- Sep 01, 2021
-
-
Peter Korsgaard authored
Signed-off-by:
Peter Korsgaard <peter@korsgaard.com>
-
- Aug 31, 2021
-
-
Fabrice Fontaine authored
Find libxcryt through pkg-config to avoid the following build failure: /home/buildroot/autobuild/run/instance-3/output-1/host/opt/ext-toolchain/bin/../lib/gcc/riscv64-buildroot-linux-musl/10.2.0/../../../../riscv64-buildroot-linux-musl/bin/ld: .libs/passverify.o: in function `.L30': passverify.c:(.text+0x368): undefined reference to `crypt_checksalt' Fixes: - http://autobuild.buildroot.org/results/20b14e222b35c2d1269960075832b784ba81aa1a Signed-off-by:
Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by:
Yann E. MORIN <yann.morin.1998@free.fr>
-
Bernd Kuhls authored
Release notes: https://sourceforge.net/p/fetchmail/mailman/message/37333073/ "It contains the security fix for CVE-2021-36386 of 6.4.20, and fixes a regression/a bug that causes log message truncation/run-together prominently visible with --logfile that was introduced into 6.4.20." Updated note for CVE-2021-36386: https://sourceforge.net/p/fetchmail/mailman/message/37333078/ Signed-off-by:
Bernd Kuhls <bernd.kuhls@t-online.de> Signed-off-by:
Peter Korsgaard <peter@korsgaard.com>
-
Bernd Kuhls authored
Quoting https://www.php.net/ "This is a security fix release." Changelog: https://www.php.net/ChangeLog-8.php#8.0.10 CVE-ID were not mentioned in any of the fixed bugs. Signed-off-by:
Bernd Kuhls <bernd.kuhls@t-online.de> Signed-off-by:
Peter Korsgaard <peter@korsgaard.com>
-
Bernd Kuhls authored
Release notes of this bugfix release: https://www.samba.org/samba/history/samba-4.14.7.html Signed-off-by:
Bernd Kuhls <bernd.kuhls@t-online.de> Signed-off-by:
Peter Korsgaard <peter@korsgaard.com>
-
- Aug 29, 2021
-
-
Fabrice Fontaine authored
cpe:2.3:a:c-ares_project:c-ares is a valid CPE identifier for this package: https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Ac-ares_project%3Ac-ares Signed-off-by:
Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by:
Yann E. MORIN <yann.morin.1998@free.fr>
-
Fabrice Fontaine authored
Fix the following build failure with nodejs raised since bump to version 12.22.5 in commit 7038b029: ../src/cares_wrap.cc:42:11: fatal error: ares_nameser.h: No such file or directory 42 | # include <ares_nameser.h> | ^~~~~~~~~~~~~~~~ Fixes: - http://autobuild.buildroot.org/results/a0f867d5e765fc1aa052de5e53ed350b3b20743f Signed-off-by:
Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by:
Yann E. MORIN <yann.morin.1998@free.fr>
-
Fabrice Fontaine authored
- NodeJS passes NULL for addr and 0 for addrlen to ares_parse_ptr_reply() on systems where malloc(0) returns NULL. This would cause a crash. - If ares_getaddrinfo() was terminated by an ares_destroy(), it would cause a crash - Crash in sortaddrinfo() if the list size equals 0 due to an unexpected DNS response - Expand number of escaped characters in DNS replies as per RFC1035 5.1 to prevent spoofing follow-up - Perform validation on hostnames to prevent possible XSS due to applications not performing valiation themselves https://c-ares.haxx.se/changelog.html#1_17_2 Signed-off-by:
Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by:
Yann E. MORIN <yann.morin.1998@free.fr>
-
- Aug 28, 2021
-
-
Yann E. MORIN authored
Since commit 39d334fa (package/pkg-qmake: add <pkg>_SYNC_QT_HEADERS support), the qmake-package infra recognises said variable but the manual has the wrong variable name, which is missing the "_QT" part. We fix that by amending the manual to document the proper variable name. Signed-off-by:
Yann E. MORIN <yann.morin.1998@free.fr>
-
Fabrice Fontaine authored
Fix build of xen with 64 bites time_t: /tmp/instance-0/output-1/build/xen-4.14.2/tools/qemu-xen/hw/input/virtio-input-host.c: In function 'virtio_input_host_handle_status': /tmp/instance-0/output-1/build/xen-4.14.2/tools/qemu-xen/hw/input/virtio-input-host.c:198:28: error: 'struct input_event' has no member named 'time' 198 | if (gettimeofday(&evdev.time, NULL)) { | ^ Fixes: - http://autobuild.buildroot.org/results/136ce42f44bf48d3db4eda7b1548bf7ac1b97d51 Signed-off-by:
Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
Fabrice Fontaine authored
Commit c4e1a075 forgot to add --enable-nls to patch resulting in the following build failure: Unknown option "--enable-nls". Fixes: - http://autobuild.buildroot.org/results/6ab2555b419355f01310f230fe612f2a3699bbfd Signed-off-by:
Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
Romain Naour authored
This version bump is needed to pass the ATF test with hardening option enabled (-fstack-protector-strong) With the version v2.2, ATF fail due to undefined references: ./build/juno/release/bl2u/arm_tzc400.o: In function `arm_tzc400_setup': arm_tzc400.c:(.text.arm_tzc400_setup+0x10): undefined reference to `__stack_chk_guard' arm_tzc400.c:(.text.arm_tzc400_setup+0x18): undefined reference to `__stack_chk_guard' arm_tzc400.c:(.text.arm_tzc400_setup+0xb8): undefined reference to `__stack_chk_guard' arm_tzc400.c:(.text.arm_tzc400_setup+0xcc): undefined reference to `__stack_chk_fail' Since commit ccac9a5b, Buildroot no longer forces ENABLE_STACK_PROTECTOR. However, we rely on the ATF build system to handle it correctly, and this wasn't the case in v2.2. Fixes: https://gitlab.com/buildroot.org/buildroot/-/jobs/1524842591 Signed-off-by:
Romain Naour <romain.naour@gmail.com> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
Conrad Ratschan authored
When BR2_REPRODUCIBLE is set and host-coreutils needs to be built, the fakedate script installed to 'host/bin/date' will be overwritten by host-coreutils. Besides, we do not need our host-coreutils for 'date' at all; we really rely on the host system to provide it. Unconditionally disable installing the 'date' binary in host-coreutils. Note that we explicitly request only ln and realpath to be installed, but the coreutils buildsystem does not strictly obey to that, as was already noticed in 885e6fdb (package/coreutils: introduce a host variant), which added that comment above HOST_COREUTILS_CONF_OPTS: # Explicitly install ln and realpath, which we *are* insterested in. # A lot of other programs still get installed, however, but disabling # them does not gain much at build time, and is a loooong list that is # difficult to maintain... So, we also update that comment to explain why we still anyway disable installation of 'date'. Signed-off-by:
Conrad Ratschan <conrad.ratschan@collins.com> [yann.morin.1998@free.fr: - unconditionally disable installing date - extend comment and commit log to explain why we need --enable-no-install-program=date despite the existing --enable-install-program=ln,realpath ] Signed-off-by:
Yann E. MORIN <yann.morin.1998@free.fr>
-
- Aug 27, 2021
-
-
Fabrice Fontaine authored
Commit 42a3fee3 forgot to add comment on headers 3.17+ Signed-off-by:
Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by:
Yann E. MORIN <yann.morin.1998@free.fr>
-
Baruch Siach authored
Since version 2.1.3 ubihealthd can be enabled without of ubifs-utils. This also fixes usability of enabling BR2_PACKAGE_MTD_UBIHEALTHD. BR2_PACKAGE_MTD_UBIFS_UTILS is a blind option. The only way to enable it is to enable BR2_PACKAGE_MTD_MKFSUBIFS that selects it. ubihealthd dependency on BR2_PACKAGE_MTD_UBIFS_UTILS makes enabling it unintuitive. Cc: Markus Mayer <mmayer@broadcom.com> Cc: Matt Weber <matthew.weber@collins.com> Signed-off-by:
Baruch Siach <baruch@tkos.co.il> Signed-off-by:
Yann E. MORIN <yann.morin.1998@free.fr>
-
Fabrice Fontaine authored
Build fails since bump to version 3.1.7 in commit 011f31ee because config.h.in is older than aclocal.m4: make[1]: Entering directory '/tmp/instance-4/output-1/build/ipmiutil-3.1.7' (CDPATH="${ZSH_VERSION+.}:" && cd . && autoheader) /bin/bash: autoheader: command not found Fixes: - http://autobuild.buildroot.org/results/2005af881726473f2cda176e90c1e41e4baea67c Signed-off-by:
Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by:
Yann E. MORIN <yann.morin.1998@free.fr>
-
Fabrice Fontaine authored
Fix CVE-2021-22931, CVE-2021-22940 and CVE-2021-22939: https://nodejs.org/en/blog/vulnerability/aug-2021-security-releases Signed-off-by:
Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by:
Yann E. MORIN <yann.morin.1998@free.fr>
-
Edgar Bonet authored
On the Aria and the Arietta AT91Bootstrap builds, the file name of the bootloader embeds its version number, and the genimage configuration needs this filename in order to build the boot filesystem image. Commit 0614f435 bumped the AT91Bootstrap version of all acmesystems' boards but failed to update genimage.cfg accordingly, which broke the builds. The Acqua board is not affected by this issue. Update the affected genimage.cfg with the correct filenames. Fixes: https://gitlab.com/buildroot.org/buildroot/-/jobs/1515521690 https://gitlab.com/buildroot.org/buildroot/-/jobs/1515521691 https://gitlab.com/buildroot.org/buildroot/-/jobs/1515521692 https://gitlab.com/buildroot.org/buildroot/-/jobs/1515521694 Signed-off-by:
Edgar Bonet <bonet@grenoble.cnrs.fr> Signed-off-by:
Yann E. MORIN <yann.morin.1998@free.fr>
-
- Aug 26, 2021
-
-
Michael Nosthoff authored
the nabble.com link is dead and lore has a good search. So use lore for the search form. Signed-off-by:
Michael Nosthoff <buildroot@heine.tech> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
Baruch Siach authored
ubihealthd requires getrandom(2) that was introduced in kernel version 3.17. ubihealthd does not build when getrandom(2) is not detected, so the following installation step fails. Technically the dependency should also be on glibc version 2.25+. But we have no way to depend on glibc versions of external toolchains. Toolchain built with kernel headers older than 3.17 can build ubihealthd, but it will fail at run-time. So this is a pretty close approximation of the actual dependency. Fixes: http://autobuild.buildroot.net/results/2d42b0a626367e4051d0e2aadcce39e974fe09d4/ http://autobuild.buildroot.net/results/a2b6dbf707275e3f8262479c0650cfc7cb9abc8d/ Cc: Matt Weber <matthew.weber@collins.com> Signed-off-by:
Baruch Siach <baruch@tkos.co.il> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
Fabrice Fontaine authored
Fix the following build failure without /usr/bin/msgfmt raised since the addition of ushare in commit 74097fd6: make[3]: Entering directory `/home/buildroot/autobuild/run/instance-3/output-1/build/ushare-2.1/po' /usr/bin/msgfmt -c --statistics -o fr.gmo fr.po make[3]: /usr/bin/msgfmt: Command not found To fix this build failure, set GMSGFMT to $(HOST_DIR)/bin/msgfmt and don't build po files if NLS is disabled Fixes: - http://autobuild.buildroot.org/results/9f6b5b8f38386135bacd2d8f6e97c1fea77bbe69 Signed-off-by:
Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
Fabrice Fontaine authored
Fixes: - Fix potential core dumped for strrchr - Fix null pointer crash in cJSON_CreateXxArray - Fix several null pointer problems on allocation failure - Fix a possible dereference of null pointer https://github.com/DaveGamble/cJSON/releases/tag/v1.7.15 Signed-off-by:
Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
This breaks some existing external toolchains. Since we're very close to a release, don't try to fix it, but instead simply revert. This reverts commit 6f911a17. Fixes: http://autobuild.buildroot.net/results/afe/afe44f4b6a3c53e5864cfb10b04529011e72cf5c/ Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
- Aug 25, 2021
-
-
Romain Naour authored
gcc 10.x is now used by default but the kernel 4.18.10 used by pc_x86_64_{efi,bios}_defconfig doesn't build with it. Bump the kernel to 4.19.204 release that contains a lot of fixes for newer gcc. Fixes: https://gitlab.com/kubu93/buildroot/-/jobs/1525741062 https://gitlab.com/kubu93/buildroot/-/jobs/1525741060 Signed-off-by:
Romain Naour <romain.naour@gmail.com> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
Romain Naour authored
The beaglev kernel is based on the 5.13 branch, update the expected linux-headers version to 5.13. This has been wrong ever since the bump of the kernel version in commit 9a1bd7cc1ce512672a5d76baa86c449e36137052: the headers were bumped to 5.12 instead of 5.13. Fixes: https://gitlab.com/kubu93/buildroot/-/jobs/1525740895 Signed-off-by:
Romain Naour <romain.naour@gmail.com> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
Gleb Mazovetskiy authored
Previously, alsa-plugins would not work if alsa-utils was installed after it. This happened because: 1. alsa-plugins copies some files $(TARGET_DIR)/usr/share/alsa/alsa.conf.d 2. alsa-utils removes these files during installation ( rm -rf $(TARGET_DIR)/usr/share/alsa/;) The `rm -rf` command was originally added as part of the fix for https://bugs.buildroot.org/show_bug.cgi?id=1573 11 years ago. The intention might have been to allow for unconfiguring some options and then rebuilding alsa-utils. However, this is a scenario that does not work anyway. The simplest fix for the `alsa-plugins` compatibility issue appears to be to remove the `rm -rf` command. Signed-off-by:
Gleb Mazovetskiy <glex.spb@gmail.com> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
Michael Fischer authored
Signed-off-by:
Michael Fischer <mf@go-sys.de> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
Thomas Petazzoni authored
Maxime has not been contributing to Buildroot for several years, so it doesn't make sense to keep him in the DEVELOPERS file and make us think that those packages are being maintained and to Cc: him on patches affecting those packages. Signed-off-by:
Thomas Petazzoni <thomas.petazzoni@bootlin.com> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
Jonah Petri authored
Some 3rd party vendor toolchains have multiple files which match these glob patterns. In this case, the shell script failed. Switching to use find and xargs solves the issue. Signed-off-by:
Jonah Petri <jonah@petri.us> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
Fabrice Fontaine authored
Fix CVE-2021-36976: libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block). https://github.com/libarchive/libarchive/releases/tag/v3.5.2 Signed-off-by:
Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
Fabrice Fontaine authored
cpe:2.3:a:linphone:belle-sip is a valid CPE identifier for this package: https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Alinphone%3Abelle-sip Signed-off-by:
Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
Romain Naour authored
TestGst1Python test segfault since the libffi bump to 3.4.2. Apply the same fix from Yocto [1] disabling static exec trampolines. Fixes: https://gitlab.com/kubu93/buildroot/-/jobs/1522848331 [1] http://git.yoctoproject.org/cgit/cgit.cgi/poky/commit/?id=dadfef3950fae4e93ce4c13ab91a2a7f41b3702e Signed-off-by:
Romain Naour <romain.naour@gmail.com> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
Fabrice Fontaine authored
Add libxcrypt optional dependency and fix the following build failure with libxcrypt and uclibc-ng raised since the addition of libxcrypt in commit 464bbe26: /home/buildroot/autobuild/instance-1/output-1/host/opt/ext-toolchain/bin/../lib/gcc/arm-buildroot-linux-uclibcgnueabihf/9.3.0/../../../../arm-buildroot-linux-uclibcgnueabihf/bin/ld: unix_chkpwd-passverify.o: in function `verify_pwd_hash': passverify.c:(.text+0xab4): undefined reference to `crypt_checksalt' Fixes: - http://autobuild.buildroot.org/results/65d68b7c9c7de1c7cb0f941ff9982f93a49a56f8 Signed-off-by:
Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
Romain Naour authored
resync the version with glibc package. Remove upstream patches. Rebase remaining patches for glibc 2.33. Signed-off-by:
Romain Naour <romain.naour@gmail.com> Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
-
- Aug 24, 2021
-
-
Romain Naour authored
The tests.package.test_docker_compose.TestDockerCompose is broken since the python-idna version bump to 3.0 because python-requests needs python-idna < 3.0. # docker-compose up -d Traceback (most recent call last): File "/usr/lib/python3.9/site-packages/pkg_resources/__init__.py", line 583, in _build_master File "/usr/lib/python3.9/site-packages/pkg_resources/__init__.py", line 900, in require File "/usr/lib/python3.9/site-packages/pkg_resources/__init__.py", line 791, in resolve pkg_resources.ContextualVersionConflict: (idna 3.2 (/usr/lib/python3.9/site-packages), Requirement.parse('idna<3,>=2.5'), {'requests'}) During handling of the above exception, another exception occurred: Traceback (most recent call last): File "/usr/bin/docker-compose", line 6, in <module> from pkg_resources import load_entry_point File "/usr/lib/python3.9/site-packages/pkg_resources/__init__.py", line 3252, in <module> File "/usr/lib/python3.9/site-packages/pkg_resources/__init__.py", line 3235, in _call_aside File "/usr/lib/python3.9/site-packages/pkg_resources/__init__.py", line 3264, in _initialize_master_working_set File "/usr/lib/python3.9/site-packages/pkg_resources/__init__.py", line 585, in _build_master File "/usr/lib/python3.9/site-packages/pkg_resources/__init__.py", line 598, in _build_from_requirements File "/usr/lib/python3.9/site-packages/pkg_resources/__init__.py", line 786, in resolve pkg_resources.DistributionNotFound: The 'idna<3,>=2.5' distribution was not found and is required by requests Fixes: https://gitlab.com/kubu93/buildroot/-/jobs/1522848327 Signed-off-by:
Romain Naour <romain.naour@gmail.com> Signed-off-by:
Thomas Petazzoni <thomas.petazzoni@bootlin.com>
-
Romain Naour authored
gcc 10.x is now used by default but the kernel 4.19 used by test_docker_compose doesn't build with it. Bump the kernel to 4.19.204 release that contains a lot of fixes for newer gcc. Signed-off-by:
Romain Naour <romain.naour@gmail.com> Signed-off-by:
Thomas Petazzoni <thomas.petazzoni@bootlin.com>
-
Romain Naour authored
check_network() must check the error code of the command used to check the network configuration with the value passed as argument "exitCode". But this argument is ignored since this commit [1]. Revert the last change of check_network(). Fixes: https://gitlab.com/kubu93/buildroot/-/jobs/1522848308 https://gitlab.com/kubu93/buildroot/-/jobs/1522848306 [1] afc1ed4d Signed-off-by:
Romain Naour <romain.naour@gmail.com> Cc: Thomas Petazzoni <thomas.petazzoni@bootlin.com> Signed-off-by:
Thomas Petazzoni <thomas.petazzoni@bootlin.com>
-
Giulio Benetti authored
Gcc bug 99140 has been fixed on gcc 8.x but reappeared on gcc 9.x while it's been fixed on gcc 10.x+. So let's update BR2_TOOLCHAIN_HAS_GCC_BUG_99140 accordingly. Fixes: http://autobuild.buildroot.net/results/c55/c55f50a8d657695f0d5492c32efa666254cd7f99/ Signed-off-by:
Giulio Benetti <giulio.benetti@benettiengineering.com> Signed-off-by:
Thomas Petazzoni <thomas.petazzoni@bootlin.com>
-
Yann E. MORIN authored
This was for the next branch, not master... This reverts commit 6fb0dbe4. Signed-off-by:
Yann E. MORIN <yann.morin.1998@free.fr>
-
Upstream commit [1] introduced an invocation of objcopy to generat loader.txt. However, objcopy, if not provided with an output file, will overwrite the input file. This is usually harmless because it will be identical, but the timestamp is updated. This may cause 'empty' to be newer than 'loader.txt', which causes 'loader.txt' and its dependencies to be rebuilt during 'make install' We provide a different set of parameters during 'make install'. In particular, we no longer pass in HOST_CONFIGURE_OPTS, so we no longer set LDFLAGS. Thus, there is no -Wl,rpath option that is passed in, which causes the resulting binaries to have an incorrect RPATH. Fix this by adding /dev/null as the output file in the objcopy invocation. Patch was sent upstream, but there's no mailing list, just a single person. Fixes: http://autobuild.buildroot.net/results/600/600aff5b839b48db80751cace5fa9670b7a3d698 (hopefully) [1] https://git.kernel.org/pub/scm/libs/libcap/libcap.git/commit/?id=efd293947f940180eedd8d0915b124f4aedccc08 Signed-off-by:
Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be> Signed-off-by:
Yann E. MORIN <yann.morin.1998@free.fr>
-