Compare commits

...

147 Commits

Author SHA1 Message Date
Raphaël Mélotte
110319c4a9 {linux, linux-headers}: bump 6.18.x series
Update the latest kernel releases to:
 - 6.18.53 -> 6.18.54

Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-10-01 08:56:03 +02:00
Bernd Kuhls
ec1365f66b package/asterisk: bump bundled pjsip to 2.17
Buildroot commit 7f48325de6 bumped the
asterisk package from 22.9.0 to 22.10.1.

This bump includes upstream commit
5d543ad80c
which bumped the bundled pjsip package to 2.17.

To allow offline builds we download the pjsip tarball so we need to keep
the version numbers in sync.

The autobuilders logs show a download process:
https://autobuild.buildroot.net/results/400/400e53158f11926446c11d22681eb8a9430caf1d/build-end.log

checking for embedded pjproject (may have to download)... configuring
[pjproject]  Downloading https://raw.githubusercontent.com/asterisk/third-party/master/pjproject/2.17/pjproject-2.17.tar.bz2 to
               /home/autobuild/autobuild/instance-3/dl/asterisk/pjproject-2.17.tar.bz2
[pjproject]  Verifying /home/autobuild/autobuild/instance-3/dl/asterisk/pjproject-2.17.tar.bz2

where the tarball was once stored in the configured download directory:

  --with-download-cache=$(ASTERISK_DL_DIR)

to be used during later autobuilder runs.

Fixes: 7f48325de6 ("package/asterisk: security bump to 22.10.1")
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
[Thomas: add comment in .mk file]
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 96a2337bd4)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 16:30:08 +02:00
Giulio Benetti
6b94ee9448 package/wireshark: security bump to v4.4.19
Fixes the following vulnerabilities:

- wnpa-sec-2026-93 · SCTP protocol dissector crash.
  https://www.wireshark.org/security/wnpa-sec-2026-93
  CVE-2026-95389.

- wnpa-sec-2026-96 · IEEE C37.118 Synchrophasor protocol dissector
  memory leak.
  https://www.wireshark.org/security/wnpa-sec-2026-96
  CVE-2026-95395.

- wnpa-sec-2026-97 · SPDY protocol dissector crash.
  https://www.wireshark.org/security/wnpa-sec-2026-97
  CVE-2026-95387.

- wnpa-sec-2026-98 · Microsoft Network Monitor file parser large loop.
  https://www.wireshark.org/security/wnpa-sec-2026-98
  CVE-2026-95394.

- wnpa-sec-2026-99 · CSN.1 protocol dissector crash.
  https://www.wireshark.org/security/wnpa-sec-2026-99
  CVE-2026-95393.

- wnpa-sec-2026-100 · MBIM protocol dissector crash. wsbuglink:21549,
  https://www.wireshark.org/security/wnpa-sec-2026-100
  CVE-2026-95392.

- wnpa-sec-2026-101 · Sharkd utility crash.
  https://www.wireshark.org/security/wnpa-sec-2026-101
  CVE-2026-95388.

- wnpa-sec-2026-102 · Frame protocol metadissector crash.
  https://www.wireshark.org/security/wnpa-sec-2026-102
  CVE-2026-96422.

- wnpa-sec-2026-103 · USB HID protocol dissector infinite loop and
  memory leak.
  https://www.wireshark.org/security/wnpa-sec-2026-103
  CVE-2026-96421.

- wnpa-sec-2026-104 · RF4CE protocol dissector crash.
  https://www.wireshark.org/security/wnpa-sec-2026-104
  CVE-2026-96417.

- wnpa-sec-2026-105 · Toshiba file parser crash.
  https://www.wireshark.org/security/wnpa-sec-2026-105
  CVE-2026-xxx.

- wnpa-sec-2026-106 · Profile import crash and possible code execution.
  https://www.wireshark.org/security/wnpa-sec-2026-106
  CVE-2026-96419.

- wnpa-sec-2026-107 · TIFF protocol dissector infinite loop.
  https://www.wireshark.org/security/wnpa-sec-2026-107
  CVE-2026-96418.

- wnpa-sec-2026-108 · X11 protocol dissector crash.
  https://www.wireshark.org/security/wnpa-sec-2026-108
  CVE-2026-96423.

- wnpa-sec-2026-109 · IEEE 802.11 protocol dissector crash.
  https://www.wireshark.org/security/wnpa-sec-2026-109
  CVE-2026-96416.

- wnpa-sec-2026-110 · Catapult DCT2000 protocol dissector crash.
  https://www.wireshark.org/security/wnpa-sec-2026-110
  CVE-2026-96415.

For more information on the version bump, see:
  - https://www.wireshark.org/docs/relnotes/wireshark-4.4.19.html

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 633d368bae)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 16:29:56 +02:00
Peter Seiderer
36df8e9c46 package/ntpsec: security bump version to 1.2.5
Fixes: CVE-2026-18321:
https://nvd.nist.gov/vuln/detail/cve-2026-18321

- bump version to 1.2.5 (for details see [1])
- rebased 0001-wscript-remove-checks-for-bsd-string.h-fixes-host-co.patch
- rebased 0002-disable-PIE-support.patch
- removed 0003-ntpd-refclock_gpsd.c-Add-missing-time.h-for-strptim.patch
  (from upstream [2])
- moved 0004-refclock_gpsd-add-build-fix-for-gcc-14.x.patch to
  0003-refclock_gpsd-add-build-fix-for-gcc-14.x.patch, rebased and enhanced
  as the original conflicts with upstream commit 5505260c ("Fix redefined
  _XOPEN_SOURCE warning in refclock_gpsd.c") [3] and leads to the following
  compile failure:

    ../../ntpd/refclock_gpsd.c:113:21: error: operator ‘<’ has no left operand
      113 |   #if _XOPEN_SOURCE < 700
          |                     ^

[1] https://lists.ntpsec.org/pipermail/devel/2026-July/011029.html
[2] 5137c155d8
[3] 5505260cd1

Signed-off-by: Peter Seiderer <ps.report@gmx.net>
[Julien: mark commit as "security bump"]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 1caeb632a6)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 16:10:45 +02:00
Bernd Kuhls
328e2e7a80 package/php: security bump version to 8.5.11
https://news-web.php.net/php.announce/506
https://www.php.net/ChangeLog-8.php#8.5.11
https://github.com/php/php-src/blob/php-8.5.11/NEWS

Fixes CVE-2025-1218, CVE-2025-14181, CVE-2026-6103, CVE-2026-17545,
CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768,
CVE-2026-91769, CVE-2026-92842 & CVE-2026-93682.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit f07eeff6df)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 16:09:45 +02:00
Adrian Perez de Castro
52c50abcd0 package/bubblewrap: security bump to version 0.13.0
While there are no CVEs for this Bubblewrap release, it includes a fix
to ensure that arguments that receive a path are not empty (which before
treated those as the root directory: a bit of a footgun!), and that is a
follow-up to the security fixes included in 0.12.0.

Additionally, it patches a number of build failures, which fixes e.g.:

  https://autobuild.buildroot.org/results/2eb2d222daaadc2eb16b42fa2ec102ab0689f038
  https://autobuild.buildroot.org/results/674413f089ce9b80a59058674b3ef6879e1d389c

Release notes:

  https://github.com/containers/bubblewrap/releases/tag/v0.13.0

Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 0867818a73)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 16:08:49 +02:00
Bernd Kuhls
ad6468b543 package/flutter-engine: fix build with pango >= 1.58.0
Buildroot commit c3aa677456 bumped pango
to 1.58.0 causing a build error with flutter-engine

../../flutter/shell/platform/linux/fl_accessible_text_field.cc:9:1:
 error: redefinition of 'glib_autoptr_clear_PangoContext'
    9 | G_DEFINE_AUTOPTR_CLEANUP_FUNC(PangoContext, g_object_unref)

../../flutter/shell/platform/linux/fl_accessible_text_field.cc:60:3:
 error: 'cleanup' argument is not a function
   60 |   g_autoptr(PangoContext) context = get_pango_context(self);

with this defconfig:

BR2_x86_64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_PACKAGE_MESA3D=y
BR2_PACKAGE_MESA3D_GALLIUM_DRIVER_SOFTPIPE=y
BR2_PACKAGE_MESA3D_OPENGL_EGL=y
BR2_PACKAGE_MESA3D_OPENGL_ES=y
BR2_PACKAGE_FLUTTER_ENGINE=y
BR2_PACKAGE_LIBGTK3=y

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 08b06173bd)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 16:08:22 +02:00
Bernd Kuhls
cfdd030bfe package/tor: security bump version to 0.4.9.13
https://gitlab.torproject.org/tpo/core/tor/-/blob/tor-0.4.9.13/ReleaseNotes

TROVE-2026-012, TROVE-2026-030, TROVE-2026-038, TROVE-2026-041,
TROVE-2026-050, TROVE-2026-051, TROVE-2026-052, TROVE-2026-053,
TROVE-2026-056 & TROVE-2026-058.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit dc5cb8f02d)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 16:08:05 +02:00
Bernd Kuhls
d852986d65 package/expat: security bump version to 2.8.5
https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/Changes
https://blog.hartwork.org/posts/expat-2-8-5-released/

Fixes CVE-2026-93990.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 67380a32f7)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 16:08:01 +02:00
Michael Fischer
2217b0b2c3 package/sdl3_image: security bump to version 3.4.6
For release notes, see:
https://github.com/libsdl-org/SDL_image/releases

3.1.1 was a preview release. Among the changes since, it fixes the XCF
loader issue reported as CVE-2026-35444 (fixed in 3.4.2). See:
https://github.com/libsdl-org/SDL_image/releases/tag/release-3.4.2

The LICENSE.txt hash changes because the copyright year was updated
upstream. The license itself is unchanged (Zlib).

Signed-off-by: Michael Fischer <mf@go-sys.de>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 74fe3559d6)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 16:07:53 +02:00
Julien Olivain
cb17178ea6 .checkpackageignore: remove entry for mrouted package
Buildroot commit [1] (package/mrouted: fix invalid daemon path in
S41mrouted) removed script execution permission but forgot to remove
the corresponding .checkpackage entry.

check-package is reporting the error:

    package/mrouted/S41mrouted:0: NotExecutable was expected to fail, did you fix the file and forget to update /builds/buildroot.org/buildroot/.checkpackageignore?

This commit fixes the issue by removing the entry.

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16661195972

[1] d8f408b1f1

Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit e2b81003a4)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 16:07:47 +02:00
Joachim Wiberg
a080b40e2f package/mrouted: fix invalid daemon path in S41mrouted
S41mrouted hard-coded /sbin/mrouted, but mrouted has always installed
to /usr/sbin/mrouted. This went unnoticed with BR2_ROOTFS_MERGED_USR=y,
but the daemon fails to start without it.

Also drop the script's executable bit to match other sysv init
scripts that do not set it.

Introduced in c25115daf2
(package/mrouted: add sysv init script).

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit d8f408b1f1)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 16:07:39 +02:00
Fiona Klute
6a4a0b32f0 package/kbd: fix static build with uClibc
Since upstream commit 7fdd8debe37ae52812b77d82e08713bd62c607f4 [1]
(included from release 2.9.0) libkbdfile unconditionally includes
dlfcn.h. uClibc provides this header only if shared library support is
enabled [2], so building kbd fails if BR2_TOOLCHAIN_BUILDROOT_UCLIBC=y
and BR2_STATIC_LIBS=y (BR2_SHARED_STATIC_LIBS=y works).

The issue has been fixed upstream [3], backport the patch.

[1] https://git.kernel.org/pub/scm/linux/kernel/git/legion/kbd.git/commit/?id=7fdd8debe37ae52812b77d82e08713bd62c607f4
[2] https://github.com/wbx-github/uclibc-ng/blob/v1.0.59/Makefile.in#L260
[3] https://github.com/legionus/kbd/issues/159

Fixes: 930660890b
Fixes: https://autobuild.buildroot.org/results/872d12bf869717ae8aec9a2ed6295cf8f7e8b098/
Fixes: https://autobuild.buildroot.org/results/056b5fe4ca230989041a1ed166c1b509f8bb0908/

Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 7eede98528)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 16:07:29 +02:00
Koen Martens
0dd1e48c4d DEVELOPERS: remove Koen Martens from capnproto and linuxconsoletools
I have left the field of software engineering and will no longer
contribute.

Signed-off-by: Koen Martens <gmc@sonologic.nl>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
(cherry picked from commit 81060d467f)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 16:07:17 +02:00
Yann E. MORIN
3f0be30e3c package/skopeo: use new upstream location
The upstream location has changed (with a forward from the old one, so
we did not notice earlier) [0] [1], with 1.23.0 the first release being
made from the new location, which was accounted for in 96aac440dd
(package/skopeo: bump version to 1.23.0) as it required the change of
the gomod, but where the new location was missed.

Eventually switch to the new location now.

[0] https://github.com/podman-container-tools/skopeo/pull/2854
[1] https://github.com/podman-container-tools/go.podman.io/pull/6

Reported-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Yann E. MORIN <yann.morin@orange.com>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
(cherry picked from commit a489e7c212)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 16:06:12 +02:00
Yann E. MORIN
b0bb3ff02d package/skopeo: security bump to version 1.24.1
Changelog:
https://github.com/podman-container-tools/skopeo/releases/tag/v1.24.1

This releases brings in a fix for:
* CVE-2025-11395

Signed-off-by: Yann E. MORIN <yann.morin@orange.com>
[Julien: add info in commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit b2c69fe0a4)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 14:45:39 +02:00
Bernd Kuhls
f5ab048dae package/skopeo: bump version to 1.24.0
https://github.com/podman-container-tools/skopeo/releases/tag/v1.24.0

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit be60575e60)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 14:45:33 +02:00
Yann E. MORIN
2e52ae72a2 package/distribution-registry: security bump to version 3.1.1
Changelog since v3.0.0:
https://github.com/distribution/distribution/releases/tag/v3.1.0
https://github.com/distribution/distribution/releases/tag/v3.1.1

This feature-release also contains security fixes:
* CVE-2026-35172
* CVE-2026-33540
* CVE-2026-41888

Drop our backported patch, included since 3.1.0

Signed-off-by: Yann E. MORIN <yann.morin@orange.com>
[Julien: add info in commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 02cc32ee5c)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-30 14:44:44 +02:00
Bernd Kuhls
b7a2b163f6 package/qt6: security bump version to 6.11.2
https://code.qt.io/cgit/qt/qtreleasenotes.git/about/qt/6.11.2/release-note.md

Security fixes:
CVE-2026-16762 in qtbase
CVE-2026-19248 in qtbase
CVE-2026-13326 in qtconnectivity
CVE-2026-8168 in qtsvg

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 43de288bd1)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:39:05 +02:00
Yegor Yefremov
7e523d398d package/stunnel: fix build on ARM Thumb-1
stunnel's configure unconditionally probes -fstack-clash-protection
using AX_APPEND_COMPILE_FLAGS. The probe compiles a trivial conftest.c,
which succeeds, so the flag ends up in CFLAGS. However, on ARM Thumb-1
gcc implements stack clash protection through -fstack-check=specific,
which it refuses for any real function body, so every source file fails
to build:

  stunnel.c:1003:1: sorry, unimplemented: '-fstack-check=specific' for Thumb-1

Force the corresponding autoconf cache variable to "no" on Thumb-1, in
the same way cmocka already works around this gcc limitation, and
consistently with the existing -fstack-protector-strong override.

Fixes:
https://autobuild.buildroot.org/results/3d691184ba83ba4d881632f2b2bb4da5aa50f491/

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 15ccf339c9)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:38:54 +02:00
Bernd Kuhls
2135ddb20d package/vboot-utils: fix build with OpenSSL >= 3.x
Remove -Werror from CFLAGS to prevent build errors due to warnings of
deprecated functions:

futility/cmd_create.c: In function ‘vb1_make_keypair’:
futility/cmd_create.c:96:9: error: ‘PEM_read_RSAPrivateKey’ is deprecated:
 Since OpenSSL 3.0 [-Werror=deprecated-declarations]
   96 |         rsa_key = PEM_read_RSAPrivateKey(fp, NULL, NULL, NULL);

futility/cmd_create.c:155:9: error: ‘RSA_free’ is deprecated:
 Since OpenSSL 3.0 [-Werror=deprecated-declarations]
  155 |         RSA_free(rsa_key);

futility/cmd_create.c:191:17: error: ‘PEM_read_RSA_PUBKEY’ is deprecated:
 Since OpenSSL 3.0 [-Werror=deprecated-declarations]
  191 |                 rsa_key = PEM_read_RSA_PUBKEY(fp, NULL, NULL, NULL);

futility/cmd_create.c:199:9: error: ‘RSA_get0_key’ is deprecated:
 Since OpenSSL 3.0 [-Werror=deprecated-declarations]
  199 |         RSA_get0_key(rsa_key, NULL, NULL, &rsa_d);

cc1: all warnings being treated as errors

The oldest build error dates back to 2024 so a backport to LTS branches
should be considered.

Fixes:
https://autobuild.buildroot.net/results/375/37554c5ce784835a36f0068d9a0c1cd931212b44/
https://autobuild.buildroot.net/results/1fa/1fabca11c7839d2d7ed809f30482595719a29c92/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 4463009364)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:38:48 +02:00
Bernd Kuhls
064d5eee96 package/jemalloc: fix build with gcc 16.x
Fixes:
https://autobuild.buildroot.net/results/6fb/6fbebb76cb0e6cafabad0890b8df226e9358a6c3/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 7253d50c82)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:38:41 +02:00
Bernd Kuhls
791b2d0794 package/ibrcommon: update patches
Replaced patch 0001 with an upstream commit.

Added Upstream: tags to patches 0002 & 0003.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit e4d9ab154e)
[raphael: resolve conflicts in .checkpackageignore]
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:38:05 +02:00
Michael Nosthoff
0d1e5de8f9 package/boost: remove dependencies on Boost.DateTime
Boost.DateTime is header-only since 1.77.0
The Boost Release Notes[0] didn't mention it but it was introduced in
the documentation of DateTime in this commit: [1]

This was bumped in buildroot in d39d8f7cee

So analog to the "header-only" move of Boost.System we have now to
gradually phase out the dependencies on this library. Ideally before
the stub is removed as it now happened for Boost.System in 1.89.0.

[0] https://www.boost.org/releases/1.77.0/
[1] 33dc6136f1

Signed-off-by: Michael Nosthoff <buildroot@heine.tech>
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit a235a33cfe)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:36:27 +02:00
Franciszek Stachura
96ebd14506 support/scripts/pkg-stats: sort latest version by state
pkg-stats columns are sorted either alphabetically or numerically. This
does not make much sense for the "Latest version" column.
This commit orders the column by whether the package is up-to-date or
not.

Signed-off-by: Franciszek Stachura <fbstachura@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 95b1e8676c)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:36:21 +02:00
Shubham Chakraborty
7f43f54232 package/libmpeg2: fix build with C23 compilers
libmpeg2 contains code using K&R-style empty parameter list
declarations, which no longer builds with C23 compilers.

This causes issues with:

- GCC >= 15.x, which defaults to C23

- GCC 14.x, since the bump of autoconf to 2.73 in commit
  a6e8c07a33, as it causes -std=c23 to
  be added in the CFLAGS by the autoconf machinery. This doesn't
  happen with GCC 13.

Fixes:

  http://autobuild.buildroot.net/results/53daf0b4bd8b476252ca219e53a966405ece7e51

Signed-off-by: Shubham Chakraborty <chakrabortyshubham66@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 8f472d08d8)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:36:02 +02:00
Bernd Kuhls
53d6021990 package/{glibc, localedef}: security bump version to 2.44-48-g1f5026241
Fixes CVE-2026-8674:
1f50262410

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 7162c4daa5)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:35:30 +02:00
Julien Olivain
039194046b support/testing: test_squid: new runtime test
Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 45eccf764a)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:34:18 +02:00
Alexis Lothoré
303a5a2004 support/testing: add tests for openscap
Add basic tests for openscap, ensuring that it builds and runs a minimal
command with different cryptographic backends:
- libgcrypt
- libnss
- no crypto backend

Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit a304c7bf12)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:34:13 +02:00
Alexis Lothoré
680074eeb1 package/openscap: allow building when crypto backend is not gcrypt
When enabling the openscap package and the libnss library _but not_
libgcrypt, the build can fail on the following error:

  ../src/libopenscap.so.33.1.3: undefined reference to `crapi_init'

The issue is due to the fact that the corresponding Makefile
systematically forces -DWITH_CRYPTO=gcrypt: openscap CMake
instrumentation then searches only this backend, fails to find it,
assumes that no crypto backend is available, and so does not include the
crapi_object in the final link step.

Commit 7c85f3adf4 ("package/openscap: new package") took into account
the fact that openscap isn't currently able to build if no crypto backend
is provided (see [0]), and so made sure to force libgcrypt inclusion if
libnss is not included. Since then, two fixes ([1] and [2]) have been
integrated upstream to allow building openscap with any backend.

Do not systematically enforce libgcrypt anymore through WITH_CRYPTO:
rather than testing nss presence, and falling back to libgcrypt, allow
both to be absent, and so relax the libgcrypt dependency to make it
optional as well. Bring the two upstream patches allowing openscap build
without any crypto backend.  Those patches can be dropped once openscap
v1.4.5 is released.

[0] https://github.com/OpenSCAP/openscap/issues/2310
[1] d12d820a94
[2] 5b858d1786

Fixes: https://autobuild.buildroot.org/results/4c905c1b0ee384149c3d85e8f2ebf0af3a12c2ad/
Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit c24ae7f2f1)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:34:04 +02:00
Sebastian Michel
c05c6ca99a package/sound-theme-borealis: add missing license information
Signed-off-by: Sebastian Michel <sebastian.michel@oss.othermo.de>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 9a9ed35b56)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:33:34 +02:00
Sebastian Michel
e776f72514 package/mali-t76x: add missing license information
Added MALI_T76X_STRIP_COMPONENTS = 0 as tar archive follows nonstandard layout with license file being in the topmost directory

Signed-off-by: Sebastian Michel <sebastian.michel@oss.othermo.de>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit a4346a3858)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:33:27 +02:00
Thomas Petazzoni
18f78bdd52 package/screen: install screenrc without executable rights
There is no reason to install a configuration file in /etc with
executable rights.

Fixes: https://gitlab.com/buildroot.org/buildroot/-/work_items/174
Fixes: 98873717c2 ("screen: enable terminfo and install screenrc")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 318d4ce4e5)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:33:21 +02:00
Thomas Petazzoni
79c0acaa2d package/gnuradio: show Config.in comment only when needed
The comment about the toolchain requirements to have Python support in
gnuradio is always displayed, even if architecture requirements are
not met and if Python is not enabled. For the latter: the option
BR2_PACKAGE_GNURADIO_PYTHON also depends on python, so it makes sense
for the Config.in comment to also depend on it.

Fixes: 7a546b87d5 ("package/python-numpy: add reverse dependency on packages using python-numpy")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit fbb9739dd8)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:33:15 +02:00
Thomas Petazzoni
76818c5a85 package/gnuradio: fix dependencies of BR2_PACKAGE_GNURADIO_PYTHON
BR2_PACKAGE_GNURADIO_PYTHON selects BR2_PACKAGE_PYTHON_NUMPY, so it
should inherit its dependencies, but BR2_TOOLCHAIN_GCC_AT_LEAST_9 was
forgotten in commit 8b3993178d, when
python-numpy got this gcc >= 9 dependency added.

Note that the existing BR2_HOST_GCC_AT_LEAST_9 dependency is correct:
it is there because gnuradio needs host-python-numpy at build time.

Fixes: 8b3993178d ("package/python-numpy: needs gcc >= 9")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit c6986e6d2e)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:33:09 +02:00
Thomas Petazzoni
8ad879736e package/tensorflow-lite: fix Config.in comment
This commit fixes 3 issues in the Config.in comment:

- It is displayed even on unsupported CPU architectures, so we add a
  "depends on BR2_PACKAGE_TENSORFLOW_LITE_ARCH_SUPPORTS"

- It doesn't mention the need for a glibc toolchain even though that's
  part of the dependencies

- The requirement for dynamic lib support should be part of the same
  comment as the other dependencies

Fixes: fd29fee3a3 ("package/tensorflow-lite: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 101d543e38)
[raphael: resolve conflicts]
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:32:12 +02:00
Thomas Petazzoni
08e14ffaa8 package/tensorflow-lite: propagate libabseil-cpp dependency
BR2_PACKAGE_TENSORFLOW_LITE selects BR2_PACKAGE_LIBABSEIL_CPP without
propagating its depends on BR2_PACKAGE_LIBABSEIL_CPP_ARCH_SUPPORTS,
which this commit fixes.

Note that this doesn't create any functional change: tensorflow-lite
is anyway limited to ARM, ARM64, x86 32-bit and x86 64-bit, all of
which are supported by libabseil-cpp.

Fixes: fd29fee3a3 ("package/tensorflow-lite: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit f5a2b35531)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:24:35 +02:00
Thomas Petazzoni
1caa3a3c22 package/rpi-rgb-led-matrix: propagate ffmpeg dependency
BR2_PACKAGE_RPI_RGB_LED_MATRIX_VIDEO_VIEWER selects
BR2_PACKAGE_FFMPEG, but without propagating its depends on, and most
notably BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS.

Fixes: e821078031 ("package/rpi-rgb-led-matrix: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 0fbbe6b681)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:24:24 +02:00
Thomas Petazzoni
2694270690 package/libgtk3: add missing !BR2_STATIC_LIBS dependency
libgtk3 selects at-spi2-core, so it should inherit its
!BR2_STATIC_LIBS, which this commit does.

This has been an issue since libgtk3 started using at-spi2-core
instead of atk in commit 2c3ca7bea1.

Fixes: 2c3ca7bea1 ("package/atk: remove package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 93282f76a5)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:24:14 +02:00
Bernd Kuhls
3ca2623690 package/ghostscript: security bump to version 10.08.0
https://ghostscript.readthedocs.io/en/gs10.08.0/News.html
"This release addresses a number of potential security issues."

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 458441ad76)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:24:01 +02:00
Bernd Kuhls
900a64b2fc package/ghostscript: link with libatomic if needed
Fixes:
https://autobuild.buildroot.net/results/eed/eed88a2a77cb8c4ff8c59bac5091221e6873004c/

The build error occurs since 2024 so a backport to LTS branches should
be considered:
https://autobuild.buildroot.net/results/1ab/1ab4767c1198838c3e3d126cdba790197d102053/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 9c0385972d)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:23:55 +02:00
Bernd Kuhls
c18415c2d9 package/unbound: security bump version to 1.26.1
https://nlnetlabs.nl/projects/unbound/download/#unbound-1-26-1

Fixes CVE-2026-81642, CVE-2026-81634, CVE-2026-82717, CVE-2026-77955,
CVE-2026-78227, CVE-2026-80225, CVE-2026-82720, CVE-2026-85501 &
CVE-2026-77860.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 098be4f99a)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:23:44 +02:00
Bernd Kuhls
a2d0ad8ca1 package/unbound: bump version to 1.26.0
https://nlnetlabs.nl/projects/unbound/download/#unbound-1-26-0

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 531be778bd)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:23:32 +02:00
Bernd Kuhls
4a11b107c0 package/exim: security bump version to 4.100.1
https://lists.exim.org/lurker/message/20260918.121220.0f87338e.en.html

Contains the following security fixes:

* GCVE-25-2026-09-50-1
* GCVE-25-2026-09-51-1
* GCVE-25-2026-09-55-1
* GCVE-25-2026-09-56-1

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 267db9da2b)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:23:04 +02:00
Laszlo Ersek
0897fac6ac linux/linux.mk: forcibly (re)enable Make jobserver for linux-rebuild-with-initramfs target
Commit 0b9efc991f ("linux: use BR2_MAKE", 2023-04-10) replaced $(MAKE)
with $(BR2_MAKE) in a number of recipes. As a consequence, the child
make is unable to discover the job server, in some cases. In those
cases, we get a warning such as:

> warning: jobserver unavailable: using -j1. Add `+' to parent make rule.

See [1] and [2].

Falling back to single job can make build considerably longer.
This longer build time issue can be reproduced in specific
conditions. This situation happens when:

1. The top GNU Make is using a "pipe" jobserver.
   This is the default when GNU Make <= 4.3 is used (and v4.3 is the
   version inside the current Buildroot Docker reference image).
   Make > 4.3 changed the default jobserver style to "fifo".
   See [3][4]. With Make > 4.3, the issue can be reproduced by
   calling "make --jobserver-style=pipe ...".
2. The root filesystem is an initramfs linked into the Kernel
  (i.e. using the config BR2_TARGET_ROOTFS_INITRAMFS=y)
3. Buildroot per-package directories is used
  (i.e. using the config BR2_PER_PACKAGE_DIRECTORIES=y)
4. The build is made in parallel, with 2 or more jobs. For example:
   make -j$(nproc)

Overall, the issue can be reproduced with the commands:

utils/docker-run
cat >.config <<EOF
BR2_aarch64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_PER_PACKAGE_DIRECTORIES=y
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_USE_ARCH_DEFAULT_CONFIG=y
BR2_TARGET_ROOTFS_INITRAMFS=y
EOF
make olddefconfig
make -j$(nproc)

The Linux Kernel is built once (with a fake empty initramfs cpio
image), when build log is showing ">>> linux 7.2.6 Building". Then,
at the end of the Buildroot build, once the CPIO filesystem is
complete, it is integrated inside the Kernel with an extra "make"
invocation when the build log shows
">>>   Rebuilding kernel with initramfs".

This second kernel "make" is not expected to rebuild the whole
kernel, since compiled objects from the first compilation are still
here. However, in the described conditions, the second kernel is
fully rebuilt. This is an undesired behaviour. The Make jobserver
issue adds up to that: this second full kernel is rebuilt with only
one job, which can significantly increase the build time.

Running the previous example on a host with 128 CPUs:
without this change, build takes 1h5m,
with this change, build takes 7m.

Note: using GNU Make >= 4.4 (with a fifo jobserver style by default)
or removing per-package directories no longer produces the issue.
For reference, running the example, without this change and without
per-package directories on the same host, the build takes 10 mins.

This commit improves the situation by prefixing the recipe with "+",
to inform the parent Make that $(BR2_MAKE) can deal with the job
server. This will give a chance to do jobs in parallel, in general.

Note: the pkg-generic.mk infra already has '+' for _BUILD_CMDS, which is
why other $(BR2_MAKE) invocations in linux.mk does not need this '+'.
See [5].

[1] https://www.gnu.org/software/make/manual/html_node/Error-Messages.html
[2] https://www.gnu.org/software/make/manual/html_node/MAKE-Variable.html
[3] https://www.gnu.org/software/make/manual/html_node/Options-Summary.html#index-_002d_002djobserver_002dstyle
[4] https://cgit.git.savannah.gnu.org/cgit/make.git/commit/?id=7ad2593b2d2bb5b9332f4444d8bf93ac6f958bc6
[5] 069b33a30e

Cc: Arnout Vandecappelle <arnout@mind.be>
Cc: Oleg Lyovin <ovlevin@sberdevices.ru>
Cc: buildroot@buildroot.org
Signed-off-by: Laszlo Ersek <laszlo.ersek@arm.com>
[Julien: extend commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 86a56dcc17)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:22:53 +02:00
Yegor Yefremov
7011d82a34 package/python-grpcio: disable for the MIPS n32 ABI
python-grpcio builds its own bundled copy of abseil-cpp, which only
implements DirectMmap() with mmap2 for the o32 ABI on MIPS:

    #if ... (defined(__mips__) && _MIPS_SIM == _MIPS_SIM_ABI32) || ...

With the n32 ABI, the "remaining 64-bit architectures" fallback is
selected instead, which fails to build because long is 32-bit there:

    third_party/abseil-cpp/absl/base/internal/direct_mmap.h:130:39:
        error: static assertion failed: Platform is not 64-bit
      130 |   static_assert(sizeof(unsigned long) == 8, "Platform is not 64-bit");
          |                 ~~~~~~~~~~~~~~~~~~~~~~^~~~
    third_party/abseil-cpp/absl/base/internal/direct_mmap.h:130:39:
        note: the comparison reduces to '(4 == 8)'

This is the same defect fixed for libabseil-cpp in the previous patch,
but the dependency added there does not help here: python-grpcio does
not use the Buildroot abseil, it compiles the copy bundled in the
tarball.

Using the Buildroot-provided abseil instead is not an option today.
setup.py does have a GRPC_PYTHON_BUILD_SYSTEM_ABSL knob, but it is
hardcoded to the build machine paths:

    if BUILD_WITH_SYSTEM_ABSL:
        CORE_C_FILES = filter(
            lambda x: "third_party/abseil-cpp" not in x, CORE_C_FILES
        )
        ABSL_INCLUDE = (os.path.join("/usr", "include"),)
    [...]
    if BUILD_WITH_SYSTEM_ABSL:
        EXTENSION_LIBRARIES += tuple(
            lib.stem[3:]
            for lib in sorted(pathlib.Path("/usr").glob("lib*/libabsl_*.so"))
        )

i.e. it would pick up the host headers and host libraries, so it cannot
be used when cross-compiling without patching setup.py. And even with
such a patch it would not fix this build failure, since Buildroot's
abseil has the very same limitation.

So just disable the package for the n32 ABI. The o32 and n64 ABIs are
unaffected. Note that n32 is the default ABI for BR2_mips64/BR2_mips64el,
so this affects every mips64 build that does not explicitly select n64.

For the LTS maintainers: python-grpcio gained MIPS support in commit
2bfad952c3, released in 2024.02, and the autobuilders have been hitting
this ever since, already with grpcio 1.60.0, the version shipped in
2024.02:

    https://autobuild.buildroot.net/results/e6cb7f473a28af8b53e7cbb8d8a582adffdeb66e/

It is still reproduced on 2025.02.x:

    https://autobuild.buildroot.net/results/9cf98bff7ce05262d6ff4221953901ae5543880e/

so a backport is needed there.

Fixes: 2bfad952c3 ("package/python-grpcio: add BR2_PACKAGE_PYTHON_GRPCIO_ARCH_SUPPORTS")
Fixes:
https://autobuild.buildroot.net/results/90405c0a3d0b2e929d5074305906e6fe3679298c/

Assisted-by: Claude:claude-opus-5
Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit d4c13e96cf)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:22:31 +02:00
Yegor Yefremov
6ba2f6c745 package/libabseil-cpp: disable for the MIPS n32 ABI
absl::base_internal::DirectMmap() only implements mmap() via mmap2 for
the o32 ABI on MIPS:

    #if ... (defined(__mips__) && _MIPS_SIM == _MIPS_SIM_ABI32) || ...

With the n32 ABI, the "remaining 64-bit architectures" fallback is
selected instead, which fails to build because long is 32-bit there:

    absl/base/internal/direct_mmap.h: In function 'void* absl::lts_20260107::base_internal::DirectMmap(void*, size_t, int, int, int, off_t)':
    absl/base/internal/direct_mmap.h:130:39: error: static assertion failed: Platform is not 64-bit
      130 |   static_assert(sizeof(unsigned long) == 8, "Platform is not 64-bit");
          |                 ~~~~~~~~~~~~~~~~~~~~~~^~~~
    absl/base/internal/direct_mmap.h:130:39: note: the comparison reduces to '(4 == 8)'

direct_mmap.h is included by absl/base/internal/low_level_alloc.cc and
absl/base/internal/poison.cc, which are always built, so the failure is
unconditional. Upstream abseil has no support for the n32 ABI, so
disable the package for that ABI.

Since n32 is the default ABI for BR2_mips64/BR2_mips64el, this affects
every mips64 build that does not explicitly select n64. The o32
(BR2_MIPS_OABI32) and n64 (BR2_MIPS_NABI64) ABIs are unaffected, and all
in-tree mips64 defconfigs use n64.

For the LTS maintainers: the ABI list in direct_mmap.h is identical in
abseil 20200225 (the version in tree when the arch dependencies were
introduced) and in the current 20260817.0, so the failure has existed
ever since mips64 was allowed. It is still reproduced on all maintained
branches, e.g.:

    2026.02.x https://autobuild.buildroot.net/results/5818407a73cfd3371cd1f726a24df6ceb9afa42d/
    2025.02.x https://autobuild.buildroot.net/results/5065bda3b91bdbee53559dd97af8ab5a63a1e112/

so a backport is needed there.

Fixes: ae0557403a ("package/libabseil-cpp: add BR2_PACKAGE_LIBABSEIL_CPP_ARCH_SUPPORTS")
Fixes:
https://autobuild.buildroot.net/results/f375584f3721d61238b9e43d9926e037802f6141/

Assisted-by: Claude:claude-opus-5
Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 263cfb165e)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:21:59 +02:00
Yegor Yefremov
4a383ac0c2 package/cannelloni: security bump to version 2.1.2
For change log, see:

https://github.com/mguentner/cannelloni/releases/tag/v2.0.1
https://github.com/mguentner/cannelloni/releases/tag/v2.1.0
https://github.com/mguentner/cannelloni/releases/tag/v2.1.1
https://github.com/mguentner/cannelloni/releases/tag/v2.1.2

2.1.2 fixes CVE-2026-37539 (CVSS 3.1 score 9.8, CWE-121): a stack based
buffer overflow in CAN frame parsing, in parseCANFrame() in parser.cpp
and decodeFrame() in decoder.cpp, allowing remote attackers to cause a
denial of service (crash) or possibly execute arbitrary code via
crafted CAN FD frames.

The advisory names v2.0.0 explicitly, so the version used so far is
affected. The CVE is not reported by
https://security.buildroot.org/master/component/cannelloni because its
NVD entry has no CPE data (vendor and product are both "n/a") and can
therefore not be matched against the package version.

Apart from the security fix, 2.0.0..2.1.2 contains only a handful of
changes: undeliverable frames are dropped after a timeout on a broken
CAN bus, variable length arrays are gone, the default remote address is
fixed, and pthreads are looked up with the CMake module instead of by
hand. 2.1.1 is a maintenance release only, as the 2.1.0 tag pointed to
a commit that was not the final one.

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 4dc8e8b6f9)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:21:41 +02:00
Yegor Yefremov
266957f4ba package/qemu: host-qemu does not support XOP capable CPUs
Commit 1f7efaf89f ("package/qemu: do not support x86_steamroller or
x86_core_avx2") excluded BR2_x86_steamroller from
BR2_PACKAGE_HOST_QEMU_ARCH_SUPPORTS. This is still needed, but for a
different reason than AVX, and the exclusion is incomplete.

steamroller is bdver3, and what the Qemu TCG engine cannot emulate
there is not AVX, but the Bulldozer-specific XOP, FMA4, TBM and LWP
extensions. In Qemu 11.0.0 (the version we currently package) and
11.1.1, target/i386/cpu.c has:

  #define TCG_EXT3_FEATURES (CPUID_EXT3_LAHF_LM | CPUID_EXT3_SVM | \
            CPUID_EXT3_CR8LEG | CPUID_EXT3_ABM | CPUID_EXT3_SSE4A | \
            CPUID_EXT3_3DNOWPREFETCH | CPUID_EXT3_KERNEL_FEATURES | \
            CPUID_EXT3_CMP_LEG)

CPUID_EXT3_XOP, CPUID_EXT3_FMA4, CPUID_EXT3_TBM and CPUID_EXT3_LWP are
defined in target/i386/cpu.h, but are not part of that mask, i.e. TCG
does not implement them. Binaries using those instructions therefore
die with:

  qemu: uncaught target signal 4 (Illegal instruction) - core dumped

This affects the whole Bulldozer family, not only steamroller:
bulldozer (bdver1), piledriver (bdver2) and excavator (bdver4) are
equally unsupported, but were never excluded.

Use the newly introduced BR2_X86_CPU_HAS_XOP symbol, which covers all
four variants, instead of listing BR2_x86_steamroller alone. As for
AVX512, this disables gobject-introspection and nodejs, which are the
two packages needing host-qemu in user mode.

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 22c0ec4fcf)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:20:06 +02:00
Yegor Yefremov
672e27ec30 arch/Config.in.x86: add BR2_X86_CPU_HAS_XOP
The AMD Bulldozer family (bdver1 to bdver4, i.e. bulldozer, piledriver,
steamroller and excavator) is the only x86 family implementing the XOP
instruction set, together with the equally Bulldozer-specific FMA4 and
LWP extensions, and TBM starting with bdver2. All of them were dropped
again with Zen.

This can be verified with:

  $ gcc -march=bdver1 -Q --help=target | grep -E '\-m(xop|fma4|tbm|lwp)'
    -mfma4      [enabled]
    -mlwp       [enabled]
    -mtbm       [disabled]
    -mxop       [enabled]

  $ gcc -march=bdver2 -Q --help=target | grep -E '\-m(xop|fma4|tbm|lwp)'
    -mfma4      [enabled]
    -mlwp       [enabled]
    -mtbm       [enabled]
    -mxop       [enabled]

with bdver3 and bdver4 behaving like bdver2.

Add a hidden BR2_X86_CPU_HAS_XOP capability symbol and select it from
those four CPU variants, so that packages which cannot cope with this
instruction set can depend on it, instead of listing the CPU variants
one by one. The first user is host-qemu, whose TCG engine does not
implement XOP.

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit f91407f012)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:19:03 +02:00
Yegor Yefremov
07b358a539 package/qemu: drop x86_core_avx2 exclusion
Commit 1f7efaf89f ("package/qemu: do not support x86_steamroller or
x86_core_avx2") excluded BR2_x86_core_avx2 from
BR2_PACKAGE_HOST_QEMU_ARCH_SUPPORTS because binaries built for that CPU
variant crashed under qemu-user. This was done at the time of Qemu 4.2,
whose TCG engine did not implement AVX at all.

Since Qemu 7.2, the TCG engine implements AVX, AVX2, F16C, FMA3 and
VAES. In Qemu 11.0.0 (the version we currently package) and 11.1.1,
target/i386/cpu.c has:

  #define TCG_EXT_FEATURES (... | CPUID_EXT_AVX | CPUID_EXT_F16C | \
            CPUID_EXT_FMA | ...)
  #define TCG_7_0_EBX_FEATURES (... | CPUID_7_0_EBX_BMI1 | \
            CPUID_7_0_EBX_BMI2 | CPUID_7_0_EBX_AVX2 | ...)

which covers everything gcc generates for -march=core-avx2.

In addition, the exclusion was inconsistent: gcc's core-avx2 is a
deprecated alias for haswell, both variants select exactly the same
BR2_X86_CPU_HAS_* symbols in arch/Config.in.x86, and haswell was never
excluded. The same goes for broadwell, skylake, zen*, x86-64-v3, ...,
which all enable AVX2 and build fine on the autobuilders.

So drop the BR2_x86_core_avx2 exclusion.

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 8d80efe017)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:18:56 +02:00
Bernd Kuhls
651efc907f package/ibm-sw-tpm2: fix build with gcc-15.x
Fixes:
https://autobuild.buildroot.net/results/d43/d4364f6e3636c696471bf8cba6d308439130e53a/

In function 'MakeIv',
    inlined from 'TestSymmetricAlgorithm' at AlgorithmTests.c:197:25:
AlgorithmTests.c:181:23: error: writing 32 bytes into a region of size
 16 [-Werror=stringop-overflow=]

The build error occurs with gcc 15.x on some platforms, gcc 14.x is not
affected.

These defconfigs build without this patch:

BR2_x86_64=y
BR2_GCC_VERSION_14_X=y
BR2_PACKAGE_IBM_SW_TPM2=y

BR2_x86_64=y
BR2_x86_x86_64_v4=y
BR2_GCC_VERSION_14_X=y
BR2_PACKAGE_IBM_SW_TPM2=y

BR2_x86_64=y
BR2_PACKAGE_IBM_SW_TPM2=y

This gcc-15 based defconfig is broken:

BR2_x86_64=y
BR2_x86_x86_64_v4=y
BR2_PACKAGE_IBM_SW_TPM2=y

The build error is not related to the recent bump of the package from
rev183-2024-03-27 to rev183-2026-08-26 because no changes were committed
upstream to AlgorithmTests.c since rev183-2024-03-27:
https://github.com/kgoldman/ibmswtpm2/commits/master/src/AlgorithmTests.c

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit b016989c61)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:18:17 +02:00
Bernd Kuhls
4c96ea868e package/sofia-sip: needs OpenSSL
Buildroot commit bb254e2304 bumped the
package to version 1.13.18 which includes upstream commit
8081a1a6d0
that added the unconditional usage of OpenSSL.

Tested with both LibreSSL and OpenSSL, the latter with all suboptions
disabled.

Fixes:
https://autobuild.buildroot.net/results/afe/afe7b327f12db86e4dc31ecc25b576bff5c4a0bb/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit ea18394dd7)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:18:10 +02:00
Raphaël Mélotte
c5d82647ff package/fcft: use release tarball instead of archive
Codeberg has changed the way it generate hashes for at least some of
the generated tarballs (see [1]).

This change affects tarballs generated by Codeberg, but not release
artifacts.
fcft turns out to have a proper release available, so use it.

[1]: https://codeberg.org/Codeberg/Community/issues/2861

Fixes:

  https://autobuild.buildroot.net/results/6792109a982924f4cf2b8bcc9a2ac7c12f5ddc55/

Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit b7cfa2371b)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:16:59 +02:00
Julien Olivain
31260954c4 support/testing: test_erlang: new runtime test
Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 9f3797e342)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:16:04 +02:00
Giulio Benetti
e128c5657c package/rtl8812au-aircrack-ng: enable additional kernel config option
Not all Linux defconfigs have CONFIG_INET enabled and this results in:
  LD [M]  88XXau.o
  MODPOST Module.symvers
ERROR: modpost: "register_inetaddr_notifier" [88XXau.ko] undefined!
ERROR: modpost: "unregister_inetaddr_notifier" [88XXau.ko] undefined!

So let's add CONFIG_INET to LINUX_CONFIG_FIXUPS.

Fixes:
https://autobuild.buildroot.org/results/6b4f17518e049a91a36be74c78cb8cde89b73bb3/

Fixes: 003ed345b1 ("package/rtl8812au-aircrack-ng: fix build failure due to double defined endianness")
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit ab8471868e)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:15:58 +02:00
Bernd Kuhls
269dc6ea31 package/libest: needs OpenSSL engines
Fixes build error:

In file included from client.c:14:
client.c: In function 'JNI_OnLoad':
./../../src/est/est.h:834:10: error: implicit declaration of function 'ERR_load_crypto_strings'; did you mean 'ERR_load_CRYPTO_strings'? [-Wimplicit-function-declaration]
  834 |     do { ERR_load_crypto_strings();      \
      |          ^~~~~~~~~~~~~~~~~~~~~~~
client.c:88:9: note: in expansion of macro 'est_apps_startup'
   88 |         est_apps_startup();
      |         ^~~~~~~~~~~~~~~~
./../../src/est/est.h:836:10: error: implicit declaration of function 'ENGINE_load_builtin_engines' [-Wimplicit-function-declaration]
  836 |          ENGINE_load_builtin_engines();  \
      |          ^~~~~~~~~~~~~~~~~~~~~~~~~~~
client.c:88:9: note: in expansion of macro 'est_apps_startup'
   88 |         est_apps_startup();
      |         ^~~~~~~~~~~~~~~~
client.c: In function 'JNI_OnUnload':
./../../src/est/est.h:860:40: error: implicit declaration of function 'ENGINE_cleanup'; did you mean 'EVP_PBE_cleanup'? [-Wimplicit-function-declaration]
  860 |          OBJ_cleanup(); EVP_cleanup(); ENGINE_cleanup(); \
      |                                        ^~~~~~~~~~~~~~
client.c:101:9: note: in expansion of macro 'est_apps_shutdown'
  101 |         est_apps_shutdown();
      |         ^~~~~~~~~~~~~~~~~
./../../src/est/est.h:862:10: error: implicit declaration of function 'ERR_free_strings'; did you mean 'ERR_load_EC_strings'? [-Wimplicit-function-declaration]
  862 |          ERR_free_strings(); } while (0)
      |          ^~~~~~~~~~~~~~~~
client.c:101:9: note: in expansion of macro 'est_apps_shutdown'
  101 |         est_apps_shutdown();
      |         ^~~~~~~~~~~~~~~~~
client.c: In function 'est_client_raise_exception':
client.c:122:17: error: implicit declaration of function 'ERR_print_errors_fp' [-Wimplicit-function-declaration]
  122 |                 ERR_print_errors_fp(stderr);
      |                 ^~~~~~~~~~~~~~~~~~~

seen with this defconfig

BR2_PACKAGE_OPENJDK=y
BR2_PACKAGE_LIBEST=y

The failing code was added upstream on Jul, 6th, 2020:
ab998c0918
and included in version 3.2.0.

Buildroot commit 5bbb1834a4 bumped the
package to a tree including the aforementioned upstream commit on Jul
24th, 2022 so a backport to LTS branches should be considered.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 7e34cd7c7e)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:15:49 +02:00
Bernd Kuhls
ebce679ef6 package/exim: bump version to 4.100
https://lists.exim.org/lurker/message/20260820.154633.91995f73.en.html

Rebased patch 0001.

Updated patch 0005, the previous version was applied upstream with
commit 497e9eb7e77ad27ae1d45281e23eefadfaa7a3bc but it did not fix all
linker errors so we sent a new patch upstream which replaces the
previous patch.

Updated hash of GPL-2.0 license file (address, name of president and
typos), a commit can not be provided from the source tree.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 8b009489f5)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:15:42 +02:00
Bernd Kuhls
0f4211f335 package/exim: disable valgrind when building with thumb1
src/valgrind.h contains inline asm not compatible with thumb1 so we
disable valgrind support for thumb1.

Fixes:
https://autobuild.buildroot.org/results/720bfa00ca926a398e901366e7ab20d08cfa9a81/

Inspired by buildroot commit 26013972ce.

The oldest build error of this kind dates back to 2022
https://autobuild.buildroot.net/results/85d/85d8e725a31bc1a3c41b2e388a17ff439274d437/
so a backport to LTS branches should be considered.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Reviewed-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Tested-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 6c4abe552f)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:15:29 +02:00
Fengwei Tan
768e3720fc support/testing: add FLAT stack size test case
Add an infrastructure test case to verify that the per-package
<PKG>_FLAT_STACKSIZE variable correctly configures the stack size in the
generated FLAT binary header.

Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 0bf4525045)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:14:55 +02:00
Bernd Kuhls
bd2a3cc2b0 package/bind: security bump version to 9.20.29
https://downloads.isc.org/isc/bind9/9.20.29/doc/arm/html/notes.html#notes-for-bind-9-20-28
"The BIND 9.20.28 release was withdrawn after the discovery of a
 regression in it during pre-release testing."

https://downloads.isc.org/isc/bind9/9.20.29/doc/arm/html/notes.html#notes-for-bind-9-20-29
https://downloads.isc.org/isc/bind9/9.20.29/doc/arm/html/changelog.html
https://seclists.org/oss-sec/2026/q3/801

Fixes CVE-2026-19033, CVE-2026-19662, CVE-2026-19666, CVE-2026-19667,
CVE-2026-19668, CVE-2026-19941, CVE-2026-75029, CVE-2026-76163,
CVE-2026-77119, CVE-2026-77692, CVE-2026-78301, CVE-2026-80274,
CVE-2026-81563 & CVE-2026-81736.

Raise the minimum gcc version to 8 to fix a build error found by the
Gitlab pipelines which would be introduced by this bump due to upstream
commit:
a891e74233

opensslrsa_link.c:53:51: error: initializer element is not constant
 static const unsigned int rsa_max_modulus_bytes = (rsa_max_modulus_bits + 7) /

make[1]: *** [package/pkg-generic.mk:273:
 /builds/bkuhls/buildroot/br-test-pkg/bootlin-aarch64-glibc-old/build/bind-9.20.29/.stamp_built]
 Error 2

According to https://stackoverflow.com/a/67000730 the code needs gcc 8.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 6c781be506)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:14:28 +02:00
Giulio Benetti
93123f25f3 package/bind: bump version to 9.20.27
https://downloads.isc.org/isc/bind9/9.20.27/doc/arm/html/notes.html#notes-for-bind-9-20-27
https://downloads.isc.org/isc/bind9/9.20.27/doc/arm/html/changelog.html

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit bdd74f011f)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:14:02 +02:00
Bernd Kuhls
2e5b9f12fa package/bind: fix Config.in comment
The comment should be shown when !BR2_INSTALL_LIBSTDCPP is true, also
treat BR2_PACKAGE_LIBURCU_ARCH_SUPPORTS as arch dependency.

Fixes: 54f96add94 ("package/bind: security  bump version to 9.20.24")
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 96ac57460f)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:08:06 +02:00
Francois Perrad
c15befa90d package/lua-lunix: fix build with gcc >= 15
Fixes:

  https://autobuild.buildroot.org/results/7fba1da21af93a7a0431fb9431dc3c8e872a00ac

Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 2d7e810f73)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:07:35 +02:00
Bernd Kuhls
0d7171fffd package/libest: bump version to r3.2.0-9-ga464ba8a6
The only commit in this bump
https://github.com/cisco/libest/commits/main/
is patch 0005 which was removed.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 26122fd02e)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:06:35 +02:00
Bernd Kuhls
9149362ba8 package/libest: fix build with gcc >= 14.x
Renumbered remaining patches.

Fixes:
https://autobuild.buildroot.net/results/149/149aad6f98163faab14232a9d3013c197579cbb4/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 2e1e3b5e09)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:05:46 +02:00
Bernd Kuhls
5244641934 package/qt5/qt5webengine-chromium: fix build with glibc >= 2.43
No autobuilder errors were recorded, the build error can be reproduced
with this defconfig:

BR2_x86_64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
BR2_PACKAGE_MESA3D=y
BR2_PACKAGE_MESA3D_GALLIUM_DRIVER_SOFTPIPE=y
BR2_PACKAGE_MESA3D_OPENGL_GLX=y
BR2_PACKAGE_MESA3D_OPENGL_EGL=y
BR2_PACKAGE_QT5=y
BR2_PACKAGE_QT5WEBENGINE=y
BR2_PACKAGE_XORG7=y

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 60dc97fcee)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:05:28 +02:00
Yegor Yefremov
e249a14e99 package/qemu: host-qemu does not support AVX512 CPUs
Building gobject-introspection for an x86 CPU variant with AVX512 fails
when g-ir-scanner runs the freshly built target binaries under
qemu-user:

  qemu: uncaught target signal 4 (Illegal instruction) - core dumped

The Qemu TCG engine implements AVX, AVX2, F16C, FMA3 and VAES since Qemu
7.2, but it does not implement the AVX512 instruction set at all [0].
Therefore no -cpu value passed through
BR2_PACKAGE_HOST_QEMU_USER_MODE_ARGS can make such binaries run, and
user-mode emulation is simply not possible for these CPU variants.

Mark those CPUs as unsupported by host-qemu, the same way it is already
done for x86_steamroller and x86_core_avx2. This relies on the existing
BR2_X86_CPU_HAS_AVX512 symbol, so all AVX512 capable variants are
covered, and it disables gobject-introspection and nodejs, which are the
two packages needing host-qemu in user mode.

[0] https://gitlab.com/qemu-project/qemu/-/issues/2878

Fixes:

  https://autobuild.buildroot.org/results/7ed7f9c36dae1ddb965a0f0021db6cd319927b47/

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit c2bd6148c6)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 18:05:20 +02:00
Michael Nosthoff
e1195dcc2a package/wpewebkit: propagate gst1-libav architecture dependency
BR2_PACKAGE_WPEWEBKIT_MULTIMEDIA selects BR2_PACKAGE_GST1_LIBAV, which
depends on BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS, but doesn't propagate
this dependency. In practice, there is no issue, as webkitgtk is only
available on a subset of CPU architectures, while
BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS makes ffmpeg available on pretty much
all CPU architectures, except Cortex-M, m68k coldfire, and some
specific cases of OpenRISC, which are not supported by webkitgtk.

But for the sake of having correct dependency propagation, let's fix
this.

The other packages selected by BR2_PACKAGE_WPEWEBKIT_MULTIMEDIA have
dependencies that are already handled at the top-level
BR2_PACKAGE_WPEWEBKIT option.

Signed-off-by: Michael Nosthoff <buildroot@heine.tech>
CC: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Acked-by: Adrian Perez de Castro <aperez@igalia.com>
Acked-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 251a80dd9d)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:56:09 +02:00
Michael Nosthoff
95cec04c18 package/wpewebkit: fix kernel headers dependency due to seccomp select
In commit
0e2c958e05 ("package/libseccomp: bump to
version 2.5.3"), the kernel headers dependency of seccomp was bumped
from 3.12 to 3.17, but BR2_PACKAGE_WEBKITGTK_SANDBOX, which is a
reverse dependency of BR2_PACKAGE_LIBSECCOMP was forgotten.

This commit fixes this inconsistency.

Fixes: 0e2c958e05 ("package/libseccomp: bump to version 2.5.3")

Signed-off-by: Michael Nosthoff <buildroot@heine.tech>
CC: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Acked-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 5279b2303c)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:55:39 +02:00
Neal Frager
16462dee66 package/xen: fix build error when BR2_PACKAGE_XEN_TOOLS not enabled
The 0002-Update-linker-flags.patch assumes that the qemu-xen files are included
in the xen source tree. However, if BR2_PACKAGE_XEN_TOOLS is not enabled, the
qemu-xen dependency will not be handled and the patch will fail to apply with
the following error.

Fixes: build error below
Applying 0002-Update-linker-flags.patch using patch:
patching file tools/Makefile
Hunk #1 succeeded at 36 (offset -1 lines).
Hunk #2 succeeded at 185 (offset -8 lines).
can't find file to patch at input line 76
Perhaps you used the wrong -p or --strip option?
The text leading up to this was:
--------------------------
|diff --git a/tools/qemu-xen/include/hw/xen/xen_native.h b/tools/qemu-xen/include/hw/xen/xen_native.h
|index 6bcc83ba..2590904e 100644
|--- a/tools/qemu-xen/include/hw/xen/xen_native.h
|+++ b/tools/qemu-xen/include/hw/xen/xen_native.h
--------------------------
No file to patch.  Skipping patch.
1 out of 1 hunk ignored
make: *** [package/pkg-generic.mk:239: output/build/xen-4.21.1/.stamp_patched] Error 1

To avoid making BR2_PACKAGE_XEN_TOOLS a required option, fix the
0002-Update-linker-flags.patch so that modifying source from the qemu-xen
package is no longer included.

Instead of patching qemu-xen, a better solution is undefining the
__XEN_INTERFACE_VERSION__ from the qemu-xen package.

To test:
BR2_aarch64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_PACKAGE_XEN=y
 # BR2_PACKAGE_XEN_TOOLS is not set

Signed-off-by: Neal Frager <neal.frager@amd.com>
Tested-by: Matt Weber <matt@thewebers.ws>
Reviewed-by: Stewart Hildebrand <stewart.hildebrand@amd.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit f63e572432)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:54:50 +02:00
Thomas Petazzoni
01f4bae85b package/glslsandbox: harmonize BR2_PACKAGE_BUSYBOX_SHOW_OTHERS select
BR2_PACKAGE_GLSLSANDBOX_PLAYER_SCRIPTS needs the full blown version of
bash and coreutils, so it selects BR2_PACKAGE_BUSYBOX_SHOW_OTHERS, but
it does so only if BR2_PACKAGE_BUSYBOX=y. Which kind of makes sense,
but is not aligned with the vast majority of other places where
BR2_PACKAGE_BUSYBOX_SHOW_OTHERS is selected, where
BR2_PACKAGE_BUSYBOX_SHOW_OTHERS is selected unconditionally. Harmonize
this with other packages.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 22540e0d41)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:54:38 +02:00
Thomas Petazzoni
bd7d7eecda package/xen: harmonize BR2_PACKAGE_BUSYBOX_SHOW_OTHERS select
BR2_PACKAGE_XEN_TOOLS needs the full blown version of bash and
coreutils, so it selects BR2_PACKAGE_BUSYBOX_SHOW_OTHERS, but it does
so only if BR2_PACKAGE_BUSYBOX=y. Which kind of makes sense, but is
not aligned with the vast majority of other places where
BR2_PACKAGE_BUSYBOX_SHOW_OTHERS is selected, where
BR2_PACKAGE_BUSYBOX_SHOW_OTHERS is selected unconditionally. Harmonize
this with other packages.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit e62e06b19d)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:54:31 +02:00
Thomas Petazzoni
3716049995 package/ndctl: propagate !BR2_STATIC_LIBS dependency
ndctl selects kmod and keyutils, both of which depend on
!BR2_STATIC_LIBS, but this dependency was not propagated into ndctl
when the package was introduced. This commit fixes this issue.

Fixes: 039c1ae13e ("package/ndctl: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 6dad789282)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:54:23 +02:00
Thomas Petazzoni
5b6bcde02f package/ndctl: fix Config.in comment
The Config.in comment has the correct dependency on
!BR2_TOOLCHAIN_HAS_THREADS, but that was not reflected in the comment
text itself.

Fixes: 039c1ae13e ("package/ndctl: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 3472fd59af)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:54:20 +02:00
Thomas Petazzoni
2378e81e77 package/strongswan: fix BR2_PACKAGE_STRONGSWAN_BOTAN dependencies
BR2_PACKAGE_STRONGSWAN_BOTAN selects BR2_PACKAGE_BOTAN, but since
commit 10a70b1af6, botan needs gcc 11,
which was not propagated to strongswan's botan option. This commit
fixes this issue.

Fixes: 10a70b1af6 ("package/botan: needs gcc >= 11")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit b56072c126)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:51:39 +02:00
Thomas Petazzoni
8b24e3a6e9 package/gerbera: propagate icu's dependency on !BR2_BINFMT_FLAT
gerbera selects BR2_PACKAGE_ICU, which depends on !BR2_BINFMT_FLAT,
but this dependency was not propagated to gerbera. In practice this is
not an issue because gerbera depends on BR2_USE_MMU, and only noMMU
platforms can use BR2_BINFMT_FLAT. But for the sake of completeness,
let's propagate this dependency.

Note: in the Config.in comment, we handle it like an architecture
dependency, like is done in package/icu/Config.in.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 6b716763e9)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:49:57 +02:00
Thomas Petazzoni
874dfd0e1a package/netdata: propagate gcc version dependency of protobuf
Since the bump of libabseil-cpp in commit
76241e89e1, it requires gcc 10. As part
of this commit, the protobuf package was updated, but not its reverse
dependency netdata. This commit fixes this issue.

Fixes: 76241e89e1 ("package/libabseil-cpp: bump to version 20260817.0")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit e91ffb1afb)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:47:09 +02:00
Thomas Petazzoni
28dfc9a5d9 package/sysprof: propagate ucontext-related dependency from libdex
BR2_PACKAGE_SYSPROF selects BR2_PACKAGE_LIBDEX but did not propagate:

	depends on BR2_TOOLCHAIN_HAS_UCONTEXT || \
		BR2_PACKAGE_LIBUCONTEXT_ARCH_SUPPORTS

from libdex. This commit fixes this missing dependency. In terms of
Config.in comment, we do the same as what libdex is doing: handle it
as a toolchain dependency (rather than an architecture dependency).

This was missed in commit a73ef093f7,
which added the ucontext related dependency to libdex, without
propagating it to sysprof.

Fixes: a73ef093f7 ("package/libdex: needs ucontext")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit cd5eab10fe)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:47:02 +02:00
Thomas Petazzoni
ffe6be0876 package/rpi-rgb-led-matrix: propagate BR2_PACKAGE_GRAPHICSMAGICK dependency
BR2_PACKAGE_RPI_RGB_LED_MATRIX_IMAGE_VIEWER selects
BR2_PACKAGE_GRAPHICSMAGICK, but did not propagate its BR2_USE_MMU
dependency. This issue exists since the package was introduced in
commit e821078031.

It fixes the following Kconfig warning:

WARNING: unmet direct dependencies detected for BR2_PACKAGE_GRAPHICSMAGICK
  Depends on [n]: BR2_USE_MMU [=n] && BR2_TOOLCHAIN_HAS_THREADS [=y]
  Selected by [y]:
  - BR2_PACKAGE_RPI_RGB_LED_MATRIX_IMAGE_VIEWER [=y] && BR2_PACKAGE_RPI_RGB_LED_MATRIX [=y]

which occurs when you configure an ARM noMMU FDPIC toolchain (because
we have noMMU, but shared libraries, so rpi-rgb-led-matrix can be
enabled).

Fixes: e821078031 ("package/rpi-rgb-led-matrix: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit e67b301f53)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:46:54 +02:00
Thomas Petazzoni
9f273c5a79 utils/getdeveloperlib.py: fix regexp used to find package infra
There's recently been autobuilder failures on
toolchain-external-bootlin, but I wasn't getting notified in the daily
autobuilder e-mail for those failures, which sounded odd as DEVELOPERS
contains:

N:      Thomas Petazzoni <thomas.petazzoni@bootlin.com>
[...]
F:      toolchain/

And indeed, testing:

$ ./utils/get-developers -p toolchain-external-bootlin

returned nothing.

Turns out that the regexp FIND_INFRA_IN_PATCH and FIND_INFRA_IN_MK
used to find the package infrastructure, and ultimately decide if a
given .mk file contains a package, was a bit too strict:

"^\+\$\(eval \$\((host-)?([^-]*)-package\)\)$"

This would only allow packages named <something>-package or
host-<something>-package, but the <something> should not contain any
dash ("-"). So this works fine for cmake-package,
host-autotools-package, but not for toolchain-external-package where
<something> is toolchain-external and it contains a dash.

We fix this by relaxing the regexp a bit and allowing any character in
<something>. Consider the rest of the regexp that expects $(eval
$(<host>-<something>-package)), it seems highly unlikely to match
anything else but the line we're interested in.

With this fix:

$ ./utils/get-developers -p toolchain-external-bootlin
Giulio Benetti <giulio.benetti@benettiengineering.com>
Romain Naour <romain.naour@gmail.com>
Thomas Petazzoni <thomas.petazzoni@bootlin.com>

This issue has existed since the toolchain-external-package
infrastructure had been added.

Fixes: 1c99d70e52 ("toolchain-external: introduce toolchain-external-package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 592d5c517e)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:46:43 +02:00
Thomas Perale
9521735392 package/zabbix: fix build without libcurl
Building zabbix without libcurl enabled would lead to the following
error:

/usr/bin/ld: .../src/libs/zbxxml/xml.c:515:(.text+0x1c64): undefined reference to `zbx_vector_str_append'

This issue has been addressed in the upstream commit [1] and backported
as a patch in Buildroot.
For more information see the upstream issue [2].

This error is reproducible with the following defconfig:

cat >.config <<EOF
BR2_arm=y
BR2_cortex_a7=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_PACKAGE_PHP=y
BR2_PACKAGE_ZABBIX=y
BR2_PACKAGE_ZABBIX_SERVER=y
BR2_PACKAGE_ZABBIX_SERVER_COPY_FRONTEND=y
EOF
make oldefconfig
make zabbix

[1] https://git.zabbix.com/projects/ZBX/repos/zabbix/commits/e8333ca2128
[2] https://support.zabbix.com/browse/ZBX-27635

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 489aefc22a)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:46:36 +02:00
Thomas Perale
4725deea9c package/zabbix: security bump to v7.2.15
Zabbix 7.2 is EOL since December 2025 [1]

For more info on the version bump, see:
 - https://www.zabbix.com/rn/rn7.2.14
 - https://www.zabbix.com/rn/rn7.2.15

This fixes the following vulnerabilties:

- CVE-2026-23920:
    Host and event action script input is validated with a regex (set by
    the administrator), but the validation runs in multiline mode. If ^
    and $ anchors are used in user input validation, an injected newline
    lets authenticated users bypass the check and inject shell commands.
    https://www.cve.org/CVERecord?id=CVE-2026-23920

- CVE-2026-23921:
    A low privilege Zabbix user with API access can exploit a blind SQL
    injection vulnerability in include/classes/api/CApiService.php to
    execute arbitrary SQL selects via the sortfield parameter. Although
    query results are not returned directly, an attacker can exfiltrate
    arbitrary database data through time-based techniques, potentially
    leading to session identifier disclosure and administrator account
    compromise.
    https://www.cve.org/CVERecord?id=CVE-2026-23921

[1] https://endoflife.date/zabbix

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 055a1e249c)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:46:30 +02:00
Thomas Perale
d5943e5047 package/zabbix: update SITE
Zabbix version 7.2 is no longer maintained. The version 7.0 is the LTS
and the stable moved to 7.4 [1]. The source location moved from "stable"
to "oldstable" directory.

This error is present in the autobuilder since the 22nd of May.

[1] https://endoflife.date/zabbix

Fixes: https://autobuild.buildroot.org/results/636/636c4514c67f1b0fcd20976d064f17b0e0a314fe//
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 7878630479)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:46:01 +02:00
Bernd Kuhls
69c37d796e package/libheif: security bump version to 1.23.4
https://github.com/strukturag/libheif/releases/tag/v1.23.4

Fixes the following CVEs:

(CVE numbers will be added when assigned.)

CVE-2026-XXXXX (GHSA-vg7w-rp49-4fc2)
CVE-2026-XXXXX (GHSA-xrp2-63fq-jm8q)
CVE-2026-XXXXX (GHSA-prgh-72vc-3xmc)
CVE-2026-XXXXX (GHSA-fqpw-fj22-78w4)
CVE-2026-XXXXX (GHSA-4rv4-953r-p24q)
CVE-2026-XXXXX (GHSA-rhgw-q5g8-xjh2)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 053c724d6e)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:45:53 +02:00
Joachim Wiberg
2a1acd674a package/lldpd: rework start script
check-package reports six warnings on S60lldpd: indentation with
spaces, no DAEMON variable, and shellcheck complaints.

The script also masks failures, the exit status of
"[ $? = 0 ] && echo OK || echo FAIL" is the one of echo, so start and
stop always return success.  Stopping does not wait for the daemon to
exit either, so a restart can race the instance on its way out.

Rewrite it after package/busybox/S01syslogd, as the manual asks.  lldpd
daemonizes and writes the PID file itself, but does not remove it on
exit, so pass the PID file to both start-stop-daemon and the daemon and
drop the stale file once the process is gone.  Also pick up arguments
from /etc/default/lldpd and add the customary reload alias.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
[Julien: remove .checkpackageignore entry to fix check-package error]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 2fd1f6b629)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:45:35 +02:00
Joachim Wiberg
e12ef9c652 package/lldpd: security bump to version 1.0.22
https://github.com/lldpd/lldpd/releases/tag/1.0.22
https://github.com/lldpd/lldpd/releases/tag/1.0.21

Fixes CVE-2026-46433, an out-of-bound read access when removing the
VLAN tag.  1.0.21 fixes path traversal vulnerabilities and arbitrary
file deletion in the privileged process.

GPG signature verified with key AEF2348766F371C689A7360095A42FE8353525F9,
LICENSE hash unchanged.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 03e4bebcd2)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 16:57:26 +02:00
Peter Korsgaard
f8c4315d4c package/x11r7/xlib_libXfont2: security bump to version 2.0.9
Fixes the following vulnerabilities:

- CVE-2026-59679: Font Server Client encoding Out-Of-Bounds Read/Write
- CVE-2026-44950: Font Server Client Cumulative Glyph Data Heap Buffer
  Overflow

For more details, see the advisory:
https://lists.x.org/archives/xorg-announce/2026-August/003734.html

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 21f18cd012)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 16:54:18 +02:00
Titouan Christophe
0597fd1ac1 {linux, linux-headers}: bump 6.{12,18} series
Update the latest kernel releases:
    - 6.12.110 -> 6.12.111
    - 6.18.52 -> 6.18.53

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-09-22 16:57:51 +02:00
Thomas Petazzoni
0e9a175cd2 package/clamav: add missing BR2_TOOLCHAIN_HAS_SYNC_4 dependency
In commit 203725a46b ("package/clamav:
bump version to 1.0.1"), select BR2_PACKAGE_JSON_C was added to
BR2_PACKAGE_CLAMAV without propagating the BR2_TOOLCHAIN_HAS_SYNC_4
dependency from BR2_PACKAGE_JSON_C.

Since at the same time a dependency on
BR2_PACKAGE_HOST_RUSTC_TARGET_ARCH_SUPPORTS was added to clamav and
Rust is not supported on the few architectures that don't have 4-byte
sync intrinsics, this has basically no effect, but ensure a correct
propagation of dependencies.

Fixes: 203725a46b ("package/clamav: bump version to 1.0.1")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 39b840beef)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:23:55 +02:00
Thomas Petazzoni
d854788bc7 package/falcosecurity-libs: drop meaningless selects
BR2_PACKAGE_FALCOSECURITY_LIBS selects BR2_PACKAGE_HOST_GRPC and
BR2_PACKAGE_HOST_PROTOBUF, neither of which exists. These selects are
anyway not needed, so drop them.

Fixes: a15e35c4eb ("falcosecurity-libs: add new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 7f5bb493e2)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:22:23 +02:00
Thomas Petazzoni
9ee7260b67 package/webkitgtk: propagate gst1-libav architecture dependency
BR2_PACKAGE_WEBKITGTK_MULTIMEDIA selects BR2_PACKAGE_GST1_LIBAV, which
depends on BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS, but doesn't propagate
this dependency. In practice, there is no issue, as webkitgtk is only
available on a subset of CPU architectures, while
BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS makes ffmpeg available on pretty much
all CPU architectures, except Cortex-M, m68k coldfire, and some
specific cases of OpenRISC, which are not supported by webkitgtk.

But for the sake of having correct dependency propagation, let's fix
this.

The other packages selected by BR2_PACKAGE_WEBKITGTK_MULTIMEDIA have
dependencies that are already handled at the top-level
BR2_PACKAGE_WEBKITGTK option.

Fixes: e6e549b9e4 ("ffmpeg: add BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit da90655637)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:22:08 +02:00
Thomas Petazzoni
3e0083751f package/webkit: fix kernel headers dependency due to seccomp select
In commit
0e2c958e05 ("package/libseccomp: bump to
version 2.5.3"), the kernel headers dependency of seccomp was bumped
from 3.12 to 3.17, but BR2_PACKAGE_WEBKITGTK_SANDBOX, which is a
reverse dependency of BR2_PACKAGE_LIBSECCOMP was forgotten.

This commit fixes this inconsistency.

Fixes: 0e2c958e05 ("package/libseccomp: bump to version 2.5.3")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit ef92929504)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:21:34 +02:00
Thomas Petazzoni
94830507f8 package/libssh: fix select BR2_PACKAGE_LIBOPENSSL_ENGINES
BR2_PACKAGE_LIBSSH_OPENSSL unconditionnally selects
BR2_PACKAGE_LIBOPENSSL_ENGINES even though libressl is also supported
as an OpenSSL provider (and BR2_PACKAGE_LIBOPENSSL_ENGINES doesn't
make sense for libressl).

This causes the following Kconfig warning:

WARNING: unmet direct dependencies detected for BR2_PACKAGE_LIBOPENSSL_ENGINES
  Depends on [n]: <choice> && BR2_PACKAGE_LIBOPENSSL [=n]
  Selected by [y]:
  - BR2_PACKAGE_LIBSSH_OPENSSL [=y] && <choice> && BR2_PACKAGE_OPENSSL [=y]

We checked that libssh, with OpenSSL support and libressl selected as
an OpenSSL provider works fine, using the following defconfig:

BR2_aarch64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_PACKAGE_LIBSSH=y
BR2_PACKAGE_LIBSSH_SERVER=y
BR2_PACKAGE_LIBRESSL=y

Fixes: 62103be918 ("package/libssh: select BR2_PACKAGE_LIBOPENSSL_ENGINES")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit f7fe354ada)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:20:58 +02:00
Thomas Petazzoni
520800d3f1 package/qt5cinex: add missing select BR2_PACKAGE_QT5BASE_GUI
BR2_PACKAGE_QT5CINEX selects BR2_PACKAGE_QT5BASE_PNG,
BR2_PACKAGE_QT5BASE_WIDGETS and BR2_PACKAGE_QT5BASE_EGLFS, which are
all sub-options of BR2_PACKAGE_QT5BASE_GUI, but we don't explicitly
selects BR2_PACKAGE_QT5BASE_GUI.

It turns out that things work because the package selects
BR2_PACKAGE_QT5GRAPHICALEFFECTS, which selects
BR2_PACKAGE_QT5DECLARATIVE_QUICK, which selects
BR2_PACKAGE_QT5BASE_GUI, but that is rather non-obvious, and it makes
more sense for BR2_PACKAGE_QT5CINEX to directly select
BR2_PACKAGE_QT5BASE_GUI if it also selects sub-options of it.

No functional change.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit f077ba9e67)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:20:21 +02:00
Thomas Petazzoni
d0f4c12dd1 package/ivi-homescreen: add missing BR2_USE_MMU dependencies
- BR2_PACKAGE_IVI_HOMESCREEN_AUDIO_PLAYERS selects gstreamer1, which
  has a depends on BR2_USE_MMU, but does not propagate it

- BR2_PACKAGE_IVI_HOMESCREEN_FLUTTER_SECURE_STORAGE_PLUGIN selects
  libsecret, which has a depends on BR2_USE_MMU, but does not propagate
  it

In practice there is no problem since ivi-homescreen depends on glibc,
and glibc doesn't support any noMMU architecture. But just by walking
the chain of option dependencies, this is not something that is
theoretically guaranteed (making automated verification of
dependencies difficult).

The other "depends on" from gstreamer1 and libsecret, BR2_USE_WCHAR
and BR2_TOOLCHAIN_HAS_THREADS are on the other hand already handled by
the top-level BR2_PACKAGE_IVI_HOMESCREEN option, so there is no
ambiguity.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 90aeea08bb)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:19:26 +02:00
Thomas Petazzoni
b65a2ca6ef package/pulseview: add missing 'select BR2_PACKAGE_QT5GUI'
BR2_PACKAGE_PULSEVIEW selects BR2_PACKAGE_QT5BASE_PNG and
BR2_PACKAGE_QT5BASE_WIDGETS, which both depend on
BR2_PACKAGE_QT5BASE_GUI. It ends working because we also select
BR2_PACKAGE_QT5SVG, which selects BR2_PACKAGE_QT5BASE_GUI, so there is
no bug, but it's bit inconsistent to select sub-options that have a
"depends on" without selecting the option they depend on.

This not a bug fix, it has no functional implication.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit aff091c39d)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:19:01 +02:00
Bernd Kuhls
b1661d3ac4 package/znc: security bump version to 1.10.3
https://github.com/znc/znc/blob/znc-1.10.3/ChangeLog.md
https://wiki.znc.in/ChangeLog/1.10.3

Fixes CVE-2020-11022, CVE-2020-11023, CVE-2026-82373 & CVE-2026-82374.

Updated _SITE according to
https://wiki.znc.in/index.php?title=ZNC&diff=3493&oldid=3460

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 43558e103b)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:13:25 +02:00
Dario Binacchi
7cc8e496a2 package/pocketpy: fix build without threads
pocketpy enables thread support by default (PK_ENABLE_THREADS=ON) and
then requires Threads from cmake, which fails on toolchains without
thread support:

  CMake Error at /usr/share/cmake-3.28/Modules/FindPackageHandleStandardArgs.cmake:230 (message):
    Could NOT find Threads (missing: Threads_FOUND)

Thread support is optional, so enable it only when the toolchain
provides threads.

Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 376daf3dd0)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:13:05 +02:00
Thomas Petazzoni
dea81ee76c package/kodi: fix definition of BR2_PACKAGE_KODI_ARCH_SUPPORTS
The definition of BR2_PACKAGE_KODI_ARCH_SUPPORTS is incorrect, it
goes like this:

 	bool
	default y if BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS
	default y if BR2_PACKAGE_HOST_OPENJDK_BIN_ARCH_SUPPORTS

so it means it would be "y" if either
BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS *OR*
BR2_PACKAGE_HOST_OPENJDK_BIN_ARCH_SUPPORTS is true. While clearly what
we need is for both to be true: ffmpeg should be available for the
target architecture, and openjdk should be available for the host
architecture.

One option was to change to:

 	bool
	default y if BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS && BR2_PACKAGE_HOST_OPENJDK_BIN_ARCH_SUPPORTS

Or:

 	bool
	default y if BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS
	depends on BR2_PACKAGE_HOST_OPENJDK_BIN_ARCH_SUPPORTS

But we preferred:

 	bool
	default y
	depends on BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS
	depends on BR2_PACKAGE_HOST_OPENJDK_BIN_ARCH_SUPPORTS

Fixes: b6a2f49429 ("package/kodi: depend on host-openjdk-bin instead of selecting BR2_NEEDS_HOST_JAVA")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 00e83bc24d)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:12:44 +02:00
Thomas Petazzoni
1e25dca170 package/kodi: propagate mariadb dependencies to BR2_PACKAGE_KODI_MYSQL
Even though kodi itself has architecture dependencies (expressed
through BR2_PACKAGE_KODI_ARCH_SUPPORTS, the option
BR2_PACKAGE_KODI_MYSQL selects BR2_PACKAGE_MARIADB, which has its own
architecture dependencies as well. Make sure to propagate those to
BR2_PACKAGE_KODI_MYSQL, which doesn't require adding a Config.in
comment as these are purely architecture dependencies.

We haven't replicate all dependencies of BR2_PACKAGE_MARIADB because
all the others are covered by the top-level BR2_PACKAGE_KODI, and
propagating them would require adding a Config.in comment for
BR2_PACKAGE_KODI_MYSQL.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 16e3d628bd)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:12:17 +02:00
Thomas Petazzoni
04496503c5 package/hidapi: propagate dependencies of libgudev
Since hidapi was introduced in commit
6267f34afd, it forgot to propagate some
dependencies of libgudev (which existed back then). Initially libgudev
was only needed when BR2_INIT_SYSTEMD=y, but still the dependencies
were not propagated for the systemd case.

Anyway, since e739dd5a11, libgudev is a
mandatory dependency of hidapi, independently from the selected init
system.

We make sure to propagate all dependencies of libgudev to hidapi, and
propagate them to the reverse dependencies of hidapi.

Fixes: 6267f34afd ("hidapi: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 74def2cdd4)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:06:11 +02:00
Thomas Petazzoni
31e728d32a package/*/Config.in: harmonize select of BR2_PACKAGE_ARGP_STANDALONE
BR2_PACKAGE_ARGP_STANDALONE is defined as follows:

config BR2_PACKAGE_ARGP_STANDALONE
	depends on !BR2_TOOLCHAIN_USES_GLIBC

Some packages did:

	select BR2_PACKAGE_ARGP_STANDALONE if !BR2_TOOLCHAIN_USES_GLIBC

while a number of others did:

	select BR2_PACKAGE_ARGP_STANDALONE if BR2_TOOLCHAIN_USES_UCLIBC || BR2_TOOLCHAIN_USES_MUSL

This commit harmonizes the situation, by settling on the first
solution ("if !BR2_TOOLCHAIN_USES_GLIBC") as it matches how
BR2_PACKAGE_ARGP_STANDALONE is defined in the first place.

No functional change.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 1799bf3680)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:05:30 +02:00
Thomas Petazzoni
dbf1a06be7 package/intel-vpl-gpu-rt: add missing BR2_TOOLCHAIN_GCC_AT_LEAST_8 dependency
BR2_PACKAGE_INTEL_VPL_GPU_RT selects BR2_PACKAGE_INTEL_MEDIADRIVER but
did not propagate "depends on BR2_TOOLCHAIN_GCC_AT_LEAST_8". This
commit fixes this issue, which was introduced in commit
ac65841def, when onevpl-intel-gpu was
introduced (it was later renamed to intel-vpl-gpu-rt).

Fixes: ac65841def ("package/onevpl-intel-gpu: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 876023bc5a)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:03:28 +02:00
Thomas Petazzoni
a8f92181b6 package/intel-mediasdk: add missing BR2_TOOLCHAIN_GCC_AT_LEAST_8 dependency
BR2_PACKAGE_INTEL_MEDIASDK selects BR2_PACKAGE_INTEL_MEDIADRIVER but
forgets to propagate the "depends on BR2_TOOLCHAIN_GCC_AT_LEAST_8".

This issue was introduced in commit
51b60c8acf, when "depends on
BR2_TOOLCHAIN_GCC_AT_LEAST_8" was added to mesa3d, propagated to
intel-mediadriver, but not intel-mediasdk.

Fixes: 51b60c8acf ("package/mesa3d: needs gcc >= 8")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit fa38fea91c)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:03:06 +02:00
Thomas Petazzoni
1ad9b84d30 package/python-memray: add missing dependency on BR2_TOOLCHAIN_GCC_AT_LEAST_4_9
BR2_PACKAGE_PYTHON_MEMRAY selects BR2_PACKAGE_LIBUNWIND but forgot to
propagate "depends on BR2_TOOLCHAIN_GCC_AT_LEAST_4_9".

Fixes: c2df8bab97 ("package/python-memray: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit e36370624d)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 12:02:38 +02:00
Thomas Petazzoni
d31f1dca9d package/python-grpcio-reflection: add missing BR2_PACKAGE_HOST_PROTOBUF_ARCH_SUPPORTS dependency
BR2_PACKAGE_PYTHON_GRPCIO_REFLECTION selects
BR2_PACKAGE_PYTHON_PROTOBUF, but forgot to replicate "depends on
BR2_PACKAGE_HOST_PROTOBUF_ARCH_SUPPORTS".

Fixes: 3217fedcb8 ("package/python-grpcio-reflection: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 74dab03495)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:58:29 +02:00
Thomas Petazzoni
c27bc6f3d0 package/python-googleapis-common-protos: add missing BR2_PACKAGE_HOST_PROTOBUF_ARCH_SUPPORTS dependency
BR2_PACKAGE_PYTHON_GOOGLEAPIS_COMMON_PROTOS selects
BR2_PACKAGE_PYTHON_PROTOBUF but did not propagate
BR2_PACKAGE_HOST_PROTOBUF_ARCH_SUPPORTS.

Fixes: d37766a886 ("package/python-googleapis-common-protos: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 548904619c)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:57:56 +02:00
Thomas Petazzoni
2802566302 package/udisks: add missing BR2_USE_MMU dependency
Commit 66ddec89e8 ("package/udisks: bump
to version 2.92") mistakenly removed the BR2_USE_MMU dependency of
udisks when dropping "select BR2_PACKAGE_LVM2". Indeed, BR2_USE_MMU is
a dependency of many other packages selected by udisks.

Interestingly, the Config.in comments in the same file still had the
"depends on BR2_USE_MMU" dependencies.

Fixes: 66ddec89e8 ("package/udisks: bump to version 2.92")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 4b8259bad9)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:57:39 +02:00
Thomas Petazzoni
e70373e51f package/bcc: propagate missing dependency from clang
Since bcc was introduced in commit
146498d13c, it lacked a dependency
propagation from clang for BR2_TOOLCHAIN_HAS_GCC_BUG_64735, this
commit fixes this mistake.

Fixes: 146498d13c ("package/bcc: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit c305370f36)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:57:14 +02:00
Thomas Petazzoni
cd8637f4ec package/go: use BR2_PACKAGE_HOST_GO_HOST_ARCH_SUPPORTS in BR2_PACKAGE_HOST_GO_TARGET_ARCH_SUPPORTS
BR2_PACKAGE_HOST_GO_TARGET_ARCH_SUPPORTS redefines the conditions to
determine if a host go compiler is available for the current host
architecture. Instead, make it explicit that those conditions are the
same by re-using BR2_PACKAGE_HOST_GO_HOST_ARCH_SUPPORTS.

No functional change.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 71d3ffd372)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:56:51 +02:00
Thomas Petazzoni
0ed93ea283 package/openscap: propagate dependencies of libxmlsec1 after bump
In commit
fef9cad1fe ("package/libxmlsec1: bump
version to 1.3.12"), libxmlsec1 was bumped, and alongside some
additional "depends on" were added.

However, these new "depends on" were not propagated to reverse
dependencies of libxmlsec1, i.e. openscap, causing Kconfig warnings:

WARNING: unmet direct dependencies detected for BR2_PACKAGE_LIBXMLSEC1
  Depends on [n]: BR2_TOOLCHAIN_GCC_AT_LEAST_7 [=n] && BR2_TOOLCHAIN_HAS_ATOMIC [=n]
  Selected by [y]:
  - BR2_PACKAGE_OPENSCAP [=y] && BR2_PACKAGE_LIBGPG_ERROR_ARCH_SUPPORTS [=y] && !BR2_STATIC_LIBS [=n] && BR2_TOOLCHAIN_HAS_THREADS_NPTL [=y]

and potentially some build issues, even though we didn't check in the
autobuilders for potential failures.

This commit fixes that by properly propagating the new dependencies.

Cc: Alexis Lothoré <alexis.lothore@bootlin.com>
Cc: Julien Olivain <ju.o@free.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Acked-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 36b2b3f561)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:56:27 +02:00
Bernd Kuhls
cbc3a7044a package/tpm2-tools: security bump version to 5.8
https://github.com/tpm2-software/tpm2-tools/blob/5.8/docs/CHANGELOG.md

Fixes: GHSA-v7w4-4gc9-qcgv, GHSA-gwfg-w3jr-xh66 & GHSA-qp88-8f4j-wv7q.

Switched to sha256 tarball hash provided by upstream.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 17be3c2dcd)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:56:03 +02:00
Adrian Perez de Castro
f9517379d1 package/xdg-dbus-proxy: security bump to verssion 0.1.8
Fixes and issue that caused broadcast messages to skip some checks.
Release notes:

  https://github.com/flatpak/xdg-dbus-proxy/releases/tag/0.1.8

Fixes:
https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-r7hp-698j-2h6c

Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
[Julien: add link to GHSA]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 51b366290b)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:55:30 +02:00
Yegor Yefremov
00bec472c7 package/imlib2: add zlib dependency
The demo programs, which have always been built and are still enabled by
default, gained a zlib dependency in imlib2 1.12.3: upstream commit
f8a451043871 ("imlib2_load: Add crc32 printout") started using zlib's
crc32() in imlib2_load, and 31006b425e11 ("imlib2_view: Optionally show
crc32 of image data") did the same for imlib2_view. Both hardcoded -lz.

Upstream commit b9555030dace ("autofoo: don't hardcode zlib flags"),
first released in 1.12.4, replaced -lz with $(ZLIB_LIBS) and added an
unconditional PKG_CHECK_MODULES(ZLIB, zlib) to the demo programs branch
of configure, turning the previously silent link-time requirement into a
configure failure:

  checking for zlib... no
  configure: error: Package requirements (zlib) were not met:

  Package 'zlib' not found

As Buildroot went straight from 1.7.3 to 1.12.5 the intermediate state
was never packaged, but the dependency has in fact been missing since the
crc32 support landed.

Fixes: https://autobuild.buildroot.org/results/4e05404c353ef985d74757d0b1ec3eda2cdff523/

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 051e5ab13b)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:55:05 +02:00
Bernd Kuhls
fa5faf8c3a package/apache: renumber patches
Buildroot commit 99bfbef093 removed patch
0002 but forgot to renumber the remaining patches.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 5c9fbf7efe)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:50:19 +02:00
Bernd Kuhls
1b3642b460 package/xz: security bump version to 5.8.4
https://github.com/tukaani-project/xz/releases/tag/v5.8.4

- lzma_alone_decoder(), lzma_lzip_decoder(),
  lzma_auto_decoder(), and lzma_microlzma_decoder(): Fix an
  invalid memory access after memory allocation has failed and
  the application reinitializes the existing decoder to decode
  a different file. This bug could at least result in a crash.
  This is tracked as GHSA-5qpq-xqfv-j9pg. CVE number is pending.
  (Also in v5.2, v5.4, and v5.6.)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 6f125a6530)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:46:11 +02:00
Adrian Perez de Castro
bc4357219a package/bubblewrap: security bump to version 0.12.0
Fixes a sandbox escape through symlink traversal tracked in
CVE-2026-87766, which affects all previous versions.

Using the bwrap binary with the setuid bit set is no longer supported
and user namespaces are now always required, so a kernel config fixup
is applied.

A new build option allows indicating the minimum kernel version that
will be used, which removes code used for backwards compatibility with
kernels older than 5.6.0 when a newer version is specified. Passing
$(LINUX_VERSION_PROBED) seems reasonable here.

This version also changed the license from LGPL-2.0+ to LGPL-2.1+,
hence the updated hash.

Release notes:

  https://github.com/containers/bubblewrap/releases/tag/v0.12.0

Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
[Julien: fix _LINUX_CONFIG_FIXUPS by adding the missing "_LINUX"]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 4cb6193d2e)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:45:36 +02:00
Titouan Christophe
d578727aae utils/checkpackagelib: add new check MissingCVEPatch
To indicate that a patch fixes a vulnerability in Buildroot, the convention is:
1. In the patch file, add a tag 'CVE: <cve id>'
2. In <pkg>.mk, and an entry to <PKG>_IGNORE_CVES, and add a comment above
   that new entry to reference the patch file(s)

However, as packages get bumped and their patches are added, removed or
rebased; it happens that IGNORE_CVES get outdated. One important issue is
marking a CVE as ignored, while the corresponding patch is not in Buildroot.

To detect such cases, add a new checker to checkpackagelib that finds
occurences of:

    # 000x-some-patch.patch
    PKG_IGNORE_CVES += CVE-XXXX-YYYY

For each one of them, ensure that the mentioned patch files actually exist
and contain the `CVE: ...` tag.

Assisted-by: Claude:claude-opus-4.8
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit b00ac4e346)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:31:30 +02:00
Titouan Christophe
99e75fa835 package/{binutils, gpsd, micropython, net-tools, util-linux, x11vnc}: fix CVE patch information
Prior to improving check-package to verify that the comment preceding
a <pkg>_IGNORE_CVES entry mentions an existing patch, and that the
patch itself contains a CVE: tag, we fix all problematic cases that
currently exist in Buildroot:

- In the case of binutils: the CVE was only applicable to binutils
  2.43/2.44, and the oldest version now supported is 2.45, so the
  patch doesn't exist anymore in Buildroot
- For x11vnc, fix a typo in the patch name
- For gpsd the patches were dropped in [1] as they are included in the
  version bump
- Similarly for micropython, the patches were dropped in [2] along with
  the version bump
- For util-linux, strip the prefix "package/util-linux/", so that the patch
  is relative to the .mk file and can be found by the new check
- Add missing 'CVE:' tag to net-tools patch 0001

[1] 37ef4f862f package/gpsd: bump version to 3.27.2
[2] 28eeca9a98 package/micropython: bump to version 1.28.0

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 636f69ab45)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:23:23 +02:00
Giulio Benetti
71ac7d15a0 package/libfuse3: security bump to version 3.18.3
Release notes:
https://github.com/libfuse/libfuse/releases/tag/fuse-3.18.3

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 7458d2323a)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:22:48 +02:00
Bernd Kuhls
151555d771 package/pcre2: security bump to version 10.48
https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48

Fixes the following security issues:

(Security fix for specific API usage, GHSA-2p8c-ff85-vh9x)
 If pcre2_jit_compile() is called with options for some match modes, and
 then pcre2_match() is used to perform a match for a different match
 mode, an out-of-bounds read can occur if the match is attempted against
 invalid UTF input.

(Security fix for pattern conversion, GHSA-q8g2-wprr-34m9)
 If pcre2_convert() is called on untrusted input on platforms with
 32-bit size_t, an out-of-bounds heap write can occur.

(Security fix, GHSA-3r4p-g7gg-ppmf) Fixed an out-of-bounds write in DFA
 matching when using a heap limit; also fixed possible integer overflows
 which could cause under-allocation of the workspace.

(Security fix, GHSA-fmgr-6ggq-9859) Added bounds checks for several
 integer overflows while compiling patterns on 32-bit CPUs, which could
 cause under-allocation followed by out-of-bounds writes.

(Security fix, GHSA-9qww-pwc4-77qq) Applied lower buffer bound to
 prevent two out-of-bounds reads while scanning backwards through
 invalid UTF data with PCRE2_MATCH_INVALID_UTF.

(Security fix for specific API usage, #937) Fixed a leak and later
 invalid free when calling the fast-path pcre2_jit_match() function with
 a match data object previously used with pcre2_match() and
 PCRE2_COPY_MATCHED_SUBJECT.

(Low-severity security fix, GHSA-q7rw-r7qq-2hx6) Fixed exposure of two
 uninitialised bytes from malloc() via pcre2_serialize_encode().

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 664db5d62c)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:22:28 +02:00
Bernd Kuhls
70d29d2b0b package/tor: security bump version to 0.4.9.12
https://gitlab.torproject.org/tpo/core/tor/-/blob/tor-0.4.9.12/ReleaseNotes
https://forum.torproject.org/t/security-release-0-4-9-12/22096

Fixes TROVE-2026-032, TROVE-2026-033, TROVE-2026-034, TROVE-2026-035,
TROVE-2026-036, TROVE-2026-042 & TROVE-2026-043.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 95649c547b)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 10:26:05 +02:00
Bernd Kuhls
720f5672db package/turbolua: security bump version to 2.1.5
https://github.com/kernelsauce/turbo/releases/tag/v2.1.5

https://github.com/kernelsauce/turbo/releases/tag/v2.1.4
Security fixes:

HTTP header injection: header values were only checked for a literal
 \r\n, so a lone \r or \n could still split a header. Now rejected on
 either character.

Transfer-Encoding requests are now rejected with 501 instead of silently
 mishandled, closing a request smuggling avenue.

A real default request body size cap (128 MB) with a 413 response,
 previously unbounded.

Secure cookie signature now binds the cookie name, so a value signed for
 one cookie can no longer be replayed under a different name.
 Verification failures return the default value instead of raising.

Constant-time comparison for the secure cookie HMAC, previously a
 timing-leaky ==.

util.secure_random_bytes reads real OS entropy (/dev/urandom,
 BCryptGenRandom on Windows) for WebSocket masks and util.rand_str,
 previously math.random.

WebSocket: unmasked client frames are rejected per RFC 6455, and
 fragmented message reassembly is capped to max_buffer_size to close a
 memory exhaustion path.

StaticFileHandler decodes the request path before the traversal check,
 closing a bypass.

Fixed a 32-byte-per-malformed-request memory leak in the C header parser
 wrapper (found via libFuzzer).

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 15a422cee1)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 10:25:49 +02:00
Bernd Kuhls
8da6415c05 package/i2pd: needs chacha support in libopenssl
/home/thomas/autobuild/instance-2/output-1/build/i2pd-2.59.0/libi2pd/Crypto.cpp:661:49:
 error: 'EVP_chacha20_poly1305' was not declared in this scope; did you
 mean 'SN_chacha20_poly1305'?

The code was added upstream in 2018:
58c92b8405

The build error could be reproduced with i2pd version 2.22.0 added to
buildroot with commit 1035e80aaa so a
backport to LTS branches should be considered.

Fixes:
https://autobuild.buildroot.net/results/bd8/bd8616f04df2e1b9e18d1e16921979a852bd566f/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 5b076d3755)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 10:25:23 +02:00
Bernd Kuhls
fc11b65ca9 package/i2pd: needs gcc >= 8
Upstream started using std::string_view
https://github.com/search?q=repo%3APurpleI2P%2Fi2pd+string_view&type=commits&s=committer-date&o=asc

with commit
a3e0b3710c

first released in version 2.54.0 which was added to buildroot with
commit dea4f02bbb.

Building the package with the gcc6-based defconfig
bootlin-aarch64-glibc-old is broken:

/builds/bkuhls/buildroot/br-test-pkg/bootlin-aarch64-glibc-old/build/i2pd-2.61.0/libi2pd/Base.h:14:23:
 fatal error: string_view: No such file or directory

BR2_TOOLCHAIN_HAS_GCC_BUG_64735 can be removed as well now as it depends
on gcc < 7.

A backport to LTS branches should be considered.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit a6bb4d52c0)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 10:24:55 +02:00
Bernd Kuhls
f9a1db7994 package/libpcap: security bump version to 1.10.7
https://github.com/the-tcpdump-group/libpcap/blob/libpcap-1.10.7/CHANGES

Fixes the following CVEs:

CVE-2026-0799: Access M[] safely in the BPF interpreter.
CVE-2026-31912: Mind the program bounds in pcap_offline_filter().
CVE-2026-31911: Fail opcodes safely in the BPF interpreter.
CVE-2026-6244: Avoid division by zero via pcap_offline_filter().
CVE-2026-6554: Limit "ja L" looping in pcap_offline_filter().
CVE-2026-18313: Fix a memory leak in rpcapd.
CVE-2026-18238: Fix RPCAP_MSG_PACKET validation.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 446c0f85b8)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 10:23:46 +02:00
Titouan Christophe
96c4fe21cb {linux, linux-headers}: bump 5.{10,15}, 6.{1,6,12,18} series
Update the latest kernel releases:
    - 5.10.269 -> 5.10.270
    - 5.15.220 -> 5.15.221
    - 6.1.187 -> 6.1.188
    - 6.6.156 -> 6.6.157
    - 6.12.109 -> 6.12.110
    - 6.18.50 -> 6.18.52

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-09-15 12:29:26 +02:00
Joseph Kogut
55f6fe7511 package/passt: disable on uclibc
Upstream lists uClibc-ng support as a "nice-to-have, eventually", and
tracks the required build fixes as an enhancement:

https://bugs.passt.top/show_bug.cgi?id=5

passt relies on interfaces and definitions missing from uClibc,
resulting in build failures such as:

qrap.c:145:25: error: 'ARG_MAX' undeclared
tcp.c:2926:34: error: storage size of 'wnd' isn't known
tcp.c:3321:47: error: 'TCP_SEND_QUEUE' undeclared

Disable passt for uClibc toolchains and propagate the dependency to
Podman's passt backend.

Fixes:
 - http://autobuild.buildroot.org/results/7e4/7e4434e01baece4d090e44b4b3713f2eeefc1e27/
 - http://autobuild.buildroot.org/results/3f6/3f60889b4599f1bc42a69076f6fe469517ea9ab5/

Signed-off-by: Joseph Kogut <joseph@anodize.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 87e95b9877)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:54:54 +02:00
Julien Olivain
58a4eac991 package/igh-ethercat: remove stale patch 0002
igh-ethercat is failing while attempting to apply patches,
with error:

    Applying 0002-Linux-6.19.0-support.patch using patch:
    patching file devices/generic.c
    Reversed (or previously applied) patch detected!  Skipping patch.
    1 out of 1 hunk ignored -- saving rejects to file devices/generic.c.rej

The package patch 0002 was added in [1] in branch "master" while it
was in release client cycle. It was cherry-picked in [2] in branch
"next" to apply the bump [3] (which removes the package patches 0001
and 0002). When the branch "next" was merged in "master" in commit [4],
the patch 0002 was kept.

This commit removes this stale patch.

[1] e4cf512c39
[2] 8a5fc970b4
[3] 0a91e760f4
[4] 5f26877955

Fixes:
- https://autobuild.buildroot.org/results/4f509f1f788c1b8dc5a840ffa2e435c5ed7b6eea/

Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit d071817969)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:54:13 +02:00
Bernd Kuhls
f170e75450 package/{glibc, localedef}: security bump version to 2.44-40-g30950ce64
Fixes CVE-2026-18374:
0b4e41fc51

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 0838e968cb)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:50:39 +02:00
Bernd Kuhls
328091ee03 package/libde265: security bump version to 1.1.2
https://github.com/strukturag/libde265/releases/tag/v1.1.2

Security fixes:
(CVE numbers will be added when assigned.)

CVE-2026-XXXXX (GHSA-xp3h-6f5r-8cxp) Heap use-after-free and double free
 in multi-threaded (WPP) decoding. A crafted stream whose slice segments
 repeat or rewind their slice_segment_address within a picture re-ran
 CTB rows that were already marked finished, so the CABAC context handoff
 between rows was no longer ordered and the shared context table was
 released twice. Slice segments that do not follow the previous one in
 tile-scan order are now rejected with the new warning
 DE265_WARNING_SLICE_SEGMENT_ADDRESS_NOT_INCREASING, and the WPP row
 progress is reset for each slice segment. (medium)

CVE-2026-XXXXX (GHSA-mm7m-v26f-wf8x) Heap use-after-free after
 de265_reset(): the pointer to the previous slice header was left
 dangling when the DPB was cleared, and a dependent slice pushed after
 the reset copied from freed memory. (medium)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit e55cb31085)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:50:33 +02:00
Bernd Kuhls
1418aa46a3 package/libheif: security bump version to 1.23.3
https://github.com/strukturag/libheif/releases/tag/v1.23.3

Fixes the following CVEs:

(CVE numbers will be added when assigned.)

CVE-2026-XXXXX (GHSA-x8r2-mggj-j6wr) Heap buffer overflow (write) in the
 uncompressed (unci) mixed-interleave decoder when the two chroma
 components declare different bit depths. Both the written bytes and the
 overflow length are controlled by the file. (critical)

CVE-2026-XXXXX (GHSA-8fmq-r4pf-7m57) Permanent decoder deadlock through
 a reference cycle between an image and its alpha auxiliary image. The
 alpha edge was not covered by the cycle guard and re-entered a held
 mutex. (high)

CVE-2026-XXXXX (GHSA-w7mc-p8jc-p853) Heap out-of-bounds read in the
 YCbCr 4:2:0 to 16-bit interleaved RGB conversion when the chroma
 planes have a lower bit depth than luma. Heap memory could end up in
 the decoded image. YCbCr conversions with mismatched luma and chroma
 bit depths are now rejected. (high)

CVE-2026-XXXXX (GHSA-4jqm-2x34-6f6r) Heap buffer overflow in the SVT-AV1
 encoder plugin when encoding a high-bit-depth alpha channel, and a
 double free on its send-picture error path. (high)

CVE-2026-84451 (GHSA-hh47-fhqr-cj2r) Incomplete fix for
 GHSA-73p7-m7gg-w2jv: the tile range check of the unci decoder (without
 icef) could still overflow, allowing an out-of-bounds read. (medium)

CVE-2026-XXXXX (GHSA-4h82-g446-83fm) Heap out-of-bounds read when
 converting odd-height 4:2:0 frames of an uncompressed (uncv) image
 sequence to RGB. (medium)

CVE-2026-XXXXX (GHSA-9rj8-5mp5-26c9) Out-of-bounds read in the RGB to
 YCbCr identity-matrix color conversion when the R, G, and B planes
 have different bit depths. (medium)

CVE-2026-84450 (GHSA-gh5q-69gg-c964) A clap property combined with an
 oversized ispe reached an assert() in the Fraction arithmetic and
 aborted the process (incomplete fix for GHSA-jc8f-p23p-5hjg). An error
 is returned instead. (medium)

(GHSA-mw6f-29j3-76f4) Several smaller findings:
 heif_image_handle_get_depth_image_handle() and
 heif_image_handle_get_depth_image_representation_info() dereferenced a
 null pointer on files without a depth image; the TIFF input decoder of
 the example tools had an unbounded EXIF tag allocation and a division
 by zero on zero YCbCr subsampling; assert()s in the PNG input decoder
 are now error returns; integer overflow in the Go binding's
 ImageAccess.GetPlane(); heif-view now verifies the decoded frame size
 before display. (medium)

(GHSA-8857-r8x5-7499) Undefined behavior (negative shift) in the HDR
 bit-depth up-conversion for target bit depths above 16. Such
 conversions are now rejected. (low)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit d148168e20)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:50:18 +02:00
Bernd Kuhls
0a07a07352 package/openvpn: security bump version to 2.7.7
https://github.com/OpenVPN/openvpn/blob/v2.7.7/Changes.rst

Fixes CVE-2026-84732, the other CVEs are Windows-only.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 25b8142ef7)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:49:07 +02:00
Marcus Hoffmann
adafcd83a5 package/python-charset-normalizer: update package url
The old url redirects here.

Signed-off-by: Marcus Hoffmann <buildroot@bubu1.eu>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
(cherry picked from commit edb18cf3f2)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:48:57 +02:00
Bernd Kuhls
f01ca534b8 package/libcamera-apps: needs gcc >= 10
Buildroot commit 9a43bf6593 bumped the gcc
dependency from 9 to 10 but forgot to propagate this change to the
libcamera-apps package.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 64ed9e6c43)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:48:39 +02:00
Bernd Kuhls
e061215200 package/qt5/qt5knx: fix license hash
Buildroot 262a7f6d2f added the package but
forgot to provide the hash for LICENSE.GPL3-EXCEPT, instead a hash for
a non-existing file was added to qt5knx.hash.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit d2b7199dea)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:48:20 +02:00
Fengwei Tan
cb1b3a6a5d support/testing, toolchain/toolchain-external/toolchain-external-bootlin: regenerate after MMU dependency update
Regenerate the Bootlin toolchain Kconfig and test configurations using
support/scripts/gen-bootlin-toolchains.

This adds BR2_USE_MMU to the affected uClibc entries and to the
architecture support conditions, and updates the generated tests.
The glibc and musl changes only reorder their existing BR2_USE_MMU
dependencies.

Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 9c6eed9ec0)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:47:56 +02:00
Fengwei Tan
4336a539d7 support/scripts/gen-bootlin-toolchains: add missing BR2_USE_MMU dependencies
The Bootlin uClibc toolchains for m68k-68xxx, riscv32-ilp32d, and
xtensa-lx60 require an MMU. However, their generated Kconfig entries
lack a BR2_USE_MMU dependency, allowing them to be selected for noMMU
configurations. External toolchain validation then fails with:

  MMU support available in C library, please enable BR2_USE_MMU

Add the missing BR2_USE_MMU dependencies for these architectures to
prevent them from being selected for noMMU targets.

Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 3469c6793c)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:47:25 +02:00
Fengwei Tan
f4c24994a7 toolchain/toolchain-external/toolchain-external-bootlin: drop duplicate BR2_TOOLCHAIN_HAS_THREADS selections
Regenerate the Bootlin toolchain Kconfig file with
support/scripts/gen-bootlin-toolchains to remove duplicate
BR2_TOOLCHAIN_HAS_THREADS selections.

Commit 184d47a7ad ("support/scripts/gen-bootlin-toolchains: add new
script to support Bootlin toolchains") initially introduced this issue.

Although commit a33e1af4a0 ("support/scripts/gen-bootlin-toolchains:
avoid selecting _HAS_THREADS multiple times") fixed the generator script,
the Config.in.options file was not regenerated accordingly.

This is a non-functional cleanup, as repeated Kconfig select statements
are harmless.

Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 9556895e78)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:46:39 +02:00
Franciszek Stachura
a0c4367fe5 support/testing: add nano test
Add a basic runtime test for nano. The test attempts to write a file
using the editor.

Signed-off-by: Franciszek Stachura <fbstachura@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 0e631348db)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:46:00 +02:00
Chris Obbard
8ecf613e3e package/dtui: require 64-bit atomic support
dtui depends on tui-textarea which unconditionally imports AtomicU64 in
src/widget.rs to pack a viewport rectangle into a single atomic word:

  use std::sync::atomic::{AtomicU64, Ordering};
  pub struct Viewport(AtomicU64);

As there is no cfg(target_has_atomic) guard in tui-textarea, its
build fails on any target for which rustc does not provide 64-bit
atomics with:

  Compiling tui-textarea v0.7.0
  error[E0432]: unresolved import `std::sync::atomic::AtomicU64`
    --> .../dtui-3.0.0/VENDOR/tui-textarea/src/widget.rs:10:25
     |
  10 | use std::sync::atomic::{AtomicU64, Ordering};
     |                         ^^^^^^^^^ no `AtomicU64` in `sync::atomic`
     |
  help: a similar name exists in the module
     |
  10 - use std::sync::atomic::{AtomicU64, Ordering};
  10 + use std::sync::atomic::{AtomicU32, Ordering};

This has been reported to tui-textarea upstream, but unfortunately the
project seems to be unmaintained (issue linked below). A sane workaround
is to disable the package on targets which lack 64-bit atomic support,
which is exactly what BR2_PACKAGE_HOST_RUSTC_TARGET_HAS_ATOMIC_U64
describes: it is n for armv5te-unknown-linux-{gnu,musl}eabi and
powerpc-unknown-linux-gnu, the only rust targets Buildroot can generate
which lack 64-bit atomics, and y everywhere else.

The same problem was hit by package/dust and worked around in commit
3abc3b97ba ("package/dust: bump to version 1.1.2") by bumping to a
version in which upstream had added the missing guard. That is not an
option here as tui-textarea 0.7.0 is the latest release.

Note that a runtime test for dtui cannot use the default
infra.basetest.BASIC_TOOLCHAIN_CONFIG, since that builds with
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV5_EABI_GLIBC_STABLE, where dtui is now
disabled; such a test would need an armv7 or aarch64 toolchain instead.

Build tested with utils/test-pkg against:
- BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV5_EABI_GLIBC_STABLE
- BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV5_EABI_MUSL_STABLE
- BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_POWERPC_E500MC_GLIBC_STABLE

all three fail with the above error before this change and are skipped
after it, while armv7 (glibc and musl), aarch64, powerpc64le and x86-64
still select and build the package.

Link: https://github.com/rhysd/tui-textarea/issues/66
Fixes: https://autobuild.buildroot.org/results/188f6442371500731453f75983590c922eab6d57
Fixes: https://autobuild.buildroot.org/results/e254db2654f18f1d2110eb8b1a32b43ad0f2a3d6
Signed-off-by: Christopher Obbard <chris.obbard@oss.qualcomm.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 99529edaef)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:42:17 +02:00
Chris Obbard
872e7b8cef package/rustc: add BR2_PACKAGE_HOST_RUSTC_TARGET_HAS_ATOMIC_U64
Rust does not provide 64-bit atomics on every target Buildroot can
generate. rustc sets max_atomic_width = 32 for three of the 25 targets
listed in RUST_TARGETS in utils/update-rust, so
core::sync::atomic::AtomicU64 and AtomicI64 simply do not exist there:

  $ rustc --print cfg --target <target> | grep target_has_atomic
  armv5te-unknown-linux-gnueabi     "16" "32" "8" "ptr"
  armv5te-unknown-linux-musleabi    "16" "32" "8" "ptr"
  powerpc-unknown-linux-gnu         "16" "32" "8" "ptr"

Every other supported target, including armv6, armv7, aarch64, all the
x86 variants, riscv64, s390x, sparc64 and both 64-bit powerpcs, has
them, e.g.:

  arm-unknown-linux-gnueabi         "16" "32" "64" "8" "ptr"
  armv7-unknown-linux-gnueabihf     "16" "32" "64" "8" "ptr"

A crate that uses 64-bit atomics without a cfg(target_has_atomic = "64")
guard therefore fails to build on those three targets with:

  error[E0432]: unresolved import `std::sync::atomic::AtomicU64`
     |
     |         atomic::{AtomicU64, AtomicU8, AtomicUsize, Ordering},
     |                  ^^^^^^^^^ no `AtomicU64` in `sync::atomic`

This has been hit at least twice already: by package/dust, worked around
in commit 3abc3b97ba ("package/dust: bump to version 1.1.2") by moving
to a release in which upstream had added the guard and by package/dtui,
which has no such release available and had to open-code the affected
architectures instead.

It is likely to keep recurring: infra.basetest.BASIC_TOOLCHAIN_CONFIG
builds with BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV5_EABI_GLIBC_STABLE, so
every runtime test that does not override the toolchain compiles for
armv5te, one of the three affected targets. That is exactly how the two
failures above were found.

Add a hidden symbol so packages can express this constraint once, rather
than each open-coding BR2_ARM_CPU_ARMV5 and BR2_powerpc and needing to
update whenever rust gains or changes a target.

Note that armv5te and 32-bit powerpc are only supported by rust for
glibc and musl, so the uclibc variants of those architectures are
already excluded by BR2_PACKAGE_HOST_RUSTC_TARGET_ARCH_SUPPORTS.

Signed-off-by: Christopher Obbard <chris.obbard@oss.qualcomm.com>
Reviewed-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 698535473f)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:39:22 +02:00
Bernd Kuhls
d0a22ac6b2 package/libxml2: security bump version to 2.15.4
https://download.gnome.org/sources/libxml2/2.15/libxml2-2.15.4.news

Fixes the following security issues:

- xmlregexp: Prevent out-of-bounds read in NXT macro
- fix: add missing overflow checks in dict.c, uri.c, and valid.c
- xmlregexp: Calc string length after null checking
- xpointer: Check overflow in xmlXPtrEvalXPtrPart
- xmlIO: Check for int overflow before calling writecallback
- fix(xinclude): propagate parseFlags in xmlXIncludeProcess and
  xmlXIncludeProcessTree

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
(cherry picked from commit 270ef20df1)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:36:46 +02:00
Bernd Kuhls
02343dd7b6 package/wireless-regdb: bump version to 2026.09.03
https://lists.infradead.org/pipermail/wireless-regdb/2026-September/001953.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
(cherry picked from commit 47c45f7f62)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:30:30 +02:00
Martin Bachmann
dca22cf037 package/dejavu: add missing license information
DEJAVU_LICENSE is primarily BitstreamVera. The license file also
specifies that DejaVu-specific changes and certain math extensions are
in the Public Domain. This matches the licensing logic used by
OpenEmbedded/Yocto.

Signed-off-by: Martin Bachmann <martin.bachmann@designwerk.com>
[Fiona: wrap lines in commit message]
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
(cherry picked from commit df61b7e9bb)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-10 11:27:04 +02:00
Titouan Christophe
dabf3d5bf6 {linux, linux-headers}: bump 6.{12,18} series
Update the latest kernel releases:
    - 6.12.108 -> 6.12.109
    - 6.18.49 -> 6.18.50

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-09-07 19:17:37 +02:00
240 changed files with 1719 additions and 1171 deletions

View File

@@ -404,9 +404,6 @@ package/hplip/0002-configure.in-fix-AM_INIT_AUTOMAKE-call.patch lib_patch.Upstre
package/i2pd/S99i2pd Shellcheck lib_sysv.Indent lib_sysv.Variables
package/i7z/0001-fix-build-with-gcc-10.patch lib_patch.Upstream
package/ibm-sw-tpm2/0001-Use-LONG_BIT-to-define-RADIX_BITS.patch lib_patch.Upstream
package/ibrcommon/0001-ibrcommon-data-File.cpp-support-POSIX-basename-call.patch lib_patch.Upstream
package/ibrcommon/0002-ibrcommon-added-openssl-1.1-compatibility-264.patch lib_patch.Upstream
package/ibrcommon/0003-ibrcommon-ssl-gcm-fix-static-build-with-openssl.patch lib_patch.Upstream
package/icu/0001-dont-build-static-dynamic-twice.patch lib_patch.Upstream
package/icu/0002-link-icudata-as-data-only.patch lib_patch.Upstream
package/icu/0003-fix-static-linking-with-icu-uc.patch lib_patch.Upstream
@@ -552,7 +549,6 @@ package/lirc-tools/0001-plugins-devinput.c-fix-build-with-musl-1.2.0.patch lib_p
package/lirc-tools/0002-configure-add-disable-doc-option.patch lib_patch.Upstream
package/lirc-tools/S25lircd lib_sysv.Indent lib_sysv.Variables
package/live555/0001-Add-a-pkg-config-file-for-the-shared-libraries.patch lib_patch.Upstream
package/lldpd/S60lldpd Shellcheck lib_sysv.Indent lib_sysv.Variables
package/lm-sensors/0001-no-host-ldconfig.patch lib_patch.Upstream
package/lmbench/0001-scripts-build-use-bin-bash-as-shell.patch lib_patch.Upstream
package/lmbench/0002-src-Makefile-add-lmbench-to-list-of-executables.patch lib_patch.Upstream
@@ -615,7 +611,6 @@ package/mono/0002-Ongoing-work-on-the-cmake-build.patch lib_patch.Upstream
package/motion/S99motion Shellcheck lib_sysv.Indent lib_sysv.Variables
package/mpir/0001-mpn-arm-udiv.asm-workaround-binutils-bug-14887.patch lib_patch.Upstream
package/mraa/0001-include-Declare-gVERSION-global-as-extern.patch lib_patch.Upstream
package/mrouted/S41mrouted NotExecutable
package/mrp/S65mrp lib_sysv.Indent lib_sysv.Variables
package/multipath-tools/S60multipathd Shellcheck
package/musl/0001-avoid-kernel-if_ether.h.patch lib_patch.Upstream

View File

@@ -159,6 +159,8 @@ F: package/libxmlsec1/
F: package/openscap/
F: package/python-scp/
F: support/testing/tests/package/test_libldns.py
F: support/testing/tests/package/test_openscap/
F: support/testing/tests/package/test_openscap.py
F: support/testing/tests/package/test_python_scp.py
N: Alistair Francis <alistair@alistair23.me>
@@ -1123,6 +1125,9 @@ F: configs/freescale_imx6ullevk_defconfig
N: Falco Hyfing <hyfinglists@gmail.com>
F: package/python-pymodbus/
N: Fengwei Tan <tfx2001@outlook.com>
F: support/testing/tests/core/test_flat_stacksize.py
N: Fiona Klute <fiona.klute@gmx.de>
F: package/*/S*
F: package/panel-mipi-dbi-firmware/
@@ -1170,6 +1175,7 @@ F: package/ser2net/
N: Franciszek Stachura <fbstachura@gmail.com>
F: support/testing/tests/package/test_memcached.py
F: support/testing/tests/package/test_nano.py
N: Francois Dugast <francois.dugast.foss@gmail.com>
F: board/sipeed/licheepi_nano/
@@ -1902,6 +1908,7 @@ F: support/testing/tests/package/test_dosfstools.py
F: support/testing/tests/package/test_dosfstools/
F: support/testing/tests/package/test_dpdk.py
F: support/testing/tests/package/test_ed.py
F: support/testing/tests/package/test_erlang.py
F: support/testing/tests/package/test_ethtool.py
F: support/testing/tests/package/test_ethtool/
F: support/testing/tests/package/test_exfatprogs.py
@@ -2041,6 +2048,7 @@ F: support/testing/tests/package/test_sed.py
F: support/testing/tests/package/test_socat.py
F: support/testing/tests/package/test_sox.py
F: support/testing/tests/package/test_sqlite.py
F: support/testing/tests/package/test_squid.py
F: support/testing/tests/package/test_strace.py
F: support/testing/tests/package/test_stress_ng.py
F: support/testing/tests/package/test_swipl.py
@@ -2120,10 +2128,6 @@ F: package/rockchip-rkbin/
N: Klaus Heinrich Kiwi <klaus@linux.vnet.ibm.com>
F: package/wqy-zenhei/
N: Koen Martens <gmc@sonologic.nl>
F: package/capnproto/
F: package/linuxconsoletools/
N: Kory Maincent <kory.maincent@bootlin.com>
F: board/octavo/osd32mp1-brk/
F: board/octavo/osd32mp1-red/

View File

@@ -20,6 +20,14 @@ config BR2_X86_CPU_HAS_AVX
config BR2_X86_CPU_HAS_AVX2
bool
# BR2_X86_CPU_HAS_XOP is selected by the AMD Bulldozer family (bdver1
# to bdver4), which is the only family implementing XOP. On those CPUs,
# gcc also enables the equally Bulldozer-specific FMA4 and LWP
# extensions (and TBM starting with bdver2). Those extensions were
# dropped again with Zen.
config BR2_X86_CPU_HAS_XOP
bool
# BR2_X86_CPU_HAS_AVX512 implies the following AVX512 extensions:
# AVX512F, AVX512BW, AVX512CD, AVX512DQ, AVX512VL
# This subset is common to Intel Xeon (excl Xeon Phi), AMD Zen 4, and
@@ -604,6 +612,7 @@ config BR2_x86_bulldozer
select BR2_X86_CPU_HAS_SSSE3
select BR2_X86_CPU_HAS_SSE4
select BR2_X86_CPU_HAS_SSE42
select BR2_X86_CPU_HAS_XOP
config BR2_x86_piledriver
bool "piledriver"
select BR2_X86_CPU_HAS_MMX
@@ -613,6 +622,7 @@ config BR2_x86_piledriver
select BR2_X86_CPU_HAS_SSSE3
select BR2_X86_CPU_HAS_SSE4
select BR2_X86_CPU_HAS_SSE42
select BR2_X86_CPU_HAS_XOP
config BR2_x86_steamroller
bool "steamroller"
select BR2_X86_CPU_HAS_MMX
@@ -622,6 +632,7 @@ config BR2_x86_steamroller
select BR2_X86_CPU_HAS_SSSE3
select BR2_X86_CPU_HAS_SSE4
select BR2_X86_CPU_HAS_SSE42
select BR2_X86_CPU_HAS_XOP
select BR2_ARCH_NEEDS_GCC_AT_LEAST_4_8
config BR2_x86_excavator
bool "excavator"
@@ -634,6 +645,7 @@ config BR2_x86_excavator
select BR2_X86_CPU_HAS_SSE42
select BR2_X86_CPU_HAS_AVX
select BR2_X86_CPU_HAS_AVX2
select BR2_X86_CPU_HAS_XOP
select BR2_ARCH_NEEDS_GCC_AT_LEAST_4_9
config BR2_x86_zen
bool "zen"

View File

@@ -1,10 +1,10 @@
# From https://www.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
sha256 e1d1ea200d22d55c9f5d5fae59e69bb3b494515705fc3390cd54231ee4f4baaf linux-6.12.108.tar.xz
sha256 aee2264a4eaf4a14344b47a0469bd42e8b4885b24f110b724262b3da956f411d linux-6.6.156.tar.xz
sha256 1b6e798aeaa708ca670a426ad5a6c86dc2237b8e59e8822876976c383873642b linux-6.1.187.tar.xz
sha256 9e59dc67624188fa12a6601f9598499cd6662a9066be572b59f935e3d7849810 linux-6.12.111.tar.xz
sha256 b74a43d0630809b7871cc906ac155e956cbc0b2e78a7451f5e6c8bfcb1208c30 linux-6.6.157.tar.xz
sha256 ed4d0acb1307c235230c89efc094e210e6290593f94a7e617f28b1001101a33a linux-6.1.188.tar.xz
# From https://www.kernel.org/pub/linux/kernel/v5.x/sha256sums.asc
sha256 b5b2992505120ac864cd9ccf7cc44541684df46c5a0b09ccdec93fb7f9aa6723 linux-5.15.220.tar.xz
sha256 9c5a168119406674ff3bcf366a3a235206eecfa7b79f04629b31a7cc678cc6e9 linux-5.10.269.tar.xz
sha256 c07882e1e528efe206567a26de30b192db8dc4369974d4ef4ce708691fa1148c linux-5.15.221.tar.xz
sha256 de73d528b04be91f6eb86660aa67a4d53b96bbf20bb5a326e78f802d744debe7 linux-5.10.270.tar.xz
# Locally computed
sha256 bd5db7fe3b0475cce4fc72db7a7f7df1c22b970aabe5ebff6ddd48098973bdf2 linux-cip-5.10.254-cip72.tar.gz
sha256 97d7d5139900c10ff7435779be4857dda531e7cf6abba52c12a5f39aae195411 linux-cip-5.10.254-cip72-rt32.tar.gz

View File

@@ -2,7 +2,7 @@
sha256 614d95fafdcb5cce2b6620e7edc6afbb606bffd4655405586815d84687841ad7 linux-7.1.13.tar.xz
# From https://www.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
sha256 ae826f33111fea6f1d279dde7299d7463c8dfd204aeb75a8fb5432bc60a28191 linux-6.18.49.tar.xz
sha256 9df30b02dd8102bbd0be52556288ef6889ddbe7f1ddb96fbf847d0becf3eacac linux-6.18.54.tar.xz
# Licenses hashes
sha256 fb5a425bd3b3cd6071a3a9aff9909a859e7c1158d54d32e07658398cd67eb6a0 COPYING

View File

@@ -708,7 +708,7 @@ linux-rebuild-with-initramfs: rootfs-cpio
linux-rebuild-with-initramfs:
@$(call MESSAGE,"Rebuilding kernel with initramfs")
# Build the kernel.
$(LINUX_MAKE_ENV) $(BR2_MAKE) $(LINUX_MAKE_FLAGS) -C $(LINUX_DIR) $(LINUX_TARGET_NAME)
+$(LINUX_MAKE_ENV) $(BR2_MAKE) $(LINUX_MAKE_FLAGS) -C $(LINUX_DIR) $(LINUX_TARGET_NAME)
$(LINUX_APPEND_DTB)
# Copy the kernel image(s) to its(their) final destination
$(call LINUX_INSTALL_IMAGE,$(BINARIES_DIR))

View File

@@ -2,7 +2,7 @@
sha256 373c98f4d4a1b923b42def0aee03f4e36aca9d1c244a8eeda646da8a97f89663 asterisk-22.10.1.tar.gz
# Locally computed
sha256 633c3dc34ffb21af8ac9ee160245c9c174379391e35cace1b6c9f516a260f683 pjproject-2.16.tar.bz2
sha256 04b2eb1f0f01aa0ad1945b167171843448a51aa6b7c3e806496d434f13a112b7 pjproject-2.17.tar.bz2
sha256 6775095bcd417d375faddc1f17cdd7706ad8aa9b9b02404990c4b0ee218ee379 libjwt-1.15.3.tar.gz
# sha1 from: http://downloads.asterisk.org/pub/telephony/sounds/releases

View File

@@ -4,6 +4,8 @@
#
################################################################################
# When bumping asterisk's version, verify that the versions of pjsip,
# libjwt and sounds below are still matching.
ASTERISK_VERSION = 22.10.1
# Use the github mirror: it's an official mirror maintained by Digium, and
# provides tarballs, which the main Asterisk git tree (behind Gerrit) does not.
@@ -12,13 +14,13 @@ ASTERISK_SITE = $(call github,asterisk,asterisk,$(ASTERISK_VERSION))
# compilation with the external pjsip produces a non-working asterisk, which
# segfaults. The reason behind this is unclear.
# https://github.com/asterisk/asterisk/issues/671
ASTERISK_PJSIP_URL = https://raw.githubusercontent.com/asterisk/third-party/master/pjproject/2.16/
ASTERISK_PJSIP_URL = https://raw.githubusercontent.com/asterisk/third-party/master/pjproject/2.17/
ASTERISK_LIBJWT_URL = https://raw.githubusercontent.com/asterisk/third-party/master/libjwt/1.15.3/
ASTERISK_SOUNDS_BASE_URL = http://downloads.asterisk.org/pub/telephony/sounds/releases
ASTERISK_EXTRA_DOWNLOADS = \
$(ASTERISK_SOUNDS_BASE_URL)/asterisk-core-sounds-en-gsm-1.6.1.tar.gz \
$(ASTERISK_SOUNDS_BASE_URL)/asterisk-moh-opsound-wav-2.03.tar.gz \
$(ASTERISK_PJSIP_URL)/pjproject-2.16.tar.bz2 \
$(ASTERISK_PJSIP_URL)/pjproject-2.17.tar.bz2 \
$(ASTERISK_LIBJWT_URL)/libjwt-1.15.3.tar.gz
ASTERISK_LICENSE = GPL-2.0, BSD-3-Clause (SHA1, resample), BSD-4-Clause (db1-ast)

View File

@@ -9,6 +9,7 @@ config BR2_PACKAGE_BCC
depends on BR2_USE_WCHAR # clang, python3
depends on BR2_TOOLCHAIN_HAS_THREADS # clang, python3
depends on !BR2_STATIC_LIBS # clang, python3
depends on !BR2_TOOLCHAIN_HAS_GCC_BUG_64735 # clang, llvm
select BR2_PACKAGE_CLANG
select BR2_PACKAGE_ELFUTILS
select BR2_PACKAGE_FLEX # needs FlexLexer.h
@@ -48,3 +49,8 @@ comment "bcc needs a glibc toolchain, C++, wchar, threads, dynamic libs, gcc >=
|| !BR2_USE_WCHAR \
|| !BR2_TOOLCHAIN_HAS_THREADS \
|| BR2_STATIC_LIBS
comment "bcc needs a toolchain not affected by GCC bug 64735"
depends on BR2_PACKAGE_LLVM_ARCH_SUPPORTS
depends on BR2_USE_MMU
depends on BR2_TOOLCHAIN_HAS_GCC_BUG_64735

View File

@@ -3,7 +3,7 @@ config BR2_PACKAGE_BCUSDK
depends on BR2_USE_MMU # libpthsem
depends on BR2_INSTALL_LIBSTDCPP
select BR2_PACKAGE_LIBPTHSEM
select BR2_PACKAGE_ARGP_STANDALONE if BR2_TOOLCHAIN_USES_UCLIBC || BR2_TOOLCHAIN_USES_MUSL
select BR2_PACKAGE_ARGP_STANDALONE if !BR2_TOOLCHAIN_USES_GLIBC
help
A free development environment for the Bus Coupling Units of
the European Installation Bus.

View File

@@ -5,7 +5,7 @@ config BR2_PACKAGE_BIND
depends on BR2_TOOLCHAIN_HAS_THREADS_NPTL # libuv
depends on BR2_INSTALL_LIBSTDCPP # liburcu
depends on !BR2_STATIC_LIBS # libuv
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 # libuv
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_8
depends on BR2_PACKAGE_LIBURCU_ARCH_SUPPORTS # liburcu
select BR2_PACKAGE_LIBCAP
select BR2_PACKAGE_LIBURCU
@@ -48,9 +48,9 @@ config BR2_PACKAGE_BIND_TOOLS
endif
comment "bind needs a toolchain w/ NPTL, dynamic library, C++, gcc >= 4.9"
comment "bind needs a toolchain w/ NPTL, dynamic library, C++, gcc >= 8"
depends on BR2_USE_MMU
depends on BR2_TOOLCHAIN_HAS_SYNC_4
depends on BR2_PACKAGE_LIBURCU_ARCH_SUPPORTS
depends on !BR2_TOOLCHAIN_HAS_THREADS_NPTL || BR2_STATIC_LIBS \
|| BR2_INSTALL_LIBSTDCPP || !BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 \
|| BR2_PACKAGE_LIBURCU_ARCH_SUPPORTS
|| !BR2_INSTALL_LIBSTDCPP || !BR2_TOOLCHAIN_GCC_AT_LEAST_8

View File

@@ -1,4 +1,4 @@
# Verified from https://ftp.isc.org/isc/bind9/9.20.26/bind-9.20.26.tar.xz.asc
# Verified from https://ftp.isc.org/isc/bind9/9.20.27/bind-9.20.29.tar.xz.asc
# with key 706B6C28620E76F91D11F7DF510A642A06C52CEC
sha256 55248def0f870c4c46b3de72978ea972615131516663188a4564dca1d20bf350 bind-9.20.26.tar.xz
sha256 587029508b3b1b43229fae416c97e5543aba45809cefaca98a5004a02a5736c1 bind-9.20.29.tar.xz
sha256 9734825d67a3ac967b2c2f7c9a83c9e5db1c2474dbe9599157c3a4188749ebd4 COPYRIGHT

View File

@@ -4,7 +4,7 @@
#
################################################################################
BIND_VERSION = 9.20.26
BIND_VERSION = 9.20.29
BIND_SOURCE= bind-$(BIND_VERSION).tar.xz
BIND_SITE = https://ftp.isc.org/isc/bind9/$(BIND_VERSION)
BIND_INSTALL_STAGING = YES

View File

@@ -21,9 +21,6 @@ BINUTILS_LICENSE = GPL-3.0+, GPL-2.0+, LGPL-2.1+
BINUTILS_LICENSE_FILES = COPYING COPYING3 COPYING.LIB
BINUTILS_CPE_ID_VENDOR = gnu
# 0003-objdump-memleak.patch
BINUTILS_IGNORE_CVES += CVE-2025-3198
ifeq ($(BINUTILS_FROM_GIT),y)
BINUTILS_DEPENDENCIES += host-flex host-bison
HOST_BINUTILS_DEPENDENCIES += host-flex host-bison

View File

@@ -95,6 +95,9 @@ config BR2_PACKAGE_BOOST_DATE_TIME
A set of date-time libraries based on generic programming
concepts.
This library is header only since boost 1.77.0. Building a
stub library is still supported for backward compatibility.
config BR2_PACKAGE_BOOST_EXCEPTION
bool "boost-exception"
help
@@ -200,7 +203,6 @@ config BR2_PACKAGE_BOOST_LOG
depends on BR2_TOOLCHAIN_SUPPORTS_ALWAYS_LOCKFREE_ATOMIC_INTS # boost-atomic
depends on !BR2_TOOLCHAIN_HAS_GCC_BUG_64735 # boost-thread
select BR2_PACKAGE_BOOST_ATOMIC
select BR2_PACKAGE_BOOST_DATE_TIME
select BR2_PACKAGE_BOOST_FILESYSTEM
select BR2_PACKAGE_BOOST_REGEX
select BR2_PACKAGE_BOOST_THREAD
@@ -359,7 +361,6 @@ config BR2_PACKAGE_BOOST_WAVE
depends on !BR2_m68k_cf
depends on BR2_TOOLCHAIN_SUPPORTS_ALWAYS_LOCKFREE_ATOMIC_INTS # boost-thread
depends on !BR2_TOOLCHAIN_HAS_GCC_BUG_64735 # boost-thread
select BR2_PACKAGE_BOOST_DATE_TIME
select BR2_PACKAGE_BOOST_FILESYSTEM
select BR2_PACKAGE_BOOST_THREAD
help

View File

@@ -1,5 +1,5 @@
# From https://github.com/containers/bubblewrap/releases/download/v0.11.2/bubblewrap-0.11.2.tar.xz.sha256sum
sha256 69abc30005d2186baf7737feacd8da35633b93cf5af38838ecff17c5f8e924f6 bubblewrap-0.11.2.tar.xz
# From https://github.com/containers/bubblewrap/releases/tag/v0.13.0
sha256 4734237473c0e5d695e4e9034a34e43b2dbf5164655bd13fa59ae376b2b7a765 bubblewrap-0.13.0.tar.xz
# Hash for license files:
sha256 b7993225104d90ddd8024fd838faf300bea5e83d91203eab98e29512acebd69c COPYING
sha256 dc626520dcd53a22f727af3ee42c770e56c97a64fe3adb063799d8ab032fe551 COPYING

View File

@@ -4,21 +4,24 @@
#
################################################################################
BUBBLEWRAP_VERSION = 0.11.2
BUBBLEWRAP_VERSION = 0.13.0
BUBBLEWRAP_SITE = https://github.com/containers/bubblewrap/releases/download/v$(BUBBLEWRAP_VERSION)
BUBBLEWRAP_SOURCE = bubblewrap-$(BUBBLEWRAP_VERSION).tar.xz
BUBBLEWRAP_DEPENDENCIES = host-pkgconf libcap
BUBBLEWRAP_LICENSE = LGPL-2.0+
BUBBLEWRAP_LICENSE = LGPL-2.1+
BUBBLEWRAP_LICENSE_FILES = COPYING
BUBBLEWRAP_CPE_ID_VENDOR = projectatomic
define BUBBLEWRAP_LINUX_CONFIG_FIXUPS
$(call KCONFIG_ENABLE_OPT,CONFIG_USER_NS)
endef
BUBBLEWRAP_CONF_OPTS = \
-Dassume_kernel=$(LINUX_VERSION_PROBED) \
-Dzsh_completion=disabled \
-Dman=disabled \
-Dpython=$(HOST_DIR)/bin/python \
-Drequire_userns=false \
-Dsupport_setuid=true \
-Dtests=false
ifeq ($(BR2_PACKAGE_BASH_COMPLETION),y)
@@ -36,10 +39,4 @@ else
BUBBLEWRAP_CONF_OPTS += -Dselinux=disabled
endif
# We need to mark bwrap as setuid, in case the kernel
# has user namespaces disabled for non-root users.
define BUBBLEWRAP_PERMISSIONS
/usr/bin/bwrap f 1755 0 0 - - - - -
endef
$(eval $(meson-package))

View File

@@ -1,3 +1,3 @@
# Locally computed
sha256 3dde63727549d4a39154e78b95f4a5dad96af236ca6cef531f347c0b923c74d5 cannelloni-2.0.0.tar.gz
sha256 c704707f7dd9f1ed64e9195097809f8882c03b1fa0a79864b8e3bf286521e3d7 cannelloni-2.1.2.tar.gz
sha256 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643 gpl-2.0.txt

View File

@@ -4,7 +4,7 @@
#
################################################################################
CANNELLONI_VERSION = 2.0.0
CANNELLONI_VERSION = 2.1.2
CANNELLONI_SITE = $(call github,mguentner,cannelloni,v$(CANNELLONI_VERSION))
CANNELLONI_LICENSE = GPL-2.0
CANNELLONI_LICENSE_FILES = gpl-2.0.txt

View File

@@ -6,6 +6,7 @@ config BR2_PACKAGE_CLAMAV
depends on BR2_USE_MMU # fork()
depends on !BR2_STATIC_LIBS # dlopen
depends on BR2_USE_WCHAR
depends on BR2_TOOLCHAIN_HAS_SYNC_4 # json-c
select BR2_PACKAGE_BZIP2
select BR2_PACKAGE_HOST_RUSTC
select BR2_PACKAGE_JSON_C
@@ -29,3 +30,4 @@ comment "clamav needs a toolchain w/ C++, dynamic library, threads, wchar"
|| !BR2_TOOLCHAIN_HAS_THREADS || !BR2_USE_WCHAR
depends on BR2_PACKAGE_HOST_RUSTC_TARGET_ARCH_SUPPORTS
depends on BR2_USE_MMU
depends on BR2_TOOLCHAIN_HAS_SYNC_4

View File

@@ -2,7 +2,7 @@ config BR2_PACKAGE_CPIO
bool "cpio"
depends on BR2_USE_WCHAR
# Need argp.h support
select BR2_PACKAGE_ARGP_STANDALONE if BR2_TOOLCHAIN_USES_UCLIBC || BR2_TOOLCHAIN_USES_MUSL
select BR2_PACKAGE_ARGP_STANDALONE if !BR2_TOOLCHAIN_USES_GLIBC
help
cpio archive utility for creation and extraction.

View File

@@ -3,8 +3,7 @@ config BR2_PACKAGE_CRYPTSETUP
depends on BR2_TOOLCHAIN_HAS_THREADS # lvm2
depends on BR2_USE_MMU # lvm2, libargon2
depends on BR2_TOOLCHAIN_HAS_SYNC_4 # json-c
select BR2_PACKAGE_ARGP_STANDALONE if BR2_PACKAGE_LIBSSH && \
(BR2_TOOLCHAIN_USES_UCLIBC || BR2_TOOLCHAIN_USES_MUSL)
select BR2_PACKAGE_ARGP_STANDALONE if BR2_PACKAGE_LIBSSH && !BR2_TOOLCHAIN_USES_GLIBC
select BR2_PACKAGE_POPT
select BR2_PACKAGE_LVM2
select BR2_PACKAGE_UTIL_LINUX

View File

@@ -7,6 +7,7 @@
DEJAVU_VERSION = 2.37
DEJAVU_SITE = https://sourceforge.net/projects/dejavu/files/dejavu/$(DEJAVU_VERSION)
DEJAVU_SOURCE = dejavu-fonts-ttf-$(DEJAVU_VERSION).tar.bz2
DEJAVU_LICENSE = Bitstream-Vera
DEJAVU_LICENSE_FILES = LICENSE
DEJAVU_FONTS_INSTALL =

View File

@@ -1,45 +0,0 @@
From 6970080b10a53d858dd444a643a2bd911de12940 Mon Sep 17 00:00:00 2001
From: Chen Qi <Qi.Chen@windriver.com>
Date: Thu, 29 May 2025 11:28:38 +0800
Subject: [PATCH] s3-aws: fix build for 386
When building for 386, we got the following build error:
registry/storage/driver/s3-aws/s3.go:312:99: cannot use
maxChunkSize (untyped int constant 5368709120) as int value
in argument to getParameterAsInteger (overflows)
This is because the s3_64bit.go is used. Adjust the build tag matching
in s3_32bit.go and s3_64bit.go to fix this issue.
Signed-off-by: Chen Qi <Qi.Chen@windriver.com>
Upstream: https://github.com/distribution/distribution/commit/6970080b10a53d858dd444a643a2bd911de12940
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
---
registry/storage/driver/s3-aws/s3_32bit.go | 2 +-
registry/storage/driver/s3-aws/s3_64bit.go | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/registry/storage/driver/s3-aws/s3_32bit.go b/registry/storage/driver/s3-aws/s3_32bit.go
index 218e3eab..84161fcb 100644
--- a/registry/storage/driver/s3-aws/s3_32bit.go
+++ b/registry/storage/driver/s3-aws/s3_32bit.go
@@ -1,4 +1,4 @@
-//go:build arm
+//go:build arm || 386
package s3
diff --git a/registry/storage/driver/s3-aws/s3_64bit.go b/registry/storage/driver/s3-aws/s3_64bit.go
index 55254e49..2ed1f92f 100644
--- a/registry/storage/driver/s3-aws/s3_64bit.go
+++ b/registry/storage/driver/s3-aws/s3_64bit.go
@@ -1,4 +1,4 @@
-//go:build !arm
+//go:build !arm && !386
package s3
--
2.51.1

View File

@@ -1,3 +1,3 @@
# Locally computed
sha256 6330e6b625c0232b43cee8ea32800a660a7d7a0c79f4f53e4d9a8a6707138d46 distribution-registry-v3.0.0-git4-go2.tar.gz
sha256 5ed3891ed90c7d097304f49aec2e1f16299770309e2f424b5ee9531b1da2429a distribution-registry-v3.1.1-git4-go2.tar.gz
sha256 cb5e8e7e5f4a3988e1063c142c60dc2df75605f4c46515e776e3aca6df976e14 LICENSE

View File

@@ -4,7 +4,7 @@
#
################################################################################
DISTRIBUTION_REGISTRY_VERSION = v3.0.0
DISTRIBUTION_REGISTRY_VERSION = v3.1.1
DISTRIBUTION_REGISTRY_SITE = https://github.com/distribution/distribution
DISTRIBUTION_REGISTRY_SITE_METHOD = git

View File

@@ -3,6 +3,8 @@ config BR2_PACKAGE_DTUI
depends on BR2_PACKAGE_HOST_RUSTC_TARGET_ARCH_SUPPORTS
depends on BR2_TOOLCHAIN_HAS_THREADS # dbus
depends on BR2_USE_MMU # dbus
# tui-textarea unconditionally uses AtomicU64
depends on BR2_PACKAGE_HOST_RUSTC_TARGET_HAS_ATOMIC_U64
select BR2_PACKAGE_DBUS # runtime
select BR2_PACKAGE_HOST_RUSTC
help
@@ -14,5 +16,6 @@ config BR2_PACKAGE_DTUI
comment "dtui needs a toolchain w/ threads"
depends on BR2_PACKAGE_HOST_RUSTC_TARGET_ARCH_SUPPORTS
depends on BR2_PACKAGE_HOST_RUSTC_TARGET_HAS_ATOMIC_U64
depends on BR2_USE_MMU
depends on !BR2_TOOLCHAIN_HAS_THREADS

View File

@@ -2,7 +2,7 @@ buildconfig is meant to be executed on the host, so it has to be compiled
using $(HOSTCC), not $(CC).
Signed-off-by: Luca Ceresoli <luca@lucaceresoli.net>
[Bernd: rebased for version 4.99]
[Bernd: rebased for version 4.100]
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
OS/Makefile-Base | 4 ++--
@@ -22,4 +22,5 @@ index 29a6ad3..420ba60 100644
+ $(FE)$(HOSTCC) $(HOSTCFLAGS) $(INCLUDE) -o buildconfig buildconfig.c
util_deps: config ../src/utils/msgid.frag
UTIL_DEPS = $(CONFIG_DEPS) ../src/utils/msgid.frag

View File

@@ -1,95 +1,37 @@
From a47de397eb1f28356086f315a443c288599d8657 Mon Sep 17 00:00:00 2001
From cb7d04db69623673e606a3249bc7de1330c8f0b6 Mon Sep 17 00:00:00 2001
From: Bernd Kuhls <bernd@kuhls.net>
Date: Sat, 1 Nov 2025 17:00:52 +0100
Date: Fri, 4 Sep 2026 18:43:42 +0200
Subject: [PATCH] Fix cross-compile by adding LD variable
Fixes cross-build error due to commit
a449ff8ca50e6df5faee2f1e83e1198c27738dfc.
Upstream: https://code.exim.org/exim/exim/pulls/3244
Hard-coding "ld" when cross-compiling is a bad idea.
Upstream: https://github.com/Exim/exim/pull/98
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
src/OS/Makefile-Base | 10 +++++-----
src/OS/Makefile-Default | 1 +
src/src/miscmods/Makefile | 2 +-
3 files changed, 7 insertions(+), 6 deletions(-)
src/miscmods/Makefile | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/OS/Makefile-Base b/OS/Makefile-Base
index 5a15b0a6b..0250647f0 100644
--- a/OS/Makefile-Base
+++ b/OS/Makefile-Base
@@ -1065,7 +1065,7 @@ dynmodules: buildlookups buildrouters buildtransports buildauths \
buildlookups: config
@cd lookups && $(MAKE) SHELL=$(SHELL) AR="$(AR)" $(MFLAGS) CC="$(CC)" CFLAGS="$(CFLAGS)" \
CFLAGS_DYNAMIC="$(CFLAGS_DYNAMIC)" HDRS="../version.h $(PHDRS)" \
- FE="$(FE)" RANLIB="$(RANLIB)" RM_COMMAND="$(RM_COMMAND)" \
+ FE="$(FE)" RANLIB="$(RANLIB)" LD="$(LD)" RM_COMMAND="$(RM_COMMAND)" \
INCLUDE="$(INCLUDE) $(IPV6_INCLUDE) $(TLS_INCLUDE) $(LOOKUP_INCLUDE)"
@echo " "
@@ -1074,7 +1074,7 @@ buildlookups: config
buildrouters: config
@cd routers && $(MAKE) SHELL=$(SHELL) AR="$(AR)" $(MFLAGS) CC="$(CC)" CFLAGS="$(CFLAGS)" \
CFLAGS_DYNAMIC="$(CFLAGS_DYNAMIC)" \
- FE="$(FE)" RANLIB="$(RANLIB)" RM_COMMAND="$(RM_COMMAND)" HDRS="$(PHDRS)" \
+ FE="$(FE)" RANLIB="$(RANLIB)" LD="$(LD)" RM_COMMAND="$(RM_COMMAND)" HDRS="$(PHDRS)" \
INCLUDE="$(INCLUDE) $(IPV6_INCLUDE) $(TLS_INCLUDE)"
@echo " "
@@ -1083,7 +1083,7 @@ buildrouters: config
buildtransports: config
@cd transports && $(MAKE) SHELL=$(SHELL) AR="$(AR)" $(MFLAGS) CC="$(CC)" CFLAGS="$(CFLAGS)" \
CFLAGS_DYNAMIC="$(CFLAGS_DYNAMIC)" \
- FE="$(FE)" RANLIB="$(RANLIB)" RM_COMMAND="$(RM_COMMAND)" HDRS="$(PHDRS)" \
+ FE="$(FE)" RANLIB="$(RANLIB)" LD="$(LD)" RM_COMMAND="$(RM_COMMAND)" HDRS="$(PHDRS)" \
INCLUDE="$(INCLUDE) $(IPV6_INCLUDE) $(TLS_INCLUDE)"
@echo " "
@@ -1092,7 +1092,7 @@ buildtransports: config
buildauths: config
@cd auths && $(MAKE) SHELL=$(SHELL) AR="$(AR)" $(MFLAGS) CC="$(CC)" CFLAGS="$(CFLAGS)" \
CFLAGS_DYNAMIC="$(CFLAGS_DYNAMIC)" \
- FE="$(FE)" RANLIB="$(RANLIB)" RM_COMMAND="$(RM_COMMAND)" HDRS="$(PHDRS)" \
+ FE="$(FE)" RANLIB="$(RANLIB)" LD="$(LD)" RM_COMMAND="$(RM_COMMAND)" HDRS="$(PHDRS)" \
INCLUDE="$(INCLUDE) $(IPV6_INCLUDE) $(TLS_INCLUDE)"
@echo " "
@@ -1101,7 +1101,7 @@ buildmisc: config
CC="$(CC)" CFLAGS="$(CFLAGS)" \
CFLAGS_DYNAMIC="$(CFLAGS_DYNAMIC)" \
LDFLAGS_PARTIAL="$(LDFLAGS_PARTIAL)" HDRS="../version.h $(PHDRS)" \
- FE="$(FE)" RANLIB="$(RANLIB)" RM_COMMAND="$(RM_COMMAND)" \
+ FE="$(FE)" RANLIB="$(RANLIB)" LD="$(LD)" RM_COMMAND="$(RM_COMMAND)" \
PERL_CC="$(PERL_CC)" PERL_CCOPTS="$(PERL_CCOPTS)" \
PERL_CFLAGS="$(PERL_CFLAGS)" PERL_LFLAGS="$(PERL_LFLAGS)" \
INCLUDE="$(INCLUDE) $(IPV6_INCLUDE)" TLS_INCLUDE="$(TLS_INCLUDE)"
diff --git a/OS/Makefile-Default b/OS/Makefile-Default
index 858361bf3..c469c7f01 100644
--- a/OS/Makefile-Default
+++ b/OS/Makefile-Default
@@ -227,6 +227,7 @@ HOSTNAME_COMMAND=/bin/hostname
RANLIB=ranlib
+LD=ld
# EXIM_CHMOD is available to specify a command that is automatically applied
# to the Exim binary immediately it is compiled. (I find this useful when
diff --git a/src/miscmods/Makefile b/src/miscmods/Makefile
index 1e46d4456..cfae5aac2 100644
index 807d6f377..5bac23a7f 100644
--- a/src/miscmods/Makefile
+++ b/src/miscmods/Makefile
@@ -62,7 +62,7 @@ dkim.o:
$(FE)$(CC) -c $(CFLAGS) $(INCLUDE) pdkim.c
$(FE)$(CC) -c $(CFLAGS) $(INCLUDE) $(TLS_INCLUDE) signing.c
$(FE)mv dkim.o dkim_tmp.o
- $(FE)ld -r -o dkim.o $(LDFLAGS_PARTIAL) \
+ $(FE)$(LD) -r -o dkim.o $(LDFLAGS_PARTIAL) \
dkim_tmp.o dkim_transport.o pdkim.o signing.o
@@ -96,7 +96,7 @@ dmarc.o dmarc_native.o:
$(FE)$(CC) -c $(CFLAGS) $(INCLUDE) $*.c
$(FE)$(CC) -c $(CFLAGS) $(INCLUDE) dmarc_common.c
$(FE)mv $@ dmarc_tmp.o
- $(FE)ld -r -o $@ $(LDFLAGS_PARTIAL) dmarc_tmp.o dmarc_common.o
+ $(FE)$(LD) -r -o $@ $(LDFLAGS_PARTIAL) dmarc_tmp.o dmarc_common.o
# Similarly, we want a single .so for the dynamic-load module
# dmarc_native is special in the same way as spf_perl
dmarc.so dmarc_native.so:
@@ -112,7 +112,7 @@ sieve_filter.o:
$(FE)$(CC) -c $(CFLAGS) $(INCLUDE) sieve_filter_body.c
$(FE)$(CC) -c $(CFLAGS) $(INCLUDE) sieve_filter_input.c
$(FE)mv sieve_filter.o sieve_filter_tmp.o
- $(FE)ld -r -o sieve_filter.o $(LDFLAGS_PARTIAL) \
+ $(FE)$(LD) -r -o sieve_filter.o $(LDFLAGS_PARTIAL) \
sieve_filter_tmp.o sieve_filter_body.o sieve_filter_input.o
sieve_filter.so:
--
2.47.3

View File

@@ -1,6 +1,6 @@
# From https://ftp.exim.org/pub/exim/exim4/00-sha256sums.txt
sha256 c2d2f80adc7c71d424fd82a46655eaa2d7d9b4ca2e77883eba9076947b7ee627 exim-4.99.5.tar.xz
sha256 e9fb41f6724a5b136d64c9d19dbc5f26494af879a3e7e3190f91639eaa79fa0d exim-4.100.1.tar.xz
# From https://ftp.exim.org/pub/exim/exim4/00-sha512sums.txt
sha512 28fd15d0d4e0114129fd42140fb5d5920fcd5cbfb6ac816197e3567c3d2ece6ec73367b43bd8d47d2b543adb89ad28a5e4c58a23210887f867a5c41c24e181b5 exim-4.99.5.tar.xz
sha512 42b7d59bca187e0e8b3cd85d97ff40fe8de9d807fb12ce38749c30056c92689ce98b09874aec06f1d83fde806fe6193312a98681b56c8baff1acfcf91244bbab exim-4.100.1.tar.xz
# Locally calculated
sha256 49240db527b7e55b312a46fc59794fde5dd006422e422257f4f057bfd27b3c8f LICENCE
sha256 edaef632cbb643e4e7a221717a6c441a4c1a7c918e6e4d56debc3d8739b233f6 LICENCE

View File

@@ -4,7 +4,7 @@
#
################################################################################
EXIM_VERSION = 4.99.5
EXIM_VERSION = 4.100.1
EXIM_SOURCE = exim-$(EXIM_VERSION).tar.xz
EXIM_SITE = https://ftp.exim.org/pub/exim/exim4
EXIM_LICENSE = GPL-2.0+
@@ -104,6 +104,7 @@ define EXIM_CONFIGURE_TOOLCHAIN
$(call exim-config-add,HOSTCFLAGS,$(HOSTCFLAGS))
$(call exim-config-add,EXTRALIBS,$(EXIM_EXTRALIBS))
$(EXIM_FIX_IP_OPTIONS_FOR_MUSL)
$(EXIM_DISABLE_VALGRIND)
endef
ifneq ($(call qstrip,$(BR2_PACKAGE_EXIM_CUSTOM_CONFIG_FILE)),)
@@ -154,6 +155,13 @@ else ifeq ($(BR2_TOOLCHAIN_USES_GLIBC),)
EXIM_CFLAGS = -DNO_EXECINFO
endif
# src/valgrind.h contains inline asm not compatible with thumb1
ifeq ($(BR2_ARM_INSTRUCTIONS_THUMB),y)
define EXIM_DISABLE_VALGRIND
$(call exim-config-change,NVALGRIND,1)
endef
endif
# We need the host version of macro_predef during the build, before
# building it we need to prepare the makefile.
define EXIM_BUILD_CMDS

View File

@@ -1,4 +1,4 @@
# From https://github.com/libexpat/libexpat/releases/tag/R_2_8_4
sha256 656ae1cc8da3b4ea513bb4e254f33e6243938084c0ec6239da873376b09985a7 expat-2.8.4.tar.xz
# From https://github.com/libexpat/libexpat/releases/tag/R_2_8_5
sha256 1e727b8933ec51a77a9a9d9afcf8e688bce45d907c13e36ab7393fe36e703182 expat-2.8.5.tar.xz
# Locally calculated
sha256 31b15de82aa19a845156169a17a5488bf597e561b2c318d159ed583139b25e87 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
EXPAT_VERSION = 2.8.4
EXPAT_VERSION = 2.8.5
EXPAT_SITE = https://github.com/libexpat/libexpat/releases/download/R_$(subst .,_,$(EXPAT_VERSION))
EXPAT_SOURCE = expat-$(EXPAT_VERSION).tar.xz
EXPAT_INSTALL_STAGING = YES

View File

@@ -14,8 +14,6 @@ config BR2_PACKAGE_FALCOSECURITY_LIBS
select BR2_PACKAGE_ELFUTILS
select BR2_PACKAGE_GRPC
select BR2_PACKAGE_GTEST
select BR2_PACKAGE_HOST_GRPC
select BR2_PACKAGE_HOST_PROTOBUF
select BR2_PACKAGE_JQ
select BR2_PACKAGE_JSONCPP
select BR2_PACKAGE_LIBB64

View File

@@ -1,3 +1,3 @@
# Locally computed
sha256 79e52aaafc0b57fa2b68ed6127de13e98318050399a939691b8ca30d44d48591 3.3.2.tar.gz
sha256 8dffe750027618e01dd4e6bc9aa9c889033c7abe4a661e9294192b58b4556264 fcft-3.3.2.tar.gz
sha256 d534a23a31500a0ac958d9634b84f532bd73ff1aca1bb8f7debbcbebc16ff39a LICENSE

View File

@@ -5,8 +5,7 @@
################################################################################
FCFT_VERSION = 3.3.2
FCFT_SOURCE = $(FCFT_VERSION).tar.gz
FCFT_SITE = https://codeberg.org/dnkl/fcft/archive
FCFT_SITE = https://codeberg.org/dnkl/fcft/releases/download/$(FCFT_VERSION)
FCFT_LICENSE = MIT
FCFT_LICENSE_FILES = LICENSE
FCFT_INSTALL_STAGING = YES

View File

@@ -0,0 +1,33 @@
From f1c316430713ae7d526f8abc1621b09958aef281 Mon Sep 17 00:00:00 2001
From: Bernd Kuhls <bernd@kuhls.net>
Date: Mon, 21 Sep 2026 22:06:06 +0200
Subject: [PATCH] Fix building on Pango 1.58.0
This version added the autoptr macros which we no longer need to define.
Upstream: https://github.com/flutter/flutter/pull/193119
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
.../flutter/shell/platform/linux/fl_accessible_text_field.cc | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/engine/src/flutter/shell/platform/linux/fl_accessible_text_field.cc b/engine/src/flutter/shell/platform/linux/fl_accessible_text_field.cc
index e99b123bbfd..f7955a32f07 100644
--- a/engine/src/flutter/shell/platform/linux/fl_accessible_text_field.cc
+++ b/engine/src/flutter/shell/platform/linux/fl_accessible_text_field.cc
@@ -6,7 +6,11 @@
#include "flutter/shell/platform/linux/public/flutter_linux/fl_standard_message_codec.h"
#include "flutter/shell/platform/linux/public/flutter_linux/fl_value.h"
+// PangoContext g_autoptr macro weren't added until 1.58.0. Add them manually.
+// https://gitlab.gnome.org/GNOME/pango/-/commit/223b147
+#if !PANGO_VERSION_CHECK(1, 58, 0)
G_DEFINE_AUTOPTR_CLEANUP_FUNC(PangoContext, g_object_unref)
+#endif
// PangoLayout g_autoptr macro weren't added until 1.49.4. Add them manually.
// https://gitlab.gnome.org/GNOME/pango/-/commit/0b84e14
#if !PANGO_VERSION_CHECK(1, 49, 4)
--
2.47.3

View File

@@ -2,7 +2,7 @@ config BR2_PACKAGE_FREEIPMI
bool "freeipmi"
depends on BR2_USE_MMU # fork()
depends on BR2_TOOLCHAIN_HAS_THREADS
select BR2_PACKAGE_ARGP_STANDALONE if BR2_TOOLCHAIN_USES_UCLIBC || BR2_TOOLCHAIN_USES_MUSL
select BR2_PACKAGE_ARGP_STANDALONE if !BR2_TOOLCHAIN_USES_GLIBC
help
FreeIPMI provides in-band and out-of-band IPMI software based
on the IPMI v1.5/2.0 specification.

View File

@@ -8,6 +8,7 @@ config BR2_PACKAGE_GERBERA
depends on BR2_INSTALL_LIBSTDCPP
depends on !BR2_STATIC_LIBS
depends on BR2_USE_WCHAR # fmt
depends on !BR2_BINFMT_FLAT # icu
select BR2_PACKAGE_CXXOPTS
select BR2_PACKAGE_FMT
select BR2_PACKAGE_ICU
@@ -32,6 +33,7 @@ config BR2_PACKAGE_GERBERA
comment "gerbera needs a toolchain w/ C++, dynamic library, threads, wchar, gcc >= 8, host gcc >= 7"
depends on BR2_USE_MMU
depends on !BR2_BINFMT_FLAT
depends on BR2_TOOLCHAIN_HAS_ATOMIC
depends on !BR2_INSTALL_LIBSTDCPP || BR2_STATIC_LIBS || \
!BR2_TOOLCHAIN_HAS_THREADS || !BR2_USE_WCHAR || \

View File

@@ -1,5 +1,5 @@
# From https://github.com/ArtifexSoftware/ghostpdl-downloads/releases/download/gs10071/SHA512SUMS
sha512 7b38ca10fa7ab648924f7db3e2e4933c3d18e04c8db1346fca4d4f7b85dfbd7888d5fc46f413613b46429fb47b675a593994c25e50e9de4dcdbee3bdd8a5e449 ghostscript-10.07.1.tar.xz
# From https://github.com/ArtifexSoftware/ghostpdl-downloads/releases/download/gs10080/SHA512SUMS
sha512 8006e2a32d03759a905b9548bdd83d4563173041006750e17e428b9eea24ad519aa4452ceecd7c073d3c420a68bf1b07ccc9e0533b1a05935f6b39ea8d9ce875 ghostscript-10.08.0.tar.xz
# Hash for license file:
sha256 8ce064f423b7c24a011b6ebf9431b8bf9861a5255e47c84bfb23fc526d030a8b LICENSE

View File

@@ -4,7 +4,7 @@
#
################################################################################
GHOSTSCRIPT_VERSION = 10.07.1
GHOSTSCRIPT_VERSION = 10.08.0
GHOSTSCRIPT_SOURCE = ghostscript-$(GHOSTSCRIPT_VERSION).tar.xz
GHOSTSCRIPT_SITE = https://github.com/ArtifexSoftware/ghostpdl-downloads/releases/download/gs$(subst .,,$(GHOSTSCRIPT_VERSION))
GHOSTSCRIPT_LICENSE = AGPL-3.0
@@ -37,6 +37,11 @@ GHOSTSCRIPT_CONF_ENV = \
CFLAGSAUX="$(HOST_CFLAGS) $(HOST_LDFLAGS)" \
PKGCONFIG="$(PKG_CONFIG_HOST_BINARY)"
# Uses __atomic_fetch_add_4
ifeq ($(BR2_TOOLCHAIN_HAS_LIBATOMIC),y)
GHOSTSCRIPT_MAKE_ENV += XTRALIBS=-latomic
endif
GHOSTSCRIPT_CONF_OPTS = \
--disable-compile-inits \
--enable-fontconfig \

View File

@@ -1,5 +1,5 @@
# Locally calculated (fetched from git)
sha256 39f6808e31a02da42f774912c6754ea22d5f076c4e935b1e233f3602d4d772c0 glibc-2.44-36-g2d5421ffca8893534d5e02ad38c28acd8e778fa3-git4.tar.gz
sha256 d55ac4dbe32f36310d7a4b9a38d3796666fe323581825cc530f2000a2209947a glibc-2.44-48-g1f5026241027260e9280039698bca031484c82ad-git4.tar.gz
# Hashes for license files
sha256 edaef632cbb643e4e7a221717a6c441a4c1a7c918e6e4d56debc3d8739b233f6 COPYINGv2

View File

@@ -7,7 +7,7 @@
# Generate version string using:
# git describe --match 'glibc-*' --abbrev=40 origin/release/MAJOR.MINOR/master | cut -d '-' -f 2-
# When updating the version, please also update localedef
GLIBC_VERSION = 2.44-36-g2d5421ffca8893534d5e02ad38c28acd8e778fa3
GLIBC_VERSION = 2.44-48-g1f5026241027260e9280039698bca031484c82ad
GLIBC_SITE = https://gitlab.com/gnutools/glibc.git
GLIBC_SITE_METHOD = git
@@ -37,6 +37,12 @@ GLIBC_IGNORE_CVES += CVE-2026-77117
# Fixed by 2.44-31-gcb61572ea3f773e1e1978f6c412cc36a30acdb0c
GLIBC_IGNORE_CVES += CVE-2026-80489
# Fixed by 2.44-39-g0b4e41fc51e6aba6216a908961b49b0622b47fa0
GLIBC_IGNORE_CVES += CVE-2026-18374
# Fixes by 2.44-48-g1f5026241027260e9280039698bca031484c82ad
GLIBC_IGNORE_CVES += CVE-2026-8674
# This CVE is considered as not being security issues by
# upstream glibc:
# https://security-tracker.debian.org/tracker/CVE-2010-4756

View File

@@ -35,7 +35,7 @@ config BR2_PACKAGE_GLSLSANDBOX_PLAYER_SCRIPTS
depends on BR2_USE_MMU # bash, python3
depends on BR2_USE_WCHAR # python3
select BR2_PACKAGE_BASH # runtime
select BR2_PACKAGE_BUSYBOX_SHOW_OTHERS if BR2_PACKAGE_BUSYBOX # bash
select BR2_PACKAGE_BUSYBOX_SHOW_OTHERS # bash
select BR2_PACKAGE_COREUTILS # runtime (timeout)
select BR2_PACKAGE_LIBCURL_CURL # runtime
select BR2_PACKAGE_IMAGEMAGICK # runtime

View File

@@ -80,6 +80,7 @@ config BR2_PACKAGE_GNURADIO_PYTHON
depends on BR2_PACKAGE_PYTHON_NUMPY_ARCH_SUPPORTS
depends on BR2_TOOLCHAIN_USES_GLIBC || BR2_TOOLCHAIN_USES_MUSL # python-numpy
depends on BR2_HOST_GCC_AT_LEAST_9 # host-python-numpy
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_9 # python-numpy
select BR2_PACKAGE_BOOST_PYTHON
select BR2_PACKAGE_PYTHON_NUMPY # runtime
select BR2_PACKAGE_PYTHON_PYBIND
@@ -87,8 +88,10 @@ config BR2_PACKAGE_GNURADIO_PYTHON
help
Enable python component
comment "python support needs a glibc or musl toolchain w/ host gcc >= 9"
depends on !BR2_HOST_GCC_AT_LEAST_9 || \
comment "python support needs a glibc or musl toolchain w/ gcc >= 9, host gcc >= 9"
depends on BR2_PACKAGE_PYTHON3
depends on BR2_PACKAGE_PYTHON_NUMPY_ARCH_SUPPORTS
depends on !BR2_TOOLCHAIN_GCC_AT_LEAST_9 || !BR2_HOST_GCC_AT_LEAST_9 || \
!(BR2_TOOLCHAIN_USES_GLIBC || BR2_TOOLCHAIN_USES_MUSL)
config BR2_PACKAGE_GNURADIO_SOAPY

View File

@@ -1,8 +1,14 @@
# Host go packages should depend on BR2_PACKAGE_HOST_GO_HOST_ARCH_SUPPORTS
config BR2_PACKAGE_HOST_GO_HOST_ARCH_SUPPORTS
bool
default y
depends on BR2_PACKAGE_HOST_GO_BOOTSTRAP_STAGE5_ARCH_SUPPORTS || BR2_PACKAGE_HOST_GO_BIN_HOST_ARCH_SUPPORTS
# Target go packages should depend on BR2_PACKAGE_HOST_GO_TARGET_ARCH_SUPPORTS
config BR2_PACKAGE_HOST_GO_TARGET_ARCH_SUPPORTS
bool
default y
depends on BR2_PACKAGE_HOST_GO_BOOTSTRAP_STAGE5_ARCH_SUPPORTS || BR2_PACKAGE_HOST_GO_BIN_HOST_ARCH_SUPPORTS
depends on BR2_PACKAGE_HOST_GO_HOST_ARCH_SUPPORTS
# See https://go.dev/doc/install/source#environment
# See src/go/build/syslist.go for the list of supported architectures
depends on (BR2_arm && BR2_TOOLCHAIN_SUPPORTS_PIE) || BR2_aarch64 \
@@ -30,12 +36,6 @@ config BR2_PACKAGE_HOST_GO_TARGET_CGO_LINKING_SUPPORTS
# cgo supports uses threads
depends on BR2_TOOLCHAIN_HAS_THREADS
# Host go packages should depend on BR2_PACKAGE_HOST_GO_HOST_ARCH_SUPPORTS
config BR2_PACKAGE_HOST_GO_HOST_ARCH_SUPPORTS
bool
default y
depends on BR2_PACKAGE_HOST_GO_BOOTSTRAP_STAGE5_ARCH_SUPPORTS || BR2_PACKAGE_HOST_GO_BIN_HOST_ARCH_SUPPORTS
# CGO linking for the host. Since we use the same compiler for target
# and host, if the target can't do CGO linking, then the host can't.
# But if the target is not supported by Go, then the host can do CGO

View File

@@ -14,12 +14,6 @@ GPSD_INSTALL_STAGING = YES
GPSD_DEPENDENCIES = host-scons host-pkgconf
# 0005-drivers-driver_nmea2000.c-Fix-issue-356-skyview-buff.patch
GPSD_IGNORE_CVES += CVE-2025-67268
# 0006-gpsd-packet.c-Fix-integer-underflow-is-malicious-Nav.patch
GPSD_IGNORE_CVES += CVE-2025-67269
GPSD_LDFLAGS = $(TARGET_LDFLAGS)
GPSD_CFLAGS = $(TARGET_CFLAGS)
GPSD_CXXFLAGS = $(TARGET_CXXFLAGS)

View File

@@ -3,6 +3,8 @@ config BR2_PACKAGE_HIDAPI
depends on BR2_PACKAGE_HAS_UDEV
depends on BR2_TOOLCHAIN_HAS_THREADS_NPTL
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 # libusb
depends on BR2_USE_MMU # libgudev
depends on BR2_USE_WCHAR # libgudev
select BR2_PACKAGE_LIBUSB
select BR2_PACKAGE_LIBGUDEV
select BR2_PACKAGE_LIBICONV if !BR2_ENABLE_LOCALE
@@ -15,7 +17,9 @@ config BR2_PACKAGE_HIDAPI
http://github.com/libusb/hidapi/
comment "hidapi needs udev /dev management and a toolchain w/ NPTL, gcc >= 4.9"
comment "hidapi needs udev /dev management and a toolchain w/ NPTL, gcc >= 4.9, wchar"
depends on BR2_USE_MMU
depends on !BR2_TOOLCHAIN_HAS_THREADS_NPTL || \
!BR2_PACKAGE_HAS_UDEV || \
!BR2_TOOLCHAIN_GCC_AT_LEAST_4_9
!BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 || \
!BR2_USE_WCHAR

View File

@@ -1,17 +1,18 @@
config BR2_PACKAGE_I2PD
bool "i2pd"
depends on BR2_USE_MMU # fork()
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_8 # string_view
depends on BR2_TOOLCHAIN_HAS_ATOMIC
# pthread_condattr_setclock
depends on BR2_TOOLCHAIN_HAS_THREADS_NPTL
depends on BR2_TOOLCHAIN_SUPPORTS_ALWAYS_LOCKFREE_ATOMIC_INTS # boost-filesystem
depends on BR2_INSTALL_LIBSTDCPP
depends on BR2_USE_WCHAR # boost
depends on !BR2_TOOLCHAIN_HAS_GCC_BUG_64735 # exception_ptr
select BR2_PACKAGE_BOOST
select BR2_PACKAGE_BOOST_FILESYSTEM
select BR2_PACKAGE_BOOST_PROGRAM_OPTIONS
select BR2_PACKAGE_OPENSSL
select BR2_PACKAGE_LIBOPENSSL_ENABLE_CHACHA if BR2_PACKAGE_LIBOPENSSL
select BR2_PACKAGE_ZLIB
help
i2pd (I2P Daemon) is a full-featured C++ implementation of I2P
@@ -24,15 +25,10 @@ config BR2_PACKAGE_I2PD
http://i2pd.website
comment "i2pd needs a toolchain w/ C++, NPTL, wchar"
comment "i2pd needs a toolchain w/ C++, gcc >= 8, NPTL, wchar"
depends on BR2_USE_MMU
depends on BR2_TOOLCHAIN_HAS_ATOMIC
depends on BR2_TOOLCHAIN_SUPPORTS_ALWAYS_LOCKFREE_ATOMIC_INTS
depends on !BR2_INSTALL_LIBSTDCPP || \
!BR2_TOOLCHAIN_GCC_AT_LEAST_8 || \
!BR2_TOOLCHAIN_HAS_THREADS_NPTL || !BR2_USE_WCHAR
comment "i2pd needs exception_ptr"
depends on BR2_USE_MMU
depends on BR2_TOOLCHAIN_HAS_ATOMIC
depends on BR2_TOOLCHAIN_SUPPORTS_ALWAYS_LOCKFREE_ATOMIC_INTS
depends on BR2_TOOLCHAIN_HAS_GCC_BUG_64735

View File

@@ -0,0 +1,45 @@
From b35faee1224f5bccf759464e69f724a03421c8a9 Mon Sep 17 00:00:00 2001
From: Arthur Gautier <arthur.gautier@arista.com>
Date: Tue, 9 Jun 2026 21:52:07 -0700
Subject: [PATCH] tpm2: fix GCC 15 stringop-overflow error in MakeIv
When compiling with GCC 15 using `CFLAGS=-march=x86-64-v4`, the compiler's
aggressively optimized vectorizer triggers a false-positive
-Wstringop-overflow error. Because x86-64-v4 enables wide AVX-512 registers,
the compiler misinterprets the loop unrolling and warns that a 64-byte
vector write is overflowing the destination buffer:
```
tpm2/TPMCmd/tpm/src/crypt/AlgorithmTests.c:158:17: error:
writing 64 bytes into a region of size 15 [-Werror=stringop-overflow=]
158 | *iv = i;
```
This fixes the warning by marking the `iv` output pointer parameter as
`volatile`. This inhibits the over-aggressive loop vectorization on this
specific buffer, silencing the compiler error without changing the
underlying logic.
Signed-off-by: Arthur Gautier <arthur.gautier@arista.com>
Source: https://github.com/stefanberger/libtpms/commit/2d9b00c4e42677cd0a9b67344f4d873ddc409a21
Upstream: https://github.com/kgoldman/ibmswtpm2/pull/25
[Bernd: rebased for ibm-sw-tpm2 package]
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
src/AlgorithmTests.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/src/AlgorithmTests.c b/src/AlgorithmTests.c
index e8549adca..28d8e780a 100644
--- a/src/AlgorithmTests.c
+++ b/src/AlgorithmTests.c
@@ -162,7 +162,7 @@
// Internal function to make the appropriate IV depending on the mode.
static UINT32 MakeIv(TPM_ALG_ID mode, // IN: symmetric mode
UINT32 size, // IN: block size of the algorithm
- BYTE* iv // OUT: IV to fill in
+ volatile BYTE* iv // OUT: IV to fill in
)
{
BYTE i;

View File

@@ -0,0 +1,46 @@
From fcea9d27f5153c8da77ebab956f75eaa1fd48836 Mon Sep 17 00:00:00 2001
From: Johannes Morgenroth <jm@m-network.de>
Date: Sun, 20 Dec 2015 12:51:53 +0100
Subject: [PATCH] ibrcommon: Use simplyfied POSIX method to get the basename
Upstream: https://github.com/ibrdtn/ibrdtn/commit/fcea9d27f5153c8da77ebab956f75eaa1fd48836
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
ibrcommon/data/File.cpp | 12 +-----------
1 file changed, 1 insertion(+), 11 deletions(-)
diff --git a/ibrcommon/data/File.cpp b/ibrcommon/data/File.cpp
index 31af4ae7..5f8e24e3 100644
--- a/ibrcommon/data/File.cpp
+++ b/ibrcommon/data/File.cpp
@@ -34,10 +34,7 @@
#include <cstring>
#include <cerrno>
#include <fstream>
-
-#if !defined(HAVE_FEATURES_H) || defined(ANDROID)
#include <libgen.h>
-#endif
#ifdef __WIN32__
#include <io.h>
@@ -225,14 +222,7 @@ namespace ibrcommon
std::string File::getBasename() const
{
-#if !defined(ANDROID) && defined(HAVE_FEATURES_H)
- return std::string(basename(_path.c_str()));
-#else
- char path[_path.length()+1];
- ::memcpy(&path, _path.c_str(), _path.length()+1);
-
- return std::string(basename(path));
-#endif
+ return std::string(basename((char*)_path.c_str()));
}
File File::get(const std::string &filename) const
--
2.47.3

View File

@@ -1,55 +0,0 @@
From d667b13a87cf3207599a19eb981a893a1d7a67ee Mon Sep 17 00:00:00 2001
From: Brendan Heading <brendanheading@gmail.com>
Date: Mon, 14 Sep 2015 23:25:52 +0100
Subject: [PATCH] ibrcommon/data/File.cpp: support POSIX basename call
Firstly, and somewhat strangely, musl chooses not to provide a basename(3)
prototype within <string.h> whenever __cplusplus is defined. This can be
solved by including the <libgen.h> header defined by POSIX 1003.1 whenever
__GLIBC__ is not defined.
However, this leads to a second problem. POSIX defines the function as
char* basename(char*) and this is the only version supported by musl.
However, the std::string.cstr() method returns a const char*.
POSIX says that the string parameter can be modified. However the GNU
implementation never modifies it. glibc therefore supports an extension
when compiling under C++ by also supplying
const char* basename(const char*). This extension is not present on musl
which is the cause of the failure.
The solution is reasonably straightforward; test if __GLIBC__ is defined
before calling basename. If not, use the fallback already provided for
other platforms whereby basename() is called on a temporary copy.
Signed-off-by: Brendan Heading <brendanheading@gmail.com>
Upstream-status: pending
---
ibrcommon/data/File.cpp | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/ibrcommon/data/File.cpp b/ibrcommon/data/File.cpp
index 31af4ae..68e9b4f 100644
--- a/ibrcommon/data/File.cpp
+++ b/ibrcommon/data/File.cpp
@@ -35,7 +35,7 @@
#include <cerrno>
#include <fstream>
-#if !defined(HAVE_FEATURES_H) || defined(ANDROID)
+#if !defined(HAVE_FEATURES_H) || !defined(__GLIBC__) || defined(ANDROID)
#include <libgen.h>
#endif
@@ -225,7 +225,7 @@ namespace ibrcommon
std::string File::getBasename() const
{
-#if !defined(ANDROID) && defined(HAVE_FEATURES_H)
+#if !defined(ANDROID) && defined(HAVE_FEATURES_H) && defined(__GLIBC__)
return std::string(basename(_path.c_str()));
#else
char path[_path.length()+1];
--
2.4.3

View File

@@ -5,8 +5,7 @@ Subject: [PATCH] ibrcommon: added openssl 1.1 compatibility (#264)
This patch adds compatibility to openssl 1.1.0.
Backported from master branch:
https://github.com/ibrdtn/ibrdtn/commit/a801d10a081e3130e24042256a43190c9eb6c112
Upstream: https://github.com/ibrdtn/ibrdtn/commit/a801d10a081e3130e24042256a43190c9eb6c112
Signed-off-by: Eneas U de Queiroz <cote2004-github@yahoo.com>
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>

View File

@@ -15,8 +15,9 @@ Makefile:560: recipe for target 'dtnd' failed
Fixes:
- http://autobuild.buildroot.org/results/1d3b4b6cf043a3e185ce758b617a0a18c3d36cdb
Upstream: https://github.com/ibrdtn/ibrdtn/commit/103bab3d4759e56b7e46cb9848e64037cd666911
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
[Upstream status: https://github.com/ibrdtn/ibrdtn/pull/269]
---
ibrcommon/ibrcommon/ssl/gcm/gcm.cpp | 10 +++++-----
ibrcommon/ibrcommon/ssl/gcm/gf128mul.cpp | 2 +-

View File

@@ -1,36 +0,0 @@
From 2c947e90d93d9c5a0129b62744de9720b48d2a17 Mon Sep 17 00:00:00 2001
From: Nicola Fontana <ntd@entidi.it>
Date: Sun, 8 Mar 2026 15:39:41 +0100
Subject: [PATCH] Linux 6.19.0 support
Commit 89aec171d9d1ab168e43fcf9754b82e4c0aef9b9 (part of linux kernel
6.19.0-rc1) introduced an arbitrarily sized sockaddr struct to be used
instead of the classical one.
Closes #200
Upstream: https://gitlab.com/etherlab.org/ethercat/-/commit/c42c9cf8bc31c56cc20ae630605495e3f19f3f9a
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
devices/generic.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/devices/generic.c b/devices/generic.c
index f6cef9b5..a08af54b 100644
--- a/devices/generic.c
+++ b/devices/generic.c
@@ -234,7 +234,11 @@ int ec_gen_device_create_socket(
sa.sll_family = AF_PACKET;
sa.sll_protocol = htons(ETH_P_ETHERCAT);
sa.sll_ifindex = desc->ifindex;
+#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 19, 0)
+ ret = kernel_bind(dev->socket, (struct sockaddr_unsized *) &sa, sizeof(sa));
+#else
ret = kernel_bind(dev->socket, (struct sockaddr *) &sa, sizeof(sa));
+#endif
if (ret) {
printk(KERN_ERR PFX "Failed to bind() socket to interface"
" (ret = %i).\n", ret);
--
2.55.0

View File

@@ -5,6 +5,7 @@ config BR2_PACKAGE_IMLIB2
bool "imlib2"
depends on !BR2_STATIC_LIBS # dlopen()
select BR2_PACKAGE_FREETYPE
select BR2_PACKAGE_ZLIB
help
Imlib 2 is the successor to Imlib. This library provides
routines to load, save and render images in various formats.

View File

@@ -12,7 +12,7 @@ IMLIB2_LICENSE_FILES = COPYING COPYING-PLAIN
IMLIB2_CPE_ID_VENDOR = enlightenment
IMLIB2_INSTALL_STAGING = YES
IMLIB2_DEPENDENCIES = host-pkgconf freetype
IMLIB2_DEPENDENCIES = host-pkgconf freetype zlib
IMLIB2_CONF_OPTS = --with-freetype-config=$(STAGING_DIR)/usr/bin/freetype-config
ifeq ($(BR2_PACKAGE_IMLIB2_X),y)

View File

@@ -3,6 +3,7 @@ config BR2_PACKAGE_INTEL_MEDIASDK
depends on BR2_x86_64
depends on !BR2_STATIC_LIBS # intel-mediadriver
depends on BR2_INSTALL_LIBSTDCPP # intel-mediadriver
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_8 # intel-mediadriver
depends on BR2_TOOLCHAIN_HAS_SYNC_1 # intel-mediadriver
depends on BR2_TOOLCHAIN_HAS_THREADS # intel-mediadriver
depends on BR2_TOOLCHAIN_HAS_THREADS_NPTL # intel-mediadriver
@@ -20,7 +21,8 @@ config BR2_PACKAGE_INTEL_MEDIASDK
http://mediasdk.intel.com/
comment "intel-mediasdk needs a toolchain w/ dynamic library, C++, NPTL"
comment "intel-mediasdk needs a toolchain w/ dynamic library, gcc >= 8, C++, NPTL"
depends on BR2_x86_64 && BR2_TOOLCHAIN_HAS_SYNC_1
depends on BR2_STATIC_LIBS || !BR2_INSTALL_LIBSTDCPP || \
!BR2_TOOLCHAIN_HAS_THREADS_NPTL
!BR2_TOOLCHAIN_HAS_THREADS_NPTL || \
!BR2_TOOLCHAIN_GCC_AT_LEAST_8

View File

@@ -4,7 +4,7 @@ config BR2_PACKAGE_INTEL_VPL_GPU_RT
depends on BR2_PACKAGE_LIBVPL_ARCH_SUPPORTS # libvpl
depends on BR2_INSTALL_LIBSTDCPP # libvpl
depends on !BR2_STATIC_LIBS # libvpl
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_7 # libvpl
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_8 # intel-mediadriver
depends on BR2_TOOLCHAIN_HAS_SYNC_1 # intel-mediadriver
depends on BR2_TOOLCHAIN_HAS_THREADS # libvpl
depends on BR2_TOOLCHAIN_HAS_THREADS_NPTL # intel-mediadriver
@@ -18,9 +18,9 @@ config BR2_PACKAGE_INTEL_VPL_GPU_RT
https://github.com/intel/vpl-gpu-rt
comment "intel-vpl-gpu-rt needs a toolchain w/ dynamic library, gcc >= 7, C++, NPTL"
comment "intel-vpl-gpu-rt needs a toolchain w/ dynamic library, gcc >= 8, C++, NPTL"
depends on BR2_x86_64
depends on BR2_PACKAGE_LIBVPL_ARCH_SUPPORTS
depends on BR2_TOOLCHAIN_HAS_SYNC_1
depends on BR2_STATIC_LIBS || !BR2_TOOLCHAIN_GCC_AT_LEAST_7 || \
depends on BR2_STATIC_LIBS || !BR2_TOOLCHAIN_GCC_AT_LEAST_8 || \
!BR2_INSTALL_LIBSTDCPP || !BR2_TOOLCHAIN_HAS_THREADS

View File

@@ -3,8 +3,7 @@ config BR2_PACKAGE_IUCODE_TOOL
depends on BR2_x86_64 || BR2_i386
select BR2_PACKAGE_INTEL_MICROCODE
select BR2_PACKAGE_INTEL_MICROCODE_INSTALL_TARGET
select BR2_PACKAGE_ARGP_STANDALONE \
if BR2_TOOLCHAIN_USES_UCLIBC || BR2_TOOLCHAIN_USES_MUSL
select BR2_PACKAGE_ARGP_STANDALONE if !BR2_TOOLCHAIN_USES_GLIBC
help
Intel processor microcode tool

View File

@@ -187,6 +187,7 @@ config BR2_PACKAGE_IVI_HOMESCREEN_TEXT_INPUT_PLUGIN
comment "plugins with external dependencies"
config BR2_PACKAGE_IVI_HOMESCREEN_AUDIO_PLAYERS
bool "Audio Players"
depends on BR2_USE_MMU # gstreamer1
select BR2_PACKAGE_GSTREAMER1
select BR2_PACKAGE_GST1_PLUGINS_BASE
select BR2_PACKAGE_GST1_PLUGINS_BASE_PLUGIN_ALSA
@@ -201,6 +202,7 @@ config BR2_PACKAGE_IVI_HOMESCREEN_AUDIO_PLAYERS
config BR2_PACKAGE_IVI_HOMESCREEN_FLUTTER_SECURE_STORAGE_PLUGIN
bool "Flutter Secure Storage"
depends on BR2_USE_MMU # libsecret
select BR2_PACKAGE_LIBSECRET
help
Store data in secure storage

View File

@@ -0,0 +1,160 @@
From 1a15fe33a48c52bfe26ea83e49f0d317a47da3ea Mon Sep 17 00:00:00 2001
From: lexprfuncall <cshapiro@meta.com>
Date: Mon, 27 Apr 2026 11:50:27 -0700
Subject: [PATCH] Replace std::__throw_bad_alloc call with standard C++ (#2900)
* Replace std::__throw_bad_alloc call with standard C++
Since December of 2025, std::__throw_bad_alloc is no longer visible
through #include <new> causing jemalloc build failures with gcc 16.
As far as I can tell, all std::__throw_bad_alloc did was arrange to
raise a std::bad_alloc exception if exceptions are enabled. I am not
sure whether its usage was truly meaningful in jemalloc since the call
is wrapped in a try catch and any usage of try catch is considered an
error when compiling with -fno-exceptions on gcc, at least.
This change adds a check to configure.ac that determines whether
exceptions are enabled by compiling a simple try catch that raises a
std::bad_alloc exception. If that test succeeds, the macro
JEMALLOC_HAVE_CXX_EXCEPTIONS is defined, and jemalloc will raise an
exception. Otherwise, we call std::terminate() to abort.
This was tested on FreeBSD with the gcc16 port with and without exceptions
enabled.
* Replace std::set_new_handler calls with std::get_new_handler
Previously, std::set_new_handler was used as a workaround for
compilers with only partial support for C++11. Now that C++14 is a
requirement to enable C++ support, we can assume std::get_new_handler
is available.
Upstream: https://github.com/jemalloc/jemalloc/commit/1a15fe33a48c52bfe26ea83e49f0d317a47da3ea
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
Makefile.in | 6 +++--
configure.ac | 23 +++++++++++++++++
.../internal/jemalloc_internal_defs.h.in | 3 +++
src/jemalloc_cpp.cpp | 25 ++++++++++---------
4 files changed, 43 insertions(+), 14 deletions(-)
diff --git a/Makefile.in b/Makefile.in
index a93048d7b8..1f9d14f1f2 100644
--- a/Makefile.in
+++ b/Makefile.in
@@ -337,9 +337,11 @@ TESTS_INTEGRATION += \
endif
ifeq (@enable_cxx@, 1)
CPP_SRCS := $(srcroot)src/jemalloc_cpp.cpp
-TESTS_INTEGRATION_CPP := $(srcroot)test/integration/cpp/basic.cpp \
- $(srcroot)test/integration/cpp/infallible_new_true.cpp \
+TESTS_INTEGRATION_CPP := $(srcroot)test/integration/cpp/basic.cpp
+ifeq (@enable_cxx_exceptions@, 1)
+TESTS_INTEGRATION_CPP += $(srcroot)test/integration/cpp/infallible_new_true.cpp \
$(srcroot)test/integration/cpp/infallible_new_false.cpp
+endif
else
CPP_SRCS :=
TESTS_INTEGRATION_CPP :=
diff --git a/configure.ac b/configure.ac
index 321a729012..d151829832 100644
--- a/configure.ac
+++ b/configure.ac
@@ -374,7 +374,30 @@ fi
if test "x$enable_cxx" = "x1"; then
AC_DEFINE([JEMALLOC_ENABLE_CXX], [ ], [ ])
fi
+if test "x$enable_cxx" = "x1"; then
+ dnl Now check whether the C++ compiler has exceptions enabled.
+ AC_LANG_PUSH([C++])
+ SAVED_CXXFLAGS="${CXXFLAGS}"
+ CXXFLAGS="${CXXFLAGS} ${EXTRA_CXXFLAGS}"
+ JE_COMPILABLE([C++ exception support], [
+#include <new>
+], [
+ try {
+ throw std::bad_alloc();
+ } catch (const std::bad_alloc &) {
+ }
+], [je_cv_cxx_exceptions])
+ CXXFLAGS="${SAVED_CXXFLAGS}"
+ AC_LANG_POP([C++])
+ if test "x${je_cv_cxx_exceptions}" = "xyes" ; then
+ AC_DEFINE([JEMALLOC_HAVE_CXX_EXCEPTIONS], [ ], [ ])
+ enable_cxx_exceptions="1"
+ else
+ enable_cxx_exceptions="0"
+ fi
+fi
AC_SUBST([enable_cxx])
+AC_SUBST([enable_cxx_exceptions])
AC_SUBST([CONFIGURE_CXXFLAGS])
AC_SUBST([SPECIFIED_CXXFLAGS])
AC_SUBST([EXTRA_CXXFLAGS])
diff --git a/include/jemalloc/internal/jemalloc_internal_defs.h.in b/include/jemalloc/internal/jemalloc_internal_defs.h.in
index 31ae2e8ed2..54d4da2032 100644
--- a/include/jemalloc/internal/jemalloc_internal_defs.h.in
+++ b/include/jemalloc/internal/jemalloc_internal_defs.h.in
@@ -465,6 +465,9 @@
/* Is C++ support being built? */
#undef JEMALLOC_ENABLE_CXX
+/* Are C++ exceptions enabled? */
+#undef JEMALLOC_HAVE_CXX_EXCEPTIONS
+
/* Performs additional size checks when defined. */
#undef JEMALLOC_OPT_SIZE_CHECKS
diff --git a/src/jemalloc_cpp.cpp b/src/jemalloc_cpp.cpp
index 4e838d3b51..ac109bb28e 100644
--- a/src/jemalloc_cpp.cpp
+++ b/src/jemalloc_cpp.cpp
@@ -1,4 +1,4 @@
-#include <mutex>
+#include <exception>
#include <new>
// NOLINTBEGIN(misc-use-anonymous-namespace)
@@ -78,29 +78,30 @@ handleOOM(std::size_t size, bool nothrow) {
void *ptr = nullptr;
while (ptr == nullptr) {
- std::new_handler handler;
- // GCC-4.8 and clang 4.0 do not have std::get_new_handler.
- {
- static std::mutex mtx;
- std::lock_guard<std::mutex> lock(mtx);
-
- handler = std::set_new_handler(nullptr);
- std::set_new_handler(handler);
- }
+ std::new_handler handler = std::get_new_handler();
if (handler == nullptr)
break;
+#ifdef JEMALLOC_HAVE_CXX_EXCEPTIONS
try {
handler();
} catch (const std::bad_alloc &) {
break;
}
+#else
+ handler();
+#endif
ptr = je_malloc(size);
}
- if (ptr == nullptr && !nothrow)
- std::__throw_bad_alloc();
+ if (ptr == nullptr && !nothrow) {
+#ifdef JEMALLOC_HAVE_CXX_EXCEPTIONS
+ throw std::bad_alloc();
+#else
+ std::terminate();
+#endif
+ }
return ptr;
}

View File

@@ -9,6 +9,8 @@ JEMALLOC_SOURCE = jemalloc-$(JEMALLOC_VERSION).tar.bz2
JEMALLOC_SITE = https://github.com/jemalloc/jemalloc/releases/download/$(JEMALLOC_VERSION)
JEMALLOC_LICENSE = BSD-2-Clause
JEMALLOC_LICENSE_FILES = COPYING
# 0001-Replace-std-__throw_bad_alloc.patch
JEMALLOC_AUTORECONF = YES
JEMALLOC_INSTALL_STAGING = YES
JEMALLOC_CONFIG_SCRIPTS = jemalloc-config

View File

@@ -0,0 +1,146 @@
From 8e552683fa36fe9d09ee3e0909e600350d0bc3cb Mon Sep 17 00:00:00 2001
From: Alexey Gladkov <legion@kernel.org>
Date: Mon, 21 Sep 2026 12:15:00 +0200
Subject: [PATCH] libkbdfile: Require dlopen and memfd_create for library
decompressors
The library decompressors need dlopen() to load compression libraries
and memfd_create() to hold decompressed data. Building them without
these facilities can fail even though external decompression commands
remain available.
Enable the library backends and ELF note support only when both
requirements are met, and apply the same condition to the ELF note
test. Otherwise, retain the external-command fallback.
Also restrict the libbz2 fallback probe to failed pkg-config lookups
so that --without-bzip2 does not inadvertently enable bzip2 support.
Link: https://github.com/legionus/kbd/issues/159
Signed-off-by: Alexey Gladkov <legion@kernel.org>
Upstream: https://github.com/legionus/kbd/commit/6ff3161c1e5d448920d412a269716cf42be155b5
[Fiona: backport to 2.9.0]
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
---
configure.ac | 19 ++++++++++++-------
src/libkbdfile/Makefile.am | 9 +++++++--
src/libkbdfile/elf-note.c | 3 +++
3 files changed, 22 insertions(+), 9 deletions(-)
diff --git a/configure.ac b/configure.ac
index 05cecab..0691167 100644
--- a/configure.ac
+++ b/configure.ac
@@ -81,7 +81,7 @@ AC_FUNC_STAT
AC_FUNC_MALLOC
AC_FUNC_REALLOC
AC_FUNC_STRERROR_R
-AC_CHECK_FUNCS([alarm dup2 endpwent memset setlocale strcasecmp strerror \
+AC_CHECK_FUNCS([alarm dup2 endpwent memset setlocale strcasecmp strerror memfd_create \
strdup strndup strchr strrchr strspn strstr strtol])
AC_SEARCH_LIBS([timer_create], [rt])
@@ -263,13 +263,18 @@ AS_IF([test "$VLOCK_PROG" = "yes"], [
])
AM_CONDITIONAL(VLOCK, test "$VLOCK_PROG" = "yes")
+AS_IF([test "$enable_dlopen" = "yes" -a "$ac_cv_func_memfd_create" = "yes"],
+ [enable_kbdfile_elfnote=yes],
+ [enable_kbdfile_elfnote=no])
+AM_CONDITIONAL(USE_ELFNOTE, test "$enable_kbdfile_elfnote" = "yes")
+
AC_ARG_WITH([zlib],
[AS_HELP_STRING([--with-zlib],
[support zlib compression @<:@default=auto@:>@])],
[],
[: m4_divert_text([DEFAULTS], [with_zlib=yes])]
)
-AS_IF([test "$with_zlib" != "no"],
+AS_IF([test "$with_zlib" != "no" -a "$enable_kbdfile_elfnote" = "yes"],
[PKG_CHECK_MODULES(ZLIB, zlib, [HAVE_ZLIB=yes], [HAVE_ZLIB=no])],
[HAVE_ZLIB=no]
)
@@ -284,11 +289,11 @@ AC_ARG_WITH([bzip2],
[],
[: m4_divert_text([DEFAULTS], [with_bzip2=yes])]
)
-AS_IF([test "$with_bzip2" != "no"],
- [PKG_CHECK_MODULES(BZIP2, bzip2, [HAVE_BZIP2=yes], [HAVE_BZIP2=no])],
+AS_IF([test "$with_bzip2" != "no" -a "$enable_kbdfile_elfnote" = "yes"],
+ [PKG_CHECK_MODULES(BZIP2, bzip2, [HAVE_BZIP2=yes], [HAVE_BZIP2=auto])],
[HAVE_BZIP2=no]
)
-AS_IF([test "$HAVE_BZIP2" = "no"], [
+AS_IF([test "$HAVE_BZIP2" = "auto"], [
AC_CHECK_LIB(bz2, BZ2_bzDecompressInit, [
HAVE_BZIP2=yes
BZIP2_LIBS=-lbz2
@@ -306,7 +311,7 @@ AC_ARG_WITH([lzma],
[],
[: m4_divert_text([DEFAULTS], [with_lzma=yes])]
)
-AS_IF([test "$with_lzma" != "no"],
+AS_IF([test "$with_lzma" != "no" -a "$enable_kbdfile_elfnote" = "yes"],
[PKG_CHECK_MODULES(LZMA, liblzma, [HAVE_LZMA=yes], [HAVE_LZMA=no])],
[HAVE_LZMA=no]
)
@@ -321,7 +326,7 @@ AC_ARG_WITH([zstd],
[],
[: m4_divert_text([DEFAULTS], [with_zstd=yes])]
)
-AS_IF([test "$with_zstd" != "no"],
+AS_IF([test "$with_zstd" != "no" -a "$enable_kbdfile_elfnote" = "yes"],
[PKG_CHECK_MODULES(ZSTD, libzstd, [HAVE_ZSTD=yes], [HAVE_ZSTD=no])],
[HAVE_ZSTD=no]
)
diff --git a/src/libkbdfile/Makefile.am b/src/libkbdfile/Makefile.am
index 2511064..ebdb28d 100644
--- a/src/libkbdfile/Makefile.am
+++ b/src/libkbdfile/Makefile.am
@@ -10,14 +10,17 @@ headers = \
libkbdfile_la_SOURCES = \
$(headers) \
contextP.h \
- elf-note.h \
- elf-note.c \
init.c \
kbdfile.c
libkbdfile_la_LIBADD =
libkbdfile_la_CFLAGS =
+if USE_ELFNOTE
+libkbdfile_la_SOURCES += \
+ elf-note.h \
+ elf-note.c
+
if USE_ZLIB
libkbdfile_la_SOURCES += kbdfile-zlib.c
libkbdfile_la_CFLAGS += $(ZLIB_CFLAGS)
@@ -38,6 +41,8 @@ libkbdfile_la_SOURCES += kbdfile-zstd.c
libkbdfile_la_CFLAGS += $(ZSTD_CFLAGS)
endif
+endif # USE_ELFNOTE
+
KBDFILE_CURRENT = 1
KBDFILE_REVISION = 0
KBDFILE_AGE = 0
diff --git a/src/libkbdfile/elf-note.c b/src/libkbdfile/elf-note.c
index 842be9d..bc4a684 100644
--- a/src/libkbdfile/elf-note.c
+++ b/src/libkbdfile/elf-note.c
@@ -6,7 +6,10 @@
#include <stdint.h>
#include <stdarg.h>
#include <errno.h>
+
+#ifdef HAVE_DLFCN_H
#include <dlfcn.h>
+#endif
#include "elf-note.h"
--
2.55.0

View File

@@ -14,6 +14,10 @@ KBD_DEPENDENCIES = \
$(TARGET_NLS_DEPENDENCIES) \
host-pkgconf
# 0002-libkbdfile-Require-dlopen-and-memfd_create-for-libra.patch
# modifies configure.ac and src/libkbdfile/Makefile.am
KBD_AUTORECONF = YES
ifeq ($(BR2_PACKAGE_BZIP2),y)
KBD_CONF_OPTS += --with-bzip2
KBD_DEPENDENCIES += bzip2

View File

@@ -1,7 +1,8 @@
config BR2_PACKAGE_KODI_ARCH_SUPPORTS
bool
default y if BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS
default y if BR2_PACKAGE_HOST_OPENJDK_BIN_ARCH_SUPPORTS
default y
depends on BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS
depends on BR2_PACKAGE_HOST_OPENJDK_BIN_ARCH_SUPPORTS
# i386: needs sse (see upstream PR 10351)
depends on !(BR2_i386 && !BR2_X86_CPU_HAS_SSE)
# m68k not supported upstream
@@ -202,6 +203,7 @@ comment "nfs support needs a toolchain w/ threads support"
config BR2_PACKAGE_KODI_MYSQL
bool "mysql"
depends on BR2_TOOLCHAIN_HAS_ATOMIC || BR2_TOOLCHAIN_HAS_SYNC_8 # mariadb
select BR2_PACKAGE_MARIADB
help
Enable MySQL support

View File

@@ -14,6 +14,10 @@ config BR2_PACKAGE_LIBABSEIL_CPP_ARCH_SUPPORTS
default y if BR2_sparc || BR2_sparc64
default y if BR2_x86_64
depends on BR2_TOOLCHAIN_HAS_UCONTEXT
# absl/base/internal/direct_mmap.h only implements DirectMmap()
# with mmap2 for the o32 ABI on MIPS, and its 64-bit fallback
# fails to build with the n32 ABI, where long is 32-bit
depends on !BR2_MIPS_NABI32
config BR2_PACKAGE_LIBABSEIL_CPP
bool "libabseil-cpp"

View File

@@ -3,7 +3,7 @@ config BR2_PACKAGE_LIBCAMERA_APPS
depends on BR2_PACKAGE_LIBCAMERA_ARCH_SUPPORTS # libcamera
depends on BR2_INSTALL_LIBSTDCPP # libcamera/boost
depends on BR2_TOOLCHAIN_HAS_THREADS # libcamera/boost
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_9 # libcamera
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_10 # libcamera
depends on !BR2_STATIC_LIBS # gnutls/libcamera
depends on BR2_USE_WCHAR # gnutls/libcamera/boost
depends on BR2_TOOLCHAIN_HEADERS_AT_LEAST_5_5
@@ -25,9 +25,9 @@ config BR2_PACKAGE_LIBCAMERA_APPS
https://github.com/raspberrypi/libcamera-apps
comment "libcamera-apps needs a toolchain w/ C++, threads, wchar, dynamic library, gcc >= 8, headers >= 5.5"
comment "libcamera-apps needs a toolchain w/ C++, threads, wchar, dynamic library, gcc >= 10, headers >= 5.5"
depends on BR2_PACKAGE_LIBCAMERA_ARCH_SUPPORTS
depends on !BR2_INSTALL_LIBSTDCPP || \
!BR2_TOOLCHAIN_HAS_THREADS || \
!BR2_TOOLCHAIN_GCC_AT_LEAST_8 || BR2_STATIC_LIBS || \
!BR2_TOOLCHAIN_GCC_AT_LEAST_10 || BR2_STATIC_LIBS || \
!BR2_USE_WCHAR || !BR2_TOOLCHAIN_HEADERS_AT_LEAST_5_5

View File

@@ -1,4 +1,4 @@
# From https://github.com/strukturag/libde265/releases/tag/v1.1.1
sha256 fd48a927e94ed74fc7ce8829d222b9d8599fcbfe8b6448ba66705babc56ab219 libde265-1.1.1.tar.gz
# From https://github.com/strukturag/libde265/releases/tag/v1.1.2
sha256 eaacd1943ab0c452c19f6136a36ca227e6b761b39a81eaca8454d48c147e1f67 libde265-1.1.2.tar.gz
# Locally computed
sha256 02cc1585a20677992e0ba578fa692635dc193735f2691dc81de924b51c4e8020 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
LIBDE265_VERSION = 1.1.1
LIBDE265_VERSION = 1.1.2
LIBDE265_SITE = https://github.com/strukturag/libde265/releases/download/v$(LIBDE265_VERSION)
LIBDE265_LICENSE = LGPL-3.0+
LIBDE265_LICENSE_FILES = COPYING

View File

@@ -0,0 +1,27 @@
From b49542dea03c4b895a860c393453ab8497dabfce Mon Sep 17 00:00:00 2001
From: Bernd Kuhls <bernd@kuhls.net>
Date: Tue, 8 Sep 2026 12:52:02 +0200
Subject: [PATCH] java/jni/client.c: include est/est_ossl_util.h
Upstream: https://github.com/cisco/libest/pull/132#issuecomment-4749526125
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
java/jni/client.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/java/jni/client.c b/java/jni/client.c
index c5bc28e..2c4663e 100644
--- a/java/jni/client.c
+++ b/java/jni/client.c
@@ -12,6 +12,7 @@
#include <stdint.h>
#include "jest.h"
#include <est/est.h>
+#include "est/est_ossl_util.h"
#include <openssl/x509v3.h>
#include <openssl/bio.h>
#include "safe_mem_lib.h"
--
2.47.3

View File

@@ -1,42 +0,0 @@
From 32fe99fa403d2f51931615745a64f8aede1ca46f Mon Sep 17 00:00:00 2001
From: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Date: Sat, 8 Jan 2022 13:38:17 +0100
Subject: [PATCH] src/est/est_locl.h: add missing extern on
e_ctx_ssl_exdata_index
Without this extern, the variable gets re-declared in each compilation
unit including est_locl.h, causing gcc >= 10 to complain with:
/home/thomas/projets/buildroot/output/host/opt/ext-toolchain/bin/../lib/gcc/arm-buildroot-linux-uclibcgnueabi/10.3.0/../../../../arm-buildroot-linux-uclibcgnueabi/bin/ld: .libs/est_client.o:(.data+0x0): multiple definition of `e_ctx_ssl_exdata_index'; .libs/est.o:(.bss+0x8): first defined here
/home/thomas/projets/buildroot/output/host/opt/ext-toolchain/bin/../lib/gcc/arm-buildroot-linux-uclibcgnueabi/10.3.0/../../../../arm-buildroot-linux-uclibcgnueabi/bin/ld: .libs/est_server.o:(.bss+0xc): multiple definition of `e_ctx_ssl_exdata_index'; .libs/est.o:(.bss+0x8): first defined here
/home/thomas/projets/buildroot/output/host/opt/ext-toolchain/bin/../lib/gcc/arm-buildroot-linux-uclibcgnueabi/10.3.0/../../../../arm-buildroot-linux-uclibcgnueabi/bin/ld: .libs/est_server_http.o:(.bss+0x3b8): multiple definition of `e_ctx_ssl_exdata_index'; .libs/est.o:(.bss+0x8): first defined here
/home/thomas/projets/buildroot/output/host/opt/ext-toolchain/bin/../lib/gcc/arm-buildroot-linux-uclibcgnueabi/10.3.0/../../../../arm-buildroot-linux-uclibcgnueabi/bin/ld: .libs/est_proxy.o:(.bss+0x0): multiple definition of `e_ctx_ssl_exdata_index'; .libs/est.o:(.bss+0x8): first defined here
/home/thomas/projets/buildroot/output/host/opt/ext-toolchain/bin/../lib/gcc/arm-buildroot-linux-uclibcgnueabi/10.3.0/../../../../arm-buildroot-linux-uclibcgnueabi/bin/ld: .libs/est_client_http.o:(.bss+0x0): multiple definition of `e_ctx_ssl_exdata_index'; .libs/est.o:(.bss+0x8): first defined here
/home/thomas/projets/buildroot/output/host/opt/ext-toolchain/bin/../lib/gcc/arm-buildroot-linux-uclibcgnueabi/10.3.0/../../../../arm-buildroot-linux-uclibcgnueabi/bin/ld: .libs/est_ossl_util.o:(.bss+0x0): multiple definition of `e_ctx_ssl_exdata_index'; .libs/est.o:(.bss+0x8): first defined here
/home/thomas/projets/buildroot/output/host/opt/ext-toolchain/bin/../lib/gcc/arm-buildroot-linux-uclibcgnueabi/10.3.0/../../../../arm-buildroot-linux-uclibcgnueabi/bin/ld: .libs/est_client_proxy.o:(.bss+0x0): multiple definition of `e_ctx_ssl_exdata_index'; .libs/est.o:(.bss+0x8): first defined here
/home/thomas/projets/buildroot/output/host/opt/ext-toolchain/bin/../lib/gcc/arm-buildroot-linux-uclibcgnueabi/10.3.0/../../../../arm-buildroot-linux-uclibcgnueabi/bin/ld: .libs/est_enhcd_cert_auth.o:(.bss+0x0): multiple definition of `e_ctx_ssl_exdata_index'; .libs/est.o:(.bss+0x8): first defined here
/home/thomas/projets/buildroot/output/host/opt/ext-toolchain/bin/../lib/gcc/arm-buildroot-linux-uclibcgnueabi/10.3.0/../../../../arm-buildroot-linux-uclibcgnueabi/bin/ld: .libs/est_server_coap.o:(.bss+0x0): multiple definition of `e_ctx_ssl_exdata_index'; .libs/est.o:(.bss+0x8): first defined here
collect2: error: ld returned 1 exit status
Upstream: https://github.com/cisco/libest/pull/107
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
---
src/est/est_locl.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/est/est_locl.h b/src/est/est_locl.h
index 62dcbea..b16f62d 100644
--- a/src/est/est_locl.h
+++ b/src/est/est_locl.h
@@ -590,7 +590,7 @@ typedef struct est_oid_list {
/*
* Index used to link the EST Ctx into the SSL structures
*/
-int e_ctx_ssl_exdata_index;
+extern int e_ctx_ssl_exdata_index;
LIBEST_TEST_API void est_log (EST_LOG_LEVEL lvl, char *format, ...);
LIBEST_TEST_API void est_log_backtrace (void);
--
2.33.1

View File

@@ -5,6 +5,7 @@ config BR2_PACKAGE_LIBEST
bool "libest"
depends on !BR2_STATIC_LIBS # libexecinfo or glibc
select BR2_PACKAGE_LIBEXECINFO if !BR2_TOOLCHAIN_USES_GLIBC
select BR2_PACKAGE_LIBOPENSSL_ENGINES
select BR2_PACKAGE_OPENSSL
select BR2_PACKAGE_OPENSSL_FORCE_LIBOPENSSL
select BR2_PACKAGE_SAFECLIB

View File

@@ -1,3 +1,3 @@
# Computed locally
sha256 83983ac05137fd73586ddcb4874e30689fe694ee9a329797b60b3defc9a87327 libest-f8a6e5b53a5f70e72fe4029981df0693b17cbb32.tar.gz
sha256 2e5c46610f6a3c12c1916c8a84de77421a88c9722e776e862a716f4a48220f2a libest-r3.2.0-9-ga464ba8a66717419ba71d289ef82c7b2315b2006.tar.gz
sha256 fbdb055f98babf8d86095d6f9b9e34d2ff21a8212e442b8f18bdcb403e44366c LICENSE

View File

@@ -4,7 +4,7 @@
#
################################################################################
LIBEST_VERSION = f8a6e5b53a5f70e72fe4029981df0693b17cbb32
LIBEST_VERSION = r3.2.0-9-ga464ba8a66717419ba71d289ef82c7b2315b2006
LIBEST_SITE = $(call github,cisco,libest,$(LIBEST_VERSION))
# We don't build examples, so we're not affected by the OpenSSL
# license

View File

@@ -1,3 +1,3 @@
# Locally calculated sha256 checksums
sha256 55a97cfd8661a9b42ff0123b44af52cac49feaec36987f4d968c046f93b42e1d libfuse3-3.18.2.tar.gz
sha256 a26f46edc8db4e2cbf1b46d36d3e18ea208871671e56434d9ceb8f7887a690d2 libfuse3-3.18.3.tar.gz
sha256 b8832d9caaa075bbbd2aef24efa09f8b7ab66a832812d88c602da0c7b4397fad LICENSE

View File

@@ -4,7 +4,7 @@
#
################################################################################
LIBFUSE3_VERSION = 3.18.2
LIBFUSE3_VERSION = 3.18.3
LIBFUSE3_SITE = $(call github,libfuse,libfuse,fuse-$(LIBFUSE3_VERSION))
LIBFUSE3_LICENSE = LGPL-2.1
LIBFUSE3_LICENSE_FILES = LICENSE

View File

@@ -1,10 +1,11 @@
comment "libgtk3 needs a toolchain w/ wchar, threads, C++, gcc >= 4.9"
comment "libgtk3 needs a toolchain w/ wchar, threads, C++, gcc >= 4.9, dynamic library"
depends on BR2_PACKAGE_HOST_RUSTC_ARCH_SUPPORTS
depends on BR2_USE_MMU
depends on BR2_TOOLCHAIN_HAS_SYNC_4
depends on !BR2_USE_WCHAR || !BR2_INSTALL_LIBSTDCPP || \
!BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 || \
!BR2_TOOLCHAIN_HAS_THREADS
!BR2_TOOLCHAIN_HAS_THREADS || \
BR2_STATIC_LIBS
comment "libgtk3 needs an OpenGL or an OpenGL-EGL backend"
depends on BR2_USE_MMU
@@ -23,6 +24,7 @@ config BR2_PACKAGE_LIBGTK3
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 # pango -> harfbuzz
depends on BR2_PACKAGE_HAS_LIBEGL || \
BR2_PACKAGE_HAS_LIBGL
depends on !BR2_STATIC_LIBS # at-spi2-core
select BR2_PACKAGE_AT_SPI2_CORE
select BR2_PACKAGE_CAIRO
select BR2_PACKAGE_CAIRO_PNG

View File

@@ -1,4 +1,4 @@
# From https://github.com/strukturag/libheif/releases/tag/v1.23.2
sha256 8bd5d41d19dc84536d118b04774709f244df6104ef66d623dad5fa4650143405 libheif-1.23.2.tar.gz
# From https://github.com/strukturag/libheif/releases/tag/v1.23.4
sha256 d0c02b4b0e978f34a1974b6f3eea7975a537bf7a9195ffeea38e7242ff316fdd libheif-1.23.4.tar.gz
# Locally computed:
sha256 fa81ce652315b013359d6e8e4744335f31a50c7c192907176d3632f78a3b4596 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
LIBHEIF_VERSION = 1.23.2
LIBHEIF_VERSION = 1.23.4
LIBHEIF_SITE = https://github.com/strukturag/libheif/releases/download/v$(LIBHEIF_VERSION)
LIBHEIF_LICENSE = LGPL-3.0+
LIBHEIF_LICENSE_FILES = COPYING

View File

@@ -1,7 +1,7 @@
config BR2_PACKAGE_LIBMANETTE
bool "libmanette"
depends on BR2_USE_MMU # libglib2
depends on BR2_USE_WCHAR # libglib2 -> gettext
depends on BR2_USE_MMU # libglib2, hidapi
depends on BR2_USE_WCHAR # libglib2, hidapi
depends on BR2_PACKAGE_HAS_UDEV # hidapi
depends on BR2_TOOLCHAIN_HAS_THREADS_NPTL # hidapi
depends on BR2_TOOLCHAIN_HEADERS_AT_LEAST_4_16

View File

@@ -16,6 +16,10 @@ LIBMPEG2_INSTALL_STAGING = YES
LIBMPEG2_AUTORECONF = YES
LIBMPEG2_CONF_OPTS = --without-x --disable-directx
# Compilers using C23 no longer allows K&R style function
# declarations, so force to use gnu89 standard.
LIBMPEG2_CONF_ENV += CFLAGS="$(TARGET_CFLAGS) -std=gnu89"
LIBMPEG2_CPE_ID_VENDOR = videolan
ifeq ($(BR2_PACKAGE_SDL),y)

View File

@@ -1,6 +1,6 @@
# Locally calculated after checking pgp signature
# https://www.tcpdump.org/release/libpcap-1.10.6.tar.gz.sig
sha256 872dd11337fe1ab02ad9d4fee047c9da244d695c6ddf34e2ebb733efd4ed8aa9 libpcap-1.10.6.tar.gz
# https://www.tcpdump.org/release/libpcap-1.10.7.tar.gz.sig
sha256 0b394ac90dbc0a9838ff97468e05c9c9a3e873dec2514cd58db65d859d296e31 libpcap-1.10.7.tar.gz
# Hash for license file:
sha256 8a54594d257e14a5260ac770f1633516cb51e3fc28c40136ce2697014eda7afd LICENSE

View File

@@ -4,7 +4,7 @@
#
################################################################################
LIBPCAP_VERSION = 1.10.6
LIBPCAP_VERSION = 1.10.7
LIBPCAP_SITE = https://www.tcpdump.org/release
LIBPCAP_LICENSE = BSD-3-Clause
LIBPCAP_LICENSE_FILES = LICENSE

View File

@@ -36,7 +36,7 @@ config BR2_PACKAGE_LIBSSH_LIBGCRYPT
config BR2_PACKAGE_LIBSSH_OPENSSL
bool "openssl"
depends on BR2_PACKAGE_OPENSSL
select BR2_PACKAGE_LIBOPENSSL_ENGINES
select BR2_PACKAGE_LIBOPENSSL_ENGINES if BR2_PACKAGE_LIBOPENSSL
endchoice

View File

@@ -1,6 +1,6 @@
config BR2_PACKAGE_LIBUIO
bool "libuio"
select BR2_PACKAGE_ARGP_STANDALONE if BR2_TOOLCHAIN_USES_UCLIBC || BR2_TOOLCHAIN_USES_MUSL
select BR2_PACKAGE_ARGP_STANDALONE if !BR2_TOOLCHAIN_USES_GLIBC
help
libuio is a light-weight C programming library to handle UIO
(Userspace I/O) device discovery and binding task.

View File

@@ -3,7 +3,7 @@ config BR2_PACKAGE_LIBV4L
depends on BR2_TOOLCHAIN_HAS_THREADS
depends on BR2_INSTALL_LIBSTDCPP
depends on BR2_TOOLCHAIN_HEADERS_AT_LEAST_3_0 # media headers
select BR2_PACKAGE_ARGP_STANDALONE if BR2_TOOLCHAIN_USES_UCLIBC || BR2_TOOLCHAIN_USES_MUSL
select BR2_PACKAGE_ARGP_STANDALONE if !BR2_TOOLCHAIN_USES_GLIBC
select BR2_PACKAGE_LIBICONV if !BR2_ENABLE_LOCALE
help
libv4l is a collection of libraries which adds a thin

View File

@@ -1,4 +1,4 @@
# From https://download.gnome.org/sources/libxml2/2.15/libxml2-2.15.3.sha256sum
sha256 78262a6e7ac170d6528ebfe2efccdf220191a5af6a6cd61ea4a9a9a5042c7a07 libxml2-2.15.3.tar.xz
# From https://download.gnome.org/sources/libxml2/2.15/libxml2-2.15.4.sha256sum
sha256 98087fd181d9070724f3fbc65c7377db03038eb92bd882374daff44940138821 libxml2-2.15.4.tar.xz
# License files, locally calculated
sha256 5d4873884a890122a4b9b20ad56ac6f7da1d796a5bfcf04a427970ac96217626 Copyright

View File

@@ -5,7 +5,7 @@
################################################################################
LIBXML2_VERSION_MAJOR = 2.15
LIBXML2_VERSION = $(LIBXML2_VERSION_MAJOR).3
LIBXML2_VERSION = $(LIBXML2_VERSION_MAJOR).4
LIBXML2_SOURCE = libxml2-$(LIBXML2_VERSION).tar.xz
LIBXML2_SITE = \
https://download.gnome.org/sources/libxml2/$(LIBXML2_VERSION_MAJOR)

View File

@@ -3,8 +3,7 @@ config BR2_PACKAGE_LINKNX
depends on BR2_INSTALL_LIBSTDCPP
depends on BR2_USE_MMU # libpthsem
select BR2_PACKAGE_LIBPTHSEM
select BR2_PACKAGE_ARGP_STANDALONE \
if BR2_TOOLCHAIN_USES_UCLIBC || BR2_TOOLCHAIN_USES_MUSL
select BR2_PACKAGE_ARGP_STANDALONE if !BR2_TOOLCHAIN_USES_GLIBC
select BR2_PACKAGE_LIBICONV if !BR2_ENABLE_LOCALE
help
Linknx is an automation platform providing high level

View File

@@ -472,12 +472,12 @@ endchoice
config BR2_DEFAULT_KERNEL_HEADERS
string
default "5.10.269" if BR2_KERNEL_HEADERS_5_10
default "5.15.220" if BR2_KERNEL_HEADERS_5_15
default "6.1.187" if BR2_KERNEL_HEADERS_6_1
default "6.6.156" if BR2_KERNEL_HEADERS_6_6
default "6.12.108" if BR2_KERNEL_HEADERS_6_12
default "6.18.49" if BR2_KERNEL_HEADERS_6_18
default "5.10.270" if BR2_KERNEL_HEADERS_5_10
default "5.15.221" if BR2_KERNEL_HEADERS_5_15
default "6.1.188" if BR2_KERNEL_HEADERS_6_1
default "6.6.157" if BR2_KERNEL_HEADERS_6_6
default "6.12.111" if BR2_KERNEL_HEADERS_6_12
default "6.18.54" if BR2_KERNEL_HEADERS_6_18
default "7.1.13" if BR2_KERNEL_HEADERS_7_1
default BR2_DEFAULT_KERNEL_VERSION if BR2_KERNEL_HEADERS_VERSION
default "custom" if BR2_KERNEL_HEADERS_CUSTOM_TARBALL

Some files were not shown because too many files have changed in this diff Show More