[OE-core] [kirkstone][PATCH] binutils : CVE-2022-38533

2022-09-05 Thread Pgowda
From: pgowda Upstream-Status: Backport [https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ef186fe54aa6d281a3ff8a9528417e5cc614c797] Signed-off-by: pgowda --- .../binutils/binutils-2.38.inc| 1 + .../binutils/0015-CVE-2022-38533.patch| 36 +++ 2

[OE-core] [PATCH][kirkstone] sqlite: add CVE-2022-35737 patch to SRC_URI

2022-09-05 Thread Lee Chee Yang
From: Chee Yang Lee SRC_URI include patch introduced in oe-core commit fdc82b2314b580c0135c16b7278ebf8786311dec Signed-off-by: Chee Yang Lee --- meta/recipes-support/sqlite/sqlite3_3.38.5.bb | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/meta/recipes-support/sqlite/sqli

[OE-core] Current high bug count owners for Yocto Project 4.1

2022-09-05 Thread Stephen Jolley
All, Below is the list as of top 35 bug owners as of the end of WW36 of who have open medium or higher bugs and enhancements against YP 4.1. There are 37 possible work days left until the final release candidates for YP 4.1 needs to be released. Who Count michael.opdenac...@bootlin.com 37

[OE-core] Yocto Project Newcomer & Unassigned Bugs - Help Needed

2022-09-05 Thread Stephen Jolley
All, The triage team is starting to try and collect up and classify bugs which a newcomer to the project would be able to work on in a way which means people can find them. They're being listed on the triage page under the appropriate heading: https://wiki.yoctoproject.org/wiki/Bug_Triage#Newc

[oe-core][PATCHv3] libsdl2: upgrade 2.0.22 -> 2.24.0

2022-09-05 Thread Markus Volk
In addition to lots of bug fixes, here are the major changes in this release: General: New version numbering scheme, similar to GLib and Flatpak. An even number in the minor version (second component) indicates a production-ready stable release such as 2.24.0, which would have been 2.0.24 under

[oe-core][PATCHv2] libsdl2: upgrade 2.0.22 -> 2.24.0

2022-09-05 Thread Markus Volk
In addition to lots of bug fixes, here are the major changes in this release: General: New version numbering scheme, similar to GLib and Flatpak. An even number in the minor version (second component) indicates a production-ready stable release such as 2.24.0, which would have been 2.0.24 under

[oe-core][PATCH] libsdl2: upgrade 2.0.22 -> 2.24.0

2022-09-05 Thread Markus Volk
In addition to lots of bug fixes, here are the major changes in this release: General: New version numbering scheme, similar to GLib and Flatpak. An even number in the minor version (second component) indicates a production-ready stable release such as 2.24.0, which would have been 2.0.24 under

Re: [OE-core] [PATCH v10] Rust Oe-Selftest implementation

2022-09-05 Thread Richard Purdie
On Mon, 2022-09-05 at 20:25 +0530, pgowda cve wrote: > Hi Richard, > > Thanks very much for reviewing the patch and your comments regarding it. > > > > thread 'main' panicked at 'RUSTDOC_LIBDIR was not set', > > > src/bootstrap/bin/rustdoc.rs:15:48 > > > note: run with `RUST_BACKTRACE=1` environm

[OE-core] [dunfell][PATCH] curl: Backport patch for CVE-2022-35252

2022-09-05 Thread Robert Joslyn
https://curl.se/docs/CVE-2022-35252.html Signed-off-by: Robert Joslyn --- .../curl/curl/CVE-2022-35252.patch| 72 +++ meta/recipes-support/curl/curl_7.69.1.bb | 1 + 2 files changed, 73 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2022-35

[OE-core] [kirkstone][PATCH] curl: Backport patch for CVE-2022-35252

2022-09-05 Thread Robert Joslyn
https://curl.se/docs/CVE-2022-35252.html Signed-off-by: Robert Joslyn --- .../curl/curl/CVE-2022-35252.patch| 72 +++ meta/recipes-support/curl/curl_7.82.0.bb | 1 + 2 files changed, 73 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2022-35

Re: [OE-core] [PATCH] rootfs-postcommands.bbclass: avoid moving ssh host keys if etc is writable

2022-09-05 Thread Peter Bergin
Thanks for the review. I have addressed them in v2 that is sent. /Peter On 2022-09-05 18:15, Peter Kjellerstedt wrote: -Original Message- From: openembedded-core@lists.openembedded.org On Behalf Of Peter Bergin Sent: den 5 september 2022 16:23 To: openembedded-core@lists.openembedded.

[OE-core] [PATCH v2] rootfs-postcommands.bbclass: avoid moving ssh host keys if etc is writable

2022-09-05 Thread Peter Bergin
When using IMAGE_FEATURE read-only-rootfs ssh host keys are moved to volatile storage. If the feature overlayfs-etc is used in addition to read-only-rootfs /etc is writable and the move is not wanted. But in the case also the IMAGE_FEATURE stateless-rootfs is used the keys will be moved as storage

[OE-core] [PATCH 1/2] oe-setup-build: add a tool for discovering config templates and setting up builds

2022-09-05 Thread Alexander Kanavin
This is the last (I believe) piece of the puzzle in setting up builds from nothing without having to write custom scripts or use external tools. After layers have been fetched and placed into their respective locations, one would surely want to proceed to the actual build, and here's how: 1. Wi

[OE-core] [PATCH 2/2] selftest/cases/bblayers.py: build python3-jsonschema only once

2022-09-05 Thread Alexander Kanavin
setUpLocal runs before every testcase, setUpClass runs only once in the beginning. Signed-off-by: Alexander Kanavin --- meta/lib/oeqa/selftest/cases/bblayers.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/meta/lib/oeqa/selftest/cases/bblayers.py b/meta/lib/oeqa/selfte

Re: [OE-core] [PATCH v2] core-image: Exclude openssh complementary packages

2022-09-05 Thread Pavel Zhukov
"Richard Purdie" writes: > On Sun, 2022-08-28 at 21:54 +0200, Pavel Zhukov wrote: >> Openssh (main) package may be marked for installation via complementary >> packages mechanism as a dependency of openssh-ptest >> and this causes conflict with dropbear [Yocto #14858] [1]. >> Excluding openssh c

[OE-core] [PATCH v3] core-image.bbclass: Exclude openssh complementary packages

2022-09-05 Thread Pavel Zhukov
Openssh (main) package may be marked for installation via complementary packages mechanism if sftp-server is installed and this causes conflict with dropbear [Yocto #14858] [1]. Excluding openssh complementary packages if packagegroup-core-ssh-dropbear is in PACKAGE_INSTALL fixes this issue. To ins

Re: [OE-core] [PATCH] rootfs-postcommands.bbclass: avoid moving ssh host keys if etc is writable

2022-09-05 Thread Peter Kjellerstedt
> -Original Message- > From: openembedded-core@lists.openembedded.org > On Behalf Of Peter Bergin > Sent: den 5 september 2022 16:23 > To: openembedded-core@lists.openembedded.org > Cc: Peter Bergin > Subject: [OE-core] [PATCH] rootfs-postcommands.bbclass: avoid moving ssh host > keys i

[OE-core] [PATCH] binutils : CVE-2022-38533

2022-09-05 Thread Pgowda
From: pgowda Upstream-Status: Backport [https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ef186fe54aa6d281a3ff8a9528417e5cc614c797] Signed-off-by: pgowda --- .../binutils/binutils-2.39.inc| 1 + .../binutils/0013-CVE-2022-38533.patch| 36 +++

Re: [OE-core] [PATCH v10] Rust Oe-Selftest implementation

2022-09-05 Thread Pgowda
Hi Richard, Thanks very much for reviewing the patch and your comments regarding it. >> thread 'main' panicked at 'RUSTDOC_LIBDIR was not set', >> src/bootstrap/bin/rustdoc.rs:15:48 >> note: run with `RUST_BACKTRACE=1` environment variable to display a >> backtrace >> error: could not document `c

[OE-core] [PATCH] rootfs-postcommands.bbclass: avoid moving ssh host keys if etc is writable

