Compare commits

..

124 Commits

Author SHA1 Message Date
Arnout Vandecappelle
93e8f75c55 Makefile: Update for 2026.05.3
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
2026-09-10 21:38:38 +02:00
Arnout Vandecappelle
4b06935cb0 CHANGES: Update for 2026.05.3
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
2026-09-10 21:36:58 +02:00
Romain Naour
ef196be6e5 board/qemu: add xtensa kernel patch
-fno-stack-protector must be passed to avoid linking errors related to
undefined references to '__stack_chk_guard' and '__stack_chk_fail' if
toolchain enforces -fstack-protector.

Fixes:
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15876432953

Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 79fd6241e4)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 16:10:29 +02:00
Sébastien Szymanski
c06375cd45 package/newt: update _SITE
Old URL returns 404, update _SITE to https://releases.pagure.org/newt

Signed-off-by: Sébastien Szymanski <sebastien.szymanski@armadeus.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 08cc0938b5)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 16:09:33 +02:00
Raphaël Mélotte
5e6c5523b6 DEVELOPERS: remove package/qemu-xen/
Commit 0b33e52c57 added
package/qemu-xen/ but it doesn't exist on 2026.05.x, so remove it.

Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 14:23:32 +02:00
Joseph Kogut
d7a74ddc65 package/passt: disable on uclibc
Upstream lists uClibc-ng support as a "nice-to-have, eventually", and
tracks the required build fixes as an enhancement:

https://bugs.passt.top/show_bug.cgi?id=5

passt relies on interfaces and definitions missing from uClibc,
resulting in build failures such as:

qrap.c:145:25: error: 'ARG_MAX' undeclared
tcp.c:2926:34: error: storage size of 'wnd' isn't known
tcp.c:3321:47: error: 'TCP_SEND_QUEUE' undeclared

Disable passt for uClibc toolchains and propagate the dependency to
Podman's passt backend.

Fixes:
 - http://autobuild.buildroot.org/results/7e4/7e4434e01baece4d090e44b4b3713f2eeefc1e27/
 - http://autobuild.buildroot.org/results/3f6/3f60889b4599f1bc42a69076f6fe469517ea9ab5/

Signed-off-by: Joseph Kogut <joseph@anodize.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 87e95b9877)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 14:23:32 +02:00
Julien Olivain
c63a52d3f9 package/igh-ethercat: remove stale patch 0002
igh-ethercat is failing while attempting to apply patches,
with error:

    Applying 0002-Linux-6.19.0-support.patch using patch:
    patching file devices/generic.c
    Reversed (or previously applied) patch detected!  Skipping patch.
    1 out of 1 hunk ignored -- saving rejects to file devices/generic.c.rej

The package patch 0002 was added in [1] in branch "master" while it
was in release client cycle. It was cherry-picked in [2] in branch
"next" to apply the bump [3] (which removes the package patches 0001
and 0002). When the branch "next" was merged in "master" in commit [4],
the patch 0002 was kept.

This commit removes this stale patch.

[1] e4cf512c39
[2] 8a5fc970b4
[3] 0a91e760f4
[4] 5f26877955

Fixes:
- https://autobuild.buildroot.org/results/4f509f1f788c1b8dc5a840ffa2e435c5ed7b6eea/

Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit d071817969)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 14:23:31 +02:00
Titouan Christophe
4f02d577b2 package/{glibc, localedef}: security bump to 2.43-63
This includes upstream fix for CVE-2026-18374, see
72351055c6

(alternative to commit 0838e968cb)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 14:23:31 +02:00
Bernd Kuhls
8107d801a1 package/libde265: security bump version to 1.1.2
https://github.com/strukturag/libde265/releases/tag/v1.1.2

Security fixes:
(CVE numbers will be added when assigned.)

CVE-2026-XXXXX (GHSA-xp3h-6f5r-8cxp) Heap use-after-free and double free
 in multi-threaded (WPP) decoding. A crafted stream whose slice segments
 repeat or rewind their slice_segment_address within a picture re-ran
 CTB rows that were already marked finished, so the CABAC context handoff
 between rows was no longer ordered and the shared context table was
 released twice. Slice segments that do not follow the previous one in
 tile-scan order are now rejected with the new warning
 DE265_WARNING_SLICE_SEGMENT_ADDRESS_NOT_INCREASING, and the WPP row
 progress is reset for each slice segment. (medium)

CVE-2026-XXXXX (GHSA-mm7m-v26f-wf8x) Heap use-after-free after
 de265_reset(): the pointer to the previous slice header was left
 dangling when the DPB was cleared, and a dependent slice pushed after
 the reset copied from freed memory. (medium)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit e55cb31085)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 14:23:31 +02:00
Bernd Kuhls
7a7ac06b15 package/libheif: security bump version to 1.23.3
https://github.com/strukturag/libheif/releases/tag/v1.23.3

Fixes the following CVEs:

(CVE numbers will be added when assigned.)

CVE-2026-XXXXX (GHSA-x8r2-mggj-j6wr) Heap buffer overflow (write) in the
 uncompressed (unci) mixed-interleave decoder when the two chroma
 components declare different bit depths. Both the written bytes and the
 overflow length are controlled by the file. (critical)

CVE-2026-XXXXX (GHSA-8fmq-r4pf-7m57) Permanent decoder deadlock through
 a reference cycle between an image and its alpha auxiliary image. The
 alpha edge was not covered by the cycle guard and re-entered a held
 mutex. (high)

CVE-2026-XXXXX (GHSA-w7mc-p8jc-p853) Heap out-of-bounds read in the
 YCbCr 4:2:0 to 16-bit interleaved RGB conversion when the chroma
 planes have a lower bit depth than luma. Heap memory could end up in
 the decoded image. YCbCr conversions with mismatched luma and chroma
 bit depths are now rejected. (high)

CVE-2026-XXXXX (GHSA-4jqm-2x34-6f6r) Heap buffer overflow in the SVT-AV1
 encoder plugin when encoding a high-bit-depth alpha channel, and a
 double free on its send-picture error path. (high)

CVE-2026-84451 (GHSA-hh47-fhqr-cj2r) Incomplete fix for
 GHSA-73p7-m7gg-w2jv: the tile range check of the unci decoder (without
 icef) could still overflow, allowing an out-of-bounds read. (medium)

CVE-2026-XXXXX (GHSA-4h82-g446-83fm) Heap out-of-bounds read when
 converting odd-height 4:2:0 frames of an uncompressed (uncv) image
 sequence to RGB. (medium)

CVE-2026-XXXXX (GHSA-9rj8-5mp5-26c9) Out-of-bounds read in the RGB to
 YCbCr identity-matrix color conversion when the R, G, and B planes
 have different bit depths. (medium)

CVE-2026-84450 (GHSA-gh5q-69gg-c964) A clap property combined with an
 oversized ispe reached an assert() in the Fraction arithmetic and
 aborted the process (incomplete fix for GHSA-jc8f-p23p-5hjg). An error
 is returned instead. (medium)

(GHSA-mw6f-29j3-76f4) Several smaller findings:
 heif_image_handle_get_depth_image_handle() and
 heif_image_handle_get_depth_image_representation_info() dereferenced a
 null pointer on files without a depth image; the TIFF input decoder of
 the example tools had an unbounded EXIF tag allocation and a division
 by zero on zero YCbCr subsampling; assert()s in the PNG input decoder
 are now error returns; integer overflow in the Go binding's
 ImageAccess.GetPlane(); heif-view now verifies the decoded frame size
 before display. (medium)

(GHSA-8857-r8x5-7499) Undefined behavior (negative shift) in the HDR
 bit-depth up-conversion for target bit depths above 16. Such
 conversions are now rejected. (low)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit d148168e20)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 14:23:31 +02:00
Bernd Kuhls
18dd913cdd package/openvpn: security bump version to 2.7.7
https://github.com/OpenVPN/openvpn/blob/v2.7.7/Changes.rst

Fixes CVE-2026-84732, the other CVEs are Windows-only.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 25b8142ef7)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 14:23:31 +02:00
Marcus Hoffmann
cbd02ce49f package/python-charset-normalizer: update package url
The old url redirects here.

Signed-off-by: Marcus Hoffmann <buildroot@bubu1.eu>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
(cherry picked from commit edb18cf3f2)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 14:23:31 +02:00
Bernd Kuhls
970b43c680 package/qt5/qt5knx: fix license hash
Buildroot 262a7f6d2f added the package but
forgot to provide the hash for LICENSE.GPL3-EXCEPT, instead a hash for
a non-existing file was added to qt5knx.hash.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit d2b7199dea)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 14:23:31 +02:00
Fengwei Tan
1eec20e67f support/testing, toolchain/toolchain-external/toolchain-external-bootlin: regenerate after MMU dependency update
Regenerate the Bootlin toolchain Kconfig and test configurations using
support/scripts/gen-bootlin-toolchains.

This adds BR2_USE_MMU to the affected uClibc entries and to the
architecture support conditions, and updates the generated tests.
The glibc and musl changes only reorder their existing BR2_USE_MMU
dependencies.

Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 9c6eed9ec0)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 14:23:31 +02:00
Fengwei Tan
9584c2499a support/scripts/gen-bootlin-toolchains: add missing BR2_USE_MMU dependencies
The Bootlin uClibc toolchains for m68k-68xxx, riscv32-ilp32d, and
xtensa-lx60 require an MMU. However, their generated Kconfig entries
lack a BR2_USE_MMU dependency, allowing them to be selected for noMMU
configurations. External toolchain validation then fails with:

  MMU support available in C library, please enable BR2_USE_MMU

Add the missing BR2_USE_MMU dependencies for these architectures to
prevent them from being selected for noMMU targets.

Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 3469c6793c)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 14:23:31 +02:00
Fengwei Tan
9f4714c066 toolchain/toolchain-external/toolchain-external-bootlin: drop duplicate BR2_TOOLCHAIN_HAS_THREADS selections
Regenerate the Bootlin toolchain Kconfig file with
support/scripts/gen-bootlin-toolchains to remove duplicate
BR2_TOOLCHAIN_HAS_THREADS selections.

Commit 184d47a7ad ("support/scripts/gen-bootlin-toolchains: add new
script to support Bootlin toolchains") initially introduced this issue.

Although commit a33e1af4a0 ("support/scripts/gen-bootlin-toolchains:
avoid selecting _HAS_THREADS multiple times") fixed the generator script,
the Config.in.options file was not regenerated accordingly.

This is a non-functional cleanup, as repeated Kconfig select statements
are harmless.

Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 9556895e78)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 14:23:31 +02:00
Franciszek Stachura
51bf18c88b support/testing: add nano test
Add a basic runtime test for nano. The test attempts to write a file
using the editor.

Signed-off-by: Franciszek Stachura <fbstachura@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 0e631348db)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 14:23:31 +02:00
Bernd Kuhls
20018ba764 package/libxml2: security bump version to 2.15.4
https://download.gnome.org/sources/libxml2/2.15/libxml2-2.15.4.news

Fixes the following security issues:

- xmlregexp: Prevent out-of-bounds read in NXT macro
- fix: add missing overflow checks in dict.c, uri.c, and valid.c
- xmlregexp: Calc string length after null checking
- xpointer: Check overflow in xmlXPtrEvalXPtrPart
- xmlIO: Check for int overflow before calling writecallback
- fix(xinclude): propagate parseFlags in xmlXIncludeProcess and
  xmlXIncludeProcessTree

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
(cherry picked from commit 270ef20df1)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:36:41 +02:00
Bernd Kuhls
a30c556ac8 package/wireless-regdb: bump version to 2026.09.03
https://lists.infradead.org/pipermail/wireless-regdb/2026-September/001953.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
(cherry picked from commit 47c45f7f62)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:30:26 +02:00
Martin Bachmann
ddab8aef0d package/dejavu: add missing license information
DEJAVU_LICENSE is primarily BitstreamVera. The license file also
specifies that DejaVu-specific changes and certain math extensions are
in the Public Domain. This matches the licensing logic used by
OpenEmbedded/Yocto.

Signed-off-by: Martin Bachmann <martin.bachmann@designwerk.com>
[Fiona: wrap lines in commit message]
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
(cherry picked from commit df61b7e9bb)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:26:59 +02:00
Thomas Perale
50a4314e75 package/erlang: security bump to v26.2.5.21
See the changelogs:

- https://www.erlang.org/patches/OTP-26.2.5.16
- https://www.erlang.org/patches/OTP-26.2.5.17
- https://www.erlang.org/patches/OTP-26.2.5.18
- https://www.erlang.org/patches/OTP-26.2.5.19
- https://www.erlang.org/patches/OTP-26.2.5.20
- https://www.erlang.org/patches/OTP-26.2.5.21

This fixes the following vulnerabilities:

- CVE-2026-21620:
    Relative Path Traversal, Improper Isolation or Compartmentalization
    vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp
    inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows
    Relative Path Traversal. This vulnerability is associated with program
    files lib/tftp/src/tftp_file.erl, src/tftp_file.erl.

For more information, see:
 - https://www.cve.org/CVERecord?id=CVE-2026-21620

- CVE-2026-23941:
    Inconsistent Interpretation of HTTP Requests ('HTTP Request
    Smuggling') vulnerability in Erlang OTP (inets httpd module) allows
    HTTP Request Smuggling.  This vulnerability is associated with program
    files lib/inets/src/http_server/httpd_request.erl and program routines
    httpd_request:parse_headers/7.  The server does not reject or
    normalize duplicate Content-Length headers. The earliest Content-
    Length in the request is used for body parsing while common reverse
    proxies (nginx, Apache httpd, Envoy) honor the last Content-Length
    value. This violates RFC 9112 Section 6.3 and allows front-end/back-
    end desynchronization, leaving attacker-controlled bytes queued as the
    start of the next request.

For more information, see:
 - https://www.cve.org/CVERecord?id=CVE-2026-23941

- CVE-2026-23942:
    Improper Limitation of a Pathname to a Restricted Directory ('Path
    Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path
    Traversal.  This vulnerability is associated with program files
    lib/ssh/src/ssh_sftpd.erl and program routines
    ssh_sftpd:is_within_root/2.  The SFTP server uses string prefix
    matching via lists:prefix/2 rather than proper path component
    validation when checking if a path is within the configured root
    directory. This allows authenticated users to access sibling
    directories that share a common name prefix with the configured root
    directory. For example, if root is set to /home/user1, paths like
    /home/user10 or /home/user1_backup would incorrectly be considered
    within the root.

For more information, see:
 - https://www.cve.org/CVERecord?id=CVE-2026-23942

- CVE-2026-23943:
    Improper Handling of Highly Compressed Data (Compression Bomb)
    vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial
    of Service via Resource Depletion.  The SSH transport layer advertises
    legacy zlib compression by default and inflates attacker-controlled
    payloads pre-authentication without any size limit, enabling reliable
    memory exhaustion DoS.  Two compression algorithms are affected:  *
    zlib: Activates immediately after key exchange, enabling
    unauthenticated attacks * zlib@openssh.com: Activates post-
    authentication, enabling authenticated attacks  Each SSH packet can
    decompress ~255 MB from 256 KB of wire data (1029:1 amplification
    ratio). Multiple packets can rapidly exhaust available memory, causing
    OOM kills in memory-constrained environments.  This vulnerability is
    associated with program files lib/ssh/src/ssh_transport.erl and
    program routines ssh_transport:decompress/2,
    ssh_transport:handle_packet_part/4.

For more information, see:
 - https://www.cve.org/CVERecord?id=CVE-2026-23943

- CVE-2026-28810:
    Generation of Predictable Numbers or Identifiers vulnerability in
    Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache
    Poisoning.  The built-in DNS resolver (inet_res) uses a sequential,
    process-global 16-bit transaction ID for UDP queries and does not
    implement source port randomization. Response validation relies almost
    entirely on this ID, making DNS cache poisoning practical for an
    attacker who can observe one query or predict the next ID. This
    conflicts with RFC 5452 recommendations for mitigating forged DNS
    answers.  inet_res is intended for use in trusted network environments
    and with trusted recursive resolvers. Earlier documentation did not
    clearly state this deployment assumption, which could lead users to
    deploy the resolver in environments where spoofed DNS responses are
    possible.  This vulnerability is associated with program files
    lib/kernel/src/inet_db.erl and lib/kernel/src/inet_res.erl.

For more information, see:
 - https://www.cve.org/CVERecord?id=CVE-2026-28810

- CVE-2026-32147:
    Improper Limitation of a Pathname to a Restricted Directory ('Path
    Traversal') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows
    an authenticated SFTP user to modify file attributes outside the
    configured chroot directory.  The SFTP daemon (ssh_sftpd) stores the
    raw, user-supplied path in file handles instead of the chroot-resolved
    path. When SSH_FXP_FSETSTAT is issued on such a handle, file
    attributes (permissions, ownership, timestamps) are modified on the
    real filesystem path, bypassing the root directory boundary entirely.
    Any authenticated SFTP user on a server configured with the root
    option can modify file attributes of files outside the intended chroot
    boundary. The prerequisite is that a target file must exist on the
    real filesystem at the same relative path. Note that this
    vulnerability only allows modification of file attributes; file
    contents cannot be read or altered through this attack vector.  If the
    SSH daemon runs as root, this enables direct privilege escalation: an
    attacker can set the setuid bit on any binary, change ownership of
    sensitive files, or make system configuration world-writable.  This
    vulnerability is associated with program files
    lib/ssh/src/ssh_sftpd.erl and program routines ssh_sftpd:do_open/4 and
    ssh_sftpd:handle_op/4.

For more information, see:
  - https://www.cve.org/CVERecord?id=CVE-2026-32147

- CVE-2026-42789:
    Improper Following of a Certificate's Chain of Trust vulnerability in
    Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate
    to be accepted as an intermediate issuer, enabling certificate chain
    forgery.  In lib/public_key/src/pubkey_cert.erl,
    pubkey_cert:validate_extensions/7 contains two flaws that together
    allow a certificate with basicConstraints cA:false and no keyUsage
    extension to be used as an intermediate issuer in a chain passed to
    public_key:pkix_path_validation/3: the cA:false clause recurses into
    the remaining extensions without rejecting the certificate when it is
    in issuer position, and the keyUsage check only fires when the
    extension is present, so a certificate lacking keyUsage entirely
    bypasses the keyCertSign enforcement.  Any party holding an end-entity
    certificate with basicConstraints cA:false and no keyUsage extension,
    issued by any CA in the victim's trust store, can use that
    certificate's private key to sign forged leaf certificates for
    arbitrary identities. public_key:pkix_path_validation/3 accepts the
    resulting chain, and by extension every TLS or mTLS endpoint built on
    the OTP ssl application that relies on the default verifier is
    affected, including server identity verification on the client side
    and client certificate verification on mTLS servers.

For more information, see:
 - https://www.cve.org/CVERecord?id=CVE-2026-42789

- CVE-2026-42790:
    Improper Certificate Validation vulnerability in Erlang OTP public_key
    (pubkey_cert and public_key modules) allows a DNS nameConstraints
    bypass via subject CommonName fallback in TLS hostname verification.
    Two flaws combine to allow a subordinate CA whose DNS nameConstraints
    are restricted (e.g. permitted;DNS:allowed.example.com) to issue a
    leaf certificate that an OTP TLS client accepts as a valid identity
    for an out-of-scope hostname (e.g. victim.example.com):  First,
    pubkey_cert:validate_names/6 in lib/public_key/src/pubkey_cert.erl
    only checks SAN DNS entries against nameConstraints. Per RFC 5280, a
    permitted DNS subtree only restricts certificates that contain a DNS-
    typed name. A leaf with no subjectAltName therefore trivially
    satisfies any permitted;DNS:... constraint regardless of its subject
    commonName.  Second, public_key:pkix_verify_hostname/3 in
    lib/public_key/src/public_key.erl falls back to the subject commonName
    when no subjectAltName is present, extracting id-at-commonName
    attributes as presented IDs and matching them against the reference
    hostname. The strict pkix_verify_hostname_match_fun(https) matcher
    does not suppress this fallback.  The result is that path validation
    accepts a CN-only leaf under a DNS-constrained intermediate (no SAN
    means the nameConstraints are not triggered), and hostname
    verification then accepts it via the CN fallback. The bypass is
    reachable from stock ssl:connect with verify_peer, a trusted CA, SNI,
    and the canonical strict https hostname matcher.

For more information, see:
 - https://www.cve.org/CVERecord?id=CVE-2026-42790

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit dfc909b1cd)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:21:30 +02:00
Bernd Kuhls
88f56e872c package/libcurl: security bump to version 8.22.0
https://curl.se/ch/8.22.0.html
https://daniel.haxx.se/blog/2026/09/02/curl-8-22-0/

Fixes the following CVEs:
CVE-2026-13608: OpenLDAP SASL authentication bypass
CVE-2026-18924: HTTP/2 server push UAF
CVE-2026-19931: Negotiate ambient user conn reuse
CVE-2026-80229: OpenSSL provider use-after-free
CVE-2026-80230: OpenSSL pinning bypass
CVE-2026-80231: native CA store conn reuse
CVE-2026-80255: secure cookie attribute bypass with tab
CVE-2026-82208: wolfSSL CA-cache hit overrides callback
CVE-2026-82209: domain-scoped PSL domain cookie

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit ad9557dba5)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:21:14 +02:00
Bernd Kuhls
0340959951 package/libopenssl: disable atomic operations for m68k Coldfire
This patch fixes a build error with OpenSSL-enabled libcurl which was
detected by the Gitlab pipelines:

checking for openssl options with pkg-config... found
configure: pkg-config: SSL_LIBS: "-lssl -lcrypto -pthread"
configure: pkg-config: SSL_LDFLAGS: "-L/builds/bkuhls/buildroot/br-test-pkg/bootlin-m68k-5208-uclibc/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib"
configure: pkg-config: SSL_CPPFLAGS: ""
checking for HMAC_Update in -lcrypto... no
checking for HMAC_Init_ex in -lcrypto... no
checking OpenSSL linking with -ldl... no
checking OpenSSL linking with -ldl and -lpthread... no
checking for SSL_set_quic_use_legacy_codepoint... no
checking for SSL_set_quic_tls_cbs... no
configure: OpenSSL version does not speak any known QUIC API
configure: OPT_OPENSSL: /builds/bkuhls/buildroot/br-test-pkg/bootlin-m68k-5208-uclibc/host/m68k-buildroot-uclinux-uclibc/sysroot/usr
configure: OPENSSL_ENABLED:
configure: error: --with-openssl was given but OpenSSL could not be detected
make[1]: *** [package/pkg-generic.mk:263: /builds/bkuhls/buildroot/br-test-pkg/bootlin-m68k-5208-uclibc/build/libcurl-8.21.0/.stamp_configured] Error 1

Although OpenSSL was found using pkg-config the build tests fail.

A local build shows the concrete error in config.log, for example:

configure:27577: checking for HMAC_Update in -lcrypto
configure:27599: /home/bernd/buildroot/output/host/bin/m68k-linux-gcc
 -o conftest -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE
 -D_FILE_OFFSET_BITS=64 -O2 -g0 -fno-dwarf2-cfi-asm -Wl,-elf2flt=-r
 -static -Werror-implicit-function-declaration -Wno-system-headers
 -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64
 -D_GNU_SOURCE     -Wl,-elf2flt=-r -static
 -L/home/bernd/buildroot/output/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib
 -L/home/bernd/buildroot/output/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib
 conftest.c -lcrypto  -lssl -lcrypto -lz -pthread -lz  >&5
/home/bernd/buildroot/output/host/opt/ext-toolchain/m68k-buildroot-uclinux-uclibc/bin/ld.real:
 /home/bernd/buildroot/output/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib/libcrypto.a(libcrypto-lib-threads_pthread.o):
 in function `ossl_rcu_read_lock':
threads_pthread.c:(.text+0xa4): undefined reference to `__atomic_fetch_add_8'

This error occurs many times for various atomic operations:

$ grep "undefined reference to \`__atomic" output/build/libcurl-8.20.0/config.log | sort -u | grep -v real
threads_pthread.c:(.text+0x28a): undefined reference to `__atomic_fetch_sub_8'
threads_pthread.c:(.text+0x3b4): undefined reference to `__atomic_fetch_add_8'
threads_pthread.c:(.text+0x9c8): undefined reference to `__atomic_is_lock_free'
threads_pthread.c:(.text+0xa4): undefined reference to `__atomic_fetch_add_8'
threads_pthread.c:(.text+0xa9c): undefined reference to `__atomic_is_lock_free'
threads_pthread.c:(.text+0xb66): undefined reference to `__atomic_is_lock_free'
threads_pthread.c:(.text+0xc30): undefined reference to `__atomic_is_lock_free'
threads_pthread.c:(.text+0xcdc): undefined reference to `__atomic_is_lock_free'

The build error can be reproduced with the current buildroot tree using
this defconfig:

BR2_m68k=y
BR2_m68k_cf5208=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_M68K_COLDFIRE_UCLIBC_STABLE=y
BR2_PACKAGE_OPENSSL=y
BR2_PACKAGE_LIBCURL=y

Although the toolchain lacks atomics support

$ grep ATOMIC .config
$

it emits atomic-related defines, for example:

$ echo | output/host/bin/m68k-linux-gcc -dM -E - | grep __ATOMIC_ACQ_REL
#define __ATOMIC_ACQ_REL 4
$

This specific define __ATOMIC_ACQ_REL is used in OpenSSL to enable
atomic support at various places:
https://github.com/openssl/openssl/blob/openssl-3.6.3/crypto/threads_pthread.c

causing the build errors we see with the mentioned defconfig.

To fix the problem we use an OpenSSL-provided define to forcefully
disable the usage of atomic intrinsics.

The misdetection of atomic intrinsics for m68k coldfire is not a new
problem:
https://lists.buildroot.org/pipermail/buildroot/2017-May/180841.html
https://lists.buildroot.org/pipermail/buildroot/2026-May/803110.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 5f8d0b78ec)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:20:58 +02:00
Peter Korsgaard
85e4676cad package/exiv2: security bump to version 0.28.9
Fixes the following vulnerabilities:

CVE-2026-68546: Heap out-of-bounds write in RemoteIo when reading from a
malicious remote server (WebReady/Curl builds)
https://github.com/Exiv2/exiv2/security/advisories/GHSA-3695-mjv8-3r52

CVE-2026-68547: Heap out-of-bounds read in RemoteIo when reading
block-aligned remote CRW files
https://github.com/Exiv2/exiv2/security/advisories/GHSA-jcgh-p9v3-pw6j

CVE-2026-49275: Out of bounds read in CrwMap::decodeBasic
https://github.com/Exiv2/exiv2/security/advisories/GHSA-hxph-pv7w-8649

Out-of-bounds write in RemoteIo::mmap
https://github.com/Exiv2/exiv2/security/advisories/GHSA-vg6c-9f6h-4x5q

Out of bounds write in http.cpp
https://github.com/Exiv2/exiv2/security/advisories/GHSA-9v3x-mhg4-wwv2

Infinite loop in QuickTimeVideo::userDataDecoder
https://github.com/Exiv2/exiv2/security/advisories/GHSA-fgw8-p7pr-37cp

For more details, see the announcement:
https://www.openwall.com/lists/oss-security/2026/08/30/1

Notice: the RemoteIo-related vulnerabilities are not applicable for
Buildroot as exiv2 is not built with libcurl support.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 94013c3a95)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:19:59 +02:00
Romain Naour
f0fd90b696 linux: disable SSP support when needed
x86 and x86_64 kernels >= 6.15 now requires ssp toolchain support
when CONFIG_STACKPROTECTOR is enabled [1].

For toolchains without SSP support, make sure to disable
CONFIG_STACKPROTECTOR to avoid link issues when building kernel
modules.

  MODPOST Module.symvers
  ERROR: modpost: "__stack_chk_guard" [drivers/<module>.ko] undefined!

While the SSP support is mandatory for glibc and musl based toolchains
[2], it's still optional for uClibc-ng based toolchains and not enabled
by default when building a new toolchain.

The Toolchain builder project enabled recently the SSP support for all
uClibc toolchains [3] to avoid such issue.

But x86 (32bits) musl based toolchains lack of SSP support due to a
long term gcc issue [4]. For a decade Alpine Linux, OpenWRT and Yocto
povide additional gcc and musl patches to workaround the gcc issue [5]

We may consider in the long term removing the support for toolchains
without SSP and doing so removing x86 (32bits) musl toolchain.

Fixes:
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832356731 (x86-64--uclibc--bleeding-edge_test)
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832356104 (x86-64--uclibc--stable_test)

https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832355429 (x86-64-core-i7--uclibc--bleeding-edge_test)
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832354341 (x86-64-core-i7--uclibc--stable_test)

https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832326525 (x86-64-v2--uclibc--bleeding-edge_test)
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832316220 (x86-64-v2--uclibc--stable_test)

https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139512 (x86-i686--uclibc--stable_test)
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139511 (x86-i686--uclibc--bleeding-edge_test)

https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139510 (x86-i686--musl--stable_test)
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139509 (x86-i686--musl--bleeding-edge_test)

https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139506 (x86-core2--uclibc--stable_test)
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139505 (x86-core2--uclibc--bleeding-edge_test)

https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139504 (x86-core2--musl--stable_test)
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139503 (x86-core2--musl--bleeding-edge_test)

[1] https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=0ee2689b9374d6fd5f43b703713a53227
[2] e811f51549
[3] 90413f6657
[4] https://www.openwall.com/lists/musl/2016/12/04/2
[5] https://git.alpinelinux.org/aports/tree/main/musl/APKBUILD#n65
    https://git.alpinelinux.org/aports/tree/main/gcc/0018-Alpine-musl-package-provides-libssp_nonshared.a.-We-.patch
    https://github.com/openwrt/openwrt/blob/v25.12.5/toolchain/gcc/patches-15.x/230-musl_libssp.patch
    https://github.com/openwrt/openwrt/blob/v25.12.5/toolchain/musl/patches/200-add_libssp_nonshared.patch
    77fb841f2e

Cc: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 32b4f3f942)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:19:11 +02:00
Romain Naour
19d5d8caf9 support/testing: TestMdnsd: improve test reliability
The mdnsd runtime test can randomly fail on slow runners.

It's hard to reproduce locally (only one failure after a few attempts)
but we can reproduce it easily by removing the while loop entirely.

It turns out that mdnsd is started by S50mdnsd before the
emulator.login() change the system date:

  [BRTEST# date -s @1788032864
  Sat Aug 29 19:47:44 UTC 2026

Since the minimal rootfs.cpio generated	for TestMdnsd doesn't have any
ntp client installed, it start with "January 1, 1970".

The date change may cause some issue to the mdnsd daemon which blocks
any response from mquery command.

