mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-10-01 22:41:43 -09:00
Compare commits
122 Commits
2024.02.10
...
2024.02.12
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
aeeeefb855 | ||
|
|
f1a76fc8ec | ||
|
|
2c20dbc8f8 | ||
|
|
cf0f2ae539 | ||
|
|
2b39d1f89c | ||
|
|
a8f8e3e658 | ||
|
|
03b06f7f5f | ||
|
|
e0403cef7d | ||
|
|
bfcceaca1d | ||
|
|
78e596e45b | ||
|
|
01e010cfc4 | ||
|
|
7d3901ca5f | ||
|
|
21357a66fb | ||
|
|
73b8529fd1 | ||
|
|
f0b2e3f224 | ||
|
|
1637223b8d | ||
|
|
01e9401746 | ||
|
|
ce05244125 | ||
|
|
9af16eaf16 | ||
|
|
b3a1b9f2ec | ||
|
|
e2e59f8891 | ||
|
|
be2a4ed89a | ||
|
|
d976cec1be | ||
|
|
3d6e2e4111 | ||
|
|
fa7d35db4c | ||
|
|
71ba740453 | ||
|
|
1e0d7b66f2 | ||
|
|
5bf8e339bc | ||
|
|
e0b0fa2f16 | ||
|
|
4d772ebe75 | ||
|
|
cd2e6cb008 | ||
|
|
2f5db263aa | ||
|
|
bc9ae1c3c3 | ||
|
|
5d65f5cd1c | ||
|
|
d1ec60b8a1 | ||
|
|
ce0e7c7d5f | ||
|
|
3a863002bd | ||
|
|
7c69185b20 | ||
|
|
79b215ac2a | ||
|
|
bba0ea2715 | ||
|
|
0bdc4429d8 | ||
|
|
d559776a3a | ||
|
|
e8e4fbe2c6 | ||
|
|
528dcfe838 | ||
|
|
6402e054b4 | ||
|
|
24f9c50ddf | ||
|
|
a829f8d17d | ||
|
|
84d0090751 | ||
|
|
7c4e482b15 | ||
|
|
809778f47b | ||
|
|
a79ec5760c | ||
|
|
82ccb6dbb0 | ||
|
|
7cd02fa986 | ||
|
|
2def1470e8 | ||
|
|
2219410297 | ||
|
|
84f78d98e7 | ||
|
|
75634fc294 | ||
|
|
29a3e446a9 | ||
|
|
6330d1e3ae | ||
|
|
a102446634 | ||
|
|
2f23cd8680 | ||
|
|
738e02a473 | ||
|
|
26044d86c3 | ||
|
|
945968d410 | ||
|
|
db19aa29a8 | ||
|
|
63f8b81999 | ||
|
|
5966aca391 | ||
|
|
c5fb4b02c9 | ||
|
|
5a63cd58ff | ||
|
|
4e1f339a6b | ||
|
|
ed17c2d17f | ||
|
|
01cbdc4e31 | ||
|
|
a25b6f62f0 | ||
|
|
d4254e03d2 | ||
|
|
da5979cc87 | ||
|
|
2fdd00da65 | ||
|
|
9909e1798f | ||
|
|
d19bbc1cd6 | ||
|
|
8ca5e59855 | ||
|
|
b4151f28d0 | ||
|
|
8e62aeb3fe | ||
|
|
96e238c706 | ||
|
|
c4a75ea14d | ||
|
|
86d4ef1d87 | ||
|
|
4c74c39fdc | ||
|
|
ca095b0205 | ||
|
|
7481c69914 | ||
|
|
011530af10 | ||
|
|
9cea6d4fd8 | ||
|
|
a34ad4d830 | ||
|
|
5b5ee3de71 | ||
|
|
d63647b8b5 | ||
|
|
c06e05409f | ||
|
|
0602a5392a | ||
|
|
f612645ae5 | ||
|
|
88084a7a6c | ||
|
|
5382f887a0 | ||
|
|
14a38001a3 | ||
|
|
9ffc3efedc | ||
|
|
acfdec5515 | ||
|
|
ebbc5e892a | ||
|
|
915aba9b25 | ||
|
|
f022e05a26 | ||
|
|
ae0ec1dacb | ||
|
|
b3b7106324 | ||
|
|
9e548b1c09 | ||
|
|
57f2a1379e | ||
|
|
87dd140335 | ||
|
|
954711047f | ||
|
|
ff13942c67 | ||
|
|
86e0a2d52c | ||
|
|
a1fae4305e | ||
|
|
49a749fa54 | ||
|
|
ade4f4b4e5 | ||
|
|
50cd11d4ef | ||
|
|
75921aed27 | ||
|
|
e09ea71e22 | ||
|
|
87af0b08d9 | ||
|
|
5ff6213f0d | ||
|
|
5eb8fed14e | ||
|
|
45958ec3d6 | ||
|
|
9e25b3b395 |
@@ -1337,7 +1337,6 @@ package/waffle/0003-drop-C-dependency.patch Upstream
|
||||
package/wampcc/0001-Add-RISC-V-endian-detection.patch Upstream
|
||||
package/wampcc/0002-include-wampcc-platform.h-fix-build-with-musl-1.2.0.patch Upstream
|
||||
package/wampcc/0003-Broken-build-on-Windows.patch Upstream
|
||||
package/watchdogd/S01watchdogd Indent NotExecutable
|
||||
package/wget/0001-lib-getrandom.c-fix-build-with-uclibc-1.0.35.patch Upstream
|
||||
package/wilc-driver/0001-cfg80211.c-fix-missing-prandom_u32-with-Linux-6.1.0.patch Upstream
|
||||
package/wilc-driver/0002-spi.c-fix-build-failure-on-remove-callback.patch Upstream
|
||||
|
||||
31
CHANGES
31
CHANGES
@@ -1,3 +1,34 @@
|
||||
2024.02.12, released March 24st, 2025
|
||||
|
||||
Important / security related fixes.
|
||||
|
||||
Defconfigs: Octavo osd23mp1: Fix TF-A/Linux compilation after
|
||||
move to newer toolchain versions.
|
||||
|
||||
Updated/fixed packages: compiler-rt, exim, expat, fio, foot,
|
||||
jbig2dec, libjxl, libxml2, musl, optee-os, php, postgresql,
|
||||
prboom, python-typing-extensions, systemd, util-linux,
|
||||
watchdogd, webkitgtk
|
||||
|
||||
2024.02.11, released February 21th, 2025
|
||||
|
||||
Important / security related fixes.
|
||||
|
||||
Updated/fixed packages: acpica, apache, assimp, asterisk,
|
||||
bind, busybox, clamav, curlpp, dillo, elfutils, ffmpeg, foot,
|
||||
freetype, git, gnutls, go, gpsd, heimdal, imagemagick,
|
||||
intel-microcode, libbsd, libcurl, libopenssl, libtasn1, mdnsd,
|
||||
mpg123, musl, nginx, nodejs, openjpeg, openssh, openvpn,
|
||||
postgresql, python-django, redis, rsync, sdbus-cpp, socat,
|
||||
tor, tzdata, uemacs, unbound, usbutils, webkitgtk, xen, zic,
|
||||
zlog, zmqpp, zstd
|
||||
|
||||
Issues resolved:
|
||||
- OpenSSH 9.8 broken
|
||||
https://gitlab.com/buildroot.org/buildroot/-/issues/11
|
||||
- samba4 build failed in master
|
||||
https://gitlab.com/buildroot.org/buildroot/-/issues/86
|
||||
|
||||
2024.02.10, released January 9th, 2025
|
||||
|
||||
Important / security related fixes.
|
||||
|
||||
26
DEVELOPERS
26
DEVELOPERS
@@ -166,6 +166,12 @@ F: package/wine/
|
||||
N: Andreas Klinger <ak@it-klinger.de>
|
||||
F: package/ply/
|
||||
|
||||
N: Andreas Naumann <dev@andin.de>
|
||||
F: package/evemu/
|
||||
F: package/libevdev/
|
||||
F: package/pkg-qmake.mk
|
||||
F: package/qt5/qt5opcua/
|
||||
|
||||
N: Andreas Ziegler <br015@umbiko.net>
|
||||
F: package/mpd/
|
||||
|
||||
@@ -544,9 +550,6 @@ F: package/alsa-plugins/
|
||||
N: Changming Huang <jerry.huang@nxp.com>
|
||||
F: package/qoriq-cadence-dp-firmware/
|
||||
|
||||
N: Chris Dimich <chris.dimich@boundarydevices.com>
|
||||
F: package/freescale-imx/imx-vpu-hantro-daemon/
|
||||
|
||||
N: Chris Packham <judge.packham@gmail.com>
|
||||
F: package/coremark/
|
||||
F: package/coremark-pro/
|
||||
@@ -1128,6 +1131,10 @@ N: Frank Vanbever <frank.vanbever@mind.be>
|
||||
F: package/libmodsecurity/
|
||||
F: package/nginx-modsecurity/
|
||||
|
||||
N: Gaël PORTAY <gael.portay+rtone@gmail.com>
|
||||
F: board/raspberrypi/
|
||||
F: configs/raspberrypi*
|
||||
|
||||
N: Gao Xiang <hsiangkao@aol.com>
|
||||
F: package/erofs-utils/
|
||||
|
||||
@@ -1135,6 +1142,7 @@ N: Gary Bisson <bisson.gary@gmail.com>
|
||||
F: board/boundarydevices/
|
||||
F: configs/nitrogen*
|
||||
F: package/freescale-imx/
|
||||
F: package/freescale-imx/imx-vpu-hantro-daemon/
|
||||
F: package/gstreamer1/gst1-imx/
|
||||
F: package/libimxvpuapi/
|
||||
F: package/mfgtools/
|
||||
@@ -1795,6 +1803,7 @@ F: support/testing/tests/package/test_kmscube/
|
||||
F: support/testing/tests/package/test_less.py
|
||||
F: support/testing/tests/package/test_libcamera.py
|
||||
F: support/testing/tests/package/test_libcamera/
|
||||
F: support/testing/tests/package/test_libcurl.py
|
||||
F: support/testing/tests/package/test_libgpgme.py
|
||||
F: support/testing/tests/package/test_libjxl.py
|
||||
F: support/testing/tests/package/test_links.py
|
||||
@@ -1834,6 +1843,8 @@ F: support/testing/tests/package/test_octave.py
|
||||
F: support/testing/tests/package/test_ola.py
|
||||
F: support/testing/tests/package/test_ola/
|
||||
F: support/testing/tests/package/test_openblas.py
|
||||
F: support/testing/tests/package/test_patch.py
|
||||
F: support/testing/tests/package/test_patch/
|
||||
F: support/testing/tests/package/test_pciutils.py
|
||||
F: support/testing/tests/package/test_perftest.py
|
||||
F: support/testing/tests/package/test_pigz.py
|
||||
@@ -1873,6 +1884,7 @@ F: support/testing/tests/package/test_usbutils.py
|
||||
F: support/testing/tests/package/test_usbutils/
|
||||
F: support/testing/tests/package/test_weston.py
|
||||
F: support/testing/tests/package/test_weston/
|
||||
F: support/testing/tests/package/test_wget.py
|
||||
F: support/testing/tests/package/test_xfsprogs.py
|
||||
F: support/testing/tests/package/test_xfsprogs/
|
||||
F: support/testing/tests/package/test_xvisor.py
|
||||
@@ -2276,12 +2288,6 @@ N: Nathaniel Roach <nroach44@gmail.com>
|
||||
F: package/bandwidthd/
|
||||
F: package/libgudev/
|
||||
|
||||
N: Naumann Andreas <ANaumann@ultratronik.de>
|
||||
F: package/evemu/
|
||||
F: package/libevdev/
|
||||
F: package/pkg-qmake.mk
|
||||
F: package/qt5/qt5opcua/
|
||||
|
||||
N: Neal Frager <neal.frager@amd.com>
|
||||
F: board/versal/
|
||||
F: board/zynq/
|
||||
@@ -3105,6 +3111,8 @@ F: package/pixz/
|
||||
F: package/zerofree/
|
||||
F: support/testing/tests/package/test_msr_tools*
|
||||
F: support/testing/tests/package/test_pixz.py
|
||||
F: support/testing/tests/package/test_xen.py
|
||||
F: support/testing/tests/package/test_xen/
|
||||
F: support/testing/tests/package/test_zerofree.py
|
||||
|
||||
N: Vinicius Tinti <viniciustinti@gmail.com>
|
||||
|
||||
4
Makefile
4
Makefile
@@ -90,9 +90,9 @@ all:
|
||||
.PHONY: all
|
||||
|
||||
# Set and export the version string
|
||||
export BR2_VERSION := 2024.02.10
|
||||
export BR2_VERSION := 2024.02.12
|
||||
# Actual time the release is cut (for reproducible builds)
|
||||
BR2_VERSION_EPOCH = 1736430000
|
||||
BR2_VERSION_EPOCH = 1742837000
|
||||
|
||||
# Save running make version since it's clobbered by the make package
|
||||
RUNNING_MAKE_VERSION := $(MAKE_VERSION)
|
||||
|
||||
@@ -0,0 +1,61 @@
|
||||
From 0f75b03c008eacb9818af3a56dc088e72a623d17 Mon Sep 17 00:00:00 2001
|
||||
From: Marco Felsch <m.felsch@pengutronix.de>
|
||||
Date: Wed, 9 Nov 2022 12:59:09 +0100
|
||||
Subject: [PATCH] feat(build): add support for new binutils versions
|
||||
|
||||
Users of GNU ld (BPF) from binutils 2.39+ will observe multiple instaces
|
||||
of a new warning when linking the bl*.elf in the form:
|
||||
|
||||
ld.bfd: warning: stm32mp1_helper.o: missing .note.GNU-stack section implies executable stack
|
||||
ld.bfd: NOTE: This behaviour is deprecated and will be removed in a future version of the linker
|
||||
ld.bfd: warning: bl2.elf has a LOAD segment with RWX permissions
|
||||
ld.bfd: warning: bl32.elf has a LOAD segment with RWX permissions
|
||||
|
||||
These new warnings are enbaled by default to secure elf binaries:
|
||||
- https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=ba951afb99912da01a6e8434126b8fac7aa75107
|
||||
- https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=0d38576a34ec64a1b4500c9277a8e9d0f07e6774
|
||||
|
||||
Fix it in a similar way to what the Linux kernel does, see:
|
||||
https://lore.kernel.org/all/20220810222442.2296651-1-ndesaulniers@google.com/
|
||||
|
||||
Following the reasoning there, we set "-z noexecstack" for all linkers
|
||||
(although LLVM's LLD defaults to it) and optional add
|
||||
--no-warn-rwx-segments since this a ld.bfd related.
|
||||
|
||||
Signed-off-by: Marco Felsch <m.felsch@pengutronix.de>
|
||||
Signed-off-by: Robert Schwebel <r.schwebel@pengutronix.de>
|
||||
Change-Id: I9430f5fa5036ca88da46cd3b945754d62616b617
|
||||
Signed-off-by: Heiko Thiery <heiko.thiery@gmail.com>
|
||||
Upstream: https://github.com/ARM-software/arm-trusted-firmware/commit/1f49db5f25cdd4e43825c9bcc0575070b80f628c
|
||||
---
|
||||
Makefile | 7 ++++++-
|
||||
1 file changed, 6 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/Makefile b/Makefile
|
||||
index 1ddb7b844..470956b19 100644
|
||||
--- a/Makefile
|
||||
+++ b/Makefile
|
||||
@@ -416,6 +416,8 @@ endif
|
||||
|
||||
GCC_V_OUTPUT := $(shell $(CC) -v 2>&1)
|
||||
|
||||
+TF_LDFLAGS += -z noexecstack
|
||||
+
|
||||
# LD = armlink
|
||||
ifneq ($(findstring armlink,$(notdir $(LD))),)
|
||||
TF_LDFLAGS += --diag_error=warning --lto_level=O1
|
||||
@@ -442,7 +444,10 @@ TF_LDFLAGS += $(subst --,-Xlinker --,$(TF_LDFLAGS_$(ARCH)))
|
||||
|
||||
# LD = gcc-ld (ld) or llvm-ld (ld.lld) or other
|
||||
else
|
||||
-TF_LDFLAGS += --fatal-warnings -O1
|
||||
+# With ld.bfd version 2.39 and newer new warnings are added. Skip those since we
|
||||
+# are not loaded by a elf loader.
|
||||
+TF_LDFLAGS += $(call ld_option, --no-warn-rwx-segments)
|
||||
+TF_LDFLAGS += -O1
|
||||
TF_LDFLAGS += --gc-sections
|
||||
# ld.lld doesn't recognize the errata flags,
|
||||
# therefore don't add those in that case
|
||||
--
|
||||
2.30.2
|
||||
|
||||
@@ -0,0 +1,61 @@
|
||||
From 0f75b03c008eacb9818af3a56dc088e72a623d17 Mon Sep 17 00:00:00 2001
|
||||
From: Marco Felsch <m.felsch@pengutronix.de>
|
||||
Date: Wed, 9 Nov 2022 12:59:09 +0100
|
||||
Subject: [PATCH] feat(build): add support for new binutils versions
|
||||
|
||||
Users of GNU ld (BPF) from binutils 2.39+ will observe multiple instaces
|
||||
of a new warning when linking the bl*.elf in the form:
|
||||
|
||||
ld.bfd: warning: stm32mp1_helper.o: missing .note.GNU-stack section implies executable stack
|
||||
ld.bfd: NOTE: This behaviour is deprecated and will be removed in a future version of the linker
|
||||
ld.bfd: warning: bl2.elf has a LOAD segment with RWX permissions
|
||||
ld.bfd: warning: bl32.elf has a LOAD segment with RWX permissions
|
||||
|
||||
These new warnings are enbaled by default to secure elf binaries:
|
||||
- https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=ba951afb99912da01a6e8434126b8fac7aa75107
|
||||
- https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=0d38576a34ec64a1b4500c9277a8e9d0f07e6774
|
||||
|
||||
Fix it in a similar way to what the Linux kernel does, see:
|
||||
https://lore.kernel.org/all/20220810222442.2296651-1-ndesaulniers@google.com/
|
||||
|
||||
Following the reasoning there, we set "-z noexecstack" for all linkers
|
||||
(although LLVM's LLD defaults to it) and optional add
|
||||
--no-warn-rwx-segments since this a ld.bfd related.
|
||||
|
||||
Signed-off-by: Marco Felsch <m.felsch@pengutronix.de>
|
||||
Signed-off-by: Robert Schwebel <r.schwebel@pengutronix.de>
|
||||
Change-Id: I9430f5fa5036ca88da46cd3b945754d62616b617
|
||||
Signed-off-by: Heiko Thiery <heiko.thiery@gmail.com>
|
||||
Upstream: https://github.com/ARM-software/arm-trusted-firmware/commit/1f49db5f25cdd4e43825c9bcc0575070b80f628c
|
||||
---
|
||||
Makefile | 7 ++++++-
|
||||
1 file changed, 6 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/Makefile b/Makefile
|
||||
index 1ddb7b844..470956b19 100644
|
||||
--- a/Makefile
|
||||
+++ b/Makefile
|
||||
@@ -416,6 +416,8 @@ endif
|
||||
|
||||
GCC_V_OUTPUT := $(shell $(CC) -v 2>&1)
|
||||
|
||||
+TF_LDFLAGS += -z noexecstack
|
||||
+
|
||||
# LD = armlink
|
||||
ifneq ($(findstring armlink,$(notdir $(LD))),)
|
||||
TF_LDFLAGS += --diag_error=warning --lto_level=O1
|
||||
@@ -442,7 +444,10 @@ TF_LDFLAGS += $(subst --,-Xlinker --,$(TF_LDFLAGS_$(ARCH)))
|
||||
|
||||
# LD = gcc-ld (ld) or llvm-ld (ld.lld) or other
|
||||
else
|
||||
-TF_LDFLAGS += --fatal-warnings -O1
|
||||
+# With ld.bfd version 2.39 and newer new warnings are added. Skip those since we
|
||||
+# are not loaded by a elf loader.
|
||||
+TF_LDFLAGS += $(call ld_option, --no-warn-rwx-segments)
|
||||
+TF_LDFLAGS += -O1
|
||||
TF_LDFLAGS += --gc-sections
|
||||
# ld.lld doesn't recognize the errata flags,
|
||||
# therefore don't add those in that case
|
||||
--
|
||||
2.30.2
|
||||
|
||||
@@ -51,7 +51,7 @@ grub-bios-setup does but it works anyway.
