From patchwork Wed Aug 5 21:26:10 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Khem Raj X-Patchwork-Id: 94645 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1D427C55174 for ; Wed, 5 Aug 2026 21:26:21 +0000 (UTC) Received: from mail-pl1-f172.google.com (mail-pl1-f172.google.com [209.85.214.172]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6224.1785965175811994991 for ; Wed, 05 Aug 2026 14:26:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=XcKuqMjx; spf=pass (domain: gmail.com, ip: 209.85.214.172, mailfrom: raj.khem@gmail.com) Received: by mail-pl1-f172.google.com with SMTP id d9443c01a7336-2ccf2360620so15361095ad.3 for ; Wed, 05 Aug 2026 14:26:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785965175; x=1786569975; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=FbLa34YiUq3IqIon3HsW/E5uC+ohJj+s6tUAEEWlSdE=; b=XcKuqMjx8NpdvT78NOqsZChOQ01mfaARCwi3Xca/aZJfX1+SebdDv7Lqa7Xj1Ij0r3 A6uHqAkEyYHA+x16GJKU9I3gekpLrc3arC+Zj8Pg7mPyNe42SS0E7r4E+Ya54NDOfURE 4O5KS0B71RhKyxXPjw4OH1k9H4ik+t6QKSSKeRpM/cqiotw/hskc9BaI7Dlhp4N1ruI+ 6rUKkYRF09ImvE+yWxbP+kXoyeLp9l7PxWipbmwQYzfic8icdX1c0Fp/zdP+FMNGHQkk Jl0nD23H5fGyyk6lVAsQGd+eU1rM2wrtMV+j2wY4wBrpLGSHOeSMGWbCAuRIzMAG4YSJ K6WQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785965175; x=1786569975; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=FbLa34YiUq3IqIon3HsW/E5uC+ohJj+s6tUAEEWlSdE=; b=HtD+0AAOUqhNbXzSEKqWi9Tv1yLhFutoAfljOjhnlevZnjN1xOlA/eWpxeU0Eo8Oc/ Pwv38RD08tB+jgf+66o7WL3KSeyu/qw5ax2t3prwUtkQd3/BfqkVexHrlGmW3iYHOlw8 A8SlWDB3rIGWdHURjsFluGZU6QQgKh+CwY1/WUIP+qpH2PducKwM7h8B0jfDFLL5ooc6 mDv9VtgFypHZx0poTHHcYVxXti3UtUC3GZXR4GmzFVhKj90iPnZxJSwWcOurPb4I9Y8H F96vVlwnxnCz4SaBVAMafjFRUAE8Z8KOQxRUPPgP0LMOBvXj1zV6nDakNftS8rcenfwn 4a1A== X-Gm-Message-State: AOJu0YxPyAKJ1ZxsNZP6kYh0OuYn31Kf/et8ROnFxhzE3hKNpldDcWw3 1f2wksS3/JbtW5pXrhgzlGdvqjf+Zswf/ph4sKWY/4+b+mudosarhF+25ZVAWESE X-Gm-Gg: AR+sD11fUGWOcG0QuqLSYUG6jNg4O5CZFKxljMWBXiwTDhWExf0njHyvd2slcP4tvAd 23GzwhUR/3SfKnctELpRu4HjKl1/iPXWHaK+v9gr77nxc/U+t9+oJmqIPsAwSj0VyTcySNTsD4E a8JPk6lqkiCweujn6weS3xrGKbIHmlDCcMl1y/tkf7cfaRojRiAqFR53De4YvTOLwdXlliLzDd8 +O+6h/9gCd/uZWE8M3UoDv30oxUekW3G8o28bDGQ+X01VdJTuG+lcapp9VbudGyjhmu/3rQqGLj Oy86sKYg/G1WhY35Xs14TlIIbs1Mc1e/Wvfr665z4KLfKdzvvGQmUCC+x9lpNZl8BLyNErd0yMd w5s092sGphLnIlN21vwAFxFPnpUizbcRW/sJUFjNUbIfAtbUJDVjjDfOloQe9XARlWy7z9ZvMtU OvK3Pf5xMekKOjkjZhW5egf3Jzy5tyUEuiI0FjVdqIETeSFU5eiEtPU+aZXHa3WFFkFRKM1oP41 je7QgRYyDoCuG0OsrYDZ5In7L40sDQ4EyyssDDynwqIKvYcZ6WeEwyZkZcdjU+cV0M/jSdVMNCX oofSHCheaM+xWBIWutYS4mzmy4d6GqyPFZkSyhOdnU9qe9uPUdprprMBKHV2FzdPzbPDD9Lr4nh x2g== X-Received: by 2002:a17:902:ebc3:b0:2d0:8b28:51ab with SMTP id d9443c01a7336-2d0ca712e65mr119760545ad.7.1785965175061; Wed, 05 Aug 2026 14:26:15 -0700 (PDT) Received: from apollo.localdomain ([208.95.233.74]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3158673be4dsm25585093eec.16.2026.08.05.14.26.14 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 05 Aug 2026 14:26:14 -0700 (PDT) From: Khem Raj X-Google-Original-From: Khem Raj To: openembedded-devel@lists.openembedded.org Cc: Khem Raj Subject: [meta-oe][PATCH 1/3] rrdtool: Fix do_configure by exporting ABS_TOP_BUILDDIR for perl bindings Date: Wed, 5 Aug 2026 14:26:10 -0700 Message-ID: <20260805212612.1351211-1-khem.raj@oss.qualcomm.com> X-Mailer: git-send-email 2.55.0 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 05 Aug 2026 