Hello,

this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe(s) *gzip* to *1.15* has 
Succeeded.

Next steps:
    - apply the patch: git am 0001-gzip-upgrade-1.14-1.15.patch
    - check the changes to upstream patches and summarize them in the commit 
message,
    - compile an image that contains the package
    - perform some basic sanity tests
    - amend the patch and sign it off: git commit -s --reset-author --amend
    - send it to the appropriate mailing list

Alternatively, if you believe the recipe should not be upgraded at this time,
you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that
automatic upgrades would no longer be attempted.

Please review the attached files for further information and build/update 
failures.
Any problem please file a bug at 
https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler

Regards,
The Upgrade Helper

-- >8 --
From 22d16541e944eb699afec797afde2b0d00928473 Mon Sep 17 00:00:00 2001
From: Upgrade Helper <[email protected]>
Date: Mon, 21 Sep 2026 05:20:52 +0000
Subject: [PATCH] gzip: upgrade 1.14 -> 1.15
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

Source: ChangeLog

2026-09-20  Jim Meyering  <[email protected]>

        version 1.15
        * NEWS: Record release date.

2026-09-10  Paul Eggert  <[email protected]>

        doc: add THANKS for bug report

        gzip: avoid last_component if !USE_ATFUNCS
        Problem reported by Bryan M.
        * gzip.c (atdir_set): New arg PARENTFD.  All uses changed.
        Use the new arg to avoid passing AT_FDCWD to unlinkat when a
        parent directory was intended.
        (treat_file) [!USE_ATFUNCS]: Use ifname, not its last component.

        gzip: use unlinkat only when using openat
        This is mostly just a cleanup, but the cleanup removes a nagging
        issue on MS-Windowsish platforms with openat+unlinkat but where
        you cannot unlink a readonly file.  In this case the code used
        plain open, but used unlinkat, which is questionable.
        * gzip.c (USE_ATFUNCS): Rename from TRY_OPENING_DIRECTORIES.
        The old name was misleading, as gzip -r opens directories
        even when USE_ATFUNCS is false.  All uses changed.
        (gzip_unlinkat, unlinkat) [!USE_ATFUNCS]:
        New compatibility function and macro.
        * util.c (xunlinkat): Remove.  All uses changed to use unlinkat.

2026-09-05  Paul Eggert  <[email protected]>

        gzip: fix undefined behavior with SIGPIPE
        This problem arose due to a combination of commit
        bb78ea465787191e8987d4b8a6594f9f23a18930 dated 2013-06-11,
        which defined SIGPIPE to 0 if not already defined, with commit
        ede0a8888a4d3d0750e1651e01f198e2faab5d59 dated 2026-05-25,
        which included tailor.h before all system .h files.
        Problem and fix reported by Collin Funk (bug#81139).
        * gzip.c (handled_sig): ifdef, not if, for SIGPIPE.
        * tailor.h (SIGPIPE): Do not #define to 0, because when we later
        include <signal.h> its #define yields undefined behavior.

        maint: update .gitignore files and bootstrap

        build: configure.ac cruft removal
        * configure.ac: Do not call AC_PROG_RANLIB, as we no longer use
        its results ourselves.  Do not use AC_C_CONST or AC_TYPE_SIZE_T,
        as it’s safe to assume C89 now.  Do not check for fcntl.h,
        limits.h, memory.h, time.h, as we no longer use the corresponding
        HAVE_FCNTL_H etc. macros.  Do not check for lstat or siginterrupt,
        as we no longer use HAVE_LSTAT or HAVE_SIGINTERRUPT.  Do not use
        AC_HEADER_DIRENT, as we no longer use any symbols that it defines.

        gzip: don’t open same dir twice when recursive
        Opening it multiple times can lead to races.
        * gzip.c (treat_file, create_outfile, open_and_stat, open_input_file):
        New arg parentfd.  All uses changed.  If nonnegative, treat it as
        the parent directory file descriptor, instead of dfd or syncdfd.
        (check_ofname): New arg atfd.  All uses changed.
        (treat_dir): Do not close fd until after processing subsidiaries.
        Instead, pass it as the parent fd to subroutines.
        Report any streamsavedir failure.

        gzip: be more cautious about using AT_FDCWD
        Without this change, gzip was more vulnerable to attackers
        changing the directory hierarchy while gzip walks through it.
        * gzip.c (ATDIR_SET_ERROR): New constant.
        (atdir_set): Return it on fail

[Changelog truncated as it exceeds 3000 characters;
the full changelog can be found in an attachment to the AUH email]
---
 .../CVE-2026-41991.patch                      | 46 +++----------------
 .../CVE-2026-41992.patch                      | 26 +++--------
 .../wrong-path-fix.patch                      |  4 +-
 .../gzip/{gzip_1.14.bb => gzip_1.15.bb}       |  2 +-
 4 files changed, 16 insertions(+), 62 deletions(-)
 rename meta/recipes-extended/gzip/{gzip-1.14 => 
gzip-1.15}/CVE-2026-41991.patch (50%)
 rename meta/recipes-extended/gzip/{gzip-1.14 => 
gzip-1.15}/CVE-2026-41992.patch (65%)
 rename meta/recipes-extended/gzip/{gzip-1.14 => 
gzip-1.15}/wrong-path-fix.patch (92%)
 rename meta/recipes-extended/gzip/{gzip_1.14.bb => gzip_1.15.bb} (94%)

diff --git a/meta/recipes-extended/gzip/gzip-1.14/CVE-2026-41991.patch 
b/meta/recipes-extended/gzip/gzip-1.15/CVE-2026-41991.patch
similarity index 50%
rename from meta/recipes-extended/gzip/gzip-1.14/CVE-2026-41991.patch
rename to meta/recipes-extended/gzip/gzip-1.15/CVE-2026-41991.patch
index b1a3644020..e72c3d355b 100644
--- a/meta/recipes-extended/gzip/gzip-1.14/CVE-2026-41991.patch
+++ b/meta/recipes-extended/gzip/gzip-1.15/CVE-2026-41991.patch
@@ -1,4 +1,4 @@
-From 661918c7c0d5acf52508107d6bcdeb72a526ce52 Mon Sep 17 00:00:00 2001
+From 286734a7f791dfb1694bf7d2d61dfae8c8105cc7 Mon Sep 17 00:00:00 2001
 From: Paul Eggert <[email protected]>
 Date: Thu, 16 Apr 2026 12:11:44 -0700
 Subject: [PATCH] gzexe: use -C if lacking mktemp
@@ -16,16 +16,14 @@ CVE: CVE-2026-41991
 Upstream-Status: Backport 
[https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269]
 Signed-off-by: Jaipaul Cheernam <[email protected]>
 ---
- NEWS     | 13 +++++++++----
- gzexe.in |  1 +
- zdiff.in |  7 +++----
- 3 files changed, 13 insertions(+), 8 deletions(-)
+ NEWS | 13 +++++++++----
+ 1 file changed, 9 insertions(+), 4 deletions(-)
 
 diff --git a/NEWS b/NEWS
-index 881b6b6..3a05d7e 100644
+index 75836f2..7881350 100644
 --- a/NEWS
 +++ b/NEWS
-@@ -4,10 +4,6 @@ GNU gzip NEWS                                    -*- outline 
-*-
+@@ -68,10 +68,6 @@ GNU gzip NEWS                                    -*- 
outline -*-
  
  ** Bug fixes
  
@@ -36,7 +34,7 @@ index 881b6b6..3a05d7e 100644
    'gzip -d' no longer omits the last partial output buffer when the
    input ends unexpectedly on an IBM Z platform.
    [bug introduced in gzip-1.11]
-@@ -18,6 +14,15 @@ GNU gzip NEWS                                    -*- 
outline -*-
+@@ -82,6 +78,15 @@ GNU gzip NEWS                                    -*- 
outline -*-
    'gzip -S' now rejects suffixes containing '/'.
    [bug present since the beginning]
  
