buildroot.git
5 years agopackage/python-psutil: bump to version 5.6.7
Asaf Kahlon [Thu, 9 Jan 2020 08:16:49 +0000 (10:16 +0200)]
package/python-psutil: bump to version 5.6.7

Signed-off-by: Asaf Kahlon <asafka7@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/zxing-cpp: bump version to 0db7f85
Peter Seiderer [Thu, 9 Jan 2020 14:32:31 +0000 (15:32 +0100)]
package/zxing-cpp: bump version to 0db7f85

- bump version to 0db7f85
- add hash for license file

Signed-off-by: Peter Seiderer <ps.report@gmx.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/zxing-cpp: disable testrunner
Peter Seiderer [Thu, 9 Jan 2020 13:21:56 +0000 (14:21 +0100)]
package/zxing-cpp: disable testrunner

In case cppunit dependency is found the testrunner is build
which needs c++11 compile support enabled, avoid by building
only libzxing and zxing targets.

Fixes:
  - http://autobuild.buildroot.net/results/f7c2c03a2b5a0147a041d873c1a36143861be764

  [ 85%] Building CXX object CMakeFiles/testrunner.dir/core/tests/src/common/BitArrayTest.cpp.o
  In file included from .../host/opt/ext-toolchain/mips64el-buildroot-linux-uclibc/include/c++/5.5.0/type_traits:35:0,
                   from .../host/mips64el-buildroot-linux-uclibc/sysroot/usr/include/cppunit/tools/StringHelper.h:7,
                   from .../host/mips64el-buildroot-linux-uclibc/sysroot/usr/include/cppunit/TestAssert.h:8,
                   from .../host/mips64el-buildroot-linux-uclibc/sysroot/usr/include/cppunit/TestCase.h:6,
                   from .../host/mips64el-buildroot-linux-uclibc/sysroot/usr/include/cppunit/TestCaller.h:5,
                   from .../host/mips64el-buildroot-linux-uclibc/sysroot/usr/include/cppunit/extensions/HelperMacros.h:9,
                   from .../build/zxing-cpp-0db7f855135222becff193671faae79c083424b6/core/tests/src/common/BitArrayTest.h:24,
                   from .../build/zxing-cpp-0db7f855135222becff193671faae79c083424b6/core/tests/src/common/BitArrayTest.cpp:21:
  .../host/opt/ext-toolchain/mips64el-buildroot-linux-uclibc/include/c++/5.5.0/bits/c++0x_warning.h:32:2: error: #error This file requires compiler and library support for the ISO C++ 2011 standard. This support must be enabled with the -std=c++11 or -std=gnu++11 compiler options.

Signed-off-by: Peter Seiderer <ps.report@gmx.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/tcpdump: remove unnecessary dependency on zlib
Mircea Gliga [Wed, 8 Jan 2020 12:08:21 +0000 (14:08 +0200)]
package/tcpdump: remove unnecessary dependency on zlib

The tcpdump package currently depends on zlib, but this is not
needed. The commit removes this non-mandatory dependency.

Signed-off-by: Mircea Gliga <gliga.mircea@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/libpcap: remove unnecessary dependency on zlib
Mircea Gliga [Wed, 8 Jan 2020 12:08:20 +0000 (14:08 +0200)]
package/libpcap: remove unnecessary dependency on zlib

The libpcap package currently depends on zlib, but this is not
needed. The commit removes this non-mandatory dependency.

Signed-off-by: Mircea Gliga <gliga.mircea@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/pugixml: bump to version 1.10
Fabrice Fontaine [Wed, 8 Jan 2020 21:50:39 +0000 (22:50 +0100)]
package/pugixml: bump to version 1.10

Update hash of license file (update in year and version)

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
5 years agopackage/libcli: bump to version 1.10.2
Fabrice Fontaine [Wed, 8 Jan 2020 21:48:26 +0000 (22:48 +0100)]
package/libcli: bump to version 1.10.2

Update hash of license file (updated LGPL-2.1:
https://github.com/dparrish/libcli/commit/41594c4284f14b828589ca0239ca29c2bdac5b96)

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
5 years agopackage/jsmn: bump to version 1.1.0
Fabrice Fontaine [Wed, 8 Jan 2020 21:44:38 +0000 (22:44 +0100)]
package/jsmn: bump to version 1.1.0

- jsmn is a single-header, header-only library since version 1.1.0 and
  https://github.com/zserge/jsmn/commit/fdcef3ebf886fa210d14956d3c068a653e76a24e
- Add hash for license file

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
5 years agopackage/mtr: bump to version 0.93
Fabrice Fontaine [Wed, 8 Jan 2020 21:42:06 +0000 (22:42 +0100)]
package/mtr: bump to version 0.93

Add hash for license file

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
5 years agopackage/libnss: fix build failure on RHEL 7 using -DLINUX
Giulio Benetti [Wed, 8 Jan 2020 17:07:44 +0000 (18:07 +0100)]
package/libnss: fix build failure on RHEL 7 using -DLINUX

NSS Makefile emits -DLINUX to OS_CFLAGS only if OS_TEST=Linux when
building for Target. But nsinstall.c is a host utility and it uses
NATIVE_FLAGS instead of OS_CFLAGS, this is why -DLINUX is not emitted.
This is necessary for the case one builds for Target OS Linux on a Host
OS that is not Linux.