|
||||
To test your BIOS image in Qemu
|
||||
-------------------------------
|
||||
|
||||
qemu-system-{i386,x86-64} -hda disk.img
|
||||
qemu-system-{i386,x86_64} -hda disk.img
|
||||
|
||||
Notes on using Grub2 for x86/x86_64 EFI-based platforms
|
||||
=======================================================
|
||||
@@ -93,7 +93,7 @@ To test your i386/x86-64 EFI image in Qemu
|
||||
|
||||
[0] https://github.com/retrage/edk2-nightly
|
||||
|
||||
2. qemu-system-{i386,x86-64} -bios <path-to-OVMF.fd> -hda disk.img
|
||||
2. qemu-system-{i386,x86_64} -bios <path-to-OVMF.fd> -hda disk.img
|
||||
|
||||
Notes on using Grub2 for ARM u-boot-based platforms
|
||||
===================================================
|
||||
|
||||
@@ -10,6 +10,10 @@ ifeq ($(BR2_TARGET_OPTEE_OS_LATEST),y)
|
||||
OPTEE_OS_LICENSE_FILES = LICENSE
|
||||
endif
|
||||
|
||||
OPTEE_OS_CPE_ID_PREFIX = cpe:2.3:o
|
||||
OPTEE_OS_CPE_ID_VENDOR = linaro
|
||||
OPTEE_OS_CPE_ID_PRODUCT = op-tee
|
||||
|
||||
OPTEE_OS_INSTALL_STAGING = YES
|
||||
OPTEE_OS_INSTALL_IMAGES = YES
|
||||
|
||||
|
||||
@@ -128,7 +128,7 @@ endif
|
||||
|
||||
config BR2_LINUX_KERNEL_VERSION
|
||||
string
|
||||
default "6.6.68" if BR2_LINUX_KERNEL_LATEST_VERSION
|
||||
default "6.6.83" if BR2_LINUX_KERNEL_LATEST_VERSION
|
||||
default "5.10.162-cip24" if BR2_LINUX_KERNEL_LATEST_CIP_VERSION
|
||||
default "5.10.162-cip24-rt10" if BR2_LINUX_KERNEL_LATEST_CIP_RT_VERSION
|
||||
default BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE \
|
||||
|
||||
@@ -1,10 +1,10 @@
|
||||
# From https://www.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
|
||||
sha256 283ff410e3f352ceed161ae30c0020301326059db03e86efcb384d46ac5840e2 linux-6.6.68.tar.xz
|
||||
sha256 e892c0b380100b7e6249060282ad07fbded092f0a2ca1d647243d0fbe9ce6e50 linux-6.1.122.tar.xz
|
||||
sha256 894bbbe63b7484a0bc576a1e11a8dbc090fbd476d6424431bdc8435e03c2c208 linux-6.6.83.tar.xz
|
||||
sha256 44caf510603b4cbbe78ef828620099d200536d666e909ddb73bb2938c7de5b16 linux-6.1.131.tar.xz
|
||||
# From https://www.kernel.org/pub/linux/kernel/v5.x/sha256sums.asc
|
||||
sha256 8fd8bbc80e7aae30aaca3b40576b283010b5e84e70f6fea1573589155ce8a9d0 linux-5.15.175.tar.xz
|
||||
sha256 fda44589a438dff8c718082e9a48843b15e5eb82f6cc2f98d48f48226063bef0 linux-5.10.232.tar.xz
|
||||
sha256 876fbae303723bcf9e01ab57b1a0a7d38045aacd481ff865dccc2cc89f591afe linux-5.4.288.tar.xz
|
||||
sha256 9319a47b1e9b5d344ff6015431856d0c9640e4faedc527c87f9129061a27136f linux-5.15.179.tar.xz
|
||||
sha256 953be3931101a94a93a644c1283ca41a7e567447ca87d3069ed4dd712dc1f1cc linux-5.10.235.tar.xz
|
||||
sha256 b3ad64a4476a7c5450b92eab9a888b84ecb64dc613fcb0128f653f58e958ef6e linux-5.4.291.tar.xz
|
||||
# From https://www.kernel.org/pub/linux/kernel/v4.x/sha256sums.asc
|
||||
sha256 607bed7de5cda31a443df4c8a78dbe5e8a9ad31afde2a4d28fe99ab4730e8de1 linux-4.19.325.tar.xz
|
||||
# Locally computed
|
||||
|
||||
@@ -1,5 +1,3 @@
|
||||
# From: https://www.intel.com/content/www/us/en/download/776303/acpi-component-architecture-downloads-unix-format-source-code-and-build-environment-with-an-intel-license.html
|
||||
sha1 3b893fb771cf3fbd3531de3036e1a5bfc624c9d2 acpica-unix-20230628.tar.gz
|
||||
# locally computed hash
|
||||
sha256 86876a745e3d224dcfd222ed3de465b47559e85811df2db9820ef09a9dff5cce acpica-unix-20230628.tar.gz
|
||||
sha256 905d6f191f3c29aa673602d9c66eb8df00f7e1b35064a081e0de81284ff17ee6 source/include/acpi.h
|
||||
sha256 9dca83cfee390b710485fbdf787048370049c05723b10cc220cfef6e13c31961 acpica-unix-20241212.tar.gz
|
||||
sha256 b28f54dc421531bbe269afd8c28bf6fdfd6affbe50c2831464f777ec1766d4a5 source/include/acpi.h
|
||||
|
||||
@@ -4,9 +4,9 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
ACPICA_VERSION = 20230628
|
||||
ACPICA_VERSION = 20241212
|
||||
ACPICA_SOURCE = acpica-unix-$(ACPICA_VERSION).tar.gz
|
||||
ACPICA_SITE = https://downloadmirror.intel.com/783534
|
||||
ACPICA_SITE = https://github.com/user-attachments/files/18117992
|
||||
ACPICA_LICENSE = BSD-3-Clause or GPL-2.0
|
||||
ACPICA_LICENSE_FILES = source/include/acpi.h
|
||||
ACPICA_DEPENDENCIES = host-bison host-flex
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
# From https://downloads.apache.org/httpd/httpd-2.4.62.tar.bz2.{sha256,sha512}
|
||||
sha256 674188e7bf44ced82da8db522da946849e22080d73d16c93f7f4df89e25729ec httpd-2.4.62.tar.bz2
|
||||
sha512 7db1876805d5c0f60f49bcb51f75cdf567120f2ff6349e68f084e9a86ae38265d9f1c67e7fca0082c9db136f3c408a88501ee11f26b1b68724ba240867171d77 httpd-2.4.62.tar.bz2
|
||||
# From https://downloads.apache.org/httpd/httpd-2.4.63.tar.bz2.{sha256,sha512}
|
||||
sha256 88fc236ab99b2864b248de7d49a008ec2afd7551e64dce8b95f58f32f94c46ab httpd-2.4.63.tar.bz2
|
||||
sha512 a804ca564dfee5907fe4ce4f36884815bace0621bc7b8c9aa7c99472a954aa19cb13733f90678ff3d58ab3c76cc0e33a27e1035dc1d8cb597a9622154c59ef48 httpd-2.4.63.tar.bz2
|
||||
# Locally computed
|
||||
sha256 47b8c2b6c3309282a99d4a3001575c790fead690cc14734628c4667d2bbffc43 LICENSE
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
APACHE_VERSION = 2.4.62
|
||||
APACHE_VERSION = 2.4.63
|
||||
APACHE_SOURCE = httpd-$(APACHE_VERSION).tar.bz2
|
||||
APACHE_SITE = https://dlcdn.apache.org/httpd
|
||||
APACHE_LICENSE = Apache-2.0
|
||||
|
||||
139
package/assimp/0001-Fix-leak-5762.patch
Normal file
139
package/assimp/0001-Fix-leak-5762.patch
Normal file
@@ -0,0 +1,139 @@
|
||||
From 4024726eca89331503bdab33d0b9186e901bbc45 Mon Sep 17 00:00:00 2001
|
||||
From: Kim Kulling <kimkulling@users.noreply.github.com>
|
||||
Date: Sat, 7 Sep 2024 21:02:34 +0200
|
||||
Subject: [PATCH] Fix leak (#5762)
|
||||
|
||||
* Fix leak
|
||||
|
||||
* Update utLogger.cpp
|
||||
|
||||
Upstream: https://github.com/assimp/assimp/commit/4024726eca89331503bdab33d0b9186e901bbc45
|
||||
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
|
||||
---
|
||||
code/Common/Assimp.cpp | 13 ++++++---
|
||||
fuzz/assimp_fuzzer.cc | 2 +-
|
||||
test/CMakeLists.txt | 1 +
|
||||
test/unit/Common/utLogger.cpp | 52 +++++++++++++++++++++++++++++++++++
|
||||
4 files changed, 63 insertions(+), 5 deletions(-)
|
||||
create mode 100644 test/unit/Common/utLogger.cpp
|
||||
|
||||
diff --git a/code/Common/Assimp.cpp b/code/Common/Assimp.cpp
|
||||
index ef3ee7b5d..91896e405 100644
|
||||
--- a/code/Common/Assimp.cpp
|
||||
+++ b/code/Common/Assimp.cpp
|
||||
@@ -359,20 +359,25 @@ void CallbackToLogRedirector(const char *msg, char *dt) {
|
||||
s->write(msg);
|
||||
}
|
||||
|
||||
+static LogStream *DefaultStream = nullptr;
|
||||
+
|
||||
// ------------------------------------------------------------------------------------------------
|
||||
ASSIMP_API aiLogStream aiGetPredefinedLogStream(aiDefaultLogStream pStream, const char *file) {
|
||||
aiLogStream sout;
|
||||
|
||||
ASSIMP_BEGIN_EXCEPTION_REGION();
|
||||
- LogStream *stream = LogStream::createDefaultStream(pStream, file);
|
||||
- if (!stream) {
|
||||
+ if (DefaultStream == nullptr) {
|
||||
+ DefaultStream = LogStream::createDefaultStream(pStream, file);
|
||||
+ }
|
||||
+
|
||||
+ if (!DefaultStream) {
|
||||
sout.callback = nullptr;
|
||||
sout.user = nullptr;
|
||||
} else {
|
||||
sout.callback = &CallbackToLogRedirector;
|
||||
- sout.user = (char *)stream;
|
||||
+ sout.user = (char *)DefaultStream;
|
||||
}
|
||||
- gPredefinedStreams.push_back(stream);
|
||||
+ gPredefinedStreams.push_back(DefaultStream);
|
||||
ASSIMP_END_EXCEPTION_REGION(aiLogStream);
|
||||
return sout;
|
||||
}
|
||||
diff --git a/fuzz/assimp_fuzzer.cc b/fuzz/assimp_fuzzer.cc
|
||||
index 8178674e8..91ffd9d69 100644
|
||||
--- a/fuzz/assimp_fuzzer.cc
|
||||
+++ b/fuzz/assimp_fuzzer.cc
|
||||
@@ -47,7 +47,7 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
using namespace Assimp;
|
||||
|
||||
extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t dataSize) {
|
||||
- aiLogStream stream = aiGetPredefinedLogStream(aiDefaultLogStream_STDOUT,NULL);
|
||||
+ aiLogStream stream = aiGetPredefinedLogStream(aiDefaultLogStream_STDOUT, nullptr);
|
||||
aiAttachLogStream(&stream);
|
||||
|
||||
Importer importer;
|
||||
diff --git a/test/CMakeLists.txt b/test/CMakeLists.txt
|
||||
index 7b7fd850a..1a45adac7 100644
|
||||
--- a/test/CMakeLists.txt
|
||||
+++ b/test/CMakeLists.txt
|
||||
@@ -100,6 +100,7 @@ SET( COMMON
|
||||
unit/Common/utBase64.cpp
|
||||
unit/Common/utHash.cpp
|
||||
unit/Common/utBaseProcess.cpp
|
||||
+ unit/Common/utLogger.cpp
|
||||
)
|
||||
|
||||
SET(Geometry
|
||||
diff --git a/test/unit/Common/utLogger.cpp b/test/unit/Common/utLogger.cpp
|
||||
new file mode 100644
|
||||
index 000000000..932240a7f
|
||||
--- /dev/null
|
||||
+++ b/test/unit/Common/utLogger.cpp
|
||||
@@ -0,0 +1,52 @@
|
||||
+/*
|
||||
+---------------------------------------------------------------------------
|
||||
+Open Asset Import Library (assimp)
|
||||
+---------------------------------------------------------------------------
|
||||
+
|
||||
+Copyright (c) 2006-2024, assimp team
|
||||
+
|
||||
+All rights reserved.
|
||||
+
|
||||
+Redistribution and use of this software in source and binary forms,
|
||||
+with or without modification, are permitted provided that the following
|
||||
+conditions are met:
|
||||
+
|
||||
+* Redistributions of source code must retain the above
|
||||
+copyright notice, this list of conditions and the
|
||||
+following disclaimer.
|
||||
+
|
||||
+* Redistributions in binary form must reproduce the above
|
||||
+copyright notice, this list of conditions and the
|
||||
+following disclaimer in the documentation and/or other
|
||||
+materials provided with the distribution.
|
||||
+
|
||||
+* Neither the name of the assimp team, nor the names of its
|
||||
+contributors may be used to endorse or promote products
|
||||
+derived from this software without specific prior
|
||||
+written permission of the assimp team.
|
||||
+
|
||||
+THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||
+"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
||||
+LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
|
||||
+A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
|
||||
+OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
|
||||
+SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
|
||||
+LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
|
||||
+DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
|
||||
+THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
|
||||
+(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
|
||||
+OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
+---------------------------------------------------------------------------
|
||||
+*/
|
||||
+
|
||||
+#include "UnitTestPCH.h"
|
||||
+#include <assimp/Importer.hpp>
|
||||
+
|
||||
+using namespace Assimp;
|
||||
+class utLogger : public ::testing::Test {};
|
||||
+
|
||||
+TEST_F(utLogger, aiGetPredefinedLogStream_leak_test) {
|
||||
+ aiLogStream stream1 = aiGetPredefinedLogStream(aiDefaultLogStream_STDOUT, nullptr);
|
||||
+ aiLogStream stream2 = aiGetPredefinedLogStream(aiDefaultLogStream_STDOUT, nullptr);
|
||||
+ ASSERT_EQ(stream1.callback, stream2.callback);
|
||||
+}
|
||||
--
|
||||
2.39.5
|
||||
|
||||
@@ -0,0 +1,39 @@
|
||||
From f12e52198669239af525e525ebb68407977f8e34 Mon Sep 17 00:00:00 2001
|
||||
From: tyler92 <tyler92@inbox.ru>
|
||||
Date: Wed, 11 Dec 2024 12:17:14 +0200
|
||||
Subject: [PATCH] Fix use after free in the CallbackToLogRedirector (#5918)
|
||||
|
||||
The heap-use-after-free vulnerability occurs in the
|
||||
CallbackToLogRedirector function. During the process of logging,
|
||||
a previously freed memory region is accessed, leading to a
|
||||
use-after-free condition. This vulnerability stems from incorrect
|
||||
memory management, specifically, freeing a log stream and then
|
||||
attempting to access it later on.
|
||||
|
||||
This patch sets NULL value for The DefaultStream global pointer.
|
||||
|
||||
Co-authored-by: Kim Kulling <kimkulling@users.noreply.github.com>
|
||||
Upstream: https://github.com/assimp/assimp/commit/f12e52198669239af525e525ebb68407977f8e34
|
||||
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
|
||||
---
|
||||
code/Common/Assimp.cpp | 4 ++++
|
||||
1 file changed, 4 insertions(+)
|
||||
|
||||
diff --git a/code/Common/Assimp.cpp b/code/Common/Assimp.cpp
|
||||
index 91896e405..22e16bd36 100644
|
||||
--- a/code/Common/Assimp.cpp
|
||||
+++ b/code/Common/Assimp.cpp
|
||||
@@ -416,6 +416,10 @@ ASSIMP_API aiReturn aiDetachLogStream(const aiLogStream *stream) {
|
||||
DefaultLogger::get()->detachStream(it->second);
|
||||
delete it->second;
|
||||
|
||||
+ if ((Assimp::LogStream *)stream->user == DefaultStream) {
|
||||
+ DefaultStream = nullptr;
|
||||
+ }
|
||||
+
|
||||
gActiveLogStreams.erase(it);
|
||||
|
||||
if (gActiveLogStreams.empty()) {
|
||||
--
|
||||
2.39.5
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
# Locally calculated
|
||||
sha256 a07666be71afe1ad4bc008c2336b7c688aca391271188eb9108d0c6db1be53f1 assimp-5.3.1.tar.gz
|
||||
sha256 66dfbaee288f2bc43172440a55d0235dfc7bf885dda6435c038e8000e79582cb assimp-5.4.3.tar.gz
|
||||
sha256 147874443d242b4e2bae97036e26ec9d6b37f706174c1bd5ecfcc8c1294cef51 LICENSE
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
ASSIMP_VERSION = 5.3.1
|
||||
ASSIMP_VERSION = 5.4.3
|
||||
ASSIMP_SITE = $(call github,assimp,assimp,v$(ASSIMP_VERSION))
|
||||
ASSIMP_LICENSE = BSD-3-Clause
|
||||
ASSIMP_LICENSE_FILES = LICENSE
|
||||
@@ -12,6 +12,10 @@ ASSIMP_CPE_ID_VENDOR = assimp
|
||||
ASSIMP_DEPENDENCIES = zlib
|
||||
ASSIMP_INSTALL_STAGING = YES
|
||||
|
||||
# 0001-Fix-leak-5762.patch
|
||||
# 0002-Fix-use-after-free-in-the-CallbackToLogRedirector-59.patch
|
||||
ASSIMP_IGNORE_CVES += CVE-2024-48423
|
||||
|
||||
# relocation truncated to fit: R_68K_GOT16O. We also need to disable
|
||||
# optimizations to not run into "Error: value -43420 out of range"
|
||||
# assembler issues.
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
# Locally computed
|
||||
sha256 a8162085b7d16f10d5cd16fc2e2cb8399dbe42bd1c321b14eec229fc0ed12570 asterisk-20.10.0.tar.gz
|
||||
sha256 94647b3f887f7dc91df51a4f88dfc3a07cc279bef86b8d05aa72f0c49d187571 asterisk-20.11.1.tar.gz
|
||||
|
||||
# sha1 from: http://downloads.asterisk.org/pub/telephony/sounds/releases
|
||||
# sha256 locally computed
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
ASTERISK_VERSION = 20.10.0
|
||||
ASTERISK_VERSION = 20.11.1
|
||||
# Use the github mirror: it's an official mirror maintained by Digium, and
|
||||
# provides tarballs, which the main Asterisk git tree (behind Gerrit) does not.
|
||||
ASTERISK_SITE = $(call github,asterisk,asterisk,$(ASTERISK_VERSION))
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Verified from https://ftp.isc.org/isc/bind9/9.18.31/bind-9.18.31.tar.xz.asc
|
||||
# with key 706B6C28620E76F91D11F7DF510A642A06C52CEC
|
||||
sha256 51b258969275c5206ef745a5aac03dbe98f1c8031fefed378d53597e7987b1b3 bind-9.18.31.tar.xz
|
||||
# Verified from https://ftp.isc.org/isc/bind9/9.18.33/bind-9.18.33.tar.xz.asc
|
||||
# with key D99CCEAF879747014F038D63182E23579462EFAA
|
||||
sha256 fb373fac5ebbc41c645160afd5a9fb451918f6c0e69ab1d9474154e2b515de40 bind-9.18.33.tar.xz
|
||||
sha256 9734825d67a3ac967b2c2f7c9a83c9e5db1c2474dbe9599157c3a4188749ebd4 COPYRIGHT
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
BIND_VERSION = 9.18.31
|
||||
BIND_VERSION = 9.18.33
|
||||
BIND_SOURCE= bind-$(BIND_VERSION).tar.xz
|
||||
BIND_SITE = https://ftp.isc.org/isc/bind9/$(BIND_VERSION)
|
||||
# bind does not support parallel builds.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
From ctxnop@gmail.com Sun Jul 21 12:10:52 2024
|
||||
From: ctxnop@gmail.com (Nop)
|
||||
Date: Sun, 21 Jul 2024 14:10:52 +0200
|
||||
From 32949508fe566aee8988cb6d8ee101ecc5e49a65 Mon Sep 17 00:00:00 2001
|
||||
From: ctxnop <ctxnop@gmail.com>
|
||||
Date: Sun, 26 Jan 2025 20:59:20 +0100
|
||||
Subject: [PATCH] menuconfig: GCC failing saying ncurses is not found
|
||||
|
||||
Newer GCC increased diagnostics levels resulting in considering the
|
||||
@@ -17,13 +17,12 @@ Signed-off-by: Fiona Klute (WIWA) <fiona.klute@gmx.de>
|
||||
scripts/kconfig/lxdialog/check-lxdialog.sh | 4 ++--
|
||||
1 file changed, 2 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/scripts/kconfig/lxdialog/check-lxdialog.sh
|
||||
b/scripts/kconfig/lxdialog/check-lxdialog.sh
|
||||
index 5075ebf2d..c644d1d48 100755
|
||||
diff --git a/scripts/kconfig/lxdialog/check-lxdialog.sh b/scripts/kconfig/lxdialog/check-lxdialog.sh
|
||||
index 5075ebf2d..08e4da3de 100755
|
||||
--- a/scripts/kconfig/lxdialog/check-lxdialog.sh
|
||||
+++ b/scripts/kconfig/lxdialog/check-lxdialog.sh
|
||||
@@ -45,9 +45,9 @@ trap "rm -f $tmp" 0 1 2 3 15
|
||||
|
||||
|
||||
# Check if we can link to ncurses
|
||||
check() {
|
||||
- $cc -x c - -o $tmp 2>/dev/null <<'EOF'
|
||||
@@ -34,5 +33,6 @@ index 5075ebf2d..c644d1d48 100755
|
||||
EOF
|
||||
if [ $? != 0 ]; then
|
||||
echo " *** Unable to find the ncurses libraries or the" 1>&2
|
||||
--
|
||||
2.45.2
|
||||
--
|
||||
2.47.1
|
||||
|
||||
|
||||
@@ -0,0 +1,154 @@
|
||||
From 7c73cdaa80faf0046b07c970321557ff04f7da64 Mon Sep 17 00:00:00 2001
|
||||
From: Denys Vlasenko <vda.linux@googlemail.com>
|
||||
Date: Fri, 26 May 2023 19:36:58 +0200
|
||||
Subject: [PATCH] awk: fix use-after-realloc (CVE-2021-42380), closes 15601
|
||||
|
||||
Signed-off-by: Denys Vlasenko <vda.linux@googlemail.com>
|
||||
|
||||
CVE: CVE-2021-42380
|
||||
Upstream-Status: Backport [https://git.busybox.net/busybox/commit/?id=5dcc443dba039b305a510c01883e9f34e42656ae]
|
||||
Signed-off-by: Peter Marko <peter.marko@siemens.com>
|
||||
[Thomas: taken from https://git.openembedded.org/openembedded-core/tree/meta/recipes-core/busybox/busybox/CVE-2021-42380.patch?id=e0ff4813b1cf4df0d851c857d57fb88d7db51bdd]
|
||||
Upstream: https://git.busybox.net/busybox/commit/?id=5dcc443dba039b305a510c01883e9f34e42656ae
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
editors/awk.c | 26 ++++++++++++++++-----
|
||||
testsuite/awk.tests | 55 +++++++++++++++++++++++++++++++++++++++++++++
|
||||
2 files changed, 75 insertions(+), 6 deletions(-)
|
||||
|
||||
diff --git a/editors/awk.c b/editors/awk.c
|
||||
index 728ee8685..2af823808 100644
|
||||
--- a/editors/awk.c
|
||||
+++ b/editors/awk.c
|
||||
@@ -555,7 +555,7 @@ struct globals {
|
||||
const char *g_progname;
|
||||
int g_lineno;
|
||||
int nfields;
|
||||
- int maxfields; /* used in fsrealloc() only */
|
||||
+ unsigned maxfields;
|
||||
var *Fields;
|
||||
char *g_pos;
|
||||
char g_saved_ch;
|
||||
@@ -1931,9 +1931,9 @@ static void fsrealloc(int size)
|
||||
{
|
||||
int i, newsize;
|
||||
|
||||
- if (size >= maxfields) {
|
||||
- /* Sanity cap, easier than catering for overflows */
|
||||
- if (size > 0xffffff)
|
||||
+ if ((unsigned)size >= maxfields) {
|
||||
+ /* Sanity cap, easier than catering for over/underflows */
|
||||
+ if ((unsigned)size > 0xffffff)
|
||||
bb_die_memory_exhausted();
|
||||
|
||||
i = maxfields;
|
||||
@@ -2891,6 +2891,7 @@ static var *evaluate(node *op, var *res)
|
||||
uint32_t opinfo;
|
||||
int opn;
|
||||
node *op1;
|
||||
+ var *old_Fields_ptr;
|
||||
|
||||
opinfo = op->info;
|
||||
opn = (opinfo & OPNMASK);
|
||||
@@ -2899,10 +2900,16 @@ static var *evaluate(node *op, var *res)
|
||||
debug_printf_eval("opinfo:%08x opn:%08x\n", opinfo, opn);
|
||||
|
||||
/* execute inevitable things */
|
||||
+ old_Fields_ptr = NULL;
|
||||
if (opinfo & OF_RES1) {
|
||||
if ((opinfo & OF_REQUIRED) && !op1)
|
||||
syntax_error(EMSG_TOO_FEW_ARGS);
|
||||
L.v = evaluate(op1, TMPVAR0);
|
||||
+ /* Does L.v point to $n variable? */
|
||||
+ if ((size_t)(L.v - Fields) < maxfields) {
|
||||
+ /* yes, remember where Fields[] is */
|
||||
+ old_Fields_ptr = Fields;
|
||||
+ }
|
||||
if (opinfo & OF_STR1) {
|
||||
L.s = getvar_s(L.v);
|
||||
debug_printf_eval("L.s:'%s'\n", L.s);
|
||||
@@ -2921,8 +2928,15 @@ static var *evaluate(node *op, var *res)
|
||||
*/
|
||||
if (opinfo & OF_RES2) {
|
||||
R.v = evaluate(op->r.n, TMPVAR1);
|
||||
- //TODO: L.v may be invalid now, set L.v to NULL to catch bugs?
|
||||
- //L.v = NULL;
|
||||
+ /* Seen in $5=$$5=$0:
|
||||
+ * Evaluation of R.v ($$5=$0 expression)
|
||||
+ * made L.v ($5) invalid. It's detected here.
