[OE-core] [PATCH] socat: upgrade 1.8.0.2 -> 1.8.0.3

2025-02-23 Thread hongxu via lists.openembedded.org
According to [1]: 2025-02-21: Socat version 1.8.0.3 has been released. It fixes a lot of minor issues and provides some minor improvements, see file CHANGES [2]. The experimental POSIXMQ feature has been improved, got a few new options, and is now considered stable. License in README has no chang

[OE-core][master][styhead][scarthgap][PATCH] libtasn1: upgrade 4.19.0 -> 4.20.0

2025-02-23 Thread Vijay Anusuri via lists.openembedded.org
From: Vijay Anusuri * Noteworthy changes in release 4.20.0 (2025-02-01) [stable] - The release tarball is now reproducible. - We publish a minimal source-only tarball generated by 'git archive'. - Update gnulib files and various build/maintenance fixes. - Fix CVE-2024-12133: Potential DoS in hand

Re: [OE-core] [qa-build-notification] QA notification for completed autobuilder build (yocto-5.1.3.rc2)

2025-02-23 Thread Jing Hui Tham via lists.openembedded.org
Hi all, Intel and WR YP QA is planning for QA execution for YP build yocto-5.1.3.rc2. We are planning to execute following tests for this cycle: OEQA-manual tests for following module: 1. OE-Core 2. BSP-hw Runtime auto test for following platforms: 1. MinnowBoard Turbot - 32bit

[OE-core] [PATCH] rpm-sequoia-crypto-policy: clean up dependencies

2025-02-23 Thread Zoltan Boszormenyi via lists.openembedded.org
Rely on host-provided python3, coreutils and make. openssl-native is not needed either, as the build scripts use crypto functionality via python. Signed-off-by: Zoltán Böszörményi --- .../rpm-sequoia/rpm-sequoia-crypto-policy_git.bb | 4 +--- 1 file changed, 1 insertion(+), 3 delet

Re: [OE-core] [PATCH V3 2/3] gpgme: upgrade 1.24.1 -> 1.24.2

2025-02-23 Thread hongxu via lists.openembedded.org
Ping //Hongxu On 2/17/25 16:22, hongxu via lists.openembedded.org wrote: Noteworthy changes in version 1.24.2 (2025-02-10) - Take care: This version is from a legacy branch of gpgme created just before we split out the C++, Qt, and Python b

Re: [OE-core] [PATCH 3/3] man-pages: upgrade 6.9.1 -> 6.11

2025-02-23 Thread hongxu via lists.openembedded.org
Ping //Hongxu On 2/17/25 15:14, hongxu via lists.openembedded.org wrote: 1. Due to upstream commit [GNUmakefile: Require the user to specify '-R' if their make(1) is too old][1], add option -R to make 2. Due to upstream commit [src/bin/pdfman, scripts/bash_aliases, pdfman.1: Make pdfman a stand

Re: [OE-core] [PATCH] Revert "python3-ctypes: depend on ldconfig only if distro-feature set"

2025-02-23 Thread Changqing Li via lists.openembedded.org
On 2/21/25 22:34, Mathieu Dubois-Briand wrote: CAUTION: This email comes from a non Wind River email account! Do not click links or open attachments unless you recognize the sender and know the content is safe. On Thu Feb 20, 2025 at 4:57 AM CET, Changqing Li via lists.openembedded.org wrote:

Re: [OE-core] [PATCH] u-boot: kernel-fitimage: Restore FIT_SIGN_INDIVIDUAL="1" behavior

2025-02-23 Thread Marek Vasut via lists.openembedded.org
On 2/23/25 11:13 PM, Rogerio Guerra Borin wrote: On 2/21/25 21:20, Marek Vasut wrote: This message originated from outside your organization OE FIT_SIGN_INDIVIDUAL is implemented in an unusual manner, where the resulting signed fitImage contains both signed images and signed configurations, pos

Re: [OE-core] [PATCH] u-boot: kernel-fitimage: Restore FIT_SIGN_INDIVIDUAL="1" behavior

2025-02-23 Thread Marek Vasut via lists.openembedded.org
On 2/24/25 12:14 AM, Adrian Freihofer wrote: Hi Marek Hi, Thank you for the patch! Signing first the image nodes and then the configuration nodes looks more reasonable to me than the other way round as done by https://lists.openembedded.org/g/openembedded-core/message/211761. It would be n

Re: [OE-core] [PATCH] u-boot: kernel-fitimage: Restore FIT_SIGN_INDIVIDUAL="1" behavior

2025-02-23 Thread Adrian Freihofer via lists.openembedded.org
Hi Marek Thank you for the patch! Signing first the image nodes and then the configuration nodes looks more reasonable to me than the other way round as done by https://lists.openembedded.org/g/openembedded-core/message/211761. Here is a branch where I am trying to improve the related oe-selftes

Re: [OE-core] [PATCH] u-boot: kernel-fitimage: Restore FIT_SIGN_INDIVIDUAL="1" behavior

2025-02-23 Thread Rogerio Guerra Borin via lists.openembedded.org
On 2/21/25 21:20, Marek Vasut wrote: This message originated from outside your organization OE FIT_SIGN_INDIVIDUAL is implemented in an unusual manner, where the resulting signed fitImage contains both signed images and signed configurations, possibly using different keys. This kind of signing o

[OE-core] OE-core CVE metrics for styhead on Sun 23 Feb 2025 02:25:11 AM HST

2025-02-23 Thread Steve Sakoman
Branch: styhead New this week: 11 CVEs CVE-2024-57906 (CVSS3: 7.1 HIGH): linux-yocto https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-57906 * CVE-2024-57907 (CVSS3: 7.1 HIGH): linux-yocto https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-57907 * CVE-2024-57908 (CVSS3: 7.1 HIGH):

[OE-core] OE-core CVE metrics for scarthgap on Sun 23 Feb 2025 01:49:29 AM HST

2025-02-23 Thread Steve Sakoman
Branch: scarthgap New this week: 0 CVEs Removed this week: 0 CVEs Full list: Found 222 unpatched CVEs CVE-2019-14899 (CVSS3: 7.4 HIGH): linux-yocto https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-14899 * CVE-2021-3714 (CVSS3: 5.9 MEDIUM): linux-yocto https://web.nvd.nist.gov/view/vu

[OE-core] OE-core CVE metrics for kirkstone on Sun 23 Feb 2025 01:21:29 AM HST

2025-02-23 Thread Steve Sakoman
Branch: kirkstone New this week: 5 CVEs CVE-2024-57906 (CVSS3: 7.1 HIGH): linux-yocto https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-57906 * CVE-2024-57907 (CVSS3: 7.1 HIGH): linux-yocto https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-57907 * CVE-2024-57908 (CVSS3: 7.1 HIGH)

[OE-core] OE-core CVE metrics for master on Sun 23 Feb 2025 01:00:01 AM HST

2025-02-23 Thread Steve Sakoman
Branch: master New this week: 0 CVEs Removed this week: 0 CVEs Full list: Found 19 unpatched CVEs CVE-2019-14899 (CVSS3: 7.4 HIGH): linux-yocto https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-14899 * CVE-2021-3714 (CVSS3: 5.9 MEDIUM): linux-yocto https://web.nvd.nist.gov/view/vuln/d

Re: [OE-core] Broken python3-grpcio on main branch

2025-02-23 Thread Peter Marko via lists.openembedded.org
I have sent a revert of problematic commit. Sorry for this trouble. Peter From: openembedded-core@lists.openembedded.org On Behalf Of unit exe via lists.openembedded.org Sent: Sunday, February 23, 2025 0:05 To: openembedded-core@lists.openembedded.org Subject: [OE-core] Broken python3-grpcio o

[OE-core] [PATCH] ccache.conf: Add include_file_ctime to sloppiness

2025-02-23 Thread Fabio Berton via lists.openembedded.org
From: Fabio Berton When multiple recipes are built in parallel, Ccache sometimes refuses to lookup some objects in cache, leading to undesired cache misses. The root cause of this is an interaction between the way how bitbake constructs a recipe sysroot and Ccache's `include_file_ctime` check. W