Fabrice Fontaine
a5f721dca6
package/mpfr: fix CPE variables
...
cpe:2.3:a:gnu:mpfr added by commit
63332c33aa has never been a valid CPE
identifier for this package
cpe:2.3:a:mpfr:gnu_mpfr is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/detail/7B981E0A-5BAC-4A80-A734-5FD4B51B04EF
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 186883f497 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 22:13:11 +01:00
Fabrice Fontaine
29095831f2
package/depot-tools: drop DEPOT_TOOLS_CPE_ID_VENDOR
...
cpe:2.3:a:google:depot-tools added by commit
48730a1a9d has never been a valid CPE ID
for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe:2.3:a:google:depot-tools
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 27fafa94a7 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 22:12:40 +01:00
Fabrice Fontaine
89aed0df34
package/crda: drop CRDA_CPE_ID_VENDOR
...
cpe:2.3:a:kernel:crda added by commit
63332c33aa has never been a valid CPE ID
for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe:2.3:a:kernel:crda
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 85d300f102 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 22:12:03 +01:00
Bernd Kuhls
8518173cd4
{linux, linux-headers}: bump 6.{1, 6}.x series
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 52a15667b1 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 22:10:20 +01:00
Fabrice Fontaine
d4e11c319d
package/freerdp: security bump to version 2.11.5
...
- Fix CVE-2024-22211
- Update Upstream tag in patches
https://github.com/FreeRDP/FreeRDP/blob/2.11.5/ChangeLog
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit dbe037dc99 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 22:09:04 +01:00
Fabrice Fontaine
563aed5287
package/cpio: fix tar.bz2 hash
...
Commit b0306d94b2 forgot to update
cpio-2.13.tar.bz2 to cpio-2.14.tar.bz2
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 0694cef47b )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 22:07:02 +01:00
Peter Korsgaard
decf0cd91b
package/{glibc, localedef}: security bump to version glibc-2.38-44-gd37c2b20a4787463d192b32041c3406c2bd91de0
...
Fixes the following security issues:
CVE-2023-6246: syslog: Fix heap buffer overflow in __vsyslog_internal
https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2024-0001;hb=HEAD
CVE-2023-6779: syslog: Heap buffer overflow in __vsyslog_internal
https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2024-0002;hb=HEAD
CVE-2023-6780: syslog: Integer overflow in __vsyslog_internal
https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2024-0003;hb=HEAD
For details, see the Qualys advisory:
https://www.openwall.com/lists/oss-security/2024/01/30/6
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 75e7c7ba8c )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 22:03:09 +01:00
Peter Korsgaard
efa40febd9
package/glibc: add CVE ignore for CVE-2023-4806
...
Commit 8519de517e (package/{glibc, localedef}: security bump to version
glibc-2.38-27-g750a45a783906a19591fb8ff6b7841470f1f5701) correctly mentioned
CVE-2023-4806 in the commit message, but forgot to add an ignore for it.
Fix that.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 62b767fd3e )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 22:02:40 +01:00
Peter Korsgaard
1c93f28c12
package/syslog-ng: needs pcre2, not pcre
...
Syslog-ng-uses pcre2 instead of pcre since 4.3.0 with:
cb6de08dc9
No autobuilder failures, as pcre2 is implicitly available through libglib2.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit d932f84d9f )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 22:01:53 +01:00
Sébastien Szymanski
47960afe4f
docs/manual/contribute.txt: fix typo
...
"who sponsored who sponsored" -> "who sponsored"
Signed-off-by: Sébastien Szymanski <sebastien.szymanski@armadeus.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit f24e85238f )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 22:01:09 +01:00
Fabrice Fontaine
111c2eeef1
package/lynx: fix openssl static build
...
Use LDFLAGS instead of LIBS to fix the following openssl static build
failure raised because lynx filters out duplicates (i.e. -lz) in
CF_ADD_LIBS:
configure:12958: checking for inet_ntoa
configure:12995: /home/autobuild/autobuild/instance-7/output-1/host/bin/x86_64-buildroot-linux-uclibc-gcc -o conftest -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -Ofast -g0 -static -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -D_GNU_SOURCE -DLINUX -static conftest.c -L/home/autobuild/autobuild/instance-7/output-1/host/bin/../x86_64-buildroot-linux-uclibc/sysroot/usr/lib64 -lssl -L/home/autobuild/autobuild/instance-7/output-1/host/bin/../x86_64-buildroot-linux-uclibc/sysroot/usr/lib64 -lz -pthread -lcrypto -lz -pthread >&5
configure:12998: $? = 0
configure:13001: test -s conftest
configure:13004: $? = 0
configure:13014: result: yes
configure:13095: checking for gethostbyname
configure:13151: result: yes
configure:13232: checking for strcasecmp
configure:13288: result: yes
configure:13401: checking for inet_aton function
configure:13443: /home/autobuild/autobuild/instance-7/output-1/host/bin/x86_64-buildroot-linux-uclibc-gcc -o conftest -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -Ofast -g0 -static -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -D_GNU_SOURCE -DLINUX -static conftest.c -L/home/autobuild/autobuild/instance-7/output-1/host/bin/../x86_64-buildroot-linux-uclibc/sysroot/usr/lib64 -lssl -lz -pthread -lcrypto >&5
[...]
/home/autobuild/autobuild/instance-7/output-1/host/bin/x86_64-buildroot-linux-uclibc-gcc -DHAVE_CONFIG_H -DLOCALEDIR=\"/usr/share/locale\" -I. -I.. -Ichrtrans -I./chrtrans -I.. -I../src -I.././WWW/Library/Implementation -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -D_GNU_SOURCE -DLINUX -I/home/autobuild/autobuild/instance-7/output-1/host/x86_64-buildroot-linux-uclibc/sysroot/usr/include -I/home/autobuild/autobuild/instance-7/output-1/host/x86_64-buildroot-linux-uclibc/sysroot/usr/include/openssl -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -Ofast -g0 -static -Wl,-rpath,/home/autobuild/autobuild/instance-7/output-1/host/bin/../x86_64-buildroot-linux-uclibc/sysroot/usr/lib64 -Wl,-rpath,/home/autobuild/autobuild/instance-7/output-1/host/x86_64-buildroot-linux-uclibc/sysroot/usr/lib -L/home/autobuild/autobuild/instance-7/output-1/host/x86_64-buildroot-linux-uclibc/sysroot/usr/lib -static -o lynx LYebcdic.o LYClean.o LYShowInfo.o LYEdit.o L
YStrings.o LYMail.o HTAlert.o GridText.o LYGetFile.o LYMain.o LYMainLoop.o LYCurses.o LYBookmark.o LYmktime.o LYUtils.o LYOptions.o LYReadCFG.o LYSearch.o LYHistory.o LYForms.o LYPrint.o LYrcFile.o LYDownload.o LYNews.o LYKeymap.o HTML.o HTFWriter.o HTInit.o DefaultStyle.o LYUpload.o LYLeaks.o LYexit.o LYJump.o LYList.o LYCgi.o LYTraversal.o LYEditmap.o LYCharSets.o LYCharUtils.o LYMap.o LYCookie.o LYStyle.o LYHash.o LYPrettySrc.o TRSTable.o parsdate.o UCdomap.o UCAux.o UCAuto.o LYSession.o LYLocal.o .././WWW/Library/Implementation/libwww.a -lz -static -lncurses -lssl -lcrypto -L/home/autobuild/autobuild/instance-7/output-1/host/bin/../x86_64-buildroot-linux-uclibc/sysroot/usr/lib64 -pthread
/home/autobuild/autobuild/instance-7/output-1/host/lib/gcc/x86_64-buildroot-linux-uclibc/11.4.0/../../../../x86_64-buildroot-linux-uclibc/bin/ld: /home/autobuild/autobuild/instance-7/output-1/host/x86_64-buildroot-linux-uclibc/sysroot/usr/lib/libcrypto.a(libcrypto-lib-c_zlib.o): in function `zlib_oneshot_expand_block':
c_zlib.c:(.text+0xb8b): undefined reference to `uncompress'
Patching aclocal.m4 is not possible as autoreconf fails due to missing
AC_DIVERT_HELP macro.
This build failure is only raised by autobuilders since 2024 for an
unknown reason.
Fixes:
- http://autobuild.buildroot.org/results/6d4119b54fc6b6111a03f81e131e83bae0d844d1
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit ef5d3327a1 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 22:00:08 +01:00
Bernd Kuhls
f24d68dde0
{linux, linux-headers}: bump 4.19.x / 5.{4, 10, 15}.x / 6.{1, 6}.x series
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 44292dabc0 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 21:59:19 +01:00
Fabrice Fontaine
8ab2a93204
package/joe: add JOE_CPE_ID_VENDOR
...
cpe:2.3:a:joseph_allen:joe is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/detail/5F530947-2060-4842-92B9-5BC61D9C5430
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 2953cd2644 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 21:53:34 +01:00
David Barbion
dcc89720bf
package/dhcpcd: bump to version 10.0.5
...
This version contains a fix for aarch64 based systems.
On such systems, dhcpcd would crash without setting any IP addresses.
See 6a36f96740
and https://github.com/NetworkConfiguration/dhcpcd/issues/260 for more
details.
Signed-off-by: David Barbion <davidb@230ruedubac.fr >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 1dfa4c56fe )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 21:52:49 +01:00
Bernd Kuhls
096eec5b39
package/tor: Fix build with libressl >= 3.8.1
...
Fixes:
http://autobuild.buildroot.net/results/85c/85cde3bcd12fb5adafb94c85d5fa636e1b5b9068/
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
[yann.morin.1998@free.fr: fix Upstream tag]
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
(cherry picked from commit 2fbeacf91f )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 18:34:48 +01:00
Fabrice Fontaine
edfc743642
package/frr: security bump to version 8.5.4
...
Fix CVE-2023-38802, CVE-2023-41360, CVE-2023-46752, CVE-2023-46753,
CVE-2023-47234 and CVE-2023-47235
https://frrouting.org/security/
https://frrouting.org/release/8.5.4/
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit c3cf06e0a8 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 18:34:21 +01:00
Fabrice Fontaine
e149a7a994
package/x11r7/xserver_xorg-server: add CPE variables
...
cpe:2.3:a:x.org:xorg-server is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/detail/79A86C02-31A5-4F25-8CA6-7C4A8CD92B7B
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit b80705800a )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 18:29:32 +01:00
Peter Korsgaard
377fac9f57
package/gstreamer1-editing-services: bump to version 1.22.9
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit c55c1263ab )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 18:28:23 +01:00
Peter Korsgaard
ced0540e61
package/gst-omx: bump to version 1.22.9
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 9f342e4a67 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 18:28:23 +01:00
Peter Korsgaard
1dbda0dc13
package/gst1-vaapi: bump to version 1.22.9
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 6f28c463cf )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 18:28:22 +01:00
Peter Korsgaard
e7015c3cf7
package/gst1-rtsp-server: bump to version 1.22.9
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 88a6cfefbf )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 18:28:21 +01:00
Peter Korsgaard
62909338f1
package/gst1-python: bump to version 1.22.9
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit d948714037 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 18:28:21 +01:00
Peter Korsgaard
6cf19efa53
package/gst1-libav: bump to version 1.22.9
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit db9b4f3b0c )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 18:28:20 +01:00
Peter Korsgaard
5c40af09b5
package/gst1-devtools: bump to version 1.22.9
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 74c32bfa5d )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 18:28:19 +01:00
Peter Korsgaard
9568634933
package/gst1-plugins-ugly: bump to version 1.22.9
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit ca65df3da2 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 18:28:18 +01:00
Peter Korsgaard
a47236d33e
package/gst1-plugins-bad: security bump to version 1.22.9
...
Fixes the following security issue:
CVE-2024-0444: Heap-based buffer overflow in the AV1 codec parser when
handling certain malformed streams before GStreamer 1.22.9
https://gstreamer.freedesktop.org/security/sa-2024-0001.html
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 3ee1148b00 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 18:28:18 +01:00
Peter Korsgaard
11a1d35fec
package/gst1-plugins-good: bump to version 1.22.9
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 3407703f2c )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 18:28:17 +01:00
Peter Korsgaard
c20e83d0a8
package/gst1-plugins-base: bump to version 1.22.9
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 6b7db1bf64 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 18:28:16 +01:00
Peter Korsgaard
e79b73744c
package/gstreamer1: bump to version 1.22.9
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit e81d29d551 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 18:28:15 +01:00
Peter Korsgaard
e6a1759858
package/darkhttpd: security bump to version 1.15
...
Fixes the following security issues:
CVE-2024-23770: Local Leak of Authentication Parameter in Process List
CVE-2024-23771: Basic Auth Timing Attack
https://security.opensuse.org/2024/01/22/darkhttpd-basic-auth-issues.html
Notice that CVE-2024-23770 is only documented as a known weakness, not
fixed.
Also change the license logic to use the dedicated COPYING file available
since 1.14:
a8ae2b1de0
This license is ISC, not MIT - So adjust DARKHTTPD_LICENSE to match.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 0c7fd35947 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 17:42:37 +01:00
Fabrice Fontaine
72a06fb11d
package/mbedtls: security bump to version 2.28.7
...
- Fix CVE-2024-23170 and CVE-2024-23775
- Mbed TLS is now released under a dual Apache-2.0 OR GPL-2.0-or-later
license. Users may choose which license they take the code under:
f429557c59
https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-01-1/
https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-01-2/
https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.6
https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.7
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 52fd4753fe )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 17:42:03 +01:00
Peter Korsgaard
087993b9ae
package/environment-setup: do not export GIT_DIR
...
Commit c07aafa087 (package/Makefile.in: set GIT_DIR=. in {HOST,
TARGET}_MAKE_ENV) added GIT_DIR=. to TARGET_MAKE_ENV (which is included in
TARGET_CONFIGURE_OPTS) to work around issues with packages getting confused
when building in a subdir of the Buildroot git repo.
This unfortunately also causes git commands to fail when
output/host/environment-setup is sourced:
git status
fatal: not a git repository: '.'
So strip GIT_DIR= from TARGET_CONFIGURE_OPTS when generating
environment-setup.
Reported-by: Mircea Gliga <gliga.mircea@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 48874afb9d )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 17:41:14 +01:00
Fabrice Fontaine
90c05d1abf
package/weston: fix build without gbm
...
Fix the following build failure without gbm raised since commit
534c22dd60 :
Message: dmabuf-feedback requires gbm which was not found. If you rather not build this, drop "dmabuf-feedback" from simple-clients option.
Move the option assignment further down, below all the simple-clients
lists; in Makefile, and because we are usign simply expanded variables,
this is not necessary, but it is easier on us humans when we review the
code.
Also add a comment explaining why the initial list is incomplete.
Fixes:
- http://autobuild.buildroot.org/results/ebbba1d73ceeaacee17fde0c6c853415cd316091
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 611c0cb198 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 17:39:37 +01:00
Yann E. MORIN
39ae2f26f3
boot/syslinux: carry fix for build failures with binutils 2.31+
...
From a report on the syslinux mailing list [0]:
The GNU linker now writes two segments of type PT_LOAD into the
program header. However, this is not supported by the wrapper
script that converts the shared object to an .efi executable.
As per comment in that file:
(...) Although there may be several LOAD program headers,
only one is currently copied.
A simple workaround I've found to work is to ask the linker to put
everything into one PT_LOAD program header.
The issue is ackowledged in the syslinux wiki page about building
syslinux [1]. This page refers to various resources, of which a Debian
patch [2].
This information is also referenced in #11861 .
Fixes : #11861
[0] https://www.syslinux.org/archives/2018-August/026167.html
[1] https://wiki.syslinux.org/wiki/index.php?title=Building
[2] https://salsa.debian.org/images-team/syslinux/-/blob/debian/master/debian/patches/0017-single-load-segment.patch
Reported-by: Sam Lancia <sam@gpsm.co.uk >
Reported-by: Meliodas <meliodasren01@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit e53a8593b4 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 17:37:18 +01:00
Yann E. MORIN
1e7fb7c7a6
package/hiredis: do not install nuget packaging file
...
The NuGet packaging description file is installed as:
$(DEST_DIR)/build/native/hiredis.targets
This is a sprurious file that has nothing to do on a Linux system,
whether that be in host/, staging/, or target/.
Backport an upstream patch to get rid of it.
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
Cc: Fabrice Fontaine <fontaine.fabrice@gmail.com >
(cherry picked from commit 52f3793d46 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 17:25:13 +01:00
Thomas Devoogdt
bd202dde79
package/webkitgtk: bump to version 2.42.2
...
Update to a new major release.
Release notes:
https://webkitgtk.org/2023/09/15/webkitgtk2.42.0-released.html
https://webkitgtk.org/2023/09/27/webkitgtk2.42.1-released.html
https://webkitgtk.org/2023/11/10/webkitgtk2.42.2-released.html
Security notes:
https://webkitgtk.org/security/WSA-2023-0008.html
- USE_JPEGXL is enabled by default now [1], so add a libjxl if used.
- ENABLE_GLES2 has been dropped, so drop it also here [2].
Instead, enable USE_OPENGL_OR_ES if libgles is present. Beware that also
libegl is needed for USE_OPENGL_OR_ES, but that one is most of the time a
dependency for libgles, so leave it out here.
- Also raise the minimal GCC version to 10.2, which is required since webkitgtk-2.42.x [3].
Similar to commit ec1ff802df ,
we do check on >= GCC 10, because we can't check on >= GCC 10.2.
[1] 93865414f3
[2] cfe917fec4
[3] 133498aaee
Signed-off-by: Thomas Devoogdt <thomas.devoogdt@barco.com >
Tested-by: Adrian Perez de Castro <aperez@igalia.com >
Acked-by: Adrian Perez de Castro <aperez@igalia.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit c4abff80b0 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 17:19:57 +01:00
Thomas Devoogdt
1e83664d4d
package/webkitgtk: make gbm support optional
...
This was added upstream in commit:
22e4c03866
The 'USE_OPENGL_OR_ES' flag is default ON, which will enable 'USE_GBM',
so ensure that we unset 'USE_GBM' if we don't have libgbm.
Signed-off-by: Thomas Devoogdt <thomas.devoogdt@barco.com >
Tested-by: Adrian Perez de Castro <aperez@igalia.com >
Acked-by: Adrian Perez de Castro <aperez@igalia.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit c06c0197f9 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 17:16:04 +01:00
Thomas Devoogdt
4848edca0d
package/webkitgtk: select wpebackend-fdo if wayland target is enabled
...
libwep & wpebackend-fdo are mandatory if ENABLE_WAYLAND_TARGET and EGL_FOUND
2e35890b1f/Source/cmake/OptionsGTK.cmake (L388-L400)
egl is mandatory if ENABLE_WAYLAND_TARGET
2e35890b1f/Source/cmake/OptionsGTK.cmake (L462-L473)
So wpebackend-fdo (-> libwpe) has to be selected if BR2_PACKAGE_LIBGTK3_WAYLAND.
Signed-off-by: Thomas Devoogdt <thomas.devoogdt@barco.com >
Tested-By: Adrian Perez de Castro <aperez@igalia.com >
Acked-by: Adrian Perez de Castro <aperez@igalia.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit b9c0e48f68 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 17:15:48 +01:00
Adrian Perez de Castro
b9b7b9cf6f
package/wpewebkit: security bump to version 2.42.4
...
The minimum GCC version is changed to 10.x, conditionals added for
USE_JPEGXL and USE_GBM. Both are optional and will be automatically
enabled if the relevent packages have been enabled. GBM is recommended
for performance, is it avoids a buffer copy on each frame rendered by
WebKit.
