Compare commits

..

395 Commits

Author SHA1 Message Date
Raphaël Mélotte
7fccf3a91e support/testing: harfbuzz: new runtime test
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-10-01 18:53:43 +02:00
Raphaël Mélotte
850e5de7ea package/harfbuzz: add upstream patch fixing builds with old gcc
Building with an old gcc version (for example with
  bootlin-aarch64-glibc-old) currently fails with the following error:
  ../src/graph/graph.hh:638:12: error: could not convert ‘g’ from ‘graph::graph_t’ to ‘graph::graph_result_t<graph::graph_t> {aka hb_result_t<graph::graph_t, graph::graph_error_t>}’
       return g;

Add an upstream patch to fix it.

No corresponding build failures on autobuilders were found at the time
the commit was made.

Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-10-01 18:53:43 +02:00
Bernd Kuhls
1eb8b44822 package/rsync: bump to version 3.5.1
https://download.samba.org/pub/rsync/NEWS#3.5.1

Switched to sha256 tarball hash provided by upstream.

Added configure options to handle new optional dependency to libidn2:
f0177d82a8

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-10-01 18:51:39 +02:00
Yegor Yefremov
34964aa111 package/igh-ethercat: bump to 1.6.13
This release replaces strncpy() with strscpy() in kernel space, which
fixes the build with Linux >= 7.2, where strncpy() is no longer
available to kernel code.

From:
https://gitlab.com/etherlab.org/ethercat/-/blob/1.6.13/NEWS.md#version-1613

- Made the macb (Cadence GEM) EtherCAT RX path allocation-free to
  avoid receive latency spikes under host memory pressure.
- Included macb in the device driver table and fixed a
  `CONFIG_MACB_USE_HWSTAMP` build issue.
- Use `strscpy` instead of the deprecated `strncpy` in kernel space,
  with a fallback for Linux < 4.2.
- Added a test build for kernel 6.18.
- Improved `ecrt_slave_config_dc()` documentation.
- Adopted the CPPlint configuration of stable-1.7, fixed CPPlint
  complaints and added exceptions for device drivers.
- Use an own pre-commit container with cache in CI.

Fixes: https://autobuild.buildroot.org/results/5c48b38fba102c38630e546eeea05cf206eb9e53/

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-10-01 18:50:39 +02:00
Baruch Siach
64002f0985 package/tcpdump: bump to version 4.99.7
Changelog:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.99/CHANGES

Signed-off-by: Baruch Siach <baruch@tkos.co.il>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-10-01 18:49:10 +02:00
Bernd Kuhls
6e0a068475 package/python3: security bump version to 3.14.8
https://www.python.org/downloads/release/python-3148/
https://docs.python.org/release/3.14.8/whatsnew/changelog.html

Security content in this releases

CVE-2026-19445 gh-156293
Use-after-free of a server-side SSLContext when sni_callback switches
contexts

CVE-2026-19553 gh-156793
SSLContext.wrap_bio() missing validation of server_hostname parameter

CVE-2026-82049 gh-157190
tarfile extraction filters allow file modification and content
disclosure via hard link to symlink

CVE-2026-15310 gh-156002
Memory exhaustion in zipfile in bzip2/LZMA/Zstandard decompression

CVE-2026-19672 gh-155999
tarfile extraction filter bypass allows creation of directories outside
the destination

CVE-2026-15806 gh-155694
urllib.request.HTTPPasswordMgr credentials for one URL scheme sent over
another scheme

CVE-2026-17084 gh-155292
StringPrep algorithm considered Unicode codepoint attributes outside
Unicode 3.2.0

gh-158446
Reject float format precision near INT_MAX

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-10-01 18:46:50 +02:00
Bernd Kuhls
97a94e01ef package/libopenssl: security bump to version 3.6.5
https://github.com/openssl/openssl/releases/tag/openssl-3.6.5

This release incorporates the following bug fixes and mitigations:

Fixed DTLS retransmissions of handshake messages from a stale buffer offset.
(CVE-2026-84782)

Fixed excessive memory allocation in relative CRLDP processing.
(CVE-2026-35189)

Fixed QUIC unvalidated amplification credit may be over-accounted.
(CVE-2026-35191)

Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC.
(CVE-2026-42772)

Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves.
(CVE-2026-54872)

Fixed QUIC STREAM fragment metadata DoS.
(CVE-2026-54873)

Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V.
(CVE-2026-54875)

Fixed out-of-bounds access after SSL_set_SSL_CTX() during a handshake.
(CVE-2026-72897)

Fixed QUIC connection-level flow control was not enforced for streams.
(CVE-2026-75804)

Fixed a NULL pointer dereference in CMP client revocation response handling.
(CVE-2026-75805)

Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS.
(CVE-2026-75806)

Fixed a timing side-channel in SM2 signature generation.
(CVE-2026-77696)

Fixed an unbounded RETIRE_CONNECTION_ID backlog in QUIC stack
implementation.
(CVE-2026-84784)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-30 21:24:23 +02:00
Bernd Kuhls
99ea0fbb3d package/pcre2: security bump to version 10.49
https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.49

This is a security-only release, to address GHSA-r9hj-j2rw-4q3m:
https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m

Switched to sha256 tarball hash provided by upstream.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-30 21:19:08 +02:00
Bernd Kuhls
c71fccc7a9 package/{glibc, localedef}: security bump version to 2.44-55-gc90398e00
Fixes CVE-2026-89092:
c90398e005

Also fix typo in comment.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-30 20:48:56 +02:00
Julien Olivain
1ad0796f2b support/testing: bubblewrap: new runtime test
Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-29 08:35:41 +02:00
Yegor Yefremov
54ccee7e67 package/libabseil-cpp: fix build on x86 32-bit with AES
Since the bump to version 20260817.0, the AES-based hash for long
strings is used whenever __SSE4_2__ and __AES__ are defined. It relies
on _mm_cvtsi128_si64() and _mm_extract_epi64(), which are only
available on x86_64, so the build fails on 32-bit x86 for CPUs that
support SSE4.2 and AES:

  hash.cc:115:32: error: '_mm_cvtsi128_si64' was not declared in this scope

Add a patch from a pending upstream pull request restricting this code
path to x86_64.

Fixes:
https://autobuild.buildroot.org/results/48198506ef76c6ebad0a802cb1fdd5270494eae1

Assisted-by: Claude:claude-opus-5
Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 23:43:19 +02:00
Yegor Yefremov
66c1665642 package/poco: convert to CMake package
Currently when building with make, the cmake config files are not
generated. This leads to problems when integrating the package in an
application built with cmake.

The CMake build system links the PDF component against the system
libpng when POCO_UNBUNDLED is enabled, while the legacy make build
system always used the bundled copy, so select libpng for the PDF
component.

POCO_NO_FPENVIRONMENT and POCO_NO_WSTRING are plain preprocessor
defines rather than CMake options, so pass them through CMAKE_CXX_FLAGS.

Poco is built as a set of shared libraries, so -latomic has to be
passed via CMAKE_SHARED_LINKER_FLAGS as well.

Disable File2Page along with PageCompiler, and tie the ActiveRecord
compiler to the ActiveRecord component, to match what the legacy make
build system omitted.

This patch is based on this one:
https://lists.buildroot.org/pipermail/buildroot/2026-April/801019.html

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 23:40:25 +02:00
Bernd Kuhls
5510a84de6 package/ecryptfs-utils: remove OpenSSL support
OpenSSL 4.0 removed support for engines.

Please note that upstream considers eCryptfs deprecated:
https://lore.kernel.org/lkml/ZyKf6ZSZrETI+4%2FS@redbud/T/#u

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 23:38:10 +02:00
Bernd Kuhls
451d9950d1 package/snort3: bump version to 3.12.2.0
https://github.com/snort3/snort3/blob/3.12.2.0/ChangeLog.md

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 23:30:46 +02:00
Bernd Kuhls
6276402ea1 package/daq3: bump version to 3.0.27
https://github.com/snort3/libdaq/blob/v3.0.27/ChangeLog.md

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 23:29:09 +02:00
Dario Binacchi
3f4e6fcd95 package/ufs-utils: bump to version 8.14.12
Release notes:
https://github.com/SanDisk-Open-Source/ufs-utils/releases/tag/v8.14.12

Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 23:24:46 +02:00
Dario Binacchi
59b5c3d2bb package/less: bump to version 710
For change log, see:
https://www.greenwoodsoftware.com/less/news.710.html

Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 23:22:49 +02:00
Dario Binacchi
af7fca093e package/atf: bump to version 0.26
Release notes:
https://github.com/freebsd/atf/releases/tag/atf-0.26

Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 23:21:44 +02:00
Fiona Klute
a2b5b7371b package/bubblewrap: fix build failure if kernel uses localversion
Bubblewrap expects the value of the assume_kernel option, if set, to
be exactly three numbers separated by dots, nothing else [1]. If that
requirement is not met configuring the build fails.

Buildroot sets assume_kernel to $(LINUX_VERSION_PROBED) since the
version bump to 0.12.0. However, the expansion of
LINUX_VERSION_PROBED may contain additional suffixes, e.g. if
CONFIG_LOCALVERSION is set, or localversion* files are present (like
in CIP kernels). So filter the version string to ignore any suffixes.

[1] https://github.com/containers/bubblewrap/blob/v0.13.0/meson.build#L94-L104

Fixes: 4cb6193d2e ("package/bubblewrap: security bump to version 0.12.0")
Fixes: https://autobuild.buildroot.org/results/e7513e4730000e46b13bb9cf25955ebd3ec5fb71/

Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
Acked-by: Adrian Perez de Castro <aperez@igalia.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 23:18:40 +02:00
Yegor Yefremov
79e6e2d88c package/lpac: bump version to 2.3.0
Release notes:
https://github.com/estkme-group/lpac/releases/tag/v2.3.0

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 23:16:22 +02:00
John Ernberg
8b57f2f421 package/util-linux-libs: Do not install to target
util-linux-libs was introduced as an intermediate package to help break
circular dependencies with util-linux, and therefor only exists to provide
more basic versions of the libraries util-linux provide, to break these
dependency chains.

There is no need to install these to target as they will never be used
there.

Under all circumstances the libraries are built and installed by the main
util-linux package.

This only solves the confict for target, the conflict will remain for
staging as that conflict is much harder to solve.

Cc: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: John Ernberg <j@j-ernberg.se>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
2026-09-28 23:08:12 +02:00
Titouan Christophe
f20b1b166b package/wireshark: bump to the latest upstream v4.6.9
Wireshark 4.6 is the current Stable version, while 4.4 is the Old Stable,
see https://www.wireshark.org/download.html

See the major changes from Wireshark 4.4 to 4.6 in these release notes:
https://www.wireshark.org/docs/relnotes/wireshark-4.6.0.html. Of notable
interest, libxml2 is now a required dependency.

This is not considered a security update because all important security fixes
that landed in Wireshark 4.6 patch releases are also available in
Wireshark 4.4.19 (currently in Buildroot).

Side discussion: Wireshark 4.2 is now EOL, see
https://www.wireshark.org/docs/wsug_html/#ChIntroEndOfSupportPlanning
As of today, Buildroot LTS 2025.02.x distributes Wireshark 4.2, and
therefore we should consider bumping it to 4.4.19, or even apply this
patch to bump to Wireshark 4.6.9 which will be supported for longer.

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 23:04:44 +02:00
Francois Perrad
c4c6ad81bf package/wireshark: fix support for lua
Since version 4.4.0 of wireshark, support for Lua 5.3 and 5.4 has been
added, and support for Lua 5.1 and 5.2 has been removed. See
https://www.wireshark.org/docs/relnotes/wireshark-4.4.0.html

This fixes an infinite loop during the build, as for some reason when
Lua 5.1 is available, the CMake check for Lua 5.3 or 5.4 loops
indefinitely, with cmake taking up 100% of one CPU core.

Fixes: 49fa20e667 ("package/wireshark: bump to latest upstream stable v4.4.9")
Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 23:02:57 +02:00
Bernd Kuhls
b3fc9c76fa package/ntp: add support for OpenSSL 4.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 15:05:00 +02:00
Bernd Kuhls
ce1bde641b package/grpc: fix build with OpenSSL 4.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 14:37:53 +02:00
Bernd Kuhls
e2f49a31c8 package/libp11: bump version to 0.4.20
https://github.com/OpenSC/libp11/blob/libp11-0.4.20/NEWS

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 14:33:23 +02:00
Bernd Kuhls
a731846e46 package/omniorb: Fix build with OpenSSL 4.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 14:17:51 +02:00
Yegor Yefremov
eb6d16df92 package/pcsc-lite: bump version to 2.5.2
Autotools support was removed upstream in 2.5.0, so switch to the meson
build system:
- the tarball is now only provided as .tar.xz
- --disable-strict has no meson equivalent and is dropped
- there is no debugatr option anymore, so define ATR_DEBUG via CFLAGS
- pass -latomic via LDFLAGS instead of LIBS
- meson installs the systemd units into the user unit directory by
  default, so pass -Dsystemdunit=system to keep them in the system
  unit directory as before

Since 2.4.0, pcscd.service runs pcscd as the unprivileged pcscd user,
so add it to the users table.

COPYING hash changed because doc/example/pcsc_demo.c was removed from
the list of GPL-3.0+ files; Buildroot already listed it as
BSD-3-Clause.

https://github.com/LudovicRousseau/PCSC/blob/2.5.2/ChangeLog

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 14:00:12 +02:00
Bernd Kuhls
7dab0537a0 package/libopenssl: remove patch 0002
Patch was committed upstream in a slightly different version
0984041283
and was first released in version 3.0 which was added to buildroot with
commit 3c66f65a6a.

Added Upstream: tag to patch 0001.

Renumbered patch 0003 and updated Upstream: tag.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 13:51:32 +02:00
Bernd Kuhls
a9d4e45d95 package/netsnmp: fix build with OpenSSL 4.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 13:50:21 +02:00
Bernd Kuhls
0edc67470b package/opensc: add support for OpenSSL 4.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 13:37:21 +02:00
Bernd Kuhls
79e1d59d27 package/gloox: fix build with OpenSSL 4.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 13:36:00 +02:00
Bernd Kuhls
061a33b36a package/mender: fix build with OpenSSL 4.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 13:26:46 +02:00
Bernd Kuhls
3caf39eb79 package/pkcs11-helper: add support for OpenSSL 4.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 13:24:40 +02:00
Bernd Kuhls
0b1caae22b package/mtd: fix build with OpenSSL 4.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 13:24:00 +02:00
Yegor Yefremov
441ccd8dab package/libsoup3: fix static build
Since the bump to 3.7.3, libsoup unconditionally includes <dlfcn.h>
in soup-init.c to detect whether libsoup2 is loaded in the same
process. Static-only toolchains such as uClibc-ng without shared
library support don't provide this header, so the build fails:

../libsoup/soup-init.c:21:10: fatal error: dlfcn.h: No such file or directory

Add a patch, submitted upstream, that checks for dlfcn.h at configure
time and skips the libsoup2 detection when it is not available.

Fixes:
https://autobuild.buildroot.org/results/4effebe5fc12146749e704dd56f695363cc8fbc3

Fixes: 55cec1d013 ("package/libsoup3: bump to 3.7.3")
Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 13:06:42 +02:00
Bernd Kuhls
df39c8c524 package/asterisk: fix build with OpenSSL 4.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-28 10:23:05 +02:00
Bernd Kuhls
e523c64d3b package/asterisk: bump version to 22.11.0
https://community.asterisk.org/t/asterisk-release-22-11-0/114073

https://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-22.11.0.html
Security Advisories Resolved: 0

Switched to tarball provided by upstream.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-27 18:56:44 +02:00
Bernd Kuhls
96a2337bd4 package/asterisk: bump bundled pjsip to 2.17
Buildroot commit 7f48325de6 bumped the
asterisk package from 22.9.0 to 22.10.1.

This bump includes upstream commit
5d543ad80c
which bumped the bundled pjsip package to 2.17.

To allow offline builds we download the pjsip tarball so we need to keep
the version numbers in sync.

The autobuilders logs show a download process:
https://autobuild.buildroot.net/results/400/400e53158f11926446c11d22681eb8a9430caf1d/build-end.log

checking for embedded pjproject (may have to download)... configuring
[pjproject]  Downloading https://raw.githubusercontent.com/asterisk/third-party/master/pjproject/2.17/pjproject-2.17.tar.bz2 to
               /home/autobuild/autobuild/instance-3/dl/asterisk/pjproject-2.17.tar.bz2
[pjproject]  Verifying /home/autobuild/autobuild/instance-3/dl/asterisk/pjproject-2.17.tar.bz2

where the tarball was once stored in the configured download directory:

  --with-download-cache=$(ASTERISK_DL_DIR)

to be used during later autobuilder runs.

Fixes: 7f48325de6 ("package/asterisk: security bump to 22.10.1")
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
[Thomas: add comment in .mk file]
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-27 18:55:45 +02:00
Peter Seiderer
ea9d29a8af package/chrony: bump version to 4.9
- bump version to 4.9 (for details see [1])

[1] https://chrony-project.org/news.html#27_aug_2026_chrony_4_9_released

Signed-off-by: Peter Seiderer <ps.report@gmx.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-27 15:05:15 +02:00
Giulio Benetti
633d368bae package/wireshark: security bump to v4.4.19
Fixes the following vulnerabilities:

- wnpa-sec-2026-93 · SCTP protocol dissector crash.
  https://www.wireshark.org/security/wnpa-sec-2026-93
  CVE-2026-95389.

- wnpa-sec-2026-96 · IEEE C37.118 Synchrophasor protocol dissector
  memory leak.
  https://www.wireshark.org/security/wnpa-sec-2026-96
  CVE-2026-95395.

- wnpa-sec-2026-97 · SPDY protocol dissector crash.
  https://www.wireshark.org/security/wnpa-sec-2026-97
  CVE-2026-95387.

- wnpa-sec-2026-98 · Microsoft Network Monitor file parser large loop.
  https://www.wireshark.org/security/wnpa-sec-2026-98
  CVE-2026-95394.

- wnpa-sec-2026-99 · CSN.1 protocol dissector crash.
  https://www.wireshark.org/security/wnpa-sec-2026-99
  CVE-2026-95393.

- wnpa-sec-2026-100 · MBIM protocol dissector crash. wsbuglink:21549,
  https://www.wireshark.org/security/wnpa-sec-2026-100
  CVE-2026-95392.

- wnpa-sec-2026-101 · Sharkd utility crash.
  https://www.wireshark.org/security/wnpa-sec-2026-101
  CVE-2026-95388.

- wnpa-sec-2026-102 · Frame protocol metadissector crash.
  https://www.wireshark.org/security/wnpa-sec-2026-102
  CVE-2026-96422.

- wnpa-sec-2026-103 · USB HID protocol dissector infinite loop and
  memory leak.
  https://www.wireshark.org/security/wnpa-sec-2026-103
  CVE-2026-96421.

- wnpa-sec-2026-104 · RF4CE protocol dissector crash.
  https://www.wireshark.org/security/wnpa-sec-2026-104
  CVE-2026-96417.

- wnpa-sec-2026-105 · Toshiba file parser crash.
  https://www.wireshark.org/security/wnpa-sec-2026-105
  CVE-2026-xxx.

- wnpa-sec-2026-106 · Profile import crash and possible code execution.
  https://www.wireshark.org/security/wnpa-sec-2026-106
  CVE-2026-96419.

- wnpa-sec-2026-107 · TIFF protocol dissector infinite loop.
  https://www.wireshark.org/security/wnpa-sec-2026-107
  CVE-2026-96418.

- wnpa-sec-2026-108 · X11 protocol dissector crash.
  https://www.wireshark.org/security/wnpa-sec-2026-108
  CVE-2026-96423.

- wnpa-sec-2026-109 · IEEE 802.11 protocol dissector crash.
  https://www.wireshark.org/security/wnpa-sec-2026-109
  CVE-2026-96416.

- wnpa-sec-2026-110 · Catapult DCT2000 protocol dissector crash.
  https://www.wireshark.org/security/wnpa-sec-2026-110
  CVE-2026-96415.

For more information on the version bump, see:
  - https://www.wireshark.org/docs/relnotes/wireshark-4.4.19.html

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-27 12:09:40 +02:00
Peter Seiderer
236fd61a83 package/iptables: bump version to 1.8.13
- bump version to 1.8.13 (for details see [1] and [2])
- remove 0001-nft-fix-interface-comparisons-in-C-commands.patch
  (from upstream [3])

[1] https://netfilter.org/projects/iptables/files/changes-iptables-1.8.12.txt
[2] https://netfilter.org/projects/iptables/files/changes-iptables-1.8.13.txt
[3] https://git.netfilter.org/iptables/commit/?id=40406dbfaefbc204134452b2747bae4f6a122848

Signed-off-by: Peter Seiderer <ps.report@gmx.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-27 10:58:22 +02:00
Peter Seiderer
7626aada6a package/nftables: bump version to 1.1.7
- bump version to 1.1.7 (for details see [1])
- update coreteam gpg key URL to newer key (used since nftables-1.1.1)

[1] https://git.netfilter.org/nftables/log/?h=v1.1.7

Signed-off-by: Peter Seiderer <ps.report@gmx.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-27 10:58:22 +02:00
Peter Seiderer
94143f61e4 package/libnftnl: bump version to 1.3.2
- bump version to 1.3.2 (for details see [1])
- change sha256 URL to https
- update coreteam gpg key URL to newer key (used since libnftnl-1.2.9)

[1] https://git.netfilter.org/libnftnl/log/?h=libnftnl-1.3.2

Signed-off-by: Peter Seiderer <ps.report@gmx.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-27 10:58:22 +02:00
Peter Seiderer
b19b1caaef package/dhcpcd: bump version to 10.5.2
- bump version to 10.5.2 (for details see [1], [2])

https://github.com/NetworkConfiguration/dhcpcd/releases/tag/v10.5.2
https://github.com/NetworkConfiguration/dhcpcd/releases

Signed-off-by: Peter Seiderer <ps.report@gmx.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-27 10:42:22 +02:00
Peter Seiderer
1caeb632a6 package/ntpsec: security bump version to 1.2.5
Fixes: CVE-2026-18321:
https://nvd.nist.gov/vuln/detail/cve-2026-18321

- bump version to 1.2.5 (for details see [1])
- rebased 0001-wscript-remove-checks-for-bsd-string.h-fixes-host-co.patch
- rebased 0002-disable-PIE-support.patch
- removed 0003-ntpd-refclock_gpsd.c-Add-missing-time.h-for-strptim.patch
  (from upstream [2])
- moved 0004-refclock_gpsd-add-build-fix-for-gcc-14.x.patch to
  0003-refclock_gpsd-add-build-fix-for-gcc-14.x.patch, rebased and enhanced
  as the original conflicts with upstream commit 5505260c ("Fix redefined
  _XOPEN_SOURCE warning in refclock_gpsd.c") [3] and leads to the following
  compile failure:

    ../../ntpd/refclock_gpsd.c:113:21: error: operator ‘<’ has no left operand
      113 |   #if _XOPEN_SOURCE < 700
          |                     ^

[1] https://lists.ntpsec.org/pipermail/devel/2026-July/011029.html
[2] 5137c155d8
[3] 5505260cd1

Signed-off-by: Peter Seiderer <ps.report@gmx.net>
[Julien: mark commit as "security bump"]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-27 10:23:34 +02:00
Bernd Kuhls
063863ee5c package/samba4: bump version to 4.25.0
https://www.samba.org/samba/history/samba-4.25.0.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-26 12:08:46 +02:00
Bernd Kuhls
f07eeff6df package/php: security bump version to 8.5.11
https://news-web.php.net/php.announce/506
https://www.php.net/ChangeLog-8.php#8.5.11
https://github.com/php/php-src/blob/php-8.5.11/NEWS

Fixes CVE-2025-1218, CVE-2025-14181, CVE-2026-6103, CVE-2026-17545,
CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768,
CVE-2026-91769, CVE-2026-92842 & CVE-2026-93682.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-26 11:32:14 +02:00
Bernd Kuhls
80114e20e4 {linux, linux-headers}: bump 7.2.x, 6.18.x series
Update the latest kernel releases to:
- 7.2.7 -> 7.2.8
- 6.18.53 -> 6.18.54

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
2026-09-25 22:11:08 +02:00
Adrian Perez de Castro
0867818a73 package/bubblewrap: security bump to version 0.13.0
While there are no CVEs for this Bubblewrap release, it includes a fix
to ensure that arguments that receive a path are not empty (which before
treated those as the root directory: a bit of a footgun!), and that is a
follow-up to the security fixes included in 0.12.0.

Additionally, it patches a number of build failures, which fixes e.g.:

  https://autobuild.buildroot.org/results/2eb2d222daaadc2eb16b42fa2ec102ab0689f038
  https://autobuild.buildroot.org/results/674413f089ce9b80a59058674b3ef6879e1d389c

Release notes:

  https://github.com/containers/bubblewrap/releases/tag/v0.13.0

Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-25 21:11:52 +02:00
Titouan Christophe
a962be2eea package/xen: bump to version 4.22.0
See the release notes:
https://wiki.xenproject.org/wiki/Xen_Project_4.22_Release_Notes?ref=xenproject.org

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-25 13:51:03 +02:00
Titouan Christophe
0bf8b2ecee package/xen: add x86_64 target
Add support for building xen for x86_64 targets. In this initial version,
do not build extra bootloaders which would require additional download
infrastructure.

Assisted-by: Claude:opus-5.5
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-25 13:51:03 +02:00
Bernd Kuhls
e7bbe36be8 package/fetchmail: bump version to 6.6.8
https://sourceforge.net/p/fetchmail/mailman/message/59396310/
"It also includes fetchmail 6.6.7's security bugfix for NTLM, which
has now been assigned CVE-2026-94184."

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-24 21:05:30 +02:00
Bernd Kuhls
15ea2f8221 package/llvm-project: bump version to 23.1.2
https://discourse.llvm.org/t/llvm-23-1-2-released/91895

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-24 20:29:50 +02:00
Bernd Kuhls
08b06173bd package/flutter-engine: fix build with pango >= 1.58.0
Buildroot commit c3aa677456 bumped pango
to 1.58.0 causing a build error with flutter-engine

../../flutter/shell/platform/linux/fl_accessible_text_field.cc:9:1:
 error: redefinition of 'glib_autoptr_clear_PangoContext'
    9 | G_DEFINE_AUTOPTR_CLEANUP_FUNC(PangoContext, g_object_unref)

../../flutter/shell/platform/linux/fl_accessible_text_field.cc:60:3:
 error: 'cleanup' argument is not a function
   60 |   g_autoptr(PangoContext) context = get_pango_context(self);

with this defconfig:

BR2_x86_64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_PACKAGE_MESA3D=y
BR2_PACKAGE_MESA3D_GALLIUM_DRIVER_SOFTPIPE=y
BR2_PACKAGE_MESA3D_OPENGL_EGL=y
BR2_PACKAGE_MESA3D_OPENGL_ES=y
BR2_PACKAGE_FLUTTER_ENGINE=y
BR2_PACKAGE_LIBGTK3=y

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-24 19:23:33 +02:00
Giulio Benetti
4919a5fecf package/nfs-utils: bump version to 3.3.1
Remove patches upstreamed in this release.

Release announce:
https://lore.kernel.org/linux-nfs/5717a803-805c-409f-a9cc-d0c33a365570@redhat.com/

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-23 21:37:45 +02:00
Bernd Kuhls
dc5cb8f02d package/tor: security bump version to 0.4.9.13
https://gitlab.torproject.org/tpo/core/tor/-/blob/tor-0.4.9.13/ReleaseNotes

TROVE-2026-012, TROVE-2026-030, TROVE-2026-038, TROVE-2026-041,
TROVE-2026-050, TROVE-2026-051, TROVE-2026-052, TROVE-2026-053,
TROVE-2026-056 & TROVE-2026-058.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-23 21:33:55 +02:00
Bernd Kuhls
67380a32f7 package/expat: security bump version to 2.8.5
https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/Changes
https://blog.hartwork.org/posts/expat-2-8-5-released/

Fixes CVE-2026-93990.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-23 21:29:34 +02:00
Michael Fischer
74fe3559d6 package/sdl3_image: security bump to version 3.4.6
For release notes, see:
https://github.com/libsdl-org/SDL_image/releases

3.1.1 was a preview release. Among the changes since, it fixes the XCF
loader issue reported as CVE-2026-35444 (fixed in 3.4.2). See:
https://github.com/libsdl-org/SDL_image/releases/tag/release-3.4.2

The LICENSE.txt hash changes because the copyright year was updated
upstream. The license itself is unchanged (Zlib).

Signed-off-by: Michael Fischer <mf@go-sys.de>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-22 22:38:24 +02:00
Alsey Coleman Miller
2e4036e3a0 package/plutovg: new package
plutovg is a standalone 2D vector graphics library providing path
filling and stroking, gradients and text rendering. It is the renderer
plutosvg is built on.

Examples are not built: they are demo programs that are never installed.

Signed-off-by: Alsey Coleman Miller <alseycmiller@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-22 21:28:32 +02:00
Julien Olivain
e2b81003a4 .checkpackageignore: remove entry for mrouted package
Buildroot commit [1] (package/mrouted: fix invalid daemon path in
S41mrouted) removed script execution permission but forgot to remove
the corresponding .checkpackage entry.

check-package is reporting the error:

    package/mrouted/S41mrouted:0: NotExecutable was expected to fail, did you fix the file and forget to update /builds/buildroot.org/buildroot/.checkpackageignore?

This commit fixes the issue by removing the entry.

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16661195972

[1] d8f408b1f1

Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-22 20:14:35 +02:00
Joachim Wiberg
1e62d0b062 package/mrouted: bump to version 4.7
Multiple changes upstream, for the full list of changes, see the release
notes: https://github.com/troglobit/mrouted/releases/tag/4.7

Package changes:

- Drop local backported patch, merged in 4.7

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-22 19:08:08 +02:00
Joachim Wiberg
d8f408b1f1 package/mrouted: fix invalid daemon path in S41mrouted
S41mrouted hard-coded /sbin/mrouted, but mrouted has always installed
to /usr/sbin/mrouted. This went unnoticed with BR2_ROOTFS_MERGED_USR=y,
but the daemon fails to start without it.

Also drop the script's executable bit to match other sysv init
scripts that do not set it.

Introduced in c25115daf2
(package/mrouted: add sysv init script).

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-22 19:08:03 +02:00
Bernd Kuhls
5ce1dc60fb package/libde265: bump version to 1.1.3
https://github.com/strukturag/libde265/releases/tag/v1.1.3

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-22 19:02:24 +02:00
Fiona Klute
7eede98528 package/kbd: fix static build with uClibc
Since upstream commit 7fdd8debe37ae52812b77d82e08713bd62c607f4 [1]
(included from release 2.9.0) libkbdfile unconditionally includes
dlfcn.h. uClibc provides this header only if shared library support is
enabled [2], so building kbd fails if BR2_TOOLCHAIN_BUILDROOT_UCLIBC=y
and BR2_STATIC_LIBS=y (BR2_SHARED_STATIC_LIBS=y works).

The issue has been fixed upstream [3], backport the patch.

[1] https://git.kernel.org/pub/scm/linux/kernel/git/legion/kbd.git/commit/?id=7fdd8debe37ae52812b77d82e08713bd62c607f4
[2] https://github.com/wbx-github/uclibc-ng/blob/v1.0.59/Makefile.in#L260
[3] https://github.com/legionus/kbd/issues/159

Fixes: 930660890b
Fixes: https://autobuild.buildroot.org/results/872d12bf869717ae8aec9a2ed6295cf8f7e8b098/
Fixes: https://autobuild.buildroot.org/results/056b5fe4ca230989041a1ed166c1b509f8bb0908/

Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-22 18:52:21 +02:00
Bernd Kuhls
309ea70367 package/utfcpp: bump version to 4.2.1
https://github.com/nemtrif/utfcpp/releases/tag/v4.2.1

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-22 18:50:41 +02:00
Stephan Hoffmann
f18c4dbdce package/libhttpserver: bump to version 2.0.0
Version 2.0.0 requires C++20 and GCC 11 or newer.

This major release changes the API exposed to applications. However,
the 0.x release series is end-of-life, so staying on version 0.19.0 is
not a viable option.

The build system detects GnuTLS through its headers and links to it
directly. Make this detection deterministic by following the
libmicrohttpd SSL option and adding the corresponding dependency.

https://github.com/etr/libhttpserver/releases/tag/2.0.0

Signed-off-by: Stephan Hoffmann <sho@relinux.de>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-22 18:47:12 +02:00
Giulio Benetti
b5ce8971bb package/harfbuzz: bump version to 14.5.0
https://github.com/harfbuzz/harfbuzz/blob/14.5.0/NEWS

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-22 18:37:01 +02:00
Bernd Kuhls
b0511042e8 package/bpftrace: bump version to 0.27.0
https://github.com/bpftrace/bpftrace/blob/v0.27.0/CHANGELOG.md

This release includes
d7a3bb54a3
which adds support for LLVM 23.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-22 12:32:49 +02:00
Bernd Kuhls
2a0a1c19c1 {linux, linux-headers}: bump 6.12.x, 6.18.x, 7.2.x series
Update the latest kernel releases to:
 - 6.12.110 -> 6.12.111
 - 6.18.52 -> 6.18.53
 - 7.2.6 -> 7.2.7

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
2026-09-22 11:04:10 +02:00
Koen Martens
81060d467f DEVELOPERS: remove Koen Martens from capnproto and linuxconsoletools
I have left the field of software engineering and will no longer
contribute.

Signed-off-by: Koen Martens <gmc@sonologic.nl>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
2026-09-22 11:01:38 +02:00
Yann E. MORIN
a489e7c212 package/skopeo: use new upstream location
The upstream location has changed (with a forward from the old one, so
we did not notice earlier) [0] [1], with 1.23.0 the first release being
made from the new location, which was accounted for in 96aac440dd
(package/skopeo: bump version to 1.23.0) as it required the change of
the gomod, but where the new location was missed.

Eventually switch to the new location now.

[0] https://github.com/podman-container-tools/skopeo/pull/2854
[1] https://github.com/podman-container-tools/go.podman.io/pull/6

Reported-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Yann E. MORIN <yann.morin@orange.com>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
2026-09-22 10:57:29 +02:00
Bernd Kuhls
45f1c387e0 package/llvm-project: bump version to 23.1.1
https://discourse.llvm.org/t/llvm-23-1-1-released/91760

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-21 20:51:09 +02:00
Yann E. MORIN
b2c69fe0a4 package/skopeo: security bump to version 1.24.1
Changelog:
https://github.com/podman-container-tools/skopeo/releases/tag/v1.24.1

This releases brings in a fix for:
* CVE-2025-11395

Signed-off-by: Yann E. MORIN <yann.morin@orange.com>
[Julien: add info in commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-21 19:44:07 +02:00
Yann E. MORIN
e80a249f49 package/docker-credential-gcr: bump version to 2.2.1
Changelog since v2.1.32:
https://github.com/GoogleCloudPlatform/docker-credential-gcr/releases/tag/v2.2.1
https://github.com/GoogleCloudPlatform/docker-credential-gcr/releases/tag/v2.2.0
https://github.com/GoogleCloudPlatform/docker-credential-gcr/releases/tag/v2.1.33

Signed-off-by: Yann E. MORIN <yann.morin@orange.com>
[Julien: add info in commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-21 19:44:03 +02:00
Yann E. MORIN
02cc32ee5c package/distribution-registry: security bump to version 3.1.1
Changelog since v3.0.0:
https://github.com/distribution/distribution/releases/tag/v3.1.0
https://github.com/distribution/distribution/releases/tag/v3.1.1

This feature-release also contains security fixes:
* CVE-2026-35172
* CVE-2026-33540
* CVE-2026-41888

Drop our backported patch, included since 3.1.0

Signed-off-by: Yann E. MORIN <yann.morin@orange.com>
[Julien: add info in commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-21 19:43:55 +02:00
Bernd Kuhls
dbf3c1f7bf package/linux-firmware: bump version to 20260916
Updated the hash of the WHENCE file, due to firmware additions and
firmware changes, but no changes to the redistribution/licensing
conditions.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-21 19:19:08 +02:00
Chen Pei
e88c26904b package/iniparser: bump version to 4.3.0
https://gitlab.com/iniparser/iniparser/-/releases/v4.3.0

Bugfix release: fixes stack-buffer-overflows in escape_value(),
iniparser_getseckeys(), iniparser_getsecnkeys() and
iniparser_dumpsection_ini(). Adds iniparser_load_buffer() to parse ini
data from memory and generates version number constants. The SONAME
major version is unchanged.

Signed-off-by: Chen Pei <cp0613@linux.alibaba.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-21 19:08:55 +02:00
Bernd Kuhls
43de288bd1 package/qt6: security bump version to 6.11.2
https://code.qt.io/cgit/qt/qtreleasenotes.git/about/qt/6.11.2/release-note.md

Security fixes:
CVE-2026-16762 in qtbase
CVE-2026-19248 in qtbase
CVE-2026-13326 in qtconnectivity
CVE-2026-8168 in qtsvg

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-20 16:56:55 +02:00
Yegor Yefremov
15ccf339c9 package/stunnel: fix build on ARM Thumb-1
stunnel's configure unconditionally probes -fstack-clash-protection
using AX_APPEND_COMPILE_FLAGS. The probe compiles a trivial conftest.c,
which succeeds, so the flag ends up in CFLAGS. However, on ARM Thumb-1
gcc implements stack clash protection through -fstack-check=specific,
which it refuses for any real function body, so every source file fails
to build:

  stunnel.c:1003:1: sorry, unimplemented: '-fstack-check=specific' for Thumb-1

Force the corresponding autoconf cache variable to "no" on Thumb-1, in
the same way cmocka already works around this gcc limitation, and
consistently with the existing -fstack-protector-strong override.

Fixes:
https://autobuild.buildroot.org/results/3d691184ba83ba4d881632f2b2bb4da5aa50f491/

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 15:44:54 +02:00
Bernd Kuhls
4463009364 package/vboot-utils: fix build with OpenSSL >= 3.x
Remove -Werror from CFLAGS to prevent build errors due to warnings of
deprecated functions:

futility/cmd_create.c: In function ‘vb1_make_keypair’:
futility/cmd_create.c:96:9: error: ‘PEM_read_RSAPrivateKey’ is deprecated:
 Since OpenSSL 3.0 [-Werror=deprecated-declarations]
   96 |         rsa_key = PEM_read_RSAPrivateKey(fp, NULL, NULL, NULL);

futility/cmd_create.c:155:9: error: ‘RSA_free’ is deprecated:
 Since OpenSSL 3.0 [-Werror=deprecated-declarations]
  155 |         RSA_free(rsa_key);

futility/cmd_create.c:191:17: error: ‘PEM_read_RSA_PUBKEY’ is deprecated:
 Since OpenSSL 3.0 [-Werror=deprecated-declarations]
  191 |                 rsa_key = PEM_read_RSA_PUBKEY(fp, NULL, NULL, NULL);

futility/cmd_create.c:199:9: error: ‘RSA_get0_key’ is deprecated:
 Since OpenSSL 3.0 [-Werror=deprecated-declarations]
  199 |         RSA_get0_key(rsa_key, NULL, NULL, &rsa_d);

cc1: all warnings being treated as errors

The oldest build error dates back to 2024 so a backport to LTS branches
should be considered.

Fixes:
https://autobuild.buildroot.net/results/375/37554c5ce784835a36f0068d9a0c1cd931212b44/
https://autobuild.buildroot.net/results/1fa/1fabca11c7839d2d7ed809f30482595719a29c92/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 15:43:07 +02:00
Bernd Kuhls
7253d50c82 package/jemalloc: fix build with gcc 16.x
Fixes:
https://autobuild.buildroot.net/results/6fb/6fbebb76cb0e6cafabad0890b8df226e9358a6c3/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 15:41:39 +02:00
Bernd Kuhls
c633879757 package/ibrcommon: fix build with OpenSSL 4.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 15:19:05 +02:00
Bernd Kuhls
e4d9ab154e package/ibrcommon: update patches
Replaced patch 0001 with an upstream commit.

Added Upstream: tags to patches 0002 & 0003.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 15:17:19 +02:00
Bernd Kuhls
03776c154e package/libpjsip: add support for OpenSSL 4.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 15:03:20 +02:00
Michael Nosthoff
a235a33cfe package/boost: remove dependencies on Boost.DateTime
Boost.DateTime is header-only since 1.77.0
The Boost Release Notes[0] didn't mention it but it was introduced in
the documentation of DateTime in this commit: [1]

This was bumped in buildroot in d39d8f7cee

So analog to the "header-only" move of Boost.System we have now to
gradually phase out the dependencies on this library. Ideally before
the stub is removed as it now happened for Boost.System in 1.89.0.

[0] https://www.boost.org/releases/1.77.0/
[1] 33dc6136f1

Signed-off-by: Michael Nosthoff <buildroot@heine.tech>
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 15:02:37 +02:00
Bernd Kuhls
e4253ee1a6 package/jwt-cpp: new package
Needed for domoticz >= 2025.1:
b30d9e9436

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 14:45:49 +02:00
Bernd Kuhls
861b7cb9b2 package/cc-tool: fix build with Boost >= 1.89
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 14:41:57 +02:00
Bernd Kuhls
52f813d51c package/libcpprestsdk: remove package
Quote from Github site https://github.com/microsoft/cpprestsdk
"This repository was archived by the owner on Jun 1, 2026. It is now
 read-only."

Building the package with boost >= 1.89 and OpenSSL >= 4.x is broken.
To not block these version bumps we remove this package.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 14:40:09 +02:00
Bernd Kuhls
32bf91daa7 package/heirloom-mailx: remove package
Building the package with OpenSSL 4.0.2 is broken:

openssl.c: In function 'ssl_select_method':
openssl.c:223:34: error: implicit declaration of function 'SSLv3_client_method'; did you mean 'SSLv23_client_method'? [-Wimplicit-function-declaration]
  223 |                         method = SSLv3_client_method();
      |                                  ^~~~~~~~~~~~~~~~~~~
      |                                  SSLv23_client_method
openssl.c:223:32: error: assignment to 'const SSL_METHOD *' {aka 'const struct ssl_method_st *'} from 'int' makes pointer from integer without a cast [-Wint-conversion]
  223 |                         method = SSLv3_client_method();
      |                                ^
openssl.c:225:34: error: implicit declaration of function 'TLSv1_client_method'; did you mean 'TLS_client_method'? [-Wimplicit-function-declaration]
  225 |                         method = TLSv1_client_method();
      |                                  ^~~~~~~~~~~~~~~~~~~
      |                                  TLS_client_method
openssl.c:225:32: error: assignment to 'const SSL_METHOD *' {aka 'const struct ssl_method_st *'} from 'int' makes pointer from integer without a cast [-Wint-conversion]
  225 |                         method = TLSv1_client_method();
      |                                ^
openssl.c: In function 'ssl_check_host':
openssl.c:342:59: error: invalid use of incomplete typedef 'ASN1_IA5STRING' {aka 'struct asn1_string_st'}
  342 |                                                 gen->d.ia5->data);
      |                                                           ^~
openssl.c:344:67: error: invalid use of incomplete typedef 'ASN1_IA5STRING' {aka 'struct asn1_string_st'}
  344 |                                                 (char *)gen->d.ia5->data)

openssl.c: In function 'smime_verify':
openssl.c:610:67: error: invalid use of incomplete typedef 'ASN1_IA5STRING' {aka 'struct asn1_string_st'}
  610 |                                                         gen->d.ia5->data,

Debian removed the package in 2015:
https://tracker.debian.org/news/727466/heirloom-mailx-removed-from-testing/

The last upstream release dates back to 2005:
https://sourceforge.net/projects/nail/files/nail/

Dropped BR2_TOOLCHAIN_HAS_GCC_BUG_101916 because no other uses this
option after the removal of heirloom-mailx.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Cc: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 14:31:50 +02:00
Fengwei Tan
0df986a59b board/visionfive2, configs/visionfive2: add support for v1.2a board
There are two revisions of the VisionFive 2: v1.2a and v1.3b. The main
difference between them is that v1.2a has one Gigabit Ethernet port and
one Fast Ethernet port, while v1.3b has two Gigabit Ethernet ports.

