From patchwork Sat Jan 24 05:32:11 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Gyorgy Sarvari X-Patchwork-Id: 79555 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 001CCD715C1 for ; Sat, 24 Jan 2026 05:32:22 +0000 (UTC) Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.13628.1769232737888150285 for ; Fri, 23 Jan 2026 21:32:18 -0800 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20230601 header.b=ent5WEJ4; spf=pass (domain: gmail.com, ip: 209.85.128.47, mailfrom: skandigraun@gmail.com) Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-47ee937ecf2so24425695e9.0 for ; Fri, 23 Jan 2026 21:32:17 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1769232736; x=1769837536; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:from:to:cc:subject:date:message-id:reply-to; bh=OftCGg8bcsgktXpatKNIWm1p/oLhgm40MktJX4eWZGI=; b=ent5WEJ4ntmhbOoOP8g2023V6WrShAfY7iYbJdG+3jy4zM7bIDeE/5E2Hj/fEDxoCq BbEnvbS8PMKk7B1+Dp10AUKLMPXfoPxYAcn6UVfsmYmqQFkJ20niskS+Wkt7KMQ/qjxT s+crNuPxmFFlODxeU4KQXndCkRLzWucFvsYrSdn7rqw1W/8BzuefoplJKhCOUWk59c0s lM5FEeoUmzfhOzpqjH+ioOMSo96XQZrTqGxjP3vjnq5drqalyPN3rhCfXpBBfZ1aB1R1 0SxlPmUI1Wc2s8Y/D7g9ZVv3OUIlX7gh6ODVrOridA/VjTeu/JHzmPDF0dgUyduuIjpI QFnQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1769232736; x=1769837536; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=OftCGg8bcsgktXpatKNIWm1p/oLhgm40MktJX4eWZGI=; b=u/jwrP9q8sgOac1u7eTktW6gpZbByDLwTUIl7Jx4l6GmcdYEgNlInw+QMbAGW4hVNV u57jrCDp9H7IzyvnE09knxUwpasFrJqeoVEYT2FEUBNh8VqgRfaZ4MralWB6bp86idMD krvZNdsnIRiUqj23UsefZH3HXwVHC0g0HhpzlMKqnQWG+rXbc33qJoQVZ73AJ5iTWwhM 1w1WCWl3e6bptpYY3t+D5kVu+CID22MpzSlFcTs1UClbUtPhNNtDhogghd/oIbzqztit m8ePkuP+1a213G70wYFWzXW6R1/2OAfEpLj3Xn6fdU4A/VoPjpd2iPUQInvwE0eMt1vu ek9Q== X-Gm-Message-State: AOJu0Yz/wsz3iej6L8LXdHSgcDwNaVSPW4/mtHSK9CXlxD/xxan2bLKw lBUm3HQAXf7v2ZSDbUG/8/Jx2AyjTWk4PA+9e32SwGsJtBEKiK1WfyHMsuyZ3w== X-Gm-Gg: AZuq6aIJ5u+PVsiI/W2X32xhIUK6UBRpYQBvKDGkg0DjOLCOTCwCttgx7vGWz/3Ieno 6myfwOdPZ5N0gqzAebyZ1ZWhtZZdhRVfmNsL2r1Axc5dB6/Usr8syHU0xvxRczuRfF2UPDh4cgC RTjgYcBGg+GrIGp94TdjUlaqJOmdFtukeX41H1AxzJh7jbZORrfNDpqiWL3F4FuOO3emQcUQyVf xb9AOB5xYw4cnr2X6qMleLxElWgmNiJY4SohyIpWwmYrjQy8orBjLPgkmZvYlXLMQozgvH3FIiK bK60/86aNDdxvrILHNqU4cA+jyf4trfrnu3wVDaJZjYxJDK9/OiTbXNyMNLcZ/czKOm8YOUVatG L43vNTmQEoe7fWL+4KDar3/Er/Ots7XCIWjaaO8tX94kcMkLyJURUfN8YsAN3sIgDqkBORKlX80 fi8CWeV4f+ X-Received: by 2002:a05:600c:820c:b0:47e:e59c:67c5 with SMTP id 5b1f17b1804b1-4804d2bea8fmr80154545e9.8.1769232735866; Fri, 23 Jan 2026 21:32:15 -0800 (PST) Received: from desktop ([51.154.145.205]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4804dbb6315sm40746155e9.4.2026.01.23.21.32.15 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 23 Jan 2026 21:32:15 -0800 (PST) From: Gyorgy Sarvari To: openembedded-devel@lists.openembedded.org Subject: [meta-python][kirkstone][PATCH 1/5] python3-paramiko: upgrade 2.10.3 -> 2.10.6 Date: Sat, 24 Jan 2026 06:32:11 +0100 Message-ID: <20260124053215.4066209-1-skandigraun@gmail.com> X-Mailer: git-send-email 2.52.0 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 24 Jan 2026 05:32:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/123802 Bugfix releases. Changelog: 2.10.4: - Servers offering certificate variants of hostkey algorithms (eg ssh-rsa-cert-v01@openssh.com) could not have their host keys verified by Paramiko clients, as it only ever considered non-cert key types for that part of connection handshaking. This has been fixed. - PKey instances’ __eq__ did not have the usual safety guard in place to ensure they were being compared to another PKey object, causing occasional spurious BadHostKeyException (among other things). This has been fixed. - Update camelCase method calls against the threading module to be snake_case; this and related tweaks should fix some deprecation warnings under Python 3.10. 2.10.5: - Windows-native SSH agent support as merged in 2.10 could encounter Errno 22 OSError exceptions in some scenarios (eg server not cleanly closing a relevant named pipe). This has been worked around and should be less problematic. - OpenSSH 7.7 and older has a bug preventing it from understanding how to perform SHA2 signature verification for RSA certificates (specifically certs - not keys), so when we added SHA2 support it broke all clients using RSA certificates with these servers. This has been fixed in a manner similar to what OpenSSH’s own client does: a version check is performed and the algorithm used is downgraded if needed. - Align signature verification algorithm with OpenSSH re: zero-padding signatures which don’t match their nominal size/length. This shouldn’t affect most users, but will help Paramiko-implemented SSH servers handle poorly behaved clients such as PuTTY. 2.10.6: - Raise SSHException explicitly when blank private key data is loaded, instead of the natural result of IndexError. This should help more bits of Paramiko or Paramiko-adjacent codebases to correctly handle this class of error. - Update SSHClient so it explicitly closes its wrapped socket object upon encountering socket errors at connection time. This should help somewhat with certain classes of memory leaks, resource warnings, and/or errors (though we hasten to remind everyone that Client and Transport have their own .close() methods for use in non-error situations!). https://www.paramiko.org/changelog.html Signed-off-by: Gyorgy Sarvari --- .../{python3-paramiko_2.10.3.bb => python3-paramiko_2.10.6.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta-python/recipes-devtools/python/{python3-paramiko_2.10.3.bb => python3-paramiko_2.10.6.bb} (82%) diff --git a/meta-python/recipes-devtools/python/python3-paramiko_2.10.3.bb b/meta-python/recipes-devtools/python/python3-paramiko_2.10.6.bb similarity index 82% rename from meta-python/recipes-devtools/python/python3-paramiko_2.10.3.bb rename to meta-python/recipes-devtools/python/python3-paramiko_2.10.6.bb index 9f7f458723..5a367df710 100644 --- a/meta-python/recipes-devtools/python/python3-paramiko_2.10.3.bb +++ b/meta-python/recipes-devtools/python/python3-paramiko_2.10.6.bb @@ -3,7 +3,7 @@ HOMEPAGE = "https://github.com/paramiko/paramiko/" LICENSE = "LGPL-2.1-only" LIC_FILES_CHKSUM = "file://LICENSE;md5=fd0120fc2e9f841c73ac707a30389af5" -SRC_URI[sha256sum] = "ddb1977853aef82804b35d72a0e597b244fa326c404c350bd00c5b01dbfee71a" +SRC_URI[sha256sum] = "faac4820a3173997c378da74b72e832b1ff075ea1a4ee3c0ba048aa30ee49cf1" PYPI_PACKAGE = "paramiko" From patchwork Sat Jan 24 05:32:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gyorgy Sarvari X-Patchwork-Id: 79552 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 01866D715C9 for ; Sat, 24 Jan 2026 05:32:22 +0000 (UTC) Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.13754.1769232738302144430 for ; Fri, 23 Jan 2026 21:32:18 -0800 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20230601 header.b=ln2hbBDD; spf=pass (domain: gmail.com, ip: 209.85.128.44, mailfrom: skandigraun@gmail.com) Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-47ee974e230so25477975e9.2 for ; Fri, 23 Jan 2026 21:32:18 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1769232737; x=1769837537; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to; bh=jKW/BFkPWekzg9e627VpdPZ7JeU5om0fxfeMZkQLrAA=; b=ln2hbBDDK/Vhl91MdEj5CO/nPO790q6R2ItUF9GqDc0j0nXS2ug914KhsDxl3NvV32 wVQNh5khCJ/dLI5vpI+cNZBd9zGXqRoe2XIo3S4vO05o3+zOAh3qACNdK2of4aUYaCcg jxU0Kx6EHseKSW/Kx3Yoi8SpdloLaFjm+ofkorkOO09jFLiMUcbFztLQL1lJrMBTH9dq qFBIOl0GwSkKLqN/m4cmp4+AoDkGUPrWYRSlvSMIxhxww25qj1AjIDRGsZryty0YpYH5 p39RsimM4a8y81AkIwO7gW+um4fS+2W4LOIg5+oDELKDfrDZyNlqgIMzdp2lu8vs7Yba HfhQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1769232737; x=1769837537; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=jKW/BFkPWekzg9e627VpdPZ7JeU5om0fxfeMZkQLrAA=; b=m6AcNl0jLpJsdJ3FXtDDQjh9i3cWjJ8qpQxGeT+CiBbiToXWOyGZiFkye0iIsGwwPM 8xwu25scmGl+Dfpz0UZzcz/vk0OE6BVzKC97x+4lJ5G7ucB1+7S9VpHaHeu/kfHKanNM /N/mMpiHBg42T+8obK1tUnStUk3weDYW61eoUTlGtzJ3fxla4ZnrO5TC5AZRQKgSJIzS tEYppM1/2CUzJeQGRnZR4d9lLMVswJ+Eg/QphKPvte4tqAgyZVbL3YAaRyI7Ap3trHgn B5T39Xboo34MbbpQWueJ/unoyv/y8gPKC6DDqTtZ7Yc5RUMCEerQ5mMBsFykdAMkAKSN TIkg== X-Gm-Message-State: AOJu0YzQHlTo25Ik3J4g+AQbc+b8vbhbgUVCkOtT4QNjUESdZ1SsQxXp SNowzUReb3s/PYyEerJYTmMmT+4YsMc5kWcgH8OFzNF5Enx4KlN/8lyKJvahWA== X-Gm-Gg: AZuq6aLtJIifs14Tf93xDsdeP8YhSaWW9Ge5EO9JlBT1WzTvLynV0n1RnXSmf0ARodf lD3iEbc0NnID5VXHwZzbLFPAiWmxAcgJs2X+Nv9hoW1xFd7rdMDqj+VwUQDVoAF7/i/GGkVzyMs SnuMz7zek4R2/nFXD6mdRAAAmwmnd+EytSDJYUi4n2nWk5Rx8ntLUaXZf131WuvYy2HXdJshEDL AtTEUqbF9snpbg9QZjF+IeU7KTFW0pOvvmFWbwvKL+MusaBIfOdyDZwLJwD2LWtjcPmQcnKlhBI YJkr+RxujMBfsaeBg7Tn8FAJbywyYXDRrT5+ymsrdEJa8h181i3xtRAnLEv2r4X3mCtacBJ4atR oV3UIgRH/u12JMmdwux41j9n4KtmPWHTKt4ur2oMdFhaW7NmWIY5DNIQZ4SbWzSL0u8SOI5qeK9 h6VCzdZXXwrMjO/t3++l0= X-Received: by 2002:a05:600d:8443:20b0:477:7925:f7fb with SMTP id 5b1f17b1804b1-48052fd65b1mr38304255e9.10.1769232736566; Fri, 23 Jan 2026 21:32:16 -0800 (PST) Received: from desktop ([51.154.145.205]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4804dbb6315sm40746155e9.4.2026.01.23.21.32.15 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 23 Jan 2026 21:32:16 -0800 (PST) From: Gyorgy Sarvari To: openembedded-devel@lists.openembedded.org Subject: [meta-oe][kirkstone][PATCH 2/5] sanlock: upgrade 3.8.4 -> 3.8.5 Date: Sat, 24 Jan 2026 06:32:12 +0100 Message-ID: <20260124053215.4066209-2-skandigraun@gmail.com> X-Mailer: git-send-email 2.52.0 In-Reply-To: <20260124053215.4066209-1-skandigraun@gmail.com> References: <20260124053215.4066209-1-skandigraun@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 24 Jan 2026 05:32:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/123803 From: Wang Mingyu setuptools.patch removed since it's included in 3.8.5. Signed-off-by: Wang Mingyu Signed-off-by: Khem Raj (cherry picked from commit cc532b9d4e0394f442cc3e3b6c7f65858a551a3c) Shortlog: python: Replace distutils with setuptools sanlock: fix memory leak of lockspace renewal_history sanlock: fix pthread_create error check Revert "sanlock: Shrink thread pool when there is no work" sanlock: fix pthread_create error paths sanlock: acquire should ignore unused options str sanlock: use helper to set max_sectors_kb Signed-off-by: Gyorgy Sarvari --- .../sanlock/sanlock/setuptools.patch | 18 ------------------ .../{sanlock_3.8.4.bb => sanlock_3.8.5.bb} | 3 +-- 2 files changed, 1 insertion(+), 20 deletions(-) delete mode 100644 meta-oe/recipes-extended/sanlock/sanlock/setuptools.patch rename meta-oe/recipes-extended/sanlock/{sanlock_3.8.4.bb => sanlock_3.8.5.bb} (95%) diff --git a/meta-oe/recipes-extended/sanlock/sanlock/setuptools.patch b/meta-oe/recipes-extended/sanlock/sanlock/setuptools.patch deleted file mode 100644 index c375e10f75..0000000000 --- a/meta-oe/recipes-extended/sanlock/sanlock/setuptools.patch +++ /dev/null @@ -1,18 +0,0 @@ -Switch to setuptools as distutils is deprecated. - -Upstream-Status: Backport [https://pagure.io/sanlock/c/75758fc10db2354dda397d3aba63c7b72a420982] -Signed-off-by: Ross Burton - -diff --git a/python/setup.py b/python/setup.py -index b3bfaf1..dfbaf21 100644 ---- a/python/setup.py -+++ b/python/setup.py -@@ -4,7 +4,7 @@ - # modify, copy, or redistribute it subject to the terms and conditions - # of the GNU General Public License v.2. - --from distutils.core import setup, Extension -+from setuptools import setup, Extension - - sanlocklib = ['sanlock'] - sanlock = Extension(name='sanlock', diff --git a/meta-oe/recipes-extended/sanlock/sanlock_3.8.4.bb b/meta-oe/recipes-extended/sanlock/sanlock_3.8.5.bb similarity index 95% rename from meta-oe/recipes-extended/sanlock/sanlock_3.8.4.bb rename to meta-oe/recipes-extended/sanlock/sanlock_3.8.5.bb index a59a5c41df..ce289a0d8e 100644 --- a/meta-oe/recipes-extended/sanlock/sanlock_3.8.4.bb +++ b/meta-oe/recipes-extended/sanlock/sanlock_3.8.5.bb @@ -15,9 +15,8 @@ PV .= "+git${SRCPV}" SRC_URI = "git://pagure.io/sanlock.git;protocol=http;branch=master \ file://0001-sanlock-Replace-cp-a-with-cp-R-no-dereference-preser.patch \ - file://setuptools.patch \ " -SRCREV = "a181e951376d49a82eef17920c8ebedec80b4823" +SRCREV = "b820c63093c4ae85d7da4f719cf3026d7fca5d09" S = "${WORKDIR}/git" From patchwork Sat Jan 24 05:32:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gyorgy Sarvari X-Patchwork-Id: 79553 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0220CD715CA for ; Sat, 24 Jan 2026 05:32:23 +0000 (UTC) Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.13629.1769232739048169765 for ; Fri, 23 Jan 2026 21:32:19 -0800 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20230601 header.b=hqzfq0t6; spf=pass (domain: gmail.com, ip: 209.85.128.49, mailfrom: skandigraun@gmail.com) Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-47d59da3d81so24857345e9.0 for ; Fri, 23 Jan 2026 21:32:18 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1769232737; x=1769837537; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to; bh=Nf3UoEXb4mf63qLTi128pZVun53rU8Lk8GIx26DSfBc=; b=hqzfq0t65ZmDq9kt7rYHkOiAV0NHgpx0tEYWRtG9DJJwtBLYmpc6zMaLEJ7XYyKHkF 8yUpPlakuY3maqHVYlFr6pktGubdaWpAAfE2Vu1IRQXvKC/x/sBh+Mq+Xd0CJcF8zobo 1IOLw1ruCigmjVK+L0VBBcUB/PjyK32OpvirrREjLIz033cXwZDy+fZwS7eMhmrwVmMZ CsBM8EfXtjkGzIA38aG5wdWzl5auadM7+xEN8lVF0yWrrLsvUN7YhVlFJNLeIZXDJds/ GFd9g4sODwvUMy5i+khq0bQc/f8yBNDBVEpg/iEb2cKriYwKaroLtg4MT1/OgfKQUxf7 Lm8A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1769232737; x=1769837537; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=Nf3UoEXb4mf63qLTi128pZVun53rU8Lk8GIx26DSfBc=; b=P1pi1vvOREV1zSO41berGVn9zOTiI9mChKr8VvW1NZxGkV+Lh+T8KFSbMOpYde1+7O xs1H0nuOo8KZdWbhgmJSo4u5g8soI1eS9AOBoXX7IPGHA9HG/OPm4Y4TM2HfpxTeIwnA c0JPfzyp1Crwvh1zSmCMZC3nBI2GKhYblO5q84JXN4+i58vH9nwFVf3MbCL0yivzmV/a p+wQNrXCsvsVxzTAZ7e9T195F9Xj74UJ7FRBmlG+J7NDnv58Qm1a+ieBShOnIHSwrjI0 AFnWtcaUTMs2vbLBqolllxo83m7h6M6o41NBDAy7JiZXK/21n0EbyyxW7+lebArD41hc UHiw== X-Gm-Message-State: AOJu0Yxq+SttM+j9SYarTB5/1JL+OIxRBx+KZJiYf6djZae9pkI+GwYb GFZEfwpY97BVb5rAP7zEKrG+rp3vEcuYxB9kvyGNhpqKemIWMZgw/h7uw+mxEg== X-Gm-Gg: AZuq6aJMWM4le8Ug4qfJRv2TDZ+0NXhGVcw+nEFzLx66Z9NtKc/VY9NOBIBq6CVZ2su p+jAU3645e9RnZO77NV4pA1gb9+OEGXxahQrAguY/6wB8WRK+2vPB7FJ98G2+AXlTwHP8lhrZXv Urud+8/chk3eoLKd8mqkUYDKe1v8IM1IAKQ/ODuh8ggxhG9BDBONH6P/2hDrIguDh3tXa3v9XpD /s6fPB1bIV6HtzNC1Ic1+1qd1mDQ2+08m+3O97f4hZCHfSG3WFtNUt9/PgJRd2oKVgimZeeecxh