Commit Graph

79531 Commits

Author SHA1 Message Date
Neal Frager
c8ce4fc7cf board/xilinx: add xilinx_v2025.2 hashes
Add hashes for xilinx_v2025.2 release tags which include the following:
arm-trusted-firmware v2.12
linux v6.12.40
uboot v2025.01
with all Xilinx downstream commits included with xilinx_v2025.2.

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-11-26 10:38:13 +01:00
Neal Frager
4a23826f48 package/bootgen: bump to xilinx_v2025.2
Bump bootgen to xilinx_v2025.2 version.

The 0001-bisonflex-Fix-build-on-machines-with-modern-flex.patch is no longer
needed because it has been committed upstream and included with the
xilinx_v2025.2 version.

0471f084b0

The 0001-lms-hash-sigs-hss_param.c-add-stdio.h-include.patch has now been
added to the package to fix the following potential build error:

The lms-hash-sigs/hss_param.c is missing an include of stdio.h. Without it,
the following build error can occur:

hss_param.c: In function ‘hss_get_parameter_set’:
hss_param.c:157:13: error: implicit declaration of function ‘printf’ [-Wimplicit-function-declaration]
  157 |             printf("Private key expired\n");
      |             ^~~~~~
hss_param.c:7:1: note: include ‘<stdio.h>’ or provide a declaration of ‘printf’
    6 | #include "lm_common.h"
  +++ |+#include <stdio.h>
    7 |
hss_param.c:157:13: warning: incompatible implicit declaration of built-in function ‘printf’ [-Wbuiltin-declaration-mismatch]
  157 |             printf("Private key expired\n");
      |             ^~~~~~
hss_param.c:157:13: note: include ‘<stdio.h>’ or provide a declaration of ‘printf’
make[3]: *** [Makefile:38: hss_param.o] Error 1
make[3]: *** Waiting for unfinished jobs....
make[2]: *** [Makefile:84: build/bin/bootgen] Error 2

The above error was reported on Debian 13 / gcc 14.2.0.

Reported-by: Peter Korsgaard <peter@korsgaard.com>
Upstream: submitted to Xilinx bootgen repo with CR-1256741

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-11-26 08:58:30 +01:00
Adrian Perez de Castro
9abe0ba95a package/woff2: fix cmake 4 compatibility
Add a patch fixing cmake 4 compatibility.

Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-25 21:23:09 +01:00
Andreas Kässens
742d83eea9 package/yajl: fix cmake 4 compatibility
Fixes deprecated CMake options.

Original patch by Rudi Heitbaum, rebased and applies with fuzz 0.

CC: Rudi Heitbaum <rudi@heitbaum.com>
Signed-off-by: Andreas Kässens <kaessens@sra.uni-hannover.de>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-25 21:22:02 +01:00
Bernd Kuhls
3837c92d71 package/ninja: bump version to 1.13.2
Release notes: https://github.com/ninja-build/ninja/releases

Version 1.13.0 added GNU Make jobserver support[1] so we switch back to
the official repo by partly reverting buildroot commit
227d7e0cba.

Comparing build times of mesa3d/iris between 1.13.2 and Kitware's latest
tag v1.13.0.gd74ef.kitware.jobserver-pipe-1 showed no difference on a
16c/32t machine with BR2_JLEVEL=0. The Kitware version adds pipe support
whose future is uncertain[2].

[1] https://github.com/ninja-build/ninja/releases/tag/v1.13.0
    https://github.com/ninja-build/ninja/pull/2506
[2] https://github.com/ninja-build/ninja/pull/2506#issuecomment-2659944455

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-24 22:06:26 +01:00
Bernd Kuhls
e46695bbe4 package/cmake: bump version to 4.2.0
Release notes:
https://cmake.org/cmake/help/latest/release/4.2.html
https://cmake.org/cmake/help/latest/release/4.1.html

License file was renamed upstream
2d42a5444f
and updated:
https://gitlab.kitware.com/cmake/cmake/-/commits/v4.0.3/LICENSE.rst?ref_type=tags

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-24 22:06:00 +01:00
Bernd Kuhls
84d9c08dbe package/meson: bump version to 1.9.1
Release notes: https://mesonbuild.com/Release-notes-for-1-9-0.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-24 22:05:36 +01:00
Zoltan Gyarmati
6a73f71736 package/proj: bump to 9.7.0
We jumped from 9.5.1 straight to 9.7.0, for release notes, see:
https://proj.org/en/stable/news.html

Signed-off-by: Zoltan Gyarmati <mr.zoltan.gyarmati@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-23 11:17:45 +01:00
Bernd Kuhls
8d996b98ea package/php-gnupg: bump version to 1.5.4
Changelog: https://pecl.php.net/package-changelog.php?package=gnupg

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-22 17:14:47 +01:00
Bernd Kuhls
3f71ae1c8c package/php-memcached: bump version to 3.4.0
Changelog: https://pecl.php.net/package-changelog.php?package=memcached

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-22 17:14:47 +01:00
Bernd Kuhls
00bc19058e package/php-amqp: bump version to 2.1.2
Changelog: https://pecl.php.net/package-changelog.php?package=amqp

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-22 17:14:47 +01:00
Marcus Hoffmann
b243b77ebe package/python-gpiod: new package
This adds the python bindings of libgpiod for version 2+.
While the python bindings for v1 were optionally built and
installed as part of the main libgpiod build, for v2 they have now been
published to pypi.org for easier consumption in the general python
ecosystem.

We need to set LINK_SYSTEM_LIBGPIOD=1 to actually build against the
system version of libgpiod which we install and not use a separate
bundled copy.

The package is licensed as libgpiod, but as published to pypi doesn't
include the LICENSE file that's part of upstream repository.
Reference pyproject.toml as that has the license identifier as a
workaround.

Signed-off-by: Marcus Hoffmann <buildroot@bubu1.eu>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-22 13:37:57 +01:00
Bernd Kuhls
3e296a1511 package/{mesa3d, mesa3d-headers}: bump version to 25.3.0
Release notes:
https://gitlab.freedesktop.org/mesa/mesa/-/blob/25.3/docs/relnotes/25.3.0.rst?ref_type=heads

Rebased patch 0001 due to upstream commit
82bafaa1fa

Rebased patch 0003 due to upstream commit
3bd0badd3a

Removed VDPAU support following upstream commit:
4b54277d2e
Added Config.in.legacy option.

Added optional dependency to libdisplay-info for Vulkan drivers:
2c870bbe20
https://gitlab.freedesktop.org/mesa/mesa/-/merge_requests/35461/diffs#0cc1139e3347f573ae1feee5b73dbc8a8a21fcfa

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
[Julien: resolve Config.in.legacy conflict]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-21 16:24:28 +01:00
Thomas Petazzoni
cad4f06931 package/binutils: remove support for binutils 2.42
Now that binutils 2.45 has been introduced and binutils 2.44 made the
default version, drop the oldest supported version, binutils 2.42,
keeping only the 3 last versions supported: 2.43, 2.44 and 2.45.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-21 12:34:33 +01:00
Thomas Petazzoni
08fa58f1da package/binutils: make binutils 2.44 be the default
Now that support for binutils 2.45 has been introduced, we follow our
policy of making binutils 2.44 the default version.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-21 12:34:33 +01:00
Thomas Petazzoni
b7d5ff9d51 package/binutils: add support for binutils 2.45.1
We bring patches 0001 and 0002 that we carry for binutils 2.44. Patch
0002 requires a small update as a nearby configure option has been
removed between 2.44 and 2.45. Patch 0003 that we have for binutils
2.44 is not needed as it is part of the 2.45 release.

Changes in 2.45:

* New versioned release of libsframe: libsframe.so.2.  This release introduces
  versioned symbols with version node name LIBSFRAME_2.0.  Some new symbols
  have been added to support the new flag SFRAME_F_FDE_FUNC_START_PCREL and
  retrieving flags from SFrame decoder and encoder objects:
    - Addition of sframe_decoder_get_flags,
      sframe_decoder_get_offsetof_fde_start_addr, sframe_encoder_get_flags,
      sframe_encoder_get_offsetof_fde_start_addr.
  This release also includes backward-incompatible ABI changes:
    - Removal of sframe_get_funcdesc_with_addr.
    - Change in the behavior of sframe_decoder_get_funcdesc_v2,
      sframe_encoder_add_funcdesc_v2 and sframe_encoder_write.

* On s390 64-bit (s390x), gas, ld, objdump, and readelf now support generating
  and processing SFrame V2 stack trace information (.sframe).  The assembler
  generates SFrame info from CFI directives with option "--gsframe".  The
  linker generates SFrame info for the linker-generated .plt section and merges
  all .sframe sections.  Both objdump and readelf dump SFrame info with option
  "--sframe[=<section-name>]".

