diff mbox series

[AUH] libpng: upgrading to 1.6.59 SUCCEEDED

Message ID 010101a1006da796-758bc284-7c22-4dfb-beeb-7a85c2beb726-000000@us-west-2.amazonses.com
State New
Headers show
Series [AUH] libpng: upgrading to 1.6.59 SUCCEEDED | expand

Commit Message

auh@yoctoproject.org Oct. 3, 2026, 6:22 a.m. UTC
Hello,

this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe(s) *libpng* to *1.6.59* has Succeeded.

Next steps:
    - apply the patch: git am 0001-libpng-upgrade-1.6.58-1.6.59.patch
    - check the changes to upstream patches and summarize them in the commit message,
    - compile an image that contains the package
    - perform some basic sanity tests
    - amend the patch and sign it off: git commit -s --reset-author --amend
    - send it to the appropriate mailing list

Alternatively, if you believe the recipe should not be upgraded at this time,
you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that
automatic upgrades would no longer be attempted.

Please review the attached files for further information and build/update failures.
Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler

Regards,
The Upgrade Helper

-- >8 --
From 083c6a33018a5a34bb398a04cb673056dec99f0c Mon Sep 17 00:00:00 2001
From: Upgrade Helper <auh@yoctoproject.org>
Date: Sat, 3 Oct 2026 05:43:30 +0000
Subject: [PATCH] libpng: upgrade 1.6.58 -> 1.6.59

Version 1.6.59 [September 28, 2026]
  Fixed CVE-2026-46675 (medium severity):
    Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt
    or iCCP decompression.
    (Reported independently by Ze Sheng and
    <JasonHonKL@users.noreply.github.com>.)
  Fixed a regression introduced in version 1.6.47 that caused libpng to reject
    hIST chunks in their correct position, after PLTE.
    (Contributed by Yuki Sekiguchi.)
  Prevented a double free of `png_struct` members after an allocation failure.
    (Contributed by Anthony Hurtado.)
  Applied fixes and updates to the CMake build.
  Adopted the REUSE Specification for licensing the CI files.
---
 ...0001-tests-stream-per-test-results-to-stdout.patch | 11 ++++-------
 .../libpng/{libpng_1.6.58.bb => libpng_1.6.59.bb}     |  2 +-
 2 files changed, 5 insertions(+), 8 deletions(-)
 rename meta/recipes-multimedia/libpng/{libpng_1.6.58.bb => libpng_1.6.59.bb} (97%)
diff mbox series

Patch

diff --git a/meta/recipes-multimedia/libpng/files/0001-tests-stream-per-test-results-to-stdout.patch b/meta/recipes-multimedia/libpng/files/0001-tests-stream-per-test-results-to-stdout.patch
index 139495d211..0c5e742bc1 100644
--- a/meta/recipes-multimedia/libpng/files/0001-tests-stream-per-test-results-to-stdout.patch
+++ b/meta/recipes-multimedia/libpng/files/0001-tests-stream-per-test-results-to-stdout.patch
@@ -1,4 +1,4 @@ 
-From e0898e243cbef677a862612f04b6bca2b07c2453 Mon Sep 17 00:00:00 2001
+From 22ec13788d1003de4b4f89eaaf47f28fe61523b2 Mon Sep 17 00:00:00 2001
 From: Trevor Gamblin <tgamblin@baylibre.com>
 Date: Wed, 12 Aug 2026 12:22:54 -0400
 Subject: [PATCH] tests: stream per-test results to stdout
@@ -34,7 +34,7 @@  Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
  create mode 100755 test-driver-tee
 
 diff --git a/Makefile.am b/Makefile.am
-index eb7078158..a2e64fbe6 100644
+index fa5bbeb..8092616 100644
 --- a/Makefile.am
 +++ b/Makefile.am
 @@ -111,6 +111,12 @@ TESTS =\
@@ -50,7 +50,7 @@  index eb7078158..a2e64fbe6 100644
  endif
  
  # man pages
-@@ -165,7 +171,7 @@ pkgconfig_DATA = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.pc
+@@ -216,7 +222,7 @@ pkgconfig_DATA = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.pc
  # not done in the source directory!
  EXTRA_DIST= \
  	ANNOUNCE AUTHORS CHANGES INSTALL LICENSE README TODO TRADEMARK \
@@ -61,7 +61,7 @@  index eb7078158..a2e64fbe6 100644
  	CMakeLists.txt example.c libpng-manual.txt
 diff --git a/test-driver-tee b/test-driver-tee
 new file mode 100755
-index 000000000..a6d5aa027
+index 0000000..a6d5aa0
 --- /dev/null
 +++ b/test-driver-tee
 @@ -0,0 +1,167 @@
@@ -232,6 +232,3 @@  index 000000000..a6d5aa027
 +# time-stamp-time-zone: "UTC0"
 +# time-stamp-end: "; # UTC"
 +# End:
--- 
-2.55.0
-
diff --git a/meta/recipes-multimedia/libpng/libpng_1.6.58.bb b/meta/recipes-multimedia/libpng/libpng_1.6.59.bb
similarity index 97%
rename from meta/recipes-multimedia/libpng/libpng_1.6.58.bb
rename to meta/recipes-multimedia/libpng/libpng_1.6.59.bb
index 928b010c9c..4dbd769cf7 100644
--- a/meta/recipes-multimedia/libpng/libpng_1.6.58.bb
+++ b/meta/recipes-multimedia/libpng/libpng_1.6.59.bb
@@ -15,7 +15,7 @@  SRC_URI = "${SOURCEFORGE_MIRROR}/${BPN}/${BPN}${LIBV}/${BP}.tar.xz \
            file://0001-tests-stream-per-test-results-to-stdout.patch \
 "
 
-SRC_URI[sha256sum] = "28eb403f51f0f7405249132cecfe82ea5c0ef97f1b32c5a65828814ae0d34775"
+SRC_URI[sha256sum] = "d80dd2a38a37f803cb9b6ac7b14bd6e74ddc3b654780a8380bdf93523fdb4389"
 
 MIRRORS += "${SOURCEFORGE_MIRROR}/project/${BPN}/${BPN}${LIBV}/ ${SOURCEFORGE_MIRROR}/project/${BPN}/${BPN}${LIBV}/older-releases/"