release-notes-4.3.4.rst 9.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206
  1. .. SPDX-License-Identifier: CC-BY-SA-2.0-UK
  2. Release notes for Yocto-4.3.4 (Nanbield)
  3. ----------------------------------------
  4. Security Fixes in Yocto-4.3.4
  5. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  6. - bind: Fix :cve_nist:`2023-4408`, :cve_nist:`2023-5517`, :cve_nist:`2023-5679` and :cve_nist:`2023-50387`
  7. - gcc: Update :term:`CVE_STATUS` for :cve_nist:`2023-4039` as fixed
  8. - glibc: Fix :cve_nist:`2023-6246`, :cve_nist:`2023-6779` and :cve_nist:`2023-6780`
  9. - gnutls: Fix :cve_nist:`2024-0553` and :cve_nist:`2024-0567`
  10. - gstreamer: Fix :cve_mitre:`2024-0444`
  11. - libssh2: fix :cve_nist:`2023-48795`
  12. - libxml2: Fix :cve_nist:`2024-25062`
  13. - linux-yocto/6.1: Fix :cve_nist:`2023-6610`, :cve_nist:`2023-6915`, :cve_nist:`2023-46838`, :cve_nist:`2023-50431`, :cve_nist:`2024-1085`, :cve_nist:`2024-1086` and :cve_nist:`2024-23849`
  14. - linux-yocto/6.1: Ignore :cve_nist:`2021-33630`, :cve_nist:`2021-33631`, :cve_nist:`2022-36402`, :cve_nist:`2023-5717`, :cve_nist:`2023-6200`, :cve_nist:`2023-35827`, :cve_nist:`2023-40791`, :cve_nist:`2023-46343`, :cve_nist:`2023-46813`, :cve_nist:`2023-46862`, :cve_nist:`2023-51042`, :cve_nist:`2023-51043`, :cve_mitre:`2023-52340`, :cve_nist:`2024-0562`, :cve_nist:`2024-0565`, :cve_nist:`2024-0582`, :cve_nist:`2024-0584`, :cve_nist:`2024-0607`, :cve_nist:`2024-0639`, :cve_nist:`2024-0641`, :cve_nist:`2024-0646`, :cve_nist:`2024-0775` and :cve_nist:`2024-22705`
  15. - openssl: fix :cve_nist:`2024-0727`
  16. - python3-jinja2: Fix :cve_nist:`2024-22195`
  17. - tiff: Fix :cve_nist:`2023-6228`, :cve_nist:`2023-52355` and :cve_nist:`2023-52356`
  18. - vim: Fix :cve_nist:`2024-22667`
  19. - wpa-supplicant: Fix :cve_nist:`2023-52160`
  20. - xserver-xorg: Fix :cve_nist:`2023-6377`, :cve_nist:`2023-6478`, :cve_nist:`2023-6816`, :cve_nist:`2024-0229`, :cve_nist:`2024-0408`, :cve_nist:`2024-0409`, :cve_nist:`2024-21885` and :cve_nist:`2024-21886`
  21. - xwayland: Fix :cve_nist:`2023-6816`, :cve_nist:`2024-0408` and :cve_nist:`2024-0409`
  22. - zlib: Ignore :cve_nist:`2023-6992`
  23. Fixes in Yocto-4.3.4
  24. ~~~~~~~~~~~~~~~~~~~~
  25. - allarch: Fix allarch corner case
  26. - at-spi2-core: Upgrade to 2.50.1
  27. - bind: Upgrade to 9.18.24
  28. - build-appliance-image: Update to nanbield head revision
  29. - contributor-guide: add notes for tests
  30. - contributor-guide: be more specific about meta-* trees
  31. - core-image-ptest: Increase disk size to 1.5G for strace ptest image
  32. - cpio: Upgrade to 2.15
  33. - curl: improve run-ptest
  34. - curl: increase test timeouts
  35. - cve-check: Log if :term:`CVE_STATUS` set but not reported for component
  36. - cve-update-nvd2-native: Add an age threshold for incremental update
  37. - cve-update-nvd2-native: Fix CVE configuration update
  38. - cve-update-nvd2-native: Fix typo in comment
  39. - cve-update-nvd2-native: Remove duplicated CVE_CHECK_DB_FILE definition
  40. - cve-update-nvd2-native: Remove rejected CVE from database
  41. - cve-update-nvd2-native: nvd_request_next: Improve comment
  42. - cve_check: cleanup logging
  43. - cve_check: handle :term:`CVE_STATUS` being set to the empty string
  44. - dev-manual: Rephrase spdx creation
  45. - dev-manual: improve descriptions of 'bitbake -S printdiff'
  46. - dev-manual: packages: clarify shared :term:`PR` service constraint
  47. - dev-manual: packages: fix capitalization
  48. - dev-manual: packages: need enough free space
