All of lore.kernel.org
 help / color / mirror / Atom feed
* [OE-core][scarthgap 00/35] Patch review
@ 2026-09-07 13:34 Yoann Congal
  2026-09-07 13:34 ` [OE-core][scarthgap 01/35] apt: mark CVE-2011-3374 as not-applicable-config Yoann Congal
                   ` (34 more replies)
  0 siblings, 35 replies; 37+ messages in thread
From: Yoann Congal @ 2026-09-07 13:34 UTC (permalink / raw)
  To: openembedded-core

Please review this set of changes for scarthgap and have comments back by
end of day Wednesday, September 9.

Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/?#/builders/29/builds/4676
* qemuppc (AB disk space issue) retried in https://autobuilder.yoctoproject.org/valkyrie/?#/builders/31/builds/1662
* pkgman-non-rpm (AB disk space issue) retried in https://autobuilder.yoctoproject.org/valkyrie/?#/builders/67/builds/4598
* oe-selftest-debian: AB disk space issue in https://autobuilder.yoctoproject.org/valkyrie/?#/builders/35/builds/4777
  but "Bitbake Selftest" passed.
  Retried in https://autobuilder.yoctoproject.org/valkyrie/?#/builders/35/builds/4779
  but, here, "Bitbake Selftest" failed on github infra issue (see #16415 – AB-INT: github infrastructure issues)
* oe-selftest-fedora failed with 16206 – [scarthgap] AB-INT: runtime_test.SystemTap.test_crosstap_* failures
  retried in https://autobuilder.yoctoproject.org/valkyrie/?#/builders/48/builds/4594

(TL;DR: No new bug seen in test with this series.)

The following changes since commit 048f2f8e8864ae5861afe95ea52efc0354bfc18c:

  build-appliance-image: Update to scarthgap head revision (2026-09-04 10:39:17 +0100)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
  https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut

for you to fetch changes up to 5b4292b3fc1586709dcdc27d7cfa3d880e6f338a:

  gnutls: Backport fix for CVE-2026-33846 (2026-09-06 01:25:16 +0200)

----------------------------------------------------------------

Anil Dongare (1):
  apt: mark CVE-2011-3374 as not-applicable-config

Bruce Ashfield (3):
  linux-yocto/6.6: update to v6.6.150
  linux-yocto/6.6: update to v6.6.151
  linux-yocto/6.6: fix tiny build

Darsh Kelaiya (3):
  python3-git: fix CVE-2026-42284
  python3-git: fix CVE-2026-44243
  python3-git: fix CVE-2026-44244

Eilís 'pidge' Ní Fhlannagáin (1):
  ovmf: fix tpm PACKAGECONFIG to use TPM2_ENABLE

Hetvi Thakar (3):
  python3-idna: Fix CVE-2026-45409
  python3-mako: Fix CVE-2026-41205
  libssh2: Fix CVE-2026-58051

Jaipaul Cheernam (2):
  util-linux: Fix CVE-2026-3184
  expat: set CVE_STATUS for CVE-2026-72522

Jakub Szczudlo (Nokia) (2):
  gnutls: fix CVE-2026-42010
  gnutls: fix for CVE-2026-42011

Peter Marko (3):
  libevent: set status for CVE-2026-63380
  alsa-lib: patch CVE-2026-56109
  busybox: patch CVE-2024-58251

Pratik Farkase (1):
  libevent: merge inherit statements

Roland Kovacs (1):
  gnutls: Backport fix for CVE-2026-33846

Ross Burton (2):
  libevent: use libtool to install test binaries
  libevent: upgrade 2.1.12 -> 2.1.13

Tim Orling (9):
  python3-babel: fix CVE_PRODUCT
  python3-click: fix CVE_PRODUCT
  python3-dbusmock: fix CVE_PRODUCT
  python3-attrs: fix CVE_PRODUCT
  python3-numpy: fix CVE_PRODUCT
  python3-pycryptodome: fix CVE_PRODUCT
  python3-wheel: fix CVE_PRODUCT
  python3-pycryptodomex: fix CVE_PRODUCT
  python3-git: fix CVE_PRODUCT

