Commit Graph

36054 Commits

Author SHA1 Message Date
Ankur Tyagi
3d989eb151
xmlsec1: upgrade 1.3.7 -> 1.3.9
Refreshed patches and updated ptest.

Changelog:
https://github.com/lsh123/xmlsec/releases/tag/1.3.8
https://github.com/lsh123/xmlsec/releases/tag/1.3.9

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:55 -08:00
Ankur Tyagi
c5560026f6
multipath-tools: upgrade 0.11.1 -> 0.11.3
Dropped 0001-libmpathutils-uxsock.c-Include-string.h-for-memcpy.patch and
0013-libdmmp-Makefile-Fix-KBUILD_BUILD_TIMESTAMP-usage.patch which are now
merged in the upstream.

Refreshed other patches for the new version.

Release Note:
https://github.com/opensvc/multipath-tools/blob/0.11.3/NEWS.md

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:55 -08:00
Ankur Tyagi
e09a58d3d2
proj: upgrade 9.6.2 -> 9.7.0
Also update HOMEPAGE and SRC_URI.

Changelog:
https://proj.org/en/stable/news.html#id2

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:55 -08:00
Ankur Tyagi
0b845a0e6a
librdkafka: upgrade 2.11.0 -> 2.11.1
Changelog:
https://github.com/confluentinc/librdkafka/releases/tag/v2.11.1

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:55 -08:00
Ankur Tyagi
e6e9277335
zchunk: upgrade 1.5.1 -> 1.5.2
Changelog:
https://github.com/zchunk/zchunk/compare/1.5.1...1.5.2

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:55 -08:00
Randy MacLeod
aa635dc5dd
nano: upgrade 8.6 -> 8.7
ChangeLog:
==========
      build: avoid a warning when configured with --disable-multibuffer
      bump version numbers and add a news item for the 8.7 release
      display: regenerate the screen after a resize during a spell check
      display: regenerate the screen only before and after waiting for input
      display: upon resize, redraw the subwindows only when fully initialized
      docs: add example of copy-to-clipboard-with-OSC52 to the sample nanorc
      docs: mention that `execute` can pipe buffer or region to the command
      gnulib: update to its current upstream state
      moving: prevent a negative relative jump from going beyond top of buffer
      new feature: execute a command without capturing the output
      startup: register the handler for SIGWINCH much earlier
      text: when blanking a line due to --autoindent, keep the mark in sync
      tweaks: improve a few comments, drop one, and unwrap some lines
      tweaks: improve the punctuation of one item in the sample nanorc
      tweaks: replace a remaining double dash with a true emdash
      tweaks: reshuffle some #ifdefs, and rename a function
      tweaks: unwrap three lines, for esthetics

Signed-off-by: Randy MacLeod <Randy.MacLeod@windriver.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:54 -08:00
Randy MacLeod
736e14743c
iperf3: Upgrade 3.18 -> 3.20
Change summary from:
  https://software.es.net/iperf/news.html#iperf-3-19-released
and RELNOTES links:

iperf-3.20 fixes a number of bugs and also adds some minor enhancements.
  https://github.com/esnet/iperf/blob/master/RELNOTES.md#iperf-320-2025-11-14

iperf-3.19.1 is a security fix release to address three issues reported
by Han Lee of Apple Information Security.
  https://github.com/esnet/iperf/blob/master/RELNOTES.md#iperf-3191-2025-07-25

iperf-3.19 includes support for MP-TCPv1 under Linux, keepalives on the
control connection, support for the MSG_TRUNC receive option, and
a number of minor bug fixes.
  https://github.com/esnet/iperf/blob/master/RELNOTES.md#iperf-319-2025-05-16

Drop 2 CVE patches that were backports.
Drop 0001-configure.ac-check-for-CPP-prog.patch
which is merged in:
   https://github.com/esnet/iperf/commit/beadb59b90e8

License-Update: The only changes were:
  ❯ git log --oneline 3.18..3.20 LICENSE
  9f6dc21 Copyright updates for 2025.
  edf5c75 Fix typo in LICENSE

Signed-off-by: Randy MacLeod <Randy.MacLeod@windriver.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:54 -08:00
Jason Schonberg
b88a959117
xfce4-screenshooter: upgrade 1.11.2 -> 1.11.3
Changelog: https://gitlab.xfce.org/apps/xfce4-screenshooter/-/tags/xfce4-screenshooter-1.11.3

Signed-off-by: Jason Schonberg <schonm@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:54 -08:00
Jason Schonberg
e884ed4163
xfce4-taskmanager: upgrade 1.5.6 -> 1.5.8
Add a HOMEPAGE while we are here.

Changelog: https://gitlab.xfce.org/apps/xfce4-taskmanager/-/tags/xfce4-taskmanager-1.5.8
Changelog: https://gitlab.xfce.org/apps/xfce4-taskmanager/-/tags/xfce4-taskmanager-1.5.7

Signed-off-by: Jason Schonberg <schonm@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:54 -08:00
Jason Schonberg
67358cfbda
xfce4-panel-profiles: upgrade 1.0.14 -> 1.0.15
Add a HOMEPAGE while we are here.

Changelog: https://gitlab.xfce.org/apps/xfce4-panel-profiles/-/tags/xfce4-panel-profiles-1.0.15

Signed-off-by: Jason Schonberg <schonm@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:54 -08:00
Jason Schonberg
71871bade9
gigolo: upgrade 0.5.3 -> 0.6.0
Add a HOMEPAGE while we are here.
Use meson build.

Changelog: https://gitlab.xfce.org/apps/gigolo/-/tags/gigolo-0.6.0
Changelog: https://gitlab.xfce.org/apps/gigolo/-/tags/gigolo-0.5.4

Signed-off-by: Jason Schonberg <schonm@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:54 -08:00
Jason Schonberg
d3d49d7e00
orage: upgrade 4.20.1 -> 4.20.2
Add a HOMEPAGE while we are here.

Changelog: https://gitlab.xfce.org/apps/orage/-/releases/orage-4.20.2

Signed-off-by: Jason Schonberg <schonm@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:53 -08:00
Liu Yiding
788169b265
rtorrent: upgrade 0.16.1 -> 0.16.2
Changelog:
 https://github.com/rakshasa/rtorrent/releases/tag/v0.16.2

Remove 0001-scripts-common.m4-Insert-spaces-in-shell-lists.patch as it was merged in upstream.

Signed-off-by: Liu Yiding <liuyd.fnst@fujitsu.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:53 -08:00
Liu Yiding
2c0c0a9ec8
libtorrent: upgrade 0.16.1 -> 0.16.2
Remove 0001-scripts-common.m4-Insert-spaces-in-shell-lists.patch as it was merged in upstream.

Signed-off-by: Liu Yiding <liuyd.fnst@fujitsu.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:53 -08:00
Liu Yiding
bac13f19ec
poppler: upgrade 25.10.0 -> 25.11.0
Changelog:
 core:
  * NSS Signatures: Tweak the logic that decides which firefox profile to use
  * NSS Signatures: call PORT_GetError() only if the preceding CERT_PKIXVerifyCert() fails
  * Splash: Performance improvements
  * Fix crashes in malformed documents

 glib:
  * Fix ocsp check for signatures validation
  * Fix warning when running glib-mkenums

Signed-off-by: Liu Yiding <liuyd.fnst@fujitsu.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:53 -08:00
Liu Yiding
030d86f141
nspr: upgrade 4.37 -> 4.38
Signed-off-by: Liu Yiding <liuyd.fnst@fujitsu.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:53 -08:00
Liu Yiding
7e33b9cc55
flatpak: upgrade 1.16.1 -> 1.17.0
Changelog:
  https://github.com/flatpak/flatpak/releases/tag/1.17.0

Signed-off-by: Liu Yiding <liuyd.fnst@fujitsu.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:53 -08:00
Tom Geelen
82c2959678
python3-yarl: add BBCLASSEXTEND = "native nativesdk"
Signed-off-by: Tom Geelen <t.f.g.geelen@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-18 08:17:52 -08:00
Khem Raj
5226464803
googlebenchmark: Disable c2y extentions diagnostics
clang-22 now finds __COUNTER__ and it complains

| sources/googlebenchmark-1.9.4/src/benchmark.cc:15:
| sources/googlebenchmark-1.9.4/include/benchmark/benchmark.h:1461:30: error: '__COUNTER__' is a C2y extension [-Werror,-Wc2y-extensions]
|  1461 | #if defined(__COUNTER__) && (__COUNTER__ + 1 == __COUNTER__ + 0)

Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-15 17:10:46 -08:00
Gyorgy Sarvari
1e2731fce0
yasm: patch CVE-2021-33456
Details: https://nvd.nist.gov/vuln/detail/CVE-2021-33465

The patch was taken from Debian:
https://sources.debian.org/patches/yasm/1.3.0-8/1020-hash-null-CVE-2021-33456.patch/

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-15 15:49:44 -08:00
Gyorgy Sarvari
66a0b01b52
yasm: patch CVE-2021-33464
Details: https://nvd.nist.gov/vuln/detail/CVE-2021-33464

The patch was taken from Debian:
https://sources.debian.org/patches/yasm/1.3.0-8/1010-nasm-pp-no-env-CVE-2021-33464.patch/

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-15 15:49:44 -08:00
Gyorgy Sarvari
cc30757a7f
yasm: patch CVE-2023-29579
Details: https://nvd.nist.gov/vuln/detail/CVE-2023-29579

The patch was taken from Debian:
https://sources.debian.org/patches/yasm/1.3.0-8/1000-x86-dir-cpu-CVE-2023-29579.patch/

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-15 15:49:44 -08:00
Gyorgy Sarvari
93f85e4fd2
yasm: add alternative CVE_PRODUCT
There are multiple vendors for yasm:

$ sqlite3 ./nvdcve_2-2.db "select distinct vendor, product from products where product = 'yasm';"
tortall|yasm
yasm_project|yasm

Both products refer to the same application

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-15 15:49:44 -08:00
Gyorgy Sarvari
62a5309732
links: set CVE_PRODUCT
There are some unrelated software called "links", which cases
false-positive CVEs to be reported by the CVE checker.

Set the vendor/product pairs that were historically used with
CVEs for this software.

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-15 15:49:44 -08:00
Khem Raj
cc1ec784bf
python3-rich-toolkit: Enable ptests
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-15 15:49:43 -08:00
Jan Vermaete
e8444aa2b0
python3-rich-toolkit: add new recipe (version 0.15.1)
Signed-off-by: Jan Vermaete <jan.vermaete@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-15 16:27:07 +00:00
Gyorgy Sarvari
1d3c3ad93c
gimp: upgrade 3.0.4 -> 3.0.6
Switch back to fetch tarballs instead of the git repository.
The project has switched from appstream-glib to appstream as a dependency,
due to the prior isn't actively developed anymore[1].

This update also contains fixes for CVE-2025-10920, CVE-2025-10921, CVE-2025-10922,
CVE-2025-10923, CVE-2025-10924, CVE-2025-10925 and CVE-2025-10934.

[1]: c27096db9e

Release notes:

Core:

  - Many false-positive build warnings have been cleaned out (and proper
    issues fixed).
  - Various crashes fixed.
  - When creating a layer mask from the layer's alpha, but the layer has
    no alpha, simply fill the mask with complete opacity instead of
    a completely transparent layer.
  - Various core infrastructure code reviewed, cleaned up, refactored
    and improved, in drawable, layer and filter handling code, tree view
    code, and more.
  - GIMP_ICONS_LIKE_A_BOSS environment variable is not working anymore
    (because "gtk-menu-images" and "gtk-button-images" have been
    deprecated in GTK3 and removed in GTK4) and was therefore removed.
  - Lock Content now shows as an undo step.
  - Add alpha channel for certain transforms.
  - Add alpha channel on filter merge, when necessary.
  - Filters can now be applied non-destructively on channels.
  - Improved Photoshop brush support.
  - After deleting a palette entry, the next entry is automatically
    selected. This allows easily deleting several entries in a row,
    among other usage.
  - Resize image to layers irrespective to selections.
  - Improved in-GUI release notes' demo script language:
    * We can now set a button value to click it:
      "toolbox:text,
      tool-options:outline=1,
      tool-options:outline-direction"
    * Color selector's module names can be used as identifiers:
      "color-editor,color-editor:CMYK=1,color-editor:total-ink-coverage"
  - Fixed Alpha to Selection on single layers with no transparency.
  - Various code is slowly ported to newer code, preparing for GTK4 port
    (in an unplanned future step):
    * Using g_set_str() (optionally redefining it in our core code to
      avoid bumping the GLib minimum requirement).
    * Start using GListModel in various pieces of code, in particular
      getting rid of more and more usage of GtkTreeView when possible
      (as it will be deprecated with GTK4).
    * New GimpRow class for all future row widgets.
    * Use more of G_DECLARE_DERIVABLE_TYPE and G_DECLARE_FINAL_TYPE
      where relevant.
    * New GimpContainerListView using a GtkListBox.
    * New GimpRowSeparator, GimpRowSettings, GimpRowFilter and
      GimpRowDrawableFilter widgets.
  - (Experimental) GEX Format was updated.
  - Palette import:
    * Set alpha value for image palette imports.
    * Fix Lab & CMYK ACB palette import.
    * Add palette format filters to import dialog, making it more
      apparent what palette formats are supported, and giving the
      ability to hide irrelevant files.
  - Improved filter actions' sensitivity to make sure they are set
    insensitive when relevant. In particular filters which cannot be run
    non-destructively (e.g. filters with aux inputs, non-interactive
    filters and GEGL Graph) must be insensitive when trying to run them
    on group layers.
  - Fix bad axis centering on zoom out.
  - Export better SVG when exporting paths.

Tools:

  - Text tool: make sure the default color is only changed when the user
    confirms the color change.
  - Foreground Selection tool: do not create a selection when no strokes
    has been made. In particular this removes the unnecessary delay
    which happened when switching to another tool without actually
    stroking anything.
  - All Transform tools: transform boundaries for preview is now
    multi-layers aware.
  - (Experimental) Seamless Clone tool: made to work again, though it is
    still too slow to get out of Playground.

Graphical User Interface:

  - Various improvements to window management:
    * Keep-Above windows are set with the Utility hint.
    * Utility windows are not made transient to a parent.
    * Transient factory dialogs follow the active display, ensuring that
      new image windows would not hide your toolbox and dock windows.
  - Various CSS improvements for styling of the interface. Some theme
    leaks were also fixed.
  - New toggle button in Brushes and Fonts dockable, allowing brush and
    font previews to optionally follow the color theme. For instance,
    when using a dark theme, the brush and font previews could be drawn
    on the theme background, using the theme foreground colors. By
    default, these data previews are still drawn as black on white.
  - Palette grid is now drawn with the theme's background color.
  - Consistent naming patterns on human-facing options (first word only
    capitalized).
  - About dialog:
    * We will now display the date and time of the last
      check in a "Up to date as of <date> at <time>" string, differing
      from the "Last checked on <date> at <time>" string. The former
      will be used to indicate that GIMP is indeed up-to-date whereas
      the latter when a new version was released and that you should
      update.
    * We now respect the system time/date format on macOS and Windows.
  - The search popup won't pop up without an image.
  - Better zoom step algorithm for data previews in container popup
    (e.g. the brush popup in paint Tool Options).
  - Disable animation in the Input Controller, Preferences and Welcome
    dialogs for stack transition when animation are disabled in system
    settings.
  - Fixed crosshair hotspot on Windows (crosshair cursor for brushes was
    offset with a non-100% display scale factor).
  - Debug/CRITICAL dialog:
    * Make sure it is non-modal.
    * Follow the theme mode under Windows.
  - While loading images, all widgets in the file dialog are made
    insensitive, except for the Cancel button and the progress bar.
  - Both grid and list views can now zoom via scroll and zoom gestures
    (it used to only work in list views).
  - Pop an error message up on startup when GIO modules to read HTTPS
    links are not found and that we therefore fail to load the remote
    gimp_versions.json file. With the AppImage package in particular, we
    depend on an environment daemon which cannot be shipped in the
    package. So the next best thing is to warn people and tell them what
    they should install to get version checks.
  - Welcome dialog:
    * The "Community Tutorials" link is now shown after the
      "Documentation" link.
    * The "Learn more" link in Release Notes tab leads to the actual
      release news for this version.

