Commit Graph
39931 Commits
Author SHA1 Message Date
Jaipaul Cheernam 2f4c38d5d6 meta-python: fix trailing whitespace
Bitbake now warns about trailing whitespace in parsed metadata lines.
Fix the affected files to silence the warnings during parsing.

Reported on:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/89/builds/4284/steps/15/logs/warnings

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 01:43:11 -07:00
Kiruthika Vijayasekar a09474fb9a pipewire: add pw-voiceui SVA voice-UI control/listen client
Add the pw-voiceui tool, a CLI for controlling and monitoring the SVA
(Sound Trigger / Voice Activation) voice-UI PipeWire node exposed by
the pw-pal-plugin (media.role=VoiceUI). Supports list/info/listen,
setting SVA parameters, and sending commands.

Add 0003-tools-add-pw-voiceui-SVA-voice-UI-control-listen-cl.patch,
reference it from SRC_URI, and list pw-voiceui in FILES:${PN}-tools.

Signed-off-by: Kiruthika Vijayasekar <kvijayas@qti.qualcomm.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 01:43:11 -07:00
Kiruthika Vijayasekar e3212d7860 tinyalsa: fix pcm_ioctl() to dispatch through plugin ops
pcm_ioctl() previously had a FIXME and always issued the ioctl
directly on pcm->fd, bypassing any loaded plugin (e.g. AGM's tinyalsa
plugin). Dispatch through pcm->ops->ioctl when a plugin is loaded,
falling back to the direct ioctl() otherwise.

Add 0002-pcm-fix-pcm_ioctl-to-dispatch-through-plugin-ops.patch and
reference it from SRC_URI.

Signed-off-by: Kiruthika Vijayasekar <kvijayas@qti.qualcomm.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 01:43:11 -07:00
Gianfranco Costamagna f191557494 vboxguestdrivers: Upgrade to 7.2.16
Signed-off-by: Gianfranco Costamagna <locutusofborg@debian.org>
Signed-off-by: Gianfranco Costamagna <costamagnagianfranco@yahoo.it>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 14:49:04 -07:00
Devansh Patel 7a393253ec python3-ujson: add CVE_PRODUCT mapping
The current inherited "python:ujson" mapping does not match the UltraJSON identities used by NVD and CVE List V5, so source-aligned CVEs are missed.

Use "ultrajson:ultrajson" for the CNA affected-data identity and "ultrajson_project:ultrajson" for the NVD dictionary CPE and configuration identity.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 12:14:08 -07:00
Devansh Patel 46ca829b65 python3-twitter: correct Tweepy CVE_PRODUCT mapping
The product-only "tweepy" value emits a wildcard-vendor identity and
hides the distinct NVD identities assigned to the packaged Tweepy source.

Use "josh_roesslein:tweepy" for its NVD dictionary CPE and
"tweepy:tweepy" for the NVD configuration-only identity. With
sbom-cve-check 1.3.3 and the pinned database snapshots, the generated
product identity changes; the current CVE report is unchanged.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 12:14:08 -07:00
Devansh Patel 3874342e00 python3-flask-user: correct CVE_PRODUCT mapping
The current "flask-user" mapping emits the wildcard-vendor
*:flask-user CPE instead of the exact NVD identity for the packaged
lingthio/Flask-User source.

Use "flask-user_project:flask-user", which is both an NVD dictionary
CPE and an NVD configuration identity. CNA affected data uses
"n/a:Flask-User" and remains covered by scanner aliases. With
sbom-cve-check 1.3.3 and the pinned 2026-08-12 data, the generated
identity changes but CVE-2021-23401 remains reported as affected.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 12:14:07 -07:00
Devansh Patel 6cbb85db1a python3-flask: correct CVE_PRODUCT mapping
The current "flask" mapping emits the wildcard-vendor *:flask CPE
instead of the exact NVD identity for the packaged pallets/flask
source.