  49. - docs: add initial stylechecks with Vale
  50. - docs: correct sdk installation default path
  51. - docs: document VIRTUAL-RUNTIME variables
  52. - docs: suppress excess use of "following" word
  53. - docs: use "manual page(s)"
  54. - docs: Makefile: remove releases.rst in "make clean"
  55. - externalsrc: fix task dependency for do_populate_lic
  56. - glibc: Remove duplicate :term:`CVE_STATUS` for :cve_nist:`2023-4527`
  57. - glibc: stable 2.38 branch updates (2.38+gitd37c2b20a4)
  58. - gnutls: Upgrade to 3.8.3
  59. - gstreamer1.0: skip a test that is known to be flaky
  60. - gstreamer: Upgrade to 1.22.9
  61. - gtk: Set :term:`CVE_PRODUCT`
  62. - kernel.bbclass: Set pkg-config variables for building modules
  63. - libxml2: Upgrade to 2.11.7
  64. - linux-firmware: Upgrade to 20240220
  65. - linux-yocto/6.1: update to v6.1.78
  66. - mdadm: Disable ptests
  67. - migration-guides: add release notes for 4.3.3
  68. - migration-guides: add release notes for 4.0.17
  69. - migration-guides: fix release notes for 4.3.3 linux-yocto/6.1 CVE entries
  70. - multilib_global.bbclass: fix parsing error with no kernel module split
  71. - openssl: fix crash on aarch64 if BTI is enabled but no Crypto instructions
  72. - openssl: Upgrade to 3.1.5
  73. - overlayfs: add missing closing parenthesis in selftest
  74. - poky.conf: bump version for 4.3.4 release
  75. - profile-manual: usage.rst: fix reference to bug report
  76. - profile-manual: usage.rst: formatting fixes
  77. - profile-manual: usage.rst: further style improvements
  78. - pseudo: Update to pull in gcc14 fix and missing statvfs64 intercept
  79. - python3-jinja2: Upgrade to 3.1.3
  80. - ref-manual: release-process: grammar fix
  81. - ref-manual: system-requirements: update packages to build docs
  82. - ref-manual: tasks: do_cleanall: recommend using '-f' instead
  83. - ref-manual: tasks: do_cleansstate: recommend using '-f' instead for a shared sstate
  84. - ref-manual: variables: adding multiple groups in :term:`GROUPADD_PARAM`
  85. - ref-manual: variables: add documentation of the variable :term:`SPDX_NAMESPACE_PREFIX`
  86. - reproducible: Fix race with externalsrc/devtool over lockfile
  87. - sdk-manual: extensible: correctly describe separate build-sysroots tasks in direct sdk workflows
  88. - tzdata : Upgrade to 2024a
  89. - udev-extraconf: fix unmount directories containing octal-escaped chars
  90. - vim: Upgrade to v9.0.2190
  91. - wireless-regdb: Upgrade to 2024.01.23
  92. - xserver-xorg: Upgrade to 21.1.11
  93. - xwayland: Upgrade to 23.2.4
  94. - yocto-uninative: Update to 4.4 for glibc 2.39
  95. Known Issues in Yocto-4.3.4
  96. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  97. - N/A
  98. Contributors to Yocto-4.3.4
  99. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  100. - Alex Kiernan
  101. - Alexander Kanavin
  102. - Alexander Sverdlin
  103. - Baruch Siach
  104. - BELOUARGA Mohamed
  105. - Benjamin Bara
  106. - Bruce Ashfield
  107. - Chen Qi
  108. - Claus Stovgaard
  109. - Dhairya Nagodra
  110. - Geoff Parker
  111. - Johan Bezem
  112. - Jonathan GUILLOT
  113. - Julien Stephan
  114. - Kai Kang
  115. - Khem Raj
  116. - Lee Chee Yang
  117. - Luca Ceresoli
  118. - Martin Jansa
  119. - Michael Halstead
  120. - Michael Opdenacker
  121. - Munehisa Kamata
  122. - Pavel Zhukov
  123. - Peter Marko
  124. - Priyal Doshi
  125. - Richard Purdie
  126. - Robert Joslyn
  127. - Ross Burton
  128. - Simone Weiß
  129. - Soumya Sambu
  130. - Steve Sakoman
  131. - Tim Orling
  132. - Wang Mingyu
  133. - Yoann Congal
  134. - Yogita Urade
  135. Repositories / Downloads for Yocto-4.3.4
  136. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  137. poky
  138. - Repository Location: :yocto_git:`/poky`
  139. - Branch: :yocto_git:`nanbield </poky/log/?h=nanbield>`
  140. - Tag: :yocto_git:`yocto-4.3.4 </poky/log/?h=yocto-4.3.4>`
  141. - Git Revision: :yocto_git:`7b8aa378d069ee31373f22caba3bd7fc7863f447 </poky/commit/?id=7b8aa378d069ee31373f22caba3bd7fc7863f447>`
  142. - Release Artefact: poky-7b8aa378d069ee31373f22caba3bd7fc7863f447
  143. - sha: 0cb14125f215cc9691cff43982e2c540a5b6018df4ed25c10933135b5bf21d0f
  144. - Download Locations:
  145. http://downloads.yoctoproject.org/releases/yocto/yocto-4.3.4/poky-7b8aa378d069ee31373f22caba3bd7fc7863f447.tar.bz2
  146. http://mirrors.kernel.org/yocto/yocto/yocto-4.3.4/poky-7b8aa378d069ee31373f22caba3bd7fc7863f447.tar.bz2
  147. openembedded-core
  148. - Repository Location: :oe_git:`/openembedded-core`
  149. - Branch: :oe_git:`nanbield </openembedded-core/log/?h=nanbield>`
  150. - Tag: :oe_git:`yocto-4.3.4 </openembedded-core/log/?h=yocto-4.3.4>`
  151. - Git Revision: :oe_git:`d0e68072d138ccc1fb5957fdc46a91871eb6a3e1 </openembedded-core/commit/?id=d0e68072d138ccc1fb5957fdc46a91871eb6a3e1>`
  152. - Release Artefact: oecore-d0e68072d138ccc1fb5957fdc46a91871eb6a3e1
  153. - sha: d311fe22ff296c466f9bea1cd26343baee5630bc37f3dda42f2d9d8cc99e3add
  154. - Download Locations:
  155. http://downloads.yoctoproject.org/releases/yocto/yocto-4.3.4/oecore-d0e68072d138ccc1fb5957fdc46a91871eb6a3e1.tar.bz2
  156. http://mirrors.kernel.org/yocto/yocto/yocto-4.3.4/oecore-d0e68072d138ccc1fb5957fdc46a91871eb6a3e1.tar.bz2
  157. meta-mingw
  158. - Repository Location: :yocto_git:`/meta-mingw`
  159. - Branch: :yocto_git:`nanbield </meta-mingw/log/?h=nanbield>`
  160. - Tag: :yocto_git:`yocto-4.3.4 </meta-mingw/log/?h=yocto-4.3.4>`
  161. - Git Revision: :yocto_git:`49617a253e09baabbf0355bc736122e9549c8ab2 </meta-mingw/commit/?id=49617a253e09baabbf0355bc736122e9549c8ab2>`
  162. - Release Artefact: meta-mingw-49617a253e09baabbf0355bc736122e9549c8ab2
  163. - sha: 2225115b73589cdbf1e491115221035c6a61679a92a93b2a3cf761ff87bf4ecc
  164. - Download Locations:
  165. http://downloads.yoctoproject.org/releases/yocto/yocto-4.3.4/meta-mingw-49617a253e09baabbf0355bc736122e9549c8ab2.tar.bz2
  166. http://mirrors.kernel.org/yocto/yocto/yocto-4.3.4/meta-mingw-49617a253e09baabbf0355bc736122e9549c8ab2.tar.bz2
  167. bitbake
  168. - Repository Location: :oe_git:`/bitbake`
  169. - Branch: :oe_git:`2.6 </bitbake/log/?h=2.6>`
  170. - Tag: :oe_git:`yocto-4.3.4 </bitbake/log/?h=yocto-4.3.4>`
  171. - Git Revision: :oe_git:`380a9ac97de5774378ded5e37d40b79b96761a0c </bitbake/commit/?id=380a9ac97de5774378ded5e37d40b79b96761a0c>`
  172. - Release Artefact: bitbake-380a9ac97de5774378ded5e37d40b79b96761a0c
  173. - sha: 78f579b9d29e72d09b6fb10ac62aa925104335e92d2afb3155bc9ab1994e36c1
  174. - Download Locations:
  175. http://downloads.yoctoproject.org/releases/yocto/yocto-4.3.4/bitbake-380a9ac97de5774378ded5e37d40b79b96761a0c.tar.bz2
  176. http://mirrors.kernel.org/yocto/yocto/yocto-4.3.4/bitbake-380a9ac97de5774378ded5e37d40b79b96761a0c.tar.bz2
  177. yocto-docs
  178. - Repository Location: :yocto_git:`/yocto-docs`
  179. - Branch: :yocto_git:`nanbield </yocto-docs/log/?h=nanbield>`
  180. - Tag: :yocto_git:`yocto-4.3.4 </yocto-docs/log/?h=yocto-4.3.4>`
  181. - Git Revision: :yocto_git:`05d08b0bbaef760157c8d35a78d7405bc5ffce55 </yocto-docs/commit/?id=05d08b0bbaef760157c8d35a78d7405bc5ffce55>`