mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-10-02 06:51:43 -09:00
Compare commits
269 Commits
2026.08-rc
...
2026.05.2
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
72d9d4fa63 | ||
|
|
a87cdf66c4 | ||
|
|
6cbac55672 | ||
|
|
409214de5f | ||
|
|
583e189d42 | ||
|
|
6700a74d5e | ||
|
|
00baa69565 | ||
|
|
08f74f598b | ||
|
|
5137a02a8a | ||
|
|
90210125f6 | ||
|
|
6b0f605183 | ||
|
|
1705db05ae | ||
|
|
685efb096b | ||
|
|
0a638fdaf6 | ||
|
|
8243a69bdb | ||
|
|
d90bf5c8c1 | ||
|
|
0916cf0a64 | ||
|
|
59df6105d0 | ||
|
|
e38702fc57 | ||
|
|
8d4e5f9ccc | ||
|
|
b5628e2437 | ||
|
|
6f5e588100 | ||
|
|
5ba2541ddd | ||
|
|
8594183fb5 | ||
|
|
ce62b98fdb | ||
|
|
eab5b0f66a | ||
|
|
f9224f7e66 | ||
|
|
e3ce1e65fd | ||
|
|
f8255ba5a3 | ||
|
|
177f5fbb29 | ||
|
|
30f11a287e | ||
|
|
1817abc750 | ||
|
|
314bd8bcda | ||
|
|
3e9c7084c7 | ||
|
|
3ec5adfa6e | ||
|
|
43d970f062 | ||
|
|
34b3608160 | ||
|
|
f185ca044f | ||
|
|
0b2d6e4b0d | ||
|
|
7cac2f9a13 | ||
|
|
a5712d326c | ||
|
|
579c1048c3 | ||
|
|
6b8e25393a | ||
|
|
31bdf1643d | ||
|
|
afdb07b5c5 | ||
|
|
5327a8ef60 | ||
|
|
78e2f9a4dd | ||
|
|
1cd4f33690 | ||
|
|
a96a106369 | ||
|
|
c507205a67 | ||
|
|
69ce103003 | ||
|
|
589028df3b | ||
|
|
98046cbf1d | ||
|
|
206e41be02 | ||
|
|
00c1e5b98c | ||
|
|
33bb1b8c9e | ||
|
|
032b8416a4 | ||
|
|
d2bdd24d24 | ||
|
|
87f64a9f70 | ||
|
|
edcb5aa58a | ||
|
|
2f7d1fa842 | ||
|
|
924b69122d | ||
|
|
8809bcb3be | ||
|
|
ac7852ed48 | ||
|
|
f60e785b4c | ||
|
|
3eed5b8f92 | ||
|
|
e2a7b2b2fe | ||
|
|
4e69061c7a | ||
|
|
9b8cd545ac | ||
|
|
ee606bf57e | ||
|
|
20f3d1df46 | ||
|
|
2ddf3b8ca9 | ||
|
|
d1fc34482a | ||
|
|
0de79da7a6 | ||
|
|
b71826fea4 | ||
|
|
f86590655a | ||
|
|
479722a5bc | ||
|
|
0b33e52c57 | ||
|
|
72916929d5 | ||
|
|
6bedcf009b | ||
|
|
d3e0161b9a | ||
|
|
039fa2334f | ||
|
|
4279f3abed | ||
|
|
fde8ba3df7 | ||
|
|
772bf9f873 | ||
|
|
1a3d80074c | ||
|
|
d383ba838b | ||
|
|
2a53b3b6bb | ||
|
|
156a50683a | ||
|
|
faaa3a4b31 | ||
|
|
8410c94db5 | ||
|
|
287dd16fe3 | ||
|
|
67b026da25 | ||
|
|
66e1be310b | ||
|
|
aae95fb47d | ||
|
|
129df62526 | ||
|
|
cad6826784 | ||
|
|
730777efad | ||
|
|
5dd3d0b434 | ||
|
|
9c42365266 | ||
|
|
bee32c9979 | ||
|
|
6b2a9d3d19 | ||
|
|
c39801d4ef | ||
|
|
5937858c88 | ||
|
|
fd9dea7f80 | ||
|
|
65d1b94830 | ||
|
|
5634ec3227 | ||
|
|
e862cede26 | ||
|
|
bcb82b7fee | ||
|
|
badd48864a | ||
|
|
cba956e327 | ||
|
|
b46e9ed92f | ||
|
|
01beb2c14d | ||
|
|
e46a64a5fa | ||
|
|
738e71b98b | ||
|
|
4ab4ded4c8 | ||
|
|
8b5c95e5a2 | ||
|
|
df6a62e169 | ||
|
|
85a70eceed | ||
|
|
f987d74fd4 | ||
|
|
8ae5fbe173 | ||
|
|
d3c2724f06 | ||
|
|
c1b826e803 | ||
|
|
f2384338cd | ||
|
|
92c296f00f | ||
|
|
3d8a7c665a | ||
|
|
c0b1e7e251 | ||
|
|
0be222379c | ||
|
|
377bd40298 | ||
|
|
cb55591ab5 | ||
|
|
031a4acf6f | ||
|
|
9cb109e5b3 | ||
|
|
aa039e5df0 | ||
|
|
e70ba3effc | ||
|
|
b4bb48dfeb | ||
|
|
c69868315d | ||
|
|
b55c4f1a5c | ||
|
|
948312c2ea | ||
|
|
637f35b9f9 | ||
|
|
9b4559d6f1 | ||
|
|
3cb7a72994 | ||
|
|
ad20ef6ad2 | ||
|
|
23a7737609 | ||
|
|
d7909644fe | ||
|
|
ce1c0d2609 | ||
|
|
f85f4793ff | ||
|
|
e2d7dbfeee | ||
|
|
9531c823cd | ||
|
|
264695881d | ||
|
|
eb65ef12a2 | ||
|
|
4d16be6c22 | ||
|
|
0329668291 | ||
|
|
6ca41028c0 | ||
|
|
1bf3cbd45d | ||
|
|
e9770b9c5b | ||
|
|
1b4724a8a1 | ||
|
|
138f03b86c | ||
|
|
1c6739c282 | ||
|
|
237e81130a | ||
|
|
47ece003cd | ||
|
|
b75d130294 | ||
|
|
095117c40d | ||
|
|
cb857ba4c8 | ||
|
|
e70f8f2ae1 | ||
|
|
afc0ca1723 | ||
|
|
21c79df9be | ||
|
|
ae90e07002 | ||
|
|
28ae0cac6f | ||
|
|
780f60dc14 | ||
|
|
0c43d7a15f | ||
|
|
af91dcfe1c | ||
|
|
d31b2b495d | ||
|
|
b8deb2b794 | ||
|
|
c7f0268cd1 | ||
|
|
0f22ac88ac | ||
|
|
57216f1a90 | ||
|
|
190ea0849b | ||
|
|
023a2fffa5 | ||
|
|
15aaee1e0b | ||
|
|
c27982162e | ||
|
|
17d604e3e4 | ||
|
|
d10430adb6 | ||
|
|
e0f6f17ca8 | ||
|
|
1526d90b3d | ||
|
|
8bb9d83070 | ||
|
|
8eb22ee91f | ||
|
|
8e9ce80c94 | ||
|
|
055e954cd4 | ||
|
|
c833ebb3e8 | ||
|
|
6a04d44b07 | ||
|
|
3313c4f10e | ||
|
|
2a0e73dfcb | ||
|
|
f532ff0fef | ||
|
|
2723abb9f4 | ||
|
|
68895e6882 | ||
|
|
5414b019bd | ||
|
|
1af9ec0567 | ||
|
|
6358506f52 | ||
|
|
83c68022c2 | ||
|
|
5ca85cc299 | ||
|
|
bf90aa9989 | ||
|
|
4def9390ab | ||
|
|
cfe9d0e7cf | ||
|
|
c981779d2a | ||
|
|
bd47a97aea | ||
|
|
9b6388b486 | ||
|
|
e4079113a6 | ||
|
|
c56adede27 | ||
|
|
0c67544f04 | ||
|
|
7d8f9f6c0f | ||
|
|
8e913e6c38 | ||
|
|
67b13f3c8d | ||
|
|
8ecb2fe3fc | ||
|
|
6001e920fe | ||
|
|
a2d659937b | ||
|
|
1e06978a0f | ||
|
|
6d8efb145e | ||
|
|
eb8932bdde | ||
|
|
7059bb9c43 | ||
|
|
4aeeffe166 | ||
|
|
c9b6846a21 | ||
|
|
cfb6bea3ff | ||
|
|
dbe1e0f6ca | ||
|
|
7c110848aa | ||
|
|
3536c9de39 | ||
|
|
d7cb451475 | ||
|
|
31ea7acc54 | ||
|
|
6f44e2660c | ||
|
|
aef386b281 | ||
|
|
d7204970be | ||
|
|
e9b1a3c0d5 | ||
|
|
e4c7462766 | ||
|
|
e554f9a84e | ||
|
|
64f5559e11 | ||
|
|
e430365223 | ||
|
|
35c3d26371 | ||
|
|
3b795d74b9 | ||
|
|
e2e56f99d2 | ||
|
|
0c7e7d2956 | ||
|
|
00055d4ea0 | ||
|
|
288b47d79b | ||
|
|
5bccec2779 | ||
|
|
170f87572f | ||
|
|
1035f0dfad | ||
|
|
4f342f960d | ||
|
|
21bb39308f | ||
|
|
45f26d60a9 | ||
|
|
6d480610fa | ||
|
|
566e3a9414 | ||
|
|
d19226ef06 | ||
|
|
75f6dc84a2 | ||
|
|
b3289aa1b6 | ||
|
|
b60dc41c12 | ||
|
|
b7ab3f2a18 | ||
|
|
11bcf5f5f6 | ||
|
|
1708ca0061 | ||
|
|
834c844e3b | ||
|
|
207b0a2699 | ||
|
|
a9014f0c96 | ||
|
|
d5d96d16b2 | ||
|
|
8dec5402e0 | ||
|
|
1103df599a | ||
|
|
ad3c92ffdb | ||
|
|
09b4a21c96 | ||
|
|
ffc2f56308 | ||
|
|
ec7ca21032 | ||
|
|
fd9b1c2521 | ||
|
|
9a327dc724 | ||
|
|
8b916532b3 |
@@ -128,6 +128,8 @@ configs/olpc_xo175_defconfig lib_defconfig.ForceCheckHash
|
||||
configs/olpc_xo1_defconfig lib_defconfig.ForceCheckHash
|
||||
configs/orangepi_pc2_defconfig lib_defconfig.ForceCheckHash
|
||||
configs/orangepi_zero_plus_defconfig lib_defconfig.ForceCheckHash
|
||||
configs/pine64_defconfig lib_defconfig.ForceCheckHash
|
||||
configs/pine64_pinecube_defconfig lib_defconfig.ForceCheckHash
|
||||
configs/sipeed_lichee_rv_defconfig lib_defconfig.ForceCheckHash
|
||||
configs/sipeed_lichee_rv_dock_defconfig lib_defconfig.ForceCheckHash
|
||||
configs/sipeed_licheepi_nano_defconfig lib_defconfig.ForceCheckHash
|
||||
@@ -185,6 +187,7 @@ package/at/0001-Makefile.in-fix-make-install-for-non-root-don-t-stri.patch lib_p
|
||||
package/at/S99at lib_sysv.Indent lib_sysv.Variables
|
||||
package/attr/0001-build-with-older-GCCs.patch lib_patch.Upstream
|
||||
package/aumix/0001-fix-incorrect-makefile-am.patch lib_patch.Upstream
|
||||
package/autoconf/0001-dont-add-dirty-to-version.patch lib_patch.Upstream
|
||||
package/automake/0001-noman.patch lib_patch.Upstream
|
||||
package/avahi/S05avahi-setup.sh lib_sysv.Indent lib_sysv.Variables
|
||||
package/avahi/S50avahi-daemon lib_sysv.Indent lib_sysv.Variables
|
||||
@@ -345,13 +348,22 @@ package/fstrcmp/0001-disable-rpath.patch lib_patch.Upstream
|
||||
package/ftop/0001-overflow.patch lib_patch.Upstream
|
||||
package/fxdiv/0001-CMake-don-t-enable-CXX-unless-building-tests-benchma.patch lib_patch.Upstream
|
||||
package/fxload/0001-fix-static-build.patch lib_patch.Upstream
|
||||
package/gcc/13.4.0/0001-disable-split-stack-for-non-thread-builds.patch lib_patch.Upstream
|
||||
package/gcc/14.4.0/0001-disable-split-stack-for-non-thread-builds.patch lib_patch.Upstream
|
||||
package/gcc/15.3.0/0001-disable-split-stack-for-non-thread-builds.patch lib_patch.Upstream
|
||||
package/gcc/16.2.0/0001-disable-split-stack-for-non-thread-builds.patch lib_patch.Upstream
|
||||
package/gcc/8.4.0/0001-xtensa-fix-PR-target-91880.patch lib_patch.Upstream
|
||||
package/gcc/8.4.0/0002-Revert-re-PR-target-92095-internal-error-with-O1-mcp.patch lib_patch.Upstream
|
||||
package/gcc/8.4.0/0003-libsanitizer-Remove-cyclades-from-libsanitizer.patch lib_patch.Upstream
|
||||
package/gcc/8.4.0/0004-disable-split-stack-for-non-thread-builds.patch lib_patch.Upstream
|
||||
package/gdb/14.2/0001-ppc-ptrace-Define-pt_regs-uapi_pt_regs-on-GLIBC-syst.patch lib_patch.Upstream
|
||||
package/gdb/14.2/0002-sh-ptrace-Define-pt_-dsp-regs-uapi_pt_-dsp-regs-on-G.patch lib_patch.Upstream
|
||||
package/gdb/14.2/0003-use-asm-sgidefs.h.patch lib_patch.Upstream
|
||||
package/gdb/14.2/0004-gdbserver-fix-build-for-m68k.patch lib_patch.Upstream
|
||||
package/gdb/14.2/0005-nat-fork-inferior-include-linux-ptrace.h.patch lib_patch.Upstream
|
||||
package/gdb/14.2/0006-Fix-getrandom-compile-for-uclibc-v1.0.35.patch lib_patch.Upstream
|
||||
package/gdb/14.2/0007-fix-musl-build-on-riscv.patch lib_patch.Upstream
|
||||
package/gdb/14.2/0008-gdbserver-Makefile.in-fix-NLS-build.patch lib_patch.Upstream
|
||||
package/gdb/14.2/0009-gdb-Fix-native-build-on-xtensa.patch lib_patch.Upstream
|
||||
package/gdb/15.2/0001-ppc-ptrace-Define-pt_regs-uapi_pt_regs-on-GLIBC-syst.patch lib_patch.Upstream
|
||||
package/gdb/15.2/0002-sh-ptrace-Define-pt_-dsp-regs-uapi_pt_-dsp-regs-on-G.patch lib_patch.Upstream
|
||||
package/gdb/15.2/0003-use-asm-sgidefs.h.patch lib_patch.Upstream
|
||||
@@ -370,15 +382,6 @@ package/gdb/16.3/0006-Fix-getrandom-compile-for-uclibc-v1.0.35.patch lib_patch.U
|
||||
package/gdb/16.3/0007-fix-musl-build-on-riscv.patch lib_patch.Upstream
|
||||
package/gdb/16.3/0008-gdbserver-Makefile.in-fix-NLS-build.patch lib_patch.Upstream
|
||||
package/gdb/16.3/0009-gdb-Fix-native-build-on-xtensa.patch lib_patch.Upstream
|
||||
package/gdb/17.1/0001-ppc-ptrace-Define-pt_regs-uapi_pt_regs-on-GLIBC-syst.patch lib_patch.Upstream
|
||||
package/gdb/17.1/0002-sh-ptrace-Define-pt_-dsp-regs-uapi_pt_-dsp-regs-on-G.patch lib_patch.Upstream
|
||||
package/gdb/17.1/0003-use-asm-sgidefs.h.patch lib_patch.Upstream
|
||||
package/gdb/17.1/0004-gdbserver-fix-build-for-m68k.patch lib_patch.Upstream
|
||||
package/gdb/17.1/0005-nat-fork-inferior-include-linux-ptrace.h.patch lib_patch.Upstream
|
||||
package/gdb/17.1/0006-Fix-getrandom-compile-for-uclibc-v1.0.35.patch lib_patch.Upstream
|
||||
package/gdb/17.1/0007-fix-musl-build-on-riscv.patch lib_patch.Upstream
|
||||
package/gdb/17.1/0008-gdbserver-Makefile.in-fix-NLS-build.patch lib_patch.Upstream
|
||||
package/gdb/17.1/0009-gdb-Fix-native-build-on-xtensa.patch lib_patch.Upstream
|
||||
package/genpart/0001-fix-return-code.patch lib_patch.Upstream
|
||||
package/gensio/0001-Fix-missing-EVP_PKEY_ED25519-build-error-on-libressl.patch lib_patch.Upstream
|
||||
package/gerbera/S99gerbera lib_sysv.Indent
|
||||
@@ -553,10 +556,12 @@ package/lirc-tools/0002-configure-add-disable-doc-option.patch lib_patch.Upstrea
|
||||
package/lirc-tools/S25lircd lib_sysv.Indent lib_sysv.Variables
|
||||
package/live555/0001-Add-a-pkg-config-file-for-the-shared-libraries.patch lib_patch.Upstream
|
||||
package/lldpd/S60lldpd Shellcheck lib_sysv.Indent lib_sysv.Variables
|
||||
package/lm-sensors/0001-no-host-ldconfig.patch lib_patch.Upstream
|
||||
package/lm-sensors/0001-static-build.patch lib_patch.Upstream
|
||||
package/lm-sensors/0002-no-host-ldconfig.patch lib_patch.Upstream
|
||||
package/lmbench/0001-scripts-build-use-bin-bash-as-shell.patch lib_patch.Upstream
|
||||
package/lmbench/0002-src-Makefile-add-lmbench-to-list-of-executables.patch lib_patch.Upstream
|
||||
package/lmbench/0003-TOO_LONG-100-usec-to-prevent-memsize-from-timingout-.patch lib_patch.Upstream
|
||||
package/localedef/0002-relax-dependency-on-GCC-to-4.8-and-binutils-to-2.24.patch lib_patch.Upstream
|
||||
package/lockfile-progs/0001-sus3v-legacy.patch lib_patch.Sob lib_patch.Upstream
|
||||
package/lshw/0001-solve-Compile-error-when-g-version-is-less-than-5.patch lib_patch.Upstream
|
||||
package/ltrace/0001-arm-plt.patch lib_patch.Upstream
|
||||
@@ -604,6 +609,7 @@ package/meson/0001-Prefer-ext-static-libs-when-default-library-static.patch lib_
|
||||
package/meson/0002-mesonbuild-dependencies-base.py-add-pkg_config_stati.patch lib_patch.Upstream
|
||||
package/mfgtools/0001-lnx_def.h-fix-conflicting-declaration-of-__time64_t.patch lib_patch.Upstream
|
||||
package/mii-diag/0001-strchr.patch lib_patch.Sob lib_patch.Upstream
|
||||
package/mini-snmpd/0001-linux.c-fix-musl-build.patch lib_patch.Upstream
|
||||
package/minidlna/S60minidlnad Shellcheck lib_sysv.Indent lib_sysv.Variables
|
||||
package/minissdpd/S50minissdpd Shellcheck lib_sysv.Indent lib_sysv.Variables
|
||||
package/modem-manager/S44modem-manager Shellcheck lib_sysv.Variables
|
||||
@@ -676,9 +682,8 @@ package/olsr/0006-build-patch-for-gpsd-3-25.patch lib_patch.Upstream
|
||||
package/olsr/S50olsr Shellcheck lib_sysv.Indent lib_sysv.Variables
|
||||
package/open-plc-utils/0001-Remove-OWNER-and-GROUPS-parameters-to-install.patch lib_patch.Upstream
|
||||
package/open2300/0001-fix-makefile.patch lib_patch.Upstream
|
||||
package/openjdk/17.0.18+8/0001-Add-ARCv2-ISA-processors-support-to-Zero.patch lib_patch.Upstream
|
||||
package/openjdk/21.0.10+7/0001-Add-ARCv2-ISA-processors-support-to-Zero.patch lib_patch.Upstream
|
||||
package/openjdk/25.0.2+10/0001-Add-ARCv2-ISA-processors-support-to-Zero.patch lib_patch.Upstream
|
||||
package/openjdk/17.0.12+7/0001-Add-ARCv2-ISA-processors-support-to-Zero.patch lib_patch.Upstream
|
||||
package/openjdk/21.0.4+7/0001-Add-ARCv2-ISA-processors-support-to-Zero.patch lib_patch.Upstream
|
||||
package/openldap/0001-fix-bignum.patch lib_patch.Upstream
|
||||
package/openldap/0002-disable-docs.patch lib_patch.Upstream
|
||||
package/openntpd/S49ntp Shellcheck lib_sysv.Variables
|
||||
@@ -766,7 +771,11 @@ package/qextserialport/0001-Create-a-main-include-file-QExtSerialPort.patch lib_
|
||||
package/qextserialport/0002-Tell-qmake-to-add-a-pkgconfig-file-to-ease-usage-wit.patch lib_patch.Upstream
|
||||
package/qt5/qt5base/0001-qtbase-Fix-build-error-when-using-EGL.patch lib_patch.Upstream
|
||||
package/qt5/qt5base/0002-double-conversion-enable-for-microblaze.patch lib_patch.Upstream
|
||||
package/qt5/qt5base/0003-double-conversion-enable-for-nios2.patch lib_patch.Upstream
|
||||
package/qt5/qt5base/0004-double-conversion-enable-for-xtensa.patch lib_patch.Upstream
|
||||
package/qt5/qt5base/0005-eglfs-avoid-breaking-compilation-for-obscure-EGLNativeDisplayType-types.patch lib_patch.Upstream
|
||||
package/qt5/qt5base/0006-Fix-build-on-riscv32.patch lib_patch.Upstream
|
||||
package/qt5/qt5base/0007-src-corelib-configure.json-fix-atomicfptr-detection.patch lib_patch.Upstream
|
||||
package/qt5/qt5base/0008-eglconvenience-add-missing-QList-include.patch lib_patch.Upstream
|
||||
package/qt5/qt5declarative/0001-qsgtexture-fix-debug-build-with-uclibc.patch lib_patch.Upstream
|
||||
package/qt5/qt5declarative/0002-qv4regexp_p-needs-c-limits-include-instead-of-plain-.patch lib_patch.Upstream
|
||||
@@ -774,8 +783,10 @@ package/qt5/qt5enginio/0001-Do-not-use-deprecated-QLinkedList.patch lib_patch.Up
|
||||
package/qt5/qt5location/0001-3rdparty-mapbox-gl-native-fix-musl-compile-pthread_g.patch lib_patch.Upstream
|
||||
package/qt5/qt5script/0001-Detect-32-bits-armv8-a-architecture.patch lib_patch.Upstream
|
||||
package/qt5/qt5tools/0001-Disable-designer-tool-fixes-configure-error.patch lib_patch.Upstream
|
||||
package/qt5/qt5webengine-chromium/0001-Don-t-rebase-sysroot-path.patch lib_patch.Upstream
|
||||
package/qt5/qt5webengine-chromium/0001-Add-python3-build-support.patch lib_patch.Upstream
|
||||
package/qt5/qt5webengine-chromium/0002-Don-t-rebase-sysroot-path.patch lib_patch.Upstream
|
||||
package/qt5/qt5webengine/0001-gn.pro-don-t-link-statically-with-libstc.patch lib_patch.Upstream
|
||||
package/qt5/qt5webengine/0002-Add-python3-build-support.patch lib_patch.Upstream
|
||||
package/qt5/qt5webkit/0001-WinCairo-PlayStation-ICU-68.1-no-longer-exposes-FALS.patch lib_patch.Upstream
|
||||
package/qt5/qt5webkit/0002-Fix-compilation-with-Python-3.9-avoid-passing-encodi.patch lib_patch.Upstream
|
||||
package/qt5/qt5webkit/0003-Let-Bison-generate-the-header-directly-to-fix-build-.patch lib_patch.Upstream
|
||||
@@ -795,6 +806,7 @@ package/restorecond/S02restorecond Shellcheck
|
||||
package/ripgrep/0001-puts-jemalloc-allocator-behind-a-cargo-feature-flag.patch lib_patch.Upstream
|
||||
package/riscv-isa-sim/0001-riscv-disable-precompiled-headers.patch lib_patch.Upstream
|
||||
package/rng-tools/S21rngd Shellcheck lib_sysv.Variables
|
||||
package/rocksdb/0001-build_tools-build_detect_platform-fix-C-tests.patch lib_patch.Upstream
|
||||
package/rpcbind/0001-Remove-yellow-pages-support.patch lib_patch.Upstream
|
||||
package/rpcbind/S30rpcbind lib_sysv.EmptyLastLine lib_sysv.Indent lib_sysv.Variables
|
||||
package/rt-tests/0001-Fix-a-build-issue-with-uClibc-ng.patch lib_patch.Upstream
|
||||
@@ -867,6 +879,7 @@ package/ti-sgx-um/0001-Makefile-do-not-install-init-script.patch lib_patch.Upstr
|
||||
package/ti-sgx-um/S80ti-sgx lib_sysv.Variables
|
||||
package/ti-utils/0001-plt.h-fix-build-with-gcc-10.patch lib_patch.Upstream
|
||||
package/tinyalsa/0001-include-time.h-before-asound.h.patch lib_patch.Upstream
|
||||
package/tinycompress/0001-wave-add-time.h-missing-header-inclusion.patch lib_patch.Upstream
|
||||
package/tinydtls/0001-sha2-sha2.c-fix-build-on-big-endian.patch lib_patch.Upstream
|
||||
package/transmission/S92transmission Shellcheck lib_sysv.ConsecutiveEmptyLines lib_sysv.Indent lib_sysv.Variables
|
||||
package/triggerhappy/S10triggerhappy Shellcheck lib_sysv.Indent lib_sysv.Variables
|
||||
|
||||
549
CHANGES
549
CHANGES
@@ -1,65 +1,3 @@
|
||||
2026.08-rc3, released August 29th, 2026
|
||||
|
||||
Fixes all over the tree.
|
||||
|
||||
Updated/fixed packages: avro-c, bind, bpftrace, collectd,
|
||||
dahdi-linux, expat, fetchmail, flex, fluidsynth, gdb, glibc,
|
||||
haproxy, jpeg-turbo, libbpf, libheif, libopenssl,
|
||||
libxml-parser-perl, localedef, mesa3d, nodejs, olsr, perl,
|
||||
php, python-avro, python-gobject, qt6, qt6declarative, redis,
|
||||
rsyslog, taglib, uclibc, unbound, weston
|
||||
|
||||
2026.08-rc2, released August 23th, 2026
|
||||
|
||||
Fixes all over the tree.
|
||||
|
||||
Infrastructure:
|
||||
- Correct <pkg>_FLAT_STACKSIZE handling for nommu
|
||||
|
||||
Defconfigs: QEMU x86-64 EFI: Fix build issue after grub2 bump.
|
||||
|
||||
Updated/fixed packages: clamav, distribution-registry, dracut,
|
||||
drogon, enscript, fluidsynth, gdb, igh-ethercat, kodi,
|
||||
libgpiod2, libssh2, linux-tools, mesa3d, mtools, netsnmp,
|
||||
putty, python-scp, uclibc, udisks, uhttpd, webkitgtk, wget,
|
||||
wireshark, xilinx-embeddedsw
|
||||
|
||||
2026.08-rc1, released August 18th, 2026
|
||||
|
||||
Fixes all over the tree and new features.
|
||||
|
||||
Architectures:
|
||||
- Support for M68K nommu
|
||||
- Support for IBM Power 10/11 variants
|
||||
|
||||
Toolchain:
|
||||
- Support for Linux 7.1.x headers
|
||||
- Binutils 2.46.1, GCC 16.2.0, now defaults to GCC 15
|
||||
- Glibc 2.44, uClibc-ng 1.0.59
|
||||
- Support for ARC-specific GCC version and external toolchain
|
||||
dropped
|
||||
|
||||
Infrastructure:
|
||||
- Support for building packages written in the hare
|
||||
programming language
|
||||
- Libudev virtual package, similar to jpeg or openssl.
|
||||
- generate-cyclonedx: fixup scp-style git sites
|
||||
|
||||
New defconfigs: QEMU PPC64LE Powernv10 / Powernv11
|
||||
|
||||
Removed defconfigs: Acmesystems aria/arietta g25, Avnet S6LX9
|
||||
Microboard, Technologic TS-4900 / TS-5500
|
||||
|
||||
New packages: agec, cpp-argparse, drogon, dtui, hare, harec,
|
||||
hare-dbus, hare-ev, hare-xml, libcppconnman, liblc3, libudev,
|
||||
libudev-zero, perl-cgi, perl-cgi-session, perl-log-message,
|
||||
perl-log-message-simple, perl-switch, python-libyang,
|
||||
python-sysv-ipc, qbe, qemu-xen, qt6grpc, qt6positioning,
|
||||
scdoc, sdl3, sdl3_gfx, sdl3_image, sdl3_ttf, sigsum-c,
|
||||
virglrenderer, wget2
|
||||
|
||||
Removed packages: argparse, ts4900-fpga
|
||||
|
||||
2026.05.2, released August 23, 2026
|
||||
|
||||
Important / security related fixes:
|
||||
@@ -191,6 +129,7 @@
|
||||
urandom-scripts, usbutils, vim, wpa_supplicant, xlib_libXfont2,
|
||||
xserver_xorg-server, xwayland, xz
|
||||
|
||||
|
||||
2026.05.1, released July 15, 2026
|
||||
|
||||
Important / security related fixes:
|
||||
@@ -298,6 +237,7 @@
|
||||
rsync, ruby, rust, shadow, shim, squid, strongswan, sudo, tiff, tmux,
|
||||
tor, util-linux, util-linux, util-linux, webkitgtk, wolfssl
|
||||
|
||||
|
||||
2026.05, released June 8th, 2026
|
||||
|
||||
Various fixes.
|
||||
@@ -411,129 +351,6 @@
|
||||
Removed packages: cegui, openswan, pcre, rubix, snort,
|
||||
spinxbase
|
||||
|
||||
2026.02.3, released June 16, 2026
|
||||
|
||||
Important / security related fixes:
|
||||
|
||||
asterisk: GHSA-8fj4-fv9f-hjpc, GHSA-g88q-c2hm-q7p7,
|
||||
GHSA-j29p-pvh2-pvqp, GHSA-x5pq-qrp4-fmrj
|
||||
bind: CVE-2026-3039, CVE-2026-3592, CVE-2026-5946, CVE-2026-5950
|
||||
capnproto: CVE-2026-322, CVE-2026-32239, CVE-2026-32240
|
||||
cups-filters: CVE-2025-64524
|
||||
dnsmasq: CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892,
|
||||
CVE-2026-4893, CVE-2026-5172
|
||||
docker-engine: CVE-2025-54388
|
||||
dropbear: CVE-2019-6111, CVE-2026-35385
|
||||
exim: (no CVE assigned), CVE-2026-48840
|
||||
expat: CVE-2026-45186
|
||||
freeipmi: CVE-2026-50031
|
||||
glibc: CVE-2026-4046, CVE-2026-4437, CVE-2026-4438, CVE-2026-5450,
|
||||
CVE-2026-5928
|
||||
gnupg2: (no CVE assigned)
|
||||
haveged: CVE-2026-41054
|
||||
imagemagick: CVE-2026-42326, CVE-2026-45031, CVE-2026-45358,
|
||||
CVE-2026-45359, CVE-2026-45624, CVE-2026-45664, CVE-2026-46520,
|
||||
CVE-2026-46521, CVE-2026-46522, CVE-2026-46523, CVE-2026-46557,
|
||||
CVE-2026-46559
|
||||
intel-microcode: CVE-2025-35979
|
||||
libde265: CVE-2026-45382, CVE-2026-45383, GHSA-ccfw-29x7-rrx3,
|
||||
GHSA-j2qq-x2xq-g9wr
|
||||
libgpg-error: T8239
|
||||
libheif: CVE-2026-32738, CVE-2026-32739, CVE-2026-32740,
|
||||
CVE-2026-32741, CVE-2026-32814, CVE-2026-32882, CVE-2026-3949,
|
||||
CVE-2026-41069, CVE-2026-41071, CVE-2026-47178, CVE-2026-47247,
|
||||
CVE-2026-47251, CVE-2026-47254, CVE-2026-47709, CVE-2026-47714,
|
||||
GHSA-5hqq-636x-r3cr, GHSA-6x5f-qchq-cxqv, GHSA-jvmp-j3cw-84mh,
|
||||
GHSA-r7qj-cg5r-r6vf
|
||||
libmad: CVE-2017-837, CVE-2017-8372, CVE-2017-8373, CVE-2017-8374
|
||||
libmodsecurity: CVE-2026-30923, CVE-2026-42268
|
||||
libssh2: CVE-2026-7598
|
||||
liburiparser: CVE-2026-44927, CVE-2026-44928
|
||||
libusb: CVE-2026-23679, CVE-2026-47104
|
||||
libvncserver: CVE-2026-3285, CVE-2026-32853, CVE-2026-32854
|
||||
mariadb: CVE-2026-34303, CVE-2026-3494, CVE-2026-44168, CVE-2026-44169,
|
||||
CVE-2026-44170, CVE-2026-44171, CVE-2026-44172, CVE-2026-44173
|
||||
memcached: (no CVE assigned)
|
||||
nginx: CVE-2026-40460, CVE-2026-40701, CVE-2026-42926, CVE-2026-42934,
|
||||
CVE-2026-42945, CVE-2026-42946, CVE-2026-9256
|
||||
php: CVE-2026-44927, CVE-2026-44928
|
||||
postgresql: CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,
|
||||
CVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,
|
||||
CVE-2026-6575, CVE-2026-6637, CVE-2026-6638
|
||||
privoxy: OVE-20260515-0001, OVE-20260515-0002
|
||||
putty: (no CVE assigned)
|
||||
python-urllib3: CVE-2026-44431, CVE-2026-44432
|
||||
python3: CVE-2026-3276, CVE-2026-7774, CVE-2026-8328, gh-146211,
|
||||
gh-146333, gh-148169, gh-148178, gh-148395, gh-149017, gh-149254,
|
||||
gh-90309
|
||||
radvd: CVE-2026-48715
|
||||
rsync: CVE-2026-29518, CVE-2026-43617, CVE-2026-43618, CVE-2026-43619,
|
||||
CVE-2026-43620, CVE-2026-45232
|
||||
runc: CVE-2025-31133, CVE-2025-52565, CVE-2025-52881
|
||||
samba4: CVE-2026-1933, CVE-2026-2340, CVE-2026-3012, CVE-2026-3238,
|
||||
CVE-2026-4408, CVE-2026-4480
|
||||
sdl2_image: CVE-2026-35444
|
||||
sed: CVE-2026-5958
|
||||
sshfs: CVE-2026-47187, CVE-2026-48711
|
||||
tor: TROVE-2026-013, TROVE-2026-014, TROVE-2026-015, TROVE-2026-016,
|
||||
TROVE-2026-017, TROVE-2026-018, TROVE-2026-019, TROVE-2026-020,
|
||||
TROVE-2026-021, TROVE-2026-022
|
||||
unbound: CVE-2026-32792, CVE-2026-33278, CVE-2026-40622,
|
||||
CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42944,
|
||||
CVE-2026-42959, CVE-2026-42960, CVE-2026-44390, CVE-2026-44608
|
||||
unzip: CVE-2021-4217
|
||||
xserver_xorg-server: (no CVE assigned)
|
||||
xwayland: (no CVE assigned)
|
||||
|
||||
Toolchain:
|
||||
|
||||
- linux-headers: bump to 5.10.257, 5.15.208, 6.1.174, 6.6.141, 6.12.91,
|
||||
6.18.33
|
||||
|
||||
Infrastructure updates/fixes:
|
||||
|
||||
- cve-check: fix vulnerabilities with different analysis
|
||||
- generate-cyclonedx: add hashes from .hash files to externalReferences
|
||||
- generate-cyclonedx: hint at missing Buildroot host package on a
|
||||
specific error
|
||||
- bump-stable-kernel-versions: update for split hash file
|
||||
- kconfig: fix compiler warnings
|
||||
- cve-check: add indication how to run
|
||||
- Remove /usr/share/info/dir from target
|
||||
- generate-cyclonedx: remove indirect dependencies from root component
|
||||
- replicate IGNORE_CVES to host packages
|
||||
- cve-check: remove 'bom-ref' for vulnerabilities
|
||||
- generate-cyclonedx: generate externalReferences with
|
||||
source-distribution
|
||||
- cve-check: fix vulnerability timestamp to RFC 3339
|
||||
- generate-cyclonedx: generate vcs externalReferences for source repos
|
||||
- gitlab-ci: use larger shared runners where necessary
|
||||
- add 'make show-info-all'
|
||||
- dependencies.sh: reject buggy uutils "install" on Ubuntu 26.04
|
||||
|
||||
Updated defconfigs: arcturus_ucp1020, at91sam9x5ek*
|
||||
|
||||
Updated / fixed packages: kexec, zsh, cups-filters, python-cbor2,
|
||||
haveged, lrzsz, ustream-ssl, expat, xwayland, libvncserver, liburing,
|
||||
sysrepo, qt53d, collectd, mariadb, gstreamer1, jemalloc, libks,
|
||||
lua-sdl2, util-linux, vlc, xfsprogs, kodi, bind, libde265,
|
||||
docker-cli, libabseil-cpp, wpewebkit, libpthsem, heirloom-mailx, icu,
|
||||
libheif, podman, unbound, dropbear, vorbis-tools, crucible, unzip,
|
||||
libssh2, python3, imagemagick, libbpf, gdb, capnproto, esp-hosted,
|
||||
freeipmi, asterisk, wireless-regdb, intel-microcode, weston,
|
||||
util-linux-libs, linux-headers, qt6base, zlib-ng, libgphoto2, hplip,
|
||||
bpftrace, postgresql, babeld, sed, libdrm, lrzip, odhcp6c, linux,
|
||||
efl, libusb, jq, sane-airscan, libmad, faad2, dnsmasq, privoxy,
|
||||
libgit2, mrp, putty, sshfs, gcc-bare-metal, graphene, mongoose,
|
||||
rsync, redis, hiredis, cairo, zic, dos2unix, libargon2,
|
||||
docker-engine, sane-backends, arm-trusted-firmware, libnss, openscap,
|
||||
opencv4, liburiparser, libdill, radvd, poppler, tzdata,
|
||||
gst1-plugins-bad, python-ecdsa, php, stellarium, python-aiodns,
|
||||
nginx, gnupg2, tor, xerces, gst1-plugins-good, libmodsecurity,
|
||||
sdl2_image, readline, libgpg-error, samba4, runc,
|
||||
xserver_xorg-server, glibc, memcached, libmicrohttpd, supertux, exim,
|
||||
python-urllib3, qt5webengine-chromium
|
||||
|
||||
2026.02.2, released May 20, 2026
|
||||
|
||||
Changes with potentially large impact:
|
||||
@@ -1766,368 +1583,6 @@
|
||||
- netsnmp: unexpected header length in /proc/net/snmp...
|
||||
https://gitlab.com/buildroot.org/buildroot/-/issues/110
|
||||
|
||||
2025.02.17, released August 23, 2026
|
||||
|
||||
Important / security related fixes:
|
||||
|
||||
apr-util: CVE-2025-49506, CVE-2026-32327, CVE-2026-34191,
|
||||
CVE-2026-34501, CVE-2026-34502
|
||||
bind: CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605,
|
||||
CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204,
|
||||
CVE-2026-13321
|
||||
botan: CVE-2026-32877, CVE-2026-32883, CVE-2026-32884, CVE-2026-34580,
|
||||
CVE-2026-34582
|
||||
busybox: CVE-2023-39810, CVE-2024-58251, CVE-2026-26157,
|
||||
CVE-2026-26158, CVE-2026-29004
|
||||
containerd: CVE-2026-35469, CVE-2026-46680, CVE-2026-47262,
|
||||
CVE-2026-53488
|
||||
dracut: CVE-2026-6893
|
||||
dropbear: (no CVE assigned)
|
||||
exim: GCVE-25-2026-07-45-1, CVE-2026-66140, CVE-2026-66141
|
||||
expat: CVE-2026-72522
|
||||
go: CVE-2026-39822
|
||||
intel-microcode: CVE-2025-31936, CVE-2025-31938, CVE-2025-35973,
|
||||
CVE-2026-20707, CVE-2026-20713, CVE-2026-20716, CVE-2026-20760,
|
||||
CVE-2026-20917
|
||||
libarchive: (no CVE assigned)
|
||||
libass: CVE-2026-61626, CVE-2026-61627
|
||||
libgcrypt: CVE-2026-41989
|
||||
libgit2: CVE-2026-53583, CVE-2026-53584, CVE-2026-53585,
|
||||
CVE-2026-53586, CVE-2026-53587
|
||||
libheif: CVE-2026-62289, CVE-2026-62291, CVE-2026-62292,
|
||||
CVE-2026-62377, GHSA-46rp-pcq2-rpmr, GHSA-73p7-m7gg-w2jv,
|
||||
GHSA-9ww4-9v47-m7pj, GHSA-jc8f-p23p-5hjg, GHSA-xpw3-9rhw-482x
|
||||
libmodsecurity: CVE-2026-52747, CVE-2026-52761
|
||||
libssh: CVE-2026-15370, CVE-2026-59843, CVE-2026-59844, CVE-2026-59845,
|
||||
CVE-2026-59846, CVE-2026-59847, CVE-2026-59848, CVE-2026-59849,
|
||||
CVE-2026-59850
|
||||
memcached: (no CVE assigned)
|
||||
ntfs-3g: CVE-2026-42616, CVE-2026-42617, CVE-2026-42618,
|
||||
CVE-2026-46569, CVE-2026-46570, CVE-2026-46571, CVE-2026-46572,
|
||||
CVE-2026-56135, CVE-2026-56136
|
||||
openssh: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997,
|
||||
CVE-2026-59998, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001,
|
||||
CVE-2026-60002
|
||||
openvpn: CVE-2026-63649
|
||||
perl: CVE-2026-13221, CVE-2026-57432, CVE-2026-8376
|
||||
php: CVE-2026-17543, CVE-2026-7260, CVE-2026-9672
|
||||
postgresql: CVE-2026-14662, CVE-2026-14663, CVE-2026-14664,
|
||||
CVE-2026-14666, CVE-2026-14668, CVE-2026-14669, CVE-2026-14670,
|
||||
CVE-2026-14671, CVE-2026-14672, CVE-2026-14673, CVE-2026-14676,
|
||||
CVE-2026-14677, CVE-2026-14678, CVE-2026-14679, CVE-2026-14680,
|
||||
CVE-2026-14681, CVE-2026-15741, CVE-2026-15742, CVE-2026-16238,
|
||||
CVE-2026-16239, CVE-2026-16241, CVE-2026-18024, CVE-2026-18408,
|
||||
CVE-2026-19385, CVE-2026-6464, CVE-2026-6469, CVE-2026-6470,
|
||||
CVE-2026-6471
|
||||
python3: CVE-2025-13462, CVE-2026-15308, CVE-2026-2297, CVE-2026-3644,
|
||||
CVE-2026-4224, CVE-2026-4519, CVE-2026-7210
|
||||
redis: (no CVE assigned)
|
||||
rsync: CVE-2026-53783, CVE-2026-53784, CVE-2026-53785, CVE-2026-53786,
|
||||
CVE-2026-53788, CVE-2026-53789, CVE-2026-53790, CVE-2026-53791,
|
||||
CVE-2026-53792, CVE-2026-53793, CVE-2026-53794, CVE-2026-53795,
|
||||
CVE-2026-53796, CVE-2026-53797, CVE-2026-53798, CVE-2026-53799,
|
||||
CVE-2026-53800, CVE-2026-53801, CVE-2026-53802, CVE-2026-53803,
|
||||
CVE-2026-70452, CVE-2026-70453, CVE-2026-70454, CVE-2026-70455,
|
||||
CVE-2026-70456, CVE-2026-70457, CVE-2026-70458, CVE-2026-70459,
|
||||
CVE-2026-70460, CVE-2026-70461, CVE-2026-70462, CVE-2026-70463,
|
||||
CVE-2026-70464
|
||||
samba4: CVE-2026-58216, CVE-2026-58218, CVE-2026-58221, CVE-2026-58222,
|
||||
CVE-2026-58224, CVE-2026-6949
|
||||
screen: (no CVE assigned)
|
||||
ser2net: GHSA-cgh5-39mg-vhfr
|
||||
socat: CVE-2026-56123
|
||||
sqlite: CVE-2026-1182, CVE-2026-11822, CVE-2026-11824
|
||||
stunnel: CVE-2026-70367, CVE-2026-70368
|
||||
syslog-ng: CVE-2026-39879
|
||||
util-linux: CVE-2026-13595
|
||||
vim: CVE-2026-28417, CVE-2026-28418, CVE-2026-28419, CVE-2026-28420,
|
||||
CVE-2026-28421, CVE-2026-28422, CVE-2026-32249, CVE-2026-33412,
|
||||
CVE-2026-34714, CVE-2026-34982, CVE-2026-35177, CVE-2026-39881,
|
||||
CVE-2026-41411, CVE-2026-42307, CVE-2026-44656, CVE-2026-45130,
|
||||
CVE-2026-46483, CVE-2026-47162, CVE-2026-47167, CVE-2026-52858,
|
||||
CVE-2026-52859, CVE-2026-52860, CVE-2026-55693, CVE-2026-55892,
|
||||
CVE-2026-55895, CVE-2026-57451, CVE-2026-57452, CVE-2026-57453,
|
||||
CVE-2026-57455, CVE-2026-57456, CVE-2026-59856, CVE-2026-59857,
|
||||
CVE-2026-59858
|
||||
wpa_supplicant: (no CVE assigned)
|
||||
xlib_libXfont2: CVE-2026-56001, CVE-2026-56002, CVE-2026-56003
|
||||
xserver_xorg-server: CVE-2026-55999, CVE-2026-56000
|
||||
xwayland: CVE-2026-55999, CVE-2026-56000
|
||||
|
||||
Toolchain:
|
||||
|
||||
- toolchain-buildroot: drop Synopsys ARC specific GCC, binutils and gdb
|
||||
- toolchain-external: drop Synopsys ARC toolchain
|
||||
- linux-headers:: bump to 5.10.265, 5.15.216, 6.1.183, 6.6.152,
|
||||
6.12.104
|
||||
|
||||
Infrastructure updates/fixes:
|
||||
|
||||
- Add license information for skeleton packages
|
||||
- Make docker image reproducible again
|
||||
- New runtime tests for guile, libgpiod2, mdnsd, php, python-pydal
|
||||
|
||||
Updated defconfigs: acmesystems_acqua_a5_*
|
||||
|
||||
Removed defconfigs: acmesystems_aria_g25_{128mb, 256mb},
|
||||
acmesystems_arietta_g25_{128mb, 256mb}, s6lx9_microboard, ts4900,
|
||||
ts5500
|
||||
|
||||
Removed packages: argparse, ts4900-fpga
|
||||
|
||||
Updated / fixed packages: apache, apr-util, arm-trusted-firmware,
|
||||
at-spi2-core, bind, binutils, botan, busybox, cantarell, cifs-utils,
|
||||
containerd, cramfs, dbus-broker, dracut, drop, dropbear,
|
||||
environment-setup, exim, expat, glibc, go, guile, gvfs,
|
||||
ifupdown-scripts, initscripts, intel-microcode, libarchive, libass,
|
||||
libcamera, libgcrypt, libgee, libgit2, libglib2, libgpg-error,
|
||||
libgtk4, libgudev, libheif, libmicrohttpd, libmodsecurity, libpeas,
|
||||
librsvg, libsecret, libsoup, libsoup3, libssh, linux, linux-headers:,
|
||||
localedef, mbedtls, memcached, mini-snmpd, nettle, ntfs-3g, ogre,
|
||||
open62541, openblas, openssh, openvpn, optee-os, p11-kit, pahole,
|
||||
perl, php, postgresql, python-paho-mqtt, python-pydal, python-web2py,
|
||||
python3, qt6, quickjs, redis, rsync, rygel, samba4, screen, ser2net,
|
||||
socat, sqlite, stunnel, syslog-ng, uclibc, urandom-scripts, usbutils,
|
||||
util-linux, vim, wpa_supplicant, xlib_libXfont2, xserver_xorg-server,
|
||||
xwayland, xz
|
||||
|
||||
2025.02.16, released July 15, 2026
|
||||
|
||||
Important / security related fixes:
|
||||
|
||||
apache: CVE-2026-29167, CVE-2026-29170, CVE-2026-34355, CVE-2026-34356,
|
||||
CVE-2026-42535, CVE-2026-42536, CVE-2026-43951, CVE-2026-44119,
|
||||
CVE-2026-44185, CVE-2026-44186, CVE-2026-44631, CVE-2026-48913,
|
||||
CVE-2026-49975
|
||||
asterisk: GHSA-3g56-cgrh-95p5, GHSA-3rhj-hhw7-m6fw,
|
||||
GHSA-4pgv-j3mr-3rcp, GHSA-589g-qgf8-m6mx, GHSA-746q-794h-cc7f,
|
||||
GHSA-8jhw-m2hg-vp3h, GHSA-8jw3-ccr9-xrmf, GHSA-g8q2-p36q-94f6,
|
||||
GHSA-h5hv-jmgj-92q2, GHSA-j2mm-57pq-jh94, GHSA-mxgm-8c6f-5p8f,
|
||||
GHSA-ph27-3m5q-mj5m, GHSA-q9fr-m7g8-6ph5, GHSA-qf8j-jp7h-c5hx,
|
||||
GHSA-r6c2-hwc2-j4mp, GHSA-vfhr-r9x9-c687, GHSA-vrfp-mg3q-3959,
|
||||
GHSA-wcvv-g26m-wx5c, GHSA-x348-j6c9-77f3, GHSA-xgj6-2gc5-5x9c
|
||||
avahi: CVE-2026-34933
|
||||
bind: (no CVE assigned), CVE-2026-3593
|
||||
cpp-httplib: CVE-2026-45352, CVE-2026-45372, CVE-2026-46527
|
||||
cups-filters: CVE-2025-64503
|
||||
expat: CVE-2026-50219, CVE-2026-56131, CVE-2026-56132, CVE-2026-56403,
|
||||
CVE-2026-56404, CVE-2026-56405, CVE-2026-56406, CVE-2026-56407,
|
||||
CVE-2026-56408, CVE-2026-56409, CVE-2026-56410, CVE-2026-56411,
|
||||
CVE-2026-56412
|
||||
ghostscript: (no CVE assigned)
|
||||
glibc: CVE-2026-5450, CVE-2026-5928
|
||||
icu: CVE-2025-5222
|
||||
imagemagick: CVE-2026-48724, CVE-2026-48733, CVE-2026-48734,
|
||||
CVE-2026-48994, CVE-2026-49218, CVE-2026-49219, CVE-2026-53460,
|
||||
CVE-2026-53461, CVE-2026-53462, CVE-2026-53463, CVE-2026-53464,
|
||||
CVE-2026-53465
|
||||
jq: CVE-2026-32316, CVE-2026-33947, CVE-2026-33948, CVE-2026-39979,
|
||||
CVE-2026-40164, CVE-2026-40612, CVE-2026-41256, CVE-2026-41257,
|
||||
CVE-2026-43894, CVE-2026-43896, CVE-2026-44777, CVE-2026-49839,
|
||||
CVE-2026-54679
|
||||
libarchive: (no CVE assigned)
|
||||
libcurl: CVE-2026-10536, CVE-2026-11352, CVE-2026-11564,
|
||||
CVE-2026-11586, CVE-2026-11856, CVE-2026-12064, CVE-2026-8286,
|
||||
CVE-2026-8458, CVE-2026-8924, CVE-2026-8925, CVE-2026-8926,
|
||||
CVE-2026-8927, CVE-2026-8932, CVE-2026-9079, CVE-2026-9080,
|
||||
CVE-2026-9545, CVE-2026-9546, CVE-2026-9547
|
||||
libevent: (no CVE assigned)
|
||||
libglib2: CVE-2025-14087
|
||||
libgsasl: CVE-2026-48829
|
||||
libinput: CVE-2026-50292
|
||||
libopenssl: CVE-2026-34180, CVE-2026-34181, CVE-2026-34182,
|
||||
CVE-2026-34183, CVE-2026-42764, CVE-2026-42766, CVE-2026-42767,
|
||||
CVE-2026-42768, CVE-2026-42769, CVE-2026-42770, CVE-2026-45445,
|
||||
CVE-2026-45446, CVE-2026-45447, CVE-2026-7383, CVE-2026-9076
|
||||
libssh2: CVE-2026-55199, CVE-2026-55200
|
||||
mariadb: CVE-2026-48163, CVE-2026-48165, CVE-2026-49261
|
||||
mesa3d: CVE-2026-40393
|
||||
mongoose: (no CVE assigned yet)
|
||||
nginx: CVE-2026-42055, CVE-2026-48142
|
||||
openjpeg: CVE-2026-6192
|
||||
openvpn: CVE-2026-11771, CVE-2026-12932, CVE-2026-12996,
|
||||
CVE-2026-13117, CVE-2026-13122, CVE-2026-13698
|
||||
php: CVE-2026-12184, CVE-2026-14355
|
||||
python-django: CVE-2026-35192, CVE-2026-35193, CVE-2026-48587,
|
||||
CVE-2026-5766, CVE-2026-6873, CVE-2026-6907, CVE-2026-7666,
|
||||
CVE-2026-8404
|
||||
python3: CVE-2026-11940, CVE-2026-9669
|
||||
redis: CVE-2026-23479, CVE-2026-23631, CVE-2026-25243
|
||||
squid: CVE-2026-33515, CVE-2026-33526, CVE-2026-47729, CVE-2026-50012
|
||||
sudo: CVE-2026-35535
|
||||
swupdate: CVE-2026-28525
|
||||
tiff: CVE-2026-36849
|
||||
tor: TROVE-2026-025, TROVE-2026-026.
|
||||
util-linux: CVE-2025-14104, CVE-2026-27456, CVE-2026-53612,
|
||||
CVE-2026-53613, CVE-2026-53614
|
||||
webkitgtk: CVE-2026-28847, CVE-2026-28883, CVE-2026-28901,
|
||||
CVE-2026-28902, CVE-2026-28903, CVE-2026-28904, CVE-2026-28905,
|
||||
CVE-2026-28907, CVE-2026-28942, CVE-2026-28946, CVE-2026-28947,
|
||||
CVE-2026-28953, CVE-2026-28955, CVE-2026-28958, CVE-2026-43658,
|
||||
CVE-2026-43660
|
||||
wolfssl: CVE-2026-10097, CVE-2026-10098, CVE-2026-10512,
|
||||
CVE-2026-10592, CVE-2026-11310, CVE-2026-11703, CVE-2026-11999,
|
||||
CVE-2026-12340, CVE-2026-55958, CVE-2026-55960, CVE-2026-55961,
|
||||
CVE-2026-55962, CVE-2026-55964, CVE-2026-55967, CVE-2026-6091,
|
||||
CVE-2026-6092, CVE-2026-6094, CVE-2026-6291, CVE-2026-6325,
|
||||
CVE-2026-6329, CVE-2026-6330, CVE-2026-6331, CVE-2026-6412,
|
||||
CVE-2026-6450, CVE-2026-6678, CVE-2026-6681, CVE-2026-6731,
|
||||
CVE-2026-7511, CVE-2026-7531, CVE-2026-7532, CVE-2026-8720
|
||||
|
||||
Toolchain:
|
||||
|
||||
- gcc: bump 14.x series to 14.4.0
|
||||
- glibc, localedef: security bump to version 2.41-143-gfc7a48bc9
|
||||
|
||||
Infrastructure updates/fixes:
|
||||
|
||||
- support/testing Improve TestPythonPy3NetworkmanagerGoi
|
||||
- generate-cyclonedx: fixup scp-style git sites
|
||||
- support/testing: Fix test_gnupg2
|
||||
- support/testing: various internal refactorings
|
||||
|
||||
Updated / fixed packages: apache, asterisk, avahi, bind, bind,
|
||||
cpp-httplib, cpp-httplib, cups-filters, expat, gcc:, ghostscript,
|
||||
glibc, hwdata, icu, imagemagick, jq, kodi-screensaver-rsxs,
|
||||
libarchive, libcurl, libepoxy, libevent, libglib2, libglib2,
|
||||
libglib2-bootstrap, libgsasl, libgsasl, libinput, libopenssl,
|
||||
libssh2, libssh2, linux, mariadb, mdnsd, mesa3d, mongoose, mpd,
|
||||
nginx, ntp, openjpeg, openrc, openvpn, php, python-django, python3,
|
||||
python3, qt5, redis, rsync, ruby, shadow, shim, squid, squid, squid,
|
||||
squid, strongswan, sudo, swupdate, tiff, tor, util-linux, util-linux,
|
||||
util-linux, util-linux, util-linux, util-linux, webkitgtk, wolfssl
|
||||
|
||||
2025.02.15, released June 16, 2026
|
||||
|
||||
Important / security related fixes:
|
||||
|
||||
asterisk: GHSA-8fj4-fv9f-hjpc, GHSA-g88q-c2hm-q7p7,
|
||||
GHSA-j29p-pvh2-pvqp, GHSA-x5pq-qrp4-fmrj
|
||||
bind: CVE-2026-3039, CVE-2026-3592, CVE-2026-5946, CVE-2026-5950
|
||||
capnproto: CVE-2026-322, CVE-2026-32239, CVE-2026-32240
|
||||
cups-filters: CVE-2025-64524
|
||||
dnsmasq: CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892,
|
||||
CVE-2026-4893, CVE-2026-5172
|
||||
dropbear: CVE-2019-6111, CVE-2026-35385
|
||||
exim: (no CVE assigned), CVE-2026-48840
|
||||
expat: CVE-2026-45186
|
||||
freeipmi: CVE-2026-50031
|
||||
glibc: CVE-2026-4046, CVE-2026-4437, CVE-2026-4438, CVE-2026-5450,
|
||||
CVE-2026-5928
|
||||
go: (no CVE assigned), CVE-2025-61726, CVE-2025-61728, CVE-2025-61730,
|
||||
CVE-2025-61731, CVE-2025-61732, CVE-2025-68121, CVE-2025-68121,
|
||||
CVE-2026-25679, CVE-2026-27137, CVE-2026-27138, CVE-2026-27139,
|
||||
CVE-2026-27140, CVE-2026-27142, CVE-2026-27143, CVE-2026-27144,
|
||||
CVE-2026-32280, CVE-2026-32281, CVE-2026-32283, CVE-2026-32288,
|
||||
CVE-2026-32289, CVE-2026-33810, CVE-2026-33811, CVE-2026-33814,
|
||||
CVE-2026-39817, CVE-2026-39819, CVE-2026-39820, CVE-2026-39823,
|
||||
CVE-2026-39825, CVE-2026-39826, CVE-2026-39836, CVE-2026-42499,
|
||||
CVE-2026-42501
|
||||
go-bootstrap-stage5: CVE-2026-33811, CVE-2026-33814, CVE-2026-39817,
|
||||
CVE-2026-39819, CVE-2026-39820, CVE-2026-39823, CVE-2026-39825,
|
||||
CVE-2026-39826, CVE-2026-39836, CVE-2026-42499, CVE-2026-42501
|
||||
haveged: CVE-2026-41054
|
||||
imagemagick: CVE-2026-42326, CVE-2026-45031, CVE-2026-45358,
|
||||
CVE-2026-45359, CVE-2026-45624, CVE-2026-45664, CVE-2026-46520,
|
||||
CVE-2026-46521, CVE-2026-46522, CVE-2026-46523, CVE-2026-46557,
|
||||
CVE-2026-46559
|
||||
intel-microcode: CVE-2025-35979
|
||||
libde265: CVE-2026-45382, CVE-2026-45383, GHSA-ccfw-29x7-rrx3,
|
||||
GHSA-j2qq-x2xq-g9wr
|
||||
libgpg-error: T8239
|
||||
libheif: CVE-2026-32738, CVE-2026-32739, CVE-2026-32740,
|
||||
CVE-2026-32741, CVE-2026-32814, CVE-2026-32882, CVE-2026-3949,
|
||||
CVE-2026-41069, CVE-2026-41071, CVE-2026-47178, CVE-2026-47247,
|
||||
CVE-2026-47251, CVE-2026-47254, CVE-2026-47709, CVE-2026-47714,
|
||||
GHSA-5hqq-636x-r3cr, GHSA-6x5f-qchq-cxqv, GHSA-jvmp-j3cw-84mh,
|
||||
GHSA-r7qj-cg5r-r6vf
|
||||
libmad: CVE-2017-837, CVE-2017-8372, CVE-2017-8373, CVE-2017-8374
|
||||
libmodsecurity: CVE-2026-30923, CVE-2026-42268
|
||||
libssh2: CVE-2026-7598
|
||||
liburiparser: CVE-2026-44927, CVE-2026-44928
|
||||
libusb: CVE-2026-23679, CVE-2026-47104
|
||||
libvncserver: CVE-2026-3285, CVE-2026-32853, CVE-2026-32854
|
||||
linux-pam: CVE-2025-6020
|
||||
mariadb: CVE-2026-34303, CVE-2026-3494, CVE-2026-44168, CVE-2026-44169,
|
||||
CVE-2026-44170, CVE-2026-44171, CVE-2026-44172, CVE-2026-44173
|
||||
memcached: (no CVE assigned)
|
||||
nginx: CVE-2026-40460, CVE-2026-40701, CVE-2026-42926, CVE-2026-42934,
|
||||
CVE-2026-42945, CVE-2026-42946, CVE-2026-9256
|
||||
openssh: CVE-2025-61984, CVE-2025-61985, CVE-2026-35385,
|
||||
CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414
|
||||
php: CVE-2025-14179, CVE-2026-6722, CVE-2026-6735, CVE-2026-7258,
|
||||
CVE-2026-7259, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568
|
||||
postgresql: CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,
|
||||
CVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,
|
||||
CVE-2026-6575, CVE-2026-6637, CVE-2026-6638
|
||||
putty: CVE-2026-48850, CVE-2026-48851, CVE-2026-48852
|
||||
python-urllib3: CVE-2026-44431, CVE-2026-44432
|
||||
python3: CVE-2026-3276, CVE-2026-7774, CVE-2026-8328
|
||||
radvd: CVE-2026-48715
|
||||
rsync: CVE-2026-29518, CVE-2026-43617, CVE-2026-43618, CVE-2026-43619,
|
||||
CVE-2026-43620, CVE-2026-45232
|
||||
runc: CVE-2025-31133, CVE-2025-52565, CVE-2025-52881
|
||||
samba4: CVE-2026-1933, CVE-2026-2340, CVE-2026-3012, CVE-2026-3238,
|
||||
CVE-2026-4408, CVE-2026-4480
|
||||
sdl2_image: CVE-2026-35444
|
||||
sed: CVE-2026-5958
|
||||
sshfs: CVE-2026-47187, CVE-2026-48711
|
||||
tor: TROVE-2026-013, TROVE-2026-014, TROVE-2026-015, TROVE-2026-016,
|
||||
TROVE-2026-017, TROVE-2026-018, TROVE-2026-019, TROVE-2026-020,
|
||||
TROVE-2026-021, TROVE-2026-022
|
||||
unbound: CVE-2026-32792, CVE-2026-33278, CVE-2026-40622,
|
||||
CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42944,
|
||||
CVE-2026-42959, CVE-2026-42960, CVE-2026-44390, CVE-2026-44608
|
||||
unzip: CVE-2021-4217
|
||||
xserver_xorg-server: (no CVE assigned)
|
||||
xwayland: (no CVE assigned)
|
||||
|
||||
Toolchain:
|
||||
|
||||
- linux-headers:: bump to 5.10.257, 5.15.208, 6.1.174, 6.6.141, 6.12.91
|
||||
|
||||
Infrastructure updates/fixes:
|
||||
|
||||
- generate-cyclonedx: generate externalReferences with
|
||||
source-distribution
|
||||
- Remove /usr/share/info/dir from target
|
||||
- bump-stable-kernel-versions: update for split hash file
|
||||
- cve-check: fix vulnerability timestamp to RFC 3339
|
||||
- cve-check: remove 'bom-ref' for vulnerabilities
|
||||
- generate-cyclonedx: add hashes from .hash files to externalReferences
|
||||
- dependencies.sh: reject buggy uutils "install" on Ubuntu 26.04
|
||||
- add 'make show-info-all'
|
||||
- cve-check: fix vulnerabilities with different analysis
|
||||
- kconfig: fix compiler warnings
|
||||
- generate-cyclonedx: remove indirect dependencies from root component
|
||||
- cve-check: add indication how to run
|
||||
- generate-cyclonedx: generate vcs externalReferences for source repos
|
||||
- gitlab-ci: use larger shared runners where necessary
|
||||
- replicate IGNORE_CVES to host packages
|
||||
- generate-cyclonedx: hint at missing Buildroot host package on a
|
||||
specific error
|
||||
|
||||
Updated defconfigs: at91sam9x5ek*
|
||||
|
||||
Updated / fixed packages: libmicrohttpd, qt53d, crucible, libgit2, php,
|
||||
esp-hosted, tzdata, libabseil-cpp, collectd, redis, swupdate,
|
||||
libdill, zsh, samba4, haveged, arm-trusted-firmware, weston,
|
||||
wireless-regdb, libssh2, go-bootstrap-stage5, jq, kodi, unbound,
|
||||
lrzip, libgpg-error, hplip, expat, heimdal, glibc, go, imagemagick,
|
||||
kexec, libnss, putty, libmad, vorbis-tools, libvncserver, rsync,
|
||||
mongoose, intel-microcode, freeipmi, openssh, dos2unix, liburiparser,
|
||||
zic, cups-filters, libks, odhcp6c, libmodsecurity, memcached,
|
||||
graphene, vlc, capnproto, faad2, gcc-bare-metal, mariadb, qt6base,
|
||||
python-ecdsa, runc, heirloom-mailx, icu, systemd, unzip, dnsmasq,
|
||||
gst1-plugins-bad, cairo, dropbear, libusb, asterisk, hiredis,
|
||||
linux-pam, sed, gstreamer1, xfsprogs, python-urllib3, radvd,
|
||||
qt5webengine-chromium, sshfs, gdb, python3, sane-backends,
|
||||
linux-headers:, zlib-ng, libheif, supertux, postgresql,
|
||||
gst1-plugins-good, libde265, libdrm, exim, linux, lrzsz, babeld,
|
||||
bind, nginx, stellarium, sdl2_image, tor, libpthsem, wpewebkit,
|
||||
libargon2, xwayland, python-cbor2, xserver_xorg-server, poppler,
|
||||
jemalloc
|
||||
|
||||
2025.02.14, released May 20, 2026
|
||||
|
||||
Changes with potentially large impact:
|
||||
|
||||
@@ -101,6 +101,11 @@ config BR2_HOST_GCC_AT_LEAST_15
|
||||
# When adding new entries above, be sure to update
|
||||
# the HOSTCC_MAX_VERSION variable in the Makefile.
|
||||
|
||||
# Hidden boolean selected by packages in need of Java in order to build
|
||||
# (example: kodi)
|
||||
config BR2_NEEDS_HOST_JAVA
|
||||
bool
|
||||
|
||||
# Hidden boolean selected by pre-built packages for x86, when they
|
||||
# need to run on x86-64 machines (example: pre-built external
|
||||
# toolchains, binary tools, etc.).
|
||||
|
||||
@@ -144,19 +144,7 @@ endif
|
||||
|
||||
###############################################################################
|
||||
|
||||
comment "Legacy options removed in 2026.08"
|
||||
|
||||
config BR2_PACKAGE_FLUIDSYNTH_SDL2
|
||||
bool "fluidsynth sdl2 audio support removed"
|
||||
select BR2_LEGACY
|
||||
help
|
||||
FluidSynth SDL2 audio support was removed in v2.5.0.
|
||||
|
||||
config BR2_PACKAGE_HOSTAPD_DRIVER_HOSTAP
|
||||
bool "hostapd hostap driver removed"
|
||||
select BR2_LEGACY
|
||||
help
|
||||
The hostap driver was removed from hostapd.
|
||||
comment "Legacy options removed in 2026.05.2"
|
||||
|
||||
config BR2_GDB_VERSION_ARC
|
||||
bool "ARC-specific gdb version removed"
|
||||
@@ -193,13 +181,6 @@ config BR2_PACKAGE_TS4900_FPGA
|
||||
The ts4900 defconfig was removed, so ts4900-fpga package
|
||||
has been dropped.
|
||||
|
||||
config BR2_GDB_VERSION_14
|
||||
bool "gdb 14.x has been removed"
|
||||
select BR2_LEGACY
|
||||
help
|
||||
GDB 14.x support has been removed, a newer version should be
|
||||
used instead.
|
||||
|
||||
config BR2_PACKAGE_ARGPARSE
|
||||
bool "argparse has been removed"
|
||||
select BR2_LEGACY
|
||||
@@ -207,40 +188,6 @@ config BR2_PACKAGE_ARGPARSE
|
||||
help
|
||||
Package argparse duplicates the package lua-argparse.
|
||||
|
||||
config BR2_KERNEL_HEADERS_7_0
|
||||
bool "kernel headers version 7.0.x are no longer supported"
|
||||
select BR2_LEGACY
|
||||
help
|
||||
Version 7.0.x of the Linux kernel headers are no longer
|
||||
maintained upstream and are now removed.
|
||||
|
||||
config BR2_PACKAGE_BLUEZ5_UTILS_PLUGINS_SAP
|
||||
bool "bluez sap plugin removed"
|
||||
select BR2_LEGACY
|
||||
help
|
||||
Build plugin for SAP profile.
|
||||
|
||||
config BR2_PACKAGE_BLUEZ5_UTILS_PLUGINS_HEALTH
|
||||
bool "bluez health plugin removed"
|
||||
select BR2_LEGACY
|
||||
help
|
||||
Build plugin for health profiles.
|
||||
|
||||
config BR2_GCC_VERSION_13_X
|
||||
bool "gcc 13.x support removed"
|
||||
select BR2_LEGACY
|
||||
help
|
||||
Support for building a toolchain based on GCC 13.x has been
|
||||
removed, chose a newer GCC version instead.
|
||||
|
||||
config BR2_PACKAGE_QEMU_TARGET_MICROBLAZEEL
|
||||
bool "qemu target microblazeel removed"
|
||||
select BR2_PACKAGE_QEMU_TARGET_MICROBLAZE
|
||||
select BR2_LEGACY
|
||||
help
|
||||
Version 11.0.0 of qemu folded microblazeel support into
|
||||
the microblaze target.
|
||||
|
||||
comment "Legacy options removed in 2026.05"
|
||||
|
||||
config BR2_PACKAGE_PTPD2
|
||||
|
||||
50
DEVELOPERS
50
DEVELOPERS
@@ -168,9 +168,6 @@ F: configs/hifive_unleashed_defconfig
|
||||
F: package/libspdm/
|
||||
F: package/xen/
|
||||
|
||||
N: Alsey Coleman Miller <alseycmiller@gmail.com>
|
||||
F: package/liblc3/
|
||||
|
||||
N: Alvaro G. M <alvaro.gamez@hazent.com>
|
||||
F: package/dcron/
|
||||
F: package/libxmlrpc/
|
||||
@@ -191,7 +188,6 @@ F: package/wine/
|
||||
|
||||
N: Andrea Ricchi <andrea.ricchi@amarulasolutions.com>
|
||||
F: package/cutekeyboard/
|
||||
F: package/libcppconnman/
|
||||
|
||||
N: Andreas Klinger <ak@it-klinger.de>
|
||||
F: package/ply/
|
||||
@@ -249,7 +245,6 @@ F: package/python-pillow/
|
||||
F: package/python-pydal/
|
||||
F: package/python-spidev/
|
||||
F: package/python-web2py/
|
||||
F: package/qpdf/
|
||||
F: package/qt5/qt5coap/
|
||||
F: package/qt5/qt5knx/
|
||||
F: package/qt5/qt5mqtt/
|
||||
@@ -452,7 +447,6 @@ F: package/libsidplay2/
|
||||
F: package/libsilk/
|
||||
F: package/libsndfile/
|
||||
F: package/libsoundtouch/
|
||||
F: package/libudev-zero/
|
||||
F: package/libudfread/
|
||||
F: package/libunibreak/
|
||||
F: package/liburiparser/
|
||||
@@ -521,7 +515,6 @@ F: package/python-pyicu/
|
||||
F: package/python-pylru/
|
||||
F: package/python-requests-oauthlib/
|
||||
F: package/python-slob/
|
||||
F: package/qt6/qt6positioning/
|
||||
F: package/rrdtool/
|
||||
F: package/rsync/
|
||||
F: package/rtmpdump/
|
||||
@@ -539,7 +532,6 @@ F: package/unixodbc/
|
||||
F: package/utfcpp/
|
||||
F: package/vlc/
|
||||
F: package/wget/
|
||||
F: package/wget2/
|
||||
F: package/wireless-regdb/
|
||||
F: package/wireless_tools/
|
||||
F: package/x264/
|
||||
@@ -712,9 +704,6 @@ F: package/perl-sys-mmap/
|
||||
F: package/perl-time-parsedate/
|
||||
F: package/perl-x10/
|
||||
|
||||
N: Christopher Obbard <chris.obbard@oss.qualcomm.com>
|
||||
F: package/dtui/
|
||||
|
||||
N: Colin Foster <colin.foster@in-advantage.com>
|
||||
F: package/python-tftpy/
|
||||
F: package/rauc-hawkbit-updater/
|
||||
@@ -822,7 +811,6 @@ F: package/babeld/
|
||||
F: package/bc/
|
||||
F: package/cmocka/
|
||||
F: package/connman/
|
||||
F: package/drogon/
|
||||
F: package/empty/
|
||||
F: package/iana-assignments/
|
||||
F: package/inih/
|
||||
@@ -1152,7 +1140,6 @@ F: package/cpulimit/
|
||||
|
||||
N: Florian Larysch <fl@n621.de>
|
||||
F: package/casync-nano/
|
||||
F: package/sigsum-c/
|
||||
F: package/sigsum-go/
|
||||
|
||||
N: Floris Bos <bos@je-eigen-domein.nl>
|
||||
@@ -1191,9 +1178,7 @@ F: package/copas/
|
||||
F: package/coxpcall/
|
||||
F: package/dado/
|
||||
F: package/ficl/
|
||||
F: package/hare*
|
||||
F: package/janet/
|
||||
F: package/qbe/
|
||||
F: package/libtomcrypt/
|
||||
F: package/libtommath/
|
||||
F: package/linenoise/
|
||||
@@ -1209,12 +1194,10 @@ F: package/lzlib/
|
||||
F: package/moarvm/
|
||||
F: package/opendoas/
|
||||
F: package/perl*
|
||||
F: package/pkg-hare.mk
|
||||
F: package/pkg-perl.mk
|
||||
F: package/pkg-luarocks.mk
|
||||
F: package/quickjs/
|
||||
F: package/rings/
|
||||
F: package/scdoc/
|
||||
F: package/wsapi/
|
||||
F: package/wsapi-fcgi/
|
||||
F: package/wsapi-xavante/
|
||||
@@ -1765,7 +1748,6 @@ F: package/llama-cpp/
|
||||
F: package/llvm-project/clang/
|
||||
F: package/llvm-project/lld/
|
||||
F: package/llvm-project/llvm/
|
||||
F: package/mesa3d/
|
||||
F: package/python-cython/
|
||||
F: package/python-pycups/
|
||||
F: package/python-raven/
|
||||
@@ -1776,8 +1758,6 @@ F: package/python-xlib/
|
||||
F: package/sentry-cli/
|
||||
F: package/sentry-native/
|
||||
F: package/unclutter-xfixes/
|
||||
F: package/virglrenderer/
|
||||
F: support/testing/tests/package/test_virglrenderer.py
|
||||
|
||||
N: Joshua Henderson <joshua.henderson@microchip.com>
|
||||
F: package/qt5/qt5wayland/
|
||||
@@ -1856,8 +1836,6 @@ F: support/testing/tests/boot/test_optee_os.py
|
||||
F: support/testing/tests/boot/test_optee_os/
|
||||
F: support/testing/tests/fs/test_btrfs.py
|
||||
F: support/testing/tests/fs/test_btrfs/
|
||||
F: support/testing/tests/fs/test_cramfs.py
|
||||
F: support/testing/tests/fs/test_cramfs/
|
||||
F: support/testing/tests/fs/test_erofs.py
|
||||
F: support/testing/tests/fs/test_erofs/
|
||||
F: support/testing/tests/fs/test_xfs.py
|
||||
@@ -2030,8 +2008,6 @@ F: support/testing/tests/package/test_python_pyqt5.py
|
||||
F: support/testing/tests/package/test_python_pyqt5/
|
||||
F: support/testing/tests/package/test_python_spake2.py
|
||||
F: support/testing/tests/package/test_python_sympy.py
|
||||
F: support/testing/tests/package/test_quickjs.py
|
||||
F: support/testing/tests/package/test_quickjs/
|
||||
F: support/testing/tests/package/test_rdma_core.py
|
||||
F: support/testing/tests/package/test_rdma_core/
|
||||
F: support/testing/tests/package/test_rrdtool.py
|
||||
@@ -2065,8 +2041,6 @@ F: support/testing/tests/package/test_weston/
|
||||
F: support/testing/tests/package/test_wget.py
|
||||
F: support/testing/tests/package/test_which.py
|
||||
F: support/testing/tests/package/test_wine.py
|
||||
F: support/testing/tests/package/test_wpa_supplicant.py
|
||||
F: support/testing/tests/package/test_wpa_supplicant/
|
||||
F: support/testing/tests/package/test_xfsprogs.py
|
||||
F: support/testing/tests/package/test_xfsprogs/
|
||||
F: support/testing/tests/package/test_xvisor.py
|
||||
@@ -2299,8 +2273,6 @@ F: support/testing/tests/package/sample_python_dbus_fast.py
|
||||
F: support/testing/tests/package/sample_python_dbus_next.py
|
||||
F: support/testing/tests/package/sample_python_pytest.py
|
||||
F: support/testing/tests/package/sample_python_pytest_asyncio.py
|
||||
F: support/testing/tests/package/test_easydbus.py
|
||||
F: support/testing/tests/package/test_easydbus/
|
||||
F: support/testing/tests/package/test_netdata.py
|
||||
F: support/testing/tests/package/test_python_dbus_next.py
|
||||
F: support/testing/tests/package/test_python_pytest.py
|
||||
@@ -2435,10 +2407,6 @@ F: configs/arcturus_ucls1012a_defconfig
|
||||
N: Michael Fischer <mf@go-sys.de>
|
||||
F: package/gnuplot/
|
||||
F: package/sdl2/
|
||||
F: package/sdl3/
|
||||
F: package/sdl3_gfx/
|
||||
F: package/sdl3_image/
|
||||
F: package/sdl3_ttf/
|
||||
|
||||
N: Michael Nosthoff <buildroot@heine.tech>
|
||||
F: package/boost/
|
||||
@@ -2684,7 +2652,6 @@ F: configs/orangepi_pc_defconfig
|
||||
F: configs/orangepi_r1_defconfig
|
||||
F: configs/sheevaplug_defconfig
|
||||
F: configs/visionfive_defconfig
|
||||
F: package/agec/
|
||||
F: package/bats-core/
|
||||
F: package/dfu-programmer/
|
||||
F: package/docker-compose/
|
||||
@@ -2719,9 +2686,7 @@ F: package/triggerhappy/
|
||||
F: package/ugetty/
|
||||
F: package/wireguard-linux-compat/
|
||||
F: package/wireguard-tools/
|
||||
F: support/testing/tests/package/test_agec.py
|
||||
F: support/testing/tests/package/test_docker_compose.py
|
||||
F: support/testing/tests/package/test_haproxy.py
|
||||
F: support/testing/tests/package/test_python_hid.py
|
||||
|
||||
N: Peter Seiderer <ps.report@gmx.net>
|
||||
@@ -3063,13 +3028,10 @@ F: package/ubus/
|
||||
F: package/wolfssl/
|
||||
|
||||
N: Shubham Chakraborty <chakrabortyshubham66@gmail.com>
|
||||
F: package/bash-completion/
|
||||
F: package/ccache/
|
||||
F: package/dos2unix/
|
||||
F: package/font-awesome/
|
||||
F: package/htop/
|
||||
F: package/hyperfine/
|
||||
F: package/libenca/
|
||||
F: package/pv/
|
||||
F: package/unrar/
|
||||
F: package/xterm/
|
||||
@@ -3302,10 +3264,7 @@ F: support/testing/tests/package/sample_python_augeas.py
|
||||
F: support/testing/tests/package/sample_python_flask.py
|
||||
F: support/testing/tests/package/sample_python_flask_expects_json.py
|
||||
F: support/testing/tests/package/sample_python_git.py
|
||||
F: support/testing/tests/package/sample_python_pyudev.py
|
||||
F: support/testing/tests/package/sample_python_unittest_xml_reporting.py
|
||||
F: support/testing/tests/package/test_bpftrace.py
|
||||
F: support/testing/tests/package/test_bpftrace/linux-bpftrace.fragment
|
||||
F: support/testing/tests/package/test_nodejs.py
|
||||
F: support/testing/tests/package/test_python_augeas.py
|
||||
F: support/testing/tests/package/test_python_crccheck.py
|
||||
@@ -3314,7 +3273,6 @@ F: support/testing/tests/package/test_python_flask_expects_json.py
|
||||
F: support/testing/tests/package/test_python_fs.py
|
||||
F: support/testing/tests/package/test_python_git.py
|
||||
F: support/testing/tests/package/test_python_pyfatfs.py
|
||||
F: support/testing/tests/package/test_python_pyudev.py
|
||||
F: support/testing/tests/package/test_python_pyusb.py
|
||||
F: support/testing/tests/package/test_python_serial.py
|
||||
F: support/testing/tests/package/test_snagboot.py
|
||||
@@ -3387,8 +3345,6 @@ F: package/dpdk/
|
||||
F: package/libecoli/
|
||||
F: package/libnss-ato/
|
||||
F: package/libyang-cpp/
|
||||
F: package/python-libyang/
|
||||
F: package/python-sysv-ipc/
|
||||
F: package/sysrepo-cpp/
|
||||
|
||||
N: Vincent Prince <vincent.prince.fr@gmail.com>
|
||||
@@ -3461,11 +3417,6 @@ F: package/evilwm/
|
||||
F: package/fbv/
|
||||
F: package/libpam-pkcs11/
|
||||
F: package/mksh/
|
||||
F: package/perl-cgi/
|
||||
F: package/perl-cgi-session/
|
||||
F: package/perl-log-message/
|
||||
F: package/perl-log-message-simple/
|
||||
F: package/perl-switch/
|
||||
F: package/ruby/
|
||||
F: package/uclibc/
|
||||
F: package/uclibc-ng-test/
|
||||
@@ -3526,7 +3477,6 @@ F: package/tpm2-pkcs11/
|
||||
N: Yann E. MORIN <yann.morin@orange.com>
|
||||
F: .editorconfig
|
||||
F: package/amazon-ecr-credential-helper/
|
||||
F: package/distribution-registry/
|
||||
F: package/docker-credential-acr-env/
|
||||
F: package/docker-credential-gcr/
|
||||
F: package/gpsd/
|
||||
|
||||
4
Makefile
4
Makefile
@@ -92,9 +92,9 @@ all:
|
||||
.PHONY: all
|
||||
|
||||
# Set and export the version string
|
||||
export BR2_VERSION := 2026.08-rc3
|
||||
export BR2_VERSION := 2026.05.2
|
||||
# Actual time the release is cut (for reproducible builds)
|
||||
BR2_VERSION_EPOCH = 1788030000
|
||||
BR2_VERSION_EPOCH = 1787518800
|
||||
|
||||
# Save running make version since it's clobbered by the make package
|
||||
RUNNING_MAKE_VERSION := $(MAKE_VERSION)
|
||||
|
||||
@@ -344,10 +344,6 @@ config BR2_ARCH_NEEDS_GCC_AT_LEAST_16
|
||||
bool
|
||||
select BR2_ARCH_NEEDS_GCC_AT_LEAST_15
|
||||
|
||||
config BR2_ARCH_NEEDS_GCC_AT_LEAST_17
|
||||
bool
|
||||
select BR2_ARCH_NEEDS_GCC_AT_LEAST_16
|
||||
|
||||
# The following string values are defined by the individual
|
||||
# Config.in.$ARCH files
|
||||
config BR2_ARCH
|
||||
|
||||
@@ -23,11 +23,6 @@ choice
|
||||
help
|
||||
Specific CPU variant to use
|
||||
|
||||
config BR2_m68k_68000
|
||||
bool "68000"
|
||||
select BR2_m68k_m68k
|
||||
select BR2_SOFT_FLOAT
|
||||
|
||||
config BR2_m68k_68030
|
||||
bool "68030"
|
||||
select BR2_m68k_m68k
|
||||
@@ -46,7 +41,6 @@ config BR2_m68k_cf5208
|
||||
endchoice
|
||||
|
||||
config BR2_GCC_TARGET_CPU
|
||||
default "68000" if BR2_m68k_68000
|
||||
default "68030" if BR2_m68k_68030
|
||||
default "68040" if BR2_m68k_68040
|
||||
default "5208" if BR2_m68k_cf5208
|
||||
|
||||
@@ -144,16 +144,6 @@ config BR2_powerpc_power9
|
||||
select BR2_POWERPC_CPU_HAS_ALTIVEC
|
||||
select BR2_POWERPC_CPU_HAS_VSX
|
||||
select BR2_ARCH_NEEDS_GCC_AT_LEAST_6
|
||||
config BR2_powerpc_power10
|
||||
bool "power10"
|
||||
select BR2_POWERPC_CPU_HAS_ALTIVEC
|
||||
select BR2_POWERPC_CPU_HAS_VSX
|
||||
select BR2_ARCH_NEEDS_GCC_AT_LEAST_11
|
||||
config BR2_powerpc_power11
|
||||
bool "power11"
|
||||
select BR2_POWERPC_CPU_HAS_ALTIVEC
|
||||
select BR2_POWERPC_CPU_HAS_VSX
|
||||
select BR2_ARCH_NEEDS_GCC_AT_LEAST_15
|
||||
endchoice
|
||||
|
||||
config BR2_POWERPC_SOFT_FLOAT
|
||||
@@ -217,8 +207,6 @@ config BR2_GCC_TARGET_CPU
|
||||
default "power7" if BR2_powerpc_power7
|
||||
default "power8" if BR2_powerpc_power8
|
||||
default "power9" if BR2_powerpc_power9
|
||||
default "power10" if BR2_powerpc_power10
|
||||
default "power11" if BR2_powerpc_power11
|
||||
|
||||
config BR2_READELF_ARCH_NAME
|
||||
default "PowerPC" if BR2_powerpc
|
||||
|
||||
@@ -1,3 +0,0 @@
|
||||
CONFIG_BLK_DEV_PMEM=y
|
||||
CONFIG_LIBNVDIMM=y
|
||||
CONFIG_OF_PMEM=y
|
||||
@@ -48,17 +48,6 @@ alternative to QEMU_EFI.fd. You will also need to change the machine
|
||||
specification to "-M virt,secure=on" on qemu command line, to enable TrustZone
|
||||
support, and you will need to increase the memory with "-m 1024".
|
||||
|
||||
HTTP boot
|
||||
---------
|
||||
|
||||
Some U-Boot and Devicetree based firmwares are capable of booting with UEFI from
|
||||
HTTP(s). [4]
|
||||
|
||||
The aarch64_efi_defconfig has appropriate persistent memory support compiled in
|
||||
the Linux kernel to support this scenario. [5]
|
||||
|
||||
[1]: https://github.com/ARM-software/ebbr
|
||||
[2]: https://developer.arm.com/architectures/system-architectures/arm-systemready
|
||||
[3]: https://github.com/glikely/u-boot-tfa-build
|
||||
[4]: https://docs.u-boot-project.org/en/latest/develop/uefi/uefi.html#uefi-http-boot-using-the-legacy-tcp-stack
|
||||
[5]: https://github.com/ARM-software/edge-iot-arch-guide/blob/main/source/http-boot/pmem_node.md
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# From https://www.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
|
||||
sha256 3712fc1ec839e4daac981176c8518912e8f452650aaedfe4381da4419613a431 linux-6.18.40.tar.xz
|
||||
sha256 37f0c5d5c242c1d604e87d48f08795e861a5a85f725b4ca11d0a538f12ff8cff linux-6.18.8.tar.xz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# From https://cdn.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
|
||||
sha256 ac26e508abd56e9f8b89872b6e10c49fc823bcc70d8068a5d8504c1a7c4ff045 linux-6.18.38.tar.xz
|
||||
sha256 1c38214fb137bae85b82b82537b5987358621b915ab2a8e4f09e60697c19474f linux-6.18.21.tar.xz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 78e8bfc382fe388f9b55aa1daf8c563522a037779b5d4c349d1415e381f1243e u-boot-2026.07.tar.bz2
|
||||
sha256 ac7c04b8b7004923b00a4e5d6699c5df4d21233bac9fda690d8cfbc209fff2fd u-boot-2026.04.tar.bz2
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# From https://cdn.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
|
||||
sha256 7d2e1b5d5ab36b3a01856e71782dad2a54e634fb2b37c0a42998def3bbf957c1 linux-6.12.96.tar.xz
|
||||
sha256 c92591d896e79ecddbc3319136f0c2f855e832b397de7593f013ad7590a43e53 linux-6.12.80.tar.xz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 78e8bfc382fe388f9b55aa1daf8c563522a037779b5d4c349d1415e381f1243e u-boot-2026.07.tar.bz2
|
||||
sha256 ac7c04b8b7004923b00a4e5d6699c5df4d21233bac9fda690d8cfbc209fff2fd u-boot-2026.04.tar.bz2
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# From https://www.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
|
||||
sha256 7d2e1b5d5ab36b3a01856e71782dad2a54e634fb2b37c0a42998def3bbf957c1 linux-6.12.96.tar.xz
|
||||
sha256 c92591d896e79ecddbc3319136f0c2f855e832b397de7593f013ad7590a43e53 linux-6.12.80.tar.xz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 78e8bfc382fe388f9b55aa1daf8c563522a037779b5d4c349d1415e381f1243e u-boot-2026.07.tar.bz2
|
||||
sha256 ac7c04b8b7004923b00a4e5d6699c5df4d21233bac9fda690d8cfbc209fff2fd u-boot-2026.04.tar.bz2
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# From https://www.kernel.org/pub/linux/kernel/v7.x/sha256sums.asc
|
||||
sha256 be41c068e88f5242a19bccdbffbe077b18c47b45f627e2325504b4fab79dd1dc linux-7.1.3.tar.xz
|
||||
# From https://www.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
|
||||
sha256 4d9f3ff73214f68c0194ef02db9ca4b7ba713253ac1045441d4e9f352bc22e14 linux-6.19.6.tar.xz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 78e8bfc382fe388f9b55aa1daf8c563522a037779b5d4c349d1415e381f1243e u-boot-2026.07.tar.bz2
|
||||
sha256 b60d5865cefdbc75da8da4156c56c458e00de75a49b80c1a2e58a96e30ad0d54 u-boot-2026.01.tar.bz2
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# From https://www.kernel.org/pub/linux/kernel/v7.x/sha256sums.asc
|
||||
sha256 be41c068e88f5242a19bccdbffbe077b18c47b45f627e2325504b4fab79dd1dc linux-7.1.3.tar.xz
|
||||
# From https://www.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
|
||||
sha256 4d9f3ff73214f68c0194ef02db9ca4b7ba713253ac1045441d4e9f352bc22e14 linux-6.19.6.tar.xz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 78e8bfc382fe388f9b55aa1daf8c563522a037779b5d4c349d1415e381f1243e u-boot-2026.07.tar.bz2
|
||||
sha256 b60d5865cefdbc75da8da4156c56c458e00de75a49b80c1a2e58a96e30ad0d54 u-boot-2026.01.tar.bz2
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 658af40a90fd8e2460d364775a0c37e0507201e49de7f69c8a22d61e179f81e1 atf-lf-6.18.20-2.0.0.tar.gz
|
||||
sha256 2d3f9c52e16766c290bdc0bc130d634e4c326a5b236dfb2f2ca3f0fa457e82d4 atf-lf-6.12.34-2.1.0.tar.gz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally computed
|
||||
sha256 206f997d41bb958099bf7a89a02a6889942b118984f81f9a45bec9907f60708f linux-lf-6.18.20-2.0.0.tar.gz
|
||||
sha256 27a1987ca0a5802d3ebb296b8134ec66d813ad86cf2a60779b45092735bbb23b linux-lf-6.12.34-2.1.0.tar.gz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally computed
|
||||
sha256 04aed627132db7b656117c7a35fb29d314172319fa3a297ea6748eebac2b5ce3 u-boot-lf-6.18.20-2.0.0.tar.gz
|
||||
sha256 2f25cde388b2f83ff7a8e3afe25aafb1db48dafb0fa3bf1e4f9fef603f3b4785 u-boot-lf-6.12.34-2.1.0.tar.gz
|
||||
|
||||
@@ -11,7 +11,7 @@ For more details about the board and the QorIQ Layerscape SoC, see the following
|
||||
Layerscape platforms are officially supported by NXP under the Layerscape
|
||||
Debian Linux SDK (LDLSDK). This uses components from Linux Factory (project
|
||||
common with i.MX), but has a slower release cadence than LF. The currently used
|
||||
tag is lf-6.18.20-2.0.0, which is in line with the latest LF tag. Generally, in
|
||||
tag is lf-6.12.34-2.1.0, which is in line with the latest LF tag. Generally, in
|
||||
Buildroot, the latest Linux Factory release tag is always used, which may be
|
||||
considered pre-release software, as it may contain features which are not yet
|
||||
documented, and it generally undergoes less testing.
|
||||
@@ -21,11 +21,11 @@ For the software Layerscape Debian Linux SDK User Guide, see:
|
||||
- https://www.nxp.com/docs/en/user-guide/UG10143.pdf
|
||||
|
||||
The components from NXP are:
|
||||
- rcw, lf-6.18.20-2.0.0
|
||||
- atf (fork), lf-6.18.20-2.0.0
|
||||
- uboot (fork), lf-6.18.20-2.0.0
|
||||
- rcw, lf-6.12.34-2.1.0
|
||||
- atf (fork), lf-6.12.34-2.1.0
|
||||
- uboot (fork), lf-6.12.34-2.1.0
|
||||
- cadence-dp-firmware (blob), 8.16
|
||||
- linux (fork), lf-6.18.20-2.0.0
|
||||
- linux (fork), lf-6.12.34-2.1.0
|
||||
|
||||
Build
|
||||
=====
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 658af40a90fd8e2460d364775a0c37e0507201e49de7f69c8a22d61e179f81e1 atf-lf-6.18.20-2.0.0.tar.gz
|
||||
sha256 2d3f9c52e16766c290bdc0bc130d634e4c326a5b236dfb2f2ca3f0fa457e82d4 atf-lf-6.12.34-2.1.0.tar.gz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally computed
|
||||
sha256 206f997d41bb958099bf7a89a02a6889942b118984f81f9a45bec9907f60708f linux-lf-6.18.20-2.0.0.tar.gz
|
||||
sha256 27a1987ca0a5802d3ebb296b8134ec66d813ad86cf2a60779b45092735bbb23b linux-lf-6.12.34-2.1.0.tar.gz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally computed
|
||||
sha256 04aed627132db7b656117c7a35fb29d314172319fa3a297ea6748eebac2b5ce3 u-boot-lf-6.18.20-2.0.0.tar.gz
|
||||
sha256 2f25cde388b2f83ff7a8e3afe25aafb1db48dafb0fa3bf1e4f9fef603f3b4785 u-boot-lf-6.12.34-2.1.0.tar.gz
|
||||
|
||||
@@ -11,7 +11,7 @@ for more details about the board and the QorIQ Layerscape SoC, see the following
|
||||
Layerscape platforms are officially supported by NXP under the Layerscape
|
||||
Debian Linux SDK (LDLSDK). This uses components from Linux Factory (project
|
||||
common with i.MX), but has a slower release cadence than LF. The currently used
|
||||
tag is lf-6.18.20-2.0.0, which is in line with the latest LF tag. Generally, in
|
||||
tag is lf-6.12.34-2.1.0, which is in line with the latest LF tag. Generally, in
|
||||
Buildroot, the latest Linux Factory release tag is always used, which may be
|
||||
considered pre-release software, as it may contain features which are not yet
|
||||
documented, and it generally undergoes less testing.
|
||||
@@ -21,13 +21,13 @@ For the software Layerscape Debian Linux SDK User Guide, see:
|
||||
- https://www.nxp.com/docs/en/user-guide/UG10143.pdf
|
||||
|
||||
The components from NXP are:
|
||||
- rcw, lf-6.18.20-2.0.0
|
||||
- atf (fork), lf-6.18.20-2.0.0
|
||||
- uboot (fork), lf-6.18.20-2.0.0
|
||||
- qoriq-fm-ucode (blob), lf-6.18.20-2.0.0
|
||||
- linux (fork), lf-6.18.20-2.0.0
|
||||
- fmlib, lf-6.18.20-2.0.0
|
||||
- fmc, lf-6.18.20-2.0.0
|
||||
- rcw, lf-6.12.34-2.1.0
|
||||
- atf (fork), lf-6.12.34-2.1.0
|
||||
- uboot (fork), lf-6.12.34-2.1.0
|
||||
- qoriq-fm-ucode (blob), lf-6.12.34-2.1.0
|
||||
- linux (fork), lf-6.12.34-2.1.0
|
||||
- fmlib, lf-6.12.34-2.1.0
|
||||
- fmc, lf-6.12.34-2.1.0
|
||||
|
||||
Build
|
||||
=====
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 658af40a90fd8e2460d364775a0c37e0507201e49de7f69c8a22d61e179f81e1 atf-lf-6.18.20-2.0.0.tar.gz
|
||||
sha256 2d3f9c52e16766c290bdc0bc130d634e4c326a5b236dfb2f2ca3f0fa457e82d4 atf-lf-6.12.34-2.1.0.tar.gz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally computed
|
||||
sha256 206f997d41bb958099bf7a89a02a6889942b118984f81f9a45bec9907f60708f linux-lf-6.18.20-2.0.0.tar.gz
|
||||
sha256 27a1987ca0a5802d3ebb296b8134ec66d813ad86cf2a60779b45092735bbb23b linux-lf-6.12.34-2.1.0.tar.gz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally computed
|
||||
sha256 04aed627132db7b656117c7a35fb29d314172319fa3a297ea6748eebac2b5ce3 u-boot-lf-6.18.20-2.0.0.tar.gz
|
||||
sha256 2f25cde388b2f83ff7a8e3afe25aafb1db48dafb0fa3bf1e4f9fef603f3b4785 u-boot-lf-6.12.34-2.1.0.tar.gz
|
||||
|
||||
@@ -12,7 +12,7 @@ For more details about the board and the QorIQ Layerscape SoC, see the following
|
||||
Layerscape platforms are officially supported by NXP under the Layerscape
|
||||
Debian Linux SDK (LDLSDK). This uses components from Linux Factory (project
|
||||
common with i.MX), but has a slower release cadence than LF. The currently used
|
||||
tag is lf-6.18.20-2.0.0, which is in line with the latest LF tag. Generally, in
|
||||
tag is lf-6.12.34-2.1.0, which is in line with the latest LF tag. Generally, in
|
||||
Buildroot, the latest Linux Factory release tag is always used, which may be
|
||||
considered pre-release software, as it may contain features which are not yet
|
||||
documented, and it generally undergoes less testing.
|
||||
@@ -22,13 +22,13 @@ For the software Layerscape Debian Linux SDK User Guide, see:
|
||||
- https://www.nxp.com/docs/en/user-guide/UG10143.pdf
|
||||
|
||||
The components from NXP are:
|
||||
- rcw, lf-6.18.20-2.0.0
|
||||
- atf (fork), lf-6.18.20-2.0.0
|
||||
- uboot (fork), lf-6.18.20-2.0.0
|
||||
- qoriq-fm-ucode (blob), lf-6.18.20-2.0.0
|
||||
- linux (fork), lf-6.18.20-2.0.0
|
||||
- fmlib, lf-6.18.20-2.0.0
|
||||
- fmc, lf-6.18.20-2.0.0
|
||||
- rcw, lf-6.12.34-2.1.0
|
||||
- atf (fork), lf-6.12.34-2.1.0
|
||||
- uboot (fork), lf-6.12.34-2.1.0
|
||||
- qoriq-fm-ucode (blob), lf-6.12.34-2.1.0
|
||||
- linux (fork), lf-6.12.34-2.1.0
|
||||
- fmlib, lf-6.12.34-2.1.0
|
||||
- fmc, lf-6.12.34-2.1.0
|
||||
|
||||
Build
|
||||
=====
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 658af40a90fd8e2460d364775a0c37e0507201e49de7f69c8a22d61e179f81e1 atf-lf-6.18.20-2.0.0.tar.gz
|
||||
sha256 2d3f9c52e16766c290bdc0bc130d634e4c326a5b236dfb2f2ca3f0fa457e82d4 atf-lf-6.12.34-2.1.0.tar.gz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally computed
|
||||
sha256 206f997d41bb958099bf7a89a02a6889942b118984f81f9a45bec9907f60708f linux-lf-6.18.20-2.0.0.tar.gz
|
||||
sha256 27a1987ca0a5802d3ebb296b8134ec66d813ad86cf2a60779b45092735bbb23b linux-lf-6.12.34-2.1.0.tar.gz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally computed
|
||||
sha256 04aed627132db7b656117c7a35fb29d314172319fa3a297ea6748eebac2b5ce3 u-boot-lf-6.18.20-2.0.0.tar.gz
|
||||
sha256 2f25cde388b2f83ff7a8e3afe25aafb1db48dafb0fa3bf1e4f9fef603f3b4785 u-boot-lf-6.12.34-2.1.0.tar.gz
|
||||
|
||||
@@ -11,7 +11,7 @@ for more details about the board and the QorIQ Layerscape SoC, see the following
|
||||
Layerscape platforms are officially supported by NXP under the Layerscape
|
||||
Debian Linux SDK (LDLSDK). This uses components from Linux Factory (project
|
||||
common with i.MX), but has a slower release cadence than LF. The currently used
|
||||
tag is lf-6.18.20-2.0.0, which is in line with the latest LF tag. Generally, in
|
||||
tag is lf-6.12.34-2.1.0, which is in line with the latest LF tag. Generally, in
|
||||
Buildroot, the latest Linux Factory release tag is always used, which may be
|
||||
considered pre-release software, as it may contain features which are not yet
|
||||
documented, and it generally undergoes less testing.
|
||||
@@ -21,13 +21,13 @@ For the software Layerscape Debian Linux SDK User Guide, see:
|
||||
- https://www.nxp.com/docs/en/user-guide/UG10143.pdf
|
||||
|
||||
The components from NXP are:
|
||||
- rcw, lf-6.18.20-2.0.0
|
||||
- atf (fork), lf-6.18.20-2.0.0
|
||||
- uboot (fork), lf-6.18.20-2.0.0
|
||||
- qoriq-fm-ucode (blob), lf-6.18.20-2.0.0
|
||||
- linux (fork), lf-6.18.20-2.0.0
|
||||
- fmlib, lf-6.18.20-2.0.0
|
||||
- fmc, lf-6.18.20-2.0.0
|
||||
- rcw, lf-6.12.34-2.1.0
|
||||
- atf (fork), lf-6.12.34-2.1.0
|
||||
- uboot (fork), lf-6.12.34-2.1.0
|
||||
- qoriq-fm-ucode (blob), lf-6.12.34-2.1.0
|
||||
- linux (fork), lf-6.12.34-2.1.0
|
||||
- fmlib, lf-6.12.34-2.1.0
|
||||
- fmc, lf-6.12.34-2.1.0
|
||||
|
||||
Build
|
||||
=====
|
||||
|
||||
@@ -5,7 +5,6 @@ CONFIG_SMP=y
|
||||
CONFIG_HYPERVISOR_GUEST=y
|
||||
CONFIG_PARAVIRT=y
|
||||
CONFIG_EFI=y
|
||||
CONFIG_EFI_STUB=y
|
||||
CONFIG_NET=y
|
||||
CONFIG_PACKET=y
|
||||
CONFIG_UNIX=y
|
||||
|
||||
@@ -1,3 +0,0 @@
|
||||
# Locally calculated
|
||||
sha256 3ab7e90d6fc3364815ad7770d7aa7af9cfd68edde43da7123f5f38f80e034c44 arm-trusted-firmware-lts-v2.12.1-git4.tar.gz
|
||||
sha256 b2c79635797bafcde84c6edadadde290b9d5e05deb3ea16a847210fd2ca83669 docs/license.rst
|
||||
@@ -1,7 +0,0 @@
|
||||
# From https://www.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
|
||||
sha256 067dadd445578284ea6158f312f7970d8940fed3e094dbe49cff66d188d3bda4 linux-6.18.32.tar.xz
|
||||
|
||||
# Locally calculated
|
||||
sha256 fb5a425bd3b3cd6071a3a9aff9909a859e7c1158d54d32e07658398cd67eb6a0 COPYING
|
||||
sha256 8780e78a1a737e127f25a65f6d95269bffd36158dc261114de7859b490bfc5aa LICENSES/preferred/GPL-2.0
|
||||
sha256 8e378ab93586eb55135d3bc119cce787f7324f48394777d00c34fa3d0be3303f LICENSES/exceptions/Linux-syscall-note
|
||||
@@ -1,3 +0,0 @@
|
||||
# Locally calculated
|
||||
sha256 ac7c04b8b7004923b00a4e5d6699c5df4d21233bac9fda690d8cfbc209fff2fd u-boot-2026.04.tar.bz2
|
||||
sha256 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643 Licenses/gpl-2.0.txt
|
||||
@@ -1,2 +0,0 @@
|
||||
# From https://www.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
|
||||
sha256 6f16ff302599f6fe34742890322cf0775703105fbd8767449682fca6af0fb782 linux-6.18.33.tar.xz
|
||||
@@ -1,2 +0,0 @@
|
||||
# Locally calculated
|
||||
sha256 ac7c04b8b7004923b00a4e5d6699c5df4d21233bac9fda690d8cfbc209fff2fd u-boot-2026.04.tar.bz2
|
||||
@@ -1,5 +1,5 @@
|
||||
CONFIG_SYS_TEXT_BASE=0x60000000
|
||||
CONFIG_BOOTCOMMAND="load hostfs - ${kernel_addr_r} zImage && load hostfs - ${ramdisk_addr_r} rootfs.cpio.uboot && setenv bootargs console=ttyAMA0,115200 earlyprintk=serial,ttyAMA0,115200 && bootz ${kernel_addr_r} ${ramdisk_addr_r} ${fdt_addr}"
|
||||
CONFIG_BOOTCOMMAND="smhload zImage ${kernel_addr_r} && smhload rootfs.cpio.uboot ${ramdisk_addr_r} && setenv bootargs console=ttyAMA0,115200 earlyprintk=serial,ttyAMA0,115200 && bootz ${kernel_addr_r} ${ramdisk_addr_r} ${fdt_addr}"
|
||||
CONFIG_SEMIHOSTING=y
|
||||
# Drop flash accesses
|
||||
CONFIG_ENV_IS_IN_FLASH=n
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
Run the emulation with:
|
||||
|
||||
qemu-system-microblaze -M petalogix-s3adsp1800,endianness=little -kernel output/images/linux.bin -serial stdio # qemu_microblazeel_mmu_defconfig
|
||||
qemu-system-microblazeel -M petalogix-s3adsp1800 -kernel output/images/linux.bin -serial stdio # qemu_microblazeel_mmu_defconfig
|
||||
|
||||
The login prompt will appear in the terminal that started Qemu.
