Hello Yoann, Siddharth, Thank you for pointing this out.
I replaced CVE-2026-58015_p2.patch with upstream commit 0919301962291a712067ee0c5d273cc392f33277<https://gitlab.gnome.org/GNOME/glib/-/commit/0919301962291a712067ee0c5d273cc392f33277>. During validation against Glib 2.78.6, I found that this unit-test commit is not standalone. It depends on these intervening commits: 1. c0531125344bb25fd66ffb7435ed6c285de09aeb<https://gitlab.gnome.org/GNOME/glib/-/commit/c0531125344bb25fd66ffb7435ed6c285de09aeb>: Improves cookie ID validation. Several test vectors in 091930196 requires this behavior. 2. 060aea67de7517d531b8fe2cdc07aa1a00ddeb22<https://gitlab.gnome.org/GNOME/glib/-/commit/060aea67de7517d531b8fe2cdc07aa1a00ddeb22>: Adds the client_get_reject_reason vfunc used by the new unit test. Without it, the test does not compile on GLib 2.78.6. The complete upstream sequence is therefore: * db9c8fae398b<https://gitlab.gnome.org/GNOME/glib/-/commit/db9c8fae398b0c457e660ce63dd5afec8993046a> <https://gitlab.gnome.org/GNOME/glib/-/commit/db9c8fae398b0c457e660ce63dd5afec8993046a> Validate cookie context * c0531125344b<https://gitlab.gnome.org/GNOME/glib/-/commit/c0531125344bb25fd66ffb7435ed6c285de09aeb> <https://gitlab.gnome.org/GNOME/glib/-/commit/c0531125344bb25fd66ffb7435ed6c285de09aeb> Improve validation of cookie ID * 060aea67de75<https://gitlab.gnome.org/GNOME/glib/-/commit/060aea67de7517d531b8fe2cdc07aa1a00ddeb22> <https://gitlab.gnome.org/GNOME/glib/-/commit/060aea67de7517d531b8fe2cdc07aa1a00ddeb22> Expose client reject reason as a new vfunc * 091930196229<https://gitlab.gnome.org/GNOME/glib/-/commit/0919301962291a712067ee0c5d273cc392f33277> <https://gitlab.gnome.org/GNOME/glib/-/commit/0919301962291a712067ee0c5d273cc392f33277> Add the unit test I will prepare v3 with these four commits in the same order, along with the requested patch-formatting corrections, and validate the complete series against the current Scarthgap branch before resubmitting. Regards, Deepak Rathore ________________________________ From: [email protected] <[email protected]> on behalf of Siddharth Doshi via lists.openembedded.org <[email protected]> Sent: Monday, July 27, 2026 11:28 PM To: [email protected] <[email protected]> Subject: Re: [OE-core] [scarthgap][PATCH v2 6/6] glib-2.0: fix CVE-2026-58015 Hello, Thank-you for sending the v2 promptly but i guess in hurry you copied the wrong helper commit. The main fix is correct which is at -> https://gitlab.gnome.org/GNOME/glib/-/commit/db9c8fae398b0c457e660ce63dd5afec8993046a but the helper commit is here -> https://gitlab.gnome.org/GNOME/glib/-/commit/0919301962291a712067ee0c5d273cc392f33277 (this mentions in git commit of being helper commit to same #3931 bug) you will need to replace patch CVE-2026-58015_p2 with contents from above commit. Regards, Siddharth
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#242310): https://lists.openembedded.org/g/openembedded-core/message/242310 Mute This Topic: https://lists.openembedded.org/mt/120465701/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