|
||||
+ */
|
||||
+ if (old_Fields_ptr) {
|
||||
+ //if (old_Fields_ptr != Fields)
|
||||
+ // debug_printf_eval("L.v moved\n");
|
||||
+ L.v += Fields - old_Fields_ptr;
|
||||
+ }
|
||||
if (opinfo & OF_STR2) {
|
||||
R.s = getvar_s(R.v);
|
||||
debug_printf_eval("R.s:'%s'\n", R.s);
|
||||
diff --git a/testsuite/awk.tests b/testsuite/awk.tests
|
||||
index bbf0fbff1..ddc51047b 100755
|
||||
--- a/testsuite/awk.tests
|
||||
+++ b/testsuite/awk.tests
|
||||
@@ -485,4 +485,59 @@ testing 'awk assign while test' \
|
||||
"" \
|
||||
"foo"
|
||||
|
||||
+# User-supplied bug (SEGV) example, was causing use-after-realloc
|
||||
+testing 'awk assign while assign' \
|
||||
+ "awk '\$5=\$\$5=\$0'; echo \$?" \
|
||||
+ "\
|
||||
+─ process timing ────────────────────────────────────┬─ ─ process timing ────────────────────────────────────┬─ overall results ────┐ results ────┐
|
||||
+│ run time : │ run time : 0 days, 0 hrs, 0 min, 56 sec │ cycles done : 0 │ days, 0 hrs, 0 min, 56 sec │ cycles done : 0 │
|
||||
+│ last new find │ last new find : 0 days, 0 hrs, 0 min, 1 sec │ corpus count : 208 │ 0 days, 0 hrs, 0 min, 1 sec │ corpus count : 208 │
|
||||
+│last saved crash : │last saved crash : none seen yet │saved crashes : 0 │ seen yet │saved crashes : 0 │
|
||||
+│ last saved hang │ last saved hang : none seen yet │ saved hangs : 0 │ none seen yet │ saved hangs : 0 │
|
||||
+├─ cycle progress ─────────────────────┬─ ├─ cycle progress ─────────────────────┬─ map coverage┴──────────────────────┤ coverage┴──────────────────────┤
|
||||
+│ now processing : │ now processing : 184.1 (88.5%) │ map density : 0.30% / 0.52% │ (88.5%) │ map density : 0.30% / 0.52% │ │ now processing : 184.1 (88.5%) │ map density : 0.30% / 0.52% │
|
||||
+│ runs timed out │ runs timed out : 0 (0.00%) │ count coverage : 2.18 bits/tuple │ 0 (0.00%) │ count coverage : 2.18 bits/tuple │
|
||||
+├─ stage progress ─────────────────────┼─ ├─ stage progress ─────────────────────┼─ findings in depth ─────────────────┤ in depth ─────────────────┤
|
||||
+│ now trying : │ now trying : havoc │ favored items : 43 (20.67%) │ │ favored items : 43 (20.67%) │
|
||||
+│ stage execs : │ stage execs : 11.2k/131k (8.51%) │ new edges on : 52 (25.00%) │ (8.51%) │ new edges on │ stage execs : 11.2k/131k (8.51%) │ new edges on : 52 (25.00%) │ 52 (25.00%) │
|
||||
+│ total execs : │ total execs : 179k │ total crashes : 0 (0 saved) │ │ total crashes : 0 (0 saved) │ │ total execs : 179k │ total crashes : 0 (0 saved) │
|
||||
+│ exec speed : │ exec speed : 3143/sec │ total tmouts : 0 (0 saved) │ │ total tmouts : 0 (0 saved) │ │ exec speed : 3143/sec │ total tmouts : 0 (0 saved) │
|
||||
+├─ fuzzing strategy yields ├─ fuzzing strategy yields ────────────┴─────────────┬─ item geometry ───────┤ item geometry ───────┤
|
||||
+│ bit flips : │ bit flips : 11/648, 4/638, 5/618 │ levels : 4 │ 4/638, 5/618 │ levels : │ bit flips : 11/648, 4/638, 5/618 │ levels : 4 │ │
|
||||
+│ byte flips : │ byte flips : 0/81, 0/71, 0/52 │ pending : 199 │ 0/71, 0/52 │ pending : 199 │
|
||||
+│ arithmetics : 11/4494, │ arithmetics : 11/4494, 0/1153, 0/0 │ pend fav : 35 │ 0/0 │ pend fav : 35 │
|
||||
+│ known ints : 1/448, 0/1986, 0/2288 │ own finds : 207 │ known ints : │ known ints : 1/448, 0/1986, 0/2288 │ own finds : 207 │ 0/1986, 0/2288 │ own finds : 207 │
|
||||
+│ dictionary : 0/0, │ dictionary : 0/0, 0/0, 0/0, 0/0 │ imported : 0 │ 0/0, 0/0 │ imported : 0 │
|
||||
+│havoc/splice : 142/146k, 23/7616 │havoc/splice : 142/146k, 23/7616 │ stability : 100.00% │ stability : 100.00% │
|
||||
+│py/custom/rq : unused, unused, │py/custom/rq : unused, unused, unused, unused ├───────────────────────┘ unused ├───────────────────────┘
|
||||
+│ trim/eff : 57.02%/26, │ trim/eff : 57.02%/26, 0.00% │ [cpu000:100%] │ [cpu000:100%]
|
||||
+└────────────────────────────────────────────────────┘^C └────────────────────────────────────────────────────┘^C
|
||||
+0
|
||||
+" \
|
||||
+ "" \
|
||||
+ "\
|
||||
+─ process timing ────────────────────────────────────┬─ overall results ────┐
|
||||
+│ run time : 0 days, 0 hrs, 0 min, 56 sec │ cycles done : 0 │
|
||||
+│ last new find : 0 days, 0 hrs, 0 min, 1 sec │ corpus count : 208 │
|
||||
+│last saved crash : none seen yet │saved crashes : 0 │
|
||||
+│ last saved hang : none seen yet │ saved hangs : 0 │
|
||||
+├─ cycle progress ─────────────────────┬─ map coverage┴──────────────────────┤
|
||||
+│ now processing : 184.1 (88.5%) │ map density : 0.30% / 0.52% │
|
||||
+│ runs timed out : 0 (0.00%) │ count coverage : 2.18 bits/tuple │
|
||||
+├─ stage progress ─────────────────────┼─ findings in depth ─────────────────┤
|
||||
+│ now trying : havoc │ favored items : 43 (20.67%) │
|
||||
+│ stage execs : 11.2k/131k (8.51%) │ new edges on : 52 (25.00%) │
|
||||
+│ total execs : 179k │ total crashes : 0 (0 saved) │
|
||||
+│ exec speed : 3143/sec │ total tmouts : 0 (0 saved) │
|
||||
+├─ fuzzing strategy yields ────────────┴─────────────┬─ item geometry ───────┤
|
||||
+│ bit flips : 11/648, 4/638, 5/618 │ levels : 4 │
|
||||
+│ byte flips : 0/81, 0/71, 0/52 │ pending : 199 │
|
||||
+│ arithmetics : 11/4494, 0/1153, 0/0 │ pend fav : 35 │
|
||||
+│ known ints : 1/448, 0/1986, 0/2288 │ own finds : 207 │
|
||||
+│ dictionary : 0/0, 0/0, 0/0, 0/0 │ imported : 0 │
|
||||
+│havoc/splice : 142/146k, 23/7616 │ stability : 100.00% │
|
||||
+│py/custom/rq : unused, unused, unused, unused ├───────────────────────┘
|
||||
+│ trim/eff : 57.02%/26, 0.00% │ [cpu000:100%]
|
||||
+└────────────────────────────────────────────────────┘^C"
|
||||
+
|
||||
exit $FAILCOUNT
|
||||
--
|
||||
2.47.1
|
||||
|
||||
@@ -0,0 +1,70 @@
|
||||
From 20a91edce02adc258038a2e9bf5bda0fe27a5050 Mon Sep 17 00:00:00 2001
|
||||
From: Natanael Copa <ncopa@alpinelinux.org>
|
||||
Date: Mon, 20 May 2024 17:55:28 +0200
|
||||
Subject: [PATCH] awk: fix use after free (CVE-2023-42363)
|
||||
|
||||
function old new delta
|
||||
evaluate 3377 3385 +8
|
||||
|
||||
Fixes https://bugs.busybox.net/show_bug.cgi?id=15865
|
||||
|
||||
Signed-off-by: Natanael Copa <ncopa@alpinelinux.org>
|
||||
Signed-off-by: Denys Vlasenko <vda.linux@googlemail.com>
|
||||
|
||||
CVE: CVE-2023-42363
|
||||
Upstream-Status: Backport [https://git.busybox.net/busybox/commit/?id=fb08d43d44d1fea1f741fafb9aa7e1958a5f69aa]
|
||||
Signed-off-by: Peter Marko <peter.marko@siemens.com>
|
||||
[Thomas: taken from https://git.openembedded.org/openembedded-core/tree/meta/recipes-core/busybox/busybox/CVE-2023-42363.patch?id=e0ff4813b1cf4df0d851c857d57fb88d7db51bdd]
|
||||
Upstream: https://git.busybox.net/busybox/commit/?id=fb08d43d44d1fea1f741fafb9aa7e1958a5f69aa
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
editors/awk.c | 21 +++++++++++++--------
|
||||
1 file changed, 13 insertions(+), 8 deletions(-)
|
||||
|
||||
diff --git a/editors/awk.c b/editors/awk.c
|
||||
index 2af823808..d45724d59 100644
|
||||
--- a/editors/awk.c
|
||||
+++ b/editors/awk.c
|
||||
@@ -2910,19 +2910,14 @@ static var *evaluate(node *op, var *res)
|
||||
/* yes, remember where Fields[] is */
|
||||
old_Fields_ptr = Fields;
|
||||
}
|
||||
- if (opinfo & OF_STR1) {
|
||||
- L.s = getvar_s(L.v);
|
||||
- debug_printf_eval("L.s:'%s'\n", L.s);
|
||||
- }
|
||||
if (opinfo & OF_NUM1) {
|
||||
L_d = getvar_i(L.v);
|
||||
debug_printf_eval("L_d:%f\n", L_d);
|
||||
}
|
||||
}
|
||||
- /* NB: Must get string/numeric values of L (done above)
|
||||
- * _before_ evaluate()'ing R.v: if both L and R are $NNNs,
|
||||
- * and right one is large, then L.v points to Fields[NNN1],
|
||||
- * second evaluate() reallocates and moves (!) Fields[],
|
||||
+ /* NB: if both L and R are $NNNs, and right one is large,
|
||||
+ * then at this pint L.v points to Fields[NNN1], second
|
||||
+ * evaluate() below reallocates and moves (!) Fields[],
|
||||
* R.v points to Fields[NNN2] but L.v now points to freed mem!
|
||||
* (Seen trying to evaluate "$444 $44444")
|
||||
*/
|
||||
@@ -2942,6 +2937,16 @@ static var *evaluate(node *op, var *res)
|
||||
debug_printf_eval("R.s:'%s'\n", R.s);
|
||||
}
|
||||
}
|
||||
+ /* Get L.s _after_ R.v is evaluated: it may have realloc'd L.v
|
||||
+ * so we must get the string after "old_Fields_ptr" correction
|
||||
+ * above. Testcase: x = (v = "abc", gsub("b", "X", v));
|
||||
+ */
|
||||
+ if (opinfo & OF_RES1) {
|
||||
+ if (opinfo & OF_STR1) {
|
||||
+ L.s = getvar_s(L.v);
|
||||
+ debug_printf_eval("L.s:'%s'\n", L.s);
|
||||
+ }
|
||||
+ }
|
||||
|
||||
debug_printf_eval("switch(0x%x)\n", XC(opinfo & OPCLSMASK));
|
||||
switch (XC(opinfo & OPCLSMASK)) {
|
||||
--
|
||||
2.47.1
|
||||
|
||||
203
package/busybox/0013-awk-fix-precedence-of-relative-to.patch
Normal file
203
package/busybox/0013-awk-fix-precedence-of-relative-to.patch
Normal file
@@ -0,0 +1,203 @@
|
||||
From 47ff44735c0cd05efd899fb3486aca77e65fbe15 Mon Sep 17 00:00:00 2001
|
||||
From: Denys Vlasenko <vda.linux@googlemail.com>
|
||||
Date: Tue, 30 May 2023 16:42:18 +0200
|
||||
Subject: [PATCH] awk: fix precedence of = relative to ==
|
||||
|
||||
Discovered while adding code to disallow assignments to non-lvalues
|
||||
|
||||
function old new delta
|
||||
parse_expr 936 991 +55
|
||||
.rodata 105243 105247 +4
|
||||
------------------------------------------------------------------------------
|
||||
(add/remove: 0/0 grow/shrink: 2/0 up/down: 59/0) Total: 59 bytes
|
||||
|
||||
CVE: CVE-2023-42364 CVE-2023-42365
|
||||
|
||||
Upstream-Status: Backport [https://git.busybox.net/busybox/commit/?id=0256e00a9d077588bd3a39f5a1ef7e2eaa2911e4]
|
||||
Signed-off-by: Denys Vlasenko <vda.linux@googlemail.com>
|
||||
(cherry picked from commit 0256e00a9d077588bd3a39f5a1ef7e2eaa2911e4)
|
||||
Signed-off-by: Khem Raj <raj.khem@gmail.com>
|
||||
[Thomas: taken from https://git.openembedded.org/openembedded-core/tree/meta/recipes-core/busybox/busybox/0001-awk-fix-precedence-of-relative-to.patch?id=e0ff4813b1cf4df0d851c857d57fb88d7db51bdd]
|
||||
Upstream: https://git.busybox.net/busybox/commit/?id=0256e00a9d077588bd3a39f5a1ef7e2eaa2911e4
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
editors/awk.c | 66 ++++++++++++++++++++++++++++++---------------
|
||||
testsuite/awk.tests | 5 ++++
|
||||
2 files changed, 50 insertions(+), 21 deletions(-)
|
||||
|
||||
diff --git a/editors/awk.c b/editors/awk.c
|
||||
index d45724d59..5962c3f6a 100644
|
||||
--- a/editors/awk.c
|
||||
+++ b/editors/awk.c
|
||||
@@ -337,7 +337,9 @@ static void debug_parse_print_tc(uint32_t n)
|
||||
#undef P
|
||||
#undef PRIMASK
|
||||
#undef PRIMASK2
|
||||
-#define P(x) (x << 24)
|
||||
+/* Smaller 'x' means _higher_ operator precedence */
|
||||
+#define PRECEDENCE(x) (x << 24)
|
||||
+#define P(x) PRECEDENCE(x)
|
||||
#define PRIMASK 0x7F000000
|
||||
#define PRIMASK2 0x7E000000
|
||||
|
||||
@@ -360,7 +362,7 @@ enum {
|
||||
OC_MOVE = 0x1f00, OC_PGETLINE = 0x2000, OC_REGEXP = 0x2100,
|
||||
OC_REPLACE = 0x2200, OC_RETURN = 0x2300, OC_SPRINTF = 0x2400,
|
||||
OC_TERNARY = 0x2500, OC_UNARY = 0x2600, OC_VAR = 0x2700,
|
||||
- OC_DONE = 0x2800,
|
||||
+ OC_CONST = 0x2800, OC_DONE = 0x2900,
|
||||
|
||||
ST_IF = 0x3000, ST_DO = 0x3100, ST_FOR = 0x3200,
|
||||
ST_WHILE = 0x3300
|
||||
@@ -440,9 +442,9 @@ static const uint32_t tokeninfo[] ALIGN4 = {
|
||||
#define TI_PREINC (OC_UNARY|xV|P(9)|'P')
|
||||
#define TI_PREDEC (OC_UNARY|xV|P(9)|'M')
|
||||
TI_PREINC, TI_PREDEC, OC_FIELD|xV|P(5),
|
||||
- OC_COMPARE|VV|P(39)|5, OC_MOVE|VV|P(74), OC_REPLACE|NV|P(74)|'+', OC_REPLACE|NV|P(74)|'-',
|
||||
- OC_REPLACE|NV|P(74)|'*', OC_REPLACE|NV|P(74)|'/', OC_REPLACE|NV|P(74)|'%', OC_REPLACE|NV|P(74)|'&',
|
||||
- OC_BINARY|NV|P(29)|'+', OC_BINARY|NV|P(29)|'-', OC_REPLACE|NV|P(74)|'&', OC_BINARY|NV|P(15)|'&',
|
||||
+ OC_COMPARE|VV|P(39)|5, OC_MOVE|VV|P(38), OC_REPLACE|NV|P(38)|'+', OC_REPLACE|NV|P(38)|'-',
|
||||
+ OC_REPLACE|NV|P(38)|'*', OC_REPLACE|NV|P(38)|'/', OC_REPLACE|NV|P(38)|'%', OC_REPLACE|NV|P(38)|'&',
|
||||
+ OC_BINARY|NV|P(29)|'+', OC_BINARY|NV|P(29)|'-', OC_REPLACE|NV|P(38)|'&', OC_BINARY|NV|P(15)|'&',
|
||||
OC_BINARY|NV|P(25)|'/', OC_BINARY|NV|P(25)|'%', OC_BINARY|NV|P(15)|'&', OC_BINARY|NV|P(25)|'*',
|
||||
OC_COMPARE|VV|P(39)|4, OC_COMPARE|VV|P(39)|3, OC_COMPARE|VV|P(39)|0, OC_COMPARE|VV|P(39)|1,
|
||||
#define TI_LESS (OC_COMPARE|VV|P(39)|2)
|
||||
@@ -1290,7 +1292,7 @@ static uint32_t next_token(uint32_t expected)
|
||||
save_tclass = tc;
|
||||
save_info = t_info;
|
||||
tc = TC_BINOPX;
|
||||
- t_info = OC_CONCAT | SS | P(35);
|
||||
+ t_info = OC_CONCAT | SS | PRECEDENCE(35);
|
||||
}
|
||||
|
||||
t_tclass = tc;
|
||||
@@ -1350,9 +1352,8 @@ static node *parse_expr(uint32_t term_tc)
|
||||
{
|
||||
node sn;
|
||||
node *cn = &sn;
|
||||
- node *vn, *glptr;
|
||||
+ node *glptr;
|
||||
uint32_t tc, expected_tc;
|
||||
- var *v;
|
||||
|
||||
debug_printf_parse("%s() term_tc(%x):", __func__, term_tc);
|
||||
debug_parse_print_tc(term_tc);
|
||||
@@ -1363,11 +1364,12 @@ static node *parse_expr(uint32_t term_tc)
|
||||
expected_tc = TS_OPERAND | TS_UOPPRE | TC_REGEXP | term_tc;
|
||||
|
||||
while (!((tc = next_token(expected_tc)) & term_tc)) {
|
||||
+ node *vn;
|
||||
|
||||
if (glptr && (t_info == TI_LESS)) {
|
||||
/* input redirection (<) attached to glptr node */
|
||||
debug_printf_parse("%s: input redir\n", __func__);
|
||||
- cn = glptr->l.n = new_node(OC_CONCAT | SS | P(37));
|
||||
+ cn = glptr->l.n = new_node(OC_CONCAT | SS | PRECEDENCE(37));
|
||||
cn->a.n = glptr;
|
||||
expected_tc = TS_OPERAND | TS_UOPPRE;
|
||||
glptr = NULL;
|
||||
@@ -1379,24 +1381,42 @@ static node *parse_expr(uint32_t term_tc)
|
||||
* previous operators with higher priority */
|
||||
vn = cn;
|
||||
while (((t_info & PRIMASK) > (vn->a.n->info & PRIMASK2))
|
||||
- || ((t_info == vn->info) && t_info == TI_COLON)
|
||||
+ || (t_info == vn->info && t_info == TI_COLON)
|
||||
) {
|
||||
vn = vn->a.n;
|
||||
if (!vn->a.n) syntax_error(EMSG_UNEXP_TOKEN);
|
||||
}
|
||||
if (t_info == TI_TERNARY)
|
||||
//TODO: why?
|
||||
- t_info += P(6);
|
||||
+ t_info += PRECEDENCE(6);
|
||||
cn = vn->a.n->r.n = new_node(t_info);
|
||||
cn->a.n = vn->a.n;
|
||||
if (tc & TS_BINOP) {
|
||||
cn->l.n = vn;
|
||||
-//FIXME: this is the place to detect and reject assignments to non-lvalues.
|
||||
-//Currently we allow "assignments" to consts and temporaries, nonsense like this:
|
||||
-// awk 'BEGIN { "qwe" = 1 }'
|
||||
-// awk 'BEGIN { 7 *= 7 }'
|
||||
-// awk 'BEGIN { length("qwe") = 1 }'
|
||||
-// awk 'BEGIN { (1+1) += 3 }'
|
||||
+
|
||||
+ /* Prevent:
|
||||
+ * awk 'BEGIN { "qwe" = 1 }'
|
||||
+ * awk 'BEGIN { 7 *= 7 }'
|
||||
+ * awk 'BEGIN { length("qwe") = 1 }'
|
||||
+ * awk 'BEGIN { (1+1) += 3 }'
|
||||
+ */
|
||||
+ /* Assignment? (including *= and friends) */
|
||||
+ if (((t_info & OPCLSMASK) == OC_MOVE)
|
||||
+ || ((t_info & OPCLSMASK) == OC_REPLACE)
|
||||
+ ) {
|
||||
+ debug_printf_parse("%s: MOVE/REPLACE vn->info:%08x\n", __func__, vn->info);
|
||||
+ /* Left side is a (variable or array element)
|
||||
+ * or function argument
|
||||
+ * or $FIELD ?
|
||||
+ */
|
||||
+ if ((vn->info & OPCLSMASK) != OC_VAR
|
||||
+ && (vn->info & OPCLSMASK) != OC_FNARG
|
||||
+ && (vn->info & OPCLSMASK) != OC_FIELD
|
||||
+ ) {
|
||||
+ syntax_error(EMSG_UNEXP_TOKEN); /* no. bad */
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
expected_tc = TS_OPERAND | TS_UOPPRE | TC_REGEXP;
|
||||
if (t_info == TI_PGETLINE) {
|
||||
/* it's a pipe */
|
||||
@@ -1432,6 +1452,8 @@ static node *parse_expr(uint32_t term_tc)
|
||||
/* one should be very careful with switch on tclass -
|
||||
* only simple tclasses should be used (TC_xyz, not TS_xyz) */
|
||||
switch (tc) {
|
||||
+ var *v;
|
||||
+
|
||||
case TC_VARIABLE:
|
||||
case TC_ARRAY:
|
||||
debug_printf_parse("%s: TC_VARIABLE | TC_ARRAY\n", __func__);
|
||||
@@ -1452,14 +1474,14 @@ static node *parse_expr(uint32_t term_tc)
|
||||
case TC_NUMBER:
|
||||
case TC_STRING:
|
||||
debug_printf_parse("%s: TC_NUMBER | TC_STRING\n", __func__);
|
||||
- cn->info = OC_VAR;
|
||||
+ cn->info = OC_CONST;
|
||||
v = cn->l.v = xzalloc(sizeof(var));
|
||||
- if (tc & TC_NUMBER)
|
||||
+ if (tc & TC_NUMBER) {
|
||||
setvar_i(v, t_double);
|
||||
- else {
|
||||
+ } else {
|
||||
setvar_s(v, t_string);
|
||||
- expected_tc &= ~TC_UOPPOST; /* "str"++ is not allowed */
|
||||
}
|
||||
+ expected_tc &= ~TC_UOPPOST; /* NUM++, "str"++ not allowed */
|
||||
break;
|
||||
|
||||
case TC_REGEXP:
|
||||
@@ -3107,6 +3129,8 @@ static var *evaluate(node *op, var *res)
|
||||
|
||||
/* -- recursive node type -- */
|
||||
|
||||
+ case XC( OC_CONST ):
|
||||
+ debug_printf_eval("CONST ");
|
||||
case XC( OC_VAR ):
|
||||
debug_printf_eval("VAR\n");
|
||||
L.v = op->l.v;
|
||||
diff --git a/testsuite/awk.tests b/testsuite/awk.tests
|
||||
index ddc51047b..a78fdcd98 100755
|
||||
--- a/testsuite/awk.tests
|
||||
+++ b/testsuite/awk.tests
|
||||
@@ -540,4 +540,9 @@ testing 'awk assign while assign' \
|
||||
│ trim/eff : 57.02%/26, 0.00% │ [cpu000:100%]
|
||||
└────────────────────────────────────────────────────┘^C"
|
||||
|
||||
+testing "awk = has higher precedence than == (despite what gawk manpage claims)" \
|
||||
+ "awk 'BEGIN { v=1; print 2==v; print 2==v=2; print v; print v=3==3; print v}'" \
|
||||
+ '0\n1\n2\n1\n3\n' \
|
||||
+ '' ''
|
||||
+
|
||||
exit $FAILCOUNT
|
||||
--
|
||||
2.47.1
|
||||
|
||||
@@ -0,0 +1,102 @@
|
||||
From 173164c6b2f2ad17dd14d3a43e5bff47abde7199 Mon Sep 17 00:00:00 2001
|
||||
From: Natanael Copa <ncopa@alpinelinux.org>
|
||||
Date: Tue, 21 May 2024 14:46:08 +0200
|
||||
Subject: [PATCH] awk: fix ternary operator and precedence of =
|
||||
|
||||
Adjust the = precedence test to match behavior of gawk, mawk and
|
||||
FreeBSD. awk 'BEGIN {print v=3==3; print v}' should print two '1'.
|
||||
|
||||
To fix this, and to unbreak the ternary conditional operator, we restore
|
||||
the precedence of = in the token list, but override this with a lower
|
||||
priority when the assignment is on the right side of a compare.
|
||||
|
||||
This fixes commit 0256e00a9d07 (awk: fix precedence of = relative to ==) [1]
|
||||
|
||||
CVE: CVE-2023-42364 CVE-2023-42365
|
||||
|
||||
Upstream-Status: Submitted [http://lists.busybox.net/pipermail/busybox/2024-May/090766.html]
|
||||
|
||||
[1] https://bugs.busybox.net/show_bug.cgi?id=15871#c6
|
||||
|
||||
Signed-off-by: Natanael Copa <ncopa@alpinelinux.org>
|
||||
(cherry picked from commit 1714301c405ef03b39605c85c23f22a190cddd95)
|
||||
Signed-off-by: Khem Raj <raj.khem@gmail.com>
|
||||
[Thomas: taken from https://git.openembedded.org/openembedded-core/tree/meta/recipes-core/busybox/busybox/0002-awk-fix-ternary-operator-and-precedence-of.patch?id=e0ff4813b1cf4df0d851c857d57fb88d7db51bdd]
|
||||
Upstream: https://git.busybox.net/busybox/commit/?id=38335df9e9f45378c3407defd38b5b610578bdda
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
editors/awk.c | 18 ++++++++++++++----
|
||||
testsuite/awk.tests | 9 +++++++--
|
||||
2 files changed, 21 insertions(+), 6 deletions(-)
|
||||
|
||||
diff --git a/editors/awk.c b/editors/awk.c
|
||||
index 5962c3f6a..9467f4644 100644
|
||||
--- a/editors/awk.c
|
||||
+++ b/editors/awk.c
|
||||
@@ -442,9 +442,10 @@ static const uint32_t tokeninfo[] ALIGN4 = {
|
||||
#define TI_PREINC (OC_UNARY|xV|P(9)|'P')
|
||||
#define TI_PREDEC (OC_UNARY|xV|P(9)|'M')
|
||||
TI_PREINC, TI_PREDEC, OC_FIELD|xV|P(5),
|
||||
- OC_COMPARE|VV|P(39)|5, OC_MOVE|VV|P(38), OC_REPLACE|NV|P(38)|'+', OC_REPLACE|NV|P(38)|'-',
|
||||
- OC_REPLACE|NV|P(38)|'*', OC_REPLACE|NV|P(38)|'/', OC_REPLACE|NV|P(38)|'%', OC_REPLACE|NV|P(38)|'&',
|
||||
- OC_BINARY|NV|P(29)|'+', OC_BINARY|NV|P(29)|'-', OC_REPLACE|NV|P(38)|'&', OC_BINARY|NV|P(15)|'&',
|
||||
+#define TI_ASSIGN (OC_MOVE|VV|P(74))
|
||||
+ OC_COMPARE|VV|P(39)|5, TI_ASSIGN, OC_REPLACE|NV|P(74)|'+', OC_REPLACE|NV|P(74)|'-',
|
||||
+ OC_REPLACE|NV|P(74)|'*', OC_REPLACE|NV|P(74)|'/', OC_REPLACE|NV|P(74)|'%', OC_REPLACE|NV|P(74)|'&',
|
||||
+ OC_BINARY|NV|P(29)|'+', OC_BINARY|NV|P(29)|'-', OC_REPLACE|NV|P(74)|'&', OC_BINARY|NV|P(15)|'&',
|
||||
OC_BINARY|NV|P(25)|'/', OC_BINARY|NV|P(25)|'%', OC_BINARY|NV|P(15)|'&', OC_BINARY|NV|P(25)|'*',
|
||||
OC_COMPARE|VV|P(39)|4, OC_COMPARE|VV|P(39)|3, OC_COMPARE|VV|P(39)|0, OC_COMPARE|VV|P(39)|1,
|
||||
#define TI_LESS (OC_COMPARE|VV|P(39)|2)
|
||||
@@ -1376,11 +1377,19 @@ static node *parse_expr(uint32_t term_tc)
|
||||
continue;
|
||||
}
|
||||
if (tc & (TS_BINOP | TC_UOPPOST)) {
|
||||
+ int prio;
|
||||
debug_printf_parse("%s: TS_BINOP | TC_UOPPOST tc:%x\n", __func__, tc);
|
||||
/* for binary and postfix-unary operators, jump back over
|
||||
* previous operators with higher priority */
|
||||
vn = cn;
|
||||
- while (((t_info & PRIMASK) > (vn->a.n->info & PRIMASK2))
|
||||
+ /* Let assignment get higher priority when used on right
|
||||
+ * side in compare. i.e: 2==v=3 */
|
||||
+ if (t_info == TI_ASSIGN && (vn->a.n->info & OPCLSMASK) == OC_COMPARE) {
|
||||
+ prio = PRECEDENCE(38);
|
||||
+ } else {
|
||||
+ prio = (t_info & PRIMASK);
|
||||
+ }
|
||||
+ while ((prio > (vn->a.n->info & PRIMASK2))
|
||||
|| (t_info == vn->info && t_info == TI_COLON)
|
||||
) {
|
||||
vn = vn->a.n;
|
||||
@@ -1412,6 +1421,7 @@ static node *parse_expr(uint32_t term_tc)
|
||||
if ((vn->info & OPCLSMASK) != OC_VAR
|
||||
&& (vn->info & OPCLSMASK) != OC_FNARG
|
||||
&& (vn->info & OPCLSMASK) != OC_FIELD
|
||||
+ && (vn->info & OPCLSMASK) != OC_COMPARE
|
||||
) {
|
||||
syntax_error(EMSG_UNEXP_TOKEN); /* no. bad */
|
||||
}
|
||||
diff --git a/testsuite/awk.tests b/testsuite/awk.tests
|
||||
index a78fdcd98..d2706dea9 100755
|
||||
--- a/testsuite/awk.tests
|
||||
+++ b/testsuite/awk.tests
|
||||
@@ -540,9 +540,14 @@ testing 'awk assign while assign' \
|
||||
│ trim/eff : 57.02%/26, 0.00% │ [cpu000:100%]
|
||||
└────────────────────────────────────────────────────┘^C"
|
||||
|
||||
-testing "awk = has higher precedence than == (despite what gawk manpage claims)" \
|
||||
+testing "awk = has higher precedence than == on right side" \
|
||||
"awk 'BEGIN { v=1; print 2==v; print 2==v=2; print v; print v=3==3; print v}'" \
|
||||
- '0\n1\n2\n1\n3\n' \
|
||||
+ '0\n1\n2\n1\n1\n' \
|
||||
+ '' ''
|
||||
+
|
||||
+testing 'awk ternary precedence' \
|
||||
+ "awk 'BEGIN { a = 0 ? \"yes\": \"no\"; print a }'" \
|
||||
+ 'no\n' \
|
||||
'' ''
|
||||
|
||||
exit $FAILCOUNT
|
||||
--
|
||||
2.47.1
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
From 54e64812090f58cffca08fcf11d2dbc471c964e1 Mon Sep 17 00:00:00 2001
|
||||
From: Valery Ushakov <uwe@stderr.spb.ru>
|
||||
Date: Wed, 24 Jan 2024 22:24:41 +0300
|
||||
Subject: [PATCH] awk.c: fix CVE-2023-42366 (bug #15874)
|
||||
|
||||
Make sure we don't read past the end of the string in next_token()
|
||||
when backslash is the last character in an (invalid) regexp.
|
||||
a fix and issue reported in bugzilla
|
||||
|
||||
https://bugs.busybox.net/show_bug.cgi?id=15874
|
||||
|
||||
Upstream-Status: Submitted [http://lists.busybox.net/pipermail/busybox/2024-May/090766.html]
|
||||
|
||||
CVE: CVE-2023-42366
|
||||
Signed-off-by: Khem Raj <raj.khem@gmail.com>
|
||||
[Thomas: https://git.openembedded.org/openembedded-core/tree/meta/recipes-core/busybox/busybox/0001-awk.c-fix-CVE-2023-42366-bug-15874.patch?id=e0ff4813b1cf4df0d851c857d57fb88d7db51bdd]
|
||||
Upstream: http://lists.busybox.net/pipermail/busybox/2024-May/090766.html
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
editors/awk.c | 6 ++++--
|
||||
1 file changed, 4 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/editors/awk.c b/editors/awk.c
|
||||
index 9467f4644..947195333 100644
|
||||
--- a/editors/awk.c
|
||||
+++ b/editors/awk.c
|
||||
@@ -1168,9 +1168,11 @@ static uint32_t next_token(uint32_t expected)
|
||||
s[-1] = bb_process_escape_sequence((const char **)&pp);
|
||||
if (*p == '\\')
|
||||
*s++ = '\\';
|
||||
- if (pp == p)
|
||||
+ if (pp == p) {
|
||||
+ if (*p == '\0')
|
||||
+ syntax_error(EMSG_UNEXP_EOS);
|
||||
*s++ = *p++;
|
||||
- else
|
||||
+ } else
|
||||
p = pp;
|
||||
}
|
||||
}
|
||||
--
|
||||
2.47.1
|
||||
|
||||
@@ -0,0 +1,54 @@
|
||||
From a378cd9c3a022500d7feaefb4e3bb43fdd789131 Mon Sep 17 00:00:00 2001
|
||||
From: Khem Raj <raj.khem@gmail.com>
|
||||
Date: Sun, 7 Mar 2021 17:30:24 -0800
|
||||
Subject: [PATCH] hwclock: Check for SYS_settimeofday before calling syscall
|
||||
|
||||
Some newer architectures e.g. RISCV32 have 64bit time_t from get go and
|
||||
thusly do not have gettimeofday_time64/settimeofday_time64 implemented
|
||||
therefore check for SYS_settimeofday definition before making the
|
||||
syscall. Fixes build for riscv32 and it will bail out at runtime.
|
||||
|
||||
Upstream-Status: Submitted [http://lists.busybox.net/pipermail/busybox/2021-March/088583.html]
|
||||
Signed-off-by: Khem Raj <raj.khem@gmail.com>
|
||||
Upstream: http://lists.busybox.net/pipermail/busybox/2021-March/088583.html
|
||||
[Thomas: this issue has been discussed on the musl mailing list, and
|
||||
the musl developers' opinion is that Busybox is wrong:
|
||||
https://www.openwall.com/lists/musl/2024/03/03/2
|
||||
https://www.openwall.com/lists/musl/2024/04/07/2. The correct fix
|
||||
isn't clear, and in the mean time, the patch from Khem turns the build
|
||||
issue into a runtime error only on the problematic architecture, which
|
||||
seems like a reasonable trade-off]
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
util-linux/hwclock.c | 7 +++++--
|
||||
1 file changed, 5 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/util-linux/hwclock.c b/util-linux/hwclock.c
|
||||
index 723b09589..b9faaabbc 100644
|
||||
--- a/util-linux/hwclock.c
|
||||
+++ b/util-linux/hwclock.c
|
||||
@@ -131,6 +131,7 @@ static void show_clock(const char **pp_rtcname, int utc)
|
||||
|
||||
static void set_kernel_tz(const struct timezone *tz)
|
||||
{
|
||||
+ int ret = 1;
|
||||
#if LIBC_IS_MUSL
|
||||
/* musl libc does not pass tz argument to syscall
|
||||
* because "it's deprecated by POSIX, therefore it's fine
|
||||
@@ -139,9 +140,11 @@ static void set_kernel_tz(const struct timezone *tz)
|
||||
#if !defined(SYS_settimeofday) && defined(SYS_settimeofday_time32)
|
||||
# define SYS_settimeofday SYS_settimeofday_time32
|
||||
#endif
|
||||
- int ret = syscall(SYS_settimeofday, NULL, tz);
|
||||
+#if defined(SYS_settimeofday)
|
||||
+ ret = syscall(SYS_settimeofday, NULL, tz);
|
||||
+#endif
|
||||
#else
|
||||
- int ret = settimeofday(NULL, tz);
|
||||
+ ret = settimeofday(NULL, tz);
|
||||
#endif
|
||||
if (ret)
|
||||
bb_simple_perror_msg_and_die("settimeofday");
|
||||
--
|
||||
2.48.1
|
||||
|
||||
@@ -15,6 +15,16 @@ BUSYBOX_CPE_ID_VENDOR = busybox
|
||||
# 0004-nslookup-sanitize-all-printed-strings-with-printable.patch
|
||||
BUSYBOX_IGNORE_CVES += CVE-2022-28391
|
||||
|
||||
# 0012-awk-fix-use-after-free-CVE-2023-42363.patch
|
||||
BUSYBOX_IGNORE_CVES += CVE-2023-42363
|
||||
|
||||
# 0013-awk-fix-precedence-of-relative-to.patch
|
||||
# 0014-awk-fix-ternary-operator-and-precedence-of.patch
|
||||
BUSYBOX_IGNORE_CVES += CVE-2023-42364 CVE-2023-42365
|
||||
|
||||
# 0015-awk.c-fix-CVE-2023-42366-bug-15874.patch
|
||||
BUSYBOX_IGNORE_CVES += CVE-2023-42366
|
||||
|
||||
BUSYBOX_CFLAGS = \
|
||||
$(TARGET_CFLAGS)
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
# Locally calculated
|
||||
sha256 f4d67240a8b2e882e18f864529040084617de066cdab9b7684951ace6ea6f3cf clamav-1.0.7.tar.gz
|
||||
sha256 4783f2ab3fc323a887c117c672dc0b4e7ace72d76f8c06e990bd49c3ef58f10a clamav-1.0.8.tar.gz
|
||||
sha256 0c4fd2fa9733fc9122503797648710851e4ee6d9e4969dd33fcbd8c63cd2f584 COPYING.txt
|
||||
sha256 d72a145c90918184a05ef65a04c9e6f7466faa59bc1b82c8f6a8ddc7ddcb9bed COPYING/COPYING.bzip2
|
||||
sha256 dfb818a0d41411c6fb1c193c68b73018ceadd1994bda41ad541cbff292894bc6 COPYING/COPYING.file
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
CLAMAV_VERSION = 1.0.7
|
||||
CLAMAV_VERSION = 1.0.8
|
||||
CLAMAV_SITE = https://www.clamav.net/downloads/production
|
||||
CLAMAV_LICENSE = GPL-2.0
|
||||
CLAMAV_LICENSE_FILES = \
|
||||
|
||||
27
package/curlpp/0001-fix-invalid-conversion.patch
Normal file
27
package/curlpp/0001-fix-invalid-conversion.patch
Normal file
@@ -0,0 +1,27 @@
|
||||
From b945d57a5acd12bda320a63eb9e45bbb7586cdde Mon Sep 17 00:00:00 2001
|
||||
From: Aaron Smith <aaron@soccergeek.net>
|
||||
Date: Mon, 16 Dec 2024 11:48:33 -0800
|
||||
Subject: [PATCH] Fix "invalid conversion from 'int' to 'CURLoption'" error
|
||||
|
||||
Use cast to 'Curloption' to fix compiler error regarding invalid conversion from 'int' to 'CURLoption'.
|
||||
|
||||
Upstream: https://github.com/jpbarrette/curlpp/pull/178
|
||||
Signed-off-by: Thomas Bonnefille <thomas.bonnefille@bootlin.com>
|
||||
---
|
||||
include/curlpp/Options.hpp | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/include/curlpp/Options.hpp b/include/curlpp/Options.hpp
|
||||
index 40b64ed..292eaa7 100644
|
||||
--- a/include/curlpp/Options.hpp
|
||||
+++ b/include/curlpp/Options.hpp
|
||||
@@ -308,7 +308,7 @@ namespace options
|
||||
typedef curlpp::OptionTrait<long, CURLOPT_LOW_SPEED_LIMIT> LowSpeedLimit;
|
||||
typedef curlpp::OptionTrait<long, CURLOPT_LOW_SPEED_TIME> LowSpeedTime;
|
||||
typedef curlpp::OptionTrait<long, CURLOPT_MAXCONNECTS> MaxConnects;
|
||||
- typedef curlpp::OptionTrait<curl_closepolicy, CURLOPT_CLOSEPOLICY> ClosePolicy;
|
||||
+ typedef curlpp::OptionTrait<curl_closepolicy, (CURLoption)CURLOPT_CLOSEPOLICY> ClosePolicy;
|
||||
typedef curlpp::OptionTrait<bool, CURLOPT_FRESH_CONNECT> FreshConnect;
|
||||
typedef curlpp::OptionTrait<bool, CURLOPT_FORBID_REUSE> ForbidReuse;
|
||||
typedef curlpp::OptionTrait<long, CURLOPT_CONNECTTIMEOUT> ConnectTimeout;
|
||||
|
||||
@@ -12,7 +12,7 @@ config BR2_PACKAGE_DILLO
|
||||
|
||||
Enable openssl package to gain https support.
|
||||
|
||||
http://www.dillo.org
|
||||
https://dillo-browser.github.io/
|
||||
|
||||
comment "dillo needs a toolchain w/ C++"
|
||||
depends on BR2_PACKAGE_XORG7 && BR2_USE_MMU
|
||||
|
||||
@@ -6,7 +6,7 @@
|
||||
|
||||
DILLO_VERSION = 3.0.5
|
||||
DILLO_SOURCE = dillo-$(DILLO_VERSION).tar.bz2
|
||||
DILLO_SITE = http://www.dillo.org/download
|
||||
DILLO_SITE = https://github.com/dillo-browser/dillo/releases/download/v$(DILLO_VERSION)/
|
||||
DILLO_LICENSE = GPL-3.0+
|
||||
DILLO_LICENSE_FILES = COPYING
|
||||
# configure.ac gets patched, so autoreconf is necessary
|
||||
|
||||
@@ -12,7 +12,7 @@ ELFUTILS_LICENSE = GPL-2.0+ or LGPL-3.0+ (library)
|
||||
ELFUTILS_LICENSE_FILES = COPYING COPYING-GPLV2 COPYING-LGPLV3
|
||||
ELFUTILS_CPE_ID_VALID = YES
|
||||
ELFUTILS_DEPENDENCIES = host-pkgconf zlib $(TARGET_NLS_DEPENDENCIES)
|
||||
HOST_ELFUTILS_DEPENDENCIES = host-pkgconf host-zlib host-bzip2 host-xz
|
||||
HOST_ELFUTILS_DEPENDENCIES = host-pkgconf host-zlib host-bzip2 host-xz host-zstd
|
||||
|
||||
# We patch configure.ac
|
||||
ELFUTILS_AUTORECONF = YES
|
||||
@@ -26,7 +26,7 @@ ELFUTILS_CONF_OPTS += \
|
||||
HOST_ELFUTILS_CONF_OPTS = \
|
||||
--with-bzlib \
|
||||
--with-lzma \
|
||||
--without-zstd \
|
||||
--with-zstd \
|
||||
--disable-demangler \
|
||||
--disable-progs
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# From https://ftp.exim.org/pub/exim/exim4/00-sha256sums.txt
|
||||
sha256 0ebc108a779f9293ba4b423c20818f9a3db79b60286d96abc6ba6b85a15852f7 exim-4.98.tar.xz
|
||||
sha256 d858b75ad2cc6bf71c9071ba26a55b3ea9add26607bd832df3cb54f82221c2ce exim-4.98.1.tar.xz
|
||||
# From https://ftp.exim.org/pub/exim/exim4/00-sha512sums.txt
|
||||
sha512 13dd963dd0899bb4d64bee44c20883e720e469a4d77456b877d6693cfc4419805a045cb561508cdf763dbb37cc84fbdc6177d68acc2183934c3224fbd03caf15 exim-4.98.tar.xz
|
||||
sha512 8f80999a41ed40e86ee16eea5cfd765e2f164ea149f40eeb410fd02fcf35c23317dc69540efe336e9e0fae930b1cc6771e0180dd70f1314531cdb139740c744e exim-4.98.1.tar.xz
|
||||
# Locally calculated
|
||||
sha256 49240db527b7e55b312a46fc59794fde5dd006422e422257f4f057bfd27b3c8f LICENCE
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
EXIM_VERSION = 4.98
|
||||
EXIM_VERSION = 4.98.1
|
||||
EXIM_SOURCE = exim-$(EXIM_VERSION).tar.xz
|
||||
EXIM_SITE = https://ftp.exim.org/pub/exim/exim4
|
||||
EXIM_LICENSE = GPL-2.0+
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
# Locally calculated
|
||||
sha256 a695629dae047055b37d50a0ff4776d1d45d0a4c842cf4ccee158441f55ff7ee expat-2.6.4.tar.xz
|
||||
sha256 25df13dd2819e85fb27a1ce0431772b7047d72af81ae78dc26b4c6e0805f48d1 expat-2.7.0.tar.xz
|
||||
sha256 122f2c27000472a201d337b9b31f7eb2b52d091b02857061a8880371612d9534 COPYING
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
EXPAT_VERSION = 2.6.4
|
||||
EXPAT_VERSION = 2.7.0
|
||||
EXPAT_SITE = https://github.com/libexpat/libexpat/releases/download/R_$(subst .,_,$(EXPAT_VERSION))
|
||||
EXPAT_SOURCE = expat-$(EXPAT_VERSION).tar.xz
|
||||
EXPAT_INSTALL_STAGING = YES
|
||||
|
||||
@@ -390,6 +390,13 @@ else
|
||||
FFMPEG_CONF_OPTS += --disable-iconv
|
||||
endif
|
||||
|
||||
ifeq ($(BR2_PACKAGE_LIBXML2),y)
|
||||
FFMPEG_CONF_OPTS += --enable-libxml2
|
||||
FFMPEG_DEPENDENCIES += libxml2
|
||||
else
|
||||
FFMPEG_CONF_OPTS += --disable-libxml2
|
||||
endif
|
||||
|
||||
# ffmpeg freetype support require fenv.h which is only
|
||||
# available/working on glibc.
|
||||
# The microblaze variant doesn't provide the needed exceptions
|
||||
@@ -407,6 +414,13 @@ else
|
||||
FFMPEG_CONF_OPTS += --disable-fontconfig
|
||||
endif
|
||||
|
||||
ifeq ($(BR2_PACKAGE_LIBFRIBIDI),y)
|
||||
FFMPEG_CONF_OPTS += --enable-libfribidi
|
||||
FFMPEG_DEPENDENCIES += libfribidi
|
||||
else
|
||||
FFMPEG_CONF_OPTS += --disable-libfribidi
|
||||
endif
|
||||
|
||||
ifeq ($(BR2_PACKAGE_OPENJPEG),y)
|
||||
FFMPEG_CONF_OPTS += --enable-libopenjpeg
|
||||
FFMPEG_DEPENDENCIES += openjpeg
|
||||
|
||||
@@ -16,7 +16,10 @@ FIO_DEPENDENCIES += libaio
|
||||
endif
|
||||
|
||||
ifeq ($(BR2_PACKAGE_LIBNFS),y)
|
||||
FIO_DEPENDENCIES += libnfs
|
||||
FIO_OPTS += --enable-libnfs
|
||||
FIO_DEPENDENCIES += host-pkgconf libnfs
|
||||
else
|
||||
FIO_OPTS += --disable-libnfs
|
||||
endif
|
||||
|
||||
ifeq ($(BR2_PACKAGE_LIBISCSI),y)
|
||||
|
||||
@@ -0,0 +1,42 @@
|
||||
From 9443ac7e2937bb4f26cf44c73bb8150860c5df45 Mon Sep 17 00:00:00 2001
|
||||
From: Thomas Bonnefille <thomas.bonnefille@bootlin.com>
|
||||
Date: Tue, 4 Feb 2025 09:48:13 +0100
|
||||
Subject: [PATCH] box-drawings: handle architecture with soft-float
|
||||
|
||||
Currently, architecture using soft-floats doesn't support instructions
|
||||
FE_INVALID, FE_DIVBYZERO, FE_OVERFLOW and FE_UNDERFLOW and so building
|
||||
on those architectures results with a build error.
|
||||
As the sqrt math function should set errno to EDOM if an error occurs,
|
||||
fetestexcept shouldn't be mandatory.
|
||||
|
||||
This commit removes the float environment error handling.
|
||||
|
||||
Upstream: https://codeberg.org/dnkl/foot/commit/9443ac7e2937bb4f26cf44c73bb8150860c5df45
|
||||
Signed-off-by: Thomas Bonnefille <thomas.bonnefille@bootlin.com>
|
||||
---
|
||||
box-drawing.c | 4 +---
|
||||
1 file changed, 1 insertion(+), 3 deletions(-)
|
||||
|
||||
diff --git a/box-drawing.c b/box-drawing.c
|
||||
index 1c613051..421ff54d 100644
|
||||
--- a/box-drawing.c
|
||||
+++ b/box-drawing.c
|
||||
@@ -1462,14 +1462,12 @@ draw_box_drawings_light_arc(struct buf *buf, char32_t wc)
|
||||
*/
|
||||
for (double i = y_min*16; i <= y_max*16; i++) {
|
||||
errno = 0;
|
||||
- feclearexcept(FE_ALL_EXCEPT);
|
||||
|
||||
double y = i / 16.;
|
||||
double x = circle_hemisphere * sqrt(c_r2 - (y - c_y) * (y - c_y)) + c_x;
|
||||
|
||||
/* See math_error(7) */
|
||||
- if (errno != 0 ||
|
||||
- fetestexcept(FE_INVALID | FE_DIVBYZERO | FE_OVERFLOW | FE_UNDERFLOW))
|
||||
+ if (errno != 0)
|
||||
{
|
||||
continue;
|
||||
}
|
||||
--
|
||||
2.48.1
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
# Locally computed
|
||||
sha256 ff81bca86178ef326588176f8bdf817bb3e0fbc891d026960144f69c8a74eb4d foot-1.16.2-git4.tar.gz
|
||||
sha256 af299b149fbb08cf2253cb9130240b42ed1a638f2d50d6239f386b03eef78835 foot-1.16.2-br1.tar.gz
|
||||
sha256 d534a23a31500a0ac958d9634b84f532bd73ff1aca1bb8f7debbcbebc16ff39a LICENSE
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# From https://sourceforge.net/projects/freetype/files/freetype2/2.13.2/
|
||||
sha1 2d8d5917a1983ebd04921f2993a88858d6f72dec freetype-2.13.2.tar.xz
|
||||
sha256 12991c4e55c506dd7f9b765933e62fd2be2e06d421505d7950a132e4f1bb484d freetype-2.13.2.tar.xz
|
||||
# From https://sourceforge.net/projects/freetype/files/freetype2/2.13.3/
|
||||
sha1 2437819d11c1205e81141735dcb0a36c0d541e96 freetype-2.13.3.tar.xz
|
||||
sha256 0550350666d427c74daeb85d5ac7bb353acba5f76956395995311a9c6f063289 freetype-2.13.3.tar.xz
|
||||
|
||||
# Locally calculated
|
||||
sha256 2e3bbb7d7c5c396368dd0853a790ec29ce5b8647163dde42a0493fb0d6556b2b LICENSE.TXT
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
FREETYPE_VERSION = 2.13.2
|
||||
FREETYPE_VERSION = 2.13.3
|
||||
FREETYPE_SOURCE = freetype-$(FREETYPE_VERSION).tar.xz
|
||||
FREETYPE_SITE = http://download.savannah.gnu.org/releases/freetype
|
||||
FREETYPE_INSTALL_STAGING = YES
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
# From: https://www.kernel.org/pub/software/scm/git/sha256sums.asc
|
||||
sha256 8b7cc3db84c5c6a2eeb39c63686ff5cde26278e32bb0d2226a8b424488420b98 git-2.43.5.tar.xz
|
||||
sha256 25f329439ebcc8a6fe160a5600499f6a179c784d8efa4d50d54e5d77a4d13a62 git-2.43.6.tar.xz
|
||||
# Locally calculated
|
||||
sha256 5b2198d1645f767585e8a88ac0499b04472164c0d2da22e75ecf97ef443ab32e COPYING
|
||||
sha256 1922f45d2c49e390032c9c0ba6d7cac904087f7cec51af30c2b2ad022ce0e76a LGPL-2.1
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
GIT_VERSION = 2.43.5
|
||||
GIT_VERSION = 2.43.6
|
||||
GIT_SOURCE = git-$(GIT_VERSION).tar.xz
|
||||
GIT_SITE = $(BR2_KERNEL_MIRROR)/software/scm/git
|
||||
GIT_LICENSE = GPL-2.0, LGPL-2.1+
|
||||
|
||||
@@ -1,798 +0,0 @@
|
||||
From 5ed597eb28c408c5968e6dfb839880ba5fa17ba1 Mon Sep 17 00:00:00 2001
|
||||
From: Daiki Ueno <ueno@gnu.org>
|
||||
Date: Fri, 6 Dec 2024 09:53:18 +0900
|
||||
Subject: [PATCH] groups: represent hybrid groups with an array of IDs
|
||||
|
||||
Previously, the supported_groups array contained externally defined
|
||||
elements, which is legitimate in C99 but caused error with Clang:
|
||||
|
||||
groups.c:93:2: error: initializer element is not a compile-time constant
|
||||
group_x25519,
|
||||
^~~~~~~~~~~~
|
||||
|
||||
This reworks the array definition of indirection through group
|
||||
IDs (gnutls_group_t, i.e., integer).
|
||||
|
||||
This also makes pqc-hybrid-kx test more exhaustive.
|
||||
|
||||
Signed-off-by: Daiki Ueno <ueno@gnu.org>
|
||||
Upstream: https://gitlab.com/gnutls/gnutls/-/commit/9cc9d5556d258d23a399abfe45715773e719d134
|
||||
Signed-off-by: Brandon Maier <brandon.maier@collins.com>
|
||||
---
|
||||
lib/algorithms.h | 7 ++
|
||||
lib/algorithms/groups.c | 161 ++++++++++++++++++++------------
|
||||
lib/ext/key_share.c | 81 ++++++++++++----
|
||||
lib/ext/supported_groups.c | 45 +++++----
|
||||
lib/gnutls_int.h | 8 +-
|
||||
lib/includes/gnutls/gnutls.h.in | 4 +-
|
||||
lib/priority.c | 25 ++---
|
||||
lib/session.c | 6 +-
|
||||
tests/pqc-hybrid-kx.sh | 101 +++++++++++++++++---
|
||||
9 files changed, 315 insertions(+), 123 deletions(-)
|
||||
|
||||
diff --git a/lib/algorithms.h b/lib/algorithms.h
|
||||
index 2e1b694c6..c4af571ce 100644
|
||||
--- a/lib/algorithms.h
|
||||
+++ b/lib/algorithms.h
|
||||
@@ -55,6 +55,9 @@
|
||||
#define IS_KEM(x) \
|
||||
(((x) == GNUTLS_PK_MLKEM768) || ((x) == GNUTLS_PK_EXP_KYBER768))
|
||||
|
||||
+
|
||||
+#define IS_GROUP_HYBRID(group) ((group)->ids[0] != GNUTLS_GROUP_INVALID)
|
||||
+
|
||||
#define SIG_SEM_PRE_TLS12 (1 << 1)
|
||||
#define SIG_SEM_TLS13 (1 << 2)
|
||||
#define SIG_SEM_DEFAULT (SIG_SEM_PRE_TLS12 | SIG_SEM_TLS13)
|
||||
@@ -493,6 +496,10 @@ const gnutls_group_entry_st *_gnutls_tls_id_to_group(unsigned num);
|
||||
const gnutls_group_entry_st *_gnutls_id_to_group(unsigned id);
|
||||
gnutls_group_t _gnutls_group_get_id(const char *name);
|
||||
|
||||
+int _gnutls_group_expand(
|
||||
+ const gnutls_group_entry_st *group,
|
||||
+ const gnutls_group_entry_st *subgroups[MAX_HYBRID_GROUPS + 1]);
|
||||
+
|
||||
gnutls_ecc_curve_t _gnutls_ecc_bits_to_curve(gnutls_pk_algorithm_t pk,
|
||||
int bits);
|
||||
#define MAX_ECC_CURVE_SIZE 66
|
||||
diff --git a/lib/algorithms/groups.c b/lib/algorithms/groups.c
|
||||
index 88d0cf630..2fbe7b8ec 100644
|
||||
--- a/lib/algorithms/groups.c
|
||||
+++ b/lib/algorithms/groups.c
|
||||
@@ -30,30 +30,6 @@
|
||||
/* Supported ECC curves
|
||||
*/
|
||||
|
||||
-#ifdef HAVE_LIBOQS
|
||||
-static const gnutls_group_entry_st group_mlkem768 = {
|
||||
- .name = "MLKEM768",
|
||||
- .id = GNUTLS_GROUP_INVALID,
|
||||
- .curve = GNUTLS_ECC_CURVE_INVALID,
|
||||
- .pk = GNUTLS_PK_MLKEM768,
|
||||
-};
|
||||
-
|
||||
-static const gnutls_group_entry_st group_kyber768 = {
|
||||
- .name = "KYBER768",
|
||||
- .id = GNUTLS_GROUP_INVALID,
|
||||
- .curve = GNUTLS_ECC_CURVE_INVALID,
|
||||
- .pk = GNUTLS_PK_EXP_KYBER768,
|
||||
-};
|
||||
-#endif
|
||||
-
|
||||
-static const gnutls_group_entry_st group_x25519 = {
|
||||
- .name = "X25519",
|
||||
- .id = GNUTLS_GROUP_X25519,
|
||||
- .curve = GNUTLS_ECC_CURVE_X25519,
|
||||
- .tls_id = 29,
|
||||
- .pk = GNUTLS_PK_ECDH_X25519,
|
||||
-};
|
||||
-
|
||||
static const gnutls_group_entry_st supported_groups[] = {
|
||||
{
|
||||
.name = "SECP192R1",
|
||||
@@ -90,7 +66,13 @@ static const gnutls_group_entry_st supported_groups[] = {
|
||||
.tls_id = 25,
|
||||
.pk = GNUTLS_PK_ECDSA,
|
||||
},
|
||||
- group_x25519,
|
||||
+ {
|
||||
+ .name = "X25519",
|
||||
+ .id = GNUTLS_GROUP_X25519,
|
||||
+ .curve = GNUTLS_ECC_CURVE_X25519,
|
||||
+ .tls_id = 29,
|
||||
+ .pk = GNUTLS_PK_ECDH_X25519,
|
||||
+ },
|
||||
#ifdef ENABLE_GOST
|
||||
/* draft-smyshlyaev-tls12-gost-suites-06, Section 6 */
|
||||
{
|
||||
@@ -191,24 +173,33 @@ static const gnutls_group_entry_st supported_groups[] = {
|
||||
.tls_id = 0x104 },
|
||||
#endif
|
||||
#ifdef HAVE_LIBOQS
|
||||
+ {
|
||||
+ .name = "MLKEM768",
|
||||
+ .id = GNUTLS_GROUP_EXP_MLKEM768,
|
||||
+ .pk = GNUTLS_PK_MLKEM768,
|
||||
+ /* absense of .tls_id means that this group alone cannot be used in TLS */
|
||||
+ },
|
||||
+ {
|
||||
+ .name = "KYBER768",
|
||||
+ .id = GNUTLS_GROUP_EXP_KYBER768,
|
||||
+ .pk = GNUTLS_PK_EXP_KYBER768,
|
||||
+ /* absense of .tls_id means that this group alone cannot be used in TLS */
|
||||
+ },
|
||||
{ .name = "SECP256R1-MLKEM768",
|
||||
.id = GNUTLS_GROUP_EXP_SECP256R1_MLKEM768,
|
||||
- .curve = GNUTLS_ECC_CURVE_SECP256R1,
|
||||
- .pk = GNUTLS_PK_ECDSA,
|
||||
- .tls_id = 0x11EB,
|
||||
- .next = &group_mlkem768 },
|
||||
+ .ids = { GNUTLS_GROUP_SECP256R1, GNUTLS_GROUP_EXP_MLKEM768,
|
||||
+ GNUTLS_GROUP_INVALID },
|
||||
+ .tls_id = 0x11EB },
|
||||
{ .name = "X25519-MLKEM768",
|
||||
.id = GNUTLS_GROUP_EXP_X25519_MLKEM768,
|
||||
- .curve = GNUTLS_ECC_CURVE_INVALID,
|
||||
- .pk = GNUTLS_PK_MLKEM768,
|
||||
- .tls_id = 0x11EC,
|
||||
- .next = &group_x25519 },
|
||||
+ .ids = { GNUTLS_GROUP_EXP_MLKEM768, GNUTLS_GROUP_X25519,
|
||||
+ GNUTLS_GROUP_INVALID },
|
||||
+ .tls_id = 0x11EC },
|
||||
{ .name = "X25519-KYBER768",
|
||||
.id = GNUTLS_GROUP_EXP_X25519_KYBER768,
|
||||
- .curve = GNUTLS_ECC_CURVE_X25519,
|
||||
- .pk = GNUTLS_PK_ECDH_X25519,
|
||||
- .tls_id = 0x6399,
|
||||
- .next = &group_kyber768 },
|
||||
+ .ids = { GNUTLS_GROUP_X25519, GNUTLS_GROUP_EXP_KYBER768,
|
||||
+ GNUTLS_GROUP_INVALID },
|
||||
+ .tls_id = 0x6399 },
|
||||
#endif
|
||||
{ 0, 0, 0 }
|
||||
};
|
||||
@@ -221,14 +212,46 @@ static const gnutls_group_entry_st supported_groups[] = {
|
||||
} \
|
||||
}
|
||||
|
||||
+static inline const gnutls_group_entry_st *group_to_entry(gnutls_group_t group)
|
||||
+{
|
||||
+ if (group == 0)
|
||||
+ return NULL;
|
||||
+
|
||||
+ GNUTLS_GROUP_LOOP(if (p->id == group) { return p; });
|
||||
+
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
+static inline bool
|
||||
+group_is_supported_standalone(const gnutls_group_entry_st *group)
|
||||
+{
|
||||
+ return group->pk != 0 && _gnutls_pk_exists(group->pk) &&
|
||||
+ (group->curve == 0 ||
|
||||
+ _gnutls_ecc_curve_is_supported(group->curve));
|
||||
+}
|
||||
+
|
||||
+static inline bool group_is_supported(const gnutls_group_entry_st *group)
|
||||
+{
|
||||
+ if (!IS_GROUP_HYBRID(group))
|
||||
+ return group_is_supported_standalone(group);
|
||||
+
|
||||
+ for (size_t i = 0;
|
||||
+ i < MAX_HYBRID_GROUPS && group->ids[i] != GNUTLS_GROUP_INVALID;
|
||||
+ i++) {
|
||||
+ const gnutls_group_entry_st *p = group_to_entry(group->ids[i]);
|
||||
+ if (!p || !group_is_supported_standalone(p))
|
||||
+ return false;
|
||||
+ }
|
||||
+
|
||||
+ return true;
|
||||
+}
|
||||
+
|
||||
/* Returns the TLS id of the given curve
|
||||
*/
|
||||
const gnutls_group_entry_st *_gnutls_tls_id_to_group(unsigned num)
|
||||
{
|
||||
GNUTLS_GROUP_LOOP(
|
||||
- if (p->tls_id == num &&
|
||||
- (p->curve == 0 ||
|
||||
- _gnutls_ecc_curve_is_supported(p->curve))) { return p; });
|
||||
+ if (p->tls_id == num && group_is_supported(p)) { return p; });
|
||||
|
||||
return NULL;
|
||||
}
|
||||
@@ -239,10 +262,7 @@ const gnutls_group_entry_st *_gnutls_id_to_group(unsigned id)
|
||||
return NULL;
|
||||
|
||||
GNUTLS_GROUP_LOOP(
|
||||
- if (p->id == id && (p->curve == 0 ||
|
||||
- _gnutls_ecc_curve_is_supported(p->curve))) {
|
||||
- return p;
|
||||
- });
|
||||
+ if (p->id == id && group_is_supported(p)) { return p; });
|
||||
|
||||
return NULL;
|
||||
}
|
||||
@@ -261,27 +281,17 @@ const gnutls_group_entry_st *_gnutls_id_to_group(unsigned id)
|
||||
**/
|
||||
const gnutls_group_t *gnutls_group_list(void)
|
||||
{
|
||||
- static gnutls_group_t groups[MAX_ALGOS] = { 0 };
|
||||
+ static gnutls_group_t groups[MAX_ALGOS + 1] = { 0 };
|
||||
|
||||
if (groups[0] == 0) {
|
||||
- int i = 0;
|
||||
+ size_t i = 0;
|
||||
|
||||
- const gnutls_group_entry_st *p;
|
||||
-
|
||||
- for (p = supported_groups; p->name != NULL; p++) {
|
||||
- const gnutls_group_entry_st *pp;
|
||||
-
|
||||
- for (pp = p; pp != NULL; pp = pp->next) {
|
||||
- if ((pp->curve != 0 &&
|
||||
- !_gnutls_ecc_curve_is_supported(
|
||||
- pp->curve)) ||
|
||||
- (pp->pk != 0 && !_gnutls_pk_exists(pp->pk)))
|
||||
- break;
|
||||
- }
|
||||
- if (pp == NULL)
|
||||
+ for (const gnutls_group_entry_st *p = supported_groups;
|
||||
+ p->name != NULL; p++) {
|
||||
+ if (group_is_supported(p))
|
||||
groups[i++] = p->id;
|
||||
}
|
||||
- groups[i++] = 0;
|
||||
+ groups[i++] = GNUTLS_GROUP_INVALID;
|
||||
}
|
||||
|
||||
return groups;
|
||||
@@ -344,3 +354,34 @@ const char *gnutls_group_get_name(gnutls_group_t group)
|
||||
|
||||
return NULL;
|
||||
}
|
||||
+
|
||||
+/* Expand GROUP into hybrid SUBGROUPS if any, otherwise an array
|
||||
+ * containing the GROUP itself. The result will be written to
|
||||
+ * SUBGROUPS, which will be NUL-terminated.
|
||||
+ */
|
||||
+int _gnutls_group_expand(
|
||||
+ const gnutls_group_entry_st *group,
|
||||
+ const gnutls_group_entry_st *subgroups[MAX_HYBRID_GROUPS + 1])
|
||||
+{
|
||||
+ size_t pos = 0;
|
||||
+
|
||||
+ if (IS_GROUP_HYBRID(group)) {
|
||||
+ for (size_t i = 0; i < MAX_HYBRID_GROUPS &&
|
||||
+ group->ids[i] != GNUTLS_GROUP_INVALID;
|
||||
+ i++) {
|
||||
+ const gnutls_group_entry_st *p =
|
||||
+ group_to_entry(group->ids[i]);
|
||||
+ /* This shouldn't happen, as GROUP is assumed
|
||||
+ * to be supported before calling this
|
||||
+ * function. */
|
||||
+ if (unlikely(!p))
|
||||
+ return gnutls_assert_val(
|
||||
+ GNUTLS_E_INTERNAL_ERROR);
|
||||
+ subgroups[pos++] = p;
|
||||
+ }
|
||||
+ } else {
|
||||
+ subgroups[pos++] = group;
|
||||
+ }
|
||||
+ subgroups[pos] = NULL;
|
||||
+ return 0;
|
||||
+}
|
||||
diff --git a/lib/ext/key_share.c b/lib/ext/key_share.c
|
||||
index 574521157..8fbe2d2bd 100644
|
||||
--- a/lib/ext/key_share.c
|
||||
+++ b/lib/ext/key_share.c
|
||||
@@ -232,6 +232,9 @@ static int client_gen_key_share(gnutls_session_t session,
|
||||
gnutls_buffer_st *extdata)
|
||||
{
|
||||
unsigned int length_pos;
|
||||
+ const gnutls_group_entry_st *groups[MAX_HYBRID_GROUPS + 1] = {
|
||||
+ NULL,
|
||||
+ };
|
||||
int ret;
|
||||
|
||||
_gnutls_handshake_log("EXT[%p]: sending key share for %s\n", session,
|
||||
@@ -247,8 +250,12 @@ static int client_gen_key_share(gnutls_session_t session,
|
||||
if (ret < 0)
|
||||
return gnutls_assert_val(ret);
|
||||
|
||||
- for (const gnutls_group_entry_st *p = group; p != NULL; p = p->next) {
|
||||
- ret = client_gen_key_share_single(session, p, extdata);
|
||||
+ ret = _gnutls_group_expand(group, groups);
|
||||
+ if (ret < 0)
|
||||
+ return gnutls_assert_val(ret);
|
||||
+
|
||||
+ for (size_t i = 0; groups[i]; i++) {
|
||||
+ ret = client_gen_key_share_single(session, groups[i], extdata);
|
||||
if (ret < 0)
|
||||
return gnutls_assert_val(ret);
|
||||
}
|
||||
@@ -345,6 +352,9 @@ static int server_gen_key_share(gnutls_session_t session,
|
||||
gnutls_buffer_st *extdata)
|
||||
{
|
||||
unsigned int length_pos;
|
||||
+ const gnutls_group_entry_st *groups[MAX_HYBRID_GROUPS + 1] = {
|
||||
+ NULL,
|
||||
+ };
|
||||
int ret;
|
||||
|
||||
_gnutls_handshake_log("EXT[%p]: sending key share for %s\n", session,
|
||||
@@ -360,8 +370,12 @@ static int server_gen_key_share(gnutls_session_t session,
|
||||
if (ret < 0)
|
||||
return gnutls_assert_val(ret);
|
||||
|
||||
- for (const gnutls_group_entry_st *p = group; p != NULL; p = p->next) {
|
||||
- ret = server_gen_key_share_single(session, p, extdata);
|
||||
+ ret = _gnutls_group_expand(group, groups);
|
||||
+ if (ret < 0)
|
||||
+ return gnutls_assert_val(ret);
|
||||
+
|
||||
+ for (size_t i = 0; groups[i]; i++) {
|
||||
+ ret = server_gen_key_share_single(session, groups[i], extdata);
|
||||
if (ret < 0)
|
||||
return gnutls_assert_val(ret);
|
||||
}
|
||||
@@ -594,13 +608,19 @@ static int server_use_key_share(gnutls_session_t session,
|
||||
const uint8_t *data, size_t data_size)
|
||||
{
|
||||
gnutls_buffer_st buffer;
|
||||
+ const gnutls_group_entry_st *groups[MAX_HYBRID_GROUPS + 1] = {
|
||||
+ NULL,
|
||||
+ };
|
||||
+ int ret;
|
||||
|
||||
_gnutls_ro_buffer_init(&buffer, data, data_size);
|
||||
|
||||
- for (const gnutls_group_entry_st *p = group; p != NULL; p = p->next) {
|
||||
- int ret;
|
||||
+ ret = _gnutls_group_expand(group, groups);
|
||||
+ if (ret < 0)
|
||||
+ return gnutls_assert_val(ret);
|
||||
|
||||
- ret = server_use_key_share_single(session, p, &buffer);
|
||||
+ for (size_t i = 0; groups[i]; i++) {
|
||||
+ ret = server_use_key_share_single(session, groups[i], &buffer);
|
||||
if (ret < 0)
|
||||
return gnutls_assert_val(ret);
|
||||
}
|
||||
@@ -775,13 +795,19 @@ static int client_use_key_share(gnutls_session_t session,
|
||||
const uint8_t *data, size_t data_size)
|
||||
{
|
||||
gnutls_buffer_st buffer;
|
||||
+ const gnutls_group_entry_st *groups[MAX_HYBRID_GROUPS + 1] = {
|
||||
+ NULL,
|
||||
+ };
|
||||
+ int ret;
|
||||
|
||||
_gnutls_ro_buffer_init(&buffer, data, data_size);
|
||||
|
||||
- for (const gnutls_group_entry_st *p = group; p != NULL; p = p->next) {
|
||||
- int ret;
|
||||
+ ret = _gnutls_group_expand(group, groups);
|
||||
+ if (ret < 0)
|
||||
+ return gnutls_assert_val(ret);
|
||||
|
||||
- ret = client_use_key_share_single(session, p, &buffer);
|
||||
+ for (size_t i = 0; groups[i]; i++) {
|
||||
+ ret = client_use_key_share_single(session, groups[i], &buffer);
|
||||
if (ret < 0)
|
||||
return gnutls_assert_val(ret);
|
||||
}
|
||||
@@ -958,18 +984,39 @@ static int key_share_recv_params(gnutls_session_t session, const uint8_t *data,
|
||||
return 0;
|
||||
}
|
||||
|
||||
+static inline bool pk_types_overlap_single(const gnutls_group_entry_st *a,
|
||||
+ const gnutls_group_entry_st *b)
|
||||
+{
|
||||
+ return a->pk == b->pk || (IS_ECDHX(a->pk) && IS_ECDHX(b->pk)) ||
|
||||
+ (IS_KEM(a->pk) && IS_KEM(b->pk));
|
||||
+}
|
||||
+
|
||||
static inline bool pk_types_overlap(const gnutls_group_entry_st *a,
|
||||
const gnutls_group_entry_st *b)
|
||||
{
|
||||
- const gnutls_group_entry_st *pa;
|
||||
+ const gnutls_group_entry_st *sa[MAX_HYBRID_GROUPS + 1] = {
|
||||
+ NULL,
|
||||
+ };
|
||||
+ const gnutls_group_entry_st *sb[MAX_HYBRID_GROUPS + 1] = {
|
||||
+ NULL,
|
||||
+ };
|
||||
+ int ret;
|
||||
+
|
||||
+ ret = _gnutls_group_expand(a, sa);
|
||||
+ if (ret < 0) {
|
||||
+ gnutls_assert();
|
||||
+ return false;
|
||||
+ }
|
||||
|
||||
- for (pa = a; pa != NULL; pa = pa->next) {
|
||||
- const gnutls_group_entry_st *pb;
|
||||
+ ret = _gnutls_group_expand(b, sb);
|
||||
+ if (ret < 0) {
|
||||
+ gnutls_assert();
|
||||
+ return false;
|
||||
+ }
|
||||
|
||||
- for (pb = b; pb != NULL; pb = pb->next) {
|
||||
- if (pa->pk == pb->pk ||
|
||||
- (IS_ECDHX(pa->pk) && IS_ECDHX(pb->pk)) ||
|
||||
- (IS_KEM(pa->pk) && IS_KEM(pb->pk)))
|
||||
+ for (size_t i = 0; sa[i]; i++) {
|
||||
+ for (size_t j = 0; sb[j]; j++) {
|
||||
+ if (pk_types_overlap_single(sa[i], sb[j]))
|
||||
return true;
|
||||
}
|
||||
}
|
||||
diff --git a/lib/ext/supported_groups.c b/lib/ext/supported_groups.c
|
||||
index 254ec4882..4c31d2f8f 100644
|
||||
--- a/lib/ext/supported_groups.c
|
||||
+++ b/lib/ext/supported_groups.c
|
||||
@@ -106,9 +106,9 @@ static int _gnutls_supported_groups_recv_params(gnutls_session_t session,
|
||||
unsigned min_dh;
|
||||
unsigned j;
|
||||
int serv_ec_idx, serv_dh_idx,
|
||||
- serv_kem_idx; /* index in server's priority listing */
|
||||
+ serv_hybrid_idx; /* index in server's priority listing */
|
||||
int cli_ec_pos, cli_dh_pos,
|
||||
- cli_kem_pos; /* position in listing sent by client */
|
||||
+ cli_hybrid_pos; /* position in listing sent by client */
|
||||
|
||||
if (session->security_parameters.entity == GNUTLS_CLIENT) {
|
||||
/* A client shouldn't receive this extension in TLS1.2. It is
|
||||
@@ -134,8 +134,8 @@ static int _gnutls_supported_groups_recv_params(gnutls_session_t session,
|
||||
/* we figure what is the minimum DH allowed for this session, if any */
|
||||
min_dh = get_min_dh(session);
|
||||
|
||||
- serv_ec_idx = serv_dh_idx = serv_kem_idx = -1;
|
||||
- cli_ec_pos = cli_dh_pos = cli_kem_pos = -1;
|
||||
+ serv_ec_idx = serv_dh_idx = serv_hybrid_idx = -1;
|
||||
+ cli_ec_pos = cli_dh_pos = cli_hybrid_pos = -1;
|
||||
|
||||
/* This extension is being processed prior to a ciphersuite being selected,
|
||||
* so we cannot rely on ciphersuite information. */
|
||||
@@ -180,14 +180,15 @@ static int _gnutls_supported_groups_recv_params(gnutls_session_t session,
|
||||
break;
|
||||
serv_ec_idx = j;
|
||||
cli_ec_pos = i;
|
||||
- } else if (IS_KEM(group->pk)) {
|
||||
- if (serv_kem_idx !=
|
||||
+ } else if (IS_GROUP_HYBRID(
|
||||
+ group)) {
|
||||
+ if (serv_hybrid_idx !=
|
||||
-1 &&
|
||||
(int)j >
|
||||
- serv_kem_idx)
|
||||
+ serv_hybrid_idx)
|
||||
break;
|
||||
- serv_kem_idx = j;
|
||||
- cli_kem_pos = i;
|
||||
+ serv_hybrid_idx = j;
|
||||
+ cli_hybrid_pos = i;
|
||||
}
|
||||
} else {
|
||||
if (group->pk == GNUTLS_PK_DH) {
|
||||
@@ -200,11 +201,13 @@ static int _gnutls_supported_groups_recv_params(gnutls_session_t session,
|
||||
break;
|
||||
cli_ec_pos = i;
|
||||
serv_ec_idx = j;
|
||||
- } else if (IS_KEM(group->pk)) {
|
||||
- if (cli_kem_pos != -1)
|
||||
+ } else if (IS_GROUP_HYBRID(
|
||||
+ group)) {
|
||||
+ if (cli_hybrid_pos !=
|
||||
+ -1)
|
||||
break;
|
||||
- cli_kem_pos = i;
|
||||
- serv_kem_idx = j;
|
||||
+ cli_hybrid_pos = i;
|
||||
+ serv_hybrid_idx = j;
|
||||
}
|
||||
}
|
||||
break;
|
||||
@@ -212,7 +215,7 @@ static int _gnutls_supported_groups_recv_params(gnutls_session_t session,
|
||||
}
|
||||
}
|
||||
|
||||
- /* serv_{dh,ec,kem}_idx contain the index of the groups we want to use.
|
||||
+ /* serv_{dh,ec,hybrid}_idx contain the index of the groups we want to use.
|
||||
*/
|
||||
if (serv_dh_idx != -1) {
|
||||
session->internals.cand_dh_group =
|
||||
@@ -236,18 +239,20 @@ static int _gnutls_supported_groups_recv_params(gnutls_session_t session,
|
||||
}
|
||||
}
|
||||
|
||||
- /* KEM can only be used in TLS 1.3, where no separation from
|
||||
- * ECDH and DH, and thus only cand_group is set here.
|
||||
+ /* PQC hybrid key exchange groups can only be used in
|
||||
+ * TLS 1.3, where no distinction between ECDH and DH
|
||||
+ * in the group definitions, and thus only cand_group
|
||||
+ * is set here.
|
||||
*/
|
||||
- if (serv_kem_idx != -1) {
|
||||
+ if (serv_hybrid_idx != -1) {
|
||||
if (session->internals.cand_group == NULL ||
|
||||
(session->internals.priorities->server_precedence &&
|
||||
- serv_kem_idx < MIN(serv_ec_idx, serv_dh_idx)) ||
|
||||
+ serv_hybrid_idx < MIN(serv_ec_idx, serv_dh_idx)) ||
|
||||
(!session->internals.priorities->server_precedence &&
|
||||
- cli_kem_pos < MIN(cli_ec_pos, cli_dh_pos))) {
|
||||
+ cli_hybrid_pos < MIN(cli_ec_pos, cli_dh_pos))) {
|
||||
session->internals.cand_group =
|
||||
session->internals.priorities->groups
|
||||
- .entry[serv_kem_idx];
|
||||
+ .entry[serv_hybrid_idx];
|
||||
}
|
||||
}
|
||||
|
||||
diff --git a/lib/gnutls_int.h b/lib/gnutls_int.h
|
||||
index fb2cacb54..01ef59729 100644
|
||||
--- a/lib/gnutls_int.h
|
||||
+++ b/lib/gnutls_int.h
|
||||
@@ -756,6 +756,8 @@ typedef struct gnutls_cipher_suite_entry_st {
|
||||
gnutls_mac_algorithm_t prf;
|
||||
} gnutls_cipher_suite_entry_st;
|
||||
|
||||
+#define MAX_HYBRID_GROUPS 2
|
||||
+
|
||||
typedef struct gnutls_group_entry_st {
|
||||
const char *name;
|
||||
gnutls_group_t id;
|
||||
@@ -765,8 +767,12 @@ typedef struct gnutls_group_entry_st {
|
||||
const unsigned *q_bits;
|
||||
gnutls_ecc_curve_t curve;
|
||||
gnutls_pk_algorithm_t pk;
|
||||
+ gnutls_group_t ids[MAX_HYBRID_GROUPS + 1]; /* IDs of subgroups
|
||||
+ * comprising a
|
||||
+ * hybrid group,
|
||||
+ * terminated with
|
||||
+ * GNUTLS_GROUP_INVALID */
|
||||
unsigned tls_id; /* The RFC4492 namedCurve ID or TLS 1.3 group ID */
|
||||
- const struct gnutls_group_entry_st *next;
|
||||
} gnutls_group_entry_st;
|
||||
|
||||
#define GNUTLS_MAC_FLAG_PREIMAGE_INSECURE \
|
||||
diff --git a/lib/includes/gnutls/gnutls.h.in b/lib/includes/gnutls/gnutls.h.in
|
||||
index 8b3bb5213..1e44fdd91 100644
|
||||
--- a/lib/includes/gnutls/gnutls.h.in
|
||||
+++ b/lib/includes/gnutls/gnutls.h.in
|
||||
@@ -1147,8 +1147,10 @@ typedef enum {
|
||||
GNUTLS_GROUP_EXP_X25519_KYBER768 = 512,
|
||||
GNUTLS_GROUP_EXP_SECP256R1_MLKEM768 = 513,
|
||||
GNUTLS_GROUP_EXP_X25519_MLKEM768 = 514,
|
||||
+ GNUTLS_GROUP_EXP_KYBER768 = 515,
|
||||
+ GNUTLS_GROUP_EXP_MLKEM768 = 516,
|
||||
GNUTLS_GROUP_EXP_MIN = GNUTLS_GROUP_EXP_X25519_KYBER768,
|
||||
- GNUTLS_GROUP_EXP_MAX = GNUTLS_GROUP_EXP_X25519_MLKEM768
|
||||
+ GNUTLS_GROUP_EXP_MAX = GNUTLS_GROUP_EXP_MLKEM768
|
||||
} gnutls_group_t;
|
||||
|
||||
/* macros to allow specifying a specific curve in gnutls_privkey_generate()
|
||||
diff --git a/lib/priority.c b/lib/priority.c
|
||||
index ac4ff2d8c..479dbccd6 100644
|
||||
--- a/lib/priority.c
|
||||
+++ b/lib/priority.c
|
||||
@@ -2566,7 +2566,7 @@ static void add_dh(gnutls_priority_t priority_cache)
|
||||
}
|
||||
}
|
||||
|
||||
-static void add_kem(gnutls_priority_t priority_cache)
|
||||
+static void add_hybrid(gnutls_priority_t priority_cache)
|
||||
{
|
||||
const gnutls_group_entry_st *ge;
|
||||
unsigned i;
|
||||
@@ -2579,7 +2579,7 @@ static void add_kem(gnutls_priority_t priority_cache)
|
||||
sizeof(priority_cache->groups.entry) /
|
||||
sizeof(priority_cache->groups.entry[0])) {
|
||||
/* do not add groups which do not correspond to enabled ciphersuites */
|
||||
- if (!IS_KEM(ge->pk))
|
||||
+ if (!IS_GROUP_HYBRID(ge))
|
||||
continue;
|
||||
priority_cache->groups
|
||||
.entry[priority_cache->groups.size++] = ge;
|
||||
@@ -2598,7 +2598,7 @@ static int set_ciphersuite_list(gnutls_priority_t priority_cache)
|
||||
const gnutls_sign_entry_st *se;
|
||||
unsigned have_ec = 0;
|
||||
unsigned have_dh = 0;
|
||||
- unsigned have_kem = 0;
|
||||
+ unsigned have_hybrid = 0;
|
||||
unsigned tls_sig_sem = 0;
|
||||
const version_entry_st *tlsmax = NULL, *vers;
|
||||
const version_entry_st *dtlsmax = NULL;
|
||||
@@ -2807,9 +2807,9 @@ static int set_ciphersuite_list(gnutls_priority_t priority_cache)
|
||||
priority_cache->cs.entry[priority_cache->cs.size++] =
|
||||
ce;
|
||||
|
||||
- if (!have_kem) {
|
||||
- have_kem = 1;
|
||||
- add_kem(priority_cache);
|
||||
+ if (!have_hybrid) {
|
||||
+ have_hybrid = 1;
|
||||
+ add_hybrid(priority_cache);
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -2851,8 +2851,8 @@ static int set_ciphersuite_list(gnutls_priority_t priority_cache)
|
||||
}
|
||||
}
|
||||
|
||||
- if (have_tls13 && (!have_ec || !have_dh || !have_kem)) {
|
||||
- /* scan groups to determine have_{ec,dh,kem} */
|
||||
+ if (have_tls13 && (!have_ec || !have_dh || !have_hybrid)) {
|
||||
+ /* scan groups to determine have_{ec,dh,hybrid} */
|
||||
for (i = 0; i < priority_cache->_supported_ecc.num_priorities;
|
||||
i++) {
|
||||
const gnutls_group_entry_st *ge;
|
||||
@@ -2865,12 +2865,13 @@ static int set_ciphersuite_list(gnutls_priority_t priority_cache)
|
||||
} else if (ge->prime && !have_dh) {
|
||||
add_dh(priority_cache);
|
||||
have_dh = 1;
|
||||
- } else if (IS_KEM(ge->pk) && !have_kem) {
|
||||
- add_kem(priority_cache);
|
||||
- have_kem = 1;
|
||||
+ } else if (IS_GROUP_HYBRID(ge) &&
|
||||
+ !have_hybrid) {
|
||||
+ add_hybrid(priority_cache);
|
||||
+ have_hybrid = 1;
|
||||
}
|
||||
|
||||
- if (have_dh && have_ec && have_kem)
|
||||
+ if (have_dh && have_ec && have_hybrid)
|
||||
break;
|
||||
}
|
||||
}
|
||||
diff --git a/lib/session.c b/lib/session.c
|
||||
index a9049a464..7fcbe4fb4 100644
|
||||
--- a/lib/session.c
|
||||
+++ b/lib/session.c
|
||||
@@ -415,7 +415,11 @@ char *gnutls_session_get_desc(gnutls_session_t session)
|
||||
snprintf(kx_name, sizeof(kx_name), "(PSK)");
|
||||
}
|
||||
} else if (group && sign_str) {
|
||||
- if (group->curve)
|
||||
+ if (IS_GROUP_HYBRID(group))
|
||||
+ snprintf(kx_name, sizeof(kx_name),
|
||||
+ "(HYBRID-%s)-(%s)", group_name,
|
||||
+ sign_str);
|
||||
+ else if (group->curve)
|
||||
snprintf(kx_name, sizeof(kx_name),
|
||||
"(ECDHE-%s)-(%s)", group_name,
|
||||
sign_str);
|
||||
diff --git a/tests/pqc-hybrid-kx.sh b/tests/pqc-hybrid-kx.sh
|
||||
index da936cf04..4984cd4b4 100644
|
||||
--- a/tests/pqc-hybrid-kx.sh
|
||||
+++ b/tests/pqc-hybrid-kx.sh
|
||||
@@ -33,34 +33,113 @@
|
||||
|
||||
. "${srcdir}/scripts/common.sh"
|
||||
|
||||
+# First check any mismatch in the gnutls-cli --list
|
||||
if ! "${CLI}" --list | grep '^Groups: .*GROUP-X25519-KYBER768.*' >/dev/null; then
|
||||
if "${CLI}" --list | grep '^Public Key Systems: .*KYBER768.*' >/dev/null; then
|
||||
- fail "KYBER768 is in Public Key Systems, while GROUP-X25519-KYBER768 is NOT in Groups"
|
||||
+ fail '' 'KYBER768 is in Public Key Systems, while GROUP-X25519-KYBER768 is NOT in Groups'
|
||||
fi
|
||||
- exit 77
|
||||
else
|
||||
if ! "${CLI}" --list | grep '^Public Key Systems: .*KYBER768.*' >/dev/null; then
|
||||
- fail "KYBER768 is NOT in Public Key Systems, while GROUP-X25519-KYBER768 is in Groups"
|
||||
+ fail '' 'KYBER768 is NOT in Public Key Systems, while GROUP-X25519-KYBER768 is in Groups'
|
||||
+ fi
|
||||
+fi
|
||||
+
|
||||
+if ! "${CLI}" --list | grep '^Groups: .*GROUP-\(SECP256R1\|X25519\)-MLKEM768.*' >/dev/null; then
|
||||
+ if "${CLI}" --list | grep '^Public Key Systems: .*ML-KEM-768.*' >/dev/null; then
|
||||
+ fail '' 'ML-KEM-768 is in Public Key Systems, while GROUP-SECP256R1-MLKEM768 or GROUP-X25519-MLKEM768 is NOT in Groups'
|
||||
+ fi
|
||||
+else
|
||||
+ if ! "${CLI}" --list | grep '^Public Key Systems: .*ML-KEM-768.*' >/dev/null; then
|
||||
+ fail '' 'ML-KEM-768 is NOT in Public Key Systems, while GROUP-SECP256R1-MLKEM768 or GROUP-X25519-MLKEM768 is in Groups'
|
||||
fi
|
||||
fi
|
||||
|
||||
+# If none of those hybrid groups is supported, skip the test
|
||||
+if ! "${CLI}" --list | grep '^Groups: .*GROUP-\(X25519-KYBER768\|SECP256R1-MLKEM768\|X25519-MLKEM768\).*' >/dev/null; then
|
||||
+ exit 77
|
||||
+fi
|
||||
+
|
||||
testdir=`create_testdir pqc-hybrid-kx`
|
||||
|
||||
KEY="$srcdir/../doc/credentials/x509/key-ecc.pem"
|
||||
CERT="$srcdir/../doc/credentials/x509/cert-ecc.pem"
|
||||
CACERT="$srcdir/../doc/credentials/x509/ca.pem"
|
||||
|
||||
-eval "${GETPORT}"
|
||||
-launch_server --echo --priority NORMAL:-GROUP-ALL:+GROUP-X25519-KYBER768 --x509keyfile="$KEY" --x509certfile="$CERT"
|
||||
-PID=$!
|
||||
-wait_server ${PID}
|
||||
+# Test all supported hybrid groups
|
||||
+for group in X25519-KYBER768 SECP256R1-MLKEM768 X25519-MLKEM768; do
|
||||
+ if ! "${CLI}" --list | grep "^Groups: .*GROUP-$group.*" >/dev/null; then
|
||||
+ echo "$group is not supported, skipping" >&2
|
||||
+ continue
|
||||
+ fi
|
||||
+
|
||||
+ eval "${GETPORT}"
|
||||
+ launch_server --echo --priority "NORMAL:-GROUP-ALL:+GROUP-$group" --x509keyfile="$KEY" --x509certfile="$CERT"
|
||||
+ PID=$!
|
||||
+ wait_server ${PID}
|
||||
+
|
||||
+ ${VALGRIND} "${CLI}" -p "${PORT}" localhost --priority "NORMAL:-GROUP-ALL:+GROUP-$group" --x509cafile="$CACERT" --logfile="$testdir/cli.log" </dev/null
|
||||
+ kill ${PID}
|
||||
+ wait
|
||||
+
|
||||
+ grep -- "- Description: (TLS1.3-X.509)-(HYBRID-$group)-(ECDSA-SECP256R1-SHA256)-(AES-256-GCM)" "$testdir/cli.log" || { echo "unexpected handshake description"; cat "$testdir/cli.log"; exit 1; }
|
||||
+done
|
||||
+
|
||||
+# KEM based groups cannot be used standalone
|
||||
+for group in KYBER768 MLKEM768; do
|
||||
+ if ! "${CLI}" --list | grep "^Groups: .*GROUP-$group.*" >/dev/null; then
|
||||
+ "$group is not supported, skipping"
|
||||
+ continue
|
||||
+ fi
|
||||
+
|
||||
+ eval "${GETPORT}"
|
||||
+ launch_server --echo --priority "NORMAL:-GROUP-ALL:+GROUP-$group" --x509keyfile="$KEY" --x509certfile="$CERT"
|
||||
+ PID=$!
|
||||
+ wait_server ${PID}
|
||||
+
|
||||
+ ${VALGRIND} "${CLI}" -p "${PORT}" localhost --priority "NORMAL:-GROUP-ALL:+GROUP-$group" --x509cafile="$CACERT" --logfile="$testdir/cli.log" </dev/null
|
||||
+ rc=$?
|
||||
+ kill ${PID}
|
||||
+ wait
|
||||
+
|
||||
+ if test $rc -eq 0; then
|
||||
+ fail '' 'Handshake succeeded with a standalone KEM group'
|
||||
+ fi
|
||||
+done
|
||||
+
|
||||
+# Check if disabling a curve will also disables hybrid groups with it
|
||||
+cat <<_EOF_ > "$testdir/test.config"
|
||||
+[overrides]
|
||||
+
|
||||
+disabled-curve = x25519
|
||||
+_EOF_
|
||||
+
|
||||
+for group in X25519-KYBER768 SECP256R1-MLKEM768 X25519-MLKEM768; do
|
||||
+ if ! "${CLI}" --list | grep "^Groups: .*GROUP-$group.*" >/dev/null; then
|
||||
+ echo "$group is not supported, skipping" >&2
|
||||
+ continue
|
||||
+ fi
|
||||
|
||||
-${VALGRIND} "${CLI}" -p "${PORT}" localhost --priority NORMAL:-GROUP-ALL:+GROUP-X25519-KYBER768 --x509cafile="$CACERT" --logfile="$testdir/cli.log" </dev/null
|
||||
+ eval "${GETPORT}"
|
||||
+ GNUTLS_SYSTEM_PRIORITY_FILE="$testdir/test.config" launch_server --echo --priority "NORMAL:-GROUP-ALL:+GROUP-$group" --x509keyfile="$KEY" --x509certfile="$CERT"
|
||||
+ PID=$!
|
||||
+ wait_server ${PID}
|
||||
|
||||
-kill ${PID}
|
||||
-wait
|
||||
+ ${VALGRIND} "${CLI}" -p "${PORT}" localhost --priority "NORMAL:-GROUP-ALL:+GROUP-$group" --x509cafile="$CACERT" --logfile="$testdir/cli.log" </dev/null
|
||||
+ rc=$?