Unless explicitly set, U-Boot automatically sets $fdtfile based on the
EEPROM product data during initialization, enabling <fdtdir>/<fdtfile>
to be loaded via extlinux.conf.

Additionally, since $fdtfile contains the directory name, preserve the
directory structure of the DTBs when copying them to the target
directory.

Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 14:29:44 +02:00
Fengwei Tan
98aa14a186 configs/visionfive2: bump Linux to 6.18.51, U-Boot to 2026.07, and OpenSBI to 1.8.1
Migrate and clean up removed kernel config options during the upgrade.

Drop uboot and spl partitions from the SD card genimage configuration,
as U-Boot has deprecated the SD card and eMMC boot modes since
v2025.10 [1]. Update the rootfs block device in the kernel command line
accordingly.

Update readme.txt to reflect the new boot flow and instructions.

[1] https://docs.u-boot.org/en/v2026.07/board/starfive/visionfive2.html#zero-stage-program-loader

Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 14:29:15 +02:00
Fengwei Tan
f919aa7456 board/visionfive2: remove non-upstream Linux config options
Remove vendor-specific config options from linux_defconfig as they are
not present in the upstream kernel.

Regenerate the defconfig by running:

  make visionfive2_defconfig
  make linux-menuconfig
  # Save and exit without making any changes.
  make linux-update-defconfig

Fixes: 4567c35d06 ("configs/visionfive2: bump OpenSBI to 1.6, Linux to 6.12.24 and U-Boot to 2025.04")
Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 14:27:25 +02:00
Fengwei Tan
c6a2765091 board/visionfive2: add rootwait to kernel command line
MMC cards are detected asynchronously, so the root device may not be
available when the kernel tries to mount the root filesystem.

Add rootwait to wait for the root device and avoid a kernel panic.

Fixes: 4567c35d06 ("configs/visionfive2: bump OpenSBI to 1.6, Linux to 6.12.24 and U-Boot to 2025.04")
Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 14:27:19 +02:00
Wei Dai
69d99305e5 package/strongswan: add systemd support
When systemd is enabled, configure strongswan with --enable-systemd
and add the systemd dependency. This builds the charon-systemd IKE
daemon, which is designed for native systemd integration (using the
systemd libraries) and is managed by systemd through a service file,
with configuration handled by the swanctl backend.

Pass --disable-systemd when systemd is not selected to keep the
build deterministic.

Signed-off-by: Wei Dai <daiwei@sunkaisens.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 14:23:14 +02:00
Wei Dai
3b04245882 package/strongswan: add eap-aka-3gpp support
Add the eap-aka-3gpp plugin, an EAP-AKA backend implementing the
3GPP MILENAGE algorithms in software. Select the EAP-AKA plugin
it depends on.

Signed-off-by: Wei Dai <daiwei@sunkaisens.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 14:23:11 +02:00
Franciszek Stachura
95b1e8676c support/scripts/pkg-stats: sort latest version by state
pkg-stats columns are sorted either alphabetically or numerically. This
does not make much sense for the "Latest version" column.
This commit orders the column by whether the package is up-to-date or
not.

Signed-off-by: Franciszek Stachura <fbstachura@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 14:19:54 +02:00
Bernd Kuhls
1380791af2 package/libdeflate: bump version to 1.26
https://github.com/ebiggers/libdeflate/blob/v1.26/NEWS.md

Switched to sha256 tarball hash provided by upstream.

Depends on gcc >= 4.8 because "libdeflate now requires a C11 compiler":
a7cbb22581

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 14:09:15 +02:00
Bernd Kuhls
d1bc4bddb4 package/capnproto: fix build with OpenSSL 4.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 14:08:16 +02:00
Bernd Kuhls
8a224bc363 package/sscep: fix build with OpenSSL 4.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 13:45:14 +02:00
Bernd Kuhls
d2dc2d0c8e package/turbolua: fix build with OpenSSL 4.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 13:43:20 +02:00
Bernd Kuhls
92e08f89a8 package/libest: fix build with OpenSSL 4.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 13:35:57 +02:00
Bernd Kuhls
5f79161e4a package/llvm-project: bump version to 23.1.0
https://discourse.llvm.org/t/llvm-23-1-0-released/91654

Removed compiler-rt patch which is included in this release.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-20 12:26:02 +02:00
Bernd Kuhls
1c78e85430 package/spirv-llvm-translator: bump version to 23.1.1
https://github.com/KhronosGroup/SPIRV-LLVM-Translator/releases/tag/v23.1.1

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-20 12:26:02 +02:00
Bernd Kuhls
e073e5a559 package/spirv-{headers, tools}: bump to version 1.4.357.0
https://github.com/KhronosGroup/SPIRV-Tools/blob/vulkan-sdk-1.4.357.0/CHANGES

Removed patch which is included in this release.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-20 12:26:02 +02:00
Julien Olivain
f8bf8d928c package/bcc: bump version to 0.37.0
Changelog:
https://github.com/iovisor/bcc/blob/v0.37.0/debian/changelog

This commit removes the package patch which is included in this
new version. It also adds another upstream patch to fix the build
with the upcoming LLVM 23.

Cc: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-20 12:23:49 +02:00
Fiona Klute (othermo GmbH)
06322989a2 support/testing/tests/fs/test_squashfs.py: add test with dm-verity
This test uses the option added in the previous commits to build a
disk image with squashfs root and matching verity tree, and boots from
it. Building a kernel is necessary to get the required device-mapper
and squashfs support.

The test also serves to demonstrate usage of a verity image, more
complex setup may use an initramfs instead of dm-mod.create.

Signed-off-by: Fiona Klute (othermo GmbH) <fiona.klute@gmx.de>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-20 12:12:21 +02:00
Fiona Klute (othermo GmbH)
036f8558c4 fs/squashfs: add options to build verity tree
Signed-off-by: Fiona Klute (othermo GmbH) <fiona.klute@gmx.de>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-20 12:12:21 +02:00
Fiona Klute (othermo GmbH)
7198cea534 fs/common.mk: add optional hook to build a verity hash tree
Using dm-verity may be useful for any read-only filesystem read from a
block device, the new hook will build the required hash tree if
enabled by a per-filesystem config option.

To use this hook, the filesystem config must define a boolean option
BR2_TARGET_ROOTFS_<FS>_VERITY, and a string option
BR2_TARGET_ROOTFS_<FS>_VERITY_EXTRA_ARGS. The latter option allows
users to override veritysetup defaults, e.g. to set a fixed hash
algorithm.

In the filesystem .mk file ROOTFS_<FS>_VERITY_EXTRA_ARGS must be
defined as the value of BR2_TARGET_ROOTFS_<FS>_VERITY_EXTRA_ARGS
without surrounding quotes, because utils/check-symbols warns about
the _EXTRA_ARGS symbol being unused if fs/common.mk uses
$(qstrip $(BR2_TARGET_ROOTFS_$(2)_VERITY_EXTRA_ARGS)) directly.

Signed-off-by: Fiona Klute (othermo GmbH) <fiona.klute@gmx.de>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-20 12:12:21 +02:00
Shubham Chakraborty
8f472d08d8 package/libmpeg2: fix build with C23 compilers
libmpeg2 contains code using K&R-style empty parameter list
declarations, which no longer builds with C23 compilers.

This causes issues with:

- GCC >= 15.x, which defaults to C23

- GCC 14.x, since the bump of autoconf to 2.73 in commit
  a6e8c07a33, as it causes -std=c23 to
  be added in the CFLAGS by the autoconf machinery. This doesn't
  happen with GCC 13.

Fixes:

  http://autobuild.buildroot.net/results/53daf0b4bd8b476252ca219e53a966405ece7e51

Signed-off-by: Shubham Chakraborty <chakrabortyshubham66@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-20 12:09:01 +02:00
Antoine Gennart
c23815ad18 package/nxp-bt-wifi-firmware: bump version to lf-6.18.20-2.0.0
The IW610 module is also available with a USB host interface, while
the current package only supports its SDIO firmware. This commit
adds this USB support.

Bump the firmware release to lf-6.18.20-2.0.0, which
provides the FwImage_IW610_USB firmware, and add a dedicated
BR2_PACKAGE_NXP_BT_WIFI_FIRMWARE_IW610_USB option.

The new release also moves firmware files out of the nxp/ directory
and no longer provides 8801 or 8997 firmware. Update the installation
paths, make the existing IW610 option explicitly SDIO, and retain legacy
configuration handling for removed or renamed options.

This commit also updates the license hash, after an update from:
LA_OPT_NXP_Software_License v57 July 2024
to:
LA_OPT_NXP_Software_License v63 May 2025

Signed-off-by: Antoine Gennart <antoine.gennart@quimesis.be>
[Julien:
 - update license hash
 - fix _VERSION to use a tag rather than a branch
]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-19 21:08:24 +02:00
Antoine Gennart
0e27b1d8a4 package/nxp-mwifiex: bump version to lf-6.18.20_2.0.0
The previous version fails to build with Linux 6.13 and newer because
mlinux/moal_main.h includes the removed net/lib80211.h header.

The header was removed by Linux commit 02f220b52670 ("wifi:
ipw2x00/lib80211: move remaining lib80211 into libipw").

The new NXP release skips this obsolete header for kernels newer
than 6.12.12 and includes the corresponding Linux 6.13 cfg80211 API
compatibility fixes.

Signed-off-by: Antoine Gennart <antoine.gennart@quimesis.be>
[Julien: fix _VERSION to use a tag rather than a branch]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-19 21:08:14 +02:00
Andreas Ziegler
f667c1c206 package/libnfs: bump version to 7.0.1
Change log:
https://github.com/sahlberg/libnfs/compare/libnfs-6.0.2...libnfs-7.0.1

All patches are dropped as they are all included in 7.0.1.

Signed-off-by: Andreas Ziegler <br025@umbiko.net>
[Thomas: bump to 7.0.1]
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Tested-by: Andreas Ziegler <br025@umbiko.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-19 18:16:48 +02:00
Bernd Kuhls
7162c4daa5 package/{glibc, localedef}: security bump version to 2.44-48-g1f5026241
Fixes CVE-2026-8674:
1f50262410

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-19 14:25:34 +02:00
Bernd Kuhls
f94d8e2531 package/intel-vpl-gpu-rt: bump version to 26.3.5
https://github.com/intel/vpl-gpu-rt/releases/tag/intel-onevpl-26.3.5
https://github.com/intel/vpl-gpu-rt/compare/intel-onevpl-26.3.4...intel-onevpl-26.3.5

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-19 13:28:18 +02:00
Bernd Kuhls
6dce485ca7 package/intel-mediadriver: bump version to 26.3.5
https://github.com/intel/media-driver/releases/tag/intel-media-26.3.5

Rebased patch 0001, needed after upstream commit
04584f8839

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-19 13:28:18 +02:00
Joseph Kogut
a936a80d9e package/passt: bump to version 2026_07_28.f8df3f1
Signed-off-by: Joseph Kogut <joseph@anodize.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-19 11:24:04 +02:00
Bernd Kuhls
d6acaf91e5 package/apr-util: bump to version 1.6.5
https://archive.apache.org/dist/apr/Announcement-aprutil-1.x.html
https://archive.apache.org/dist/apr/CHANGES-APR-UTIL-1.6

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-19 11:15:21 +02:00
Manuel Diener
5a91b41f08 package/python-annotated-doc: bump to 0.0.5
See the release notes here:
https://github.com/fastapi/annotated-doc/releases/tag/0.0.5

Signed-off-by: Manuel Diener <manuel.diener@oss.othermo.de>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-19 10:44:55 +02:00
Julien Olivain
45eccf764a support/testing: test_squid: new runtime test
Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 23:51:42 +02:00
Alexis Lothoré
a304c7bf12 support/testing: add tests for openscap
Add basic tests for openscap, ensuring that it builds and runs a minimal
command with different cryptographic backends:
- libgcrypt
- libnss
- no crypto backend

Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 23:33:16 +02:00
Alexis Lothoré
c24ae7f2f1 package/openscap: allow building when crypto backend is not gcrypt
When enabling the openscap package and the libnss library _but not_
libgcrypt, the build can fail on the following error:

  ../src/libopenscap.so.33.1.3: undefined reference to `crapi_init'

The issue is due to the fact that the corresponding Makefile
systematically forces -DWITH_CRYPTO=gcrypt: openscap CMake
instrumentation then searches only this backend, fails to find it,
assumes that no crypto backend is available, and so does not include the
crapi_object in the final link step.

Commit 7c85f3adf4 ("package/openscap: new package") took into account
the fact that openscap isn't currently able to build if no crypto backend
is provided (see [0]), and so made sure to force libgcrypt inclusion if
libnss is not included. Since then, two fixes ([1] and [2]) have been
integrated upstream to allow building openscap with any backend.

Do not systematically enforce libgcrypt anymore through WITH_CRYPTO:
rather than testing nss presence, and falling back to libgcrypt, allow
both to be absent, and so relax the libgcrypt dependency to make it
optional as well. Bring the two upstream patches allowing openscap build
without any crypto backend.  Those patches can be dropped once openscap
v1.4.5 is released.

[0] https://github.com/OpenSCAP/openscap/issues/2310
[1] d12d820a94
[2] 5b858d1786

Fixes: https://autobuild.buildroot.org/results/4c905c1b0ee384149c3d85e8f2ebf0af3a12c2ad/
Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 23:31:43 +02:00
Andrea Ricchi
e44b1c4195 package/cutekeyboard: bump version to 1.7.0
Release notes: https://github.com/amarula/cutekeyboard/releases/tag/v1.7.0

Signed-off-by: Andrea Ricchi <andrea.ricchi@amarulasolutions.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 23:19:10 +02:00
Sebastian Michel
9a9ed35b56 package/sound-theme-borealis: add missing license information
Signed-off-by: Sebastian Michel <sebastian.michel@oss.othermo.de>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 22:48:02 +02:00
Thomas Petazzoni
fc5e3c8d9c package/xmlstarlet: replace += by = when appropriate
For unconditional dependencies, using += isn't useful, and our common
practice is to use a simple = assignment.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 22:45:49 +02:00
Bernd Kuhls
6fec797ebb package/xmlstarlet: bump version to 1.7.0
Upstream site switched to Github:
https://sourceforge.net/p/xmlstar/feature-requests/50/

Release notes:
https://github.com/xmlstarlet/xmlstarlet/releases/tag/1.7.0

Removed patches which are included in this release.
Instead of patch 0002 a different fix was committed upstream:
f300cd048d

Switched to pkgconf to detect libxml2/libxslt expect for static builds:
27063aa63c

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 22:30:07 +02:00
Sebastian Michel
a4346a3858 package/mali-t76x: add missing license information
Added MALI_T76X_STRIP_COMPONENTS = 0 as tar archive follows nonstandard layout with license file being in the topmost directory

Signed-off-by: Sebastian Michel <sebastian.michel@oss.othermo.de>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 22:25:07 +02:00
Bernd Kuhls
f8a1acdb6c package/swig: bump version to 4.5.1
https://www.swig.org/Release/RELEASENOTES

Added upstream sha1 & sha256 hashes.

Switched _SITE to https.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Reviewed-by: Yegor Yefremov <yegorslists@googlemail.com>
Tested-by: Fiona Klute <fiona.klute@gmx.de>  # libselinux
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 21:53:41 +02:00
Bernd Kuhls
0d3fb5c061 package/trace-cmd: fix build with swig >= 4.5.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 21:53:30 +02:00
Bernd Kuhls
f70de5ac39 package/python-pylibfdt: fix build with swig >= 4.5.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 21:53:23 +02:00
Bernd Kuhls
82b1b68a07 package/libftdi1: fix build with swig >= 4.5.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Reviewed-by: Yegor Yefremov <yegorslists@googlemail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 21:53:01 +02:00
Bernd Kuhls
46d379207d package/libcec: fix build with swig >= 4.5.0
Patch 0002 fixes the build with swig >= 4.5.0.
Patch 0001 is needed to cleanly apply patch 0002.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 21:52:53 +02:00
Bernd Kuhls
9aeb5f6f5c package/libselinux: fix build with swig >= 4.5.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Tested-by: Fiona Klute <fiona.klute@gmx.de>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 21:52:36 +02:00
Bernd Kuhls
591e6b9981 package/{, lib}apparmor: bump to version 4.1.8
https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_4.1.8
https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_4.1.7
https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_4.1.6
https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_4.1.5
https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_4.1.4
https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_4.1.3
https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_4.1.2

Switched tarballs to bz2.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 21:52:22 +02:00
Bernd Kuhls
83aefd8099 package/oprofile: fix build with binutils 2.47
Fixes build error using this defconfig:

BR2_BINUTILS_VERSION_2_47_X=y
BR2_TOOLCHAIN_BUILDROOT_CXX=y
BR2_PACKAGE_OPROFILE=y

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 21:38:58 +02:00
Thomas Petazzoni
318d4ce4e5 package/screen: install screenrc without executable rights
There is no reason to install a configuration file in /etc with
executable rights.

Fixes: https://gitlab.com/buildroot.org/buildroot/-/work_items/174
Fixes: 98873717c2 ("screen: enable terminfo and install screenrc")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 21:25:52 +02:00
Thomas Petazzoni
fbb9739dd8 package/gnuradio: show Config.in comment only when needed
The comment about the toolchain requirements to have Python support in
gnuradio is always displayed, even if architecture requirements are
not met and if Python is not enabled. For the latter: the option
BR2_PACKAGE_GNURADIO_PYTHON also depends on python, so it makes sense
for the Config.in comment to also depend on it.

Fixes: 7a546b87d5 ("package/python-numpy: add reverse dependency on packages using python-numpy")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 21:25:36 +02:00
Thomas Petazzoni
c6986e6d2e package/gnuradio: fix dependencies of BR2_PACKAGE_GNURADIO_PYTHON
BR2_PACKAGE_GNURADIO_PYTHON selects BR2_PACKAGE_PYTHON_NUMPY, so it
should inherit its dependencies, but BR2_TOOLCHAIN_GCC_AT_LEAST_9 was
forgotten in commit 8b3993178d, when
python-numpy got this gcc >= 9 dependency added.

Note that the existing BR2_HOST_GCC_AT_LEAST_9 dependency is correct:
it is there because gnuradio needs host-python-numpy at build time.

Fixes: 8b3993178d ("package/python-numpy: needs gcc >= 9")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 21:25:36 +02:00
Thomas Petazzoni
101d543e38 package/tensorflow-lite: fix Config.in comment
This commit fixes 3 issues in the Config.in comment:

- It is displayed even on unsupported CPU architectures, so we add a
  "depends on BR2_PACKAGE_TENSORFLOW_LITE_ARCH_SUPPORTS"

- It doesn't mention the need for a glibc toolchain even though that's
  part of the dependencies

- The requirement for dynamic lib support should be part of the same
  comment as the other dependencies

Fixes: fd29fee3a3 ("package/tensorflow-lite: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 21:25:29 +02:00
Thomas Petazzoni
f5a2b35531 package/tensorflow-lite: propagate libabseil-cpp dependency
BR2_PACKAGE_TENSORFLOW_LITE selects BR2_PACKAGE_LIBABSEIL_CPP without
propagating its depends on BR2_PACKAGE_LIBABSEIL_CPP_ARCH_SUPPORTS,
which this commit fixes.

Note that this doesn't create any functional change: tensorflow-lite
is anyway limited to ARM, ARM64, x86 32-bit and x86 64-bit, all of
which are supported by libabseil-cpp.

Fixes: fd29fee3a3 ("package/tensorflow-lite: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 21:25:29 +02:00
Thomas Petazzoni
0fbbe6b681 package/rpi-rgb-led-matrix: propagate ffmpeg dependency
BR2_PACKAGE_RPI_RGB_LED_MATRIX_VIDEO_VIEWER selects
BR2_PACKAGE_FFMPEG, but without propagating its depends on, and most
notably BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS.

Fixes: e821078031 ("package/rpi-rgb-led-matrix: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 21:25:16 +02:00
Thomas Petazzoni
56cdcb8206 package/opencv4: update gcc version dependency related to protobuf
Another instance of libaseil-cpp requiring gcc >= 10, which means
protobuf needs >= 10, and that wasn't propagated to all reverse
dependencies of protobuf, in this commit: opencv4.

Fixes: 76241e89e1 ("package/libabseil-cpp: bump to version 20260817.0")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 21:25:09 +02:00
Thomas Petazzoni
93282f76a5 package/libgtk3: add missing !BR2_STATIC_LIBS dependency
libgtk3 selects at-spi2-core, so it should inherit its
!BR2_STATIC_LIBS, which this commit does.

This has been an issue since libgtk3 started using at-spi2-core
instead of atk in commit 2c3ca7bea1.

Fixes: 2c3ca7bea1 ("package/atk: remove package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 21:24:57 +02:00
Giulio Benetti
a3164c837e package/rpcbind: bump version to 1.3.1
Changelog:
https://sourceforge.net/projects/rpcbind/files/rpcbind/1.3.1/1.3.1-Changelog/download

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 21:07:53 +02:00
Giulio Benetti
e59900428f package/libtirpc: bump to version 1.3.8
Changes 1.3.7..1.3.8:

b2a58e4 Release 1.3.8
65d2745 libtirpc: Bound maxsize in xdr_rpc_gss_unwrap_data() decode calls
ccc1acf libtirpc: limit XDR decode node count
9c15036 libtirpc: Fix use-after-free in xdr_pmaplist() XDR_FREE path
01796f8 libtirpc: fix rpc_gss_get_principal_name to allocate memory correctly
468d4e6 Add missing exports for rpc_gss_getcred + authdes_getucred

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 21:07:38 +02:00
Bernd Kuhls
458441ad76 package/ghostscript: security bump to version 10.08.0
https://ghostscript.readthedocs.io/en/gs10.08.0/News.html
"This release addresses a number of potential security issues."

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 20:48:35 +02:00
Bernd Kuhls
9c0385972d package/ghostscript: link with libatomic if needed
Fixes:
https://autobuild.buildroot.net/results/eed/eed88a2a77cb8c4ff8c59bac5091221e6873004c/

The build error occurs since 2024 so a backport to LTS branches should
be considered:
https://autobuild.buildroot.net/results/1ab/1ab4767c1198838c3e3d126cdba790197d102053/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 20:48:35 +02:00
Thomas Devoogdt
55cec1d013 package/libsoup3: bump to 3.7.3
News:
- https://download.gnome.org/sources/libsoup/3.7/libsoup-3.7.1.news
- https://download.gnome.org/sources/libsoup/3.7/libsoup-3.7.2.news
- https://download.gnome.org/sources/libsoup/3.7/libsoup-3.7.3.news

Add zstd support which was added upstream:
579ff56747

Signed-off-by: Thomas Devoogdt <thomas@devoogdt.com>
Reviewed-by: Adrian Perez de Castro <aperez@igalia.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 19:41:25 +02:00
Thomas Devoogdt
d24f5fcc20 package/lighttpd: bump to 1.4.85
See here for changes:
https://www.lighttpd.net/2026/07/08/1.4.85/

Signed-off-by: Thomas Devoogdt <thomas@devoogdt.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 19:41:25 +02:00
Bernd Kuhls
098be4f99a package/unbound: security bump version to 1.26.1
https://nlnetlabs.nl/projects/unbound/download/#unbound-1-26-1

Fixes CVE-2026-81642, CVE-2026-81634, CVE-2026-82717, CVE-2026-77955,
CVE-2026-78227, CVE-2026-80225, CVE-2026-82720, CVE-2026-85501 &
CVE-2026-77860.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 18:56:05 +02:00
Bernd Kuhls
267db9da2b package/exim: security bump version to 4.100.1
https://lists.exim.org/lurker/message/20260918.121220.0f87338e.en.html

Contains the following security fixes:

* GCVE-25-2026-09-50-1
* GCVE-25-2026-09-51-1
* GCVE-25-2026-09-55-1
* GCVE-25-2026-09-56-1

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 18:44:07 +02:00
Laszlo Ersek
86a56dcc17 linux/linux.mk: forcibly (re)enable Make jobserver for linux-rebuild-with-initramfs target
Commit 0b9efc991f ("linux: use BR2_MAKE", 2023-04-10) replaced $(MAKE)
with $(BR2_MAKE) in a number of recipes. As a consequence, the child
make is unable to discover the job server, in some cases. In those
cases, we get a warning such as:

> warning: jobserver unavailable: using -j1. Add `+' to parent make rule.

See [1] and [2].

Falling back to single job can make build considerably longer.
This longer build time issue can be reproduced in specific
conditions. This situation happens when:

1. The top GNU Make is using a "pipe" jobserver.
   This is the default when GNU Make <= 4.3 is used (and v4.3 is the
   version inside the current Buildroot Docker reference image).
   Make > 4.3 changed the default jobserver style to "fifo".
   See [3][4]. With Make > 4.3, the issue can be reproduced by
   calling "make --jobserver-style=pipe ...".
2. The root filesystem is an initramfs linked into the Kernel
  (i.e. using the config BR2_TARGET_ROOTFS_INITRAMFS=y)
3. Buildroot per-package directories is used
  (i.e. using the config BR2_PER_PACKAGE_DIRECTORIES=y)
4. The build is made in parallel, with 2 or more jobs. For example:
   make -j$(nproc)

Overall, the issue can be reproduced with the commands:

utils/docker-run
cat >.config <<EOF
BR2_aarch64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_PER_PACKAGE_DIRECTORIES=y
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_USE_ARCH_DEFAULT_CONFIG=y
BR2_TARGET_ROOTFS_INITRAMFS=y
EOF
make olddefconfig
make -j$(nproc)

The Linux Kernel is built once (with a fake empty initramfs cpio
image), when build log is showing ">>> linux 7.2.6 Building". Then,
at the end of the Buildroot build, once the CPIO filesystem is
complete, it is integrated inside the Kernel with an extra "make"
invocation when the build log shows
">>>   Rebuilding kernel with initramfs".

This second kernel "make" is not expected to rebuild the whole
kernel, since compiled objects from the first compilation are still
here. However, in the described conditions, the second kernel is
fully rebuilt. This is an undesired behaviour. The Make jobserver
issue adds up to that: this second full kernel is rebuilt with only
one job, which can significantly increase the build time.

Running the previous example on a host with 128 CPUs:
without this change, build takes 1h5m,
with this change, build takes 7m.

Note: using GNU Make >= 4.4 (with a fifo jobserver style by default)
or removing per-package directories no longer produces the issue.
For reference, running the example, without this change and without
per-package directories on the same host, the build takes 10 mins.

This commit improves the situation by prefixing the recipe with "+",
to inform the parent Make that $(BR2_MAKE) can deal with the job
server. This will give a chance to do jobs in parallel, in general.

Note: the pkg-generic.mk infra already has '+' for _BUILD_CMDS, which is
why other $(BR2_MAKE) invocations in linux.mk does not need this '+'.
See [5].

[1] https://www.gnu.org/software/make/manual/html_node/Error-Messages.html
[2] https://www.gnu.org/software/make/manual/html_node/MAKE-Variable.html
[3] https://www.gnu.org/software/make/manual/html_node/Options-Summary.html#index-_002d_002djobserver_002dstyle
[4] https://cgit.git.savannah.gnu.org/cgit/make.git/commit/?id=7ad2593b2d2bb5b9332f4444d8bf93ac6f958bc6
[5] 069b33a30e

Cc: Arnout Vandecappelle <arnout@mind.be>
Cc: Oleg Lyovin <ovlevin@sberdevices.ru>
Cc: buildroot@buildroot.org
Signed-off-by: Laszlo Ersek <laszlo.ersek@arm.com>
[Julien: extend commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 13:56:11 +02:00
Thomas Perale
72cb1abbcd docs/website: add Texas Instrument as a gold sponsor
Texas Instrument is a semiconductor company that designs, manufactures
and sells analog and embedded processing chips for markets such as
industrial, automotive, personal electronics, enterprise systems and
communications equipment [1][2].

Thank you for sponsoring LTS maintenance !

[1] https://www.ti.com/
[2] https://www.linkedin.com/company/texas-instruments

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-18 13:38:13 +02:00
Bernd Kuhls
35fdb41610 package/cog: fix build with weston 16.x
Buildroot commit c5c0a76751 bumped weston
to 16.0.0 causing a configure error with cog:

Run-time dependency libweston-15-protocols found: NO  (tried pkg-config)
Run-time dependency libweston-14-protocols found: NO  (tried pkg-config)
Run-time dependency libweston-13-protocols found: NO  (tried pkg-config)
Run-time dependency libweston-12-protocols found: NO  (tried pkg-config)
Run-time dependency libweston-11-protocols found: NO  (tried pkg-config)
Run-time dependency libweston-10-protocols found: NO  (tried pkg-config)
Run-time dependency libweston-9-protocols found: NO  (tried pkg-config)
Run-time dependency libweston-8-protocols found: NO  (tried pkg-config)

output/build/cog-0.18.5/platform/wayland/meson.build:67:8: ERROR:
 Problem encountered: No usable weston-protocols dependency found

This error was not yet found by the autobuilders and is solved by adding
a patch James Hilliard sent upstream.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 09:37:54 +02:00
Yegor Yefremov
d4c13e96cf package/python-grpcio: disable for the MIPS n32 ABI
python-grpcio builds its own bundled copy of abseil-cpp, which only
implements DirectMmap() with mmap2 for the o32 ABI on MIPS:

    #if ... (defined(__mips__) && _MIPS_SIM == _MIPS_SIM_ABI32) || ...

With the n32 ABI, the "remaining 64-bit architectures" fallback is
selected instead, which fails to build because long is 32-bit there:

    third_party/abseil-cpp/absl/base/internal/direct_mmap.h:130:39:
        error: static assertion failed: Platform is not 64-bit
      130 |   static_assert(sizeof(unsigned long) == 8, "Platform is not 64-bit");
          |                 ~~~~~~~~~~~~~~~~~~~~~~^~~~
    third_party/abseil-cpp/absl/base/internal/direct_mmap.h:130:39:
        note: the comparison reduces to '(4 == 8)'

This is the same defect fixed for libabseil-cpp in the previous patch,
but the dependency added there does not help here: python-grpcio does
not use the Buildroot abseil, it compiles the copy bundled in the
tarball.

Using the Buildroot-provided abseil instead is not an option today.
setup.py does have a GRPC_PYTHON_BUILD_SYSTEM_ABSL knob, but it is
hardcoded to the build machine paths:

    if BUILD_WITH_SYSTEM_ABSL:
        CORE_C_FILES = filter(
            lambda x: "third_party/abseil-cpp" not in x, CORE_C_FILES
        )
        ABSL_INCLUDE = (os.path.join("/usr", "include"),)
    [...]
    if BUILD_WITH_SYSTEM_ABSL:
        EXTENSION_LIBRARIES += tuple(
            lib.stem[3:]
            for lib in sorted(pathlib.Path("/usr").glob("lib*/libabsl_*.so"))
        )

i.e. it would pick up the host headers and host libraries, so it cannot
be used when cross-compiling without patching setup.py. And even with
such a patch it would not fix this build failure, since Buildroot's
abseil has the very same limitation.

So just disable the package for the n32 ABI. The o32 and n64 ABIs are
unaffected. Note that n32 is the default ABI for BR2_mips64/BR2_mips64el,
so this affects every mips64 build that does not explicitly select n64.

For the LTS maintainers: python-grpcio gained MIPS support in commit
2bfad952c3, released in 2024.02, and the autobuilders have been hitting
this ever since, already with grpcio 1.60.0, the version shipped in
2024.02:

    https://autobuild.buildroot.net/results/e6cb7f473a28af8b53e7cbb8d8a582adffdeb66e/

It is still reproduced on 2025.02.x:

    https://autobuild.buildroot.net/results/9cf98bff7ce05262d6ff4221953901ae5543880e/

so a backport is needed there.

Fixes: 2bfad952c3 ("package/python-grpcio: add BR2_PACKAGE_PYTHON_GRPCIO_ARCH_SUPPORTS")
Fixes:
https://autobuild.buildroot.net/results/90405c0a3d0b2e929d5074305906e6fe3679298c/

Assisted-by: Claude:claude-opus-5
Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 09:36:08 +02:00
Yegor Yefremov
263cfb165e package/libabseil-cpp: disable for the MIPS n32 ABI
absl::base_internal::DirectMmap() only implements mmap() via mmap2 for
the o32 ABI on MIPS:

    #if ... (defined(__mips__) && _MIPS_SIM == _MIPS_SIM_ABI32) || ...

With the n32 ABI, the "remaining 64-bit architectures" fallback is
selected instead, which fails to build because long is 32-bit there:

    absl/base/internal/direct_mmap.h: In function 'void* absl::lts_20260107::base_internal::DirectMmap(void*, size_t, int, int, int, off_t)':
    absl/base/internal/direct_mmap.h:130:39: error: static assertion failed: Platform is not 64-bit
      130 |   static_assert(sizeof(unsigned long) == 8, "Platform is not 64-bit");
          |                 ~~~~~~~~~~~~~~~~~~~~~~^~~~
    absl/base/internal/direct_mmap.h:130:39: note: the comparison reduces to '(4 == 8)'

direct_mmap.h is included by absl/base/internal/low_level_alloc.cc and
absl/base/internal/poison.cc, which are always built, so the failure is
unconditional. Upstream abseil has no support for the n32 ABI, so
disable the package for that ABI.

Since n32 is the default ABI for BR2_mips64/BR2_mips64el, this affects
every mips64 build that does not explicitly select n64. The o32
(BR2_MIPS_OABI32) and n64 (BR2_MIPS_NABI64) ABIs are unaffected, and all
in-tree mips64 defconfigs use n64.

For the LTS maintainers: the ABI list in direct_mmap.h is identical in
abseil 20200225 (the version in tree when the arch dependencies were
introduced) and in the current 20260817.0, so the failure has existed
ever since mips64 was allowed. It is still reproduced on all maintained
branches, e.g.:

    2026.02.x https://autobuild.buildroot.net/results/5818407a73cfd3371cd1f726a24df6ceb9afa42d/
    2025.02.x https://autobuild.buildroot.net/results/5065bda3b91bdbee53559dd97af8ab5a63a1e112/

so a backport is needed there.

Fixes: ae0557403a ("package/libabseil-cpp: add BR2_PACKAGE_LIBABSEIL_CPP_ARCH_SUPPORTS")
Fixes:
https://autobuild.buildroot.net/results/f375584f3721d61238b9e43d9926e037802f6141/

Assisted-by: Claude:claude-opus-5
Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 09:36:06 +02:00
Yegor Yefremov
4dc8e8b6f9 package/cannelloni: security bump to version 2.1.2
For change log, see:

https://github.com/mguentner/cannelloni/releases/tag/v2.0.1
https://github.com/mguentner/cannelloni/releases/tag/v2.1.0
https://github.com/mguentner/cannelloni/releases/tag/v2.1.1
https://github.com/mguentner/cannelloni/releases/tag/v2.1.2

2.1.2 fixes CVE-2026-37539 (CVSS 3.1 score 9.8, CWE-121): a stack based
buffer overflow in CAN frame parsing, in parseCANFrame() in parser.cpp
and decodeFrame() in decoder.cpp, allowing remote attackers to cause a
denial of service (crash) or possibly execute arbitrary code via
crafted CAN FD frames.

The advisory names v2.0.0 explicitly, so the version used so far is
affected. The CVE is not reported by
https://security.buildroot.org/master/component/cannelloni because its
NVD entry has no CPE data (vendor and product are both "n/a") and can
therefore not be matched against the package version.

Apart from the security fix, 2.0.0..2.1.2 contains only a handful of
changes: undeliverable frames are dropped after a timeout on a broken
CAN bus, variable length arrays are gone, the default remote address is
fixed, and pthreads are looked up with the CMake module instead of by
hand. 2.1.1 is a maintenance release only, as the 2.1.0 tag pointed to
a commit that was not the final one.

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 09:35:24 +02:00
Thomas Devoogdt
c337b249bf package/libsrtp: bump to 2.8.0
https://github.com/cisco/libsrtp/releases/tag/v2.8.0

Signed-off-by: Thomas Devoogdt <thomas@devoogdt.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-18 09:33:18 +02:00
Bernd Kuhls
2ca7fb5e7b package/wpewebkit: fix build with CMake 4.4
Buildroot commit 526f8b43ed bumped CMake
from 4.3.4 to 4.4.0 causing a configure error with this package:

CMake Error at Source/cmake/WebKitMacros.cmake:311 (if):
  if given arguments:

    "(" "NOT" "_linked_into" ")" "OR" "(" "WTF" "STREQUAL" ")" "OR" "("
 "NOT" "IN_LIST" "LLIntSettingsExtractor_FRAMEWORKS" ")"

  Unknown arguments specified
Call Stack (most recent call first):
  Source/cmake/WebKitMacros.cmake:393 (_WEBKIT_TARGET_LINK_FRAMEWORK)
  Source/JavaScriptCore/CMakeLists.txt:409 (WEBKIT_EXECUTABLE)

The error can be reproduced with this defconfig:

BR2_x86_64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_FORCE_HOST_BUILD=y
BR2_PACKAGE_MESA3D=y
BR2_PACKAGE_MESA3D_GALLIUM_DRIVER_SOFTPIPE=y
BR2_PACKAGE_MESA3D_OPENGL_EGL=y
BR2_PACKAGE_MESA3D_OPENGL_ES=y
BR2_PACKAGE_WPEWEBKIT=y
BR2_PACKAGE_WPEWEBKIT_SANDBOX=y
BR2_PACKAGE_WPEWEBKIT_MULTIMEDIA=y
BR2_PACKAGE_WPEWEBKIT_MEDIA_STREAM=y
BR2_PACKAGE_WPEWEBKIT_WEBDRIVER=y

To fix the problem we add an upstream commit.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-17 17:10:35 +02:00
Yegor Yefremov
22c0ec4fcf package/qemu: host-qemu does not support XOP capable CPUs
Commit 1f7efaf89f ("package/qemu: do not support x86_steamroller or
x86_core_avx2") excluded BR2_x86_steamroller from
BR2_PACKAGE_HOST_QEMU_ARCH_SUPPORTS. This is still needed, but for a
different reason than AVX, and the exclusion is incomplete.

steamroller is bdver3, and what the Qemu TCG engine cannot emulate
there is not AVX, but the Bulldozer-specific XOP, FMA4, TBM and LWP
extensions. In Qemu 11.0.0 (the version we currently package) and
11.1.1, target/i386/cpu.c has:

  #define TCG_EXT3_FEATURES (CPUID_EXT3_LAHF_LM | CPUID_EXT3_SVM | \
            CPUID_EXT3_CR8LEG | CPUID_EXT3_ABM | CPUID_EXT3_SSE4A | \
            CPUID_EXT3_3DNOWPREFETCH | CPUID_EXT3_KERNEL_FEATURES | \
            CPUID_EXT3_CMP_LEG)

CPUID_EXT3_XOP, CPUID_EXT3_FMA4, CPUID_EXT3_TBM and CPUID_EXT3_LWP are
defined in target/i386/cpu.h, but are not part of that mask, i.e. TCG
does not implement them. Binaries using those instructions therefore
die with:

  qemu: uncaught target signal 4 (Illegal instruction) - core dumped

This affects the whole Bulldozer family, not only steamroller:
bulldozer (bdver1), piledriver (bdver2) and excavator (bdver4) are
equally unsupported, but were never excluded.

Use the newly introduced BR2_X86_CPU_HAS_XOP symbol, which covers all
four variants, instead of listing BR2_x86_steamroller alone. As for
AVX512, this disables gobject-introspection and nodejs, which are the
two packages needing host-qemu in user mode.

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-17 11:13:17 +02:00
Yegor Yefremov
f91407f012 arch/Config.in.x86: add BR2_X86_CPU_HAS_XOP
The AMD Bulldozer family (bdver1 to bdver4, i.e. bulldozer, piledriver,
steamroller and excavator) is the only x86 family implementing the XOP
instruction set, together with the equally Bulldozer-specific FMA4 and
LWP extensions, and TBM starting with bdver2. All of them were dropped
again with Zen.

This can be verified with:

  $ gcc -march=bdver1 -Q --help=target | grep -E '\-m(xop|fma4|tbm|lwp)'
    -mfma4      [enabled]
    -mlwp       [enabled]
    -mtbm       [disabled]
    -mxop       [enabled]

  $ gcc -march=bdver2 -Q --help=target | grep -E '\-m(xop|fma4|tbm|lwp)'
    -mfma4      [enabled]
    -mlwp       [enabled]
    -mtbm       [enabled]
    -mxop       [enabled]

with bdver3 and bdver4 behaving like bdver2.

Add a hidden BR2_X86_CPU_HAS_XOP capability symbol and select it from
those four CPU variants, so that packages which cannot cope with this
instruction set can depend on it, instead of listing the CPU variants
one by one. The first user is host-qemu, whose TCG engine does not
implement XOP.

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-17 11:13:10 +02:00
Yegor Yefremov
8d80efe017 package/qemu: drop x86_core_avx2 exclusion
Commit 1f7efaf89f ("package/qemu: do not support x86_steamroller or
x86_core_avx2") excluded BR2_x86_core_avx2 from
BR2_PACKAGE_HOST_QEMU_ARCH_SUPPORTS because binaries built for that CPU
variant crashed under qemu-user. This was done at the time of Qemu 4.2,
whose TCG engine did not implement AVX at all.

Since Qemu 7.2, the TCG engine implements AVX, AVX2, F16C, FMA3 and
VAES. In Qemu 11.0.0 (the version we currently package) and 11.1.1,
target/i386/cpu.c has:

  #define TCG_EXT_FEATURES (... | CPUID_EXT_AVX | CPUID_EXT_F16C | \
            CPUID_EXT_FMA | ...)
  #define TCG_7_0_EBX_FEATURES (... | CPUID_7_0_EBX_BMI1 | \
            CPUID_7_0_EBX_BMI2 | CPUID_7_0_EBX_AVX2 | ...)

which covers everything gcc generates for -march=core-avx2.

In addition, the exclusion was inconsistent: gcc's core-avx2 is a
deprecated alias for haswell, both variants select exactly the same
BR2_X86_CPU_HAS_* symbols in arch/Config.in.x86, and haswell was never
excluded. The same goes for broadwell, skylake, zen*, x86-64-v3, ...,
which all enable AVX2 and build fine on the autobuilders.

So drop the BR2_x86_core_avx2 exclusion.

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-17 11:13:07 +02:00
Bernd Kuhls
feb628adb0 package/lttng-tools: remove unneeded patch
Upstream added the configure option --enable-tests with commit
6ba949601d
which was first released in version 2.15.0.

While bumping the package from 2.14.0 to 2.16.0 with buildroot commit
edd3a015cd this new option was not taken
into consideration. We can therefore now remove our own patch to
implement this configure option.

Renumbered remaining patch.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-17 09:45:41 +02:00
Joachim Wiberg
bdf4dc05c5 package/mdnsd: bump to version 1.2
- Add support for running as an uprivileged user
 - Fix undefined behavior when caching malformed records

Release notes: https://github.com/troglobit/mdnsd/releases/tag/v1.2

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-17 09:43:24 +02:00
Joachim Wiberg
b1708d7055 package/mg: bump to version 4.1
Adds double-width UTF-8 rendering with Unicode 17 character widths,
a new line-wrap-mode, shift-PgUp/PgDn selection, and yaml, text,
git-commit, diff, conf and makefile modes with syntax highlighting.
Fixes shifted-key selection in VTE terminals built --without-curses
and several ~/.mg startup file bugs.

Release notes: https://github.com/troglobit/mg/releases/tag/v4.1

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-17 09:43:14 +02:00
Alexander Shirokov
e38f9b9f96 package/broot: bump to version 1.60.1
Changelog: https://github.com/Canop/broot/blob/v1.60.1/CHANGELOG.md

Signed-off-by: Alexander Shirokov <shirokovalexs@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-17 08:37:52 +02:00
Bernd Kuhls
b016989c61 package/ibm-sw-tpm2: fix build with gcc-15.x
Fixes:
https://autobuild.buildroot.net/results/d43/d4364f6e3636c696471bf8cba6d308439130e53a/

In function 'MakeIv',
    inlined from 'TestSymmetricAlgorithm' at AlgorithmTests.c:197:25:
AlgorithmTests.c:181:23: error: writing 32 bytes into a region of size
 16 [-Werror=stringop-overflow=]

The build error occurs with gcc 15.x on some platforms, gcc 14.x is not
affected.

These defconfigs build without this patch:

BR2_x86_64=y
BR2_GCC_VERSION_14_X=y
BR2_PACKAGE_IBM_SW_TPM2=y

BR2_x86_64=y
BR2_x86_x86_64_v4=y
BR2_GCC_VERSION_14_X=y
BR2_PACKAGE_IBM_SW_TPM2=y

BR2_x86_64=y
BR2_PACKAGE_IBM_SW_TPM2=y

This gcc-15 based defconfig is broken:

BR2_x86_64=y
BR2_x86_x86_64_v4=y
BR2_PACKAGE_IBM_SW_TPM2=y

The build error is not related to the recent bump of the package from
rev183-2024-03-27 to rev183-2026-08-26 because no changes were committed
upstream to AlgorithmTests.c since rev183-2024-03-27:
https://github.com/kgoldman/ibmswtpm2/commits/master/src/AlgorithmTests.c

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-17 08:36:15 +02:00
Bernd Kuhls
ea18394dd7 package/sofia-sip: needs OpenSSL
Buildroot commit bb254e2304 bumped the
package to version 1.13.18 which includes upstream commit
8081a1a6d0
that added the unconditional usage of OpenSSL.

Tested with both LibreSSL and OpenSSL, the latter with all suboptions
disabled.

Fixes:
https://autobuild.buildroot.net/results/afe/afe7b327f12db86e4dc31ecc25b576bff5c4a0bb/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-17 08:34:51 +02:00
Andreas Vida
a7acedfeeb package/cups: install D-Bus config file cups.conf
When CUPS is built with D-Bus enabled,
install cups.conf under /usr/share/dbus-1/system.d
as it already happens in other packages that have D-Bus configs
e.g. dnsmasq, wpa_supplicant etc.

Signed-off-by: Andreas Vida <andreas.vida@ginzinger.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 23:41:48 +02:00
Raphaël Mélotte
b7cfa2371b package/fcft: use release tarball instead of archive
Codeberg has changed the way it generate hashes for at least some of
the generated tarballs (see [1]).

This change affects tarballs generated by Codeberg, but not release
artifacts.
fcft turns out to have a proper release available, so use it.

[1]: https://codeberg.org/Codeberg/Community/issues/2861

Fixes:

  https://autobuild.buildroot.net/results/6792109a982924f4cf2b8bcc9a2ac7c12f5ddc55/

Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 23:34:08 +02:00
Julien Olivain
9f3797e342 support/testing: test_erlang: new runtime test
Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 23:27:36 +02:00
Giulio Benetti
ab8471868e package/rtl8812au-aircrack-ng: enable additional kernel config option
Not all Linux defconfigs have CONFIG_INET enabled and this results in:
  LD [M]  88XXau.o
  MODPOST Module.symvers
ERROR: modpost: "register_inetaddr_notifier" [88XXau.ko] undefined!
ERROR: modpost: "unregister_inetaddr_notifier" [88XXau.ko] undefined!

So let's add CONFIG_INET to LINUX_CONFIG_FIXUPS.

Fixes:
https://autobuild.buildroot.org/results/6b4f17518e049a91a36be74c78cb8cde89b73bb3/

Fixes: 003ed345b1 ("package/rtl8812au-aircrack-ng: fix build failure due to double defined endianness")
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 23:13:17 +02:00
Bernd Kuhls
7e34cd7c7e package/libest: needs OpenSSL engines
Fixes build error:

In file included from client.c:14:
client.c: In function 'JNI_OnLoad':
./../../src/est/est.h:834:10: error: implicit declaration of function 'ERR_load_crypto_strings'; did you mean 'ERR_load_CRYPTO_strings'? [-Wimplicit-function-declaration]
  834 |     do { ERR_load_crypto_strings();      \
      |          ^~~~~~~~~~~~~~~~~~~~~~~
client.c:88:9: note: in expansion of macro 'est_apps_startup'
   88 |         est_apps_startup();
      |         ^~~~~~~~~~~~~~~~
./../../src/est/est.h:836:10: error: implicit declaration of function 'ENGINE_load_builtin_engines' [-Wimplicit-function-declaration]
  836 |          ENGINE_load_builtin_engines();  \
      |          ^~~~~~~~~~~~~~~~~~~~~~~~~~~
client.c:88:9: note: in expansion of macro 'est_apps_startup'
   88 |         est_apps_startup();
      |         ^~~~~~~~~~~~~~~~
client.c: In function 'JNI_OnUnload':
./../../src/est/est.h:860:40: error: implicit declaration of function 'ENGINE_cleanup'; did you mean 'EVP_PBE_cleanup'? [-Wimplicit-function-declaration]
  860 |          OBJ_cleanup(); EVP_cleanup(); ENGINE_cleanup(); \
      |                                        ^~~~~~~~~~~~~~
client.c:101:9: note: in expansion of macro 'est_apps_shutdown'
  101 |         est_apps_shutdown();
      |         ^~~~~~~~~~~~~~~~~
./../../src/est/est.h:862:10: error: implicit declaration of function 'ERR_free_strings'; did you mean 'ERR_load_EC_strings'? [-Wimplicit-function-declaration]
  862 |          ERR_free_strings(); } while (0)
      |          ^~~~~~~~~~~~~~~~
client.c:101:9: note: in expansion of macro 'est_apps_shutdown'
  101 |         est_apps_shutdown();
      |         ^~~~~~~~~~~~~~~~~
client.c: In function 'est_client_raise_exception':
client.c:122:17: error: implicit declaration of function 'ERR_print_errors_fp' [-Wimplicit-function-declaration]
  122 |                 ERR_print_errors_fp(stderr);
      |                 ^~~~~~~~~~~~~~~~~~~

seen with this defconfig

BR2_PACKAGE_OPENJDK=y
BR2_PACKAGE_LIBEST=y

The failing code was added upstream on Jul, 6th, 2020:
ab998c0918
and included in version 3.2.0.

Buildroot commit 5bbb1834a4 bumped the
package to a tree including the aforementioned upstream commit on Jul
24th, 2022 so a backport to LTS branches should be considered.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 23:03:52 +02:00
Bernd Kuhls
8b009489f5 package/exim: bump version to 4.100
https://lists.exim.org/lurker/message/20260820.154633.91995f73.en.html

Rebased patch 0001.

Updated patch 0005, the previous version was applied upstream with
commit 497e9eb7e77ad27ae1d45281e23eefadfaa7a3bc but it did not fix all
linker errors so we sent a new patch upstream which replaces the
previous patch.

Updated hash of GPL-2.0 license file (address, name of president and
typos), a commit can not be provided from the source tree.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 23:01:56 +02:00
Bernd Kuhls
6c4abe552f package/exim: disable valgrind when building with thumb1
src/valgrind.h contains inline asm not compatible with thumb1 so we
disable valgrind support for thumb1.

Fixes:
https://autobuild.buildroot.org/results/720bfa00ca926a398e901366e7ab20d08cfa9a81/

Inspired by buildroot commit 26013972ce.

The oldest build error of this kind dates back to 2022
https://autobuild.buildroot.net/results/85d/85d8e725a31bc1a3c41b2e388a17ff439274d437/
so a backport to LTS branches should be considered.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Reviewed-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Tested-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 23:01:51 +02:00
Fengwei Tan
0bf4525045 support/testing: add FLAT stack size test case
Add an infrastructure test case to verify that the per-package
<PKG>_FLAT_STACKSIZE variable correctly configures the stack size in the
generated FLAT binary header.

Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 22:44:49 +02:00
Bernd Kuhls
6c781be506 package/bind: security bump version to 9.20.29
https://downloads.isc.org/isc/bind9/9.20.29/doc/arm/html/notes.html#notes-for-bind-9-20-28
"The BIND 9.20.28 release was withdrawn after the discovery of a
 regression in it during pre-release testing."

https://downloads.isc.org/isc/bind9/9.20.29/doc/arm/html/notes.html#notes-for-bind-9-20-29
https://downloads.isc.org/isc/bind9/9.20.29/doc/arm/html/changelog.html
https://seclists.org/oss-sec/2026/q3/801

Fixes CVE-2026-19033, CVE-2026-19662, CVE-2026-19666, CVE-2026-19667,
CVE-2026-19668, CVE-2026-19941, CVE-2026-75029, CVE-2026-76163,
CVE-2026-77119, CVE-2026-77692, CVE-2026-78301, CVE-2026-80274,
CVE-2026-81563 & CVE-2026-81736.

Raise the minimum gcc version to 8 to fix a build error found by the
Gitlab pipelines which would be introduced by this bump due to upstream
commit:
a891e74233

opensslrsa_link.c:53:51: error: initializer element is not constant
 static const unsigned int rsa_max_modulus_bytes = (rsa_max_modulus_bits + 7) /

make[1]: *** [package/pkg-generic.mk:273:
 /builds/bkuhls/buildroot/br-test-pkg/bootlin-aarch64-glibc-old/build/bind-9.20.29/.stamp_built]
 Error 2

According to https://stackoverflow.com/a/67000730 the code needs gcc 8.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 22:39:26 +02:00
Bernd Kuhls
96ac57460f package/bind: fix Config.in comment
The comment should be shown when !BR2_INSTALL_LIBSTDCPP is true, also
treat BR2_PACKAGE_LIBURCU_ARCH_SUPPORTS as arch dependency.

Fixes: 54f96add94 ("package/bind: security  bump version to 9.20.24")
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 22:38:32 +02:00
Francois Perrad
5ab14b940a package/luv: bump to version 1.52.1-0
Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 22:09:25 +02:00
Francois Perrad
b424201cc0 package/luasyslog: bump to version 2.2.2
Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 22:09:22 +02:00
Francois Perrad
2d7e810f73 package/lua-lunix: fix build with gcc >= 15
Fixes:

  https://autobuild.buildroot.org/results/7fba1da21af93a7a0431fb9431dc3c8e872a00ac

Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 22:04:09 +02:00
Bernd Kuhls
26122fd02e package/libest: bump version to r3.2.0-9-ga464ba8a6
The only commit in this bump
https://github.com/cisco/libest/commits/main/
is patch 0005 which was removed.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 21:48:33 +02:00
Bernd Kuhls
2e1e3b5e09 package/libest: fix build with gcc >= 14.x
Renumbered remaining patches.

Fixes:
https://autobuild.buildroot.net/results/149/149aad6f98163faab14232a9d3013c197579cbb4/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 21:48:08 +02:00
Bernd Kuhls
60dc97fcee package/qt5/qt5webengine-chromium: fix build with glibc >= 2.43
No autobuilder errors were recorded, the build error can be reproduced
with this defconfig:

BR2_x86_64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
BR2_PACKAGE_MESA3D=y
BR2_PACKAGE_MESA3D_GALLIUM_DRIVER_SOFTPIPE=y
BR2_PACKAGE_MESA3D_OPENGL_GLX=y
BR2_PACKAGE_MESA3D_OPENGL_EGL=y
BR2_PACKAGE_QT5=y
BR2_PACKAGE_QT5WEBENGINE=y
BR2_PACKAGE_XORG7=y

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 21:26:50 +02:00
Bernd Kuhls
cd6291f7c9 package/tpm2-openssl: bump version to 1.3.0
https://github.com/tpm2-software/tpm2-openssl/releases/tag/1.3.0

Update license hash due to copyright year bump:
3fb3a5ff7f

Pass -Wno-error to make sure warnings are not treated as errors, to
workaround the fact that -Werror is pasedd by the build system since
upstream commit
c3a8758cad
first included in this release.

This fixes a build error seen with the Gitlab pipelines for
bootlin-aarch64-glibc-old:

src/tpm2-provider-encoder.c:
 In function ‘tpm2_rsa_encoder_encode_SubjectPublicKeyInfo_der’:
 src/tpm2-provider-encoder.c:86:71: error: the comparison will always  evaluate as ‘true’ for the address of ‘tpm2_rsa_encode_public_
SubjectPublicKeyInfo_der’ will never be NULL [-Werror=address]

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 21:24:23 +02:00
Bernd Kuhls
bfcba48c74 package/liburcu: bump version to 0.15.6
https://git.lttng.org/?p=urcu.git;a=blob;f=ChangeLog;h=44d0d303b649682d05b3be85fa702eb919343807

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 21:09:24 +02:00
Bernd Kuhls
edd3a015cd package/lttng-tools: bump version to 2.16.0
https://git.lttng.org/?p=lttng-tools.git;a=blob_plain;f=ChangeLog;hb=72dcc536523727343cb23e2a0fefd41044511d16

Added Upstream: tag to patch 0001.

Removed patch 0002 which is included in this release.

Added new patch 0002 to fix a build error on musl introduced by this
bump due to upstream commit:
968475a48b

Updated license file paths according to upstream commit
https://git.lttng.org/?p=lttng-tools.git;a=history;f=LICENSES;hb=refs/heads/stable-2.16

Updated license hashes due to upstream commit
https://git.lttng.org/?p=lttng-tools.git;a=commit;h=c09078e13a4ede575724009520c37a8b8d3e68d6

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 21:09:21 +02:00
Bernd Kuhls
885055fe78 package/lttng-libust: bump version to 2.16.0
https://git.lttng.org/?p=lttng-ust.git;a=blob_plain;f=ChangeLog;hb=c896a32e65fd23d30ec541f78e7cb5867ba531c1

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 21:05:11 +02:00
Bernd Kuhls
69863b92c9 package/lttng-modules: bump version to 2.16.0
https://git.lttng.org/?p=lttng-modules.git;a=blob_plain;f=ChangeLog;hb=53eb8c30aa8a8afaf7bc46a9959a94bd0508d18e

Fixes build errors with newer kernels.

Please note that the previous 2.14 branch does not support kernel
versions >= 7.2:
https://git.lttng.org/?p=lttng-modules.git;a=commitdiff;h=7db42e0238d347eff969c1b1cf66fb5320da1bab

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 21:05:06 +02:00
Yegor Yefremov
c2bd6148c6 package/qemu: host-qemu does not support AVX512 CPUs
Building gobject-introspection for an x86 CPU variant with AVX512 fails
when g-ir-scanner runs the freshly built target binaries under
qemu-user:

  qemu: uncaught target signal 4 (Illegal instruction) - core dumped

The Qemu TCG engine implements AVX, AVX2, F16C, FMA3 and VAES since Qemu
7.2, but it does not implement the AVX512 instruction set at all [0].
Therefore no -cpu value passed through
BR2_PACKAGE_HOST_QEMU_USER_MODE_ARGS can make such binaries run, and
user-mode emulation is simply not possible for these CPU variants.

Mark those CPUs as unsupported by host-qemu, the same way it is already
done for x86_steamroller and x86_core_avx2. This relies on the existing
BR2_X86_CPU_HAS_AVX512 symbol, so all AVX512 capable variants are
covered, and it disables gobject-introspection and nodejs, which are the
two packages needing host-qemu in user mode.

[0] https://gitlab.com/qemu-project/qemu/-/issues/2878

Fixes:

  https://autobuild.buildroot.org/results/7ed7f9c36dae1ddb965a0f0021db6cd319927b47/

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 20:54:19 +02:00
Waldemar Brodkorb
05cbe542f9 package/libpam-pkcs11: bump to 0.6.14
Minor bugfix release, see here for a Changelog:
https://github.com/OpenSC/pam_pkcs11/releases/tag/pam_pkcs11-0.6.14

Signed-off-by: Waldemar Brodkorb <wbx@openadk.org>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 20:51:29 +02:00
Yegor Yefremov
6e2e24a740 package/libuci: bump version to 74f6277
Changelog:

 - 74f6277 cli: in batch mode, print empty line if get fails
 - ccc1719 libuci: fix extra new lines added to errorstr
 - 66127cd formal: fix workflow permissions
 - 5bea135 github: ci: add MIPS64, PowerPC64 and RISCV64
 - ebb3a01 build: install uci
 - 238963f github: ci: add powerpc arch
 - dec51f4 github: ci: add cmake build and source directories
 - 8022b2e uci: add a simple build script
 - e1ab90c github: ci: add tests
 - b65c091 github: ci: disable json-c tests
 - c1e2eee github: fix CI apt dependencies
 - 2e46a74 github: improve CI
 - 57c1e8c github: add CI build
 - 5e69eda CMakeLists: fix CMake warning for INCLUDE macro
 - 272fc13 lua: CMakeLists: drop redundant cmake_minimum_required
 - a072095 lua: CMakeLists: update cmake minimum required version to 3.10
 - 9033e8c blob: use blobmsg_parse_attr in __uci_blob_check_equal

This bump fixes the configure failure with cmake 4.x when the Lua
bindings are enabled: upstream commits a072095 and 272fc13 drop the
"cmake_minimum_required(VERSION 2.6)" statement from lua/CMakeLists.txt,
so the Lua subdirectory now inherits the top-level 3.13 minimum instead
of being rejected with "Compatibility with CMake < 3.5 has been removed
from CMake".

The license file hashes are updated as well, cli.c and libuci.c changed
but their license headers are untouched.

Fixes:
https://autobuild.buildroot.org/results/43ce08497863ff54c8acf3b0bbe7cfbdbc640d14/

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 20:50:23 +02:00
Bernd Kuhls
69283cd161 package/intel-vpl-gpu-rt: bump version to 26.3.4
https://github.com/intel/vpl-gpu-rt/releases/tag/intel-onevpl-26.3.4

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 20:48:12 +02:00
Bernd Kuhls
f2e4fb9093 package/intel-mediadriver: bump version to 26.3.4
https://github.com/intel/media-driver/releases/tag/intel-media-26.3.4

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 20:48:08 +02:00
Bernd Kuhls
84decc3a1d package/intel-gmmlib: bump version to 22.10.2
https://github.com/intel/gmmlib/releases/tag/intel-gmmlib-22.10.2

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 20:48:05 +02:00
Torben Voltmer
5c730e8e04 package/espflash: bump to version 4.6.0
For release notes, see:
https://github.com/esp-rs/espflash/releases/tag/v4.6.0

Update the Config.in help text to match the list of supported
target devices, since espflash now also supports ESP32-H4 and
ESP32-S31.

Signed-off-by: Torben Voltmer <mail@t-voltmer.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 20:46:29 +02:00
Michael Nosthoff
251a80dd9d package/wpewebkit: propagate gst1-libav architecture dependency
BR2_PACKAGE_WPEWEBKIT_MULTIMEDIA selects BR2_PACKAGE_GST1_LIBAV, which
depends on BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS, but doesn't propagate
this dependency. In practice, there is no issue, as webkitgtk is only
available on a subset of CPU architectures, while
BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS makes ffmpeg available on pretty much
all CPU architectures, except Cortex-M, m68k coldfire, and some
specific cases of OpenRISC, which are not supported by webkitgtk.

But for the sake of having correct dependency propagation, let's fix
this.

The other packages selected by BR2_PACKAGE_WPEWEBKIT_MULTIMEDIA have
dependencies that are already handled at the top-level
BR2_PACKAGE_WPEWEBKIT option.

Signed-off-by: Michael Nosthoff <buildroot@heine.tech>
CC: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Acked-by: Adrian Perez de Castro <aperez@igalia.com>
Acked-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 20:43:01 +02:00
Michael Nosthoff
5279b2303c package/wpewebkit: fix kernel headers dependency due to seccomp select
In commit
0e2c958e05 ("package/libseccomp: bump to
version 2.5.3"), the kernel headers dependency of seccomp was bumped
from 3.12 to 3.17, but BR2_PACKAGE_WEBKITGTK_SANDBOX, which is a
reverse dependency of BR2_PACKAGE_LIBSECCOMP was forgotten.

This commit fixes this inconsistency.

Fixes: 0e2c958e05 ("package/libseccomp: bump to version 2.5.3")

Signed-off-by: Michael Nosthoff <buildroot@heine.tech>
CC: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Acked-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-16 20:41:57 +02:00
Neal Frager
f63e572432 package/xen: fix build error when BR2_PACKAGE_XEN_TOOLS not enabled
The 0002-Update-linker-flags.patch assumes that the qemu-xen files are included
in the xen source tree. However, if BR2_PACKAGE_XEN_TOOLS is not enabled, the
qemu-xen dependency will not be handled and the patch will fail to apply with
the following error.

Fixes: build error below
Applying 0002-Update-linker-flags.patch using patch:
patching file tools/Makefile
Hunk #1 succeeded at 36 (offset -1 lines).
Hunk #2 succeeded at 185 (offset -8 lines).
can't find file to patch at input line 76
Perhaps you used the wrong -p or --strip option?
The text leading up to this was:
--------------------------
|diff --git a/tools/qemu-xen/include/hw/xen/xen_native.h b/tools/qemu-xen/include/hw/xen/xen_native.h
|index 6bcc83ba..2590904e 100644
|--- a/tools/qemu-xen/include/hw/xen/xen_native.h
|+++ b/tools/qemu-xen/include/hw/xen/xen_native.h
--------------------------
No file to patch.  Skipping patch.
1 out of 1 hunk ignored
make: *** [package/pkg-generic.mk:239: output/build/xen-4.21.1/.stamp_patched] Error 1

To avoid making BR2_PACKAGE_XEN_TOOLS a required option, fix the
0002-Update-linker-flags.patch so that modifying source from the qemu-xen
package is no longer included.

Instead of patching qemu-xen, a better solution is undefining the
__XEN_INTERFACE_VERSION__ from the qemu-xen package.

To test:
BR2_aarch64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_PACKAGE_XEN=y
 # BR2_PACKAGE_XEN_TOOLS is not set

Signed-off-by: Neal Frager <neal.frager@amd.com>
Tested-by: Matt Weber <matt@thewebers.ws>
Reviewed-by: Stewart Hildebrand <stewart.hildebrand@amd.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-16 08:51:53 +02:00
Bernd Kuhls
05021d4075 package/haproxy: bump version to 3.4.4
https://www.haproxy.org/news.html
https://www.haproxy.com/blog/announcing-haproxy-3-4
http://www.haproxy.org/download/3.4/src/CHANGELOG
https://git.haproxy.org/?p=haproxy-3.4.git;a=blob_plain;f=CHANGELOG

Version 3.4.x is the new LTS release which also added OpenSSL 4.0
compatibility.

Removed patch which is included in this release.

Disabled static builds due to upstream commit
https://git.haproxy.org/?p=haproxy-2.8.git;a=commitdiff;h=eaba76b02dd41e0a1a2e85a3e71f91dfc529916d
which was added to version 2.8 and causes build errors during static
linking:

/builds/bkuhls/buildroot/br-test-pkg/br-arm-full-static/host/opt/ext-toolchain/bin/../lib/gcc/arm-buildroot-linux-uclibcgnueabi/9.3.0/../../../../arm-buildroot-linux-uclibcgnueabi/bin/ld:
 /builds/bkuhls/buildroot/br-test-pkg/br-arm-full-static/host/arm-buildroot-linux-uclibcgnueabi/sysroot/usr/bin/../../usr/lib/libc.a(free.os):
 in function `malloc_trim':
free.c:(.text+0x24c): multiple definition of `malloc_trim';
 src/pool.o:pool.c:(.text+0xa14): first defined here

as suggested by Julien:
https://lists.buildroot.org/pipermail/buildroot/2025-July/782675.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-16 08:44:09 +02:00
Thomas Petazzoni
22540e0d41 package/glslsandbox: harmonize BR2_PACKAGE_BUSYBOX_SHOW_OTHERS select
BR2_PACKAGE_GLSLSANDBOX_PLAYER_SCRIPTS needs the full blown version of
bash and coreutils, so it selects BR2_PACKAGE_BUSYBOX_SHOW_OTHERS, but
it does so only if BR2_PACKAGE_BUSYBOX=y. Which kind of makes sense,
but is not aligned with the vast majority of other places where
BR2_PACKAGE_BUSYBOX_SHOW_OTHERS is selected, where
BR2_PACKAGE_BUSYBOX_SHOW_OTHERS is selected unconditionally. Harmonize
this with other packages.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-15 19:29:57 +02:00
Thomas Petazzoni
e62e06b19d package/xen: harmonize BR2_PACKAGE_BUSYBOX_SHOW_OTHERS select
BR2_PACKAGE_XEN_TOOLS needs the full blown version of bash and
coreutils, so it selects BR2_PACKAGE_BUSYBOX_SHOW_OTHERS, but it does
so only if BR2_PACKAGE_BUSYBOX=y. Which kind of makes sense, but is
not aligned with the vast majority of other places where
BR2_PACKAGE_BUSYBOX_SHOW_OTHERS is selected, where
BR2_PACKAGE_BUSYBOX_SHOW_OTHERS is selected unconditionally. Harmonize
this with other packages.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-15 19:29:57 +02:00
Thomas Petazzoni
6dad789282 package/ndctl: propagate !BR2_STATIC_LIBS dependency
ndctl selects kmod and keyutils, both of which depend on
!BR2_STATIC_LIBS, but this dependency was not propagated into ndctl
when the package was introduced. This commit fixes this issue.

Fixes: 039c1ae13e ("package/ndctl: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-15 19:29:51 +02:00
Thomas Petazzoni
3472fd59af package/ndctl: fix Config.in comment
The Config.in comment has the correct dependency on
!BR2_TOOLCHAIN_HAS_THREADS, but that was not reflected in the comment
text itself.

Fixes: 039c1ae13e ("package/ndctl: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-15 19:29:51 +02:00
Thomas Petazzoni
b56072c126 package/strongswan: fix BR2_PACKAGE_STRONGSWAN_BOTAN dependencies
BR2_PACKAGE_STRONGSWAN_BOTAN selects BR2_PACKAGE_BOTAN, but since
commit 10a70b1af6, botan needs gcc 11,
which was not propagated to strongswan's botan option. This commit
fixes this issue.

Fixes: 10a70b1af6 ("package/botan: needs gcc >= 11")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-15 19:25:09 +02:00
Thomas Petazzoni
6b716763e9 package/gerbera: propagate icu's dependency on !BR2_BINFMT_FLAT
gerbera selects BR2_PACKAGE_ICU, which depends on !BR2_BINFMT_FLAT,
but this dependency was not propagated to gerbera. In practice this is
not an issue because gerbera depends on BR2_USE_MMU, and only noMMU
platforms can use BR2_BINFMT_FLAT. But for the sake of completeness,
let's propagate this dependency.

Note: in the Config.in comment, we handle it like an architecture
dependency, like is done in package/icu/Config.in.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-15 19:24:54 +02:00
Thomas Petazzoni
e91ffb1afb package/netdata: propagate gcc version dependency of protobuf
Since the bump of libabseil-cpp in commit
76241e89e1, it requires gcc 10. As part
of this commit, the protobuf package was updated, but not its reverse
dependency netdata. This commit fixes this issue.

Fixes: 76241e89e1 ("package/libabseil-cpp: bump to version 20260817.0")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-15 19:24:29 +02:00
Thomas Petazzoni
cd5eab10fe package/sysprof: propagate ucontext-related dependency from libdex
BR2_PACKAGE_SYSPROF selects BR2_PACKAGE_LIBDEX but did not propagate:

	depends on BR2_TOOLCHAIN_HAS_UCONTEXT || \
		BR2_PACKAGE_LIBUCONTEXT_ARCH_SUPPORTS

from libdex. This commit fixes this missing dependency. In terms of
Config.in comment, we do the same as what libdex is doing: handle it
as a toolchain dependency (rather than an architecture dependency).

This was missed in commit a73ef093f7,
which added the ucontext related dependency to libdex, without
propagating it to sysprof.

Fixes: a73ef093f7 ("package/libdex: needs ucontext")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-15 19:14:22 +02:00
Thomas Petazzoni
e67b301f53 package/rpi-rgb-led-matrix: propagate BR2_PACKAGE_GRAPHICSMAGICK dependency
BR2_PACKAGE_RPI_RGB_LED_MATRIX_IMAGE_VIEWER selects
BR2_PACKAGE_GRAPHICSMAGICK, but did not propagate its BR2_USE_MMU
dependency. This issue exists since the package was introduced in
commit e821078031.

It fixes the following Kconfig warning:

WARNING: unmet direct dependencies detected for BR2_PACKAGE_GRAPHICSMAGICK
  Depends on [n]: BR2_USE_MMU [=n] && BR2_TOOLCHAIN_HAS_THREADS [=y]
  Selected by [y]:
  - BR2_PACKAGE_RPI_RGB_LED_MATRIX_IMAGE_VIEWER [=y] && BR2_PACKAGE_RPI_RGB_LED_MATRIX [=y]

which occurs when you configure an ARM noMMU FDPIC toolchain (because
we have noMMU, but shared libraries, so rpi-rgb-led-matrix can be
enabled).

Fixes: e821078031 ("package/rpi-rgb-led-matrix: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-15 19:14:15 +02:00
Thomas Petazzoni
d64b05108c package/gstreamer1/gst1-plugins-bad: fix dependency on gcc version
Since the bump of libabseil-cpp in commit
76241e89e1, it requires gcc 10. As part
of this commit, the webrtc-audio-processing package was updated, but
not its reverse dependency gst1-plugins-bad. This commit fixes this
issue.

Fixes: 76241e89e1 ("package/libabseil-cpp: bump to version 20260817.0")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-15 19:14:09 +02:00
Thomas Petazzoni
592d5c517e utils/getdeveloperlib.py: fix regexp used to find package infra
There's recently been autobuilder failures on
toolchain-external-bootlin, but I wasn't getting notified in the daily
autobuilder e-mail for those failures, which sounded odd as DEVELOPERS
contains:

N:      Thomas Petazzoni <thomas.petazzoni@bootlin.com>
[...]
F:      toolchain/

And indeed, testing:

$ ./utils/get-developers -p toolchain-external-bootlin

returned nothing.

Turns out that the regexp FIND_INFRA_IN_PATCH and FIND_INFRA_IN_MK
used to find the package infrastructure, and ultimately decide if a
given .mk file contains a package, was a bit too strict:

"^\+\$\(eval \$\((host-)?([^-]*)-package\)\)$"

This would only allow packages named <something>-package or
host-<something>-package, but the <something> should not contain any
dash ("-"). So this works fine for cmake-package,
host-autotools-package, but not for toolchain-external-package where
<something> is toolchain-external and it contains a dash.

We fix this by relaxing the regexp a bit and allowing any character in
<something>. Consider the rest of the regexp that expects $(eval
$(<host>-<something>-package)), it seems highly unlikely to match
anything else but the line we're interested in.

With this fix:

$ ./utils/get-developers -p toolchain-external-bootlin
Giulio Benetti <giulio.benetti@benettiengineering.com>
Romain Naour <romain.naour@gmail.com>
Thomas Petazzoni <thomas.petazzoni@bootlin.com>

This issue has existed since the toolchain-external-package
infrastructure had been added.

Fixes: 1c99d70e52 ("toolchain-external: introduce toolchain-external-package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-15 19:08:17 +02:00
Thomas Perale
489aefc22a package/zabbix: fix build without libcurl
Building zabbix without libcurl enabled would lead to the following
error:

/usr/bin/ld: .../src/libs/zbxxml/xml.c:515:(.text+0x1c64): undefined reference to `zbx_vector_str_append'

This issue has been addressed in the upstream commit [1] and backported
as a patch in Buildroot.
For more information see the upstream issue [2].

This error is reproducible with the following defconfig:

cat >.config <<EOF
BR2_arm=y
BR2_cortex_a7=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_PACKAGE_PHP=y
BR2_PACKAGE_ZABBIX=y
BR2_PACKAGE_ZABBIX_SERVER=y
BR2_PACKAGE_ZABBIX_SERVER_COPY_FRONTEND=y
EOF
make oldefconfig
make zabbix

[1] https://git.zabbix.com/projects/ZBX/repos/zabbix/commits/e8333ca2128
[2] https://support.zabbix.com/browse/ZBX-27635

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-15 18:52:35 +02:00
Thomas Perale
055a1e249c package/zabbix: security bump to v7.2.15
Zabbix 7.2 is EOL since December 2025 [1]

For more info on the version bump, see:
 - https://www.zabbix.com/rn/rn7.2.14
 - https://www.zabbix.com/rn/rn7.2.15

This fixes the following vulnerabilties:

- CVE-2026-23920:
    Host and event action script input is validated with a regex (set by
    the administrator), but the validation runs in multiline mode. If ^
    and $ anchors are used in user input validation, an injected newline
    lets authenticated users bypass the check and inject shell commands.
    https://www.cve.org/CVERecord?id=CVE-2026-23920

- CVE-2026-23921:
    A low privilege Zabbix user with API access can exploit a blind SQL
    injection vulnerability in include/classes/api/CApiService.php to
    execute arbitrary SQL selects via the sortfield parameter. Although
    query results are not returned directly, an attacker can exfiltrate
    arbitrary database data through time-based techniques, potentially
    leading to session identifier disclosure and administrator account
    compromise.
    https://www.cve.org/CVERecord?id=CVE-2026-23921

[1] https://endoflife.date/zabbix

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-15 18:52:33 +02:00
Thomas Perale
7878630479 package/zabbix: update SITE
Zabbix version 7.2 is no longer maintained. The version 7.0 is the LTS
and the stable moved to 7.4 [1]. The source location moved from "stable"
to "oldstable" directory.

This error is present in the autobuilder since the 22nd of May.

[1] https://endoflife.date/zabbix

Fixes: https://autobuild.buildroot.org/results/636/636c4514c67f1b0fcd20976d064f17b0e0a314fe//
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-15 18:52:09 +02:00
Bernd Kuhls
053c724d6e package/libheif: security bump version to 1.23.4
https://github.com/strukturag/libheif/releases/tag/v1.23.4

Fixes the following CVEs:

(CVE numbers will be added when assigned.)

CVE-2026-XXXXX (GHSA-vg7w-rp49-4fc2)
CVE-2026-XXXXX (GHSA-xrp2-63fq-jm8q)
CVE-2026-XXXXX (GHSA-prgh-72vc-3xmc)
CVE-2026-XXXXX (GHSA-fqpw-fj22-78w4)
CVE-2026-XXXXX (GHSA-4rv4-953r-p24q)
CVE-2026-XXXXX (GHSA-rhgw-q5g8-xjh2)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-15 18:49:39 +02:00
Bernd Kuhls
b26324b6c0 package/linux-firmware: bump version to 20260910
Updated the hash of the WHENCE file, due to firmware additions and
firmware changes, but no changes to the redistribution/licensing
conditions.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-15 18:28:42 +02:00
Joachim Wiberg
2fd1f6b629 package/lldpd: rework start script
check-package reports six warnings on S60lldpd: indentation with
spaces, no DAEMON variable, and shellcheck complaints.

The script also masks failures, the exit status of
"[ $? = 0 ] && echo OK || echo FAIL" is the one of echo, so start and
stop always return success.  Stopping does not wait for the daemon to
exit either, so a restart can race the instance on its way out.

Rewrite it after package/busybox/S01syslogd, as the manual asks.  lldpd
daemonizes and writes the PID file itself, but does not remove it on
exit, so pass the PID file to both start-stop-daemon and the daemon and
drop the stale file once the process is gone.  Also pick up arguments
from /etc/default/lldpd and add the customary reload alias.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
[Julien: remove .checkpackageignore entry to fix check-package error]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-14 21:36:27 +02:00
Joachim Wiberg
03e4bebcd2 package/lldpd: security bump to version 1.0.22
https://github.com/lldpd/lldpd/releases/tag/1.0.22
https://github.com/lldpd/lldpd/releases/tag/1.0.21

Fixes CVE-2026-46433, an out-of-bound read access when removing the
VLAN tag.  1.0.21 fixes path traversal vulnerabilities and arbitrary
file deletion in the privileged process.

GPG signature verified with key AEF2348766F371C689A7360095A42FE8353525F9,
LICENSE hash unchanged.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-14 21:33:58 +02:00
Peter Korsgaard
21f18cd012 package/x11r7/xlib_libXfont2: security bump to version 2.0.9
Fixes the following vulnerabilities:

- CVE-2026-59679: Font Server Client encoding Out-Of-Bounds Read/Write
- CVE-2026-44950: Font Server Client Cumulative Glyph Data Heap Buffer
  Overflow

For more details, see the advisory:
https://lists.x.org/archives/xorg-announce/2026-August/003734.html

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-14 21:19:52 +02:00
Bernd Kuhls
38918ea48e {linux, linux-headers}: bump 7.2.x, 6.18.x, 6.12.x, 6.6.x, 6.1.x, 5.15.x, 5.10.x series
Update the latest kernel releases to:
 - 7.2.5 -> 7.2.6
 - 6.18.51 -> 6.18.52
 - 6.12.109 -> 6.12.110
 - 6.6.156 -> 6.6.157
 - 6.1.187 -> 6.1.188
 - 5.15.220 -> 5.15.221
 - 5.10.269 -> 5.10.270

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-14 19:41:35 +02:00
Thomas Petazzoni
04d7d7bdeb package/mosh: bump gcc version requirement due to protobuf
In commit
76241e89e1 ("package/libabseil-cpp: bump
to version 20260817.0"), libabseil-cpp was bumped, which required the
gcc >= 8.x dependency to be upgraded to a gcc >= 10.x dependency. This
was properly done in package/protobuf as part of this commit, as
protobuf is a reverse dependency of libabseil-cpp.

However, mosh, which is a reverse dependency of protobuf, was
forgotten, and it no longer carries the correct gcc dependency.

This commit fixes this issue.

Fixes: 76241e89e1 ("package/libabseil-cpp: bump to version 20260817.0")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 21:59:28 +02:00
Thomas Petazzoni
39b840beef package/clamav: add missing BR2_TOOLCHAIN_HAS_SYNC_4 dependency
In commit 203725a46b ("package/clamav:
bump version to 1.0.1"), select BR2_PACKAGE_JSON_C was added to
BR2_PACKAGE_CLAMAV without propagating the BR2_TOOLCHAIN_HAS_SYNC_4
dependency from BR2_PACKAGE_JSON_C.

Since at the same time a dependency on
BR2_PACKAGE_HOST_RUSTC_TARGET_ARCH_SUPPORTS was added to clamav and
Rust is not supported on the few architectures that don't have 4-byte
sync intrinsics, this has basically no effect, but ensure a correct
propagation of dependencies.

Fixes: 203725a46b ("package/clamav: bump version to 1.0.1")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 21:59:07 +02:00
Thomas Petazzoni
7f5bb493e2 package/falcosecurity-libs: drop meaningless selects
BR2_PACKAGE_FALCOSECURITY_LIBS selects BR2_PACKAGE_HOST_GRPC and
BR2_PACKAGE_HOST_PROTOBUF, neither of which exists. These selects are
anyway not needed, so drop them.

Fixes: a15e35c4eb ("falcosecurity-libs: add new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 21:23:48 +02:00
Thomas Petazzoni
da90655637 package/webkitgtk: propagate gst1-libav architecture dependency
BR2_PACKAGE_WEBKITGTK_MULTIMEDIA selects BR2_PACKAGE_GST1_LIBAV, which
depends on BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS, but doesn't propagate
this dependency. In practice, there is no issue, as webkitgtk is only
available on a subset of CPU architectures, while
BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS makes ffmpeg available on pretty much
all CPU architectures, except Cortex-M, m68k coldfire, and some
specific cases of OpenRISC, which are not supported by webkitgtk.

But for the sake of having correct dependency propagation, let's fix
this.

The other packages selected by BR2_PACKAGE_WEBKITGTK_MULTIMEDIA have
dependencies that are already handled at the top-level
BR2_PACKAGE_WEBKITGTK option.

Fixes: e6e549b9e4 ("ffmpeg: add BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 21:23:42 +02:00
Thomas Petazzoni
ef92929504 package/webkit: fix kernel headers dependency due to seccomp select
In commit
0e2c958e05 ("package/libseccomp: bump to
version 2.5.3"), the kernel headers dependency of seccomp was bumped
from 3.12 to 3.17, but BR2_PACKAGE_WEBKITGTK_SANDBOX, which is a
reverse dependency of BR2_PACKAGE_LIBSECCOMP was forgotten.

This commit fixes this inconsistency.

Fixes: 0e2c958e05 ("package/libseccomp: bump to version 2.5.3")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 21:23:36 +02:00
Thomas Petazzoni
f7fe354ada package/libssh: fix select BR2_PACKAGE_LIBOPENSSL_ENGINES
BR2_PACKAGE_LIBSSH_OPENSSL unconditionnally selects
BR2_PACKAGE_LIBOPENSSL_ENGINES even though libressl is also supported
as an OpenSSL provider (and BR2_PACKAGE_LIBOPENSSL_ENGINES doesn't
make sense for libressl).

This causes the following Kconfig warning:

WARNING: unmet direct dependencies detected for BR2_PACKAGE_LIBOPENSSL_ENGINES
  Depends on [n]: <choice> && BR2_PACKAGE_LIBOPENSSL [=n]
  Selected by [y]:
  - BR2_PACKAGE_LIBSSH_OPENSSL [=y] && <choice> && BR2_PACKAGE_OPENSSL [=y]

We checked that libssh, with OpenSSL support and libressl selected as
an OpenSSL provider works fine, using the following defconfig:

BR2_aarch64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_PACKAGE_LIBSSH=y
BR2_PACKAGE_LIBSSH_SERVER=y
BR2_PACKAGE_LIBRESSL=y

Fixes: 62103be918 ("package/libssh: select BR2_PACKAGE_LIBOPENSSL_ENGINES")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 21:23:28 +02:00
Thomas Petazzoni
e96b7a0ef2 package/usbguard: fix gcc version dependency after libabseil-cpp bump
In commit
76241e89e1 ("package/libabseil-cpp: bump
to version 20260817.0"), libabseil-cpp was bumped, which required the
gcc >= 8.x dependency to be upgraded to a gcc >= 10.x dependency. This
was properly done in package/protobuf as part of this commit, as
protobuf is a reverse dependency of libabseil-cpp.

