From patchwork Fri Jun 16 03:51:23 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: auh@yoctoproject.org X-Patchwork-Id: 25742 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6AF17C05053 for ; Fri, 16 Jun 2023 03:51:28 +0000 (UTC) Received: from a27-23.smtp-out.us-west-2.amazonses.com (a27-23.smtp-out.us-west-2.amazonses.com [54.240.27.23]) by mx.groups.io with SMTP id smtpd.web11.817.1686887484447303153 for ; Thu, 15 Jun 2023 20:51:24 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@yoctoproject.org header.s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky header.b=NPX+uR0c; spf=pass (domain: us-west-2.amazonses.com, ip: 54.240.27.23, mailfrom: 01010188c25448fc-d0ff24c7-11be-42e9-9454-684f27d9765d-000000@us-west-2.amazonses.com) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky; d=yoctoproject.org; t=1686887483; h=Content-Type:MIME-Version:From:To:Cc:Subject:Message-Id:Date; bh=09WDRnhO2RTEh1f6k5d2+SeTRQrhCFIti66JJmnn6iQ=; b=NPX+uR0cn99TzTuE4ZUQ7f0X0wMfsAq7cZbhGBkfXOJBNicPBZuhuGYU+83vwImz rEM9YUj8L0hfpS97ySpWkjYmhzEVRs2fPHRJxDGIhUCZVbyJjzS22Sx+SphlwD1k5Cq n0/BXSH3izOronI6dpneHy3VgYneyNiHU9PsNBG8= DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=hsbnp7p3ensaochzwyq5wwmceodymuwv; d=amazonses.com; t=1686887483; h=Content-Type:MIME-Version:From:To:Cc:Subject:Message-Id:Date:Feedback-ID; bh=09WDRnhO2RTEh1f6k5d2+SeTRQrhCFIti66JJmnn6iQ=; b=bwtQGTbZZvlgtnH2DHmqP9B17RsRzIfDLwB1U6MTzmXnZeEp/IAUbW0sVD22FdMw y4d6OTINCsd/tpsOEPnDH9x6NwcdiAXmX8auuJU4ARrjAT6bTDoCed7Ytv2DIeGbrjz /6oo2KSqcQpeLEQjw5knsuaQmJhHO7V7oRxmAgx8= MIME-Version: 1.0 From: auh@yoctoproject.org To: Chen Qi Cc: openembedded-core@lists.openembedded.org Subject: [AUH] cups: upgrading to 2.4.5 SUCCEEDED Message-ID: <01010188c25448fc-d0ff24c7-11be-42e9-9454-684f27d9765d-000000@us-west-2.amazonses.com> Date: Fri, 16 Jun 2023 03:51:23 +0000 Feedback-ID: 1.us-west-2.9np3MYPs3fEaOBysGKSlUD4KtcmPijcmS9Az2Hwf7iQ=:AmazonSES X-SES-Outgoing: 2023.06.16-54.240.27.23 List-Id: X-Webhook-Received: from li982-79.members.linode.com [45.33.32.79] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 16 Jun 2023 03:51:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/182955 Hello, this email is a notification from the Auto Upgrade Helper that the automatic attempt to upgrade the recipe *cups* to *2.4.5* has Succeeded. Next steps: - apply the patch: git am 0001-cups-upgrade-2.4.2-2.4.5.patch - check the changes to upstream patches and summarize them in the commit message, - compile an image that contains the package - perform some basic sanity tests - amend the patch and sign it off: git commit -s --reset-author --amend - send it to the appropriate mailing list Alternatively, if you believe the recipe should not be upgraded at this time, you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that automatic upgrades would no longer be attempted. Please review the attached files for further information and build/update failures. Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler Regards, The Upgrade Helper -- >8 -- From b258fc3f863defcd07454bfd6cec2389629fe81a Mon Sep 17 00:00:00 2001 From: Upgrade Helper Date: Thu, 15 Jun 2023 15:32:46 +0000 Subject: [PATCH] cups: upgrade 2.4.2 -> 2.4.5 --- meta/recipes-extended/cups/cups.inc | 1 - .../cups/cups/CVE-2023-32324.patch | 36 ------------------- .../cups/{cups_2.4.2.bb => cups_2.4.5.bb} | 2 +- 3 files changed, 1 insertion(+), 38 deletions(-) delete mode 100644 meta/recipes-extended/cups/cups/CVE-2023-32324.patch rename meta/recipes-extended/cups/{cups_2.4.2.bb => cups_2.4.5.bb} (51%) diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index d77758fd3f..da320b1085 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -15,7 +15,6 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://0004-cups-fix-multilib-install-file-conflicts.patch \ file://volatiles.99_cups \ file://cups-volatiles.conf \ - file://CVE-2023-32324.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2023-32324.patch b/meta/recipes-extended/cups/cups/CVE-2023-32324.patch deleted file mode 100644 index 40b89c9899..0000000000 --- a/meta/recipes-extended/cups/cups/CVE-2023-32324.patch +++ /dev/null @@ -1,36 +0,0 @@ -From 07cbffd11107eed3aaf1c64e35552aec20f792da Mon Sep 17 00:00:00 2001 -From: Zdenek Dohnal -Date: Thu, 1 Jun 2023 12:04:00 +0200 -Subject: [PATCH] cups/string.c: Return if `size` is 0 (fixes CVE-2023-32324) - -CVE: CVE-2023-32324 -Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/fd8bc2d32589] - -(cherry picked from commit fd8bc2d32589d1fd91fe1c0521be2a7c0462109e) -Signed-off-by: Sanjay Chitroda ---- - cups/string.c | 4 ++++ - 1 file changed, 4 insertions(+) - -diff --git a/cups/string.c b/cups/string.c -index 93cdad19..6ef58515 100644 ---- a/cups/string.c -+++ b/cups/string.c -@@ -1,6 +1,7 @@ - /* - * String functions for CUPS. - * -+ * Copyright © 2023 by OpenPrinting. - * Copyright © 2007-2019 by Apple Inc. - * Copyright © 1997-2007 by Easy Software Products. - * -@@ -730,6 +731,9 @@ _cups_strlcpy(char *dst, /* O - Destination string */ - size_t srclen; /* Length of source string */ - - -+ if (size == 0) -+ return (0); -+ - /* - * Figure out how much room is needed... - */ diff --git a/meta/recipes-extended/cups/cups_2.4.2.bb b/meta/recipes-extended/cups/cups_2.4.5.bb similarity index 51% rename from meta/recipes-extended/cups/cups_2.4.2.bb rename to meta/recipes-extended/cups/cups_2.4.5.bb index f5ca749bac..e1bb43aa3c 100644 --- a/meta/recipes-extended/cups/cups_2.4.2.bb +++ b/meta/recipes-extended/cups/cups_2.4.5.bb @@ -2,4 +2,4 @@ require cups.inc LIC_FILES_CHKSUM = "file://LICENSE;md5=3b83ef96387f14655fc854ddc3c6bd57" -SRC_URI[sha256sum] = "f03ccb40b087d1e30940a40e0141dcbba263f39974c20eb9f2521066c9c6c908" +SRC_URI[sha256sum] = "9a404de55f74525b0a6851df0cfdebfa1215aec0e7c2f7be6b9b09b6916fb000"