James Hilliard
9eeca607ba
package/python{3}-setuptools: bump to version 41.4.0
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:46:09 +02:00
Peter Korsgaard
505a70edbe
package/gd: add post-2.2.5 security fixes from upstream
...
Fixes the following security vulnerablities:
- CVE-2018-1000222: Libgd version 2.2.5 contains a Double Free Vulnerability
vulnerability in gdImageBmpPtr Function that can result in Remote Code
Execution . This attack appear to be exploitable via Specially Crafted
Jpeg Image can trigger double free
- CVE-2018-5711: gd_gif_in.c in the GD Graphics Library (aka libgd), as used
in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x
before 7.2.1, has an integer signedness error that leads to an infinite
loop via a crafted GIF file, as demonstrated by a call to the
imagecreatefromgif or imagecreatefromstring PHP function
- CVE-2019-11038: When using the gdImageCreateFromXbm() function in the GD
Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP
versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it
is possible to supply data that will cause the function to use the value
of uninitialized variable. This may lead to disclosing contents of the
stack that has been left there by previous code
- CVE-2019-6978: The GD Graphics Library (aka LibGD) 2.2.5 has a double free
in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:45:31 +02:00
Petr Vorel
e1281472ec
package/ltp-testsuite: enable build under musl
...
This requires to remove a lot of broken code until it's fixed in upstream.
Added 2 patches from upcoming release.
Signed-off-by: Petr Vorel <petr.vorel@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:44:22 +02:00
Fabrice Fontaine
d17f54af03
package/boost: fix build with python 3.8
...
Fixes:
- http://autobuild.buildroot.org/results/81489f92ceb6287a4d6c52b2bb16a80e8c5c430a
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:43:56 +02:00
Bernd Kuhls
6c480d40f0
package/tvheadend: bump version
...
Rebased patch.
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:40:56 +02:00
Peter Seiderer
d0f3c9de49
package/libv4l: bump version to 1.18.0
...
- remove 0001-fixup-lfs-mismatch-in-preload-libraries.patch
(Upstream applied [1])
- remove 0002-keytable-fix-EVIOCSCLOCKID-related-compile-failure.patch
(Upstream applied [2])
- remove 0003-Build-sdlcam-only-if-jpeg-is-enabled.patch
(Upstream applied [3])
- remove 0004-v4l2-compliance-needs-fork.patch
(Upstream applied [4])
Despite all patches (specially the ones touching
configure.ac/Makefile.am) keep LIBV4L_AUTORECONF = YES to get correct
utils/qv4l linker flags (seems the original debian based libtool sets
a wrong link_all_deplibs parameter), see [5] for details.
[1] https://git.linuxtv.org/v4l-utils.git/commit/?id=9f0354c3320f3cc62983f726bfed66e1d0c21f83
[2] https://git.linuxtv.org/v4l-utils.git/commit/?id=a3367e92f4b06667a36fb9485f22f7df52891a2f
[3] https://git.linuxtv.org/v4l-utils.git/commit/?id=692c2f0f35dd663e84d363867f2841d387726154
[4] https://git.linuxtv.org/v4l-utils.git/commit/?id=577ab225929c4e8dce7d2b911eeed38469a559bb
[5] http://lists.busybox.net/pipermail/buildroot/2019-October/261558.html
Signed-off-by: Peter Seiderer <ps.report@gmx.net >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:38:12 +02:00
Bernd Kuhls
c953eadafc
package/nano: bump version to 4.5
...
Release notes:
https://lists.gnu.org/archive/html/info-gnu/2019-10/msg00001.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:36:51 +02:00
Bernd Kuhls
134b9518ff
package/screen: bump version to 4.7.0
...
Release notes:
https://lists.gnu.org/archive/html/info-gnu/2019-10/msg00000.html
Removed patches applied upstream:
- 0001-compiler-sanity-checks.patch
https://git.savannah.gnu.org/cgit/screen.git/commit/?h=v.4.7.0&id=6b320186db7df1e58fdd2c836af54c86cc596981
- 0003-cross-compilation-AC_TRY_RUN.patch
https://git.savannah.gnu.org/cgit/screen.git/commit/?h=v.4.7.0&id=abba47ce4206506c49858d944e904fff86ae65cc
- 0004-cross-compilation-ignore-host-fs.patch
https://git.savannah.gnu.org/cgit/screen.git/commit/?h=v.4.7.0&id=c573b89139e7a068f5573abd565605bed60f293f
- 0005-avoid-identifying-as-SVR4.patch
https://git.savannah.gnu.org/cgit/screen.git/commit/?h=v.4.7.0&id=ec90292592dd2c9d5c108390841e3df24e377ed5
Rebased 0001-no-memcpy-fallback.patch
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:36:07 +02:00
Bernd Kuhls
22b9ca664d
package/libmicrohttpd: bump version to 0.9.67
...
Release notes:
https://lists.gnu.org/archive/html/libmicrohttpd/2019-10/msg00014.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:35:41 +02:00
Bernd Kuhls
2e6822f9c1
package/x11r7/xkeyboard-config: bump version to 2.28
...
Changelog: https://cgit.freedesktop.org/xkeyboard-config/log/
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:35:35 +02:00
Bernd Kuhls
ac1c16f096
DEVELOPERS: remove myself from asterisk
...
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:34:59 +02:00
Bernd Kuhls
c607818b11
package/asterisk: bump version to 16.6.1
...
Release notes:
https://www.asterisk.org/downloads/asterisk-news/asterisk-1660-now-available
https://www.asterisk.org/downloads/asterisk-news/asterisk-1661-now-available
Updated license hash after upstream commit, no license changes:
b096389660
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:25:09 +02:00
Peter Seiderer
764c96f61e
package/libinput: bump version to 1.14.2
...
For details see [1].
[1] https://lists.freedesktop.org/archives/wayland-devel/2019-October/040936.html
Signed-off-by: Peter Seiderer <ps.report@gmx.net >
Reviewed-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:16:37 +02:00
Bernd Kuhls
e713991d26
package/gqrx: bump version to 2.11.5
...
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:15:52 +02:00
Bernd Kuhls
0e07bfaad4
package/gnuradio: bump version to 3.7.13.5
...
The hash for the tarball is not present in
http://gnuradio.org/releases/gnuradio/sha256sums so we provide a self-
computed hash.
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:15:41 +02:00
Bernd Kuhls
3029eb045c
package/gnutls: bump version to 3.6.10
...
Release notes:
https://lists.gnupg.org/pipermail/gnutls-help/2019-September/004574.html
Removed patch applied upstream, also removed autoreconf.
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:15:30 +02:00
Thomas Petazzoni
051c71f999
package/python-keyring: fix syntax error in Config.in
...
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 21:07:14 +02:00
Asaf Kahlon
393f4c379e
package/python-flask: bump version to 1.1.1
...
LICENSE was renamed to LICENSE.rst with little rephrasing.
In addition, statements about the documentation licensing were
moved from LICENSE to docs/license.rst so this file was added
to _LICENSE_FILES (plus hash).
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 20:47:08 +02:00
Asaf Kahlon
4cee5723e0
package/python-secretstorage: drop Python 2 support
...
Since version 3.0.0, secretstorage doesn't support Python 2 anymore.
Update its reverese dependency (python-keyring) as well.
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 20:33:23 +02:00
Asaf Kahlon
9b746f81e7
package/python-asgiref: drop Python 2 support
...
Asgiref doesn't support Python 2 since version 2.0.0.
All the recursive reverse dependencies already support Python 3 only.
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 20:32:59 +02:00
Asaf Kahlon
8542a545ec
package/python-more-itertools: drop Python 2 support
...
Since version 6.0.0, the package supports only Python 3, and will
lead to syntax errors when in use with Python 2.
In addition, the dependency of python-six is no longer needed.
The reursive reverse dependencies were updated accordingly.
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 19:33:01 +02:00
Giulio Benetti
551d81c079
package/libnss: security bump to version 3.47
...