21:26:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/128823 1.10.3 grew a third branch in bindings/perl-shared/Makefile.PL: when ABS_TOP_BUILDDIR is unset it assumes a standalone build, pkg-config probes for an installed librrd and dies. | pkg-config could not find librrd. Is rrdtool installed? | Try: brew install rrdtool (macOS) or apt install librrd-dev (Debian/Ubuntu) bindings/Makefile.am always passes ABS_TOP_SRCDIR, ABS_TOP_BUILDDIR and ABS_SRCDIR when it runs Makefile.PL, but do_configure re-runs it by hand to redo the perl bindings and did not. Export them there too so the in-tree branch is taken and RRDs links against -L${B}/src/.libs -lrrd. Verified on aarch64 for qemuarm64: do_configure fails before the change with the error above, and do_compile and do_package succeed after. Signed-off-by: Khem Raj --- meta-oe/recipes-extended/rrdtool/rrdtool_1.10.3.bb | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/meta-oe/recipes-extended/rrdtool/rrdtool_1.10.3.bb b/meta-oe/recipes-extended/rrdtool/rrdtool_1.10.3.bb index a434927b23..656cee7ffa 100644 --- a/meta-oe/recipes-extended/rrdtool/rrdtool_1.10.3.bb +++ b/meta-oe/recipes-extended/rrdtool/rrdtool_1.10.3.bb @@ -97,9 +97,14 @@ do_configure() { ${B}/bindings/Makefile #redo the perl bindings + # perl-shared/Makefile.PL only links against the in-tree librrd when + # ABS_TOP_BUILDDIR is set, which is what bindings/Makefile.am does. Without + # it the standalone branch pkg-config probes for an installed librrd and + # dies with "pkg-config could not find librrd", so export them here too. ( cd ${S}/bindings/perl-shared; - perl Makefile.PL INSTALLDIRS="vendor" INSTALLPRIVLIB="abc"; + ABS_TOP_SRCDIR="${S}" ABS_TOP_BUILDDIR="${B}" ABS_SRCDIR="${S}/bindings/perl-shared" \ + perl Makefile.PL INSTALLDIRS="vendor" INSTALLPRIVLIB="abc"; cd ../../bindings/perl-piped; perl Makefile.PL INSTALLDIRS="vendor"; From patchwork Wed Aug 5 21:26:11 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Khem Raj X-Patchwork-Id: 94647 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4CE35C55ABF for ; Wed, 5 Aug 2026 21:26:21 +0000 (UTC) Received: from mail-pg1-f175.google.com (mail-pg1-f175.google.com [209.85.215.175]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6225.1785965178126920463 for ; Wed, 05 Aug 2026 14:26:18 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=VWV/M/Ci; spf=pass (domain: gmail.com, ip: 209.85.215.175, mailfrom: raj.khem@gmail.com) Received: by mail-pg1-f175.google.com with SMTP id 41be03b00d2f7-c9eefcf9175so1341250a12.3 for ; Wed, 05 Aug 2026 14:26:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785965177; x=1786569977; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hp5VsKYh5uUkzqNQC5HtFslW1Dv7Zd9auz0nVetuLVA=; b=VWV/M/CioorEUE55yLeeNsTPpcFX0HF1Vl2Fgqm/YULyimI3XSn0GhFkB9m+y+Y93R MxJfVAgOQTflZPIjjoJd48dnM9I2tY6CSKCO9cI1OAwLuj+u6I8aHGDvj2PI7plqyWlW gWFCCOMBqVY3EepdvGTArecePwfLdwve47vgBhFU9tUEUyvTbJsTs0XPmd2UE0+4y4sp RzLCFzCgYg3sM8c/ujzar56dDfeUbxrmqF3AT8UQbLTh6LkoAopciUiOi+fSq9sfqTX1 nh9lJeBbmjzI4dBB3dIuQZ6elAI70gv6VipS1Rj2A79w5seTDBSZHH9we1GA4kqmUkKJ SknA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785965177; x=1786569977; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=hp5VsKYh5uUkzqNQC5HtFslW1Dv7Zd9auz0nVetuLVA=; b=bT9U24M0kF3uUt/N6s1UHTErQ8+6/2Z2qy69kV61jc6WkyCqixZCkediEInfaBogyZ e6lH0fFnff3XQEb5v2tmBqKCyfLT0QF9Z92la2bYFlLjW9UbKJEjCzd52aOSb2FKE5JF