Release notes:
- https://wpewebkit.org/release/wpewebkit-2.40.4.html
- https://wpewebkit.org/release/wpewebkit-2.40.5.html
- https://wpewebkit.org/release/wpewebkit-2.42.0.html
- https://wpewebkit.org/release/wpewebkit-2.42.1.html
- https://wpewebkit.org/release/wpewebkit-2.42.2.html
- https://wpewebkit.org/release/wpewebkit-2.42.3.html
- https://wpewebkit.org/release/wpewebkit-2.42.4.html
This update covers fixes for CVE-2023-37450, CVE-2023-38133,
CVE-2023-38572, CVE-2023-38592, CVE-2023-38594, CVE-2023-38595,
CVE-2023-38597, CVE-2023-38599, CVE-2023-38600, CVE-2023-38611,
CVE-2023-40397, CVE-2023-39928, CVE-2023-39434, CVE-2023-40451,
CVE-2023-41074, CVE-2023-41993, CVE-2023-32359, CVE-2023-41983,
CVE-2023-42852, CVE-2023-42916, CVE-2023-42917, CVE-2023-42883,
and CVE-2023-42890.
Relevant security advisories:
- https://wpewebkit.org/security/WSA-2023-0006.html
- https://wpewebkit.org/security/WSA-2023-0007.html
- https://wpewebkit.org/security/WSA-2023-0008.html
- https://wpewebkit.org/security/WSA-2023-0009.html
- https://wpewebkit.org/security/WSA-2023-0010.html
- https://wpewebkit.org/security/WSA-2023-0011.html
- https://wpewebkit.org/security/WSA-2023-0012.html
Signed-off-by: Adrian Perez de Castro <aperez@igalia.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 7a8c112df7 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 14:43:22 +01:00
Fabrice Fontaine
817f16ca02
package/falcosecurity-libs: drop FALCOSECURITY_LIBS_CPE_ID_VENDOR
...
FALCOSECURITY_LIBS_CPE_ID_VENDOR is plain wrong since the addition of
the package in commit a15e35c4eb , indeed
falco:falcosecurity-libs is not a valid CPE ID:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe:2.3:a:falco:falcosecurity-libs
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 9b36995c2c )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 14:41:35 +01:00
Fabrice Fontaine
a07d1795ff
package/faad2: force arm mode instead of Thumb mode
...
Fix the following build failure in Thumb mode:
/tmp/ccfzn6FH.s:36: Error: selected processor does not support `smull r2,r3,r1,r0' in Thumb mode
Fixes:
- http://autobuild.buildroot.org/results/838808b4751244ee01cde6b8261212b49e511a32
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
[Peter: reword comment slightly]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit a338277608 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 14:38:54 +01:00
Adrian Perez de Castro
9a46e9e171
package/cog: bump to version 0.18.2
...
This is a small bugfix release, with a fix for a crash in the DRM/KMS
module that affects i.MX6 boards and probably others. Release notes:
https://wpewebkit.org/release/cog-0.18.2.html
Signed-off-by: Adrian Perez de Castro <aperez@igalia.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit afe633d6be )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 14:37:19 +01:00
Peter Korsgaard
8667430da2
package/xserver_xorg-server: security bump to version 21.1.11
...
Fixes the following security issues:
1) CVE-2023-6816 can be triggered by passing an invalid array index to
DeviceFocusEvent or ProcXIQueryPointer.
2) CVE-2024-0229 can be triggered if a device has both a button and a
key class and zero buttons.
3) CVE-2024-21885 can be triggered if a device with a given ID was
removed and a new device with the same ID added both in the same
operation.
4) CVE-2024-21886 can be triggered by disabling a master device with
disabled slave devices.
5) CVE-2024-0409 can be triggered by enabling SELinux
xserver_object_manager and running a client.
6) CVE-2024-0408 can be triggered by enabling SELinux
xserver_object_manager and creating a GLX PBuffer.
For details, see the advisory:
https://lists.x.org/archives/xorg-announce/2024-January/003444.html
Switch to .tar.gz as the announcement mail only contained hashes for that:
https://lists.x.org/archives/xorg-announce/2024-January/003442.html
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 219178ef3e )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 14:35:17 +01:00
Peter Korsgaard
f2bc7c3e8a
package/xwayland: security bump to version 23.2.4
...
Fixes the following security issues:
1) CVE-2023-6816 can be triggered by passing an invalid array index to
DeviceFocusEvent or ProcXIQueryPointer.
2) CVE-2024-0229 can be triggered if a device has both a button and a
key class and zero buttons.
