]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/log
thirdparty/openembedded/openembedded-core.git
2 weeks agowic: upgrade 0.3.0 -> 0.3.1
Alexander Kanavin [Mon, 6 Jul 2026 17:16:58 +0000 (19:16 +0200)] 
wic: upgrade 0.3.0 -> 0.3.1

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agowaffle: upgrade 1.8.2 -> 1.8.3
Alexander Kanavin [Mon, 6 Jul 2026 17:16:57 +0000 (19:16 +0200)] 
waffle: upgrade 1.8.2 -> 1.8.3

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agottyrun: upgrade 2.42.1 -> 2.43.0
Alexander Kanavin [Mon, 6 Jul 2026 17:16:54 +0000 (19:16 +0200)] 
ttyrun: upgrade 2.42.1 -> 2.43.0

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agotcl: upgrade 9.0.3 -> 9.0.4
Alexander Kanavin [Mon, 6 Jul 2026 17:16:53 +0000 (19:16 +0200)] 
tcl: upgrade 9.0.3 -> 9.0.4

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agosqlite3: upgrade 3.53.2 -> 3.53.3
Alexander Kanavin [Mon, 6 Jul 2026 17:16:51 +0000 (19:16 +0200)] 
sqlite3: upgrade 3.53.2 -> 3.53.3

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agosocat: upgrade 1.8.1.1 -> 1.8.1.3
Alexander Kanavin [Mon, 6 Jul 2026 17:16:50 +0000 (19:16 +0200)] 
socat: upgrade 1.8.1.1 -> 1.8.1.3

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agopython3-wcwidth: upgrade 0.8.1 -> 0.8.2
Alexander Kanavin [Mon, 6 Jul 2026 17:16:47 +0000 (19:16 +0200)] 
python3-wcwidth: upgrade 0.8.1 -> 0.8.2

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agopython3-vcs-versioning: upgrade 1.1.1 -> 2.2.2
Alexander Kanavin [Mon, 6 Jul 2026 17:16:46 +0000 (19:16 +0200)] 
python3-vcs-versioning: upgrade 1.1.1 -> 2.2.2

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agopython3-setuptools-scm: upgrade 10.0.5 -> 10.2.0
Alexander Kanavin [Mon, 6 Jul 2026 17:16:45 +0000 (19:16 +0200)] 
python3-setuptools-scm: upgrade 10.0.5 -> 10.2.0

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agopython3-pytest: upgrade 9.1.0 -> 9.1.1
Alexander Kanavin [Mon, 6 Jul 2026 17:16:43 +0000 (19:16 +0200)] 
python3-pytest: upgrade 9.1.0 -> 9.1.1

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agopython3-pdm: upgrade 2.27.0 -> 2.28.0
Alexander Kanavin [Mon, 6 Jul 2026 17:16:42 +0000 (19:16 +0200)] 
python3-pdm: upgrade 2.27.0 -> 2.28.0

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agopython3-hypothesis: upgrade 6.155.2 -> 6.155.7
Alexander Kanavin [Mon, 6 Jul 2026 17:16:41 +0000 (19:16 +0200)] 
python3-hypothesis: upgrade 6.155.2 -> 6.155.7

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agolighttpd: upgrade 1.4.83 -> 1.4.84
Alexander Kanavin [Mon, 6 Jul 2026 17:16:36 +0000 (19:16 +0200)] 
lighttpd: upgrade 1.4.83 -> 1.4.84

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agolibpsl: upgrade 0.21.5 -> 0.22.0
Alexander Kanavin [Mon, 6 Jul 2026 17:16:35 +0000 (19:16 +0200)] 
libpsl: upgrade 0.21.5 -> 0.22.0

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agolibffi: upgrade 3.5.2 -> 3.6.0
Alexander Kanavin [Mon, 6 Jul 2026 17:16:33 +0000 (19:16 +0200)] 
libffi: upgrade 3.5.2 -> 3.6.0

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agolibarchive: upgrade 3.8.7 -> 3.8.8
Alexander Kanavin [Mon, 6 Jul 2026 17:16:32 +0000 (19:16 +0200)] 
libarchive: upgrade 3.8.7 -> 3.8.8

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agoiproute2: upgrade 7.0.0 -> 7.1.0
Alexander Kanavin [Mon, 6 Jul 2026 17:16:30 +0000 (19:16 +0200)] 
iproute2: upgrade 7.0.0 -> 7.1.0

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agoglib-2.0: upgrade 2.88.1 -> 2.88.2
Alexander Kanavin [Mon, 6 Jul 2026 17:16:26 +0000 (19:16 +0200)] 
glib-2.0: upgrade 2.88.1 -> 2.88.2

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agoexpat: upgrade 2.8.1 -> 2.8.2
Alexander Kanavin [Mon, 6 Jul 2026 17:16:23 +0000 (19:16 +0200)] 
expat: upgrade 2.8.1 -> 2.8.2

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agocmake: upgrade 4.3.3 -> 4.3.4
Alexander Kanavin [Mon, 6 Jul 2026 17:16:22 +0000 (19:16 +0200)] 
cmake: upgrade 4.3.3 -> 4.3.4

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agobarebox-tools: upgrade 2026.06.0 -> 2026.06.1
Alexander Kanavin [Mon, 6 Jul 2026 17:16:21 +0000 (19:16 +0200)] 
barebox-tools: upgrade 2026.06.0 -> 2026.06.1

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2 weeks agoat-spi2-core: upgrade 2.60.4 -> 2.60.5
Alexander Kanavin [Mon, 6 Jul 2026 17:16:19 +0000 (19:16 +0200)] 
at-spi2-core: upgrade 2.60.4 -> 2.60.5

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agopackage_pkgdata: Drop unneeded vardepsexlude
Richard Purdie [Mon, 6 Jul 2026 14:02:54 +0000 (15:02 +0100)] 
package_pkgdata: Drop unneeded vardepsexlude

These vardepsexclude entries don't make sense as the function no longer
references them, they can be dropped.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agostaging: Fix vardepsexclude
Richard Purdie [Mon, 6 Jul 2026 13:53:37 +0000 (14:53 +0100)] 
staging: Fix vardepsexclude

Set staging_populate_sysroot_dir vardepsexclude correctly (which does reference the variables)
and remove the incorrect pieces from extend_recipe_sysroot.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoselftest/locales: opt out of ptests in DISTRO_FEATURES
Alexander Kanavin [Fri, 3 Jul 2026 17:36:47 +0000 (19:36 +0200)] 
selftest/locales: opt out of ptests in DISTRO_FEATURES

selftests/locales tests configure glibc-locales to produce a restricted set,
and build core-image-minimal. This is problematic if something in
the dependency chain of that image relies on locales not in that set.

Until now, by coincidence, nothing did, but recent version updates
(particularly, json-c which relies on xxd in its ptest) pull in glib-2.0,
which for its ptest requires various locales not in the set. This causes
package_qa errors.

To address this particular error, and to minimize chances of it happening
again, let's build images for this selftest without ptest enabled; typically
only ptests want locales.

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoclasses/insane: increase shebang size limit
Ross Burton [Fri, 3 Jul 2026 10:07:10 +0000 (11:07 +0100)] 
classes/insane: increase shebang size limit

Since Linux 5.1 the shebang buffer has been 256 bytes[1], so update the
check to match.

Also rewrite the test, create a variable for the magic number (that has
the same name as the kernel #define), read double that so we either have
a full line, or definitely are over the buffer, don't pointlessly try to
decode the bytes as UTF-8, and consolidate the test logic to entirely
inside the try block.

Also update the tests: sysroot-shebang-test needs updating to write a
longer shebang, and generalise the test case so that the string being
searched for isn't so specific.

[1] linux 6eb3c3d0a52dc ("exec: increase BINPRM_BUF_SIZE to 256")

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoclasses/insane: clean up do_qa_sysroot
Ross Burton [Fri, 3 Jul 2026 10:07:09 +0000 (11:07 +0100)] 
classes/insane: clean up do_qa_sysroot

do_populate_sysroot copies SYSROOT_DIRS into SYSROOT_DESTDIR, so there's
no need to loop over SYSROOT_DIRS when checking files: qa_check_staged
can just recurse down the entire tree.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoclasses/insane: create one CachedPath instance in qa_check_staged
Ross Burton [Fri, 3 Jul 2026 10:07:08 +0000 (11:07 +0100)] 
classes/insane: create one CachedPath instance in qa_check_staged

There's no need to create a new CachedPath instance for every file that
we want to scan, just create one at the beginning of the function.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agotune-cortexa32: enable Thumb-2 and fix AArch32 crypto FPU selection
Alex Kiernan [Wed, 1 Jul 2026 11:58:12 +0000 (12:58 +0100)] 
tune-cortexa32: enable Thumb-2 and fix AArch32 crypto FPU selection

Cortex-A32 is an AArch32-only ARMv8-A core, but its tune was configured
as if it were a plain 64-bit-style tune: TUNE_FEATURES lacked both 'arm'
and 'thumb', so userspace and the kernel were built as fixed-width ARM
rather than Thumb-2, and the package architecture names did not match a
Thumb-2 build.

Add 'thumb' so the core is built as Thumb-2, and 'arm' so that
feature-arm-thumb.inc honours a recipe's explicit ARM_INSTRUCTION_SET =
"arm" instead of silently forcing it to thumb. Without 'arm', ARM_M_OPT
is pinned to "thumb" and recipes that request ARM warn, e.g.:

  Recipe 'libmad' selects ARM_INSTRUCTION_SET to be 'arm', but tune
  configuration overrides it to 'thumb'

On AArch32 the ARMv8 crypto extensions (AES/SHA) are part of the FPU,
not just the -march ISA. The 'crypto' feature only appends '+crypto' to
-march and leaves -mfpu at plain 'neon', so building the AES intrinsics
(e.g. mbedtls aesce.c) fails:

  error: inlining failed in call to 'always_inline' 'vaesdq_u8':
  target specific option mismatch

Select the crypto FPU by appending crypto-neon-fp-armv8 as the last word
of TUNE_CCARGS_MFPU when both 'crypto' and 'neon' are active, mirroring
the vfpv4+neon -> neon-vfpv4 idiom in feature-arm-neon.inc.

Update PACKAGE_EXTRA_ARCHS to match the resulting package arches:
cortexa32hf-neon becomes cortexa32t2hf-neon, and the crypto variant
becomes cortexa32t2hf-neon plus cortexa32t2hf-crypto-neon-fp-armv8.

AI-Generated: Claude Code (Claude Opus 4.8)
Signed-off-by: Alex Kiernan <alex.kiernan@gmail.com>
Signed-off-by: Alex Kiernan <alexk@a-squared-projects.uk>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agorust-target-config: armv8a AArch32 Thumb build fixes
Alex Kiernan [Wed, 1 Jul 2026 11:58:11 +0000 (12:58 +0100)] 
rust-target-config: armv8a AArch32 Thumb build fixes

llvm_features_from_tune() calls target_is_armv7() to gate both the +v7
LLVM feature and the +thumb2 feature. target_is_armv7() (in
rust-common.bbclass) only recognises armv7a/armv7r/armv7m/armv7ve -- it
returns False for armv8a.  As a result an ARMv8-A AArch32 Thumb build
gets "+neon,+thumb-mode" in the target JSON but neither "+v8" nor
"+thumb2".

LLVM's ParseARMTriple() returns "" for "arm-..." triples
(ARM::parseArch("arm") = INVALID), leaving HasV4TOps unset in the
MCSubtargetInfo used for module-level inline asm parsing.  The ARM ASM
parser's hasThumb() then returns false and ".thumb" directives in
compiler_builtins naked-function trampolines (__aeabi_uldivmod etc.)
are rejected.

This produces two failures when building libstd-rs / compiler_builtins:

  1. core: "LLVM ERROR: Cannot select: br" in core::fmt::num -- LLVM ARM
     ISel patterns for Thumb-2 unconditional branches (t2B) are gated on
     HasV8Ops as well as IsThumb2; without +v8 the pattern never fires.

  2. compiler_builtins: "target does not support Thumb mode" on .thumb
     directives in naked-function trampolines (__aeabi_uldivmod etc.) --
     two separate paths both require +thumb2: HasV4TOps in the
     MCSubtargetInfo (set transitively via ParseARMTriple) and
     FeatureThumb2 in the code-gen ARMSubtarget.

The natural fix would be to change RUST_TARGET_SYS to "armv8a-...", but
"armv8a" is not a recognised Rust target architecture so the triple is
not valid there.  Instead rust_sys_to_llvm_target() rewrites only the
JSON llvm-target field, leaving RUST_TARGET_SYS and rust-common.bbclass
unchanged.

- Add +v8 to llvm_features_from_tune for armv8a AArch32.

- Add +thumb2 to llvm_features_from_tune for armv8a AArch32 Thumb.

- Extend rust_sys_to_llvm_target() to accept the datastore and rewrite
  the "arm-..." triple to "armv8a-..." for armv8a AArch32 targets, so
  the JSON llvm-target field uses "armv8a-..." while RUST_TARGET_SYS
  keeps "arm-...".  ParseARMTriple then adds "+armv8-a" to the
  MCSubtargetInfo, transitively setting HasV4TOps and making hasThumb()
  return true.

The TARGET_ARCH == 'arm' guard is required because AArch64 tunes also
carry armv8a in TUNE_FEATURES (via arch-armv8a.inc) but must not be
affected.

AI-Generated: Claude Code (Claude Opus 4.8)
Signed-off-by: Alex Kiernan <alex.kiernan@gmail.com>
Signed-off-by: Alex Kiernan <alexk@a-squared-projects.uk>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoclasses/archiver: remove SRPM mode
Ross Burton [Fri, 19 Jun 2026 14:12:22 +0000 (15:12 +0100)] 
classes/archiver: remove SRPM mode

The archiver supports saving the source code in either a tarball or a
Source RPM (SRPM).  Tarballs are a logical choice as they're a standard
format for source code, but SRPMs are primarily a way to distribute
source plus packaging scripts for RPM-based distributions, and the SRPMs
generated by the archiver do not include any packaging scripts.

This can result in confusion when people may think that you can take the
SRPM generated by the archiver and rebuild it with rpmbuild, whereas this
will not work.

I think we should remove the SRPM mode from the archiver on the grounds
that tarballs are idiomatic for sharing software, and SRPMs are actively
confusing.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoclasses/archiver: change numbered list to bullets
Ross Burton [Fri, 19 Jun 2026 14:12:21 +0000 (15:12 +0100)] 
classes/archiver: change numbered list to bullets

Change this numbered list to bullets because there's no ordering
and any edits to the list will be more invasive than required.

No meaningful changes to the content beyond the list type.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agopython3-sphinx-argparse: update 0.5.2 -> 0.6.0
Antonin Godard [Thu, 2 Jul 2026 07:00:49 +0000 (09:00 +0200)] 
python3-sphinx-argparse: update 0.5.2 -> 0.6.0

Changelog:

- Added default feature to disable ArgumentParser coloring
- Trying to fix RTD refusing to build
- Moved color-disabling into parse_parser to fix subparsers
- Unpinned ruff for CI + Cleaned up workflow files a little
- Updated license metadata
- Changed filename field to be explicit
- Fixed MyPy
- Added try-catch for autodoc mock-import

License file was renamed but its content unchanged.

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agowebkitgtk: allow usign clang to compile for arm target
João Marcos Costa [Mon, 29 Jun 2026 12:23:10 +0000 (14:23 +0200)] 
webkitgtk: allow usign clang to compile for arm target

This commit reverts:
be459bf17d: "webkitgtk: Use gcc to compile for arm target"

The issue #132322 [1] was resolved, and the corresponding fix [2] is
available in LLVM's v22.1.8 (currently used in oe-core master). It is
actually available since v22.1.0.

[1] https://github.com/llvm/llvm-project/issues/132322
[2] https://github.com/llvm/llvm-project/commit/5e803587eee0

I tested it with MACHINE="qemuarm", and it builds correctly.

Signed-off-by: João Marcos Costa <joaomarcos.costa@bootlin.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoopensbi: don't override ELFFLAGS, silence ldflags QA for bare-metal ELFs
Gustavo Henrique Nihei [Wed, 1 Jul 2026 19:26:13 +0000 (16:26 -0300)] 
opensbi: don't override ELFFLAGS, silence ldflags QA for bare-metal ELFs

opensbi_1.8.1.bb passes ELFFLAGS="${LDFLAGS}" via EXTRA_OEMAKE. Being a
make command-line assignment, it overrides OpenSBI's in-Makefile
"ELFFLAGS +=" and drops the mandatory firmware link flags:

  -Wl,--gc-sections
  -Wl,--exclude-libs,ALL
  -Wl,--build-id=none
  -Wl,--no-dynamic-linker -Wl,-pie

Losing --gc-sections retains unused fdt_*/atomic_* code and grows .text;
losing -pie/--no-dynamic-linker drops the M-mode firmware hardening.

The distro LDFLAGS were not reaching the link regardless: OpenSBI
rebuilds CC from CROSS_COMPILE (Makefile: CC = $(CROSS_COMPILE)gcc), so
oe's CC and its TARGET_CC_ARCH += "${LDFLAGS}" do not apply, and passing
them via ELFFLAGS was the only path in. They are also dynamic-linking
flags with no role in bare-metal firmware, so drop the override;
REPRODUCIBLE=y and CROSS_COMPILE stay.

Removing it re-exposes an ldflags QA warning that the injected
--hash-style=gnu had been satisfying. These firmware ELFs are bare-metal
M-mode binaries (--build-id=none, no dynamic linker) that legitimately
carry no GNU_HASH, so add INSANE_SKIP += "ldflags", as linux-firmware
does.

Tested on oe-core master (DISTRO=nodistro, MACHINE=qemuriscv64) via the
oe-nodistro-master bitbake-setup config:

  bitbake opensbi
  grep -c gc-sections .../opensbi/*/temp/log.do_compile   # 0 -> 4

Before, the fw_jump.elf link carries only the LDFLAGS content (-Wl,-O1,
--hash-style=gnu, --as-needed, -z relro/now) with OpenSBI's flags absent,
and do_package_qa reports ldflags errors on all three firmware ELFs.
After, the link carries OpenSBI's flags (-Wl,--gc-sections,
--exclude-libs,ALL, --build-id=none, --no-dynamic-linker, -pie) and QA
passes. On a single-SoC defconfig, restoring --gc-sections roughly
halves fw_jump.bin.

Fixes: 9f95660886db ("opensbi: Pass CROSS_COMPILE and REPRODUCIBLE flags")
AI-Generated: Uses Cursor

Signed-off-by: Gustavo Henrique Nihei <gustavo.nihei@espressif.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agowebkitgtk: add PACKAGECONFIG for bubblewrap
Markus Volk [Wed, 1 Jul 2026 17:48:52 +0000 (19:48 +0200)] 
webkitgtk: add PACKAGECONFIG for bubblewrap

disabled by default

Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agowebkitgtk: add PACKAGECONFIG for webrtc
Markus Volk [Wed, 1 Jul 2026 17:48:51 +0000 (19:48 +0200)] 
webkitgtk: add PACKAGECONFIG for webrtc

disabled by default

Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agowebkitgtk: add PACKAGECONFIG for librice
Markus Volk [Wed, 1 Jul 2026 16:55:35 +0000 (18:55 +0200)] 
webkitgtk: add PACKAGECONFIG for librice

This avoids:
| -- Checking for module 'rice-proto'
| --   Package 'rice-proto' not found
| -- Checking for module 'rice-io'
| --   Package 'rice-io' not found
| -- Could NOT find Rice (missing: Io Proto) (Required is at least version "0.1.1")
| CMake Error at Source/cmake/GStreamerChecks.cmake:67 (message):
|   librice-{io,proto} is needed for USE_LIBRICE.

Note: librice is availabe in meta-oe

Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agomeson: remove obsolete SSL_CERT_DIR assignment in the wrapper script
Ross Burton [Wed, 1 Jul 2026 16:12:50 +0000 (17:12 +0100)] 
meson: remove obsolete SSL_CERT_DIR assignment in the wrapper script

The wrapper script no longer needs to set SSL_CERT_DIR to what it hopes
is the right path, as openssl now does this when initialising the SDK[1].

[1] oe-core d6b15d1e70b ("openssl: export necessary env vars in SDK")

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agomeson: remove obsolete environment unsets
Ross Burton [Wed, 1 Jul 2026 16:12:49 +0000 (17:12 +0100)] 
meson: remove obsolete environment unsets

We no longer need to remove environment variables because their behaviour
was fixed in meson 0.54.0[1].  The corresponding cleanup was done in
meson.bbclass some time ago[2] but was not done here.

[1] https://mesonbuild.com/Release-notes-for-0-54-0.html#environment-variables-with-cross-builds
[2] oe-core 20a5af2583d ("meson: use native-file instead of environment variables")

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agomeson: add explanatory comment to the meson-native wrapper script
Ross Burton [Wed, 1 Jul 2026 16:12:48 +0000 (17:12 +0100)] 
meson: add explanatory comment to the meson-native wrapper script

Add a clarification comment because it's not immediately obvious that
meson-native is used in eSDKs (whereas nativesdk-meson is used in a SDK).

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agopatchtest: correctly abort --directory test
Trevor Gamblin [Thu, 2 Jul 2026 15:22:13 +0000 (11:22 -0400)] 
patchtest: correctly abort --directory test

Currently, patchtest run with --directory responds to a CTRL+C press by
aborting only the current patch being tested, and moves onto the next.
Instead, this key press should stop the test entirely. Remove usage of
the unittest.installHandler() function (which intercepts the signal) and
handle it ourselves.

Also make sure that the branch is properly reset with git am --abort
afterwards, and that the return code is properly set in the sigint
handler function. Finally, update patchtest_parser.py so that the helper
info reflects this change.

AI-Generated: Uses Claude Code

Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agopatchtest: tests: test_python_pylint.py: use more Pythonic comparison, fix indent
Trevor Gamblin [Thu, 2 Jul 2026 15:22:12 +0000 (11:22 -0400)] 
patchtest: tests: test_python_pylint.py: use more Pythonic comparison, fix indent

- Use "!=" instead of "is not" when checking for a renamed file
- Fix the pylint readlines() block so that indentation is consistent
  with the rest of the module (four spaces instead of eight)

Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agopatchtest: tests: test_patch.py: simplify source patch and upstream status checking
Trevor Gamblin [Thu, 2 Jul 2026 15:22:11 +0000 (11:22 -0400)] 
patchtest: tests: test_patch.py: simplify source patch and upstream status checking

- Only check for new patches once in setUp(), rather than in each
  function
- Fix misleading "CVE" messages when we're really looking for any new
  source patches which are added
- Move patterns for checking patch upstream status into the relevant
  test

Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agopatchtest: tests: test_metadata.py: simplify SRC_URI collection, remove unneeded...
Trevor Gamblin [Thu, 2 Jul 2026 15:22:10 +0000 (11:22 -0400)] 
patchtest: tests: test_metadata.py: simplify SRC_URI collection, remove unneeded import

The pretest_src_uri_left_files() and test_src_uri_left_files() functions
both use the same logic to check for changes, so encapsulate that into a
function for easier re-use. Also remove a pyparsing import which isn't
needed, since it already gets pulled in through other patchtest modules.

Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agopatchtest: tests: test_mbox.py: improve variable and message clarity, fix whitespace
Trevor Gamblin [Thu, 2 Jul 2026 15:22:09 +0000 (11:22 -0400)] 
patchtest: tests: test_mbox.py: improve variable and message clarity, fix whitespace

- Rename "l" to "length" so it's clearer
- Make the message printed for an invalid author (AUH, in particular)
  more explicit
- Remove an extra space in an if block inside test_target_mailing_list()

Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agopatchtest: tests: base.py: remove duplicate Commit object
Trevor Gamblin [Thu, 2 Jul 2026 15:22:08 +0000 (11:22 -0400)] 
patchtest: tests: base.py: remove duplicate Commit object

This is declared twice, so delete one occurrence.

Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agolibarchive: skip fuzz tests in ptest run
Siva Balasubramanian [Fri, 3 Jul 2026 07:00:42 +0000 (12:30 +0530)] 
libarchive: skip fuzz tests in ptest run

The libarchive fuzz tests (test_fuzz_ar, test_fuzz_cab, test_fuzz_cpio,
test_fuzz_iso9660, ...) run 1000 randomised iterations per archive format
and are intended for dedicated fuzzing infrastructure rather than routine
ptest execution. On the time and memory constrained autobuilder QEMU
targets they regularly time out, e.g.:

  158: test_fuzz_iso9660    Timeout! System state:

Upstream provides the SKIP_TEST_FUZZ environment variable to skip these
tests. Export it from run-ptest so the fuzz tests are skipped rather than
run, while the rest of the test suite continues to execute normally.

[YOCTO #16340]

Signed-off-by: Siva Balasubramanian <sivakumar.bs@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agokea: remove obsolete staticdev packaging
Ross Burton [Wed, 1 Jul 2026 16:25:14 +0000 (17:25 +0100)] 
kea: remove obsolete staticdev packaging

Kea doesn't build pointless static libraries for dynamically loaded
modules anymore, so remove this line.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agokea: fix python module packaging
Ross Burton [Wed, 1 Jul 2026 15:26:22 +0000 (16:26 +0100)] 
kea: fix python module packaging

This was previously installing into the wrong target directory because
it was using the python3-native's directory layout.

Now that meson.bbclass is telling meson where to put files, we need to
inherit python3-dir and package the correct files.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoconf/templates/local.conf.sample: add comment about headless qemu
Ross Burton [Thu, 2 Jul 2026 12:57:24 +0000 (13:57 +0100)] 
conf/templates/local.conf.sample: add comment about headless qemu

Add a comment showing how to disable qemu-system-native options if the
build machine is headless, to reduce build dependencies.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoat-spi2-core: inherit python3-dir not python3targetconfig
Ross Burton [Thu, 2 Jul 2026 12:56:25 +0000 (13:56 +0100)] 
at-spi2-core: inherit python3-dir not python3targetconfig

Now that meson.bbclass tells meson where to install Python files this
recipe just needs to know the value of PYTHON_SITEPACKAGES_DIR for
FILES, so just inherit python3-dir to remove a dependency on the target
python recipe.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agopython3-pycairo: inherit python3-dir not python3targetconfig
Ross Burton [Thu, 2 Jul 2026 12:56:24 +0000 (13:56 +0100)] 
python3-pycairo: inherit python3-dir not python3targetconfig

Now that meson.bbclass tells meson where to install Python files this
recipe just needs to know the value of PYTHON_SITEPACKAGES_DIR for
FILES, so just inherit python3-dir to remove a dependency on the target
python recipe.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoblueprint-compiler: inherit python3-dir not python3targetconfig
Ross Burton [Thu, 2 Jul 2026 12:56:23 +0000 (13:56 +0100)] 
blueprint-compiler: inherit python3-dir not python3targetconfig

Now that meson.bbclass tells meson where to install Python files this
recipe just needs to know the value of PYTHON_SITEPACKAGES_DIR for
FILES, so just inherit python3-dir to remove a dependency on the target
python recipe.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoclasses/meson: set python install locations in the cross file
Ross Burton [Thu, 2 Jul 2026 12:56:22 +0000 (13:56 +0100)] 
classes/meson: set python install locations in the cross file

Instead of needing recipes to inherit python3targetconfig so that Python
when asked will report the correct target directory to install into, we
can pass the right directory via meson's cross file.

This means recipes that currently inherit python3targetconfig to get
this path no longer need to.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agowic-tools: Change to MACHINE_ARCH
Joshua Watt [Tue, 30 Jun 2026 21:01:44 +0000 (15:01 -0600)] 
wic-tools: Change to MACHINE_ARCH

Changes wic-tools to be MACHINE_ARCH. This isn't exactly an ideal, but
wic-tools is attempting to provide a target sysroot that (potentially)
contains the EFI binaries for wic (and, this is the only way wic is
willing to find those binaries). Since the EFI binaries are
MACHINE_ARCH, wic-tools must also be MACHINE_ARCH otherwise it causes
problems.

Signed-off-by: Joshua Watt <JPEWhacker@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agomultilib: Add systemd-boot to NON_MULTILIB_RECIPES
Joshua Watt [Tue, 30 Jun 2026 21:01:43 +0000 (15:01 -0600)] 
multilib: Add systemd-boot to NON_MULTILIB_RECIPES

systemd-boot is EFI firmware (like grub-efi) and doesn't make sense to
be multilib

Signed-off-by: Joshua Watt <JPEWhacker@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agosystemd-boot: Change to MACHINE_ARCH
Joshua Watt [Tue, 30 Jun 2026 21:01:42 +0000 (15:01 -0600)] 
systemd-boot: Change to MACHINE_ARCH

Machines can change EFI_PROVIDER which changes the way systemd-boot is
built, meaning two machine may not build it the same way. As such, the
arch should be MACHINE_ARCH.

Signed-off-by: Joshua Watt <JPEWhacker@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agogrub-efi: Change to MACHINE_ARCH
Joshua Watt [Tue, 30 Jun 2026 21:01:41 +0000 (15:01 -0600)] 
grub-efi: Change to MACHINE_ARCH

Machines can change EFI_PROVIDER which changes the way grub-efi is
built, meaning two machine may not build it the same way. As such, the
arch should be MACHINE_ARCH.

Signed-off-by: Joshua Watt <JPEWhacker@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agobluez5: upgrade 5.86 -> 5.87
Richard Purdie [Sun, 5 Jul 2026 05:09:14 +0000 (05:09 +0000)] 
bluez5: upgrade 5.86 -> 5.87

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoenchant2: upgrade 2.8.16 -> 2.8.18
Richard Purdie [Sun, 5 Jul 2026 05:39:32 +0000 (05:39 +0000)] 
enchant2: upgrade 2.8.16 -> 2.8.18

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agopython3-setuptools: upgrade 82.0.1 -> 83.0.0
Richard Purdie [Sun, 5 Jul 2026 05:32:53 +0000 (05:32 +0000)] 
python3-setuptools: upgrade 82.0.1 -> 83.0.0

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agogpgme: upgrade 2.1.0 -> 2.1.2
Richard Purdie [Wed, 1 Jul 2026 06:34:04 +0000 (06:34 +0000)] 
gpgme: upgrade 2.1.0 -> 2.1.2

License-Update: Copyright years changed

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agolibjpeg-turbo: Add PIC flags
Richard Purdie [Sun, 5 Jul 2026 09:43:12 +0000 (10:43 +0100)] 
libjpeg-turbo: Add PIC flags

Our cross compiler generates PIE by default but the host may not. Add
oppropriate cmake flags to avoid build failures in the native variant
on hosts like OpenSUSE 16.0.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agolibjpeg-turbo: upgrade 3.1.4.1 -> 3.2.0
Richard Purdie [Wed, 1 Jul 2026 06:18:35 +0000 (06:18 +0000)] 
libjpeg-turbo: upgrade 3.1.4.1 -> 3.2.0

According to this commit, the zlib license does not apply:

https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9ef0d03e1e5f0140636215afe627954b81602c38

however the zlib source is still there and still used by libspng so I'm leaving
LICENSE unchanged.

License-Update: Upstream changed the wording around zlib but it is still present

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoerofs-utils: upgrade 1.9.1 -> 1.9.2
Richard Purdie [Thu, 2 Jul 2026 05:20:13 +0000 (05:20 +0000)] 
erofs-utils: upgrade 1.9.1 -> 1.9.2

License-Update: Switch to GPL-2.0-or-later OR MIT instead of Apache-2.0

https://git.kernel.org/pub/scm/linux/kernel/git/xiang/erofs-utils.git/commit/?id=c0a809cf5dccf9956b573bdd2ae51f1f100f9f90

"""
erofs-utils uses two different licensing patterns:

 - Most liberofs files in the `lib` and `include` directories
   use a dual GPL-2.0+ OR MIT license whenever possible.

 - All other files use the MIT license unless explicitly stated
   otherwise.

This model was chosen to maximize the ability of erofs-utils to
integrate with various ecosystems.

However, liberofs uses a GPL-2.0+ OR MIT dual license because some
parts should be shared with the Linux kernel.
"""

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agopython3-uv-build: upgrade 0.11.21 -> 0.11.26
Richard Purdie [Wed, 1 Jul 2026 06:06:54 +0000 (06:06 +0000)] 
python3-uv-build: upgrade 0.11.21 -> 0.11.26

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agopython3-rpds-py: upgrade 2026.5.1 -> 2026.6.3
Richard Purdie [Wed, 1 Jul 2026 06:00:36 +0000 (06:00 +0000)] 
python3-rpds-py: upgrade 2026.5.1 -> 2026.6.3

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agopython3-cython: upgrade 3.2.5 -> 3.2.8
Richard Purdie [Wed, 1 Jul 2026 05:55:14 +0000 (05:55 +0000)] 
python3-cython: upgrade 3.2.5 -> 3.2.8

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agolibxmlb: upgrade 0.3.27 -> 0.3.28
Richard Purdie [Wed, 1 Jul 2026 06:11:21 +0000 (06:11 +0000)] 
libxmlb: upgrade 0.3.27 -> 0.3.28

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoigt-gpu-tools: upgrade 2.4 -> 2.5
Richard Purdie [Wed, 1 Jul 2026 06:15:34 +0000 (06:15 +0000)] 
igt-gpu-tools: upgrade 2.4 -> 2.5

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agodiffoscope: upgrade 319 -> 323
Richard Purdie [Wed, 1 Jul 2026 06:26:50 +0000 (06:26 +0000)] 
diffoscope: upgrade 319 -> 323

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agomesa/mesa-tools-native: Upgrade 26.1.2 -> 26.1.4
Richard Purdie [Fri, 3 Jul 2026 07:31:22 +0000 (08:31 +0100)] 
mesa/mesa-tools-native: Upgrade 26.1.2 -> 26.1.4

Patch from Alexander Kanavin <alex@linutronix.de> added to resolve qemuarmv5
build failure.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agojansson: upgrade 2.15.0 -> 2.15.1
Richard Purdie [Thu, 2 Jul 2026 05:25:01 +0000 (05:25 +0000)] 
jansson: upgrade 2.15.0 -> 2.15.1

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agopython3-typing-extensions: upgrade 4.15.0 -> 4.16.0
Richard Purdie [Fri, 3 Jul 2026 05:18:38 +0000 (05:18 +0000)] 
python3-typing-extensions: upgrade 4.15.0 -> 4.16.0

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agolibadwaita: upgrade 1.9.1 -> 1.9.2
Richard Purdie [Fri, 3 Jul 2026 05:31:40 +0000 (05:31 +0000)] 
libadwaita: upgrade 1.9.1 -> 1.9.2

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agohwdata: upgrade 0.408 -> 0.409
Richard Purdie [Fri, 3 Jul 2026 05:34:48 +0000 (05:34 +0000)] 
hwdata: upgrade 0.408 -> 0.409

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agolibevent: upgrade 2.1.12 -> 2.1.13
Ross Burton [Thu, 2 Jul 2026 13:24:16 +0000 (14:24 +0100)] 
libevent: upgrade 2.1.12 -> 2.1.13

Security Fixes (evtag, evrpc):

  Fix an out-of-bounds read in decode_tag_internal.
  (Found by @Brubbish. GHSA-fj29-64w6-73h6)

  Fix an integer overflow in evtag_unmarshal_header.
  (Found by @Brubbish. GHSA-45c6-qx49-89m8)

Security Fixes (evhttp):

  Discard HTTP trailers, to prevent header smuggling attacks.
  (Found by @sebastianosrt. GHSA-2gmv-p5m7-98p6)

  Restrict HTTP header parsing to prevent request smuggling.
  (Originally reported by @xclow3n; and then by @kodareef5,
  @nstaller0490, @AsafMeizneer, and @yaotushaozhu.
  GHSA-q39v-w2g7-gr8j.)

  Treat CRLF and %00 more strictly in HTTP headers, to prevent
  parser mismatch attacks.
  (Reported by @xclow3n and @AsafMeizner. See GHSA-q39v-w2g7-gr8j,
  GHSA-jcwh-pvf2-73p2.)

  Fix a heap out-of-bound write that could occur when using
  AF_UNIX sockets and compiling libevent with -DNDEBUG.
  (Found by @mat-mo. GHSA-cvq5-vrvr-j338)

Security fixes (evbuffer, bufferevent):

  Fixed a dangling pointer in evbuffer_add_reference.
  (Found by @DarkaMaul. GHSA-c2pj-cg4r-88c8)

Security fixes (evdns):

  Fix an out-of-bounds write in dnsname_to_labels
  when building a DNS response of 2^16 bytes.
  (Found by @sectroyer. GHSA-58rx-7448-jw47)

Security fixes (example code):

  Avoid using strcpy() in sample/http-server.c.
  (Reported by @sectroyer. GHSA-5rgj-2c58-7jrc.)

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agopatchelf: upgrade 0.18.0+git -> 0.19.0
Richard Purdie [Sat, 27 Jun 2026 05:22:02 +0000 (05:22 +0000)] 
patchelf: upgrade 0.18.0+git -> 0.19.0

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agodhcpcd: patch CVE-2026-56117
Theo Gaige (Schneider Electric) [Wed, 1 Jul 2026 10:46:37 +0000 (12:46 +0200)] 
dhcpcd: patch CVE-2026-56117

Backport patch [1] mentionned in [2]

[1] https://github.com/NetworkConfiguration/dhcpcd/commit/78ea09ed1633a583dbcde6e7bab9df4639ec8a34

[2] https://security-tracker.debian.org/tracker/CVE-2026-56117

Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
3 weeks agodhcpcd: patch CVE-2026-56116
Theo Gaige (Schneider Electric) [Wed, 1 Jul 2026 10:46:36 +0000 (12:46 +0200)] 
dhcpcd: patch CVE-2026-56116

Backport patch [1] mentionned in [2]

[1] https://github.com/NetworkConfiguration/dhcpcd/commit/708b4a56bae080a5b18c2e0c4c6fbe103131a2b0

[2] https://security-tracker.debian.org/tracker/CVE-2026-56116

Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
3 weeks agodhcpcd: patch CVE-2026-56114
Theo Gaige (Schneider Electric) [Wed, 1 Jul 2026 10:46:35 +0000 (12:46 +0200)] 
dhcpcd: patch CVE-2026-56114

Backport patch [1] mentionned in [2]

[1] https://github.com/NetworkConfiguration/dhcpcd/commit/2f00c7bfc408b6582d331932dfa47829c4819029

[2] https://security-tracker.debian.org/tracker/CVE-2026-56114

Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
3 weeks agodhcpcd: patch CVE-2026-56113
Theo Gaige (Schneider Electric) [Wed, 1 Jul 2026 10:46:34 +0000 (12:46 +0200)] 
dhcpcd: patch CVE-2026-56113

Backport patch [1] mentionned in [2]

[1] https://github.com/NetworkConfiguration/dhcpcd/commit/5733d3c59a5651f64357ac11c98b4f39895c8d25

[2] https://security-tracker.debian.org/tracker/CVE-2026-56113

Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
3 weeks agognupg: fix CVE-2026-57062
Roland Kovacs [Wed, 1 Jul 2026 08:26:39 +0000 (10:26 +0200)] 
gnupg: fix CVE-2026-57062

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20
mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be
12 bytes but 4 bytes is accepted.

Signed-off-by: Roland Kovacs <roland.kovacs@est.tech>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
3 weeks agognupg: Upgrade 2.5.17 -> 2.5.20
Roland Kovacs [Wed, 1 Jul 2026 08:26:38 +0000 (10:26 +0200)] 
gnupg: Upgrade 2.5.17 -> 2.5.20

Bug fixes included in this release:
   - gpg: Fix wrong assertion failure which could very rarely occur
     during key signature checking.  [rG693f5642f6]
   - gpg: Consider certify-only keys for revocation signature check.
     [T8196]
   - gpgsm: Fix possible double free in the CMS parser.  [T8240]
   - gpgsm: Fix possible too early removal of ephemeral keys.  [T8236]
   - gpgsm: Avoid emitting a final FAILURE status line if --status-fd
     is not used.  [rG69c27fe377]
   - gpgsm: Fix a regression in 2.5.19 for password encrypted GCM
     data.  [rG60a823c97b]
   - agent: Fix not using cache for pinentry loopback.  [rGd4b608a31f]
   - agent: Fix command PUT_SECRET by saving input line.  [rG1875bc185e]
   - keyboxd: Mark keys searched but not imported via LDAP correctly
     as ephemeral.  [T8048]
   - scdaemon: Avoid buffer overflow with SC-HSM cards providing RSA
     keys > 2k.  [T8244]
   - dirmngr: Fix uninitialized use of the dns_any union in
     dns_rr_cmp.  [T8251]
 Release-info: https://dev.gnupg.org/T7997

Signed-off-by: Roland Kovacs <roland.kovacs@est.tech>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
3 weeks agopackage_pkgdata: fix typo to stop calling undefined function
Adam Blank [Sat, 18 Apr 2026 18:34:01 +0000 (20:34 +0200)] 
package_pkgdata: fix typo to stop calling undefined function

The function is named 'package_populate_pkgdata_dir' but the
call was to 'staging_package_populate_pkgdata_dir'.

To ensure other problematic variable dependencies aren't added,
set vardepseclude to match variables which are normally excluded
elsewhere.

[RP: tweaked commit message]
Signed-off-by: Adam Blank <adam.blank.g@gmail.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoscripts/oe-publish-sdk: Convert string subprocess parameters to list
Richard Purdie [Sat, 13 Jun 2026 12:55:04 +0000 (13:55 +0100)] 
scripts/oe-publish-sdk: Convert string subprocess parameters to list

Convert string subprocess commands to lists and drop the shell=True. We
can drop the sh indirection in one case too.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoqemu: add ppc64le support to COMPATIBLE_HOST
Andrew Geissler [Tue, 16 Jun 2026 20:50:30 +0000 (15:50 -0500)] 
qemu: add ppc64le support to COMPATIBLE_HOST

The move to qemu 11 and the enforcement of 64 bit machines broke ppc64le
machines. Add ppc64le wherever there is a ppc64 machine.

Signed-off-by: Andrew Geissler <geissonator@yahoo.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agosstate/staging: Add SSTATETASKS vardepsexclude entries
Richard Purdie [Wed, 1 Jul 2026 17:06:31 +0000 (18:06 +0100)] 
sstate/staging: Add SSTATETASKS vardepsexclude entries

Tasks should never be dependning on SSTATETASKS since that can change for things
which code should be independent from (e.g. package backend), breaking sstate reuse.
Add the appropriate vardepexclude entres.

This currently isn't an issue due to extend_recipe_sysroot being globally
excluded from hashes.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
3 weeks agokea: remove install-umask workaround
Ross Burton [Thu, 2 Jul 2026 12:30:17 +0000 (13:30 +0100)] 
kea: remove install-umask workaround

This workaround is no longer needed as the upstream commit that fixes
the problem is part of 3.2.0.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agodhcpcd: Add PACKAGECONFIG for seccomp
Alex Kiernan [Tue, 30 Jun 2026 15:17:05 +0000 (16:17 +0100)] 
dhcpcd: Add PACKAGECONFIG for seccomp

Pass --enable/disable-seccomp to the build based on DISTRO_FEATURES.

Signed-off-by: Alex Kiernan <alex.kiernan@gmail.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agosanity.bbclass: warn on cargo config files outside the build tree
Hemanth Kumar M D [Thu, 25 Jun 2026 06:52:13 +0000 (23:52 -0700)] 
sanity.bbclass: warn on cargo config files outside the build tree

Cargo walks from CWD up to the filesystem root merging every
.cargo/config[.toml] it finds. Any such file above BASE_WORKDIR is
silently picked up and can override Yocto's linker, registry or
compiler settings, leading to build failures.

Until cargo provides a proper fix upstream, add a warning so users
get a clear diagnostic instead of a build error.

Upstream meta-issue: https://github.com/rust-lang/cargo/issues/9769

[YOCTO #15637]

Signed-off-by: Hemanth Kumar M D <Hemanth.KumarMD@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agodropbear: Add missing WTFPL & Unlicense in LICENSE and LIC_FILES_CHKSUM
Yoann Congal [Tue, 30 Jun 2026 13:48:54 +0000 (15:48 +0200)] 
dropbear: Add missing WTFPL & Unlicense in LICENSE and LIC_FILES_CHKSUM

Vendored libtomcrypt and libtommath are respectively WTFPL and
Unlicense: update LICENSE to reflect that and include vendored LICENSE
files in LIC_FILES_CHKSUM to detect changes.

Note: libtomcrypt/LICENSE also specify "Public domain" but that is not a
real licence, so choose the alternative: WTFPL.

Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agolibxml2: patch CVE-2026-11979
Anton Skorup [Tue, 30 Jun 2026 06:20:51 +0000 (08:20 +0200)] 
libxml2: patch CVE-2026-11979

Pick patch from [1] linked from [2].

[1] https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e
[2] https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1124

Signed-off-by: Anton Skorup <anton.skorup@axis.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agosystemd-systemctl-native: remove systemd-sysv-install logic
Ross Burton [Mon, 29 Jun 2026 14:15:59 +0000 (15:15 +0100)] 
systemd-systemctl-native: remove systemd-sysv-install logic

The use of systemd-sysv-install was removed before Wrynose[1], so we do
not need to install it in systemd-systemctl-native.

[1] oe-core d9ec9e20eeb ("systemd: Stop supporting sysvinit compatibility")

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agosystemd-systemctl-native: update MESON_TARGET for direct ninja use
Ross Burton [Mon, 29 Jun 2026 14:15:58 +0000 (15:15 +0100)] 
systemd-systemctl-native: update MESON_TARGET for direct ninja use

We can't specify the target type now that the Meson class calls ninja
directly, so drop it. This doesn't change what is built.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoclasses/meson: use ninja explicitly when compiling
Ross Burton [Mon, 29 Jun 2026 14:15:57 +0000 (15:15 +0100)] 
classes/meson: use ninja explicitly when compiling

"meson compile" is essentially a glorified wrapper around calling ninja
that doesn't support all of the options that ninja does, so calling it
directly means builds are fractionally faster and we get direct control
over the flags that ninja is passed.

A longer rationale can be found in the Gentoo change by Eli Schwartz
that caused this patch, who is both a Gentoo and Meson developer:

https://github.com/gentoo/gentoo/commit/66011abd663671947fe07835f0d9cc360f5de317

The only change is that the compile target doesn't support the optional
convenience target type, but this is rarely used.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoglib-2.0: refresh gio-querymodules install path patch
Ross Burton [Mon, 29 Jun 2026 15:39:42 +0000 (16:39 +0100)] 
glib-2.0: refresh gio-querymodules install path patch

This patch was badly rebased onto upstream changes and ended up setting
install_dir twice. Refresh the patch to change the existing value
instead of adding another.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agobc: set CVE_PRODUCT
Daniel Turull [Mon, 29 Jun 2026 13:19:35 +0000 (15:19 +0200)] 
bc: set CVE_PRODUCT

Set vendor to gnu similar as other tools from gnu
to have clear naming for registering into vulnerability management tools

Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
3 weeks agoclang_git.bb: remove dangling comment
João Marcos Costa [Mon, 29 Jun 2026 11:06:19 +0000 (13:06 +0200)] 
clang_git.bb: remove dangling comment

CMAKE_VERBOSE is already enabled in cmake.bbclass (inherited in this
recipe). I would have considering uncommenting the line if it originally
meant to disable the verbose mode.

Signed-off-by: João Marcos Costa <joaomarcos.costa@bootlin.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>