[OE-core] [PATCH][dunfell 3/3] virglrenderer: fix CVE-2022-0135

2022-09-12 Thread Lee Chee Yang
From: Chee Yang Lee Signed-off-by: Chee Yang Lee --- .../virglrenderer/CVE-2022-0135.patch | 100 ++ .../virglrenderer/virglrenderer_0.8.2.bb | 1 + 2 files changed, 101 insertions(+) create mode 100644

[OE-core] [PATCH][dunfell 2/3] gnutls: fix CVE-2021-4209

2022-09-12 Thread Lee Chee Yang
From: Chee Yang Lee Signed-off-by: Chee Yang Lee --- .../gnutls/gnutls/CVE-2021-4209.patch | 37 +++ meta/recipes-support/gnutls/gnutls_3.6.14.bb | 1 + 2 files changed, 38 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2021-4209.patch diff

[OE-core] [PATCH][dunfell 1/3] connman: fix CVE-2022-32292

2022-09-12 Thread Lee Chee Yang
From: Chee Yang Lee Signed-off-by: Chee Yang Lee --- .../connman/connman/CVE-2022-32292.patch | 37 +++ .../connman/connman_1.37.bb | 1 + 2 files changed, 38 insertions(+) create mode 100644

Re: [OE-core] OE-core CVE metrics for master on Sun 11 Sep 2022 04:00:01 AM HST

2022-09-12 Thread Khem Raj
On 9/11/22 7:02 AM, Steve Sakoman wrote: Branch: master New this week: 10 CVEs CVE-2020-35538 (CVSS3: 5.5 MEDIUM): libjpeg-turbo:libjpeg-turbo-native https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-35538 * CVE-2022-1354 (CVSS3: 5.5 MEDIUM): tiff

[OE-core] [PATCH] inetutils: Fix remote DoS vulnerability in inetutils-telnetd

2022-09-12 Thread Khem Raj
Signed-off-by: Khem Raj --- .../inetutils/inetutils/CVE-2022-39028.patch | 54 +++ .../inetutils/inetutils_2.3.bb| 1 + 2 files changed, 55 insertions(+) create mode 100644 meta/recipes-connectivity/inetutils/inetutils/CVE-2022-39028.patch diff --git

[OE-core] [PATCH 2/2] binutils: Ignore CVE-2022-38126 CVE-2022-38127

2022-09-12 Thread Khem Raj
They are already part of backports to 2_36 branch as noted Signed-off-by: Khem Raj --- meta/recipes-devtools/binutils/binutils-2.39.inc | 4 1 file changed, 4 insertions(+) diff --git a/meta/recipes-devtools/binutils/binutils-2.39.inc b/meta/recipes-devtools/binutils/binutils-2.39.inc

[OE-core] [PATCH 1/2] glibc: Upgrade to tip of 2.36 branch

2022-09-12 Thread Khem Raj
Adresses CVE-2022-39046 Brings in following changeset * c399271c10 nscd: Fix netlink cache invalidation if epoll is used [BZ #29415] * b46412fb17 Add NEWS entry for CVE-2022-39046 * 645d94808a syslog: Remove extra whitespace between timestamp and message (BZ#29544) * b3736d1a3c elf: Restore how

[OE-core] Current high bug count owners for Yocto Project 4.1

2022-09-12 Thread Stephen Jolley
All, Below is the list as of top 35 bug owners as of the end of WW37 of who have open medium or higher bugs and enhancements against YP 4.1. There are 33 possible work days left until the final release candidates for YP 4.1 needs to be released. Who Count michael.opdenac...@bootlin.com 37

[OE-core] Yocto Project Newcomer & Unassigned Bugs - Help Needed

2022-09-12 Thread Stephen Jolley
All, The triage team is starting to try and collect up and classify bugs which a newcomer to the project would be able to work on in a way which means people can find them. They're being listed on the triage page under the appropriate heading:

[OE-core] [dunfell][PATCH] tiff: Security fixes CVE-2022-1354 and CVE-2022-1355

2022-09-12 Thread Lee Chee Yang
From: Yi Zhao References: https://nvd.nist.gov/vuln/detail/CVE-2022-1354 https://security-tracker.debian.org/tracker/CVE-2022-1354 https://nvd.nist.gov/vuln/detail/CVE-2022-1355 https://security-tracker.debian.org/tracker/CVE-2022-1355 Patches from: CVE-2022-1354:

[OE-core] [PATCH] vim: Upgrade 9.0.0341 -> 9.0.0453

2022-09-12 Thread Richard Purdie
Includes fixes for CVE-2022-3099 and CVE-2022-3134. Signed-off-by: Richard Purdie --- meta/recipes-support/vim/vim.inc | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 33a82992433..70dc2dfecf5

Re: [OE-core] [PATCH v3 2/2] nfs-ganesha: Replace unfs3 with nfs-ganesha

2022-09-12 Thread Adrian Freihofer
Hi Paulo This looks very interesting. Is the goal here to just replace unfs3 on a device running a Yocto-based firmware, or is the goal also to enable the User Space NFS server for development without root privileges as documented here:

Re: [OE-core] [PATCH] libxml2: don't override XML_CATALOG_FILES in xmllint wrapper if already set

2022-09-12 Thread Andreas Müller
On Mon, Sep 12, 2022 at 11:43 AM Richard Purdie wrote: > > On Sun, 2022-09-11 at 23:21 +0100, Richard Purdie via > lists.openembedded.org wrote: > > On Fri, 2022-09-09 at 23:54 +0100, Richard Purdie via > > lists.openembedded.org wrote: > > > On Fri, 2022-09-09 at 17:36 +0100, Ross Burton wrote:

Re: [OE-core] CVE raffle: collision avoidance

2022-09-12 Thread Steve Sakoman
On Mon, Sep 12, 2022 at 10:01 AM Marta Rybczynska wrote: > > On Mon, Sep 12, 2022 at 9:16 PM Steve Sakoman wrote: > > > > On Mon, Sep 12, 2022 at 8:57 AM Martin Jansa wrote: > > > > > > You mean this list? > > > https://lists.yoctoproject.org/g/yocto-security/message/655 > > > > Yes, I assumed

Re: [OE-core] CVE raffle: collision avoidance

2022-09-12 Thread Marta Rybczynska
On Mon, Sep 12, 2022 at 9:16 PM Steve Sakoman wrote: > > On Mon, Sep 12, 2022 at 8:57 AM Martin Jansa wrote: > > > > You mean this list? > > https://lists.yoctoproject.org/g/yocto-security/message/655 > > Yes, I assumed everyone was aware of the weekly CVE list! Did you > have something else in

Re: [OE-core] [PATCH 1/1] watchdog: Remove unneeded tirpc dependency

2022-09-12 Thread Khem Raj
On Mon, Sep 12, 2022 at 12:08 PM Paulo Neves wrote: > > it should as there is no rpc code in the project as far as i scanned. I > built it with musl successfully. OK thanks for confirming. > > Paulo Neves > > On 9/12/22 17:06, Khem Raj wrote: > > On Mon, Sep 12, 2022 at 2:21 AM Paulo Neves

Re: [OE-core] CVE raffle: collision avoidance

2022-09-12 Thread Steve Sakoman
On Mon, Sep 12, 2022 at 8:57 AM Martin Jansa wrote: > > You mean this list? > https://lists.yoctoproject.org/g/yocto-security/message/655 Yes, I assumed everyone was aware of the weekly CVE list! Did you have something else in mind? Steve > On Mon, Sep 12, 2022 at 8:56 PM Marta Rybczynska

Re: [OE-core] [PATCH 1/1] watchdog: Remove unneeded tirpc dependency

2022-09-12 Thread Paulo Neves
it should as there is no rpc code in the project as far as i scanned. I built it with musl successfully. Paulo Neves On 9/12/22 17:06, Khem Raj wrote: On Mon, Sep 12, 2022 at 2:21 AM Paulo Neves wrote: watchdog code does not have any dependency on rpc code, therefore the dependency and

Re: [OE-core] CVE raffle: collision avoidance

2022-09-12 Thread Martin Jansa
You mean this list? https://lists.yoctoproject.org/g/yocto-security/message/655 On Mon, Sep 12, 2022 at 8:56 PM Marta Rybczynska wrote: > > > > On Mon, 12 Sept 2022, 17:55 Steve Sakoman, wrote: > >> Reply to this thread noting which CVE you plan to work on. Please >> don't claim one unless

Re: [OE-core] CVE raffle: collision avoidance

2022-09-12 Thread Marta Rybczynska
On Mon, 12 Sept 2022, 17:55 Steve Sakoman, wrote: > Reply to this thread noting which CVE you plan to work on. Please > don't claim one unless you really intend to follow through! > > Hello Steve, What about sending the list of pending CVEs (from the existing dunfell/kirkstone/master lists) for

[OE-core] CVE raffle: collision avoidance

2022-09-12 Thread Steve Sakoman
Reply to this thread noting which CVE you plan to work on. Please don't claim one unless you really intend to follow through! Thanks! Steve -=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#170539):

[OE-core] Dunfell CVE reduction fun: Raffle #2

2022-09-12 Thread Steve Sakoman
Sadly the CVE count for dunfell has been creeping up over the past few months. Several people regularly contribute CVE patches for dunfell and their efforts are much appreciated. But we need more help! To encourage more folks to contribute to this effort I'm going to be holding a raffle from now

Re: [OE-core] [PATCH 1/1] watchdog: Remove unneeded tirpc dependency

2022-09-12 Thread Khem Raj
On Mon, Sep 12, 2022 at 2:21 AM Paulo Neves wrote: > > watchdog code does not have any dependency on rpc code, > therefore the dependency and flags to try to use it are > removed. > > Signed-off-by: Paulo Neves > --- > meta/recipes-extended/watchdog/watchdog_5.16.bb | 4 > 1 file changed,

Re: [OE-core] [PATCH] binutils: update USE_ALTERNATIVES_FOR for symlink files

2022-09-12 Thread Richard Purdie
On Sun, 2022-09-11 at 16:47 +0800, kai wrote: > From: Kai Kang > > It provides more binary files by binutils 2.39. Then add them to > USE_ALTERNATIVES_FOR as others to handle symlink files via > update-alternative mechanism. > > Signed-off-by: Kai Kang > --- >

Re: [OE-core] Kirkstone Rust - native only error

2022-09-12 Thread Peter Bergin
Hi Joel, On 2022-09-11 03:00, Joel Winarske wrote: I'm putting together a recipe that requires two passes, native, then target.  I'm hitting a python error only in the native pass.  I can cross compile the tool without error, so the problem is  isolated to native.  Any ideas? Recipe is

Re: [OE-core] [PATCH] libxml2: don't override XML_CATALOG_FILES in xmllint wrapper if already set

2022-09-12 Thread Richard Purdie
On Sun, 2022-09-11 at 23:21 +0100, Richard Purdie via lists.openembedded.org wrote: > On Fri, 2022-09-09 at 23:54 +0100, Richard Purdie via > lists.openembedded.org wrote: > > On Fri, 2022-09-09 at 17:36 +0100, Ross Burton wrote: > > > The KDE build uses custom catalogs by setting

[OE-core] [PATCH 1/1] watchdog: Remove unneeded tirpc dependency

2022-09-12 Thread Paulo Neves
watchdog code does not have any dependency on rpc code, therefore the dependency and flags to try to use it are removed. Signed-off-by: Paulo Neves --- meta/recipes-extended/watchdog/watchdog_5.16.bb | 4 1 file changed, 4 deletions(-) diff --git

[OE-core] [PATCH v4] rust: Use libc++ runtime when using clang with llvm runtime

2022-09-12 Thread Khem Raj
meta-clang has options when it comes to C++ runtime, default is to use gnu runtime, other options are llvm runtime and android runtime. This patch helps when a distro is using llvm runtime for C/C++ runtime. It informs the rust build system about right C++ runtime to configure for when such a

[OE-core] [PATCH 6/7] python3-rfc3986-validator: switch from SRC_URI:append to SRC_URI +=

2022-09-12 Thread Mikko Rapeli
The :append can not be removed via bbappends if needed. Thus it's better for open source layers to use += append if possible. Signed-off-by: Mikko Rapeli --- meta/recipes-devtools/python/python3-rfc3986-validator_0.1.1.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git

[OE-core] [PATCH 5/7] go-native: switch from SRC_URI:append to SRC_URI +=

2022-09-12 Thread Mikko Rapeli
The :append can not be removed if needed in other layers. Signed-off-by: Mikko Rapeli --- meta/recipes-devtools/go/go-native_1.19.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-devtools/go/go-native_1.19.bb b/meta/recipes-devtools/go/go-native_1.19.bb index

[OE-core] [PATCH 7/7] linux-libc-headers: switch from SRC_URI:append to SRC_URI +=

2022-09-12 Thread Mikko Rapeli
The :append can not be removed via bbappends in custom layers so it's better to use += appends when ever possible. Signed-off-by: Mikko Rapeli --- .../linux-libc-headers/linux-libc-headers_5.19.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git

[OE-core] [PATCH 4/7] glibc-tests: use += instead of :append

2022-09-12 Thread Mikko Rapeli
:append can not be modified in bbappends and thus += is better in re-usable, generic layers and recipes. Signed-off-by: Mikko Rapeli --- meta/recipes-core/glibc/glibc-tests_2.36.bb | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git

[OE-core] [PATCH 3/7] u-boot: switch from append to += in SRC_URI

2022-09-12 Thread Mikko Rapeli
+= allows custom layers to change the SRC_URI e.g. when updating the whole recipe to newer u-boot version. With :append, there is no way to change the variable from a bbappend. Signed-off-by: Mikko Rapeli --- meta/recipes-bsp/u-boot/u-boot_2022.07.bb | 2 +- 1 file changed, 1 insertion(+), 1

[OE-core] [PATCH 2/7] kernel-dev/common.rst: remove SRC_URI:append from examples

2022-09-12 Thread Mikko Rapeli
It's better to use SRC_URI += to append patches etc. If anything is added via :append, that can no longer be removed at all. If common, re-usable layers use SRC_URI:append, then users can not change those patches or SRC_URI entries without completely replacing the recipe with a copy in their own

[OE-core] [PATCH 1/7] common-tasks.rst: remove SRC_URI:append from examples

2022-09-12 Thread Mikko Rapeli
Using SRC_URI:append without recipe, machine or architecture specific limitations makes the :append'ed text unremovable and thus users and custom layers can not change the variable anymore. This makes it hard to e.g. override SRC_URI completely in a bbappend to update the full recipe to a newer

Re: [OE-core] [PATCH v3] rust: Use libc++ runtime when using clang with llvm runtime

2022-09-12 Thread Richard Purdie
On Sun, 2022-09-11 at 16:28 -0700, Khem Raj wrote: > meta-clang has options when it comes to C++ runtime, default is to use > gnu runtime, other options are llvm runtime and android runtime. This > patch helps when a distro is using llvm runtime for C/C++ runtime. It > informs the rust build