When the problem occurs, "mquery -T _http._tcp" reply is empty:

  # mquery -T _http._tcp
  Querying _http._tcp.local. for PTR (12) ... press Ctrl-C to stop

To workaround the issue, restart mdnsd manually.

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16185948555

Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 45636d67c9)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:19:08 +02:00
Fiona Klute (othermo GmbH)
caf1881c63 package/dracut: pass HOST_CONFIGURE_OPTS to make
Dracut-internal executables were linked against system libraries,
instead of Buildroot host packages. For example:

$ ldd host/lib/dracut/dracut-install
	linux-vdso.so.1 (0x00007f578cf06000)
	libc.so.6 => /usr/lib/x86_64-linux-gnu/libc.so.6 (0x00007f578cccd000)
	libkmod.so.2 => /usr/lib/x86_64-linux-gnu/libkmod.so.2 (0x00007f578ccb1000)
	/lib64/ld-linux-x86-64.so.2 (0x00007f578cf08000)
	libcrypto.so.3 => /usr/lib/x86_64-linux-gnu/libcrypto.so.3 (0x00007f578c600000)
	libz.so.1 => /usr/lib/x86_64-linux-gnu/libz.so.1 (0x00007f578cc92000)
	libzstd.so.1 => /usr/lib/x86_64-linux-gnu/libzstd.so.1 (0x00007f578c536000)

The reason is that Dracut is not a "real" autoconf package, and the
hand-written ./configure script does not preserve LDFLAGS for
make. Pass the environment variables directly to fix this.

Signed-off-by: Fiona Klute (othermo GmbH) <fiona.klute@gmx.de>
[Julien: add comment in dracut.mk]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 45acb281ca)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:19:06 +02:00
Thomas Petazzoni
d928b8ff37 package/dpdk: make the libvirt dependency explicit
examples/vm_power_manager/meson.build in DPDK detects the presence of
libvirt:

opt_dep = cc.find_library('virt', required : false)

and then builds some examples or not depending on the availability of
libvirt. Let's make this optional dependency explicit in dpdk.mk, even
if there's no explicit enable/disable option for it.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 55a7ece9e5)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:19:03 +02:00
Thomas Petazzoni
4c87c3a547 package/dpdk: fix example build issue when libvirt is present
When libvirt is present before DPDK is built, some additional examples
are compiled. One of them fails to build due to a missing <stdlib.h>
include. Let's import a patch from OpenSuse, that we have submitted
upstream, to fix this issue.

We couldn't find any autobuilder failure for this issue, but the
following defconfig allows to reproduce the failure:

BR2_aarch64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
BR2_PACKAGE_DPDK=y
BR2_PACKAGE_DPDK_EXAMPLES=y
BR2_PACKAGE_LIBVIRT=y

The problem exists since DPDK v19.11, so it has been in Buildroot
since DPDK was introduced in commit
d17d1b6bde.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit db3d0d44ac)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:19:00 +02:00
Julien Olivain
5738c7a254 package/perl: apply perl-cross patch only on target perl
Buildroot commit [1] (package/perl: fix build issue with musl)
introduced a patch that is meant to be applied on top of perl-cross,
which is extracted on top of perl only in the target variant.

Since the patch was introduced as a normal package patch, the Buildroot
infra is trying to always apply it, even for the host package variant.
Since perl-cross is not extracted for the host variant, some patched
files are missing. In that case, the host-perl is failing with error:

    >>> host-perl 5.42.3 Patching
    Applying 0001-configure-keep-_GNU_SOURCE-in-build-flags.patch using patch:
    can't find file to patch at input line 46

This commit fixes the issue by moving the package patch in a dedicated
"perl-cross" subdirectory, to make sure it will no longer be applied by
the infra. We apply the patch only for the target package variant using
a _POST_PATCH_HOOKS hook.

Fixes:
- [1]
- https://gitlab.com/buildroot.org/buildroot/-/jobs/16185948610 (TestPerlXMLLibXML)
- ...and few other tests requiring host-perl

[1] d950fff290

Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 8dea6e7c08)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:18:57 +02:00
Thomas Petazzoni
82a3b54ce6 package/libnfs: fix gnutls support
In Buildroot commit a035a0f99f, libnfs
was bumped from 5.0.3 to 6.0.2, and 6.0.2 brought optional gnutls
support.

Unfortunately, the gnutls support was a bit buggy, as the libnfs
library ends up using gnutls symbols without being linked to
libgnutls, causing build failures down the road when other packages
try to link against libnfs.

We backport 3 commits from upstream 6.0.2..7.0.0 to address this
issue.

Fixes:

  https://autobuild.buildroot.net/results/b070248b2bceaceaaed8e826b1247ccfba1ba9fb
  https://autobuild.buildroot.net/results/e1461b76121addd8f04f08819b2e3e453a12c679
  https://autobuild.buildroot.net/results/87c79193d2ea86f47e36232fe514837ad99c5f30

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Tested-by: Andreas Ziegler <br025@umbiko.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 88a4958afa)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:18:54 +02:00
Bernd Kuhls
8d0417d8bf package/proftpd: security bump version to 1.3.9d
https://github.com/proftpd/proftpd/blob/v1.3.9d/NEWS

Version 1.3.9b fixes CVE-2026-44331.

Switched to sha256 tarball hash provided by upstream.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 3577d1442e)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:18:52 +02:00
Jimmy Durand Wesolowski
07f7dd7d03 package/openssh: ensure libxcrypt is enabled to provide a crypt() implementation
When OpenSSL is enabled, if DES support is enabled, OpenSSH uses
DES_crypt. However, without OpenSSL or its DES support, there is no
available crypt() implementation for OpenSSH libopenbsd-compat xcrypt()
function, resulting in the following error:

.../host/bin/i686-buildroot-linux-gnu-gcc -o sshd-auth sshd-auth.o
  auth2-methods.o auth-rhosts.o auth-passwd.o sshpty.o sshlogin.o
  servconf.o serverloop.o auth.o auth2.o auth-options.o session.o
  auth2-chall.o groupaccess.o auth-bsdauth.o auth2-hostbased.o
  auth2-kbdint.o auth2-none.o auth2-passwd.o auth2-pubkey.o
  auth2-pubkeyfile.o auth2-gss.o gss-serv.o gss-serv-krb5.o
  monitor_wrap.o auth-krb5.o audit.o audit-bsm.o audit-linux.o
  platform.o loginrec.o auth-pam.o auth-shadow.o auth-sia.o
  sandbox-null.o sandbox-rlimit.o sandbox-darwin.o
  sandbox-seccomp-filter.o sandbox-capsicum.o sandbox-solaris.o
  sftp-server.o sftp-common.o uidswap.o ssh-pkcs11-client.o
  ssh-sk-client.o -L. -Lopenbsd-compat/ -D_LARGEFILE_SOURCE
  -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0
  -D_FORTIFY_SOURCE=1 -Wl,-z,relro -Wl,-z,now -Wl,-z,noexecstack
  -fstack-protector-strong -pie -lssh -lopenbsd-compat
  -L.../host/bin/../i686-buildroot-linux-gnu/sysroot/usr/lib
  -lssl -lcrypto -lcrypto -lz
.../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../
  i686-buildroot-linux-gnu/bin/ld:
  openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt':
xcrypt.c:(.text+0x51): undefined reference to `crypt'
.../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../
  i686-buildroot-linux-gnu/bin/ld:
openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt':
xcrypt.c:(.text+0x51): undefined reference to `crypt' collect2: error:
ld returned 1 exit status make[2]: *** [Makefile:233: sshd-auth] Error
1 make[2]: *** Waiting for unfinished jobs....  collect2: error: ld
returned 1 exit status make[2]: *** [Makefile:230: sshd-session] Error
1 make[1]: *** [package/pkg-generic.mk:273:
.../build/openssh-10.4p1/.stamp_built]
Error 2 make: *** [Makefile:83: _all] Error 2

This commit enables BR2_PACKAGE_LIBXCRYPT with OpenSSH as long as
glibc is used. Since "sshd-auth" is compiled regardless of
BR2_PACKAGE_OPENSSH_SERVER, we need to enable it with BR2_PACKAGE_OPENSSH.

Signed-off-by: Jimmy Durand Wesolowski <jimmy.wesolowski@mobileye.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 913512e302)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:18:49 +02:00
Bernd Kuhls
6acf07c704 package/expat: security bump version to 2.8.4
https://github.com/libexpat/libexpat/blob/R_2_8_4/expat/Changes
https://blog.hartwork.org/posts/expat-2-8-4-released/

Fixes CVE-2026-66046, CVE-2026-76641, CVE-2026-76956 & CVE-2026-76957.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 4c504ef75d)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:18:45 +02:00
Titouan Christophe
5594aeb3c7 {linux, linux-headers}: bump 5.{10,15}, 6.{1,6,12,18} series
Update the latest kernel releases:
    - 5.10.268 -> 5.10.269
    - 5.15.219 -> 5.15.220
    - 6.1.186 -> 6.1.187
    - 6.6.155 -> 6.6.156
    - 6.12.107 -> 6.12.109
    - 6.18.48 -> 6.18.50

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-09-07 19:18:13 +02:00
Bernd Kuhls
4a7136948f package/dnsmasq: bump version to 2.93
https://thekelleys.org.uk/dnsmasq/CHANGELOG

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 374d0a02e4)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-04 14:24:50 +02:00
Titouan Christophe via buildroot
6f8312c820 package/vim: fix hash for README.txt
Buildroot commit 297f6f1921 updated vim.
However README.txt (used as part of the license hash check) has been updated
upstream in [1], without any corresponding hash change in Buildroot, leading
to build failure.

Fixes: https://gitlab.com/buildroot.org/buildroot/-/work_items/189

NB: This also affects 2025.02.x & 2026.05.x, so this patch
    should be applied there too.

[1] e7e21018fc

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
(cherry picked from commit cb18f3a74a)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-04 14:06:32 +02:00
Romain Naour
611ddaa9ce package/python-gobject: bump to 3.56
This version bump is required following the glib security version bump
to 2.88.3 [1] to fix a runtime issue due to GLib-2.0 backward
compatibility removal [2].

We prefer updating python-gobject to 3.56 stable release instead of
backporting complex commits from 3.55.x unstable release [3].

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152329 (TestFirewalldSysVInit)
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152332 (TestFirewalldSystemd)

[1] e313a2d259
[2] e02603d44d
[3] 74e4e0f40a

Runtime tested with TestGst1Python and TestFirewalld{Systemd,SysVInit}.

Cc: Fiona Klute <fiona.klute@gmx.de>
Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit b4949ce4c9)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-04 14:06:19 +02:00
Thomas Petazzoni
0e6359561e docs/website: patchwork is now at patchwork.buildroot.org
patchwork.buildroot.org used to be a redirect to patchwork.ozlabs.org,
but we are now running our own instance, so let's adjust the links in
the website accordingly.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 2eefcb245f)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:06:43 +02:00
Thomas Petazzoni
570f561440 docs/manual: patchwork is now at patchwork.buildroot.org
patchwork.buildroot.org used to be a redirect to patchwork.ozlabs.org,
but we are now running our own instance, so let's adjust the links in
the manual accordingly.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 2d7d9d8200)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:06:43 +02:00
Bernd Kuhls
501c3332ef package/libldns: security bump version to 1.9.2
https://community.nlnetlabs.nl/t/ldns-1-9-1-released/3403
https://community.nlnetlabs.nl/t/ldns-1-9-2-released/3404
"Please do not install ldns version 1.9.1 as it has a wrong .so version.
 Install ldns version 1.9.2 instead."

Fixes CVE-2026-10846.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 911dc3a5d2)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:06:43 +02:00
Titouan Christophe
68a4ee1b61 package/{glibc, localedef}: security bump to v2.43-61
This fixes the following known vulnerabilities:
- CVE-2026-19499
- CVE-2026-77117
- CVE-2026-80489

(alternative to commit be382f6061)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:36 +02:00
Alessandro Rubini
b1f69852c7 package/opencv: fix webp dependency
When BR2_PACKAGE_OPENCV4_WITH_WEBP=y we need to enable mux and demux
support in webp, otherwise the build of OpenCV fails as follows:

    CMake Error: The following variables are used in this project,
         but they are set to NOTFOUND.
    Please set them or make sure they are set and tested correctly
         in the CMake files:
    WEBP_DEMUX_LIBRARY
    linked by target "opencv_imgcodecs"
         in directory [...]/build/opencv4-4.13.0/modules/imgcodecs
    WEBP_MUX_LIBRARY
    linked by target "opencv_imgcodecs"
         in directory [...]/build/opencv4-4.13.0/modules/imgcodecs

The issue already exists in 2025.02.x.

Fixes:

  https://autobuild.buildroot.net/results/d3e0446a87d32469267e241866c4224143170f31/

Signed-off-by: Alessandro Rubini <rubini@gnudd.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit e1ec936cf7)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:36 +02:00
Robert P. J. Day
8c0aa62b1b docs/manual: post-image.sh/post-build.sh should use '-', not '_'
Even though it's only documentation, the form of the names of the
post-image.sh and post-build.sh scripts should be consistent with the
names of those scripts used in the code base, using hyphen, not
underscore.

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit c529a2c286)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:36 +02:00
Robert P. J. Day
35e36abe69 docs/manual: minor aesthetic cleanups in "Getting Buildroot"
Minor tweaks including proper capitalization.

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit dd2fb3de11)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:36 +02:00
Robert P. J. Day
cc25813ec1 docs/manual: update intro, make gender-neutral
Besides just updating a little terminology, remove the awkward
reference to "his" when referring to developers.

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 59efb9037f)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:36 +02:00
Alexis Lothoré via buildroot
3faf4c244c package/erlang: fix link failure on odbcserver
host-erlang build can fail with the following error:

  make[5]: Nothing to be done for 'opt'.
   MAKE	opt
   CC	../priv/bin/x86_64-pc-linux-gnu/odbcserver
  /usr/bin/ld: ../priv/obj/x86_64-pc-linux-gnu/odbcserver.o: in function `encode_column_dyn':
  odbcserver.c:(.text+0x6b4): undefined reference to `ei_x_encode_tuple_header'
  /usr/bin/ld: odbcserver.c:(.text+0x6c2): undefined reference to `ei_x_encode_tuple_header'
  /usr/bin/ld: odbcserver.c:(.text+0x6d4): undefined reference to `ei_x_encode_ulong'
  /usr/bin/ld: odbcserver.c:(.text+0x6e7): undefined reference to `ei_x_encode_ulong'
  /usr/bin/ld: odbcserver.c:(.text+0x6fa): undefined reference to `ei_x_encode_ulong'
  /usr/bin/ld: odbcserver.c:(.text+0x708): undefined reference to `ei_x_encode_tuple_header'
  /usr/bin/ld: odbcserver.c:(.text+0x71b): undefined reference to `ei_x_encode_ulong'
  /usr/bin/ld: odbcserver.c:(.text+0x72e): undefined reference to `ei_x_encode_ulong'
  [...]

This can be reproduced with the following minimal defconfig (and
libei.so present on host, see details below):

  BR2_x86_64=y
  BR2_TOOLCHAIN_EXTERNAL=y
  BR2_PACKAGE_ERLANG=y

Those missing symbols are part of the erl_interface, exposed by libei.a.
host-erlang builds correctly libei.a _before_ odbcserver.c (it can be
found in lib/erl_interface/obj/x86_64-pc-linux-gnu/libei.a), but the
failure is actually due to the build command generated and used for
odbcserver.c, especially the link arguments:

  /usr/bin/gcc \
  [...]
  -o ../priv/bin/x86_64-pc-linux-gnu/odbcserver \
  ../priv/obj/x86_64-pc-linux-gnu/odbcserver.o \
  -L/usr/lib64 \
  -lodbc \
  -L/home/alexis/src/buildroot/erlang-master/build/host-erlang-custom/lib/erl_interface/obj/x86_64-pc-linux-gnu \
  -lpthread -lei

/usr/lib64 is searched before the path where libei.a has been built, so
if whether a valid libei.a or libei.so is found there, it shadows the
expected libei.a. In the build from which the logs above come, the
notable point is that the host system indeed have a valid libei.so, but
is completely unrelated to erl_interface; it rather exposes the Emulated
Input protocol aimed at Wayland stack; and so it obviously contains none
of the expected ei_* symbols.

Upstream has already identified and fixed the issue, the fix is already
released in versions >= 27.x.y. Erlang 26 (the version currently
packaged in buildroot), isn't supported anymore (only the three latest
releases are supported, see
https://github.com/erlang/otp/blob/master/SECURITY.md), so there won't
be any new minor update that will release this fix.

Pick and backport the fixing patch so that the current version packaged
in buildroot can still build.

Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 5ea2135a56)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:36 +02:00
Bernd Kuhls
f6e9fad4ca package/libheif: security bump version to 1.23.2
https://github.com/strukturag/libheif/releases/tag/v1.23.2

Fixes the following CVEs:

(CVE numbers will be added upstream when assigned.)

CVE-2026-XXXXX (GHSA-g89c-p67h-r497)
 Heap buffer overflow in scale_nearest_neighbor() via duplicate alpha
 planes from nested iden/auxl items. (critical)

(GHSA-2jg2-4ch7-h545)
 Out-of-bounds read and write in derived-item and pixel-plane handling.
 Through iden and auxl item chains, a crafted file could attach pixel
 planes whose size differs from the image geometry; crop, scale, and
 plane-extraction code then indexed those planes with the wrong size.
 A working code-execution exploit was confirmed. Plane sizes are now
 validated wherever they are consumed. (critical)

CVE-2026-XXXXX (GHSA-24wx-9w62-c96w)
 brotli/zlib decompression of mime metadata and unci image data had no
 effective output-size limit, so a decompression bomb could exhaust
 memory. Decompressed output is now bounded by the security limits.
 (high)

CVE-2026-XXXXX (GHSA-x8xm-cm2c-cfc8)
 Chains of derived-image references (grid, iovl, iden) bypassed decode
 caching and memory limits, causing CPU and memory amplification. (high)

CVE-2026-XXXXX (GHSA-xw34-mjcp-jqh8)
 Sequence sample-timing initialization could produce non-terminating
 decode loops and unbounded memory, bypassing max_sequence_frames.
 (high)

CVE-2026-XXXXX (GHSA-j264-xvrp-5v7q)
 Out-of-bounds write in the unci encoder when
 heif_context_add_image_tile() is given a tile whose planes do not match
 its declared size. (high)

CVE-2026-XXXXX (GHSA-p58j-h3vm-3fp5)
 Heap out-of-bounds read in the inline-mask region API when
 mask_data_len does not match the region geometry. (medium)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 0fe2d74ffd)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:36 +02:00
Thomas Petazzoni
38ff0dcef3 package/collectd: fix build of virt plugin
Since the bump of libxml2 from 2.13.8 to 2.15.0 in Buildroot commit
d81922c1ef, the "virt" plugin of
collectd no longer builds:

src/virt.c:2208:49: error: expected ';', ',' or ')' before 'ATTRIBUTE_UNUSED'
 2208 | static void virt_eventloop_timeout_cb(int timer ATTRIBUTE_UNUSED,
      |                                                 ^~~~~~~~~~~~~~~~
src/virt.c: In function 'register_event_impl':
src/virt.c:2221:26: error: 'virt_eventloop_timeout_cb' undeclared (first use in this function)
 2221 |                          virt_eventloop_timeout_cb, NULL, NULL) < 0) {
      |                          ^~~~~~~~~~~~~~~~~~~~~~~~~
src/virt.c:2221:26: note: each undeclared identifier is reported only once for each function it appears in

This is due to the fact that the virt plugin code was incorrectly
using the ATTRIBUTE_UNUSED define, which was supposed to be an
internal define of libxml2. But it turns out that up to libxml2 2.14.0
and its commit 208f27f9641a59863ce1f7d4992df77f7eb0ea9d, this define
had been made publicly available. It could therefore mistakenly be
used by collectd's virt plugin... until libxml2 was upgraded.

We backport an upstream patch from collectd that fixes the issue.

Fixes:

  https://autobuild.buildroot.net/results/4c8463f0372560f4c3a20b0f67854460f0d1c400/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 83fc4aa55e)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:35 +02:00
Thomas Petazzoni
b0bc636ee5 support/testing: add bpftrace test
This commit adds a simple bpftrace test that ensures that not only it
builds fine, but it also runs properly on a minimal test scenario.

Assisted-by: GPT-5.6
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
[Julien:
 - reindent emulator.boot() options
 - add a call to "bpftrace --version"
]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit e06cfae9cb)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:35 +02:00
Thomas Petazzoni
1e3fce311c package/bpftrace: bump to version 0.26.1 to fix build with LLVM 22
Since Buildroot commit 25cb3813e7 which
bumped LLVM from 21.x to 22.x, the build of bpftrace is broken as
bpftrace 0.24.2 only supports LLVM up to 21.

We tried backporting the bpftrace patch that allows using LLVM up to
version 22 but the patch didn't apply cleanly but more importantly it
wasn't clear if this patch was sufficient. Therefore, we opt for
bumping bpftrace entirely to fix the issue.

Packaging changes:

- The new version of bpftrace no longer needs host-bison/host-flex,
  because bpftrace is now using a handwritten parser.

- Pass -DUSE_SYSTEM_LIBBPF:BOOL=ON to ensure the system libbpf version
  is used, and not the bundled version

- Now depends on kernel headers >= 5.10 because it needs CAP_BPF and
  CAP_PERFMON

Upstream changelog:
https://github.com/bpftrace/bpftrace/blob/v0.26.1/CHANGELOG.md

Fixes:

  https://autobuild.buildroot.net/results/a3e3fd696685864977c688aa11c2653357cf6207/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
[Julien: add link to upstream changelog]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit cc25888c88)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:35 +02:00
Thomas Petazzoni
fdb7dacc73 package/libbpf: update UAPI header installation work-around
bpftrace often needs very recent kernel headers, more recent than the
runtime version actually needed. We already had a workaround in
libbpf making sure that if the kernel headers are older than 6.1, we
would install the libbpf provided headers instead.

As we are about to update bpftrace to a newer version that uses
BPF_TRACE_KPROBE_SESSION, which was introduced in Linux 6.10, we need
to update this workaround accordingly and ensure that the libbpf
header is installed if the kernel headers are older than 6.10.

This is necessary for the update of bpftrace to 0.26.1.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit e9c540ddd2)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:35 +02:00
Peter Korsgaard
569beee827 support/testing: add haproxy test
Based on the lighttpd test case.  Verify that we can download index.html
from haproxy in front of lighttpd.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 211cfafa16)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:35 +02:00
Peter Korsgaard
1d812dfa97 package/haproxy: needs signed overflow handling
haproxy has a runtime test to verify that it is built with -fwrapv:

haproxy
FATAL ERROR: invalid code detected -- cannot go further, please recompile!
The source code was miscompiled by the compiler, which usually indicates that
some of the CFLAGS needed to work around overzealous compiler optimizations
were overwritten at build time. Please do not force CFLAGS, and read Makefile
and INSTALL files to decide on the best way to pass your local build options.

Build options :
  TARGET  = custom
  CPU     = generic
  CC      = /home/peko/source/buildroot/output-haproxy/host/bin/arm-linux-gcc
  CFLAGS  = -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0 -D_FORTIFY_SOURCE=1 -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0 -D_FORTIFY_SOURCE=1
  OPTIONS = USE_THREAD=1 USE_DL=1
  DEBUG   = -DDEBUG_STRICT -DDEBUG_MEMORY_POOLS

Which comes from:
https://github.com/haproxy/haproxy/blob/v2.6.0/src/haproxy.c#L3008-L3037

So build it with -fwrapv to fix that.

Notice that this message also embeds the build path (through CC), breaking
reproducible builds.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 94aa7f40b5)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:35 +02:00
Julien Olivain
dd26121981 support/testing: wpa_supplicant: new runtime test
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 6eaa34ecdf)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:35 +02:00
Julien Olivain
91a64de253 support/testing: quickjs: new runtime test
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 4e62ac3a21)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:35 +02:00
Julien Olivain
82d7b01818 support/testing: fs: new cramfs runtime test
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit bd4ac802e4)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:35 +02:00
Thomas Petazzoni
3e050a8758 package/mesa3d: fix build issue with gcc < 13
Since upstream commit
e42e3193137d1b21e84b499336e7a8887b8a8689 ("intel: add Jay"), a C23
construct is used in the intel driver code:

enum jay_predication : uint8_t

This causes a build issue with GCC < 13:

In file included from ../src/intel/compiler/jay/jay_builder.h:12,
                 from ../src/intel/compiler/jay/jay_from_nir.c:23:
../src/intel/compiler/jay/jay_ir.h:582:22: error: expected identifier or ‘(’ before ‘:’ token
  582 | enum jay_predication : uint8_t {
      |                      ^
../src/intel/compiler/jay/jay_ir.h:637:25: error: field ‘predication’ has incomplete type
  637 |    enum jay_predication predication;
      |                         ^~~~~~~~~~~

We fix that by integrating a patch already available in
OpenEmbedded. It changes the code to not use the C23 construct.

This build issue was encountered on host-mesa3d while building an
allyespackageconfig configuration inside our standard Docker
container.

Buildroot commit
c073c97617 ("package/{mesa3d,
mesa3d-headers}: bump version to 26.1.0") that switched to mesa3d
26.1.0, which contains the problematic commit. Therefore 2026.05 is
affected, but not earlier Buildroot versions.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 79554a4520)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:35 +02:00
Thomas Petazzoni
37c47ee265 package/olsr: fix build with GCC >= 15
This commit introduces a patch, submitted upstream, that fixes the
build of OLSR with GCC >= 15.

Fixes:

  https://autobuild.buildroot.net/results/650edf74dec513ad540f80f4d3ef8c8222dfd711/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 34473e672b)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:35 +02:00
Thomas Petazzoni
d6e2a733a2 package/perl: fix build issue with musl
perl does not build with musl due to memrchr() being unavailable. This
is caused by a perl-cross bug, which does function availability
detection with _GNU_SOURCE defined, but then does the build without
_GNU_SOURCE defined. At least OpenEmbedded and NixOS have faced the
same issue, and worked it around in slightly different ways.

On our side, we create a patch, which was submitted upstream, to solve
the issue.

This issue has been introduced in perl-cross commit b40c560f5d5e,
which was first merged in perl-cross release 1.4.1. From a Buildroot
perspective, we bumped from perl-cross 1.4 to 1.4.1 in commit
8a289667f5, which was merged
2023.05. And indeed the build failure can be reproduced even on our
LTS 2025.02.x, so the fix needs to be backported there.

It should be noted that even if the patch is against perl-cross, we
add it to package/perl/ directly, as patches in perl are applied after
perl has been extracted *and* perl-cross has been extracted on top.

Fixes:

  https://autobuild.buildroot.net/results/3e47ade0963642988fd8e1be9a6e8042700619ec/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit d950fff290)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:35 +02:00
Romain Naour
c9b0b42b90 package/qt6: fix c++ static_assert issue
Since the last qt6 version bump to 6.11.1 [1], the TestQuazipQt6 fail to
build due to a c++ static_assert issue.

Backport a patch from v6.11.2 release.

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060153667 (TestQuazipQt6)

[1] 05cd38635a

Signed-off-by: Romain Naour <romain.naour@smile.fr>
[Julien: fix link to qt6 version bump commit]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 240ea08d3f)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:35 +02:00
Thomas Petazzoni
82e55ddd36 package/qt6/qt6declarative: fix select of host-qt6base network
The BR2_PACKAGE_QT6DECLARATIVE_QUICK option has some logic to select
network support in host-qt6base if network support is enabled in
qt6base. However, it turns out that this is actually required at the
top level BR2_PACKAGE_QT6DECLARATIVE option: as soon as network
support is available in qt6base, the qt6declarative build will assume
that qmlprofiler is available... but that requires network support in
host-qt6base.

This fixes the following build failure:

CMake Error at /home/thomas/autobuild/instance-2/output-1/build/qt6base-6.9.1/cmake/QtToolHelpers.cmake:784 (message):
  Failed to find the host tool "Qt6::qmlprofiler".  It is part of the
  Qt6QmlTools package, but the package did not contain the tool.  Make sure
  that the host module Qml was built with all features enabled (no explicitly
  disabled tools).
Call Stack (most recent call first):
  /home/thomas/autobuild/instance-2/output-1/build/qt6base-6.9.1/cmake/QtToolHelpers.cmake:83 (qt_internal_find_tool)
  tools/qmlprofiler/CMakeLists.txt:11 (qt_internal_add_tool)

Fixes:

  https://autobuild.buildroot.net/results/72c956fdf982382d2981c649c456d1edc2c9d6b2/

We did not trace back exactly since when the problem exists, but we
verified that the problem exists in 2025.02.x. It can be reproduced
with the following defconfig:

BR2_aarch64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_PACKAGE_QT6=y
BR2_PACKAGE_QT6BASE_NETWORK=y
BR2_PACKAGE_QT6DECLARATIVE=y

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 50a1dd2676)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:35 +02:00
Thomas Petazzoni
f434e6629c package/qt6/qt6declarative: move comment where it belongs
The commit "Enable host test module to ensure that qmltestrunner is
built" in qt6declarative's Config.in feels lonely under
BR2_PACKAGE_QT6DECLARATIVE. It's because it's actually related to a
select done in the sub-option BR2_PACKAGE_QT6DECLARATIVE_QUICK, so
move it there.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 29add67666)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:35 +02:00
Romain Naour
13bccb86cc support/testing: TestPythonPy3Gobject: test glib 2.88 regression
In Glib >= 2.88, GLib.unix_signal_add has been moved to a separate
platform-specific library. This break backward compatibility from
GLib-2.0. A workaround has been applied to pygobject >= 3.55.3
74e4e0f40a

This issue currently break TestFirewalldSysVInit and
TestFirewalldSystemd runtime tests since the bump to glib 2.88.3 [1]:

https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152329 (TestFirewalldSysVInit)
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152332 (TestFirewalldSystemd)

Break the test TestPythonPy3Gobject now in order to reproduce the same
issue than for Firewalld test.

[1] e313a2d259

Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 3bd3d5004d)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:34 +02:00
Julien Olivain
1a52019185 support/testing: php: fix test by switching to "Debian" filesystem layout
Buildroot commit [1] (package/apache: use "Debian" filesystem
layout to fix read-only rootfs) changed the filesystem layout.
This had the effect of installing files to different locations
and breaking the test_php runtime test.

This commit fixes the issue by updating the file paths to their
right locations. The "httpd.conf" was updated by following the
same recipe described in the comment (starting from a config
file as installed by the apache Buildroot package).

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152979

[1] 1006666f67

Signed-off-by: Julien Olivain <ju.o@free.fr>
Tested-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 23fd881bdb)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:34 +02:00
Thomas Petazzoni
827a28714b package/dahdi-linux: backport commits to fix build with recent kernels
Fixes build with kernels >= 6.15.

Fixes:

  https://autobuild.buildroot.net/results/ed73aa844a18cfc15e942ced4ae363c3d0d09015/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit f57da3c953)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:34 +02:00
Thomas Petazzoni
4e189ef988 package/bind: fix thread dependency
In commit 54f96add94 ("package/bind:
security bump version to 9.20.24") the depends on
BR2_TOOLCHAIN_HAS_THREADS_NPTL was incorrectly downgraded to
BR2_TOOLCHAIN_HAS_THREADS:

-       depends on BR2_TOOLCHAIN_HAS_THREADS_NPTL # libuv
+       depends on BR2_TOOLCHAIN_HAS_THREADS # liburcu, libuv

This is wrong because libuv depends on
BR2_TOOLCHAIN_HAS_THREADS_NPTL. This causes unmet dependencies:

WARNING: unmet direct dependencies detected for BR2_PACKAGE_LIBUV
  Depends on [n]: BR2_TOOLCHAIN_HAS_THREADS_NPTL [=n] && BR2_USE_MMU [=y] && !BR2_STATIC_LIBS [=n] && BR2_TOOLCHAIN_HAS_SYNC_4 [=y] && BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 [=y]
  Selected by [y]:
  - BR2_PACKAGE_BIND [=y] && BR2_USE_MMU [=y] && BR2_TOOLCHAIN_HAS_SYNC_4 [=y] && BR2_TOOLCHAIN_HAS_THREADS [=y] && BR2_INSTALL_LIBSTDCPP [=y] && !BR2_STATIC_LIBS [=n] && BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 [=y] && BR2_PACKAGE_LIBURCU_ARCH_SUPPORTS [=y]

Fix that by switching back to the BR2_TOOLCHAIN_HAS_THREADS_NPTL
dependency.

Fixes: 54f96add94 ("package/bind: security bump version to 9.20.24")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit d8dde961bc)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:34 +02:00
Thomas Perale
d1f92ff02f package/rsyslog: upstream patch CVE-2026-19654
- CVE-2026-19654:
    A unauthenticated remote peer may lead rsyslogd to crash due to a flaw
    in the optional imptcp module. A crafted input sequence during
    oversize-frame recovery can cause an invalid internal message length
    and terminate rsyslogd. No confidentiality or integrity impact,
    privilege escalation, or code execution has been identified. imtcp and
    the default imptcp framing modes are not affected.

For more information, see:
  - https://www.cve.org/CVERecord?id=CVE-2026-19654
  - 07b3c40a5a

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 52ae04257a)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 13:03:30 +02:00
Thomas Perale
98d94ec62c package/unbound: security bump to v1.25.2
See the changelog:

- https://nlnetlabs.nl/projects/unbound/download/#unbound-1-25-2

It fixes the following vulnerabilities:

- CVE-2026-14586: Assertion in libngtcp2 when under pressure in high
  concurrency DNS-over-QUIC environments.
- CVE-2026-32665: Remote DNS-over-QUIC denial of service due to
  `quic-size` budget bypass.
- CVE-2026-40691: Packet of death for DNSCrypt over TCP.
- CVE-2026-41637 Degradation of resolution service from improperly
  accounted client-terminated DNS-over-QUIC queries.
- CVE-2026-42955: Extra fix for CVE-2026-40622 to also clamp the TTL of
  A/AAAA records disallowing a one-time 'ghost domain' delegation
  renewal via glue records.
- CVE-2026-44621: Libunbound applications configured with
  'unwanted-reply-threshold' could eventually be abruptly terminated.
- CVE-2026-44687: Off-by-one error in 'harden-below-nxdomain' logic can
  shadow a stub/forward zone by a legitimate parent's NXDOMAIN.
- CVE-2026-44690: Cross-zone wildcard cache poisoning via RRSIG.labels
  manipulation.
- CVE-2026-46582: A wildcard replay, as another piece of data, triggers
  poisoning in the serve expired reply path.
- CVE-2026-50045: 'max-global-quota' reset by DNSSEC validation
  restarts.
- CVE-2026-50046: Possible heap use-after-free in an error path when a
  DoT forwarded query is jostled out.
- CVE-2026-50243: 'response-ip'/'rpz' can rewrite BOGUS answers instead
  of returning SERVFAIL.
- CVE-2026-50248: BOGUS configured primary hostname accepted for XFR in
  auth/rpz zones.
- CVE-2026-50251: Attacker supplied `0.0.0.0`/`::` glue triggers
  defensive full-cache flush.
- CVE-2026-50252: Possible cache poisoning attack by mapping source port
  population per thread.
- CVE-2026-52863: Memory corruption could lead to crash and denial of
  service.
- CVE-2026-54478: DNS Cookie bypass when combined with proxy-protocol
  use.
- CVE-2026-55708: Privacy/configuration issue when adding local data in
  views through 'unbound-control'.
- CVE-2026-55717: 'serve-expired-client-timeout' and 'response-ip' CNAME
  redirect could lead to a crash.
- CVE-2026-55973: 'dns-error-reporting: yes' leads to stack buffer
  overflow.
- CVE-2026-55990: Packet of death for a DNSCrypt misconfigured Unbound.
- CVE-2026-55991: Remote DNS-over-QUIC (DoQ) flow-control assertion
  failure in libngtcp2.
- CVE-2026-56416: Possible heap buffer overflow when validator
  canonicalizes RDATA that contains domain name.
- CVE-2026-56444: Degradation of resolution service when
  'discard-timeout' and 'serve-expired-client-timeout' are combined in
  unusual configuration.

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit d0619dfc6b)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 11:21:00 +02:00
Titouan Christophe
60aa783c47 package/{avro-c, python-avro}: security bump to v1.12.2
This release includes a broad round of hardening against malformed and
adversarial input across the Python SDK (bounding allocations and enforcing
decompression limits before trusting size fields read from the input).

See the release notes https://avro.apache.org/blog/2026/08/12/avro-1.12.2/

Also update the download url, because www-eu.apache.org/dist/...
is a redirection to downloads.apache.org/...

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 02d8a41f09)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 11:20:57 +02:00
Thomas Perale
39011caddb package/nodejs: security bump to v22.23.2
See the release notes:

- https://github.com/nodejs/node/releases/tag/v22.23.2
- https://github.com/nodejs/node/releases/tag/v22.23.1
- https://github.com/nodejs/node/releases/tag/v22.22.1
- https://github.com/nodejs/node/releases/tag/v22.22.2
- https://github.com/nodejs/node/releases/tag/v22.22.3

It fixes the following vulnerabilities:

- (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High
- (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
- (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
- (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
- (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
- (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
- (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
- (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
- (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
- (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low

The LICENSE was changed in 22.22.1, see [1].

[1] 9cafec084e

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 6f5d678c37)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 11:20:55 +02:00
Bernd Kuhls
ffa22bebc6 package/libopenssl: security bump to version 3.6.4
https://github.com/openssl/openssl/releases/tag/openssl-3.6.4

This release incorporates the following bug fixes and mitigations:

Fixed QUIC server being able to trigger double free when processing
INITIAL packet.
(CVE-2026-18798)

Fixed heap buffer overflow in CMS key unwrapping.
(CVE-2026-63072)

Fixed invalid pointer dereference in CMP server via crafted protectionAlg.
(CVE-2026-63076)

Fixed unbounded memory growth in QUIC server incoming channel queue.
(CVE-2026-14456)

Fixed RPK server signature algorithm selection being able to dereference
a missing certificate.
(CVE-2026-14457)

Fixed excessive memory use buffering DTLS records for a future epoch.
(CVE-2026-54874)

Fixed client-side memory leak in OCSP response checking.
(CVE-2026-54876)

Fixed untrusted Sender DN being used as a format string in CMP response
validation.
(CVE-2026-63073)

Fixed CMP indefinite cache growth of extraCerts.
(CVE-2026-63074)

Fixed QUIC ACK-only packet retention being able to cause memory exhaustion.
(CVE-2026-63075)

Fixed possibility of AEAD forgeries with empty ciphertext when using
EVP_Cipher().
(CVE-2026-75803)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 198317785a)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-04 11:20:43 +02:00
Waldemar Brodkorb
70c1144c83 package/uclibc: fix m68000 toolchain builds
Add a patch from Upstream to fix building of a m68000
toolchain.

Fixes:
 - https://autobuild.buildroot.net/results/4cc/4cc0de3d33339bd50792ca224f10dfd18a636b00/

Signed-off-by: Waldemar Brodkorb <wbx@openadk.org>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 7906653200)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-03 10:33:32 +02:00
Waldemar Brodkorb
2ddcd15a4f package/uclibc: fix for gcc libquadmath conflict
As seen in the Buildroot autobuilders, struct rm_ctx should
not be exposed in the public fenv.h header.

Fixes:
 - https://autobuild.buildroot.net/results/761/7613538e0847a10eb3e2a7e40f3ae76386ac015b/

Signed-off-by: Waldemar Brodkorb <wbx@openadk.org>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit e1a9ff1d67)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-03 10:33:02 +02:00
Thomas Devoogdt
259ffa20e6 package/expat: fix no high quality entropy warning on Linux <3.17 or glibc <2.25
In some situations (old Linux <3.17 or glibc <2.25), expat fail at
compilation time with the error:

xmlparse.c:150:4: error: #error You do not have support for any sources of high quality entropy enabled.
For end user security, that is probably not what you want. Your options include:
  * Linux >=3.17 + glibc >=2.25 (getrandom): HAVE_GETRANDOM,
  * Linux >=3.17 + glibc (including <2.25) (syscall SYS_getrandom): HAVE_SYSCALL_GETRANDOM,
  * BSD / macOS >=10.7 / glibc >=2.36 (arc4random_buf): HAVE_ARC4RANDOM_BUF,
  * BSD / macOS (including <10.7) / glibc >=2.36 (arc4random): HAVE_ARC4RANDOM,
  * BSD / macOS >=10.12 / glibc >=2.25 (getentropy): HAVE_GETENTROPY,
  * Linux (including <3.17) / BSD / macOS (including <10.7) / Solaris >=8 (/dev/urandom): XML_DEV_URANDOM,
  * Windows >=Vista (rand_s): _WIN32.
If you insist on not using any of these, bypass this error by defining XML_POOR_ENTROPY and be vulnerable to hash flooding;
you have been warned. If you have reasons to patch this detection code away or need changes to the build system, please open a bug. Thank you!

This is caused by the upstream commit [1] "Autotools: Stop using
/dev/urandom by default", first included in expat 2.8.2. The
Buildroot expat package was bumped to that version in commit [2].

But since all Linux systems have /dev/urandom, we can just enable
it by default.

Note: this commit does not globally switch the entropy source to
/dev/urandom. It is rather enabling it in the list of available
sources. On more recent Linux systems (linux >= 3.17, glibc >= 2.25),
other sources will be chosen. The entropy source preference order
amongst the enabled sources is defined in [3].

This commit also changes the _CONF_OPTS to multiline layout to fit
within the 80 characters.

[1] d30eca113a
[2] 6b1f6f7a48
[3] https://github.com/libexpat/libexpat/blob/R_2_8_3/expat/lib/xmlparse.c#L1115-L1142

Signed-off-by: Thomas Devoogdt <thomas.devoogdt@barco.com>
[Julien: add extra info in the commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit c22fc74f2b)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-03 10:31:06 +02:00
Thomas Petazzoni
210d964e93 package/gdb: handle xxhash optional dependency
Since gdb 9.x, gdb can optionally use the xxhash library. Since we
currently don't do anything about it, it's a potential "silent"
dependency.

In particular, for host-gdb, this means host-gdb might end up being
linked with the system-provided xxhash library if available.

This patch handles this dependency:

- For the target package, by looking at the value of
  BR2_PACKAGE_XXHASH

- For the host package, by looking at the value of a newly introduced
  BR2_PACKAGE_HOST_GDB_XXHASH

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 9dc567aa78)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-03 10:30:38 +02:00
Thomas Petazzoni
816bae3a58 package/gdb: handle lzma option for host-gdb
For target gdb, we properly enable/disable lzma support depending on
BR2_PACKAGE_XZ.

However, for host-gdb we don't do anything, which can lead the gdb
configure script to detect and use a system-provided xz library, which
is not desired.

Instead, add an explicit option BR2_PACKAGE_HOST_GDB_LZMA, which when
enabled pulls in host-xz, but also when disabled ensures gdb doesn't
try to use a system-provided xz library.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit c3adba81d1)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-03 10:29:28 +02:00
Thomas Petazzoni
a5952f6629 toolchain/Config.in: refine BR2_TOOLCHAIN_HAS_LIBQUADMATH definition
In commit a2380157f6 ("toolchain: enable
libquadmath for PowerPC with VSX"), the definition of
BR2_TOOLCHAIN_HAS_LIBQUADMATH has been extended to also be true when
BR2_POWERPC_CPU_HAS_VSX.

However, practical experiments show that when 64-bit VSX-capable cores
are used in 32-bit mode, libquadmath is not built by GCC, causing
build failures:

cp: cannot stat '/home/autobuild/autobuild/instance-3/output-1/host/powerpc-buildroot-linux-musl/lib*/libquadmath*': No such file or directory

We did an extensive testing, building the 27 combinations of:

- GCC versions: 14, 15, 16
- C library: glibc, uclibc, musl
- PowerPC 32-bit, PowerPC 64-bit, PowerPC 64-bit little endian

This testing provides the following results:

|      gcc14 |       powerpc64 |      glibc |         OK |
|      gcc14 |     powerpc64le |      glibc |         OK |
|      gcc14 |     powerpc64le |       musl |         OK |
|      gcc14 |     powerpc64le |     uclibc |    SKIPPED |
|      gcc14 |       powerpc64 |       musl |         OK |
|      gcc14 |       powerpc64 |     uclibc |    SKIPPED |
|      gcc14 |         powerpc |      glibc |     FAILED |
|      gcc14 |         powerpc |       musl |     FAILED |
|      gcc14 |         powerpc |     uclibc |     FAILED |
|      gcc15 |       powerpc64 |      glibc |         OK |
|      gcc15 |     powerpc64le |      glibc |         OK |
|      gcc15 |     powerpc64le |       musl |         OK |
|      gcc15 |     powerpc64le |     uclibc |    SKIPPED |
|      gcc15 |       powerpc64 |       musl |         OK |
|      gcc15 |       powerpc64 |     uclibc |    SKIPPED |
|      gcc15 |         powerpc |      glibc |     FAILED |
|      gcc15 |         powerpc |       musl |     FAILED |
|      gcc15 |         powerpc |     uclibc |     FAILED |
|      gcc16 |       powerpc64 |      glibc |         OK |
|      gcc16 |     powerpc64le |      glibc |         OK |
|      gcc16 |     powerpc64le |       musl |         OK |
|      gcc16 |     powerpc64le |     uclibc |    SKIPPED |
|      gcc16 |       powerpc64 |       musl |         OK |
|      gcc16 |       powerpc64 |     uclibc |    SKIPPED |
|      gcc16 |         powerpc |      glibc |     FAILED |
|      gcc16 |         powerpc |       musl |     FAILED |
|      gcc16 |         powerpc |     uclibc |     FAILED |

The "SKIPPED" are when the configuration is not possible: uClibc
doesn't support powerpc64 or powerpc64le.

Then, as we can see, the build fails for all "powerpc"
configuration. Our conclusion is therefore that libquadmath is not
supported on PowerPC 32-bit. While we were not able to find direct
evidence in the gcc code base, this practical experiment shows that is
simply doesn't work on PowerPC 32-bit.

So, we take the logical action of adjusting
BR2_TOOLCHAIN_HAS_LIBQUADMATH so that it is true only on
powerpc64/powerpc64le.

Fixes:

  https://autobuild.buildroot.org/results/46d435c9f5086a8695f4f6cd4026bb0d194de13c/

Cc: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 06426297c4)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-03 10:28:38 +02:00
Bernd Kuhls
6b17df1a5d package/taglib: needs gcc >= 7
Fixes a build error caught by the Gitlab pipelines:

/builds/bkuhls/buildroot/br-test-pkg/bootlin-aarch64-glibc-old/build/taglib-2.3/taglib/mpeg/mpegfile.cpp:113:10:
 error: expected primary-expression before ‘const’
       if(const Header header(&file, headerOffset + i, true); header.isValid()) {

which was introduced by code format changes in upstream commit
dfe2aa5253
which was first released with taglib 2.0, added to buildroot with commit
9cd3464afa.

This "init-statement" C++17 language feature was described in proposal
P0305R1, and according to
https://en.cppreference.com/cpp/compiler_support/17, this feature was
only supported in gcc starting from gcc 7.x.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit d16e4939ca)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-03 10:21:59 +02:00
Adam Ford
6af3c65b28 package/libxml-parser-perl: add host-libxcrypt dependency
host-libxml-parser-perl compiles XS modules against the system perl
headers, which #include <crypt.h>. On build hosts without libcrypt-dev
installed, the build fails:

    .../CORE/reentr.h:126:16: fatal error: crypt.h: No such file or directory

Declaring host-libxcrypt ensures crypt.h is present in the per-package
host sysroot before the build.

This can for example be reproduced on a minimal Debian Forky system,
where libc6-dev no longer pulls libxcrypt-dev.

Signed-off-by: Adam Ford <aford173@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 7e036c739f)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-03 10:11:53 +02:00
Thomas Perale via buildroot
a75f7dd5e9 docs/manual: update 'releases' to reflect LTS changes
With the release of 2025.02, LTS releases are now made every two years
with a 3-year support.

This reflect the table showed at https://lts.buildroot.org/#releases.

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 70f762ea6e)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-03 10:08:07 +02:00
Titouan Christophe
c456b4b224 package/redis: security bump to v8.6.6
See the release notes:
https://github.com/redis/redis/blob/8.6.6/00-RELEASENOTES

This fixes CVE-2026-62356

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
(alternative to commit fab3c4eb92)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-03 10:01:36 +02:00
Bernd Kuhls
b226c11847 package/jpeg-turbo: fix libm linking issue
Buildroot commit bb38f6f720 bumped the
package to 3.2.0. This version first included upstream commit
ed00e0f4b3
which removed the dependency to libm causing build errors detected by
the autobuilders.

Disabling the build of tests by the previous patch of this series is not
enough because the build will fail on other tools like

[ 98%] Linking C executable djpeg-static
/home/bernd/buildroot/output/per-package/jpeg-turbo/host/bin/../lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 src/spng/CMakeFiles/spng-static.dir/spng.c.o: in function
 `spng_decode_image':
spng.c:(.text+0x4c62): undefined reference to `__fpclassifyf'

Add upstream commit to fix the problem.

Fixes:
https://autobuild.buildroot.net/results/981/98114d4ea7afe62bb4cef934a06bf289d863ad3f/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit c0a51767a0)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-03 09:53:45 +02:00
Bernd Kuhls
13726d5e6b package/jpeg-turbo: use configure option WITH_{TESTS, TOOLS}
Buildroot commit c531fe6520 bumped the
package to 3.1.2. This version first included upstream commit
942ac87e47
which added configure options to disable the build of command-line
tools and tests.

This patch replaces the current _POST_INSTALL_TARGET_HOOK with the new
configure option and disables the build of tests.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit d74a065a16)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-03 09:52:05 +02:00
Titouan Christophe
28d08f28a0 {linux, linux-headers}: bump 5.{10,15}, 6.{1,6,12,18} series
Update the latest kernel releases:
    - 5.10.267 -> 5.10.268
    - 5.15.218 -> 5.15.219
    - 6.1.185 -> 6.1.186
    - 6.6.154 -> 6.6.155
    - 6.12.106 -> 6.12.107
    - 6.18.47 -> 6.18.48

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-09-02 11:57:47 +02:00
Thomas Perale
3cb3013193 Revert "package/fluidsynth: security bump to version 2.5.7"
This reverts commit a40212568c.

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-08-28 16:40:17 +02:00
Titouan Christophe
458f2bf01b {linux, linux-headers}: bump 5.{10,15}, 6.{1,6,12,18} series
Update the latest kernel releases:
    - 5.10.265 -> 5.10.267
    - 5.15.216 -> 5.15.218
    - 6.1.183 -> 6.1.185
    - 6.6.152 -> 6.6.154
    - 6.12.104 -> 6.12.106
    - 6.18.45 -> 6.18.47

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:05 +02:00
Bernd Kuhls
4e62f3cb9d package/clamav: requires DES in openssl
Buildroot commit 8b1d8dd25d bumped the
package from 1.4.3 to 1.5.1 which includes upstream commit
8d485b9bfd
that adds the usage of the OpenSSL crate from rust.

This crate depends on DES and causes build errors when missing:

/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 ../libclamav/libclamav.so.12.1.0: undefined reference to `EVP_des_ede3_cfb8'
/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 ../libclamav/libclamav.so.12.1.0: undefined reference to `EVP_des_ede3_cbc'
/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 ../libclamav/libclamav.so.12.1.0: undefined reference to `EVP_des_ede3_cfb64'
/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 ../libclamav/libclamav.so.12.1.0: undefined reference to `EVP_des_ede3_ecb'
/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 ../libclamav/libclamav.so.12.1.0: undefined reference to `EVP_des_ecb'
/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 ../libclamav/libclamav.so.12.1.0: undefined reference to `EVP_des_ede3'
/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 ../libclamav/libclamav.so.12.1.0: undefined reference to `EVP_des_ede3_ofb'
/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 ../libclamav/libclamav.so.12.1.0: undefined reference to `EVP_des_cbc'

Fixes:
https://autobuild.buildroot.net/results/b93/b9359c5c177f3e4bcef991cde3c2dcf412dee5de/
https://autobuild.buildroot.net/results/300/300721a882f3410528878db730aaff1aa6822986/
https://autobuild.buildroot.net/results/a16/a163a9229c04f638a46e6250dc135c475e5d1576/
https://autobuild.buildroot.net/results/7e8/7e88cba9974f6f5acd125b69b95b7269d8128886/

A backport to LTS branches should be considered.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit c4f41f4f3f)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:05 +02:00
Thomas Devoogdt
0266c972b8 package/webkitgtk: fix wrong config option
Commit 713d63b "package/webkitgtk: add option to enable MiniBrowser",
added support to select BR2_PACKAGE_WEBKITGTK_MINIBROWSER, but forgot
to drop the default -DENABLE_MINIBROWSER=ON entry.

Signed-off-by: Thomas Devoogdt <thomas@devoogdt.com>
Acked-By: Adrian Perez de Castro <aperez@igalia.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 9f292bb7a1)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:05 +02:00
Julien Olivain
a40212568c package/fluidsynth: security bump to version 2.5.7
For change log since v2.4.7, see:
https://github.com/FluidSynth/fluidsynth/releases

According to:
https://github.com/FluidSynth/fluidsynth/blob/master/doc/wiki/ChangeLog.md

FluidSynth 2.5.6 fixes:
CVE-2026-58264 - a heap-based buffer overrun in command handler (GHSA-mqmq-w63q-cj94)
CVE-2026-61714 - a heap-based buffer overflow in MIDI player (GHSA-976m-35rw-h3m6)
CVE-2026-61721 - a heap-based buffer overrun for DLS samples (GHSA-59ph-rx8r-8p4j)
CVE-2026-61723 - a DLS ptbl chunk integer overflow (GHSA-r4mc-v3p8-pv47)
CVE-2026-61722 - a DLS articulation chunk integer overflow (GHSA-hp72-35pr-6h6r)
CVE-2026-61720 - a SF2 DMOD chunk integer underflow (GHSA-rmc4-c8hw-455w)

FluidSynth 2.5.2 fixes:
CVE-2025-68617 - a heap-based use-after-free involving DLS files (GHSA-ffw2-xvvp-39ch)

SDL2 audio support was removed upstream in commit:
89145b004a

It was replaced by the newer SDL3. This commit reflects that change
(update option name and comments, add legacy option entry).

Also, dynamic library dependency was added in Buildroot commit:
111a1c7091
This commot removes the duplicate dependency for SDL3.

FluidSynth also added a native DLS soundfont support in:
c959f8d208
It is enabled by default and uses C++17. This commit adds a new
option with a dependency on gcc >= 7.

The license option hash is also updated, after the FSF address
update in:
db42fa333b

Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 566bdcb97f)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:05 +02:00
Benjamin DeCamp
3ec18f2715 package/linux-tools/S10hyperv: fix invalid return value
In both start() and stop(), ret is only assigned on failure. When
hypervkvpd starts or stops successfully, return "$ret" expands to an
empty string and causes:

  /etc/init.d/S10hyperv: return: line 31: Illegal number:

Those double quotes were added in Buildroot commit [1], to fix a
new ShellCheck warning at that time. This was not a complete fix.

Only removing the double quote would reintroduce the ShellCheck
warning. This would also reintroduce a check-package error.

Since a bare return is equivalent to a "return 0", this commit
also initializes with ret=0. Doing so will tell ShellCheck "ret" is
an integer. Therefore, the ShellCheck warning will no longer be
reported.

This commit fixes the invalid return value by removing the double
quotes and initialzing "ret=0".

[1] c4173d8b08

Signed-off-by: Benjamin DeCamp <benjamin8532@protonmail.com>
[Julien:
 - add "ret=0" initialization in script to fix check-package error
 - add extra info in the commit log
]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 667335cd18)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:05 +02:00
Thomas Petazzoni
8242797d31 package/enscript: fix build issue with musl and gcc >= 15
enscript currently fails to build with musl with gcc >= 15. In order
to fix this, we need to bring a number of patches from upstream, and
add 2 others that were submitted upstream.

From upstream, we bring
0002-Add-CFLAG-std-c89-so-it-compiles-with-the-old-standa.patch, which
switches to -std=c89 to get the compiler back to "old" behavior.

However, as this commit patches configure.ac, we need to autoreconf,
but autoreconf is broken, so we also take
0003-Automake-1.12-and-up-no-longer-supports-pre-ANSI.patch from
upstream, which drops a problematic autoconf macro.

However, once you drop this problematic autoconf macro, the PROTOTYPES
define is never set by anything, causing the __P macro to no longer be
defined properly. This is fixed by
0004-Fix-prototype-detection-when-__STDC__-is-defined-but.patch that
we have submitted upstream.

Once you're there, you realize that switching to -std=c89 has the side
effect that musl's <limits.h> no longer defines PATH_MAX, because it
needs one of:

  #if defined(_POSIX_SOURCE) || defined(_POSIX_C_SOURCE) \
   || defined(_XOPEN_SOURCE) || defined(_GNU_SOURCE) || defined(_BSD_SOURCE)

and a side effect of -std=c89 is that none of these is defined
anymore. So we introduce 0005-Use-std-gnu89-instead-of-std-c89.patch,
which switches to -std=gnu89. This patch has also been submitted
upstream.

With all of these efforts, we get a successful build on musl with gcc
>= 15.

This commit needs to be backported to Buildroot versions that support
gcc 15.x, so that means the currently maintained 2026.x branches, but
not 2025.02 as only up to gcc 14.x was supported then.

Fixes:

  https://autobuild.buildroot.org/results/d39d14bbbb3a51d67fe962b877c7f66ff1204ecf/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit edffc0bc50)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:05 +02:00
Stefan Müller
018c7b9108 package/libssh2: fix CVE-2026-66035
Backport the fix for CVE-2026-66035.

The ETM decrypt path does not validate the received packet length before
calculating the decrypt buffer size. A malformed packet can therefore
lead to a heap overflow.

Use Debian's libssh2 1.11.1 backport of the upstream fix.

Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
[Julien: add links to Debian patches]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 03757abfce)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:05 +02:00
Stefan Müller
7d1c8b992f package/libssh2: fix CVE-2026-66034
Backport the fix for CVE-2026-66034.

The publickey subsystem does not sufficiently validate the length of a
server-controlled comment field. A malformed response can therefore
cause an out-of-bounds read.

Use Debian's libssh2 1.11.1 backport of the upstream fix.

Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
[Julien: add links to Debian patches]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 58581deeca)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Stefan Müller
24f10b7bd8 package/libssh2: fix CVE-2026-66033
Backport the fix for CVE-2026-66033.

The OpenSSL AES-GCM cipher path lacks runtime bounds checks around the
input block size. A malformed packet can therefore lead to an
out-of-bounds read or write.

Use Debian's libssh2 1.11.1 backport of the upstream fix.

Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
[Julien: add links to Debian patches]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 6755a00cd2)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Stefan Müller
56ad2396ee package/libssh2: fix CVE-2026-66032
Backport the fix for CVE-2026-66032.

A SFTP error path can leave a dangling pointer after freeing the
response buffer, which may result in a double free on subsequent error
handling.

Use Debian's libssh2 1.11.1 backport of the upstream fix.

Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
[Julien: add links to Debian patches]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 05c13e87e9)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Stefan Müller
28f764e641 package/libssh2: fix CVE-2025-15661
Backport the SFTP symlink bounds checking fix for CVE-2025-15661.

The initial fix requires the LIBSSH2_UNCONST compatibility backport on
libssh2 1.11.1. Also include the upstream follow-up fixing
SSH_FXP_STATUS handling introduced by the initial security fix.

The patches are based on the upstream fixes and Debian's libssh2 1.11.1
backports.

Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
[Julien: add links to Debian patches]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 546fd31c70)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Fiona Klute (Othermo GmbH)
bf04be147b package/dracut: disable dracut-cpio if host-rustc is not available
Since upstream commit 89a86dcb0a3248606824de50f5c63f61cfe0369c (first
release: 106) if cargo exists on PATH the Dracut configure script
enables building dracut-cpio by default, and calls "cargo --version"
to check if cargo works. This fails on the autobuilders:

error: rustup could not choose a version of cargo to run, because one wasn't specified explicitly, and no default is configured.
help: run 'rustup default stable' to download the latest stable release of Rust and set it as your default toolchain.
dracut couldn't find cargo for dracut-cpio build

The affected configs either don't have BR2_PACKAGE_HOST_RUSTC enabled,
or build-time.log.gz shows host-rustc was not installed before the
host-dracut build, so presumably the "cargo" that produces the rustup
error is an external one already installed on the autobuilders.

To fix this, enable dracut-cpio only if BR2_PACKAGE_HOST_RUSTC=y, and
add a dependency on host-rustc in that case. According to the
documentation [1, see "enhanced_cpio"] dracut-cpio is supposed to
optimize archive creation for copy-on-write filesystems, so it should
not matter much for Buildroot. The --disable-dracut-cpio option was
added in upstream commit 4a4ab928a49e81e02104ec5466160664e59c3965
(same release).

Fixes: https://autobuild.buildroot.org/results/5f557d708cce997e7f039f17e30640b02ba9180a/
Fixes: https://autobuild.buildroot.org/results/f04ca3c4598f62a7e87d84bc111eb8b161b34a70/
(and more)

[1] https://dracut-ng.github.io/dracut/man/dracut.conf.5.html#_configuration_options

Signed-off-by: Fiona Klute (Othermo GmbH) <fiona.klute@gmx.de>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit ff7f973a16)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Stefan Müller
140b534bc2 package/wget: fix CVE-2026-58471
Backport the upstream fix for a heap buffer overflow in
convert_fname() when growing the iconv output buffer.

Backport to: 2025.02.x

Signed-off-by: Stefan Müller <stemu86@gmx.ch>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit e991fa0716)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Stefan Müller
fd6d1b7f99 package/wget: fix CVE-2026-58470
Backport the upstream fix for integer overflows while parsing
Content-Range headers, together with the follow-up fix using
strtoll() for wgint values.

Backport to: 2025.02.x

Signed-off-by: Stefan Müller <stemu86@gmx.ch>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 89485adb29)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Stefan Müller
5710385a72 package/wget: fix CVE-2026-58469
Backport the upstream fix for a buffer underflow in
clean_metalink_string(), together with the two required follow-up
fixes for the inverted whitespace check and missing ctype.h include.

Backport to: 2025.02.x

Signed-off-by: Stefan Müller <stemu86@gmx.ch>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 937e33237e)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Giulio Benetti
e419b2bcfc package/putty: security bump to version 0.85
Release notes:
https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html

THe release notes has 4 security related fixes. No CVE assigned.

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
[Julien: mark the commit as "security" related]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 131952483b)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Neal Frager
c267ef53bc boot/xilinx-embeddedsw: versal2_plm: configure xilpm runtime lib correctly
The xilpm_runtime_lib is not enabled by default in the versal2_plm Makefile:
97f2baf7f6/lib/sw_apps/versal_plm/src/versal_2ve_2vm/Makefile (L13)

Without it, there is a silent runtime failure.

Add config XILPM_RUNTIME_LIB=SUBSYS to make sure the xilpm_runtime_lib is
correctly configured and included to fix the problem.

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit c7810e5847)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Yann E. MORIN
79cfcaf399 DEVELOPERS: add Yann E. MORIN (work) for distribution-registry
Signed-off-by: Yann E. MORIN <yann.morin@orange.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 0480567def)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Yann E. MORIN
c1bfd5d5ab package/distribution-registry: needs NPTL
distribution-registry calls pthread_getattr_np() which is only available
with NPTL; i.e. always available with glibc (where it originates from,
since 2.2.3), always available with musl (which has had it since 0.9.10
in 2013), and only available when uClibc has NPTL (since 1.0.0 in 2015).

Fixes: https://autobuild.buildroot.org/results/9395500a8baee6c6142f96d7bc97e81725c2e754/

Signed-off-by: Yann E. MORIN <yann.morin@orange.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit d21a81ef8c)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Luca Ceresoli
d16f8597fe docs/manual: fix typo
Fix significant -> significantly.

Signed-off-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit b088e5dbe4)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Waldemar Brodkorb
b1b2c3f00a package/uclibc: PPC fix e500 fenv support
Problem found via Buildroot autobuilders, seems to be some
bitrotting code. Tested with qemu_ppc_mpc8544ds_defconfig
and a hard-float toolchain.

Fixes:
 - https://autobuild.buildroot.net/results/464/46448883b1682718aeff066d204349d8e9a3b1d1/
 - https://gitlab.com/buildroot.org/buildroot/-/jobs/15969219363

Signed-off-by: Waldemar Brodkorb <wbx@openadk.org>
[Julien: add link to CI build failure]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 5795000c25)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Thomas Petazzoni
848e36f65b package/igh-ethercat: backport upstream fix to build with Linux >= 6.19.0
Fixes:

  https://autobuild.buildroot.org/results/9b270904b2f7cf9eaa661c98370c582a61ff2342/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit e4cf512c39)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Romain Naour
424d201ab6 support/testing: remove TestGdbArc
The Arc specific gdb version was removed by commit [1]
but we still have the TestGdbArc that was testing this
version of gdb.

We can now safely remove TestGdbArc.

[1] 0b3d526226

Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 2f6b34f851)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Bernd Kuhls
d446361292 package/netsnmp: add upstream patch to fix build of depending packages
Buildroot commit ed27a33ba0 bumped the
package from 5.9.4 to 5.9.5.2 which includes upstream commit
7536a8d6d3
that breaks the build of other packages depending on netsnmp like ntp:

ntpSnmpSubagentObject.c: In function 'init_ntpSnmpSubagentObject':
./ntpSnmpSubagentObject.h:51:1: error: ISO C90 forbids mixed
 declarations and code [-Werror=declaration-after-statement]
   51 | static oid oidname##_oid [] = { __VA_ARGS__ };

For details see https://github.com/net-snmp/net-snmp/issues/1035

Fixes:
https://autobuild.buildroot.net/results/395/395a3b18719e4ec0c0b94b0692caaa9566ee57c6/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 139025f793)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Bernd Kuhls
d485b0677c package/uhttpd: bump version, fix cmake 4 compatibility
This bump includes upstream commit
https://git.openwrt.org/?p=project/uhttpd.git;a=commitdiff;h=ebb92e6b339b88bbc6b76501b6603c52d4887ba1
which fixes cmake 4 builds. No backports necessary because the cmake 4
bump commit e46695bbe4 is not present in
any older branches.

Updated hash of header file which is used as license file due to
upstream commits:
https://github.com/openwrt/uhttpd/commits/master/uhttpd.h

Disabled new configure option UCODE_SUPPORT which was added by upstream
commit:
https://git.openwrt.org/?p=project/uhttpd.git;a=commitdiff;h=3ceccd02d86bf4d6609f46d8b30963cc52034cc2

Fixes:
https://autobuild.buildroot.net/results/cc2/cc265d34aed684b88032edd04ca0fc88186ec676/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 88c353351a)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Fengwei Tan
202c0c4eac package/Makefile.in: fix support for $(PKG)_FLAT_STACKSIZE
When a package defines $(PKG)_FLAT_STACKSIZE, ELF2FLT_FLAGS contains
-Wl,-elf2flt="-r -s<stack-size>". The embedded quotes are needed to
keep both elf2flt options in single linker argument.

However, many package Makefiles wrap $(TARGET_CFLAGS) in double quotes,
for example:

  CFLAGS="$(TARGET_CFLAGS)"

After expansion, the embedded quote terminates the outer CFLAGS quote.
As a result, the shell interprets "-s<stack-size> ..." as a command
instead of passing it to the compiler.

Pass -r and -s<stack-size> in separate -Wl arguments instead. This
avoids embedded quotes; GCC forwards both -elf2flt options to
ld-elf2flt, which collects them before invoking elf2flt.

This got broken by commit
04d7ea4720 ("package: Makefile.in: fix
elf2flt invocation options"), which by adding -r as an elf2flt
argument, did not correctly handle -s$($(PKG)_FLAT_STACKSIZE).

Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
[Thomas: improve commit message]
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit e913afbeb1)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Giulio Benetti
13baef4c77 package/wireshark: security bump to v4.4.18
Fixes the following vulnerabilities:

- wnpa-sec-2026-64 · Sharkd utility crash
  https://www.wireshark.org/security/wnpa-sec-2026-64

- wnpa-sec-2026-65 · Sharkd utility crash
  https://www.wireshark.org/security/wnpa-sec-2026-65

- wnpa-sec-2026-66 · UMTS FP protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-66

- wnpa-sec-2026-67 · RDP protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-67

- wnpa-sec-2026-69 · Dissection engine reassembly crash
  https://www.wireshark.org/security/wnpa-sec-2026-69

- wnpa-sec-2026-70 · BUSMASTER file parser abnormal exit
  https://www.wireshark.org/security/wnpa-sec-2026-70

- wnpa-sec-2026-71 · Tektronix K12xx file parser crash
  https://www.wireshark.org/security/wnpa-sec-2026-71

- wnpa-sec-2026-72 · ERF file parser crash
  https://www.wireshark.org/security/wnpa-sec-2026-72

- wnpa-sec-2026-73 · Bluetooth Attribute Protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-73

- wnpa-sec-2026-74 · Catapult DCT2000 file parser crash
  https://www.wireshark.org/security/wnpa-sec-2026-74

- wnpa-sec-2026-75 · C12.22 protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-75

- wnpa-sec-2026-76 · CMS protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-76

- wnpa-sec-2026-77 · H.245 protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-77

- wnpa-sec-2026-78 · Kerberos protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-78

- wnpa-sec-2026-79 · Bluetooth HFP Profile protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-79

- wnpa-sec-2026-80 · Bluetooth BR/EDR FHS protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-80

- wnpa-sec-2026-81 · 3gpp phone log file parser crash
  https://www.wireshark.org/security/wnpa-sec-2026-81

- wnpa-sec-2026-83 · CMS protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-83

- wnpa-sec-2026-84 · Pcapng file parser crash
  https://www.wireshark.org/security/wnpa-sec-2026-84

- wnpa-sec-2026-85 · SSH protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-85

- wnpa-sec-2026-86 · ESS protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-86

- wnpa-sec-2026-87 · X.509IF protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-87

- wnpa-sec-2026-88 · RRC protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-88

- wnpa-sec-2026-89 · C12.22 protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-89

- wnpa-sec-2026-91 · Bluetooth AVRCP Profile
  https://www.wireshark.org/security/wnpa-sec-2026-91

For more information on the version bump, see:
  - https://www.wireshark.org/docs/relnotes/wireshark-4.4.18.html

[Peter: add list of vulnerabilities]
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 5245c41441)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Giulio Benetti
98816aaa9e package/wireshark: bump to v4.4.17
For more information on the version bump, see:
  - https://www.wireshark.org/docs/relnotes/wireshark-4.4.17.html

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 1d257e242c)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Giulio Benetti
34cc95533a package/udisks: security bump to version 2.11.2
This fixes this CVE:
CVE-2026-7867:
https://github.com/storaged-project/udisks/security/advisories/GHSA-j42g-v9jw-6ph3

Release notes:
https://github.com/storaged-project/udisks/releases/tag/udisks-2.11.2

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 93049b2559)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Roy Kollen Svendsen
9c36b45ac6 package/qt6: bump version to 6.11.1
For details see [1], [2], [3], [4], [5], [6], [7] and [8].

[1] https://code.qt.io/cgit/qt/qtreleasenotes.git/about/qt/6.9.2/release-note.md
[2] https://code.qt.io/cgit/qt/qtreleasenotes.git/about/qt/6.9.3/release-note.md

[3] https://code.qt.io/cgit/qt/qtreleasenotes.git/about/qt/6.10.0/release-note.md
[4] https://code.qt.io/cgit/qt/qtreleasenotes.git/about/qt/6.10.1/release-note.md
[5] https://code.qt.io/cgit/qt/qtreleasenotes.git/about/qt/6.10.2/release-note.md
[6] https://code.qt.io/cgit/qt/qtreleasenotes.git/about/qt/6.10.3/release-note.md

[7] https://code.qt.io/cgit/qt/qtreleasenotes.git/about/qt/6.11.0/release-note.md
[8] https://code.qt.io/cgit/qt/qtreleasenotes.git/about/qt/6.11.1/release-note.md

qt6multimedia:
Removed 0001-ffmpeg8.patch since the fix is included in this version. It
guarded AV_CODEC_CAP_SUBFRAMES, which FFmpeg deprecated and removed; the
guard was upstreamed in 6.9.2.

Signed-off-by: Roy Kollen Svendsen <roykollensvendsen@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 05cd38635a)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Alsey Coleman Miller
de57d9bcd9 package/wine: select libxkbcommon and libxml2 for the Wayland driver
wine.mk passes --with-wayland whenever BR2_PACKAGE_WAYLAND is enabled,
but nothing guarantees the rest of what wine's Wayland test needs is in
the configuration. That test is:

  WINE_NOTICE_WITH(wayland, [test -z "$WAYLAND_CLIENT_LIBS" \
    -o -z "$WAYLAND_SCANNER" -o -z "$XKBCOMMON_LIBS" \
    -o -z "$XKBREGISTRY_LIBS" -o "$ac_cv_header_linux_input_h" = "no"], ...)

and because --with-wayland is passed explicitly, WINE_NOTICE_WITH turns
into AC_MSG_ERROR rather than a notice.

So wine needs libxkbcommon, and it needs the libxkbregistry part of it,
which is only built when libxml2 is available. Select both when Wayland
support is enabled, and add libxkbcommon to the build dependencies.

Note that libxml2 is not a direct dependency of wine, it only has to be
in the configuration so that libxkbcommon builds libxkbregistry; the
build ordering is handled by libxkbcommon's own dependency on libxml2.

Signed-off-by: Alsey Coleman Miller <alseycmiller@gmail.com>
Reviewed-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit a5e7f7af9f)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Alsey Coleman Miller
92c3e21893 package/libxkbcommon: build libxkbregistry when libxml2 is available
libxkbregistry is the keyboard layout catalogue half of the library. It
parses the XML layout registry and so needs libxml2, which is presumably
why it was disabled unconditionally rather than wired to a dependency.

wine needs it. Its configure.ac requires XKBREGISTRY_LIBS alongside
wayland-client, wayland-scanner, xkbcommon and linux/input.h before it
will build the Wayland driver, and wine.mk passes --with-wayland for any
build with BR2_PACKAGE_WAYLAND - which turns that notice into a hard
error:

  checking for wayland-client.h... yes
  checking for wl_display_connect in -lwayland-client... yes
  checking for wayland-scanner... .../host/bin/wayland-scanner
  checking for xkb_context_new in -lxkbcommon... yes
  checking for wayland-egl.h... yes
  checking for wl_egl_window_create in -lwayland-egl... yes
  configure: error: Wayland development files not found, the Wayland
    driver won't be supported.
  This is an error since --with-wayland was requested.

Every other term of that test passes; only XKBREGISTRY_LIBS is empty, so
wine and wayland together could not be built on any architecture.

Gated on BR2_PACKAGE_LIBXML2 rather than turned on outright, because
meson.build takes dependency('libxml-2.0') unconditionally once
enable-xkbregistry is set, so a target without libxml2 would fail to
configure.

Regarding since when this is broken, three pieces had to come together:

 - libxkbcommon has passed -Denable-xkbregistry=false since commit
   1791bc30a5 ("package/libxkbcommon: bump version to 1.0.1", Sep 2020),
   i.e. Buildroot 2020.11. libxkbregistry has therefore never been built
   in Buildroot.

 - wine's configure gained the XKBREGISTRY_LIBS term in its Wayland
   test in wine 9.0, with upstream commit d64ea8e4a6c9
   ("winewayland.drv: Enumerate Xkb layouts and create matching HKL.",
   Nov 2023).

 - wine.mk started passing --with-wayland in commit 7cb49e7712
   ("package/wine: bump to version 9.19", Oct 2024), which is what turns
   the missing XKBREGISTRY_LIBS from a notice into a hard error.

The breakage therefore dates from Buildroot 2024.11, and every branch
since is affected, including the LTS one: 2025.02.x carries wine 10.0,
whose configure has the XKBREGISTRY_LIBS check, together with
libxkbcommon 1.9.2 built with -Denable-xkbregistry=false, and its wine.mk
passes --with-wayland. 2025.05.x and 2025.08.x are in the same state.
A backport to 2025.02.x is thus needed.

Signed-off-by: Alsey Coleman Miller <alseycmiller@gmail.com>
Reviewed-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 4349b22b91)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Nicolas Cavallari
7fee4818cd package/libgit2: security bump version to 1.9.7
Fixes CVE-2026-5917 when used with libssh2

Release notes:
https://github.com/libgit2/libgit2/releases/tag/v1.9.7

Signed-off-by: Nicolas Cavallari <nicolas.cavallari@green-communications.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 2d40ae9f2c)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Peter Korsgaard
20d16b3694 package/go: security bump to version 1.26.6
Fixes the following security issues:

 - x/mod/sumdb/tlog: fix transparency log tile verification bypass

   A malicious GOPROXY was previously capable of forging up to two sumdb
   tiles that allow for a requested module to bypass the GOSUMDB check and
   persist attacker-controlled module content to a local Go module cache.

   This attack allows for a malicious GOPROXY to serve malicious module
   content that cannot be detected by evaluating the transparency log.

   All tiles are now correctly verified against their parents.

   In order to determine if you have been affected:

   rm -r go.sum go.work.sum vendor/ && go mod tidy

   Thanks to Filippo Valsorda (Geomys) for reporting this issue.

   This is CVE-2026-56865 and Go issue https://go.dev/issue/80744.

 - x/mod/sumdb: ignore unrelated, unauthenticated hashes in Lookup

   A malicious GOSUMDB was capable of serving arbitrary module content not
   contained within the transparency log.

   This attack allows for a coordinating GOPROXY and GOSUMDB to serve a
   client malicious module content that cannot be detected by evaluating
   the transparency log.

   In order to determine if you have been affected:

   rm -r go.sum go.work.sum vendor/ && go mod tidy

   Thanks to mundur for reporting this issue.

   This is CVE-2026-56864 and Go issue https://go.dev/issue/80745.

 - encoding/xml: add recursion depth guard during decode

   Previously, DecodeElement would reset the depth counter causing it to
   never fire; this could lead to stack exhaustion.

   This is CVE-2026-56859 and Go issue https://go.dev/issue/80481.

 - net/http: apply ReadHeaderTimeout when doing unencrypted HTTP/2 check

   When a server is configured to support unencrypted HTTP/2, it reads a few
   bytes from each new connection to see if they contain the HTTP/2 client
   preface.  Previously, this was being done with no timeout applied.
   ReadHeaderTimeout is now applied for this.

   This is CVE-2026-56853 and Go issue https://go.dev/issue/80205.

 - net/url: avoid quadratic complexity in resolvePath

   Previously, resolving relative paths containing parent directory (..)
   segments performed string conversions and buffer rewrites on each step,
   resulting in quadratic time complexity and high memory allocation
   overhead.

   Now, path resolution operates on a byte buffer using index-based
   backtracking for ..  segments, eliminating the quadratic time complexity
   and significantly reducing memory allocations.

   This is CVE-2026-56860 and Go issue https://go.dev/issue/80494.

 - golang.org/x/net/dns/dnsmessage: panic when parsing invalid SVCB record

   Parsing an invalid SVCB or HTTPS RR can panic when the size of a
   parameter value overflows the message buffer.

   Thanks to Mundur (https://github.com/M0nd0R) for reporting this issue.

   This is CVE-2026-46600 and Go issue https://go.dev/issue/79795.

 - crypto/tls: limit handshake messages we are willing to accept post-handshake

   Previously, we always counted handshake messages, such as KeyUpdate, as
   state-advancing, regardless of whether a handshake has been completed or
   not.  As a result, a malicious client can keep sending KeyUpdate messages
   to force the server to keep performing key derivation operations
   indefinitely.

   Thanks to Qi Deng of Aurascape.ai for reporting this issue.

   This is CVE-2026-56862 and Go issue https://go.dev/issue/80528.

 - html/template: fix Javascript regexp context tracking

   Previously, pathological inputs could close an unescaped / early,
   allowing for attack-controlled data to inject arbitrary content,
   potentially leading to XSS.

   Thanks to Ali Sherif for reporting this issue.

   This is CVE-2026-56858 and Go issue https://go.dev/issue/80435.

 - x/net/idna: failure to reject ASCII-only Punycode-encoded labels

   The ToASCII and ToUnicode functions incorrectly accepted Punycode-encoded
   labels that decode to an ASCII-only label.  For example,
   ToUnicode("xn--example-.com") incorrectly returned the name "example.com"
   rather than an error.

   The idna package implements the processing algorithm from UTS 46.  Older
   versions of UTS 46 included a specification bug which permitted multiple
   ASCII labels to decode to the same Unicode label.  UTS 46 revision 33
   fixed the specification bug.  The idna package now implements the updated
   specification.

   This behavior can lead to privilege escalation in programs using the idna
   package.  For example, a program which performs privilege checks on the
   ASCII hostname may reject "example.com" but permit "xn--example-.com".
   If that program subsequently converts the ASCII hostname to Unicode, it
   will inadvertently permits access to the Unicode name "example.com".

   Thanks to KC1zs4 (https://github.com/KC1zs4) for reporting this issue.

   This is CVE-2026-39821 and Go issue https://go.dev/issue/78760.

 - encoding/asn1: enforce maximum recursion depth

   Enforce a recursion limit in Unmarshal to prevent stack exhaustion when
   parsing deeply-nested, recursive structures.

   Thanks to Marwan Atia (marwansamir688@gmail.com) for reporting this issue.

   This is CVE-2026-33818 and Go issue https://go.dev/issue/80405.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 9e9110bf23)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Yann E. MORIN
662b43976b package/go: decrease debug level for CGO linking
Workaround an upstream issue that arises when packages are build with
gdb -g3 debug level:
    https://github.com/golang/go/issues/77436

This has been fixed upstream, but is not released yet, so add a comment
stating when to remove the workaround.

Fixes:
    https://autobuild.buildroot.org/results/97cd9c2586a0cc2a16cdb2a75dae1836feb5ffc3/
    (and probably a lot more...)

Signed-off-by: Yann E. MORIN <yann.morin@orange.com>
Cc: Christian Stewart <christian@aperture.us>
Cc: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit ec8f1b03e6)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Bernd Kuhls
5bec46058a package/hostapd: bump version to 2.12
https://lists.infradead.org/pipermail/hostap/2026-August/045441.html

Removed patches which are included in this release.

Removed the hostap driver from the package due to its upstream removal:
https://git.w1.fi/cgit/hostap/commit/?id=dfd207d96c1bbc4a2013db638bc1d48cc0865c27

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 83f79dd82c)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Fred Lefranc
edad306d63 packages/haproxy: security bump to version 2.6.32
Bugfix release with large number of (security) fixes.

HAProxy 2.6.32 was released on 2026/07/29. It added 33 new commits
after version 2.6.31.

As for the 2.8.27, the announce is an expurgated copy-paste of the 3.4.3
announce:

* stats: Two issues about the stats page, reported by Red Hat/AISLE
  Research, were fixed.

  Proxies updated through the stats page while in "stats admin" mode were
  not subject to the "stats scope" filtering, meaning a scope meant to
  restrict which proxies are visible/actionable could be silently bypassed
  on POST requests.
  Separately, POST requests to the stats interface did not validate that the
  Origin (or Referer) header matched the Host, which is now checked to
  mitigate CSRF attacks.

* ssl-gencert: A memory leak on every certificate generation was fixed.

  Two temporary buffers were not freed after generating a certificate on the
  fly, leaking memory each time a new SNI triggered certificate
  generation. This issue was reported by Red Hat/AISLE Research.

* sample/protobuf: buffer overflows after pointer-shift converters, reported
  by Red Hat/AISLE Research and Charles Vosburgh, were fixed.

  Several converters (protobuf/ungrpc field extraction, ltrim())
  move the sample's data pointer forward on success but did not shrink the
  sample's recorded buffer capacity accordingly. A converter chained
  afterwards that relies on that capacity (e.g. padding via memset()) could
  then write past the end of the buffer, leading to heap corruption or a
  worker crash. All the affected converters now adjust the capacity
  together with the pointer.

* protobuf: A nested-path validation bypass reported by Red Hat/AISLE
  Research was fixed.

  The protobuf field lookup used for the protobuf()/ungrpc() converters did
  not strictly enforce hierarchical boundaries, so a flat sibling field
  could incorrectly satisfy a nested-path lookup (e.g. matching a root-level
  field as if it were nested under a parent). The lookup was rewritten as a
  strict, non-recursive path walker that correctly bounds each nesting
  level.
  Separately, a crash because of deprecated protobuf group wire types was
  fixed. These wire types are now explicitly rejected.

* http-fetch: Two crashes reachable from health-check configurations were
  fixed.

  "res.body"/"res.hdr"/... and similar response fetches assumed the
  health-check receive buffer always held an HTX message, which is only true
  for actual HTTP checks; on a plain TCP check, a hostile/misbehaving server
  could craft the first bytes of its reply to be misinterpreted as HTX
  internal fields, causing a wild read and worker crash (or leaking
  arbitrary process memory).
  Separately, "capture.req.hdr"/"capture.res.hdr" only validated the upper
  bound of their index argument, so a negative capture id was accepted at
  boot and dereferenced an out-of-bounds array entry at runtime, crashing
  the worker on the very first request.

* slz: Several issues were fixed in the SLZ library.

  A stream alternating many literals in the 144-255 range with cheap
  back-references could keep inflating indefinitely instead of falling
  back to a stored block, exceeding the library's documented worst-case
  output size by several percent. A new accounting mechanism now bounds
  this overhead. Practical impact on haproxy requires tune.bufsize above
  ~43 kB with the default reserve.
  Five small correctness fixes inherited from upstream libslz were also
  backported: Avoid reading up to a few bytes past the end of very short
  inputs on architectures without fast unaligned access; stop appending an
  extra, misplaced block to an already-finished deflate/gzip/zlib stream
  (which could corrupt the trailing checksum in ~2% of fuzzed streams); fix
  the Adler32 checksum accumulator sign handling on 32-bit systems
  (affecting the zlib format only); avoid an undefined-behaviour signed left
  shift when assembling input words byte by byte; and use the exact bit cost
  when deciding whether to emit the last literals of a block as a stored
  block, avoiding compressed output slightly larger than the documented
  worst case.

* peers: A heap overflow when replicating large stick-table dictionary
  entries was fixed.

  peer_prepare_updatemsg() never verified that a stick-table entry's
  dictionary value (e.g. server_key, up to ~16 kB) actually fit in the
  update message being built. Since the peers protocol is plain-text and
  unauthenticated, a rogue or compromised peer could plant an oversized
  entry that overflows the 16 kB trash buffer as soon as the victim
  replicates ("teaches") it, confirmed as a heap-buffer-overflow write. The
  function now checks the available room before encoding and fails cleanly
  if it doesn't fit. This was reported and fixes by Matt Suiche from Tolmo
  Inc.

And, as usual, the bunch of minor fixes here and there, mainly raised during
AI-assisted code reviews. Most were never noticed:

* HTX API: Some bugs about how the HTX API was used were fixed here and
  there.

* http-act: Double-frees and a couple of state bugs on parsing errors were
  fixed.

* http-fetch/http-ana/http-htx: Few out-of-bounds reads were fixed.

* http-conv: The last input character could be lost when calling url-dec
  converter, when the input buffer was full. This was fixed by failing the
  converter in that case.

* mux-h1: An extra 200ms delay was observed on some H2-to-H1 messages
  because the end of the message was not always properly detected. This
  case is now properly handled.

* sample: An edge case in be2hex() was fixed.

For more details, see the announcement:
https://www.mail-archive.com/haproxy@formilux.org/msg47353.html

Signed-off-by: Fred Lefranc <fred.lefranc.evs@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 335a57525f)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
Giulio Benetti
44867126f0 package/mongoose: security bump to version 7.23
Release notes:
https://github.com/cesanta/mongoose/releases/tag/7.23

Fixes CVE-2026-73261, CVE-2026-73260, CVE-2026-63626, CVE-2026-73252,
CVE-2026-73251.

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 2bf6549d18)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:58:04 +02:00
208 changed files with 3299 additions and 947 deletions

97
CHANGES
View File

@@ -1,3 +1,100 @@
2026.05.3, released September 10, 2026
Important / security related fixes:
avro-c: (no CVE assigned)
dnsmasq: CVE-2026-12725, CVE-2026-12969
erlang: CVE-2026-21620, CVE-2026-23941, CVE-2026-23942, CVE-2026-23943,
CVE-2026-28810, CVE-2026-32147, CVE-2026-42789, CVE-2026-42790
exiv2: CVE-2026-49275, CVE-2026-68546, CVE-2026-68547,
GHSA-3695-mjv8-3r52, GHSA-9v3x-mhg4-wwv2, GHSA-fgw8-p7pr-37cp,
GHSA-hxph-pv7w-8649, GHSA-jcgh-p9v3-pw6j, GHSA-vg6c-9f6h-4x5q
expat: CVE-2026-66046, CVE-2026-76641, CVE-2026-76956, CVE-2026-76957
glibc: CVE-2026-18374, CVE-2026-19499, CVE-2026-77117, CVE-2026-80489
go: CVE-2026-33818, CVE-2026-39821, CVE-2026-46600, CVE-2026-56853,
CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862,
CVE-2026-56864, CVE-2026-56865
haproxy: (no CVE assigned)
hostapd: CVE-2026-58374
libcurl: CVE-2026-13608, CVE-2026-18924, CVE-2026-19931,
CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255,
CVE-2026-82208, CVE-2026-82209
libde265: GHSA-mm7m-v26f-wf8x, GHSA-xp3h-6f5r-8cxp
libgit2: CVE-2026-5917
libheif: CVE-2026-84450, CVE-2026-84451, GHSA-24wx-9w62-c96w,
GHSA-2jg2-4ch7-h545, GHSA-4h82-g446-83fm, GHSA-4jqm-2x34-6f6r,
GHSA-73p7-m7gg-w2jv, GHSA-8857-r8x5-7499, GHSA-8fmq-r4pf-7m57,
GHSA-9rj8-5mp5-26c9, GHSA-g89c-p67h-r497, GHSA-gh5q-69gg-c964,
GHSA-hh47-fhqr-cj2r, GHSA-j264-xvrp-5v7q, GHSA-jc8f-p23p-5hjg,
GHSA-mw6f-29j3-76f4, GHSA-p58j-h3vm-3fp5, GHSA-w7mc-p8jc-p853,
GHSA-x8r2-mggj-j6wr, GHSA-x8xm-cm2c-cfc8, GHSA-xw34-mjcp-jqh8
libldns: CVE-2026-10846
libopenssl: CVE-2026-14456, CVE-2026-14457, CVE-2026-18798,
CVE-2026-54874, CVE-2026-54876, CVE-2026-63072, CVE-2026-63073,
CVE-2026-63074, CVE-2026-63075, CVE-2026-63076, CVE-2026-75803
libssh2: CVE-2025-15661, CVE-2026-66032, CVE-2026-66033,
CVE-2026-66034, CVE-2026-66035
localedef: CVE-2026-18374, CVE-2026-19499, CVE-2026-77117,
CVE-2026-80489
mongoose: CVE-2026-63626, CVE-2026-73251, CVE-2026-73252,
CVE-2026-73260, CVE-2026-73261
nodejs: CVE-2026-56846, CVE-2026-56847, CVE-2026-56848, CVE-2026-56850,
CVE-2026-58039, CVE-2026-58040, CVE-2026-58042, CVE-2026-58043,
CVE-2026-58044, CVE-2026-58045
openvpn: CVE-2026-84732
proftpd: CVE-2026-44331
putty: (no CVE assigned)
python-avro: (no CVE assigned)
redis: CVE-2026-62356
rsyslog: CVE-2026-19654
udisks: CVE-2026-7867, GHSA-j42g-v9jw-6ph3
unbound: CVE-2026-14586, CVE-2026-32665, CVE-2026-40622,
CVE-2026-40691, CVE-2026-41637, CVE-2026-42955, CVE-2026-44621,
CVE-2026-44687, CVE-2026-44690, CVE-2026-46582, CVE-2026-50045,
CVE-2026-50046, CVE-2026-50243, CVE-2026-50248, CVE-2026-50251,
CVE-2026-50252, CVE-2026-52863, CVE-2026-54478, CVE-2026-55708,
CVE-2026-55717, CVE-2026-55973, CVE-2026-55990, CVE-2026-55991,
CVE-2026-56416, CVE-2026-56444
wget: CVE-2026-58469, CVE-2026-58470, CVE-2026-58471
wireshark: CVE-2026-15163, CVE-2026-15164, CVE-2026-15166,
CVE-2026-15167, CVE-2026-15168, CVE-2026-15169, CVE-2026-15170,
CVE-2026-15171, CVE-2026-15172, CVE-2026-15174, CVE-2026-76879,
CVE-2026-76880, CVE-2026-76881, CVE-2026-76882, CVE-2026-76883,
CVE-2026-76884, CVE-2026-76885, CVE-2026-76886, CVE-2026-76887,
CVE-2026-76888, CVE-2026-76889, CVE-2026-76890, CVE-2026-76891,
CVE-2026-76917, CVE-2026-76918, CVE-2026-76919, CVE-2026-76920,
CVE-2026-76921, CVE-2026-76922, CVE-2026-76923, CVE-2026-76924,
CVE-2026-76926, CVE-2026-76927, CVE-2026-76928, CVE-2026-76929
Toolchain:
- linux-headers: bump to 5.10.269, 5.15.220, 6.1.187, 6.6.156,
6.12.109, 6.18.50
- powerpc: correctly track libquadmath
Infrastructure updates/fixes:
- Fix setting of stack size for FLAT binaries
- Various fixes to the runtime tests
- manual: document the LTS release cadence correctly
- manual: document move of patchwork to patchwork.buildroot.org
Updated defconfigs: qemu_xtensa_lx60*
Updated / fixed packages: avro-c, bind, bpftrace, clamav, collectd,
dahdi-linux, dejavu, distribution-registry, dnsmasq, dpdk, dracut,
enscript, erlang, exiv2, expat, gdb, glibc, go, haproxy, hostapd,
igh-ethercat, jpeg-turbo, libbpf, libcurl, libde265, libgit2,
libheif, libldns, libnfs, libopenssl, libssh2, libxkbcommon,
libxml-parser-perl, libxml2, linux, linux-headers, linux-tools,
localedef, mesa3d, mongoose, netsnmp, newt, nodejs, olsr, opencv4,
openssh, openvpn, passt, perl, powerpc, proftpd, putty, python-avro,
python-charset-normalizer, python-gobject, qt5knx, qt6, qt6base,
qt6declarative, redis, rsyslog, taglib, toolchain-external-bootlin,
uclibc, udisks, uhttpd, unbound, vim, webkitgtk, wget, wine,
wireless-regdb, wireshark, xilinx-embeddedsw
2026.05.2, released August 23, 2026
Important / security related fixes:

View File

@@ -146,6 +146,12 @@ endif
comment "Legacy options removed in 2026.05.2"
config BR2_PACKAGE_HOSTAPD_DRIVER_HOSTAP
bool "hostapd hostap driver removed"
select BR2_LEGACY
help
The hostap driver was removed from hostapd.
config BR2_GDB_VERSION_ARC
bool "ARC-specific gdb version removed"
select BR2_LEGACY

View File

@@ -1157,6 +1157,7 @@ F: package/ser2net/
N: Franciszek Stachura <fbstachura@gmail.com>
F: support/testing/tests/package/test_memcached.py
F: support/testing/tests/package/test_nano.py
N: Francois Dugast <francois.dugast.foss@gmail.com>
F: board/sipeed/licheepi_nano/
@@ -1836,6 +1837,8 @@ F: support/testing/tests/boot/test_optee_os.py
F: support/testing/tests/boot/test_optee_os/
F: support/testing/tests/fs/test_btrfs.py
F: support/testing/tests/fs/test_btrfs/
F: support/testing/tests/fs/test_cramfs.py
F: support/testing/tests/fs/test_cramfs/
F: support/testing/tests/fs/test_erofs.py
F: support/testing/tests/fs/test_erofs/
F: support/testing/tests/fs/test_xfs.py
@@ -2008,6 +2011,8 @@ F: support/testing/tests/package/test_python_pyqt5.py
F: support/testing/tests/package/test_python_pyqt5/
F: support/testing/tests/package/test_python_spake2.py
F: support/testing/tests/package/test_python_sympy.py
F: support/testing/tests/package/test_quickjs.py
F: support/testing/tests/package/test_quickjs/
F: support/testing/tests/package/test_rdma_core.py
F: support/testing/tests/package/test_rdma_core/
F: support/testing/tests/package/test_rrdtool.py
@@ -2041,6 +2046,8 @@ F: support/testing/tests/package/test_weston/
F: support/testing/tests/package/test_wget.py
F: support/testing/tests/package/test_which.py
F: support/testing/tests/package/test_wine.py
F: support/testing/tests/package/test_wpa_supplicant.py
F: support/testing/tests/package/test_wpa_supplicant/
F: support/testing/tests/package/test_xfsprogs.py
F: support/testing/tests/package/test_xfsprogs/
F: support/testing/tests/package/test_xvisor.py
@@ -2499,7 +2506,6 @@ F: package/binutils-bare-metal/
F: package/bootgen/
F: package/gcc-bare-metal/
F: package/newlib-bare-metal/
F: package/qemu-xen/
F: package/xen/
F: package/xilinx-fpgautil/
F: toolchain/toolchain-bare-metal-buildroot/
@@ -2687,6 +2693,7 @@ F: package/ugetty/
F: package/wireguard-linux-compat/
F: package/wireguard-tools/
F: support/testing/tests/package/test_docker_compose.py
F: support/testing/tests/package/test_haproxy.py
F: support/testing/tests/package/test_python_hid.py
N: Peter Seiderer <ps.report@gmx.net>
@@ -3265,6 +3272,8 @@ F: support/testing/tests/package/sample_python_flask.py
F: support/testing/tests/package/sample_python_flask_expects_json.py
F: support/testing/tests/package/sample_python_git.py
F: support/testing/tests/package/sample_python_unittest_xml_reporting.py
F: support/testing/tests/package/test_bpftrace.py
F: support/testing/tests/package/test_bpftrace/linux-bpftrace.fragment
F: support/testing/tests/package/test_nodejs.py
F: support/testing/tests/package/test_python_augeas.py
F: support/testing/tests/package/test_python_crccheck.py
@@ -3477,6 +3486,7 @@ F: package/tpm2-pkcs11/
N: Yann E. MORIN <yann.morin@orange.com>
F: .editorconfig
F: package/amazon-ecr-credential-helper/
F: package/distribution-registry/
F: package/docker-credential-acr-env/
F: package/docker-credential-gcr/
F: package/gpsd/

View File

@@ -92,9 +92,9 @@ all:
.PHONY: all
# Set and export the version string
export BR2_VERSION := 2026.05.2
export BR2_VERSION := 2026.05.3
# Actual time the release is cut (for reproducible builds)
BR2_VERSION_EPOCH = 1787518800
BR2_VERSION_EPOCH = 1789069200
# Save running make version since it's clobbered by the make package
RUNNING_MAKE_VERSION := $(MAKE_VERSION)

View File

@@ -0,0 +1,36 @@
From 5358d4e20801ffbb1c0834eab36c003049d4055f Mon Sep 17 00:00:00 2001
From: Romain Naour <romain.naour@smile.fr>
Date: Sun, 16 Aug 2026 22:27:28 +0200
Subject: [PATCH] xtensa: disable SSP when needed
-fno-stack-protector must be passed to avoid linking errors related to
undefined references to '__stack_chk_guard' and '__stack_chk_fail' if
toolchain enforces -fstack-protector.
Fixes:
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15876432953
Upstream: Submitted to Max Filippov via email for initial review.
Cc: Max Filippov <jcmvbkbc@gmail.com>
Signed-off-by: Romain Naour <romain.naour@smile.fr>
---
arch/xtensa/boot/Makefile | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/xtensa/boot/Makefile b/arch/xtensa/boot/Makefile
index d8b0fadf429a9..dfb758cdb2756 100644
--- a/arch/xtensa/boot/Makefile
+++ b/arch/xtensa/boot/Makefile
@@ -9,7 +9,7 @@
# KBUILD_CFLAGS used when building rest of boot (takes effect recursively)
-KBUILD_CFLAGS += -fno-builtin
+KBUILD_CFLAGS += -fno-builtin -fno-stack-protector
subdir-y := lib
targets += vmlinux.bin vmlinux.bin.gz
--
2.55.0

View File

@@ -53,7 +53,8 @@ define XILINX_EMBEDDEDSW_BUILD_VERSAL2_PLM
COMPILER=$(XILINX_EMBEDDEDSW_MICROBLAZE_CC) \
ARCHIVER=$(XILINX_EMBEDDEDSW_MICROBLAZE_AR) \
CC=$(XILINX_EMBEDDEDSW_MICROBLAZE_CC) \
CFLAGS=$(XILINX_EMBEDDEDSW_CFLAGS)
CFLAGS=$(XILINX_EMBEDDEDSW_CFLAGS) \
XILPM_RUNTIME_LIB=SUBSYS
endef
define XILINX_EMBEDDEDSW_INSTALL_VERSAL2_PLM

View File

@@ -2,7 +2,7 @@ BR2_xtensa=y
BR2_XTENSA_CUSTOM=y
BR2_XTENSA_OVERLAY_FILE="https://github.com/jcmvbkbc/xtensa-toolchain-build/raw/95291b7c39e6f790d0b2f062c945a630290f2c81/overlays/xtensa_dc233c.tar.gz"
BR2_PACKAGE_HOST_LINUX_HEADERS_CUSTOM_6_18=y
BR2_GLOBAL_PATCH_DIR="board/qemu/patches"
BR2_GLOBAL_PATCH_DIR="board/qemu/patches board/qemu/xtensa-lx60/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_TARGET_GENERIC_GETTY_PORT="ttyS0"
BR2_SYSTEM_DHCP="eth0"

View File

@@ -3,7 +3,7 @@ BR2_XTENSA_CUSTOM=y
BR2_XTENSA_OVERLAY_FILE="https://github.com/jcmvbkbc/xtensa-toolchain-build/raw/95291b7c39e6f790d0b2f062c945a630290f2c81/overlays/xtensa_dc233c.tar.gz"
# BR2_XTENSA_USE_MMU is not set
BR2_PACKAGE_HOST_LINUX_HEADERS_CUSTOM_6_18=y
BR2_GLOBAL_PATCH_DIR="board/qemu/patches"
BR2_GLOBAL_PATCH_DIR="board/qemu/patches board/qemu/xtensa-lx60/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_TARGET_GENERIC_GETTY_PORT="ttyS0"
BR2_SYSTEM_DHCP="eth0"

View File

@@ -460,7 +460,7 @@ editing the commit message. Below the +Signed-off-by+ section, add
Although the changelog will be visible for the reviewers in the mail
thread, as well as in
https://patchwork.ozlabs.org/project/buildroot/list/[patchwork], +git+
https://patchwork.buildroot.org/project/buildroot/list/[patchwork], +git+
will automatically ignores lines below +---+ when the patch will be
merged. This is the intended behavior: the changelog is not meant to
be preserved forever in the +git+ history of the project.
@@ -513,19 +513,19 @@ $ git format-patch -v4 -M -s -o outgoing origin/master
When you provide a new version of a patch, please mark the old one as
superseded in
https://patchwork.ozlabs.org/project/buildroot/list/[patchwork]. You
https://patchwork.buildroot.org/project/buildroot/list/[patchwork]. You
need to create an account on
https://patchwork.ozlabs.org/project/buildroot/list/[patchwork] to be
https://patchwork.buildroot.org/project/buildroot/list/[patchwork] to be
able to modify the status of your patches. Note that you can only change
the status of patches you submitted yourself, which means the email
address you register in
https://patchwork.ozlabs.org/project/buildroot/list/[patchwork] should
https://patchwork.buildroot.org/project/buildroot/list/[patchwork] should
match the one you use for sending patches to the mailing list.
You can also add the +--in-reply-to=<message-id>+ option when
submitting a patch to the mailing list. The id of the mail to reply to
can be found under the "Message Id" tag on
https://patchwork.ozlabs.org/project/buildroot/list/[patchwork]. The
https://patchwork.buildroot.org/project/buildroot/list/[patchwork]. The
advantage of *in-reply-to* is that patchwork will automatically mark
the previous version of the patch as superseded.
@@ -664,7 +664,7 @@ Creating a basic test case involves:
advantage of using +infra.basetest.BASIC_TOOLCHAIN_CONFIG+ is that a
matching Linux kernel image is provided, which allows to boot the
resulting image in Qemu without having to build a Linux kernel image
as part of the test case, therefore significant decreasing the build
as part of the test case, therefore significantly decreasing the build
time required for the test case.
* Implementing a +def test_run(self):+ function to implement the

View File

@@ -23,8 +23,8 @@ to you.
| +-- linux.config
| +-- busybox.config
| +-- <other configuration files>
| +-- post_build.sh
| +-- post_image.sh
| +-- post-build.sh
| +-- post-image.sh
| +-- rootfs_overlay/
| | +-- etc/
| | +-- <some files>
@@ -84,7 +84,7 @@ layers 'common' and 'fooboard' is:
+-- board/
+-- <company>/
+-- common/
| +-- post_build.sh
| +-- post-build.sh
| +-- rootfs_overlay/
| | +-- ...
| +-- patches/
@@ -94,7 +94,7 @@ layers 'common' and 'fooboard' is:
+-- linux.config
+-- busybox.config
+-- <other configuration files>
+-- post_build.sh
+-- post-build.sh
+-- rootfs_overlay/
| +-- ...
+-- patches/

View File

@@ -35,9 +35,9 @@ your project can be skipped.
Set +BR2_ROOTFS_OVERLAY+
to +board/<manufacturer>/<boardname>/rootfs-overlay+.
. Create a post-build script
+board/<manufacturer>/<boardname>/post_build.sh+. Set
+board/<manufacturer>/<boardname>/post-build.sh+. Set
+BR2_ROOTFS_POST_BUILD_SCRIPT+ to
+board/<manufacturer>/<boardname>/post_build.sh+
+board/<manufacturer>/<boardname>/post-build.sh+
. If additional setuid permissions have to be set or device nodes have
to be created, create +board/<manufacturer>/<boardname>/device_table.txt+
and add that path to +BR2_ROOTFS_DEVICE_TABLE+.

View File

@@ -52,7 +52,7 @@ Using post-build scripts, you can remove or modify any file in your
post-build cleanup scripts.
+
As shown in xref:customize-dir-structure[], the recommended path for
this script is +board/<company>/<boardname>/post_build.sh+.
this script is +board/<company>/<boardname>/post-build.sh+.
+
The post-build scripts are run with the main Buildroot tree as current
working directory. The path to the target filesystem is passed as the

View File

@@ -15,14 +15,14 @@ available in `support/misc/Vagrantfile` in the Buildroot source tree
to quickly set up a virtual machine with the needed dependencies to
get started.
If you want to setup an isolated buildroot environment on Linux or Mac
Os X, paste this line onto your terminal:
If you want to set up an isolated Buildroot environment on Linux or Mac
OS X, paste this line into your terminal:
----
curl -O https://buildroot.org/downloads/Vagrantfile; vagrant up
----
If you are on Windows, paste this into your powershell:
If you are on Windows, paste this into your PowerShell:
----
(new-object System.Net.WebClient).DownloadFile(

View File

@@ -16,11 +16,11 @@ filesystem with Buildroot).
Buildroot is useful mainly for people working with embedded systems.
Embedded systems often use processors that are not the regular x86
processors everyone is used to having in his PC. They can be PowerPC
processors, MIPS processors, ARM processors, etc.
processors developers are used to having in their PCs, including
ARM (both 32- and 64-bit), MIPS, PowerPC, RISC-V and more.
Buildroot supports numerous processors and their variants; it also
comes with default configurations for several boards available
comes with default configurations for hundreds of boards available
off-the-shelf. Besides this, a number of third-party projects are based on,
or develop their BSP footnote:[BSP: Board Support Package] or
SDK footnote:[SDK: Software Development Kit] on top of Buildroot.

View File

@@ -5,19 +5,21 @@
== Release Engineering
=== Releases
The Buildroot project makes quarterly releases with monthly bugfix
releases. The first release of each year is a long term support
release, LTS.
The Buildroot project makes quarterly stable releases with monthly bugfix
releases. Starting with 2025.02, the first release of every odd-numbered year
is a long-term support (LTS) release supported for three years.
- Quarterly releases: 2020.02, 2020.05, 2020.08, and 2020.11
- Bugfix releases: 2020.02.1, 2020.02.2, ...
- LTS releases: 2020.02, 2021.02, ...
- LTS releases: 2025.02, 2027.02, 2029.02 ...
- Non-LTS releases: 2025.05, 2025.08, 2025.11, 2026.02, ...
- Bugfix releases: 2025.02.1, 2025.02.2, ...
Releases are supported until the first bugfix release of the next
release, e.g., 2020.05.x is EOL when 2020.08.1 is released.
LTS releases are supported for three years, with a one-year overlap with the
next LTS release, e.g., 2025.02.x is EOL when 2028.02 is released.
LTS releases are supported until the first bugfix release of the next
LTS, e.g., 2020.02.x is supported until 2021.02.1 is released.
Non-LTS releases are supported until the next release, e.g., 2025.05.x is EOL
when 2025.08 is released.
See the table at https://lts.buildroot.org/#releases[lts.buildroot.org].
=== Development

View File

@@ -68,4 +68,4 @@ review comments in a clean and concise web interface, it can be useful
for all Buildroot developers.
+
The Buildroot patch management interface is available at
https://patchwork.ozlabs.org/project/buildroot/list/[].
https://patchwork.buildroot.org/project/buildroot/list/[].

View File

@@ -18,7 +18,7 @@
autobuild failures</a></li>
<li>Reviewing and testing patches sent by other developers. See the
<a href="https://lists.buildroot.org/mailman/listinfo/buildroot">mailing list
</a> or <a href="https://patchwork.ozlabs.org/project/buildroot/list/">
</a> or <a href="https://patchwork.buildroot.org/project/buildroot/list/">
patchwork</a>.</li>
<li>Working on items from the
<a href="https://www.elinux.org/Buildroot#Todo_list">TODO list</a></li>

View File

@@ -1,10 +1,10 @@
# From https://www.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
sha256 949d166a1263bd0cf0c5aab44eeb57869615099e7c48bf88d0e4adb77379b999 linux-6.12.104.tar.xz
sha256 778b058c63da849d0b74006b23509255b2bed57c62a5151e9dd7a62e2cdd70d6 linux-6.6.152.tar.xz
sha256 362d07fe4938c415ce651aefee063a5c4151109b39c97be039bbaa8312ffc0e2 linux-6.1.183.tar.xz
sha256 5484e552a334e15019f4aeba89e5b58f04651cf2f4e24e04de9f152f1c38e3fa linux-6.12.109.tar.xz
sha256 aee2264a4eaf4a14344b47a0469bd42e8b4885b24f110b724262b3da956f411d linux-6.6.156.tar.xz
sha256 1b6e798aeaa708ca670a426ad5a6c86dc2237b8e59e8822876976c383873642b linux-6.1.187.tar.xz
# From https://www.kernel.org/pub/linux/kernel/v5.x/sha256sums.asc
sha256 09affb2005aea3f44eec3f3eab4c1944e00707355ea7ca7fa2ba6b34a82605ed linux-5.15.216.tar.xz
sha256 d10cb9169e49da3d5f7154a01e450012486565fa9442e23d660b0581a3f92645 linux-5.10.265.tar.xz
sha256 b5b2992505120ac864cd9ccf7cc44541684df46c5a0b09ccdec93fb7f9aa6723 linux-5.15.220.tar.xz
sha256 9c5a168119406674ff3bcf366a3a235206eecfa7b79f04629b31a7cc678cc6e9 linux-5.10.269.tar.xz
# Locally computed
sha256 bd5db7fe3b0475cce4fc72db7a7f7df1c22b970aabe5ebff6ddd48098973bdf2 linux-cip-5.10.254-cip72.tar.gz
sha256 97d7d5139900c10ff7435779be4857dda531e7cf6abba52c12a5f39aae195411 linux-cip-5.10.254-cip72-rt32.tar.gz

View File

@@ -2,7 +2,7 @@
sha256 de9999b784d2293f00d39c62d8f92a08ab8a54bc4e80ffd250a0c09cb07a0f98 linux-7.0.14.tar.xz
# From https://www.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
sha256 30fa4a56579ca614ac125a12614f7f6466f87ab1278aef7b951dd74156deab33 linux-6.18.45.tar.xz
sha256 d2fc041dab4e11d9645e3ba53be058faa52b8ce28a8a97c889bb2cacee170461 linux-6.18.50.tar.xz
# Licenses hashes
sha256 fb5a425bd3b3cd6071a3a9aff9909a859e7c1158d54d32e07658398cd67eb6a0 COPYING

View File

@@ -419,6 +419,17 @@ define LINUX_KCONFIG_FIXUP_CMDS_ROOTFS_CPIO
endef
endif
# Since kernel >= 6.15.y, x86 and x86_64 kernels requires a toolchain
# with SSP support when CONFIG_STACKPROTECTOR is enabled.
# For toolchains without SSP support, make sure to disable
# CONFIG_STACKPROTECTOR to avoid link issues when building kernel
# modules.
ifeq ($(BR2_i386)$(BR2_x86_64):$(BR2_TOOLCHAIN_HAS_SSP),y:)
define LINUX_FIXUP_CONFIG_STACKPROTECTOR
$(call KCONFIG_DISABLE_OPT,CONFIG_STACKPROTECTOR)
endef
endif
define LINUX_KCONFIG_FIXUP_CMDS
@$(call MESSAGE,"Updating kernel config with fixups")
$(if $(LINUX_NEEDS_MODULES),
@@ -429,6 +440,7 @@ define LINUX_KCONFIG_FIXUP_CMDS
)
$(LINUX_FIXUP_CONFIG_ENDIANNESS)
$(LINUX_FIXUP_CONFIG_PAHOLE_CHECK)
$(LINUX_FIXUP_CONFIG_STACKPROTECTOR)
$(if $(BR2_arm)$(BR2_armeb),
$(call KCONFIG_ENABLE_OPT,CONFIG_AEABI))
$(if $(BR2_powerpc)$(BR2_powerpc64)$(BR2_powerpc64le),

View File

@@ -218,7 +218,7 @@ ifeq ($(BR2_riscv),y)
TARGET_CFLAGS += -fPIC
endif
ELF2FLT_FLAGS = $(if $($(PKG)_FLAT_STACKSIZE),\
-Wl$(comma)-elf2flt="-r -s$($(PKG)_FLAT_STACKSIZE)",\
-Wl$(comma)-elf2flt=-r -Wl$(comma)-elf2flt=-s$($(PKG)_FLAT_STACKSIZE),\
-Wl$(comma)-elf2flt=-r)
TARGET_CFLAGS += $(ELF2FLT_FLAGS)
TARGET_CXXFLAGS += $(ELF2FLT_FLAGS)

View File

@@ -1,3 +1,3 @@
# Locally computed
sha256 b64e31b94719499549622aa92f1d96d1742967ced261a0931b63be3bbe907f2c avro-c-1.12.1.tar.gz
# From https://downloads.apache.org/avro/avro-1.12.2/c/avro-c-1.12.2.tar.gz.sha512
sha512 bed6a7e324e7cac52d2bdfe0a596ab90c32c0f99ffecb517a72e465dad5fcfddc49dbfde0efa33e4c8ad73f2e97ad2c90d52f31a51f55b05576a9b36b2c3546b avro-c-1.12.2.tar.gz
sha256 d62488d6ba17132e92c23c03c80bfedc848267f96ab36489fec860f76cf6819a LICENSE

View File

@@ -5,8 +5,8 @@
################################################################################
# When updating the version, please also update python-avro
AVRO_C_VERSION = 1.12.1
AVRO_C_SITE = https://www-eu.apache.org/dist/avro/avro-$(AVRO_C_VERSION)/c
AVRO_C_VERSION = 1.12.2
AVRO_C_SITE = https://downloads.apache.org/avro/avro-$(AVRO_C_VERSION)/c
AVRO_C_LICENSE = Apache-2.0
AVRO_C_LICENSE_FILES = LICENSE
AVRO_C_INSTALL_STAGING = YES

View File

@@ -2,7 +2,7 @@ config BR2_PACKAGE_BIND
bool "bind"
depends on BR2_USE_MMU # fork(), libcap, libuv
depends on BR2_TOOLCHAIN_HAS_SYNC_4 # libuv
depends on BR2_TOOLCHAIN_HAS_THREADS # liburcu, libuv
depends on BR2_TOOLCHAIN_HAS_THREADS_NPTL # libuv
depends on BR2_INSTALL_LIBSTDCPP # liburcu
depends on !BR2_STATIC_LIBS # libuv
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 # libuv
@@ -48,9 +48,9 @@ config BR2_PACKAGE_BIND_TOOLS
endif
comment "bind needs a toolchain w/ threads, dynamic library, C++, gcc >= 4.9"
comment "bind needs a toolchain w/ NPTL, dynamic library, C++, gcc >= 4.9"
depends on BR2_USE_MMU
depends on BR2_TOOLCHAIN_HAS_SYNC_4
depends on !BR2_TOOLCHAIN_HAS_THREADS || BR2_STATIC_LIBS \
depends on !BR2_TOOLCHAIN_HAS_THREADS_NPTL || BR2_STATIC_LIBS \
|| BR2_INSTALL_LIBSTDCPP || !BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 \
|| BR2_PACKAGE_LIBURCU_ARCH_SUPPORTS

View File

@@ -14,7 +14,7 @@ config BR2_PACKAGE_BPFTRACE
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_7 # bcc -> clang
depends on BR2_INSTALL_LIBSTDCPP # bcc -> clang
depends on BR2_HOST_GCC_AT_LEAST_7 # bcc -> clang
depends on BR2_TOOLCHAIN_HEADERS_AT_LEAST_4_13 # libbpf
depends on BR2_TOOLCHAIN_HEADERS_AT_LEAST_5_10 # CAP_BPF, CAP_PERFMON
depends on BR2_USE_WCHAR # bcc -> clang, bcc -> python3, libbpf
depends on BR2_TOOLCHAIN_HAS_THREADS # bcc -> clang, bcc -> python3, libbpf
depends on !BR2_STATIC_LIBS # bcc -> clang, bcc -> python3, libbpf
@@ -47,10 +47,10 @@ config BR2_PACKAGE_BPFTRACE
https://www.github.com/iovisor/bpftrace
comment "bpftrace needs a glibc toolchain w/ C++, gcc >= 7, host gcc >= 7, kernel headers >= 4.13"
comment "bpftrace needs a glibc toolchain w/ C++, gcc >= 7, host gcc >= 7, kernel headers >= 5.10"
depends on BR2_PACKAGE_BPFTRACE_ARCH_SUPPORTS
depends on BR2_USE_MMU
depends on BR2_TOOLCHAIN_HAS_SYNC_4
depends on !BR2_TOOLCHAIN_USES_GLIBC || !BR2_INSTALL_LIBSTDCPP \
|| !BR2_TOOLCHAIN_GCC_AT_LEAST_7 || !BR2_HOST_GCC_AT_LEAST_7 \
|| !BR2_TOOLCHAIN_HEADERS_AT_LEAST_4_13
|| !BR2_TOOLCHAIN_HEADERS_AT_LEAST_5_10

View File

@@ -1,3 +1,3 @@
# locally calculated
sha256 e0514aa3e1a032b0b2de2cf3c281bfee9b9e80509498e70ed78786bbd64db373 bpftrace-0.24.2.tar.gz
sha256 555368f32f94bfcb74b119a3d9c67b68200be6375b8f452f794a2d3f6ebbcd16 bpftrace-0.26.1.tar.gz
sha256 cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30 LICENSE

View File

@@ -4,7 +4,7 @@
#
################################################################################
BPFTRACE_VERSION = 0.24.2
BPFTRACE_VERSION = 0.26.1
BPFTRACE_SITE = $(call github,bpftrace,bpftrace,v$(BPFTRACE_VERSION))
BPFTRACE_LICENSE = Apache-2.0
BPFTRACE_LICENSE_FILES = LICENSE
@@ -13,8 +13,6 @@ BPFTRACE_DEPENDENCIES = \
bzip2 \
cereal \
elfutils \
host-bison \
host-flex \
host-vim \
libbpf \
llvm \
@@ -29,6 +27,7 @@ BPFTRACE_CONF_OPTS += \
-DBUILD_SHARED_LIBS:BOOL=OFF \
-DBUILD_TESTING:BOOL=OFF \
-DCMAKE_CXX_FLAGS="$(TARGET_CXXFLAGS) -I$(STAGING_DIR)/usr/include/bpf" \
-DENABLE_MAN:BOOL=OFF
-DENABLE_MAN:BOOL=OFF \
-DUSE_SYSTEM_LIBBPF:BOOL=ON
$(eval $(cmake-package))

View File

@@ -14,6 +14,7 @@ config BR2_PACKAGE_CLAMAV
select BR2_PACKAGE_LIBXML2
select BR2_PACKAGE_MUSL_FTS if !BR2_TOOLCHAIN_USES_GLIBC
select BR2_PACKAGE_OPENSSL
select BR2_PACKAGE_LIBOPENSSL_ENABLE_DES if BR2_PACKAGE_LIBOPENSSL
select BR2_PACKAGE_PCRE2
select BR2_PACKAGE_ZLIB
select BR2_PACKAGE_ZLIB_FORCE_LIBZLIB

View File

@@ -0,0 +1,45 @@
From be6ac1ed28b4842e8f2e54c39a2b3fc48feaf8b2 Mon Sep 17 00:00:00 2001
From: "Matwey V. Kornilov" <matwey.kornilov@gmail.com>
Date: Sun, 26 Oct 2025 18:36:56 +0300
Subject: [PATCH] virt: Drop ATTRIBUTE_UNUSED for virt_eventloop_timeout_cb
ATTRIBUTE_UNUSED seems to be never was a public part of the libvirt interface
and leads to the following issue with recent libvirt versions were
ATTRIBUTE_UNUSED has been renamed to G_GNUC_UNUSED:
src/virt.c:2209:49: error: expected ';', ',' or ')' before 'ATTRIBUTE_UNUSED'
2209 | static void virt_eventloop_timeout_cb(int timer ATTRIBUTE_UNUSED,
| ^~~~~~~~~~~~~~~~
src/virt.c: In function 'register_event_impl':
src/virt.c:2222:26: error: 'virt_eventloop_timeout_cb' undeclared (first use in this function)
2222 | virt_eventloop_timeout_cb, NULL, NULL) < 0) {
| ^~~~~~~~~~~~~~~~~~~~~~~~~
src/virt.c:2222:26: note: each undeclared identifier is reported only once for each function it appears in
Drop ATTRIBUTE_UNUSED here as there is little use from it.
Upstream: https://github.com/collectd/collectd/commit/050877ed952ffc15c849803a9b3e77c5cec15f81
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
src/virt.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/src/virt.c b/src/virt.c
index 01c7c777..ee0440e9 100644
--- a/src/virt.c
+++ b/src/virt.c
@@ -2205,8 +2205,9 @@ static int domain_lifecycle_event_cb(__attribute__((unused)) virConnectPtr con_,
return 0;
}
-static void virt_eventloop_timeout_cb(int timer ATTRIBUTE_UNUSED,
- void *timer_info) {}
+static void
+virt_eventloop_timeout_cb(__attribute__((unused)) int timer,
+ __attribute__((unused)) void *timer_info) {}
static int register_event_impl(void) {
if (virEventRegisterDefaultImpl() < 0) {
--
2.55.0

View File

@@ -0,0 +1,38 @@
From 96a67c8e51997a18bfc0942416b815057e279caf Mon Sep 17 00:00:00 2001
From: InterLinked1 <24227567+InterLinked1@users.noreply.github.com>
Date: Tue, 8 Jul 2025 18:35:56 -0400
Subject: [PATCH] kernel.h: Add wrappers for del_timer and del_timer_sync.
del_timer[_sync] was renamed to timer_delete[_sync] in kernel
commit bb663f0f3c396c6d05f6c5eeeea96ced20ff112e, and the
compatibility wrappers were removed completely in kernel commit
8fa7292fee5c5240402371ea89ab285ec856c916. Add the wrappers
back on newer kernels to allow compilation.
Resolves: #91
Upstream: https://github.com/asterisk/dahdi-linux/commit/67d909a8a73364d6fa47bbf8baf314175c94f546
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
include/dahdi/kernel.h | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/include/dahdi/kernel.h b/include/dahdi/kernel.h
index ab129a8..ddd3eb4 100644
--- a/include/dahdi/kernel.h
+++ b/include/dahdi/kernel.h
@@ -62,6 +62,11 @@
#define netif_napi_add netif_napi_add_weight
#endif
+#if LINUX_VERSION_CODE >= KERNEL_VERSION(6,15,0)
+#define del_timer timer_delete
+#define del_timer_sync timer_delete_sync
+#endif
+
#if LINUX_VERSION_CODE >= KERNEL_VERSION(5, 18, 0)
#include <linux/pci.h>
#include <linux/dma-mapping.h>
--
2.55.0

View File

@@ -0,0 +1,186 @@
From fc3748466d96fa465fe665403b73d6f4f75c124b Mon Sep 17 00:00:00 2001
From: InterLinked1 <24227567+InterLinked1@users.noreply.github.com>
Date: Fri, 21 Feb 2025 21:42:19 -0500
Subject: [PATCH] Kbuild: Use ccflags-y instead of EXTRA_CFLAGS.
ccflags-y was added to the kernel back in 2007, in commit
f77bf01425b11947eeb3b5b54. Recent kernel commit
dbd83ea09699390892e5efecddd74ae43a00f071 has now completely
removed the deprecated EXTRA_CFLAGS.
Comments in Kbuild and the Makefile for the oct612x library were
added back when it was created in 2013 in commit f65299e8b2e6ffb0b07089759f8c4ff33a695c09
to use the newer ccflags-y based on the kernel version,
but the change was never made to conditionally move away
from the EXTRA_CFLAGS.
Now that the older way no longer exists, always use ccflags-y.
Resolves: #76
Upstream: https://github.com/asterisk/dahdi-linux/commit/9d5b120cb5573d39bcd9e3d8a7b212e25ab5c2c4
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
drivers/dahdi/Kbuild | 4 ++--
drivers/dahdi/oct612x/Kbuild | 5 +----
drivers/dahdi/oct612x/Makefile | 5 +----
drivers/dahdi/voicebus/Kbuild | 4 ++--
drivers/dahdi/wcb4xxp/Kbuild | 2 +-
drivers/dahdi/wct4xxp/Kbuild | 6 +++---
drivers/dahdi/wctc4xxp/Kbuild | 4 ++--
drivers/dahdi/wctdm24xxp/Kbuild | 2 +-
drivers/dahdi/xpp/Kbuild | 4 ++--
9 files changed, 15 insertions(+), 21 deletions(-)
diff --git a/drivers/dahdi/Kbuild b/drivers/dahdi/Kbuild
index cd0365b..9c9355a 100644
--- a/drivers/dahdi/Kbuild
+++ b/drivers/dahdi/Kbuild
@@ -75,13 +75,13 @@ CFLAGS_MODULE += -I$(DAHDI_INCLUDE) -I$(src) -Wno-format-truncation
BAD_KERNELS_VERS := 22 34 34.0.1 34.0.2
BAD_KERNELS := $(foreach ver,$(BAD_KERNELS_VERS),2.6.9-$(ver).EL 2.6.9-$(ver).ELsmp)
ifneq (,$(filter $(KVERS),$(BAD_KERNELS)))
-EXTRA_CFLAGS+=-Drw_lock_t=rwlock_t
+ccflags-y+=-Drw_lock_t=rwlock_t
endif
# A number of Fedora 10 (9 also?) kernels backported hrtimer to 2.6.27
# as part of an ALSA backport. TODO: Any better way to detect that?
ifeq (1,$(shell fgrep -q ' hrtimer_set_expires' include/linux/hrtimer.h 2>/dev/null && echo 1))
-EXTRA_CFLAGS+=-DHAVE_HRTIMER_ACCESSORS=1
+ccflags-y+=-DHAVE_HRTIMER_ACCESSORS=1
endif
ifeq (1,$(shell fgrep -q 'wait_for_completion_timeout' include/linux/completion.h 2>/dev/null && echo 1))
diff --git a/drivers/dahdi/oct612x/Kbuild b/drivers/dahdi/oct612x/Kbuild
index ac53fe7..5015f7e 100644
--- a/drivers/dahdi/oct612x/Kbuild
+++ b/drivers/dahdi/oct612x/Kbuild
@@ -24,9 +24,6 @@ octapi_files = octdeviceapi/oct6100api/oct6100_api/oct6100_adpcm_chan.o \
apilib/llman/octapi_llman.o \
oct612x-user.o
-# TODO: ccflags was added in 2.6.24 in commit f77bf01425b11947eeb3b5b54. This
-# should be changed to a conditional compilation based on the Kernel Version.
-# ccflags-y := -I$(src)/.. -Wno-undef -I$(src)/include -I$(src)/octdeviceapi -I$(src)/octdeviceapi/oct6100api
-EXTRA_CFLAGS = -I$(src)/.. -Wno-undef -I$(src)/include -I$(src)/octdeviceapi -I$(src)/octdeviceapi/oct6100api
+ccflags-y := -I$(src)/.. -Wno-undef -I$(src)/include -I$(src)/octdeviceapi -I$(src)/octdeviceapi/oct6100api
obj-$(DAHDI_BUILD_ALL)$(CONFIG_DAHDI_OCT612X) := oct612x.o
oct612x-objs := $(octapi_files)
diff --git a/drivers/dahdi/oct612x/Makefile b/drivers/dahdi/oct612x/Makefile
index 5d29143..d01997b 100644
--- a/drivers/dahdi/oct612x/Makefile
+++ b/drivers/dahdi/oct612x/Makefile
@@ -23,8 +23,5 @@ octapi_files = octdeviceapi/oct6100api/oct6100_api/oct6100_adpcm_chan.o \
apilib/largmath/octapi_largmath.o \
apilib/llman/octapi_llman.o
-# TODO: ccflags was added in 2.6.24 in commit f77bf01425b11947eeb3b5b54. This
-# should be changed to a conditional compilation based on the Kernel Version.
-# ccflags-y := -I$(src)/.. -Wno-undef -I$(src)/include -I$(src)/octdeviceapi -I$(src)/octdeviceapi/oct6100api
-EXTRA_CFLAGS = -I$(src)/.. -Wno-undef -I$(src)/include -I$(src)/octdeviceapi -I$(src)/octdeviceapi/oct6100api
+ccflags-y := -I$(src)/.. -Wno-undef -I$(src)/include -I$(src)/octdeviceapi -I$(src)/octdeviceapi/oct6100api
lib-y := $(octapi_files)
diff --git a/drivers/dahdi/voicebus/Kbuild b/drivers/dahdi/voicebus/Kbuild
index 3bf9640..45026d9 100644
--- a/drivers/dahdi/voicebus/Kbuild
+++ b/drivers/dahdi/voicebus/Kbuild
@@ -8,10 +8,10 @@ ifneq ($(HOTPLUG_FIRMWARE),yes)
dahdi_voicebus-objs += $(FIRM_DIR)/dahdi-fw-vpmoct032.o
$(warning WARNING: You are compiling firmware into voicebus.ko which is not available under the terms of the GPL. It may be a violation of the GPL to distribute the resulting image since it combines both GPL and non-GPL work. You should consult a lawyer of your own before distributing such an image.)
else
- EXTRA_CFLAGS+=-DHOTPLUG_FIRMWARE
+ ccflags-y+=-DHOTPLUG_FIRMWARE
endif
-EXTRA_CFLAGS += -I$(src)/.. -Wno-undef
+ccflags-y += -I$(src)/.. -Wno-undef
$(obj)/$(FIRM_DIR)/dahdi-fw-vpmoct032.o: $(obj)/voicebus.o
$(MAKE) -C $(obj)/$(FIRM_DIR) dahdi-fw-vpmoct032.o
diff --git a/drivers/dahdi/wcb4xxp/Kbuild b/drivers/dahdi/wcb4xxp/Kbuild
index 80606bf..59ffc8d 100644
--- a/drivers/dahdi/wcb4xxp/Kbuild
+++ b/drivers/dahdi/wcb4xxp/Kbuild
@@ -1,6 +1,6 @@
obj-m += wcb4xxp.o
-EXTRA_CFLAGS += -I$(src)/.. -Wno-undef
+ccflags-y += -I$(src)/.. -Wno-undef
wcb4xxp-objs := base.o
diff --git a/drivers/dahdi/wct4xxp/Kbuild b/drivers/dahdi/wct4xxp/Kbuild
index cf01ccf..eeeb2f6 100644
--- a/drivers/dahdi/wct4xxp/Kbuild
+++ b/drivers/dahdi/wct4xxp/Kbuild
@@ -2,16 +2,16 @@ obj-$(DAHDI_BUILD_ALL)$(CONFIG_DAHDI_WCT4XXP) += wct4xxp.o
FIRM_DIR := ../firmware
-EXTRA_CFLAGS += -I$(src)/.. -I$(src)/../oct612x/ $(shell $(src)/../oct612x/octasic-helper cflags $(src)/../oct612x) -Wno-undef
+ccflags-y += -I$(src)/.. -I$(src)/../oct612x/ $(shell $(src)/../oct612x/octasic-helper cflags $(src)/../oct612x) -Wno-undef
# The OCT612X source files are from a vendor drop and we do not want to edit
# them to make this warning go away. Therefore, turn off the
# unused-but-set-variable warning for this driver.
-EXTRA_CFLAGS += $(call cc-option, -Wno-unused-but-set-variable)
+ccflags-y += $(call cc-option, -Wno-unused-but-set-variable)
ifeq ($(HOTPLUG_FIRMWARE),yes)
- EXTRA_CFLAGS+=-DHOTPLUG_FIRMWARE
+ ccflags-y+=-DHOTPLUG_FIRMWARE
endif
wct4xxp-objs := base.o vpm450m.o
diff --git a/drivers/dahdi/wctc4xxp/Kbuild b/drivers/dahdi/wctc4xxp/Kbuild
index 9f97498..2f1bfbf 100644
--- a/drivers/dahdi/wctc4xxp/Kbuild
+++ b/drivers/dahdi/wctc4xxp/Kbuild
@@ -2,10 +2,10 @@ obj-$(DAHDI_BUILD_ALL)$(CONFIG_DAHDI_WCTC4XXP) += wctc4xxp.o
FIRM_DIR := ../firmware
-EXTRA_CFLAGS += -I$(src)/.. -Wno-undef
+ccflags-y += -I$(src)/.. -Wno-undef
ifeq ($(HOTPLUG_FIRMWARE),yes)
- EXTRA_CFLAGS+=-DHOTPLUG_FIRMWARE
+ ccflags-y+=-DHOTPLUG_FIRMWARE
endif
wctc4xxp-objs := base.o
diff --git a/drivers/dahdi/wctdm24xxp/Kbuild b/drivers/dahdi/wctdm24xxp/Kbuild
index 22cc71a..c9d96b7 100644
--- a/drivers/dahdi/wctdm24xxp/Kbuild
+++ b/drivers/dahdi/wctdm24xxp/Kbuild
@@ -1,5 +1,5 @@
obj-$(DAHDI_BUILD_ALL)$(CONFIG_DAHDI_WCTDM24XXP) += wctdm24xxp.o
-EXTRA_CFLAGS += -I$(src)/.. -Wno-undef
+ccflags-y += -I$(src)/.. -Wno-undef
wctdm24xxp-objs := base.o xhfc.o
diff --git a/drivers/dahdi/xpp/Kbuild b/drivers/dahdi/xpp/Kbuild
index e46a9d7..02d3149 100644
--- a/drivers/dahdi/xpp/Kbuild
+++ b/drivers/dahdi/xpp/Kbuild
@@ -1,4 +1,4 @@
-EXTRA_CFLAGS = $(XPP_LOCAL_CFLAGS) \
+ccflags-y = $(XPP_LOCAL_CFLAGS) \
-DDEBUG \
-DPOLL_DIGITAL_INPUTS \
-DDEBUG_PCMTX \
@@ -32,7 +32,7 @@ xpd_echo-objs += card_echo.o
xpp_mmap-objs += mmapbus.o mmapdrv.o
ifeq (y,$(PARPORT_DEBUG))
-EXTRA_CFLAGS += -DDEBUG_SYNC_PARPORT
+ccflags-y += -DDEBUG_SYNC_PARPORT
obj-m += parport_debug.o
endif
--
2.55.0

View File

@@ -0,0 +1,35 @@
From 13e360f1bc65dba29ba22c46f30ba868bea9805d Mon Sep 17 00:00:00 2001
From: InterLinked1 <24227567+InterLinked1@users.noreply.github.com>
Date: Sat, 12 Jul 2025 17:52:40 -0400
Subject: [PATCH] kernel.h: Add wrapper for renamed from_timer function.
from_timer was renamed to timer_container_of in kernel commit
41cb08555c4164996d67c78b3bf1c658075b75f1 as part of updates to
the timer APIs. Add a compatibility wrapper for kernels >= 6.16.0.
Resolves: #95
Upstream: https://github.com/asterisk/dahdi-linux/commit/0d864e9f97ba22e340380ce24a1bd366ca33ebc2
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
include/dahdi/kernel.h | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/include/dahdi/kernel.h b/include/dahdi/kernel.h
index ddd3eb4..01fe113 100644
--- a/include/dahdi/kernel.h
+++ b/include/dahdi/kernel.h
@@ -58,6 +58,10 @@
#include <linux/poll.h>
+#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 16, 0)
+#define from_timer timer_container_of
+#endif
+
#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 1, 0)
#define netif_napi_add netif_napi_add_weight
#endif
--
2.55.0

View File

@@ -7,6 +7,7 @@
DEJAVU_VERSION = 2.37
DEJAVU_SITE = https://sourceforge.net/projects/dejavu/files/dejavu/$(DEJAVU_VERSION)
DEJAVU_SOURCE = dejavu-fonts-ttf-$(DEJAVU_VERSION).tar.bz2
DEJAVU_LICENSE = Bitstream-Vera
DEJAVU_LICENSE_FILES = LICENSE
DEJAVU_FONTS_INSTALL =

View File

@@ -1,5 +1,6 @@
config BR2_PACKAGE_DISTRIBUTION_REGISTRY
bool "distribution-registry"
depends on BR2_TOOLCHAIN_HAS_THREADS_NPTL # pthread_*_np()
depends on BR2_PACKAGE_HOST_GO_TARGET_ARCH_SUPPORTS
depends on BR2_PACKAGE_HOST_GO_TARGET_CGO_LINKING_SUPPORTS
help

View File

@@ -1,6 +1,6 @@
# Locally calculated after checking pgp signature
# https://thekelleys.org.uk/dnsmasq/dnsmasq-2.92rel2.tar.xz.asc
sha256 43d72b8c129bdf33d17bafedc98823f63e46b5005128066bf0d2a472a32ce06a dnsmasq-2.92rel2.tar.xz
# https://thekelleys.org.uk/dnsmasq/dnsmasq-2.93.tar.xz.asc
sha256 0c00d4e5c97c8306e5fb932b348b34269c9c29a0e7df0e8e82958b407092bc19 dnsmasq-2.93.tar.xz
# Locally calculated
sha256 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643 COPYING
sha256 8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903 COPYING-v3

View File

@@ -4,7 +4,7 @@
#
################################################################################
DNSMASQ_VERSION = 2.92rel2
DNSMASQ_VERSION = 2.93
DNSMASQ_SOURCE = dnsmasq-$(DNSMASQ_VERSION).tar.xz
DNSMASQ_SITE = https://thekelleys.org.uk/dnsmasq
DNSMASQ_MAKE_ENV = $(TARGET_MAKE_ENV) CC="$(TARGET_CC)"

View File

@@ -0,0 +1,46 @@
From 9f6c3191b3178294d698cdca859ce9dac78517ff Mon Sep 17 00:00:00 2001
From: Guillaume Gardet <Guillaume.Gardet@arm.com>
Date: Thu, 29 Aug 2024 16:33:19 +0200
Subject: [PATCH] examples/vm_power_manager: add missing <stdlib.h> header
include for strtol
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
strtol is defined in stdlib.h
Fixes the following build failure:
../examples/vm_power_manager/guest_cli/vm_power_cli_guest.c: In function ‘cmd_query_freq_list_parsed’:
../examples/vm_power_manager/guest_cli/vm_power_cli_guest.c:208:42: error: implicit declaration of function ‘strtol’; did you mean ‘strtok’? [-Wimplicit-function-declaration]
208 | lcore_id = (unsigned int)strtol(res->cpu_num, &ep, 10);
| ^~~~~~
| strtok
Fixes: 0e8f47491f090f44a4956429cb27f6942b6618b0 ("examples/vm_power: add command to query CPU frequency")
Signed-off-by: Guillaume Gardet <guillaume.gardet@arm.com>
[Thomas:
- retrieve patch from
https://build.opensuse.org/projects/openSUSE:42:Factory-Candidates-Check/packages/dpdk/files/0001-examples-vm_power_manager-add-missing-header.patch?expand=1
- improve commit message]
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Upstream: https://mails.dpdk.org/archives/dev/2026-August/344552.html
---
examples/vm_power_manager/guest_cli/vm_power_cli_guest.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/examples/vm_power_manager/guest_cli/vm_power_cli_guest.c b/examples/vm_power_manager/guest_cli/vm_power_cli_guest.c
index 4114593cee..63a59c8b10 100644
--- a/examples/vm_power_manager/guest_cli/vm_power_cli_guest.c
+++ b/examples/vm_power_manager/guest_cli/vm_power_cli_guest.c
@@ -6,6 +6,7 @@
#include <stdint.h>
#include <string.h>
#include <stdio.h>
+#include <stdlib.h>
#include <termios.h>
#include <cmdline_rdline.h>
--
2.55.0

View File

@@ -112,6 +112,10 @@ ifeq ($(BR2_PACKAGE_LIBBPF),y)
DPDK_DEPENDENCIES += libbpf
endif
ifeq ($(BR2_PACKAGE_LIBVIRT),y)
DPDK_DEPENDENCIES += libvirt
endif
ifeq ($(BR2_PACKAGE_RDMA_CORE),y)
DPDK_DEPENDENCIES += rdma-core
endif

View File

@@ -11,8 +11,18 @@ DRACUT_LICENSE_FILES = COPYING
DRACUT_CPE_ID_VALID = YES
HOST_DRACUT_DEPENDENCIES = host-pkgconf host-kmod host-cross-ldd
# Dracut is not a real autotools package, and the hand-written
# ./configure script does not preserve LDFLAGS for make.
HOST_DRACUT_MAKE_ENV = $(HOST_CONFIGURE_OPTS)
HOST_DRACUT_INSTALL_OPTS = systemdsystemunitdir="" install
ifeq ($(BR2_PACKAGE_HOST_RUSTC),y)
HOST_DRACUT_CONF_OPTS += --enable-dracut-cpio
HOST_DRACUT_DEPENDENCIES += host-rustc
else
HOST_DRACUT_CONF_OPTS += --disable-dracut-cpio
endif
define HOST_DRACUT_POST_INSTALL_WRAPPER_SCRIPT
mv $(HOST_DIR)/bin/dracut $(HOST_DIR)/bin/dracut.real
sed -e "s%@@TARGET_CROSS@@%$(TARGET_CROSS)%" \

View File

@@ -0,0 +1,29 @@
From c0c7e9ad51b2e9aebea46f0179446fcf896f8d63 Mon Sep 17 00:00:00 2001
From: Wim Stockman <wimstockman@gmail.com>
Date: Fri, 20 Feb 2026 10:51:37 +0100
Subject: [PATCH] Add CFLAG=-std=c89 so it compiles with the old standard,
modern standard gives problems
Upstream: https://git.savannah.gnu.org/cgit/enscript.git/commit/?id=111ad375a6e598c896441e10f4cf1e2fc1496c42
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
configure.ac | 3 +++
1 file changed, 3 insertions(+)
diff --git a/configure.ac b/configure.ac
index 465100a..b867912 100644
--- a/configure.ac
+++ b/configure.ac
@@ -10,6 +10,9 @@ AC_PROG_INSTALL
AC_PROG_CC
+# Force C89 standard and fix modern GCC global variable handling
+CFLAGS="$CFLAGS -std=c89"
+
AC_USE_SYSTEM_EXTENSIONS
AM_C_PROTOTYPES
--
2.55.0

View File

@@ -1,19 +0,0 @@
Fix build with gcc 15.x
Upstream: https://savannah.gnu.org/bugs/?66845
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
diff --git a/compat/regex.c b/compat/regex.c
index c6907f3..87f2840 100644
--- a/compat/regex.c
+++ b/compat/regex.c
@@ -336,7 +336,7 @@ typedef char boolean;
#define false 0
#define true 1
-static int re_match_2_internal ();
+static int re_match_2_internal (struct re_pattern_buffer*, const char*, int, const char*, int, int, struct re_registers*, int);
/* These are the command codes that appear in compiled regular
expressions. Some opcodes are followed by argument bytes. A

View File

@@ -0,0 +1,28 @@
From d74ef70aec3fe9e5e27468f31532eb41188707cf Mon Sep 17 00:00:00 2001
From: Werner Fink <werner@suse.de>
Date: Tue, 23 Jan 2018 15:26:45 +0100
Subject: [PATCH] Automake 1.12 and up no longer supports pre-ANSI
Signed-off-by: Werner Fink <werner@suse.de>
Signed-off-by: James Cloos <cloos@jhcloos.com>
Upstream: https://git.savannah.gnu.org/cgit/enscript.git/commit/?id=a356d343aa9db52b75432cde927b6f9bad6a7c44
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
configure.ac | 1 -
1 file changed, 1 deletion(-)
diff --git a/configure.ac b/configure.ac
index b867912..4431cb1 100644
--- a/configure.ac
+++ b/configure.ac
@@ -14,7 +14,6 @@ AC_PROG_CC
CFLAGS="$CFLAGS -std=c89"
AC_USE_SYSTEM_EXTENSIONS
-AM_C_PROTOTYPES
AC_C_CONST
AC_FUNC_ALLOCA
--
2.55.0

View File

@@ -0,0 +1,107 @@
From 83238ba35f966bb35a065e6d141f3ccf714f4324 Mon Sep 17 00:00:00 2001
From: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Date: Sat, 22 Aug 2026 14:50:56 +0200
Subject: [PATCH] Fix prototype detection when __STDC__ is defined but
PROTOTYPES is not
Commit a356d343aa9db52b75432cde927b6f9bad6a7c44 ("Automake 1.12 and up
no longer supports pre-ANSI") dropped the AM_C_PROTOTYPES call from
configure.ac, so PROTOTYPES is no longer defined by configure. The
headers' fallback to K&R-style prototypes breaks compilation with
modern compilers.
Check for __STDC__ directly as a fallback, which is defined by all
conforming C89/C99 compilers.
Upstream: https://savannah.gnu.org/bugs/index.php?68633
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
afmlib/afm.h | 2 +-
afmlib/afmint.h | 2 +-
afmlib/strhash.h | 2 +-
compat/xalloc.h | 2 +-
src/gsint.h | 2 +-
states/defs.h | 2 +-
6 files changed, 6 insertions(+), 6 deletions(-)
diff --git a/afmlib/afm.h b/afmlib/afm.h
index 19855ce..a79648d 100644
--- a/afmlib/afm.h
+++ b/afmlib/afm.h
@@ -24,7 +24,7 @@
#define AFM_H
#ifndef ___P
-#if PROTOTYPES
+#if defined(__STDC__) || defined(PROTOTYPES)
#define ___P(protos) protos
#else /* no PROTOTYPES */
#define ___P(protos) ()
diff --git a/afmlib/afmint.h b/afmlib/afmint.h
index 7995ae5..aee449a 100644
--- a/afmlib/afmint.h
+++ b/afmlib/afmint.h
@@ -34,7 +34,7 @@
#include <stdio.h>
#ifndef ___P
-#if PROTOTYPES
+#if defined(__STDC__) || defined(PROTOTYPES)
#define ___P(protos) protos
#else /* no PROTOTYPES */
#define ___P(protos) ()
diff --git a/afmlib/strhash.h b/afmlib/strhash.h
index 938b2de..a91c0a9 100644
--- a/afmlib/strhash.h
+++ b/afmlib/strhash.h
@@ -24,7 +24,7 @@
#define STRHASH_H
#ifndef ___P
-#if PROTOTYPES
+#if defined(__STDC__) || defined(PROTOTYPES)
#define ___P(protos) protos
#else /* no PROTOTYPES */
#define ___P(protos) ()
diff --git a/compat/xalloc.h b/compat/xalloc.h
index 203bcb8..fd50b68 100644
--- a/compat/xalloc.h
+++ b/compat/xalloc.h
@@ -28,7 +28,7 @@
#define XALLOC_H
#ifndef ___P
-#if PROTOTYPES
+#if defined(__STDC__) || defined(PROTOTYPES)
#define ___P(protos) protos
#else /* no PROTOTYPES */
#define ___P(protos) ()
diff --git a/src/gsint.h b/src/gsint.h
index 3c2527a..001961c 100644
--- a/src/gsint.h
+++ b/src/gsint.h
@@ -39,7 +39,7 @@
#include <sys/stat.h>
#ifndef ___P
-#if PROTOTYPES
+#if defined(__STDC__) || defined(PROTOTYPES)
#define ___P(protos) protos
#else /* no PROTOTYPES */
#define ___P(protos) ()
diff --git a/states/defs.h b/states/defs.h
index 2808900..63155a9 100644
--- a/states/defs.h
+++ b/states/defs.h
@@ -37,7 +37,7 @@
#include <ctype.h>
#ifndef ___P
-#if PROTOTYPES
+#if defined(__STDC__) || defined(PROTOTYPES)
#define ___P(protos) protos
#else /* no PROTOTYPES */
#define ___P(protos) ()
--
2.55.0

View File

@@ -0,0 +1,35 @@
From be920933dbe1fb73c27fecb280200f6f06abfdc2 Mon Sep 17 00:00:00 2001
From: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Date: Sat, 22 Aug 2026 15:19:17 +0200
Subject: [PATCH] Use -std=gnu89 instead of -std=c89
-std=c89 suppresses feature test macros, which causes <limits.h> to
not define PATH_MAX on certain C libraries (e.g. musl). Using
-std=gnu89 enables _GNU_SOURCE and other extensions, ensuring
PATH_MAX and other POSIX constants are available.
This most notably fixes the build with the musl C library.
Upstream: https://savannah.gnu.org/bugs/index.php?68634
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
configure.ac | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/configure.ac b/configure.ac
index 4431cb1..46ea59d 100644
--- a/configure.ac
+++ b/configure.ac
@@ -11,7 +11,8 @@ AC_PROG_INSTALL
AC_PROG_CC
# Force C89 standard and fix modern GCC global variable handling
-CFLAGS="$CFLAGS -std=c89"
+# Use GNU89 to access PATH_MAX in <limits.h>
+CFLAGS="$CFLAGS -std=gnu89"
AC_USE_SYSTEM_EXTENSIONS
--
2.55.0

View File

@@ -9,6 +9,10 @@ ENSCRIPT_SITE = $(BR2_GNU_MIRROR)/enscript
ENSCRIPT_LICENSE = GPL-3.0+
ENSCRIPT_LICENSE_FILES = COPYING
ENSCRIPT_CPE_ID_VENDOR = gnu
# 0002-Add-CFLAG-std-c89-so-it-compiles-with-the-old-standa.patch
# 0003-Automake-1.12-and-up-no-longer-supports-pre-ANSI.patch
# 0005-Use-std-gnu89-instead-of-std-c89.patch
ENSCRIPT_AUTORECONF = YES
# Enable pthread threads if toolchain supports threads
ifeq ($(BR2_TOOLCHAIN_HAS_THREADS),y)

