Fixes the following security vulnerability:
CVE-2024-10573: An out-of-bounds write flaw was found in mpg123 when
handling crafted streams. When decoding PCM, the libmpg123 may write past
the end of a heap-located buffer. Consequently, heap corruption may happen,
and arbitrary code execution is not discarded. The complexity required to
exploit this flaw is considered high as the payload must be validated by the
MPEG decoder and the PCM synth before execution. Additionally, to
successfully execute the attack, the user must scan through the stream,
making web live stream content (such as web radios) a very unlikely attack
vector.
https://www.openwall.com/lists/oss-security/2024/10/30/2
Release notes:
https://sourceforge.net/p/mpg123/mailman/message/58834094/
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
Fixes the following security vulnerability:
CVE-2024-8508: A vulnerability has been discovered in Unbound when handling
replies with very large RRsets that Unbound needs to perform name
compression for.
https://nlnetlabs.nl/downloads/unbound/CVE-2024-8508.txt
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
[Julien: update pgp key id in hash file]
Signed-off-by: Julien Olivain <ju.o@free.fr>
Fixes the following security vulnerability:
CVE-2024-12133: Potential DoS in handling of numerous SEQUENCE OF or SET
https://lists.gnu.org/archive/html/help-libtasn1/2025-02/msg00001.html
Adjust the license files after upstream moved the license clarification to
README.md and moved the COPYING* files top the top level directory /
slightly updated the COPYING* files (http->https) with:
73cc886c3f
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
When building host-fakeroot on host with large number of CPUs,
compilation can randomly fail. Failures are observed on hosts
with 24 CPUs or more.
Build logs show errors such as:
make -j$(nproc)
...
awk -f ./wrapawk < ./wrapfunc.inp
awk -f ./wrapawk < ./wrapfunc.inp
...
In file included from libfakeroot.c:265:
wraptmpf.h:607: error: unterminated #ifdef
607 | #ifdef __APPLE__
|
wraptmpf.h:601: error: unterminated #ifdef
601 | #ifdef HAVE_FTS_CHILDREN
|
wraptmpf.h:2: error: unterminated #ifndef
2 | #ifndef WRAPTMPF_H
|
...
This commit fixes the issue by adding a package patch.
Fixes:
- https://gitlab.com/buildroot.org/buildroot/-/jobs/9085451831
- https://gitlab.com/buildroot.org/buildroot/-/jobs/9085451244
- https://gitlab.com/buildroot.org/buildroot/-/jobs/9085451198
- and many more...
Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
As of release 3.49.0, the author has replaced the configure script used in
the precompiled amalgamation tarball with Autosetup instead of Autotools.
Buildroot commit [1] bumped sqlite to 3.49.0 without changing the
package infra. This introduced build issues.
The "autotools-package" and "host-autotools-package" lines are no longer
available, so those have to be replaced by the "generic-package" and
"host-generic-package" lines in the .mk file.
The Autosetup configuration script does not support the
"enable-dynamic-extensions" and "disable-static-shell" options,
so the relevant lines in the .mk file are removed.
The Autosetup configuration script can automatically detect whether
threads are supported and set the relevant SQLITE_THREADSAFE flag,
so the relevant lines in the .mk file are removed.
Fixes:
https://autobuild.buildroot.org/?reason=sqlite-3.49.0
[1] db85638cea
Signed-off-by: Scott Fan <fancp2007@gmail.com>
Tested-by: Fiona Klute (WIWA) <fiona.klute@gmx.de>
[Julien: add link to commit which introduced the build issue]
Signed-off-by: Julien Olivain <ju.o@free.fr>
Exporting the download variables can cause unfortunate name clashes, as
occurred with the SCP variable used by Binman for compiling U-Boot [1].
Do not globally export the package download commands anymore; instead,
pass them to the dl-wrapper environment.
The issue can be reproduced by building the rock5b_defconfig.
