diff mbox series

[AUH] gnupg: upgrading to 2.5.21 SUCCEEDED

Message ID 0101019f92a6103d-1b1d1884-203a-4c0f-89e0-ebb803212e3c-000000@us-west-2.amazonses.com
State New
Headers show
Series [AUH] gnupg: upgrading to 2.5.21 SUCCEEDED | expand

Commit Message

auh@yoctoproject.org July 24, 2026, 5:43 a.m. UTC
Hello,

this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe(s) *gnupg* to *2.5.21* has Succeeded.

Next steps:
    - apply the patch: git am 0001-gnupg-upgrade-2.5.20-2.5.21.patch
    - check the changes to upstream patches and summarize them in the commit message,
    - compile an image that contains the package
    - perform some basic sanity tests
    - amend the patch and sign it off: git commit -s --reset-author --amend
    - send it to the appropriate mailing list

Alternatively, if you believe the recipe should not be upgraded at this time,
you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that
automatic upgrades would no longer be attempted.

Please review the attached files for further information and build/update failures.
Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler

Regards,
The Upgrade Helper

-- >8 --
From cbb4c197516cff9f1a59025545b93183e62b7013 Mon Sep 17 00:00:00 2001
From: Upgrade Helper <auh@yoctoproject.org>
Date: Fri, 24 Jul 2026 05:40:12 +0000
Subject: [PATCH] gnupg: upgrade 2.5.20 -> 2.5.21

Source: ChangeLog

2026-07-02  Werner Koch  <wk@gnupg.org>

	Release 2.5.21.
	+ commit 363096d9c9a973ac8dcad8ee4efd479f50add290

2026-06-30  Werner Koch  <wk@gnupg.org>

	speedo: Create a pkgversioninfo.txt file.
	+ commit 8716b4dac4a79b600d18847b8bc0193bd06e1fc1
	* build-aux/mk-sbom.sh: New.  Taken from gpg4win and extended.
	* Makefile.am (EXTRA_DIST): Add it.
	* build-aux/speedo.mk (gnupg_ver_this): Use sed to extract version.
	(gnupg_commit_id): new.
	(00-unpack): Call mk-sbom.sh.
	(clean-pkg-versions: Clear version files.
	($(bdir)/pkgversioninfo.txt): New.
	(all-speedo,installer): Depend on above.
	(dist-source): Exclude autom4te.cache just in case
	* build-aux/speedo/w32/inst.nsi: Install pkgversioninfo.txt.

2026-06-30  NIIBE Yutaka  <gniibe@fsij.org>

	scd: Fix condition to retrieve ATR.
	+ commit ca25a7a61bebbe4e27dd5568c5b049675b7aa4ae
	* scd/app.c (atr_to_cardtype): Call apdu_get_atr when ATR is NULL.

2026-06-29  Werner Koch  <wk@gnupg.org>

	speedo: Fix passing configure args to w32 builds.
	+ commit 7af73849a5dbbc5c70e43c3a3f5d70c639c80ab4
	* build-aux/speedo.mk (pkgcfg): Use correct number of dollar signs.

	common: Prepare to get rid of map_w32_to_errno.
	+ commit bf808091534f587e8cdacf351b0e7ba060165fd8
	* common/sysutils.c (gnupg_w32_set_errno): Use gpgrt function if
	  available.

	agent: Make batch import of Kyber keys work.
	+ commit 4fca79b67bba04bc5ef2a4402e948c01821ceac5
	* agent/command.c (cmd_import_key): Allow --unattended also for
	  composite keys.

2026-06-26  NIIBE Yutaka  <gniibe@fsij.org>

	dirmngr: Add a validation check in get_dns_cert_standard.
	+ commit c3ec7678799a161b9265969e7ad3fd59605b18ab
	* dirmngr/dns-stuff.c (get_dns_cert_standard): Validate the length.

2026-06-19  NIIBE Yutaka  <gniibe@fsij.org>

	build: Update ldap.m4 for POSIX with no LDAP_DEPRECATED.
	+ commit d3822099fdd4d84323afae4bacaadfeab9cb3e27
	* m4/ldap.m4: Check ldap_err2string, instead.

2026-06-18  Werner Koch  <wk@gnupg.org>

	gpgsm: Require a minimum tag length for GCM decryption.
	+ commit 4c7e68cf3d335328821bdbb70db309a60d0e4fd4
	* sm/decrypt.c (gpgsm_decrypt): Require a minimum authtaglen.

2026-06-18  NIIBE Yutaka  <gniibe@fsij.org>

	w32:common: Fix usleep in w32_wait_when_sharing_violation.
	+ commit ab9ce5f5e775a3a6a37923299685ac371f740103
	* common/sysutils.c (w32_wait_when_sharing_violation): WTIME is
	in milliseconds.

2026-06-17  Philip Le  <philip.le@gnupg.com>

	gpg: Fix copy_signature.
	+ commit 56e11ffe971d5cc58185b4e8d02b82dc432c634b
	* g10/free-packet.c (copy_signature): Set the signers_uid of the new
	copy to NULL if it is not present in the source signature.

	gpg: Use the INT_RCP_FPR subpacket in revocation signatures.
	+ commit 9e0e5547d2a008332873a9b632f82f9414ad887f
	* common/openpgpdefs.h (sigsubpkttype_t): Add Intended Recipient
	Fingerprint signature subpacket.
	* g10/build-packet.c (build_sig_subpkt): Build the Intended Recipient
	Fingerprint signature subpacket for v4 and v5 keys.
	* g10/free-packet.c (fre

[Changelog truncated as it exceeds 3000 characters;
the full changelog can be found in an attachment to the AUH email]
---
 ...erride-init-is-not-needed-with-gcc-9.patch |  2 +-
 ...-a-custom-value-for-the-location-of-.patch |  6 +--
 ...use-pkgconfig-instead-of-npth-config.patch |  2 +-
 .../gnupg/gnupg/CVE-2026-57062.patch          | 43 -------------------
 .../gnupg/gnupg/relocate.patch                | 18 ++++----
 .../{gnupg_2.5.20.bb => gnupg_2.5.21.bb}      |  4 +-
 6 files changed, 16 insertions(+), 59 deletions(-)
 delete mode 100644 meta/recipes-support/gnupg/gnupg/CVE-2026-57062.patch
 rename meta/recipes-support/gnupg/{gnupg_2.5.20.bb => gnupg_2.5.21.bb} (95%)
diff mbox series

Patch

diff --git a/meta/recipes-support/gnupg/gnupg/0001-Woverride-init-is-not-needed-with-gcc-9.patch b/meta/recipes-support/gnupg/gnupg/0001-Woverride-init-is-not-needed-with-gcc-9.patch
index b48db40970..7a3fa59c54 100644
--- a/meta/recipes-support/gnupg/gnupg/0001-Woverride-init-is-not-needed-with-gcc-9.patch
+++ b/meta/recipes-support/gnupg/gnupg/0001-Woverride-init-is-not-needed-with-gcc-9.patch
@@ -1,4 +1,4 @@ 
-From 9b7ef8aa1a5d71fc95f36a92874d3faa4579fc4e Mon Sep 17 00:00:00 2001
+From 46db1301b1b71f47aa131b9a3de9d1cf356cf408 Mon Sep 17 00:00:00 2001
 From: Khem Raj <raj.khem@gmail.com>
 Date: Thu, 20 Dec 2018 17:37:48 -0800
 Subject: [PATCH] Woverride-init is not needed with gcc 9
diff --git a/meta/recipes-support/gnupg/gnupg/0001-configure.ac-use-a-custom-value-for-the-location-of-.patch b/meta/recipes-support/gnupg/gnupg/0001-configure.ac-use-a-custom-value-for-the-location-of-.patch
index bfee9c9904..1c7cd7ba7b 100644
--- a/meta/recipes-support/gnupg/gnupg/0001-configure.ac-use-a-custom-value-for-the-location-of-.patch
+++ b/meta/recipes-support/gnupg/gnupg/0001-configure.ac-use-a-custom-value-for-the-location-of-.patch
@@ -1,4 +1,4 @@ 
-From 84a16d46a72a2501cbe3a4a83ea7f8393ada4038 Mon Sep 17 00:00:00 2001
+From fd060f524e50c7c3f8694f71630ac151627235f1 Mon Sep 17 00:00:00 2001
 From: Alexander Kanavin <alex.kanavin@gmail.com>
 Date: Mon, 22 Jan 2018 18:00:21 +0200
 Subject: [PATCH] configure.ac: use a custom value for the location of
@@ -13,10 +13,10 @@  Signed-off-by: Alexander Kanavin <alex.kanavin@gmail.com>
  1 file changed, 1 insertion(+), 1 deletion(-)
 
 diff --git a/configure.ac b/configure.ac
-index 023604b..c84442c 100644
+index 5ac4d0b..09615c5 100644
 --- a/configure.ac
 +++ b/configure.ac
-@@ -1908,7 +1908,7 @@ AC_DEFINE_UNQUOTED(GPGCONF_DISP_NAME, "GPGConf",
+@@ -1909,7 +1909,7 @@ AC_DEFINE_UNQUOTED(GPGCONF_DISP_NAME, "GPGConf",
  
  AC_DEFINE_UNQUOTED(GPGTAR_NAME, "gpgtar", [The name of the gpgtar tool])
  
diff --git a/meta/recipes-support/gnupg/gnupg/0002-use-pkgconfig-instead-of-npth-config.patch b/meta/recipes-support/gnupg/gnupg/0002-use-pkgconfig-instead-of-npth-config.patch
index 90d53674d4..f4c9b2161a 100644
--- a/meta/recipes-support/gnupg/gnupg/0002-use-pkgconfig-instead-of-npth-config.patch
+++ b/meta/recipes-support/gnupg/gnupg/0002-use-pkgconfig-instead-of-npth-config.patch
@@ -1,4 +1,4 @@ 
-From 0c3a09a95875e5744a910a0d3c93fa2e9dbe8c69 Mon Sep 17 00:00:00 2001
+From b8a99b2d9caa05f54be25635e3b1687753fe7196 Mon Sep 17 00:00:00 2001
 From: Saul Wold <sgw@linux.intel.com>
 Date: Wed, 16 Aug 2017 11:16:30 +0800
 Subject: [PATCH] use pkgconfig instead of npth config
diff --git a/meta/recipes-support/gnupg/gnupg/CVE-2026-57062.patch b/meta/recipes-support/gnupg/gnupg/CVE-2026-57062.patch
deleted file mode 100644
index f298b6e9a8..0000000000
--- a/meta/recipes-support/gnupg/gnupg/CVE-2026-57062.patch
+++ /dev/null
@@ -1,43 +0,0 @@ 
-From d586f50ee849c8cbeaea47b50c64446c1becbf9b Mon Sep 17 00:00:00 2001
-From: Werner Koch <wk@gnupg.org>
-Date: Thu, 18 Jun 2026 10:51:34 +0200
-Subject: [PATCH] gpgsm: Require a minimum tag length for GCM decryption.
-
-* sm/decrypt.c (gpgsm_decrypt): Require a minimum authtaglen.
---
-
-Reported-by: Thai Duong <thai@calif.io>
-This is similar to OpenSSL's
-CVE-id: CVE-2026-34182
-
-CVE: CVE-2026-57062
-Upstream-Status: Backport [https://github.com/gpg/gnupg/commit/4c7e68cf3d335328821bdbb70db309a60d0e4fd4]
-
-Signed-off-by: Roland Kovacs <roland.kovacs@est.tech>
----
- sm/decrypt.c | 9 ++++++++-
- 1 file changed, 8 insertions(+), 1 deletion(-)
-
-diff --git a/sm/decrypt.c b/sm/decrypt.c
-index 20fb96060..92a33c6e6 100644
---- a/sm/decrypt.c
-+++ b/sm/decrypt.c
-@@ -1447,7 +1447,14 @@ gpgsm_decrypt (ctrl_t ctrl, estream_t in_fp, estream_t out_fp)
-                 }
-               if (DBG_CRYPTO)
-                 log_printhex (authtag, authtaglen, "Authtag ...:");
--              rc = gcry_cipher_checktag (dfparm.hd, authtag, authtaglen);
-+              if (authtaglen < 12)
-+                {
-+                  log_info ("authentication tag is too short (%zu octets)\n",
-+                            authtaglen);
-+                  rc = gpg_error (GPG_ERR_CHECKSUM);
-+                }
-+              else
-+                rc = gcry_cipher_checktag (dfparm.hd, authtag, authtaglen);
-               xfree (authtag);
-               if (rc)
-                 log_error ("data is not authentic: %s\n", gpg_strerror (rc));
--- 
-2.34.1
-
diff --git a/meta/recipes-support/gnupg/gnupg/relocate.patch b/meta/recipes-support/gnupg/gnupg/relocate.patch
index fedb7f6407..02f03386ec 100644
--- a/meta/recipes-support/gnupg/gnupg/relocate.patch
+++ b/meta/recipes-support/gnupg/gnupg/relocate.patch
@@ -1,4 +1,4 @@ 
-From 8d7658741da050f604bcf26f8a6c24a0b15df94b Mon Sep 17 00:00:00 2001
+From c70694bd3e71cc1fec6ccb3ea0f694c3863ebd48 Mon Sep 17 00:00:00 2001
 From: Ross Burton <ross.burton@intel.com>
 Date: Wed, 19 Sep 2018 14:44:40 +0100
 Subject: [PATCH] Allow the environment to override where gnupg looks for its
@@ -13,10 +13,10 @@  Signed-off-by: Alexander Kanavin <alex@linutronix.de>
  1 file changed, 7 insertions(+), 7 deletions(-)
 
 diff --git a/common/homedir.c b/common/homedir.c
-index d26ddd9..24224c0 100644
+index 835f0ea..0a67a33 100644
 --- a/common/homedir.c
 +++ b/common/homedir.c
-@@ -1451,7 +1451,7 @@ gnupg_socketdir (void)
+@@ -1526,7 +1526,7 @@ gnupg_socketdir (void)
    if (!name)
      {
        unsigned int dummy;
@@ -25,7 +25,7 @@  index d26ddd9..24224c0 100644
        gpgrt_annotate_leaked_object (name);
      }
  
-@@ -1480,7 +1480,7 @@ gnupg_sysconfdir (void)
+@@ -1555,7 +1555,7 @@ gnupg_sysconfdir (void)
    if (dir)
      return dir;
    else
@@ -34,7 +34,7 @@  index d26ddd9..24224c0 100644
  #endif /*!HAVE_W32_SYSTEM*/
  }
  
-@@ -1516,7 +1516,7 @@ gnupg_bindir (void)
+@@ -1591,7 +1591,7 @@ gnupg_bindir (void)
        return name;
      }
    else
@@ -43,7 +43,7 @@  index d26ddd9..24224c0 100644
  #endif /*!HAVE_W32_SYSTEM*/
  }
  
-@@ -1543,7 +1543,7 @@ gnupg_libexecdir (void)
+@@ -1618,7 +1618,7 @@ gnupg_libexecdir (void)
        return name;
      }
    else
@@ -52,7 +52,7 @@  index d26ddd9..24224c0 100644
  #endif /*!HAVE_W32_SYSTEM*/
  }
  
-@@ -1573,7 +1573,7 @@ gnupg_libdir (void)
+@@ -1648,7 +1648,7 @@ gnupg_libdir (void)
        return name;
      }
    else
@@ -61,7 +61,7 @@  index d26ddd9..24224c0 100644
  #endif /*!HAVE_W32_SYSTEM*/
  }
  
-@@ -1604,7 +1604,7 @@ gnupg_datadir (void)
+@@ -1679,7 +1679,7 @@ gnupg_datadir (void)
        return name;
      }
    else
@@ -70,7 +70,7 @@  index d26ddd9..24224c0 100644
  #endif /*!HAVE_W32_SYSTEM*/
  }
  
-@@ -1636,7 +1636,7 @@ gnupg_localedir (void)
+@@ -1711,7 +1711,7 @@ gnupg_localedir (void)
        return name;
      }
    else
diff --git a/meta/recipes-support/gnupg/gnupg_2.5.20.bb b/meta/recipes-support/gnupg/gnupg_2.5.21.bb
similarity index 95%
rename from meta/recipes-support/gnupg/gnupg_2.5.20.bb
rename to meta/recipes-support/gnupg/gnupg_2.5.21.bb
index 4a72d8c8f0..e34c09fc8c 100644
--- a/meta/recipes-support/gnupg/gnupg_2.5.20.bb
+++ b/meta/recipes-support/gnupg/gnupg_2.5.21.bb
@@ -20,13 +20,13 @@  UPSTREAM_CHECK_URI = "https://gnupg.org/ftp/gcrypt/gnupg/"
 SRC_URI = "${GNUPG_MIRROR}/${BPN}/${BPN}-${PV}.tar.bz2 \
            file://0002-use-pkgconfig-instead-of-npth-config.patch \
            file://0001-Woverride-init-is-not-needed-with-gcc-9.patch \
-           file://CVE-2026-57062.patch \
+           file://relocate.patch \
            "
 SRC_URI:append:class-native = " file://0001-configure.ac-use-a-custom-value-for-the-location-of-.patch \
                                 file://relocate.patch"
 SRC_URI:append:class-nativesdk = " file://relocate.patch"
 
-SRC_URI[sha256sum] = "6461266e99c308419a379abe6c356d54c214136c4589bd65951091138989ffc6"
+SRC_URI[sha256sum] = "e3af2c8caa46a66a9329fa7c6880af260451914d819595beabc2c26597b31352"
 
 EXTRA_OECONF = "--disable-ldap \
 		--disable-ccid-driver \