Xd4VRbIn0tnxGk3qdgHsWsLuOiTWMlHF+a8U8+Xkxi50+0jhpmgOCas/9glc4nF6s6Km pQIVHYTGbiJsrxa9cOK4nF6qLfHXqkH9T18uCnNdu+qCusMHj2c2ZgAV/qP3x14/rxjl 1QodJwGuePGbLrh+XhiEj+BNNy1aEwatIr8vlJ8t55AsGHZyAoFXo01vVaGCE4k6dhxj TXSQ== X-Gm-Message-State: AOJu0YwwvkhQKmMOXkFWpVDIrt0ctbMy3v0Ng9URG0iLUEEyvEg6cfIT rBVYA/tiEjDFYRJZgCCm6glQ4YWnWSELRAjr7mM0iQ4hPf+BvP9oz+qX8bktLZk/ X-Gm-Gg: AR+sD12s0Vp607pA2UQGVA+dB9+XGWNHJTtYj1NjdniTd9518ojbTIYPJocmz5mlJ1a KY1CR3gcBJ+EeP65HIXv5CAoc8ugQy+5d2O6mpNMBu+mOPF5w7yfkBvqx08uNS1aX3fuXBRyLHL HXgO5K1BABB62PzbbQMUpLGQweAu1iInD2CgrKR5fisNZTGWthRivhvTiu3ZWRFS0bsNXPA2s1F BP+SoimjZzQE6qi9ShmBUC6vAMmaPVdL6pvq9BAQGcHTJ223z5fUebkeVYD9gxXU+Jj8reRdgZa kqOHZwSMNCnytxMmZqhGrZbPZETHR9pbJ8Y69nY91hgGgKwXV2m1YFMwT3BAWX0R9P+7U2+LVOf BueMpO5gFSw8QAxOoIyb+HY8HLcUxSh1cpZNTf47YkRJ8IlrVaCPRC1IX+l8RJb2bvQ44ZBFhwX t3U8bNNDOIyGn6pDmO+vgeppbKyOCbSv9ZKgSj3haYzAFl7lxK3VWg5tMP1u2WlZRqpLyRw8kdK jtMyB/yaJdQ0bV6Y7fSjpGLVnZoUSZyVxR5THLDLcSo50JaZiPfaC2MKse9I6HIGJM1irX6Zwgk HGk+VhOG+EHkSgGGPvTOUAd67Tc/EnRVeHgFHC2cJLfjP6uXP2Aed1GP3KLtUDn0IUHO/WEko8g 7cg== X-Received: by 2002:a05:6a20:6a08:b0:3c3:859b:9178 with SMTP id adf61e73a8af0-3cb85f508cemr11379064637.34.1785965177229; Wed, 05 Aug 2026 14:26:17 -0700 (PDT) Received: from apollo.localdomain ([208.95.233.74]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3158673be4dsm25585093eec.16.2026.08.05.14.26.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 05 Aug 2026 14:26:16 -0700 (PDT) From: Khem Raj X-Google-Original-From: Khem Raj To: openembedded-devel@lists.openembedded.org Cc: Khem Raj Subject: [meta-networking][PATCH 2/3] net-snmp: Backport upstream fix for explicit library linking Date: Wed, 5 Aug 2026 14:26:11 -0700 Message-ID: <20260805212612.1351211-2-khem.raj@oss.qualcomm.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805212612.1351211-1-khem.raj@oss.qualcomm.com> References: <20260805212612.1351211-1-khem.raj@oss.qualcomm.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 05 Aug 2026 21:26:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/128824 libnetsnmptrapd uses symbols that live in libnetsnmpagent, but apps/Makefile.in only passes $(MIBLIB) and $(USELIBS) to the link. That works with GNU ld, which resolves symbols through the DT_NEEDED entries of the libraries named on the command line, and libnetsnmpmibs records a dependency on libnetsnmpagent. lld deliberately does not, so the link fails: | ld.lld: error: undefined symbol: init_vacm_config_tokens | >>> referenced by snmptrapd_auth.c:51 | >>> .libs/snmptrapd_auth.o:(init_netsnmp_trapd_auth) | ld.lld: error: undefined symbol: send_v2trap | >>> referenced by snmptrapd_handlers.c:886 | >>> .libs/snmptrapd_handlers.o:(axforward_handler) Backport upstream commit 5e66246bd994 which names $(AGENTLIB) explicitly and additionally links libcrypto into libnetsnmpmibs and the apps, both of which rely on the same transitive resolution. The libnetsnmptrapd.la hunk is rebased because 5.9.5.2 still puts $(LDFLAGS) at the end of that link command. Verified on aarch64 for qemuarm64: do_compile fails before the change with the errors above; after it do_compile and do_package succeed and libnetsnmptrapd.so records DT_NEEDED on libnetsnmpmibs, libnetsnmpagent and libnetsnmp directly. Signed-off-by: Khem Raj --- ...akefile.in-Link-libraries-explicitly.patch | 103 ++++++++++++++++++ .../net-snmp/net-snmp_5.9.5.2.bb | 1 + 2 files changed, 104 insertions(+) create mode 100644 meta-networking/recipes-protocols/net-snmp/net-snmp/0012-apps-Makefile.in-Link-libraries-explicitly.patch diff --git a/meta-networking/recipes-protocols/net-snmp/net-snmp/0012-apps-Makefile.in-Link-libraries-explicitly.patch b/meta-networking/recipes-protocols/net-snmp/net-snmp/0012-apps-Makefile.in-Link-libraries-explicitly.patch new file mode 100644 index 0000000000..5129282ef2 --- /dev/null +++ b/meta-networking/recipes-protocols/net-snmp/net-snmp/0012-apps-Makefile.in-Link-libraries-explicitly.patch @@ -0,0 +1,103 @@ +From 5e66246bd994a2f693bd02773823691c8d07a070 Mon Sep 17 00:00:00 2001 +From: Bart Van Assche +Date: Fri, 24 Jul 2026 09:34:18 -0700 +Subject: [PATCH] apps/Makefile.in: Link libraries explicitly + +When building Net-SNMP with -no-undefined (which is used for libraries like +libnetsnmpmibs.la and libnetsnmptrapd.la) and link_all_deplibs=no (default on +modern systems to prevent overlinking), compilation fails due to undefined +references to symbols from transitive dependencies. + +1. libnetsnmpmibs.la fails to link because it uses OpenSSL DH/BN symbols + (when snmp-usm-dh-objects-mib is enabled) but does not link with + libcrypto directly. Fix this by adding LIBCRYPTO to LMIBLIBS in + configure if OpenSSL is used, and exporting LIBCRYPTO. + +2. libnetsnmptrapd.la fails to link because it uses symbols from + libnetsnmpagent.la (like vacm_check_view_contents) but does not link with + it directly. Fix this by adding $(AGENTLIB) to libnetsnmptrapd.la link + line in apps/Makefile.in. + +3. Executables in apps/ (like snmpusm and snmptls) fail to link because + they use OpenSSL symbols directly but do not link with libcrypto/libssl + directly. Fix this by adding @LIBCRYPTO@ to LIBS in apps/Makefile.in. + +This makes Net-SNMP compatible with newer versions of libtool. + +Upstream-Status: Backport [https://github.com/net-snmp/net-snmp/commit/5e66246bd994a2f693bd02773823691c8d07a070] + +The libnetsnmptrapd.la hunk is rebased: 5.9.5.2 still puts $(LDFLAGS) at +the end of that link command, upstream has since moved it before +$(LLIBTRAPD_OBJS). The change itself is unmodified. + +Signed-off-by: Khem Raj +--- + apps/Makefile.in | 4 ++-- + configure | 7 +++++++ + configure.d/config_os_libs2 | 6 ++++++ + 3 files changed, 15 insertions(+), 2 deletions(-) + +diff --git a/apps/Makefile.in b/apps/Makefile.in +index 57b8524..252fd84 100644 +--- a/apps/Makefile.in ++++ b/apps/Makefile.in +@@ -95,7 +95,7 @@ MYSQL_LIBS = @MYSQL_LIBS@ + MYSQL_INCLUDES = @MYSQL_INCLUDES@ + + VAL_LIBS = @VAL_LIBS@ +-LIBS = $(USELIBS) $(VAL_LIBS) @LIBS@ ++LIBS = $(USELIBS) $(VAL_LIBS) @LIBS@ @LIBCRYPTO@ + PERLLDOPTS_FOR_APPS = @PERLLDOPTS_FOR_APPS@ + PERLLDOPTS_FOR_LIBS = @PERLLDOPTS_FOR_LIBS@ + +@@ -235,7 +235,7 @@ snmppcap$(EXEEXT): snmppcap.$(OSUFFIX) $(USEAGENTLIBS) + $(LINK) ${CFLAGS} -o $@ snmppcap.$(OSUFFIX) ${LDFLAGS} ${USEAGENTLIBS} ${LIBS} -lpcap + + libnetsnmptrapd.