From patchwork Tue Aug 11 07:23:49 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: auh@yoctoproject.org X-Patchwork-Id: 94935 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7D371C5CFED for ; Tue, 11 Aug 2026 07:24:01 +0000 (UTC) Received: from a27-30.smtp-out.us-west-2.amazonses.com (a27-30.smtp-out.us-west-2.amazonses.com [54.240.27.30]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.49078.1786433030909749959 for ; Tue, 11 Aug 2026 00:23:51 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@yoctoproject.org header.s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky header.b=hM7HBejC; dkim=pass header.i=@amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=a7AIMdMx; spf=pass (domain: us-west-2.amazonses.com, ip: 54.240.27.30, mailfrom: 0101019fefb4c738-f00e78f1-8fad-45cf-896f-01d3952b1b0d-000000@us-west-2.amazonses.com) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky; d=yoctoproject.org; t=1786433030; h=Content-Type:MIME-Version:From:To:Cc:Subject:Message-Id:Date; bh=JMuvrVpd2Aa8r9Td9TMasAZ2/gecyl3u+N3si113Oms=; b=hM7HBejCyg1uJiFO65p96U9EH1qgUY3Zk/9JxuW31Gxv/IoFKjNf7cQoxRuxtVN9 L8yjMfz5AtVcsTs767v2O+jm6p0QSgTEweiWXjiG5E8x7Mk+OfqdpuR2An0kSzosmPJ 7zEvMVn5CSRrR9n0dZ7XH6dvk0zTcLsF+xvezkCY= DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=hsbnp7p3ensaochzwyq5wwmceodymuwv; d=amazonses.com; t=1786433030; h=Content-Type:MIME-Version:From:To:Cc:Subject:Message-Id:Date:Feedback-ID; bh=JMuvrVpd2Aa8r9Td9TMasAZ2/gecyl3u+N3si113Oms=; b=a7AIMdMx6A9SSnPNuiAe5/sQplL7/PxI2pUMRe5n8ilw1c5cA5rX8cQh0WcNaGkH eU3FcKeT+rXLKFDomboZL/ZDAhgdGPm8b15Zmp7y1Uu/svWNOVlpFmiLpOT2oEk03DG yxltKp+W6I1eeQcy74v2ZNEDHeTvhY91yk5SX28s= MIME-Version: 1.0 From: auh@yoctoproject.org To: Yi Zhao Cc: openembedded-core@lists.openembedded.org Subject: [AUH] expat: upgrading to 2.8.3 FAILED Message-ID: <0101019fefb4c738-f00e78f1-8fad-45cf-896f-01d3952b1b0d-000000@us-west-2.amazonses.com> Date: Tue, 11 Aug 2026 07:23:49 +0000 Feedback-ID: ::1.us-west-2.9np3MYPs3fEaOBysGKSlUD4KtcmPijcmS9Az2Hwf7iQ=:AmazonSES X-SES-Outgoing: 2026.08.11-54.240.27.30 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 11 Aug 2026 07:24:01 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/243157 Hello, this email is a notification from the Auto Upgrade Helper that the automatic attempt to upgrade the recipe(s) *expat* to *2.8.3* has Failed(do_compile). Detailed error information: do_compile failed Next steps: - apply the patch: git am 0001-expat-upgrade-2.8.2-2.8.3.patch - check the changes to upstream patches and summarize them in the commit message, - compile an image that contains the package - perform some basic sanity tests - amend the patch and sign it off: git commit -s --reset-author --amend - send it to the appropriate mailing list Alternatively, if you believe the recipe should not be upgraded at this time, you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that automatic upgrades would no longer be attempted. Please review the attached files for further information and build/update failures. Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler Regards, The Upgrade Helper -- >8 -- From d2b7e4be9455f116b71ec1954850b265ac72c63f Mon Sep 17 00:00:00 2001 From: Upgrade Helper Date: Tue, 11 Aug 2026 05:33:49 +0000 Subject: [PATCH] expat: upgrade 2.8.2 -> 2.8.3 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Source: Changes !! Expat has UNFIXED SECURITY ISSUES! !! !! Please see https://github.com/libexpat/libexpat/issues/1160 for details. !! !! Starting 2026-08-01, for up to six months my work maintaining libexpat !! !! will be funded by the City of Munich as part of their !! !! Open Source Sabbatical (https://opensource.muenchen.de/sabbatical.html) !! !! — thank you! !! !! Sebastian Pipping -- Berlin, 2026-08-03 !! Release 2.8.3 Mon August 10 2026 Security fixes: #1296 CVE-2026-72522 -- Fix an out-of-bounds read and the resulting infinite loop caused by treating low surrogates (Unicode) the same as high surrogates in functions *_toUtf16. Needs Expat compiled with 16bit character support (e.g. with Firefox and/or on Windows) to be affected. Upstream CVSS 3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (CVSS score: 7.5) (Note the "AV:N" for network/remote, the "AV:L" in NVD by Mitre is mistaken.) Original bug report from Mozilla at: https://bugzilla.mozilla.org/show_bug.cgi?id=2053153 Bug fixes: #1297 #1300 lib: Fix support for 2+ GiB documents (regression from 2.8.2) #1286 lib: Reject empty version in the XML declaration #1305 #1306 lib: Fix printf format for AIX Other changes: #1309 CMake|AIX: Enable EXPAT_DEV_URANDOM by default for AIX #1295 CMake|Windows: Add a 64bit MinGW toolchain file #1287 #1289 CMake|Windows: Start invoking MSVC with /source-charset:utf-8 #1289 CMake|Windows: Start requiring MSVC 2015 Update 2 or later #1300 Document the current wrap-around issues with functions - XML_GetCurrentByteIndex - XML_GetCurrentColumnNumber - XML_GetCurrentLineNumber - XML_GetAttributeInfo explicitly. #1303 Address Clang Static Analyzer 22 warning `core.NullPointerArithm` #1313 #1314 Version info bumped from 13:2:12 (libexpat*.so.1.12.2) to 13:3:12 (libexpat*.so.1.12.3); see https://verbump.de/ for what these numbers do Infrastructure: #1311 CI: Limit workflow runtime and package installation runtime #1310 CI: Pin Cppcheck version for a robust CI #1310 CI: Migrate Cppcheck CI from macOS to Linux #1312 CI: Get CFLAGS and CXXFLAGS back in sync for both Emscripten and WASI SDK #1304 CI: Activate AddressSanitizer for MSVC Windows CI #1308 CI: Introduce zizmor static analysis for GitHub Actions #1308 C [Changelog truncated as it exceeds 3000 characters; the full changelog can be found in an attachment to the AUH email] --- meta/recipes-core/expat/{expat_2.8.2.bb => expat_2.8.3.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-core/expat/{expat_2.8.2.bb => expat_2.8.3.bb} (92%) diff --git a/meta/recipes-core/expat/expat_2.8.2.bb b/meta/recipes-core/expat/expat_2.8.3.bb similarity index 92% rename from meta/recipes-core/expat/expat_2.8.2.bb rename to meta/recipes-core/expat/expat_2.8.3.bb index 0b9dbe161b..79e8c15227 100644 --- a/meta/recipes-core/expat/expat_2.8.2.bb +++ b/meta/recipes-core/expat/expat_2.8.3.bb @@ -15,7 +15,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" UPSTREAM_CHECK_REGEX = "releases/tag/R_(?P.+)" -SRC_URI[sha256sum] = "69e7f52417d85b1c2b7fe855e176eec55d0b2d7d92d691372d833a1c7df7923b" +SRC_URI[sha256sum] = "b4cc2483927d5e90bf8c40b44a6b95b368b42a8a96e25883fce188b48a92b670" EXTRA_OECMAKE:class-native += "-DEXPAT_BUILD_DOCS=OFF"