dcabeb82c53d8 Mon Sep 17 00:00:00 2001 +From 3aeeddb1325679d5c0471ad86806e92e72187138 Mon Sep 17 00:00:00 2001 From: Alexander Kanavin <alex@linutronix.de> Date: Sun, 12 Sep 2021 21:44:36 +0200 Subject: [PATCH] sysconfig.py: use platlibdir also for purelib @@ -8,13 +8,12 @@ is not correct. Upstream-Status: Inappropriate [oe-core specific] Signed-off-by: Alexander Kanavin <alex@linutronix.de> - --- Lib/sysconfig.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Lib/sysconfig.py b/Lib/sysconfig.py -index 122d441..79c0510 100644 +index 517b13a..6258b68 100644 --- a/Lib/sysconfig.py +++ b/Lib/sysconfig.py @@ -28,7 +28,7 @@ _INSTALL_SCHEMES = { diff --git a/poky/meta/recipes-devtools/python/python3/0001-test_active_children-skip-problematic-test.patch b/poky/meta/recipes-devtools/python/python3/0001-test_active_children-skip-problematic-test.patch new file mode 100644 index 0000000000..164c8b5180 --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3/0001-test_active_children-skip-problematic-test.patch @@ -0,0 +1,27 @@ +From a83311a1030b816f422dbb4457fc38c1289c224d Mon Sep 17 00:00:00 2001 +From: Trevor Gamblin <tgamblin@baylibre.com> +Date: Thu, 13 Jun 2024 10:54:31 -0400 +Subject: [PATCH] test_active_children: skip problematic test + +This test is failing in some tests on the Autobuilder. Since it's of a +similar nature to other failing/hanging tests, disable it for now. + +Upstream-Status: Inappropriate [OE-Specific] + +Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com> +--- + Lib/test/_test_multiprocessing.py | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/Lib/test/_test_multiprocessing.py b/Lib/test/_test_multiprocessing.py +index 1f94dec..3632219 100644 +--- a/Lib/test/_test_multiprocessing.py ++++ b/Lib/test/_test_multiprocessing.py +@@ -585,6 +585,7 @@ class _TestProcess(BaseTestCase): + self.assertTrue(type(cpus) is int) + self.assertTrue(cpus >= 1) + ++ @unittest.skip("skipping problematic test") + def test_active_children(self): + self.assertEqual(type(self.active_children()), list) + diff --git a/poky/meta/recipes-devtools/python/python3/0001-test_ctypes.test_find-skip-without-tools-sdk.patch b/poky/meta/recipes-devtools/python/python3/0001-test_ctypes.test_find-skip-without-tools-sdk.patch index b4fe946cba..307e4bf306 100644 --- a/poky/meta/recipes-devtools/python/python3/0001-test_ctypes.test_find-skip-without-tools-sdk.patch +++ b/poky/meta/recipes-devtools/python/python3/0001-test_ctypes.test_find-skip-without-tools-sdk.patch @@ -1,4 +1,4 @@ -From b64c131a576a4b4f821514e711ab91b1394fb4ff Mon Sep 17 00:00:00 2001 +From fbbf04dbeae217b985073263499174960e5fd142 Mon Sep 17 00:00:00 2001 From: Tim Orling <timothy.t.orling@intel.com> Date: Fri, 18 Jun 2021 11:56:50 -0700 Subject: [PATCH] test_ctypes.test_find: skip without tools-sdk @@ -10,13 +10,12 @@ easiest way to dynamically check for that is looking for Upstream-Status: Inappropriate [oe-specific] Signed-off-by: Tim Orling <timothy.t.orling@intel.com> - --- Lib/test/test_ctypes/test_find.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/Lib/test/test_ctypes/test_find.py b/Lib/test/test_ctypes/test_find.py -index 1ff9d01..59def26 100644 +index a41e949..eb5fe19 100644 --- a/Lib/test/test_ctypes/test_find.py +++ b/Lib/test/test_ctypes/test_find.py @@ -113,10 +113,12 @@ class FindLibraryLinux(unittest.TestCase): diff --git a/poky/meta/recipes-devtools/python/python3/0001-test_deadlock-skip-problematic-test.patch b/poky/meta/recipes-devtools/python/python3/0001-test_deadlock-skip-problematic-test.patch new file mode 100644 index 0000000000..e07f7392f6 --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3/0001-test_deadlock-skip-problematic-test.patch @@ -0,0 +1,27 @@ +From 9d658dd20f02edcf878b245d638c474c808ab8d1 Mon Sep 17 00:00:00 2001 +From: Trevor Gamblin <tgamblin@baylibre.com> +Date: Wed, 12 Jun 2024 10:29:03 -0400 +Subject: [PATCH] test_deadlock: skip problematic test + +This test hangs frequently when run on the Autobuilder. Disable it in +testing until the cause can be determined. + +Upstream-Status: Inappropriate [OE-Specific] + +Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com> +--- + Lib/test/test_concurrent_futures/test_deadlock.py | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/Lib/test/test_concurrent_futures/test_deadlock.py b/Lib/test/test_concurrent_futures/test_deadlock.py +index e8cd8f6..021906b 100644 +--- a/Lib/test/test_concurrent_futures/test_deadlock.py ++++ b/Lib/test/test_concurrent_futures/test_deadlock.py +@@ -90,6 +90,7 @@ class ErrorAtUnpickle(object): + return _raise_error_ignore_stderr, (UnpicklingError, ) + + ++@unittest.skip("skipping problematic test") + class ExecutorDeadlockTest: + TIMEOUT = support.LONG_TIMEOUT + diff --git a/poky/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch b/poky/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch index 410a9fc7f1..535c48c769 100644 --- a/poky/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch +++ b/poky/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch @@ -1,4 +1,4 @@ -From ef5728f0af14da5c9f80b0f038fe5bf6d44cb0e9 Mon Sep 17 00:00:00 2001 +From fcd5b7d30d3245ce92ea45dfbab3c7b7da690c20 Mon Sep 17 00:00:00 2001 From: Mingli Yu <mingli.yu@windriver.com> Date: Mon, 5 Aug 2019 15:57:39 +0800 Subject: [PATCH] test_locale.py: correct the test output format @@ -26,16 +26,15 @@ Upstream-Status: Submitted [https://github.com/python/cpython/pull/15132] Rebased for 3.9.4, still not accepted upstream Signed-off-by: Alejandro Hernandez <alejandro@enedino.org> Signed-off-by: Mingli Yu <mingli.yu@windriver.com> - --- Lib/test/test_locale.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Lib/test/test_locale.py b/Lib/test/test_locale.py -index b0d7998..cb12153 100644 +index cde80a4..e8ffd71 100644 --- a/Lib/test/test_locale.py +++ b/Lib/test/test_locale.py -@@ -557,7 +557,7 @@ class TestMiscellaneous(unittest.TestCase): +@@ -561,7 +561,7 @@ class TestMiscellaneous(unittest.TestCase): self.skipTest('test needs Turkish locale') loc = locale.getlocale(locale.LC_CTYPE) if verbose: diff --git a/poky/meta/recipes-devtools/python/python3/0001-test_readline-skip-limited-history-test.patch b/poky/meta/recipes-devtools/python/python3/0001-test_readline-skip-limited-history-test.patch new file mode 100644 index 0000000000..f9dc0ddcda --- /dev/null +++ b/poky/meta/recipes-devtools/python/python3/0001-test_readline-skip-limited-history-test.patch @@ -0,0 +1,38 @@ +From 34fd0bc8afc67a11eea5d73f9e0edf045c5ce541 Mon Sep 17 00:00:00 2001 +From: Trevor Gamblin <tgamblin@baylibre.com> +Date: Tue, 13 Aug 2024 11:07:05 -0400 +Subject: [PATCH] test_readline: skip limited history test + +This test was added recently and is failing on the ptest image when +using the default PACKAGECONFIG settings (i.e. with editline instead of +readline).. Disable it until the proper fix is determined. + +A bug has been opened upstream: https://github.com/python/cpython/issues/123018 + +Upstream-Status: Inappropriate [OE-specific] + +Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com> +--- + Lib/test/test_readline.py | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/Lib/test/test_readline.py b/Lib/test/test_readline.py +index fab124a..291dd48 100644 +--- a/Lib/test/test_readline.py ++++ b/Lib/test/test_readline.py +@@ -141,6 +141,7 @@ class TestHistoryManipulation (unittest.TestCase): + self.assertEqual(readline.get_history_item(1), "entrée 1") + self.assertEqual(readline.get_history_item(2), "entrée 22") + ++ @unittest.skip("Skipping problematic test") + def test_write_read_limited_history(self): + previous_length = readline.get_history_length() + self.addCleanup(readline.set_history_length, previous_length) +@@ -379,6 +380,7 @@ readline.write_history_file(history_file) + self.assertIn(b"done", output) + + ++ @unittest.skip("Skipping problematic test") + def test_write_read_limited_history(self): + previous_length = readline.get_history_length() + self.addCleanup(readline.set_history_length, previous_length) diff --git a/poky/meta/recipes-devtools/python/python3/0001-test_shutdown-skip-problematic-test.patch b/poky/meta/recipes-devtools/python/python3/0001-test_shutdown-skip-problematic-test.patch index 1d4cda18b1..61fe5e9ba1 100644 --- a/poky/meta/recipes-devtools/python/python3/0001-test_shutdown-skip-problematic-test.patch +++ b/poky/meta/recipes-devtools/python/python3/0001-test_shutdown-skip-problematic-test.patch @@ -1,4 +1,4 @@ -From 9d4cdbde100798ba9fa1cf3f82dbaf18fd10a543 Mon Sep 17 00:00:00 2001 +From d09a034acba8922158d38fd16be970b5a454428a Mon Sep 17 00:00:00 2001 From: Trevor Gamblin <tgamblin@baylibre.com> Date: Wed, 8 May 2024 11:58:09 -0400 Subject: [PATCH] test_shutdown: skip problematic test @@ -14,7 +14,7 @@ Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com> 1 file changed, 3 insertions(+) diff --git a/Lib/test/test_concurrent_futures/test_shutdown.py b/Lib/test/test_concurrent_futures/test_shutdown.py -index 7a4065afd4..6b878a48bf 100644 +index 7a4065a..6b878a4 100644 --- a/Lib/test/test_concurrent_futures/test_shutdown.py +++ b/Lib/test/test_concurrent_futures/test_shutdown.py @@ -20,6 +20,7 @@ def sleep_and_print(t, msg): @@ -25,7 +25,7 @@ index 7a4065afd4..6b878a48bf 100644 class ExecutorShutdownTest: def test_run_after_shutdown(self): self.executor.shutdown() -@@ -156,6 +157,7 @@ def timeout(_signum, _frame): +@@ -156,6 +157,7 @@ class ExecutorShutdownTest: signal.signal(signal.SIGALRM, old_handler) @@ -33,7 +33,7 @@ index 7a4065afd4..6b878a48bf 100644 class ThreadPoolShutdownTest(ThreadPoolMixin, ExecutorShutdownTest, BaseTestCase): def test_threads_terminate(self): def acquire_lock(lock): -@@ -252,6 +254,7 @@ def test_cancel_futures_wait_false(self): +@@ -252,6 +254,7 @@ class ThreadPoolShutdownTest(ThreadPoolMixin, ExecutorShutdownTest, BaseTestCase self.assertIn(out.strip(), [b"apple", b""]) @@ -41,6 +41,3 @@ index 7a4065afd4..6b878a48bf 100644 class ProcessPoolShutdownTest(ExecutorShutdownTest): def test_processes_terminate(self): def acquire_lock(lock): --- -2.45.0 - diff --git a/poky/meta/recipes-devtools/python/python3/0001-test_storlines-skip-due-to-load-variability.patch b/poky/meta/recipes-devtools/python/python3/0001-test_storlines-skip-due-to-load-variability.patch index 0d0eb08459..88cd93a51f 100644 --- a/poky/meta/recipes-devtools/python/python3/0001-test_storlines-skip-due-to-load-variability.patch +++ b/poky/meta/recipes-devtools/python/python3/0001-test_storlines-skip-due-to-load-variability.patch @@ -1,4 +1,4 @@ -From dc69a1afdb3ba619705ff71e14f19ed3142e422f Mon Sep 17 00:00:00 2001 +From 6715560de4d622c2d72ee7b587c916ac647c54bb Mon Sep 17 00:00:00 2001 From: Trevor Gamblin <tgamblin@baylibre.com> Date: Fri, 6 Oct 2023 10:59:44 -0400 Subject: [PATCH] test_storlines: skip due to load variability @@ -11,16 +11,15 @@ Upstream-Status: Inappropriate [OE-Specific] [YOCTO #14933] Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com> - --- Lib/test/test_ftplib.py | 1 + 1 file changed, 1 insertion(+) diff --git a/Lib/test/test_ftplib.py b/Lib/test/test_ftplib.py -index 2f191ea..dc29346 100644 +index 4c4a449..b8c79a4 100644 --- a/Lib/test/test_ftplib.py +++ b/Lib/test/test_ftplib.py -@@ -626,6 +626,7 @@ class TestFTPClass(TestCase): +@@ -629,6 +629,7 @@ class TestFTPClass(TestCase): self.client.storbinary('stor', f, rest=r) self.assertEqual(self.server.handler_instance.rest, str(r)) diff --git a/poky/meta/recipes-devtools/python/python3/0020-configure.ac-setup.py-do-not-add-a-curses-include-pa.patch b/poky/meta/recipes-devtools/python/python3/0020-configure.ac-setup.py-do-not-add-a-curses-include-pa.patch index 0661249bfd..e917c8bdf0 100644 --- a/poky/meta/recipes-devtools/python/python3/0020-configure.ac-setup.py-do-not-add-a-curses-include-pa.patch +++ b/poky/meta/recipes-devtools/python/python3/0020-configure.ac-setup.py-do-not-add-a-curses-include-pa.patch @@ -1,4 +1,4 @@ -From d0205c60d08f51d84bd8ddc07a57e8c71710fdad Mon Sep 17 00:00:00 2001 +From 011b21dc9b090c0b97eaecbd80a9e0c1cd39b12d Mon Sep 17 00:00:00 2001 From: Alexander Kanavin <alex@linutronix.de> Date: Fri, 17 Nov 2023 14:16:40 +0100 Subject: [PATCH] configure.ac: do not add a curses include path from the host @@ -15,10 +15,10 @@ Signed-off-by: Alexander Kanavin <alex.kanavin@gmail.com> 1 file changed, 6 deletions(-) diff --git a/configure.ac b/configure.ac -index c49cd4f..affdedf 100644 +index 6e465a4..13c4835 100644 --- a/configure.ac +++ b/configure.ac -@@ -6508,12 +6508,6 @@ AS_VAR_IF([have_panel], [no], [ +@@ -6558,12 +6558,6 @@ AS_VAR_IF([have_panel], [no], [ AC_MSG_RESULT([$have_panel (CFLAGS: $PANEL_CFLAGS, LIBS: $PANEL_LIBS)]) ]) diff --git a/poky/meta/recipes-devtools/python/python3/cgi_py.patch b/poky/meta/recipes-devtools/python/python3/cgi_py.patch index 8262c88e73..880a463760 100644 --- a/poky/meta/recipes-devtools/python/python3/cgi_py.patch +++ b/poky/meta/recipes-devtools/python/python3/cgi_py.patch @@ -1,4 +1,4 @@ -From a56778372fe8dc7c42f5ffd911d89498c22dd064 Mon Sep 17 00:00:00 2001 +From 6ebd9de3505be0965cfc37e2e4d0d882d75f0ec2 Mon Sep 17 00:00:00 2001 From: Mark Hatle <mark.hatle@windriver.com> Date: Wed, 21 Sep 2011 20:55:33 -0500 Subject: [PATCH] Lib/cgi.py: Update the script as mentioned in the comment @@ -6,7 +6,6 @@ Subject: [PATCH] Lib/cgi.py: Update the script as mentioned in the comment Upstream-Status: Inappropriate [distribution] Signed-off-by: Mark Hatle <mark.hatle@windriver.com> - --- Lib/cgi.py | 11 +---------- 1 file changed, 1 insertion(+), 10 deletions(-) diff --git a/poky/meta/recipes-devtools/python/python3/crosspythonpath.patch b/poky/meta/recipes-devtools/python/python3/crosspythonpath.patch index 2c4aef0511..24268fb91a 100644 --- a/poky/meta/recipes-devtools/python/python3/crosspythonpath.patch +++ b/poky/meta/recipes-devtools/python/python3/crosspythonpath.patch @@ -1,4 +1,4 @@ -From 