L2uA1IMIhz2UqZKpcTHAWUFm/J97+DpxB89eShe9Am3Eo1CKEwTlIX+JT2v0+YOzlUgJ2PXxcDq vU4/5shmw4C6FV9DBxEDD9+BnhQTgUPM6SxBncso3Zt6Ot0/XOKex+NC9qYJRPT6aeii77eGQQJ +zRViP4/l5 X-Received: by 2002:a05:600c:35c6:b0:480:4a90:1afd with SMTP id 5b1f17b1804b1-4804d251994mr92726205e9.0.1769232737367; Fri, 23 Jan 2026 21:32:17 -0800 (PST) Received: from desktop ([51.154.145.205]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4804dbb6315sm40746155e9.4.2026.01.23.21.32.16 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 23 Jan 2026 21:32:16 -0800 (PST) From: Gyorgy Sarvari To: openembedded-devel@lists.openembedded.org Subject: [meta-gnome][kirkstone][PATCH 3/5] yelp: patch CVE-2025-3155 Date: Sat, 24 Jan 2026 06:32:13 +0100 Message-ID: <20260124053215.4066209-3-skandigraun@gmail.com> X-Mailer: git-send-email 2.52.0 In-Reply-To: <20260124053215.4066209-1-skandigraun@gmail.com> References: <20260124053215.4066209-1-skandigraun@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 24 Jan 2026 05:32:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/123804 Details: https://nvd.nist.gov/vuln/detail/CVE-2025-3155 Pick the patch that refers to this CVE explicitly in its description. Signed-off-by: Gyorgy Sarvari --- .../yelp/yelp/CVE-2025-3155.patch | 119 ++++++++++++++++++ meta-gnome/recipes-gnome/yelp/yelp_42.2.bb | 1 + 2 files changed, 120 insertions(+) create mode 100644 meta-gnome/recipes-gnome/yelp/yelp/CVE-2025-3155.patch diff --git a/meta-gnome/recipes-gnome/yelp/yelp/CVE-2025-3155.patch b/meta-gnome/recipes-gnome/yelp/yelp/CVE-2025-3155.patch new file mode 100644 index 0000000000..01f62bf961 --- /dev/null +++ b/meta-gnome/recipes-gnome/yelp/yelp/CVE-2025-3155.patch @@ -0,0 +1,119 @@ +From 24d4f06a8692f448c635201c26e6fa19581f5760 Mon Sep 17 00:00:00 2001 +From: Shaun McCance +Date: Fri, 18 Apr 2025 11:33:01 -0400 +Subject: [PATCH] Initial fix for CVE-2025-3155 from parrot409 + +https://gitlab.gnome.org/GNOME/yelp/-/issues/221 + +CVE: CVE-2025-3155 +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/yelp/-/commit/a2f3caf8500287981331c4ff54369e9c5747cd9d] +Signed-off-by: Gyorgy Sarvari +--- + data/xslt/mal2html.xsl.in | 5 +++++ + data/xslt/man2html.xsl.in | 2 +- + data/xslt/yelp-common.xsl.in | 7 +++++++ + libyelp/yelp-transform.c | 19 +++++++++++++++++++ + libyelp/yelp-view.c | 2 +- + 5 files changed, 33 insertions(+), 2 deletions(-) + +diff --git a/data/xslt/mal2html.xsl.in b/data/xslt/mal2html.xsl.in +index 9e44b73..0a74da5 100644 +--- a/data/xslt/mal2html.xsl.in ++++ b/data/xslt/mal2html.xsl.in +@@ -19,6 +19,11 @@ + + + ++ ++ ++ ++ ++ + + + +diff --git a/data/xslt/man2html.xsl.in b/data/xslt/man2html.xsl.in +index 676ce3e..56bc1f5 100644 +--- a/data/xslt/man2html.xsl.in ++++ b/data/xslt/man2html.xsl.in +@@ -131,7 +131,7 @@ + the correct styling and a single character which we measure the + width of and update each sheet as required. + --> +-