- Mar 13, 2025
-
-
Alessio Cascone authored
Starting from 2023d version, tzcode makefile does not use anymore "cc" variable for C compiler, due to Makefile refactoring. Replacing "cc" with "CC" fixes the issue. (From OE-Core rev: 0216c229d5c60d0023b0a7d6e8ee41bdfa16f8ef) Signed-off-by:
Alessio Cascone <alessio.cascone@vimar.com> Signed-off-by:
Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com> Signed-off-by:
Richard Purdie <richard.purdie@linuxfoundation.org> (cherry picked from commit b3cdfca5ef84ed2054faef9abddef3aeed930e17) Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Priyal Doshi authored
(From OE-Core rev: 4dc7731d350eab8952330f01beb5acdba7d88bb9) Signed-off-by:
Priyal Doshi <pdoshi@mvista.com> Signed-off-by:
Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com> Signed-off-by:
Richard Purdie <richard.purdie@linuxfoundation.org> (cherry picked from commit a15c4e6793c55c8084a61298ef3695e1db2f60cd) Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
* Noteworthy changes in release 4.20.0 (2025-02-01) [stable] - The release tarball is now reproducible. - We publish a minimal source-only tarball generated by 'git archive'. - Update gnulib files and various build/maintenance fixes. - Fix CVE-2024-12133: Potential DoS in handling of numerous SEQUENCE OF or SET OF elements License-Update: file COPYING.LESSER renamed to COPYING.LESSERv2 & Copyright year updated to 2025 (From OE-Core rev: 0ff5d08053d92eeae5b2a23f8e0d7a280488723c) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Hitendra Prajapati authored
Upstream-Status: Backport from https://github.com/ruby/cgi/commit/cd1eb08076c8b8e310d4d553d427763f2577a1b6 (From OE-Core rev: 44665939783cb2b32f5ade1772e0ceef47f9a853) Signed-off-by:
Hitendra Prajapati <hprajapati@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Deepesh Varatharajan authored
PR32560 stack-buffer-overflow at objdump disassemble_bytes Backport a patch from upstream to fix CVE-2025-0840 Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=baac6c221e9d69335bf41366a1c7d87d8ab2f893 ] (From OE-Core rev: e12ee4b1713aa25465aa3f866d345d84e9eb948a) Signed-off-by:
Deepesh Varatharajan <Deepesh.Varatharajan@windriver.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Upstream-Status: Backport from https://github.com/openssh/openssh-portable/commit/0832aac79517611dd4de93ad0a83577994d9c907 (From OE-Core rev: 934c212859e12235599835e8cfd8857e4be44ff8) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
- Mar 08, 2025
-
-
Ross Burton authored
This was removed in 2019, so swap it for poky-altcfg. (From yocto-docs rev: 9b4c36f7b02dd4bedfec90206744a1e90e37733c) Signed-off-by:
Ross Burton <ross.burton@arm.com> Reviewed-by:
Quentin Schulz <quentin.schulz@cherry.de> Signed-off-by:
Antonin Godard <antonin.godard@bootlin.com> (cherry picked from commit 7f7f6570befdda280c174a5f9776b20f53f3ea0d) Signed-off-by:
Antonin Godard <antonin.godard@bootlin.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Ross Burton authored
core-image-lsb was removed in 2019[1], so remove all of the incredibly obsolete references in the documentation. [1] oe-core fb064356af615d67d85b65942103bf943d84d290 (From yocto-docs rev: 6001f1baa513566639abee86376dc72748f3cd34) Signed-off-by:
Ross Burton <ross.burton@arm.com> Reviewed-by:
Quentin Schulz <quentin.schulz@cherry.de> Signed-off-by:
Antonin Godard <antonin.godard@bootlin.com> (cherry picked from commit 062445a49919eff117b5478c1fb18d125c1f895c) Signed-off-by:
Antonin Godard <antonin.godard@bootlin.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Lee Chee Yang authored
(From yocto-docs rev: da811a5e6cf298bc63157814d57befdc125d9d32) Signed-off-by:
Lee Chee Yang <chee.yang.lee@intel.com> Signed-off-by:
Antonin Godard <antonin.godard@bootlin.com> (cherry picked from commit 4649514cdfae496f43711d6b830a0a835c3a1534) Signed-off-by:
Antonin Godard <antonin.godard@bootlin.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Johannes Kauffmann authored
Building weston with core-image-weston SDK fails: ``` ../libweston/renderer-gl/gl-shader-config-color-transformation.c:29:10: fatal error: GLES3/gl3.h: No such file or directory 29 | #include <GLES3/gl3.h> | ^~~~~~~~~~~~~ ``` Both GLES2 and GLES3 implementations are contained in libGLESv2.so.2, which is packaged in libgles2-mesa. However, the headers are split between libgles2-mesa-dev and libgles3-mesa-dev, which is why the GLES3 headers end up missing in the SDK sysroot. Add a dependency so the GLES3 headers are properly associated with the GLES3 implementation. (From OE-Core rev: 7e1308ec413e69a8427ac5998431005d9e4b8033) (From OE-Core rev: 0d9f2fcc2058407eb138297d9f8f12595851b963) Signed-off-by:
Tom Hochstein <tom.hochstein@oss.nxp.com> Signed-off-by:
Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com> Signed-off-by:
Richard Purdie <richard.purdie@linuxfoundation.org> Signed-off-by:
Johannes Kauffmann <johanneskauffmann@hotmail.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
The patches are copied from xserver-xorg recipe. CVE reported for both and patches apply on both. Upstream-Commit: https://gitlab.freedesktop.org/xorg/xserver/-/commit/16a1242d & https://gitlab.freedesktop.org/xorg/xserver/-/commit/f52cea2f & https://gitlab.freedesktop.org/xorg/xserver/-/commit/8cbc90c8 & https://gitlab.freedesktop.org/xorg/xserver/-/commit/c2857989 (From OE-Core rev: 58f5a6a28d353f14c672bb99820608ec82f05e6e) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Patch copied from xserver-xorg recipe. CVE reported for both and patch apply on both. Upstream-Commit: https://gitlab.freedesktop.org/xorg/xserver/-/commit/6e0f332b (From OE-Core rev: b02bf5f9abb4d2a514f9ea883cd1fe6057367c92) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
The patches are copied from xserver-xorg recipe. CVE reported for both and patches apply on both. Upstream-Commit: https://gitlab.freedesktop.org/xorg/xserver/-/commit/c1ff84be & https://gitlab.freedesktop.org/xorg/xserver/-/commit/b07192a8 (From OE-Core rev: d79cd91d2abc1b0e9e1e47d18af140d351dce298) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Patch copied from xserver-xorg recipe. CVE reported for both and patch apply on both. Upstream-Commit: https://gitlab.freedesktop.org/xorg/xserver/-/commit/bba9df1a (From OE-Core rev: f01c281b94ff137003ef108e33a8c3230c541c46) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Patch copied from xserver-xorg recipe. CVE reported for both and patch apply on both. Upstream-Commit: https://gitlab.freedesktop.org/xorg/xserver/-/commit/0e4ed949 (From OE-Core rev: a7f4c6b1946e7215d8df561340d7a1cd0b2d5c27) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Patch copied from xserver-xorg recipe. CVE reported for both and patch apply on both. Upstream-Commit: https://gitlab.freedesktop.org/xorg/xserver/-/commit/80d69f01 (From OE-Core rev: 45738e56aaf5dac1a471cb37088d3cd24764156d) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Patch copied from xserver-xorg recipe. CVE reported for both and patch apply on both. Upstream-Commit: https://gitlab.freedesktop.org/xorg/xserver/-/commit/11fcda87 (From OE-Core rev: e0768162f0ece29392d4f387d263d62dd4083836) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
The patches are copied from xserver-xorg recipe. CVE reported for both and patches apply on both. Upstream-Commit: https://gitlab.freedesktop.org/xorg/xserver/-/commit/01642f26 & https://gitlab.freedesktop.org/xorg/xserver/-/commit/b0a09ba6 (From OE-Core rev: 2d8bf72c892a3a6422e2a294fb6528ff67971e6d) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Patch copied from xserver-xorg recipe. CVE reported for both and patch apply on both. Upstream-Commit: https://gitlab.freedesktop.org/xorg/xserver/-/commit/ba1d14f8eff2a123bd7ff4d48c02e1d5131358e0 (From OE-Core rev: 2158a34839068b878344d214d3fc9feeb17e504a) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
The patches are copied from xserver-xorg recipe. CVE reported for both and patches apply on both. Upstream-Commit: https://gitlab.freedesktop.org/xorg/xserver/-/commit/bdca6c3d1f5057ee & https://gitlab.freedesktop.org/xorg/xserver/-/commit/337d8d48b618d4fc (From OE-Core rev: 1c4b1e7877210243707a91d6a9d37ed4546bc8a7) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Patch copied from xserver-xorg recipe. CVE reported for both and patch apply on both. Upstream-Commit: https://gitlab.freedesktop.org/xorg/xserver/-/commit/3e77295f888c67fc7645db5d0c00926a29ffecee (From OE-Core rev: 3575ad718c8ea7d808247842df19982f00725187) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Patch copied from xserver-xorg recipe. CVE reported for both and patch apply on both. Upstream-Commit: https://gitlab.freedesktop.org/xorg/xserver/-/commit/96798fc1967491c80a4d0c8d9e0a80586cb2152b (From OE-Core rev: 4e41b1c8cccd3b2f359ee949cad402b9418f5983) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
The patches are copied from xserver-xorg recipe. CVE reported for both and patches apply on both. Upstream-Commit: https://gitlab.freedesktop.org/xorg/xserver/-/commit/bc1fdbe46559dd947674375946bbef54dd0ce36b & https://gitlab.freedesktop.org/xorg/xserver/-/commit/26769aa71fcbe0a8403b7fb13b7c9010cc07c3a8 (From OE-Core rev: 77487fb0756951e29628f41ff00db12a5f9d7c27) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Patch copied from xserver-xorg recipe. CVE reported for both and patch apply on both. Upstream-Commit: https://gitlab.freedesktop.org/xorg/xserver/-/commit/4a5e9b1895627d40d26045bd0b7ef3dce503cbd1 (From OE-Core rev: 4b0f6aaa994eeab5d18211ace8034ec8b92b7419) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Peter Marko authored
This vulnerability has now a CVE assigned. (From OE-Core rev: 204ff9dd9c62a8a346e89880b2e15a4c0e9ad6e0) Signed-off-by:
Peter Marko <peter.marko@siemens.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
- Mar 04, 2025
-
-
Hitendra Prajapati authored
Backport fixes for: * CVE-2025-1352 - Upstream-Status: Backport from https://sourceware.org/git/?p=elfutils.git;a=commit;h=2636426a091bd6c6f7f02e49ab20d4cdc6bfc753 * CVE-2025-1372 - Upstream-Status: Backport from https://sourceware.org/git/?p=elfutils.git;a=commit;h=73db9d2021cab9e23fd734b0a76a612d52a6f1db (From OE-Core rev: 8ea258ad9c83be5d9548a796f7dda4ac820fc435) Signed-off-by:
Hitendra Prajapati <hprajapati@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Guocai He authored
Update SRC_URI for xz. The the tarball of xz-.tar.gz has been changed from https://tukaani.org/xz/xz-.tar.gz to https://sourceforge.net/projects/lzmautils/files/xz-.tar.gz (From OE-Core rev: 3f0803557ffa0fae557895f955ab2dcac38d7262) Signed-off-by:
Guocai He <guocai.he.cn@windriver.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Guocai He authored
Update SRC_URI for tzcode. Update the http to https in SRC_URI to fix the do_fetch issue. (From OE-Core rev: b663540d143b0e5fcb9ceeec45cde7fe3e68f9bb) Signed-off-by:
Guocai He <guocai.he.cn@windriver.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Moritz Haase authored
When testing a Yocto SDK installer on Alpine 3.21, we recently ended up with a broken SDK. One of the commands the relocation script calls in a piped multi-command chain failed (see [0]), but the installer did not realize that - since it doesn't use 'set -o pipefail'. Thus, the error was never reported to the user and the installer claimed to have set up the SDK correctly - which wasn't the case. Given that the SDK installer is a POSIX-compliant shell script and that the 'pipefail' option used to be missing from the standard, it's not surprising that it isn't used. Thankfully however, in June of 2024, a new version of POSIX (POSIX.1-2024) was released - and that one finally includes the 'pipefail' option (see [1]). A number of shells already support it, so let's enable it if available to make the SDK installer more robust. The change has been tested locally using SDK installers for internal projects, based on both Kirkstone and Scarthgap. [0]: https://gitlab.alpinelinux.org/alpine/aports/-/issues/16797 [1]: https://pubs.opengroup.org/onlinepubs/9799919799.2024edition/utilities/V3_chap02.html#set (From OE-Core rev: 1cb4b41c7faf77fcc347b1276d86d4288968c926) (From OE-Core rev: 1de469f1ffb1680e3a75da2c3895fb1e4f43859f) Signed-off-by:
Moritz Haase <Moritz.Haase@bmw.de> Signed-off-by:
Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com> Signed-off-by:
Richard Purdie <richard.purdie@linuxfoundation.org> (cherry picked from commit 10dce263) Signed-off-by:
Akash Hadke <akash.hadke27@gmail.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Libo Chen authored
Update SRC_URI to fix the following error: WARNING: virglrenderer-native-0.9.1-r0 do_fetch: Failed to fetch URL git://anongit.freedesktop.org/git/virglrenderer;branch=branch-0.9.1 , attempting MIRRORS if available (From OE-Core rev: 72450859dd5ee5395b64917516f185a2eed52775) Signed-off-by:
Libo Chen <libo.chen.cn@windriver.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Jiaying Song authored
Change the SRC_URI to the correct value due to the following error: WARNING: boost-native-1.86.0-r0 do_fetch: Checksum failure encountered with download of https://boostorg.jfrog.io/artifactory/main/release/1.86.0/source/boost_1_86_0.tar.bz2 - will attempt other sources if available (From OE-Core rev: 3b4c5ce6b89477307f3a2c30c7e275473b0c9f00) Signed-off-by:
Jiaying Song <jsong-cn@ala-lpggp7.wrs.com> Signed-off-by:
Richard Purdie <richard.purdie@linuxfoundation.org> backport to kirkstone. Signed-off-by:
Libo Chen <libo.chen.cn@windriver.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Narpat Mali authored
Latest stable branch update which includes 396 commits and the full list of changes can be found at: https://github.com/systemd/systemd-stable/compare/v250.5...v250.14 All the patches were refreshed with devtool. Backported this upstreamed patch to resolve the compile error while building systemd with qemumips machine. - 0001-core-fix-build-when-seccomp-is-off.patch These 2 below patches were modified to resolve the merge conflicts introduced by systemd v250.14 version: 1. 0001-Move-sysusers.d-sysctl.d-binfmt.d-modules-load.d-to-.patch - This patch was just adjusted based on the systemd v250.14 version. 2. 0001-pass-correct-parameters-to-getdents64.patch - For this patch, there was a commit reverted as part of the v250.8 tag: https://github.com/systemd/systemd-stable/commit/51089e007f2f45fc15e37e7a9dcf3045416e1239 These below 6 patches were dropped as systemd v250.14 already has the changes: - 0001-shared-json-allow-json_variant_dump-to-return-an-err.patch - CVE-2022-3821.patch - CVE-2022-4415-1.patch - CVE-2022-4415-2.patch - CVE-2022-45873.patch - CVE-2023-7008.patch (From OE-Core rev: 371d030a665e3c963a586ab02d10f1f36b225435) Signed-off-by:
Narpat Mali <narpat.falna@gmail.com> Signed-off-by:
Randy Macleod <randy.macleod@windriver.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Includes security fixes for CVE-2024-12705 CVE-2024-11187 and other bug fixes Release Notes: https://downloads.isc.org/isc/bind9/9.18.33/doc/arm/html/notes.html#notes-for-bind-9-18-33 https://downloads.isc.org/isc/bind9/9.18.33/doc/arm/html/notes.html#notes-for-bind-9-18-32 https://downloads.isc.org/isc/bind9/9.18.33/doc/arm/html/notes.html#notes-for-bind-9-18-31 https://downloads.isc.org/isc/bind9/9.18.33/doc/arm/html/notes.html#notes-for-bind-9-18-30 https://downloads.isc.org/isc/bind9/9.18.33/doc/arm/html/notes.html#notes-for-bind-9-18-29 (From OE-Core rev: 3488171fb594a28f8e9ed110e94c6a191f8f390e) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Upstream-Status: Backport from https://gitlab.freedesktop.org/xorg/xserver/-/commit/16a1242d & https://gitlab.freedesktop.org/xorg/xserver/-/commit/f52cea2f & https://gitlab.freedesktop.org/xorg/xserver/-/commit/8cbc90c8 & https://gitlab.freedesktop.org/xorg/xserver/-/commit/c2857989 (From OE-Core rev: edc4a85c1aa5a137d4f5d8fbc74135c6805511db) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Upstream-Status: Backport from https://gitlab.freedesktop.org/xorg/xserver/-/commit/6e0f332b (From OE-Core rev: 4227ae54a29ca8b454e56ffd27de2bbce00b6b89) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Upstream-Status: Backport from https://gitlab.freedesktop.org/xorg/xserver/-/commit/c1ff84be & https://gitlab.freedesktop.org/xorg/xserver/-/commit/b07192a8 (From OE-Core rev: c013fec3e5dd86544366308f53a031b080b140c6) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Upstream-Status: Backport from https://gitlab.freedesktop.org/xorg/xserver/-/commit/bba9df1a (From OE-Core rev: 645ad1bcf8675873a7ab4778ffd2dd59dbb7b037) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Upstream-Status: Backport from https://gitlab.freedesktop.org/xorg/xserver/-/commit/0e4ed949 (From OE-Core rev: 9d095e34da2adde63358a878cfac45ea28727bdf) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Upstream-Status: Backport from https://gitlab.freedesktop.org/xorg/xserver/-/commit/80d69f01 (From OE-Core rev: d510d87d9bb3e3489a4482dd0ce66e4bc7622ca0) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-
Vijay Anusuri authored
Upstream-Status: Backport from https://gitlab.freedesktop.org/xorg/xserver/-/commit/11fcda87 (From OE-Core rev: 78d718f0a683f9fb81aa24b39f148d2acf2e1fc6) Signed-off-by:
Vijay Anusuri <vanusuri@mvista.com> Signed-off-by:
Steve Sakoman <steve@sakoman.com>
-