Vijay Anusuri (4):
  p11-kit: Fix CVE-2026-13757
  libxfont2: Fix CVE-2026-56001
  libxfont2: Fix CVE-2026-56002
  libxfont2: Fix CVE-2026-56003

 .../busybox/busybox/CVE-2024-58251.patch      |  51 ++++
 meta/recipes-core/busybox/busybox_1.36.1.bb   |   1 +
 meta/recipes-core/expat/expat_2.6.4.bb        |   3 +
 meta/recipes-core/ovmf/ovmf_git.bb            |   2 +-
 meta/recipes-core/util-linux/util-linux.inc   |   1 +
 .../util-linux/util-linux/CVE-2026-3184.patch |  61 ++++
 meta/recipes-devtools/apt/apt_2.6.1.bb        |   3 +
 .../python/python3-attrs_23.2.0.bb            |   2 +
 .../python/python3-babel_2.14.0.bb            |   2 +
 .../python/python3-click_8.1.7.bb             |   2 +
 .../python/python3-dbusmock_0.31.1.bb         |   2 +
 .../python/python3-git/CVE-2026-42284.patch   |  37 +++
 .../python3-git/CVE-2026-44243_p1.patch       | 136 +++++++++
 .../python3-git/CVE-2026-44243_p2.patch       |  86 ++++++
 .../python3-git/CVE-2026-44244_p1.patch       | 104 +++++++
 .../python3-git/CVE-2026-44244_p2.patch       |  30 ++
 .../python/python3-git_3.1.42.bb              |   8 +
 .../python3-idna/CVE-2026-45409_p1.patch      |  75 +++++
 .../python3-idna/CVE-2026-45409_p2.patch      |  48 ++++
 .../python3-idna/CVE-2026-45409_p3.patch      |  72 +++++
 .../python/python3-idna_3.7.bb                |   5 +
 .../python/python3-mako/CVE-2026-41205.patch  | 110 ++++++++
 .../python/python3-mako_1.3.2.bb              |   2 +
 .../python/python3-numpy_1.26.4.bb            |   2 +
 .../python/python3-pycryptodome_3.20.0.bb     |   1 +
 .../python/python3-pycryptodomex_3.20.0.bb    |   2 +
 .../python/python3-wheel_0.42.0.bb            |   2 +
 .../xorg-lib/libxfont2/CVE-2026-56001.patch   |  75 +++++
 .../xorg-lib/libxfont2/CVE-2026-56002.patch   | 138 +++++++++
 .../xorg-lib/libxfont2/CVE-2026-56003.patch   | 114 ++++++++
 .../xorg-lib/libxfont2_2.0.6.bb               |   5 +
 .../linux/linux-yocto-rt_6.6.bb               |   6 +-
 .../linux/linux-yocto-tiny_6.6.bb             |   6 +-
 meta/recipes-kernel/linux/linux-yocto_6.6.bb  |  28 +-
 .../alsa/alsa-lib/CVE-2026-56109.patch        |  33 +++
 .../alsa/alsa-lib_1.2.11.bb                   |   1 +
 .../gnutls/gnutls/CVE-2026-33846.patch        |  66 +++++
 .../gnutls/gnutls/CVE-2026-42010.patch        |  41 +++
 .../gnutls/gnutls/CVE-2026-42011_p1.patch     |  43 +++
 .../gnutls/gnutls/CVE-2026-42011_p2.patch     | 141 ++++++++++
 meta/recipes-support/gnutls/gnutls_3.8.4.bb   |   4 +
 ....c-patch-out-tests-that-require-a-wo.patch |   8 +-
 ...ncrease-default-timeval-tolerance-50.patch |  10 +-
 ...-monotonic_prc_fallback-as-retriable.patch |  11 +-
 ...ts-are-marked-failed-only-when-all-a.patch |   9 +-
 .../libevent/Makefile-missing-test-dir.patch  |  14 +-
 ...{libevent_2.1.12.bb => libevent_2.1.13.bb} |  16 +-
 .../libssh2/libssh2/CVE-2026-58051.patch      |  34 +++
 .../recipes-support/libssh2/libssh2_1.11.1.bb |   1 +
 .../p11-kit/files/CVE-2026-13757.patch        | 265 ++++++++++++++++++
 .../recipes-support/p11-kit/p11-kit_0.25.3.bb |   1 +
 51 files changed, 1863 insertions(+), 57 deletions(-)
 create mode 100644 meta/recipes-core/busybox/busybox/CVE-2024-58251.patch
 create mode 100644 meta/recipes-core/util-linux/util-linux/CVE-2026-3184.patch
 create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch
 create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch
 create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch
 create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch
 create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch
 create mode 100644 meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p1.patch
 create mode 100644 meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p2.patch
 create mode 100644 meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p3.patch
 create mode 100644 meta/recipes-devtools/python/python3-mako/CVE-2026-41205.patch
 create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56001.patch
 create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56002.patch
 create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56003.patch
 create mode 100644 meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-56109.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-33846.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42010.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p1.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p2.patch
 rename meta/recipes-support/libevent/{libevent_2.1.12.bb => libevent_2.1.13.bb} (84%)
 create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch
 create mode 100644 meta/recipes-support/p11-kit/files/CVE-2026-13757.patch