View File

@@ -0,0 +1,32 @@
From de58cbe979942308eb8823a526cd68b06d5dc662 Mon Sep 17 00:00:00 2001
From: Sacha <sachahony@gmail.com>
Date: Wed, 13 Mar 2024 13:28:41 +0100
Subject: [PATCH] Change libs order to avoid picking up system libei
Upstream: https://github.com/erlang/otp/commit/de58cbe
Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
---
lib/odbc/c_src/Makefile.in | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/lib/odbc/c_src/Makefile.in b/lib/odbc/c_src/Makefile.in
index d1b26743a6a4..03ed314f6a26 100644
--- a/lib/odbc/c_src/Makefile.in
+++ b/lib/odbc/c_src/Makefile.in
@@ -80,10 +80,10 @@ ODBC_INCLUDE = @ODBC_INCLUDE@
# ----------------------------------------------------
CC = @CC@
CFLAGS = $(TYPEFLAGS) @CFLAGS@ @THR_DEFS@ @DEFS@
-EI_LDFLAGS = -L$(EI_ROOT)/obj$(TYPEMARKER)/$(TARGET)
+EI_LDFLAGS = -L$(EI_ROOT)/obj$(TYPEMARKER)/$(TARGET) $(EI_LIB)
LD = @LD@
-LDFLAGS = $(ODBC_LIB) $(EI_LDFLAGS)
-LIBS = @LIBS@ @THR_LIBS@ $(EI_LIB)
+LDFLAGS = $(EI_LDFLAGS) $(ODBC_LIB)
+LIBS = @LIBS@ @THR_LIBS@
INCLUDES = -I. $(ODBC_INCLUDE) $(EI_INCLUDE)
TARGET_FLAGS = @TARGET_FLAGS@
--
2.55.0

View File

@@ -1,5 +1,5 @@
# From https://github.com/erlang/otp/releases/download/OTP-26.2.5.15/SHA256.txt
sha256 28e6d63d82927f132d56289dd3c428ef8bce6bf2283c8549aa0a7afca1a8fe3b otp_src_26.2.5.15.tar.gz
# From https://github.com/erlang/otp/releases/download/OTP-26.2.5.21/SHA256.txt
sha256 e1fde86f4e2874d4c136221a34753b5b785d762b910fb3fb35a23a6a7faf0a64 otp_src_26.2.5.21.tar.gz
# Hash for license file
sha256 809fa1ed21450f59827d1e9aec720bbc4b687434fa22283c6cb5dd82a47ab9c0 LICENSE.txt

View File

@@ -4,7 +4,7 @@
#
################################################################################
ERLANG_VERSION = 26.2.5.15
ERLANG_VERSION = 26.2.5.21
ERLANG_RELEASE = $(firstword $(subst ., ,$(ERLANG_VERSION)))
ERLANG_SITE = \
https://github.com/erlang/otp/releases/download/OTP-$(ERLANG_VERSION)

View File

@@ -1,3 +1,3 @@
# Locally calculated
sha256 ea51b0609f58a9afa063b60daa1539948b62247721e154f4fff0ad3aec9f9756 exiv2-0.28.8.tar.gz
sha256 700b76b97695b2fab4ef8c79619c68ae57d09e0c130724791cafbd39e0eb4aef exiv2-0.28.9.tar.gz
sha256 a7ba75cb966aca374711e2af49e5f3aea6a4443a803440f5d93e73a5a1222f66 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
EXIV2_VERSION = 0.28.8
EXIV2_VERSION = 0.28.9
EXIV2_SITE = $(call github,Exiv2,exiv2,v$(EXIV2_VERSION))
EXIV2_INSTALL_STAGING = YES
EXIV2_LICENSE = GPL-2.0+

View File

@@ -1,4 +1,4 @@
# From https://github.com/libexpat/libexpat/releases/tag/R_2_8_3
sha256 f6256df90c906773d344da084402b7d3e4f22ed41b1a59c989098a83d3ea0c85 expat-2.8.3.tar.xz
# From https://github.com/libexpat/libexpat/releases/tag/R_2_8_4
sha256 656ae1cc8da3b4ea513bb4e254f33e6243938084c0ec6239da873376b09985a7 expat-2.8.4.tar.xz
# Locally calculated
sha256 31b15de82aa19a845156169a17a5488bf597e561b2c318d159ed583139b25e87 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
EXPAT_VERSION = 2.8.3
EXPAT_VERSION = 2.8.4
EXPAT_SITE = https://github.com/libexpat/libexpat/releases/download/R_$(subst .,_,$(EXPAT_VERSION))
EXPAT_SOURCE = expat-$(EXPAT_VERSION).tar.xz
EXPAT_INSTALL_STAGING = YES
@@ -14,8 +14,16 @@ EXPAT_CPE_ID_VENDOR = libexpat_project
EXPAT_CPE_ID_PRODUCT = libexpat
EXPAT_CONF_OPTS = \
--without-docbook --without-examples --without-tests --without-xmlwf
HOST_EXPAT_CONF_OPTS = --without-docbook --without-examples --without-tests
--with-dev-urandom \
--without-docbook \
--without-examples \
--without-tests \
--without-xmlwf
HOST_EXPAT_CONF_OPTS = \
--without-docbook \
--without-examples \
--without-tests
$(eval $(autotools-package))
$(eval $(host-autotools-package))

View File

@@ -39,6 +39,16 @@ config BR2_PACKAGE_HOST_GDB_SIM
help
This option enables the simulator support in the cross gdb.
config BR2_PACKAGE_HOST_GDB_LZMA
bool "lzma support"
help
This option enables lzma support in the cross gdb.
config BR2_PACKAGE_HOST_GDB_XXHASH
bool "xxhash support"
help
This option enables xxhash support in the cross gdb.
choice
prompt "GDB debugger Version"
default BR2_GDB_VERSION_15

View File

@@ -217,6 +217,14 @@ else
GDB_CONF_OPTS += --without-expat
endif
ifeq ($(BR2_PACKAGE_XXHASH),y)
GDB_CONF_OPTS += --with-xxhash
GDB_CONF_OPTS += --with-xxhash-prefix=$(STAGING_DIR)/usr
GDB_DEPENDENCIES += xxhash
else
GDB_CONF_OPTS += --without-xxhash
endif
ifeq ($(BR2_PACKAGE_XZ),y)
GDB_CONF_OPTS += --with-lzma
GDB_CONF_OPTS += --with-liblzma-prefix=$(STAGING_DIR)/usr
@@ -293,6 +301,22 @@ else
HOST_GDB_CONF_OPTS += --disable-sim
endif
ifeq ($(BR2_PACKAGE_HOST_GDB_LZMA),y)
HOST_GDB_CONF_OPTS += --with-lzma
HOST_GDB_CONF_OPTS += --with-liblzma-prefix=$(HOST_DIR)
HOST_GDB_DEPENDENCIES += host-xz
else
HOST_GDB_CONF_OPTS += --without-lzma
endif
ifeq ($(BR2_PACKAGE_HOST_GDB_XXHASH),y)
HOST_GDB_CONF_OPTS += --with-xxhash
HOST_GDB_CONF_OPTS += --with-xxhash-prefix=$(HOST_DIR)
HOST_GDB_DEPENDENCIES += host-xxhash
else
HOST_GDB_CONF_OPTS += --without-xxhash
endif
# Since gdb 9, in-tree builds for GDB are not allowed anymore,
# so we create a 'build' subdirectory in the gdb sources, and
# build from there.

View File

@@ -1,5 +1,5 @@
# Locally calculated (fetched from git)
sha256 6c6ec86c66f0484c6916e849e20433ebc67869649c72a772cdf1bb6ca408d516 glibc-2.43-49-g8017bcfc4d9bd16083cb7f3d8eda7d07b4593b09-git4.tar.gz
sha256 1ee5c22f4a934db14cf942e73fc072c1e4ef68a4be944d4aec1a5acfa9cf813f glibc-2.43-63-g20b3e8717652bdc2f89c99c4cc6e38d56a754866-git4.tar.gz
# Hashes for license files
sha256 edaef632cbb643e4e7a221717a6c441a4c1a7c918e6e4d56debc3d8739b233f6 COPYINGv2

View File

@@ -7,7 +7,7 @@
# Generate version string using:
# git describe --match 'glibc-*' --abbrev=40 origin/release/MAJOR.MINOR/master | cut -d '-' -f 2-
# When updating the version, please also update localedef
GLIBC_VERSION = 2.43-49-g8017bcfc4d9bd16083cb7f3d8eda7d07b4593b09
GLIBC_VERSION = 2.43-63-g20b3e8717652bdc2f89c99c4cc6e38d56a754866
GLIBC_SITE = https://gitlab.com/gnutools/glibc.git
GLIBC_SITE_METHOD = git
@@ -61,6 +61,15 @@ GLIBC_IGNORE_CVES += CVE-2026-6238
# Fixed by glibc-2.43-45-gdae425b554207f7c4599c7fac707ad4c08545674
GLIBC_IGNORE_CVES += CVE-2026-6791
# Fixed in glibc-2.43-54-713998bf001027c2507cb56f9d1c73e46a6bad0b
GLIBC_IGNORE_CVES += CVE-2026-19499
# Fixed in glibc-2.43-55-138c43f0180945b014e284a87b332d4d8237f537
GLIBC_IGNORE_CVES += CVE-2026-77117
# Fixed in glibc-2.43-56-3ad1bbd8f94a207efb108a38d434695eab8a1831
GLIBC_IGNORE_CVES += CVE-2026-80489
# This CVE is considered as not being security issues by
# upstream glibc:
# https://security-tracker.debian.org/tracker/CVE-2010-4756

View File

@@ -1,9 +1,9 @@
# sha256 checksum from https://go.dev/dl/
sha256 495be4bc87176ac567392e5b4116abd98466d33d7b49d41e764ccc6976b2dc42 go1.26.5.src.tar.gz
sha256 88c162b204e6eefcc32499453b492e80209f4a4c78c33092636901c540fb0d05 go1.26.5.linux-386.tar.gz
sha256 5c2c3b16caefa1d968a94c1daca04a7ca301a496d9b086e17ad77bb81393f053 go1.26.5.linux-amd64.tar.gz
sha256 fe4789e92b1f33358680864bbe8704289e7bb5fc207d80623c308935bd696d49 go1.26.5.linux-arm64.tar.gz
sha256 6dae9edab81c13bccf962dec15f1fd2ec26c14a6821b4d2c92dab4130c289d7a go1.26.5.linux-armv6l.tar.gz
sha256 c5d60e2b303bb612f20cd82786594b64874e73b35134025e27d3390bf284ae43 go1.26.5.linux-ppc64le.tar.gz
sha256 09ce3c504c0323968b75a717244dca4f25cd4cf0443e5ff6bc0bfa74add89fa7 go1.26.5.linux-s390x.tar.gz
sha256 a0721c54c688901448d77ad9b3ec7ea7c474730755ff891382e92ecb93ff2cb1 go1.26.6.src.tar.gz
sha256 f09a71029fc5cd2940fbe36b0eb1fb2d8f3407cd6adb6b7b4de3eaf04007f8c4 go1.26.6.linux-386.tar.gz
sha256 708effb774be8237570d0add163225abbdfaf4fca28b2611df167beba4feef89 go1.26.6.linux-amd64.tar.gz
sha256 d0507e9e9d7fe012aae570108cbd76c15de879e17130ab8cb90d4d7445cb1f2e go1.26.6.linux-arm64.tar.gz
sha256 e1379a2fe77bd30fa29833074388247e7c65416e09279f746f20de2d5cf4dfea go1.26.6.linux-armv6l.tar.gz
sha256 232b65543a42eda95df6a63f76235c1795bb535eba5c74e509faec71bc648388 go1.26.6.linux-ppc64le.tar.gz
sha256 958757933d38172dd544085d253c8738cf09793d24c8bc0422e5e1e1fffa4fde go1.26.6.linux-s390x.tar.gz
sha256 911f8f5782931320f5b8d1160a76365b83aea6447ee6c04fa6d5591467db9dad LICENSE

View File

@@ -4,7 +4,10 @@
#
################################################################################
GO_VERSION = 1.26.5
# When bumping this to 1.27 (or beyond), remove the workaround for
# upstream issue https://github.com/golang/go/issues/77436, below
# (i.e. revert the commit adding these lines).
GO_VERSION = 1.26.6
HOST_GO_GOPATH = $(HOST_DIR)/share/go-path
HOST_GO_HOST_CACHE = $(HOST_DIR)/share/host-go-cache
@@ -75,11 +78,14 @@ HOST_GO_TARGET_ENV = \
$(if $(GO_GOARM),GOARM=$(GO_GOARM)) \
CC="$(TARGET_CC)" \
CXX="$(TARGET_CXX)" \
CGO_CFLAGS="$(TARGET_CFLAGS)" \
CGO_CXXFLAGS="$(TARGET_CXXFLAGS)" \
CGO_LDFLAGS="$(TARGET_LDFLAGS)" \
GOTOOLDIR="$(HOST_GO_TOOLDIR)"
# Workaround for https://github.com/golang/go/issues/77436
HOST_GO_TARGET_ENV += \
CGO_CFLAGS="$(subst -g3,-g2,$(TARGET_CFLAGS))" \
CGO_CXXFLAGS="$(subst -g3,-g2,$(TARGET_CXXFLAGS))"
# Allow packages to use cgo support if it is available for the target. They
# will need the toolchain for cgo support; for convenence, include that
# dependency here.

View File

@@ -403,13 +403,15 @@ config BR2_PACKAGE_GST1_PLUGINS_GOOD_PLUGIN_SPEEX
config BR2_PACKAGE_GST1_PLUGINS_GOOD_PLUGIN_TAGLIB
bool "taglib"
depends on BR2_INSTALL_LIBSTDCPP
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_7 # C++17
depends on BR2_USE_WCHAR
select BR2_PACKAGE_TAGLIB
help
Taglib tagging plugin library
comment "taglib needs a toolchain w/ C++, wchar"
depends on !BR2_INSTALL_LIBSTDCPP || !BR2_USE_WCHAR
comment "taglib needs a toolchain w/ C++, wchar, gcc >= 7"
depends on !BR2_INSTALL_LIBSTDCPP || !BR2_USE_WCHAR \
|| !BR2_TOOLCHAIN_GCC_AT_LEAST_7
config BR2_PACKAGE_GST1_PLUGINS_GOOD_PLUGIN_TWOLAME
bool "twolame"

View File

@@ -1,5 +1,5 @@
# From: http://www.haproxy.org/download/2.6/src/haproxy-2.6.27.tar.gz.sha256
sha256 ccdaf08e8653f9651992212b51af0b5513c2e2cf0cd822ca67c94cffe10386a6 haproxy-2.6.27.tar.gz
# From: http://www.haproxy.org/download/2.6/src/haproxy-2.6.32.tar.gz.sha256
sha256 8791585ee3bd24cde652d1d840ac7b1f73f086d5e9ec41c5e079592703ea52a4 haproxy-2.6.32.tar.gz
# Locally computed:
sha256 0717ca51fceaa25ac9e5ccc62e0c727dcf27796057201fb5fded56a25ff6ca28 LICENSE
sha256 5df07007198989c622f5d41de8d703e7bef3d0e79d62e24332ee739a452af62a doc/lgpl.txt

View File

@@ -5,7 +5,7 @@
################################################################################
HAPROXY_VERSION_MAJOR = 2.6
HAPROXY_VERSION = $(HAPROXY_VERSION_MAJOR).27
HAPROXY_VERSION = $(HAPROXY_VERSION_MAJOR).32
HAPROXY_SITE = http://www.haproxy.org/download/$(HAPROXY_VERSION_MAJOR)/src
HAPROXY_LICENSE = GPL-2.0+ and LGPL-2.1+ with exceptions
HAPROXY_LICENSE_FILES = LICENSE doc/lgpl.txt doc/gpl.txt
@@ -15,8 +15,10 @@ HAPROXY_CPE_ID_VENDOR = haproxy
# https://git.haproxy.org/?p=haproxy-2.6.git;a=commit;h=832b672eee54866c7a42a1d46078cc9ae0d544d9
HAPROXY_IGNORE_CVES += CVE-2023-45539
# haproxy relies on signed overflow, so MUST be built with -fwrapv
HAPROXY_MAKE_OPTS = \
LD=$(TARGET_CC) \
CFLAGS="$(TARGET_CFLAGS) -fwrapv" \
PREFIX=/usr \
TARGET=custom

View File

@@ -1,82 +0,0 @@
From 726432d7622cc0088ac353d073b59628b590ea44 Mon Sep 17 00:00:00 2001
From: Jouni Malinen <j@w1.fi>
Date: Sat, 25 Jan 2025 11:21:16 +0200
Subject: RADIUS: Drop pending request only when accepting the response
The case of an invalid authenticator in a RADIUS response could imply
that the response is not from the correct RADIUS server and as such,
such a response should be discarded without changing internal state for
the pending request. The case of an unknown response (RADIUS_RX_UNKNOWN)
is somewhat more complex since it could have been indicated before
validating the authenticator. In any case, it seems better to change the
state for the pending request only when we have fully accepted the
response.
Allowing the internal state of pending RADIUS request to change based on
responses that are not fully validation could have allow at least a
theoretical DoS attack if an attacker were to have means for injecting
RADIUS messages to the network using the IP address of the real RADIUS
server and being able to do so more quickly than the real server and
with the matching identifier from the request header (i.e., either by
flooding 256 responses quickly or by having means to capture the RADIUS
request). These should not really be realistic options in a properly
protected deployment, but nevertheless it is good to be more careful in
processing RADIUS responses.
Remove a pending RADIUS request from the internal list only when having
fully accepted a matching RADIUS response, i.e., after one of the
registered handlers has confirmed that the authenticator is valid and
processing of the response has succeeded.
Upstream: https://git.w1.fi/cgit/hostap/commit/?id=726432d7622cc0088ac353d073b59628b590ea44
CVE: CVE-2025-24912
Signed-off-by: Jouni Malinen <j@w1.fi>
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
---
src/radius/radius_client.c | 15 +++++++--------
1 file changed, 7 insertions(+), 8 deletions(-)
diff --git a/src/radius/radius_client.c b/src/radius/radius_client.c
index 2a7f36170..7909b29a7 100644
--- a/src/radius/radius_client.c
+++ b/src/radius/radius_client.c
@@ -1259,13 +1259,6 @@ static void radius_client_receive(int sock, void *eloop_ctx, void *sock_ctx)
roundtrip / 100, roundtrip % 100);
rconf->round_trip_time = roundtrip;
- /* Remove ACKed RADIUS packet from retransmit list */
- if (prev_req)
- prev_req->next = req->next;
- else
- radius->msgs = req->next;
- radius->num_msgs--;
-
for (i = 0; i < num_handlers; i++) {
RadiusRxResult res;
res = handlers[i].handler(msg, req->msg, req->shared_secret,
@@ -1276,6 +1269,13 @@ static void radius_client_receive(int sock, void *eloop_ctx, void *sock_ctx)
radius_msg_free(msg);
/* fall through */
case RADIUS_RX_QUEUED:
+ /* Remove ACKed RADIUS packet from retransmit list */
+ if (prev_req)
+ prev_req->next = req->next;
+ else
+ radius->msgs = req->next;
+ radius->num_msgs--;
+
radius_client_msg_free(req);
return;
case RADIUS_RX_INVALID_AUTHENTICATOR:
@@ -1297,7 +1297,6 @@ static void radius_client_receive(int sock, void *eloop_ctx, void *sock_ctx)
msg_type, hdr->code, hdr->identifier,
invalid_authenticator ? " [INVALID AUTHENTICATOR]" :
"");
- radius_client_msg_free(req);
fail:
radius_msg_free(msg);
--
cgit v1.2.3

View File

@@ -1,74 +0,0 @@
From 339a334551ca911187cc870f4f97ef08e11db109 Mon Sep 17 00:00:00 2001
From: Jouni Malinen <quic_jouni@quicinc.com>
Date: Wed, 5 Feb 2025 19:23:39 +0200
Subject: RADIUS: Fix pending request dropping
A recent change to this moved the place where the processed RADIUS
request was removed from the pending list to happen after the message
handler had been called. This did not take into account possibility of
the handler adding a new pending request in the list and the prev_req
pointer not necessarily pointing to the correct entry anymore. As such,
some of the pending requests could have been lost and that would result
in not being able to process responses to those requests and also, to a
memory leak.
Fix this by determining prev_req at the point when the pending request
is being removed, i.e., after the handler function has already added a
new entry.
Fixes: 726432d7622c ("RADIUS: Drop pending request only when accepting the response")
Upstream: https://git.w1.fi/cgit/hostap/commit/?id=339a334551ca911187cc870f4f97ef08e11db109
CVE: CVE-2025-24912
Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
---
src/radius/radius_client.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/src/radius/radius_client.c b/src/radius/radius_client.c
index 7909b29a7..d4faa7936 100644
--- a/src/radius/radius_client.c
+++ b/src/radius/radius_client.c
@@ -1099,7 +1099,7 @@ static void radius_client_receive(int sock, void *eloop_ctx, void *sock_ctx)
struct radius_hdr *hdr;
struct radius_rx_handler *handlers;
size_t num_handlers, i;
- struct radius_msg_list *req, *prev_req;
+ struct radius_msg_list *req, *prev_req, *r;
struct os_reltime now;
struct hostapd_radius_server *rconf;
int invalid_authenticator = 0;
@@ -1224,7 +1224,6 @@ static void radius_client_receive(int sock, void *eloop_ctx, void *sock_ctx)
break;
}
- prev_req = NULL;
req = radius->msgs;
while (req) {
/* TODO: also match by src addr:port of the packet when using
@@ -1236,7 +1235,6 @@ static void radius_client_receive(int sock, void *eloop_ctx, void *sock_ctx)
hdr->identifier)
break;
- prev_req = req;
req = req->next;
}
@@ -1270,6 +1268,12 @@ static void radius_client_receive(int sock, void *eloop_ctx, void *sock_ctx)
/* fall through */
case RADIUS_RX_QUEUED:
/* Remove ACKed RADIUS packet from retransmit list */
+ prev_req = NULL;
+ for (r = radius->msgs; r; r = r->next) {
+ if (r == req)
+ break;
+ prev_req = r;
+ }
if (prev_req)
prev_req->next = req->next;
else
--
cgit v1.2.3

View File

@@ -14,13 +14,6 @@ config BR2_PACKAGE_HOSTAPD
if BR2_PACKAGE_HOSTAPD
config BR2_PACKAGE_HOSTAPD_DRIVER_HOSTAP
bool "Enable hostap driver"
default y
select BR2_PACKAGE_HOSTAPD_HAS_WIFI_DRIVERS
help
Enable support for Host AP driver.
config BR2_PACKAGE_HOSTAPD_DRIVER_NL80211
bool "Enable nl80211 driver"
default y
@@ -41,7 +34,6 @@ config BR2_PACKAGE_HOSTAPD_DRIVER_WIRED
config BR2_PACKAGE_HOSTAPD_DRIVER_NONE
bool
default y
depends on !BR2_PACKAGE_HOSTAPD_DRIVER_HOSTAP
depends on !BR2_PACKAGE_HOSTAPD_DRIVER_NL80211
depends on !BR2_PACKAGE_HOSTAPD_DRIVER_WIRED

View File

@@ -1,3 +1,3 @@
# Locally calculated
sha256 2b3facb632fd4f65e32f4bf82a76b4b72c501f995a4f62e330219fe7aed1747a hostapd-2.11.tar.gz
sha256 f1b5992bbdd015c3ccb7faaadd62ef58ed821e15b9329bf2ceb27511ccc3f562 README
sha256 f43502561c28ba47ab77e18e1a973d07361c68cc8b14178e619bd5796b70eabd hostapd-2.12.tar.gz
sha256 83be1b142c59ccf0d6c5dde0695d8f84dfba109bea058e78ec2942389ccf327f README

View File

@@ -4,7 +4,7 @@
#
################################################################################
HOSTAPD_VERSION = 2.11
HOSTAPD_VERSION = 2.12
HOSTAPD_SITE = http://w1.fi/releases
HOSTAPD_SUBDIR = hostapd
HOSTAPD_CONFIG = $(HOSTAPD_DIR)/$(HOSTAPD_SUBDIR)/.config
@@ -16,10 +16,6 @@ HOSTAPD_LICENSE_FILES = README
HOSTAPD_CPE_ID_VENDOR = w1.fi
HOSTAPD_SELINUX_MODULES = hostapd
# 0001-RADIUS-Drop-pending-request-only-when-accepting-the-response.patch
# 0002-RADIUS-Fix-pending-request-dropping.patch
HOSTAPD_IGNORE_CVES += CVE-2025-24912
HOSTAPD_CONFIG_ENABLE = \
CONFIG_INTERNAL_LIBTOMMATH \
CONFIG_DEBUG_FILE \
@@ -37,10 +33,6 @@ HOSTAPD_CONFIG_DISABLE += CONFIG_EAP_PWD CONFIG_EAP_TEAP
HOSTAPD_CONFIG_EDITS += 's/\#\(CONFIG_TLS=\).*/\1internal/'
endif
ifeq ($(BR2_PACKAGE_HOSTAPD_DRIVER_HOSTAP),)
HOSTAPD_CONFIG_DISABLE += CONFIG_DRIVER_HOSTAP
endif
ifeq ($(BR2_PACKAGE_HOSTAPD_DRIVER_NL80211),)
HOSTAPD_CONFIG_DISABLE += CONFIG_DRIVER_NL80211
endif

View File

@@ -0,0 +1,113 @@
From 0da22762971551462cfad8f0b11cfb037472a4e8 Mon Sep 17 00:00:00 2001
From: DRC <information@libjpeg-turbo.org>
Date: Thu, 16 Jul 2026 12:09:54 -0400
Subject: [PATCH] libspng: Really remove gamma correction code
We really don't use it, and fpclassify() apparently introduces yet
another libm dependency in some cases (although I can't reproduce that.)
Fixes #904
Upstream: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/0da22762971551462cfad8f0b11cfb037472a4e8
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
src/spng/spng.c | 20 ++++++++++++++++++--
1 file changed, 18 insertions(+), 2 deletions(-)
diff --git a/src/spng/spng.c b/src/spng/spng.c
index 06249d68..aeadb67e 100644
--- a/src/spng/spng.c
+++ b/src/spng/spng.c
@@ -353,9 +353,12 @@ struct spng_ctx
int widest_pass;
int last_pass; /* last non-empty pass */
+#if 0 /* libjpeg-turbo: Eliminate unused gamma correction code, which
+ introduces an unwanted libm dependency */
uint16_t *gamma_lut; /* points to either _lut8 or _lut16 */
uint16_t *gamma_lut16;
uint16_t gamma_lut8[256];
+#endif
unsigned char trns_px[8];
union spng__decode_plte decode_plte;
struct spng_sbit decode_sb;
@@ -1742,6 +1745,8 @@ static uint16_t sample_to_target(uint16_t sample, unsigned bit_depth, unsigned s
return sample;
}
+#if 0 /* libjpeg-turbo: Eliminate unused gamma correction code, which
+ introduces an unwanted libm dependency */
static inline void gamma_correct_row(unsigned char *row, uint32_t pixels, int fmt, const uint16_t *gamma_lut)
{
uint32_t i;
@@ -1785,6 +1790,7 @@ static inline void gamma_correct_row(unsigned char *row, uint32_t pixels, int fm
}
}
}
+#endif
/* Apply transparency to output row */
static inline void trns_row(unsigned char *row,
@@ -3302,7 +3308,10 @@ int spng_decode_scanline(spng_ctx *ctx, void *out, size_t len)
const struct spng_subimage *sub = ctx->subimage;
const struct spng_ihdr *ihdr = &ctx->ihdr;
+#if 0 /* libjpeg-turbo: Eliminate unused gamma correction code, which
+ introduces an unwanted libm dependency */
const uint16_t *gamma_lut = ctx->gamma_lut;
+#endif
unsigned char *trns_px = ctx->trns_px;
const struct spng_sbit *sb = &ctx->decode_sb;
const struct spng_plte_entry *plte = ctx->decode_plte.rgba;
@@ -3529,7 +3538,10 @@ int spng_decode_scanline(spng_ctx *ctx, void *out, size_t len)
if(f.do_scaling) scale_row(out, width, fmt, processing_depth, sb);
+#if 0 /* libjpeg-turbo: Eliminate unused gamma correction code, which
+ introduces an unwanted libm dependency */
if(f.apply_gamma) gamma_correct_row(out, width, fmt, gamma_lut);
+#endif
/* The previous scanline is always defiltered */
void *t = ctx->prev_scanline;
@@ -3768,6 +3780,8 @@ int spng_decode_image(spng_ctx *ctx, void *out, size_t len, int fmt, int flags)
/*if(f.same_layout && !flags && !f.interlaced) f.zerocopy = 1;*/
+#if 0 /* libjpeg-turbo: Eliminate unused gamma correction code, which
+ introduces an unwanted libm dependency */
uint16_t *gamma_lut = NULL;
if(f.apply_gamma)
@@ -3807,15 +3821,14 @@ int spng_decode_image(spng_ctx *ctx, void *out, size_t len, int fmt, int flags)
unsigned i;
for(i=0; i < lut_entries; i++)
{
-#if 0 /* libjpeg-turbo: Eliminate libm dependency */
float c = pow((float)i / max, exponent) * max;
-#endif
float c = 0.0f;
if(c > max) c = max;
gamma_lut[i] = (uint16_t)c;
}
}
+#endif
struct spng_sbit *sb = &ctx->decode_sb;
@@ -5000,7 +5013,10 @@ void spng_ctx_free(spng_ctx *ctx)
if(!ctx->user_owns_out_png) spng__free(ctx, ctx->out_png);
+#if 0 /* libjpeg-turbo: Eliminate unused gamma correction code, which
+ introduces an unwanted libm dependency */
spng__free(ctx, ctx->gamma_lut16);
+#endif
spng__free(ctx, ctx->row_buf);
spng__free(ctx, ctx->scanline_buf);
--
2.47.3

View File

@@ -15,7 +15,7 @@ JPEG_TURBO_INSTALL_STAGING = YES
JPEG_TURBO_PROVIDES = jpeg
JPEG_TURBO_DEPENDENCIES = host-pkgconf
JPEG_TURBO_CONF_OPTS = -DWITH_JPEG8=ON
JPEG_TURBO_CONF_OPTS = -DWITH_JPEG8=ON -DWITH_TESTS=OFF
ifeq ($(BR2_STATIC_LIBS),y)
JPEG_TURBO_CONF_OPTS += -DENABLE_STATIC=ON -DENABLE_SHARED=OFF
@@ -43,11 +43,10 @@ ifeq ($(BR2_STATIC_LIBS),)
JPEG_TURBO_CONF_OPTS += -DCMAKE_POSITION_INDEPENDENT_CODE=ON
endif
ifeq ($(BR2_PACKAGE_JPEG_TURBO_TOOLS),)
define JPEG_TURBO_REMOVE_TOOLS
rm -f $(addprefix $(TARGET_DIR)/usr/bin/,cjpeg djpeg jpegtran rdjpgcom tjbench wrjpgcom)
endef
JPEG_TURBO_POST_INSTALL_TARGET_HOOKS += JPEG_TURBO_REMOVE_TOOLS
ifeq ($(BR2_PACKAGE_JPEG_TURBO_TOOLS),y)
JPEG_TURBO_CONF_OPTS += -DWITH_TOOLS=ON
else
JPEG_TURBO_CONF_OPTS += -DWITH_TOOLS=OFF
endif
$(eval $(cmake-package))

