From patchwork Sat Jul 1 16:02:03 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: auh@yoctoproject.org X-Patchwork-Id: 26823 Return-Path: Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 66D34C10F1A for ; Sat, 1 Jul 2023 16:02:07 +0000 (UTC) Received: from a27-33.smtp-out.us-west-2.amazonses.com (a27-33.smtp-out.us-west-2.amazonses.com [54.240.27.33]) by mx.groups.io with SMTP id smtpd.web11.10765.1688227323201429882 for ; Sat, 01 Jul 2023 09:02:03 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@yoctoproject.org header.s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky header.b=MOkyQrPR; spf=pass (domain: us-west-2.amazonses.com, ip: 54.240.27.33, mailfrom: 0101018912309cdb-31acff41-b9a4-4856-a1d4-e90761f55bd5-000000@us-west-2.amazonses.com) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky; d=yoctoproject.org; t=1688227323; h=Content-Type:MIME-Version:From:To:Cc:Subject:Message-Id:Date; bh=semxEoxEIiKiobbfufzAOiMo5EN8TAaEXQx6GsZverQ=; b=MOkyQrPRlBYwhQBMqFIzgwMb/6l8UNn4A5GPCDKJRJtPVRjih8aCyAtGKLP7q1o6 3vK2hG2NW+gtK/5aBCh+WlJvcy2wXdSBA4uGvyFkmYbLstCcHoFBzxOGwDgH6vyasSq 2X/O/A5DMXCO+YOGQG2YyPGhZpreI1QeCDaM+GB4= DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=hsbnp7p3ensaochzwyq5wwmceodymuwv; d=amazonses.com; t=1688227323; h=Content-Type:MIME-Version:From:To:Cc:Subject:Message-Id:Date:Feedback-ID; bh=semxEoxEIiKiobbfufzAOiMo5EN8TAaEXQx6GsZverQ=; b=PbyfmtrraGx1ZUgSof47q2du5+l426yHuOME8Ayl+JAa4njwyAmNrzFZi2NPwfGj bHPAj66k6ikGmeSzvp49BbCMd5t7ZKrAYBG/G1vQiPMLZiaCkeXky5eTRjImZSZpUQB mulRg18u1o88rVeQmSmSaJ/15JQKDxywv72pofUM= MIME-Version: 1.0 From: auh@yoctoproject.org To: Chen Qi Cc: openembedded-core@lists.openembedded.org Subject: [AUH] cups: upgrading to 2.4.6 FAILED Message-ID: <0101018912309cdb-31acff41-b9a4-4856-a1d4-e90761f55bd5-000000@us-west-2.amazonses.com> Date: Sat, 1 Jul 2023 16:02:03 +0000 Feedback-ID: 1.us-west-2.9np3MYPs3fEaOBysGKSlUD4KtcmPijcmS9Az2Hwf7iQ=:AmazonSES X-SES-Outgoing: 2023.07.01-54.240.27.33 List-Id: X-Webhook-Received: from li982-79.members.linode.com [45.33.32.79] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 01 Jul 2023 16:02:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/183744 Hello, this email is a notification from the Auto Upgrade Helper that the automatic attempt to upgrade the recipe *cups* to *2.4.6* has Failed(do_compile). Detailed error information: do_compile failed Next steps: - apply the patch: git am 0001-cups-upgrade-2.4.2-2.4.6.patch - check the changes to upstream patches and summarize them in the commit message, - compile an image that contains the package - perform some basic sanity tests - amend the patch and sign it off: git commit -s --reset-author --amend - send it to the appropriate mailing list Alternatively, if you believe the recipe should not be upgraded at this time, you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that automatic upgrades would no longer be attempted. Please review the attached files for further information and build/update failures. Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler Regards, The Upgrade Helper -- >8 -- From 6ff7a4db8cbcdd6a9b057ea405de312cbb83921b Mon Sep 17 00:00:00 2001 From: Upgrade Helper Date: Sat, 1 Jul 2023 10:18:36 +0000 Subject: [PATCH] cups: upgrade 2.4.2 -> 2.4.6 --- meta/recipes-extended/cups/cups.inc | 1 - .../cups/cups/CVE-2023-32324.patch | 36 ------------------- .../cups/{cups_2.4.2.bb => cups_2.4.6.bb} | 2 +- 3 files changed, 1 insertion(+), 38 deletions(-) delete mode 100644 meta/recipes-extended/cups/cups/CVE-2023-32324.patch rename meta/recipes-extended/cups/{cups_2.4.2.bb => cups_2.4.6.bb} (51%) diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index d77758fd3f..da320b1085 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -15,7 +15,6 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://0004-cups-fix-multilib-install-file-conflicts.patch \ file://volatiles.99_cups \ file://cups-volatiles.conf \ - file://CVE-2023-32324.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2023-32324.patch b/meta/recipes-extended/cups/cups/CVE-2023-32324.patch deleted file mode 100644 index 40b89c9899..0000000000 --- a/meta/recipes-extended/cups/cups/CVE-2023-32324.patch +++ /dev/null @@ -1,36 +0,0 @@ -From 07cbffd11107eed3aaf1c64e35552aec20f792da Mon Sep 17 00:00:00 2001 -From: Zdenek Dohnal -Date: Thu, 1 Jun 2023 12:04:00 +0200 -Subject: [PATCH] cups/string.c: Return if `size` is 0 (fixes CVE-2023-32324) - -CVE: CVE-2023-32324 -Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/fd8bc2d32589] - -(cherry picked from commit fd8bc2d32589d1fd91fe1c0521be2a7c0462109e) -Signed-off-by: Sanjay Chitroda ---- - cups/string.c | 4 ++++ - 1 file changed, 4 insertions(+) - -diff --git a/cups/string.c b/cups/string.c -index 93cdad19..6ef58515 100644 ---- a/cups/string.c -+++ b/cups/string.c -@@ -1,6 +1,7 @@ - /* - * String functions for CUPS. - * -+ * Copyright © 2023 by OpenPrinting. - * Copyright © 2007-2019 by Apple Inc. - * Copyright © 1997-2007 by Easy Software Products. - * -@@ -730,6 +731,9 @@ _cups_strlcpy(char *dst, /* O - Destination string */ - size_t srclen; /* Length of source string */ - - -+ if (size == 0) -+ return (0); -+ - /* - * Figure out how much room is needed... - */ diff --git a/meta/recipes-extended/cups/cups_2.4.2.bb b/meta/recipes-extended/cups/cups_2.4.6.bb similarity index 51% rename from meta/recipes-extended/cups/cups_2.4.2.bb rename to meta/recipes-extended/cups/cups_2.4.6.bb index f5ca749bac..58029fdbd4 100644 --- a/meta/recipes-extended/cups/cups_2.4.2.bb +++ b/meta/recipes-extended/cups/cups_2.4.6.bb @@ -2,4 +2,4 @@ require cups.inc LIC_FILES_CHKSUM = "file://LICENSE;md5=3b83ef96387f14655fc854ddc3c6bd57" -SRC_URI[sha256sum] = "f03ccb40b087d1e30940a40e0141dcbba263f39974c20eb9f2521066c9c6c908" +SRC_URI[sha256sum] = "58e970cf1955e1cc87d0847c32526d9c2ccee335e5f0e3882b283138ba0e7262"