However, usbguard, which is a reverse dependency of protobuf, was
forgotten, and it no longer carries the correct gcc dependency.

This commit fixes this issue.

Fixes: 76241e89e1 ("package/libabseil-cpp: bump to version 20260817.0")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 21:23:23 +02:00
Thomas Petazzoni
f077ba9e67 package/qt5cinex: add missing select BR2_PACKAGE_QT5BASE_GUI
BR2_PACKAGE_QT5CINEX selects BR2_PACKAGE_QT5BASE_PNG,
BR2_PACKAGE_QT5BASE_WIDGETS and BR2_PACKAGE_QT5BASE_EGLFS, which are
all sub-options of BR2_PACKAGE_QT5BASE_GUI, but we don't explicitly
selects BR2_PACKAGE_QT5BASE_GUI.

It turns out that things work because the package selects
BR2_PACKAGE_QT5GRAPHICALEFFECTS, which selects
BR2_PACKAGE_QT5DECLARATIVE_QUICK, which selects
BR2_PACKAGE_QT5BASE_GUI, but that is rather non-obvious, and it makes
more sense for BR2_PACKAGE_QT5CINEX to directly select
BR2_PACKAGE_QT5BASE_GUI if it also selects sub-options of it.

No functional change.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 21:23:17 +02:00
Thomas Petazzoni
90aeea08bb package/ivi-homescreen: add missing BR2_USE_MMU dependencies
- BR2_PACKAGE_IVI_HOMESCREEN_AUDIO_PLAYERS selects gstreamer1, which
  has a depends on BR2_USE_MMU, but does not propagate it

- BR2_PACKAGE_IVI_HOMESCREEN_FLUTTER_SECURE_STORAGE_PLUGIN selects
  libsecret, which has a depends on BR2_USE_MMU, but does not propagate
  it

In practice there is no problem since ivi-homescreen depends on glibc,
and glibc doesn't support any noMMU architecture. But just by walking
the chain of option dependencies, this is not something that is
theoretically guaranteed (making automated verification of
dependencies difficult).

The other "depends on" from gstreamer1 and libsecret, BR2_USE_WCHAR
and BR2_TOOLCHAIN_HAS_THREADS are on the other hand already handled by
the top-level BR2_PACKAGE_IVI_HOMESCREEN option, so there is no
ambiguity.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 21:23:12 +02:00
Thomas Petazzoni
aff091c39d package/pulseview: add missing 'select BR2_PACKAGE_QT5GUI'
BR2_PACKAGE_PULSEVIEW selects BR2_PACKAGE_QT5BASE_PNG and
BR2_PACKAGE_QT5BASE_WIDGETS, which both depend on
BR2_PACKAGE_QT5BASE_GUI. It ends working because we also select
BR2_PACKAGE_QT5SVG, which selects BR2_PACKAGE_QT5BASE_GUI, so there is
no bug, but it's bit inconsistent to select sub-options that have a
"depends on" without selecting the option they depend on.

This not a bug fix, it has no functional implication.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 21:23:06 +02:00
Bernd Kuhls
43558e103b package/znc: security bump version to 1.10.3
https://github.com/znc/znc/blob/znc-1.10.3/ChangeLog.md
https://wiki.znc.in/ChangeLog/1.10.3

Fixes CVE-2020-11022, CVE-2020-11023, CVE-2026-82373 & CVE-2026-82374.

Updated _SITE according to
https://wiki.znc.in/index.php?title=ZNC&diff=3493&oldid=3460

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 19:33:49 +02:00
Dario Binacchi
e8ee9feba1 package/pocketpy: bump to version 2.2.0
Release notes:
https://github.com/pocketpy/pocketpy/releases/tag/v2.2.0

Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 18:30:51 +02:00
Dario Binacchi
376daf3dd0 package/pocketpy: fix build without threads
pocketpy enables thread support by default (PK_ENABLE_THREADS=ON) and
then requires Threads from cmake, which fails on toolchains without
thread support:

  CMake Error at /usr/share/cmake-3.28/Modules/FindPackageHandleStandardArgs.cmake:230 (message):
    Could NOT find Threads (missing: Threads_FOUND)

Thread support is optional, so enable it only when the toolchain
provides threads.

Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 18:30:51 +02:00
Viacheslav Bocharov
a38ff8ca81 package/rtl8822cs: bump driver version to latest with support kernel 7.2+
Update rtl8822cs driver to latest of the jethome-iot/rtl88x2cs.

Fixes:
  http://autobuild.buildroot.org/results/d4705d1a933528bad1f4afdf8f621c71bda8eada

Signed-off-by: Viacheslav Bocharov <v@baodeep.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 18:16:23 +02:00
Bernd Kuhls
56c76fe2cd package/taglib: bump version to 2.3.2
https://github.com/taglib/taglib/blob/v2.3.2/CHANGELOG.md
https://mail.kde.org/pipermail/taglib-devel/2026-September/003127.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 17:59:50 +02:00
Thomas Petazzoni
00e83bc24d package/kodi: fix definition of BR2_PACKAGE_KODI_ARCH_SUPPORTS
The definition of BR2_PACKAGE_KODI_ARCH_SUPPORTS is incorrect, it
goes like this:

 	bool
	default y if BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS
	default y if BR2_PACKAGE_HOST_OPENJDK_BIN_ARCH_SUPPORTS

so it means it would be "y" if either
BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS *OR*
BR2_PACKAGE_HOST_OPENJDK_BIN_ARCH_SUPPORTS is true. While clearly what
we need is for both to be true: ffmpeg should be available for the
target architecture, and openjdk should be available for the host
architecture.

One option was to change to:

 	bool
	default y if BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS && BR2_PACKAGE_HOST_OPENJDK_BIN_ARCH_SUPPORTS

Or:

 	bool
	default y if BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS
	depends on BR2_PACKAGE_HOST_OPENJDK_BIN_ARCH_SUPPORTS

But we preferred:

 	bool
	default y
	depends on BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS
	depends on BR2_PACKAGE_HOST_OPENJDK_BIN_ARCH_SUPPORTS

Fixes: b6a2f49429 ("package/kodi: depend on host-openjdk-bin instead of selecting BR2_NEEDS_HOST_JAVA")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 17:37:31 +02:00
Thomas Petazzoni
16e3d628bd package/kodi: propagate mariadb dependencies to BR2_PACKAGE_KODI_MYSQL
Even though kodi itself has architecture dependencies (expressed
through BR2_PACKAGE_KODI_ARCH_SUPPORTS, the option
BR2_PACKAGE_KODI_MYSQL selects BR2_PACKAGE_MARIADB, which has its own
architecture dependencies as well. Make sure to propagate those to
BR2_PACKAGE_KODI_MYSQL, which doesn't require adding a Config.in
comment as these are purely architecture dependencies.

We haven't replicate all dependencies of BR2_PACKAGE_MARIADB because
all the others are covered by the top-level BR2_PACKAGE_KODI, and
propagating them would require adding a Config.in comment for
BR2_PACKAGE_KODI_MYSQL.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 17:23:24 +02:00
Thomas Petazzoni
74def2cdd4 package/hidapi: propagate dependencies of libgudev
Since hidapi was introduced in commit
6267f34afd, it forgot to propagate some
dependencies of libgudev (which existed back then). Initially libgudev
was only needed when BR2_INIT_SYSTEMD=y, but still the dependencies
were not propagated for the systemd case.

Anyway, since e739dd5a11, libgudev is a
mandatory dependency of hidapi, independently from the selected init
system.

We make sure to propagate all dependencies of libgudev to hidapi, and
propagate them to the reverse dependencies of hidapi.

Fixes: 6267f34afd ("hidapi: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 16:57:04 +02:00
Dario Binacchi
0aeecbb889 package/atf: bump to version 0.25
The removed patch has been merged [1].

Since version 0.24, a C++20 compiler is required [2], so add a
dependency on gcc >= 10 and propagate it to kyua, which selects atf.

Release notes:
https://github.com/freebsd/atf/releases/tag/atf-0.25
https://github.com/freebsd/atf/releases/tag/atf-0.24

[1] 67e7d350a1
[2] 35134a317c
Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
[Julien: add link to v0.24 release notes]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 14:28:09 +02:00
Alexander Shirokov
6dc29e431f package/zellij: bump to version 0.45.1
Changelog: https://github.com/zellij-org/zellij/blob/v0.45.1/CHANGELOG.md

Signed-off-by: Alexander Shirokov <shirokovalexs@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 12:54:33 +02:00
Bernd Kuhls
c314f34213 package/monit: bump version to 6.0.0
https://mmonit.com/monit/changes/
https://bitbucket.org/tildeslash/monit/commits/tag/release-6-0-0

Rebased patch 0002.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 12:46:26 +02:00
Bernd Kuhls
3ca5af794f package/ruby: bump version to 4.0.6
https://www.ruby-lang.org/en/news/2026/07/14/ruby-4-0-6-released/
https://github.com/ruby/ruby/releases/tag/v4.0.6

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 12:27:19 +02:00
Bernd Kuhls
be60575e60 package/skopeo: bump version to 1.24.0
https://github.com/podman-container-tools/skopeo/releases/tag/v1.24.0

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 12:26:27 +02:00
Michael Fischer
60084ced05 package/libconfuse: bump to version 3.4
The backported fix is dropped, as 3.4 ships it:

  0001-Fix-163-unterminated-username-used-with-getpwnam.patch
    -> upstream commit d73777c2c356, released in 3.4

With the patch gone, LIBCONFUSE_IGNORE_CVES is no longer needed either.

3.4 also fixes three robustness defects that carry no CVE:

  #180  isspace() argument fix, could crash the lexer
  #182  stack exhaustion from deeply nested sections
  #187  null dereference on an empty comment with CFGF_COMMENTS

Upstream release notes:
https://github.com/libconfuse/libconfuse/releases/tag/v3.4

Signed-off-by: Michael Fischer <mf@go-sys.de>
[Fiona: add link to upstream release notes]
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
2026-09-13 12:22:02 +02:00
Thomas Petazzoni
d5990da7b1 toolchain/toolchain-external/toolchain-external-bootlin: regenerate after ARMv7 EABIhf toolchain fix
The gen-bootlin-toolchains script has been fixed to generate more
correct conditions for the ARMv7 EABIhf toolchains (both little and
big endian). This change will make sure the toolchain cannot be
selected in a BR2_arm=y, BR2_ARM_CPU_ARMV8A=y, BR2_ARM_EABI=y
configuration.

Fixes:

  https://autobuild.buildroot.org/results/3ce1dbd480c71b782ef722c39034cb039a036523/

Reported-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 11:56:17 +02:00
Thomas Petazzoni
43a8c35a38 support/scripts/gen-bootlin-toolchains: fix ARMv7 EABIhf toolchains condition
The ARMv7 EABIhf toolchains can currently be selected with ARMv8 cores
selected, even when EABI is used due to how the condition is
constructed. This obviously fails as those toolchains are EABIhf,
causing the following build issue:

Incorrect ABI setting: EABI selected, but toolchain is incompatible

This is for example what happens with:

BR2_arm=y
BR2_cortex_a32=y
BR2_ARM_EABI=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV7_EABIHF_GLIBC_BLEEDING_EDGE=y

In order to address this, we adjust the script generating the Bootlin
toolchain package so that EABIhf is required for both ARMv7 and
ARMv8.

Please note that we already require BR2_arm for those toolchains, so
we are *only* talking about ARMv8 cores being used in 32-bit mode.

This will be needed to fix:

  https://autobuild.buildroot.org/results/3ce1dbd480c71b782ef722c39034cb039a036523/

Reported-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 11:56:17 +02:00
Adrian Perez de Castro
acd98af32e package/wlroots: bump to version 0.20.2
Both .1 and .2 have been minor bugfix releases. Changelog:

  https://gitlab.freedesktop.org/wlroots/wlroots/-/tags/0.20.2
  https://gitlab.freedesktop.org/wlroots/wlroots/-/tags/0.20.1

Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 11:31:28 +02:00
Adrian Perez de Castro
4cbe7861de package/cage: bump to version 0.3.1
This minor release fixes a crash that could happen when a surface
requests to be fullscreened right away during startup. Release notes:

  https://github.com/cage-kiosk/cage/releases/tag/v0.3.1

Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 11:31:23 +02:00
Thomas Petazzoni
1799bf3680 package/*/Config.in: harmonize select of BR2_PACKAGE_ARGP_STANDALONE
BR2_PACKAGE_ARGP_STANDALONE is defined as follows:

config BR2_PACKAGE_ARGP_STANDALONE
	depends on !BR2_TOOLCHAIN_USES_GLIBC

Some packages did:

	select BR2_PACKAGE_ARGP_STANDALONE if !BR2_TOOLCHAIN_USES_GLIBC

while a number of others did:

	select BR2_PACKAGE_ARGP_STANDALONE if BR2_TOOLCHAIN_USES_UCLIBC || BR2_TOOLCHAIN_USES_MUSL

This commit harmonizes the situation, by settling on the first
solution ("if !BR2_TOOLCHAIN_USES_GLIBC") as it matches how
BR2_PACKAGE_ARGP_STANDALONE is defined in the first place.

No functional change.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 11:27:27 +02:00
Giulio Benetti
2f5620dbac package/cryptsetup: bump version to 2.8.8
For release note, see:
https://gitlab.com/cryptsetup/cryptsetup/-/blob/v2.8.8/docs/v2.8.8-ReleaseNotes

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
2026-09-13 11:25:49 +02:00
Thomas Petazzoni
876023bc5a package/intel-vpl-gpu-rt: add missing BR2_TOOLCHAIN_GCC_AT_LEAST_8 dependency
BR2_PACKAGE_INTEL_VPL_GPU_RT selects BR2_PACKAGE_INTEL_MEDIADRIVER but
did not propagate "depends on BR2_TOOLCHAIN_GCC_AT_LEAST_8". This
commit fixes this issue, which was introduced in commit
ac65841def, when onevpl-intel-gpu was
introduced (it was later renamed to intel-vpl-gpu-rt).

Fixes: ac65841def ("package/onevpl-intel-gpu: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 10:52:30 +02:00
Thomas Petazzoni
fa38fea91c package/intel-mediasdk: add missing BR2_TOOLCHAIN_GCC_AT_LEAST_8 dependency
BR2_PACKAGE_INTEL_MEDIASDK selects BR2_PACKAGE_INTEL_MEDIADRIVER but
forgets to propagate the "depends on BR2_TOOLCHAIN_GCC_AT_LEAST_8".

This issue was introduced in commit
51b60c8acf, when "depends on
BR2_TOOLCHAIN_GCC_AT_LEAST_8" was added to mesa3d, propagated to
intel-mediadriver, but not intel-mediasdk.

Fixes: 51b60c8acf ("package/mesa3d: needs gcc >= 8")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 10:52:30 +02:00
Thomas Petazzoni
e36370624d package/python-memray: add missing dependency on BR2_TOOLCHAIN_GCC_AT_LEAST_4_9
BR2_PACKAGE_PYTHON_MEMRAY selects BR2_PACKAGE_LIBUNWIND but forgot to
propagate "depends on BR2_TOOLCHAIN_GCC_AT_LEAST_4_9".

Fixes: c2df8bab97 ("package/python-memray: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 10:47:01 +02:00
Thomas Petazzoni
74dab03495 package/python-grpcio-reflection: add missing BR2_PACKAGE_HOST_PROTOBUF_ARCH_SUPPORTS dependency
BR2_PACKAGE_PYTHON_GRPCIO_REFLECTION selects
BR2_PACKAGE_PYTHON_PROTOBUF, but forgot to replicate "depends on
BR2_PACKAGE_HOST_PROTOBUF_ARCH_SUPPORTS".

Fixes: 3217fedcb8 ("package/python-grpcio-reflection: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 10:43:07 +02:00
Thomas Petazzoni
548904619c package/python-googleapis-common-protos: add missing BR2_PACKAGE_HOST_PROTOBUF_ARCH_SUPPORTS dependency
BR2_PACKAGE_PYTHON_GOOGLEAPIS_COMMON_PROTOS selects
BR2_PACKAGE_PYTHON_PROTOBUF but did not propagate
BR2_PACKAGE_HOST_PROTOBUF_ARCH_SUPPORTS.

Fixes: d37766a886 ("package/python-googleapis-common-protos: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 10:43:07 +02:00
Thomas Petazzoni
4b8259bad9 package/udisks: add missing BR2_USE_MMU dependency
Commit 66ddec89e8 ("package/udisks: bump
to version 2.92") mistakenly removed the BR2_USE_MMU dependency of
udisks when dropping "select BR2_PACKAGE_LVM2". Indeed, BR2_USE_MMU is
a dependency of many other packages selected by udisks.

Interestingly, the Config.in comments in the same file still had the
"depends on BR2_USE_MMU" dependencies.

Fixes: 66ddec89e8 ("package/udisks: bump to version 2.92")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 10:23:50 +02:00
Thomas Petazzoni
c305370f36 package/bcc: propagate missing dependency from clang
Since bcc was introduced in commit
146498d13c, it lacked a dependency
propagation from clang for BR2_TOOLCHAIN_HAS_GCC_BUG_64735, this
commit fixes this mistake.

Fixes: 146498d13c ("package/bcc: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 10:15:56 +02:00
Thomas Petazzoni
ccad393abf package/mpd: enable smb support on uClibc
samba4 is available on !musl, but samba support in mpd is available
only with glibc. Turns out that samba support in mpd builds just fine
with uClibc-ng, and that samba4 no longer needs native RPC support: it
can use libtirpc when needed (it's handled in the samba4 package
itself).

Tested with the following defconfig:

BR2_aarch64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_UCLIBC_BLEEDING_EDGE=y
BR2_PACKAGE_MPD=y
BR2_PACKAGE_MPD_LIBSMBCLIENT=y

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 09:52:26 +02:00
Thomas Petazzoni
71d3ffd372 package/go: use BR2_PACKAGE_HOST_GO_HOST_ARCH_SUPPORTS in BR2_PACKAGE_HOST_GO_TARGET_ARCH_SUPPORTS
BR2_PACKAGE_HOST_GO_TARGET_ARCH_SUPPORTS redefines the conditions to
determine if a host go compiler is available for the current host
architecture. Instead, make it explicit that those conditions are the
same by re-using BR2_PACKAGE_HOST_GO_HOST_ARCH_SUPPORTS.

No functional change.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 09:47:14 +02:00
Thomas Petazzoni
36b2b3f561 package/openscap: propagate dependencies of libxmlsec1 after bump
In commit
fef9cad1fe ("package/libxmlsec1: bump
version to 1.3.12"), libxmlsec1 was bumped, and alongside some
additional "depends on" were added.

However, these new "depends on" were not propagated to reverse
dependencies of libxmlsec1, i.e. openscap, causing Kconfig warnings:

WARNING: unmet direct dependencies detected for BR2_PACKAGE_LIBXMLSEC1
  Depends on [n]: BR2_TOOLCHAIN_GCC_AT_LEAST_7 [=n] && BR2_TOOLCHAIN_HAS_ATOMIC [=n]
  Selected by [y]:
  - BR2_PACKAGE_OPENSCAP [=y] && BR2_PACKAGE_LIBGPG_ERROR_ARCH_SUPPORTS [=y] && !BR2_STATIC_LIBS [=n] && BR2_TOOLCHAIN_HAS_THREADS_NPTL [=y]

and potentially some build issues, even though we didn't check in the
autobuilders for potential failures.

This commit fixes that by properly propagating the new dependencies.

Cc: Alexis Lothoré <alexis.lothore@bootlin.com>
Cc: Julien Olivain <ju.o@free.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Acked-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-13 09:31:00 +02:00
Bernd Kuhls
cf7cd535da package/ibm-sw-tpm2: bump version to rev183-2026-08-26
Rebased patch 0001 and added Upstream: tag.

Removed patches which are included in this release.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 16:22:45 +02:00
Bernd Kuhls
4a63b6269e package/tpm2-pkcs11: bump version to 1.10.1
https://github.com/tpm2-software/tpm2-pkcs11/blob/1.10.1/CHANGELOG.md

Switched to sha256 tarball hash provided by upstream.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 16:22:43 +02:00
Bernd Kuhls
17be3c2dcd package/tpm2-tools: security bump version to 5.8
https://github.com/tpm2-software/tpm2-tools/blob/5.8/docs/CHANGELOG.md

Fixes: GHSA-v7w4-4gc9-qcgv, GHSA-gwfg-w3jr-xh66 & GHSA-qp88-8f4j-wv7q.

Switched to sha256 tarball hash provided by upstream.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 16:22:41 +02:00
Adrian Perez de Castro
51b366290b package/xdg-dbus-proxy: security bump to verssion 0.1.8
Fixes and issue that caused broadcast messages to skip some checks.
Release notes:

  https://github.com/flatpak/xdg-dbus-proxy/releases/tag/0.1.8

Fixes:
https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-r7hp-698j-2h6c

Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
[Julien: add link to GHSA]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 16:11:24 +02:00
Yegor Yefremov
051e5ab13b package/imlib2: add zlib dependency
The demo programs, which have always been built and are still enabled by
default, gained a zlib dependency in imlib2 1.12.3: upstream commit
f8a451043871 ("imlib2_load: Add crc32 printout") started using zlib's
crc32() in imlib2_load, and 31006b425e11 ("imlib2_view: Optionally show
crc32 of image data") did the same for imlib2_view. Both hardcoded -lz.

Upstream commit b9555030dace ("autofoo: don't hardcode zlib flags"),
first released in 1.12.4, replaced -lz with $(ZLIB_LIBS) and added an
unconditional PKG_CHECK_MODULES(ZLIB, zlib) to the demo programs branch
of configure, turning the previously silent link-time requirement into a
configure failure:

  checking for zlib... no
  configure: error: Package requirements (zlib) were not met:

  Package 'zlib' not found

As Buildroot went straight from 1.7.3 to 1.12.5 the intermediate state
was never packaged, but the dependency has in fact been missing since the
crc32 support landed.

Fixes: https://autobuild.buildroot.org/results/4e05404c353ef985d74757d0b1ec3eda2cdff523/

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 16:03:22 +02:00
Bernd Kuhls
d540a10df9 package/softhsm2: bump version to 2.7.0
https://github.com/softhsm/SoftHSMv2/releases/tag/2.7.0

Switched repo to new standalone repo:
2355064ce4
Also update the package home page in Config.in.

We need to use the github helper to download the code which also needs
autoreconf.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
[Julien: update the package home page in Config.in]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 15:50:55 +02:00
Bernd Kuhls
0e5019c2e4 package/thrift: bump version to 0.24.0
https://github.com/apache/thrift/blob/v0.24.0/CHANGES.md

Please note that this bump includes CVE-2026-41608:
https://lists.apache.org/thread/vwsbcwqdpwdtp8qkjo11ol6rodbfm21f
which fixes a security bug in the python bindings that are not used by
buildroot.

Building this defconfig

BR2_aarch64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_CUSTOM=y
BR2_TOOLCHAIN_EXTERNAL_DOWNLOAD=y
BR2_TOOLCHAIN_EXTERNAL_URL="http://toolchains.bootlin.com/downloads/releases/toolchains/aarch64--glibc--bleeding-edge-2017.05-toolchains-1-2.tar.bz2"
BR2_TOOLCHAIN_EXTERNAL_GCC_6=y
BR2_TOOLCHAIN_EXTERNAL_HEADERS_4_9=y
BR2_TOOLCHAIN_EXTERNAL_CUSTOM_GLIBC=y
BR2_TOOLCHAIN_EXTERNAL_CXX=y
BR2_PACKAGE_THRIFT=y

without this bump does not cause build errors.

The Gitlab pipelines detected a build error for this bump with the
defconfig bootlin-aarch64-glibc-old:

/builds/bkuhls/buildroot/br-test-pkg/bootlin-aarch64-glibc-old/build/thrift-0.24.0/lib/cpp/src/thrift/transport/TBufferTransports.h:110:32:
 error: ‘ptrdiff_t’ does not name a type

To fix the problem we add a patch to include cstddef.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 15:37:17 +02:00
Bernd Kuhls
c25fed67e6 package/omniorb: bump version to 4.3.4
https://sourceforge.net/p/omniorb/svn/HEAD/tree/tags/4_3_4/omniORB/ReleaseNotes.txt

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 15:29:28 +02:00
Bernd Kuhls
ceaf9e557d package/libcdio: bump version to 2.4.0
https://github.com/libcdio/libcdio/releases/tag/2.4.0

Disable the configure detection of help2man to fix a build error on
Fedora 44 hosts:
https://lists.buildroot.org/pipermail/buildroot/2026-September/809202.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 15:18:40 +02:00
Bernd Kuhls
667c8bda32 package/luaossl: bump version to 20260910
https://github.com/wahern/luaossl/releases/tag/rel-20260910

Updated license hash due to copyright year bump:
efaf49dc35

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Acked-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 15:09:37 +02:00
Bernd Kuhls
ee5c69065e package/sentry-cli: bump version to 3.7.0
https://github.com/getsentry/sentry-cli/blob/3.7.0/CHANGELOG.md

Removed patch which is not needed anymore.

Updated license hash due to upstream commits:

copyright year bump:
734fa8cddc

switch to FSL-1.1-MIT license:
3ed4ada174

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 15:04:18 +02:00
Bernd Kuhls
c527520f07 package/utfcpp: bump version to 4.2.0
https://github.com/nemtrif/utfcpp/releases/tag/v4.2.0

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 13:16:26 +02:00
Bernd Kuhls
08b18e6571 package/meson: bump version to 1.12.0
https://mesonbuild.com/Release-notes-for-1-12-0.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 13:09:36 +02:00
Bernd Kuhls
d5f5eeaff4 package/grpc: bump version to 1.83.1
https://github.com/grpc/grpc/releases/tag/v1.83.1
https://github.com/grpc/grpc/releases/tag/v1.83.0
https://github.com/grpc/grpc/releases/tag/v1.82.2
https://github.com/grpc/grpc/releases/tag/v1.82.1
https://github.com/grpc/grpc/releases/tag/v1.82.0
https://github.com/grpc/grpc/releases/tag/v1.81.1
https://github.com/grpc/grpc/releases/tag/v1.81.0

Rebased patch 0001.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 11:33:57 +02:00
Michael Nosthoff
5839ccb520 package/{python-}protobuf: bump to version 36.1
changelog:
https://github.com/protocolbuffers/protobuf/releases/tag/v36.1
https://github.com/protocolbuffers/protobuf/releases/tag/v36.0

Signed-off-by: Michael Nosthoff <buildroot@heine.tech>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 11:31:20 +02:00
Michael Nosthoff
76241e89e1 package/libabseil-cpp: bump to version 20260817.0
- libabseil now requires gcc >= 10
- drop patch trying to fix build with gcc <= 12 as this is now handled
  in protobuf >= 35 directly.

Changelog:
https://github.com/abseil/abseil-cpp/releases/tag/20260817.0
https://github.com/abseil/abseil-cpp/releases/tag/20260526.0

Signed-off-by: Michael Nosthoff <buildroot@heine.tech>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 11:24:40 +02:00
Giulio Benetti
dc1f1818d9 package/libnss: bump version to 3.129
Drop local patch that has been upstreamed.

For release notes since 3.127, see:
https://hg-edge.mozilla.org/projects/nss/file/NSS_3_128_RTM/doc/src/releases/nss_3_128.md
https://hg-edge.mozilla.org/projects/nss/file/NSS_3_129_RTM/doc/src/releases/nss_3_129.md

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
[Julien: add link to 3.128 release notes in commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-12 11:13:27 +02:00
Bernd Kuhls
9a1c11c997 {linux, linux-headers}: bump 7.2.x, 6.18.x series
Update the latest kernel releases to:
 - 7.2.4 -> 7.2.5
 - 6.18.50 -> 6.18.51

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-12 09:38:40 +02:00
Bernd Kuhls
8af3e34fd4 package/freeradius-server: bump version to 3.2.10
Removed patch 0004 due to upstream commit:
60d60eed11
which removes the patched code part.

Added new patch 0004 to fix build errors resulting from the commit
mentioned above.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-12 09:38:01 +02:00
Bernd Kuhls
5c9fbf7efe package/apache: renumber patches
Buildroot commit 99bfbef093 removed patch
0002 but forgot to renumber the remaining patches.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-12 09:37:28 +02:00
Bernd Kuhls
fcb0643274 package/samba4: bump version to 4.24.7
https://www.samba.org/samba/history/samba-4.24.7.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-12 09:37:12 +02:00
Bernd Kuhls
6f125a6530 package/xz: security bump version to 5.8.4
https://github.com/tukaani-project/xz/releases/tag/v5.8.4

- lzma_alone_decoder(), lzma_lzip_decoder(),
  lzma_auto_decoder(), and lzma_microlzma_decoder(): Fix an
  invalid memory access after memory allocation has failed and
  the application reinitializes the existing decoder to decode
  a different file. This bug could at least result in a crash.
  This is tracked as GHSA-5qpq-xqfv-j9pg. CVE number is pending.
  (Also in v5.2, v5.4, and v5.6.)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-12 09:37:00 +02:00
Adrian Perez de Castro
4cb6193d2e package/bubblewrap: security bump to version 0.12.0
Fixes a sandbox escape through symlink traversal tracked in
CVE-2026-87766, which affects all previous versions.

Using the bwrap binary with the setuid bit set is no longer supported
and user namespaces are now always required, so a kernel config fixup
is applied.

A new build option allows indicating the minimum kernel version that
will be used, which removes code used for backwards compatibility with
kernels older than 5.6.0 when a newer version is specified. Passing
$(LINUX_VERSION_PROBED) seems reasonable here.

This version also changed the license from LGPL-2.0+ to LGPL-2.1+,
hence the updated hash.

Release notes:

  https://github.com/containers/bubblewrap/releases/tag/v0.12.0

Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
[Julien: fix _LINUX_CONFIG_FIXUPS by adding the missing "_LINUX"]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-10 21:58:53 +02:00
James Hilliard
8067813e99 package/python-cython: bump to version 3.2.3
Signed-off-by: James Hilliard <james.hilliard1@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-10 21:48:37 +02:00
James Hilliard
2603561b12 package/python-propcache: skip dependency check
The python-propcache package specifies an unnecessarily strict cython
version, disable the check so that we can update cython.

Signed-off-by: James Hilliard <james.hilliard1@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-10 21:48:36 +02:00
Arnout Vandecappelle
2083b53b32 CHANGES: Update for 2026.05.3
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>

(cherry picked from commit 4b06935cb0)
2026-09-10 21:43:57 +02:00
Arnout Vandecappelle
3a22cd2d84 Update news.html and download.html for 2026.05.3
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
2026-09-10 21:43:56 +02:00
Titouan Christophe
b00ac4e346 utils/checkpackagelib: add new check MissingCVEPatch
To indicate that a patch fixes a vulnerability in Buildroot, the convention is:
1. In the patch file, add a tag 'CVE: <cve id>'
2. In <pkg>.mk, and an entry to <PKG>_IGNORE_CVES, and add a comment above
   that new entry to reference the patch file(s)

However, as packages get bumped and their patches are added, removed or
rebased; it happens that IGNORE_CVES get outdated. One important issue is
marking a CVE as ignored, while the corresponding patch is not in Buildroot.

To detect such cases, add a new checker to checkpackagelib that finds
occurences of:

    # 000x-some-patch.patch
    PKG_IGNORE_CVES += CVE-XXXX-YYYY

For each one of them, ensure that the mentioned patch files actually exist
and contain the `CVE: ...` tag.

Assisted-by: Claude:claude-opus-4.8
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-10 21:38:47 +02:00
Titouan Christophe
636f69ab45 package/{binutils, gpsd, micropython, net-tools, util-linux, x11vnc}: fix CVE patch information
Prior to improving check-package to verify that the comment preceding
a <pkg>_IGNORE_CVES entry mentions an existing patch, and that the
patch itself contains a CVE: tag, we fix all problematic cases that
currently exist in Buildroot:

- In the case of binutils: the CVE was only applicable to binutils
  2.43/2.44, and the oldest version now supported is 2.45, so the
  patch doesn't exist anymore in Buildroot
- For x11vnc, fix a typo in the patch name
- For gpsd the patches were dropped in [1] as they are included in the
  version bump
- Similarly for micropython, the patches were dropped in [2] along with
  the version bump
- For util-linux, strip the prefix "package/util-linux/", so that the patch
  is relative to the .mk file and can be found by the new check
- Add missing 'CVE:' tag to net-tools patch 0001

[1] 37ef4f862f package/gpsd: bump version to 3.27.2
[2] 28eeca9a98 package/micropython: bump to version 1.28.0

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-10 21:38:46 +02:00
Arnout Vandecappelle
8d8eb658ce docs/website/download.html: re-add the old stable
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
2026-09-10 21:25:20 +02:00
Arnout Vandecappelle
d705dc5d96 CHANGES: Update for 2025.02.18
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>

(cherry picked from commit 0f81c9d8cd)
2026-09-10 21:20:09 +02:00
Arnout Vandecappelle
3c4238b9f1 Update news.html and download.html for 2025.02.18
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
2026-09-10 21:20:08 +02:00
Giulio Benetti
7458d2323a package/libfuse3: security bump to version 3.18.3
Release notes:
https://github.com/libfuse/libfuse/releases/tag/fuse-3.18.3

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-10 20:47:37 +02:00
Bernd Kuhls
664db5d62c package/pcre2: security bump to version 10.48
https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48

Fixes the following security issues:

(Security fix for specific API usage, GHSA-2p8c-ff85-vh9x)
 If pcre2_jit_compile() is called with options for some match modes, and
 then pcre2_match() is used to perform a match for a different match
 mode, an out-of-bounds read can occur if the match is attempted against
 invalid UTF input.

(Security fix for pattern conversion, GHSA-q8g2-wprr-34m9)
 If pcre2_convert() is called on untrusted input on platforms with
 32-bit size_t, an out-of-bounds heap write can occur.

(Security fix, GHSA-3r4p-g7gg-ppmf) Fixed an out-of-bounds write in DFA
 matching when using a heap limit; also fixed possible integer overflows
 which could cause under-allocation of the workspace.

(Security fix, GHSA-fmgr-6ggq-9859) Added bounds checks for several
 integer overflows while compiling patterns on 32-bit CPUs, which could
 cause under-allocation followed by out-of-bounds writes.

(Security fix, GHSA-9qww-pwc4-77qq) Applied lower buffer bound to
 prevent two out-of-bounds reads while scanning backwards through
 invalid UTF data with PCRE2_MATCH_INVALID_UTF.

(Security fix for specific API usage, #937) Fixed a leak and later
 invalid free when calling the fast-path pcre2_jit_match() function with
 a match data object previously used with pcre2_match() and
 PCRE2_COPY_MATCHED_SUBJECT.

(Low-severity security fix, GHSA-q7rw-r7qq-2hx6) Fixed exposure of two
 uninitialised bytes from malloc() via pcre2_serialize_encode().

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-10 20:43:10 +02:00
Bernd Kuhls
95649c547b package/tor: security bump version to 0.4.9.12
https://gitlab.torproject.org/tpo/core/tor/-/blob/tor-0.4.9.12/ReleaseNotes
https://forum.torproject.org/t/security-release-0-4-9-12/22096

Fixes TROVE-2026-032, TROVE-2026-033, TROVE-2026-034, TROVE-2026-035,
TROVE-2026-036, TROVE-2026-042 & TROVE-2026-043.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-09 23:27:25 +02:00
Bernd Kuhls
15a422cee1 package/turbolua: security bump version to 2.1.5
https://github.com/kernelsauce/turbo/releases/tag/v2.1.5

https://github.com/kernelsauce/turbo/releases/tag/v2.1.4
Security fixes:

HTTP header injection: header values were only checked for a literal
 \r\n, so a lone \r or \n could still split a header. Now rejected on
 either character.

Transfer-Encoding requests are now rejected with 501 instead of silently
 mishandled, closing a request smuggling avenue.

A real default request body size cap (128 MB) with a 413 response,
 previously unbounded.

Secure cookie signature now binds the cookie name, so a value signed for
 one cookie can no longer be replayed under a different name.
 Verification failures return the default value instead of raising.

Constant-time comparison for the secure cookie HMAC, previously a
 timing-leaky ==.

util.secure_random_bytes reads real OS entropy (/dev/urandom,
 BCryptGenRandom on Windows) for WebSocket masks and util.rand_str,
 previously math.random.

WebSocket: unmasked client frames are rejected per RFC 6455, and
 fragmented message reassembly is capped to max_buffer_size to close a
 memory exhaustion path.

StaticFileHandler decodes the request path before the traversal check,
 closing a bypass.

Fixed a 32-byte-per-malformed-request memory leak in the C header parser
 wrapper (found via libFuzzer).

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-09 23:18:18 +02:00
Romain Naour
271bad50ff docs/website/sponsors.html: announce Smile as sponsor for the February 2026 Buildroot meeting
Thank Smile for sponsoring the Buildroot Developers Meeting of
February 2026 by providing the meeting room.

https://elinux.org/Buildroot:DeveloperDaysFOSDEM2026

Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-09 23:10:05 +02:00
Bernd Kuhls
a9643c31c6 package/intel-vpl-gpu-rt: bump version to 26.3.3
https://github.com/intel/vpl-gpu-rt/releases/tag/intel-onevpl-26.3.3
https://github.com/intel/vpl-gpu-rt/releases/tag/intel-onevpl-26.3.2

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-09 17:01:45 +02:00
Bernd Kuhls
6084d8bb7f package/intel-mediadriver: bump version to 26.3.3
https://github.com/intel/media-driver/releases/tag/intel-media-26.3.3
https://github.com/intel/media-driver/releases/tag/intel-media-26.3.2

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-09 17:01:43 +02:00
Alexander Sverdlin
2ffcb1e181 package/mini-snmpd: bump to version 2.1
Fixes:
- Reassemble SNMP requests split across TCP segments, and drop
  over-large messages, by Noam Rathaus
- Fix encoded-length accounting for decoded OIDs, by Noam Rathaus
- Zero-fill memory from the internal `allocate()` helper
- Build the interface trap OIDs without a run-time format string
- Avoid needless variable shadowing under `-Wshadow`

Signed-off-by: Alexander Sverdlin <alexander.sverdlin@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-09 17:00:43 +02:00
Bogdan Radulescu
36fa003547 package/nettest: new package
nettest measures download and upload throughput, latency, jitter and
packet loss using the RMBT protocol. The same binary runs as either the
client or the measurement server it tests against.

Written in Rust with no native library dependencies: the target binary
links only libc, libm and libgcc_s, and is fully static when built
against musl.

Signed-off-by: Bogdan Radulescu <bogdan@nimblex.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-09 16:50:45 +02:00
Bernd Kuhls
2d71c874d2 package/i2pd: bump version to 2.61.0
https://github.com/PurpleI2P/i2pd/blob/2.61.0/ChangeLog

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-09 15:46:00 +02:00
Bernd Kuhls
5b076d3755 package/i2pd: needs chacha support in libopenssl
/home/thomas/autobuild/instance-2/output-1/build/i2pd-2.59.0/libi2pd/Crypto.cpp:661:49:
 error: 'EVP_chacha20_poly1305' was not declared in this scope; did you
 mean 'SN_chacha20_poly1305'?

The code was added upstream in 2018:
58c92b8405

The build error could be reproduced with i2pd version 2.22.0 added to
buildroot with commit 1035e80aaa so a
backport to LTS branches should be considered.

Fixes:
https://autobuild.buildroot.net/results/bd8/bd8616f04df2e1b9e18d1e16921979a852bd566f/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-09 15:45:59 +02:00
Bernd Kuhls
a6bb4d52c0 package/i2pd: needs gcc >= 8
Upstream started using std::string_view
https://github.com/search?q=repo%3APurpleI2P%2Fi2pd+string_view&type=commits&s=committer-date&o=asc

with commit
a3e0b3710c

first released in version 2.54.0 which was added to buildroot with
commit dea4f02bbb.

Building the package with the gcc6-based defconfig
bootlin-aarch64-glibc-old is broken:

/builds/bkuhls/buildroot/br-test-pkg/bootlin-aarch64-glibc-old/build/i2pd-2.61.0/libi2pd/Base.h:14:23:
 fatal error: string_view: No such file or directory

BR2_TOOLCHAIN_HAS_GCC_BUG_64735 can be removed as well now as it depends
on gcc < 7.

A backport to LTS branches should be considered.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-09 15:45:59 +02:00
Thomas Petazzoni
eeec7b495f tooolchain/toolchain-external: update toolchain-external-bootlin to 2026.08
All toolchains have been rebuilt based on Buildroot 2026.08, which
means:

* The bleeding-edge toolchains are based on gcc 16.2, binutils 2.46.1,
  gdb 17.1, kernel headers 6.12, glibc 2.44, musl 1.2.6 or uclibc-ng
  1.0.59.

* The stable toolchains are based on gcc 15.3, binutils 2.45.1, gdb
  16.3, kernel headers 5.10, glibc 2.44, musl 1.2.6 or uclibc-ng 1.0.59.

The runtime tests related to those toolchains all pass fine:

  https://gitlab.com/tpetazzoni/buildroot/-/pipelines/2824569690

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-08 19:16:01 +02:00
Alexander Shirokov
d0c6a0c40e package/broot: bump to version 1.60.0
Changelog: https://github.com/Canop/broot/blob/v1.60.0/CHANGELOG.md

Signed-off-by: Alexander Shirokov <shirokovalexs@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-07 21:55:03 +02:00
Bernd Kuhls
005c57acae package/{rust, rust-bin}: bump version to 1.98.1
https://blog.rust-lang.org/2026/09/03/Rust-1.98.1/
https://blog.rust-lang.org/2026/08/20/Rust-1.98.0/

Disable the new option compress-debuginfo, introduced in version 1.98.0
65f06572fb

to disable a build error reported by Julien:
https://lore.kernel.org/buildroot/507d53e20261b7a015f33af381003c51@free.fr/

rust-lld: error: --compress-debug-sections: LLVM was not built with
LLVM_ENABLE_ZLIB or did not find zlib at build time

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-07 21:35:03 +02:00
Baruch Siach
325912fa2b package/strace: fix build with uclibc
Commit a1e25fe705 ("package/strace: bump version to 7.2") breaks strace
build with uclibc because of missing header. Add a patch to fix that.

Fixes:
https://autobuild.buildroot.org/results/054705652027d990fb1b418ed4a3c129fb0cdfe3/

Signed-off-by: Baruch Siach <baruch@tkos.co.il>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-07 20:41:20 +02:00
Bernd Kuhls
b69d0b3a9c {linux, linux-headers}: bump 6.12.x, 6.18.x, 7.2.x series
Update the latest kernel releases to:
 - 6.12.108 -> 6.12.109
 - 6.18.49 -> 6.18.50
 - 7.2.3 -> 7.2.4

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-07 20:28:42 +02:00
Bernd Kuhls
446c0f85b8 package/libpcap: security bump version to 1.10.7
https://github.com/the-tcpdump-group/libpcap/blob/libpcap-1.10.7/CHANGES

Fixes the following CVEs:

CVE-2026-0799: Access M[] safely in the BPF interpreter.
CVE-2026-31912: Mind the program bounds in pcap_offline_filter().
CVE-2026-31911: Fail opcodes safely in the BPF interpreter.
CVE-2026-6244: Avoid division by zero via pcap_offline_filter().
CVE-2026-6554: Limit "ja L" looping in pcap_offline_filter().
CVE-2026-18313: Fix a memory leak in rpcapd.
CVE-2026-18238: Fix RPCAP_MSG_PACKET validation.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-07 20:20:57 +02:00
Joseph Kogut
87e95b9877 package/passt: disable on uclibc
Upstream lists uClibc-ng support as a "nice-to-have, eventually", and
tracks the required build fixes as an enhancement:

https://bugs.passt.top/show_bug.cgi?id=5

passt relies on interfaces and definitions missing from uClibc,
resulting in build failures such as:

qrap.c:145:25: error: 'ARG_MAX' undeclared
tcp.c:2926:34: error: storage size of 'wnd' isn't known
tcp.c:3321:47: error: 'TCP_SEND_QUEUE' undeclared

Disable passt for uClibc toolchains and propagate the dependency to
Podman's passt backend.

Fixes:
 - http://autobuild.buildroot.org/results/7e4/7e4434e01baece4d090e44b4b3713f2eeefc1e27/
 - http://autobuild.buildroot.org/results/3f6/3f60889b4599f1bc42a69076f6fe469517ea9ab5/

Signed-off-by: Joseph Kogut <joseph@anodize.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-07 08:04:24 +02:00
Bernd Kuhls
531be778bd package/unbound: bump version to 1.26.0
https://nlnetlabs.nl/projects/unbound/download/#unbound-1-26-0

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 22:35:20 +02:00
Bernd Kuhls
a0c5a20073 package/squid: bump version to 7.7
https://github.com/squid-cache/squid/blob/SQUID_7_7/ChangeLog

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 21:44:25 +02:00
Bernd Kuhls
5a2e1177f9 package/mutt: bump version to 2.4.1
http://www.mutt.org/news.html
http://www.mutt.org/relnotes/2.4/
https://gitlab.com/muttmua/mutt/raw/stable/UPDATING

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 21:42:03 +02:00
Bernd Kuhls
d1fbea37a6 package/libcap-ng: bump version to 0.9.5
https://github.com/stevegrubb/libcap-ng/blob/v0.9.5/ChangeLog

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 21:38:17 +02:00
Bernd Kuhls
e3c4a32d34 package/hwdata: bump version to 0.411
https://github.com/vcrhonek/hwdata/releases/tag/v0.411
https://github.com/vcrhonek/hwdata/releases/tag/v0.410

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 21:28:41 +02:00
Bernd Kuhls
612460dffd package/cmake: bump version to 4.4.3
https://cmake.org/cmake/help/latest/release/4.4.html#id2

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 21:10:04 +02:00
Bernd Kuhls
f77c8cf14e package/ccache: bump version to 4.14
https://ccache.dev/releasenotes.html#_ccache_4_14

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 20:25:59 +02:00
Bernd Kuhls
d9e8462570 package/openldap: bump version to 2.6.14
https://github.com/openldap/openldap/blob/OPENLDAP_REL_ENG_2_6_14/CHANGES
https://www.openldap.org/software/release/changes_lts.html

Rebased patch 0001.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 18:55:00 +02:00
Torben Voltmer
490c380155 package/espflash: bump to version 4.5.0
For release notes, see:
https://github.com/esp-rs/espflash/releases/tag/v4.1.0
https://github.com/esp-rs/espflash/releases/tag/v4.2.0
https://github.com/esp-rs/espflash/releases/tag/v4.3.0
https://github.com/esp-rs/espflash/releases/tag/v4.4.0
https://github.com/esp-rs/espflash/releases/tag/v4.5.0

Update the Config.in help text to match the list of supported
target devices, since espflash now also supports ESP32-C5 and ESP32-C61.

Signed-off-by: Torben Voltmer <mail@t-voltmer.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 18:43:07 +02:00
Julien Olivain
d071817969 package/igh-ethercat: remove stale patch 0002
igh-ethercat is failing while attempting to apply patches,
with error:

    Applying 0002-Linux-6.19.0-support.patch using patch:
    patching file devices/generic.c
    Reversed (or previously applied) patch detected!  Skipping patch.
    1 out of 1 hunk ignored -- saving rejects to file devices/generic.c.rej

The package patch 0002 was added in [1] in branch "master" while it
was in release client cycle. It was cherry-picked in [2] in branch
"next" to apply the bump [3] (which removes the package patches 0001
and 0002). When the branch "next" was merged in "master" in commit [4],
the patch 0002 was kept.

This commit removes this stale patch.

[1] e4cf512c39
[2] 8a5fc970b4
[3] 0a91e760f4
[4] 5f26877955

Fixes:
- https://autobuild.buildroot.org/results/4f509f1f788c1b8dc5a840ffa2e435c5ed7b6eea/

Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 14:51:12 +02:00
Bernd Kuhls
a07a17d00e package/binutils: remove support for binutils 2.44
Now that binutils 2.47 has been introduced and binutils 2.46.1 made
the default version, drop the oldest supported version, binutils 2.44,
keeping only the 3 last versions supported: 2.45.1, 2.46.1 and 2.47.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 13:56:45 +02:00
Bernd Kuhls
c70effd711 package/binutils: make binutils 2.46.1 be the default
Now that support for binutils 2.47 has been introduced, we follow our
policy of making binutils 2.46.1 the default version.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 13:56:45 +02:00
Bernd Kuhls
a4c3a288e6 package/binutils: add support for binutils 2.47
https://sourceware.org/pipermail/binutils/2026-July/150449.html

We bring and rebased patches 0001 and 0002 that we carry for binutils
2.46.1.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 13:56:45 +02:00
Bernd Kuhls
f7e943bf42 package/linux-headers: drop 7.1.x option
The 7.1.x series is now EOL upstream, so drop the linux-headers
option and add legacy handling for it.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 13:56:45 +02:00
Bernd Kuhls
7e2c623193 linux: bump latest version to 7.2
For an overview of changes in 7.2, see:
https://kernelnewbies.org/Linux_7.2

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
[Julien: rename "7.1.13" symlink to "7.2.3"]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 13:56:35 +02:00
Bernd Kuhls
6528b3e3f8 {toolchain, linux-headers}: add support for 7.2 headers
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 13:04:41 +02:00
Bernd Kuhls
a1e25fe705 package/strace: bump version to 7.2
https://github.com/strace/strace/releases/tag/v7.2

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 13:04:41 +02:00
Bernd Kuhls
0838e968cb package/{glibc, localedef}: security bump version to 2.44-40-g30950ce64
Fixes CVE-2026-18374:
0b4e41fc51

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 12:18:36 +02:00
Bernd Kuhls
e55cb31085 package/libde265: security bump version to 1.1.2
https://github.com/strukturag/libde265/releases/tag/v1.1.2

Security fixes:
(CVE numbers will be added when assigned.)

CVE-2026-XXXXX (GHSA-xp3h-6f5r-8cxp) Heap use-after-free and double free
 in multi-threaded (WPP) decoding. A crafted stream whose slice segments
 repeat or rewind their slice_segment_address within a picture re-ran
 CTB rows that were already marked finished, so the CABAC context handoff
 between rows was no longer ordered and the shared context table was
 released twice. Slice segments that do not follow the previous one in
 tile-scan order are now rejected with the new warning
 DE265_WARNING_SLICE_SEGMENT_ADDRESS_NOT_INCREASING, and the WPP row
 progress is reset for each slice segment. (medium)

CVE-2026-XXXXX (GHSA-mm7m-v26f-wf8x) Heap use-after-free after
 de265_reset(): the pointer to the previous slice header was left
 dangling when the DPB was cleared, and a dependent slice pushed after
 the reset copied from freed memory. (medium)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 12:15:48 +02:00
Bernd Kuhls
d148168e20 package/libheif: security bump version to 1.23.3
https://github.com/strukturag/libheif/releases/tag/v1.23.3

Fixes the following CVEs:

(CVE numbers will be added when assigned.)

CVE-2026-XXXXX (GHSA-x8r2-mggj-j6wr) Heap buffer overflow (write) in the
 uncompressed (unci) mixed-interleave decoder when the two chroma
 components declare different bit depths. Both the written bytes and the
 overflow length are controlled by the file. (critical)

CVE-2026-XXXXX (GHSA-8fmq-r4pf-7m57) Permanent decoder deadlock through
 a reference cycle between an image and its alpha auxiliary image. The
 alpha edge was not covered by the cycle guard and re-entered a held
 mutex. (high)

CVE-2026-XXXXX (GHSA-w7mc-p8jc-p853) Heap out-of-bounds read in the
 YCbCr 4:2:0 to 16-bit interleaved RGB conversion when the chroma
 planes have a lower bit depth than luma. Heap memory could end up in
 the decoded image. YCbCr conversions with mismatched luma and chroma
 bit depths are now rejected. (high)

CVE-2026-XXXXX (GHSA-4jqm-2x34-6f6r) Heap buffer overflow in the SVT-AV1
 encoder plugin when encoding a high-bit-depth alpha channel, and a
 double free on its send-picture error path. (high)

CVE-2026-84451 (GHSA-hh47-fhqr-cj2r) Incomplete fix for
 GHSA-73p7-m7gg-w2jv: the tile range check of the unci decoder (without
 icef) could still overflow, allowing an out-of-bounds read. (medium)

CVE-2026-XXXXX (GHSA-4h82-g446-83fm) Heap out-of-bounds read when
 converting odd-height 4:2:0 frames of an uncompressed (uncv) image
 sequence to RGB. (medium)

CVE-2026-XXXXX (GHSA-9rj8-5mp5-26c9) Out-of-bounds read in the RGB to
 YCbCr identity-matrix color conversion when the R, G, and B planes
 have different bit depths. (medium)

CVE-2026-84450 (GHSA-gh5q-69gg-c964) A clap property combined with an
 oversized ispe reached an assert() in the Fraction arithmetic and
 aborted the process (incomplete fix for GHSA-jc8f-p23p-5hjg). An error
 is returned instead. (medium)

(GHSA-mw6f-29j3-76f4) Several smaller findings:
 heif_image_handle_get_depth_image_handle() and
 heif_image_handle_get_depth_image_representation_info() dereferenced a
 null pointer on files without a depth image; the TIFF input decoder of
 the example tools had an unbounded EXIF tag allocation and a division
 by zero on zero YCbCr subsampling; assert()s in the PNG input decoder
 are now error returns; integer overflow in the Go binding's
 ImageAccess.GetPlane(); heif-view now verifies the decoded frame size
 before display. (medium)

(GHSA-8857-r8x5-7499) Undefined behavior (negative shift) in the HDR
 bit-depth up-conversion for target bit depths above 16. Such
 conversions are now rejected. (low)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 12:05:25 +02:00
Bernd Kuhls
25b8142ef7 package/openvpn: security bump version to 2.7.7
https://github.com/OpenVPN/openvpn/blob/v2.7.7/Changes.rst

Fixes CVE-2026-84732, the other CVEs are Windows-only.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 12:00:27 +02:00
Marcus Hoffmann
edb18cf3f2 package/python-charset-normalizer: update package url
The old url redirects here.

Signed-off-by: Marcus Hoffmann <buildroot@bubu1.eu>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
2026-09-06 11:56:31 +02:00
Bernd Kuhls
98258e3064 package/llama-cpp: bump version to b10702
https://github.com/ggml-org/llama.cpp/releases

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 11:30:41 +02:00
Bernd Kuhls
64ed9e6c43 package/libcamera-apps: needs gcc >= 10
Buildroot commit 9a43bf6593 bumped the gcc
dependency from 9 to 10 but forgot to propagate this change to the
libcamera-apps package.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 11:28:21 +02:00
Bernd Kuhls
d2b7199dea package/qt5/qt5knx: fix license hash
Buildroot 262a7f6d2f added the package but
forgot to provide the hash for LICENSE.GPL3-EXCEPT, instead a hash for
a non-existing file was added to qt5knx.hash.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 11:23:20 +02:00
Peter Korsgaard
4a242e9e7a package/agec: bump version to 1.0.0
Largely a bugfix release.  Fixes an encryption issue if the cleartext was
exactly 8KB + N*64KB long.

https://git.sr.ht/~min/agec/refs/1.0.0

Drop now upstreamed 0001-io.c-isarmor-do-not-set-eof-for-35-byte-files.patch:

7a529662f9

Upstream renamed the agec-keygen utility to agecgen, so update the test to
match.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 11:11:32 +02:00
Raphaël Gallais-Pou
c5c0a76751 package/weston: bump version to 16.0.0
Release announce:
https://lore.freedesktop.org/wayland-devel/alXq76OX4dVWoP3M@xpredator/T/#u

Removed already-deprecated config options:
  * 'deprecated-backend-drm-screencast-vaapi' [1].
  * 'deprecated-shell-fullscreen' [2].
  * 'deprecated-screenshare' [3].

The 'pipewire' and 'remoting' plugins has been deprecated in [4].
They have already been removed in the main development branch in
upstream commit [5] and [6] (not yet in this version 16.0.0).

This commit removes the "remoting" option (rather than changing it to
"deprecated-remoting") because Buildroot was not enabling this option
and this deprecated option is now disabled by default.

This commit also removes the "pipewire" option (rather than changing
it to "deprecated-pipewire"). The commit log of [4] says the
replacement is the "pipewire-backend" option, which is already used
in Buildroot.

Tested on STM32MP157C-DK2.

[1] 7c3e3d7544
[2] 29b740ffee
[3] 3bd77f7817
[4] ec74bd0403
[5] 4606c49d28
[6] d587dfea5b

Signed-off-by: Raphaël Gallais-Pou <rgallaispou@gmail.com>
[Julien:
 - update link in hash file comment
 - add removed options in Config.in.legacy
 - add back package patch which is not included in release
 - reword commit log (fix and add links to upstream commits)
]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-06 10:52:15 +02:00
Fengwei Tan
9c6eed9ec0 support/testing, toolchain/toolchain-external/toolchain-external-bootlin: regenerate after MMU dependency update
Regenerate the Bootlin toolchain Kconfig and test configurations using
support/scripts/gen-bootlin-toolchains.

This adds BR2_USE_MMU to the affected uClibc entries and to the
architecture support conditions, and updates the generated tests.
The glibc and musl changes only reorder their existing BR2_USE_MMU
dependencies.

Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-05 20:50:26 +02:00
Fengwei Tan
3469c6793c support/scripts/gen-bootlin-toolchains: add missing BR2_USE_MMU dependencies
The Bootlin uClibc toolchains for m68k-68xxx, riscv32-ilp32d, and
xtensa-lx60 require an MMU. However, their generated Kconfig entries
lack a BR2_USE_MMU dependency, allowing them to be selected for noMMU
configurations. External toolchain validation then fails with:

  MMU support available in C library, please enable BR2_USE_MMU

Add the missing BR2_USE_MMU dependencies for these architectures to
prevent them from being selected for noMMU targets.

Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-05 20:50:25 +02:00
Fengwei Tan
9556895e78 toolchain/toolchain-external/toolchain-external-bootlin: drop duplicate BR2_TOOLCHAIN_HAS_THREADS selections
Regenerate the Bootlin toolchain Kconfig file with
support/scripts/gen-bootlin-toolchains to remove duplicate
BR2_TOOLCHAIN_HAS_THREADS selections.

Commit 184d47a7ad ("support/scripts/gen-bootlin-toolchains: add new
script to support Bootlin toolchains") initially introduced this issue.

Although commit a33e1af4a0 ("support/scripts/gen-bootlin-toolchains:
avoid selecting _HAS_THREADS multiple times") fixed the generator script,
the Config.in.options file was not regenerated accordingly.

This is a non-functional cleanup, as repeated Kconfig select statements
are harmless.

Signed-off-by: Fengwei Tan <tfx2001@outlook.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-05 20:50:24 +02:00
Francois Perrad
1f6e5d8836 package/luasql-sqlite3: bump to version 2.8.0
update homepage, Kepler Project is gone

diff doc/us/license.html: update copyright years and homepage

Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-05 18:27:45 +02:00
Francois Perrad
064e09e028 package/luajson: bump to version 1.3.5
Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-05 18:27:45 +02:00
Francois Perrad
ed4b68385d package/luafilesystem: bump to version 1.9.0
update homepage, Kepler Project is gone

diff LICENSE:
    -Copyright © 2003-2014 Kepler Project.
    +Copyright © 2003-2010 Kepler Project.
    +Copyright © 2010-2022 The LuaFileSystem authors.

Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-05 18:27:45 +02:00
Francois Perrad
173cfaf5a3 package/luadbi-sqlite3: bump to version 0.7.5
Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-05 18:27:45 +02:00
Francois Perrad
b0a256dfc5 package/luadbi: bump to version 0.7.5
Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-05 18:27:45 +02:00
Francois Perrad
196f186837 package/luabitop: bump to version 1.0.3
Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-05 18:27:45 +02:00
Francois Perrad
64c94ae884 package/lua-utf8: bump to version 0.2.1
Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-05 18:27:45 +02:00
Francois Perrad
a0db52966b package/lua-std-debug: bump to version 1.1.0
diff LICENSE.md: update copyright years
    -Copyright (C) 2002-2018 `std._debug` authors
    +Copyright (C) 2002-2026 `std._debug` authors

Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-05 18:27:45 +02:00
Francois Perrad
c3e961b5af package/lua-lrexlib-pcre2: bump to version 2.9.4
diff LICENSE: update copyright years

see changelog on https://github.com/rrthomas/lrexlib/blob/rel-2-9-4/NEWS

Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-05 18:27:45 +02:00
Francois Perrad
bdfdd430ae package/lua-datafile: bump to version 0.11
Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-05 18:27:45 +02:00
Francois Perrad
409f7867a7 package/lua-compat53: bump to version 0.15.1
Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-05 18:27:45 +02:00
Francois Perrad
87229b381a package/lsqlite3: bump to version 0.9.7
Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-05 18:27:45 +02:00
Francois Perrad
6fbe63e14c package/lua: bump to version 5.4.9
For differences with 5.4.8, see:
https://www.lua.org/work/diffs-lua-5.4.8-lua-5.4.9.html

Signed-off-by: Francois Perrad <francois.perrad.86@gmail.com>a
[Julien: add link to diff with previous version]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-05 18:26:29 +02:00
Bernd Kuhls
7b611fbd80 package/gnupg2: bump version to 2.5.22
https://lists.gnupg.org/pipermail/gnupg-announce/2026q3/000509.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-05 17:13:25 +02:00
Bernd Kuhls
6910dbda29 package/libksba: bump to version 1.8.1
https://github.com/gpg/libksba/blob/libksba-1.8.1/NEWS
https://dev.gnupg.org/T8253

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-05 17:13:25 +02:00
Bernd Kuhls
627c482434 package/libgcrypt: bump version to 1.12.3
Release notes:
https://lists.gnupg.org/pipermail/gnupg-announce/2026q3/000508.html

Contains a number of bugfixes, some of which may have (low severity)
security impact.  As stated by Werner Koch:

 All in all we received 26 reports alone from ANSSI but as even the reporter
 mentioned, the real world attack severity is not critical.  Thus we don't
 consider 1.12.3 a security fix release.  There are some bugs which should
 be fixed to avoid crashes, and thus may lead to DoS.  However, 16384 bit
 RSA keys can also be used for a practical DoS; it all depends on your use
 case.

https://www.openwall.com/lists/oss-security/2026/08/31/11

Added upstream patch to fix a build error introduced by this bump that
was detected by the Gitlab pipelines:

sm4-intel-avx512-amd64.S: Assembler messages:
sm4-intel-avx512-amd64.S:138: Error: operand size mismatch for `vsm4rnds4'

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
[Julien: add extra info in commit log from Peter original submission from
 https://lore.kernel.org/buildroot/20260901192724.1021544-1-peter@korsgaard.com/
]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-05 17:09:02 +02:00
Franciszek Stachura
0e631348db support/testing: add nano test
Add a basic runtime test for nano. The test attempts to write a file
using the editor.

Signed-off-by: Franciszek Stachura <fbstachura@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-05 16:06:18 +02:00
Franciszek Stachura
967380b316 package/nano: bump to version 9.2
Changelog:
https://www.nano-editor.org/dist/v9/ChangeLog
Signed-off-by: Franciszek Stachura <fbstachura@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-05 16:06:11 +02:00
Chris Obbard
99529edaef package/dtui: require 64-bit atomic support
dtui depends on tui-textarea which unconditionally imports AtomicU64 in
src/widget.rs to pack a viewport rectangle into a single atomic word:

  use std::sync::atomic::{AtomicU64, Ordering};
  pub struct Viewport(AtomicU64);

As there is no cfg(target_has_atomic) guard in tui-textarea, its
build fails on any target for which rustc does not provide 64-bit
atomics with:

  Compiling tui-textarea v0.7.0
  error[E0432]: unresolved import `std::sync::atomic::AtomicU64`
    --> .../dtui-3.0.0/VENDOR/tui-textarea/src/widget.rs:10:25
     |
  10 | use std::sync::atomic::{AtomicU64, Ordering};
     |                         ^^^^^^^^^ no `AtomicU64` in `sync::atomic`
     |
  help: a similar name exists in the module
     |
  10 - use std::sync::atomic::{AtomicU64, Ordering};
  10 + use std::sync::atomic::{AtomicU32, Ordering};

This has been reported to tui-textarea upstream, but unfortunately the
project seems to be unmaintained (issue linked below). A sane workaround
is to disable the package on targets which lack 64-bit atomic support,
which is exactly what BR2_PACKAGE_HOST_RUSTC_TARGET_HAS_ATOMIC_U64
describes: it is n for armv5te-unknown-linux-{gnu,musl}eabi and
powerpc-unknown-linux-gnu, the only rust targets Buildroot can generate
which lack 64-bit atomics, and y everywhere else.

The same problem was hit by package/dust and worked around in commit
3abc3b97ba ("package/dust: bump to version 1.1.2") by bumping to a
version in which upstream had added the missing guard. That is not an
option here as tui-textarea 0.7.0 is the latest release.

Note that a runtime test for dtui cannot use the default
infra.basetest.BASIC_TOOLCHAIN_CONFIG, since that builds with
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV5_EABI_GLIBC_STABLE, where dtui is now
disabled; such a test would need an armv7 or aarch64 toolchain instead.

Build tested with utils/test-pkg against:
- BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV5_EABI_GLIBC_STABLE
- BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV5_EABI_MUSL_STABLE
- BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_POWERPC_E500MC_GLIBC_STABLE

all three fail with the above error before this change and are skipped
after it, while armv7 (glibc and musl), aarch64, powerpc64le and x86-64
still select and build the package.

Link: https://github.com/rhysd/tui-textarea/issues/66
Fixes: https://autobuild.buildroot.org/results/188f6442371500731453f75983590c922eab6d57
Fixes: https://autobuild.buildroot.org/results/e254db2654f18f1d2110eb8b1a32b43ad0f2a3d6
Signed-off-by: Christopher Obbard <chris.obbard@oss.qualcomm.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-05 15:53:04 +02:00
Chris Obbard
698535473f package/rustc: add BR2_PACKAGE_HOST_RUSTC_TARGET_HAS_ATOMIC_U64
Rust does not provide 64-bit atomics on every target Buildroot can
generate. rustc sets max_atomic_width = 32 for three of the 25 targets
listed in RUST_TARGETS in utils/update-rust, so
core::sync::atomic::AtomicU64 and AtomicI64 simply do not exist there:

  $ rustc --print cfg --target <target> | grep target_has_atomic
  armv5te-unknown-linux-gnueabi     "16" "32" "8" "ptr"
  armv5te-unknown-linux-musleabi    "16" "32" "8" "ptr"
  powerpc-unknown-linux-gnu         "16" "32" "8" "ptr"

Every other supported target, including armv6, armv7, aarch64, all the
x86 variants, riscv64, s390x, sparc64 and both 64-bit powerpcs, has
them, e.g.:

  arm-unknown-linux-gnueabi         "16" "32" "64" "8" "ptr"
  armv7-unknown-linux-gnueabihf     "16" "32" "64" "8" "ptr"

A crate that uses 64-bit atomics without a cfg(target_has_atomic = "64")
guard therefore fails to build on those three targets with:

  error[E0432]: unresolved import `std::sync::atomic::AtomicU64`
     |
     |         atomic::{AtomicU64, AtomicU8, AtomicUsize, Ordering},
     |                  ^^^^^^^^^ no `AtomicU64` in `sync::atomic`

This has been hit at least twice already: by package/dust, worked around
in commit 3abc3b97ba ("package/dust: bump to version 1.1.2") by moving
to a release in which upstream had added the guard and by package/dtui,
which has no such release available and had to open-code the affected
architectures instead.

It is likely to keep recurring: infra.basetest.BASIC_TOOLCHAIN_CONFIG
builds with BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV5_EABI_GLIBC_STABLE, so
every runtime test that does not override the toolchain compiles for
armv5te, one of the three affected targets. That is exactly how the two
failures above were found.

Add a hidden symbol so packages can express this constraint once, rather
than each open-coding BR2_ARM_CPU_ARMV5 and BR2_powerpc and needing to
update whenever rust gains or changes a target.

Note that armv5te and 32-bit powerpc are only supported by rust for
glibc and musl, so the uclibc variants of those architectures are
already excluded by BR2_PACKAGE_HOST_RUSTC_TARGET_ARCH_SUPPORTS.

Signed-off-by: Christopher Obbard <chris.obbard@oss.qualcomm.com>
Reviewed-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-05 15:52:15 +02:00
Michael Nosthoff
7209f55cd2 package/gtest: bump to version 1.18.0
changelog:
https://github.com/google/googletest/releases/tag/v1.18.0

Signed-off-by: Michael Nosthoff <buildroot@heine.tech>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-05 15:49:59 +02:00
Michael Nosthoff
a7652a2f48 package/catch2: bump to version 3.16.0
changelog:
https://github.com/catchorg/Catch2/releases/tag/v3.16.0

Signed-off-by: Michael Nosthoff <buildroot@heine.tech>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-09-05 15:49:00 +02:00
Bernd Kuhls
ab9097227c package/rrdtool: bump version to 1.11.0
https://github.com/oetiker/rrdtool-1.x/blob/v1.11.0/CHANGES

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
2026-09-05 11:47:22 +02:00
Bernd Kuhls
270ef20df1 package/libxml2: security bump version to 2.15.4
https://download.gnome.org/sources/libxml2/2.15/libxml2-2.15.4.news

Fixes the following security issues:

- xmlregexp: Prevent out-of-bounds read in NXT macro
- fix: add missing overflow checks in dict.c, uri.c, and valid.c
- xmlregexp: Calc string length after null checking
- xpointer: Check overflow in xmlXPtrEvalXPtrPart
- xmlIO: Check for int overflow before calling writecallback
- fix(xinclude): propagate parseFlags in xmlXIncludeProcess and
  xmlXIncludeProcessTree

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
2026-09-05 11:47:22 +02:00
Bernd Kuhls
47c45f7f62 package/wireless-regdb: bump version to 2026.09.03
https://lists.infradead.org/pipermail/wireless-regdb/2026-September/001953.html

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
2026-09-04 22:43:52 +02:00
Martin Bachmann
df61b7e9bb package/dejavu: add missing license information
DEJAVU_LICENSE is primarily BitstreamVera. The license file also
specifies that DejaVu-specific changes and certain math extensions are
in the Public Domain. This matches the licensing logic used by
OpenEmbedded/Yocto.

Signed-off-by: Martin Bachmann <martin.bachmann@designwerk.com>
[Fiona: wrap lines in commit message]
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
2026-09-04 22:37:32 +02:00
Peter Korsgaard
5f26877955 Merge branch 'next'
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-04 18:18:19 +02:00
Peter Korsgaard
db652bbaba Kickoff 2026.11 cycle
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-04 18:17:01 +02:00
Peter Korsgaard
91a2916a97 docs/website/news.html: add 2026.08 announcement link
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-04 18:16:22 +02:00
Neal Frager
f92220f16b board/xilinx: remove xilinx_2026.1/linux.hash
Now that all Xilinx boards have been bumped to Linux 6.18.40, remove the hash
for the xlnx_rebase_v6.18_LTS_2026.1 release tag.

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-01 20:11:39 +02:00
Neal Frager
6c3c5f8728 configs/versal2_*: bump to Linux 6.18.40
Bump the versal2 defconfig to Linux 6.18.40.

Run tested on a versal2 vek385 evaluation board.

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-01 20:11:27 +02:00
Neal Frager
0dae674d98 configs/versal_*: bump to Linux 6.18.40
Bump the versal defconfigs to Linux 6.18.40.

Run tested on a versal vek280 evaluation board.

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-01 20:10:43 +02:00
Neal Frager
b1009287df configs/zynqmp_*: bump to Linux 6.18.40
Bump the zynqmp defconfigs to Linux 6.18.40.

Run tested on a zynqmp zcu102 evaluation board.
Run tested on a kria kv260 evaluation board.

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-01 20:10:12 +02:00
Neal Frager
cfd58dedd1 configs/zynq_*: bump to Linux 6.18.40
Bump the zynq defconfigs to Linux 6.18.40.

Run-tested on a ZC702 Evaluation Board.

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-01 20:09:49 +02:00
Neal Frager
1a87a2669d board/xilinx: add Linux 6.18.40 hash
Add the hash for the Xilinx Linux 6.18.40 release tag.

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-09-01 20:09:29 +02:00
Christian Stewart
798741f4dc package/go: new major version 1.27
Bump to go1.27.0. The go-bootstrap-stage5 package (go1.25.x) still
satisfies the bootstrap requirement, so no bootstrap stage changes are
needed.

Remove the workaround for https://github.com/golang/go/issues/77436,
which the go.mk comment scheduled for removal at this bump: restore the
plain CGO_CFLAGS and CGO_CXXFLAGS settings in HOST_GO_TARGET_ENV.

https://go.dev/doc/go1.27#bootstrap

Signed-off-by: Christian Stewart <christian@aperture.us>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-31 22:00:08 +02:00
Mattia Narducci
ed881dfca7 package/ser2net: bump version to 4.6.8
Changelog: https://sourceforge.net/p/ser2net/news

Updated licenses hashes due to upstream commit:
2bc83f0954

Drop patch 0001 that was a backport of a upstream security fix.

Add a upstream patch to fix build against uClibc.

Signed-off-by: Mattia Narducci <mattianarducci1@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-30 00:15:38 +02:00
Mattia Narducci
1982fdeaa4 package/gensio: add portaudio optional dependency
Portaudio is an optional dependency which is enabled by default since
version 2.7.3 when alsa-lib is not available:
71eef5e3ce

Signed-off-by: Mattia Narducci <mattianarducci1@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:57:00 +02:00
Mattia Narducci
e9c340a394 package/gensio: add udev optional dependency
Udev is an optional dependency used to directly control cm108 sound
device gpios. It is enabled by default since version 2.6.3:
c1b5c0a214

Signed-off-by: Mattia Narducci <mattianarducci1@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:56:53 +02:00
Mattia Narducci
9c18b1668b package/gensio: bump version to 3.0.4
Changelog: https://sourceforge.net/p/ser2net/news

Static builds are no longer supported starting with version 2.6.0 [1]
even when compiling all modules (gensios) in the library.

Updated licenses hashes due to upstream commit:
859e4465cf

Removed patch 0001 which is now upstream.

[1] 7b3786f5fb

Signed-off-by: Mattia Narducci <mattianarducci1@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:54:47 +02:00
Alexis Lothoré via buildroot
6851345aa8 package/erlang: fix link failure on odbcserver
host-erlang build can fail with the following error:

  make[5]: Nothing to be done for 'opt'.
   MAKE	opt
   CC	../priv/bin/x86_64-pc-linux-gnu/odbcserver
  /usr/bin/ld: ../priv/obj/x86_64-pc-linux-gnu/odbcserver.o: in function `encode_column_dyn':
  odbcserver.c:(.text+0x6b4): undefined reference to `ei_x_encode_tuple_header'
  /usr/bin/ld: odbcserver.c:(.text+0x6c2): undefined reference to `ei_x_encode_tuple_header'
  /usr/bin/ld: odbcserver.c:(.text+0x6d4): undefined reference to `ei_x_encode_ulong'
  /usr/bin/ld: odbcserver.c:(.text+0x6e7): undefined reference to `ei_x_encode_ulong'
  /usr/bin/ld: odbcserver.c:(.text+0x6fa): undefined reference to `ei_x_encode_ulong'
  /usr/bin/ld: odbcserver.c:(.text+0x708): undefined reference to `ei_x_encode_tuple_header'
  /usr/bin/ld: odbcserver.c:(.text+0x71b): undefined reference to `ei_x_encode_ulong'
  /usr/bin/ld: odbcserver.c:(.text+0x72e): undefined reference to `ei_x_encode_ulong'
  [...]

This can be reproduced with the following minimal defconfig (and
libei.so present on host, see details below):

  BR2_x86_64=y
  BR2_TOOLCHAIN_EXTERNAL=y
  BR2_PACKAGE_ERLANG=y

Those missing symbols are part of the erl_interface, exposed by libei.a.
host-erlang builds correctly libei.a _before_ odbcserver.c (it can be
found in lib/erl_interface/obj/x86_64-pc-linux-gnu/libei.a), but the
failure is actually due to the build command generated and used for
odbcserver.c, especially the link arguments:

  /usr/bin/gcc \
  [...]
  -o ../priv/bin/x86_64-pc-linux-gnu/odbcserver \
  ../priv/obj/x86_64-pc-linux-gnu/odbcserver.o \
  -L/usr/lib64 \
  -lodbc \
  -L/home/alexis/src/buildroot/erlang-master/build/host-erlang-custom/lib/erl_interface/obj/x86_64-pc-linux-gnu \
  -lpthread -lei

/usr/lib64 is searched before the path where libei.a has been built, so
if whether a valid libei.a or libei.so is found there, it shadows the
expected libei.a. In the build from which the logs above come, the
notable point is that the host system indeed have a valid libei.so, but
is completely unrelated to erl_interface; it rather exposes the Emulated
Input protocol aimed at Wayland stack; and so it obviously contains none
of the expected ei_* symbols.

Upstream has already identified and fixed the issue, the fix is already
released in versions >= 27.x.y. Erlang 26 (the version currently
packaged in buildroot), isn't supported anymore (only the three latest
releases are supported, see
https://github.com/erlang/otp/blob/master/SECURITY.md), so there won't
be any new minor update that will release this fix.

Pick and backport the fixing patch so that the current version packaged
in buildroot can still build.

The issue affects 2025.02.x, 2026.05.x and master.

Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:08:37 +02:00
Alexis Lothoré via buildroot
2c36fe80fe package/qt5: relax openssl constraint to allow compatible implementations
Qt5 can be built with or without openssl support. Following some build
failures, commit a94d39d693 ("package/qt5: fix build failure due to
libressl use") enforced libopenssl as the only valid implementation for
Qt5 openssl support.

While this solution is fine to filter between the two openssl variants
officially supported by Buildroot, it prevents users bringing their own
OpenSSL implementations (through the virtual package mechanism) from
building Qt5 with openssl support, even if the custom implementation
matches the expected OpenSSL API.

Allow compatible external implementations to be provided for Qt5 openssl
support. Relax the constraint by partially reverting a94d39d693 and
checking that the selected openssl implementation isn't libressl. It
then becomes up to users to ensure that the implementation they are
providing is fully compatible with libopenssl's. Some qt5
sub-packages enforce BR2_PACKAGE_OPENSSL_FORCE_LIBOPENSSL, they don't
need any update as it does not really strictly select libopenssl, it
rather prevents libressl, so it still allows custom providers.

Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:05:36 +02:00
Alexander Shirokov
f48ae88805 package/broot: bump to version 1.59.0
Changelog: https://github.com/Canop/broot/blob/v1.59.0/CHANGELOG.md

Signed-off-by: Alexander Shirokov <shirokovalexs@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-28 14:03:48 +02:00
Giulio Benetti
7e6e19e97b package/harfbuzz: bump version to 14.4.0
https://github.com/harfbuzz/harfbuzz/blob/14.4.0/NEWS

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-28 13:46:32 +02:00
Giulio Benetti
323f7e8492 package/libnss: bump version to 3.127
Rework local patch

For release note, see:
8c4f491f67/doc/src/releases/nss_3_127.md

NOTE: libnss version 3.127 requires libnspr version 4.39.

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
[Julien: fix libnspr version typo in commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-25 23:17:12 +02:00
Giulio Benetti
4221e786e0 package/libnspr: bump to version 4.39
Changelog:
54e7c1b080

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-25 23:08:29 +02:00
Adrian Perez de Castro
009d34015b package/libpsl: bump to version 0.23.3
The most relevant change is included in 0.23.0, which fixed handling
of trailing dots (so e.g. "co.uk" and "co.uk." are treated as the same
suffix). Otherwise, it's mostly cleanups and support for non-Linux
platforms:

  https://github.com/rockdaboot/libpsl/releases/tag/0.22.0
  https://github.com/rockdaboot/libpsl/releases/tag/0.23.0
  https://github.com/rockdaboot/libpsl/releases/tag/0.23.2
  https://github.com/rockdaboot/libpsl/releases/tag/0.23.3

The COPYING license file was changed to a symlink to LICENSE.
The changed hash for the license file does not imply a license change:
it is unchanged, but the copyright year was removed in favor of a note
telling to check the Git history. See:
da54796618

Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
[Julien:
 - rename COPYING license file to LICENSE
 - add extra info in commit log
]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-25 22:44:09 +02:00
Alexander Shirokov
a8dd506faa package/zellij: bump to version 0.45.0
Changelog: https://github.com/zellij-org/zellij/blob/v0.45.0/CHANGELOG.md

Signed-off-by: Alexander Shirokov <shirokovalexs@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-24 23:37:22 +02:00
Luca Ceresoli
3d6c68d625 package/heaptrack: new package
Add heaptrack, a memory allocation tracer toolkit.

This implementation builds all the command line components, not the
heaptrack_gui graphical visualization program.

Signed-off-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-24 21:52:41 +02:00
Petr Vorel
a0c0208e1b package/nfs-utils: bump version to 2.9.2
Remove patches upstreamed in this release.

Release announce:
https://lore.kernel.org/linux-nfs/dc0f6f41-84be-4a70-92db-89890bded3ab@redhat.com/

Backport 3 patches from upstream fixing this release regressions:

* 67ed1bdb ("exportfs: link failure with --disable-nfsdctl")
* cec8eeb6 ("getport: fix missing stddef.h inclusion")
* cf80edae ("statd: fix memory leak in sm_mon_1_svc() when existing host re-monitors")

And 4th patch which fixes error on old toolchains, e.g.
br-arm-full-static or bootlin-aarch64-glibc-old.

Signed-off-by: Petr Vorel <petr.vorel@gmail.com>
[Julien: fix check-package errors]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-22 15:24:04 +02:00
José Luis Salvador Rufo
43cbd2b46a package/zfs: bump version to 2.4.4
For release note, see:
https://github.com/openzfs/zfs/releases/tag/zfs-2.4.4

Signed-off-by: José Luis Salvador Rufo <salvador.joseluis@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-22 13:14:32 +02:00
Giulio Benetti
bdd74f011f package/bind: bump version to 9.20.27
https://downloads.isc.org/isc/bind9/9.20.27/doc/arm/html/notes.html#notes-for-bind-9-20-27
https://downloads.isc.org/isc/bind9/9.20.27/doc/arm/html/changelog.html

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-22 12:45:30 +02:00
Thomas Petazzoni
0a91e760f4 package/igh-ethercat: bump to 1.6.12
The two patches are upstream, so they can be dropped.

From NEWS.md:

Version 1.6.12

- Backported CCAT fixes from Beckhoff

Version 1.6.11

- Protect datagram receiving mechanism against re-ordering
- Prevent creating datagrams that are too large for one frame
- Reacted to stmmac API changed during Linux 6.12
- Adapted debug ring to kernel 5.6+ time API changes
- Use str.read() to read into char* (deprecated in C++20)
- Unload `ec_bhf` before loading CCAT
- Added cpplint checks in pre-commit and CI tests.
- Improved and formatted markdown documents and added pre-commit checks

Version 1.6.10

- Added RasPi 5 macb (Cadence GEM / RP1) driver for kernel 6.18.
- Added igb and igc for kernel 6.8
- Security fixes against malicious subdevices
  - Protected `rec_size` calculation in FoE.
  - Check for malicious EoE frame details.
- Avoid writing invalid MAC onto r8169 NIC on removal
- Fixed insufficient re-allocation of SoE request buffer.

Version 1.6.9

- Protect datagram injection mechanism against re-ordering.
- Fixed for genet and igb drivers for openSUSE Leap 16.0 kernel 6.12.
- tty: Implemented new timer interface since kernel 6.15.
- Do not require .config to exist in kernel sources.
- Fix: Attach slaves before calculating DCs.
- Discard EoE traffic in CoE statemachine, if EoE is disabled.
- Support for Linux 6.19
- Added `--with-kmod-dir` and `--with-ip-cmd` configuration switches
  to specify the paths of the tools used in the `ethercatctl` script.
- Changed the default path of the `ip` command to `/sbin/ip`.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-21 22:29:18 +02:00
Thomas Petazzoni
8a5fc970b4 package/igh-ethercat: backport upstream fix to build with Linux >= 6.19.0
Fixes:

  https://autobuild.buildroot.org/results/9b270904b2f7cf9eaa661c98370c582a61ff2342/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit e4cf512c39)
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-21 22:29:18 +02:00
715 changed files with 9499 additions and 6715 deletions

View File

@@ -380,7 +380,6 @@ package/gdb/17.1/0007-fix-musl-build-on-riscv.patch lib_patch.Upstream
package/gdb/17.1/0008-gdbserver-Makefile.in-fix-NLS-build.patch lib_patch.Upstream
package/gdb/17.1/0009-gdb-Fix-native-build-on-xtensa.patch lib_patch.Upstream
package/genpart/0001-fix-return-code.patch lib_patch.Upstream
package/gensio/0001-Fix-missing-EVP_PKEY_ED25519-build-error-on-libressl.patch lib_patch.Upstream
package/gerbera/S99gerbera lib_sysv.Indent
package/git-crypt/0001-fix-build-with-libressl-3.5.0.patch lib_patch.Upstream
package/glorytun/0001-Add-support-for-Apple-silicon.patch lib_patch.Upstream
@@ -403,10 +402,6 @@ package/hplip/0001-build-use-pkg-config-to-discover-libusb.patch lib_patch.Upstr
package/hplip/0002-configure.in-fix-AM_INIT_AUTOMAKE-call.patch lib_patch.Upstream
package/i2pd/S99i2pd Shellcheck lib_sysv.Indent lib_sysv.Variables
package/i7z/0001-fix-build-with-gcc-10.patch lib_patch.Upstream
package/ibm-sw-tpm2/0001-Use-LONG_BIT-to-define-RADIX_BITS.patch lib_patch.Upstream
package/ibrcommon/0001-ibrcommon-data-File.cpp-support-POSIX-basename-call.patch lib_patch.Upstream
package/ibrcommon/0002-ibrcommon-added-openssl-1.1-compatibility-264.patch lib_patch.Upstream
package/ibrcommon/0003-ibrcommon-ssl-gcm-fix-static-build-with-openssl.patch lib_patch.Upstream
package/icu/0001-dont-build-static-dynamic-twice.patch lib_patch.Upstream
package/icu/0002-link-icudata-as-data-only.patch lib_patch.Upstream
package/icu/0003-fix-static-linking-with-icu-uc.patch lib_patch.Upstream
@@ -507,8 +502,6 @@ package/libnfc/0001-autotools-make-example-build-optional.patch lib_patch.Upstre
package/libnss/0001-Bug-1801182-Allow-overriding-OS_ARCH-OS_TEST-and-OS_.patch lib_patch.Upstream
package/libodb-mysql/0001-fix-syntax-issue-while-checking-ldflags.patch lib_patch.Upstream
package/libodb-mysql/0002-mariadb-FTBFS-fix.patch lib_patch.Upstream
package/libopenssl/0001-Reproducible-build-do-not-leak-compiler-path.patch lib_patch.Upstream
package/libopenssl/0002-Configure-use-ELFv2-ABI-on-some-ppc64-big-endian-sys.patch lib_patch.Upstream
package/liboping/0001-fix-utf8-support.patch lib_patch.Upstream
package/liboping/0002-Open-raw-sockets-when-adding-hosts-not-when-doing-th.patch lib_patch.Upstream
package/liboping/0003-Fix-compile-break-with-GCC-7-buffer-overflow-with-snprintf.patch lib_patch.Upstream
@@ -552,7 +545,6 @@ package/lirc-tools/0001-plugins-devinput.c-fix-build-with-musl-1.2.0.patch lib_p
package/lirc-tools/0002-configure-add-disable-doc-option.patch lib_patch.Upstream
package/lirc-tools/S25lircd lib_sysv.Indent lib_sysv.Variables
package/live555/0001-Add-a-pkg-config-file-for-the-shared-libraries.patch lib_patch.Upstream
package/lldpd/S60lldpd Shellcheck lib_sysv.Indent lib_sysv.Variables
package/lm-sensors/0001-no-host-ldconfig.patch lib_patch.Upstream
package/lmbench/0001-scripts-build-use-bin-bash-as-shell.patch lib_patch.Upstream
package/lmbench/0002-src-Makefile-add-lmbench-to-list-of-executables.patch lib_patch.Upstream
@@ -564,7 +556,6 @@ package/ltrace/0002-sparc-add-missing-library.h-include.patch lib_patch.Upstream
package/lttng-babeltrace/0001-tests-lib-Makefile.am-remove-unneeded-static-flag.patch lib_patch.Upstream
package/lttng-babeltrace/0002-configure.ac-fix-popt-static-build.patch lib_patch.Upstream
package/lttng-libust/0001-configure.ac-add-disable-tests.patch lib_patch.Upstream
package/lttng-tools/0001-configure.ac-add-disable-tests.patch lib_patch.Upstream
package/lua-gd/0001-Protect-declaration-of-LgdImageCreateFromPng-with-GD.patch lib_patch.Upstream
package/lua-lunix/0001-remove-link-with-librt.patch lib_patch.Upstream
package/lua-sdl2/0001-Do-not-reference-host-directory-for-headers.patch lib_patch.Upstream
@@ -615,7 +606,6 @@ package/mono/0002-Ongoing-work-on-the-cmake-build.patch lib_patch.Upstream
package/motion/S99motion Shellcheck lib_sysv.Indent lib_sysv.Variables
package/mpir/0001-mpn-arm-udiv.asm-workaround-binutils-bug-14887.patch lib_patch.Upstream
package/mraa/0001-include-Declare-gVERSION-global-as-extern.patch lib_patch.Upstream
package/mrouted/S41mrouted NotExecutable
package/mrp/S65mrp lib_sysv.Indent lib_sysv.Variables
package/multipath-tools/S60multipathd Shellcheck
package/musl/0001-avoid-kernel-if_ether.h.patch lib_patch.Upstream

185
CHANGES
View File

@@ -69,6 +69,102 @@
Removed packages: argparse, ts4900-fpga
2026.05.3, released September 10, 2026
Important / security related fixes:
avro-c: (no CVE assigned)
dnsmasq: CVE-2026-12725, CVE-2026-12969
erlang: CVE-2026-21620, CVE-2026-23941, CVE-2026-23942, CVE-2026-23943,
CVE-2026-28810, CVE-2026-32147, CVE-2026-42789, CVE-2026-42790
exiv2: CVE-2026-49275, CVE-2026-68546, CVE-2026-68547,
GHSA-3695-mjv8-3r52, GHSA-9v3x-mhg4-wwv2, GHSA-fgw8-p7pr-37cp,
GHSA-hxph-pv7w-8649, GHSA-jcgh-p9v3-pw6j, GHSA-vg6c-9f6h-4x5q
expat: CVE-2026-66046, CVE-2026-76641, CVE-2026-76956, CVE-2026-76957
glibc: CVE-2026-18374, CVE-2026-19499, CVE-2026-77117, CVE-2026-80489
go: CVE-2026-33818, CVE-2026-39821, CVE-2026-46600, CVE-2026-56853,
CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862,
CVE-2026-56864, CVE-2026-56865
haproxy: (no CVE assigned)
hostapd: CVE-2026-58374
libcurl: CVE-2026-13608, CVE-2026-18924, CVE-2026-19931,
CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255,
CVE-2026-82208, CVE-2026-82209
libde265: GHSA-mm7m-v26f-wf8x, GHSA-xp3h-6f5r-8cxp
libgit2: CVE-2026-5917
libheif: CVE-2026-84450, CVE-2026-84451, GHSA-24wx-9w62-c96w,
GHSA-2jg2-4ch7-h545, GHSA-4h82-g446-83fm, GHSA-4jqm-2x34-6f6r,
GHSA-73p7-m7gg-w2jv, GHSA-8857-r8x5-7499, GHSA-8fmq-r4pf-7m57,
GHSA-9rj8-5mp5-26c9, GHSA-g89c-p67h-r497, GHSA-gh5q-69gg-c964,
GHSA-hh47-fhqr-cj2r, GHSA-j264-xvrp-5v7q, GHSA-jc8f-p23p-5hjg,
GHSA-mw6f-29j3-76f4, GHSA-p58j-h3vm-3fp5, GHSA-w7mc-p8jc-p853,
GHSA-x8r2-mggj-j6wr, GHSA-x8xm-cm2c-cfc8, GHSA-xw34-mjcp-jqh8
libldns: CVE-2026-10846
libopenssl: CVE-2026-14456, CVE-2026-14457, CVE-2026-18798,
CVE-2026-54874, CVE-2026-54876, CVE-2026-63072, CVE-2026-63073,
CVE-2026-63074, CVE-2026-63075, CVE-2026-63076, CVE-2026-75803
libssh2: CVE-2025-15661, CVE-2026-66032, CVE-2026-66033,
CVE-2026-66034, CVE-2026-66035
localedef: CVE-2026-18374, CVE-2026-19499, CVE-2026-77117,
CVE-2026-80489
mongoose: CVE-2026-63626, CVE-2026-73251, CVE-2026-73252,
CVE-2026-73260, CVE-2026-73261
nodejs: CVE-2026-56846, CVE-2026-56847, CVE-2026-56848, CVE-2026-56850,
CVE-2026-58039, CVE-2026-58040, CVE-2026-58042, CVE-2026-58043,
CVE-2026-58044, CVE-2026-58045
openvpn: CVE-2026-84732
proftpd: CVE-2026-44331
putty: (no CVE assigned)
python-avro: (no CVE assigned)
redis: CVE-2026-62356
rsyslog: CVE-2026-19654
udisks: CVE-2026-7867, GHSA-j42g-v9jw-6ph3
unbound: CVE-2026-14586, CVE-2026-32665, CVE-2026-40622,
CVE-2026-40691, CVE-2026-41637, CVE-2026-42955, CVE-2026-44621,
CVE-2026-44687, CVE-2026-44690, CVE-2026-46582, CVE-2026-50045,
CVE-2026-50046, CVE-2026-50243, CVE-2026-50248, CVE-2026-50251,
CVE-2026-50252, CVE-2026-52863, CVE-2026-54478, CVE-2026-55708,
CVE-2026-55717, CVE-2026-55973, CVE-2026-55990, CVE-2026-55991,
CVE-2026-56416, CVE-2026-56444
wget: CVE-2026-58469, CVE-2026-58470, CVE-2026-58471
wireshark: CVE-2026-15163, CVE-2026-15164, CVE-2026-15166,
CVE-2026-15167, CVE-2026-15168, CVE-2026-15169, CVE-2026-15170,
CVE-2026-15171, CVE-2026-15172, CVE-2026-15174, CVE-2026-76879,
CVE-2026-76880, CVE-2026-76881, CVE-2026-76882, CVE-2026-76883,
CVE-2026-76884, CVE-2026-76885, CVE-2026-76886, CVE-2026-76887,
CVE-2026-76888, CVE-2026-76889, CVE-2026-76890, CVE-2026-76891,
CVE-2026-76917, CVE-2026-76918, CVE-2026-76919, CVE-2026-76920,
CVE-2026-76921, CVE-2026-76922, CVE-2026-76923, CVE-2026-76924,
CVE-2026-76926, CVE-2026-76927, CVE-2026-76928, CVE-2026-76929
Toolchain:
- linux-headers: bump to 5.10.269, 5.15.220, 6.1.187, 6.6.156,
6.12.109, 6.18.50
- powerpc: correctly track libquadmath
Infrastructure updates/fixes:
- Fix setting of stack size for FLAT binaries
- Various fixes to the runtime tests
- manual: document the LTS release cadence correctly
- manual: document move of patchwork to patchwork.buildroot.org
Updated defconfigs: qemu_xtensa_lx60*
Updated / fixed packages: avro-c, bind, bpftrace, clamav, collectd,
dahdi-linux, dejavu, distribution-registry, dnsmasq, dpdk, dracut,
enscript, erlang, exiv2, expat, gdb, glibc, go, haproxy, hostapd,
igh-ethercat, jpeg-turbo, libbpf, libcurl, libde265, libgit2,
libheif, libldns, libnfs, libopenssl, libssh2, libxkbcommon,
libxml-parser-perl, libxml2, linux, linux-headers, linux-tools,
localedef, mesa3d, mongoose, netsnmp, newt, nodejs, olsr, opencv4,
openssh, openvpn, passt, perl, powerpc, proftpd, putty, python-avro,
python-charset-normalizer, python-gobject, qt5knx, qt6, qt6base,
qt6declarative, redis, rsyslog, taglib, toolchain-external-bootlin,
uclibc, udisks, uhttpd, unbound, vim, webkitgtk, wget, wine,
wireless-regdb, wireshark, xilinx-embeddedsw
2026.05.2, released August 23, 2026
Important / security related fixes:
@@ -1775,6 +1871,95 @@
- netsnmp: unexpected header length in /proc/net/snmp...
https://gitlab.com/buildroot.org/buildroot/-/issues/110
2025.02.18, released September 10, 2026
Important / security related fixes:
avro-c: (no CVE assigned)
clamav: CVE-2026-20031, CVE-2026-20213, CVE-2026-20214, CVE-2026-20215,
CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244,
CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347,
CVE-2026-20348
dnsmasq: CVE-2026-12725, CVE-2026-12969
erlang: CVE-2026-21620, CVE-2026-23941, CVE-2026-23942, CVE-2026-23943,
CVE-2026-28810, CVE-2026-32147, CVE-2026-42789, CVE-2026-42790
exiv2: CVE-2026-49275, CVE-2026-68546, CVE-2026-68547,
GHSA-3695-mjv8-3r52, GHSA-9v3x-mhg4-wwv2, GHSA-fgw8-p7pr-37cp,
GHSA-hxph-pv7w-8649, GHSA-jcgh-p9v3-pw6j, GHSA-vg6c-9f6h-4x5q
expat: CVE-2026-66046, CVE-2026-76641, CVE-2026-76956, CVE-2026-76957
glibc: CVE-2026-18374, CVE-2026-19499, CVE-2026-5435, CVE-2026-6238,
CVE-2026-6368, CVE-2026-6791, CVE-2026-77117, CVE-2026-80489
go: CVE-2026-33818, CVE-2026-39821, CVE-2026-46600, CVE-2026-56853,
CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862,
CVE-2026-56864, CVE-2026-56865
haproxy: (no CVE assigned)
hostapd: CVE-2026-58374
libcurl: CVE-2026-13608, CVE-2026-18924, CVE-2026-19931,
CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255,
CVE-2026-82208, CVE-2026-82209
libde265: GHSA-mm7m-v26f-wf8x, GHSA-xp3h-6f5r-8cxp
libgit2: CVE-2026-5917
libheif: CVE-2026-84450, CVE-2026-84451, GHSA-24wx-9w62-c96w,
GHSA-2jg2-4ch7-h545, GHSA-4h82-g446-83fm, GHSA-4jqm-2x34-6f6r,
GHSA-73p7-m7gg-w2jv, GHSA-8857-r8x5-7499, GHSA-8fmq-r4pf-7m57,
GHSA-9rj8-5mp5-26c9, GHSA-g89c-p67h-r497, GHSA-gh5q-69gg-c964,
GHSA-hh47-fhqr-cj2r, GHSA-j264-xvrp-5v7q, GHSA-jc8f-p23p-5hjg,
GHSA-mw6f-29j3-76f4, GHSA-p58j-h3vm-3fp5, GHSA-w7mc-p8jc-p853,
GHSA-x8r2-mggj-j6wr, GHSA-x8xm-cm2c-cfc8, GHSA-xw34-mjcp-jqh8
libldns: CVE-2026-10846
libopenssl: CVE-2026-14456, CVE-2026-14457, CVE-2026-18798,
CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074,
CVE-2026-63075, CVE-2026-63076, CVE-2026-75803
libssh2: CVE-2025-15661, CVE-2026-66032, CVE-2026-66033,
CVE-2026-66034, CVE-2026-66035
libxml2: CVE-2026-11979
localedef: CVE-2026-18374, CVE-2026-19499, CVE-2026-5435,
CVE-2026-6238, CVE-2026-6368, CVE-2026-6791, CVE-2026-77117,
CVE-2026-80489
mongoose: CVE-2026-63626, CVE-2026-73251, CVE-2026-73252,
CVE-2026-73260, CVE-2026-73261
nodejs: CVE-2026-56846, CVE-2026-56847, CVE-2026-56848, CVE-2026-56850,
CVE-2026-58039, CVE-2026-58040, CVE-2026-58042, CVE-2026-58043,
CVE-2026-58044, CVE-2026-58045
openvpn: CVE-2026-84732
proftpd: CVE-2026-44331
python-avro: (no CVE assigned)
redis: (no CVE assigned)
rsyslog: CVE-2026-19654
udisks: CVE-2026-7867
unbound: CVE-2026-14586, CVE-2026-32665, CVE-2026-40622,
CVE-2026-40691, CVE-2026-41637, CVE-2026-42955, CVE-2026-44621,
CVE-2026-44687, CVE-2026-44690, CVE-2026-46582, CVE-2026-50045,
CVE-2026-50046, CVE-2026-50243, CVE-2026-50248, CVE-2026-50251,
CVE-2026-50252, CVE-2026-52863, CVE-2026-54478, CVE-2026-55708,
CVE-2026-55717, CVE-2026-55973, CVE-2026-55990, CVE-2026-55991,
CVE-2026-56416, CVE-2026-56444
wget: CVE-2026-58469, CVE-2026-58470, CVE-2026-58471
Toolchain:
- linux-headers: bump to 5.10.269, 5.15.220, 6.1.187, 6.6.156, 6.12.109
- powerpc: correctly track libquadmath
Infrastructure updates/fixes:
- Various fixes to the runtime tests
- manual: document move of patchwork to patchwork.buildroot.org
- manual: document the LTS release cadence correctly
- Fix setting of stack size for FLAT binaries
Updated defconfigs: qemu_xtensa_lx60*
Updated / fixed packages: avro-c, bind, clamav, collectd, dejavu,
dnsmasq, dpdk, dracut, erlang, exiv2, expat, gcc-bare-metal, gdb,
glibc, go, haproxy, hostapd, libcurl, libde265, libgit2, libheif,
libldns, libopenssl, libssh2, libxkbcommon, libxml-parser-perl,
libxml2, linux, linux-headers, linux-tools, localedef, mongoose,
mosquitto, newt, nodejs, opencv4, openssh, openvpn, perl, powerpc,
proftpd, python-avro, python-charset-normalizer, qt5knx,
qt6declarative, redis, rsyslog, taglib, uclibc, udisks, unbound, vim,
webkitgtk, wget, wine, wireless-regdb
2025.02.17, released August 23, 2026
Important / security related fixes:

View File

@@ -144,6 +144,83 @@ endif
###############################################################################
comment "Legacy options removed in 2026.11"
config BR2_PACKAGE_LIBCPPRESTSDK
bool "libcpprestsdk has been removed"
select BR2_LEGACY
help
libcpprestsdk is unmaintained and has been removed
config BR2_PACKAGE_HEIRLOOM_MAILX
bool "heirloom-mailx has been removed"
select BR2_LEGACY
help
The heirloom-mailx package has been removed because it is
incompatible with OpenSSL >= 4.x
config BR2_PACKAGE_NXP_BT_WIFI_FIRMWARE_8801
bool "nxp-bt-wifi-firmware 8801 support removed"
select BR2_LEGACY
help
The 8801 firmware is no longer available in the selected NXP
firmware release.
config BR2_PACKAGE_NXP_BT_WIFI_FIRMWARE_8997
bool "nxp-bt-wifi-firmware 8997 support removed"
select BR2_LEGACY
help
The 8997 firmware is no longer available in the selected NXP
firmware release.
config BR2_PACKAGE_NXP_BT_WIFI_FIRMWARE_8997_SD
bool "nxp-bt-wifi-firmware 8997 SD support removed"
select BR2_LEGACY
help
The 8997 firmware is no longer available in the selected NXP
firmware release.
config BR2_PACKAGE_NXP_BT_WIFI_FIRMWARE_8997_PCIE
bool "nxp-bt-wifi-firmware 8997 PCIe support removed"
select BR2_LEGACY
help
The 8997 firmware is no longer available in the selected NXP
firmware release.
config BR2_PACKAGE_NXP_BT_WIFI_FIRMWARE_IW610
bool "nxp-bt-wifi-firmware IW610 option renamed"
select BR2_PACKAGE_NXP_BT_WIFI_FIRMWARE_IW610_SD
select BR2_LEGACY
help
The IW610 firmware option was renamed to distinguish SD and
USB interfaces.
config BR2_BINUTILS_VERSION_2_44_X
bool "binutils 2.44 has been removed"
select BR2_LEGACY
help
binutils 2.44 has been removed, select a newer version
instead.
config BR2_KERNEL_HEADERS_7_1
bool "kernel headers version 7.1.x are no longer supported"
select BR2_LEGACY
help
Version 7.1.x of the Linux kernel headers are no longer
maintained upstream and are now removed.
config BR2_PACKAGE_WESTON_SCREENSHARE
bool "weston screenshare option removed"
select BR2_LEGACY
help
Weston screenshare option was removed in v16.0.0.
config BR2_PACKAGE_WESTON_SHELL_FULLSCREEN
bool "weston fullscreen shell removed"
select BR2_LEGACY
help
Weston fullscreen shell option was removed in v16.0.0.
comment "Legacy options removed in 2026.08"
config BR2_PACKAGE_FLUIDSYNTH_SDL2

View File

@@ -159,6 +159,8 @@ F: package/libxmlsec1/
F: package/openscap/
F: package/python-scp/
F: support/testing/tests/package/test_libldns.py
F: support/testing/tests/package/test_openscap/
F: support/testing/tests/package/test_openscap.py
F: support/testing/tests/package/test_python_scp.py
N: Alistair Francis <alistair@alistair23.me>
@@ -170,6 +172,7 @@ F: package/xen/
N: Alsey Coleman Miller <alseycmiller@gmail.com>
F: package/liblc3/
F: package/plutovg/
N: Alvaro G. M <alvaro.gamez@hazent.com>
F: package/dcron/
@@ -408,6 +411,7 @@ F: package/intel-mediasdk/
F: package/intel-microcode/
F: package/intel-vpl-gpu-rt/
F: package/jsoncpp/
F: package/jwt-cpp/
F: package/kodi*
F: package/lame/
F: package/lcms2/
@@ -564,6 +568,7 @@ F: package/libgpiod2/
N: Bogdan Radulescu <bogdan@nimblex.net>
F: package/iftop/
F: package/ncdu/
F: package/nettest/
N: Brandon Maier <brandon.maier@collins.com>
F: board/freescale/ls1046a-frwy/
@@ -1028,6 +1033,7 @@ F: package/bitcoin/
N: Fabrice Fontaine <fabrice.fontaine@orange.com>
F: package/domoticz/
F: package/jwt-cpp/
F: package/libmediaart/
F: package/libmaxminddb/
F: package/openzwave/
@@ -1123,6 +1129,9 @@ F: configs/freescale_imx6ullevk_defconfig
N: Falco Hyfing <hyfinglists@gmail.com>
F: package/python-pymodbus/
N: Fengwei Tan <tfx2001@outlook.com>
F: support/testing/tests/core/test_flat_stacksize.py
N: Fiona Klute <fiona.klute@gmx.de>
F: package/*/S*
F: package/panel-mipi-dbi-firmware/
@@ -1170,6 +1179,7 @@ F: package/ser2net/
N: Franciszek Stachura <fbstachura@gmail.com>
F: support/testing/tests/package/test_memcached.py
F: support/testing/tests/package/test_nano.py
N: Francois Dugast <francois.dugast.foss@gmail.com>
F: board/sipeed/licheepi_nano/
@@ -1889,6 +1899,7 @@ F: support/testing/tests/package/test_bitcoin.py
F: support/testing/tests/package/test_brotli.py
F: support/testing/tests/package/test_btrfs_progs.py
F: support/testing/tests/package/test_btrfs_progs/
F: support/testing/tests/package/test_bubblewrap.py
F: support/testing/tests/package/test_bzip2.py
F: support/testing/tests/package/test_compressor_base.py
F: support/testing/tests/package/test_connman.py
@@ -1902,6 +1913,7 @@ F: support/testing/tests/package/test_dosfstools.py
F: support/testing/tests/package/test_dosfstools/
F: support/testing/tests/package/test_dpdk.py
F: support/testing/tests/package/test_ed.py
F: support/testing/tests/package/test_erlang.py
F: support/testing/tests/package/test_ethtool.py
F: support/testing/tests/package/test_ethtool/
F: support/testing/tests/package/test_exfatprogs.py
@@ -2041,6 +2053,7 @@ F: support/testing/tests/package/test_sed.py
F: support/testing/tests/package/test_socat.py
F: support/testing/tests/package/test_sox.py
F: support/testing/tests/package/test_sqlite.py
F: support/testing/tests/package/test_squid.py
F: support/testing/tests/package/test_strace.py
F: support/testing/tests/package/test_stress_ng.py
F: support/testing/tests/package/test_swipl.py
@@ -2120,10 +2133,6 @@ F: package/rockchip-rkbin/
N: Klaus Heinrich Kiwi <klaus@linux.vnet.ibm.com>
F: package/wqy-zenhei/
N: Koen Martens <gmc@sonologic.nl>
F: package/capnproto/
F: package/linuxconsoletools/
N: Kory Maincent <kory.maincent@bootlin.com>
F: board/octavo/osd32mp1-brk/
F: board/octavo/osd32mp1-red/
@@ -2198,6 +2207,7 @@ F: configs/zynq_zc706_defconfig
F: configs/zynqmp_zcu106_defconfig
F: package/agentpp/
F: package/exim/
F: package/heaptrack/
F: package/libpjsip/
F: package/linux-tools/linux-tool-usbtools.mk.in
F: package/qpid-proton/
@@ -2206,6 +2216,7 @@ F: package/snmppp/
F: package/stm32flash/
F: package/unzip/
F: support/legal-info/
F: support/testing/tests/package/test_heaptrack.py
N: Lucas De Marchi <lucas.de.marchi@gmail.com>
F: package/fswebcam/
@@ -2850,6 +2861,7 @@ F: support/testing/tests/package/sample_python_s3transfer.py
F: support/testing/tests/package/sample_python_sdbus.py
F: support/testing/tests/package/sample_python_sdbus_networkmanager.py
F: support/testing/tests/package/sample_python_urllib3.py
F: support/testing/tests/package/test_harfbuzz.py
F: support/testing/tests/package/test_nginx_modsecurity/
F: support/testing/tests/package/test_nginx_modsecurity.py
F: support/testing/tests/package/test_python_jmespath.py
@@ -3247,7 +3259,6 @@ F: package/gcc/
F: package/genext2fs/
F: package/getent/
F: package/gnu-efi/
F: package/heirloom-mailx/
F: package/igh-ethercat/
F: package/intltool/
F: package/jh71xx-tools/

View File

@@ -92,7 +92,7 @@ all:
.PHONY: all
# Set and export the version string
export BR2_VERSION := 2026.08
export BR2_VERSION := 2026.11-git
# Actual time the release is cut (for reproducible builds)
BR2_VERSION_EPOCH = 1788535000

View File

@@ -20,6 +20,14 @@ config BR2_X86_CPU_HAS_AVX
config BR2_X86_CPU_HAS_AVX2
bool
# BR2_X86_CPU_HAS_XOP is selected by the AMD Bulldozer family (bdver1
# to bdver4), which is the only family implementing XOP. On those CPUs,
# gcc also enables the equally Bulldozer-specific FMA4 and LWP
# extensions (and TBM starting with bdver2). Those extensions were
# dropped again with Zen.
config BR2_X86_CPU_HAS_XOP
bool
# BR2_X86_CPU_HAS_AVX512 implies the following AVX512 extensions:
# AVX512F, AVX512BW, AVX512CD, AVX512DQ, AVX512VL
# This subset is common to Intel Xeon (excl Xeon Phi), AMD Zen 4, and
@@ -604,6 +612,7 @@ config BR2_x86_bulldozer
select BR2_X86_CPU_HAS_SSSE3
select BR2_X86_CPU_HAS_SSE4
select BR2_X86_CPU_HAS_SSE42
select BR2_X86_CPU_HAS_XOP
config BR2_x86_piledriver
bool "piledriver"
select BR2_X86_CPU_HAS_MMX
@@ -613,6 +622,7 @@ config BR2_x86_piledriver
select BR2_X86_CPU_HAS_SSSE3
select BR2_X86_CPU_HAS_SSE4
select BR2_X86_CPU_HAS_SSE42
select BR2_X86_CPU_HAS_XOP
config BR2_x86_steamroller
bool "steamroller"
select BR2_X86_CPU_HAS_MMX
@@ -622,6 +632,7 @@ config BR2_x86_steamroller
select BR2_X86_CPU_HAS_SSSE3
select BR2_X86_CPU_HAS_SSE4
select BR2_X86_CPU_HAS_SSE42
select BR2_X86_CPU_HAS_XOP
select BR2_ARCH_NEEDS_GCC_AT_LEAST_4_8
config BR2_x86_excavator
bool "excavator"
@@ -634,6 +645,7 @@ config BR2_x86_excavator
select BR2_X86_CPU_HAS_SSE42
select BR2_X86_CPU_HAS_AVX
select BR2_X86_CPU_HAS_AVX2
select BR2_X86_CPU_HAS_XOP
select BR2_ARCH_NEEDS_GCC_AT_LEAST_4_9
config BR2_x86_zen
bool "zen"

View File

@@ -5,16 +5,6 @@ image sdcard.img {
partition-table-type = "gpt"
}
partition spl {
partition-type-uuid = 2E54B353-1271-4842-806F-E436D6AF6985
image = "u-boot-spl.bin.normal.out"
}
partition uboot {
partition-type-uuid = BC13C2FF-59E6-4262-A352-B275FD6F7172
image = "u-boot.itb"
}
partition rootfs {
partition-type-uuid = 0FC63DAF-8483-4772-8E79-3D69D8477DE4
bootable = true

View File

@@ -3,7 +3,6 @@ CONFIG_COMPILE_TEST=y
CONFIG_DEFAULT_HOSTNAME="StarFive"
CONFIG_SYSVIPC=y
CONFIG_POSIX_MQUEUE=y
CONFIG_USELIB=y
CONFIG_NO_HZ_IDLE=y
CONFIG_HIGH_RES_TIMERS=y
CONFIG_BPF_SYSCALL=y
@@ -22,7 +21,6 @@ CONFIG_PERF_EVENTS=y
CONFIG_SOC_STARFIVE=y
CONFIG_NONPORTABLE=y
CONFIG_SMP=y
CONFIG_RISCV_AMP=y
CONFIG_HZ_100=y
CONFIG_HIBERNATION=y
CONFIG_PM_STD_PARTITION="PARTLABEL=hibernation"
@@ -40,6 +38,7 @@ CONFIG_CPU_FREQ_GOV_CONSERVATIVE=y
CONFIG_CPU_FREQ_GOV_SCHEDUTIL=y
CONFIG_CPUFREQ_DT=y
# CONFIG_SECCOMP is not set
# CONFIG_GCC_PLUGINS is not set
CONFIG_MODULES=y
CONFIG_MODULE_UNLOAD=y
CONFIG_BINFMT_MISC=y
@@ -59,6 +58,7 @@ CONFIG_NF_CONNTRACK=y
CONFIG_NF_TABLES=y
CONFIG_NFT_CT=y
CONFIG_NFT_COMPAT=y
CONFIG_NETFILTER_XTABLES_LEGACY=y
CONFIG_NETFILTER_XT_MATCH_CONNTRACK=y
CONFIG_NETFILTER_XT_MATCH_IPCOMP=y
CONFIG_NETFILTER_XT_MATCH_IPRANGE=y
@@ -69,6 +69,7 @@ CONFIG_NETFILTER_XT_MATCH_SOCKET=y
CONFIG_NETFILTER_XT_MATCH_STATE=y
CONFIG_NETFILTER_XT_MATCH_STRING=y
CONFIG_NETFILTER_XT_MATCH_U32=y
CONFIG_IP_NF_IPTABLES_LEGACY=y
CONFIG_NF_TABLES_IPV4=y
CONFIG_NFT_DUP_IPV4=y
CONFIG_NFT_FIB_IPV4=y
@@ -87,7 +88,6 @@ CONFIG_BT_RFCOMM_TTY=y
CONFIG_BT_BNEP=y
CONFIG_BT_BNEP_MC_FILTER=y
CONFIG_BT_BNEP_PROTO_FILTER=y
CONFIG_BT_AICUSB=y
CONFIG_CFG80211=y
CONFIG_MAC80211=y
CONFIG_RFKILL=y
@@ -104,7 +104,6 @@ CONFIG_MTD_BLOCK=y
CONFIG_MTD_CFI=y
CONFIG_MTD_CFI_ADV_OPTIONS=y
CONFIG_MTD_SPI_NOR=y
CONFIG_OF_CONFIGFS=y
CONFIG_BLK_DEV_LOOP=y
CONFIG_VIRTIO_BLK=y
CONFIG_BLK_DEV_NVME=y
@@ -159,21 +158,15 @@ CONFIG_MARVELL_PHY=y
CONFIG_MICREL_PHY=y
CONFIG_MICROCHIP_PHY=y
CONFIG_MOTORCOMM_PHY=y
CONFIG_IPMS_CAN=y
CONFIG_IWLWIFI=y
CONFIG_IWLDVM=y
CONFIG_IWLMVM=y
# CONFIG_RTL_CARDS is not set
CONFIG_USB_WIFI_ECR6600U=y
CONFIG_AIC_WLAN_SUPPORT=y
CONFIG_AIC8800_WLAN_SUPPORT=m
CONFIG_AIC_LOADFW_SUPPORT=m
CONFIG_INPUT_EVDEV=y
# CONFIG_INPUT_KEYBOARD is not set
# CONFIG_INPUT_MOUSE is not set
CONFIG_INPUT_TOUCHSCREEN=y
CONFIG_TOUCHSCREEN_GOODIX=y
CONFIG_TOUCHSCREEN_TINKER_FT5406=y
CONFIG_SERIO_LIBPS2=y
CONFIG_SERIAL_8250=y
CONFIG_SERIAL_8250_CONSOLE=y
@@ -205,7 +198,6 @@ CONFIG_THERMAL=y
CONFIG_CPU_THERMAL=y
CONFIG_DEVFREQ_THERMAL=y
CONFIG_THERMAL_EMULATION=y
# CONFIG_HISI_THERMAL is not set
CONFIG_WATCHDOG=y
CONFIG_WATCHDOG_SYSFS=y
CONFIG_MFD_AXP20X_I2C=y
@@ -221,10 +213,7 @@ CONFIG_V4L_PLATFORM_DRIVERS=y
CONFIG_V4L_MEM2MEM_DRIVERS=y
CONFIG_VIDEO_CADENCE_CSI2RX=y
CONFIG_VIDEO_WAVE_VPU=m
CONFIG_VIN_SENSOR_OV4689=y
CONFIG_VIDEO_STF_VIN=y
CONFIG_VIDEO_IMX219=y
CONFIG_VIDEO_IMX708=y
# CONFIG_CXD2880_SPI_DRV is not set
# CONFIG_MEDIA_TUNER_E4000 is not set
# CONFIG_MEDIA_TUNER_FC0011 is not set
@@ -371,13 +360,8 @@ CONFIG_VIDEO_IMX708=y
# CONFIG_DVB_SP2 is not set
CONFIG_DRM=y
CONFIG_DRM_PANEL_JADARD_JD9365DA_H3=y
CONFIG_DRM_PANEL_STARFIVE_JADARD=y
CONFIG_DRM_PANEL_SIMPLE=y
CONFIG_DRM_TOSHIBA_TC358762=y
CONFIG_DRM_VERISILICON=y
CONFIG_STARFIVE_INNO_HDMI=y
CONFIG_STARFIVE_DSI=y
CONFIG_DRM_IMG_ROGUE=y
CONFIG_FB=y
CONFIG_BACKLIGHT_CLASS_DEVICE=y
CONFIG_SOUND=y
@@ -386,10 +370,8 @@ CONFIG_SND_USB_AUDIO=y
CONFIG_SND_SOC=y
CONFIG_SND_DESIGNWARE_I2S=y
CONFIG_SND_SOC_RZ=m
CONFIG_SND_SOC_STARFIVE=y
CONFIG_SND_SOC_JH7110_PWMDAC=y
CONFIG_SND_SOC_JH7110_TDM=y
CONFIG_SND_SOC_AC108=y
CONFIG_SND_SOC_WM8960=y
CONFIG_SND_SIMPLE_CARD=y
CONFIG_UHID=y
@@ -477,7 +459,6 @@ CONFIG_LEDS_CLASS=y
CONFIG_LEDS_GPIO=y
CONFIG_LEDS_TRIGGER_HEARTBEAT=y
CONFIG_RTC_CLASS=y
CONFIG_RTC_DRV_STARFIVE=y
CONFIG_RTC_DRV_GOLDFISH=y
CONFIG_DMADEVICES=y
CONFIG_AMBA_PL08X=y
@@ -492,22 +473,16 @@ CONFIG_CLK_STARFIVE_JH7110_STG=y
CONFIG_CLK_STARFIVE_JH7110_ISP=y
CONFIG_CLK_STARFIVE_JH7110_VOUT=y
CONFIG_MAILBOX=y
CONFIG_STARFIVE_IPI_MBOX=y
CONFIG_STARFIVE_MBOX=m
CONFIG_STARFIVE_MBOX_TEST=m
# CONFIG_IOMMU_SUPPORT is not set
CONFIG_RPMSG_CHAR=y
CONFIG_RPMSG_CTRL=y
CONFIG_RPMSG_STARFIVE=m
CONFIG_RPMSG_VIRTIO=y
CONFIG_PM_DEVFREQ=y
CONFIG_IIO=y
CONFIG_IIO_ST_ACCEL_3AXIS=y
CONFIG_PWM=y
CONFIG_PWM_OCORES=y
CONFIG_PHY_STARFIVE_JH7110_PCIE=y
CONFIG_PHY_STARFIVE_JH7110_USB=y
CONFIG_PHY_M31_DPHY_RX0=y
CONFIG_RAS=y
CONFIG_EXT4_FS=y
CONFIG_EXT4_FS_POSIX_ACL=y
@@ -546,7 +521,7 @@ CONFIG_NLS_CODEPAGE_437=y
CONFIG_NLS_ISO8859_1=y
CONFIG_INIT_STACK_NONE=y
CONFIG_CRYPTO_USER=y
CONFIG_CRYPTO_TEST=m
CONFIG_CRYPTO_BENCHMARK=m
CONFIG_CRYPTO_USER_API_HASH=y
CONFIG_CRYPTO_USER_API_SKCIPHER=y
CONFIG_CRYPTO_USER_API_RNG=y

View File

@@ -1,4 +1,4 @@
label linux
kernel /boot/Image
devicetree /boot/jh7110-starfive-visionfive-2-v1.3b.dtb
append console=ttyS0,115200 root=/dev/mmcblk1p3
fdtdir /boot
append console=ttyS0,115200 root=/dev/mmcblk1p1 rootwait

View File

@@ -1,2 +1,2 @@
# Locally calculated
sha256 643142c1b5991560dd12f950825cc19e4497b95b82641918ecff1177f4130c1d linux-6.12.24.tar.xz
sha256 ba2f60f858bf4d1f929101faa356c93dc8b925b17aaa9f95eabd4627758df613 linux-6.18.51.tar.xz

View File

@@ -1,2 +1,2 @@
# Locally calculated
sha256 d11702103f177a2914e94eec57ce5ed820296d874f6b6525c4482e55d71a3667 opensbi-1.6.tar.gz
sha256 fb1ae61a85e966322101acb1c982f84d9eaafc4de7dd474a7d7546d9bb321c6f opensbi-1.8.1.tar.gz

View File

@@ -1,2 +1,2 @@
# Locally calculated
sha256 439d3bef296effd54130be6a731c5b118be7fddd7fcc663ccbc5fb18294d8718 u-boot-2025.04.tar.bz2
sha256 78e8bfc382fe388f9b55aa1daf8c563522a037779b5d4c349d1415e381f1243e u-boot-2026.07.tar.bz2

View File

@@ -1,8 +1,8 @@
Starfive VisionFive2
StarFive VisionFive2
====================
The VisionFive2 is a low-cost RISC-V 64-bit based platform, powered by a
Starfive JH7110 processor.
StarFive JH7110 processor.
https://doc-en.rvspace.org/Doc_Center/visionfive_2.html
@@ -24,33 +24,36 @@ If you have a booting device use u-boot and tftp:
# tftpboot 0x82000000 spi-nor.img
# sf probe
# sf update 0x82000000 0x0 {filesize}
# sf update 0x82000000 0x0 ${filesize}
Otherwise, follow the recovery instruction:
Otherwise, follow the recovery instructions:
https://doc-en.rvspace.org/VisionFive2/Quick_Start_Guide/VisionFive2_SDK_QSG/recovering_bootloader%20-%20vf2.html
How to write the SD card
========================
Copy the bootable "sdcard.img" onto an SD card with "dd":
Write "sdcard.img" onto an SD card with "dd":
$ sudo dd if=output/images/sdcard.img of=/dev/sdX
$ sudo dd if=output/images/sdcard.img of=/dev/sdX bs=1M conv=fsync
Preparing the board
===================
Connect a TTL UART cable to pin 6 (GND), 8 (TX) and 10 (RX).
Use the correct mode for booting:
- SD card RGPIO_0=1, GRPIO_1=0
- SPI NOR flash RGPIO_0=1, GRPIO_1=1
Note that Buildroot puts the bootloader both in SPI NOR and on the SD card,
so after flashing as instructed above, either boot mode should work.
Select SPI NOR flash boot mode:
- RGPIO_0=0, RGPIO_1=0
https://doc-en.rvspace.org/VisionFive2/Quick_Start_Guide/VisionFive2_SDK_QSG/boot_mode_settings.html
Insert your SD card.
Power-up the board using an USB-C cable.
Note that starting with U-Boot v2025.10, booting U-Boot directly from an
SD card is no longer supported on this board. In this configuration, the
bootloader is loaded from SPI NOR flash, while the SD card contains the
Linux kernel, device trees and root filesystem.
https://docs.u-boot.org/en/v2026.07/board/starfive/visionfive2.html#zero-stage-program-loader

View File

@@ -1,5 +1,5 @@
# Locally calculated
sha256 23c9cf18f5f419dfaafe5c3d3eda4812eb71bf1f2fbf3b35470478bbaa3d96bb xlnx_rebase_v6.18_LTS_2026.1.tar.gz
sha256 bdb5c40d7b43f8a1ea6ee34e2392a389935120b11cf54c36ad3ccff937b1a179 xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40.tar.gz
# Locally calculated
sha256 fb5a425bd3b3cd6071a3a9aff9909a859e7c1158d54d32e07658398cd67eb6a0 COPYING

View File

@@ -6,14 +6,14 @@ BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH="microblazeel-buildroot-elf riscv32-buildroot-elf"
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_MULTILIB=y
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches board/xilinx/linux_6.18.40/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_ROOTFS_POST_BUILD_SCRIPT="board/versal2/post-build.sh"
BR2_ROOTFS_POST_IMAGE_SCRIPT="board/versal2/post-image.sh"
BR2_ROOTFS_POST_SCRIPT_ARGS="ttyAMA1,115200 sdd2"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1)/xlnx_rebase_v6.18_LTS_2026.1.tar.gz"
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40)/xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40.tar.gz"
BR2_LINUX_KERNEL_DEFCONFIG="xilinx"
BR2_LINUX_KERNEL_NEEDS_HOST_OPENSSL=y
BR2_PACKAGE_XILINX_FPGAUTIL=y

View File

@@ -5,14 +5,14 @@ BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH="microblazeel-buildroot-elf"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches board/xilinx/linux_6.18.40/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_ROOTFS_POST_BUILD_SCRIPT="board/versal/post-build.sh"
BR2_ROOTFS_POST_IMAGE_SCRIPT="board/versal/post-image.sh"
BR2_ROOTFS_POST_SCRIPT_ARGS="ttyAMA0,115200 mmcblk0p2"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1)/xlnx_rebase_v6.18_LTS_2026.1.tar.gz"
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40)/xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40.tar.gz"
BR2_LINUX_KERNEL_DEFCONFIG="xilinx"
BR2_LINUX_KERNEL_DTS_SUPPORT=y
BR2_LINUX_KERNEL_INTREE_DTS_NAME="xilinx/versal-vck190-rev1.1"

View File

@@ -5,14 +5,14 @@ BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH="microblazeel-buildroot-elf"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches board/xilinx/linux_6.18.40/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_ROOTFS_POST_BUILD_SCRIPT="board/versal/post-build.sh"
BR2_ROOTFS_POST_IMAGE_SCRIPT="board/versal/post-image.sh"
BR2_ROOTFS_POST_SCRIPT_ARGS="ttyAMA0,115200 mmcblk0p2"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1)/xlnx_rebase_v6.18_LTS_2026.1.tar.gz"
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40)/xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40.tar.gz"
BR2_LINUX_KERNEL_DEFCONFIG="xilinx"
BR2_LINUX_KERNEL_DTS_SUPPORT=y
BR2_LINUX_KERNEL_INTREE_DTS_NAME="xilinx/versal-vek280-revB"

View File

@@ -5,14 +5,14 @@ BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH="microblazeel-buildroot-elf"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches board/xilinx/linux_6.18.40/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_ROOTFS_POST_BUILD_SCRIPT="board/versal/post-build.sh"
BR2_ROOTFS_POST_IMAGE_SCRIPT="board/versal/post-image.sh"
BR2_ROOTFS_POST_SCRIPT_ARGS="ttyAMA0,115200 mmcblk0p2"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1)/xlnx_rebase_v6.18_LTS_2026.1.tar.gz"
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40)/xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40.tar.gz"
BR2_LINUX_KERNEL_DEFCONFIG="xilinx"
BR2_LINUX_KERNEL_DTS_SUPPORT=y
BR2_LINUX_KERNEL_INTREE_DTS_NAME="xilinx/versal-vpk120-revB"

View File

@@ -5,14 +5,14 @@ BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH="microblazeel-buildroot-elf"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches board/xilinx/linux_6.18.40/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_ROOTFS_POST_BUILD_SCRIPT="board/versal/post-build.sh"
BR2_ROOTFS_POST_IMAGE_SCRIPT="board/versal/post-image.sh"
BR2_ROOTFS_POST_SCRIPT_ARGS="ttyAMA0,115200 mmcblk0p2"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1)/xlnx_rebase_v6.18_LTS_2026.1.tar.gz"
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40)/xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40.tar.gz"
BR2_LINUX_KERNEL_DEFCONFIG="xilinx"
BR2_LINUX_KERNEL_DTS_SUPPORT=y
BR2_LINUX_KERNEL_INTREE_DTS_NAME="xilinx/versal-vpk180-revA"

View File

@@ -1,5 +1,5 @@
BR2_riscv=y
BR2_PACKAGE_HOST_LINUX_HEADERS_CUSTOM_6_12=y
BR2_PACKAGE_HOST_LINUX_HEADERS_CUSTOM_6_18=y
BR2_GLOBAL_PATCH_DIR="board/visionfive2/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_SYSTEM_DHCP="eth0"
@@ -7,11 +7,12 @@ BR2_ROOTFS_OVERLAY="board/visionfive2/overlay"
BR2_ROOTFS_POST_IMAGE_SCRIPT="board/visionfive2/post-image.sh"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.24"
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.51"
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="board/visionfive2/linux_defconfig"
BR2_LINUX_KERNEL_DTS_SUPPORT=y
BR2_LINUX_KERNEL_INTREE_DTS_NAME="starfive/jh7110-starfive-visionfive-2-v1.3b"
BR2_LINUX_KERNEL_INTREE_DTS_NAME="starfive/jh7110-starfive-visionfive-2-v1.2a starfive/jh7110-starfive-visionfive-2-v1.3b"
BR2_LINUX_KERNEL_DTB_KEEP_DIRNAME=y
BR2_LINUX_KERNEL_INSTALL_TARGET=y
BR2_LINUX_KERNEL_NEEDS_HOST_OPENSSL=y
BR2_TARGET_ROOTFS_EXT2=y
@@ -19,14 +20,14 @@ BR2_TARGET_ROOTFS_EXT2_4=y
# BR2_TARGET_ROOTFS_TAR is not set
BR2_TARGET_OPENSBI=y
BR2_TARGET_OPENSBI_CUSTOM_VERSION=y
BR2_TARGET_OPENSBI_CUSTOM_VERSION_VALUE="1.6"
BR2_TARGET_OPENSBI_CUSTOM_VERSION_VALUE="1.8.1"
BR2_TARGET_OPENSBI_PLAT="generic"
# BR2_TARGET_OPENSBI_INSTALL_JUMP_IMG is not set
BR2_TARGET_OPENSBI_ADDITIONAL_VARIABLES="FW_TEXT_START=0x40000000 FW_OPTIONS=0"
BR2_TARGET_UBOOT=y
BR2_TARGET_UBOOT_BUILD_SYSTEM_KCONFIG=y
BR2_TARGET_UBOOT_CUSTOM_VERSION=y
BR2_TARGET_UBOOT_CUSTOM_VERSION_VALUE="2025.04"
BR2_TARGET_UBOOT_CUSTOM_VERSION_VALUE="2026.07"
BR2_TARGET_UBOOT_BOARD_DEFCONFIG="starfive_visionfive2"
BR2_TARGET_UBOOT_NEEDS_DTC=y
BR2_TARGET_UBOOT_NEEDS_PYLIBFDT=y

View File

@@ -5,13 +5,13 @@ BR2_ARM_ENABLE_VFP=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV7_EABIHF_GLIBC_STABLE=y
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches board/xilinx/linux_6.18.40/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_ROOTFS_POST_BUILD_SCRIPT="board/zynq/post-build.sh"
BR2_ROOTFS_POST_IMAGE_SCRIPT="board/zynq/post-image.sh"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1)/xlnx_rebase_v6.18_LTS_2026.1.tar.gz"
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40)/xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40.tar.gz"
BR2_LINUX_KERNEL_DEFCONFIG="xilinx_zynq"
BR2_LINUX_KERNEL_UIMAGE=y
BR2_LINUX_KERNEL_UIMAGE_LOADADDR="0x8000"

View File

@@ -5,13 +5,13 @@ BR2_ARM_ENABLE_VFP=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV7_EABIHF_GLIBC_STABLE=y
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches board/xilinx/linux_6.18.40/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_ROOTFS_POST_BUILD_SCRIPT="board/zynq/post-build.sh"
BR2_ROOTFS_POST_IMAGE_SCRIPT="board/zynq/post-image.sh"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1)/xlnx_rebase_v6.18_LTS_2026.1.tar.gz"
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40)/xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40.tar.gz"
BR2_LINUX_KERNEL_DEFCONFIG="xilinx_zynq"
BR2_LINUX_KERNEL_UIMAGE=y
BR2_LINUX_KERNEL_UIMAGE_LOADADDR="0x8000"

View File

@@ -5,13 +5,13 @@ BR2_ARM_ENABLE_VFP=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV7_EABIHF_GLIBC_STABLE=y
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches board/xilinx/linux_6.18.40/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_ROOTFS_POST_BUILD_SCRIPT="board/zynq/post-build.sh"
BR2_ROOTFS_POST_IMAGE_SCRIPT="board/zynq/post-image.sh"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1)/xlnx_rebase_v6.18_LTS_2026.1.tar.gz"
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40)/xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40.tar.gz"
BR2_LINUX_KERNEL_DEFCONFIG="xilinx_zynq"
BR2_LINUX_KERNEL_UIMAGE=y
BR2_LINUX_KERNEL_UIMAGE_LOADADDR="0x8000"

View File

@@ -5,13 +5,13 @@ BR2_ARM_ENABLE_VFP=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV7_EABIHF_GLIBC_STABLE=y
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches board/xilinx/linux_6.18.40/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_ROOTFS_POST_BUILD_SCRIPT="board/zynq/post-build.sh"
BR2_ROOTFS_POST_IMAGE_SCRIPT="board/zynq/post-image.sh"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1)/xlnx_rebase_v6.18_LTS_2026.1.tar.gz"
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40)/xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40.tar.gz"
BR2_LINUX_KERNEL_DEFCONFIG="xilinx_zynq"
BR2_LINUX_KERNEL_UIMAGE=y
BR2_LINUX_KERNEL_UIMAGE_LOADADDR="0x8000"

View File

@@ -4,14 +4,14 @@ BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH="microblazeel-buildroot-elf"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches board/xilinx/linux_6.18.40/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_ROOTFS_POST_BUILD_SCRIPT="board/zynqmp/post-build.sh"
BR2_ROOTFS_POST_IMAGE_SCRIPT="board/zynqmp/post-image.sh"
BR2_ROOTFS_POST_SCRIPT_ARGS="ttyPS1,115200 sda2"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1)/xlnx_rebase_v6.18_LTS_2026.1.tar.gz"
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40)/xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40.tar.gz"
BR2_LINUX_KERNEL_DEFCONFIG="xilinx"
BR2_LINUX_KERNEL_DTS_SUPPORT=y
BR2_LINUX_KERNEL_INTREE_DTS_NAME="xilinx/zynqmp-smk-k24-revA-sck-kd-g-revA"

View File

@@ -4,14 +4,14 @@ BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH="microblazeel-buildroot-elf"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches board/xilinx/linux_6.18.40/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_ROOTFS_POST_BUILD_SCRIPT="board/zynqmp/post-build.sh"
BR2_ROOTFS_POST_IMAGE_SCRIPT="board/zynqmp/post-image.sh"
BR2_ROOTFS_POST_SCRIPT_ARGS="ttyPS1,115200 sda2"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1)/xlnx_rebase_v6.18_LTS_2026.1.tar.gz"
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40)/xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40.tar.gz"
BR2_LINUX_KERNEL_DEFCONFIG="xilinx"
BR2_LINUX_KERNEL_DTS_SUPPORT=y
BR2_LINUX_KERNEL_INTREE_DTS_NAME="xilinx/zynqmp-smk-k26-revA-sck-kr-g-revB"

View File

@@ -4,14 +4,14 @@ BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH="microblazeel-buildroot-elf"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches board/xilinx/linux_6.18.40/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_ROOTFS_POST_BUILD_SCRIPT="board/zynqmp/post-build.sh"
BR2_ROOTFS_POST_IMAGE_SCRIPT="board/zynqmp/post-image.sh"
BR2_ROOTFS_POST_SCRIPT_ARGS="ttyPS1,115200 mmcblk1p2"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1)/xlnx_rebase_v6.18_LTS_2026.1.tar.gz"
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40)/xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40.tar.gz"
BR2_LINUX_KERNEL_DEFCONFIG="xilinx"
BR2_LINUX_KERNEL_DTS_SUPPORT=y
BR2_LINUX_KERNEL_INTREE_DTS_NAME="xilinx/zynqmp-smk-k26-revA-sck-kv-g-revB"

View File

@@ -4,14 +4,14 @@ BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH="microblazeel-buildroot-elf"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches board/xilinx/linux_6.18.40/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_ROOTFS_POST_BUILD_SCRIPT="board/zynqmp/post-build.sh"
BR2_ROOTFS_POST_IMAGE_SCRIPT="board/zynqmp/post-image.sh"
BR2_ROOTFS_POST_SCRIPT_ARGS="ttyPS0,115200 mmcblk0p2"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1)/xlnx_rebase_v6.18_LTS_2026.1.tar.gz"
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40)/xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40.tar.gz"
BR2_LINUX_KERNEL_DEFCONFIG="xilinx"
BR2_LINUX_KERNEL_DTS_SUPPORT=y
BR2_LINUX_KERNEL_INTREE_DTS_NAME="xilinx/zynqmp-zcu102-rev1.0"

View File

@@ -4,14 +4,14 @@ BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH="microblazeel-buildroot-elf"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches board/xilinx/linux_6.18.40/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_ROOTFS_POST_BUILD_SCRIPT="board/zynqmp/post-build.sh"
BR2_ROOTFS_POST_IMAGE_SCRIPT="board/zynqmp/post-image.sh"
BR2_ROOTFS_POST_SCRIPT_ARGS="ttyPS0,115200 mmcblk0p2"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1)/xlnx_rebase_v6.18_LTS_2026.1.tar.gz"
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40)/xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40.tar.gz"
BR2_LINUX_KERNEL_DEFCONFIG="xilinx"
BR2_LINUX_KERNEL_DTS_SUPPORT=y
BR2_LINUX_KERNEL_INTREE_DTS_NAME="xilinx/zynqmp-zcu104-revC"

View File

@@ -4,14 +4,14 @@ BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT=y
BR2_TOOLCHAIN_BARE_METAL_BUILDROOT_ARCH="microblazeel-buildroot-elf"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches"
BR2_GLOBAL_PATCH_DIR="board/xilinx/xilinx_v2026.1/patches board/xilinx/linux_6.18.40/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_ROOTFS_POST_BUILD_SCRIPT="board/zynqmp/post-build.sh"
BR2_ROOTFS_POST_IMAGE_SCRIPT="board/zynqmp/post-image.sh"
BR2_ROOTFS_POST_SCRIPT_ARGS="ttyPS0,115200 mmcblk0p2"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL=y
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1)/xlnx_rebase_v6.18_LTS_2026.1.tar.gz"
BR2_LINUX_KERNEL_CUSTOM_TARBALL_LOCATION="$(call github,Xilinx,linux-xlnx,xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40)/xlnx_rebase_v6.18_LTS_2026.1_update_merge_v6.18.40.tar.gz"
BR2_LINUX_KERNEL_DEFCONFIG="xilinx"
BR2_LINUX_KERNEL_DTS_SUPPORT=y
BR2_LINUX_KERNEL_INTREE_DTS_NAME="xilinx/zynqmp-zcu106-revA"

View File

@@ -70,30 +70,56 @@
<a href="/downloads/buildroot-2026.08.tar.xz.sign">[PGP sig]</a>
</td>
</tr>
<tr>
<th>Old stable</th>
<th>2026.05.x</th>
<td>September 2026</td>
<td>
2026.05.3<br/>
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2026.05.3/CHANGES">
Changelog
</a>
</td>
<td>2026-09-10</td>
<td>
<a href="/downloads/buildroot-2026.05.3.tar.gz">
<img src="images/zip.png" width="24" alt="">
.tar.gz
</a><br/>
<a href="/downloads/buildroot-2026.05.3.tar.gz.sign">[PGP sig]</a>
</td>
<td>
<a href="/downloads/buildroot-2026.05.3.tar.xz">
<img src="images/package.png" width="24" alt="">
.tar.xz
</a><br/>
<a href="/downloads/buildroot-2026.05.3.tar.xz.sign">[PGP sig]</a>
</td>
</tr>
<tr>
<th>Long-term support</th>
<th>2025.02.x</th>
<td>March 2028</td>
<td>
2025.02.17<br/>
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2025.02.17/CHANGES">
2025.02.18<br/>
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2025.02.18/CHANGES">
Changelog
</a>
</td>
<td>2026-08-23</td>
<td>2026-09-10</td>
<td>
<a href="/downloads/buildroot-2025.02.17.tar.gz">
<a href="/downloads/buildroot-2025.02.18.tar.gz">
<img src="images/zip.png" width="24" alt="">
.tar.gz
</a><br/>
<a href="/downloads/buildroot-2025.02.17.tar.gz.sign">[PGP sig]</a>
<a href="/downloads/buildroot-2025.02.18.tar.gz.sign">[PGP sig]</a>
</td>
<td>
<a href="/downloads/buildroot-2025.02.17.tar.xz">
<a href="/downloads/buildroot-2025.02.18.tar.xz">
<img src="images/package.png" width="24" alt="">
.tar.xz
</a><br/>
<a href="/downloads/buildroot-2025.02.17.tar.xz.sign">[PGP sig]</a>
<a href="/downloads/buildroot-2025.02.18.tar.xz.sign">[PGP sig]</a>
</td>
</tr>
</table>

Binary file not shown.

After

Width:  |  Height:  |  Size: 2.7 KiB

View File

@@ -9,6 +9,44 @@
<h2>News</h2>
<ul class="timeline">
<li class="timeline-inverted">
<div class="timeline-badge"><i class="glyphicon glyphicon-thumbs-up"></i></div>
<div class="timeline-panel">
<div class="timeline-heading">
<h4 class="timeline-title">2026.05.3 released</h4>
<p><small class="text-muted"><i class="glyphicon glyphicon-time"></i>10 September 2026</small></p>
</div>
<div class="timeline-body">
<p>The 2026.05.3 bugfix release is out, fixing a number of important /
security related issues discovered since the 2026.05.2 release. See the
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2026.05.3/CHANGES">CHANGES</a>
file for more details, read the
<a href="https://lore.kernel.org/buildroot/buildroot-2026.05.3-announce-1789069201@buildroot.org/T/#u">announcement</a>
and go to the <a href="/downloads/">downloads page</a> to pick up the
<a href="/downloads/buildroot-2026.05.3.tar.xz">2026.05.3 release</a>.</p>
</div>
</div>
</li>
<li class="timeline">
<div class="timeline-badge"><i class="glyphicon glyphicon-thumbs-up"></i></div>
<div class="timeline-panel">
<div class="timeline-heading">
<h4 class="timeline-title">2025.02.18 released</h4>
<p><small class="text-muted"><i class="glyphicon glyphicon-time"></i>10 September 2026</small></p>
</div>
<div class="timeline-body">
<p>The 2025.02.18 bugfix release is out, fixing a number of important /
security related issues discovered since the 2025.02.17 release. See the
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2025.02.18/CHANGES">CHANGES</a>
file for more details, read the
<a href="https://lore.kernel.org/buildroot/buildroot-2025.02.18-announce-1789067743@buildroot.org/T/#u">announcement</a>
and go to the <a href="/downloads/">downloads page</a> to pick up the
<a href="/downloads/buildroot-2025.02.18.tar.xz">2025.02.18 release</a>.</p>
</div>
</div>
</li>
<li class="timeline-inverted">
<div class="timeline-badge"><i class="glyphicon glyphicon-thumbs-up"></i></div>
<div class="timeline-panel">
@@ -20,7 +58,8 @@
<p>The stable 2026.08 release is out - Thanks to everyone
contributing and testing the release candidates. See the
<a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2026.08/CHANGES">CHANGES</a>
file for more details
file for more details, read the
<a href="https://lore.kernel.org/buildroot/878q5hf0yd.fsf@dell.be.48ers.dk/T/#u">announcement</a>
and go to the <a href="/downloads/">downloads page</a> to pick up the
<a href="/downloads/buildroot-2026.08.tar.xz">2026.08 release</a>.</p>
</div>

View File

@@ -47,7 +47,20 @@
</div>
</div>
</div>
<div class="sponsor-entry">
<div class="panel panel-default panel-lts-sponsor">
<div class="panel-body">
<div class="sponsor-title">
<a href="https://www.ti.com/">
<img class="img-responsive" src="images/ti-logo.png"/>
</a>
</div>
<div class="sponsor-body">
<a href="https://www.ti.com">Texas Instruments</a>
</div>
</div>
</div>
</div>
</div>
</div>
@@ -136,8 +149,8 @@
<div class="sponsor-body">
<a href="http://www.smile.eu">Smile</a> is sponsoring the
Buildroot project by hosting
the <a href="https://elinux.org/Buildroot:DeveloperDaysFOSDEM2025">Buildroot
Developers Meeting of February 2025</a> in Brussels,
the <a href="https://elinux.org/Buildroot:DeveloperDaysFOSDEM2026">Buildroot
Developers Meeting of February 2026</a> in Brussels,
after the FOSDEM
<a href="https://www.fosdem.org">conference</a>.
</div>
@@ -218,7 +231,7 @@
<div class="sponsor-body">
<a href="https://www.smile.eu">Smile</a> provided the
meeting location Buildroot Developers days after
FOSDEM 2023, 2024 and 2025, for the
FOSDEM each year since 2023, for the
<a href="https://elinux.org/Buildroot:DeveloperDaysELCE2019">ELCE
2019</a> meeting and sponsored the Buildroot Summer
Camp 2016: Smile sponsored the participation of Romain

View File

@@ -215,6 +215,15 @@ TARGETS_ROOTFS += rootfs-$(1)
PACKAGES += $$(filter-out rootfs-%,$$(ROOTFS_$(2)_FINAL_RECURSIVE_DEPENDENCIES))
endif
ifeq ($$(BR2_TARGET_ROOTFS_$(2)_VERITY),y)
ROOTFS_$(2)_DEPENDENCIES += host-cryptsetup
define ROOTFS_$(2)_VERITY_FORMAT
@$$(call MESSAGE,"Generating verity hash tree $$(@F).verity")
$(HOST_DIR)/sbin/veritysetup format --root-hash-file $$@.verity.root-hash $$(ROOTFS_$(2)_VERITY_EXTRA_ARGS) $$@ $$@.verity
endef
ROOTFS_$(2)_POST_GEN_HOOKS += ROOTFS_$(2)_VERITY_FORMAT
endif
# Check for legacy POST_TARGETS rules
ifneq ($$(ROOTFS_$(2)_POST_TARGETS),)
$$(error Filesystem $(1) uses post-target rules, which are no longer supported.\

View File

@@ -121,4 +121,27 @@ config BR2_TARGET_ROOTFS_SQUASHFS_COMP_OPTS
default "-Xcompression-level 22" if BR2_TARGET_ROOTFS_SQUASHFS4_ZSTD
depends on BR2_TARGET_ROOTFS_SQUASHFS_EXTREME_COMP
config BR2_TARGET_ROOTFS_SQUASHFS_VERITY
bool "create verity hash data for root filesystem"
select BR2_PACKAGE_HOST_CRYPTSETUP
help
Create verity hash tree for the root filesystem. This allows
setting up a dm-verity device for the root filesystem, to
ensure data integrity. The root hash must be provided from a
trusted source, or with a kernel-verifiable signature.
The verity hash image will be called rootfs.squashfs.verity,
with the root hash in rootfs.squashfs.verity.root-hash.
if BR2_TARGET_ROOTFS_SQUASHFS_VERITY
config BR2_TARGET_ROOTFS_SQUASHFS_VERITY_EXTRA_ARGS
string "Additional arguments for veritysetup"
help
Additional arguments for the "veritysetup format" call. Use
this if you want to set options, e.g. the hash algorithm,
instead of using defaults.
endif # BR2_TARGET_ROOTFS_SQUASHFS_VERITY
endif

View File

@@ -32,6 +32,10 @@ else
ROOTFS_SQUASHFS_ARGS += -comp gzip
endif
ifeq ($(BR2_TARGET_ROOTFS_SQUASHFS_VERITY),y)
ROOTFS_SQUASHFS_VERITY_EXTRA_ARGS = $(call qstrip,$(BR2_TARGET_ROOTFS_SQUASHFS_VERITY_EXTRA_ARGS))
endif
define ROOTFS_SQUASHFS_CMD
$(HOST_DIR)/bin/mksquashfs $(TARGET_DIR) $@ $(ROOTFS_SQUASHFS_ARGS)
endef

View File

@@ -30,8 +30,8 @@ choice
prompt "Kernel version"
config BR2_LINUX_KERNEL_LATEST_VERSION
bool "Latest version (7.1)"
select BR2_TOOLCHAIN_HEADERS_AT_LEAST_7_1 if BR2_KERNEL_HEADERS_AS_KERNEL
bool "Latest version (7.2)"
select BR2_TOOLCHAIN_HEADERS_AT_LEAST_7_2 if BR2_KERNEL_HEADERS_AS_KERNEL
# mips always generates an ITB image
select BR2_PACKAGE_HOST_UBOOT_TOOLS if BR2_mips || BR2_mipsel || BR2_mips64 || BR2_mips64el
select BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT if BR2_mips || BR2_mipsel || BR2_mips64 || BR2_mips64el
@@ -143,7 +143,7 @@ config BR2_LINUX_KERNEL_CUSTOM_REPO_GIT_SUBMODULES
config BR2_LINUX_KERNEL_VERSION
string
default "7.1.13" if BR2_LINUX_KERNEL_LATEST_VERSION
default "7.2.8" if BR2_LINUX_KERNEL_LATEST_VERSION
default "5.10.254-cip72" if BR2_LINUX_KERNEL_LATEST_CIP_VERSION
default "5.10.254-cip72-rt32" if BR2_LINUX_KERNEL_LATEST_CIP_RT_VERSION
default BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE \

View File

@@ -1,10 +1,10 @@
# From https://www.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
sha256 e1d1ea200d22d55c9f5d5fae59e69bb3b494515705fc3390cd54231ee4f4baaf linux-6.12.108.tar.xz
sha256 aee2264a4eaf4a14344b47a0469bd42e8b4885b24f110b724262b3da956f411d linux-6.6.156.tar.xz
sha256 1b6e798aeaa708ca670a426ad5a6c86dc2237b8e59e8822876976c383873642b linux-6.1.187.tar.xz
sha256 9e59dc67624188fa12a6601f9598499cd6662a9066be572b59f935e3d7849810 linux-6.12.111.tar.xz
sha256 b74a43d0630809b7871cc906ac155e956cbc0b2e78a7451f5e6c8bfcb1208c30 linux-6.6.157.tar.xz
sha256 ed4d0acb1307c235230c89efc094e210e6290593f94a7e617f28b1001101a33a linux-6.1.188.tar.xz
# From https://www.kernel.org/pub/linux/kernel/v5.x/sha256sums.asc
sha256 b5b2992505120ac864cd9ccf7cc44541684df46c5a0b09ccdec93fb7f9aa6723 linux-5.15.220.tar.xz
sha256 9c5a168119406674ff3bcf366a3a235206eecfa7b79f04629b31a7cc678cc6e9 linux-5.10.269.tar.xz
sha256 c07882e1e528efe206567a26de30b192db8dc4369974d4ef4ce708691fa1148c linux-5.15.221.tar.xz
sha256 de73d528b04be91f6eb86660aa67a4d53b96bbf20bb5a326e78f802d744debe7 linux-5.10.270.tar.xz
# Locally computed
sha256 bd5db7fe3b0475cce4fc72db7a7f7df1c22b970aabe5ebff6ddd48098973bdf2 linux-cip-5.10.254-cip72.tar.gz
sha256 97d7d5139900c10ff7435779be4857dda531e7cf6abba52c12a5f39aae195411 linux-cip-5.10.254-cip72-rt32.tar.gz

View File

@@ -1,8 +1,8 @@
# From https://www.kernel.org/pub/linux/kernel/v7.x/sha256sums.asc
sha256 614d95fafdcb5cce2b6620e7edc6afbb606bffd4655405586815d84687841ad7 linux-7.1.13.tar.xz
sha256 12e8d5a973d1ad7c5a5c69882e4022b131ed715db7003fdcd760ddf8c3e51941 linux-7.2.8.tar.xz
# From https://www.kernel.org/pub/linux/kernel/v6.x/sha256sums.asc
sha256 ae826f33111fea6f1d279dde7299d7463c8dfd204aeb75a8fb5432bc60a28191 linux-6.18.49.tar.xz
sha256 9df30b02dd8102bbd0be52556288ef6889ddbe7f1ddb96fbf847d0becf3eacac linux-6.18.54.tar.xz
# Licenses hashes
sha256 fb5a425bd3b3cd6071a3a9aff9909a859e7c1158d54d32e07658398cd67eb6a0 COPYING

View File

@@ -708,7 +708,7 @@ linux-rebuild-with-initramfs: rootfs-cpio
linux-rebuild-with-initramfs:
@$(call MESSAGE,"Rebuilding kernel with initramfs")
# Build the kernel.
$(LINUX_MAKE_ENV) $(BR2_MAKE) $(LINUX_MAKE_FLAGS) -C $(LINUX_DIR) $(LINUX_TARGET_NAME)
+$(LINUX_MAKE_ENV) $(BR2_MAKE) $(LINUX_MAKE_FLAGS) -C $(LINUX_DIR) $(LINUX_TARGET_NAME)
$(LINUX_APPEND_DTB)
# Copy the kernel image(s) to its(their) final destination
$(call LINUX_INSTALL_IMAGE,$(BINARIES_DIR))

View File

@@ -106,6 +106,7 @@ menu "Debugging, profiling and benchmark"
source "package/fwts/Config.in"
source "package/gdb/Config.in"
source "package/google-breakpad/Config.in"
source "package/heaptrack/Config.in"
source "package/hyperfine/Config.in"
source "package/iozone/Config.in"
source "package/k3conf/Config.in"
@@ -350,6 +351,7 @@ comment "Graphic libraries"
source "package/mesa3d-headers/Config.in"
source "package/ocrad/Config.in"
source "package/ogre/Config.in"
source "package/plutovg/Config.in"
source "package/psplash/Config.in"
source "package/sdl/Config.in"
source "package/sdl_gfx/Config.in"
@@ -1907,6 +1909,7 @@ menu "JSON/XML"
source "package/json-for-modern-cpp/Config.in"
source "package/json-glib/Config.in"
source "package/jsoncpp/Config.in"
source "package/jwt-cpp/Config.in"
source "package/libfastjson/Config.in"
source "package/libjson/Config.in"
source "package/libroxml/Config.in"
@@ -2019,7 +2022,6 @@ menu "Networking"
source "package/libcgicc/Config.in"
source "package/libcoap/Config.in"
source "package/libcppconnman/Config.in"
source "package/libcpprestsdk/Config.in"
source "package/libcurl/Config.in"
source "package/libdnet/Config.in"
source "package/libeXosip2/Config.in"
@@ -2361,7 +2363,6 @@ menu "Mail"
source "package/dovecot/Config.in"
source "package/exim/Config.in"
source "package/fetchmail/Config.in"
source "package/heirloom-mailx/Config.in"
source "package/libesmtp/Config.in"
source "package/msmtp/Config.in"
source "package/mutt/Config.in"
@@ -2558,6 +2559,7 @@ endif
source "package/nethogs/Config.in"
source "package/netplug/Config.in"
source "package/netsnmp/Config.in"
source "package/nettest/Config.in"
source "package/network-manager/Config.in"
source "package/network-manager-openvpn/Config.in"
source "package/networkd-dispatcher/Config.in"

View File

@@ -1,35 +0,0 @@
From eb8ccfe5bb32273226d80236caab7a9386d71071 Mon Sep 17 00:00:00 2001
From: Peter Korsgaard <peter@korsgaard.com>
Date: Thu, 18 Jun 2026 15:12:38 +0200
Subject: [PATCH] io.c: isarmor(): do not set eof for <35 byte files
Encryption is silently broken for <35 byte files since commit b374d8de5a
("stop reading after first EOF"), as readall() sets the eof flag when it was
unable to read the entire 35 bytes in isarmor(), causing bread() to return
EOF and ignore the <35 bytes already read.
Fix it by only setting the eof flag in isarmor() if nothing could be read.
Upstream: mailed to amin@firemail.cc
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
---
io.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/io.c b/io.c
index 15ed4f7..2773022 100644
--- a/io.c
+++ b/io.c
@@ -128,8 +128,7 @@ isarmor(Ibuf *b)
nr = readall(b->fd, b->buf, sizeof(armorfirst) - 1, &b->eof);
if(nr == -1)
return -1;
- if(nr == 0)
- b->eof = 1;
+ b->eof = (nr == 0);
b->size = nr;
if((usize)nr < sizeof(armorfirst) - 1)
return 0;
--
2.47.3

View File

@@ -1,3 +1,3 @@
# Locally calculated
sha256 97958ff82eaa6aa89328f4319d585e362130168c478cf6a85ba3f4d05e453669 0.1.0.tar.gz
sha256 7f52eb6ca021f6dd6313e1b0798d5d363edf868d0b987eb56d7039c4fce01f70 1.0.0.tar.gz
sha256 f7f37a8bb7d993825b10f5ce2838c1c452d902eda63cd180fdabc7c3a5dd0341 LICENSE

View File

@@ -4,7 +4,7 @@
#
################################################################################
AGEC_VERSION = 0.1.0
AGEC_VERSION = 1.0.0
AGEC_SOURCE = $(AGEC_VERSION).tar.gz
AGEC_SITE = https://git.sr.ht/~min/agec/archive
AGEC_LICENSE = 0BSD

View File

@@ -1,5 +1,5 @@
# From https://gitlab.com/apparmor/apparmor/-/releases/v4.1.1
sha256 f125aae32964e4e84443fec005f37f37abd5164f30620239c42864655a1b0281 apparmor-v4.1.1.tar.gz
# From https://gitlab.com/apparmor/apparmor/-/releases/v4.1.8
sha256 e5b61bdda754ce55091d390094bdc9eaa7e5c60ae24e75cea18f51c288afa65d apparmor-v4.1.8.tar.bz2
# locally computed
sha256 a7e0cdcbea5c14927cedfc600d46526bdcbb1eb0a4d951e2ea53c2a6de159cb4 LICENSE

View File

@@ -6,8 +6,8 @@
# When updating the version here, please also update the libapparmor package
APPARMOR_VERSION_MAJOR = 4.1
APPARMOR_VERSION = $(APPARMOR_VERSION_MAJOR).1
APPARMOR_SOURCE = apparmor-v$(APPARMOR_VERSION).tar.gz
APPARMOR_VERSION = $(APPARMOR_VERSION_MAJOR).8
APPARMOR_SOURCE = apparmor-v$(APPARMOR_VERSION).tar.bz2
APPARMOR_SITE = https://gitlab.com/apparmor/apparmor/-/archive/v$(APPARMOR_VERSION)
APPARMOR_DL_SUBDIR = apparmor
APPARMOR_LICENSE = GPL-2.0

View File

@@ -1,4 +1,4 @@
# From https://archive.apache.org/dist/apr/apr-util-1.6.4.tar.bz2.sha256
sha256 3e2ae08f40efa0c3701e54a954cefa08242de22a69f91a8ae44fc1e624ba309b apr-util-1.6.4.tar.bz2
# From https://archive.apache.org/dist/apr/apr-util-1.6.5.tar.bz2.sha256
sha256 96de1dd6f6a0476d2d2e7964926d8c1ddc3bb0e210e1b1812d3ba5a454a392e2 apr-util-1.6.5.tar.bz2
# Locally calculated
sha256 ef5609d18601645ad6fe22c6c122094be40e976725c1d0490778abacc836e7a2 LICENSE

View File

@@ -4,7 +4,7 @@
#
################################################################################
APR_UTIL_VERSION = 1.6.4
APR_UTIL_VERSION = 1.6.5
APR_UTIL_SOURCE = apr-util-$(APR_UTIL_VERSION).tar.bz2
APR_UTIL_SITE = https://archive.apache.org/dist/apr
APR_UTIL_LICENSE = Apache-2.0

View File

@@ -0,0 +1,63 @@
From 520061e78d1ec24d0d4b97555e11de01f4db8c2a Mon Sep 17 00:00:00 2001
From: Bernd Kuhls <bernd@kuhls.net>
Date: Sun, 13 Sep 2026 13:08:28 +0200
Subject: [PATCH] Fix build of bundled libpjsip with OpenSSL 4.x
Source of the patch:
https://github.com/pjsip/pjproject/commit/3923fad2e4f6f3403c3d6f1176b113c1c1b91066
Upstream: https://github.com/asterisk/asterisk/commit/9a3bd18d4d4c4310eef46b5e6db9d7f3d0268768
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
.../pjproject/patches/0030-openssl4.patch | 38 +++++++++++++++++++
1 file changed, 38 insertions(+)
create mode 100644 third-party/pjproject/patches/0030-openssl4.patch
diff --git a/third-party/pjproject/patches/0030-openssl4.patch b/third-party/pjproject/patches/0030-openssl4.patch
new file mode 100644
index 0000000000..bfeefa2677
--- /dev/null
+++ b/third-party/pjproject/patches/0030-openssl4.patch
@@ -0,0 +1,38 @@
+From 3923fad2e4f6f3403c3d6f1176b113c1c1b91066 Mon Sep 17 00:00:00 2001
+From: Ravi Kant Sharma <rks1986@gmail.com>
+Date: Wed, 24 Jun 2026 11:30:40 +0200
+Subject: [PATCH] ssl_sock_ossl: fix OpenSSL 4.0 compatibility (#5036)
+
+---
+ pjlib/src/pj/ssl_sock_ossl.c | 11 ++++-------
+ 1 file changed, 4 insertions(+), 7 deletions(-)
+
+diff --git a/pjlib/src/pj/ssl_sock_ossl.c b/pjlib/src/pj/ssl_sock_ossl.c
+index 000aabad61..93fcf10f14 100644
+--- a/pjlib/src/pj/ssl_sock_ossl.c
++++ b/pjlib/src/pj/ssl_sock_ossl.c
+@@ -1645,10 +1645,7 @@ static pj_status_t init_ossl_ctx(pj_ssl_sock_t *ssock)
+ if (PEM_read_bio_X509(new_bio, &x, NULL, NULL) == NULL)
+ break;
+
+- if ((xn = X509_get_subject_name(x)) == NULL)
+- break;
+-
+- if ((xn = X509_NAME_dup(xn)) == NULL )
++ if ((xn = X509_NAME_dup(X509_get_subject_name(x))) == NULL )
+ break;
+
+ #if !USING_BORINGSSL
+@@ -2105,9 +2102,9 @@ static pj_bool_t parse_ossl_asn1_time(pj_time_val *tv, pj_bool_t *gmt,
+ pj_parsed_time pt;
+ int i;
+
+- utc = tm->type == V_ASN1_UTCTIME;
+- p = (char*)tm->data;
+- len = tm->length;
++ utc = ASN1_STRING_type(tm) == V_ASN1_UTCTIME;
++ p = (char*)M_ASN1_STRING_data(tm);
++ len = M_ASN1_STRING_length(tm);
+ end = p + len - 1;
+
+ /* GMT */
--
2.47.3

View File

@@ -1,8 +1,8 @@
# Locally computed
sha256 373c98f4d4a1b923b42def0aee03f4e36aca9d1c244a8eeda646da8a97f89663 asterisk-22.10.1.tar.gz
# From https://github.com/asterisk/asterisk/releases/download/22.11.0/asterisk-22.11.0.sha256
sha256 3bd5ee040509a3d3cd9b1ba9520c18e6ec0a7e7981ca68c457dcd36ba3c54d94 asterisk-22.11.0.tar.gz
# Locally computed
sha256 633c3dc34ffb21af8ac9ee160245c9c174379391e35cace1b6c9f516a260f683 pjproject-2.16.tar.bz2
sha256 04b2eb1f0f01aa0ad1945b167171843448a51aa6b7c3e806496d434f13a112b7 pjproject-2.17.tar.bz2
sha256 6775095bcd417d375faddc1f17cdd7706ad8aa9b9b02404990c4b0ee218ee379 libjwt-1.15.3.tar.gz
# sha1 from: http://downloads.asterisk.org/pub/telephony/sounds/releases

View File

@@ -4,21 +4,23 @@
#
################################################################################
ASTERISK_VERSION = 22.10.1
# When bumping asterisk's version, verify that the versions of pjsip,
# libjwt and sounds below are still matching.
ASTERISK_VERSION = 22.11.0
# Use the github mirror: it's an official mirror maintained by Digium, and
# provides tarballs, which the main Asterisk git tree (behind Gerrit) does not.
ASTERISK_SITE = $(call github,asterisk,asterisk,$(ASTERISK_VERSION))
ASTERISK_SITE = https://github.com/asterisk/asterisk/releases/download/$(ASTERISK_VERSION)
# compilation with the external pjsip produces a non-working asterisk, which
# segfaults. The reason behind this is unclear.
# https://github.com/asterisk/asterisk/issues/671
ASTERISK_PJSIP_URL = https://raw.githubusercontent.com/asterisk/third-party/master/pjproject/2.16/
ASTERISK_PJSIP_URL = https://raw.githubusercontent.com/asterisk/third-party/master/pjproject/2.17/
ASTERISK_LIBJWT_URL = https://raw.githubusercontent.com/asterisk/third-party/master/libjwt/1.15.3/
ASTERISK_SOUNDS_BASE_URL = http://downloads.asterisk.org/pub/telephony/sounds/releases
ASTERISK_EXTRA_DOWNLOADS = \
$(ASTERISK_SOUNDS_BASE_URL)/asterisk-core-sounds-en-gsm-1.6.1.tar.gz \
$(ASTERISK_SOUNDS_BASE_URL)/asterisk-moh-opsound-wav-2.03.tar.gz \
$(ASTERISK_PJSIP_URL)/pjproject-2.16.tar.bz2 \
$(ASTERISK_PJSIP_URL)/pjproject-2.17.tar.bz2 \
$(ASTERISK_LIBJWT_URL)/libjwt-1.15.3.tar.gz
ASTERISK_LICENSE = GPL-2.0, BSD-3-Clause (SHA1, resample), BSD-4-Clause (db1-ast)

View File

@@ -1,33 +0,0 @@
From 67e7d350a15aff88c151b1fc838dac83d35be955 Mon Sep 17 00:00:00 2001
From: Bernd Kuhls <bernd@kuhls.net>
Date: Sat, 22 Nov 2025 23:47:41 +0100
Subject: [PATCH] atf-check.cpp: include time.h
Fixes build error with gcc 14 as reported by the buildroot autobuilders:
https://autobuild.buildroot.net/results/41b/41b25ee8e66e34323eca011e4b5fe479ece9ed76/build-end.log
atf-sh/atf-check.cpp: In function 'useconds_t get_monotonic_useconds()':
atf-sh/atf-check.cpp:183:24: error: 'CLOCK_MONOTONIC' was not declared in this scope
Upstream: https://github.com/freebsd/atf/commit/67e7d350a15aff88c151b1fc838dac83d35be955
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
atf-sh/atf-check.cpp | 1 +
1 file changed, 1 insertion(+)
diff --git a/atf-sh/atf-check.cpp b/atf-sh/atf-check.cpp
index 1354e3a..94da413 100644
--- a/atf-sh/atf-check.cpp
+++ b/atf-sh/atf-check.cpp
@@ -30,6 +30,7 @@ extern "C" {
#include <limits.h>
#include <signal.h>
#include <stdint.h>
+#include <time.h>
#include <unistd.h>
}
--
2.47.3

View File

@@ -1,6 +1,7 @@
config BR2_PACKAGE_ATF
bool "atf"
depends on BR2_INSTALL_LIBSTDCPP
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_10 # C++20
depends on BR2_USE_MMU # fork()
help
ATF, or Automated Testing Framework, is a collection of
@@ -8,6 +9,6 @@ config BR2_PACKAGE_ATF
https://github.com/freebsd/atf
comment "atf needs a toolchain w/ C++"
depends on !BR2_INSTALL_LIBSTDCPP
comment "atf needs a toolchain w/ C++, gcc >= 10"
depends on !BR2_INSTALL_LIBSTDCPP || !BR2_TOOLCHAIN_GCC_AT_LEAST_10
depends on BR2_USE_MMU

View File

@@ -1,3 +1,3 @@
# Locally computed
sha256 a64e2427d021297f25b3f2e1798f8ec4dc3061ffb01a1cd3f66cc4cee486b10f atf-0.23.tar.gz
sha256 bae70930bef565faacb95b10e5673601df0d7f25db720cc735060d115c92ee73 atf-0.26.tar.gz
sha256 2a15172ddf6386297734c9800c899e6e8dc16c5a03931dcf95a9ab321a24cfe4 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
ATF_VERSION = 0.23
ATF_VERSION = 0.26
ATF_SITE = https://github.com/freebsd/atf/releases/download/atf-$(ATF_VERSION)
ATF_INSTALL_STAGING = YES
ATF_LICENSE = BSD-2-Clause, BSD-3-Clause

View File

@@ -1,64 +0,0 @@
From 4c7be1ec6ab74e973f8d18a9011fa349c3d9dd58 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Holger=20Hoffst=C3=A4tte?= <holger@applied-asynchrony.com>
Date: Mon, 2 Mar 2026 10:03:15 +0100
Subject: [PATCH] Fix build with LLVM-22
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
LLVM-22 changed the signatures of various createDiagnostics() calls [1].
Introduce a new version macro guard and adapt the code to the changed API.
Fixes #5483
[1] https://github.com/llvm/llvm-project/commit/30633f30894129919050f24fdd1f8f6bc46beae0
Signed-off-by: Holger Hoffstätte <holger@applied-asynchrony.com>
Upstream: https://github.com/iovisor/bcc/commit/4c7be1ec6ab74e973f8d18a9011fa349c3d9dd58
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
src/cc/frontends/clang/loader.cc | 15 ++++++++++++---
1 file changed, 12 insertions(+), 3 deletions(-)
diff --git a/src/cc/frontends/clang/loader.cc b/src/cc/frontends/clang/loader.cc
index 6f8387aaf017..1f706344724d 100644
--- a/src/cc/frontends/clang/loader.cc
+++ b/src/cc/frontends/clang/loader.cc
@@ -464,7 +464,10 @@ int ClangLoader::do_compile(
}
invocation0.getFrontendOpts().DisableFree = false;
-#if LLVM_VERSION_MAJOR >= 20
+#if LLVM_VERSION_MAJOR >= 22
+ compiler0.setVirtualFileSystem(llvm::vfs::getRealFileSystem());
+ compiler0.createDiagnostics(new IgnoringDiagConsumer());
+#elif LLVM_VERSION_MAJOR >= 20
compiler0.createDiagnostics(*llvm::vfs::getRealFileSystem(), new IgnoringDiagConsumer());
#else
compiler0.createDiagnostics(new IgnoringDiagConsumer());
@@ -487,7 +490,10 @@ int ClangLoader::do_compile(
add_main_input(invocation1, main_path, &*out_buf);
invocation1.getFrontendOpts().DisableFree = false;
-#if LLVM_VERSION_MAJOR >= 20
+#if LLVM_VERSION_MAJOR >= 22
+ compiler1.setVirtualFileSystem(llvm::vfs::getRealFileSystem());
+ compiler1.createDiagnostics();
+#elif LLVM_VERSION_MAJOR >= 20
compiler1.createDiagnostics(*llvm::vfs::getRealFileSystem());
#else
compiler1.createDiagnostics();
@@ -517,7 +523,10 @@ int ClangLoader::do_compile(
invocation2.getCodeGenOpts().setInlining(CodeGenOptions::NormalInlining);
// suppress warnings in the 2nd pass, but bail out on errors (our fault)
invocation2.getDiagnosticOpts().IgnoreWarnings = true;
-#if LLVM_VERSION_MAJOR >= 20
+#if LLVM_VERSION_MAJOR >= 22
+ compiler2.setVirtualFileSystem(llvm::vfs::getRealFileSystem());
+ compiler2.createDiagnostics();
+#elif LLVM_VERSION_MAJOR >= 20
compiler2.createDiagnostics(*llvm::vfs::getRealFileSystem());
#else
compiler2.createDiagnostics();

View File

@@ -0,0 +1,38 @@
From e5418ece42eb5bb322d220a2ff94f545d72a6f8a Mon Sep 17 00:00:00 2001
From: Viktor Malik <viktor.malik@gmail.com>
Date: Thu, 13 Aug 2026 08:22:00 +0200
Subject: [PATCH] src/cc: Fix MCContext constructor for LLVM 23
Two LLVM 23 patches [1,2] changed the MCContext constructor to take
MCAsmInfo, MCRegisterInfo, and MCSubtargetInfo by a reference rather
than by a pointer. Reflect the change in call of the constructor.
[1] https://github.com/llvm/llvm-project/commit/13e98d834101efd1794cdd026377c508293ee21b
[2] https://github.com/llvm/llvm-project/commit/d50631faad3003e73589528c83d3bbbad7ba72f1
Upstream: https://github.com/iovisor/bcc/commit/dad0db93fd0f443b2a4f43bc2f23c621c9202516
Signed-off-by: Viktor Malik <viktor.malik@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
---
src/cc/bcc_debug.cc | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/src/cc/bcc_debug.cc b/src/cc/bcc_debug.cc
index 2e53c44d..0812c4ab 100644
--- a/src/cc/bcc_debug.cc
+++ b/src/cc/bcc_debug.cc
@@ -148,7 +148,11 @@ void SourceDebugger::dump() {
T->createMCSubtargetInfo(TripleArg, "", ""));
MCObjectFileInfo MOFI;
#if LLVM_VERSION_MAJOR >= 13
+#if LLVM_VERSION_MAJOR >= 23
+ MCContext Ctx(TheTriple, *MAI, *MRI, *STI, nullptr);
+#else
MCContext Ctx(TheTriple, MAI.get(), MRI.get(), STI.get(), nullptr);
+#endif
Ctx.setObjectFileInfo(&MOFI);
MOFI.initMCObjectFileInfo(Ctx, false, false);
#else
--
2.55.0

View File

@@ -9,6 +9,7 @@ config BR2_PACKAGE_BCC
depends on BR2_USE_WCHAR # clang, python3
depends on BR2_TOOLCHAIN_HAS_THREADS # clang, python3
depends on !BR2_STATIC_LIBS # clang, python3
depends on !BR2_TOOLCHAIN_HAS_GCC_BUG_64735 # clang, llvm
select BR2_PACKAGE_CLANG
select BR2_PACKAGE_ELFUTILS
select BR2_PACKAGE_FLEX # needs FlexLexer.h
@@ -48,3 +49,8 @@ comment "bcc needs a glibc toolchain, C++, wchar, threads, dynamic libs, gcc >=
|| !BR2_USE_WCHAR \
|| !BR2_TOOLCHAIN_HAS_THREADS \
|| BR2_STATIC_LIBS
comment "bcc needs a toolchain not affected by GCC bug 64735"
depends on BR2_PACKAGE_LLVM_ARCH_SUPPORTS
depends on BR2_USE_MMU
depends on BR2_TOOLCHAIN_HAS_GCC_BUG_64735

View File

@@ -1,3 +1,3 @@
# locally calculated
sha256 ea8562246801c52a9c21c47076dae9ff1d3719bb86b96d7a6222b3724461f52c bcc-v0.36.1-git4.tar.gz
sha256 fa4302ee54d8638ca08fa7f2d1dfe7f39d4bd1bd02ccd2b298b0148369f3a680 bcc-v0.37.0-git4.tar.gz
sha256 b40930bbcf80744c86c46a12bc9da056641d722716c378f5659b9e555ef833e1 LICENSE.txt

View File

@@ -4,7 +4,7 @@
#
################################################################################
BCC_VERSION = v0.36.1
BCC_VERSION = v0.37.0
BCC_SITE = https://github.com/iovisor/bcc
BCC_SITE_METHOD = git
BCC_GIT_SUBMODULES = YES

View File

@@ -3,7 +3,7 @@ config BR2_PACKAGE_BCUSDK
depends on BR2_USE_MMU # libpthsem
depends on BR2_INSTALL_LIBSTDCPP
select BR2_PACKAGE_LIBPTHSEM
select BR2_PACKAGE_ARGP_STANDALONE if BR2_TOOLCHAIN_USES_UCLIBC || BR2_TOOLCHAIN_USES_MUSL
select BR2_PACKAGE_ARGP_STANDALONE if !BR2_TOOLCHAIN_USES_GLIBC
help
A free development environment for the Bus Coupling Units of
the European Installation Bus.

View File

@@ -5,7 +5,7 @@ config BR2_PACKAGE_BIND
depends on BR2_TOOLCHAIN_HAS_THREADS_NPTL # libuv
depends on BR2_INSTALL_LIBSTDCPP # liburcu
depends on !BR2_STATIC_LIBS # libuv
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 # libuv
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_8
depends on BR2_PACKAGE_LIBURCU_ARCH_SUPPORTS # liburcu
select BR2_PACKAGE_LIBCAP
select BR2_PACKAGE_LIBURCU
@@ -48,9 +48,9 @@ config BR2_PACKAGE_BIND_TOOLS
endif
comment "bind needs a toolchain w/ NPTL, dynamic library, C++, gcc >= 4.9"
comment "bind needs a toolchain w/ NPTL, dynamic library, C++, gcc >= 8"
depends on BR2_USE_MMU
depends on BR2_TOOLCHAIN_HAS_SYNC_4
depends on BR2_PACKAGE_LIBURCU_ARCH_SUPPORTS
depends on !BR2_TOOLCHAIN_HAS_THREADS_NPTL || BR2_STATIC_LIBS \
|| BR2_INSTALL_LIBSTDCPP || !BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 \
|| BR2_PACKAGE_LIBURCU_ARCH_SUPPORTS
|| !BR2_INSTALL_LIBSTDCPP || !BR2_TOOLCHAIN_GCC_AT_LEAST_8

View File

@@ -1,4 +1,4 @@
# Verified from https://ftp.isc.org/isc/bind9/9.20.26/bind-9.20.26.tar.xz.asc
# Verified from https://ftp.isc.org/isc/bind9/9.20.27/bind-9.20.29.tar.xz.asc
# with key 706B6C28620E76F91D11F7DF510A642A06C52CEC
sha256 55248def0f870c4c46b3de72978ea972615131516663188a4564dca1d20bf350 bind-9.20.26.tar.xz
sha256 587029508b3b1b43229fae416c97e5543aba45809cefaca98a5004a02a5736c1 bind-9.20.29.tar.xz
sha256 9734825d67a3ac967b2c2f7c9a83c9e5db1c2474dbe9599157c3a4188749ebd4 COPYRIGHT

View File

@@ -4,7 +4,7 @@
#
################################################################################
BIND_VERSION = 9.20.26
BIND_VERSION = 9.20.29
BIND_SOURCE= bind-$(BIND_VERSION).tar.xz
BIND_SITE = https://ftp.isc.org/isc/bind9/$(BIND_VERSION)
BIND_INSTALL_STAGING = YES

View File

@@ -1,31 +0,0 @@
From ba6ad3a18cb26b79e0e3b84c39f707535bbc344d Mon Sep 17 00:00:00 2001
From: Alan Modra <amodra@gmail.com>
Date: Wed, 19 Feb 2025 07:58:54 +1030
Subject: [PATCH] PR32716, objdump -i memory leak
PR binutils/32716
* bucomm.c (display_info): Free arg.info.
Upstream: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ba6ad3a18cb26b79e0e3b84c39f707535bbc344d
CVE: CVE-2025-3198
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
---
binutils/bucomm.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/binutils/bucomm.c b/binutils/bucomm.c
index ccf54099154..d4554737db1 100644
--- a/binutils/bucomm.c
+++ b/binutils/bucomm.c
@@ -435,6 +435,7 @@ display_info (void)
if (!arg.error)
display_target_tables (&arg);
+ free (arg.info);
return arg.error;
}
--
2.43.5

View File

@@ -1,61 +0,0 @@
From d320649e1805e5330a09b103d4ca890a12815f56 Mon Sep 17 00:00:00 2001
From: "H.J. Lu" <hjl.tools@gmail.com>
Date: Tue, 18 Nov 2025 12:09:54 +0800
Subject: [PATCH] or1k: Mark undefined TLS symbol as STT_TLS
Update or1k_apply_fix to handle all TLS relocations.
PR gas/33426
* config/tc-or1k.c (or1k_apply_fix): Handle all TLS relocations.
Signed-off-by: H.J. Lu <hjl.tools@gmail.com>
Upstream: https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=d320649e1805e5330a09b103d4ca890a12815f56
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
gas/config/tc-or1k.c | 18 ++++++++++++------
1 file changed, 12 insertions(+), 6 deletions(-)
diff --git a/gas/config/tc-or1k.c b/gas/config/tc-or1k.c
index f5a20b94fa7..798cf6d6acc 100644
--- a/gas/config/tc-or1k.c
+++ b/gas/config/tc-or1k.c
@@ -354,22 +354,28 @@ or1k_apply_fix (struct fix *f, valueT *t, segT s)
switch (f->fx_r_type)
{
+ case BFD_RELOC_OR1K_TLS_DTPMOD:
+ case BFD_RELOC_OR1K_TLS_DTPOFF:
case BFD_RELOC_OR1K_TLS_GD_HI16:
+ case BFD_RELOC_OR1K_TLS_GD_LO13:
case BFD_RELOC_OR1K_TLS_GD_LO16:
case BFD_RELOC_OR1K_TLS_GD_PG21:
- case BFD_RELOC_OR1K_TLS_GD_LO13:
+ case BFD_RELOC_OR1K_TLS_IE_AHI16:
+ case BFD_RELOC_OR1K_TLS_IE_HI16:
+ case BFD_RELOC_OR1K_TLS_IE_LO13:
+ case BFD_RELOC_OR1K_TLS_IE_LO16:
+ case BFD_RELOC_OR1K_TLS_IE_PG21:
case BFD_RELOC_OR1K_TLS_LDM_HI16:
+ case BFD_RELOC_OR1K_TLS_LDM_LO13:
case BFD_RELOC_OR1K_TLS_LDM_LO16:
case BFD_RELOC_OR1K_TLS_LDM_PG21:
- case BFD_RELOC_OR1K_TLS_LDM_LO13:
case BFD_RELOC_OR1K_TLS_LDO_HI16:
case BFD_RELOC_OR1K_TLS_LDO_LO16:
- case BFD_RELOC_OR1K_TLS_IE_HI16:
- case BFD_RELOC_OR1K_TLS_IE_LO16:
- case BFD_RELOC_OR1K_TLS_IE_PG21:
- case BFD_RELOC_OR1K_TLS_IE_LO13:
+ case BFD_RELOC_OR1K_TLS_LE_AHI16:
case BFD_RELOC_OR1K_TLS_LE_HI16:
case BFD_RELOC_OR1K_TLS_LE_LO16:
+ case BFD_RELOC_OR1K_TLS_LE_SLO16:
+ case BFD_RELOC_OR1K_TLS_TPOFF:
S_SET_THREAD_LOCAL (f->fx_addsy);
break;
default:
--
2.43.7

View File

@@ -1,35 +0,0 @@
From 5f66aee7f4bec7a2d8378034116f5e5c3dc50f41 Mon Sep 17 00:00:00 2001
From: Andreas Schwab <schwab@suse.de>
Date: Sat, 22 Nov 2025 11:29:43 +0100
Subject: [PATCH] gprofng: protect against standard library macros
The CALL_UTIL macro can expand to an unparsable expression of the argument
is a macro, like with the new const-preserving standard library macros in
C23.
* gprofng/src/collector_module.h (CALL_UTIL): Add parens to not
expand its argument if it is a function-like macro.
Upstream: https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=5f66aee7f4bec7a2d8378034116f5e5c3dc50f41
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
gprofng/src/collector_module.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/gprofng/src/collector_module.h b/gprofng/src/collector_module.h
index b64d69c45ab..859a6dd1f7d 100644
--- a/gprofng/src/collector_module.h
+++ b/gprofng/src/collector_module.h
@@ -119,7 +119,7 @@ typedef struct CollectorUtilFuncs
extern CollectorUtilFuncs __collector_util_funcs;
extern int __collector_dlsym_guard;
-#define CALL_UTIL(x) __collector_util_funcs.x
+#define CALL_UTIL(x) (__collector_util_funcs.x)
/* The following constants define the meaning of the "void *arg"
* argument of getFrameInfo().
--
2.43.7

View File

@@ -1,4 +1,4 @@
From d5f66b0da8d1e0ed091bff65f8a4db10a82a5420 Mon Sep 17 00:00:00 2001
From 0bf75276c392cac7794e78e1572abcd793d99e4e Mon Sep 17 00:00:00 2001
From: Romain Naour <romain.naour@gmail.com>
Date: Fri, 25 Dec 2015 11:38:13 +0100
Subject: [PATCH] sh-conf
@@ -14,6 +14,8 @@ Upstream: N/A [Buildroot specific]
Signed-off-by: Romain Naour <romain.naour@gmail.com>
[Thomas: rebase on top of 2.29, in which sh64 support was removed.]
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
[Bernd: rebased for version 2.47]
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
configure | 2 +-
configure.ac | 2 +-
@@ -23,9 +25,9 @@ diff --git a/configure b/configure
index bbfb5979546..bcd95684ae1 100755
--- a/configure
+++ b/configure
@@ -4056,7 +4056,7 @@ case "${target}" in
@@ -4197,7 +4197,7 @@
nvptx*-*-*)
noconfigdirs="$noconfigdirs target-libssp target-libstdc++-v3 target-libobjc"
noconfigdirs="$noconfigdirs target-libssp"
;;
- sh-*-*)
+ sh*-*-*)
@@ -36,9 +38,9 @@ diff --git a/configure.ac b/configure.ac
index f9694cdf901..d6a3623ba50 100644
--- a/configure.ac
+++ b/configure.ac
@@ -1278,7 +1278,7 @@ case "${target}" in
@@ -1366,7 +1366,7 @@
nvptx*-*-*)
noconfigdirs="$noconfigdirs target-libssp target-libstdc++-v3 target-libobjc"
noconfigdirs="$noconfigdirs target-libssp"
;;
- sh-*-*)
+ sh*-*-*)
@@ -46,5 +48,5 @@ index f9694cdf901..d6a3623ba50 100644
sh*-*-elf)
;;
--
2.48.1
2.51.1

View File

@@ -1,4 +1,4 @@
From 947a56b4ba73ec3fbf9c1fcff46d65754ba12e27 Mon Sep 17 00:00:00 2001
From 92f4bd0e1713577e30491e99a0226088eaeae740 Mon Sep 17 00:00:00 2001
From: Romain Naour <romain.naour@gmail.com>
Date: Fri, 25 Dec 2015 11:45:38 +0100
Subject: [PATCH] poison-system-directories
@@ -15,6 +15,8 @@ Signed-off-by: Romain Naour <romain.naour@gmail.com>
[Gustavo: adapt to binutils 2.25]
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
[Bernd: rebased for version 2.47]
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Upstream-Status: Inappropriate [distribution: codesourcery]
Upstream: N/A [Buildroot specific]
@@ -83,10 +85,10 @@ Signed-off-by: Scott Garman <scott.a.garman@intel.com>
9 files changed, 88 insertions(+)
diff --git a/ld/config.in b/ld/config.in
index 2d7b6406d2b..37cd12d20fa 100644
index 790efd336be..2b237bcda5e 100644
--- a/ld/config.in
+++ b/ld/config.in
@@ -78,6 +78,9 @@
@@ -86,6 +86,9 @@
language is requested. */
#undef ENABLE_NLS
@@ -97,27 +99,27 @@ index 2d7b6406d2b..37cd12d20fa 100644
#undef EXTRA_SHLIB_EXTENSION
diff --git a/ld/configure b/ld/configure
index d3995b73c06..2317f06682e 100755
index cd410bd64d1..7e9913949d4 100755
--- a/ld/configure
+++ b/ld/configure
@@ -844,6 +844,7 @@ with_lib_path
@@ -843,6 +843,7 @@ enable_checking
with_lib_path
enable_targets
enable_64_bit_bfd
with_sysroot
+enable_poison_system_directories
enable_gold
enable_got
enable_compressed_debug_sections
@@ -1537,6 +1538,8 @@ Optional Features:
--disable-largefile omit support for large files
--enable-checking enable run-time checks
--enable-targets alternative target configurations
--enable-64-bit-bfd 64-bit support (on hosts with narrower word sizes)
+ --enable-poison-system-directories
+ warn for use of native system library directories
--enable-gold[=ARG] build gold [ARG={default,yes,no}]
--enable-got=<type> GOT handling scheme (target, single, negative,
multigot)
@@ -15592,7 +15595,18 @@ else
@@ -15768,7 +15771,18 @@ else
fi
@@ -137,10 +139,10 @@ index d3995b73c06..2317f06682e 100755
# Check whether --enable-got was given.
if test "${enable_got+set}" = set; then :
diff --git a/ld/configure.ac b/ld/configure.ac
index 228f2ee4089..50a4b0f4db1 100644
index f528ae42ef7..dcf1e17fae6 100644
--- a/ld/configure.ac
+++ b/ld/configure.ac
@@ -102,6 +102,16 @@ AC_SUBST(use_sysroot)
@@ -115,6 +115,16 @@ AC_SUBST(use_sysroot)
AC_SUBST(TARGET_SYSTEM_ROOT)
AC_SUBST(TARGET_SYSTEM_ROOT_DEFINE)
@@ -158,7 +160,7 @@ index 228f2ee4089..50a4b0f4db1 100644
dnl "install_as_default" is set to false if gold is the default linker.
dnl "installed_linker" is the installed BFD linker name.
diff --git a/ld/ld.h b/ld/ld.h
index 254f0a097bb..daf777c65c8 100644
index c8688153bd4..0b16caf347a 100644
--- a/ld/ld.h
+++ b/ld/ld.h
@@ -166,6 +166,14 @@ typedef struct
@@ -177,10 +179,10 @@ index 254f0a097bb..daf777c65c8 100644
enum endian_enum endian;
diff --git a/ld/ld.texi b/ld/ld.texi
index f6384ad82dd..9d972ec9725 100644
index cf750d15259..1acaa26f107 100644
--- a/ld/ld.texi
+++ b/ld/ld.texi
@@ -3263,6 +3263,18 @@ bit string identifying the original linked file does not change.
@@ -3427,6 +3427,18 @@ bit string identifying the original linked file does not change.
Passing @code{none} for @var{style} disables the setting from any
@code{--build-id} options earlier on the command line.
@@ -200,10 +202,10 @@ index f6384ad82dd..9d972ec9725 100644
@item --package-metadata=@var{JSON}
Request the creation of a @code{.note.package} ELF note section. The
diff --git a/ld/ldfile.c b/ld/ldfile.c
index 12551504ae6..c6bfb98e522 100644
index 75fd360d5e3..3526ea8146c 100644
--- a/ld/ldfile.c
+++ b/ld/ldfile.c
@@ -328,6 +328,22 @@ ldfile_add_library_path (const char *name, bool cmdline)
@@ -326,6 +326,22 @@ ldfile_add_library_path (const char *name, bool cmdline)
new_dirs->name = concat (ld_sysroot, name + strlen ("$SYSROOT"), (const char *) NULL);
else
new_dirs->name = xstrdup (name);
@@ -227,10 +229,10 @@ index 12551504ae6..c6bfb98e522 100644
static void
diff --git a/ld/ldlex.h b/ld/ldlex.h
index b8b7d6b6829..c4b91482452 100644
index c8d61478c60..4b175dca108 100644
--- a/ld/ldlex.h
+++ b/ld/ldlex.h
@@ -171,6 +171,8 @@ enum option_values
@@ -174,6 +174,8 @@ enum option_values
OPTION_CTF_VARIABLES,
OPTION_NO_CTF_VARIABLES,
OPTION_CTF_SHARE_TYPES,
@@ -240,10 +242,10 @@ index b8b7d6b6829..c4b91482452 100644
OPTION_NO_ERROR_EXECSTACK,
OPTION_WARN_EXECSTACK_OBJECTS,
diff --git a/ld/ldmain.c b/ld/ldmain.c
index f1c5f7035c5..69dd2d89357 100644
index 67c60c3f80d..c2365e4006c 100644
--- a/ld/ldmain.c
+++ b/ld/ldmain.c
@@ -351,6 +351,8 @@ main (int argc, char **argv)
@@ -760,6 +760,8 @@ main (int argc, char **argv)
command_line.warn_mismatch = true;
command_line.warn_search_mismatch = true;
command_line.check_section_addresses = -1;
@@ -253,10 +255,10 @@ index f1c5f7035c5..69dd2d89357 100644
/* We initialize DEMANGLING based on the environment variable
COLLECT_NO_DEMANGLE. The gcc collect2 program will demangle the
diff --git a/ld/lexsup.c b/ld/lexsup.c
index 5399aa45b72..a04346bee58 100644
index bde20465835..422866f4ea9 100644
--- a/ld/lexsup.c
+++ b/ld/lexsup.c
@@ -650,6 +650,14 @@ static const struct ld_option ld_options[] =
@@ -653,6 +653,14 @@ static const struct ld_option ld_options[] =
" <method> is: share-unconflicted (default),\n"
" share-duplicated"),
TWO_DASHES },
@@ -271,7 +273,7 @@ index 5399aa45b72..a04346bee58 100644
};
#define OPTION_COUNT ARRAY_SIZE (ld_options)
@@ -662,6 +670,7 @@ parse_args (unsigned argc, char **argv)
@@ -665,6 +673,7 @@ parse_args (unsigned argc, char **argv)
int ingroup = 0;
char *default_dirlist = NULL;
char *shortopts;
@@ -279,7 +281,7 @@ index 5399aa45b72..a04346bee58 100644
struct option *longopts;
struct option *really_longopts;
int last_optind;
@@ -1789,6 +1798,14 @@ parse_args (unsigned argc, char **argv)
@@ -1849,6 +1858,14 @@ parse_args (unsigned argc, char **argv)
}
break;
@@ -294,7 +296,7 @@ index 5399aa45b72..a04346bee58 100644
case OPTION_PUSH_STATE:
input_flags.pushed = xmemdup (&input_flags,
sizeof (input_flags),
@@ -1933,6 +1950,10 @@ parse_args (unsigned argc, char **argv)
@@ -1999,6 +2016,10 @@ parse_args (unsigned argc, char **argv)
command_line.soname = NULL;
}
@@ -306,5 +308,5 @@ index 5399aa45b72..a04346bee58 100644
{
einfo (_("%P: missing --end-group; added as last command line option\n"));
--
2.48.1
2.51.1

View File

@@ -7,26 +7,26 @@ config BR2_PACKAGE_HOST_BINUTILS_SUPPORTS_CFI
choice
prompt "Binutils Version"
default BR2_BINUTILS_VERSION_2_45_X
default BR2_BINUTILS_VERSION_2_46_X
help
Select the version of binutils you wish to use.
config BR2_BINUTILS_VERSION_2_44_X
bool "binutils 2.44"
config BR2_BINUTILS_VERSION_2_45_X
bool "binutils 2.45.1"
config BR2_BINUTILS_VERSION_2_46_X
bool "binutils 2.46.1"
config BR2_BINUTILS_VERSION_2_47_X
bool "binutils 2.47"
endchoice
config BR2_BINUTILS_VERSION
string
default "2.44" if BR2_BINUTILS_VERSION_2_44_X
default "2.45.1" if BR2_BINUTILS_VERSION_2_45_X
default "2.46.1" if BR2_BINUTILS_VERSION_2_46_X
default "2.47" if BR2_BINUTILS_VERSION_2_47_X
config BR2_BINUTILS_GPROFNG
bool "gprofng support"

View File

@@ -1,7 +1,7 @@
# From https://gcc.gnu.org/pub/binutils/releases/sha512.sum
sha512 b85d3bbc0e334cf67a96219d3c7c65fbf3e832b2c98a7417bf131f3645a0307057ec81cd2b29ff2563cec53e3d42f73e2c60cc5708e80d4a730efdcc6ae14ad7 binutils-2.44.tar.xz
sha512 ea030419eba387579ab717be7e3223fc99e93b586860b06003c12489f93441640d4082736f76aa5e98233db4f46e232f536a45e471486de1f5b64e1b827c167e binutils-2.45.1.tar.xz
sha512 a5c65e56e400ed3fb8906a995dbb93eb5bea54b16344244653d7f44ef29ceb60270da263b19d25302c37759784e14fcb4b9421b29e0e2c7f450bd99f6bb4595c binutils-2.46.1.tar.xz
sha512 3126a1064374d8da40d4d70630c204ed1e75d542c447d53fca9778c7ceff095c28e9b445e15a313fef9729082d7966471ee6b5b715d479aa6d568528743e1d98 binutils-2.47.tar.xz
# locally computed
sha256 231f7edcc7352d7734a96eef0b8030f77982678c516876fcb81e25b32d68564c COPYING

View File

@@ -8,7 +8,7 @@
# If not, we do like other packages
BINUTILS_VERSION = $(call qstrip,$(BR2_BINUTILS_VERSION))
ifeq ($(BINUTILS_VERSION),)
BINUTILS_VERSION = 2.45.1
BINUTILS_VERSION = 2.46.1
endif # BINUTILS_VERSION
BINUTILS_SITE ?= $(BR2_GNU_MIRROR)/binutils
@@ -21,9 +21,6 @@ BINUTILS_LICENSE = GPL-3.0+, GPL-2.0+, LGPL-2.1+
BINUTILS_LICENSE_FILES = COPYING COPYING3 COPYING.LIB
BINUTILS_CPE_ID_VENDOR = gnu
# 0003-objdump-memleak.patch
BINUTILS_IGNORE_CVES += CVE-2025-3198
ifeq ($(BINUTILS_FROM_GIT),y)
BINUTILS_DEPENDENCIES += host-flex host-bison
HOST_BINUTILS_DEPENDENCIES += host-flex host-bison

View File

@@ -95,6 +95,9 @@ config BR2_PACKAGE_BOOST_DATE_TIME
A set of date-time libraries based on generic programming
concepts.
This library is header only since boost 1.77.0. Building a
stub library is still supported for backward compatibility.
config BR2_PACKAGE_BOOST_EXCEPTION
bool "boost-exception"
help
@@ -200,7 +203,6 @@ config BR2_PACKAGE_BOOST_LOG
depends on BR2_TOOLCHAIN_SUPPORTS_ALWAYS_LOCKFREE_ATOMIC_INTS # boost-atomic
depends on !BR2_TOOLCHAIN_HAS_GCC_BUG_64735 # boost-thread
select BR2_PACKAGE_BOOST_ATOMIC
select BR2_PACKAGE_BOOST_DATE_TIME
select BR2_PACKAGE_BOOST_FILESYSTEM
select BR2_PACKAGE_BOOST_REGEX
select BR2_PACKAGE_BOOST_THREAD
@@ -359,7 +361,6 @@ config BR2_PACKAGE_BOOST_WAVE
depends on !BR2_m68k_cf
depends on BR2_TOOLCHAIN_SUPPORTS_ALWAYS_LOCKFREE_ATOMIC_INTS # boost-thread
depends on !BR2_TOOLCHAIN_HAS_GCC_BUG_64735 # boost-thread
select BR2_PACKAGE_BOOST_DATE_TIME
select BR2_PACKAGE_BOOST_FILESYSTEM
select BR2_PACKAGE_BOOST_THREAD
help

View File

@@ -1,3 +1,3 @@
# locally calculated
sha256 555368f32f94bfcb74b119a3d9c67b68200be6375b8f452f794a2d3f6ebbcd16 bpftrace-0.26.1.tar.gz
sha256 87bf01fc3269ada7109531b0d964ceb5527d1ef7b9c9a4269b3aabdf872f0e26 bpftrace-0.27.0.tar.gz
sha256 cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30 LICENSE

View File

@@ -4,7 +4,7 @@
#
################################################################################
BPFTRACE_VERSION = 0.26.1
BPFTRACE_VERSION = 0.27.0
BPFTRACE_SITE = $(call github,bpftrace,bpftrace,v$(BPFTRACE_VERSION))
BPFTRACE_LICENSE = Apache-2.0
BPFTRACE_LICENSE_FILES = LICENSE

View File

@@ -1,3 +1,3 @@
# Locally generated
sha256 cad8fb5e23b422aef80ea14797de7c709c97a5d2bb8019cddaea87811b17a652 broot-1.58.0-cargo6.tar.gz
sha256 6daf2a7381fdbce5acc08261c2899304b4a1efa7c33623e456b8c45853cdb7a0 broot-1.60.1-cargo6.tar.gz
sha256 89461664ce2aee7d80ea8fba7118fe7abd490d76ba435cf1d81d3128e060711f LICENSE

View File

@@ -4,7 +4,7 @@
#
################################################################################
BROOT_VERSION = 1.58.0
BROOT_VERSION = 1.60.1
BROOT_SITE = $(call github,Canop,broot,v$(BROOT_VERSION))
BROOT_LICENSE = MIT
BROOT_LICENSE_FILES = LICENSE

View File

@@ -1,5 +1,5 @@
# From https://github.com/containers/bubblewrap/releases/download/v0.11.2/bubblewrap-0.11.2.tar.xz.sha256sum
sha256 69abc30005d2186baf7737feacd8da35633b93cf5af38838ecff17c5f8e924f6 bubblewrap-0.11.2.tar.xz
# From https://github.com/containers/bubblewrap/releases/tag/v0.13.0
sha256 4734237473c0e5d695e4e9034a34e43b2dbf5164655bd13fa59ae376b2b7a765 bubblewrap-0.13.0.tar.xz
# Hash for license files:
sha256 b7993225104d90ddd8024fd838faf300bea5e83d91203eab98e29512acebd69c COPYING
sha256 dc626520dcd53a22f727af3ee42c770e56c97a64fe3adb063799d8ab032fe551 COPYING

View File

@@ -4,21 +4,24 @@
#
################################################################################
BUBBLEWRAP_VERSION = 0.11.2
BUBBLEWRAP_VERSION = 0.13.0
BUBBLEWRAP_SITE = https://github.com/containers/bubblewrap/releases/download/v$(BUBBLEWRAP_VERSION)
BUBBLEWRAP_SOURCE = bubblewrap-$(BUBBLEWRAP_VERSION).tar.xz
BUBBLEWRAP_DEPENDENCIES = host-pkgconf libcap
BUBBLEWRAP_LICENSE = LGPL-2.0+
BUBBLEWRAP_LICENSE = LGPL-2.1+
BUBBLEWRAP_LICENSE_FILES = COPYING
BUBBLEWRAP_CPE_ID_VENDOR = projectatomic
define BUBBLEWRAP_LINUX_CONFIG_FIXUPS
$(call KCONFIG_ENABLE_OPT,CONFIG_USER_NS)
endef
BUBBLEWRAP_CONF_OPTS = \
-Dassume_kernel=$(shell echo $(LINUX_VERSION_PROBED) | grep -o '^[0-9]\+\.[0-9]\+\.[0-9]\+') \
-Dzsh_completion=disabled \
-Dman=disabled \
-Dpython=$(HOST_DIR)/bin/python \
-Drequire_userns=false \
-Dsupport_setuid=true \
-Dtests=false
ifeq ($(BR2_PACKAGE_BASH_COMPLETION),y)
@@ -36,10 +39,4 @@ else
BUBBLEWRAP_CONF_OPTS += -Dselinux=disabled
endif
# We need to mark bwrap as setuid, in case the kernel
# has user namespaces disabled for non-root users.
define BUBBLEWRAP_PERMISSIONS
/usr/bin/bwrap f 1755 0 0 - - - - -
endef
$(eval $(meson-package))

View File

@@ -1,5 +1,5 @@
# Locally computed, after checking PGP signature
sha256 cd2510f83bef3e08e660d99492ca7761b218ecb53ee01cdbbeee3d6aabc7734e cage-0.3.0.tar.gz
sha256 edafc173b6f56a3e1564933e272a54aaa9fe158d330e6a415d57b44ab880fe2b cage-0.3.1.tar.gz
# Hashes for license files:
sha256 e117104073335dbaf78596fb1bedf89dda63c71f60f0b665947b2d369c77ecee LICENSE

View File

@@ -4,7 +4,7 @@
#
################################################################################
CAGE_VERSION = 0.3.0
CAGE_VERSION = 0.3.1
CAGE_SITE = https://github.com/cage-kiosk/cage/releases/download/v$(CAGE_VERSION)
CAGE_LICENSE = MIT
CAGE_LICENSE_FILES = LICENSE

View File

@@ -1,3 +1,3 @@
# Locally computed
sha256 3dde63727549d4a39154e78b95f4a5dad96af236ca6cef531f347c0b923c74d5 cannelloni-2.0.0.tar.gz
sha256 c704707f7dd9f1ed64e9195097809f8882c03b1fa0a79864b8e3bf286521e3d7 cannelloni-2.1.2.tar.gz
sha256 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643 gpl-2.0.txt

View File

@@ -4,7 +4,7 @@
#
################################################################################
CANNELLONI_VERSION = 2.0.0
CANNELLONI_VERSION = 2.1.2
CANNELLONI_SITE = $(call github,mguentner,cannelloni,v$(CANNELLONI_VERSION))
CANNELLONI_LICENSE = GPL-2.0
CANNELLONI_LICENSE_FILES = gpl-2.0.txt

View File

@@ -0,0 +1,38 @@
From 33960e1a762667f890701775e184cbd06ee1bb66 Mon Sep 17 00:00:00 2001
From: tony mancill <tmancill@debian.org>
Date: Wed, 27 May 2026 06:13:20 -0700
Subject: [PATCH] Address compiler errors when building against OpenSSL 4.0
See https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137594
Upstream: https://github.com/capnproto/capnproto/commit/33960e1a762667f890701775e184cbd06ee1bb66
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
c++/src/kj/compat/tls.c++ | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/c++/src/kj/compat/tls.c++ b/c++/src/kj/compat/tls.c++
index 6affeb1f..87e308aa 100644
--- a/c++/src/kj/compat/tls.c++
+++ b/c++/src/kj/compat/tls.c++
@@ -1125,13 +1125,13 @@ kj::String TlsPeerIdentity::getCommonName() {
KJ_FAIL_REQUIRE("client did not provide a certificate") { return nullptr; }
}
- X509_NAME* subj = X509_get_subject_name(reinterpret_cast<X509*>(cert));
+ const X509_NAME* subj = X509_get_subject_name(reinterpret_cast<X509*>(cert));
int index = X509_NAME_get_index_by_NID(subj, NID_commonName, -1);
KJ_ASSERT(index != -1, "certificate has no common name?");
- X509_NAME_ENTRY* entry = X509_NAME_get_entry(subj, index);
+ const X509_NAME_ENTRY* entry = X509_NAME_get_entry(subj, index);
KJ_ASSERT(entry != nullptr);
- ASN1_STRING* data = X509_NAME_ENTRY_get_data(entry);
+ const ASN1_STRING* data = X509_NAME_ENTRY_get_data(entry);
KJ_ASSERT(data != nullptr);
unsigned char* out = nullptr;
--
2.47.3

View File

@@ -0,0 +1,29 @@
From 84dbf3c307dd98b5b7461d314a3b7e42318e374b Mon Sep 17 00:00:00 2001
From: tony mancill <tmancill@debian.org>
Date: Thu, 28 May 2026 21:32:58 -0700
Subject: [PATCH] Maintain compatibility with older OpenSSL versions
Upstream: https://github.com/capnproto/capnproto/commit/84dbf3c307dd98b5b7461d314a3b7e42318e374b
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
c++/src/kj/compat/tls.c++ | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/c++/src/kj/compat/tls.c++ b/c++/src/kj/compat/tls.c++
index 87e308aa..f7026d98 100644
--- a/c++/src/kj/compat/tls.c++
+++ b/c++/src/kj/compat/tls.c++
@@ -1127,7 +1127,8 @@ kj::String TlsPeerIdentity::getCommonName() {
const X509_NAME* subj = X509_get_subject_name(reinterpret_cast<X509*>(cert));
- int index = X509_NAME_get_index_by_NID(subj, NID_commonName, -1);
+ // Cast away const for compatibility with older OpenSSL versions
+ int index = X509_NAME_get_index_by_NID(const_cast<X509_NAME*>(subj), NID_commonName, -1);
KJ_ASSERT(index != -1, "certificate has no common name?");
const X509_NAME_ENTRY* entry = X509_NAME_get_entry(subj, index);
KJ_ASSERT(entry != nullptr);
--
2.47.3

View File

@@ -1,3 +1,3 @@
# Locally computed:
sha256 be23a52b85cf04cd9587612147a10b023d59ed9757fa1843cc99e615d6c0893c catch2-3.15.1.tar.gz
sha256 0957cae5821b17ce07f0833aaa52b5137643a8382203221f363a8303c109af34 catch2-3.16.0.tar.gz
sha256 c9bff75738922193e67fa726fa225535870d2aa1059f91452c411736284ad566 LICENSE.txt

View File

@@ -4,7 +4,7 @@
#
################################################################################
CATCH2_VERSION = 3.15.1
CATCH2_VERSION = 3.16.0
CATCH2_SITE = $(call github,catchorg,Catch2,v$(CATCH2_VERSION))
CATCH2_INSTALL_STAGING = YES
CATCH2_INSTALL_TARGET = NO

File diff suppressed because it is too large Load Diff

View File

@@ -1,5 +1,5 @@
# From https://github.com/ccache/ccache/releases/tag/v4.13.6
sha256 a7de667ca08cf67c3c8af9f213f6aa701a1188a2b3163fb74483858ce5e79fbb ccache-4.13.6.tar.xz
# From https://github.com/ccache/ccache/releases/tag/v4.14
sha256 b093ac5d38204cb4d9f29b0bbd570675aa5a592a78e6675b2c506dbe045234e7 ccache-4.14.tar.xz
# sha256 computed locally
sha256 80b5112739a423dfac7bed1ca8a1df3cccda3d794425441997d4462b83db4dd5 GPL-3.0.txt
sha256 072c40891d4ec8e1bcc93420031ebbbeb90b8f2c49fcd7c872d1bb05564c345c LICENSE.adoc

View File

@@ -4,7 +4,7 @@
#
################################################################################
CCACHE_VERSION = 4.13.6
CCACHE_VERSION = 4.14
CCACHE_SITE = https://github.com/ccache/ccache/releases/download/v$(CCACHE_VERSION)
CCACHE_SOURCE = ccache-$(CCACHE_VERSION).tar.xz
CCACHE_LICENSE = GPL-3.0+, others

View File

@@ -1,5 +1,5 @@
# Locally calculated after checking pgp signature
# https://chrony-project.org/releases/chrony-4.8-tar-gz-asc.txt
sha256 33ea8eb2a4daeaa506e8fcafd5d6d89027ed6f2f0609645c6f149b560d301706 chrony-4.8.tar.gz
# https://chrony-project.org/releases/chrony-4.9-tar-gz-asc.txt
sha256 4924c6f530105bcd5b9e9e33c48a2ae1bfd889222c8480bc41601110efc864d0 chrony-4.9.tar.gz
# Locally calculated
sha256 ab15fd526bd8dd18a9e77ebc139656bf4d33e97fc7238cd11bf60e2b9b8666c6 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
CHRONY_VERSION = 4.8
CHRONY_VERSION = 4.9
CHRONY_SITE = https://chrony-project.org/releases
CHRONY_LICENSE = GPL-2.0
CHRONY_LICENSE_FILES = COPYING

View File

@@ -6,6 +6,7 @@ config BR2_PACKAGE_CLAMAV
depends on BR2_USE_MMU # fork()
depends on !BR2_STATIC_LIBS # dlopen
depends on BR2_USE_WCHAR
depends on BR2_TOOLCHAIN_HAS_SYNC_4 # json-c
select BR2_PACKAGE_BZIP2
select BR2_PACKAGE_HOST_RUSTC
select BR2_PACKAGE_JSON_C
@@ -29,3 +30,4 @@ comment "clamav needs a toolchain w/ C++, dynamic library, threads, wchar"
|| !BR2_TOOLCHAIN_HAS_THREADS || !BR2_USE_WCHAR
depends on BR2_PACKAGE_HOST_RUSTC_TARGET_ARCH_SUPPORTS
depends on BR2_USE_MMU
depends on BR2_TOOLCHAIN_HAS_SYNC_4

View File

@@ -1,5 +1,5 @@
# From https://cmake.org/files/v4.4/cmake-4.4.0-SHA-256.txt
sha256 65757f442fdd242e27f1728fc26dc0cba4164f7a0791a5c788631c00080369bc cmake-4.4.0.tar.gz
# From https://cmake.org/files/v4.4/cmake-4.4.3-SHA-256.txt
sha256 c46400618b4f1f2b43507f24fb22f3ae830c3416cf23b776e16e1d413aa892f0 cmake-4.4.3.tar.gz
# Locally calculated
sha256 4382e7c1879ac90e3f101a395d23846fa4dbcaa1eed7265b43681e348754825d LICENSE.rst

View File

@@ -6,7 +6,7 @@
# When updating the version, please also update BR2_HOST_CMAKE_AT_LEAST_X_Y
CMAKE_VERSION_MAJOR = 4.4
CMAKE_VERSION = $(CMAKE_VERSION_MAJOR).0
CMAKE_VERSION = $(CMAKE_VERSION_MAJOR).3
CMAKE_SITE = https://cmake.org/files/v$(CMAKE_VERSION_MAJOR)
CMAKE_LICENSE = BSD-3-Clause
CMAKE_LICENSE_FILES = LICENSE.rst

Some files were not shown because too many files have changed in this diff Show More