[OE-core][dunfell][PATCH] libjpeg-turbo: CVE-2020-35538 Null pointer dereference in jcopy_sample_rows() function

2023-06-22 Thread Vijay Anusuri
From: Vijay Anusuri Upstream-Status: Backport [https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9120a247436e84c0b4eea828cb11e8f665fcde30 & https://github.com/libjpeg-turbo/libjpeg-turbo/commit/a46c111d9f3642f0ef3819e7298846ccc61869e0] Signed-off-by: Vijay Anusuri --- .../jpeg/files/CVE-20

[OE-core][kirkstone][PATCH] libcap: CVE-2023-2603 Integer Overflow in _libcap_strdup()

2023-06-22 Thread vkumbhar
Signed-off-by: Vivek Kumbhar --- .../libcap/files/CVE-2023-2603.patch | 31 +++ meta/recipes-support/libcap/libcap_2.66.bb| 1 + 2 files changed, 32 insertions(+) create mode 100644 meta/recipes-support/libcap/files/CVE-2023-2603.patch diff --git a/meta/recipes-sup

Re: [OE-core] [kirkstone 1/5] linux-yocto/5.10: update to v5.10.176

2023-06-22 Thread Bruce Ashfield
I think I kept all the versions -> release mappings straight. Apologies if I screwed one up! Bruce On Thu, Jun 22, 2023 at 7:18 PM Bruce Ashfield via lists.openembedded.org wrote: > > From: Bruce Ashfield > > Updating to the latest korg -stable release that comprises > the following commits:

[OE-core][dunfell 1/3] linux-yocto/5.4: update to v5.4.246

2023-06-22 Thread Bruce Ashfield
From: Bruce Ashfield Updating to the latest korg -stable release that comprises the following commits: f568a20f058f Linux 5.4.246 6c0fc4725f6f drm/edid: fix objtool warning in drm_cvt_modes() 914bf541c3bb wifi: rtlwifi: 8192de: correct checking of IQK reload 58bc9baaef92 drm/edi

[OE-core][dunfell 2/3] linux-yocto/5.4: update to v5.4.247

2023-06-22 Thread Bruce Ashfield
From: Bruce Ashfield Updating to the latest korg -stable release that comprises the following commits: 61a2f83e4762 Linux 5.4.247 4b0199bc8189 Revert "staging: rtl8192e: Replace macro RTL_PCI_DEVICE with PCI_DEVICE" 85258ae30708 mtd: spinand: macronix: Add support for MX35LFxGE4AD

[OE-core][dunfell 3/3] linux-yocto/5.4: update to v5.4.248

2023-06-22 Thread Bruce Ashfield
From: Bruce Ashfield Updating to the latest korg -stable release that comprises the following commits: f2b499c27a95 Linux 5.4.248 1cdc48aaff18 mmc: block: ensure error propagation for non-blk de517032ee39 drm/nouveau/kms: Fix NULL pointer dereference in nouveau_connector_detect_dep

[OE-core][kirkstone 3/4] linux-yocto/5.10: update to v5.10.184

2023-06-22 Thread Bruce Ashfield
From: Bruce Ashfield Updating to the latest korg -stable release that comprises the following commits: a1f0beb13d9b Linux 5.10.184 7f896130eff7 Revert "staging: rtl8192e: Replace macro RTL_PCI_DEVICE with PCI_DEVICE" b60e862e133f btrfs: unset reloc control if transaction commit fai

[OE-core][kirkstone 4/4] linux-yocto/5.10: update to v5.10.185

2023-06-22 Thread Bruce Ashfield
From: Bruce Ashfield Updating to the latest korg -stable release that comprises the following commits: ef0d5feb32ab Linux 5.10.185 ed2bf5cee6c6 um: Fix build w/o CONFIG_PM_SLEEP f73ec12dc718 drm/i915/gen11+: Only load DRAM information from pcode 27458487c8f4 drm/i915/dg1: Wait f

[OE-core][kirkstone 2/4] linux-yocto/5.10: update to v5.10.183

2023-06-22 Thread Bruce Ashfield
From: Bruce Ashfield Updating to the latest korg -stable release that comprises the following commits: 7356714b95aa Linux 5.10.183 842156dc0aad ARM: defconfig: drop CONFIG_DRM_RCAR_LVDS 2c0ea7a06db5 ext4: enable the lazy init thread when remounting read/write 92450a1eaa9e selfte

