* [PATCH 2/6] libxml2: upgrade 2.15.3 -> 2.15.4
2026-09-06 8:05 [PATCH 1/6] hwdata: upgrade 0.410 -> 0.411 Richard Purdie
@ 2026-09-06 8:05 ` Richard Purdie
2026-09-06 8:05 ` [PATCH 3/6] pkgconf: upgrade 3.0.6 -> 3.0.7 Richard Purdie
` (3 subsequent siblings)
4 siblings, 0 replies; 7+ messages in thread
From: Richard Purdie @ 2026-09-06 8:05 UTC (permalink / raw)
To: openembedded-core
v2.15.4: Sep 01 2026
- xmlregexp: Prevent out-of-bounds read in NXT macro
- fix: add missing overflow checks in dict.c, uri.c, and valid.c
- xmlregexp: Calc string length after null checking
- xpointer: Check overflow in xmlXPtrEvalXPtrPart
- xmlIO: Check for int overflow before calling writecallback
- fix(xinclude): propagate parseFlags in xmlXIncludeProcess and xmlXIncludeProcessTree
- Improve bound checks for xmlcatalog and xmllint arguments (out-of-bound)
- Fix memory leak in static Windows library (memory-leak)
- xmlreader: Copy DTD in xmlTextReaderDumpCopy
- parser: Fix double free in xmlIOParseDTD (double-free)
- parser: fix division-by-zero when maxAmpl is set to 0
- parser: Fix memory leak in xmlCtxtSetSaxHandler (memory-leak)
- catalog: Make sure to reset catalog resolve cache
- xmlAddChild: unlink node before free for text nodes (memory-leak)
- Normalize entity values in attr in xmlNodeGetContent
- Handle whitespace for date/time/duration types
- catalog: Fix NULL deref for nextCatalog without 'catalog' attribute (null-deref)
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
---
...-installation-directories-in-libxml2.patch | 6 +-
.../libxml/libxml2/CVE-2026-11979.patch | 81 -------------------
.../libxml/libxml2/install-tests.patch | 2 +-
.../{libxml2_2.15.3.bb => libxml2_2.15.4.bb} | 3 +-
4 files changed, 5 insertions(+), 87 deletions(-)
delete mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch
rename meta/recipes-core/libxml/{libxml2_2.15.3.bb => libxml2_2.15.4.bb} (96%)
diff --git a/meta/recipes-core/libxml/libxml2/0001-Revert-cmake-Fix-installation-directories-in-libxml2.patch b/meta/recipes-core/libxml/libxml2/0001-Revert-cmake-Fix-installation-directories-in-libxml2.patch
index d19b284866d..a1d24b596e0 100644
--- a/meta/recipes-core/libxml/libxml2/0001-Revert-cmake-Fix-installation-directories-in-libxml2.patch
+++ b/meta/recipes-core/libxml/libxml2/0001-Revert-cmake-Fix-installation-directories-in-libxml2.patch
@@ -1,4 +1,4 @@
-From 803e6f21d3d7ef6399f6ffe58cd28fa6dc7b94e9 Mon Sep 17 00:00:00 2001
+From aa31b72c260de3f15289db8d78c9674b0cf55f7f Mon Sep 17 00:00:00 2001
From: Peter Marko <peter.marko@siemens.com>
Date: Mon, 26 May 2025 21:11:14 +0200
Subject: [PATCH] Revert "cmake: Fix installation directories in
@@ -66,10 +66,10 @@ index ff6433f..b775cfe 100644
set(LIBXML2_LIBRARIES ${LIBXML2_LIBRARY})
set(LIBXML2_INCLUDE_DIRS ${LIBXML2_INCLUDE_DIR})
diff --git a/meson.build b/meson.build
-index 2cfecb6..f78da31 100644
+index f8337ea..19fdbb0 100644
--- a/meson.build
+++ b/meson.build
-@@ -593,9 +593,6 @@ config_cmake = configuration_data()
+@@ -594,9 +594,6 @@ config_cmake = configuration_data()
config_cmake.set('LIBXML_MAJOR_VERSION', v_maj)
config_cmake.set('LIBXML_MINOR_VERSION', v_min)
config_cmake.set('LIBXML_MICRO_VERSION', v_mic)
diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch
deleted file mode 100644
index a14e566681e..00000000000
--- a/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch
+++ /dev/null
@@ -1,81 +0,0 @@
-From dfad0660f7dab3b5f8317b703b16ad0b0d12697d Mon Sep 17 00:00:00 2001
-From: Daniel Garcia Moreno <daniel.garcia@suse.com>
-Date: Fri, 22 May 2026 12:21:20 +0200
-Subject: [PATCH] xmlcatalog: overflow check for large --shell commands
-
-Fix https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1124
-
-CVE: CVE-2026-11979
-Signed-off-by: Anton Skorup <anton.skorup@axis.com>
-Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e]
----
- test/catalogs/test.sh | 11 +++++++++++
- xmlcatalog.c | 16 ++++++++++++++++
- 2 files changed, 27 insertions(+)
-
-diff --git a/test/catalogs/test.sh b/test/catalogs/test.sh
-index 7e5eaa76..84e8b90a 100755
---- a/test/catalogs/test.sh
-+++ b/test/catalogs/test.sh
-@@ -10,6 +10,17 @@ fi
-
- exitcode=0
-
-+# Test xmlcatalog --shell command line
-+# Case 1: Really long argument (470 chars)
-+input=""; for i in {1..470}; do input="${input}A"; done
-+echo $input | $xmlcatalog --shell test/catalogs/dockbook.xml || exit 1
-+# Case 2: public + long argument
-+input="public "; for i in {1..470}; do input="${input}A"; done
-+echo $input | $xmlcatalog --shell test/catalogs/dockbook.xml || exit 1
-+# Case 3: public + lots of args
-+input="public "; for i in {1..80}; do input="${input} x"; done
-+echo $input | $xmlcatalog --shell test/catalogs/dockbook.xml || exit 1
-+
- for i in test/catalogs/*.script ; do
- name=$(basename $i .script)
- xml="./test/catalogs/$name.xml"
-diff --git a/xmlcatalog.c b/xmlcatalog.c
-index b400c7cb..5113e930 100644
---- a/xmlcatalog.c
-+++ b/xmlcatalog.c
-@@ -135,6 +135,12 @@ static void usershell(void) {
- (*cur != '\n') && (*cur != '\r')) {
- if (*cur == 0)
- break;
-+ /* Do not read beyond the command array capacity */
-+ if (i >= (int)sizeof(command) - 2) {
-+ printf("Invalid command %s\n", cur);
-+ i = 0;
-+ break;
-+ }
- command[i++] = *cur++;
- }
- command[i] = 0;
-@@ -152,6 +158,11 @@ static void usershell(void) {
- while ((*cur != '\n') && (*cur != '\r') && (*cur != 0)) {
- if (*cur == 0)
- break;
-+ if (i >= (int)sizeof(arg) - 2) {
-+ printf("Invalid arg %s\n", arg);
-+ i = 0;
-+ break;
-+ }
- arg[i++] = *cur++;
- }
- arg[i] = 0;
-@@ -164,6 +175,11 @@ static void usershell(void) {
- cur = arg;
- memset(argv, 0, sizeof(argv));
- while (*cur != 0) {
-+ if (i >= (int)sizeof(argv) / (int)sizeof(char*)) {
-+ printf("Too much arguments\n");
-+ break;
-+ }
-+
- while ((*cur == ' ') || (*cur == '\t')) cur++;
- if (*cur == '\'') {
- cur++;
---
-2.43.0
-
diff --git a/meta/recipes-core/libxml/libxml2/install-tests.patch b/meta/recipes-core/libxml/libxml2/install-tests.patch
index 996ade614e2..55559b7df3e 100644
--- a/meta/recipes-core/libxml/libxml2/install-tests.patch
+++ b/meta/recipes-core/libxml/libxml2/install-tests.patch
@@ -1,4 +1,4 @@
-From c6b547e06beb0f0ba99e30d036f055eaed9ec4dc Mon Sep 17 00:00:00 2001
+From 11159757ae9ff484e02764b36cef970b3d0178c2 Mon Sep 17 00:00:00 2001
From: Ross Burton <ross.burton@arm.com>
Date: Fri, 17 Oct 2025 14:15:36 +0800
Subject: [PATCH] add yocto-specific install-ptest target
diff --git a/meta/recipes-core/libxml/libxml2_2.15.3.bb b/meta/recipes-core/libxml/libxml2_2.15.4.bb