$(LIB_EXTENSION)$(LIB_VERSION): $(LLIBTRAPD_OBJS) +- $(LIB_LD_CMD) $@ ${LLIBTRAPD_OBJS} $(MIBLIB) $(MYSQL_LIBS) $(USELIBS) $(PERLLDOPTS_FOR_LIBS) $(LDFLAGS) ++ $(LIB_LD_CMD) $@ ${LLIBTRAPD_OBJS} $(MIBLIB) $(AGENTLIB) $(MYSQL_LIBS) $(USELIBS) $(PERLLDOPTS_FOR_LIBS) $(LDFLAGS) + $(RANLIB) $@ + + snmpinforminstall: +diff --git a/configure b/configure +index 6ef0026..4270aff 100755 +--- a/configure ++++ b/configure +@@ -683,6 +683,7 @@ PERLLDOPTS_FOR_APPS + PERLLDOPTS_FOR_LIBS + EMBEDPERLUNINSTALL + EMBEDPERLINSTALL ++LIBCRYPTO + LIBCURSES + HAVE_LIBCURSES + NETSNMP_BUILD_PCAP_PROG_FALSE +@@ -32065,6 +32066,12 @@ printf "%s\n" "$netsnmp_cv_func_ceil_LNETSNMPLIBS" >&6; } + fi + + ++if test x$CRYPTO != x; then ++ LMIBLIBS="$LMIBLIBS $LIBCRYPTO" ++fi ++ ++ ++ + cat >confcache <<\_ACEOF + # This file is a shell script that caches the results of configure + # tests run on this system so they can be shared between configure +diff --git a/configure.d/config_os_libs2 b/configure.d/config_os_libs2 +index 5787e58..d21ea77 100644 +--- a/configure.d/config_os_libs2 ++++ b/configure.d/config_os_libs2 +@@ -718,3 +718,9 @@ AC_SUBST([LIBCURSES]) + # libm for ceil + # + NETSNMP_SEARCH_LIBS(ceil, m,,,, LNETSNMPLIBS) ++ ++if test x$CRYPTO != x; then ++ LMIBLIBS="$LMIBLIBS $LIBCRYPTO" ++fi ++ ++AC_SUBST(LIBCRYPTO) +-- +2.43.0 + diff --git a/meta-networking/recipes-protocols/net-snmp/net-snmp_5.9.5.2.bb b/meta-networking/recipes-protocols/net-snmp/net-snmp_5.9.5.2.bb index 00a7b50cdf..48704d020f 100644 --- a/meta-networking/recipes-protocols/net-snmp/net-snmp_5.9.5.2.bb +++ b/meta-networking/recipes-protocols/net-snmp/net-snmp_5.9.5.2.bb @@ -24,6 +24,7 @@ SRC_URI = "${SOURCEFORGE_MIRROR}/net-snmp/net-snmp-${PV}.tar.gz \ file://0009-net-snmp-fix-for-disable-des.patch \ file://0010-net-snmp-Reproducibility-Don-t-check-build-host-for.patch \ file://0011-ac_add_search_path.m4-keep-consistent-between-32bit-.patch \ + file://0012-apps-Makefile.in-Link-libraries-explicitly.patch \ file://netsnmp-swinst-crash.patch \ " SRC_URI[sha256sum] = "16707719f833184a4b72835dac359ae188123b06b5e42817c00790d7dc1384bf" From patchwork Wed Aug 5 21:26:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Khem Raj X-Patchwork-Id: 94646 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1F24DC561E6 for ; Wed, 5 Aug 2026 21:26:21 +0000 (UTC) Received: from mail-pg1-f181.google.com (mail-pg1-f181.google.com [209.85.215.181]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6106.1785965179241242415 for ; Wed, 05 Aug 2026 14:26:19 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=ausK7kvG; spf=pass (domain: gmail.com, ip: 209.85.215.181, mailfrom: raj.khem@gmail.com) Received: by mail-pg1-f181.google.com with SMTP id 41be03b00d2f7-cbe3fed2f58so1233075a12.3 for ; Wed, 05 Aug 2026 14:26:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785965179; x=1786569979; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=am69Zl6c9X7OKQcnmcDDOCqJhLtAuqm9gwewp3ty2KA=; b=ausK7kvG7/o/kP/eeAmbgG85s8yVLpmoYhZIsbvL2fF3+4l22ae0sggC/Y+QiZOrDZ NZrIsd9iCiE5pCVehbUczLXCHHXu6CemJKJA9aaPYTFe2syXsCXwaQGXvHooHZsebY3i 5VEEOSnxmzz+AixJMWO2YhlmiNNUUJ1KYIJztKuuCmO8DK9BZz4fsh0aySpqmgrlO5EF fxQP9B7UzI9x8utgpLypNeQ7uaDfREUZNO6DtK34sS5QMQLu6yMqepl/H2+xL75DBNp8 A5bfgmZ40RkUkGX4RKb904+Zos927AUEaYNbqqAN5AVSbrALpypPpBXEORUI9iLLB+qz y3Qw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785965179; x=1786569979; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=am69Zl6c9X7OKQcnmcDDOCqJhLtAuqm9gwewp3ty2KA=; b=tRMRoNca1OGH3X2o2RCIAz3dMjv9Sk1z/o5flOcp0dGwOIRxWGP2tOV2MkzTUpb+ab n4O9eNTa5lfmHsaxKb1i+Op4My6bi0VO5mxLJNUnruYOHi5hiEndHHD+EmxWD29P3UjI L/Z2r/aikWjhxsu5GgwTDzl9rVH/7oTLblW7Fi7lDdvWKRbgwzHRvUqlNKEPJvAMR0gI TnGpVp5zUeKQeCRem4/Dmx4mKDm03qagzOeyBgTJcZPSTCOr9DiUGr1oEP0XmbiCjbNQ FfV3JokYogaAadtYN5wauKZW4pZXyt9TptYQpGwx/d7RyqiFzgjgx/+qJ6nA9xcvpwz1 mPKg== X-Gm-Message-State: AOJu0YwoWvEMnqWVJtrw5n83GYA1eZH55uDn8IPefcvb2UrF75rzc91z FaHCThx8e2D8bueubB3kqU3oF9/6nY2IsbpiWSghF1ucB21EJNkEC+dT4ORtIJ3I X-Gm-Gg: AR+sD13NGtpj/Y1ybA4iPZ57mumzcgHgVS9VZ02sYMaWZyY00no4rDPJ+VSV0Scs2Cm LFS2TXEYBQ7QQC5AJjRM7UBt3TtUwuqvR+7rdrVQNHTnz5oACjt1LC7O0DY3RYQWb0kyAV3casP y8cjGbBDnLSGoyKrNtwvRZB2jqnlL6m9XYs/R18run+1oW+739QwKTKagLEi26Dy9qmGoIrJ9tE aATAxTDWyD6fntNqd2OsF7+5dfrxheMI0iMGwDcRRnreHzNYjlz9GSbUxNUi1SveHoikvD5Vz6B NI0s3mI8BfvpLiZ4hAshwFOKRr6WvL7RjwVM5gQjP3BDxsmBDYic1NDk1h8cSySwhGiDf7R3frX inNj8WOn2u0XvNYa2XgBoMYzMWFhqqGSo1t+osvKuQxtTACLVRbaCio9X18+Wl0jux6i3QI59Wo yjd6oX4TP7QkcFKa6sjZqT5deMw/Qaw++KO/dSUqGoaShk859peO66IvOYOm4SDJjE5lhkN2pOB 9dibUQmNfB/JRPw6rOGmdN74144N90LMtHzURVDp5RAkRm7Cshm0bdv2Sx8YMvgcm1Fa7MwKmN2 5ZaLNIzcCMSqU8SzezwVMaAxRGVAH25j0a4pOARdBU9OCbSK6NK1tZ8B4Mxsm+hkAQ1IPR6Cqia BSA== X-Received: by 2002:a05:6a21:70c8:b0:3c3:b226:f165 with SMTP id adf61e73a8af0-3cb8603af69mr11093944637.35.1785965178491; Wed, 05 Aug 2026 14:26:18 -0700 (PDT) Received: from apollo.localdomain ([208.95.233.74]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3158673be4dsm25585093eec.16.2026.08.05.14.26.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 05 Aug 2026 14:26:17 -0700 (PDT) From: Khem Raj X-Google-Original-From: Khem Raj To: openembedded-devel@lists.openembedded.org Cc: Khem Raj Subject: [meta-oe][PATCH 3/3] cjose: Fix build with clang by initializing decoded buffer lengths Date: Wed, 5 Aug 2026 14:26:12 -0700 Message-ID: <20260805212612.1351211-3-khem.raj@oss.qualcomm.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805212612.1351211-1-khem.raj@oss.qualcomm.com> References: <20260805212612.1351211-1-khem.raj@oss.qualcomm.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 05 Aug 2026 21:26:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/128825 _cjose_jwk_import_RSA() and _cjose_jwk_import_EC() declare their *_buflen variables in the middle of the function, interleaved with error paths that goto a shared cleanup label. An early decode failure jumps over the remaining declarations, and the cleanup block then reads them uninitialized: | jwk.c:1501:9: error: variable 'dq_buflen' is used uninitialized | whenever 'if' condition is true | [-Werror,-Wsometimes-uninitialized] | jwk.c:1554:39: note: uninitialized use occurs here | _cjose_cleanse_dealloc(dq_buffer, dq_buflen); _cjose_cleanse_dealloc() uses the length to wipe key material, so this is an out-of-bounds write hazard on the error path rather than just a warning. src/Makefile.am builds with -Werror, so clang also makes it fatal; the 0.6.2.4 -> 0.6.2.7 upgrade exposed it. Verified on aarch64 for qemuarm64: do_compile fails before the change with 20 such errors, and do_compile and do_package succeed after. Signed-off-by: Khem Raj --- ...-the-decoded-buffer-lengths-up-front.patch | 149 ++++++++++++++++++ .../recipes-support/cjose/cjose_0.6.2.7.bb | 4 +- 2 files changed, 152 insertions(+), 1 deletion(-) create mode 100644 meta-oe/recipes-support/cjose/cjose/0001-jwk-initialize-the-decoded-buffer-lengths-up-front.patch diff --git a/meta-oe/recipes-support/cjose/cjose/0001-jwk-initialize-the-decoded-buffer-lengths-up-front.patch b/meta-oe/recipes-support/cjose/cjose/0001-jwk-initialize-the-decoded-buffer-lengths-up-front.patch new file mode 