mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-10-01 06:21:56 -09:00
package/slirp: security bump to version 4.3.1
- Use an up to date fork (spice slirp is archived and has not been updated since 2012) - Add COPYRIGHT as the license file - BSD-4-Clause has been replaced by BSD-3-Clause since3bac39137af9f6e69c4e- Add hash file - Switch to meson-package - Fix multiple security vulnerabilities: CVE-2014-3640, CVE-2017-11434, CVE-2019-6778, CVE-2019-9824, CVE-2019-14378 and CVE-2020-10756 Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com> Reviewed-by: Alistair Francis <alistair.francis@wdc.com> Signed-off-by: Peter Korsgaard <peter@korsgaard.com> (cherry picked from commit97fcae8ddf) Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
This commit is contained in:
committed by
Peter Korsgaard
parent
124239f9aa
commit
c335124eac
@@ -1,16 +1,10 @@
|
|||||||
config BR2_PACKAGE_SLIRP
|
config BR2_PACKAGE_SLIRP
|
||||||
bool "slirp"
|
bool "slirp"
|
||||||
help
|
help
|
||||||
The Spice project aims to provide a complete open source
|
libslirp is a user-mode networking library used by virtual
|
||||||
solution for interaction with virtualized desktop devices.
|
machines, containers or various tools.
|
||||||
The Spice project deals with both the virtualized devices
|
|
||||||
and the front-end. Interaction between front-end and
|
|
||||||
back-end is done using VD-Interfaces.
|
|
||||||
|
|
||||||
This package implements the slirp-part for Spice. Slirp
|
https://gitlab.freedesktop.org/slirp/libslirp/
|
||||||
emulates a PPP or SLIP connection over a normal terminal.
|
|
||||||
|
|
||||||
http://www.spice-space.org/
|
|
||||||
|
|
||||||
NOTE:
|
NOTE:
|
||||||
This package has some history of a unique kind:
|
This package has some history of a unique kind:
|
||||||
@@ -21,5 +15,6 @@ config BR2_PACKAGE_SLIRP
|
|||||||
- during that period, QEMU (Fabrice BELLARD) forked the code
|
- during that period, QEMU (Fabrice BELLARD) forked the code
|
||||||
and included it in QEMU
|
and included it in QEMU
|
||||||
- and it was imported from this breed by the Spice project
|
- and it was imported from this breed by the Spice project
|
||||||
around May 2009
|
around May 2009 which archived it in 2012
|
||||||
- which is what we use here
|
- So we switched to
|
||||||
|
https://gitlab.freedesktop.org/slirp/libslirp
|
||||||
|
|||||||
3
package/slirp/slirp.hash
Normal file
3
package/slirp/slirp.hash
Normal file
@@ -0,0 +1,3 @@
|
|||||||
|
# Locally computed:
|
||||||
|
sha256 6b1641f04d41bc45f94018ac8d42d3c9f3ba0e463cbeacf5f26fe83fc050161e libslirp-v4.3.1.tar.bz2
|
||||||
|
sha256 b28aecf4796a6a22054167f0a976de13d9db335669d37afd2dc7ea4c335e1e13 COPYRIGHT
|
||||||
@@ -4,18 +4,12 @@
|
|||||||
#
|
#
|
||||||
################################################################################
|
################################################################################
|
||||||
|
|
||||||
# There's no tarball releases of slirp, so we use the git repo
|
SLIRP_VERSION = 4.3.1
|
||||||
# Also, there's no tag, so we use a random SHA1 (master's HEAD
|
SLIRP_SOURCE = libslirp-v$(SLIRP_VERSION).tar.bz2
|
||||||
# of today)
|
SLIRP_SITE = \
|
||||||
SLIRP_VERSION = 8c2da74c1385242f20799fec8c04f8378edc6550
|
https://gitlab.freedesktop.org/slirp/libslirp/-/archive/v$(SLIRP_VERSION)
|
||||||
SLIRP_SITE = git://anongit.freedesktop.org/spice/slirp
|
SLIRP_LICENSE = BSD-3-Clause
|
||||||
SLIRP_LICENSE = BSD-4-Clause, BSD-2-Clause
|
SLIRP_LICENSE_FILES = COPYRIGHT
|
||||||
# Note: The license file 'COPYRIGHT' is missing from the sources,
|
|
||||||
# although some files refer to it.
|
|
||||||
SLIRP_INSTALL_STAGING = YES
|
SLIRP_INSTALL_STAGING = YES
|
||||||
|
|
||||||
# As we're using the git tree, there's no ./configure,
|
$(eval $(meson-package))
|
||||||
# so we need to autoreconf.
|
|
||||||
SLIRP_AUTORECONF = YES
|
|
||||||
|
|
||||||
$(eval $(autotools-package))
|
|
||||||
|
|||||||
Reference in New Issue
Block a user