Yocto BitBake Question & answerのブログ https://yoctobbq.lineo.co.jp/?q=blog ja Yocto4.2.2(Mickledore)リリース https://yoctobbq.lineo.co.jp/?q=node/491 <div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>2023年5月5日にリリースされたYocto4.2 (Mickledore)の2回目のポイントリリース4.2.2公開のアナウンスが2022年7月20日付けでありました。</p> <p>当初予定より2日早く7月8日版を利用し、7月10日にQA開始、7月15日にQA完了、TSCによるQA結果の確認を経て1日早い7月20日にリリースとなっています。</p> <p>今回の更新では、26個のCVEのFIXの他、linux-yocto は、5.15.118 / 6.1.35 へのバージョンアップを含む更新が行われています。</p> <p>7/8以降次のリリースに向けて、NVDのデータベースv2へのアクセス方法の改良(タイムアウト対策を主体)を目的としたコミットが既に行われています。</p> <p>次のポイントリリース4.2.3 は 2023/8/28にQA開始、2023/9/8 のリリースを予定しています。</p> <p>本リリースの詳細は以下のURLでご確認ください。<br /> <a href="https://lists.yoctoproject.org/g/yocto-announce/message/283">https://lists.yoctoproject.org/g/yocto-announce/message/283</a></p> <p>---------------<br /> Known Issues<br /> ---------------<br /> N/A</p> <p>---------------<br /> Security Fixes<br /> ---------------<br /> binutils: Fix CVE-2023-1972<br /> cups: Fix CVE-2023-32324<br /> curl: Fix CVE-2023-28319 CVE-2023-28320 CVE-2023-28321 CVE-2023-28322<br /> dbus: Fix CVE-2023-34969<br /> git: Fix CVE-2023-25652 CVE-2023-29007<br /> git: Ignore CVE-2023-25815<br /> libwebp: Fix CVE-2023-1999<br /> libxml2: Fix CVE-2023-28484 CVE-2023-29469<br /> libxpm: Fix CVE-2022-44617<br /> ninja: Ignore CVE-2021-4336<br /> openssl: Fix CVE-2023-2650 CVE-2023-1255 CVE-2023-0466 CVE-2023-0465 CVE-2023-0464<br /> perl: Fix CVE-2023-31484 CVE-2023-31486<br /> sysstat: Fix CVE-2023-33204<br /> tiff: Fix CVE-2023-2731 CVE-2023-25434 CVE-2023-26965<br /> vim: Fix CVE-2023-2426</p> <p>---------------<br /> Fixes<br /> ---------------<br /> apr: Upgrade to 1.7.4<br /> avahi: fix D-Bus introspection<br /> babeltrace2: Always use BFD linker when building tests with ld-is-lld distro feature<br /> babeltrace2: Upgrade to 2.0.5<br /> baremetal-helloworld: Update SRCREV to fix entry addresses for ARM architectures<br /> bind: Upgrade to 9.18.15<br /> binutils: move packaging of gprofng static lib into common .inc<br /> binutils: package static libs from gprofng<br /> binutils: stable 2.40 branch updates (7343182dd1)<br /> bitbake.conf: add unzstd in HOSTTOOLS<br /> bitbake: runqueue: Fix deferred task/multiconfig race issue<br /> bno_plot.py, btt_plot.py: Ask for python3 specifically<br /> build-appliance-image: Update to mickledore head revision<br /> busybox: Upgrade to 1.36.1<br /> cmake.bbclass: do not search host paths for find_program()<br /> conf: add nice level to the hash config ignred variables<br /> connman: fix warning by specifying runstatedir at configure time<br /> cpio: Run ptests under ptest user<br /> dbus: Upgrade to 1.14.8<br /> devtool: Fix the wrong variable in srcuri_entry<br /> dnf: only write the log lock to root for native dnf<br /> docs: bsp-guide: bsp: fix typo<br /> dpkg: Upgrade to v1.21.22<br /> e2fsprogs: Fix error SRCDIR when using usrmerge DISTRO_FEATURES<br /> e2fsprogs: fix ptest bug for second running<br /> ell: Upgrade to 0.57<br /> expect: Add ptest support<br /> fribidi: Upgrade to 1.0.13<br /> gawk: Upgrade to 5.2.2<br /> gcc : upgrade to v12.3<br /> gdb: fix crashes when debugging threads with Arm Pointer Authentication enabled<br /> gdb: Upgrade to 13.2<br /> git: Upgrade to 2.39.3<br /> glib-networking: use correct error code in ptest<br /> glibc: Pass linker choice via compiler flags<br /> glibc: stable 2.37 branch updates.<br /> gnupg: Upgrade to 2.4.2<br /> go.bbclass: don&#039;t use test to check output from ls<br /> go: Upgrade to 1.20.5<br /> go: Use -no-pie to build target cgo<br /> gobject-introspection: remove obsolete DEPENDS<br /> grub: submit determinism.patch upstream<br /> gstreamer1.0: Upgrade to 1.22.3<br /> gtk4: Upgrade to 4.10.4<br /> image-live.bbclass: respect IMAGE_MACHINE_SUFFIX<br /> image_types: Fix reproducible builds for initramfs and UKI img<br /> inetutils: remove unused patch files<br /> ipk: Revert Decode byte data to string in manifest handling<br /> iso-codes: Upgrade to 4.15.0<br /> kernel: don&#039;t force PAHOLE=false<br /> kmod: remove unused ptest.patch<br /> kmscube: Correct DEPENDS to avoid overwrite<br /> layer.conf: Add missing dependency exclusion<br /> lib/terminal.py: Add urxvt terminal<br /> libbsd: Add correct license for all packages<br /> libdnf: Upgrade to 0.70.1<br /> libgcrypt: Upgrade to 1.10.2<br /> libgloss: remove unused patch file<br /> libmicrohttpd: Upgrade to 0.9.77<br /> libmodule-build-perl: Upgrade to 0.4234<br /> libx11: remove unused patch and FILESEXTRAPATHS<br /> libx11: Upgrade to 1.8.5<br /> libxfixes: Upgrade to v6.0.1<br /> libxft: Upgrade to 2.3.8<br /> libxi: Upgrade to v1.8.1<br /> libxml2: Do not use lld linker when building with tests on rv64<br /> libxml2: Upgrade to 2.10.4<br /> libxpm: Upgrade to 3.5.16<br /> linux-firmware: Upgrade to 20230515<br /> linux-yocto/5.15: cfg: fix DECNET configuration warning<br /> linux-yocto/5.15: Upgrade to v5.15.118<br /> linux-yocto/6.1: fix intermittent x86 boot hangs<br /> linux-yocto/6.1: Upgrade to v6.1.35<br /> linux-yocto: move build / debug dependencies to .inc<br /> logrotate: Do not create logrotate.status file<br /> maintainers.inc: correct Carlos Rafael Giani&#039;s email address<br /> maintainers.inc: correct unassigned entries<br /> maintainers.inc: unassign Adrian Bunk from wireless-regdb<br /> maintainers.inc: unassign Alistair Francis from opensbi<br /> maintainers.inc: unassign Andreas Müller from itstool entry<br /> maintainers.inc: unassign Chase Qi from libc-test<br /> maintainers.inc: unassign Oleksandr Kravchuk from python3 and all other items<br /> maintainers.inc: unassign Pascal Bach from cmake entry<br /> maintainers.inc: unassign Ricardo Neri from ovmf<br /> maintainers.inc: update version for gcc-source<br /> maintainers.inc: unassign Richard Weinberger from erofs-utils entry<br /> meta: depend on autoconf-archive-native, not autoconf-archive<br /> meta: lib: oe: npm_registry: Add more safe caracters<br /> migration-guides: add release notes for 4.2.1<br /> minicom: remove unused patch files<br /> mobile-broadband-provider-info: Upgrade to 20230416<br /> musl: Correct SRC_URI<br /> oeqa/selftest/bbtests: add non-existent prefile/postfile tests<br /> oeqa/selftest/cases/devtool.py: skip all tests require folder a git repo<br /> oeqa: adding selftest-hello and use it to speed up tests<br /> openssh: Remove BSD-4-clause contents completely from codebase<br /> openssl: fix building on riscv32<br /> openssl: Upgrade to 3.1.1<br /> overview-manual: concepts.rst: Fix a typo<br /> parted: Add missing libuuid to linker cmdline for libparted-fs-resize.so<br /> perf: Make built-in libtraceevent plugins cohabit with external libtraceevent<br /> piglit: Add missing glslang dependencies<br /> piglit: Fix c++11-narrowing warnings in tests<br /> pkgconf: Upgrade to 1.9.5<br /> pm-utils: fix multilib conflictions<br /> poky.conf: bump version for 4.2.2 release<br /> populate_sdk_base.bbclass: respect MLPREFIX for ptest-pkgs&#039;s ptest-runner<br /> profile-manual: fix blktrace remote usage instructions<br /> psmisc: Set ALTERNATIVE for pstree to resolve conflict with busybox<br /> ptest-runner: Ensure data writes don&#039;t race<br /> ptest-runner: Pull in &quot;runner: Remove threads and mutexes&quot; fix<br /> ptest-runner: Pull in sync fix to improve log warnings<br /> python3-bcrypt: Use BFD linker when building tests<br /> python3-numpy: remove NPY_INLINE, use inline instead<br /> qemu: a pending patch was submitted and accepted upstream<br /> qemu: remove unused qemu-7.0.0-glibc-2.36.patch<br /> qemurunner.py: fix error message about qmp<br /> qemurunner: avoid leaking server_socket<br /> ref-manual: add clarification for SRCREV<br /> ref-manual: classes.rst: fix typo<br /> rootfs-postcommands.bbclass: add post func remove_unused_dnf_log_lock<br /> rpcsvc-proto: Upgrade to 1.4.4<br /> rpm: drop unused 0001-Rip-out-partial-support-for-unused-MD2-and-RIPEMD160.patch<br /> rpm: Upgrade to 4.18.1<br /> rpm: write macros under libdir<br /> runqemu-gen-tapdevs: Refactoring<br /> runqemu-ifupdown/get-tapdevs: Add support for ip tuntap<br /> scripts/runqemu: allocate unfsd ports in a way that doesn&#039;t race or clash with unrelated processes<br /> scripts/runqemu: split lock dir creation into a reusable function<br /> scripts: fix buildstats diff/summary hard bound to host python3<br /> sdk.py: error out when moving file fails<br /> sdk.py: fix moving dnf contents<br /> selftest/license: Exclude from world<br /> selftest/reproducible: Allow native/cross reuse in test<br /> serf: Upgrade to 1.3.10<br /> staging.bbclass: do not add extend_recipe_sysroot to prefuncs of prepare_recipe_sysroot<br /> strace: Disable failing test<br /> strace: Merge two similar patches<br /> strace: Update patches/tests with upstream fixes<br /> sysfsutils: fetch a supported fork from github<br /> systemd-systemctl: support instance expansion in WantedBy<br /> systemd: Drop a backport<br /> tiff: Remove unused patch from tiff<br /> uninative: Upgrade to 3.10 to support gcc 13<br /> uninative: Upgrade to 4.0 to include latest gcc 13.1.1<br /> unzip: fix configure check for cross compilation<br /> unzip: remove hardcoded LARGE_FILE_SUPPORT<br /> useradd-example: package typo correction<br /> useradd-staticids.bbclass: improve error message<br /> v86d: Improve kernel dependency<br /> vim: Upgrade to 9.0.1527<br /> weston-init: add profile to point users to global socket<br /> weston-init: add the weston user to the wayland group<br /> weston-init: add weston user to the render group<br /> weston-init: fix the mixed indentation<br /> weston-init: guard against systemd configs<br /> weston-init: make sure the render group exists<br /> wget: Upgrade to 1.21.4<br /> wireless-regdb: Upgrade to 2023.05.03<br /> xdpyinfo: Upgrade to 1.3.4<br /> xf86-video-intel: Use the HTTPS protocol to fetch the Git repositories<br /> xinput: upgrade to v1.6.4<br /> xwininfo: upgrade to v1.1.6<br /> xz: Upgrade to 5.4.3<br /> yocto-bsps: update to v5.15.106<br /> zip: fix configure check by using _Static_assert<br /> zip: remove unnecessary LARGE_FILE_SUPPORT CLFAGS</p> </div></div></div> Thu, 20 Jul 2023 13:23:44 +0000 yakuhito 491 at https://yoctobbq.lineo.co.jp https://yoctobbq.lineo.co.jp/?q=node/491#comments Yocto4.0.11 LTS(Kirkstone)リリース https://yoctobbq.lineo.co.jp/?q=node/489 <div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>2022年4月にリリースされたYocto4.0 LTS (Kirkstone)の11回目のポイントリリース4.0.11公開のアナウンスが2023年7月4日付けでありました。<br /> 当初予定より3日早く6月23日版で構築、QAは7月3日に完了、TSC Teamのチェックを経て、予定より3日早く早く7月4日のリリースアナウンスとなりました。</p> <p>今回のリリースでの主な変更点:<br />   〇 CVEに登録された脆弱性への対応<br />   〇 カーネルは 5.10は. 5.10.175から5.10.180へ、5.15は 5.15.108 から 5.15.113 へアップグレード</p> <p>  リリースアナウンスの時点で、次のポイントリリースに向けてのコミットが複数行われています。<br /> 。</p> <p>次のポイントリリース4.0.12 は 2023/08/07 版で構築、QA後の2023/08/18 のリリースを予定しています。</p> <p>本リリースの詳細は以下のURLでご確認ください。<br /> <a href="https://lists.yoctoproject.org/g/yocto-announce/message/282">https://lists.yoctoproject.org/g/yocto-announce/message/282</a></p> <p>---------------<br /> Known Issues<br /> ---------------<br /> N/A</p> <p>---------------<br /> Security Fixes<br /> ---------------<br /> cups: Fix CVE-2023-32324<br /> curl: Fix CVE-2023-28319 CVE-2023-28320 CVE-2023-28321 CVE-2023-28322<br /> git: Ignore CVE-2023-25815<br /> go: Fix CVE-2023-24539 CVE-2023-24540<br /> nasm: Fix CVE-2022-46457<br /> openssh: Fix CVE-2023-28531<br /> openssl: Fix CVE-2023-1255 CVE-2023-2650<br /> perl: Fix CVE-2023-31484<br /> python3-requests: Fix for CVE-2023-32681<br /> sysstat: Fix CVE-2023-33204<br /> vim: Fix CVE-2023-2426<br /> webkitgtk: fix CVE-2022-42867 CVE-2022-46691 CVE-2022-46699 CVE-2022-46700</p> <p>---------------<br /> Fixes<br /> ---------------<br /> Revert &quot;docs: conf.py: fix cve extlinks caption for sphinx &lt;4.0&quot;<br /> Revert &quot;ipk: Decode byte data to string in manifest handling&quot;<br /> avahi: fix D-Bus introspection<br /> build-appliance-image: Update to kirkstone head revision<br /> conf.py: add macro for Mitre CVE links<br /> conf: add nice level to the hash config ignred variables<br /> cpio: Fix wrong CRC with ASCII CRC for large files<br /> cve-update-nvd2-native: added the missing http import<br /> cve-update-nvd2-native: new CVE database fetcher<br /> dhcpcd: use git instead of tarballs<br /> e2fsprogs: fix ptest bug for second running<br /> gcc-runtime: Use static dummy libstdc++<br /> glibc: stable 2.35 branch updates (cbceb903c4d7)<br /> go.bbclass: don&#039;t use test to check output from ls<br /> gstreamer1.0: Upgrade to 1.20.6<br /> iso-codes: Upgrade to 4.15.0<br /> kernel-devicetree: allow specification of dtb directory<br /> kernel-devicetree: make shell scripts posix compliant<br /> kernel-devicetree: recursively search for dtbs<br /> kernel: don&#039;t force PAHOLE=false<br /> kmscube: Correct DEPENDS to avoid overwrite<br /> lib/terminal.py: Add urxvt terminal<br /> license.bbclass: Include LICENSE in the output when it fails to parse<br /> linux-yocto/5.10: Upgrade to v5.10.180<br /> linux-yocto/5.15: Upgrade to v5.15.113<br /> llvm: backport a fix for build with gcc-13<br /> maintainers.inc: Fix email address typo<br /> maintainers.inc: Move repo to unassigned<br /> migration-guides: add release notes for 4.0.10<br /> migration-guides: use new cve_mitre macro<br /> nghttp2: Deleted the entries for -client and -server, and removed a dependency on them from the main package.<br /> oeqa/selftest/cases/devtool.py: skip all tests require folder a git repo<br /> openssh: Remove BSD-4-clause contents completely from codebase<br /> openssl: Upgrade to 3.0.9<br /> overview-manual: concepts.rst: Fix a typo<br /> p11-kit: add native to BBCLASSEXTEND<br /> package: enable recursion on file globs<br /> package_manager/ipk: fix config path generation in _create_custom_config()<br /> piglit: Add PACKAGECONFIG for glx and opencl<br /> piglit: Add missing glslang dependencies<br /> piglit: Fix build time dependency<br /> poky.conf: bump version for 4.0.11<br /> profile-manual: fix blktrace remote usage instructions<br /> quilt: Fix merge.test race condition<br /> ref-manual: add clarification for SRCREV<br /> selftest/reproducible: Allow native/cross reuse in test<br /> staging.bbclass: do not add extend_recipe_sysroot to prefuncs of prepare_recipe_sysroot<br /> systemd-networkd: backport fix for rm unmanaged wifi<br /> systemd-systemctl: fix instance template WantedBy symlink construction<br /> systemd-systemctl: support instance expansion in WantedBy<br /> uninative: Upgrade to 3.10 to support gcc 13<br /> uninative: Upgrade to 4.0 to include latest gcc 13.1.1<br /> vim: Upgrade to 9.0.1527<br /> waffle: Upgrade to 1.7.2<br /> weston: add xwayland to DEPENDS for PACKAGECONFIG xwayland</p> </div></div></div> Tue, 04 Jul 2023 04:15:01 +0000 yakuhito 489 at https://yoctobbq.lineo.co.jp https://yoctobbq.lineo.co.jp/?q=node/489#comments Yocto3.1.26 LTS(Dunfell 23.26)リリース https://yoctobbq.lineo.co.jp/?q=node/487 <div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>Yocto3.1.26 LTS(Dunfell 23.26)リリース</p> <p>一昨年4月にリリースされたYocto3.1LTS(Dunfell)の26回目のポイントリリース、3.1.26公開のアナウンスが 2023年6月28日付けでありました。</p> <p>予定より2日早い6月17日版で構築、6/22にQA完了、TSCの承認を経て予定より2日早く、6月28日 にリリースされています。</p> <p>今回のリリースでは、CVEへの対応、UpStreanでのアップデート対応の他、linux-yoctoに対するNVDのデータベースに未反映のFix済CVEがignore-listに追加され、linux-yoctoのunfixedは、実際に未対応のもののみ表示されるようになりました。<br /> kernelは5.4.237 から 5.4.243 にアップデートしています。</p> <p>6/29 9:00 現在、次回リリースに向けてコミットは始まっており、CVEのFIXの他、cve-checkで参照するNVDのデータベースが、現在のフォーマットでの提供が2023年末で終了となることへの対応が入っています。</p> <p>次のバージョン 3.1.27 は 2023/07/31版で構築、2023/8/11リリースの予定となっています。</p> <p>本リリースの詳細は以下のURLでご確認ください。<br /> <a href="https://lists.yoctoproject.org/g/yocto-announce/message/281">https://lists.yoctoproject.org/g/yocto-announce/message/281</a></p> <p>---------------<br /> Known Issues<br /> ---------------<br /> N/A</p> <p>---------------<br /> Security Fixes<br /> ---------------<br /> connman: Fix CVE-2023-28488<br /> curl: Update fix for CVE-2023-27534<br /> ffmpeg: Fix CVE-2022-48434<br /> freetype: Fix CVE-2023-2004<br /> ghostscript: Fix CVE-2023-28879<br /> git: Fix CVE-2023-25652 CVE-2023-29007<br /> go: Fix CVE-2023-24538 CVE-2023-24539 CVE-2023-24540<br /> libwebp: Fix CVE-2023-1999<br /> libxml2: Fix CVE-2023-28484 CVE-2023-29469<br /> linux-yocto: Ignore CVE-2014-8171 CVE-2017-1000255 CVE-2018-10840 CVE-2018-10876 CVE-2018-10882 CVE-2018-10902 CVE-2018-14625 CVE-2018-16880 CVE-2018-16884 CVE-2018-5873 CVE-2019-20810 CVE-2019-3819 CVE-2020-10690 CVE-2020-10711 CVE-2020-10732 CVE-2020-10742 CVE-2020-10757 CVE-2020-10766 CVE-2020-10767 CVE-2020-10768 CVE-2020-10781 CVE-2020-10942 CVE-2020-11494 CVE-2020-11565 CVE-2020-11608 CVE-2020-11609 CVE-2020-11668 CVE-2020-11884 CVE-2020-12464 CVE-2020-12465 CVE-2020-12653 CVE-2020-12654 CVE-2020-12655 CVE-2020-12657 CVE-2020-12659 CVE-2020-12768 CVE-2020-12770 CVE-2020-12771 CVE-2020-12826 CVE-2020-12888 CVE-2020-13143 CVE-2020-14314 CVE-2020-14331 CVE-2020-14351 CVE-2020-14381 CVE-2020-14385 CVE-2020-14390 CVE-2020-15393 CVE-2020-15436 CVE-2020-15437 CVE-2020-15780 CVE-2020-16119 CVE-2020-16166 CVE-2020-1749 CVE-2020-24394 CVE-2020-25211 CVE-2020-25212 CVE-2020-25284 CVE-2020-25285 CVE-2020-25639 CVE-2020-25641 CVE-2020-25643 CVE-2020-25645 CVE-2020-25656 CVE-2020-25672 CVE-2020-25704 CVE-2020-25705 CVE-2020-26088 CVE-2020-26541 CVE-2020-27170 CVE-2020-27171 CVE-2020-27675 CVE-2020-27777 CVE-2020-27784 CVE-2020-27830 CVE-2020-28097 CVE-2020-28374 CVE-2020-28915 CVE-2020-28941 CVE-2020-28974 CVE-2020-29368 CVE-2020-29369 CVE-2020-29370 CVE-2020-29371 CVE-2020-29373 CVE-2020-29374 CVE-2020-29660 CVE-2020-35508 CVE-2020-36158 CVE-2020-36311 CVE-2020-36312 CVE-2020-36322 CVE-2020-36386 CVE-2020-36516 CVE-2020-36557 CVE-2020-36558 CVE-2020-8428 CVE-2020-8647 CVE-2020-8649 CVE-2020-8992 CVE-2020-9383 CVE-2021-20265 CVE-2021-20292 CVE-2021-20321 CVE-2021-23133 CVE-2021-23134 CVE-2021-27363 CVE-2021-27364 CVE-2021-28714 CVE-2021-28715 CVE-2021-28950 CVE-2021-28964 CVE-2021-28971 CVE-2021-28972 CVE-2021-29265 CVE-2021-29647 CVE-2021-29650 CVE-2021-30002 CVE-2021-3178 CVE-2021-31916 CVE-2021-32399 CVE-2021-3348 CVE-2021-33656 CVE-2021-34693 CVE-2021-3483 CVE-2021-35039 CVE-2021-3506 CVE-2021-3564 CVE-2021-3573 CVE-2021-3609 CVE-2021-3612 CVE-2021-3635 CVE-2021-3640 CVE-2021-3653 CVE-2021-3679 CVE-2021-37159r CVE-2021-3732 CVE-2021-3739 CVE-2021-3744 CVE-2021-3752 CVE-2021-3753 CVE-2021-3759 CVE-2021-3764 CVE-2021-38160 CVE-2021-38198 CVE-2021-38199 CVE-2021-38204 CVE-2021-38205 CVE-2021-38207 CVE-2021-38208 CVE-2021-38209 CVE-2021-3923 CVE-2021-4002 CVE-2021-40490 CVE-2021-4083 CVE-2021-4135 CVE-2021-4149 CVE-2021-4155 CVE-2021-4159 CVE-2021-41864 CVE-2021-42008 CVE-2021-4203 CVE-2021-42252 CVE-2021-42739 CVE-2021-43389 CVE-2021-43975 CVE-2021-43976 CVE-2021-44733 CVE-2021-45095 CVE-2021-45480 CVE-2021-45485 CVE-2021-45486 CVE-2021-45868 CVE-2022-0322 CVE-2022-0330 CVE-2022-0487 CVE-2022-0492 CVE-2022-0494 CVE-2022-0812 CVE-2022-0850 CVE-2022-0854 CVE-2022-1011 CVE-2022-1016 CVE-2022-1055 CVE-2022-1195 CVE-2022-1198 CVE-2022-1199 CVE-2022-1353 CVE-2022-1419 CVE-2022-1462 CVE-2022-1734 CVE-2022-2196 CVE-2022-2318 CVE-2022-2380 CVE-2022-24448 CVE-2022-24959 CVE-2022-2503 CVE-2022-25258 CVE-2022-25375 CVE-2022-25636 CVE-2022-26365 CVE-2022-26490 CVE-2022-2663 CVE-2022-26966 CVE-2022-27223 CVE-2022-27666 CVE-2022-28356 CVE-2022-28388 CVE-2022-28389 CVE-2022-28390 CVE-2022-2873 CVE-2022-28893 CVE-2022-3028 CVE-2022-3105 CVE-2022-3107 CVE-2022-3111 CVE-2022-3115 CVE-2022-3202 CVE-2022-32250 CVE-2022-32296 CVE-2022-32981 CVE-2022-3303 CVE-2022-33740 CVE-2022-33741 CVE-2022-33742 CVE-2022-33744 CVE-2022-33981 CVE-2022-3424 CVE-2022-3435 CVE-2022-3521 CVE-2022-3545 CVE-2022-3564 CVE-2022-3586 CVE-2022-3594 CVE-2022-36123 CVE-2022-3621 CVE-2022-3623 CVE-2022-36280 CVE-2022-3629 CVE-2022-3633 CVE-2022-3635 CVE-2022-3646 CVE-2022-3649 CVE-2022-36879 CVE-2022-36946 CVE-2022-3707 CVE-2022-39188 CVE-2022-39842 CVE-2022-40307 CVE-2022-40768 CVE-2022-4095 CVE-2022-41218 CVE-2022-41222 CVE-2022-4139 CVE-2022-41849 CVE-2022-41850 CVE-2022-41858 CVE-2022-42328 CVE-2022-42329 CVE-2022-42703 CVE-2022-42721 CVE-2022-42895 CVE-2022-4382 CVE-2022-4662 CVE-2022-47929 CVE-2023-0394 CVE-2023-0458 CVE-2023-0461 CVE-2023-1073 CVE-2023-1074 CVE-2023-1077 CVE-2023-1078 CVE-2023-1079 CVE-2023-1095 CVE-2023-1118 CVE-2023-1382 CVE-2023-1390 CVE-2023-1513 CVE-2023-1829 CVE-2023-1838 CVE-2023-1998 CVE-2023-2008 CVE-2023-2162 CVE-2023-2166 CVE-2023-2177 CVE-2023-23006 CVE-2023-23454 CVE-2023-23455 CVE-2023-23559 CVE-2023-25012 CVE-2023-26545 CVE-2023-28327 CVE-2023-28328 CVE-2023-28772<br /> vim: Fix CVE-2023-2426<br /> xserver-xorg: Fix CVE-2023-0494 CVE-2023-1393</p> <p>---------------<br /> Fixes<br /> ---------------<br /> build-appliance-image: Update to dunfell head revision (d91c3c124231)<br /> cpio: Fix wrong CRC with ASCII CRC for large files<br /> documentation: update for 3.1.26<br /> e2fsprogs: fix ptest bug for second running<br /> libbsd: Add correct license for all packages<br /> linux-firmware: upgrade to 20230404<br /> linux-yocto/5.4: upgrade to v5.4.243<br /> oeqa/utils/metadata.py: Fix running oe-selftest running with no distro set<br /> openssh: Move sshdgenkeys.service to sshd.socket<br /> perf: Depend on native setuptools3<br /> poky.conf: bump version for 3.1.26<br /> populate_sdk_ext.bbclass: set METADATA_REVISION with an DISTRO override<br /> pypi.bbclass: Set CVE_PRODUCT to PYPI_PACKAGE<br /> run-postinsts: Set dependency for ldconfig to avoid boot issues<br /> selftest/reproducible: Allow native/cross reuse in test<br /> selftest: skip virgl test on ubuntu 22.10, fedora 37, and all rocky<br /> vim: Upgrade to 9.0.1527<br /> wic/bootimg-efi: if fixed-size is set then use that for mkdosfs</p> </div></div></div> Thu, 29 Jun 2023 00:01:42 +0000 yakuhito 487 at https://yoctobbq.lineo.co.jp https://yoctobbq.lineo.co.jp/?q=node/487#comments Yocto4.2.1 (Mickledore)リリース https://yoctobbq.lineo.co.jp/?q=node/482 <div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>2023年5月5日にリリースされたYocto4.2 (Mickledore)の1回目のポイントリリース4.2.1公開のアナウンスが2022年5月29日付けでありました。</p> <p>当初予定より2日早く5月19日版で構築され、QAを問題無くパスしたため4日早い5月29日にリリースとなっています。<br /> 今回のリリースは、4.2リリース版が2023/4/22のコミットを使用となったため、更新されたものは通常に比べて少なくkernelバージョンの変更はありません。</p> <p>次のポイントリリース4.2.2 は 2023/7/10 版で構築、QA後の2023/7/21 のリリースを予定しています。</p> <p>本リリースの詳細は以下のURLでご確認ください。<br /> <a href="https://lists.yoctoproject.org/g/yocto-announce/message/279">https://lists.yoctoproject.org/g/yocto-announce/message/279</a></p> <p>----------------<br /> Known Issues<br /> ----------------<br /> N/A</p> <p>----------------<br /> Security Fixes<br /> ----------------<br /> connman: Fix CVE-2023-28488<br /> linux-yocto: Ignore CVE-2023-1652 CVE-2023-1829<br /> ghostscript: Fx CVE-2023-28879<br /> qemu: Ignore CVE-2023-0664<br /> ruby: Fix CVE-2022-28738 CVE-2022-28739<br /> tiff: Fix CVE-2022-4645<br /> xwayland: Fix CVE-2023-1393</p> <p>----------------<br /> Fixes<br /> ----------------<br /> apr: upgrade to 1.7.3<br /> bind: upgrade to 9.18.13<br /> build-appliance-image: Update to mickledore head revision<br /> cargo: Fix build on musl/riscv<br /> cpio: fix appending to archives larger than 2GB<br /> cracklib: upgrade to 2.9.11<br /> cve-update-nvd2-native: added the missing http import<br /> dev-manual: init-manager.rst: add summary<br /> dhcpcd: use git instead of tarballs<br /> docs: add support for mickledore (4.2) release<br /> gawk: Add skipped.txt to emit test to ignore<br /> gawk: Disable known ptest fails on musl<br /> gawk: Remove redundant patch<br /> glib-networking: Add test retry to avoid failures<br /> glib-networking: Correct glib error handling in test patch<br /> gtk4: upgrade to 4.10.3<br /> kernel-devsrc: depend on python3-core instead of python3<br /> kernel-fitimage: Fix the default dtb config check<br /> kernel: improve initramfs bundle processing time<br /> libarchive: Enable acls, xattr for native as well as target<br /> libhandy: upgrade to 1.8.2<br /> libnotify: remove dependency dbus<br /> libpam: Fix the xtests/tst-pam_motd[1|3] failures<br /> libpcap: upgrade to 1.10.4<br /> libsdl2: upgrade to 2.26.5<br /> libxml2: Disable icu tests on musl<br /> license.bbclass: Include LICENSE in the output when it fails to parse<br /> linux-firmware: upgrade to 20230404<br /> machine/qemuarm*: don&#039;t explicitly set vmalloc<br /> maintainers.inc: Fix email address typo<br /> maintainers.inc: Move repo to unassigned<br /> man-pages: upgrade to 6.04<br /> manuals: document SPDX_CUSTOM_ANNOTATION_VARS<br /> manuals: expand init manager documentation<br /> mesa: upgrade to 23.0.3<br /> migration-guides: add release-notes for 4.1.4<br /> migration-guides: fixes and improvements to 4.2 release notes<br /> migration-guides: release-notes-4.0.9.rst: add missing SPDX info<br /> migration-guides: release-notes-4.2: add doc improvement highlights<br /> mpg123: upgrade to 1.31.3<br /> mtools: upgrade to 4.0.43<br /> oeqa/utils/metadata.py: Fix running oe-selftest running with no distro set<br /> overview-manual: development-environment: update text and screenshots<br /> overview-manual: update section about source archives<br /> package_manager/ipk: fix config path generation in _create_custom_config()<br /> pango: upgrade to 1.50.14<br /> perl: patch out build paths from native binaries<br /> poky.conf: bump version for 4.2.1 release<br /> populate_sdk_ext.bbclass: redirect stderr to stdout so that both end in LOGFILE<br /> populate_sdk_ext.bbclass: set METADATA_REVISION with an DISTRO override<br /> python3targetconfig.bbclass: Extend PYTHONPATH instead of overwriting<br /> qemu: Add fix for powerpc instruction fallback issue<br /> qemu: Update ppc instruction fix to match revised upstream version<br /> quilt: Fix merge.test race condition<br /> recipes: Default to https git protocol where possible<br /> ref-manual: add &quot;Mixin&quot; term<br /> ref-manual: classes.rst: document devicetree.bbclass<br /> ref-manual: classes: kernel: document automatic defconfig usage<br /> ref-manual: classes: kernel: remove incorrect sentence opening<br /> ref-manual: remove unused and obsolete file<br /> ref-manual: system-requirements.rst: fix AlmaLinux variable name<br /> ref-manual: variables.rst: add wikipedia shortcut for &quot;getty&quot;<br /> ref-manual: variables.rst: document KERNEL_DANGLING_FEATURES_WARN_ONLY<br /> ref-manual: variables.rst: don&#039;t mention the INIT_MANAGER &quot;none&quot; option<br /> release-notes-4.2: remove/merge duplicates entries<br /> release-notes-4.2: update RC3 changes<br /> release-notes-4.2: update known issues and Repositories/Downloads<br /> releases.svg: fix and explain duration of Hardknott 3.3<br /> ruby: upgrade to 3.2.2<br /> rust: upgrade to 1.68.2<br /> selftest/distrodata: clean up exception lists in recipe maintainers test<br /> systemd-systemctl: fix instance template WantedBy symlink construction<br /> texinfo: upgrade to 7.0.3<br /> unfs3: fix symlink time setting issue<br /> update-alternatives.bbclass: fix old override syntax<br /> vala: upgrade to 0.56.6<br /> waffle: upgrade to 1.7.2<br /> weston: add xwayland to DEPENDS for PACKAGECONFIG xwayland<br /> wpebackend-fdo: upgrade to 1.14.2<br /> xserver-xorg: upgrade to 21.1.8<br /> xwayland: upgrade to 23.1.1</p> </div></div></div> Mon, 29 May 2023 07:44:08 +0000 yakuhito 482 at https://yoctobbq.lineo.co.jp https://yoctobbq.lineo.co.jp/?q=node/482#comments Yocto4.0.10 LTS(Kirkstone)リリース https://yoctobbq.lineo.co.jp/?q=node/479 <div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>2022年4月にリリースされたYocto4.0 LTS (Kirkstone)の10回目のポイントリリース4.0.10公開のアナウンスが2023年5月24日付けでありました。<br /> 当初予定より3日早く5月12日版で構築、QAは5月18日に完了、TSC Teamのチェックを経て、予定より2日早く早く5月24日のリリースアナウンスとなりました。</p> <p>今回のリリースでの主な変更点:<br />   〇 CVEに登録された脆弱性への対応<br />   〇 カーネルは 5.15.103 から 5.15.108 にアップグレード<br />   〇 linux-yocto に対して、Upstreamで対処済であるにも関わらずNVDのデータベースに反映されていないFixに関して、cve-check実行時に対処済であることが判るようにcve-exclusion.inc ファイルに記載</p> <p>  リリースアナウンスの時点で、5月12日以降 次のポイントリリースに向けてのコミットは行われていません。</p> <p>次のポイントリリース4.0.11 は 2023/6/26 版で構築、QA後の2023/7/7 のリリースを予定しています。</p> <p>本リリースの詳細は以下のURLでご確認ください。<br /> <a href="https://lists.yoctoproject.org/g/yocto-announce/message/278">https://lists.yoctoproject.org/g/yocto-announce/message/278</a></p> <p>----------------<br /> Known Issues<br /> ----------------<br /> N/A</p> <p>----------------<br /> Security Fixes<br /> ----------------<br /> binutils: Fix CVE-2023-1579 CVE-2023-1972 CVE-2023-25584 CVE-2023-25585 CVE-2023-25588<br /> cargo : Ignore cve-2022-46176<br /> connman: Fix CVE-2023-28488<br /> curl: Fix CVE-2023-27533 CVE-2023-27534 CVE-2023-27535 CVE-2023-27536 CVE-2023-27538<br /> ffmpeg: Fix CVE-2022-48434<br /> freetype: Fix CVE-2023-2004<br /> ghostscript: Fix CVE-2023-29979<br /> git: Fix CVE-2023-25652 CVE-2023-29007<br /> go: Fix CVE-2022-41722 CVE-2022-41724 CVE-2022-41725 CVE-2023-24534 CVE-2023-24537 CVE-2023-24538<br /> go: Ignore CVE-2022-41716<br /> libxml2: Fix CVE-2023-28484 CVE-2023-29469<br /> libxpm: Fix CVE-2022-4883 CVE-2022-44617 CVE-2022-46285<br /> linux-yocto: Ignore CVE-2021-3759 CVE-2021-4135 CVE-2021-4155 CVE-2022-0168 CVE-2022-0171 CVE-2022-1016 CVE-2022-1184 CVE-2022-1198 CVE-2022-1199 CVE-2022-1462 CVE-2022-1734 CVE-2022-1852 CVE-2022-1882 CVE-2022-1998 CVE-2022-2078 CVE-2022-2196 CVE-2022-2318 CVE-2022-2380 CVE-2022-2503 CVE-2022-26365 CVE-2022-2663 CVE-2022-2873 CVE-2022-2905 CVE-2022-2959 CVE-2022-3028 CVE-2022-3078 CVE-2022-3104 CVE-2022-3105 CVE-2022-3106 CVE-2022-3107 CVE-2022-3111 CVE-2022-3112 CVE-2022-3113 CVE-2022-3115 CVE-2022-3202 CVE-2022-32250 CVE-2022-32296 CVE-2022-32981 CVE-2022-3303 CVE-2022-33740 CVE-2022-33741 CVE-2022-33742 CVE-2022-33743 CVE-2022-33744 CVE-2022-33981 CVE-2022-3424 CVE-2022-3435 CVE-2022-34918 CVE-2022-3521 CVE-2022-3545 CVE-2022-3564 CVE-2022-3586 CVE-2022-3594 CVE-2022-36123 CVE-2022-3621 CVE-2022-3623 CVE-2022-3629 CVE-2022-3633 CVE-2022-3635 CVE-2022-3646 CVE-2022-3649 CVE-2022-36879 CVE-2022-36946 CVE-2022-3707 CVE-2022-39188 CVE-2022-39190 CVE-2022-39842 CVE-2022-40307 CVE-2022-40768 CVE-2022-4095 CVE-2022-41218 CVE-2022-4139 CVE-2022-41849 CVE-2022-41850 CVE-2022-41858 CVE-2022-42328 CVE-2022-42329 CVE-2022-42703 CVE-2022-42721 CVE-2022-42722 CVE-2022-42895 CVE-2022-4382 CVE-2022-4662 CVE-2022-47518 CVE-2022-47519 CVE-2022-47520 CVE-2022-47929 CVE-2023-0179 CVE-2023-0394 CVE-2023-0461 CVE-2023-0590 CVE-2023-1073 CVE-2023-1074 CVE-2023-1077 CVE-2023-1078 CVE-2023-1079 CVE-2023-1095 CVE-2023-1118 CVE-2023-1249 CVE-2023-1252 CVE-2023-1281 CVE-2023-1382 CVE-2023-1513 CVE-2023-1829 CVE-2023-1838 CVE-2023-1998 CVE-2023-2006 CVE-2023-2008 CVE-2023-2162 CVE-2023-2166 CVE-2023-2177 CVE-2023-22999 CVE-2023-23002 CVE-2023-23004 CVE-2023-23454 CVE-2023-23455 CVE-2023-23559 CVE-2023-25012 CVE-2023-26545 CVE-2023-28327 CVE-2023-28328<br /> nasm: Fix CVE-2022-44370<br /> python3-cryptography: Fix CVE-2023-23931<br /> qemu: Ignore CVE-2023-0664<br /> ruby: Fix CVE-2023-28755 CVE-2023-28756<br /> screen: Fix CVE-2023-24626<br /> shadow: Fix CVE-2023-29383<br /> tiff: Fix CVE-2022-4645<br /> webkitgtk: Fix CVE-2022-32888 CVE-2022-32923<br /> xserver-xorg: Fix CVE-2023-1393</p> <p>----------------<br /> Fixes<br /> ----------------<br /> bitbake: bin/utils: Ensure locale en_US.UTF-8 is available on the system<br /> build-appliance-image: Update to kirkstone head revision<br /> cmake: add CMAKE_SYSROOT to generated toolchain file<br /> glibc: stable 2.35 branch updates.<br /> kernel-devsrc: depend on python3-core instead of python3<br /> kernel: improve initramfs bundle processing time<br /> libarchive: Enable acls, xattr for native as well as target<br /> libbsd: Add correct license for all packages<br /> libpam: Fix the xtests/tst-pam_motd[1|3] failures<br /> libxpm: upgrade to 3.5.15<br /> linux-firmware: upgrade to 20230404<br /> linux-yocto/5.15: upgrade to v5.15.108<br /> migration-guides: add release-notes for 4.0.9<br /> oeqa/utils/metadata.py: Fix running oe-selftest running with no distro set<br /> openssl: Move microblaze to linux-latomic config<br /> package.bbclass: correct check for /build in copydebugsources()<br /> poky.conf: bump version for 4.0.10<br /> populate_sdk_base: add zip options<br /> populate_sdk_ext.bbclass: set METADATA_REVISION with an DISTRO override<br /> run-postinsts: Set dependency for ldconfig to avoid boot issues<br /> update-alternatives.bbclass: fix old override syntax<br /> wic/bootimg-efi: if fixed-size is set then use that for mkdosfs<br /> wpebackend-fdo: upgrade to 1.14.2<br /> xorg-lib-common: Add variable to set tarball type<br /> xserver-xorg: upgrade to 21.1.8</p> </div></div></div> Wed, 24 May 2023 05:40:04 +0000 yakuhito 479 at https://yoctobbq.lineo.co.jp https://yoctobbq.lineo.co.jp/?q=node/479#comments Yocto3.1.25 LTS(Dunfell 23.25)リリース https://yoctobbq.lineo.co.jp/?q=node/477 <div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>一昨年4月にリリースされたYocto3.1LTS(Dunfell)の25回目のポイントリリース、3.1.25公開のアナウンスが 2023年5月12日付けでありました。</p> <p>予定より5日早い5月3日版で構築、QAを経て予定より7日早く、5月12日 にリリースされています。</p> <p>今回のリリースでは、CVEへの対応、UpStreanでのアップデート対応の他、SBoMに対応したSPDXを生成するcreate-spdx2.2.bbclassのバックポートが含まれ、dunfellでもSBoMの生成が可能となりました。<br /> kernelは5.4.230 から 5.4.237 にアップデートしています。</p> <p>5/15 9:00 現在、5/2以降のコミットは行われていません。</p> <p>次のバージョン 3.1.26 は 2023/06/19版で構築、2023/6/30リリースの予定となっています。</p> <p>本リリースの詳細は以下のURLでご確認ください。<br /> <a href="https://lists.yoctoproject.org/g/yocto-announce/message/277">https://lists.yoctoproject.org/g/yocto-announce/message/277</a></p> <p>----------------<br /> Known Issues<br /> ----------------<br /> N/A</p> <p>----------------<br /> Security Fixes<br /> ----------------<br /> curl: Fix CVE-2023-23916 CVE-2023-27534 CVE-2023-27538 CVE-2023-27533 CVE-2023-27535 CVE-2023-27536<br /> ffmpeg: Fix CVE-2022-3341<br /> ghostscript: Fix CVE-2021-45944<br /> git: Fix CVE-2023-22490 CVE-2023-23946<br /> git: Ignore CVE-2023-22743<br /> go: Fix CVE-2020-29510 CVE-2022-41722 CVE-2022-41723 CVE-2023-24534 CVE-2023-24537<br /> go: Ignore CVE-2022-1705 CVE-2022-41716<br /> libarchive: Fix CVE-2022-26280<br /> libksba: Fix CVE-2022-3515<br /> openssl: Fix CVE-2023-0464 CVE-2023-0465 CVE-2023-0466<br /> qemu: Fix CVE-2020-15469 CVE-2020-15859 CVE-2020-17380 CVE-2020-35504 CVE-2020-35505 CVE-2021-3409 CVE-2022-26354 CVE-2022-4144<br /> qemu: Ignore CVE-2023-0664<br /> ruby: Fix CVE-2023-28756<br /> screen: Fix CVE-2023-24626<br /> sudo: Fix CVE-2023-28486 CVE-2023-28487<br /> systemd: Fix CVE-2023-26604<br /> vim: Fix CVE-2023-1127 CVE-2023-1170 CVE-2023-1175 CVE-2023-1264 CVE-2023-1355</p> <p>----------------<br /> Fixes<br /> ----------------<br /> base-files: Drop localhost.localdomain from hosts file<br /> bitbake: tests/fetch.py: fix link to project documentation<br /> bmap-tools: switch to main branch<br /> build-appliance-image: Update to dunfell head revision<br /> buildtools-tarball: Handle spaces within user $PATH<br /> classes/create-spdx: Backport<br /> classes/package: Add extended packaged data<br /> classes/package: Use gzip for extended package data<br /> create-spdx: Use gzip for compression<br /> cve-check: Fix false negative version issue<br /> documentation: update for 3.1.25<br /> ghostscript: add CVE tag &quot;CVE-2021-45944&quot; for check-stack-limits-after-function-evalution.patch<br /> glibc: Add missing binutils dependency<br /> lib/resulttool: fix typo breaking resulttool log --ptest<br /> licenses: Add GPL+ licenses to map<br /> linux-yocto/5.4: update to v5.4.237<br /> oeqa rtc.py: skip if read-only-rootfs<br /> poky.conf: bump version for 3.1.25<br /> populate_sdk_base: add zip options<br /> populate_sdk_ext: Handle spaces within user $PATH<br /> pybootchartui: Fix python syntax issue<br /> qemu: fix build error introduced by CVE-2021-3929 fix<br /> qemu: fix compile error which imported by CVE-2022-4144<br /> staging/multilib: Fix manifest corruption<br /> staging: Separate out different multiconfig manifests<br /> systemd: Fix systemd when used with busybox less<br /> systemd: fix wrong nobody-group assignment<br /> toolchain-scripts: Handle spaces within user $PATH<br /> vim: set modified-by to the recipe MAINTAINER<br /> vim: upgrade to 9.0.1429</p> </div></div></div> Sun, 14 May 2023 23:58:06 +0000 yakuhito 477 at https://yoctobbq.lineo.co.jp https://yoctobbq.lineo.co.jp/?q=node/477#comments Yocto4.1.4 (Langdale) リリース https://yoctobbq.lineo.co.jp/?q=node/476 <div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>Yocto Project から Yocto4.1.4(Langdale) 公開のアナウンスが2023年5月12日付けでありました。<br /> 2023/04/28版で構築が行われQAを経て予定されていた5月13日より1日早くのリリースとなっています。</p> <p>今回のリリースでは、従来同様CVEの対応及びレシピのアップデートの他、kernel.orgでリリース後に対応したCVEがcve-check実行時に反映されるようになりました。 <br /> linux-yocto_5.15 は、5.15.108 にアップデートされています。(5.19は据え置き)</p> <p>LTSとLTSの間にリリースされたバージョンのため、今回のリリースでYocto Projectとしてのメンテナンスは終了となります。</p> <p>本リリースの詳細は以下のURLでご確認ください。<br /> <a href="https://lists.yoctoproject.org/g/yocto-announce/message/276">https://lists.yoctoproject.org/g/yocto-announce/message/276</a></p> <p>----------------<br /> Known Issues<br /> ----------------<br /> N/A</p> <p>----------------<br /> Security Fixes<br /> ----------------<br /> cve-extra-exclusions/linux-yocto: Ignore CVE-2020-27784 CVE-2021-3669 CVE-2021-3759 CVE-2021-4218 CVE-2022-0480 CVE-2022-1184 CVE-2022-1462 CVE-2022-2308 CVE-2022-2327 CVE-2022-26365 CVE-2022-2663 CVE-2022-2785 CVE-2022-3176 CVE-2022-33740 CVE-2022-33741 CVE-2022-33742 CVE-2022-3526 CVE-2022-3563 CVE-2022-3621 CVE-2022-3623 CVE-2022-3624 CVE-2022-3625 CVE-2022-3629 CVE-2022-3630 CVE-2022-3633 CVE-2022-3635 CVE-2022-3636 CVE-2022-3637 CVE-2022-3646 CVE-2022-3649<br /> cve-extra-exclusions/linux-yocto 5.15: Ignore CVE-2022-3435 CVE-2022-3534 CVE-2022-3564 CVE-2022-3564 CVE-2022-3619 CVE-2022-3640 CVE-2022-42895 CVE-2022-42896 CVE-2022-4382 CVE-2023-0266 CVE-2023-0394<br /> epiphany: Fix CVE-2023-26081<br /> git: Ignore CVE-2023-22743<br /> go: Fix CVE-2022-41722 CVE-2022-41723 CVE-2022-41724 CVE-2022-41725 CVE-2023-24532<br /> harfbuzz: Fix CVE-2023-25193<br /> libmicrohttpd: Fix CVE-2023-27371<br /> libxml2: Fix CVE-2022-40303 CVE-2022-40304<br /> openssl: Fix CVE-2023-0464 CVE-2023-0465 CVE-2023-0466<br /> python3-setuptools: Fix CVE-2022-40897<br /> qemu: Fix CVE-2022-4144<br /> screen: Fix CVE-2023-24626<br /> shadow: Ignore CVE-2016-15024<br /> tiff: Fix CVE-2022-48281 CVE-2023-0795 CVE-2023-0796 CVE-2023-0797 CVE-2023-0798 CVE-2023-0799 CVE-2023-0800 CVE-2023-0801 CVE-2023-0802 CVE-2023-0803 CVE-2023-0804<br /> vim: Fix CVE-2023-1127 CVE-2023-1170 CVE-2023-1175 CVE-2023-1264 CVE-2023-1355<br /> xdg-utils: Fix CVE-2022-4055<br /> xserver-xorg: Fix for CVE-2023-1393</p> <p>----------------<br /> Fixes<br /> ----------------<br /> apt: re-enable version check<br /> base-files: Drop localhost.localdomain from hosts file<br /> binutils: Fix nativesdk ld.so search<br /> bitbake: bin/utils: Ensure locale en_US.UTF-8 is available on the system<br /> bitbake: cookerdata: Drop dubious exception handling code<br /> bitbake: cookerdata: Improve early exception handling<br /> bitbake: cookerdata: Remove incorrect SystemExit usage<br /> bitbake: fetch/git: Fix local clone url to make it work with repo<br /> bitbake: toaster: Add refreshed oe-core and poky fixtures<br /> bitbake: toaster: fixtures/README: django 1.8 -&gt; 3.2<br /> bitbake: toaster: fixtures/gen_fixtures.py: update branches<br /> bitbake: utils: Allow to_boolean to support int values<br /> bmap-tools: switch to main branch<br /> build-appliance-image: Update to langdale head revision<br /> buildtools-tarball: Handle spaces within user $PATH<br /> busybox: move hwclock init earlier in startup<br /> cargo.bbclass: use offline mode for building<br /> cpio: Fix wrong CRC with ASCII CRC for large files<br /> cracklib: update github branch to &#039;main&#039;<br /> cups: add/fix web interface packaging<br /> cups: check PACKAGECONFIG for pam feature<br /> cups: use BUILDROOT instead of DESTDIR<br /> cve-check: Fix false negative version issue<br /> devtool/upgrade: do not delete the workspace/recipes directory<br /> dhcpcd: Fix install conflict when enable multilib.<br /> ffmpeg: fix build failure when vulkan is enabled<br /> filemap.py: enforce maximum of 4kb block size<br /> gcc-shared-source: do not use ${S}/.. in deploy_source_date_epoch<br /> glibc: Add missing binutils dependency<br /> go: upgrade to 1.19.7<br /> image_types: fix multiubi var init<br /> image_types: fix vname var init in multiubi_mkfs() function<br /> iso-codes: upgrade to 4.13.0<br /> kernel-devsrc: fix mismatched compiler warning<br /> lib/oe/gpg_sign.py: Avoid race when creating .sig files in detach_sign<br /> lib/resulttool: fix typo breaking resulttool log --ptest<br /> libcomps: Fix callback function prototype for PyCOMPS_hash<br /> libdnf: upgrade to 0.70.0<br /> libgit2: update license information<br /> libmicrohttpd: upgrade to 0.9.76<br /> linux-yocto-rt/5.15: upgrade to -rt59<br /> linux-yocto/5.15: upgrade to v5.15.108<br /> linux: inherit pkgconfig in kernel.bbclass<br /> lttng-modules: upgrade to v2.13.9<br /> lua: Fix install conflict when enable multilib.<br /> mdadm: Fix raid0, 06wrmostly and 02lineargrow tests<br /> mesa-demos: packageconfig weston should have a dependency on wayland-protocols<br /> meson: Fix wrapper handling of implicit setup command<br /> meson: remove obsolete RPATH stripping patch<br /> migration-guides: update release notes<br /> oeqa ping.py: avoid busylooping failing ping command<br /> oeqa ping.py: fail test if target IP address has not been set<br /> oeqa rtc.py: skip if read-only-rootfs<br /> oeqa/runtime: clean up deprecated backslash expansion<br /> oeqa/sdk: Improve Meson test<br /> oeqa/selftest/cases/package.py: adding unittest for package rename conflicts<br /> oeqa/selftest/cases/runqemu: update imports<br /> oeqa/selftest/prservice: Improve debug output for failure<br /> oeqa/selftest/reproducible: Split different packages from missing packages output<br /> oeqa/selftest: OESelftestTestContext: convert relative to full path when newbuilddir is provided<br /> oeqa/targetcontrol: do not set dump_host_cmds redundantly<br /> oeqa/targetcontrol: fix misspelled RuntimeError<br /> oeqa/targetcontrol: remove unused imports<br /> oeqa/utils/commands: fix usage of undefined EPIPE<br /> oeqa/utils/commands: remove unused imports<br /> oeqa/utils/qemurunner: replace hard-coded user &#039;root&#039; in debug output<br /> oeqs/selftest: OESelftestTestContext: replace the os.environ after subprocess.check_output<br /> package.bbclass: check packages name conflict in do_package<br /> pango: upgrade to 1.50.13<br /> piglit: Fix build time dependency<br /> poky.conf: bump version for 4.1.4<br /> populate_sdk_base: add zip options<br /> populate_sdk_ext: Handle spaces within user $PATH<br /> pybootchart: Fix extents handling to account for cpu/io/mem pressure changes<br /> pybootchartui: Fix python syntax issue<br /> report-error: catch Nothing PROVIDES error<br /> rpm: Fix hdr_hash function prototype<br /> run-postinsts: Set dependency for ldconfig to avoid boot issues<br /> runqemu: respect IMAGE_LINK_NAME<br /> runqemu: Revert &quot;workaround for APIC hang on pre 4.15 kernels on qemux86q&quot;<br /> scripts/lib/buildstats: handle top-level build_stats not being complete<br /> selftest/recipetool: Stop test corrupting tinfoil class<br /> selftest/runtime_test/virgl: Disable for all Rocky Linux<br /> selftest: devtool: set BB_HASHSERVE_UPSTREAM when setting SSTATE_MIRROR<br /> selftest: runqemu: better check for ROOTFS: in the log<br /> selftest: runqemu: use better error message when asserts fail<br /> shadow: Fix can not print full login timeout message<br /> staging/multilib: Fix manifest corruption<br /> staging: Separate out different multiconfig manifests<br /> sudo: upgrade to 1.9.13p3<br /> systemd.bbclass: Add /usr/lib/systemd to searchpaths as well<br /> systemd: add group sgx to udev package<br /> systemd: fix wrong nobody-group assignment<br /> timezone: use &#039;tz&#039; subdir instead of ${WORKDIR} directly<br /> toolchain-scripts: Handle spaces within user $PATH<br /> tzcode-native: fix build with gcc-13 on host<br /> tzdata: upgrade to 2023c<br /> tzdata: use separate B instead of WORKDIR for zic output<br /> u-boot: Map arm64 into map for u-boot dts installation<br /> uninative: Upgrade to 3.9 to include glibc 2.37<br /> vala: Fix install conflict when enable multilib.<br /> vim: add missing pkgconfig inherit<br /> vim: set modified-by to the recipe MAINTAINER<br /> vim: upgrade to 9.0.1429<br /> xcb-proto: Fix install conflict when enable multilib.</p> </div></div></div> Sun, 14 May 2023 23:56:41 +0000 yakuhito 476 at https://yoctobbq.lineo.co.jp https://yoctobbq.lineo.co.jp/?q=node/476#comments Yocto4.2 (Mickledore) リリース https://yoctobbq.lineo.co.jp/?q=node/475 <div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>Yocto4.2 (Mickledore ) リリース</p> <p>Yocto Project から Yocto4.1(Mickledore ) 公開のアナウンスが2023年5月5日付けでありました。</p> <p>当初は、4月3日版で構築、QA後の4月28日にリリース予定でしたが、QAテスト中に複数の問題が発生し対応を行った4月22日版で構築されたRC3がQAを経てリリースされています。<br /> 4月22日以降、git.yoctopeoject.org 上ではリリースに合わせたドキュメントの更新が行われています。</p> <p>・kernel はLTSカーネル6.1.25 及び5.15.108が提供されています。<br /> ・glibc は。2.37 が提供されています。<br /> ・開発ホストでは。Python3.8 及びgcc8.0 以降が必要となります。</p> <p>今回のリリースは、LTSとLTSの間でのリリースで幾つかの機能追加が行われています。