* For SFrame stack trace format, the function start address in each SFrame
  FDE has a changed encoding:  The 32-bit signed integer now holds the offset
  of the start PC of the associated function from the sfde_func_start_address
  field itself (instead of the earlier where it was the offset from the start
  of the SFrame section itself).  All SFrame sections generated by gas and ld
  now default to this new encoding, setting the (new)
  SFRAME_F_FDE_FUNC_START_PCREL flag.

  Relocatable SFrame links are now fixed.

* Readelf now recognizes RISC-V GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS and
  GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED for zicfiss and zicfilp
  extensions.

* For RISC-V dis-assembler, the definition of mapping symbol $x is changed,
  so the file needs to be rebuilt since 2.45 once used .option arch directives.

* The LoongArch disassembler now properly accepts multiple disassembly
  options given by -M, such as "-M no-aliases,numeric".  (Previously only the
  first option took effect.)

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
[Julien: fix BR2_BINUTILS_VERSION_2_45_X prompt to 2.45.1]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-21 12:34:33 +01:00
Peter Korsgaard
36a2dc7f5e Update for 2025.11-rc1
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025.11-rc1
2025-11-20 21:49:56 +01:00
Thomas Perale
e09bf9e951 docs/manual: add information on CycloneDX
This patch adds information on how to generate a CycloneDX SBOM in
Buildroot. It also mentions how to track CVEs with that given SBOM.

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
[Peter: reword slightly]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-11-20 21:34:32 +01:00
Bernd Kuhls
40a7ae995c package/php: bump version to 8.4.15
Release notes:
https://www.php.net/releases/8.4/en.php
https://news-web.php.net/php.announce/473

Changelog: https://www.php.net/ChangeLog-8.php#PHP_8_4

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-11-20 21:16:35 +01:00
Bernd Kuhls
d62053fd1a package/mender-artifact: bump version to 4.2.0
Release notes:
https://github.com/mendersoftware/mender-artifact/releases/tag/4.2.0

https://github.com/mendersoftware/mender-artifact/releases/tag/4.1.1
(mentions CVE-2025-22868 as fixed, but this is a host-only package)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-20 21:07:35 +01:00
Pierre-Yves Kerbrat
e2f67d3f17 package/rdma-core: bump to version v60.0
For change log since v58.0, see:
https://github.com/linux-rdma/rdma-core/releases/tag/v59.0
https://github.com/linux-rdma/rdma-core/releases/tag/v60.0

Signed-off-by: Pierre-Yves Kerbrat <pkerbrat@free.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-20 19:18:59 +01:00
Bernd Kuhls
1023741fb1 package/pcre2: bump version to 10.47
Release notes:
https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.47

Updated license hash due to upstream commits:
4f5a2ada2e
1fffb0d44e
d8a9f2fe55

Added license file for sljit:
d8a9f2fe55

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-20 19:01:56 +01:00
Thomas Perale
51558fa3ea DEVELOPERS: add Thomas Perale to cve-check & cve.py
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-11-20 17:43:06 +01:00
Thomas Perale
6762c42e74 support/scripts/cve-check: add cve-check script
Enriches the input CycloneDX SBOM with vulnerability information and
analysis from the NVD database.

The NVD database is cloned using a mirror of it and the content is compared
locally. By default the path 'dl/buildroot-nvd' is used.

Example usage to analyse vulnerabilities of an input CycloneDX SBOM:

$ make show-info | utils/generate-cyclonedx | support/script/cve-check

The 'cve-check' can also be used to only enrich the vulnerabilities
present on the input SBOM with a set metadata (description, cvss,
references, ...) without applying an analysis.

With the following command the vulnerabilities ignored by Buildroot
present in the CycloneDX SBOM are enriched with description, cvss, etc
...

$ make show-info | utils/generate-cyclonedx | support/script/cve-check --enrich-only

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
[Peter: fix minor flake8 issues]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-11-20 17:13:40 +01:00
Thomas Perale
867017e736 support/scripts/cve.py: don't call download_nvd
This patch move the 'download_nvd' call to the 'pkg-stats' script
instead of automatically calling 'read_nvd_dir'.

Since the cve.py file can be used as a library it's up to the caller to
decide whether or not to update the NVD database.

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-11-20 17:03:39 +01:00
Bernd Kuhls
903c0db86e package/python-scp: fix dependency
Buildroot commit 3963c3c06e added this
package which selects python-paramiko but forgot to add its dependency.

