mbox

[wrynose,00/28] Patch review

Message ID cover.1790494949.git.yoann.congal@smile.fr
State Not Applicable, archived
Headers show

Pull-request

https://git.openembedded.org/openembedded-core-contrib stable/wrynose-review

Message

Yoann Congal Sept. 27, 2026, 7:42 a.m. UTC
Please review this set of changes for wrynose and have comments back by
end of day Tuesday, September 29.

Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/?#/builders/29/builds/4811

The following changes since commit cc4695f65beb6e5069fbecc16475fa5a27c768e9:

  mesa: align x86 mesa config with LLVM graphics (2026-09-24 12:36:03 +0200)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/wrynose-review
  https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/wrynose-review

for you to fetch changes up to 40993b0c42411caa5df71a75739b569fdffe981f:

  linux-yocto/6.18: fix kernel reproducibility issues (2026-09-26 23:10:37 +0200)

----------------------------------------------------------------

Adrian Freihofer (1):
  bitbake.conf: pseudo add rootfs-dbg to PSEUDO_INCLUDE_PATHS

Ankur Tyagi (3):
  ffmpeg: mark CVE-2026-52295, CVE-2026-52296 and CVE-2026-52297 fixed
  libxfont2: patch CVE-2026-59679
  libxfont2: patch CVE-2026-44950

Benjamin Robin (3):
  sbom-cve-check-update-db: Exclude recipes from rm_work
  python3-sbom-cve-check: update to version 1.3.4
  python3-sbom-cve-check: update to version 1.3.5

Bhavesh R Maheshwari (3):
  ffmpeg: Fix for CVE-2026-66037
  ffmpeg: Fix for CVE-2026-66038
  ffmpeg: Fix for CVE-2026-66039

Bruce Ashfield (4):
  linux-yocto/6.18: rt: update to v6.18.37-rt6
  linux-yocto/6.18: update to v6.18.50
  linux-yocto/6.18: update to v6.18.52
  linux-yocto/6.18: fix kernel reproducibility issues

Daniel Dragomir (1):
  toolchain-scripts: fix kernel host tool builds broken in the SDK

Devansh Patel (1):
  vim: Fix CVE-2026-28417 hostname regression

Jonas Juffinger (1):
  kernel-fit-image: Don't add hash node when signing is enabled

Peter Marko (2):
  go: upgrade 1.26.7 -> 1.26.8
  fmt: update branch name to main

Richard Purdie (4):
  dhcpcd: upgrade 10.3.1 -> 10.3.2
  sbom-cve-check-update-{nvd-native,cvelist-native}: upgrade 2026.08.25
    -> 2026.09.12
  sstate: Update mtime/atime for sig/siginfo files in
    sstate_checkhashes()
  sstate: Update unpack touch code to be consistent

Roopa Kalmath (1):
  qemu: fix CVE-2026-48914

Tim Orling (1):
  at-spi2-core: RDEPENDS on gsettings-desktop-schemas

Wang Mingyu (1):
  sbom-cve-check-update-nvd-native,sbom-cve-check-update-cvelist-native:
    upgrade 2026.08.03-000011 -> 2026.08.25-000009

Xiuzhuo Shang (1):
  bluez5: restrict delta=0 RSSI to proximity filters

Yoann Congal (1):
  cpio: fix "CVE:" marker in CVE-2026-66484.patch

 meta/classes-global/sstate.bbclass            | 16 +--
 meta/classes-recipe/toolchain-scripts.bbclass |  2 +
 meta/conf/bitbake.conf                        |  2 +-
 meta/lib/oe/fitimage.py                       |  2 +-
 meta/lib/oeqa/selftest/cases/fitimage.py      |  8 +-
 meta/recipes-connectivity/bluez5/bluez5.inc   |  1 +
 ...ct-delta-0-RSSI-to-proximity-filters.patch | 86 ++++++++++++++++
 .../{dhcpcd_10.3.1.bb => dhcpcd_10.3.2.bb}    |  2 +-
 ...mprove-the-sitation-of-working-with-.patch |  2 +-
 ...-conflict-error-when-enable-multilib.patch |  4 +-
 ...e-INCLUDEDIR-to-prevent-build-issues.patch |  4 +-
 meta/recipes-devtools/fmt/fmt_12.1.0.bb       |  2 +-
 .../go/{go-1.26.7.inc => go-1.26.8.inc}       |  2 +-
 ...e_1.26.7.bb => go-binary-native_1.26.8.bb} |  6 +-
 ..._1.26.7.bb => go-cross-canadian_1.26.8.bb} |  0
 ...{go-cross_1.26.7.bb => go-cross_1.26.8.bb} |  0
 ...osssdk_1.26.7.bb => go-crosssdk_1.26.8.bb} |  0
 ...runtime_1.26.7.bb => go-runtime_1.26.8.bb} |  0
 .../go/{go_1.26.7.bb => go_1.26.8.bb}         |  0
 meta/recipes-devtools/qemu/qemu.inc           |  1 +
 .../qemu/qemu/CVE-2026-48914.patch            | 60 +++++++++++
 ...3.3.bb => python3-sbom-cve-check_1.3.5.bb} |  2 +-
 ...check-update-cvelist-native_2026-09-12.bb} |  2 +-
 .../sbom-cve-check-update-db.inc              |  1 +
 ...ck-update-nvd-native_2026.09.12-000023.bb} |  2 +-
 .../cpio/files/CVE-2026-66484.patch           |  2 +-
 .../xorg-lib/libxfont2/CVE-2026-44950.patch   | 99 +++++++++++++++++++
 .../xorg-lib/libxfont2/CVE-2026-59679.patch   | 93 +++++++++++++++++
 .../xorg-lib/libxfont2_2.0.7.bb               |  2 +
 .../linux/linux-yocto-rt_6.18.bb              |  6 +-
 .../linux/linux-yocto-tiny_6.18.bb            |  6 +-
 meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 ++---
 .../ffmpeg/ffmpeg/CVE-2026-66037.patch        | 39 ++++++++
 .../ffmpeg/ffmpeg/CVE-2026-66038.patch        | 50 ++++++++++
 .../ffmpeg/ffmpeg/CVE-2026-66039.patch        | 38 +++++++
 .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb |  6 ++
 .../atk/at-spi2-core_2.60.0.bb                |  2 +
 .../vim/files/CVE-2026-28417-regression.patch | 65 ++++++++++++
 meta/recipes-support/vim/vim.inc              |  1 +
 39 files changed, 596 insertions(+), 44 deletions(-)
 create mode 100644 meta/recipes-connectivity/bluez5/bluez5/0001-adapter-restrict-delta-0-RSSI-to-proximity-filters.patch
 rename meta/recipes-connectivity/dhcpcd/{dhcpcd_10.3.1.bb => dhcpcd_10.3.2.bb} (97%)
 rename meta/recipes-devtools/go/{go-1.26.7.inc => go-1.26.8.inc} (90%)
 rename meta/recipes-devtools/go/{go-binary-native_1.26.7.bb => go-binary-native_1.26.8.bb} (80%)
 rename meta/recipes-devtools/go/{go-cross-canadian_1.26.7.bb => go-cross-canadian_1.26.8.bb} (100%)
 rename meta/recipes-devtools/go/{go-cross_1.26.7.bb => go-cross_1.26.8.bb} (100%)
 rename meta/recipes-devtools/go/{go-crosssdk_1.26.7.bb => go-crosssdk_1.26.8.bb} (100%)
 rename meta/recipes-devtools/go/{go-runtime_1.26.7.bb => go-runtime_1.26.8.bb} (100%)
 rename meta/recipes-devtools/go/{go_1.26.7.bb => go_1.26.8.bb} (100%)
 create mode 100644 meta/recipes-devtools/qemu/qemu/CVE-2026-48914.patch
 rename meta/recipes-devtools/sbom-cve-check/{python3-sbom-cve-check_1.3.3.bb => python3-sbom-cve-check_1.3.5.bb} (82%)
 rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-cvelist-native_2026-08-03.bb => sbom-cve-check-update-cvelist-native_2026-09-12.bb} (89%)
 rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-nvd-native_2026.08.03-000011.bb => sbom-cve-check-update-nvd-native_2026.09.12-000023.bb} (89%)
 create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-44950.patch
 create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-59679.patch
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66037.patch
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66038.patch
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66039.patch
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-28417-regression.patch