Use "palletsprojects:flask", which is both an NVD dictionary CPE and
an NVD configuration identity. CNA affected data uses "pallets:flask"
and "The Pallets Project:Flask", which remain covered by scanner
aliases. With sbom-cve-check 1.3.3 and the pinned 2026-08-12 data, the
generated identity changes but the current CVE report does not.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 12:14:07 -07:00
Devansh Patel 33d7be4319 python3-aiohttp: correct CVE_PRODUCT mapping
The current "aiohttp" mapping emits the wildcard-vendor *:aiohttp CPE
instead of the exact NVD identity for the packaged aio-libs/aiohttp
source.

Use "aiohttp:aiohttp", which is both an NVD dictionary CPE and an NVD
configuration identity. CNA affected data uses "aio-libs:aiohttp" and
remains covered by scanner aliases. With sbom-cve-check 1.3.3 and the
pinned 2026-08-12 data, the generated identity changes but the current
CVE report does not.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 12:14:07 -07:00
Devansh Patel ae093476ee python3-waitress: correct CVE_PRODUCT mapping
The current product-only "waitress" mapping emits a wildcard-vendor identity instead of the exact identities assigned to the packaged Pylons source.

Use "pylons:waitress" for the CNA affected-data identity and "agendaless:waitress" for the NVD dictionary CPE and configuration identity. This changes the generated product identity, but sbom-cve-check 1.3.3 with the pinned databases leaves the current CVE report unchanged.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 12:14:07 -07:00
Devansh Patel fd0b8a36e6 python3-werkzeug: correct CVE_PRODUCT mapping
The current product-only "werkzeug" mapping emits a wildcard-vendor identity instead of the exact identities assigned to the packaged Pallets source.

Use "pallets:werkzeug" for the CNA affected-data identity and "palletsprojects:werkzeug" for the NVD dictionary CPE and configuration identity. This changes the generated product identity, but sbom-cve-check 1.3.3 with the pinned databases leaves the current CVE report unchanged.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 12:14:07 -07:00
Ankur Tyagi fa89b2d67c swagger-ui: upgrade 5.32.13 -> 5.32.14
Changelog:
https://github.com/swagger-api/swagger-ui/releases/tag/v5.32.14

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-23 09:42:41 -07:00
krant 54d51c2c2a libfaketime: extend to nativesdk
Needed for reproducible UEFI capsules in meta-tegra.

Signed-off-by: krant <aleksey.vasilenko@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-23 09:42:41 -07:00
Khem Raj 7af0bdb0fe hunspell: keep ptest failure diagnostics instead of discarding them
run-ptest ran each case as "./test.sh $test > /dev/null 2>&1", throwing
away the only thing that explains a failure: test.sh prints which check
failed and which words were misrecognised, e.g.

  Fail in base.good. Good words recognised as wrong:
  <words>

Without it a failing hunspell ptest reports a bare "FAIL: <name>" and
gives no way to tell a packaging problem from a real defect when the
suite runs on target.

Capture the output and print it, indented, under the FAIL line, and
take test.sh's exit status directly rather than reading $? inside the
else branch of the if that consumed it.

Signed-off-by: Khem Raj <raj.khem@gmail.com>
2026-08-22 18:50:05 -07:00
Khem Raj 5094e3aedf hunspell: add missing gconv ptest RDEPENDS
All 25 ptest failures are missing glibc character-set converters. With
run-ptest no longer discarding test.sh output, the cause is explicit:

  error - iconv_open: ISO8859-1 -> UTF-8
  error - iconv_open: UTF-8 -> ISO8859-1
  =============================================
  Fail in allcaps3.good. Good words recognised as wrong:

Aggregated over the run: 382 ISO8859-1 and 10 ISO8859-15 iconv_open
failures, and every one of the 25 failing tests reports them.

Only glibc-gconv-iso8859-2 was pulled in, but the test corpus needs more
than that. Dictionaries with no SET line in their .aff fall back to
ISO8859-1 in both consumers of the default:

  csutil.hxx:99      #define SPELL_ENCODING "ISO8859-1"
  affixmgr.cxx:3502  if (encoding.empty()) encoding = SPELL_ENCODING;
  hashmgr.cxx:97     if (!csconv) csconv = get_current_cs(SPELL_ENCODING);

and 92 of the 144 installed .aff files have no SET, which is why tests
with pure-ASCII data and no SET line still needed a converter. The
encodings actually referenced across the corpus are ISO8859-1,
ISO8859-15, ISO-8859-15, ISO8859-2 and UTF-8; UTF-8 is built into glibc,
so add the two missing ISO8859 modules.

Signed-off-by: Khem Raj <raj.khem@gmail.com>
2026-08-22 18:50:04 -07:00
Khem Raj 2362496fa0 xdg-dbus-proxy: skip ptest when dbus-daemon is unavailable
tests/test-proxy.c setup() spawns the reference bus implementation
directly:

  g_subprocess_launcher_spawn (launcher, &error, "dbus-daemon",
                               "--session", "--print-address=1",
                               "--nofork", NULL);

so the test aborts on distros that select a different
VIRTUAL-RUNTIME_dbus:

  ERROR:../tests/test-proxy.c:75:setup: assertion failed (error == NULL):
  Failed to execute child process "dbus-daemon" (No such file or directory)
  FAIL: xdg-dbus-proxy/test-proxy.test (Child process killed by signal 6)

dbus-daemon is packaged only in dbus, and dbus-broker carries
"RCONFLICTS:dbus-broker: dbus", so the two cannot be co-installed;
dbus-broker-launch is not CLI-compatible and cannot stand in. The
existing RDEPENDS on ${VIRTUAL-RUNTIME_dbus} already pulls in dbus (and
hence dbus-daemon) on distros that use it, so report the test as skipped
rather than failed when the daemon genuinely is not installable.

Signed-off-by: Khem Raj <raj.khem@gmail.com>
2026-08-22 18:50:04 -07:00
Khem Raj 8df282147e freerdp3: install cmdline-tests data for ptest
TestCommandLineToCommaSeparatedValues fails because its JSON test cases
are never installed.

With no arguments the test runs runJsonTests(), which globs
TEST_SOURCE_DIR/cmdline-tests/*.json via FindFirstFileA and returns -1
when the directory cannot be opened. do_configure:prepend already
rewrites TEST_SOURCE_DIR for this CMakeLists to ${PTEST_PATH}/test, and
the built driver confirms it:

  $ strings Testing/TestWinPRUtils | grep -e cmdline-tests -e ptest/test
  cmdline-tests
  cmdline-tests%c*.json
  /usr/lib/freerdp3/ptest/test

but do_install_ptest only copies *bmp out of
winpr/libwinpr/utils/test, so /usr/lib/freerdp3/ptest/test/cmdline-tests
does not exist on target and the glob always fails. Copy the directory
alongside the other test data.

Signed-off-by: Khem Raj <raj.khem@gmail.com>
2026-08-22 18:50:04 -07:00
Khem Raj f1fc1f3908 libdbi-perl: add missing perl module ptest RDEPENDS
All 6 ptest failures (t/31methcache, t/35thrclone, t/40profile,
t/41prof_dump, t/42prof_data, t/43prof_env) are missing runtime perl
modules, in two groups:

Module::Load, required by DBI/Profile.pm line 682:

  Can't locate Module/Load.pm in @INC ... at
  /usr/lib/perl5/vendor_perl/5.44.0/aarch64-linux/DBI/Profile.pm line 682.

This breaks t/40profile and t/43prof_env directly, and cascades into
t/41prof_dump and t/42prof_data: once DBI/Profile.pm fails to compile,
%INC is poisoned, so those two report "Attempt to reload DBI/Profile.pm
aborted" and a missing DBI::Profile->flush_to_disk method rather than
the underlying cause. Provided by perl-module-load.

Test2::Util::Sig, required by Test2/IPC/Driver/Files.pm line 18, which
Test::Builder pulls in when a test enables Test2 IPC (threads/forking):

  Can't locate Test2/Util/Sig.pm in @INC ... at
  /usr/lib/perl5/5.44.0/Test2/IPC/Driver/Files.pm line 18.

This makes Test::More unusable in t/31methcache and t/35thrclone, which
is why only those two of the many Test::More-based tests fail. Provided
by perl-module-test2-util-sig.

Signed-off-by: Khem Raj <raj.khem@gmail.com>
2026-08-22 18:50:04 -07:00
Khem Raj 3193da66d3 pegtl: install ptest data files where the tests look for them
14 of the 257 pegtl tests failed - every test that reads a data file
(input_file_input, input_mmap_input, internal_file_mapper,
internal_read_file_stdio, stream_*_input, example_json, ...) while the
243 tests that parse in-memory strings passed.

Upstream runs its tests from the source root:

  src/test/CMakeLists.txt:299
  add_test(NAME ${exename} WORKING_DIRECTORY ${CMAKE_SOURCE_DIR} ...)

so the tests open their data with CWD-relative literals - grepping the
test sources shows src/test/data/duseltronik.txt (7 references),
src/test/data/test_data.txt (4) and src/test/data/{blns,pass1-3,
fail1-39}.json. run-ptest executes the binaries from ${PTEST_PATH}, so
the data has to be at ${PTEST_PATH}/src/test/data/.

The recipe instead installed it to src/test/pegtl/data - one directory
too deep - and copied only *.json, so test_data.txt and
duseltronik.txt were missing entirely. Install all of src/test/data
to the path the tests actually use. The binaries stay in
src/test/pegtl, which is where run-ptest globs for them.

Signed-off-by: Khem Raj <raj.khem@gmail.com>
2026-08-22 18:50:04 -07:00
Khem Raj 075b833d3e postgresql: drop bashisms from ptest runner
run-ptest has a #!/bin/sh shebang but used two constructs that are not
available in the target /bin/sh (dash), so the suite died immediately
after starting the server and reported no test results at all:

  run-ptest: line 54: stdbuf: not found
  run-ptest: line 58: syntax error: bad substitution
  ERROR: Exit status is 2

${PIPESTATUS[0]} is a bash array reference; dash has no PIPESTATUS and
fails with "bad substitution". stdbuf is coreutils-only and is not
guaranteed to be installed on the target.

Capture pg_regress output to a temporary file and use $? directly
instead of piping live into sed, which removes the need for both
PIPESTATUS and stdbuf while keeping the same PASS:/FAIL: translation.

Signed-off-by: Khem Raj <raj.khem@gmail.com>
2026-08-22 18:50:04 -07:00
Khem Raj 176c2485b9 fwupd: use VIRTUAL-RUNTIME_dbus for ptest RDEPENDS
Same problem as xdg-dbus-proxy: the hardcoded "dbus" RDEPENDS makes
meta-oe-image-ptest-fwupd fail do_rootfs on a distro whose
VIRTUAL-RUNTIME_dbus is dbus-broker, since dbus-broker RCONFLICTS with
the dbus provided by dbus-1 while systemd requires dbus-broker.

Signed-off-by: Khem Raj <raj.khem@gmail.com>
2026-08-22 18:50:04 -07:00
Khem Raj 63bff20667 xdg-dbus-proxy: use VIRTUAL-RUNTIME_dbus for ptest RDEPENDS
Hardcoding "dbus" makes the ptest image unbuildable on any distro that
selects a different system bus implementation. On a systemd distro
setting VIRTUAL-RUNTIME_dbus = "dbus-broker", do_rootfs fails to
solve:

  package dbus-broker-37 conflicts with dbus provided by dbus-1-1.16.2
  package systemd requires dbus-broker, but none of the providers can
    be installed
  package xdg-dbus-proxy-ptest requires dbus, but none of the providers
    can be installed

Depend on ${VIRTUAL-RUNTIME_dbus} instead so the ptest package pulls
in whichever bus the distro actually uses.

Signed-off-by: Khem Raj <raj.khem@gmail.com>
2026-08-22 18:50:03 -07:00
Michal Sieron 0e1bcb85b4 ntp: Stop building and delivering ntpdate
ntpdate has been deprecated. meta-openembedded@6315006aadd in theory
dropped it, but in practice the binary was still being built and
shipped, but now as part of ntp-utils package.
To avoid this, let's patch it out of the build.

Signed-off-by: Michal Sieron <michal.sieron@nokia.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-22 18:50:03 -07:00
Devansh Patel 3ea522b0ec python3-pymongo: correct CVE_PRODUCT mapping
The product-only "pymongo" value emits a wildcard-vendor identity and
omits the second authoritative name for the packaged MongoDB Python
driver.

Use "mongodb:python_driver" for its NVD dictionary CPE family and
"mongodb:pymongo" for its NVD dictionary CPE and configuration identity.
With sbom-cve-check 1.3.3 and the pinned database snapshots, the
generated product identity changes; the current CVE report is unchanged.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-22 18:50:03 -07:00
Devansh Patel a5f68ce920 python3-m2crypto: correct CVE_PRODUCT mapping
The current product-only "m2crypto" mapping generates a wildcard-vendor
identity instead of the two vendors used for the packaged source.

Use "heikkitoivonen:m2crypto" and "m2crypto_project:m2crypto" for their
exact NVD dictionary CPE and NVD configuration identities. This changes
the generated CPE set, but sbom-cve-check 1.3.3 with the pinned NVD
snapshot has no current CVE report delta.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-22 18:50:03 -07:00
Devansh Patel 26fa8b053b python3-py: correct CVE_PRODUCT mapping
The product-only "py" mapping generates a wildcard-vendor identity
instead of the exact NVD identity for the packaged pytest-dev py
source. Use "pytest:py" for its NVD dictionary CPE and configuration
matches.

This changes the generated product identity. With sbom-cve-check 1.3.3,
the current CVE report is unchanged using the pinned database snapshots;
both mappings report CVE-2020-29651 and CVE-2022-42969.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-22 18:50:03 -07:00
Devansh Patel d26cd38796 python3-simpleeval: add CVE_PRODUCT mapping
The current inherited "python:simpleeval" mapping is wrong for the
packaged danthedeckie SimpleEval source and misses its vulnerability
record.

Use "danthedeckie:simpleeval" for the source-aligned NVD dictionary
CPE, NVD configuration identity, and CNA affected-data identity.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-22 18:50:03 -07:00
Wang Mingyu fb0e8e64ff pcsc-lite: install systemd system units
pcsc-lite 2.5.0 defaults to installing systemd user units, which leaves the
package without a system-level pcscd.service while SYSTEMD_SERVICE still
enables pcscd.socket. On target systems this makes systemctl status pcscd
fail, and systemctl --user start pcscd can fail because the user unit
requires polkit.service from the user manager.

Select upstream Meson systemdunit=system so pcscd.service and pcscd.socket
are installed as system units. Keep upstream sysusers.d packaging so
systemd-sysusers can create the pcscd system user required by the
generated service and socket units.

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-22 18:50:02 -07:00
Khem Raj b31a666c34 linux-atm: Remove recipe
Linux commit 8f9616500c59 ("atm: remove orphaned uAPI for deleted drivers,
protocols and SVCs") deleted atm uAPI headers and ioctls in
linux/atmdev.h, legacy ATM drivers had been dropped from the kernel.

linux-atm is the userspace side of exactly those interfaces, so it no
longer builds once linux-libc-headers is 7.2:

  | ispl_l.l:15:10: fatal error: 'linux/atmsvc.h' file not found
  | ispl_y.y:15:10: fatal error: 'linux/atmsvc.h' file not found
  | src/test/isp.c:19:10: fatal error: 'linux/atmsvc.h' file not found
  | make[3]: *** [Makefile:589: ispl_y.o] Error 1

Remove the package

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-22 18:50:02 -07:00
Khem Raj b249fbbf1b vboxguestdrivers: fix vboxvideo build on kernels lacking drm_fb_helper_alloc_info
Now that KERN_MAJ reflects the target kernel instead of the build host's
uname -r, vboxvideo is actually built for kernels older than 7.x -- and it
does not compile against 6.18.44:

  vbox_fb.c:336:16: error: implicit declaration of function 'drm_fb_helper_alloc_info'; did you mean 'drm_fb_helper_fill_info'? [-Wimplicit-function-declaration]
  vbox_fb.c:336:14: error: assignment to 'struct fb_info *' from 'int' makes pointer from integer without a cast [-Wint-conversion]

Linux commit 63c971af4036 ("drm/fb-helper: Allocate and release fb_info in a
single place") moved the struct fb_info allocation out of the drivers and into
the DRM core, and made drm_fb_helper_alloc_info() static; drivers now find the
instance ready to use in fb_helper->info by the time their .fbdev_probe
callback runs. vbox_fb.c guards its call with RTLNX_VER_MIN(6,19,0), which is
where the change landed in mainline.

Bumping that version check is not a fix. The commit was pulled into stable as
a Stable-dep-of and therefore appears in the *middle* of several series --
v6.6.151, v6.12.103 and v6.18.44 have all dropped the declaration that
v6.6.150, v6.12.102 and v6.18.43 still carry. No LINUX_VERSION_CODE
comparison can express that, and guessing wrong the other way is worse than a
build failure: on a 6.18.0..6.18.43 kernel fb_helper->info is still NULL when
.fbdev_probe runs, so the driver would dereference NULL at runtime.

So add an escape hatch to vbox_fb.c and let the build system decide. do_compile
greps the kernel headers we are actually compiling against and passes
-DVBOX_NO_DRM_FB_HELPER_ALLOC_INFO through KCFLAGS when the declaration is
gone. KCFLAGS rather than EXTRA_CFLAGS/VBOXMOD_CFLAGS because a command-line
assignment of the latter two would clobber the include paths they carry, while
KCFLAGS is untouched by VirtualBox's makefiles and propagates cleanly into the
nested $(MAKE) -C $(KERN_DIR). Leaving the macro undefined keeps the previous
behaviour, so nothing changes for kernels that still export the function, and
7.x is unaffected -- VBOX_VIDEO_MODULE is empty there and the in-tree
drivers/gpu/drm/vboxvideo driver is used instead.

Verified on qemux86-64 against linux-yocto 6.18.44, from cleansstate:
vboxguest.ko, vboxsf.ko and vboxvideo.ko all build with no modpost warnings,
the -D reaches the vbox_fb.o compile line, kernel-module-vboxvideo ships the
module, and `nm -u vboxvideo.ko` no longer references
drm_fb_helper_alloc_info -- all 155 remaining undefined symbols are exported
by the kernel's Module.symvers.

Signed-off-by: Khem Raj <raj.khem@gmail.com>
2026-08-22 18:49:05 -07:00
Devansh Patel 43fd2c88f1 python3-filelock: set CVE_PRODUCT
The inherited python:filelock mapping does not identify the tox-dev source packaged by this recipe, so filelock CVEs are missed.

Use tox-dev:filelock to match the source identity used by NVD and CNA.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:21 -07:00
Zheng Ruoqin 90b2d0bc80 freeradius: Fix permissions after generating certificates with make
To fix Permissions denied error of certificate files

Signed-off-by: Zheng Ruoqin <zhengrq.fnst@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:21 -07:00
Ankur Tyagi 53981b6afb cockpit: add UPSTREAM_CHECK variables
Fixes:
$ devtool latest-version cockpit
...
INFO: Current version: 364
INFO: Latest version:

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:21 -07:00
Ankur Tyagi 55a3373bdc cmocka: update SRC_URI and add UPSTREAM_CHECK_TAGREGEX
Fixes:
$ devtool latest-version cmocka
...
fatal: https://git.cryptomilk.org/projects/cmocka.git/info/refs not valid: could not determine hash algorithm; is this a git repository?

INFO: Current version: 2.0.2
INFO: Latest version:

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:20 -07:00
Ankur Tyagi 0da1f93b2b uim: fix UPSTREAM_CHECK_REGEX
Fixes:
$ devtool latest-version uim
...
INFO: Current version: 1.9.6
INFO: Latest version: 11.28

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:20 -07:00
Ankur Tyagi 8bd0e695f6 onig: fix UPSTREAM_CHECK_REGEX
Fixes:
$ devtool latest-version onig
...
INFO: Current version: 6.9.10
INFO: Latest version: 11.28

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:20 -07:00
Ankur Tyagi e70d68e6c2 msktutil: fix UPSTREAM_CHECK_REGEX
Fixes:
$ devtool latest-version msktutil
...
INFO: Current version: 1.2.2
INFO: Latest version: 11.28

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:20 -07:00
Ankur Tyagi e4322952c4 librdkafka: upgrade 2.11.1 -> 2.15.0
Changelog:
https://github.com/confluentinc/librdkafka/blob/v2.15.0/CHANGELOG.md

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:19 -07:00
Ankur Tyagi 75ff2f86da librdkafka: add UPSTREAM_CHECK_GITTAGREGEX
Also include tag in the SRC_URI

Fixes:
$ devtool latest-version librdkafka
...
INFO: Current version: 2.11.1
INFO: Latest version: 64
INFO: Latest version's commit: 1f33da62396378c1f8a92ac4b8c8b4beb6b40617

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:19 -07:00
Ankur Tyagi eb5279046c libpaper: fix UPSTREAM_CHECK_REGEX
Fixes:
$ devtool latest-version libpaper
...
INFO: Current version: 2.2.8
INFO: Latest version: 11.28

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:19 -07:00
Ankur Tyagi 8f4359c9c4 libp11: upgrade 0.4.19 -> 0.4.20
Drop patch that is part of the upstream version

Changelog:
https://github.com/OpenSC/libp11/releases/tag/libp11-0.4.20

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:19 -07:00
Ankur Tyagi 852b471634 libconfuse: upgrade 3.3 -> 3.4
Drop patches that are part of the upstream version

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:18 -07:00
Ankur Tyagi 111eca9530 glaze: upgrade 8.0.0 -> 8.1.0
Changelog:
https://github.com/stephenberry/glaze/releases/tag/v8.1.0

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:18 -07:00
Ankur Tyagi b640c86ea7 freeipmi: add UPSTREAM_CHECK variables
Fixes:
$ devtool latest-version freeipmi
...
INFO: Current version: 1.6.18
INFO: Latest version:

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:18 -07:00
Ankur Tyagi 722eb15f44 exempi: add UPSTREAM_CHECK variables
Fixes:
$ devtool latest-version exempi
...
INFO: Current version: 2.6.6
INFO: Latest version:

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:18 -07:00
Ankur Tyagi b7c1c19585 cjose: upgrade 0.6.2.7 -> 0.6.2.8
Drop patch that is part of the upstream version.

Changelog:
https://github.com/OpenIDC/cjose/releases/tag/v0.6.2.8

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:17 -07:00
Ankur Tyagi 86423c8449 cabextract: add UPSTREAM_CHECK variables
Fixes:
$ devtool latest-version cabextract
...
INFO: Current version: 1.11
INFO: Latest version: 1.11-1

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:17 -07:00
Khem Raj 282f300817 python3-msgspec: add recipe
Fast serialization and validation library for JSON, MessagePack, YAML and
TOML. Added as a runtime dependency of the forthcoming python3-max recipe,
but useful on its own.

Signed-off-by: Khem Raj <raj.khem@gmail.com>
2026-08-20 19:39:15 -07:00
Jaipaul Cheernam 1a7e4f3433 libtracefs: remove recipe (moved to oe-core)
libtracefs has been imported into openembedded-core [1] as it is now
required by powertop 2.16 (upstream commit 2b133ed [2]). Remove it
from meta-oe to avoid duplicate recipes.

- This commit is depends on [1]

[1] https://lists.openembedded.org/g/openembedded-core/topic/120806764
[2] https://github.com/fenrus75/powertop/commit/2b133ed512c6852cf81cb98831bdfd585c0317bf

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 19:32:51 -07:00
Himanshu Jadon 47037e87d5 suitesparse: avoid install rpath buildpaths QA
SuiteSparse adds -Wl,-rpath=$(INSTALL_LIB) while linking shared
libraries on Linux. In the OpenEmbedded build this value can resolve to
a build or install path under TMPDIR, so installed ELF files can keep an
absolute build path and fail buildpaths QA.

The packaged libraries do not need this install-tree rpath. Runtime
resolution is handled through normal package dependencies and the target
library search path. Keep the librt link and drop only the rpath entry.

Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 11:10:54 -07:00