After discussing upstream [*], it turned out that our current patch,
introduced with commit fe4b47a12181 (package/libnss: fix build failure
on RHEL 7) to fix the bug, is wrong. The best way to fix it is to append
-DLINUX to NATIVE_FLAGS in libnss.mk.

[*] https://bugzilla.mozilla.org/show_bug.cgi?id=1603398

So let's append -DLINUX to NATIVE_FLAGS after HOST_CFLAGS to make sure
<getopt.h> is included, since in nsintall.c it is included only if LINUX
macro is defined and this caused the build failure not finding getopt
functions and macros in some build environment(i.e. RHEL 7). On other
build environments getopt.h is indirectly included by unistd.h this is
why it worked on them.

This reverts commit fe4b47a12181b89eecb9a8e324f1ad053147f948.

Fixes:
    http://autobuild.buildroot.net/results/797/797f07ff757e7972d8c96b6a9f6abe68d17e0808/

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
[yann.morin.1998@free.fr:
  - meld the two commits into one
  - update and rearrange the commit log accordingly
]
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
5 years agopackage/perl-net-ping: remove it
Francois Perrad [Wed, 8 Jan 2020 15:10:41 +0000 (16:10 +0100)]
package/perl-net-ping: remove it

Net::Ping is a Perl core module (ie. bundled with perl)
Signed-off-by: Francois Perrad <francois.perrad@gadz.org>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
5 years agopackage/perl-mime-base64: remove it
Francois Perrad [Wed, 8 Jan 2020 15:10:40 +0000 (16:10 +0100)]
package/perl-mime-base64: remove it

MIME::Base64 is a Perl core module (ie. bundled with perl)
Signed-off-by: Francois Perrad <francois.perrad@gadz.org>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
5 years agopackage/perl-math-bigint: remove it
Francois Perrad [Wed, 8 Jan 2020 15:10:39 +0000 (16:10 +0100)]
package/perl-math-bigint: remove it

Math::BigInt is a Perl core module (ie. bundled with perl)

This package was never released with BR,
so no need to add an entry in Config.legacy

Signed-off-by: Francois Perrad <francois.perrad@gadz.org>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
5 years agopackage/perl-digest-md5: remove it
Francois Perrad [Wed, 8 Jan 2020 15:10:38 +0000 (16:10 +0100)]
package/perl-digest-md5: remove it

Digest::MD5 is a Perl core module (ie. bundled with perl)
Signed-off-by: Francois Perrad <francois.perrad@gadz.org>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
5 years agoutils/scancpan: warn when a module is a perl core module
Francois Perrad [Wed, 8 Jan 2020 15:10:37 +0000 (16:10 +0100)]
utils/scancpan: warn when a module is a perl core module

we don't want create new BR package with perl core module,
because core modules are already included in perl distribution,
and built with the BR package perl.

Signed-off-by: Francois Perrad <francois.perrad@gadz.org>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
5 years agopackage/bluez-alsa: bump to version 2.0.0
Jörg Krause [Wed, 8 Jan 2020 14:18:08 +0000 (15:18 +0100)]
package/bluez-alsa: bump to version 2.0.0

Version 2.0.0 adds support for MP3 with lame and full MPEG support with
mpg123, both optional.

Signed-off-by: Jörg Krause <joerg.krause@embedded.rocks>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
5 years agopackage/avro-c: depends on BR2_TOOLCHAIN_HAS_SYNC_4
Titouan Christophe [Thu, 2 Jan 2020 17:51:35 +0000 (18:51 +0100)]
package/avro-c: depends on BR2_TOOLCHAIN_HAS_SYNC_4

Fixes: http://autobuild.buildroot.net/results/989/989b4e8aaeff51bb5236c4b31e3783a0e07e4a82
Signed-off-by: Titouan Christophe <titouan.christophe@railnova.eu>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/python-semver: bump to version 2.9.0
Peter Korsgaard [Tue, 7 Jan 2020 09:12:44 +0000 (10:12 +0100)]
package/python-semver: bump to version 2.9.0

The license text is now included in the tarball, so add it to _LICENSE_FILES
and add a hash for it.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/alsa-lib: bump version to 1.2.1.2
Bernd Kuhls [Sat, 4 Jan 2020 19:46:00 +0000 (20:46 +0100)]
package/alsa-lib: bump version to 1.2.1.2

Switched _SITE to https.

Release notes:
https://www.alsa-project.org/wiki/Changes_v1.2.1.1_v1.2.1.2

Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/exim: fix host build
Bernd Kuhls [Sat, 4 Jan 2020 21:34:59 +0000 (22:34 +0100)]
package/exim: fix host build

Fixes:
http://autobuild.buildroot.net/results/5a7/5a765f0e65e20266c7203412a46c684a40b66ea3/

Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>
Reviewed-by: Luca Ceresoli <luca@lucaceresoli.net>
Tested-by: Luca Ceresoli <luca@lucaceresoli.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/bustle: bump to version 0.7.5
Fabrice Fontaine [Sat, 4 Jan 2020 18:45:13 +0000 (19:45 +0100)]
package/bustle: bump to version 0.7.5

- Switch homepage to https://gitlab.freedesktop.org/bustle/bustle/
- Switch site to
  https://www.freedesktop.org/software/bustle/$(BUSTLE_VERSION)
- Add hash for license file

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/samba4: do not force target python
Fabrice Fontaine [Fri, 3 Jan 2020 13:43:41 +0000 (14:43 +0100)]
package/samba4: do not force target python

Samba does not need python on the target for file server functionality.
It does need it for the Active Directory Domain Controller feature,
which is already configured in buildroot as optional and already depends
on python3 since commit 4485a75859fbae99090b065ddd7c088a65571d37.

An unnecessary target python greatly increases the size of the target
filesystem. A somewhat minimal configuration with a samba server shunk
from an 82 MB rootfs to 53 MB with this patch.

Signed-off-by: Trent Piepho <trent.piepho@synapse.com>
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agotoolchain-external: update Arm AArch64 BE toolchain 9.2-2019.12
Romain Naour [Tue, 7 Jan 2020 21:30:14 +0000 (22:30 +0100)]
toolchain-external: update Arm AArch64 BE toolchain 9.2-2019.12

Update to gcc 9.2.1, gdb 8.3.0, binutils 2.33.1.

The download url has been fixed:
https://bugs.linaro.org/show_bug.cgi?id=5529

See "Release Note":
https://developer.arm.com/open-source/gnu-toolchain/gnu-a/downloads#

Signed-off-by: Romain Naour <romain.naour@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/libinput: bump version to 1.15.0
Peter Seiderer [Wed, 8 Jan 2020 08:12:07 +0000 (09:12 +0100)]
package/libinput: bump version to 1.15.0

For details see [1].

[1] https://lists.freedesktop.org/archives/wayland-devel/2020-January/041115.html

Signed-off-by: Peter Seiderer <ps.report@gmx.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/libcurl: bump version to 7.68.0
Peter Korsgaard [Wed, 8 Jan 2020 07:41:09 +0000 (08:41 +0100)]
package/libcurl: bump version to 7.68.0

Notice that 7.68.0 includes a Windows-only security fix:

- CVE-2019-15601: SMB access smuggling via FILE URL on Windows
  https://curl.haxx.se/docs/CVE-2019-15601.html

So not applicable to Buildroot.

Update the license hash for a copyright year update:

-Copyright (c) 1996 - 2019, Daniel Stenberg, <daniel@haxx.se>, and many
+Copyright (c) 1996 - 2020, Daniel Stenberg, <daniel@haxx.se>, and many

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/jsoncpp: disable tests
Fabrice Fontaine [Wed, 8 Jan 2020 06:53:24 +0000 (07:53 +0100)]
package/jsoncpp: disable tests

Disable tests to avoid a build failure on gcc 4.8 because of
std::hexfloat added in version 1.9.2 with
https://github.com/open-source-parsers/jsoncpp/commit/638ad269e75f28f9830f7bfc01278aeaf5b00135

Fixes:
 - http://autobuild.buildroot.org/results/f816229b835f61fa3e4c84aa659d30f81191f369

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/python-nested-dict: new package
Adam Duskett [Mon, 25 Nov 2019 19:43:17 +0000 (11:43 -0800)]
package/python-nested-dict: new package

Python dictionary with automatic and arbitrary levels of nestedness.

Signed-off-by: Adam Duskett <aduskett@greenlots.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/mesa3d: fix gallium nouveau driver with gcc 4.9
Fabrice Fontaine [Sun, 29 Dec 2019 09:24:14 +0000 (10:24 +0100)]
package/mesa3d: fix gallium nouveau driver with gcc 4.9

Fixes:
 - http://autobuild.buildroot.org/results/599dc3478ed65d36fbf9f5e9625691dfa813b530

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/leveldb: fix static build with -latomic
Fabrice Fontaine [Fri, 27 Dec 2019 09:40:00 +0000 (10:40 +0100)]
package/leveldb: fix static build with -latomic

Drop workaround and use an upstreamable solution to link with -latomic

Fixes:
 - http://autobuild.buildroot.org/results/01d5a50581ac9e9b46f40e6f9665f74897db5e6f

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/leveldb: disable benchmarks and tests
Fabrice Fontaine [Fri, 27 Dec 2019 09:39:59 +0000 (10:39 +0100)]
package/leveldb: disable benchmarks and tests

Benchmarks and tests are enabled by default and benchmarks optionally
depend on sqlite

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/lvm2: install udev rules
Pascal de Bruijn [Thu, 2 Jan 2020 15:26:45 +0000 (16:26 +0100)]
package/lvm2: install udev rules

Without the device-mapper udev rules, dm devices will not get a proper
symlink like /dev/disk/by-label/LABEL, which in turn causes fstab
LABEL= mounts to fails.

And by extension causes shenanigans with systemd, where it will
unmount a manually mounted disk because it can't resolve the label.

Signed-off-by: Pascal de Bruijn <p.debruijn@unilogic.nl>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/coreutils: drop useless patch
Yann E. MORIN [Mon, 6 Jan 2020 21:23:36 +0000 (22:23 +0100)]
package/coreutils: drop useless patch

Until version 8.23, we needed to patch coreutils to ensure that options
be passed before non-options when calling help2man (during the build).
Our patch would just swap around two consecutive lines, and required
autoreconfguring and gettextising.

However, in coreutils 8.24, upstream applied a semantically equivalent
fix, but we did not notice, and we blindly fixed the patch by swapping
the previously faulty lines, even though the issue was no longer present
to begin with (if one would need an example of cargo cult, this is it).

Drop our patch, as it has not been needed for the past 4.5 years.

This means that we can also stop autoreconfiguring and gettextising.
Woot!

Rename the remaining patch.

Reported-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
Cc: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/ejabberd: add hash for license file
Johan Oudinet [Tue, 7 Jan 2020 12:18:02 +0000 (13:18 +0100)]
package/ejabberd: add hash for license file

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-*: add hash for license files
Johan Oudinet [Tue, 7 Jan 2020 12:16:02 +0000 (13:16 +0100)]
package/erlang-*: add hash for license files

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/libnss: bump to version 3.49
Giulio Benetti [Tue, 7 Jan 2020 16:27:47 +0000 (17:27 +0100)]
package/libnss: bump to version 3.49

Drop 2 upstreamed patches while bumping version.

Release notes:
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.49_release_notes

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/moarvm: bump to version 2020.01
Francois Perrad [Tue, 7 Jan 2020 19:25:18 +0000 (20:25 +0100)]
package/moarvm: bump to version 2020.01

Signed-off-by: Francois Perrad <francois.perrad@gadz.org>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agoconfigs/olimex_a20_olinuxino_lime*: bump kernel version
Francois Perrad [Tue, 7 Jan 2020 19:25:05 +0000 (20:25 +0100)]
configs/olimex_a20_olinuxino_lime*: bump kernel version

Signed-off-by: Francois Perrad <francois.perrad@gadz.org>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agoconfigs/olimex_imx233_olinuxino: bump kernel version
Francois Perrad [Tue, 7 Jan 2020 19:24:49 +0000 (20:24 +0100)]
configs/olimex_imx233_olinuxino: bump kernel version

Signed-off-by: Francois Perrad <francois.perrad@gadz.org>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agoconfigs/mx6cubox: bump kernel version
Francois Perrad [Tue, 7 Jan 2020 19:24:30 +0000 (20:24 +0100)]
configs/mx6cubox: bump kernel version

Signed-off-by: Francois Perrad <francois.perrad@gadz.org>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agoconfigs/imx6ulevk: Bump the kernel version
Fabio Estevam [Mon, 6 Jan 2020 22:46:47 +0000 (19:46 -0300)]
configs/imx6ulevk: Bump the kernel version

Bump the kernel version to 5.4.8.

Signed-off-by: Fabio Estevam <festevam@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/libselinux: fix python module install patch
Yann E. MORIN [Tue, 7 Jan 2020 17:12:48 +0000 (18:12 +0100)]
package/libselinux: fix python module install patch

Since commit 2768a0eb4 (package/libselinux: add dependency on
host-coreutils for ln --relative), we dropped a previous patch
which touched the same line, so the python module install patch
no longer applies.

Rather than drop use of ln --relative, which we now have (and
which was all that fuss was for), just drop the use of the PYCEXT
use altogether.

Fixes:
  - http://autobuild.buildroot.org/results/c8f/c8fe5b47e422bac13b4d5fa10bd1ee5218021585/ (host)
  - http://autobuild.buildroot.org/results/402/4026a34c6c096354ba99e8c202210428fa2795d2/ (target)

Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
Cc: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Cc: Adam Duskett <aduskett@gmail.com>
Cc: Clayton Shotwell <clayton.shotwell@rockwellcollins.com>
Cc: Matt Weber <matthew.weber@rockwellcollins.com>
Cc: Marcus Folkesson <marcus.folkesson@gmail.com>
reviewed-by: Adam Duskett <aduskett@gmail.com>

5 years agopackage/angularjs: bump version to 1.7.9
Ignacy Gawędzki [Mon, 6 Jan 2020 09:42:44 +0000 (10:42 +0100)]
package/angularjs: bump version to 1.7.9

Signed-off-by: Ignacy Gawędzki <ignacy.gawedzki@green-communications.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/mksh: update to version 57
Pascal de Bruijn [Mon, 6 Jan 2020 10:20:42 +0000 (11:20 +0100)]
package/mksh: update to version 57

Signed-off-by: Pascal de Bruijn <p.debruijn@unilogic.nl>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/docker-engine: fix hash of license file
Fabrice Fontaine [Mon, 6 Jan 2020 22:01:51 +0000 (23:01 +0100)]
package/docker-engine: fix hash of license file

Commit 0161899ae56d2c886df890ae352665bb07c88869 forgot to update hash of
license file (update in year):
https://github.com/docker/engine/commit/68906e6dcdd115be8b12913a7d1c4d9c4db6c495

Fixes:
 - http://autobuild.buildroot.org/results/3d1ccae5f3e4eeed9a3bf2eb29fd194b868bc0a7

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/bullet: bump to version 2.89
Romain Naour [Mon, 6 Jan 2020 21:48:55 +0000 (22:48 +0100)]
package/bullet: bump to version 2.89

https://github.com/bulletphysics/bullet3/releases/tag/2.89

Signed-off-by: Romain Naour <romain.naour@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/clang: bump to version 9.0.1
Romain Naour [Mon, 6 Jan 2020 21:47:42 +0000 (22:47 +0100)]
package/clang: bump to version 9.0.1

Go back to the github url download again.

Cc: Joseph Kogut <joseph.kogut@gmail.com>
Cc: Valentin Korenblit <valentinkorenblit@gmail.com>
Signed-off-by: Romain Naour <romain.naour@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/llvm: bump to version 9.0.1
Romain Naour [Mon, 6 Jan 2020 21:47:41 +0000 (22:47 +0100)]
package/llvm: bump to version 9.0.1

Go back to the github url download again.

See:
http://lists.llvm.org/pipermail/llvm-announce/2019-December/000086.html

Cc: Joseph Kogut <joseph.kogut@gmail.com>
Cc: Valentin Korenblit <valentinkorenblit@gmail.com>
Signed-off-by: Romain Naour <romain.naour@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/python-colorlog: bump to version 4.1.0
Joris Offouga [Mon, 6 Jan 2020 21:09:20 +0000 (22:09 +0100)]
package/python-colorlog: bump to version 4.1.0

Signed-off-by: Joris Offouga <offougajoris@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/libubootenv: bump to version cc628ee
Pierre-Jean Texier [Mon, 6 Jan 2020 19:51:40 +0000 (20:51 +0100)]
package/libubootenv: bump to version cc628ee

This includes the following changes:

cc628ee libuboot: wrap libuboot in extern "C" for C++
bf6ff63 Prepare 0.2
3393485 Fix compiler warning
8f7c00a uboot_env: fix the resarch of ubi volume

Signed-off-by: Pierre-Jean Texier <pjtexier@koncepto.io>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/libarchive: security bump to version 3.4.1
Pierre-Jean Texier [Mon, 6 Jan 2020 19:56:37 +0000 (20:56 +0100)]
package/libarchive: security bump to version 3.4.1

Fixes the following security vulnerabilities:

- CVE-2019-19221: In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c
 has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example,
 bsdtar crashes via a crafted archive.

And adds various security fixes.  For details, see :

https://github.com/libarchive/libarchive/releases/tag/v3.4.1

Also remove upstreamed patch.

Signed-off-by: Pierre-Jean Texier <pjtexier@koncepto.io>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agoDEVELOPERS: Fix warning with get-developers
Joris Offouga [Mon, 6 Jan 2020 21:43:56 +0000 (22:43 +0100)]
DEVELOPERS: Fix warning with get-developers

erlang-p1-iconv does not exist as a package in buildroot and cause warning
with get-developers :

./utils/get-developers -p erlang-p1-iconv
WARNING: 'package/erlang-p1-iconv/' doesn't match any file

Signed-off-by: Joris Offouga <offougajoris@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agotoolchain/toolchain-wrapper: handle __{BASE_,}FILE__ macro for reproducibility
Atharva Lele [Sat, 31 Aug 2019 18:01:13 +0000 (23:31 +0530)]
toolchain/toolchain-wrapper: handle __{BASE_,}FILE__ macro for reproducibility

Many tools use __FILE__ or __BASE_FILE__ for debugging and both
capture the build path. This results in non-reproducible images when
building in different directories.

If the config uses GCC 8 or above, we use -ffile-prefix-map=old=new
and let gcc take care of the path remapping in __FILE__. Since GCC
versions before v8 did not have this feature, we use an empty string
in that case, and disable the builtin-macro-redefined warning which
would otherwise trigger and cause build issues with -Werror.

Signed-off-by: Atharva Lele <itsatharva@gmail.com>
[Thomas:
 - as suggested by Arnout, use the empty string for the __FILE__ and
   __BASE_FILE__ value
 - as suggested by Romain, also handle __BASE_FILE__ in addition to
   __FILE__
 - pass -Wno-builtin-macro-redefined to avoid build errors when
   -Werror is passed]
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/mender-grubenv: fix installation with genimage.sh script
Adam Duskett [Mon, 2 Sep 2019 22:34:41 +0000 (15:34 -0700)]
package/mender-grubenv: fix installation with genimage.sh script

mender-grubenv currently has 3 problems that prevent an x86_64-efi image from
successfully being made with the genimage.sh script.

- mender-grubenv does not currently depend on Grub2.
  While Grub2 is not needed to build the mender-grubenv package, Grub2 needs
  to be built first for mender-grubenv to overwrite the default Grub2 files
  reliably.

- The MENDER_GRUBENV_ENV_DIR variable points to /boot/efi/EFI/BOOT instead of
  /boot/EFI/BOOT, which is where the Grub2 package installs the default files.
  This variable now points to the correct location.

- The Grub2 package installs images to $(BINARIES_DIR)/efi-part, which the
  mender-grubenv package currently does not do. As such; the default Grub2
  configuration file is used instead of the one provided by mender-grubenv.
  Adding a MENDER_GRUBENV_INSTALL_IMAGES_CMDS define in mender-grubenv.mk which
  copies the installed files from $(TARGET_DIR)/boot/EFI to
  $(BINARIES_DIR)/efi-part fixes this issue.

Signed-off-by: Adam Duskett <aduskett@greenlots.com>
[Thomas:
 - drop "runtime" on the depends on BR2_TARGET_GRUB2 since we now have
   a build-time dependency on it
 - explicitly copy the files installed by mender-grubenv in
   MENDER_GRUBENV_INSTALL_IMAGES_CMDS instead of blindly copying
   everything that is in $(TARGET_DIR)/boot/EFI]
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/lua-codegen: new package
Francois Perrad [Thu, 5 Sep 2019 08:08:39 +0000 (10:08 +0200)]
package/lua-codegen: new package

Signed-off-by: Francois Perrad <francois.perrad@gadz.org>
Reviewed-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/libsepol: add dependency on host-coreutils for ln --relative
Yann E. MORIN [Wed, 18 Dec 2019 20:39:07 +0000 (21:39 +0100)]
package/libsepol: add dependency on host-coreutils for ln --relative

Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
Cc: Adam Duskett <aduskett@gmail.com>
Cc: Clayton Shotwell <clayton.shotwell@rockwellcollins.com>
Cc: Matt Weber <matthew.weber@rockwellcollins.com>
Cc: Marcus Folkesson <marcus.folkesson@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/libselinux: add dependency on host-coreutils for ln --relative
Yann E. MORIN [Wed, 18 Dec 2019 20:39:06 +0000 (21:39 +0100)]
package/libselinux: add dependency on host-coreutils for ln --relative

Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
Cc: Adam Duskett <aduskett@gmail.com>
Cc: Clayton Shotwell <clayton.shotwell@rockwellcollins.com>
Cc: Matt Weber <matthew.weber@rockwellcollins.com>
Cc: Marcus Folkesson <marcus.folkesson@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/systemd: add dependency on host-coreutils
Yann E. MORIN [Wed, 18 Dec 2019 20:39:05 +0000 (21:39 +0100)]
package/systemd: add dependency on host-coreutils

This is needed as systemd has gained a dependency on realpath(1) which
was introduced in coreutils too recently for our supported distro to
have it (Ubuntu 14.04 does not have it from coreutils, although there is
a dedicated package for it).

This also means that we now have a ln that understands --relative, so we
can drop our workaround, that upstream said they would never accept
anyway [0].

[0] https://github.com/systemd/systemd/pull/5682

Fixes:
    http://autobuild.buildroot.org/results/a9a/a9a285e482285d062892bab0d1a2e2f89928c92d/
    http://autobuild.buildroot.org/results/6f5/6f5b1065859d866af6fa719f611c3ea7f4b88760/
    ...

Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
Cc: Adam Duskett <aduskett@gmail.com>
Cc: Maxime Hadjinlian <maxime.hadjinlian@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agocore/dependencies: check if we need to build our own host-coreutils
Yann E. MORIN [Wed, 18 Dec 2019 20:39:04 +0000 (21:39 +0100)]
core/dependencies: check if we need to build our own host-coreutils

Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/coreutils: introduce a host variant
Yann E. MORIN [Wed, 18 Dec 2019 20:39:03 +0000 (21:39 +0100)]
package/coreutils: introduce a host variant

More and more packages are now depending on ln --relative, some require
realpath, both of which only got introduced in "recent" versions of
coreutils; older distros had a separate realpath, though, but that is
not in the list of our required dependencies, and was not installed by
default.

So, we introduce a minimal host variant of coreutils to provide those
programs.

Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-p1-iconv: remove package
Johan Oudinet [Mon, 6 Jan 2020 16:11:15 +0000 (17:11 +0100)]
package/erlang-p1-iconv: remove package

This package was a dependency to ejabberd-18.09. It is not anymore
use by any package nor maintain upstream, so remove it.

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/ejabberd: bump to version 19.09.1
Johan Oudinet [Mon, 6 Jan 2020 16:11:14 +0000 (17:11 +0100)]
package/ejabberd: bump to version 19.09.1

There are two remainning patches to:

- change the Makefile rules so dependencies are not downloaded/compiled;
- fix ejabberd user in ejabberdctl script.

The erlang-p1-iconv package is not anymore a dependency for ejabberd.

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-p1-acme: new package
Johan Oudinet [Mon, 6 Jan 2020 16:11:13 +0000 (17:11 +0100)]
package/erlang-p1-acme: new package

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-p1-yconf: new package
Johan Oudinet [Mon, 6 Jan 2020 16:11:12 +0000 (17:11 +0100)]
package/erlang-p1-yconf: new package

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-p1-pkix: new package
Johan Oudinet [Mon, 6 Jan 2020 16:11:11 +0000 (17:11 +0100)]
package/erlang-p1-pkix: new package

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-p1-mqtree: new package
Johan Oudinet [Mon, 6 Jan 2020 16:11:10 +0000 (17:11 +0100)]
package/erlang-p1-mqtree: new package

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-idna: new package
Johan Oudinet [Mon, 6 Jan 2020 16:11:09 +0000 (17:11 +0100)]
package/erlang-idna: new package

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-jose: new package
Johan Oudinet [Mon, 6 Jan 2020 16:11:08 +0000 (17:11 +0100)]
package/erlang-jose: new package

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-base64url: new package
Johan Oudinet [Mon, 6 Jan 2020 16:11:07 +0000 (17:11 +0100)]
package/erlang-base64url: new package

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-p1-yaml: bump to version 1.0.21
Johan Oudinet [Mon, 6 Jan 2020 16:11:06 +0000 (17:11 +0100)]
package/erlang-p1-yaml: bump to version 1.0.21

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-p1-xmpp: bump to version 1.4.2
Johan Oudinet [Mon, 6 Jan 2020 16:11:05 +0000 (17:11 +0100)]
package/erlang-p1-xmpp: bump to version 1.4.2

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-p1-zlib: bump to version 1.0.6
Johan Oudinet [Mon, 6 Jan 2020 16:11:04 +0000 (17:11 +0100)]
package/erlang-p1-zlib: bump to version 1.0.6

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-p1-xml: bump to version 1.1.37
Johan Oudinet [Mon, 6 Jan 2020 16:11:03 +0000 (17:11 +0100)]
package/erlang-p1-xml: bump to version 1.1.37

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-p1-stun: bump to version 1.0.29
Johan Oudinet [Mon, 6 Jan 2020 16:11:02 +0000 (17:11 +0100)]
package/erlang-p1-stun: bump to version 1.0.29

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-p1-tls: bump to version 1.1.2
Johan Oudinet [Mon, 6 Jan 2020 16:11:01 +0000 (17:11 +0100)]
package/erlang-p1-tls: bump to version 1.1.2

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-p1-stringprep: bump to version 1.0.17
Johan Oudinet [Mon, 6 Jan 2020 16:11:00 +0000 (17:11 +0100)]
package/erlang-p1-stringprep: bump to version 1.0.17

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-p1-sip: bump to version 1.0.30
Johan Oudinet [Mon, 6 Jan 2020 16:10:59 +0000 (17:10 +0100)]
package/erlang-p1-sip: bump to version 1.0.30

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-p1-oauth2: bump to version 0.6.5
Johan Oudinet [Mon, 6 Jan 2020 16:10:58 +0000 (17:10 +0100)]
package/erlang-p1-oauth2: bump to version 0.6.5

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-p1-cache-tab: bump to version 1.0.20
Johan Oudinet [Mon, 6 Jan 2020 16:10:57 +0000 (17:10 +0100)]
package/erlang-p1-cache-tab: bump to version 1.0.20

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-eimp: bump to version 1.0.12
Johan Oudinet [Mon, 6 Jan 2020 16:10:56 +0000 (17:10 +0100)]
package/erlang-eimp: bump to version 1.0.12

While at it, add the hash file which was missing.

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-lager: bump to version 3.6.10
Johan Oudinet [Mon, 6 Jan 2020 16:10:55 +0000 (17:10 +0100)]
package/erlang-lager: bump to version 3.6.10

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agopackage/erlang-p1-utils: bump to version 1.0.16
Johan Oudinet [Mon, 6 Jan 2020 16:10:54 +0000 (17:10 +0100)]
package/erlang-p1-utils: bump to version 1.0.16

Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
5 years agoconfigs/raspberrypi0w_defconfig: fix post script args
Christopher McCrory [Fri, 3 Jan 2020 00:37:52 +0000 (00:37 +0000)]
configs/raspberrypi0w_defconfig: fix post script args

Commit ada40afb324 updated the raspberrypi*defconfigs to use
 -add-miniuart-bt-overlay instead of -add-pi3-miniuart-bt-overlay.
Update raspberrypi0w_defconfig also.

Signed-off-by: Christopher McCrory <chrismcc@gmail.com>
Reviewed-by: Peter Seiderer <ps.report@gmx.net>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
5 years agopackage/pcsc-lite: bump to version 1.8.26
Fabrice Fontaine [Fri, 3 Jan 2020 18:54:00 +0000 (19:54 +0100)]
package/pcsc-lite: bump to version 1.8.26

Remove patch (already in version) and so drop autoreconf

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/ncmpc: bump to version 0.36
Fabrice Fontaine [Fri, 3 Jan 2020 18:58:12 +0000 (19:58 +0100)]
package/ncmpc: bump to version 0.36

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/bubblewrap: bump to version 0.4.0
Fabrice Fontaine [Fri, 3 Jan 2020 19:01:53 +0000 (20:01 +0100)]
package/bubblewrap: bump to version 0.4.0

musl is supported since
https://github.com/containers/bubblewrap/commit/300da62ab6d14aaeeed20172a03090932bb23119

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/libsigrokdecode: bump to v0.5.3
Bartosz Golaszewski [Mon, 6 Jan 2020 10:01:08 +0000 (11:01 +0100)]
package/libsigrokdecode: bump to v0.5.3

Remove the patch that's now upstream.

Signed-off-by: Bartosz Golaszewski <bgolaszewski@baylibre.com>
[Peter: drop _AUTORECONF]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/libsigrok: bump to v0.5.2
Bartosz Golaszewski [Mon, 6 Jan 2020 10:01:02 +0000 (11:01 +0100)]
package/libsigrok: bump to v0.5.2

Remove the patch that's now upstream.

Signed-off-by: Bartosz Golaszewski <bgolaszewski@baylibre.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/doxygen: bump to v1.8.17
Bartosz Golaszewski [Mon, 6 Jan 2020 10:00:53 +0000 (11:00 +0100)]
package/doxygen: bump to v1.8.17

Signed-off-by: Bartosz Golaszewski <bgolaszewski@baylibre.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years ago{linux, linux-headers}: bump 4.19.x / 5.4.x series
Bernd Kuhls [Sun, 5 Jan 2020 21:39:53 +0000 (22:39 +0100)]
{linux, linux-headers}: bump 4.19.x / 5.4.x series

Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/docker-cli: security bump to 19.03.5
Christian Stewart [Tue, 3 Dec 2019 04:50:03 +0000 (20:50 -0800)]
package/docker-cli: security bump to 19.03.5

Fixes the following security vulnerabilities:

- CVE-2019-14271: In Docker 19.03.x before 19.03.1 linked against the GNU C
  Library (aka glibc), code injection can occur when the nsswitch facility
  dynamically loads a library inside a chroot that contains the contents of
  the container

Signed-off-by: Christian Stewart <christian@paral.in>
[Peter: mention security impact]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/docker-engine: security bump to 19.03.5
Christian Stewart [Tue, 3 Dec 2019 04:50:02 +0000 (20:50 -0800)]
package/docker-engine: security bump to 19.03.5

Fixes the following security vulnerabilities:

- CVE-2019-14271: In Docker 19.03.x before 19.03.1 linked against the GNU C
  Library (aka glibc), code injection can occur when the nsswitch facility
  dynamically loads a library inside a chroot that contains the contents of
  the container

Signed-off-by: Christian Stewart <christian@paral.in>
[Peter: mention security impact]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/docker-containerd: security bump to 1.2.11
Christian Stewart [Tue, 3 Dec 2019 04:50:01 +0000 (20:50 -0800)]
package/docker-containerd: security bump to 1.2.11

Fixes the following security vulnerabilities:

containerd 1.2.9/gRPC:

- CVE-2019-9512: Some HTTP/2 implementations are vulnerable to ping floods,
  potentially leading to a denial of service.  The attacker sends continual
  pings to an HTTP/2 peer, causing the peer to build an internal queue of
  responses.  Depending on how efficiently this data is queued, this can
  consume excess CPU, memory, or both

- CVE-2019-9514: Some HTTP/2 implementations are vulnerable to a reset
  flood, potentially leading to a denial of service.  The attacker opens a
  number of streams and sends an invalid request over each stream that
  should solicit a stream of RST_STREAM frames from the peer.  Depending on
  how the peer queues the RST_STREAM frames, this can consume excess memory,
  CPU, or both

- CVE-2019-9515: Some HTTP/2 implementations are vulnerable to a settings
  flood, potentially leading to a denial of service.  The attacker sends a
  stream of SETTINGS frames to the peer.  Since the RFC requires that the
  peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS
  frame is almost equivalent in behavior to a ping.  Depending on how
  efficiently this data is queued, this can consume excess CPU, memory, or
  both

containerd 1.2.10/runc:

- CVE-2019-16884: runc through 1.0.0-rc8, as used in Docker through
  19.03.2-ce and other products, allows AppArmor restriction bypass because
  libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a
  malicious Docker image can mount over a /proc director

Signed-off-by: Christian Stewart <christian@paral.in>
[Peter: mention security impact]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/runc: security bump to 1.0.0-rc9
Christian Stewart [Tue, 3 Dec 2019 04:50:00 +0000 (20:50 -0800)]
package/runc: security bump to 1.0.0-rc9

Fixes the following security vulnerability:

- CVE-2019-16884: runc through 1.0.0-rc8, as used in Docker through
  19.03.2-ce and other products, allows AppArmor restriction bypass because
  libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a
  malicious Docker image can mount over a /proc directory.

Signed-off-by: Christian Stewart <christian@paral.in>
[Peter: mention security impact]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/nano: bump version to 4.7
Bernd Kuhls [Sat, 4 Jan 2020 20:04:37 +0000 (21:04 +0100)]
package/nano: bump version to 4.7

Release notes:
4.6: https://lists.gnu.org/archive/html/info-gnu/2019-11/msg00011.html
4.7: https://lists.gnu.org/archive/html/info-gnu/2019-12/msg00005.html

Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/libmicrohttpd: bump version to 0.9.69
Bernd Kuhls [Sat, 4 Jan 2020 20:00:57 +0000 (21:00 +0100)]
package/libmicrohttpd: bump version to 0.9.69

Release notes:
https://lists.gnu.org/archive/html/info-gnu/2019-12/msg00003.html

Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/jsoncpp: bump version to 1.9.2
Bernd Kuhls [Sat, 4 Jan 2020 19:50:04 +0000 (20:50 +0100)]
package/jsoncpp: bump version to 1.9.2

Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/tvheadend: bump version
Bernd Kuhls [Sat, 4 Jan 2020 18:54:14 +0000 (19:54 +0100)]
package/tvheadend: bump version

Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/libva-utils: bump version to 2.6.0
Bernd Kuhls [Sat, 4 Jan 2020 18:45:41 +0000 (19:45 +0100)]
package/libva-utils: bump version to 2.6.0

Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/libva-intel-driver: bump version to 2.4.0
Bernd Kuhls [Sat, 4 Jan 2020 18:45:40 +0000 (19:45 +0100)]
package/libva-intel-driver: bump version to 2.4.0

Removed patch applied upstream.

Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 years agopackage/libva: bump version to 2.6.0
Bernd Kuhls [Sat, 4 Jan 2020 18:45:39 +0000 (19:45 +0100)]
package/libva: bump version to 2.6.0

Added bugfix patch to fix known issue suggested by upstream:
https://github.com/intel/libva/releases/tag/2.6.0

Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>