Re: [OE-core][master][scarthgap][PATCH] libstd-rs,rust-cross-canadian: set CVE_PRODUCT to rust

2024-07-30 Thread Peter Marko via lists.openembedded.org
Gentle ping for scrathgap > -Original Message- > From: Marko, Peter (ADV D EU SK BFS1) > Sent: Sunday, July 14, 2024 11:36 > To: openembedded-core@lists.openembedded.org > Cc: Marko, Peter (ADV D EU SK BFS1) > Subject: [OE-core][master][scarthgap][PATCH] libstd-rs,rust-cross-canadian: >

[OE-core][scarthgap][PATCH 1/1] qemu: upgrade 8.2.2 -> 8.2.3

2024-07-30 Thread Urade, Yogita via lists.openembedded.org
From: Yogita Urade This includes fix for: CVE-2024-26327, CVE-2024-26328 and CVE-2024-3447 General changelog for 8.2: https://wiki.qemu.org/ChangeLog/8.2 Droped 0001-linux-user-x86_64-Handle-the-vsyscall-page-in-open_s.patch, CVE-2024-3446 and CVE-2024-3567 since already contained the fix. Sig

[OE-core][kirkstone][PATCH] gtk+3 : backport fix for CVE-2024-6655

2024-07-30 Thread Ashish Sharma via lists.openembedded.org
stop looking for modules in cwd in gtk/gtkmodules.c. Upstream-Status: Backport [https://launchpad.net/ubuntu/+source/gtk+3.0/3.24.33-1ubuntu2.2] Signed-off-by: Ashish Sharma --- .../gtk+/gtk+3/CVE-2024-6655.patch| 39 +++ meta/recipes-gnome/gtk+/gtk+3_3.24.34.bb

Re: [OE-core][scarthgap][PATCH] orc: upgrade 0.4.38 -> 0.4.39

2024-07-30 Thread Vijay Anusuri via lists.openembedded.org
Ok Steve. Patch for master has already been submitted. https://lists.openembedded.org/g/openembedded-core/message/202585 Thanks & Regards, Vijay On Tue, Jul 30, 2024 at 7:47 PM Steve Sakoman wrote: > I won't be able to take this patch until it hits master first. > > Steve > > On Tue, Jul 30,

[OE-core] [openembedded-core V3][master][PATCH]xinetd: use monotonic time

2024-07-30 Thread Li Wang via lists.openembedded.org
when using xinet.d to limit rsync connections and time is set back, the connection limit is reached very quickly and rsync gets deactivated, if time is changed again, rsync is never reactivated. date -s "xxx" xinetd[xxx]: Deactivating service rsync due to excessive incoming connections. Restartin

[OE-core] Patchtest results for [PATCH v2] icu: Backport patch to fix build issues with long paths (>512 chars)

2024-07-30 Thread Patchtest
Thank you for your submission. Patchtest identified one or more issues with the patch. Please see the log below for more information: --- Testing patch /home/patchtest/share/mboxes/v2-icu-Backport-patch-to-fix-build-issues-with-long-paths-512-chars.patch FAIL: test commit message presence: Pleas

[OE-core] [PATCH v2] icu: Backport patch to fix build issues with long paths (>512 chars)

2024-07-30 Thread Carlos Alberto Lopez Perez
Signed-off-by: Carlos Alberto Lopez Perez --- ...813_rise_buffer_sizes_pkgdata_PR3058.patch | 72 +++ meta/recipes-support/icu/icu_75-1.bb | 1 + 2 files changed, 73 insertions(+) create mode 100644 meta/recipes-support/icu/icu/ICU-22813_rise_buffer_sizes_pkgdata_PR305

[OE-core][PATCH 2/2] scripts/patchtest.README: cleanup, add selftest notes

2024-07-30 Thread Trevor Gamblin
Make some minor fixes to grammar and layout, and add a short new section describing how to setup and use the patchtest selftests properly. Signed-off-by: Trevor Gamblin --- scripts/patchtest.README | 60 ++-- 1 file changed, 33 insertions(+), 27 deletions(-)