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
# Locally calculated
|
||||
sha256 68e065413926778e276ec3abd28bb32fa82abaa4a6898d570c1f48fbdb08bcd0 u-boot-2022.04.tar.bz2
|
||||
sha256 b99611f1ed237bf3541bdc8434b68c96a6e05967061f992443cb30aabebef5b3 u-boot-2024.01.tar.bz2
|
||||
sha256 ac7c04b8b7004923b00a4e5d6699c5df4d21233bac9fda690d8cfbc209fff2fd u-boot-2026.04.tar.bz2
|
||||
|
||||
@@ -1,14 +0,0 @@
|
||||
Run the emulation with:
|
||||
|
||||
qemu-system-ppc64 \
|
||||
-M powernv10 \
|
||||
-kernel output/images/vmlinux \
|
||||
-append "console=hvc0 rootwait root=/dev/nvme0n1" \
|
||||
-device nvme,bus=pcie.3,addr=0x0,drive=drive0,serial=1234 \
|
||||
-drive file=output/images/rootfs.ext2,if=none,id=drive0,format=raw,cache=none \
|
||||
-device e1000e,netdev=net0,mac=C0:FF:EE:00:01:03,bus=pcie.1,addr=0x0 \
|
||||
-netdev user,id=net0 \
|
||||
-serial mon:stdio \
|
||||
-nographic # qemu_ppc64le_powernv10_defconfig
|
||||
|
||||
The login prompt will appear in the terminal window.
|
||||
@@ -1,14 +0,0 @@
|
||||
Run the emulation with:
|
||||
|
||||
qemu-system-ppc64 \
|
||||
-M powernv11 \
|
||||
-kernel output/images/vmlinux \
|
||||
-append "console=hvc0 rootwait root=/dev/nvme0n1" \
|
||||
-device nvme,bus=pcie.3,addr=0x0,drive=drive0,serial=1234 \
|
||||
-drive file=output/images/rootfs.ext2,if=none,id=drive0,format=raw,cache=none \
|
||||
-device e1000e,netdev=net0,mac=C0:FF:EE:00:01:03,bus=pcie.1,addr=0x0 \
|
||||
-netdev user,id=net0 \
|
||||
-serial mon:stdio \
|
||||
-nographic # qemu_ppc64le_powernv11_defconfig
|
||||
|
||||
The login prompt will appear in the terminal window.
|
||||
@@ -3,7 +3,6 @@ CONFIG_SMP=y
|
||||
CONFIG_HYPERVISOR_GUEST=y
|
||||
CONFIG_PARAVIRT=y
|
||||
CONFIG_EFI=y
|
||||
CONFIG_EFI_STUB=y
|
||||
# CONFIG_GCC_PLUGINS is not set
|
||||
CONFIG_MODULES=y
|
||||
CONFIG_MODULE_UNLOAD=y
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 a9e8c51fcb1e695d1d35dde5886cba579cb6f29c9646c5889f39d63841d4b9f6 linux-6.12.95.tar.xz
|
||||
sha256 c92591d896e79ecddbc3319136f0c2f855e832b397de7593f013ad7590a43e53 linux-6.12.80.tar.xz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 2ef152f25b682e59c3684d6d73d7c5a138495615f6b045e95266eb3d0bc0d04e optee-client-4.9.0.tar.gz
|
||||
sha256 a9a91bdb433df795c87a6d15198effbd648e3671ae611f2a3f8b41229d61cce0 optee-client-4.3.0.tar.gz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 9400e16c45bfa45f15585b2c933b86c449e7de05def0ecaaa62a4f38973a3a45 optee-os-4.9.0.tar.gz
|
||||
sha256 390b271905c828d6def9fa6a77bbaa425f3b434d733c8eb18f582ccbc6896096 optee-os-4.3.0.tar.gz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 78e8bfc382fe388f9b55aa1daf8c563522a037779b5d4c349d1415e381f1243e u-boot-2026.07.tar.bz2
|
||||
sha256 ac7c04b8b7004923b00a4e5d6699c5df4d21233bac9fda690d8cfbc209fff2fd u-boot-2026.04.tar.bz2
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 f6529bfe1a457adab69156fb7fa2232cc203eb63f5e46210f9953d6fc9f70a30 linux-6.1.177.tar.xz
|
||||
sha256 2818053c07976ba4ed5f44deb0f5dc7ae7b0975d7918c313d48d8fe7c4e598cb linux-6.1.167.tar.xz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 beb954e53617928b751944a89b6670bf9a9c7177c641b24c5dba504e46f1d961 linux-5.15.211.tar.xz
|
||||
sha256 0bc1bdf74957e276793691865ffb71505809706d9243a42e9704aad0f128cdd4 linux-5.15.202.tar.xz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 78e8bfc382fe388f9b55aa1daf8c563522a037779b5d4c349d1415e381f1243e u-boot-2026.07.tar.bz2
|
||||
sha256 ac7c04b8b7004923b00a4e5d6699c5df4d21233bac9fda690d8cfbc209fff2fd u-boot-2026.04.tar.bz2
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 beb954e53617928b751944a89b6670bf9a9c7177c641b24c5dba504e46f1d961 linux-5.15.211.tar.xz
|
||||
sha256 0bc1bdf74957e276793691865ffb71505809706d9243a42e9704aad0f128cdd4 linux-5.15.202.tar.xz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 78e8bfc382fe388f9b55aa1daf8c563522a037779b5d4c349d1415e381f1243e u-boot-2026.07.tar.bz2
|
||||
sha256 ac7c04b8b7004923b00a4e5d6699c5df4d21233bac9fda690d8cfbc209fff2fd u-boot-2026.04.tar.bz2
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 beb954e53617928b751944a89b6670bf9a9c7177c641b24c5dba504e46f1d961 linux-5.15.211.tar.xz
|
||||
sha256 0bc1bdf74957e276793691865ffb71505809706d9243a42e9704aad0f128cdd4 linux-5.15.202.tar.xz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 78e8bfc382fe388f9b55aa1daf8c563522a037779b5d4c349d1415e381f1243e u-boot-2026.07.tar.bz2
|
||||
sha256 ac7c04b8b7004923b00a4e5d6699c5df4d21233bac9fda690d8cfbc209fff2fd u-boot-2026.04.tar.bz2
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 a7a7e3d2ae9d95e74197223a8d4eb5f6be7aac21b6e6de27e9685d001c1f8cb0 linux-6.18.39.tar.xz
|
||||
sha256 1c38214fb137bae85b82b82537b5987358621b915ab2a8e4f09e60697c19474f linux-6.18.21.tar.xz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 78e8bfc382fe388f9b55aa1daf8c563522a037779b5d4c349d1415e381f1243e u-boot-2026.07.tar.bz2
|
||||
sha256 ac7c04b8b7004923b00a4e5d6699c5df4d21233bac9fda690d8cfbc209fff2fd u-boot-2026.04.tar.bz2
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 a9e8c51fcb1e695d1d35dde5886cba579cb6f29c9646c5889f39d63841d4b9f6 linux-6.12.95.tar.xz
|
||||
sha256 c92591d896e79ecddbc3319136f0c2f855e832b397de7593f013ad7590a43e53 linux-6.12.80.tar.xz
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 78e8bfc382fe388f9b55aa1daf8c563522a037779b5d4c349d1415e381f1243e u-boot-2026.07.tar.bz2
|
||||
sha256 ac7c04b8b7004923b00a4e5d6699c5df4d21233bac9fda690d8cfbc209fff2fd u-boot-2026.04.tar.bz2
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
# Locally calculated
|
||||
sha256 ea59fbfb702857a24f96ee8e9cf04f997942db1de98f8406b7daf9dcc8f4e9ea xlnx_rebase_v2.12_2025.2.tar.gz
|
||||
|
||||
# Locally calculated
|
||||
sha256 b2c79635797bafcde84c6edadadde290b9d5e05deb3ea16a847210fd2ca83669 docs/license.rst
|
||||
@@ -1,7 +1,7 @@
|
||||
# Locally calculated
|
||||
sha256 23c9cf18f5f419dfaafe5c3d3eda4812eb71bf1f2fbf3b35470478bbaa3d96bb xlnx_rebase_v6.18_LTS_2026.1.tar.gz
|
||||
sha256 002fa6c617d3d3eaf1e16219079f4e4303b84ea472b2b3c5d47f766a106a79c7 xlnx_rebase_v6.12_LTS_merge_6.12.70.tar.gz
|
||||
|
||||
# Locally calculated
|
||||
sha256 fb5a425bd3b3cd6071a3a9aff9909a859e7c1158d54d32e07658398cd67eb6a0 COPYING
|
||||
sha256 8780e78a1a737e127f25a65f6d95269bffd36158dc261114de7859b490bfc5aa LICENSES/preferred/GPL-2.0
|
||||
sha256 f6b78c087c3ebdf0f3c13415070dd480a3f35d8fc76f3d02180a407c1c812f79 LICENSES/preferred/GPL-2.0
|
||||
sha256 8e378ab93586eb55135d3bc119cce787f7324f48394777d00c34fa3d0be3303f LICENSES/exceptions/Linux-syscall-note
|
||||
2
board/xilinx/patches/optee-os/optee-os.hash
Normal file
2
board/xilinx/patches/optee-os/optee-os.hash
Normal file
@@ -0,0 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 3b8969a25815a0be84f34033827e5eb557e10f0f13ebabaee339461f8520ec72 xlnx_rebase_v4.5.0_2025.2.tar.gz
|
||||
2
board/xilinx/patches/uboot/uboot.hash
Normal file
2
board/xilinx/patches/uboot/uboot.hash
Normal file
@@ -0,0 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 8819cbebda739436d5d2fbdef578ec3c9b902f7edbe0ce4ed6f0ddf254fcf2a7 xlnx_rebase_v2025.01_2025.2.tar.gz
|
||||
@@ -1,5 +0,0 @@
|
||||
# Locally calculated
|
||||
sha256 6047af5f352fa7aaacd988a3fe0d018627dcc200dfdf93de0c0dc8072adef828 xlnx-rebase-v2.14_2026.1.tar.gz
|
||||
|
||||
# Locally calculated
|
||||
sha256 dbc8c4c1042f833ac961730cda41f87b6845068d9b5be2c90726504cfc82382e docs/license.rst
|
||||
@@ -1,2 +0,0 @@
|
||||
# Locally calculated
|
||||
sha256 0d33919008db24241580ac54c355d5c7efb18b089c2a7248704676a769790380 xlnx-rebase-v4.9.0_2026.1.tar.gz
|
||||
@@ -1,2 +0,0 @@
|
||||
# Locally calculated
|
||||
sha256 bc42689fffa878f9852120b167b871d8294697441cdd9f8347506a30d4024e8c xlnx-rebase-v2026.01_2026.1.tar.gz
|
||||
@@ -0,0 +1,37 @@
|
||||
From 4d4dae6a52b1749642261a15f5dcc1e3d4150b36 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Olivain <ju.o@free.fr>
|
||||
Date: Fri, 22 Dec 2023 19:02:53 +0100
|
||||
Subject: [PATCH] Add missing grub-core/extra_deps.lst file in release tarball
|
||||
|
||||
A file is missing in the grub-2.12 release tarballs (both .gz and .xz).
|
||||
See [1]. The issue was reported in [2] and fixed upstream in [3].
|
||||
|
||||
This patch adds the missing file, on top of the release tarball. This
|
||||
patch won't apply on upstream git, since the file is present in the
|
||||
source repository. Since the issue is fixed upstream in [3], it is
|
||||
expected upcoming releases tarballs will include the file.
|
||||
|
||||
The file content was fetched from the upstream git repo:
|
||||
https://git.savannah.gnu.org/gitweb/?p=grub.git;a=blob_plain;f=grub-core/extra_deps.lst;hb=refs/tags/grub-2.12
|
||||
|
||||
[1] https://ftp.gnu.org/gnu/grub/grub-2.12.tar.xz
|
||||
[2] https://lists.gnu.org/archive/html/grub-devel/2023-12/msg00054.html
|
||||
[3] https://git.savannah.gnu.org/gitweb/?p=grub.git;a=commit;h=b835601c7639ed1890f2d3db91900a8506011a8e
|
||||
|
||||
Signed-off-by: Julien Olivain <ju.o@free.fr>
|
||||
Upstream: Fixed by: https://git.savannah.gnu.org/gitweb/?p=grub.git;a=commit;h=b835601c7639ed1890f2d3db91900a8506011a8e
|
||||
---
|
||||
grub-core/extra_deps.lst | 1 +
|
||||
1 file changed, 1 insertion(+)
|
||||
create mode 100644 grub-core/extra_deps.lst
|
||||
|
||||
diff --git a/grub-core/extra_deps.lst b/grub-core/extra_deps.lst
|
||||
new file mode 100644
|
||||
index 0000000..f44ad6a
|
||||
--- /dev/null
|
||||
+++ b/grub-core/extra_deps.lst
|
||||
@@ -0,0 +1 @@
|
||||
+depends bli part_gpt
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,75 +0,0 @@
|
||||
From 3a9d2dd2f5fb07b75a74c307d61b9b9fc5d20a62 Mon Sep 17 00:00:00 2001
|
||||
From: Yi Zhao <yi.zhao@windriver.com>
|
||||
Date: Fri, 27 Feb 2026 11:46:54 +0800
|
||||
Subject: [PATCH] Revert "configure: Check linker for --image-base support"
|
||||
|
||||
This reverts commit 1a5417f39a0ccefcdd5440f2a67f84d2d2e26960.
|
||||
|
||||
Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
|
||||
Upstream: temporary revert, until upstream fixes the issue, see
|
||||
discussion at
|
||||
https://lists.gnu.org/archive/html/grub-devel/2026-02/msg00039.html
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
acinclude.m4 | 5 -----
|
||||
configure.ac | 14 ++------------
|
||||
2 files changed, 2 insertions(+), 17 deletions(-)
|
||||
|
||||
diff --git a/acinclude.m4 b/acinclude.m4
|
||||
index 70c1912f8..fa7840f09 100644
|
||||
--- a/acinclude.m4
|
||||
+++ b/acinclude.m4
|
||||
@@ -79,11 +79,6 @@ AC_DEFUN([grub_PROG_OBJCOPY_ABSOLUTE],
|
||||
[AC_MSG_CHECKING([whether ${TARGET_OBJCOPY} works for absolute addresses])
|
||||
AC_CACHE_VAL(grub_cv_prog_objcopy_absolute,
|
||||
[cat > conftest.c <<\EOF
|
||||
-asm (
|
||||
- ".globl start, _start, __start\n"
|
||||
- ".ifdef cmain; .set start = _start = __start = cmain\n.endif\n"
|
||||
- ".ifdef _cmain; .set start = _start = __start = _cmain\n.endif\n"
|
||||
-);
|
||||
void cmain (void);
|
||||
void
|
||||
cmain (void)
|
||||
diff --git a/configure.ac b/configure.ac
|
||||
index d8ca1b7c1..041cfbab4 100644
|
||||
--- a/configure.ac
|
||||
+++ b/configure.ac
|
||||
@@ -1461,6 +1461,7 @@ elif test x$grub_cv_target_cc_link_format = x-mi386pe || test x$grub_cv_target_c
|
||||
TARGET_IMG_LDSCRIPT='$(top_srcdir)'"/conf/i386-cygwin-img-ld.sc"
|
||||
TARGET_IMG_LDFLAGS="-Wl,-T${TARGET_IMG_LDSCRIPT}"
|
||||
TARGET_IMG_LDFLAGS_AC="-Wl,-T${srcdir}/conf/i386-cygwin-img-ld.sc"
|
||||
+ TARGET_IMG_BASE_LDOPT="-Wl,-Ttext"
|
||||
TARGET_IMG_CFLAGS=
|
||||
else
|
||||
TARGET_APPLE_LINKER=0
|
||||
@@ -1468,6 +1469,7 @@ else
|
||||
TARGET_IMG_LDSCRIPT=
|
||||
TARGET_IMG_LDFLAGS='-Wl,-N'
|
||||
TARGET_IMG_LDFLAGS_AC='-Wl,-N'
|
||||
+ TARGET_IMG_BASE_LDOPT="-Wl,-Ttext"
|
||||
TARGET_IMG_CFLAGS=
|
||||
fi
|
||||
|
||||
@@ -1798,18 +1800,6 @@ grub_PROG_TARGET_CC
|
||||
m4_ifndef([AX_CHECK_LINK_FLAG], [m4_fatal([autoconf-archive is missing. You must install it to generate the configure script.])])
|
||||
|
||||
if test "x$TARGET_APPLE_LINKER" != x1 ; then
|
||||
-AX_CHECK_LINK_FLAG([-Wl,--image-base,0x400000],
|
||||
- [TARGET_IMG_BASE_LDOPT="-Wl,--image-base"],
|
||||
- [TARGET_IMG_BASE_LDOPT="-Wl,-Ttext"],
|
||||
- [],
|
||||
- [AC_LANG_SOURCE([
|
||||
-asm (".globl start; start:");
|
||||
-asm (".globl _start; _start:");
|
||||
-asm (".globl __start; __start:");
|
||||
-void __main (void);
|
||||
-void __main (void) {}
|
||||
-int main (void);
|
||||
- ])])
|
||||
grub_PROG_OBJCOPY_ABSOLUTE
|
||||
fi
|
||||
grub_PROG_LD_BUILD_ID_NONE
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,36 +0,0 @@
|
||||
From d0f516385dc73e8dd92b78ce08c1df100434fe67 Mon Sep 17 00:00:00 2001
|
||||
From: Yi Zhao <yi.zhao@windriver.com>
|
||||
Date: Fri, 27 Feb 2026 13:58:44 +0800
|
||||
Subject: [PATCH] Revert "configure: Print a more helpful error if
|
||||
autoconf-archive is not installed"
|
||||
|
||||
This reverts commit ac042f3f58d33ce9cd5ff61750f06da1a1d7b0eb.
|
||||
|
||||
Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
|
||||
Upstream: temporary revert, until upstream fixes the issue, see
|
||||
discussion at
|
||||
https://lists.gnu.org/archive/html/grub-devel/2026-02/msg00039.html
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
configure.ac | 5 -----
|
||||
1 file changed, 5 deletions(-)
|
||||
|
||||
diff --git a/configure.ac b/configure.ac
|
||||
index 041cfbab4..209c0fb11 100644
|
||||
--- a/configure.ac
|
||||
+++ b/configure.ac
|
||||
@@ -1794,11 +1794,6 @@ LIBS=""
|
||||
# Defined in acinclude.m4.
|
||||
grub_ASM_USCORE
|
||||
grub_PROG_TARGET_CC
|
||||
-
|
||||
-# The error message produced by autoconf if autoconf-archive is not installed is
|
||||
-# quite misleading and not very helpful. So, try point people in the right direction.
|
||||
-m4_ifndef([AX_CHECK_LINK_FLAG], [m4_fatal([autoconf-archive is missing. You must install it to generate the configure script.])])
|
||||
-
|
||||
if test "x$TARGET_APPLE_LINKER" != x1 ; then
|
||||
grub_PROG_OBJCOPY_ABSOLUTE
|
||||
fi
|
||||
--
|
||||
2.43.0
|
||||
|
||||
70
boot/grub2/0002-misc-Implement-grub_strlcpy.patch
Normal file
70
boot/grub2/0002-misc-Implement-grub_strlcpy.patch
Normal file
@@ -0,0 +1,70 @@
|
||||
From 67241595d3dae392589ee74b65cd40ea090d1837 Mon Sep 17 00:00:00 2001
|
||||
From: B Horn <b@horn.uk>
|
||||
Date: Sat, 15 Jun 2024 02:33:08 +0100
|
||||
Subject: [PATCH] misc: Implement grub_strlcpy()
|
||||
|
||||
grub_strlcpy() acts the same way as strlcpy() does on most *NIX,
|
||||
returning the length of src and ensuring dest is always NUL
|
||||
terminated except when size is 0.
|
||||
|
||||
Signed-off-by: B Horn <b@horn.uk>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: ea703528a8581a2ea7e0bad424a70fdf0aec7d8f
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
include/grub/misc.h | 39 +++++++++++++++++++++++++++++++++++++++
|
||||
1 file changed, 39 insertions(+)
|
||||
|
||||
diff --git a/include/grub/misc.h b/include/grub/misc.h
|
||||
index 1b35a167f..103175480 100644
|
||||
--- a/include/grub/misc.h
|
||||
+++ b/include/grub/misc.h
|
||||
@@ -64,6 +64,45 @@ grub_stpcpy (char *dest, const char *src)
|
||||
return d - 1;
|
||||
}
|
||||
|
||||
+static inline grub_size_t
|
||||
+grub_strlcpy (char *dest, const char *src, grub_size_t size)
|
||||
+{
|
||||
+ char *d = dest;
|
||||
+ grub_size_t res = 0;
|
||||
+ /*
|
||||
+ * We do not subtract one from size here to avoid dealing with underflowing
|
||||
+ * the value, which is why to_copy is always checked to be greater than one
|
||||
+ * throughout this function.
|
||||
+ */
|
||||
+ grub_size_t to_copy = size;
|
||||
+
|
||||
+ /* Copy size - 1 bytes to dest. */
|
||||
+ if (to_copy > 1)
|
||||
+ while ((*d++ = *src++) != '\0' && ++res && --to_copy > 1)
|
||||
+ ;
|
||||
+
|
||||
+ /*
|
||||
+ * NUL terminate if size != 0. The previous step may have copied a NUL byte
|
||||
+ * if it reached the end of the string, but we know dest[size - 1] must always
|
||||
+ * be a NUL byte.
|
||||
+ */
|
||||
+ if (size != 0)
|
||||
+ dest[size - 1] = '\0';
|
||||
+
|
||||
+ /* If there is still space in dest, but are here, we reached the end of src. */
|
||||
+ if (to_copy > 1)
|
||||
+ return res;
|
||||
+
|
||||
+ /*
|
||||
+ * If we haven't reached the end of the string, iterate through to determine
|
||||
+ * the strings total length.
|
||||
+ */
|
||||
+ while (*src++ != '\0' && ++res)
|
||||
+ ;
|
||||
+
|
||||
+ return res;
|
||||
+}
|
||||
+
|
||||
/* XXX: If grub_memmove is too slow, we must implement grub_memcpy. */
|
||||
static inline void *
|
||||
grub_memcpy (void *dest, const void *src, grub_size_t n)
|
||||
--
|
||||
2.50.1
|
||||
|
||||
36
boot/grub2/0003-fs-ufs-Fix-a-heap-OOB-write.patch
Normal file
36
boot/grub2/0003-fs-ufs-Fix-a-heap-OOB-write.patch
Normal file
@@ -0,0 +1,36 @@
|
||||
From ab0f52dadcda56782b3e82be0b15fa6eb0e9cee1 Mon Sep 17 00:00:00 2001
|
||||
From: B Horn <b@horn.uk>
|
||||
Date: Sun, 12 May 2024 02:03:33 +0100
|
||||
Subject: [PATCH] fs/ufs: Fix a heap OOB write
|
||||
|
||||
grub_strcpy() was used to copy a symlink name from the filesystem
|
||||
image to a heap allocated buffer. This led to a OOB write to adjacent
|
||||
heap allocations. Fix by using grub_strlcpy().
|
||||
|
||||
Fixes: CVE-2024-45781
|
||||
|
||||
Reported-by: B Horn <b@horn.uk>
|
||||
Signed-off-by: B Horn <b@horn.uk>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: c1a291b01f4f1dcd6a22b61f1c81a45a966d16ba
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/fs/ufs.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/grub-core/fs/ufs.c b/grub-core/fs/ufs.c
|
||||
index a354c92d9..01235101b 100644
|
||||
--- a/grub-core/fs/ufs.c
|
||||
+++ b/grub-core/fs/ufs.c
|
||||
@@ -463,7 +463,7 @@ grub_ufs_lookup_symlink (struct grub_ufs_data *data, int ino)
|
||||
/* Check against zero is paylindromic, no need to swap. */
|
||||
if (data->inode.nblocks == 0
|
||||
&& INODE_SIZE (data) <= sizeof (data->inode.symlink))
|
||||
- grub_strcpy (symlink, (char *) data->inode.symlink);
|
||||
+ grub_strlcpy (symlink, (char *) data->inode.symlink, sz);
|
||||
else
|
||||
{
|
||||
if (grub_ufs_read_file (data, 0, 0, 0, sz, symlink) < 0)
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,36 @@
|
||||
From 157e6e2a3da139dc2e08cf41b49115965cdaa1d3 Mon Sep 17 00:00:00 2001
|
||||
From: B Horn <b@horn.uk>
|
||||
Date: Sun, 12 May 2024 02:48:33 +0100
|
||||
Subject: [PATCH] fs/hfs: Fix stack OOB write with grub_strcpy()
|
||||
|
||||
Replaced with grub_strlcpy().
|
||||
|
||||
CVE: CVE-2024-45782
|
||||
CVE: CVE-2024-56737
|
||||
Fixes: https://savannah.gnu.org/bugs/?66599
|
||||
|
||||
Reported-by: B Horn <b@horn.uk>
|
||||
Signed-off-by: B Horn <b@horn.uk>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: 417547c10410b714e43f08f74137c24015f8f4c3
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/fs/hfs.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/grub-core/fs/hfs.c b/grub-core/fs/hfs.c
|
||||
index 91dc0e69c..920112b03 100644
|
||||
--- a/grub-core/fs/hfs.c
|
||||
+++ b/grub-core/fs/hfs.c
|
||||
@@ -379,7 +379,7 @@ grub_hfs_mount (grub_disk_t disk)
|
||||
volume name. */
|
||||
key.parent_dir = grub_cpu_to_be32_compile_time (1);
|
||||
key.strlen = data->sblock.volname[0];
|
||||
- grub_strcpy ((char *) key.str, (char *) (data->sblock.volname + 1));
|
||||
+ grub_strlcpy ((char *) key.str, (char *) (data->sblock.volname + 1), sizeof (key.str));
|
||||
|
||||
if (grub_hfs_find_node (data, (char *) &key, data->cat_root,
|
||||
0, (char *) &dir, sizeof (dir)) == 0)
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,45 @@
|
||||
From 2233c409ada20d1ab4a6a00a50cdde35e5a36589 Mon Sep 17 00:00:00 2001
|
||||
From: B Horn <b@horn.uk>
|
||||
Date: Sun, 12 May 2024 02:47:54 +0100
|
||||
Subject: [PATCH] fs/tar: Initialize name in grub_cpio_find_file()
|
||||
|
||||
It was possible to iterate through grub_cpio_find_file() without
|
||||
allocating name and not setting mode to GRUB_ARCHELP_ATTR_END, which
|
||||
would cause the uninitialized value for name to be used as an argument
|
||||
for canonicalize() in grub_archelp_dir().
|
||||
|
||||
Reported-by: B Horn <b@horn.uk>
|
||||
Signed-off-by: B Horn <b@horn.uk>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: 2c8ac08c99466c0697f704242363fc687f492a0d
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/fs/tar.c | 5 +++++
|
||||
1 file changed, 5 insertions(+)
|
||||
|
||||
diff --git a/grub-core/fs/tar.c b/grub-core/fs/tar.c
|
||||
index c551ed6b5..646bce5eb 100644
|
||||
--- a/grub-core/fs/tar.c
|
||||
+++ b/grub-core/fs/tar.c
|
||||
@@ -78,6 +78,7 @@ grub_cpio_find_file (struct grub_archelp_data *data, char **name,
|
||||
int reread = 0, have_longname = 0, have_longlink = 0;
|
||||
|
||||
data->hofs = data->next_hofs;
|
||||
+ *name = NULL;
|
||||
|
||||
for (reread = 0; reread < 3; reread++)
|
||||
{
|
||||
@@ -202,6 +203,10 @@ grub_cpio_find_file (struct grub_archelp_data *data, char **name,
|
||||
}
|
||||
return GRUB_ERR_NONE;
|
||||
}
|
||||
+
|
||||
+ if (*name == NULL)
|
||||
+ return grub_error (GRUB_ERR_BAD_FS, "invalid tar archive");
|
||||
+
|
||||
return GRUB_ERR_NONE;
|
||||
}
|
||||
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,94 @@
|
||||
From 472e180b6aac8cb4f25affa687e68f9be4e3df79 Mon Sep 17 00:00:00 2001
|
||||
From: Lidong Chen <lidong.chen@oracle.com>
|
||||
Date: Fri, 22 Nov 2024 06:27:58 +0000
|
||||
Subject: [PATCH] fs/tar: Integer overflow leads to heap OOB write
|
||||
|
||||
Both namesize and linksize are derived from hd.size, a 12-digit octal
|
||||
number parsed by read_number(). Later direct arithmetic calculation like
|
||||
"namesize + 1" and "linksize + 1" may exceed the maximum value of
|
||||
grub_size_t leading to heap OOB write. This patch fixes the issue by
|
||||
using grub_add() and checking for an overflow.
|
||||
|
||||
CVE: CVE-2024-45780
|
||||
|
||||
Reported-by: Nils Langius <nils@langius.de>
|
||||
Signed-off-by: Lidong Chen <lidong.chen@oracle.com>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Reviewed-by: Alec Brown <alec.r.brown@oracle.com>
|
||||
Upstream: 0087bc6902182fe5cedce2d034c75a79cf6dd4f3
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/fs/tar.c | 23 ++++++++++++++++++-----
|
||||
1 file changed, 18 insertions(+), 5 deletions(-)
|
||||
|
||||
diff --git a/grub-core/fs/tar.c b/grub-core/fs/tar.c
|
||||
index 646bce5eb..386c09022 100644
|
||||
--- a/grub-core/fs/tar.c
|
||||
+++ b/grub-core/fs/tar.c
|
||||
@@ -25,6 +25,7 @@
|
||||
#include <grub/mm.h>
|
||||
#include <grub/dl.h>
|
||||
#include <grub/i18n.h>
|
||||
+#include <grub/safemath.h>
|
||||
|
||||
GRUB_MOD_LICENSE ("GPLv3+");
|
||||
|
||||
@@ -76,6 +77,7 @@ grub_cpio_find_file (struct grub_archelp_data *data, char **name,
|
||||
{
|
||||
struct head hd;
|
||||
int reread = 0, have_longname = 0, have_longlink = 0;
|
||||
+ grub_size_t sz;
|
||||
|
||||
data->hofs = data->next_hofs;
|
||||
*name = NULL;
|
||||
@@ -98,7 +100,11 @@ grub_cpio_find_file (struct grub_archelp_data *data, char **name,
|
||||
{
|
||||
grub_err_t err;
|
||||
grub_size_t namesize = read_number (hd.size, sizeof (hd.size));
|
||||
- *name = grub_malloc (namesize + 1);
|
||||
+
|
||||
+ if (grub_add (namesize, 1, &sz))
|
||||
+ return grub_error (GRUB_ERR_BAD_FS, N_("name size overflow"));
|
||||
+
|
||||
+ *name = grub_malloc (sz);
|
||||
if (*name == NULL)
|
||||
return grub_errno;
|
||||
err = grub_disk_read (data->disk, 0,
|
||||
@@ -118,15 +124,19 @@ grub_cpio_find_file (struct grub_archelp_data *data, char **name,
|
||||
{
|
||||
grub_err_t err;
|
||||
grub_size_t linksize = read_number (hd.size, sizeof (hd.size));
|
||||
- if (data->linkname_alloc < linksize + 1)
|
||||
+
|
||||
+ if (grub_add (linksize, 1, &sz))
|
||||
+ return grub_error (GRUB_ERR_BAD_FS, N_("link size overflow"));
|
||||
+
|
||||
+ if (data->linkname_alloc < sz)
|
||||
{
|
||||
char *n;
|
||||
- n = grub_calloc (2, linksize + 1);
|
||||
+ n = grub_calloc (2, sz);
|
||||
if (!n)
|
||||
return grub_errno;
|
||||
grub_free (data->linkname);
|
||||
data->linkname = n;
|
||||
- data->linkname_alloc = 2 * (linksize + 1);
|
||||
+ data->linkname_alloc = 2 * (sz);
|
||||
}
|
||||
|
||||
err = grub_disk_read (data->disk, 0,
|
||||
@@ -149,7 +159,10 @@ grub_cpio_find_file (struct grub_archelp_data *data, char **name,
|
||||
while (extra_size < sizeof (hd.prefix)
|
||||
&& hd.prefix[extra_size])
|
||||
extra_size++;
|
||||
- *name = grub_malloc (sizeof (hd.name) + extra_size + 2);
|
||||
+
|
||||
+ if (grub_add (sizeof (hd.name) + 2, extra_size, &sz))
|
||||
+ return grub_error (GRUB_ERR_BAD_FS, N_("long name size overflow"));
|
||||
+ *name = grub_malloc (sz);
|
||||
if (*name == NULL)
|
||||
return grub_errno;
|
||||
if (hd.prefix[0])
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,36 @@
|
||||
From 95f391673c0a08c2410454536614ef543cac6629 Mon Sep 17 00:00:00 2001
|
||||
From: B Horn <b@horn.uk>
|
||||
Date: Sun, 12 May 2024 06:15:03 +0100
|
||||
Subject: [PATCH] fs/f2fs: Set a grub_errno if mount fails
|
||||
|
||||
It was previously possible for grub_errno to not be set when
|
||||
grub_f2fs_mount() failed if nat_bitmap_ptr() returned NULL.
|
||||
|
||||
This issue is solved by ensuring a grub_errno is set in the fail case.
|
||||
|
||||
Reported-by: B Horn <b@horn.uk>
|
||||
Signed-off-by: B Horn <b@horn.uk>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: 563436258cde64da6b974880abff1bf0959f4da3
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/fs/f2fs.c | 3 +++
|
||||
1 file changed, 3 insertions(+)
|
||||
|
||||
diff --git a/grub-core/fs/f2fs.c b/grub-core/fs/f2fs.c
|
||||
index 855e24618..db8a65f8d 100644
|
||||
--- a/grub-core/fs/f2fs.c
|
||||
+++ b/grub-core/fs/f2fs.c
|
||||
@@ -872,6 +872,9 @@ grub_f2fs_mount (grub_disk_t disk)
|
||||
return data;
|
||||
|
||||
fail:
|
||||
+ if (grub_errno == GRUB_ERR_NONE)
|
||||
+ grub_error (GRUB_ERR_BAD_FS, "not a F2FS filesystem");
|
||||
+
|
||||
grub_free (data);
|
||||
|
||||
return NULL;
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,40 @@
|
||||
From 947e9e98d35edd7b359498b5f31338dc228f5081 Mon Sep 17 00:00:00 2001
|
||||
From: B Horn <b@horn.uk>
|
||||
Date: Sun, 12 May 2024 06:22:51 +0100
|
||||
Subject: [PATCH] fs/hfsplus: Set a grub_errno if mount fails
|
||||
|
||||
It was possible for mount to fail but not set grub_errno. This led to
|
||||
a possible double decrement of the module reference count if the NULL
|
||||
page was mapped.
|
||||
|
||||
Fixing in general as a similar bug was fixed in commit 61b13c187
|
||||
(fs/hfsplus: Set grub_errno to prevent NULL pointer access) and there
|
||||
are likely more variants around.
|
||||
|
||||
Fixes: CVE-2024-45783
|
||||
|
||||
Reported-by: B Horn <b@horn.uk>
|
||||
Signed-off-by: B Horn <b@horn.uk>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: f7c070a2e28dfab7137db0739fb8db1dc02d8898
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/fs/hfsplus.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/grub-core/fs/hfsplus.c b/grub-core/fs/hfsplus.c
|
||||
index 295822f69..de71fd486 100644
|
||||
--- a/grub-core/fs/hfsplus.c
|
||||
+++ b/grub-core/fs/hfsplus.c
|
||||
@@ -405,7 +405,7 @@ grub_hfsplus_mount (grub_disk_t disk)
|
||||
|
||||
fail:
|
||||
|
||||
- if (grub_errno == GRUB_ERR_OUT_OF_RANGE)
|
||||
+ if (grub_errno == GRUB_ERR_OUT_OF_RANGE || grub_errno == GRUB_ERR_NONE)
|
||||
grub_error (GRUB_ERR_BAD_FS, "not a HFS+ filesystem");
|
||||
|
||||
grub_free (data);
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
From a0e37c98e6f330110e4009f8e5ba73ca0c2eaff5 Mon Sep 17 00:00:00 2001
|
||||
From: B Horn <b@horn.uk>
|
||||
Date: Sun, 12 May 2024 06:37:08 +0100
|
||||
Subject: [PATCH] fs/iso9660: Set a grub_errno if mount fails
|
||||
|
||||
It was possible for a grub_errno to not be set if mount of an ISO 9660
|
||||
filesystem failed when set_rockridge() returned 0.
|
||||
|
||||
This isn't known to be exploitable as the other filesystems due to
|
||||
filesystem helper checking the requested file type. Though fixing
|
||||
as a precaution.
|
||||
|
||||
Reported-by: B Horn <b@horn.uk>
|
||||
Signed-off-by: B Horn <b@horn.uk>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: 965db5970811d18069b34f28f5f31ddadde90a97
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/fs/iso9660.c | 3 +++
|
||||
1 file changed, 3 insertions(+)
|
||||
|
||||
diff --git a/grub-core/fs/iso9660.c b/grub-core/fs/iso9660.c
|
||||
index 8c348b59a..8d480e602 100644
|
||||
--- a/grub-core/fs/iso9660.c
|
||||
+++ b/grub-core/fs/iso9660.c
|
||||
@@ -551,6 +551,9 @@ grub_iso9660_mount (grub_disk_t disk)
|
||||
return data;
|
||||
|
||||
fail:
|
||||
+ if (grub_errno == GRUB_ERR_NONE)
|
||||
+ grub_error (GRUB_ERR_BAD_FS, "not a ISO9660 filesystem");
|
||||
+
|
||||
grub_free (data);
|
||||
return 0;
|
||||
}
|
||||
--
|
||||
2.50.1
|
||||
|
||||
55
boot/grub2/0010-fs-iso9660-Fix-invalid-free.patch
Normal file
55
boot/grub2/0010-fs-iso9660-Fix-invalid-free.patch
Normal file
@@ -0,0 +1,55 @@
|
||||
From 3acd964eafdd32e8ab7d7c04b18171052a859d3a Mon Sep 17 00:00:00 2001
|
||||
From: Michael Chang <mchang@suse.com>
|
||||
Date: Fri, 31 May 2024 15:14:42 +0800
|
||||
Subject: [PATCH] fs/iso9660: Fix invalid free
|
||||
|
||||
The ctx->filename can point to either a string literal or a dynamically
|
||||
allocated string. The ctx->filename_alloc field is used to indicate the
|
||||
type of allocation.
|
||||
|
||||
An issue has been identified where ctx->filename is reassigned to
|
||||
a string literal in susp_iterate_dir() but ctx->filename_alloc is not
|
||||
correctly handled. This oversight causes a memory leak and an invalid
|
||||
free operation later.
|
||||
|
||||
The fix involves checking ctx->filename_alloc, freeing the allocated
|
||||
string if necessary and clearing ctx->filename_alloc for string literals.
|
||||
|
||||
Reported-by: Daniel Axtens <dja@axtens.net>
|
||||
Signed-off-by: Michael Chang <mchang@suse.com>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: 1443833a9535a5873f7de3798cf4d8389f366611
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/fs/iso9660.c | 14 ++++++++++++--
|
||||
1 file changed, 12 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/grub-core/fs/iso9660.c b/grub-core/fs/iso9660.c
|
||||
index 8d480e602..8e3c95c4f 100644
|
||||
--- a/grub-core/fs/iso9660.c
|
||||
+++ b/grub-core/fs/iso9660.c
|
||||
@@ -628,9 +628,19 @@ susp_iterate_dir (struct grub_iso9660_susp_entry *entry,
|
||||
filename type is stored. */
|
||||
/* FIXME: Fix this slightly improper cast. */
|
||||
if (entry->data[0] & GRUB_ISO9660_RR_DOT)
|
||||
- ctx->filename = (char *) ".";
|
||||
+ {
|
||||
+ if (ctx->filename_alloc)
|
||||
+ grub_free (ctx->filename);
|
||||
+ ctx->filename_alloc = 0;
|
||||
+ ctx->filename = (char *) ".";
|
||||
+ }
|
||||
else if (entry->data[0] & GRUB_ISO9660_RR_DOTDOT)
|
||||
- ctx->filename = (char *) "..";
|
||||
+ {
|
||||
+ if (ctx->filename_alloc)
|
||||
+ grub_free (ctx->filename);
|
||||
+ ctx->filename_alloc = 0;
|
||||
+ ctx->filename = (char *) "..";
|
||||
+ }
|
||||
else if (entry->len >= 5)
|
||||
{
|
||||
grub_size_t off = 0, csize = 1;
|
||||
--
|
||||
2.50.1
|
||||
|
||||
68
boot/grub2/0011-fs-jfs-Fix-OOB-read-in-jfs_getent.patch
Normal file
68
boot/grub2/0011-fs-jfs-Fix-OOB-read-in-jfs_getent.patch
Normal file
@@ -0,0 +1,68 @@
|
||||
From b01accc4d132a252f02bf57c31f5fff8ce98a339 Mon Sep 17 00:00:00 2001
|
||||
From: Lidong Chen <lidong.chen@oracle.com>
|
||||
Date: Fri, 22 Nov 2024 06:27:59 +0000
|
||||
Subject: [PATCH] fs/jfs: Fix OOB read in jfs_getent()
|
||||
|
||||
The JFS fuzzing revealed an OOB read in grub_jfs_getent(). The crash
|
||||
was caused by an invalid leaf nodes count, diro->dirpage->header.count,
|
||||
which was larger than the maximum number of leaf nodes allowed in an
|
||||
inode. This fix is to ensure that the leaf nodes count is validated in
|
||||
grub_jfs_opendir() before calling grub_jfs_getent().
|
||||
|
||||
On the occasion replace existing raw numbers with newly defined constant.
|
||||
|
||||
Signed-off-by: Lidong Chen <lidong.chen@oracle.com>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Reviewed-by: Alec Brown <alec.r.brown@oracle.com>
|
||||
Upstream: 66175696f3a385b14bdf1ebcda7755834bd2d5fb
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/fs/jfs.c | 17 +++++++++++++++--
|
||||
1 file changed, 15 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/grub-core/fs/jfs.c b/grub-core/fs/jfs.c
|
||||
index 6f7c43904..32dec7fb7 100644
|
||||
--- a/grub-core/fs/jfs.c
|
||||
+++ b/grub-core/fs/jfs.c
|
||||
@@ -41,6 +41,12 @@ GRUB_MOD_LICENSE ("GPLv3+");
|
||||
|
||||
#define GRUB_JFS_TREE_LEAF 2
|
||||
|
||||
+/*
|
||||
+ * Define max entries stored in-line in an inode.
|
||||
+ * https://jfs.sourceforge.net/project/pub/jfslayout.pdf
|
||||
+ */
|
||||
+#define GRUB_JFS_INODE_INLINE_ENTRIES 8
|
||||
+
|
||||
struct grub_jfs_sblock
|
||||
{
|
||||
/* The magic for JFS. It should contain the string "JFS1". */
|
||||
@@ -203,9 +209,9 @@ struct grub_jfs_inode
|
||||
grub_uint8_t freecnt;
|
||||
grub_uint8_t freelist;
|
||||
grub_uint32_t idotdot;
|
||||
- grub_uint8_t sorted[8];
|
||||
+ grub_uint8_t sorted[GRUB_JFS_INODE_INLINE_ENTRIES];
|
||||
} header;
|
||||
- struct grub_jfs_leaf_dirent dirents[8];
|
||||
+ struct grub_jfs_leaf_dirent dirents[GRUB_JFS_INODE_INLINE_ENTRIES];
|
||||
} GRUB_PACKED dir;
|
||||
/* Fast symlink. */
|
||||
struct
|
||||
@@ -453,6 +459,13 @@ grub_jfs_opendir (struct grub_jfs_data *data, struct grub_jfs_inode *inode)
|
||||
/* Check if the entire tree is contained within the inode. */
|
||||
if (inode->file.tree.flags & GRUB_JFS_TREE_LEAF)
|
||||
{
|
||||
+ if (inode->dir.header.count > GRUB_JFS_INODE_INLINE_ENTRIES)
|
||||
+ {
|
||||
+ grub_free (diro);
|
||||
+ grub_error (GRUB_ERR_BAD_FS, N_("invalid JFS inode"));
|
||||
+ return 0;
|
||||
+ }
|
||||
+
|
||||
diro->leaf = inode->dir.dirents;
|
||||
diro->next_leaf = (struct grub_jfs_leaf_next_dirent *) de;
|
||||
diro->sorted = inode->dir.header.sorted;
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,69 @@
|
||||
From b35b73b9d779e88fb4e6f53fb10a5bfebf3475aa Mon Sep 17 00:00:00 2001
|
||||
From: Lidong Chen <lidong.chen@oracle.com>
|
||||
Date: Fri, 22 Nov 2024 06:28:00 +0000
|
||||
Subject: [PATCH] fs/jfs: Fix OOB read caused by invalid dir slot index
|
||||
|
||||
While fuzz testing JFS with ASAN enabled an OOB read was detected in
|
||||
grub_jfs_opendir(). The issue occurred due to an invalid directory slot
|
||||
index in the first entry of the sorted directory slot array in the inode
|
||||
directory header. The fix ensures the slot index is validated before
|
||||
accessing it. Given that an internal or a leaf node in a directory B+
|
||||
tree is a 4 KiB in size and each directory slot is always 32 bytes, the
|
||||
max number of slots in a node is 128. The validation ensures that the
|
||||
slot index doesn't exceed this limit.
|
||||
|
||||
[1] https://jfs.sourceforge.net/project/pub/jfslayout.pdf
|
||||
|
||||
JFS will allocate 4K of disk space for an internal node of the B+ tree.
|
||||
An internal node looks the same as a leaf node.
|
||||
- page 10
|
||||
|
||||
Fixed number of Directory Slots depending on the size of the node. These are
|
||||
the slots to be used for storing the directory slot array and the directory
|
||||
entries or router entries. A directory slot is always 32 bytes.
|
||||
...
|
||||
A Directory Slot Array which is a sorted array of indices to the directory
|
||||
slots that are currently in use.
|
||||
...
|
||||
An internal or a leaf node in the directory B+ tree is a 4K page.
|
||||
- page 25
|
||||
|
||||
Signed-off-by: Lidong Chen <lidong.chen@oracle.com>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Reviewed-by: Alec Brown <alec.r.brown@oracle.com>
|
||||
Upstream: ab09fd0531f3523ac0ef833404526c98c08248f7
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/fs/jfs.c | 9 +++++++++
|
||||
1 file changed, 9 insertions(+)
|
||||
|
||||
diff --git a/grub-core/fs/jfs.c b/grub-core/fs/jfs.c
|
||||
index 32dec7fb7..88fb884df 100644
|
||||
--- a/grub-core/fs/jfs.c
|
||||
+++ b/grub-core/fs/jfs.c
|
||||
@@ -46,6 +46,7 @@ GRUB_MOD_LICENSE ("GPLv3+");
|
||||
* https://jfs.sourceforge.net/project/pub/jfslayout.pdf
|
||||
*/
|
||||
#define GRUB_JFS_INODE_INLINE_ENTRIES 8
|
||||
+#define GRUB_JFS_DIR_MAX_SLOTS 128
|
||||
|
||||
struct grub_jfs_sblock
|
||||
{
|
||||
@@ -481,6 +482,14 @@ grub_jfs_opendir (struct grub_jfs_data *data, struct grub_jfs_inode *inode)
|
||||
return 0;
|
||||
}
|
||||
|
||||
+ if (inode->dir.header.sorted[0] >= GRUB_JFS_DIR_MAX_SLOTS)
|
||||
+ {
|
||||
+ grub_error (GRUB_ERR_BAD_FS, N_("invalid directory slot index"));
|
||||
+ grub_free (diro->dirpage);
|
||||
+ grub_free (diro);
|
||||
+ return 0;
|
||||
+ }
|
||||
+
|
||||
blk = grub_le_to_cpu32 (de[inode->dir.header.sorted[0]].ex.blk2);
|
||||
blk <<= (grub_le_to_cpu16 (data->sblock.log2_blksz) - GRUB_DISK_SECTOR_BITS);
|
||||
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,133 @@
|
||||
From 978c4c79935a375cb16d94e8114d96fee013c288 Mon Sep 17 00:00:00 2001
|
||||
From: Lidong Chen <lidong.chen@oracle.com>
|
||||
Date: Mon, 16 Dec 2024 20:22:39 +0000
|
||||
Subject: [PATCH] fs/jfs: Use full 40 bits offset and address for a data extent
|
||||
|
||||
An extent's logical offset and address are represented as a 40-bit value
|
||||
split into two parts: the most significant 8 bits and the least
|
||||
significant 32 bits. Currently the JFS code uses only the least
|
||||
significant 32 bits value for offsets and addresses assuming the data
|
||||
size will never exceed the 32-bit range. This approach ignores the most
|
||||
significant 8 bits potentially leading to incorrect offsets and
|
||||
addresses for larger values. The patch fixes it by incorporating the
|
||||
most significant 8 bits into the calculation to get the full 40-bits
|
||||
value for offsets and addresses.
|
||||
|
||||
https://jfs.sourceforge.net/project/pub/jfslayout.pdf
|
||||
|
||||
"off1,off2 is a 40-bit field, containing the logical offset of the first
|
||||
block in the extent.
|
||||
...
|
||||
addr1,addr2 is a 40-bit field, containing the address of the extent."
|
||||
|
||||
Signed-off-by: Lidong Chen <lidong.chen@oracle.com>
|
||||
Reviewed-by: Alec Brown <alec.r.brown@oracle.com>
|
||||
Reviewed-by: Ross Philipson <ross.philipson@oracle.com>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: bd999310fe67f35a66de3bfa2836da91589d04ef
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/fs/jfs.c | 41 +++++++++++++++++++++++++++++------------
|
||||
1 file changed, 29 insertions(+), 12 deletions(-)
|
||||
|
||||
diff --git a/grub-core/fs/jfs.c b/grub-core/fs/jfs.c
|
||||
index 88fb884df..2bde48d45 100644
|
||||
--- a/grub-core/fs/jfs.c
|
||||
+++ b/grub-core/fs/jfs.c
|
||||
@@ -265,6 +265,20 @@ static grub_dl_t my_mod;
|
||||
|
||||
static grub_err_t grub_jfs_lookup_symlink (struct grub_jfs_data *data, grub_uint32_t ino);
|
||||
|
||||
+/*
|
||||
+ * An extent's offset, physical and logical, is represented as a 40-bit value.
|
||||
+ * This 40-bit value is split into two parts:
|
||||
+ * - offset1: the most signficant 8 bits of the offset,
|
||||
+ * - offset2: the least significant 32 bits of the offset.
|
||||
+ *
|
||||
+ * This function calculates and returns the 64-bit offset of an extent.
|
||||
+ */
|
||||
+static grub_uint64_t
|
||||
+get_ext_offset (grub_uint8_t offset1, grub_uint32_t offset2)
|
||||
+{
|
||||
+ return (((grub_uint64_t) offset1 << 32) | grub_le_to_cpu32 (offset2));
|
||||
+}
|
||||
+
|
||||
static grub_int64_t
|
||||
getblk (struct grub_jfs_treehead *treehead,
|
||||
struct grub_jfs_tree_extent *extents,
|
||||
@@ -274,22 +288,25 @@ getblk (struct grub_jfs_treehead *treehead,
|
||||
{
|
||||
int found = -1;
|
||||
int i;
|
||||
+ grub_uint64_t ext_offset, ext_blk;
|
||||
|
||||
for (i = 0; i < grub_le_to_cpu16 (treehead->count) - 2 &&
|
||||
i < max_extents; i++)
|
||||
{
|
||||
+ ext_offset = get_ext_offset (extents[i].offset1, extents[i].offset2);
|
||||
+ ext_blk = get_ext_offset (extents[i].extent.blk1, extents[i].extent.blk2);
|
||||
+
|
||||
if (treehead->flags & GRUB_JFS_TREE_LEAF)
|
||||
{
|
||||
/* Read the leafnode. */
|
||||
- if (grub_le_to_cpu32 (extents[i].offset2) <= blk
|
||||
+ if (ext_offset <= blk
|
||||
&& ((grub_le_to_cpu16 (extents[i].extent.length))
|
||||
+ (extents[i].extent.length2 << 16)
|
||||
- + grub_le_to_cpu32 (extents[i].offset2)) > blk)
|
||||
- return (blk - grub_le_to_cpu32 (extents[i].offset2)
|
||||
- + grub_le_to_cpu32 (extents[i].extent.blk2));
|
||||
+ + ext_offset) > blk)
|
||||
+ return (blk - ext_offset + ext_blk);
|
||||
}
|
||||
else
|
||||
- if (blk >= grub_le_to_cpu32 (extents[i].offset2))
|
||||
+ if (blk >= ext_offset)
|
||||
found = i;
|
||||
}
|
||||
|
||||
@@ -307,10 +324,9 @@ getblk (struct grub_jfs_treehead *treehead,
|
||||
return -1;
|
||||
|
||||
if (!grub_disk_read (data->disk,
|
||||
- ((grub_disk_addr_t) grub_le_to_cpu32 (extents[found].extent.blk2))
|
||||
- << (grub_le_to_cpu16 (data->sblock.log2_blksz)
|
||||
- - GRUB_DISK_SECTOR_BITS), 0,
|
||||
- sizeof (*tree), (char *) tree))
|
||||
+ (grub_disk_addr_t) ext_blk
|
||||
+ << (grub_le_to_cpu16 (data->sblock.log2_blksz) - GRUB_DISK_SECTOR_BITS),
|
||||
+ 0, sizeof (*tree), (char *) tree))
|
||||
{
|
||||
if (grub_memcmp (&tree->treehead, treehead, sizeof (struct grub_jfs_treehead)) ||
|
||||
grub_memcmp (&tree->extents, extents, 254 * sizeof (struct grub_jfs_tree_extent)))
|
||||
@@ -361,7 +377,7 @@ grub_jfs_read_inode (struct grub_jfs_data *data, grub_uint32_t ino,
|
||||
sizeof (iag_inodes), &iag_inodes))
|
||||
return grub_errno;
|
||||
|
||||
- inoblk = grub_le_to_cpu32 (iag_inodes[inoext].blk2);
|
||||
+ inoblk = get_ext_offset (iag_inodes[inoext].blk1, iag_inodes[inoext].blk2);
|
||||
inoblk <<= (grub_le_to_cpu16 (data->sblock.log2_blksz)
|
||||
- GRUB_DISK_SECTOR_BITS);
|
||||
inoblk += inonum;
|
||||
@@ -490,7 +506,8 @@ grub_jfs_opendir (struct grub_jfs_data *data, struct grub_jfs_inode *inode)
|
||||
return 0;
|
||||
}
|
||||
|
||||
- blk = grub_le_to_cpu32 (de[inode->dir.header.sorted[0]].ex.blk2);
|
||||
+ blk = get_ext_offset (de[inode->dir.header.sorted[0]].ex.blk1,
|
||||
+ de[inode->dir.header.sorted[0]].ex.blk2);
|
||||
blk <<= (grub_le_to_cpu16 (data->sblock.log2_blksz) - GRUB_DISK_SECTOR_BITS);
|
||||
|
||||
/* Read in the nodes until we are on the leaf node level. */
|
||||
@@ -508,7 +525,7 @@ grub_jfs_opendir (struct grub_jfs_data *data, struct grub_jfs_inode *inode)
|
||||
|
||||
de = (struct grub_jfs_internal_dirent *) diro->dirpage->dirent;
|
||||
index = diro->dirpage->sorted[diro->dirpage->header.sindex * 32];
|
||||
- blk = (grub_le_to_cpu32 (de[index].ex.blk2)
|
||||
+ blk = (get_ext_offset (de[index].ex.blk1, de[index].ex.blk2)
|
||||
<< (grub_le_to_cpu16 (data->sblock.log2_blksz)
|
||||
- GRUB_DISK_SECTOR_BITS));
|
||||
} while (!(diro->dirpage->header.flags & GRUB_JFS_TREE_LEAF));
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,90 @@
|
||||
From 32f319d100c3b8f9b04e6a175f599c7411a54555 Mon Sep 17 00:00:00 2001
|
||||
From: Lidong Chen <lidong.chen@oracle.com>
|
||||
Date: Mon, 16 Dec 2024 20:22:40 +0000
|
||||
Subject: [PATCH] fs/jfs: Inconsistent signed/unsigned types usage in return
|
||||
values
|
||||
|
||||
The getblk() returns a value of type grub_int64_t which is assigned to
|
||||
iagblk and inoblk, both of type grub_uint64_t, in grub_jfs_read_inode()
|
||||
via grub_jfs_blkno(). This patch fixes the type mismatch in the
|
||||
functions. Additionally, the getblk() will return 0 instead of -1 on
|
||||
failure cases. This change is safe because grub_errno is always set in
|
||||
getblk() to indicate errors and it is later checked in the callers.
|
||||
|
||||
Signed-off-by: Lidong Chen <lidong.chen@oracle.com>
|
||||
Reviewed-by: Alec Brown <alec.r.brown@oracle.com>
|
||||
Reviewed-by: Ross Philipson <ross.philipson@oracle.com>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: edd995a26ec98654d907a9436a296c2d82bc4b28
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/fs/jfs.c | 15 +++++++++------
|
||||
1 file changed, 9 insertions(+), 6 deletions(-)
|
||||
|
||||
diff --git a/grub-core/fs/jfs.c b/grub-core/fs/jfs.c
|
||||
index 2bde48d45..70a2f4947 100644
|
||||
--- a/grub-core/fs/jfs.c
|
||||
+++ b/grub-core/fs/jfs.c
|
||||
@@ -279,7 +279,7 @@ get_ext_offset (grub_uint8_t offset1, grub_uint32_t offset2)
|
||||
return (((grub_uint64_t) offset1 << 32) | grub_le_to_cpu32 (offset2));
|
||||
}
|
||||
|
||||
-static grub_int64_t
|
||||
+static grub_uint64_t
|
||||
getblk (struct grub_jfs_treehead *treehead,
|
||||
struct grub_jfs_tree_extent *extents,
|
||||
int max_extents,
|
||||
@@ -290,6 +290,8 @@ getblk (struct grub_jfs_treehead *treehead,
|
||||
int i;
|
||||
grub_uint64_t ext_offset, ext_blk;
|
||||
|
||||
+ grub_errno = GRUB_ERR_NONE;
|
||||
+
|
||||
for (i = 0; i < grub_le_to_cpu16 (treehead->count) - 2 &&
|
||||
i < max_extents; i++)
|
||||
{
|
||||
@@ -312,7 +314,7 @@ getblk (struct grub_jfs_treehead *treehead,
|
||||
|
||||
if (found != -1)
|
||||
{
|
||||
- grub_int64_t ret = -1;
|
||||
+ grub_uint64_t ret = 0;
|
||||
struct
|
||||
{
|
||||
struct grub_jfs_treehead treehead;
|
||||
@@ -321,7 +323,7 @@ getblk (struct grub_jfs_treehead *treehead,
|
||||
|
||||
tree = grub_zalloc (sizeof (*tree));
|
||||
if (!tree)
|
||||
- return -1;
|
||||
+ return 0;
|
||||
|
||||
if (!grub_disk_read (data->disk,
|
||||
(grub_disk_addr_t) ext_blk
|
||||
@@ -334,19 +336,20 @@ getblk (struct grub_jfs_treehead *treehead,
|
||||
else
|
||||
{
|
||||
grub_error (GRUB_ERR_BAD_FS, "jfs: infinite recursion detected");
|
||||
- ret = -1;
|
||||
+ ret = 0;
|
||||
}
|
||||
}
|
||||
grub_free (tree);
|
||||
return ret;
|
||||
}
|
||||
|
||||
- return -1;
|
||||
+ grub_error (GRUB_ERR_READ_ERROR, "jfs: block %" PRIuGRUB_UINT64_T " not found", blk);
|
||||
+ return 0;
|
||||
}
|
||||
|
||||
/* Get the block number for the block BLK in the node INODE in the
|
||||
mounted filesystem DATA. */
|
||||
-static grub_int64_t
|
||||
+static grub_uint64_t
|
||||
grub_jfs_blkno (struct grub_jfs_data *data, struct grub_jfs_inode *inode,
|
||||
grub_uint64_t blk)
|
||||
{
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,51 @@
|
||||
From 7da8e2e23db5f1ddb9c4dc992c69349149163c4c Mon Sep 17 00:00:00 2001
|
||||
From: Michael Chang <mchang@suse.com>
|
||||
Date: Fri, 31 May 2024 15:14:23 +0800
|
||||
Subject: [PATCH] fs/ext2: Fix out-of-bounds read for inline extents
|
||||
|
||||
When inline extents are used, i.e. the extent tree depth equals zero,
|
||||
a maximum of four entries can fit into the inode's data block. If the
|
||||
extent header states a number of entries greater than four the current
|
||||
ext2 implementation causes an out-of-bounds read. Fix this issue by
|
||||
capping the number of extents to four when reading inline extents.
|
||||
|
||||
Reported-by: Daniel Axtens <dja@axtens.net>
|
||||
Signed-off-by: Michael Chang <mchang@suse.com>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: 7e2f750f0a795c4d64ec7dc7591edac8da2e978c
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/fs/ext2.c | 10 +++++++++-
|
||||
1 file changed, 9 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/grub-core/fs/ext2.c b/grub-core/fs/ext2.c
|
||||
index e1cc5e62a..3f9f6b208 100644
|
||||
--- a/grub-core/fs/ext2.c
|
||||
+++ b/grub-core/fs/ext2.c
|
||||
@@ -495,6 +495,8 @@ grub_ext2_read_block (grub_fshelp_node_t node, grub_disk_addr_t fileblock)
|
||||
struct grub_ext4_extent *ext;
|
||||
int i;
|
||||
grub_disk_addr_t ret;
|
||||
+ grub_uint16_t nent;
|
||||
+ const grub_uint16_t max_inline_ext = sizeof (inode->blocks) / sizeof (*ext) - 1; /* Minus 1 extent header. */
|
||||
|
||||
if (grub_ext4_find_leaf (data, (struct grub_ext4_extent_header *) inode->blocks.dir_blocks,
|
||||
fileblock, &leaf) != GRUB_ERR_NONE)
|
||||
@@ -508,7 +510,13 @@ grub_ext2_read_block (grub_fshelp_node_t node, grub_disk_addr_t fileblock)
|
||||
return 0;
|
||||
|
||||
ext = (struct grub_ext4_extent *) (leaf + 1);
|
||||
- for (i = 0; i < grub_le_to_cpu16 (leaf->entries); i++)
|
||||
+
|
||||
+ nent = grub_le_to_cpu16 (leaf->entries);
|
||||
+
|
||||
+ if (leaf->depth == 0)
|
||||
+ nent = grub_min (nent, max_inline_ext);
|
||||
+
|
||||
+ for (i = 0; i < nent; i++)
|
||||
{
|
||||
if (fileblock < grub_le_to_cpu32 (ext[i].block))
|
||||
break;
|
||||
--
|
||||
2.50.1
|
||||
|
||||
48
boot/grub2/0016-fs-xfs-Fix-out-of-bounds-read.patch
Normal file
48
boot/grub2/0016-fs-xfs-Fix-out-of-bounds-read.patch
Normal file
@@ -0,0 +1,48 @@
|
||||
From 854503d76e7dbc25f999d6be3e2ef4e8067f4152 Mon Sep 17 00:00:00 2001
|
||||
From: Michael Chang <mchang@suse.com>
|
||||
Date: Fri, 31 May 2024 15:14:57 +0800
|
||||
Subject: [PATCH] fs/xfs: Fix out-of-bounds read
|
||||
|
||||
The number of records in the root key array read from disk was not being
|
||||
validated against the size of the root node. This could lead to an
|
||||
out-of-bounds read.
|
||||
|
||||
This patch adds a check to ensure that the number of records in the root
|
||||
key array does not exceed the expected size of a root node read from
|
||||
disk. If this check detects an out-of-bounds condition the operation is
|
||||
aborted to prevent random errors due to metadata corruption.
|
||||
|
||||
Reported-by: Daniel Axtens <dja@axtens.net>
|
||||
Signed-off-by: Michael Chang <mchang@suse.com>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: 6ccc77b59d16578b10eaf8a4fe85c20b229f0d8a
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/fs/xfs.c | 11 +++++++++++
|
||||
1 file changed, 11 insertions(+)
|
||||
|
||||
diff --git a/grub-core/fs/xfs.c b/grub-core/fs/xfs.c
|
||||
index bc2224dbb..d2d533531 100644
|
||||
--- a/grub-core/fs/xfs.c
|
||||
+++ b/grub-core/fs/xfs.c
|
||||
@@ -595,6 +595,17 @@ grub_xfs_read_block (grub_fshelp_node_t node, grub_disk_addr_t fileblock)
|
||||
do
|
||||
{
|
||||
grub_uint64_t i;
|
||||
+ grub_addr_t keys_end, data_end;
|
||||
+
|
||||
+ if (grub_mul (sizeof (grub_uint64_t), nrec, &keys_end) ||
|
||||
+ grub_add ((grub_addr_t) keys, keys_end, &keys_end) ||
|
||||
+ grub_add ((grub_addr_t) node->data, node->data->data_size, &data_end) ||
|
||||
+ keys_end > data_end)
|
||||
+ {
|
||||
+ grub_error (GRUB_ERR_BAD_FS, "invalid number of XFS root keys");
|
||||
+ grub_free (leaf);
|
||||
+ return 0;
|
||||
+ }
|
||||
|
||||
for (i = 0; i < nrec; i++)
|
||||
{
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,47 @@
|
||||
From 9a5c23756f2e2d4ee8438bf449881c8f854e59ab Mon Sep 17 00:00:00 2001
|
||||
From: B Horn <b@horn.uk>
|
||||
Date: Sun, 12 May 2024 06:03:58 +0100
|
||||
Subject: [PATCH] fs/xfs: Ensuring failing to mount sets a grub_errno
|
||||
|
||||
It was previously possible for grub_xfs_mount() to return NULL without
|
||||
setting grub_errno if the XFS version was invalid. This resulted in it
|
||||
being possible for grub_dl_unref() to be called twice allowing the XFS
|
||||
module to be unloaded while there were still references to it.
|
||||
|
||||
Fixing this problem in general by ensuring a grub_errno is set if the
|
||||
fail label is reached.
|
||||
|
||||
Reported-by: B Horn <b@horn.uk>
|
||||
Signed-off-by: B Horn <b@horn.uk>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: d1d6b7ea58aa5a80a4c4d0666b49460056c8ef0a
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/fs/xfs.c | 4 +++-
|
||||
1 file changed, 3 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/grub-core/fs/xfs.c b/grub-core/fs/xfs.c
|
||||
index d2d533531..56738a135 100644
|
||||
--- a/grub-core/fs/xfs.c
|
||||
+++ b/grub-core/fs/xfs.c
|
||||
@@ -327,6 +327,8 @@ static int grub_xfs_sb_valid(struct grub_xfs_data *data)
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
+
|
||||
+ grub_error (GRUB_ERR_BAD_FS, "unsupported XFS filesystem version");
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -1058,7 +1060,7 @@ grub_xfs_mount (grub_disk_t disk)
|
||||
return data;
|
||||
fail:
|
||||
|
||||
- if (grub_errno == GRUB_ERR_OUT_OF_RANGE)
|
||||
+ if (grub_errno == GRUB_ERR_OUT_OF_RANGE || grub_errno == GRUB_ERR_NONE)
|
||||
grub_error (GRUB_ERR_BAD_FS, "not an XFS filesystem");
|
||||
|
||||
grub_free (data);
|
||||
--
|
||||
2.50.1
|
||||
|
||||
37
boot/grub2/0018-kern-file-Ensure-file-data-is-set.patch
Normal file
37
boot/grub2/0018-kern-file-Ensure-file-data-is-set.patch
Normal file
@@ -0,0 +1,37 @@
|
||||
From 816fb20ed0a80032e2eaf4c4ccaf989bf20908be Mon Sep 17 00:00:00 2001
|
||||
From: B Horn <b@horn.uk>
|
||||
Date: Sun, 12 May 2024 03:01:40 +0100
|
||||
Subject: [PATCH] kern/file: Ensure file->data is set
|
||||
|
||||
This is to avoid a generic issue were some filesystems would not set
|
||||
data and also not set a grub_errno. This meant it was possible for many
|
||||
filesystems to grub_dl_unref() themselves multiple times resulting in
|
||||
it being possible to unload the filesystems while there were still
|
||||
references to them, e.g., via a loopback.
|
||||
|
||||
Reported-by: B Horn <b@horn.uk>
|
||||
Signed-off-by: B Horn <b@horn.uk>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: a7910687294b29288ac649e71b47493c93294f17
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/kern/file.c | 3 +++
|
||||
1 file changed, 3 insertions(+)
|
||||
|
||||
diff --git a/grub-core/kern/file.c b/grub-core/kern/file.c
|
||||
index 750177248..e990507fc 100644
|
||||
--- a/grub-core/kern/file.c
|
||||
+++ b/grub-core/kern/file.c
|
||||
@@ -114,6 +114,9 @@ grub_file_open (const char *name, enum grub_file_type type)
|
||||
if ((file->fs->fs_open) (file, file_name) != GRUB_ERR_NONE)
|
||||
goto fail;
|
||||
|
||||
+ if (file->data == NULL)
|
||||
+ goto fail;
|
||||
+
|
||||
file->name = grub_strdup (name);
|
||||
grub_errno = GRUB_ERR_NONE;
|
||||
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,449 @@
|
||||
From a27c4b6da2f4a014e5d096e75790e860bcdb2472 Mon Sep 17 00:00:00 2001
|
||||
From: B Horn <b@horn.uk>
|
||||
Date: Sun, 12 May 2024 10:15:03 +0100
|
||||
Subject: [PATCH] kern/file: Implement filesystem reference counting
|
||||
|
||||
The grub_file_open() and grub_file_close() should be the only places
|
||||
that allow a reference to a filesystem to stay open. So, add grub_dl_t
|
||||
to grub_fs_t and set this in the GRUB_MOD_INIT() for each filesystem to
|
||||
avoid issues when filesystems forget to do it themselves or do not track
|
||||
their own references, e.g. squash4.
|
||||
|
||||
The fs_label(), fs_uuid(), fs_mtime() and fs_read() should all ref and
|
||||
unref in the same function but it is essentially redundant in GRUB
|
||||
single threaded model.
|
||||
|
||||
Signed-off-by: B Horn <b@horn.uk>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
|
||||
Conflicts:
|
||||
grub-core/fs/erofs.c
|
||||
|
||||
Upstream: 16f196874fbe360a1b3c66064ec15adadf94c57b
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/fs/affs.c | 1 +
|
||||
grub-core/fs/bfs.c | 1 +
|
||||
grub-core/fs/btrfs.c | 1 +
|
||||
grub-core/fs/cbfs.c | 1 +
|
||||
grub-core/fs/cpio.c | 1 +
|
||||
grub-core/fs/cpio_be.c | 1 +
|
||||
grub-core/fs/ext2.c | 1 +
|
||||
grub-core/fs/f2fs.c | 1 +
|
||||
grub-core/fs/fat.c | 1 +
|
||||
grub-core/fs/hfs.c | 1 +
|
||||
grub-core/fs/hfsplus.c | 1 +
|
||||
grub-core/fs/iso9660.c | 1 +
|
||||
grub-core/fs/jfs.c | 1 +
|
||||
grub-core/fs/minix.c | 1 +
|
||||
grub-core/fs/newc.c | 1 +
|
||||
grub-core/fs/nilfs2.c | 1 +
|
||||
grub-core/fs/ntfs.c | 1 +
|
||||
grub-core/fs/odc.c | 1 +
|
||||
grub-core/fs/proc.c | 1 +
|
||||
grub-core/fs/reiserfs.c | 1 +
|
||||
grub-core/fs/romfs.c | 1 +
|
||||
grub-core/fs/sfs.c | 1 +
|
||||
grub-core/fs/squash4.c | 1 +
|
||||
grub-core/fs/tar.c | 1 +
|
||||
grub-core/fs/udf.c | 1 +
|
||||
grub-core/fs/ufs.c | 1 +
|
||||
grub-core/fs/xfs.c | 1 +
|
||||
grub-core/fs/zfs/zfs.c | 1 +
|
||||
grub-core/kern/file.c | 7 +++++++
|
||||
include/grub/fs.h | 4 ++++
|
||||
30 files changed, 39 insertions(+)
|
||||
|
||||
diff --git a/grub-core/fs/affs.c b/grub-core/fs/affs.c
|
||||
index ed606b3f1..9b0afb954 100644
|
||||
--- a/grub-core/fs/affs.c
|
||||
+++ b/grub-core/fs/affs.c
|
||||
@@ -703,6 +703,7 @@ static struct grub_fs grub_affs_fs =
|
||||
|
||||
GRUB_MOD_INIT(affs)
|
||||
{
|
||||
+ grub_affs_fs.mod = mod;
|
||||
grub_fs_register (&grub_affs_fs);
|
||||
my_mod = mod;
|
||||
}
|
||||
diff --git a/grub-core/fs/bfs.c b/grub-core/fs/bfs.c
|
||||
index 07cb3e3ac..f37b16895 100644
|
||||
--- a/grub-core/fs/bfs.c
|
||||
+++ b/grub-core/fs/bfs.c
|
||||
@@ -1106,6 +1106,7 @@ GRUB_MOD_INIT (bfs)
|
||||
{
|
||||
COMPILE_TIME_ASSERT (1 << LOG_EXTENT_SIZE ==
|
||||
sizeof (struct grub_bfs_extent));
|
||||
+ grub_bfs_fs.mod = mod;
|
||||
grub_fs_register (&grub_bfs_fs);
|
||||
}
|
||||
|
||||
diff --git a/grub-core/fs/btrfs.c b/grub-core/fs/btrfs.c
|
||||
index ba0c58352..aae81482b 100644
|
||||
--- a/grub-core/fs/btrfs.c
|
||||
+++ b/grub-core/fs/btrfs.c
|
||||
@@ -2413,6 +2413,7 @@ static struct grub_fs grub_btrfs_fs = {
|
||||
|
||||
GRUB_MOD_INIT (btrfs)
|
||||
{
|
||||
+ grub_btrfs_fs.mod = mod;
|
||||
grub_fs_register (&grub_btrfs_fs);
|
||||
}
|
||||
|
||||
diff --git a/grub-core/fs/cbfs.c b/grub-core/fs/cbfs.c
|
||||
index 8ab7106af..2332745fe 100644
|
||||
--- a/grub-core/fs/cbfs.c
|
||||
+++ b/grub-core/fs/cbfs.c
|
||||
@@ -390,6 +390,7 @@ GRUB_MOD_INIT (cbfs)
|
||||
#if (defined (__i386__) || defined (__x86_64__)) && !defined (GRUB_UTIL) && !defined (GRUB_MACHINE_EMU) && !defined (GRUB_MACHINE_XEN)
|
||||
init_cbfsdisk ();
|
||||
#endif
|
||||
+ grub_cbfs_fs.mod = mod;
|
||||
grub_fs_register (&grub_cbfs_fs);
|
||||
}
|
||||
|
||||
diff --git a/grub-core/fs/cpio.c b/grub-core/fs/cpio.c
|
||||
index dab5f9898..1799f7ff5 100644
|
||||
--- a/grub-core/fs/cpio.c
|
||||
+++ b/grub-core/fs/cpio.c
|
||||
@@ -52,6 +52,7 @@ read_number (const grub_uint16_t *arr, grub_size_t size)
|
||||
|
||||
GRUB_MOD_INIT (cpio)
|
||||
{
|
||||
+ grub_cpio_fs.mod = mod;
|
||||
grub_fs_register (&grub_cpio_fs);
|
||||
}
|
||||
|
||||
diff --git a/grub-core/fs/cpio_be.c b/grub-core/fs/cpio_be.c
|
||||
index 846548892..7bed1b848 100644
|
||||
--- a/grub-core/fs/cpio_be.c
|
||||
+++ b/grub-core/fs/cpio_be.c
|
||||
@@ -52,6 +52,7 @@ read_number (const grub_uint16_t *arr, grub_size_t size)
|
||||
|
||||
GRUB_MOD_INIT (cpio_be)
|
||||
{
|
||||
+ grub_cpio_fs.mod = mod;
|
||||
grub_fs_register (&grub_cpio_fs);
|
||||
}
|
||||
|
||||
diff --git a/grub-core/fs/ext2.c b/grub-core/fs/ext2.c
|
||||
index 3f9f6b208..c3058f7e7 100644
|
||||
--- a/grub-core/fs/ext2.c
|
||||
+++ b/grub-core/fs/ext2.c
|
||||
@@ -1131,6 +1131,7 @@ static struct grub_fs grub_ext2_fs =
|
||||
|
||||
GRUB_MOD_INIT(ext2)
|
||||
{
|
||||
+ grub_ext2_fs.mod = mod;
|
||||
grub_fs_register (&grub_ext2_fs);
|
||||
my_mod = mod;
|
||||
}
|
||||
diff --git a/grub-core/fs/f2fs.c b/grub-core/fs/f2fs.c
|
||||
index db8a65f8d..f6d6beaa5 100644
|
||||
--- a/grub-core/fs/f2fs.c
|
||||
+++ b/grub-core/fs/f2fs.c
|
||||
@@ -1353,6 +1353,7 @@ static struct grub_fs grub_f2fs_fs = {
|
||||
|
||||
GRUB_MOD_INIT (f2fs)
|
||||
{
|
||||
+ grub_f2fs_fs.mod = mod;
|
||||
grub_fs_register (&grub_f2fs_fs);
|
||||
my_mod = mod;
|
||||
}
|
||||
diff --git a/grub-core/fs/fat.c b/grub-core/fs/fat.c
|
||||
index c5efed724..6e62b915d 100644
|
||||
--- a/grub-core/fs/fat.c
|
||||
+++ b/grub-core/fs/fat.c
|
||||
@@ -1312,6 +1312,7 @@ GRUB_MOD_INIT(fat)
|
||||
#endif
|
||||
{
|
||||
COMPILE_TIME_ASSERT (sizeof (struct grub_fat_dir_entry) == 32);
|
||||
+ grub_fat_fs.mod = mod;
|
||||
grub_fs_register (&grub_fat_fs);
|
||||
my_mod = mod;
|
||||
}
|
||||
diff --git a/grub-core/fs/hfs.c b/grub-core/fs/hfs.c
|
||||
index 920112b03..ce7581dd5 100644
|
||||
--- a/grub-core/fs/hfs.c
|
||||
+++ b/grub-core/fs/hfs.c
|
||||
@@ -1434,6 +1434,7 @@ static struct grub_fs grub_hfs_fs =
|
||||
|
||||
GRUB_MOD_INIT(hfs)
|
||||
{
|
||||
+ grub_hfs_fs.mod = mod;
|
||||
if (!grub_is_lockdown ())
|
||||
grub_fs_register (&grub_hfs_fs);
|
||||
my_mod = mod;
|
||||
diff --git a/grub-core/fs/hfsplus.c b/grub-core/fs/hfsplus.c
|
||||
index de71fd486..3f203abcc 100644
|
||||
--- a/grub-core/fs/hfsplus.c
|
||||
+++ b/grub-core/fs/hfsplus.c
|
||||
@@ -1176,6 +1176,7 @@ static struct grub_fs grub_hfsplus_fs =
|
||||
|
||||
GRUB_MOD_INIT(hfsplus)
|
||||
{
|
||||
+ grub_hfsplus_fs.mod = mod;
|
||||
grub_fs_register (&grub_hfsplus_fs);
|
||||
my_mod = mod;
|
||||
}
|
||||
diff --git a/grub-core/fs/iso9660.c b/grub-core/fs/iso9660.c
|
||||
index 8e3c95c4f..c73cb9ce0 100644
|
||||
--- a/grub-core/fs/iso9660.c
|
||||
+++ b/grub-core/fs/iso9660.c
|
||||
@@ -1260,6 +1260,7 @@ static struct grub_fs grub_iso9660_fs =
|
||||
|
||||
GRUB_MOD_INIT(iso9660)
|
||||
{
|
||||
+ grub_iso9660_fs.mod = mod;
|
||||
grub_fs_register (&grub_iso9660_fs);
|
||||
my_mod = mod;
|
||||
}
|
||||
diff --git a/grub-core/fs/jfs.c b/grub-core/fs/jfs.c
|
||||
index 70a2f4947..b0283ac00 100644
|
||||
--- a/grub-core/fs/jfs.c
|
||||
+++ b/grub-core/fs/jfs.c
|
||||
@@ -1005,6 +1005,7 @@ static struct grub_fs grub_jfs_fs =
|
||||
|
||||
GRUB_MOD_INIT(jfs)
|
||||
{
|
||||
+ grub_jfs_fs.mod = mod;
|
||||
grub_fs_register (&grub_jfs_fs);
|
||||
my_mod = mod;
|
||||
}
|
||||
diff --git a/grub-core/fs/minix.c b/grub-core/fs/minix.c
|
||||
index 5354951d1..b7679c3e2 100644
|
||||
--- a/grub-core/fs/minix.c
|
||||
+++ b/grub-core/fs/minix.c
|
||||
@@ -734,6 +734,7 @@ GRUB_MOD_INIT(minix)
|
||||
#endif
|
||||
#endif
|
||||
{
|
||||
+ grub_minix_fs.mod = mod;
|
||||
grub_fs_register (&grub_minix_fs);
|
||||
my_mod = mod;
|
||||
}
|
||||
diff --git a/grub-core/fs/newc.c b/grub-core/fs/newc.c
|
||||
index 4fb8b2e3d..43b7f8b64 100644
|
||||
--- a/grub-core/fs/newc.c
|
||||
+++ b/grub-core/fs/newc.c
|
||||
@@ -64,6 +64,7 @@ read_number (const char *str, grub_size_t size)
|
||||
|
||||
GRUB_MOD_INIT (newc)
|
||||
{
|
||||
+ grub_cpio_fs.mod = mod;
|
||||
grub_fs_register (&grub_cpio_fs);
|
||||
}
|
||||
|
||||
diff --git a/grub-core/fs/nilfs2.c b/grub-core/fs/nilfs2.c
|
||||
index fc7374ead..4e1e71738 100644
|
||||
--- a/grub-core/fs/nilfs2.c
|
||||
+++ b/grub-core/fs/nilfs2.c
|
||||
@@ -1231,6 +1231,7 @@ GRUB_MOD_INIT (nilfs2)
|
||||
grub_nilfs2_dat_entry));
|
||||
COMPILE_TIME_ASSERT (1 << LOG_INODE_SIZE
|
||||
== sizeof (struct grub_nilfs2_inode));
|
||||
+ grub_nilfs2_fs.mod = mod;
|
||||
grub_fs_register (&grub_nilfs2_fs);
|
||||
my_mod = mod;
|
||||
}
|
||||
diff --git a/grub-core/fs/ntfs.c b/grub-core/fs/ntfs.c
|
||||
index de435aa14..560917dc2 100644
|
||||
--- a/grub-core/fs/ntfs.c
|
||||
+++ b/grub-core/fs/ntfs.c
|
||||
@@ -1320,6 +1320,7 @@ static struct grub_fs grub_ntfs_fs =
|
||||
|
||||
GRUB_MOD_INIT (ntfs)
|
||||
{
|
||||
+ grub_ntfs_fs.mod = mod;
|
||||
grub_fs_register (&grub_ntfs_fs);
|
||||
my_mod = mod;
|
||||
}
|
||||
diff --git a/grub-core/fs/odc.c b/grub-core/fs/odc.c
|
||||
index 790000622..8e4e8aeac 100644
|
||||
--- a/grub-core/fs/odc.c
|
||||
+++ b/grub-core/fs/odc.c
|
||||
@@ -52,6 +52,7 @@ read_number (const char *str, grub_size_t size)
|
||||
|
||||
GRUB_MOD_INIT (odc)
|
||||
{
|
||||
+ grub_cpio_fs.mod = mod;
|
||||
grub_fs_register (&grub_cpio_fs);
|
||||
}
|
||||
|
||||
diff --git a/grub-core/fs/proc.c b/grub-core/fs/proc.c
|
||||
index 5f516502d..bcde43349 100644
|
||||
--- a/grub-core/fs/proc.c
|
||||
+++ b/grub-core/fs/proc.c
|
||||
@@ -192,6 +192,7 @@ static struct grub_fs grub_procfs_fs =
|
||||
|
||||
GRUB_MOD_INIT (procfs)
|
||||
{
|
||||
+ grub_procfs_fs.mod = mod;
|
||||
grub_disk_dev_register (&grub_procfs_dev);
|
||||
grub_fs_register (&grub_procfs_fs);
|
||||
}
|
||||
diff --git a/grub-core/fs/reiserfs.c b/grub-core/fs/reiserfs.c
|
||||
index 36b26ac98..c3850e013 100644
|
||||
--- a/grub-core/fs/reiserfs.c
|
||||
+++ b/grub-core/fs/reiserfs.c
|
||||
@@ -1417,6 +1417,7 @@ static struct grub_fs grub_reiserfs_fs =
|
||||
|
||||
GRUB_MOD_INIT(reiserfs)
|
||||
{
|
||||
+ grub_reiserfs_fs.mod = mod;
|
||||
grub_fs_register (&grub_reiserfs_fs);
|
||||
my_mod = mod;
|
||||
}
|
||||
diff --git a/grub-core/fs/romfs.c b/grub-core/fs/romfs.c
|
||||
index 1f7dcfca1..56b0b2b2f 100644
|
||||
--- a/grub-core/fs/romfs.c
|
||||
+++ b/grub-core/fs/romfs.c
|
||||
@@ -475,6 +475,7 @@ static struct grub_fs grub_romfs_fs =
|
||||
|
||||
GRUB_MOD_INIT(romfs)
|
||||
{
|
||||
+ grub_romfs_fs.mod = mod;
|
||||
grub_fs_register (&grub_romfs_fs);
|
||||
}
|
||||
|
||||
diff --git a/grub-core/fs/sfs.c b/grub-core/fs/sfs.c
|
||||
index 983e88008..f0d7cac43 100644
|
||||
--- a/grub-core/fs/sfs.c
|
||||
+++ b/grub-core/fs/sfs.c
|
||||
@@ -779,6 +779,7 @@ static struct grub_fs grub_sfs_fs =
|
||||
|
||||
GRUB_MOD_INIT(sfs)
|
||||
{
|
||||
+ grub_sfs_fs.mod = mod;
|
||||
grub_fs_register (&grub_sfs_fs);
|
||||
my_mod = mod;
|
||||
}
|
||||
diff --git a/grub-core/fs/squash4.c b/grub-core/fs/squash4.c
|
||||
index a30e6ebe1..6e9d63874 100644
|
||||
--- a/grub-core/fs/squash4.c
|
||||
+++ b/grub-core/fs/squash4.c
|
||||
@@ -1044,6 +1044,7 @@ static struct grub_fs grub_squash_fs =
|
||||
|
||||
GRUB_MOD_INIT(squash4)
|
||||
{
|
||||
+ grub_squash_fs.mod = mod;
|
||||
grub_fs_register (&grub_squash_fs);
|
||||
}
|
||||
|
||||
diff --git a/grub-core/fs/tar.c b/grub-core/fs/tar.c
|
||||
index 386c09022..fd2ec1f74 100644
|
||||
--- a/grub-core/fs/tar.c
|
||||
+++ b/grub-core/fs/tar.c
|
||||
@@ -354,6 +354,7 @@ static struct grub_fs grub_cpio_fs = {
|
||||
|
||||
GRUB_MOD_INIT (tar)
|
||||
{
|
||||
+ grub_cpio_fs.mod = mod;
|
||||
grub_fs_register (&grub_cpio_fs);
|
||||
}
|
||||
|
||||
diff --git a/grub-core/fs/udf.c b/grub-core/fs/udf.c
|
||||
index b836e6107..8765c633c 100644
|
||||
--- a/grub-core/fs/udf.c
|
||||
+++ b/grub-core/fs/udf.c
|
||||
@@ -1455,6 +1455,7 @@ static struct grub_fs grub_udf_fs = {
|
||||
|
||||
GRUB_MOD_INIT (udf)
|
||||
{
|
||||
+ grub_udf_fs.mod = mod;
|
||||
grub_fs_register (&grub_udf_fs);
|
||||
my_mod = mod;
|
||||
}
|
||||
diff --git a/grub-core/fs/ufs.c b/grub-core/fs/ufs.c
|
||||
index 01235101b..e82d9356d 100644
|
||||
--- a/grub-core/fs/ufs.c
|
||||
+++ b/grub-core/fs/ufs.c
|
||||
@@ -899,6 +899,7 @@ GRUB_MOD_INIT(ufs1)
|
||||
#endif
|
||||
#endif
|
||||
{
|
||||
+ grub_ufs_fs.mod = mod;
|
||||
grub_fs_register (&grub_ufs_fs);
|
||||
my_mod = mod;
|
||||
}
|
||||
diff --git a/grub-core/fs/xfs.c b/grub-core/fs/xfs.c
|
||||
index 56738a135..74feeb86a 100644
|
||||
--- a/grub-core/fs/xfs.c
|
||||
+++ b/grub-core/fs/xfs.c
|
||||
@@ -1294,6 +1294,7 @@ static struct grub_fs grub_xfs_fs =
|
||||
|
||||
GRUB_MOD_INIT(xfs)
|
||||
{
|
||||
+ grub_xfs_fs.mod = mod;
|
||||
grub_fs_register (&grub_xfs_fs);
|
||||
my_mod = mod;
|
||||
}
|
||||
diff --git a/grub-core/fs/zfs/zfs.c b/grub-core/fs/zfs/zfs.c
|
||||
index b5453e006..a497b1869 100644
|
||||
--- a/grub-core/fs/zfs/zfs.c
|
||||
+++ b/grub-core/fs/zfs/zfs.c
|
||||
@@ -4424,6 +4424,7 @@ static struct grub_fs grub_zfs_fs = {
|
||||
GRUB_MOD_INIT (zfs)
|
||||
{
|
||||
COMPILE_TIME_ASSERT (sizeof (zap_leaf_chunk_t) == ZAP_LEAF_CHUNKSIZE);
|
||||
+ grub_zfs_fs.mod = mod;
|
||||
grub_fs_register (&grub_zfs_fs);
|
||||
#ifndef GRUB_UTIL
|
||||
my_mod = mod;
|
||||
diff --git a/grub-core/kern/file.c b/grub-core/kern/file.c
|
||||
index e990507fc..6e7efe89a 100644
|
||||
--- a/grub-core/kern/file.c
|
||||
+++ b/grub-core/kern/file.c
|
||||
@@ -25,6 +25,7 @@
|
||||
#include <grub/fs.h>
|
||||
#include <grub/device.h>
|
||||
#include <grub/i18n.h>
|
||||
+#include <grub/dl.h>
|
||||
|
||||
void (*EXPORT_VAR (grub_grubnet_fini)) (void);
|
||||
|
||||
@@ -117,6 +118,9 @@ grub_file_open (const char *name, enum grub_file_type type)
|
||||
if (file->data == NULL)
|
||||
goto fail;
|
||||
|
||||
+ if (file->fs->mod)
|
||||
+ grub_dl_ref (file->fs->mod);
|
||||
+
|
||||
file->name = grub_strdup (name);
|
||||
grub_errno = GRUB_ERR_NONE;
|
||||
|
||||
@@ -197,6 +201,9 @@ grub_file_read (grub_file_t file, void *buf, grub_size_t len)
|
||||
grub_err_t
|
||||
grub_file_close (grub_file_t file)
|
||||
{
|
||||
+ if (file->fs->mod)
|
||||
+ grub_dl_unref (file->fs->mod);
|
||||
+
|
||||
if (file->fs->fs_close)
|
||||
(file->fs->fs_close) (file);
|
||||
|
||||
diff --git a/include/grub/fs.h b/include/grub/fs.h
|
||||
index 026bc3bb8..df4c93b16 100644
|
||||
--- a/include/grub/fs.h
|
||||
+++ b/include/grub/fs.h
|
||||
@@ -23,6 +23,7 @@
|
||||
#include <grub/device.h>
|
||||
#include <grub/symbol.h>
|
||||
#include <grub/types.h>
|
||||
+#include <grub/dl.h>
|
||||
|
||||
#include <grub/list.h>
|
||||
/* For embedding types. */
|
||||
@@ -57,6 +58,9 @@ struct grub_fs
|
||||
/* My name. */
|
||||
const char *name;
|
||||
|
||||
+ /* My module */
|
||||
+ grub_dl_t mod;
|
||||
+
|
||||
/* Call HOOK with each file under DIR. */
|
||||
grub_err_t (*fs_dir) (grub_device_t device, const char *path,
|
||||
grub_fs_dir_hook_t hook, void *hook_data);
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,108 @@
|
||||
From a81ef3044791e7ee02bd349b5ec0adcbf6947555 Mon Sep 17 00:00:00 2001
|
||||
From: B Horn <b@horn.uk>
|
||||
Date: Sun, 12 May 2024 03:26:19 +0100
|
||||
Subject: [PATCH] disk/loopback: Reference tracking for the loopback
|
||||
|
||||
It was possible to delete a loopback while there were still references
|
||||
to it. This led to an exploitable use-after-free.
|
||||
|
||||
Fixed by implementing a reference counting in the grub_loopback struct.
|
||||
|
||||
Reported-by: B Horn <b@horn.uk>
|
||||
Signed-off-by: B Horn <b@horn.uk>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: 67f70f70a36b6e87a65f928fe1e840a12eafb7ae
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/disk/loopback.c | 18 ++++++++++++++++++
|
||||
include/grub/err.h | 3 ++-
|
||||
2 files changed, 20 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/grub-core/disk/loopback.c b/grub-core/disk/loopback.c
|
||||
index 4635dcfde..2bea4e922 100644
|
||||
--- a/grub-core/disk/loopback.c
|
||||
+++ b/grub-core/disk/loopback.c
|
||||
@@ -24,6 +24,7 @@
|
||||
#include <grub/mm.h>
|
||||
#include <grub/extcmd.h>
|
||||
#include <grub/i18n.h>
|
||||
+#include <grub/safemath.h>
|
||||
|
||||
GRUB_MOD_LICENSE ("GPLv3+");
|
||||
|
||||
@@ -33,6 +34,7 @@ struct grub_loopback
|
||||
grub_file_t file;
|
||||
struct grub_loopback *next;
|
||||
unsigned long id;
|
||||
+ grub_uint64_t refcnt;
|
||||
};
|
||||
|
||||
static struct grub_loopback *loopback_list;
|
||||
@@ -64,6 +66,8 @@ delete_loopback (const char *name)
|
||||
if (! dev)
|
||||
return grub_error (GRUB_ERR_BAD_DEVICE, "device not found");
|
||||
|
||||
+ if (dev->refcnt > 0)
|
||||
+ return grub_error (GRUB_ERR_STILL_REFERENCED, "device still referenced");
|
||||
/* Remove the device from the list. */
|
||||
*prev = dev->next;
|
||||
|
||||
@@ -120,6 +124,7 @@ grub_cmd_loopback (grub_extcmd_context_t ctxt, int argc, char **args)
|
||||
|
||||
newdev->file = file;
|
||||
newdev->id = last_id++;
|
||||
+ newdev->refcnt = 0;
|
||||
|
||||
/* Add the new entry to the list. */
|
||||
newdev->next = loopback_list;
|
||||
@@ -161,6 +166,9 @@ grub_loopback_open (const char *name, grub_disk_t disk)
|
||||
if (! dev)
|
||||
return grub_error (GRUB_ERR_UNKNOWN_DEVICE, "can't open device");
|
||||
|
||||
+ if (grub_add (dev->refcnt, 1, &dev->refcnt))
|
||||
+ grub_fatal ("Reference count overflow");
|
||||
+
|
||||
/* Use the filesize for the disk size, round up to a complete sector. */
|
||||
if (dev->file->size != GRUB_FILE_SIZE_UNKNOWN)
|
||||
disk->total_sectors = ((dev->file->size + GRUB_DISK_SECTOR_SIZE - 1)
|
||||
@@ -178,6 +186,15 @@ grub_loopback_open (const char *name, grub_disk_t disk)
|
||||
return 0;
|
||||
}
|
||||
|
||||
+static void
|
||||
+grub_loopback_close (grub_disk_t disk)
|
||||
+{
|
||||
+ struct grub_loopback *dev = disk->data;
|
||||
+
|
||||
+ if (grub_sub (dev->refcnt, 1, &dev->refcnt))
|
||||
+ grub_fatal ("Reference count underflow");
|
||||
+}
|
||||
+
|
||||
static grub_err_t
|
||||
grub_loopback_read (grub_disk_t disk, grub_disk_addr_t sector,
|
||||
grub_size_t size, char *buf)
|
||||
@@ -220,6 +237,7 @@ static struct grub_disk_dev grub_loopback_dev =
|
||||
.id = GRUB_DISK_DEVICE_LOOPBACK_ID,
|
||||
.disk_iterate = grub_loopback_iterate,
|
||||
.disk_open = grub_loopback_open,
|
||||
+ .disk_close = grub_loopback_close,
|
||||
.disk_read = grub_loopback_read,
|
||||
.disk_write = grub_loopback_write,
|
||||
.next = 0
|
||||
diff --git a/include/grub/err.h b/include/grub/err.h
|
||||
index 1c07034cd..b0e54e0a0 100644
|
||||
--- a/include/grub/err.h
|
||||
+++ b/include/grub/err.h
|
||||
@@ -73,7 +73,8 @@ typedef enum
|
||||
GRUB_ERR_NET_NO_DOMAIN,
|
||||
GRUB_ERR_EOF,
|
||||
GRUB_ERR_BAD_SIGNATURE,
|
||||
- GRUB_ERR_BAD_FIRMWARE
|
||||
+ GRUB_ERR_BAD_FIRMWARE,
|
||||
+ GRUB_ERR_STILL_REFERENCED
|
||||
}
|
||||
grub_err_t;
|
||||
|
||||
--
|
||||
2.50.1
|
||||
|
||||
125
boot/grub2/0021-kern-disk-Limit-recursion-depth.patch
Normal file
125
boot/grub2/0021-kern-disk-Limit-recursion-depth.patch
Normal file
@@ -0,0 +1,125 @@
|
||||
From 195331a7a64c2a4ba754e2527ca8973012db68c9 Mon Sep 17 00:00:00 2001
|
||||
From: B Horn <b@horn.uk>
|
||||
Date: Sun, 12 May 2024 04:09:24 +0100
|
||||
Subject: [PATCH] kern/disk: Limit recursion depth
|
||||
|
||||
The grub_disk_read() may trigger other disk reads, e.g. via loopbacks.
|
||||
This may lead to very deep recursion which can corrupt the heap. So, fix
|
||||
the issue by limiting reads depth.
|
||||
|
||||
Reported-by: B Horn <b@horn.uk>
|
||||
Signed-off-by: B Horn <b@horn.uk>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: 18212f0648b6de7d71d4c8f41eb4d8b78b3a299b
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/kern/disk.c | 27 ++++++++++++++++++++-------
|
||||
include/grub/err.h | 3 ++-
|
||||
2 files changed, 22 insertions(+), 8 deletions(-)
|
||||
|
||||
diff --git a/grub-core/kern/disk.c b/grub-core/kern/disk.c
|
||||
index 1eda58fe9..82e04fd00 100644
|
||||
--- a/grub-core/kern/disk.c
|
||||
+++ b/grub-core/kern/disk.c
|
||||
@@ -28,6 +28,10 @@
|
||||
|
||||
#define GRUB_CACHE_TIMEOUT 2
|
||||
|
||||
+/* Disk reads may trigger other disk reads. So, limit recursion depth. */
|
||||
+#define MAX_READ_RECURSION_DEPTH 16
|
||||
+static unsigned int read_recursion_depth = 0;
|
||||
+
|
||||
/* The last time the disk was used. */
|
||||
static grub_uint64_t grub_last_time = 0;
|
||||
|
||||
@@ -417,6 +421,8 @@ grub_err_t
|
||||
grub_disk_read (grub_disk_t disk, grub_disk_addr_t sector,
|
||||
grub_off_t offset, grub_size_t size, void *buf)
|
||||
{
|
||||
+ grub_err_t err = GRUB_ERR_NONE;
|
||||
+
|
||||
/* First of all, check if the region is within the disk. */
|
||||
if (grub_disk_adjust_range (disk, §or, &offset, size) != GRUB_ERR_NONE)
|
||||
{
|
||||
@@ -427,12 +433,17 @@ grub_disk_read (grub_disk_t disk, grub_disk_addr_t sector,
|
||||
return grub_errno;
|
||||
}
|
||||
|
||||
+ if (++read_recursion_depth >= MAX_READ_RECURSION_DEPTH)
|
||||
+ {
|
||||
+ grub_error (GRUB_ERR_RECURSION_DEPTH, "grub_disk_read(): Maximum recursion depth exceeded");
|
||||
+ goto error;
|
||||
+ }
|
||||
+
|
||||
/* First read until first cache boundary. */
|
||||
if (offset || (sector & (GRUB_DISK_CACHE_SIZE - 1)))
|
||||
{
|
||||
grub_disk_addr_t start_sector;
|
||||
grub_size_t pos;
|
||||
- grub_err_t err;
|
||||
grub_size_t len;
|
||||
|
||||
start_sector = sector & ~((grub_disk_addr_t) GRUB_DISK_CACHE_SIZE - 1);
|
||||
@@ -444,7 +455,7 @@ grub_disk_read (grub_disk_t disk, grub_disk_addr_t sector,
|
||||
err = grub_disk_read_small (disk, start_sector,
|
||||
offset + pos, len, buf);
|
||||
if (err)
|
||||
- return err;
|
||||
+ goto error;
|
||||
buf = (char *) buf + len;
|
||||
size -= len;
|
||||
offset += len;
|
||||
@@ -457,7 +468,6 @@ grub_disk_read (grub_disk_t disk, grub_disk_addr_t sector,
|
||||
{
|
||||
char *data = NULL;
|
||||
grub_disk_addr_t agglomerate;
|
||||
- grub_err_t err;
|
||||
|
||||
/* agglomerate read until we find a first cached entry. */
|
||||
for (agglomerate = 0; agglomerate
|
||||
@@ -493,7 +503,7 @@ grub_disk_read (grub_disk_t disk, grub_disk_addr_t sector,
|
||||
- disk->log_sector_size),
|
||||
buf);
|
||||
if (err)
|
||||
- return err;
|
||||
+ goto error;
|
||||
|
||||
for (i = 0; i < agglomerate; i ++)
|
||||
grub_disk_cache_store (disk->dev->id, disk->id,
|
||||
@@ -527,13 +537,16 @@ grub_disk_read (grub_disk_t disk, grub_disk_addr_t sector,
|
||||
/* And now read the last part. */
|
||||
if (size)
|
||||
{
|
||||
- grub_err_t err;
|
||||
err = grub_disk_read_small (disk, sector, 0, size, buf);
|
||||
if (err)
|
||||
- return err;
|
||||
+ goto error;
|
||||
}
|
||||
|
||||
- return grub_errno;
|
||||
+ err = grub_errno;
|
||||
+
|
||||
+ error:
|
||||
+ read_recursion_depth--;
|
||||
+ return err;
|
||||
}
|
||||
|
||||
grub_uint64_t
|
||||
diff --git a/include/grub/err.h b/include/grub/err.h
|
||||
index b0e54e0a0..202fa8a7a 100644
|
||||
--- a/include/grub/err.h
|
||||
+++ b/include/grub/err.h
|
||||
@@ -74,7 +74,8 @@ typedef enum
|
||||
GRUB_ERR_EOF,
|
||||
GRUB_ERR_BAD_SIGNATURE,
|
||||
GRUB_ERR_BAD_FIRMWARE,
|
||||
- GRUB_ERR_STILL_REFERENCED
|
||||
+ GRUB_ERR_STILL_REFERENCED,
|
||||
+ GRUB_ERR_RECURSION_DEPTH
|
||||
}
|
||||
grub_err_t;
|
||||
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,49 @@
|
||||
From 3f1c5f55e7ef7b872c3ae59c0c41f1e07508a943 Mon Sep 17 00:00:00 2001
|
||||
From: B Horn <b@horn.uk>
|
||||
Date: Sat, 16 Nov 2024 21:24:19 +0000
|
||||
Subject: [PATCH] kern/partition: Limit recursion in part_iterate()
|
||||
|
||||
The part_iterate() is used by grub_partition_iterate() as a callback in
|
||||
the partition iterate functions. However, part_iterate() may also call
|
||||
the partition iterate functions which may lead to recursion. Fix potential
|
||||
issue by limiting the recursion depth.
|
||||
|
||||
Signed-off-by: B Horn <b@horn.uk>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: 8a7103fddfd6664f41081f3bb88eebbf2871da2a
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/kern/partition.c | 10 +++++++++-
|
||||
1 file changed, 9 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/grub-core/kern/partition.c b/grub-core/kern/partition.c
|
||||
index edad9f9e4..704512a20 100644
|
||||
--- a/grub-core/kern/partition.c
|
||||
+++ b/grub-core/kern/partition.c
|
||||
@@ -28,6 +28,9 @@
|
||||
|
||||
grub_partition_map_t grub_partition_map_list;
|
||||
|
||||
+#define MAX_RECURSION_DEPTH 32
|
||||
+static unsigned int recursion_depth = 0;
|
||||
+
|
||||
/*
|
||||
* Checks that disk->partition contains part. This function assumes that the
|
||||
* start of part is relative to the start of disk->partition. Returns 1 if
|
||||
@@ -208,7 +211,12 @@ part_iterate (grub_disk_t dsk, const grub_partition_t partition, void *data)
|
||||
FOR_PARTITION_MAPS(partmap)
|
||||
{
|
||||
grub_err_t err;
|
||||
- err = partmap->iterate (dsk, part_iterate, ctx);
|
||||
+ recursion_depth++;
|
||||
+ if (recursion_depth <= MAX_RECURSION_DEPTH)
|
||||
+ err = partmap->iterate (dsk, part_iterate, ctx);
|
||||
+ else
|
||||
+ err = grub_error (GRUB_ERR_RECURSION_DEPTH, "maximum recursion depth exceeded");
|
||||
+ recursion_depth--;
|
||||
if (err)
|
||||
grub_errno = GRUB_ERR_NONE;
|
||||
if (ctx->ret)
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,60 @@
|
||||
From 2a094a7116c56519a42a13c96e77bdeda6069076 Mon Sep 17 00:00:00 2001
|
||||
From: B Horn <b@horn.uk>
|
||||
Date: Thu, 18 Apr 2024 19:04:13 +0100
|
||||
Subject: [PATCH] script/execute: Limit the recursion depth
|
||||
|
||||
If unbounded recursion is allowed it becomes possible to collide the
|
||||
stack with the heap. As UEFI firmware often lacks guard pages this
|
||||
becomes an exploitable issue as it is possible in some cases to do
|
||||
a controlled overwrite of a section of this heap region with
|
||||
arbitrary data.
|
||||
|
||||
Reported-by: B Horn <b@horn.uk>
|
||||
Signed-off-by: B Horn <b@horn.uk>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: d8a937ccae5c6d86dc4375698afca5cefdcd01e1
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/script/execute.c | 14 ++++++++++++++
|
||||
1 file changed, 14 insertions(+)
|
||||
|
||||
diff --git a/grub-core/script/execute.c b/grub-core/script/execute.c
|
||||
index 14ff09094..e1450f45d 100644
|
||||
--- a/grub-core/script/execute.c
|
||||
+++ b/grub-core/script/execute.c
|
||||
@@ -33,10 +33,18 @@
|
||||
is sizeof (int) * 3, and one extra for a possible -ve sign. */
|
||||
#define ERRNO_DIGITS_MAX (sizeof (int) * 3 + 1)
|
||||
|
||||
+/*
|
||||
+ * A limit on recursion, to avoid colliding with the heap. UEFI defines a baseline
|
||||
+ * stack size of 128 KiB. So, assuming at most 1-2 KiB per iteration this should
|
||||
+ * keep us safe.
|
||||
+ */
|
||||
+#define MAX_RECURSION_DEPTH 64
|
||||
+
|
||||
static unsigned long is_continue;
|
||||
static unsigned long active_loops;
|
||||
static unsigned long active_breaks;
|
||||
static unsigned long function_return;
|
||||
+static unsigned long recursion_depth;
|
||||
|
||||
#define GRUB_SCRIPT_SCOPE_MALLOCED 1
|
||||
#define GRUB_SCRIPT_SCOPE_ARGS_MALLOCED 2
|
||||
@@ -816,7 +824,13 @@ grub_script_execute_cmd (struct grub_script_cmd *cmd)
|
||||
if (cmd == 0)
|
||||
return 0;
|
||||
|
||||
+ recursion_depth++;
|
||||
+
|
||||
+ if (recursion_depth >= MAX_RECURSION_DEPTH)
|
||||
+ return grub_error (GRUB_ERR_RECURSION_DEPTH, N_("maximum recursion depth exceeded"));
|
||||
+
|
||||
ret = cmd->exec (cmd);
|
||||
+ recursion_depth--;
|
||||
|
||||
grub_snprintf (errnobuf, sizeof (errnobuf), "%d", ret);
|
||||
grub_env_set ("?", errnobuf);
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,34 @@
|
||||
From b9a8d2cb984f0a5fd92fe7275dfa280466dd82ce Mon Sep 17 00:00:00 2001
|
||||
From: B Horn <b@horn.uk>
|
||||
Date: Thu, 28 Nov 2024 04:05:04 +0000
|
||||
Subject: [PATCH] net: Unregister net_default_ip and net_default_mac variables
|
||||
hooks on unload
|
||||
|
||||
The net module is a dependency of normal. So, it shouldn't be possible
|
||||
to unload the net. Though unregister variables hooks as a precaution.
|
||||
It also gets in line with unregistering the other net module hooks.
|
||||
|
||||
Signed-off-by: B Horn <b@horn.uk>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
Upstream: a1dd8e59da26f1a9608381d3a1a6c0f465282b1d
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/net/net.c | 2 ++
|
||||
1 file changed, 2 insertions(+)
|
||||
|
||||
diff --git a/grub-core/net/net.c b/grub-core/net/net.c
|
||||
index 8cad4fb6d..f69c67b64 100644
|
||||
--- a/grub-core/net/net.c
|
||||
+++ b/grub-core/net/net.c
|
||||
@@ -2072,6 +2072,8 @@ GRUB_MOD_FINI(net)
|
||||
{
|
||||
grub_register_variable_hook ("net_default_server", 0, 0);
|
||||
grub_register_variable_hook ("pxe_default_server", 0, 0);
|
||||
+ grub_register_variable_hook ("net_default_ip", 0, 0);
|
||||
+ grub_register_variable_hook ("net_default_mac", 0, 0);
|
||||
|
||||
grub_bootp_fini ();
|
||||
grub_dns_fini ();
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,93 @@
|
||||
From 883c8721591c1f7a186e2f3cdc8a4f140bd81ce9 Mon Sep 17 00:00:00 2001
|
||||
From: B Horn <b@horn.uk>
|
||||
Date: Fri, 1 Nov 2024 23:49:48 +0000
|
||||
Subject: [PATCH] net: Remove variables hooks when interface is unregisted
|
||||
|
||||
The grub_net_network_level_interface_unregister(), previously
|
||||
implemented in a header, did not remove the variables hooks that
|
||||
were registered in grub_net_network_level_interface_register().
|
||||
Fix this by implementing the same logic used to register the
|
||||
variables and move the function into the grub-core/net/net.c.
|
||||
|
||||
Signed-off-by: B Horn <b@horn.uk>
|
||||
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
||||
|
||||
Conflicts:
|
||||
grub-core/net/net.c
|
||||
|
||||
Upstream: aa8b4d7facef7b75a2703274b1b9d4e0e734c401
|
||||
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
||||
---
|
||||
grub-core/net/net.c | 33 +++++++++++++++++++++++++++++++++
|
||||
include/grub/net.h | 11 +----------
|
||||
2 files changed, 34 insertions(+), 10 deletions(-)
|
||||
|
||||
diff --git a/grub-core/net/net.c b/grub-core/net/net.c
|
||||
index f69c67b64..8dbb0eada 100644
|
||||
--- a/grub-core/net/net.c
|
||||
+++ b/grub-core/net/net.c
|
||||
@@ -1094,6 +1094,39 @@ grub_cmd_delroute (struct grub_command *cmd __attribute__ ((unused)),
|
||||
return GRUB_ERR_NONE;
|
||||
}
|
||||
|
||||
+void
|
||||
+grub_net_network_level_interface_unregister (struct grub_net_network_level_interface *inter)
|
||||
+{
|
||||
+ char *name;
|
||||
+
|
||||
+ {
|
||||
+ char buf[GRUB_NET_MAX_STR_HWADDR_LEN];
|
||||
+
|
||||
+ grub_net_hwaddr_to_str (&inter->hwaddress, buf);
|
||||
+ name = grub_xasprintf ("net_%s_mac", inter->name);
|
||||
+ if (name != NULL)
|
||||
+ grub_register_variable_hook (name, NULL, NULL);
|
||||
+ grub_free (name);
|
||||
+ }
|
||||
+
|
||||
+ {
|
||||
+ char buf[GRUB_NET_MAX_STR_ADDR_LEN];
|
||||
+
|
||||
+ grub_net_addr_to_str (&inter->address, buf);
|
||||
+ name = grub_xasprintf ("net_%s_ip", inter->name);
|
||||
+ if (name != NULL)
|
||||
+ grub_register_variable_hook (name, NULL, NULL);
|
||||
+ grub_free (name);
|
||||
+ }
|
||||
+
|
||||
+ inter->card->num_ifaces--;
|
||||
+ *inter->prev = inter->next;
|
||||
+ if (inter->next)
|
||||
+ inter->next->prev = inter->prev;
|
||||
+ inter->next = 0;
|
||||
+ inter->prev = 0;
|
||||
+}
|
||||
+
|
||||
grub_err_t
|
||||
grub_net_add_route (const char *name,
|
||||
grub_net_network_level_netaddress_t target,
|
||||
diff --git a/include/grub/net.h b/include/grub/net.h
|
||||
index 844e501c1..228d04963 100644
|
||||
--- a/include/grub/net.h
|
||||
+++ b/include/grub/net.h
|
||||
@@ -540,16 +540,7 @@ void grub_bootp_fini (void);
|
||||
void grub_dns_init (void);
|
||||
void grub_dns_fini (void);
|
||||
|
||||
-static inline void
|
||||
-grub_net_network_level_interface_unregister (struct grub_net_network_level_interface *inter)
|
||||
-{
|
||||
- inter->card->num_ifaces--;
|
||||
- *inter->prev = inter->next;
|
||||
- if (inter->next)
|
||||
- inter->next->prev = inter->prev;
|
||||
- inter->next = 0;
|
||||
- inter->prev = 0;
|
||||
-}
|
||||
+void grub_net_network_level_interface_unregister (struct grub_net_network_level_interface *inter);
|
||||
|
||||
void
|
||||
grub_net_tcp_retransmit (void);
|
||||
--
|
||||
2.50.1
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user