Commit Graph

76524 Commits

Author SHA1 Message Date
Neal Frager
3761177a89 boot/xilinx-embeddedsw: change dependency
Now that BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH can contain multiple tuples,
BR2_TARGET_XILINX_EMBEDDEDSW can no longer be dependent on:

depends on BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH = "microblazeel-xilinx-elf"

A valid definition could have "microblazeel-xilinx-elf" as just one of many
tuples in the list.

For this reason, this patch changes the dependency to:

depends on BR2_TOOLCHAIN_BARE_METAL_BUILDROOT

One side effect of this is that the user comment will be displayed now when
using multiple tuples, even if one of them is the required tuple.

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Arnout Vandecappelle <arnout@mind.be>
2025-02-17 23:22:20 +01:00
Neal Frager
02b9d987c4 toolchain/toolchain-bare-metal-buildroot: update help text for multiple tuple support
Now that binutils-bare-metal, gcc-bare-metal and newlib-bare-metal packages
have been upgraded to support a list of architecture tuples, this patch
updates the toolchain-bare-metal-buildroot help text to describe the new
capability.

BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH is still backwards compatible with
its prior definition as defining a single tuple with this new definition
works exactly the same as before.

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Arnout Vandecappelle <arnout@mind.be>
2025-02-17 23:22:19 +01:00
Neal Frager
28ae74a134 package/newlib-bare-metal: add multiple tuple support
Add support to gcc-bare-metal to support multiple architecture tuples
with the BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH string.

To do this, custom configure, build and install commands are needed, so that
each step goes through a loop of the architecture tuples in the list.

To keep consistency with autotools, all the relevant target configurations
have been copied into the NEWLIB_BARE_METAL_CONF_OPTS while removing any
configurations that do not apply to newlib.

Also, the following configs were not taken because newlib is being built for
each of the bare-metal targets and not the main target of Buildroot.

$$(TARGET_CONFIGURE_OPTS)
$$(TARGET_CONFIGURE_ARGS)
--target=$$(GNU_TARGET_NAME)
--host=$$(GNU_TARGET_NAME)

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Arnout Vandecappelle <arnout@mind.be>
2025-02-17 22:48:43 +01:00
Neal Frager
1ff6caf801 package/gcc-bare-metal: add multiple tuple support
Add support to gcc-bare-metal to support multiple architecture tuples
with the BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH string.

To do this, custom configure, build and install commands are needed, so that
each step goes through a loop of the architecture tuples in the list.

To keep consistency with autotools, all the relevant host configurations have
been copied into the HOST_GCC_BARE_METAL_CONF_OPTS while removing any
configurations that do not apply to gcc and removing redundant configs.

autotools redundant configs covered by $(HOST_CONFIGURE_OPTS):
	CFLAGS="$$(HOST_CFLAGS)"
	LDFLAGS="$$(HOST_LDFLAGS)"

autotools configs not applicable to gcc:
	--disable-gtk-doc
	--disable-gtk-doc-html
	--disable-doc
	--disable-docs
	--disable-documentation
	--disable-debug
	--with-xmlto=no
	--with-fop=no
	--disable-nls

While we're at it: the following configuration option was incorrect:
--disable-initfini_array -> --disable-initfini-array
configure converts - to _ anyway so it makes no difference, but it's
better to be consistent.

Signed-off-by: Neal Frager <neal.frager@amd.com>
[Arnout: keep --disable-libstdcxx-pch and better explanation for
--disable-initfini-array]
Signed-off-by: Arnout Vandecappelle <arnout@mind.be>
2025-02-17 22:47:38 +01:00
Neal Frager
57d73ec8e0 package/binutils-bare-metal: add multiple tuple support
Add support to binutils-bare-metal to support multiple architecture tuples
with the BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH string.

To do this, custom configure, build and install commands are needed, so that
each step goes through a loop of the architecture tuples in the list.

To keep consistency with autotools, all the relevant host configurations have
been copied into the HOST_BINUTILS_BARE_METAL_CONF_OPTS while removing any
configurations that do not apply to binutils and removing redundant configs.

autotools redundant configs covered by $(HOST_CONFIGURE_OPTS):
	CFLAGS="$$(HOST_CFLAGS)"
	LDFLAGS="$$(HOST_LDFLAGS)"

autotools configs not applicable to binutils:
	--disable-gtk-doc
	--disable-gtk-doc-html
	--disable-doc
	--disable-docs
	--disable-documentation
	--disable-debug
	--with-xmlto=no
	--with-fop=no
	--disable-nls

One of the configurations already in the binutils-bare-metal package was not
needed.

--enable-static -> handled by --disable-shared

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Arnout Vandecappelle <arnout@mind.be>
2025-02-17 22:24:26 +01:00
Scott Fan
8a1ae9e0b1 package/sqlite: fix build issue if C++ is not enabled since bump to 3.49.0
Buildroot commit [1] bumped sqlite to 3.49.0, and commit [2] fixed the
package infra. But if the toolchain does not have C++ support enabled,
the following error will occur.
  Error: failed to find: no

The reason was CXX has been set to 'no' in the package/Makefile.in file.
ifneq ($(BR2_INSTALL_LIBSTDCPP),y)
TARGET_CONFIGURE_OPTS += CXX=no
endif

Then the autosetup script will look for a required path ('no' above),
and will exit with an error if not found.

To solve it, we can set CXX to 'false' instead of 'no', so that the
autosetup script will skip checking for a C++ compiler.

Fixes:
  https://autobuild.buildroot.org/?reason=sqlite-3.49.0
  https://autobuild.buildroot.org/results/569a3750681cc10688ac663450dc2773a317bb07/

[1] db85638cea
[2] a93680be30

Signed-off-by: Scott Fan <fancp2007@gmail.com>
[Julien: add a link to an actual build failure]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-17 21:40:53 +01:00
Scott Fan
004db1f5f3 package/sqlite: fix configure options for readline/editline support
The autosetup script will skip checking for readline.h when cross-compiling,
which will cause line-editing support for the sqlite3 shell to always be "none".

In this case, if the --editline option is provided, an error will be reported:
ERROR: Explicit --editline failed to find a matching library.

However, we can enable readline or editline support by specifying the CFLAGS
and LDFLAGS values ​​instead of having it handled automatically by the
autosetup configure script.

In addition, the libedit package actually depends on the ncurses package,
just like the readline package. So when using the libedit package,
also add the ncurses dependency.

Tested-by: Waldemar Brodkorb <wbx@openadk.org>
Signed-off-by: Scott Fan <fancp2007@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-17 21:35:36 +01:00
Maxim Kochetkov
ef3d171e50 package/libosmium: bump version to 2.21.0
Release-notes: https://github.com/osmcode/libosmium/releases/tag/v2.21.0

Bump minimal GCC version to 5. (Switched to C++14 as minimum requirement)
a83fbf8852

Remove support for projection using the Proj library
711721cb1f

Signed-off-by: Maxim Kochetkov <fido_max@inbox.ru>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-17 21:28:45 +01:00
Scott Fan
0ee5c51d6a package/timescaledb: bump version to 2.18.1
Release notes: https://github.com/timescale/timescaledb/blob/2.18.1/CHANGELOG.md

Signed-off-by: Scott Fan <fancp2007@gmail.com>
Reviewed-by: Maxim Kochetkov <fido_max@inbox.ru>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-17 21:23:29 +01:00
Aleksandr Makarov
ee53f5fcba package/cpp-httplib: bump to version 0.19.0
For release note, see:
https://github.com/yhirose/cpp-httplib/releases/tag/v0.19.0

Signed-off-by: Aleksandr Makarov <aleksandr.o.makarov@gmail.com>
[Julien: add link to release note]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-17 21:17:37 +01:00
Peter Korsgaard
ad82b28427 package/assimp: add upstream security fix for CVE-2024-48423
Fixes the following security issue:

CVE-2024-48423: An issue in assimp v.5.4.3 allows a local attacker to
execute arbitrary code via the CallbackToLogRedirector function within the
Assimp library

https://github.com/assimp/assimp/issues/5788
https://www.cve.org/CVERecord?id=CVE-2024-48423

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-17 21:12:22 +01:00
Scott Fan
d95ea2dcf3 configs/cubieboard2: bump Linux to 6.12.14 and U-Boot to 2025.01
Signed-off-by: Scott Fan <fancp2007@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-17 19:47:54 +01:00
Scott Fan
071741f981 configs/cubieboard1: bump Linux to 6.12.14 and U-Boot to 2025.01
Signed-off-by: Scott Fan <fancp2007@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-17 19:47:51 +01:00
Gilles Talis
08e53fbf7b package/xapian: bump to version 1.4.27
Change log for version 1.4.27:
https://trac.xapian.org/wiki/ReleaseOverview/1.4.27

Signed-off-by: Gilles Talis <gilles.talis@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 18:35:23 +01:00
Gilles Talis
2577fbedbe package/webp: bump to version 1.5.0
ChangeLog (concise version):
https://github.com/webmproject/libwebp/blob/main/NEWS

ChangeLog (detailed version):
https://github.com/webmproject/libwebp/blob/main/ChangeLog

Signed-off-by: Gilles Talis <gilles.talis@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 18:33:09 +01:00
Gilles Talis
f32da8b984 package/tesseract-ocr: bump to version 5.5.0
Change log:
https://github.com/tesseract-ocr/tesseract/blob/main/ChangeLog

Signed-off-by: Gilles Talis <gilles.talis@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 18:27:19 +01:00
Gilles Talis
ca5618a42f package/restclient-cpp: bump to version 0.5.3
ChangeLog:
https://github.com/mrtazz/restclient-cpp/blob/main/CHANGELOG.md

Signed-off-by: Gilles Talis <gilles.talis@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 18:24:46 +01:00
Gilles Talis
605d17e56f package/httping: bump to version ffb9201042813c58d020df41697f6445df96f438
Use the latest upstream verified commit.
Also fixes multiple issues like:
https://autobuild.buildroot.org/results/fe33a0d9cfa242cbcda0c5fb759b84efc6662097

that were due to the usage of OpenSSL deprecated routines
(ERR_remove_state and ENGINE_cleanup)

The build failure happen since Buildroot commit [1] "package/httping:
update to latest git" and when BR2_PACKAGE_HTTPING_SSL=y.

[1] 1c2fa85cb1

Signed-off-by: Gilles Talis <gilles.talis@gmail.com>
[Julien:
 - remove test-pkg result from commit log,
 - add info on the failure
]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 18:19:09 +01:00
Gilles Talis
90047d0c22 package/leptonica: bump to version 1.85.0
Change log:
http://www.leptonica.org/source/version-notes.html

Signed-off-by: Gilles Talis <gilles.talis@gmail.com>
[Julien: add "package/" in patch title]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 18:06:33 +01:00
Gilles Talis
34a488ba7b configs/friendlyarm_nanopi_r2s: update BSP versions
- Switch to Linux LTS release 6.12.13
- Switch to U-Boot 2024.10
- Switch to ATF 2.12
- Add BR2_TARGET_UBOOT_NEEDS_PYELFTOOLS option required to build U-Boot
- Also fixes multiple occurrences of this issue:
https://gitlab.com/buildroot.org/buildroot/-/jobs/9122556338

Signed-off-by: Gilles Talis <gilles.talis@gmail.com>
[Julien: add missing BR2_TARGET_UBOOT_NEEDS_GNUTLS=y]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 17:50:18 +01:00
Bernd Kuhls
b74f9b8a97 package/intel-vpl-gpu-rt: bump version to 25.1.2
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 16:50:52 +01:00
Bernd Kuhls
6da3745ecb package/intel-mediadriver: bump version to 25.1.2
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 16:50:48 +01:00
Bernd Kuhls
f3d9ab5711 package/linux-firmware: bump version to 20250211
Updating the hash of the WHENCE file, due to firmware additions and
firmware changes, but no changes to the redistribution/licensing
conditions.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 16:39:27 +01:00
Bernd Kuhls
67a0f96b88 package/intel-microcode: security bump version to 20250211
Release notes:
https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250211

CVE-2024-31068:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01166.html

CVE-2024-36293
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01213.html

CVE-2023-43758, CVE-2023-34440, CVE-2024-24582, CVE-2024-29214,
CVE-2024-28127, CVE-2024-39279, CVE-2024-31157 & CVE-2024-28047:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01139.html

CVE-2024-39355:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01228.html

CVE-2024-37020:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01194.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 16:28:59 +01:00
Bernd Kuhls
b8638648d6 {linux, linux-headers}: bump 6.{6, 12}.x series
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 16:26:25 +01:00
Peter Macleod Thompson
678ad7d69d package/sdl2_image: bump version to 2.8.4
For release notes since 2.8.2, see:
https://github.com/libsdl-org/SDL_image/releases/tag/release-2.8.3
https://github.com/libsdl-org/SDL_image/releases/tag/release-2.8.4

Signed-off-by: Peter Macleod Thompson <peter.macleod.thompson@gmail.com>
[Julien: add links to release notes]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 15:05:51 +01:00
Peter Macleod Thompson
9f5ef2d872 package/sdl2_ttf: bump version to 2.24.0
For release note, see:
https://github.com/libsdl-org/SDL_ttf/releases/tag/release-2.24.0

This commit also updates the license hash, after year update in:
cf8e187373

Signed-off-by: Peter Macleod Thompson <peter.macleod.thompson@gmail.com>
[Julien: add link to release note and comment about licence hash change]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 15:05:11 +01:00
Jan Čermák
9ee276732a package/erofs-utils: bump to version 1.8.5
Bump to latest maintenance release containing various fixes and performance
improvements, for details see the changelog:
https://git.kernel.org/pub/scm/linux/kernel/git/xiang/erofs-utils.git/tree/ChangeLog?h=v1.8.5

Signed-off-by: Jan Čermák <sairon@sairon.cz>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 13:47:34 +01:00
Yann E. MORIN
7ba7da8f7d package/skopeo: bump to version 1.18.0
For change log, see:
https://github.com/containers/skopeo/releases/tag/v1.18.0

Signed-off-by: Yann E. MORIN <yann.morin@orange.com>
[Julien: add link to change log]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 13:31:36 +01:00
Dario Binacchi
c7f4a9a1e7 package/armadillo: bump to version 14.2.3
Release notes:
https://arma.sourceforge.net/docs.html#changelog

Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 13:07:59 +01:00
Vincent Fazio
e2870d7669 package/python-evdev: bump to version 1.9.0
Since Buildroot commit [1] "package/python-evdev: bump to version
1.8.0", python-evdev is failing to build with error:

    evdev/ecodes.c: In function 'PyInit__ecodes':
    evdev/ecodes.c:65:29: error: 'BUS_AMD_SFH' undeclared (first use in this function)
       65 |     PyModule_AddIntMacro(m, BUS_AMD_SFH);
          |                             ^~~~~~~~~~~
    /home/autobuild/autobuild/instance-8/output-1/build/python3-3.12.8/Include/modsupport.h:61:70: note: in definition of macro 'PyModule_AddIntMacro'
       61 | #define PyModule_AddIntMacro(m, c) PyModule_AddIntConstant((m), #c, (c))
          |                                                                      ^
    ...

Upstream commit [2] included in this version fixes issues when
building wheels.

Fixes:
- https://gitlab.com/buildroot.org/buildroot/-/jobs/9085451384
- https://autobuild.buildroot.org/results/61a3b74e60f2f0f93e312803812ab4d98c492599/
- and many others...

[1] 455ef44d26
[2] 3ff9816e08

Signed-off-by: Vincent Fazio <vfazio@xes-inc.com>
[Julien: reworded the commit log to add extra info]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 12:47:52 +01:00
Vincent Fazio
9bc3bbce38 support/testing: test_python_{gnupg, spake2}: increase timeout value
Previously, these tests had the potential for timing out with the
default 5 second timeout value if initializing /dev/urandom took too
long.

Now the tests use a 10 second timeout value.

Signed-off-by: Vincent Fazio <vfazio@xes-inc.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 12:13:44 +01:00
Vincent Fazio
41b08a779b support/testing: test_python_txaio: include twisted sample
Prior to b7d251293a, txaio would test both asyncio and twisted.

Add back the twisted sample and include the twisted package in the
config so both modes of the package are tested.

Fixes: b7d251293a ("package/python-txaio: drop python 2 support")
Signed-off-by: Vincent Fazio <vfazio@xes-inc.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 12:05:11 +01:00
Леонид Юрьев (Leonid Yuriev)
acb81d4a69 package/libmdbx: bump version to 0.13.4
This is stable release "Sigma Boy" of frontward libmdbx branch with new superior features.

Since 0.13.x libmdbx is licensed under the Apache 2.0 License.
For notes about the license change, credits and acknowledgments,
please refer to the COPYRIGHT file within original libmdbx source code
repository https://gitflic.ru/project/erthink/libmdbx

Please visit https://libmdbx.dqdkfa.ru for more information, changelog,
documentation, C++ API description and links to the original git repo
with the source code. Questions, feedback and suggestions are welcome
to the Telegram' group https://t.me/libmdbx.

Signed-off-by: Леонид Юрьев (Leonid Yuriev) <leo@yuriev.ru>
[Julien: remove _REDISTRIBUTE = YES to fix check-package error]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 11:55:41 +01:00
Giulio Benetti
4c98a3ddc3 package/libblockdev: bump to version 3.3.0
For change log, see:
https://github.com/storaged-project/libblockdev/blob/3.3.0/NEWS.rst

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 11:39:13 +01:00
Maxim Kochetkov
1040a4b714 package/protozero: bump version to 1.8.0
Release-notes: https://github.com/mapbox/protozero/releases/tag/v1.8.0
Drop upstream patch.
Updated license hash due to copyright year bump:
e91587f4bb

Bump minimal GCC version to 5. (Switched to C++14 as minimum requirement)

Signed-off-by: Maxim Kochetkov <fido_max@inbox.ru>
[Julien: remove patch entry in .checkpackageignore]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 11:24:19 +01:00
Yann E. MORIN
d9b8a2a5f1 package/zmqpp: unbreak indentation of option in menuconfig
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
Cc: Simon Dawson <spdawson@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-16 11:15:50 +01:00
Peter Korsgaard
59a8322ce8 package/angularjs: drop package
The package has not been updated since 2020, has known vulnerabilities and
the upstream Github project has been archived as of April 12, 2024 - So drop
the package.

For reference, AngularJS website [1] reads, at the time of
this commit:
"""
AngularJS support has officially ended as of January 2022.
See what ending support means [2] and read the end of life
announcement [3].
"""

[1] https://angularjs.org/
[2] https://docs.angularjs.org/misc/version-support-status
[3] https://goo.gle/angularjs-end-of-life

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
[Julien: add end-of-life announce and links in commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-15 22:17:51 +01:00
Peter Korsgaard
e9c0222bf4 package/angular-websocket: drop package
The package has not been updated since it was added in 2016 and the upstream
Github project has been archived as of Feb 17, 2024 - So drop the package.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-15 22:13:51 +01:00
Peter Korsgaard
b5ff38782c package/imagemagick: bump to version 7.1.1-43
For various bugfixes.  Notice that 7.1.1-36 fixed a security vulnerability
(CVE-2024-41817), but that issue is specific to the AppImage version:

https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8rxc-922v-phg8

Release notes:
https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.1-43

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-15 22:00:24 +01:00
Peter Korsgaard
befcc152f9 package/musl: add upstream security fixes for CVE-2025-26519
Fixes CVE-2025-26519: Musl libc: input-controlled out-of-bounds write
primitive in iconv()

https://www.openwall.com/lists/musl/2025/02/13/1

Fixes:
https://nvd.nist.gov/vuln/detail/CVE-2025-26519

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
[Julien: add link to cve]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-15 21:56:55 +01:00
Peter Korsgaard
30da391756 package/assimp: security bump to version 5.4.3
Fixes the following security vulnerability:

CVE-2024-40724: Heap-based buffer overflow vulnerability in Assimp versions
prior to 5.4.2 allows a local attacker to execute arbitrary code by
inputting a specially crafted file into the product.

https://github.com/assimp/assimp/pull/5651

Fixes:
https://nvd.nist.gov/vuln/detail/cve-2024-40724

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
[Julien: add link to cve]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-15 21:38:28 +01:00
Peter Korsgaard
35d2880e33 package/mpg123: security bump to version 1.32.8
Fixes the following security vulnerability:

