diff mbox series

[06/10] dropbear: upgrade 2026.92 -> 2026.94

Message ID 20260727064158.3784068-6-richard.purdie@linuxfoundation.org
State New
Headers show
Series [01/10] libical: upgrade 4.0.3 -> 4.0.4 | expand

Commit Message

Richard Purdie July 27, 2026, 6:41 a.m. UTC
2026.94 - 23 July 2026

- Fix scp build failure regression from 2026.93
  The new ascii_isdigit() etc wasn't linked.

- Print square brackets around ipv6 addresses with ports, eg
  [2a00:f10:400:2:1c00:bcff:fe00:1c6]:22
  Patch from Seo Suchan

- Support longer paths in scp.

- Avoid some build warnings, add increase github action coverage of
  config options.

2026.93 - 21 July 2026

Note >> for compatibility/configuration changes

- Security: Fix a use-after-free in X11 forwarding that could possibly lead
  to memory corruption. This is vulnerable to authenticated users if X11
  forwarding is enabled. By default X11 forwarding is not built.
  In 2026.89 the server is running as the authenticated user for X11
  forwarding, in earlier versions it runs as root.
  This removes X11 "single connection" which has probably never been used.
  Reported by @peter-pe
  https://github.com/mkj/dropbear/commit/882f83806d5e133037cd28e954a878984ef7b9c4

- >> "permitlisten" authorized_keys lines will now be ignored if
  the port is invalid (>65535). From Basavaraj S Maneppagol.

- >> In 2026.92, the configure option --enable-plugin-deprecated
  wasn't correctly renamed. This is now implemented.
  Patch from Alexander Dahl

- Two factor auth "-t" is no longer deprecated, it will be kept.
  The "DEPRECATED_TWO_FACTOR" option is ignored, and no longer required.

- Fix out of bounds read during utmp/wtmp log file handling, reported by
  Basavaraj S Maneppagol.

- More robust handling of ascii inputs for some platforms.
  From Basavaraj S Maneppagol

- Convert manpages to mdoc format, from shrub

  [Updated 16 July: This is no longer planned to be removed, future releases
  will ignore DEPRECATED_TWO_FACTOR and always enable it, like previously]

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
---
 .../dropbear/{dropbear_2026.92.bb => dropbear_2026.94.bb}       | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
 rename meta/recipes-core/dropbear/{dropbear_2026.92.bb => dropbear_2026.94.bb} (98%)

Comments

patchtest@automation.yoctoproject.org July 27, 2026, 6:50 a.m. UTC | #1
Thank you for your submission. Patchtest identified one
or more issues with the patch. Please see the log below for
more information:

---
Testing patch /home/patchtest/share/mboxes/06-10-dropbear-upgrade-2026.92---2026.94.patch

FAIL: test commit message user tags: Mbox includes one or more GitHub-style username tags. Ensure that any "@" symbols are stripped out of usernames (test_mbox.TestMbox.test_commit_message_user_tags)

PASS: pretest src uri left files (test_metadata.TestMetadata.pretest_src_uri_left_files)
PASS: test CVE check ignore (test_metadata.TestMetadata.test_cve_check_ignore)
PASS: test Signed-off-by presence (test_mbox.TestMbox.test_signed_off_by_presence)
PASS: test author valid (test_mbox.TestMbox.test_author_valid)
PASS: test commit message presence (test_mbox.TestMbox.test_commit_message_presence)
PASS: test lic files chksum modified not mentioned (test_metadata.TestMetadata.test_lic_files_chksum_modified_not_mentioned)
PASS: test max line length (test_metadata.TestMetadata.test_max_line_length)
PASS: test mbox format (test_mbox.TestMbox.test_mbox_format)
PASS: test non-AUH upgrade (test_mbox.TestMbox.test_non_auh_upgrade)
PASS: test shortlog format (test_mbox.TestMbox.test_shortlog_format)
PASS: test shortlog length (test_mbox.TestMbox.test_shortlog_length)
PASS: test src uri left files (test_metadata.TestMetadata.test_src_uri_left_files)
PASS: test target mailing list (test_mbox.TestMbox.test_target_mailing_list)

SKIP: pretest pylint: No python related patches, skipping test (test_python_pylint.PyLint.pretest_pylint)
SKIP: test CVE tag format: No new source patches introduced (test_patch.TestPatch.test_cve_tag_format)
SKIP: test Signed-off-by presence: No new source patches introduced (test_patch.TestPatch.test_signed_off_by_presence)
SKIP: test Upstream-Status presence: No new source patches introduced (test_patch.TestPatch.test_upstream_status_presence_format)
SKIP: test bugzilla entry format: No bug ID found (test_mbox.TestMbox.test_bugzilla_entry_format)
SKIP: test lic files chksum presence: No added recipes, skipping test (test_metadata.TestMetadata.test_lic_files_chksum_presence)
SKIP: test license presence: No added recipes, skipping test (test_metadata.TestMetadata.test_license_presence)
SKIP: test pylint: No python related patches, skipping test (test_python_pylint.PyLint.test_pylint)
SKIP: test series merge on head: Merge test is disabled for now (test_mbox.TestMbox.test_series_merge_on_head)
SKIP: test summary presence: No added recipes, skipping test (test_metadata.TestMetadata.test_summary_presence)

---

Please address the issues identified and
submit a new revision of the patch, or alternatively, reply to this
email with an explanation of why the patch should be accepted. If you
believe these results are due to an error in patchtest, please submit a
bug at https://bugzilla.yoctoproject.org/ (use the 'Patchtest' category
under 'Yocto Project Subprojects'). For more information on specific
failures, see: https://wiki.yoctoproject.org/wiki/Patchtest. Thank
you!
diff mbox series

Patch

diff --git a/meta/recipes-core/dropbear/dropbear_2026.92.bb b/meta/recipes-core/dropbear/dropbear_2026.94.bb
similarity index 98%
rename from meta/recipes-core/dropbear/dropbear_2026.92.bb
rename to meta/recipes-core/dropbear/dropbear_2026.94.bb
index 4d9a9e10ebc..dd9863d96d1 100644
--- a/meta/recipes-core/dropbear/dropbear_2026.92.bb
+++ b/meta/recipes-core/dropbear/dropbear_2026.94.bb
@@ -27,7 +27,7 @@  SRC_URI = "http://matt.ucc.asn.au/dropbear/releases/dropbear-${PV}.tar.bz2 \
            ${@bb.utils.contains('DISTRO_FEATURES', 'pam', '${PAM_SRC_URI}', '', d)} \
            "
 
-SRC_URI[sha256sum] = "91dcb5234de8dea68dd82c55411c9fc986b457ab58372a780ee8a870419c2f7e"
+SRC_URI[sha256sum] = "e098034a843699200c8c977a991fff73159735bf795d5f72ef672c41a6b1ae81"
 MIRRORS += "http://matt.ucc.asn.au/dropbear/releases/ https://dropbear.nl/mirror/releases/"
 
 PAM_SRC_URI = "file://0005-dropbear-enable-pam.patch \