Branch: master
New this week: 5 CVEs
CVE-2022-46456 (CVSS3: 7.8 HIGH): nasm:nasm-native
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-46456 *
CVE-2022-46457 (CVSS3: 5.5 MEDIUM): nasm:nasm-native
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-46457 *
CVE-2023-0049 (CVSS3:
The runtime dependency on libsoup set via PACKAGECONFIG does not work.
The problem is the dependency is placed on the main package, but the
soup package has no dependency on the main package.
I considered modifying the call to do_split_packages from
gstreamer1.0-plugins-packaging.inc, changing
Branch: kirkstone
New this week: 3 CVEs
CVE-2023-0049 (CVSS3: 7.8 HIGH): vim
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0049 *
CVE-2023-0051 (CVSS3: 7.8 HIGH): vim
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0051 *
CVE-2023-0054 (CVSS3: 7.8 HIGH): vim
On Sun, 2023-01-15 at 15:54 +, Tom Hochstein wrote:
> Okay, will this do the trick?
>
> +RDEPENDS:${PN}-soup += "${MLPREFIX}${@bb.utils.contains('PACKAGECONFIG',
> 'soup2', 'libsoup-2.4', 'libsoup', d)}"
>
> Is this a general rule that explicit RDEPENDS require explicit MLPREFIX?
If
Branch: dunfell
New this week: 3 CVEs
CVE-2022-3715 (CVSS3: 7.8 HIGH): bash
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3715 *
CVE-2023-0049 (CVSS3: 7.8 HIGH): vim
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0049 *
CVE-2023-0051 (CVSS3: 7.8 HIGH): vim
Branch: langdale
New this week: 3 CVEs
CVE-2023-0049 (CVSS3: 7.8 HIGH): vim
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0049 *
CVE-2023-0051 (CVSS3: 7.8 HIGH): vim
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0051 *
CVE-2023-0054 (CVSS3: 7.8 HIGH): vim
On Sat, 2023-01-14 at 17:49 -0600, Tom Hochstein wrote:
> The runtime dependency on libsoup set via PACKAGECONFIG does not work.
> The problem is the dependency is placed on the main package, but the
> soup package has no dependency on the main package.
>
> I considered modifying the call to
Okay, will this do the trick?
+RDEPENDS:${PN}-soup += "${MLPREFIX}${@bb.utils.contains('PACKAGECONFIG',
'soup2', 'libsoup-2.4', 'libsoup', d)}"
Is this a general rule that explicit RDEPENDS require explicit MLPREFIX?
Tom
-Original Message-
From: Richard Purdie
Sent: Sunday, January
Signed-off-by: Khem Raj
---
...-use-_Alignof-to-avoid-UB-in-ALIGNOF.patch | 45 +++
meta/recipes-graphics/xorg-lib/libxcb_1.15.bb | 3 +-
2 files changed, 47 insertions(+), 1 deletion(-)
create mode 100644
Signed-off-by: Khem Raj
---
...0001-Switch-from-C99-to-C11-standard.patch | 40 +
...efine-check_alignof-for-std-c11-and-.patch | 44 +++
meta/recipes-core/glib-2.0/glib-2.0_2.74.4.bb | 2 +
3 files changed, 86 insertions(+)
create mode 100644
Fixes an UB found with with clang
Signed-off-by: Khem Raj
---
...GNOF-using-_Alignof-when-using-C11-o.patch | 42 +++
meta/recipes-core/dbus/dbus_1.14.4.bb | 1 +
2 files changed, 43 insertions(+)
create mode 100644
Signed-off-by: Khem Raj
---
meta/recipes-devtools/m4/m4-1.4.19.inc| 1 +
...lot-using-_Alignof-when-using-C11-or.patch | 49 +++
2 files changed, 50 insertions(+)
create mode 100644
Signed-off-by: Khem Raj
---
...sing-_Alignof-when-using-C11-or-newe.patch | 51 +++
meta/recipes-devtools/opkg/opkg_0.6.1.bb | 1 +
2 files changed, 52 insertions(+)
create mode 100644
libsframe is newly added in binutils 2.40
Signed-off-by: Khem Raj
---
meta/recipes-devtools/binutils/binutils_2.40.bb | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/meta/recipes-devtools/binutils/binutils_2.40.bb
b/meta/recipes-devtools/binutils/binutils_2.40.bb
index
Signed-off-by: Khem Raj
---
meta/recipes-devtools/binutils/binutils.inc | 10 ++
1 file changed, 10 insertions(+)
diff --git a/meta/recipes-devtools/binutils/binutils.inc
b/meta/recipes-devtools/binutils/binutils.inc
index 98acf0a222..2b38aeb62d 100644
---
On 13/01/2023 16:04:42+0800, Changqing Li wrote:
>
> On 1/5/23 22:09, Alexandre Belloni wrote:
> > CAUTION: This email comes from a non Wind River email account!
> > Do not click links or open attachments unless you recognize the sender and
> > know the content is safe.
> >
> > This fails on
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *acpica* to *20221022* has
Failed (devtool error).
Detailed error information:
The following devtool command failed: upgrade acpica -V 20221022
NOTE: Starting bitbake server...
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-pygments* to *2.14.0*
has Succeeded.
Next steps:
- apply the patch: git am 0001-python3-pygments-upgrade-2.13.0-2.14.0.patch
- check the changes to upstream patches
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *u-boot-tools* to *2023.01*
has Failed(do_compile).
Detailed error information:
do_compile failed
Next steps:
- apply the patch: git am
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-iniconfig* to *2.0.0*
has Failed(do_compile).
Detailed error information:
do_compile failed
Next steps:
- apply the patch: git am
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *rust* to *1.66.1* has
Failed(do_compile).
Detailed error information:
do_compile failed
Next steps:
- apply the patch: git am 0001-rust-upgrade-1.66.0-1.66.1.patch
-
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *patchelf* to *0.17.2* has
Succeeded.
Next steps:
- apply the patch: git am 0001-patchelf-upgrade-0.17.0-0.17.2.patch
- check the changes to upstream patches and summarize
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-pytest* to *7.2.1*
has Succeeded.
Next steps:
- apply the patch: git am 0001-python3-pytest-upgrade-7.2.0-7.2.1.patch
- check the changes to upstream patches and
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-pytz* to *2022.7.1*
has Succeeded.
Next steps:
- apply the patch: git am 0001-python3-pytz-upgrade-2022.7-2022.7.1.patch
- check the changes to upstream patches and
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-importlib-metadata*
to *6.0.0* has Succeeded.
Next steps:
- apply the patch: git am
0001-python3-importlib-metadata-upgrade-5.2.0-6.0.0.patch
- check the changes
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *man-db* to *2.11.2* has
Succeeded.
Next steps:
- apply the patch: git am 0001-man-db-upgrade-2.11.1-2.11.2.patch
- check the changes to upstream patches and summarize them
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *mpg123* to *1.31.2* has
Succeeded.
Next steps:
- apply the patch: git am 0001-mpg123-upgrade-1.31.1-1.31.2.patch
- check the changes to upstream patches and summarize them
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *igt-gpu-tools* to *1.27* has
Failed(do_compile).
Detailed error information:
do_compile failed
Next steps:
- apply the patch: git am
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-urllib3* to *1.26.14*
has Succeeded.
Next steps:
- apply the patch: git am 0001-python3-urllib3-upgrade-1.26.13-1.26.14.patch
- check the changes to upstream
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *lighttpd* to *1.4.68* has
Failed(do_compile).
Detailed error information:
do_compile failed
Next steps:
- apply the patch: git am 0001-lighttpd-upgrade-1.4.67-1.4.68.patch
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *libpcap* to *1.10.3* has
Succeeded.
Next steps:
- apply the patch: git am 0001-libpcap-upgrade-1.10.2-1.10.3.patch
- check the changes to upstream patches and summarize
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *ethtool* to *6.1* has
Failed(do_compile).
Detailed error information:
do_compile failed
Next steps:
- apply the patch: git am 0001-ethtool-upgrade-6.0-6.1.patch
- check
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *puzzles* to
*e66d027a81211d327319cf45bb4155e689513f72* has Succeeded.
Next steps:
- apply the patch: git am 0001-puzzles-upgrade-to-latest-revision.patch
- check the
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-setuptools* to
*65.7.0* has Succeeded.
Next steps:
- apply the patch: git am
0001-python3-setuptools-upgrade-65.6.3-65.7.0.patch
- check the changes to upstream
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-pbr* to *5.11.1* has
Succeeded.
Next steps:
- apply the patch: git am 0001-python3-pbr-upgrade-5.11.0-5.11.1.patch
- check the changes to upstream patches and
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-wcwidth* to *0.2.6*
has Succeeded.
Next steps:
- apply the patch: git am 0001-python3-wcwidth-upgrade-0.2.5-0.2.6.patch
- check the changes to upstream patches and
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *man-pages* to *6.02* has
Succeeded.
Next steps:
- apply the patch: git am 0001-man-pages-upgrade-6.01-6.02.patch
- check the changes to upstream patches and summarize them
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *vulkan-samples* to
*a42d4eab1e5fe7814dfbe91e3bbaf8ab62cf03f6* has Failed(other errors).
Detailed error information:
'MACHINE=qemux86 bitbake vulkan-samples' failed
WARNING: Host
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *lttng-tools* to *2.13.9* has
Failed (devtool error).
Detailed error information:
Running 'devtool upgrade' for recipe lttng-tools failed.
NOTE: Starting bitbake server...
NOTE:
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *piglit* to
*d8cc3f2da5b429ac199438454ec7feaf7eff1bf3* has Succeeded.
Next steps:
- apply the patch: git am 0001-piglit-upgrade-to-latest-revision.patch
- check the changes
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *ed* to *1.19* has Succeeded.
Next steps:
- apply the patch: git am 0001-ed-upgrade-1.18-1.19.patch
- check the changes to upstream patches and summarize them in the commit
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *rng-tools* to *6.16* has
Failed (devtool error).
Detailed error information:
The following devtool command failed: finish -f rng-tools
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *lttng-modules* to *2.13.8*
has Failed(do_compile).
Detailed error information:
do_compile failed
Next steps:
- apply the patch: git am
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *stress-ng* to *0.15.02* has
Succeeded.
Next steps:
- apply the patch: git am 0001-stress-ng-upgrade-0.15.01-0.15.02.patch
- check the changes to upstream patches and
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *diffoscope* to *232* has
Succeeded.
Next steps:
- apply the patch: git am 0001-diffoscope-upgrade-230-232.patch
- check the changes to upstream patches and summarize them
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *libwebp* to *1.3.0* has
Succeeded.
Next steps:
- apply the patch: git am 0001-libwebp-upgrade-1.2.4-1.3.0.patch
- check the changes to upstream patches and summarize them
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *dpkg* to *1.21.18* has
Succeeded.
Next steps:
- apply the patch: git am 0001-dpkg-upgrade-1.21.17-1.21.18.patch
- check the changes to upstream patches and summarize them
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-hatchling* to
*1.12.2* has Succeeded.
Next steps:
- apply the patch: git am 0001-python3-hatchling-upgrade-1.12.1-1.12.2.patch
- check the changes to upstream
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *u-boot* to *2023.01* has
Failed (devtool error).
Detailed error information:
Running 'devtool upgrade' for recipe u-boot failed.
NOTE: Starting bitbake server...
NOTE:
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *go* to *1.19.5* has
Failed(do_compile).
Detailed error information:
do_compile failed
Next steps:
- apply the patch: git am 0001-go-upgrade-1.19.4-1.19.5.patch
- check
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *ncurses* to *6.4* has
Succeeded.
Next steps:
- apply the patch: git am 0001-ncurses-upgrade-6.3-20220423-6.4.patch
- check the changes to upstream patches and summarize
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-cython* to *0.29.33*
has Succeeded.
Next steps:
- apply the patch: git am 0001-python3-cython-upgrade-0.29.32-0.29.33.patch
- check the changes to upstream patches
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-cryptography-vectors*
to *39.0.0* has Succeeded.
Next steps:
- apply the patch: git am
0001-python3-cryptography-vectors-upgrade-38.0.4-39.0.0.patch
- check the
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-hypothesis* to
*6.62.1* has Succeeded.
Next steps:
- apply the patch: git am
0001-python3-hypothesis-upgrade-6.61.0-6.62.1.patch
- check the changes to upstream
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-packaging* to *23.0*
has Succeeded.
Next steps:
- apply the patch: git am 0001-python3-packaging-upgrade-22.0-23.0.patch
- check the changes to upstream patches and
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *mc* to *4.8.29* has Failed
(devtool error).
Detailed error information:
The following devtool command failed: upgrade mc -V 4.8.29
NOTE: Starting bitbake server...
NOTE:
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *go-runtime* to *1.19.5* has
Failed(do_compile).
Detailed error information:
do_compile failed
Next steps:
- apply the patch: git am
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-dbusmock* to *0.28.7*
has Succeeded.
Next steps:
- apply the patch: git am 0001-python3-dbusmock-upgrade-0.28.6-0.28.7.patch
- check the changes to upstream patches
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *busybox* to *1.36.0* has
Failed (devtool error).
Detailed error information:
Running 'devtool upgrade' for recipe busybox failed.
NOTE: Starting bitbake server...
NOTE:
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-alabaster* to
*0.7.13* has Succeeded.
Next steps:
- apply the patch: git am 0001-python3-alabaster-upgrade-0.7.12-0.7.13.patch
- check the changes to upstream
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *llvm* to *15.0.7* has
Succeeded.
Next steps:
- apply the patch: git am 0001-llvm-upgrade-15.0.6-15.0.7.patch
- check the changes to upstream patches and summarize them in
Hello,
this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe *python3-cryptography* to
*39.0.0* has Failed(do_compile).
Detailed error information:
do_compile failed
Next steps:
- apply the patch: git am
Backport needed patches
Signed-off-by: Khem Raj
---
.../0001-Use-__alignof__-with-clang.patch | 42 +++
meta/recipes-extended/cpio/cpio_2.13.bb | 1 +
2 files changed, 43 insertions(+)
create mode 100644
Thanks. Do you think the tests for the script should as well be
adjusted so that they fail without the change, and pass with it?
(test_bitbakelayers_setup in meta/lib/oeqa/selftest/cases/bblayers.py)
This is clearly fixing a problem you saw in local testing, and it
would be good to ensure the
From: Lee Chee Yang
upgrade include fixes for CVE-2022-39253 CVE-2022-39260
Release notes:
https://github.com/git/git/blob/master/Documentation/RelNotes/2.37.4.txt
Signed-off-by: Lee Chee Yang
---
meta/recipes-devtools/git/{git_2.37.3.bb => git_2.37.4.bb} | 2 +-
1 file changed, 1
Hello Alex,
This patch fixed the https://bugzilla.yoctoproject.org/show_bug.cgi?id=14975 (
'bitbake core-image-full-cmdline' built without any issues.)
But, I tried a ' hello world ' program in booted image (bitbake
core-image-minimal by adding ' cargo ' to IMAGE_INSTALL:append) and getting
Backport fix from master to allow gcc to use proper linker path for
musl [Yocto #14977]
Fixes:
| qemu-arm: Could not open '/lib/ld-musl-armhf.so.1': No such file or directory
Signed-off-by: Pavel Zhukov
---
meta/recipes-devtools/gcc/gcc-11.3.inc | 1 +
Backport fix from master to allow gcc to use proper linker path for
musl [Yocto #14977].
Fixes:
| qemu-arm: Could not open '/lib/ld-musl-armhf.so.1': No such file or directory
Signed-off-by: Pavel Zhukov
---
meta/recipes-devtools/gcc/gcc-11.3.inc| 1 -
This is more complete (and more invasive) refactor of musl dynamic
linker patches in kirkstone branch. No changes have been made to
the master's version except removing of not yet existing loongarch.
This obsoletes "gcc: Fix build with musl and usrmerge on arm" patch which has
been sent earlier
69 matches
Mail list logo