CVE-2024-10573: An out-of-bounds write flaw was found in mpg123 when
handling crafted streams.  When decoding PCM, the libmpg123 may write past
the end of a heap-located buffer.  Consequently, heap corruption may happen,
and arbitrary code execution is not discarded.  The complexity required to
exploit this flaw is considered high as the payload must be validated by the
MPEG decoder and the PCM synth before execution.  Additionally, to
successfully execute the attack, the user must scan through the stream,
making web live stream content (such as web radios) a very unlikely attack
vector.

https://www.openwall.com/lists/oss-security/2024/10/30/2

Release notes:
https://sourceforge.net/p/mpg123/mailman/message/58834094/

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-15 21:26:39 +01:00
Peter Korsgaard
3f98b643fb package/unbound: security bump to version 1.21.1
Fixes the following security vulnerability:

CVE-2024-8508: A vulnerability has been discovered in Unbound when handling
replies with very large RRsets that Unbound needs to perform name
compression for.

https://nlnetlabs.nl/downloads/unbound/CVE-2024-8508.txt

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
[Julien: update pgp key id in hash file]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-15 20:53:10 +01:00
Peter Korsgaard
2867f4be42 package/libtasn1: security bump to version 4.20.0
Fixes the following security vulnerability:

CVE-2024-12133: Potential DoS in handling of numerous SEQUENCE OF or SET

https://lists.gnu.org/archive/html/help-libtasn1/2025-02/msg00001.html

Adjust the license files after upstream moved the license clarification to
README.md and moved the COPYING* files top the top level directory /
slightly updated the COPYING* files (http->https) with:

73cc886c3f

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-15 20:43:15 +01:00
Adrian Perez de Castro
3dc8a793b6 package/wlroots: bump to version 0.18.2
This is a minor bugfix release. Changelog:

  https://gitlab.freedesktop.org/wlroots/wlroots/-/releases/0.18.2

Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-02-15 14:20:57 +01:00
Julien Olivain
45c13bf249 package/fakeroot: add patch to fix parallel build
When building host-fakeroot on host with large number of CPUs,
compilation can randomly fail. Failures are observed on hosts
with 24 CPUs or more.

Build logs show errors such as:

    make -j$(nproc)
    ...
    awk -f ./wrapawk < ./wrapfunc.inp
    awk -f ./wrapawk < ./wrapfunc.inp
    ...
    In file included from libfakeroot.c:265:
    wraptmpf.h:607: error: unterminated #ifdef
      607 | #ifdef __APPLE__
          |
    wraptmpf.h:601: error: unterminated #ifdef
      601 | #ifdef HAVE_FTS_CHILDREN
          |
    wraptmpf.h:2: error: unterminated #ifndef
        2 | #ifndef WRAPTMPF_H
          |
    ...

This commit fixes the issue by adding a package patch.

Fixes:
- https://gitlab.com/buildroot.org/buildroot/-/jobs/9085451831
- https://gitlab.com/buildroot.org/buildroot/-/jobs/9085451244
- https://gitlab.com/buildroot.org/buildroot/-/jobs/9085451198
- and many more...

Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-02-15 09:34:52 +01:00
Bernd Kuhls
32dd92d18e package/php: bump version to 8.3.17
Changelog: https://www.php.net/ChangeLog-8.php#PHP_8_3
Release notes: https://news-web.php.net/php.announce/452

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-02-15 09:32:18 +01:00
Bernd Kuhls
9189b8afb8 package/postgresql: security bump version to 17.3
Release notes:
https://www.postgresql.org/docs/release/17.3/
https://www.postgresql.org/about/news/postgresql-173-167-1511-1416-and-1319-released-3015/

Fixes CVE-2025-1094:
https://www.postgresql.org/support/security/CVE-2025-1094/

Updated license hash due to copyright year bump:
https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=759620716adb347c1d8c8b2e6f7d88b947a54c98

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Reviewed-by: Maxim Kochetkov <fido_max@inbox.ru>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-02-15 09:31:48 +01:00
Bernd Kuhls
f6770cc13e package/libcurl: bump version to 8.12.1
Changelog: https://curl.se/ch/8.12.1.html

Removed patch which is included in this release.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-02-15 09:31:17 +01:00