Yocto Project Documentation
 help / color / mirror / Atom feed
* [PATCH 00/11] Final release note updates for 5.2
@ 2025-03-28 13:07 Antonin Godard
  2025-03-28 13:07 ` [PATCH 01/11] migration-guides/release-notes-5.2.rst: add the list of contributors Antonin Godard
                   ` (11 more replies)
  0 siblings, 12 replies; 24+ messages in thread
From: Antonin Godard @ 2025-03-28 13:07 UTC (permalink / raw)
  To: docs; +Cc: Thomas Petazzoni, Antonin Godard

This series makes the final updates before the 5.2 release, which
includes adding the recipe upgrades, license changes, as well as cleaning
up a few empty sections.

It also updates the release notes / migration guide and overall
documentation with regards to the latest changes on Poky.

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
---
Antonin Godard (11):
      migration-guides/release-notes-5.2.rst: add the list of contributors
      migration-guides/release-notes-5.2.rst: add recipe upgrades
      migration-guides/release-notes-5.2.rst: add LICENSE recipe changes
      migration-guides/release-notes-5.2.rst: add security fixes
      migration-guides/release-notes-5.2.rst: add an entry for addfragments
      migration-guides/migration-5.2.rst: final update for 5.2
      ref-manual/system-requirements.rst: update list of supported distributions
      poky.yaml.in: bump minimum required Python version to 3.9
      ref-manual/variables.rst: document the GRUB_MKIMAGE_OPTS variable
      ref-manual/variables.rst: document the SPDX_PACKAGE_VERSION variable
      migration-guides/{migration,release-note}-5.2: update for 5.2 release

 documentation/migration-guides/migration-5.2.rst   |   39 +-
 .../migration-guides/release-notes-5.2.rst         | 1516 +++++++++++++++++++-
 documentation/poky.yaml.in                         |    2 +-
 documentation/ref-manual/system-requirements.rst   |   10 +-
 documentation/ref-manual/variables.rst             |   10 +
 5 files changed, 1567 insertions(+), 10 deletions(-)
---
base-commit: ea1636013722c12e72ca115240c8ce533e05ece2
change-id: 20250327-release-note-5-2-updates-2-8fb5d45989bd

Best regards,
-- 
Antonin Godard <antonin.godard@bootlin.com>



^ permalink raw reply	[flat|nested] 24+ messages in thread

* [PATCH 01/11] migration-guides/release-notes-5.2.rst: add the list of contributors
  2025-03-28 13:07 [PATCH 00/11] Final release note updates for 5.2 Antonin Godard
@ 2025-03-28 13:07 ` Antonin Godard
  2025-03-28 13:07 ` [PATCH 02/11] migration-guides/release-notes-5.2.rst: add recipe upgrades Antonin Godard
                   ` (10 subsequent siblings)
  11 siblings, 0 replies; 24+ messages in thread
From: Antonin Godard @ 2025-03-28 13:07 UTC (permalink / raw)
  To: docs; +Cc: Thomas Petazzoni, Antonin Godard

Obtained by running:

  git log --format=%an yocto-5.1..walnascar | sort | uniq

On the Poky repository.

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
---
 .../migration-guides/release-notes-5.2.rst         | 193 +++++++++++++++++++++
 1 file changed, 193 insertions(+)

diff --git a/documentation/migration-guides/release-notes-5.2.rst b/documentation/migration-guides/release-notes-5.2.rst
index a8e6e2b6e..923d3809a 100644
--- a/documentation/migration-guides/release-notes-5.2.rst
+++ b/documentation/migration-guides/release-notes-5.2.rst
@@ -715,5 +715,198 @@ Recipe Upgrades in |yocto-ver|
 Contributors to |yocto-ver|
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
+Thanks to the following people who contributed to this release:
+
+-  Aditya Tayade
+-  Adrian Freihofer
+-  Alban Bedel
+-  Aleksandar Nikolic
+-  Alessio Cascone
+-  Alexander Hirsch
+-  Alexander Kanavin
+-  Alexander Sverdlin
+-  Alexander van Gessel
+-  Alexander Yurkov
+-  Alexandre Marques
+-  Alexis Cellier
+-  Alex Kiernan
+-  Andrej Valek
+-  Angelo Ribeiro
+-  Antonin Godard
+-  Archana Polampalli
+-  Artur Kowalski
+-  Awais Belal
+-  Balaji Pothunoori
+-  Bartosz Golaszewski
+-  Bastian Germann
+-  Bastian Krause
+-  Bastien JAUNY
+-  BELHADJ SALEM Talel
+-  Benjamin Bara
+-  Benjamin Grossschartner
+-  Benjamin Szőke
+-  Bin Lan
+-  Bruce Ashfield
+-  Changhyeok Bae
+-  Changqing Li
+-  Chen Qi
+-  Chris Laplante
+-  Christian Lindeberg
+-  Christian Taedcke
+-  Christos Gavros
+-  Claus Stovgaard
+-  Clayton Casciato
+-  Colin McAllister
+-  Daniel Ammann
+-  Daniel McGregor
+-  Dan McGregor
+-  Deepesh Varatharajan
+-  Deepthi Hemraj
+-  Denis OSTERLAND-HEIM
+-  Denys Dmytriyenko
+-  Derek Straka
+-  Divya Chellam
+-  Dmitry Baryshkov
+-  Enrico Jörns
+-  Enrico Scholz
+-  Eric Meyers
+-  Esben Haabendal
+-  Etienne Cordonnier
+-  Fabio Berton
+-  Fabio Estevam
+-  Gaël PORTAY
+-  Georgi, Tom
+-  Guðni Már Gilbert
+-  Guénaël Muller
+-  Harish Sadineni
+-  Haseeb Ashraf
+-  Hiago De Franco
+-  Hongxu Jia
+-  Igor Opaniuk
+-  Jagadeesh Krishnanjanappa
+-  Jamin Lin
+-  Jason Schonberg
+-  Jean-Pierre Geslin
+-  Jermain Horsman
+-  Jesse Riemens
+-  Jiaying Song
+-  Jinfeng Wang
+-  João Henrique Ferreira de Freitas
+-  Joerg Schmidt
+-  Jonas Gorski
+-  Jon Mason
+-  Jörg Sommer
+-  Jose Quaresma
+-  Joshua Watt
+-  Julien Stephan
+-  Justin Bronder
+-  Kai Kang
+-  Katariina Lounento
+-  Katawann
+-  Kevin Hao
+-  Khem Raj
+-  Koen Kooi
+-  Lee Chee Yang
+-  Lei Maohui
+-  Lei YU
+-  Leon Anavi
+-  Louis Rannou
+-  Maik Otto
+-  Makarios Christakis
+-  Marc Ferland
+-  Marco Felsch
+-  Marek Vasut
+-  Mark Hatle
+-  Markus Volk
+-  Marta Rybczynska
+-  Martin Jansa
+-  Mathieu Dubois-Briand
+-  Matthias Schiffer
+-  Maxin John
+-  Michael Estner
+-  Michael Halstead
+-  Michael Nazzareno Trimarchi
+-  Michael Opdenacker
+-  Michelle Lin
+-  Mikko Rapeli
+-  Ming Liu
+-  Moritz Haase
+-  Nick Owens
+-  Nicolas Dechesne
+-  Nikolai Merinov
+-  Niko Mauno
+-  Ninette Adhikari
+-  Ola x Nilsson
+-  Oleksandr Hnatiuk
+-  Oliver Kästner
+-  Omri Sarig
+-  Pascal Eberhard
+-  Patrik Nordvall
+-  Paul Barker
+-  Pavel Zhukov
+-  Pedro Ferreira
+-  Peter Bergin
+-  Peter Delevoryas
+-  Peter Kjellerstedt
+-  Peter Marko
+-  Peter Tatrai
+-  Philip Lorenz
+-  Priyal Doshi
+-  Purushottam Choudhary
+-  Quentin Schulz
+-  Ralph Siemsen
+-  Randy MacLeod
+-  Ranjitsinh Rathod
+-  Rasmus Villemoes
+-  Regis Dargent
+-  Ricardo Salveti
+-  Richard Purdie
+-  Robert Yang
+-  Rohini Sangam
+-  Roland Hieber
+-  Ross Burton
+-  Ryan Eatmon
+-  Savvas Etairidis
+-  Sean Nyekjaer
+-  Sebastian Zenker
+-  Sergei Zhmylev
+-  Shunsuke Tokumoto
+-  Sid-Ali
+-  Simon A. Eugster
+-  Simone Weiß
+-  Slawomir Stepien
+-  Sofiane HAMAM
+-  Stefan Gloor
+-  Stefan Herbrechtsmeier
+-  Stefan Koch
+-  Stefan Mueller-Klieser
+-  Steve Sakoman
+-  Sunil Dora
+-  Sven Kalmbach
+-  Talel BELHAJSALEM
+-  Thomas Perrot
+-  Thomas Roos
+-  Tim Orling
+-  Tom Hochstein
+-  Trevor Gamblin
+-  Ulrich Ölmann
+-  Valeria Petrov
+-  Victor J. Hansen
+-  Victor Kamensky
+-  Vijay Anusuri
+-  Vince Chang
+-  Vivek Puar
+-  Vyacheslav Yurkov
+-  Walter Schweizer
+-  Wang Mingyu
+-  Weisser, Pascal
+-  Xiangyu Chen
+-  Xiaotian Wu
+-  Yash Shinde
+-  Yi Zhao
+-  Yoann Congal
+-  Yogita Urade
+-  Zoltán Böszörményi
+
 Repositories / Downloads for Yocto-|yocto-ver|
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

-- 
2.47.0



^ permalink raw reply related	[flat|nested] 24+ messages in thread

* [PATCH 02/11] migration-guides/release-notes-5.2.rst: add recipe upgrades
  2025-03-28 13:07 [PATCH 00/11] Final release note updates for 5.2 Antonin Godard
  2025-03-28 13:07 ` [PATCH 01/11] migration-guides/release-notes-5.2.rst: add the list of contributors Antonin Godard
@ 2025-03-28 13:07 ` Antonin Godard
  2025-03-28 13:07 ` [PATCH 03/11] migration-guides/release-notes-5.2.rst: add LICENSE recipe changes Antonin Godard
                   ` (9 subsequent siblings)
  11 siblings, 0 replies; 24+ messages in thread
From: Antonin Godard @ 2025-03-28 13:07 UTC (permalink / raw)
  To: docs; +Cc: Thomas Petazzoni, Antonin Godard

Extracted from layers.openembedded.org branch comparison tool.

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
---
 .../migration-guides/release-notes-5.2.rst         | 1170 ++++++++++++++++++++
 1 file changed, 1170 insertions(+)

diff --git a/documentation/migration-guides/release-notes-5.2.rst b/documentation/migration-guides/release-notes-5.2.rst
index 923d3809a..081100870 100644
--- a/documentation/migration-guides/release-notes-5.2.rst
+++ b/documentation/migration-guides/release-notes-5.2.rst
@@ -712,6 +712,1176 @@ Security Fixes in |yocto-ver|
 Recipe Upgrades in |yocto-ver|
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
+.. list-table::
+   :widths: 20 40 40
+   :header-rows: 1
+
+   * - Recipe
+     - Previous version
+     - New version
+   * - ``adwaita-icon-theme``
+     - 46.2
+     - 48.0
+   * - ``alsa-lib``
+     - 1.2.12
+     - 1.2.13
+   * - ``alsa-ucm-conf``
+     - 1.2.12
+     - 1.2.13
+   * - ``alsa-utils``
+     - 1.2.12
+     - 1.2.13
+   * - ``appstream``
+     - 1.0.3
+     - 1.0.4
+   * - ``at-spi2-core``
+     - 2.52.0
+     - 2.56.0
+   * - ``autoconf-archive``
+     - 2023.02.20
+     - 2024.10.16
+   * - ``babeltrace2``
+     - 2.0.6
+     - 2.1.0
+   * - ``base-passwd``
+     - 3.6.4
+     - 3.6.6
+   * - ``bash``
+     - 5.2.32
+     - 5.2.37
+   * - ``bash-completion``
+     - 2.14.0
+     - 2.16.0
+   * - ``bc``
+     - 1.07.1
+     - 1.08.1
+   * - ``bind``
+     - 9.20.1
+     - 9.20.6
+   * - ``binutils``
+     - 2.43.1
+     - 2.44
+   * - ``binutils-cross``
+     - 2.43.1
+     - 2.44
+   * - ``binutils-cross-canadian``
+     - 2.43.1
+     - 2.44
+   * - ``binutils-crosssdk``
+     - 2.43.1
+     - 2.44
+   * - ``binutils-testsuite``
+     - 2.43.1
+     - 2.44
+   * - ``bluez5``
+     - 5.78
+     - 5.79
+   * - ``boost``
+     - 1.86.0
+     - 1.87.0
+   * - ``boost-build-native``
+     - 1.86.0
+     - 1.87.0
+   * - ``btrfs-tools``
+     - 6.10.1
+     - 6.13
+   * - ``build-appliance-image``
+     - 15.0.0 (6a5ba188b79e…)
+     - 15.0.0 (2fe7f46e1779…)
+   * - ``busybox``
+     - 1.36.1
+     - 1.37.0
+   * - ``busybox-inittab``
+     - 1.36.1
+     - 1.37.0
+   * - ``ca-certificates``
+     - 20240203
+     - 20241223
+   * - ``cairo``
+     - 1.18.2
+     - 1.18.4
+   * - ``cargo``
+     - 1.79.0
+     - 1.84.1
+   * - ``ccache``
+     - 4.10.2
+     - 4.11
+   * - ``chrpath``
+     - 0.16
+     - 0.18
+   * - ``cmake``
+     - 3.30.2
+     - 3.31.6
+   * - ``cmake-native``
+     - 3.30.2
+     - 3.31.6
+   * - ``connman``
+     - 1.42
+     - 1.43
+   * - ``coreutils``
+     - 9.5
+     - 9.6
+   * - ``cracklib``
+     - 2.10.2
+     - 2.10.3
+   * - ``createrepo-c``
+     - 1.1.4
+     - 1.2.0
+   * - ``cross-localedef-native``
+     - 2.40+git
+     - 2.41+git
+   * - ``cups``
+     - 2.4.10
+     - 2.4.11
+   * - ``curl``
+     - 8.9.1
+     - 8.12.1
+   * - ``dbus``
+     - 1.14.10
+     - 1.16.2
+   * - ``dbus-glib``
+     - 0.112
+     - 0.114
+   * - ``debianutils``
+     - 5.20
+     - 5.21
+   * - ``debugedit``
+     - 5.0
+     - 5.1
+   * - ``desktop-file-utils``
+     - 0.27
+     - 0.28
+   * - ``dhcpcd``
+     - 10.0.10
+     - 10.2.2
+   * - ``diffoscope``
+     - 277
+     - 289
+   * - ``diffstat``
+     - 1.66
+     - 1.67
+   * - ``diffutils``
+     - 3.10
+     - 3.11
+   * - ``dnf``
+     - 4.21.1
+     - 4.22.0
+   * - ``dropbear``
+     - 2024.85
+     - 2024.86
+   * - ``dtc``
+     - 1.7.0
+     - 1.7.2
+   * - ``ed``
+     - 1.20.2
+     - 1.21
+   * - ``efivar``
+     - 39+39+git
+     - 39
+   * - ``elfutils``
+     - 0.191
+     - 0.192
+   * - ``ell``
+     - 0.68
+     - 0.74
+   * - ``epiphany``
+     - 46.3
+     - 48.0
+   * - ``erofs-utils``
+     - 1.8.1
+     - 1.8.5
+   * - ``ethtool``
+     - 6.10
+     - 6.11
+   * - ``expat``
+     - 2.6.4
+     - 2.7.0
+   * - ``ffmpeg``
+     - 7.0.2
+     - 7.1.1
+   * - ``file``
+     - 5.45
+     - 5.46
+   * - ``fmt``
+     - 11.0.2
+     - 11.1.4
+   * - ``fribidi``
+     - 1.0.15
+     - 1.0.16
+   * - ``gawk``
+     - 5.3.0
+     - 5.3.1
+   * - ``gcr``
+     - 4.3.0
+     - 4.3.1
+   * - ``gdb``
+     - 15.1
+     - 16.2
+   * - ``gdb-cross``
+     - 15.1
+     - 16.2
+   * - ``gdb-cross-canadian``
+     - 15.1
+     - 16.2
+   * - ``gettext``
+     - 0.22.5
+     - 0.23.1
+   * - ``gettext-minimal-native``
+     - 0.22.5
+     - 0.23.1
+   * - ``ghostscript``
+     - 10.04.0
+     - 10.05.0
+   * - ``gi-docgen``
+     - 2024.1
+     - 2025.3
+   * - ``git``
+     - 2.46.1
+     - 2.49.0
+   * - ``glib-2``
+     - .0 2.80.4
+     - 2.84.0
+   * - ``glib-2``
+     - .0-initial 2.80.4
+     - 2.84.0
+   * - ``glibc``
+     - 2.40+git
+     - 2.41+git
+   * - ``glibc-locale``
+     - 2.40+git
+     - 2.41+git
+   * - ``glibc-mtrace``
+     - 2.40+git
+     - 2.41+git
+   * - ``glibc-scripts``
+     - 2.40+git
+     - 2.41+git
+   * - ``glibc-testsuite``
+     - 2.40+git
+     - 2.41+git
+   * - ``glibc-y2038-tests``
+     - 2.40+git
+     - 2.41+git
+   * - ``glslang``
+     - 1.3.290.0
+     - 1.4.309.0
+   * - ``gnu-efi``
+     - 3.0.18
+     - 4.0.0
+   * - ``gnupg``
+     - 2.5.0
+     - 2.5.5
+   * - ``gnutls``
+     - 3.8.6
+     - 3.8.9
+   * - ``go``
+     - 1.22.12
+     - 1.24.1
+   * - ``go-binary-native``
+     - 1.22.12
+     - 1.24.1
+   * - ``go-cross-canadian``
+     - 1.22.12
+     - 1.24.1
+   * - ``go-cross-core2-32``
+     - 1.22.12
+     - 1.24.1
+   * - ``go-crosssdk``
+     - 1.22.12
+     - 1.24.1
+   * - ``go-helloworld``
+     - 0.1 (39e772fc2670…)
+     - 0.1 (d7b0ac127859…)
+   * - ``go-runtime``
+     - 1.22.12
+     - 1.24.1
+   * - ``gobject-introspection``
+     - 1.80.1
+     - 1.84.0
+   * - ``gpgme``
+     - 1.23.2
+     - 1.24.2
+   * - ``gsettings-desktop-schemas``
+     - 46.1
+     - 48.0
+   * - ``gst-devtools``
+     - 1.24.10
+     - 1.24.12
+   * - ``gstreamer1``
+     - .0 1.24.10
+     - 1.24.12
+   * - ``gstreamer1``
+     - .0-libav 1.24.10
+     - 1.24.12
+   * - ``gstreamer1``
+     - .0-plugins-bad 1.24.10
+     - 1.24.12
+   * - ``gstreamer1``
+     - .0-plugins-base 1.24.10
+     - 1.24.12
+   * - ``gstreamer1``
+     - .0-plugins-good 1.24.10
+     - 1.24.12
+   * - ``gstreamer1``
+     - .0-plugins-ugly 1.24.10
+     - 1.24.12
+   * - ``gstreamer1``
+     - .0-python 1.24.10
+     - 1.24.12
+   * - ``gstreamer1``
+     - .0-rtsp-server 1.24.10
+     - 1.24.12
+   * - ``gstreamer1``
+     - .0-vaapi 1.24.10
+     - 1.24.12
+   * - ``gtk4``
+     - 4.14.5
+     - 4.18.1
+   * - ``harfbuzz``
+     - 9.0.0
+     - 10.4.0
+   * - ``hwlatdetect``
+     - 2.7
+     - 2.8
+   * - ``i2c-tools``
+     - 4.3
+     - 4.4
+   * - ``icu``
+     - 75-1
+     - 76-1
+   * - ``ifupdown``
+     - 0.8.43
+     - 0.8.44
+   * - ``igt-gpu-tools``
+     - 1.28
+     - 1.30
+   * - ``inetutils``
+     - 2.5
+     - 2.6
+   * - ``init-system-helpers``
+     - 1.66
+     - 1.68
+   * - ``iproute2``
+     - 6.10.0
+     - 6.13.0
+   * - ``iptables``
+     - 1.8.10
+     - 1.8.11
+   * - ``iputils``
+     - 20240117
+     - 20240905
+   * - ``iso-codes``
+     - 4.16.0
+     - 4.17.0
+   * - ``json-c``
+     - 0.17
+     - 0.18
+   * - ``json-glib``
+     - 1.8.0
+     - 1.10.6
+   * - ``kbd``
+     - 2.6.4
+     - 2.7.1
+   * - ``kern-tools-native``
+     - 0.3+git (7160ebe8b865…)
+     - 0.3+git (bfca22a52ec5…)
+   * - ``kexec-tools``
+     - 2.0.29
+     - 2.0.30
+   * - ``kmod``
+     - 33
+     - 34.1
+   * - ``kmscube``
+     - 0.0.1+git (b2f97f53e01e…)
+     - 0.0.1+git (311eaaaa473d…)
+   * - ``less``
+     - 661
+     - 668
+   * - ``libadwaita``
+     - 1.5.3
+     - 1.7.0
+   * - ``libarchive``
+     - 3.7.4
+     - 3.7.8
+   * - ``libassuan``
+     - 3.0.1
+     - 3.0.2
+   * - ``libcap``
+     - 2.70
+     - 2.75
+   * - ``libdnf``
+     - 0.73.3
+     - 0.73.4
+   * - ``libdrm``
+     - 2.4.123
+     - 2.4.124
+   * - ``libedit``
+     - 20240808-3.1
+     - 20250104-3.1
+   * - ``libexif``
+     - 0.6.24
+     - 0.6.25
+   * - ``libffi``
+     - 3.4.6
+     - 3.4.7
+   * - ``libgit2``
+     - 1.8.1
+     - 1.9.0
+   * - ``libgpg-error``
+     - 1.50
+     - 1.51
+   * - ``libical``
+     - 3.0.18
+     - 3.0.20
+   * - ``libice``
+     - 1.1.1
+     - 1.1.2
+   * - ``libidn2``
+     - 2.3.7
+     - 2.3.8
+   * - ``libinput``
+     - 1.26.1
+     - 1.27.1
+   * - ``libjitterentropy``
+     - 3.5.0
+     - 3.6.2
+   * - ``libmatchbox``
+     - 1.12
+     - 1.13
+   * - ``libnl``
+     - 3.10.0
+     - 3.11.0
+   * - ``libnotify``
+     - 0.8.3
+     - 0.8.4
+   * - ``libpam``
+     - 1.6.1
+     - 1.7.0
+   * - ``libpcre2``
+     - 10.44
+     - 10.45
+   * - ``libpipeline``
+     - 1.5.7
+     - 1.5.8
+   * - ``libpng``
+     - 1.6.43
+     - 1.6.47
+   * - ``libportal``
+     - 0.7.1
+     - 0.9.1
+   * - ``libproxy``
+     - 0.5.8
+     - 0.5.9
+   * - ``librepo``
+     - 1.18.1
+     - 1.19.0
+   * - ``librsvg``
+     - 2.58.2
+     - 2.59.2
+   * - ``libsdl2``
+     - 2.30.7
+     - 2.32.2
+   * - ``libseccomp``
+     - 2.5.5
+     - 2.6.0
+   * - ``libsecret``
+     - 0.21.4
+     - 0.21.6
+   * - ``libslirp``
+     - 4.8.0
+     - 4.9.0
+   * - ``libsm``
+     - 1.2.4
+     - 1.2.6
+   * - ``libsolv``
+     - 0.7.30
+     - 0.7.31
+   * - ``libsoup``
+     - 3.6.0
+     - 3.6.4
+   * - ``libssh2``
+     - 1.11.0
+     - 1.11.1
+   * - ``libstd-rs``
+     - 1.79.0
+     - 1.84.1
+   * - ``libtest-warnings-perl``
+     - 0.033
+     - 0.038
+   * - ``libtirpc``
+     - 1.3.5
+     - 1.3.6
+   * - ``libtool``
+     - 2.5.2
+     - 2.5.4
+   * - ``libtool-cross``
+     - 2.5.2
+     - 2.5.4
+   * - ``libtool-native``
+     - 2.5.2
+     - 2.5.4
+   * - ``libtraceevent``
+     - 1.8.3
+     - 1.8.4
+   * - ``libtry-tiny-perl``
+     - 0.31
+     - 0.32
+   * - ``libubootenv``
+     - 0.3.5
+     - 0.3.6
+   * - ``libunistring``
+     - 1.2
+     - 1.3
+   * - ``liburcu``
+     - 0.14.1
+     - 0.15.1
+   * - ``libuv``
+     - 1.48.0
+     - 1.50.0
+   * - ``libwebp``
+     - 1.4.0
+     - 1.5.0
+   * - ``libwpe``
+     - 1.16.0
+     - 1.16.2
+   * - ``libx11``
+     - 1.8.10
+     - 1.8.12
+   * - ``libxau``
+     - 1.0.11
+     - 1.0.12
+   * - ``libxcrypt``
+     - 4.4.36
+     - 4.4.38
+   * - ``libxcrypt-compat``
+     - 4.4.36
+     - 4.4.38
+   * - ``libxcursor``
+     - 1.2.2
+     - 1.2.3
+   * - ``libxcvt``
+     - 0.1.2
+     - 0.1.3
+   * - ``libxi``
+     - 1.8.1
+     - 1.8.2
+   * - ``libxkbcommon``
+     - 1.7.0
+     - 1.8.1
+   * - ``libxmlb``
+     - 0.3.19
+     - 0.3.22
+   * - ``libxrender``
+     - 0.9.11
+     - 0.9.12
+   * - ``libxshmfence``
+     - 1.3.2
+     - 1.3.3
+   * - ``libxslt``
+     - 1.1.42
+     - 1.1.43
+   * - ``libxt``
+     - 1.3.0
+     - 1.3.1
+   * - ``libxv``
+     - 1.0.12
+     - 1.0.13
+   * - ``libxxf86vm``
+     - 1.1.5
+     - 1.1.6
+   * - ``lighttpd``
+     - 1.4.76
+     - 1.4.77
+   * - ``linux-firmware``
+     - 20240909
+     - 20250311
+   * - ``linux-libc-headers``
+     - 6.10
+     - 6.12
+   * - ``linux-yocto``
+     - 6.6.75+git, 6.10.14+git
+     - 6.12.19+git
+   * - ``linux-yocto-dev``
+     - 6.11+git
+     - 6.14+git
+   * - ``linux-yocto-rt``
+     - 6.6.75+git, 6.10.14+git
+     - 6.12.19+git
+   * - ``linux-yocto-tiny``
+     - 6.6.75+git, 6.10.14+git
+     - 6.12.19+git
+   * - ``llvm``
+     - 18.1.8
+     - 20.1.0
+   * - ``log4cplus``
+     - 2.1.1
+     - 2.1.2
+   * - ``lsof``
+     - 4.99.3
+     - 4.99.4
+   * - ``ltp``
+     - 20240524
+     - 20250130
+   * - ``lttng-modules``
+     - 2.13.14
+     - 2.13.17
+   * - ``lzip``
+     - 1.24.1
+     - 1.25
+   * - ``lzlib``
+     - 1.14
+     - 1.15
+   * - ``man-db``
+     - 2.12.1
+     - 2.13.0
+   * - ``man-pages``
+     - 6.9.1
+     - 6.13
+   * - ``mc``
+     - 4.8.32
+     - 4.8.33
+   * - ``mesa-demos``
+     - 8.5.0
+     - 9.0.0
+   * - ``meson``
+     - 1.5.1
+     - 1.7.0
+   * - ``minicom``
+     - 2.9
+     - 2.10
+   * - ``mmc-utils``
+     - 0.1+git (123fd8b2ac39…)
+     - 0.1+git (2aef4cd9a84d…)
+   * - ``mpg123``
+     - 1.32.7
+     - 1.32.10
+   * - ``msmtp``
+     - 1.8.26
+     - 1.8.28
+   * - ``mtd-utils``
+     - 2.2.0
+     - 2.3.0
+   * - ``mtools``
+     - 4.0.44
+     - 4.0.48
+   * - ``musl``
+     - 1.2.5+git (dd1e63c3638d…)
+     - 1.2.5+git (c47ad25ea3b4…)
+   * - ``nativesdk-libtool``
+     - 2.5.2
+     - 2.5.4
+   * - ``netbase``
+     - 6.4
+     - 6.5
+   * - ``nettle``
+     - 3.10
+     - 3.10.1
+   * - ``nfs-utils``
+     - 2.6.4
+     - 2.8.2
+   * - ``nghttp2``
+     - 1.63.0
+     - 1.65.0
+   * - ``npth``
+     - 1.7
+     - 1.8
+   * - ``numactl``
+     - 2.0.18
+     - 2.0.19
+   * - ``ofono``
+     - 2.10
+     - 2.15
+   * - ``opensbi``
+     - 1.5.1
+     - 1.6
+   * - ``openssh``
+     - 9.8p1
+     - 9.9p2
+   * - ``openssl``
+     - 3.3.1
+     - 3.4.1
+   * - ``orc``
+     - 0.4.40
+     - 0.4.41
+   * - ``ovmf``
+     - edk2-stable202402
+     - edk2-stable202411
+   * - ``pango``
+     - 1.54.0
+     - 1.56.2
+   * - ``piglit``
+     - 1.0+gitr (c11c9374c144…)
+     - 1.0+gitr (fc8179d31904…)
+   * - ``pixman``
+     - 0.42.2
+     - 0.44.2
+   * - ``pkgconf``
+     - 2.3.0
+     - 2.4.3
+   * - ``ppp``
+     - 2.5.0
+     - 2.5.2
+   * - ``procps``
+     - 4.0.4
+     - 4.0.5
+   * - ``psplash``
+     - 0.1+git (ecc191375669…)
+     - 0.1+git (1f64c654129f…)
+   * - ``ptest-runner``
+     - 2.4.5+git
+     - 2.4.5.1
+   * - ``puzzles``
+     - 0.0+git (1c1899ee1c4e…)
+     - 0.0+git (7da464122232…)
+   * - ``python3``
+     - 3.12.9
+     - 3.13.2
+   * - ``python3-attrs``
+     - 24.2.0
+     - 25.3.0
+   * - ``python3-babel``
+     - 2.16.0
+     - 2.17.0
+   * - ``python3-bcrypt``
+     - 4.2.0
+     - 4.3.0
+   * - ``python3-beartype``
+     - 0.18.5
+     - 0.20.0
+   * - ``python3-build``
+     - 1.2.1
+     - 1.2.2
+   * - ``python3-certifi``
+     - 2024.8.30
+     - 2025.1.31
+   * - ``python3-cffi``
+     - 1.17.0
+     - 1.17.1
+   * - ``python3-click``
+     - 8.1.7
+     - 8.1.8
+   * - ``python3-cryptography``
+     - 42.0.8
+     - 44.0.2
+   * - ``python3-cryptography-vectors``
+     - 42.0.8
+     - 44.0.2
+   * - ``python3-cython``
+     - 3.0.11
+     - 3.0.12
+   * - ``python3-dbus``
+     - 1.3.2
+     - 1.4.0
+   * - ``python3-dbusmock``
+     - 0.32.1
+     - 0.33.0
+   * - ``python3-dtc``
+     - 1.7.0
+     - 1.7.2
+   * - ``python3-dtschema``
+     - 2024.5
+     - 2025.2
+   * - ``python3-flit-core``
+     - 3.9.0
+     - 3.11.0
+   * - ``python3-gitdb``
+     - 4.0.11
+     - 4.0.12
+   * - ``python3-hatchling``
+     - 1.25.0
+     - 1.27.0
+   * - ``python3-hypothesis``
+     - 6.111.2
+     - 6.129.2
+   * - ``python3-idna``
+     - 3.8
+     - 3.10
+   * - ``python3-jinja2``
+     - 3.1.4
+     - 3.1.6
+   * - ``python3-jsonschema-specifications``
+     - 2023.12.1
+     - 2024.10.1
+   * - ``python3-license-expression``
+     - 30.3.1
+     - 30.4.1
+   * - ``python3-lxml``
+     - 5.3.0
+     - 5.3.1
+   * - ``python3-mako``
+     - 1.3.5
+     - 1.3.9
+   * - ``python3-markdown``
+     - 3.6
+     - 3.7
+   * - ``python3-markupsafe``
+     - 2.1.5
+     - 3.0.2
+   * - ``python3-maturin``
+     - 1.7.1
+     - 1.8.3
+   * - ``python3-meson-python``
+     - 0.16.0
+     - 0.17.1
+   * - ``python3-more-itertools``
+     - 10.4.0
+     - 10.6.0
+   * - ``python3-numpy``
+     - 1.26.4
+     - 2.2.3
+   * - ``python3-packaging``
+     - 24.1
+     - 24.2
+   * - ``python3-pip``
+     - 24.2
+     - 25.0.1
+   * - ``python3-poetry-core``
+     - 1.9.0
+     - 2.1.1
+   * - ``python3-psutil``
+     - 6.0.0
+     - 7.0.0
+   * - ``python3-pyasn1``
+     - 0.6.0
+     - 0.6.1
+   * - ``python3-pycairo``
+     - 1.26.1
+     - 1.27.0
+   * - ``python3-pycryptodome``
+     - 3.20.0
+     - 3.22.0
+   * - ``python3-pycryptodomex``
+     - 3.20.0
+     - 3.22.0
+   * - ``python3-pyelftools``
+     - 0.31
+     - 0.32
+   * - ``python3-pygments``
+     - 2.18.0
+     - 2.19.1
+   * - ``python3-pygobject``
+     - 3.48.2
+     - 3.52.2
+   * - ``python3-pyopenssl``
+     - 24.2.1
+     - 25.0.0
+   * - ``python3-pyparsing``
+     - 3.1.4
+     - 3.2.1
+   * - ``python3-pyproject-hooks``
+     - 1.0.0
+     - 1.2.0
+   * - ``python3-pyproject-metadata``
+     - 0.8.0
+     - 0.9.1
+   * - ``python3-pytest``
+     - 8.3.2
+     - 8.3.5
+   * - ``python3-pytest-subtests``
+     - 0.13.1
+     - 0.14.1
+   * - ``python3-pytz``
+     - 2024.1
+     - 2025.1
+   * - ``python3-rdflib``
+     - 7.0.0
+     - 7.1.3
+   * - ``python3-referencing``
+     - 0.35.1
+     - 0.36.2
+   * - ``python3-rpds-py``
+     - 0.20.0
+     - 0.22.3
+   * - ``python3-ruamel-yaml``
+     - 0.18.6
+     - 0.18.10
+   * - ``python3-scons``
+     - 4.8.0
+     - 4.9.0
+   * - ``python3-setuptools``
+     - 72.1.0
+     - 76.0.0
+   * - ``python3-setuptools-rust``
+     - 1.10.1
+     - 1.11.0
+   * - ``python3-setuptools-scm``
+     - 8.1.0
+     - 8.2.0
+   * - ``python3-six``
+     - 1.16.0
+     - 1.17.0
+   * - ``python3-spdx-tools``
+     - 0.8.2
+     - 0.8.3
+   * - ``python3-sphinx``
+     - 8.0.2
+     - 8.2.1
+   * - ``python3-sphinx-rtd-theme``
+     - 2.0.0
+     - 3.0.2
+   * - ``python3-trove-classifiers``
+     - 2024.7.2
+     - 2025.3.13.13
+   * - ``python3-typogrify``
+     - 2.0.7
+     - 2.1.0
+   * - ``python3-urllib3``
+     - 2.2.2
+     - 2.3.0
+   * - ``python3-websockets``
+     - 13.0.1
+     - 15.0.1
+   * - ``python3-wheel``
+     - 0.44.0
+     - 0.45.1
+   * - ``python3-xmltodict``
+     - 0.13.0
+     - 0.14.2
+   * - ``python3-yamllint``
+     - 1.35.1
+     - 1.36.0
+   * - ``python3-zipp``
+     - 3.20.1
+     - 3.21.0
+   * - ``qemu``
+     - 9.0.2
+     - 9.2.0
+   * - ``qemu-native``
+     - 9.0.2
+     - 9.2.0
+   * - ``qemu-system-native``
+     - 9.0.2
+     - 9.2.0
+   * - ``re2c``
+     - 3.1
+     - 4.1
+   * - ``repo``
+     - 2.46
+     - 2.52
+   * - ``rpm``
+     - 4.19.1.1
+     - 4.20.0
+   * - ``rsync``
+     - 3.3.0
+     - 3.4.1
+   * - ``rt-tests``
+     - 2.7
+     - 2.8
+   * - ``ruby``
+     - 3.3.4
+     - 3.4.2
+   * - ``rust``
+     - 1.79.0
+     - 1.84.1
+   * - ``rust-cross-canadian``
+     - 1.79.0
+     - 1.84.1
+   * - ``rust-llvm``
+     - 1.79.0
+     - 1.84.1
+   * - ``screen``
+     - 4.9.1
+     - 5.0.0
+   * - ``seatd``
+     - 0.8.0
+     - 0.9.1
+   * - ``shaderc``
+     - 2024.1
+     - 2024.3
+   * - ``shadow``
+     - 4.16.0
+     - 4.17.3
+   * - ``socat``
+     - 1.8.0.0
+     - 1.8.0.3
+   * - ``spirv-headers``
+     - 1.3.290.0
+     - 1.4.309.0
+   * - ``spirv-tools``
+     - 1.3.290.0
+     - 1.4.309.0
+   * - ``sqlite3``
+     - 3.46.1
+     - 3.48.0
+   * - ``strace``
+     - 6.10
+     - 6.12
+   * - ``stress-ng``
+     - 0.18.02
+     - 0.18.11
+   * - ``subversion``
+     - 1.14.3
+     - 1.14.5
+   * - ``sudo``
+     - 1.9.15p5
+     - 1.9.16p2
+   * - ``swig``
+     - 4.2.1
+     - 4.3.0
+   * - ``sysklogd``
+     - 2.6.1
+     - 2.7.1
+   * - ``sysstat``
+     - 12.7.6
+     - 12.7.7
+   * - ``systemd``
+     - 256.5
+     - 257.4
+   * - ``systemd-boot``
+     - 256.5
+     - 257.4
+   * - ``systemd-boot-native``
+     - 256.5
+     - 257.4
+   * - ``systemd-systemctl-native``
+     - 1.0
+     - 257.4
+   * - ``systemtap``
+     - 5.1
+     - 5.2
+   * - ``systemtap-native``
+     - 5.1
+     - 5.2
+   * - ``sysvinit``
+     - 3.04
+     - 3.14
+   * - ``tcl``
+     - 8.6.14
+     - 9.0.1
+   * - ``texinfo``
+     - 7.1
+     - 7.2
+   * - ``tiff``
+     - 4.6.0
+     - 4.7.0
+   * - ``ttyrun``
+     - 2.34.0
+     - 2.37.0
+   * - ``u-boot``
+     - 2024.07
+     - 2025.01
+   * - ``u-boot-tools``
+     - 2024.07
+     - 2025.01
+   * - ``usbutils``
+     - 017
+     - 018
+   * - ``utfcpp``
+     - 4.0.5
+     - 4.0.6
+   * - ``util-linux``
+     - 2.40.2
+     - 2.40.4
+   * - ``util-linux-libuuid``
+     - 2.40.2
+     - 2.40.4
+   * - ``util-macros``
+     - 1.20.1
+     - 1.20.2
+   * - ``vala``
+     - 0.56.17
+     - 0.56.18
+   * - ``valgrind``
+     - 3.23.0
+     - 3.24.0
+   * - ``vim``
+     - 9.1.1043
+     - 9.1.1198
+   * - ``vim-tiny``
+     - 9.1.1043
+     - 9.1.1198
+   * - ``virglrenderer``
+     - 1.0.1
+     - 1.1.0
+   * - ``vte``
+     - 0.76.3
+     - 0.78.2
+   * - ``vulkan-headers``
+     - 1.3.290.0
+     - 1.4.309.0
+   * - ``vulkan-loader``
+     - 1.3.290.0
+     - 1.4.309.0
+   * - ``vulkan-samples``
+     - git (fdce530c0295…)
+     - git (8547ce1022a1…)
+   * - ``vulkan-tools``
+     - 1.3.290.0
+     - 1.4.309.0
+   * - ``vulkan-utility-libraries``
+     - 1.3.290.0
+     - 1.4.309.0
+   * - ``vulkan-validation-layers``
+     - 1.3.290.0
+     - 1.4.309.0
+   * - ``vulkan-volk``
+     - 1.3.290.0
+     - 1.4.309.0
+   * - ``wayland-protocols``
+     - 1.37
+     - 1.41
+   * - ``webkitgtk``
+     - 2.44.3
+     - 2.48.0
+   * - ``weston``
+     - 13.0.3
+     - 14.0.1
+   * - ``wget``
+     - 1.24.5
+     - 1.25.0
+   * - ``wireless-regdb``
+     - 2024.10.07
+     - 2025.02.20
+   * - ``wpebackend-fdo``
+     - 1.14.2
+     - 1.16.0
+   * - ``xauth``
+     - 1.1.3
+     - 1.1.4
+   * - ``xcb-util-cursor``
+     - 0.1.4
+     - 0.1.5
+   * - ``xf86-input-evdev``
+     - 2.10.6
+     - 2.11.0
+   * - ``xf86-input-libinput``
+     - 1.4.0
+     - 1.5.0
+   * - ``xf86-input-synaptics``
+     - 1.9.2
+     - 1.10.0
+   * - ``xf86-video-fbdev``
+     - 0.5.0
+     - 0.5.1
+   * - ``xhost``
+     - 1.0.9
+     - 1.0.10
+   * - ``xinit``
+     - 1.4.2
+     - 1.4.4
+   * - ``xkeyboard-config``
+     - 2.42
+     - 2.44
+   * - ``xprop``
+     - 1.2.7
+     - 1.2.8
+   * - ``xrandr``
+     - 1.5.2
+     - 1.5.3
+   * - ``xtrans``
+     - 1.5.0
+     - 1.6.0
+   * - ``xxhash``
+     - 0.8.2
+     - 0.8.3
+   * - ``xz``
+     - 5.6.2
+     - 5.6.4
+   * - ``zstd``
+     - 1.5.6
+     - 1.5.
+       7
+
 Contributors to |yocto-ver|
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