2022-09-05 Thread Peter Bergin
When using IMAGE_FEATURE read-only-rootfs ssh host keys are moved to volatile storage. If the feature overlayfs-etc is used in addition to read-only-rootfs /etc is writable and the move is not wanted. But in the case also the IMAGE_FEATURE stateless-roots is used the keys will be moved as storage

[OE-Core][dunfell][PATCH 2/2] libarchive: Fix CVE-2021-31566 issue

2022-09-05 Thread Ranjitsinh Rathod via lists.openembedded.org
Add patch to fix CVE-2021-31566 issue for libarchive Link: http://deb.debian.org/debian/pool/main/liba/libarchive/libarchive_3.4.3-2+deb11u1.debian.tar.xz Signed-off-by: Ranjitsinh Rathod --- .../libarchive/CVE-2021-31566-01.patch| 23 +++ .../libarchive/CVE-2021-31566-02.patch

[OE-Core][dunfell][PATCH 1/2] libarchive: Fix CVE-2021-23177 issue

2022-09-05 Thread Ranjitsinh Rathod via lists.openembedded.org
Add patch to fix CVE-2021-23177 issue for libarchive Link: http://deb.debian.org/debian/pool/main/liba/libarchive/libarchive_3.4.3-2+deb11u1.debian.tar.xz Signed-off-by: Ranjitsinh Rathod --- .../libarchive/CVE-2021-23177.patch | 183 ++ .../libarchive/libarchive_3.4.2

[OE-core] [PATCH] systemd: Fix unwritable /var/lock when no sysvinit handling

2022-09-05 Thread niko.ma...@vaisala.com via lists.openembedded.org
Commit 8089cefed8e83c0348037768c292058f1bcbbbe5 ("systemd: Add PACKAGECONFIG for sysvinit") decoupled enabling of systemd's sysvinit handling behavior behind a distinct PACKAGECONFIG feature. This new option affects among other things the installing of tmpfiles.d/legacy.conf, which is responsible

Re: [OE-core] [PATCH] rust-cross-canadian: Fix for the linker issues caused by using the shell

2022-09-05 Thread Richard Purdie
On Mon, 2022-09-05 at 00:12 -0700, Sundeep KOKKONDA wrote: > Using CC args causing linker error "unknown executable format" so I > called linker directly. > Also, I wrote my initial code without any hardcoded symbols and that > test code works in my local machine but when the same code executed > i

[OE-core] [PATCH] tiff: backport fix for CVE-2022-2953

2022-09-05 Thread Ross Burton
Signed-off-by: Ross Burton --- .../libtiff/files/CVE-2022-2953.patch | 86 +++ meta/recipes-multimedia/libtiff/tiff_4.4.0.bb | 1 + 2 files changed, 87 insertions(+) create mode 100644 meta/recipes-multimedia/libtiff/files/CVE-2022-2953.patch diff --git a/meta/recipes-m

[OE-core] [PATCH] xmlto: remove redundant patches

2022-09-05 Thread Ross Burton
0001-Skip-validating-xmlto-output isn't needed as xmllint will use the local catalogues correctly now[1]. configure.in-drop-the-test-of-xmllint-and-xsltproc can be dropped if we pre-load the result of AC_PATH_PROG with ac_cv_path_XMLLINT. [1] oe-core 8159b47e7aca57ade2ecf24d8ff9a0abf26a Sign

[OE-core] [PATCH] vala: upgrade 0.56.2 -> 0.56.3

2022-09-05 Thread wangmy
Changelog: == * Various improvements and bug fixes: - vala: Don't unconditionally expect ObjectType of Class [#1341] - vala: Make try-statement parsing more resilient [#1304] - vala: Avoid problems with '\' in #line directives on Windows [#1353] - gidlparser: Set source reference o

[OE-core] [PATCH] python3-pytest: upgrade 7.1.2 -> 7.1.3

2022-09-05 Thread wangmy
Signed-off-by: Wang Mingyu --- .../python/{python3-pytest_7.1.2.bb => python3-pytest_7.1.3.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/python/{python3-pytest_7.1.2.bb => python3-pytest_7.1.3.bb} (93%) diff --git a/meta/recipes-devtools/python/python3-

[OE-core] [PATCH] python3-pathspec: upgrade 0.9.0 -> 0.10.1

2022-09-05 Thread wangmy
Changelog: == Bug fixes: Fix documentation on pathspec.pattern.RegexPattern.match_file(). Issue #60: Remove redundant wheel dep from pyproject.toml. Issue #61: Dist failure for Fedora, CentOS, EPEL. Issue #62: Since version 0.10.0 pure wildcard does not work in some cases. Imp

[OE-core] [PATCH] python3-mako: upgrade 1.2.1 -> 1.2.2

2022-09-05 Thread wangmy
Signed-off-by: Wang Mingyu --- .../python/{python3-mako_1.2.1.bb => python3-mako_1.2.2.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/python/{python3-mako_1.2.1.bb => python3-mako_1.2.2.bb} (85%) diff --git a/meta/recipes-devtools/python/python3-mako

Re: [OE-core] [PATCH] libxml2: wrap xmllint to use the correct XML catalogues

2022-09-05 Thread Ross Burton
On 3 Sep 2022, at 13:12, Richard Purdie wrote: > > On Sat, 2022-09-03 at 12:11 +0200, Andreas Müller wrote: >> Hi, >> >> this is a major change on behaviour and causing trouble at least for >> KDE's kdoctools. Am no expert but I guess kdoctools uses custom >> catalogs. Worked around trouble in

[OE-core] [PATCH] python3-dtschema: upgrade 2022.8.1 -> 2022.8.3

2022-09-05 Thread wangmy
Signed-off-by: Wang Mingyu --- ...ython3-dtschema_2022.8.1.bb => python3-dtschema_2022.8.3.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/python/{python3-dtschema_2022.8.1.bb => python3-dtschema_2022.8.3.bb} (83%) diff --git a/meta/recipes-devtools/pytho

[OE-core] [PATCH] piglit: upgrade to latest revision

2022-09-05 Thread wangmy
0004-CMakeLists.txt-add-missing-endian.h-check.patch removed sinct it's included in new version. Signed-off-by: Wang Mingyu --- ...Lists.txt-add-missing-endian.h-check.patch | 25 --- meta/recipes-graphics/piglit/piglit_git.bb| 6 ++--- 2 files changed, 3 insertions(+), 28 d

[OE-core] [PATCH] mesa: upgrade 22.1.6 -> 22.1.7

2022-09-05 Thread wangmy
Signed-off-by: Wang Mingyu --- .../mesa/{mesa-gl_22.1.6.bb => mesa-gl_22.1.7.bb} | 0 meta/recipes-graphics/mesa/mesa.inc | 2 +- meta/recipes-graphics/mesa/{mesa_22.1.6.bb => mesa_22.1.7.bb} | 0 3 files changed, 1 insertion(+), 1 deletion(-) rename m

[OE-core] [PATCH] kmscube: upgrade to latest revision

2022-09-05 Thread wangmy
0001-drm-common.c-do-not-use-invalid-modifier.patch 0001-texturator-Use-correct-GL-extension-header.patch removed since they're included in new version. Signed-off-by: Wang Mingyu --- ...common.c-do-not-use-invalid-modifier.patch | 27 --- ...ator-Use-correct-GL-extension-header.patc

[OE-core] [PATCH] cracklib: upgrade 2.9.7 -> 2.9.8

2022-09-05 Thread wangmy
0001-rules-Drop-using-register-keyword.patch 0002-rules-Correct-parameter-types-to-Debug-calls.patch removed since they're included in 2.9.8 Signed-off-by: Wang Mingyu --- ...01-rules-Drop-using-register-keyword.patch | 278 -- ...rrect-parameter-types-to-Debug-calls.patch | 40

Re: [OE-core] [PATCH] rust-cross-canadian: Fix for the linker issues caused by using the shell

2022-09-05 Thread Sundeep KOKKONDA
Hello Richard, Using CC args causing linker error " unknown executable format " so I called linker directly. Also, I wrote my initial code without any hardcoded symbols and that test code works in my local machine but when the same code executed in Yocto build environment SIGSEGV faults are rep