5b66463c10fec1440e977d5a21a0167862d6d79c Mon Sep 17 00:00:00 2001 +From 0bcdb84db7801507b155a40db2228ba516edeb73 Mon Sep 17 00:00:00 2001 From: Ricardo Ribalda <ricardo@ribalda.com> Date: Tue, 18 Nov 2014 03:35:33 -0500 Subject: [PATCH] configure.ac: add CROSSPYTHONPATH into PYTHONPATH for @@ -14,13 +14,12 @@ Upstream-Status: Inappropriate [OE-Core integration specific] Credits-to: Mark Hatle <mark.hatle@windriver.com> Credits-to: Jackie Huang <jackie.huang@windriver.com> Signed-off-by: Ricardo Ribalda <ricardo@ribalda.com> - --- configure.ac | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/configure.ac b/configure.ac -index cb9e198..d81c19a 100644 +index 955daad..6e465a4 100644 --- a/configure.ac +++ b/configure.ac @@ -165,7 +165,7 @@ AC_ARG_WITH([build-python], diff --git a/poky/meta/recipes-devtools/python/python3/deterministic_imports.patch b/poky/meta/recipes-devtools/python/python3/deterministic_imports.patch index 104df94964..9bfdf5cd47 100644 --- a/poky/meta/recipes-devtools/python/python3/deterministic_imports.patch +++ b/poky/meta/recipes-devtools/python/python3/deterministic_imports.patch @@ -1,4 +1,4 @@ -From 039d5e652796b55f1132afa568c7432b6ed89afd Mon Sep 17 00:00:00 2001 +From 1d6f0f5f8a1279fc9bc06266caa3f3b6f234c4cb Mon Sep 17 00:00:00 2001 From: Richard Purdie <richard.purdie@linuxfoundation.org> Date: Fri, 27 May 2022 17:05:44 +0100 Subject: [PATCH] python3: Ensure stale empty python module directories don't @@ -11,15 +11,14 @@ has caused a long string of different issues for us. As a result, patch this to a behaviour which works for us. -Upstream-Status: Pending [need to talk to upstream to see if they'll take one or both fixes] +Upstream-Status: Submitted [https://github.com/python/cpython/issues/120492; need to first talk to upstream to see if they'll take one or both fixes] Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> - --- Lib/importlib/metadata/__init__.py | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/Lib/importlib/metadata/__init__.py b/Lib/importlib/metadata/__init__.py -index 82e0ce1..969cac4 100644 +index e6ca178..ac5a75b 100644 --- a/Lib/importlib/metadata/__init__.py +++ b/Lib/importlib/metadata/__init__.py @@ -710,7 +710,14 @@ class Lookup: diff --git a/poky/meta/recipes-devtools/python/python3/makerace.patch b/poky/meta/recipes-devtools/python/python3/makerace.patch index c1b20703e6..fbe12a5fca 100644 --- a/poky/meta/recipes-devtools/python/python3/makerace.patch +++ b/poky/meta/recipes-devtools/python/python3/makerace.patch @@ -1,4 +1,4 @@ -From 9f827c29adbe656af3c8fc963fdd8f47aec0c442 Mon Sep 17 00:00:00 2001 +From be22dd9b091af8f971f924fdbce5b439d9b2e850 Mon Sep 17 00:00:00 2001 From: Richard Purdie <richard.purdie@linuxfoundation.org> Date: Tue, 13 Jul 2021 23:19:29 +0100 Subject: [PATCH] python3: Fix make race @@ -17,10 +17,10 @@ Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Makefile.pre.in b/Makefile.pre.in -index 381feb0..77bf09a 100644 +index dce36a5..2d235d2 100644 --- a/Makefile.pre.in +++ b/Makefile.pre.in -@@ -2250,7 +2250,7 @@ COMPILEALL_OPTS=-j0 +@@ -2267,7 +2267,7 @@ COMPILEALL_OPTS=-j0 TEST_MODULES=@TEST_MODULES@ .PHONY: libinstall diff --git a/poky/meta/recipes-devtools/python/python3/python3-manifest.json b/poky/meta/recipes-devtools/python/python3/python3-manifest.json index 46092d4004..292c5bbc5d 100644 --- a/poky/meta/recipes-devtools/python/python3/python3-manifest.json +++ b/poky/meta/recipes-devtools/python/python3/python3-manifest.json @@ -216,7 +216,7 @@ }, "core": { "summary": "Python interpreter and core modules", - "rdepends": [], + "rdepends": ["compression"], "files": [ "${bindir}/python${PYTHON_MAJMIN}", "${bindir}/python${PYTHON_MAJMIN}.real", diff --git a/poky/meta/recipes-devtools/python/python3_3.12.4.bb b/poky/meta/recipes-devtools/python/python3_3.12.12.bb index 0cb84b91b4..9a957c59bc 100644 --- a/poky/meta/recipes-devtools/python/python3_3.12.4.bb +++ b/poky/meta/recipes-devtools/python/python3_3.12.12.bb @@ -29,20 +29,23 @@ SRC_URI = "http://www.python.org/ftp/python/${PV}/Python-${PV}.tar.xz \ file://0001-Update-test_sysconfig-for-posix_user-purelib.patch \ file://0001-skip-no_stdout_fileno-test-due-to-load-variability.patch \ file://0001-test_storlines-skip-due-to-load-variability.patch \ - file://0001-gh-114492-Initialize-struct-termios-before-calling-t.patch \ file://0001-test_shutdown-skip-problematic-test.patch \ + file://0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch \ + file://0001-test_deadlock-skip-problematic-test.patch \ + file://0001-test_active_children-skip-problematic-test.patch \ + file://0001-test_readline-skip-limited-history-test.patch \ " SRC_URI:append:class-native = " \ file://0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch \ " -SRC_URI[sha256sum] = "f6d419a6d8743ab26700801b4908d26d97e8b986e14f95de31b32de2b0e79554" +SRC_URI[sha256sum] = "fb85a13414b028c49ba18bbd523c2d055a30b56b18b92ce454ea2c51edc656c4" # exclude pre-releases for both python 2.x and 3.x UPSTREAM_CHECK_REGEX = "[Pp]ython-(?P<pver>\d+(\.\d+)+).tar" -CVE_PRODUCT = "python cpython" +CVE_PRODUCT = "python:python python_software_foundation:python cpython" CVE_STATUS[CVE-2007-4559] = "disputed: Upstream consider this expected behaviour" CVE_STATUS[CVE-2019-18348] = "not-applicable-config: This is not exploitable when glibc has CVE-2016-10739 fixed" @@ -181,14 +184,14 @@ do_install:append:class-native() { # when they're only used for python called with -O or -OO. #find ${D} -name *opt-*.pyc -delete # Remove all pyc files. There are a ton of them and it is probably faster to let - # python create the ones it wants at runtime rather than manage in the sstate + # python create the ones it wants at runtime rather than manage in the sstate # tarballs and sysroot creation. find ${D} -name *.pyc -delete # Nothing should be looking into ${B} for python3-native sed -i -e 's:${B}:/build/path/unavailable/:g' \ ${D}/${libdir}/python${PYTHON_MAJMIN}/config-${PYTHON_MAJMIN}${PYTHON_ABI}*/Makefile - + # disable the lookup in user's site-packages globally sed -i 's#ENABLE_USER_SITE = None#ENABLE_USER_SITE = False#' ${D}${libdir}/python${PYTHON_MAJMIN}/site.py @@ -223,7 +226,7 @@ do_install:append() { rm -f ${D}${libdir}/python${PYTHON_MAJMIN}/test/__pycache__/test_range.cpython* rm -f ${D}${libdir}/python${PYTHON_MAJMIN}/test/__pycache__/test_xml_etree.cpython* - # Similar to the above, we're getting reproducibility issues with + # Similar to the above, we're getting reproducibility issues with # /usr/lib/python3.10/__pycache__/traceback.cpython-310.pyc # so remove it too rm -f ${D}${libdir}/python${PYTHON_MAJMIN}/__pycache__/traceback.cpython* @@ -300,7 +303,7 @@ py_package_preprocess () { cd - mv ${PKGD}/${bindir}/python${PYTHON_MAJMIN}-config ${PKGD}/${bindir}/python${PYTHON_MAJMIN}-config-${MULTILIB_SUFFIX} - + #Remove the unneeded copy of target sysconfig data rm -rf ${PKGD}/${libdir}/python-sysconfigdata } |