[OE-core][kirkstone 1/4] linux-yocto/5.10: update to v5.10.182

2023-06-22 Thread Bruce Ashfield
From: Bruce Ashfield Updating to the latest korg -stable release that comprises the following commits: c7992b6c7f0e Linux 5.10.182 468bebc426ba netfilter: ctnetlink: Support offloaded conntrack entry deletion 18c14d3028c0 ipv{4,6}/raw: fix output xfrm lookup wrt protocol 221875

[OE-core] [kirkstone 1/5] linux-yocto/5.10: update to v5.10.176

2023-06-22 Thread Bruce Ashfield
From: Bruce Ashfield Updating to the latest korg -stable release that comprises the following commits: ca9787bdecfa Linux 5.10.176 e57f797e3ffa HID: uhid: Over-ride the default maximum data buffer value with our own 9bc878756b01 HID: core: Provide new max_buffer_size attribute to o

[OE-core][mickledore 5/5] linux-yocto/5.15: update to v5.15.118

2023-06-22 Thread Bruce Ashfield
From: Bruce Ashfield Updating to the latest korg -stable release that comprises the following commits: f67653019430 Linux 5.15.118 e5bf1f7d1fc8 nilfs2: reject devices with insufficient block count 2bc9231afc64 mmc: block: ensure error propagation for non-blk 4b7b50d4eb1a of: ove

[OE-core][mickledore 4/5] linux-yocto/5.15: update to v5.15.117

2023-06-22 Thread Bruce Ashfield
From: Bruce Ashfield Updating to the latest korg -stable release that comprises the following commits: 471e639e59d1 Linux 5.15.117 ef876dd25830 Revert "staging: rtl8192e: Replace macro RTL_PCI_DEVICE with PCI_DEVICE" 6cfe9ddb6aa6 xfs: verify buffer contents when we skip log replay

[OE-core][mickledore 3/5] linux-yocto/5.15: update to v5.15.116

2023-06-22 Thread Bruce Ashfield
From: Bruce Ashfield Updating to the latest korg -stable release that comprises the following commits: 7349e40704a0 Linux 5.15.116 62886f17d3e6 RDMA/irdma: Do not generate SW completions for NOPs 14d148401c52 RDMA/irdma: Fix drain SQ hang with no completion e88b19b252db ARM: def

[OE-core][mickledore 2/5] linux-yocto/5.15: update to v5.15.115

2023-06-22 Thread Bruce Ashfield
From: Bruce Ashfield Updating to the latest korg -stable release that comprises the following commits: d7af3e5ba454 Linux 5.15.115 e226893c935f netfilter: ctnetlink: Support offloaded conntrack entry deletion 395d846c61c5 ipv{4,6}/raw: fix output xfrm lookup wrt protocol 1bb8a6

[OE-core][mickledore 1/5] linux-yocto/5.15: update to v5.15.114

2023-06-22 Thread Bruce Ashfield
From: Bruce Ashfield Updating to the latest korg -stable release that comprises the following commits: 0ab06468cbd1 Linux 5.15.114 193c59ba7299 net: phy: mscc: add VSC8502 to MODULE_DEVICE_TABLE 350b95e86ca9 3c589_cs: Fix an error handling path in tc589_probe() 7c2fa3e56d95 regu

[OE-core] [PATCH 2/2] linux-yocto/6.1: update to v6.1.35

2023-06-22 Thread Bruce Ashfield
From: Bruce Ashfield Updating to the latest korg -stable release that comprises the following commits: e84a4e368abe Linux 6.1.35 a76d4933c38e kbuild: Update assembler calls to use proper flags and language target 5abcd2c18dbb MIPS: Prefer cc-option for additions to cflags 1d485

[OE-core] [PATCH 1/2] linux-yocto/6.1: update to v6.1.34

2023-06-22 Thread Bruce Ashfield
From: Bruce Ashfield Updating to the latest korg -stable release that comprises the following commits: ca87e77a2ef8 Linux 6.1.34 1aaa74177f06 Revert "staging: rtl8192e: Replace macro RTL_PCI_DEVICE with PCI_DEVICE" a7e9c2e40708 wifi: rtw88: correct PS calculation for SUPPORTS_DYNAM

[OE-core] [PATCH] weston: Cleanup and fix x11 and xwayland dependencies

2023-06-22 Thread Tom Hochstein
For the x11 backend package config, drop the redundant dependencies libxcb and cairo. The former is listed twice in the package config, while the latter is also listed globally. For the xwayland package config, add the missing dependencies libxcb and libxcursor. These dependencies are hidden when

Re: [OE-core] [PATCH v2 2/3] insane: ignore nativesdk-${PN}-src host contaminated issue

2023-06-22 Thread Maxime Roussin-Bélanger
Hello Alex, On Thu, Jun 22, 2023 at 12:24 PM Alexander Kanavin wrote: > > I'm not sure I understand this. The check is to ensure build process > works as it should, specifically to prevent build host ownership > leaking into packages. Yes this information doesn't matter when these > packages are

Re: [OE-core] [PATCH v2 3/3] bitbake.conf: add debug symbol for sdk

2023-06-22 Thread Maxime Roussin-Bélanger
Hi Alex, I don't want a complete debug build. I want to keep optimization and have the debug symbols. I don't think I can achieve that with DEBUG_BUILD. Max On Thu, Jun 22, 2023 at 12:30 PM Alexander Kanavin wrote: > > This change is unnecessary, as there is already a mechanism. Just > slightly

[OE-core] [PATCH 6/9] runqemu-gen-tapdevs: remove uid parameter

2023-06-22 Thread Adrian Freihofer
The uid parameter is no longer needed since ip tuntap is used internally. Remove it. Backward compatibility to 3 or 4 parameters is still supported. Signed-off-by: Adrian Freihofer --- scripts/runqemu-gen-tapdevs | 33 ++--- 1 file changed, 18 insertions(+), 15 deleti

[OE-core] [PATCH 9/9] runqemu: configurable tap names

2023-06-22 Thread Adrian Freihofer
Support the new environment variable OE_TAP_NAME. Signed-off-by: Adrian Freihofer --- scripts/runqemu | 8 ++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/scripts/runqemu b/scripts/runqemu index bd1f8366b63..e1aa5a925c8 100755 --- a/scripts/runqemu +++ b/scripts/runqemu @@

[OE-core] [PATCH 7/9] runqemu-gen-tapdevs: configurable tap names

2023-06-22 Thread Adrian Freihofer
Feature: Hard-coding the interface names to tap* is not always a good idea. Signed-off-by: Adrian Freihofer --- scripts/runqemu-gen-tapdevs | 10 +++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/scripts/runqemu-gen-tapdevs b/scripts/runqemu-gen-tapdevs index 7f67ee5540e..

[OE-core] [PATCH 8/9] runqemu-gen-tapdevs: remove only our taps

2023-06-22 Thread Adrian Freihofer
Ignore itnerfaces with other names than what the runqemu scripts created. Signed-off-by: Adrian Freihofer --- scripts/runqemu-gen-tapdevs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/runqemu-gen-tapdevs b/scripts/runqemu-gen-tapdevs index cbf80089290..a00c79c4420 1

[OE-core] [PATCH 5/9] runqemu-gen-tapdevs: remove staging dir parameter

2023-06-22 Thread Adrian Freihofer
The parameter staging_bindir_native is no longer used. Remove it. For now the script is backward compatible. With 4 parameters it logs an error message but still works. Signed-off-by: Adrian Freihofer --- scripts/runqemu-gen-tapdevs | 12 +++- 1 file changed, 7 insertions(+), 5 deletions

[OE-core] [PATCH 3/9] runqemu-ifup: fix tap index

2023-06-22 Thread Adrian Freihofer
Recent patches changed the index of the tap interfaces. They start now with tap1 instead of tap0. Also the IP address starts with 192.168.7.3 instead of 192.168.7.1. This gets reverted to the previous behavior. Signed-off-by: Adrian Freihofer --- scripts/runqemu-ifup | 9 +++-- 1 file change

[OE-core] [PATCH 4/9] runqemu-ifup: remove only our taps

2023-06-22 Thread Adrian Freihofer
If there are other tap interfaces than the interfaces created by the runqemu-* scripts, these interfaces are not ignored. This is now fixed by filtering the interfaces for a specific prefix in the interface name. Signed-off-by: Adrian Freihofer --- scripts/runqemu-ifup | 2 +- 1 file changed, 1

[OE-core] [PATCH 1/9] runqemu-ifup: remove uid parameter

2023-06-22 Thread Adrian Freihofer
ip tuntap does not need the uid, it was an unused variable/parameter. Backward compatibility should be fine. Signed-off-by: Adrian Freihofer --- scripts/runqemu-ifup | 13 - 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/scripts/runqemu-ifup b/scripts/runqemu-ifup inde

[OE-core] [PATCH 2/9] runqemu-ifup: configurable tap names

2023-06-22 Thread Adrian Freihofer
Feature: Hard-coding the interface names to tap* is not always a good idea. Introduce an environment variable which allows to change this: OE_TAP_NAME. Signed-off-by: Adrian Freihofer --- scripts/runqemu-ifup | 14 +- 1 file changed, 9 insertions(+), 5 deletions(-) diff --git a/scri

[OE-core] [PATCH 0/9] fixes for runqemu-gen-tapdevs

2023-06-22 Thread Adrian Freihofer
At least on my machine recent the changes related to the tap interface setup for Qemu broke even more than already discussed e.g. here: https://lists.openembedded.org/g/openembedded-core/message/183176 These patches should fix and improve the related scripts: - First interface is now tap1 with IP a

Re: [OE-core] [PATCH v2 2/3] insane: ignore nativesdk-${PN}-src host contaminated issue

2023-06-22 Thread Maxime Roussin-Bélanger
Hello Alex, On Thu, Jun 22, 2023 at 12:24 PM Alexander Kanavin wrote: > > I'm not sure I understand this. The check is to ensure build process > works as it should, specifically to prevent build host ownership > leaking into packages. Yes this information doesn't matter when these > packages are

[OE-core] [PATCH v2 1/3] wayland-utils: Upgrade 1.1.0 -> 1.2.0

2023-06-22 Thread Eilís 'pidge' Ní Fhlannagáin
Signed-off-by: Eilís 'pidge' Ní Fhlannagáin --- ...ayland-info-Fix-build-without-libdrm.patch | 42 --- ...-utils_1.1.0.bb => wayland-utils_1.2.0.bb} | 3 +- 2 files changed, 1 insertion(+), 44 deletions(-) delete mode 100644 meta/recipes-graphics/wayland/files/0001-wayland-inf

[OE-core] [PATCH v2 0/3] wayland/weston upgrades

2023-06-22 Thread Eilís 'pidge' Ní Fhlannagáin
Nothing really surprising here, except we should note that launcher-logind is being depreciated so some thought on how that is dealt with will need to occur and that we'll need to pull xcb-util-cursor from meta-openembedded as it's needed here for weston's ptest now. Eilís 'pidge' Ní Fhlannagáin

[OE-core] [PATCH v2 2/3] weston: Upgrade 11.0.1 -> 12.0.1

2023-06-22 Thread Eilís 'pidge' Ní Fhlannagáin
Tracking https://gitlab.freedesktop.org/wayland/weston/-/issues/488 we're keeping -Ddeprecated-launcher-logind but plans should be made to remove this/work around. We also need to add xcb-util-cursor from meta-openembedded as this is now required for ptest. When this is pulled we can remove from m

[OE-core] [PATCH v2 3/3] xwayland: Upgrade 23.1.1 -> 23.1.2

2023-06-22 Thread Eilís 'pidge' Ní Fhlannagáin
Signed-off-by: Eilís 'pidge' Ní Fhlannagáin --- .../xwayland/{xwayland_23.1.1.bb => xwayland_23.1.2.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-graphics/xwayland/{xwayland_23.1.1.bb => xwayland_23.1.2.bb} (95%) diff --git a/meta/recipes-graphics/xwayla

Re: [OE-core] [PATCH] rootfs-postcommands: Set vardeps for write_image_test_data

2023-06-22 Thread Peter Hoyes
On 19/06/2023 13:07, Richard Purdie wrote: On Mon, 2023-06-19 at 12:47 +0100, Peter Hoyes wrote: It sounds like moving testdata creation to a separate task doesn't bring much benefit so I'll revert to something based off this patch. It looks like a relatively small number of variables are a

Re: [OE-core] [PATCH V4 1/3] kernel-module-split: make autoload and probeconf distribution specific

2023-06-22 Thread Luca Ceresoli via lists.openembedded.org
Hi Jose, On Thu, 22 Jun 2023 08:44:51 + "Jose Quaresma" wrote: > Also take the oportunity to only add configuration files to FILES > and CONFFILES when they exist and are used. > > The modules-load.d [1] - Configure kernel modules to load at boot > should install their configuration files i

[OE-core] [PATCH v2] rootfs-postcommands: Set vardeps for write_image_test_data

2023-06-22 Thread Peter Hoyes
From: Peter Hoyes The testdata.json file generated as part of the rootfs postprocess commands currently contains almost all Bitbake variables and is used by OEQA test cases to inspect the build environment. However only a small number of variables are actually used and the testdata.json is not au

Re: [OE-core] [PATCH v2 3/3] bitbake.conf: add debug symbol for sdk

2023-06-22 Thread Alexander Kanavin
This change is unnecessary, as there is already a mechanism. Just slightly further down you can see that BUILDSDK_CFLAGS pulls in BUILD_OPTIMIZATION, which sets -g if you enable DEBUG_BUILD in your config. Alex On Thu, 22 Jun 2023 at 18:20, Maxime Roussin-Bélanger wrote: > > From: Maxime Roussin

Re: [OE-core][PATCH v7 0/3] CVE-check handling

2023-06-22 Thread Luca Ceresoli via lists.openembedded.org
Hello Andrej, On Thu, 22 Jun 2023 14:07:41 + "Andrej Valek via lists.openembedded.org" wrote: > OK, > > Now I know what's the problem. SPDX are being created without inheriting the > cve-check class. > > Regards, > Andrej > > On Thu, 2023-06-22 at 15:59 +0200, Valek Andrej wrote: > > Hell

Re: [OE-core] [PATCH v2 2/3] insane: ignore nativesdk-${PN}-src host contaminated issue

2023-06-22 Thread Alexander Kanavin
I'm not sure I understand this. The check is to ensure build process works as it should, specifically to prevent build host ownership leaking into packages. Yes this information doesn't matter when these packages are installed, but it matters for correctness of the build. Alex On Thu, 22 Jun 2023

[OE-core] [PATCH v2 3/3] bitbake.conf: add debug symbol for sdk

2023-06-22 Thread Maxime Roussin-Bélanger
From: Maxime Roussin-Belanger Without adding debug flag nativesdk dbg package is not packaged since there is no debugging information Signed-off-by: Maxime Roussin-Belanger --- v2: New commit meta/conf/bitbake.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/conf/

[OE-core] [PATCH v2 2/3] insane: ignore nativesdk-${PN}-src host contaminated issue

2023-06-22 Thread Maxime Roussin-Bélanger
From: Maxime Roussin-Belanger nativesdk-${PN}-src will be installed to a different machine and files ownership will change at install. Since the ownership will change based on how the user will install the sdk there is no point in checking ownership Signed-off-by: Maxime Roussin-Belanger --- v2

[OE-core] [PATCH v2 1/3] package: fix src packaging path for nativesdk

2023-06-22 Thread Maxime Roussin-Bélanger
From: Maxime Roussin-Belanger Directory tree doesn't contain the correct structure when packaging for source files for the sdk. Since the structure is incorrect, they won't be part of the installed sdk. Having source files in nativesdk is necessary when using it as a development sysroot for debu

Re: [OE-Core][kirkstone][PATCH 0/8] Backport all weston-init qol updates

2023-06-22 Thread Randolph Sapp via lists.openembedded.org
On 6/15/23 16:04, r...@ti.com wrote: From: Randolph Sapp Backport all the weston-init QOL updates. Getting closer to the point where we can actually drop our distro specific weston-init bbappend. May submit a few more QOL patches sooner or later to completely drop it. Ming Liu (1): weston-i

[OE-core][dunfell 14/14] systemd-systemctl: support instance expansion in WantedBy

2023-06-22 Thread Steve Sakoman
From: Ian Ray Refactor _process_deps to expand systemd instance specifier "%i" to the template instance. This change expands on prior commit e510222b57 ("systemd-systemctl: fix instance template WantedBy symlink construction") by substituting every "%i" pattern-match with the instance name. The

[OE-core][dunfell 13/14] systemd-systemctl: fix instance template WantedBy symlink construction

2023-06-22 Thread Steve Sakoman
From: Martin Siegumfeldt Fix issue of the below instance template systemd service dependency [Install] WantedBy=svc-wants@%i.service creating the symlink (instance "a" example) /etc/systemd/system/svc-wants@%i.service.wants/svc-wanted-by@a.service which should be /etc/systemd/system/svc-want

[OE-core][dunfell 12/14] kernel-fitimage: use correct kernel image

2023-06-22 Thread Steve Sakoman
From: Andrej Valek Even if initramfs_bundle_path was used, a wrong compression was reflected in output its template file. Use linux.bin as universal kernel image. The linux.bin file covers both cases because it's beying created from vmlinux. We know, that vmlinux is created inside compressed dir

[OE-core][dunfell 11/14] kernel-fitimage: adding support for Initramfs bundle and u-boot script

2023-06-22 Thread Steve Sakoman
From: Abdellatif El Khlifi This commit adds Initramfs bundle support to the FIT image in addition to u-boot boot script capability. These new features are selectable. In case of Initramfs, the kernel is configured to be bundled with the rootfs in the same binary (ie: zImage-initramfs-.bin). Whe