100644 index 0000000000..eace7b659f --- /dev/null +++ b/meta-oe/recipes-support/cjose/cjose/0001-jwk-initialize-the-decoded-buffer-lengths-up-front.patch @@ -0,0 +1,149 @@ +From 5e8337d3c0ad2b19b78098f72814fbe2442226c9 Mon Sep 17 00:00:00 2001 +From: Khem Raj +Date: Wed, 5 Aug 2026 19:27:04 +0000 +Subject: [PATCH] jwk: initialize the decoded buffer lengths up front + +_cjose_jwk_import_EC() and _cjose_jwk_import_RSA() declare their +*_buflen variables in the middle of the function, interleaved with +error paths that goto the shared cleanup label. When an early decode +fails, the goto jumps over the remaining declarations and the cleanup +block then reads them uninitialized: + +| jwk.c:1501:9: error: variable 'dq_buflen' is used uninitialized +| whenever 'if' condition is true +| [-Werror,-Wsometimes-uninitialized] +| jwk.c:1554:39: note: uninitialized use occurs here +| _cjose_cleanse_dealloc(dq_buffer, dq_buflen); + +_cjose_cleanse_dealloc() uses the length to wipe key material, so this +is a real out-of-bounds write hazard on the error path, not just a +warning. src/Makefile.am builds with -Werror, so it also breaks the +build with clang. + +Declare the lengths alongside the buffers they pair with and assign +them where they were previously initialized. + +Upstream-Status: Submitted [https://github.com/OpenIDC/cjose/pull/32] +Signed-off-by: Khem Raj +--- + src/jwk.c | 25 ++++++++++++++----------- + 1 file changed, 14 insertions(+), 11 deletions(-) + +diff --git a/src/jwk.c b/src/jwk.c +index 9c57a0b..58f872b 100644 +--- a/src/jwk.c ++++ b/src/jwk.c +@@ -1371,6 +1371,9 @@ static cjose_jwk_t *_cjose_jwk_import_EC(json_t *jwk_json, cjose_err *err) + uint8_t *x_buffer = NULL; + uint8_t *y_buffer = NULL; + uint8_t *d_buffer = NULL; ++ size_t x_buflen = 0; ++ size_t y_buflen = 0; ++ size_t d_buflen = 0; + + // get the value of the crv attribute + const char *crv_str = _get_json_object_string_attribute(jwk_json, CJOSE_JWK_CRV_STR, err); +@@ -1389,7 +1392,7 @@ static cjose_jwk_t *_cjose_jwk_import_EC(json_t *jwk_json, cjose_err *err) + } + + // get the decoded value of the x coordinate +- size_t x_buflen = (size_t)_ec_size_for_curve(crv, err); ++ x_buflen = (size_t)_ec_size_for_curve(crv, err); + if (!_decode_json_object_base64url_attribute(jwk_json, CJOSE_JWK_X_STR, &x_buffer, &x_buflen, err)) + { + CJOSE_ERROR(err, CJOSE_ERR_INVALID_ARG); +@@ -1397,7 +1400,7 @@ static cjose_jwk_t *_cjose_jwk_import_EC(json_t *jwk_json, cjose_err *err) + } + + // get the decoded value of the y coordinate +- size_t y_buflen = (size_t)_ec_size_for_curve(crv, err); ++ y_buflen = (size_t)_ec_size_for_curve(crv, err); + if (!_decode_json_object_base64url_attribute(jwk_json, CJOSE_JWK_Y_STR, &y_buffer, &y_buflen, err)) + { + CJOSE_ERROR(err, CJOSE_ERR_INVALID_ARG); +@@ -1405,7 +1408,7 @@ static cjose_jwk_t *_cjose_jwk_import_EC(json_t *jwk_json, cjose_err *err) + } + + // get the decoded value of the private key d +- size_t d_buflen = (size_t)_ec_size_for_curve(crv, err); ++ d_buflen = (size_t)_ec_size_for_curve(crv, err); + if (!_decode_json_object_base64url_attribute(jwk_json, CJOSE_JWK_D_STR, &d_buffer, &d_buflen, err)) + { + CJOSE_ERROR(err, CJOSE_ERR_INVALID_ARG); +@@ -1455,9 +1458,16 @@ static cjose_jwk_t *_cjose_jwk_import_RSA(json_t *jwk_json, cjose_err *err) + uint8_t *dp_buffer = NULL; + uint8_t *dq_buffer = NULL; + uint8_t *qi_buffer = NULL; ++ size_t n_buflen = 0; ++ size_t e_buflen = 0; ++ size_t d_buflen = 0; ++ size_t p_buflen = 0; ++ size_t q_buflen = 0; ++ size_t dp_buflen = 0; ++ size_t dq_buflen = 0; ++ size_t qi_buflen = 0; + + // get the decoded value of n (buflen = 0 means no particular expected len) +- size_t n_buflen = 0; + if (!