Compare commits

..

141 Commits

Author SHA1 Message Date
Peter Korsgaard
d5180309b1 Update for 2026.08
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-04 17:31:57 +02:00
Peter Korsgaard
f3a1c36e84 docs/website/news.html: add 2026.08-rc3 announcement
Was missed when the download page was updated for 2026.08-rc3 in commit
e6b06b8d9c ("Update for 2026.08-rc3").

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-04 17:30:58 +02:00
Thomas Perale
05ee0ab1e0 docs/website: add Othermo as a silver sponsor
Othermo offers manufacturer-independent operational monitoring for
energy centers and boiler rooms. They connect a wide range of peripheral
such as meters, pumps or pressure maintenance [1][2].

Thank you for sponsoring LTS maintenance !

[1] https://othermo.de/
[2] https://www.linkedin.com/company/othermo-gmbh/

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-04 16:58:41 +02:00
Thomas Perale
dfc909b1cd package/erlang: security bump to v26.2.5.21
See the changelogs:

- https://www.erlang.org/patches/OTP-26.2.5.16
- https://www.erlang.org/patches/OTP-26.2.5.17
- https://www.erlang.org/patches/OTP-26.2.5.18
- https://www.erlang.org/patches/OTP-26.2.5.19
- https://www.erlang.org/patches/OTP-26.2.5.20
- https://www.erlang.org/patches/OTP-26.2.5.21

This fixes the following vulnerabilities:

- CVE-2026-21620:
    Relative Path Traversal, Improper Isolation or Compartmentalization
    vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp
    inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows
    Relative Path Traversal. This vulnerability is associated with program
    files lib/tftp/src/tftp_file.erl, src/tftp_file.erl.

For more information, see:
 - https://www.cve.org/CVERecord?id=CVE-2026-21620

- CVE-2026-23941:
    Inconsistent Interpretation of HTTP Requests ('HTTP Request
    Smuggling') vulnerability in Erlang OTP (inets httpd module) allows
    HTTP Request Smuggling.  This vulnerability is associated with program
    files lib/inets/src/http_server/httpd_request.erl and program routines
    httpd_request:parse_headers/7.  The server does not reject or
    normalize duplicate Content-Length headers. The earliest Content-
    Length in the request is used for body parsing while common reverse
    proxies (nginx, Apache httpd, Envoy) honor the last Content-Length
    value. This violates RFC 9112 Section 6.3 and allows front-end/back-
    end desynchronization, leaving attacker-controlled bytes queued as the
    start of the next request.

For more information, see:
 - https://www.cve.org/CVERecord?id=CVE-2026-23941

- CVE-2026-23942:
    Improper Limitation of a Pathname to a Restricted Directory ('Path
    Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path
    Traversal.  This vulnerability is associated with program files
    lib/ssh/src/ssh_sftpd.erl and program routines
    ssh_sftpd:is_within_root/2.  The SFTP server uses string prefix
    matching via lists:prefix/2 rather than proper path component
    validation when checking if a path is within the configured root
    directory. This allows authenticated users to access sibling
    directories that share a common name prefix with the configured root
    directory. For example, if root is set to /home/user1, paths like
    /home/user10 or /home/user1_backup would incorrectly be considered
    within the root.

For more information, see:
 - https://www.cve.org/CVERecord?id=CVE-2026-23942

- CVE-2026-23943:
    Improper Handling of Highly Compressed Data (Compression Bomb)
    vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial
    of Service via Resource Depletion.  The SSH transport layer advertises
    legacy zlib compression by default and inflates attacker-controlled
    payloads pre-authentication without any size limit, enabling reliable
    memory exhaustion DoS.  Two compression algorithms are affected:  *
    zlib: Activates immediately after key exchange, enabling
    unauthenticated attacks * zlib@openssh.com: Activates post-
    authentication, enabling authenticated attacks  Each SSH packet can
    decompress ~255 MB from 256 KB of wire data (1029:1 amplification
    ratio). Multiple packets can rapidly exhaust available memory, causing
    OOM kills in memory-constrained environments.  This vulnerability is
    associated with program files lib/ssh/src/ssh_transport.erl and
    program routines ssh_transport:decompress/2,
    ssh_transport:handle_packet_part/4.

For more information, see:
 - https://www.cve.org/CVERecord?id=CVE-2026-23943

- CVE-2026-28810:
    Generation of Predictable Numbers or Identifiers vulnerability in
    Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache
    Poisoning.  The built-in DNS resolver (inet_res) uses a sequential,
    process-global 16-bit transaction ID for UDP queries and does not
    implement source port randomization. Response validation relies almost
    entirely on this ID, making DNS cache poisoning practical for an
    attacker who can observe one query or predict the next ID. This
    conflicts with RFC 5452 recommendations for mitigating forged DNS
    answers.  inet_res is intended for use in trusted network environments
    and with trusted recursive resolvers. Earlier documentation did not
    clearly state this deployment assumption, which could lead users to
    deploy the resolver in environments where spoofed DNS responses are
    possible.  This vulnerability is associated with program files
    lib/kernel/src/inet_db.erl and lib/kernel/src/inet_res.erl.

For more information, see:
 - https://www.cve.org/CVERecord?id=CVE-2026-28810

- CVE-2026-32147:
    Improper Limitation of a Pathname to a Restricted Directory ('Path
    Traversal') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows
    an authenticated SFTP user to modify file attributes outside the
    configured chroot directory.  The SFTP daemon (ssh_sftpd) stores the
    raw, user-supplied path in file handles instead of the chroot-resolved
    path. When SSH_FXP_FSETSTAT is issued on such a handle, file
    attributes (permissions, ownership, timestamps) are modified on the
    real filesystem path, bypassing the root directory boundary entirely.
    Any authenticated SFTP user on a server configured with the root
    option can modify file attributes of files outside the intended chroot
    boundary. The prerequisite is that a target file must exist on the
    real filesystem at the same relative path. Note that this
    vulnerability only allows modification of file attributes; file
    contents cannot be read or altered through this attack vector.  If the
    SSH daemon runs as root, this enables direct privilege escalation: an
    attacker can set the setuid bit on any binary, change ownership of
    sensitive files, or make system configuration world-writable.  This
    vulnerability is associated with program files
    lib/ssh/src/ssh_sftpd.erl and program routines ssh_sftpd:do_open/4 and
    ssh_sftpd:handle_op/4.

For more information, see:
  - https://www.cve.org/CVERecord?id=CVE-2026-32147

- CVE-2026-42789:
    Improper Following of a Certificate's Chain of Trust vulnerability in
    Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate
    to be accepted as an intermediate issuer, enabling certificate chain
    forgery.  In lib/public_key/src/pubkey_cert.erl,
    pubkey_cert:validate_extensions/7 contains two flaws that together
    allow a certificate with basicConstraints cA:false and no keyUsage
    extension to be used as an intermediate issuer in a chain passed to
    public_key:pkix_path_validation/3: the cA:false clause recurses into
    the remaining extensions without rejecting the certificate when it is
    in issuer position, and the keyUsage check only fires when the
    extension is present, so a certificate lacking keyUsage entirely
    bypasses the keyCertSign enforcement.  Any party holding an end-entity
    certificate with basicConstraints cA:false and no keyUsage extension,
    issued by any CA in the victim's trust store, can use that
    certificate's private key to sign forged leaf certificates for
    arbitrary identities. public_key:pkix_path_validation/3 accepts the
    resulting chain, and by extension every TLS or mTLS endpoint built on
    the OTP ssl application that relies on the default verifier is
    affected, including server identity verification on the client side
    and client certificate verification on mTLS servers.

For more information, see:
 - https://www.cve.org/CVERecord?id=CVE-2026-42789

- CVE-2026-42790:
    Improper Certificate Validation vulnerability in Erlang OTP public_key
    (pubkey_cert and public_key modules) allows a DNS nameConstraints
    bypass via subject CommonName fallback in TLS hostname verification.
    Two flaws combine to allow a subordinate CA whose DNS nameConstraints
    are restricted (e.g. permitted;DNS:allowed.example.com) to issue a
    leaf certificate that an OTP TLS client accepts as a valid identity
    for an out-of-scope hostname (e.g. victim.example.com):  First,
    pubkey_cert:validate_names/6 in lib/public_key/src/pubkey_cert.erl
    only checks SAN DNS entries against nameConstraints. Per RFC 5280, a
    permitted DNS subtree only restricts certificates that contain a DNS-
    typed name. A leaf with no subjectAltName therefore trivially
    satisfies any permitted;DNS:... constraint regardless of its subject
    commonName.  Second, public_key:pkix_verify_hostname/3 in
    lib/public_key/src/public_key.erl falls back to the subject commonName
    when no subjectAltName is present, extracting id-at-commonName
    attributes as presented IDs and matching them against the reference
    hostname. The strict pkix_verify_hostname_match_fun(https) matcher
    does not suppress this fallback.  The result is that path validation
    accepts a CN-only leaf under a DNS-constrained intermediate (no SAN
    means the nameConstraints are not triggered), and hostname
    verification then accepts it via the CN fallback. The bypass is
    reachable from stock ssl:connect with verify_peer, a trusted CA, SNI,
    and the canonical strict https hostname matcher.

For more information, see:
 - https://www.cve.org/CVERecord?id=CVE-2026-42790

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-04 13:53:31 +02:00
Bernd Kuhls
ad9557dba5 package/libcurl: security bump to version 8.22.0
https://curl.se/ch/8.22.0.html
https://daniel.haxx.se/blog/2026/09/02/curl-8-22-0/

Fixes the following CVEs:
CVE-2026-13608: OpenLDAP SASL authentication bypass
CVE-2026-18924: HTTP/2 server push UAF
CVE-2026-19931: Negotiate ambient user conn reuse
CVE-2026-80229: OpenSSL provider use-after-free
CVE-2026-80230: OpenSSL pinning bypass
CVE-2026-80231: native CA store conn reuse
CVE-2026-80255: secure cookie attribute bypass with tab
CVE-2026-82208: wolfSSL CA-cache hit overrides callback
CVE-2026-82209: domain-scoped PSL domain cookie

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-04 13:46:58 +02:00
Bernd Kuhls
5f8d0b78ec package/libopenssl: disable atomic operations for m68k Coldfire
This patch fixes a build error with OpenSSL-enabled libcurl which was
detected by the Gitlab pipelines:

checking for openssl options with pkg-config... found
configure: pkg-config: SSL_LIBS: "-lssl -lcrypto -pthread"
configure: pkg-config: SSL_LDFLAGS: "-L/builds/bkuhls/buildroot/br-test-pkg/bootlin-m68k-5208-uclibc/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib"
configure: pkg-config: SSL_CPPFLAGS: ""
checking for HMAC_Update in -lcrypto... no
checking for HMAC_Init_ex in -lcrypto... no
checking OpenSSL linking with -ldl... no
checking OpenSSL linking with -ldl and -lpthread... no
checking for SSL_set_quic_use_legacy_codepoint... no
checking for SSL_set_quic_tls_cbs... no
configure: OpenSSL version does not speak any known QUIC API
configure: OPT_OPENSSL: /builds/bkuhls/buildroot/br-test-pkg/bootlin-m68k-5208-uclibc/host/m68k-buildroot-uclinux-uclibc/sysroot/usr
configure: OPENSSL_ENABLED:
configure: error: --with-openssl was given but OpenSSL could not be detected
make[1]: *** [package/pkg-generic.mk:263: /builds/bkuhls/buildroot/br-test-pkg/bootlin-m68k-5208-uclibc/build/libcurl-8.21.0/.stamp_configured] Error 1

Although OpenSSL was found using pkg-config the build tests fail.

A local build shows the concrete error in config.log, for example:

configure:27577: checking for HMAC_Update in -lcrypto
configure:27599: /home/bernd/buildroot/output/host/bin/m68k-linux-gcc
 -o conftest -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE
 -D_FILE_OFFSET_BITS=64 -O2 -g0 -fno-dwarf2-cfi-asm -Wl,-elf2flt=-r
 -static -Werror-implicit-function-declaration -Wno-system-headers
 -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64
 -D_GNU_SOURCE     -Wl,-elf2flt=-r -static
 -L/home/bernd/buildroot/output/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib
 -L/home/bernd/buildroot/output/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib
 conftest.c -lcrypto  -lssl -lcrypto -lz -pthread -lz  >&5
/home/bernd/buildroot/output/host/opt/ext-toolchain/m68k-buildroot-uclinux-uclibc/bin/ld.real:
 /home/bernd/buildroot/output/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib/libcrypto.a(libcrypto-lib-threads_pthread.o):
 in function `ossl_rcu_read_lock':
threads_pthread.c:(.text+0xa4): undefined reference to `__atomic_fetch_add_8'

This error occurs many times for various atomic operations:

$ grep "undefined reference to \`__atomic" output/build/libcurl-8.20.0/config.log | sort -u | grep -v real
threads_pthread.c:(.text+0x28a): undefined reference to `__atomic_fetch_sub_8'
threads_pthread.c:(.text+0x3b4): undefined reference to `__atomic_fetch_add_8'
threads_pthread.c:(.text+0x9c8): undefined reference to `__atomic_is_lock_free'
threads_pthread.c:(.text+0xa4): undefined reference to `__atomic_fetch_add_8'
threads_pthread.c:(.text+0xa9c): undefined reference to `__atomic_is_lock_free'
threads_pthread.c:(.text+0xb66): undefined reference to `__atomic_is_lock_free'
threads_pthread.c:(.text+0xc30): undefined reference to `__atomic_is_lock_free'
threads_pthread.c:(.text+0xcdc): undefined reference to `__atomic_is_lock_free'

The build error can be reproduced with the current buildroot tree using
this defconfig:

BR2_m68k=y
BR2_m68k_cf5208=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_M68K_COLDFIRE_UCLIBC_STABLE=y
BR2_PACKAGE_OPENSSL=y
BR2_PACKAGE_LIBCURL=y

Although the toolchain lacks atomics support

$ grep ATOMIC .config
$

it emits atomic-related defines, for example:

$ echo | output/host/bin/m68k-linux-gcc -dM -E - | grep __ATOMIC_ACQ_REL
#define __ATOMIC_ACQ_REL 4
$

This specific define __ATOMIC_ACQ_REL is used in OpenSSL to enable
atomic support at various places:
https://github.com/openssl/openssl/blob/openssl-3.6.3/crypto/threads_pthread.c

causing the build errors we see with the mentioned defconfig.

To fix the problem we use an OpenSSL-provided define to forcefully
disable the usage of atomic intrinsics.

The misdetection of atomic intrinsics for m68k coldfire is not a new
problem:
https://lists.buildroot.org/pipermail/buildroot/2017-May/180841.html
https://lists.buildroot.org/pipermail/buildroot/2026-May/803110.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-03 21:08:18 +02:00
Bernd Kuhls
c05de97a2b {linux, linux-headers}: bump 6.12.x, 6.6.x, 6.1.x, 5.15.x, 5.10.x, 7.1.x, 6.18.x series
Update the latest kernel releases to:
 - 6.12.107 -> 6.12.108
 - 6.6.155 -> 6.6.156
 - 6.1.186 -> 6.1.187
 - 5.15.219 -> 5.15.220
 - 5.10.268 -> 5.10.269
 - 7.1.12 -> 7.1.13
 - 6.18.48 -> 6.18.49

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-02 22:27:10 +02:00
Andreas Ziegler
8f38b17f76 package/mpd: update to version 0.24.15
Version 0.24.15 change log:

* protocol
	fix crash on "sticker delete" and "sticker find"
* database
	upnp: fix crash bug
* input
	alsa, curl, nfs: fix stalled transfers
* playlist
	asx, pls, rss, xspf: limit to 16 MB
	cue: fix problem playing CUE tracks in music directory root
* player
	fix noise with replay gain and cross-fade

Signed-off-by: Andreas Ziegler <br025@umbiko.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-02 21:28:15 +02:00
Alexis Lothoré
672b5f9213 package/openscap: drop duplicate patch
Commit bd5b267b1d ("package/openscap: fix build failure with dbus and
musl") brought an upstream patch to fix a build failure on the openscap
package, detected by the autobuilder on buildroot 2026.02.x, which had
openscap 1.3.12 at that time. bd5b267b1d has recently been merged on
master; openscap has already been bumped to 1.4.4 on this branch, and so
it already brings the needed fix for musl+dbus build configurations,
hence making the patch step fail. This upstream patch is then not needed
anymore on any maintained branch.

Fixes: https://autobuild.buildroot.org/results/d11d0b82dcdb4bf10f6c37db8bdbc42a78bdf28b/
Fixes: https://autobuild.buildroot.org/results/4397a4ef94ccf482f1ab9d24b6334adb0222a580/
Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-02 21:25:29 +02:00
Peter Korsgaard
94013c3a95 package/exiv2: security bump to version 0.28.9
Fixes the following vulnerabilities:

CVE-2026-68546: Heap out-of-bounds write in RemoteIo when reading from a
malicious remote server (WebReady/Curl builds)
https://github.com/Exiv2/exiv2/security/advisories/GHSA-3695-mjv8-3r52

CVE-2026-68547: Heap out-of-bounds read in RemoteIo when reading
block-aligned remote CRW files
https://github.com/Exiv2/exiv2/security/advisories/GHSA-jcgh-p9v3-pw6j

CVE-2026-49275: Out of bounds read in CrwMap::decodeBasic
https://github.com/Exiv2/exiv2/security/advisories/GHSA-hxph-pv7w-8649

Out-of-bounds write in RemoteIo::mmap
https://github.com/Exiv2/exiv2/security/advisories/GHSA-vg6c-9f6h-4x5q

Out of bounds write in http.cpp
https://github.com/Exiv2/exiv2/security/advisories/GHSA-9v3x-mhg4-wwv2

Infinite loop in QuickTimeVideo::userDataDecoder
https://github.com/Exiv2/exiv2/security/advisories/GHSA-fgw8-p7pr-37cp

For more details, see the announcement:
https://www.openwall.com/lists/oss-security/2026/08/30/1

Notice: the RemoteIo-related vulnerabilities are not applicable for
Buildroot as exiv2 is not built with libcurl support.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-02 21:04:20 +02:00
Romain Naour
79fd6241e4 board/qemu: add xtensa kernel patch
-fno-stack-protector must be passed to avoid linking errors related to
undefined references to '__stack_chk_guard' and '__stack_chk_fail' if
toolchain enforces -fstack-protector.

Fixes:
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15876432953

Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-01 23:58:23 +02:00
Romain Naour
789485b3e7 package/gcc: enable decimal float on s390
Floating-point type _Float16 added in gcc-16 on s390 now requires
decimal floating-point support enabled in the toolchain [1][2].

Without decimal floating-point, gcc 16.2.0 fails to build with:

../../../libgcc/config/s390/_dpd_sd_to_hf.c:27:25: error: decimal floating-point not supported for this target
   27 | HFtype __dpd_truncsdhf (_Decimal32);
      |                         ^~~~~~~~~~
../../../libgcc/config/s390/_dpd_sd_to_hf.c:31:16: error: decimal floating-point not supported for this target
   31 | force_convert (_Decimal32 x)
      |                ^~~~~~~~~~
../../../libgcc/config/s390/_dpd_hf_to_td.c:34:1: error: decimal floating-point not supported for this target
   34 | _Decimal128
      | ^~~~~~~~~~~
../../../libgcc/config/s390/_dpd_sd_to_hf.c:35:18: error: decimal floating-point not supported for this target
   35 | __dpd_truncsdhf (_Decimal32 x)

Enable decimal floating-point support as suggested by Alexander
Egorenkov.

Fixes:
https://lore.kernel.org/buildroot/ansJ5dXXblvYeMLB@windsurf/

[1] https://gcc.gnu.org/gcc-16/changes.html#s390
[2] https://gcc.gnu.org/git/?p=gcc.git;a=commit;h=5d6d56d837c3dbeabd382c1fb4f7d21d9891f4b9

Cc: Alexander Egorenkov <egorenar@linux.ibm.com>
Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-01 23:56:47 +02:00
Sébastien Szymanski
08cc0938b5 package/newt: update _SITE
Old URL returns 404, update _SITE to https://releases.pagure.org/newt

Signed-off-by: Sébastien Szymanski <sebastien.szymanski@armadeus.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-01 23:41:26 +02:00
Romain Naour
32b4f3f942 linux: disable SSP support when needed
x86 and x86_64 kernels >= 6.15 now requires ssp toolchain support
when CONFIG_STACKPROTECTOR is enabled [1].

For toolchains without SSP support, make sure to disable
CONFIG_STACKPROTECTOR to avoid link issues when building kernel
modules.

  MODPOST Module.symvers
  ERROR: modpost: "__stack_chk_guard" [drivers/<module>.ko] undefined!

While the SSP support is mandatory for glibc and musl based toolchains
[2], it's still optional for uClibc-ng based toolchains and not enabled
by default when building a new toolchain.

The Toolchain builder project enabled recently the SSP support for all
uClibc toolchains [3] to avoid such issue.

But x86 (32bits) musl based toolchains lack of SSP support due to a
long term gcc issue [4]. For a decade Alpine Linux, OpenWRT and Yocto
povide additional gcc and musl patches to workaround the gcc issue [5]

We may consider in the long term removing the support for toolchains
without SSP and doing so removing x86 (32bits) musl toolchain.

Fixes:
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832356731 (x86-64--uclibc--bleeding-edge_test)
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832356104 (x86-64--uclibc--stable_test)

https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832355429 (x86-64-core-i7--uclibc--bleeding-edge_test)
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832354341 (x86-64-core-i7--uclibc--stable_test)

https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832326525 (x86-64-v2--uclibc--bleeding-edge_test)
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832316220 (x86-64-v2--uclibc--stable_test)

https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139512 (x86-i686--uclibc--stable_test)
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139511 (x86-i686--uclibc--bleeding-edge_test)

https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139510 (x86-i686--musl--stable_test)
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139509 (x86-i686--musl--bleeding-edge_test)

https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139506 (x86-core2--uclibc--stable_test)
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139505 (x86-core2--uclibc--bleeding-edge_test)

https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139504 (x86-core2--musl--stable_test)
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139503 (x86-core2--musl--bleeding-edge_test)

[1] https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=0ee2689b9374d6fd5f43b703713a53227
[2] e811f51549
[3] 90413f6657
[4] https://www.openwall.com/lists/musl/2016/12/04/2
[5] https://git.alpinelinux.org/aports/tree/main/musl/APKBUILD#n65
    https://git.alpinelinux.org/aports/tree/main/gcc/0018-Alpine-musl-package-provides-libssp_nonshared.a.-We-.patch
    https://github.com/openwrt/openwrt/blob/v25.12.5/toolchain/gcc/patches-15.x/230-musl_libssp.patch
    https://github.com/openwrt/openwrt/blob/v25.12.5/toolchain/musl/patches/200-add_libssp_nonshared.patch
    77fb841f2e

Cc: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-01 23:00:29 +02:00
Romain Naour
45636d67c9 support/testing: TestMdnsd: improve test reliability
The mdnsd runtime test can randomly fail on slow runners.

It's hard to reproduce locally (only one failure after a few attempts)
but we can reproduce it easily by removing the while loop entirely.

It turns out that mdnsd is started by S50mdnsd before the
emulator.login() change the system date:

  [BRTEST# date -s @1788032864
  Sat Aug 29 19:47:44 UTC 2026

Since the minimal rootfs.cpio generated	for TestMdnsd doesn't have any
ntp client installed, it start with "January 1, 1970".

The date change may cause some issue to the mdnsd daemon which blocks
any response from mquery command.

When the problem occurs, "mquery -T _http._tcp" reply is empty:

  # mquery -T _http._tcp
  Querying _http._tcp.local. for PTR (12) ... press Ctrl-C to stop

To workaround the issue, restart mdnsd manually.

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16185948555

Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-01 21:31:01 +02:00
Romain Naour
e56c6b32fd Revert "support/testing: TestMdnsd: improve test reliability"
The issue was reproduced in 2026.08-rc3 Gitlab-CI pipeline [1] despite
the fix applied.

[1] https://gitlab.com/buildroot.org/buildroot/-/jobs/16185948555

This reverts commit b4b1de1f7f.

Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-01 21:31:01 +02:00
Fiona Klute (othermo GmbH)
45acb281ca package/dracut: pass HOST_CONFIGURE_OPTS to make
Dracut-internal executables were linked against system libraries,
instead of Buildroot host packages. For example:

$ ldd host/lib/dracut/dracut-install
	linux-vdso.so.1 (0x00007f578cf06000)
	libc.so.6 => /usr/lib/x86_64-linux-gnu/libc.so.6 (0x00007f578cccd000)
	libkmod.so.2 => /usr/lib/x86_64-linux-gnu/libkmod.so.2 (0x00007f578ccb1000)
	/lib64/ld-linux-x86-64.so.2 (0x00007f578cf08000)
	libcrypto.so.3 => /usr/lib/x86_64-linux-gnu/libcrypto.so.3 (0x00007f578c600000)
	libz.so.1 => /usr/lib/x86_64-linux-gnu/libz.so.1 (0x00007f578cc92000)
	libzstd.so.1 => /usr/lib/x86_64-linux-gnu/libzstd.so.1 (0x00007f578c536000)

The reason is that Dracut is not a "real" autoconf package, and the
hand-written ./configure script does not preserve LDFLAGS for
make. Pass the environment variables directly to fix this.

Signed-off-by: Fiona Klute (othermo GmbH) <fiona.klute@gmx.de>
[Julien: add comment in dracut.mk]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-01 21:14:52 +02:00
Bernd Kuhls
a31afeb8a4 package/ncmpc: fix build with fmt >= 12.2.0
Buildroot commit cc5c36afff bumped fmt to
version 12.2.0 causing build errors with ncmpc which are fixed by adding
an upstream patch.

Fixes:
https://autobuild.buildroot.net/results/b97/b97146ba1b4996b644c564898f5633dd8c0d4b83/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-01 21:07:36 +02:00
Thomas Petazzoni
55a7ece9e5 package/dpdk: make the libvirt dependency explicit
examples/vm_power_manager/meson.build in DPDK detects the presence of
libvirt:

opt_dep = cc.find_library('virt', required : false)

and then builds some examples or not depending on the availability of
libvirt. Let's make this optional dependency explicit in dpdk.mk, even
if there's no explicit enable/disable option for it.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-01 16:10:56 +02:00
Thomas Petazzoni
db3d0d44ac package/dpdk: fix example build issue when libvirt is present
When libvirt is present before DPDK is built, some additional examples
are compiled. One of them fails to build due to a missing <stdlib.h>
include. Let's import a patch from OpenSuse, that we have submitted
upstream, to fix this issue.

We couldn't find any autobuilder failure for this issue, but the
following defconfig allows to reproduce the failure:

BR2_aarch64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
BR2_PACKAGE_DPDK=y
BR2_PACKAGE_DPDK_EXAMPLES=y
BR2_PACKAGE_LIBVIRT=y

The problem exists since DPDK v19.11, so it has been in Buildroot
since DPDK was introduced in commit
d17d1b6bde.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-01 16:10:34 +02:00
Dario Binacchi
0742e67d2f package/drogon: Fix incomplete 'struct tm' type on uClibc
Add a patch including <time.h> in Date.h to fix the following build
failure:

  Date.cc:98:28: error: return type 'struct trantor::tm' is incomplete
     98 | struct tm Date::tmStruct() const
        |                            ^~~~~

Fixes:
- https://autobuild.buildroot.org/results/e48e0fc1b95a8ad5de964b1e6d12bc45ac39f0b4

Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-01 16:09:26 +02:00
Julien Olivain
8dea6e7c08 package/perl: apply perl-cross patch only on target perl
Buildroot commit [1] (package/perl: fix build issue with musl)
introduced a patch that is meant to be applied on top of perl-cross,
which is extracted on top of perl only in the target variant.

Since the patch was introduced as a normal package patch, the Buildroot
infra is trying to always apply it, even for the host package variant.
Since perl-cross is not extracted for the host variant, some patched
files are missing. In that case, the host-perl is failing with error:

    >>> host-perl 5.42.3 Patching
    Applying 0001-configure-keep-_GNU_SOURCE-in-build-flags.patch using patch:
    can't find file to patch at input line 46

This commit fixes the issue by moving the package patch in a dedicated
"perl-cross" subdirectory, to make sure it will no longer be applied by
the infra. We apply the patch only for the target package variant using
a _POST_PATCH_HOOKS hook.

Fixes:
- [1]
- https://gitlab.com/buildroot.org/buildroot/-/jobs/16185948610 (TestPerlXMLLibXML)
- ...and few other tests requiring host-perl

[1] d950fff290

Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-31 22:39:22 +02:00
Thomas Petazzoni
88a4958afa package/libnfs: fix gnutls support
In Buildroot commit a035a0f99f, libnfs
was bumped from 5.0.3 to 6.0.2, and 6.0.2 brought optional gnutls
support.

Unfortunately, the gnutls support was a bit buggy, as the libnfs
library ends up using gnutls symbols without being linked to
libgnutls, causing build failures down the road when other packages
try to link against libnfs.

We backport 3 commits from upstream 6.0.2..7.0.0 to address this
issue.

Fixes:

  https://autobuild.buildroot.net/results/b070248b2bceaceaaed8e826b1247ccfba1ba9fb
  https://autobuild.buildroot.net/results/e1461b76121addd8f04f08819b2e3e453a12c679
  https://autobuild.buildroot.net/results/87c79193d2ea86f47e36232fe514837ad99c5f30

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Tested-by: Andreas Ziegler <br025@umbiko.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-31 22:35:57 +02:00
Bernd Kuhls
3577d1442e package/proftpd: security bump version to 1.3.9d
https://github.com/proftpd/proftpd/blob/v1.3.9d/NEWS

Version 1.3.9b fixes CVE-2026-44331.

Switched to sha256 tarball hash provided by upstream.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-31 21:30:33 +02:00
Jimmy Durand Wesolowski
913512e302 package/openssh: ensure libxcrypt is enabled to provide a crypt() implementation
When OpenSSL is enabled, if DES support is enabled, OpenSSH uses
DES_crypt. However, without OpenSSL or its DES support, there is no
available crypt() implementation for OpenSSH libopenbsd-compat xcrypt()
function, resulting in the following error:

.../host/bin/i686-buildroot-linux-gnu-gcc -o sshd-auth sshd-auth.o
  auth2-methods.o auth-rhosts.o auth-passwd.o sshpty.o sshlogin.o
  servconf.o serverloop.o auth.o auth2.o auth-options.o session.o
  auth2-chall.o groupaccess.o auth-bsdauth.o auth2-hostbased.o
  auth2-kbdint.o auth2-none.o auth2-passwd.o auth2-pubkey.o
  auth2-pubkeyfile.o auth2-gss.o gss-serv.o gss-serv-krb5.o
  monitor_wrap.o auth-krb5.o audit.o audit-bsm.o audit-linux.o
  platform.o loginrec.o auth-pam.o auth-shadow.o auth-sia.o
  sandbox-null.o sandbox-rlimit.o sandbox-darwin.o
  sandbox-seccomp-filter.o sandbox-capsicum.o sandbox-solaris.o
  sftp-server.o sftp-common.o uidswap.o ssh-pkcs11-client.o
  ssh-sk-client.o -L. -Lopenbsd-compat/ -D_LARGEFILE_SOURCE
  -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0
  -D_FORTIFY_SOURCE=1 -Wl,-z,relro -Wl,-z,now -Wl,-z,noexecstack
  -fstack-protector-strong -pie -lssh -lopenbsd-compat
  -L.../host/bin/../i686-buildroot-linux-gnu/sysroot/usr/lib
  -lssl -lcrypto -lcrypto -lz
.../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../
  i686-buildroot-linux-gnu/bin/ld:
  openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt':
xcrypt.c:(.text+0x51): undefined reference to `crypt'
.../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../
  i686-buildroot-linux-gnu/bin/ld:
openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt':
xcrypt.c:(.text+0x51): undefined reference to `crypt' collect2: error:
ld returned 1 exit status make[2]: *** [Makefile:233: sshd-auth] Error
1 make[2]: *** Waiting for unfinished jobs....  collect2: error: ld
returned 1 exit status make[2]: *** [Makefile:230: sshd-session] Error
1 make[1]: *** [package/pkg-generic.mk:273:
.../build/openssh-10.4p1/.stamp_built]
Error 2 make: *** [Makefile:83: _all] Error 2

This commit enables BR2_PACKAGE_LIBXCRYPT with OpenSSH as long as
glibc is used. Since "sshd-auth" is compiled regardless of
BR2_PACKAGE_OPENSSH_SERVER, we need to enable it with BR2_PACKAGE_OPENSSH.

Signed-off-by: Jimmy Durand Wesolowski <jimmy.wesolowski@mobileye.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-31 21:10:23 +02:00
Bernd Kuhls
4c504ef75d package/expat: security bump version to 2.8.4
https://github.com/libexpat/libexpat/blob/R_2_8_4/expat/Changes
https://blog.hartwork.org/posts/expat-2-8-4-released/

Fixes CVE-2026-66046, CVE-2026-76641, CVE-2026-76956 & CVE-2026-76957.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-31 21:08:46 +02:00
Titouan Christophe via buildroot
cb18f3a74a package/vim: fix hash for README.txt
Buildroot commit 297f6f1921 updated vim.
However README.txt (used as part of the license hash check) has been updated
upstream in [1], without any corresponding hash change in Buildroot, leading
to build failure.

Fixes: https://gitlab.com/buildroot.org/buildroot/-/work_items/189

NB: This also affects 2025.02.x & 2026.05.x, so this patch
    should be applied there too.

[1] e7e21018fc

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
2026-08-31 16:31:35 +02:00
Thomas Petazzoni
2eefcb245f docs/website: patchwork is now at patchwork.buildroot.org
patchwork.buildroot.org used to be a redirect to patchwork.ozlabs.org,
but we are now running our own instance, so let's adjust the links in
the website accordingly.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-31 07:59:29 +02:00
Thomas Petazzoni
2d7d9d8200 docs/manual: patchwork is now at patchwork.buildroot.org
patchwork.buildroot.org used to be a redirect to patchwork.ozlabs.org,
but we are now running our own instance, so let's adjust the links in
the manual accordingly.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-31 07:58:52 +02:00
Bernd Kuhls
911dc3a5d2 package/libldns: security bump version to 1.9.2
https://community.nlnetlabs.nl/t/ldns-1-9-1-released/3403
https://community.nlnetlabs.nl/t/ldns-1-9-2-released/3404
"Please do not install ldns version 1.9.1 as it has a wrong .so version.
 Install ldns version 1.9.2 instead."

Fixes CVE-2026-10846.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-30 22:38:46 +02:00
Bernd Kuhls
6bd5918183 package/freeswitch: security bump version to 1.11.3
https://github.com/signalwire/freeswitch/releases/tag/v1.11.3
"This is an important release containing critical security fixes and
 stability improvements. [...] We strongly encourage all users to
 upgrade to v1.11.3 as soon as possible."

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-30 18:53:13 +02:00
Bernd Kuhls
be382f6061 package/{glibc, localedef}: security bump version to 2.44-36-g2d5421ffc
Fixes the following CVEs:

CVE-2026-19499:
63b53df549

CVE-2026-77117:
6f9b2bfa50

CVE-2026-80489:
cb61572ea3

Added GLIBC_IGNORE_CVES for CVE-2026-19542 which was forgotten in
buildroot commit 58f3137738.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-30 18:24:23 +02:00
Alessandro Rubini
e1ec936cf7 package/opencv: fix webp dependency
When BR2_PACKAGE_OPENCV4_WITH_WEBP=y we need to enable mux and demux
support in webp, otherwise the build of OpenCV fails as follows:

    CMake Error: The following variables are used in this project,
         but they are set to NOTFOUND.
    Please set them or make sure they are set and tested correctly
         in the CMake files:
    WEBP_DEMUX_LIBRARY
    linked by target "opencv_imgcodecs"
         in directory [...]/build/opencv4-4.13.0/modules/imgcodecs
    WEBP_MUX_LIBRARY
    linked by target "opencv_imgcodecs"
         in directory [...]/build/opencv4-4.13.0/modules/imgcodecs

The issue already exists in 2025.02.x.