Fixes the following security issues:
CVE-2019-11756: Remove refcounting from sftk_FreeSession
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 19:14:49 +02:00
Giulio Benetti
a8be14639c
package/libnspr: bump to version 4.23
...
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 19:14:40 +02:00
Carlos Santos
0cc009f29e
package/sysvinit: bump to version 2.96
...
Signed-off-by: Carlos Santos <unixmania@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 19:14:06 +02:00
Asaf Kahlon
3d5444b19f
package/python-xlsxwriter: bump to version 1.2.2
...
And fix indentation in hash file.
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 19:10:51 +02:00
Asaf Kahlon
acaa18c133
package/python-pymodbus: bump to version 2.2.0
...
* Update dependency list.
* Take tarball from PyPI.
* Add hash for license file.
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 19:10:45 +02:00
Asaf Kahlon
6c22e58d9c
package/python-flup: bump to version 1.0.3
...
License isn't shipped with the tarball so we take
PKG-INFO as license file.
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 19:10:31 +02:00
Asaf Kahlon
08a794b5b4
package/python-flask-sqlalchemy: bump to version 2.4.1
...
License is provided with the tarball, so there's no need to
use PKG-INFO.
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 19:10:10 +02:00
Asaf Kahlon
02aaa25610
package/python-docker: bump to version 4.1.0
...
python-docker-pycreds is no longer needed as a dependency.
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 19:09:52 +02:00
Asaf Kahlon
6d64218cc7
package/python-cheroot: bump to version 8.2.1
...
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 19:09:43 +02:00
Asaf Kahlon
c28de26c30
package/python-asn1crypyo: bump to version 1.2.0
...
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 19:09:38 +02:00
Carlos Santos
1ef6d39565
package/qemu: move patch 3 to the 3.1.1.1 subdir
...
Required since the bump from 3.1.1.
Signed-off-by: Carlos Santos <unixmania@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-21 19:07:33 +02:00
Carlos Santos
5e968678fd
package/qemu: fix crash with uClibc-ng
...
On uClibc-ng sysconf(_SC_LEVEL1_{I,D}CACHE_LINESIZE) returns -1, which
is a valid result, meaning that the limit is indeterminate. Add a patch
that handles this situation using fallback values instead of crashing
due to an assertion failure.
Upstream status:
https://lists.nongnu.org/archive/html/qemu-devel/2019-10/msg04115.html
Signed-off-by: Carlos Santos <unixmania@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 16:26:24 +02:00
Romain Naour
0575627967
package/gcc: or1k allow gcc 9.2 with uClibc-ng
...
Binutils 2.32 and GCC 9.2 are now fixed thanks to Stafford Horne.
https://mailman.uclibc-ng.org/pipermail/devel/2019-August/001895.html
Fixes:
https://mailman.uclibc-ng.org/pipermail/devel/2019-August/001885.html
Signed-off-by: Romain Naour <romain.naour@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 16:19:35 +02:00
Romain Naour
e1c7dffb25
package/binutils/2.32: backport or1k upstream patch
...
Without this patch, the system build using qemu_or1k_defconfig
(gcc 9.2, binutils 2.32 and uClibc 1.0.32) doesn't boot.
https://mailman.uclibc-ng.org/pipermail/devel/2019-August/001895.html
Signed-off-by: Romain Naour <romain.naour@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 16:18:28 +02:00
Romain Naour
d87177f201
package/gcc/9.2.0: backport or1k upstream patch
...
Without this patch, the system build using qemu_or1k_defconfig
(gcc 9.2, binutils 2.33.1 and uClibc 1.0.32) doesn't boot.
https://mailman.uclibc-ng.org/pipermail/devel/2019-August/001895.html
Signed-off-by: Romain Naour <romain.naour@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 16:18:10 +02:00
Asaf Kahlon
32d411cae6
package/python-cffi: bump to version 1.13.0
...
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 15:58:24 +02:00
Pierre-Jean Texier
44159498f1
DEVELOPERS: add Pierre-Jean Texier for sbc
...
