release-notes-4.0.7.rst 10.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242
  1. .. SPDX-License-Identifier: CC-BY-SA-2.0-UK
  2. Release notes for Yocto-4.0.7 (Kirkstone)
  3. -----------------------------------------
  4. Security Fixes in Yocto-4.0.7
  5. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  6. - binutils: Fix :cve_nist:`2022-4285`
  7. - curl: Fix :cve_nist:`2022-43551` and :cve_mitre:`2022-43552`
  8. - ffmpeg: Fix :cve_nist:`2022-3109` and :cve_nist:`2022-3341`
  9. - go: Fix :cve_nist:`2022-41715` and :cve_nist:`2022-41717`
  10. - libX11: Fix :cve_nist:`2022-3554` and :cve_nist:`2022-3555`
  11. - libarchive: Fix :cve_nist:`2022-36227`
  12. - libksba: Fix :cve_nist:`2022-47629`
  13. - libpng: Fix :cve_nist:`2019-6129`
  14. - libxml2: Fix :cve_nist:`2022-40303` and :cve_nist:`2022-40304`
  15. - openssl: Fix :cve_nist:`2022-3996`
  16. - python3: Fix :cve_nist:`2022-45061`
  17. - python3-git: Fix :cve_nist:`2022-24439`
  18. - python3-setuptools: Fix :cve_nist:`2022-40897`
  19. - python3-wheel: Fix :cve_nist:`2022-40898`
  20. - qemu: Fix :cve_nist:`2022-4144`
  21. - sqlite: Fix :cve_nist:`2022-46908`
  22. - systemd: Fix :cve_nist:`2022-45873`
  23. - vim: Fix :cve_nist:`2023-0049`, :cve_nist:`2023-0051`, :cve_nist:`2023-0054` and :cve_nist:`2023-0088`
  24. - webkitgtk: Fix :cve_nist:`2022-32886`, :cve_mitre:`2022-32891` and :cve_nist:`2022-32912`
  25. Fixes in Yocto-4.0.7
  26. ~~~~~~~~~~~~~~~~~~~~
  27. - Revert "gstreamer1.0: disable flaky gstbin:test_watch_for_state_change test"
  28. - at: Change when files are copied
  29. - baremetal-image: Avoid overriding qemu variables from IMAGE_CLASSES
  30. - base.bbclass: Fix way to check ccache path
  31. - bc: extend to nativesdk
  32. - bind: upgrade to 9.18.10
  33. - busybox: always start do_compile with orig config files
  34. - busybox: rm temporary files if do_compile was interrupted
  35. - cairo: fix CVE patches assigned wrong CVE number
  36. - cairo: update patch for :cve_nist:`2019-6461` with upstream solution
  37. - classes/create-spdx: Add SPDX_PRETTY option
  38. - classes: image: Set empty weak default IMAGE_LINGUAS
  39. - combo-layer: add sync-revs command
  40. - combo-layer: dont use bb.utils.rename
  41. - combo-layer: remove unused import
  42. - curl: Correct LICENSE from MIT-open-group to curl
  43. - cve-check: write the cve manifest to IMGDEPLOYDIR
  44. - cve-update-db-native: avoid incomplete updates
  45. - cve-update-db-native: show IP on failure
  46. - dbus: Add missing CVE product name
  47. - devtool/upgrade: correctly handle recipes where S is a subdir of upstream tree
  48. - devtool: process local files only for the main branch
  49. - dhcpcd: backport two patches to fix runtime error
  50. - docs: kernel-dev: faq: update tip on how to not include kernel in image
  51. - docs: migration-4.0: specify variable name change for kernel inclusion in image recipe
  52. - efibootmgr: update compilation with musl
  53. - externalsrc: fix lookup for .gitmodules
  54. - ffmpeg: refresh patches to apply cleanly
  55. - freetype:update mirror site.
  56. - gcc: Refactor linker patches and fix linker on arm with usrmerge
  57. - glibc: stable 2.35 branch updates.
  58. - go-crosssdk: avoid host contamination by GOCACHE
  59. - gstreamer1.0: Fix race conditions in gstbin tests
  60. - gstreamer1.0: upgrade to 1.20.5
  61. - gtk-icon-cache: Fix GTKIC_CMD if-else condition
  62. - harfbuzz: remove bindir only if it exists
  63. - kernel-fitimage: Adjust order of dtb/dtbo files
  64. - kernel-fitimage: Allow user to select dtb when multiple dtb exists
  65. - kernel.bbclass: remove empty module directories to prevent QA issues
  66. - lib/buildstats: fix parsing of trees with reduced_proc_pressure directories
  67. - lib/oe/reproducible: Use git log without gpg signature
  68. - libepoxy: remove upstreamed patch
  69. - libnewt: update 0.52.21 -> 0.52.23
  70. - libseccomp: fix typo in DESCRIPTION
  71. - libxcrypt-compat: upgrade 4.4.30 -> 4.4.33
  72. - libxml2: fix test data checksums
  73. - linux-firmware: upgrade 20221109 -> 20221214
  74. - linux-yocto/5.10: update to v5.10.152
  75. - linux-yocto/5.10: update to v5.10.154
  76. - linux-yocto/5.10: update to v5.10.160
  77. - linux-yocto/5.15: fix perf build with clang
  78. - linux-yocto/5.15: libbpf: Fix build warning on ref_ctr_off
  79. - linux-yocto/5.15: ltp and squashfs fixes
  80. - linux-yocto/5.15: powerpc: Fix reschedule bug in KUAP-unlocked user copy
  81. - linux-yocto/5.15: update to v5.15.84
  82. - lsof: add update-alternatives logic
  83. - lttng-modules: update 2.13.7 -> 2.13.8
  84. - manuals: add 4.0.5 and 4.0.6 release notes
  85. - manuals: document SPDX_PRETTY variable
  86. - mpfr: upgrade 4.1.0 -> 4.1.1
  87. - oeqa/concurrencytest: Add number of failures to summary output
  88. - oeqa/rpm.py: Increase timeout and add debug output
  89. - oeqa/selftest/externalsrc: add test for srctree_hash_files
  90. - openssh: remove RRECOMMENDS to rng-tools for sshd package
  91. - poky.conf: bump version for 4.0.7
  92. - qemuboot.bbclass: make sure runqemu boots bundled initramfs kernel image
  93. - rm_work.bbclass: use HOSTTOOLS 'rm' binary exclusively
  94. - rm_work: adjust dependency to make do_rm_work_all depend on do_rm_work
  95. - ruby: merge .inc into .bb
  96. - ruby: update 3.1.2 -> 3.1.3
  97. - selftest/virgl: use pkg-config from the host
  98. - tiff: Add packageconfig knob for webp
  99. - toolchain-scripts: compatibility with unbound variable protection
  100. - tzdata: update 2022d -> 2022g
  101. - valgrind: skip the boost_thread test on arm
  102. - xserver-xorg: upgrade 21.1.4 -> 21.1.6
  103. - xwayland: libxshmfence is needed when dri3 is enabled
  104. - xwayland: upgrade 22.1.5 -> 22.1.7
  105. - yocto-check-layer: Allow OE-Core to be tested
  106. Known Issues in Yocto-4.0.7
  107. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  108. - N/A
  109. Contributors to Yocto-4.0.7
  110. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  111. - Alejandro Hernandez Samaniego
  112. - Alex Kiernan
  113. - Alex Stewart
  114. - Alexander Kanavin
  115. - Antonin Godard
  116. - Benoît Mauduit
  117. - Bhabu Bindu
  118. - Bruce Ashfield
  119. - Carlos Alberto Lopez Perez
  120. - Changqing Li
  121. - Chen Qi
  122. - Daniel Gomez
  123. - Florin Diaconescu
  124. - He Zhe
  125. - Hitendra Prajapati
  126. - Jagadeesh Krishnanjanappa
  127. - Jan Kircher
  128. - Jermain Horsman
  129. - Jose Quaresma
  130. - Joshua Watt
  131. - KARN JYE LAU
  132. - Kai Kang
  133. - Khem Raj
  134. - Luis
  135. - Marta Rybczynska
  136. - Martin Jansa
  137. - Mathieu Dubois-Briand
  138. - Michael Opdenacker
  139. - Narpat Mali
  140. - Ovidiu Panait
  141. - Pavel Zhukov
  142. - Peter Marko
  143. - Petr Kubizňák
  144. - Quentin Schulz
  145. - Randy MacLeod
  146. - Ranjitsinh Rathod
  147. - Richard Purdie
  148. - Robert Andersson
  149. - Ross Burton
  150. - Sandeep Gundlupet Raju
  151. - Saul Wold
  152. - Steve Sakoman
  153. - Vivek Kumbhar
  154. - Wang Mingyu
  155. - Xiangyu Chen
  156. - Yash Shinde
  157. - Yogita Urade
  158. Repositories / Downloads for Yocto-4.0.7
  159. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  160. poky
  161. - Repository Location: :yocto_git:`/poky`
  162. - Branch: :yocto_git:`kirkstone </poky/log/?h=kirkstone>`
