Bernd Kuhls
1e20824fb7
package/pure-ftpd: bump version to 1.0.51
...
Changelog: https://github.com/jedisct1/pure-ftpd/blob/master/ChangeLog
Updated copyright hash due to copyright year bump:
cf1a9705c6
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit ad54a80465 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 09:41:36 +02:00
Fabrice Fontaine
f948d3b9ea
package/libcurl: fix build without sched_yield
...
Fix the following build failure without sched_yield raised since bump to
version 7.84.0 in commit b034109dd6 :
In file included from easy.c:89:
easy_lock.h: In function 'curl_simple_lock_lock':
easy_lock.h:56:7: error: implicit declaration of function 'sched_yield' [-Werror=implicit-function-declaration]
56 | sched_yield();
| ^~~~~~~~~~~
Fixes:
- http://autobuild.buildroot.org/results/fbc80a0002d640210c81a4c518856c02669059b7
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Reviewed-by: Baruch Siach <baruch@tkos.co.il >
Tested-by: Giulio Benetti <giulio.benetti@benettiengineering.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit a5adc9b658 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 09:39:35 +02:00
Bernd Kuhls
ed1d5f709c
package/libcurl: security bump to version 7.84.0
...
Fixes the following security issues:
- CVE-2022-32205: Set-Cookie denial of service
https://curl.se/docs/CVE-2022-32205.html
- CVE-2022-32206: HTTP compression denial of service
https://curl.se/docs/CVE-2022-32206.html
- CVE-2022-32207: Unpreserved file permissions
https://curl.se/docs/CVE-2022-32207.html
- CVE-2022-32208: FTP-KRB bad message verification
https://curl.se/docs/CVE-2022-32208.html
Changelog: https://curl.se/changes.html
Upstream removed configure option --enable-hidden-symbols:
0c2d3118aa
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
[Peter: mark as security bump]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit b034109dd6 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 09:39:32 +02:00
Леонид Юрьев (Leonid Yuriev)
d1dd5f6f54
package/libmdbx: bump version to 0.11.8
...
This is stable bugfix release of libmdbx.
The project's website now is on https://libmdbx.dqdkfa.ru/
Release notes for v0.11.8 https://gitflic.ru/project/erthink/libmdbx/release/06268038-39ff-4270-9be8-9f26d5543015
The complete ChangeLog: https://gitflic.ru/project/erthink/libmdbx/blob?file=ChangeLog.md
Signed-off-by: Леонид Юрьев (Leonid Yuriev) <leo@yuriev.ru >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit c099842544 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 09:10:55 +02:00
Fabrice Fontaine
06b3e897e0
package/rabbitmq-server: replace RABBITMQ_SERVER_CPE_ID_VENDOR
...
pivotal_software has been replaced by vmware in March 2022:
<cpe-item name="cpe:/a:pivotal_software:rabbitmq:3.7.28" deprecated="true" deprecation_date="2022-03-17T14:05:30.170Z">
<reference href="https://www.rabbitmq.com/ ">Product</reference>
<reference href="https://github.com/rabbitmq/rabbitmq-server/releases ">Change Log</reference>
<cpe-23:cpe23-item name="cpe:2.3:a:pivotal_software:rabbitmq:3.7.28:*:*:*:*:*:*:*">
<cpe-23:deprecated-by name="cpe:2.3:a:vmware:rabbitmq:3.7.28:*:*:*:*:*:*:*" type="NAME_CORRECTION"/>
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Avmware%3Arabbitmq
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit e5189a09d7 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 09:09:33 +02:00
Fabrice Fontaine
7a58fd8ffa
package/nginx: replace NGINX_CPE_ID_VENDOR
...
nginx has been replaced by f5 since February 2022:
<cpe-item name="cpe:/a:nginx:nginx:1.18.0" deprecated="true" deprecation_date="2022-02-22T19:26:32.967Z">
<reference href="https://nginx.org/en/CHANGES-1.18 ">Change Log</reference>
<cpe-23:cpe23-item name="cpe:2.3:a:nginx:nginx:1.18.0:*:*:*:*:*:*:*">
<cpe-23:deprecated-by name="cpe:2.3:a:f5:nginx:1.18.0:*:*:*:*:*:*:*" type="NAME_CORRECTION"/>
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Af5%3Anginx
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 3bd30f4a13 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 09:08:41 +02:00
Fabrice Fontaine
ec2a21e297
package/systemd: replace SYSTEMD_CPE_ID_VENDOR
...
freedesktop has been replaced by systemd_project since January 2022:
<cpe-item name="cpe:/a:freedesktop:systemd:247:rc1" deprecated="true" deprecation_date="2022-01-28T19:09:42.747Z">
<title xml:lang="en-US">freedesktop systemd 247 Release Candidate 1</title>
<reference href="https://github.com/systemd/systemd/releases ">Change Log</reference>
<cpe-23:cpe23-item name="cpe:2.3:a:freedesktop:systemd:247:rc1:*:*:*:*:*:*">
<cpe-23:deprecated-by name="cpe:2.3:a:systemd_project:systemd:247:rc1:*:*:*:*:*:*" type="NAME_CORRECTION"/>
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Asystemd_project%3Asystemd
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit a143c012ef )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 09:08:34 +02:00
Fabrice Fontaine
8e47d96581
package/tcpreplay: fix build with musl-fts
...
Fix the following build failure with musl-fts raised since bump to
version 4.4.1 in commit cc66cf922b and
e1f4c2ac91 :
/home/giuliobenetti/autobuild/run/instance-1/output-1/host/opt/ext-toolchain/bin/../lib/gcc/powerpc-buildroot-linux-uclibc/10.3.0/../../../../powerpc-buildroot-linux-uclibc/bin/ld: tcpreplay-tcpreplay.o: in function `main':
tcpreplay.c:(.text.startup+0x21c): undefined reference to `fts_open'
Fixes:
- http://autobuild.buildroot.org/results/e47940b5b158395329c0132bb1bbea429c4dc249
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
(cherry picked from commit 4138151e44 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 09:07:26 +02:00
Fabrice Fontaine
be3ce29e30
package/tcpreplay: security bump to version 4.4.1
...
- Fix CVE-2021-45386: tcpreplay 4.3.4 has a Reachable Assertion in
add_tree_ipv6() at tree.c
- Fix CVE-2021-45387: tcpreplay 4.3.4 has a Reachable Assertion in
add_tree_ipv4() at tree.c.
https://github.com/appneta/tcpreplay/blob/v4.4.1/docs/CHANGELOG
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit cc66cf922b )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 09:07:17 +02:00
Fabrice Fontaine
0c565bccd5
package/tcpreplay: replace TCPREPLAY_CPE_ID_VENDOR
...
tcpreplay has been replaced by broadcom since April 2022:
<cpe-item name="cpe:/a:tcpreplay:tcpreplay:4.3.1" deprecated="true" deprecation_date="2022-04-02T03:29:17.303Z">
<title xml:lang="en-US">tcpreplay 4.3.1</title>
<reference href="http://tcpreplay.synfin.net/wiki/Download ">Vendor</reference>
<reference href="https://sourceforge.net/projects/tcpreplay/ ">Product</reference>
<cpe-23:cpe23-item name="cpe:2.3:a:tcpreplay:tcpreplay:4.3.1:*:*:*:*:*:*:*">
<cpe-23:deprecated-by name="cpe:2.3:a:broadcom:tcpreplay:4.3.1:*:*:*:*:*:*:*" type="NAME_CORRECTION"/>
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Abroadcom%3Atcpreplay
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 77bf0a1e63 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 09:07:10 +02:00
Fabrice Fontaine
1f1b283c69
package/darkhttpd: add DARKHTTPD_CPE_ID_VENDOR
...
cpe:2.3:a:darkhttpd_project:darkhttpd is a valid CPE identifier for this
package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Adarkhttpd_project%3Adarkhttpd
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit b27b4adaa4 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 09:06:41 +02:00
Fabrice Fontaine
68de34c986
package/libpjsip: fix CVE-2022-31031
...