-- 
2.47.0



^ permalink raw reply related	[flat|nested] 24+ messages in thread

* [PATCH 03/11] migration-guides/release-notes-5.2.rst: add LICENSE recipe changes
  2025-03-28 13:07 [PATCH 00/11] Final release note updates for 5.2 Antonin Godard
  2025-03-28 13:07 ` [PATCH 01/11] migration-guides/release-notes-5.2.rst: add the list of contributors Antonin Godard
  2025-03-28 13:07 ` [PATCH 02/11] migration-guides/release-notes-5.2.rst: add recipe upgrades Antonin Godard
@ 2025-03-28 13:07 ` Antonin Godard
  2025-03-28 13:07 ` [PATCH 04/11] migration-guides/release-notes-5.2.rst: add security fixes Antonin Godard
                   ` (8 subsequent siblings)
  11 siblings, 0 replies; 24+ messages in thread
From: Antonin Godard @ 2025-03-28 13:07 UTC (permalink / raw)
  To: docs; +Cc: Thomas Petazzoni, Antonin Godard

Document LICENSE changes between the 5.1 and 5.2 release.
Extracted for commits message containing the "License-Update:" field in
Poky, between tag yocto-5.1 and walnascar.

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
---
 .../migration-guides/release-notes-5.2.rst         | 58 +++++++++++++++++++++-
 1 file changed, 57 insertions(+), 1 deletion(-)

diff --git a/documentation/migration-guides/release-notes-5.2.rst b/documentation/migration-guides/release-notes-5.2.rst
index 081100870..1e05631d9 100644
--- a/documentation/migration-guides/release-notes-5.2.rst
+++ b/documentation/migration-guides/release-notes-5.2.rst
@@ -704,7 +704,63 @@ Known Issues in |yocto-ver|
 Recipe License changes in |yocto-ver|
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
-The following corrections have been made to the :term:`LICENSE` values set by recipes:
+The following changes have been made to the :term:`LICENSE` values set by recipes:
+
+.. list-table::
+   :widths: 20 40 40
+   :header-rows: 1
+
+   * - Recipe
+     - Previous value
+     - New value
+   * - ``babeltrace2``
+     - ``MIT & GPL-2.0-only & LGPL-2.1-only & BSD-2-Clause``
+     - ``MIT & GPL-2.0-only & LGPL-2.1-only & BSD-2-Clause & BSD-4-Clause & GPL-3.0-or-later & CC-BY-SA-4.0 & PSF-2.0``
+   * - ``busybox``
+     - ``GPL-2.0-only & bzip2-1.0.4``
+     - ``GPL-2.0-only & bzip2-1.0.6``
+   * - ``dbus-glib``
+     - ``AFL-2.1 | GPL-2.0-or-later``
+     - ``(AFL-2.1 & LGPL-2.0-or-later & MIT) | (GPL-2.0-or-later & LGPL-2.0-or-later & MIT)``
+   * - ``diffstat``
+     - ``MIT``
+     - ``X11``
+   * - ``docbook-xsl-stylesheets``
+     - ``XSL``
+     - ``DocBook-XML``
+   * - ``font-util``
+     - ``Unicode-TOU & BSD-4-Clause & BSD-2-Clause``
+     - ``Unicode-TOU & MIT & X11 & BSD-2-Clause``
+   * - ``json-glib``
+     - ``LGPL-2.1-only``
+     - ``LGPL-2.1-or-later``
+   * - ``libbsd``
+     - ``BSD-3-Clause & BSD-4-Clause & ISC & PD``
+     - ``BSD-3-Clause & ISC & PD``
+   * - ``libxfont2``
+     - ``MIT & MIT & BSD-4-Clause & BSD-2-Clause``
+     - ``MIT & MIT & BSD-4-Clause-UC & BSD-2-Clause``
+   * - ``libxkbcommon``
+     - ``MIT & MIT``
+     - ``MIT & MIT-open-group & HPND & HPND-sell-variant & X11``
+   * - ``man-pages``
+     - ``GPL-2.0-or-later & GPL-2.0-only & GPL-1.0-or-later & BSD-2-Clause & BSD-3-Clause & BSD-4-Clause & MIT``
+     - ``GPL-2.0-or-later & GPL-2.0-only & GPL-1.0-or-later & BSD-2-Clause & BSD-3-Clause & BSD-4-Clause-UC & MIT``
+   * - ``ppp``
+     - ``BSD-3-Clause & BSD-3-Clause-Attribution & GPL-2.0-or-later & LGPL-2.0-or-later & PD & RSA-MD & MIT``
+     - ``BSD-2-Clause & GPL-2.0-or-later & LGPL-2.0-or-later & PD & RSA-MD & MIT``
+   * - ``tcf-agent``
+     - ``EPL-1.0 | EDL-1.0``
+     - ``EPL-1.0 | BSD-3-Clause``
+   * - ``unfs3``
+     - ``unfs3``
+     - ``BSD-3-Clause``
+   * - ``usbutils``
+     - ``GPL-2.0-or-later & (GPL-2.0-only | GPL-3.0-only)``
+     - ``GPL-2.0-or-later & (GPL-2.0-only | GPL-3.0-only) & CC0-1.0 & LGPL-2.1-or-later & MIT``
+   * - ``util-linux``
+     - ``GPL-1.0-or-later & GPL-2.0-only & GPL-2.0-or-later & LGPL-2.1-or-later & BSD-2-Clause & BSD-3-Clause & BSD-4-Clause & MIT``
+     - ``GPL-1.0-or-later & GPL-2.0-only & GPL-2.0-or-later & LGPL-2.1-or-later & BSD-2-Clause & BSD-3-Clause & BSD-4-Clause-UC & MIT``
 
 Security Fixes in |yocto-ver|
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

-- 
2.47.0



^ permalink raw reply related	[flat|nested] 24+ messages in thread

* [PATCH 04/11] migration-guides/release-notes-5.2.rst: add security fixes
  2025-03-28 13:07 [PATCH 00/11] Final release note updates for 5.2 Antonin Godard
                   ` (2 preceding siblings ...)
  2025-03-28 13:07 ` [PATCH 03/11] migration-guides/release-notes-5.2.rst: add LICENSE recipe changes Antonin Godard
@ 2025-03-28 13:07 ` Antonin Godard
  2025-04-12 16:38   ` [docs] " Takayasu Ito
  2025-03-28 13:07 ` [PATCH 05/11] migration-guides/release-notes-5.2.rst: add an entry for addfragments Antonin Godard
                   ` (7 subsequent siblings)
  11 siblings, 1 reply; 24+ messages in thread
From: Antonin Godard @ 2025-03-28 13:07 UTC (permalink / raw)
  To: docs; +Cc: Thomas Petazzoni, Antonin Godard

Add security fixes by going through the log between yocto-5.1 and
walnascar branch tip on Poky.