Signed-off-by: Pierre-Jean Texier <pjtexier@koncepto.io >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 15:57:48 +02:00
Pierre-Jean Texier
f9ef108e7e
package/sbc: bump to version 1.4
...
Also add hashes for license files
Signed-off-by: Pierre-Jean Texier <pjtexier@koncepto.io >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 15:57:44 +02:00
Asaf Kahlon
d6e3884dfd
package/python-dialog: bump to version 3.4.0
...
* Verify .asc file from sourceforge.
* Add hash for license file.
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 15:43:11 +02:00
Asaf Kahlon
7df07cb611
package/python: security bump to version 2.7.17
...
This release fixes CVE-2019-9740, CVE-2019-9948, CVE-2019-15903.
Adjust 0002-Fix-get_python_inc-for-cross-compilation.patch for 2.7.17.
Remove the following patches (now on upstream):
* 0035-bpo-35907-CVE-2019-9948-urllib-rejects-local_file-sc.patch
* 0036-bpo-36216-Add-check-for-characters-in-netloc-that-no.patch
* 0037-3.7-bpo-36216-Only-print-test-messages-when-verbose-.patch
* 0038-bpo-36742-Fixes-handling-of-pre-normalization-charac.patch
* 0039-bpo-36742-Corrects-fix-to-handle-decomposition-in-us.patch
* 0040-2.7-bpo-36742-Fix-urlparse.urlsplit-error-message-fo.patch
* 0041-bpo-30458-Disallow-control-chars-in-http-URLs-GH-127.patch
Full release details at:
https://github.com/python/cpython/blob/v2.7.17/Misc/NEWS.d/2.7.17rc1.rst
run-tests results:
10:30:20 TestPython2 Starting
10:30:21 TestPython2 Building
10:37:37 TestPython2 Building done
10:37:47 TestPython2 Cleaning up
.
----------------------------------------------------------------------
Ran 1 test in 448.616s
OK
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 15:42:56 +02:00
Asaf Kahlon
d9b606bc0f
package/python-automat: bump to version 0.8.0
...
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 15:41:36 +02:00
Asaf Kahlon
b7c4722216
package/libuv: bump to version 1.33.1
...
Fixes:
- http://autobuild.buildroot.net/results/017ce1062a61b25f949c0b8c4b73cac128037901
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 15:41:20 +02:00
Asaf Kahlon
553d2599d4
package/python-psycopg2: bump to version 2.8.4
...
Signed-off-by: Asaf Kahlon <asafka7@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 15:38:27 +02:00
Bernd Kuhls
1da3fa7863
package/ghostscript: security bump version to 9.50
...
Fixes CVE-2019-10216:
https://security-tracker.debian.org/tracker/CVE-2019-10216
Removed patch applied upstream.
Release notes:
https://ghostscript.com/pipermail/gs-devel/2019-October/010232.html
Changelog:
https://www.ghostscript.com/doc/9.50/News.htm
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 15:38:12 +02:00
Bernd Kuhls
36bcb31d14
package/cups-filters: bump version to 1.25.11
...
Removed patch applied upstream:
1fa0931286
Drop CUPS_FILTERS_MAKE_LN_SRF_EXECUTABLE which is no longer needed now
that the ln-srf script is part of the tarball and not added through a
patch.
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 15:37:03 +02:00
Bernd Kuhls
8e13f45586
package/expat: bump version to 2.2.9
...
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 15:17:19 +02:00
Bernd Kuhls
7b527090d2
package/elfutils: bump version to 0.177
...
Removed patched applied upstream, rebased remaining patches.
Added md5 hash provided by upstream.
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 15:17:06 +02:00
Bernd Kuhls
6a2ebcaf6a
package/dialog: bump version to 1.3-20190808
...
Added license hash, switched _SITE to https.
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 15:16:34 +02:00
Bernd Kuhls
e1d56bb945
package/dav1d: bump version to 0.5.0
...
Fixes:
http://autobuild.buildroot.net/results/c2e/c2e5b1d8c59d9ca37f06efc67c0928f7df1096ce/
due to upstream commit
e65abadff6
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2019-10-20 15:15:58 +02:00