^ permalink raw reply	[flat|nested] 37+ messages in thread
* [OE-core][scarthgap 00/35] Patch review
@ 2024-06-30 20:07 Steve Sakoman
  0 siblings, 0 replies; 37+ messages in thread
From: Steve Sakoman @ 2024-06-30 20:07 UTC (permalink / raw)
  To: openembedded-core

Please review this set of changes for scarthgap and have comments back by
end of day Tuesday, July 2

Passed a-full on autobuilder:

https://autobuilder.yoctoproject.org/typhoon/#/builders/83/builds/7092

The following changes since commit 803cc32e72b4fc2fc28d92090e61f5dd288a10cb:

  build-appliance-image: Update to scarthgap head revision (2024-06-24 06:47:53 -0700)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
  https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut

Adithya Balakumar (1):
  wic/partition.py: Set hash_seed for empty ext partition

Bruce Ashfield (17):
  linux-yocto/6.6: update to v6.6.24
  linux-yocto/6.6: update CVE exclusions (6.6.24)
  linux-yocto/6.6: update to v6.6.25
  linux-yocto/6.6: update CVE exclusions (6.6.25)
  linux-yocto/6.6: nft: enable veth
  linux-yocto/6.6: update to v6.6.27
  linux-yocto/6.6: update CVE exclusions (6.6.27)
  linux-yocto/6.6: cfg: drop obselete options
  linux-yocto/6.6: update to v6.6.28
  linux-yocto/6.6: update CVE exclusions (6.6.28)
  linux-yocto/6.6: update to v6.6.29
  linux-yocto/6.6: update CVE exclusions (6.6.29)
  linux-yocto/6.6: fix kselftest failures
  linux-yocto/6.6: update to v6.6.30
  linux-yocto/6.6: intel configuration changes
  linux-yocto/6.6: update to v6.6.32
  linux-yocto/6.6: cfg: introduce Intel NPU fragment

Dmitry Baryshkov (2):
  ffmpeg: backport patches to use new Vulkan AV1 codec API
  ffmpeg: backport patch to fix errors with GCC 14

Jonas Gorski (1):
  linuxloader: add -armhf on arm only for TARGET_FPU 'hard'

Jose Quaresma (3):
  go: upgrade 1.22.2 -> 1.22.3
  go: upgrade 1.22.3 -> 1.22.4
  go: drop the old 1.4 bootstrap C version

Richard Purdie (2):
  maintainers: Drop go-native as recipe removed
  linux-yocto-custom: Fix comment override syntax

Ross Burton (4):
  expect: fix configure with GCC 14
  libxcrypt: correct the check for a working libucontext.h
  bash: fix configure checks that fail with GCC 14.1
  insane: handle dangling symlinks in the libdir QA check