<br /> 一部を紹介しますと、<br /> ・bitbakeの機能追加<br /> ・rustの構築に関する機能追加<br /> ・サポートアーキテクチャとして、 LoongArch の追加<br /> ・x86-64-v3  tune の追加<br /> ・gtk4の追加 (meta-gnomeから移動)<br /> ・32bitアーキテクチャ向けのY2038対応の追加<br /> といったものがあります。<br /> より詳細な情報につきましては、弊社ブログ <a href="https://www.lineo.co.jp/blog/yocto/">https://www.lineo.co.jp/blog/yocto/</a> 5月号にてお知らせします。</p> <p>次のポイントリリース 4.2.1 は 2023年5月22版で構築、QA後の2023年6月2日を予定しています。</p> <p>本リリースの詳細は以下のURLでご確認ください。<br /><a href="https://lists.yoctoproject.org/g/yocto-announce/message/275">https://lists.yoctoproject.org/g/yocto-announce/message/275</a></p> <p>-----------------------------------</p> <p>New Features / Enhancements in 4.2<br /> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</p> <p>-- Linux kernel 6.1, glibc 2.37 and ~350 other recipe upgrades</p> <p>-- Python 3.8+ and GCC 8.0+ are now the minimum required versions on the build host<br /> For host distributions that do not provide it, this is included as part of the<br /> buildtools tarball.</p> <p>-- BitBake in this release now supports a new addpylib directive to enable<br /> Python libraries within layers.</p> <p> This directive should be added to your layer configuration<br /> as in the below example from 'meta/conf/layer.conf' :</p> <p> addpylib ${LAYERDIR}/lib oe</p> <p>-- BitBake in this release now supports a new addpylib directive to enable<br /> Python libraries within layers. For more information,<br /> see `bitbake-user-manual/bitbake-user-manual-metadata:extending python library code`.</p> <p>-- BitBake has seen multiple internal changes that may improve<br /> memory and disk usage as well as parsing time, in particular:</p> <p> - BitBake's Cooker server is now multithreaded.</p> <p> - Ctrl+C can now be used to interrupt some long-running operations<br /> that previously ignored it.</p> <p> - BitBake's cache has been extended to include more hash<br /> debugging data, but has also been optimized to compress cache data</p> <p> - BitBake's UI will now ping the server regularly to ensure<br /> it is still alive.</p> <p>-- New variables:</p> <p> - 'VOLATILE_TMP_DIR' allows to specify<br /> whether '/tmp' should be on persistent storage<br /> or in RAM.</p> <p> - 'SPDX_CUSTOM_ANNOTATION_VARS' allows to add<br /> specific comments to the 'SPDX' description of a recipe.</p> <p>-- Rust improvements:</p> <p> - This release adds Cargo support on the target, and includes<br /> automated QA tests for this functionality.</p> <p> - It also supports checksums for Rust crates and makes<br /> them mandatory for each crate in a recipe.</p> <p> - New 'cargo-update-recipe-crates' class to<br /> enable updating 'SRC_URI' crate lists from 'Cargo.lock'</p> <p> - Enabled building Rust for baremetal targets</p> <p> - You can now also easily select to build beta or nightly<br /> versions of Rust with a new 'RUST_CHANNEL' variable<br /> (use at own risk)</p> <p> - Support for local GitHub repos in 'SRC_URI' as<br /> replacements for Cargo dependencies</p> <p> - Use built-in Rust targets for '-native' builds to save several<br /> minutes building the Rust toolchain</p> <p>-- Architecture-specific enhancements:</p> <p> - This release adds initial support for the LoongArch<br /> (loongarch64) architecture, though there is no testing for it yet.</p> <p> - New 'x86-64-v3' tunes (AVX, AVX2, BMI1, BMI2, F16C, FMA, LZCNT, MOVBE, XSAVE)</p> <p> - go: add support to build on ppc64le<br /> - rust: rustfmt now working and installed for riscv32<br /> - libpng: enable NEON for aarch64 to ensure consistency with arm32.<br /> - baremetal-helloworld: Enable x86 and x86-64 ports</p> <p>-- Kernel-related enhancements:</p> <p> - Added some support for building 6.2/6.3-rc kernels<br /> - linux-yocto-dev: mark as compatible with qemuarm64 and qemuarmv5<br /> - Add kernel specific OBJCOPY to help switching toolchains cleanly for kernel build between gcc and clang</p> <p>-- New core recipes:</p> <p> - debugedit<br /> - gtk4 (import from meta-gnome)<br /> - gcr: add recipe for gcr-4<br /> - graphene (import from meta-oe)<br /> - libc-test<br /> - libportal (import from meta-gnome)<br /> - libslirp<br /> - libtest-fatal-perl<br /> - libtest-warnings-perl (import from meta-perl)<br /> - libtry-tiny-perl<br /> - python3-build<br /> - python3-pyproject-hooks<br /> - python3-hatch-fancy-pypi-readme<br /> - python3-unittest-automake</p> <p>-- QEMU/runqemu enhancements:</p> <p> - Set 'QB_SMP' with ?= to make it easier to modify<br /> - Set 'QB_CPU' with ?= to make it easier to modify (x86 configuration only)<br /> - New 'QB_NFSROOTFS_EXTRA_OPT' to allow extra options to be appended to the NFS rootfs options in kernel boot args, e.g. "wsize=4096,rsize=4096"<br /> - New 'QB_SETUP_CMD' and 'QB_CLEANUP_CMD' to enable running custom shell setup and cleanup commands before and after QEMU.<br /> - 'QB_DEFAULT_KERNEL' now defaults to pick the bundled initramfs kernel image if the Linux kernel image is generated with 'INITRAMFS_IMAGE_BUNDLE' set to "1"<br /> - Split out the QEMU guest agent to its own 'qemu-guest-agent' package<br /> - runqemu: new 'guestagent' option to enable communication with the guest agent<br /> - runqemu: respect 'IMAGE_LINK_NAME' when searching for image</p> <p>-- Image-related enhancements:</p> <p> - Add 7-Zip support in image conversion types (7zip)<br /> - New 'IMAGE_MACHINE_SUFFIX' variable to allow easily removing machine name suffix from image file names</p> <p>-- wic Image Creator enhancements:</p> <p> - bootimg-efi.py : add support for directly loading Linux kernel UEFI stub<br /> - bootimg-efi.py : implement '--include-path'<br /> - Allow usage of 'fstype=none' to specify an unformatted partition<br /> - Implement repeatable disk identifiers based on 'SOURCE_DATE_EPOCH'</p> <p>-- FIT image related improvements:</p> <p> - FIT image signing support has been reworked to remove interdependencies and make it more easily extensible<br /> - Skip FDT section creation for applicable symlinks to avoid the same dtb being duplicated<br /> - New 'FIT_CONF_DEFAULT_DTB' variable to enable selecting default dtb when multiple dtbs exist</p> <p>-- SDK-related improvements:</p> <p> - Extended the following recipes to nativesdk:</p> <p> - bc<br /> - gi-docgen<br /> - gperf<br /> - python3-iniconfig<br /> - python3-atomicwrites<br /> - python3-markdown<br /> - python3-smartypants<br /> - python3-typogrify<br /> - ruby<br /> - unifdef</p> <p> - New 'SDK_ZIP_OPTIONS' variable to enable passing additional options to the zip command when preparing the SDK zip archive<br /> - New Rust SDK target packagegroup (packagegroup-rust-sdk-target)</p> <p>-- Testing:</p> <p> - The ptest images have changed structure in this release. The<br /> underlying core-image-ptest recipe now uses 'BBCLASSEXTEND' to<br /> create a variant for each ptest enabled recipe in OE-Core.</p> <p> For example, this means that core-image-ptest-bzip2,<br /> core-image-ptest-lttng-tools and many more image targets now exist<br /> and can be built/tested individually.</p> <p> The core-image-ptest-all and core-image-ptest-fast targets are now<br /> wrappers that target groups of individual images and means that the tests<br /> can be executed in parallel during our automated testing. This also means<br /> the dependencies are more accurately tested.</p> <p> - It is now possible to track regression changes between releases using<br /> 'yocto_testresults_query.py', which is a thin wrapper over 'resulttool'.<br /> Here is an example command, which allowed to spot and fix a regression in the<br /> 'quilt' ptest:</p> <p> yocto_testresults_query.py regression-report 4.2_M1 4.2_M2</p> <p> See this blog post about regression detection:</p> <p> <a href="https://bootlin.com/blog/continuous-integration-in-yocto-improving-the-regressions-detection">https://bootlin.com/blog/continuous-integration-in-yocto-improving-the-r...</a></p> <p> - This release adds support for parallel ptest execution with a ptest per image.<br /> This takes ptest execution time from 3.5 hours to around 45 minutes on the autobuilder.</p> <p> - Basic Rust compile/run and cargo tests</p> <p> - New 'python3-unittest-automake' recipe which provides modules for pytest<br /> and unittest to adjust their output to automake-style for easier integration<br /> with the ptest system.</p> <p> - ptest support added to 'bc', 'cpio' and 'gnutls', and fixes made to<br /> ptests in numerous other recipes.</p> <p> - 'ptest-runner' now adds a non-root "ptest" user to run tests.</p> <p> - 'resulttool': add a '--list-ptest' option to the log subcommand to list ptest names<br /> in a results file</p> <p> - 'resulttool': regression: add metadata filtering for oeselftest</p> <p>-- New 'PACKAGECONFIG' options in the following recipes:</p> <p> - at-spi2-core<br /> - base-passwd<br /> - cronie<br /> - cups<br /> - curl<br /> - file<br /> - gstreamer1.0-plugins-good<br /> - gtk+3<br /> - iproute2<br /> - libsdl2<br /> - libtiff<br /> - llvm<br /> - mesa<br /> - psmisc<br /> - qemu<br /> - sudo<br /> - systemd<br /> - tiff<br /> - util-linux</p> <p>-- Extended the following recipes to native:</p> <p> - iso-codes<br /> - libxkbcommon<br /> - p11-kit<br /> - python3-atomicwrites<br /> - python3-dbusmock<br /> - python3-iniconfig<br /> - xkeyboard-config</p> <p>-- Utility script changes:</p> <p> - 'devtool': ignore patch-fuzz errors when extracting source in order to enable fixing fuzz issues<br /> - 'oe-setup-layers': make efficiently idempotent<br /> - 'oe-setup-layers': print a note about submodules if present<br /> - New 'buildstats-summary' script to show a summary of the buildstats data<br /> - report-error.bbclass: catch 'Nothing PROVIDES' error<br /> - 'combo-layer': add 'sync-revs' command<br /> - 'convert-overrides': allow command-line customizations</p> <p>-- bitbake-layers improvements:</p> <p> - 'layerindex-fetch': checkout layer(s) branch when clone exists<br /> - 'create': add '-a'/'--add-layer option' to add layer to 'bblayers.conf' after creating layer<br /> - 'show-layers': improve output layout</p> <p>-- Other BitBake improvements:</p> <p> - Inline Python snippets can now include dictionary expressions<br /> - Evaluate the value of export/unexport/network flags so that they can be reset to "0"<br /> - Make 'EXCLUDE_FROM_WORLD' boolean so that it can be reset to "0"<br /> - Support int values in 'bb.utils.to_boolean()' in addition to strings<br /> - 'bitbake-getvar': Add a 'quiet' command line argument<br /> - Allow the '@' character in variable flag names<br /> - Python library code will now be included when calculating task hashes<br /> - 'fetch2/npmsw': add more short forms for git operations<br /> - Display a warning when 'SRCREV = "${AUTOREV}"' is set too late to be effective<br /> - Display all missing 'SRC_URI' checksums at once<br /> - Improve error message for a missing multiconfig<br /> - Switch to a new 'BB_CACHEDIR' variable for codeparser cache location<br /> - Mechanism introduced to reduce the codeparser cache unnecessarily growing in size</p> <p>-- Packaging changes:</p> <p> - 'rng-tools' is no longer recommended by 'openssh', and the 'rng-tools'<br /> service files have been split out to their own package<br /> - linux-firmware: split 'rtl8761' and 'amdgpu' firmware<br /> - linux-firmware: add new firmware file to '${PN}-qcom-adreno-a530'<br /> - iproute2: separate 'routel' and add Python dependency<br /> - xinetd: move 'xconv.pl' script to separate package<br /> - perf: enable debug/source packaging</p> <p>-- Miscellaneous changes:</p> <p> - Supporting 64 bit dates on 32 bit platforms: several packages have been<br /> updated to pass year 2038 tests, and a QA check for 32 bit time and file<br /> offset functions has been added (default off)</p> <p> - Patch fuzz/Upstream-Status checking has been reworked:</p> <p> - Upstream-Status checking is now configurable from 'WARN_QA'/'ERROR_QA' (patch-status-core)<br /> - Can now be enabled for non-core layers (patch-status-noncore)<br /> - 'patch-fuzz' is now in 'ERROR_QA' by default, and actually stops the build</p> <p> - Many packages were updated to add large file support.</p> <p> - vulkan-loader: allow headless targets to build the loader<br /> - dhcpcd: fix to work with systemd<br /> - u-boot: add /boot to 'SYSROOT_DIRS' to allow boot files to be used by other recipes<br /> - linux-firmware: don't put the firmware into the sysroot<br /> - cups: add 'PACKAGECONFIG' to control web interface and default to off<br /> - buildtools-tarball: export certificates to python and curl<br /> - yocto-check-layer: allow OE-Core to be tested<br /> - yocto-check-layer: check for patch file upstream status<br /> - boost: enable building 'Boost.URL' library<br /> - native.bbclass: drop special variable handling<br /> - Poky: make it easier to set 'INIT_MANAGER' from local.conf<br /> - 'create-spdx': add support for custom annotations (SPDX_CUSTOM_ANNOTATION_VARS)<br /> - 'create-spdx': report downloads as separate packages<br /> - 'create-spdx': remove the top-level image SPDX file and the JSON index file from 'DEPLOYDIR' to avoid confusion<br /> - 'os-release': replace 'DISTRO_CODENAME' with 'VERSION_CODENAME' (still set from 'DISTRO_CODENAME')<br /> - weston: add kiosk shell<br /> - overlayfs.bbclass: Allow unused mount points<br /> - 'sstatesig': emit more helpful error message when not finding sstate manifest<br /> - pypi.bbclass: Set 'SRC_URI' downloadfilename with an optional prefix<br /> - 'poky-bleeding' distro: update and rework<br /> - package.bbclass : check if package names conflict via 'PKG:${PN}' override in 'do_package'<br /> - cve-update-nvd2-native: new NVD CVE database fetcher using the 2.0 API<br /> - mirrors.bbclass: use shallow tarball for 'binutils-native'/'nativesdk-binutils'<br /> - 'meta/conf': move default configuration templates into 'meta/conf/templates/default'<br /> - binutils: enable '--enable-new-dtags' as per many Linux distributions<br /> - base-files: drop 'localhost.localdomain' from hosts file as per many Linux distributions<br /> - packagegroup-core-boot: make 'init-ifupdown' package a recommendation</p> <p>Known Issues in 4.2<br /> ~~~~~~~~~~~~~~~~~~~</p> <p>-- N/A</p> <p>Recipe License changes in 4.2<br /> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</p> <p>The following corrections have been made to the 'LICENSE' values set by recipes:</p> <p>-- curl: set 'LICENSE' appropriately to 'curl' as it is a special derivative of the MIT/X license, not exactly that license.<br /> -- libgit2: added 'Zlib', 'ISC', 'LGPL-2.1-or-later' and 'CC0-1.0' to 'LICENSE' covering portions of the included code.<br /> -- linux-firmware: set package 'LICENSE' appropriately for all qcom packages</p> <p>Security Fixes in 4.2<br /> ~~~~~~~~~~~~~~~~~~~~~</p> <p>-- apr-util: CVE-2022-25147<br /> -- apr: CVE-2022-24963 CVE-2022-28331<br /> -- binutils: CVE-2022-4285 CVE-2023-25586<br /> -- curl: CVE-2022-32221 CVE-2022-35260 CVE-2022-42915 CVE-2022-42916 CVE-2022-43551 CVE-2022-43552<br /> -- dbus: CVE-2022-42010 CVE-2022-42011 CVE-2022-42012<br /> -- epiphany: CVE-2023-26081<br /> -- expat: CVE-2022-43680<br /> -- ffmpeg: CVE-2022-3964 CVE-2022-3965<br /> -- git: CVE-2022-23521 CVE-2022-23521 CVE-2022-39260 CVE-2022-41903 CVE-2022-41953 (ignored)<br /> -- glibc: CVE-2023-25139 (ignored)<br /> -- go: CVE-2023-24532 CVE-2023-24537<br /> -- grub2: CVE-2022-2601 CVE-2022-3775 CVE-2022-28736<br /> -- inetutils: CVE-2019-0053<br /> -- less: CVE-2022-46663<br /> -- libarchive: CVE-2022-36227<br /> -- libinput: CVE-2022-1215<br /> -- libksba: CVE-2022-47629<br /> -- libpam: CVE-2022-28321<br /> -- libpng: CVE-2019-6129<br /> -- libx11: CVE-2022-3554<br /> -- openssh: CVE-2023-28531<br /> -- openssl: CVE-2022-3358 CVE-2022-3786 CVE-2022-3602 CVE-2022-3996 CVE-2023-0286 CVE-2022-4304 CVE-2022-4203 CVE-2023-0215 CVE-2022-4450 CVE-2023-0216 CVE-2023-0217 CVE-2023-0401 CVE-2023-0464<br /> -- pkgconf: CVE-2023-24056<br /> -- ppp: CVE-2022-4603<br /> -- python3-cryptography{-vectors}: CVE-2022-3602 CVE-2022-3786 CVE-2023-23931<br /> -- python3: CVE-2022-37460<br /> -- qemu: CVE-2022-3165<br /> -- rust: CVE-2022-46176<br /> -- rxvt-unicode: CVE-2022-4170<br /> -- screen: CVE-2023-24626<br /> -- shadow: CVE-2023-29383 CVE-2016-15024 (ignored)<br /> -- sudo: CVE-2023-22809 CVE-2022-43995<br /> -- systemd: CVE-2022-4415 (ignored)<br /> -- tar: CVE-2022-48303<br /> -- tiff: CVE-2022-3599 CVE-2022-3597 CVE-2022-3626 CVE-2022-3627 CVE-2022-3570 CVE-2022-3598 CVE-2022-3970 CVE-2022-48281<br /> -- vim: CVE-2022-3352 CVE-2022-4141 CVE-2023-0049 CVE-2023-0051 CVE-2023-0054 CVE-2023-0288 CVE-2023-1127 CVE-2023-1170 CVE-2023-1175 CVE-2023-1127 CVE-2023-1170 CVE-2023-1175 CVE-2023-1264 CVE-2023-1355 CVE-2023-0433 CVE-2022-47024 CVE-2022-3705<br /> -- xdg-utils: CVE-2022-4055<br /> -- xserver-xorg: CVE-2022-3550 CVE-2022-3551 CVE-2023-1393 CVE-2023-0494 CVE-2022-3553 (ignored)</p> <p>Recipe Upgrades in 4.2<br /> ~~~~~~~~~~~~~~~~~~~~~~</p> <p>-- acpid: upgrade 2.0.33 -&gt; 2.0.34<br /> -- adwaita-icon-theme: update 42.0 -&gt; 43<br /> -- alsa-lib: upgrade 1.2.7.2 -&gt; 1.2.8<br /> -- alsa-ucm-conf: upgrade 1.2.7.2 -&gt; 1.2.8<br /> -- alsa-utils: upgrade 1.2.7 -&gt; 1.2.8<br /> -- apr: update 1.7.0 -&gt; 1.7.2<br /> -- apr-util: update 1.6.1 -&gt; 1.6.3<br /> -- argp-standalone: replace with a maintained fork<br /> -- at-spi2-core: upgrade 2.44.1 -&gt; 2.46.0<br /> -- autoconf-archive: upgrade 2022.09.03 -&gt; 2023.02.20<br /> -- babeltrace: upgrade 1.5.8 -&gt; 1.5.11<br /> -- base-passwd: Update to 3.6.1<br /> -- bash: update 5.1.16 -&gt; 5.2.15<br /> -- bind: upgrade 9.18.7 -&gt; 9.18.12<br /> -- binutils: Upgrade to 2.40 release<br /> -- bluez: update 5.65 -&gt; 5.66<br /> -- boost-build-native: update 1.80.0 -&gt; 1.81.0<br /> -- boost: upgrade 1.80.0 -&gt; 1.81.0<br /> -- btrfs-tools: upgrade 5.19.1 -&gt; 6.1.3<br /> -- busybox: 1.35.0 -&gt; 1.36.0<br /> -- ccache: upgrade 4.6.3 -&gt; 4.7.4<br /> -- cmake: update 3.24.0 -&gt; 3.25.2<br /> -- cracklib: upgrade to v2.9.10<br /> -- curl: upgrade 7.86.0 -&gt; 8.0.1<br /> -- dbus: upgrade 1.14.0 -&gt; 1.14.6<br /> -- diffoscope: upgrade 221 -&gt; 236<br /> -- diffstat: upgrade 1.64 -&gt; 1.65<br /> -- diffutils: update 3.8 -&gt; 3.9<br /> -- dos2unix: upgrade 7.4.3 -&gt; 7.4.4<br /> -- dpkg: update 1.21.9 -&gt; 1.21.21<br /> -- dropbear: upgrade 2022.82 -&gt; 2022.83<br /> -- dtc: upgrade 1.6.1 -&gt; 1.7.0<br /> -- e2fsprogs: upgrade 1.46.5 -&gt; 1.47.0<br /> -- ed: upgrade 1.18 -&gt; 1.19<br /> -- elfutils: update 0.187 -&gt; 0.188<br /> -- ell: upgrade 0.53 -&gt; 0.56<br /> -- enchant2: upgrade 2.3.3 -&gt; 2.3.4<br /> -- encodings: update 1.0.6 -&gt; 1.0.7<br /> -- epiphany: update 42.4 -&gt; 43.1<br /> -- ethtool: upgrade 5.19 -&gt; 6.2<br /> -- expat: upgrade to 2.5.0<br /> -- ffmpeg: upgrade 5.1.1 -&gt; 5.1.2<br /> -- file: upgrade 5.43 -&gt; 5.44<br /> -- flac: update 1.4.0 -&gt; 1.4.2<br /> -- font-alias: update 1.0.4 -&gt; 1.0.5<br /> -- fontconfig: upgrade 2.14.0 -&gt; 2.14.2<br /> -- font-util: upgrade 1.3.3 -&gt; 1.4.0<br /> -- freetype: update 2.12.1 -&gt; 2.13.0<br /> -- gawk: update 5.1.1 -&gt; 5.2.1<br /> -- gcr3: update 3.40.0 -&gt; 3.41.1<br /> -- gcr: rename gcr -&gt; gcr3<br /> -- gdb: Upgrade to 13.1<br /> -- gdk-pixbuf: upgrade 2.42.9 -&gt; 2.42.10<br /> -- gettext: update 0.21 -&gt; 0.21.1<br /> -- ghostscript: update 9.56.1 -&gt; 10.0.0<br /> -- gi-docgen: upgrade 2022.1 -&gt; 2023.1<br /> -- git: upgrade 2.37.3 -&gt; 2.39.2<br /> -- glib-2.0: update 2.72.3 -&gt; 2.74.6<br /> -- glibc: upgrade to 2.37 release + stable updates<br /> -- glib-networking: update 2.72.2 -&gt; 2.74.0<br /> -- glslang: upgrade 1.3.236.0 -&gt; 1.3.239.0<br /> -- gnu-config: upgrade to latest revision<br /> -- gnupg: upgrade 2.3.7 -&gt; 2.4.0<br /> -- gnutls: upgrade 3.7.7 -&gt; 3.8.0<br /> -- gobject-introspection: upgrade 1.72.0 -&gt; 1.74.0<br /> -- go: update 1.19 -&gt; 1.20.1<br /> -- grep: update 3.7 -&gt; 3.10<br /> -- gsettings-desktop-schemas: upgrade 42.0 -&gt; 43.0<br /> -- gstreamer1.0: upgrade 1.20.3 -&gt; 1.22.0<br /> -- gtk+3: upgrade 3.24.34 -&gt; 3.24.36<br /> -- gtk4: update 4.8.2 -&gt; 4.10.0<br /> -- harfbuzz: upgrade 5.1.0 -&gt; 7.1.0<br /> -- hdparm: update 9.64 -&gt; 9.65<br /> -- help2man: upgrade 1.49.2 -&gt; 1.49.3<br /> -- icu: update 71.1 -&gt; 72-1<br /> -- ifupdown: upgrade 0.8.37 -&gt; 0.8.41<br /> -- igt-gpu-tools: upgrade 1.26 -&gt; 1.27.1<br /> -- inetutils: upgrade 2.3 -&gt; 2.4<br /> -- init-system-helpers: upgrade 1.64 -&gt; 1.65.2<br /> -- iproute2: upgrade 5.19.0 -&gt; 6.2.0<br /> -- iptables: update 1.8.8 -&gt; 1.8.9<br /> -- iputils: update to 20221126<br /> -- iso-codes: upgrade 4.11.0 -&gt; 4.13.0<br /> -- jquery: upgrade 3.6.0 -&gt; 3.6.3<br /> -- kexec-tools: upgrade 2.0.25 -&gt; 2.0.26<br /> -- kmscube: upgrade to latest revision<br /> -- libarchive: upgrade 3.6.1 -&gt; 3.6.2<br /> -- libbsd: upgrade 0.11.6 -&gt; 0.11.7<br /> -- libcap: upgrade 2.65 -&gt; 2.67<br /> -- libdnf: update 0.69.0 -&gt; 0.70.0<br /> -- libdrm: upgrade 2.4.113 -&gt; 2.4.115<br /> -- libedit: upgrade 20210910-3.1 -&gt; 20221030-3.1<br /> -- libepoxy: update 1.5.9 -&gt; 1.5.10<br /> -- libffi: upgrade 3.4.2 -&gt; 3.4.4<br /> -- libfontenc: upgrade 1.1.6 -&gt; 1.1.7<br /> -- libgit2: upgrade 1.5.0 -&gt; 1.6.3<br /> -- libgpg-error: update 1.45 -&gt; 1.46<br /> -- libhandy: update 1.6.3 -&gt; 1.8.1<br /> -- libical: upgrade 3.0.14 -&gt; 3.0.16<br /> -- libice: update 1.0.10 -&gt; 1.1.1<br /> -- libidn2: upgrade 2.3.3 -&gt; 2.3.4<br /> -- libinput: upgrade 1.19.4 -&gt; 1.22.1<br /> -- libjpeg-turbo: upgrade 2.1.4 -&gt; 2.1.5.1<br /> -- libksba: upgrade 1.6.0 -&gt; 1.6.3<br /> -- libmicrohttpd: upgrade 0.9.75 -&gt; 0.9.76<br /> -- libmodule-build-perl: update 0.4231 -&gt; 0.4232<br /> -- libmpc: upgrade 1.2.1 -&gt; 1.3.1<br /> -- libnewt: update 0.52.21 -&gt; 0.52.23<br /> -- libnotify: upgrade 0.8.1 -&gt; 0.8.2<br /> -- libpcap: upgrade 1.10.1 -&gt; 1.10.3<br /> -- libpciaccess: update 0.16 -&gt; 0.17<br /> -- libpcre2: upgrade 10.40 -&gt; 10.42<br /> -- libpipeline: upgrade 1.5.6 -&gt; 1.5.7<br /> -- libpng: upgrade 1.6.38 -&gt; 1.6.39<br /> -- libpsl: upgrade 0.21.1 -&gt; 0.21.2<br /> -- librepo: upgrade 1.14.5 -&gt; 1.15.1<br /> -- libsdl2: upgrade 2.24.1 -&gt; 2.26.3<br /> -- libsm: 1.2.3 &gt; 1.2.4<br /> -- libsndfile1: upgrade 1.1.0 -&gt; 1.2.0<br /> -- libsolv: upgrade 0.7.22 -&gt; 0.7.23<br /> -- libsoup-2.4: upgrade 2.74.2 -&gt; 2.74.3<br /> -- libsoup: upgrade 3.0.7 -&gt; 3.2.2<br /> -- libtest-fatal-perl: upgrade 0.016 -&gt; 0.017<br /> -- libtest-needs-perl: upgrade 0.002009 -&gt; 0.002010<br /> -- libunistring: upgrade 1.0 -&gt; 1.1<br /> -- liburcu: upgrade 0.13.2 -&gt; 0.14.0<br /> -- liburi-perl: upgrade 5.08 -&gt; 5.17<br /> -- libva: upgrade 2.15.0 -&gt; 2.16.0<br /> -- libva-utils: upgrade 2.15.0 -&gt; 2.17.1<br /> -- libwebp: upgrade 1.2.4 -&gt; 1.3.0<br /> -- libwpe: upgrade 1.12.3 -&gt; 1.14.1<br /> -- libx11: 1.8.1 -&gt; 1.8.4<br /> -- libx11-compose-data: 1.6.8 -&gt; 1.8.4<br /> -- libxau: upgrade 1.0.10 -&gt; 1.0.11<br /> -- libxcomposite: update 0.4.5 -&gt; 0.4.6<br /> -- libxcrypt-compat: upgrade 4.4.30 -&gt; 4.4.33<br /> -- libxcrypt: upgrade 4.4.28 -&gt; 4.4.30<br /> -- libxdamage: update 1.1.5 -&gt; 1.1.6<br /> -- libxdmcp: update 1.1.3 -&gt; 1.1.4<br /> -- libxext: update 1.3.4 -&gt; 1.3.5<br /> -- libxft: update 2.3.4 -&gt; 2.3.6<br /> -- libxft: upgrade 2.3.6 -&gt; 2.3.7<br /> -- libxinerama: update 1.1.4 -&gt; 1.1.5<br /> -- libxkbcommon: upgrade 1.4.1 -&gt; 1.5.0<br /> -- libxkbfile: update 1.1.0 -&gt; 1.1.1<br /> -- libxkbfile: upgrade 1.1.1 -&gt; 1.1.2<br /> -- libxml2: upgrade 2.9.14 -&gt; 2.10.3<br /> -- libxmu: update 1.1.3 -&gt; 1.1.4<br /> -- libxpm: update 3.5.13 -&gt; 3.5.15<br /> -- libxrandr: update 1.5.2 -&gt; 1.5.3<br /> -- libxrender: update 0.9.10 -&gt; 0.9.11<br /> -- libxres: update 1.2.1 -&gt; 1.2.2<br /> -- libxscrnsaver: update 1.2.3 -&gt; 1.2.4<br /> -- libxshmfence: update 1.3 -&gt; 1.3.2<br /> -- libxslt: upgrade 1.1.35 -&gt; 1.1.37<br /> -- libxtst: update 1.2.3 -&gt; 1.2.4<br /> -- libxv: update 1.0.11 -&gt; 1.0.12<br /> -- libxxf86vm: update 1.1.4 -&gt; 1.1.5<br /> -- lighttpd: upgrade 1.4.66 -&gt; 1.4.69<br /> -- linux-firmware: upgrade 20220913 -&gt; 20230210<br /> -- linux-libc-headers: bump to 6.1<br /> -- linux-yocto/5.15: update genericx86* machines to v5.15.103<br /> -- linux-yocto/5.15: update to v5.15.108<br /> -- linux-yocto/6.1: update to v6.1.25<br /> -- linux-yocto-dev: bump to v6.3<br /> -- linux-yocto-rt/5.15: update to -rt59<br /> -- linux-yocto-rt/6.1: update to -rt7<br /> -- llvm: update 14.0.6 -&gt; 15.0.7<br /> -- log4cplus: upgrade 2.0.8 -&gt; 2.1.0<br /> -- logrotate: upgrade 3.20.1 -&gt; 3.21.0<br /> -- lsof: upgrade 4.95.0 -&gt; 4.98.0<br /> -- ltp: upgrade 20220527 -&gt; 20230127<br /> -- lttng-modules: upgrade 2.13.4 -&gt; 2.13.9<br /> -- lttng-tools: update 2.13.8 -&gt; 2.13.9<br /> -- lttng-ust: upgrade 2.13.4 -&gt; 2.13.5<br /> -- makedepend: upgrade 1.0.6 -&gt; 1.0.8<br /> -- make: update 4.3 -&gt; 4.4.1<br /> -- man-db: update 2.10.2 -&gt; 2.11.2<br /> -- man-pages: upgrade 5.13 -&gt; 6.03<br /> -- matchbox-config-gtk: Update to latest SRCREV<br /> -- matchbox-desktop-2: Update 2.2 -&gt; 2.3<br /> -- matchbox-panel-2: Update 2.11 -&gt; 2.12<br /> -- matchbox-terminal: Update to latest SRCREV<br /> -- matchbox-wm: Update 1.2.2 -&gt; 1.2.3<br /> -- mc: update 4.8.28 -&gt; 4.8.29<br /> -- mesa: update 22.2.0 -&gt; 23.0.0<br /> -- meson: upgrade 0.63.2 -&gt; 1.0.1<br /> -- mmc-utils: upgrade to latest revision<br /> -- mobile-broadband-provider-info: upgrade 20220725 -&gt; 20221107<br /> -- mpfr: upgrade 4.1.0 -&gt; 4.2.0<br /> -- mpg123: upgrade 1.30.2 -&gt; 1.31.2<br /> -- msmtp: upgrade 1.8.22 -&gt; 1.8.23<br /> -- mtd-utils: upgrade 2.1.4 -&gt; 2.1.5<br /> -- mtools: upgrade 4.0.40 -&gt; 4.0.42<br /> -- musl-obstack: Update to 1.2.3<br /> -- musl: Upgrade to latest master<br /> -- nasm: update 2.15.05 -&gt; 2.16.01<br /> -- ncurses: upgrade 6.3+20220423 -&gt; 6.4<br /> -- netbase: upgrade 6.3 -&gt; 6.4<br /> -- newlib: Upgrade 4.2.0 -&gt; 4.3.0<br /> -- nghttp2: upgrade 1.49.0 -&gt; 1.52.0<br /> -- numactl: upgrade 2.0.15 -&gt; 2.0.16<br /> -- opensbi: Upgrade to 1.2 release<br /> -- openssh: upgrade 9.0p1 -&gt; 9.3p1<br /> -- openssl: Upgrade 3.0.5 -&gt; 3.1.0<br /> -- opkg: upgrade to version 0.6.1<br /> -- orc: upgrade 0.4.32 -&gt; 0.4.33<br /> -- ovmf: upgrade edk2-stable202205 -&gt; edk2-stable202211<br /> -- pango: upgrade 1.50.9 -&gt; 1.50.13<br /> -- patchelf: upgrade 0.15.0 -&gt; 0.17.2<br /> -- pciutils: upgrade 3.8.0 -&gt; 3.9.0<br /> -- piglit: upgrade to latest revision<br /> -- pinentry: update 1.2.0 -&gt; 1.2.1<br /> -- pixman: upgrade 0.40.0 -&gt; 0.42.2<br /> -- pkgconf: upgrade 1.9.3 -&gt; 1.9.4<br /> -- popt: update 1.18 -&gt; 1.19<br /> -- powertop: upgrade 2.14 -&gt; 2.15<br /> -- procps: update 3.3.17 -&gt; 4.0.3<br /> -- psmisc: upgrade 23.5 -&gt; 23.6<br /> -- puzzles: upgrade to latest revision<br /> -- python3-alabaster: upgrade 0.7.12 -&gt; 0.7.13<br /> -- python3-attrs: upgrade 22.1.0 -&gt; 22.2.0<br /> -- python3-babel: upgrade 2.10.3 -&gt; 2.12.1<br /> -- python3-bcrypt: upgrade 3.2.2 -&gt; 4.0.1<br /> -- python3-certifi: upgrade 2022.9.14 -&gt; 2022.12.7<br /> -- python3-chardet: upgrade 5.0.0 -&gt; 5.1.0<br /> -- python3-cryptography: upgrade 38.0.3 -&gt; 39.0.4<br /> -- python3-cryptography-vectors: upgrade 37.0.4 -&gt; 39.0.2<br /> -- python3-cython: upgrade 0.29.32 -&gt; 0.29.33<br /> -- python3-dbusmock: update 0.28.4 -&gt; 0.28.7<br /> -- python3-dbus: upgrade 1.2.18 -&gt; 1.3.2<br /> -- python3-dtschema: upgrade 2022.8.3 -&gt; 2023.1<br /> -- python3-flit-core: upgrade 3.7.1 -&gt; 3.8.0<br /> -- python3-gitdb: upgrade 4.0.9 -&gt; 4.0.10<br /> -- python3-git: upgrade 3.1.27 -&gt; 3.1.31<br /> -- python3-hatch-fancy-pypi-readme: upgrade 22.7.0 -&gt; 22.8.0<br /> -- python3-hatchling: upgrade 1.9.0 -&gt; 1.13.0<br /> -- python3-hatch-vcs: upgrade 0.2.0 -&gt; 0.3.0<br /> -- python3-hypothesis: upgrade 6.54.5 -&gt; 6.68.2<br /> -- python3-importlib-metadata: upgrade 4.12.0 -&gt; 6.0.0<br /> -- python3-iniconfig: upgrade 1.1.1 -&gt; 2.0.0<br /> -- python3-installer: update 0.5.1 -&gt; 0.6.0<br /> -- python3-iso8601: upgrade 1.0.2 -&gt; 1.1.0<br /> -- python3-jsonschema: upgrade 4.9.1 -&gt; 4.17.3<br /> -- python3-lxml: upgrade 4.9.1 -&gt; 4.9.2<br /> -- python3-mako: upgrade 1.2.2 -&gt; 1.2.4<br /> -- python3-markupsafe: upgrade 2.1.1 -&gt; 2.1.2<br /> -- python3-more-itertools: upgrade 8.14.0 -&gt; 9.1.0<br /> -- python3-numpy: upgrade 1.23.3 -&gt; 1.24.2<br /> -- python3-packaging: upgrade to 23.0<br /> -- python3-pathspec: upgrade 0.10.1 -&gt; 0.11.0<br /> -- python3-pbr: upgrade 5.10.0 -&gt; 5.11.1<br /> -- python3-pip: upgrade 22.2.2 -&gt; 23.0.1<br /> -- python3-poetry-core: upgrade 1.0.8 -&gt; 1.5.2<br /> -- python3-psutil: upgrade 5.9.2 -&gt; 5.9.4<br /> -- python3-pycairo: upgrade 1.21.0 -&gt; 1.23.0<br /> -- python3-pycryptodome: upgrade 3.15.0 -&gt; 3.17<br /> -- python3-pycryptodomex: upgrade 3.15.0 -&gt; 3.17<br /> -- python3-pygments: upgrade 2.13.0 -&gt; 2.14.0<br /> -- python3-pyopenssl: upgrade 22.0.0 -&gt; 23.0.0<br /> -- python3-pyrsistent: upgrade 0.18.1 -&gt; 0.19.3<br /> -- python3-pytest-subtests: upgrade 0.8.0 -&gt; 0.10.0<br /> -- python3-pytest: upgrade 7.1.3 -&gt; 7.2.2<br /> -- python3-pytz: upgrade 2022.2.1 -&gt; 2022.7.1<br /> -- python3-requests: upgrade 2.28.1 -&gt; 2.28.2<br /> -- python3-scons: upgrade 4.4.0 -&gt; 4.5.2<br /> -- python3-setuptools-rust: upgrade 1.5.1 -&gt; 1.5.2<br /> -- python3-setuptools-scm: upgrade 7.0.5 -&gt; 7.1.0<br /> -- python3-setuptools: upgrade 65.0.2 -&gt; 67.6.0<br /> -- python3-sphinxcontrib-applehelp: update 1.0.2 -&gt; 1.0.4<br /> -- python3-sphinxcontrib-htmlhelp: 2.0.0 -&gt; 2.0.1<br /> -- python3-sphinx-rtd-theme: upgrade 1.0.0 -&gt; 1.2.0<br /> -- python3-sphinx: upgrade 5.1.1 -&gt; 6.1.3<br /> -- python3-subunit: upgrade 1.4.0 -&gt; 1.4.2<br /> -- python3-testtools: upgrade 2.5.0 -&gt; 2.6.0<br /> -- python3-typing-extensions: upgrade 4.3.0 -&gt; 4.5.0<br /> -- python3: update 3.10.6 -&gt; 3.11.2<br /> -- python3-urllib3: upgrade 1.26.12 -&gt; 1.26.15<br /> -- python3-wcwidth: upgrade 0.2.5 -&gt; 0.2.6<br /> -- python3-wheel: upgrade 0.37.1 -&gt; 0.40.0<br /> -- python3-zipp: upgrade 3.8.1 -&gt; 3.15.0<br /> -- qemu: update 7.1.0 -&gt; 7.2.0<br /> -- quota: update 4.06 -&gt; 4.09<br /> -- readline: update 8.1.2 -&gt; 8.2<br /> -- repo: upgrade 2.29.2 -&gt; 2.32<br /> -- rgb: update 1.0.6 -&gt; 1.1.0<br /> -- rng-tools: upgrade 6.15 -&gt; 6.16<br /> -- rsync: update 3.2.5 -&gt; 3.2.7<br /> -- rt-tests: update 2.4 -&gt; 2.5<br /> -- ruby: update 3.1.2 -&gt; 3.2.1<br /> -- rust: update 1.63.0 -&gt; 1.68.1<br /> -- rxvt-unicode: upgrade 9.30 -&gt; 9.31<br /> -- sed: update 4.8 -&gt; 4.9<br /> -- shaderc: upgrade 2022.2 -&gt; 2023.2<br /> -- shadow: update 4.12.1 -&gt; 4.13<br /> -- socat: upgrade 1.7.4.3 -&gt; 1.7.4.4<br /> -- spirv-headers: upgrade 1.3.236.0 -&gt; 1.3.239.0<br /> -- spirv-tools: upgrade 1.3.236.0 -&gt; 1.3.239.0<br /> -- sqlite3: upgrade 3.39.3 -&gt; 3.41.0<br /> -- strace: upgrade 5.19 -&gt; 6.2<br /> -- stress-ng: update 0.14.03 -&gt; 0.15.06<br /> -- sudo: upgrade 1.9.11p3 -&gt; 1.9.13p3<br /> -- swig: update 4.0.2 -&gt; 4.1.1<br /> -- sysstat: upgrade 12.6.0 -&gt; 12.6.2<br /> -- systemd: update 251.4 -&gt; 253.1<br /> -- systemtap: upgrade 4.7 -&gt; 4.8<br /> -- taglib: upgrade 1.12 -&gt; 1.13<br /> -- tcf-agent: Update to current version<br /> -- tcl: update 8.6.11 -&gt; 8.6.13<br /> -- texinfo: update 6.8 -&gt; 7.0.2<br /> -- tiff: update 4.4.0 -&gt; 4.5.0<br /> -- tzdata: update 2022d -&gt; 2023c<br /> -- u-boot: upgrade 2022.07 -&gt; 2023.01<br /> -- unfs: update 0.9.22 -&gt; 0.10.0<br /> -- usbutils: upgrade 014 -&gt; 015<br /> -- util-macros: upgrade 1.19.3 -&gt; 1.20.0<br /> -- vala: upgrade 0.56.3 -&gt; 0.56.4<br /> -- valgrind: update to 3.20.0<br /> -- vim: Upgrade 9.0.0598 -&gt; 9.0.1429<br /> -- virglrenderer: upgrade 0.10.3 -&gt; 0.10.4<br /> -- vte: update 0.68.0 -&gt; 0.72.0<br /> -- vulkan-headers: upgrade 1.3.236.0 -&gt; 1.3.239.0<br /> -- vulkan-loader: upgrade 1.3.236.0 -&gt; 1.3.239.0<br /> -- vulkan-samples: update to latest revision<br /> -- vulkan-tools: upgrade 1.3.236.0 -&gt; 1.3.239.0<br /> -- vulkan: update 1.3.216.0 -&gt; 1.3.236.0<br /> -- wayland-protocols: upgrade 1.26 -&gt; 1.31<br /> -- wayland-utils: update 1.0.0 -&gt; 1.1.0<br /> -- webkitgtk: update 2.36.7 -&gt; 2.38.5<br /> -- weston: update 10.0.2 -&gt; 11.0.1<br /> -- wireless-regdb: upgrade 2022.08.12 -&gt; 2023.02.13<br /> -- wpebackend-fdo: upgrade 1.12.1 -&gt; 1.14.0<br /> -- xcb-util: update 0.4.0 -&gt; 0.4.1<br /> -- xcb-util-keysyms: 0.4.0 -&gt; 0.4.1<br /> -- xcb-util-renderutil: 0.3.9 -&gt; 0.3.10<br /> -- xcb-util-wm: 0.4.1 -&gt; 0.4.2<br /> -- xcb-util-image: 0.4.0 -&gt; 0.4.1<br /> -- xf86-input-mouse: update 1.9.3 -&gt; 1.9.4<br /> -- xf86-input-vmmouse: update 13.1.0 -&gt; 13.2.0<br /> -- xf86-video-vesa: update 2.5.0 -&gt; 2.6.0<br /> -- xf86-video-vmware: update 13.3.0 -&gt; 13.4.0<br /> -- xhost: update 1.0.8 -&gt; 1.0.9<br /> -- xinit: update 1.4.1 -&gt; 1.4.2<br /> -- xkbcomp: update 1.4.5 -&gt; 1.4.6<br /> -- xkeyboard-config: upgrade 2.36 -&gt; 2.38<br /> -- xprop: update 1.2.5 -&gt; 1.2.6<br /> -- xrandr: upgrade 1.5.1 -&gt; 1.5.2<br /> -- xserver-xorg: upgrade 21.1.4 -&gt; 21.1.7<br /> -- xset: update 1.2.4 -&gt; 1.2.5<br /> -- xvinfo: update 1.1.4 -&gt; 1.1.5<br /> -- xwayland: upgrade 22.1.3 -&gt; 22.1.8<br /> -- xz: upgrade 5.2.6 -&gt; 5.4.2<br /> -- zlib: upgrade 1.2.12 -&gt; 1.2.13<br /> -- zstd: upgrade 1.5.2 -&gt; 1.5.4</p> </div></div></div> Mon, 08 May 2023 00:28:48 +0000 yakuhito 475 at https://yoctobbq.lineo.co.jp https://yoctobbq.lineo.co.jp/?q=node/475#comments Yocto4.0.9 LTS(Kirkstone)リリース https://yoctobbq.lineo.co.jp/?q=node/474 <div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>2022年4月にリリースされたYocto4.0 LTS (Kirkstone)の9回目のポイントリリース4.0.9公開のアナウンスが2023年4月22日付けでありました。<br /> 当初予定より1日遅れの4月11日版で構築、QA後の4月22日にリリースアナウンスとなりました。</p> <p>今回のリリースでの主な変更点:<br />   〇 CVEに登録された脆弱性への対応<br />   〇 カーネルは 5.10.160/5.15.91から5.10.175/5.15.103 にアップグレード<br />   〇 bitbake/devtool といったツールの不具合対策<br />   〇 いくつかのレシピのアップデート</p> <p>  リリースアナウンスの時点で、4月11日以降 次のポイントリリースに向けて既に複数の脆弱性対策を含んだコミットが行われています。<br />   ・binutils : CVE-20230-1579<br />   ・curl: CVE-2023-27533 CVE-2023-27534<br />   ・tiff: CVE-2022-4645<br />   ・go; CVE-2022-41724 CVE-2022-41725</p> <p>次のポイントリリース4.0.10 は 2023/5/15 版で構築、QA後の2023/5/26 のリリースを予定しています。</p> <p>本リリースの詳細は以下のURLでご確認ください。<br /> <a href="https://lists.yoctoproject.org/g/yocto-announce/message/274">https://lists.yoctoproject.org/g/yocto-announce/message/274</a></p> <p>※上記アナウンスでは、opensslのcve-2022-2879 が Security Fixesに含まれていますが、Yocto4.0.7に先行してバックポートパッチが適応され、既に対応されていたため、下記のFixeedでは除外してあります。</p> <p>---------------<br /> Known Issues<br /> ---------------<br /> N/A</p> <p>---------------<br /> Security Fixes<br /> ---------------<br /> binutils: Fix CVE-2023-22608<br /> curl: Fix CVE-2023-23914 CVE-2023-23915 CVE-2023-23916<br /> epiphany: Fix CVE-2023-26081<br /> git: Ignore CVE-2023-22743<br /> glibc: Fix CVE-2023-0687<br /> gnutls: Fix CVE-2023-0361<br /> go: Fix CVE-2022-2879 CVE-2022-41720 CVE-2022-41723<br /> harfbuzz: Fix CVE-2023-25193<br /> less: Fix CVE-2022-46663<br /> libmicrohttpd: Fix CVE-2023-27371<br /> libsdl2: Fix CVE-2022-4743<br /> openssl: Fix CVE-2023-0464 CVE-2023-0465 CVE-2023-0466<br /> pkgconf: Fix CVE-2023-24056<br /> python3: Fix CVE-2023-24329<br /> shadow: Ignore CVE-2016-15024<br /> systemd: Fix CVE-2022-4415<br /> tiff: Fix CVE-2023-0800 CVE-2023-0801 CVE-2023-0802 CVE-2023-0803 CVE-2023-0804<br /> vim: Fix CVE-2023-0433 CVE-2023-0512 CVE-2023-1127 CVE-2023-1170 CVE-2023-1175 CVE-2023-1264 CVE-2023-1355<br /> xserver-xorg: Fix CVE-2023-0494<br /> xwayland: Fix CVE-2023-0494</p> <p>---------------<br /> Fixes<br /> ---------------<br /> base-files: Drop localhost.localdomain from hosts file<br /> binutils: Fix nativesdk ld.so search<br /> bitbake: cookerdata: Drop dubious exception handling code<br /> bitbake: cookerdata: Improve early exception handling<br /> bitbake: cookerdata: Remove incorrect SystemExit usage<br /> bitbake: fetch/git: Fix local clone url to make it work with repo<br /> bitbake: utils: Allow to_boolean to support int values<br /> bmap-tools: switch to main branch<br /> buildtools-tarball: Handle spaces within user $PATH<br /> busybox: Fix depmod patch<br /> cracklib: update github branch to &#039;main&#039;<br /> cups: add/fix web interface packaging<br /> cups: check PACKAGECONFIG for pam feature<br /> cups: use BUILDROOT instead of DESTDIR<br /> curl: fix dependencies when building with ldap/ldaps<br /> cve-check: Fix false negative version issue<br /> dbus: upgrade to 1.14.6<br /> devtool/upgrade: do not delete the workspace/recipes directory<br /> dhcpcd: Fix install conflict when enable multilib.<br /> dhcpcd: fix dhcpcd start failure on qemuppc64<br /> gcc-shared-source: do not use ${S}/.. in deploy_source_date_epoch<br /> glibc: Add missing binutils dependency<br /> image_types: fix multiubi var init<br /> iso-codes: upgrade to 4.13.0<br /> json-c: Add ptest for json-c<br /> kernel-yocto: fix kernel-meta data detection<br /> lib/buildstats: handle tasks that never finished<br /> lib/resulttool: fix typo breaking resulttool log --ptest<br /> libjpeg-turbo: upgrade to 2.1.5.1<br /> libmicrohttpd: upgrade to 0.9.76<br /> libseccomp: fix for the ptest result format<br /> libssh2: Clean up ptest patch/coverage<br /> linux-firmware: add yamato fw files to qcom-adreno-a2xx package<br /> linux-firmware: properly set license for all Qualcomm firmware<br /> linux-firmware: upgrade to 20230210<br /> linux-yocto-rt/5.15: update to -rt59<br /> linux-yocto/5.10: upgrade to v5.10.175<br /> linux-yocto/5.15: upgrade to v5.15.103<br /> linux: inherit pkgconfig in kernel.bbclass<br /> lttng-modules: fix for kernel 6.2+<br /> lttng-modules: upgrade to v2.13.9<br /> lua: Fix install conflict when enable multilib.<br /> mdadm: Fix raid0, 06wrmostly and 02lineargrow tests<br /> meson: Fix wrapper handling of implicit setup command<br /> migration-guides: add 4.0.8 release notes<br /> nghttp2: never build python bindings<br /> oeqa rtc.py: skip if read-only-rootfs<br /> oeqa ssh.py: fix hangs in run()<br /> oeqa/sdk: Improve Meson test<br /> oeqa/selftest/prservice: Improve debug output for failure<br /> oeqa/selftest/resulttooltests: fix minor typo<br /> openssl: upgrade to 3.0.8<br /> package.bbclase: Add check for /build in copydebugsources()<br /> patchelf: replace a rejected patch with an equivalent uninative.bbclass tweak<br /> poky.conf: bump version for 4.0.9<br /> populate_sdk_ext: Handle spaces within user $PATH<br /> pybootchartui: Fix python syntax issue<br /> python3-git: fix indent error<br /> python3-setuptools-rust-native: Add direct dependency of native python3 modules<br /> qemu: Revert &quot;fix CVE-2021-3507&quot; as not applicable for qemu 6.2<br /> rsync: Add missing prototypes to function declarations<br /> rsync: Turn on -pedantic-errors at the end of &#039;configure&#039;<br /> runqemu: kill qemu if it hangs<br /> scripts/lib/buildstats: handle top-level build_stats not being complete<br /> selftest/recipetool: Stop test corrupting tinfoil class<br /> selftest/runtime_test/virgl: Disable for all Rocky Linux<br /> selftest: devtool: set BB_HASHSERVE_UPSTREAM when setting SSTATE_MIRROR<br /> sstatesig: Improve output hash calculation<br /> staging/multilib: Fix manifest corruption<br /> staging: Separate out different multiconfig manifests<br /> sudo: update 1.9.12p2 -&gt; 1.9.13p3<br /> systemd.bbclass: Add /usr/lib/systemd to searchpaths as well<br /> systemd: add group sgx to udev package<br /> systemd: fix wrong nobody-group assignment<br /> timezone: use &#039;tz&#039; subdir instead of ${WORKDIR} directly<br /> toolchain-scripts: Handle spaces within user $PATH<br /> tzcode-native: fix build with gcc-13 on host<br /> tzdata: use separate B instead of WORKDIR for zic output<br /> uninative: upgrade to 3.9 to include libgcc and glibc 2.37<br /> vala: Fix install conflict when enable multilib.<br /> vim: add missing pkgconfig inherit<br /> vim: set modified-by to the recipe MAINTAINER<br /> vim: upgrade to 9.0.1429<br /> wic: Fix usage of fstype=none in wic<br /> wireless-regdb: upgrade to 2023.02.13<br /> xserver-xorg: upgrade to 21.1.7<br /> xwayland: upgrade to 22.1.8</p> </div></div></div> Tue, 25 Apr 2023 03:18:56 +0000 yakuhito 474 at https://yoctobbq.lineo.co.jp https://yoctobbq.lineo.co.jp/?q=node/474#comments Yocto3.1.24 LTS(Dunfell 23.24)リリース https://yoctobbq.lineo.co.jp/?q=node/471 <div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>一昨年4月にリリースされたYocto3.1LTS(Dunfell)の24回目のポイントリリース、3.1.24公開のアナウンスが 2023年3月22日付けでありました。</p> <p>予定より5日早い3月15日版で構築、QAを経て予定より9日早く、3月22日 にリリースされています。</p> <p>今回のリリースでは、CVEへの対応、UpStreanでのアップデート対応、bitbakeやbusyboxの構築時のbug fix 等もが含まれています。<br /> kernelに関しては5.4.230で変更はありません。</p> <p>3/22 17:00 現在、3/15以降のコミットは行われていません。</p> <p>次のバージョン 3.1.25 は 4.2のリリース後の2023/05/8版で構築、2023/5/19リリースの予定となっています。<br /> 3.1.24 から、ubuntu-22.04 fedoro-36 almalinx-8,7 が 構築確認対象バージョンに追加されています。</p> <p>本リリースの詳細は以下のURLでご確認ください。<br /> <a href="https://lists.yoctoproject.org/g/yocto-announce/message/273">https://lists.yoctoproject.org/g/yocto-announce/message/273</a></p> <p>----------------<br /> Known Issues<br /> ----------------<br /> N/A</p> <p>- ---------------<br /> Security Fixes<br /> - ---------------<br /> apr-util: Fix CVE-2022-25147<br /> apr: Fix CVE-2022-24963 CVE-2022-28331 CVE-2021-35940<br /> bluez5: Ignore CVE-2022-39177<br /> curl: Fix CVE-2022-43552<br /> git: Fix CVE-2022-23521 CVE-2022-41903<br /> git: Ignore CVE-2022-41953<br /> glibc: Fix CVE-2023-0687<br /> gnutls: Fix CVE-2023-0361<br /> harfbuzz: Fix CVE-2023-25193<br /> openssl: Fix CVE-2022-4304 CVE-2022-4450 CVE-2023-0215 CVE-2023-0286<br /> qemu: fix CVE-2021-3929<br /> shadow: ignore CVE-2016-15024<br /> sudo: Fix CVE-2023-22809<br /> tar: Fix CVE-2022-48303<br /> tiff: Fix CVE-2022-3570 CVE-2022-3597 CVE-2022-3598 CVE-2022-3599 CVE-2022-3626 CVE-2022-3627 CVE-2022-3970 CVE-2022-48281 CVE-2023-0795 CVE-2023-0796 CVE-2023-0797 CVE-2023-0798 CVE-2023-0799 CVE-2023-0800 CVE-2023-0801 CVE-2023-0802 CVE-2023-0803 CVE-2023-0804<br /> vim: Fix CVE-2023-0433 CVE-2023-0512</p> <p>----------------<br /> Fixes<br /> ----------------<br /> apr-util: Fix CFLAGS used in build<br /> apr-util: Upgrade to 1.6.3<br /> apr: Cache configure tests which use AC_TRY_RUN<br /> apr: Fix to work with autoconf 2.70<br /> apr: Use correct strerror_r implementation based on libc type<br /> apr: Upgrade to 1.7.2<br /> bitbake: cooker: Drop sre_constants usage<br /> bitbake: runqueue: Avoid deadlock avoidance task graph corruption<br /> bitbake: runqueue: Ensure deferred tasks are sorted by multiconfig<br /> bitbake: runqueue: Fix issues with multiconfig deferred task deadlock messages<br /> bitbake: runqueue: Fix multiconfig deferred task sstate validity caching issue<br /> bitbake: runqueue: Handle deferred task rehashing in multiconfig builds<br /> bitbake: runqueue: Improve multiconfig deferred task issues<br /> build-appliance-image: Update to dunfell head revision<br /> busybox: always start do_compile with orig config files<br /> busybox: rm temporary files if do_compile was interrupted<br /> classes/fs-uuid: Fix command output decoding issue<br /> devshell: Do not add scripts/git-intercept to PATH<br /> devtool/menuconfig: remove True option to getVar calls<br /> documentation: update for 3.1.24<br /> gcc: Fix inconsistent noexcept specifier for valarray in libstdc++<br /> go: remove True option to getVar calls<br /> image.bbclass: print all QA functions exceptions<br /> image.bbclass: remove True option to getVarFlag calls<br /> kernel-yocto: fix kernel-meta data detection<br /> libc-locale: Fix on target locale generation<br /> license_image: remove True option to getVar calls<br /> linux-firmware: add yamato fw files to qcom-adreno-a2xx package<br /> linux-firmware: properly set license for all Qualcomm firmware<br /> linux-firmware: Upgrade to 20230210<br /> linux: inherit pkgconfig in kernel.bbclass<br /> make-mod-scripts: Ensure kernel build output is deterministic<br /> meta: remove True option to getVar and getVarFlag calls (again)<br /> nativesdk: Handle chown/chgrp calls in nativesdk do_install tasks<br /> oeqa context.py: fix --target-ip comment to include ssh port number<br /> oeqa/qemurunner: do not use Popen.poll() when terminating runqemu with a signal<br /> oeqa/selftest/prservice: Improve debug output for failure<br /> openssl: Upgrade to 1.1.1t<br /> overview-manual: update patchwork instance URL<br /> poky.conf: Update SANITY_TESTED_DISTROS to match autobuilder<br /> poky.conf: bump version for 3.1.24<br /> profile-manual: update WireShark hyperlinks<br /> qemu: Fix slirp determinism issue<br /> quilt: fix intermittent failure in faildiff.test<br /> quilt: use upstreamed faildiff.test fix<br /> ref-manual: document SSTATE_EXCLUDEDEPS_SYSROOT<br /> ref-system-requirements.rst: add AlmaLinux 8.7, Fedora 35, Fedora 36, and Ubuntu 22.04 to list of supported distros<br /> vim: add missing pkgconfig inherit<br /> vim: Upgrade to 9.0.1293<br /> wireless-regdb: Upgrade to 2023.02.13</p> </div></div></div> Wed, 22 Mar 2023 08:47:54 +0000 yakuhito 471 at https://yoctobbq.lineo.co.jp https://yoctobbq.lineo.co.jp/?q=node/471#comments