Fixes:

  https://autobuild.buildroot.net/results/d3e0446a87d32469267e241866c4224143170f31/

Signed-off-by: Alessandro Rubini <rubini@gnudd.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:32:51 +02:00
Robert P. J. Day
c529a2c286 docs/manual: post-image.sh/post-build.sh should use '-', not '_'
Even though it's only documentation, the form of the names of the
post-image.sh and post-build.sh scripts should be consistent with the
names of those scripts used in the code base, using hyphen, not
underscore.

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:20:11 +02:00
Robert P. J. Day
dd2fb3de11 docs/manual: minor aesthetic cleanups in "Getting Buildroot"
Minor tweaks including proper capitalization.

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:20:06 +02:00
Robert P. J. Day
59efb9037f docs/manual: update intro, make gender-neutral
Besides just updating a little terminology, remove the awkward
reference to "his" when referring to developers.

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:20:01 +02:00
Alexis Lothoré via buildroot
bd5b267b1d package/openscap: fix build failure with dbus and musl
The openscap build can fail with the following error:

In file included from [...]/src/OVAL/probes/unix/linux/systemdunitproperty_probe.c:38:
[...]/src/OVAL/probes/unix/linux/systemdshared.h: In function ‘get_all_systemd_units’:
[...]/src/OVAL/probes/unix/linux/systemdshared.h:188:50: error: implicit declaration of function ‘basename’; did you mean ‘rename’? [-Wimplicit-function-declaration]
  188 |                 char *unit_name_s = oscap_strdup(basename(value.str));
      |                                                  ^~~~~~~~
      |                                                  rename
In file included from [...]/src/OVAL/probes/unix/linux/systemdunitdependency_probe.c:37:
[...]/src/OVAL/probes/unix/linux/systemdshared.h: In function ‘get_all_systemd_units’:
[...]/src/OVAL/probes/unix/linux/systemdshared.h:188:50: error: implicit declaration of function ‘basename’; did you mean ‘rename’? [-Wimplicit-function-declaration]
  188 |                 char *unit_name_s = oscap_strdup(basename(value.str));
      |                                                  ^~~~~~~~
      |                                                  rename

This error happens when:
- dbus is enabled in the configuration, making openscap build probes
  code
- the toolchain uses musl, which does not declare basename() in string.h
  the way glibc does

The build error can be reproduced with the following minimal defconfig:

  BR2_arm=y
  BR2_cortex_a9=y
  BR2_ARM_ENABLE_NEON=y
  BR2_ARM_ENABLE_VFP=y
  BR2_TOOLCHAIN_EXTERNAL=y
  BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
  BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV7_EABIHF_MUSL_BLEEDING_EDGE=y
  BR2_PACKAGE_DBUS=y
  BR2_PACKAGE_OPENSCAP=y

Backport the upstream fix to allow openscap to build with such
configuration. The custom patch can be removed once openscap is
re-released on its branch 1.3.x.

The issue affects master, 2026.05.x and 2025.02.x

Fixes: https://autobuild.buildroot.org/results/a874d4f34d36fa9f8566be90ad2d5facb99aec24/
Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:13:21 +02:00
Alexis Lothoré via buildroot
5ea2135a56 package/erlang: fix link failure on odbcserver
host-erlang build can fail with the following error:

  make[5]: Nothing to be done for 'opt'.
   MAKE	opt
   CC	../priv/bin/x86_64-pc-linux-gnu/odbcserver
  /usr/bin/ld: ../priv/obj/x86_64-pc-linux-gnu/odbcserver.o: in function `encode_column_dyn':
  odbcserver.c:(.text+0x6b4): undefined reference to `ei_x_encode_tuple_header'
  /usr/bin/ld: odbcserver.c:(.text+0x6c2): undefined reference to `ei_x_encode_tuple_header'
  /usr/bin/ld: odbcserver.c:(.text+0x6d4): undefined reference to `ei_x_encode_ulong'
  /usr/bin/ld: odbcserver.c:(.text+0x6e7): undefined reference to `ei_x_encode_ulong'
  /usr/bin/ld: odbcserver.c:(.text+0x6fa): undefined reference to `ei_x_encode_ulong'
  /usr/bin/ld: odbcserver.c:(.text+0x708): undefined reference to `ei_x_encode_tuple_header'
  /usr/bin/ld: odbcserver.c:(.text+0x71b): undefined reference to `ei_x_encode_ulong'
  /usr/bin/ld: odbcserver.c:(.text+0x72e): undefined reference to `ei_x_encode_ulong'
  [...]

This can be reproduced with the following minimal defconfig (and
libei.so present on host, see details below):

  BR2_x86_64=y
  BR2_TOOLCHAIN_EXTERNAL=y
  BR2_PACKAGE_ERLANG=y

Those missing symbols are part of the erl_interface, exposed by libei.a.
host-erlang builds correctly libei.a _before_ odbcserver.c (it can be
found in lib/erl_interface/obj/x86_64-pc-linux-gnu/libei.a), but the
failure is actually due to the build command generated and used for
odbcserver.c, especially the link arguments:

  /usr/bin/gcc \
  [...]
  -o ../priv/bin/x86_64-pc-linux-gnu/odbcserver \
  ../priv/obj/x86_64-pc-linux-gnu/odbcserver.o \
  -L/usr/lib64 \
  -lodbc \
  -L/home/alexis/src/buildroot/erlang-master/build/host-erlang-custom/lib/erl_interface/obj/x86_64-pc-linux-gnu \
  -lpthread -lei

/usr/lib64 is searched before the path where libei.a has been built, so
if whether a valid libei.a or libei.so is found there, it shadows the
expected libei.a. In the build from which the logs above come, the
notable point is that the host system indeed have a valid libei.so, but
is completely unrelated to erl_interface; it rather exposes the Emulated
Input protocol aimed at Wayland stack; and so it obviously contains none
of the expected ei_* symbols.

Upstream has already identified and fixed the issue, the fix is already
released in versions >= 27.x.y. Erlang 26 (the version currently
packaged in buildroot), isn't supported anymore (only the three latest
releases are supported, see
https://github.com/erlang/otp/blob/master/SECURITY.md), so there won't
be any new minor update that will release this fix.

Pick and backport the fixing patch so that the current version packaged
in buildroot can still build.

Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:09:58 +02:00
Peter Korsgaard
e6b06b8d9c Update for 2026.08-rc3
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-29 21:08:24 +02:00
Neal Frager
dea4bf0eca configs/versal2_vek385_defconfig: remove useless atf console config
The VERSAL2_CONSOLE variable does not actually exist when building the atf
with plat=versal2. So the current VERSAL2_CONSOLE=cadence1 is not actually
doing anything. For this reason, the atf will print on its default console
which is UART0 or pl011_0.

The correct definition would be CONSOLE=pl011_1 in order to build the atf to
print on UART1 or pl011_1.

However, the git repo xparameters.h of the versal2_plm is not currently
enabling UART1 because the XPAR_XUARTPSV_NUM_INSTANCES is set to 1 including
the address defines only for UART0.
97f2baf7f6/lib/sw_apps/versal_plm/misc/versal_2ve_2vm/xparameters.h (L1519)

The problem with this is that the plm is not configuring UART1, so the atf
will crash at boot time, if it is built with CONSOLE=pl011_1 and the plm has
not already enabled UART1.

For now, we will remove the unnecessary config that is doing nothing.  The
versal2_vek385_defconfig is working, but users need to currently open two
console windows to see the boot log because the current config is the
following.

plm - console uart0
asufw - console uart0
atf - console uart0

optee-os - console uart1
u-boot - console uart1
Linux - console uart1

A patch has been submitted to the embeddedsw repo to fix the xparameters.h
file such that the plm will correctly enable UART1. Once this is applied, we
will configure the plm and atf to use UART1 with the versal2_vek385_defconfig.

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-29 21:00:22 +02:00
Bernd Kuhls
7e13318329 {linux, linux-headers}: bump 6.12.x, 6.6.x, 6.1.x, 5.15.x, 5.10.x, 7.1.x, 6.18.x series
Update the latest kernel releases to:
 - 6.12.106 -> 6.12.107
 - 6.6.154 -> 6.6.155
 - 6.1.185 -> 6.1.186
 - 5.15.218 -> 5.15.219
 - 5.10.267 -> 5.10.268
 - 7.1.11 -> 7.1.12
 - 6.18.47 -> 6.18.48

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-29 20:29:30 +02:00
Bernd Kuhls
437a3632ca package/fetchmail: bump version to 6.6.7
https://sourceforge.net/p/fetchmail/mailman/message/59381086/
"Fetchmail 6.6.7 bugfix version has been released"

https://sourceforge.net/p/fetchmail/mailman/message/59350877/
"The 6.6.6 critical bug fix release of fetchmail is available"

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-29 20:25:48 +02:00
Bernd Kuhls
0fe2d74ffd package/libheif: security bump version to 1.23.2
https://github.com/strukturag/libheif/releases/tag/v1.23.2

Fixes the following CVEs:

(CVE numbers will be added upstream when assigned.)

CVE-2026-XXXXX (GHSA-g89c-p67h-r497)
 Heap buffer overflow in scale_nearest_neighbor() via duplicate alpha
 planes from nested iden/auxl items. (critical)

(GHSA-2jg2-4ch7-h545)
 Out-of-bounds read and write in derived-item and pixel-plane handling.
 Through iden and auxl item chains, a crafted file could attach pixel
 planes whose size differs from the image geometry; crop, scale, and
 plane-extraction code then indexed those planes with the wrong size.
 A working code-execution exploit was confirmed. Plane sizes are now
 validated wherever they are consumed. (critical)

CVE-2026-XXXXX (GHSA-24wx-9w62-c96w)
 brotli/zlib decompression of mime metadata and unci image data had no
 effective output-size limit, so a decompression bomb could exhaust
 memory. Decompressed output is now bounded by the security limits.
 (high)

CVE-2026-XXXXX (GHSA-x8xm-cm2c-cfc8)
 Chains of derived-image references (grid, iovl, iden) bypassed decode
 caching and memory limits, causing CPU and memory amplification. (high)

CVE-2026-XXXXX (GHSA-xw34-mjcp-jqh8)
 Sequence sample-timing initialization could produce non-terminating
 decode loops and unbounded memory, bypassing max_sequence_frames.
 (high)

CVE-2026-XXXXX (GHSA-j264-xvrp-5v7q)
 Out-of-bounds write in the unci encoder when
 heif_context_add_image_tile() is given a tile whose planes do not match
 its declared size. (high)

CVE-2026-XXXXX (GHSA-p58j-h3vm-3fp5)
 Heap out-of-bounds read in the inline-mask region API when
 mask_data_len does not match the region geometry. (medium)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-29 20:24:48 +02:00
Thomas Petazzoni
83fc4aa55e package/collectd: fix build of virt plugin
Since the bump of libxml2 from 2.13.8 to 2.15.0 in Buildroot commit
d81922c1ef, the "virt" plugin of
collectd no longer builds:

src/virt.c:2208:49: error: expected ';', ',' or ')' before 'ATTRIBUTE_UNUSED'
 2208 | static void virt_eventloop_timeout_cb(int timer ATTRIBUTE_UNUSED,
      |                                                 ^~~~~~~~~~~~~~~~
src/virt.c: In function 'register_event_impl':
src/virt.c:2221:26: error: 'virt_eventloop_timeout_cb' undeclared (first use in this function)
 2221 |                          virt_eventloop_timeout_cb, NULL, NULL) < 0) {
      |                          ^~~~~~~~~~~~~~~~~~~~~~~~~
src/virt.c:2221:26: note: each undeclared identifier is reported only once for each function it appears in

This is due to the fact that the virt plugin code was incorrectly
using the ATTRIBUTE_UNUSED define, which was supposed to be an
internal define of libxml2. But it turns out that up to libxml2 2.14.0
and its commit 208f27f9641a59863ce1f7d4992df77f7eb0ea9d, this define
had been made publicly available. It could therefore mistakenly be
used by collectd's virt plugin... until libxml2 was upgraded.

We backport an upstream patch from collectd that fixes the issue.

Fixes:

  https://autobuild.buildroot.net/results/4c8463f0372560f4c3a20b0f67854460f0d1c400/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-28 13:28:47 +02:00
Thomas Petazzoni
e06cfae9cb support/testing: add bpftrace test
This commit adds a simple bpftrace test that ensures that not only it
builds fine, but it also runs properly on a minimal test scenario.

Assisted-by: GPT-5.6
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
[Julien:
 - reindent emulator.boot() options
 - add a call to "bpftrace --version"
]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-28 11:47:12 +02:00
Thomas Petazzoni
cc25888c88 package/bpftrace: bump to version 0.26.1 to fix build with LLVM 22
Since Buildroot commit 25cb3813e7 which
bumped LLVM from 21.x to 22.x, the build of bpftrace is broken as
bpftrace 0.24.2 only supports LLVM up to 21.

We tried backporting the bpftrace patch that allows using LLVM up to
version 22 but the patch didn't apply cleanly but more importantly it
wasn't clear if this patch was sufficient. Therefore, we opt for
bumping bpftrace entirely to fix the issue.

Packaging changes:

- The new version of bpftrace no longer needs host-bison/host-flex,
  because bpftrace is now using a handwritten parser.

- Pass -DUSE_SYSTEM_LIBBPF:BOOL=ON to ensure the system libbpf version
  is used, and not the bundled version

- Now depends on kernel headers >= 5.10 because it needs CAP_BPF and
  CAP_PERFMON

Upstream changelog:
https://github.com/bpftrace/bpftrace/blob/v0.26.1/CHANGELOG.md

Fixes:

  https://autobuild.buildroot.net/results/a3e3fd696685864977c688aa11c2653357cf6207/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
[Julien: add link to upstream changelog]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-28 11:47:12 +02:00
Thomas Petazzoni
e9c540ddd2 package/libbpf: update UAPI header installation work-around
bpftrace often needs very recent kernel headers, more recent than the
runtime version actually needed. We already had a workaround in
libbpf making sure that if the kernel headers are older than 6.1, we
would install the libbpf provided headers instead.

As we are about to update bpftrace to a newer version that uses
BPF_TRACE_KPROBE_SESSION, which was introduced in Linux 6.10, we need
to update this workaround accordingly and ensure that the libbpf
header is installed if the kernel headers are older than 6.10.

This is necessary for the update of bpftrace to 0.26.1.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-28 11:47:12 +02:00
Thomas Petazzoni
a51521cbe6 package/fluidsynth: fix download-while-configure since 2.5.7 bump
Since commit
566bdcb97f ("package/fluidsynth:
security bump to version 2.5.7"), fluidsynth tries to download some
"gcem" code during its configure step, which not only violates
Buildroot's policies, but also breaks the build if network is not
available during the build.

To fix this, we add an EXTRA_DOWNLOADS to grab gcem and extract it at
the right place. Some minor fix (submitted upstream) is needed to
ensure the FindGCEM.cmake logic properly finds that gcem is already in
the source tree.

Fixes:

  https://autobuild.buildroot.net/results/048df28f6ab97a16731e62d7f56c6eba565cda63/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-28 11:10:48 +02:00
Bernd Kuhls
6561717f18 package/php: bump version to 8.5.10
https://news-web.php.net/php.announce/504
"This is a bugfix release."

https://www.php.net/ChangeLog-8.php#8.5.10
https://github.com/php/php-src/blob/php-8.5.10/NEWS

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-28 10:47:57 +02:00
Peter Korsgaard
211cfafa16 support/testing: add haproxy test
Based on the lighttpd test case.  Verify that we can download index.html
from haproxy in front of lighttpd.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 23:01:15 +02:00
Peter Korsgaard
94aa7f40b5 package/haproxy: needs signed overflow handling
haproxy has a runtime test to verify that it is built with -fwrapv:

haproxy
FATAL ERROR: invalid code detected -- cannot go further, please recompile!
The source code was miscompiled by the compiler, which usually indicates that
some of the CFLAGS needed to work around overzealous compiler optimizations
were overwritten at build time. Please do not force CFLAGS, and read Makefile
and INSTALL files to decide on the best way to pass your local build options.

Build options :
  TARGET  = custom
  CPU     = generic
  CC      = /home/peko/source/buildroot/output-haproxy/host/bin/arm-linux-gcc
  CFLAGS  = -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0 -D_FORTIFY_SOURCE=1 -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0 -D_FORTIFY_SOURCE=1
  OPTIONS = USE_THREAD=1 USE_DL=1
  DEBUG   = -DDEBUG_STRICT -DDEBUG_MEMORY_POOLS

Which comes from:
https://github.com/haproxy/haproxy/blob/v2.6.0/src/haproxy.c#L3008-L3037

So build it with -fwrapv to fix that.

Notice that this message also embeds the build path (through CC), breaking
reproducible builds.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 23:01:15 +02:00
Bernd Kuhls
e1ba84b9a7 {linux, linux-headers}: bump 6.12.x, 6.6.x, 6.1.x, 5.15.x, 5.10.x, 7.1.x, 6.18.x series
Update the latest kernel releases to:
 - 6.12.105 -> 6.12.106
 - 6.6.153 -> 6.6.154
 - 6.1.184 -> 6.1.185
 - 5.15.217 -> 5.15.218
 - 5.10.266 -> 5.10.267
 - 7.1.10 -> 7.1.11
 - 6.18.46 -> 6.18.47

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 22:50:38 +02:00
Julien Olivain
6eaa34ecdf support/testing: wpa_supplicant: new runtime test
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 22:49:34 +02:00
Julien Olivain
4e62ac3a21 support/testing: quickjs: new runtime test
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 22:49:26 +02:00
Julien Olivain
bd4ac802e4 support/testing: fs: new cramfs runtime test
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 22:49:20 +02:00
Thomas Petazzoni
79554a4520 package/mesa3d: fix build issue with gcc < 13
Since upstream commit
e42e3193137d1b21e84b499336e7a8887b8a8689 ("intel: add Jay"), a C23
construct is used in the intel driver code:

enum jay_predication : uint8_t

This causes a build issue with GCC < 13:

In file included from ../src/intel/compiler/jay/jay_builder.h:12,
                 from ../src/intel/compiler/jay/jay_from_nir.c:23:
../src/intel/compiler/jay/jay_ir.h:582:22: error: expected identifier or ‘(’ before ‘:’ token
  582 | enum jay_predication : uint8_t {
      |                      ^
../src/intel/compiler/jay/jay_ir.h:637:25: error: field ‘predication’ has incomplete type
  637 |    enum jay_predication predication;
      |                         ^~~~~~~~~~~

We fix that by integrating a patch already available in
OpenEmbedded. It changes the code to not use the C23 construct.

This build issue was encountered on host-mesa3d while building an
allyespackageconfig configuration inside our standard Docker
container.

Buildroot commit
c073c97617 ("package/{mesa3d,
mesa3d-headers}: bump version to 26.1.0") that switched to mesa3d
26.1.0, which contains the problematic commit. Therefore 2026.05 is
affected, but not earlier Buildroot versions.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 22:42:55 +02:00
Thomas Petazzoni
34473e672b package/olsr: fix build with GCC >= 15
This commit introduces a patch, submitted upstream, that fixes the
build of OLSR with GCC >= 15.

Fixes:

  https://autobuild.buildroot.net/results/650edf74dec513ad540f80f4d3ef8c8222dfd711/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 22:40:08 +02:00
Thomas Petazzoni
d950fff290 package/perl: fix build issue with musl
perl does not build with musl due to memrchr() being unavailable. This
is caused by a perl-cross bug, which does function availability
detection with _GNU_SOURCE defined, but then does the build without
_GNU_SOURCE defined. At least OpenEmbedded and NixOS have faced the
same issue, and worked it around in slightly different ways.

On our side, we create a patch, which was submitted upstream, to solve
the issue.

This issue has been introduced in perl-cross commit b40c560f5d5e,
which was first merged in perl-cross release 1.4.1. From a Buildroot
perspective, we bumped from perl-cross 1.4 to 1.4.1 in commit
8a289667f5, which was merged
2023.05. And indeed the build failure can be reproduced even on our
LTS 2025.02.x, so the fix needs to be backported there.

It should be noted that even if the patch is against perl-cross, we
add it to package/perl/ directly, as patches in perl are applied after
perl has been extracted *and* perl-cross has been extracted on top.

Fixes:

  https://autobuild.buildroot.net/results/3e47ade0963642988fd8e1be9a6e8042700619ec/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 22:29:08 +02:00
Thomas Petazzoni
7538f675d7 package/bind: fix build with old host GCC since autoconf bump
Since the bump of autoconf to version 2.73 in Buildroot commit, the
build of target bind fails if the host compiler is too old, because
the bind build system tries to use -std=gnu23 when building host tools
which isn't supported by older GCC releases, causing:

checking whether the C compiler works... no
configure: error: in '/home/thomas/autobuild/instance-2/output-1/build/bind-9.20.26':
configure: error: C compiler cannot create executables
See 'config.log' for more details
make: *** [package/pkg-generic.mk:263: /home/thomas/autobuild/instance-2/output-1/build/bind-9.20.26/.stamp_configured] Error 77

To fix this, we backport a number of patches from autoconf-archive, to
fix the m4/ax_prog_cc_for_build.m4 macro file, so that it works with
autoconf 2.73.

OpenEmbedded has a similar fix:
https://git.openembedded.org/openembedded-core/tree/meta/recipes-connectivity/bind/bind/0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch
but did not backport as carefully the autoconf-archive commits (and
their commit message reverts to sudo).

The patches can be dropped when we update to a newer version of bind
that itself has an updated copy of the m4/ax_prog_cc_for_build.m4
file.

Fixes:

  https://autobuild.buildroot.net/results/13e07755101b7cae2f84eef173ef752f92842e71/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 22:23:42 +02:00
Romain Naour
240ea08d3f package/qt6: fix c++ static_assert issue
Since the last qt6 version bump to 6.11.1 [1], the TestQuazipQt6 fail to
build due to a c++ static_assert issue.

Backport a patch from v6.11.2 release.

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060153667 (TestQuazipQt6)

[1] 05cd38635a

Signed-off-by: Romain Naour <romain.naour@smile.fr>
[Julien: fix link to qt6 version bump commit]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 21:28:45 +02:00
Thomas Petazzoni
50a1dd2676 package/qt6/qt6declarative: fix select of host-qt6base network
The BR2_PACKAGE_QT6DECLARATIVE_QUICK option has some logic to select
network support in host-qt6base if network support is enabled in
qt6base. However, it turns out that this is actually required at the
top level BR2_PACKAGE_QT6DECLARATIVE option: as soon as network
support is available in qt6base, the qt6declarative build will assume
that qmlprofiler is available... but that requires network support in
host-qt6base.

This fixes the following build failure:

CMake Error at /home/thomas/autobuild/instance-2/output-1/build/qt6base-6.9.1/cmake/QtToolHelpers.cmake:784 (message):
  Failed to find the host tool "Qt6::qmlprofiler".  It is part of the
  Qt6QmlTools package, but the package did not contain the tool.  Make sure
  that the host module Qml was built with all features enabled (no explicitly
  disabled tools).
Call Stack (most recent call first):
  /home/thomas/autobuild/instance-2/output-1/build/qt6base-6.9.1/cmake/QtToolHelpers.cmake:83 (qt_internal_find_tool)
  tools/qmlprofiler/CMakeLists.txt:11 (qt_internal_add_tool)

Fixes:

  https://autobuild.buildroot.net/results/72c956fdf982382d2981c649c456d1edc2c9d6b2/

We did not trace back exactly since when the problem exists, but we
verified that the problem exists in 2025.02.x. It can be reproduced
with the following defconfig:

BR2_aarch64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_PACKAGE_QT6=y
BR2_PACKAGE_QT6BASE_NETWORK=y
BR2_PACKAGE_QT6DECLARATIVE=y

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 19:55:57 +02:00
Thomas Petazzoni
29add67666 package/qt6/qt6declarative: move comment where it belongs
The commit "Enable host test module to ensure that qmltestrunner is
built" in qt6declarative's Config.in feels lonely under
BR2_PACKAGE_QT6DECLARATIVE. It's because it's actually related to a
select done in the sub-option BR2_PACKAGE_QT6DECLARATIVE_QUICK, so
move it there.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 19:55:57 +02:00
Romain Naour
b4949ce4c9 package/python-gobject: bump to 3.56
This version bump is required following the glib security version bump
to 2.88.3 [1] to fix a runtime issue due to GLib-2.0 backward
compatibility removal [2].

We prefer updating python-gobject to 3.56 stable release instead of
backporting complex commits from 3.55.x unstable release [3].

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152329 (TestFirewalldSysVInit)
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152332 (TestFirewalldSystemd)

[1] e313a2d259
[2] e02603d44d
[3] 74e4e0f40a

Runtime tested with TestGst1Python and TestFirewalld{Systemd,SysVInit}.

Cc: Fiona Klute <fiona.klute@gmx.de>
Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 19:55:18 +02:00
Romain Naour
803cac2271 support/testing: TestFirewalld{Systemd, SysVInit}: fix expected ouput
Since Firewalld v2.4.3 [1] firewall-cmd added a new log line while
waiting for dbus connection [2].

  [BRTEST# firewall-cmd --state
  Waiting on dbus connection...
  running

The line "Waiting on dbus connection..." is not always printed by
firewall-cmd, so we have to search explicitely for the expected
string to get a reproducible test result.

Update both TestFirewalld accordingly.

This change is required to fix:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152329 (TestFirewalldSysVInit)
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152332 (TestFirewalldSystemd)

[1] 380dd8a348
[2] 5e1c37c966

Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 19:55:18 +02:00
Romain Naour
3bd3d5004d support/testing: TestPythonPy3Gobject: test glib 2.88 regression
In Glib >= 2.88, GLib.unix_signal_add has been moved to a separate
platform-specific library. This break backward compatibility from
GLib-2.0. A workaround has been applied to pygobject >= 3.55.3
74e4e0f40a

This issue currently break TestFirewalldSysVInit and
TestFirewalldSystemd runtime tests since the bump to glib 2.88.3 [1]:

https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152329 (TestFirewalldSysVInit)
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152332 (TestFirewalldSystemd)

Break the test TestPythonPy3Gobject now in order to reproduce the same
issue than for Firewalld test.

[1] e313a2d259

Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 19:55:18 +02:00
Romain Naour
b4b1de1f7f support/testing: TestMdnsd: improve test reliability
The mdnsd runtime test can randomly fail on slow runners.

It's hard to reproduce locally (only one failure after a few attempts)
but we can reproduce it easily by removing the while loop entirely.

It means that the "sleep 1" is not used on the Gitlab runner.
The timestamp of the failed job seems to confirm that [1].

07:06:55    [BRTEST# while ! ifconfig eth0 | grep -q 'inet addr'; do sleep 1; done
07:06:55    [BRTEST# echo $?
07:06:55    0
07:06:55    [BRTEST# mquery -T _http._tcp |grep -F buildroot._http._tcp.local
07:06:55    [BRTEST# echo $?
07:06:55    1

So wait a bit for mdnsd to be ready.

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152862

Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 23:49:49 +02:00
Julien Olivain
23fd881bdb support/testing: php: fix test by switching to "Debian" filesystem layout
Buildroot commit [1] (package/apache: use "Debian" filesystem
layout to fix read-only rootfs) changed the filesystem layout.
This had the effect of installing files to different locations
and breaking the test_php runtime test.

This commit fixes the issue by updating the file paths to their
right locations. The "httpd.conf" was updated by following the
same recipe described in the comment (starting from a config
file as installed by the apache Buildroot package).

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152979

[1] 1006666f67

Signed-off-by: Julien Olivain <ju.o@free.fr>
Tested-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 23:47:56 +02:00
Thomas Petazzoni
d21a1ac886 package/flex: fix build with old host GCC since autoconf bump
Since the bump of autoconf to version 2.73 in Buildroot commit [1], the
build of target flex fails if the host compiler is too old, because
the flex build system tries to use -std=gnu23 which isn't supported by
older GCC releases, causing:

gcc: error: unrecognized command-line option '-std=gnu23'; did you mean '-std=gnu2x'?
gcc: error: unrecognized command-line option '-std=gnu23'; did you mean '-std=gnu2x'?
make[3]: *** [Makefile:1162: stage1flex-buf.o] Error 1

(Indeed the *target* flex package does build some host tools using the
host GCC compiler.)

To fix this issue, we backport an upstream commit that isn't yet in
any flex release.

Fixes:

  https://autobuild.buildroot.net/results/aac730b57adb5b54964f1054de781750952ef7d4/

[1] a6e8c07a33

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
[Julien: add link to commit]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 23:44:29 +02:00
Thomas Petazzoni
f57da3c953 package/dahdi-linux: backport commits to fix build with recent kernels
Fixes build with kernels >= 6.15.

Fixes:

  https://autobuild.buildroot.net/results/ed73aa844a18cfc15e942ced4ae363c3d0d09015/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 23:06:42 +02:00
Thomas Petazzoni
d8dde961bc package/bind: fix thread dependency
In commit 54f96add94 ("package/bind:
security bump version to 9.20.24") the depends on
BR2_TOOLCHAIN_HAS_THREADS_NPTL was incorrectly downgraded to
BR2_TOOLCHAIN_HAS_THREADS:

-       depends on BR2_TOOLCHAIN_HAS_THREADS_NPTL # libuv
+       depends on BR2_TOOLCHAIN_HAS_THREADS # liburcu, libuv

This is wrong because libuv depends on
BR2_TOOLCHAIN_HAS_THREADS_NPTL. This causes unmet dependencies:

WARNING: unmet direct dependencies detected for BR2_PACKAGE_LIBUV
  Depends on [n]: BR2_TOOLCHAIN_HAS_THREADS_NPTL [=n] && BR2_USE_MMU [=y] && !BR2_STATIC_LIBS [=n] && BR2_TOOLCHAIN_HAS_SYNC_4 [=y] && BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 [=y]
  Selected by [y]:
  - BR2_PACKAGE_BIND [=y] && BR2_USE_MMU [=y] && BR2_TOOLCHAIN_HAS_SYNC_4 [=y] && BR2_TOOLCHAIN_HAS_THREADS [=y] && BR2_INSTALL_LIBSTDCPP [=y] && !BR2_STATIC_LIBS [=n] && BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 [=y] && BR2_PACKAGE_LIBURCU_ARCH_SUPPORTS [=y]

Fix that by switching back to the BR2_TOOLCHAIN_HAS_THREADS_NPTL
dependency.

Fixes: 54f96add94 ("package/bind: security bump version to 9.20.24")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 22:58:39 +02:00
Thomas Perale
52ae04257a package/rsyslog: upstream patch CVE-2026-19654
- CVE-2026-19654:
    A unauthenticated remote peer may lead rsyslogd to crash due to a flaw
    in the optional imptcp module. A crafted input sequence during
    oversize-frame recovery can cause an invalid internal message length
    and terminate rsyslogd. No confidentiality or integrity impact,
    privilege escalation, or code execution has been identified. imtcp and
    the default imptcp framing modes are not affected.

For more information, see:
  - https://www.cve.org/CVERecord?id=CVE-2026-19654
  - 07b3c40a5a

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 22:51:41 +02:00
Thomas Perale
d0619dfc6b package/unbound: security bump to v1.25.2
See the changelog:

- https://nlnetlabs.nl/projects/unbound/download/#unbound-1-25-2

It fixes the following vulnerabilities:

- CVE-2026-14586: Assertion in libngtcp2 when under pressure in high
  concurrency DNS-over-QUIC environments.
- CVE-2026-32665: Remote DNS-over-QUIC denial of service due to
  `quic-size` budget bypass.
- CVE-2026-40691: Packet of death for DNSCrypt over TCP.
- CVE-2026-41637 Degradation of resolution service from improperly
  accounted client-terminated DNS-over-QUIC queries.
- CVE-2026-42955: Extra fix for CVE-2026-40622 to also clamp the TTL of
  A/AAAA records disallowing a one-time 'ghost domain' delegation
  renewal via glue records.
- CVE-2026-44621: Libunbound applications configured with
  'unwanted-reply-threshold' could eventually be abruptly terminated.
- CVE-2026-44687: Off-by-one error in 'harden-below-nxdomain' logic can
  shadow a stub/forward zone by a legitimate parent's NXDOMAIN.
- CVE-2026-44690: Cross-zone wildcard cache poisoning via RRSIG.labels
  manipulation.
- CVE-2026-46582: A wildcard replay, as another piece of data, triggers
  poisoning in the serve expired reply path.
- CVE-2026-50045: 'max-global-quota' reset by DNSSEC validation
  restarts.
- CVE-2026-50046: Possible heap use-after-free in an error path when a
  DoT forwarded query is jostled out.
- CVE-2026-50243: 'response-ip'/'rpz' can rewrite BOGUS answers instead
  of returning SERVFAIL.
- CVE-2026-50248: BOGUS configured primary hostname accepted for XFR in
  auth/rpz zones.
- CVE-2026-50251: Attacker supplied `0.0.0.0`/`::` glue triggers
  defensive full-cache flush.
- CVE-2026-50252: Possible cache poisoning attack by mapping source port
  population per thread.
- CVE-2026-52863: Memory corruption could lead to crash and denial of
  service.
- CVE-2026-54478: DNS Cookie bypass when combined with proxy-protocol
  use.
- CVE-2026-55708: Privacy/configuration issue when adding local data in
  views through 'unbound-control'.
- CVE-2026-55717: 'serve-expired-client-timeout' and 'response-ip' CNAME
  redirect could lead to a crash.
- CVE-2026-55973: 'dns-error-reporting: yes' leads to stack buffer
  overflow.
- CVE-2026-55990: Packet of death for a DNSCrypt misconfigured Unbound.
- CVE-2026-55991: Remote DNS-over-QUIC (DoQ) flow-control assertion
  failure in libngtcp2.
- CVE-2026-56416: Possible heap buffer overflow when validator
  canonicalizes RDATA that contains domain name.
- CVE-2026-56444: Degradation of resolution service when
  'discard-timeout' and 'serve-expired-client-timeout' are combined in
  unusual configuration.

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 22:44:23 +02:00
Titouan Christophe
02d8a41f09 package/{avro-c, python-avro}: security bump to v1.12.2
This release includes a broad round of hardening against malformed and
adversarial input across the Python SDK (bounding allocations and enforcing
decompression limits before trusting size fields read from the input).

See the release notes https://avro.apache.org/blog/2026/08/12/avro-1.12.2/

Also update the download url, because www-eu.apache.org/dist/...
is a redirection to downloads.apache.org/...

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 22:35:24 +02:00
Thomas Perale
6f5d678c37 package/nodejs: security bump to v22.23.2
See the release notes:

- https://github.com/nodejs/node/releases/tag/v22.23.2
- https://github.com/nodejs/node/releases/tag/v22.23.1
- https://github.com/nodejs/node/releases/tag/v22.22.1
- https://github.com/nodejs/node/releases/tag/v22.22.2
- https://github.com/nodejs/node/releases/tag/v22.22.3

It fixes the following vulnerabilities:

- (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High
- (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
- (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
- (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
- (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
- (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
- (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
- (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
- (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
- (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low

The LICENSE was changed in 22.22.1, see [1].

[1] 9cafec084e

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 20:37:40 +02:00
Bernd Kuhls
198317785a package/libopenssl: security bump to version 3.6.4
https://github.com/openssl/openssl/releases/tag/openssl-3.6.4

This release incorporates the following bug fixes and mitigations:

Fixed QUIC server being able to trigger double free when processing
INITIAL packet.
(CVE-2026-18798)

Fixed heap buffer overflow in CMS key unwrapping.
(CVE-2026-63072)

Fixed invalid pointer dereference in CMP server via crafted protectionAlg.
(CVE-2026-63076)

Fixed unbounded memory growth in QUIC server incoming channel queue.
(CVE-2026-14456)

Fixed RPK server signature algorithm selection being able to dereference
a missing certificate.
(CVE-2026-14457)

Fixed excessive memory use buffering DTLS records for a future epoch.
(CVE-2026-54874)

Fixed client-side memory leak in OCSP response checking.
(CVE-2026-54876)

Fixed untrusted Sender DN being used as a format string in CMP response
validation.
(CVE-2026-63073)

Fixed CMP indefinite cache growth of extraCerts.
(CVE-2026-63074)

Fixed QUIC ACK-only packet retention being able to cause memory exhaustion.
(CVE-2026-63075)

Fixed possibility of AEAD forgeries with empty ciphertext when using
EVP_Cipher().
(CVE-2026-75803)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-25 22:48:38 +02:00
Waldemar Brodkorb
7906653200 package/uclibc: fix m68000 toolchain builds
Add a patch from Upstream to fix building of a m68000
toolchain.

Fixes:
 - https://autobuild.buildroot.net/results/4cc/4cc0de3d33339bd50792ca224f10dfd18a636b00/

Signed-off-by: Waldemar Brodkorb <wbx@openadk.org>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-25 22:11:11 +02:00
Waldemar Brodkorb
e1a9ff1d67 package/uclibc: fix for gcc libquadmath conflict
As seen in the Buildroot autobuilders, struct rm_ctx should
not be exposed in the public fenv.h header.

Fixes:
 - https://autobuild.buildroot.net/results/761/7613538e0847a10eb3e2a7e40f3ae76386ac015b/

Signed-off-by: Waldemar Brodkorb <wbx@openadk.org>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-25 22:11:11 +02:00
Thomas Devoogdt
c22fc74f2b package/expat: fix no high quality entropy warning on Linux <3.17 or glibc <2.25
In some situations (old Linux <3.17 or glibc <2.25), expat fail at
compilation time with the error:

xmlparse.c:150:4: error: #error You do not have support for any sources of high quality entropy enabled.
For end user security, that is probably not what you want. Your options include:
  * Linux >=3.17 + glibc >=2.25 (getrandom): HAVE_GETRANDOM,
  * Linux >=3.17 + glibc (including <2.25) (syscall SYS_getrandom): HAVE_SYSCALL_GETRANDOM,
  * BSD / macOS >=10.7 / glibc >=2.36 (arc4random_buf): HAVE_ARC4RANDOM_BUF,
  * BSD / macOS (including <10.7) / glibc >=2.36 (arc4random): HAVE_ARC4RANDOM,
  * BSD / macOS >=10.12 / glibc >=2.25 (getentropy): HAVE_GETENTROPY,
  * Linux (including <3.17) / BSD / macOS (including <10.7) / Solaris >=8 (/dev/urandom): XML_DEV_URANDOM,
  * Windows >=Vista (rand_s): _WIN32.
If you insist on not using any of these, bypass this error by defining XML_POOR_ENTROPY and be vulnerable to hash flooding;
you have been warned. If you have reasons to patch this detection code away or need changes to the build system, please open a bug. Thank you!

This is caused by the upstream commit [1] "Autotools: Stop using
/dev/urandom by default", first included in expat 2.8.2. The
Buildroot expat package was bumped to that version in commit [2].

But since all Linux systems have /dev/urandom, we can just enable
it by default.

Note: this commit does not globally switch the entropy source to
/dev/urandom. It is rather enabling it in the list of available
sources. On more recent Linux systems (linux >= 3.17, glibc >= 2.25),
other sources will be chosen. The entropy source preference order
amongst the enabled sources is defined in [3].

This commit also changes the _CONF_OPTS to multiline layout to fit
within the 80 characters.

[1] d30eca113a
[2] 6b1f6f7a48
[3] https://github.com/libexpat/libexpat/blob/R_2_8_3/expat/lib/xmlparse.c#L1115-L1142

Signed-off-by: Thomas Devoogdt <thomas.devoogdt@barco.com>
[Julien: add extra info in the commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-25 21:57:53 +02:00
Thomas Petazzoni
9dc567aa78 package/gdb: handle xxhash optional dependency
Since gdb 9.x, gdb can optionally use the xxhash library. Since we
currently don't do anything about it, it's a potential "silent"
dependency.

In particular, for host-gdb, this means host-gdb might end up being
linked with the system-provided xxhash library if available.

This patch handles this dependency:

- For the target package, by looking at the value of
  BR2_PACKAGE_XXHASH

- For the host package, by looking at the value of a newly introduced
  BR2_PACKAGE_HOST_GDB_XXHASH

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-25 13:52:49 +02:00
Thomas Petazzoni
c3adba81d1 package/gdb: handle lzma option for host-gdb
For target gdb, we properly enable/disable lzma support depending on
BR2_PACKAGE_XZ.

However, for host-gdb we don't do anything, which can lead the gdb
configure script to detect and use a system-provided xz library, which
is not desired.

Instead, add an explicit option BR2_PACKAGE_HOST_GDB_LZMA, which when
enabled pulls in host-xz, but also when disabled ensures gdb doesn't
try to use a system-provided xz library.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-25 13:48:11 +02:00
Neal Frager
a7072372c6 configs/versal2_vek385_defconfig: config atf to load optee-os
Add the option to configure the atf to load the optee-os binary:
BR2_TARGET_ARM_TRUSTED_FIRMWARE_BL32_OPTEE=y

Without this, everything was still booting, and even though the versal2_plm
was loading the optee-os to its runtime location, it was never actually
loaded by the atf.

With this option enabled, atf is now properly loading optee with the boot log
below.

NOTICE:  BL31: Executing from 0xbbf00000
NOTICE:  BL31: Secure code at 0x1800000
NOTICE:  BL31: Non secure code at 0x40000000
NOTICE:  BL31: v2.14.0(release):custom
NOTICE:  BL31: Built : 08:41:36, Aug 25 2026
KATs execution completed.
In task dispatch loop
I/TC:
I/TC: Non-secure external DT found
I/TC: pl011: device parameters ignored (115200n8)
I/TC: Switching console to device: /axi/serial@f1930000
I/TC: OP-TEE version: Unknown_4.9 (gcc version 14.3.0 (Buildroot 2021.11-18033-g83947c7bb6)) #1 Mon Aug 24 08:45:53 UTC 2026 aarch64
I/TC: WARNING: This OP-TEE configuration might be insecure!
I/TC: WARNING: Please check https://optee.readthedocs.io/en/latest/architecture/porting_guidelines.html
I/TC: Primary CPU initializing
I/TC: Cluster shift early-configured: 1 (cores per cluster: 2)
I/TC: ASU initialization complete
I/TC: OP-TEE OS Running on Platform AMD Versal Gen 2
I/TC: ASU ECC: NIST_P192=SW NIST_P224=SW NIST_P256=HW
I/TC: ASU ECC: NIST_P384=SW NIST_P521=SW
I/TC: ASU RSA driver successfully initialized
I/TC: Primary CPU switching to normal world boot

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-25 10:49:36 +02:00
Thomas Petazzoni
06426297c4 toolchain/Config.in: refine BR2_TOOLCHAIN_HAS_LIBQUADMATH definition
In commit a2380157f6 ("toolchain: enable
libquadmath for PowerPC with VSX"), the definition of
BR2_TOOLCHAIN_HAS_LIBQUADMATH has been extended to also be true when
BR2_POWERPC_CPU_HAS_VSX.

However, practical experiments show that when 64-bit VSX-capable cores
are used in 32-bit mode, libquadmath is not built by GCC, causing
build failures:

cp: cannot stat '/home/autobuild/autobuild/instance-3/output-1/host/powerpc-buildroot-linux-musl/lib*/libquadmath*': No such file or directory

We did an extensive testing, building the 27 combinations of:

- GCC versions: 14, 15, 16
- C library: glibc, uclibc, musl
- PowerPC 32-bit, PowerPC 64-bit, PowerPC 64-bit little endian

This testing provides the following results:

|      gcc14 |       powerpc64 |      glibc |         OK |
|      gcc14 |     powerpc64le |      glibc |         OK |
|      gcc14 |     powerpc64le |       musl |         OK |
|      gcc14 |     powerpc64le |     uclibc |    SKIPPED |
|      gcc14 |       powerpc64 |       musl |         OK |
|      gcc14 |       powerpc64 |     uclibc |    SKIPPED |
|      gcc14 |         powerpc |      glibc |     FAILED |
|      gcc14 |         powerpc |       musl |     FAILED |
|      gcc14 |         powerpc |     uclibc |     FAILED |
|      gcc15 |       powerpc64 |      glibc |         OK |
|      gcc15 |     powerpc64le |      glibc |         OK |
|      gcc15 |     powerpc64le |       musl |         OK |
|      gcc15 |     powerpc64le |     uclibc |    SKIPPED |
|      gcc15 |       powerpc64 |       musl |         OK |
|      gcc15 |       powerpc64 |     uclibc |    SKIPPED |
|      gcc15 |         powerpc |      glibc |     FAILED |
|      gcc15 |         powerpc |       musl |     FAILED |
|      gcc15 |         powerpc |     uclibc |     FAILED |
|      gcc16 |       powerpc64 |      glibc |         OK |
|      gcc16 |     powerpc64le |      glibc |         OK |
|      gcc16 |     powerpc64le |       musl |         OK |
|      gcc16 |     powerpc64le |     uclibc |    SKIPPED |
|      gcc16 |       powerpc64 |       musl |         OK |
|      gcc16 |       powerpc64 |     uclibc |    SKIPPED |
|      gcc16 |         powerpc |      glibc |     FAILED |
|      gcc16 |         powerpc |       musl |     FAILED |
|      gcc16 |         powerpc |     uclibc |     FAILED |

The "SKIPPED" are when the configuration is not possible: uClibc
doesn't support powerpc64 or powerpc64le.

Then, as we can see, the build fails for all "powerpc"
configuration. Our conclusion is therefore that libquadmath is not
supported on PowerPC 32-bit. While we were not able to find direct
evidence in the gcc code base, this practical experiment shows that is
simply doesn't work on PowerPC 32-bit.

So, we take the logical action of adjusting
BR2_TOOLCHAIN_HAS_LIBQUADMATH so that it is true only on
powerpc64/powerpc64le.

Fixes:

  https://autobuild.buildroot.org/results/46d435c9f5086a8695f4f6cd4026bb0d194de13c/

Cc: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-25 10:34:02 +02:00
Julien Olivain
c782302e2f package/weston: add patch to fix with libdisplay-info 0.4.0
Buildroot commit [1] bumped libdisplay-info to 0.4.0.
The weston version 15.0.1 in Buildroot has a strict condition on
libdisplay-info < 0.4.0. See [2].

This commit fixes the issue by adding an upstream patch which relaxes this
condition.

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060154054

[1] 766d3a6e87
[2] https://gitlab.freedesktop.org/wayland/weston/-/blob/15.0.1/meson.build#L181

Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-25 10:27:50 +02:00
Bernd Kuhls
58f3137738 package/{glibc, localedef}: security bump version to 2.44-27-gae9225d55
Fixes CVE-2026-19542:
d6ff274313
https://sourceware.org/bugzilla/show_bug.cgi?id=34506

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-25 10:26:50 +02:00
Bernd Kuhls
f4efa90c5f {linux, linux-headers}: bump 6.12.x, 6.6.x, 6.1.x, 5.15.x, 5.10.x, 7.1.x, 6.18.x series
Update the latest kernel releases to:
 - 7.1.9 -> 7.1.10
 - 6.18.45 -> 6.18.46
 - 6.12.104 -> 6.12.105
 - 6.6.152 -> 6.6.153
 - 6.1.183 -> 6.1.184
 - 5.15.216 -> 5.15.217
 - 5.10.265 -> 5.10.266

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-25 10:23:46 +02:00
Bernd Kuhls
8e336d3845 package/taglib: bump version to 2.3.1
https://github.com/taglib/taglib/blob/v2.3.1/CHANGELOG.md
https://mail.kde.org/pipermail/taglib-devel/2026-July/003124.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-24 22:09:13 +02:00
Bernd Kuhls
d16e4939ca package/taglib: needs gcc >= 7
Fixes a build error caught by the Gitlab pipelines:

/builds/bkuhls/buildroot/br-test-pkg/bootlin-aarch64-glibc-old/build/taglib-2.3/taglib/mpeg/mpegfile.cpp:113:10:
 error: expected primary-expression before ‘const’
       if(const Header header(&file, headerOffset + i, true); header.isValid()) {

which was introduced by code format changes in upstream commit
dfe2aa5253
which was first released with taglib 2.0, added to buildroot with commit
9cd3464afa.

This "init-statement" C++17 language feature was described in proposal
P0305R1, and according to
https://en.cppreference.com/cpp/compiler_support/17, this feature was
only supported in gcc starting from gcc 7.x.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-24 21:57:54 +02:00
Bernd Kuhls
1a0a2134e6 package/taglib: mp4 support needs threads
Buildroot commit 1c5730ebb5 bumped the
package from version 2.2.1 to version 2.3 which includes upstream commit
5d63187a8b
that uses std::call_once and is only available with threads support.

Inspired by buildroot commit f9a2d65cae
which fixed a similar error.

This patch fixes a build error

/builds/bkuhls/buildroot/br-test-pkg/br-arm-full-nothread/build/taglib-2.3/taglib/mp4/mp4itemfactory.cpp:51:16:
 error: ‘once_flag’ in namespace ‘std’ does not name a type

caught by the Gitlab pipelines. To reproduce use this defconfig:

  BR2_arm=y
  BR2_arm1176jzf_s=y
  BR2_TOOLCHAIN_EXTERNAL=y
  BR2_TOOLCHAIN_EXTERNAL_CUSTOM=y
  BR2_TOOLCHAIN_EXTERNAL_DOWNLOAD=y
  BR2_TOOLCHAIN_EXTERNAL_URL="http://autobuild.buildroot.org/toolchains/tarballs/br-arm11-full-nothread-2020.11.2.tar.bz2"
  BR2_TOOLCHAIN_EXTERNAL_GCC_9=y
  BR2_TOOLCHAIN_EXTERNAL_HEADERS_5_9=y
  BR2_TOOLCHAIN_EXTERNAL_LOCALE=y
  # BR2_TOOLCHAIN_EXTERNAL_HAS_THREADS is not set
  BR2_TOOLCHAIN_EXTERNAL_CXX=y
  BR2_PER_PACKAGE_DIRECTORIES=y
  BR2_PACKAGE_TAGLIB=y

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-24 21:40:00 +02:00
Adam Ford
7e036c739f package/libxml-parser-perl: add host-libxcrypt dependency
host-libxml-parser-perl compiles XS modules against the system perl
headers, which #include <crypt.h>. On build hosts without libcrypt-dev
installed, the build fails:

    .../CORE/reentr.h:126:16: fatal error: crypt.h: No such file or directory

Declaring host-libxcrypt ensures crypt.h is present in the per-package
host sysroot before the build.

This can for example be reproduced on a minimal Debian Forky system,
where libc6-dev no longer pulls libxcrypt-dev.

Signed-off-by: Adam Ford <aford173@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-24 21:14:39 +02:00
Thomas Perale
087a15f578 website/lts: update release wording
Update the release wording to align with the documentation.

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-24 20:51:23 +02:00
Thomas Perale via buildroot
70f762ea6e docs/manual: update 'releases' to reflect LTS changes
With the release of 2025.02, LTS releases are now made every two years
with a 3-year support.

This reflect the table showed at https://lts.buildroot.org/#releases.

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-24 19:48:42 +02:00
Titouan Christophe
fab3c4eb92 package/redis: security bump to v8.10.1
See the release notes:
https://github.com/redis/redis/blob/8.10.1/00-RELEASENOTES

Notably, this fixes CVE-2026-62356: miscalculated buffer size in
`CMSketch` RDB loading may lead to heap OOB write, as well as other
security fixes without CVE number

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-24 18:58:00 +02:00
Bernd Kuhls
c0a51767a0 package/jpeg-turbo: fix libm linking issue
Buildroot commit bb38f6f720 bumped the
package to 3.2.0. This version first included upstream commit
ed00e0f4b3
which removed the dependency to libm causing build errors detected by
the autobuilders.

Disabling the build of tests by the previous patch of this series is not
enough because the build will fail on other tools like

[ 98%] Linking C executable djpeg-static
/home/bernd/buildroot/output/per-package/jpeg-turbo/host/bin/../lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 src/spng/CMakeFiles/spng-static.dir/spng.c.o: in function
 `spng_decode_image':
spng.c:(.text+0x4c62): undefined reference to `__fpclassifyf'

Add upstream commit to fix the problem.

Fixes:
https://autobuild.buildroot.net/results/981/98114d4ea7afe62bb4cef934a06bf289d863ad3f/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-24 08:41:49 +02:00
Bernd Kuhls
d74a065a16 package/jpeg-turbo: use configure option WITH_{TESTS, TOOLS}
Buildroot commit c531fe6520 bumped the
package to 3.1.2. This version first included upstream commit
942ac87e47
which added configure options to disable the build of command-line
tools and tests.

This patch replaces the current _POST_INSTALL_TARGET_HOOK with the new
configure option and disables the build of tests.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-24 08:28:33 +02:00
Peter Korsgaard
212b7edc22 Update for 2026.08-rc2
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-23 23:08:54 +02:00
Arnout Vandecappelle
66c46083e2 CHANGES: Update for 2026.05.2
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>

(cherry picked from commit a87cdf66c4)
2026-08-23 23:06:03 +02:00
Arnout Vandecappelle
312dd92bcd Update news.html and download.html for 2026.05.2
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
2026-08-23 23:05:51 +02:00
Arnout Vandecappelle
157342931b CHANGES: Update for 2025.02.17
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>

(cherry picked from commit f8089744f9)
2026-08-23 22:59:06 +02:00
Arnout Vandecappelle
46679da1df Update news.html and download.html for 2025.02.17
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
2026-08-23 22:59:05 +02:00
Julien Olivain
df9e3f9b30 Revert "package/fakeroot: bump to version 2.1.4"
This major fakeroot bump is introducing xattr issues on hosts with
SELinux enabled (for example a Fedora 44 default installation).

Trying to build defconfigs such as:

    make qemu_aarch64_virt_defconfig
    make

produces error when building the filesystem image:

    >>>   Generating filesystem image rootfs.ext2
    ...
    mke2fs 1.47.4 (6-Mar-2025)
    ...
    Copying files into the device: set_inode_xattr: No data available while reading attribute "security.selinux" of /buildroot/output/build/buildroot-fs/ext2/target"
    populate_fs3: No data available while copying xattrs on root directory
    mkfs.ext4: No data available while populating file system

This reverts commit 344d64f385.

Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-23 22:34:03 +02:00
Julien Olivain
9fdc16a79d Revert "package/btrfs-progs: bump to version 7.1"
We need to revert the fakeroot update which is introducing
filesystem build issue.

Since btrfs-progs needed this new fakeroot version, it needs to be
reverted too.

This commit reverts to the previous btrfs-progs version, which is not
using the nftw() libc function.

This reverts commit 7aba8ecc6a.

Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-23 22:20:21 +02:00
Julien Olivain
ca2c31b019 board/qemu/x86_64-efi/linux.config: enable CONFIG_EFI_STUB to fix with grub2 >= 2.14
Since Buildroot commit [1] (boot/grub2: bump to version 2.14), the
qemu_x86_64_efi_defconfig fails at boot time with the error:

    !!!! X64 Exception Type - 0E(#PF - Page-Fault)  CPU Apic ID - 00000000 !!!!
    ExceptionData - 0000000000000003  I:0 R:0 U:0 W:1 P:1 PK:0 SS:0 SGX:0

This issue happens because EDK2 and Grub 2.14 are enabling NX and the
kernel lacks the CONFIG_EFI_STUB configuration. For the full explanation
see the commit log of [2] (board/pc/linux.config: enable CONFIG_EFI_STUB).

This commit enables CONFIG_EFI_STUB=y.

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/15969219375

[1] da278ba1da
[2] 1c1fa6ce67

Reported-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-23 22:04:34 +02:00
Bernd Kuhls
c4f41f4f3f package/clamav: requires DES in openssl
Buildroot commit 8b1d8dd25d bumped the
package from 1.4.3 to 1.5.1 which includes upstream commit
8d485b9bfd
that adds the usage of the OpenSSL crate from rust.

This crate depends on DES and causes build errors when missing:

/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 ../libclamav/libclamav.so.12.1.0: undefined reference to `EVP_des_ede3_cfb8'
/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 ../libclamav/libclamav.so.12.1.0: undefined reference to `EVP_des_ede3_cbc'
/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 ../libclamav/libclamav.so.12.1.0: undefined reference to `EVP_des_ede3_cfb64'
/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 ../libclamav/libclamav.so.12.1.0: undefined reference to `EVP_des_ede3_ecb'
/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 ../libclamav/libclamav.so.12.1.0: undefined reference to `EVP_des_ecb'
/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 ../libclamav/libclamav.so.12.1.0: undefined reference to `EVP_des_ede3'
/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 ../libclamav/libclamav.so.12.1.0: undefined reference to `EVP_des_ede3_ofb'
/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../i686-buildroot-linux-gnu/bin/ld:
 ../libclamav/libclamav.so.12.1.0: undefined reference to `EVP_des_cbc'

Fixes:
https://autobuild.buildroot.net/results/b93/b9359c5c177f3e4bcef991cde3c2dcf412dee5de/
https://autobuild.buildroot.net/results/300/300721a882f3410528878db730aaff1aa6822986/
https://autobuild.buildroot.net/results/a16/a163a9229c04f638a46e6250dc135c475e5d1576/
https://autobuild.buildroot.net/results/7e8/7e88cba9974f6f5acd125b69b95b7269d8128886/

A backport to LTS branches should be considered.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-23 21:56:28 +02:00
Thomas Perale
3e0d162011 docs/website: link LTS tooling documentation and staging branch
Users asked where the notes are available and if the information are
publicly available.

Those changes clearly explain the location and convention of the staging
branches and also link to more documentation on how to read the
annotations.

Also update the timing of the different steps to be less specific.

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Reviewed-by: Quentin Schulz <quentin.schulz@cherry.de>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-23 21:44:49 +02:00
Thomas Devoogdt
9f292bb7a1 package/webkitgtk: fix wrong config option
Commit 713d63b "package/webkitgtk: add option to enable MiniBrowser",
added support to select BR2_PACKAGE_WEBKITGTK_MINIBROWSER, but forgot
to drop the default -DENABLE_MINIBROWSER=ON entry.

Signed-off-by: Thomas Devoogdt <thomas@devoogdt.com>
Acked-By: Adrian Perez de Castro <aperez@igalia.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-23 21:38:39 +02:00
Julien Olivain
566bdcb97f package/fluidsynth: security bump to version 2.5.7
For change log since v2.4.7, see:
https://github.com/FluidSynth/fluidsynth/releases

According to:
https://github.com/FluidSynth/fluidsynth/blob/master/doc/wiki/ChangeLog.md

FluidSynth 2.5.6 fixes:
CVE-2026-58264 - a heap-based buffer overrun in command handler (GHSA-mqmq-w63q-cj94)
CVE-2026-61714 - a heap-based buffer overflow in MIDI player (GHSA-976m-35rw-h3m6)
CVE-2026-61721 - a heap-based buffer overrun for DLS samples (GHSA-59ph-rx8r-8p4j)
CVE-2026-61723 - a DLS ptbl chunk integer overflow (GHSA-r4mc-v3p8-pv47)
CVE-2026-61722 - a DLS articulation chunk integer overflow (GHSA-hp72-35pr-6h6r)
CVE-2026-61720 - a SF2 DMOD chunk integer underflow (GHSA-rmc4-c8hw-455w)

FluidSynth 2.5.2 fixes:
CVE-2025-68617 - a heap-based use-after-free involving DLS files (GHSA-ffw2-xvvp-39ch)

SDL2 audio support was removed upstream in commit:
89145b004a

It was replaced by the newer SDL3. This commit reflects that change
(update option name and comments, add legacy option entry).

Also, dynamic library dependency was added in Buildroot commit:
111a1c7091
This commot removes the duplicate dependency for SDL3.

FluidSynth also added a native DLS soundfont support in:
c959f8d208
It is enabled by default and uses C++17. This commit adds a new
option with a dependency on gcc >= 7.

The license option hash is also updated, after the FSF address
update in:
db42fa333b

Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-23 21:29:20 +02:00
Christopher Obbard
88351e5f9b DEVELOPERS: update email for Christopher Obbard
Update my email address.

Signed-off-by: Christopher Obbard <chris.obbard@oss.qualcomm.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-23 21:18:27 +02:00
Benjamin DeCamp
667335cd18 package/linux-tools/S10hyperv: fix invalid return value
In both start() and stop(), ret is only assigned on failure. When
hypervkvpd starts or stops successfully, return "$ret" expands to an
empty string and causes:

  /etc/init.d/S10hyperv: return: line 31: Illegal number:

Those double quotes were added in Buildroot commit [1], to fix a
new ShellCheck warning at that time. This was not a complete fix.

Only removing the double quote would reintroduce the ShellCheck
warning. This would also reintroduce a check-package error.

Since a bare return is equivalent to a "return 0", this commit
also initializes with ret=0. Doing so will tell ShellCheck "ret" is
an integer. Therefore, the ShellCheck warning will no longer be
reported.

This commit fixes the invalid return value by removing the double
quotes and initialzing "ret=0".

[1] c4173d8b08

Signed-off-by: Benjamin DeCamp <benjamin8532@protonmail.com>
[Julien:
 - add "ret=0" initialization in script to fix check-package error
 - add extra info in the commit log
]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-23 17:23:51 +02:00
Edgar Bonet
c3f3705a2f package/libgpiod2: fix build failure on missing C++ compiler
The meson build configuration of libgpiod2 unconditionally requires a
C++ compiler, although it is only useful if building the C++ bindings.
This is causing autobuild failures with an obscure error message:
"ERROR: Unable to get gcc pre-processor defines".

Fix the failures by only requiring a C++ compiler when we want the C++
bindings.

Fixes:
 - https://autobuild.buildroot.org/results/d1c19ffa0c599bd2ba9be965a98fc8f778d6e366
 - https://autobuild.buildroot.org/results/c6b3c9311d628bdb4ea103431767493fab9a3668
 - https://autobuild.buildroot.org/results/8e799050c5779c680ff5e5136571f57d29239f2f
 - https://autobuild.buildroot.org/results/d6d8833acfe00559579defbbf3ca34c0edbe7869

Signed-off-by: Edgar Bonet <bonet@grenoble.cnrs.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-23 15:53:47 +02:00
Thomas Petazzoni
edffc0bc50 package/enscript: fix build issue with musl and gcc >= 15
enscript currently fails to build with musl with gcc >= 15. In order
to fix this, we need to bring a number of patches from upstream, and
add 2 others that were submitted upstream.

From upstream, we bring
0002-Add-CFLAG-std-c89-so-it-compiles-with-the-old-standa.patch, which
switches to -std=c89 to get the compiler back to "old" behavior.

However, as this commit patches configure.ac, we need to autoreconf,
but autoreconf is broken, so we also take
0003-Automake-1.12-and-up-no-longer-supports-pre-ANSI.patch from
upstream, which drops a problematic autoconf macro.

However, once you drop this problematic autoconf macro, the PROTOTYPES
define is never set by anything, causing the __P macro to no longer be
defined properly. This is fixed by
0004-Fix-prototype-detection-when-__STDC__-is-defined-but.patch that
we have submitted upstream.

Once you're there, you realize that switching to -std=c89 has the side
effect that musl's <limits.h> no longer defines PATH_MAX, because it
needs one of:

  #if defined(_POSIX_SOURCE) || defined(_POSIX_C_SOURCE) \
   || defined(_XOPEN_SOURCE) || defined(_GNU_SOURCE) || defined(_BSD_SOURCE)

and a side effect of -std=c89 is that none of these is defined
anymore. So we introduce 0005-Use-std-gnu89-instead-of-std-c89.patch,
which switches to -std=gnu89. This patch has also been submitted
upstream.

With all of these efforts, we get a successful build on musl with gcc
>= 15.

This commit needs to be backported to Buildroot versions that support
gcc 15.x, so that means the currently maintained 2026.x branches, but
not 2025.02 as only up to gcc 14.x was supported then.

Fixes:

  https://autobuild.buildroot.org/results/d39d14bbbb3a51d67fe962b877c7f66ff1204ecf/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-23 00:09:18 +02:00
Stefan Müller
03757abfce package/libssh2: fix CVE-2026-66035
Backport the fix for CVE-2026-66035.

The ETM decrypt path does not validate the received packet length before
calculating the decrypt buffer size. A malformed packet can therefore
lead to a heap overflow.

Use Debian's libssh2 1.11.1 backport of the upstream fix.

Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
[Julien: add links to Debian patches]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-22 23:54:17 +02:00
Stefan Müller
58581deeca package/libssh2: fix CVE-2026-66034
Backport the fix for CVE-2026-66034.

The publickey subsystem does not sufficiently validate the length of a
server-controlled comment field. A malformed response can therefore
cause an out-of-bounds read.

Use Debian's libssh2 1.11.1 backport of the upstream fix.

Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
[Julien: add links to Debian patches]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-22 23:54:17 +02:00
Stefan Müller
6755a00cd2 package/libssh2: fix CVE-2026-66033
Backport the fix for CVE-2026-66033.

The OpenSSL AES-GCM cipher path lacks runtime bounds checks around the
input block size. A malformed packet can therefore lead to an
out-of-bounds read or write.

Use Debian's libssh2 1.11.1 backport of the upstream fix.

Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
[Julien: add links to Debian patches]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-22 23:54:17 +02:00
Stefan Müller
05c13e87e9 package/libssh2: fix CVE-2026-66032
Backport the fix for CVE-2026-66032.

A SFTP error path can leave a dangling pointer after freeing the
response buffer, which may result in a double free on subsequent error
handling.

Use Debian's libssh2 1.11.1 backport of the upstream fix.

Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
[Julien: add links to Debian patches]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-22 23:54:17 +02:00
Stefan Müller
546fd31c70 package/libssh2: fix CVE-2025-15661
Backport the SFTP symlink bounds checking fix for CVE-2025-15661.

The initial fix requires the LIBSSH2_UNCONST compatibility backport on
libssh2 1.11.1. Also include the upstream follow-up fixing
SSH_FXP_STATUS handling introduced by the initial security fix.

The patches are based on the upstream fixes and Debian's libssh2 1.11.1
backports.

Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com>
[Julien: add links to Debian patches]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-22 23:54:17 +02:00
Fiona Klute (Othermo GmbH)
ff7f973a16 package/dracut: disable dracut-cpio if host-rustc is not available
Since upstream commit 89a86dcb0a3248606824de50f5c63f61cfe0369c (first
release: 106) if cargo exists on PATH the Dracut configure script
enables building dracut-cpio by default, and calls "cargo --version"
to check if cargo works. This fails on the autobuilders:

error: rustup could not choose a version of cargo to run, because one wasn't specified explicitly, and no default is configured.
help: run 'rustup default stable' to download the latest stable release of Rust and set it as your default toolchain.
dracut couldn't find cargo for dracut-cpio build

The affected configs either don't have BR2_PACKAGE_HOST_RUSTC enabled,
or build-time.log.gz shows host-rustc was not installed before the
host-dracut build, so presumably the "cargo" that produces the rustup
error is an external one already installed on the autobuilders.

To fix this, enable dracut-cpio only if BR2_PACKAGE_HOST_RUSTC=y, and
add a dependency on host-rustc in that case. According to the
documentation [1, see "enhanced_cpio"] dracut-cpio is supposed to
optimize archive creation for copy-on-write filesystems, so it should
not matter much for Buildroot. The --disable-dracut-cpio option was
added in upstream commit 4a4ab928a49e81e02104ec5466160664e59c3965
(same release).

Fixes: https://autobuild.buildroot.org/results/5f557d708cce997e7f039f17e30640b02ba9180a/
Fixes: https://autobuild.buildroot.org/results/f04ca3c4598f62a7e87d84bc111eb8b161b34a70/
(and more)

[1] https://dracut-ng.github.io/dracut/man/dracut.conf.5.html#_configuration_options

Signed-off-by: Fiona Klute (Othermo GmbH) <fiona.klute@gmx.de>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-22 22:11:54 +02:00
Stefan Müller
e991fa0716 package/wget: fix CVE-2026-58471
Backport the upstream fix for a heap buffer overflow in
convert_fname() when growing the iconv output buffer.

Backport to: 2025.02.x

Signed-off-by: Stefan Müller <stemu86@gmx.ch>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-22 17:56:05 +02:00
Stefan Müller
89485adb29 package/wget: fix CVE-2026-58470
Backport the upstream fix for integer overflows while parsing
Content-Range headers, together with the follow-up fix using
strtoll() for wgint values.

Backport to: 2025.02.x

Signed-off-by: Stefan Müller <stemu86@gmx.ch>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-22 17:56:05 +02:00
Stefan Müller
937e33237e package/wget: fix CVE-2026-58469
Backport the upstream fix for a buffer underflow in
clean_metalink_string(), together with the two required follow-up
fixes for the inverted whitespace check and missing ctype.h include.

Backport to: 2025.02.x

Signed-off-by: Stefan Müller <stemu86@gmx.ch>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-22 17:56:05 +02:00
Giulio Benetti
131952483b package/putty: security bump to version 0.85
Release notes:
https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html

THe release notes has 4 security related fixes. No CVE assigned.

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
[Julien: mark the commit as "security" related]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-22 16:25:52 +02:00
Philippe MONTCHO
883fc1b41d package/mtools: bump version to 4.0.49
Release note:
https://lists.gnu.org/archive/html/info-mtools/2025-06/msg00005.html

Signed-off-by: Philippe MONTCHO <philippemontcho@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-22 12:35:58 +02:00
Alexis Lothoré
50f635f8df package/python-scp: bump version to 0.16.1
Changelog: 8f2a778cc6

Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-22 12:20:21 +02:00
Neal Frager
c7810e5847 boot/xilinx-embeddedsw: versal2_plm: configure xilpm runtime lib correctly
The xilpm_runtime_lib is not enabled by default in the versal2_plm Makefile:
97f2baf7f6/lib/sw_apps/versal_plm/src/versal_2ve_2vm/Makefile (L13)

Without it, there is a silent runtime failure.

Add config XILPM_RUNTIME_LIB=SUBSYS to make sure the xilpm_runtime_lib is
correctly configured and included to fix the problem.

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-22 00:22:44 +02:00
Yann E. MORIN
0480567def DEVELOPERS: add Yann E. MORIN (work) for distribution-registry
Signed-off-by: Yann E. MORIN <yann.morin@orange.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-21 23:43:00 +02:00
Yann E. MORIN
d21a81ef8c package/distribution-registry: needs NPTL
distribution-registry calls pthread_getattr_np() which is only available
with NPTL; i.e. always available with glibc (where it originates from,
since 2.2.3), always available with musl (which has had it since 0.9.10
in 2013), and only available when uClibc has NPTL (since 1.0.0 in 2015).

Fixes: https://autobuild.buildroot.org/results/9395500a8baee6c6142f96d7bc97e81725c2e754/

Signed-off-by: Yann E. MORIN <yann.morin@orange.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-21 23:43:00 +02:00
Luca Ceresoli
b088e5dbe4 docs/manual: fix typo
Fix significant -> significantly.

Signed-off-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-21 23:11:46 +02:00
Waldemar Brodkorb
5795000c25 package/uclibc: PPC fix e500 fenv support
Problem found via Buildroot autobuilders, seems to be some
bitrotting code. Tested with qemu_ppc_mpc8544ds_defconfig
and a hard-float toolchain.

Fixes:
 - https://autobuild.buildroot.net/results/464/46448883b1682718aeff066d204349d8e9a3b1d1/
 - https://gitlab.com/buildroot.org/buildroot/-/jobs/15969219363

Signed-off-by: Waldemar Brodkorb <wbx@openadk.org>
[Julien: add link to CI build failure]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-21 22:39:59 +02:00
Thomas Petazzoni
e4cf512c39 package/igh-ethercat: backport upstream fix to build with Linux >= 6.19.0
Fixes:

  https://autobuild.buildroot.org/results/9b270904b2f7cf9eaa661c98370c582a61ff2342/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-21 22:13:27 +02:00
Romain Naour
7eb4a552c4 package/gdb: fix gdb default version
We need to select one of the 3 gdb versions available when host-gdb is
not selected but the condition was removed while removing gdb 14.x
in commit [1], so gdb package fail to download the archive.

Select BR2_GDB_VERSION_16 when !BR2_PACKAGE_HOST_GDB.

[1] 6737c90bc6

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/15969219536 (TestGdbFullTarget)
https://gitlab.com/buildroot.org/buildroot/-/jobs/15969219539 (TestGdbserverOnly)

Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-21 21:37:00 +02:00
Romain Naour
2f6b34f851 support/testing: remove TestGdbArc
The Arc specific gdb version was removed by commit [1]
but we still have the TestGdbArc that was testing this
version of gdb.

We can now safely remove TestGdbArc.

[1] 0b3d526226

Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-21 21:28:56 +02:00
Dario Binacchi
4788039a89 package/drogon: fix build with examples
Some examples embed CSP views, whose C++ sources are generated at build
time by drogon_ctl. When cross-compiling, CMake looks the tool up in
PATH, so the build fails with:

  [ 77%] Generating HelloView.h, HelloView.cc
  /bin/sh: 1: drogon_ctl: not found
  make[3]: *** [examples/CMakeFiles/helloworld.dir/build.make:74: examples/HelloView.h] Error 127

Add host-drogon to the dependencies, as it installs drogon_ctl in
$(HOST_DIR)/bin.

Fixes:
- https://autobuild.buildroot.org/results/b8f38b0645932cb5506515d6d313b64d824c8ce0

Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-21 20:59:40 +02:00
Bernd Kuhls
772ff404c5 package/{mesa3d, mesa3d-headers}: bump version to 26.1.8
Release notes of this bugfix release:
https://lists.freedesktop.org/archives/mesa-announce/2026-August/000865.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-21 18:15:44 +02:00
Bernd Kuhls
fcac6c4f25 {linux, linux-headers}: bump 6.12.x, 6.6.x, 6.1.x, 5.15.x, 5.10.x, 7.1.x, 6.18.x series
Update the latest kernel releases to:
 - 7.1.8 -> 7.1.9
 - 6.18.44 -> 6.18.45
 - 6.12.103 -> 6.12.104
 - 6.6.151 -> 6.6.152
 - 6.1.182 -> 6.1.183
 - 5.15.215 -> 5.15.216
 - 5.10.264 -> 5.10.265

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-21 18:13:12 +02:00
Bernd Kuhls
86102dd827 package/kodi: add upstream patch to fix build on s390, mark unavailable on m68k
Build errors were found by the Gitlab pipelines with these defconfigs:

- bootlin-m68k-68040-uclibc
  CMake Error at cmake/scripts/linux/ArchSetup.cmake:50 (message):
    Unknown CPU: m68k

- bootlin-s390x-z13-glibc
  CMake Error at cmake/scripts/linux/ArchSetup.cmake:50 (message):
    Unknown CPU: s390x

Backport an upstream commit from the upcoming Piers branch to fix the
restriction in ArchSetup.cmake.

This caused a different build error on m68k later on:

/builds/bkuhls/buildroot/br-test-pkg/bootlin-m68k-68040-uclibc/build/kodi-21.3-Omega/xbmc/utils/MathUtils.h:142:5:
 error: unknown register name ‘st’ in ‘asm’
  142 |     __asm__ __volatile__ (

because m68k is not part of the list of archs to disable asm code:
https://github.com/xbmc/xbmc/blob/Omega/xbmc/utils/MathUtils.h#L26

Upstream rejected to add m68k there:
https://github.com/xbmc/xbmc/pull/22519
https://github.com/xbmc/xbmc/pull/22357#issuecomment-1368358471

so we disable m68k in BR2_PACKAGE_KODI_ARCH_SUPPORTS.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-21 00:15:52 +02:00
Bernd Kuhls
139025f793 package/netsnmp: add upstream patch to fix build of depending packages
Buildroot commit ed27a33ba0 bumped the
package from 5.9.4 to 5.9.5.2 which includes upstream commit
7536a8d6d3
that breaks the build of other packages depending on netsnmp like ntp:

ntpSnmpSubagentObject.c: In function 'init_ntpSnmpSubagentObject':
./ntpSnmpSubagentObject.h:51:1: error: ISO C90 forbids mixed
 declarations and code [-Werror=declaration-after-statement]
   51 | static oid oidname##_oid [] = { __VA_ARGS__ };

For details see https://github.com/net-snmp/net-snmp/issues/1035

Fixes:
https://autobuild.buildroot.net/results/395/395a3b18719e4ec0c0b94b0692caaa9566ee57c6/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-20 23:10:16 +02:00
Bernd Kuhls
88c353351a package/uhttpd: bump version, fix cmake 4 compatibility
This bump includes upstream commit
https://git.openwrt.org/?p=project/uhttpd.git;a=commitdiff;h=ebb92e6b339b88bbc6b76501b6603c52d4887ba1
which fixes cmake 4 builds. No backports necessary because the cmake 4
bump commit e46695bbe4 is not present in
any older branches.

Updated hash of header file which is used as license file due to
upstream commits:
https://github.com/openwrt/uhttpd/commits/master/uhttpd.h

Disabled new configure option UCODE_SUPPORT which was added by upstream
commit:
https://git.openwrt.org/?p=project/uhttpd.git;a=commitdiff;h=3ceccd02d86bf4d6609f46d8b30963cc52034cc2

Fixes:
https://autobuild.buildroot.net/results/cc2/cc265d34aed684b88032edd04ca0fc88186ec676/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-20 22:40:41 +02:00
Fengwei Tan
e913afbeb1 package/Makefile.in: fix support for $(PKG)_FLAT_STACKSIZE
When a package defines $(PKG)_FLAT_STACKSIZE, ELF2FLT_FLAGS contains
-Wl,-elf2flt="-r -s<stack-size>". The embedded quotes are needed to
keep both elf2flt options in single linker argument.

However, many package Makefiles wrap $(TARGET_CFLAGS) in double quotes,
for example:

  CFLAGS="$(TARGET_CFLAGS)"

After expansion, the embedded quote terminates the outer CFLAGS quote.
As a result, the shell interprets "-s<stack-size> ..." as a command
instead of passing it to the compiler.

Pass -r and -s<stack-size> in separate -Wl arguments instead. This
avoids embedded quotes; GCC forwards both -elf2flt options to
ld-elf2flt, which collects them before invoking elf2flt.

This got broken by commit
04d7ea4720 ("package: Makefile.in: fix
elf2flt invocation options"), which by adding -r as an elf2flt
argument, did not correctly handle -s$($(PKG)_FLAT_STACKSIZE).

Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
[Thomas: improve commit message]
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-20 21:14:48 +02:00
Giulio Benetti
5245c41441 package/wireshark: security bump to v4.4.18
Fixes the following vulnerabilities:

- wnpa-sec-2026-64 · Sharkd utility crash
  https://www.wireshark.org/security/wnpa-sec-2026-64

- wnpa-sec-2026-65 · Sharkd utility crash
  https://www.wireshark.org/security/wnpa-sec-2026-65

- wnpa-sec-2026-66 · UMTS FP protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-66

- wnpa-sec-2026-67 · RDP protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-67

- wnpa-sec-2026-69 · Dissection engine reassembly crash
  https://www.wireshark.org/security/wnpa-sec-2026-69

- wnpa-sec-2026-70 · BUSMASTER file parser abnormal exit
  https://www.wireshark.org/security/wnpa-sec-2026-70

- wnpa-sec-2026-71 · Tektronix K12xx file parser crash
  https://www.wireshark.org/security/wnpa-sec-2026-71

- wnpa-sec-2026-72 · ERF file parser crash
  https://www.wireshark.org/security/wnpa-sec-2026-72

- wnpa-sec-2026-73 · Bluetooth Attribute Protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-73

- wnpa-sec-2026-74 · Catapult DCT2000 file parser crash
  https://www.wireshark.org/security/wnpa-sec-2026-74

- wnpa-sec-2026-75 · C12.22 protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-75

- wnpa-sec-2026-76 · CMS protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-76

- wnpa-sec-2026-77 · H.245 protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-77

- wnpa-sec-2026-78 · Kerberos protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-78

- wnpa-sec-2026-79 · Bluetooth HFP Profile protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-79

- wnpa-sec-2026-80 · Bluetooth BR/EDR FHS protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-80

- wnpa-sec-2026-81 · 3gpp phone log file parser crash
  https://www.wireshark.org/security/wnpa-sec-2026-81

- wnpa-sec-2026-83 · CMS protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-83

- wnpa-sec-2026-84 · Pcapng file parser crash
  https://www.wireshark.org/security/wnpa-sec-2026-84

- wnpa-sec-2026-85 · SSH protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-85

- wnpa-sec-2026-86 · ESS protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-86

- wnpa-sec-2026-87 · X.509IF protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-87

- wnpa-sec-2026-88 · RRC protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-88

- wnpa-sec-2026-89 · C12.22 protocol dissector crash
  https://www.wireshark.org/security/wnpa-sec-2026-89

- wnpa-sec-2026-91 · Bluetooth AVRCP Profile
  https://www.wireshark.org/security/wnpa-sec-2026-91

For more information on the version bump, see:
  - https://www.wireshark.org/docs/relnotes/wireshark-4.4.18.html

[Peter: add list of vulnerabilities]
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-19 11:42:33 +02:00
Giulio Benetti
93049b2559 package/udisks: security bump to version 2.11.2
This fixes this CVE:
CVE-2026-7867:
https://github.com/storaged-project/udisks/security/advisories/GHSA-j42g-v9jw-6ph3

Release notes:
https://github.com/storaged-project/udisks/releases/tag/udisks-2.11.2

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-19 11:42:17 +02:00
Fiona Klute
7aba8ecc6a package/btrfs-progs: bump to version 7.1
Upstream changelog:
https://git.kernel.org/pub/scm/linux/kernel/git/kdave/btrfs-progs.git/tree/CHANGES?h=v7.1

Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-18 23:47:31 +02:00
Fiona Klute
344d64f385 package/fakeroot: bump to version 2.1.4
The source archive does not contain a pre-build configure script any
more, so enable autoreconf. Fakeroot also contains an experimental
Meson build definition since 2.1, but Buildroot should keep using
autotools until the Meson build is stable.

Since v6.10.1 btrfs-progs uses nftw() [1], which package/fakeroot did
not support before v2.0 [2]. This update allows updating btrfs-progs
past v6.10 without breaking build of btrfs rootfs images.

Upstream changes:
https://salsa.debian.org/clint/fakeroot/-/compare/upstream%2F1.37.2...upstream%2F2.1.4

[1] https://git.kernel.org/pub/scm/linux/kernel/git/kdave/btrfs-progs.git/commit?id=c6464d3f99ed1dabceff1168eabb207492c37624
[2] 3502c515c7

Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-18 23:47:30 +02:00
201 changed files with 4615 additions and 294 deletions

291
CHANGES
View File

@@ -1,3 +1,38 @@
2026.08, released September 4th, 2026
Various fixes.
Updated/fixed packages: dpdk, dracut, drogon, erlang, exiv2,
expat, freeswitch, gcc, glibc, libcurl, libldns, libnfs,
libopenssl, mpd, ncmpc, newt, opencv, openscap, openssh, perl,
proftpd, qemu, vim
2026.08-rc3, released August 29th, 2026
Fixes all over the tree.
Updated/fixed packages: avro-c, bind, bpftrace, collectd,
dahdi-linux, expat, fetchmail, flex, fluidsynth, gdb, glibc,
haproxy, jpeg-turbo, libbpf, libheif, libopenssl,
libxml-parser-perl, localedef, mesa3d, nodejs, olsr, perl,
php, python-avro, python-gobject, qt6, qt6declarative, redis,
rsyslog, taglib, uclibc, unbound, weston
2026.08-rc2, released August 23th, 2026
Fixes all over the tree.
Infrastructure:
- Correct <pkg>_FLAT_STACKSIZE handling for nommu
Defconfigs: QEMU x86-64 EFI: Fix build issue after grub2 bump.
Updated/fixed packages: clamav, distribution-registry, dracut,
drogon, enscript, fluidsynth, gdb, igh-ethercat, kodi,
libgpiod2, libssh2, linux-tools, mesa3d, mtools, netsnmp,
putty, python-scp, uclibc, udisks, uhttpd, webkitgtk, wget,
wireshark, xilinx-embeddedsw
2026.08-rc1, released August 18th, 2026
Fixes all over the tree and new features.
@@ -34,6 +69,137 @@
Removed packages: argparse, ts4900-fpga
2026.05.2, released August 23, 2026
Important / security related fixes:
apr-util: CVE-2025-49506, CVE-2026-32327, CVE-2026-34191,
CVE-2026-34501, CVE-2026-34502
bind: CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605,
CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204,
CVE-2026-13321
botan: CVE-2026-32877, CVE-2026-32883, CVE-2026-32884, CVE-2026-34580,
CVE-2026-34582
busybox: CVE-2024-58251
clamav: CVE-2025-8088, CVE-2026-20337, CVE-2026-20338, CVE-2026-20339,
CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, CVE-2026-20348
containerd: CVE-2026-35469, CVE-2026-46680, CVE-2026-47262,
CVE-2026-53488
dracut: CVE-2026-6893
dropbear: (no CVE assigned)
exim: GCVE-25-2026-07-45-1, CVE-2026-66140, CVE-2026-66141
expat: CVE-2026-72522
glibc: CVE-2026-6368
go: CVE-2026-39822
intel-microcode: CVE-2025-31936, CVE-2025-31938, CVE-2025-35973,
CVE-2026-20707, CVE-2026-20713, CVE-2026-20716, CVE-2026-20760,
CVE-2026-20917
libarchive: (no CVE assigned)
libass: CVE-2026-61626, CVE-2026-61627
libgit2: CVE-2026-53583, CVE-2026-53584, CVE-2026-53585,
CVE-2026-53586, CVE-2026-53587
libglib2: CVE-2025-13601, CVE-2025-14087, CVE-2025-14512,
CVE-2026-1484, CVE-2026-1485, CVE-2026-1489, CVE-2026-15588,
CVE-2026-58010, CVE-2026-58011, CVE-2026-58012, CVE-2026-58013,
CVE-2026-58014, CVE-2026-58015
libheif: CVE-2026-62289, CVE-2026-62291, CVE-2026-62292,
CVE-2026-62377, GHSA-46rp-pcq2-rpmr, GHSA-73p7-m7gg-w2jv,
GHSA-9ww4-9v47-m7pj, GHSA-jc8f-p23p-5hjg, GHSA-xpw3-9rhw-482x
libmodsecurity: CVE-2026-52747, CVE-2026-52761
libssh: CVE-2026-15370, CVE-2026-59843, CVE-2026-59844, CVE-2026-59845,
CVE-2026-59846, CVE-2026-59847, CVE-2026-59848, CVE-2026-59849,
CVE-2026-59850
localedef: CVE-2026-6368
memcached: (no CVE assigned)
ntfs-3g: CVE-2026-42616, CVE-2026-42617, CVE-2026-42618,
CVE-2026-46569, CVE-2026-46570, CVE-2026-46571, CVE-2026-46572,
CVE-2026-56135, CVE-2026-56136
openssh: (no CVE assigned)
openvpn: CVE-2026-63649, CVE-2026-63650
perl: CVE-2026-13221, CVE-2026-57432, CVE-2026-8376
php: CVE-2026-17543, CVE-2026-17544, CVE-2026-7260, CVE-2026-9672
postgresql: CVE-2026-14662, CVE-2026-14663, CVE-2026-14664,
CVE-2026-14666, CVE-2026-14668, CVE-2026-14669, CVE-2026-14670,
CVE-2026-14671, CVE-2026-14672, CVE-2026-14673, CVE-2026-14676,
CVE-2026-14677, CVE-2026-14678, CVE-2026-14679, CVE-2026-14680,
CVE-2026-14681, CVE-2026-15741, CVE-2026-15742, CVE-2026-16238,
CVE-2026-16239, CVE-2026-16241, CVE-2026-18024, CVE-2026-18408,
CVE-2026-19385, CVE-2026-6464, CVE-2026-6469, CVE-2026-6470,
CVE-2026-6471
python3: CVE-2026-0864, CVE-2026-11972, CVE-2026-12003, CVE-2026-15308,
CVE-2026-4360
rsync: CVE-2026-53783, CVE-2026-53784, CVE-2026-53785, CVE-2026-53786,
CVE-2026-53788, CVE-2026-53789, CVE-2026-53790, CVE-2026-53791,
CVE-2026-53792, CVE-2026-53793, CVE-2026-53794, CVE-2026-53795,
CVE-2026-53796, CVE-2026-53797, CVE-2026-53798, CVE-2026-53799,
CVE-2026-53800, CVE-2026-53801, CVE-2026-53802, CVE-2026-53803,
CVE-2026-70452, CVE-2026-70453, CVE-2026-70454, CVE-2026-70455,
CVE-2026-70456, CVE-2026-70457, CVE-2026-70458, CVE-2026-70459,
CVE-2026-70460, CVE-2026-70461, CVE-2026-70462, CVE-2026-70463,
CVE-2026-70464
samba4: CVE-2026-58216, CVE-2026-58218, CVE-2026-58221, CVE-2026-58222,
CVE-2026-58224, CVE-2026-6949
screen: (no CVE assigned)
ser2net: GHSA-cgh5-39mg-vhfr
socat: CVE-2026-56123
stunnel: CVE-2026-70367, CVE-2026-70368
syslog-ng: CVE-2026-39879
vim: CVE-2026-28417, CVE-2026-28418, CVE-2026-28419, CVE-2026-28420,
CVE-2026-28421, CVE-2026-28422, CVE-2026-32249, CVE-2026-33412,
CVE-2026-34714, CVE-2026-34982, CVE-2026-35177, CVE-2026-39881,
CVE-2026-41411, CVE-2026-42307, CVE-2026-44656, CVE-2026-45130,
CVE-2026-46483, CVE-2026-47162, CVE-2026-47167, CVE-2026-52858,
CVE-2026-52859, CVE-2026-52860, CVE-2026-55693, CVE-2026-55892,
CVE-2026-55895, CVE-2026-57451, CVE-2026-57452, CVE-2026-57453,
CVE-2026-57455, CVE-2026-57456, CVE-2026-59856, CVE-2026-59857,
CVE-2026-59858
wpa_supplicant: (no CVE assigned)
xlib_libXfont2: CVE-2026-56001, CVE-2026-56002, CVE-2026-56003
xserver_xorg-server: CVE-2026-55999, CVE-2026-56000
xwayland: CVE-2026-55999, CVE-2026-56000
Toolchain:
- gcc: fix mips/glibc build issue
- glibc: bump to 2.43-49-g8017bcfc4d
- linux-headers: bump to 5.10.265, 5.15.216, 6.1.183, 6.6.152,
6.12.104, 6.18.45, 7.0.14
- toolchain-buildroot: drop Synopsys ARC specific versions
- toolchain-external: drop Synopsys ARC toolchain
Infrastructure updates/fixes:
- Add license information for skeleton packages
- Make docker image reproducible again
- New runtime tests for guile, libgpiod2, mdnsd, php, python-pydal
Updated defconfigs: freescale_imx91frdm, freescale_imx93frdm
Removed defconfigs: acmesystems_aria_g25_{128mb, 256mb},
acmesystems_arietta_g25_{128mb, 256mb}, s6lx9_microboard, ts4900,
ts5500
Removed packages: argparse, ts4900-fpga
Updated / fixed packages: amazon-ecr-credential-helper, apache,
apr-util, arm-trusted-firmware, armadillo, at-spi2-core, atop, bind,
binutils, bitcoin, botan, busybox, cantarell, cifs-utils, clamav,
containerd, cramfs, dbus-broker, docker-credential-acr-env,
docker-credential-gcr, dracut, dropbear, environment-setup, exim,
expat, gcc, glibc, go, guile, gvfs, ifupdown-scripts, igt-gpu-tools,
initscripts, intel-microcode, libarchive, libass, libcamera, libgee,
libgit2, libglib2, libgpg-error, libgtk4, libgudev, libheif,
libmicrohttpd, libmodsecurity, libnpupnp, libpeas, librsvg,
libsecret, libsoup, libsoup3, libssh, libvpl, linux, linux-headers,
localedef, mbedtls, memcached, mini-snmpd, mosquitto, nettle,
network-manager, ntfs-3g, ogre, open62541, openblas, openssh,
openvpn, optee-os, p11-kit, pahole, perl, php, postgresql,
python-paho-mqtt, python-pydal, python-web2py, python3, quickjs,
redis, rsync, rygel, samba4, screen, ser2net, socat, stunnel,
syslog-ng, toolchain-external, uboot-tools, uclibc, ugetty,
urandom-scripts, usbutils, vim, wpa_supplicant, xlib_libXfont2,
xserver_xorg-server, xwayland, xz
2026.05.1, released July 15, 2026
Important / security related fixes:
@@ -1609,6 +1775,131 @@
- netsnmp: unexpected header length in /proc/net/snmp...
https://gitlab.com/buildroot.org/buildroot/-/issues/110
2025.02.17, released August 23, 2026
Important / security related fixes:
apr-util: CVE-2025-49506, CVE-2026-32327, CVE-2026-34191,
CVE-2026-34501, CVE-2026-34502
bind: CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605,
CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204,
CVE-2026-13321
botan: CVE-2026-32877, CVE-2026-32883, CVE-2026-32884, CVE-2026-34580,
CVE-2026-34582
busybox: CVE-2023-39810, CVE-2024-58251, CVE-2026-26157,
CVE-2026-26158, CVE-2026-29004
containerd: CVE-2026-35469, CVE-2026-46680, CVE-2026-47262,
CVE-2026-53488
dracut: CVE-2026-6893
dropbear: (no CVE assigned)
exim: GCVE-25-2026-07-45-1, CVE-2026-66140, CVE-2026-66141
expat: CVE-2026-72522
go: CVE-2026-39822
intel-microcode: CVE-2025-31936, CVE-2025-31938, CVE-2025-35973,
CVE-2026-20707, CVE-2026-20713, CVE-2026-20716, CVE-2026-20760,
CVE-2026-20917
libarchive: (no CVE assigned)
libass: CVE-2026-61626, CVE-2026-61627
libgcrypt: CVE-2026-41989
libgit2: CVE-2026-53583, CVE-2026-53584, CVE-2026-53585,
CVE-2026-53586, CVE-2026-53587
libheif: CVE-2026-62289, CVE-2026-62291, CVE-2026-62292,
CVE-2026-62377, GHSA-46rp-pcq2-rpmr, GHSA-73p7-m7gg-w2jv,
GHSA-9ww4-9v47-m7pj, GHSA-jc8f-p23p-5hjg, GHSA-xpw3-9rhw-482x
libmodsecurity: CVE-2026-52747, CVE-2026-52761
libssh: CVE-2026-15370, CVE-2026-59843, CVE-2026-59844, CVE-2026-59845,
CVE-2026-59846, CVE-2026-59847, CVE-2026-59848, CVE-2026-59849,
CVE-2026-59850
memcached: (no CVE assigned)
ntfs-3g: CVE-2026-42616, CVE-2026-42617, CVE-2026-42618,
CVE-2026-46569, CVE-2026-46570, CVE-2026-46571, CVE-2026-46572,
CVE-2026-56135, CVE-2026-56136
openssh: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997,
CVE-2026-59998, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001,
CVE-2026-60002
openvpn: CVE-2026-63649
perl: CVE-2026-13221, CVE-2026-57432, CVE-2026-8376
php: CVE-2026-17543, CVE-2026-7260, CVE-2026-9672
postgresql: CVE-2026-14662, CVE-2026-14663, CVE-2026-14664,
CVE-2026-14666, CVE-2026-14668, CVE-2026-14669, CVE-2026-14670,
CVE-2026-14671, CVE-2026-14672, CVE-2026-14673, CVE-2026-14676,
CVE-2026-14677, CVE-2026-14678, CVE-2026-14679, CVE-2026-14680,
CVE-2026-14681, CVE-2026-15741, CVE-2026-15742, CVE-2026-16238,
CVE-2026-16239, CVE-2026-16241, CVE-2026-18024, CVE-2026-18408,
CVE-2026-19385, CVE-2026-6464, CVE-2026-6469, CVE-2026-6470,
CVE-2026-6471
python3: CVE-2025-13462, CVE-2026-15308, CVE-2026-2297, CVE-2026-3644,
CVE-2026-4224, CVE-2026-4519, CVE-2026-7210
redis: (no CVE assigned)
rsync: CVE-2026-53783, CVE-2026-53784, CVE-2026-53785, CVE-2026-53786,
CVE-2026-53788, CVE-2026-53789, CVE-2026-53790, CVE-2026-53791,
CVE-2026-53792, CVE-2026-53793, CVE-2026-53794, CVE-2026-53795,
CVE-2026-53796, CVE-2026-53797, CVE-2026-53798, CVE-2026-53799,
CVE-2026-53800, CVE-2026-53801, CVE-2026-53802, CVE-2026-53803,
CVE-2026-70452, CVE-2026-70453, CVE-2026-70454, CVE-2026-70455,
CVE-2026-70456, CVE-2026-70457, CVE-2026-70458, CVE-2026-70459,
CVE-2026-70460, CVE-2026-70461, CVE-2026-70462, CVE-2026-70463,
CVE-2026-70464
samba4: CVE-2026-58216, CVE-2026-58218, CVE-2026-58221, CVE-2026-58222,
CVE-2026-58224, CVE-2026-6949
screen: (no CVE assigned)
ser2net: GHSA-cgh5-39mg-vhfr
socat: CVE-2026-56123
sqlite: CVE-2026-1182, CVE-2026-11822, CVE-2026-11824
stunnel: CVE-2026-70367, CVE-2026-70368
syslog-ng: CVE-2026-39879
util-linux: CVE-2026-13595
vim: CVE-2026-28417, CVE-2026-28418, CVE-2026-28419, CVE-2026-28420,
CVE-2026-28421, CVE-2026-28422, CVE-2026-32249, CVE-2026-33412,
CVE-2026-34714, CVE-2026-34982, CVE-2026-35177, CVE-2026-39881,
CVE-2026-41411, CVE-2026-42307, CVE-2026-44656, CVE-2026-45130,
CVE-2026-46483, CVE-2026-47162, CVE-2026-47167, CVE-2026-52858,
CVE-2026-52859, CVE-2026-52860, CVE-2026-55693, CVE-2026-55892,
CVE-2026-55895, CVE-2026-57451, CVE-2026-57452, CVE-2026-57453,
CVE-2026-57455, CVE-2026-57456, CVE-2026-59856, CVE-2026-59857,
CVE-2026-59858
wpa_supplicant: (no CVE assigned)
xlib_libXfont2: CVE-2026-56001, CVE-2026-56002, CVE-2026-56003
xserver_xorg-server: CVE-2026-55999, CVE-2026-56000
xwayland: CVE-2026-55999, CVE-2026-56000
Toolchain:
- toolchain-buildroot: drop Synopsys ARC specific GCC, binutils and gdb
- toolchain-external: drop Synopsys ARC toolchain
- linux-headers:: bump to 5.10.265, 5.15.216, 6.1.183, 6.6.152,
6.12.104
Infrastructure updates/fixes:
- Add license information for skeleton packages
- Make docker image reproducible again
- New runtime tests for guile, libgpiod2, mdnsd, php, python-pydal
Updated defconfigs: acmesystems_acqua_a5_*
Removed defconfigs: acmesystems_aria_g25_{128mb, 256mb},
acmesystems_arietta_g25_{128mb, 256mb}, s6lx9_microboard, ts4900,
ts5500
Removed packages: argparse, ts4900-fpga
Updated / fixed packages: apache, apr-util, arm-trusted-firmware,
at-spi2-core, bind, binutils, botan, busybox, cantarell, cifs-utils,
containerd, cramfs, dbus-broker, dracut, drop, dropbear,
environment-setup, exim, expat, glibc, go, guile, gvfs,
ifupdown-scripts, initscripts, intel-microcode, libarchive, libass,
libcamera, libgcrypt, libgee, libgit2, libglib2, libgpg-error,
libgtk4, libgudev, libheif, libmicrohttpd, libmodsecurity, libpeas,
librsvg, libsecret, libsoup, libsoup3, libssh, linux, linux-headers:,
localedef, mbedtls, memcached, mini-snmpd, nettle, ntfs-3g, ogre,
open62541, openblas, openssh, openvpn, optee-os, p11-kit, pahole,
perl, php, postgresql, python-paho-mqtt, python-pydal, python-web2py,
python3, qt6, quickjs, redis, rsync, rygel, samba4, screen, ser2net,
socat, sqlite, stunnel, syslog-ng, uclibc, urandom-scripts, usbutils,
util-linux, vim, wpa_supplicant, xlib_libXfont2, xserver_xorg-server,
xwayland, xz
2025.02.16, released July 15, 2026
Important / security related fixes:

View File

@@ -146,6 +146,12 @@ endif
comment "Legacy options removed in 2026.08"
config BR2_PACKAGE_FLUIDSYNTH_SDL2
bool "fluidsynth sdl2 audio support removed"
select BR2_LEGACY
help
FluidSynth SDL2 audio support was removed in v2.5.0.
config BR2_PACKAGE_HOSTAPD_DRIVER_HOSTAP
bool "hostapd hostap driver removed"
select BR2_LEGACY

View File

@@ -712,7 +712,7 @@ F: package/perl-sys-mmap/
F: package/perl-time-parsedate/
F: package/perl-x10/
N: Christopher Obbard <obbardc@gmail.com>
N: Christopher Obbard <chris.obbard@oss.qualcomm.com>
F: package/dtui/
N: Colin Foster <colin.foster@in-advantage.com>
@@ -1856,6 +1856,8 @@ F: support/testing/tests/boot/test_optee_os.py
F: support/testing/tests/boot/test_optee_os/
F: support/testing/tests/fs/test_btrfs.py
F: support/testing/tests/fs/test_btrfs/
F: support/testing/tests/fs/test_cramfs.py
F: support/testing/tests/fs/test_cramfs/
F: support/testing/tests/fs/test_erofs.py
F: support/testing/tests/fs/test_erofs/
F: support/testing/tests/fs/test_xfs.py
@@ -2028,6 +2030,8 @@ F: support/testing/tests/package/test_python_pyqt5.py
F: support/testing/tests/package/test_python_pyqt5/
F: support/testing/tests/package/test_python_spake2.py
F: support/testing/tests/package/test_python_sympy.py
F: support/testing/tests/package/test_quickjs.py
F: support/testing/tests/package/test_quickjs/
F: support/testing/tests/package/test_rdma_core.py
F: support/testing/tests/package/test_rdma_core/
F: support/testing/tests/package/test_rrdtool.py
@@ -2061,6 +2065,8 @@ F: support/testing/tests/package/test_weston/
F: support/testing/tests/package/test_wget.py
F: support/testing/tests/package/test_which.py
F: support/testing/tests/package/test_wine.py
F: support/testing/tests/package/test_wpa_supplicant.py
F: support/testing/tests/package/test_wpa_supplicant/
F: support/testing/tests/package/test_xfsprogs.py
F: support/testing/tests/package/test_xfsprogs/
F: support/testing/tests/package/test_xvisor.py
@@ -2715,6 +2721,7 @@ F: package/wireguard-linux-compat/
F: package/wireguard-tools/
F: support/testing/tests/package/test_agec.py
F: support/testing/tests/package/test_docker_compose.py
F: support/testing/tests/package/test_haproxy.py
F: support/testing/tests/package/test_python_hid.py
N: Peter Seiderer <ps.report@gmx.net>
@@ -3297,6 +3304,8 @@ F: support/testing/tests/package/sample_python_flask_expects_json.py
F: support/testing/tests/package/sample_python_git.py
F: support/testing/tests/package/sample_python_pyudev.py
F: support/testing/tests/package/sample_python_unittest_xml_reporting.py
F: support/testing/tests/package/test_bpftrace.py
F: support/testing/tests/package/test_bpftrace/linux-bpftrace.fragment
F: support/testing/tests/package/test_nodejs.py
F: support/testing/tests/package/test_python_augeas.py
F: support/testing/tests/package/test_python_crccheck.py
@@ -3517,6 +3526,7 @@ F: package/tpm2-pkcs11/
N: Yann E. MORIN <yann.morin@orange.com>
F: .editorconfig
F: package/amazon-ecr-credential-helper/
F: package/distribution-registry/
F: package/docker-credential-acr-env/
F: package/docker-credential-gcr/
F: package/gpsd/

View File

@@ -92,9 +92,9 @@ all:
.PHONY: all
# Set and export the version string
export BR2_VERSION := 2026.08-rc1
export BR2_VERSION := 2026.08
# Actual time the release is cut (for reproducible builds)
BR2_VERSION_EPOCH = 1787088000
BR2_VERSION_EPOCH = 1788535000
# Save running make version since it's clobbered by the make package
RUNNING_MAKE_VERSION := $(MAKE_VERSION)

View File

@@ -3,6 +3,7 @@ CONFIG_SMP=y
CONFIG_HYPERVISOR_GUEST=y
CONFIG_PARAVIRT=y
CONFIG_EFI=y
CONFIG_EFI_STUB=y
# CONFIG_GCC_PLUGINS is not set
CONFIG_MODULES=y
CONFIG_MODULE_UNLOAD=y

View File

@@ -0,0 +1,36 @@
From 5358d4e20801ffbb1c0834eab36c003049d4055f Mon Sep 17 00:00:00 2001
From: Romain Naour <romain.naour@smile.fr>
Date: Sun, 16 Aug 2026 22:27:28 +0200
Subject: [PATCH] xtensa: disable SSP when needed
-fno-stack-protector must be passed to avoid linking errors related to
undefined references to '__stack_chk_guard' and '__stack_chk_fail' if
toolchain enforces -fstack-protector.
Fixes:
https://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15876432953
Upstream: Submitted to Max Filippov via email for initial review.
Cc: Max Filippov <jcmvbkbc@gmail.com>
Signed-off-by: Romain Naour <romain.naour@smile.fr>
---
arch/xtensa/boot/Makefile | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/xtensa/boot/Makefile b/arch/xtensa/boot/Makefile
index d8b0fadf429a9..dfb758cdb2756 100644
--- a/arch/xtensa/boot/Makefile
+++ b/arch/xtensa/boot/Makefile
@@ -9,7 +9,7 @@
# KBUILD_CFLAGS used when building rest of boot (takes effect recursively)
-KBUILD_CFLAGS += -fno-builtin
+KBUILD_CFLAGS += -fno-builtin -fno-stack-protector
subdir-y := lib
targets += vmlinux.bin vmlinux.bin.gz
--
2.55.0

View File

@@ -53,7 +53,8 @@ define XILINX_EMBEDDEDSW_BUILD_VERSAL2_PLM
COMPILER=$(XILINX_EMBEDDEDSW_MICROBLAZE_CC) \
ARCHIVER=$(XILINX_EMBEDDEDSW_MICROBLAZE_AR) \
CC=$(XILINX_EMBEDDEDSW_MICROBLAZE_CC) \
CFLAGS=$(XILINX_EMBEDDEDSW_CFLAGS)
CFLAGS=$(XILINX_EMBEDDEDSW_CFLAGS) \
XILPM_RUNTIME_LIB=SUBSYS
endef
define XILINX_EMBEDDEDSW_INSTALL_VERSAL2_PLM