Siddharth Doshi (1):
  libxml2: Upgrade 2.12.6 -> 2.12.8

Sundeep KOKKONDA (1):
  binutils: stable 2.42 branch updates

Trevor Gamblin (1):
  python3: upgrade 3.12.3 -> 3.12.4

Vijay Anusuri (1):
  wget: Fix for CVE-2024-38428

joshua Watt (1):
  classes/create-spdx-2.2: Fix SPDX Namespace Prefix

 .../linux/linux-yocto-custom.bb               |    2 +-
 meta/classes-global/insane.bbclass            |    4 +-
 meta/classes-recipe/linuxloader.bbclass       |    2 +-
 meta/classes/create-spdx-2.2.bbclass          |    2 +-
 meta/conf/distro/include/maintainers.inc      |    1 -
 .../libxcrypt/files/configure-c99.patch       |   39 +
 meta/recipes-core/libxcrypt/libxcrypt.inc     |    3 +-
 .../{libxml2_2.12.6.bb => libxml2_2.12.8.bb}  |    2 +-
 .../binutils/binutils-2.42.inc                |    3 +-
 ...sserts-from-operand-qualifier-decode.patch |  382 ---
 .../expect/expect/expect-configure-c99.patch  |  201 ++
 meta/recipes-devtools/expect/expect_5.45.4.bb |    1 +
 .../go/{go-1.22.2.inc => go-1.22.4.inc}       |    2 +-
 ...e_1.22.2.bb => go-binary-native_1.22.4.bb} |    6 +-
 ..._1.22.2.bb => go-cross-canadian_1.22.4.bb} |    0
 ...{go-cross_1.22.2.bb => go-cross_1.22.4.bb} |    0
 ...osssdk_1.22.2.bb => go-crosssdk_1.22.4.bb} |    0
 meta/recipes-devtools/go/go-native_1.22.2.bb  |   58 -
 ...runtime_1.22.2.bb => go-runtime_1.22.4.bb} |    0
 .../go/{go_1.22.2.bb => go_1.22.4.bb}         |    0
 .../{python3_3.12.3.bb => python3_3.12.4.bb}  |    2 +-
 .../bash/bash/0001-fix-c99.patch              |   41 +
 meta/recipes-extended/bash/bash_5.2.21.bb     |    1 +
 .../wget/wget/CVE-2024-38428.patch            |   79 +
 meta/recipes-extended/wget/wget_1.21.4.bb     |    1 +
 .../linux/cve-exclusion_6.6.inc               | 2720 ++++++++++++-----
 .../linux/linux-yocto-rt_6.6.bb               |    6 +-
 .../linux/linux-yocto-tiny_6.6.bb             |    6 +-
 meta/recipes-kernel/linux/linux-yocto_6.6.bb  |   28 +-
 .../ffmpeg/ffmpeg/av1_ordering_info.patch     |   91 +
 .../ffmpeg/ffmpeg/vulkan_av1_stable_API.patch | 1382 +++++++++
 .../ffmpeg/ffmpeg/vulkan_fix_gcc14.patch      |  102 +
 .../recipes-multimedia/ffmpeg/ffmpeg_6.1.1.bb |    7 +-
 scripts/lib/wic/partition.py                  |   37 +-
 34 files changed, 3999 insertions(+), 1212 deletions(-)
 create mode 100644 meta/recipes-core/libxcrypt/files/configure-c99.patch
 rename meta/recipes-core/libxml/{libxml2_2.12.6.bb => libxml2_2.12.8.bb} (97%)
 delete mode 100644 meta/recipes-devtools/binutils/binutils/0016-aarch64-Remove-asserts-from-operand-qualifier-decode.patch
 create mode 100644 meta/recipes-devtools/expect/expect/expect-configure-c99.patch
 rename meta/recipes-devtools/go/{go-1.22.2.inc => go-1.22.4.inc} (89%)
 rename meta/recipes-devtools/go/{go-binary-native_1.22.2.bb => go-binary-native_1.22.4.bb} (78%)
 rename meta/recipes-devtools/go/{go-cross-canadian_1.22.2.bb => go-cross-canadian_1.22.4.bb} (100%)
 rename meta/recipes-devtools/go/{go-cross_1.22.2.bb => go-cross_1.22.4.bb} (100%)
 rename meta/recipes-devtools/go/{go-crosssdk_1.22.2.bb => go-crosssdk_1.22.4.bb} (100%)
 delete mode 100644 meta/recipes-devtools/go/go-native_1.22.2.bb
 rename meta/recipes-devtools/go/{go-runtime_1.22.2.bb => go-runtime_1.22.4.bb} (100%)
 rename meta/recipes-devtools/go/{go_1.22.2.bb => go_1.22.4.bb} (100%)
 rename meta/recipes-devtools/python/{python3_3.12.3.bb => python3_3.12.4.bb} (99%)
 create mode 100644 meta/recipes-extended/bash/bash/0001-fix-c99.patch
 create mode 100644 meta/recipes-extended/wget/wget/CVE-2024-38428.patch
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/av1_ordering_info.patch
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/vulkan_av1_stable_API.patch
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/vulkan_fix_gcc14.patch