Fixes warning:

WARNING: unmet direct dependencies detected for BR2_PACKAGE_PYTHON_PARAMIKO
  Depends on [n]: BR2_PACKAGE_PYTHON3 [=y] && BR2_PACKAGE_HOST_RUSTC_TARGET_ARCH_SUPPORTS [=n]
  Selected by [y]:
  - BR2_PACKAGE_PYTHON_SCP [=y] && BR2_PACKAGE_PYTHON3 [=y]

seen with https://autobuild.buildroot.net/results/423/4235283218bc49f53bf7cafd4a67f380dba659c0/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-11-20 17:01:03 +01:00
Bernd Kuhls
bb004ddba2 package/e2fsprogs: bump version to 1.47.3
Release notes:
https://git.kernel.org/pub/scm/fs/ext2/e2fsprogs.git/tree/doc/RelNotes/v1.47.3.txt

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-11-20 17:00:05 +01:00
Bernd Kuhls
56a1c162c5 package/llvm-project: bump to version 21.1.6
Release notes:
https://discourse.llvm.org/t/llvm-21-1-6-released/88895

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-19 21:43:02 +01:00
Bernd Kuhls
658e2287bf package/spirv-llvm-translator: bump version to 21.1.2
Release notes:
https://github.com/KhronosGroup/SPIRV-LLVM-Translator/releases/tag/v21.1.2

Changelog:
https://github.com/KhronosGroup/SPIRV-LLVM-Translator/compare/v21.1.1...v21.1.2

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-19 21:42:05 +01:00
Zoltan Gyarmati
cc5a1d3daa package/shapelib: bump to 1.6.2
For release notes, see:
http://shapelib.maptools.org/release.html

Signed-off-by: Zoltan Gyarmati <mr.zoltan.gyarmati@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-19 21:37:24 +01:00
Bernd Kuhls
55d1f2825b package/openvpn: security bump version to 2.6.16
Fixes CVE-2025-13086.

Release notes:
https://sourceforge.net/p/openvpn/mailman/message/59261309/

Changelog:
https://github.com/OpenVPN/openvpn/blob/release/2.6/ChangeLog
https://github.com/OpenVPN/openvpn/blob/release/2.6/Changes.rst

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-19 21:30:41 +01:00
Peter Korsgaard
779827f765 package/python-django: security bump to version 5.2.8
Fixed the following security issues:

CVE-2025-64458: Potential denial-of-service vulnerability in
HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

CVE-2025-64459: Potential SQL injection via _connector keyword argument

https://docs.djangoproject.com/en/5.2/releases/5.2.8/

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-19 21:13:59 +01:00
Bernd Kuhls
45a9ca057f package/llvm-project: bump to version 21.1.5
Release notes: https://discourse.llvm.org/t/llvm-21-1-5-released/88776

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-19 21:08:03 +01:00
Bernd Kuhls
4298e21e0a package/openocd: fix build with jimtcl 0.83
Buildroot commit 283821fc31 bumped jimtcl
to version 0.83 causing build errors with openocd.

Add two upstream commits to fix the problem.

Fixes:
https://autobuild.buildroot.net/results/f20/f20667f8fe159de6601a81a827f26d4f0382d673/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-11-19 20:35:11 +01:00
Pierre-Yves Kerbrat
8e5e8ea2cf package/rauc: bump to 1.15
Changelog: https://github.com/rauc/rauc/releases/tag/v1.15

The COPYING license hash file is updated, due to upstream update:
fe86f27725

Signed-off-by: Pierre-Yves Kerbrat <pkerbrat@free.fr>
Reviewed-by: Marcus Hoffmann <buildroot@bubu1.eu>
Tested-by: Marcus Hoffmann <buildroot@bubu1.eu>
[Julien: add link to upstream commit updating the license]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-19 19:16:49 +01:00
José Luis Salvador Rufo
6ff1bd328a package/zfs: bump version to 2.3.5
For release note, see:
https://github.com/openzfs/zfs/releases/tag/zfs-2.3.5

Signed-off-by: José Luis Salvador Rufo <salvador.joseluis@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-18 22:13:14 +01:00
Zoltan Gyarmati
2549e2b4fe package/quazip: bump version to 1.5
For release notes, see:
https://github.com/stachenov/quazip/releases/tag/v1.5

Signed-off-by: Zoltan Gyarmati <mr.zoltan.gyarmati@gmail.com>
[Julien: add link to release notes]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-18 22:03:58 +01:00
Pierre-Yves Kerbrat
2ce329692a package/stress-ng: bump to 0.19.06
Changelog:
https://github.com/ColinIanKing/stress-ng/blob/V0.19.06/debian/changelog

