From patchwork Mon Aug 3 05:10:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: auh@yoctoproject.org X-Patchwork-Id: 94269 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 01AEDC55162 for ; Mon, 3 Aug 2026 05:10:47 +0000 (UTC) Received: from a27-33.smtp-out.us-west-2.amazonses.com (a27-33.smtp-out.us-west-2.amazonses.com [54.240.27.33]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.36841.1785733838436177497 for ; Sun, 02 Aug 2026 22:10:38 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@yoctoproject.org header.s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky header.b=DtVmRjkH; dkim=pass header.i=@amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=q7DyqWvY; spf=pass (domain: us-west-2.amazonses.com, ip: 54.240.27.33, mailfrom: 0101019fc607f254-8fb1dfbe-682e-464b-a5f6-f8c908f175e2-000000@us-west-2.amazonses.com) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky; d=yoctoproject.org; t=1785733837; h=Content-Type:MIME-Version:From:To:Subject:Message-Id:Date; bh=VdThTEXRjq05RAEI5QCBHOJo09a50+eSV1ieWXU7qZM=; b=DtVmRjkH2FYeXfrxP6FsNa20My1lAd7BDl48bryZBu+DdbNnKwvbvmhVSXUJRM6E xNQhfujvERD+irvsODxf1CBGnkyT4JarUX2MBYbCAERpTBQ2eUFzYYfuSln8Kcw91zH Oi+QtCEMVU6ksMWkDst0ulCk80Qutsh6M4DVJ6C0= DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=hsbnp7p3ensaochzwyq5wwmceodymuwv; d=amazonses.com; t=1785733837; h=Content-Type:MIME-Version:From:To:Subject:Message-Id:Date:Feedback-ID; bh=VdThTEXRjq05RAEI5QCBHOJo09a50+eSV1ieWXU7qZM=; b=q7DyqWvYjhyJMYkRsq2EjOAquDlfnAFSFGUShcb1JEoTcZpKDCVKGugypRXCaGc4 6NtayYYYEQ6VJUyXrULDsSR95S7c0s3VP7jbfDo8EIYYb3gTq+bb0YrlAUcIiIiJAPH AJhi7LbEgoqgT311HNDvKkBoc0EOMrdLgKdLE0co= MIME-Version: 1.0 From: auh@yoctoproject.org To: openembedded-core@lists.openembedded.org Subject: [AUH] mpg123: upgrading to 1.33.7 SUCCEEDED Message-ID: <0101019fc607f254-8fb1dfbe-682e-464b-a5f6-f8c908f175e2-000000@us-west-2.amazonses.com> Date: Mon, 3 Aug 2026 05:10:37 +0000 Feedback-ID: ::1.us-west-2.9np3MYPs3fEaOBysGKSlUD4KtcmPijcmS9Az2Hwf7iQ=:AmazonSES X-SES-Outgoing: 2026.08.03-54.240.27.33 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 03 Aug 2026 05:10:46 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242602 Hello, this email is a notification from the Auto Upgrade Helper that the automatic attempt to upgrade the recipe(s) *mpg123* to *1.33.7* has Succeeded. Next steps: - apply the patch: git am 0001-mpg123-upgrade-1.33.6-1.33.7.patch - check the changes to upstream patches and summarize them in the commit message, - compile an image that contains the package - perform some basic sanity tests - amend the patch and sign it off: git commit -s --reset-author --amend - send it to the appropriate mailing list Alternatively, if you believe the recipe should not be upgraded at this time, you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that automatic upgrades would no longer be attempted. Please review the attached files for further information and build/update failures. Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler Regards, The Upgrade Helper -- >8 -- From e70aa335817809b70b7b6291090e6135630af55b Mon Sep 17 00:00:00 2001 From: Upgrade Helper Date: Mon, 3 Aug 2026 05:10:34 +0000 Subject: [PATCH] mpg123: upgrade 1.33.6 -> 1.33.7 Source: NEWS 1.33.7 ------ - mpg123: -- Fix heap buffer overflows in unicode path conversion on Windows (bug 388, thanks to Alejandro Ramos). -- Fix information disclosure of uninitialied memory for --auth-file without line endings. (bug 390, thanks to Alejandro Ramos) -- Fix out-of-bounds read/write when combining --continue --random --listentry where n is larger than the