PJSIP is a free and open source multimedia communication library written
in C language implementing standard based protocols such as SIP, SDP,
RTP, STUN, TURN, and ICE. In versions prior to and including 2.12.1 a
stack buffer overflow vulnerability affects PJSIP users that use STUN in
their applications, either by: setting a STUN server in their
account/media config in PJSUA/PJSUA2 level, or directly using
`pjlib-util/stun_simple` API.
https://github.com/pjsip/pjproject/security/advisories/GHSA-26j7-ww69-c4qj
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Reviewed-by: Luca Ceresoli <luca.ceresoli@bootlin.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 7ea3831685 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 09:04:13 +02:00
Fabrice Fontaine
a65cbbc9ff
package/bdwgc: fix build without NPTL
...
Fix the following guile build failure without NPTL raised since the
addition of bdwgc in commit b0476427f6 and
7896408d41 :
configure:60776: checking for GC_is_heap_ptr
configure:60776: /home/buildroot/autobuild/instance-2/output-1/host/bin/arm-buildroot-linux-uclibcgnueabi-gcc -std=gnu11 -o conftest -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O1 -g0 -DHAVE_GC_SET_FINALIZER_NOTIFIER -DHAVE_GC_GET_HEAP_USAGE_SAFE -DHAVE_GC_GET_FREE_SPACE_DIVISOR -DHAVE_GC_SET_FINALIZE_ON_DEMAND -flto -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 conftest.c -L/home/buildroot/autobuild/instance-2/output-1/host/bin/../arm-buildroot-linux-uclibcgnueabi/sysroot/usr/lib -latomic_ops -lgc -lpthread -ldl -latomic -lm >&5
/home/buildroot/autobuild/instance-2/output-1/host/lib/gcc/arm-buildroot-linux-uclibcgnueabi/10.3.0/../../../../arm-buildroot-linux-uclibcgnueabi/bin/ld: /home/buildroot/autobuild/instance-2/output-1/host/bin/../arm-buildroot-linux-uclibcgnueabi/sysroot/usr/lib/libgc.so: undefined reference to `pthread_getattr_np'
[...]
In file included from ../libguile/alist.h:26,
from ../libguile.h:31,
from guile.c:38:
../libguile/pairs.h:205:1: error: conflicting types for 'GC_is_heap_ptr'
205 | GC_is_heap_ptr (void *ptr)
| ^~~~~~~~~~~~~~
In file included from ../libguile/bdw-gc.h:48,
from ../libguile/gc.h:142,
from ../libguile/pairs.h:26,
from ../libguile/alist.h:26,
from ../libguile.h:31,
from guile.c:38:
/home/buildroot/autobuild/instance-2/output-1/host/arm-buildroot-linux-uclibcgnueabi/sysroot/usr/include/gc/gc.h:551:20: note: previous declaration of 'GC_is_heap_ptr' was here
551 | GC_API int GC_CALL GC_is_heap_ptr(const void *);
| ^~~~~~~~~~~~~~
Fixes:
- http://autobuild.buildroot.org/results/819f231a60fc81f9a8dd07bf5411aa9d8f78c3bb
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 41d60d0164 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 09:00:57 +02:00
Fabrice Fontaine
977644b7d1
package/cups: fix CUPS_CPE_ID_VENDOR
...
CUPS_CPE_ID_VENDOR is wrong since switch to OpenPrinting upstream
repository in commit 8cf034ab0f :
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Aopenprinting%3Acups
While at it, also fix URL in Config.in
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit b598a284f1 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:32:32 +02:00
James Hilliard
d1f700b3f1
package/gst1-python: bump version to 1.20.3
...
Drop patch which is now upstream.