-- 
2.34.1



^ permalink raw reply	[flat|nested] 37+ messages in thread

end of thread, other threads:[~2026-09-07 13:36 UTC | newest]

Thread overview: 37+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-07 13:34 [OE-core][scarthgap 00/35] Patch review Yoann Congal
2026-09-07 13:34 ` [OE-core][scarthgap 01/35] apt: mark CVE-2011-3374 as not-applicable-config Yoann Congal
2026-09-07 13:34 ` [OE-core][scarthgap 02/35] python3-idna: Fix CVE-2026-45409 Yoann Congal
2026-09-07 13:34 ` [OE-core][scarthgap 03/35] p11-kit: Fix CVE-2026-13757 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 04/35] util-linux: Fix CVE-2026-3184 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 05/35] libxfont2: Fix CVE-2026-56001 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 06/35] libxfont2: Fix CVE-2026-56002 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 07/35] libxfont2: Fix CVE-2026-56003 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 08/35] libevent: use libtool to install test binaries Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 09/35] libevent: merge inherit statements Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 10/35] libevent: upgrade 2.1.12 -> 2.1.13 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 11/35] libevent: set status for CVE-2026-63380 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 12/35] alsa-lib: patch CVE-2026-56109 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 13/35] gnutls: fix CVE-2026-42010 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 14/35] gnutls: fix for CVE-2026-42011 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 15/35] python3-babel: fix CVE_PRODUCT Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 16/35] python3-click: " Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 17/35] python3-dbusmock: " Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 18/35] python3-attrs: " Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 19/35] python3-numpy: " Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 20/35] python3-pycryptodome: " Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 21/35] python3-wheel: " Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 22/35] python3-pycryptodomex: " Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 23/35] python3-git: fix CVE-2026-42284 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 24/35] python3-git: fix CVE-2026-44243 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 25/35] python3-git: fix CVE-2026-44244 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 26/35] expat: set CVE_STATUS for CVE-2026-72522 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 27/35] ovmf: fix tpm PACKAGECONFIG to use TPM2_ENABLE Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 28/35] python3-mako: Fix CVE-2026-41205 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 29/35] linux-yocto/6.6: update to v6.6.150 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 30/35] linux-yocto/6.6: update to v6.6.151 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 31/35] linux-yocto/6.6: fix tiny build Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 32/35] libssh2: Fix CVE-2026-58051 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 33/35] python3-git: fix CVE_PRODUCT Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 34/35] busybox: patch CVE-2024-58251 Yoann Congal
2026-09-07 13:35 ` [OE-core][scarthgap 35/35] gnutls: Backport fix for CVE-2026-33846 Yoann Congal
  -- strict thread matches above, loose matches on Subject: below --
2024-06-30 20:07 [OE-core][scarthgap 00/35] Patch review Steve Sakoman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.