summaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
* unicode-ucd: Rename the license.txt in DL_DIR to avoid conflictsGyorgy Sarvari2025-11-171-2/+2
| | | | | | | | | | | | | | Since this file is downloaded and upstream does not version it on changes we have to ensure that we store the versions in DL_DIR and also ensure they do not step on each other Fixes stdio: WARNING: unicode-ucd-14.0.0-r0 do_fetch: Checksum mismatch for local file /srv/autobuilder/valkyrie.yocto.io/current_sources/license.txt stdio: WARNING: unicode-ucd-14.0.0-r0 do_fetch: Renaming /srv/autobuilder/valkyrie.yocto.io/current_sources/license.txt to /srv/autobuilder/valkyrie.yocto.io/current_sources/license.txt_bad-checksum_f7830d126f59d83842565d3dddedc79db4ca978ed52aee0ebcc040ea76a85519 Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 830535e5b6699d769b07c838fc5fecf0b5afbf0e) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* unicode-ucd: Updates due to license.txt updatesGyorgy Sarvari2025-11-171-3/+3
| | | | | | | | | | This is downloaded and does not have version, so we have to update it whenever upstream update it. The copyright year is changed this time. Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 6121f2907aff77839bfdff9fdedb7e9bee6b1628) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* consolation: fix SRC_URI protocolGyorgy Sarvari2025-11-171-1/+1
| | | | | | | Switch to https protocol to avoid fetching failures (anonymous fetching with git protocol is not available anymore on this server). Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* netsniff-ng: update SRC_URI branchGyorgy Sarvari2025-11-171-1/+1
| | | | | | master branch was renamed to main Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* ncftp: correct SRC_URIGyorgy Sarvari2025-11-171-2/+2
| | | | | | | The original xz-compressed tarball isn't available at the download location anymore - switch to the gz tarball which is still there. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* usbredir: update SRC_URIGyorgy Sarvari2025-11-171-3/+1
| | | | | | The previous git repositoy was moved to freedesktop's gitlab instance. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* transmission: update SRC_URI branchGyorgy Sarvari2025-11-171-1/+1
| | | | | | Master branch was renamed to main. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* xf86-video-armsoc: fix SRC_URIGyorgy Sarvari2025-11-171-1/+1
| | | | | | | | The previously used repo was moved to freedesktop's gitlab instance. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 955c5ab47ae7c44484474b18a0e9ffba467b47f3)
* cmpi-bindings: update SRC_URI branchGyorgy Sarvari2025-11-171-1/+1
| | | | | | Master branch was renamed to main. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* http-parser: fix SRC_URI branchGyorgy Sarvari2025-11-171-1/+1
| | | | | | | | master was renamed to main Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 8fb37f0f954e234d132468adba2072a70812a818)
* zabbix: update SRC_URIGyorgy Sarvari2025-11-171-1/+1
| | | | | | The downloaded artifact was moved to a new folder. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libssh: fix CVE-2025-8277Rajeshkumar Ramasamy2025-11-114-0/+160
| | | | | | | | | | | | | | | | | | | | A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client side, particularly when using libgcrypt, which impacts application stability and availability. Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-8277 Upstream-patch: https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=266174a6d36687b65cf90174f06af90b8b27c65f https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=8e4d67aa9eda455bfad9ac610e54b7a548d0aa08 https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=1c763e29d138db87665e98983f468d2dd0f286c1 Signed-off-by: Rajeshkumar Ramasamy <rajeshkumar.ramasamy@windriver.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libssh: fix CVE-2025-4878Rajeshkumar Ramasamy2025-11-113-0/+2231
| | | | | | | | | | | | | | | | | A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption. Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-4878 Upstream-patch: https://git.libssh.org/projects/libssh.git/commit/?id=697650caa97eaf7623924c75f9fcfec6dd423cd1 https://git.libssh.org/projects/libssh.git/commit/?id=b35ee876adc92a208d47194772e99f9c71e0bedb Signed-off-by: Rajeshkumar Ramasamy <rajeshkumar.ramasamy@windriver.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* poco: remove mongodb from ptest RDEPENDSGyorgy Sarvari2025-11-101-1/+4
| | | | | | | | | | | | mongodb is in the dynamic-layers section of meta-oe, and not available by default - which makes the layer not YP compatible. To avoid this breakage, remove mongodb from RDEPENDS. To run ptests fully, this is still required to be present however (bbappend, or local.conf...). Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* python3-aiohttp: Fix CVE-2024-23829Soumya Sambu2025-11-072-0/+345
| | | | | | | | | | | | | | | | | | | | | | | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input. Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling. The unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities. This vulnerability exists due to an incomplete fix for CVE-2023-47627. Version 3.9.2 fixes this vulnerability. References: https://nvd.nist.gov/vuln/detail/CVE-2024-23829 https://security-tracker.debian.org/tracker/CVE-2024-23829 Upstream patch: https://github.com/aio-libs/aiohttp/commit/d33bc21414e283c9e6fe7f6caf69e2ed60d66c82 Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* python3-pillow: Fix CVE-2024-28219Soumya Sambu2025-11-072-0/+44
| | | | | | | | | | | | | | | In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy. References: https://nvd.nist.gov/vuln/detail/CVE-2024-28219 https://security-tracker.debian.org/tracker/CVE-2024-28219 Upstream patch: https://github.com/python-pillow/Pillow/commit/2a93aba5cfcf6e241ab4f9392c13e3b74032c061 Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* gimp: patch CVE-2022-32990Gyorgy Sarvari2025-11-074-0/+313
| | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2022-32990 Pick the patches that resolved the issue mentioned in the nvd report. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* gimp: patch CVE-2022-30067Gyorgy Sarvari2025-11-072-1/+67
| | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2022-30067 Pick patch that resolved the issue mentioned in the nvd report. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* inotify-tools: add PASS/FAIL status to run-ptest scriptGyorgy Sarvari2025-11-071-2/+2
| | | | Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* inotify-tools: add ptest support for inotify-toolsNikhil R2025-11-052-1/+30
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Add ptest support for inotify-tools by introducing a run-ptest script. The ptest verifies the correct functioning of inotify event handling and related utilities. Test coverage includes: - File creation, modification, and deletion event monitoring - Event handling and command-line option parsing - Basic consistency and behavior of inotify event queues The ptest completes in under 20 seconds output: root@qemux86-64:~# ptest-runner inotify-tools START: ptest-runner BEGIN: /usr/lib/inotify-tools/ptest If you want to do a malloc trace, set MALLOC_TRACE to a path for logging. event_to_str: test begin event_to_str: test end event_to_str_sep: test begin event_to_str_sep: test end str_to_event: test begin str_to_event: test end str_to_event_sep: test begin str_to_event_sep: test end basic_watch_info: test begin basic_watch_info: test end watch_limit: test begin watch_limit: Warning, this test may take a while watch_limit: test end tst_inotifytools_snprintf: test begin tst_inotifytools_snprintf: test end Out of 362746 tests, 362746 succeeded and 0 failed. All tests passed successfully. DURATION: 16 END: /usr/lib/inotify-tools/ptest STOP: ptest-runner TOTAL: 1 FAIL: 0 Verified that enabling ptest does not modify existing package contents for inotify-tools Signed-off-by: Nikhil R <nikhil.r@bmwtechworks.in> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* hostapd: patch CVE-2022-37660Peter Marko2025-11-055-0/+1211
| | | | | | | | | | | | Pick patches according to oe-core patch for this CVE in wpa-supplicant. Leave out commit which patched only files not present in hostapd. Note that Debian just picked the last commit (actually fixing the CVE) and removed not-applicable parts, but it is probably better to be consistent with oe-core status. Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* mbedtls: upgrade 2.28.9 -> 2.28.10Yi Zhao2025-11-051-2/+2
| | | | | | | | | | | ChangeLog https://github.com/Mbed-TLS/mbedtls/releases/tag/mbedtls-2.28.10 Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit ca08c742230b758f6ebb428901d51169f1e6044a) Signed-off-by: Haixiao Yan <haixiao.yan.cn@windriver.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* frr: add CVE_PRODUCTChen Qi2025-11-031-0/+2
| | | | | | | | | The CVE_PRODUCT is frrouting in NVD database. Signed-off-by: Chen Qi <Qi.Chen@windriver.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 10c7793832ec492da50c89889c5cdd114962b7a5) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* gimp: ignore CVE-2007-3741Gyorgy Sarvari2025-11-021-0/+3
| | | | | | | | | It has been fixed in version 2.2.16: [1] references [2]. [1]: https://bugzilla.redhat.com/show_bug.cgi?id=248053 [2]: https://bugzilla.gnome.org/show_bug.cgi?id=453973 Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* hostapd: patch CVE-2025-24912Peter Marko2025-11-023-0/+151
| | | | | | | | | | | | | | Pick patches as listed in NVD CVE report. Note that Debian lists one of the patches as introducing the vulnerability. This is against what the original report [1] says. Also the commit messages provide hints that the first patch fixes this issue and second is fixing problem with the first patch. [1] https://jvn.jp/en/jp/JVN19358384/ Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libnet-dns-perl: fix ptestsGyorgy Sarvari2025-11-022-1/+16
| | | | | | Enable network connection to get a test unstuck that was trying to access the network. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* python3-aspectlib: fix ptestsGyorgy Sarvari2025-11-022-0/+55
| | | | | | Backport patch that adapts failing tests. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libxml++: fix ptestsGyorgy Sarvari2025-11-023-84/+11
| | | | | | | | | The previous version installed the examples as ptests, not the actual tests. This change compiles the tests on the build machine, install them, and execute them on the target machine. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* opensc: fix CVE-2023-5992Zhang Peng2025-11-0211-0/+1254
| | | | | | | | | | | | | | | | | | CVE-2023-5992: A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data. Reference: [https://nvd.nist.gov/vuln/detail/CVE-2023-5992] [https://github.com/OpenSC/OpenSC/wiki/CVE-2023-5992] Upstream patches: [https://github.com/OpenSC/OpenSC/pull/2948] [https://github.com/OpenSC/OpenSC/pull/3016] Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* ostree: fix ptestsGyorgy Sarvari2025-11-023-1/+116
| | | | | | | | | | | | 1. Fix tests that output colored text but try to verify uncolored text - filter the output through "tee" to remove coloring. 2. Add missing dependency 3. Fix a test that fails when C.utf-8 locale is not available on the machine (patch submitted upstream) 4. Enable network connection by setting a nameserver in resolv.conf While execution is possible, it still requires both ostree and busybox to be compiled statically. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* poco: fix ptestsGyorgy Sarvari2025-11-023-8/+53
| | | | | | | | | 1. Add a patch to fix an incorrect and failing test 2. Add missing dependencies and test files 3. Enable network in run-ptest script by adding a nameserver 4. Start mongodb from run-ptest script, if it wouldn't be running. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* mongodb: add tzdata to runtime dependenciesGyorgy Sarvari2025-11-021-0/+1
| | | | | | | | | Though tzdata is present in almost all images, some of them are lacking it: most notably minimal ptest images. mongodb relies on tzdata, otherwise it doesn't even start up. To ensure that mongodb can be started up successfully, explicitly add tzdata to its dependencies. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libencode-perl: fix ptestsGyorgy Sarvari2025-10-291-0/+2
| | | | | | Add missing dependencies. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libmime-types-perl: fix ptestsGyorgy Sarvari2025-10-291-1/+1
| | | | | | Add missing dependency Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libfile-slurper-perl: fix ptestsGyorgy Sarvari2025-10-291-0/+5
| | | | | | Install missing test file. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libdbd-sqlite-perl: fix ptestsGyorgy Sarvari2025-10-291-0/+3
| | | | | | Install missing files. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libcrypt-openssl-guess-perl: fix ptestsGyorgy Sarvari2025-10-291-0/+1
| | | | | | Add missing dependency. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libconfig-autoconf-perl: fix ptestsGyorgy Sarvari2025-10-292-2/+56
| | | | | | | | | | | | | | | Add missing dependencies. Also, fixing the tests have surfaced an actual bug: the module expects unversioned perl library to be present on the system (or at least present in Perl's $Config{libperl}), however the OE Perl build has a versioned library, which causes final linking to fail. A patch to correct this is part of this change, and it has been submitted upstream also. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libauthen-sasl-perl: fix ptestGyorgy Sarvari2025-10-291-0/+4
| | | | | | Add missing dependencies. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libopenmpt: fix ptestsGyorgy Sarvari2025-10-291-0/+1
| | | | | | Install missing test file. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* fuse3: fix ptestsGyorgy Sarvari2025-10-292-0/+4
| | | | | | | Add run-ptest to SRC_URI, and add missing kernel module that's required for the tests. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* sshfs-fuse: fix ptestsGyorgy Sarvari2025-10-292-0/+11
| | | | | | | Disable host key checking during tests, so the test can be executed without human intervention. Also add missing dependency. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* net-snmp: fix ptestsGyorgy Sarvari2025-10-291-1/+5
| | | | | | Add missing dependencies. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* openl2tp: Fix ptestsKhem Raj2025-10-292-4/+4
| | | | | | | | | | | | | | - Detect active network interface to use, instead of asking user, this needs to run in automation - Find the location of ppp_null.so with find instead of rpm, rpm is a distro choice it can be assumed to be always there. - Add missing runtime deps for ptests - Kill openl2tpd started by run-ptest script before exiting, otherwise ptest runner hangs forever. Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit d30427f475f273ab8c5dd83b2c076bb4fc8a9a82) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* frr: fix CVE-2024-31949Zhang Peng2025-10-292-0/+154
| | | | | | | | | | | | | | | | CVE-2024-31949: In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing. Reference: [https://nvd.nist.gov/vuln/detail/CVE-2024-31949] [https://salsa.debian.org/lts-team/packages/frr/-/blob/debian/7.5.1-1.1+deb10u4/debian/patches/CVE-2024-31949.patch?ref_type=tags] Upstream patches: [https://github.com/FRRouting/frr/pull/15640/commits/30a332dad86fafd2b0b6c61d23de59ed969a219b] Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* freediameter: fix run-ptest reportingGyorgy Sarvari2025-10-271-1/+1
| | | | | | Add PASS/FAIL printout at the end of the execution. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* python3-scapy: fix ptestsGyorgy Sarvari2025-10-272-0/+20
| | | | | | | | 1. Enable network access during tests by setting a nameserver 2. Add missing tshark dependency 3. Install missing test files Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libtest-harness-perl: fix ptestsGyorgy Sarvari2025-10-271-0/+12
| | | | | | Add missing dependencies. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libunix-statgrab: fix ptestsGyorgy Sarvari2025-10-271-0/+4
| | | | | | Add missing argument to perl in run-ptest script - one of the tests require it. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libxml-libxml-perl: fix ptestsGyorgy Sarvari2025-10-271-0/+2
| | | | | | Add missing dependencies. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>