Openembedded Core Discussions
 help / color / mirror / Atom feed
From: <daniel.turull@ericsson.com>
To: <openembedded-core@lists.openembedded.org>
Cc: Daniel Turull <daniel.turull@ericsson.com>,
	Richard Purdie <richard.purdie@linuxfoundation.org>
Subject: [wrynose][PATCH 07/20] xz: inherit upstream-stable-release-point
Date: Wed, 2 Sep 2026 11:59:07 +0200	[thread overview]
Message-ID: <20260902095920.2840293-8-daniel.turull@ericsson.com> (raw)
In-Reply-To: <20260902095920.2840293-1-daniel.turull@ericsson.com>

From: Daniel Turull <daniel.turull@ericsson.com>

XZ Utils's README documents that an even minor (Y) is a stable series
where the revision (Z) "is incremented when bugs get fixed without adding
any new features". So upgrades within a major.minor are stable point
upgrades per the OE-Core stable release policy (ref-manual, "Stable Point
Release Upgrades").

  https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
  https://github.com/tukaani-project/xz/blob/v5.8.3/README#L138

Checked the last two point releases for feature creep:

  5.8.3 (Mar 31 2026): one CVE (CVE-2026-34743, a buffer overflow in
  lzma_index_append), one invalid-memory-access fix, build portability
  fixes for Windows ARM64EC and Hurd, and man page translations. No new
  options or API.
  5.8.2 (Dec 17 2025): build portability fixes for four toolchains, a
  RHEL 9 kernel-bug workaround, and a resource-aware memory-limit default
  tweak that is a bugfix rather than a new feature. No new options or
  API.

Already tracked this way on the OE stable branches, counting only bumps
made since each branch forked from master: kirkstone picked up 5.2.6 and
scarthgap 5.4.7, one bump each.

AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>

Adapted for wrynose: applied to xz_5.8.2.bb (upstream: xz_5.8.3.bb).
(cherry picked from commit e336ba1ed32bc924dab329afe1d687e0382f1c87)
---
 meta/recipes-extended/xz/xz_5.8.2.bb | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/meta/recipes-extended/xz/xz_5.8.2.bb b/meta/recipes-extended/xz/xz_5.8.2.bb
index 15eaa7a52f..5e7ad1fc70 100644
--- a/meta/recipes-extended/xz/xz_5.8.2.bb
+++ b/meta/recipes-extended/xz/xz_5.8.2.bb
@@ -33,6 +33,10 @@ SRC_URI[sha256sum] = "ce09c50a5962786b83e5da389c90dd2c15ecd0980a258dd01f70f9e7ce
 UPSTREAM_CHECK_REGEX = "releases/tag/v(?P<pver>\d+(\.\d+)+)"
 UPSTREAM_CHECK_URI = "https://github.com/tukaani-project/xz/releases/"
 
+# XZ Utils publishes bugfix/security-only micro releases on its stable
+# (even-minor) branches.
+inherit upstream-stable-release-point
+
 CACHED_CONFIGUREVARS += "gl_cv_posix_shell=/bin/sh"
 
 inherit autotools gettext ptest


  parent reply	other threads:[~2026-09-02  9:59 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-02  9:59 [wrynose][PATCH 00/20] backport inherit upstream-stable-release-point daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 01/20] recipeutils: add optional stable_upgrade parameter to get_recipe_upgrade_status daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 02/20] upstream-stable-release-point.bbclass: add bbclass for stable point upgrade daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 03/20] devtool/upgrade.py: add --stable option daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 04/20] systemd: inherit upstream-stable-release-point daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 05/20] glib-2.0: " daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 06/20] dbus: " daniel.turull
2026-09-02  9:59 ` daniel.turull [this message]
2026-09-02  9:59 ` [wrynose][PATCH 08/20] git: " daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 09/20] perl: " daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 10/20] libxml2: " daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 11/20] python3: " daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 12/20] openssl: " daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 13/20] binutils: " daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 14/20] libgcrypt: " daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 15/20] sqlite3: " daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 16/20] lttng-tools: " daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 17/20] util-linux: " daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 18/20] lttng-ust: " daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 19/20] babeltrace2: " daniel.turull
2026-09-02  9:59 ` [wrynose][PATCH 20/20] lttng-modules: " daniel.turull

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260902095920.2840293-8-daniel.turull@ericsson.com \
    --to=daniel.turull@ericsson.com \
    --cc=openembedded-core@lists.openembedded.org \
    --cc=richard.purdie@linuxfoundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox