mirror of
https://git.yoctoproject.org/poky
synced 2026-09-16 18:49:34 +02:00
Compare commits
184 Commits
yocto-5.0.
...
yocto-5.0.
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
64e69ed237 | ||
|
|
b70aeb3af5 | ||
|
|
23ecb8d810 | ||
|
|
4f226dfe73 | ||
|
|
779318a316 | ||
|
|
ac4a16fccc | ||
|
|
2145f1ba3e | ||
|
|
7856e112fe | ||
|
|
751f10349c | ||
|
|
569c16668e | ||
|
|
95f043e03b | ||
|
|
33b3f081f0 | ||
|
|
ced8ad236d | ||
|
|
63b78c24e1 | ||
|
|
b39088793e | ||
|
|
1030d3c2c7 | ||
|
|
24a462fdc0 | ||
|
|
cb79d2f107 | ||
|
|
f02ff451cd | ||
|
|
b28d0cf59a | ||
|
|
001428f528 | ||
|
|
69957c8adf | ||
|
|
23aeeb9e5d | ||
|
|
0656d53a6b | ||
|
|
59e4468e8f | ||
|
|
b18a694103 | ||
|
|
af36ad9afb | ||
|
|
7909382fca | ||
|
|
1d8a4f3ba2 | ||
|
|
bd1db1a566 | ||
|
|
39d4d55423 | ||
|
|
6885998553 | ||
|
|
74cc040335 | ||
|
|
c38773f228 | ||
|
|
604781030b | ||
|
|
44913c2842 | ||
|
|
12c7c6841f | ||
|
|
2b8eb621c1 | ||
|
|
2c527003ab | ||
|
|
12aa2868f6 | ||
|
|
8ef6ff8a53 | ||
|
|
067f3e473d | ||
|
|
8859330d24 | ||
|
|
97081e82e0 | ||
|
|
65887ca9e7 | ||
|
|
2003935a78 | ||
|
|
524a237691 | ||
|
|
6c3ab4e59e | ||
|
|
12e69785c0 | ||
|
|
f7aca85b42 | ||
|
|
745aacf2e3 | ||
|
|
e0baff51a3 | ||
|
|
1ba3cd7c88 | ||
|
|
3cd1dbb582 | ||
|
|
5a83b18b4d | ||
|
|
8ce6b5c8c7 | ||
|
|
c72ed1013c | ||
|
|
077627338a | ||
|
|
e1223f066d | ||
|
|
c5366e63b1 | ||
|
|
f1d5865685 | ||
|
|
8e0b74b1d8 | ||
|
|
676f7e731a | ||
|
|
0623e8b986 | ||
|
|
0939d72e83 | ||
|
|
1c0ffd724f | ||
|
|
7a6a4aa3b1 | ||
|
|
9b68c3fb71 | ||
|
|
26302ae479 | ||
|
|
860d4b1c86 | ||
|
|
cb5f298597 | ||
|
|
5cd9ed667f | ||
|
|
e84e827496 | ||
|
|
a59438acc8 | ||
|
|
337c659854 | ||
|
|
32067f2db1 | ||
|
|
5de2230907 | ||
|
|
173c1c523d | ||
|
|
d8015a395d | ||
|
|
9011c7faaa | ||
|
|
f511852928 | ||
|
|
e640c1faf0 | ||
|
|
6dacef99fb | ||
|
|
11fbd90126 | ||
|
|
6ae62b54aa | ||
|
|
97deef61ea | ||
|
|
f5a87ca676 | ||
|
|
bb040b7305 | ||
|
|
d0d68df4c3 | ||
|
|
75764cf5d7 | ||
|
|
ffc5320e51 | ||
|
|
9747726708 | ||
|
|
44fd9295ca | ||
|
|
38a2761a99 | ||
|
|
4ae1f9aec6 | ||
|
|
6fa69de2bc | ||
|
|
335776489f | ||
|
|
9184e90773 | ||
|
|
8b7ff1d843 | ||
|
|
b9993675ea | ||
|
|
012eac4b8f | ||
|
|
cb5e6f65a5 | ||
|
|
b2a7dabed0 | ||
|
|
6f56dca72f | ||
|
|
a116ddae05 | ||
|
|
5c16db6e87 | ||
|
|
82cf81a3e9 | ||
|
|
51d4fee207 | ||
|
|
e5c6f86964 | ||
|
|
600aca66db | ||
|
|
9852ff8b42 | ||
|
|
fe1d12b1a4 | ||
|
|
f8b89ba589 | ||
|
|
83fd2a9ab4 | ||
|
|
9916b7471e | ||
|
|
7d7d132471 | ||
|
|
e895f7c264 | ||
|
|
211a713181 | ||
|
|
4f83b7b498 | ||
|
|
bdb543e713 | ||
|
|
91ed772bf3 | ||
|
|
82f8ecb35d | ||
|
|
247c484238 | ||
|
|
3b4d998c7a | ||
|
|
a184998193 | ||
|
|
3d80d019e6 | ||
|
|
8a839ef416 | ||
|
|
c5f228145b | ||
|
|
9c72283ec8 | ||
|
|
fca50b3652 | ||
|
|
865d0fd2d6 | ||
|
|
9a906f991a | ||
|
|
46891dba64 | ||
|
|
21137ce7bb | ||
|
|
515c8e27b7 | ||
|
|
0c2fa146c5 | ||
|
|
96f1bb2af7 | ||
|
|
ca405952dc | ||
|
|
f55e6c80f1 | ||
|
|
cd6939b8ba | ||
|
|
082c373810 | ||
|
|
72b30efa58 | ||
|
|
5f7a875f6d | ||
|
|
74551a4b4b | ||
|
|
a8a3e88a5e | ||
|
|
6ccffb86e8 | ||
|
|
c574139f59 | ||
|
|
95ac28ddfa | ||
|
|
7aad94e82e | ||
|
|
ae2f076ef7 | ||
|
|
8cb3e690c5 | ||
|
|
8f694f00c4 | ||
|
|
de00d925c6 | ||
|
|
db642a22a1 | ||
|
|
dbf61c2308 | ||
|
|
502e6c40a5 | ||
|
|
94181a64fd | ||
|
|
ca2b19114c | ||
|
|
bac60a09b6 | ||
|
|
ba66043d77 | ||
|
|
623f85f957 | ||
|
|
d29b27fb31 | ||
|
|
4e6df49262 | ||
|
|
c223541984 | ||
|
|
37b718ecb9 | ||
|
|
b8085938de | ||
|
|
75cbb0daa1 | ||
|
|
c70d4a799a | ||
|
|
af5ab14071 | ||
|
|
e146cbbc73 | ||
|
|
cbaaf0dcf7 | ||
|
|
84db80f823 | ||
|
|
6dc01c1e09 | ||
|
|
be96cd2ddb | ||
|
|
fbbf0d711c | ||
|
|
be05e58dcf | ||
|
|
9ba4cbc08e | ||
|
|
84ecefc9f2 | ||
|
|
6b7474f7ca | ||
|
|
2f9c3b01d1 | ||
|
|
4d3cdfe6ce | ||
|
|
26efce957c | ||
|
|
3899ca2590 | ||
|
|
a448bff87a |
@@ -24,7 +24,7 @@ for full details on how to submit changes.
|
||||
As a quick guide, patches should be sent to bitbake-devel@lists.openembedded.org
|
||||
The git command to do that would be:
|
||||
|
||||
git send-email -M -1 --to bitbake-devel@lists.openembedded.org
|
||||
git send-email -M -1 --to bitbake-devel@lists.openembedded.org --subject-prefix='2.8][PATCH'
|
||||
|
||||
If you're sending a patch related to the BitBake manual, make sure you copy
|
||||
the Yocto Project documentation mailing list:
|
||||
|
||||
@@ -763,8 +763,20 @@ def mkdirhier(directory):
|
||||
try:
|
||||
os.makedirs(directory)
|
||||
except OSError as e:
|
||||
if e.errno != errno.EEXIST or not os.path.isdir(directory):
|
||||
if e.errno != errno.EEXIST:
|
||||
raise e
|
||||
if os.path.isdir(directory):
|
||||
return
|
||||
# We can end up here if there is a race between two mkdirs on an NFS mount,
|
||||
# which happens more often with sstate that you'd think. The server returns
|
||||
# EEXIST but the local attribute cache is out of date. It can be refreshed with
|
||||
# an opendir call, so try that (via listdir) and check the directory again
|
||||
# before we really fail.
|
||||
os.listdir(os.path.dirname(directory))
|
||||
if os.path.isdir(directory):
|
||||
return
|
||||
bb.warn("mkdir: %s is not a directory?")
|
||||
raise e
|
||||
|
||||
def movefile(src, dest, newmtime = None, sstat = None):
|
||||
"""Moves a file from src to dest, preserving all permissions and
|
||||
|
||||
@@ -4,6 +4,8 @@ url = "https://pypi.org/simple"
|
||||
verify_ssl = true
|
||||
|
||||
[dev-packages]
|
||||
sphinx-lint = "*"
|
||||
vale = "*"
|
||||
|
||||
[packages]
|
||||
sphinx = "*"
|
||||
|
||||
@@ -151,6 +151,13 @@ dependencies in a virtual environment:
|
||||
$ pipenv install
|
||||
$ pipenv run make html
|
||||
|
||||
Note: if you decide to use Pipenv for installing the dependencies, don't forget
|
||||
to prefix all the make commands below with "pipenv run ". The make commands
|
||||
which already start with "pipenv run " don't need to be prefixed a second time
|
||||
but require you to use Pipenv for them to run and aren't available when
|
||||
following the instructions from
|
||||
https://docs.yoctoproject.org/dev/ref-manual/system-requirements.html#required-packages-for-the-build-host.
|
||||
|
||||
Style checking the Yocto Project documentation
|
||||
==============================================
|
||||
|
||||
@@ -159,19 +166,19 @@ to validate the text style.
|
||||
|
||||
To install Vale:
|
||||
|
||||
$ pip install vale
|
||||
$ pipenv install --dev
|
||||
|
||||
To run Vale:
|
||||
|
||||
$ make stylecheck
|
||||
$ pipenv run make stylecheck
|
||||
|
||||
Style checking the whole documentation might take some time and generate a
|
||||
lot of warnings/errors, thus one can run Vale on a subset of files or
|
||||
directories:
|
||||
|
||||
$ make stylecheck VALEDOCS=<file>
|
||||
$ make stylecheck VALEDOCS="<file1> <file2>"
|
||||
$ make stylecheck VALEDOCS=<dir>
|
||||
$ pipenv run make stylecheck VALEDOCS=<file>
|
||||
$ pipenv run make stylecheck VALEDOCS="<file1> <file2>"
|
||||
$ pipenv run make stylecheck VALEDOCS=<dir>
|
||||
|
||||
Lint checking the Yocto Project documentation
|
||||
=============================================
|
||||
@@ -181,19 +188,19 @@ the project uses sphinx-lint (https://github.com/sphinx-contrib/sphinx-lint).
|
||||
|
||||
To install sphinx-lint:
|
||||
|
||||
$ pip install sphinx-lint
|
||||
$ pipenv install --dev
|
||||
|
||||
To run sphinx-lint:
|
||||
|
||||
$ make sphinx-lint
|
||||
$ pipenv run make sphinx-lint
|
||||
|
||||
Lint checking the whole documentation might take some time and generate a
|
||||
lot of warnings/errors, thus one can run sphinx-lint on a subset of files
|
||||
or directories:
|
||||
|
||||
$ make sphinx-lint SPHINXLINTDOCS=<file>
|
||||
$ make sphinx-lint SPHINXLINTDOCS="<file1> <file2>"
|
||||
$ make sphinx-lint SPHINXLINTDOCS=<dir>
|
||||
$ pipenv run make sphinx-lint SPHINXLINTDOCS=<file>
|
||||
$ pipenv run make sphinx-lint SPHINXLINTDOCS="<file1> <file2>"
|
||||
$ pipenv run make sphinx-lint SPHINXLINTDOCS=<dir>
|
||||
|
||||
Sphinx theme and CSS customization
|
||||
==================================
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
.. SPDX-License-Identifier: CC-BY-SA-2.0-UK
|
||||
|
||||
=====================
|
||||
BitBake Documentation
|
||||
=====================
|
||||
===================
|
||||
BitBake User Manual
|
||||
===================
|
||||
|
||||
|
|
||||
|
||||
|
||||
@@ -19,11 +19,8 @@ build a reference embedded OS called Poky.
|
||||
you want to use Yocto Project on to build an image
|
||||
(:term:`Build Host`) is not
|
||||
a native Linux system, you can still perform these steps by using
|
||||
CROss PlatformS (CROPS) and setting up a Poky container. See the
|
||||
:ref:`dev-manual/start:setting up to use cross platforms (crops)`
|
||||
section
|
||||
in the Yocto Project Development Tasks Manual for more
|
||||
information.
|
||||
an :wikipedia:`OCI container <Open_Container_Initiative>` (using
|
||||
`Docker <https://www.docker.com/>`__ or `Podman <https://podman.io/>`__).
|
||||
|
||||
- You may use version 2 of Windows Subsystem For Linux (WSL 2) to set
|
||||
up a build host using Windows 10 or later, Windows Server 2019 or later.
|
||||
|
||||
@@ -147,8 +147,7 @@ section.
|
||||
#. *Set Up the Build Environment:* Be sure you are set up to use BitBake
|
||||
in a shell. See the ":ref:`dev-manual/start:preparing the build host`"
|
||||
section in the Yocto Project Development Tasks Manual for information on how
|
||||
to get a build host ready that is either a native Linux machine or a machine
|
||||
that uses CROPS.
|
||||
to get a :term:`build host` ready.
|
||||
|
||||
#. *Clone the poky Repository:* You need to have a local copy of the
|
||||
Yocto Project :term:`Source Directory` (i.e. a local
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
.. SPDX-License-Identifier: CC-BY-SA-2.0-UK
|
||||
|
||||
Identify the component
|
||||
**********************
|
||||
Identifying the component
|
||||
*************************
|
||||
|
||||
The Yocto Project and OpenEmbedded ecosystem is built of :term:`layers <Layer>`
|
||||
so the first step is to identify the component where the issue likely lies.
|
||||
|
||||
@@ -268,14 +268,19 @@ License Updates
|
||||
~~~~~~~~~~~~~~~
|
||||
|
||||
When you change the :term:`LICENSE` or :term:`LIC_FILES_CHKSUM` in the recipe
|
||||
you need to briefly explain the reason for the change via a ``License-Update:``
|
||||
tag. Often it's quite trivial, such as::
|
||||
due to upstream making modifications to the license files, you need to briefly
|
||||
explain the reason for the change via a ``License-Update:`` tag. Often it's
|
||||
quite trivial, such as::
|
||||
|
||||
License-Update: copyright years refreshed
|
||||
|
||||
Less often, the actual licensing terms themselves will have changed. If so, do
|
||||
try to link to upstream making/justifying that decision.
|
||||
|
||||
The ``License-Update:`` tag is not needed for commits which fix incorrect
|
||||
license data in our metadata (for an example see OE-Core commit
|
||||
:oecore_rev:`6c8b76d240d2457578a58787121bc5873d724ee2`).
|
||||
|
||||
Tips and Guidelines for Writing Recipes
|
||||
---------------------------------------
|
||||
|
||||
|
||||
@@ -702,6 +702,12 @@ page.
|
||||
|
||||
.. note::
|
||||
|
||||
Patches submitted for a stable branch need to be isolated changes that are
|
||||
human readable and understandable. Fixes for CVEs or other issues which have
|
||||
a high complexity, consist of a large number of commits and/or a large
|
||||
numbers of changed lines are unlikely to be accepted due to the difficulty
|
||||
they cause with maintainability and scalability.
|
||||
|
||||
Changes will not typically be accepted for branches which are marked as
|
||||
End-Of-Life (EOL).
|
||||
|
||||
|
||||
@@ -825,7 +825,7 @@ different ways:
|
||||
- *systemd:* System Management Daemon (systemd) was designed to replace
|
||||
SysVinit and to provide enhanced management of services. For more
|
||||
information on systemd, see the systemd homepage at
|
||||
https://freedesktop.org/wiki/Software/systemd/.
|
||||
https://systemd.io/.
|
||||
|
||||
To enable a service using systemd, your recipe needs to inherit the
|
||||
:ref:`ref-classes-systemd` class. See the ``systemd.bbclass`` file
|
||||
|
||||
@@ -31,9 +31,18 @@ If needed, it can be disabled from a :term:`configuration file`::
|
||||
|
||||
INHERIT_DISTRO:remove = "create-spdx"
|
||||
|
||||
SPDX version 3 support is available on Yocto &DISTRO_NAME;, but disabled by
|
||||
default. To enable it, add the following statements from a :term:`configuration
|
||||
file`::
|
||||
|
||||
INHERIT_DISTRO:remove = "create-spdx"
|
||||
INHERIT_DISTRO:append = " create-spdx-3.0"
|
||||
|
||||
The following documentation will make the assumption that SPDX3 is used.
|
||||
|
||||
Upon building an image, you will then get the compressed archive
|
||||
``IMAGE-MACHINE.spdx.tar.zst`` contains the index and the files for the single
|
||||
recipes.
|
||||
``IMAGE-MACHINE.spdx.json`` file in ``tmp/deploy/images/MACHINE/`` inside
|
||||
the :term:`Build Directory`.
|
||||
|
||||
The :ref:`ref-classes-create-spdx` class offers options to include
|
||||
more information in the output :term:`SPDX` data:
|
||||
@@ -50,19 +59,7 @@ more information in the output :term:`SPDX` data:
|
||||
|
||||
Though the toplevel :term:`SPDX` output is available in
|
||||
``tmp/deploy/images/MACHINE/`` inside the :term:`Build Directory`, ancillary
|
||||
generated files are available in ``tmp/deploy/spdx`` too, such as:
|
||||
|
||||
- The individual :term:`SPDX` JSON files in the ``IMAGE-MACHINE.spdx.tar.zst``
|
||||
archive.
|
||||
|
||||
- Compressed archives of the files in the generated target packages,
|
||||
in ``packages/packagename.tar.zst`` (when :term:`SPDX_ARCHIVE_PACKAGED`
|
||||
is set).
|
||||
|
||||
- Compressed archives of the source files used to build the host tools
|
||||
and the target packages in ``recipes/recipe-packagename.tar.zst``
|
||||
(when :term:`SPDX_ARCHIVE_SOURCES` is set). Those are needed to fulfill
|
||||
"source code access" license requirements.
|
||||
generated files are available in ``tmp/deploy/spdx`` too.
|
||||
|
||||
See also the :term:`SPDX_CUSTOM_ANNOTATION_VARS` variable which allows
|
||||
to associate custom notes to a recipe.
|
||||
|
||||
@@ -251,11 +251,10 @@ Preparing the Build Host
|
||||
This section provides procedures to set up a system to be used as your
|
||||
:term:`Build Host` for
|
||||
development using the Yocto Project. Your build host can be a native
|
||||
Linux machine (recommended), it can be a machine (Linux, Mac, or
|
||||
Windows) that uses `CROPS <https://github.com/crops/poky-container>`__,
|
||||
which leverages `Docker Containers <https://www.docker.com/>`__ or it
|
||||
can be a Windows machine capable of running version 2 of Windows Subsystem
|
||||
For Linux (WSL 2).
|
||||
Linux machine (recommended), it can be an :wikipedia:`OCI container
|
||||
<Open_Container_Initiative>` (such as `Docker <https://www.docker.com/>`__ or
|
||||
`Podman <https://podman.io/>`__), or it can be a Windows machine capable of
|
||||
running version 2 of Windows Subsystem For Linux (WSL 2).
|
||||
|
||||
.. note::
|
||||
|
||||
@@ -339,101 +338,6 @@ the `Yocto Project BitBake
|
||||
<https://marketplace.visualstudio.com/items?itemName=yocto-project.yocto-bitbake>`__
|
||||
extension accordingly.
|
||||
|
||||
Setting Up to Use CROss PlatformS (CROPS)
|
||||
-----------------------------------------
|
||||
|
||||
With `CROPS <https://github.com/crops/poky-container>`__, which
|
||||
leverages `Docker Containers <https://www.docker.com/>`__, you can
|
||||
create a Yocto Project development environment that is operating system
|
||||
agnostic. You can set up a container in which you can develop using the
|
||||
Yocto Project on a Windows, Mac, or Linux machine.
|
||||
|
||||
Follow these general steps to prepare a Windows, Mac, or Linux machine
|
||||
as your Yocto Project build host:
|
||||
|
||||
#. *Determine What Your Build Host Needs:*
|
||||
`Docker <https://www.docker.com/what-docker>`__ is a software
|
||||
container platform that you need to install on the build host.
|
||||
Depending on your build host, you might have to install different
|
||||
software to support Docker containers. Go to the Docker installation
|
||||
page and read about the platform requirements in "`Supported
|
||||
Platforms <https://docs.docker.com/engine/install/#supported-platforms>`__"
|
||||
your build host needs to run containers.
|
||||
|
||||
#. *Choose What To Install:* Depending on whether or not your build host
|
||||
meets system requirements, you need to install "Docker CE Stable" or
|
||||
the "Docker Toolbox". Most situations call for Docker CE. However, if
|
||||
you have a build host that does not meet requirements (e.g.
|
||||
Pre-Windows 10 or Windows 10 "Home" version), you must install Docker
|
||||
Toolbox instead.
|
||||
|
||||
#. *Go to the Install Site for Your Platform:* Click the link for the
|
||||
Docker edition associated with your build host's native software. For
|
||||
example, if your build host is running Microsoft Windows Version 10
|
||||
and you want the Docker CE Stable edition, click that link under
|
||||
"Supported Platforms".
|
||||
|
||||
#. *Install the Software:* Once you have understood all the
|
||||
pre-requisites, you can download and install the appropriate
|
||||
software. Follow the instructions for your specific machine and the
|
||||
type of the software you need to install:
|
||||
|
||||
- Install `Docker Desktop on
|
||||
Windows <https://docs.docker.com/docker-for-windows/install/#install-docker-desktop-on-windows>`__
|
||||
for Windows build hosts that meet requirements.
|
||||
|
||||
- Install `Docker Desktop on
|
||||
MacOs <https://docs.docker.com/docker-for-mac/install/#install-and-run-docker-desktop-on-mac>`__
|
||||
for Mac build hosts that meet requirements.
|
||||
|
||||
- Install `Docker Engine on
|
||||
CentOS <https://docs.docker.com/engine/install/centos/>`__
|
||||
for Linux build hosts running the CentOS distribution.
|
||||
|
||||
- Install `Docker Engine on
|
||||
Debian <https://docs.docker.com/engine/install/debian/>`__
|
||||
for Linux build hosts running the Debian distribution.
|
||||
|
||||
- Install `Docker Engine for
|
||||
Fedora <https://docs.docker.com/engine/install/fedora/>`__
|
||||
for Linux build hosts running the Fedora distribution.
|
||||
|
||||
- Install `Docker Engine for
|
||||
Ubuntu <https://docs.docker.com/engine/install/ubuntu/>`__
|
||||
for Linux build hosts running the Ubuntu distribution.
|
||||
|
||||
#. *Optionally Orient Yourself With Docker:* If you are unfamiliar with
|
||||
Docker and the container concept, you can learn more here -
|
||||
https://docs.docker.com/get-started/.
|
||||
|
||||
#. *Launch Docker or Docker Toolbox:* You should be able to launch
|
||||
Docker or the Docker Toolbox and have a terminal shell on your
|
||||
development host.
|
||||
|
||||
#. *Set Up the Containers to Use the Yocto Project:* Go to
|
||||
https://github.com/crops/docker-win-mac-docs/wiki and follow
|
||||
the directions for your particular build host (i.e. Linux, Mac, or
|
||||
Windows).
|
||||
|
||||
Once you complete the setup instructions for your machine, you have
|
||||
the Poky, Extensible SDK, and Toaster containers available. You can
|
||||
click those links from the page and learn more about using each of
|
||||
those containers.
|
||||
|
||||
Once you have a container set up, everything is in place to develop just
|
||||
as if you were running on a native Linux machine. If you are going to
|
||||
use the Poky container, see the
|
||||
":ref:`dev-manual/start:cloning the \`\`poky\`\` repository`"
|
||||
section. If you are going to use the Extensible SDK container, see the
|
||||
":doc:`/sdk-manual/extensible`" Chapter in the Yocto
|
||||
Project Application Development and the Extensible Software Development
|
||||
Kit (eSDK) manual. If you are going to use the Toaster container, see
|
||||
the ":doc:`/toaster-manual/setup-and-use`"
|
||||
section in the Toaster User Manual. If you are a VSCode user, you can configure
|
||||
the `Yocto Project BitBake
|
||||
<https://marketplace.visualstudio.com/items?itemName=yocto-project.yocto-bitbake>`__
|
||||
extension accordingly.
|
||||
|
||||
Setting Up to Use Windows Subsystem For Linux (WSL 2)
|
||||
-----------------------------------------------------
|
||||
|
||||
|
||||
@@ -3,8 +3,8 @@
|
||||
Using x32 psABI
|
||||
***************
|
||||
|
||||
x32 processor-specific Application Binary Interface (`x32
|
||||
psABI <https://software.intel.com/en-us/node/628948>`__) is a native
|
||||
x32 processor-specific Application Binary Interface (:wikipedia:`x32
|
||||
psABI <X32_ABI>`) is a native
|
||||
32-bit processor-specific ABI for Intel 64 (x86-64) architectures. An
|
||||
ABI defines the calling conventions between functions in a processing
|
||||
environment. The interface determines what registers are used and what
|
||||
|
||||
@@ -5,10 +5,21 @@
|
||||
You can adapt this file completely to your liking, but it should at least
|
||||
contain the root `toctree` directive.
|
||||
|
||||
==========================================
|
||||
Welcome to the Yocto Project Documentation
|
||||
==========================================
|
||||
|
||||
|
|
||||
.. only:: html
|
||||
|
||||
This is the top level of the Yocto Project documentation tree. The Yocto
|
||||
Project documentation is always a work in progress, just like the Yocto
|
||||
Project itself. Improvements to the documentation are always welcome; join
|
||||
the :yocto_lists:`docs mailing list </g/docs>` if you want to help out.
|
||||
|
||||
Introduction and Overview
|
||||
=========================
|
||||
|
||||
Get started using the Yocto Project.
|
||||
|
||||
.. toctree::
|
||||
:maxdepth: 1
|
||||
@@ -17,15 +28,41 @@ Welcome to the Yocto Project Documentation
|
||||
Quick Build <brief-yoctoprojectqs/index>
|
||||
what-i-wish-id-known
|
||||
transitioning-to-a-custom-environment
|
||||
Yocto Project Technical Overview <https://www.yoctoproject.org/development/technical-overview/>
|
||||
Tips and Tricks Wiki <https://wiki.yoctoproject.org/wiki/TipsAndTricks>
|
||||
|
||||
Get familiar with the development environment and concepts of the Yocto Project.
|
||||
|
||||
.. toctree::
|
||||
:maxdepth: 2
|
||||
|
||||
Overview and Concepts <overview-manual/index>
|
||||
|
||||
Additional introductory resources.
|
||||
|
||||
- `Technical Overview (external website) <https://www.yoctoproject.org/development/technical-overview/>`__
|
||||
- `Tips and Tricks Wiki (external website) <https://wiki.yoctoproject.org/wiki/TipsAndTricks>`__
|
||||
|
||||
Contributing to the Yocto Project
|
||||
=================================
|
||||
|
||||
Guides on how to contribute to the different parts of the Yocto Project.
|
||||
|
||||
.. toctree::
|
||||
:maxdepth: 2
|
||||
:caption: Contributor Guide
|
||||
|
||||
Contributor Guide <contributor-guide/index>
|
||||
|
||||
Manuals
|
||||
=======
|
||||
|
||||
A collection of manuals covering many aspects of the Yocto Project, including
|
||||
reference definitions, tutorials, and details about the project's
|
||||
infrastructure.
|
||||
|
||||
.. toctree::
|
||||
:maxdepth: 1
|
||||
:caption: Manuals
|
||||
|
||||
Overview and Concepts Manual <overview-manual/index>
|
||||
Contributor Guide <contributor-guide/index>
|
||||
Reference Manual <ref-manual/index>
|
||||
Board Support Package (BSP) Developer's guide <bsp-guide/index>
|
||||
Development Tasks Manual <dev-manual/index>
|
||||
@@ -34,20 +71,35 @@ Welcome to the Yocto Project Documentation
|
||||
Application Development and the Extensible SDK (eSDK) <sdk-manual/index>
|
||||
Toaster Manual <toaster-manual/index>
|
||||
Test Environment Manual <test-manual/index>
|
||||
bitbake
|
||||
BitBake User Manual <bitbake>
|
||||
|
||||
Security Reference
|
||||
==================
|
||||
|
||||
Security-related processes and contact information for vulnerability reporting.
|
||||
|
||||
.. toctree::
|
||||
:maxdepth: 1
|
||||
:caption: Security
|
||||
:caption: Security Reference
|
||||
|
||||
Yocto Project Security Reference <security-reference/index>
|
||||
|
||||
Release Information
|
||||
===================
|
||||
|
||||
Release notes and migration guides for the different Yocto Project releases.
|
||||
|
||||
.. toctree::
|
||||
:maxdepth: 2
|
||||
:caption: Release Information
|
||||
|
||||
Release Notes and Migration Guides <migration-guides/index>
|
||||
|
||||
.. toctree::
|
||||
:maxdepth: 1
|
||||
:caption: Release Manuals
|
||||
:hidden:
|
||||
|
||||
Release Information <migration-guides/index>
|
||||
releases
|
||||
|
||||
.. toctree::
|
||||
|
||||
@@ -696,21 +696,6 @@ the ":ref:`kernel-dev/common:getting ready to develop using ``devtool```" Sectio
|
||||
|
||||
$ devtool modify linux-yocto
|
||||
|
||||
.. note::
|
||||
|
||||
During the checkout operation, there is a bug that could cause
|
||||
errors such as the following:
|
||||
|
||||
.. code-block:: none
|
||||
|
||||
ERROR: Taskhash mismatch 2c793438c2d9f8c3681fd5f7bc819efa versus
|
||||
be3a89ce7c47178880ba7bf6293d7404 for
|
||||
/path/to/esdk/layers/poky/meta/recipes-kernel/linux/linux-yocto_4.10.bb.do_unpack
|
||||
|
||||
|
||||
You can safely ignore these messages. The source code is correctly
|
||||
checked out.
|
||||
|
||||
#. *Edit the Source Files* Follow these steps to make some simple
|
||||
changes to the source files:
|
||||
|
||||
|
||||
@@ -25,3 +25,4 @@ Release 5.0 (scarthgap)
|
||||
release-notes-5.0.16
|
||||
release-notes-5.0.17
|
||||
release-notes-5.0.18
|
||||
release-notes-5.0.19
|
||||
|
||||
@@ -200,7 +200,7 @@ openembedded-core
|
||||
|
||||
meta-mingw
|
||||
|
||||
- Repository Location: :yocto_git:`meta-mingw`
|
||||
- Repository Location: :yocto_git:`/meta-mingw`
|
||||
- Branch: :yocto_git:`honister </meta-mingw/log/?h=honister>`
|
||||
- Tag: :yocto_git:`yocto-3.4.2 </meta-mingw/tag/?h=yocto-3.4.2>`
|
||||
- Git Revision: :yocto_git:`f5d761cbd5c957e4405c5d40b0c236d263c916a8 </meta-mingw/commit/?id=f5d761cbd5c957e4405c5d40b0c236d263c916a8>`
|
||||
@@ -239,4 +239,4 @@ yocto-docs
|
||||
- Repository Location: :yocto_git:`/yocto-docs`
|
||||
- Branch: :yocto_git:`honister </yocto-docs/log/?h=honister>`
|
||||
- Tag: :yocto_git:`yocto-3.4.2 </yocto-docs/tag/?h=yocto-3.4.2>`
|
||||
- Git Revision: :yocto_git:`3061d3d62054a5c3b9e16bfce4bcd186fa7a23d2` </yocto-docs/commit/?3061d3d62054a5c3b9e16bfce4bcd186fa7a23d2>`
|
||||
- Git Revision: :yocto_git:`3061d3d62054a5c3b9e16bfce4bcd186fa7a23d2 </yocto-docs/commit/?3061d3d62054a5c3b9e16bfce4bcd186fa7a23d2>`
|
||||
|
||||
@@ -73,7 +73,7 @@ New Features / Enhancements in 4.3
|
||||
for the latest long-term release (6.1).
|
||||
|
||||
- The list of fixed kernel CVEs is updated regularly using data from
|
||||
`linuxkernelcves.com <https://linuxkernelcves.com>`__.
|
||||
`linuxkernelcves.com <https://web.archive.org/web/20240420122324/https://www.linuxkernelcves.com/>`__.
|
||||
|
||||
- A ``showconfig`` task was added to the :ref:`ref-classes-cml1` class, to
|
||||
easily examine the final generated ``.config`` file.
|
||||
|
||||
663
documentation/migration-guides/release-notes-5.0.19.rst
Normal file
663
documentation/migration-guides/release-notes-5.0.19.rst
Normal file
@@ -0,0 +1,663 @@
|
||||
Release notes for Yocto-5.0.19 (Scarthgap)
|
||||
------------------------------------------
|
||||
|
||||
gawk-native is now built from source instead of used from the host when
|
||||
building grub2 & glibc to avoid reproducibility issues on newer host
|
||||
distros.
|
||||
|
||||
Security Fixes in Yocto-5.0.19
|
||||
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
- avahi: Remove a reference to the rejected :cve_nist:`2021-36217`
|
||||
- binutils: Fix :cve_nist:`2025-69644`
|
||||
- busybox: Fix :cve_nist:`2026-29004`
|
||||
- dpkg: Fix :cve_nist:`2026-2219`
|
||||
- go: Fix :cve_nist:`2025-58183`, :cve_mitre:`2026-25679`, :cve_nist:`2026-27140`,
|
||||
:cve_nist:`2026-27142`, :cve_nist:`2026-27143`, :cve_nist:`2026-27144`, :cve_nist:`2026-27145`,
|
||||
:cve_nist:`2026-32280`, :cve_nist:`2026-32283`, :cve_nist:`2026-32288`, :cve_nist:`2026-32289`,
|
||||
:cve_nist:`2026-33811`, :cve_nist:`2026-39817`, :cve_nist:`2026-39819`, :cve_nist:`2026-39820`,
|
||||
:cve_nist:`2026-39825`, :cve_nist:`2026-39826`, :cve_nist:`2026-42499`, :cve_nist:`2026-42501`,
|
||||
:cve_nist:`2026-42504` and :cve_nist:`2026-42507`
|
||||
- go: Ignore :cve_nist:`2026-39836`
|
||||
- libarchive: Fix :cve_nist:`2026-4424`
|
||||
- libexif: Fix :cve_nist:`2026-32775`, :cve_nist:`2026-40385` and :cve_nist:`2026-40386`
|
||||
- libinput: Fix :cve_nist:`2026-50292`
|
||||
- libpng: Fix :cve_nist:`2026-33416`
|
||||
- libsolv: Fix :cve_nist:`2026-9150`
|
||||
- libsoup: Fix :cve_nist:`2025-11021` and :cve_nist:`2026-2369`
|
||||
- libssh2: Fix :cve_nist:`2026-7598`
|
||||
- libusb1: Fix :cve_nist:`2026-23679` and :cve_nist:`2026-47104`
|
||||
- libxml-parser-perl: Fix :cve_nist:`2006-10003`
|
||||
- linux-yocto/6.6: Fix :cve_nist:`2023-52920`, :cve_nist:`2024-14027`, :cve_nist:`2024-27022`,
|
||||
:cve_nist:`2024-56647`, :cve_nist:`2025-21739`, :cve_nist:`2025-22125`, :cve_nist:`2025-38531`,
|
||||
:cve_nist:`2025-38584`, :cve_nist:`2025-38710`, :cve_nist:`2025-39981`, :cve_nist:`2025-40219`,
|
||||
:cve_nist:`2025-68315`, :cve_nist:`2025-71184`, :cve_nist:`2025-71239`, :cve_nist:`2025-71265`,
|
||||
:cve_nist:`2025-71266`, :cve_nist:`2025-71267`, :cve_nist:`2025-71269`, :cve_nist:`2025-71274`,
|
||||
:cve_nist:`2025-71286`, :cve_nist:`2025-71287`, :cve_nist:`2025-71288`, :cve_nist:`2025-71291`,
|
||||
:cve_nist:`2025-71292`, :cve_nist:`2025-71295`, :cve_nist:`2025-71297`, :cve_nist:`2025-71304`,
|
||||
:cve_nist:`2025-71305`, :cve_nist:`2026-23004`, :cve_nist:`2026-23171`, :cve_nist:`2026-23231`,
|
||||
:cve_nist:`2026-23242`, :cve_nist:`2026-23243`, :cve_nist:`2026-23244`, :cve_nist:`2026-23245`,
|
||||
:cve_nist:`2026-23246`, :cve_nist:`2026-23253`, :cve_nist:`2026-23255`, :cve_nist:`2026-23268`,
|
||||
:cve_nist:`2026-23269`, :cve_nist:`2026-23270`, :cve_nist:`2026-23271`, :cve_nist:`2026-23272`,
|
||||
:cve_nist:`2026-23273`, :cve_nist:`2026-23274`, :cve_nist:`2026-23277`, :cve_nist:`2026-23279`,
|
||||
:cve_nist:`2026-23281`, :cve_nist:`2026-23284`, :cve_nist:`2026-23285`, :cve_nist:`2026-23286`,
|
||||
:cve_nist:`2026-23287`, :cve_nist:`2026-23289`, :cve_nist:`2026-23290`, :cve_nist:`2026-23291`,
|
||||
:cve_nist:`2026-23292`, :cve_nist:`2026-23293`, :cve_nist:`2026-23296`, :cve_nist:`2026-23298`,
|
||||
:cve_nist:`2026-23300`, :cve_nist:`2026-23302`, :cve_nist:`2026-23303`, :cve_nist:`2026-23304`,
|
||||
:cve_nist:`2026-23306`, :cve_nist:`2026-23307`, :cve_nist:`2026-23308`, :cve_nist:`2026-23310`,
|
||||
:cve_nist:`2026-23312`, :cve_nist:`2026-23313`, :cve_nist:`2026-23315`, :cve_nist:`2026-23317`,
|
||||
:cve_nist:`2026-23318`, :cve_nist:`2026-23319`, :cve_nist:`2026-23321`, :cve_nist:`2026-23324`,
|
||||
:cve_nist:`2026-23325`, :cve_nist:`2026-23330`, :cve_nist:`2026-23334`, :cve_nist:`2026-23335`,
|
||||
:cve_nist:`2026-23336`, :cve_nist:`2026-23339`, :cve_nist:`2026-23340`, :cve_nist:`2026-23343`,
|
||||
:cve_nist:`2026-23347`, :cve_nist:`2026-23351`, :cve_nist:`2026-23352`, :cve_nist:`2026-23356`,
|
||||
:cve_nist:`2026-23357`, :cve_nist:`2026-23359`, :cve_nist:`2026-23360`, :cve_nist:`2026-23362`,
|
||||
:cve_nist:`2026-23364`, :cve_nist:`2026-23365`, :cve_nist:`2026-23367`, :cve_nist:`2026-23368`,
|
||||
:cve_nist:`2026-23370`, :cve_nist:`2026-23372`, :cve_nist:`2026-23374`, :cve_nist:`2026-23378`,
|
||||
:cve_nist:`2026-23379`, :cve_nist:`2026-23381`, :cve_nist:`2026-23382`, :cve_nist:`2026-23386`,
|
||||
:cve_nist:`2026-23387`, :cve_nist:`2026-23388`, :cve_nist:`2026-23389`, :cve_nist:`2026-23391`,
|
||||
:cve_nist:`2026-23392`, :cve_nist:`2026-23395`, :cve_nist:`2026-23396`, :cve_nist:`2026-23397`,
|
||||
:cve_nist:`2026-23398`, :cve_nist:`2026-23399`, :cve_nist:`2026-23401`, :cve_nist:`2026-23403`,
|
||||
:cve_nist:`2026-23404`, :cve_nist:`2026-23405`, :cve_nist:`2026-23406`, :cve_nist:`2026-23407`,
|
||||
:cve_nist:`2026-23408`, :cve_nist:`2026-23409`, :cve_nist:`2026-23410`, :cve_nist:`2026-23411`,
|
||||
:cve_nist:`2026-23412`, :cve_nist:`2026-23413`, :cve_nist:`2026-23414`, :cve_nist:`2026-23419`,
|
||||
:cve_nist:`2026-23420`, :cve_nist:`2026-23422`, :cve_nist:`2026-23426`, :cve_nist:`2026-23427`,
|
||||
:cve_nist:`2026-23428`, :cve_nist:`2026-23434`, :cve_nist:`2026-23438`, :cve_nist:`2026-23439`,
|
||||
:cve_nist:`2026-23440`, :cve_nist:`2026-23441`, :cve_nist:`2026-23442`, :cve_nist:`2026-23443`,
|
||||
:cve_nist:`2026-23444`, :cve_nist:`2026-23446`, :cve_nist:`2026-23447`, :cve_nist:`2026-23448`,
|
||||
:cve_nist:`2026-23449`, :cve_nist:`2026-23450`, :cve_nist:`2026-23452`, :cve_nist:`2026-23454`,
|
||||
:cve_nist:`2026-23455`, :cve_nist:`2026-23456`, :cve_nist:`2026-23457`, :cve_nist:`2026-23458`,
|
||||
:cve_nist:`2026-23460`, :cve_nist:`2026-23461`, :cve_nist:`2026-23462`, :cve_nist:`2026-23463`,
|
||||
:cve_nist:`2026-23465`, :cve_nist:`2026-23468`, :cve_nist:`2026-23474`, :cve_nist:`2026-23475`,
|
||||
:cve_nist:`2026-31389`, :cve_nist:`2026-31391`, :cve_nist:`2026-31392`, :cve_nist:`2026-31393`,
|
||||
:cve_nist:`2026-31396`, :cve_nist:`2026-31399`, :cve_nist:`2026-31400`, :cve_nist:`2026-31402`,
|
||||
:cve_nist:`2026-31403`, :cve_nist:`2026-31405`, :cve_nist:`2026-31407`, :cve_nist:`2026-31408`,
|
||||
:cve_nist:`2026-31409`, :cve_nist:`2026-31411`, :cve_nist:`2026-31412`, :cve_nist:`2026-31414`,
|
||||
:cve_nist:`2026-31415`, :cve_nist:`2026-31416`, :cve_nist:`2026-31417`, :cve_nist:`2026-31418`,
|
||||
:cve_nist:`2026-31421`, :cve_nist:`2026-31422`, :cve_nist:`2026-31423`, :cve_nist:`2026-31424`,
|
||||
:cve_nist:`2026-31425`, :cve_nist:`2026-31426`, :cve_nist:`2026-31427`, :cve_nist:`2026-31428`,
|
||||
:cve_nist:`2026-31429`, :cve_nist:`2026-31430`, :cve_nist:`2026-31431`, :cve_nist:`2026-31433`,
|
||||
:cve_nist:`2026-31434`, :cve_nist:`2026-31439`, :cve_nist:`2026-31440`, :cve_nist:`2026-31441`,
|
||||
:cve_nist:`2026-31446`, :cve_nist:`2026-31447`, :cve_nist:`2026-31448`, :cve_nist:`2026-31449`,
|
||||
:cve_nist:`2026-31450`, :cve_nist:`2026-31451`, :cve_nist:`2026-31452`, :cve_nist:`2026-31453`,
|
||||
:cve_nist:`2026-31454`, :cve_nist:`2026-31455`, :cve_nist:`2026-31458`, :cve_nist:`2026-31464`,
|
||||
:cve_nist:`2026-31466`, :cve_nist:`2026-31467`, :cve_nist:`2026-31469`, :cve_nist:`2026-31473`,
|
||||
:cve_nist:`2026-31474`, :cve_nist:`2026-31476`, :cve_nist:`2026-31477`, :cve_nist:`2026-31478`,
|
||||
:cve_nist:`2026-31480`, :cve_nist:`2026-31482`, :cve_nist:`2026-31483`, :cve_nist:`2026-31485`,
|
||||
:cve_nist:`2026-31488`, :cve_nist:`2026-31489`, :cve_nist:`2026-31492`, :cve_nist:`2026-31494`,
|
||||
:cve_nist:`2026-31495`, :cve_nist:`2026-31496`, :cve_nist:`2026-31497`, :cve_nist:`2026-31498`,
|
||||
:cve_nist:`2026-31500`, :cve_nist:`2026-31503`, :cve_nist:`2026-31504`, :cve_nist:`2026-31507`,
|
||||
:cve_nist:`2026-31508`, :cve_nist:`2026-31509`, :cve_nist:`2026-31510`, :cve_nist:`2026-31512`,
|
||||
:cve_nist:`2026-31515`, :cve_nist:`2026-31518`, :cve_nist:`2026-31519`, :cve_nist:`2026-31520`,
|
||||
:cve_nist:`2026-31521`, :cve_nist:`2026-31522`, :cve_nist:`2026-31523`, :cve_nist:`2026-31524`,
|
||||
:cve_nist:`2026-31525`, :cve_nist:`2026-31528`, :cve_nist:`2026-31532`, :cve_nist:`2026-31533`,
|
||||
:cve_nist:`2026-31540`, :cve_nist:`2026-31542`, :cve_nist:`2026-31545`, :cve_nist:`2026-31546`,
|
||||
:cve_nist:`2026-31548`, :cve_nist:`2026-31549`, :cve_nist:`2026-31550`, :cve_nist:`2026-31551`,
|
||||
:cve_nist:`2026-31552`, :cve_nist:`2026-31555`, :cve_nist:`2026-31563`, :cve_nist:`2026-31565`,
|
||||
:cve_nist:`2026-31566`, :cve_nist:`2026-31570`, :cve_nist:`2026-31576`, :cve_nist:`2026-31577`,
|
||||
:cve_nist:`2026-31578`, :cve_nist:`2026-31580`, :cve_nist:`2026-31581`, :cve_nist:`2026-31583`,
|
||||
:cve_nist:`2026-31584`, :cve_nist:`2026-31585`, :cve_nist:`2026-31586`, :cve_nist:`2026-31587`,
|
||||
:cve_nist:`2026-31588`, :cve_nist:`2026-31590`, :cve_nist:`2026-31594`, :cve_nist:`2026-31595`,
|
||||
:cve_nist:`2026-31596`, :cve_nist:`2026-31597`, :cve_nist:`2026-31598`, :cve_nist:`2026-31599`,
|
||||
:cve_nist:`2026-31602`, :cve_nist:`2026-31603`, :cve_nist:`2026-31604`, :cve_nist:`2026-31605`,
|
||||
:cve_nist:`2026-31607`, :cve_nist:`2026-31610`, :cve_nist:`2026-31611`, :cve_nist:`2026-31612`,
|
||||
:cve_nist:`2026-31613`, :cve_nist:`2026-31614`, :cve_nist:`2026-31615`, :cve_nist:`2026-31616`,
|
||||
:cve_nist:`2026-31617`, :cve_nist:`2026-31618`, :cve_nist:`2026-31619`, :cve_nist:`2026-31622`,
|
||||
:cve_nist:`2026-31623`, :cve_nist:`2026-31624`, :cve_nist:`2026-31625`, :cve_nist:`2026-31626`,
|
||||
:cve_nist:`2026-31627`, :cve_nist:`2026-31628`, :cve_nist:`2026-31629`, :cve_nist:`2026-31634`,
|
||||
:cve_nist:`2026-31637`, :cve_nist:`2026-31638`, :cve_nist:`2026-31639`, :cve_nist:`2026-31642`,
|
||||
:cve_nist:`2026-31646`, :cve_nist:`2026-31648`, :cve_nist:`2026-31649`, :cve_nist:`2026-31651`,
|
||||
:cve_nist:`2026-31655`, :cve_nist:`2026-31656`, :cve_nist:`2026-31657`, :cve_nist:`2026-31658`,
|
||||
:cve_nist:`2026-31659`, :cve_nist:`2026-31660`, :cve_nist:`2026-31661`, :cve_nist:`2026-31662`,
|
||||
:cve_nist:`2026-31664`, :cve_nist:`2026-31665`, :cve_nist:`2026-31667`, :cve_nist:`2026-31668`,
|
||||
:cve_nist:`2026-31669`, :cve_nist:`2026-31670`, :cve_nist:`2026-31671`, :cve_nist:`2026-31672`,
|
||||
:cve_nist:`2026-31673`, :cve_nist:`2026-31674`, :cve_nist:`2026-31675`, :cve_nist:`2026-31676`,
|
||||
:cve_nist:`2026-31678`, :cve_nist:`2026-31679`, :cve_nist:`2026-31680`, :cve_nist:`2026-31681`,
|
||||
:cve_nist:`2026-31682`, :cve_nist:`2026-31683`, :cve_nist:`2026-31684`, :cve_nist:`2026-31685`,
|
||||
:cve_nist:`2026-31686`, :cve_nist:`2026-31689`, :cve_nist:`2026-31693`, :cve_nist:`2026-31694`,
|
||||
:cve_nist:`2026-31695`, :cve_nist:`2026-31696`, :cve_nist:`2026-31697`, :cve_nist:`2026-31698`,
|
||||
:cve_nist:`2026-31699`, :cve_nist:`2026-31700`, :cve_nist:`2026-31701`, :cve_nist:`2026-31702`,
|
||||
:cve_nist:`2026-31704`, :cve_nist:`2026-31705`, :cve_nist:`2026-31707`, :cve_nist:`2026-31708`,
|
||||
:cve_nist:`2026-31709`, :cve_nist:`2026-31711`, :cve_nist:`2026-31712`, :cve_nist:`2026-31714`,
|
||||
:cve_nist:`2026-31715`, :cve_nist:`2026-31716`, :cve_nist:`2026-31718`, :cve_nist:`2026-31720`,
|
||||
:cve_nist:`2026-31721`, :cve_nist:`2026-31726`, :cve_nist:`2026-31728`, :cve_nist:`2026-31730`,
|
||||
:cve_nist:`2026-31737`, :cve_nist:`2026-31738`, :cve_nist:`2026-31740`, :cve_nist:`2026-31741`,
|
||||
:cve_nist:`2026-31747`, :cve_nist:`2026-31748`, :cve_nist:`2026-31749`, :cve_nist:`2026-31751`,
|
||||
:cve_nist:`2026-31752`, :cve_nist:`2026-31754`, :cve_nist:`2026-31755`, :cve_nist:`2026-31756`,
|
||||
:cve_nist:`2026-31758`, :cve_nist:`2026-31759`, :cve_nist:`2026-31761`, :cve_nist:`2026-31762`,
|
||||
:cve_nist:`2026-31763`, :cve_nist:`2026-31768`, :cve_nist:`2026-31770`, :cve_nist:`2026-31773`,
|
||||
:cve_nist:`2026-31778`, :cve_nist:`2026-31779`, :cve_nist:`2026-31780`, :cve_nist:`2026-31781`,
|
||||
:cve_nist:`2026-31786`, :cve_nist:`2026-31787`, :cve_nist:`2026-31788`, :cve_nist:`2026-43007`,
|
||||
:cve_nist:`2026-43011`, :cve_nist:`2026-43013`, :cve_nist:`2026-43014`, :cve_nist:`2026-43015`,
|
||||
:cve_nist:`2026-43016`, :cve_nist:`2026-43017`, :cve_nist:`2026-43018`, :cve_nist:`2026-43020`,
|
||||
:cve_nist:`2026-43023`, :cve_nist:`2026-43024`, :cve_nist:`2026-43025`, :cve_nist:`2026-43026`,
|
||||
:cve_nist:`2026-43027`, :cve_nist:`2026-43028`, :cve_nist:`2026-43030`, :cve_nist:`2026-43032`,
|
||||
:cve_nist:`2026-43033`, :cve_nist:`2026-43035`, :cve_nist:`2026-43037`, :cve_nist:`2026-43038`,
|
||||
:cve_nist:`2026-43040`, :cve_nist:`2026-43041`, :cve_nist:`2026-43043`, :cve_nist:`2026-43044`,
|
||||
:cve_nist:`2026-43046`, :cve_nist:`2026-43047`, :cve_nist:`2026-43050`, :cve_nist:`2026-43051`,
|
||||
:cve_nist:`2026-43054`, :cve_nist:`2026-43056`, :cve_nist:`2026-43057`, :cve_nist:`2026-43058`,
|
||||
:cve_nist:`2026-43060`, :cve_nist:`2026-43061`, :cve_nist:`2026-43062`, :cve_nist:`2026-43064`,
|
||||
:cve_nist:`2026-43065`, :cve_nist:`2026-43066`, :cve_nist:`2026-43067`, :cve_nist:`2026-43068`,
|
||||
:cve_nist:`2026-43069`, :cve_nist:`2026-43071`, :cve_nist:`2026-43072`, :cve_nist:`2026-43074`,
|
||||
:cve_nist:`2026-43075`, :cve_nist:`2026-43076`, :cve_nist:`2026-43077`, :cve_nist:`2026-43078`,
|
||||
:cve_nist:`2026-43079`, :cve_nist:`2026-43080`, :cve_nist:`2026-43081`, :cve_nist:`2026-43082`,
|
||||
:cve_nist:`2026-43085`, :cve_nist:`2026-43086`, :cve_nist:`2026-43089`, :cve_nist:`2026-43091`,
|
||||
:cve_nist:`2026-43092`, :cve_nist:`2026-43093`, :cve_nist:`2026-43094`, :cve_nist:`2026-43098`,
|
||||
:cve_nist:`2026-43099`, :cve_nist:`2026-43103`, :cve_nist:`2026-43104`, :cve_nist:`2026-43105`,
|
||||
:cve_nist:`2026-43109`, :cve_nist:`2026-43110`, :cve_nist:`2026-43111`, :cve_nist:`2026-43112`,
|
||||
:cve_nist:`2026-43113`, :cve_nist:`2026-43114`, :cve_nist:`2026-43117`, :cve_nist:`2026-43120`,
|
||||
:cve_nist:`2026-43123`, :cve_nist:`2026-43124`, :cve_nist:`2026-43128`, :cve_nist:`2026-43130`,
|
||||
:cve_nist:`2026-43132`, :cve_nist:`2026-43133`, :cve_nist:`2026-43134`, :cve_nist:`2026-43135`,
|
||||
:cve_nist:`2026-43136`, :cve_nist:`2026-43137`, :cve_nist:`2026-43139`, :cve_nist:`2026-43140`,
|
||||
:cve_nist:`2026-43141`, :cve_nist:`2026-43143`, :cve_nist:`2026-43145`, :cve_nist:`2026-43147`,
|
||||
:cve_nist:`2026-43148`, :cve_nist:`2026-43149`, :cve_nist:`2026-43150`, :cve_nist:`2026-43152`,
|
||||
:cve_nist:`2026-43156`, :cve_nist:`2026-43157`, :cve_nist:`2026-43158`, :cve_nist:`2026-43159`,
|
||||
:cve_nist:`2026-43162`, :cve_nist:`2026-43163`, :cve_nist:`2026-43167`, :cve_nist:`2026-43168`,
|
||||
:cve_nist:`2026-43170`, :cve_nist:`2026-43171`, :cve_nist:`2026-43173`, :cve_nist:`2026-43180`,
|
||||
:cve_nist:`2026-43182`, :cve_nist:`2026-43183`, :cve_nist:`2026-43184`, :cve_nist:`2026-43186`,
|
||||
:cve_nist:`2026-43187`, :cve_nist:`2026-43189`, :cve_nist:`2026-43190`, :cve_nist:`2026-43194`,
|
||||
:cve_nist:`2026-43196`, :cve_nist:`2026-43200`, :cve_nist:`2026-43202`, :cve_nist:`2026-43203`,
|
||||
:cve_nist:`2026-43205`, :cve_nist:`2026-43206`, :cve_nist:`2026-43207`, :cve_nist:`2026-43209`,
|
||||
:cve_nist:`2026-43211`, :cve_nist:`2026-43212`, :cve_nist:`2026-43214`, :cve_nist:`2026-43215`,
|
||||
:cve_nist:`2026-43218`, :cve_nist:`2026-43221`, :cve_nist:`2026-43222`, :cve_nist:`2026-43223`,
|
||||
:cve_nist:`2026-43225`, :cve_nist:`2026-43226`, :cve_nist:`2026-43227`, :cve_nist:`2026-43230`,
|
||||
:cve_nist:`2026-43231`, :cve_nist:`2026-43232`, :cve_nist:`2026-43233`, :cve_nist:`2026-43236`,
|
||||
:cve_nist:`2026-43238`, :cve_nist:`2026-43239`, :cve_nist:`2026-43240`, :cve_nist:`2026-43241`,
|
||||
:cve_nist:`2026-43242`, :cve_nist:`2026-43245`, :cve_nist:`2026-43246`, :cve_nist:`2026-43251`,
|
||||
:cve_nist:`2026-43252`, :cve_nist:`2026-43253`, :cve_nist:`2026-43255`, :cve_nist:`2026-43256`,
|
||||
:cve_nist:`2026-43257`, :cve_nist:`2026-43261`, :cve_nist:`2026-43262`, :cve_nist:`2026-43264`,
|
||||
:cve_nist:`2026-43265`, :cve_nist:`2026-43266`, :cve_nist:`2026-43268`, :cve_nist:`2026-43269`,
|
||||
:cve_nist:`2026-43270`, :cve_nist:`2026-43271`, :cve_nist:`2026-43273`, :cve_nist:`2026-43275`,
|
||||
:cve_nist:`2026-43277`, :cve_nist:`2026-43278`, :cve_nist:`2026-43279`, :cve_nist:`2026-43281`,
|
||||
:cve_nist:`2026-43283`, :cve_nist:`2026-43284`, :cve_nist:`2026-43287`, :cve_nist:`2026-43288`,
|
||||
:cve_nist:`2026-43289`, :cve_nist:`2026-43291`, :cve_nist:`2026-43295`, :cve_nist:`2026-43296`,
|
||||
:cve_nist:`2026-43302`, :cve_nist:`2026-43304`, :cve_nist:`2026-43312`, :cve_nist:`2026-43313`,
|
||||
:cve_nist:`2026-43314`, :cve_nist:`2026-43315`, :cve_nist:`2026-43316`, :cve_nist:`2026-43324`,
|
||||
:cve_nist:`2026-43327`, :cve_nist:`2026-43328`, :cve_nist:`2026-43329`, :cve_nist:`2026-43330`,
|
||||
:cve_nist:`2026-43332`, :cve_nist:`2026-43333`, :cve_nist:`2026-43334`, :cve_nist:`2026-43336`,
|
||||
:cve_nist:`2026-43339`, :cve_nist:`2026-43340`, :cve_nist:`2026-43341`, :cve_nist:`2026-43342`,
|
||||
:cve_nist:`2026-43343`, :cve_nist:`2026-43345`, :cve_nist:`2026-43350`, :cve_nist:`2026-43355`,
|
||||
:cve_nist:`2026-43357`, :cve_nist:`2026-43359`, :cve_nist:`2026-43360`, :cve_nist:`2026-43361`,
|
||||
:cve_nist:`2026-43362`, :cve_nist:`2026-43363`, :cve_nist:`2026-43365`, :cve_nist:`2026-43366`,
|
||||
:cve_nist:`2026-43368`, :cve_nist:`2026-43370`, :cve_nist:`2026-43371`, :cve_nist:`2026-43372`,
|
||||
:cve_nist:`2026-43373`, :cve_nist:`2026-43376`, :cve_nist:`2026-43377`, :cve_nist:`2026-43378`,
|
||||
:cve_nist:`2026-43379`, :cve_nist:`2026-43380`, :cve_nist:`2026-43381`, :cve_nist:`2026-43382`,
|
||||
:cve_nist:`2026-43383`, :cve_nist:`2026-43386`, :cve_nist:`2026-43387`, :cve_nist:`2026-43397`,
|
||||
:cve_nist:`2026-43405`, :cve_nist:`2026-43406`, :cve_nist:`2026-43407`, :cve_nist:`2026-43409`,
|
||||
:cve_nist:`2026-43411`, :cve_nist:`2026-43412`, :cve_nist:`2026-43413`, :cve_nist:`2026-43415`,
|
||||
:cve_nist:`2026-43419`, :cve_nist:`2026-43420`, :cve_nist:`2026-43424`, :cve_nist:`2026-43425`,
|
||||
:cve_nist:`2026-43426`, :cve_nist:`2026-43427`, :cve_nist:`2026-43428`, :cve_nist:`2026-43429`,
|
||||
:cve_nist:`2026-43430`, :cve_nist:`2026-43432`, :cve_nist:`2026-43436`, :cve_nist:`2026-43437`,
|
||||
:cve_nist:`2026-43439`, :cve_nist:`2026-43441`, :cve_nist:`2026-43445`, :cve_nist:`2026-43448`,
|
||||
:cve_nist:`2026-43449`, :cve_nist:`2026-43450`, :cve_nist:`2026-43451`, :cve_nist:`2026-43452`,
|
||||
:cve_nist:`2026-43453`, :cve_nist:`2026-43455`, :cve_nist:`2026-43457`, :cve_nist:`2026-43458`,
|
||||
:cve_nist:`2026-43459`, :cve_nist:`2026-43466`, :cve_nist:`2026-43468`, :cve_nist:`2026-43469`,
|
||||
:cve_nist:`2026-43471`, :cve_nist:`2026-43472`, :cve_nist:`2026-43473`, :cve_nist:`2026-43475`,
|
||||
:cve_nist:`2026-43476`, :cve_nist:`2026-43480`, :cve_nist:`2026-43483`, :cve_nist:`2026-43484`,
|
||||
:cve_nist:`2026-43488`, :cve_nist:`2026-43490`, :cve_nist:`2026-43491`, :cve_nist:`2026-43492`,
|
||||
:cve_nist:`2026-43493`, :cve_nist:`2026-43494`, :cve_nist:`2026-43495`, :cve_nist:`2026-43496`,
|
||||
:cve_nist:`2026-43497`, :cve_nist:`2026-43499`, :cve_nist:`2026-43500`, :cve_nist:`2026-43501`,
|
||||
:cve_nist:`2026-43502`, :cve_nist:`2026-43503`, :cve_nist:`2026-45834`, :cve_nist:`2026-45835`,
|
||||
:cve_nist:`2026-45836`, :cve_nist:`2026-45838`, :cve_nist:`2026-45839`, :cve_nist:`2026-45840`,
|
||||
:cve_nist:`2026-45841`, :cve_nist:`2026-45842`, :cve_nist:`2026-45843`, :cve_nist:`2026-45844`,
|
||||
:cve_nist:`2026-45845`, :cve_nist:`2026-45846`, :cve_nist:`2026-45847`, :cve_nist:`2026-45848`,
|
||||
:cve_nist:`2026-45849`, :cve_nist:`2026-45851`, :cve_nist:`2026-45852`, :cve_nist:`2026-45856`,
|
||||
:cve_nist:`2026-45857`, :cve_nist:`2026-45858`, :cve_nist:`2026-45860`, :cve_nist:`2026-45862`,
|
||||
:cve_nist:`2026-45864`, :cve_nist:`2026-45865`, :cve_nist:`2026-45866`, :cve_nist:`2026-45867`,
|
||||
:cve_nist:`2026-45868`, :cve_nist:`2026-45869`, :cve_nist:`2026-45870`, :cve_nist:`2026-45871`,
|
||||
:cve_nist:`2026-45872`, :cve_nist:`2026-45873`, :cve_nist:`2026-45875`, :cve_nist:`2026-45878`,
|
||||
:cve_nist:`2026-45879`, :cve_nist:`2026-45880`, :cve_nist:`2026-45881`, :cve_nist:`2026-45883`,
|
||||
:cve_nist:`2026-45885`, :cve_nist:`2026-45886`, :cve_nist:`2026-45890`, :cve_nist:`2026-45891`,
|
||||
:cve_nist:`2026-45895`, :cve_nist:`2026-45899`, :cve_nist:`2026-45902`, :cve_nist:`2026-45904`,
|
||||
:cve_nist:`2026-45905`, :cve_nist:`2026-45910`, :cve_nist:`2026-45911`, :cve_nist:`2026-45912`,
|
||||
:cve_nist:`2026-45913`, :cve_nist:`2026-45914`, :cve_nist:`2026-45915`, :cve_nist:`2026-45916`,
|
||||
:cve_nist:`2026-45919`, :cve_nist:`2026-45920`, :cve_nist:`2026-45921`, :cve_nist:`2026-45923`,
|
||||
:cve_nist:`2026-45924`, :cve_nist:`2026-45935`, :cve_nist:`2026-45936`, :cve_nist:`2026-45941`,
|
||||
:cve_nist:`2026-45942`, :cve_nist:`2026-45946`, :cve_nist:`2026-45947`, :cve_nist:`2026-45948`,
|
||||
:cve_nist:`2026-45954`, :cve_nist:`2026-45956`, :cve_nist:`2026-45957`, :cve_nist:`2026-45958`,
|
||||
:cve_nist:`2026-45960`, :cve_nist:`2026-45962`, :cve_nist:`2026-45964`, :cve_nist:`2026-45965`,
|
||||
:cve_nist:`2026-45968`, :cve_nist:`2026-45969`, :cve_nist:`2026-45970`, :cve_nist:`2026-45972`,
|
||||
:cve_nist:`2026-45974`, :cve_nist:`2026-45976`, :cve_nist:`2026-45978`, :cve_nist:`2026-45981`,
|
||||
:cve_nist:`2026-45982`, :cve_nist:`2026-45983`, :cve_nist:`2026-45984`, :cve_nist:`2026-45985`,
|
||||
:cve_nist:`2026-45986`, :cve_nist:`2026-45987`, :cve_nist:`2026-45988`, :cve_nist:`2026-45989`,
|
||||
:cve_nist:`2026-45991`, :cve_nist:`2026-45993`, :cve_nist:`2026-45994`, :cve_nist:`2026-45996`,
|
||||
:cve_nist:`2026-45997`, :cve_nist:`2026-45998`, :cve_nist:`2026-45999`, :cve_nist:`2026-46000`,
|
||||
:cve_nist:`2026-46002`, :cve_nist:`2026-46003`, :cve_nist:`2026-46004`, :cve_nist:`2026-46005`,
|
||||
:cve_nist:`2026-46006`, :cve_nist:`2026-46009`, :cve_nist:`2026-46011`, :cve_nist:`2026-46012`,
|
||||
:cve_nist:`2026-46015`, :cve_nist:`2026-46016`, :cve_nist:`2026-46018`, :cve_nist:`2026-46019`,
|
||||
:cve_nist:`2026-46021`, :cve_nist:`2026-46022`, :cve_nist:`2026-46023`, :cve_nist:`2026-46024`,
|
||||
:cve_nist:`2026-46026`, :cve_nist:`2026-46027`, :cve_nist:`2026-46028`, :cve_nist:`2026-46031`,
|
||||
:cve_nist:`2026-46033`, :cve_nist:`2026-46037`, :cve_nist:`2026-46038`, :cve_nist:`2026-46040`,
|
||||
:cve_nist:`2026-46043`, :cve_nist:`2026-46046`, :cve_nist:`2026-46047`, :cve_nist:`2026-46049`,
|
||||
:cve_nist:`2026-46050`, :cve_nist:`2026-46051`, :cve_nist:`2026-46052`, :cve_nist:`2026-46053`,
|
||||
:cve_nist:`2026-46056`, :cve_nist:`2026-46058`, :cve_nist:`2026-46062`, :cve_nist:`2026-46063`,
|
||||
:cve_nist:`2026-46064`, :cve_nist:`2026-46065`, :cve_nist:`2026-46068`, :cve_nist:`2026-46069`,
|
||||
:cve_nist:`2026-46070`, :cve_nist:`2026-46072`, :cve_nist:`2026-46075`, :cve_nist:`2026-46077`,
|
||||
:cve_nist:`2026-46078`, :cve_nist:`2026-46079`, :cve_nist:`2026-46080`, :cve_nist:`2026-46082`,
|
||||
:cve_nist:`2026-46083`, :cve_nist:`2026-46084`, :cve_nist:`2026-46086`, :cve_nist:`2026-46088`,
|
||||
:cve_nist:`2026-46089`, :cve_nist:`2026-46091`, :cve_nist:`2026-46094`, :cve_nist:`2026-46098`,
|
||||
:cve_nist:`2026-46099`, :cve_nist:`2026-46101`, :cve_nist:`2026-46102`, :cve_nist:`2026-46103`,
|
||||
:cve_nist:`2026-46106`, :cve_nist:`2026-46107`, :cve_nist:`2026-46108`, :cve_nist:`2026-46110`,
|
||||
:cve_nist:`2026-46111`, :cve_nist:`2026-46112`, :cve_nist:`2026-46113`, :cve_nist:`2026-46114`,
|
||||
:cve_nist:`2026-46115`, :cve_nist:`2026-46116`, :cve_nist:`2026-46119`, :cve_nist:`2026-46120`,
|
||||
:cve_nist:`2026-46121`, :cve_nist:`2026-46122`, :cve_nist:`2026-46123`, :cve_nist:`2026-46124`,
|
||||
:cve_nist:`2026-46125`, :cve_nist:`2026-46127`, :cve_nist:`2026-46128`, :cve_nist:`2026-46129`,
|
||||
:cve_nist:`2026-46131`, :cve_nist:`2026-46132`, :cve_nist:`2026-46133`, :cve_nist:`2026-46136`,
|
||||
:cve_nist:`2026-46137`, :cve_nist:`2026-46138`, :cve_nist:`2026-46142`, :cve_nist:`2026-46143`,
|
||||
:cve_nist:`2026-46144`, :cve_nist:`2026-46145`, :cve_nist:`2026-46146`, :cve_nist:`2026-46149`,
|
||||
:cve_nist:`2026-46150`, :cve_nist:`2026-46151`, :cve_nist:`2026-46152`, :cve_nist:`2026-46155`,
|
||||
:cve_nist:`2026-46158`, :cve_nist:`2026-46159`, :cve_nist:`2026-46160`, :cve_nist:`2026-46161`,
|
||||
:cve_nist:`2026-46163`, :cve_nist:`2026-46164`, :cve_nist:`2026-46167`, :cve_nist:`2026-46168`,
|
||||
:cve_nist:`2026-46169`, :cve_nist:`2026-46170`, :cve_nist:`2026-46172`, :cve_nist:`2026-46173`,
|
||||
:cve_nist:`2026-46174`, :cve_nist:`2026-46176`, :cve_nist:`2026-46177`, :cve_nist:`2026-46178`,
|
||||
:cve_nist:`2026-46179`, :cve_nist:`2026-46180`, :cve_nist:`2026-46184`, :cve_nist:`2026-46185`,
|
||||
:cve_nist:`2026-46186`, :cve_nist:`2026-46187`, :cve_nist:`2026-46189`, :cve_nist:`2026-46190`,
|
||||
:cve_nist:`2026-46191`, :cve_nist:`2026-46193`, :cve_nist:`2026-46194`, :cve_nist:`2026-46195`,
|
||||
:cve_nist:`2026-46196`, :cve_nist:`2026-46197`, :cve_nist:`2026-46198`, :cve_nist:`2026-46199`,
|
||||
:cve_nist:`2026-46204`, :cve_nist:`2026-46205`, :cve_nist:`2026-46206`, :cve_nist:`2026-46208`,
|
||||
:cve_nist:`2026-46209`, :cve_nist:`2026-46212`, :cve_nist:`2026-46214`, :cve_nist:`2026-46218`,
|
||||
:cve_nist:`2026-46219`, :cve_nist:`2026-46220`, :cve_nist:`2026-46225`, :cve_nist:`2026-46226`,
|
||||
:cve_nist:`2026-46227`, :cve_nist:`2026-46229`, :cve_nist:`2026-46230`, :cve_nist:`2026-46231`,
|
||||
:cve_nist:`2026-46232`, :cve_nist:`2026-46233`, :cve_nist:`2026-46234`, :cve_nist:`2026-46235`,
|
||||
:cve_nist:`2026-46236`, :cve_nist:`2026-46238`, :cve_nist:`2026-46243`, :cve_nist:`2026-46244`,
|
||||
:cve_nist:`2026-46247`, :cve_nist:`2026-46249`, :cve_nist:`2026-46250`, :cve_nist:`2026-46251`,
|
||||
:cve_nist:`2026-46253`, :cve_nist:`2026-46255`, :cve_nist:`2026-46259`, :cve_nist:`2026-46260`,
|
||||
:cve_nist:`2026-46261`, :cve_nist:`2026-46262`, :cve_nist:`2026-46265`, :cve_nist:`2026-46266`,
|
||||
:cve_nist:`2026-46267`, :cve_nist:`2026-46270`, :cve_nist:`2026-46273`, :cve_nist:`2026-46274`,
|
||||
:cve_nist:`2026-46275`, :cve_nist:`2026-46276`, :cve_nist:`2026-46280`, :cve_nist:`2026-46285`,
|
||||
:cve_nist:`2026-46286`, :cve_nist:`2026-46287`, :cve_nist:`2026-46289`, :cve_nist:`2026-46291`,
|
||||
:cve_nist:`2026-46292`, :cve_nist:`2026-46293`, :cve_nist:`2026-46294`, :cve_nist:`2026-46296`,
|
||||
:cve_nist:`2026-46299`, :cve_nist:`2026-46300`, :cve_nist:`2026-46301`, :cve_nist:`2026-46303`,
|
||||
:cve_nist:`2026-46304`, :cve_nist:`2026-46306`, :cve_nist:`2026-46307`, :cve_nist:`2026-46312`,
|
||||
:cve_nist:`2026-46319`, :cve_nist:`2026-46323`, :cve_nist:`2026-46328`, :cve_nist:`2026-46333`,
|
||||
:cve_nist:`2026-52911`, :cve_nist:`2026-52912`, :cve_nist:`2026-52914`, :cve_nist:`2026-52915`,
|
||||
:cve_nist:`2026-52916`, :cve_nist:`2026-52918`, :cve_nist:`2026-52919`, :cve_nist:`2026-52920`,
|
||||
:cve_nist:`2026-52921`, :cve_nist:`2026-52922`, :cve_nist:`2026-52923`, :cve_nist:`2026-52925`,
|
||||
:cve_nist:`2026-52926`, :cve_nist:`2026-52931`, :cve_nist:`2026-52933`, :cve_nist:`2026-52936`,
|
||||
:cve_nist:`2026-52941`, :cve_nist:`2026-53128`, :cve_nist:`2026-53130`, :cve_nist:`2026-53279`,
|
||||
:cve_nist:`2026-53287`, :cve_nist:`2026-53289`, :cve_nist:`2026-53291`, :cve_nist:`2026-53293`,
|
||||
:cve_nist:`2026-53294`, :cve_nist:`2026-53295`, :cve_nist:`2026-53296`, :cve_nist:`2026-53303`,
|
||||
:cve_nist:`2026-53304`, :cve_nist:`2026-53306`, :cve_nist:`2026-53309`, :cve_nist:`2026-53314`
|
||||
and :cve_nist:`2026-53320`
|
||||
- linux-yocto/6.6: Ignore :cve_nist:`2023-53012`, :cve_nist:`2023-53187`, :cve_nist:`2024-26949`,
|
||||
:cve_nist:`2024-26997`, :cve_nist:`2024-35983`, :cve_nist:`2024-36002`, :cve_nist:`2024-36288`,
|
||||
:cve_nist:`2024-38542`, :cve_nist:`2024-38595`, :cve_nist:`2024-40920`, :cve_nist:`2024-40921`,
|
||||
:cve_nist:`2024-40986`, :cve_nist:`2024-42111`, :cve_nist:`2024-42112`, :cve_nist:`2024-42150`,
|
||||
:cve_nist:`2024-43820`, :cve_nist:`2024-43838`, :cve_nist:`2024-47711`, :cve_nist:`2024-49854`,
|
||||
:cve_nist:`2024-50042`, :cve_nist:`2024-50097`, :cve_nist:`2024-50203`, :cve_nist:`2024-50206`,
|
||||
:cve_nist:`2024-50238`, :cve_nist:`2024-50241`, :cve_nist:`2024-50249`, :cve_nist:`2024-50281`,
|
||||
:cve_nist:`2024-53073`, :cve_nist:`2024-53097`, :cve_nist:`2024-53115`, :cve_nist:`2024-53133`,
|
||||
:cve_nist:`2024-53169`, :cve_nist:`2024-53201`, :cve_nist:`2024-54191`, :cve_nist:`2024-54460`,
|
||||
:cve_nist:`2024-56542`, :cve_nist:`2024-56550`, :cve_nist:`2024-56561`, :cve_nist:`2024-56782`,
|
||||
:cve_nist:`2024-57805`, :cve_nist:`2024-57852`, :cve_nist:`2024-57879`, :cve_nist:`2024-57935`,
|
||||
:cve_nist:`2024-57952`, :cve_nist:`2024-57990`, :cve_nist:`2024-58008`, :cve_nist:`2024-58081`,
|
||||
:cve_nist:`2025-21752`, :cve_nist:`2025-21809`, :cve_nist:`2025-21813`, :cve_nist:`2025-21902`,
|
||||
:cve_nist:`2025-22026`, :cve_nist:`2025-22030`, :cve_nist:`2025-22032`, :cve_nist:`2025-22069`,
|
||||
:cve_nist:`2025-22112`, :cve_nist:`2025-37760`, :cve_nist:`2025-37814`, :cve_nist:`2025-37827`,
|
||||
:cve_nist:`2025-37845`, :cve_nist:`2025-37868`, :cve_nist:`2025-37871`, :cve_nist:`2025-37878`,
|
||||
:cve_nist:`2025-37895`, :cve_nist:`2025-37929`, :cve_nist:`2025-37962`, :cve_nist:`2025-37974`,
|
||||
:cve_nist:`2025-38055`, :cve_nist:`2025-38098`, :cve_nist:`2025-38099`, :cve_nist:`2025-38162`,
|
||||
:cve_nist:`2025-38169`, :cve_nist:`2025-38201`, :cve_nist:`2025-38224`, :cve_nist:`2025-38234`,
|
||||
:cve_nist:`2025-38289`, :cve_nist:`2025-38325`, :cve_nist:`2025-38372`, :cve_nist:`2025-38373`,
|
||||
:cve_nist:`2025-38405`, :cve_nist:`2025-38421`, :cve_nist:`2025-38484`, :cve_nist:`2025-38551`,
|
||||
:cve_nist:`2025-38567`, :cve_nist:`2025-38675`, :cve_nist:`2025-38733`, :cve_nist:`2025-38736`,
|
||||
:cve_nist:`2025-39688`, :cve_nist:`2025-39725`, :cve_nist:`2025-39775`, :cve_nist:`2025-39807`,
|
||||
:cve_nist:`2025-39872`, :cve_nist:`2025-39930`, :cve_nist:`2025-39948`, :cve_nist:`2025-39965`,
|
||||
:cve_nist:`2025-39999`, :cve_nist:`2025-40005`, :cve_nist:`2025-40007`, :cve_nist:`2025-40082`,
|
||||
:cve_nist:`2025-40101`, :cve_nist:`2025-40131`, :cve_nist:`2025-40199`, :cve_nist:`2025-40213`,
|
||||
:cve_nist:`2025-40290`, :cve_nist:`2025-40327`, :cve_nist:`2025-40332`, :cve_nist:`2025-40344`,
|
||||
:cve_nist:`2025-68195`, :cve_nist:`2025-68207`, :cve_nist:`2025-68213`, :cve_nist:`2025-68215`,
|
||||
:cve_nist:`2025-68298`, :cve_nist:`2025-68351`, :cve_nist:`2025-68357`, :cve_nist:`2025-68358`,
|
||||
:cve_nist:`2025-68823`, :cve_nist:`2025-71070`, :cve_nist:`2025-71076`, :cve_nist:`2025-71135`,
|
||||
:cve_nist:`2025-71145`, :cve_nist:`2025-71146`, :cve_nist:`2025-71155`, :cve_nist:`2025-71204`,
|
||||
:cve_nist:`2025-71220`, :cve_nist:`2025-71222`, :cve_nist:`2025-71223`, :cve_nist:`2025-71224`,
|
||||
:cve_nist:`2025-71229`, :cve_nist:`2025-71232`, :cve_nist:`2025-71233`, :cve_nist:`2025-71235`,
|
||||
:cve_nist:`2025-71236`, :cve_nist:`2025-71237`, :cve_nist:`2025-71238`, :cve_nist:`2025-71268`,
|
||||
:cve_nist:`2025-71270`, :cve_nist:`2025-71271`, :cve_nist:`2025-71290`, :cve_nist:`2025-71293`,
|
||||
:cve_nist:`2025-71294`, :cve_nist:`2025-71296`, :cve_nist:`2025-71298`, :cve_nist:`2025-71299`,
|
||||
:cve_nist:`2025-71300`, :cve_nist:`2025-71301`, :cve_nist:`2025-71302`, :cve_nist:`2026-23014`,
|
||||
:cve_nist:`2026-23018`, :cve_nist:`2026-23079`, :cve_nist:`2026-23100`, :cve_nist:`2026-23111`,
|
||||
:cve_nist:`2026-23112`, :cve_nist:`2026-23143`, :cve_nist:`2026-23148`, :cve_nist:`2026-23151`,
|
||||
:cve_nist:`2026-23166`, :cve_nist:`2026-23169`, :cve_nist:`2026-23176`, :cve_nist:`2026-23178`,
|
||||
:cve_nist:`2026-23180`, :cve_nist:`2026-23182`, :cve_nist:`2026-23187`, :cve_nist:`2026-23189`,
|
||||
:cve_nist:`2026-23190`, :cve_nist:`2026-23193`, :cve_nist:`2026-23198`, :cve_nist:`2026-23200`,
|
||||
:cve_nist:`2026-23201`, :cve_nist:`2026-23202`, :cve_nist:`2026-23204`, :cve_nist:`2026-23205`,
|
||||
:cve_nist:`2026-23206`, :cve_nist:`2026-23209`, :cve_nist:`2026-23216`, :cve_nist:`2026-23217`,
|
||||
:cve_nist:`2026-23220`, :cve_nist:`2026-23221`, :cve_nist:`2026-23222`, :cve_nist:`2026-23228`,
|
||||
:cve_nist:`2026-23229`, :cve_nist:`2026-23230`, :cve_nist:`2026-23233`, :cve_nist:`2026-23234`,
|
||||
:cve_nist:`2026-23235`, :cve_nist:`2026-23236`, :cve_nist:`2026-23237`, :cve_nist:`2026-23238`,
|
||||
:cve_nist:`2026-23254`, :cve_nist:`2026-23256`, :cve_nist:`2026-23257`, :cve_nist:`2026-23258`,
|
||||
:cve_nist:`2026-23260`, :cve_nist:`2026-23261`, :cve_nist:`2026-23262`, :cve_nist:`2026-23264`,
|
||||
:cve_nist:`2026-23266`, :cve_nist:`2026-23267`, :cve_nist:`2026-23288`, :cve_nist:`2026-23341`,
|
||||
:cve_nist:`2026-23355`, :cve_nist:`2026-23376`, :cve_nist:`2026-23418`, :cve_nist:`2026-23421`,
|
||||
:cve_nist:`2026-23423`, :cve_nist:`2026-23424`, :cve_nist:`2026-23425`, :cve_nist:`2026-23429`,
|
||||
:cve_nist:`2026-23430`, :cve_nist:`2026-23431`, :cve_nist:`2026-23432`, :cve_nist:`2026-23433`,
|
||||
:cve_nist:`2026-23435`, :cve_nist:`2026-23436`, :cve_nist:`2026-23437`, :cve_nist:`2026-23445`,
|
||||
:cve_nist:`2026-23451`, :cve_nist:`2026-23453`, :cve_nist:`2026-23459`, :cve_nist:`2026-23464`,
|
||||
:cve_nist:`2026-23466`, :cve_nist:`2026-23467`, :cve_nist:`2026-23469`, :cve_nist:`2026-23470`,
|
||||
:cve_nist:`2026-31390`, :cve_nist:`2026-31394`, :cve_nist:`2026-31395`, :cve_nist:`2026-31397`,
|
||||
:cve_nist:`2026-31398`, :cve_nist:`2026-31401`, :cve_nist:`2026-31404`, :cve_nist:`2026-31406`,
|
||||
:cve_nist:`2026-31413`, :cve_nist:`2026-31435`, :cve_nist:`2026-31436`, :cve_nist:`2026-31437`,
|
||||
:cve_nist:`2026-31438`, :cve_nist:`2026-31442`, :cve_nist:`2026-31443`, :cve_nist:`2026-31444`,
|
||||
:cve_nist:`2026-31445`, :cve_nist:`2026-31456`, :cve_nist:`2026-31457`, :cve_nist:`2026-31459`,
|
||||
:cve_nist:`2026-31460`, :cve_nist:`2026-31461`, :cve_nist:`2026-31463`, :cve_nist:`2026-31465`,
|
||||
:cve_nist:`2026-31468`, :cve_nist:`2026-31470`, :cve_nist:`2026-31471`, :cve_nist:`2026-31472`,
|
||||
:cve_nist:`2026-31475`, :cve_nist:`2026-31479`, :cve_nist:`2026-31481`, :cve_nist:`2026-31484`,
|
||||
:cve_nist:`2026-31490`, :cve_nist:`2026-31491`, :cve_nist:`2026-31499`, :cve_nist:`2026-31501`,
|
||||
:cve_nist:`2026-31511`, :cve_nist:`2026-31513`, :cve_nist:`2026-31514`, :cve_nist:`2026-31517`,
|
||||
:cve_nist:`2026-31526`, :cve_nist:`2026-31529`, :cve_nist:`2026-31535`, :cve_nist:`2026-31538`,
|
||||
:cve_nist:`2026-31539`, :cve_nist:`2026-31541`, :cve_nist:`2026-31543`, :cve_nist:`2026-31544`,
|
||||
:cve_nist:`2026-31547`, :cve_nist:`2026-31553`, :cve_nist:`2026-31554`, :cve_nist:`2026-31556`,
|
||||
:cve_nist:`2026-31558`, :cve_nist:`2026-31559`, :cve_nist:`2026-31561`, :cve_nist:`2026-31562`,
|
||||
:cve_nist:`2026-31564`, :cve_nist:`2026-31567`, :cve_nist:`2026-31569`, :cve_nist:`2026-31571`,
|
||||
:cve_nist:`2026-31572`, :cve_nist:`2026-31573`, :cve_nist:`2026-31574`, :cve_nist:`2026-31575`,
|
||||
:cve_nist:`2026-31582`, :cve_nist:`2026-31589`, :cve_nist:`2026-31591`, :cve_nist:`2026-31593`,
|
||||
:cve_nist:`2026-31600`, :cve_nist:`2026-31601`, :cve_nist:`2026-31608`, :cve_nist:`2026-31609`,
|
||||
:cve_nist:`2026-31620`, :cve_nist:`2026-31621`, :cve_nist:`2026-31631`, :cve_nist:`2026-31632`,
|
||||
:cve_nist:`2026-31633`, :cve_nist:`2026-31635`, :cve_nist:`2026-31636`, :cve_nist:`2026-31640`,
|
||||
:cve_nist:`2026-31641`, :cve_nist:`2026-31643`, :cve_nist:`2026-31644`, :cve_nist:`2026-31647`,
|
||||
:cve_nist:`2026-31650`, :cve_nist:`2026-31652`, :cve_nist:`2026-31653`, :cve_nist:`2026-31654`,
|
||||
:cve_nist:`2026-31666`, :cve_nist:`2026-31687`, :cve_nist:`2026-31690`, :cve_nist:`2026-31691`,
|
||||
:cve_nist:`2026-31703`, :cve_nist:`2026-31710`, :cve_nist:`2026-31713`, :cve_nist:`2026-31719`,
|
||||
:cve_nist:`2026-31727`, :cve_nist:`2026-31731`, :cve_nist:`2026-31732`, :cve_nist:`2026-31733`,
|
||||
:cve_nist:`2026-31734`, :cve_nist:`2026-31735`, :cve_nist:`2026-31736`, :cve_nist:`2026-31739`,
|
||||
:cve_nist:`2026-31742`, :cve_nist:`2026-31743`, :cve_nist:`2026-31744`, :cve_nist:`2026-31745`,
|
||||
:cve_nist:`2026-31746`, :cve_nist:`2026-31750`, :cve_nist:`2026-31753`, :cve_nist:`2026-31757`,
|
||||
:cve_nist:`2026-31760`, :cve_nist:`2026-31764`, :cve_nist:`2026-31765`, :cve_nist:`2026-31766`,
|
||||
:cve_nist:`2026-31769`, :cve_nist:`2026-31772`, :cve_nist:`2026-31774`, :cve_nist:`2026-31775`,
|
||||
:cve_nist:`2026-31776`, :cve_nist:`2026-31782`, :cve_nist:`2026-31783`, :cve_nist:`2026-31784`,
|
||||
:cve_nist:`2026-31785`, :cve_nist:`2026-43004`, :cve_nist:`2026-43005`, :cve_nist:`2026-43006`,
|
||||
:cve_nist:`2026-43008`, :cve_nist:`2026-43012`, :cve_nist:`2026-43021`, :cve_nist:`2026-43031`,
|
||||
:cve_nist:`2026-43034`, :cve_nist:`2026-43039`, :cve_nist:`2026-43045`, :cve_nist:`2026-43055`,
|
||||
:cve_nist:`2026-43059`, :cve_nist:`2026-43063`, :cve_nist:`2026-43070`, :cve_nist:`2026-43084`,
|
||||
:cve_nist:`2026-43087`, :cve_nist:`2026-43090`, :cve_nist:`2026-43095`, :cve_nist:`2026-43096`,
|
||||
:cve_nist:`2026-43097`, :cve_nist:`2026-43100`, :cve_nist:`2026-43102`, :cve_nist:`2026-43106`,
|
||||
:cve_nist:`2026-43108`, :cve_nist:`2026-43121`, :cve_nist:`2026-43122`, :cve_nist:`2026-43131`,
|
||||
:cve_nist:`2026-43138`, :cve_nist:`2026-43142`, :cve_nist:`2026-43144`, :cve_nist:`2026-43146`,
|
||||
:cve_nist:`2026-43151`, :cve_nist:`2026-43154`, :cve_nist:`2026-43155`, :cve_nist:`2026-43160`,
|
||||
:cve_nist:`2026-43164`, :cve_nist:`2026-43165`, :cve_nist:`2026-43166`, :cve_nist:`2026-43169`,
|
||||
:cve_nist:`2026-43174`, :cve_nist:`2026-43175`, :cve_nist:`2026-43176`, :cve_nist:`2026-43177`,
|
||||
:cve_nist:`2026-43178`, :cve_nist:`2026-43179`, :cve_nist:`2026-43181`, :cve_nist:`2026-43188`,
|
||||
:cve_nist:`2026-43191`, :cve_nist:`2026-43192`, :cve_nist:`2026-43193`, :cve_nist:`2026-43195`,
|
||||
:cve_nist:`2026-43201`, :cve_nist:`2026-43208`, :cve_nist:`2026-43210`, :cve_nist:`2026-43217`,
|
||||
:cve_nist:`2026-43220`, :cve_nist:`2026-43224`, :cve_nist:`2026-43228`, :cve_nist:`2026-43229`,
|
||||
:cve_nist:`2026-43235`, :cve_nist:`2026-43237`, :cve_nist:`2026-43243`, :cve_nist:`2026-43247`,
|
||||
:cve_nist:`2026-43254`, :cve_nist:`2026-43259`, :cve_nist:`2026-43260`, :cve_nist:`2026-43263`,
|
||||
:cve_nist:`2026-43267`, :cve_nist:`2026-43272`, :cve_nist:`2026-43274`, :cve_nist:`2026-43276`,
|
||||
:cve_nist:`2026-43280`, :cve_nist:`2026-43282`, :cve_nist:`2026-43285`, :cve_nist:`2026-43286`,
|
||||
:cve_nist:`2026-43290`, :cve_nist:`2026-43292`, :cve_nist:`2026-43293`, :cve_nist:`2026-43297`,
|
||||
:cve_nist:`2026-43300`, :cve_nist:`2026-43301`, :cve_nist:`2026-43305`, :cve_nist:`2026-43306`,
|
||||
:cve_nist:`2026-43307`, :cve_nist:`2026-43320`, :cve_nist:`2026-43321`, :cve_nist:`2026-43322`,
|
||||
:cve_nist:`2026-43323`, :cve_nist:`2026-43325`, :cve_nist:`2026-43326`, :cve_nist:`2026-43335`,
|
||||
:cve_nist:`2026-43337`, :cve_nist:`2026-43346`, :cve_nist:`2026-43347`, :cve_nist:`2026-43348`,
|
||||
:cve_nist:`2026-43349`, :cve_nist:`2026-43351`, :cve_nist:`2026-43354`, :cve_nist:`2026-43356`,
|
||||
:cve_nist:`2026-43358`, :cve_nist:`2026-43364`, :cve_nist:`2026-43367`, :cve_nist:`2026-43369`,
|
||||
:cve_nist:`2026-43374`, :cve_nist:`2026-43375`, :cve_nist:`2026-43384`, :cve_nist:`2026-43385`,
|
||||
:cve_nist:`2026-43388`, :cve_nist:`2026-43389`, :cve_nist:`2026-43390`, :cve_nist:`2026-43391`,
|
||||
:cve_nist:`2026-43392`, :cve_nist:`2026-43393`, :cve_nist:`2026-43394`, :cve_nist:`2026-43395`,
|
||||
:cve_nist:`2026-43396`, :cve_nist:`2026-43398`, :cve_nist:`2026-43399`, :cve_nist:`2026-43400`,
|
||||
:cve_nist:`2026-43401`, :cve_nist:`2026-43402`, :cve_nist:`2026-43403`, :cve_nist:`2026-43404`,
|
||||
:cve_nist:`2026-43408`, :cve_nist:`2026-43410`, :cve_nist:`2026-43417`, :cve_nist:`2026-43418`,
|
||||
:cve_nist:`2026-43422`, :cve_nist:`2026-43423`, :cve_nist:`2026-43431`, :cve_nist:`2026-43433`,
|
||||
:cve_nist:`2026-43434`, :cve_nist:`2026-43435`, :cve_nist:`2026-43438`, :cve_nist:`2026-43440`,
|
||||
:cve_nist:`2026-43442`, :cve_nist:`2026-43444`, :cve_nist:`2026-43446`, :cve_nist:`2026-43447`,
|
||||
:cve_nist:`2026-43454`, :cve_nist:`2026-43460`, :cve_nist:`2026-43461`, :cve_nist:`2026-43462`,
|
||||
:cve_nist:`2026-43463`, :cve_nist:`2026-43467`, :cve_nist:`2026-43470`, :cve_nist:`2026-43474`,
|
||||
:cve_nist:`2026-43477`, :cve_nist:`2026-43478`, :cve_nist:`2026-43479`, :cve_nist:`2026-43481`,
|
||||
:cve_nist:`2026-43482`, :cve_nist:`2026-43485`, :cve_nist:`2026-43486`, :cve_nist:`2026-43487`,
|
||||
:cve_nist:`2026-43489` and :cve_nist:`2026-43498`
|
||||
- lz4: Remove a reference to the rejected :cve_nist:`2025-62813`
|
||||
- nfs-utils: Fix :cve_nist:`2025-12801`
|
||||
- openssh: Fix :cve_nist:`2026-35386`, :cve_nist:`2026-35385`, :cve_nist:`2026-35387` and
|
||||
:cve_nist:`2026-35388`
|
||||
- python3-requests: Fix :cve_nist:`2026-25645`
|
||||
- python3: Fix :cve_nist:`2025-13462`, :cve_nist:`2026-0672`, :cve_nist:`2026-1502`,
|
||||
:cve_nist:`2026-3644`, :cve_nist:`2026-4224`, :cve_nist:`2026-4519`, :cve_nist:`2026-4786`,
|
||||
:cve_nist:`2026-6019` and :cve_nist:`2026-6100`
|
||||
- python3: Ignore :cve_nist:`2026-3087`
|
||||
- qemu: Fix :cve_nist:`2024-6519`
|
||||
- qemu: fix :cve_nist:`2025-11234`
|
||||
- rust,libstd-rs: Ignore :cve_nist:`2024-3566`
|
||||
- tiff: fix :cve_nist:`2026-4775`
|
||||
- util-linux: Fix :cve_nist:`2026-27456`
|
||||
- xserver-xorg: Fix :cve_nist:`2026-33999`, :cve_nist:`2026-34000`, :cve_nist:`2026-34001`,
|
||||
:cve_nist:`2026-34002` and :cve_nist:`2026-34003`
|
||||
- xwayland: Fix :cve_nist:`2026-33999`, :cve_nist:`2026-34000`, :cve_nist:`2026-34001`,
|
||||
:cve_nist:`2026-34002` and :cve_nist:`2026-34003`
|
||||
- xz: Fix :cve_nist:`2026-34743`
|
||||
|
||||
Fixes in Yocto-5.0.19
|
||||
~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
- apr-util: Add :term:`CVE_PRODUCT` to support product name
|
||||
- apr: Add :term:`CVE_PRODUCT` to support product name
|
||||
- bitbake: data: fix issue with varflag exclusion
|
||||
- bitbake: fetch2/git: quote shallow extra ref arguments
|
||||
- bitbake: fetch2/wget: handle HTTP 308 Permanent Redirect
|
||||
- bitbake: fetch2/wget: limit auth on checkstatus redirects
|
||||
- bitbake: fetch2: Unpack RPMs with --no-absolute-filenames
|
||||
- bitbake: fetch2: validate deb/ipk data member names
|
||||
- bitbake: fetch2: validate striplevel parameter
|
||||
- bitbake: hashserv/tests: use valid 64-character unihashes
|
||||
- bitbake: hashserv: validate unihash values
|
||||
- bitbake: tests/fetch: cover checkstatus redirect auth handling
|
||||
- bsp-guide: mention bootloader and device tree in BSP intro
|
||||
- bsp-guide: update guide to reflect newer beaglebone
|
||||
- build-appliance-image: Update to scarthgap head revisions
|
||||
- build-manual: update :term:`ROOTFS_POSTPROCESS_COMMAND` example
|
||||
- bzip2: set :term:`CVE_PRODUCT`
|
||||
- cargo: set :term:`CVE_PRODUCT`
|
||||
- classes/base: prefer gnu-prefixed :term:`HOSTTOOLS`
|
||||
- classes/gtk-icon-cache: fix libdir passed to the postrm intercept
|
||||
- conf/machine: fix typos in ARM and x86 README files
|
||||
- contributor-guide: couple minor typo/grammar fixes
|
||||
- contributor-guide: fix type "maintainance" to "maintenance"
|
||||
- dev-manual: drop "PREFERRED_VERSION" from x86-base.inc snippet
|
||||
- dev-manual: fix broken grammar in "Libraries" section
|
||||
- dev-manual: fix grammatical error, missing word "with"
|
||||
- dev-manual: fully define SOLIBS-related variables in bitbake.conf
|
||||
- dev-manual: remove semicolons for rootfs commands
|
||||
- dev-manual: SysVinit is the default init manager for Poky
|
||||
- dev-manual: update :term:`AUTOREV` explanation to match current file
|
||||
- devtool: prevent 'devtool modify -n' from corrupting kernel Git repos
|
||||
- docs: conf.py: add a :yocto_bug: role
|
||||
- docs: conf.py: define new \*_path roles
|
||||
- docs: conf.py: define new {oecore,bitbake,meta_yocto}_rev roles
|
||||
- docs: index.rst: update "Software Overview" to "Technical Overview"
|
||||
- docs: "Transitioning ..." Various pedantic cleanups
|
||||
- docs: What I Wish I'd Known: Various pedantic cleanups
|
||||
- docs: YP Quick Build: delete extraneous periods in list
|
||||
- gawk-native: fix gcc-15/C23 compilation issues
|
||||
- gawk: trim native build configuration
|
||||
- gawk: use native gawk when building glibc and grub
|
||||
- gdb: backport a patch to fix static_assert in recent GCC
|
||||
- gnupg: upgrade to 2.4.9
|
||||
- go.bbclass: change GOTMPDIR to improve reproducibility
|
||||
- go.bbclass: disable workspaces
|
||||
- grub/glibc: Bump versions to resolve hashequiv/reproducibility issues
|
||||
- kernel-dev: remove references to defunct LTSI project
|
||||
- linux-yocto/6.6: address ltp hang
|
||||
- linux-yocto/6.6: genericarm64 fix configuration audit warning
|
||||
- linux-yocto/6.6: update to v6.6.142
|
||||
- lttng-modules: Fix trace_hrtimer_start build failure
|
||||
- meta/lib/oe/package.py: fix path to kernel sources in save_debugsources_info
|
||||
- meta: fix generation of kernel CONFIGi\_ in SPDX3
|
||||
- migration-guide: add release notes for 4.0.35 5.0.18
|
||||
- oeqa/core/runner: stub addDuration in OETestResult
|
||||
- oeqa/runtime/parselogs: update pci BAR ignore for kernel 6.10
|
||||
- oeqa: Drop /git/ from our urls
|
||||
- oeqa: runtime: go: Increase test_go_compile/test_go_module timeout
|
||||
- openssl: upgrade to 3.5.7
|
||||
- overview-manual: add ":term:" for OE Build System
|
||||
- overview-manual: fix "checkout" versus "check out"
|
||||
- overview-manual: fix typo, "semi-colon" -> "colon"
|
||||
- overview-manual: hyphens not allowed in file version
|
||||
- overview-manual: inform the reader early of "bitbake-getvar"
|
||||
- overview-manual: mention that patch files can be compressed
|
||||
- overview-manual: provide a more expansive definition of "layer"
|
||||
- overview-manual: remind reader that meta-poky is a distro layer
|
||||
- overview-manual: update deploy.bbclass snippet
|
||||
- overview-manual: use correct spelling "counterpart"
|
||||
- overview-manual: yp-intro.rst: add link to "buildbot"
|
||||
- overview-manual: yp-intro.rst: delete really old references
|
||||
- perl: link to the system zlib instead of a vendored copy
|
||||
- poky.conf: Bump version for 5.0.19 release
|
||||
- pseudo: Update to 1.9.8
|
||||
- python_setuptools_build_meta: clean the build directory in configure
|
||||
- recipe-style-guide.rst: two minor grammatical tweaks
|
||||
- recipetool: Recognise https://git. as git urls
|
||||
- ref-manual/variables.rst: link \*MIRRORS definitions to the BitBake manual
|
||||
- ref-manual: add more explanation to glossary variable :term:`LICENSE`
|
||||
- ref-manual: clarify that :term:`PACKAGE_EXCLUDE` supports DEB packaging
|
||||
- ref-manual: clarify use of "PACKAGE_ARCH" in a packagegroup
|
||||
- ref-manual: document :term:`RM_WORK_EXCLUDE_ITEMS` variable
|
||||
- scripts/install-buildtools: Update to 5.0.18
|
||||
- security-team.rst: update my email address and key
|
||||
- security-team: Add section on multi-project embargoes
|
||||
- security-team: Tidy and update section on security team operations
|
||||
- security-team: Update membership list
|
||||
- setuptools3: clean the build directory in configure
|
||||
- setuptools3_legacy: ensure ${B} is clean
|
||||
- systemd: update musl specific patch to apply
|
||||
- tzdata/tzcode-native: upgrade to 2026b
|
||||
- wic: filemap: use separate fd for SEEK_HOLE probes
|
||||
|
||||
|
||||
Known Issues in Yocto-5.0.19
|
||||
~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
- N/A
|
||||
|
||||
Contributors to Yocto-5.0.19
|
||||
~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
Thanks to the following people who contributed to this release:
|
||||
|
||||
- Adarsh Jagadish Kamini
|
||||
- Alexander Kanavin
|
||||
- Amaury Couderc
|
||||
- Anders Heimer
|
||||
- Anil Dongare
|
||||
- Ankur Tyagi
|
||||
- Antonin Godard
|
||||
- Benjamin Robin (Schneider Electric)
|
||||
- Bruce Ashfield
|
||||
- Changqing Li
|
||||
- Deepak Rathore
|
||||
- Enrico Jörns
|
||||
- Guðni Már Gilbert
|
||||
- He Zhe
|
||||
- Himanshu Jadon
|
||||
- Hitendra Prajapati
|
||||
- Hugo SIMELIERE (Schneider Electric)
|
||||
- Jonas Munsin
|
||||
- João Marcos Costa (Schneider Electric)
|
||||
- Lee Chee Yang
|
||||
- Marcio Henriques
|
||||
- Mark Hatle
|
||||
- Marta Rybczynska
|
||||
- Martin Jansa
|
||||
- Mathieu Dubois-Briand
|
||||
- Naman Jain
|
||||
- Paul Barker
|
||||
- Peter Bergin
|
||||
- Peter Marko
|
||||
- Prabhudasu Vatala
|
||||
- Richard Purdie
|
||||
- Robert P. J. Day
|
||||
- Ross Burton
|
||||
- Shubham Pushpkar
|
||||
- Sudhir Dumbhare
|
||||
- Theo Gaige (Schneider Electric)
|
||||
- Trevor Woerner
|
||||
- Vijay Anusuri
|
||||
- Yoann Congal
|
||||
- Zahir Hussain
|
||||
|
||||
|
||||
Repositories / Downloads for Yocto-5.0.19
|
||||
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
yocto-docs
|
||||
|
||||
- Repository Location: :yocto_git:`/yocto-docs`
|
||||
- Branch: :yocto_git:`scarthgap </yocto-docs/log/?h=scarthgap>`
|
||||
- Tag: :yocto_git:`yocto-5.0.19 </yocto-docs/log/?h=yocto-5.0.19>`
|
||||
- Git Revision: :yocto_git:`1b819d324780a699d9307a2d4e68c69b576ab748 </yocto-docs/commit/?id=1b819d324780a699d9307a2d4e68c69b576ab748>`
|
||||
- Release Artefact: yocto-docs-1b819d324780a699d9307a2d4e68c69b576ab748
|
||||
- sha: b2c484d8d13b05b133f6f23f44e7757e4b53d93c27c9ea76d1a2e5f759f51af0
|
||||
- Download Locations:
|
||||
|
||||
https://downloads.yoctoproject.org/releases/yocto/yocto-5.0.19/yocto-docs-1b819d324780a699d9307a2d4e68c69b576ab748.tar.bz2
|
||||
|
||||
https://mirrors.edge.kernel.org/yocto/yocto/yocto-5.0.19/yocto-docs-1b819d324780a699d9307a2d4e68c69b576ab748.tar.bz2
|
||||
|
||||
poky
|
||||
|
||||
- Repository Location: :yocto_git:`/poky`
|
||||
- Branch: :yocto_git:`scarthgap </poky/log/?h=scarthgap>`
|
||||
- Tag: :yocto_git:`yocto-5.0.19 </poky/log/?h=yocto-5.0.19>`
|
||||
- Git Revision: :yocto_git:`bb98354685781296e3b3737e7762412100f359c2 </poky/commit/?id=bb98354685781296e3b3737e7762412100f359c2>`
|
||||
- Release Artefact: poky-bb98354685781296e3b3737e7762412100f359c2
|
||||
- sha: 37fd9eeff8043e6d7d595421b8ac40d38357d2d4ce3a6d0f86a0f7d884c995c3
|
||||
- Download Locations:
|
||||
|
||||
https://downloads.yoctoproject.org/releases/yocto/yocto-5.0.19/poky-bb98354685781296e3b3737e7762412100f359c2.tar.bz2
|
||||
|
||||
https://mirrors.edge.kernel.org/yocto/yocto/yocto-5.0.19/poky-bb98354685781296e3b3737e7762412100f359c2.tar.bz2
|
||||
|
||||
openembedded-core
|
||||
|
||||
- Repository Location: :oe_git:`/openembedded-core`
|
||||
- Branch: :oe_git:`scarthgap </openembedded-core/log/?h=scarthgap>`
|
||||
- Tag: :oe_git:`yocto-5.0.19 </openembedded-core/log/?h=yocto-5.0.19>`
|
||||
- Git Revision: :oe_git:`2814f0962f56c8d1afa4de76d2895ba9b5cb767d </openembedded-core/commit/?id=2814f0962f56c8d1afa4de76d2895ba9b5cb767d>`
|
||||
- Release Artefact: oecore-2814f0962f56c8d1afa4de76d2895ba9b5cb767d
|
||||
- sha: 8556e454499fcda4026dc58fb8fc627861720f5c006bd72bf3b455dabd22a0e8
|
||||
- Download Locations:
|
||||
|
||||
https://downloads.yoctoproject.org/releases/yocto/yocto-5.0.19/oecore-2814f0962f56c8d1afa4de76d2895ba9b5cb767d.tar.bz2
|
||||
|
||||
https://mirrors.edge.kernel.org/yocto/yocto/yocto-5.0.19/oecore-2814f0962f56c8d1afa4de76d2895ba9b5cb767d.tar.bz2
|
||||
|
||||
meta-yocto
|
||||
|
||||
- Repository Location: :yocto_git:`/meta-yocto`
|
||||
- Branch: :yocto_git:`scarthgap </meta-yocto/log/?h=scarthgap>`
|
||||
- Tag: :yocto_git:`yocto-5.0.19 </meta-yocto/log/?h=yocto-5.0.19>`
|
||||
- Git Revision: :yocto_git:`2f749ae477c3b94dce71038f025180d7f612dab0 </meta-yocto/commit/?id=2f749ae477c3b94dce71038f025180d7f612dab0>`
|
||||
- Release Artefact: meta-yocto-2f749ae477c3b94dce71038f025180d7f612dab0
|
||||
- sha: 754237ee59a67d31da1f242555c77b75a96d9cdabdf0a4c9cfd98e378643d031
|
||||
- Download Locations:
|
||||
|
||||
https://downloads.yoctoproject.org/releases/yocto/yocto-5.0.19/meta-yocto-2f749ae477c3b94dce71038f025180d7f612dab0.tar.bz2
|
||||
|
||||
https://mirrors.edge.kernel.org/yocto/yocto/yocto-5.0.19/meta-yocto-2f749ae477c3b94dce71038f025180d7f612dab0.tar.bz2
|
||||
|
||||
meta-mingw
|
||||
|
||||
- Repository Location: :yocto_git:`/meta-mingw`
|
||||
- Branch: :yocto_git:`scarthgap </meta-mingw/log/?h=scarthgap>`
|
||||
- Tag: :yocto_git:`yocto-5.0.19 </meta-mingw/log/?h=yocto-5.0.19>`
|
||||
- Git Revision: :yocto_git:`bd9fef71ec005be3c3a6d7f8b99d8116daf70c4f </meta-mingw/commit/?id=bd9fef71ec005be3c3a6d7f8b99d8116daf70c4f>`
|
||||
- Release Artefact: meta-mingw-bd9fef71ec005be3c3a6d7f8b99d8116daf70c4f
|
||||
- sha: ab073def6487f237ac125d239b3739bf02415270959546b6b287778664f0ae65
|
||||
- Download Locations:
|
||||
|
||||
https://downloads.yoctoproject.org/releases/yocto/yocto-5.0.19/meta-mingw-bd9fef71ec005be3c3a6d7f8b99d8116daf70c4f.tar.bz2
|
||||
|
||||
https://mirrors.edge.kernel.org/yocto/yocto/yocto-5.0.19/meta-mingw-bd9fef71ec005be3c3a6d7f8b99d8116daf70c4f.tar.bz2
|
||||
|
||||
bitbake
|
||||
|
||||
- Repository Location: :oe_git:`/bitbake`
|
||||
- Branch: :oe_git:`2.8 </bitbake/log/?h=2.8>`
|
||||
- Tag: :oe_git:`yocto-5.0.19 </bitbake/log/?h=yocto-5.0.19>`
|
||||
- Git Revision: :oe_git:`0880963fea4d91a034e4a6e007d23f98658ab986 </bitbake/commit/?id=0880963fea4d91a034e4a6e007d23f98658ab986>`
|
||||
- Release Artefact: bitbake-0880963fea4d91a034e4a6e007d23f98658ab986
|
||||
- sha: 2bbf83d622fd4ad7ef0110378a9c88b683b2d82a911aba681b561446ec2f486b
|
||||
- Download Locations:
|
||||
|
||||
https://downloads.yoctoproject.org/releases/yocto/yocto-5.0.19/bitbake-0880963fea4d91a034e4a6e007d23f98658ab986.tar.bz2
|
||||
|
||||
https://mirrors.edge.kernel.org/yocto/yocto/yocto-5.0.19/bitbake-0880963fea4d91a034e4a6e007d23f98658ab986.tar.bz2
|
||||
|
||||
@@ -166,7 +166,7 @@ New Features / Enhancements in 5.0
|
||||
``meta/lib/patchtest/tests``) and make a number of improvements to enable
|
||||
it to validate patches submitted on the mailing list again. Additionally,
|
||||
make it work with the original upstream version of
|
||||
`Patchwork <http://jk.ozlabs.org/projects/patchwork/>`__.