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 613a3ac3d0 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:32:32 +02:00
James Hilliard
431a3fd201
package/gst-omx: bump version to 1.20.3
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit a9281777a3 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:32:32 +02:00
James Hilliard
995d28a74f
package/gstreamer1-editing-services: bump version to 1.20.3
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 7ceabd4846 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:32:31 +02:00
James Hilliard
6f1064240b
package/gst1-rtsp-server: bump version to 1.20.3
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 5b073d8bbc )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:32:31 +02:00
James Hilliard
8ca7a33659
package/gst1-vaapi: bump version to 1.20.3
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 347af9f125 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:32:31 +02:00
James Hilliard
5011081550
package/gst1-libav: bump version to 1.20.3
...
Drop patch which is now upstream.
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 88d70d2c2b )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:32:31 +02:00
James Hilliard
2742cf49b6
package/gst1-devtools: bump version to 1.20.3
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 6bf46fc5cc )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:32:31 +02:00
James Hilliard
c6a20a9d32
package/gst1-plugins-ugly: bump version to 1.20.3
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 2d230792e3 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:32:31 +02:00
James Hilliard
4b53df1729
package/gst1-plugins-bad: bump version to 1.20.3
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 65852010cd )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:32:31 +02:00
James Hilliard
7070762da9
package/gst1-plugins-good: security bump to version 1.20.3
...
Fixes the following security issues:
- avidemux: Fix integer overflow resulting in heap corruption in DIB buffer
inversion code
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/2609
- matroskademux: Avoid integer-overflow resulting in heap corruption in
WavPack header handling code
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/2613
- matroskademux, qtdemux: Fix integer overflows in zlib/bz2/etc
decompression code
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/2611
- smpte: Fix integer overflow with possible heap corruption in GstMask
creation
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/2605
- smpte: integer overflow with possible heap corruption in GstMask creation
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/1231
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit ce4a549dbe )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:32:31 +02:00
James Hilliard
c8f5b29805
package/gst1-plugins-base: bump version to 1.20.3
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit b1a2a28460 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:32:30 +02:00
James Hilliard
49cf74f457
package/gstreamer1: bump to version 1.20.3
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit d8376fc31e )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:32:30 +02:00
Fabrice Fontaine
1597bcd136
package/libsndfile: fix libsndfile.pc
...
Fix the following build failure with libsamplerate or minimodem raised
since bump to version 1.1.0 in commit
c59a9d12b7 :
powerpc-buildroot-linux-uclibc-gcc.br_real: error: EXTERNAL_MPEG_LIBS@: No such file or directory
Add host-pkgconf dependency to avoid the following build failure when
running autoreconf:
configure.ac:345: error: macro PKG_INSTALLDIR is not defined; is a m4 file missing?
m4/ax_require_defined.m4:35: AX_REQUIRE_DEFINED is expanded from...
Fixes:
- http://autobuild.buildroot.org/results/6de2d7634b1958693b7cf96fbcc79121f92347e9
- http://autobuild.buildroot.org/results/bf66b19cacd6394957f534035af647ddd8037d60
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
(cherry picked from commit affabe47a2 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:24:23 +02:00
Fabrice Fontaine
50fda39538
package/libsndfile: security bump to version 1.1.0
...
Fix the following security issues:
- Heap buffer overflow in wavlike_ima_decode_block()
- Heap buffer overflow in msadpcm_decode_block()
- Heap buffer overflow in psf_binheader_readf()
- Index out of bounds in psf_nms_adpcm_decode_block()
- Heap buffer overflow in flac_buffer_copy()
- Heap buffer overflow in copyPredictorTo24()
- Uninitialized variable in psf_binheader_readf()
Drop patch (already in version)
While at it, also drop mention of CVE-2018-13419 which is correctly
tagged as only affecting version 1.0.28 in NVD NIST database:
https://nvd.nist.gov/vuln/detail/CVE-2018-13419
https://github.com/libsndfile/libsndfile/releases/tag/1.1.0
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit c59a9d12b7 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:24:21 +02:00
Angelo Compagnucci
f431001592
package/cups: security bump to version 2.4.2
...