similarity index 96%
rename from meta/recipes-core/libxml/libxml2_2.15.3.bb
rename to meta/recipes-core/libxml/libxml2_2.15.4.bb
index 8b0ba294122..99f3b9675aa 100644
--- a/meta/recipes-core/libxml/libxml2_2.15.3.bb
+++ b/meta/recipes-core/libxml/libxml2_2.15.4.bb
@@ -18,10 +18,9 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt
file://run-ptest \
file://install-tests.patch \
file://0001-Revert-cmake-Fix-installation-directories-in-libxml2.patch \
- file://CVE-2026-11979.patch \
"
-SRC_URI[archive.sha256sum] = "78262a6e7ac170d6528ebfe2efccdf220191a5af6a6cd61ea4a9a9a5042c7a07"
+SRC_URI[archive.sha256sum] = "98087fd181d9070724f3fbc65c7377db03038eb92bd882374daff44940138821"
SRC_URI[testtar.sha256sum] = "c6b2d42ee50b8b236e711a97d68e6c4b5c8d83e69a2be4722379f08702ea7273"
CVE_STATUS[CVE-2025-6170] = "fixed-version: fixed in version 2.14.5"
^ permalink raw reply related [flat|nested] 7+ messages in thread* [PATCH 3/6] pkgconf: upgrade 3.0.6 -> 3.0.7
2026-09-06 8:05 [PATCH 1/6] hwdata: upgrade 0.410 -> 0.411 Richard Purdie
2026-09-06 8:05 ` [PATCH 2/6] libxml2: upgrade 2.15.3 -> 2.15.4 Richard Purdie
@ 2026-09-06 8:05 ` Richard Purdie
2026-09-06 8:05 ` [PATCH 4/6] python3-uv-build: upgrade 0.12.9 -> 0.12.10 Richard Purdie
` (2 subsequent siblings)
4 siblings, 0 replies; 7+ messages in thread
From: Richard Purdie @ 2026-09-06 8:05 UTC (permalink / raw)
To: openembedded-core
Source: NEWS
Changes from 3.0.6 to 3.0.7:
----------------------------
* Correctness fixes:
- spdxtool now serializes the SPDX 3.0 suppliedBy property as a single Agent
reference instead of a one-element array, as required by the official JSON
schema.
- bomtool no longer emits PackageDownloadLocation twice for each package.
These fixes were contributed by R. Christian McDonald.
* Build, packaging and portability fixes:
- The Windows installer uses a default installation directory without a
space in its name. Patch by Kai Pastor.
- Skip the spdxtool allocation-failure test for static builds, where linker
wrapping also intercepts libpkgconf allocations and invalidates the test.
See https://github.com/pkgconf/pkgconf/issues/593.
- Use PKGCONF_ITEM_SIZE instead of PATH_MAX in the test runner, allowing it
to build on systems where PATH_MAX is not declared, such as GNU Hurd.
See https://github.com/pkgconf/pkgconf/issues/600.
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
---
.../pkgconf/{pkgconf_3.0.6.bb => pkgconf_3.0.7.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-devtools/pkgconf/{pkgconf_3.0.6.bb => pkgconf_3.0.7.bb} (97%)
diff --git a/meta/recipes-devtools/pkgconf/pkgconf_3.0.6.bb b/meta/recipes-devtools/pkgconf/pkgconf_3.0.7.bb
similarity index 97%
rename from meta/recipes-devtools/pkgconf/pkgconf_3.0.6.bb
rename to meta/recipes-devtools/pkgconf/pkgconf_3.0.7.bb
index 471433e7b54..4579476ae4d 100644
--- a/meta/recipes-devtools/pkgconf/pkgconf_3.0.6.bb
+++ b/meta/recipes-devtools/pkgconf/pkgconf_3.0.7.bb
@@ -20,7 +20,7 @@ SRC_URI = "\
file://pkg-config-native.in \
file://pkg-config-esdk.in \
"
-SRC_URI[sha256sum] = "c88a653fbabfa2a5857a30f6b6ad6c40dbacc3b7c72cc066e5c7dc4571cbddaa"
+SRC_URI[sha256sum] = "c926ff491cbd9a331a589160811bd97ab1749b4d5198a519338f2cdfabe6940a"