View File

@@ -2,7 +2,7 @@ BR2_xtensa=y
BR2_XTENSA_CUSTOM=y
BR2_XTENSA_OVERLAY_FILE="https://github.com/jcmvbkbc/xtensa-toolchain-build/raw/95291b7c39e6f790d0b2f062c945a630290f2c81/overlays/xtensa_dc233c.tar.gz"
BR2_PACKAGE_HOST_LINUX_HEADERS_CUSTOM_6_18=y
BR2_GLOBAL_PATCH_DIR="board/qemu/patches"
BR2_GLOBAL_PATCH_DIR="board/qemu/patches board/qemu/xtensa-lx60/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_TARGET_GENERIC_GETTY_PORT="ttyS0"
BR2_SYSTEM_DHCP="eth0"

View File

@@ -3,7 +3,7 @@ BR2_XTENSA_CUSTOM=y
BR2_XTENSA_OVERLAY_FILE="https://github.com/jcmvbkbc/xtensa-toolchain-build/raw/95291b7c39e6f790d0b2f062c945a630290f2c81/overlays/xtensa_dc233c.tar.gz"
# BR2_XTENSA_USE_MMU is not set
BR2_PACKAGE_HOST_LINUX_HEADERS_CUSTOM_6_18=y
BR2_GLOBAL_PATCH_DIR="board/qemu/patches"
BR2_GLOBAL_PATCH_DIR="board/qemu/patches board/qemu/xtensa-lx60/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_TARGET_GENERIC_GETTY_PORT="ttyS0"
BR2_SYSTEM_DHCP="eth0"

View File

@@ -25,7 +25,7 @@ BR2_TARGET_ARM_TRUSTED_FIRMWARE_CUSTOM_TARBALL=y
BR2_TARGET_ARM_TRUSTED_FIRMWARE_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,arm-trusted-firmware,xlnx-rebase-v2.14_2026.1)/xlnx-rebase-v2.14_2026.1.tar.gz"
BR2_TARGET_ARM_TRUSTED_FIRMWARE_PLATFORM="versal2"
BR2_TARGET_ARM_TRUSTED_FIRMWARE_BL31_UBOOT=y
BR2_TARGET_ARM_TRUSTED_FIRMWARE_ADDITIONAL_VARIABLES="VERSAL2_CONSOLE=cadence1"
BR2_TARGET_ARM_TRUSTED_FIRMWARE_BL32_OPTEE=y
BR2_TARGET_OPTEE_OS=y
BR2_TARGET_OPTEE_OS_CUSTOM_TARBALL=y
BR2_TARGET_OPTEE_OS_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,optee_os,xlnx-rebase-v4.9.0_2026.1)/xlnx-rebase-v4.9.0_2026.1.tar.gz"

View File

@@ -460,7 +460,7 @@ editing the commit message. Below the +Signed-off-by+ section, add
Although the changelog will be visible for the reviewers in the mail
thread, as well as in
https://patchwork.ozlabs.org/project/buildroot/list/[patchwork], +git+
https://patchwork.buildroot.org/project/buildroot/list/[patchwork], +git+
will automatically ignores lines below +---+ when the patch will be
merged. This is the intended behavior: the changelog is not meant to
be preserved forever in the +git+ history of the project.
@@ -513,19 +513,19 @@ $ git format-patch -v4 -M -s -o outgoing origin/master
When you provide a new version of a patch, please mark the old one as
superseded in
https://patchwork.ozlabs.org/project/buildroot/list/[patchwork]. You
https://patchwork.buildroot.org/project/buildroot/list/[patchwork]. You
need to create an account on
https://patchwork.ozlabs.org/project/buildroot/list/[patchwork] to be
https://patchwork.buildroot.org/project/buildroot/list/[patchwork] to be
able to modify the status of your patches. Note that you can only change
the status of patches you submitted yourself, which means the email
address you register in
https://patchwork.ozlabs.org/project/buildroot/list/[patchwork] should
https://patchwork.buildroot.org/project/buildroot/list/[patchwork] should
match the one you use for sending patches to the mailing list.
You can also add the +--in-reply-to=<message-id>+ option when
submitting a patch to the mailing list. The id of the mail to reply to
can be found under the "Message Id" tag on
https://patchwork.ozlabs.org/project/buildroot/list/[patchwork]. The
https://patchwork.buildroot.org/project/buildroot/list/[patchwork]. The
advantage of *in-reply-to* is that patchwork will automatically mark
the previous version of the patch as superseded.
@@ -664,7 +664,7 @@ Creating a basic test case involves:
advantage of using +infra.basetest.BASIC_TOOLCHAIN_CONFIG+ is that a
matching Linux kernel image is provided, which allows to boot the
resulting image in Qemu without having to build a Linux kernel image
as part of the test case, therefore significant decreasing the build
as part of the test case, therefore significantly decreasing the build
time required for the test case.
* Implementing a +def test_run(self):+ function to implement the

View File

@@ -23,8 +23,8 @@ to you.
| +-- linux.config
| +-- busybox.config
| +-- <other configuration files>
| +-- post_build.sh
| +-- post_image.sh
| +-- post-build.sh
| +-- post-image.sh
| +-- rootfs_overlay/
| | +-- etc/
| | +-- <some files>
@@ -84,7 +84,7 @@ layers 'common' and 'fooboard' is:
+-- board/
+-- <company>/
+-- common/
| +-- post_build.sh
| +-- post-build.sh
| +-- rootfs_overlay/
| | +-- ...
| +-- patches/
@@ -94,7 +94,7 @@ layers 'common' and 'fooboard' is:
+-- linux.config
+-- busybox.config
+-- <other configuration files>
+-- post_build.sh
+-- post-build.sh
+-- rootfs_overlay/
| +-- ...
+-- patches/

View File

@@ -35,9 +35,9 @@ your project can be skipped.
Set +BR2_ROOTFS_OVERLAY+
to +board/<manufacturer>/<boardname>/rootfs-overlay+.
. Create a post-build script
+board/<manufacturer>/<boardname>/post_build.sh+. Set
+board/<manufacturer>/<boardname>/post-build.sh+. Set
+BR2_ROOTFS_POST_BUILD_SCRIPT+ to
+board/<manufacturer>/<boardname>/post_build.sh+
+board/<manufacturer>/<boardname>/post-build.sh+
. If additional setuid permissions have to be set or device nodes have
to be created, create +board/<manufacturer>/<boardname>/device_table.txt+
and add that path to +BR2_ROOTFS_DEVICE_TABLE+.

View File

@@ -52,7 +52,7 @@ Using post-build scripts, you can remove or modify any file in your
post-build cleanup scripts.
+
As shown in xref:customize-dir-structure[], the recommended path for
this script is +board/<company>/<boardname>/post_build.sh+.
this script is +board/<company>/<boardname>/post-build.sh+.
+
The post-build scripts are run with the main Buildroot tree as current
working directory. The path to the target filesystem is passed as the

View File

@@ -15,14 +15,14 @@ available in `support/misc/Vagrantfile` in the Buildroot source tree
to quickly set up a virtual machine with the needed dependencies to
get started.
If you want to setup an isolated buildroot environment on Linux or Mac
Os X, paste this line onto your terminal:
If you want to set up an isolated Buildroot environment on Linux or Mac
OS X, paste this line into your terminal:
----
curl -O https://buildroot.org/downloads/Vagrantfile; vagrant up
----
If you are on Windows, paste this into your powershell:
If you are on Windows, paste this into your PowerShell:
----
(new-object System.Net.WebClient).DownloadFile(

View File

@@ -16,11 +16,11 @@ filesystem with Buildroot).
Buildroot is useful mainly for people working with embedded systems.
Embedded systems often use processors that are not the regular x86
processors everyone is used to having in his PC. They can be PowerPC
processors, MIPS processors, ARM processors, etc.
processors developers are used to having in their PCs, including
ARM (both 32- and 64-bit), MIPS, PowerPC, RISC-V and more.
Buildroot supports numerous processors and their variants; it also
comes with default configurations for several boards available
comes with default configurations for hundreds of boards available
off-the-shelf. Besides this, a number of third-party projects are based on,
or develop their BSP footnote:[BSP: Board Support Package] or
SDK footnote:[SDK: Software Development Kit] on top of Buildroot.

View File

@@ -5,19 +5,21 @@
== Release Engineering
=== Releases
The Buildroot project makes quarterly releases with monthly bugfix
releases. The first release of each year is a long term support
release, LTS.
The Buildroot project makes quarterly stable releases with monthly bugfix
releases. Starting with 2025.02, the first release of every odd-numbered year
is a long-term support (LTS) release supported for three years.
- Quarterly releases: 2020.02, 2020.05, 2020.08, and 2020.11
- Bugfix releases: 2020.02.1, 2020.02.2, ...
- LTS releases: 2020.02, 2021.02, ...
- LTS releases: 2025.02, 2027.02, 2029.02 ...
- Non-LTS releases: 2025.05, 2025.08, 2025.11, 2026.02, ...
- Bugfix releases: 2025.02.1, 2025.02.2, ...
Releases are supported until the first bugfix release of the next
release, e.g., 2020.05.x is EOL when 2020.08.1 is released.
LTS releases are supported for three years, with a one-year overlap with the
next LTS release, e.g., 2025.02.x is EOL when 2028.02 is released.
LTS releases are supported until the first bugfix release of the next
LTS, e.g., 2020.02.x is supported until 2021.02.1 is released.
Non-LTS releases are supported until the next release, e.g., 2025.05.x is EOL
when 2025.08 is released.
See the table at https://lts.buildroot.org/#releases[lts.buildroot.org].
=== Development

View File

@@ -68,4 +68,4 @@ review comments in a clean and concise web interface, it can be useful
for all Buildroot developers.
+
The Buildroot patch management interface is available at
https://patchwork.ozlabs.org/project/buildroot/list/[].
https://patchwork.buildroot.org/project/buildroot/list/[].

View File

@@ -18,7 +18,7 @@
autobuild failures</a></li>
<li>Reviewing and testing patches sent by other developers. See the
<a href="https://lists.buildroot.org/mailman/listinfo/buildroot">mailing list
</a> or <a href="https://patchwork.ozlabs.org/project/buildroot/list/">
</a> or <a href="https://patchwork.buildroot.org/project/buildroot/list/">
patchwork</a>.</li>
<li>Working on items from the
<a href="https://www.elinux.org/Buildroot#Todo_list">TODO list</a></li>

View File

@@ -16,56 +16,58 @@
<th>Latest release date</th>
<th colspan="2">Downloads</td>
</tr>
<!--
<tr>
<th>Candidate</th>
<th>2026.08.x</th>
<td>December 2026</td>
<td>
2026.08-rc1<br/>
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2026.08-rc1/CHANGES">
2026.08-rc3<br/>
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2026.08-rc3/CHANGES">
Changelog
</a>
</td>
<td>2026-08-18</td>
<td>2026-08-23</td>
<td>
<a href="/downloads/buildroot-2026.08-rc1.tar.gz">
<a href="/downloads/buildroot-2026.08-rc3.tar.gz">
<img src="images/zip.png" width="24" alt="">
.tar.gz
</a><br/>
<a href="/downloads/buildroot-2026.08-rc1.tar.gz.sign">[PGP sig]</a>
<a href="/downloads/buildroot-2026.08-rc3.tar.gz.sign">[PGP sig]</a>
</td>
<td>
<a href="/downloads/buildroot-2026.08-rc1.tar.xz">
<a href="/downloads/buildroot-2026.08-rc3.tar.xz">
<img src="images/package.png" width="24" alt="">
.tar.xz
</a><br/>
<a href="/downloads/buildroot-2026.08-rc1.tar.xz.sign">[PGP sig]</a>
<a href="/downloads/buildroot-2026.08-rc3.tar.xz.sign">[PGP sig]</a>
</td>
</tr>
-->
<tr>
<th>Stable</th>
<th>2026.05.1.x</th>
<td>September 2026</td>
<th>2026.08.x</th>
<td>December 2026</td>
<td>
2026.05.1<br/>
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2026.05.1/CHANGES">
2026.08<br/>
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2026.08/CHANGES">
Changelog
</a>
</td>
<td>2026-07-15</td>
<td>2026-09-04</td>
<td>
<a href="/downloads/buildroot-2026.05.1.tar.gz">
<a href="/downloads/buildroot-2026.08.tar.gz">
<img src="images/zip.png" width="24" alt="">
.tar.gz
</a><br/>
<a href="/downloads/buildroot-2026.05.1.tar.gz.sign">[PGP sig]</a>
<a href="/downloads/buildroot-2026.08.tar.gz.sign">[PGP sig]</a>
</td>
<td>
<a href="/downloads/buildroot-2026.05.1.tar.xz">
<a href="/downloads/buildroot-2026.08.tar.xz">
<img src="images/package.png" width="24" alt="">
.tar.xz
</a><br/>
<a href="/downloads/buildroot-2026.05.1.tar.xz.sign">[PGP sig]</a>
<a href="/downloads/buildroot-2026.08.tar.xz.sign">[PGP sig]</a>
</td>
</tr>
<tr>
@@ -73,25 +75,25 @@
<th>2025.02.x</th>
<td>March 2028</td>
<td>
2025.02.16<br/>
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2025.02.16/CHANGES">
2025.02.17<br/>
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2025.02.17/CHANGES">
Changelog
</a>
</td>
<td>2026-07-15</td>
<td>2026-08-23</td>
<td>
<a href="/downloads/buildroot-2025.02.16.tar.gz">
<a href="/downloads/buildroot-2025.02.17.tar.gz">
<img src="images/zip.png" width="24" alt="">
.tar.gz
</a><br/>
<a href="/downloads/buildroot-2025.02.16.tar.gz.sign">[PGP sig]</a>
<a href="/downloads/buildroot-2025.02.17.tar.gz.sign">[PGP sig]</a>
</td>
<td>
<a href="/downloads/buildroot-2025.02.16.tar.xz">
<a href="/downloads/buildroot-2025.02.17.tar.xz">
<img src="images/package.png" width="24" alt="">
.tar.xz
</a><br/>
<a href="/downloads/buildroot-2025.02.16.tar.xz.sign">[PGP sig]</a>
<a href="/downloads/buildroot-2025.02.17.tar.xz.sign">[PGP sig]</a>
</td>
</tr>
</table>

Binary file not shown.

After

Width:  |  Height:  |  Size: 5.4 KiB

View File

@@ -46,7 +46,7 @@
<p class="br-lts-item-text">
Tracking of the vulnerabilities affecting Buildroot
is available at
<a href="https://security.buildroot.org/2025.02.x/vulnerability">security.buildroot.org</a>.
<a href="https://security.buildroot.org/">security.buildroot.org</a>.
<br/>
LTS stewards ensure this data remains up-to-date by actively
maintaining Buildroot packages metadata.
@@ -80,7 +80,7 @@
</h2>
<p class="br-lts-item-text">
Vulnerability fixes applied to the <code>master</code> branch will be
prioritized for backporting to the LTS & stable branches.
prioritized for backporting to stable branches.
</p>
</div>
</div>
@@ -98,9 +98,9 @@
<br/>
To address these requirements, the release model evolves into the following.
<br/>
The LTS releases are now extended for a 3-year period. An LTS release
is started every 2 years.
In between, stable releases are made every 3 months.
Starting with 2025.02, the first release of every odd-numbered year is a long-term
support (LTS) release supported for three years.
In between, non-LTS releases are made every 3 months.
</p>
<br/>
@@ -166,10 +166,6 @@
<br/>
<br/>
<p>
More details about the LTS workflow at <a href="https://gitlab.com/buildroot.org/buildroot-lts-tools">buildroot.org/buildroot-lts-tools</a>.
</p>
<div id="organization" class="br-lts-section-header">
<div class="br-lts-bg-grid"></div>
<div class="br-lts-title-box">How we work</div>
@@ -181,12 +177,28 @@
analyze based on the previous week's commits to the master branch. The
commits are then annotated to define a list of candidates for the LTS
branches.
<br><br>
On Thursday, the candidates are cherry-picked to a staging branch to be
reviewed by the other maintainers. On Thursday evening the branch is
synced with upstream and contributors are notified. Feedback from
users, sponsors and autobuilders are then collected and vulnerability
analyses updated.
</p>
<p>
Mid-week, the candidates are cherry-picked to a staging branch hosted on
<a href="https://gitlab.com/essensium-mind/buildroot/">gitlab.com/essensium-mind/buildroot</a>.
Every maintained branch has a staging branch, with the <code>.x</code>
suffix replaced by <code>.pre</code>. The staging branch allows other
maintainers to review the changes before they are pushed upstream.
</p>
<p>
By the end of the week, the staging branches are pushed upstream and
contributors are notified. Feedback from users, sponsors and
<a href="https://autobuild.buildroot.org/">autobuilders</a>
are then collected and
<a href="https://security.buildroot.org/">vulnerability analyses</a>
updated.
</p>
<p>
For more information about the development workflow, see the
<a href="https://gitlab.com/buildroot.org/buildroot-lts-tools/-/blob/main/tools/README.md">documentation</a>.
</p>
<br/>
@@ -222,13 +234,13 @@
</div>
<div class="br-lts-chart-row br-lts-chart-row--tall">
<div class="br-lts-chart-label">Sync with upstream branch</div>
<div class="br-lts-bar br-lts-col-start-9"></div>
<div class="br-lts-chart-label">Push to upstream branch</div>
<div class="br-lts-bar br-lts-bar--span-2 br-lts-col-start-9"></div>
</div>
<div class="br-lts-chart-row br-lts-chart-row--tall">
<div class="br-lts-chart-label">Update vulns</div>
<div class="br-lts-bar br-lts-col-start-10"></div>
<div class="br-lts-bar br-lts-bar--span-2 br-lts-col-start-10"></div>
</div>
</div>
@@ -316,7 +328,7 @@
To make sure the packages of interest to the sponsors don't
include regressions between releases.
Sponsors may submit a list of packages to be tested
before an LTS & stable release.
before a bugfix release.
</p>
</div>
</div>

View File

@@ -9,6 +9,104 @@
<h2>News</h2>
<ul class="timeline">
<li class="timeline-inverted">
<div class="timeline-badge"><i class="glyphicon glyphicon-thumbs-up"></i></div>
<div class="timeline-panel">
<div class="timeline-heading">
<h4 class="timeline-title">2026.08 released</h4>
<p><small class="text-muted"><i class="glyphicon glyphicon-time"></i>4 September 2026</small></p>
</div>
<div class="timeline-body">
<p>The stable 2026.08 release is out - Thanks to everyone
contributing and testing the release candidates. See the
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2026.08/CHANGES">CHANGES</a>
file for more details
and go to the <a href="/downloads/">downloads page</a> to pick up the
<a href="/downloads/buildroot-2026.08.tar.xz">2026.08 release</a>.</p>
</div>
</div>
</li>
<li>
<div class="timeline-badge"><i class="glyphicon glyphicon-thumbs-up"></i></div>
<div class="timeline-panel">
<div class="timeline-heading">
<h4 class="timeline-title">2026.08-rc3 released</h4>
<p><small class="text-muted"><i class="glyphicon glyphicon-time"></i>29 August 2026</small></p>
</div>
<div class="timeline-body">
<p>Another week, another release candidate with more cleanups and build fixes. See the
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2026.08-rc3/CHANGES">CHANGES</a>
file for more details.</p>
<p>Go to the <a href="/downloads/">downloads page</a> to pick up the
<a href="/downloads/buildroot-2026.08-rc3.tar.xz">2026.08-rc3
release</a>, and report any problems found to the
<a href="support.html">mailing list</a> or
<a href="https://gitlab.com/buildroot.org/buildroot/-/issues">bug tracker</a>.</p>
</div>
</div>
</li>
<li class="timeline-inverted">
<div class="timeline-badge"><i class="glyphicon glyphicon-thumbs-up"></i></div>
<div class="timeline-panel">
<div class="timeline-heading">
<h4 class="timeline-title">2026.08-rc2 released</h4>
<p><small class="text-muted"><i class="glyphicon glyphicon-time"></i>23 August 2026</small></p>
</div>
<div class="timeline-body">
<p>Another week, another release candidate with more cleanups and build fixes. See the
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2026.08-rc2/CHANGES">CHANGES</a>
file for more details.</p>
<p>Go to the <a href="/downloads/">downloads page</a> to pick up the
<a href="/downloads/buildroot-2026.08-rc2.tar.xz">2026.08-rc2
release</a>, and report any problems found to the
<a href="support.html">mailing list</a> or
<a href="https://gitlab.com/buildroot.org/buildroot/-/issues">bug tracker</a>.</p>
</div>
</div>
</li>
<li class="timeline">
<div class="timeline-badge"><i class="glyphicon glyphicon-thumbs-up"></i></div>
<div class="timeline-panel">
<div class="timeline-heading">
<h4 class="timeline-title">2026.05.2 released</h4>
<p><small class="text-muted"><i class="glyphicon glyphicon-time"></i>23 August 2026</small></p>
</div>
<div class="timeline-body">
<p>The 2026.05.2 bugfix release is out, fixing a number of important /
security related issues discovered since the 2026.05.1 release. See the
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2026.05.2/CHANGES">CHANGES</a>
file for more details, read the
<a href="https://lore.kernel.org/buildroot/buildroot-2026.05.2-announce-1787518882@buildroot.org/T/#u">announcement</a>
and go to the <a href="/downloads/">downloads page</a> to pick up the
<a href="/downloads/buildroot-2026.05.2.tar.xz">2026.05.2 release</a>.</p>
</div>
</div>
</li>
<li class="timeline-inverted">
<div class="timeline-badge"><i class="glyphicon glyphicon-thumbs-up"></i></div>
<div class="timeline-panel">
<div class="timeline-heading">
<h4 class="timeline-title">2025.02.17 released</h4>
<p><small class="text-muted"><i class="glyphicon glyphicon-time"></i>23 August 2026</small></p>
</div>
<div class="timeline-body">
<p>The 2025.02.17 bugfix release is out, fixing a number of important /
security related issues discovered since the 2025.02.16 release. See the
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2025.02.17/CHANGES">CHANGES</a>
file for more details, read the
<a href="https://lore.kernel.org/buildroot/buildroot-2025.02.17-announce-1787518716@buildroot.org/T/#u">announcement</a>
and go to the <a href="/downloads/">downloads page</a> to pick up the
<a href="/downloads/buildroot-2025.02.17.tar.xz">2025.02.17 release</a>.</p>
</div>
</div>
</li>
<li>
<div class="timeline-badge"><i class="glyphicon glyphicon-thumbs-up"></i></div>
<div class="timeline-panel">

View File

@@ -68,6 +68,20 @@
</div>
</div>
</div>
<div class="sponsor-entry">
<div class="panel panel-default panel-lts-sponsor">
<div class="panel-body">
<div class="sponsor-title">
<a href="https://othermo.de/">
<img class="img-responsive center-block" style="width: 100%;" src="images/othermo-logo.png"/>
</a>
</div>
<div class="sponsor-body">
<a href="https://othermo.de">Othermo</a>
</div>
</div>
</div>
</div>
</div>
</div>

View File

@@ -143,7 +143,7 @@ config BR2_LINUX_KERNEL_CUSTOM_REPO_GIT_SUBMODULES
config BR2_LINUX_KERNEL_VERSION
string
default "7.1.8" if BR2_LINUX_KERNEL_LATEST_VERSION
default "7.1.13" if BR2_LINUX_KERNEL_LATEST_VERSION
default "5.10.254-cip72" if BR2_LINUX_KERNEL_LATEST_CIP_VERSION
default "5.10.254-cip72-rt32" if BR2_LINUX_KERNEL_LATEST_CIP_RT_VERSION
default BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE \

View File

@@ -1,10 +1,10 @@
# From https://www.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
sha256 f143aaade8877ba5616e788b4482576db28481bcf557ef537f4fcc3938fc3176 linux-6.12.103.tar.xz
sha256 de01e5ae73412b70bceb41a6f97da6d0f29b6536f1f00f8b6a6fd40c729969f7 linux-6.6.151.tar.xz
sha256 f38416bb6e8024a21ae868c7f29cd15293a73755e3484c7f2f4adea5b03c1f85 linux-6.1.182.tar.xz
sha256 e1d1ea200d22d55c9f5d5fae59e69bb3b494515705fc3390cd54231ee4f4baaf linux-6.12.108.tar.xz
sha256 aee2264a4eaf4a14344b47a0469bd42e8b4885b24f110b724262b3da956f411d linux-6.6.156.tar.xz
sha256 1b6e798aeaa708ca670a426ad5a6c86dc2237b8e59e8822876976c383873642b linux-6.1.187.tar.xz
# From https://www.kernel.org/pub/linux/kernel/v5.x/sha256sums.asc
sha256 d57f279da0813fa6d69fb2e59cf9a364be4faa1cd18cb76b0b64c074fd23b7a7 linux-5.15.215.tar.xz
sha256 f27552ec32783512c81918c3b8f155fed8dbaf8a90a5a20afdc01aac715b489e linux-5.10.264.tar.xz
sha256 b5b2992505120ac864cd9ccf7cc44541684df46c5a0b09ccdec93fb7f9aa6723 linux-5.15.220.tar.xz
sha256 9c5a168119406674ff3bcf366a3a235206eecfa7b79f04629b31a7cc678cc6e9 linux-5.10.269.tar.xz
# Locally computed
sha256 bd5db7fe3b0475cce4fc72db7a7f7df1c22b970aabe5ebff6ddd48098973bdf2 linux-cip-5.10.254-cip72.tar.gz
sha256 97d7d5139900c10ff7435779be4857dda531e7cf6abba52c12a5f39aae195411 linux-cip-5.10.254-cip72-rt32.tar.gz

View File

@@ -1,8 +1,8 @@
# From https://www.kernel.org/pub/linux/kernel/v7.x/sha256sums.asc
sha256 ff01dcb449279d5b4cfccdb01fee639cf5ff1803f1749a77844dd33915422c49 linux-7.1.8.tar.xz
sha256 614d95fafdcb5cce2b6620e7edc6afbb606bffd4655405586815d84687841ad7 linux-7.1.13.tar.xz
# From https://www.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
sha256 0f72d938f06828e82c90405174fe572287db7bfe089e2fc46572a99a7f240d43 linux-6.18.44.tar.xz
sha256 ae826f33111fea6f1d279dde7299d7463c8dfd204aeb75a8fb5432bc60a28191 linux-6.18.49.tar.xz
# Licenses hashes
sha256 fb5a425bd3b3cd6071a3a9aff9909a859e7c1158d54d32e07658398cd67eb6a0 COPYING

View File

@@ -419,6 +419,17 @@ define LINUX_KCONFIG_FIXUP_CMDS_ROOTFS_CPIO
endef
endif
# Since kernel >= 6.15.y, x86 and x86_64 kernels requires a toolchain
# with SSP support when CONFIG_STACKPROTECTOR is enabled.
# For toolchains without SSP support, make sure to disable
# CONFIG_STACKPROTECTOR to avoid link issues when building kernel
# modules.
ifeq ($(BR2_i386)$(BR2_x86_64):$(BR2_TOOLCHAIN_HAS_SSP),y:)
define LINUX_FIXUP_CONFIG_STACKPROTECTOR
$(call KCONFIG_DISABLE_OPT,CONFIG_STACKPROTECTOR)
endef
endif
define LINUX_KCONFIG_FIXUP_CMDS
@$(call MESSAGE,"Updating kernel config with fixups")
$(if $(LINUX_NEEDS_MODULES),
@@ -429,6 +440,7 @@ define LINUX_KCONFIG_FIXUP_CMDS
)
$(LINUX_FIXUP_CONFIG_ENDIANNESS)
$(LINUX_FIXUP_CONFIG_PAHOLE_CHECK)
$(LINUX_FIXUP_CONFIG_STACKPROTECTOR)
$(if $(BR2_arm)$(BR2_armeb),
$(call KCONFIG_ENABLE_OPT,CONFIG_AEABI))
$(if $(BR2_powerpc)$(BR2_powerpc64)$(BR2_powerpc64le),

View File

@@ -218,7 +218,7 @@ ifeq ($(BR2_riscv),y)
TARGET_CFLAGS += -fPIC
endif
ELF2FLT_FLAGS = $(if $($(PKG)_FLAT_STACKSIZE),\
-Wl$(comma)-elf2flt="-r -s$($(PKG)_FLAT_STACKSIZE)",\
-Wl$(comma)-elf2flt=-r -Wl$(comma)-elf2flt=-s$($(PKG)_FLAT_STACKSIZE),\
-Wl$(comma)-elf2flt=-r)
TARGET_CFLAGS += $(ELF2FLT_FLAGS)
TARGET_CXXFLAGS += $(ELF2FLT_FLAGS)

View File

@@ -1,3 +1,3 @@
# Locally computed
sha256 b64e31b94719499549622aa92f1d96d1742967ced261a0931b63be3bbe907f2c avro-c-1.12.1.tar.gz
# From https://downloads.apache.org/avro/avro-1.12.2/c/avro-c-1.12.2.tar.gz.sha512
sha512 bed6a7e324e7cac52d2bdfe0a596ab90c32c0f99ffecb517a72e465dad5fcfddc49dbfde0efa33e4c8ad73f2e97ad2c90d52f31a51f55b05576a9b36b2c3546b avro-c-1.12.2.tar.gz
sha256 d62488d6ba17132e92c23c03c80bfedc848267f96ab36489fec860f76cf6819a LICENSE

View File

@@ -5,8 +5,8 @@
################################################################################
# When updating the version, please also update python-avro
AVRO_C_VERSION = 1.12.1
AVRO_C_SITE = https://www-eu.apache.org/dist/avro/avro-$(AVRO_C_VERSION)/c
AVRO_C_VERSION = 1.12.2
AVRO_C_SITE = https://downloads.apache.org/avro/avro-$(AVRO_C_VERSION)/c
AVRO_C_LICENSE = Apache-2.0
AVRO_C_LICENSE_FILES = LICENSE
AVRO_C_INSTALL_STAGING = YES

View File

@@ -0,0 +1,41 @@
From 2755b093cd69fb980ecb22d905cc6658c895d44a Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Ondr=CC=8Cej=20Sury=CC=81?= <ondrej@isc.org>
Date: Tue, 26 Apr 2022 15:24:18 +0200
Subject: [PATCH] ax_prog_cc_for_build: Properly restore ac_cv_c_compiler_gnu
The ac_cv_c_compiler_gnu wasn't properly restored to original
state (f.e. yes), but value of the "save" variable was used:
ac_cv_c_compiler_gnu=${ac_cv_c_compiler_gnu=saved_ac_cv_c_compiler_gnu}
Additionally, we don't need to cache the saved_ac_cv_c_compiler_gnu
and was_set_ac_cv_c_compiler_gnu, so remove the ac_cv_ from their names.
This would not manifest on a single run, but any repeated run with cache
file (./configure -C) would be broken.
Upstream: https://github.com/autoconf-archive/autoconf-archive/commit/13018ae91007cfa1b1a3877db8ef5cb233af1ae6
[Thomas: partial backport only. Most of the commit is already in bind,
except the serial number update, which is needed for follow-up commits
to apply cleanly]
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
m4/ax_prog_cc_for_build.m4 | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/m4/ax_prog_cc_for_build.m4 b/m4/ax_prog_cc_for_build.m4
index f6518db..1db8d73 100644
--- a/m4/ax_prog_cc_for_build.m4
+++ b/m4/ax_prog_cc_for_build.m4
@@ -32,7 +32,7 @@
# and this notice are preserved. This file is offered as-is, without any
# warranty.
-#serial 20
+#serial 21
AU_ALIAS([AC_PROG_CC_FOR_BUILD], [AX_PROG_CC_FOR_BUILD])
AC_DEFUN([AX_PROG_CC_FOR_BUILD], [dnl
--
2.55.0

View File

@@ -0,0 +1,38 @@
From ce23f1b3db8be19ca74589958a9af56c3ee888d0 Mon Sep 17 00:00:00 2001
From: Dimitri Papadopoulos
<3234522+DimitriPapadopoulos@users.noreply.github.com>
Date: Mon, 25 Dec 2023 13:04:00 +0100
Subject: [PATCH] Fix typos found by codespell
Upstream: https://github.com/autoconf-archive/autoconf-archive/commit/7d383b7aea765a8bc557ec6e88461c6da2db034e
[Thomas: partial backport, only changes to ax_prog_cc_for_build.m4 were kept]
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
m4/ax_prog_cc_for_build.m4 | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/m4/ax_prog_cc_for_build.m4 b/m4/ax_prog_cc_for_build.m4
index 1db8d73..2f44436 100644
--- a/m4/ax_prog_cc_for_build.m4
+++ b/m4/ax_prog_cc_for_build.m4
@@ -32,7 +32,7 @@
# and this notice are preserved. This file is offered as-is, without any
# warranty.
-#serial 21
+#serial 22
AU_ALIAS([AC_PROG_CC_FOR_BUILD], [AX_PROG_CC_FOR_BUILD])
AC_DEFUN([AX_PROG_CC_FOR_BUILD], [dnl
@@ -141,7 +141,7 @@ popdef([ac_cv_prog_gcc])dnl
popdef([ac_cv_prog_CPP])dnl
dnl restore global variables ac_ext, ac_cpp, ac_compile,
-dnl ac_link, ac_compiler_gnu (dependant on the current
+dnl ac_link, ac_compiler_gnu (dependent on the current
dnl language after popping):
AC_LANG_POP([C])
--
2.55.0

View File

@@ -0,0 +1,131 @@
From 13a06f535e2bf7176b0adf6a0d92dc40731275b0 Mon Sep 17 00:00:00 2001
From: Kang-Che Sung <explorer09@gmail.com>
Date: Wed, 16 Oct 2024 21:54:20 +0800
Subject: [PATCH] ax_prog_cc_for_build: Fix BUILD_{EXE,OBJ}EXT for Autoconf
2.70
Autoconf 2.70 introduced a change in AC_SUBST behavior that the variable
name in AC_SUBST no longer gets macro expanded. This breaks the rename
syntaxes of BUILD_EXEEXT and BUILD_OBJEXT in AX_PROG_CC_FOR_BUILD.
Change to an alternative approach of assigning BUILD_EXEEXT and
BUILD_OBJEXT manually. The values of EXEEXT and OBJEXT have to be fixed
too at the end of the AX_PROG_CC_FOR_BUILD code.
Upstream: https://github.com/autoconf-archive/autoconf-archive/commit/6702aeaa9c824d463c3f31d5c31c5eff2646f552
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
m4/ax_prog_cc_for_build.m4 | 40 +++++++++++++++++++++++++++-----------
1 file changed, 29 insertions(+), 11 deletions(-)
diff --git a/m4/ax_prog_cc_for_build.m4 b/m4/ax_prog_cc_for_build.m4
index 2f44436..22e02d5 100644
--- a/m4/ax_prog_cc_for_build.m4
+++ b/m4/ax_prog_cc_for_build.m4
@@ -32,7 +32,7 @@
# and this notice are preserved. This file is offered as-is, without any
# warranty.
-#serial 22
+#serial 23
AU_ALIAS([AC_PROG_CC_FOR_BUILD], [AX_PROG_CC_FOR_BUILD])
AC_DEFUN([AX_PROG_CC_FOR_BUILD], [dnl
@@ -51,8 +51,6 @@ pushdef([ac_cv_prog_cc_works], ac_cv_build_prog_cc_works)dnl
pushdef([ac_cv_prog_cc_cross], ac_cv_build_prog_cc_cross)dnl
pushdef([ac_cv_prog_cc_g], ac_cv_build_prog_cc_g)dnl
pushdef([ac_cv_c_compiler_gnu], ac_cv_build_c_compiler_gnu)dnl
-pushdef([ac_cv_exeext], ac_cv_build_exeext)dnl
-pushdef([ac_cv_objext], ac_cv_build_objext)dnl
pushdef([ac_exeext], ac_build_exeext)dnl
pushdef([ac_objext], ac_build_objext)dnl
pushdef([CC], CC_FOR_BUILD)dnl
@@ -60,9 +58,7 @@ pushdef([CPP], CPP_FOR_BUILD)dnl
pushdef([GCC], GCC_FOR_BUILD)dnl
pushdef([CFLAGS], CFLAGS_FOR_BUILD)dnl
pushdef([CPPFLAGS], CPPFLAGS_FOR_BUILD)dnl
-pushdef([EXEEXT], BUILD_EXEEXT)dnl
pushdef([LDFLAGS], LDFLAGS_FOR_BUILD)dnl
-pushdef([OBJEXT], BUILD_OBJEXT)dnl
pushdef([host], build)dnl
pushdef([host_alias], build_alias)dnl
pushdef([host_cpu], build_cpu)dnl
@@ -77,6 +73,24 @@ pushdef([ac_tool_prefix], ac_build_tool_prefix)dnl
pushdef([am_cv_CC_dependencies_compiler_type], am_cv_build_CC_dependencies_compiler_type)dnl
pushdef([am_cv_prog_cc_c_o], am_cv_build_prog_cc_c_o)dnl
pushdef([cross_compiling], cross_compiling_build)dnl
+dnl
+dnl These variables are problematic to rename by M4 macros, so we save
+dnl their values in alternative names, and restore the values later.
+dnl
+dnl _AC_COMPILER_EXEEXT and _AC_COMPILER_OBJEXT internally call
+dnl AC_SUBST which prevents the renaming of EXEEXT and OBJEXT
+dnl variables. It's not a good idea to rename ac_cv_exeext and
+dnl ac_cv_objext either as they're related.
+dnl Renaming ac_exeext and ac_objext is safe though.
+dnl
+ac_cv_host_exeext=$ac_cv_exeext
+AS_VAR_SET_IF([ac_cv_build_exeext],
+ [ac_cv_exeext=$ac_cv_build_exeext],
+ [AS_UNSET([ac_cv_exeext])])
+ac_cv_host_objext=$ac_cv_objext
+AS_VAR_SET_IF([ac_cv_build_objext],
+ [ac_cv_objext=$ac_cv_build_objext],
+ [AS_UNSET([ac_cv_objext])])
cross_compiling_build=no
@@ -104,6 +118,9 @@ _AC_COMPILER_EXEEXT
_AC_COMPILER_OBJEXT
AC_PROG_CPP
+BUILD_EXEEXT=$ac_cv_exeext
+BUILD_OBJEXT=$ac_cv_objext
+
dnl Restore the old definitions
dnl
popdef([cross_compiling])dnl
@@ -120,9 +137,7 @@ popdef([host_vendor])dnl
popdef([host_cpu])dnl
popdef([host_alias])dnl
popdef([host])dnl
-popdef([OBJEXT])dnl
popdef([LDFLAGS])dnl
-popdef([EXEEXT])dnl
popdef([CPPFLAGS])dnl
popdef([CFLAGS])dnl
popdef([GCC])dnl
@@ -130,8 +145,6 @@ popdef([CPP])dnl
popdef([CC])dnl
popdef([ac_objext])dnl
popdef([ac_exeext])dnl
-popdef([ac_cv_objext])dnl
-popdef([ac_cv_exeext])dnl
popdef([ac_cv_c_compiler_gnu])dnl
popdef([ac_cv_prog_cc_g])dnl
popdef([ac_cv_prog_cc_cross])dnl
@@ -139,6 +152,11 @@ popdef([ac_cv_prog_cc_works])dnl
popdef([ac_cv_prog_cc_c89])dnl
popdef([ac_cv_prog_gcc])dnl
popdef([ac_cv_prog_CPP])dnl
+dnl
+ac_cv_exeext=$ac_cv_host_exeext
+EXEEXT=$ac_cv_host_exeext
+ac_cv_objext=$ac_cv_host_objext
+OBJEXT=$ac_cv_host_objext
dnl restore global variables ac_ext, ac_cpp, ac_compile,
dnl ac_link, ac_compiler_gnu (dependent on the current
@@ -147,8 +165,8 @@ AC_LANG_POP([C])
dnl Finally, set Makefile variables
dnl
-AC_SUBST(BUILD_EXEEXT)dnl
-AC_SUBST(BUILD_OBJEXT)dnl
+AC_SUBST([BUILD_EXEEXT])dnl
+AC_SUBST([BUILD_OBJEXT])dnl
AC_SUBST([CFLAGS_FOR_BUILD])dnl
AC_SUBST([CPPFLAGS_FOR_BUILD])dnl
AC_SUBST([LDFLAGS_FOR_BUILD])dnl
--
2.55.0

View File

@@ -0,0 +1,93 @@
From 9ee4288eec9a850730419064a6e8fb1b5c3e3883 Mon Sep 17 00:00:00 2001
From: Kang-Che Sung <explorer09@gmail.com>
Date: Wed, 16 Oct 2024 21:55:04 +0800
Subject: [PATCH] ax_prog_cc_for_build: Tweak ac_cv_c_compiler_gnu code
Adjust the code of setting ac_cv_c_compiler_gnu to align with the code
of ac_cv_exeext and ac_cv_objext. The solution is now permanent rather
than just a workaround.
Upstream: https://github.com/autoconf-archive/autoconf-archive/commit/55aac85bdf705fd8f0a6b0fab1f0638052400f8f
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
m4/ax_prog_cc_for_build.m4 | 28 +++++++++++-----------------
1 file changed, 11 insertions(+), 17 deletions(-)
diff --git a/m4/ax_prog_cc_for_build.m4 b/m4/ax_prog_cc_for_build.m4
index 22e02d5..9001fb4 100644
--- a/m4/ax_prog_cc_for_build.m4
+++ b/m4/ax_prog_cc_for_build.m4
@@ -32,7 +32,7 @@
# and this notice are preserved. This file is offered as-is, without any
# warranty.
-#serial 23
+#serial 24
AU_ALIAS([AC_PROG_CC_FOR_BUILD], [AX_PROG_CC_FOR_BUILD])
AC_DEFUN([AX_PROG_CC_FOR_BUILD], [dnl
@@ -50,7 +50,6 @@ pushdef([ac_cv_prog_gcc], ac_cv_build_prog_gcc)dnl
pushdef([ac_cv_prog_cc_works], ac_cv_build_prog_cc_works)dnl
pushdef([ac_cv_prog_cc_cross], ac_cv_build_prog_cc_cross)dnl
pushdef([ac_cv_prog_cc_g], ac_cv_build_prog_cc_g)dnl
-pushdef([ac_cv_c_compiler_gnu], ac_cv_build_c_compiler_gnu)dnl
pushdef([ac_exeext], ac_build_exeext)dnl
pushdef([ac_objext], ac_build_objext)dnl
pushdef([CC], CC_FOR_BUILD)dnl
@@ -91,6 +90,14 @@ ac_cv_host_objext=$ac_cv_objext
AS_VAR_SET_IF([ac_cv_build_objext],
[ac_cv_objext=$ac_cv_build_objext],
[AS_UNSET([ac_cv_objext])])
+dnl
+dnl ac_cv_c_compiler_gnu is used in _AC_LANG_COMPILER_GNU (called by
+dnl AC_PROG_CC) indirectly.
+dnl
+ac_cv_host_c_compiler_gnu=$ac_cv_c_compiler_gnu
+AS_VAR_SET_IF([ac_cv_build_c_compiler_gnu],
+ [ac_cv_c_compiler_gnu=$ac_cv_build_c_compiler_gnu],
+ [AS_UNSET([ac_cv_c_compiler_gnu])])
cross_compiling_build=no
@@ -99,21 +106,7 @@ AS_IF([test -n "$build"], [ac_build_tool_prefix="$build-"],
[test -n "$build_alias"],[ac_build_tool_prefix="$build_alias-"])
AC_LANG_PUSH([C])
-
-dnl The pushdef([ac_cv_c_compiler_gnu], ...) currently does not cover
-dnl the use of this variable in _AC_LANG_COMPILER_GNU called by
-dnl AC_PROG_CC. Unset this cache variable temporarily as a workaround.
-was_set_c_compiler_gnu=${[ac_cv_c_compiler_gnu]+y}
-AS_IF([test ${was_set_c_compiler_gnu}],
- [saved_c_compiler_gnu=$[ac_cv_c_compiler_gnu]
- AS_UNSET([[ac_cv_c_compiler_gnu]])])
-
AC_PROG_CC
-
-dnl Restore ac_cv_c_compiler_gnu
-AS_IF([test ${was_set_c_compiler_gnu}],
- [[ac_cv_c_compiler_gnu]=$[saved_c_compiler_gnu]])
-
_AC_COMPILER_EXEEXT
_AC_COMPILER_OBJEXT
AC_PROG_CPP
@@ -145,7 +138,6 @@ popdef([CPP])dnl
popdef([CC])dnl
popdef([ac_objext])dnl
popdef([ac_exeext])dnl
-popdef([ac_cv_c_compiler_gnu])dnl
popdef([ac_cv_prog_cc_g])dnl
popdef([ac_cv_prog_cc_cross])dnl
popdef([ac_cv_prog_cc_works])dnl
@@ -157,6 +149,8 @@ ac_cv_exeext=$ac_cv_host_exeext
EXEEXT=$ac_cv_host_exeext
ac_cv_objext=$ac_cv_host_objext
OBJEXT=$ac_cv_host_objext
+ac_cv_c_compiler_gnu=$ac_cv_host_c_compiler_gnu
+ac_compiler_gnu=$ac_cv_host_c_compiler_gnu
dnl restore global variables ac_ext, ac_cpp, ac_compile,
dnl ac_link, ac_compiler_gnu (dependent on the current
--
2.55.0

View File

@@ -0,0 +1,57 @@
From 205b621a9b01bd05921a5795d6b64b24f87377c7 Mon Sep 17 00:00:00 2001
From: Kang-Che Sung <explorer09@gmail.com>
Date: Wed, 16 Oct 2024 21:55:25 +0800
Subject: [PATCH] ax_prog_cc_for_build: Fix ac_cv_prog_cc_c{99,11} regression
Fix regression where the ac_cv_prog_cc_c99 and ac_cv_prog_cc_c11 macros
are not popped after the AX_PROG_CC_FOR_BUILD call. This can cause
subsequents calls of AC_PROG_CC to use wrong cache variables to
indicate C standard support.
(Regression from serial 19 (16790f97456a6c9b4319dd6ef7b73c9ebc8cae84).
Note: It's unlikely for projects to call AC_PROG_CC again after
AX_PROG_CC_FOR_BUILD, but such usage is valid.)
Upstream: https://github.com/autoconf-archive/autoconf-archive/commit/12ab63676b4bad9481cf36c119c1c4ffab0c0bc2
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
m4/ax_prog_cc_for_build.m4 | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/m4/ax_prog_cc_for_build.m4 b/m4/ax_prog_cc_for_build.m4
index 9001fb4..fd9b953 100644
--- a/m4/ax_prog_cc_for_build.m4
+++ b/m4/ax_prog_cc_for_build.m4
@@ -32,7 +32,7 @@
# and this notice are preserved. This file is offered as-is, without any
# warranty.
-#serial 24
+#serial 25
AU_ALIAS([AC_PROG_CC_FOR_BUILD], [AX_PROG_CC_FOR_BUILD])
AC_DEFUN([AX_PROG_CC_FOR_BUILD], [dnl
@@ -43,10 +43,10 @@ AC_REQUIRE([AC_CANONICAL_BUILD])dnl
dnl Use the standard macros, but make them use other variable names
dnl
pushdef([ac_cv_prog_CPP], ac_cv_build_prog_CPP)dnl
+pushdef([ac_cv_prog_gcc], ac_cv_build_prog_gcc)dnl
pushdef([ac_cv_prog_cc_c89], ac_cv_build_prog_cc_c89)dnl
pushdef([ac_cv_prog_cc_c99], ac_cv_build_prog_cc_c99)dnl
pushdef([ac_cv_prog_cc_c11], ac_cv_build_prog_cc_c11)dnl
-pushdef([ac_cv_prog_gcc], ac_cv_build_prog_gcc)dnl
pushdef([ac_cv_prog_cc_works], ac_cv_build_prog_cc_works)dnl
pushdef([ac_cv_prog_cc_cross], ac_cv_build_prog_cc_cross)dnl
pushdef([ac_cv_prog_cc_g], ac_cv_build_prog_cc_g)dnl
@@ -141,6 +141,8 @@ popdef([ac_exeext])dnl
popdef([ac_cv_prog_cc_g])dnl
popdef([ac_cv_prog_cc_cross])dnl
popdef([ac_cv_prog_cc_works])dnl
+popdef([ac_cv_prog_cc_c11])dnl
+popdef([ac_cv_prog_cc_c99])dnl
popdef([ac_cv_prog_cc_c89])dnl
popdef([ac_cv_prog_gcc])dnl
popdef([ac_cv_prog_CPP])dnl
--
2.55.0

View File

@@ -0,0 +1,62 @@
From 00d6e2057fe3fa1f2b74c76605a09b227b7a1af9 Mon Sep 17 00:00:00 2001
From: Kang-Che Sung <explorer09@gmail.com>
Date: Wed, 16 Oct 2024 21:56:44 +0800
Subject: [PATCH] ax_prog_cc_for_build: Support ac_{,cv_}build_prog_cc_stdc
Improve compatibility with Autoconf 2.70 and later. Add support for
these variables for indicating build compiler capabilities:
* ac_cv_build_prog_cc_stdc (corresponding to ac_cv_prog_cc_stdc;
Autoconf 2.70)
* ac_build_prog_cc_stdc (corresponding to ac_prog_cc_stdc;
Autoconf 2.70)
* ac_cv_build_prog_cc_c23 (corresponding to ac_cv_prog_cc_c23;
Autoconf 2.73)
Upstream: https://github.com/autoconf-archive/autoconf-archive/commit/8a970ce96721f516fef4226e5eca8da341159765
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
m4/ax_prog_cc_for_build.m4 | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/m4/ax_prog_cc_for_build.m4 b/m4/ax_prog_cc_for_build.m4
index fd9b953..4d1de99 100644
--- a/m4/ax_prog_cc_for_build.m4
+++ b/m4/ax_prog_cc_for_build.m4
@@ -32,7 +32,7 @@
# and this notice are preserved. This file is offered as-is, without any
# warranty.
-#serial 25
+#serial 26
AU_ALIAS([AC_PROG_CC_FOR_BUILD], [AX_PROG_CC_FOR_BUILD])
AC_DEFUN([AX_PROG_CC_FOR_BUILD], [dnl
@@ -47,9 +47,12 @@ pushdef([ac_cv_prog_gcc], ac_cv_build_prog_gcc)dnl
pushdef([ac_cv_prog_cc_c89], ac_cv_build_prog_cc_c89)dnl
pushdef([ac_cv_prog_cc_c99], ac_cv_build_prog_cc_c99)dnl
pushdef([ac_cv_prog_cc_c11], ac_cv_build_prog_cc_c11)dnl
+pushdef([ac_cv_prog_cc_c23], ac_cv_build_prog_cc_c23)dnl
+pushdef([ac_cv_prog_cc_stdc], ac_cv_build_prog_cc_stdc)dnl
pushdef([ac_cv_prog_cc_works], ac_cv_build_prog_cc_works)dnl
pushdef([ac_cv_prog_cc_cross], ac_cv_build_prog_cc_cross)dnl
pushdef([ac_cv_prog_cc_g], ac_cv_build_prog_cc_g)dnl
+pushdef([ac_prog_cc_stdc], ac_build_prog_cc_stdc)dnl
pushdef([ac_exeext], ac_build_exeext)dnl
pushdef([ac_objext], ac_build_objext)dnl
pushdef([CC], CC_FOR_BUILD)dnl
@@ -138,9 +141,12 @@ popdef([CPP])dnl
popdef([CC])dnl
popdef([ac_objext])dnl
popdef([ac_exeext])dnl
+popdef([ac_prog_cc_stdc])dnl
popdef([ac_cv_prog_cc_g])dnl
popdef([ac_cv_prog_cc_cross])dnl
popdef([ac_cv_prog_cc_works])dnl
+popdef([ac_cv_prog_cc_stdc])dnl
+popdef([ac_cv_prog_cc_c23])dnl
popdef([ac_cv_prog_cc_c11])dnl
popdef([ac_cv_prog_cc_c99])dnl
popdef([ac_cv_prog_cc_c89])dnl
--
2.55.0

View File

@@ -2,7 +2,7 @@ config BR2_PACKAGE_BIND
bool "bind"
depends on BR2_USE_MMU # fork(), libcap, libuv
depends on BR2_TOOLCHAIN_HAS_SYNC_4 # libuv
depends on BR2_TOOLCHAIN_HAS_THREADS # liburcu, libuv
depends on BR2_TOOLCHAIN_HAS_THREADS_NPTL # libuv
depends on BR2_INSTALL_LIBSTDCPP # liburcu
depends on !BR2_STATIC_LIBS # libuv
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 # libuv
@@ -48,9 +48,9 @@ config BR2_PACKAGE_BIND_TOOLS
endif
comment "bind needs a toolchain w/ threads, dynamic library, C++, gcc >= 4.9"
comment "bind needs a toolchain w/ NPTL, dynamic library, C++, gcc >= 4.9"
depends on BR2_USE_MMU
depends on BR2_TOOLCHAIN_HAS_SYNC_4
depends on !BR2_TOOLCHAIN_HAS_THREADS || BR2_STATIC_LIBS \
depends on !BR2_TOOLCHAIN_HAS_THREADS_NPTL || BR2_STATIC_LIBS \
|| BR2_INSTALL_LIBSTDCPP || !BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 \
|| BR2_PACKAGE_LIBURCU_ARCH_SUPPORTS

View File

@@ -14,7 +14,7 @@ config BR2_PACKAGE_BPFTRACE
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_7 # bcc -> clang
depends on BR2_INSTALL_LIBSTDCPP # bcc -> clang
depends on BR2_HOST_GCC_AT_LEAST_7 # bcc -> clang
depends on BR2_TOOLCHAIN_HEADERS_AT_LEAST_4_13 # libbpf
depends on BR2_TOOLCHAIN_HEADERS_AT_LEAST_5_10 # CAP_BPF, CAP_PERFMON
depends on BR2_USE_WCHAR # bcc -> clang, bcc -> python3, libbpf
depends on BR2_TOOLCHAIN_HAS_THREADS # bcc -> clang, bcc -> python3, libbpf
depends on !BR2_STATIC_LIBS # bcc -> clang, bcc -> python3, libbpf
@@ -47,10 +47,10 @@ config BR2_PACKAGE_BPFTRACE
https://www.github.com/iovisor/bpftrace
comment "bpftrace needs a glibc toolchain w/ C++, gcc >= 7, host gcc >= 7, kernel headers >= 4.13"
comment "bpftrace needs a glibc toolchain w/ C++, gcc >= 7, host gcc >= 7, kernel headers >= 5.10"
depends on BR2_PACKAGE_BPFTRACE_ARCH_SUPPORTS
depends on BR2_USE_MMU
depends on BR2_TOOLCHAIN_HAS_SYNC_4
depends on !BR2_TOOLCHAIN_USES_GLIBC || !BR2_INSTALL_LIBSTDCPP \
|| !BR2_TOOLCHAIN_GCC_AT_LEAST_7 || !BR2_HOST_GCC_AT_LEAST_7 \
|| !BR2_TOOLCHAIN_HEADERS_AT_LEAST_4_13
|| !BR2_TOOLCHAIN_HEADERS_AT_LEAST_5_10

View File

@@ -1,3 +1,3 @@
# locally calculated
sha256 e0514aa3e1a032b0b2de2cf3c281bfee9b9e80509498e70ed78786bbd64db373 bpftrace-0.24.2.tar.gz
sha256 555368f32f94bfcb74b119a3d9c67b68200be6375b8f452f794a2d3f6ebbcd16 bpftrace-0.26.1.tar.gz
sha256 cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30 LICENSE

View File

@@ -4,7 +4,7 @@
#
################################################################################
BPFTRACE_VERSION = 0.24.2
BPFTRACE_VERSION = 0.26.1
BPFTRACE_SITE = $(call github,bpftrace,bpftrace,v$(BPFTRACE_VERSION))
BPFTRACE_LICENSE = Apache-2.0
BPFTRACE_LICENSE_FILES = LICENSE
@@ -13,8 +13,6 @@ BPFTRACE_DEPENDENCIES = \
bzip2 \
cereal \
elfutils \
host-bison \
host-flex \
host-vim \
libbpf \
llvm \
@@ -29,6 +27,7 @@ BPFTRACE_CONF_OPTS += \
-DBUILD_SHARED_LIBS:BOOL=OFF \
-DBUILD_TESTING:BOOL=OFF \
-DCMAKE_CXX_FLAGS="$(TARGET_CXXFLAGS) -I$(STAGING_DIR)/usr/include/bpf" \
-DENABLE_MAN:BOOL=OFF
-DENABLE_MAN:BOOL=OFF \
-DUSE_SYSTEM_LIBBPF:BOOL=ON
$(eval $(cmake-package))

View File

@@ -14,6 +14,7 @@ config BR2_PACKAGE_CLAMAV
select BR2_PACKAGE_LIBXML2
select BR2_PACKAGE_MUSL_FTS if !BR2_TOOLCHAIN_USES_GLIBC
select BR2_PACKAGE_OPENSSL
select BR2_PACKAGE_LIBOPENSSL_ENABLE_DES if BR2_PACKAGE_LIBOPENSSL
select BR2_PACKAGE_PCRE2
select BR2_PACKAGE_ZLIB
select BR2_PACKAGE_ZLIB_FORCE_LIBZLIB

View File

@@ -0,0 +1,45 @@
From be6ac1ed28b4842e8f2e54c39a2b3fc48feaf8b2 Mon Sep 17 00:00:00 2001
From: "Matwey V. Kornilov" <matwey.kornilov@gmail.com>
Date: Sun, 26 Oct 2025 18:36:56 +0300
Subject: [PATCH] virt: Drop ATTRIBUTE_UNUSED for virt_eventloop_timeout_cb
ATTRIBUTE_UNUSED seems to be never was a public part of the libvirt interface
and leads to the following issue with recent libvirt versions were
ATTRIBUTE_UNUSED has been renamed to G_GNUC_UNUSED:
src/virt.c:2209:49: error: expected ';', ',' or ')' before 'ATTRIBUTE_UNUSED'
2209 | static void virt_eventloop_timeout_cb(int timer ATTRIBUTE_UNUSED,
| ^~~~~~~~~~~~~~~~
src/virt.c: In function 'register_event_impl':
src/virt.c:2222:26: error: 'virt_eventloop_timeout_cb' undeclared (first use in this function)
2222 | virt_eventloop_timeout_cb, NULL, NULL) < 0) {
| ^~~~~~~~~~~~~~~~~~~~~~~~~
src/virt.c:2222:26: note: each undeclared identifier is reported only once for each function it appears in
Drop ATTRIBUTE_UNUSED here as there is little use from it.
Upstream: https://github.com/collectd/collectd/commit/050877ed952ffc15c849803a9b3e77c5cec15f81
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
src/virt.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/src/virt.c b/src/virt.c
index 01c7c777..ee0440e9 100644
--- a/src/virt.c
+++ b/src/virt.c
@@ -2205,8 +2205,9 @@ static int domain_lifecycle_event_cb(__attribute__((unused)) virConnectPtr con_,
return 0;
}
-static void virt_eventloop_timeout_cb(int timer ATTRIBUTE_UNUSED,
- void *timer_info) {}
+static void
+virt_eventloop_timeout_cb(__attribute__((unused)) int timer,
+ __attribute__((unused)) void *timer_info) {}
static int register_event_impl(void) {
if (virEventRegisterDefaultImpl() < 0) {
--
2.55.0

View File

@@ -0,0 +1,38 @@
From 96a67c8e51997a18bfc0942416b815057e279caf Mon Sep 17 00:00:00 2001
From: InterLinked1 <24227567+InterLinked1@users.noreply.github.com>
Date: Tue, 8 Jul 2025 18:35:56 -0400
Subject: [PATCH] kernel.h: Add wrappers for del_timer and del_timer_sync.
del_timer[_sync] was renamed to timer_delete[_sync] in kernel
commit bb663f0f3c396c6d05f6c5eeeea96ced20ff112e, and the
compatibility wrappers were removed completely in kernel commit
8fa7292fee5c5240402371ea89ab285ec856c916. Add the wrappers
back on newer kernels to allow compilation.
Resolves: #91
Upstream: https://github.com/asterisk/dahdi-linux/commit/67d909a8a73364d6fa47bbf8baf314175c94f546
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
include/dahdi/kernel.h | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/include/dahdi/kernel.h b/include/dahdi/kernel.h
index ab129a8..ddd3eb4 100644
--- a/include/dahdi/kernel.h
+++ b/include/dahdi/kernel.h
@@ -62,6 +62,11 @@
#define netif_napi_add netif_napi_add_weight
#endif
+#if LINUX_VERSION_CODE >= KERNEL_VERSION(6,15,0)
+#define del_timer timer_delete
+#define del_timer_sync timer_delete_sync
+#endif
+
#if LINUX_VERSION_CODE >= KERNEL_VERSION(5, 18, 0)
#include <linux/pci.h>
#include <linux/dma-mapping.h>
--
2.55.0

View File

@@ -0,0 +1,186 @@
From fc3748466d96fa465fe665403b73d6f4f75c124b Mon Sep 17 00:00:00 2001
From: InterLinked1 <24227567+InterLinked1@users.noreply.github.com>
Date: Fri, 21 Feb 2025 21:42:19 -0500
Subject: [PATCH] Kbuild: Use ccflags-y instead of EXTRA_CFLAGS.
ccflags-y was added to the kernel back in 2007, in commit
f77bf01425b11947eeb3b5b54. Recent kernel commit
dbd83ea09699390892e5efecddd74ae43a00f071 has now completely
removed the deprecated EXTRA_CFLAGS.
Comments in Kbuild and the Makefile for the oct612x library were
added back when it was created in 2013 in commit f65299e8b2e6ffb0b07089759f8c4ff33a695c09
to use the newer ccflags-y based on the kernel version,
but the change was never made to conditionally move away
from the EXTRA_CFLAGS.
Now that the older way no longer exists, always use ccflags-y.
Resolves: #76
Upstream: https://github.com/asterisk/dahdi-linux/commit/9d5b120cb5573d39bcd9e3d8a7b212e25ab5c2c4
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
drivers/dahdi/Kbuild | 4 ++--
drivers/dahdi/oct612x/Kbuild | 5 +----
drivers/dahdi/oct612x/Makefile | 5 +----
drivers/dahdi/voicebus/Kbuild | 4 ++--
drivers/dahdi/wcb4xxp/Kbuild | 2 +-
drivers/dahdi/wct4xxp/Kbuild | 6 +++---
drivers/dahdi/wctc4xxp/Kbuild | 4 ++--
drivers/dahdi/wctdm24xxp/Kbuild | 2 +-
drivers/dahdi/xpp/Kbuild | 4 ++--
9 files changed, 15 insertions(+), 21 deletions(-)
diff --git a/drivers/dahdi/Kbuild b/drivers/dahdi/Kbuild
index cd0365b..9c9355a 100644
--- a/drivers/dahdi/Kbuild
+++ b/drivers/dahdi/Kbuild
@@ -75,13 +75,13 @@ CFLAGS_MODULE += -I$(DAHDI_INCLUDE) -I$(src) -Wno-format-truncation
BAD_KERNELS_VERS := 22 34 34.0.1 34.0.2
BAD_KERNELS := $(foreach ver,$(BAD_KERNELS_VERS),2.6.9-$(ver).EL 2.6.9-$(ver).ELsmp)
ifneq (,$(filter $(KVERS),$(BAD_KERNELS)))
-EXTRA_CFLAGS+=-Drw_lock_t=rwlock_t
+ccflags-y+=-Drw_lock_t=rwlock_t
endif
# A number of Fedora 10 (9 also?) kernels backported hrtimer to 2.6.27
# as part of an ALSA backport. TODO: Any better way to detect that?
ifeq (1,$(shell fgrep -q ' hrtimer_set_expires' include/linux/hrtimer.h 2>/dev/null && echo 1))
-EXTRA_CFLAGS+=-DHAVE_HRTIMER_ACCESSORS=1
+ccflags-y+=-DHAVE_HRTIMER_ACCESSORS=1
endif
ifeq (1,$(shell fgrep -q 'wait_for_completion_timeout' include/linux/completion.h 2>/dev/null && echo 1))
diff --git a/drivers/dahdi/oct612x/Kbuild b/drivers/dahdi/oct612x/Kbuild
index ac53fe7..5015f7e 100644
--- a/drivers/dahdi/oct612x/Kbuild
+++ b/drivers/dahdi/oct612x/Kbuild
@@ -24,9 +24,6 @@ octapi_files = octdeviceapi/oct6100api/oct6100_api/oct6100_adpcm_chan.o \
apilib/llman/octapi_llman.o \
oct612x-user.o
-# TODO: ccflags was added in 2.6.24 in commit f77bf01425b11947eeb3b5b54. This
-# should be changed to a conditional compilation based on the Kernel Version.
-# ccflags-y := -I$(src)/.. -Wno-undef -I$(src)/include -I$(src)/octdeviceapi -I$(src)/octdeviceapi/oct6100api
-EXTRA_CFLAGS = -I$(src)/.. -Wno-undef -I$(src)/include -I$(src)/octdeviceapi -I$(src)/octdeviceapi/oct6100api
+ccflags-y := -I$(src)/.. -Wno-undef -I$(src)/include -I$(src)/octdeviceapi -I$(src)/octdeviceapi/oct6100api
obj-$(DAHDI_BUILD_ALL)$(CONFIG_DAHDI_OCT612X) := oct612x.o
oct612x-objs := $(octapi_files)
diff --git a/drivers/dahdi/oct612x/Makefile b/drivers/dahdi/oct612x/Makefile
index 5d29143..d01997b 100644
--- a/drivers/dahdi/oct612x/Makefile
+++ b/drivers/dahdi/oct612x/Makefile
@@ -23,8 +23,5 @@ octapi_files = octdeviceapi/oct6100api/oct6100_api/oct6100_adpcm_chan.o \
apilib/largmath/octapi_largmath.o \
apilib/llman/octapi_llman.o
-# TODO: ccflags was added in 2.6.24 in commit f77bf01425b11947eeb3b5b54. This
-# should be changed to a conditional compilation based on the Kernel Version.
-# ccflags-y := -I$(src)/.. -Wno-undef -I$(src)/include -I$(src)/octdeviceapi -I$(src)/octdeviceapi/oct6100api
-EXTRA_CFLAGS = -I$(src)/.. -Wno-undef -I$(src)/include -I$(src)/octdeviceapi -I$(src)/octdeviceapi/oct6100api
+ccflags-y := -I$(src)/.. -Wno-undef -I$(src)/include -I$(src)/octdeviceapi -I$(src)/octdeviceapi/oct6100api
lib-y := $(octapi_files)
diff --git a/drivers/dahdi/voicebus/Kbuild b/drivers/dahdi/voicebus/Kbuild
index 3bf9640..45026d9 100644
--- a/drivers/dahdi/voicebus/Kbuild
+++ b/drivers/dahdi/voicebus/Kbuild
@@ -8,10 +8,10 @@ ifneq ($(HOTPLUG_FIRMWARE),yes)
dahdi_voicebus-objs += $(FIRM_DIR)/dahdi-fw-vpmoct032.o
$(warning WARNING: You are compiling firmware into voicebus.ko which is not available under the terms of the GPL. It may be a violation of the GPL to distribute the resulting image since it combines both GPL and non-GPL work. You should consult a lawyer of your own before distributing such an image.)
else
- EXTRA_CFLAGS+=-DHOTPLUG_FIRMWARE
+ ccflags-y+=-DHOTPLUG_FIRMWARE
endif
-EXTRA_CFLAGS += -I$(src)/.. -Wno-undef
+ccflags-y += -I$(src)/.. -Wno-undef
$(obj)/$(FIRM_DIR)/dahdi-fw-vpmoct032.o: $(obj)/voicebus.o
$(MAKE) -C $(obj)/$(FIRM_DIR) dahdi-fw-vpmoct032.o
diff --git a/drivers/dahdi/wcb4xxp/Kbuild b/drivers/dahdi/wcb4xxp/Kbuild
index 80606bf..59ffc8d 100644
--- a/drivers/dahdi/wcb4xxp/Kbuild
+++ b/drivers/dahdi/wcb4xxp/Kbuild
@@ -1,6 +1,6 @@
obj-m += wcb4xxp.o
-EXTRA_CFLAGS += -I$(src)/.. -Wno-undef
+ccflags-y += -I$(src)/.. -Wno-undef
wcb4xxp-objs := base.o
diff --git a/drivers/dahdi/wct4xxp/Kbuild b/drivers/dahdi/wct4xxp/Kbuild
index cf01ccf..eeeb2f6 100644
--- a/drivers/dahdi/wct4xxp/Kbuild
+++ b/drivers/dahdi/wct4xxp/Kbuild
@@ -2,16 +2,16 @@ obj-$(DAHDI_BUILD_ALL)$(CONFIG_DAHDI_WCT4XXP) += wct4xxp.o
FIRM_DIR := ../firmware
-EXTRA_CFLAGS += -I$(src)/.. -I$(src)/../oct612x/ $(shell $(src)/../oct612x/octasic-helper cflags $(src)/../oct612x) -Wno-undef
+ccflags-y += -I$(src)/.. -I$(src)/../oct612x/ $(shell $(src)/../oct612x/octasic-helper cflags $(src)/../oct612x) -Wno-undef
# The OCT612X source files are from a vendor drop and we do not want to edit
# them to make this warning go away. Therefore, turn off the
# unused-but-set-variable warning for this driver.
-EXTRA_CFLAGS += $(call cc-option, -Wno-unused-but-set-variable)
+ccflags-y += $(call cc-option, -Wno-unused-but-set-variable)
ifeq ($(HOTPLUG_FIRMWARE),yes)
- EXTRA_CFLAGS+=-DHOTPLUG_FIRMWARE
+ ccflags-y+=-DHOTPLUG_FIRMWARE
endif
wct4xxp-objs := base.o vpm450m.o
diff --git a/drivers/dahdi/wctc4xxp/Kbuild b/drivers/dahdi/wctc4xxp/Kbuild
index 9f97498..2f1bfbf 100644
--- a/drivers/dahdi/wctc4xxp/Kbuild
+++ b/drivers/dahdi/wctc4xxp/Kbuild
@@ -2,10 +2,10 @@ obj-$(DAHDI_BUILD_ALL)$(CONFIG_DAHDI_WCTC4XXP) += wctc4xxp.o
FIRM_DIR := ../firmware
-EXTRA_CFLAGS += -I$(src)/.. -Wno-undef
+ccflags-y += -I$(src)/.. -Wno-undef
ifeq ($(HOTPLUG_FIRMWARE),yes)
- EXTRA_CFLAGS+=-DHOTPLUG_FIRMWARE
+ ccflags-y+=-DHOTPLUG_FIRMWARE
endif
wctc4xxp-objs := base.o
diff --git a/drivers/dahdi/wctdm24xxp/Kbuild b/drivers/dahdi/wctdm24xxp/Kbuild
index 22cc71a..c9d96b7 100644
--- a/drivers/dahdi/wctdm24xxp/Kbuild
+++ b/drivers/dahdi/wctdm24xxp/Kbuild
@@ -1,5 +1,5 @@
obj-$(DAHDI_BUILD_ALL)$(CONFIG_DAHDI_WCTDM24XXP) += wctdm24xxp.o
-EXTRA_CFLAGS += -I$(src)/.. -Wno-undef
+ccflags-y += -I$(src)/.. -Wno-undef
wctdm24xxp-objs := base.o xhfc.o
diff --git a/drivers/dahdi/xpp/Kbuild b/drivers/dahdi/xpp/Kbuild
index e46a9d7..02d3149 100644
--- a/drivers/dahdi/xpp/Kbuild
+++ b/drivers/dahdi/xpp/Kbuild
@@ -1,4 +1,4 @@
-EXTRA_CFLAGS = $(XPP_LOCAL_CFLAGS) \
+ccflags-y = $(XPP_LOCAL_CFLAGS) \
-DDEBUG \
-DPOLL_DIGITAL_INPUTS \
-DDEBUG_PCMTX \
@@ -32,7 +32,7 @@ xpd_echo-objs += card_echo.o
xpp_mmap-objs += mmapbus.o mmapdrv.o
ifeq (y,$(PARPORT_DEBUG))
-EXTRA_CFLAGS += -DDEBUG_SYNC_PARPORT
+ccflags-y += -DDEBUG_SYNC_PARPORT
obj-m += parport_debug.o
endif
--
2.55.0