[OE-core][dunfell 10/14] uninative.bbclass: handle read only files outside of patchelf

2023-06-22 Thread Steve Sakoman
We are seeing autobuilder failures with the latest uninative: patchelf: open: Permission denied See upstream discussion which suggests handling read-only files explicitly outside of patchelf: https://github.com/NixOS/patchelf/pull/89 Signed-off-by: Steve Sakoman --- meta/classes/uninative.bbcl

[OE-core][dunfell 09/14] uninative: Upgrade to 4.0 to include latest gcc 13.1.1

2023-06-22 Thread Steve Sakoman
From: Michael Halstead Signed-off-by: Michael Halstead Signed-off-by: Richard Purdie (cherry picked from commit f87becb69e02bdf055dffb633ed4f6d36b36f7a7) Signed-off-by: Steve Sakoman --- meta/conf/distro/include/yocto-uninative.inc | 8 1 file changed, 4 insertions(+), 4 deletions(-)

[OE-core][dunfell 08/14] uninative: Upgrade to 3.10 to support gcc 13

2023-06-22 Thread Steve Sakoman
From: Michael Halstead Signed-off-by: Michael Halstead Signed-off-by: Richard Purdie (cherry picked from commit f811bffb861b23238e8291394bd6e8407f013619) Signed-off-by: Steve Sakoman --- meta/conf/distro/include/yocto-uninative.inc | 8 1 file changed, 4 insertions(+), 4 deletions(-)

[OE-core][dunfell 07/14] uninative: Upgrade to 3.9 to include glibc 2.37

2023-06-22 Thread Steve Sakoman
From: Michael Halstead Update uninative to work with the new glibc 2.37. Signed-off-by: Michael Halstead Signed-off-by: Richard Purdie (cherry picked from commit 360971a6ba562fa0b29bd062b96ede2d3a47fa2e) Signed-off-by: Steve Sakoman --- meta/conf/distro/include/yocto-uninative.inc | 10 +

[OE-core][dunfell 06/14] uninative: Upgrade to 3.8.1 to include libgcc

2023-06-22 Thread Steve Sakoman
From: Michael Halstead Including libgcc solves issues with libpthread. Signed-off-by: Michael Halstead Signed-off-by: Richard Purdie (cherry picked from commit 36eb46589fb01374d4738a2c376386c68d06aa83) Signed-off-by: Steve Sakoman --- meta/conf/distro/include/yocto-uninative.inc | 8

[OE-core][dunfell 05/14] uninative: Ensure uninative is enabled in all cases for BuildStarted event

2023-06-22 Thread Steve Sakoman
From: Richard Purdie Recent changes in bitbake mean the datastore is not always reset between ConfigParsed and BuildStarted. This means in a fresh buiild, with memory resident bitbake active, uninative may end up disabled. Update the code so the enable code is always run at BuildStarted if neede

[OE-core][dunfell 03/14] cve-update-nvd2-native: new CVE database fetcher

2023-06-22 Thread Steve Sakoman
From: Marta Rybczynska Add new fetcher for the NVD database using the 2.0 API [1]. The implementation changes as little as possible, keeping the current database format (but using a different database file for the transition period), with a notable exception of not using the META table. Minor ch

[OE-core][dunfell 04/14] cve-update-nvd2-native: added the missing http import

2023-06-22 Thread Steve Sakoman
From: Jan Vermaete Signed-off-by: Jan Vermaete Signed-off-by: Luca Ceresoli (cherry picked from commit 39d2cde7eb922cb0a2cf9402cd8b3ae3b4cc2f62) Signed-off-by: Steve Sakoman --- meta/recipes-core/meta/cve-update-nvd2-native.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-c

[OE-core][dunfell 02/14] openssl: CVE-2023-2650 Possible DoS translating ASN.1 object identifiers

2023-06-22 Thread Steve Sakoman
From: Hitendra Prajapati Upstream-Status: Backport from https://github.com/openssl/openssl/commit/9e209944b35cf82368071f160a744b6178f9b098 Signed-off-by: Hitendra Prajapati Signed-off-by: Steve Sakoman --- .../openssl/openssl/CVE-2023-2650.patch | 122 ++ .../openssl/op

[OE-core][dunfell 01/14] cups: Fix CVE-2023-32324

2023-06-22 Thread Steve Sakoman
From: Sanjay Chitroda OpenPrinting CUPS is an open source printing system. In versions 2.4.2 and prior, a heap buffer overflow vulnerability would allow a remote attacker to launch a denial of service (DoS) attack. A buffer overflow vulnerability in the function `format_log_line` could allow remo