|
||||
+ kill ${PID}
|
||||
+ wait
|
||||
|
||||
-grep -- '- Description: (TLS1.3-X.509)-(ECDHE-X25519-KYBER768)-(ECDSA-SECP256R1-SHA256)-(AES-256-GCM)' "$testdir/cli.log" || { echo "unexpected handshake description"; exit 1; }
|
||||
+ case "$group" in
|
||||
+ X25519*)
|
||||
+ if test $rc -eq 0; then
|
||||
+ fail '' 'Handshake succeeded with a hybrid group with X25519'
|
||||
+ fi
|
||||
+ ;;
|
||||
+ *)
|
||||
+ grep -- "- Description: (TLS1.3-X.509)-(HYBRID-$group)-(ECDSA-SECP256R1-SHA256)-(AES-256-GCM)" "$testdir/cli.log" || { echo "unexpected handshake description"; cat "$testdir/cli.log"; exit 1; }
|
||||
+ ;;
|
||||
+ esac
|
||||
+done
|
||||
|
||||
rm -rf "$testdir"
|
||||
exit 0
|
||||
--
|
||||
2.47.1
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
# Locally calculated after checking pgp signature
|
||||
# https://www.gnupg.org/ftp/gcrypt/gnutls/v3.8/gnutls-3.8.8.tar.xz.sig
|
||||
sha256 ac4f020e583880b51380ed226e59033244bc536cad2623f2e26f5afa2939d8fb gnutls-3.8.8.tar.xz
|
||||
# https://www.gnupg.org/ftp/gcrypt/gnutls/v3.8/gnutls-3.8.9.tar.xz.sig
|
||||
sha256 69e113d802d1670c4d5ac1b99040b1f2d5c7c05daec5003813c049b5184820ed gnutls-3.8.9.tar.xz
|
||||
# Locally calculated
|
||||
sha256 3972dc9744f6499f0f9b2dbf76696f2ae7ad8af9b23dde66d6af86c9dfb36986 doc/COPYING
|
||||
sha256 dc626520dcd53a22f727af3ee42c770e56c97a64fe3adb063799d8ab032fe551 doc/COPYING.LESSER
|
||||
sha256 3972dc9744f6499f0f9b2dbf76696f2ae7ad8af9b23dde66d6af86c9dfb36986 COPYING
|
||||
sha256 20e50fe7aae3e56378ebf0417d9de904f55a0e61e4df315333e632a4d3555d95 COPYING.LESSERv2
|
||||
sha256 5e4aca90e8e08e47558dfd21e2a42251a139242b0016a06708739eeb8f0da60c README.md
|
||||
|
||||
@@ -6,11 +6,11 @@
|
||||
|
||||
# When bumping, make sure *all* --without-libfoo-prefix options are in GNUTLS_CONF_OPTS
|
||||
GNUTLS_VERSION_MAJOR = 3.8
|
||||
GNUTLS_VERSION = $(GNUTLS_VERSION_MAJOR).8
|
||||
GNUTLS_VERSION = $(GNUTLS_VERSION_MAJOR).9
|
||||
GNUTLS_SOURCE = gnutls-$(GNUTLS_VERSION).tar.xz
|
||||
GNUTLS_SITE = https://www.gnupg.org/ftp/gcrypt/gnutls/v$(GNUTLS_VERSION_MAJOR)
|
||||
GNUTLS_LICENSE = LGPL-2.1+ (core library)
|
||||
GNUTLS_LICENSE_FILES = doc/COPYING.LESSER
|
||||
GNUTLS_LICENSE_FILES = COPYING.LESSERv2 README.md
|
||||
|
||||
GNUTLS_DEPENDENCIES = host-pkgconf libtasn1 libunistring nettle
|
||||
GNUTLS_CPE_ID_VENDOR = gnu
|
||||
@@ -66,7 +66,7 @@ HOST_GNUTLS_CONF_OPTS = \
|
||||
|
||||
ifeq ($(BR2_PACKAGE_GNUTLS_OPENSSL),y)
|
||||
GNUTLS_LICENSE += , GPL-3.0+ (gnutls-openssl library)
|
||||
GNUTLS_LICENSE_FILES += doc/COPYING
|
||||
GNUTLS_LICENSE_FILES += COPYING
|
||||
GNUTLS_CONF_OPTS += --enable-openssl-compatibility
|
||||
else
|
||||
GNUTLS_CONF_OPTS += --disable-openssl-compatibility
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
# From https://go.dev/dl
|
||||
sha256 1e94fd48be750d1fafb4d9b3b6dd31a6e9d2735d339bf2462bc97b64ca4c1037 go1.22.10.src.tar.gz
|
||||
sha256 012a7e1f37f362c0918c1dfa3334458ac2da1628c4b9cf4d9ca02db986e17d71 go1.22.12.src.tar.gz
|
||||
sha256 2d36597f7117c38b006835ae7f537487207d8ec407aa9d9980794b2030cbc067 LICENSE
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
GO_VERSION = 1.22.10
|
||||
GO_VERSION = 1.22.12
|
||||
GO_SITE = https://storage.googleapis.com/golang
|
||||
GO_SOURCE = go$(GO_VERSION).src.tar.gz
|
||||
|
||||
|
||||
@@ -80,6 +80,7 @@ config BR2_PACKAGE_GPSD_PYTHON
|
||||
bool "build Python support and modules"
|
||||
depends on BR2_USE_WCHAR # python3
|
||||
select BR2_PACKAGE_PYTHON3
|
||||
select BR2_PACKAGE_PYTHON_SERIAL # runtime
|
||||
help
|
||||
Python libraries and tools for the gpsd service daemon
|
||||
including gpsfake test harness.
|
||||
|
||||
@@ -6,7 +6,7 @@
|
||||
|
||||
HEIMDAL_VERSION = f4faaeaba371fff3f8d1bc14389f5e6d70ca8e17
|
||||
HEIMDAL_SITE = $(call github,heimdal,heimdal,$(HEIMDAL_VERSION))
|
||||
HOST_HEIMDAL_DEPENDENCIES = host-e2fsprogs host-ncurses host-pkgconf
|
||||
HOST_HEIMDAL_DEPENDENCIES = host-e2fsprogs host-ncurses host-pkgconf host-libxcrypt host-flex host-bison
|
||||
HOST_HEIMDAL_AUTORECONF = YES
|
||||
HEIMDAL_INSTALL_STAGING = YES
|
||||
# static because of -fPIC issues with e2fsprogs on x86_64 host
|
||||
@@ -29,7 +29,7 @@ HOST_HEIMDAL_CONF_OPTS = \
|
||||
--disable-heimdal-documentation
|
||||
|
||||
# Don't use compile_et from e2fsprogs as it raises a build failure with samba4
|
||||
HOST_HEIMDAL_CONF_ENV = ac_cv_prog_COMPILE_ET=no MAKEINFO=true
|
||||
HOST_HEIMDAL_CONF_ENV = ac_cv_prog_COMPILE_ET=no MAKEINFO=true LIBS=-lcrypt
|
||||
HEIMDAL_LICENSE = BSD-3-Clause
|
||||
HEIMDAL_LICENSE_FILES = LICENSE
|
||||
HEIMDAL_CPE_ID_VALID = YES
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
# Locally computed
|
||||
sha256 c82210ea3fdbd044b656ba3d5b42df1da9a18e78fc0e500169bad70d3b0d9ba3 imagemagick-7.1.1-31.tar.gz
|
||||
sha256 ceb972266b23dc7c1cfce0da5a7f0c9acfb4dc81f40eb542a49476fedbc2618f imagemagick-7.1.1-43.tar.gz
|
||||
sha256 a556c5292c87c9a6ac795c80669b0c3660f9f729de8c476bf2b10f83ab1b34ec LICENSE
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
IMAGEMAGICK_VERSION = 7.1.1-31
|
||||
IMAGEMAGICK_VERSION = 7.1.1-43
|
||||
IMAGEMAGICK_SITE = $(call github,ImageMagick,ImageMagick,$(IMAGEMAGICK_VERSION))
|
||||
IMAGEMAGICK_LICENSE = Apache-2.0
|
||||
IMAGEMAGICK_LICENSE_FILES = LICENSE
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
# Locally computed
|
||||
sha256 37246208ef68039be752438c72400a688a2238df13a7f5282497c80be2d8366d intel-microcode-20241112.tar.gz
|
||||
sha256 1da88b51953c9da2e20b5c94b3d7270cf87ea5babcaa56e3d6a5c9eaf11694b3 intel-microcode-20250211.tar.gz
|
||||
sha256 03efb1491c7e899feb2665fa299363e64035e5444c1b8bc1f6ebed30de964e12 license
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
INTEL_MICROCODE_VERSION = 20241112
|
||||
INTEL_MICROCODE_VERSION = 20250211
|
||||
INTEL_MICROCODE_SITE = $(call github,intel,Intel-Linux-Processor-Microcode-Data-Files,microcode-$(INTEL_MICROCODE_VERSION))
|
||||
INTEL_MICROCODE_LICENSE = PROPRIETARY
|
||||
INTEL_MICROCODE_LICENSE_FILES = license
|
||||
|
||||
@@ -0,0 +1,28 @@
|
||||
From e60a9f388bd5655cb514491ef8d55d403aef0773 Mon Sep 17 00:00:00 2001
|
||||
From: Sebastian Rasmussen <sebras@gmail.com>
|
||||
Date: Sun, 5 Nov 2023 12:21:52 +0100
|
||||
Subject: [PATCH] Bug 705041: jbig2dec: Avoid uninitialized allocator in
|
||||
command-line tool.
|
||||
|
||||
Upstream: https://github.com/ArtifexSoftware/jbig2dec/commit/ee53a7e4bc7819d32e8c0b2057885bcc97586bf3
|
||||
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
|
||||
---
|
||||
jbig2dec.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/jbig2dec.c b/jbig2dec.c
|
||||
index 15d204d..1e1dad8 100644
|
||||
--- a/jbig2dec.c
|
||||
+++ b/jbig2dec.c
|
||||
@@ -567,7 +567,7 @@ main(int argc, char **argv)
|
||||
{
|
||||
jbig2dec_params_t params;
|
||||
jbig2dec_error_callback_state_t error_callback_state;
|
||||
- jbig2dec_allocator_t allocator_;
|
||||
+ jbig2dec_allocator_t allocator_ = { 0 };
|
||||
jbig2dec_allocator_t *allocator = &allocator_;
|
||||
Jbig2Ctx *ctx = NULL;
|
||||
FILE *f = NULL, *f_page = NULL;
|
||||
--
|
||||
2.48.1
|
||||
|
||||
@@ -14,4 +14,7 @@ JBIG2DEC_INSTALL_STAGING = YES
|
||||
# tarball is missing install-sh, install.sh, or shtool
|
||||
JBIG2DEC_AUTORECONF = YES
|
||||
|
||||
# 0001-Bug-705041-jbig2dec-Avoid-uninitialized-allocator-in.patch
|
||||
JBIG2DEC_IGNORE_CVES += CVE-2023-46361
|
||||
|
||||
$(eval $(autotools-package))
|
||||
|
||||
@@ -3,7 +3,6 @@ config BR2_PACKAGE_LIBBSD_ARCH_SUPPORTS
|
||||
default y
|
||||
# libbsd does not support those architectures (see src/local-elf.h)
|
||||
depends on !BR2_microblaze
|
||||
depends on !BR2_arc
|
||||
depends on !BR2_xtensa
|
||||
|
||||
config BR2_PACKAGE_LIBBSD
|
||||
|
||||
@@ -1,44 +0,0 @@
|
||||
From 58d490091d097ba2ad108cc66c97e242e5aacb9c Mon Sep 17 00:00:00 2001
|
||||
Message-ID: <58d490091d097ba2ad108cc66c97e242e5aacb9c.1727153835.git.baruch@tkos.co.il>
|
||||
From: Baruch Siach <baruch@tkos.co.il>
|
||||
Date: Tue, 24 Sep 2024 07:52:13 +0300
|
||||
Subject: [PATCH] curl_trc: fix build with verbose messages disabled
|
||||
|
||||
Add empty definition of Curl_trc_ws() to fix this following build error:
|
||||
|
||||
In file included from sendf.h:29,
|
||||
from ws.c:35:
|
||||
ws.c: In function 'Curl_ws_accept':
|
||||
curl_trc.h:100:10: error: implicit declaration of function 'Curl_trc_ws'; did you mean 'Curl_trc_ftp'? [-Wimplicit-function-declaration]
|
||||
100 | Curl_trc_ws(data, __VA_ARGS__); } while(0)
|
||||
| ^~~~~~~~~~~
|
||||
ws.c:779:5: note: in expansion of macro 'CURL_TRC_WS'
|
||||
779 | CURL_TRC_WS(data, "WS, using chunk size %zu", chunk_size);
|
||||
| ^~~~~~~~~~~
|
||||
|
||||
Signed-off-by: Baruch Siach <baruch@tkos.co.il>
|
||||
Upstream: https://github.com/curl/curl/pull/15026
|
||||
---
|
||||
lib/curl_trc.h | 6 ++++++
|
||||
1 file changed, 6 insertions(+)
|
||||
|
||||
diff --git a/lib/curl_trc.h b/lib/curl_trc.h
|
||||
index 5f675b453fd3..1801d33cea7c 100644
|
||||
--- a/lib/curl_trc.h
|
||||
+++ b/lib/curl_trc.h
|
||||
@@ -226,6 +226,12 @@ static void Curl_trc_smtp(struct Curl_easy *data, const char *fmt, ...)
|
||||
(void)data; (void)fmt;
|
||||
}
|
||||
#endif
|
||||
+#if defined(USE_WEBSOCKETS) && !defined(CURL_DISABLE_HTTP)
|
||||
+static void Curl_trc_ws(struct Curl_easy *data, const char *fmt, ...)
|
||||
+{
|
||||
+ (void)data; (void)fmt;
|
||||
+}
|
||||
+#endif
|
||||
|
||||
#endif /* !defined(CURL_DISABLE_VERBOSE_STRINGS) */
|
||||
|
||||
--
|
||||
2.45.2
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
# Locally calculated after checking pgp signature
|
||||
# https://curl.se/download/curl-8.11.1.tar.xz.asc
|
||||
# https://curl.se/download/curl-8.12.1.tar.xz.asc
|
||||
# signed with key 27EDEAF22F3ABCEB50DB9A125CC908FDB71E12C2
|
||||
sha256 c7ca7db48b0909743eaef34250da02c19bc61d4f1dcedd6603f109409536ab56 curl-8.11.1.tar.xz
|
||||
sha256 adb1fc06547fd136244179809f7b7c2d2ae6c4534f160aa513af9b6a12866a32 COPYING
|
||||
sha256 0341f1ed97a26c811abaebd37d62b833956792b7607ea3f15d001613c76de202 curl-8.12.1.tar.xz
|
||||
sha256 e18f1989333b70044b2adfb7dc2f905d0119dbdcac3bc9f4bc9d540e3a29de5b COPYING
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
LIBCURL_VERSION = 8.11.1
|
||||
LIBCURL_VERSION = 8.12.1
|
||||
LIBCURL_SOURCE = curl-$(LIBCURL_VERSION).tar.xz
|
||||
LIBCURL_SITE = https://curl.se/download
|
||||
LIBCURL_DEPENDENCIES = host-pkgconf \
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Locally computed:
|
||||
sha256 d83bbe188d8fa9725bb75109c922c37fcff8c3b802808f3a6c2c14aaf8337d9f libjxl-0.9.0.tar.gz
|
||||
sha256 ac9f034bf80516f072450edfb31d93c156e7136791df0d0ce14c5d0d3990fe64 libjxl-0.9.4.tar.gz
|
||||
sha256 8405932022a556380c2d8c272eff154a923feb197233f348ce5f7334fb0a5ede LICENSE
|
||||
sha256 91915f8ae056a68a3c5bdf05d9f6f78bb6903e27a8ca3a8434c9e4ac87300575 PATENTS
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
LIBJXL_VERSION = 0.9.0
|
||||
LIBJXL_VERSION = 0.9.4
|
||||
LIBJXL_SITE = $(call github,libjxl,libjxl,v$(LIBJXL_VERSION))
|
||||
LIBJXL_LICENSE = BSD-3-Clause
|
||||
LIBJXL_LICENSE_FILES = LICENSE PATENTS
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
# From https://github.com/openssl/openssl/releases/download/openssl-3.2.3/openssl-3.2.3.tar.gz.sha256
|
||||
sha256 52b5f1c6b8022bc5868c308c54fb77705e702d6c6f4594f99a0df216acf46239 openssl-3.2.3.tar.gz
|
||||
# From https://github.com/openssl/openssl/releases/download/openssl-3.2.4/openssl-3.2.4.tar.gz.sha256
|
||||
sha256 b23ad7fd9f73e43ad1767e636040e88ba7c9e5775bfa5618436a0dd2c17c3716 openssl-3.2.4.tar.gz
|
||||
|
||||
# License files
|
||||
sha256 7d5450cb2d142651b8afa315b5f238efc805dad827d91ba367d8516bc9d49e7a LICENSE.txt
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
LIBOPENSSL_VERSION = 3.2.3
|
||||
LIBOPENSSL_VERSION = 3.2.4
|
||||
LIBOPENSSL_SITE = https://github.com/openssl/openssl/releases/download/openssl-$(LIBOPENSSL_VERSION)
|
||||
LIBOPENSSL_SOURCE = openssl-$(LIBOPENSSL_VERSION).tar.gz
|
||||
LIBOPENSSL_LICENSE = Apache-2.0
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# Locally calculated after checking pgp signature
|
||||
# https://ftp.gnu.org/gnu/libtasn1/libtasn1-4.19.0.tar.gz.sig
|
||||
sha256 1613f0ac1cf484d6ec0ce3b8c06d56263cc7242f1c23b30d82d23de345a63f7a libtasn1-4.19.0.tar.gz
|
||||
# https://ftp.gnu.org/gnu/libtasn1/libtasn1-4.20.0.tar.gz.sig
|
||||
sha256 92e0e3bd4c02d4aeee76036b2ddd83f0c732ba4cda5cb71d583272b23587a76c libtasn1-4.20.0.tar.gz
|
||||
# Locally calculated
|
||||
sha256 7446831f659f7ebfd8d497acc7f05dfa8e31c6cb6ba1b45df33d4895ab80f5a6 COPYING
|
||||
sha256 8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903 doc/COPYING
|
||||
sha256 dc626520dcd53a22f727af3ee42c770e56c97a64fe3adb063799d8ab032fe551 doc/COPYING.LESSER
|
||||
sha256 990ef6a87f29a9d3db33698b94ea026a5d0f81bbf9806333d73699a250b7e5d6 README.md
|
||||
sha256 3972dc9744f6499f0f9b2dbf76696f2ae7ad8af9b23dde66d6af86c9dfb36986 COPYING
|
||||
sha256 20e50fe7aae3e56378ebf0417d9de904f55a0e61e4df315333e632a4d3555d95 COPYING.LESSERv2
|
||||
|
||||
@@ -4,11 +4,11 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
LIBTASN1_VERSION = 4.19.0
|
||||
LIBTASN1_VERSION = 4.20.0
|
||||
LIBTASN1_SITE = $(BR2_GNU_MIRROR)/libtasn1
|
||||
LIBTASN1_DEPENDENCIES = host-bison host-pkgconf
|
||||
LIBTASN1_LICENSE = GPL-3.0+ (tests, tools), LGPL-2.1+ (library)
|
||||
LIBTASN1_LICENSE_FILES = COPYING doc/COPYING doc/COPYING.LESSER
|
||||
LIBTASN1_LICENSE_FILES = README.md COPYING COPYING.LESSERv2
|
||||
LIBTASN1_CPE_ID_VENDOR = gnu
|
||||
LIBTASN1_INSTALL_STAGING = YES
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# From https://download.gnome.org/sources/libxml2/2.12/libxml2-2.12.9.sha256sum
|
||||
sha256 59912db536ab56a3996489ea0299768c7bcffe57169f0235e7f962a91f483590 libxml2-2.12.9.tar.xz
|
||||
# From https://download.gnome.org/sources/libxml2/2.12/libxml2-2.12.10.sha256sum
|
||||
sha256 c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995 libxml2-2.12.10.tar.xz
|
||||
# License files, locally calculated
|
||||
sha256 7fb0a66f3989f9bd5c7e5438a3de02cd4a7a47dde0aea2f7ea2ba2ff454ee6a4 Copyright
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
################################################################################
|
||||
|
||||
LIBXML2_VERSION_MAJOR = 2.12
|
||||
LIBXML2_VERSION = $(LIBXML2_VERSION_MAJOR).9
|
||||
LIBXML2_VERSION = $(LIBXML2_VERSION_MAJOR).10
|
||||
LIBXML2_SOURCE = libxml2-$(LIBXML2_VERSION).tar.xz
|
||||
LIBXML2_SITE = \
|
||||
https://download.gnome.org/sources/libxml2/$(LIBXML2_VERSION_MAJOR)
|
||||
|
||||
@@ -404,11 +404,11 @@ endchoice
|
||||
config BR2_DEFAULT_KERNEL_HEADERS
|
||||
string
|
||||
default "4.19.325" if BR2_KERNEL_HEADERS_4_19
|
||||
default "5.4.288" if BR2_KERNEL_HEADERS_5_4
|
||||
default "5.10.232" if BR2_KERNEL_HEADERS_5_10
|
||||
default "5.15.175" if BR2_KERNEL_HEADERS_5_15
|
||||
default "6.1.122" if BR2_KERNEL_HEADERS_6_1
|
||||
default "6.6.68" if BR2_KERNEL_HEADERS_6_6
|
||||
default "5.4.291" if BR2_KERNEL_HEADERS_5_4
|
||||
default "5.10.235" if BR2_KERNEL_HEADERS_5_10
|
||||
default "5.15.179" if BR2_KERNEL_HEADERS_5_15
|
||||
default "6.1.131" if BR2_KERNEL_HEADERS_6_1
|
||||
default "6.6.83" if BR2_KERNEL_HEADERS_6_6
|
||||
default BR2_DEFAULT_KERNEL_VERSION if BR2_KERNEL_HEADERS_VERSION
|
||||
default "custom" if BR2_KERNEL_HEADERS_CUSTOM_TARBALL
|
||||
default BR2_KERNEL_HEADERS_CUSTOM_REPO_VERSION \
|
||||
|
||||
@@ -16,7 +16,7 @@ COMPILER_RT_SUPPORTS_IN_SOURCE_BUILD = NO
|
||||
COMPILER_RT_INSTALL_STAGING = YES
|
||||
COMPILER_RT_INSTALL_TARGET = NO
|
||||
|
||||
COMPILER_RT_CONF_OPTS=-DCOMPILER_RT_STANDALONE_BUILD=OFF \
|
||||
COMPILER_RT_CONF_OPTS = \
|
||||
-DCOMPILER_RT_STANDALONE_BUILD=ON \
|
||||
-DCOMPILER_RT_DEFAULT_TARGET_TRIPLE=$(GNU_TARGET_NAME) \
|
||||
-DLLVM_CONFIG_PATH=$(HOST_DIR)/bin/llvm-config \
|
||||
|
||||
@@ -36,7 +36,9 @@ reload() {
|
||||
|
||||
case "$1" in
|
||||
start|stop|restart|reload)
|
||||
if "$1"; then
|
||||
"$1"
|
||||
status=$?
|
||||
if [ "$status" -eq 0 ]; then
|
||||
echo "OK"
|
||||
else
|
||||
echo "FAIL"
|
||||
@@ -48,4 +50,4 @@ case "$1" in
|
||||
;;
|
||||
esac
|
||||
|
||||
exit $?
