From patchwork Thu Jul 23 13:55:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ross Burton X-Patchwork-Id: 93363 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B37DAC531D2 for ; Thu, 23 Jul 2026 13:55:21 +0000 (UTC) Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.24008.1784814920410576187 for ; Thu, 23 Jul 2026 06:55:20 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@arm.com header.s=foss header.b=jzLeN1h2; spf=pass (domain: arm.com, ip: 217.140.110.172, mailfrom: ross.burton@arm.com) Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id B603D1477 for ; Thu, 23 Jul 2026 06:55:15 -0700 (PDT) Received: from cesw-amp-gbt-1s-m12830-04.lab.cambridge.arm.com (usa-sjc-imap-foss1.foss.arm.com [10.121.207.14]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPA id 826303F66F for ; Thu, 23 Jul 2026 06:55:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=arm.com; s=foss; t=1784814919; bh=oE3rfdguClGmyTD2a/+Y9IAJN2AK8WF8ewgStH17aI8=; h=From:To:Subject:Date:From; b=jzLeN1h2OYe7AUjk76Bet04YLMGvkY+45bwOPxFI5c30n8jEKfAqPJTReVSrYXum7 DXhYZ6prIFp7o5KxMe0lmI0qptD042Uw+7gkpc6NX7uf9iSa9Y7KYjxk6Dt5IQg9ss cSd6UFGsz6SVCb8nSoJ/XKxwxDXoWXfy51j/r8h8= From: Ross Burton To: openembedded-core@lists.openembedded.org Subject: [PATCH 1/3] curl: add option for libpsl, the Public Suffix List library Date: Thu, 23 Jul 2026 14:55:12 +0100 Message-ID: <20260723135515.1297700-1-ross.burton@arm.com> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 23 Jul 2026 13:55:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241844 Instead of hardcoding this to disabled, add a PACKAGECONFIG. No behavioural changes in this patch. Signed-off-by: Ross Burton --- meta/recipes-support/curl/curl_8.21.0.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-support/curl/curl_8.21.0.bb b/meta/recipes-support/curl/curl_8.21.0.bb index d245e7fe60f..399b915dee8 100644 --- a/meta/recipes-support/curl/curl_8.21.0.bb +++ b/meta/recipes-support/curl/curl_8.21.0.bb @@ -55,6 +55,7 @@ PACKAGECONFIG[ldap] = "--enable-ldap,--disable-ldap,openldap" PACKAGECONFIG[ldaps] = "--enable-ldaps,--disable-ldaps,openldap" PACKAGECONFIG[libgsasl] = "--with-libgsasl,--without-libgsasl,libgsasl" PACKAGECONFIG[libidn] = "--with-libidn2,--without-libidn2,libidn2" +PACKAGECONFIG[libpsl] = "--with-libpsl,--without-libpsl,libpsl" PACKAGECONFIG[libssh] = "--with-libssh,--without-libssh,libssh" PACKAGECONFIG[libssh2] = "--with-libssh2,--without-libssh2,libssh2" PACKAGECONFIG[mbedtls] = "--with-mbedtls,--without-mbedtls,mbedtls" @@ -85,7 +86,6 @@ CURL_CA_BUNDLE_BASE_DIR:class-target = "${sysconfdir}" EXTRA_OECONF = " \ --disable-libcurl-option \ - --without-libpsl \ --enable-optimize \ --with-ca-bundle=${CURL_CA_BUNDLE_BASE_DIR}/ssl/certs/ca-certificates.crt \ ${@'--without-ssl' if (bb.utils.filter('PACKAGECONFIG', 'gnutls mbedtls openssl schannel', d) == '') else ''} \ From patchwork Thu Jul 23 13:55:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ross Burton X-Patchwork-Id: 93362 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A6469C531CF for ; Thu, 23 Jul 2026 13:55:21 +0000 (UTC) Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.24009.1784814920976886662 for ; Thu, 23 Jul 2026 06:55:21 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@arm.com header.s=foss header.b=TRvFD+QQ; spf=pass (domain: arm.com, ip: 217.140.110.172, mailfrom: ross.burton@arm.com) Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id 64A761595 for ; Thu, 23 Jul 2026 06:55:16 -0700 (PDT) Received: from cesw-amp-gbt-1s-m12830-04.lab.cambridge.arm.com (usa-sjc-imap-foss1.foss.arm.com [10.121.207.14]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPA id 348613F66F for ; Thu, 23 Jul 2026 06:55:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=arm.com; s=foss; t=1784814920; bh=yJEleY7inMSdS8mxRMC5g8nIxDXu1V+AFRbbynNDByU=; h=From:To:Subject:Date:In-Reply-To:References:From; b=TRvFD+QQrqv4qkKsU1tnOxj/LL79jy+2CLWUHYLzE66z7B4k/vuADyDecmCFGbFX/ sKpUDyqCaWBSrIzmEK1UC2fL53frO2U+EjwIqLEZ++hoessj6MyX8jEUdHvaznrM6u zQSofYE5euTJeav/lLsPDf9cc7w0m45HXZN47XRY= From: Ross Burton To: openembedded-core@lists.openembedded.org Subject: [PATCH 2/3] curl: enable libpsl in target builds Date: Thu, 23 Jul 2026 14:55:13 +0100 Message-ID: <20260723135515.1297700-2-ross.burton@arm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260723135515.1297700-1-ross.burton@arm.com> References: <20260723135515.1297700-1-ross.burton@arm.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 23 Jul 2026 13:55:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241845 The Public Suffix List[1] is a list of domains that people can register domains under, for example ".com" or ".co.uk". This is useful because it means browsers and other HTTP using tools can prevent malicious web sites from setting privacy-damaging "supercookies". In the interest of being more secure out of the box, enable libpsl in target builds of curl. [1] https://publicsuffix.org Signed-off-by: Ross Burton --- meta/recipes-support/curl/curl_8.21.0.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-support/curl/curl_8.21.0.bb b/meta/recipes-support/curl/curl_8.21.0.bb index 399b915dee8..e8c024d18a7 100644 --- a/meta/recipes-support/curl/curl_8.21.0.bb +++ b/meta/recipes-support/curl/curl_8.21.0.bb @@ -29,7 +29,7 @@ CVE_STATUS[CVE-2024-32928] = "ignored: CURLOPT_SSL_VERIFYPEER was disabled on go inherit autotools pkgconfig binconfig multilib_header ptest COMMON_PACKAGECONFIG = "basic-auth bearer-auth digest-auth ipfs negotiate-auth openssl proxy threaded-resolver verbose zlib" -PACKAGECONFIG ??= "${COMMON_PACKAGECONFIG} ${@bb.utils.filter('DISTRO_FEATURES', 'ipv6', d)} aws libidn" +PACKAGECONFIG ??= "${COMMON_PACKAGECONFIG} ${@bb.utils.filter('DISTRO_FEATURES', 'ipv6', d)} aws libidn libpsl" PACKAGECONFIG:class-native = "${COMMON_PACKAGECONFIG} ipv6" PACKAGECONFIG:class-nativesdk = "${COMMON_PACKAGECONFIG} ipv6" From patchwork Thu Jul 23 13:55:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ross Burton X-Patchwork-Id: 93364 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B42FFC531CA for ; Thu, 23 Jul 2026 13:55:31 +0000 (UTC) Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.24080.1784814921792873692 for ; Thu, 23 Jul 2026 06:55:21 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@arm.com header.s=foss header.b=OgNJ+q7L; spf=pass (domain: arm.com, ip: 217.140.110.172, mailfrom: ross.burton@arm.com) Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id 168811477 for ; Thu, 23 Jul 2026 06:55:17 -0700 (PDT) Received: from cesw-amp-gbt-1s-m12830-04.lab.cambridge.arm.com (usa-sjc-imap-foss1.foss.arm.com [10.121.207.14]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPA id DAA323F66F for ; Thu, 23 Jul 2026 06:55:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=arm.com; s=foss; t=1784814921; bh=JOnzQ5ILlsnMmCislkMqXgItB/oa73Qkq6z4Z29ETUI=; h=From:To:Subject:Date:In-Reply-To:References:From; b=OgNJ+q7Lk78OIqTCvB93XjcMVsQTjUu/Qb3iHqebO3W5Ox1XQlCHk5GO3MHOQtoqJ /o3UolGa+FArZ9FOudjzwMppe776Qc6JjherA8afY9akkArfGX5azHVE1Oh5pZybYV n5T9KCKWejoVZ0EihOoWbWpnYabMxqSt1IOXo3Oc= From: Ross Burton To: openembedded-core@lists.openembedded.org Subject: [PATCH 3/3] wget: enable libpsl in target builds Date: Thu, 23 Jul 2026 14:55:14 +0100 Message-ID: <20260723135515.1297700-3-ross.burton@arm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260723135515.1297700-1-ross.burton@arm.com> References: <20260723135515.1297700-1-ross.burton@arm.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 23 Jul 2026 13:55:31 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241846 The Public Suffix List[1] is a list of domains that people can register domains under, for example ".com" or ".co.uk". This is useful because it means browsers and other HTTP using tools can prevent malicious web sites from setting privacy-damaging "supercookies". In the interest of being more secure out of the box, enable libpsl in builds of wget (note that we never build wget-native, as it is provided by the host). [1] https://publicsuffix.org Signed-off-by: Ross Burton --- meta/recipes-extended/wget/wget_1.25.0.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-extended/wget/wget_1.25.0.bb b/meta/recipes-extended/wget/wget_1.25.0.bb index 10b2bc19a5d..1d202df9f42 100644 --- a/meta/recipes-extended/wget/wget_1.25.0.bb +++ b/meta/recipes-extended/wget/wget_1.25.0.bb @@ -25,7 +25,7 @@ EXTRA_OECONF = "--without-libgnutls-prefix --without-libssl-prefix \ EXTRA_OEMAKE += 'TOOLCHAIN_OPTIONS="${TOOLCHAIN_OPTIONS}" \ DEBUG_PREFIX_MAP="${DEBUG_PREFIX_MAP}"' -PACKAGECONFIG ??= "gnutls pcre2 zlib \ +PACKAGECONFIG ??= "gnutls pcre2 zlib libpsl \ ${@bb.utils.filter('DISTRO_FEATURES', 'ipv6', d)}" PACKAGECONFIG[ares] = "--with-cares,--without-cares,c-ares" PACKAGECONFIG[gnutls] = "--with-ssl=gnutls,,gnutls"