Fixes CVE-2022-26691
https://github.com/OpenPrinting/cups/blob/master/CHANGES.md
Signed-off-by: Angelo Compagnucci <angelo@amarulasolutions.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 433fd541ea )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:18:19 +02:00
Angelo Compagnucci
a431164d4f
package/cups: bump to version 2.4.1
...
NOTICE hash is changed due to a copyright year update.
Signed-off-by: Angelo Compagnucci <angelo@amarulasolutions.com >
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be >
(cherry picked from commit bac3eadda8 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:18:01 +02:00
Fabrice Fontaine
2a01961719
package/paxtest: disable on microblaze
...
Disable paxtest on microblaze to avoid the following build failure:
shlibtest.c:9:1: error: requested alignment '65536' exceeds object file maximum 32768
9 | char shbss[PAGE_SIZE_MAX] __pagealigned;
| ^~~~
Updating second patch to set PAGE_SIZE_MAX to 32768 will raise another
build failure:
/tmp/cccMSYDr.s: Assembler messages:
/tmp/cccMSYDr.s: Error: PC relative branch to label buf which is not in the instruction space
Fixes:
- http://autobuild.buildroot.org/results/aba489143b4017617f67c1012bba1f4687708380
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit abfca98ea2 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:16:01 +02:00
James Hilliard
8cd128da92
package/{webkitgtk, wpewebkit}: select debugutils for multimedia
...
When using webkit with multimedia support the fakevideosink element
is used in some places, as such we should select debugutils which
provides fakevideosink when building with multimedia support.
See:
12086bcde7/Source/WebCore/platform/graphics/gstreamer/MediaPlayerPrivateGStreamer.cpp (L3863)
Additionally webkit may also use the fpsdisplaysink element which
is also provided by debugutils.
See:
12086bcde7/Source/WebCore/platform/graphics/gstreamer/MediaPlayerPrivateGStreamer.cpp (L3897)
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Acked-by: Adrian Perez de Castro <aperez@igalia.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit e826142874 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-22 08:14:20 +02:00
Peter Korsgaard
2ccfe0066e
package/wireguard-linux-compat: bump version to 1.0.20211208
...
For details, see the announcement:
https://lists.zx2c4.com/pipermail/wireguard/2021-December/007369.html
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit df27a9daa6 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 23:50:18 +02:00
Nicolas POIROT
e924e351f6
docs/manual: fix configurations listing command
...
Signed-off-by: Nicolas POIROT <ni.poirot@laposte.net >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 5c5f30cbc7 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 23:43:45 +02:00
Fabrice Fontaine
8f6aebdb2e
package/ecryptfs-utils: add libgpgme optional dependency
...
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be >
(cherry picked from commit e122d962a1 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 19:09:32 +02:00
Fabrice Fontaine
59e7917e61
package/ecryptfs-utils: add pkcs11-helper optional dependency
...
pkcs11-helper is an optional dependency which needs openssl
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be >
(cherry picked from commit f90061fc38 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 19:09:28 +02:00
Fabrice Fontaine
c3a3cf97e9
package/fxload: fix static build
...
Fix the following static build failure:
/home/buildroot/autobuild/instance-3/output-1/host/bin/sh4-buildroot-linux-musl-gcc -o fxload ezusb.o main.o
/home/buildroot/autobuild/instance-3/output-1/host/lib/gcc/sh4-buildroot-linux-musl/10.3.0/../../../../sh4-buildroot-linux-musl/bin/ld: /home/buildroot/autobuild/instance-3/output-1/host/lib/gcc/sh4-buildroot-linux-musl/10.3.0/libgcc.a(unwind-dw2.o): in function `size_of_encoded_value':
/home/buildroot/autobuild/instance-3/output-1/build/host-gcc-final-10.3.0/build/sh4-buildroot-linux-musl/libgcc/../../../libgcc/unwind-pe.h:89: undefined reference to `abort'
Fixes:
- http://autobuild.buildroot.org/results/bca28d7a6d2b324fb61fe99b8af4b86caa2350ee
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be >
(cherry picked from commit dbfb753749 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 19:03:30 +02:00
Fabrice Fontaine
1f484313c5
package/libtalloc: fix build wihout SSP
...
Fix the following build failure without SSP raised since the addition of
the package in commit f0d37e275a :
/home/autobuild/autobuild/instance-5/output-1/host/lib/gcc/i686-buildroot-linux-musl/9.4.0/../../../../i686-buildroot-linux-musl/bin/ld: talloc.c.5.o: in function `_vasprintf_tc':
talloc.c:(.text+0x427d): undefined reference to `__stack_chk_fail_local'
Fixes:
- http://autobuild.buildroot.org/results/e221bde25c7622db99761d0adcd56663296beb15
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be >
(cherry picked from commit 6a8dae6ddd )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 19:01:21 +02:00
Fabrice Fontaine
2d021a7e71
package/libmodsecurity: needs dynamic library with libcurl and mbedtls
...
libmodsecurity embeds several mbedtls source files since version 3.0.0
and
a3ae686f25
resulting in the following static build failure if curl is built with
mbedtls support:
/home/buildroot/autobuild/instance-0/output-1/host/opt/ext-toolchain/m68k-buildroot-uclinux-uclibc/bin/ld.real: /home/buildroot/autobuild/instance-0/output-1/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib/libmbedcrypto.a(md5.c.o): in function `mbedtls_md5_free':
md5.c:(.text+0x16): multiple definition of `mbedtls_md5_free'; ../../src/.libs/libmodsecurity.a(libmbedtls_la-md5.o):md5.c:(.text+0x16): first defined here
Fixes:
- http://autobuild.buildroot.org/results/98472a3a41cdbcb3d02289a437074a267f4b2e8e
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be >
(cherry picked from commit 9fc652a373 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 18:35:54 +02:00
Fabrice Fontaine
a087851b4e
package/procrank_linux: fix static build
...
Pass TARGET_CFLAGS which will contain -static to fix the following
static build failure:
/home/buildroot/autobuild/instance-0/output-1/host/bin/sh4a-buildroot-linux-musl-gcc -Wall procrank.c -Ilibpagemap/include -Llibpagemap -lpagemap -o procrank
/home/buildroot/autobuild/instance-0/output-1/host/lib/gcc/sh4a-buildroot-linux-musl/10.3.0/../../../../sh4a-buildroot-linux-musl/bin/ld: /home/buildroot/autobuild/instance-0/output-1/host/lib/gcc/sh4a-buildroot-linux-musl/10.3.0/libgcc.a(unwind-dw2.o): in function `size_of_encoded_value':
/home/buildroot/autobuild/instance-0/output-1/build/host-gcc-final-10.3.0/build/sh4a-buildroot-linux-musl/libgcc/../../../libgcc/unwind-pe.h:89: undefined reference to `abort'
Fixes:
- http://autobuild.buildroot.org/results/8eccc34c99a75501179fe93a80646cc684261ff4
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be >
(cherry picked from commit 22b7fb8a8d )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 18:26:54 +02:00
Fabrice Fontaine
a1ccba72dd
package/sofia-sip: security bump to version 1.13.8
...
Fix CVE-2022-31001, CVE-2022-31002 and CVE-2022-31003:
https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-79jq-hh82-cv9g
https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-g3x6-p824-x6hm
https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-8w5j-6g2j-pxcp
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be >
(cherry picked from commit d4b47d41ca )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 18:24:21 +02:00
Fabrice Fontaine
2f7b6e3990
package/sofia-sip: fix version
...
Fix version to better match what is expected by NVD NIST database,
release-monitoring.org as well as upstream github
(https://github.com/freeswitch/sofia-sip/tags )
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be >
(cherry picked from commit 978800fadb )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 18:24:12 +02:00
Fabrice Fontaine
2ac47218c6
package/sofia-sip: add SOFIA_SIP_CPE_ID_VENDOR
...
cpe:2.3:a:signalwire:sofia-sip is a valid CPE identifier for this
package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Asignalwire%3Asofia-sip
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be >
(cherry picked from commit b77ee6ce55 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 18:24:06 +02:00
Angelo Compagnucci
2a066059d6
package/wpa_supplicant: fixing "Invalid configuration line"
...