|
||||
exit "$status"
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# From https://sourceforge.net/projects/mpg123/files/mpg123/1.32.3/
|
||||
sha1 3a94848a620db7917c757cb21e261c711e44618f mpg123-1.32.3.tar.bz2
|
||||
# From https://sourceforge.net/projects/mpg123/files/mpg123/1.32.8/
|
||||
sha1 dc4d8d9d7fdc9c6c85e3036734eb937272a97800 mpg123-1.32.8.tar.bz2
|
||||
# Locally calculated
|
||||
sha256 2d9913a57d4ee8f497a182c6e82582602409782a4fb481e989feebf4435867b4 mpg123-1.32.3.tar.bz2
|
||||
sha256 feee1374c79540e0e405df0bc45fde20ad67011425c361a2759e2146894a27a7 mpg123-1.32.8.tar.bz2
|
||||
# License file
|
||||
sha256 c22482728a634a8dfdb4ff72a96d4c1ed64cd8f3e79335c401751ac591609366 COPYING
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
MPG123_VERSION = 1.32.3
|
||||
MPG123_VERSION = 1.32.8
|
||||
MPG123_SOURCE = mpg123-$(MPG123_VERSION).tar.bz2
|
||||
MPG123_SITE = https://downloads.sourceforge.net/project/mpg123/mpg123/$(MPG123_VERSION)
|
||||
MPG123_INSTALL_STAGING = YES
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
From e5adcd97b5196e29991b524237381a0202a60659 Mon Sep 17 00:00:00 2001
|
||||
From: Rich Felker <dalias@aerifal.cx>
|
||||
Date: Sun, 9 Feb 2025 10:07:19 -0500
|
||||
Subject: [PATCH] iconv: fix erroneous input validation in EUC-KR decoder
|
||||
|
||||
as a result of incorrect bounds checking on the lead byte being
|
||||
decoded, certain invalid inputs which should produce an encoding
|
||||
error, such as "\xc8\x41", instead produced out-of-bounds loads from
|
||||
the ksc table.
|
||||
|
||||
in a worst case, the loaded value may not be a valid unicode scalar
|
||||
value, in which case, if the output encoding was UTF-8, wctomb would
|
||||
return (size_t)-1, causing an overflow in the output pointer and
|
||||
remaining buffer size which could clobber memory outside of the output
|
||||
buffer.
|
||||
|
||||
bug report was submitted in private by Nick Wellnhofer on account of
|
||||
potential security implications.
|
||||
|
||||
Upstream: https://git.musl-libc.org/cgit/musl/commit/?id=e5adcd97b5196e29991b524237381a0202a60659
|
||||
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
|
||||
---
|
||||
src/locale/iconv.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/locale/iconv.c b/src/locale/iconv.c
|
||||
index 9605c8e9..008c93f0 100644
|
||||
--- a/src/locale/iconv.c
|
||||
+++ b/src/locale/iconv.c
|
||||
@@ -502,7 +502,7 @@ size_t iconv(iconv_t cd, char **restrict in, size_t *restrict inb, char **restri
|
||||
if (c >= 93 || d >= 94) {
|
||||
c += (0xa1-0x81);
|
||||
d += 0xa1;
|
||||
- if (c >= 93 || c>=0xc6-0x81 && d>0x52)
|
||||
+ if (c > 0xc6-0x81 || c==0xc6-0x81 && d>0x52)
|
||||
goto ilseq;
|
||||
if (d-'A'<26) d = d-'A';
|
||||
else if (d-'a'<26) d = d-'a'+26;
|
||||
--
|
||||
2.39.5
|
||||
|
||||
@@ -0,0 +1,40 @@
|
||||
From c47ad25ea3b484e10326f933e927c0bc8cded3da Mon Sep 17 00:00:00 2001
|
||||
From: Rich Felker <dalias@aerifal.cx>
|
||||
Date: Wed, 12 Feb 2025 17:06:30 -0500
|
||||
Subject: [PATCH] iconv: harden UTF-8 output code path against input decoder
|
||||
bugs
|
||||
|
||||
the UTF-8 output code was written assuming an invariant that iconv's
|
||||
decoders only emit valid Unicode Scalar Values which wctomb can encode
|
||||
successfully, thereby always returning a value between 1 and 4.
|
||||
|
||||
if this invariant is not satisfied, wctomb returns (size_t)-1, and the
|
||||
subsequent adjustments to the output buffer pointer and remaining
|
||||
output byte count overflow, moving the output position backwards,
|
||||
potentially past the beginning of the buffer, without storing any
|
||||
bytes.
|
||||
|
||||
Upstream: https://git.musl-libc.org/cgit/musl/commit/?id=c47ad25ea3b484e10326f933e927c0bc8cded3da
|
||||
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
|
||||
---
|
||||
src/locale/iconv.c | 4 ++++
|
||||
1 file changed, 4 insertions(+)
|
||||
|
||||
diff --git a/src/locale/iconv.c b/src/locale/iconv.c
|
||||
index 008c93f0..52178950 100644
|
||||
--- a/src/locale/iconv.c
|
||||
+++ b/src/locale/iconv.c
|
||||
@@ -545,6 +545,10 @@ size_t iconv(iconv_t cd, char **restrict in, size_t *restrict inb, char **restri
|
||||
if (*outb < k) goto toobig;
|
||||
memcpy(*out, tmp, k);
|
||||
} else k = wctomb_utf8(*out, c);
|
||||
+ /* This failure condition should be unreachable, but
|
||||
+ * is included to prevent decoder bugs from translating
|
||||
+ * into advancement outside the output buffer range. */
|
||||
+ if (k>4) goto ilseq;
|
||||
*out += k;
|
||||
*outb -= k;
|
||||
break;
|
||||
--
|
||||
2.39.5
|
||||
|
||||
26
package/musl/0006-m68k-fix-poll.patch
Normal file
26
package/musl/0006-m68k-fix-poll.patch
Normal file
@@ -0,0 +1,26 @@
|
||||
From b09e3174a695d1db60b2abc442d29ed3f87f0358 Mon Sep 17 00:00:00 2001
|
||||
From: Baruch Siach <baruch@tkos.co.il>
|
||||
Date: Wed, 7 Aug 2024 08:51:03 +0300
|
||||
Subject: m68k: fix POLLWRNORM and POLLWRBAND
|
||||
|
||||
As noted in commit f5011c62c3 ("fix POLLWRNORM and POLLWRBAND on mips")
|
||||
m68k uses a different definition.
|
||||
|
||||
Signed-off-by: Daniel Palmer <daniel@0x0f.com>
|
||||
Upstream: https://git.musl-libc.org/cgit/musl/commit/?id=b09e3174a695d1db60b2abc442d29ed3f87f0358
|
||||
---
|
||||
arch/m68k/bits/poll.h | 2 ++
|
||||
1 file changed, 2 insertions(+)
|
||||
create mode 100644 arch/m68k/bits/poll.h
|
||||
|
||||
diff --git a/arch/m68k/bits/poll.h b/arch/m68k/bits/poll.h
|
||||
new file mode 100644
|
||||
index 00000000..00063f41
|
||||
--- /dev/null
|
||||
+++ b/arch/m68k/bits/poll.h
|
||||
@@ -0,0 +1,2 @@
|
||||
+#define POLLWRNORM POLLOUT
|
||||
+#define POLLWRBAND 256
|
||||
--
|
||||
cgit v1.2.1
|
||||
|
||||
@@ -26,6 +26,10 @@ MUSL_ADD_TOOLCHAIN_DEPENDENCY = NO
|
||||
|
||||
MUSL_INSTALL_STAGING = YES
|
||||
|
||||
# 0004-iconv-fix-erroneous-input-validation-in-EUC-KR-decod.patch
|
||||
# 0005-iconv-harden-UTF-8-output-code-path-against-input-de.patch
|
||||
MUSL_IGNORE_CVES += CVE-2025-26519
|
||||
|
||||
# musl does not build with LTO, so explicitly disable it
|
||||
# when using a compiler that may have support for LTO
|
||||
ifeq ($(BR2_TOOLCHAIN_GCC_AT_LEAST_4_7),y)
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Locally calculated after checking pgp signature
|
||||
sha256 627fe086209bba80a2853a0add9d958d7ebbdffa1a8467a5784c9a6b4f03d738 nginx-1.26.2.tar.gz
|
||||
sha256 69ee2b237744036e61d24b836668aad3040dda461fe6f570f1787eab570c75aa nginx-1.26.3.tar.gz
|
||||
# License files, locally calculated
|
||||
sha256 f19c4caea60247490199c5a6d0134281e3fb20b3d7577e6873c628597f5381d9 LICENSE
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
NGINX_VERSION = 1.26.2
|
||||
NGINX_VERSION = 1.26.3
|
||||
NGINX_SITE = https://nginx.org/download
|
||||
NGINX_LICENSE = BSD-2-Clause
|
||||
NGINX_LICENSE_FILES = LICENSE
|
||||
|
||||
@@ -1,8 +1,10 @@
|
||||
# From https://nodejs.org/dist/v20.15.1/SHASUMS256.txt.asc
|
||||
sha256 10d47a46ef208b3e4b226e4d595a82659123b22397ed77b7975d989114ec317e node-v20.15.1-linux-arm64.tar.xz
|
||||
sha256 7bc120efdd8018f6915471b963d9b80adf4ed406d6dc9edb4ae944b85f505c4c node-v20.15.1-linux-armv7l.tar.xz
|
||||
sha256 b33e684802251397ad62ad3f8a1836267ee8b7723f87f669470018ad0035287b node-v20.15.1-linux-ppc64le.tar.xz
|
||||
sha256 26700f8d3e78112ad4a2618a9c8e2816e38a49ecf0213ece80e54c38cb02563f node-v20.15.1-linux-x64.tar.xz
|
||||
sha256 fdd53a5729d936691a2a1151046fb4897721cb8b0fca2af957823a9b40fe0c34 node-v20.15.1.tar.xz
|
||||
# From https://nodejs.org/dist/v20.18.2/SHASUMS256.txt.asc
|
||||
sha256 05819d72dcc0aa788baab1066e18ede5f1ab6730a1925cd6b15c131b55fd4272 node-v20.18.2-headers.tar.xz
|
||||
sha256 5c1437aa16e7e6a2e0687a42c4d3f0a8f8a2039cda8880cb3be8cd983aeefb44 node-v20.18.2-linux-arm64.tar.xz
|
||||
sha256 63d4df56fb2e34a5077345f78941094204d2223ce03b8ebc9c1500e6e2aae68d node-v20.18.2-linux-armv7l.tar.xz
|
||||
sha256 828a2635261ca225cd4a8a4b1a914003cdc7b30656c2e9092ac7aab02ac361db node-v20.18.2-linux-ppc64le.tar.xz
|
||||
sha256 4e50f727ae09bdafecf2322c72faf7cd82bf3b8851a16b8bb63974e0d8d6eceb node-v20.18.2-linux-x64.tar.xz
|
||||
sha256 69bf81b70f3a95ae0763459f02860c282d7e3a47567c8afaf126cc778176a882 node-v20.18.2.tar.xz
|
||||
|
||||
# Locally calculated
|
||||
sha256 49cd410e0fe6a8879a40d0764092d1e6114cc85fe41d4efed990d028eec25582 LICENSE
|
||||
sha256 4f0e8660d7fe2f8f7759a54c53907300c555992b580e846b30b75121c53ad180 LICENSE
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
################################################################################
|
||||
|
||||
# _VERSION, _SOURCE and _SITE must be kept empty to avoid downloading anything
|
||||
NODEJS_COMMON_VERSION = 20.15.1
|
||||
NODEJS_COMMON_VERSION = 20.18.2
|
||||
NODEJS_COMMON_SOURCE = node-v$(NODEJS_COMMON_VERSION).tar.xz
|
||||
NODEJS_COMMON_SITE = http://nodejs.org/dist/v$(NODEJS_COMMON_VERSION)
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
config BR2_PACKAGE_HOST_ODB
|
||||
bool "host-odb"
|
||||
bool "host odb"
|
||||
select BR2_NEEDS_HOST_GCC_PLUGIN_SUPPORT
|
||||
help
|
||||
This is a compiler that takes a specially crafted c++ header
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
# Locally computed:
|
||||
sha256 90e3896fed910c376aaf79cdd98bdfdaf98c6472efd8e1debf0a854938cbda6a openjpeg-2.5.2.tar.gz
|
||||
sha256 368fe0468228e767433c9ebdea82ad9d801a3ad1e4234421f352c8b06e7aa707 openjpeg-2.5.3.tar.gz
|
||||
sha256 a6af136f3e15038a666b61f376612a07d9a4e48cb7c01adbf3e33b3f14ab49b6 LICENSE
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
OPENJPEG_VERSION = 2.5.2
|
||||
OPENJPEG_VERSION = 2.5.3
|
||||
OPENJPEG_SITE = $(call github,uclouvain,openjpeg,v$(OPENJPEG_VERSION))
|
||||
OPENJPEG_LICENSE = BSD-2-Clause
|
||||
OPENJPEG_LICENSE_FILES = LICENSE
|
||||
|
||||
@@ -1,32 +0,0 @@
|
||||
From f9193f03db0029fc9c31fbdb5c66a2737446bd8f Mon Sep 17 00:00:00 2001
|
||||
From: Darren Tucker <dtucker@dtucker.net>
|
||||
Date: Mon, 25 Mar 2024 09:28:02 +1100
|
||||
Subject: [PATCH] Improve detection of -fzero-call-used-regs=used.
|
||||
|
||||
Should better detect problems with gcc 13 on m68k. bz#3673 from Colin
|
||||
Watson via bz#3673 and https://gcc.gnu.org/bugzilla/show_bug.cgi?id=110934
|
||||
|
||||
Signed-off-by: Darren Tucker <dtucker@dtucker.net>
|
||||
Upstream: https://github.com/openssh/openssh-portable/commit/f9193f03db0029fc9c31fbdb5c66a2737446bd8f
|
||||
---
|
||||
m4/openssh.m4 | 3 +++
|
||||
1 file changed, 3 insertions(+)
|
||||
|
||||
diff --git a/m4/openssh.m4 b/m4/openssh.m4
|
||||
index 033df501c3d8..176a8d1c9282 100644
|
||||
--- a/m4/openssh.m4
|
||||
+++ b/m4/openssh.m4
|
||||
@@ -20,7 +20,10 @@ char *f2(char *s, ...) {
|
||||
va_end(args);
|
||||
return strdup(ret);
|
||||
}
|
||||
+int i;
|
||||
+double d;
|
||||
const char *f3(int s) {
|
||||
+ i = (int)d;
|
||||
return s ? "good" : "gooder";
|
||||
}
|
||||
int main(int argc, char **argv) {
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,41 +0,0 @@
|
||||
From 7f4a743171f9e6b283207d448de6562219774fbf Mon Sep 17 00:00:00 2001
|
||||
From: Salvatore Bonaccorso <carnil@debian.org>
|
||||
Date: Tue, 25 Jun 2024 12:24:29 +0100
|
||||
Subject: Disable async-signal-unsafe code from the sshsigdie() function
|
||||
|
||||
Address signal handler race condition: if a client does not authenticate
|
||||
within LoginGraceTime seconds (120 by default, 600 in old OpenSSH
|
||||
versions), then sshd's SIGALRM handler is called asynchronously, but
|
||||
this signal handler calls various functions that are not
|
||||
async-signal-safe (for example, syslog()).
|
||||
|
||||
This is a regression from CVE-2006-5051 ("Signal handler race condition
|
||||
in OpenSSH before 4.4 allows remote attackers to cause a denial of
|
||||
service (crash), and possibly execute arbitrary code")
|
||||
|
||||
Signed-off-by: Salvatore Bonaccorso <carnil@debian.org>
|
||||
Upstream: https://salsa.debian.org/ssh-team/openssh/-/blob/525bb16e45edac4c03b95e106380d70aecbaf27e/debian/patches/sshsigdie-async-signal-unsafe.patch
|
||||
Patch-Name: sshsigdie-async-signal-unsafe.patch
|
||||
---
|
||||
log.c | 2 ++
|
||||
1 file changed, 2 insertions(+)
|
||||
|
||||
diff --git a/log.c b/log.c
|
||||
index 6a8b1fc4a..57256660f 100644
|
||||
--- a/log.c
|
||||
+++ b/log.c
|
||||
@@ -452,12 +452,14 @@ void
|
||||
sshsigdie(const char *file, const char *func, int line, int showfunc,
|
||||
LogLevel level, const char *suffix, const char *fmt, ...)
|
||||
{
|
||||
+#if 0
|
||||
va_list args;
|
||||
|
||||
va_start(args, fmt);
|
||||
sshlogv(file, func, line, showfunc, SYSLOG_LEVEL_FATAL,
|
||||
suffix, fmt, args);
|
||||
va_end(args);
|
||||
+#endif
|
||||
_exit(1);
|
||||
}
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# From https://www.openssh.com/txt/release-9.7
|
||||
sha256 490426f766d82a2763fcacd8d83ea3d70798750c7bd2aff2e57dc5660f773ffd openssh-9.7p1.tar.gz
|
||||
# From https://www.openssh.com/txt/release-9.9p2
|
||||
sha256 91aadb603e08cc285eddf965e1199d02585fa94d994d6cae5b41e1721e215673 openssh-9.9p2.tar.gz
|
||||
# Locally calculated
|
||||
sha256 05c30446ba738934b3f1efa965b454c122ca26cc4b268e5ae6843f58ccd1b16d LICENCE
|
||||
sha256 5bb5b160726ef5756e4f32fe95b35249c294962419650f48d05134b486d27ccb LICENCE
|
||||
|
||||
@@ -4,8 +4,8 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
OPENSSH_VERSION_MAJOR = 9.7
|
||||
OPENSSH_VERSION_MINOR = p1
|
||||
OPENSSH_VERSION_MAJOR = 9.9
|
||||
OPENSSH_VERSION_MINOR = p2
|
||||
OPENSSH_VERSION = $(OPENSSH_VERSION_MAJOR)$(OPENSSH_VERSION_MINOR)
|
||||
OPENSSH_CPE_ID_VERSION = $(OPENSSH_VERSION_MAJOR)
|
||||
OPENSSH_CPE_ID_UPDATE = $(OPENSSH_VERSION_MINOR)
|
||||
@@ -13,12 +13,6 @@ OPENSSH_SITE = http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable
|
||||
OPENSSH_LICENSE = BSD-3-Clause, BSD-2-Clause, Public Domain
|
||||
OPENSSH_LICENSE_FILES = LICENCE
|
||||
|
||||
# 0001-Improve-detection-of-fzero-call-used-regs-used.patch
|
||||
OPENSSH_AUTORECONF = YES
|
||||
|
||||
# 0002-sshsigdie-async-signal-unsafe.patch
|
||||
OPENSSH_IGNORE_CVES += CVE-2024-6387
|
||||
|
||||
OPENSSH_CONF_ENV = \
|
||||
LD="$(TARGET_CC)" \
|
||||
LDFLAGS="$(TARGET_CFLAGS)" \
|
||||
@@ -118,6 +112,7 @@ endif
|
||||
ifeq ($(BR2_PACKAGE_OPENSSH_SERVER),y)
|
||||
define OPENSSH_INSTALL_SERVER_PROGRAMS
|
||||
$(INSTALL) -D -m 0755 $(@D)/sshd $(TARGET_DIR)/usr/sbin/sshd
|
||||
$(INSTALL) -D -m 0755 $(@D)/sshd-session $(TARGET_DIR)/usr/libexec/sshd-session
|
||||
$(INSTALL) -D -m 0755 $(@D)/sftp-server $(TARGET_DIR)/usr/libexec/sftp-server
|
||||
endef
|
||||
OPENSSH_POST_INSTALL_TARGET_HOOKS += OPENSSH_INSTALL_SERVER_PROGRAMS
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
# Locally calculated after checking signature
|
||||
sha256 1c610fddeb686e34f1367c347e027e418e07523a10f4d8ce4a2c2af2f61a1929 openvpn-2.6.12.tar.gz
|
||||
sha256 1af10b86922bd7c99827cc0f151dfe9684337b8e5ebdb397539172841ac24a6a openvpn-2.6.13.tar.gz
|
||||
sha256 1fcb78d7e478bb8a9408010bdc91b36e213b1facfad093df3f7ce7e28af19043 COPYRIGHT.GPL
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
OPENVPN_VERSION = 2.6.12
|
||||
OPENVPN_VERSION = 2.6.13
|
||||
OPENVPN_SITE = https://swupdate.openvpn.net/community/releases
|
||||
OPENVPN_DEPENDENCIES = host-pkgconf libcap-ng
|
||||
OPENVPN_LICENSE = GPL-2.0
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
# From https://www.php.net/downloads.php
|
||||
sha256 54747400cb4874288ad41a785e6147e2ff546cceeeb55c23c00c771ac125c6ef php-8.2.26.tar.xz
|
||||
sha256 af8c9153153a7f489153b7a74f2f29a5ee36f5cb2c6c6929c98411a577e89c91 php-8.2.28.tar.xz
|
||||
|
||||
# License file
|
||||
sha256 b42e4df5e50e6ecda1047d503d6d91d71032d09ed1027ba1ef29eed26f890c5a LICENSE
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
PHP_VERSION = 8.2.26
|
||||
PHP_VERSION = 8.2.28
|
||||
PHP_SITE = https://www.php.net/distributions
|
||||
PHP_SOURCE = php-$(PHP_VERSION).tar.xz
|
||||
PHP_INSTALL_STAGING = YES
|
||||
|
||||
@@ -1173,7 +1173,7 @@ else
|
||||
endif # other packages
|
||||
|
||||
endif # redistribute
|
||||
@$$(call legal-manifest,$$(call UPPERCASE,$(4)),$$($(2)_RAWNAME),$$($(2)_VERSION),$$(subst $$(space)$$(comma),$$(comma),$$($(2)_LICENSE)),$$($(2)_MANIFEST_LICENSE_FILES),$$($(2)_ACTUAL_SOURCE_TARBALL),$$($(2)_ACTUAL_SOURCE_SITE),$$(call legal-deps,$(1)))
|
||||
@$$(call legal-manifest,$$(call UPPERCASE,$(4)),$$($(2)_RAWNAME),$$($(2)_DL_VERSION),$$(subst $$(space)$$(comma),$$(comma),$$($(2)_LICENSE)),$$($(2)_MANIFEST_LICENSE_FILES),$$($(2)_ACTUAL_SOURCE_TARBALL),$$($(2)_ACTUAL_SOURCE_SITE),$$(call legal-deps,$(1)))
|
||||
endif # ifneq ($$(call qstrip,$$($(2)_SOURCE)),)
|
||||
$$(foreach hook,$$($(2)_POST_LEGAL_INFO_HOOKS),$$(call $$(hook))$$(sep))
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# From https://ftp.postgresql.org/pub/source/v16.6/postgresql-16.6.tar.bz2.sha256
|
||||
sha256 23369cdaccd45270ac5dcc30fa9da205d5be33fa505e1f17a0418d2caeca477b postgresql-16.6.tar.bz2
|
||||
# From https://ftp.postgresql.org/pub/source/v16.8/postgresql-16.8.tar.bz2.sha256
|
||||
sha256 9468083a56ce0ee7d294601b74dad3dd9fc69d87aff61f0a9fb63c813ff7efd8 postgresql-16.8.tar.bz2
|
||||
# License file, Locally calculated
|
||||
sha256 9bf20ee493926a7e17a74bc7f05089fbc014269667b1540bc35a6b194a40c9de COPYRIGHT
|
||||
sha256 e3822c4797fadcab31a3fc73f75c28ac20c73d72b565da91e9974cf9398ef4d2 COPYRIGHT
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
POSTGRESQL_VERSION = 16.6
|
||||
POSTGRESQL_VERSION = 16.8
|
||||
POSTGRESQL_SOURCE = postgresql-$(POSTGRESQL_VERSION).tar.bz2
|
||||
POSTGRESQL_SITE = https://ftp.postgresql.org/pub/source/v$(POSTGRESQL_VERSION)
|
||||
POSTGRESQL_LICENSE = PostgreSQL
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user