  163. - Tag: :yocto_git:`yocto-4.0.7 </poky/log/?h=yocto-4.0.7>`
  164. - Git Revision: :yocto_git:`65dafea22018052fe7b2e17e6e4d7eb754224d38 </poky/commit/?id=65dafea22018052fe7b2e17e6e4d7eb754224d38>`
  165. - Release Artefact: poky-65dafea22018052fe7b2e17e6e4d7eb754224d38
  166. - sha: 6b1b67600b84503e2d5d29bcd6038547339f4f9413b830cd2408df825eda642d
  167. - Download Locations:
  168. http://downloads.yoctoproject.org/releases/yocto/yocto-4.0.7/poky-65dafea22018052fe7b2e17e6e4d7eb754224d38.tar.bz2
  169. http://mirrors.kernel.org/yocto/yocto/yocto-4.0.7/poky-65dafea22018052fe7b2e17e6e4d7eb754224d38.tar.bz2
  170. openembedded-core
  171. - Repository Location: :oe_git:`/openembedded-core`
  172. - Branch: :oe_git:`kirkstone </openembedded-core/log/?h=kirkstone>`
  173. - Tag: :oe_git:`yocto-4.0.7 </openembedded-core/log/?h=yocto-4.0.7>`
  174. - Git Revision: :oe_git:`a8c82902384f7430519a31732a4bb631f21693ac </openembedded-core/commit/?id=a8c82902384f7430519a31732a4bb631f21693ac>`
  175. - Release Artefact: oecore-a8c82902384f7430519a31732a4bb631f21693ac
  176. - sha: 6f2dbc4ea1e388620ef77ac3a7bbb2b5956bb8bf9349b0c16cd7610e9996f5ea
  177. - Download Locations:
  178. http://downloads.yoctoproject.org/releases/yocto/yocto-4.0.7/oecore-a8c82902384f7430519a31732a4bb631f21693ac.tar.bz2
  179. http://mirrors.kernel.org/yocto/yocto/yocto-4.0.7/oecore-a8c82902384f7430519a31732a4bb631f21693ac.tar.bz2
  180. meta-mingw
  181. - Repository Location: :yocto_git:`/meta-mingw`
  182. - Branch: :yocto_git:`kirkstone </meta-mingw/log/?h=kirkstone>`
  183. - Tag: :yocto_git:`yocto-4.0.7 </meta-mingw/log/?h=yocto-4.0.7>`
  184. - Git Revision: :yocto_git:`a90614a6498c3345704e9611f2842eb933dc51c1 </meta-mingw/commit/?id=a90614a6498c3345704e9611f2842eb933dc51c1>`
  185. - Release Artefact: meta-mingw-a90614a6498c3345704e9611f2842eb933dc51c1
  186. - sha: 49f9900bfbbc1c68136f8115b314e95d0b7f6be75edf36a75d9bcd1cca7c6302
  187. - Download Locations:
  188. http://downloads.yoctoproject.org/releases/yocto/yocto-4.0.7/meta-mingw-a90614a6498c3345704e9611f2842eb933dc51c1.tar.bz2
  189. http://mirrors.kernel.org/yocto/yocto/yocto-4.0.7/meta-mingw-a90614a6498c3345704e9611f2842eb933dc51c1.tar.bz2
  190. meta-gplv2
  191. - Repository Location: :yocto_git:`/meta-gplv2`
  192. - Branch: :yocto_git:`kirkstone </meta-gplv2/log/?h=kirkstone>`
  193. - Tag: :yocto_git:`yocto-4.0.7 </meta-gplv2/log/?h=yocto-4.0.7>`
  194. - Git Revision: :yocto_git:`d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a </meta-gplv2/commit/?id=d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a>`
  195. - Release Artefact: meta-gplv2-d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a
  196. - sha: c386f59f8a672747dc3d0be1d4234b6039273d0e57933eb87caa20f56b9cca6d
  197. - Download Locations:
  198. http://downloads.yoctoproject.org/releases/yocto/yocto-4.0.7/meta-gplv2-d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a.tar.bz2
  199. http://mirrors.kernel.org/yocto/yocto/yocto-4.0.7/meta-gplv2-d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a.tar.bz2
  200. bitbake
  201. - Repository Location: :oe_git:`/bitbake`
  202. - Branch: :oe_git:`2.0 </bitbake/log/?h=2.0>`
  203. - Tag: :oe_git:`yocto-4.0.7 </bitbake/log/?h=yocto-4.0.7>`
  204. - Git Revision: :oe_git:`7e268c107bb0240d583d2c34e24a71e373382509 </bitbake/commit/?id=7e268c107bb0240d583d2c34e24a71e373382509>`
  205. - Release Artefact: bitbake-7e268c107bb0240d583d2c34e24a71e373382509
  206. - sha: c3e2899012358c95962c7a5c85cf98dc30c58eae0861c374124e96d9556bb901
  207. - Download Locations:
  208. http://downloads.yoctoproject.org/releases/yocto/yocto-4.0.7/bitbake-7e268c107bb0240d583d2c34e24a71e373382509.tar.bz2
  209. http://mirrors.kernel.org/yocto/yocto/yocto-4.0.7/bitbake-7e268c107bb0240d583d2c34e24a71e373382509.tar.bz2
  210. yocto-docs
  211. - Repository Location: :yocto_git:`/yocto-docs`
  212. - Branch: :yocto_git:`kirkstone </yocto-docs/log/?h=kirkstone>`
  213. - Tag: :yocto_git:`yocto-4.0.7 </yocto-docs/log/?h=yocto-4.0.7>`
  214. - Git Revision: :yocto_git:`5883e897c34f25401b358a597fb6e18d80f7f90b </yocto-docs/commit/?id=5883e897c34f25401b358a597fb6e18d80f7f90b>`