[OE-core][dunfell 00/14] Patch review

2023-06-22 Thread Steve Sakoman
Please review this set of changes for dunfell and have comments back by end of day Monday. Passed a-full on autobuilder: https://autobuilder.yoctoproject.org/typhoon/#/builders/83/builds/5493 The following changes since commit 77f6fbfa18b4ad77c3756cfdc45d441a20210781: build-appliance-image: U

Re: [OE-core][PATCH v7 0/3] CVE-check handling

2023-06-22 Thread Andrej Valek via lists.openembedded.org
OK, Now I know what's the problem. SPDX are being created without inheriting the cve-check class. Regards, Andrej On Thu, 2023-06-22 at 15:59 +0200, Valek Andrej wrote: > Hello Luca, > > I wanted to check the logs, but it requires a login/password. Would it be > possible to send a link where is

[OE-core] [PATCH] logrotate: Do not create logrotate.status file

2023-06-22 Thread Jermain Horsman
From: Jermain Horsman The first time logrotate runs it reports an error: error: state file /var/lib/logrotate.status is world-readable and thus can be locked from other unprivileged users. Skipping lock acquisition... This check was added with https://github.com/logrotate/logrotate/commit

Re: [OE-core][PATCH v7 0/3] CVE-check handling

2023-06-22 Thread Andrej Valek via lists.openembedded.org
Hello Luca, I wanted to check the logs, but it requires a login/password. Would it be possible to send a link where is not required? Maybe here https://autobuilder.yoctoproject.org/typhoon/#/ ? Regards, Andrej On Thu, 2023-06-22 at 15:55 +0200, Luca Ceresoli wrote: > Hello Andrej, > > On Thu, 2

Re: [OE-core][PATCH v7 0/3] CVE-check handling

2023-06-22 Thread Luca Ceresoli via lists.openembedded.org
Hello Andrej, On Thu, 22 Jun 2023 13:50:32 + "Andrej Valek via lists.openembedded.org" wrote: > Hello Luca, > > How can I reproduce it? I've executed "bitbake qemu -c create_spdx" but it > didn't print any warning. Should I build an image? I don't know how to reproduce _exactly_ the build

Re: [OE-core][PATCH v7 0/3] CVE-check handling

2023-06-22 Thread Andrej Valek via lists.openembedded.org
Hello Luca, How can I reproduce it? I've executed "bitbake qemu -c create_spdx" but it didn't print any warning. Should I build an image? Regards, Andrej On Thu, 2023-06-22 at 14:42 +0200, Luca Ceresoli wrote: > Hello Andrej, > > On Thu, 22 Jun 2023 08:59:02 +0200 > "Andrej Valek via lists.open

Re: [OE-core][PATCH v7 0/3] CVE-check handling

2023-06-22 Thread Luca Ceresoli via lists.openembedded.org
Hello Andrej, On Thu, 22 Jun 2023 08:59:02 +0200 "Andrej Valek via lists.openembedded.org" wrote: > After discussion in all parallel threads we proposed following variant which > covers both expressed requirements to have very small number of different cve > statuses and also very large number o

[OE-core][PATCH v8 1/3] cve-check: add option to add additional patched CVEs

2023-06-22 Thread Andrej Valek via lists.openembedded.org
From: Andrej Valek - Replace CVE_CHECK_IGNORE with CVE_STATUS to be more flexible. The CVE_STATUS should contain an information about status wich is decoded in 3 items: - generic status: "Ignored", "Patched" or "Unpatched" - more detailed status enum - description: free text describing reason for

[OE-core][PATCH v8 2/3] oeqa/selftest/cve_check: rework test to new cve status handling

2023-06-22 Thread Andrej Valek via lists.openembedded.org
From: Andrej Valek - After introducing the CVE_STATUS and CVE_CHECK_STATUSMAP flag variables, CVEs could contain a more information for assigned statuses. - Add an example conversion in logrotate recipe. Signed-off-by: Andrej Valek --- meta/lib/oeqa/selftest/cases/cve_check.py | 26 +++

[OE-core][PATCH v8 0/3] CVE-check handling

2023-06-22 Thread Andrej Valek via lists.openembedded.org
After discussion in all parallel threads we proposed following variant which covers both expressed requirements to have very small number of different cve statuses and also very large number of them at the same time. This is a compromise version which maybe is not ideal but deals with conflicting r

Re: [OE-core] [PATCH V4 1/3] kernel-module-split: make autoload and probeconf distribution specific

2023-06-22 Thread Jose Quaresma
Peter Kjellerstedt escreveu no dia quinta, 22/06/2023 à(s) 10:49: > > -Original Message- > > From: Jose Quaresma > > Sent: den 22 juni 2023 10:45 > > To: openembedded-core@lists.openembedded.org > > Cc: Jose Quaresma ; Ola x Nilsson < > ola.x.nils...@axis.com>; Peter Kjellerstedt > > Su

Re: [OE-core] [PATCH V3 1/3] kernel-module-split: make autoload and probeconf distribution specific

2023-06-22 Thread Jose Quaresma
Hi Luca, Luca Ceresoli escreveu no dia quinta, 22/06/2023 à(s) 10:34: > Hi Jose, > > On Thu, 22 Jun 2023 00:18:03 +0100 > "Jose Quaresma" wrote: > > > Hi Luca, > > > > Luca Ceresoli escreveu no dia quarta, > > 21/06/2023 à(s) 21:22: > > > > > Hi Jose, > > > > > > On Tue, 20 Jun 2023 22:19:42 +

Re: [OE-core] [PATCH V4 1/3] kernel-module-split: make autoload and probeconf distribution specific

2023-06-22 Thread Peter Kjellerstedt
> -Original Message- > From: Jose Quaresma > Sent: den 22 juni 2023 10:45 > To: openembedded-core@lists.openembedded.org > Cc: Jose Quaresma ; Ola x Nilsson > ; Peter Kjellerstedt > Subject: [PATCH V4 1/3] kernel-module-split: make autoload and probeconf > distribution specific > > Als

Re: [OE-core] [PATCH] package: fix src packaging path for nativesdk

2023-06-22 Thread Luca Ceresoli via lists.openembedded.org
Hello Maxime, On Tue, 20 Jun 2023 17:36:40 -0400 Maxime Roussin-Bélanger wrote: > From: Maxime Roussin-Belanger > > Directory tree doesn't contain the correct structure when packaging > for source files for the sdk. Since the structure is incorrect, > they won't be part of the installed sdk. >

Re: [OE-core] [PATCH V3 1/3] kernel-module-split: make autoload and probeconf distribution specific

2023-06-22 Thread Luca Ceresoli via lists.openembedded.org
Hi Jose, On Thu, 22 Jun 2023 00:18:03 +0100 "Jose Quaresma" wrote: > Hi Luca, > > Luca Ceresoli escreveu no dia quarta, > 21/06/2023 à(s) 21:22: > > > Hi Jose, > > > > On Tue, 20 Jun 2023 22:19:42 + > > "Jose Quaresma" wrote: > > > > > Also take the oportunity to only add configuration

Re: [OE-core] [qa-build-notification] QA notification for completed autobuilder build (yocto-3.1.26.rc2)

2023-06-22 Thread Jing Hui Tham
Hi All, QA for yocto-3.1.26.rc2 is completed. This is the full report for this release: https://git.yoctoproject.org/cgit/cgit.cgi/yocto-testresults-contrib/tree/?h=intel-yocto-testresults === Summary No high milestone defects. No new issue found. Thanks, Jing Hui > -

[OE-core] [PATCH V4 3/3] kernel: autoload and probeconf are handled by kernel-module-split

2023-06-22 Thread Jose Quaresma
Signed-off-by: Jose Quaresma --- meta/classes-recipe/kernel.bbclass | 2 -- 1 file changed, 2 deletions(-) diff --git a/meta/classes-recipe/kernel.bbclass b/meta/classes-recipe/kernel.bbclass index e82b696d1a..855c784149 100644 --- a/meta/classes-recipe/kernel.bbclass +++ b/meta/classes-recipe/

[OE-core] [PATCH V4 1/3] kernel-module-split: make autoload and probeconf distribution specific

2023-06-22 Thread Jose Quaresma
Also take the oportunity to only add configuration files to FILES and CONFFILES when they exist and are used. The modules-load.d [1] - Configure kernel modules to load at boot should install their configuration files in /usr/lib/modules-load.d. The modprobe.d [2] - Configuration directory for mod

[OE-core] [PATCH V4 2/3] kernel-module-split: use context manager to open files

2023-06-22 Thread Jose Quaresma
Signed-off-by: Jose Quaresma --- .../kernel-module-split.bbclass | 23 --- 1 file changed, 10 insertions(+), 13 deletions(-) diff --git a/meta/classes-recipe/kernel-module-split.bbclass b/meta/classes-recipe/kernel-module-split.bbclass index 1d5e39b44d..e19ad8e3c5