_decode_json_object_base64url_attribute(jwk_json, CJOSE_JWK_N_STR, &n_buffer, &n_buflen, err)) + { + CJOSE_ERROR(err, CJOSE_ERR_INVALID_ARG); +@@ -1465,7 +1475,6 @@ static cjose_jwk_t *_cjose_jwk_import_RSA(json_t *jwk_json, cjose_err *err) + } + + // get the decoded value of e +- size_t e_buflen = 0; + if (!_decode_json_object_base64url_attribute(jwk_json, CJOSE_JWK_E_STR, &e_buffer, &e_buflen, err)) + { + CJOSE_ERROR(err, CJOSE_ERR_INVALID_ARG); +@@ -1473,7 +1482,6 @@ static cjose_jwk_t *_cjose_jwk_import_RSA(json_t *jwk_json, cjose_err *err) + } + + // get the decoded value of d +- size_t d_buflen = 0; + if (!_decode_json_object_base64url_attribute(jwk_json, CJOSE_JWK_D_STR, &d_buffer, &d_buflen, err)) + { + CJOSE_ERROR(err, CJOSE_ERR_INVALID_ARG); +@@ -1481,7 +1489,6 @@ static cjose_jwk_t *_cjose_jwk_import_RSA(json_t *jwk_json, cjose_err *err) + } + + // get the decoded value of p +- size_t p_buflen = 0; + if (!_decode_json_object_base64url_attribute(jwk_json, CJOSE_JWK_P_STR, &p_buffer, &p_buflen, err)) + { + CJOSE_ERROR(err, CJOSE_ERR_INVALID_ARG); +@@ -1489,7 +1496,6 @@ static cjose_jwk_t *_cjose_jwk_import_RSA(json_t *jwk_json, cjose_err *err) + } + + // get the decoded value of q +- size_t q_buflen = 0; + if (!_decode_json_object_base64url_attribute(jwk_json, CJOSE_JWK_Q_STR, &q_buffer, &q_buflen, err)) + { + CJOSE_ERROR(err, CJOSE_ERR_INVALID_ARG); +@@ -1497,7 +1503,6 @@ static cjose_jwk_t *_cjose_jwk_import_RSA(json_t *jwk_json, cjose_err *err) + } + + // get the decoded value of dp +- size_t dp_buflen = 0; + if (!_decode_json_object_base64url_attribute(jwk_json, CJOSE_JWK_DP_STR, &dp_buffer, &dp_buflen, err)) + { + CJOSE_ERROR(err, CJOSE_ERR_INVALID_ARG); +@@ -1505,7 +1510,6 @@ static cjose_jwk_t *_cjose_jwk_import_RSA(json_t *jwk_json, cjose_err *err) + } + + // get the decoded value of dq +- size_t dq_buflen = 0; + if (!_decode_json_object_base64url_attribute(jwk_json, CJOSE_JWK_DQ_STR, &dq_buffer, &dq_buflen, err)) + { + CJOSE_ERROR(err, CJOSE_ERR_INVALID_ARG); +@@ -1513,7 +1517,6 @@ static cjose_jwk_t *_cjose_jwk_import_RSA(json_t *jwk_json, cjose_err *err) + } + + // get the decoded value of qi +- size_t qi_buflen = 0; + if (!_decode_json_object_base64url_attribute(jwk_json, CJOSE_JWK_QI_STR, &qi_buffer, &qi_buflen, err)) + { + CJOSE_ERROR(err, CJOSE_ERR_INVALID_ARG); +-- +2.43.0 + diff --git a/meta-oe/recipes-support/cjose/cjose_0.6.2.7.bb b/meta-oe/recipes-support/cjose/cjose_0.6.2.7.bb index b35cf349f1..4538d33ef6 100644 --- a/meta-oe/recipes-support/cjose/cjose_0.6.2.7.bb +++ b/meta-oe/recipes-support/cjose/cjose_0.6.2.7.bb @@ -3,7 +3,9 @@ HOMEPAGE = "https://github.com/OpenIDC/cjose" LICENSE = "MIT" LIC_FILES_CHKSUM = "file://LICENSE;md5=7249e2f9437adfb8c88d870438042f0e" -SRC_URI = "git://github.com/OpenIDC/cjose;protocol=https;branch=version-0.6.2.x;tag=v${PV}" +SRC_URI = "git://github.com/OpenIDC/cjose;protocol=https;branch=version-0.6.2.x;tag=v${PV} \ + file://0001-jwk-initialize-the-decoded-buffer-lengths-up-front.patch \ + " SRCREV = "10af8915a666b50caa5500cdc3f2523b916be720"