Default configuration file is wrong for the default compiling options.
Fixes:
Successfully initialized wpa_supplicant
Line 1: unknown global field 'ctrl_interface=/var/run/wpa_supplicant'.
Line 1: Invalid configuration line
'ctrl_interface=/var/run/wpa_supplicant'.
Failed to read or parse configuration '/etc/wpa_supplicant.conf'.
Signed-off-by: Angelo Compagnucci <angelo@amarulasolutions.com >
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be >
(cherry picked from commit a76294cd6c )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 18:09:50 +02:00
Fabrice Fontaine
aee9de937d
package/qdecoder: security bump to version 12.1.0
...
This is a maintenance release includes important security updates that
fixes possible vulnerability in URL decoding (see the report attached
below). All the qDecoder users are recommended to upgrade to this
version as soon as possible.
Fix CVE-2022-32265
Update hash of COPYING (change in year and URL removed:
51bdcc2c15
745878212d )
https://github.com/wolkykim/qdecoder/releases/tag/v12.1.0
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit c79d8cb72c )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 18:00:30 +02:00
Bernd Kuhls
4f8f9c1506
package/postgresql: bump version to 14.4
...
Release notes:
https://www.postgresql.org/about/news/postgresql-144-released-2470/
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 2579cc2cb3 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 17:34:12 +02:00
Nicolas Cavallari
6ad9faf26a
package/avahi: fix GNUism in S05avahi-setup.sh
...
This script uses "chown user.group" instead of the POSIX "chown
user:group". The first syntax is a deprecated GNU extension.
Since coreutils 9.1, chown started issuing a warning when this syntax is
used¹.
The result is that if both avahi and coreutils are enabled, this message
appears during boot:
chown: warning: '.' should be ':': 'avahi.avahi'
[1] https://git.savannah.gnu.org/cgit/gnulib.git/commit/lib/userspec.c?id=23cca8268d21f5d58ed0209002d5673d0518c426
Signed-off-by: Nicolas Cavallari <nicolas.cavallari@green-communications.fr >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit ccea032c75 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 17:10:59 +02:00
Fabrice Fontaine
9363299e19
package/libabseil-cpp: fix musl build on mips
...
Fix the following musl build failure on mips:
In file included from /nvmedata/autobuild/instance-15/output-1/build/libabseil-cpp-20211102.0/absl/base/internal/low_level_alloc.cc:26:
/nvmedata/autobuild/instance-15/output-1/build/libabseil-cpp-20211102.0/absl/base/internal/direct_mmap.h:49:10: fatal error: sgidefs.h: No such file or directory
49 | #include <sgidefs.h>
| ^~~~~~~~~~~
Fixes:
- http://autobuild.buildroot.org/results/3fa027e602bacb22316fb5d9b233baa0b0f0e845
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 4e56904624 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 17:09:59 +02:00
Fabrice Fontaine
2f0a8aa0c1
package/iptables: drop duplicated dependency
...
libnetfilter_conntrack dependency is wrongly duplicated since commit
b835171cf9
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
[Peter: drop from "main" _DEPENDENCIES instead]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 857447d2d2 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 17:09:06 +02:00
Nicola Di Lieto
3bb7408b5f
package/uacme: allow ualpn with mbedTLS
...
Following the update to mbedTLS 2.28.0 in commit 0f8aab08 , ualpn can
work with mbedTLS without restrictions.
References
https://git.buildroot.net/buildroot/commit?id=96c3b52132b41716ca445b4c73a1a8886c26e5ee
https://github.com/ndilieto/uacme/issues/23#issuecomment-1043409796
bbee626cf5
https://github.com/Mbed-TLS/mbedtls/pull/3243
Signed-off-by: Nicola Di Lieto <nicola.dilieto@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 6c7b46945e )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-07-19 17:07:43 +02:00