* [PATCH 1/5] cairo: upgrade 1.18.4 -> 1.18.6
@ 2026-09-21 14:58 Richard Purdie
2026-09-21 14:58 ` [PATCH 2/5] harfbuzz: upgrade 14.4.0 -> 14.5.0 Richard Purdie
` (3 more replies)
0 siblings, 4 replies; 5+ messages in thread
From: Richard Purdie @ 2026-09-21 14:58 UTC (permalink / raw)
To: openembedded-core
Release 1.18.6 (2026-09-20 Emmanuele Bassi <ebassi@gnome.org>)
==============================================================
A new stable release.
The XCB surface triggered an UAF warning when building with GCC. [#898]
The clipping code was accessing various fields in a guard value, and
causing a crash inside Inkscape. See: https://gitlab.com/inkscape/inkscape/-/issues/5631
Multiple fixes for the Windows backends, including improvements in the
thread safety of the DirectWrite code. [#897]
The DirectWrite backend now supports COLRv1 fonts. [#903]
Multiple fixes for building with MSVC and ClangCL.
A leak in the PDF surfaces has been fixed. [!644]
Various gaps between abutting rectangles when drawing with ANTIALIAS_NONE
were removed by using absolute coordinates and avoiding rounding
errors. [#976]
Remove an overflow when computing the buffer size in the XRender code. [#950]
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
---
.../cairo-get_bitmap_surface-bsc1036789-CVE-2017-7475.diff | 6 +++---
.../cairo/{cairo_1.18.4.bb => cairo_1.18.6.bb} | 2 +-
2 files changed, 4 insertions(+), 4 deletions(-)
rename meta/recipes-graphics/cairo/{cairo_1.18.4.bb => cairo_1.18.6.bb} (97%)
diff --git a/meta/recipes-graphics/cairo/cairo/cairo-get_bitmap_surface-bsc1036789-CVE-2017-7475.diff b/meta/recipes-graphics/cairo/cairo/cairo-get_bitmap_surface-bsc1036789-CVE-2017-7475.diff
index 79ef16dfb91..c6c5ba09c62 100644
--- a/meta/recipes-graphics/cairo/cairo/cairo-get_bitmap_surface-bsc1036789-CVE-2017-7475.diff
+++ b/meta/recipes-graphics/cairo/cairo/cairo-get_bitmap_surface-bsc1036789-CVE-2017-7475.diff
@@ -1,4 +1,4 @@
-From 054ad9b65e074899c82e75cfc6623cfe29ab1fea Mon Sep 17 00:00:00 2001
+From e21fd76dc2572061d078a41fd5faa76592483e88 Mon Sep 17 00:00:00 2001
From: Fan Xin <fan.xin@jp.fujitsu.com>
Date: Tue, 6 Jun 2017 15:57:52 +0900
Subject: [PATCH] Cairo: Fix Denial-of-Service Attack due to Logical Problem in
@@ -15,10 +15,10 @@ Signed-off-by: Fan Xin <fan.xin@jp.fujitsu.com>
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/cairo-ft-font.c b/src/cairo-ft-font.c
-index b5d08ee..5e20ae1 100644
+index b9bdf81..fa9c05d 100644
--- a/src/cairo-ft-font.c
+++ b/src/cairo-ft-font.c
-@@ -1220,7 +1220,7 @@ _get_bitmap_surface (FT_Bitmap *bitmap,
+@@ -1231,7 +1231,7 @@ _get_bitmap_surface (FT_Bitmap *bitmap,
width = bitmap->width;
height = bitmap->rows;
diff --git a/meta/recipes-graphics/cairo/cairo_1.18.4.bb b/meta/recipes-graphics/cairo/cairo_1.18.6.bb
similarity index 97%
rename from meta/recipes-graphics/cairo/cairo_1.18.4.bb
rename to meta/recipes-graphics/cairo/cairo_1.18.6.bb
index ae448101d90..138ad7492b1 100644
--- a/meta/recipes-graphics/cairo/cairo_1.18.4.bb
+++ b/meta/recipes-graphics/cairo/cairo_1.18.6.bb
@@ -31,7 +31,7 @@ SRC_URI = "http://cairographics.org/releases/cairo-${PV}.tar.xz \
file://cairo-get_bitmap_surface-bsc1036789-CVE-2017-7475.diff \
"
-SRC_URI[sha256sum] = "445ed8208a6e4823de1226a74ca319d3600e83f6369f99b14265006599c32ccb"
+SRC_URI[sha256sum] = "1c767308174337a74694da0f3ec069c271452163a1ef4540964c50c301f157d4"
inherit meson pkgconfig upstream-version-is-even gtk-doc multilib_script
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH 2/5] harfbuzz: upgrade 14.4.0 -> 14.5.0
2026-09-21 14:58 [PATCH 1/5] cairo: upgrade 1.18.4 -> 1.18.6 Richard Purdie
@ 2026-09-21 14:58 ` Richard Purdie
2026-09-21 14:58 ` [PATCH 3/5] python3-pyparsing: upgrade 3.3.2 -> 3.3.3 Richard Purdie
` (2 subsequent siblings)
3 siblings, 0 replies; 5+ messages in thread
From: Richard Purdie @ 2026-09-21 14:58 UTC (permalink / raw)
To: openembedded-core
Overview of changes leading to 14.5.0
Monday, September 21, 2026
=====================================
- Update Unicode 18.0 data and script support, including script values for
Jurchen, Proto-Cuneiform, and Seal, and the corresponding shaping support.
- Add support for VARC table subsetting, including pruning auxiliary data,
remapping glyph IDs, and guarding the feature in lean builds.
- Add rendering work budgets to the draw and paint APIs and share them across
the raster, vector, GPU, and Cairo renderers so nested outline work remains
bounded.
- Improve performance in set iteration, lookup traversal, and the repacker, and
add coverage for new benchmarks and fuzzing seeds.
- Fix various correctness and robustness issues across the CFF, Graphite,
DirectWrite, and repacker code paths, including memory leaks, overflow checks,
bounds issues, and malformed-font handling.
- Various build, portability, and CI fixes.
- New API:
* Common:
+HB_BUDGET_DEFAULT
+HB_BUDGET_UNLIMITED
+HB_SCRIPT_JURCHEN
+HB_SCRIPT_PROTO_CUNEIFORM
+HB_SCRIPT_SEAL
* Draw:
+hb_draw_set_budget_func_t
+hb_draw_get_budget_func_t
+hb_draw_get_budget_remaining_func_t
+hb_draw_funcs_set_set_budget_func()
+hb_draw_funcs_set_get_budget_func()
+hb_draw_funcs_set_get_budget_remaining_func()
+hb_draw_set_budget()
+hb_draw_get_budget()
+hb_draw_get_budget_remaining()
* Paint:
+hb_paint_set_budget_func_t
+hb_paint_get_budget_func_t
+hb_paint_get_budget_remaining_func_t
+hb_paint_funcs_set_set_budget_func()
+hb_paint_funcs_set_get_budget_func()
+hb_paint_funcs_set_get_budget_remaining_func()
+hb_paint_set_budget()
+hb_paint_get_budget()
+hb_paint_get_budget_remaining()
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
---
.../harfbuzz/{harfbuzz_14.4.0.bb => harfbuzz_14.5.0.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-graphics/harfbuzz/{harfbuzz_14.4.0.bb => harfbuzz_14.5.0.bb} (96%)
diff --git a/meta/recipes-graphics/harfbuzz/harfbuzz_14.4.0.bb b/meta/recipes-graphics/harfbuzz/harfbuzz_14.5.0.bb
similarity index 96%
rename from meta/recipes-graphics/harfbuzz/harfbuzz_14.4.0.bb
rename to meta/recipes-graphics/harfbuzz/harfbuzz_14.5.0.bb
index a5c601b1dee..438aa23133c 100644
--- a/meta/recipes-graphics/harfbuzz/harfbuzz_14.4.0.bb
+++ b/meta/recipes-graphics/harfbuzz/harfbuzz_14.5.0.bb
@@ -9,7 +9,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=b98429b8e8e3c2a67cfef01e99e4893d \
"
SRC_URI = "${GITHUB_BASE_URI}/download/${PV}/${BPN}-${PV}.tar.xz"
-SRC_URI[sha256sum] = "2357ed966c6ced7bfa720b0640c0231065af01158fbea215093ffa15aed44371"
+SRC_URI[sha256sum] = "b7132e148358a45185c9feafd049dbaf243649d3c44414b3534d9c95d18592b9"
inherit meson pkgconfig lib_package gtk-doc gobject-introspection github-releases
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH 3/5] python3-pyparsing: upgrade 3.3.2 -> 3.3.3
2026-09-21 14:58 [PATCH 1/5] cairo: upgrade 1.18.4 -> 1.18.6 Richard Purdie
2026-09-21 14:58 ` [PATCH 2/5] harfbuzz: upgrade 14.4.0 -> 14.5.0 Richard Purdie
@ 2026-09-21 14:58 ` Richard Purdie
2026-09-21 14:58 ` [PATCH 4/5] stress-ng: upgrade 0.22.00 -> 0.22.01 Richard Purdie
2026-09-21 14:58 ` [PATCH 5/5] utfcpp: upgrade 4.2.0 -> 4.2.1 Richard Purdie
3 siblings, 0 replies; 5+ messages in thread
From: Richard Purdie @ 2026-09-21 14:58 UTC (permalink / raw)
To: openembedded-core
Version 3.3.3 - September, 2026
-------------------------------
- Added support for Python 3.15.
- Fixed CI unit test jobs selecting a tox environment with no test commands.
The matrix and fallback now select `py-unit`, as diagnosed and proposed by
glaziermag in issue #662; submitted by Neal Lin et AI.
- Refactored recursive implementations in pyparsing, for improved performance and
reduced memory usage.
- repetition using a large upper bound with multiplication or slicing notation
has replaced a recursive `Optional` expression with a modified `ZeroOrMore`
expression, using a new `max` argument. PR #652, submitted by sudo.
- `nested_expr` now uses an internal class that maintains its own stack for
managing nesting levels.
- `infix_notation` replaced its recursive implementation with a shunting-yard
algorithm.
These changes should not cause any regressions in existing code, and tests
show significant performance improvements for some of the more complex examples.
Railroad diagrams may render differently, since they now no longer rely on
recursion using `Forward` expressions.
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
---
.../{python3-pyparsing_3.3.2.bb => python3-pyparsing_3.3.3.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-devtools/python/{python3-pyparsing_3.3.2.bb => python3-pyparsing_3.3.3.bb} (90%)
diff --git a/meta/recipes-devtools/python/python3-pyparsing_3.3.2.bb b/meta/recipes-devtools/python/python3-pyparsing_3.3.3.bb
similarity index 90%
rename from meta/recipes-devtools/python/python3-pyparsing_3.3.2.bb
rename to meta/recipes-devtools/python/python3-pyparsing_3.3.3.bb
index 2565751f287..fbb0d642936 100644
--- a/meta/recipes-devtools/python/python3-pyparsing_3.3.2.bb
+++ b/meta/recipes-devtools/python/python3-pyparsing_3.3.3.bb
@@ -10,7 +10,7 @@ BUGTRACKER = "https://github.com/pyparsing/pyparsing/issues"
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=9c8a9625037eff2407f8456010875183"
-SRC_URI[sha256sum] = "c777f4d763f140633dcb6d8a3eda953bf7a214dc4eff598413c070bcdc117cbc"
+SRC_URI[sha256sum] = "928ae7e20211f3b6f3915a72f06a0cfd29ab9d24279dd6346b6b1a7146397d36"
inherit pypi python_flit_core
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH 4/5] stress-ng: upgrade 0.22.00 -> 0.22.01
2026-09-21 14:58 [PATCH 1/5] cairo: upgrade 1.18.4 -> 1.18.6 Richard Purdie
2026-09-21 14:58 ` [PATCH 2/5] harfbuzz: upgrade 14.4.0 -> 14.5.0 Richard Purdie
2026-09-21 14:58 ` [PATCH 3/5] python3-pyparsing: upgrade 3.3.2 -> 3.3.3 Richard Purdie
@ 2026-09-21 14:58 ` Richard Purdie
2026-09-21 14:58 ` [PATCH 5/5] utfcpp: upgrade 4.2.0 -> 4.2.1 Richard Purdie
3 siblings, 0 replies; 5+ messages in thread
From: Richard Purdie @ 2026-09-21 14:58 UTC (permalink / raw)
To: openembedded-core
stress-ng (0.22.01-1) unstable; urgency=medium
* Sync to upstream version 0.22.01
-- Colin Ian King <colin.i.king@gmail.com> Sun, 20 Sep 2026 14:30:12 +0100
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
---
.../stress-ng/{stress-ng_0.22.00.bb => stress-ng_0.22.01.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-extended/stress-ng/{stress-ng_0.22.00.bb => stress-ng_0.22.01.bb} (94%)
diff --git a/meta/recipes-extended/stress-ng/stress-ng_0.22.00.bb b/meta/recipes-extended/stress-ng/stress-ng_0.22.01.bb
similarity index 94%
rename from meta/recipes-extended/stress-ng/stress-ng_0.22.00.bb
rename to meta/recipes-extended/stress-ng/stress-ng_0.22.01.bb
index 5c68f813110..548edf292b0 100644
--- a/meta/recipes-extended/stress-ng/stress-ng_0.22.00.bb
+++ b/meta/recipes-extended/stress-ng/stress-ng_0.22.01.bb
@@ -6,7 +6,7 @@ LICENSE = "GPL-2.0-only"
LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
SRC_URI = "git://github.com/ColinIanKing/stress-ng.git;protocol=https;branch=master;tag=V${PV}"
-SRCREV = "6c2ab8831bca51f17d97538d106996ca411c4c79"
+SRCREV = "72a9d0cae0f420a887991d4024d3101c4af7a4fc"
DEPENDS = "coreutils-native libbsd"
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH 5/5] utfcpp: upgrade 4.2.0 -> 4.2.1
2026-09-21 14:58 [PATCH 1/5] cairo: upgrade 1.18.4 -> 1.18.6 Richard Purdie
` (2 preceding siblings ...)
2026-09-21 14:58 ` [PATCH 4/5] stress-ng: upgrade 0.22.00 -> 0.22.01 Richard Purdie
@ 2026-09-21 14:58 ` Richard Purdie
3 siblings, 0 replies; 5+ messages in thread
From: Richard Purdie @ 2026-09-21 14:58 UTC (permalink / raw)
To: openembedded-core
3d1ff6d Release 4.2.1
32e3ed1 next16: report invalid_utf16 for a lone trail surrogate at the end of a range (#147)
30e55c2 Add utf8cpp::utf8cpp target available when consuming directly (#146)
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
---
.../recipes-support/utfcpp/{utfcpp_4.2.0.bb => utfcpp_4.2.1.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-support/utfcpp/{utfcpp_4.2.0.bb => utfcpp_4.2.1.bb} (94%)
diff --git a/meta/recipes-support/utfcpp/utfcpp_4.2.0.bb b/meta/recipes-support/utfcpp/utfcpp_4.2.1.bb
similarity index 94%
rename from meta/recipes-support/utfcpp/utfcpp_4.2.0.bb
rename to meta/recipes-support/utfcpp/utfcpp_4.2.1.bb
index c56d03b7c74..e891b7fc576 100644
--- a/meta/recipes-support/utfcpp/utfcpp_4.2.0.bb
+++ b/meta/recipes-support/utfcpp/utfcpp_4.2.1.bb
@@ -11,7 +11,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=e4224ccaecb14d942c71d31bef20d78c \
SRC_URI = "git://github.com/nemtrif/utfcpp;protocol=https;branch=master;tag=v${PV} \
file://run-ptest"
-SRCREV = "2d8e20b22dcb3e9b3c4f52103182ebda949c6089"
+SRCREV = "3d1ff6dbf54e471c846dff55dda6c8ee10c0ee5c"
inherit cmake ptest
^ permalink raw reply related [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-21 14:58 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-21 14:58 [PATCH 1/5] cairo: upgrade 1.18.4 -> 1.18.6 Richard Purdie
2026-09-21 14:58 ` [PATCH 2/5] harfbuzz: upgrade 14.4.0 -> 14.5.0 Richard Purdie
2026-09-21 14:58 ` [PATCH 3/5] python3-pyparsing: upgrade 3.3.2 -> 3.3.3 Richard Purdie
2026-09-21 14:58 ` [PATCH 4/5] stress-ng: upgrade 0.22.00 -> 0.22.01 Richard Purdie
2026-09-21 14:58 ` [PATCH 5/5] utfcpp: upgrade 4.2.0 -> 4.2.1 Richard Purdie
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox