Files
buildroot/package/ntpsec/0001-wscript-remove-checks-for-bsd-string.h-fixes-host-co.patch
Peter Seiderer 1caeb632a6 package/ntpsec: security bump version to 1.2.5
Fixes: CVE-2026-18321:
https://nvd.nist.gov/vuln/detail/cve-2026-18321

- bump version to 1.2.5 (for details see [1])
- rebased 0001-wscript-remove-checks-for-bsd-string.h-fixes-host-co.patch
- rebased 0002-disable-PIE-support.patch
- removed 0003-ntpd-refclock_gpsd.c-Add-missing-time.h-for-strptim.patch
  (from upstream [2])
- moved 0004-refclock_gpsd-add-build-fix-for-gcc-14.x.patch to
  0003-refclock_gpsd-add-build-fix-for-gcc-14.x.patch, rebased and enhanced
  as the original conflicts with upstream commit 5505260c ("Fix redefined
  _XOPEN_SOURCE warning in refclock_gpsd.c") [3] and leads to the following
  compile failure:

    ../../ntpd/refclock_gpsd.c:113:21: error: operator ‘<’ has no left operand
      113 |   #if _XOPEN_SOURCE < 700
          |                     ^

[1] https://lists.ntpsec.org/pipermail/devel/2026-July/011029.html
[2] 5137c155d8
[3] 5505260cd1

Signed-off-by: Peter Seiderer <ps.report@gmx.net>
[Julien: mark commit as "security bump"]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-27 10:23:34 +02:00

76 lines
2.6 KiB
Diff

From 01d75b8d4624883133964deedc4c83e20adbee82 Mon Sep 17 00:00:00 2001
From: Peter Seiderer <ps.report@gmx.net>
Date: Thu, 16 Dec 2021 23:27:35 +0100
Subject: [PATCH] wscript: remove checks for bsd/string.h, fixes host-compile
failure
Fixes the following host-compile failure while cross-compiling
in case target libbsd is found:
[2/2] Compiling build/host/ntpd/ntp_parser.tab.c
In file included from ../../include/ntp.h:15,
from .../build/ntpsec-1_2_1/ntpd/ntp_parser.y:16:
../../include/ntp_stdlib.h:20:10: fatal error: bsd/string.h: No such file or directory
20 | #include <bsd/string.h>
| ^~~~~~~~~~~~~~
compilation terminated.
Signed-off-by: Peter Seiderer <ps.report@gmx.net>
[Rebased on ntpsec-1.2.5]
Signed-off-by: Peter Seiderer <ps.report@gmx.net>
---
include/ntp_stdlib.h | 4 ----
wscript | 14 --------------
2 files changed, 18 deletions(-)
diff --git a/include/ntp_stdlib.h b/include/ntp_stdlib.h
index 80e4765cf..c6cb04d04 100644
--- a/include/ntp_stdlib.h
+++ b/include/ntp_stdlib.h
@@ -16,10 +16,6 @@
#include "ntp_malloc.h"
#include "ntp_syslog.h"
-#ifdef HAVE_BSD_STRING_H
-#include <bsd/string.h>
-#endif
-
#ifdef __GNUC__
#define NTP_PRINTF(fmt, args) __attribute__((__format__(__printf__, fmt, args)))
#else
diff --git a/wscript b/wscript
index 65592c997..ba8939aff 100644
--- a/wscript
+++ b/wscript
@@ -643,19 +643,6 @@ int main(int argc, char **argv) {
prerequisites=ft[1], use=ft[2],
mandatory=ft[3])
- # check for BSD versions outside of libc
- if not ctx.get_define("HAVE_STRLCAT"):
- ret = probe_function(ctx, function='strlcat',
- prerequisites=['bsd/string.h'])
- if ret:
- ctx.define("HAVE_STRLCAT", 1, comment="Using bsd/strlcat")
-
- if not ctx.get_define("HAVE_STRLCPY"):
- ret = probe_function(ctx, function='strlcpy',
- prerequisites=['bsd/string.h'])
- if ret:
- ctx.define("HAVE_STRLCPY", 1, comment="Using bsd/strlcpy")
-
# Nobody uses the symbol, but this seems like a good sanity check.
ctx.check_cc(header_name="stdbool.h", mandatory=True,
comment="Sanity check.")
@@ -674,7 +661,6 @@ int main(int argc, char **argv) {
optional_headers = (
"alloca.h",
("arpa/nameser.h", ["sys/types.h"]),
- "bsd/string.h", # bsd emulation
("ifaddrs.h", ["sys/types.h"]),
("linux/if_addr.h", ["sys/socket.h"]),
("linux/rtnetlink.h", ["sys/socket.h"]),
--
2.55.0