Plug-ins:

  - PDF export: do not draw disabled layer masks.
  - Jigsaw: the plug-in can now draw on transparent layers.
  - Various file format fixes and improvements: JPEG 2000 import, TIFF
    import, DDS import, SVG import, PSP import, FITS export, ICNS
    import, Dicom import, WBMP import, Farbfeld import, XWD import, ILBM
    import.
  - Sphere Designer: use spin scale instead of spin entries (the latter
    is unusable with little horizontal space).
  - Animation Play: frames are shown again in the playback progress bar.
  - Vala Goat Exercise: ignoring C warning in this Vala plug-in as it is
    generated code and we cannot control it.
  - file-gih: brush pipe selection modes now have nice, translatable
    names.
  - Metadata viewer: port from GtkTreeView to GtkListBox.
  - File Raw Data: reduce Raw Data load dialogue height by moving to a
    2-column layout.
  - SVG import: it is now possible to break aspect ratio with specific
    width/height arguments, when calling the PDB procedure
    non-interactively (from other plug-ins).
  - Print: when run through a portal print dialog, the "Image Settings"
    will be exposed as a secondary dialog, outputted after the portal
    dialog, instead of a tab on the main print dialog (because it is not
    possible to tweak the print dialog when it is created by a portal).
    This will bring back usable workflow of printing with GIMP when run
    in a sandbox (e.g. Flatpak or Snap).
  - Recompose: fixed for YCbCr decomposed images.
  - Fixed vulnerabilities: ZDI-CAN-27684, ZDI-CAN-27863, ZDI-CAN-27878,
    ZDI-CAN-27836, ZDI-CAN-27823, ZDI-CAN-27793.
  - C Source and HTML export can now be run non-interactively too (e.g.
    from other plug-ins).
  - Map Object: fix missing spin boxes.
  - Small Tiles: fix display lag.

API:

  - libgimpui:
    * new function: gimp_prop_toggle_new()
    * updated widget default for GimpChoice in GimpProcedureDialog: when
      the number of choices is below 3, a radio frame is used, and a
      combo box otherwise (it used to always be a combo box).
    * GimpExportProcedureDialog: comment text area will be made
      (in)sensitive depending on the checked state of "Save Comment"
      option.
    * Use arrows for GimpSpinScale cursors.
    * GimpColorScales: no decimal for u8 RGB color selector. This change
      will help further distinguish between the 0...100 and 0..255 views
      in the Color Selectors.
    * Internal color drags now use a "application/x-geglcolor" target
      since "application/x-color" is standard and should not be used for
      our more powerful color formats.
  - libgimp:
    * new enum type: GimpTRCType
    * gimp_file_save() sets the XCF or exported files accordingly.
    * Metadata:
      + Favor existing image comment instead of always loading comment
        from metadata.
      + Fix handling of "charset=" in comments.
      + Better heuristic to choose the comment to export, especially
        when it has been edited in the export dialog comment field.
      + XMP modification date format fix and Exif.Image.DateTime
        metadata has been modernized, also adding the timezone.
  - PDB/libgimp:
    * Allow nullable sample points and guide types for some
      functions.
    * GeglParamFilePath can now be passed across the wire.
  - macOS: improve dock icon flashing issue.

Build:

  - CI scripts synced to latest `master` state.
  - Windows file format association list is now generated at build time,
    avoiding discrepancies.
  - Build scripts are made POSIX-compliant for better portability across
    platforms.
  - New nightly Snap package.
  - New nightly Aarch64 flatpak.
  - Core code ported from appstream-glib to libappstream.
  - Windows installer now uses the latest InnoSetup again.
  - New option -Dwin-debugging=dwarf to generate DWARF symbols on
    Windows (defaults to CodeView symbols).
  - Compilation should work again fine with older librsvg (before the
    Rust port).
  - release-stats.sh script updated to generate text directly pastable
    into our release news.
  - CI:
    * Linux builds ported from unmaintained Kaniko to Buildah.
    * Colored output and .pdb support for builds of dependency using
      CMake.
    * Ability to apply remote patches on dependency builds.
    * New job "branches-check" to warn about dead branches.
    * Our Debian jobs are now built with GCC again (the CLang builds are
      switched to weekly scheduled jobs).
  - Clean out deprecation warnings on GLib and GTK/GDK based on our
    minimum requirement of these dependencies thanks to
    GLIB_VERSION_MIN_REQUIRED() and GLIB_VERSION_MAX_ALLOWED() macros
    (and equivalent GDK macros).
  - We now build Exiv2 ourselves on Windows as a temporary workaround to
    issue #12626.
  - Improved packages binary caching with ORAS for Flatpak.
  - AppImage: we now depend on Debian Trixie.

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 15:04:26 -08:00
Martin Jansa
4e63a846b6
python3-icontract: upgrade to 2.7.1
Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:39:49 -08:00
Martin Jansa
a78e6d2109
python3-checksec-py, python3-pylddwrap, python3-icontract: add recipes
they were sent for meta-security long time ago in 2021:
https://lists.yoctoproject.org/g/yocto/message/54470
but never merged there, now there are lief, docopt, rich, asttokens
already in meta-python and checksec-py depends on lief version, e.g.
976d530867
is needed to fixcompatibility with newer lief currently in meta-python

Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:39:48 -08:00
Gyorgy Sarvari
38ea8a4617
rsyslog: set status for CVE-2015-3243
Details: https://nvd.nist.gov/vuln/detail/CVE-2015-3243

The issue is about file permissions: by default rsyslog creates world-readable
files. In case a log message contains some sensitive information, then that's
exposed to every user on the system.

However the rsyslog.conf file that is shipped with the recipe solves it: it
already sets non-world-readable default permissions on all files, so this
vulnerability is fixed in the default OE recipe.

See also this package in OpenSuse[1], where it is solved the same way.

[1]: https://build.opensuse.org/requests/619439/changes (rsyslog.conf.in)

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:39:48 -08:00
Ankur Tyagi
fe8d5e0cc0
liburing: upgrade 2.9 -> 2.12
Dropped patch which is now merged upstream.

Changelog:
https://github.com/axboe/liburing/releases/tag/liburing-2.10
https://github.com/axboe/liburing/releases/tag/liburing-2.11
https://github.com/axboe/liburing/releases/tag/liburing-2.12

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:39:48 -08:00
Ankur Tyagi
c050aeebcc
libnvme: upgrade 1.12 -> 1.16.1
Use PACKAGECONFIG to support liburing which is now disabled by default.
Dropped patch which is now merged in the upstream.

Changelog:
https://github.com/linux-nvme/libnvme/releases/tag/v1.13
https://github.com/linux-nvme/libnvme/releases/tag/v1.14
https://github.com/linux-nvme/libnvme/releases/tag/v1.15
https://github.com/linux-nvme/libnvme/releases/tag/v1.16
https://github.com/linux-nvme/libnvme/releases/tag/v1.16.1

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:39:48 -08:00
Ankur Tyagi
9ce3999da9
tbb: upgrade 2022.1.0 -> 2022.3.0
Changelog:
https://github.com/uxlfoundation/oneTBB/releases/tag/v2022.2.0
https://github.com/uxlfoundation/oneTBB/releases/tag/v2022.3.0

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:39:48 -08:00
Ankur Tyagi
6b15a5a293
libtracefs: upgrade 1.8.1 -> 1.8.2
New version added trace_sql.bash for tracefs_sql() bash completions.

Changelog:
https://git.kernel.org/pub/scm/libs/libtrace/libtracefs.git/tag/?h=libtracefs-1.8.2

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:39:48 -08:00
Ankur Tyagi
11a10b9661
libbpf: upgrade 1.5.0 -> 1.6.2
Dropped patches which are now merged in the upstream

Changelog:
https://github.com/libbpf/libbpf/releases/tag/v1.5.1
https://github.com/libbpf/libbpf/releases/tag/v1.6.0
https://github.com/libbpf/libbpf/releases/tag/v1.6.1
https://github.com/libbpf/libbpf/releases/tag/v1.6.2

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:39:47 -08:00
Khem Raj
78f49691d7
audiofile: Fix build with clang++
When tests are enabled additional C++ code is compiled and clang does
not like the code.

Cc: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:36:56 -08:00
Gyorgy Sarvari
e16a7d11d1
audiofile: patch CVE-2018-13440 and CVE-2018-17059
Details:
https://nvd.nist.gov/vuln/detail/CVE-2018-13440
https://nvd.nist.gov/vuln/detail/CVE-2018-17059

The patches have been backported from Debian - upstream
has been inactive for almost a decade by now.

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:36:56 -08:00
Gyorgy Sarvari
6c98db2449
audiofile: backport test for CVE-2015-7747
This is a backported patch from opensuse, which contains a testcase
for CVE-2015-7747 (which is already patched in ths recipe, but not
tested explicitly).

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:36:56 -08:00
Gyorgy Sarvari
85ded08df0
audiofile: add ptest support
It's under 15 seconds to execute it.

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:36:55 -08:00
Gyorgy Sarvari
8ef997336a
audiofile: patch CVE-2019-13147 and CVE-2022-24599
Details: https://nvd.nist.gov/vuln/detail/CVE-2019-13147
https://nvd.nist.gov/vuln/detail/CVE-2022-24599

These patches are used by opensuse to mitigate the corresponding vulnerabulities.

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:36:55 -08:00
Hongxu Jia
513e5f1a66
python3-aiohttp: apply compile option -flax-vector-conversions for gcc
The clang does not need option -flax-vector-conversions to
avoid build failure for 32bit arm target

Signed-off-by: Hongxu Jia <hongxu.jia@windriver.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:36:55 -08:00
Hongxu Jia
fdec68e4b1
mariadb: support reproducible builds
In order to support reproducible builds [1]

1. While using bison to generate source code, add option --file-prefix-map [2]
to remove build path prefix in the generated header file.

2. Remove link directories for Yocto to drop source path
from compile link option

[1] https://reproducible-builds.org/
[2] https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=dd878d18519689c7bbcd72de4c9f9e53085a3cbf

Signed-off-by: Hongxu Jia <hongxu.jia@windriver.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:36:55 -08:00
Hongxu Jia
5375b936eb
libhugetlbfs: support reproducible builds
When compressing docs, do not save the original file name and
timestamp by default (gzip -n). Make archives be reproducible
at each build

Signed-off-by: Hongxu Jia <hongxu.jia@windriver.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:36:55 -08:00
Khem Raj
736c792dff
samba: Backport fixes to build with glibc 2.43
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-13 23:02:37 -08:00
Khem Raj
f3cc7f1d7f
cbindgen: Fix getrandom build with musl/riscv32
New upgrade to 0.29.2 broke it.

Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-13 23:02:37 -08:00
Alistair Francis
423eb6775a
libspdm: upgrade 3.7.0 -> 3.8.1
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-13 23:02:36 -08:00
Markus Volk
b9370342b4
fex: add recipe
Fex is a fast usermode x86 and x86-64 emulator for Arm64 Linux
It is used by 'valve' to run windows games on snapdragon

Compilation requires TOOLCHAIN = "clang"

Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-13 23:02:36 -08:00
Anuj Mittal
c1af157c78
remmina: add DEPENDS on curl
remmina has a hard dependency on curl [1]. This doesn't result in an
error on branches with gtk4 because curl gets pulled in via vte ->
gtk4 -> gstreamer-plugins-bad -> curl.

Add an explicit DEPENDS on curl to reflect the dependency.

[1] a8afdd728d/src/CMakeLists.txt (L259)

Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-13 23:02:36 -08:00
Jan Vermaete
7fc0a7ac15
python3-uvicorn: new recipe (0.38.0) from meta-homeassistant
Moved the recipe from meta-homeassistant to meta-openembedded.
@see: https://github.com/meta-homeassistant/meta-homeassistant/pull/177#issuecomment-3510619876

- version bump from 0.35.0 to 0.38.0 (current latest release)
- added ptests
   - patch to skip 5 tests that did not pass the run
   - added tests to PTESTS_SLOW_META_PYTHON

Signed-off-by: Jan Vermaete <jan.vermaete@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-13 19:05:06 -08:00
Gyorgy Sarvari
d4543917cb
hdf5: upgrade 1.14.6 -> 2.0.0
Drop patches that were incorporated in this release.

License-Update: Switched to 3-clause BSD license:
edd7bea821

Release notes:
https://github.com/HDFGroup/hdf5/releases/tag/2.0.0

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-13 18:21:07 -08:00