From patchwork Thu Oct 1 06:31:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: auh@yoctoproject.org X-Patchwork-Id: 99788 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3CB93CA5FD7 for ; Thu, 1 Oct 2026 06:31:53 +0000 (UTC) Received: from a27-191.smtp-out.us-west-2.amazonses.com (a27-191.smtp-out.us-west-2.amazonses.com [54.240.27.191]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5425.1790836304317151112 for ; Wed, 30 Sep 2026 23:31:44 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@yoctoproject.org header.s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky header.b=mPKyO+Qv; dkim=pass header.i=@amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=3TyC5kse; spf=pass (domain: us-west-2.amazonses.com, ip: 54.240.27.191, mailfrom: 010101a0f62965ff-365a260b-5a0a-4c59-ac01-e840d45b41bd-000000@us-west-2.amazonses.com) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky; d=yoctoproject.org; t=1790836303; h=Content-Type:MIME-Version:From:To:Subject:Message-Id:Date; bh=HES4qXKJrae95bHcuSpqpbalA1WQ1NvVeVnDfyJika0=; b=mPKyO+QvLFrPlYWBZkHBkDoaK078CnYzfB6KSGfU1eKjUf6c0G2RWueO+wvcL8+Q e99JQ0NolA2xg5BUMoCNVcF1HHh7XVQiHd1jTxZ8HRev5KLN7Wsm/ddCcsUduCy/76+ nFRTqfmHbY5uhDVCi+KpSYquUOvMYQN+LTNmjTU0= DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=hsbnp7p3ensaochzwyq5wwmceodymuwv; d=amazonses.com; t=1790836303; h=Content-Type:MIME-Version:From:To:Subject:Message-Id:Date:Feedback-ID; bh=HES4qXKJrae95bHcuSpqpbalA1WQ1NvVeVnDfyJika0=; b=3TyC5ksemLWY5VB1Kl+THjimjKaSGzZ2RxqEwdNAYLb8ZLXzSlXQpdWRlpGONUhr I8fwdKX8MScxAX0EDMNwGjpDWE5HexEVhrF4rSd66WGd38TJfb/3SP5+mdwsBTeP9+l 3E+80fKgUkJMNsnrXDzxDBrQvO5JrwIkgQ3Mzg9w= MIME-Version: 1.0 From: auh@yoctoproject.org To: openembedded-core@lists.openembedded.org Subject: [AUH] harfbuzz: upgrading to 14.5.1 SUCCEEDED Message-ID: <010101a0f62965ff-365a260b-5a0a-4c59-ac01-e840d45b41bd-000000@us-west-2.amazonses.com> Date: Thu, 1 Oct 2026 06:31:43 +0000 Feedback-ID: ::1.us-west-2.9np3MYPs3fEaOBysGKSlUD4KtcmPijcmS9Az2Hwf7iQ=:AmazonSES X-SES-Outgoing: 2026.10.01-54.240.27.191 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 01 Oct 2026 06:31:53 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247007 Hello, this email is a notification from the Auto Upgrade Helper that the automatic attempt to upgrade the recipe(s) *harfbuzz* to *14.5.1* has Succeeded. Next steps: - apply the patch: git am 0001-harfbuzz-upgrade-14.5.0-14.5.1.patch - check the changes to upstream patches and summarize them in the commit message, - compile an image that contains the package - perform some basic sanity tests - amend the patch and sign it off: git commit -s --reset-author --amend - send it to the appropriate mailing list Alternatively, if you believe the recipe should not be upgraded at this time, you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that automatic upgrades would no longer be attempted. Please review the attached files for further information and build/update failures. Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler Regards, The Upgrade Helper -- >8 -- From cc1bd71f146542e1d3003495b7106ced1fe062e2 Mon Sep 17 00:00:00 2001 From: Upgrade Helper Date: Thu, 1 Oct 2026 06:11:55 +0000 Subject: [PATCH] harfbuzz: upgrade 14.5.0 -> 14.5.1 Overview of changes leading to 14.5.1 Thursday, October 1, 2026 ===================================== - Map the `fonupa` (Uralic Phonetic Alphabet) BCP 47 variant to the `UPPH` OpenType language system tag. - Produce smaller `cmap` subtables and drop no-op variation device tables when subsetting. - Fix possible deadlock in `hb_font_destroy()` after `hb_ft_font_set_funcs()`, a regression from 14.5.0. - Fix signed integer overflows when scaling glyph extents and applying synthetic slant and emboldening. - Fix float-to-int overflow in `VARC` component axis coordinates with malformed fonts. - Fix a memory leak in the experimental WebAssembly shaper when shaping with features. - Fix accumulator overflows in the experimental raster library when rendering glyphs with very many overlapping edges. - Fix heap buffer overflow in the experimental GPU library with malicious `COLR` fonts. - Various build and CI fixes. --- .../harfbuzz/{harfbuzz_14.5.0.bb => harfbuzz_14.5.1.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-graphics/harfbuzz/{harfbuzz_14.5.0.bb => harfbuzz_14.5.1.bb} (96%) diff --git a/meta/recipes-graphics/harfbuzz/harfbuzz_14.5.0.bb b/meta/recipes-graphics/harfbuzz/harfbuzz_14.5.1.bb similarity index 96% rename from meta/recipes-graphics/harfbuzz/harfbuzz_14.5.0.bb rename to meta/recipes-graphics/harfbuzz/harfbuzz_14.5.1.bb index 438aa23133..d10f1bfa01 100644 --- a/meta/recipes-graphics/harfbuzz/harfbuzz_14.5.0.bb +++ b/meta/recipes-graphics/harfbuzz/harfbuzz_14.5.1.bb @@ -9,7 +9,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=b98429b8e8e3c2a67cfef01e99e4893d \ " SRC_URI = "${GITHUB_BASE_URI}/download/${PV}/${BPN}-${PV}.tar.xz" -SRC_URI[sha256sum] = "b7132e148358a45185c9feafd049dbaf243649d3c44414b3534d9c95d18592b9" +SRC_URI[sha256sum] = "7e2fa4e8c7c98e8d8140671f5772542afaaa6acccfbd746506886b6d85f7f8d6" inherit meson pkgconfig lib_package gtk-doc gobject-introspection github-releases