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
---
 .../migration-guides/release-notes-5.2.rst         | 67 ++++++++++++++++++++++
 1 file changed, 67 insertions(+)

diff --git a/documentation/migration-guides/release-notes-5.2.rst b/documentation/migration-guides/release-notes-5.2.rst
index 1e05631d9..d583f3e9d 100644
--- a/documentation/migration-guides/release-notes-5.2.rst
+++ b/documentation/migration-guides/release-notes-5.2.rst
@@ -765,6 +765,73 @@ The following changes have been made to the :term:`LICENSE` values set by recipe
 Security Fixes in |yocto-ver|
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
+The following CVEs have been fixed:
+
+.. list-table::
+   :widths: 30 70
+   :header-rows: 1
+
+   * - Recipe
+     - CVE IDs
+   * - ``barebox``
+     - :cve_nist:`2025-26721`, :cve_nist:`2025-26722`, :cve_nist:`2025-26723`, :cve_nist:`2025-26724`, :cve_nist:`2025-26725`
+   * - ``binutils``
+     - :cve_nist:`2024-53589`, :cve_nist:`2025-1153`
+   * - ``curl``
+     - :cve_nist:`2024-8096`, :cve_nist:`2024-9681`, :cve_nist:`2024-11053`, :cve_nist:`2025-0167`, :cve_nist:`2025-0665`, :cve_nist:`2025-0725`
+   * - ``expat``
+     - :cve_nist:`2024-50602`, :cve_nist:`2024-8176`
+   * - ``ghostscript``
+     - :cve_nist:`2024-46951`, :cve_nist:`2024-46952`, :cve_nist:`2024-46953`, :cve_nist:`2024-46954`, :cve_nist:`2024-46955`, :cve_nist:`2024-46956`
+   * - ``gnutls``
+     - :cve_nist:`2024-12243`
+   * - ``go``
+     - :cve_nist:`2024-34155`, :cve_nist:`2024-34156`, :cve_nist:`2024-34158`, :cve_nist:`2024-45336`, :cve_nist:`2024-45341`, :cve_nist:`2025-22866`, :cve_nist:`2025-22870`
+   * - ``grub``
+     - :cve_nist:`2024-45781`, :cve_nist:`2024-45782`, :cve_nist:`2024-56737`, :cve_nist:`2024-45780`, :cve_nist:`2024-45783`, :cve_nist:`2025-0624`, :cve_nist:`2024-45774`, :cve_nist:`2024-45775`, :cve_nist:`2025-0622`, :cve_nist:`2024-45776`, :cve_nist:`2024-45777`, :cve_nist:`2025-0690`, :cve_nist:`2025-1118`, :cve_nist:`2024-45778`, :cve_nist:`2024-45779`, :cve_nist:`2025-0677`, :cve_nist:`2025-0684`, :cve_nist:`2025-0685`, :cve_nist:`2025-0686`, :cve_nist:`2025-0689`, :cve_nist:`2025-0678`, :cve_nist:`2025-1125`
+   * - ``libarchive``
+     - :cve_nist:`2024-57970`, :cve_nist:`2025-25724`, :cve_nist:`2025-1632`
+   * - ``libcap``
+     - :cve_nist:`2025-1390`
+   * - ``libsndfile1``
+     - :cve_nist:`2024-50612`
+   * - ``libssh2``
+     - :cve_nist:`2023-48795`
+   * - ``libtasn1``
+     - :cve_nist:`2024-12133`
+   * - ``libxml2``
+     - :cve_nist:`2025-24928`, :cve_nist:`2024-56171`
+   * - ``ofono``
+     - :cve_nist:`2024-7539`, :cve_nist:`2024-7540`, :cve_nist:`2024-7541`, :cve_nist:`2024-7542`
+   * - ``omvf``
+     - :cve_nist:`2023-45236`, :cve_nist:`2023-45237`, :cve_nist:`2024-25742`
+   * - ``openssl``
+     - :cve_nist:`2024-9143`, :cve_nist:`2024-12797`, :cve_nist:`2024-13176`
+   * - ``orc``
+     - :cve_nist:`2024-40897`
+   * - ``python3``
+     - :cve_nist:`2025-0938`, :cve_nist:`2024-12254`
+   * - ``qemu``
+     - :cve_nist:`2024-6505`
+   * - ``rsync``
+     - :cve_nist:`2024-12084`, :cve_nist:`2024-12085`, :cve_nist:`2024-12086`, :cve_nist:`2024-12087`, :cve_nist:`2024-12088`, :cve_nist:`2024-12747`
+   * - ``ruby``
+     - :cve_nist:`2024-41123`, :cve_nist:`2024-41946`
+   * - ``rust``
+     - :cve_nist:`2024-43402`
+   * - ``tiff``
+     - :cve_nist:`2023-52356`, :cve_nist:`2023-6228`, :cve_nist:`2023-6277`
+   * - ``vim``
+     - :cve_nist:`2024-45306`, :cve_nist:`2024-47814`, :cve_nist:`2025-22134`, :cve_nist:`2025-24014`, :cve_nist:`2025-26603`, :cve_nist:`2025-1215`, :cve_nist:`2025-27423`, :cve_nist:`2025-29768`
+   * - ``webkitgtk``
+     - :cve_nist:`2025-24143`, :cve_nist:`2025-24150`, :cve_nist:`2025-24158`, :cve_nist:`2025-24162`
+   * - ``wpa-supplicant``
+     - :cve_nist:`2024-5290`
+   * - ``xserver-xorg``
+     - :cve_nist:`2024-9632`, :cve_nist:`2025-26594`, :cve_nist:`2025-26595`, :cve_nist:`2025-26596`, :cve_nist:`2025-26597`, :cve_nist:`2025-26598`, :cve_nist:`2025-26599`, :cve_nist:`2025-26600`, :cve_nist:`2025-26601`
+   * - ``xwayland``
+     - :cve_nist:`2024-9632`, :cve_nist:`2025-26594`, :cve_nist:`2025-26595`, :cve_nist:`2025-26596`, :cve_nist:`2025-26597`, :cve_nist:`2025-26598`, :cve_nist:`2025-26599`, :cve_nist:`2025-26600`, :cve_nist:`2025-26601`
+
 Recipe Upgrades in |yocto-ver|
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

-- 
2.47.0



^ permalink raw reply related	[flat|nested] 24+ messages in thread

* [PATCH 05/11] migration-guides/release-notes-5.2.rst: add an entry for addfragments
  2025-03-28 13:07 [PATCH 00/11] Final release note updates for 5.2 Antonin Godard
                   ` (3 preceding siblings ...)
  2025-03-28 13:07 ` [PATCH 04/11] migration-guides/release-notes-5.2.rst: add security fixes Antonin Godard
@ 2025-03-28 13:07 ` Antonin Godard
  2025-03-28 13:07 ` [PATCH 06/11] migration-guides/migration-5.2.rst: final update for 5.2 Antonin Godard
                   ` (6 subsequent siblings)
  11 siblings, 0 replies; 24+ messages in thread
From: Antonin Godard @ 2025-03-28 13:07 UTC (permalink / raw)
  To: docs; +Cc: Thomas Petazzoni, Antonin Godard

This should be clearly mentioned in the BitBake section as it is an
valuable addition to 5.2.

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
---
 documentation/migration-guides/release-notes-5.2.rst | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/documentation/migration-guides/release-notes-5.2.rst b/documentation/migration-guides/release-notes-5.2.rst
index d583f3e9d..cbef0d686 100644
--- a/documentation/migration-guides/release-notes-5.2.rst
+++ b/documentation/migration-guides/release-notes-5.2.rst
@@ -302,6 +302,12 @@ New Features / Enhancements in |yocto-ver|
 
 -  BitBake changes:
 
+   -  Add a new concept of configuration fragment, which allows providing
+      configuration snippets contained in layers in a structured and controlled
+      way. For more information, see the
+      :ref:`bitbake:bitbake-user-manual/bitbake-user-manual-metadata:\`\`addfragments\`\`
+      Directive` section of the BitBake User Manual.
+
    -  Add a new ``include_all`` directive, which can be used to include multiple
       files present in the same location in different layers.
 

-- 
2.47.0



^ permalink raw reply related	[flat|nested] 24+ messages in thread

* [PATCH 06/11] migration-guides/migration-5.2.rst: final update for 5.2
  2025-03-28 13:07 [PATCH 00/11] Final release note updates for 5.2 Antonin Godard
                   ` (4 preceding siblings ...)
  2025-03-28 13:07 ` [PATCH 05/11] migration-guides/release-notes-5.2.rst: add an entry for addfragments Antonin Godard
@ 2025-03-28 13:07 ` Antonin Godard
  2025-03-28 13:07 ` [PATCH 07/11] ref-manual/system-requirements.rst: update list of supported distributions Antonin Godard
                   ` (5 subsequent siblings)
  11 siblings, 0 replies; 24+ messages in thread
From: Antonin Godard @ 2025-03-28 13:07 UTC (permalink / raw)
  To: docs; +Cc: Thomas Petazzoni, Antonin Godard

- Add new/removed supported distributions.
- Set the oldest supported kernel.
- Remove empty sections.

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
---
 documentation/migration-guides/migration-5.2.rst | 13 +++++++++----
 1 file changed, 9 insertions(+), 4 deletions(-)

diff --git a/documentation/migration-guides/migration-5.2.rst b/documentation/migration-guides/migration-5.2.rst
index b5df4412e..59a2782f2 100644
--- a/documentation/migration-guides/migration-5.2.rst
+++ b/documentation/migration-guides/migration-5.2.rst
@@ -39,7 +39,7 @@ section of the Yocto Project Reference Manual.
 Supported kernel versions
 ~~~~~~~~~~~~~~~~~~~~~~~~~
 
-The :term:`OLDEST_KERNEL` setting is XXX in this release, meaning that
+The :term:`OLDEST_KERNEL` setting is 5.15 in this release, meaning that
 out the box, older kernels are not supported. See :ref:`4.3 migration notes
 <migration-4.3-supported-kernel-versions>` for details.
 
@@ -49,12 +49,17 @@ Supported distributions
 Compared to the previous releases, running BitBake is supported on new
 GNU/Linux distributions:
 
+-  Fedora 41
+-  CentOS Stream 9
+
 On the other hand, some earlier distributions are no longer supported:
 
-See :ref:`all supported distributions <system-requirements-supported-distros>`.
+-  CentOS Stream 8
+-  Fedora 38
+-  OpenSUSE Leap 15.4
+-  Ubuntu 20.04
 
-Go language changes
-~~~~~~~~~~~~~~~~~~~
+See :ref:`all supported distributions <system-requirements-supported-distros>`.
 
 Rust language changes
 ~~~~~~~~~~~~~~~~~~~~~

-- 
2.47.0



^ permalink raw reply related	[flat|nested] 24+ messages in thread

* [PATCH 07/11] ref-manual/system-requirements.rst: update list of supported distributions
  2025-03-28 13:07 [PATCH 00/11] Final release note updates for 5.2 Antonin Godard
                   ` (5 preceding siblings ...)
  2025-03-28 13:07 ` [PATCH 06/11] migration-guides/migration-5.2.rst: final update for 5.2 Antonin Godard
@ 2025-03-28 13:07 ` Antonin Godard
  2025-03-28 13:07 ` [PATCH 08/11] poky.yaml.in: bump minimum required Python version to 3.9 Antonin Godard
                   ` (4 subsequent siblings)
  11 siblings, 0 replies; 24+ messages in thread
From: Antonin Godard @ 2025-03-28 13:07 UTC (permalink / raw)
  To: docs; +Cc: Thomas Petazzoni, Antonin Godard

Before the 5.2 release, update the list of supported distributions to
match the SANITY_TESTED_DISTROS variable in poky.conf.

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
---
 documentation/ref-manual/system-requirements.rst | 10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

diff --git a/documentation/ref-manual/system-requirements.rst b/documentation/ref-manual/system-requirements.rst
index 93b95a7fb..df0a61dd9 100644
--- a/documentation/ref-manual/system-requirements.rst
+++ b/documentation/ref-manual/system-requirements.rst
@@ -64,20 +64,20 @@ supported on the following distributions:
 
 -  Ubuntu 24.04 (LTS)
 
--  Fedora 38
+-  Ubuntu 24.10
 
 -  Fedora 39
 
 -  Fedora 40
 
--  CentOS Stream 8
+-  Fedora 41
+
+-  CentOS Stream 9
 
 -  Debian GNU/Linux 11 (Bullseye)
 
 -  Debian GNU/Linux 12 (Bookworm)
 
--  OpenSUSE Leap 15.4
-
 -  OpenSUSE Leap 15.5
 
 -  OpenSUSE Leap 15.6
@@ -86,6 +86,8 @@ supported on the following distributions:
 
 -  AlmaLinux 9
 
+-  Rocky 8
+
 -  Rocky 9
 
 The following distribution versions are still tested, even though the

-- 
2.47.0



^ permalink raw reply related	[flat|nested] 24+ messages in thread

* [PATCH 08/11] poky.yaml.in: bump minimum required Python version to 3.9
  2025-03-28 13:07 [PATCH 00/11] Final release note updates for 5.2 Antonin Godard
                   ` (6 preceding siblings ...)
  2025-03-28 13:07 ` [PATCH 07/11] ref-manual/system-requirements.rst: update list of supported distributions Antonin Godard
@ 2025-03-28 13:07 ` Antonin Godard
  2025-03-28 13:07 ` [PATCH 09/11] ref-manual/variables.rst: document the GRUB_MKIMAGE_OPTS variable Antonin Godard
                   ` (3 subsequent siblings)
  11 siblings, 0 replies; 24+ messages in thread
From: Antonin Godard @ 2025-03-28 13:07 UTC (permalink / raw)
  To: docs; +Cc: Thomas Petazzoni, Antonin Godard

After commit 67566c7410e1 ("bitbake: lib/bb: Bump minimum python version
requirement to 3.9") on Poky.

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
---
 documentation/poky.yaml.in | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/documentation/poky.yaml.in b/documentation/poky.yaml.in
index c93b78066..aeda3665e 100644
--- a/documentation/poky.yaml.in
+++ b/documentation/poky.yaml.in
@@ -13,7 +13,7 @@ DOCCONF_VERSION : "dev"
 BITBAKE_SERIES : ""
 YOCTO_DL_URL : "https://downloads.yoctoproject.org"
 YOCTO_RELEASE_DL_URL : "&YOCTO_DL_URL;/releases/yocto/yocto-&DISTRO;"
-MIN_PYTHON_VERSION : "3.8.0"
+MIN_PYTHON_VERSION : "3.9.0"
 MIN_TAR_VERSION : "1.28"
 MIN_GIT_VERSION : "1.8.3.1"
 MIN_GCC_VERSION : "8.0"

-- 
2.47.0



^ permalink raw reply related	[flat|nested] 24+ messages in thread

* [PATCH 09/11] ref-manual/variables.rst: document the GRUB_MKIMAGE_OPTS variable
  2025-03-28 13:07 [PATCH 00/11] Final release note updates for 5.2 Antonin Godard
                   ` (7 preceding siblings ...)
  2025-03-28 13:07 ` [PATCH 08/11] poky.yaml.in: bump minimum required Python version to 3.9 Antonin Godard
@ 2025-03-28 13:07 ` Antonin Godard
  2025-03-28 13:07 ` [PATCH 10/11] ref-manual/variables.rst: document the SPDX_PACKAGE_VERSION variable Antonin Godard
                   ` (2 subsequent siblings)
  11 siblings, 0 replies; 24+ messages in thread
From: Antonin Godard @ 2025-03-28 13:07 UTC (permalink / raw)
  To: docs; +Cc: Thomas Petazzoni, Antonin Godard

This new Grub variable controls the options passed to the grub-mkimage
command in the Grub recipe.

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
---
 documentation/ref-manual/variables.rst | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/documentation/ref-manual/variables.rst b/documentation/ref-manual/variables.rst
index dace40f59..20563d61f 100644
--- a/documentation/ref-manual/variables.rst
+++ b/documentation/ref-manual/variables.rst
@@ -3435,6 +3435,11 @@ system and gives an overview of their function and contents.
       See the :ref:`ref-classes-grub-efi` class for more
       information on how this variable is used.
 
+   :term:`GRUB_MKIMAGE_OPTS`
+      This variable controls additional options passed to the ``grub-mkimage``
+      command in the GNU GRand Unified Bootloader (GRUB) recipe during the
+      ``do_mkimage`` task.
+
    :term:`GRUB_OPTS`
       Additional options to add to the GNU GRand Unified Bootloader (GRUB)
       configuration. Use a semi-colon character (``;``) to separate

-- 
2.47.0



^ permalink raw reply related	[flat|nested] 24+ messages in thread

* [PATCH 10/11] ref-manual/variables.rst: document the SPDX_PACKAGE_VERSION variable
  2025-03-28 13:07 [PATCH 00/11] Final release note updates for 5.2 Antonin Godard
                   ` (8 preceding siblings ...)
  2025-03-28 13:07 ` [PATCH 09/11] ref-manual/variables.rst: document the GRUB_MKIMAGE_OPTS variable Antonin Godard
@ 2025-03-28 13:07 ` Antonin Godard
  2025-03-28 13:07 ` [PATCH 11/11] migration-guides/{migration,release-note}-5.2: update for 5.2 release Antonin Godard
  2025-03-28 14:44 ` [docs] [PATCH 00/11] Final release note updates for 5.2 Yoann Congal
  11 siblings, 0 replies; 24+ messages in thread
From: Antonin Godard @ 2025-03-28 13:07 UTC (permalink / raw)
  To: docs; +Cc: Thomas Petazzoni, Antonin Godard

This variable controls the package version as seen in the SPDX 3.0 JSON
output (software_packageVersion). The default value for this variable is
PV.

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
---
 documentation/ref-manual/variables.rst | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/documentation/ref-manual/variables.rst b/documentation/ref-manual/variables.rst
index 20563d61f..62e339ed8 100644
--- a/documentation/ref-manual/variables.rst
+++ b/documentation/ref-manual/variables.rst
@@ -8420,6 +8420,11 @@ system and gives an overview of their function and contents.
       and the prefix of ``documentNamespace``. It is set by default to
       ``http://spdx.org/spdxdoc``.
 
+   :term:`SPDX_PACKAGE_VERSION`
+      This variable controls the package version as seen in the SPDX 3.0 JSON
+      output (``software_packageVersion``). The default value for this variable
+      is :term:`PV`.
+
    :term:`SPDX_PRETTY`
       This option makes the SPDX output more human-readable, using
       identation and newlines, instead of the default output in a

-- 
2.47.0



^ permalink raw reply related	[flat|nested] 24+ messages in thread

* [PATCH 11/11] migration-guides/{migration,release-note}-5.2: update for 5.2 release
  2025-03-28 13:07 [PATCH 00/11] Final release note updates for 5.2 Antonin Godard
                   ` (9 preceding siblings ...)
  2025-03-28 13:07 ` [PATCH 10/11] ref-manual/variables.rst: document the SPDX_PACKAGE_VERSION variable Antonin Godard
@ 2025-03-28 13:07 ` Antonin Godard
  2025-03-28 16:03   ` [docs] " Quentin Schulz
  2025-03-28 14:44 ` [docs] [PATCH 00/11] Final release note updates for 5.2 Yoann Congal
  11 siblings, 1 reply; 24+ messages in thread
From: Antonin Godard @ 2025-03-28 13:07 UTC (permalink / raw)
  To: docs; +Cc: Thomas Petazzoni, Antonin Godard

Document changes between 0e91a1dabf27 ("adwaita-icon-theme: upgrade 47.0
-> 48.0") up to b3c21a23ad3a ("migration-guides/release-notes-5.2:
update for upcoming 5.2 release") in Poky.

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
---
 documentation/migration-guides/migration-5.2.rst   | 26 ++++++++++++++++++++++
 .../migration-guides/release-notes-5.2.rst         | 22 ++++++++++++++++++
 2 files changed, 48 insertions(+)

diff --git a/documentation/migration-guides/migration-5.2.rst b/documentation/migration-guides/migration-5.2.rst
index 59a2782f2..c54f054c7 100644
--- a/documentation/migration-guides/migration-5.2.rst
+++ b/documentation/migration-guides/migration-5.2.rst
@@ -178,6 +178,32 @@ This should now be replaced by::
 
    UBOOT_ENTRYPOINT ?= "0x20008000"
 
