]> code.ossystems Code Review - openembedded-core.git/log
openembedded-core.git
5 years agocve-update-db-native: clean up JSON fetching
Ross Burton [Fri, 19 Jul 2019 20:33:19 +0000 (21:33 +0100)]
cve-update-db-native: clean up JSON fetching

Currently the code fetches the compressed JSON, writes it to a temporary file,
uncompresses that with gzip and passes the fake file object to update_db().

Instead, uncompress the gzip'd data in memory and pass the JSON directly to
update_db().

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agocve-update-db-native: improve metadata parsing
Ross Burton [Fri, 19 Jul 2019 20:33:18 +0000 (21:33 +0100)]
cve-update-db-native: improve metadata parsing

The metadata parser is fragile: first it coerces a bytes() to a str() (so the
string is b'LastModifiedDate:2019...'), assumes the first line is the date, and
then uses a regex to parse (which then includes the trailing quote as part of
the date).

Clean this up by parsing the bytes as UTF-8 (ASCII is probably fine, but this is
safer), iterate through the lines and split on colons to find the right
key/value pair.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agocve-update-db-native: use executemany() to optimise CPE insertion
Ross Burton [Fri, 19 Jul 2019 20:33:17 +0000 (21:33 +0100)]
cve-update-db-native: use executemany() to optimise CPE insertion

Instead of calling execute() repeatedly, rewrite the function to be a generator
and use executemany() for performance.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoopenssl: fix valgrind errors on v1.1.1c
Bonnans, Laurent [Fri, 19 Jul 2019 14:27:48 +0000 (14:27 +0000)]
openssl: fix valgrind errors on v1.1.1c

Running valgrind against code using Openssl v1.1.1c reports a large number of
uninitialized memory errors. This fix from upstream solves this problem.

Signed-off-by: Laurent Bonnans <laurent.bonnans@here.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agodevtool: remove temp dir in upgrade
Chen Qi [Fri, 19 Jul 2019 10:00:09 +0000 (18:00 +0800)]
devtool: remove temp dir in upgrade

For now, the temp dir is left in system, although the temporary
source directory has been cleaned up. So we clean it up too.

Signed-off-by: Chen Qi <Qi.Chen@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoruntime_test.py: use track_for_cleanup for temp dir
Chen Qi [Fri, 19 Jul 2019 10:00:08 +0000 (18:00 +0800)]
runtime_test.py: use track_for_cleanup for temp dir

Use track_for_cleanup for temp dir to avoid such temp
dir being not cleaned up when something goes wrong, e.g.,
building image failure.

Signed-off-by: Chen Qi <Qi.Chen@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agocve-update-db: actually inherit native
Ross Burton [Thu, 18 Jul 2019 20:03:59 +0000 (21:03 +0100)]
cve-update-db: actually inherit native

The recipe was called -native but didn't inherit native.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agocve-update-db-native: use os.path.join instead of +
Ross Burton [Thu, 18 Jul 2019 20:03:58 +0000 (21:03 +0100)]
cve-update-db-native: use os.path.join instead of +

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agogdb: fix CVE-2017-9778
Anuj Mittal [Fri, 19 Jul 2019 05:55:28 +0000 (13:55 +0800)]
gdb: fix CVE-2017-9778

Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agopython: include CVE patches for python-native as well
Anuj Mittal [Fri, 19 Jul 2019 05:55:27 +0000 (13:55 +0800)]
python: include CVE patches for python-native as well

Also avoids maintaining a different set of patches for both.

Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agounzip: fix CVE-2019-13232
Anuj Mittal [Fri, 19 Jul 2019 01:31:08 +0000 (09:31 +0800)]
unzip: fix CVE-2019-13232

Include the fix by Mark Adler which has also been adopted by Debian.

Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoglibc: CVE-2018-20796 is same as CVE-2019-9169
Anuj Mittal [Fri, 19 Jul 2019 01:31:07 +0000 (09:31 +0800)]
glibc: CVE-2018-20796 is same as CVE-2019-9169

See:
https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141
https://www.securityfocus.com/bid/107160

Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agorsync: fix CVEs for included zlib
Anuj Mittal [Fri, 19 Jul 2019 01:31:06 +0000 (09:31 +0800)]
rsync: fix CVEs for included zlib

rsync includes its own copy of zlib and doesn't recommend linking with
the system version [1].

Import CVE fixes that impact zlib version 1.2.8 [2] that is currently used
by rsync.

[1] https://git.samba.org/rsync.git/?p=rsync.git;a=blob;f=zlib/README.rsync
[2] https://nvd.nist.gov/vuln/search/results?form_type=Advanced&cves=on&cpe_version=cpe%3a%2fa%3agnu%3azlib%3a1.2.8

Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoiptables: Security Advisory - iptables - CVE-2019-11360
Li Zhou [Fri, 19 Jul 2019 07:35:46 +0000 (15:35 +0800)]
iptables: Security Advisory - iptables - CVE-2019-11360

Porting patch from <https://git.netfilter.org/iptables/commit/iptables/
xshared.c?id=2ae1099a42e6a0f06de305ca13a842ac83d4683e> to solve
CVE-2019-11360.

Signed-off-by: Li Zhou <li.zhou@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoltp: upgrade 20190115 -> 20190517
Yi Zhao [Fri, 19 Jul 2019 05:13:18 +0000 (13:13 +0800)]
ltp: upgrade 20190115 -> 20190517

Drop the following patches since the issues have been fixed upstream:
  0001-file01.sh-Fix-in-was-not-recognized.patch
  0001-lapi-Define-TST_ABI-32-64-to-detect-target-type.patch
  0001-syscalls-setrlimit03.c-read-proc-sys-fs-nr_open-for-.patch
  0007-fix-__WORDSIZE-undeclared-when-building-with-musl.patch
  0009-fix-redefinition-of-struct-msgbuf-error-building-wit.patch
  0021-Define-_GNU_SOURCE-for-MREMAP_MAYMOVE-definition.patch
  0023-ptrace-Use-int-instead-of-enum-__ptrace_request.patch
  0024-rt_sigaction-rt_sigprocmark-Define-_GNU_SOURCE.patch
  0026-crash01-Define-_GNU_SOURCE.patch
  0028-rt_sigaction.h-Use-sighandler_t-instead-of-__sighand.patch
  0034-periodic_output.patch
  0039-commands-ar01-Fix-for-test-in-deterministic-mode.patch
  define-sigrtmin-and-sigrtmax-for-musl.patch
  setregid01-security-string-formatting.patch

Refresh the following patches:
  0004-build-Add-option-to-select-libc-implementation.patch
  0005-kernel-controllers-Link-with-libfts-explicitly-on-mu.patch
  0008-Check-if-__GLIBC_PREREQ-is-defined-before-using-it.patch
  0018-guard-mallocopt-with-__GLIBC__.patch
  0020-getdents-define-getdents-getdents64-only-for-glibc.patch
  0035-fix-test_proc_kill-hang.patch
  0036-testcases-network-nfsv4-acl-acl1.c-Security-fix-on-s.patch
  0001-open_posix_testsuite-mmap24-2-Relax-condition-a-bit.patch
  0001-shmctl01-don-t-use-hardcoded-index-0-for-SHM_STAT-te.patch
  0001-diotest4-Let-kernel-pick-an-address-when-calling-mma.patch
  0001-getrlimit03-adjust-a-bit-of-code-to-compatiable-with.patch

Add patch:
  0006-rt_tgsigqueueinfo-disable-test-on-musl.patch

Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agosystemd-bootconf: Mark as machine specific
Ricardo Ribalda Delgado [Tue, 25 Jun 2019 07:14:42 +0000 (09:14 +0200)]
systemd-bootconf: Mark as machine specific

APPEND is usually attached to a machine. This patch avoids multiconfig
errors such as:

| NOTE: Direct dependencies are ['multiconfig:qt5022:/workdir/repo/poky/meta/recipes-core/glibc/glibc_2.29.bb:do_populate_sysroot', 'multiconfig:qt5022:virtual:native:/workdir/repo/poky/meta/recipes-devtools/pseudo/pseudo_git.bb:do_populate_sysroot', 'multiconfig:qt5022:/workdir/repo/poky/meta/recipes-devtools/quilt/quilt-native_0.65.bb:do_populate_sysroot', 'multiconfig:qt5022:/workdir/repo/poky/meta/recipes-devtools/gcc/gcc-cross_8.3.bb:do_populate_sysroot', 'multiconfig:qt5022:/workdir/repo/poky/meta/recipes-devtools/gcc/gcc-runtime_8.3.bb:do_populate_sysroot']
| NOTE: Installed into sysroot: []
| NOTE: Skipping as already exists in sysroot: ['glibc', 'pseudo-native', 'quilt-native', 'gcc-cross-x86_64', 'gcc-runtime', 'libgcc', 'linux-libc-headers', 'libtool-native', 'texinfo-dummy-native', 'libmpc-native', 'flex-native', 'automake-native', 'zlib-native', 'mpfr-native', 'gmp-native', 'binutils-cross-x86_64', 'xz-native', 'autoconf-native', 'gnu-config-native', 'gettext-minimal-native', 'm4-native']
| DEBUG: Python function extend_recipe_sysroot finished
| DEBUG: Executing shell function do_install
| install: cannot stat 'loader.conf': No such file or directory
| WARNING: exit code 1 from a shell command.
| ERROR: Function failed: do_install (log file is located at /workdir/build/tmp/work/bobcat-poky-linux/systemd-bootconf/1.00-r0/temp/log.do_install.737)
NOTE: recipe systemd-bootconf-1.00-r0: task do_install: Failed
ERROR: Task (multiconfig:qt5022:/workdir/repo/poky/meta/recipes-core/systemd/systemd-bootconf_1.00.bb:do_install) failed with exit code '1'

Signed-off-by: Ricardo Ribalda Delgado <ricardo@ribalda.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agowic: Fix (again) partition files UIDs on multi rootfs images
Ricardo Ribalda Delgado [Thu, 18 Jul 2019 13:13:56 +0000 (15:13 +0200)]
wic: Fix (again) partition files UIDs on multi rootfs images

Commit 450335ba5e73a375eb9932b4c4cf37979640dbfc copies the pseudo
database to the working directory in order to have ownership information
when the filesystem is generated.

Unfortunately this does not work anymore. The filenames on the database
are absolute and there is no information about the new directory.

Instead of fixing the database, we could redo a bit the way we patch the
fstab file. Now I am saving the old contents of fstab, modifying the
file and then reverting the changes on exit.

This is faster than the previous approach, although it can cause
indeterminism if the application is killed before finishing.

Signed-off-by: Ricardo Ribalda Delgado <ricardo@ribalda.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agocve-update-db-native: Remove hash column from database.
Pierre Le Magourou [Thu, 18 Jul 2019 12:41:19 +0000 (14:41 +0200)]
cve-update-db-native: Remove hash column from database.

djb2 hash algorithm was found to do collisions, so the database was
sometime missing data. Remove this hash mechanism, clear and populate
elements from scratch in PRODUCTS table if the current year needs an
update.

Signed-off-by: Pierre Le Magourou <pierre.lemagourou@softbankrobotics.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agocve-check: Replace CVE_CHECK_CVE_WHITELIST by CVE_CHECK_WHITELIST
Pierre Le Magourou [Thu, 18 Jul 2019 12:41:18 +0000 (14:41 +0200)]
cve-check: Replace CVE_CHECK_CVE_WHITELIST by CVE_CHECK_WHITELIST

CVE_CHECK_WHITELIST does not contain version anymore, as it was not
used. This variable should be set per recipe.

Signed-off-by: Pierre Le Magourou <pierre.lemagourou@softbankrobotics.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agosquashfs-tools: upgrade to commit f95864afe883
Ulrich Ölmann [Thu, 18 Jul 2019 11:50:39 +0000 (13:50 +0200)]
squashfs-tools: upgrade to commit f95864afe883

The master branch's current tip commit as of this writing is [1], see the
squashfs-tool's repo at [0].

Because of commits [2]-[4] which are included in the master branch three
corresponding patches are dropped as they are not needed anymore. The single
remaining patch was rebased on top of [1] to apply cleanly.

Commits [5] & [6] introduced interesting features, namely zstd support and
reproducibility of created SquashFS images. They are reflected in two new
PACKAGECONFIG options now, but only the latter ("reproducible") is appended to
the default options as OE-core does not contain a recipe to build zstd at the
moment (a working zstd recipe can be found e.g. in meta-rauc, see [7]).

[0] https://github.com/plougher/squashfs-tools.git
[1] f95864afe883 ("unsquashfs-4: Add more sanity checks + fix CVE-2015-4645/6")
[2] 46bdc1726e5a ("mksquashfs: Make a load of functions static")
[3] b0ca8a5c98ff ("pseudo.c: add explicit <sys/stat.h> include")
[4] f95864afe883 ("unsquashfs-4: Add more sanity checks + fix CVE-2015-4645/6")
[5] 6113361316d5 ("squashfs-tools: Add zstd support")
[6] e0d74d07bb35 ("Add configuration and Mksquashfs build options for
                   reproducible builds")
[7] https://layers.openembedded.org/layerindex/recipe/79049/

Signed-off-by: Ulrich Ölmann <u.oelmann@pengutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agocurl: upgrade 7.65.1 -> 7.65.2
Anuj Mittal [Thu, 18 Jul 2019 02:21:01 +0000 (10:21 +0800)]
curl: upgrade 7.65.1 -> 7.65.2

Changelog:
https://curl.haxx.se/changes.html#7_65_2

Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agodebianutils: upgrade 4.8.6.1 -> 4.8.6.3
Yi Zhao [Thu, 18 Jul 2019 08:03:24 +0000 (16:03 +0800)]
debianutils: upgrade 4.8.6.1 -> 4.8.6.3

Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoopenssl: set CVE vendor to openssl
Anuj Mittal [Thu, 18 Jul 2019 04:42:00 +0000 (12:42 +0800)]
openssl: set CVE vendor to openssl

Differentiate it from openssl gem for Ruby.

Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agolibpciaccess:upgrade 0.14 -> 0.16
Zang Ruochen [Thu, 18 Jul 2019 04:01:43 +0000 (12:01 +0800)]
libpciaccess:upgrade 0.14 -> 0.16

-Upgrade from libpciaccess_0.14.bb to libpciaccess_0.16.bb.

-libpciaccess/0004-Don-t-include-sys-io.h-on-arm.patch
 Removed since this is included in 0.16.

Signed-off-by: Zang Ruochen <zangrc.fnst@cn.fujitsu.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoxwininfo:upgrade 1.1.4 -> 1.1.5
Zang Ruochen [Thu, 18 Jul 2019 03:23:58 +0000 (11:23 +0800)]
xwininfo:upgrade 1.1.4 -> 1.1.5

-Upgrade from xwininfo_1.1.4.bb to xwininfo_1.1.5.bb.

Signed-off-by: Zang Ruochen <zangrc.fnst@cn.fujitsu.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agolibice:upgrade 1.0.9 -> 1.0.10
Zang Ruochen [Thu, 18 Jul 2019 03:12:23 +0000 (11:12 +0800)]
libice:upgrade 1.0.9 -> 1.0.10

-Upgrade from libice_1.0.9.bb to libice_1.0.10.bb.

-libice/CVE-2017-2626.patch
 Removed since this is included in 1.0.10.

Signed-off-by: Zang Ruochen <zangrc.fnst@cn.fujitsu.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agovte: upgrade 0.56.1 -> 0.56.3
Anuj Mittal [Thu, 18 Jul 2019 02:16:06 +0000 (10:16 +0800)]
vte: upgrade 0.56.1 -> 0.56.3

Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoglib-2.0: upgrade 2.60.4 -> 2.60.5
Anuj Mittal [Thu, 18 Jul 2019 02:16:05 +0000 (10:16 +0800)]
glib-2.0: upgrade 2.60.4 -> 2.60.5

Changes:
https://github.com/GNOME/glib/blob/glib-2-60/NEWS

Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agobzip2: upgrade 1.0.7 -> 1.0.8
Anuj Mittal [Thu, 18 Jul 2019 02:16:04 +0000 (10:16 +0800)]
bzip2: upgrade 1.0.7 -> 1.0.8

License-Update: Change in version and copyright year/date.

Changelog:
https://sourceware.org/git/?p=bzip2.git;a=blob;f=CHANGES

Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoqemu: fix CVE-2019-12155
Anuj Mittal [Thu, 18 Jul 2019 02:16:03 +0000 (10:16 +0800)]
qemu: fix CVE-2019-12155

Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agobinutils: CVE-2019-9070 is same as CVE-2019-9071
Anuj Mittal [Thu, 18 Jul 2019 02:16:02 +0000 (10:16 +0800)]
binutils: CVE-2019-9070 is same as CVE-2019-9071

See:

https://gcc.gnu.org/bugzilla/show_bug.cgi?id=89395

Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agodefaultsetup.conf: enable select init manager
Kai Kang [Thu, 4 Jul 2019 13:45:19 +0000 (21:45 +0800)]
defaultsetup.conf: enable select init manager

Introduce a new variable INIT_MANAGER and create 4 init-manager-*.inc
files to configure init manager settings. Available values of
INIT_MANAGER are sysvinit, systemd, mdev-busybox and a default of none.
'none' provides backwards compatibility.

The settings of various VIRTUAL-RUNTIME variables are moved into these
files from the packagegroups.

[YOCTO #13031]

[Modifications by RP for backwards compatibility]

Signed-off-by: Kai Kang <kai.kang@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agostaging: Drop clean_recipe_sysroot
Richard Purdie [Thu, 18 Jul 2019 11:46:12 +0000 (12:46 +0100)]
staging: Drop clean_recipe_sysroot

With recent changes to runqueue, this fuction is unsafe as setscene tasks can run
at the same time as normal ones and doing things before do_fetch no longer
offers any guarantees.

There is other code which cleans out things from the sysroots as tasks rerun so
we should rely upon that instead.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agopkgconf: upgrade 1.6.1 -> 1.6.3
Ross Burton [Wed, 17 Jul 2019 20:54:32 +0000 (21:54 +0100)]
pkgconf: upgrade 1.6.1 -> 1.6.3

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agopiglit: upgrade to latest revision
Ross Burton [Wed, 17 Jul 2019 20:54:31 +0000 (21:54 +0100)]
piglit: upgrade to latest revision

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agopackage_manager: Ensure the base-feed directory exists
Alistair Francis [Wed, 17 Jul 2019 20:53:40 +0000 (13:53 -0700)]
package_manager: Ensure the base-feed directory exists

Ensure that the /etc/opkg directory exists before we try to create a
file there.

Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoqemurunner.py: Be more verbose about problems
Alistair Francis [Wed, 17 Jul 2019 20:52:10 +0000 (13:52 -0700)]
qemurunner.py: Be more verbose about problems

Instead of hiding problems in the debug log let's print them as warnings
instead.

Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoopensbi: Fix installed-vs-shipped warning
Alistair Francis [Wed, 17 Jul 2019 20:51:49 +0000 (13:51 -0700)]
opensbi: Fix installed-vs-shipped warning

Fix the following warning by just deleting the files:
WARNING: opensbi-0.4-r0 do_package: QA Issue: opensbi: Files/directories were installed but not shipped in any package:
  /lib
  /lib/libsbiutils.a
  /lib/libsbi.a

Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoxkeyboard-config: remove redundant intltool dependency
Ross Burton [Wed, 17 Jul 2019 20:09:49 +0000 (21:09 +0100)]
xkeyboard-config: remove redundant intltool dependency

Upstream now uses plain gettext.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoltp: getrlimit03: adjust-a-bit-of-code-to-compatiable-with mips32
Hongzhi.Song [Wed, 17 Jul 2019 09:50:39 +0000 (02:50 -0700)]
ltp: getrlimit03: adjust-a-bit-of-code-to-compatiable-with mips32

Error info:
getrlimit03.c:104: FAIL: __NR_prlimit64(0) had rlim_cur =
ffffffffffffffff but __NR_getrlimit(0) had rlim_cur = 7fffffff

According to kernel code: [arch/mips/include/uapi/asm/resource.h]
RLIM_INFINITY is set to 0x7fffffffUL instead of ULONG_MAX on mips32.

 /*
 * SuS says limits have to be unsigned.
 * Which makes a ton more sense anyway,
 * but we keep the old value on MIPS32,
 * for compatibility:
 */
 #ifndef __mips64
 # define RLIM_INFINITY      0x7fffffffUL
 #endif

Adding conditional statement about mips to fix this.

Signed-off-by: Hongzhi.Song <hongzhi.song@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agocve-update-db-native: use SQL placeholders instead of format strings
Ross Burton [Wed, 17 Jul 2019 10:45:38 +0000 (11:45 +0100)]
cve-update-db-native: use SQL placeholders instead of format strings

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoflex: set CVE_PRODUCT to include vendor
Ross Burton [Wed, 17 Jul 2019 10:45:37 +0000 (11:45 +0100)]
flex: set CVE_PRODUCT to include vendor

There are many projects called Flex and they have CVEs, so also set the vendor
to remove these false positives.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agocve-check: allow comparison of Vendor as well as Product
Ross Burton [Wed, 17 Jul 2019 10:45:36 +0000 (11:45 +0100)]
cve-check: allow comparison of Vendor as well as Product

Some product names are too vague to be searched without also matching the
vendor, for example Flex could be the parser compiler we ship, or Adobe Flex, or
Apache Flex, or IBM Flex.

If entries in CVE_PRODUCT contain a colon then split it as vendor:product to improve the search.

Also don't use .format() to construct SQL as that can lead to security
issues. Instead, use ? placeholders and lets sqlite3 handle the escaping.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agofreetype: add --tag CC to libtool arguments
Mikko Rapeli [Wed, 17 Jul 2019 14:46:43 +0000 (17:46 +0300)]
freetype: add --tag CC to libtool arguments

Fixes build failures on aarch64:

aarch64-poky-linux-libtool: compile: unable to infer tagged configuration

Signed-off-by: Mikko Rapeli <mikko.rapeli@bmw.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agooe/copy_buildsystem: move layer into layers directory
Andrej Valek [Wed, 17 Jul 2019 13:25:44 +0000 (15:25 +0200)]
oe/copy_buildsystem: move layer into layers directory

Layers could be located outside from poky but inside the build directory.
This case should be covered in eSDK.
meta-abc
meta-def/meta-ghi
meta-def/poky
meta-def/meta-oe/meta-oe
...

It should take all enabled layers and put them into 'layers' dir during
build-time with respecting new relative path to poky.
layers/meta-abc
layers/meta-ghi
layers/poky
layers/meta-oe/meta-oe
...

Signed-off-by: Andrej Valek <andrej.valek@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agocve-check.bbclass: initialize to_append
Mikko Rapeli [Wed, 17 Jul 2019 09:08:37 +0000 (12:08 +0300)]
cve-check.bbclass: initialize to_append

Fixes build failure with core-image-minimal:

Exception: UnboundLocalError: local variable 'to_append' referenced before assignment

Signed-off-by: Mikko Rapeli <mikko.rapeli@bmw.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agobusybox: enable unicode support
Mikko Rapeli [Wed, 17 Jul 2019 09:08:36 +0000 (12:08 +0300)]
busybox: enable unicode support

While creating and deleting files with unicode or other
encodings works, it's annoying when ls and other core utils
show questionmarks instead of the unicode characters.
In 2019, it's quite common that users of embedded devices
based on yocto need unicode support. Debugging a box with
unicode encoded file names is a bit annoying when core utils
from busybox don't support them.

The unicode config fragment has the same config as Debian in their
deb and udeb builds of version 1:1.30.1-4.

If developers do not want this or other default yocto features in busybox,
or optimize the configuration for size, then they likely run a completely
custom configuration. Thus I think it's safe to enable unicode support
by default.

Signed-off-by: Mikko Rapeli <mikko.rapeli@bmw.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoed: set CVE vendor to avoid false positives
Ross Burton [Wed, 17 Jul 2019 11:03:24 +0000 (12:03 +0100)]
ed: set CVE vendor to avoid false positives

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agogit: set CVE vendor to git-scm
Ross Burton [Wed, 17 Jul 2019 11:03:23 +0000 (12:03 +0100)]
git: set CVE vendor to git-scm

There's a Jenkins plugin for Git.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoboost: set CVE vendor to Boost
Ross Burton [Wed, 17 Jul 2019 11:03:22 +0000 (12:03 +0100)]
boost: set CVE vendor to Boost

There's a Boost module for Drupal.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agosubversion: set CVE vendor to Apache
Ross Burton [Wed, 17 Jul 2019 11:03:21 +0000 (12:03 +0100)]
subversion: set CVE vendor to Apache

There's a Jenkins plugin for Subversion.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agokernel-fitimage: uboot-sign: fix missing signature
Jun Nie [Wed, 10 Jul 2019 07:10:56 +0000 (15:10 +0800)]
kernel-fitimage: uboot-sign: fix missing signature

u-boot.bin with dtb & signature should be placed in ${B} so that
it can be deployed by u-boot as expected. Otherwise, the version
without signature is installed.

Signed-off-by: Jun Nie <jun.nie@linaro.org>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agopython3: upgrade 3.7.3 -> 3.7.4
Anuj Mittal [Wed, 17 Jul 2019 03:04:08 +0000 (11:04 +0800)]
python3: upgrade 3.7.3 -> 3.7.4

Also fixes CVE-2019-9740, CVE-2019-9948. For details, see:

https://docs.python.org/3.7/whatsnew/changelog.html#python-3-7-4-final

Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agopython: fix CVE-2019-9740
Anuj Mittal [Wed, 17 Jul 2019 03:04:07 +0000 (11:04 +0800)]
python: fix CVE-2019-9740

Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agowic: add support for kernel with initramfs bundled
Chee Yang Lee [Wed, 17 Jul 2019 02:02:42 +0000 (10:02 +0800)]
wic: add support for kernel with initramfs bundled

when INITRAMFS_IMAGE_BUNDLE and INITRAMFS_IMAGE are set, wic should
look for kernel with initramfs image bundled.

Include required variable MACHINE, INITRAMFS_IMAGE_BUNDLE,
INITRAMFS_IMAGE, INITRAMFS_LINK_NAME and KERNEL_IMAGETYPE in WICVARS.
No longer require default value for variable kernel as KERNEL_IMAGETYPE
is not optional variable and included in WICVARS.
image_types_wic to inherit kernel-artifact-names to obtain default
INITRAMFS_LINK_NAME when INITRAMFS_IMAGE_BUNDLE are set.

update wic.Wic2.test_image_env test case to filter optional
variable INITRAMFS_LINK_NAME, INITRAMFS_IMAGE and INITRAMFS_IMAGE_BUNDLE.

Signed-off-by: Chee Yang Lee <chee.yang.lee@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agonasm: fix CVE-2018-19755
Anuj Mittal [Wed, 17 Jul 2019 00:49:37 +0000 (08:49 +0800)]
nasm: fix CVE-2018-19755

Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoopkg/package/rootfs_ipk: allow overwriting OPKGLIBDIR
Adrian Ratiu [Tue, 16 Jul 2019 21:55:58 +0000 (00:55 +0300)]
opkg/package/rootfs_ipk: allow overwriting OPKGLIBDIR

Some distributions for various reasons (like for example mounting a
tmpfs over /var at runtime) can't use /var/lib to store the opkg
metadata, so a different path is required to have a functioning
package manager.

${localstatedir} can't be modified to something other than the
hardcoded value in bitbake.conf because other recipes depending on it
will fail to install.

So the only recourse, which is also the least invasive, is to allow
distros to overwrite the OPKGLIBDIR variable just like they are also
allowed to overwrite OPKGBUILDCMD.

Signed-off-by: Adrian Ratiu <adrian.ratiu@collabora.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agolibid3tag: handle unknown encodings (CVE-2017-11550)
Ross Burton [Tue, 16 Jul 2019 12:47:39 +0000 (13:47 +0100)]
libid3tag: handle unknown encodings (CVE-2017-11550)

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agolibid3tag: CVE-2017-11551 is the same as CVE-2004-2779
Ross Burton [Tue, 16 Jul 2019 12:47:27 +0000 (13:47 +0100)]
libid3tag: CVE-2017-11551 is the same as CVE-2004-2779

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoglibc: exclude child recipes from CVE scanning
Ross Burton [Tue, 16 Jul 2019 12:47:21 +0000 (13:47 +0100)]
glibc: exclude child recipes from CVE scanning

As glibc will be scanned for CVEs, we don't need to scan glibc-locale,
glibc-mtrace, and glibc-scripts which are all separate recipes for technical
reasons.

Exclude the recipes by setting CVE_PRODUCT in the recipe, instead of using the
global whitelist.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agocve-check-tool: remove
Ross Burton [Tue, 16 Jul 2019 12:46:50 +0000 (13:46 +0100)]
cve-check-tool: remove

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agocve-check: remove redundant readline CVE whitelisting
Ross Burton [Tue, 16 Jul 2019 12:46:43 +0000 (13:46 +0100)]
cve-check: remove redundant readline CVE whitelisting

CVE-2014-2524 is a readline CVE that was fixed in 6.3patch3 onwards, but the
tooling wasn't able to detect this version.  As we now ship readline 8 we don't
need to manually whitelist it, and if we did then the whitelisting should be in
the readline recipe.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agosystemd: Fix interface bring-up on kernels >= 5.2
Ricardo Ribalda Delgado [Mon, 15 Jul 2019 14:32:52 +0000 (16:32 +0200)]
systemd: Fix interface bring-up on kernels >= 5.2

With kernels >=5.2  systemd-networkd is unable to bring up the link.

eth0: Could not bring up interface: Invalid argument

This is already reported upstream and fixed on master:

https://github.com/systemd/systemd/issues/12784

They recommend Debian to backport two patches.

Signed-off-by: Ricardo Ribalda Delgado <ricardo@ribalda.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agomdadm: make ptest output format align with common style
Changqing Li [Tue, 16 Jul 2019 03:48:42 +0000 (11:48 +0800)]
mdadm: make ptest output format align with common style

Signed-off-by: Changqing Li <changqing.li@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoopkg: make ptest output format align with common style
Changqing Li [Tue, 16 Jul 2019 03:48:41 +0000 (11:48 +0800)]
opkg: make ptest output format align with common style

Signed-off-by: Changqing Li <changqing.li@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoscripts/buildstats-diff: Add option to filter tasks
Joshua Watt [Mon, 15 Jul 2019 15:47:33 +0000 (10:47 -0500)]
scripts/buildstats-diff: Add option to filter tasks

Adds a command line option to filter out the buildstats-diff report by
one more more tasks. e.g.:

 buildstats-diff --only-task do_compile A B

will only show the differences for do_compile tasks. The --only-task
option can be specified multiple times to filter out multiple tasks at
once.

Signed-off-by: Joshua Watt <JPEWhacker@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agonfs-mountd: Add missing dependency on systemd service
Ricardo Ribalda Delgado [Mon, 15 Jul 2019 14:14:58 +0000 (16:14 +0200)]
nfs-mountd: Add missing dependency on systemd service

As described on: https://www.spinics.net/lists/linux-nfs/msg62022.html

mountd requires rpcbind, otherwise it can can fail to start, which can
lead to nfsroot not booting.

Upstream: http://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=907426b00bdcd69d9a56ac1870990e8ae8c6fe9f

Signed-off-by: Ricardo Ribalda Delgado <ricardo@ribalda.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agowebkitgtk: set incomptible with tune mips
Kai Kang [Mon, 15 Jul 2019 10:20:16 +0000 (06:20 -0400)]
webkitgtk: set incomptible with tune mips

It fails to compile webkit when default tune is 'mips':

| .../tmp-glibc/work/mips-wrs-linux/webkitgtk/2.24.2-r0/webkitgtk-2.24.2
| /Source/JavaScriptCore/assembler/MacroAssemblerMIPS.h:418:23:
| error: static assertion failed: CLZ opcode is not available for this ISA

So don't build webkit when default tune is mips.

Signed-off-by: Kai Kang <kai.kang@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agodevtool: provide support for devtool menuconfig command
Sai Hari Chandana Kalluri [Wed, 10 Jul 2019 18:27:34 +0000 (11:27 -0700)]
devtool: provide support for devtool menuconfig command

All packages that support the menuconfig task will be able to run
devtool menuconfig command. This would allow the user to modify the
current configure options and create a config fragment which can be
added to a recipe using devtool finish.

1. The patch checks if devtool menuconfig command is called for a valid
package.
2. It checks for oe-local-files dir within source and creates one if
needed, this directory is needed to store the final generated config
fragment so that devtool finish can update the recipe.
3. Menuconfig command is called for users to make necessary changes.
After saving the changes, diffconfig command is run to generate the
fragment.

Syntax:
devtool menuconfig <package name>
 Ex: devtool menuconfig linux-yocto

The config fragment is saved as devtool-fragment.cfg within
oe-local-files dir.

Ex:
<workspace_path>/sources/linux-yocto/oe-local-files/devtool-fragment.cfg

Run devtool finish to update the recipe by appending the config fragment
to SRC_URI and place a copy of the fragment within the layer where the
recipe resides.
Ex: devtool finish linux-yocto meta

[YOCTO #10416]

Signed-off-by: Sai Hari Chandana Kalluri <chandana.kalluri@xilinx.com>
Signed-off-by: Alejandro Enedino Hernandez Samaniego <alejandr@xilinx.com>
Signed-off-by: Paul Eggleton <paul.eggleton@linux.intel.com>
5 years agodevtool/standard.py: Create a copy of kernel source within work-shared if not present
Sai Hari Chandana Kalluri [Wed, 10 Jul 2019 18:27:33 +0000 (11:27 -0700)]
devtool/standard.py: Create a copy of kernel source within work-shared if not present

If kernel source is not already downloaded i.e staging kernel dir is
empty, place a copy of the source when the user runs devtool modify
linux-yocto.  This way the kernel source is available for other packages
that use it.

[YOCTO #10416]

Signed-off-by: Sai Hari Chandana Kalluri <chandana.kalluri@xilinx.com>
Signed-off-by: Alejandro Enedino Hernandez Samaniego <alejandr@xilinx.com>
Signed-off-by: Paul Eggleton <paul.eggleton@linux.intel.com>
5 years agodevtool/standard.py: Update devtool modify to copy source from work-shared if its...
Sai Hari Chandana Kalluri [Wed, 10 Jul 2019 18:27:32 +0000 (11:27 -0700)]
devtool/standard.py: Update devtool modify to copy source from work-shared if its already downloaded

In the regular devtool modify flow, the kernel source is fetched by
running do_fetch task. This is an overhead in time and space.

This patch updates modify command to check if the kernel source is
already downloaded. If so, then instead of calling do_fetch, copy the
source from work-shared to devtool workspace by creating hard links
else run the usual devtool modify flow and call do_fetch task.

[YOCTO #10416]

Signed-off-by: Sai Hari Chandana Kalluri <chandana.kalluri@xilinx.com>
Signed-off-by: Alejandro Enedino Hernandez Samaniego <alejandr@xilinx.com>
Signed-off-by: Paul Eggleton <paul.eggleton@linux.intel.com>
5 years agotimezone: update to 2019b
Armin Kuster [Sun, 14 Jul 2019 16:53:45 +0000 (09:53 -0700)]
timezone: update to 2019b

Briefly:
  Brazil no longer observes DST.
  'zic -b slim' outputs smaller TZif files; please try it out.
  Palestine's 2019 spring-forward transition was on 03-29, not 03-30.

Changes to future timestamps

  Brazil has canceled DST and will stay on standard time indefinitely.
  (Thanks to Steffen Thorsen, Marcus Diniz, and Daniel Soares de
  Oliveira.)

  Predictions for Morocco now go through 2087 instead of 2037, to
  work around a problem on newlib when using TZif files output by
  zic 2019a or earlier.  (Problem reported by David Gauchard.)

Changes to past and future timestamps

  Palestine's 2019 spring transition was 03-29 at 00:00, not 03-30
  at 01:00.  (Thanks to Sharef Mustafa and Even Scharning.)  Guess
  future transitions to be March's last Friday at 00:00.

Changes to past timestamps

  Hong Kong's 1941-06-15 spring-forward transition was at 03:00, not
  03:30.  Its 1945 transition from JST to HKT was on 11-18 at 02:00,
  not 09-15 at 00:00.  In 1946 its spring-forward transition was on
  04-21 at 00:00, not the previous day at 03:30.  From 1946 through
  1952 its fall-back transitions occurred at 04:30, not at 03:30.
  In 1947 its fall-back transition was on 11-30, not 12-30.
  (Thanks to P Chan.)

Changes to past time zone abbreviations

  Italy's 1866 transition to Rome Mean Time was on December 12, not
  September 22.  This affects only the time zone abbreviation for
  Europe/Rome between those dates.  (Thanks to Stephen Trainor and
  Luigi Rosa.)

Changes affecting metadata only

  Add info about the Crimea situation in zone1970.tab and zone.tab.
  (Problem reported by Serhii Demediuk.)

Changes to code

  zic's new -b option supports a way to control data bloat and to
  test for year-2038 bugs in software that reads TZif files.
  'zic -b fat' and 'zic -b slim' generate larger and smaller output;
  for example, changing from fat to slim shrinks the Europe/London
  file from 3648 to 1599 bytes, saving about 56%.  Fat and slim
  files represent the same set of timestamps and use the same TZif
  format as documented in tzfile(5) and in Internet RFC 8536.
  Fat format attempts to work around bugs or incompatibilities in
  older software, notably software that mishandles 64-bit TZif data
  or uses obsolete TZ strings like "EET-2EEST" that lack DST rules.
  Slim format is more efficient and does not work around 64-bit bugs
  or obsolete TZ strings.  Currently zic defaults to fat format
  unless you compile with -DZIC_BLOAT_DEFAULT=\"slim\"; this
  out-of-the-box default is intended to change in future releases
  as the buggy software often mishandles timestamps anyway.

  zic no longer treats a set of rules ending in 2037 specially.
  Previously, zic assumed that such a ruleset meant that future
  timestamps could not be predicted, and therefore omitted a
  POSIX-like TZ string in the TZif output.  The old behavior is no
  longer needed for current tzdata, and caused problems with newlib
  when used with older tzdata (reported by David Gauchard).

  zic no longer generates some artifact transitions.  For example,
  Europe/London no longer has a no-op transition in January 1996.

Changes to build procedure

  tzdata.zi now assumes zic 2017c or later.  This shrinks tzdata.zi
  by a percent or so.

Changes to documentation and commentary

  The Makefile now documents the POSIXRULES macro as being obsolete,
  and similarly, zic's -p POSIXRULES option is now documented as
  being obsolete.  Although the POSIXRULES feature still exists and
  works as before, in practice it is rarely used for its intended
  purpose, and it does not work either in the default reference
  implementation (for timestamps after 2037) or in common
  implementations such as GNU/Linux (for contemporary timestamps).
  Since POSIXRULES was designed primarily as a temporary transition
  facility for System V platforms that died off decades ago, it is
  being decommissioned rather than institutionalized.

  New info on Bonin Islands and Marcus (thanks to Wakaba and Phake
  Nick).

Signed-off-by: Armin Kuster <akuster808@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agosystemd: backport patch to fix sysctl warning on boot
Matthias Schiffer [Wed, 10 Jul 2019 12:13:53 +0000 (14:13 +0200)]
systemd: backport patch to fix sysctl warning on boot

Due to improved validation of sysctl settings in recent kernels (5.2+, but
also stable kernels like 4.19.53), systemd will log an error message like

    systemd[1]: Failed to bump fs.file-max, ignoring: Invalid argument

during boot. Backport the bugfix from the systemd master.

Signed-off-by: Matthias Schiffer <matthias.schiffer@ew.tq-group.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agorootfs-postcommands: Cope with empty IMAGE_LINK_NAME in write_image_test_data
Mike Crowe [Mon, 15 Jul 2019 12:51:00 +0000 (13:51 +0100)]
rootfs-postcommands: Cope with empty IMAGE_LINK_NAME in write_image_test_data

Ensure that we don't create an image test data symlink named
".testdata.json" when IMAGE_LINK_NAME is empty.

Signed-off-by: Mike Crowe <mac@mcrowe.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agorootfs-postcommands: Cope with empty IMAGE_LINK_NAME in write_image_manifest
Mike Crowe [Mon, 15 Jul 2019 12:50:59 +0000 (13:50 +0100)]
rootfs-postcommands: Cope with empty IMAGE_LINK_NAME in write_image_manifest

Ensure that we don't create a symlink named ".manifest" if IMAGE_LINK_NAME
is empty.

Signed-off-by: Mike Crowe <mac@mcrowe.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agonativesdk-meson: Remove some unused variables
Peter Kjellerstedt [Mon, 15 Jul 2019 11:25:49 +0000 (13:25 +0200)]
nativesdk-meson: Remove some unused variables

Signed-off-by: Peter Kjellerstedt <peter.kjellerstedt@axis.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agomeson.bbclass: Remove the MESON_*_ARGS variables
Peter Kjellerstedt [Mon, 15 Jul 2019 11:25:48 +0000 (13:25 +0200)]
meson.bbclass: Remove the MESON_*_ARGS variables

The options in ${HOST_CC_ARCH}${TOOLCHAIN_OPTIONS} are already passed
via ${CC}/${CXX} and there is no reason to pass them a second time. Thus
we can remove MESON_TOOLCHAIN_ARGS. And when it is removed, the other
MESON_*_ARGS variables revert to the standard CFLAGS, CXXFLAGS and
LDFLAGS, so just use them directly instead.

Apart from the obvious improvement with not passing a lot of options
twice, this also solves a problem where -pie would be passed on the
command line in a way that it would prevent building any dynamic
libraries using meson if using a toolchain that is not built with
--enable-default-pie and if security_flags.inc is used.

Signed-off-by: Peter Kjellerstedt <peter.kjellerstedt@axis.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agotiff: fix CVE-2019-7663
Ross Burton [Mon, 15 Jul 2019 11:04:13 +0000 (12:04 +0100)]
tiff: fix CVE-2019-7663

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agotiff: fix CVE-2019-6128
Ross Burton [Mon, 15 Jul 2019 11:04:12 +0000 (12:04 +0100)]
tiff: fix CVE-2019-6128

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agotiff: remove redundant patch
Ross Burton [Mon, 15 Jul 2019 11:04:11 +0000 (12:04 +0100)]
tiff: remove redundant patch

The patching to make the new libtool work (from 2008) is no longer needed.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoe2fsprogs: Remove patch that disabled 64bit for ext4 by default
Adrian Bunk [Sun, 14 Jul 2019 09:48:49 +0000 (12:48 +0300)]
e2fsprogs: Remove patch that disabled 64bit for ext4 by default

OE no longer ships a git snapshot of e2fsprogs,
so use the new upstream default now.

Signed-off-by: Adrian Bunk <bunk@stusta.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoxauth:upgrade 1.0.10 -> 1.1
Zang Ruochen [Mon, 15 Jul 2019 06:23:28 +0000 (14:23 +0800)]
xauth:upgrade 1.0.10 -> 1.1

-Upgrade from xauth_1.0.10.bb to xauth_1.1.bb.

Signed-off-by: Zang Ruochen <zangrc.fnst@cn.fujitsu.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoiproute2: update to 5.2.0
Oleksandr Kravchuk [Mon, 15 Jul 2019 02:33:37 +0000 (04:33 +0200)]
iproute2: update to 5.2.0

Signed-off-by: Oleksandr Kravchuk <open.source@oleksandr-kravchuk.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agomsmtp: use alternatives to manage /usr/lib/sendmail
Chen Qi [Mon, 15 Jul 2019 08:35:38 +0000 (16:35 +0800)]
msmtp: use alternatives to manage /usr/lib/sendmail

There are several packages which all provide /usr/lib/sendmail
when lsb is enabled. So use alternative to manage it.

Signed-off-by: Chen Qi <Qi.Chen@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agomdadm: fix ptest hang
Mingli Yu [Mon, 15 Jul 2019 08:56:18 +0000 (16:56 +0800)]
mdadm: fix ptest hang

Before commit[80d17497b7 mdadm: improve the run-ptest],
the mdadm ptest just run some tests without
"--keep-going" option. After the option added in
commit 80d17497b7, all test cases have chance to
be called.

But the logic in mdadm upstream commit
[e2a8e9d tests: wait for complete rebuild in integrity checks]
will make the test enter infinite loop especially in
qemu env as commit e2a8e9d update the logic from
"check wait" to "check state 'U*'" for testcase
tests/01r5integ and tests/01raid6integ. Considering all
other cases still use "check wait" logic, so revert e2a8e9d
to make tests/01r5integ and tests/01raid6integ also use
"check wait" logic to avoid the infinite loop.

[YOCTO #13368]

Signed-off-by: Mingli Yu <Mingli.Yu@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoclasses/icecc: Disable remote pre-processing by default
Joshua Watt [Fri, 12 Jul 2019 16:21:14 +0000 (11:21 -0500)]
classes/icecc: Disable remote pre-processing by default

Unfortunately, GCC has a number of outstanding bugs related to using
-fdirectives-only, which causes a lot of errors when using Icecream.
See:

https://gcc.gnu.org/bugzilla/show_bug.cgi?id=47254
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88475
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=89658
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=91152

Until many of these are addressed, it is better to disable remote
preprocessing.

Signed-off-by: Joshua Watt <JPEWhacker@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoninja: use Python 3
Ross Burton [Thu, 11 Jul 2019 23:54:23 +0000 (00:54 +0100)]
ninja: use Python 3

As part of the mission to remove the use of Python 2, explicitly bootstrap Ninja
with Python 3.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoqemu: use Python 3 to build
Ross Burton [Thu, 11 Jul 2019 23:54:31 +0000 (00:54 +0100)]
qemu: use Python 3 to build

As part of the mission to remove the use of Python 2, explicitly use Python 3
when building qemu.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agogrub: build with python 3
Ross Burton [Thu, 11 Jul 2019 23:54:27 +0000 (00:54 +0100)]
grub: build with python 3

As part of the mission to remove the use of Python 2, explicitly use Python 3
when building grub.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agolibpsl: update Upstream-Status
Ross Burton [Thu, 11 Jul 2019 23:54:15 +0000 (00:54 +0100)]
libpsl: update Upstream-Status

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agometa: Remove remnants of bluez4 support
Adrian Bunk [Fri, 12 Jul 2019 07:48:13 +0000 (10:48 +0300)]
meta: Remove remnants of bluez4 support

bluez4 was removed from meta-oe 2 years ago.

Simplfy the setup of the two level bluetooth and bluez4/bluez5
distro features by removing the bluez4/bluez5 distro features.

This also removes the no longer required bluetooth class.

Signed-off-by: Adrian Bunk <bunk@stusta.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoqemurunner.py: fix race condition at qemu startup
Chen Qi [Fri, 12 Jul 2019 07:31:13 +0000 (15:31 +0800)]
qemurunner.py: fix race condition at qemu startup

When handling pid file, qemu would first create the file, stat it,
lock it and then write actually contents to it.

So it's possbile that when reading the pid file, the content is empty.

[YOCTO #13390]

Signed-off-by: Chen Qi <Qi.Chen@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agooeqa/runtime/rpm: Move test_rpm_query_nonroot test case to RpmBasicTest
Chen Qi [Fri, 12 Jul 2019 08:55:28 +0000 (16:55 +0800)]
oeqa/runtime/rpm: Move test_rpm_query_nonroot test case to RpmBasicTest

The test_rpm_query_nonroot test case was in RpmInstallRemoveTest.
But it should logically belong to RpmBasicTest. So move it there.

Signed-off-by: Chen Qi <Qi.Chen@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agooeqa/runtime/rpm: ensure no user process running before deleting user
Chen Qi [Fri, 12 Jul 2019 08:55:27 +0000 (16:55 +0800)]
oeqa/runtime/rpm: ensure no user process running before deleting user

In case of systemd, `su -c 'xxx' test1' via ssh will create
several processes owned by test1, e.g. /lib/system/systemd --user.

These processes are actually managed by user@UID.service
(e.g. user@1000.service). And such service is managed
automatically by systemd. In other words, it will be cleaned
up by systemd automatically.

So we need to wait for systemd to clean it up before trying to
use `userdel' to delete the user.

Signed-off-by: Chen Qi <Qi.Chen@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoglibc-package.inc: Do not use bitbake variable syntax for shell variables
Peter Kjellerstedt [Fri, 12 Jul 2019 10:13:16 +0000 (12:13 +0200)]
glibc-package.inc: Do not use bitbake variable syntax for shell variables

Using bitbake variable syntax (i.e., ${FOO}) for shell variables is
bad practice. First of all it is confusing, but more importantly it
can lead to weird problems if someone actually defines a bitbake
variable with the same name as the shell variable.

Also correct the indentation in stash_locale_cleanup().

Signed-off-by: Peter Kjellerstedt <peter.kjellerstedt@axis.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agosysstat: Use sysstat.service in source for cron with systemd
Haiqing Bai [Fri, 12 Jul 2019 12:49:26 +0000 (13:49 +0100)]
sysstat: Use sysstat.service in source for cron with systemd

The sysstat.service script in source launchs sysstat-collect and sysstat-summary
services when cron is installed with systemd. At this time, the upstream
sysstat.service must be installed.

Signed-off-by: Haiqing Bai <Haiqing.Bai@windriver.com>
Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agoRevert "sysstat: use service file from source codes"
Ross Burton [Fri, 12 Jul 2019 12:49:25 +0000 (13:49 +0100)]
Revert "sysstat: use service file from source codes"

This doesn't actually work as the unit file is only installed if cron support is
enabled.

This reverts commit 721f09d4897425c7131470bd756eee1b90937feb.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agosstate: Add tweak to avoid multiple sstate stats messages
Richard Purdie [Fri, 12 Jul 2019 12:54:19 +0000 (13:54 +0100)]
sstate: Add tweak to avoid multiple sstate stats messages

After the recent changes in bitbake to runqueue, we need to recheck sstate validity,
particularly in multiconfig builds where tasks have the same checksum.

Avoid printing summary messages in this case. Also avoid multiple events to toaster
which may not be expecting that at later points in the code.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agonss: Upgrade 3.44.1 -> 3.45
Zang Ruochen [Thu, 11 Jul 2019 06:53:33 +0000 (14:53 +0800)]
nss: Upgrade 3.44.1 -> 3.45

Upgrade from nss_3.44.1.bb to nss_3.45.bb.

Signed-off-by: Zang Ruochen <zangrc.fnst@cn.fujitsu.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
5 years agosqlite3: Upgrade 3.28.0 -> 3.29.0
Zang Ruochen [Thu, 11 Jul 2019 05:18:56 +0000 (13:18 +0800)]
sqlite3: Upgrade 3.28.0 -> 3.29.0

Upgrade from sqlite3_3.28.0.bb to sqlite3_3.29.0.bb.

Signed-off-by: Zang Ruochen <zangrc.fnst@cn.fujitsu.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>