UPSTREAM_CHECK_REGEX = "pkgconf-(?P<pver>\d+\.\d+\.(?!9\d+)\d+)\.tar"
inherit autotools pkgconfig
^ permalink raw reply related [flat|nested] 7+ messages in thread* [PATCH 4/6] python3-uv-build: upgrade 0.12.9 -> 0.12.10
2026-09-06 8:05 [PATCH 1/6] hwdata: upgrade 0.410 -> 0.411 Richard Purdie
2026-09-06 8:05 ` [PATCH 2/6] libxml2: upgrade 2.15.3 -> 2.15.4 Richard Purdie
2026-09-06 8:05 ` [PATCH 3/6] pkgconf: upgrade 3.0.6 -> 3.0.7 Richard Purdie
@ 2026-09-06 8:05 ` Richard Purdie
2026-09-06 8:18 ` Patchtest results for " patchtest
2026-09-06 8:05 ` [PATCH 5/6] swig: upgrade 4.5.0 -> 4.5.1 Richard Purdie
2026-09-06 8:05 ` [PATCH 6/6] taglib: upgrade 2.3.1 -> 2.3.2 Richard Purdie
4 siblings, 1 reply; 7+ messages in thread
From: Richard Purdie @ 2026-09-06 8:05 UTC (permalink / raw)
To: openembedded-core
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
---
.../{python3-uv-build_0.12.9.bb => python3-uv-build_0.12.10.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-devtools/python/{python3-uv-build_0.12.9.bb => python3-uv-build_0.12.10.bb} (92%)
diff --git a/meta/recipes-devtools/python/python3-uv-build_0.12.9.bb b/meta/recipes-devtools/python/python3-uv-build_0.12.10.bb
similarity index 92%
rename from meta/recipes-devtools/python/python3-uv-build_0.12.9.bb
rename to meta/recipes-devtools/python/python3-uv-build_0.12.10.bb
index db313f57578..12cf5c7cc33 100644
--- a/meta/recipes-devtools/python/python3-uv-build_0.12.9.bb
+++ b/meta/recipes-devtools/python/python3-uv-build_0.12.10.bb
@@ -11,7 +11,7 @@ LIC_FILES_CHKSUM = "file://LICENSE-APACHE;md5=86d3f3a95c324c9479bd8986968f4327 \
file://crates/uv-pep508/License-Apache;md5=e23fadd6ceef8c618fc1c65191d846fa \
file://crates/uv-pep508/License-BSD;md5=ef7a6027dc4c2389b9afad7e690274c7"
-SRC_URI[sha256sum] = "5811820c072a3f7489133594028f451eea7d65ad94e97f58bff70da1b1a5970d"
+SRC_URI[sha256sum] = "c83c0f1dd2c921091d1974f56d64221c010e173d9e6d52ec2a2582650c2d5197"
require ${BPN}-crates.inc
^ permalink raw reply related [flat|nested] 7+ messages in thread* Patchtest results for [PATCH 4/6] python3-uv-build: upgrade 0.12.9 -> 0.12.10
2026-09-06 8:05 ` [PATCH 4/6] python3-uv-build: upgrade 0.12.9 -> 0.12.10 Richard Purdie
@ 2026-09-06 8:18 ` patchtest
0 siblings, 0 replies; 7+ messages in thread
From: patchtest @ 2026-09-06 8:18 UTC (permalink / raw)
To: Richard Purdie; +Cc: openembedded-core
[-- Attachment #1: Type: text/plain, Size: 3162 bytes --]
Thank you for your submission. Patchtest identified one
or more issues with the patch. Please see the log below for
more information:
---
Testing patch /home/patchtest/share/mboxes/4-6-python3-uv-build-upgrade-0.12.9---0.12.10.patch
FAIL: test commit message presence: Please include a commit message on your patch explaining the change (test_mbox.TestMbox.test_commit_message_presence)
PASS: test CVE check ignore (test_metadata.TestMetadata.test_cve_check_ignore)
PASS: test Signed-off-by presence (test_mbox.TestMbox.test_signed_off_by_presence)
PASS: test auh changelog truncation notice (test_mbox.TestMbox.test_auh_changelog_truncation_notice)
PASS: test author valid (test_mbox.TestMbox.test_author_valid)
PASS: test commit message user tags (test_mbox.TestMbox.test_commit_message_user_tags)