@@ -52,35 +50,3 @@ index 881b6b6..3a05d7e 100644
  ** Changes in behavior
  
    The GZIP environment variable is now silently ignored except for the
-diff --git a/gzexe.in b/gzexe.in
-index 1267d6e..09a2571 100644
---- a/gzexe.in
-+++ b/gzexe.in
-@@ -127,6 +127,7 @@ for i do
-     tmp=`mktemp "${dir}gzexeXXXXXXXXX"`
-   else
-     tmp=${dir}gzexe$$
-+    (umask 77; set -C; > "$tmp")
-   fi && { cp -p "$file" "$tmp" 2>/dev/null || cp "$file" "$tmp"; } || {
-     res=$?
-     printf >&2 '%s\n' "$0: cannot copy $file"
-diff --git a/zdiff.in b/zdiff.in
-index a8689a0..c04a8c0 100644
---- a/zdiff.in
-+++ b/zdiff.in
-@@ -156,12 +156,11 @@ case $file2 in
-                           *) TMPDIR=/tmp/;;
-                         esac
-                         if command -v mktemp >/dev/null 2>&1; then
--                          tmp=`mktemp "${TMPDIR}zdiffXXXXXXXXX"` ||
--                            exit 2
-+                          tmp=`mktemp "${TMPDIR}zdiffXXXXXXXXX"`
-                         else
--                          set -C
-                           tmp=${TMPDIR}zdiff$$
--                        fi
-+                          (umask 77; set -C; > "$tmp")
-+                        fi &&
-                         'gzip' -cdfq -- "$file2" > "$tmp" || exit 2
-                         gzip_status=$(
-                           exec 4>&1
diff --git a/meta/recipes-extended/gzip/gzip-1.14/CVE-2026-41992.patch 
b/meta/recipes-extended/gzip/gzip-1.15/CVE-2026-41992.patch
similarity index 65%
rename from meta/recipes-extended/gzip/gzip-1.14/CVE-2026-41992.patch
rename to meta/recipes-extended/gzip/gzip-1.15/CVE-2026-41992.patch
index f55c89978d..00378dd179 100644
--- a/meta/recipes-extended/gzip/gzip-1.14/CVE-2026-41992.patch
+++ b/meta/recipes-extended/gzip/gzip-1.15/CVE-2026-41992.patch
@@ -1,7 +1,8 @@
-From 63dbf6b3b9e6e781df1a6a64e609b10e23969681 Mon Sep 17 00:00:00 2001
+From 3a355dd8d9bc7ec9640447e5542acaefecf3fec5 Mon Sep 17 00:00:00 2001
 From: Paul Eggert <[email protected]>
 Date: Wed, 15 Apr 2026 12:00:17 -0700
-Subject: =?UTF-8?q?gzip:=20don=E2=80=99t=20mishandle=20.lzh=20after=20.Z?=
+Subject: [PATCH] =?UTF-8?q?gzip:=20don=E2=80=99t=20mishandle=20.lzh=20afte?=
+ =?UTF-8?q?r=20.Z?=
 MIME-Version: 1.0
 Content-Type: text/plain; charset=UTF-8
 Content-Transfer-Encoding: 8bit
@@ -14,15 +15,14 @@ Upstream-Status: Backport 
[https://cgit.git.savannah.gnu.org/cgit/gzip.git/commi
 Signed-off-by: Jaipaul Cheernam <[email protected]>
 ---
  NEWS    | 4 ++++
- THANKS  | 1 +
  unlzh.c | 6 ++++++
- 3 files changed, 11 insertions(+)
+ 2 files changed, 10 insertions(+)
 
 diff --git a/NEWS b/NEWS
-index 6388227..8fb8918 100644
+index a8657a8..75836f2 100644
 --- a/NEWS
 +++ b/NEWS
-@@ -4,6 +4,10 @@ GNU gzip NEWS                                    -*- outline 
-*-
+@@ -68,6 +68,10 @@ GNU gzip NEWS                                    -*- 
outline -*-
  
  ** Bug fixes
  
@@ -33,20 +33,8 @@ index 6388227..8fb8918 100644
    'gzip -d' no longer omits the last partial output buffer when the
    input ends unexpectedly on an IBM Z platform.
    [bug introduced in gzip-1.11]
-diff --git a/THANKS b/THANKS
-index 4e545d9..a7d25e4 100644
---- a/THANKS
-+++ b/THANKS
-@@ -186,6 +186,7 @@ Jamie Lokier            [email protected]
- Richard Lloyd           [email protected]
- David J. MacKenzie    [email protected]
- John R MacMillan        [email protected]
-+Michał Majchrowicz    [email protected]
- Ron Male                [email protected]
- Jakub Martisko                [email protected]
- Don R. Maszle           [email protected]
 diff --git a/unlzh.c b/unlzh.c
-index 3320196..a6cf109 100644
+index 7fde9c6..2e31c27 100644
 --- a/unlzh.c
 +++ b/unlzh.c
 @@ -232,6 +232,12 @@ read_c_len ()
diff --git a/meta/recipes-extended/gzip/gzip-1.14/wrong-path-fix.patch 
b/meta/recipes-extended/gzip/gzip-1.15/wrong-path-fix.patch
similarity index 92%
rename from meta/recipes-extended/gzip/gzip-1.14/wrong-path-fix.patch
rename to meta/recipes-extended/gzip/gzip-1.15/wrong-path-fix.patch
index 4d5e7a8e02..cff379d133 100644
--- a/meta/recipes-extended/gzip/gzip-1.14/wrong-path-fix.patch
+++ b/meta/recipes-extended/gzip/gzip-1.15/wrong-path-fix.patch
@@ -1,4 +1,4 @@
-From eda9b1d08c517acbdc5b26c24c94a3985f29c749 Mon Sep 17 00:00:00 2001
+From 885f15530d7e5442d5399b5216fcfc988eb2d721 Mon Sep 17 00:00:00 2001
 From: Ming Liu <[email protected]>
 Date: Fri, 21 Nov 2014 04:50:57 -0500
 Subject: [PATCH] fix MakeMaker issues with using wrong SHELL/GREP
@@ -20,7 +20,7 @@ Upstream-Status: Pending
  1 file changed, 1 insertion(+), 2 deletions(-)
 
 diff --git a/Makefile.am b/Makefile.am
-index 23e0d3e..3455878 100644
+index 6491c8b..596fd9a 100644
 --- a/Makefile.am
 +++ b/Makefile.am
 @@ -95,8 +95,7 @@ SUFFIXES = .in
diff --git a/meta/recipes-extended/gzip/gzip_1.14.bb 
b/meta/recipes-extended/gzip/gzip_1.15.bb
similarity index 94%
rename from meta/recipes-extended/gzip/gzip_1.14.bb
rename to meta/recipes-extended/gzip/gzip_1.15.bb
index d6bd36f89f..d1340c36bd 100644
--- a/meta/recipes-extended/gzip/gzip_1.14.bb
+++ b/meta/recipes-extended/gzip/gzip_1.15.bb
@@ -42,4 +42,4 @@ do_install_ptest() {
             ${B}/tests/Makefile > ${D}${PTEST_PATH}/src/tests/Makefile
 }
 
-SRC_URI[sha256sum] = 
"613d6ea44f1248d7370c7ccdeee0dd0017a09e6c39de894b3c6f03f981191c6b"
+SRC_URI[sha256sum] = 
"545886cf57fa88a65e967fbf705903d7fcb2567c82c7342493e82e8d7b1a210b"
-- 
2.47.1

packages/x86-64-v3-poky-linux/gzip/gzip-dbg: PKGV changed from 1.14 [default] 
to 1.15 [default]
packages/x86-64-v3-poky-linux/gzip/gzip-dbg: PV changed from "1.14" to "1.15"
packages/x86-64-v3-poky-linux/gzip/gzip-dbg: PKGSIZE changed from 416504 to 
397144 (-5%)
packages/x86-64-v3-poky-linux/gzip/gzip-dev: PKGV changed from 1.14 [default] 
to 1.15 [default]
packages/x86-64-v3-poky-linux/gzip/gzip-dev: PV changed from "1.14" to "1.15"
packages/x86-64-v3-poky-linux/gzip/gzip-doc: PKGV changed from 1.14 [default] 
to 1.15 [default]
packages/x86-64-v3-poky-linux/gzip/gzip-doc: PV changed from "1.14" to "1.15"
packages/x86-64-v3-poky-linux/gzip/gzip-doc: PKGSIZE changed from 73966 to 
73806 (-0%)
packages/x86-64-v3-poky-linux/gzip/gzip-locale: PKGV changed from 1.14 
[default] to 1.15 [default]
packages/x86-64-v3-poky-linux/gzip/gzip-locale: PV changed from "1.14" to "1.15"
packages/x86-64-v3-poky-linux/gzip/gzip-ptest: PKGV changed from 1.14 [default] 
to 1.15 [default]
packages/x86-64-v3-poky-linux/gzip/gzip-ptest: PV changed from "1.14" to "1.15"
packages/x86-64-v3-poky-linux/gzip/gzip-ptest: PKGSIZE changed from 247784 to 
237447 (-4%)
packages/x86-64-v3-poky-linux/gzip/gzip-ptest: FILELIST: added 
"/usr/lib/gzip/ptest/src/tests/lzw-lzh-abuse 
/usr/lib/gzip/ptest/src/tests/lzh-lzh-ctable-abuse 
/usr/lib/gzip/ptest/src/tests/zdiff-abuse 
/usr/lib/gzip/ptest/src/tests/unzip-valid"
packages/x86-64-v3-poky-linux/gzip/gzip-src: PKGV changed from 1.14 [default] 
to 1.15 [default]
packages/x86-64-v3-poky-linux/gzip/gzip-src: PV changed from "1.14" to "1.15"
packages/x86-64-v3-poky-linux/gzip/gzip-src: PKGSIZE changed from 1243826 to 
916953 (-26%)
packages/x86-64-v3-poky-linux/gzip/gzip-src: FILELIST: directory renamed 
/usr/src/debug/gzip/1.14 -> /usr/src/debug/gzip/1.15, removed 
"/usr/src/debug/gzip/1.14/lib/crc-x86_64-pclmul.c 
/usr/src/debug/gzip/1.14/lib/unistd-safer.h 
/usr/src/debug/gzip/1.14/lib/crc-x86_64.h 
/usr/src/debug/gzip/1.14/lib/dup-safer.c /usr/src/debug/gzip/1.14/lib/savedir.c 
/usr/src/debug/gzip/1.14/lib/fd-safer.c /usr/src/debug/gzip/1.14/lib/fseterr.c 
/usr/src/debug/gzip/1.14/lib/basename-lgpl.h 
/usr/src/debug/gzip/1.14/lib/open-safer.c 
/usr/src/debug/gzip/1.14/lib/vasnprintf.c 
/usr/src/debug/gzip/1.14/lib/fseterr.h /usr/src/debug/gzip/1.14/lib/savedir.h 
/usr/src/debug/gzip/1.14/lib/stdlib.h /usr/src/debug/gzip/1.14/lib/vasnprintf.h 
/usr/src/debug/gzip/1.14/lib/crc-sliceby8.h 
/usr/src/debug/gzip/1.14/lib/timespec.h /usr/src/debug/gzip/1.14/lib/fprintf.c 
/usr/src/debug/gzip/1.14/lib/basename-lgpl.c 
/usr/src/debug/gzip/1.14/lib/gettime.c 
/usr/src/debug/gzip/1.14/lib/reallocarray.c /usr/src/debug/gzip/1.14/lib/f
 flush.c /usr/src/debug/gzip/1.14/lib/printf.c 
/usr/src/debug/gzip/1.14/lib/stdio.h /usr/src/debug/gzip/1.14/lib/printf-args.c 
/usr/src/debug/gzip/1.14/lib/printf-parse.h 
/usr/src/debug/gzip/1.14/lib/fseeko.c /usr/src/debug/gzip/1.14/lib/wchar.h 
/usr/src/debug/gzip/1.14/lib/fclose.c /usr/src/debug/gzip/1.14/lib/fpucw.h 
/usr/src/debug/gzip/1.14/lib/printf-args.h 
/usr/src/debug/gzip/1.14/lib/printf-parse.c 
/usr/src/debug/gzip/1.14/lib/getopt-core.h 
/usr/src/debug/gzip/1.14/lib/vfzprintf.c /usr/src/debug/gzip/1.14/lib/xmalloc.c 
/usr/src/debug/gzip/1.14/lib/getopt.c /usr/src/debug/gzip/1.14/lib/yesno.h 
/usr/src/debug/gzip/1.14/lib/yesno.c /usr/src/debug/gzip/1.14/lib/fcntl.c 
/usr/src/debug/gzip/1.14/lib/utimens.c 
/usr/src/debug/gzip/1.14/lib/openat-safer.c /usr/src/debug/gzip/1.14/lib/crc.h 
/usr/src/debug/gzip/1.14/lib/idx.h /usr/src/debug/gzip/1.14/lib/getopt-ext.h 
/usr/src/debug/gzip/1.14/lib/getopt_int.h /usr/src/debug/gzip/1.14/lib/fcntl.h 
/usr/src/debug/gzip/1.14/lib/utimens.h /usr/
 src/debug/gzip/1.14/lib/crc.c /usr/src/debug/gzip/1.14/lib/fcntl-safer.h 
/usr/src/debug/gzip/1.14/lib/xsize.h /usr/src/debug/gzip/1.14/lib/stat-time.h 
/usr/src/debug/gzip/1.14/lib/ialloc.h /usr/src/debug/gzip/1.14/lib/xalloc.h 
/usr/src/debug/gzip/1.14/lib/dirent.h /usr/src/debug/gzip/1.14/lib/vfprintf.c 
/usr/src/debug/gzip/1.14/lib/string.h /usr/src/debug/gzip/1.14/lib/getopt1.c", 
added "/usr/src/debug/gzip/1.15/lib/crc-x86_64-pclmul.c 
/usr/src/debug/gzip/1.15/lib/crc-x86_64.h 
/usr/src/debug/gzip/1.15/lib/savedir.c 
/usr/src/debug/gzip/1.15/lib/basename-lgpl.h 
/usr/src/debug/gzip/1.15/lib/stdopen.h /usr/src/debug/gzip/1.15/lib/savedir.h 
/usr/src/debug/gzip/1.15/lib/stdlib.h /usr/src/debug/gzip/1.15/lib/timespec.h 
/usr/src/debug/gzip/1.15/lib/basename-lgpl.c 
/usr/src/debug/gzip/1.15/lib/stdopen.c 
/usr/src/debug/gzip/1.15/lib/crc-sliceby8.h 
/usr/src/debug/gzip/1.15/lib/gettime.c /usr/src/debug/gzip/1.15/lib/issymlink.h 
/usr/src/debug/gzip/1.15/lib/fflush.c /usr/src/debug/gzip/1.15/lib/
 reallocarray.c /usr/src/debug/gzip/1.15/lib/stdio.h 
/usr/src/debug/gzip/1.15/lib/cpu-supports.h 
/usr/src/debug/gzip/1.15/lib/fseeko.c /usr/src/debug/gzip/1.15/lib/fclose.c 
/usr/src/debug/gzip/1.15/lib/xmalloc.c 
/usr/src/debug/gzip/1.15/lib/cpu-supports.c 
/usr/src/debug/gzip/1.15/lib/getopt-core.h 
/usr/src/debug/gzip/1.15/lib/getopt.c /usr/src/debug/gzip/1.15/lib/yesno.h 
/usr/src/debug/gzip/1.15/lib/yesno.c /usr/src/debug/gzip/1.15/lib/fcntl.c 
/usr/src/debug/gzip/1.15/lib/utimens.c /usr/src/debug/gzip/1.15/lib/crc.h 
/usr/src/debug/gzip/1.15/lib/idx.h /usr/src/debug/gzip/1.15/lib/quotearg.c 
/usr/src/debug/gzip/1.15/lib/getopt-ext.h 
/usr/src/debug/gzip/1.15/lib/getopt_int.h /usr/src/debug/gzip/1.15/lib/fcntl.h 
/usr/src/debug/gzip/1.15/lib/utimens.h /usr/src/debug/gzip/1.15/lib/quotearg.h 
/usr/src/debug/gzip/1.15/lib/crc.c /usr/src/debug/gzip/1.15/lib/c-ctype.h 
/usr/src/debug/gzip/1.15/lib/quote.h /usr/src/debug/gzip/1.15/lib/stat-time.h 
/usr/src/debug/gzip/1.15/lib/ialloc.h /usr/src/de
 bug/gzip/1.15/lib/xalloc.h /usr/src/debug/gzip/1.15/lib/dirent.h 
/usr/src/debug/gzip/1.15/lib/gettext.h /usr/src/debug/gzip/1.15/lib/string.h 
/usr/src/debug/gzip/1.15/lib/getopt1.c"
packages/x86-64-v3-poky-linux/gzip/gzip-staticdev: PKGV changed from 1.14 
[default] to 1.15 [default]
packages/x86-64-v3-poky-linux/gzip/gzip-staticdev: PV changed from "1.14" to 
"1.15"
packages/x86-64-v3-poky-linux/gzip/gzip: PKGV changed from 1.14 [default] to 
1.15 [default]
packages/x86-64-v3-poky-linux/gzip/gzip: PV changed from "1.14" to "1.15"
packages/x86-64-v3-poky-linux/gzip/gzip: PKGSIZE changed from 165255 to 161055 
(-3%)
packages/x86-64-v3-poky-linux/gzip: PKGV changed from 1.14 [default] to 1.15 
[default]
packages/x86-64-v3-poky-linux/gzip: SRC_URI changed from 
"https://ftpmirror.gnu.org//gzip/gzip-1.14.tar.gz file://run-ptest 
file://CVE-2026-41992.patch file://CVE-2026-41991.patch 
file://wrong-path-fix.patch" to 
"https://ftpmirror.gnu.org//gzip/gzip-1.15.tar.gz file://run-ptest 
file://CVE-2026-41992.patch file://CVE-2026-41991.patch 
file://wrong-path-fix.patch"
packages/x86-64-v3-poky-linux/gzip: PV changed from "1.14" to "1.15"
Changelog for gzip: 1.14 -> 1.15
Source: ChangeLog

2026-09-20  Jim Meyering  <[email protected]>

        version 1.15
        * NEWS: Record release date.

2026-09-10  Paul Eggert  <[email protected]>

        doc: add THANKS for bug report

        gzip: avoid last_component if !USE_ATFUNCS
        Problem reported by Bryan M.
        * gzip.c (atdir_set): New arg PARENTFD.  All uses changed.
        Use the new arg to avoid passing AT_FDCWD to unlinkat when a
        parent directory was intended.
        (treat_file) [!USE_ATFUNCS]: Use ifname, not its last component.

        gzip: use unlinkat only when using openat
        This is mostly just a cleanup, but the cleanup removes a nagging
        issue on MS-Windowsish platforms with openat+unlinkat but where
        you cannot unlink a readonly file.  In this case the code used
        plain open, but used unlinkat, which is questionable.
        * gzip.c (USE_ATFUNCS): Rename from TRY_OPENING_DIRECTORIES.
        The old name was misleading, as gzip -r opens directories
        even when USE_ATFUNCS is false.  All uses changed.
        (gzip_unlinkat, unlinkat) [!USE_ATFUNCS]:
        New compatibility function and macro.
        * util.c (xunlinkat): Remove.  All uses changed to use unlinkat.

2026-09-05  Paul Eggert  <[email protected]>

        gzip: fix undefined behavior with SIGPIPE
        This problem arose due to a combination of commit
        bb78ea465787191e8987d4b8a6594f9f23a18930 dated 2013-06-11,
        which defined SIGPIPE to 0 if not already defined, with commit
        ede0a8888a4d3d0750e1651e01f198e2faab5d59 dated 2026-05-25,
        which included tailor.h before all system .h files.
        Problem and fix reported by Collin Funk (bug#81139).
        * gzip.c (handled_sig): ifdef, not if, for SIGPIPE.
        * tailor.h (SIGPIPE): Do not #define to 0, because when we later
        include <signal.h> its #define yields undefined behavior.

        maint: update .gitignore files and bootstrap

        build: configure.ac cruft removal
        * configure.ac: Do not call AC_PROG_RANLIB, as we no longer use
        its results ourselves.  Do not use AC_C_CONST or AC_TYPE_SIZE_T,
        as it’s safe to assume C89 now.  Do not check for fcntl.h,
        limits.h, memory.h, time.h, as we no longer use the corresponding
        HAVE_FCNTL_H etc. macros.  Do not check for lstat or siginterrupt,
        as we no longer use HAVE_LSTAT or HAVE_SIGINTERRUPT.  Do not use
        AC_HEADER_DIRENT, as we no longer use any symbols that it defines.

        gzip: don’t open same dir twice when recursive
        Opening it multiple times can lead to races.
        * gzip.c (treat_file, create_outfile, open_and_stat, open_input_file):
        New arg parentfd.  All uses changed.  If nonnegative, treat it as
        the parent directory file descriptor, instead of dfd or syncdfd.
        (check_ofname): New arg atfd.  All uses changed.
        (treat_dir): Do not close fd until after processing subsidiaries.
        Instead, pass it as the parent fd to subroutines.
        Report any streamsavedir failure.

        gzip: be more cautious about using AT_FDCWD
        Without this change, gzip was more vulnerable to attackers
        changing the directory hierarchy while gzip walks through it.
        * gzip.c (ATDIR_SET_ERROR): New constant.
        (atdir_set): Return it on failure, so that callers can distinguish
        failure from AT_FDCWD.  All uses changed.  Do not update the cache
        if the new call fails.
        (create_outfile, open_and_stat): Report directory failures
        instead of silently ignoring them and falling back on AT_FDCWD.

        gzip: fix race in attacker-controlled directory
        Do not let an attacker cause you to remove a victim file
        merely because they can control an ancestor directory.
        * gzip.c (remove_ofname_dfd): New var.
        (atdir_set): Do not open directories if sending to stdout,
        as we are not destructive in this case.
        (create_outfile, open_and_stat): Use atdir_set even if KEEP, as we
        need it for the output file now.
        (create_outfile): Save atfd and base, not ofname.
        (remove_output_file): Use remove_ofname_dfd, not dfd,
        because dfd is not volatile and so is unsafe in a signal handler.

        gzip: shrink critical section
        * gzip.c (remove_output_file): Move non-critical code
        out of the critical section.

        gzip: use relative unlinkat
        * gzip.c (treat_file): Simplify and pull name calculation out of
        critical section.  No need to call atdir_eq here
        (check_ofname, remove_output_file): Unlink relative to dfd
        if dfd is nonnegative.

        maint: sort THANKS
        * THANKS: Sort.

        gzip: refactor unlink calls
        This should simplify future improvements.
        * gzip.c (TRY_OPENING_DIRECTORIES) [UNLINK_READONLY_BUG]:
        Now false instead of true.
        (gzip_unlinkat, unlinkat): Remove.
        All callers changed to use xunlinkat.
        * util.c (xunlinkat): New function, replacing xunlink.
        All callers changed.

        build: avoid fdopendir module
        This further simplifies gzip and shrinks attack surface
        on older platforms.  gzip no longer needs the old code
        to save and restore working directories.
        Reverts some of commit b5f88a3a283655adfc6c03fcb61031367e6d6d88
        dated 2009-11-19 13:59:11 +0100.
        * bootstrap.conf (gnulib_modules): Remove fdopendir.
        * configure.ac: Check for fdopendir and opendir.
        * gzip.c (NO_DIR): Default to (!HAVE_FDOPENDIR && !HAVE_OPENDIR).
        (treat_dir) [!NO_DIR && !HAVE_FDOPENDIR]: Fall back on opendir.

        build: avoid openat, unlinkat modules
        Instead of using Gnulib’s openat and unlinkat modules,
        simplify gzip by not calling the functions if the
        operating system does not have them natively.
        This simplifies gzip and shrinks its attack surface.
        * bootstrap.conf (gnulib_modules): Remove openat, unlinkat.
        * configure.ac: Check for openat, unlinkat.
        * gzip.c (TRY_OPENING_DIRECTORIES): New macro,
        taken from atdir_set body.
        (gzip_openat, gzip_unlinkat, openat, unlinkat)
        [!TRY_OPENING_DIRECTORIES]: New functions and macros, that ignore
        the directory file descriptor and flags.  This simplifies later code.
        (atdir_set): Use TRY_OPENING_DIRECTORIES instead.
        (open_and_stat): Pass 0 mode to openat, in case
        TRY_OPENING_DIRECTORIES is in use.

        maint: prefer stdopen to *-safer
        This should simplify future maintenance.
        * bootstrap.conf (gnulib_modules): Replace fcntl-safer,
        openat-safer, unistd-safer with fcntl-h, openat, unistd-h.
        Add stdopen.
        * gzip.c: Include <stdopen.h>, <fcntl.h> instead of <fcntl--.h>.
        (main): Call stdopen as soon as practical.

        build: update gnulib submodule to latest

        gzip: fix flags used to open directories
        * gzip.c (dfd): Now AT_FDCWD, not -1, when negative.
        All uses changed.
        (syncdfd): New static var.
        (atdir_set): Return AT_FDCWD, not -1, when returning negative.
        All uses changed.  For dfd prefer O_PATH to O_SEARCH on GNU platforms,
        as O_SEARCH incorrectly limits gzip to readable directories there.
        Set syncdfd to a file descriptor opened with O_RDONLY,
        as GNU platforms reject fdatasync with an O_PATH descriptor,
        and even without the O_PATH change,
        FreeBSD platforms reject fdatasync with an O_SEARCH descriptor.
        (treat_file): Use syncdfd, not dfd, to sync directory.

2026-09-04  Paul Eggert  <[email protected]>

        gzip: add FIXME re comment vs confusing code
        From a question about the code by Mark Adler.

        build: work around OpenBSD i386 glitch
        Problem reported by Bruno Haible (Bug#81766).
        * configure.ac (gzip_cv_assembler): 'no' on OpenBSD i386.

2026-09-03  Jim Meyering  <[email protected]>

        gzip: fix s390 build failure with -m31
        * dfltcc.c (is_dfltcc_enabled): Use the STFLE opcode rather than the
        mnemonic, as Linux does: with 'gcc -m31' the assembler's default
        machine predates z9-109, so it rejects the mnemonic.
        Reported by Bruno Haible in https://bugs.gnu.org/81766

2026-09-01  Paul Eggert  <[email protected]>

        tests: port timestamp tests to Solaris x86
        Problem reported by Bruno Haible (Bug#81766).
        * tests/timestamp: Accept test results if time_t is 32 bits but
        'touch' supports 64 bits.

2026-09-01  Jim Meyering  <[email protected]>

        build: update gnulib to latest

        build: avoid failure when combining --enable-gcc-warnings and GCC16+
        * configure.ac: Add gl_WARN_ADD([-Wno-keyword-macro]), to suppress many
        new warnings like this from GCC16:
          ./lib/config.h:2403:9: error: keyword 'restrict' defined as macro \
            [-Werror=keyword-macro]
          2403 | #define restrict __restrict__

2026-08-30  Jim Meyering  <[email protected]>

        tests: test for the lzh-lzh fix
        * tests/lzh-lzh-ctable-abuse: New file.  Two crafted .lzh files that 
would
        let c_table state from the first leak into the decoding of the second.
        Result: the second file silently decodes to \x01 rather than \0.
        * tests/Makefile.am (TESTS): Add it.

2026-08-30  Jim Meyering  <[email protected]>

        gzip: don’t mishandle .lzh after .lzh
        If an .lzh member ends up with all code lengths zero, make_table
        neither stores a symbol in c_table nor runs its own clearing loop, so
        decode_c decodes with whatever table the previously decompressed .lzh
        member left behind.  The member then decodes differently depending on
        what preceded it in the same process.

        * unlzh.c (huf_decode_start): Clear c_table too.
        * NEWS: Mention this.

2026-08-30  Jim Meyering  <[email protected]>

        tests: test for the lzw-lzh fix
        * tests/Makefile.am (TESTS): Add it.
        * tests/lzw-lzh-abuse: New file.  Show how a poisoning .Z can
        cause a following .lzh file to silently decompress improperly.

2026-08-25  Paul Eggert  <[email protected]>

        gzip: unaligned access if __riscv_misaligned_fast
        Optimization suggested by Huang Shangcheng (Bug#81705).
        * tailor.h (UNALIGNED_OK) [__riscv_misaligned_fast]:
        Define if not already defined.

2026-08-11  Paul Eggert  <[email protected]>

        gzip: don’t mishandle .lzh after .Z (better fix)
        * unlzh.c (read_c_len): Move clearing of left and right from here ...
        (huf_decode_start): ... to here.
        Problem and fix reported by Elias Hasas.

2026-07-08  Paul Eggert  <[email protected]>

        build: update gnulib submodule to latest

        maint: avoid wchar-h
        * bootstrap.conf: Avoid wchar-h. Suggested by Bruno Haible in:
        https://lists.gnu.org/r/bug-gnulib/2026-07/msg00012.html

2026-06-03  Paul Eggert  <[email protected]>

        build: update gnulib submodule to latest

        build: substitute GNULIBHEADERS_OVERRIDE_WINT_T too
        Problem reported by Bruno Haible (Bug#81174).
        * configure.ac (GNULIBHEADERS_OVERRIDE_WINT_T): AC_SUBST it.

2026-05-30  Paul Eggert  <[email protected]>

        build: slim down wchar-h etc. configuration
        Since we don’t rely on Gnulib’s mbszero, uchar-h, wchar-h etc., we
        can omit some configuration bureaucracy.
        * bootstrap.conf (gnulib_tool_option_extras): Avoid mbszero too.
        (bootstrap_post_import_hook): Remove m4/locale-en.m4, m4/wint_t.m4.
        * configure.ac (gt_LOCALE_EN_UTF8, gt_TYPE_WINT_T)
        (GNULIBHEADERS_OVERRIDE_WINT_T): Define dummies.
        * lib/.gitignore, m4/.gitignore: Update.

        gzip: escape C1 controls when quoting
        Problem reported by Lasse Collin <https://bugs.gnu.org/81135#29>.
        * gzip.c: Include <locale.h>.
        (main): Start off with setlocale (LC_ALL, ""), so that multibyte
        encodings work.  From the tryB suggestion of Bruno Haible
        <https://bugs.gnu.org/81135#5> except it’s done even on native
        MS-Windows.

        build: update gnulib submodule to latest
        * configure.ac (_QUOTEARG_AVOID_UCHAR_H): New macro, replacing
        USE_C_LOCALE; needed for latest Gnulib.

2026-05-29  Paul Eggert  <[email protected]>

        build: update gnulib submodule to latest

2026-05-26  Paul Eggert  <[email protected]>

        gzip: don’t include <c-ctype.h>
        Problem reported by Bruno Haible (Bug#81123).
        * gzip.c: Don’t include <c-ctype.h>.

        gzexe: fix message typo in previous change
        Reported by Vincent Lefevre (Bug#79321).

2026-05-25  Paul Eggert  <[email protected]>

        gzip: tolower → c_tolower
        * tailor.h (casemap)
        [MSDOS || OS2 || WIN32 || _WIN32 || ATARI || atarist]:
        Define to c_tolower, not to tolower, since we no longer
        include <ctype.h>.

        gzip: quote oddball file names in diagnostics
        * NEWS: Mention this.
        * bootstrap.conf (gnulib_modules): Add c-ctype, quotearg.
        (gnulib_tool_option_extras): Avoid c32isprint, mbrtoc32,
        mbsinit, mbszero, uchar-h.
        * configure.ac (USE_C_LOCALE): Define.
        * gzexe.in, zdiff.in, zforce.in, zgrep.in:
        Do not send file names to stderr; it’s not worth the trouble
        to try to safely quote them in these rarely-used scripts.
        * gzip.c, util.c: Reorder includes for sanity, putting config.h
        first, then tailor.h, then our others, then Gnulib’s, then POSIX’s.
        * gzip.c, trees.c, util.c:
        Include <c-ctype.h> instead of <ctype.h>; all function uses changed.
        * gzip.c (progerror, main, treat_file, create_outfile, open_input_file)
        (make_ofname, get_method, do_list, check_ofname, copy_stat, treat_dir):
        * unlzw.c (unlzw):
        * unzip.c (check_zipfile, unzip):
        * util.c (gzip_error, warning, read_error, write_err):
        * zip.c (zip):
        Quote unusual file names in diagnostics.
        * gzip.c (progerror): Treat null argument as naming standard input,
        so that we needn’t quote it.  Argument changed.
        * lib/.gitignore, m4/.gitignore: Update.
        * tests/null-suffix-clobber: Adjust to match new quoting behavior.
        * util.c (quotef, quotef_n): New functions.
        * zip.c: Don’t include <ctype.h>; not needed.

        gzip: pacify -Wuseless-cast
        * gzip.c (treat_file, do_list):
        Use compound literal instead of cast.
        (treat_file): Use uintmax_t, not unsigned long, with a format to match.
        (get_method): Omit useless cast.

        gzip: nice_match fixes for x86
        Pacify -Wmissing-variable-declarations on x86.
        * deflate.c (static_unless_ASMV): Remove.
        (nice_match): Adjust to the removal, and make sure there is
        an external definition for nice_match if needs to be external
        for the assembly-language version.

        build: Gnulib is now -Wkeyword-macro safe
        * configure.ac: Remove gl_WARN_ADD([-Wno-keyword-macro]),
        as we fixed the Gnulib issue with ‘restrict’.

        build: update gnulib submodule to latest

2026-05-25  Jim Meyering  <[email protected]>

        tests: port pipe-output and zgrep-signal to Cygwin
        * tests/zgrep-signal: Use skip_, not framework_failure_,
        when SIGPIPE is not delivered, since that is a platform
        limitation, not a test infrastructure problem.
        * tests/pipe-output: Skip the no-trap iteration on Cygwin,
        where SIGPIPE delivery is unreliable.
        * tests/Makefile.am (TESTS_ENVIRONMENT): Add host_os.
        Problem reported by Bruno Haible in
        https://lists.gnu.org/r/bug-gzip/2026-05/msg00001.html

        build: update gnulib to latest

        build: avoid new failure when combining --enable-gcc-warnings and GCC16
        * configure.ac: Add gl_WARN_ADD([-Wno-keyword-macro]), to suppress many
        new warnings like this from GCC16:
          ./config.h:2418:9: warning: keyword 'restrict' defined as macro\
            [-Wkeyword-macro]
           2418 | #define restrict __restrict__

2026-05-12  Paul Eggert  <[email protected]>

        znew: stop supporting -P
        * NEWS, THANKS: Mention this.
        * znew.1, znew.in: Stop documenting -P and its bugs.
        * znew.in: Issue a warning if -P is used, and otherwise ignore it.

2026-05-09  Paul Eggert  <[email protected]>

        gzip: pacify GCC 16 -Wuseless-cast
        * gzip.h (put_byte, put_ubyte, put_short, SH):
        * trees.c (ct_init, build_bl_tree, send_all_trees)
        (flush_block):
        * unlzh.c (unlzh):
        Omit useless casts.
        * gzip.h (put_short, put_long, SH): Replace possibly-useful casts
        with compound literals.  They are “possibly-useful” because it
        depends on the type of the macro’s argument.

2026-04-28  Jim Meyering  <[email protected]>

        build: update gnulib to latest

2026-04-25  Jim Meyering  <[email protected]>

        doc: mention pigz and zlib in SEE ALSO
        * gzip.1 (SEE ALSO): Add pigz(1).
        Mention zlib as the library for programmatic gzip I/O.
        Prompted by Bruno Haible in https://bugs.gnu.org/79794

2026-04-25  Collin Funk  <[email protected]>

        maint: assume proper behavior of tolower
        * gzip.h (tolow): Remove macro.
        * tailor.h (casemap): Use tolower instead of tolow.
        * util.c (strlwr): Likewise.

2026-04-22  Jim Meyering  <[email protected]>

        tests: test for the latest fix
        * tests/zdiff-abuse: New file.
        * tests/Makefile.am (TESTS): Add it.

2026-04-22  Collin Funk  <[email protected]>

        zdiff: escape arguments given to short options
        * zdiff.in: Escape $arg.
        Reported in https://bugs.gnu.org/80882
        * THANKS: Update.

2026-04-20  Paul Eggert  <[email protected]>

        zgrep: fix quoting typo
        * zgrep.in: Fix quoting typo in option parsing.
        Problem reported by Leenear (bug#80868).

2026-04-19  Paul Eggert  <[email protected]>

        tests: use $GREP not grep
        Problem reported by Bruno Haible in:
        https://bugs.gnu.org/80855#64
        * tests/pipe-output, tests/zdiff, tests/zgrep-binary:
        * tests/zgrep-context:
        Use $GREP, not grep.  Also, be consistent about unsetting
        GREP_OPTIONS, for portability to GNU grep 3.5 and earlier
        when the user unwisely set GREP_OPTIONS.

2026-04-19  Jim Meyering  <[email protected]>

        tests: zgrep-abuse: skip if we cannot create the exploit input
        * tests/zgrep-abuse: Just test the creation of the exploit
        file directly.  Apparently touch'ing a "|"-afflicted file name
        works fine, but redirection fails.

2026-04-19  Bruno Haible  <[email protected]>

        build: Fix syntax error in configure (regression yesterday)
        * configure.ac: Fix typo in yesterday's commit.

2026-04-18  Jim Meyering  <[email protected]>

        maint: fix a comment typo
        * tests/pipe-output: Fix comment typo: NFAIL -> MINFAIL

2026-04-18  Paul Eggert  <[email protected]>

        maint: port pipe-output to Alpine
        * tests/pipe-output: Don’t assume that the underlying
        commands cmp, diff, grep do the right thing on output errors.
        Problem reported by Bruno Haible in:
        https://bugs.gnu.org/80855#11

        maint: avoid AC_REQUIRE at top level
        * configure.ac (gzip_cv_assembler): Don’t use AC_REQUIRE at top
        level.  Instead, just check that Gnulib has set host_os as usual.

        gzip: fix diagnostic after failed write
        * gzip.c (main, finish_out): Check ferror after fflush.
        That way, if the fflush fails we get a more-precise errno.
        If ferror fails, just report EIO regardless of actual error.
        (create_outfile): Do not assume a successful sigprocmask
        leaves errno alone, when issuing a diagnostic after a failed
        write.  This fixes an unlikely bug I introduced in commit
        a979d9c4db0adbf341eb329abaf3560aa12f10fd dated 2006-12-07.
        * util.c (write_err): New function, with most of the old
        write_error’s implementation.
        (write_error): Use it.

2026-04-18  Jim Meyering  <[email protected]>

        tests: avoid two cygwin test failures
        * tests/list-big: Upon failure to create the 4GiB sparse file,
        _skip the test, rather than merely using framework_failure_.
        * tests/zgrep-abuse: Add an up-front _skip test for file systems
        that reject file names containing "|".
        Reported by Bruno Haible in
        https://mail.gnu.org/r/bug-gzip/2026-04/msg00009.html

2026-04-18  Paul Eggert  <[email protected]>

        doc: add Sam James's pointer to TEXTREL issue

2026-04-18  Bruno Haible  <[email protected]>

        build: Fix broken executable on 32-bit x86 systems with musl libc
        * configure.ac (gzip_cv_assembler): Set to no on musl libc.

2026-04-17  Paul Eggert  <[email protected]>

        maint: prune lib/.gitignore some more
        * lib/.gitignore: Remove recent additions that likely crept
        in only because an old source directory was being used.
        This reverts back to what this file was a couple of days ago,
        except /glthread is also removed since recent Gnulib changes
        made it unnecessary.

2026-04-17  Jim Meyering  <[email protected]>

        build: remove setlocale-null-unlocked. not needed after all
        * bootstrap.conf (gnulib_modules): Remove setlocale-null-unlocked.
        * lib/.gitignore: Update. Also add several generated file and directory 
names.
        * m4/.gitignore: Update.

        build: avoid new build failure due to missing setlocale.h
        * bootstrap.conf (gnulib_modules): Add setlocale-null-unlocked.
        This is not the right place to add this: the gnulib setlocale
        module probably needs an added dependency. I expect to revert
        this change once gnulib is fixed.

        maint: avoid syntax-check doubled-word false positive
        * znew.in: "if if ..." looks odd but is totally fine per POSIX.
        It triggered the "make syntax-check" doubled word failure. Adding braces
        makes it more readable to me and avoids the syntax-check failure.
        * NEWS: fix typo: s/propery/properly/
        * lib/.gitignore: Update.
        * m4/.gitignore: Likewise.

2026-04-16  Paul Eggert  <[email protected]>

        gzip: omit unnecessary fillbuf casts
        * unlzh.c: Omit unnecessary casts in calls to fillbuf.

        gzip: minor subbitbuf cleanups
        * unlzh.c (subbitbuf): Now uch, not unsigned, since it has
        at most CHAR_BIT bits.
        (fillbuf): Use simpler EOF check, that doesn’t need casts.

        gzip: fix subbitbuf junk bug
        * unlzh.c (fillbuf): Clear any high-order junk bits
        from subbitbuf.  Problem reported by Michał Majchrowicz.

        gzip: fix bitbuf << 16 bug
        (Problem reported by Michał Majchrowicz.)
        * unlzh.c (fillbuf): Avoid undefined behavior when shifting bitbuf
        left by 16.  No known practical platforms do the wrong thing here,
        so this fix is mostly for completeness.

        znew: use -C
        * znew.in: Also use -C here, when creating a temp.

        gzexe: use -C if lacking mktemp
        (Problem reported by Michał Majchrowicz.)
        * gzexe.in: If mktemp is needed but not installed,
        use ‘set -C’ to avoid a race when creating a temporary file.
        * zdiff.in: Use the same pattern here, even though the old
        code was probably OK anyway.

        gzip: replace puts loop with single printf
        * gzip.c (license_msg, help_msg):
        Now single strings instead of arrays of pointers to strings.
        This is a bit simpler (avoids need for puts loops).

2026-04-15  Paul Eggert  <[email protected]>

        gzip: use unlocked I/O
        * bootstrap.conf (gnulib_modules): Add unlocked-io.
        * gzip.c (putstring, eputstring):
        New functions.  Prefer them to printf/fprintf
        when either will do, as these can use unlocked I/O with glibc.
        * gzip.h: Include unlocked-io.h instead of stdio.h.

        maint: avoid unnecessary #include <stdio.h>
        * bits.c, deflate.c, unlzh.c:
        No need to include stdio.h, since gzip.h does.

        maint: avoid windows-once, windows-tls
        * bootstrap.conf (gnulib_tool_option_extras):
        Avoid windows-once, windows-tls; these are recent Gnulib
        additions that gzip doesn’t need, for the same reason
        it doesn’t need windows-spin.

        build: update gnulib submodule to latest

        gzip: don’t mishandle .lzh after .Z
        Problem reported by Michał Majchrowicz.
        * unlzh.c (read_c_len): Clear left and right when n == 0.

        maint: update .gitignore

2026-04-10  Paul Eggert  <[email protected]>

        maint: avoid sigprocmask-related locking
        This affects only MS-Windows; it avoids the need for some
        code that is needed only on multithreaded MS-Windows apps.
        * bootstrap.conf (gnulib_tool_option_extras):
        Avoid windows-spin instead of avoiding lock.
        * configure.ac (GNULIB_SIGPROCMASK_SINGLE_THREAD):
        Define this instead of defining GNULIB_PTHREAD_SIGMASK_SINGLE_THREAD.

        build: update gnulib submodule to latest

2026-04-05  Paul Eggert  <[email protected]>

        maint: adjust to GNULIB sigprogcmask changes
        * bootstrap.conf (gnulib_modules):
        Add sigprocmask, since gzip.c uses it directly.
        (gnulib_tool_option_extras): Also avoid threadlib,
        which would otherwise be pulled in by pthread_sigmask.
        * configure.ac (GNULIB_PTHREAD_SIGMASK_SINGLE_THREAD):
        Define this instead of defining GNULIB_SIGACTION_SINGLE_THREAD.
        The latter was a misspelling, and in the meantime Gnulib has evolved
        to use GNULIB_PTHREAD_SIGMASK_SINGLE_THREAD anyway.

        build: update gnulib submodule to latest

2026-04-01  Paul Eggert  <[email protected]>

        build: update gnulib submodule to latest

        maint: avoid sigaction locking
        * configure.ac (GNULIB_SIGACTION_SINGLE_THREAD):
        Define to avoid unnecessary locking in sigaction,
        needed for the next sync from Gnulib.  See:
        https://lists.gnu.org/r/bug-gnulib/2026-04/msg00008.html

2026-03-31  Paul Eggert  <[email protected]>

        gzip: pacify Oracle Solaris Studio 12.6
        * gzip.c (create_outfile): Remove unreachable code.

        maint: update .gitignore files
        * .gitignore, lib/.gitignore, m4/.gitignore:
        Adjust to match current Gnulib.

        gzip: depend on fewer Gnulib modules
        * bootstrap.conf (gnulib_modules):
        Remove fprintf-posix and printf-posix, as we don’t need their
        fixes and they drag in too many other Gnulib modules.
        (gnulib_tool_option_extras): Avoid the ‘lock’ module.

        build: update gnulib submodule to latest

2026-03-29  Paul Eggert  <[email protected]>

        gzip: pacify -Wzero-as-null-pointer-constant
        * bootstrap.conf (gnulib_modules): Add stdcountof-h,
        which we already depended on indirectly.
        * gzip.c: Include stdcountof.h.
        (license_msg, help_msg): Do not NULL-terminate.
        All uses changed.
        (longopts): Prefer NULL to 0 in pointer contexts.
        (get_suffix, install_signal_handlers):
        Prefer countof to doing it by hand.

2026-03-28  Paul Eggert  <[email protected]>

        build: update gnulib submodule to latest

2026-03-27  Paul Eggert  <[email protected]>

        Avoid Gnulib modules more consistently
        * bootstrap.conf (avoided_gnulib_modules): Remove.
        All uses removed.
        (gnulib_tool_option_extras): Avoid gnulib-i18n here,
        next to the other place we’re avoiding Gnulib modules.

2026-01-02  Jim Meyering  <[email protected]>

        maint: update --version copyright dates
        * gunzip.in, gzexe.in, gzip.c, zcat.in, zcmp.in, zdiff.in, zforce.in,
        zgrep.in, zless.in, zmore.in, znew.in: Also update the --version 
copyright
        dates (while updated by update-copyright, those didn't satisfy 
syntax-check)
        by running this:

          grep -l 2025-2026 *.in gzip.c|xargs perl -pi -e 's/2025-2026/2026/'

2026-01-02  Jim Meyering  <[email protected]>

        maint: update copyright dates

        build: update gnulib to latest; and bootstrap

2025-11-09  Jim Meyering  <[email protected]>

        build: update gnulib to latest

2025-09-11  Paul Eggert  <[email protected]>

        build: update gnulib submodule to latest

2025-09-09  Paul Eggert  <[email protected]>

        gzip: report "-Inf%" for negative infinity
        * tests/list: Test for this.
        * util.c (display_ratio):
        Say "-%Inf%" if the compression ratio is negative infinity.
        From a suggestion by Mark Adler <https://bugs.gnu.org/79414#13>.

2025-06-17  Paul Eggert  <[email protected]>

        gzip: fix NEWS
        * NEWS: Fix as per <https://bugs.gnu.org/78799#38>.

2025-06-16  Paul Eggert  <[email protected]>

        maint: add NEWS entry re PKZIP fixes

        gzip: don’t assume EOF == -1
        Although EOF == -1 on all known platforms, POSIX and C don’t
        guarantee it.  Fix code that silently assumes this.
        * deflate.c (lm_init, fill_window):
        * gzip.c (get_method):
        * util.c (fill_inbuf):
        Don’t assume EOF == -1, or that converting EOF to unsigned
        and back to int yields -1.  Instead, statically check
        EOF-related assumptions.
        * deflate.c (fill_window): Check for more < EOF, not more != EOF.

        unzip: add regression test for recent fixes
        * tests/unzip-valid: New test, taken from Bug#78799.
        * tests/Makefile.am (TESTS): Add it.

        unzip: use GNU style in newly-added code
        * unzip.c (unzip): Use GNU style.

2025-06-16  Mark Adler  <[email protected]>

        zip: correctly handle PKZIP data descriptors
        * unzip.c (DATSIG, L8): New macros.
        (unzip): Previously only one of the four possible data descriptors was
        handled. Check for all four when validating the uncompressed
        data with the CRC and length in the data descriptor. This also now
        checks the full eight-byte uncompressed length for zip files.

2025-06-16  Paul Eggert  <[email protected]>

        unzip: refactor loop that never loops
        * unzip.c (bad_zipfile): New static function,
        with most of the old contents of check_zipfile.
        This is clearer than the trick of having a loop that never loops.
        (check_zipfile): Use it.

        gzip: get_method 2nd arg is bool
        * gzip.c (get_method): Use bool for boolean.

2025-06-16  Mark Adler  <[email protected]>

        zip: correctly handle PKZIP signatures and the local header
        This fixes bugs in the lack of detection of spanning signatures,
        lack of detection of empty zip files, checking the compression
        method, failure to skip over the file name and extra field in the
        SMALL_MEM case, failure to get the CRC and uncompressed length in
        the SMALL_MEM case, failure to check for invalid combinations of
        header information, the lack of detection of a Zip64 entry, and
        a possible decompression of a zip entry after a gzip member.
        * gzip.c (get_method): New arg FIRST.  All callers changed.
        * gzip.h (PKZIP_MAGIC): Now just the two-byte magic header.
        * unzip.c (SPNSIG, ONESIG, Z64SIG, ENDSIG): New macros.
        (RAND_HEAD_LEN, decrypt): Remove.  All uses removed.
        (orig_crc, orig_len): New static vars.
        (check_zipfile, unzip): Handle PKZIP signatures and the local header.

2025-06-16  Paul Eggert  <[email protected]>

        maint: use GNU style in lines just untabbed

2025-06-16  Mark Adler  <[email protected]>

        maint: replace tabs in the source code with spaces

2025-05-30  Paul Eggert  <[email protected]>

        gzip: fix s390x build failure
        Problem reported by Jakub Martisko <https://bugs.gnu.org/78618>.
        * dfltcc.c: Include errno.h.

        gzip: fix another uninitialized read
        This can occur if you define DYNALLOC.
        Problem reported by Mohamed Maatallah <https://bugs.gnu.org/78639#13>.
        * gzip.c (get_method): Don’t memcmp more bytes than were read.
        Also, no need to do two memcmp’s now, or to check inptr.

2025-05-29  Paul Eggert  <[email protected]>

        gzip: fix uninitialized read
        Problem reported by Mohamed Maatallah <https://bugs.gnu.org/78639>.
        * unzip.c (check_zipfile):
        Don’t read past end of initialized data in the input buffer.

2025-04-27  Paul Eggert  <[email protected]>

        tests: port to Busybox od
        Problem reported by Xinjian Ma (Bug#78084).
        * tests/reference: Skip this test if od does not support -An -tx1
        as POSIX requires. Also, omit an unnecessary use of tr, since
        the $(...) already does that.

        maint: post-release administrivia
        * NEWS: Add header line for next release.
        * .prev-version: Record previous version.
        * cfg.mk (old_NEWS_hash): Auto-update.

Attachment: 0001-gzip-upgrade-1.14-1.15.patch
Description: Binary data

packages/x86-64-v3-poky-linux/gzip/gzip-ptest: FILELIST: added 
"/usr/lib/gzip/ptest/src/tests/unzip-valid 
/usr/lib/gzip/ptest/src/tests/lzw-lzh-abuse 
/usr/lib/gzip/ptest/src/tests/lzh-lzh-ctable-abuse 
/usr/lib/gzip/ptest/src/tests/zdiff-abuse"
packages/x86-64-v3-poky-linux/gzip/gzip-src: PKGSIZE changed from 1243826 to 
916953 (-26%)
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246282): 
https://lists.openembedded.org/g/openembedded-core/message/246282
Mute This Topic: https://lists.openembedded.org/mt/121353231/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to