View File

@@ -18,14 +18,12 @@ define LIBBPF_BUILD_CMDS
-C $(@D)/src
endef
# bpftrace uses bpf_iter_link_info.task that was added since kernel 6.1
# bpftrace uses BPF_TRACE_KPROBE_SESSION that was added since kernel 6.10
# so we need to update some uapi headers in STAGING_DIR if the toolchain
# is build with linux-headers < 6.1.
# is build with linux-headers < 6.1.0
# Otherwise bpftrace is broken due to out of date linux/bpf.h installed
# by the toolchain.
# https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=f0d74c4da1f060d2a66976193712a5e6abd361f5
# https://github.com/bpftrace/bpftrace/commit/7578314df67df6bbdffaf493ff3b4d182b235b34
ifeq ($(BR2_TOOLCHAIN_HEADERS_AT_LEAST_6_1),)
ifeq ($(BR2_TOOLCHAIN_HEADERS_AT_LEAST_6_10),)
LIBBPF_UPDATE_UAPI_HEADERS = install_uapi_headers UAPIDIR=/usr/include/bpf
define LIBBPF_FIX_STAGING_PC

View File

@@ -1,7 +1,7 @@
# From https://github.com/curl/curl/releases/tag/curl-8_21_0
# From https://github.com/curl/curl/releases/tag/curl-8_22_0
# after checking pgp signature:
# https://curl.se/download/curl-8.21.0.tar.xz.asc
# https://curl.se/download/curl-8.22.0.tar.xz.asc
# signed with key 27EDEAF22F3ABCEB50DB9A125CC908FDB71E12C2
sha256 aa1b66a70eace83dc624508745646c08ae561de512ab403adffb93ac87fc72e6 curl-8.21.0.tar.xz
sha256 f7ef3ae8a22e521f289803fe93543eb64c329b58aa73a9e224dfd915a2a5f4f7 curl-8.22.0.tar.xz
# Locally computed
sha256 82f2f4427d6545ee5aaac4f0b80428da6cc8ba41c2cf5da3a03680ec327b9681 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
LIBCURL_VERSION = 8.21.0
LIBCURL_VERSION = 8.22.0
LIBCURL_SOURCE = curl-$(LIBCURL_VERSION).tar.xz
LIBCURL_SITE = https://curl.se/download
LIBCURL_DEPENDENCIES = host-pkgconf \

View File

@@ -1,4 +1,4 @@
# From https://github.com/strukturag/libde265/releases/tag/v1.1.1
sha256 fd48a927e94ed74fc7ce8829d222b9d8599fcbfe8b6448ba66705babc56ab219 libde265-1.1.1.tar.gz
# From https://github.com/strukturag/libde265/releases/tag/v1.1.2
sha256 eaacd1943ab0c452c19f6136a36ca227e6b761b39a81eaca8454d48c147e1f67 libde265-1.1.2.tar.gz
# Locally computed
sha256 02cc1585a20677992e0ba578fa692635dc193735f2691dc81de924b51c4e8020 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
LIBDE265_VERSION = 1.1.1
LIBDE265_VERSION = 1.1.2
LIBDE265_SITE = https://github.com/strukturag/libde265/releases/download/v$(LIBDE265_VERSION)
LIBDE265_LICENSE = LGPL-3.0+
LIBDE265_LICENSE_FILES = COPYING

View File

@@ -1,3 +1,3 @@
# Locally calculated
sha256 a88a42a4ea9bdab7aa8686eead3bf7d9c6dd74529caca16ab22eaa92433d31d9 libgit2-1.9.6.tar.gz
sha256 1a4fbe7589e814777ae76b64734ad80f4ecad22cd33a22682a2aaea4ae5375e7 libgit2-1.9.7.tar.gz
sha256 e0938121c0554985fe17196ac38fc590d149268e9c46e0c0e7a2eae1354fae71 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
LIBGIT2_VERSION = 1.9.6
LIBGIT2_VERSION = 1.9.7
LIBGIT2_SITE = $(call github,libgit2,libgit2,v$(LIBGIT2_VERSION))
LIBGIT2_LICENSE = \
GPL-2.0 with linking exception, \

View File

@@ -1,4 +1,4 @@
# From https://github.com/strukturag/libheif/releases/tag/v1.23.1
sha256 0de0327f60fcd47de90d5654c6fe152232738d60d84fe084ec3e0f35e03b166a libheif-1.23.1.tar.gz
# From https://github.com/strukturag/libheif/releases/tag/v1.23.3
sha256 11c1179e0e4bec33624b87f22ec42c1e993a40d946d44d26f9c431cf1456a863 libheif-1.23.3.tar.gz
# Locally computed:
sha256 fa81ce652315b013359d6e8e4744335f31a50c7c192907176d3632f78a3b4596 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
LIBHEIF_VERSION = 1.23.1
LIBHEIF_VERSION = 1.23.3
LIBHEIF_SITE = https://github.com/strukturag/libheif/releases/download/v$(LIBHEIF_VERSION)
LIBHEIF_LICENSE = LGPL-3.0+
LIBHEIF_LICENSE_FILES = COPYING

View File

@@ -1,7 +1,7 @@
# From https://www.nlnetlabs.nl/downloads/ldns/ldns-1.9.0.tar.gz.sha1
sha1 9cfe5623dcd40cee0e480b438318c3c4a26c1ecf ldns-1.9.0.tar.gz
# From https://www.nlnetlabs.nl/downloads/ldns/ldns-1.9.0.tar.gz.sha256
sha256 abaeed2858fbea84a4eb9833e19e7d23380cc0f3d9b6548b962be42276ffdcb3 ldns-1.9.0.tar.gz
# From https://www.nlnetlabs.nl/downloads/ldns/ldns-1.9.2.tar.gz.sha1
sha1 d197d9fb46e1802a7160368b38bf063b493f1be1 ldns-1.9.2.tar.gz
# From https://www.nlnetlabs.nl/downloads/ldns/ldns-1.9.2.tar.gz.sha256
sha256 b524fa21994b6e834200ceb8c27f1b84bda5982fe35706f058196c079db94d5d ldns-1.9.2.tar.gz
# Hash for license file:
sha256 9e0b1505c358d1a7c79555ee8bd1acbe2985dbc74dd81f3697cebf2161e922e6 LICENSE

View File

@@ -4,7 +4,7 @@
#
################################################################################
LIBLDNS_VERSION = 1.9.0
LIBLDNS_VERSION = 1.9.2
LIBLDNS_SOURCE = ldns-$(LIBLDNS_VERSION).tar.gz
LIBLDNS_SITE = https://www.nlnetlabs.nl/downloads/ldns
LIBLDNS_LICENSE = BSD-3-Clause

View File

@@ -0,0 +1,26 @@
From f054ce197a286fdd2fcb33ec1d9c236c5976adfb Mon Sep 17 00:00:00 2001
From: fundawang <fundawang@yeah.net>
Date: Sun, 26 Jan 2025 16:39:03 +0800
Subject: [PATCH] move link against gnutls into main library, as it is
referenced by tls/libtls.la
Upstream: d205297a10bf8d7f8846bf42f0ed618543a561a9
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
lib/Makefile.am | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/lib/Makefile.am b/lib/Makefile.am
index 82376cb..33be5e4 100644
--- a/lib/Makefile.am
+++ b/lib/Makefile.am
@@ -48,5 +48,5 @@ libnfs_la_LIBADD = \
if HAVE_TLS
libnfs_la_CPPFLAGS += -I$(abs_top_srcdir)/tls
-libnfs_la_LIBADD += ../tls/libtls.la
+libnfs_la_LIBADD += ../tls/libtls.la -lgnutls
endif
--
2.55.0

View File

@@ -0,0 +1,29 @@
From 74437cb4e9d47daeeb3f851c5b14eb0d207ceb17 Mon Sep 17 00:00:00 2001
From: fundawang <fundawang@yeah.net>
Date: Sun, 26 Jan 2025 16:39:59 +0800
Subject: [PATCH] move link against gnutls into main library, as it is
referenced by tls/libtls.la
Upstream: 546c9ed8624403078ef993138b56dce4c3558523
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
utils/Makefile.am | 3 ---
1 file changed, 3 deletions(-)
diff --git a/utils/Makefile.am b/utils/Makefile.am
index bd584b8..2ae7636 100644
--- a/utils/Makefile.am
+++ b/utils/Makefile.am
@@ -16,9 +16,6 @@ AM_CPPFLAGS = \
"-D_U_=__attribute__((unused))"
COMMON_LIBS = ../lib/libnfs.la $(LIBSOCKET)
-if HAVE_TLS
-COMMON_LIBS += -lgnutls
-endif
nfs_cat_LDADD = $(COMMON_LIBS)
nfs_ls_LDADD = $(COMMON_LIBS)
--
2.55.0

View File

@@ -0,0 +1,41 @@
From 8c6bf2f173fdca0a954ed206b3a386e33b5de47b Mon Sep 17 00:00:00 2001
From: Andreas Ziegler <15275159+aeolio@users.noreply.github.com>
Date: Sun, 28 Jun 2026 06:20:48 +0000
Subject: [PATCH] autotools: fix 'undefined reference' if libnfs was built with
gnutls support (#587)
Signed-off-by: Andreas Ziegler <15275159+aeolio@users.noreply.github.com>
Upstream: a3e86449217fe5429c38e2b06c4f7e6b3cd3be32
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
configure.ac | 2 ++
libnfs.pc.in | 2 +-
2 files changed, 3 insertions(+), 1 deletion(-)
diff --git a/configure.ac b/configure.ac
index a012004..6e5100f 100644
--- a/configure.ac
+++ b/configure.ac
@@ -284,6 +284,8 @@ AC_COMPILE_IFELSE([AC_LANG_PROGRAM([[
[[const char *v = GNUTLS_VERSION;]])],[libnfs_cv_HAVE_TLS=yes],[libnfs_cv_HAVE_TLS=no])])
if test x"$libnfs_cv_HAVE_TLS" = x"yes"; then
AC_DEFINE(HAVE_TLS,1,[Whether we have linux tls support])
+ # tell pkg-config that gnutls needs to be linked also
+ AC_SUBST(tls_library,"-lgnutls")
fi
AM_CONDITIONAL([HAVE_TLS], [test $libnfs_cv_HAVE_TLS = yes])
diff --git a/libnfs.pc.in b/libnfs.pc.in
index fdc012c..42be7b2 100644
--- a/libnfs.pc.in
+++ b/libnfs.pc.in
@@ -10,5 +10,5 @@ Description: libnfs is a client library for accessing NFS shares over a network.
Version: @VERSION@
Requires:
Conflicts:
-Libs: -L${libdir} -lnfs
+Libs: -L${libdir} -lnfs @tls_library@
Cflags: -I${includedir}
--
2.55.0

View File

@@ -1,5 +1,5 @@
# From https://github.com/openssl/openssl/releases/download/openssl-3.6.3/openssl-3.6.3.tar.gz.sha256
sha256 243a86649cf6f23eeb6a2ff2456e09e5d77dd9018a54d3d96b0c6bdd6ba6c7f1 openssl-3.6.3.tar.gz
# From https://github.com/openssl/openssl/releases/download/openssl-3.6.4/openssl-3.6.4.tar.gz.sha256
sha256 9bffaa1ad1e07b354c21bd3324ec02fa15579f45a7d0494b3e74bc449b7333ef openssl-3.6.4.tar.gz
# License files
sha256 7d5450cb2d142651b8afa315b5f238efc805dad827d91ba367d8516bc9d49e7a LICENSE.txt

View File

@@ -4,7 +4,7 @@
#
################################################################################
LIBOPENSSL_VERSION = 3.6.3
LIBOPENSSL_VERSION = 3.6.4
LIBOPENSSL_SITE = https://github.com/openssl/openssl/releases/download/openssl-$(LIBOPENSSL_VERSION)
LIBOPENSSL_SOURCE = openssl-$(LIBOPENSSL_VERSION).tar.gz
LIBOPENSSL_LICENSE = Apache-2.0
@@ -23,6 +23,10 @@ ifeq ($(BR2_m68k_cf),y)
LIBOPENSSL_CFLAGS += -mxgot
# resolves an assembler "out of range error" with blake2 and sha512 algorithms
LIBOPENSSL_CFLAGS += -DOPENSSL_SMALL_FOOTPRINT
# disable atomic operations
ifeq ($(BR2_TOOLCHAIN_HAS_ATOMIC),)
LIBOPENSSL_CFLAGS += -DBROKEN_CLANG_ATOMICS
endif
endif
ifeq ($(BR2_USE_MMU),)

View File

@@ -0,0 +1,117 @@
From 2dae3024897e1898d389835151f4e9606227721d Mon Sep 17 00:00:00 2001
From: Will Cosgrove <will@panic.com>
Date: Fri, 10 Oct 2025 08:26:20 -0700
Subject: [PATCH] Update sftp_symlink to avoid out of bounds read on malformed
packet #1705 (#1717)
CVE: CVE-2025-15661
Upstream: https://sources.debian.org/patches/libssh2/1.11.1-6/CVE-2025-15661.patch/
Upstream: https://github.com/libssh2/libssh2/commit/2dae3024897e1898d389835151f4e9606227721d
Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
---
--- libssh2-1.11.1.orig/src/sftp.c
+++ libssh2-1.11.1/src/sftp.c
@@ -3795,15 +3795,19 @@ static int sftp_symlink(LIBSSH2_SFTP *sf
{
LIBSSH2_CHANNEL *channel = sftp->channel;
LIBSSH2_SESSION *session = channel->session;
- size_t data_len = 0, link_len;
+ size_t data_len = 0, lk_len;
/* 13 = packet_len(4) + packet_type(1) + request_id(4) + path_len(4) */
ssize_t packet_len =
path_len + 13 +
((link_type == LIBSSH2_SFTP_SYMLINK) ? (4 + target_len) : 0);
unsigned char *s, *data = NULL;
+ struct string_buf buf;
static const unsigned char link_responses[2] =
{ SSH_FXP_NAME, SSH_FXP_STATUS };
int retcode;
+ unsigned char packet_type;
+ uint32_t tmp_u32;
+ unsigned char *lk_target;
if(sftp->symlink_state == libssh2_NB_state_idle) {
sftp->last_errno = LIBSSH2_FX_OK;
@@ -3891,8 +3895,25 @@ static int sftp_symlink(LIBSSH2_SFTP *sf
sftp->symlink_state = libssh2_NB_state_idle;
- if(data[0] == SSH_FXP_STATUS) {
- retcode = _libssh2_ntohu32(data + 5);
+ buf.data = (unsigned char *)LIBSSH2_UNCONST(data);
+ buf.dataptr = buf.data;
+ buf.len = data_len;
+
+ if(_libssh2_get_byte(&buf, &packet_type)) {
+ LIBSSH2_FREE(session, data);
+ return _libssh2_error(session, LIBSSH2_ERROR_SFTP_PROTOCOL,
+ "SFTP Protocol Error (type)");
+ }
+
+ if(packet_type == SSH_FXP_STATUS) {
+ if(_libssh2_get_u32(&buf, &tmp_u32)) {
+ LIBSSH2_FREE(session, data);
+ return _libssh2_error(session, LIBSSH2_ERROR_SFTP_PROTOCOL,
+ "SFTP Protocol Error (code)");
+ }
+
+ retcode = (int)tmp_u32;
+
LIBSSH2_FREE(session, data);
if(retcode == LIBSSH2_FX_OK)
return LIBSSH2_ERROR_NONE;
@@ -3903,30 +3924,37 @@ static int sftp_symlink(LIBSSH2_SFTP *sf
}
}
- if(_libssh2_ntohu32(data + 5) < 1) {
+ /* advance past id */
+ if(_libssh2_get_u32(&buf, &tmp_u32)) {
LIBSSH2_FREE(session, data);
return _libssh2_error(session, LIBSSH2_ERROR_SFTP_PROTOCOL,
- "Invalid READLINK/REALPATH response, "
- "no name entries");
+ "SFTP Protocol Error (id)");
}
- if(data_len < 13) {
- if(data_len > 0) {
- LIBSSH2_FREE(session, data);
- }
+ /* look for at least one link */
+ if(_libssh2_get_u32(&buf, &tmp_u32) || tmp_u32 < 1) {
+ LIBSSH2_FREE(session, data);
return _libssh2_error(session, LIBSSH2_ERROR_SFTP_PROTOCOL,
- "SFTP stat packet too short");
+ "Invalid READLINK/REALPATH response, "
+ "no name entries");
}
- /* this reads a u32 and stores it into a signed 32bit value */
- link_len = _libssh2_ntohu32(data + 9);
- if(link_len < target_len) {
- memcpy(target, data + 13, link_len);
- target[link_len] = 0;
- retcode = (int)link_len;
+ if(_libssh2_get_string(&buf, &lk_target, &lk_len) == LIBSSH2_ERROR_NONE) {
+ if(lk_len < target_len) {
+ memcpy(target, lk_target, lk_len);
+ target[lk_len] = '\0';
+ retcode = (int)lk_len;
+ }
+ else {
+ retcode = LIBSSH2_ERROR_BUFFER_TOO_SMALL;
+ }
}
- else
- retcode = LIBSSH2_ERROR_BUFFER_TOO_SMALL;
+ else {
+ LIBSSH2_FREE(session, data);
+ return _libssh2_error(session, LIBSSH2_ERROR_SFTP_PROTOCOL,
+ "SFTP Protocol Error (filename)");
+ }
+
LIBSSH2_FREE(session, data);
return retcode;

View File

@@ -0,0 +1,30 @@
Needed by the fix for CVE-2025-15661
Cherrypicked from
commit 606c102e52f8447de2b745dd6c5ddf418defc519
Author: Viktor Szakats <commit@vsz.me>
Date: Thu Jan 30 21:18:23 2025 +0100
CVE: CVE-2025-15661
Upstream: https://sources.debian.org/patches/libssh2/1.11.1-6/libssh-unconst-backport.patch/
Upstream: https://github.com/libssh2/libssh2/commit/606c102e52f8447de2b745dd6c5ddf418defc519
Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
---
--- libssh2-1.11.1.orig/src/libssh2_priv.h
+++ libssh2-1.11.1/src/libssh2_priv.h
@@ -117,6 +117,14 @@
#define UINT32_MAX 0xffffffffU
#endif
+#ifdef _WIN64
+#define LIBSSH2_UNCONST(p) ((void *)(libssh2_uint64_t)(const void *)(p))
+#elif defined(_MSC_VER)
+#define LIBSSH2_UNCONST(p) ((void *)(unsigned int)(const void *)(p))
+#else
+#define LIBSSH2_UNCONST(p) ((void *)(uintptr_t)(const void *)(p))
+#endif
+
#if (defined(__GNUC__) || defined(__clang__)) && \
defined(__STDC_VERSION__) && (__STDC_VERSION__ >= 199901L) && \
!defined(LIBSSH2_NO_FMT_CHECKS)

View File

@@ -0,0 +1,46 @@
From 4ed26f5740bdd409269ed9fb48a28bf8f565b681 Mon Sep 17 00:00:00 2001
From: Will Cosgrove <will@panic.com>
Date: Mon, 20 Oct 2025 14:04:52 -0700
Subject: [PATCH] Fix sftp_symlink when getting SSH_FXP_STATUS response (#1731)
Move advancing past packet ID before reading the FXP_STATUS response.
CVE: CVE-2025-15661
Upstream: https://github.com/libssh2/libssh2/commit/4ed26f5740bdd409269ed9fb48a28bf8f565b681
Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
---
src/sftp.c | 14 +++++++-------
1 file changed, 7 insertions(+), 7 deletions(-)
diff --git a/src/sftp.c b/src/sftp.c
index 70d7686daf..bb297b831a 100644
--- a/src/sftp.c
+++ b/src/sftp.c
@@ -4006,6 +4006,13 @@ static int sftp_symlink(LIBSSH2_SFTP *sftp, const char *path,
"SFTP Protocol Error (type)");
}
+ /* advance past id */
+ if(_libssh2_get_u32(&buf, &tmp_u32)) {
+ LIBSSH2_FREE(session, data);
+ return _libssh2_error(session, LIBSSH2_ERROR_SFTP_PROTOCOL,
+ "SFTP Protocol Error (id)");
+ }
+
if(packet_type == SSH_FXP_STATUS) {
if(_libssh2_get_u32(&buf, &tmp_u32)) {
LIBSSH2_FREE(session, data);
@@ -4025,13 +4032,6 @@ static int sftp_symlink(LIBSSH2_SFTP *sftp, const char *path,
}
}
- /* advance past id */
- if(_libssh2_get_u32(&buf, &tmp_u32)) {
- LIBSSH2_FREE(session, data);
- return _libssh2_error(session, LIBSSH2_ERROR_SFTP_PROTOCOL,
- "SFTP Protocol Error (id)");
- }
-
/* look for at least one link */
if(_libssh2_get_u32(&buf, &tmp_u32) || tmp_u32 < 1) {
LIBSSH2_FREE(session, data);

View File

@@ -0,0 +1,29 @@
From 5e4776146552d898b9c0e1b313cd093fa8dc92d0 Mon Sep 17 00:00:00 2001
From: Will Cosgrove <will@panic.com>
Date: Thu, 2 Jul 2026 11:00:23 -0700
Subject: [PATCH] Prevent dangling pointer by nullifying data (#2180)
Set data to NULL after freeing it to avoid dangling pointer. fixes
GHSA-px3w-7g75-hg7w.
Credit: VladimirEliTokarev
Forwarded: not-needed
CVE: CVE-2026-66032
Upstream: https://sources.debian.org/patches/libssh2/1.11.1-6/CVE-2026-66032.patch/
Upstream: https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0
Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
---
src/sftp.c | 1 +
1 file changed, 1 insertion(+)
--- a/src/sftp.c
+++ b/src/sftp.c
@@ -1279,6 +1279,7 @@
"got HANDLE FXOK"));
LIBSSH2_FREE(session, data);
+ data = NULL;
/* silly situation, but check for a HANDLE */
rc = sftp_packet_require(sftp, SSH_FXP_HANDLE,

View File

@@ -0,0 +1,45 @@
From a2ed82d40964bbc0d64cd717aa0a5a892117d2e6 Mon Sep 17 00:00:00 2001
From: Viktor Szakats <commit@vsz.me>
Date: Thu, 23 Jul 2026 10:32:04 +0200
Subject: [PATCH] openssl: fix potential OOB read/write with AES-GCM in
`ssh2_cipher_crypt()`
By applying two bounds checks to non-debug builds.
Reported-by: Vladimir Eli Tokarev
Fixes GHSA-c4f7-cvfc-33j7
Follow-up to 3c953c05d67eb1ebcfd3316f279f12c4b1d600b4 #797
Closes #2401
Forwarded: not-needed
CVE: CVE-2026-66033
Upstream: https://sources.debian.org/patches/libssh2/1.11.1-6/CVE-2026-66033.patch/
Upstream: https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6
Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
---
src/openssl.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)
--- a/src/openssl.c
+++ b/src/openssl.c
@@ -1042,13 +1042,15 @@
const int aadlen = (is_aesgcm && IS_FIRST(firstlast)) ? 4 : 0;
/* size of AT, if present */
const int authenticationtag = IS_LAST(firstlast) ? authlen : 0;
- /* length to encrypt */
- const int cryptlen = (unsigned int)blocksize - aadlen - authenticationtag;
+ unsigned int cryptlen; /* length to encrypt */
(void)algo;
- assert(blocksize <= sizeof(buf));
- assert(cryptlen >= 0);
+ if(blocksize > sizeof(buf) ||
+ blocksize < (size_t)(aadlen + authenticationtag))
+ return 1;
+
+ cryptlen = (unsigned int)blocksize - aadlen - authenticationtag;
#if LIBSSH2_AES_GCM
/* First block */

View File

@@ -0,0 +1,36 @@
From a13bb6c773f0d55ad1628cede57e99803cd898d9 Mon Sep 17 00:00:00 2001
From: Viktor Szakats <commit@vsz.me>
Date: Sat, 4 Jul 2026 11:19:49 +0200
Subject: [PATCH] publickey: fix potential OOB read in
`libssh2_publickey_list_fetch()`
Reported-by: Vladimir Eli Tokarev
Fixes GHSA-w6g9-cpfp-22gc
Closes #2202
Forwarded: not-needed
CVE: CVE-2026-66034
Upstream: https://sources.debian.org/patches/libssh2/1.11.1-6/CVE-2026-66034.patch/
Upstream: https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9
Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
---
src/publickey.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/src/publickey.c
+++ b/src/publickey.c
@@ -988,6 +988,13 @@
}
if(comment_len) {
+ if(pkey->listFetch_s + comment_len >
+ pkey->listFetch_data + pkey->listFetch_data_len) {
+ _libssh2_error(session, LIBSSH2_ERROR_BUFFER_TOO_SMALL,
+ "ListFetch data too short");
+ goto err_exit;
+ }
+
list[keys].num_attrs = 1;
list[keys].attrs =
LIBSSH2_ALLOC(session,

View File

@@ -0,0 +1,42 @@
From 42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4 Mon Sep 17 00:00:00 2001
From: Viktor Szakats <commit@vsz.me>
Date: Fri, 3 Jul 2026 18:22:55 +0200
Subject: [PATCH] transport: fix potential heap overflow on ETM decrypt
Reported-by: Vladimir Eli Tokarev
Fixes GHSA-6c79-444r-wx26
Closes #2198
Forwarded: not-needed
CVE: CVE-2026-66035
Upstream: https://sources.debian.org/patches/libssh2/1.11.1-6/CVE-2026-66035.patch/
Upstream: https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4
Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
---
src/transport.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
--- a/src/transport.c
+++ b/src/transport.c
@@ -242,6 +242,12 @@
unsigned char *decrypt_buffer;
int blocksize = session->remote.crypt->blocksize;
+ if(p->total_num < mac_len + 4 + (size_t)blocksize) {
+ LIBSSH2_FREE(session, p->payload);
+ return LIBSSH2_ERROR_DECRYPT;
+ }
+ decrypt_size = (ssize_t)(p->total_num - mac_len - 4);
+
rc = decrypt(session, p->payload + 4,
first_block, blocksize, FIRST_BLOCK);
if(rc) {
@@ -249,7 +255,6 @@
}
/* we need buffer for decrypt */
- decrypt_size = p->total_num - mac_len - 4;
decrypt_buffer = LIBSSH2_ALLOC(session, decrypt_size);
if(!decrypt_buffer) {
return LIBSSH2_ERROR_ALLOC;

View File

@@ -22,6 +22,23 @@ LIBSSH2_IGNORE_CVES += CVE-2026-55199
# 0003-transport-c-Additional-boundary-checks-for-packet-length.patch
LIBSSH2_IGNORE_CVES += CVE-2026-55200
# 0004-sftp-symlink-fix-out-of-bounds-read.patch
# 0005-libssh2-priv-backport-LIBSSH2_UNCONST.patch
# 0006-sftp-symlink-fix-SSH_FXP_STATUS-response.patch
LIBSSH2_IGNORE_CVES += CVE-2025-15661
# 0007-sftp-prevent-dangling-pointer-after-free.patch
LIBSSH2_IGNORE_CVES += CVE-2026-66032
# 0008-openssl-fix-AES-GCM-bounds-checks.patch
LIBSSH2_IGNORE_CVES += CVE-2026-66033
# 0009-publickey-fix-potential-OOB-read.patch
LIBSSH2_IGNORE_CVES += CVE-2026-66034
# 0010-transport-fix-potential-heap-overflow-on-ETM-decrypt.patch
LIBSSH2_IGNORE_CVES += CVE-2026-66035
ifeq ($(BR2_PACKAGE_LIBSSH2_MBEDTLS),y)
LIBSSH2_DEPENDENCIES += mbedtls
LIBSSH2_CONF_OPTS += --with-libmbedcrypto-prefix=$(STAGING_DIR)/usr \

View File

@@ -12,8 +12,14 @@ LIBXKBCOMMON_CPE_ID_VENDOR = xkbcommon
LIBXKBCOMMON_INSTALL_STAGING = YES
LIBXKBCOMMON_DEPENDENCIES = host-bison host-flex
LIBXKBCOMMON_CONF_OPTS = \
-Denable-docs=false \
-Denable-xkbregistry=false
-Denable-docs=false
ifeq ($(BR2_PACKAGE_LIBXML2),y)
LIBXKBCOMMON_CONF_OPTS += -Denable-xkbregistry=true
LIBXKBCOMMON_DEPENDENCIES += libxml2
else
LIBXKBCOMMON_CONF_OPTS += -Denable-xkbregistry=false
endif
ifeq ($(BR2_PACKAGE_XORG7),y)
LIBXKBCOMMON_CONF_OPTS += -Denable-x11=true

View File

@@ -7,7 +7,7 @@
LIBXML_PARSER_PERL_VERSION = 2.47
LIBXML_PARSER_PERL_SOURCE = XML-Parser-$(LIBXML_PARSER_PERL_VERSION).tar.gz
LIBXML_PARSER_PERL_SITE = $(BR2_CPAN_MIRROR)/authors/id/T/TO/TODDR
HOST_LIBXML_PARSER_PERL_DEPENDENCIES = host-expat
HOST_LIBXML_PARSER_PERL_DEPENDENCIES = host-expat host-libxcrypt
LIBXML_PARSER_PERL_LICENSE = Artistic or GPL-1.0+
LIBXML_PARSER_PERL_LICENSE_FILES = README
LIBXML_PARSER_PERL_RUN_PERL = `which perl`

View File

@@ -1,4 +1,4 @@
# From https://download.gnome.org/sources/libxml2/2.15/libxml2-2.15.3.sha256sum
sha256 78262a6e7ac170d6528ebfe2efccdf220191a5af6a6cd61ea4a9a9a5042c7a07 libxml2-2.15.3.tar.xz
# From https://download.gnome.org/sources/libxml2/2.15/libxml2-2.15.4.sha256sum
sha256 98087fd181d9070724f3fbc65c7377db03038eb92bd882374daff44940138821 libxml2-2.15.4.tar.xz
# License files, locally calculated
sha256 5d4873884a890122a4b9b20ad56ac6f7da1d796a5bfcf04a427970ac96217626 Copyright

View File

@@ -5,7 +5,7 @@
################################################################################
LIBXML2_VERSION_MAJOR = 2.15
LIBXML2_VERSION = $(LIBXML2_VERSION_MAJOR).3
LIBXML2_VERSION = $(LIBXML2_VERSION_MAJOR).4
LIBXML2_SOURCE = libxml2-$(LIBXML2_VERSION).tar.xz
LIBXML2_SITE = \
https://download.gnome.org/sources/libxml2/$(LIBXML2_VERSION_MAJOR)

Some files were not shown because too many files have changed in this diff Show More