+
+Git fetcher: support for multiple revisions per URL removed
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+
+The support for having multiple Git revisions per URL in :term:`SRC_URI` was
+removed from BitBake, which means the following syntax is not supported
+anymore::
+
+   SRC_URI = "git://some.host/somepath;branch=branchX,branchY;name=nameX,nameY"
+   SRCREV_nameX = "xxxxxxxxxxxxxxxxxxxx"
+   SRCREV_nameY = "yyyyyyyyyyyyyyyyyyyy"
+
+This was rarely used in the core repositories, and this removal simplifies the
+code logic in several places.
+
+Git fetcher: Branch parameter now required in :term:`SRC_URI`
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+
+The ``branch`` parameter is now required when specifying a Git repository in
+:term:`SRC_URI`, for example::
+
+   SRC_URI = "git://some.host/somepath;branch=branchX"
+
+A missing ``branch`` parameter used to produce a warning, and will now produce
+an error.
+
 Recipe changes
 ~~~~~~~~~~~~~~
 
diff --git a/documentation/migration-guides/release-notes-5.2.rst b/documentation/migration-guides/release-notes-5.2.rst
index cbef0d686..05fc92e85 100644
--- a/documentation/migration-guides/release-notes-5.2.rst
+++ b/documentation/migration-guides/release-notes-5.2.rst
@@ -43,6 +43,13 @@ New Features / Enhancements in |yocto-ver|
       This can be used for authentication of private NPM registries, among other
       uses.
 
+   -  The :term:`GRUB_MKIMAGE_OPTS` can be used to control the flags to the
+      ``grub-mkimage`` command in the context of the Grub recipe (``grub-efi``).
+
+   -  The :term:`SPDX_PACKAGE_VERSION` variable controls the package version as
+      seen in the SPDX 3.0 JSON output (``software_packageVersion``). The default
+      value for this variable is :term:`PV`.
+
 -  Kernel-related changes:
 
    -  :ref:`ref-classes-cml1`: in :ref:`ref-tasks-diffconfig`, do not override
@@ -81,6 +88,10 @@ New Features / Enhancements in |yocto-ver|
        -  ``qcom-x1e80100-lenovo-t14s-g6-adreno``
        -  ``qcom-x1e80100-lenovo-t14s-g6-audio``
        -  ``qcom-x1e80100-lenovo-t14s-g6-compute``
+       -  ``qcom-adreno-a623``
+       -  ``qcom-qcs8300-adreno``
+       -  ``qca-qca2066``
+       -  ``qcom-adreno-a2xx``
 
    -  ``linux-firmware``: split ``amgpu``, ``ath10k``, ``ath11k`` and ``ath12k``
       in separate packages.
@@ -208,6 +219,10 @@ New Features / Enhancements in |yocto-ver|
    -  ``rust-target-config``: Update the data layout for the *x86-64* target, as
       it was different in Rust from LLVM, which produced a data layout error.
 
+   -  The :term:`PACKAGECONFIG_CONFARGS` value if now passed to the ``cargo
+      build`` command, which means that Rust recipes can now properly define
+      their :term:`PACKAGECONFIG` configuration.
+
 -  Wic Image Creator changes:
 
    -  Allow the ``--exclude-path`` option to exclude symlinks.
@@ -330,6 +345,8 @@ New Features / Enhancements in |yocto-ver|
       -  ``wget``: increase timeout to 100s from 30s to match CDN worst
          response time.
 
+      -  ``wget``: Support setting :term:`PV` in :term:`SRC_URI`.
+
       -  Add support for fast initial shallow fetch. The fetcher will prefer an
          initial shallow clone, but will re-utilize an existing bare clone if
          there is one. If the remote server does not allow shallow fetches, the
@@ -494,6 +511,8 @@ New Features / Enhancements in |yocto-ver|
    -  ``systemd``: ``apparmor``, ``fido``, ``mountfsd``, ``nsresourced``
    -  ``ovmf``: ``debug``
    -  ``webkitgtk``: ``assertions``
+   -  ``iproute2``: ``iptables``
+   -  ``man-db``: ``col``
 
 -  Systemd related changes:
 
@@ -540,6 +559,9 @@ New Features / Enhancements in |yocto-ver|
    -  Add a sanity check to validate that the C++ toolchain is functional on the
       host.
 
+   -  Add a sanity check to check that the C++ compiler on the host supports
+      C++20.
+
    -  Add a sanity check to verify that :term:`TOPDIR` does not contain
       non-ASCII characters, as it may lead to unexpected build errors.
 

-- 
2.47.0



^ permalink raw reply related	[flat|nested] 24+ messages in thread

* Re: [docs] [PATCH 00/11] Final release note updates for 5.2
  2025-03-28 13:07 [PATCH 00/11] Final release note updates for 5.2 Antonin Godard
                   ` (10 preceding siblings ...)
  2025-03-28 13:07 ` [PATCH 11/11] migration-guides/{migration,release-note}-5.2: update for 5.2 release Antonin Godard
@ 2025-03-28 14:44 ` Yoann Congal
  2025-03-28 14:49   ` Antonin Godard
  11 siblings, 1 reply; 24+ messages in thread
From: Yoann Congal @ 2025-03-28 14:44 UTC (permalink / raw)
  To: antonin.godard; +Cc: docs, Thomas Petazzoni

[-- Attachment #1: Type: text/plain, Size: 2830 bytes --]

Hi Antonin,

Le ven. 28 mars 2025 à 14:07, Antonin Godard via lists.yoctoproject.org
<antonin.godard=bootlin.com@lists.yoctoproject.org> a écrit :

> This series makes the final updates before the 5.2 release, which
> includes adding the recipe upgrades, license changes, as well as cleaning
> up a few empty sections.
>
> It also updates the release notes / migration guide and overall
> documentation with regards to the latest changes on Poky.
>

I don't see
[PATCH] poky.yaml.in: Raise minimum GCC version to 10.1
https://lists.yoctoproject.org/g/docs/message/6606
in your 5.2 branch. I feel like it should be in it.

It might conflict with
[PATCH 08/11] poky.yaml.in: bump minimum required Python version to 3.9
https://lists.yoctoproject.org/g/docs/message/6663

Tell me if you want me to rebase/resend to a branch.

Regards,


> Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
> ---
> Antonin Godard (11):
>       migration-guides/release-notes-5.2.rst: add the list of contributors
>       migration-guides/release-notes-5.2.rst: add recipe upgrades
>       migration-guides/release-notes-5.2.rst: add LICENSE recipe changes
>       migration-guides/release-notes-5.2.rst: add security fixes
>       migration-guides/release-notes-5.2.rst: add an entry for addfragments
>       migration-guides/migration-5.2.rst: final update for 5.2
>       ref-manual/system-requirements.rst: update list of supported
> distributions
>       poky.yaml.in: bump minimum required Python version to 3.9
>       ref-manual/variables.rst: document the GRUB_MKIMAGE_OPTS variable
>       ref-manual/variables.rst: document the SPDX_PACKAGE_VERSION variable
>       migration-guides/{migration,release-note}-5.2: update for 5.2 release
>
>  documentation/migration-guides/migration-5.2.rst   |   39 +-
>  .../migration-guides/release-notes-5.2.rst         | 1516
> +++++++++++++++++++-
>  documentation/poky.yaml.in                         |    2 +-
>  documentation/ref-manual/system-requirements.rst   |   10 +-
>  documentation/ref-manual/variables.rst             |   10 +
>  5 files changed, 1567 insertions(+), 10 deletions(-)
> ---
> base-commit: ea1636013722c12e72ca115240c8ce533e05ece2
> change-id: 20250327-release-note-5-2-updates-2-8fb5d45989bd
>
> Best regards,
> --
> Antonin Godard <antonin.godard@bootlin.com>
>
>
> -=-=-=-=-=-=-=-=-=-=-=-
> Links: You receive all messages sent to this group.
> View/Reply Online (#6656):
> https://lists.yoctoproject.org/g/docs/message/6656
> Mute This Topic: https://lists.yoctoproject.org/mt/111953529/4316185
> Group Owner: docs+owner@lists.yoctoproject.org
> Unsubscribe: https://lists.yoctoproject.org/g/docs/unsub [
> yoann.congal@smile.fr]
> -=-=-=-=-=-=-=-=-=-=-=-
>
>

-- 
Yoann Congal
Smile ECS

[-- Attachment #2: Type: text/html, Size: 4730 bytes --]

^ permalink raw reply	[flat|nested] 24+ messages in thread

* Re: [docs] [PATCH 00/11] Final release note updates for 5.2
  2025-03-28 14:44 ` [docs] [PATCH 00/11] Final release note updates for 5.2 Yoann Congal
@ 2025-03-28 14:49   ` Antonin Godard
  2025-03-28 14:52     ` Yoann Congal
  0 siblings, 1 reply; 24+ messages in thread
From: Antonin Godard @ 2025-03-28 14:49 UTC (permalink / raw)
  To: Yoann Congal, antonin.godard; +Cc: docs, Thomas Petazzoni

Hi Yoann,

On Fri Mar 28, 2025 at 3:44 PM CET, Yoann Congal wrote:
> Hi Antonin,
>
> Le ven. 28 mars 2025 à 14:07, Antonin Godard via lists.yoctoproject.org
> <antonin.godard=bootlin.com@lists.yoctoproject.org> a écrit :
>
>> This series makes the final updates before the 5.2 release, which
>> includes adding the recipe upgrades, license changes, as well as cleaning
>> up a few empty sections.
>>
>> It also updates the release notes / migration guide and overall
>> documentation with regards to the latest changes on Poky.
>>
>
> I don't see
> [PATCH] poky.yaml.in: Raise minimum GCC version to 10.1
> https://lists.yoctoproject.org/g/docs/message/6606
> in your 5.2 branch. I feel like it should be in it.
>
> It might conflict with
> [PATCH 08/11] poky.yaml.in: bump minimum required Python version to 3.9
> https://lists.yoctoproject.org/g/docs/message/6663
>
> Tell me if you want me to rebase/resend to a branch.

Sorry, I just forgot (and didn't get that you were talking about this patch on
IRC, I confounded it with your C++ toolchain flag sanity check patch somehow).

Applied to master-next, thanks for the awareness!

Regards,
Antonin

-- 
Antonin Godard, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com


^ permalink raw reply	[flat|nested] 24+ messages in thread

* Re: [docs] [PATCH 00/11] Final release note updates for 5.2
  2025-03-28 14:49   ` Antonin Godard
@ 2025-03-28 14:52     ` Yoann Congal
  0 siblings, 0 replies; 24+ messages in thread
From: Yoann Congal @ 2025-03-28 14:52 UTC (permalink / raw)
  To: Antonin Godard; +Cc: docs, Thomas Petazzoni

[-- Attachment #1: Type: text/plain, Size: 1560 bytes --]

Le ven. 28 mars 2025 à 15:49, Antonin Godard <antonin.godard@bootlin.com> a
écrit :

> Hi Yoann,
>
> On Fri Mar 28, 2025 at 3:44 PM CET, Yoann Congal wrote:
> > Hi Antonin,
> >
> > Le ven. 28 mars 2025 à 14:07, Antonin Godard via lists.yoctoproject.org
> > <antonin.godard=bootlin.com@lists.yoctoproject.org> a écrit :
> >
> >> This series makes the final updates before the 5.2 release, which
> >> includes adding the recipe upgrades, license changes, as well as
> cleaning
> >> up a few empty sections.
> >>
> >> It also updates the release notes / migration guide and overall
> >> documentation with regards to the latest changes on Poky.
> >>
> >
> > I don't see
> > [PATCH] poky.yaml.in: Raise minimum GCC version to 10.1
> > https://lists.yoctoproject.org/g/docs/message/6606
> > in your 5.2 branch. I feel like it should be in it.
> >
> > It might conflict with
> > [PATCH 08/11] poky.yaml.in: bump minimum required Python version to 3.9
> > https://lists.yoctoproject.org/g/docs/message/6663
> >
> > Tell me if you want me to rebase/resend to a branch.
>
> Sorry, I just forgot (and didn't get that you were talking about this
> patch on
> IRC, I confounded it with your C++ toolchain flag sanity check patch
> somehow).
>

Well those are close, one document the other.


> Applied to master-next, thanks for the awareness!
>

Thank you :)


> Regards,
> Antonin
>
> --
> Antonin Godard, Bootlin
> Embedded Linux and Kernel engineering
> https://bootlin.com
>


-- 
Yoann Congal
Smile ECS

[-- Attachment #2: Type: text/html, Size: 3163 bytes --]

^ permalink raw reply	[flat|nested] 24+ messages in thread

* Re: [docs] [PATCH 11/11] migration-guides/{migration,release-note}-5.2: update for 5.2 release
  2025-03-28 13:07 ` [PATCH 11/11] migration-guides/{migration,release-note}-5.2: update for 5.2 release Antonin Godard
@ 2025-03-28 16:03   ` Quentin Schulz
  2025-03-28 16:47     ` Richard Purdie
  0 siblings, 1 reply; 24+ messages in thread
From: Quentin Schulz @ 2025-03-28 16:03 UTC (permalink / raw)
  To: antonin.godard, docs; +Cc: Thomas Petazzoni

Hi Antonin,

On 3/28/25 2:07 PM, Antonin Godard via lists.yoctoproject.org wrote:
> Document changes between 0e91a1dabf27 ("adwaita-icon-theme: upgrade 47.0
> -> 48.0") up to b3c21a23ad3a ("migration-guides/release-notes-5.2:
> update for upcoming 5.2 release") in Poky.
> 
> Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
> ---
>   documentation/migration-guides/migration-5.2.rst   | 26 ++++++++++++++++++++++
>   .../migration-guides/release-notes-5.2.rst         | 22 ++++++++++++++++++
>   2 files changed, 48 insertions(+)
> 
> diff --git a/documentation/migration-guides/migration-5.2.rst b/documentation/migration-guides/migration-5.2.rst
> index 59a2782f2..c54f054c7 100644
> --- a/documentation/migration-guides/migration-5.2.rst
> +++ b/documentation/migration-guides/migration-5.2.rst
> @@ -178,6 +178,32 @@ This should now be replaced by::
>   
>      UBOOT_ENTRYPOINT ?= "0x20008000"
>   
> +
> +Git fetcher: support for multiple revisions per URL removed
> +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
> +
> +The support for having multiple Git revisions per URL in :term:`SRC_URI` was
> +removed from BitBake, which means the following syntax is not supported
> +anymore::
> +
> +   SRC_URI = "git://some.host/somepath;branch=branchX,branchY;name=nameX,nameY"
> +   SRCREV_nameX = "xxxxxxxxxxxxxxxxxxxx"
> +   SRCREV_nameY = "yyyyyyyyyyyyyyyyyyyy"
> +
> +This was rarely used in the core repositories, and this removal simplifies the
> +code logic in several places.
> +

Can we suggest the user how to transition away from that? What was this 
even supposed to do?

> +Git fetcher: Branch parameter now required in :term:`SRC_URI`
> +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
> +
> +The ``branch`` parameter is now required when specifying a Git repository in
> +:term:`SRC_URI`, for example::
> +
> +   SRC_URI = "git://some.host/somepath;branch=branchX"
> +
> +A missing ``branch`` parameter used to produce a warning, and will now produce
> +an error.
> +

You can specify that it used to default to "master" when it was missing, 
so if the recipe was building without, you likely want to have 
;branch=master in there? (I haven't re-checked but I believe that's the 
case?).

>   Recipe changes
>   ~~~~~~~~~~~~~~
>   
> diff --git a/documentation/migration-guides/release-notes-5.2.rst b/documentation/migration-guides/release-notes-5.2.rst
> index cbef0d686..05fc92e85 100644
> --- a/documentation/migration-guides/release-notes-5.2.rst
> +++ b/documentation/migration-guides/release-notes-5.2.rst
> @@ -43,6 +43,13 @@ New Features / Enhancements in |yocto-ver|
>         This can be used for authentication of private NPM registries, among other
>         uses.
>   
> +   -  The :term:`GRUB_MKIMAGE_OPTS` can be used to control the flags to the
> +      ``grub-mkimage`` command in the context of the Grub recipe (``grub-efi``).

It should be GRUB, all uppercase? https://en.wikipedia.org/wiki/GNU_GRUB

> +
> +   -  The :term:`SPDX_PACKAGE_VERSION` variable controls the package version as
> +      seen in the SPDX 3.0 JSON output (``software_packageVersion``). The default
> +      value for this variable is :term:`PV`.
> +

Would recommend not giving the default value here if it's already in the 
glossary, let's avoid having to modify multiple places if this gets 
changed in the future.

>   -  Kernel-related changes:
>   
>      -  :ref:`ref-classes-cml1`: in :ref:`ref-tasks-diffconfig`, do not override
> @@ -81,6 +88,10 @@ New Features / Enhancements in |yocto-ver|
>          -  ``qcom-x1e80100-lenovo-t14s-g6-adreno``
>          -  ``qcom-x1e80100-lenovo-t14s-g6-audio``
>          -  ``qcom-x1e80100-lenovo-t14s-g6-compute``
> +       -  ``qcom-adreno-a623``
> +       -  ``qcom-qcs8300-adreno``
> +       -  ``qca-qca2066``
> +       -  ``qcom-adreno-a2xx``

The git diff indentation seems odd, but maybe everything;s fine (a case 
of tabs vs spaces maybe?).

>   
>      -  ``linux-firmware``: split ``amgpu``, ``ath10k``, ``ath11k`` and ``ath12k``
>         in separate packages.
> @@ -208,6 +219,10 @@ New Features / Enhancements in |yocto-ver|
>      -  ``rust-target-config``: Update the data layout for the *x86-64* target, as
>         it was different in Rust from LLVM, which produced a data layout error.
>   
> +   -  The :term:`PACKAGECONFIG_CONFARGS` value if now passed to the ``cargo
> +      build`` command, which means that Rust recipes can now properly define
> +      their :term:`PACKAGECONFIG` configuration.
> +
>   -  Wic Image Creator changes:
>   
>      -  Allow the ``--exclude-path`` option to exclude symlinks.
> @@ -330,6 +345,8 @@ New Features / Enhancements in |yocto-ver|
>         -  ``wget``: increase timeout to 100s from 30s to match CDN worst
>            response time.
>   
> +      -  ``wget``: Support setting :term:`PV` in :term:`SRC_URI`.
> +

Sorry, don't understand what that means? Do you have a commit to refer to?

>         -  Add support for fast initial shallow fetch. The fetcher will prefer an
>            initial shallow clone, but will re-utilize an existing bare clone if
>            there is one. If the remote server does not allow shallow fetches, the
> @@ -494,6 +511,8 @@ New Features / Enhancements in |yocto-ver|
>      -  ``systemd``: ``apparmor``, ``fido``, ``mountfsd``, ``nsresourced``
>      -  ``ovmf``: ``debug``
>      -  ``webkitgtk``: ``assertions``
> +   -  ``iproute2``: ``iptables``
> +   -  ``man-db``: ``col``
>   

odd indentation in git diff but maybe just a tabs vs space issue?

Cheers,
Quentin


^ permalink raw reply	[flat|nested] 24+ messages in thread

* Re: [docs] [PATCH 11/11] migration-guides/{migration,release-note}-5.2: update for 5.2 release
  2025-03-28 16:03   ` [docs] " Quentin Schulz
@ 2025-03-28 16:47     ` Richard Purdie
  2025-03-31  8:32       ` Quentin Schulz
  0 siblings, 1 reply; 24+ messages in thread
From: Richard Purdie @ 2025-03-28 16:47 UTC (permalink / raw)
  To: quentin.schulz, antonin.godard, docs; +Cc: Thomas Petazzoni

On Fri, 2025-03-28 at 17:03 +0100, Quentin Schulz via lists.yoctoproject.org wrote:
> Hi Antonin,
> 
> On 3/28/25 2:07 PM, Antonin Godard via lists.yoctoproject.org wrote:
> > Document changes between 0e91a1dabf27 ("adwaita-icon-theme: upgrade 47.0
> > -> 48.0") up to b3c21a23ad3a ("migration-guides/release-notes-5.2:
> > update for upcoming 5.2 release") in Poky.
> > 
> > Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
> > ---
> >   documentation/migration-guides/migration-5.2.rst   | 26 ++++++++++++++++++++++
> >   .../migration-guides/release-notes-5.2.rst         | 22 ++++++++++++++++++
> >   2 files changed, 48 insertions(+)
> > 
> > diff --git a/documentation/migration-guides/migration-5.2.rst b/documentation/migration-guides/migration-5.2.rst
> > index 59a2782f2..c54f054c7 100644
> > --- a/documentation/migration-guides/migration-5.2.rst
> > +++ b/documentation/migration-guides/migration-5.2.rst
> > @@ -178,6 +178,32 @@ This should now be replaced by::
> >   
> >      UBOOT_ENTRYPOINT ?= "0x20008000"
> >   
> > +
> > +Git fetcher: support for multiple revisions per URL removed
> > +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
> > +
> > +The support for having multiple Git revisions per URL in :term:`SRC_URI` was
> > +removed from BitBake, which means the following syntax is not supported
> > +anymore::
> > +
> > +   SRC_URI = "git://some.host/somepath;branch=branchX,branchY;name=nameX,nameY"
> > +   SRCREV_nameX = "xxxxxxxxxxxxxxxxxxxx"
> > +   SRCREV_nameY = "yyyyyyyyyyyyyyyyyyyy"
> > +
> > +This was rarely used in the core repositories, and this removal simplifies the
> > +code logic in several places.
> > +
> 
> Can we suggest the user how to transition away from that? What was this 
> even supposed to do?

It would only have ever been useful with bare clones where there wasn't
a checkout. The only user I know of used to be the kernel recipe but
that no longer does this.

Cheers,

Richard


^ permalink raw reply	[flat|nested] 24+ messages in thread

* Re: [docs] [PATCH 11/11] migration-guides/{migration,release-note}-5.2: update for 5.2 release
  2025-03-28 16:47     ` Richard Purdie
@ 2025-03-31  8:32       ` Quentin Schulz
  2025-04-03 15:39         ` Richard Purdie
  0 siblings, 1 reply; 24+ messages in thread
From: Quentin Schulz @ 2025-03-31  8:32 UTC (permalink / raw)
  To: Richard Purdie, antonin.godard, docs; +Cc: Thomas Petazzoni

Hi Richard,

On 3/28/25 5:47 PM, Richard Purdie wrote:
> On Fri, 2025-03-28 at 17:03 +0100, Quentin Schulz via lists.yoctoproject.org wrote:
>> Hi Antonin,
>>
>> On 3/28/25 2:07 PM, Antonin Godard via lists.yoctoproject.org wrote:
>>> Document changes between 0e91a1dabf27 ("adwaita-icon-theme: upgrade 47.0
>>> -> 48.0") up to b3c21a23ad3a ("migration-guides/release-notes-5.2:
>>> update for upcoming 5.2 release") in Poky.
>>>
>>> Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
>>> ---
>>>    documentation/migration-guides/migration-5.2.rst   | 26 ++++++++++++++++++++++
>>>    .../migration-guides/release-notes-5.2.rst         | 22 ++++++++++++++++++
>>>    2 files changed, 48 insertions(+)
>>>
>>> diff --git a/documentation/migration-guides/migration-5.2.rst b/documentation/migration-guides/migration-5.2.rst
>>> index 59a2782f2..c54f054c7 100644
>>> --- a/documentation/migration-guides/migration-5.2.rst
>>> +++ b/documentation/migration-guides/migration-5.2.rst
>>> @@ -178,6 +178,32 @@ This should now be replaced by::
>>>    
>>>       UBOOT_ENTRYPOINT ?= "0x20008000"
>>>    
>>> +
>>> +Git fetcher: support for multiple revisions per URL removed
>>> +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>>> +
>>> +The support for having multiple Git revisions per URL in :term:`SRC_URI` was
>>> +removed from BitBake, which means the following syntax is not supported
>>> +anymore::
>>> +
>>> +   SRC_URI = "git://some.host/somepath;branch=branchX,branchY;name=nameX,nameY"
>>> +   SRCREV_nameX = "xxxxxxxxxxxxxxxxxxxx"
>>> +   SRCREV_nameY = "yyyyyyyyyyyyyyyyyyyy"
>>> +
>>> +This was rarely used in the core repositories, and this removal simplifies the
>>> +code logic in several places.
>>> +
>>
>> Can we suggest the user how to transition away from that? What was this
>> even supposed to do?
> 
> It would only have ever been useful with bare clones where there wasn't
> a checkout. The only user I know of used to be the kernel recipe but
> that no longer does this.
> 

Ah yes, was doing my grep in git history from bitbake repo instead of 
poky :)

It seems like what we did was split the code into a separate git 
repository but I assume we can do the same by having the same git repo, 
simply in a second SRC_URI entry.

git log -p -G ";branch=.*,.*\""

followed by a search for \.bb, \.inc in the pager returned 
c29aac6a8b5b417ad46f3cdf9c1a2d61c4f6cdd5 in poky.

So I guess we can say:

"""
If one of your recipes is still using this mechanism, you can split the 
code source fetching into two separate entries::

    SRC_URI = "git://some.host/somepath;branch=branchX;name=nameX"
    SRC_URI += "git://some.host/somepath;branch=branchY;name=nameY"
    SRCREV_nameX = "xxxxxxxxxxxxxxxxxxxx"
    SRCREV_nameY = "yyyyyyyyyyyyyyyyyyyy"

"""

(NOT tested).

Cheers,
Quentin


^ permalink raw reply	[flat|nested] 24+ messages in thread

* Re: [docs] [PATCH 11/11] migration-guides/{migration,release-note}-5.2: update for 5.2 release
  2025-03-31  8:32       ` Quentin Schulz
@ 2025-04-03 15:39         ` Richard Purdie
  0 siblings, 0 replies; 24+ messages in thread
From: Richard Purdie @ 2025-04-03 15:39 UTC (permalink / raw)
  To: Quentin Schulz, antonin.godard, docs; +Cc: Thomas Petazzoni

On Mon, 2025-03-31 at 10:32 +0200, Quentin Schulz wrote:
> Hi Richard,
> 
> On 3/28/25 5:47 PM, Richard Purdie wrote:
> > On Fri, 2025-03-28 at 17:03 +0100, Quentin Schulz via
> > lists.yoctoproject.org wrote:
> > > Hi Antonin,
> > > 
> > > On 3/28/25 2:07 PM, Antonin Godard via lists.yoctoproject.org
> > > wrote:
> > > > Document changes between 0e91a1dabf27 ("adwaita-icon-theme:
> > > > upgrade 47.0
> > > > -> 48.0") up to b3c21a23ad3a ("migration-guides/release-notes-
> > > > 5.2:
> > > > update for upcoming 5.2 release") in Poky.
> > > > 
> > > > Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
> > > > ---
> > > >    documentation/migration-guides/migration-5.2.rst   | 26
> > > > ++++++++++++++++++++++
> > > >    .../migration-guides/release-notes-5.2.rst         | 22
> > > > ++++++++++++++++++
> > > >    2 files changed, 48 insertions(+)
> > > > 
> > > > diff --git a/documentation/migration-guides/migration-5.2.rst
> > > > b/documentation/migration-guides/migration-5.2.rst
> > > > index 59a2782f2..c54f054c7 100644
> > > > --- a/documentation/migration-guides/migration-5.2.rst
> > > > +++ b/documentation/migration-guides/migration-5.2.rst
> > > > @@ -178,6 +178,32 @@ This should now be replaced by::
> > > >    
> > > >       UBOOT_ENTRYPOINT ?= "0x20008000"
> > > >    
> > > > +
> > > > +Git fetcher: support for multiple revisions per URL removed
> > > > +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
> > > > +
> > > > +The support for having multiple Git revisions per URL in
> > > > :term:`SRC_URI` was
> > > > +removed from BitBake, which means the following syntax is not
> > > > supported
> > > > +anymore::
> > > > +
> > > > +   SRC_URI =
> > > > "git://some.host/somepath;branch=branchX,branchY;name=nameX,nam
> > > > eY"
> > > > +   SRCREV_nameX = "xxxxxxxxxxxxxxxxxxxx"
> > > > +   SRCREV_nameY = "yyyyyyyyyyyyyyyyyyyy"
> > > > +
> > > > +This was rarely used in the core repositories, and this
> > > > removal simplifies the
> > > > +code logic in several places.
> > > > +
> > > 
> > > Can we suggest the user how to transition away from that? What
> > > was this
> > > even supposed to do?
> > 
> > It would only have ever been useful with bare clones where there
> > wasn't
> > a checkout. The only user I know of used to be the kernel recipe
> > but
> > that no longer does this.
> > 
> 
> Ah yes, was doing my grep in git history from bitbake repo instead of
> poky :)
> 
> It seems like what we did was split the code into a separate git 
> repository but I assume we can do the same by having the same git
> repo, 
> simply in a second SRC_URI entry.
> 
> git log -p -G ";branch=.*,.*\""
> 
> followed by a search for \.bb, \.inc in the pager returned 
> c29aac6a8b5b417ad46f3cdf9c1a2d61c4f6cdd5 in poky.
> 
> So I guess we can say:
> 
> """
> If one of your recipes is still using this mechanism, you can split
> the 
> code source fetching into two separate entries::
> 
>     SRC_URI = "git://some.host/somepath;branch=branchX;name=nameX"
>     SRC_URI += "git://some.host/somepath;branch=branchY;name=nameY"
>     SRCREV_nameX = "xxxxxxxxxxxxxxxxxxxx"
>     SRCREV_nameY = "yyyyyyyyyyyyyyyyyyyy"
> 
> """
> 
> (NOT tested).

Multiple revisions only worked with bareclones otherwise it wouldn't
know how to checkout the resulting code during unpack. The above has
the same issue, it wouldn't know how to unpack the resulting code.

With a bare clone the checkout is left to the recipe so it isn't an
issue in that case.

For that reason I think examples are probably not needed as very little
code should be using this (hopefully nothing).

Cheers,

Richard



^ permalink raw reply	[flat|nested] 24+ messages in thread

* Re: [docs] [PATCH 04/11] migration-guides/release-notes-5.2.rst: add security fixes
  2025-03-28 13:07 ` [PATCH 04/11] migration-guides/release-notes-5.2.rst: add security fixes Antonin Godard
@ 2025-04-12 16:38   ` Takayasu Ito
  2025-04-15 11:56     ` Antonin Godard
  0 siblings, 1 reply; 24+ messages in thread
From: Takayasu Ito @ 2025-04-12 16:38 UTC (permalink / raw)
  To: antonin.godard, docs; +Cc: Thomas Petazzoni

Hi all.

* CVEs that have been fixed but are not on the list

< +   * -  ``gstreamer1.0``
< +     - :cve_nist:`2024-47606`
< +   * -  ``gstreamer1.0-plugins-base``
< +     - :cve_nist:`2024-47538`, :cve_nist:`2024-47541`, :cve_nist:`2024-47542`,  :cve_nist:`2024-47600`, 
:cve_nist:`2024-47607`, :cve_nist:`2024-47615`, :cve_nist:`2024-47835`
< +   * -  ``gstreamer1.0-plugins-good``
< +     - :cve_nist:`2024-47537`, :cve_nist:`2024-47539`, :cve_nist:`2024-47540`, :cve_nist:`2024-47543`, 
:cve_nist:`2024-47544`, :cve_nist:`2024-47545`, :cve_nist:`2024-47546`, :cve_nist:`2024-47596`, :cve_nist:`2024-47597`, 
:cve_nist:`2024-47598`, :cve_nist:`2024-47599`, :cve_nist:`2024-47601`, :cve_nist:`2024-47602`, :cve_nist:`2024-47603`, 
:cve_nist:`2024-47606`, :cve_nist:`2024-47613`, :cve_nist:`2024-47774`, :cve_nist:`2024-47775`, :cve_nist:`2024-47776`, 
:cve_nist:`2024-47777`, :cve_nist:`2024-47778`, :cve_nist:`2024-47834`
see https://gstreamer.freedesktop.org/security/

< +   * - ``openssh``
< +     - :cve_nist:`2025-26465`, :cve_nist:`2025-26466`
see https://www.openssh.com/txt/release-9.9p2

< +   * - ``socat``
< +     - :cve_nist:`2024-54661`
see http://www.dest-unreach.org/socat/

* CVEs already fixed in previous releases

 > +   * - ``libssh2``
 > +     - :cve_nist:`2023-48795`

The patch for CVE-2023-28795, which is no longer needed due to libssh2 upgrading to 1.11.1, was committed on 2024/01/24 and has 
already been fixed at the time of the scarthgap release, so we do not consider it necessary to post it to this list of fixes.
see: 
https://git.yoctoproject.org/poky/commit/meta/recipes-support/libssh2/libssh2?h=walnascar&id=3adac25f899054b7d1d8c14458a1a4cd310abbd7


* CVE numbers that should be changed in ascending order

 > +   * - ``expat``
 > +     - :cve_nist:`2024-50602`, :cve_nist:`2024-8176`
< +   * - ``expat``
< +     - :cve_nist:`2024-8176`, :cve_nist:`2024-50602`


 > +   * - ``grub``
 > +     - :cve_nist:`2024-45781`, :cve_nist:`2024-45782`, :cve_nist:`2024-56737`, :cve_nist:`2024-45780`, 
:cve_nist:`2024-45783`, :cve_nist:`2025-0624`, :cve_nist:`2024-45774`, :cve_nist:`2024-45775`, :cve_nist:`2025-0622`, 
:cve_nist:`2024-45776`, :cve_nist:`2024-45777`, :cve_nist:`2025-0690`, :cve_nist:`2025-1118`, :cve_nist:`2024-45778`, 
:cve_nist:`2024-45779`, :cve_nist:`2025-0677`, :cve_nist:`2025-0684`, :cve_nist:`2025-0685`, :cve_nist:`2025-0686`, 
:cve_nist:`2025-0689`, :cve_nist:`2025-0678`, :cve_nist:`2025-1125`
< +   * - ``grub``
< +     - :cve_nist:`2024-45774`, :cve_nist:`2024-45775`, :cve_nist:`2024-45776`, :cve_nist:`2024-45777`, 
:cve_nist:`2024-45778`, :cve_nist:`2024-45779`, :cve_nist:`2024-45780`, :cve_nist:`2024-45781`, :cve_nist:`2024-45782`, 
:cve_nist:`2024-45783`, :cve_nist:`2024-56737`, :cve_nist:`2025-0622`, :cve_nist:`2025-0624`, :cve_nist:`2025-0677`, 
:cve_nist:`2025-0678`, :cve_nist:`2025-0684`, :cve_nist:`2025-0685`, :cve_nist:`2025-0686`, :cve_nist:`2025-0689`, 
:cve_nist:`2025-0690`, :cve_nist:`2025-1118`, :cve_nist:`2025-1125`

 > +   * - ``libarchive``
 > +     - :cve_nist:`2024-57970`, :cve_nist:`2025-25724`, :cve_nist:`2025-1632`
< +   * - ``libarchive``
< +     - :cve_nist:`2024-57970`, :cve_nist:`2025-1632`, :cve_nist:`2025-25724`

 > +   * - ``libxml2``
 > +     - :cve_nist:`2025-24928`, :cve_nist:`2024-56171`
< +   * - ``libxml2``
< +     - :cve_nist:`2024-56171`, :cve_nist:`2025-24928`

 > +   * - ``tiff``
 > +     - :cve_nist:`2023-52356`, :cve_nist:`2023-6228`, :cve_nist:`2023-6277`
< +   * - ``tiff``
< +     - :cve_nist:`2023-6277`, :cve_nist:`2023-52356`, :cve_nist:`2023-6228`

 > +   * - ``vim``
 > +     - :cve_nist:`2024-45306`, :cve_nist:`2024-47814`, :cve_nist:`2025-22134`, :cve_nist:`2025-24014`, 
:cve_nist:`2025-26603`, :cve_nist:`2025-1215`, :cve_nist:`2025-27423`, :cve_nist:`2025-29768`
< +   * - ``vim``
< +     - :cve_nist:`2024-45306`, :cve_nist:`2024-47814`, :cve_nist:`2025-1215`, :cve_nist:`2025-22134`, :cve_nist:`2025-24014`, 
:cve_nist:`2025-26603`, :cve_nist:`2025-27423`, :cve_nist:`2025-29768`



On 2025/03/28 22:07, Antonin Godard via lists.yoctoproject.org wrote:
> Add security fixes by going through the log between yocto-5.1 and
> walnascar branch tip on Poky.
> 
> Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
> ---
>   .../migration-guides/release-notes-5.2.rst         | 67 ++++++++++++++++++++++
>   1 file changed, 67 insertions(+)
> 
> diff --git a/documentation/migration-guides/release-notes-5.2.rst b/documentation/migration-guides/release-notes-5.2.rst
> index 1e05631d9..d583f3e9d 100644
> --- a/documentation/migration-guides/release-notes-5.2.rst
> +++ b/documentation/migration-guides/release-notes-5.2.rst
> @@ -765,6 +765,73 @@ The following changes have been made to the :term:`LICENSE` values set by recipe
>   Security Fixes in |yocto-ver|
>   ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>   
> +The following CVEs have been fixed:
> +
> +.. list-table::
> +   :widths: 30 70
> +   :header-rows: 1
> +
> +   * - Recipe
> +     - CVE IDs
> +   * - ``barebox``
> +     - :cve_nist:`2025-26721`, :cve_nist:`2025-26722`, :cve_nist:`2025-26723`, :cve_nist:`2025-26724`, :cve_nist:`2025-26725`
> +   * - ``binutils``
> +     - :cve_nist:`2024-53589`, :cve_nist:`2025-1153`
> +   * - ``curl``
> +     - :cve_nist:`2024-8096`, :cve_nist:`2024-9681`, :cve_nist:`2024-11053`, :cve_nist:`2025-0167`, :cve_nist:`2025-0665`, :cve_nist:`2025-0725`
> +   * - ``expat``
> +     - :cve_nist:`2024-50602`, :cve_nist:`2024-8176`
> +   * - ``ghostscript``
> +     - :cve_nist:`2024-46951`, :cve_nist:`2024-46952`, :cve_nist:`2024-46953`, :cve_nist:`2024-46954`, :cve_nist:`2024-46955`, :cve_nist:`2024-46956`
> +   * - ``gnutls``
> +     - :cve_nist:`2024-12243`
> +   * - ``go``
> +     - :cve_nist:`2024-34155`, :cve_nist:`2024-34156`, :cve_nist:`2024-34158`, :cve_nist:`2024-45336`, :cve_nist:`2024-45341`, :cve_nist:`2025-22866`, :cve_nist:`2025-22870`
> +   * - ``grub``
> +     - :cve_nist:`2024-45781`, :cve_nist:`2024-45782`, :cve_nist:`2024-56737`, :cve_nist:`2024-45780`, :cve_nist:`2024-45783`, :cve_nist:`2025-0624`, :cve_nist:`2024-45774`, :cve_nist:`2024-45775`, :cve_nist:`2025-0622`, :cve_nist:`2024-45776`, :cve_nist:`2024-45777`, :cve_nist:`2025-0690`, :cve_nist:`2025-1118`, :cve_nist:`2024-45778`, :cve_nist:`2024-45779`, :cve_nist:`2025-0677`, :cve_nist:`2025-0684`, :cve_nist:`2025-0685`, :cve_nist:`2025-0686`, :cve_nist:`2025-0689`, :cve_nist:`2025-0678`, :cve_nist:`2025-1125`
> +   * - ``libarchive``
> +     - :cve_nist:`2024-57970`, :cve_nist:`2025-25724`, :cve_nist:`2025-1632`
> +   * - ``libcap``
> +     - :cve_nist:`2025-1390`
> +   * - ``libsndfile1``
> +     - :cve_nist:`2024-50612`
> +   * - ``libssh2``
> +     - :cve_nist:`2023-48795`
> +   * - ``libtasn1``
> +     - :cve_nist:`2024-12133`
> +   * - ``libxml2``
> +     - :cve_nist:`2025-24928`, :cve_nist:`2024-56171`
> +   * - ``ofono``
> +     - :cve_nist:`2024-7539`, :cve_nist:`2024-7540`, :cve_nist:`2024-7541`, :cve_nist:`2024-7542`
> +   * - ``omvf``
> +     - :cve_nist:`2023-45236`, :cve_nist:`2023-45237`, :cve_nist:`2024-25742`
> +   * - ``openssl``
> +     - :cve_nist:`2024-9143`, :cve_nist:`2024-12797`, :cve_nist:`2024-13176`
> +   * - ``orc``
> +     - :cve_nist:`2024-40897`
> +   * - ``python3``
> +     - :cve_nist:`2025-0938`, :cve_nist:`2024-12254`
> +   * - ``qemu``
> +     - :cve_nist:`2024-6505`
> +   * - ``rsync``
> +     - :cve_nist:`2024-12084`, :cve_nist:`2024-12085`, :cve_nist:`2024-12086`, :cve_nist:`2024-12087`, :cve_nist:`2024-12088`, :cve_nist:`2024-12747`
> +   * - ``ruby``
> +     - :cve_nist:`2024-41123`, :cve_nist:`2024-41946`
> +   * - ``rust``
> +     - :cve_nist:`2024-43402`
> +   * - ``tiff``
> +     - :cve_nist:`2023-52356`, :cve_nist:`2023-6228`, :cve_nist:`2023-6277`
> +   * - ``vim``
> +     - :cve_nist:`2024-45306`, :cve_nist:`2024-47814`, :cve_nist:`2025-22134`, :cve_nist:`2025-24014`, :cve_nist:`2025-26603`, :cve_nist:`2025-1215`, :cve_nist:`2025-27423`, :cve_nist:`2025-29768`
> +   * - ``webkitgtk``
> +     - :cve_nist:`2025-24143`, :cve_nist:`2025-24150`, :cve_nist:`2025-24158`, :cve_nist:`2025-24162`
> +   * - ``wpa-supplicant``
> +     - :cve_nist:`2024-5290`
> +   * - ``xserver-xorg``
> +     - :cve_nist:`2024-9632`, :cve_nist:`2025-26594`, :cve_nist:`2025-26595`, :cve_nist:`2025-26596`, :cve_nist:`2025-26597`, :cve_nist:`2025-26598`, :cve_nist:`2025-26599`, :cve_nist:`2025-26600`, :cve_nist:`2025-26601`
> +   * - ``xwayland``
> +     - :cve_nist:`2024-9632`, :cve_nist:`2025-26594`, :cve_nist:`2025-26595`, :cve_nist:`2025-26596`, :cve_nist:`2025-26597`, :cve_nist:`2025-26598`, :cve_nist:`2025-26599`, :cve_nist:`2025-26600`, :cve_nist:`2025-26601`
> +
>   Recipe Upgrades in |yocto-ver|
>   ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>   
> 
> 
> 
> -=-=-=-=-=-=-=-=-=-=-=-
> Links: You receive all messages sent to this group.
> View/Reply Online (#6658): https://lists.yoctoproject.org/g/docs/message/6658
> Mute This Topic: https://lists.yoctoproject.org/mt/111953531/7581020
> Group Owner: docs+owner@lists.yoctoproject.org
> Unsubscribe: https://lists.yoctoproject.org/g/docs/unsub [ypa.takayasu.ito@gmail.com]
> -=-=-=-=-=-=-=-=-=-=-=-
> 

-- 
Takayasu Ito
Yocto Project Ambassador
ti@itrc.jp



^ permalink raw reply	[flat|nested] 24+ messages in thread

* Re: [docs] [PATCH 04/11] migration-guides/release-notes-5.2.rst: add security fixes
  2025-04-12 16:38   ` [docs] " Takayasu Ito
@ 2025-04-15 11:56     ` Antonin Godard
  2025-04-15 22:34       ` Takayasu Ito
  0 siblings, 1 reply; 24+ messages in thread
From: Antonin Godard @ 2025-04-15 11:56 UTC (permalink / raw)
  To: Takayasu Ito, docs; +Cc: Thomas Petazzoni

Hi Takayasu,

On Sat Apr 12, 2025 at 6:38 PM CEST, Takayasu Ito wrote:
> Hi all.
>
> * CVEs that have been fixed but are not on the list
>
> < +   * -  ``gstreamer1.0``
> < +     - :cve_nist:`2024-47606`
> < +   * -  ``gstreamer1.0-plugins-base``
> < +     - :cve_nist:`2024-47538`, :cve_nist:`2024-47541`, :cve_nist:`2024-47542`,  :cve_nist:`2024-47600`, 
> :cve_nist:`2024-47607`, :cve_nist:`2024-47615`, :cve_nist:`2024-47835`
> < +   * -  ``gstreamer1.0-plugins-good``
> < +     - :cve_nist:`2024-47537`, :cve_nist:`2024-47539`, :cve_nist:`2024-47540`, :cve_nist:`2024-47543`, 
> :cve_nist:`2024-47544`, :cve_nist:`2024-47545`, :cve_nist:`2024-47546`, :cve_nist:`2024-47596`, :cve_nist:`2024-47597`, 
> :cve_nist:`2024-47598`, :cve_nist:`2024-47599`, :cve_nist:`2024-47601`, :cve_nist:`2024-47602`, :cve_nist:`2024-47603`, 
> :cve_nist:`2024-47606`, :cve_nist:`2024-47613`, :cve_nist:`2024-47774`, :cve_nist:`2024-47775`, :cve_nist:`2024-47776`, 
> :cve_nist:`2024-47777`, :cve_nist:`2024-47778`, :cve_nist:`2024-47834`
> see https://gstreamer.freedesktop.org/security/
>
> < +   * - ``openssh``
> < +     - :cve_nist:`2025-26465`, :cve_nist:`2025-26466`
> see https://www.openssh.com/txt/release-9.9p2
>
> < +   * - ``socat``
> < +     - :cve_nist:`2024-54661`
> see http://www.dest-unreach.org/socat/
>
> * CVEs already fixed in previous releases
>
>  > +   * - ``libssh2``
>  > +     - :cve_nist:`2023-48795`
>
> The patch for CVE-2023-28795, which is no longer needed due to libssh2 upgrading to 1.11.1, was committed on 2024/01/24 and has 
> already been fixed at the time of the scarthgap release, so we do not consider it necessary to post it to this list of fixes.
> see: 
> https://git.yoctoproject.org/poky/commit/meta/recipes-support/libssh2/libssh2?h=walnascar&id=3adac25f899054b7d1d8c14458a1a4cd310abbd7
>
>
> * CVE numbers that should be changed in ascending order
>
>  > +   * - ``expat``
>  > +     - :cve_nist:`2024-50602`, :cve_nist:`2024-8176`
> < +   * - ``expat``
> < +     - :cve_nist:`2024-8176`, :cve_nist:`2024-50602`
>
>
>  > +   * - ``grub``
>  > +     - :cve_nist:`2024-45781`, :cve_nist:`2024-45782`, :cve_nist:`2024-56737`, :cve_nist:`2024-45780`, 
> :cve_nist:`2024-45783`, :cve_nist:`2025-0624`, :cve_nist:`2024-45774`, :cve_nist:`2024-45775`, :cve_nist:`2025-0622`, 
> :cve_nist:`2024-45776`, :cve_nist:`2024-45777`, :cve_nist:`2025-0690`, :cve_nist:`2025-1118`, :cve_nist:`2024-45778`, 
> :cve_nist:`2024-45779`, :cve_nist:`2025-0677`, :cve_nist:`2025-0684`, :cve_nist:`2025-0685`, :cve_nist:`2025-0686`, 
> :cve_nist:`2025-0689`, :cve_nist:`2025-0678`, :cve_nist:`2025-1125`
> < +   * - ``grub``
> < +     - :cve_nist:`2024-45774`, :cve_nist:`2024-45775`, :cve_nist:`2024-45776`, :cve_nist:`2024-45777`, 
> :cve_nist:`2024-45778`, :cve_nist:`2024-45779`, :cve_nist:`2024-45780`, :cve_nist:`2024-45781`, :cve_nist:`2024-45782`, 
> :cve_nist:`2024-45783`, :cve_nist:`2024-56737`, :cve_nist:`2025-0622`, :cve_nist:`2025-0624`, :cve_nist:`2025-0677`, 
> :cve_nist:`2025-0678`, :cve_nist:`2025-0684`, :cve_nist:`2025-0685`, :cve_nist:`2025-0686`, :cve_nist:`2025-0689`, 
> :cve_nist:`2025-0690`, :cve_nist:`2025-1118`, :cve_nist:`2025-1125`
>
>  > +   * - ``libarchive``
>  > +     - :cve_nist:`2024-57970`, :cve_nist:`2025-25724`, :cve_nist:`2025-1632`
> < +   * - ``libarchive``
> < +     - :cve_nist:`2024-57970`, :cve_nist:`2025-1632`, :cve_nist:`2025-25724`
>
>  > +   * - ``libxml2``
>  > +     - :cve_nist:`2025-24928`, :cve_nist:`2024-56171`
> < +   * - ``libxml2``
> < +     - :cve_nist:`2024-56171`, :cve_nist:`2025-24928`
>
>  > +   * - ``tiff``
>  > +     - :cve_nist:`2023-52356`, :cve_nist:`2023-6228`, :cve_nist:`2023-6277`
> < +   * - ``tiff``
> < +     - :cve_nist:`2023-6277`, :cve_nist:`2023-52356`, :cve_nist:`2023-6228`
>
>  > +   * - ``vim``
>  > +     - :cve_nist:`2024-45306`, :cve_nist:`2024-47814`, :cve_nist:`2025-22134`, :cve_nist:`2025-24014`, 
> :cve_nist:`2025-26603`, :cve_nist:`2025-1215`, :cve_nist:`2025-27423`, :cve_nist:`2025-29768`
> < +   * - ``vim``
> < +     - :cve_nist:`2024-45306`, :cve_nist:`2024-47814`, :cve_nist:`2025-1215`, :cve_nist:`2025-22134`, :cve_nist:`2025-24014`, 
> :cve_nist:`2025-26603`, :cve_nist:`2025-27423`, :cve_nist:`2025-29768`

Thanks!

Can you please send a patch on the mailing list with these additions? So that
you take credit for the changes. Please also describe how you came up with this
list.

Regards,
Antonin

-- 
Antonin Godard, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com


^ permalink raw reply	[flat|nested] 24+ messages in thread

* Re: [docs] [PATCH 04/11] migration-guides/release-notes-5.2.rst: add security fixes
  2025-04-15 11:56     ` Antonin Godard
@ 2025-04-15 22:34       ` Takayasu Ito
  2025-04-16  7:27         ` Antonin Godard
  0 siblings, 1 reply; 24+ messages in thread
From: Takayasu Ito @ 2025-04-15 22:34 UTC (permalink / raw)
  To: Antonin Godard, docs; +Cc: Thomas Petazzoni

Hi Antonin,

I could not post the patch because I did not have the development environment with me due to machine trouble.

On 2025/04/15 20:56, Antonin Godard wrote:
> Hi Takayasu,
> 
> On Sat Apr 12, 2025 at 6:38 PM CEST, Takayasu Ito wrote:
>> Hi all.
>>
>> * CVEs that have been fixed but are not on the list
>>
>> < +   * -  ``gstreamer1.0``
>> < +     - :cve_nist:`2024-47606`
>> < +   * -  ``gstreamer1.0-plugins-base``
>> < +     - :cve_nist:`2024-47538`, :cve_nist:`2024-47541`, :cve_nist:`2024-47542`,  :cve_nist:`2024-47600`,
>> :cve_nist:`2024-47607`, :cve_nist:`2024-47615`, :cve_nist:`2024-47835`
>> < +   * -  ``gstreamer1.0-plugins-good``
>> < +     - :cve_nist:`2024-47537`, :cve_nist:`2024-47539`, :cve_nist:`2024-47540`, :cve_nist:`2024-47543`,
>> :cve_nist:`2024-47544`, :cve_nist:`2024-47545`, :cve_nist:`2024-47546`, :cve_nist:`2024-47596`, :cve_nist:`2024-47597`,
>> :cve_nist:`2024-47598`, :cve_nist:`2024-47599`, :cve_nist:`2024-47601`, :cve_nist:`2024-47602`, :cve_nist:`2024-47603`,
>> :cve_nist:`2024-47606`, :cve_nist:`2024-47613`, :cve_nist:`2024-47774`, :cve_nist:`2024-47775`, :cve_nist:`2024-47776`,
>> :cve_nist:`2024-47777`, :cve_nist:`2024-47778`, :cve_nist:`2024-47834`
>> see https://gstreamer.freedesktop.org/security/
>>
>> < +   * - ``openssh``
>> < +     - :cve_nist:`2025-26465`, :cve_nist:`2025-26466`
>> see https://www.openssh.com/txt/release-9.9p2
>>
>> < +   * - ``socat``
>> < +     - :cve_nist:`2024-54661`
>> see http://www.dest-unreach.org/socat/
>>
>> * CVEs already fixed in previous releases
>>
>>   > +   * - ``libssh2``
>>   > +     - :cve_nist:`2023-48795`
>>
>> The patch for CVE-2023-28795, which is no longer needed due to libssh2 upgrading to 1.11.1, was committed on 2024/01/24 and has
>> already been fixed at the time of the scarthgap release, so we do not consider it necessary to post it to this list of fixes.
>> see:
>> https://git.yoctoproject.org/poky/commit/meta/recipes-support/libssh2/libssh2?h=walnascar&id=3adac25f899054b7d1d8c14458a1a4cd310abbd7
>>
>>
>> * CVE numbers that should be changed in ascending order
>>
>>   > +   * - ``expat``
>>   > +     - :cve_nist:`2024-50602`, :cve_nist:`2024-8176`
>> < +   * - ``expat``
>> < +     - :cve_nist:`2024-8176`, :cve_nist:`2024-50602`
>>
>>
>>   > +   * - ``grub``
>>   > +     - :cve_nist:`2024-45781`, :cve_nist:`2024-45782`, :cve_nist:`2024-56737`, :cve_nist:`2024-45780`,
>> :cve_nist:`2024-45783`, :cve_nist:`2025-0624`, :cve_nist:`2024-45774`, :cve_nist:`2024-45775`, :cve_nist:`2025-0622`,
>> :cve_nist:`2024-45776`, :cve_nist:`2024-45777`, :cve_nist:`2025-0690`, :cve_nist:`2025-1118`, :cve_nist:`2024-45778`,
>> :cve_nist:`2024-45779`, :cve_nist:`2025-0677`, :cve_nist:`2025-0684`, :cve_nist:`2025-0685`, :cve_nist:`2025-0686`,
>> :cve_nist:`2025-0689`, :cve_nist:`2025-0678`, :cve_nist:`2025-1125`
>> < +   * - ``grub``
>> < +     - :cve_nist:`2024-45774`, :cve_nist:`2024-45775`, :cve_nist:`2024-45776`, :cve_nist:`2024-45777`,
>> :cve_nist:`2024-45778`, :cve_nist:`2024-45779`, :cve_nist:`2024-45780`, :cve_nist:`2024-45781`, :cve_nist:`2024-45782`,
>> :cve_nist:`2024-45783`, :cve_nist:`2024-56737`, :cve_nist:`2025-0622`, :cve_nist:`2025-0624`, :cve_nist:`2025-0677`,
>> :cve_nist:`2025-0678`, :cve_nist:`2025-0684`, :cve_nist:`2025-0685`, :cve_nist:`2025-0686`, :cve_nist:`2025-0689`,
>> :cve_nist:`2025-0690`, :cve_nist:`2025-1118`, :cve_nist:`2025-1125`
>>
>>   > +   * - ``libarchive``
>>   > +     - :cve_nist:`2024-57970`, :cve_nist:`2025-25724`, :cve_nist:`2025-1632`
>> < +   * - ``libarchive``
>> < +     - :cve_nist:`2024-57970`, :cve_nist:`2025-1632`, :cve_nist:`2025-25724`
>>
>>   > +   * - ``libxml2``
>>   > +     - :cve_nist:`2025-24928`, :cve_nist:`2024-56171`
>> < +   * - ``libxml2``
>> < +     - :cve_nist:`2024-56171`, :cve_nist:`2025-24928`
>>
>>   > +   * - ``tiff``
>>   > +     - :cve_nist:`2023-52356`, :cve_nist:`2023-6228`, :cve_nist:`2023-6277`
>> < +   * - ``tiff``
>> < +     - :cve_nist:`2023-6277`, :cve_nist:`2023-52356`, :cve_nist:`2023-6228`
>>
>>   > +   * - ``vim``
>>   > +     - :cve_nist:`2024-45306`, :cve_nist:`2024-47814`, :cve_nist:`2025-22134`, :cve_nist:`2025-24014`,
>> :cve_nist:`2025-26603`, :cve_nist:`2025-1215`, :cve_nist:`2025-27423`, :cve_nist:`2025-29768`
>> < +   * - ``vim``
>> < +     - :cve_nist:`2024-45306`, :cve_nist:`2024-47814`, :cve_nist:`2025-1215`, :cve_nist:`2025-22134`, :cve_nist:`2025-24014`,
>> :cve_nist:`2025-26603`, :cve_nist:`2025-27423`, :cve_nist:`2025-29768`
> 
> Thanks!
> 
> Can you please send a patch on the mailing list with these additions? So that
> you take credit for the changes. Please also describe how you came up with this
> list.
> 
> Regards,
> Antonin
> 

-- 
Takayasu Ito
Yocto Project Ambassador
ypa.takayasu.ito@gmail.com



^ permalink raw reply	[flat|nested] 24+ messages in thread

* Re: [docs] [PATCH 04/11] migration-guides/release-notes-5.2.rst: add security fixes
  2025-04-15 22:34       ` Takayasu Ito
@ 2025-04-16  7:27         ` Antonin Godard
  2025-04-20 15:27           ` Takayasu Ito
  0 siblings, 1 reply; 24+ messages in thread
From: Antonin Godard @ 2025-04-16  7:27 UTC (permalink / raw)
  To: Takayasu Ito, docs; +Cc: Thomas Petazzoni

Hi Takayasu,

On Wed Apr 16, 2025 at 12:34 AM CEST, Takayasu Ito wrote:
> Hi Antonin,
>
> I could not post the patch because I did not have the development environment with me due to machine trouble.

Okay, that's fine.

Could you please explain how you obtained these results?
It's not straightforward for me to assert the validity of your changes. I would
just need a way to reproduce the results you obtained. cve-check, maybe?

Antonin

-- 
Antonin Godard, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com


^ permalink raw reply	[flat|nested] 24+ messages in thread

* Re: [docs] [PATCH 04/11] migration-guides/release-notes-5.2.rst: add security fixes
  2025-04-16  7:27         ` Antonin Godard
@ 2025-04-20 15:27           ` Takayasu Ito
  0 siblings, 0 replies; 24+ messages in thread
From: Takayasu Ito @ 2025-04-20 15:27 UTC (permalink / raw)
  To: Antonin Godard, docs; +Cc: Thomas Petazzoni

Hi Antonin,

The decision is based on the upstream release notes and accompanying information.

As for gstreamer, three update commits have been made.

gstreamer1.0: upgrade 1.24.6 -> 1.24.9
https://git.yoctoproject.org/poky/commit/meta/recipes-multimedia/gstreamer?h=walnascar&id=0770b0 ecea8accb0edb9137595b2c7e0b94bb69b

gstreamer1.0: upgrade 1.24.9 -> 1.24.10
https://git.yoctoproject.org/poky/commit/?h=walnascar&id=d84 bc502cc610cbda9bf19e0320537287bf8a674

gstreamer1.0: upgrade 1.24.10 -> 1.24.12
https://git.yoctoproject.org/poky/commit/?h=walnascar&id= 925d5f1c725ceeb36c180b38a22dfdedd0dfc220

Release information for these updates is found at
https://gstreamer.freedesktop.org/news/

In it, it is stated that the security fixe is included in the 1.24.9 and 1.24.10 releases.

The details are confirmed at
https://gstreamer.freedesktop.org/security/

We can confirm that GStreamer-SA-2024-0004 through GStreamer-SA-2024-0030 were addressed in this release of walnascar.



On 2025/04/16 16:27, Antonin Godard wrote:
> Hi Takayasu,
> 
> On Wed Apr 16, 2025 at 12:34 AM CEST, Takayasu Ito wrote:
>> Hi Antonin,
>>
>> I could not post the patch because I did not have the development environment with me due to machine trouble.
> 
> Okay, that's fine.
> 
> Could you please explain how you obtained these results?
> It's not straightforward for me to assert the validity of your changes. I would
> just need a way to reproduce the results you obtained. cve-check, maybe?
> 
> Antonin
> 

-- 
Takayasu Ito
Yocto Project Ambassador
ypa.takayasu.ito@gmail.com



^ permalink raw reply	[flat|nested] 24+ messages in thread

end of thread, other threads:[~2025-04-20 15:27 UTC | newest]

Thread overview: 24+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-03-28 13:07 [PATCH 00/11] Final release note updates for 5.2 Antonin Godard
2025-03-28 13:07 ` [PATCH 01/11] migration-guides/release-notes-5.2.rst: add the list of contributors Antonin Godard
2025-03-28 13:07 ` [PATCH 02/11] migration-guides/release-notes-5.2.rst: add recipe upgrades Antonin Godard
2025-03-28 13:07 ` [PATCH 03/11] migration-guides/release-notes-5.2.rst: add LICENSE recipe changes Antonin Godard
2025-03-28 13:07 ` [PATCH 04/11] migration-guides/release-notes-5.2.rst: add security fixes Antonin Godard
2025-04-12 16:38   ` [docs] " Takayasu Ito
2025-04-15 11:56     ` Antonin Godard
2025-04-15 22:34       ` Takayasu Ito
2025-04-16  7:27         ` Antonin Godard
2025-04-20 15:27           ` Takayasu Ito
2025-03-28 13:07 ` [PATCH 05/11] migration-guides/release-notes-5.2.rst: add an entry for addfragments Antonin Godard
2025-03-28 13:07 ` [PATCH 06/11] migration-guides/migration-5.2.rst: final update for 5.2 Antonin Godard
2025-03-28 13:07 ` [PATCH 07/11] ref-manual/system-requirements.rst: update list of supported distributions Antonin Godard
2025-03-28 13:07 ` [PATCH 08/11] poky.yaml.in: bump minimum required Python version to 3.9 Antonin Godard
2025-03-28 13:07 ` [PATCH 09/11] ref-manual/variables.rst: document the GRUB_MKIMAGE_OPTS variable Antonin Godard
2025-03-28 13:07 ` [PATCH 10/11] ref-manual/variables.rst: document the SPDX_PACKAGE_VERSION variable Antonin Godard
2025-03-28 13:07 ` [PATCH 11/11] migration-guides/{migration,release-note}-5.2: update for 5.2 release Antonin Godard
2025-03-28 16:03   ` [docs] " Quentin Schulz
2025-03-28 16:47     ` Richard Purdie
2025-03-31  8:32       ` Quentin Schulz
2025-04-03 15:39         ` Richard Purdie
2025-03-28 14:44 ` [docs] [PATCH 00/11] Final release note updates for 5.2 Yoann Congal
2025-03-28 14:49   ` Antonin Godard
2025-03-28 14:52     ` Yoann Congal

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox