From f896922914d5b07c2837ba5bcd539ea4f5169498 Mon Sep 17 00:00:00 2001 From: Gyorgy Sarvari Date: Mon, 20 Apr 2026 08:27:39 +0200 Subject: libcoap: upgrade 4.3.5a -> 4.3.5b Contains fix fox CVE-2026-29013 Shortlog: https://github.com/obgm/libcoap/compare/v4.3.5a...v4.3.5b Signed-off-by: Gyorgy Sarvari Signed-off-by: Khem Raj --- .../recipes-devtools/libcoap/libcoap_4.3.5a.bb | 66 ---------------------- .../recipes-devtools/libcoap/libcoap_4.3.5b.bb | 66 ++++++++++++++++++++++ 2 files changed, 66 insertions(+), 66 deletions(-) delete mode 100644 meta-networking/recipes-devtools/libcoap/libcoap_4.3.5a.bb create mode 100644 meta-networking/recipes-devtools/libcoap/libcoap_4.3.5b.bb (limited to 'meta-networking') diff --git a/meta-networking/recipes-devtools/libcoap/libcoap_4.3.5a.bb b/meta-networking/recipes-devtools/libcoap/libcoap_4.3.5a.bb deleted file mode 100644 index 611795e17d..0000000000 --- a/meta-networking/recipes-devtools/libcoap/libcoap_4.3.5a.bb +++ /dev/null @@ -1,66 +0,0 @@ -SUMMARY = "A C implementation of the Constrained Application Protocol" -DESCRIPTION = "libcoap implements a lightweight application-protocol for \ -devices that are constrained their resources such as computing power, \ -RF range, memory, bandwith, or network packet sizes." -HOMEPAGE = "https://libcoap.net/" - -LICENSE = "BSD-2-Clause & BSD-3-Clause" -LIC_FILES_CHKSUM = "file://LICENSE;md5=05d17535846895e23ea4c79b16a9e904" - -SRC_URI = "git://github.com/obgm/libcoap.git;branch=release-4.3.5-patches;protocol=https;tag=v${PV} \ - file://run-ptest \ - " -SRCREV = "e3fdcdcfbd1588754fe9dd4b754ac9397260f0f9" - -# patch releases often use alphabetical suffixes -CVE_VERSION_SUFFIX = "alphabetical" - -inherit autotools manpages pkgconfig ptest - -DEPENDS += "ctags-native" - -PACKAGECONFIG ?= "\ - async openssl tcp \ - ${@bb.utils.contains('PTEST_ENABLED', '1', 'tests', '', d)} \ -" -PACKAGECONFIG[async] = "--enable-async,--disable-async" -PACKAGECONFIG[gnutls] = "--with-gnutls,--without-gnutls,gnutls,,,openssl mbedtls wolfssl" -PACKAGECONFIG[manpages] = "--enable-documentation --enable-doxygen --enable-manpages,--disable-documentation,asciidoc-native doxygen-native graphviz-native" -PACKAGECONFIG[mbedtls] = "--with-mbedtls,--without-mbedtls,mbedtls,,,gnutls openssl wolfssl" -PACKAGECONFIG[openssl] = "--with-openssl,--without-openssl,openssl,,,gnutls mbedtls wolfssl" -PACKAGECONFIG[small-stack] = "--enable-small-stack,--disable-small-stack" -PACKAGECONFIG[tcp] = "--enable-tcp,--disable-tcp" -PACKAGECONFIG[tests] = "--enable-tests,--disable-tests,cunit" -PACKAGECONFIG[wolfssl] = "--with-wolfssl,--without-wolfssl,wolfssl,,,gnutls mbedtls openssl" - -EXTRA_OECONF = "\ - --with-epoll --enable-add-default-names \ - --without-tinydtls --without-submodule-tinydtls \ - ${@bb.utils.contains_any('PACKAGECONFIG', 'gnutls openssl mbedtls', '--enable-dtls', '--disable-dtls', d)} \ -" - -python () { - if d.getVar('PTEST_ENABLED') == "1": - d.setVar('DISABLE_STATIC', '') -} - -export SGML_CATALOG_FILES = "file://${STAGING_ETCDIR_NATIVE}/xml/catalog" - -do_compile:prepend() { - oe_runmake update-map-file -} - -do_install_ptest () { - install -d ${D}${PTEST_PATH} - install -m 0755 ${UNPACKDIR}/run-ptest ${D}${PTEST_PATH}/run-ptest - install -m 0755 ${B}/tests/testdriver ${D}${PTEST_PATH}/testdriver -} - -PACKAGE_BEFORE_PN += "\ - ${PN}-bin \ -" - -FILES:${PN}-bin = "${bindir}" -FILES:${PN}-dev += "${datadir}/${BPN}/examples" - -CVE_STATUS[CVE-2025-50518] = "disputed: happens only when library is used incorrectly" diff --git a/meta-networking/recipes-devtools/libcoap/libcoap_4.3.5b.bb b/meta-networking/recipes-devtools/libcoap/libcoap_4.3.5b.bb new file mode 100644 index 0000000000..e7279013ed --- /dev/null +++ b/meta-networking/recipes-devtools/libcoap/libcoap_4.3.5b.bb @@ -0,0 +1,66 @@ +SUMMARY = "A C implementation of the Constrained Application Protocol" +DESCRIPTION = "libcoap implements a lightweight application-protocol for \ +devices that are constrained their resources such as computing power, \ +RF range, memory, bandwith, or network packet sizes." +HOMEPAGE = "https://libcoap.net/" + +LICENSE = "BSD-2-Clause & BSD-3-Clause" +LIC_FILES_CHKSUM = "file://LICENSE;md5=05d17535846895e23ea4c79b16a9e904" + +SRC_URI = "git://github.com/obgm/libcoap.git;branch=release-4.3.5-patches;protocol=https;tag=v${PV} \ + file://run-ptest \ + " +SRCREV = "851533c3cf63d16984d370ce39d586ecb3694971" + +# patch releases often use alphabetical suffixes +CVE_VERSION_SUFFIX = "alphabetical" + +inherit autotools manpages pkgconfig ptest + +DEPENDS += "ctags-native" + +PACKAGECONFIG ?= "\ + async openssl tcp \ + ${@bb.utils.contains('PTEST_ENABLED', '1', 'tests', '', d)} \ +" +PACKAGECONFIG[async] = "--enable-async,--disable-async" +PACKAGECONFIG[gnutls] = "--with-gnutls,--without-gnutls,gnutls,,,openssl mbedtls wolfssl" +PACKAGECONFIG[manpages] = "--enable-documentation --enable-doxygen --enable-manpages,--disable-documentation,asciidoc-native doxygen-native graphviz-native" +PACKAGECONFIG[mbedtls] = "--with-mbedtls,--without-mbedtls,mbedtls,,,gnutls openssl wolfssl" +PACKAGECONFIG[openssl] = "--with-openssl,--without-openssl,openssl,,,gnutls mbedtls wolfssl" +PACKAGECONFIG[small-stack] = "--enable-small-stack,--disable-small-stack" +PACKAGECONFIG[tcp] = "--enable-tcp,--disable-tcp" +PACKAGECONFIG[tests] = "--enable-tests,--disable-tests,cunit" +PACKAGECONFIG[wolfssl] = "--with-wolfssl,--without-wolfssl,wolfssl,,,gnutls mbedtls openssl" + +EXTRA_OECONF = "\ + --with-epoll --enable-add-default-names \ + --without-tinydtls --without-submodule-tinydtls \ + ${@bb.utils.contains_any('PACKAGECONFIG', 'gnutls openssl mbedtls', '--enable-dtls', '--disable-dtls', d)} \ +" + +python () { + if d.getVar('PTEST_ENABLED') == "1": + d.setVar('DISABLE_STATIC', '') +} + +export SGML_CATALOG_FILES = "file://${STAGING_ETCDIR_NATIVE}/xml/catalog" + +do_compile:prepend() { + oe_runmake update-map-file +} + +do_install_ptest () { + install -d ${D}${PTEST_PATH} + install -m 0755 ${UNPACKDIR}/run-ptest ${D}${PTEST_PATH}/run-ptest + install -m 0755 ${B}/tests/testdriver ${D}${PTEST_PATH}/testdriver +} + +PACKAGE_BEFORE_PN += "\ + ${PN}-bin \ +" + +FILES:${PN}-bin = "${bindir}" +FILES:${PN}-dev += "${datadir}/${BPN}/examples" + +CVE_STATUS[CVE-2025-50518] = "disputed: happens only when library is used incorrectly" -- cgit v1.2.3-54-g00ecf