Signed-off-by: Pierre-Yves Kerbrat <pkerbrat@free.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-18 18:06:28 +01:00
Bernd Kuhls
88c26c4814 DEVELOPERS: remove Julien Corjon, e-mail bounces
<corjon.j@ecagroup.com>: host ecagroup-com.mail.protection.outlook.com[52.101.166.0]
 said: 550 5.4.1 Recipient address rejected: Access denied.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-11-18 08:05:02 +01:00
Yi Zheng
d6d8b5823a fs/squashfs: correct aarch64 conditional
BR_aarch64 is not defined. it seems should be BR2_aarch64

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-11-18 08:02:01 +01:00
Bernd Kuhls
5db55534af DEVELOPERS: remove Bernd Kuhls from libdecor & libfreeglut
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-17 23:18:15 +01:00
Bernd Kuhls
a1f5023bd9 package/libdecor: bump version to 0.2.4
Commit log:
https://gitlab.freedesktop.org/libdecor/libdecor/-/commits/0.2.4

Switched to xz tarball and hash provided by upstream.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-17 23:18:15 +01:00
Bernd Kuhls
75a566edb4 package/libfreeglut: bump version to 3.8.0
Changelog: https://github.com/freeglut/freeglut/blob/v3.8.0/ChangeLog

Removed all patches, they are included in this release.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-17 23:18:15 +01:00
Yann E. MORIN
855cd60573 package/distribution-registry: fix build on i386
The S3 storage drivers defines the maximum size of a chunk to a value
thqt does not fit in the native integer on 32-bit architectures. This
causes build failures:

    registry/storage/driver/s3-aws/s3.go:312:99: cannot use maxChunkSize
    (untyped int constant 5368709120) as int value in argument to
    getParameterAsInteger (overflows)

Ideally, we'd like to use a build tag that refers to whether the
architecture is 32- or 64-bit, but there is no such flag. Sigh...

Instead, backport a patch from upstream that papers over the issue, by
using the i386 build tag (of course, that still misses other 32-bit
archs, but are they really relevant in this case?).

Fixes:
https://autobuild.buildroot.org/results/8fa9c5f63f690b27336051be5178f0516e0c54d4/

Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
[Julien: add "Fixes:" link]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-17 22:28:52 +01:00
Dario Binacchi
ea9d7398ca package/pocketpy: bump to version 2.1.4
Release notes:
https://github.com/pocketpy/pocketpy/releases/tag/v2.1.4

Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-17 22:17:39 +01:00
Dario Binacchi
6a45133a5f package/uuu: bump to version 1.5.239
Release notes:
https://github.com/nxp-imx/mfgtools/releases/tag/uuu_1.5.239

Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-17 22:10:03 +01:00
Bernd Kuhls
0bf0d30591 package/libdrm: bump version to 2.4.129
Release notes:
https://lists.x.org/archives/xorg-announce/2025-November/003642.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-17 22:03:34 +01:00
Peter Korsgaard
80764d7208 package/luksmeta: security bump to version 10
Fixes the following security issue:

CVE-2025-11568: A  data corruption vulnerability has been identified in the
luksmeta utility when used with the LUKS1 disk encryption format.

https://github.com/advisories/GHSA-pvmm-7c2r-wmp4
https://github.com/latchset/luksmeta/releases/tag/v10

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-17 21:50:34 +01:00
Alexander Shirokov
6fb10dcf21 package/broot: bump version to 1.53.0
Changelog:
https://github.com/Canop/broot/blob/v1.53.0/CHANGELOG.md

Signed-off-by: Alexander Shirokov <shirokovalexs@gmail.com>
[Julien: update changelog URL to use tag]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-17 21:34:16 +01:00
Titouan Christophe
896e19a5c6 package/redis: security bump to v8.2.3
See the release notes: https://github.com/redis/redis/releases/tag/8.2.3

This fixes the following vulnerability:
- CVE-2025-62507:
    Redis is an open source, in-memory database that persists on disk. In
    versions 8.2.0 and above, a user can run the XACKDEL command with
    multiple ID's and trigger a stack buffer overflow, which may
    potentially lead to remote code execution. This issue is fixed in
    version 8.2.3. To workaround this issue without patching the redis-
    server executable is to prevent users from executing XACKDEL
    operation. This can be done using ACL to restrict XACKDEL command.
    https://www.cve.org/CVERecord?id=CVE-2025-62507

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-11-17 21:09:58 +01:00