Files
buildroot/package/fluidsynth/Config.in
Julien Olivain 566bdcb97f package/fluidsynth: security bump to version 2.5.7
For change log since v2.4.7, see:
https://github.com/FluidSynth/fluidsynth/releases

According to:
https://github.com/FluidSynth/fluidsynth/blob/master/doc/wiki/ChangeLog.md

FluidSynth 2.5.6 fixes:
CVE-2026-58264 - a heap-based buffer overrun in command handler (GHSA-mqmq-w63q-cj94)
CVE-2026-61714 - a heap-based buffer overflow in MIDI player (GHSA-976m-35rw-h3m6)
CVE-2026-61721 - a heap-based buffer overrun for DLS samples (GHSA-59ph-rx8r-8p4j)
CVE-2026-61723 - a DLS ptbl chunk integer overflow (GHSA-r4mc-v3p8-pv47)
CVE-2026-61722 - a DLS articulation chunk integer overflow (GHSA-hp72-35pr-6h6r)
CVE-2026-61720 - a SF2 DMOD chunk integer underflow (GHSA-rmc4-c8hw-455w)

FluidSynth 2.5.2 fixes:
CVE-2025-68617 - a heap-based use-after-free involving DLS files (GHSA-ffw2-xvvp-39ch)

SDL2 audio support was removed upstream in commit:
89145b004a

It was replaced by the newer SDL3. This commit reflects that change
(update option name and comments, add legacy option entry).

Also, dynamic library dependency was added in Buildroot commit:
111a1c7091
This commot removes the duplicate dependency for SDL3.

FluidSynth also added a native DLS soundfont support in:
c959f8d208
It is enabled by default and uses C++17. This commit adds a new
option with a dependency on gcc >= 7.

The license option hash is also updated, after the FSF address
update in:
db42fa333b

Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-23 21:29:20 +02:00

135 lines
3.9 KiB
Plaintext

config BR2_PACKAGE_FLUIDSYNTH
bool "fluidsynth"
depends on BR2_USE_WCHAR # libglib2
depends on BR2_TOOLCHAIN_HAS_THREADS # libglib2
depends on BR2_USE_MMU # libglib2
# the .pc file installed by fluidsynth does not mention its
# indirect dependencies in Libs.private.
depends on !BR2_STATIC_LIBS
depends on BR2_INSTALL_LIBSTDCPP
select BR2_PACKAGE_LIBGLIB2
help
FluidSynth is a real-time software synthesizer based on the
SoundFont 2 specifications and has reached widespread
distribution. FluidSynth itself does not have a graphical
user interface, but due to its powerful API several
applications utilize it and it has even found its way onto
embedded systems and is used in some mobile apps.
http://www.fluidsynth.org/
if BR2_PACKAGE_FLUIDSYNTH
comment "Output support"
config BR2_PACKAGE_FLUIDSYNTH_ALSA_LIB
bool "alsa"
default y
depends on BR2_TOOLCHAIN_HAS_THREADS
select BR2_PACKAGE_ALSA_LIB
select BR2_PACKAGE_ALSA_LIB_RAWMIDI
select BR2_PACKAGE_ALSA_LIB_SEQ
help
Enable alsa support.
comment "alsa support needs a toolchain w/ threads"
depends on !BR2_TOOLCHAIN_HAS_THREADS
config BR2_PACKAGE_FLUIDSYNTH_JACK2
bool "jack2"
depends on BR2_TOOLCHAIN_HAS_THREADS # jack2
depends on BR2_USE_MMU # jack2
depends on BR2_INSTALL_LIBSTDCPP # jack2
depends on !BR2_STATIC_LIBS # jack2
depends on BR2_TOOLCHAIN_HAS_SYNC_4 # jack2
select BR2_PACKAGE_JACK2
help
Enable jack support.
comment "jack support needs a toolchain w/ dynamic library, threads, C++"
depends on BR2_TOOLCHAIN_HAS_SYNC_4
depends on BR2_USE_MMU
depends on BR2_STATIC_LIBS || !BR2_INSTALL_LIBSTDCPP || \
!BR2_TOOLCHAIN_HAS_THREADS
config BR2_PACKAGE_FLUIDSYNTH_LIBSNDFILE
bool "libsndfile"
select BR2_PACKAGE_LIBSNDFILE
help
Enable libsndfile support, for writing output to WAV files.
config BR2_PACKAGE_FLUIDSYNTH_PORTAUDIO
bool "portaudio"
depends on BR2_TOOLCHAIN_HAS_THREADS
select BR2_PACKAGE_PORTAUDIO
help
Enable portaudio support.
comment "portaudio support needs a toolchain w/ threads"
depends on !BR2_TOOLCHAIN_HAS_THREADS
config BR2_PACKAGE_FLUIDSYNTH_PULSEAUDIO
bool "pulseaudio"
depends on BR2_PACKAGE_PULSEAUDIO_HAS_ATOMIC # pulseaudio
depends on BR2_USE_WCHAR # pulseaudio
depends on BR2_TOOLCHAIN_HAS_THREADS # pulseaudio
depends on !BR2_STATIC_LIBS # pulseaudio
depends on BR2_USE_MMU # pulseaudio
select BR2_PACKAGE_PULSEAUDIO
help
Enable PulseAudio support.
comment "pulseaudio support needs a toolchain w/ dynamic library, wchar, threads"
depends on BR2_USE_MMU
depends on BR2_PACKAGE_PULSEAUDIO_HAS_ATOMIC
depends on BR2_STATIC_LIBS || !BR2_USE_MMU || !BR2_TOOLCHAIN_HAS_THREADS
config BR2_PACKAGE_FLUIDSYNTH_SDL3
bool "sdl3"
select BR2_PACKAGE_SDL3
help
Enable SDL3 audio support.
comment "Misc options"
config BR2_PACKAGE_FLUIDSYNTH_DBUS
bool "dbus"
depends on BR2_TOOLCHAIN_HAS_THREADS
depends on BR2_USE_MMU
select BR2_PACKAGE_DBUS
help
Enable dbus support.
comment "dbus support needs a toolchain w/ threads"
depends on BR2_USE_MMU
depends on !BR2_TOOLCHAIN_HAS_THREADS
config BR2_PACKAGE_FLUIDSYNTH_FLOATS
bool "32-bit single precision float"
help
Enable 32-bit single precision float support, instead of
64-bit double precision floats for DSP samples.
config BR2_PACKAGE_FLUIDSYNTH_NATIVE_DLS
bool "Native DLS soundfont"
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_7 # C++17
help
Enable the native DLS soundfont format support.
comment "native dls soundfont support needs gcc >= 7"
depends on !BR2_TOOLCHAIN_GCC_AT_LEAST_7
config BR2_PACKAGE_FLUIDSYNTH_READLINE
bool "readline"
select BR2_PACKAGE_READLINE
help
Enable readline support, for better line editing in FluidSynth
shell.
endif # BR2_PACKAGE_FLUIDSYNTH
comment "fluidsynth needs a toolchain w/ threads, wchar, dynamic library, C++"
depends on BR2_USE_MMU
depends on !BR2_USE_WCHAR || !BR2_TOOLCHAIN_HAS_THREADS || \
BR2_STATIC_LIBS || !BR2_INSTALL_LIBSTDCPP