|
||||
`Patchwork <https://web.archive.org/web/20250823174533/http://jk.ozlabs.org/projects/patchwork/>`__.
|
||||
|
||||
- Add an optional ``unimplemented-ptest`` QA warning to detect upstream
|
||||
packages with tests, that do not use ptest.
|
||||
@@ -217,7 +217,7 @@ New Features / Enhancements in 5.0
|
||||
state directory (i.e., ``/run``).
|
||||
|
||||
- Allow to disable colored text output through the
|
||||
`NO_COLOR <https://no-color.org/>`__ environment variable.
|
||||
``NO_COLOR`` environment variable.
|
||||
|
||||
- ``git-make-shallow`` script: add support for Git's ``safe.bareRepository=explicit``
|
||||
configuration setting.
|
||||
|
||||
@@ -58,16 +58,12 @@ Project. Most find that it is best to have a native Linux machine
|
||||
function as the development host. However, it is possible to use a
|
||||
system that does not run Linux as its operating system as your
|
||||
development host. When you have a Mac or Windows-based system, you can
|
||||
set it up as the development host by using
|
||||
`CROPS <https://github.com/crops/poky-container>`__, which leverages
|
||||
`Docker Containers <https://www.docker.com/>`__. Once you take the steps
|
||||
to set up a CROPS machine, you effectively have access to a shell
|
||||
set it up as the development host by using an :wikipedia:`OCI container
|
||||
<Open_Container_Initiative>` (using `Docker <https://www.docker.com/>`__ or
|
||||
`Podman <https://podman.io/>`__). Once you take the steps
|
||||
to set up container, you effectively have access to a shell
|
||||
environment that is similar to what you see when using a Linux-based
|
||||
development host. For the steps needed to set up a system using CROPS,
|
||||
see the
|
||||
":ref:`dev-manual/start:setting up to use cross platforms (crops)`"
|
||||
section in
|
||||
the Yocto Project Development Tasks Manual.
|
||||
development host.
|
||||
|
||||
If your development host is going to be a system that runs a Linux
|
||||
distribution, you must still take steps to prepare the system
|
||||
@@ -87,7 +83,7 @@ are several ways of working in the Yocto Project environment:
|
||||
which uses
|
||||
BitBake, in a command-line environment from a shell on your
|
||||
development host. You can accomplish this from a host that is a
|
||||
native Linux machine or from a host that has been set up with CROPS.
|
||||
native Linux machine or from a container.
|
||||
Either way, you create, modify, and build images and applications all
|
||||
within a shell-based environment using components and tools available
|
||||
through your Linux distribution and the Yocto Project.
|
||||
@@ -365,7 +361,7 @@ commands.
|
||||
.. note::
|
||||
|
||||
- For more information on Git, see
|
||||
https://git-scm.com/documentation.
|
||||
https://git-scm.com/docs.
|
||||
|
||||
- If you need to download Git, it is recommended that you add Git to
|
||||
your system through your distribution's "software store" (e.g. for
|
||||
@@ -496,7 +492,7 @@ you can manage with a small set of basic operations and workflows once
|
||||
you understand the basic philosophy behind Git. You do not have to be an
|
||||
expert in Git to be functional. A good place to look for instruction on
|
||||
a minimal set of Git commands is
|
||||
`here <https://git-scm.com/documentation>`__.
|
||||
`here <https://git-scm.com/docs>`__.
|
||||
|
||||
The following list of Git commands briefly describes some basic Git
|
||||
operations as a way to get started. As with any set of commands, this
|
||||
|
||||
@@ -4,15 +4,70 @@
|
||||
Yocto Project Overview and Concepts Manual
|
||||
==========================================
|
||||
|
||||
|
|
||||
Welcome to the Yocto Project Overview and Concepts Manual! This manual
|
||||
introduces the Yocto Project by providing concepts, software overviews,
|
||||
best-known-methods (BKMs), and any other high-level introductory
|
||||
information suitable for a new Yocto Project user.
|
||||
|
||||
Here is what you can get from this manual:
|
||||
|
||||
- :ref:`overview-manual/yp-intro:introducing the yocto project`\ *:*
|
||||
This chapter provides an introduction to the Yocto Project. You will learn
|
||||
about features and challenges of the Yocto Project, the layer model,
|
||||
components and tools, development methods, the
|
||||
:term:`Poky` reference distribution, the
|
||||
:term:`OpenEmbedded Build System` workflow, and some basic Yocto terms.
|
||||
|
||||
- :ref:`overview-manual/development-environment:the yocto project development environment`\ *:*
|
||||
This chapter helps you get started understanding the Yocto Project
|
||||
development environment. You will learn about open source, development hosts,
|
||||
Yocto Project source repositories, workflows using Git and the Yocto
|
||||
Project, a Git primer, and information about licensing.
|
||||
|
||||
- :doc:`/overview-manual/concepts` *:* This
|
||||
chapter presents various concepts regarding the Yocto Project. You
|
||||
can find conceptual information about components, development,
|
||||
cross-toolchains, and so forth.
|
||||
|
||||
This manual does not give you the following:
|
||||
|
||||
- *Step-by-step Instructions for Development Tasks:* Instructional
|
||||
procedures reside in other manuals within the Yocto Project
|
||||
documentation set. For example, the :doc:`/dev-manual/index`
|
||||
provides examples on how to perform
|
||||
various development tasks. As another example, the
|
||||
:doc:`/sdk-manual/index` manual contains detailed
|
||||
instructions on how to install an SDK, which is used to develop
|
||||
applications for target hardware.
|
||||
|
||||
- *Reference Material:* This type of material resides in an appropriate
|
||||
reference manual. For example, system variables are documented in the
|
||||
:doc:`/ref-manual/index`. As another
|
||||
example, the :doc:`/bsp-guide/index` contains reference information on
|
||||
BSPs.
|
||||
|
||||
- *Detailed Public Information Not Specific to the Yocto Project:* For
|
||||
example, exhaustive information on how to use the Source Control
|
||||
Manager Git is better covered with Internet searches and official Git
|
||||
Documentation than through the Yocto Project documentation.
|
||||
|
||||
.. toctree::
|
||||
:caption: Table of Contents
|
||||
:numbered:
|
||||
|
||||
intro
|
||||
yp-intro
|
||||
development-environment
|
||||
concepts
|
||||
|
||||
Because this manual presents information for many different topics,
|
||||
supplemental information is recommended for full comprehension. For
|
||||
additional introductory information on the Yocto Project, see the
|
||||
:yocto_home:`Yocto Project Website <>`. If you want to build an image
|
||||
with no knowledge of Yocto Project as a way of quickly testing it out,
|
||||
see the :doc:`/brief-yoctoprojectqs/index` document.
|
||||
For a comprehensive list of links and other documentation, see the
|
||||
":ref:`Links and Related
|
||||
Documentation <resources-links-and-related-documentation>`"
|
||||
section in the Yocto Project Reference Manual.
|
||||
|
||||
.. include:: /boilerplate.rst
|
||||
|
||||
@@ -1,69 +0,0 @@
|
||||
.. SPDX-License-Identifier: CC-BY-SA-2.0-UK
|
||||
|
||||
**********************************************
|
||||
The Yocto Project Overview and Concepts Manual
|
||||
**********************************************
|
||||
|
||||
Welcome
|
||||
=======
|
||||
|
||||
Welcome to the Yocto Project Overview and Concepts Manual! This manual
|
||||
introduces the Yocto Project by providing concepts, software overviews,
|
||||
best-known-methods (BKMs), and any other high-level introductory
|
||||
information suitable for a new Yocto Project user.
|
||||
|
||||
Here is what you can get from this manual:
|
||||
|
||||
- :ref:`overview-manual/yp-intro:introducing the yocto project`\ *:*
|
||||
This chapter provides an introduction to the Yocto Project. You will learn
|
||||
about features and challenges of the Yocto Project, the layer model,
|
||||
components and tools, development methods, the
|
||||
:term:`Poky` reference distribution, the
|
||||
:term:`OpenEmbedded Build System` workflow, and some basic Yocto terms.
|
||||
|
||||
- :ref:`overview-manual/development-environment:the yocto project development environment`\ *:*
|
||||
This chapter helps you get started understanding the Yocto Project
|
||||
development environment. You will learn about open source, development hosts,
|
||||
Yocto Project source repositories, workflows using Git and the Yocto
|
||||
Project, a Git primer, and information about licensing.
|
||||
|
||||
- :doc:`/overview-manual/concepts` *:* This
|
||||
chapter presents various concepts regarding the Yocto Project. You
|
||||
can find conceptual information about components, development,
|
||||
cross-toolchains, and so forth.
|
||||
|
||||
This manual does not give you the following:
|
||||
|
||||
- *Step-by-step Instructions for Development Tasks:* Instructional
|
||||
procedures reside in other manuals within the Yocto Project
|
||||
documentation set. For example, the :doc:`/dev-manual/index`
|
||||
provides examples on how to perform
|
||||
various development tasks. As another example, the
|
||||
:doc:`/sdk-manual/index` manual contains detailed
|
||||
instructions on how to install an SDK, which is used to develop
|
||||
applications for target hardware.
|
||||
|
||||
- *Reference Material:* This type of material resides in an appropriate
|
||||
reference manual. For example, system variables are documented in the
|
||||
:doc:`/ref-manual/index`. As another
|
||||
example, the :doc:`/bsp-guide/index` contains reference information on
|
||||
BSPs.
|
||||
|
||||
- *Detailed Public Information Not Specific to the Yocto Project:* For
|
||||
example, exhaustive information on how to use the Source Control
|
||||
Manager Git is better covered with Internet searches and official Git
|
||||
Documentation than through the Yocto Project documentation.
|
||||
|
||||
Other Information
|
||||
=================
|
||||
|
||||
Because this manual presents information for many different topics,
|
||||
supplemental information is recommended for full comprehension. For
|
||||
additional introductory information on the Yocto Project, see the
|
||||
:yocto_home:`Yocto Project Website <>`. If you want to build an image
|
||||
with no knowledge of Yocto Project as a way of quickly testing it out,
|
||||
see the :doc:`/brief-yoctoprojectqs/index` document.
|
||||
For a comprehensive list of links and other documentation, see the
|
||||
":ref:`Links and Related
|
||||
Documentation <resources-links-and-related-documentation>`"
|
||||
section in the Yocto Project Reference Manual.
|
||||
@@ -285,13 +285,6 @@ Development Tools
|
||||
Here are tools that help you develop images and applications using
|
||||
the Yocto Project:
|
||||
|
||||
- *CROPS:* `CROPS <https://github.com/crops/poky-container/>`__ is an
|
||||
open source, cross-platform development framework that leverages
|
||||
`Docker Containers <https://www.docker.com/>`__. CROPS provides an
|
||||
easily managed, extensible environment that allows you to build
|
||||
binaries for a variety of architectures on Windows, Linux and Mac OS
|
||||
X hosts.
|
||||
|
||||
- *devtool:* This command-line tool is available as part of the
|
||||
extensible SDK (eSDK) and is its cornerstone. You can use ``devtool``
|
||||
to help build, test, and package software within the eSDK. You can
|
||||
@@ -534,9 +527,9 @@ Linux.
|
||||
Build Appliance was useful as a way to try out development in the
|
||||
Yocto Project environment.
|
||||
|
||||
#. *CROPS:* The final and best solution available now for developing
|
||||
using the Yocto Project on a system not native to Linux is with
|
||||
:ref:`CROPS <overview-manual/yp-intro:development tools>`.
|
||||
#. *CROPS:* Used to be a solution available for developing
|
||||
using the Yocto Project on a system not native to Linux (see
|
||||
https://github.com/crops/poky-container).
|
||||
|
||||
Development Methods
|
||||
===================
|
||||
@@ -570,25 +563,10 @@ Build Host runs, you have several choices.
|
||||
":ref:`dev-manual/start:setting up a native linux host`"
|
||||
section in the Yocto Project Development Tasks Manual.
|
||||
|
||||
- *CROss PlatformS (CROPS):* Typically, you use
|
||||
`CROPS <https://github.com/crops/poky-container/>`__, which leverages
|
||||
`Docker Containers <https://www.docker.com/>`__, to set up a Build
|
||||
Host that is not running Linux (e.g. Microsoft Windows or macOS).
|
||||
|
||||
.. note::
|
||||
|
||||
You can, however, use CROPS on a Linux-based system.
|
||||
|
||||
CROPS is an open source, cross-platform development framework that
|
||||
provides an easily managed, extensible environment for building
|
||||
binaries targeted for a variety of architectures on Windows, macOS,
|
||||
or Linux hosts. Once the Build Host is set up using CROPS, you can
|
||||
prepare a shell environment to mimic that of a shell being used on a
|
||||
system natively running Linux.
|
||||
|
||||
For information on how to set up a Build Host with CROPS, see the
|
||||
":ref:`dev-manual/start:setting up to use cross platforms (crops)`"
|
||||
section in the Yocto Project Development Tasks Manual.
|
||||
- *OCI Containers:* Typically, you use an :wikipedia:`OCI container
|
||||
<Open_Container_Initiative>` (with `Docker <https://www.docker.com/>`__ or
|
||||
`Podman <https://podman.io/>`__ for example), to set up a :term:`Build
|
||||
Host` that is not running Linux (e.g. Microsoft Windows or macOS).
|
||||
|
||||
- *Windows Subsystem For Linux (WSL 2):* You may use Windows Subsystem
|
||||
For Linux version 2 to set up a Build Host using Windows 10 or later,
|
||||
|
||||
@@ -39,7 +39,7 @@ other tools when it seems useful to do so.
|
||||
The coverage below details some of the most common ways you'll likely
|
||||
want to apply the tool; full documentation can be found either within
|
||||
the tool itself or in the manual pages at
|
||||
`perf(1) <https://linux.die.net/man/1/perf>`__.
|
||||
:manpage:`perf(1)`.
|
||||
|
||||
perf Setup
|
||||
----------
|
||||
@@ -869,8 +869,8 @@ goes a little way to support the idea mentioned previously that given
|
||||
the right kind of trace data, higher-level profiling-type summaries can
|
||||
be derived from it.
|
||||
|
||||
Documentation on using the `'perf script' Python
|
||||
binding <https://linux.die.net/man/1/perf-script-python>`__.
|
||||
Documentation on using the :manpage:`'perf script' Python
|
||||
binding <perf-script-python(1)>`.
|
||||
|
||||
System-Wide Tracing and Profiling
|
||||
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
@@ -1150,23 +1150,19 @@ perf Documentation
|
||||
Online versions of the manual pages for the commands discussed in this
|
||||
section can be found here:
|
||||
|
||||
- The `'perf stat' manual page <https://linux.die.net/man/1/perf-stat>`__.
|
||||
- The :manpage:`'perf stat' manual page <perf-stat(1)>`.
|
||||
|
||||
- The `'perf record'
|
||||
manual page <https://linux.die.net/man/1/perf-record>`__.
|
||||
- The :manpage:`'perf record' manual page <perf-record(1)>`.
|
||||
|
||||
- The `'perf report'
|
||||
manual page <https://linux.die.net/man/1/perf-report>`__.
|
||||
- The :manpage:`'perf report' manual page <perf-report(1)>`.
|
||||
|
||||
- The `'perf probe' manual page <https://linux.die.net/man/1/perf-probe>`__.
|
||||
- The :manpage:`'perf probe' manual page <perf-probe(1)>`.
|
||||
|
||||
- The `'perf script'
|
||||
manual page <https://linux.die.net/man/1/perf-script>`__.
|
||||
- The :manpage:`'perf script' manual page <perf-script(1)>`.
|
||||
|
||||
- Documentation on using the `'perf script' Python
|
||||
binding <https://linux.die.net/man/1/perf-script-python>`__.
|
||||
- Documentation on using the :manpage:`'perf script' Python binding <perf-script-python(1)>`.
|
||||
|
||||
- The top-level `perf(1) manual page <https://linux.die.net/man/1/perf>`__.
|
||||
- The top-level :manpage:`perf(1) manual page <perf(1)>`.
|
||||
|
||||
Normally, you should be able to open the manual pages via perf itself
|
||||
e.g. ``perf help`` or ``perf help record``.
|
||||
@@ -1781,7 +1777,7 @@ gather / print / aggregate data extracted from the context they end up being
|
||||
called under.
|
||||
|
||||
For example, this probe from the `SystemTap
|
||||
tutorial <https://sourceware.org/systemtap/tutorial/>`__ just prints a
|
||||
tutorial <https://sourceware.org/systemtap/tutorial.html>`__ just prints a
|
||||
line every time any process on the system runs ``open()`` on a file. For each line,
|
||||
it prints the executable name of the program that opened the file, along
|
||||
with its PID, and the name of the file it opened (or tried to open), which it
|
||||
@@ -1957,7 +1953,7 @@ SystemTap Documentation
|
||||
-----------------------
|
||||
|
||||
The SystemTap language reference can be found here: `SystemTap Language
|
||||
Reference <https://sourceware.org/systemtap/langref/>`__
|
||||
Reference <https://sourceware.org/systemtap/langref.html>`__
|
||||
|
||||
Links to other SystemTap documents, tutorials, and examples can be found
|
||||
here: `SystemTap documentation
|
||||
@@ -2388,7 +2384,7 @@ first part of the filenames::
|
||||
The report shows each event that was
|
||||
found in the blktrace data, along with a summary of the overall block
|
||||
I/O traffic during the run. You can look at the
|
||||
`blkparse <https://linux.die.net/man/1/blkparse>`__ manual page to learn the
|
||||
:manpage:`blkparse(1)` manual page to learn the
|
||||
meaning of each field displayed in the trace listing.
|
||||
|
||||
Live Mode
|
||||
@@ -2588,14 +2584,14 @@ blktrace Documentation
|
||||
Online versions of the manual pages for the commands discussed in this
|
||||
section can be found here:
|
||||
|
||||
- https://linux.die.net/man/8/blktrace
|
||||
- :manpage:`blktrace(8)`
|
||||
|
||||
- https://linux.die.net/man/1/blkparse
|
||||
- :manpage:`blkparse(1)`
|
||||
|
||||
- https://linux.die.net/man/8/btrace
|
||||
- :manpage:`btrace(8)`
|
||||
|
||||
The above manual pages, along with manuals for the other blktrace utilities
|
||||
(``btt``, ``blkiomon``, etc) can be found in the ``/doc`` directory of the blktrace
|
||||
tools git repository::
|
||||
|
||||
$ git clone git://git.kernel.dk/blktrace.git
|
||||
$ git clone https://git.kernel.org/pub/scm/linux/kernel/git/axboe/blktrace.git
|
||||
|
||||
@@ -515,7 +515,7 @@ by the :term:`SPDX_PRETTY`, :term:`SPDX_ARCHIVE_PACKAGED`,
|
||||
|
||||
See the description of these variables and the
|
||||
":ref:`dev-manual/sbom:creating a software bill of materials`"
|
||||
section in the Yocto Project Development Manual for more details.
|
||||
section in the Yocto Project Development Tasks Manual for more details.
|
||||
|
||||
.. _ref-classes-cross:
|
||||
|
||||
@@ -2327,11 +2327,8 @@ consider some further things about using RPM:
|
||||
perform on-device upgrades.
|
||||
|
||||
You can find additional information on the effects of the package class
|
||||
at these two Yocto Project mailing list links:
|
||||
|
||||
- :yocto_lists:`/pipermail/poky/2011-May/006362.html`
|
||||
|
||||
- :yocto_lists:`/pipermail/poky/2011-May/006363.html`
|
||||
at this Yocto Project mailing list link:
|
||||
:yocto_lists:`/g/poky/topic/61292484#msg6286`
|
||||
|
||||
.. _ref-classes-package_deb:
|
||||
|
||||
@@ -2689,7 +2686,7 @@ This class is intended to be inherited by individual recipes. However,
|
||||
the class' functionality is largely disabled unless "ptest" appears in
|
||||
:term:`DISTRO_FEATURES`. See the
|
||||
":ref:`test-manual/ptest:testing packages with ptest`"
|
||||
section in the Yocto Project Development Tasks Manual for more information
|
||||
section in the Yocto Project Test Environment Manual for more information
|
||||
on ptest.
|
||||
|
||||
.. _ref-classes-ptest-cargo:
|
||||
@@ -2713,7 +2710,7 @@ have tests intended to be executed with ``gnome-desktop-testing``.
|
||||
|
||||
For information on setting up and running ptests, see the
|
||||
":ref:`test-manual/ptest:testing packages with ptest`"
|
||||
section in the Yocto Project Development Tasks Manual.
|
||||
section in the Yocto Project Test Environment Manual.
|
||||
|
||||
.. _ref-classes-python3-dir:
|
||||
|
||||
@@ -3000,7 +2997,7 @@ Python version 3.x extensions that use build systems based on ``setuptools``
|
||||
``pyproject.toml`` format). Unlike :ref:`ref-classes-setuptools3`,
|
||||
this uses the traditional ``setup.py`` ``build`` and ``install`` commands and
|
||||
not wheels. This use of ``setuptools`` like this is
|
||||
`deprecated <https://github.com/pypa/setuptools/blob/main/CHANGES.rst#v5830>`__
|
||||
`deprecated <https://github.com/pypa/setuptools/blob/14cc4452199818e60cf01cd9cea96e90761abce7/NEWS.rst#v5830>`__
|
||||
but still relatively common.
|
||||
|
||||
.. _ref-classes-setuptools3-base:
|
||||
@@ -3265,7 +3262,7 @@ the :term:`SYSTEMD_BOOT_CFG`,
|
||||
:term:`SYSTEMD_BOOT_TIMEOUT` variables.
|
||||
|
||||
You can also see the `Systemd-boot
|
||||
documentation <https://www.freedesktop.org/wiki/Software/systemd/systemd-boot/>`__
|
||||
documentation <https://systemd.io/BOOT/>`__
|
||||
for more information.
|
||||
|
||||
.. _ref-classes-terminal:
|
||||
|
||||
@@ -105,7 +105,8 @@ attempt before any others by adding something like the following to the
|
||||
git://.*/.* &YOCTO_DL_URL;/mirror/sources/ \
|
||||
ftp://.*/.* &YOCTO_DL_URL;/mirror/sources/ \
|
||||
http://.*/.* &YOCTO_DL_URL;/mirror/sources/ \
|
||||
https://.*/.* &YOCTO_DL_URL;/mirror/sources/"
|
||||
https://.*/.* &YOCTO_DL_URL;/mirror/sources/ \
|
||||
"
|
||||
|
||||
These changes cause the build system to intercept Git, FTP, HTTP, and
|
||||
HTTPS requests and direct them to the ``http://`` sources mirror. You
|
||||
@@ -144,7 +145,8 @@ file as long as the :term:`PREMIRRORS` server is current::
|
||||
git://.*/.* &YOCTO_DL_URL;/mirror/sources/ \
|
||||
ftp://.*/.* &YOCTO_DL_URL;/mirror/sources/ \
|
||||
http://.*/.* &YOCTO_DL_URL;/mirror/sources/ \
|
||||
https://.*/.* &YOCTO_DL_URL;/mirror/sources/"
|
||||
https://.*/.* &YOCTO_DL_URL;/mirror/sources/ \
|
||||
"
|
||||
BB_FETCH_PREMIRRORONLY = "1"
|
||||
|
||||
These changes would cause the build system to successfully fetch source
|
||||
|
||||
@@ -208,7 +208,7 @@ metadata, as extra layers can define their own:
|
||||
- *ptest:* Enables building the package tests where supported by
|
||||
individual recipes. For more information on package tests, see the
|
||||
":ref:`test-manual/ptest:testing packages with ptest`" section
|
||||
in the Yocto Project Development Tasks Manual.
|
||||
in the Yocto Project Test Environment Manual.
|
||||
|
||||
- *pulseaudio:* Include support for
|
||||
`PulseAudio <https://www.freedesktop.org/wiki/Software/PulseAudio/>`__.
|
||||
@@ -357,7 +357,7 @@ The image features available for all images are:
|
||||
different package name (or names) within the image recipe or at the
|
||||
distro configuration level.
|
||||
|
||||
- *stateless-rootfs:*: specifies that the image should be created as
|
||||
- *stateless-rootfs:* specifies that the image should be created as
|
||||
stateless - when using ``systemd``, ``systemctl-native`` will not
|
||||
be run on the image, leaving the image for population at runtime by
|
||||
systemd.
|
||||
|
||||
@@ -37,10 +37,7 @@ Here is a list of supported recipes:
|
||||
- ``build-appliance-image``: An example virtual machine that contains
|
||||
all the pieces required to run builds using the build system as well
|
||||
as the build system itself. You can boot and run the image using
|
||||
either the `VMware
|
||||
Player <https://www.vmware.com/products/player/overview.html>`__ or
|
||||
`VMware
|
||||
Workstation <https://www.vmware.com/products/workstation/overview.html>`__.
|
||||
`VMware Workstation <https://www.vmware.com/products/desktop-hypervisor/workstation-and-fusion>`__.
|
||||
For more information on this image, see the :yocto_home:`Build
|
||||
Appliance </software-item/build-appliance>` page
|
||||
on the Yocto Project website.
|
||||
|
||||
@@ -151,8 +151,8 @@ upgrade to the following :term:`LTS` release.
|
||||
|
||||
The currently supported :term:`LTS` releases are:
|
||||
|
||||
- Version 6.0 ("Wrynose"), released in May 2026 and supported until April 2030.
|
||||
- Version 5.0 ("Scarthgap"), released in April 2024 and supported until April 2028.
|
||||
- Version 4.0 ("Kirkstone"), released in May 2022 and supported until May 2026.
|
||||
|
||||
See :yocto_wiki:`/Stable_Release_and_LTS` for details about the management
|
||||
of stable and :term:`LTS` releases.
|
||||
|
||||
@@ -658,7 +658,7 @@ When invoked by the user, this task creates a file containing the
|
||||
differences between the original config as produced by
|
||||
:ref:`ref-tasks-kernel_configme` task and the
|
||||
changes made by the user with other methods (i.e. using
|
||||
(:ref:`ref-tasks-kernel_menuconfig`). Once the
|
||||
(:ref:`ref-tasks-menuconfig`). Once the
|
||||
file of differences is created, it can be used to create a config
|
||||
fragment that only contains the differences. You can invoke this task
|
||||
from the command line as follows::
|
||||
@@ -686,7 +686,7 @@ kernel with the correct branches checked out.
|
||||
-------------------------
|
||||
|
||||
Validates the configuration produced by the
|
||||
:ref:`ref-tasks-kernel_menuconfig` task. The
|
||||
:ref:`ref-tasks-menuconfig` task. The
|
||||
:ref:`ref-tasks-kernel_configcheck` task produces warnings when a requested
|
||||
configuration does not appear in the final ``.config`` file or when you
|
||||
override a policy configuration in a hardware configuration fragment.
|
||||
@@ -711,26 +711,6 @@ passed to the kernel configuration phase proper. This is also the time
|
||||
during which user-specified defconfigs are applied if present, and where
|
||||
configuration modes such as ``--allnoconfig`` are applied.
|
||||
|
||||
.. _ref-tasks-kernel_menuconfig:
|
||||
|
||||
``do_kernel_menuconfig``
|
||||
------------------------
|
||||
|
||||
Invoked by the user to manipulate the ``.config`` file used to build a
|
||||
linux-yocto recipe. This task starts the Linux kernel configuration
|
||||
tool, which you then use to modify the kernel configuration.
|
||||
|
||||
.. note::
|
||||
|
||||
You can also invoke this tool from the command line as follows::
|
||||
|
||||
$ bitbake linux-yocto -c menuconfig
|
||||
|
||||
|
||||
See the ":ref:`kernel-dev/common:using ``menuconfig```"
|
||||
section in the Yocto Project Linux Kernel Development Manual for more
|
||||
information on this configuration tool.
|
||||
|
||||
.. _ref-tasks-kernel_metadata:
|
||||
|
||||
``do_kernel_metadata``
|
||||
@@ -749,10 +729,19 @@ which can then be applied by subsequent tasks such as
|
||||
``do_menuconfig``
|
||||
-----------------
|
||||
|
||||
Runs ``make menuconfig`` for the kernel. For information on
|
||||
``menuconfig``, see the
|
||||
":ref:`kernel-dev/common:using ``menuconfig```"
|
||||
section in the Yocto Project Linux Kernel Development Manual.
|
||||
Invoked by the user to manipulate the ``.config`` file used to build a
|
||||
linux-yocto recipe. This task starts the Linux kernel configuration
|
||||
tool, which you then use to modify the kernel configuration.
|
||||
|
||||
You can invoke this tool from the command line as follows:
|
||||
|
||||
.. code-block:: console
|
||||
|
||||
$ bitbake linux-yocto -c menuconfig
|
||||
|
||||
See the ":ref:`kernel-dev/common:using ``menuconfig```"
|
||||
section in the Yocto Project Linux Kernel Development Manual for more
|
||||
information on this configuration tool.
|
||||
|
||||
.. _ref-tasks-savedefconfig:
|
||||
|
||||
@@ -763,7 +752,7 @@ When invoked by the user, creates a defconfig file that can be used
|
||||
instead of the default defconfig. The saved defconfig contains the
|
||||
differences between the default defconfig and the changes made by the
|
||||
user using other methods (i.e. the
|
||||
:ref:`ref-tasks-kernel_menuconfig` task. You
|
||||
:ref:`ref-tasks-menuconfig` task. You
|
||||
can invoke the task using the following command::
|
||||
|
||||
$ bitbake linux-yocto -c savedefconfig
|
||||
@@ -785,22 +774,29 @@ can successfully build the kernel modules in the next step of the build.
|
||||
``do_sizecheck``
|
||||
----------------
|
||||
|
||||
After the kernel has been built, this task checks the size of the
|
||||
stripped kernel image against
|
||||
:term:`KERNEL_IMAGE_MAXSIZE`. If that
|
||||
variable was set and the size of the stripped kernel exceeds that size,
|
||||
the kernel build produces a warning to that effect.
|
||||
If the variable :term:`KERNEL_IMAGE_MAXSIZE` is set, this task compares
|
||||
the size of all stripped kernel images listed in :term:`KERNEL_IMAGETYPES`
|
||||
against that value. If more than one image type is listed there, warn on
|
||||
any that exceed that value, but fail only if none of them fit.
|
||||
|
||||
.. _ref-tasks-strip:
|
||||
|
||||
``do_strip``
|
||||
------------
|
||||
|
||||
If ``KERNEL_IMAGE_STRIP_EXTRA_SECTIONS`` is defined, this task strips
|
||||
If :term:`KERNEL_IMAGE_STRIP_EXTRA_SECTIONS` is defined, this task strips
|
||||
the sections named in that variable from ``vmlinux``. This stripping is
|
||||
typically used to remove nonessential sections such as ``.comment``
|
||||
sections from a size-sensitive configuration.
|
||||
|
||||
Common sections to strip:
|
||||
|
||||
- ``.comment``: Holds compiler version strings and information
|
||||
|
||||
- ``.note.*``: Extra notes often left by the compiler
|
||||
|
||||
- ``.debug``: Debugging information
|
||||
|
||||
.. _ref-tasks-validate_branches:
|
||||
|
||||
``do_validate_branches``
|
||||
|
||||
@@ -1463,6 +1463,11 @@ system and gives an overview of their function and contents.
|
||||
:term:`CCACHE_DISABLE` variable can be set to "1" in a recipe to disable
|
||||
`Ccache` support. This is useful when the recipe is known to not support it.
|
||||
|
||||
:term:`CCACHE_NATIVE_RECIPES_ALLOWED`
|
||||
The :term:`CCACHE_NATIVE_RECIPES_ALLOWED` variable can be set in a
|
||||
:term:`configuration file` to a list of native recipes that are allowed to
|
||||
be optimized with the :ref:`ref-classes-ccache` class.
|
||||
|
||||
:term:`CCACHE_TOP_DIR`
|
||||
When inheriting the :ref:`ref-classes-ccache` class, the
|
||||
:term:`CCACHE_TOP_DIR` variable can be set to the location of where
|
||||
@@ -1727,15 +1732,52 @@ system and gives an overview of their function and contents.
|
||||
Where :term:`AUTOTOOLS_SCRIPT_PATH` is the location of the of the
|
||||
Autotools build system scripts, which defaults to :term:`S`.
|
||||
|
||||
:term:`CONFLICT_COMBINED_FEATURES`
|
||||
When inheriting the :ref:`ref-classes-features_check`
|
||||
class, this variable identifies combined features (see
|
||||
:term:`COMBINED_FEATURES` for what this means) that would be in conflict
|
||||
should the recipe be built. In other words, if the
|
||||
:term:`CONFLICT_COMBINED_FEATURES` variable lists a feature that also
|
||||
appears in :term:`COMBINED_FEATURES` within the current configuration,
|
||||
then the recipe will be skipped, and if the build system attempts to build
|
||||
the recipe then an error will be triggered.
|
||||
|
||||
:term:`CONFLICT_DISTRO_FEATURES`
|
||||
When inheriting the :ref:`ref-classes-features_check`
|
||||
class, this variable identifies distribution features that would be
|
||||
class, this variable identifies distro features that would be
|
||||
in conflict should the recipe be built. In other words, if the
|
||||
:term:`CONFLICT_DISTRO_FEATURES` variable lists a feature that also
|
||||
appears in :term:`DISTRO_FEATURES` within the current configuration, then
|
||||
the recipe will be skipped, and if the build system attempts to build
|
||||
the recipe then an error will be triggered.
|
||||
|
||||
:term:`CONFLICT_IMAGE_FEATURES`
|
||||
When inheriting the :ref:`ref-classes-features_check`
|
||||
class, this variable identifies image features that would be
|
||||
in conflict should the recipe be built. In other words, if the
|
||||
:term:`CONFLICT_IMAGE_FEATURES` variable lists a feature that also
|
||||
appears in :term:`IMAGE_FEATURES` within the current configuration, then
|
||||
the recipe will be skipped, and if the build system attempts to build
|
||||
the recipe then an error will be triggered.
|
||||
|
||||
:term:`CONFLICT_MACHINE_FEATURES`
|
||||
When inheriting the :ref:`ref-classes-features_check`
|
||||
class, this variable identifies machine features that would be
|
||||
in conflict should the recipe be built. In other words, if the
|
||||
:term:`CONFLICT_MACHINE_FEATURES` variable lists a feature that also
|
||||
appears in :term:`MACHINE_FEATURES` within the current configuration, then
|
||||
the recipe will be skipped, and if the build system attempts to build
|
||||
the recipe then an error will be triggered.
|
||||
|
||||
:term:`CONFLICT_TUNE_FEATURES`
|
||||
When inheriting the :ref:`ref-classes-features_check`
|
||||
class, this variable identifies tune features that would be
|
||||
in conflict should the recipe be built. In other words, if the
|
||||
:term:`CONFLICT_TUNE_FEATURES` variable lists a feature that also
|
||||
appears in :term:`TUNE_FEATURES` within the current configuration, then
|
||||
the recipe will be skipped, and if the build system attempts to build
|
||||
the recipe then an error will be triggered.
|
||||
|
||||
:term:`CONVERSION_CMD`
|
||||
This variable is used for storing image conversion commands.
|
||||
Image conversion can convert an image into different objects like:
|
||||
@@ -3522,7 +3564,7 @@ system and gives an overview of their function and contents.
|
||||
GROUPADD_PARAM:${PN} = "-g 880 group1; -g 890 group2"
|
||||
|
||||
For information on the standard Linux shell command
|
||||
``groupadd``, see https://linux.die.net/man/8/groupadd.
|
||||
``groupadd``, see :manpage:`groupadd(8)`.
|
||||
|
||||
:term:`GROUPMEMS_PARAM`
|
||||
When inheriting the :ref:`ref-classes-useradd` class,
|
||||
@@ -3946,6 +3988,21 @@ system and gives an overview of their function and contents.
|
||||
or ``:prepend``. You must use the ``+=`` operator to add one or
|
||||
more options to the :term:`IMAGE_FSTYPES` variable.
|
||||
|
||||
:term:`IMAGE_FSTYPES_DEBUGFS`
|
||||
The :term:`IMAGE_FSTYPES_DEBUGFS` holds a list of filesystem image types
|
||||
to generate when the :term:`IMAGE_GEN_DEBUGFS` variable is set to "1". The
|
||||
content of this variable is the same as what is supported by the
|
||||
:term:`IMAGE_FSTYPES` variable.
|
||||
|
||||
:term:`IMAGE_GEN_DEBUGFS`
|
||||
When set to "1" in an :ref:`ref-classes-image` recipe, the
|
||||
:term:`OpenEmbedded Build System` will generate a companion image that
|
||||
contains the debug symbols and source code for the packages installed on
|
||||
the image. The :term:`OpenEmbedded Build System` does this by adding all
|
||||
the available ``-dbg`` and ``-src`` packages available in the package
|
||||
feed, which are automatically generated during
|
||||
:ref:`overview-manual/concepts:Package Splitting`.
|
||||
|
||||
:term:`IMAGE_INSTALL`
|
||||
Used by recipes to specify the packages to install into an image
|
||||
through the :ref:`ref-classes-image` class. Use the
|
||||
@@ -5053,17 +5110,18 @@ system and gives an overview of their function and contents.
|
||||
information.
|
||||
|
||||
:term:`KERNEL_IMAGE_MAXSIZE`
|
||||
Specifies the maximum size of the kernel image file in kilobytes. If
|
||||
:term:`KERNEL_IMAGE_MAXSIZE` is set, the size of the kernel image file is
|
||||
checked against the set value during the
|
||||
:ref:`ref-tasks-sizecheck` task. The task fails if
|
||||
the kernel image file is larger than the setting.
|
||||
Specifies the maximum allowable size of the kernel image file in kibibytes.
|
||||
If this variable is set, the sizes of all of the kernel image files listed
|
||||
in :term:`KERNEL_IMAGETYPES` are checked against this value during the
|
||||
:ref:`ref-tasks-sizecheck` task. That task will warn about any of the
|
||||
kernel images that exceed the maximum, and will fail only if all images
|
||||
are too large.
|
||||
|
||||
:term:`KERNEL_IMAGE_MAXSIZE` is useful for target devices that have a
|
||||
limited amount of space in which the kernel image must be stored.
|
||||
|
||||
By default, this variable is not set, which means the size of the
|
||||
kernel image is not checked.
|
||||
kernel images are not checked.
|
||||
|
||||
:term:`KERNEL_IMAGE_NAME`
|
||||
The base name of the kernel image. This variable is set in the
|
||||
@@ -5073,6 +5131,13 @@ system and gives an overview of their function and contents.
|
||||
|
||||
See :term:`KERNEL_ARTIFACT_NAME` for additional information.
|
||||
|
||||
:term:`KERNEL_IMAGE_STRIP_EXTRA_SECTIONS`
|
||||
If this variable is set, it should contain the sections to be
|
||||
stripped from the ``vmlinux`` image by the kernel-related
|
||||
:ref:`ref-tasks-strip` task. As a simple example::
|
||||
|
||||
KERNEL_IMAGE_STRIP_EXTRA_SECTIONS = ".comment .note.* .debug"
|
||||
|
||||
:term:`KERNEL_IMAGETYPE`
|
||||
The type of kernel to build for a device, usually set by the machine
|
||||
configuration files and defaults to "zImage". This variable is used
|
||||
@@ -5510,6 +5575,19 @@ system and gives an overview of their function and contents.
|
||||
$ uname -r
|
||||
3.7.0-rc8-custom
|
||||
|
||||
:term:`LOCALE_PATHS`
|
||||
The :term:`LOCALE_PATHS` variable holds a whitespace separated list of
|
||||
paths that are scanned to construct ``-locale`` packages during
|
||||
:ref:`overview-manual/concepts:Package Splitting`. The list
|
||||
contains ``${datadir}/locale`` by default.
|
||||
|
||||
:term:`LOCALE_UTF8_IS_DEFAULT`
|
||||
If set, locale names are renamed such that those lacking an explicit
|
||||
encoding (e.g. ``en_US``) will always be UTF-8, and non-UTF-8 encodings
|
||||
are renamed to, e.g., ``en_US.ISO-8859-1``. Otherwise, the encoding is
|
||||
specified by `Glibc`'s ``SUPPORTED`` file. This is not supported for
|
||||
pre-compiled locales.
|
||||
|
||||
:term:`LOG_DIR`
|
||||
Specifies the directory to which the OpenEmbedded build system writes
|
||||
overall log files. The default directory is ``${TMPDIR}/log``.
|
||||
@@ -5828,7 +5906,7 @@ system and gives an overview of their function and contents.
|
||||
See the :term:`KERNEL_MODULE_AUTOLOAD` variable for more information.
|
||||
|
||||
:term:`module_conf`
|
||||
Specifies `modprobe.d <https://linux.die.net/man/5/modprobe.d>`__
|
||||
Specifies :manpage:`modprobe.d(5)`
|
||||
syntax lines for inclusion in the ``/etc/modprobe.d/modname.conf``
|
||||
file.
|
||||
|
||||
@@ -6501,6 +6579,53 @@ system and gives an overview of their function and contents.
|
||||
install, the build system does not generate an error. This variable
|
||||
is generally not user-defined.
|
||||
|
||||
:term:`PACKAGE_NO_LOCALE`
|
||||
The :term:`PACKAGE_NO_LOCALE` variable can be set to "1" to prevent the
|
||||
:term:`OpenEmbedded Build System` from splitting the locales found in the
|
||||
:term:`PKGD` directory into split packages.
|
||||
|
||||
For example, the ``quilt`` recipe automatically produces split packages
|
||||
after the :ref:`ref-tasks-package` task is run. Taking a look inside the
|
||||
:term:`WORKDIR` directory of ``quilt``:
|
||||
|
||||
.. code-block:: console
|
||||
|
||||
$ ls -1 packages-split/
|
||||
guards
|
||||
guards-doc
|
||||
quilt
|
||||
quilt-dbg
|
||||
quilt-dev
|
||||
quilt-doc
|
||||
quilt-locale-de
|
||||
quilt-locale-fr
|
||||
quilt-locale-ja
|
||||
quilt-locale-ru
|
||||
quilt-ptest
|
||||
quilt-src
|
||||
quilt-staticdev
|
||||
|
||||
We can see the ``quilt-locale-*`` packages were automatically generated.
|
||||
Setting :term:`PACKAGE_NO_LOCALE` to "1" would produce the following
|
||||
packages:
|
||||
|
||||
.. code-block:: console
|
||||
|
||||
$ ls -1 packages-split/
|
||||
guards
|
||||
guards-doc
|
||||
quilt
|
||||
quilt-dbg
|
||||
quilt-dev
|
||||
quilt-doc
|
||||
quilt-locale
|
||||
quilt-ptest
|
||||
quilt-src
|
||||
quilt-staticdev
|
||||
|
||||
The ``quilt-locale`` package contains the merged content of the previous
|
||||
``quilt-locale-*`` packages.
|
||||
|
||||
:term:`PACKAGE_PREPROCESS_FUNCS`
|
||||
Specifies a list of functions run to pre-process the
|
||||
:term:`PKGD` directory prior to splitting the files out
|
||||
@@ -6648,6 +6773,12 @@ system and gives an overview of their function and contents.
|
||||
:ref:`ref-tasks-configure` task, then you need to use
|
||||
:term:`PACKAGECONFIG_CONFARGS` appropriately.
|
||||
|
||||
:term:`PACKAGEFUNCS`
|
||||
The :term:`PACKAGEFUNCS` variable holds a list of functions which are
|
||||
executed to process metadata based on split packages found in the
|
||||
:term:`PKGDEST` directory. These functions are executed in the
|
||||
:ref:`ref-classes-package` class in the order found in the list.
|
||||
|
||||
:term:`PACKAGEGROUP_DISABLE_COMPLEMENTARY`
|
||||
For recipes inheriting the :ref:`ref-classes-packagegroup` class, setting
|
||||
:term:`PACKAGEGROUP_DISABLE_COMPLEMENTARY` to "1" specifies that the
|
||||
@@ -7101,7 +7232,8 @@ system and gives an overview of their function and contents.
|
||||
git://.*/.* &YOCTO_DL_URL;/mirror/sources/ \
|
||||
ftp://.*/.* &YOCTO_DL_URL;/mirror/sources/ \
|
||||
http://.*/.* &YOCTO_DL_URL;/mirror/sources/ \
|
||||
https://.*/.* &YOCTO_DL_URL;/mirror/sources/"
|
||||
https://.*/.* &YOCTO_DL_URL;/mirror/sources/ \
|
||||
"
|
||||
|
||||
These changes cause the
|
||||
build system to intercept Git, FTP, HTTP, and HTTPS requests and
|
||||
@@ -7281,6 +7413,167 @@ system and gives an overview of their function and contents.
|
||||
|
||||
QA_EMPTY_DIRS_RECOMMENDATION:/dev = "but all devices must be created at runtime"
|
||||
|
||||
:term:`QB_CMDLINE_IP_SLIRP`
|
||||
|
||||
If :term:`QB_NETWORK_DEVICE` adds more than one network interface to QEMU,
|
||||
usually the ``ip=`` Linux kernel command line argument needs to be changed
|
||||
accordingly. The :term:`QB_CMDLINE_IP_SLIRP` variable allows controlling
|
||||
this value. See the Linux kernel documentation for more details:
|
||||
https://www.kernel.org/doc/Documentation/filesystems/nfs/nfsroot.txt.
|
||||
|
||||
:term:`QB_CMDLINE_IP_TAP`
|
||||
|
||||
This variable is similar to the :term:`QB_CMDLINE_IP_SLIRP` variable.
|
||||
|
||||
Use as follows::
|
||||
|
||||
QB_CMDLINE_IP_TAP = "ip=192.168.7.@CLIENT@::192.168.7.@GATEWAY@:255.255.255.0::eth0"
|
||||
|
||||
Since the tap interface requires static IP configuration, ``runqemu``
|
||||
replaces the ``@CLIENT@`` and ``@GATEWAY@`` place holders by the IP and
|
||||
the gateway address of the QEMU guest.
|
||||
|
||||
:term:`QB_DEFAULT_BIOS`
|
||||
The :term:`QB_DEFAULT_BIOS` variable can be used to provide a default
|
||||
value for the path of a file located in :term:`DEPLOY_DIR_IMAGE` and
|
||||
used by ``runqemu`` to specify the `-bios <https://www.qemu.org/docs/master/system/invocation.html#hxtool-8>`__
|
||||
option of QEMU. For example, this variable can be set as follows to
|
||||
emulate U-Boot for the :oecore_path:`qemuarm64 <meta/conf/machine/qemuarm64.conf>`
|
||||
machine::
|
||||
|
||||
QB_DEFAULT_BIOS = "u-boot.bin"
|
||||
|
||||
The above example makes the assumption the U-Boot recipe was built
|
||||
and that the ``u-boot.bin`` is deployed in the :term:`DEPLOY_DIR_IMAGE`
|
||||
directory.
|
||||
|
||||
.. note::
|
||||
|
||||
When using ``runqemu``, the ``BIOS`` environment variable takes
|
||||
precedence over this variable.
|
||||
|
||||
:term:`QB_DEFAULT_FSTYPE`
|
||||
|
||||
The :term:`QB_DEFAULT_FSTYPE` variable controls the default filesystem
|
||||
type to boot. It is represented as the file extension of one of the root
|
||||
filesystem image extension found in :term:`DEPLOY_DIR_IMAGE`. For example:
|
||||
``ext4.zst``.
|
||||
|
||||
:term:`QB_DEFAULT_KERNEL`
|
||||
|
||||
When using ``runqemu``, the :term:`QB_DEFAULT_KERNEL` variable controls
|
||||
the default Linux kernel image to boot, found in :term:`DEPLOY_DIR_IMAGE`. For
|
||||
example: ``bzImage``.
|
||||
|
||||
:term:`QB_DRIVE_TYPE`
|
||||
|
||||
When using ``runqemu``, the :term:`QB_DRIVE_TYPE` variable specifies the
|
||||
type of drive to emulate when starting the emulated machine.
|
||||
Valid values are:
|
||||
|
||||
- ``/dev/hd``: emulates an IDE drive.
|
||||
- ``/dev/mmcblk``: emulates an SD Card.
|
||||
- ``/dev/sd``: emulates an SCSI drive.
|
||||
- ``/dev/vd``: emulates a VirtIO drive.
|
||||
- ``/dev/vdb``: emulates a block VirtIO drive.
|
||||
|
||||
:term:`QB_GRAPHICS`
|
||||
|
||||
When using ``runqemu``, the :term:`QB_GRAPHICS` variable controls the QEMU
|
||||
video card type to emulate. For example: ``-vga std``.
|
||||
|
||||
This value is appended to the argument list when running ``qemu``.
|
||||
|
||||
:term:`QB_KERNEL_CMDLINE_APPEND`
|
||||
|
||||
The :term:`QB_KERNEL_CMDLINE_APPEND` variable controls the options passed
|
||||
to the Linux kernel's ``-append`` QEMU options, which controls the Linux kernel
|
||||
command-line.
|
||||
|
||||
For example::
|
||||
|
||||
QB_KERNEL_CMDLINE_APPEND = "console=ttyS0"
|
||||
|
||||
:term:`QB_MEM`
|
||||
|
||||
The :term:`QB_MEM` variable controls the amount of memory allocated to the
|
||||
emulated machine. Specify as follows::
|
||||
|
||||
QB_MEM = "-m 512"
|
||||
|
||||
:term:`QB_NETWORK_DEVICE`
|
||||
|
||||
When using ``runqemu``, the :term:`QB_NETWORK_DEVICE` variable controls
|
||||
the network device instantiated by QEMU. This value needs to be compatible
|
||||
with the :term:`QB_TAP_OPT` variable.
|
||||
|
||||
Example::
|
||||
|
||||
QB_NETWORK_DEVICE = "-device virtio-net-pci,netdev=net0,mac=@MAC@"
|
||||
|
||||
``runqemu`` replaces ``@MAC@`` with a predefined mac address.
|
||||
|
||||
:term:`QB_NFSROOTFS_EXTRA_OPT`
|
||||
|
||||
When using ``runqemu``, the :term:`QB_NFSROOTFS_EXTRA_OPT` variable
|
||||
controls extra options to be appended to the NFS rootfs options in the
|
||||
Linux kernel command-line.
|
||||
|
||||
For example::
|
||||
|
||||
QB_NFSROOTFS_EXTRA_OPT = "wsize=4096,rsize=4096"
|
||||
|
||||
:term:`QB_OPT_APPEND`
|
||||
|
||||
When using ``runqemu``, the :term:`QB_OPT_APPEND` variable controls
|
||||
general options to append to QEMU when starting.
|
||||
|
||||
:term:`QB_RNG`
|
||||
|
||||
When using ``runqemu``, the :term:`QB_RNG` variable controls
|
||||
pass-through for host random number generator, it can speedup boot
|
||||
in system mode, where system is experiencing entropy starvation.
|
||||
|
||||
For example::
|
||||
|
||||
QB_RNG = "-object rng-random,filename=/dev/urandom,id=rng0 -device virtio-rng-pci,rng=rng0"
|
||||
|
||||
:term:`QB_ROOTFS_EXTRA_OPT`
|
||||
|
||||
When using ``runqemu``, the :term:`QB_ROOTFS_EXTRA_OPT` variable controls
|
||||
extra options to be appended to the rootfs device options.
|
||||
|
||||
:term:`QB_SERIAL_OPT`
|
||||
|
||||
When using ``runqemu``, the :term:`QB_SERIAL_OPT` variable controls the
|
||||
serial port option.
|
||||
|
||||
For example::
|
||||
|
||||
QB_SERIAL_OPT = "-serial mon:stdio"
|
||||
|
||||
:term:`QB_SMP`
|
||||
|
||||
When using ``runqemu``, the :term:`QB_SMP` variable controls
|
||||
amount of CPU cores made availalble inside the QEMU guest, each mapped to
|
||||
a thread on the host.
|
||||
|
||||
For example::
|
||||
|
||||
QB_SMP = "-smp 8".
|
||||
|
||||
:term:`QB_TAP_OPT`
|
||||
|
||||
When using ``runqemu``, the :term:`QB_TAP_OPT` variable controls
|
||||
the network option for "tap" mode.
|
||||
|
||||
For example::
|
||||
|
||||
QB_TAP_OPT = "-netdev tap,id=net0,ifname=@TAP@,script=no,downscript=no"
|
||||
|
||||
Note that ``runqemu`` will replace ``@TAP@`` with the tap interface in
|
||||
use, such as ``tap0``, ``tap1``, etc.
|
||||
|
||||
:term:`RANLIB`
|
||||
The minimal command and arguments to run :manpage:`ranlib <ranlib(1)>`.
|
||||
|
||||
@@ -9827,7 +10120,8 @@ system and gives an overview of their function and contents.
|
||||
For background information on cross-development toolchains in the
|
||||
Yocto Project development environment, see the
|
||||
":ref:`sdk-manual/intro:the cross-development toolchain`"
|
||||
section in the Yocto Project Overview and Concepts Manual. For
|
||||
section in the Yocto Project Application Development and Software
|
||||
Development Kits (SDK/eSDK) Manual. For
|
||||
information on setting up a cross-development environment, see the
|
||||
:doc:`/sdk-manual/index` manual.
|
||||
|
||||
@@ -9875,7 +10169,8 @@ system and gives an overview of their function and contents.
|
||||
For background information on cross-development toolchains in the
|
||||
Yocto Project development environment, see the
|
||||
":ref:`sdk-manual/intro:the cross-development toolchain`"
|
||||
section in the Yocto Project Overview and Concepts Manual. For
|
||||
section in the Yocto Project Application Development and Software
|
||||
Development Kits (SDK/eSDK) Manual. For
|
||||
information on setting up a cross-development environment, see the
|
||||
:doc:`/sdk-manual/index` manual.
|
||||
|
||||
@@ -10500,7 +10795,7 @@ system and gives an overview of their function and contents.
|
||||
|
||||
For information on the
|
||||
standard Linux shell command ``useradd``, see
|
||||
https://linux.die.net/man/8/useradd.
|
||||
:manpage:`useradd(8)`.
|
||||
|
||||
:term:`USERADD_UID_TABLES`
|
||||
Specifies a password file to use for obtaining static user
|
||||
|
||||
@@ -96,8 +96,7 @@ build the SDK installer. Follow these steps:
|
||||
#. *Set Up the Build Environment:* Be sure you are set up to use BitBake
|
||||
in a shell. See the ":ref:`dev-manual/start:preparing the build host`" section
|
||||
in the Yocto Project Development Tasks Manual for information on how
|
||||
to get a build host ready that is either a native Linux machine or a
|
||||
machine that uses CROPS.
|
||||
to get a :term:`build host` ready.
|
||||
|
||||
#. *Clone the ``poky`` Repository:* You need to have a local copy of the
|
||||
Yocto Project :term:`Source Directory`
|
||||
|
||||
@@ -103,6 +103,10 @@ em {
|
||||
background: #f8f8f8;
|
||||
}
|
||||
|
||||
section#welcome-to-the-yocto-project-documentation p.caption {
|
||||
display: none;
|
||||
}
|
||||
|
||||
@media screen {
|
||||
.wy-nav-content {
|
||||
max-width: 1000px;
|
||||
|
||||
@@ -141,7 +141,7 @@ the following types of tests:
|
||||
built by the OpenEmbedded build system on the target machine. See the
|
||||
:ref:`Testing Packages With
|
||||
ptest <test-manual/ptest:Testing Packages With ptest>` section
|
||||
in the Yocto Project Development Tasks Manual and the
|
||||
in the Yocto Project Test Environment Manual and the
|
||||
":yocto_wiki:`Ptest </Ptest>`" Wiki page for more
|
||||
information on Ptest.
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
DISTRO = "poky"
|
||||
DISTRO_NAME = "Poky (Yocto Project Reference Distro)"
|
||||
DISTRO_VERSION = "5.0.19"
|
||||
DISTRO_VERSION = "5.0.20"
|
||||
DISTRO_CODENAME = "scarthgap"
|
||||
SDK_VENDOR = "-pokysdk"
|
||||
SDK_VERSION = "${@d.getVar('DISTRO_VERSION').replace('snapshot-${METADATA_REVISION}', 'snapshot')}"
|
||||
|
||||
@@ -468,8 +468,7 @@ PACKAGEFUNCS += " \
|
||||
package_do_shlibs \
|
||||
package_do_pkgconfig \
|
||||
read_shlibdeps \
|
||||
package_depchains \
|
||||
emit_pkgdata"
|
||||
package_depchains"
|
||||
|
||||
python do_package () {
|
||||
# Change the following version to cause sstate to invalidate the package
|
||||
@@ -561,9 +560,13 @@ python do_package () {
|
||||
for file in files:
|
||||
pkgfiles[pkg].append(walkroot + os.sep + file)
|
||||
|
||||
|
||||
# We want emit_pkgdata to run last, after everything
|
||||
for f in (d.getVar('PACKAGEFUNCS') or '').split():
|
||||
bb.build.exec_func(f, d)
|
||||
|
||||
bb.build.exec_func("emit_pkgdata", d)
|
||||
|
||||
oe.qa.exit_if_errors(d)
|
||||
}
|
||||
|
||||
|
||||
@@ -36,7 +36,8 @@ def get_crates(f):
|
||||
crates_candidates = list(filter(lambda c: 'crates.io' in c.get('source', ''), crates['package']))
|
||||
|
||||
if not crates_candidates:
|
||||
raise ValueError("Unable to find any candidate crates that use crates.io")
|
||||
print("WARNING: Unable to find any candidate crates that use crates.io")
|
||||
return None
|
||||
|
||||
# Update crates uri and their checksum, to avoid name clashing on the checksum
|
||||
# we need to rename crates with name and version to have a unique key
|
||||
@@ -63,14 +64,11 @@ for root, dirs, files in os.walk('${CARGO_LOCK_SRC_DIR}'):
|
||||
continue
|
||||
for file in files:
|
||||
if file == 'Cargo.lock':
|
||||
try:
|
||||
cargo_lock_path = os.path.join(root, file)
|
||||
crates += get_crates(os.path.join(root, file))
|
||||
except Exception as e:
|
||||
raise ValueError("Cannot parse '%s'" % cargo_lock_path) from e
|
||||
else:
|
||||
found = True
|
||||
if not found:
|
||||
cargo_lock_path = os.path.join(root, file)
|
||||
c = get_crates(cargo_lock_path)
|
||||
if c is not None:
|
||||
crates += c
|
||||
if crates is None:
|
||||
raise ValueError("Unable to find any Cargo.lock in ${CARGO_LOCK_SRC_DIR}")
|
||||
open("${TARGET_FILE}", 'w').write(crates)
|
||||
EOF
|
||||
|
||||
@@ -71,7 +71,7 @@ python do_create_image_sbom_spdx() {
|
||||
}
|
||||
addtask do_create_image_sbom_spdx after do_create_rootfs_spdx do_create_image_spdx before do_build
|
||||
SSTATETASKS += "do_create_image_sbom_spdx"
|
||||
SSTATE_SKIP_CREATION:task-create-image-sbom = "1"
|
||||
SSTATE_SKIP_CREATION:task-create-image-sbom-spdx = "1"
|
||||
do_create_image_sbom_spdx[sstate-inputdirs] = "${SPDXIMAGEDEPLOYDIR}"
|
||||
do_create_image_sbom_spdx[sstate-outputdirs] = "${DEPLOY_DIR_IMAGE}"
|
||||
do_create_image_sbom_spdx[stamp-extra-info] = "${MACHINE_ARCH}"
|
||||
|
||||
@@ -294,7 +294,7 @@ def get_deployed_files(man_file):
|
||||
dep_files.append(os.path.basename(f))
|
||||
return dep_files
|
||||
|
||||
ROOTFS_POSTPROCESS_COMMAND:prepend = "write_package_manifest license_create_manifest "
|
||||
ROOTFS_POSTUNINSTALL_COMMAND:prepend = "write_package_manifest license_create_manifest "
|
||||
do_rootfs[recrdeptask] += "do_populate_lic"
|
||||
|
||||
python do_populate_lic_deploy() {
|
||||
|
||||
@@ -10,4 +10,4 @@ deltask do_create_spdx_runtime
|
||||
deltask do_create_package_spdx
|
||||
deltask do_create_rootfs_spdx
|
||||
deltask do_create_image_spdx
|
||||
deltask do_create_image_sbom
|
||||
deltask do_create_image_sbom_spdx
|
||||
|
||||
@@ -229,7 +229,7 @@ python vex_write_rootfs_manifest () {
|
||||
bb.plain("Image VEX JSON report stored in: %s" % manifest_name)
|
||||
}
|
||||
|
||||
ROOTFS_POSTPROCESS_COMMAND:prepend = "vex_write_rootfs_manifest; "
|
||||
ROOTFS_POSTUNINSTALL_COMMAND:prepend = "vex_write_rootfs_manifest "
|
||||
do_rootfs[recrdeptask] += "do_generate_vex "
|
||||
do_populate_sdk[recrdeptask] += "do_generate_vex "
|
||||
|
||||
|
||||
@@ -19,6 +19,8 @@ PACKAGECONFIG ??= "openssl"
|
||||
# a host build dependency.
|
||||
PACKAGECONFIG[openssl] = ",,openssl-native"
|
||||
|
||||
CVE_PRODUCT = "denx:u-boot"
|
||||
|
||||
# Allow setting an additional version string that will be picked up by the
|
||||
# u-boot build system and appended to the u-boot version. If the .scmversion
|
||||
# file already exists it will not be overwritten.
|
||||
|
||||
@@ -20,7 +20,7 @@ SRC_URI = "https://ftp.isc.org/isc/bind9/${PV}/${BPN}-${PV}.tar.xz \
|
||||
file://0001-avoid-start-failure-with-bind-user.patch \
|
||||
"
|
||||
|
||||
SRC_URI[sha256sum] = "81f5035a25c576af1a93f0061cf70bde6d00a0c7bd1274abf73f5b5389a6f82d"
|
||||
SRC_URI[sha256sum] = "c43ce4548ebed788cd9df63658a7de105ceafba43fcd63fa352b1093e525cd24"
|
||||
|
||||
UPSTREAM_CHECK_URI = "https://ftp.isc.org/isc/bind9/"
|
||||
# follow the ESV versions divisible by 2
|
||||
@@ -15,6 +15,9 @@ SRC_URI = "git://github.com/NetworkConfiguration/dhcpcd;protocol=https;branch=ma
|
||||
file://dhcpcd.service \
|
||||
file://dhcpcd@.service \
|
||||
file://0001-dhcpcd.8-Fix-conflict-error-when-enable-multilib.patch \
|
||||
file://CVE-2026-56113.patch \
|
||||
file://CVE-2026-56114.patch \
|
||||
file://CVE-2026-56117.patch \
|
||||
"
|
||||
|
||||
SRCREV = "1c8ae59836fa87b4c63c598087f0460ec20ed862"
|
||||
|
||||
92
meta/recipes-connectivity/dhcpcd/files/CVE-2026-56113.patch
Normal file
92
meta/recipes-connectivity/dhcpcd/files/CVE-2026-56113.patch
Normal file
@@ -0,0 +1,92 @@
|
||||
From 9f953ada0df6e7a568f006f3ae0ff10a77a95924 Mon Sep 17 00:00:00 2001
|
||||
From: Roy Marples <roy@marples.name>
|
||||
Date: Tue, 23 Jun 2026 02:17:10 +0100
|
||||
Subject: [PATCH] DHCPv6: When deprecating addresses, restart on prefix
|
||||
deletions
|
||||
|
||||
As that might invalidate the next address to iterate on.
|
||||
|
||||
Reported-by: CuB3y0nd <root@cubeyond.net>
|
||||
|
||||
(cherry picked from commit 5733d3c59a5651f64357ac11c98b4f39895c8d25)
|
||||
|
||||
CVE: CVE-2026-56113
|
||||
Upstream-Status: Backport [https://github.com/NetworkConfiguration/dhcpcd/commit/5733d3c59a5651f64357ac11c98b4f39895c8d25]
|
||||
Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
|
||||
---
|
||||
src/dhcp6.c | 21 ++++++++++++++++++---
|
||||
1 file changed, 18 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/src/dhcp6.c b/src/dhcp6.c
|
||||
index bdc3664e..5154bf41 100644
|
||||
--- a/src/dhcp6.c
|
||||
+++ b/src/dhcp6.c
|
||||
@@ -2480,12 +2480,13 @@ dhcp6_findia(struct interface *ifp, struct dhcp6_message *m, size_t l,
|
||||
}
|
||||
|
||||
#ifndef SMALL
|
||||
-static void
|
||||
+static bool
|
||||
dhcp6_deprecatedele(struct ipv6_addr *ia)
|
||||
{
|
||||
struct ipv6_addr *da, *dan, *dda;
|
||||
struct timespec now;
|
||||
struct dhcp6_state *state;
|
||||
+ bool freed = false;
|
||||
|
||||
timespecclear(&now);
|
||||
TAILQ_FOREACH_SAFE(da, &ia->pd_pfxs, pd_next, dan) {
|
||||
@@ -2511,11 +2512,14 @@ dhcp6_deprecatedele(struct ipv6_addr *ia)
|
||||
if (IN6_ARE_ADDR_EQUAL(&dda->addr, &da->addr))
|
||||
break;
|
||||
}
|
||||
- if (dda != NULL) {
|
||||
+ if (dda != ia && dda != NULL) {
|
||||
TAILQ_REMOVE(&state->addrs, dda, next);
|
||||
ipv6_freeaddr(dda);
|
||||
+ freed = true;
|
||||
}
|
||||
}
|
||||
+
|
||||
+ return freed;
|
||||
}
|
||||
#endif
|
||||
|
||||
@@ -2523,7 +2527,11 @@ static void
|
||||
dhcp6_deprecateaddrs(struct ipv6_addrhead *addrs)
|
||||
{
|
||||
struct ipv6_addr *ia, *ian;
|
||||
+#ifndef SMALL
|
||||
+ bool again;
|
||||
+#endif
|
||||
|
||||
+again:
|
||||
TAILQ_FOREACH_SAFE(ia, addrs, next, ian) {
|
||||
if (ia->flags & IPV6_AF_EXTENDED)
|
||||
;
|
||||
@@ -2545,7 +2553,9 @@ dhcp6_deprecateaddrs(struct ipv6_addrhead *addrs)
|
||||
/* If we delegated from this prefix, deprecate or remove
|
||||
* the delegations. */
|
||||
if (ia->flags & IPV6_AF_DELEGATEDPFX)
|
||||
- dhcp6_deprecatedele(ia);
|
||||
+ again = dhcp6_deprecatedele(ia);
|
||||
+ else
|
||||
+ again = false;
|
||||
#endif
|
||||
|
||||
if (ia->flags & IPV6_AF_REQUEST) {
|
||||
@@ -2558,6 +2568,11 @@ dhcp6_deprecateaddrs(struct ipv6_addrhead *addrs)
|
||||
if (ia->flags & IPV6_AF_EXTENDED)
|
||||
ipv6_deleteaddr(ia);
|
||||
ipv6_freeaddr(ia);
|
||||
+#ifndef SMALL
|
||||
+ /* Deletion may invalidate the next pointer so restart */
|
||||
+ if (again)
|
||||
+ goto again;
|
||||
+#endif
|
||||
}
|
||||
}
|
||||
|
||||
--
|
||||
2.43.0
|
||||
|
||||
34
meta/recipes-connectivity/dhcpcd/files/CVE-2026-56114.patch
Normal file
34
meta/recipes-connectivity/dhcpcd/files/CVE-2026-56114.patch
Normal file
@@ -0,0 +1,34 @@
|
||||
From fd86ded940524f60174582faa96f583c168589ef Mon Sep 17 00:00:00 2001
|
||||
From: Roy Marples <roy@marples.name>
|
||||
Date: Tue, 23 Jun 2026 02:06:55 +0100
|
||||
Subject: [PATCH] DHCPv6: Prefix exclude option can be 17 octets (#671)
|
||||
|
||||
Well that's a simple off by one error
|
||||
|
||||
Reported-by: CuB3y0nd <root@cubeyond.net>
|
||||
|
||||
(cherry picked from commit 2f00c7bfc408b6582d331932dfa47829c4819029)
|
||||
|
||||
CVE: CVE-2026-56114
|
||||
Upstream-Status: Backport [https://github.com/NetworkConfiguration/dhcpcd/commit/2f00c7bfc408b6582d331932dfa47829c4819029]
|
||||
Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
|
||||
---
|
||||
src/dhcp6.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/dhcp6.c b/src/dhcp6.c
|
||||
index 5154bf41..1eac9f23 100644
|
||||
--- a/src/dhcp6.c
|
||||
+++ b/src/dhcp6.c
|
||||
@@ -1006,7 +1006,7 @@ dhcp6_makemessage(struct interface *ifp)
|
||||
|
||||
/* RFC6603 Section 4.2 */
|
||||
if (ap->prefix_exclude_len) {
|
||||
- uint8_t exb[16], *ep, u8;
|
||||
+ uint8_t exb[17], *ep, u8;
|
||||
const uint8_t *pp;
|
||||
|
||||
n = (size_t)((ap->prefix_exclude_len -
|
||||
--
|
||||
2.43.0
|
||||
|
||||
167
meta/recipes-connectivity/dhcpcd/files/CVE-2026-56117.patch
Normal file
167
meta/recipes-connectivity/dhcpcd/files/CVE-2026-56117.patch
Normal file
@@ -0,0 +1,167 @@
|
||||
From 52e0746deeace02b0ea039441d6cdc58f026018d Mon Sep 17 00:00:00 2001
|
||||
From: Roy Marples <roy@marples.name>
|
||||
Date: Mon, 22 Jun 2026 23:41:53 +0100
|
||||
Subject: [PATCH] control: Avoid hangup in the recvdata path
|
||||
|
||||
Instead return an error and bubble it up where it can be
|
||||
hangup / freed more cleanly.
|
||||
|
||||
Reported-by: CuB3y0nd <root@cubeyond.net>
|
||||
|
||||
(cherry picked from commit 78ea09ed1633a583dbcde6e7bab9df4639ec8a34)
|
||||
|
||||
CVE: CVE-2026-56117
|
||||
Upstream-Status: Backport [https://github.com/NetworkConfiguration/dhcpcd/commit/78ea09ed1633a583dbcde6e7bab9df4639ec8a34]
|
||||
Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
|
||||
---
|
||||
src/control.c | 47 ++++++++++++++++++++++++-------------------
|
||||
src/control.h | 2 +-
|
||||
src/privsep-control.c | 7 ++++++-
|
||||
3 files changed, 33 insertions(+), 23 deletions(-)
|
||||
|
||||
diff --git a/src/control.c b/src/control.c
|
||||
index 17fd13aa..20480f69 100644
|
||||
--- a/src/control.c
|
||||
+++ b/src/control.c
|
||||
@@ -115,10 +115,8 @@ control_handle_read(struct fd_list *fd)
|
||||
bytes = read(fd->fd, buffer, sizeof(buffer) - 1);
|
||||
if (bytes == -1)
|
||||
logerr(__func__);
|
||||
- if (bytes == -1 || bytes == 0) {
|
||||
- control_hangup(fd);
|
||||
- return -1;
|
||||
- }
|
||||
+ if (bytes == -1 || bytes == 0)
|
||||
+ return (int)bytes;
|
||||
|
||||
#ifdef PRIVSEP
|
||||
if (IN_PRIVSEP(fd->ctx)) {
|
||||
@@ -134,15 +132,13 @@ control_handle_read(struct fd_list *fd)
|
||||
if (err == 1 &&
|
||||
ps_ctl_sendargs(fd, buffer, (size_t)bytes) == -1) {
|
||||
logerr(__func__);
|
||||
- control_free(fd);
|
||||
return -1;
|
||||
}
|
||||
- return 0;
|
||||
+ return 1;
|
||||
}
|
||||
#endif
|
||||
|
||||
- control_recvdata(fd, buffer, (size_t)bytes);
|
||||
- return 0;
|
||||
+ return control_recvdata(fd, buffer, (size_t)bytes);
|
||||
}
|
||||
|
||||
static int
|
||||
@@ -205,23 +201,31 @@ static void
|
||||
control_handle_data(void *arg, unsigned short events)
|
||||
{
|
||||
struct fd_list *fd = arg;
|
||||
+ int err;
|
||||
|
||||
if (!(events & (ELE_READ | ELE_WRITE | ELE_HANGUP)))
|
||||
logerrx("%s: unexpected event 0x%04x", __func__, events);
|
||||
|
||||
if (events & ELE_WRITE && !(events & ELE_HANGUP)) {
|
||||
- if (control_handle_write(fd) == -1)
|
||||
- return;
|
||||
+ err = control_handle_write(fd);
|
||||
+ if (err == -1)
|
||||
+ goto hangup;
|
||||
}
|
||||
if (events & ELE_READ) {
|
||||
- if (control_handle_read(fd) == -1)
|
||||
- return;
|
||||
+ err = control_handle_read(fd);
|
||||
+ if (err == -1 || err == 0)
|
||||
+ goto hangup;
|
||||
}
|
||||
if (events & ELE_HANGUP)
|
||||
- control_hangup(fd);
|
||||
+ goto hangup;
|
||||
+
|
||||
+ return;
|
||||
+
|
||||
+hangup:
|
||||
+ control_hangup(fd);
|
||||
}
|
||||
|
||||
-void
|
||||
+int
|
||||
control_recvdata(struct fd_list *fd, char *data, size_t len)
|
||||
{
|
||||
char *p = data, *e;
|
||||
@@ -243,12 +247,13 @@ control_recvdata(struct fd_list *fd, char *data, size_t len)
|
||||
if (e == NULL) {
|
||||
errno = EINVAL;
|
||||
logerrx("%s: no terminator", __func__);
|
||||
- return;
|
||||
+ return -1;
|
||||
}
|
||||
- if ((size_t)argc >= sizeof(argvp) / sizeof(argvp[0])) {
|
||||
+ if ((size_t)argc + 1 >=
|
||||
+ sizeof(argvp) / sizeof(argvp[0])) {
|
||||
errno = ENOBUFS;
|
||||
logerrx("%s: no arg buffer", __func__);
|
||||
- return;
|
||||
+ return -1;
|
||||
}
|
||||
*ap++ = p;
|
||||
argc++;
|
||||
@@ -268,12 +273,12 @@ control_recvdata(struct fd_list *fd, char *data, size_t len)
|
||||
*ap = NULL;
|
||||
if (dhcpcd_handleargs(fd->ctx, fd, argc, argvp) == -1) {
|
||||
logerr(__func__);
|
||||
- if (errno != EINTR && errno != EAGAIN) {
|
||||
- control_free(fd);
|
||||
- return;
|
||||
- }
|
||||
+ if (errno != EINTR && errno != EAGAIN)
|
||||
+ return -1;
|
||||
}
|
||||
}
|
||||
+
|
||||
+ return 1;
|
||||
}
|
||||
|
||||
struct fd_list *
|
||||
diff --git a/src/control.h b/src/control.h
|
||||
index f5e2bc7e..c5511dd7 100644
|
||||
--- a/src/control.h
|
||||
+++ b/src/control.h
|
||||
@@ -75,5 +75,5 @@ struct fd_list *control_new(struct dhcpcd_ctx *, int, unsigned int);
|
||||
void control_free(struct fd_list *);
|
||||
void control_delete(struct fd_list *);
|
||||
int control_queue(struct fd_list *, void *, size_t);
|
||||
-void control_recvdata(struct fd_list *fd, char *, size_t);
|
||||
+int control_recvdata(struct fd_list *fd, char *, size_t);
|
||||
#endif
|
||||
diff --git a/src/privsep-control.c b/src/privsep-control.c
|
||||
index 40bfb164..954126c0 100644
|
||||
--- a/src/privsep-control.c
|
||||
+++ b/src/privsep-control.c
|
||||
@@ -108,6 +108,7 @@ ps_ctl_dispatch(void *arg, struct ps_msghdr *psm, struct msghdr *msg)
|
||||
struct iovec *iov = msg->msg_iov;
|
||||
struct fd_list *fd;
|
||||
unsigned int fd_flags = FD_SENDLEN;
|
||||
+ int err;
|
||||
|
||||
switch (psm->ps_flags) {
|
||||
case PS_CTL_PRIV:
|
||||
@@ -131,7 +132,11 @@ ps_ctl_dispatch(void *arg, struct ps_msghdr *psm, struct msghdr *msg)
|
||||
if (fd == NULL)
|
||||
return -1;
|
||||
ctx->ps_control_client = fd;
|
||||
- control_recvdata(fd, iov->iov_base, iov->iov_len);
|
||||
+ err = control_recvdata(fd, iov->iov_base, iov->iov_len);
|
||||
+ if (err == -1 || err == 0) {
|
||||
+ control_free(fd);
|
||||
+ ctx->ps_control_client = NULL;
|
||||
+ }
|
||||
break;
|
||||
case PS_CTL_EOF:
|
||||
ctx->ps_control_client = NULL;
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -14,7 +14,7 @@ Reported by Christos Papakonstantinou of Cantina and Spearbit.
|
||||
|
||||
OpenBSD-Commit-ID: c790e2687c35989ae34a00e709be935c55b16a86
|
||||
|
||||
CVE: CVE-2026-35387
|
||||
CVE: CVE-2026-35414 CVE-2026-35387
|
||||
Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/fd1c7e131f331942d20f42f31e79912d570081fa]
|
||||
Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
|
||||
---
|
||||
@@ -0,0 +1,42 @@
|
||||
From b340eaa274a7e7dffea03bcb62169249bbddab37 Mon Sep 17 00:00:00 2001
|
||||
From: "djm@openbsd.org" <djm@openbsd.org>
|
||||
Date: Mon, 29 Jun 2026 01:47:21 +0000
|
||||
Subject: [PATCH] upstream: avoid download to server-controlled path when
|
||||
performing
|
||||
|
||||
download on the commandline. From Swival scanner
|
||||
|
||||
CVE: CVE-2026-59995
|
||||
Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/1b39f39657d2e58f8ec57341581a39bbf0be645b]
|
||||
|
||||
Backport Changes:
|
||||
- Retained the Scarthgap sftp.c OpenBSD revision identifier because the
|
||||
10.4 identifier does not describe the older source baseline.
|
||||
|
||||
OpenBSD-Commit-ID: d1b2c44305fdfe6d51eed9ecc727e59478bf311f
|
||||
(cherry picked from commit 1b39f39657d2e58f8ec57341581a39bbf0be645b)
|
||||
Signed-off-by: Devansh Patel <devanshp@cisco.com>
|
||||
---
|
||||
sftp.c | 9 ++-------
|
||||
1 file changed, 2 insertions(+), 7 deletions(-)
|
||||
|
||||
diff --git a/sftp.c b/sftp.c
|
||||
index c609b4153..487e53976 100644
|
||||
--- a/sftp.c
|
||||
+++ b/sftp.c
|
||||
@@ -2268,13 +2268,8 @@ interactive_loop(struct sftp_conn *conn, char *file1, char *file2)
|
||||
return (-1);
|
||||
}
|
||||
} else {
|
||||
- /* XXX this is wrong wrt quoting */
|
||||
- snprintf(cmd, sizeof cmd, "get%s %s%s%s",
|
||||
- global_aflag ? " -a" : "", dir,
|
||||
- file2 == NULL ? "" : " ",
|
||||
- file2 == NULL ? "" : file2);
|
||||
- err = parse_dispatch_command(conn, cmd,
|
||||
- &remote_path, startdir, 1, 0);
|
||||
+ err = process_get(conn, dir, file2, remote_path, 0, 0,
|
||||
+ global_aflag, 0);
|
||||
free(dir);
|
||||
free(startdir);
|
||||
free(remote_path);
|
||||
@@ -0,0 +1,37 @@
|
||||
From 762b3d438547893d62ce3e147dce6cef14697b09 Mon Sep 17 00:00:00 2001
|
||||
From: "djm@openbsd.org" <djm@openbsd.org>
|
||||
Date: Sun, 28 Jun 2026 23:47:16 +0000
|
||||
Subject: [PATCH] upstream: resist that return ".." via remote glob during
|
||||
|
||||
remote/remote copies, similar to fixes for bz3871 for remote/local copies.
|
||||
From Swival scanner
|
||||
|
||||
CVE: CVE-2026-59996
|
||||
Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/36480181fa22f98e180b4f9e10203480c0346c78]
|
||||
|
||||
Backport Changes:
|
||||
- Retained the Scarthgap scp.c OpenBSD revision identifier because the
|
||||
10.4 identifier does not describe the older source baseline.
|
||||
|
||||
OpenBSD-Commit-ID: c0c20a1b746db55c08e53658bf21ea9405b300a5
|
||||
(cherry picked from commit 36480181fa22f98e180b4f9e10203480c0346c78)
|
||||
Signed-off-by: Devansh Patel <devanshp@cisco.com>
|
||||
---
|
||||
scp.c | 4 ++++
|
||||
1 file changed, 4 insertions(+)
|
||||
|
||||
diff --git a/scp.c b/scp.c
|
||||
index 2c21fa19a..00d87517d 100644
|
||||
--- a/scp.c
|
||||
+++ b/scp.c
|
||||
@@ -2043,6 +2043,10 @@ throughlocal_sftp(struct sftp_conn *from, struct sftp_conn *to,
|
||||
goto out;
|
||||
}
|
||||
|
||||
+ /* Special handling for source of '..' */
|
||||
+ if (strcmp(filename, "..") == 0)
|
||||
+ filename = "."; /* Download to dest, not dest/.. */
|
||||
+
|
||||
if (targetisdir)
|
||||
abs_dst = sftp_path_append(target, filename);
|
||||
else
|
||||
@@ -0,0 +1,58 @@
|
||||
From 3011cbb6bb73f3f3dc90fa1d48736803fa407509 Mon Sep 17 00:00:00 2001
|
||||
From: "djm@openbsd.org" <djm@openbsd.org>
|
||||
Date: Fri, 5 Jun 2026 08:53:07 +0000
|
||||
Subject: [PATCH] upstream: pass >9 commandline arguments to the internal-sftp
|
||||
server,
|
||||
|
||||
previously they were silently dropped; reported by Steve Caffrey ok deraadt@
|
||||
|
||||
CVE: CVE-2026-59997
|
||||
Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/e9916c44c1324ab9ab022719e4df08a390a83014]
|
||||
|
||||
Backport Changes:
|
||||
- Retained the Scarthgap session.c OpenBSD revision identifier because the
|
||||
10.4 identifier does not describe the older source baseline.
|
||||
|
||||
OpenBSD-Commit-ID: ee6cd5430a3ca027c3223af54b58ad3cc7ccd624
|
||||
(cherry picked from commit e9916c44c1324ab9ab022719e4df08a390a83014)
|
||||
Signed-off-by: Devansh Patel <devanshp@cisco.com>
|
||||
---
|
||||
session.c | 19 ++++++++++---------
|
||||
1 file changed, 10 insertions(+), 9 deletions(-)
|
||||
|
||||
diff --git a/session.c b/session.c
|
||||
index eb932b8bf..1a01ecf74 100644
|
||||
--- a/session.c
|
||||
+++ b/session.c
|
||||
@@ -1650,21 +1650,22 @@ do_child(struct ssh *ssh, Session *s, const char *command)
|
||||
exit(1);
|
||||
} else if (s->is_subsystem == SUBSYSTEM_INT_SFTP) {
|
||||
extern int optind, optreset;
|
||||
- int i;
|
||||
- char *p, *args;
|
||||
+ int sftp_argc;
|
||||
+ char **sftp_argv;
|
||||
|
||||
setproctitle("%s@%s", s->pw->pw_name, INTERNAL_SFTP_NAME);
|
||||
- args = xstrdup(command ? command : "sftp-server");
|
||||
- for (i = 0, (p = strtok(args, " ")); p; (p = strtok(NULL, " ")))
|
||||
- if (i < ARGV_MAX - 1)
|
||||
- argv[i++] = p;
|
||||
- argv[i] = NULL;
|
||||
+ if (argv_split(command == NULL ? "sftp-server" : command,
|
||||
+ &sftp_argc, &sftp_argv, 1) != 0) {
|
||||
+ error("internal error: can't split internal-sftp "
|
||||
+ "arguments");
|
||||
+ exit(1);
|
||||
+ }
|
||||
optind = optreset = 1;
|
||||
- __progname = argv[0];
|
||||
+ __progname = sftp_argv[0];
|
||||
#ifdef WITH_SELINUX
|
||||
ssh_selinux_change_context("sftpd_t");
|
||||
#endif
|
||||
- exit(sftp_server_main(i, argv, s->pw));
|
||||
+ exit(sftp_server_main(sftp_argc, sftp_argv, s->pw));
|
||||
}
|
||||
|
||||
fflush(NULL);
|
||||
@@ -0,0 +1,36 @@
|
||||
From 1c719fa7d0fb0aa335f0e8d5db5d5e5d01c894e5 Mon Sep 17 00:00:00 2001
|
||||
From: "djm@openbsd.org" <djm@openbsd.org>
|
||||
Date: Sun, 31 May 2026 04:47:29 +0000
|
||||
Subject: [PATCH] upstream: DisableForwarding=yes didn't override
|
||||
PermitTunnel=yes
|
||||
|
||||
Reported independently by Huzaifa Sidhpurwala of Redhat and Marko
|
||||
Jevtic; ok markus@
|
||||
|
||||
CVE: CVE-2026-59999
|
||||
Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/8dfe7ed6e2fd988de08df508355a196b956b2753]
|
||||
|
||||
Backport Changes:
|
||||
- Retained the Scarthgap serverloop.c OpenBSD revision identifier because
|
||||
the 10.4 identifier does not describe the older source baseline.
|
||||
|
||||
OpenBSD-Commit-ID: b5c13f0746cf079b21f8deba47407fad49ccbf4c
|
||||
(cherry picked from commit 8dfe7ed6e2fd988de08df508355a196b956b2753)
|
||||
Signed-off-by: Devansh Patel <devanshp@cisco.com>
|
||||
---
|
||||
serverloop.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/serverloop.c b/serverloop.c
|
||||
index f3683c2e4..c1fe99d12 100644
|
||||
--- a/serverloop.c
|
||||
+++ b/serverloop.c
|
||||
@@ -531,7 +531,7 @@ server_request_tun(struct ssh *ssh)
|
||||
ssh_packet_send_debug(ssh, "Unsupported tunnel device mode.");
|
||||
return NULL;
|
||||
}
|
||||
- if ((options.permit_tun & mode) == 0) {
|
||||
+ if ((options.permit_tun & mode) == 0 || options.disable_forwarding) {
|
||||
ssh_packet_send_debug(ssh, "Server has rejected tunnel device "
|
||||
"forwarding");
|
||||
return NULL;
|
||||
140
meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch
Normal file
140
meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch
Normal file
@@ -0,0 +1,140 @@
|
||||
From 055316632809a2e2e58eac2020699b52187d1b11 Mon Sep 17 00:00:00 2001
|
||||
From: "djm@openbsd.org" <djm@openbsd.org>
|
||||
Date: Mon, 6 Jul 2026 07:53:30 +0000
|
||||
Subject: [PATCH] upstream: Fix multiple RFC 4462 (GSSAPIAuthentication)
|
||||
compliance
|
||||
|
||||
problems
|
||||
|
||||
1) Remove an early failure return for GSSAPI authentication attempts
|
||||
made for invalid accounts that yielded different behaviour for
|
||||
valid vs invalid accounts.
|
||||
|
||||
2) Fix a situation where some GSSAPI requestes were not correctly
|
||||
subjected to MaxAuthTries.
|
||||
|
||||
3) Fix a moderate pre-authentication resource DoS related to #2.
|
||||
|
||||
Add missing logging for error cases.
|
||||
|
||||
Report and fixes from Manfred Kaiser, milCERT AT
|
||||
|
||||
CVE: CVE-2026-60000
|
||||
Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/5d04ca6af739b82fd30d84d2783ca802ebfa1192]
|
||||
|
||||
Backport Changes:
|
||||
- Kept Scarthgap's PRIVSEP(ssh_gssapi_server_ctx()) interface and its
|
||||
authentication-context guard while applying the upstream RFC 4462 state,
|
||||
failure, logging, and MaxAuthTries changes.
|
||||
- Retained the Scarthgap auth2-gss.c OpenBSD revision identifier.
|
||||
|
||||
OpenBSD-Commit-ID: ca0acdd64eea435d6f89534538a9eb404a5629d3
|
||||
(cherry picked from commit 5d04ca6af739b82fd30d84d2783ca802ebfa1192)
|
||||
Signed-off-by: Devansh Patel <devanshp@cisco.com>
|
||||
---
|
||||
auth2-gss.c | 53 ++++++++++++++++++++++++-----------------------------
|
||||
1 file changed, 24 insertions(+), 29 deletions(-)
|
||||
|
||||
diff --git a/auth2-gss.c b/auth2-gss.c
|
||||
index 195578bcf..6846eae5b 100644
|
||||
--- a/auth2-gss.c
|
||||
+++ b/auth2-gss.c
|
||||
@@ -110,12 +110,6 @@ userauth_gssapi(struct ssh *ssh, const char *method)
|
||||
return (0);
|
||||
}
|
||||
|
||||
- if (!authctxt->valid || authctxt->user == NULL) {
|
||||
- debug2_f("disabled because of invalid user");
|
||||
- free(doid);
|
||||
- return (0);
|
||||
- }
|
||||
-
|
||||
if (GSS_ERROR(PRIVSEP(ssh_gssapi_server_ctx(&ctxt, &goid)))) {
|
||||
if (ctxt != NULL)
|
||||
ssh_gssapi_delete_ctx(&ctxt);
|
||||
@@ -177,8 +171,14 @@ input_gssapi_token(int type, u_int32_t plen, struct ssh *ssh)
|
||||
(r = sshpkt_send(ssh)) != 0)
|
||||
fatal_fr(r, "send ERRTOK packet");
|
||||
}
|
||||
+ logit("Failed gssapi-with-mic for %s%.100s "
|
||||
+ "from %.200s port %d ssh2",
|
||||
+ authctxt->valid ? "" : "invalid user ",
|
||||
+ authctxt->user,
|
||||
+ ssh_remote_ipaddr(ssh), ssh_remote_port(ssh));
|
||||
authctxt->postponed = 0;
|
||||
ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
|
||||
+ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_ERRTOK, NULL);
|
||||
userauth_finish(ssh, 0, "gssapi-with-mic", NULL);
|
||||
} else {
|
||||
if (send_tok.length != 0) {
|
||||
@@ -190,14 +190,18 @@ input_gssapi_token(int type, u_int32_t plen, struct ssh *ssh)
|
||||
fatal_fr(r, "send TOKEN packet");
|
||||
}
|
||||
if (maj_status == GSS_S_COMPLETE) {
|
||||
- ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
|
||||
- if (flags & GSS_C_INTEG_FLAG)
|
||||
- ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_MIC,
|
||||
+ ssh_dispatch_set(ssh,
|
||||
+ SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
|
||||
+ /* note: keep ERRTOK handler as per RFC 4462 s3.4 */
|
||||
+ if (flags & GSS_C_INTEG_FLAG) {
|
||||
+ ssh_dispatch_set(ssh,
|
||||
+ SSH2_MSG_USERAUTH_GSSAPI_MIC,
|
||||
&input_gssapi_mic);
|
||||
- else
|
||||
+ } else {
|
||||
ssh_dispatch_set(ssh,
|
||||
SSH2_MSG_USERAUTH_GSSAPI_EXCHANGE_COMPLETE,
|
||||
&input_gssapi_exchange_complete);
|
||||
+ }
|
||||
}
|
||||
}
|
||||
|
||||
@@ -209,10 +213,6 @@ static int
|
||||
input_gssapi_errtok(int type, u_int32_t plen, struct ssh *ssh)
|
||||
{
|
||||
Authctxt *authctxt = ssh->authctxt;
|
||||
- Gssctxt *gssctxt;
|
||||
- gss_buffer_desc send_tok = GSS_C_EMPTY_BUFFER;
|
||||
- gss_buffer_desc recv_tok;
|
||||
- OM_uint32 maj_status;
|
||||
int r;
|
||||
u_char *p;
|
||||
size_t len;
|
||||
@@ -220,26 +220,21 @@ input_gssapi_errtok(int type, u_int32_t plen, struct ssh *ssh)
|
||||
if (authctxt == NULL || (authctxt->methoddata == NULL && !use_privsep))
|
||||
fatal("No authentication or GSSAPI context");
|
||||
|
||||
- gssctxt = authctxt->methoddata;
|
||||
- if ((r = sshpkt_get_string(ssh, &p, &len)) != 0 ||
|
||||
+ /* Minimal error handling - just cancel auth and return FAILURE */
|
||||
+ if ((r = sshpkt_get_string_direct(ssh, NULL, NULL)) != 0 ||
|
||||
(r = sshpkt_get_end(ssh)) != 0)
|
||||
fatal_fr(r, "parse packet");
|
||||
- recv_tok.value = p;
|
||||
- recv_tok.length = len;
|
||||
-
|
||||
- /* Push the error token into GSSAPI to see what it says */
|
||||
- maj_status = PRIVSEP(ssh_gssapi_accept_ctx(gssctxt, &recv_tok,
|
||||
- &send_tok, NULL));
|
||||
-
|
||||
- free(recv_tok.value);
|
||||
|
||||
- /* We can't return anything to the client, even if we wanted to */
|
||||
+ logit("Failed gssapi-with-mic for %s%.100s from %.200s port %d ssh2",
|
||||
+ authctxt->valid ? "" : "invalid user ",
|
||||
+ authctxt->user,
|
||||
+ ssh_remote_ipaddr(ssh), ssh_remote_port(ssh));
|
||||
+ authctxt->postponed = 0;
|
||||
ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
|
||||
ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_ERRTOK, NULL);
|
||||
-
|
||||
- /* The client will have already moved on to the next auth */
|
||||
-
|
||||
- gss_release_buffer(&maj_status, &send_tok);
|
||||
+ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_MIC, NULL);
|
||||
+ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_EXCHANGE_COMPLETE, NULL);
|
||||
+ userauth_finish(ssh, 0, "gssapi-with-mic", NULL);
|
||||
return 0;
|
||||
}
|
||||
|
||||
130
meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch
Normal file
130
meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch
Normal file
@@ -0,0 +1,130 @@
|
||||
From ef41798b35a53757f8aa08ad14ee1463b0fe9b15 Mon Sep 17 00:00:00 2001
|
||||
From: "djm@openbsd.org" <djm@openbsd.org>
|
||||
Date: Mon, 6 Jul 2026 07:44:48 +0000
|
||||
Subject: [PATCH] upstream: Fix cases in GSSAPI and keyboard-interactive
|
||||
|
||||
authentication where the minimum per-attempt delay was not being enforced.
|
||||
|
||||
Reported by Orange Cyberdefense Vulnerability Team
|
||||
|
||||
CVE: CVE-2026-60001
|
||||
Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/d43ba60c91cb323ca921049b7d43b1908c318454]
|
||||
|
||||
Backport Changes:
|
||||
- Kept Scarthgap's PRIVSEP(ssh_gssapi_userok()) interface and GSSAPI
|
||||
display-name recording while adding the upstream failure-delay calls;
|
||||
mm_ssh_gssapi_userok() belongs to the later split-sshd architecture.
|
||||
- Retained the Scarthgap OpenBSD revision identifiers in auth.h,
|
||||
auth2-chall.c, auth2-gss.c, and auth2.c.
|
||||
|
||||
OpenBSD-Commit-ID: c40bd35cc2428fcaccad7a141703c28baa6da01e
|
||||
(cherry picked from commit d43ba60c91cb323ca921049b7d43b1908c318454)
|
||||
Signed-off-by: Devansh Patel <devanshp@cisco.com>
|
||||
---
|
||||
auth.h | 1 +
|
||||
auth2-chall.c | 4 ++++
|
||||
auth2-gss.c | 7 +++++++
|
||||
auth2.c | 10 ++++++++--
|
||||
4 files changed, 20 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/auth.h b/auth.h
|
||||
index 6d2d39762..9ad4898c5 100644
|
||||
--- a/auth.h
|
||||
+++ b/auth.h
|
||||
@@ -173,6 +173,7 @@ void auth_log(struct ssh *, int, int, const char *, const char *);
|
||||
void auth_maxtries_exceeded(struct ssh *) __attribute__((noreturn));
|
||||
void userauth_finish(struct ssh *, int, const char *, const char *);
|
||||
int auth_root_allowed(struct ssh *, const char *);
|
||||
+void auth_failure_delay(Authctxt *, double);
|
||||
|
||||
char *auth2_read_banner(void);
|
||||
int auth2_methods_valid(const char *, int);
|
||||
diff --git a/auth2-chall.c b/auth2-chall.c
|
||||
index 021df8291..20e70d222 100644
|
||||
--- a/auth2-chall.c
|
||||
+++ b/auth2-chall.c
|
||||
@@ -296,6 +296,7 @@ input_userauth_info_response(int type, u_int32_t seq, struct ssh *ssh)
|
||||
u_int i, nresp;
|
||||
const char *devicename = NULL;
|
||||
char **response = NULL;
|
||||
+ double tstart = monotime_double();
|
||||
|
||||
if (authctxt == NULL)
|
||||
fatal_f("no authctxt");
|
||||
@@ -354,6 +355,9 @@ input_userauth_info_response(int type, u_int32_t seq, struct ssh *ssh)
|
||||
auth2_challenge_start(ssh);
|
||||
}
|
||||
}
|
||||
+
|
||||
+ if (!authenticated)
|
||||
+ auth_failure_delay(authctxt, tstart);
|
||||
userauth_finish(ssh, authenticated, "keyboard-interactive",
|
||||
devicename);
|
||||
return 0;
|
||||
diff --git a/auth2-gss.c b/auth2-gss.c
|
||||
index f72a38998..195578bcf 100644
|
||||
--- a/auth2-gss.c
|
||||
+++ b/auth2-gss.c
|
||||
@@ -255,6 +255,7 @@ input_gssapi_exchange_complete(int type, u_int32_t plen, struct ssh *ssh)
|
||||
Authctxt *authctxt = ssh->authctxt;
|
||||
int r, authenticated;
|
||||
const char *displayname;
|
||||
+ double tstart = monotime_double();
|
||||
|
||||
if (authctxt == NULL || (authctxt->methoddata == NULL && !use_privsep))
|
||||
fatal("No authentication or GSSAPI context");
|
||||
@@ -268,6 +269,8 @@ input_gssapi_exchange_complete(int type, u_int32_t plen, struct ssh *ssh)
|
||||
fatal_fr(r, "parse packet");
|
||||
|
||||
authenticated = PRIVSEP(ssh_gssapi_userok(authctxt->user));
|
||||
+ if (!authenticated)
|
||||
+ auth_failure_delay(authctxt, tstart);
|
||||
|
||||
if ((!use_privsep || mm_is_monitor()) &&
|
||||
(displayname = ssh_gssapi_displayname()) != NULL)
|
||||
@@ -293,6 +296,7 @@ input_gssapi_mic(int type, u_int32_t plen, struct ssh *ssh)
|
||||
const char *displayname;
|
||||
u_char *p;
|
||||
size_t len;
|
||||
+ double tstart = monotime_double();
|
||||
|
||||
if (authctxt == NULL || (authctxt->methoddata == NULL && !use_privsep))
|
||||
fatal("No authentication or GSSAPI context");
|
||||
@@ -320,6 +324,9 @@ input_gssapi_mic(int type, u_int32_t plen, struct ssh *ssh)
|
||||
sshbuf_free(b);
|
||||
free(mic.value);
|
||||
|
||||
+ if (!authenticated)
|
||||
+ auth_failure_delay(authctxt, tstart);
|
||||
+
|
||||
if ((!use_privsep || mm_is_monitor()) &&
|
||||
(displayname = ssh_gssapi_displayname()) != NULL)
|
||||
auth2_record_info(authctxt, "%s", displayname);
|
||||
diff --git a/auth2.c b/auth2.c
|
||||
index 271789a77..18077d625 100644
|
||||
--- a/auth2.c
|
||||
+++ b/auth2.c
|
||||
@@ -265,6 +265,12 @@ ensure_minimum_time_since(double start, double seconds)
|
||||
nanosleep(&ts, NULL);
|
||||
}
|
||||
|
||||
+void
|
||||
+auth_failure_delay(Authctxt *authctxt, double tstart)
|
||||
+{
|
||||
+ ensure_minimum_time_since(tstart, user_specific_delay(authctxt->user));
|
||||
+}
|
||||
+
|
||||
static int
|
||||
input_userauth_request(int type, u_int32_t seq, struct ssh *ssh)
|
||||
{
|
||||
@@ -348,8 +354,8 @@ input_userauth_request(int type, u_int32_t seq, struct ssh *ssh)
|
||||
authenticated = m->userauth(ssh, method);
|
||||
}
|
||||
if (!authctxt->authenticated && strcmp(method, "none") != 0)
|
||||
- ensure_minimum_time_since(tstart,
|
||||
- user_specific_delay(authctxt->user));
|
||||
+ auth_failure_delay(authctxt, tstart);
|
||||
+
|
||||
userauth_finish(ssh, authenticated, method, NULL);
|
||||
r = 0;
|
||||
out:
|
||||
226
meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch
Normal file
226
meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch
Normal file
@@ -0,0 +1,226 @@
|
||||
From 767104acedd68c317b9d8fb603561e1a8be9e76a Mon Sep 17 00:00:00 2001
|
||||
From: "djm@openbsd.org" <djm@openbsd.org>
|
||||
Date: Mon, 6 Jul 2026 07:49:58 +0000
|
||||
Subject: [PATCH] upstream: fix ownership and lifetime of several bits of
|
||||
client
|
||||
|
||||
state that need to persist for the life of the connection, especially the
|
||||
cached hostkey that was being incorrectly freed early on some paths, possibly
|
||||
allowing its use after free.
|
||||
|
||||
Reported by Zhenpeng (Leo) Lin from depthfirst.com
|
||||
|
||||
CVE: CVE-2026-60002
|
||||
Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/e8bdfb151a356d0171fea4194dd205fbb252be23]
|
||||
|
||||
Backport Changes:
|
||||
- Retained Scarthgap's valid_hostname() and valid_ruser() helpers when
|
||||
relocating ssh_conn_info_free() from ssh.c to sshconnect.c.
|
||||
- Retained Scarthgap's ext-info-c proposal handling while applying the
|
||||
upstream connection-state ownership and lifetime changes.
|
||||
- Retained the Scarthgap OpenBSD revision identifiers in ssh.c,
|
||||
sshconnect.c, sshconnect.h, and sshconnect2.c.
|
||||
|
||||
OpenBSD-Commit-ID: faaa6ad72e7d69d41fa8b197b606265b7d9bc73f
|
||||
(cherry picked from commit e8bdfb151a356d0171fea4194dd205fbb252be23)
|
||||
Signed-off-by: Devansh Patel <devanshp@cisco.com>
|
||||
---
|
||||
ssh.c | 24 ++----------------------
|
||||
sshconnect.c | 47 +++++++++++++++++++++++++++++++++++++++++++++--
|
||||
sshconnect.h | 7 +++++--
|
||||
sshconnect2.c | 20 +++++++++++---------
|
||||
4 files changed, 63 insertions(+), 35 deletions(-)
|
||||
|
||||
diff --git a/ssh.c b/ssh.c
|
||||
index 9c49f98a8..aecdb79ea 100644
|
||||
--- a/ssh.c
|
||||
+++ b/ssh.c
|
||||
@@ -606,26 +606,6 @@ set_addrinfo_port(struct addrinfo *addrs, int port)
|
||||
}
|
||||
}
|
||||
|
||||
-static void
|
||||
-ssh_conn_info_free(struct ssh_conn_info *cinfo)
|
||||
-{
|
||||
- if (cinfo == NULL)
|
||||
- return;
|
||||
- free(cinfo->conn_hash_hex);
|
||||
- free(cinfo->shorthost);
|
||||
- free(cinfo->uidstr);
|
||||
- free(cinfo->keyalias);
|
||||
- free(cinfo->thishost);
|
||||
- free(cinfo->host_arg);
|
||||
- free(cinfo->portstr);
|
||||
- free(cinfo->remhost);
|
||||
- free(cinfo->remuser);
|
||||
- free(cinfo->homedir);
|
||||
- free(cinfo->locuser);
|
||||
- free(cinfo->jmphost);
|
||||
- free(cinfo);
|
||||
-}
|
||||
-
|
||||
static int
|
||||
valid_hostname(const char *s)
|
||||
{
|
||||
@@ -1771,8 +1751,8 @@ main(int ac, char **av)
|
||||
ssh_signal(SIGCHLD, main_sigchld_handler);
|
||||
|
||||
/* Log into the remote system. Never returns if the login fails. */
|
||||
- ssh_login(ssh, &sensitive_data, host, (struct sockaddr *)&hostaddr,
|
||||
- options.port, pw, timeout_ms, cinfo);
|
||||
+ ssh_login(ssh, &sensitive_data, host, &hostaddr, options.port,
|
||||
+ pw, timeout_ms, cinfo);
|
||||
|
||||
/* We no longer need the private host keys. Clear them now. */
|
||||
if (sensitive_data.nkeys != 0) {
|
||||
diff --git a/sshconnect.c b/sshconnect.c
|
||||
index bd077c75c..7823b6782 100644
|
||||
--- a/sshconnect.c
|
||||
+++ b/sshconnect.c
|
||||
@@ -83,6 +83,49 @@ extern char *__progname;
|
||||
static int show_other_keys(struct hostkeys *, struct sshkey *);
|
||||
static void warn_changed_key(struct sshkey *);
|
||||
|
||||
+void
|
||||
+ssh_conn_info_free(struct ssh_conn_info *cinfo)
|
||||
+{
|
||||
+ if (cinfo == NULL)
|
||||
+ return;
|
||||
+ free(cinfo->conn_hash_hex);
|
||||
+ free(cinfo->shorthost);
|
||||
+ free(cinfo->uidstr);
|
||||
+ free(cinfo->keyalias);
|
||||
+ free(cinfo->thishost);
|
||||
+ free(cinfo->host_arg);
|
||||
+ free(cinfo->portstr);
|
||||
+ free(cinfo->remhost);
|
||||
+ free(cinfo->remuser);
|
||||
+ free(cinfo->homedir);
|
||||
+ free(cinfo->locuser);
|
||||
+ free(cinfo->jmphost);
|
||||
+ freezero(cinfo, sizeof(*cinfo));
|
||||
+}
|
||||
+
|
||||
+struct ssh_conn_info *
|
||||
+ssh_conn_info_dup(const struct ssh_conn_info *cinfo)
|
||||
+{
|
||||
+ struct ssh_conn_info *ret;
|
||||
+
|
||||
+ if (cinfo == NULL)
|
||||
+ return NULL;
|
||||
+ ret = xcalloc(1, sizeof(*ret));
|
||||
+ ret->conn_hash_hex = xstrdup(cinfo->conn_hash_hex);
|
||||
+ ret->shorthost = xstrdup(cinfo->shorthost);
|
||||
+ ret->uidstr = xstrdup(cinfo->uidstr);
|
||||
+ ret->keyalias = xstrdup(cinfo->keyalias);
|
||||
+ ret->thishost = xstrdup(cinfo->thishost);
|
||||
+ ret->host_arg = xstrdup(cinfo->host_arg);
|
||||
+ ret->portstr = xstrdup(cinfo->portstr);
|
||||
+ ret->remhost = xstrdup(cinfo->remhost);
|
||||
+ ret->remuser = xstrdup(cinfo->remuser);
|
||||
+ ret->homedir = xstrdup(cinfo->homedir);
|
||||
+ ret->locuser = xstrdup(cinfo->locuser);
|
||||
+ ret->jmphost = xstrdup(cinfo->jmphost);
|
||||
+ return ret;
|
||||
+}
|
||||
+
|
||||
/* Expand a proxy command */
|
||||
static char *
|
||||
expand_proxy_command(const char *proxy_command, const char *user,
|
||||
@@ -1559,8 +1602,8 @@ out:
|
||||
*/
|
||||
void
|
||||
ssh_login(struct ssh *ssh, Sensitive *sensitive, const char *orighost,
|
||||
- struct sockaddr *hostaddr, u_short port, struct passwd *pw, int timeout_ms,
|
||||
- const struct ssh_conn_info *cinfo)
|
||||
+ struct sockaddr_storage *hostaddr, u_short port, struct passwd *pw,
|
||||
+ int timeout_ms, const struct ssh_conn_info *cinfo)
|
||||
{
|
||||
char *host;
|
||||
char *server_user, *local_user;
|
||||
diff --git a/sshconnect.h b/sshconnect.h
|
||||
index 79d35cc19..da2a73f5a 100644
|
||||
--- a/sshconnect.h
|
||||
+++ b/sshconnect.h
|
||||
@@ -71,7 +71,7 @@ int ssh_connect(struct ssh *, const char *, const char *,
|
||||
void ssh_kill_proxy_command(void);
|
||||
|
||||
void ssh_login(struct ssh *, Sensitive *, const char *,
|
||||
- struct sockaddr *, u_short, struct passwd *, int,
|
||||
+ struct sockaddr_storage *, u_short, struct passwd *, int,
|
||||
const struct ssh_conn_info *);
|
||||
|
||||
int verify_host_key(char *, struct sockaddr *, struct sshkey *,
|
||||
@@ -80,7 +80,7 @@ int verify_host_key(char *, struct sockaddr *, struct sshkey *,
|
||||
void get_hostfile_hostname_ipaddr(char *, struct sockaddr *, u_short,
|
||||
char **, char **);
|
||||
|
||||
-void ssh_kex2(struct ssh *ssh, char *, struct sockaddr *, u_short,
|
||||
+void ssh_kex2(struct ssh *ssh, char *, struct sockaddr_storage *, u_short,
|
||||
const struct ssh_conn_info *);
|
||||
|
||||
void ssh_userauth2(struct ssh *ssh, const char *, const char *,
|
||||
@@ -94,3 +94,6 @@ void maybe_add_key_to_agent(const char *, struct sshkey *,
|
||||
void load_hostkeys_command(struct hostkeys *, const char *,
|
||||
const char *, const struct ssh_conn_info *,
|
||||
const struct sshkey *, const char *);
|
||||
+
|
||||
+void ssh_conn_info_free(struct ssh_conn_info *);
|
||||
+struct ssh_conn_info *ssh_conn_info_dup(const struct ssh_conn_info *);
|
||||
diff --git a/sshconnect2.c b/sshconnect2.c
|
||||
index a296c9b8c..9efb3da8a 100644
|
||||
--- a/sshconnect2.c
|
||||
+++ b/sshconnect2.c
|
||||
@@ -89,7 +89,7 @@ extern Options options;
|
||||
*/
|
||||
|
||||
static char *xxx_host;
|
||||
-static struct sockaddr *xxx_hostaddr;
|
||||
+static struct sockaddr_storage xxx_hostaddr;
|
||||
static const struct ssh_conn_info *xxx_conn_info;
|
||||
static int key_type_allowed(struct sshkey *, const char *);
|
||||
|
||||
@@ -105,7 +105,7 @@ verify_host_key_callback(struct sshkey *hostkey, struct ssh *ssh)
|
||||
fatal("Server host key %s not in HostKeyAlgorithms",
|
||||
sshkey_ssh_name(hostkey));
|
||||
}
|
||||
- if (verify_host_key(xxx_host, xxx_hostaddr, hostkey,
|
||||
+ if (verify_host_key(xxx_host, (struct sockaddr *)&xxx_hostaddr, hostkey,
|
||||
xxx_conn_info) != 0)
|
||||
fatal("Host key verification failed.");
|
||||
return 0;
|
||||
@@ -222,16 +222,16 @@ order_hostkeyalgs(char *host, struct sockaddr *hostaddr, u_short port,
|
||||
}
|
||||
|
||||
void
|
||||
-ssh_kex2(struct ssh *ssh, char *host, struct sockaddr *hostaddr, u_short port,
|
||||
- const struct ssh_conn_info *cinfo)
|
||||
+ssh_kex2(struct ssh *ssh, char *host, struct sockaddr_storage *hostaddr,
|
||||
+ u_short port, const struct ssh_conn_info *cinfo)
|
||||
{
|
||||
char *myproposal[PROPOSAL_MAX];
|
||||
char *s, *all_key, *hkalgs = NULL;
|
||||
int r, use_known_hosts_order = 0;
|
||||
|
||||
- xxx_host = host;
|
||||
- xxx_hostaddr = hostaddr;
|
||||
- xxx_conn_info = cinfo;
|
||||
+ xxx_host = xstrdup(host);
|
||||
+ xxx_hostaddr = *hostaddr;
|
||||
+ xxx_conn_info = ssh_conn_info_dup(cinfo);
|
||||
|
||||
if (options.rekey_limit || options.rekey_interval)
|
||||
ssh_packet_set_rekey_limits(ssh, options.rekey_limit,
|
||||
@@ -257,8 +257,10 @@ ssh_kex2(struct ssh *ssh, char *host, struct sockaddr *hostaddr, u_short port,
|
||||
if ((s = kex_names_cat(options.kex_algorithms, "ext-info-c")) == NULL)
|
||||
fatal_f("kex_names_cat");
|
||||
|
||||
- if (use_known_hosts_order)
|
||||
- hkalgs = order_hostkeyalgs(host, hostaddr, port, cinfo);
|
||||
+ if (use_known_hosts_order) {
|
||||
+ hkalgs = order_hostkeyalgs(host, (struct sockaddr *)hostaddr,
|
||||
+ port, cinfo);
|
||||
+ }
|
||||
|
||||
kex_proposal_populate_entries(ssh, myproposal, s, options.ciphers,
|
||||
options.macs, compression_alg_list(options.compression),
|
||||
@@ -35,8 +35,15 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
|
||||
file://CVE-2025-61985.patch \
|
||||
file://CVE-2025-61984_CVE-2026-35386.patch \
|
||||
file://CVE-2026-35385.patch \
|
||||
file://CVE-2026-35387.patch \
|
||||
file://CVE-2026-35414-CVE-2026-35387.patch \
|
||||
file://CVE-2026-35388.patch \
|
||||
file://CVE-2026-59999.patch \
|
||||
file://CVE-2026-59997.patch \
|
||||
file://CVE-2026-59996.patch \
|
||||
file://CVE-2026-59995.patch \
|
||||
file://CVE-2026-60001.patch \
|
||||
file://CVE-2026-60002.patch \
|
||||
file://CVE-2026-60000.patch \
|
||||
"
|
||||
SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
|
||||
|
||||
@@ -49,6 +56,8 @@ Red Hat Enterprise Linux 7 and when running in a Kerberos environment"
|
||||
|
||||
CVE_STATUS[CVE-2008-3844] = "not-applicable-platform: Only applies to some distributed RHEL binaries."
|
||||
CVE_STATUS[CVE-2023-51767] = "upstream-wontfix: It was demonstrated on modified sshd and does not exist in upstream openssh https://bugzilla.mindrot.org/show_bug.cgi?id=3656#c1."
|
||||
CVE_STATUS[CVE-2026-3497] = "not-applicable-platform: Only affects GSSAPI Key Exchange patches used by some Linux distributions and does not exist in upstream openssh."
|
||||
CVE_STATUS[CVE-2026-59998] = "${@bb.utils.contains('PACKAGECONFIG', 'kerberos', 'unpatched', 'not-applicable-config: GSSAPI/Kerberos support is disabled in the default OpenSSH configuration', d)}"
|
||||
|
||||
PAM_SRC_URI = "file://sshd"
|
||||
|
||||
|
||||
150
meta/recipes-connectivity/socat/files/CVE-2026-56123.patch
Normal file
150
meta/recipes-connectivity/socat/files/CVE-2026-56123.patch
Normal file
@@ -0,0 +1,150 @@
|
||||
From d44cd1cc4fbb70a9ae9e71890024ae8367fcb912 Mon Sep 17 00:00:00 2001
|
||||
From: Gerhard Rieger <gerhard@dest-unreach.org>
|
||||
Date: Thu, 25 Jun 2026 14:55:59 +0200
|
||||
Subject: [PATCH] Version 1.8.1.2 - fixed SOCKS5 client buffer overflow
|
||||
(CVE-2026-56123)
|
||||
|
||||
CVE: CVE-2026-56123
|
||||
Upstream-Status: Backport [repo.or.cz/socat.git/commitdiff/d44cd1cc4fbb70a9ae9e71890024ae8367fcb912]
|
||||
Signed-off-by: Peter Marko <peter.marko@siemens.com>
|
||||
---
|
||||
CHANGES | 13 ++++++++++
|
||||
test.sh | 73 ++++++++++++++++++++++++++++++++++++++++++++++++++++
|
||||
xio-socks5.h | 4 +--
|
||||
3 files changed, 88 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/CHANGES b/CHANGES
|
||||
index ba82024..3c2f230 100644
|
||||
--- a/CHANGES
|
||||
+++ b/CHANGES
|
||||
@@ -1,4 +1,17 @@
|
||||
|
||||
+Security:
|
||||
+ Socat security advisory 10
|
||||
+ CVE-2026-56123
|
||||
+ There was a possible heap overflow in the socks5 client code. It could
|
||||
+ be triggered by connecting to a malicious socks5 server that expected
|
||||
+ this connection and had knowledge about details of the client binary
|
||||
+ code.
|
||||
+ Only builds with C signed char (vs.unsigned char) are affected.
|
||||
+ Thanks to Tristan Madani for finding and reporting this issue, and for
|
||||
+ conveying the process.
|
||||
+ Test: SOCKS5_OVERFL
|
||||
+
|
||||
+
|
||||
####################### V 1.8.0.0
|
||||
|
||||
Security:
|
||||
diff --git a/test.sh b/test.sh
|
||||
index 53bbb2a..467ac57 100755
|
||||
--- a/test.sh
|
||||
+++ b/test.sh
|
||||
@@ -601,6 +601,9 @@ rm -rf "$TD" || (echo "cannot rm $TD" >&2; exit 1)
|
||||
mkdir -p "$TD"
|
||||
#trap "rm -r $TD" 0 3
|
||||
|
||||
+BINDIR=$td/bin
|
||||
+mkdir -p $BINDIR
|
||||
+
|
||||
echo "Using temp directory $TD"
|
||||
|
||||
case "$TESTS" in
|
||||
@@ -19217,6 +19220,76 @@ fi # NUMCOND
|
||||
esac
|
||||
N=$((N+1))
|
||||
|
||||
+# Above tests introduced with 1.8.1.0 (none with 1.8.1.1)
|
||||
+#==============================================================================
|
||||
+# Below tests introduced with 1.8.1.2
|
||||
+
|
||||
+
|
||||
+# Test socks5 client buffer overflow (CVE-2026-56123)
|
||||
+NAME=SOCKS5_OVERFL
|
||||
+case "$TESTS" in
|
||||
+*%$N%*|*%functions%*|*%bugs%*|*%security%*|*%socks5%*|*%socks%*|*%%*|*%%*|*%socket%*|*%$NAME%*)
|
||||
+#*%internet%*|*%root%*|*%listen%*|*%fork%*|*%ip4%*|*%tcp4%*|*%bug%*|...
|
||||
+TEST="$NAME: socks5 client buffer overflow"
|
||||
+# Start a listener that emulates a malicious socks5 server, using a temporary
|
||||
+# shell script;
|
||||
+# connect using Socat with socks5 client;
|
||||
+# when is terminates with rc=0 the test succeeded (not vulnerable)
|
||||
+if ! eval $NUMCOND; then :
|
||||
+# Check if this test can be performed meaningfully
|
||||
+elif ! cond=$(checkconds \
|
||||
+ "" \
|
||||
+ "" \
|
||||
+ "" \
|
||||
+ "IP4 TCP LISTEN SHELL GOPEN SOCKS5" \
|
||||
+ "TCP4-LISTEN SHELL GOPEN SOCKS5" \
|
||||
+ "socksport" \
|
||||
+ "tcp4" ); then
|
||||
+ $PRINTF "test $F_n $TEST... ${YELLOW}$cond${NORMAL}\n" $N
|
||||
+ cant
|
||||
+else
|
||||
+ mkdir -p "$BINDIR"
|
||||
+ tf="$td/test$N.stdout"
|
||||
+ te="$td/test$N.stderr"
|
||||
+ tdiff="$td/test$N.diff"
|
||||
+ tsh="$BINDIR/test$N.sh"
|
||||
+ cat >"$tsh" <<__EOF__
|
||||
+$ECHO -n "\\x05\\x00"
|
||||
+relsleep 1
|
||||
+$ECHO -n "\\x05\\x00\\x00\\x03\\xfdAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"
|
||||
+__EOF__
|
||||
+ chmod a+x "$tsh"
|
||||
+ newport tcp4 # -> PORT
|
||||
+ CMD0="$TRACE $SOCAT $opts TCP4-LISTEN:$PORT SHELL:$tsh"
|
||||
+ CMD1="$TRACE $SOCAT $opts /dev/null SOCKS5:$LOCALHOST4:17.34.51.68:85,socksport=$PORT"
|
||||
+ printf "test $F_n $TEST... " $N
|
||||
+ $CMD0 >/dev/null 2>"${te}0" &
|
||||
+ pid0=$!
|
||||
+ waittcp4port $PORT 1
|
||||
+ $CMD1 >"${tf}1" 2>"${te}1"
|
||||
+ rc1=$?
|
||||
+ kill $pid0 2>/dev/null; wait
|
||||
+ if [ "$rc1" -ne 0 ]; then
|
||||
+ $PRINTF "$FAILED (rc1=$rc1)\n"
|
||||
+ echo "$CMD0 &"
|
||||
+ cat "${te}0" >&2
|
||||
+ echo "$CMD1"
|
||||
+ cat "${te}1" >&2
|
||||
+ failed
|
||||
+ else
|
||||
+ $PRINTF "$OK\n"
|
||||
+ if [ "$VERBOSE" ]; then echo "$CMD0 &"; fi
|
||||
+ if [ "$DEBUG" ]; then cat "${te}0" >&2; fi
|
||||
+ if [ "$VERBOSE" ]; then echo "$CMD1"; fi
|
||||
+ if [ "$DEBUG" ]; then cat "${te}1" >&2; fi
|
||||
+ ok
|
||||
+ fi
|
||||
+fi # NUMCOND
|
||||
+ ;;
|
||||
+esac
|
||||
+N=$((N+1))
|
||||
+
|
||||
+
|
||||
# end of common tests
|
||||
|
||||
##################################################################################
|
||||
diff --git a/xio-socks5.h b/xio-socks5.h
|
||||
index 4dab76b..d4712d2 100644
|
||||
--- a/xio-socks5.h
|
||||
+++ b/xio-socks5.h
|
||||
@@ -23,7 +23,7 @@ struct socks5_request {
|
||||
uint8_t command;
|
||||
uint8_t reserved;
|
||||
uint8_t address_type;
|
||||
- char dstdata[];
|
||||
+ unsigned char dstdata[];
|
||||
};
|
||||
|
||||
struct socks5_reply {
|
||||
@@ -31,7 +31,7 @@ struct socks5_reply {
|
||||
uint8_t reply;
|
||||
uint8_t reserved;
|
||||
uint8_t address_type;
|
||||
- char dstdata[];
|
||||
+ unsigned char dstdata[];
|
||||
};
|
||||
|
||||
extern const struct addrdesc xioaddr_socks5_connect;
|
||||
@@ -12,6 +12,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263 \
|
||||
SRC_URI = "http://www.dest-unreach.org/socat/download/socat-${PV}.tar.bz2 \
|
||||
file://0001-fix-compile-procan.c-failed.patch \
|
||||
file://CVE-2024-54661.patch \
|
||||
file://CVE-2026-56123.patch \
|
||||
"
|
||||
|
||||
SRC_URI[sha256sum] = "e1de683dd22ee0e3a6c6bbff269abe18ab0c9d7eb650204f125155b9005faca7"
|
||||
|
||||
155
meta/recipes-core/busybox/busybox/CVE-2026-38754.patch
Normal file
155
meta/recipes-core/busybox/busybox/CVE-2026-38754.patch
Normal file
@@ -0,0 +1,155 @@
|
||||
From a448b6d5b21e5b21249391389b6f0551d9bea136 Mon Sep 17 00:00:00 2001
|
||||
From: Sanghyun Park <sanghyun.park.cnu@gmail.com>
|
||||
Date: Thu, 18 Jun 2026 17:04:20 +0900
|
||||
Subject: [PATCH] ash: fix out-of-bounds read in ifsbreakup()
|
||||
|
||||
ifsfree() does not only release allocated ifsregion nodes; it also clears
|
||||
the global IFS region state used by ifsbreakup(). If argstr() raises an
|
||||
error while expanding an argument, ash longjmps out of expandarg() before
|
||||
that cleanup runs, leaving stale IFS split offsets behind.
|
||||
|
||||
A later expansion can reuse the stack for a shorter string. ifsbreakup()
|
||||
then sees the stale IFS state, trusts the old offsets, and can walk past
|
||||
the current stack block before dereferencing p.
|
||||
|
||||
Follow dash's root-cause fix: when an expansion-related handler catches
|
||||
EXERROR and continues, restore the handler and call ifsfree(). Apply
|
||||
the cleanup to redirectsafe(), expandstr(), and evaltree().
|
||||
|
||||
Upstream commit:
|
||||
|
||||
Date: Mon Dec 5 23:02:01 2022 +0800
|
||||
expand: Add ifsfree to expand to fix a logic error that causes a buffer over-read
|
||||
|
||||
On Mon, Jun 20, 2022 at 02:27:10PM -0400, Alex Gorinson wrote:
|
||||
> Due to a logic error in the ifsbreakup function in expand.c if a
|
||||
> heredoc and normal command is run one after the other by means of a
|
||||
> semi-colon, when the second command drops into ifsbreakup the command
|
||||
> will be evaluated with the ifslastp/ifsfirst struct that was set when
|
||||
> the here doc was evaluated. This results in a buffer over-read that
|
||||
> can leak the program's heap, stack, and arena addresses which can be
|
||||
> used to beat ASLR.
|
||||
>
|
||||
> Steps to Reproduce:
|
||||
> First bug:
|
||||
> cmd args: ~/exampleDir/example> dash
|
||||
> $ M='AAAAAAAAAAAAAAAAA' <note: 17 A's>
|
||||
> $ q00(){
|
||||
> $ <<000;echo
|
||||
> $ ${D?$M$M$M$M$M$M} <note: 6 $M's>
|
||||
> $ 000
|
||||
> $ }
|
||||
> $ q00 <note: After the q00 is typed in, the leak
|
||||
> should be echo'd out; this works with ash, busybox ash, and dash and
|
||||
> with all option args.>
|
||||
>
|
||||
> Patch:
|
||||
> Adding the following to expand.c will fix both bugs in one go.
|
||||
> (Thank you to Harald van Dijk and Michael Greenberg for doing the
|
||||
> heavy lifting for this patch!)
|
||||
> ==========================
|
||||
> --- a/src/expand.c
|
||||
> +++ b/src/expand.c
|
||||
> @@ -859,6 +859,7 @@
|
||||
> if (discard)
|
||||
> return -1;
|
||||
>
|
||||
> +ifsfree();
|
||||
> sh_error("Bad substitution");
|
||||
> }
|
||||
>
|
||||
> @@ -1739,6 +1740,7 @@
|
||||
> } else
|
||||
> msg = umsg;
|
||||
> }
|
||||
> +ifsfree();
|
||||
> sh_error("%.*s: %s%s", end - var - 1, var, msg, tail);
|
||||
> }
|
||||
> ==========================
|
||||
|
||||
Thanks for the report!
|
||||
|
||||
I think it's better to add the ifsfree() call to the exception
|
||||
handling path as other sh_error calls may trigger this too.
|
||||
|
||||
function old new delta
|
||||
restore_handler_expandarg - 33 +33
|
||||
evaltree 725 711 -14
|
||||
static.redirectsafe 141 124 -17
|
||||
expandstr 262 242 -20
|
||||
------------------------------------------------------------------------------
|
||||
(add/remove: 1/0 grow/shrink: 0/3 up/down: 36/-45) Total: -18 bytes
|
||||
|
||||
Signed-off-by: Sanghyun Park <sanghyun.park.cnu@gmail.com>
|
||||
Signed-off-by: Denys Vlasenko <vda.linux@googlemail.com>
|
||||
|
||||
CVE: CVE-2026-38754
|
||||
Upstream-Status: Backport [https://github.com/vda-linux/busybox_mirror/commit/a448b6d5b21e5b21249391389b6f0551d9bea136]
|
||||
Signed-off-by: Peter Marko <peter.marko@siemens.com>
|
||||
---
|
||||
shell/ash.c | 24 +++++++++++++++---------
|
||||
1 file changed, 15 insertions(+), 9 deletions(-)
|
||||
|
||||
diff --git a/shell/ash.c b/shell/ash.c
|
||||
index fb887f31b..b8ff67b16 100644
|
||||
--- a/shell/ash.c
|
||||
+++ b/shell/ash.c
|
||||
@@ -5480,6 +5480,7 @@ stoppedjobs(void)
|
||||
*/
|
||||
/* openhere needs this forward reference */
|
||||
static void expandhere(union node *arg);
|
||||
+static void ifsfree(void);
|
||||
static int
|
||||
openhere(union node *redir)
|
||||
{
|
||||
@@ -5909,6 +5910,17 @@ redirect(union node *redir, int flags)
|
||||
// preverrout_fd = copied_fd2;
|
||||
}
|
||||
|
||||
+static void
|
||||
+restore_handler_expandarg(struct jmploc *savehandler, int err)
|
||||
+{
|
||||
+ exception_handler = savehandler;
|
||||
+ if (err) {
|
||||
+ if (exception_type != EXERROR)
|
||||
+ longjmp(exception_handler->loc, 1);
|
||||
+ ifsfree();
|
||||
+ }
|
||||
+}
|
||||
+
|
||||
static int
|
||||
redirectsafe(union node *redir, int flags)
|
||||
{
|
||||
@@ -5924,9 +5936,7 @@ redirectsafe(union node *redir, int flags)
|
||||
exception_handler = &jmploc;
|
||||
redirect(redir, flags);
|
||||
}
|
||||
- exception_handler = savehandler;
|
||||
- if (err && exception_type != EXERROR)
|
||||
- longjmp(exception_handler->loc, 1);
|
||||
+ restore_handler_expandarg(savehandler, err);
|
||||
RESTORE_INT(saveint);
|
||||
return err;
|
||||
}
|
||||
@@ -9435,9 +9445,7 @@ evaltree(union node *n, int flags)
|
||||
trap_depth--;
|
||||
in_trap_ERR = 0;
|
||||
|
||||
- exception_handler = savehandler;
|
||||
- if (err && exception_type != EXERROR)
|
||||
- longjmp(exception_handler->loc, 1);
|
||||
+ restore_handler_expandarg(savehandler, err);
|
||||
|
||||
exitstatus = savestatus;
|
||||
}
|
||||
@@ -13444,9 +13452,7 @@ expandstr(const char *ps, int syntax_type)
|
||||
result = stackblock();
|
||||
|
||||
out:
|
||||
- exception_handler = savehandler;
|
||||
- if (err && exception_type != EXERROR)
|
||||
- longjmp(exception_handler->loc, 1);
|
||||
+ restore_handler_expandarg(savehandler, err);
|
||||
|
||||
doprompt = saveprompt;
|
||||
/* Try: PS1='`xxx(`' */
|
||||
@@ -66,6 +66,7 @@ SRC_URI = "https://busybox.net/downloads/busybox-${PV}.tar.bz2;name=tarball \
|
||||
file://CVE-2026-26157-CVE-2026-26158-02.patch \
|
||||
file://CVE-2026-29004-01.patch \
|
||||
file://CVE-2026-29004-02.patch \
|
||||
file://CVE-2026-38754.patch \
|
||||
"
|
||||
SRC_URI:append:libc-musl = " file://musl.cfg "
|
||||
# TODO http://lists.busybox.net/pipermail/busybox/2023-January/090078.html
|
||||
|
||||
50
meta/recipes-core/expat/expat/CVE-2026-41080-01.patch
Normal file
50
meta/recipes-core/expat/expat/CVE-2026-41080-01.patch
Normal file
@@ -0,0 +1,50 @@
|
||||
From fe04a7f0ff8afe57ba33d919f368b1ba23bcda92 Mon Sep 17 00:00:00 2001
|
||||
From: Sebastian Pipping <sebastian@pipping.org>
|
||||
Date: Sun, 30 Mar 2025 19:26:55 +0200
|
||||
Subject: [PATCH 1/3] lib/xmlparse.c: Address clang-tidy warning
|
||||
misc-no-recursion
|
||||
|
||||
CVE: CVE-2026-41080
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/fe04a7f0ff8afe57ba33d919f368b1ba23bcda92]
|
||||
Signed-off-by: Peter Marko <peter.marko@siemens.com>
|
||||
---
|
||||
lib/xmlparse.c | 17 ++++++++++-------
|
||||
1 file changed, 10 insertions(+), 7 deletions(-)
|
||||
|
||||
diff --git a/lib/xmlparse.c b/lib/xmlparse.c
|
||||
index 9bc67f38..cb25c37b 100644
|
||||
--- a/lib/xmlparse.c
|
||||
+++ b/lib/xmlparse.c
|
||||
@@ -1243,9 +1243,10 @@ generate_hash_secret_salt(XML_Parser parser) {
|
||||
|
||||
static unsigned long
|
||||
get_hash_secret_salt(XML_Parser parser) {
|
||||
- if (parser->m_parentParser != NULL)
|
||||
- return get_hash_secret_salt(parser->m_parentParser);
|
||||
- return parser->m_hash_secret_salt;
|
||||
+ const XML_Parser rootParser = getRootParserOf(parser, NULL);
|
||||
+ assert(! rootParser->m_parentParser);
|
||||
+
|
||||
+ return rootParser->m_hash_secret_salt;
|
||||
}
|
||||
|
||||
static enum XML_Error
|
||||
@@ -2321,12 +2322,14 @@ int XMLCALL
|
||||
XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt) {
|
||||
if (parser == NULL)
|
||||
return 0;
|
||||
- if (parser->m_parentParser)
|
||||
- return XML_SetHashSalt(parser->m_parentParser, hash_salt);
|
||||
+
|
||||
+ const XML_Parser rootParser = getRootParserOf(parser, NULL);
|
||||
+ assert(! rootParser->m_parentParser);
|
||||
+
|
||||
/* block after XML_Parse()/XML_ParseBuffer() has been called */
|
||||
- if (parserBusy(parser))
|
||||
+ if (parserBusy(rootParser))
|
||||
return 0;
|
||||
- parser->m_hash_secret_salt = hash_salt;
|
||||
+ rootParser->m_hash_secret_salt = hash_salt;
|
||||
return 1;
|
||||
}
|
||||
|
||||
29
meta/recipes-core/expat/expat/CVE-2026-41080-02.patch
Normal file
29
meta/recipes-core/expat/expat/CVE-2026-41080-02.patch
Normal file
@@ -0,0 +1,29 @@
|
||||
From 7fb2c7a454edc9e2880073a27f899c31d9b078ce Mon Sep 17 00:00:00 2001
|
||||
From: Atrem Borovik <polzovatellllk@gmail.com>
|
||||
Date: Sat, 20 Dec 2025 13:22:16 +0300
|
||||
Subject: [PATCH 2/3] WASI: remove getpid
|
||||
|
||||
CVE: CVE-2026-41080
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/7fb2c7a454edc9e2880073a27f899c31d9b078ce]
|
||||
Signed-off-by: Peter Marko <peter.marko@siemens.com>
|
||||
---
|
||||
lib/xmlparse.c | 5 ++++-
|
||||
1 file changed, 4 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/lib/xmlparse.c b/lib/xmlparse.c
|
||||
index cb25c37b..1bafb948 100644
|
||||
--- a/lib/xmlparse.c
|
||||
+++ b/lib/xmlparse.c
|
||||
@@ -1228,8 +1228,11 @@ generate_hash_secret_salt(XML_Parser parser) {
|
||||
# endif /* ! defined(_WIN32) && defined(XML_DEV_URANDOM) */
|
||||
/* .. and self-made low quality for backup: */
|
||||
|
||||
+ entropy = gather_time_entropy();
|
||||
+# if ! defined(__wasi__)
|
||||
/* Process ID is 0 bits entropy if attacker has local access */
|
||||
- entropy = gather_time_entropy() ^ getpid();
|
||||
+ entropy ^= getpid();
|
||||
+# endif
|
||||
|
||||
/* Factors are 2^31-1 and 2^61-1 (Mersenne primes M31 and M61) */
|
||||
if (sizeof(unsigned long) == 4) {
|
||||
467
meta/recipes-core/expat/expat/CVE-2026-41080-03.patch
Normal file
467
meta/recipes-core/expat/expat/CVE-2026-41080-03.patch
Normal file
@@ -0,0 +1,467 @@
|
||||
From b77ab600e1893fdcfc3868d0a46efcc87c87943d Mon Sep 17 00:00:00 2001
|
||||
From: Sebastian Pipping <sebastian@pipping.org>
|
||||
Date: Wed, 8 Apr 2026 15:41:54 +0200
|
||||
Subject: [PATCH 3/3] [CVE-2026-41080] Improve protection against hash flooding
|
||||
(fixes #47)
|
||||
|
||||
Fixes #47
|
||||
|
||||
CVE: CVE-2026-41080
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1183]
|
||||
Signed-off-by: Peter Marko <peter.marko@siemens.com>
|
||||
---
|
||||
Changes | 16 ++++++
|
||||
doc/reference.html | 51 ++++++++++++++--
|
||||
lib/expat.h | 12 ++++
|
||||
lib/internal.h | 2 +
|
||||
lib/xmlparse.c | 118 ++++++++++++++++++++++++++------------
|
||||
tests/basic_tests.c | 25 ++++++++
|
||||
6 files changed, 181 insertions(+), 43 deletions(-)
|
||||
|
||||
diff --git a/Changes b/Changes
|
||||
index 4265d608..1d87d6a0 100644
|
||||
--- a/Changes
|
||||
+++ b/Changes
|
||||
@@ -30,6 +30,22 @@
|
||||
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
||||
|
||||
Patches:
|
||||
+ Security fixes:
|
||||
+ #47 #1183 CVE-2026-41080 -- The existing hash flooding protection
|
||||
+ (based on SipHash) only used 4 to 8 bytes of entropy for
|
||||
+ a salt, when 16 bytes of salt are supported by the
|
||||
+ implementation of SipHash used by Expat. Now full 16 bytes
|
||||
+ of entropy are used to improve protection against hash
|
||||
+ flooding attacks.
|
||||
+ Existing API function XML_SetHashSalt is now deprecated
|
||||
+ because of its limitations, and its use should be
|
||||
+ considered a vulnerability. Please either use the new API
|
||||
+ function XML_SetHashSalt16Bytes (with known-high-quality
|
||||
+ entropy input only!) instead, or leave the derivation of
|
||||
+ a 16-bytes hash salt from high quality entropy to Expat's
|
||||
+ internal machinery (by *not* calling either of the two
|
||||
+ XML_SetHashSalt* functions).
|
||||
+
|
||||
Security fixes:
|
||||
#1018 #1034 CVE-2025-59375 -- Disallow use of disproportional amounts of
|
||||
dynamic memory from within an Expat parser (e.g. previously
|
||||
diff --git a/doc/reference.html b/doc/reference.html
|
||||
index 8f14b011..7f374f84 100644
|
||||
--- a/doc/reference.html
|
||||
+++ b/doc/reference.html
|
||||
@@ -174,7 +174,8 @@ interface.</p>
|
||||
<li><a href="#XML_GetAttributeInfo">XML_GetAttributeInfo</a></li>
|
||||
<li><a href="#XML_SetEncoding">XML_SetEncoding</a></li>
|
||||
<li><a href="#XML_SetParamEntityParsing">XML_SetParamEntityParsing</a></li>
|
||||
- <li><a href="#XML_SetHashSalt">XML_SetHashSalt</a></li>
|
||||
+ <li><a href="#XML_SetHashSalt">XML_SetHashSalt</a> (deprecated)</li>
|
||||
+ <li><a href="#XML_SetHashSalt16Bytes">XML_SetHashSalt16Bytes</a></li>
|
||||
<li><a href="#XML_UseForeignDTD">XML_UseForeignDTD</a></li>
|
||||
<li><a href="#XML_SetReturnNSTriplet">XML_SetReturnNSTriplet</a></li>
|
||||
<li><a href="#XML_DefaultCurrent">XML_DefaultCurrent</a></li>
|
||||
@@ -2553,10 +2554,10 @@ The choices for <code>code</code> are:
|
||||
no effect and will always return 0.
|
||||
</div>
|
||||
|
||||
-<h4 id="XML_SetHashSalt">XML_SetHashSalt</h4>
|
||||
+<h4 id="XML_SetHashSalt">XML_SetHashSalt (deprecated)</h4>
|
||||
<pre class="fcndec">
|
||||
int XMLCALL
|
||||
-XML_SetHashSalt(XML_Parser p,
|
||||
+XML_SetHashSalt(XML_Parser parser,
|
||||
unsigned long hash_salt);
|
||||
</pre>
|
||||
<div class="fcndef">
|
||||
@@ -2564,15 +2565,55 @@ Sets the hash salt to use for internal hash calculations.
|
||||
Helps in preventing DoS attacks based on predicting hash
|
||||
function behavior. In order to have an effect this must be called
|
||||
before parsing has started. Returns 1 if successful, 0 when called
|
||||
-after <code>XML_Parse</code> or <code>XML_ParseBuffer</code>.
|
||||
+after <code>XML_Parse</code> or <code>XML_ParseBuffer</code> or when
|
||||
+ <code>parser</code> is <code>NULL</code>.
|
||||
+ <p>
|
||||
+ <b>Note:</b> Function <code>XML_SetHashSalt</code> is
|
||||
+ <strong>deprecated</strong>. Please use function <code><a href=
|
||||
+ "#XML_SetHashSalt16Bytes">XML_SetHashSalt16Bytes</a></code> instead for better
|
||||
+ security. <code>XML_SetHashSalt</code> only provides 4 to 8 bytes of entropy
|
||||
+ (depending on the size of type <code>unsigned long</code>) while the SipHash
|
||||
+ implementation used by Expat can leverage up to 16 bytes of entropy — at least
|
||||
+ twice as much. Function <code><a href=
|
||||
+ "#XML_SetHashSalt16Bytes">XML_SetHashSalt16Bytes</a></code> of Expat >=2.7.6
|
||||
+ (and where backported) matches the amount of entropy supported by SipHash.
|
||||
+ </p>.
|
||||
<p><b>Note:</b> This call is optional, as the parser will auto-generate
|
||||
-a new random salt value if no value has been set at the start of parsing.</p>
|
||||
+a new random salt value internally if no value has been set by the start of parsing.</p>
|
||||
<p><b>Note:</b> One should not call <code>XML_SetHashSalt</code> with a
|
||||
hash salt value of 0, as this value is used as sentinel value to indicate
|
||||
that <code>XML_SetHashSalt</code> has <b>not</b> been called. Consequently
|
||||
such a call will have no effect, even if it returns 1.</p>
|
||||
</div>
|
||||
|
||||
+ <h4 id="XML_SetHashSalt16Bytes">
|
||||
+ XML_SetHashSalt16Bytes
|
||||
+ </h4>
|
||||
+
|
||||
+ <pre class="fcndec">
|
||||
+/* Added in Expat 2.7.6. */
|
||||
+XML_Bool XMLCALL
|
||||
+XML_SetHashSalt16Bytes(XML_Parser parser,
|
||||
+ const uint8_t entropy[16]);
|
||||
+</pre>
|
||||
+ <div class="fcndef">
|
||||
+ Sets the hash salt to use for internal hash calculations. Helps in preventing DoS
|
||||
+ attacks based on predicting hash function behavior. In order to have an effect
|
||||
+ this must be called before parsing has started. Returns <code>XML_TRUE</code> if
|
||||
+ successful, <code>XML_FALSE</code> when called after <code>XML_Parse</code> or
|
||||
+ <code>XML_ParseBuffer</code> or when <code>parser</code> is <code>NULL</code>.
|
||||
+ <p>
|
||||
+ <b>Note:</b> Setting a salt that is <em>not</em> from a source of high quality
|
||||
+ entropy (like <code>getentropy(3)</code>) will make the parser vulnerable to
|
||||
+ hash flooding attacks.
|
||||
+ </p>
|
||||
+
|
||||
+ <p>
|
||||
+ <b>Note:</b> This call is optional, as the parser will auto-generate a new
|
||||
+ random salt value internally if no value has been set by the start of parsing.
|
||||
+ </p>
|
||||
+ </div>
|
||||
+
|
||||
<h4 id="XML_UseForeignDTD">XML_UseForeignDTD</h4>
|
||||
<pre class="fcndec">
|
||||
enum XML_Error XMLCALL
|
||||
diff --git a/lib/expat.h b/lib/expat.h
|
||||
index df207e9e..b356e002 100644
|
||||
--- a/lib/expat.h
|
||||
+++ b/lib/expat.h
|
||||
@@ -44,6 +44,7 @@
|
||||
#ifndef Expat_INCLUDED
|
||||
#define Expat_INCLUDED 1
|
||||
|
||||
+# include <stdint.h> // for uint8_t
|
||||
#include <stdlib.h>
|
||||
#include "expat_external.h"
|
||||
|
||||
@@ -916,10 +917,21 @@ XML_SetParamEntityParsing(XML_Parser parser,
|
||||
function behavior. This must be called before parsing is started.
|
||||
Returns 1 if successful, 0 when called after parsing has started.
|
||||
Note: If parser == NULL, the function will do nothing and return 0.
|
||||
+ DEPRECATED since Expat 2.7.6.
|
||||
*/
|
||||
XMLPARSEAPI(int)
|
||||
XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt);
|
||||
|
||||
+/* Sets the hash salt to use for internal hash calculations.
|
||||
+ Helps in preventing DoS attacks based on predicting hash function behavior.
|
||||
+ This must be called before parsing is started.
|
||||
+ Returns XML_TRUE if successful, XML_FALSE when called after parsing has
|
||||
+ started or when parser is NULL.
|
||||
+ Added in Expat 2.7.6.
|
||||
+*/
|
||||
+XMLPARSEAPI(XML_Bool)
|
||||
+XML_SetHashSalt16Bytes(XML_Parser parser, const uint8_t entropy[16]);
|
||||
+
|
||||
/* If XML_Parse or XML_ParseBuffer have returned XML_STATUS_ERROR, then
|
||||
XML_GetErrorCode returns information about the error.
|
||||
*/
|
||||
diff --git a/lib/internal.h b/lib/internal.h
|
||||
index 32faaa05..617d6454 100644
|
||||
--- a/lib/internal.h
|
||||
+++ b/lib/internal.h
|
||||
@@ -113,6 +113,7 @@
|
||||
#if defined(_WIN32) \
|
||||
&& (! defined(__USE_MINGW_ANSI_STDIO) \
|
||||
|| (1 - __USE_MINGW_ANSI_STDIO - 1 == 0))
|
||||
+# define EXPAT_FMT_LLX(midpart) "%" midpart "I64x"
|
||||
# define EXPAT_FMT_ULL(midpart) "%" midpart "I64u"
|
||||
# if defined(_WIN64) // Note: modifiers "td" and "zu" do not work for MinGW
|
||||
# define EXPAT_FMT_PTRDIFF_T(midpart) "%" midpart "I64d"
|
||||
@@ -122,6 +123,7 @@
|
||||
# define EXPAT_FMT_SIZE_T(midpart) "%" midpart "u"
|
||||
# endif
|
||||
#else
|
||||
+# define EXPAT_FMT_LLX(midpart) "%" midpart "llx"
|
||||
# define EXPAT_FMT_ULL(midpart) "%" midpart "llu"
|
||||
# if ! defined(ULONG_MAX)
|
||||
# error Compiler did not define ULONG_MAX for us
|
||||
diff --git a/lib/xmlparse.c b/lib/xmlparse.c
|
||||
index 1bafb948..75a7e5d0 100644
|
||||
--- a/lib/xmlparse.c
|
||||
+++ b/lib/xmlparse.c
|
||||
@@ -604,7 +604,7 @@ static ELEMENT_TYPE *getElementType(XML_Parser parser, const ENCODING *enc,
|
||||
|
||||
static XML_Char *copyString(const XML_Char *s, XML_Parser parser);
|
||||
|
||||
-static unsigned long generate_hash_secret_salt(XML_Parser parser);
|
||||
+static struct sipkey generate_hash_secret_salt(void);
|
||||
static XML_Bool startParsing(XML_Parser parser);
|
||||
|
||||
static XML_Parser parserCreate(const XML_Char *encodingName,
|
||||
@@ -777,7 +777,8 @@ struct XML_ParserStruct {
|
||||
XML_Bool m_useForeignDTD;
|
||||
enum XML_ParamEntityParsing m_paramEntityParsing;
|
||||
#endif
|
||||
- unsigned long m_hash_secret_salt;
|
||||
+ struct sipkey m_hash_secret_salt_128;
|
||||
+ XML_Bool m_hash_secret_salt_set;
|
||||
#if XML_GE == 1
|
||||
ACCOUNTING m_accounting;
|
||||
MALLOC_TRACKER m_alloc_tracker;
|
||||
@@ -1189,69 +1190,65 @@ gather_time_entropy(void) {
|
||||
|
||||
#endif /* ! defined(HAVE_ARC4RANDOM_BUF) && ! defined(HAVE_ARC4RANDOM) */
|
||||
|
||||
-static unsigned long
|
||||
-ENTROPY_DEBUG(const char *label, unsigned long entropy) {
|
||||
+static struct sipkey
|
||||
+ENTROPY_DEBUG(const char *label, struct sipkey entropy_128) {
|
||||
if (getDebugLevel("EXPAT_ENTROPY_DEBUG", 0) >= 1u) {
|
||||
- fprintf(stderr, "expat: Entropy: %s --> 0x%0*lx (%lu bytes)\n", label,
|
||||
- (int)sizeof(entropy) * 2, entropy, (unsigned long)sizeof(entropy));
|
||||
+ fprintf(stderr,
|
||||
+ "expat: Entropy: %s --> [0x" EXPAT_FMT_LLX(
|
||||
+ "016") ", 0x" EXPAT_FMT_LLX("016") "] (16 bytes)\n",
|
||||
+ label, (unsigned long long)entropy_128.k[0],
|
||||
+ (unsigned long long)entropy_128.k[1]);
|
||||
}
|
||||
- return entropy;
|
||||
+ return entropy_128;
|
||||
}
|
||||
|
||||
-static unsigned long
|
||||
-generate_hash_secret_salt(XML_Parser parser) {
|
||||
- unsigned long entropy;
|
||||
- (void)parser;
|
||||
+static struct sipkey
|
||||
+generate_hash_secret_salt(void) {
|
||||
+ struct sipkey entropy;
|
||||
|
||||
/* "Failproof" high quality providers: */
|
||||
#if defined(HAVE_ARC4RANDOM_BUF)
|
||||
arc4random_buf(&entropy, sizeof(entropy));
|
||||
return ENTROPY_DEBUG("arc4random_buf", entropy);
|
||||
#elif defined(HAVE_ARC4RANDOM)
|
||||
- writeRandomBytes_arc4random((void *)&entropy, sizeof(entropy));
|
||||
+ writeRandomBytes_arc4random(&entropy, sizeof(entropy));
|
||||
return ENTROPY_DEBUG("arc4random", entropy);
|
||||
#else
|
||||
/* Try high quality providers first .. */
|
||||
# ifdef _WIN32
|
||||
- if (writeRandomBytes_rand_s((void *)&entropy, sizeof(entropy))) {
|
||||
+ if (writeRandomBytes_rand_s(&entropy, sizeof(entropy))) {
|
||||
return ENTROPY_DEBUG("rand_s", entropy);
|
||||
}
|
||||
# elif defined(HAVE_GETRANDOM) || defined(HAVE_SYSCALL_GETRANDOM)
|
||||
- if (writeRandomBytes_getrandom_nonblock((void *)&entropy, sizeof(entropy))) {
|
||||
+ if (writeRandomBytes_getrandom_nonblock(&entropy, sizeof(entropy))) {
|
||||
return ENTROPY_DEBUG("getrandom", entropy);
|
||||
}
|
||||
# endif
|
||||
# if ! defined(_WIN32) && defined(XML_DEV_URANDOM)
|
||||
- if (writeRandomBytes_dev_urandom((void *)&entropy, sizeof(entropy))) {
|
||||
+ if (writeRandomBytes_dev_urandom(&entropy, sizeof(entropy))) {
|
||||
return ENTROPY_DEBUG("/dev/urandom", entropy);
|
||||
}
|
||||
# endif /* ! defined(_WIN32) && defined(XML_DEV_URANDOM) */
|
||||
/* .. and self-made low quality for backup: */
|
||||
|
||||
- entropy = gather_time_entropy();
|
||||
+ entropy.k[0] = 0;
|
||||
+ entropy.k[1] = gather_time_entropy();
|
||||
# if ! defined(__wasi__)
|
||||
/* Process ID is 0 bits entropy if attacker has local access */
|
||||
- entropy ^= getpid();
|
||||
+ entropy.k[1] ^= getpid();
|
||||
# endif
|
||||
|
||||
/* Factors are 2^31-1 and 2^61-1 (Mersenne primes M31 and M61) */
|
||||
if (sizeof(unsigned long) == 4) {
|
||||
- return ENTROPY_DEBUG("fallback(4)", entropy * 2147483647);
|
||||
+ entropy.k[1] *= 2147483647;
|
||||
+ return ENTROPY_DEBUG("fallback(4)", entropy);
|
||||
} else {
|
||||
- return ENTROPY_DEBUG("fallback(8)",
|
||||
- entropy * (unsigned long)2305843009213693951ULL);
|
||||
+ entropy.k[1] *= 2305843009213693951ULL;
|
||||
+ return ENTROPY_DEBUG("fallback(8)", entropy);
|
||||
}
|
||||
#endif
|
||||
}
|
||||
|
||||
-static unsigned long
|
||||
-get_hash_secret_salt(XML_Parser parser) {
|
||||
- const XML_Parser rootParser = getRootParserOf(parser, NULL);
|
||||
- assert(! rootParser->m_parentParser);
|
||||
-
|
||||
- return rootParser->m_hash_secret_salt;
|
||||
-}
|
||||
-
|
||||
static enum XML_Error
|
||||
callProcessor(XML_Parser parser, const char *start, const char *end,
|
||||
const char **endPtr) {
|
||||
@@ -1320,8 +1316,10 @@ callProcessor(XML_Parser parser, const char *start, const char *end,
|
||||
static XML_Bool /* only valid for root parser */
|
||||
startParsing(XML_Parser parser) {
|
||||
/* hash functions must be initialized before setContext() is called */
|
||||
- if (parser->m_hash_secret_salt == 0)
|
||||
- parser->m_hash_secret_salt = generate_hash_secret_salt(parser);
|
||||
+ if (parser->m_hash_secret_salt_set != XML_TRUE) {
|
||||
+ parser->m_hash_secret_salt_128 = generate_hash_secret_salt();
|
||||
+ parser->m_hash_secret_salt_set = XML_TRUE;
|
||||
+ }
|
||||
if (parser->m_ns) {
|
||||
/* implicit context only set for root parser, since child
|
||||
parsers (i.e. external entity parsers) will inherit it
|
||||
@@ -1609,7 +1607,9 @@ parserInit(XML_Parser parser, const XML_Char *encodingName) {
|
||||
parser->m_useForeignDTD = XML_FALSE;
|
||||
parser->m_paramEntityParsing = XML_PARAM_ENTITY_PARSING_NEVER;
|
||||
#endif
|
||||
- parser->m_hash_secret_salt = 0;
|
||||
+ parser->m_hash_secret_salt_128.k[0] = 0;
|
||||
+ parser->m_hash_secret_salt_128.k[1] = 0;
|
||||
+ parser->m_hash_secret_salt_set = XML_FALSE;
|
||||
|
||||
#if XML_GE == 1
|
||||
memset(&parser->m_accounting, 0, sizeof(ACCOUNTING));
|
||||
@@ -1776,7 +1776,8 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context,
|
||||
from hash tables associated with either parser without us having
|
||||
to worry which hash secrets each table has.
|
||||
*/
|
||||
- unsigned long oldhash_secret_salt;
|
||||
+ struct sipkey oldhash_secret_salt_128;
|
||||
+ XML_Bool oldhash_secret_salt_set;
|
||||
XML_Bool oldReparseDeferralEnabled;
|
||||
|
||||
/* Validate the oldParser parameter before we pull everything out of it */
|
||||
@@ -1822,7 +1823,8 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context,
|
||||
from hash tables associated with either parser without us having
|
||||
to worry which hash secrets each table has.
|
||||
*/
|
||||
- oldhash_secret_salt = parser->m_hash_secret_salt;
|
||||
+ oldhash_secret_salt_128 = parser->m_hash_secret_salt_128;
|
||||
+ oldhash_secret_salt_set = parser->m_hash_secret_salt_set;
|
||||
oldReparseDeferralEnabled = parser->m_reparseDeferralEnabled;
|
||||
|
||||
#ifdef XML_DTD
|
||||
@@ -1877,7 +1879,8 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context,
|
||||
parser->m_externalEntityRefHandlerArg = oldExternalEntityRefHandlerArg;
|
||||
parser->m_defaultExpandInternalEntities = oldDefaultExpandInternalEntities;
|
||||
parser->m_ns_triplets = oldns_triplets;
|
||||
- parser->m_hash_secret_salt = oldhash_secret_salt;
|
||||
+ parser->m_hash_secret_salt_128 = oldhash_secret_salt_128;
|
||||
+ parser->m_hash_secret_salt_set = oldhash_secret_salt_set;
|
||||
parser->m_reparseDeferralEnabled = oldReparseDeferralEnabled;
|
||||
parser->m_parentParser = oldParser;
|
||||
#ifdef XML_DTD
|
||||
@@ -2321,6 +2324,7 @@ XML_SetParamEntityParsing(XML_Parser parser,
|
||||
#endif
|
||||
}
|
||||
|
||||
+// DEPRECATED since Expat 2.7.6.
|
||||
int XMLCALL
|
||||
XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt) {
|
||||
if (parser == NULL)
|
||||
@@ -2332,10 +2336,46 @@ XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt) {
|
||||
/* block after XML_Parse()/XML_ParseBuffer() has been called */
|
||||
if (parserBusy(rootParser))
|
||||
return 0;
|
||||
- rootParser->m_hash_secret_salt = hash_salt;
|
||||
+
|
||||
+ rootParser->m_hash_secret_salt_128.k[0] = 0;
|
||||
+ rootParser->m_hash_secret_salt_128.k[1] = hash_salt;
|
||||
+
|
||||
+ if (hash_salt != 0) { // to remain backwards compatible
|
||||
+ rootParser->m_hash_secret_salt_set = XML_TRUE;
|
||||
+
|
||||
+ if (sizeof(unsigned long) == 4)
|
||||
+ ENTROPY_DEBUG("explicit(4)", rootParser->m_hash_secret_salt_128);
|
||||
+ else
|
||||
+ ENTROPY_DEBUG("explicit(8)", rootParser->m_hash_secret_salt_128);
|
||||
+ }
|
||||
+
|
||||
return 1;
|
||||
}
|
||||
|
||||
+XML_Bool XMLCALL
|
||||
+XML_SetHashSalt16Bytes(XML_Parser parser, const uint8_t entropy[16]) {
|
||||
+ if (parser == NULL)
|
||||
+ return XML_FALSE;
|
||||
+
|
||||
+ if (entropy == NULL)
|
||||
+ return XML_FALSE;
|
||||
+
|
||||
+ const XML_Parser rootParser = getRootParserOf(parser, NULL);
|
||||
+ assert(! rootParser->m_parentParser);
|
||||
+
|
||||
+ /* block after XML_Parse()/XML_ParseBuffer() has been called */
|
||||
+ if (parserBusy(rootParser))
|
||||
+ return XML_FALSE;
|
||||
+
|
||||
+ sip_tokey(&(rootParser->m_hash_secret_salt_128), entropy);
|
||||
+
|
||||
+ rootParser->m_hash_secret_salt_set = XML_TRUE;
|
||||
+
|
||||
+ ENTROPY_DEBUG("explicit(16)", rootParser->m_hash_secret_salt_128);
|
||||
+
|
||||
+ return XML_TRUE;
|
||||
+}
|
||||
+
|
||||
enum XML_Status XMLCALL
|
||||
XML_Parse(XML_Parser parser, const char *s, int len, int isFinal) {
|
||||
if ((parser == NULL) || (len < 0) || ((s == NULL) && (len != 0))) {
|
||||
@@ -7837,8 +7877,10 @@ keylen(KEY s) {
|
||||
|
||||
static void
|
||||
copy_salt_to_sipkey(XML_Parser parser, struct sipkey *key) {
|
||||
- key->k[0] = 0;
|
||||
- key->k[1] = get_hash_secret_salt(parser);
|
||||
+ const XML_Parser rootParser = getRootParserOf(parser, NULL);
|
||||
+ assert(! rootParser->m_parentParser);
|
||||
+
|
||||
+ *key = rootParser->m_hash_secret_salt_128;
|
||||
}
|
||||
|
||||
static unsigned long FASTCALL
|
||||
diff --git a/tests/basic_tests.c b/tests/basic_tests.c
|
||||
index 023d9ce4..380caf19 100644
|
||||
--- a/tests/basic_tests.c
|
||||
+++ b/tests/basic_tests.c
|
||||
@@ -204,6 +204,30 @@ START_TEST(test_hash_collision) {
|
||||
END_TEST
|
||||
#undef COLLIDING_HASH_SALT
|
||||
|
||||
+START_TEST(test_hash_salt_setter) {
|
||||
+ const uint8_t entropy[16] = {'0', '1', '2', '3', '4', '5', '6', '7',
|
||||
+ '8', '9', 'a', 'b', 'c', 'd', 'e', 'f'};
|
||||
+ XML_Parser parser = XML_ParserCreate(NULL);
|
||||
+
|
||||
+ // NULL parser should be rejected
|
||||
+ assert_true(XML_SetHashSalt16Bytes(NULL, entropy) == XML_FALSE);
|
||||
+
|
||||
+ // NULL entropy should be rejected
|
||||
+ assert_true(XML_SetHashSalt16Bytes(parser, NULL) == XML_FALSE);
|
||||
+
|
||||
+ // Setting should be allowed more than once
|
||||
+ assert_true(XML_SetHashSalt16Bytes(parser, entropy) == XML_TRUE);
|
||||
+ assert_true(XML_SetHashSalt16Bytes(parser, entropy) == XML_TRUE);
|
||||
+
|
||||
+ // But not after parsing has started
|
||||
+ assert_true(XML_Parse(parser, "", 0, XML_FALSE /* isFinal */)
|
||||
+ == XML_STATUS_OK);
|
||||
+ assert_true(XML_SetHashSalt16Bytes(parser, entropy) == XML_FALSE);
|
||||
+
|
||||
+ XML_ParserFree(parser);
|
||||
+}
|
||||
+END_TEST
|
||||
+
|
||||
/* Regression test for SF bug #491986. */
|
||||
START_TEST(test_danish_latin1) {
|
||||
const char *text = "<?xml version='1.0' encoding='iso-8859-1'?>\n"
|
||||
@@ -6244,6 +6268,7 @@ make_basic_test_case(Suite *s) {
|
||||
tcase_add_test(tc_basic, test_bom_utf16_le);
|
||||
tcase_add_test(tc_basic, test_nobom_utf16_le);
|
||||
tcase_add_test(tc_basic, test_hash_collision);
|
||||
+ tcase_add_test(tc_basic, test_hash_salt_setter);
|
||||
tcase_add_test(tc_basic, test_illegal_utf8);
|
||||
tcase_add_test(tc_basic, test_utf8_auto_align);
|
||||
tcase_add_test(tc_basic, test_utf16);
|
||||
70
meta/recipes-core/expat/expat/CVE-2026-45186-01.patch
Normal file
70
meta/recipes-core/expat/expat/CVE-2026-45186-01.patch
Normal file
@@ -0,0 +1,70 @@
|
||||
From 3020144133b2d860c44f4eeacf72e5f2843235a3 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Berkay=20Eren=20=C3=9Cr=C3=BCn?= <berkay.ueruen@siemens.com>
|
||||
Date: Fri, 13 Mar 2026 13:26:45 +0100
|
||||
Subject: [PATCH 1/7] Make "counting_start_element_handler" count default attrs
|
||||
|
||||
(cherry picked from commit 0802a5892030610144b736dec6e2f63e8600fe85)
|
||||
|
||||
CVE: CVE-2026-45186
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/0802a5892030610144b736dec6e2f63e8600fe85]
|
||||
Signed-off-by: Theo Gaige <tgaige.opensource@witekio.com>
|
||||
---
|
||||
tests/basic_tests.c | 8 ++++----
|
||||
tests/handlers.c | 2 +-
|
||||
tests/handlers.h | 1 +
|
||||
3 files changed, 6 insertions(+), 5 deletions(-)
|
||||
|
||||
diff --git a/tests/basic_tests.c b/tests/basic_tests.c
|
||||
index 023d9ce..d6edb16 100644
|
||||
--- a/tests/basic_tests.c
|
||||
+++ b/tests/basic_tests.c
|
||||
@@ -2439,9 +2439,9 @@ START_TEST(test_attributes) {
|
||||
{XCS("id"), XCS("one")},
|
||||
{NULL, NULL}};
|
||||
AttrInfo tag_info[] = {{XCS("c"), XCS("3")}, {NULL, NULL}};
|
||||
- ElementInfo info[] = {{XCS("doc"), 3, XCS("id"), NULL},
|
||||
- {XCS("tag"), 1, NULL, NULL},
|
||||
- {NULL, 0, NULL, NULL}};
|
||||
+ ElementInfo info[] = {{XCS("doc"), 3, 0, XCS("id"), NULL},
|
||||
+ {XCS("tag"), 1, 0, NULL, NULL},
|
||||
+ {NULL, 0, 0, NULL, NULL}};
|
||||
info[0].attributes = doc_info;
|
||||
info[1].attributes = tag_info;
|
||||
|
||||
@@ -5496,7 +5496,7 @@ START_TEST(test_deep_nested_attribute_entity) {
|
||||
(long unsigned)(N_LINES - 1));
|
||||
|
||||
AttrInfo doc_info[] = {{XCS("name"), XCS("deepText")}, {NULL, NULL}};
|
||||
- ElementInfo info[] = {{XCS("foo"), 1, NULL, NULL}, {NULL, 0, NULL, NULL}};
|
||||
+ ElementInfo info[] = {{XCS("foo"), 1, 0, NULL, NULL}, {NULL, 0, 0, NULL, NULL}};
|
||||
info[0].attributes = doc_info;
|
||||
|
||||
XML_Parser parser = XML_ParserCreate(NULL);
|
||||
diff --git a/tests/handlers.c b/tests/handlers.c
|
||||
index e658223..9ff7b35 100644
|
||||
--- a/tests/handlers.c
|
||||
+++ b/tests/handlers.c
|
||||
@@ -137,7 +137,7 @@ counting_start_element_handler(void *userData, const XML_Char *name,
|
||||
fail("ID does not have the correct name");
|
||||
return;
|
||||
}
|
||||
- for (i = 0; i < info->attr_count; i++) {
|
||||
+ for (i = 0; i < info->attr_count + info->default_attr_count; i++) {
|
||||
attr = info->attributes;
|
||||
while (attr->name != NULL) {
|
||||
if (! xcstrcmp(atts[0], attr->name))
|
||||
diff --git a/tests/handlers.h b/tests/handlers.h
|
||||
index ac4ca94..11d45eb 100644
|
||||
--- a/tests/handlers.h
|
||||
+++ b/tests/handlers.h
|
||||
@@ -88,6 +88,7 @@ typedef struct attrInfo {
|
||||
typedef struct elementInfo {
|
||||
const XML_Char *name;
|
||||
int attr_count;
|
||||
+ int default_attr_count;
|
||||
const XML_Char *id_name;
|
||||
AttrInfo *attributes;
|
||||
} ElementInfo;
|
||||
--
|
||||
2.43.0
|
||||
|
||||
318
meta/recipes-core/expat/expat/CVE-2026-45186-02.patch
Normal file
318
meta/recipes-core/expat/expat/CVE-2026-45186-02.patch
Normal file
@@ -0,0 +1,318 @@
|
||||
From ba12af3b3ffd98b9e31c3a01a20d392c89aa974e Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Berkay=20Eren=20=C3=9Cr=C3=BCn?= <berkay.ueruen@siemens.com>
|
||||
Date: Fri, 13 Mar 2026 13:27:31 +0100
|
||||
Subject: [PATCH 2/7] test(attlist): Cover duplicate attribute names
|
||||
|
||||
Co-authored-by: Sebastian Pipping <sebastian@pipping.org>
|
||||
(cherry picked from commit e569f47181c43dca5d262089e541ddf9a9c09927)
|
||||
|
||||
CVE: CVE-2026-45186
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/e569f47181c43dca5d262089e541ddf9a9c09927]
|
||||
Signed-off-by: Theo Gaige <tgaige.opensource@witekio.com>
|
||||
---
|
||||
tests/basic_tests.c | 282 ++++++++++++++++++++++++++++++++++++++++++++
|
||||
1 file changed, 282 insertions(+)
|
||||
|
||||
diff --git a/tests/basic_tests.c b/tests/basic_tests.c
|
||||
index d6edb16..907a458 100644
|
||||
--- a/tests/basic_tests.c
|
||||
+++ b/tests/basic_tests.c
|
||||
@@ -2462,6 +2462,279 @@ START_TEST(test_attributes) {
|
||||
}
|
||||
END_TEST
|
||||
|
||||
+START_TEST(test_duplicate_cdata_attribute) {
|
||||
+ /*
|
||||
+ https://www.w3.org/TR/xml/#attdecls
|
||||
+
|
||||
+ Test the following statement from the linked specification:
|
||||
+ When more than one definition is provided for the same attribute of a given
|
||||
+ element type, the first declaration is binding and later declarations are
|
||||
+ ignored.
|
||||
+ */
|
||||
+
|
||||
+ const char *text
|
||||
+ = "<!DOCTYPE doc [\n"
|
||||
+ " <!ATTLIST doc attribute CDATA 'expected' attribute CDATA 'ignored'>\n"
|
||||
+ "]>\n"
|
||||
+ "<doc/>\n";
|
||||
+ AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected")}, {NULL, NULL}};
|
||||
+ ElementInfo info[]
|
||||
+ = {{XCS("doc"), 0, 1, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}};
|
||||
+
|
||||
+ XML_Parser parser = XML_ParserCreate(NULL);
|
||||
+ assert_true(parser != NULL);
|
||||
+
|
||||
+ ParserAndElementInfo parserAndElementInfos = {
|
||||
+ parser,
|
||||
+ info,
|
||||
+ };
|
||||
+
|
||||
+ XML_SetStartElementHandler(parser, counting_start_element_handler);
|
||||
+ XML_SetUserData(parser, &parserAndElementInfos);
|
||||
+
|
||||
+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
|
||||
+ != XML_STATUS_OK)
|
||||
+ xml_failure(parser);
|
||||
+
|
||||
+ XML_ParserFree(parser);
|
||||
+}
|
||||
+END_TEST
|
||||
+
|
||||
+START_TEST(test_duplicate_id_attribute_1) {
|
||||
+ /*
|
||||
+ https://www.w3.org/TR/xml/#attdecls
|
||||
+
|
||||
+ Test the following statement from the linked specification:
|
||||
+ When more than one definition is provided for the same attribute of a given
|
||||
+ element type, the first declaration is binding and later declarations are
|
||||
+ ignored.
|
||||
+ */
|
||||
+
|
||||
+ const char *text
|
||||
+ = "<!DOCTYPE doc [\n"
|
||||
+ " <!ATTLIST doc identifier CDATA 'expected' identifier ID #REQUIRED>\n"
|
||||
+ "]>\n"
|
||||
+ "<doc/>\n";
|
||||
+ AttrInfo doc_info[] = {{XCS("identifier"), XCS("expected")}, {NULL, NULL}};
|
||||
+ ElementInfo info[]
|
||||
+ = {{XCS("doc"), 0, 1, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}};
|
||||
+
|
||||
+ XML_Parser parser = XML_ParserCreate(NULL);
|
||||
+ assert_true(parser != NULL);
|
||||
+
|
||||
+ ParserAndElementInfo parserAndElementInfos = {
|
||||
+ parser,
|
||||
+ info,
|
||||
+ };
|
||||
+
|
||||
+ XML_SetStartElementHandler(parser, counting_start_element_handler);
|
||||
+ XML_SetUserData(parser, &parserAndElementInfos);
|
||||
+
|
||||
+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
|
||||
+ != XML_STATUS_OK)
|
||||
+ xml_failure(parser);
|
||||
+
|
||||
+ XML_ParserFree(parser);
|
||||
+}
|
||||
+END_TEST
|
||||
+
|
||||
+START_TEST(test_duplicate_id_attribute_2) {
|
||||
+ /*
|
||||
+ https://www.w3.org/TR/xml/#attdecls
|
||||
+
|
||||
+ Test the following statement from the linked specification:
|
||||
+ When more than one definition is provided for the same attribute of a given
|
||||
+ element type, the first declaration is binding and later declarations are
|
||||
+ ignored.
|
||||
+ */
|
||||
+
|
||||
+ const char *text
|
||||
+ = "<!DOCTYPE doc [\n"
|
||||
+ " <!ATTLIST doc identifier ID #REQUIRED identifier CDATA 'unexpected'>\n"
|
||||
+ "]>\n"
|
||||
+ "<doc/>\n";
|
||||
+ AttrInfo doc_info[] = {{NULL, NULL}};
|
||||
+
|
||||
+ ElementInfo info[]
|
||||
+ = {{XCS("doc"), 0, 0, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}};
|
||||
+
|
||||
+ XML_Parser parser = XML_ParserCreate(NULL);
|
||||
+ assert_true(parser != NULL);
|
||||
+
|
||||
+ ParserAndElementInfo parserAndElementInfos = {
|
||||
+ parser,
|
||||
+ info,
|
||||
+ };
|
||||
+
|
||||
+ XML_SetStartElementHandler(parser, counting_start_element_handler);
|
||||
+ XML_SetUserData(parser, &parserAndElementInfos);
|
||||
+
|
||||
+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
|
||||
+ != XML_STATUS_OK)
|
||||
+ xml_failure(parser);
|
||||
+
|
||||
+ XML_ParserFree(parser);
|
||||
+}
|
||||
+END_TEST
|
||||
+
|
||||
+START_TEST(test_duplicate_cdata_attribute_multiple_attlistdecl) {
|
||||
+ /*
|
||||
+ https://www.w3.org/TR/xml/#attdecls
|
||||
+
|
||||
+ Test the following statement from the linked specification:
|
||||
+ When more than one AttlistDecl is provided for a given element type,
|
||||
+ the contents of all those provided are merged.
|
||||
+ */
|
||||
+ const char *text = "<!DOCTYPE doc [\n"
|
||||
+ " <!ATTLIST doc attribute CDATA 'expected'>\n"
|
||||
+ " <!ATTLIST doc attribute CDATA 'ignored'>\n"
|
||||
+ "]>\n"
|
||||
+ "<doc/>\n";
|
||||
+ AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected")}, {NULL, NULL}};
|
||||
+ ElementInfo info[]
|
||||
+ = {{XCS("doc"), 0, 1, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}};
|
||||
+
|
||||
+ XML_Parser parser = XML_ParserCreate(NULL);
|
||||
+ assert_true(parser != NULL);
|
||||
+
|
||||
+ ParserAndElementInfo parserAndElementInfos = {
|
||||
+ parser,
|
||||
+ info,
|
||||
+ };
|
||||
+
|
||||
+ XML_SetStartElementHandler(parser, counting_start_element_handler);
|
||||
+ XML_SetUserData(parser, &parserAndElementInfos);
|
||||
+
|
||||
+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
|
||||
+ != XML_STATUS_OK)
|
||||
+ xml_failure(parser);
|
||||
+
|
||||
+ XML_ParserFree(parser);
|
||||
+}
|
||||
+END_TEST
|
||||
+
|
||||
+START_TEST(test_duplicate_cdata_attribute_multiple_attlistdecl_2) {
|
||||
+ /*
|
||||
+ https://www.w3.org/TR/xml/#attdecls
|
||||
+
|
||||
+ Test the following statement from the linked specification:
|
||||
+ When more than one AttlistDecl is provided for a given element type,
|
||||
+ the contents of all those provided are merged.
|
||||
+ */
|
||||
+ const char *text = "<!DOCTYPE doc [\n"
|
||||
+ " <!ATTLIST doc attribute CDATA 'expected_doc'>\n"
|
||||
+ " <!ATTLIST tag attribute CDATA 'expected_tag'>\n"
|
||||
+ " <!ATTLIST doc attribute CDATA 'ignored_doc'>\n"
|
||||
+ "]>\n"
|
||||
+ "<doc><tag></tag></doc>\n";
|
||||
+ AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected_doc")}, {NULL, NULL}};
|
||||
+ AttrInfo tag_info[] = {{XCS("attribute"), XCS("expected_tag")}, {NULL, NULL}};
|
||||
+ ElementInfo info[] = {{XCS("doc"), 0, 1, NULL, doc_info},
|
||||
+ {XCS("tag"), 0, 1, NULL, tag_info},
|
||||
+ {NULL, 0, 0, NULL, NULL}};
|
||||
+
|
||||
+ XML_Parser parser = XML_ParserCreate(NULL);
|
||||
+ assert_true(parser != NULL);
|
||||
+
|
||||
+ ParserAndElementInfo parserAndElementInfos = {
|
||||
+ parser,
|
||||
+ info,
|
||||
+ };
|
||||
+
|
||||
+ XML_SetStartElementHandler(parser, counting_start_element_handler);
|
||||
+ XML_SetUserData(parser, &parserAndElementInfos);
|
||||
+
|
||||
+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
|
||||
+ != XML_STATUS_OK)
|
||||
+ xml_failure(parser);
|
||||
+
|
||||
+ XML_ParserFree(parser);
|
||||
+}
|
||||
+END_TEST
|
||||
+
|
||||
+START_TEST(test_duplicate_cdata_attribute_multiple_attlistdecl_3) {
|
||||
+ /*
|
||||
+ https://www.w3.org/TR/xml/#attdecls
|
||||
+
|
||||
+ Test the following statement from the linked specification:
|
||||
+ When more than one AttlistDecl is provided for a given element type,
|
||||
+ the contents of all those provided are merged.
|
||||
+ */
|
||||
+ const char *text
|
||||
+ = "<!DOCTYPE doc [\n"
|
||||
+ " <!ATTLIST doc attribute CDATA 'expected_doc'>\n"
|
||||
+ " <!ATTLIST tag attribute CDATA 'expected_tag'>\n"
|
||||
+ " <!ATTLIST doc second_attribute CDATA 'second_expected_doc' attribute CDATA 'ignored_doc'>\n"
|
||||
+ "]>\n"
|
||||
+ "<doc><tag></tag></doc>\n";
|
||||
+ AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected_doc")},
|
||||
+ {XCS("second_attribute"), XCS("second_expected_doc")},
|
||||
+ {NULL, NULL}};
|
||||
+ AttrInfo tag_info[] = {{XCS("attribute"), XCS("expected_tag")}, {NULL, NULL}};
|
||||
+ ElementInfo info[] = {{XCS("doc"), 0, 2, NULL, doc_info},
|
||||
+ {XCS("tag"), 0, 1, NULL, tag_info},
|
||||
+ {NULL, 0, 0, NULL, NULL}};
|
||||
+
|
||||
+ XML_Parser parser = XML_ParserCreate(NULL);
|
||||
+ assert_true(parser != NULL);
|
||||
+
|
||||
+ ParserAndElementInfo parserAndElementInfos = {
|
||||
+ parser,
|
||||
+ info,
|
||||
+ };
|
||||
+
|
||||
+ XML_SetStartElementHandler(parser, counting_start_element_handler);
|
||||
+ XML_SetUserData(parser, &parserAndElementInfos);
|
||||
+
|
||||
+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
|
||||
+ != XML_STATUS_OK)
|
||||
+ xml_failure(parser);
|
||||
+
|
||||
+ XML_ParserFree(parser);
|
||||
+}
|
||||
+END_TEST
|
||||
+
|
||||
+START_TEST(test_duplicate_id_attribute_multiple_attlistdecl) {
|
||||
+ /*
|
||||
+ https://www.w3.org/TR/xml/#attdecls
|
||||
+
|
||||
+ Test the following statement from the linked specification:
|
||||
+ When more than one AttlistDecl is provided for a given element type,
|
||||
+ the contents of all those provided are merged.
|
||||
+ */
|
||||
+ const char *text = "<!DOCTYPE doc [\n"
|
||||
+ " <!ATTLIST doc identifier ID #REQUIRED>\n"
|
||||
+ " <!ATTLIST tag identifier CDATA 'identifier_tag'>\n"
|
||||
+ " <!ATTLIST doc identifier CDATA 'ignored'>\n"
|
||||
+ "]>\n"
|
||||
+ "<doc identifier='doc_identity'><tag></tag></doc>\n";
|
||||
+ AttrInfo doc_info[]
|
||||
+ = {{XCS("identifier"), XCS("doc_identity")}, {NULL, NULL}};
|
||||
+ AttrInfo tag_info[]
|
||||
+ = {{XCS("identifier"), XCS("identifier_tag")}, {NULL, NULL}};
|
||||
+ ElementInfo info[] = {{XCS("doc"), 1, 0, XCS("identifier"), doc_info},
|
||||
+ {XCS("tag"), 0, 1, NULL, tag_info},
|
||||
+ {NULL, 0, 0, NULL, NULL}};
|
||||
+
|
||||
+ XML_Parser parser = XML_ParserCreate(NULL);
|
||||
+ assert_true(parser != NULL);
|
||||
+
|
||||
+ ParserAndElementInfo parserAndElementInfos = {
|
||||
+ parser,
|
||||
+ info,
|
||||
+ };
|
||||
+
|
||||
+ XML_SetStartElementHandler(parser, counting_start_element_handler);
|
||||
+ XML_SetUserData(parser, &parserAndElementInfos);
|
||||
+
|
||||
+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
|
||||
+ != XML_STATUS_OK)
|
||||
+ xml_failure(parser);
|
||||
+
|
||||
+ XML_ParserFree(parser);
|
||||
+}
|
||||
+END_TEST
|
||||
+
|
||||
/* Test reset works correctly in the middle of processing an internal
|
||||
* entity. Exercises some obscure code in XML_ParserReset().
|
||||
*/
|
||||
@@ -6325,6 +6598,15 @@ make_basic_test_case(Suite *s) {
|
||||
tcase_add_test__ifdef_xml_dtd(tc_basic, test_empty_foreign_dtd);
|
||||
tcase_add_test(tc_basic, test_set_base);
|
||||
tcase_add_test(tc_basic, test_attributes);
|
||||
+ tcase_add_test(tc_basic, test_duplicate_cdata_attribute);
|
||||
+ tcase_add_test(tc_basic, test_duplicate_id_attribute_1);
|
||||
+ tcase_add_test(tc_basic, test_duplicate_id_attribute_2);
|
||||
+ tcase_add_test(tc_basic, test_duplicate_cdata_attribute_multiple_attlistdecl);
|
||||
+ tcase_add_test(tc_basic,
|
||||
+ test_duplicate_cdata_attribute_multiple_attlistdecl_2);
|
||||
+ tcase_add_test(tc_basic,
|
||||
+ test_duplicate_cdata_attribute_multiple_attlistdecl_3);
|
||||
+ tcase_add_test(tc_basic, test_duplicate_id_attribute_multiple_attlistdecl);
|
||||
tcase_add_test__if_xml_ge(tc_basic, test_reset_in_entity);
|
||||
tcase_add_test(tc_basic, test_resume_invalid_parse);
|
||||
tcase_add_test(tc_basic, test_resume_resuspended);
|
||||
--
|
||||
2.43.0
|
||||
|
||||
46
meta/recipes-core/expat/expat/CVE-2026-45186-03.patch
Normal file
46
meta/recipes-core/expat/expat/CVE-2026-45186-03.patch
Normal file
@@ -0,0 +1,46 @@
|
||||
From 852ab610685b45c62017556c38096d941c154963 Mon Sep 17 00:00:00 2001
|
||||
From: Sebastian Pipping <sebastian@pipping.org>
|
||||
Date: Mon, 20 Apr 2026 13:44:43 +0200
|
||||
Subject: [PATCH 3/7] tests: Define .attributes the first time around
|
||||
|
||||
(cherry picked from commit 05307d352a5aa858cdda57ec53a53b597b3a4a82)
|
||||
|
||||
CVE: CVE-2026-45186
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/05307d352a5aa858cdda57ec53a53b597b3a4a82]
|
||||
Signed-off-by: Theo Gaige <tgaige.opensource@witekio.com>
|
||||
---
|
||||
tests/basic_tests.c | 10 ++++------
|
||||
1 file changed, 4 insertions(+), 6 deletions(-)
|
||||
|
||||
diff --git a/tests/basic_tests.c b/tests/basic_tests.c
|
||||
index 907a458..b0178fc 100644
|
||||
--- a/tests/basic_tests.c
|
||||
+++ b/tests/basic_tests.c
|
||||
@@ -2439,11 +2439,9 @@ START_TEST(test_attributes) {
|
||||
{XCS("id"), XCS("one")},
|
||||
{NULL, NULL}};
|
||||
AttrInfo tag_info[] = {{XCS("c"), XCS("3")}, {NULL, NULL}};
|
||||
- ElementInfo info[] = {{XCS("doc"), 3, 0, XCS("id"), NULL},
|
||||
- {XCS("tag"), 1, 0, NULL, NULL},
|
||||
+ ElementInfo info[] = {{XCS("doc"), 3, 0, XCS("id"), doc_info},
|
||||
+ {XCS("tag"), 1, 0, NULL, tag_info},
|
||||
{NULL, 0, 0, NULL, NULL}};
|
||||
- info[0].attributes = doc_info;
|
||||
- info[1].attributes = tag_info;
|
||||
|
||||
XML_Parser parser = XML_ParserCreate(NULL);
|
||||
assert_true(parser != NULL);
|
||||
@@ -5769,8 +5767,8 @@ START_TEST(test_deep_nested_attribute_entity) {
|
||||
(long unsigned)(N_LINES - 1));
|
||||
|
||||
AttrInfo doc_info[] = {{XCS("name"), XCS("deepText")}, {NULL, NULL}};
|
||||
- ElementInfo info[] = {{XCS("foo"), 1, 0, NULL, NULL}, {NULL, 0, 0, NULL, NULL}};
|
||||
- info[0].attributes = doc_info;
|
||||
+ ElementInfo info[]
|
||||
+ = {{XCS("foo"), 1, 0, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}};
|
||||
|
||||
XML_Parser parser = XML_ParserCreate(NULL);
|
||||
ParserAndElementInfo parserPlusElemenInfo = {parser, info};
|
||||
--
|
||||
2.43.0
|
||||
|
||||
32
meta/recipes-core/expat/expat/CVE-2026-45186-04.patch
Normal file
32
meta/recipes-core/expat/expat/CVE-2026-45186-04.patch
Normal file
@@ -0,0 +1,32 @@
|
||||
From 89c6acdcd919b64014b180fadec46b0d25760832 Mon Sep 17 00:00:00 2001
|
||||
From: Sebastian Pipping <sebastian@pipping.org>
|
||||
Date: Mon, 13 Apr 2026 01:34:03 +0200
|
||||
Subject: [PATCH 4/7] tests: Make counting_start_element_handler enforce
|
||||
complete attribute lists
|
||||
|
||||
(cherry picked from commit 4176aff73840711060913e0ac6aa1168d8ba5c8d)
|
||||
|
||||
CVE: CVE-2026-45186
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/4176aff73840711060913e0ac6aa1168d8ba5c8d]
|
||||
Signed-off-by: Theo Gaige <tgaige.opensource@witekio.com>
|
||||
---
|
||||
tests/handlers.c | 3 +++
|
||||
1 file changed, 3 insertions(+)
|
||||
|
||||
diff --git a/tests/handlers.c b/tests/handlers.c
|
||||
index 9ff7b35..5e72e8b 100644
|
||||
--- a/tests/handlers.c
|
||||
+++ b/tests/handlers.c
|
||||
@@ -155,6 +155,9 @@ counting_start_element_handler(void *userData, const XML_Char *name,
|
||||
/* Remember, two entries in atts per attribute (see above) */
|
||||
atts += 2;
|
||||
}
|
||||
+
|
||||
+ // Self-test that the test case's list of expected attributes is complete
|
||||
+ assert_true(atts[0] == NULL);
|
||||
}
|
||||
|
||||
void XMLCALL
|
||||
--
|
||||
2.43.0
|
||||
|
||||
32
meta/recipes-core/expat/expat/CVE-2026-45186-05.patch
Normal file
32
meta/recipes-core/expat/expat/CVE-2026-45186-05.patch
Normal file
@@ -0,0 +1,32 @@
|
||||
From d352c83afaa3945c964aba74cb60a00822af96d3 Mon Sep 17 00:00:00 2001
|
||||
From: Sebastian Pipping <sebastian@pipping.org>
|
||||
Date: Sun, 8 Mar 2026 22:14:41 +0100
|
||||
Subject: [PATCH 5/7] lib: Extract a constant for upcoming reuse
|
||||
|
||||
(cherry picked from commit fb35f2d2040d114f355bae8a7450942533237530)
|
||||
|
||||
CVE: CVE-2026-45186
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/fb35f2d2040d114f355bae8a7450942533237530]
|
||||
Signed-off-by: Theo Gaige <tgaige.opensource@witekio.com>
|
||||
---
|
||||
lib/xmlparse.c | 3 ++-
|
||||
1 file changed, 2 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/lib/xmlparse.c b/lib/xmlparse.c
|
||||
index 9bc67f3..8d3e8db 100644
|
||||
--- a/lib/xmlparse.c
|
||||
+++ b/lib/xmlparse.c
|
||||
@@ -7708,8 +7708,9 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd,
|
||||
newE->prefix = (PREFIX *)lookup(oldParser, &(newDtd->prefixes),
|
||||
oldE->prefix->name, 0);
|
||||
for (i = 0; i < newE->nDefaultAtts; i++) {
|
||||
+ const XML_Char *const attributeName = oldE->defaultAtts[i].id->name;
|
||||
newE->defaultAtts[i].id = (ATTRIBUTE_ID *)lookup(
|
||||
- oldParser, &(newDtd->attributeIds), oldE->defaultAtts[i].id->name, 0);
|
||||
+ oldParser, &(newDtd->attributeIds), attributeName, 0);
|
||||
newE->defaultAtts[i].isCdata = oldE->defaultAtts[i].isCdata;
|
||||
if (oldE->defaultAtts[i].value) {
|
||||
newE->defaultAtts[i].value
|
||||
--
|
||||
2.43.0
|
||||
|
||||
87
meta/recipes-core/expat/expat/CVE-2026-45186-06.patch
Normal file
87
meta/recipes-core/expat/expat/CVE-2026-45186-06.patch
Normal file
@@ -0,0 +1,87 @@
|
||||
From a2c8ddb3d6f4df7af64e05bed4b3a4edeae33fd0 Mon Sep 17 00:00:00 2001
|
||||
From: Sebastian Pipping <sebastian@pipping.org>
|
||||
Date: Sun, 8 Mar 2026 23:05:49 +0100
|
||||
Subject: [PATCH 6/7] lib: Introduce ELEMENT_TYPE.defaultAttsNames
|
||||
|
||||
(cherry picked from commit 7f0f1b9e70d937072d2e9e37ae9edf27784cc080)
|
||||
|
||||
CVE: CVE-2026-45186
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/7f0f1b9e70d937072d2e9e37ae9edf27784cc080]
|
||||
Signed-off-by: Theo Gaige <tgaige.opensource@witekio.com>
|
||||
---
|
||||
lib/xmlparse.c | 17 +++++++++++++++++
|
||||
1 file changed, 17 insertions(+)
|
||||
|
||||
diff --git a/lib/xmlparse.c b/lib/xmlparse.c
|
||||
index 8d3e8db..4a29c18 100644
|
||||
--- a/lib/xmlparse.c
|
||||
+++ b/lib/xmlparse.c
|
||||
@@ -388,6 +388,7 @@ typedef struct {
|
||||
int nDefaultAtts;
|
||||
int allocDefaultAtts;
|
||||
DEFAULT_ATTRIBUTE *defaultAtts;
|
||||
+ HASH_TABLE defaultAttsNames;
|
||||
} ELEMENT_TYPE;
|
||||
|
||||
typedef struct {
|
||||
@@ -3844,6 +3845,8 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr,
|
||||
sizeof(ELEMENT_TYPE));
|
||||
if (! elementType)
|
||||
return XML_ERROR_NO_MEMORY;
|
||||
+ if (! elementType->defaultAttsNames.parser)
|
||||
+ hashTableInit(&(elementType->defaultAttsNames), parser);
|
||||
if (parser->m_ns && ! setElementTypePrefix(parser, elementType))
|
||||
return XML_ERROR_NO_MEMORY;
|
||||
}
|
||||
@@ -7549,6 +7552,7 @@ dtdReset(DTD *p, XML_Parser parser) {
|
||||
ELEMENT_TYPE *e = (ELEMENT_TYPE *)hashTableIterNext(&iter);
|
||||
if (! e)
|
||||
break;
|
||||
+ hashTableDestroy(&(e->defaultAttsNames));
|
||||
if (e->allocDefaultAtts != 0)
|
||||
FREE(parser, e->defaultAtts);
|
||||
}
|
||||
@@ -7590,6 +7594,7 @@ dtdDestroy(DTD *p, XML_Bool isDocEntity, XML_Parser parser) {
|
||||
ELEMENT_TYPE *e = (ELEMENT_TYPE *)hashTableIterNext(&iter);
|
||||
if (! e)
|
||||
break;
|
||||
+ hashTableDestroy(&(e->defaultAttsNames));
|
||||
if (e->allocDefaultAtts != 0)
|
||||
FREE(parser, e->defaultAtts);
|
||||
}
|
||||
@@ -7683,6 +7688,10 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd,
|
||||
sizeof(ELEMENT_TYPE));
|
||||
if (! newE)
|
||||
return 0;
|
||||
+
|
||||
+ if (! newE->defaultAttsNames.parser)
|
||||
+ hashTableInit(&(newE->defaultAttsNames), parser);
|
||||
+
|
||||
if (oldE->nDefaultAtts) {
|
||||
/* Detect and prevent integer overflow.
|
||||
* The preprocessor guard addresses the "always false" warning
|
||||
@@ -7719,6 +7728,12 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd,
|
||||
return 0;
|
||||
} else
|
||||
newE->defaultAtts[i].value = NULL;
|
||||
+
|
||||
+ NAMED *const nameAddedOrFound = (NAMED *)lookup(
|
||||
+ parser, &(newE->defaultAttsNames), attributeName, sizeof(NAMED));
|
||||
+ if (! nameAddedOrFound) {
|
||||
+ return 0;
|
||||
+ }
|
||||
}
|
||||
}
|
||||
|
||||
@@ -8458,6 +8473,8 @@ getElementType(XML_Parser parser, const ENCODING *enc, const char *ptr,
|
||||
sizeof(ELEMENT_TYPE));
|
||||
if (! ret)
|
||||
return NULL;
|
||||
+ if (! ret->defaultAttsNames.parser)
|
||||
+ hashTableInit(&(ret->defaultAttsNames), getRootParserOf(parser, NULL));
|
||||
if (ret->name != name)
|
||||
poolDiscard(&dtd->pool);
|
||||
else {
|
||||
--
|
||||
2.43.0
|
||||
|
||||
52
meta/recipes-core/expat/expat/CVE-2026-45186-07.patch
Normal file
52
meta/recipes-core/expat/expat/CVE-2026-45186-07.patch
Normal file
@@ -0,0 +1,52 @@
|
||||
From 0e4829f4be500ce687b37ec82f9650b86c8419c7 Mon Sep 17 00:00:00 2001
|
||||
From: Sebastian Pipping <sebastian@pipping.org>
|
||||
Date: Sun, 8 Mar 2026 23:06:29 +0100
|
||||
Subject: [PATCH 7/7] lib: Leverage ELEMENT_TYPE.defaultAttsNames for attribute
|
||||
collision detection
|
||||
|
||||
.. to resolve quadratic runtime behavior
|
||||
|
||||
(cherry picked from commit 4cd4eb0683e04cd45a2ffc81a08ca2a2663994b5)
|
||||
|
||||
CVE: CVE-2026-45186
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/4cd4eb0683e04cd45a2ffc81a08ca2a2663994b5]
|
||||
Signed-off-by: Theo Gaige <tgaige.opensource@witekio.com>
|
||||
---
|
||||
lib/xmlparse.c | 14 ++++++++++----
|
||||
1 file changed, 10 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/lib/xmlparse.c b/lib/xmlparse.c
|
||||
index 4a29c18..b3f0b73 100644
|
||||
--- a/lib/xmlparse.c
|
||||
+++ b/lib/xmlparse.c
|
||||
@@ -7177,10 +7177,10 @@ defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *attId, XML_Bool isCdata,
|
||||
if (value || isId) {
|
||||
/* The handling of default attributes gets messed up if we have
|
||||
a default which duplicates a non-default. */
|
||||
- int i;
|
||||
- for (i = 0; i < type->nDefaultAtts; i++)
|
||||
- if (attId == type->defaultAtts[i].id)
|
||||
- return 1;
|
||||
+ NAMED *const nameFound
|
||||
+ = (NAMED *)lookup(parser, &(type->defaultAttsNames), attId->name, 0);
|
||||
+ if (nameFound)
|
||||
+ return 1;
|
||||
if (isId && ! type->idAtt && ! attId->xmlns)
|
||||
type->idAtt = attId;
|
||||
}
|
||||
@@ -7227,6 +7227,12 @@ defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *attId, XML_Bool isCdata,
|
||||
att->isCdata = isCdata;
|
||||
if (! isCdata)
|
||||
attId->maybeTokenized = XML_TRUE;
|
||||
+
|
||||
+ NAMED *const nameAddedOrFound = (NAMED *)lookup(
|
||||
+ parser, &(type->defaultAttsNames), attId->name, sizeof(NAMED));
|
||||
+ if (! nameAddedOrFound)
|
||||
+ return 0;
|
||||
+
|
||||
type->nDefaultAtts += 1;
|
||||
return 1;
|
||||
}
|
||||
--
|
||||
2.43.0
|
||||
|
||||
80
meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch
Normal file
80
meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch
Normal file
@@ -0,0 +1,80 @@
|
||||
From 9d1c131840a501e6664c5770046153235467f574 Mon Sep 17 00:00:00 2001
|
||||
From: Matthew Fernandez <matthew.fernandez@gmail.com>
|
||||
Date: Thu, 4 Jun 2026 17:01:02 -0700
|
||||
Subject: [PATCH 13/17] lib: Remove reuse of `m_groupSize` to count
|
||||
`m_scaffIndex` allocation
|
||||
|
||||
The sizes of the two arrays `m_groupConnector` and `scaffIndex` need to
|
||||
vary independently. This change is a step towards allowing this.
|
||||
|
||||
Anthropic: ANT-2026-00037
|
||||
Anthropic: ANT-2026-03621
|
||||
Anthropic: ANT-2026-03867
|
||||
Co-authored-by: Alessandro Gario <alessandro.gario@trailofbits.com>
|
||||
|
||||
CVE: CVE-2026-56132
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/3a4eaf47af8fd7abda38ea2c08308c91152061f3]
|
||||
|
||||
Backport Changes:
|
||||
- Adapt scaffIndex sizing to Scarthgap 2.6.4, where m_groupSize is
|
||||
not temporarily doubled before reallocation.
|
||||
Keep the branch's equivalent size_t overflow check.
|
||||
|
||||
(cherry picked from commit 3a4eaf47af8fd7abda38ea2c08308c91152061f3)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/lib/xmlparse.c | 6 ++++++
|
||||
1 file changed, 6 insertions(+)
|
||||
|
||||
diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
|
||||
index 8439dc0e..e9ad78df 100644
|
||||
--- a/expat/lib/xmlparse.c
|
||||
+++ b/expat/lib/xmlparse.c
|
||||
@@ -423,6 +423,7 @@ typedef struct {
|
||||
unsigned scaffCount;
|
||||
int scaffLevel;
|
||||
int *scaffIndex;
|
||||
+ size_t scaffIndexSize;
|
||||
} DTD;
|
||||
|
||||
enum EntityType {
|
||||
@@ -5975,6 +5976,7 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end,
|
||||
if (new_scaff_index == NULL)
|
||||
return XML_ERROR_NO_MEMORY;
|
||||
dtd->scaffIndex = new_scaff_index;
|
||||
+ dtd->scaffIndexSize = parser->m_groupSize;
|
||||
}
|
||||
} else {
|
||||
parser->m_groupConnector = MALLOC(parser, parser->m_groupSize = 32);
|
||||
@@ -7575,6 +7577,7 @@ dtdCreate(XML_Parser parser) {
|
||||
|
||||
p->in_eldecl = XML_FALSE;
|
||||
p->scaffIndex = NULL;
|
||||
+ p->scaffIndexSize = 0;
|
||||
p->scaffold = NULL;
|
||||
p->scaffLevel = 0;
|
||||
p->scaffSize = 0;
|
||||
@@ -7615,6 +7618,7 @@ dtdReset(DTD *p, XML_Parser parser) {
|
||||
|
||||
FREE(parser, p->scaffIndex);
|
||||
p->scaffIndex = NULL;
|
||||
+ p->scaffIndexSize = 0;
|
||||
FREE(parser, p->scaffold);
|
||||
p->scaffold = NULL;
|
||||
|
||||
@@ -7790,6 +7794,7 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd,
|
||||
newDtd->scaffSize = oldDtd->scaffSize;
|
||||
newDtd->scaffLevel = oldDtd->scaffLevel;
|
||||
newDtd->scaffIndex = oldDtd->scaffIndex;
|
||||
+ newDtd->scaffIndexSize = oldDtd->scaffIndexSize;
|
||||
|
||||
return 1;
|
||||
} /* End dtdCopy */
|
||||
@@ -8310,6 +8315,7 @@ nextScaffoldPart(XML_Parser parser) {
|
||||
dtd->scaffIndex = MALLOC(parser, parser->m_groupSize * sizeof(int));
|
||||
if (! dtd->scaffIndex)
|
||||
return -1;
|
||||
+ dtd->scaffIndexSize = parser->m_groupSize;
|
||||
dtd->scaffIndex[0] = 0;
|
||||
}
|
||||
|
||||
60
meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch
Normal file
60
meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch
Normal file
@@ -0,0 +1,60 @@
|
||||
From a4c1b874dffcc80ee63ca3b4d6a1537c56da8dc1 Mon Sep 17 00:00:00 2001
|
||||
From: Matthew Fernandez <matthew.fernandez@gmail.com>
|
||||
Date: Thu, 4 Jun 2026 17:01:02 -0700
|
||||
Subject: [PATCH 14/17] lib: doProlog: Fix out-of-bound scaffolding index store
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
The scaffold backing array is reallocated using the caller parser’s
|
||||
per-parser `m_groupSize`, but the DTD struct (which carries
|
||||
`scaffIndex`) is shared between a parent parser and any external
|
||||
parameter-entity sub-parser created via
|
||||
`XML_ExternalEntityParserCreate(parent, NULL, …)`. A sub-parser whose
|
||||
group nesting is shallower than the parent’s can `REALLOC` the shared
|
||||
`scaffIndex` down to its own size; when the parent resumes and parses a
|
||||
deeper element content model, its bounds check passes (its private
|
||||
`m_groupSize` is still large enough), the doubling-grow path is skipped,
|
||||
and the next write lands past the shrunken buffer.
|
||||
|
||||
Anthropic: ANT-2026-00037
|
||||
Anthropic: ANT-2026-03621
|
||||
Anthropic: ANT-2026-03867
|
||||
Co-authored-by: Alessandro Gario <alessandro.gario@trailofbits.com>
|
||||
Reported-by: Trail of Bits, in collaboration with Anthropic
|
||||
|
||||
CVE: CVE-2026-56132
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/58400483d7c97be316d7a77739c0a6af5d55932e]
|
||||
|
||||
(cherry picked from commit 58400483d7c97be316d7a77739c0a6af5d55932e)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/lib/xmlparse.c | 15 +++++++++++++++
|
||||
1 file changed, 15 insertions(+)
|
||||
|
||||
diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
|
||||
index e9ad78df..c46c17bc 100644
|
||||
--- a/expat/lib/xmlparse.c
|
||||
+++ b/expat/lib/xmlparse.c
|
||||
@@ -5992,6 +5992,21 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end,
|
||||
if (myindex < 0)
|
||||
return XML_ERROR_NO_MEMORY;
|
||||
assert(dtd->scaffIndex != NULL);
|
||||
+ if ((size_t)dtd->scaffLevel >= dtd->scaffIndexSize) {
|
||||
+ /* Detect and prevent integer overflow */
|
||||
+ if (dtd->scaffIndexSize > SIZE_MAX / 2 / sizeof(int)) {
|
||||
+ return XML_ERROR_NO_MEMORY;
|
||||
+ }
|
||||
+ assert(dtd->scaffIndexSize > 0);
|
||||
+ const size_t new_size = dtd->scaffIndexSize * 2;
|
||||
+ int *const new_scaff_index
|
||||
+ = REALLOC(parser, dtd->scaffIndex, new_size * sizeof(int));
|
||||
+ if (new_scaff_index == NULL) {
|
||||
+ return XML_ERROR_NO_MEMORY;
|
||||
+ }
|
||||
+ dtd->scaffIndex = new_scaff_index;
|
||||
+ dtd->scaffIndexSize = new_size;
|
||||
+ }
|
||||
dtd->scaffIndex[dtd->scaffLevel] = myindex;
|
||||
dtd->scaffLevel++;
|
||||
dtd->scaffold[myindex].type = XML_CTYPE_SEQ;
|
||||
74
meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch
Normal file
74
meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch
Normal file
@@ -0,0 +1,74 @@
|
||||
From 5d4d0dab46e077b327f70a7c02a307287e8d1fe5 Mon Sep 17 00:00:00 2001
|
||||
From: Matthew Fernandez <matthew.fernandez@gmail.com>
|
||||
Date: Thu, 4 Jun 2026 17:01:02 -0700
|
||||
Subject: [PATCH 15/17] tests: Add a test case for scaffolding array limits in
|
||||
shared DTDs
|
||||
|
||||
This test case provokes the bug fixed in the previous commit.
|
||||
|
||||
Anthropic: ANT-2026-00037
|
||||
Anthropic: ANT-2026-03621
|
||||
Anthropic: ANT-2026-03867
|
||||
Co-authored-by: Alessandro Gario <alessandro.gario@trailofbits.com>
|
||||
Reported-by: Trail of Bits, in collaboration with Anthropic
|
||||
|
||||
CVE: CVE-2026-56132
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/353919b3b9f2174073a557ac7d517a5f3cd0cbbf]
|
||||
|
||||
(cherry picked from commit 353919b3b9f2174073a557ac7d517a5f3cd0cbbf)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/tests/basic_tests.c | 33 +++++++++++++++++++++++++++++++++
|
||||
1 file changed, 33 insertions(+)
|
||||
|
||||
diff --git a/expat/tests/basic_tests.c b/expat/tests/basic_tests.c
|
||||
index 023d9ce4..d52dcf1c 100644
|
||||
--- a/expat/tests/basic_tests.c
|
||||
+++ b/expat/tests/basic_tests.c
|
||||
@@ -4044,6 +4044,37 @@ START_TEST(test_skipped_external_entity) {
|
||||
}
|
||||
END_TEST
|
||||
|
||||
+START_TEST(test_scaff_index_shared_across_external_entity_parser) {
|
||||
+ const char text[]
|
||||
+ = "<!DOCTYPE doc [\n"
|
||||
+ "<!ELEMENT a "
|
||||
+ "((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((b))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))>\n"
|
||||
+ "<!ENTITY % e SYSTEM 'ext'>\n"
|
||||
+ "%e;\n"
|
||||
+ "<!ELEMENT c "
|
||||
+ "(((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((d)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))>\n"
|
||||
+ "]>\n"
|
||||
+ "<doc/>";
|
||||
+ ExtOption options[]
|
||||
+ = {{XCS("ext"),
|
||||
+ "<!ELEMENT x "
|
||||
+ "((((((((((((((((((((((((((((((((y))))))))))))))))))))))))))))))))>"},
|
||||
+ {NULL, NULL}};
|
||||
+
|
||||
+ XML_Parser parser = XML_ParserCreate(NULL);
|
||||
+ XML_SetParamEntityParsing(parser, XML_PARAM_ENTITY_PARSING_ALWAYS);
|
||||
+ XML_SetUserData(parser, options);
|
||||
+ XML_SetExternalEntityRefHandler(parser, external_entity_optioner);
|
||||
+ XML_SetElementDeclHandler(parser, dummy_element_decl_handler);
|
||||
+
|
||||
+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
|
||||
+ == XML_STATUS_ERROR)
|
||||
+ xml_failure(parser);
|
||||
+
|
||||
+ XML_ParserFree(parser);
|
||||
+}
|
||||
+END_TEST
|
||||
+
|
||||
/* Test a different form of unknown external entity */
|
||||
START_TEST(test_skipped_null_loaded_ext_entity) {
|
||||
const char *text = "<!DOCTYPE doc SYSTEM 'http://example.org/one.ent'>\n"
|
||||
@@ -6399,6 +6430,8 @@ make_basic_test_case(Suite *s) {
|
||||
tcase_add_test(tc_basic, test_trailing_cr_in_att_value);
|
||||
tcase_add_test(tc_basic, test_standalone_internal_entity);
|
||||
tcase_add_test(tc_basic, test_skipped_external_entity);
|
||||
+ tcase_add_test__ifdef_xml_dtd(
|
||||
+ tc_basic, test_scaff_index_shared_across_external_entity_parser);
|
||||
tcase_add_test(tc_basic, test_skipped_null_loaded_ext_entity);
|
||||
tcase_add_test(tc_basic, test_skipped_unloaded_ext_entity);
|
||||
tcase_add_test__ifdef_xml_dtd(tc_basic, test_param_entity_with_trailing_cr);
|
||||
60
meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch
Normal file
60
meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch
Normal file
@@ -0,0 +1,60 @@
|
||||
From a7d7ed5d6dbcc7231529357d64eb19ede3114868 Mon Sep 17 00:00:00 2001
|
||||
From: Matthew Fernandez <matthew.fernandez@gmail.com>
|
||||
Date: Thu, 4 Jun 2026 17:01:02 -0700
|
||||
Subject: [PATCH 16/17] lib: Remove unnecessary `scaffIndex` expansion
|
||||
|
||||
Following the previous changes, all locations that append entries to
|
||||
`scaffIndex` handle expanding the array if it is not already large
|
||||
enough. So this extra expansion code is no longer necessary. In some
|
||||
cases such as processing siblings with alternating scaffolding counts,
|
||||
this logic would actually _shrink_ the array only to then later
|
||||
re-expand it.
|
||||
|
||||
Anthropic: ANT-2026-00037
|
||||
Anthropic: ANT-2026-03621
|
||||
Anthropic: ANT-2026-03867
|
||||
Co-authored-by: Alessandro Gario <alessandro.gario@trailofbits.com>
|
||||
|
||||
CVE: CVE-2026-56132
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/bca93b4ba9e15fd84425568d772b69baebf790e4]
|
||||
|
||||
Backport Changes:
|
||||
- Remove the Scarthgap 2.6.4 scaffIndex resize block because later
|
||||
append paths already expand the array when required.
|
||||
|
||||
(cherry picked from commit bca93b4ba9e15fd84425568d772b69baebf790e4)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/lib/xmlparse.c | 19 -------------------
|
||||
1 file changed, 19 deletions(-)
|
||||
|
||||
diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
|
||||
index c46c17bc..3afe2884 100644
|
||||
--- a/expat/lib/xmlparse.c
|
||||
+++ b/expat/lib/xmlparse.c
|
||||
@@ -5959,25 +5959,6 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end,
|
||||
}
|
||||
parser->m_groupConnector = new_connector;
|
||||
}
|
||||
-
|
||||
- if (dtd->scaffIndex) {
|
||||
- /* Detect and prevent integer overflow.
|
||||
- * The preprocessor guard addresses the "always false" warning
|
||||
- * from -Wtype-limits on platforms where
|
||||
- * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */
|
||||
-#if UINT_MAX >= SIZE_MAX
|
||||
- if (parser->m_groupSize > (size_t)(-1) / sizeof(int)) {
|
||||
- return XML_ERROR_NO_MEMORY;
|
||||
- }
|
||||
-#endif
|
||||
-
|
||||
- int *const new_scaff_index = REALLOC(
|
||||
- parser, dtd->scaffIndex, parser->m_groupSize * sizeof(int));
|
||||
- if (new_scaff_index == NULL)
|
||||
- return XML_ERROR_NO_MEMORY;
|
||||
- dtd->scaffIndex = new_scaff_index;
|
||||
- dtd->scaffIndexSize = parser->m_groupSize;
|
||||
- }
|
||||
} else {
|
||||
parser->m_groupConnector = MALLOC(parser, parser->m_groupSize = 32);
|
||||
if (! parser->m_groupConnector) {
|
||||
56
meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch
Normal file
56
meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch
Normal file
@@ -0,0 +1,56 @@
|
||||
From 778ba31c47f9930fe339194f4d97081e43893362 Mon Sep 17 00:00:00 2001
|
||||
From: Matthew Fernandez <matthew.fernandez@gmail.com>
|
||||
Date: Thu, 4 Jun 2026 17:01:02 -0700
|
||||
Subject: [PATCH 17/17] lib: Remove indented scoping of `new_connector` local
|
||||
|
||||
Following the previous change, the lifetime of `new_connector` as
|
||||
constrained by this introduced scope was identical to the parent scope.
|
||||
|
||||
CVE: CVE-2026-56132
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/08baa7ef9d168b99094249998fd78f8d190526e5]
|
||||
|
||||
Backport Changes:
|
||||
- Retain the Scarthgap 2.6.4 unsigned integer overflow guard while
|
||||
removing only the redundant new_connector scope.
|
||||
|
||||
(cherry picked from commit 08baa7ef9d168b99094249998fd78f8d190526e5)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/lib/xmlparse.c | 22 ++++++++++------------
|
||||
1 file changed, 10 insertions(+), 12 deletions(-)
|
||||
|
||||
diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
|
||||
index 3afe2884..df8331d5 100644
|
||||
--- a/expat/lib/xmlparse.c
|
||||
+++ b/expat/lib/xmlparse.c
|
||||
@@ -5945,20 +5945,18 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end,
|
||||
case XML_ROLE_GROUP_OPEN:
|
||||
if (parser->m_prologState.level >= parser->m_groupSize) {
|
||||
if (parser->m_groupSize) {
|
||||
- {
|
||||
- /* Detect and prevent integer overflow */
|
||||
- if (parser->m_groupSize > (unsigned int)(-1) / 2u) {
|
||||
- return XML_ERROR_NO_MEMORY;
|
||||
- }
|
||||
+ /* Detect and prevent integer overflow */
|
||||
+ if (parser->m_groupSize > (unsigned int)(-1) / 2u) {
|
||||
+ return XML_ERROR_NO_MEMORY;
|
||||
+ }
|
||||
|
||||
- char *const new_connector = REALLOC(
|
||||
- parser, parser->m_groupConnector, parser->m_groupSize *= 2);
|
||||
- if (new_connector == NULL) {
|
||||
- parser->m_groupSize /= 2;
|
||||
- return XML_ERROR_NO_MEMORY;
|
||||
- }
|
||||
- parser->m_groupConnector = new_connector;
|
||||
+ char *const new_connector = REALLOC(parser, parser->m_groupConnector,
|
||||
+ parser->m_groupSize *= 2);
|
||||
+ if (new_connector == NULL) {
|
||||
+ parser->m_groupSize /= 2;
|
||||
+ return XML_ERROR_NO_MEMORY;
|
||||
}
|
||||
+ parser->m_groupConnector = new_connector;
|
||||
} else {
|
||||
parser->m_groupConnector = MALLOC(parser, parser->m_groupSize = 32);
|
||||
if (! parser->m_groupConnector) {
|
||||
81
meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch
Normal file
81
meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch
Normal file
@@ -0,0 +1,81 @@
|
||||
From b689559597116ee75a633453e2f7177c8541b04e Mon Sep 17 00:00:00 2001
|
||||
From: Sebastian Pipping <sebastian@pipping.org>
|
||||
Date: Wed, 20 May 2026 12:12:10 +0200
|
||||
Subject: [PATCH 01/17] lib: Protect function `storeAtts` from signed integer
|
||||
overflow
|
||||
|
||||
CVE: CVE-2026-56403
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/12dc6d8d3d65f79471a94d8565f6bf1cf245f648]
|
||||
|
||||
Backport Changes:
|
||||
- Adapt storeAtts to the Scarthgap 2.6.4 loop and URI allocation
|
||||
logic while preserving the upstream overflow checks.
|
||||
|
||||
(cherry picked from commit 12dc6d8d3d65f79471a94d8565f6bf1cf245f648)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/lib/xmlparse.c | 30 ++++++++++++++++++++----------
|
||||
1 file changed, 20 insertions(+), 10 deletions(-)
|
||||
|
||||
diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
|
||||
index 9bc67f38..df92a3ca 100644
|
||||
--- a/expat/lib/xmlparse.c
|
||||
+++ b/expat/lib/xmlparse.c
|
||||
@@ -4226,26 +4226,32 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr,
|
||||
return XML_ERROR_NONE;
|
||||
prefixLen = 0;
|
||||
if (parser->m_ns_triplets && binding->prefix->name) {
|
||||
- for (; binding->prefix->name[prefixLen++];)
|
||||
- ; /* prefixLen includes null terminator */
|
||||
+ size_t candidateLen = 0;
|
||||
+ for (; binding->prefix->name[candidateLen++];)
|
||||
+ ; /* candidateLen includes null terminator */
|
||||
+ /* Detect and prevent integer overflow */
|
||||
+ if (candidateLen > INT_MAX)
|
||||
+ return XML_ERROR_NO_MEMORY;
|
||||
+ prefixLen = (int)candidateLen;
|
||||
}
|
||||
tagNamePtr->localPart = localPart;
|
||||
tagNamePtr->uriLen = binding->uriLen;
|
||||
tagNamePtr->prefix = binding->prefix->name;
|
||||
tagNamePtr->prefixLen = prefixLen;
|
||||
- for (i = 0; localPart[i++];)
|
||||
- ; /* i includes null terminator */
|
||||
+
|
||||
+ size_t localPartLen = 0;
|
||||
+ for (; localPart[localPartLen++];)
|
||||
+ ; /* localPartLen includes null terminator */
|
||||
|
||||
/* Detect and prevent integer overflow */
|
||||
- if (binding->uriLen > INT_MAX - prefixLen
|
||||
- || i > INT_MAX - (binding->uriLen + prefixLen)) {
|
||||
+ if (localPartLen > INT_MAX || binding->uriLen > INT_MAX - prefixLen
|
||||
+ || localPartLen > (size_t)INT_MAX - (binding->uriLen + prefixLen)) {
|
||||
return XML_ERROR_NO_MEMORY;
|
||||
}
|
||||
|
||||
- n = i + binding->uriLen + prefixLen;
|
||||
+ n = (int)localPartLen + binding->uriLen + prefixLen;
|
||||
if (n > binding->uriAlloc) {
|
||||
TAG *p;
|
||||
-
|
||||
/* Detect and prevent integer overflow */
|
||||
if (n > INT_MAX - EXPAND_SPARE) {
|
||||
return XML_ERROR_NO_MEMORY;
|
||||
@@ -4273,10 +4279,14 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr,
|
||||
}
|
||||
/* if m_namespaceSeparator != '\0' then uri includes it already */
|
||||
uri = binding->uri + binding->uriLen;
|
||||
- memcpy(uri, localPart, i * sizeof(XML_Char));
|
||||
+ /* Detect and prevent integer overflow */
|
||||
+ if (localPartLen > SIZE_MAX / sizeof(XML_Char)) {
|
||||
+ return XML_ERROR_NO_MEMORY;
|
||||
+ }
|
||||
+ memcpy(uri, localPart, localPartLen * sizeof(XML_Char));
|
||||
/* we always have a namespace separator between localPart and prefix */
|
||||
if (prefixLen) {
|
||||
- uri += i - 1;
|
||||
+ uri += localPartLen - 1;
|
||||
*uri = parser->m_namespaceSeparator; /* replace null terminator */
|
||||
memcpy(uri + 1, binding->prefix->name, prefixLen * sizeof(XML_Char));
|
||||
}
|
||||
52
meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch
Normal file
52
meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch
Normal file
@@ -0,0 +1,52 @@
|
||||
From 2855ce68a1ce9732267c06734427930364ab66c1 Mon Sep 17 00:00:00 2001
|
||||
From: Sebastian Pipping <sebastian@pipping.org>
|
||||
Date: Fri, 22 May 2026 00:43:52 +0200
|
||||
Subject: [PATCH 02/17] xmlwf: Protect function `xcsdup` from signed integer
|
||||
overflow
|
||||
|
||||
CVE: CVE-2026-56403
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/147c8f36d6277d5c6011c098370a8362aed47b15]
|
||||
|
||||
Backport Changes:
|
||||
- Add stdint.h and convert count and numBytes to size_t because
|
||||
Scarthgap 2.6.4 lacks these upstream prerequisites.
|
||||
|
||||
(cherry picked from commit 147c8f36d6277d5c6011c098370a8362aed47b15)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/xmlwf/xmlwf.c | 10 ++++++++--
|
||||
1 file changed, 8 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/expat/xmlwf/xmlwf.c b/expat/xmlwf/xmlwf.c
|
||||
index fd4fc3f8..7bbdb303 100644
|
||||
--- a/expat/xmlwf/xmlwf.c
|
||||
+++ b/expat/xmlwf/xmlwf.c
|
||||
@@ -45,6 +45,7 @@
|
||||
|
||||
#include <assert.h>
|
||||
#include <stdio.h>
|
||||
+#include <stdint.h>
|
||||
#include <stdlib.h>
|
||||
#include <stddef.h>
|
||||
#include <string.h>
|
||||
@@ -304,13 +305,18 @@ processingInstruction(void *userData, const XML_Char *target,
|
||||
static XML_Char *
|
||||
xcsdup(const XML_Char *s) {
|
||||
XML_Char *result;
|
||||
- int count = 0;
|
||||
- int numBytes;
|
||||
+ size_t count = 0;
|
||||
+ size_t numBytes;
|
||||
|
||||
/* Get the length of the string, including terminator */
|
||||
while (s[count++] != 0) {
|
||||
/* Do nothing */
|
||||
}
|
||||
+
|
||||
+ // Detect and prevent integer overflow
|
||||
+ if (count > SIZE_MAX / sizeof(XML_Char))
|
||||
+ return NULL;
|
||||
+
|
||||
numBytes = count * sizeof(XML_Char);
|
||||
result = malloc(numBytes);
|
||||
if (result == NULL)
|
||||
45
meta/recipes-core/expat/expat/CVE-2026-56404.patch
Normal file
45
meta/recipes-core/expat/expat/CVE-2026-56404.patch
Normal file
@@ -0,0 +1,45 @@
|
||||
From d8e09a54fa9214e64d8e73057ca6918d08857022 Mon Sep 17 00:00:00 2001
|
||||
From: netliomax25-code <netliomax25@gmail.com>
|
||||
Date: Thu, 28 May 2026 12:44:11 +0530
|
||||
Subject: [PATCH 04/17] lib: protect function addBinding from signed integer
|
||||
overflow
|
||||
|
||||
CVE: CVE-2026-56404
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/babfc48090977cbf7be24b2c48f6053dca75c164]
|
||||
|
||||
(cherry picked from commit babfc48090977cbf7be24b2c48f6053dca75c164)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/lib/xmlparse.c | 11 ++++++++++-
|
||||
1 file changed, 10 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
|
||||
index 12bbe23e..9d21e136 100644
|
||||
--- a/expat/lib/xmlparse.c
|
||||
+++ b/expat/lib/xmlparse.c
|
||||
@@ -4456,6 +4456,10 @@ addBinding(XML_Parser parser, PREFIX *prefix, const ATTRIBUTE_ID *attId,
|
||||
}
|
||||
|
||||
for (len = 0; uri[len]; len++) {
|
||||
+ /* Detect and prevent signed integer overflow */
|
||||
+ if (len == INT_MAX) {
|
||||
+ return XML_ERROR_NO_MEMORY;
|
||||
+ }
|
||||
if (isXML && (len > xmlLen || uri[len] != xmlNamespace[len]))
|
||||
isXML = XML_FALSE;
|
||||
|
||||
@@ -4496,8 +4500,13 @@ addBinding(XML_Parser parser, PREFIX *prefix, const ATTRIBUTE_ID *attId,
|
||||
if (isXMLNS)
|
||||
return XML_ERROR_RESERVED_NAMESPACE_URI;
|
||||
|
||||
- if (parser->m_namespaceSeparator)
|
||||
+ if (parser->m_namespaceSeparator) {
|
||||
+ /* Detect and prevent signed integer overflow */
|
||||
+ if (len == INT_MAX) {
|
||||
+ return XML_ERROR_NO_MEMORY;
|
||||
+ }
|
||||
len++;
|
||||
+ }
|
||||
if (parser->m_freeBindingList) {
|
||||
b = parser->m_freeBindingList;
|
||||
if (len > b->uriAlloc) {
|
||||
30
meta/recipes-core/expat/expat/CVE-2026-56405.patch
Normal file
30
meta/recipes-core/expat/expat/CVE-2026-56405.patch
Normal file
@@ -0,0 +1,30 @@
|
||||
From 49ba5bdafa7aaee9b77a32ffaa798e625bd46e73 Mon Sep 17 00:00:00 2001
|
||||
From: netliomax25-code <netliomax25@gmail.com>
|
||||
Date: Fri, 29 May 2026 11:45:17 +0530
|
||||
Subject: [PATCH 05/17] lib: Protect function getAttributeId from signed
|
||||
integer overflow
|
||||
|
||||
CVE: CVE-2026-56405
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/2c6c42d33689f6b266a5267b639e03cde17e53c0]
|
||||
|
||||
(cherry picked from commit 2c6c42d33689f6b266a5267b639e03cde17e53c0)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/lib/xmlparse.c | 4 ++++
|
||||
1 file changed, 4 insertions(+)
|
||||
|
||||
diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
|
||||
index 9d21e136..80ad0811 100644
|
||||
--- a/expat/lib/xmlparse.c
|
||||
+++ b/expat/lib/xmlparse.c
|
||||
@@ -7312,6 +7312,10 @@ getAttributeId(XML_Parser parser, const ENCODING *enc, const char *start,
|
||||
} else {
|
||||
int i;
|
||||
for (i = 0; name[i]; i++) {
|
||||
+ /* Detect and prevent signed integer overflow */
|
||||
+ if (i == INT_MAX) {
|
||||
+ return NULL;
|
||||
+ }
|
||||
/* attributes without prefix are *not* in the default namespace */
|
||||
if (name[i] == XML_T(ASCII_COLON)) {
|
||||
int j;
|
||||
59
meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch
Normal file
59
meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch
Normal file
@@ -0,0 +1,59 @@
|
||||
From 9aafa47798332618f08af046c3471de1f3a9e031 Mon Sep 17 00:00:00 2001
|
||||
From: Matthew Fernandez <matthew.fernandez@gmail.com>
|
||||
Date: Wed, 27 May 2026 17:01:44 -0700
|
||||
Subject: [PATCH 08/17] lib: Make `XML_Index` overflow check more intuitive
|
||||
|
||||
In fixing a bug, 7e5b71b748491b6e459e5c9a1d090820f94544d8 introduced a magic number `2` in this code that made it difficult to understand the rationale for this overflow check without reading the commit log. This change introduces some more readable constants to use in these situations.
|
||||
|
||||
CVE: CVE-2026-56406
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/252ff1a307b1490ce0f430632791e7e52d7e43fd]
|
||||
|
||||
Backport Changes:
|
||||
- Adapt include context for Scarthgap 2.6.4 and expose SIZE_MAX in
|
||||
the existing stdint.h comment.
|
||||
|
||||
(cherry picked from commit 252ff1a307b1490ce0f430632791e7e52d7e43fd)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/lib/xmlparse.c | 12 +++++++++---
|
||||
1 file changed, 9 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
|
||||
index 80ad0811..5bf706b0 100644
|
||||
--- a/expat/lib/xmlparse.c
|
||||
+++ b/expat/lib/xmlparse.c
|
||||
@@ -97,10 +97,10 @@
|
||||
#include <stddef.h>
|
||||
#include <string.h> /* memset(), memcpy() */
|
||||
#include <assert.h>
|
||||
-#include <limits.h> /* UINT_MAX */
|
||||
+#include <limits.h> /* INT_MAX, LLONG_MAX, LONG_MAX, UINT_MAX */
|
||||
#include <stdio.h> /* fprintf */
|
||||
#include <stdlib.h> /* getenv, rand_s */
|
||||
-#include <stdint.h> /* uintptr_t */
|
||||
+#include <stdint.h> /* SIZE_MAX, uintptr_t */
|
||||
#include <math.h> /* isnan */
|
||||
|
||||
#ifdef _WIN32
|
||||
@@ -211,6 +211,12 @@ typedef char ICHAR;
|
||||
|
||||
#endif
|
||||
|
||||
+#ifdef XML_LARGE_SIZE
|
||||
+# define XML_INDEX_MAX LLONG_MAX
|
||||
+#else
|
||||
+# define XML_INDEX_MAX LONG_MAX
|
||||
+#endif
|
||||
+
|
||||
/* Round up n to be a multiple of sz, where sz is a power of 2. */
|
||||
#define ROUND_UP(n, sz) (((n) + ((sz) - 1)) & ~((sz) - 1))
|
||||
|
||||
@@ -2360,7 +2366,7 @@ XML_Parse(XML_Parser parser, const char *s, int len, int isFinal) {
|
||||
int nLeftOver;
|
||||
enum XML_Status result;
|
||||
/* Detect overflow (a+b > MAX <==> b > MAX-a) */
|
||||
- if ((XML_Size)len > ((XML_Size)-1) / 2 - parser->m_parseEndByteIndex) {
|
||||
+ if (len > XML_INDEX_MAX - parser->m_parseEndByteIndex) {
|
||||
parser->m_errorCode = XML_ERROR_NO_MEMORY;
|
||||
parser->m_eventPtr = parser->m_eventEndPtr = NULL;
|
||||
parser->m_processor = errorProcessor;
|
||||
34
meta/recipes-core/expat/expat/CVE-2026-56406.patch
Normal file
34
meta/recipes-core/expat/expat/CVE-2026-56406.patch
Normal file
@@ -0,0 +1,34 @@
|
||||
From 5db699faa6af1c66e96abec5dbd1908efd64ef70 Mon Sep 17 00:00:00 2001
|
||||
From: Sebastian Pipping <sebastian@pipping.org>
|
||||
Date: Sun, 31 May 2026 15:18:58 +0200
|
||||
Subject: [PATCH 09/17] lib: Copy overflow check from `XML_Parse` to
|
||||
`XML_ParseBuffer`
|
||||
|
||||
CVE: CVE-2026-56406
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/99d8454fdf900a6d00c2a52748e6c0eeb507574d]
|
||||
|
||||
(cherry picked from commit 99d8454fdf900a6d00c2a52748e6c0eeb507574d)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/lib/xmlparse.c | 8 ++++++++
|
||||
1 file changed, 8 insertions(+)
|
||||
|
||||
diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
|
||||
index 5bf706b0..9f07b860 100644
|
||||
--- a/expat/lib/xmlparse.c
|
||||
+++ b/expat/lib/xmlparse.c
|
||||
@@ -2483,6 +2483,14 @@ XML_ParseBuffer(XML_Parser parser, int len, int isFinal) {
|
||||
parser->m_parsingStatus.parsing = XML_PARSING;
|
||||
}
|
||||
|
||||
+ // Detect and avoid integer overflow
|
||||
+ if (len > XML_INDEX_MAX - parser->m_parseEndByteIndex) {
|
||||
+ parser->m_errorCode = XML_ERROR_NO_MEMORY;
|
||||
+ parser->m_eventPtr = parser->m_eventEndPtr = NULL;
|
||||
+ parser->m_processor = errorProcessor;
|
||||
+ return XML_STATUS_ERROR;
|
||||
+ }
|
||||
+
|
||||
start = parser->m_bufferPtr;
|
||||
parser->m_positionPtr = start;
|
||||
parser->m_bufferEnd += len;
|
||||
41
meta/recipes-core/expat/expat/CVE-2026-56407.patch
Normal file
41
meta/recipes-core/expat/expat/CVE-2026-56407.patch
Normal file
@@ -0,0 +1,41 @@
|
||||
From d1cd2bd7da8ed830e9432660616e9b4831df959a Mon Sep 17 00:00:00 2001
|
||||
From: netliomax25-code <netliomax25@gmail.com>
|
||||
Date: Tue, 2 Jun 2026 11:59:01 +0530
|
||||
Subject: [PATCH 12/17] cap entity textLen against signed integer overflow
|
||||
|
||||
CVE: CVE-2026-56407
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13]
|
||||
|
||||
(cherry picked from commit 30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/lib/xmlparse.c | 9 +++++++++
|
||||
1 file changed, 9 insertions(+)
|
||||
|
||||
diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
|
||||
index 9f07b860..8439dc0e 100644
|
||||
--- a/expat/lib/xmlparse.c
|
||||
+++ b/expat/lib/xmlparse.c
|
||||
@@ -5655,6 +5655,10 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end,
|
||||
parser, enc, s + enc->minBytesPerChar, next - enc->minBytesPerChar,
|
||||
XML_ACCOUNT_NONE);
|
||||
if (parser->m_declEntity) {
|
||||
+ /* Detect and prevent signed integer overflow */
|
||||
+ if ((size_t)poolLength(&dtd->entityValuePool) > (size_t)INT_MAX) {
|
||||
+ return XML_ERROR_NO_MEMORY;
|
||||
+ }
|
||||
parser->m_declEntity->textPtr = poolStart(&dtd->entityValuePool);
|
||||
parser->m_declEntity->textLen
|
||||
= (int)(poolLength(&dtd->entityValuePool));
|
||||
@@ -7076,6 +7080,11 @@ storeSelfEntityValue(XML_Parser parser, ENTITY *entity) {
|
||||
return XML_ERROR_NO_MEMORY;
|
||||
}
|
||||
|
||||
+ /* Detect and prevent signed integer overflow */
|
||||
+ if ((size_t)poolLength(pool) > (size_t)INT_MAX) {
|
||||
+ poolDiscard(pool);
|
||||
+ return XML_ERROR_NO_MEMORY;
|
||||
+ }
|
||||
entity->textPtr = poolStart(pool);
|
||||
entity->textLen = (int)(poolLength(pool));
|
||||
poolFinish(pool);
|
||||
29
meta/recipes-core/expat/expat/CVE-2026-56408.patch
Normal file
29
meta/recipes-core/expat/expat/CVE-2026-56408.patch
Normal file
@@ -0,0 +1,29 @@
|
||||
From c1ad5610cf060c6374d8f8d3b39163edd7053321 Mon Sep 17 00:00:00 2001
|
||||
From: Sebastian Pipping <sebastian@pipping.org>
|
||||
Date: Thu, 23 Apr 2026 10:31:45 +0200
|
||||
Subject: [PATCH 03/17] lib: Waterproof `copyString` from integer overflow
|
||||
|
||||
CVE: CVE-2026-56408
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/16e2efd867ea8567ffa012210b52ef5918e20817]
|
||||
|
||||
(cherry picked from commit 16e2efd867ea8567ffa012210b52ef5918e20817)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/lib/xmlparse.c | 4 ++++
|
||||
1 file changed, 4 insertions(+)
|
||||
|
||||
diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
|
||||
index df92a3ca..12bbe23e 100644
|
||||
--- a/expat/lib/xmlparse.c
|
||||
+++ b/expat/lib/xmlparse.c
|
||||
@@ -8489,6 +8489,10 @@ copyString(const XML_Char *s, XML_Parser parser) {
|
||||
/* Include the terminator */
|
||||
charsRequired++;
|
||||
|
||||
+ /* Detect and prevent integer overflow */
|
||||
+ if (charsRequired > SIZE_MAX / sizeof(XML_Char))
|
||||
+ return NULL;
|
||||
+
|
||||
/* Now allocate space for the copy */
|
||||
result = MALLOC(parser, charsRequired * sizeof(XML_Char));
|
||||
if (result == NULL)
|
||||
51
meta/recipes-core/expat/expat/CVE-2026-56409.patch
Normal file
51
meta/recipes-core/expat/expat/CVE-2026-56409.patch
Normal file
@@ -0,0 +1,51 @@
|
||||
From 174ce18f2a283be634d830a5259bd07142635fe8 Mon Sep 17 00:00:00 2001
|
||||
From: netliomax25-code <netliomax25@gmail.com>
|
||||
Date: Mon, 1 Jun 2026 11:53:19 +0530
|
||||
Subject: [PATCH 10/17] xmlwf: protect output path join from integer overflow
|
||||
|
||||
CVE: CVE-2026-56409
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e]
|
||||
|
||||
Backport Changes:
|
||||
- Adapt the allocation hunk to the explicit XML_Char cast used by
|
||||
Scarthgap 2.6.4; overflow checks are unchanged.
|
||||
|
||||
(cherry picked from commit 61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/xmlwf/xmlwf.c | 22 ++++++++++++++++++++--
|
||||
1 file changed, 20 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/expat/xmlwf/xmlwf.c b/expat/xmlwf/xmlwf.c
|
||||
index 7bbdb303..bd5f68a4 100644
|
||||
--- a/expat/xmlwf/xmlwf.c
|
||||
+++ b/expat/xmlwf/xmlwf.c
|
||||
@@ -1240,8 +1240,26 @@ tmain(int argc, XML_Char **argv) {
|
||||
}
|
||||
#endif
|
||||
}
|
||||
- outName = (XML_Char *)malloc((tcslen(outputDir) + tcslen(file) + 2)
|
||||
- * sizeof(XML_Char));
|
||||
+ const size_t outputDirLen = tcslen(outputDir);
|
||||
+ const size_t fileLen = tcslen(file);
|
||||
+
|
||||
+ /* Detect and prevent integer overflow in the addition (without
|
||||
+ risking underflow) and the multiplication, mirroring the guards
|
||||
+ in xcsdup() and resolveSystemId() */
|
||||
+ if (outputDirLen > SIZE_MAX - fileLen
|
||||
+ || outputDirLen > SIZE_MAX - fileLen - 2) {
|
||||
+ tperror(T("Could not allocate memory"));
|
||||
+ exit(XMLWF_EXIT_INTERNAL_ERROR);
|
||||
+ }
|
||||
+
|
||||
+ const size_t charsRequired = outputDirLen + fileLen + 2;
|
||||
+
|
||||
+ if (charsRequired > SIZE_MAX / sizeof(XML_Char)) {
|
||||
+ tperror(T("Could not allocate memory"));
|
||||
+ exit(XMLWF_EXIT_INTERNAL_ERROR);
|
||||
+ }
|
||||
+
|
||||
+ outName = malloc(charsRequired * sizeof(XML_Char));
|
||||
if (! outName) {
|
||||
tperror(T("Could not allocate memory"));
|
||||
exit(XMLWF_EXIT_INTERNAL_ERROR);
|
||||
46
meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch
Normal file
46
meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch
Normal file
@@ -0,0 +1,46 @@
|
||||
From b454931c42290c9f0faf2a01f9634d82db636bac Mon Sep 17 00:00:00 2001
|
||||
From: netliomax25-code <netliomax25@gmail.com>
|
||||
Date: Fri, 29 May 2026 17:51:25 +0530
|
||||
Subject: [PATCH 06/17] xmlwf: protect resolveSystemId from integer overflow
|
||||
|
||||
CVE: CVE-2026-56410
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/deeb97f7c88d17a16b0ea2521a13733abc283347]
|
||||
|
||||
Backport Changes:
|
||||
- Adapt the allocation hunk to Scarthgap 2.6.4's explicit cast and
|
||||
include stdint.h so SIZE_MAX is available.
|
||||
|
||||
(cherry picked from commit deeb97f7c88d17a16b0ea2521a13733abc283347)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/xmlwf/xmlfile.c | 10 ++++++++--
|
||||
1 file changed, 8 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/expat/xmlwf/xmlfile.c b/expat/xmlwf/xmlfile.c
|
||||
index 9c4f7f8d..ad691b12 100644
|
||||
--- a/expat/xmlwf/xmlfile.c
|
||||
+++ b/expat/xmlwf/xmlfile.c
|
||||
@@ -41,6 +41,7 @@
|
||||
#include "expat_config.h"
|
||||
|
||||
#include <stdio.h>
|
||||
+#include <stdint.h>
|
||||
#include <stdlib.h>
|
||||
#include <stddef.h>
|
||||
#include <string.h>
|
||||
@@ -130,8 +131,13 @@ resolveSystemId(const XML_Char *base, const XML_Char *systemId,
|
||||
#endif
|
||||
)
|
||||
return systemId;
|
||||
- *toFree = (XML_Char *)malloc((tcslen(base) + tcslen(systemId) + 2)
|
||||
- * sizeof(XML_Char));
|
||||
+ const size_t charsRequired = tcslen(base) + tcslen(systemId) + 2;
|
||||
+
|
||||
+ /* Detect and prevent integer overflow */
|
||||
+ if (charsRequired > SIZE_MAX / sizeof(XML_Char))
|
||||
+ return systemId;
|
||||
+
|
||||
+ *toFree = malloc(charsRequired * sizeof(XML_Char));
|
||||
if (! *toFree)
|
||||
return systemId;
|
||||
tcscpy(*toFree, base);
|
||||
39
meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch
Normal file
39
meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch
Normal file
@@ -0,0 +1,39 @@
|
||||
From 7e6230212ddc4ea74115218fdbe5717e8e1c0f2b Mon Sep 17 00:00:00 2001
|
||||
From: netliomax25-code <netliomax25@gmail.com>
|
||||
Date: Sat, 30 May 2026 11:28:51 +0530
|
||||
Subject: [PATCH 07/17] xmlwf: guard each operator in resolveSystemId length
|
||||
sum
|
||||
|
||||
CVE: CVE-2026-56410
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea]
|
||||
|
||||
(cherry picked from commit cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/xmlwf/xmlfile.c | 12 ++++++++++--
|
||||
1 file changed, 10 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/expat/xmlwf/xmlfile.c b/expat/xmlwf/xmlfile.c
|
||||
index ad691b12..4d2e3220 100644
|
||||
--- a/expat/xmlwf/xmlfile.c
|
||||
+++ b/expat/xmlwf/xmlfile.c
|
||||
@@ -131,9 +131,17 @@ resolveSystemId(const XML_Char *base, const XML_Char *systemId,
|
||||
#endif
|
||||
)
|
||||
return systemId;
|
||||
- const size_t charsRequired = tcslen(base) + tcslen(systemId) + 2;
|
||||
+ const size_t baseLen = tcslen(base);
|
||||
+ const size_t systemIdLen = tcslen(systemId);
|
||||
|
||||
- /* Detect and prevent integer overflow */
|
||||
+ /* Detect and prevent integer overflow in the addition (without risking
|
||||
+ underflow) */
|
||||
+ if (baseLen > SIZE_MAX - systemIdLen || baseLen > SIZE_MAX - systemIdLen - 2)
|
||||
+ return systemId;
|
||||
+
|
||||
+ const size_t charsRequired = baseLen + systemIdLen + 2;
|
||||
+
|
||||
+ /* Detect and prevent integer overflow in the multiplication */
|
||||
if (charsRequired > SIZE_MAX / sizeof(XML_Char))
|
||||
return systemId;
|
||||
|
||||
50
meta/recipes-core/expat/expat/CVE-2026-56411.patch
Normal file
50
meta/recipes-core/expat/expat/CVE-2026-56411.patch
Normal file
@@ -0,0 +1,50 @@
|
||||
From 5e696e78f8c4a709c4f774973b142e57090c4364 Mon Sep 17 00:00:00 2001
|
||||
From: netliomax25-code <netliomax25@gmail.com>
|
||||
Date: Tue, 2 Jun 2026 13:13:34 +0530
|
||||
Subject: [PATCH 11/17] xmlwf: protect notation list allocation from integer
|
||||
overflow
|
||||
|
||||
CVE: CVE-2026-56411
|
||||
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/528a4e5017e1bd3b48b689fd0c131df940ae3ea5]
|
||||
|
||||
Backport Changes:
|
||||
- Use Scarthgap 2.6.4 freeNotations cleanup and return directly
|
||||
because the newer shared cleanUp label is absent.
|
||||
|
||||
(cherry picked from commit 528a4e5017e1bd3b48b689fd0c131df940ae3ea5)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
expat/xmlwf/xmlwf.c | 12 ++++++++++--
|
||||
1 file changed, 10 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/expat/xmlwf/xmlwf.c b/expat/xmlwf/xmlwf.c
|
||||
index bd5f68a4..6a3d31b7 100644
|
||||
--- a/expat/xmlwf/xmlwf.c
|
||||
+++ b/expat/xmlwf/xmlwf.c
|
||||
@@ -387,9 +387,9 @@ static void XMLCALL
|
||||
endDoctypeDecl(void *userData) {
|
||||
XmlwfUserData *data = (XmlwfUserData *)userData;
|
||||
NotationList **notations;
|
||||
- int notationCount = 0;
|
||||
+ size_t notationCount = 0;
|
||||
NotationList *p;
|
||||
- int i;
|
||||
+ size_t i;
|
||||
|
||||
/* How many notations do we have? */
|
||||
for (p = data->notationListHead; p != NULL; p = p->next)
|
||||
@@ -401,6 +401,14 @@ endDoctypeDecl(void *userData) {
|
||||
return;
|
||||
}
|
||||
|
||||
+ /* Detect and prevent integer overflow in the multiplication, mirroring
|
||||
+ the guards in xcsdup() and resolveSystemId() */
|
||||
+ if (notationCount > SIZE_MAX / sizeof(NotationList *)) {
|
||||
+ fprintf(stderr, "Unable to sort notations");
|
||||
+ freeNotations(data);
|
||||
+ return;
|
||||
+ }
|
||||
+
|
||||
notations = malloc(notationCount * sizeof(NotationList *));
|
||||
if (notations == NULL) {
|
||||
fprintf(stderr, "Unable to sort notations");
|
||||
@@ -51,6 +51,33 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \
|
||||
file://CVE-2026-32777-02.patch \
|
||||
file://CVE-2026-32778-01.patch \
|
||||
file://CVE-2026-32778-02.patch \
|
||||
file://CVE-2026-41080-01.patch \
|
||||
file://CVE-2026-41080-02.patch \
|
||||
file://CVE-2026-41080-03.patch \
|
||||
file://CVE-2026-45186-01.patch \
|
||||
file://CVE-2026-45186-02.patch \
|
||||
file://CVE-2026-45186-03.patch \
|
||||
file://CVE-2026-45186-04.patch \
|
||||
file://CVE-2026-45186-05.patch \
|
||||
file://CVE-2026-45186-06.patch \
|
||||
file://CVE-2026-45186-07.patch \
|
||||
file://CVE-2026-56403_p1.patch;striplevel=2 \
|
||||
file://CVE-2026-56403_p2.patch;striplevel=2 \
|
||||
file://CVE-2026-56408.patch;striplevel=2 \
|
||||
file://CVE-2026-56404.patch;striplevel=2 \
|
||||
file://CVE-2026-56405.patch;striplevel=2 \
|
||||
file://CVE-2026-56410_p1.patch;striplevel=2 \
|
||||
file://CVE-2026-56410_p2.patch;striplevel=2 \
|
||||
file://CVE-2026-56406-dependent.patch;striplevel=2 \
|
||||
file://CVE-2026-56406.patch;striplevel=2 \
|
||||
file://CVE-2026-56409.patch;striplevel=2 \
|
||||
file://CVE-2026-56411.patch;striplevel=2 \
|
||||
file://CVE-2026-56407.patch;striplevel=2 \
|
||||
file://CVE-2026-56132_p1.patch;striplevel=2 \
|
||||
file://CVE-2026-56132_p2.patch;striplevel=2 \
|
||||
file://CVE-2026-56132_p3.patch;striplevel=2 \
|
||||
file://CVE-2026-56132_p4.patch;striplevel=2 \
|
||||
file://CVE-2026-56132_p5.patch;striplevel=2 \
|
||||
"
|
||||
|
||||
GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/"
|
||||
|
||||
113
meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch
Normal file
113
meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch
Normal file
@@ -0,0 +1,113 @@
|
||||
From 333f164f00fb874e3c670ce70d2a2a3667b9ebf9 Mon Sep 17 00:00:00 2001
|
||||
From: Philip Withnall <pwithnall@gnome.org>
|
||||
Date: Sun, 29 Mar 2026 19:10:41 +0100
|
||||
Subject: [PATCH] gvariant: Fix an off-by-one error in an offset comparison
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
This allows a single byte out-of-bounds read off the end of the
|
||||
(potentially untrusted) byte array backing a `GVariant` when it’s
|
||||
being checked for normal form.
|
||||
|
||||
I can’t see how this could practically be exploited, but it’s certainly
|
||||
a security bug as the `GVariant` normal form checking code is supposed
|
||||
to be robust to malicious inputs.
|
||||
|
||||
Spotted by linhlhq as #YWH-PGM9867-190, and fix and reproducer provided
|
||||
by them too, thanks. Confirmed and turned into a unit test by me.
|
||||
|
||||
Fixes: #3915
|
||||
|
||||
CVE: CVE-2026-58010
|
||||
Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/aa1cb87d56111ef989811e824f0ac77484cc997f]
|
||||
|
||||
Signed-off-by: Philip Withnall <pwithnall@gnome.org>
|
||||
(cherry picked from commit aa1cb87d56111ef989811e824f0ac77484cc997f)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
glib/gvariant-serialiser.c | 2 +-
|
||||
glib/tests/gvariant.c | 48 ++++++++++++++++++++++++++++++++++++++
|
||||
2 files changed, 49 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/glib/gvariant-serialiser.c b/glib/gvariant-serialiser.c
|
||||
index 4e4a73ad1..99a1d3fbd 100644
|
||||
--- a/glib/gvariant-serialiser.c
|
||||
+++ b/glib/gvariant-serialiser.c
|
||||
@@ -1247,7 +1247,7 @@ gvs_tuple_is_normal (GVariantSerialised value)
|
||||
|
||||
while (offset & alignment)
|
||||
{
|
||||
- if (offset > value.size || value.data[offset] != '\0')
|
||||
+ if (offset >= value.size || value.data[offset] != '\0')
|
||||
return FALSE;
|
||||
offset++;
|
||||
}
|
||||
diff --git a/glib/tests/gvariant.c b/glib/tests/gvariant.c
|
||||
index c8f13360c..55e2cee00 100644
|
||||
--- a/glib/tests/gvariant.c
|
||||
+++ b/glib/tests/gvariant.c
|
||||
@@ -5637,6 +5637,52 @@ test_normal_checking_tuple_offsets5 (void)
|
||||
g_variant_unref (variant);
|
||||
}
|
||||
|
||||
+/* This is a regression test that looping over the padding bytes in a short
|
||||
+ * (non-normal) tuple doesn’t overflow the input data.
|
||||
+ *
|
||||
+ * See https://gitlab.gnome.org/GNOME/glib/-/issues/3915 */
|
||||
+static void
|
||||
+test_normal_checking_tuple_offsets6 (void)
|
||||
+{
|
||||
+ /*
|
||||
+ * Type: (ynqiuxthdsog) — 12 members, first member 'y' (byte) has
|
||||
+ * alignment 0, second 'n' (int16) has alignment 1.
|
||||
+ * With 1 byte of data (0x28), after reading the first byte member,
|
||||
+ * offset=1, alignment check for 'n' requires offset to be even,
|
||||
+ * so the while loop checks value.data[1] — but size is only 1.
|
||||
+ *
|
||||
+ * Use heap allocation via GBytes so ASan reports heap-buffer-overflow.
|
||||
+ */
|
||||
+ guint8 *heap_data = NULL;
|
||||
+ GBytes *bytes = NULL;
|
||||
+ const GVariantType *data_type = G_VARIANT_TYPE ("(ynqiuxthdsog)");
|
||||
+ GVariant *variant = NULL;
|
||||
+ GVariant *normal_variant = NULL;
|
||||
+ GVariant *expected = NULL;
|
||||
+
|
||||
+ g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/issues/3915");
|
||||
+
|
||||
+ heap_data = g_malloc (1);
|
||||
+ heap_data[0] = 0x28;
|
||||
+ bytes = g_bytes_new_take (heap_data, 1);
|
||||
+
|
||||
+ variant = g_variant_new_from_bytes (data_type, bytes, FALSE);
|
||||
+ g_assert_nonnull (variant);
|
||||
+
|
||||
+ g_assert_false (g_variant_is_normal_form (variant));
|
||||
+
|
||||
+ normal_variant = g_variant_get_normal_form (variant);
|
||||
+ g_assert_nonnull (normal_variant);
|
||||
+
|
||||
+ expected = g_variant_new_parsed ("(byte 0x28, int16 0, uint16 0, 0, uint32 0, int64 0, uint64 0, handle 0, 0.0, '', objectpath '/', signature '')");
|
||||
+ g_assert_cmpvariant (expected, variant);
|
||||
+ g_assert_cmpvariant (expected, normal_variant);
|
||||
+
|
||||
+ g_variant_unref (expected);
|
||||
+ g_variant_unref (normal_variant);
|
||||
+ g_variant_unref (variant);
|
||||
+}
|
||||
+
|
||||
/* Test that an otherwise-valid serialised GVariant is considered non-normal if
|
||||
* its offset table entries are too wide.
|
||||
*
|
||||
@@ -5890,6 +5936,8 @@ main (int argc, char **argv)
|
||||
test_normal_checking_tuple_offsets4);
|
||||
g_test_add_func ("/gvariant/normal-checking/tuple-offsets5",
|
||||
test_normal_checking_tuple_offsets5);
|
||||
+ g_test_add_func ("/gvariant/normal-checking/tuple-offsets6",
|
||||
+ test_normal_checking_tuple_offsets6);
|
||||
g_test_add_func ("/gvariant/normal-checking/tuple-offsets/minimal-sized",
|
||||
test_normal_checking_tuple_offsets_minimal_sized);
|
||||
g_test_add_func ("/gvariant/normal-checking/empty-object-path",
|
||||
--
|
||||
2.35.6
|
||||
78
meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch
Normal file
78
meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch
Normal file
@@ -0,0 +1,78 @@
|
||||
From 371dbccb6b9a9a42b93c4b371214b159e7e94792 Mon Sep 17 00:00:00 2001
|
||||
From: Philip Withnall <pwithnall@gnome.org>
|
||||
Date: Sun, 29 Mar 2026 23:46:17 +0100
|
||||
Subject: [PATCH] gdatetime: Add missing range validation to
|
||||
g_date_time_add_full()
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Otherwise it’s possible to create a non-`NULL` but invalid `GDateTime`,
|
||||
which breaks all kinds of internal assumptions.
|
||||
|
||||
Spotted by linhlhq as #YWH-PGM9867-191. Thanks to them for providing a
|
||||
suggested fix and a test case, which I have adapted and validated.
|
||||
|
||||
Fixes: #3917
|
||||
|
||||
CVE: CVE-2026-58011
|
||||
Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/ae27363f025ffc131e2d75ee88a5cd8320dffe3b]
|
||||
|
||||
Backport Changes:
|
||||
- Used the target branch's existing literal day bounds because it does
|
||||
not have upstream's MIN_DAYS/MAX_DAYS helper macros.
|
||||
|
||||
Signed-off-by: Philip Withnall <pwithnall@gnome.org>
|
||||
(cherry picked from commit ae27363f025ffc131e2d75ee88a5cd8320dffe3b)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
glib/gdatetime.c | 4 +++-
|
||||
glib/tests/gdatetime.c | 18 ++++++++++++++++++
|
||||
2 files changed, 21 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/glib/gdatetime.c b/glib/gdatetime.c
|
||||
index 2640e3b24..73eea643b 100644
|
||||
--- a/glib/gdatetime.c
|
||||
+++ b/glib/gdatetime.c
|
||||
@@ -2024,7 +2024,9 @@ g_date_time_add_full (GDateTime *datetime,
|
||||
new->days = full_time / USEC_PER_DAY;
|
||||
new->usec = full_time % USEC_PER_DAY;
|
||||
|
||||
- /* XXX validate */
|
||||
+ /* Validate it’s still in the range 0001-01-01 to 9999-12-31 */
|
||||
+ if (new->days < 1 || new->days > 3652059)
|
||||
+ g_clear_pointer (&new, g_date_time_unref);
|
||||
|
||||
return new;
|
||||
}
|
||||
diff --git a/glib/tests/gdatetime.c b/glib/tests/gdatetime.c
|
||||
index 49390c900..527d61a11 100644
|
||||
--- a/glib/tests/gdatetime.c
|
||||
+++ b/glib/tests/gdatetime.c
|
||||
@@ -1117,6 +1117,24 @@ test_GDateTime_add_full (void)
|
||||
TEST_ADD_FULL (2010, 8, 25, 22, 45, 0,
|
||||
0, 1, 6, 1, 25, 0,
|
||||
2010, 10, 2, 0, 10, 0);
|
||||
+
|
||||
+#define TEST_ADD_FULL_ERROR(y,m,d,h,mi,s,ay,am,ad,ah,ami,as) G_STMT_START { \
|
||||
+ GDateTime *dt; \
|
||||
+ dt = g_date_time_new_utc (y, m, d, h, mi, s); \
|
||||
+ g_assert_null (g_date_time_add_full (dt, ay, am, ad, ah, ami, as)); \
|
||||
+ g_date_time_unref (dt); \
|
||||
+} G_STMT_END
|
||||
+
|
||||
+ TEST_ADD_FULL_ERROR ( 1, 12, 1, 0, 0, 0,
|
||||
+ -1, 0, 0, 0, 0, 0);
|
||||
+ TEST_ADD_FULL_ERROR ( 1, 12, 1, 0, 0, 0,
|
||||
+ 10000, 0, 0, 0, 0, 0);
|
||||
+ TEST_ADD_FULL_ERROR ( 9999, 12, 1, 0, 0, 0,
|
||||
+ -10000, 0, 0, 0, 0, 0);
|
||||
+ TEST_ADD_FULL_ERROR ( 1, 12, 1, 0, 0, 0,
|
||||
+ 0, 0, 3660001, 0, 0, 0);
|
||||
+ TEST_ADD_FULL_ERROR ( 9999, 12, 1, 0, 0, 0,
|
||||
+ 0, 0, -3660001, 0, 0, 0);
|
||||
}
|
||||
|
||||
static void
|
||||
--
|
||||
2.35.6
|
||||
228
meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch
Normal file
228
meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch
Normal file
@@ -0,0 +1,228 @@
|
||||
From 74564fefcec22fc1efc187c36aa1fb8dcfe34454 Mon Sep 17 00:00:00 2001
|
||||
From: Philip Withnall <pwithnall@gnome.org>
|
||||
Date: Tue, 31 Mar 2026 16:13:57 +0100
|
||||
Subject: [PATCH] gregex: Fix case changing substitutions with G_REGEX_RAW
|
||||
|
||||
In `G_REGEX_RAW` mode, the input string is treated as a byte array
|
||||
(basically ASCII) rather than a unichar array. Accordingly, the case
|
||||
changing code for substitutions needs to operate on bytes with
|
||||
`G_REGEX_RAW`, rather than operating on unichars.
|
||||
|
||||
This fixes a potential buffer overflow when trying to do a case change
|
||||
on a match of a set of bytes which are a truncated multi-byte UTF-8
|
||||
encoding at the end of the input buffer.
|
||||
|
||||
Spotted by linhlhq as #YWH-PGM9867-193. I adapted their reproducer as
|
||||
the unit test, but implemented the fix in `gregex.c` independently.
|
||||
|
||||
Fixes: #3918
|
||||
|
||||
CVE: CVE-2026-58012
|
||||
Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/d337aabd24ee2b8ac2a690dba3ccf26aa70e638f]
|
||||
|
||||
Signed-off-by: Philip Withnall <pwithnall@gnome.org>
|
||||
(cherry picked from commit d337aabd24ee2b8ac2a690dba3ccf26aa70e638f)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
glib/gregex.c | 59 ++++++++++++++++++++++++++++++++++------------
|
||||
glib/tests/regex.c | 53 +++++++++++++++++++++++++++++++++++++++++
|
||||
2 files changed, 97 insertions(+), 15 deletions(-)
|
||||
|
||||
diff --git a/glib/gregex.c b/glib/gregex.c
|
||||
index 116ecacbb..496b34bbd 100644
|
||||
--- a/glib/gregex.c
|
||||
+++ b/glib/gregex.c
|
||||
@@ -3147,19 +3147,25 @@ split_replacement (const gchar *replacement,
|
||||
return g_list_reverse (list);
|
||||
}
|
||||
|
||||
-/* Change the case of c based on change_case. */
|
||||
-#define CHANGE_CASE(c, change_case) \
|
||||
+/* Change the case of c based on change_case.
|
||||
+ * g_ascii_to*() will happily pass through non-ASCII bytes unchanged. */
|
||||
+#define UTF8_CHANGE_CASE(c, change_case) \
|
||||
(((change_case) & CHANGE_CASE_LOWER_MASK) ? \
|
||||
g_unichar_tolower (c) : \
|
||||
g_unichar_toupper (c))
|
||||
+#define RAW_CHANGE_CASE(c, change_case) \
|
||||
+ (((change_case) & CHANGE_CASE_LOWER_MASK) ? \
|
||||
+ g_ascii_tolower (c) : \
|
||||
+ g_ascii_toupper (c))
|
||||
|
||||
+/* If @text_is_raw is set, @text might not be valid UTF-8 (but will be
|
||||
+ * nul-terminated). */
|
||||
static void
|
||||
string_append (GString *string,
|
||||
const gchar *text,
|
||||
+ gboolean text_is_raw,
|
||||
ChangeCase *change_case)
|
||||
{
|
||||
- gunichar c;
|
||||
-
|
||||
if (text[0] == '\0')
|
||||
return;
|
||||
|
||||
@@ -3169,22 +3175,44 @@ string_append (GString *string,
|
||||
}
|
||||
else if (*change_case & CHANGE_CASE_SINGLE_MASK)
|
||||
{
|
||||
- c = g_utf8_get_char (text);
|
||||
- g_string_append_unichar (string, CHANGE_CASE (c, *change_case));
|
||||
- g_string_append (string, g_utf8_next_char (text));
|
||||
+ if (!text_is_raw)
|
||||
+ {
|
||||
+ gunichar c = g_utf8_get_char (text);
|
||||
+ g_string_append_unichar (string, UTF8_CHANGE_CASE (c, *change_case));
|
||||
+ g_string_append (string, g_utf8_next_char (text));
|
||||
+ }
|
||||
+ else
|
||||
+ {
|
||||
+ g_string_append_c (string, RAW_CHANGE_CASE (text[0], *change_case));
|
||||
+ g_string_append (string, text + 1);
|
||||
+ }
|
||||
+
|
||||
*change_case = CHANGE_CASE_NONE;
|
||||
}
|
||||
else
|
||||
{
|
||||
- while (*text != '\0')
|
||||
+ if (!text_is_raw)
|
||||
{
|
||||
- c = g_utf8_get_char (text);
|
||||
- g_string_append_unichar (string, CHANGE_CASE (c, *change_case));
|
||||
- text = g_utf8_next_char (text);
|
||||
+ while (*text != '\0')
|
||||
+ {
|
||||
+ gunichar c = g_utf8_get_char (text);
|
||||
+ g_string_append_unichar (string, UTF8_CHANGE_CASE (c, *change_case));
|
||||
+ text = g_utf8_next_char (text);
|
||||
+ }
|
||||
+ }
|
||||
+ else
|
||||
+ {
|
||||
+ while (*text != '\0')
|
||||
+ {
|
||||
+ char c = *text;
|
||||
+ g_string_append_c (string, RAW_CHANGE_CASE (c, *change_case));
|
||||
+ text++;
|
||||
+ }
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
+/* @match_info is (nullable) */
|
||||
static gboolean
|
||||
interpolate_replacement (const GMatchInfo *match_info,
|
||||
GString *result,
|
||||
@@ -3194,6 +3222,7 @@ interpolate_replacement (const GMatchInfo *match_info,
|
||||
InterpolationData *idata;
|
||||
gchar *match;
|
||||
ChangeCase change_case = CHANGE_CASE_NONE;
|
||||
+ gboolean is_raw = (match_info != NULL && (match_info->regex->orig_compile_opts & G_REGEX_RAW));
|
||||
|
||||
for (list = data; list; list = list->next)
|
||||
{
|
||||
@@ -3201,10 +3230,10 @@ interpolate_replacement (const GMatchInfo *match_info,
|
||||
switch (idata->type)
|
||||
{
|
||||
case REPL_TYPE_STRING:
|
||||
- string_append (result, idata->text, &change_case);
|
||||
+ string_append (result, idata->text, is_raw, &change_case);
|
||||
break;
|
||||
case REPL_TYPE_CHARACTER:
|
||||
- g_string_append_c (result, CHANGE_CASE (idata->c, change_case));
|
||||
+ g_string_append_c (result, UTF8_CHANGE_CASE (idata->c, change_case));
|
||||
if (change_case & CHANGE_CASE_SINGLE_MASK)
|
||||
change_case = CHANGE_CASE_NONE;
|
||||
break;
|
||||
@@ -3212,7 +3241,7 @@ interpolate_replacement (const GMatchInfo *match_info,
|
||||
match = g_match_info_fetch (match_info, idata->num);
|
||||
if (match)
|
||||
{
|
||||
- string_append (result, match, &change_case);
|
||||
+ string_append (result, match, is_raw, &change_case);
|
||||
g_free (match);
|
||||
}
|
||||
break;
|
||||
@@ -3220,7 +3249,7 @@ interpolate_replacement (const GMatchInfo *match_info,
|
||||
match = g_match_info_fetch_named (match_info, idata->text);
|
||||
if (match)
|
||||
{
|
||||
- string_append (result, match, &change_case);
|
||||
+ string_append (result, match, is_raw, &change_case);
|
||||
g_free (match);
|
||||
}
|
||||
break;
|
||||
diff --git a/glib/tests/regex.c b/glib/tests/regex.c
|
||||
index d7a698ec6..bffb52a87 100644
|
||||
--- a/glib/tests/regex.c
|
||||
+++ b/glib/tests/regex.c
|
||||
@@ -2529,6 +2529,58 @@ test_compiled_regex_after_jit_failure (void)
|
||||
g_regex_unref (regex);
|
||||
}
|
||||
|
||||
+static void
|
||||
+test_replace_raw_change_case (void)
|
||||
+{
|
||||
+ GError *local_error = NULL;
|
||||
+ GRegex *regex = NULL;
|
||||
+
|
||||
+ g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/issues/3918");
|
||||
+ g_test_summary ("Test that case changes as part of a replacement are handled correctly in G_REGEX_RAW mode");
|
||||
+
|
||||
+ /*
|
||||
+ * Match a multi-byte sequence in RAW mode. The pattern matches
|
||||
+ * exactly 2 bytes. The subject contains a 4-byte UTF-8 lead (0xF4)
|
||||
+ * followed by only one continuation byte, then NUL.
|
||||
+ *
|
||||
+ * The matched substring will be "\xf4\x80" (2 bytes, heap-allocated
|
||||
+ * as 3-byte buffer with NUL). If the code regresses and tries to handle
|
||||
+ * the replacement as UTF-8 then g_utf8_get_char() would see 0xF4 and try
|
||||
+ * to read 4 bytes, going 1 byte past the NUL into OOB territory.
|
||||
+ */
|
||||
+ regex = g_regex_new ("..", G_REGEX_RAW, 0, &local_error);
|
||||
+ g_assert_no_error (local_error);
|
||||
+
|
||||
+ /*
|
||||
+ * Build a subject string with truncated UTF-8.
|
||||
+ * \xF4 = 4-byte UTF-8 lead byte
|
||||
+ * \x80 = continuation byte
|
||||
+ * No 3rd/4th continuation bytes — the match is only 2 bytes.
|
||||
+ *
|
||||
+ * \U\0 = uppercase the entire match → triggers string_append()
|
||||
+ * with case change on the 2-byte non-UTF-8 match.
|
||||
+ */
|
||||
+ char subject[] = "\xf4\x80";
|
||||
+ char *result = g_regex_replace (regex, subject, -1, 0, "\\U\\0", 0, &local_error);
|
||||
+ g_assert_no_error (local_error);
|
||||
+
|
||||
+ g_clear_pointer (&result, g_free);
|
||||
+ g_clear_pointer (®ex, g_regex_unref);
|
||||
+
|
||||
+ /*
|
||||
+ * Second variant: single-char case change \u with \0 backreference.
|
||||
+ */
|
||||
+ regex = g_regex_new (".", G_REGEX_RAW, 0, &local_error);
|
||||
+ g_assert_no_error (local_error);
|
||||
+
|
||||
+ char subject2[] = "\xe6\xb0"; /* 3-byte UTF-8 lead, only 2 bytes */
|
||||
+ result = g_regex_replace (regex, subject2, -1, 0, "\\u\\0", 0, &local_error);
|
||||
+ g_assert_no_error (local_error);
|
||||
+
|
||||
+ g_clear_pointer (&result, g_free);
|
||||
+ g_clear_pointer (®ex, g_regex_unref);
|
||||
+}
|
||||
+
|
||||
int
|
||||
main (int argc, char *argv[])
|
||||
{
|
||||
@@ -2550,6 +2602,7 @@ main (int argc, char *argv[])
|
||||
g_test_add_func ("/regex/jit-unsupported-matching", test_jit_unsupported_matching_options);
|
||||
g_test_add_func ("/regex/unmatched-named-subpattern", test_unmatched_named_subpattern);
|
||||
g_test_add_func ("/regex/compiled-regex-after-jit-failure", test_compiled_regex_after_jit_failure);
|
||||
+ g_test_add_func ("/regex/replace-raw-change-case", test_replace_raw_change_case);
|
||||
|
||||
/* TEST_NEW(pattern, compile_opts, match_opts) */
|
||||
TEST_NEW("[A-Z]+", G_REGEX_CASELESS | G_REGEX_EXTENDED | G_REGEX_OPTIMIZE, G_REGEX_MATCH_NOTBOL | G_REGEX_MATCH_PARTIAL);
|
||||
--
|
||||
2.35.6
|
||||
140
meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch
Normal file
140
meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch
Normal file
@@ -0,0 +1,140 @@
|
||||
From cb9d97e1b261d75eb8ea255e0a9f3e846d547af7 Mon Sep 17 00:00:00 2001
|
||||
From: Philip Withnall <pwithnall@gnome.org>
|
||||
Date: Tue, 28 Apr 2026 16:45:14 +0100
|
||||
Subject: [PATCH] giochannel: Fix memcmp() off the end of the buffer with long
|
||||
terminators
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
If the line terminator is longer than a single byte, and the current
|
||||
line extends to the end of the buffer, and the buffer (which is a
|
||||
`GString`) is near a power of two in length (as that’s how `GString`s
|
||||
are allocated) it’s possible for the `memcmp()` which checks the
|
||||
terminator to read off the end of the string buffer.
|
||||
|
||||
Fix that by checking the terminator length against the last character
|
||||
before calling `memcmp()`. Add a unit test.
|
||||
|
||||
Spotted by linhlhq as #YWH-PGM9867-199. The fix is theirs (validated by
|
||||
me), and the unit test is adapted from their proof of concept.
|
||||
|
||||
Fixes: #3925
|
||||
|
||||
CVE: CVE-2026-58013
|
||||
Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/6a2583dec39bfe05553b16d9b7419d6c2a257244]
|
||||
|
||||
Backport Changes:
|
||||
- Added the <stdint.h> include for the regression test because these target
|
||||
branches do not otherwise expose uint8_t in glib/tests/io-channel.c.
|
||||
|
||||
Signed-off-by: Philip Withnall <pwithnall@gnome.org>
|
||||
(cherry picked from commit 6a2583dec39bfe05553b16d9b7419d6c2a257244)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
glib/giochannel.c | 3 ++-
|
||||
glib/tests/io-channel.c | 61 +++++++++++++++++++++++++++++++++++++++++
|
||||
2 files changed, 63 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/glib/giochannel.c b/glib/giochannel.c
|
||||
index 7572c47a2..8d867d0fb 100644
|
||||
--- a/glib/giochannel.c
|
||||
+++ b/glib/giochannel.c
|
||||
@@ -1833,7 +1833,8 @@ read_again:
|
||||
{
|
||||
if (channel->line_term)
|
||||
{
|
||||
- if (memcmp (channel->line_term, nextchar, line_term_len) == 0)
|
||||
+ if ((size_t) (lastchar - nextchar) >= line_term_len &&
|
||||
+ memcmp (channel->line_term, nextchar, line_term_len) == 0)
|
||||
{
|
||||
line_length = nextchar - use_buf->str;
|
||||
got_term_len = line_term_len;
|
||||
diff --git a/glib/tests/io-channel.c b/glib/tests/io-channel.c
|
||||
index c5dd01d04..cf81a9f6b 100644
|
||||
--- a/glib/tests/io-channel.c
|
||||
+++ b/glib/tests/io-channel.c
|
||||
@@ -29,6 +29,7 @@
|
||||
|
||||
#include <glib.h>
|
||||
#include <glib/gstdio.h>
|
||||
+#include <stdint.h>
|
||||
|
||||
static void
|
||||
test_small_writes (void)
|
||||
@@ -216,6 +217,65 @@ test_read_line_embedded_nuls (void)
|
||||
g_free (filename);
|
||||
}
|
||||
|
||||
+static void
|
||||
+test_read_line_long_terminator (void)
|
||||
+{
|
||||
+ uint8_t *test_data = NULL;
|
||||
+ size_t test_data_len = 0;
|
||||
+ int fd;
|
||||
+ char *filename = NULL;
|
||||
+ GIOChannel *channel = NULL;
|
||||
+ GError *local_error = NULL;
|
||||
+ char *line = NULL;
|
||||
+ size_t line_length, terminator_pos;
|
||||
+ const char *line_term;
|
||||
+ int line_term_length;
|
||||
+ GIOStatus status;
|
||||
+
|
||||
+ g_test_summary ("Test that reading a line when using a long terminator doesn’t over-read the buffer.");
|
||||
+ g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/work_items/3925");
|
||||
+
|
||||
+ /* Write out a temporary file containing 2047 bytes. This is enough to make it
|
||||
+ * near the length of the GString buffer when read back in. */
|
||||
+ fd = g_file_open_tmp ("glib-test-io-channel-XXXXXX", &filename, &local_error);
|
||||
+ g_assert_no_error (local_error);
|
||||
+ g_close (g_steal_fd (&fd), NULL);
|
||||
+
|
||||
+ test_data_len = 2047;
|
||||
+ test_data = g_malloc (test_data_len);
|
||||
+ memset (test_data, 'M', test_data_len);
|
||||
+ g_file_set_contents (filename, (const gchar *) test_data, test_data_len, &local_error);
|
||||
+ g_assert_no_error (local_error);
|
||||
+
|
||||
+ /* Create the channel. */
|
||||
+ channel = g_io_channel_new_file (filename, "r", &local_error);
|
||||
+ g_assert_no_error (local_error);
|
||||
+
|
||||
+ /* Use a long line terminator so it could potentially over-read the end of the buffer. */
|
||||
+ g_io_channel_set_line_term (channel, "DEADBEEF", 8);
|
||||
+
|
||||
+ line_term = g_io_channel_get_line_term (channel, &line_term_length);
|
||||
+ g_assert_cmpstr (line_term, ==, "DEADBEEF");
|
||||
+ g_assert_cmpint (line_term_length, ==, 8);
|
||||
+
|
||||
+ g_io_channel_set_encoding (channel, "UTF-8", &local_error);
|
||||
+ g_assert_no_error (local_error);
|
||||
+
|
||||
+ status = g_io_channel_read_line (channel, &line, &line_length,
|
||||
+ &terminator_pos, &local_error);
|
||||
+ g_assert_no_error (local_error);
|
||||
+ g_assert_cmpint (status, ==, G_IO_STATUS_NORMAL);
|
||||
+ g_assert_cmpuint (line_length, ==, 2047);
|
||||
+ g_assert_cmpuint (terminator_pos, ==, 2047);
|
||||
+ g_assert_cmpmem (line, line_length, test_data, test_data_len);
|
||||
+
|
||||
+ g_free (line);
|
||||
+ g_io_channel_unref (channel);
|
||||
+ g_free (test_data);
|
||||
+ g_unlink (filename);
|
||||
+ g_free (filename);
|
||||
+}
|
||||
+
|
||||
int
|
||||
main (int argc,
|
||||
char *argv[])
|
||||
@@ -224,6 +283,7 @@ main (int argc,
|
||||
|
||||
g_test_add_func ("/io-channel/read-write", test_read_write);
|
||||
g_test_add_func ("/io-channel/read-line/embedded-nuls", test_read_line_embedded_nuls);
|
||||
+ g_test_add_func ("/io-channel/read-line/long-terminator", test_read_line_long_terminator);
|
||||
|
||||
return g_test_run ();
|
||||
}
|
||||
--
|
||||
2.35.6
|
||||
106
meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch
Normal file
106
meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch
Normal file
@@ -0,0 +1,106 @@
|
||||
From ba0478c206bc04542df774343c6c85f77df49f6e Mon Sep 17 00:00:00 2001
|
||||
From: Philip Withnall <pwithnall@gnome.org>
|
||||
Date: Sat, 11 Apr 2026 14:42:57 +0100
|
||||
Subject: [PATCH] gkeyfile: Fix a one-byte heap under-read with
|
||||
g_key_file_get_locale_string_list()
|
||||
|
||||
If this method was called on a key file key which has an empty value,
|
||||
`len == 0` and this leads to a one-byte under-read off the start of the
|
||||
key file buffer.
|
||||
|
||||
Spotted by linhlhq as #YWH-PGM9867-200. The suggested fix is theirs, and
|
||||
the unit test is adapted from their report. I added the fuzzing test.
|
||||
|
||||
Fixes: #3930
|
||||
|
||||
CVE: CVE-2026-58014
|
||||
Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/94ecb5b44a1cae09f481dd5e693832f129948893]
|
||||
|
||||
Signed-off-by: Philip Withnall <pwithnall@gnome.org>
|
||||
(cherry picked from commit 94ecb5b44a1cae09f481dd5e693832f129948893)
|
||||
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||
---
|
||||
fuzzing/fuzz_key.c | 9 +++++++++
|
||||
glib/gkeyfile.c | 2 +-
|
||||
glib/tests/keyfile.c | 23 +++++++++++++++++++++++
|
||||
3 files changed, 33 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/fuzzing/fuzz_key.c b/fuzzing/fuzz_key.c
|
||||
index 77cb684..7d00443 100644
|
||||
--- a/fuzzing/fuzz_key.c
|
||||
+++ b/fuzzing/fuzz_key.c
|
||||
@@ -26,11 +26,20 @@ test_parse (const gchar *data,
|
||||
GKeyFileFlags flags)
|
||||
{
|
||||
GKeyFile *key = NULL;
|
||||
+ char *comment = NULL;
|
||||
+ char **list = NULL;
|
||||
|
||||
key = g_key_file_new ();
|
||||
g_key_file_load_from_data (key, (const gchar*) data, size, G_KEY_FILE_NONE,
|
||||
NULL);
|
||||
|
||||
+ /* Also try some additional parsing and see if it crashes */
|
||||
+ comment = g_key_file_get_comment (key, "group", "key", NULL);
|
||||
+ g_free (comment);
|
||||
+
|
||||
+ list = g_key_file_get_locale_string_list (key, "group", "key", "de", NULL, NULL);
|
||||
+ g_strfreev (list);
|
||||
+
|
||||
g_key_file_free (key);
|
||||
}
|
||||
|
||||
diff --git a/glib/gkeyfile.c b/glib/gkeyfile.c
|
||||
index d08a485..54d77a5 100644
|
||||
--- a/glib/gkeyfile.c
|
||||
+++ b/glib/gkeyfile.c
|
||||
@@ -2421,7 +2421,7 @@ g_key_file_get_locale_string_list (GKeyFile *key_file,
|
||||
}
|
||||
|
||||
len = strlen (value);
|
||||
- if (value[len - 1] == key_file->list_separator)
|
||||
+ if (len > 0 && value[len - 1] == key_file->list_separator)
|
||||
value[len - 1] = '\0';
|
||||
|
||||
list_separator[0] = key_file->list_separator;
|
||||
diff --git a/glib/tests/keyfile.c b/glib/tests/keyfile.c
|
||||
index bc125c1..289bd2b 100644
|
||||
--- a/glib/tests/keyfile.c
|
||||
+++ b/glib/tests/keyfile.c
|
||||
@@ -850,6 +850,28 @@ test_locale_string_multiple_loads (void)
|
||||
g_free (old_locale);
|
||||
}
|
||||
|
||||
+static void
|
||||
+test_locale_string_empty (void)
|
||||
+{
|
||||
+ GKeyFile *keyfile = NULL;
|
||||
+ GError *local_error = NULL;
|
||||
+ const char *data =
|
||||
+ "[valid]\n"
|
||||
+ "key1=\n";
|
||||
+
|
||||
+ g_test_summary ("Check that loading an empty translatable string works");
|
||||
+ g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/issues/3930");
|
||||
+
|
||||
+ keyfile = g_key_file_new ();
|
||||
+
|
||||
+ g_key_file_load_from_data (keyfile, data, -1, G_KEY_FILE_NONE, &local_error);
|
||||
+ g_assert_no_error (local_error);
|
||||
+
|
||||
+ check_locale_string_list_value (keyfile, "valid", "key1", NULL, NULL);
|
||||
+
|
||||
+ g_key_file_free (keyfile);
|
||||
+}
|
||||
+
|
||||
static void
|
||||
test_lists (void)
|
||||
{
|
||||
@@ -1939,6 +1961,7 @@ main (int argc, char *argv[])
|
||||
g_test_add_func ("/keyfile/number", test_number);
|
||||
g_test_add_func ("/keyfile/locale-string", test_locale_string);
|
||||
g_test_add_func ("/keyfile/locale-string/multiple-loads", test_locale_string_multiple_loads);
|
||||
+ g_test_add_func ("/keyfile/locale-string/empty", test_locale_string_empty);
|
||||
g_test_add_func ("/keyfile/lists", test_lists);
|
||||
g_test_add_func ("/keyfile/lists-set-get", test_lists_set_get);
|
||||
g_test_add_func ("/keyfile/group-remove", test_group_remove);
|
||||
94
meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58016-1.patch
Normal file
94
meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58016-1.patch
Normal file
@@ -0,0 +1,94 @@
|
||||
From 38eee3870fbcf6bdf8e6b1281bc7a98d32b68521 Mon Sep 17 00:00:00 2001
|
||||
From: Philip Withnall <pwithnall@gnome.org>
|
||||
Date: Thu, 16 Apr 2026 15:27:37 +0100
|
||||
Subject: [PATCH 1/2] gdbusintrospection: Fix XML parser state handling for
|
||||
<node> element nesting
|
||||
|
||||
The check for whether a `<node>` element in D-Bus introspection XML was
|
||||
nested correctly was broken. `<node>` elements can only be at the top
|
||||
level, or nested immediately within another `<node>` element.
|
||||
|
||||
Fix the check and add some unit tests for it.
|
||||
|
||||
Spotted by linhlhq as #YWH-PGM9867-204. The fix is mine, and the unit test
|
||||
uses example XML strings adapted from their report.
|
||||
|
||||
Signed-off-by: Philip Withnall <pwithnall@gnome.org>
|
||||
|
||||
Fixes: #3932
|
||||
|
||||
CVE: CVE-2026-58016
|
||||
Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/c9da977c178fbfc0e4caf99f9fdf5dc433d6fcc2]
|
||||
|
||||
Signed-off-by: Benjamin Robin <benjamin.robin@bootlin.com>
|
||||
---
|
||||
gio/gdbusintrospection.c | 2 +-
|
||||
gio/tests/gdbus-introspection.c | 33 +++++++++++++++++++++++++++++++++
|
||||
2 files changed, 34 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/gio/gdbusintrospection.c b/gio/gdbusintrospection.c
|
||||
index c7be334ce2f7..6f722ee6153d 100644
|
||||
--- a/gio/gdbusintrospection.c
|
||||
+++ b/gio/gdbusintrospection.c
|
||||
@@ -1272,7 +1272,7 @@ parser_start_element (GMarkupParseContext *context,
|
||||
/* ---------------------------------------------------------------------------------------------------- */
|
||||
if (strcmp (element_name, "node") == 0)
|
||||
{
|
||||
- if (!(g_slist_length (stack) >= 1 || strcmp (stack->next->data, "node") != 0))
|
||||
+ if (stack->next != NULL && strcmp (stack->next->data, "node") != 0)
|
||||
{
|
||||
g_set_error_literal (error,
|
||||
G_MARKUP_ERROR,
|
||||
diff --git a/gio/tests/gdbus-introspection.c b/gio/tests/gdbus-introspection.c
|
||||
index 44cb7a96af45..daca313f77e7 100644
|
||||
--- a/gio/tests/gdbus-introspection.c
|
||||
+++ b/gio/tests/gdbus-introspection.c
|
||||
@@ -299,6 +299,38 @@ test_extra_data (void)
|
||||
g_dbus_node_info_unref (info);
|
||||
}
|
||||
|
||||
+static void
|
||||
+test_invalid (void)
|
||||
+{
|
||||
+ const struct
|
||||
+ {
|
||||
+ const char *xml;
|
||||
+ GMarkupError expected_error_code;
|
||||
+ }
|
||||
+ vectors[] =
|
||||
+ {
|
||||
+ { "", G_MARKUP_ERROR_EMPTY },
|
||||
+ { "<node><interface name=\"I\"><method name=\"M\"><node><interface name=\"I2\"></interface></node></method>", G_MARKUP_ERROR_INVALID_CONTENT },
|
||||
+ { "<node><interface name=\"I\"><signal name=\"S\"><node><interface name=\"I2\"><signal name=\"S2\"></signal></interface></node></signal>", G_MARKUP_ERROR_INVALID_CONTENT },
|
||||
+ { "<node><interface name=\"I\"><property name=\"P\" type=\"s\" access=\"read\"><node><interface name=\"I2\"></interface></node></property>", G_MARKUP_ERROR_INVALID_CONTENT },
|
||||
+ { "<node><interface name=\"I\"><method name=\"M\"><arg type=\"\"><node><interface name=\"I2\"><method name=\"M2\"></method></interface></node></arg>", G_MARKUP_ERROR_INVALID_CONTENT },
|
||||
+ };
|
||||
+
|
||||
+ for (size_t i = 0; i < G_N_ELEMENTS (vectors); i++)
|
||||
+ {
|
||||
+ GDBusNodeInfo *node;
|
||||
+ GError *local_error = NULL;
|
||||
+
|
||||
+ g_test_message ("Testing parsing of %s gives an error", vectors[i].xml);
|
||||
+
|
||||
+ node = g_dbus_node_info_new_for_xml (vectors[i].xml, &local_error);
|
||||
+ g_assert_error (local_error, G_MARKUP_ERROR, (int) vectors[i].expected_error_code);
|
||||
+ g_assert_null (node);
|
||||
+
|
||||
+ g_clear_error (&local_error);
|
||||
+ }
|
||||
+}
|
||||
+
|
||||
/* ---------------------------------------------------------------------------------------------------- */
|
||||
|
||||
int
|
||||
@@ -316,6 +348,7 @@ main (int argc,
|
||||
g_test_add_func ("/gdbus/introspection-generate", test_generate);
|
||||
g_test_add_func ("/gdbus/introspection-default-direction", test_default_direction);
|
||||
g_test_add_func ("/gdbus/introspection-extra-data", test_extra_data);
|
||||
+ g_test_add_func ("/gdbus/introspection/invalid", test_invalid);
|
||||
|
||||
ret = session_bus_run ();
|
||||
|
||||
--
|
||||
2.54.0
|
||||
98
meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58016-2.patch
Normal file
98
meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58016-2.patch
Normal file
@@ -0,0 +1,98 @@
|
||||
From a75052ceeebea434f271b670766acd5416bc83b9 Mon Sep 17 00:00:00 2001
|
||||
From: Philip Withnall <pwithnall@gnome.org>
|
||||
Date: Thu, 16 Apr 2026 15:08:10 +0100
|
||||
Subject: [PATCH 2/2] gdbusintrospection: Add some assertions before array
|
||||
dereferences
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
The state handling inside the D-Bus introspection XML parser is
|
||||
complicated, and it’s possible that these dereferences of the
|
||||
`len - 1`th element might get reached when the array is empty.
|
||||
|
||||
Make failures like that more debuggable by adding an assertion on the
|
||||
length beforehand.
|
||||
|
||||
Signed-off-by: Philip Withnall <pwithnall@gnome.org>
|
||||
|
||||
Helps: #3932
|
||||
|
||||
CVE: CVE-2026-58016
|
||||
Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/656ad4582cb1d7a7fa8bafe3ce8aec6aa3c17da0]
|
||||
|
||||
Signed-off-by: Benjamin Robin <benjamin.robin@bootlin.com>
|
||||
---
|
||||
gio/gdbusintrospection.c | 8 ++++++++
|
||||
1 file changed, 8 insertions(+)
|
||||
|
||||
diff --git a/gio/gdbusintrospection.c b/gio/gdbusintrospection.c
|
||||
index 6f722ee6153d..ed0d291f99f0 100644
|
||||
--- a/gio/gdbusintrospection.c
|
||||
+++ b/gio/gdbusintrospection.c
|
||||
@@ -1110,6 +1110,7 @@ parse_data_get_annotation (ParseData *data,
|
||||
{
|
||||
if (create_new)
|
||||
g_ptr_array_add (data->annotations, g_new0 (GDBusAnnotationInfo, 1));
|
||||
+ g_assert (data->annotations->len > 0);
|
||||
return data->annotations->pdata[data->annotations->len - 1];
|
||||
}
|
||||
|
||||
@@ -1119,6 +1120,7 @@ parse_data_get_arg (ParseData *data,
|
||||
{
|
||||
if (create_new)
|
||||
g_ptr_array_add (data->args, g_new0 (GDBusArgInfo, 1));
|
||||
+ g_assert (data->args->len > 0);
|
||||
return data->args->pdata[data->args->len - 1];
|
||||
}
|
||||
|
||||
@@ -1128,6 +1130,7 @@ parse_data_get_out_arg (ParseData *data,
|
||||
{
|
||||
if (create_new)
|
||||
g_ptr_array_add (data->out_args, g_new0 (GDBusArgInfo, 1));
|
||||
+ g_assert (data->out_args->len > 0);
|
||||
return data->out_args->pdata[data->out_args->len - 1];
|
||||
}
|
||||
|
||||
@@ -1137,6 +1140,7 @@ parse_data_get_method (ParseData *data,
|
||||
{
|
||||
if (create_new)
|
||||
g_ptr_array_add (data->methods, g_new0 (GDBusMethodInfo, 1));
|
||||
+ g_assert (data->methods->len > 0);
|
||||
return data->methods->pdata[data->methods->len - 1];
|
||||
}
|
||||
|
||||
@@ -1146,6 +1150,7 @@ parse_data_get_signal (ParseData *data,
|
||||
{
|
||||
if (create_new)
|
||||
g_ptr_array_add (data->signals, g_new0 (GDBusSignalInfo, 1));
|
||||
+ g_assert (data->signals->len > 0);
|
||||
return data->signals->pdata[data->signals->len - 1];
|
||||
}
|
||||
|
||||
@@ -1155,6 +1160,7 @@ parse_data_get_property (ParseData *data,
|
||||
{
|
||||
if (create_new)
|
||||
g_ptr_array_add (data->properties, g_new0 (GDBusPropertyInfo, 1));
|
||||
+ g_assert (data->properties->len > 0);
|
||||
return data->properties->pdata[data->properties->len - 1];
|
||||
}
|
||||
|
||||
@@ -1164,6 +1170,7 @@ parse_data_get_interface (ParseData *data,
|
||||
{
|
||||
if (create_new)
|
||||
g_ptr_array_add (data->interfaces, g_new0 (GDBusInterfaceInfo, 1));
|
||||
+ g_assert (data->interfaces->len > 0);
|
||||
return data->interfaces->pdata[data->interfaces->len - 1];
|
||||
}
|
||||
|
||||
@@ -1173,6 +1180,7 @@ parse_data_get_node (ParseData *data,
|
||||
{
|
||||
if (create_new)
|
||||
g_ptr_array_add (data->nodes, g_new0 (GDBusNodeInfo, 1));
|
||||
+ g_assert (data->nodes->len > 0);
|
||||
return data->nodes->pdata[data->nodes->len - 1];
|
||||
}
|
||||
|
||||
--
|
||||
2.54.0
|
||||
@@ -47,6 +47,13 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
|
||||
file://CVE-2026-1489-02.patch \
|
||||
file://CVE-2026-1489-03.patch \
|
||||
file://CVE-2026-1489-04.patch \
|
||||
file://CVE-2026-58016-1.patch \
|
||||
file://CVE-2026-58016-2.patch \
|
||||
file://CVE-2026-58010.patch \
|
||||
file://CVE-2026-58011.patch \
|
||||
file://CVE-2026-58012.patch \
|
||||
file://CVE-2026-58013.patch \
|
||||
file://CVE-2026-58014.patch \
|
||||
"
|
||||
SRC_URI:append:class-native = " file://relocate-modules.patch \
|
||||
file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \
|
||||
|
||||
@@ -31,6 +31,7 @@ do_check:append () {
|
||||
}
|
||||
|
||||
inherit nopackages
|
||||
inherit nospdx
|
||||
deltask do_stash_locale
|
||||
deltask do_install
|
||||
deltask do_populate_sysroot
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
SRCBRANCH ?= "release/2.39/master"
|
||||
PV = "2.39+git"
|
||||
SRCREV_glibc ?= "ce65d944e38a20cb70af2a48a4b8aa5d8fabe1cc"
|
||||
SRCREV_glibc ?= "be1e627cd72db31161a3b4ce1c8114674f0895eb"
|
||||
SRCREV_localedef ?= "cba02c503d7c853a38ccfb83c57e343ca5ecd7e5"
|
||||
|
||||
GLIBC_GIT_URI ?= "git://sourceware.org/git/glibc.git;protocol=https"
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user