<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/poky.git/meta/recipes-devtools, branch sumo-next</title>
<subtitle>Mirror of git.yoctoproject.org/poky</subtitle>
<id>https://git.enea.com/cgit/linux/poky.git/atom?h=sumo-next</id>
<link rel='self' href='https://git.enea.com/cgit/linux/poky.git/atom?h=sumo-next'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/'/>
<updated>2019-11-07T19:47:27+00:00</updated>
<entry>
<title>git: set CVE vendor to git-scm</title>
<updated>2019-11-07T19:47:27+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@intel.com</email>
</author>
<published>2019-11-06T15:38:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=8d61ccc45cd2e7cb0e8d02e0a8618eb6973dd51f'/>
<id>urn:sha1:8d61ccc45cd2e7cb0e8d02e0a8618eb6973dd51f</id>
<content type='text'>
There's a Jenkins plugin for Git.

(From OE-Core rev: f2adf5e4d3e9afc6d45665bbe728c69d195a46ef)

(From OE-Core rev: a28d17187dd4c7ac6aa7e5d28f3cfc0c9060bd94)

Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>subversion: set CVE vendor to Apache</title>
<updated>2019-11-07T19:47:27+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@intel.com</email>
</author>
<published>2019-11-06T15:38:01+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=ceb4c456201f09b9eb510cf16622bbe15ad49f51'/>
<id>urn:sha1:ceb4c456201f09b9eb510cf16622bbe15ad49f51</id>
<content type='text'>
There's a Jenkins plugin for Subversion.

(From OE-Core rev: ac115c3b5f1dcb95fb7d39537693fe0dcd330451)

(From OE-Core rev: 457d52c1a86bad074e174e2004c54ac5be1728bd)

Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;

Conflicts:
	meta/recipes-devtools/subversion/subversion_1.12.0.bb
</content>
</entry>
<entry>
<title>rsync: fix CVEs for included zlib</title>
<updated>2019-11-07T19:47:27+00:00</updated>
<author>
<name>Anuj Mittal</name>
<email>anuj.mittal@intel.com</email>
</author>
<published>2019-11-06T15:37:58+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=95d6d83772813f25afe1e48cb38fd47bbaaa0f96'/>
<id>urn:sha1:95d6d83772813f25afe1e48cb38fd47bbaaa0f96</id>
<content type='text'>
rsync includes its own copy of zlib and doesn't recommend linking with
the system version [1].

Import CVE fixes that impact zlib version 1.2.8 [2] that is currently used
by rsync.

[1] https://git.samba.org/rsync.git/?p=rsync.git;a=blob;f=zlib/README.rsync
[2] https://nvd.nist.gov/vuln/search/results?form_type=Advanced&amp;cves=on&amp;cpe_version=cpe%3a%2fa%3agnu%3azlib%3a1.2.8

(From OE-Core rev: a55fbb4cb489853dfb0b4553f6e187c3f3633f48)

(From OE-Core rev: 1ce0a922853b6136a019763b64e58194bb0df00f)

Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;

Conflicts:
	meta/recipes-devtools/rsync/rsync_3.1.3.bb
</content>
</entry>
<entry>
<title>flex: set CVE_PRODUCT to include vendor</title>
<updated>2019-11-07T19:47:27+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@intel.com</email>
</author>
<published>2019-11-06T15:37:52+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=88f18c52705a7e53c8291f290d20c08a12bd0ed7'/>
<id>urn:sha1:88f18c52705a7e53c8291f290d20c08a12bd0ed7</id>
<content type='text'>
There are many projects called Flex and they have CVEs, so also set the vendor
to remove these false positives.

(From OE-Core rev: 0598ccdcb31e16f1d1227197591b10ba441fcfe2)

(From OE-Core rev: 22544792c5b3bd9be0af7c2b7c6dd7e68aa00f83)

Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;

Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>squashfs-tools: set CVE_PRODUCT</title>
<updated>2019-11-07T19:47:27+00:00</updated>
<author>
<name>Chen Qi</name>
<email>Qi.Chen@windriver.com</email>
</author>
<published>2019-11-06T15:37:50+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=7c7b9386384fb0f8c4043328274146b06c528516'/>
<id>urn:sha1:7c7b9386384fb0f8c4043328274146b06c528516</id>
<content type='text'>
(From OE-Core rev: 8f03a33f61a94e9b8d8232283204588ce18b45a0)

(From OE-Core rev: 5ebaa9b41501c64e939b671b37dc616e98d2a803)

Signed-off-by: Chen Qi &lt;Qi.Chen@windriver.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>nasm: add CVE_PRODUCT</title>
<updated>2019-11-07T19:47:27+00:00</updated>
<author>
<name>Chen Qi</name>
<email>Qi.Chen@windriver.com</email>
</author>
<published>2019-11-06T15:37:46+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=2631f10aac9079e579e53dedf84900e511be417e'/>
<id>urn:sha1:2631f10aac9079e579e53dedf84900e511be417e</id>
<content type='text'>
(From OE-Core rev: e61c42ee49029ae8ffec58128dd083031305d9e5)

(From OE-Core rev: 29a898902b52bada1dafdf82a32d1151ed818a06)

Signed-off-by: Chen Qi &lt;Qi.Chen@windriver.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;

Conflicts:
	meta/recipes-devtools/nasm/nasm_2.14.02.bb
</content>
</entry>
<entry>
<title>cve-check-tool: remove</title>
<updated>2019-11-07T19:47:26+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@intel.com</email>
</author>
<published>2019-11-06T15:37:29+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=054d2fb421bc894ea7d96316087b91b579374531'/>
<id>urn:sha1:054d2fb421bc894ea7d96316087b91b579374531</id>
<content type='text'>
(From OE-Core rev: 5388ed6d1378d647a65912dbd537f9ef3cb5760a)

(From OE-Core rev: eb227c8885580fc08dccc005056bb1fdb691ea1d)

Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>run-postinsts: for dpkg/opkg, do not rely on /etc/*-postinsts</title>
<updated>2019-03-24T16:49:54+00:00</updated>
<author>
<name>Stefan Agner</name>
<email>stefan.agner@toradex.com</email>
</author>
<published>2018-05-16T09:13:51+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=b4daa5ba9679d21d0eff7b9ab102c7f26f56e2f9'/>
<id>urn:sha1:b4daa5ba9679d21d0eff7b9ab102c7f26f56e2f9</id>
<content type='text'>
Start opkg/dpkg as soon as the respective package managers status
file is present, no matter whether /etc/$pm-postinsts exists. This
decouples the implicit link between postinsts scripts in /etc and
the package manager: Currently the package manager is only started
if those scripts are present, although the package manager does not
use those scripts at all! Package managers install their own set of
postinst scripts.

The behavior when using rpm packages stays the same.

Note that using the package managers capability to execute postinst
scripts is preferred for good reasons: It makes sure that the
package managers database reflects that the packages have been
completely installed and configured.

This change allows to drop installation of the postinsts scripts
when package management is present. This will be done in a separate
change.

Note: Before commit 5aae19959a44 ("rootfs.py: Change logic to
unistall packages") rootfs.py did not install /etc/$pm-postinsts
when package management is installed! The change caused YOCTO #8235
which lead to the behavior change of run-postinsts in first place.

(From OE-Core rev: 85e498a4671426999610d90c87c354d41cfe8443)

Signed-off-by: Stefan Agner &lt;stefan.agner@toradex.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>libtool-cross: Handle ccache sstate 'infection' issues</title>
<updated>2019-02-25T22:27:46+00:00</updated>
<author>
<name>Richard Purdie</name>
<email>richard.purdie@linuxfoundation.org</email>
</author>
<published>2018-08-10T10:10:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=6ab2cac421149ebe29d3e0feed165a5fd84a6c8d'/>
<id>urn:sha1:6ab2cac421149ebe29d3e0feed165a5fd84a6c8d</id>
<content type='text'>
On a system without ccache, f you:

INHERIT += "ccache"
bitbake libtool-cross
&lt;remove INHERIT&gt;
bitbake apmd

then it fails due to being unable to find ccache. The references to ccache are
coded into libtool-cross but the sstate checksum doesn't reflect this due to the
way the class is coded (output should be the same regardless).

The simplest solution is to remove references to ccache from the libtool script.
The output then works regardless of whether ccache is present or not. The
libtool-cross script is only used in a handful of cases (most of the time its
dynamically generated by autoconf) so any performance issue is minor.

(From OE-Core rev: ed550a49d2114c56e5bc033ecd0e83073d2d4067)

(From OE-Core rev: ee6a2e0ccb11e5f5267bc2e406203c78b0443415)

Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>libtool: Fix patch status tag</title>
<updated>2019-02-25T22:27:46+00:00</updated>
<author>
<name>Richard Purdie</name>
<email>richard.purdie@linuxfoundation.org</email>
</author>
<published>2018-08-01T09:27:45+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=ddd90424203865cda864238a33cc5cd42e65d546'/>
<id>urn:sha1:ddd90424203865cda864238a33cc5cd42e65d546</id>
<content type='text'>
(From OE-Core rev: 28fc470e5e10ee9cce893d037ed5e518bc5612f5)

(From OE-Core rev: c7c4920fc287bdb5f7a0bca7b2ec2ab7a43f58fd)

Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
</feed>