playlist size. (bug 391, thanks to Alejandro Ramos) -- Fix a harmless valgrind memory leak report by not nulling playlist name. -- Fix error handling of win32_net_writestring() (Windows only) by actually using a signed type, also preventing a OOB read on failure. (bug 392 by Alejandro Ramos) -- Fix a mostly harmless OOB read of 1 byte when printing USLT lyrics. (bug 392) -- Fix leaking file descriptor on read error from --equalizer file. (bug 392) -- Hardening of loading HTTP(S) via curl or wget against funky URLs by including the -- separator. No actual vulnerability, tough, just extra care. (bug 392) - out123: -- Fix heap overrun on --endian conversion with differing input and output channel counts. (bug 391) -- Fix parsing of filter specs with whitespace before commas, which resulted in out-of-bounds writes before. (bug 391) - libmpg123, mpg123: Harden memory realloc calls against multiplication overflow of size_t in arguments. Specifically, this addresses part of bug 389 with possible application abuse of mpg123_set_index64(). (bug 389 by Alejandro Ramos) - libmpg123: -- Fix possible use of uninitialized values in layer III dequantization. III_dequantize_sample() for consistent output also for strange input. The new code seems to be slightly faster after some rearrangements. (thanks to He Huang, Swinburne University of Technology (discovered using NexusSan)) -- Fix a double free when deleting a handle after failed mpg123_decoder() call (possibly among others). (bug 389) -- More strong wording in API that ID3 text convenience links are short-lived, but safeguard against ignorant use by nulling them early. (bug 389) -- Prevent double free in mpg123_set_index() 32 bit wrapper being called with index size 0. (bug 392) -- Harden against an application wielding a foot gun by handing in an undersized decoding buffer betwee seek and read (return error before trying to decode and discard frames in that case). (bug 392) -- Do properly terminate ID3v2 texts coming in UTF16 encoding when they overwrite previous frames, like with other encodings. The symptom was a shorter second frame resulting in a combined text with the earlier longer frame. (bug 392) -- Check and properly handle null source buffer and zero size in mpg123_store_utf8() instead of reading past (before) buffers. (bug 392) -- Ensure clients get ID3v1 data with (unmotivated) mpg123_id3_raw() only if the parser decided that it is there, not possibly the last 128 bytes of a seekable stream without ID3v1 tag. (bug 392) -- Prevent impossible N [Changelog truncated as it exceeds 3000 characters; the full changelog can be found in an attachment to the AUH email] --- .../mpg123/{mpg123_1.33.6.bb => mpg123_1.33.7.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-multimedia/mpg123/{mpg123_1.33.6.bb => mpg123_1.33.7.bb} (96%) diff --git a/meta/recipes-multimedia/mpg123/mpg123_1.33.6.bb b/meta/recipes-multimedia/mpg123/mpg123_1.33.7.bb similarity index 96% rename from meta/recipes-multimedia/mpg123/mpg123_1.33.6.bb rename to meta/recipes-multimedia/mpg123/mpg123_1.33.7.bb index 7fa048c9fc..002c4f1cc6 100644 --- a/meta/recipes-multimedia/mpg123/mpg123_1.33.6.bb +++ b/meta/recipes-multimedia/mpg123/mpg123_1.33.7.bb @@ -10,7 +10,7 @@ LICENSE = "LGPL-2.1-only" LIC_FILES_CHKSUM = "file://COPYING;md5=e7b9c15fcfb986abb4cc5e8400a24169" SRC_URI = "https://www.mpg123.de/download/${BP}.tar.bz2" -SRC_URI[sha256sum] = "929a7c18ba662b8927aed4de229ad9ae8ab2b4806dd0f30b90113eb1b4e2195a" +SRC_URI[sha256sum] = "31d0e35a4ca567ec9b5ebda6c3062bb4435d6d3eacd6ef0d95cadd7854dc03ee" UPSTREAM_CHECK_REGEX = "mpg123-(?P\d+(\.\d+)+)\.tar"