Hello,

this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe(s) *apr-util* to *1.6.5* has 
Failed (devtool error).

Detailed error information:

Running 'devtool upgrade' for recipe apr-util failed.
NOTE: Reconnecting to bitbake server...
Loading cache...done.
Loaded 0 entries from dependency cache.
Parsing recipes...done.
Parsing of 956 .bb files complete (0 cached, 956 parsed). 1987 targets, 40 
skipped, 0 masked, 0 errors.
NOTE: Resolving any missing task queue dependencies

Build Configuration:
BB_VERSION           = "2.19.0"
BUILD_SYS            = "x86_64-linux"
NATIVELSBSTRING      = "universal"
TARGET_SYS           = "x86_64-poky-linux"
MACHINE              = "qemux86-64"
SDKMACHINE           = "x86_64"
DISTRO               = "poky"
DISTRO_VERSION       = 
"6.0.99+snapshot-6b46d76dd91d5187112b59b2a46b00dedbe7084c"
TUNE_FEATURES        = "m64 x86-64-v3"
meta                 = 
"tmp-auh-upgrades:6b46d76dd91d5187112b59b2a46b00dedbe7084c"
meta-yocto-bsp       
meta-poky            = "master:0afedb9b1195525861f9140d6f33e9cd4118b199"
workspace            = "<unknown>:<unknown>"

Initialising tasks...NOTE: The /proc/pressure files can't be read. Continuing 
build without monitoring pressure
Sstate summary: Wanted 10 Local 10 Mirrors 0 Missed 0 Current 20 (100% match, 
100% complete)
done.
NOTE: Executing Tasks
NOTE: Tasks Summary: Attempted 103 tasks of which 100 didn't need to be rerun 
and all succeeded.
NOTE: Writing buildhistory
NOTE: Writing buildhistory took: 1 seconds
Loading cache...done.
Loaded 0 entries from dependency cache.
Parsing recipes...WARNING: 
/srv/pokybuild/yocto-worker/auh/build/build/workspace/recipes/recipetool/tmp-recipetool-7rf8z65l.bb:
 tmp-recipetool-7rf8z65l: LICENSE is using "CLOSED", which is deprecated. 
Convert to using a license ref pointing to an actual license file, e.g.
LICENSE = "LicenseRef-tmp-recipetool-7rf8z65l-CLOSED"
done.
Parsing of 957 .bb files complete (0 cached, 957 parsed). 1988 targets, 40 
skipped, 0 masked, 0 errors.

Summary: There was 1 WARNING message.
NOTE: Resolving any missing task queue dependencies

Build Configuration:
BB_VERSION           = "2.19.0"
BUILD_SYS            = "x86_64-linux"
NATIVELSBSTRING      = "universal"
TARGET_SYS           = "x86_64-poky-linux"
MACHINE              = "qemux86-64"
SDKMACHINE           = "x86_64"
DISTRO               = "poky"
DISTRO_VERSION       = 
"6.0.99+snapshot-6b46d76dd91d5187112b59b2a46b00dedbe7084c"
TUNE_FEATURES        = "m64 x86-64-v3"
meta                 = 
"tmp-auh-upgrades:6b46d76dd91d5187112b59b2a46b00dedbe7084c"
meta-yocto-bsp       
meta-poky            = "master:0afedb9b1195525861f9140d6f33e9cd4118b199"
workspace            = "<unknown>:<unknown>"

Initialising tasks...NOTE: The /proc/pressure files can't be read. Continuing 
build without monitoring pressure
Sstate summary: Wanted 1 Local 0 Mirrors 0 Missed 1 Current 0 (0% match, 0% 
complete)
done.
NOTE: Executing Tasks
WARNING: tmp-recipetool-7rf8z65l: LICENSE is using "CLOSED", which is 
deprecated. Convert to using a license ref pointing to an actual license file, 
e.g.
LICENSE = "LicenseRef-tmp-recipetool-7rf8z65l-CLOSED"
WARNING: tmp-recipetool-7rf8z65l: LICENSE is using "CLOSED", which is 
deprecated. Convert to using a license ref pointing to an actual license file, 
e.g.
LICENSE = "LicenseRef-tmp-recipetool-7rf8z65l-CLOSED"
WARNING: tmp-recipetool-7rf8z65l: LICENSE is using "CLOSED", which is 
deprecated. Convert to using a license ref pointing to an actual license file, 
e.g.
LICENSE = "LicenseRef-tmp-recipetool-7rf8z65l-CLOSED"
NOTE: Tasks Summary: Attempted 3 tasks of which 0 didn't need to be rerun and 
all succeeded.
NOTE: Writing buildhistory
NOTE: Writing buildhistory took: 1 seconds
WARNING: tmp-recipetool-7rf8z65l: LICENSE is using "CLOSED", which is 
deprecated. Convert to using a license ref pointing to an actual license file, 
e.g.
LICENSE = "LicenseRef-tmp-recipetool-7rf8z65l-CLOSED"
Adding changed files:   0% |                                   | ETA:  --:--:--
Adding changed files:   0% |                                   | ETA:  --:--:--
Adding changed files: 100% |####################################| Time: 0:00:00
INFO: Extracting current version source...
INFO: Extracting upgraded version source...
INFO: Fetching https://archive.apache.org/dist/apr/apr-util-1.6.5.tar.gz...
INFO: Rebasing devtool onto c7c983069eaca301b7d015b563a961809749b1d6
WARNING: Command 'git rebase c7c983069eaca301b7d015b563a961809749b1d6' failed:
Auto-merging test/testxlate.c
CONFLICT (content): Merge conflict in test/testxlate.c

You will need to resolve conflicts in order to complete the upgrade.
INFO: Upgraded source extracted to 
/srv/pokybuild/yocto-worker/auh/build/build/workspace/sources/apr-util
INFO: New recipe is 
/srv/pokybuild/yocto-worker/auh/build/build/workspace/recipes/apr-util/apr-util_1.6.5.bb
INFO: Changelog extracted to 
/srv/pokybuild/yocto-worker/auh/build/build/workspace/changelogs/apr-util.txt



Please review the attached files for further information and build/update 
failures.
Any problem please file a bug at 
https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler

Regards,
The Upgrade Helper
Changelog for apr-util: 1.6.3 -> 1.6.5
Source: CHANGES

Changes with APR-util 1.6.5

  *) Fix oracle DBD compilation errors introduced in 1.6.4. PR 70170.

Changes with APR-util 1.6.4

  *) SECURITY: CVE-2026-34502: Heap buffer overflow in APR memcached
     client (cve.mitre.org)
     Heap-based Buffer Overflow vulnerability in Apache Portable
     Runtime Utility memcached client
     This issue affects Apache Portable Runtime Utility: from 1.3.0
     through 1.6.3.
     Credits: Elhanan Haenel

  *) SECURITY: CVE-2026-34501: Apache Portable Runtime Utility: Heap
     buffer overflow in APR redis client (cve.mitre.org)
     Heap-based Buffer Overflow vulnerability in Apache Portable
     Runtime Utility redis client.
     This issue affects Apache Portable Runtime Utility: from 1.6.0
     through 1.6.3.
     Users are recommended to upgrade to version 1.6.4, which fixes
     the issue.
     Credits: Elhanan Haenel

  *) SECURITY: CVE-2026-34191: Apache Portable Runtime Utility: SQL
     Injection in apr_dbd_oracle (cve.mitre.org)
     Improper Neutralization of Special Elements used in an SQL
     Command ('SQL Injection') vulnerability in Apache Portable
     Runtime Utility via apr_dbd_oracle provider.
     This issue affects Apache Portable Runtime Utility: from 1.6.0
     through 1.6.3.
     Users are recommended to upgrade to version 1.6.4, which fixes
     the issue.
     Credits: Elhanan Haenel

  *) SECURITY: CVE-2026-32327: Apache Portable Runtime Utility:
     apr-util XML stack recursion crash (cve.mitre.org)
     A bug in APR-util version 1.6.3 (and earlier) allows a stack
     recursion attack against any library consumer which parses XML
     from untrusted sources and uses the apr_xml_quote_elem()
     function.
     Users are recommended to upgrade to version 1.6.4, which fixes
     this issue.
     Credits: Younghyo Cho @ CISLab, SeoulTech

  *) SECURITY: CVE-2025-49506: apr_password_validate() vulnerable to
     timing attack (cve.mitre.org)
     APR-util versions 1.6.3 (and earlier) function
     apr_password_validate() was not constant-time with regards to
     hashes or passwords comparisons, potentially leaking their
     content via a side channel timing attack particularly on
     platforms without crypt() such as  Windows, BeOS, NetWare, or
     Android.
     Users are recommended to upgrade to version 1.6.4, which fixes
     this issue.
     Credits: Michael Rowley <michael csirt.global>

  *) apr_brigade: Don't split the final LF in apr_brigade_split_line() to
     avoid producing an empty bucket.  PR 64273
     [Barnim Dzwillo <dzwillo strato.de>, Joe Orton]

  *) apr_brigade: Metadata buckets are now ignored in
     apr_brigade_split_line, apr_brigade_flatten and
     apr_brigade_to_iovec, fixing possible undefined behaviour.  PR 68278
     [Ben Kallus <benjamin.p.kallus.gr dartmouth.edu>, Joe Orton]

  *) apr_crypto_openssl: Compatibility with OpenSSL 3.  [Yann Ylavic]

  *) apr_crypto_openssl: use OPENSSL_init_crypto() to initialise OpenSSL
     on versions 1.1+. [Graham Leggett]

  *) apr_memcache: Fix name lookup to allow IPv6 as well as IPv4.
     [Lubos Uhliarik <luhliari redhat.com>]

  *) configure: Fix Berkeley DB detection with compilers enforcing
     strict C99 compliance.  PR 66396.
     [Florian Weimer <fweimer redhat.com>]

Changes with APR-util 1.6.3

  *) Correct a packaging issue in 1.6.2. The contents of the release were
     correct, but the top level directory was misnamed.
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#243166): 
https://lists.openembedded.org/g/openembedded-core/message/243166
Mute This Topic: https://lists.openembedded.org/mt/120698519/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to