mirror of
https://git.yoctoproject.org/poky
synced 2026-09-29 07:36:20 +02:00
backport fix for: CVE-2022-1920 CVE-2022-1921 CVE-2022-1922 CVE-2022-1923 CVE-2022-1924 CVE-2022-1925 CVE-2022-2122 also set ignore at gstreamer1.0_1.16.3.bb (From OE-Core rev: c852d3e6742fe82b9f4ec84b077d6e1b0bfd021e) Signed-off-by: Chee Yang Lee <chee.yang.lee@intel.com> Signed-off-by: Steve Sakoman <steve@sakoman.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
95 lines
3.9 KiB
BlitzBasic
95 lines
3.9 KiB
BlitzBasic
SUMMARY = "GStreamer 1.0 multimedia framework"
|
|
DESCRIPTION = "GStreamer is a multimedia framework for encoding and decoding video and sound. \
|
|
It supports a wide range of formats including mp3, ogg, avi, mpeg and quicktime."
|
|
HOMEPAGE = "http://gstreamer.freedesktop.org/"
|
|
BUGTRACKER = "https://bugzilla.gnome.org/enter_bug.cgi?product=Gstreamer"
|
|
SECTION = "multimedia"
|
|
LICENSE = "LGPLv2+"
|
|
|
|
DEPENDS = "glib-2.0 glib-2.0-native libxml2 bison-native flex-native"
|
|
|
|
inherit meson pkgconfig gettext upstream-version-is-even gobject-introspection gtk-doc
|
|
|
|
LIC_FILES_CHKSUM = "file://COPYING;md5=6762ed442b3822387a51c92d928ead0d \
|
|
file://gst/gst.h;beginline=1;endline=21;md5=e059138481205ee2c6fc1c079c016d0d"
|
|
|
|
S = "${WORKDIR}/gstreamer-${PV}"
|
|
|
|
SRC_URI = " \
|
|
https://gstreamer.freedesktop.org/src/gstreamer/gstreamer-${PV}.tar.xz \
|
|
file://0001-gst-gstpluginloader.c-when-env-var-is-set-do-not-fal.patch \
|
|
file://0002-meson-build-gir-even-when-cross-compiling-if-introsp.patch \
|
|
file://0003-meson-Add-valgrind-feature.patch \
|
|
file://0004-meson-Add-option-for-installed-tests.patch \
|
|
file://0005-bufferpool-only-resize-in-reset-when-maxsize-is-larger.patch \
|
|
file://0006-tests-seek-Don-t-use-too-strict-timeout-for-validati.patch \
|
|
"
|
|
SRC_URI[md5sum] = "beecf6965a17fb17fa3b262fd36df70a"
|
|
SRC_URI[sha256sum] = "692f037968e454e508b0f71d9674e2e26c78475021407fcf8193b1c7e59543c7"
|
|
|
|
PACKAGECONFIG ??= "${@bb.utils.contains('PTEST_ENABLED', '1', 'tests', '', d)} \
|
|
check \
|
|
debug \
|
|
tools"
|
|
|
|
PACKAGECONFIG[debug] = "-Dgst_debug=true,-Dgst_debug=false"
|
|
PACKAGECONFIG[tracer-hooks] = "-Dtracer_hooks=true,-Dtracer_hooks=false"
|
|
PACKAGECONFIG[check] = "-Dcheck=enabled,-Dcheck=disabled"
|
|
PACKAGECONFIG[tests] = "-Dtests=enabled -Dinstalled-tests=true,-Dtests=disabled -Dinstalled-tests=false"
|
|
PACKAGECONFIG[valgrind] = "-Dvalgrind=enabled,-Dvalgrind=disabled,valgrind,"
|
|
PACKAGECONFIG[unwind] = "-Dlibunwind=enabled,-Dlibunwind=disabled,libunwind"
|
|
PACKAGECONFIG[dw] = "-Dlibdw=enabled,-Dlibdw=disabled,elfutils"
|
|
PACKAGECONFIG[bash-completion] = "-Dbash-completion=enabled,-Dbash-completion=disabled,bash-completion"
|
|
PACKAGECONFIG[tools] = "-Dtools=enabled,-Dtools=disabled"
|
|
PACKAGECONFIG[setcap] = "-Dptp-helper-permissions=capabilities,,libcap libcap-native"
|
|
|
|
# TODO: put this in a gettext.bbclass patch
|
|
def gettext_oemeson(d):
|
|
if d.getVar('USE_NLS') == 'no':
|
|
return '-Dnls=disabled'
|
|
# Remove the NLS bits if USE_NLS is no or INHIBIT_DEFAULT_DEPS is set
|
|
if d.getVar('INHIBIT_DEFAULT_DEPS') and not oe.utils.inherits(d, 'cross-canadian'):
|
|
return '-Dnls=disabled'
|
|
return '-Dnls=enabled'
|
|
|
|
EXTRA_OEMESON += " \
|
|
-Dexamples=disabled \
|
|
-Ddbghelp=disabled \
|
|
${@gettext_oemeson(d)} \
|
|
"
|
|
|
|
GTKDOC_MESON_OPTION = "gtk_doc"
|
|
GTKDOC_MESON_ENABLE_FLAG = "enabled"
|
|
GTKDOC_MESON_DISABLE_FLAG = "disabled"
|
|
|
|
GIR_MESON_ENABLE_FLAG = "enabled"
|
|
GIR_MESON_DISABLE_FLAG = "disabled"
|
|
|
|
PACKAGES += "${PN}-bash-completion"
|
|
|
|
# Add the core element plugins to the main package
|
|
FILES_${PN} += "${libdir}/gstreamer-1.0/*.so"
|
|
FILES_${PN}-dev += "${libdir}/gstreamer-1.0/*.a ${libdir}/gstreamer-1.0/include"
|
|
FILES_${PN}-bash-completion += "${datadir}/bash-completion/completions/ ${datadir}/bash-completion/helpers/gst*"
|
|
FILES_${PN}-dbg += "${datadir}/gdb ${datadir}/gstreamer-1.0/gdb"
|
|
|
|
CVE_PRODUCT = "gstreamer"
|
|
|
|
# CPE entries for gst-plugins-base are listed as gstreamer issues
|
|
# so we need to ignore the false hits
|
|
CVE_CHECK_WHITELIST += "CVE-2021-3522"
|
|
|
|
# CPE entries for gst-plugins-good are listed as gstreamer issues
|
|
# so we need to ignore the false hits
|
|
CVE_CHECK_WHITELIST += "CVE-2021-3497"
|
|
CVE_CHECK_WHITELIST += "CVE-2021-3498"
|
|
CVE_CHECK_WHITELIST += "CVE-2022-1920"
|
|
CVE_CHECK_WHITELIST += "CVE-2022-1921"
|
|
CVE_CHECK_WHITELIST += "CVE-2022-1922"
|
|
CVE_CHECK_WHITELIST += "CVE-2022-1923"
|
|
CVE_CHECK_WHITELIST += "CVE-2022-1924"
|
|
CVE_CHECK_WHITELIST += "CVE-2022-1925"
|
|
CVE_CHECK_WHITELIST += "CVE-2022-2122"
|
|
|
|
require gstreamer1.0-ptest.inc
|