In that case, compilation fails with output:
usage: binman [-h] [-B BUILD_DIR] [-D] [-H] [--tooldir TOOLDIR]
[--toolpath TOOLPATH] [-T THREADS] [--test-section-timeout]
[-v VERBOSITY] [-V]
{build,bintool-docs,entry-docs,ls,extract,replace,sign,test,tool}
...
binman: error: unrecognized arguments: -o ConnectTimeout=10
This build failure is due to the naming clash on the "SCP" environment
variable. The "SCP" initially exported in package/pkg-download.mk
refers to the SSH Secure File Copy command. While the "SCP" variable
in U-Boot refers to the "System Control Processor firmware blob",
which is a binary file used by u-boot to build a boot image.
Even if the name clash has always been present, the build issues were
occuring since commit [2].
Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/9122556697
(and many others)
[1] https://lore.kernel.org/buildroot/a023971c7c8bfa4826a9a8721500c7ff@free.fr/T/
[2] 4bce3270d6
Cc: Julien Olivain <ju.o@free.fr>
Suggested-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
[Julien:
- reorder variables alphabetically
- add LOCALFILES variable
- add info in commit log (build failure log, example to reproduce,
details about the name clash)
]
Signed-off-by: Julien Olivain <ju.o@free.fr>
Following the addition of the firmware upload API in linux v6.6, using
debugfs for firmware updating has been removed. Update the
update-gateware script to use the firmware upload API with sysfs and
enable applying the overlays during boot.
The fw_upload interface can detect when there is an overlay file and
will write it correctly. Use this functionality to write the overlay
file and remove dd command related code.
Fixes: 8ce97fd550 ("configs/beaglev_fire: bump Linux and U-Boot")
Reviewed-by: Conor Dooley <conor.dooley@microchip.com>
Signed-off-by: Jamie Gibbons <jamie.gibbons@microchip.com>
Signed-off-by: Romain Naour <romain.naour@smile.fr>
buildx correctly complains about our ENV lines:
3 warnings found (use docker --debug to expand):
- LegacyKeyValueFormat: "ENV key=value" should be used instead of legacy "ENV key value" format (line 21)
- LegacyKeyValueFormat: "ENV key=value" should be used instead of legacy "ENV key value" format (line 94)
- LegacyKeyValueFormat: "ENV key=value" should be used instead of legacy "ENV key value" format (line 95)
The ENV syntax is defined as ENV FOO=BAR, not ENV FOO BAR, so adjust the
Dockerfile to match to get rid of this warning.
https://docs.docker.com/reference/dockerfile/#env
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
With the new 'buildx' command using 'BuildKit' since Docker 23.0 [1],
it become easy to build the same image for several architectures [2].
The only requirement is to use a Dockerfile without any architecture
specific definition.
Since our current Dockefile contains already some i386 specific
packages (g++-multilib,libc6:i386) to provide x86 32bits support,
we have to install them conditionally.
Update the build process described in the Dockerfile accordingly.
For now, Aarch64 hosts can't be used by the Buildroot testsuite (yet)
since the Bootlin external toolchain (used by default) currently only
support x86_64 hosts.
[1] https://docs.docker.com/engine/release-notes/23.0/
[2] https://www.docker.com/blog/multi-arch-build-and-images-the-simple-way/
[3] https://www.docker.com/blog/multi-arch-build-what-about-gitlab-ci/
Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
The mimic package hasn't been updated in recent years and
downloading this package is now broken.
This commit removes the mimic package.
Signed-off-by: Thomas Bonnefille <thomas.bonnefille@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
The commit b4006287f8 "package/go: security bump to version 1.23.6"
removed the go source from the go-bin package `.hash` file.
Since that commit, a number of autobuild errors for the host-go-bin
package started spawning during the 'legal-info' step.
Because the package 'go-bin' defines the '_ACTUAL_SOURCE_TARBALL'
variable the source hash is still required for the legal-info.
Similarly to the 'nodejs' package, the hash files for both the `go-bin`
and `go-src` package are shared in the `package/go` directory with the
help of a symbolic link used to make the subdirectories point to that
common `.hash` file.
Fixes:
https://autobuild.buildroot.org/results/337/33763441a065ddb07e944e26ad8f1f6d43b68592
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Romain Naour <romain.naour@smile.fr>
Since commit b11956fb66 ("support/dependencies: require tar >= 1.35"),
Buildroot will build host-tar if the host does not have >= 1.35 available,
so add it to the container to save build time.
Debian 12 only provides tar 1.34. Tar 1.35 is available in testing - But
that then depends on a newer glibc, so instead build it from source using
the --disable-year2038 flag like we do for host-tar and install it into
/usr/local/bin so it shadows the Debian one.
This step runs as root (and needs to for make install), so add
FORCE_UNSAFE_CONFIGURE=1 as otherwise the configure script errors out.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Commit afece24a72 ("support/download: introduce curl backend for FTP
transfers") added curl download support, so add it to the container as well.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
The error was introduced by the libcurl bump to 8.12.0 with buildroot
commit 2da031c2e5.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
Commit 52154e5206 (package/zstd: build multithreaded library if
supported) added an override of a previously defined variable, so an
explicit check-package exception was added in 0f0e913f10
(package/zstd: rework build and install). Eventually, in 253a951c4f
(package/zstd: fix build without threads) the variable override was
removed.
However, the check-package exception was left out during the rework in
253a951c4f, so it now excludes nothing.
Drop this exception now.
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
Cc: Andrey Smirnov <andrew.smirnov@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
As pointed out by shellcheck, the exit code of the start/stop/restart/reload
command is clobbered by the 'echo "FAIL'" statement:
In package/mdnsd/S50mdnsd line 52:
exit $?
^-- SC2320 (warning): This $? refers to echo/printf, not a previous command. Assign to variable to avoid it being overwritten.
So introduce a $status variable to keep track of it, similar to how it is
done in S40iwd.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
SC2086 is now reported for missing Double quote around
$FN since shellcheck 0.9.0:
In utils/config line 175:
if grep -q "# ${BR2_PREFIX}$ARG is not set" $FN ; then
^-^ SC2086 (info): Double quote to prevent globbing and word splitting.
In utils/config line 178:
if V="$(grep "^${BR2_PREFIX}$ARG=" $FN)"; then
^-^ SC2086 (info): Double quote to prevent globbing and word splitting.
Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
SC2086 is now reported for auto_id since shellcheck 0.9.0:
In support/scripts/mkusers line 453:
add_one_group "${g}" ${auto_id}
^--------^ SC2086 (info): Double quote to prevent globbing and word splitting.
So quote it to get rid of this error.
Signed-off-by: Romain Naour <romain.naour@smile.fr>
[Peter: quote variable instead of disabling check]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
As for SC1090 and SC2016 [1], disable SC1091 and SC2294 too since they
are now reported by shellcheck 0.9.0:
In support/download/curl line 42:
eval ${CURL} "${@}"
^--^ SC2294 (warning): eval negates the benefit of arrays. Drop eval to preserve whitespace/symbols (or eval as string).
[1] bcee3ca6d6
Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Shellcheck 0.9.0 now report SC2086:
In package/kodi/br-kodi line 38:
exit ${ret}
^----^ SC2086 (info): Double quote to prevent globbing and word splitting.
Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
As stated in shellcheck wiki about SC2329 [1]
"ShellCheck is currently bad at figuring out functions that are invoked via trap.
In such cases, please ignore the message with a directive."
While adding SC2329 check after shellcheck v0.10.0 release, it also
reduced the amount of false result returned by shellcheck v0.9.0.
So disable SC2317 and SC2329.
[1] https://www.shellcheck.net/wiki/SC2329
[2] 4f81dbe839
Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
flake8 5.0.4 provided by Debian 12 (bookworm) now detect a missing
whitespace after 'assert' keyword:
E275 missing whitespace after keyword
Signed-off-by: Romain Naour <romain.naour@smile.fr>
[Peter: fix subject, drop extra paranthesises]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
When check-package fail due to flake8 coding style checks, it suggest
to use flake8 command line:
run 'flake8' and fix the warnings
But flake8 is actually missing from the container used by
utils/docker-run, so add it to the container as well.
Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>