3) CVE-2024-21885 can be triggered if a device with a given ID was
removed and a new device with the same ID added both in the same
operation.
4) CVE-2024-21886 can be triggered by disabling a master device with
disabled slave devices.
5) CVE-2024-0409 can be triggered by enabling SELinux
xserver_object_manager and running a client.
6) CVE-2024-0408 can be triggered by enabling SELinux
xserver_object_manager and creating a GLX PBuffer.
For details, see the advisory:
https://lists.x.org/archives/xorg-announce/2024-January/003444.html
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit b8d9e75eb8 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 14:34:38 +01:00
Peter Korsgaard
0bb42e170d
package/refpolicy: move patch to version subdir for custom git support
...
Commit e88823d667 (package/refpolicy: fix build with smartmontools) added
a 0001-policy-modules-services-smartmon.te-make-fstools-opt.patch patch, but
forgot to put it in the version specific sub directory - Breaking builds
using BR2_PACKAGE_REFPOLICY_CUSTOM_GIT as shown by the TestSELinuxCustomGit
test:
>>> refpolicy RELEASE_2_20200818 Extracting
gzip -d -c /builds/buildroot.org/buildroot/test-dl/refpolicy/refpolicy-RELEASE_2_20200818-br1.tar.gz | tar --strip-components=1 -C /builds/buildroot.org/buildroot/test-output/TestSELinuxCustomGit/build/refpolicy-RELEASE_2_20200818 -xf -
>>> refpolicy RELEASE_2_20200818 Patching
Applying 0001-policy-modules-services-smartmon.te-make-fstools-opt.patch using patch:
patching file policy/modules/services/smartmon.te
Hunk #1 FAILED at 143.
1 out of 1 hunk FAILED -- saving rejects to file policy/modules/services/smartmon.te.rej
make[1]: *** [package/pkg-generic.mk:241: /builds/buildroot.org/buildroot/test-output/TestSELinuxCustomGit/build/refpolicy-RELEASE_2_20200818/.stamp_patched] Error 1
https://gitlab.com/buildroot.org/buildroot/-/jobs/5929796183
Fix it by moving the patch to a versioned sub directory.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit bde468127c )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 12:47:20 +01:00
Bernd Kuhls
b448305ae6
package/php: bump version to 8.2.15
...
Changelog: https://www.php.net/ChangeLog-8.php#8.2.15
Release notes: https://www.php.net/releases/8_2_15.php
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit ed7335d256 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 12:46:14 +01:00
Bernd Kuhls
963d79affe
{linux, linux-headers}: bump 4.19.x / 5.{4, 10, 15}.x / 6.{1, 6}.x series
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 02692b723a )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 12:43:39 +01:00
Fabrice Fontaine
f0d9bc0fd0
package/xterm: bump to version 389
...
- Update hash of COPYING (update in year)
- This bump will fix the following musl build failure raised since bump
to version 384 in commit 164d635f37 :
./main.c:802:34: error: 'TAB3' undeclared here (not in a function); did you mean 'TAB0'?
802 | { -1, XTTYMODE__tabs, TAB3 },
| ^~~~
| TAB0
https://invisible-island.net/xterm/xterm.log.html#xterm_389
Fixes:
- http://autobuild.buildroot.org/results/51f98577b851bdbb0a0ab93c9ef94977776c1b1b
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 6a49c39492 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-28 12:39:54 +01:00
Francois Perrad
278aa1eb42
package/gnutls: security bump to 3.8.3
...
see CVE-2024-0553: Fix more timing side-channel inside RSA-PSK key exchange
see CVE-2024-0567: Fix assertion failure when verifying a certificate chain with a cycle of cross signatures
Signed-off-by: Francois Perrad <francois.perrad@gadz.org >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit b136bed2fd )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-04 22:41:52 +01:00
Adam Duskett
84d9bf5b18
package/flutter-pi: Fix help text for gstreamer audio player
...
The help text is currently copy and pasted from the gstreamer video
player plugin help text. Change it to reflect the text from the
CMakeLists.txt file.
Signed-off-by: Adam Duskett <adam.duskett@amarulasolutions.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 7437cad018 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2024-02-04 22:32:00 +01:00