[OE-core][PATCH 1/2] patchtest/patch.py: remove cruft

2024-07-30 Thread Trevor Gamblin
Remove some minor chunks of code in patch.py that serve no purpose. Signed-off-by: Trevor Gamblin --- meta/lib/patchtest/patch.py | 19 --- 1 file changed, 19 deletions(-) diff --git a/meta/lib/patchtest/patch.py b/meta/lib/patchtest/patch.py index baf6283873..90faf3eeb4 100644

Re: [OE-core] [PATCH v4] tclibc-picolibc: Adds a new TCLIBC variant to build with picolibc as C library

2024-07-30 Thread Alejandro Hernandez Samaniego
Sure thing, I'm in the process of doing so On Tue, Jul 30, 2024, 1:00 PM Alexander Kanavin wrote: > Can you submit the pending avoid_polluting_cross_directories.patch > upstream please? > > Alex > > On Tue, 18 Jun 2024 at 20:09, Alejandro Hernandez Samaniego via > lists.openembedded.org > wrote

Re: [OE-core] [PATCH v4] tclibc-picolibc: Adds a new TCLIBC variant to build with picolibc as C library

2024-07-30 Thread Alexander Kanavin
Can you submit the pending avoid_polluting_cross_directories.patch upstream please? Alex On Tue, 18 Jun 2024 at 20:09, Alejandro Hernandez Samaniego via lists.openembedded.org wrote: > > Enables usage of TCLIBC=picolibc extending OE functionality to build and use > picolibc based toolchains to b

[OE-core][master][PATCH] bind: Upgrade 9.18.27 -> 9.18.28

2024-07-30 Thread Ashish Sharma via lists.openembedded.org
Includes security fixes for: CVE-2024-1975 CVE-2024-1737 CVE-2024-0760 CVE-2024-4076 Changelog: = https://gitlab.isc.org/isc-projects/bind9/-/blob/v9.18.28/CHANGES Signed-off-by: Ashish Sharma

Re: [OE-core][kirkstone][PATCH] libarchive: ignore CVE-2024-37407

2024-07-30 Thread Marta Rybczynska
On Thu, Jul 18, 2024 at 6:43 PM Peter Marko via lists.openembedded.org wrote: > From: Peter Marko > > History of code changes: > * introduced: > https://github.com/ilibarchive/libarchive/commit/390d83012fdba8c8db7fc9915338805882b0597a > (v3.7.2-52-g390d8301) > * reverted: 6 > https://github.com/

[OE-core] Yocto Project Status 30 July 2024 (WW31)

2024-07-30 Thread Stephen Jolley
Current Dev Position: YP 5.1 M3 Next Deadline: YP 5.1 M3 Build 26 Aug. 2024 Next Team Meetings: - Bug Triage meeting Thursday Aug.2nd at 7:30 am PST ( https://zoom.us/j/454367603?pwd=ZGxoa2ZXL3FkM3Y0bFd5aVpHVVZ6dz09) - Weekly Project Engineering Sync Tuesday July 30th at 8 am PS

Re: [OE-core][scarthgap][PATCH] bind: Upgrade 9.18.25 -> 9.18.28

2024-07-30 Thread Steve Sakoman
I can't take a version bump to 9.18.28 until master is also updated. Could you submit a master patch? I can then update scarthgap and kirkstone. Thanks! Steve On Tue, Jul 30, 2024 at 3:40 AM Ashish Sharma via lists.openembedded.org wrote: > > Includes security fixes for: >

Re: [OE-core][scarthgap][PATCH] orc: upgrade 0.4.38 -> 0.4.39

2024-07-30 Thread Steve Sakoman
I won't be able to take this patch until it hits master first. Steve On Tue, Jul 30, 2024 at 3:10 AM Vijay Anusuri via lists.openembedded.org wrote: > > From: Vijay Anusuri > > Changelog: > > - Security: Fix error message printing buffer overflow leading to possible > code executation in orc

Re: [OE-core] [kirkstone][PATCH] llvm: Fix CVE-2024-31852

2024-07-30 Thread Steve Sakoman
On Tue, Jul 30, 2024 at 5:15 AM Hemraj, Deepthi via lists.openembedded.org wrote: > > From: Deepthi Hemraj > > Signed-off-by: Deepthi Hemraj > --- > .../llvm/0008-llvm-Fix-CVE-2024-31852-1.patch | 85 + > .../llvm/0009-llvm-Fix-CVE-2024-31852-2.patch | 117 ++ > met

[OE-core] meson: buildtype flags get overriden by CFLAGS

2024-07-30 Thread Petr Kubizňák
I have issues with setting optimization flags in meson-built project. 1. In do_write_config task, meson.cross is generated with `c = ${CC}` and `c_args = ${CFLAGS}`. 2. In do_configure, meson setup is called with recipe-defined buildtype and generated meson.cross file. 3. In do_compile, compile

[OE-core] [kirkstone][PATCH] llvm: Fix CVE-2024-31852

2024-07-30 Thread Hemraj, Deepthi via lists.openembedded.org
From: Deepthi Hemraj Signed-off-by: Deepthi Hemraj --- .../llvm/0008-llvm-Fix-CVE-2024-31852-1.patch | 85 + .../llvm/0009-llvm-Fix-CVE-2024-31852-2.patch | 117 ++ meta/recipes-devtools/llvm/llvm_git.bb| 2 + 3 files changed, 204 insertions(+) create mod

[OE-core][kirkstone][PATCH V2] bind: Upgrade 9.18.24 -> 9.18.28

2024-07-30 Thread Ashish Sharma via lists.openembedded.org
Includes security fixes for: CVE-2024-1975 CVE-2024-1737 CVE-2024-0760 CVE-2024-4076 Changelog: = https://gitlab.isc.org/isc-projects/bind9/-/blob/v9.18.28/CHANGES Signed-off-by: Ashish Sharma

Re: [OE-core] [scarthgap][master] license archiving is failed to tmp/deploy/licenses

2024-07-30 Thread Alexander Kanavin
On Tue, 30 Jul 2024 at 00:35, Livius via lists.openembedded.org wrote: > No, it is not in my scope. I am not the responsible or mainntainer for it, > and i do not understand the latest patch what it like to do and what should > it resolved. I can not solve it, sorry. It was reported a half year

[OE-core][scarthgap][PATCH] bind: Upgrade 9.18.25 -> 9.18.28

2024-07-30 Thread Ashish Sharma via lists.openembedded.org
Includes security fixes for: CVE-2024-1975 CVE-2024-1737 CVE-2024-0760 CVE-2024-4076 Changelog: = https://gitlab.isc.org/isc-projects/bind9/-/blob/v9.18.28/CHANGES Signed-off-by: Ashish Sharma

Re: [OE-core] [openembedded-core V2][master][PATCH]xinetd: use monotonic time

2024-07-30 Thread Alexander Kanavin
On Tue, 30 Jul 2024 at 04:06, Wang, Li wrote: > >> +Upstream-Status: Pending > > Is this patch taken from here? > > https://github.com/openSUSE/xinetd/pull/45 > > > > If so, it has an incorrect upstream-status. Please fix that. > > yes, but the upstream does not merge the patch, yet. > > in this

[OE-core][scarthgap][PATCH] orc: upgrade 0.4.38 -> 0.4.39

2024-07-30 Thread Vijay Anusuri via lists.openembedded.org
From: Vijay Anusuri Changelog: - Security: Fix error message printing buffer overflow leading to possible code executation in orcc with specific input files (CVE-2024-40897). This only affects developers and CI environments using orcc, not users of liborc (Sebastian Dröge, L. E. Segovia) -

Re: [OE-core] [PATCH 06/33] libnl: upgrade 3.9.0 -> 3.10.0

2024-07-30 Thread Joao Marcos Costa via lists.openembedded.org
Hello, Wang On 7/29/24 03:09, wangmy via lists.openembedded.org wrote: From: Wang Mingyu Signed-off-by: Wang Mingyu --- meta/recipes-support/libnl/{libnl_3.9.0.bb => libnl_3.10.0.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-support/libnl/{libnl_3.9.0.bb =>

Re: [OE-core] [PATCH 1/1] classes: add new retain class for retaining build results

2024-07-30 Thread Richard Purdie
Hi Paul, On Sun, 2024-07-28 at 17:22 -0700, Paul Eggleton via lists.openembedded.org wrote: > From: Paul Eggleton > > If you are running your builds inside an environment where you don't > have access to the build tree (e.g. an autobuilder where you can only > download final artifacts such as im