PASS: test lic files chksum modified not mentioned (test_metadata.TestMetadata.test_lic_files_chksum_modified_not_mentioned)
PASS: test max line length (test_metadata.TestMetadata.test_max_line_length)
PASS: test mbox format (test_mbox.TestMbox.test_mbox_format)
PASS: test non-AUH upgrade (test_mbox.TestMbox.test_non_auh_upgrade)
PASS: test shortlog format (test_mbox.TestMbox.test_shortlog_format)
PASS: test shortlog length (test_mbox.TestMbox.test_shortlog_length)
PASS: test target mailing list (test_mbox.TestMbox.test_target_mailing_list)
SKIP: pretest pylint: No python related patches, skipping test (test_python_pylint.PyLint.pretest_pylint)
SKIP: pretest src uri left files: Patch cannot be merged (test_metadata.TestMetadata.pretest_src_uri_left_files)
SKIP: test CVE tag format: No new source patches introduced (test_patch.TestPatch.test_cve_tag_format)
SKIP: test Signed-off-by presence: No new source patches introduced (test_patch.TestPatch.test_signed_off_by_presence)
SKIP: test Upstream-Status presence: No new source patches introduced (test_patch.TestPatch.test_upstream_status_presence_format)
SKIP: test bugzilla entry format: No bug ID found (test_mbox.TestMbox.test_bugzilla_entry_format)
SKIP: test lic files chksum presence: No added recipes, skipping test (test_metadata.TestMetadata.test_lic_files_chksum_presence)
SKIP: test license presence: No added recipes, skipping test (test_metadata.TestMetadata.test_license_presence)
SKIP: test pylint: No python related patches, skipping test (test_python_pylint.PyLint.test_pylint)
SKIP: test series merge on head: Merge test is disabled for now (test_mbox.TestMbox.test_series_merge_on_head)
SKIP: test src uri left files: Patch cannot be merged (test_metadata.TestMetadata.test_src_uri_left_files)
SKIP: test summary presence: No added recipes, skipping test (test_metadata.TestMetadata.test_summary_presence)
---
Please address the issues identified and
submit a new revision of the patch, or alternatively, reply to this
email with an explanation of why the patch should be accepted. If you
believe these results are due to an error in patchtest, please submit a
bug at https://bugzilla.yoctoproject.org/ (use the 'Patchtest' category
under 'Yocto Project Subprojects'). For more information on specific
failures, see: https://wiki.yoctoproject.org/wiki/Patchtest. Thank
you!
^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH 5/6] swig: upgrade 4.5.0 -> 4.5.1
2026-09-06 8:05 [PATCH 1/6] hwdata: upgrade 0.410 -> 0.411 Richard Purdie
` (2 preceding siblings ...)
2026-09-06 8:05 ` [PATCH 4/6] python3-uv-build: upgrade 0.12.9 -> 0.12.10 Richard Purdie
@ 2026-09-06 8:05 ` Richard Purdie
2026-09-06 8:05 ` [PATCH 6/6] taglib: upgrade 2.3.1 -> 2.3.2 Richard Purdie
4 siblings, 0 replies; 7+ messages in thread
From: Richard Purdie @ 2026-09-06 8:05 UTC (permalink / raw)
To: openembedded-core
- Regression fix for %rename using a format string, such as Ruby's -autorename,
dropping a class template's partial specializations.
- Regression fix restoring the %typemaps_string_alloc macro for string classes
using custom allocators.
- Python fix for compile errors in a module that %imports another module already
using the STL containers.
- MinGW configure and CMake PCRE2 version build fixes.
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
---
meta/recipes-devtools/swig/swig/determinism.patch | 2 +-
meta/recipes-devtools/swig/{swig_4.5.0.bb => swig_4.5.1.bb} | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
rename meta/recipes-devtools/swig/{swig_4.5.0.bb => swig_4.5.1.bb} (94%)
diff --git a/meta/recipes-devtools/swig/swig/determinism.patch b/meta/recipes-devtools/swig/swig/determinism.patch
index 9b021091cd9..c298dec322d 100644
--- a/meta/recipes-devtools/swig/swig/determinism.patch
+++ b/meta/recipes-devtools/swig/swig/determinism.patch
@@ -1,4 +1,4 @@
-From 218e2a20ff978cb28fefdf7b35af8a27768df4db Mon Sep 17 00:00:00 2001
+From db5d5b5fc68eb99ea69f85dfadde541c786ac6d1 Mon Sep 17 00:00:00 2001
From: Richard Purdie <richard.purdie@linuxfoundation.org>
Date: Mon, 10 Aug 2026 11:13:20 +0000
Subject: [PATCH] swig: Fix reproducibility issue
diff --git a/meta/recipes-devtools/swig/swig_4.5.0.bb b/meta/recipes-devtools/swig/swig_4.5.1.bb
similarity index 94%
rename from meta/recipes-devtools/swig/swig_4.5.0.bb
rename to meta/recipes-devtools/swig/swig_4.5.1.bb
index 161c23f0af3..250fc57a3a6 100644
--- a/meta/recipes-devtools/swig/swig_4.5.0.bb
+++ b/meta/recipes-devtools/swig/swig_4.5.1.bb
@@ -15,7 +15,7 @@ DEPENDS = "libpcre2 bison-native"
SRC_URI = "${SOURCEFORGE_MIRROR}/${BPN}/${BPN}-${PV}.tar.gz \
file://determinism.patch \
"
-SRC_URI[sha256sum] = "22ae0e887f8cca8031a325c67d005207653200b40e71edb3f88780e28e47d0ff"
+SRC_URI[sha256sum] = "7fec50b27deddab5455a9633780b6341eddfb96215a7619e93a76eb27178f653"
UPSTREAM_CHECK_URI = "https://sourceforge.net/projects/swig/files/swig/"
UPSTREAM_CHECK_REGEX = "swig-(?P<pver>\d+(\.\d+)+)"
^ permalink raw reply related [flat|nested] 7+ messages in thread* [PATCH 6/6] taglib: upgrade 2.3.1 -> 2.3.2
2026-09-06 8:05 [PATCH 1/6] hwdata: upgrade 0.410 -> 0.411 Richard Purdie
` (3 preceding siblings ...)
2026-09-06 8:05 ` [PATCH 5/6] swig: upgrade 4.5.0 -> 4.5.1 Richard Purdie
@ 2026-09-06 8:05 ` Richard Purdie
4 siblings, 0 replies; 7+ messages in thread
From: Richard Purdie @ 2026-09-06 8:05 UTC (permalink / raw)
To: openembedded-core
TagLib 2.3.2 (Sep 5, 2026)
==========================
* MP3: Fix parsing of per-frame unsynchronized ID3v2 frames.
* MP3: Accept iTunes ID3 frames with space padded ID3v2.2 ID.
* MP4: More tolerant handling of `covr` atom with wrong flags.
* MP4: Support additional codecs (AC3, DTS, EAC3, FLAC, Opus).
* Ogg: Support Vorbis comments from a multiplexed stream.
* WMA: Improve property interface for ASF files.
* RIFF: Support RF64 and BW64 64-bit extensions.
* Matroska: Fix file scanning with fast read style.
* Matroska: Load attachment data lazily on demand.
* Matroska: Read the segment title without audio properties.
* Verify values parsed from files to prevent resource exhaustion, denial of
service attacks and out of range conversions by crafted input for various
file formats (AIFF, APE, DSDIFF, FLAC, MP3, MP4, MPC, Matroska, Ogg, SHN,
WMA, XM).
* Fix data races in lazily initialized shared caches, test thread safety.
* Use `Requires.private` for zlib with `pkg-config`.
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
---
.../recipes-support/taglib/{taglib_2.3.1.bb => taglib_2.3.2.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-support/taglib/{taglib_2.3.1.bb => taglib_2.3.2.bb} (95%)
diff --git a/meta/recipes-support/taglib/taglib_2.3.1.bb b/meta/recipes-support/taglib/taglib_2.3.2.bb
similarity index 95%
rename from meta/recipes-support/taglib/taglib_2.3.1.bb
rename to meta/recipes-support/taglib/taglib_2.3.2.bb
index 0852295650d..1156e44e67f 100644
--- a/meta/recipes-support/taglib/taglib_2.3.1.bb
+++ b/meta/recipes-support/taglib/taglib_2.3.2.bb
@@ -11,7 +11,7 @@ DEPENDS = "zlib utfcpp"
SRC_URI = "http://taglib.github.io/releases/${BP}.tar.gz"
-SRC_URI[sha256sum] = "a19d90e6fd41d09a0281ec0fe762d51491d7a6ccffc923c4f7868c5e647ca230"
+SRC_URI[sha256sum] = "3ca2d8afaa7f1cf7f6ed10e511ebc368bfacd6dcaa3dbfa690b89e502e8963dc"
UPSTREAM_CHECK_URI = "https://taglib.org/"
UPSTREAM_CHECK_REGEX = "taglib-(?P<pver>\d+(\.\d+)+)\.tar"
^ permalink raw reply related [flat|nested] 7+ messages in thread