View File

@@ -0,0 +1,35 @@
From 13e360f1bc65dba29ba22c46f30ba868bea9805d Mon Sep 17 00:00:00 2001
From: InterLinked1 <24227567+InterLinked1@users.noreply.github.com>
Date: Sat, 12 Jul 2025 17:52:40 -0400
Subject: [PATCH] kernel.h: Add wrapper for renamed from_timer function.
from_timer was renamed to timer_container_of in kernel commit
41cb08555c4164996d67c78b3bf1c658075b75f1 as part of updates to
the timer APIs. Add a compatibility wrapper for kernels >= 6.16.0.
Resolves: #95
Upstream: https://github.com/asterisk/dahdi-linux/commit/0d864e9f97ba22e340380ce24a1bd366ca33ebc2
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
include/dahdi/kernel.h | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/include/dahdi/kernel.h b/include/dahdi/kernel.h
index ddd3eb4..01fe113 100644
--- a/include/dahdi/kernel.h
+++ b/include/dahdi/kernel.h
@@ -58,6 +58,10 @@
#include <linux/poll.h>
+#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 16, 0)
+#define from_timer timer_container_of
+#endif
+
#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 1, 0)
#define netif_napi_add netif_napi_add_weight
#endif
--
2.55.0

View File

@@ -1,5 +1,6 @@
config BR2_PACKAGE_DISTRIBUTION_REGISTRY
bool "distribution-registry"
depends on BR2_TOOLCHAIN_HAS_THREADS_NPTL # pthread_*_np()
depends on BR2_PACKAGE_HOST_GO_TARGET_ARCH_SUPPORTS
depends on BR2_PACKAGE_HOST_GO_TARGET_CGO_LINKING_SUPPORTS
help

View File

@@ -0,0 +1,46 @@
From 9f6c3191b3178294d698cdca859ce9dac78517ff Mon Sep 17 00:00:00 2001
From: Guillaume Gardet <Guillaume.Gardet@arm.com>
Date: Thu, 29 Aug 2024 16:33:19 +0200
Subject: [PATCH] examples/vm_power_manager: add missing <stdlib.h> header
include for strtol
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
strtol is defined in stdlib.h
Fixes the following build failure:
../examples/vm_power_manager/guest_cli/vm_power_cli_guest.c: In function ‘cmd_query_freq_list_parsed’:
../examples/vm_power_manager/guest_cli/vm_power_cli_guest.c:208:42: error: implicit declaration of function ‘strtol’; did you mean ‘strtok’? [-Wimplicit-function-declaration]
208 | lcore_id = (unsigned int)strtol(res->cpu_num, &ep, 10);
| ^~~~~~
| strtok
Fixes: 0e8f47491f090f44a4956429cb27f6942b6618b0 ("examples/vm_power: add command to query CPU frequency")
Signed-off-by: Guillaume Gardet <guillaume.gardet@arm.com>
[Thomas:
- retrieve patch from
https://build.opensuse.org/projects/openSUSE:42:Factory-Candidates-Check/packages/dpdk/files/0001-examples-vm_power_manager-add-missing-header.patch?expand=1
- improve commit message]
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Upstream: https://mails.dpdk.org/archives/dev/2026-August/344552.html
---
examples/vm_power_manager/guest_cli/vm_power_cli_guest.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/examples/vm_power_manager/guest_cli/vm_power_cli_guest.c b/examples/vm_power_manager/guest_cli/vm_power_cli_guest.c
index 4114593cee..63a59c8b10 100644
--- a/examples/vm_power_manager/guest_cli/vm_power_cli_guest.c
+++ b/examples/vm_power_manager/guest_cli/vm_power_cli_guest.c
@@ -6,6 +6,7 @@
#include <stdint.h>
#include <string.h>
#include <stdio.h>
+#include <stdlib.h>
#include <termios.h>
#include <cmdline_rdline.h>
--
2.55.0

View File

@@ -112,6 +112,10 @@ ifeq ($(BR2_PACKAGE_LIBBPF),y)
DPDK_DEPENDENCIES += libbpf
endif
ifeq ($(BR2_PACKAGE_LIBVIRT),y)
DPDK_DEPENDENCIES += libvirt
endif
ifeq ($(BR2_PACKAGE_RDMA_CORE),y)
DPDK_DEPENDENCIES += rdma-core
endif

View File

@@ -11,8 +11,18 @@ DRACUT_LICENSE_FILES = COPYING
DRACUT_CPE_ID_VALID = YES
HOST_DRACUT_DEPENDENCIES = host-pkgconf host-kmod host-cross-ldd
# Dracut is not a real autotools package, and the hand-written
# ./configure script does not preserve LDFLAGS for make.
HOST_DRACUT_MAKE_ENV = $(HOST_CONFIGURE_OPTS)
HOST_DRACUT_INSTALL_OPTS = systemdsystemunitdir="" install
ifeq ($(BR2_PACKAGE_HOST_RUSTC),y)
HOST_DRACUT_CONF_OPTS += --enable-dracut-cpio
HOST_DRACUT_DEPENDENCIES += host-rustc
else
HOST_DRACUT_CONF_OPTS += --disable-dracut-cpio
endif
define HOST_DRACUT_POST_INSTALL_WRAPPER_SCRIPT
mv $(HOST_DIR)/bin/dracut $(HOST_DIR)/bin/dracut.real
sed -e "s%@@TARGET_CROSS@@%$(TARGET_CROSS)%" \

View File

@@ -0,0 +1,36 @@
From cd29aa61d299c82d82d3285215fc4fc65e4d4fb9 Mon Sep 17 00:00:00 2001
From: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Date: Sun, 30 Aug 2026 12:00:00 +0200
Subject: [PATCH] Fix incomplete 'struct tm' type on uClibc
Fix a build failure [1] reported by Buildroot autobuild for the
mips/uClibc configuration:
Date.cc:98:28: error: return type 'struct trantor::tm' is incomplete
98 | struct tm Date::tmStruct() const
| ^~~~~
Add the missing include to Date.h.
[1] https://autobuild.buildroot.org/results/e48e0fc1b95a8ad5de964b1e6d12bc45ac39f0b4/
Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Upstream: https://github.com/an-tao/trantor/pull/415
---
trantor/utils/Date.h | 1 +
1 file changed, 1 insertion(+)
diff --git a/trantor/trantor/utils/Date.h b/trantor/trantor/utils/Date.h
index 4367d76e0305..41b02d355d14 100644
--- a/trantor/trantor/utils/Date.h
+++ b/trantor/trantor/utils/Date.h
@@ -16,6 +16,7 @@
#include <trantor/exports.h>
#include <stdint.h>
+#include <time.h>
#include <string>
namespace trantor
--
2.43.0

View File

@@ -41,6 +41,11 @@ DROGON_CONF_OPTS += -DBUILD_CTL=OFF
endif
ifeq ($(BR2_PACKAGE_DROGON_EXAMPLES),y)
# Some examples embed CSP views, whose C++ sources are generated at
# build time by drogon_ctl. When cross-compiling, CMake does not
# substitute the drogon_ctl target executable in the custom command, so
# the tool is looked up in PATH and must be provided by host-drogon.
DROGON_DEPENDENCIES += host-drogon
DROGON_CONF_OPTS += -DBUILD_EXAMPLES=ON
else
DROGON_CONF_OPTS += -DBUILD_EXAMPLES=OFF

View File

@@ -0,0 +1,29 @@
From c0c7e9ad51b2e9aebea46f0179446fcf896f8d63 Mon Sep 17 00:00:00 2001
From: Wim Stockman <wimstockman@gmail.com>
Date: Fri, 20 Feb 2026 10:51:37 +0100
Subject: [PATCH] Add CFLAG=-std=c89 so it compiles with the old standard,
modern standard gives problems
Upstream: https://git.savannah.gnu.org/cgit/enscript.git/commit/?id=111ad375a6e598c896441e10f4cf1e2fc1496c42
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
configure.ac | 3 +++
1 file changed, 3 insertions(+)
diff --git a/configure.ac b/configure.ac
index 465100a..b867912 100644
--- a/configure.ac
+++ b/configure.ac
@@ -10,6 +10,9 @@ AC_PROG_INSTALL
AC_PROG_CC
+# Force C89 standard and fix modern GCC global variable handling
+CFLAGS="$CFLAGS -std=c89"
+
AC_USE_SYSTEM_EXTENSIONS
AM_C_PROTOTYPES
--
2.55.0

View File

@@ -1,19 +0,0 @@
Fix build with gcc 15.x
Upstream: https://savannah.gnu.org/bugs/?66845
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
diff --git a/compat/regex.c b/compat/regex.c
index c6907f3..87f2840 100644
--- a/compat/regex.c
+++ b/compat/regex.c
@@ -336,7 +336,7 @@ typedef char boolean;
#define false 0
#define true 1
-static int re_match_2_internal ();
+static int re_match_2_internal (struct re_pattern_buffer*, const char*, int, const char*, int, int, struct re_registers*, int);
/* These are the command codes that appear in compiled regular
expressions. Some opcodes are followed by argument bytes. A

View File

@@ -0,0 +1,28 @@
From d74ef70aec3fe9e5e27468f31532eb41188707cf Mon Sep 17 00:00:00 2001
From: Werner Fink <werner@suse.de>
Date: Tue, 23 Jan 2018 15:26:45 +0100
Subject: [PATCH] Automake 1.12 and up no longer supports pre-ANSI
Signed-off-by: Werner Fink <werner@suse.de>
Signed-off-by: James Cloos <cloos@jhcloos.com>
Upstream: https://git.savannah.gnu.org/cgit/enscript.git/commit/?id=a356d343aa9db52b75432cde927b6f9bad6a7c44
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
configure.ac | 1 -
1 file changed, 1 deletion(-)
diff --git a/configure.ac b/configure.ac
index b867912..4431cb1 100644
--- a/configure.ac
+++ b/configure.ac
@@ -14,7 +14,6 @@ AC_PROG_CC
CFLAGS="$CFLAGS -std=c89"
AC_USE_SYSTEM_EXTENSIONS
-AM_C_PROTOTYPES
AC_C_CONST
AC_FUNC_ALLOCA
--
2.55.0

View File

@@ -0,0 +1,107 @@
From 83238ba35f966bb35a065e6d141f3ccf714f4324 Mon Sep 17 00:00:00 2001
From: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Date: Sat, 22 Aug 2026 14:50:56 +0200
Subject: [PATCH] Fix prototype detection when __STDC__ is defined but
PROTOTYPES is not
Commit a356d343aa9db52b75432cde927b6f9bad6a7c44 ("Automake 1.12 and up
no longer supports pre-ANSI") dropped the AM_C_PROTOTYPES call from
configure.ac, so PROTOTYPES is no longer defined by configure. The
headers' fallback to K&R-style prototypes breaks compilation with
modern compilers.
Check for __STDC__ directly as a fallback, which is defined by all
conforming C89/C99 compilers.
Upstream: https://savannah.gnu.org/bugs/index.php?68633
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
afmlib/afm.h | 2 +-
afmlib/afmint.h | 2 +-
afmlib/strhash.h | 2 +-
compat/xalloc.h | 2 +-
src/gsint.h | 2 +-
states/defs.h | 2 +-
6 files changed, 6 insertions(+), 6 deletions(-)
diff --git a/afmlib/afm.h b/afmlib/afm.h
index 19855ce..a79648d 100644
--- a/afmlib/afm.h
+++ b/afmlib/afm.h
@@ -24,7 +24,7 @@
#define AFM_H
#ifndef ___P
-#if PROTOTYPES
+#if defined(__STDC__) || defined(PROTOTYPES)
#define ___P(protos) protos
#else /* no PROTOTYPES */
#define ___P(protos) ()
diff --git a/afmlib/afmint.h b/afmlib/afmint.h
index 7995ae5..aee449a 100644
--- a/afmlib/afmint.h
+++ b/afmlib/afmint.h
@@ -34,7 +34,7 @@
#include <stdio.h>
#ifndef ___P
-#if PROTOTYPES
+#if defined(__STDC__) || defined(PROTOTYPES)
#define ___P(protos) protos
#else /* no PROTOTYPES */
#define ___P(protos) ()
diff --git a/afmlib/strhash.h b/afmlib/strhash.h
index 938b2de..a91c0a9 100644
--- a/afmlib/strhash.h
+++ b/afmlib/strhash.h
@@ -24,7 +24,7 @@
#define STRHASH_H
#ifndef ___P
-#if PROTOTYPES
+#if defined(__STDC__) || defined(PROTOTYPES)
#define ___P(protos) protos
#else /* no PROTOTYPES */
#define ___P(protos) ()
diff --git a/compat/xalloc.h b/compat/xalloc.h
index 203bcb8..fd50b68 100644
--- a/compat/xalloc.h
+++ b/compat/xalloc.h
@@ -28,7 +28,7 @@
#define XALLOC_H
#ifndef ___P
-#if PROTOTYPES
+#if defined(__STDC__) || defined(PROTOTYPES)
#define ___P(protos) protos
#else /* no PROTOTYPES */
#define ___P(protos) ()
diff --git a/src/gsint.h b/src/gsint.h
index 3c2527a..001961c 100644
--- a/src/gsint.h
+++ b/src/gsint.h
@@ -39,7 +39,7 @@
#include <sys/stat.h>
#ifndef ___P
-#if PROTOTYPES
+#if defined(__STDC__) || defined(PROTOTYPES)
#define ___P(protos) protos
#else /* no PROTOTYPES */
#define ___P(protos) ()
diff --git a/states/defs.h b/states/defs.h
index 2808900..63155a9 100644
--- a/states/defs.h
+++ b/states/defs.h
@@ -37,7 +37,7 @@
#include <ctype.h>
#ifndef ___P
-#if PROTOTYPES
+#if defined(__STDC__) || defined(PROTOTYPES)
#define ___P(protos) protos
#else /* no PROTOTYPES */
#define ___P(protos) ()
--
2.55.0

View File

@@ -0,0 +1,35 @@
From be920933dbe1fb73c27fecb280200f6f06abfdc2 Mon Sep 17 00:00:00 2001
From: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Date: Sat, 22 Aug 2026 15:19:17 +0200
Subject: [PATCH] Use -std=gnu89 instead of -std=c89
-std=c89 suppresses feature test macros, which causes <limits.h> to
not define PATH_MAX on certain C libraries (e.g. musl). Using
-std=gnu89 enables _GNU_SOURCE and other extensions, ensuring
PATH_MAX and other POSIX constants are available.
This most notably fixes the build with the musl C library.
Upstream: https://savannah.gnu.org/bugs/index.php?68634
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
configure.ac | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/configure.ac b/configure.ac
index 4431cb1..46ea59d 100644
--- a/configure.ac
+++ b/configure.ac
@@ -11,7 +11,8 @@ AC_PROG_INSTALL
AC_PROG_CC
# Force C89 standard and fix modern GCC global variable handling
-CFLAGS="$CFLAGS -std=c89"
+# Use GNU89 to access PATH_MAX in <limits.h>
+CFLAGS="$CFLAGS -std=gnu89"
AC_USE_SYSTEM_EXTENSIONS
--
2.55.0

View File

@@ -9,6 +9,10 @@ ENSCRIPT_SITE = $(BR2_GNU_MIRROR)/enscript
ENSCRIPT_LICENSE = GPL-3.0+
ENSCRIPT_LICENSE_FILES = COPYING
ENSCRIPT_CPE_ID_VENDOR = gnu
# 0002-Add-CFLAG-std-c89-so-it-compiles-with-the-old-standa.patch
# 0003-Automake-1.12-and-up-no-longer-supports-pre-ANSI.patch
# 0005-Use-std-gnu89-instead-of-std-c89.patch
ENSCRIPT_AUTORECONF = YES
# Enable pthread threads if toolchain supports threads
ifeq ($(BR2_TOOLCHAIN_HAS_THREADS),y)

View File

@@ -0,0 +1,32 @@
From de58cbe979942308eb8823a526cd68b06d5dc662 Mon Sep 17 00:00:00 2001
From: Sacha <sachahony@gmail.com>
Date: Wed, 13 Mar 2024 13:28:41 +0100
Subject: [PATCH] Change libs order to avoid picking up system libei
Upstream: https://github.com/erlang/otp/commit/de58cbe
Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
---
lib/odbc/c_src/Makefile.in | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/lib/odbc/c_src/Makefile.in b/lib/odbc/c_src/Makefile.in
index d1b26743a6a4..03ed314f6a26 100644
--- a/lib/odbc/c_src/Makefile.in
+++ b/lib/odbc/c_src/Makefile.in
@@ -80,10 +80,10 @@ ODBC_INCLUDE = @ODBC_INCLUDE@
# ----------------------------------------------------
CC = @CC@
CFLAGS = $(TYPEFLAGS) @CFLAGS@ @THR_DEFS@ @DEFS@
-EI_LDFLAGS = -L$(EI_ROOT)/obj$(TYPEMARKER)/$(TARGET)
+EI_LDFLAGS = -L$(EI_ROOT)/obj$(TYPEMARKER)/$(TARGET) $(EI_LIB)
LD = @LD@
-LDFLAGS = $(ODBC_LIB) $(EI_LDFLAGS)
-LIBS = @LIBS@ @THR_LIBS@ $(EI_LIB)
+LDFLAGS = $(EI_LDFLAGS) $(ODBC_LIB)
+LIBS = @LIBS@ @THR_LIBS@
INCLUDES = -I. $(ODBC_INCLUDE) $(EI_INCLUDE)
TARGET_FLAGS = @TARGET_FLAGS@
--
2.55.0

View File

@@ -1,5 +1,5 @@
# From https://github.com/erlang/otp/releases/download/OTP-26.2.5.15/SHA256.txt
sha256 28e6d63d82927f132d56289dd3c428ef8bce6bf2283c8549aa0a7afca1a8fe3b otp_src_26.2.5.15.tar.gz
# From https://github.com/erlang/otp/releases/download/OTP-26.2.5.21/SHA256.txt
sha256 e1fde86f4e2874d4c136221a34753b5b785d762b910fb3fb35a23a6a7faf0a64 otp_src_26.2.5.21.tar.gz
# Hash for license file
sha256 809fa1ed21450f59827d1e9aec720bbc4b687434fa22283c6cb5dd82a47ab9c0 LICENSE.txt

View File

@@ -4,7 +4,7 @@
#
################################################################################
ERLANG_VERSION = 26.2.5.15
ERLANG_VERSION = 26.2.5.21
ERLANG_RELEASE = $(firstword $(subst ., ,$(ERLANG_VERSION)))
ERLANG_SITE = \
https://github.com/erlang/otp/releases/download/OTP-$(ERLANG_VERSION)

View File

@@ -1,3 +1,3 @@
# Locally calculated
sha256 ea51b0609f58a9afa063b60daa1539948b62247721e154f4fff0ad3aec9f9756 exiv2-0.28.8.tar.gz
sha256 700b76b97695b2fab4ef8c79619c68ae57d09e0c130724791cafbd39e0eb4aef exiv2-0.28.9.tar.gz
sha256 a7ba75cb966aca374711e2af49e5f3aea6a4443a803440f5d93e73a5a1222f66 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
EXIV2_VERSION = 0.28.8
EXIV2_VERSION = 0.28.9
EXIV2_SITE = $(call github,Exiv2,exiv2,v$(EXIV2_VERSION))
EXIV2_INSTALL_STAGING = YES
EXIV2_LICENSE = GPL-2.0+

View File

@@ -1,4 +1,4 @@
# From https://github.com/libexpat/libexpat/releases/tag/R_2_8_3
sha256 f6256df90c906773d344da084402b7d3e4f22ed41b1a59c989098a83d3ea0c85 expat-2.8.3.tar.xz
# From https://github.com/libexpat/libexpat/releases/tag/R_2_8_4
sha256 656ae1cc8da3b4ea513bb4e254f33e6243938084c0ec6239da873376b09985a7 expat-2.8.4.tar.xz
# Locally calculated
sha256 31b15de82aa19a845156169a17a5488bf597e561b2c318d159ed583139b25e87 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
EXPAT_VERSION = 2.8.3
EXPAT_VERSION = 2.8.4
EXPAT_SITE = https://github.com/libexpat/libexpat/releases/download/R_$(subst .,_,$(EXPAT_VERSION))
EXPAT_SOURCE = expat-$(EXPAT_VERSION).tar.xz
EXPAT_INSTALL_STAGING = YES
@@ -14,8 +14,16 @@ EXPAT_CPE_ID_VENDOR = libexpat_project
EXPAT_CPE_ID_PRODUCT = libexpat
EXPAT_CONF_OPTS = \
--without-docbook --without-examples --without-tests --without-xmlwf
HOST_EXPAT_CONF_OPTS = --without-docbook --without-examples --without-tests
--with-dev-urandom \
--without-docbook \
--without-examples \
--without-tests \
--without-xmlwf
HOST_EXPAT_CONF_OPTS = \
--without-docbook \
--without-examples \
--without-tests
$(eval $(autotools-package))
$(eval $(host-autotools-package))

View File

@@ -1,4 +1,4 @@
# From https://sourceforge.net/p/fetchmail/mailman/message/59347909/
sha256 ab0320fe4df0b5ee8659189e66590d9de96aadbf929fe59f353ae7a317e9ef1e fetchmail-6.6.5.tar.xz
# From https://sourceforge.net/p/fetchmail/mailman/message/59381086/
sha256 bece8aaaa68e029eed9fd55fffd2adc7dd6cd5e9574d5bf92e2d9208bd97a881 fetchmail-6.6.7.tar.xz
# Locally computed:
sha256 48aea24325e55932dbd79b30f558b9c87a416d675fe5f94445e8be5cb6606fde COPYING

View File

@@ -5,7 +5,7 @@
################################################################################
FETCHMAIL_VERSION_MAJOR = 6.6
FETCHMAIL_VERSION = $(FETCHMAIL_VERSION_MAJOR).5
FETCHMAIL_VERSION = $(FETCHMAIL_VERSION_MAJOR).7
FETCHMAIL_SOURCE = fetchmail-$(FETCHMAIL_VERSION).tar.xz
FETCHMAIL_SITE = https://downloads.sourceforge.net/project/fetchmail/branch_$(FETCHMAIL_VERSION_MAJOR)
FETCHMAIL_LICENSE = GPL-2.0; some exceptions are mentioned in COPYING

View File

@@ -0,0 +1,184 @@
From 5f441f438f086553698e899fa0a475dbb0237d02 Mon Sep 17 00:00:00 2001
From: Explorer09 <explorer09@gmail.com>
Date: Wed, 8 May 2024 21:04:01 +0800
Subject: [PATCH] build: Update AX_PROG_CC_FOR_BUILD to fix BUILD_EXEEXT
problems
Upstream: 787edd41833e14e986ff093f7216e7005aca5fe2
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
m4/ax_prog_cc_for_build.m4 | 102 ++++++++++++++++++++++++++++---------
1 file changed, 77 insertions(+), 25 deletions(-)
diff --git a/m4/ax_prog_cc_for_build.m4 b/m4/ax_prog_cc_for_build.m4
index 77fd346..3d28252 100644
--- a/m4/ax_prog_cc_for_build.m4
+++ b/m4/ax_prog_cc_for_build.m4
@@ -1,5 +1,5 @@
# ===========================================================================
-# http://www.gnu.org/software/autoconf-archive/ax_prog_cc_for_build.html
+# https://www.gnu.org/software/autoconf-archive/ax_prog_cc_for_build.html
# ===========================================================================
#
# SYNOPSIS
@@ -32,28 +32,34 @@
# and this notice are preserved. This file is offered as-is, without any
# warranty.
-#serial 8
+#serial 21
+# With patches not yet merged upstream
+# <https://savannah.gnu.org/patch/index.php?10452>
AU_ALIAS([AC_PROG_CC_FOR_BUILD], [AX_PROG_CC_FOR_BUILD])
AC_DEFUN([AX_PROG_CC_FOR_BUILD], [dnl
AC_REQUIRE([AC_PROG_CC])dnl
AC_REQUIRE([AC_PROG_CPP])dnl
-AC_REQUIRE([AC_EXEEXT])dnl
-AC_REQUIRE([AC_CANONICAL_HOST])dnl
+AC_REQUIRE([AC_CANONICAL_BUILD])dnl
dnl Use the standard macros, but make them use other variable names
dnl
pushdef([ac_cv_prog_CPP], ac_cv_build_prog_CPP)dnl
pushdef([ac_cv_prog_gcc], ac_cv_build_prog_gcc)dnl
+pushdef([ac_cv_prog_cc_c89], ac_cv_build_prog_cc_c89)dnl
+pushdef([ac_cv_prog_cc_c99], ac_cv_build_prog_cc_c99)dnl
+pushdef([ac_cv_prog_cc_c11], ac_cv_build_prog_cc_c11)dnl
+pushdef([ac_cv_prog_cc_c23], ac_cv_build_prog_cc_c23)dnl
+pushdef([ac_cv_prog_cc_stdc], ac_cv_build_prog_cc_stdc)dnl
pushdef([ac_cv_prog_cc_works], ac_cv_build_prog_cc_works)dnl
pushdef([ac_cv_prog_cc_cross], ac_cv_build_prog_cc_cross)dnl
pushdef([ac_cv_prog_cc_g], ac_cv_build_prog_cc_g)dnl
-pushdef([ac_cv_exeext], ac_cv_build_exeext)dnl
-pushdef([ac_cv_objext], ac_cv_build_objext)dnl
+pushdef([ac_prog_cc_stdc], ac_build_prog_cc_stdc)dnl
pushdef([ac_exeext], ac_build_exeext)dnl
pushdef([ac_objext], ac_build_objext)dnl
pushdef([CC], CC_FOR_BUILD)dnl
pushdef([CPP], CPP_FOR_BUILD)dnl
+pushdef([GCC], GCC_FOR_BUILD)dnl
pushdef([CFLAGS], CFLAGS_FOR_BUILD)dnl
pushdef([CPPFLAGS], CPPFLAGS_FOR_BUILD)dnl
pushdef([LDFLAGS], LDFLAGS_FOR_BUILD)dnl
@@ -67,27 +73,58 @@ pushdef([ac_cv_host_alias], ac_cv_build_alias)dnl
pushdef([ac_cv_host_cpu], ac_cv_build_cpu)dnl
pushdef([ac_cv_host_vendor], ac_cv_build_vendor)dnl
pushdef([ac_cv_host_os], ac_cv_build_os)dnl
-pushdef([ac_cpp], ac_build_cpp)dnl
-pushdef([ac_compile], ac_build_compile)dnl
-pushdef([ac_link], ac_build_link)dnl
+pushdef([ac_tool_prefix], ac_build_tool_prefix)dnl
+pushdef([am_cv_CC_dependencies_compiler_type], am_cv_build_CC_dependencies_compiler_type)dnl
+pushdef([am_cv_prog_cc_c_o], am_cv_build_prog_cc_c_o)dnl
+pushdef([cross_compiling], cross_compiling_build)dnl
+dnl
+dnl These variables are problematic to rename by M4 macros, so we save
+dnl their values in alternative names, and restore the values later.
+dnl
+dnl _AC_COMPILER_EXEEXT and _AC_COMPILER_OBJEXT internally call
+dnl AC_SUBST which prevents the renaming of EXEEXT and OBJEXT
+dnl variables. It's not a good idea to rename ac_cv_exeext and
+dnl ac_cv_objext either as they're related.
+dnl Renaming ac_exeext and ac_objext is safe though.
+dnl
+ac_cv_host_exeext=$ac_cv_exeext
+AS_VAR_SET_IF([ac_cv_build_exeext],
+ [ac_cv_exeext=$ac_cv_build_exeext],
+ [AS_UNSET([ac_cv_exeext])])
+ac_cv_host_objext=$ac_cv_objext
+AS_VAR_SET_IF([ac_cv_build_objext],
+ [ac_cv_objext=$ac_cv_build_objext],
+ [AS_UNSET([ac_cv_objext])])
+dnl
+dnl ac_cv_c_compiler_gnu is used in _AC_LANG_COMPILER_GNU (called by
+dnl AC_PROG_CC) indirectly.
+dnl
+ac_cv_host_c_compiler_gnu=$ac_cv_c_compiler_gnu
+AS_VAR_SET_IF([ac_cv_build_c_compiler_gnu],
+ [ac_cv_c_compiler_gnu=$ac_cv_build_c_compiler_gnu],
+ [AS_UNSET([ac_cv_c_compiler_gnu])])
+
+cross_compiling_build=no
-save_cross_compiling=$cross_compiling
-save_ac_tool_prefix=$ac_tool_prefix
-cross_compiling=no
-ac_tool_prefix=
+ac_build_tool_prefix=
+AS_IF([test -n "$build"], [ac_build_tool_prefix="$build-"],
+ [test -n "$build_alias"],[ac_build_tool_prefix="$build_alias-"])
+AC_LANG_PUSH([C])
AC_PROG_CC
+_AC_COMPILER_EXEEXT
+_AC_COMPILER_OBJEXT
AC_PROG_CPP
-AC_EXEEXT
-ac_tool_prefix=$save_ac_tool_prefix
-cross_compiling=$save_cross_compiling
+BUILD_EXEEXT=$ac_cv_exeext
+BUILD_OBJEXT=$ac_cv_objext
dnl Restore the old definitions
dnl
-popdef([ac_link])dnl
-popdef([ac_compile])dnl
-popdef([ac_cpp])dnl
+popdef([cross_compiling])dnl
+popdef([am_cv_prog_cc_c_o])dnl
+popdef([am_cv_CC_dependencies_compiler_type])dnl
+popdef([ac_tool_prefix])dnl
popdef([ac_cv_host_os])dnl
popdef([ac_cv_host_vendor])dnl
popdef([ac_cv_host_cpu])dnl
@@ -101,24 +138,39 @@ popdef([host])dnl
popdef([LDFLAGS])dnl
popdef([CPPFLAGS])dnl
popdef([CFLAGS])dnl
+popdef([GCC])dnl
popdef([CPP])dnl
popdef([CC])dnl
popdef([ac_objext])dnl
popdef([ac_exeext])dnl
-popdef([ac_cv_objext])dnl
-popdef([ac_cv_exeext])dnl
+popdef([ac_prog_cc_stdc])dnl
popdef([ac_cv_prog_cc_g])dnl
popdef([ac_cv_prog_cc_cross])dnl
popdef([ac_cv_prog_cc_works])dnl
+popdef([ac_cv_prog_cc_stdc])dnl
+popdef([ac_cv_prog_cc_c23])dnl
+popdef([ac_cv_prog_cc_c11])dnl
+popdef([ac_cv_prog_cc_c99])dnl
+popdef([ac_cv_prog_cc_c89])dnl
popdef([ac_cv_prog_gcc])dnl
popdef([ac_cv_prog_CPP])dnl
+dnl
+ac_cv_exeext=$ac_cv_host_exeext
+EXEEXT=$ac_cv_host_exeext
+ac_cv_objext=$ac_cv_host_objext
+OBJEXT=$ac_cv_host_objext
+ac_cv_c_compiler_gnu=$ac_cv_host_c_compiler_gnu
+ac_compiler_gnu=$ac_cv_host_c_compiler_gnu
+
+dnl restore global variables ac_ext, ac_cpp, ac_compile,
+dnl ac_link, ac_compiler_gnu (dependant on the current
+dnl language after popping):
+AC_LANG_POP([C])
dnl Finally, set Makefile variables
dnl
-BUILD_EXEEXT=$ac_build_exeext
-BUILD_OBJEXT=$ac_build_objext
-AC_SUBST(BUILD_EXEEXT)dnl
-AC_SUBST(BUILD_OBJEXT)dnl
+AC_SUBST([BUILD_EXEEXT])dnl
+AC_SUBST([BUILD_OBJEXT])dnl
AC_SUBST([CFLAGS_FOR_BUILD])dnl
AC_SUBST([CPPFLAGS_FOR_BUILD])dnl
AC_SUBST([LDFLAGS_FOR_BUILD])dnl
--
2.55.0

View File

@@ -0,0 +1,41 @@
From f558b8656efe8bba7dd94f4acfceb1294a7ded22 Mon Sep 17 00:00:00 2001
From: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Date: Thu, 27 Aug 2026 08:59:32 +0200
Subject: [PATCH] cmake: fix finding bundled GCEM with a sysroot
CMAKE_FIND_ROOT_PATH_MODE_INCLUDE may be set to ONLY when cross
compiling, to ensure that header searches use the target sysroot
instead of accidentally finding host headers.
This causes find_path() to re-root the absolute path to the bundled
GCEM headers under the target sysroot, making FindGCEM miss
gcem/include/gcem.hpp in situations where
CMAKE_FIND_ROOT_PATH_MODE_INCLUDE is set to ONLY.
To fix this, this commit passes NO_CMAKE_FIND_ROOT_PATH to prevent
sysroot re-rooting when searching this source-tree path. It allows to
properly detected gcem/include/gcem.hpp and avoid the download if
already present.
Upstream: https://github.com/FluidSynth/fluidsynth/pull/1835
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
cmake_admin/FindGCEM.cmake | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/cmake_admin/FindGCEM.cmake b/cmake_admin/FindGCEM.cmake
index 980951cc..e02d97f8 100644
--- a/cmake_admin/FindGCEM.cmake
+++ b/cmake_admin/FindGCEM.cmake
@@ -23,7 +23,7 @@ This will define the following variables:
#]=======================================================================]
# Find the headers and library
-find_path(GCEM_INCLUDE_DIR NAMES "gcem.hpp" PATHS "${CMAKE_CURRENT_SOURCE_DIR}/gcem/include")
+find_path(GCEM_INCLUDE_DIR NAMES "gcem.hpp" PATHS "${CMAKE_CURRENT_SOURCE_DIR}/gcem/include" NO_CMAKE_FIND_ROOT_PATH)
include(FindPackageHandleStandardArgs)
--
2.55.0

View File

@@ -84,15 +84,11 @@ comment "pulseaudio support needs a toolchain w/ dynamic library, wchar, threads
depends on BR2_PACKAGE_PULSEAUDIO_HAS_ATOMIC
depends on BR2_STATIC_LIBS || !BR2_USE_MMU || !BR2_TOOLCHAIN_HAS_THREADS
config BR2_PACKAGE_FLUIDSYNTH_SDL2
bool "sdl2"
depends on !BR2_STATIC_LIBS
select BR2_PACKAGE_SDL2
config BR2_PACKAGE_FLUIDSYNTH_SDL3
bool "sdl3"
select BR2_PACKAGE_SDL3
help
Enable SDL2 audio support.
comment "SDL2 audio support needs a toolchain w/ dynamic library"
depends on BR2_STATIC_LIBS
Enable SDL3 audio support.
comment "Misc options"
@@ -114,6 +110,15 @@ config BR2_PACKAGE_FLUIDSYNTH_FLOATS
Enable 32-bit single precision float support, instead of
64-bit double precision floats for DSP samples.
config BR2_PACKAGE_FLUIDSYNTH_NATIVE_DLS
bool "Native DLS soundfont"
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_7 # C++17
help
Enable the native DLS soundfont format support.
comment "native dls soundfont support needs gcc >= 7"
depends on !BR2_TOOLCHAIN_GCC_AT_LEAST_7
config BR2_PACKAGE_FLUIDSYNTH_READLINE
bool "readline"
select BR2_PACKAGE_READLINE

View File

@@ -1,3 +1,4 @@
# Locally computed
sha256 7fb0e328c66a24161049e2b9e27c3b6e51a6904b31b1a647f73cc1f322523e88 fluidsynth-2.4.7.tar.gz
sha256 9b872a8a070b8ad329c4bd380fb1bf0000f564c75023ec8e1e6803f15364b9e9 LICENSE
sha256 ce27840221ab00dd59bf27e85ecbba480c6c2a7c9fbec4243658f68f59c07f4a fluidsynth-2.5.7.tar.gz
sha256 34ab0ee87a9eb26d3087fa9b49c2572ea8ee03db0c9705b83648301a3a3fc172 gcem-012ae73c6d0a2cb09ffe86475f5c6fba3926e200.tar.gz
sha256 20e50fe7aae3e56378ebf0417d9de904f55a0e61e4df315333e632a4d3555d95 LICENSE

View File

@@ -4,7 +4,7 @@
#
################################################################################
FLUIDSYNTH_VERSION = 2.4.7
FLUIDSYNTH_VERSION = 2.5.7
FLUIDSYNTH_SITE = $(call github,FluidSynth,fluidsynth,v$(FLUIDSYNTH_VERSION))
FLUIDSYNTH_LICENSE = LGPL-2.1+
FLUIDSYNTH_LICENSE_FILES = LICENSE
@@ -12,6 +12,18 @@ FLUIDSYNTH_CPE_ID_VENDOR = fluidsynth
FLUIDSYNTH_INSTALL_STAGING = YES
FLUIDSYNTH_DEPENDENCIES = libglib2
FLUIDSYNTH_GCEM_VERSION = 012ae73c6d0a2cb09ffe86475f5c6fba3926e200
FLUIDSYNTH_EXTRA_DOWNLOADS = $(call github,kthohr,gcem,$(FLUIDSYNTH_GCEM_VERSION))/gcem-$(FLUIDSYNTH_GCEM_VERSION).tar.gz
define FLUIDSYNTH_GCEM_EXTRACT
$(call suitable-extractor,$(notdir $(FLUIDSYNTH_EXTRA_DOWNLOADS))) \
$(FLUIDSYNTH_DL_DIR)/$(notdir $(FLUIDSYNTH_EXTRA_DOWNLOADS)) | \
$(TAR) -C $(@D)/ $(TAR_OPTIONS) -
rmdir $(@D)/gcem
ln -sf gcem-$(FLUIDSYNTH_GCEM_VERSION) $(@D)/gcem
endef
FLUIDSYNTH_POST_EXTRACT_HOOKS += FLUIDSYNTH_GCEM_EXTRACT
ifeq ($(BR2_PACKAGE_FLUIDSYNTH_ALSA_LIB),y)
FLUIDSYNTH_CONF_OPTS += -Denable-alsa=1
FLUIDSYNTH_DEPENDENCIES += alsa-lib
@@ -46,6 +58,12 @@ else
FLUIDSYNTH_CONF_OPTS += -Denable-libsndfile=0
endif
ifeq ($(BR2_PACKAGE_FLUIDSYNTH_NATIVE_DLS),y)
FLUIDSYNTH_CONF_OPTS += -Denable-native-dls=1
else
FLUIDSYNTH_CONF_OPTS += -Denable-native-dls=0
endif
ifeq ($(BR2_PACKAGE_FLUIDSYNTH_PORTAUDIO),y)
FLUIDSYNTH_CONF_OPTS += -Denable-portaudio=1
FLUIDSYNTH_DEPENDENCIES += portaudio
@@ -67,11 +85,11 @@ else
FLUIDSYNTH_CONF_OPTS += -Denable-readline=0
endif
ifeq ($(BR2_PACKAGE_FLUIDSYNTH_SDL2),y)
FLUIDSYNTH_CONF_OPTS += -Denable-sdl2=1
FLUIDSYNTH_DEPENDENCIES += sdl2
ifeq ($(BR2_PACKAGE_FLUIDSYNTH_SDL3),y)
FLUIDSYNTH_CONF_OPTS += -Denable-sdl3=1
FLUIDSYNTH_DEPENDENCIES += sdl3
else
FLUIDSYNTH_CONF_OPTS += -Denable-sdl2=0
FLUIDSYNTH_CONF_OPTS += -Denable-sdl3=0
endif
ifeq ($(BR2_PACKAGE_SYSTEMD),y)

View File

@@ -1,5 +1,5 @@
# From https://files.freeswitch.org/freeswitch-releases/freeswitch-1.11.2.-release.tar.xz.sha256
sha256 1a460e28a0309bf2e29397f0dc7cebecaa579c9f19efa9a301dfc6bf5015d17e freeswitch-1.11.2.-release.tar.xz
# From https://files.freeswitch.org/freeswitch-releases/freeswitch-1.11.3.-release.tar.xz.sha256
sha256 4c93cbce869cf928bc9e8b3a48fe40337199b348ab668def77e3f739796a3852 freeswitch-1.11.3.-release.tar.xz
# Locally computed
sha256 75c933202f40939cdc3827fce20a1efdaa38291e2b5a65d234eb16e2cffda66a COPYING
sha256 c3e3388768dae8bf4edcc4108f95be815b8a05c0b0aef6e4c3d8df81affdfa34 docs/OPENH264_BINARY_LICENSE.txt

View File

@@ -4,7 +4,7 @@
#
################################################################################
FREESWITCH_VERSION = 1.11.2
FREESWITCH_VERSION = 1.11.3
FREESWITCH_SOURCE = freeswitch-$(FREESWITCH_VERSION).-release.tar.xz
FREESWITCH_SITE = https://files.freeswitch.org/freeswitch-releases
# External modules need headers/libs from staging

View File

@@ -70,7 +70,6 @@ HOST_GCC_COMMON_CONF_OPTS = \
--with-gnu-ld \
--disable-libssp \
--disable-multilib \
--disable-decimal-float \
--enable-plugins \
--enable-lto \
--with-gmp=$(HOST_DIR) \
@@ -80,6 +79,15 @@ HOST_GCC_COMMON_CONF_OPTS = \
--with-bugurl="https://gitlab.com/buildroot.org/buildroot/-/issues" \
--without-zstd
# https://gcc.gnu.org/gcc-16/changes.html#s390
# Floating-point type _Float16 added in gcc-16 on s390 now requires
# decimal float support enabled in the toolchain.
ifeq ($(BR2_s390x)$(BR2_TOOLCHAIN_GCC_AT_LEAST_16),yy)
HOST_GCC_COMMON_CONF_OPTS += --enable-decimal-float
else
HOST_GCC_COMMON_CONF_OPTS += --disable-decimal-float
endif
ifeq ($(BR2_REPRODUCIBLE),y)
HOST_GCC_COMMON_CONF_OPTS += --with-debug-prefix-map=$(BASE_DIR)=buildroot
endif

View File

@@ -44,6 +44,16 @@ config BR2_PACKAGE_HOST_GDB_SIM
help
This option enables the simulator support in the cross gdb.
config BR2_PACKAGE_HOST_GDB_LZMA
bool "lzma support"
help
This option enables lzma support in the cross gdb.
config BR2_PACKAGE_HOST_GDB_XXHASH
bool "xxhash support"
help
This option enables xxhash support in the cross gdb.
choice
prompt "GDB debugger Version"
default BR2_GDB_VERSION_16
@@ -67,6 +77,6 @@ endif
config BR2_GDB_VERSION
string
default "15.2" if BR2_GDB_VERSION_15
default "16.3" if BR2_GDB_VERSION_16
default "16.3" if BR2_GDB_VERSION_16 || !BR2_PACKAGE_HOST_GDB
default "17.1" if BR2_GDB_VERSION_17
depends on BR2_PACKAGE_GDB || BR2_PACKAGE_HOST_GDB

View File

@@ -217,6 +217,14 @@ else
GDB_CONF_OPTS += --without-expat
endif
ifeq ($(BR2_PACKAGE_XXHASH),y)
GDB_CONF_OPTS += --with-xxhash
GDB_CONF_OPTS += --with-xxhash-prefix=$(STAGING_DIR)/usr
GDB_DEPENDENCIES += xxhash
else
GDB_CONF_OPTS += --without-xxhash
endif
ifeq ($(BR2_PACKAGE_XZ),y)
GDB_CONF_OPTS += --with-lzma
GDB_CONF_OPTS += --with-liblzma-prefix=$(STAGING_DIR)/usr
@@ -293,6 +301,22 @@ else
HOST_GDB_CONF_OPTS += --disable-sim
endif
ifeq ($(BR2_PACKAGE_HOST_GDB_LZMA),y)
HOST_GDB_CONF_OPTS += --with-lzma
HOST_GDB_CONF_OPTS += --with-liblzma-prefix=$(HOST_DIR)
HOST_GDB_DEPENDENCIES += host-xz
else
HOST_GDB_CONF_OPTS += --without-lzma
endif
ifeq ($(BR2_PACKAGE_HOST_GDB_XXHASH),y)
HOST_GDB_CONF_OPTS += --with-xxhash
HOST_GDB_CONF_OPTS += --with-xxhash-prefix=$(HOST_DIR)
HOST_GDB_DEPENDENCIES += host-xxhash
else
HOST_GDB_CONF_OPTS += --without-xxhash
endif
# Since gdb 9, in-tree builds for GDB are not allowed anymore,
# so we create a 'build' subdirectory in the gdb sources, and
# build from there.

View File

@@ -1,5 +1,5 @@
# Locally calculated (fetched from git)
sha256 a818ca8450ef1e19a2413b2c9a2882f381f05be07b31e9b38085b6ba193d0af2 glibc-2.44-23-g11ac3d78fc5e4f7f2846002e099f773ad8ff82fc-git4.tar.gz
sha256 39f6808e31a02da42f774912c6754ea22d5f076c4e935b1e233f3602d4d772c0 glibc-2.44-36-g2d5421ffca8893534d5e02ad38c28acd8e778fa3-git4.tar.gz
# Hashes for license files
sha256 edaef632cbb643e4e7a221717a6c441a4c1a7c918e6e4d56debc3d8739b233f6 COPYINGv2

View File

@@ -7,7 +7,7 @@
# Generate version string using:
# git describe --match 'glibc-*' --abbrev=40 origin/release/MAJOR.MINOR/master | cut -d '-' -f 2-
# When updating the version, please also update localedef
GLIBC_VERSION = 2.44-23-g11ac3d78fc5e4f7f2846002e099f773ad8ff82fc
GLIBC_VERSION = 2.44-36-g2d5421ffca8893534d5e02ad38c28acd8e778fa3
GLIBC_SITE = https://gitlab.com/gnutools/glibc.git
GLIBC_SITE_METHOD = git
@@ -25,6 +25,18 @@ GLIBC_CPE_ID_VENDOR = gnu
# allow proper matching with the CPE database.
GLIBC_CPE_ID_VERSION = $(word 1, $(subst -,$(space),$(GLIBC_VERSION)))
# Fixed by 2.44-26-gd6ff274313d79feb864cc10eb775b91c817a67e9
GLIBC_IGNORE_CVES += CVE-2026-19542
# Fixed by 2.44-29-g63b53df549451a5d69fcba6d7612ea99f517e8e3
GLIBC_IGNORE_CVES += CVE-2026-19499
# Fixed by 2.44-30-g6f9b2bfa500bf5d1cff5d990adfff4b71298dadd
GLIBC_IGNORE_CVES += CVE-2026-77117
# Fixed by 2.44-31-gcb61572ea3f773e1e1978f6c412cc36a30acdb0c
GLIBC_IGNORE_CVES += CVE-2026-80489
# This CVE is considered as not being security issues by
# upstream glibc:
# https://security-tracker.debian.org/tracker/CVE-2010-4756

View File

@@ -403,13 +403,15 @@ config BR2_PACKAGE_GST1_PLUGINS_GOOD_PLUGIN_SPEEX
config BR2_PACKAGE_GST1_PLUGINS_GOOD_PLUGIN_TAGLIB
bool "taglib"
depends on BR2_INSTALL_LIBSTDCPP
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_7 # C++17
depends on BR2_USE_WCHAR
select BR2_PACKAGE_TAGLIB
help
Taglib tagging plugin library
comment "taglib needs a toolchain w/ C++, wchar"
depends on !BR2_INSTALL_LIBSTDCPP || !BR2_USE_WCHAR
comment "taglib needs a toolchain w/ C++, wchar, gcc >= 7"
depends on !BR2_INSTALL_LIBSTDCPP || !BR2_USE_WCHAR \
|| !BR2_TOOLCHAIN_GCC_AT_LEAST_7
config BR2_PACKAGE_GST1_PLUGINS_GOOD_PLUGIN_TWOLAME
bool "twolame"

View File

@@ -15,8 +15,10 @@ HAPROXY_CPE_ID_VENDOR = haproxy
# https://git.haproxy.org/?p=haproxy-2.6.git;a=commit;h=832b672eee54866c7a42a1d46078cc9ae0d544d9
HAPROXY_IGNORE_CVES += CVE-2023-45539
# haproxy relies on signed overflow, so MUST be built with -fwrapv
HAPROXY_MAKE_OPTS = \
LD=$(TARGET_CC) \
CFLAGS="$(TARGET_CFLAGS) -fwrapv" \
PREFIX=/usr \
TARGET=custom

View File

@@ -0,0 +1,36 @@
From 2c947e90d93d9c5a0129b62744de9720b48d2a17 Mon Sep 17 00:00:00 2001
From: Nicola Fontana <ntd@entidi.it>
Date: Sun, 8 Mar 2026 15:39:41 +0100
Subject: [PATCH] Linux 6.19.0 support
Commit 89aec171d9d1ab168e43fcf9754b82e4c0aef9b9 (part of linux kernel
6.19.0-rc1) introduced an arbitrarily sized sockaddr struct to be used
instead of the classical one.
Closes #200
Upstream: https://gitlab.com/etherlab.org/ethercat/-/commit/c42c9cf8bc31c56cc20ae630605495e3f19f3f9a
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
devices/generic.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/devices/generic.c b/devices/generic.c
index f6cef9b5..a08af54b 100644
--- a/devices/generic.c
+++ b/devices/generic.c
@@ -234,7 +234,11 @@ int ec_gen_device_create_socket(
sa.sll_family = AF_PACKET;
sa.sll_protocol = htons(ETH_P_ETHERCAT);
sa.sll_ifindex = desc->ifindex;
+#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 19, 0)
+ ret = kernel_bind(dev->socket, (struct sockaddr_unsized *) &sa, sizeof(sa));
+#else
ret = kernel_bind(dev->socket, (struct sockaddr *) &sa, sizeof(sa));
+#endif
if (ret) {
printk(KERN_ERR PFX "Failed to bind() socket to interface"
" (ret = %i).\n", ret);
--
2.55.0

View File

@@ -0,0 +1,113 @@
From 0da22762971551462cfad8f0b11cfb037472a4e8 Mon Sep 17 00:00:00 2001
From: DRC <information@libjpeg-turbo.org>
Date: Thu, 16 Jul 2026 12:09:54 -0400
Subject: [PATCH] libspng: Really remove gamma correction code
We really don't use it, and fpclassify() apparently introduces yet
another libm dependency in some cases (although I can't reproduce that.)
Fixes #904
Upstream: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/0da22762971551462cfad8f0b11cfb037472a4e8
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
src/spng/spng.c | 20 ++++++++++++++++++--
1 file changed, 18 insertions(+), 2 deletions(-)
diff --git a/src/spng/spng.c b/src/spng/spng.c
index 06249d68..aeadb67e 100644
--- a/src/spng/spng.c
+++ b/src/spng/spng.c
@@ -353,9 +353,12 @@ struct spng_ctx
int widest_pass;
int last_pass; /* last non-empty pass */
+#if 0 /* libjpeg-turbo: Eliminate unused gamma correction code, which
+ introduces an unwanted libm dependency */
uint16_t *gamma_lut; /* points to either _lut8 or _lut16 */
uint16_t *gamma_lut16;
uint16_t gamma_lut8[256];
+#endif
unsigned char trns_px[8];
union spng__decode_plte decode_plte;
struct spng_sbit decode_sb;
@@ -1742,6 +1745,8 @@ static uint16_t sample_to_target(uint16_t sample, unsigned bit_depth, unsigned s
return sample;
}
+#if 0 /* libjpeg-turbo: Eliminate unused gamma correction code, which
+ introduces an unwanted libm dependency */
static inline void gamma_correct_row(unsigned char *row, uint32_t pixels, int fmt, const uint16_t *gamma_lut)
{
uint32_t i;
@@ -1785,6 +1790,7 @@ static inline void gamma_correct_row(unsigned char *row, uint32_t pixels, int fm
}
}
}
+#endif
/* Apply transparency to output row */
static inline void trns_row(unsigned char *row,
@@ -3302,7 +3308,10 @@ int spng_decode_scanline(spng_ctx *ctx, void *out, size_t len)
const struct spng_subimage *sub = ctx->subimage;
const struct spng_ihdr *ihdr = &ctx->ihdr;
+#if 0 /* libjpeg-turbo: Eliminate unused gamma correction code, which
+ introduces an unwanted libm dependency */
const uint16_t *gamma_lut = ctx->gamma_lut;
+#endif
unsigned char *trns_px = ctx->trns_px;
const struct spng_sbit *sb = &ctx->decode_sb;
const struct spng_plte_entry *plte = ctx->decode_plte.rgba;
@@ -3529,7 +3538,10 @@ int spng_decode_scanline(spng_ctx *ctx, void *out, size_t len)
if(f.do_scaling) scale_row(out, width, fmt, processing_depth, sb);
+#if 0 /* libjpeg-turbo: Eliminate unused gamma correction code, which
+ introduces an unwanted libm dependency */
if(f.apply_gamma) gamma_correct_row(out, width, fmt, gamma_lut);
+#endif
/* The previous scanline is always defiltered */
void *t = ctx->prev_scanline;
@@ -3768,6 +3780,8 @@ int spng_decode_image(spng_ctx *ctx, void *out, size_t len, int fmt, int flags)
/*if(f.same_layout && !flags && !f.interlaced) f.zerocopy = 1;*/
+#if 0 /* libjpeg-turbo: Eliminate unused gamma correction code, which
+ introduces an unwanted libm dependency */
uint16_t *gamma_lut = NULL;
if(f.apply_gamma)
@@ -3807,15 +3821,14 @@ int spng_decode_image(spng_ctx *ctx, void *out, size_t len, int fmt, int flags)
unsigned i;
for(i=0; i < lut_entries; i++)
{
-#if 0 /* libjpeg-turbo: Eliminate libm dependency */
float c = pow((float)i / max, exponent) * max;
-#endif
float c = 0.0f;
if(c > max) c = max;
gamma_lut[i] = (uint16_t)c;
}
}
+#endif
struct spng_sbit *sb = &ctx->decode_sb;
@@ -5000,7 +5013,10 @@ void spng_ctx_free(spng_ctx *ctx)
if(!ctx->user_owns_out_png) spng__free(ctx, ctx->out_png);
+#if 0 /* libjpeg-turbo: Eliminate unused gamma correction code, which
+ introduces an unwanted libm dependency */
spng__free(ctx, ctx->gamma_lut16);
+#endif
spng__free(ctx, ctx->row_buf);
spng__free(ctx, ctx->scanline_buf);
--
2.47.3

View File

@@ -15,7 +15,7 @@ JPEG_TURBO_INSTALL_STAGING = YES
JPEG_TURBO_PROVIDES = jpeg
JPEG_TURBO_DEPENDENCIES = host-pkgconf
JPEG_TURBO_CONF_OPTS = -DWITH_JPEG8=ON
JPEG_TURBO_CONF_OPTS = -DWITH_JPEG8=ON -DWITH_TESTS=OFF
ifeq ($(BR2_STATIC_LIBS),y)
JPEG_TURBO_CONF_OPTS += -DENABLE_STATIC=ON -DENABLE_SHARED=OFF
@@ -43,11 +43,10 @@ ifeq ($(BR2_STATIC_LIBS),)
JPEG_TURBO_CONF_OPTS += -DCMAKE_POSITION_INDEPENDENT_CODE=ON
endif
ifeq ($(BR2_PACKAGE_JPEG_TURBO_TOOLS),)
define JPEG_TURBO_REMOVE_TOOLS
rm -f $(addprefix $(TARGET_DIR)/usr/bin/,cjpeg djpeg jpegtran rdjpgcom tjbench wrjpgcom)
endef
JPEG_TURBO_POST_INSTALL_TARGET_HOOKS += JPEG_TURBO_REMOVE_TOOLS
ifeq ($(BR2_PACKAGE_JPEG_TURBO_TOOLS),y)
JPEG_TURBO_CONF_OPTS += -DWITH_TOOLS=ON
else
JPEG_TURBO_CONF_OPTS += -DWITH_TOOLS=OFF
endif
$(eval $(cmake-package))

View File

@@ -0,0 +1,41 @@
From 1695ba12380272056f369f434747839b2ae38d91 Mon Sep 17 00:00:00 2001
From: fossdd <fossdd@pwned.life>
Date: Sat, 22 Feb 2025 20:59:28 +0100
Subject: [PATCH] [cmake] Set ARCH to CPU by default
Reduces complexity of redundant architecture names and allows building
for other architectures implicitly.
Upstream: https://github.com/xbmc/xbmc/commit/1695ba12380272056f369f434747839b2ae38d91
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
cmake/scripts/linux/ArchSetup.cmake | 11 +----------
1 file changed, 1 insertion(+), 10 deletions(-)
diff --git a/cmake/scripts/linux/ArchSetup.cmake b/cmake/scripts/linux/ArchSetup.cmake
index ab142177c8..f29a870a1e 100644
--- a/cmake/scripts/linux/ArchSetup.cmake
+++ b/cmake/scripts/linux/ArchSetup.cmake
@@ -37,17 +37,8 @@ else()
elseif(CPU MATCHES aarch64 OR CPU MATCHES arm64)
set(ARCH aarch64)
set(NEON True)
- elseif(CPU MATCHES riscv64)
- set(ARCH riscv64)
- set(NEON False)
- elseif(CPU MATCHES ppc64le)
- set(ARCH ppc64le)
- set(NEON False)
- elseif(CPU MATCHES loongarch64)
- set(ARCH loongarch64)
- set(NEON False)
else()
- message(SEND_ERROR "Unknown CPU: ${CPU}")
+ set(ARCH ${CPU})
endif()
endif()
--
2.47.3

View File

@@ -4,6 +4,8 @@ config BR2_PACKAGE_KODI_ARCH_SUPPORTS
default y if BR2_PACKAGE_HOST_OPENJDK_BIN_ARCH_SUPPORTS
# i386: needs sse (see upstream PR 10351)
depends on !(BR2_i386 && !BR2_X86_CPU_HAS_SSE)
# m68k not supported upstream
depends on !BR2_m68k
depends on BR2_USE_MMU # libcdio, and others
comment "kodi needs python3 w/ .py modules, a uClibc or glibc toolchain w/ C++, threads, wchar, dynamic library, gcc >= 9.x, host gcc >= 9.x"

View File

@@ -18,14 +18,12 @@ define LIBBPF_BUILD_CMDS
-C $(@D)/src
endef
# bpftrace uses bpf_iter_link_info.task that was added since kernel 6.1
# bpftrace uses BPF_TRACE_KPROBE_SESSION that was added since kernel 6.10
# so we need to update some uapi headers in STAGING_DIR if the toolchain
# is build with linux-headers < 6.1.
# is build with linux-headers < 6.1.0
# Otherwise bpftrace is broken due to out of date linux/bpf.h installed
# by the toolchain.
# https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=f0d74c4da1f060d2a66976193712a5e6abd361f5
# https://github.com/bpftrace/bpftrace/commit/7578314df67df6bbdffaf493ff3b4d182b235b34
ifeq ($(BR2_TOOLCHAIN_HEADERS_AT_LEAST_6_1),)
ifeq ($(BR2_TOOLCHAIN_HEADERS_AT_LEAST_6_10),)
LIBBPF_UPDATE_UAPI_HEADERS = install_uapi_headers UAPIDIR=/usr/include/bpf
define LIBBPF_FIX_STAGING_PC

View File

@@ -1,7 +1,7 @@
# From https://github.com/curl/curl/releases/tag/curl-8_21_0
# From https://github.com/curl/curl/releases/tag/curl-8_22_0
# after checking pgp signature:
# https://curl.se/download/curl-8.21.0.tar.xz.asc
# https://curl.se/download/curl-8.22.0.tar.xz.asc
# signed with key 27EDEAF22F3ABCEB50DB9A125CC908FDB71E12C2
sha256 aa1b66a70eace83dc624508745646c08ae561de512ab403adffb93ac87fc72e6 curl-8.21.0.tar.xz
sha256 f7ef3ae8a22e521f289803fe93543eb64c329b58aa73a9e224dfd915a2a5f4f7 curl-8.22.0.tar.xz
# Locally computed
sha256 82f2f4427d6545ee5aaac4f0b80428da6cc8ba41c2cf5da3a03680ec327b9681 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
LIBCURL_VERSION = 8.21.0
LIBCURL_VERSION = 8.22.0
LIBCURL_SOURCE = curl-$(LIBCURL_VERSION).tar.xz
LIBCURL_SITE = https://curl.se/download
LIBCURL_DEPENDENCIES = host-pkgconf \

View File

@@ -0,0 +1,46 @@
From fce6b611e2530602c44fd914222529028173c509 Mon Sep 17 00:00:00 2001
From: Edgar Bonet <bonet@grenoble.cnrs.fr>
Date: Wed, 19 Aug 2026 18:15:25 +0200
Subject: [PATCH] build: do not require a C++ compiler if it is not needed
Languages specified in the meson project() function are considered hard
dependencies. When trying to build libgpiod in an environment lacking a
C++ compiler, the build fails with an obscure error message ("ERROR:
Unable to get gcc pre-processor defines").
As the C++ compiler is only needed for building the C++ bindings, do not
require it unless the option bindings-cxx is enabled.
Signed-off-by: Edgar Bonet <bonet@grenoble.cnrs.fr>
Upstream: https://lore.kernel.org/linux-gpio/0eb5c26d-731c-4ebb-be34-76466cf57720@grenoble.cnrs.fr/
---
meson.build | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/meson.build b/meson.build
index c030b50..fed612f 100644
--- a/meson.build
+++ b/meson.build
@@ -1,7 +1,7 @@
# SPDX-License-Identifier: GPL-2.0-or-later
# SPDX-FileCopyrightText: 2026 Qualcomm Technologies, Inc. and/or its subsidiaries
-project('libgpiod', ['c', 'cpp'],
+project('libgpiod', 'c',
version: '2.3.1',
license: 'LGPL-2.1-or-later',
default_options: [
@@ -56,6 +56,10 @@ opt_dbus = get_option('dbus')
opt_introspection = get_option('introspection')
opt_systemd = get_option('systemd')
+if opt_bindings_cxx.allowed()
+ add_languages('cpp')
+endif
+
if get_option('profiling')
profiling_c_args = ['-fprofile-arcs', '-ftest-coverage']
profiling_link_args = ['-lgcov']
--
2.43.0

View File

@@ -1,4 +1,4 @@
# From https://github.com/strukturag/libheif/releases/tag/v1.23.1
sha256 0de0327f60fcd47de90d5654c6fe152232738d60d84fe084ec3e0f35e03b166a libheif-1.23.1.tar.gz
# From https://github.com/strukturag/libheif/releases/tag/v1.23.2
sha256 8bd5d41d19dc84536d118b04774709f244df6104ef66d623dad5fa4650143405 libheif-1.23.2.tar.gz
# Locally computed:
sha256 fa81ce652315b013359d6e8e4744335f31a50c7c192907176d3632f78a3b4596 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
LIBHEIF_VERSION = 1.23.1
LIBHEIF_VERSION = 1.23.2
LIBHEIF_SITE = https://github.com/strukturag/libheif/releases/download/v$(LIBHEIF_VERSION)
LIBHEIF_LICENSE = LGPL-3.0+
LIBHEIF_LICENSE_FILES = COPYING

View File

@@ -1,7 +1,7 @@
# From https://www.nlnetlabs.nl/downloads/ldns/ldns-1.9.0.tar.gz.sha1
sha1 9cfe5623dcd40cee0e480b438318c3c4a26c1ecf ldns-1.9.0.tar.gz
# From https://www.nlnetlabs.nl/downloads/ldns/ldns-1.9.0.tar.gz.sha256
sha256 abaeed2858fbea84a4eb9833e19e7d23380cc0f3d9b6548b962be42276ffdcb3 ldns-1.9.0.tar.gz
# From https://www.nlnetlabs.nl/downloads/ldns/ldns-1.9.2.tar.gz.sha1
sha1 d197d9fb46e1802a7160368b38bf063b493f1be1 ldns-1.9.2.tar.gz
# From https://www.nlnetlabs.nl/downloads/ldns/ldns-1.9.2.tar.gz.sha256
sha256 b524fa21994b6e834200ceb8c27f1b84bda5982fe35706f058196c079db94d5d ldns-1.9.2.tar.gz
# Hash for license file:
sha256 9e0b1505c358d1a7c79555ee8bd1acbe2985dbc74dd81f3697cebf2161e922e6 LICENSE

View File

@@ -4,7 +4,7 @@
#
################################################################################
LIBLDNS_VERSION = 1.9.0
LIBLDNS_VERSION = 1.9.2
LIBLDNS_SOURCE = ldns-$(LIBLDNS_VERSION).tar.gz
LIBLDNS_SITE = https://www.nlnetlabs.nl/downloads/ldns
LIBLDNS_LICENSE = BSD-3-Clause

View File

@@ -0,0 +1,26 @@
From f054ce197a286fdd2fcb33ec1d9c236c5976adfb Mon Sep 17 00:00:00 2001
From: fundawang <fundawang@yeah.net>
Date: Sun, 26 Jan 2025 16:39:03 +0800
Subject: [PATCH] move link against gnutls into main library, as it is
referenced by tls/libtls.la
Upstream: d205297a10bf8d7f8846bf42f0ed618543a561a9
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
lib/Makefile.am | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/lib/Makefile.am b/lib/Makefile.am
index 82376cb..33be5e4 100644
--- a/lib/Makefile.am
+++ b/lib/Makefile.am
@@ -48,5 +48,5 @@ libnfs_la_LIBADD = \
if HAVE_TLS
libnfs_la_CPPFLAGS += -I$(abs_top_srcdir)/tls
-libnfs_la_LIBADD += ../tls/libtls.la
+libnfs_la_LIBADD += ../tls/libtls.la -lgnutls
endif
--
2.55.0

View File

@@ -0,0 +1,29 @@
From 74437cb4e9d47daeeb3f851c5b14eb0d207ceb17 Mon Sep 17 00:00:00 2001
From: fundawang <fundawang@yeah.net>
Date: Sun, 26 Jan 2025 16:39:59 +0800
Subject: [PATCH] move link against gnutls into main library, as it is
referenced by tls/libtls.la
Upstream: 546c9ed8624403078ef993138b56dce4c3558523
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
utils/Makefile.am | 3 ---
1 file changed, 3 deletions(-)
diff --git a/utils/Makefile.am b/utils/Makefile.am
index bd584b8..2ae7636 100644
--- a/utils/Makefile.am
+++ b/utils/Makefile.am
@@ -16,9 +16,6 @@ AM_CPPFLAGS = \
"-D_U_=__attribute__((unused))"
COMMON_LIBS = ../lib/libnfs.la $(LIBSOCKET)
-if HAVE_TLS
-COMMON_LIBS += -lgnutls
-endif
nfs_cat_LDADD = $(COMMON_LIBS)
nfs_ls_LDADD = $(COMMON_LIBS)
--
2.55.0

View File

@@ -0,0 +1,41 @@
From 8c6bf2f173fdca0a954ed206b3a386e33b5de47b Mon Sep 17 00:00:00 2001
From: Andreas Ziegler <15275159+aeolio@users.noreply.github.com>
Date: Sun, 28 Jun 2026 06:20:48 +0000
Subject: [PATCH] autotools: fix 'undefined reference' if libnfs was built with
gnutls support (#587)
Signed-off-by: Andreas Ziegler <15275159+aeolio@users.noreply.github.com>
Upstream: a3e86449217fe5429c38e2b06c4f7e6b3cd3be32
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
configure.ac | 2 ++
libnfs.pc.in | 2 +-
2 files changed, 3 insertions(+), 1 deletion(-)
diff --git a/configure.ac b/configure.ac
index a012004..6e5100f 100644
--- a/configure.ac
+++ b/configure.ac
@@ -284,6 +284,8 @@ AC_COMPILE_IFELSE([AC_LANG_PROGRAM([[
[[const char *v = GNUTLS_VERSION;]])],[libnfs_cv_HAVE_TLS=yes],[libnfs_cv_HAVE_TLS=no])])
if test x"$libnfs_cv_HAVE_TLS" = x"yes"; then
AC_DEFINE(HAVE_TLS,1,[Whether we have linux tls support])
+ # tell pkg-config that gnutls needs to be linked also
+ AC_SUBST(tls_library,"-lgnutls")
fi
AM_CONDITIONAL([HAVE_TLS], [test $libnfs_cv_HAVE_TLS = yes])
diff --git a/libnfs.pc.in b/libnfs.pc.in
index fdc012c..42be7b2 100644
--- a/libnfs.pc.in
+++ b/libnfs.pc.in
@@ -10,5 +10,5 @@ Description: libnfs is a client library for accessing NFS shares over a network.
Version: @VERSION@
Requires:
Conflicts:
-Libs: -L${libdir} -lnfs
+Libs: -L${libdir} -lnfs @tls_library@
Cflags: -I${includedir}
--
2.55.0

View File

@@ -1,5 +1,5 @@
# From https://github.com/openssl/openssl/releases/download/openssl-3.6.3/openssl-3.6.3.tar.gz.sha256
sha256 243a86649cf6f23eeb6a2ff2456e09e5d77dd9018a54d3d96b0c6bdd6ba6c7f1 openssl-3.6.3.tar.gz
# From https://github.com/openssl/openssl/releases/download/openssl-3.6.4/openssl-3.6.4.tar.gz.sha256
sha256 9bffaa1ad1e07b354c21bd3324ec02fa15579f45a7d0494b3e74bc449b7333ef openssl-3.6.4.tar.gz
# License files
sha256 7d5450cb2d142651b8afa315b5f238efc805dad827d91ba367d8516bc9d49e7a LICENSE.txt

View File

@@ -4,7 +4,7 @@
#
################################################################################
LIBOPENSSL_VERSION = 3.6.3
LIBOPENSSL_VERSION = 3.6.4
LIBOPENSSL_SITE = https://github.com/openssl/openssl/releases/download/openssl-$(LIBOPENSSL_VERSION)
LIBOPENSSL_SOURCE = openssl-$(LIBOPENSSL_VERSION).tar.gz
LIBOPENSSL_LICENSE = Apache-2.0
@@ -23,6 +23,10 @@ ifeq ($(BR2_m68k_cf),y)
LIBOPENSSL_CFLAGS += -mxgot
# resolves an assembler "out of range error" with blake2 and sha512 algorithms
LIBOPENSSL_CFLAGS += -DOPENSSL_SMALL_FOOTPRINT
# disable atomic operations
ifeq ($(BR2_TOOLCHAIN_HAS_ATOMIC),)
LIBOPENSSL_CFLAGS += -DBROKEN_CLANG_ATOMICS
endif
endif
ifeq ($(BR2_USE_MMU),)

Some files were not shown because too many files have changed in this diff Show More