public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
* [PATCH] core205: Ship gdb
@ 2026-10-02 11:23 Adolf Belka
  2026-10-02 11:23 ` [PATCH] core205: Ship libpng Adolf Belka
                   ` (11 more replies)
  0 siblings, 12 replies; 13+ messages in thread
From: Adolf Belka @ 2026-10-02 11:23 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/core/205/filelists/gdb | 1 +
 1 file changed, 1 insertion(+)
 create mode 120000 config/rootfiles/core/205/filelists/gdb

diff --git a/config/rootfiles/core/205/filelists/gdb b/config/rootfiles/core/205/filelists/gdb
new file mode 120000
index 000000000..e3081af71
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/gdb
@@ -0,0 +1 @@
+../../../common/gdb
\ No newline at end of file
-- 
2.55.0



^ permalink raw reply	[flat|nested] 13+ messages in thread

* [PATCH] core205: Ship libpng
  2026-10-02 11:23 [PATCH] core205: Ship gdb Adolf Belka
@ 2026-10-02 11:23 ` Adolf Belka
  2026-10-02 11:23 ` [PATCH] core205: Ship pam Adolf Belka
                   ` (10 subsequent siblings)
  11 siblings, 0 replies; 13+ messages in thread
From: Adolf Belka @ 2026-10-02 11:23 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/core/205/filelists/libpng | 1 +
 1 file changed, 1 insertion(+)
 create mode 120000 config/rootfiles/core/205/filelists/libpng

diff --git a/config/rootfiles/core/205/filelists/libpng b/config/rootfiles/core/205/filelists/libpng
new file mode 120000
index 000000000..8ef96e2c1
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/libpng
@@ -0,0 +1 @@
+../../../common/libpng
\ No newline at end of file
-- 
2.55.0



^ permalink raw reply	[flat|nested] 13+ messages in thread

* [PATCH] core205: Ship pam
  2026-10-02 11:23 [PATCH] core205: Ship gdb Adolf Belka
  2026-10-02 11:23 ` [PATCH] core205: Ship libpng Adolf Belka
@ 2026-10-02 11:23 ` Adolf Belka
  2026-10-02 11:23 ` [PATCH] freeradius: Update to version 3.2.10 Adolf Belka
                   ` (9 subsequent siblings)
  11 siblings, 0 replies; 13+ messages in thread
From: Adolf Belka @ 2026-10-02 11:23 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/core/205/filelists/pam | 1 +
 1 file changed, 1 insertion(+)
 create mode 120000 config/rootfiles/core/205/filelists/pam

diff --git a/config/rootfiles/core/205/filelists/pam b/config/rootfiles/core/205/filelists/pam
new file mode 120000
index 000000000..660a1d80e
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/pam
@@ -0,0 +1 @@
+../../../common/pam
\ No newline at end of file
-- 
2.55.0



^ permalink raw reply	[flat|nested] 13+ messages in thread

* [PATCH] freeradius: Update to version 3.2.10
  2026-10-02 11:23 [PATCH] core205: Ship gdb Adolf Belka
  2026-10-02 11:23 ` [PATCH] core205: Ship libpng Adolf Belka
  2026-10-02 11:23 ` [PATCH] core205: Ship pam Adolf Belka
@ 2026-10-02 11:23 ` Adolf Belka
  2026-10-02 11:23 ` [PATCH] gdb: Update to version 18.1 Adolf Belka
                   ` (8 subsequent siblings)
  11 siblings, 0 replies; 13+ messages in thread
From: Adolf Belka @ 2026-10-02 11:23 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

- Update from version 3.2.8 to 3.2.10
- Update of rootfile
- Changelog
3.2.10
	Correct bug where detail file reader would not read files. Patch from Bjørn
	 Mork. Fixes #5870
3.2.9
Configuration changes
    Add protocol_error = yes configuration to clients. If set, the server can return
	Protocol-Error responses to the client.
    radclient can now suppress Message-Authenticator in Access-Request, when the
	input packet contains Message-Authenticator !* ANY Don't use this in production!
    Set suppress_secrets = true by default.
    Add connect_fail_interval to home_server configuration. If a connection fails,
	the server will wait this time before trying to connect again.
    Add certificate_fail_interval to home_server configuration. If a connection
	succeeds but the home_server certificate is invalid, the server will wait
	this time before trying to connect again.
    Add update section to home_server configuration. Status-Server packets can
	therefore be customized.
    Add cipher_suites to tls{} configuration. See raddb/sites-available/tls. This is
	mainly used to set the cipher suites for TLS-PSK with TLS 1.3.
Feature improvements
    Initial implementation of Protocol-Failure as per IETF draft. The functionality
	is disabled by default, but can be enabled via new configuration flags.
    Always allow Protocol-Error packet as valid response to any packet.
    Add Error-Cause attributes to CoA-NAK and Disconnect-NAK
    Added filter_username_nai to policy.d/filter, mainly for use in eduroam.
    Updates to VSCode default configuration.
    Cleanups and add log messages for rlm_proxy_rate_limit.
    Allow 389ds legacy PBKDF2_SHA256 to use arbitrary iteration count. (#5654)
    Amend policy insert_acct_class/acct_unique to work in environments with multiple
	Class attributes (#5337)
    Tweak sqlippool messages to make them clearer.
    Print log message if the server receives a correct authenticated proxy response
	packet, but which has an unexpected code. e.g. received Access-Accept in
	response to an Accounting-Request.
    New installations now set "suppress_secrets=true" by default. The server also
	prints messages in debug mode which explains why the secrets are being
	suppressed.
    Allow parallel build for Debian. Fixes #5774.
    Add RTBrick and other dictionaries.
    Add documentation for ntlm_auth and spaces in passwords. Addresses #5654.
Bug fixes
    Many minor bug fixes and cleanups.
    Fixes to RadSec.
    Many other fixes to socket and event handling, which enable increased scalability.
    Fix issues found with EAP-MSCHAPv2, EAP-PWD, and EAP-MD5.
    Fix run_dir (#5637) and MemoryLimit (#5639)
    Disable the PCRE JIT at run time if it can't allocate executable memory.
    Set selinux boolean to allow PCRE2 JIT
    If you set the clock 25 years in the future, don't spam systemd. Fixes #5642
    Don't load the OpenSSL legacy provider when built with --enable-fips-workaround.
	Fixes #5644.
    Address potential leaks when opening many RADIUS/TLS proxy sockets.
    Encode multiple DHCP Option 82 as one option, instead of as multiple options.
    Update the rlm_cache_redis driver to reconnect on connection failure. Fixes #5651.
    Tweaks to the processing state machine to handle more corner cases / race
	conditions. Thanks to Paul Dekkers for testing.
    Don't close the main listen socket for TCP. Fixes #5661.
    Fix rlm_dspk to properly support dynamic filenames.
    Don't crash in corner cases when running Post-Proxy-Type Fail.
    Use correct name offsets in proxy_rate_limit. Fixes #5675.
    push fallback virtual server to child thread. Fixes #5679.
    Correct corner case in hash table. Fixes #5680.
    Allow new proxy sockets after reaching "too many sockets", when we close an
	existing proxy connection. Fixes #5964.
    fix consistent load balancing. Fixes #5770.
    Address pthread APIs. Fixes #5772.
    Install headers needed to build modules. Fixes #5778.
    Initialize scope in IPv6 address lookups. Fixes #5798.
    Don't load legacy provider on --enable-fips-workaround. Fixes #5775.
    Hoist mutex lock in TLS sockets. Fixes #5480
    Fix occasional EAP-PWD authentication failure.
    Fix memcache storing of dates.
    Add more debugging information for TEAP. TEAP has limited utility, due to the
	incompleteness of the spec, and the severe limitations of the Windows TEAP
	supplicant.
    Return stats for "auth+acct" home servers. Fixes #5866.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/packages/freeradius | 18 ++++++++++++++----
 lfs/freeradius                       | 24 +++++++++++-------------
 2 files changed, 25 insertions(+), 17 deletions(-)

diff --git a/config/rootfiles/packages/freeradius b/config/rootfiles/packages/freeradius
index 411769253..fdd5a4598 100644
--- a/config/rootfiles/packages/freeradius
+++ b/config/rootfiles/packages/freeradius
@@ -250,6 +250,7 @@ etc/raddb
 #etc/raddb/mods-enabled/detail
 #etc/raddb/mods-enabled/detail.log
 #etc/raddb/mods-enabled/digest
+#etc/raddb/mods-enabled/dpsk
 #etc/raddb/mods-enabled/dynamic_clients
 #etc/raddb/mods-enabled/eap
 #etc/raddb/mods-enabled/echo
@@ -331,9 +332,12 @@ usr/bin/map_unit
 usr/bin/rad_counter
 usr/bin/radattr
 usr/bin/radclient
+usr/bin/radconf2json
 usr/bin/radcrypt
+usr/bin/raddict2json
 usr/bin/radeapclient
 usr/bin/radlast
+usr/bin/radmod2json
 usr/bin/radsecret
 usr/bin/radsniff
 usr/bin/radsqlrelay
@@ -346,10 +350,13 @@ usr/bin/smbencrypt
 #usr/include/freeradius
 #usr/include/freeradius/attributes.h
 #usr/include/freeradius/autoconf.h
+#usr/include/freeradius/automask.h
 #usr/include/freeradius/base64.h
 #usr/include/freeradius/build.h
+#usr/include/freeradius/clients.h
 #usr/include/freeradius/conf.h
 #usr/include/freeradius/conffile.h
+#usr/include/freeradius/connection.h
 #usr/include/freeradius/detail.h
 #usr/include/freeradius/event.h
 #usr/include/freeradius/features.h
@@ -357,6 +364,8 @@ usr/bin/smbencrypt
 #usr/include/freeradius/hash.h
 #usr/include/freeradius/heap.h
 #usr/include/freeradius/libradius.h
+#usr/include/freeradius/listen.h
+#usr/include/freeradius/log.h
 #usr/include/freeradius/map.h
 #usr/include/freeradius/md4.h
 #usr/include/freeradius/md5.h
@@ -364,6 +373,7 @@ usr/bin/smbencrypt
 #usr/include/freeradius/modcall.h
 #usr/include/freeradius/modules.h
 #usr/include/freeradius/packet.h
+#usr/include/freeradius/process.h
 #usr/include/freeradius/rad_assert.h
 #usr/include/freeradius/radius.h
 #usr/include/freeradius/radiusd.h
@@ -411,9 +421,11 @@ usr/bin/smbencrypt
 #usr/include/freeradius/tcp.h
 #usr/include/freeradius/threads.h
 #usr/include/freeradius/tls.h
+#usr/include/freeradius/tmpl.h
 #usr/include/freeradius/token.h
 #usr/include/freeradius/udpfromto.h
 #usr/include/freeradius/vqp.h
+#usr/include/freeradius/xlat.h
 #usr/lib/freeradius
 #usr/lib/freeradius/libfreeradius-dhcp.a
 #usr/lib/freeradius/libfreeradius-dhcp.la
@@ -597,9 +609,6 @@ usr/lib/freeradius/rlm_sqlippool.so
 #usr/lib/freeradius/rlm_totp.a
 #usr/lib/freeradius/rlm_totp.la
 usr/lib/freeradius/rlm_totp.so
-#usr/lib/freeradius/rlm_unbound.a
-#usr/lib/freeradius/rlm_unbound.la
-usr/lib/freeradius/rlm_unbound.so
 #usr/lib/freeradius/rlm_unix.a
 #usr/lib/freeradius/rlm_unix.la
 usr/lib/freeradius/rlm_unix.so
@@ -686,6 +695,7 @@ usr/sbin/radmin
 #usr/share/doc/freeradius/antora/modules/developers/pages/coverage.adoc
 #usr/share/doc/freeradius/antora/modules/developers/pages/index.adoc
 #usr/share/doc/freeradius/antora/modules/developers/pages/profile.adoc
+#usr/share/doc/freeradius/antora/modules/developers/pages/protocol-error.adoc
 #usr/share/doc/freeradius/antora/modules/developers/pages/release-method.adoc
 #usr/share/doc/freeradius/antora/modules/howto
 #usr/share/doc/freeradius/antora/modules/howto/nav.adoc
@@ -899,7 +909,6 @@ usr/sbin/radmin
 #usr/share/doc/freeradius/rfc/draft-kamath-pppext-eap-mschapv2-00.txt
 #usr/share/doc/freeradius/rfc/draft-sterman-aaa-sip-00.txt
 #usr/share/doc/freeradius/rfc/genref.pl
-#usr/share/doc/freeradius/rfc/leap.txt
 #usr/share/doc/freeradius/rfc/per-rfc.pl
 #usr/share/doc/freeradius/rfc/rewrite.pl
 #usr/share/doc/freeradius/rfc/rfc1157.txt
@@ -1198,6 +1207,7 @@ usr/share/freeradius
 #usr/share/freeradius/dictionary.riverbed
 #usr/share/freeradius/dictionary.riverstone
 #usr/share/freeradius/dictionary.roaringpenguin
+#usr/share/freeradius/dictionary.rtbrick
 #usr/share/freeradius/dictionary.ruckus
 #usr/share/freeradius/dictionary.ruggedcom
 #usr/share/freeradius/dictionary.sangoma
diff --git a/lfs/freeradius b/lfs/freeradius
index 1a5ea7117..ec13b8ce3 100644
--- a/lfs/freeradius
+++ b/lfs/freeradius
@@ -26,7 +26,7 @@ include Config
 
 SUMMARY    = RADIUS Server
 
-VER        = 3.2.8
+VER        = 3.2.10
 
 THISAPP    = freeradius-server-$(VER)
 DL_FILE    = $(THISAPP).tar.bz2
@@ -34,7 +34,7 @@ DL_FROM    = $(URL_IPFIRE)
 DIR_APP    = $(DIR_SRC)/$(THISAPP)
 TARGET     = $(DIR_INFO)/$(THISAPP)
 PROG       = freeradius
-PAK_VER    = 26
+PAK_VER    = 27
 
 DEPS       = libtalloc samba
 
@@ -48,7 +48,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = 6266c00c68cbb02de65f88d976453fdcdda552d7554199030640f9bcd60f208afaf75aaac8fbf0a2eea0022eb23ad7b809cb910d48618261ea9f52100732c469
+$(DL_FILE)_BLAKE2 = 2e4b88f13c5742e60fd5b2931e93cb861b8fd0b9b12ba340a08f185884b64e49f035e14387a19b9ae4ae7c71ec9249132c0ccf19febfcdefd4725ddef0877a77
 
 install : $(TARGET)
 
@@ -83,16 +83,14 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects))
 	@rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar axf $(DIR_DL)/$(DL_FILE)
 	cd $(DIR_APP) && patch -Np1 < $(DIR_SRC)/src/patches/freeradius-no-buildtime-cert-gen.patch
 	$(UPDATE_AUTOMAKE)
-	cd $(DIR_APP) && \
-		./configure \
-			--prefix=/usr \
-			--sysconfdir=/etc \
-			--libdir=/usr/lib/freeradius \
-			--localstatedir=/var \
-			--with-threads \
-			--disable-openssl-version-check \
-			LDFLAGS="$(LDFLAGS)"
-
+	cd $(DIR_APP) && ./configure \
+				--prefix=/usr \
+				--sysconfdir=/etc \
+				--libdir=/usr/lib/freeradius \
+				--localstatedir=/var \
+				--with-threads \
+				--disable-openssl-version-check \
+				LDFLAGS="$(LDFLAGS)"
 	cd $(DIR_APP) && make $(MAKETUNING)
 	cd $(DIR_APP) && make install
 
-- 
2.55.0



^ permalink raw reply	[flat|nested] 13+ messages in thread

* [PATCH] gdb: Update to version 18.1
  2026-10-02 11:23 [PATCH] core205: Ship gdb Adolf Belka
                   ` (2 preceding siblings ...)
  2026-10-02 11:23 ` [PATCH] freeradius: Update to version 3.2.10 Adolf Belka
@ 2026-10-02 11:23 ` Adolf Belka
  2026-10-02 11:23 ` [PATCH] git: Update to version 2.56.0 Adolf Belka
                   ` (7 subsequent siblings)
  11 siblings, 0 replies; 13+ messages in thread
From: Adolf Belka @ 2026-10-02 11:23 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

- Update from version 17.2 to 18.1
- Update of rootfile
- Changelog
18.1
Major improvements to the Windows native target:
    Non-stop mode is now supported (requires Windows 10 or later).
    Scheduler-locking (“set scheduler-locking on”) now works.
    Native Thread Local Storage (TLS) variables are now supported.
    On the Windows Terminal console, GDB now supports true-color 24-bit colors, and,
	when the output codepage is 65001, emoji styling and UTF-8 text in general
	(the host charset is then set to UTF-8 automatically).
    File names are now consistently shown with forward slashes, instead of a mix of
	slash styles, e.g. “C:/proj/src/main.c” instead of “C:/proj/src.c”. This
	affects all interpreters (CLI, TUI, GDB/MI, DAP) and everywhere GDB shows a
	file or directory name.
GDB now adds all type symbols to the .gdb_index section, fixing cases where GDB could
	fail to find a type when relying on the index. Existing indexes should be
	regenerated.
Improved handling of inferior arguments:
    “set args”, “run”, “start” and “starti” now accept arguments containing a newline
	character, within a quoted argument.
    New –no-escape-args command line option for GDB, an alternative to –args that
	does not escape special shell characters within the arguments. gdbserver
	accepts a –no-escape-args flag with the same effect on the inferior arguments.
    When connecting to a remote server that supports the new qExecAndArgs packet,
	GDB copies the argument string from the server into its own ‘args’ setting,
	so that the arguments are visible with “show args” and reused by subsequent runs.
When connected to an extended-remote target, GDB can now set the ‘remote exec-file’
	automatically, using the current executable, if the remote was not started
	with an executable and the user did not set one explicitly.
The add-inferior, clone-inferior and MI -add-inferior commands now warn and create
	the new inferior without a connection when the current connection cannot be
	shared (e.g. core files, or the Windows native target). Sharing these
	previously tended to crash GDB.
“info locals” now shows a “shadowed” annotation and location information for
	variables that shadow, or are shadowed by, others.
Support for the Floating Point Mode Register (FPMR) on AArch64.
GDB now supports libipt v2.2 events originating from Event Tracing (“set record
	btrace pt event-tracing on”) on a FRED-enabled system, and from Trigger Tracing.
GDB now supports arbitrary (non-standard) baud rates for serial connections on
	systems whose libc accepts them through cfsetispeed/cfsetospeed, such as
	glibc 2.42 and later, and GNU Hurd.
“info inferiors” now shows the core file loaded in an inferior, if any.
New “essential” help command class, listing what we believe is close to a minimal set
	of commands for a new GDB user.
New commands:
    “set/show/unset local-environment”, analogs of the “environment” commands,
	affecting the environment of subprocesses started by GDB itself, such as
	those started by “shell” and “pipe”.
    “save history”, “save skip” and “save user”, to save the command history, the
	current skips, and the user-defined commands to a file.
    “info proc environ”, to print the initial environment variables of a process
	(Linux only).
    “set/show progress-bars enabled”, to disable the progress bars GDB shows for long
	operations, such as while debuginfod downloads content.
    “delete skip”, “enable skip” and “disable skip”, new aliases for “skip delete”,
	“skip enable” and “skip disable”.
    “set/show debug gnu-ifunc” and “set/show debug ctf”.
New targets:
    GNU/Linux/MicroBlaze (gdbserver) microblazeel-*linux*
    AArch64 MinGW aarch64-*-mingw*
Python API enhancements:
    New gdb.Corefile class, representing a loaded core file, with the new
	Inferior.corefile attribute, plus the new gdb.CorefileMappedFile and
	gdb.CorefileMappedFileRegion types describing the files mapped when the core
	file was created.
    New gdb.Style class, gdb.StyleParameterSet class, and gdb.INTENSITY_* constants,
	for representing styles and creating custom “set/show style NAME …”
	parameters. gdb.write() takes a new optional ‘style’ argument.
    New gdb.events.selected_context event registry, emitting a SelectedContextEvent
	whenever the user changes the selected inferior, thread or frame.
    New gdb.events.corefile_changed event registry, emitting a CorefileChangedEvent
	whenever the core file of an inferior changes.
    New gdb.Symtab.source_lines method, returning the source lines of the file
	associated with a symtab.
    The Architecture.disassemble method accepts a new ‘styling’ argument, to get ANSI
	escape sequences in the assembly strings.
    New gdb.Block.ranges attribute, listing the ranges of a block.
Debugger Adapter Protocol changes:
    Unhandled Ada exceptions can now be caught using the “unhandled” exception filter.
    The launch and attach requests accept a new adaSourceCharset parameter, and the
	attach request accepts a new coreFile parameter.
    Constants are now returned in scopes.
Remote protocol changes:
    New qExecAndArgs packet, returning the executable file name and argument string
	the server was started with.
    New single-inf-arg qSupported feature, letting GDB send the inferior arguments as
	a single string in the vRun packet.
Incompatible changes:
    Support for the stabs and mdebug debug information formats, and for the dbx
	binary file format, has been removed.
    Support for the Common Trace Format (CTF) has been removed: trace information is
	now saved exclusively in GDB’s own “tfile” format, the “target ctf” command
	is gone, and “tsave” and MI “-trace-save” no longer accept the “-ctf” flag.
	The –with-babeltrace configure option has been removed as well.
    Support for .gdb_index sections older than version 7 has been removed.
    Support for DWP (DWARF Package File) version 1 has been removed.
    The format of execution records saved by “record save” has changed; previous
	formats are no longer supported.
    Guile 2.2 is now the minimum supported Guile version, and the deprecated memory
	port buffer size procedures have been removed; use ‘setvbuf’ instead.
    The “maint check psymtabs”, “maint info psymtabs” and “maint print psymbols”
	commands have been removed, as GDB no longer uses partial symbol tables
	internally.
    “maintenance info program-spaces” no longer displays the core file name; use
	“info inferiors” instead.
    GDB no longer supports AIX 7.1; the minimum supported version is now AIX 7.2 TL5,
	and only DWARF debug information is supported on AIX going forward.
    The s390 32-bit target (s390-*) is deprecated and planned for removal in a future
	release, along with the elf32-s390 target format. configure now errors out
	for this target, which can be overridden with –enable-obsolete. The s390
	64-bit target (s390x-*) remains supported.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/common/gdb |  2 +-
 lfs/gdb                     | 19 +++++++++----------
 2 files changed, 10 insertions(+), 11 deletions(-)

diff --git a/config/rootfiles/common/gdb b/config/rootfiles/common/gdb
index 0cced1090..11dc18355 100644
--- a/config/rootfiles/common/gdb
+++ b/config/rootfiles/common/gdb
@@ -80,6 +80,7 @@
 #usr/share/gdb/syscalls/netbsd.xml
 #usr/share/gdb/syscalls/ppc-linux.xml
 #usr/share/gdb/syscalls/ppc64-linux.xml
+#usr/share/gdb/syscalls/riscv-linux.xml
 #usr/share/gdb/syscalls/s390-linux.xml
 #usr/share/gdb/syscalls/s390x-linux.xml
 #usr/share/gdb/syscalls/sparc-linux.xml
@@ -98,7 +99,6 @@
 #usr/share/info/gdb.info-7
 #usr/share/info/gdb.info-8
 #usr/share/info/gdb.info-9
-#usr/share/info/stabs.info
 #usr/share/man/man1/gcore.1
 #usr/share/man/man1/gdb-add-index.1
 #usr/share/man/man1/gdb.1
diff --git a/lfs/gdb b/lfs/gdb
index 426a99226..bba92a46e 100644
--- a/lfs/gdb
+++ b/lfs/gdb
@@ -24,7 +24,7 @@
 
 include Config
 
-VER        = 17.2
+VER        = 18.1
 
 THISAPP    = gdb-$(VER)
 DL_FILE    = $(THISAPP).tar.xz
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = 3c6c893e1d26d534918fb07b64f2e5b368825a64f888171f07443c5ebed456e7c26ed223d78bf304ee5f145c6f3c08c790c993c7b955d168e2fd8e656c6e1e9a
+$(DL_FILE)_BLAKE2 = 9cf68cd96ecd1b2f51235f80f30d4024eadea7e11fe8af1cde0103176c622b770d79fde2205739fad8fe314ffecddd450626976e1897b04899027d0d88f30e1d
 
 install : $(TARGET)
 
@@ -71,14 +71,13 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects))
 	@$(PREBUILD)
 	@rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar axf $(DIR_DL)/$(DL_FILE)
 	cd $(DIR_APP) && mkdir -pv build
-	cd $(DIR_APP)/build && \
-		../configure \
-			--prefix=/usr \
-			--sysconfdir=/etc \
-			--disable-nls \
-			--enable-tui \
-			--with-system-readline \
-			--with-python=/usr/bin/python3
+	cd $(DIR_APP)/build && ../configure \
+					--prefix=/usr \
+					--sysconfdir=/etc \
+					--disable-nls \
+					--enable-tui \
+					--with-system-readline \
+					--with-python=/usr/bin/python3
 	cd $(DIR_APP)/build && make $(MAKETUNING)
 	cd $(DIR_APP)/build && make install
 	@rm -rf $(DIR_APP)
-- 
2.55.0



^ permalink raw reply	[flat|nested] 13+ messages in thread

* [PATCH] git: Update to version 2.56.0
  2026-10-02 11:23 [PATCH] core205: Ship gdb Adolf Belka
                   ` (3 preceding siblings ...)
  2026-10-02 11:23 ` [PATCH] gdb: Update to version 18.1 Adolf Belka
@ 2026-10-02 11:23 ` Adolf Belka
  2026-10-02 11:23 ` [PATCH] iperf3: Update to version 3.22 Adolf Belka
                   ` (6 subsequent siblings)
  11 siblings, 0 replies; 13+ messages in thread
From: Adolf Belka @ 2026-10-02 11:23 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

- Update from version 2.55.0 to 2.56.0
- Update of rootfile
- Changelog
2.56.0
	This too large to include here (nearly 1000 lines) For details see following
	 file in the tarball /Documentation/RelNotes/2.56.0.adoc

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/packages/git | 2 ++
 lfs/git                       | 6 +++---
 2 files changed, 5 insertions(+), 3 deletions(-)

diff --git a/config/rootfiles/packages/git b/config/rootfiles/packages/git
index ef88227d3..074072ae1 100644
--- a/config/rootfiles/packages/git
+++ b/config/rootfiles/packages/git
@@ -321,6 +321,7 @@ usr/share/git-core/templates/info/exclude
 #usr/share/gitweb/static/git-logo.png
 #usr/share/gitweb/static/gitweb.css
 #usr/share/gitweb/static/gitweb.js
+#usr/share/locale/af/LC_MESSAGES/git.mo
 #usr/share/locale/bg/LC_MESSAGES/git.mo
 #usr/share/locale/ca/LC_MESSAGES/git.mo
 #usr/share/locale/de/LC_MESSAGES/git.mo
@@ -333,6 +334,7 @@ usr/share/git-core/templates/info/exclude
 #usr/share/locale/it/LC_MESSAGES/git.mo
 #usr/share/locale/ko/LC_MESSAGES/git.mo
 #usr/share/locale/pl/LC_MESSAGES/git.mo
+#usr/share/locale/pt_BR/LC_MESSAGES/git.mo
 #usr/share/locale/pt_PT/LC_MESSAGES/git.mo
 #usr/share/locale/ru/LC_MESSAGES/git.mo
 #usr/share/locale/sv/LC_MESSAGES/git.mo
diff --git a/lfs/git b/lfs/git
index 461f6a130..6a46eba8e 100644
--- a/lfs/git
+++ b/lfs/git
@@ -24,7 +24,7 @@
 
 include Config
 
-VER        = 2.55.0
+VER        = 2.56.0
 SUMMARY    = Fast, scalable, distributed revision control system
 
 THISAPP    = git-$(VER)
@@ -33,7 +33,7 @@ DL_FROM    = $(URL_IPFIRE)
 DIR_APP    = $(DIR_SRC)/$(THISAPP)
 TARGET     = $(DIR_INFO)/$(THISAPP)
 PROG       = git
-PAK_VER    = 43
+PAK_VER    = 44
 
 DEPS       = perl-Authen-SASL perl-Net-SMTP-SSL
 
@@ -47,7 +47,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = 7666d99f1002a20ec3ca89fdfcbe1156cf6ed3bbc3823a8e7903d0ff177db91ce1309cf17466d813338e83d9782f748b1dc450ce3fa8bae82211a61042acea26
+$(DL_FILE)_BLAKE2 = 578a2e503a085acd1a98d6623b6294916397979a6089f3ccb063dfa39a4f0a8349bb3f4f8ce6de508ef0e1b53c259e33c791a495b090e54d62d213ccd28f62b4
 
 install : $(TARGET)
 
-- 
2.55.0



^ permalink raw reply	[flat|nested] 13+ messages in thread

* [PATCH] iperf3: Update to version 3.22
  2026-10-02 11:23 [PATCH] core205: Ship gdb Adolf Belka
                   ` (4 preceding siblings ...)
  2026-10-02 11:23 ` [PATCH] git: Update to version 2.56.0 Adolf Belka
@ 2026-10-02 11:23 ` Adolf Belka
  2026-10-02 11:23 ` [PATCH] libpng: Update to version 1.6.59 Adolf Belka
                   ` (5 subsequent siblings)
  11 siblings, 0 replies; 13+ messages in thread
From: Adolf Belka @ 2026-10-02 11:23 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

- Update from version 3.21 to 3.22
- No change in rootfile
- 4 CVE fixes
- Changelog
3.22
* Security notes
    * Thanks to Claude and Ada Logics for finding and reporting two
      potential security vulnerabilities. One is a remote
      use-after-free in iperf_server_api.c (ANT-2026-E5BA80X9 /
      CVE-2026-101283) and the other is a heap buffer overflow in
      iperf_auth.c (ANT-2026-FXH14FHV / CVE-2026-101276).
    * Thanks to Justin Stitt for reporting and fixing a heap-buffer
      overflow was fixed in iperf_auth.c (PR #2027).
    * Thanks to Ravindu Lakmina Munaweera (Github: @Ravi-lk) for
      reporting and fixing a DOS infinite-loop (CVE-2026-102253).
    * Thanks to Dirk Müller for finding and reporting an issue with
      test parameters (PR #2039, CVE-2026-71217).
    * The iperf-3.18 release notes were updated to reflect that a code
      change in that version addresses CVE-2026-71218.
* Notable user-visible changes
    * Attempting to set zero parallel streams is no longer allowed (PR
      #2048).
    * Zerocopy and rx-copy are now allowed in the case of reverse
      direction tests and the server (sending side) supports these
      features but the client (receiving side) does not (#2045,
      PR #2044).
    * The limit on GSO_MAX_DG_IN_BF was fixed to limit the number of segments
      to the maximum allowed (#2032 / PR #2033). This change unbreaks
      GSO for small message sizes.
* Notable developer-visible changes
    * In iperf_auth.c, in addition to fixing the heap buffer overflow, the
      return value of several functions is checked (PR #2046, PR #2040).
    * Several file descriptor leaks have been fixed (PR #2034).
    * In iperf_tcp, connections now timeout to prevent a race condition in
      accepting new connections to avoid a deadlock (#2029, PR #2030).
    * Periodic timers are now cancelled at the end of a test (#2018,
      PR #2021).
    * DSCP/TOS is now correctly set in the first UDP/TCP stream packet
      (#510, #830, PR #2047).

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 lfs/iperf3 | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/lfs/iperf3 b/lfs/iperf3
index 7c4095ed9..01b0f3252 100644
--- a/lfs/iperf3
+++ b/lfs/iperf3
@@ -26,7 +26,7 @@ include Config
 
 SUMMARY    = A tool to measure network performance
 
-VER        = 3.21
+VER        = 3.22
 
 THISAPP    = iperf-$(VER)
 DL_FILE    = $(THISAPP).tar.gz
@@ -34,7 +34,7 @@ DL_FROM    = $(URL_IPFIRE)
 DIR_APP    = $(DIR_SRC)/$(THISAPP)
 TARGET     = $(DIR_INFO)/$(THISAPP)
 PROG       = iperf3
-PAK_VER    = 9
+PAK_VER    = 10
 
 DEPS       =
 
@@ -51,7 +51,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = 696a13caaa5cf52a69c65566ae4d2d8788a4225d689d32e73306f5174dad141c92ea3acdda9a929803a1e57eee6844350be2da749e5f44c48bf0ab7890e97745
+$(DL_FILE)_BLAKE2 = 1e06b7faca73002b760dba4bab1349140970daaa427e46a2ac5b96030494b6465e6875d58f550283e608bfcdcea76a13857d3b2d69f46a8bb78cfe0964ee95b2
 
 install : $(TARGET)
 check : $(patsubst %,$(DIR_CHK)/%,$(objects))
-- 
2.55.0



^ permalink raw reply	[flat|nested] 13+ messages in thread

* [PATCH] libpng: Update to version 1.6.59
  2026-10-02 11:23 [PATCH] core205: Ship gdb Adolf Belka
                   ` (5 preceding siblings ...)
  2026-10-02 11:23 ` [PATCH] iperf3: Update to version 3.22 Adolf Belka
@ 2026-10-02 11:23 ` Adolf Belka
  2026-10-02 11:23 ` [PATCH] ntfs-3g: Update to version 2026.9.28 Adolf Belka
                   ` (4 subsequent siblings)
  11 siblings, 0 replies; 13+ messages in thread
From: Adolf Belka @ 2026-10-02 11:23 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

- Update from version 1.6.58 to 1.6.59
- Update of rootfile
- 1 CVE fix
- Changelog
1.6.59
  Fixed CVE-2026-46675 (medium severity):
    Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt
    or iCCP decompression.
    (Reported independently by Ze Sheng and
    <JasonHonKL@users.noreply.github.com>.)
  Fixed a regression introduced in version 1.6.47 that caused libpng to reject
    hIST chunks in their correct position, after PLTE.
    (Contributed by Yuki Sekiguchi.)
  Prevented a double free of `png_struct` members after an allocation failure.
    (Contributed by Anthony Hurtado.)
  Applied fixes and updates to the CMake build.
  Adopted the REUSE Specification for licensing the CI files.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/common/libpng | 2 +-
 lfs/libpng                     | 4 ++--
 2 files changed, 3 insertions(+), 3 deletions(-)

diff --git a/config/rootfiles/common/libpng b/config/rootfiles/common/libpng
index ef7d888f3..5c7cf4867 100644
--- a/config/rootfiles/common/libpng
+++ b/config/rootfiles/common/libpng
@@ -16,7 +16,7 @@ usr/lib/libpng.so
 #usr/lib/libpng16.la
 usr/lib/libpng16.so
 usr/lib/libpng16.so.16
-usr/lib/libpng16.so.16.58.0
+usr/lib/libpng16.so.16.59.0
 #usr/lib/pkgconfig/libpng.pc
 #usr/lib/pkgconfig/libpng16.pc
 #usr/share/man/man3/libpng.3
diff --git a/lfs/libpng b/lfs/libpng
index 6aa7fbee9..2375432b0 100644
--- a/lfs/libpng
+++ b/lfs/libpng
@@ -24,7 +24,7 @@
 
 include Config
 
-VER        = 1.6.58
+VER        = 1.6.59
 
 THISAPP    = libpng-$(VER)
 DL_FILE    = $(THISAPP).tar.xz
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = 51042e8f2b56d469b516db9cbde6d4b6813a62d1b7117898ba32a9a5ac5cd73832c627d7377745e5d5154aade6ec6928fc6b9cd9b96885f64b7ca7df19ca40ec
+$(DL_FILE)_BLAKE2 = f2656b0d9a3865faf957e8600a7617516d9139d15c6d7581c06b4829b4c9338ec5f747e4ccfcc49b6b9f5a96f0476121eda99457469c8e1cfecd8ecc3b1697ed
 
 install : $(TARGET)
 
-- 
2.55.0



^ permalink raw reply	[flat|nested] 13+ messages in thread

* [PATCH] ntfs-3g: Update to version 2026.9.28
  2026-10-02 11:23 [PATCH] core205: Ship gdb Adolf Belka
                   ` (6 preceding siblings ...)
  2026-10-02 11:23 ` [PATCH] libpng: Update to version 1.6.59 Adolf Belka
@ 2026-10-02 11:23 ` Adolf Belka
  2026-10-02 11:23 ` [PATCH] pam: Update to version 1.7.3 Adolf Belka
                   ` (3 subsequent siblings)
  11 siblings, 0 replies; 13+ messages in thread
From: Adolf Belka @ 2026-10-02 11:23 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

- Update from version 2026.7.7 to 2026.9.28
- Update of rootfile
- 8 CVE fixes in 2026.9.18
- Changelog
2026.9.28
	Fix regression caused by overly strict return value check after MST fixups
	 which was introduced in a security hardening commit (issues #217 and #218).
	Fix option parsing issues in ntfslabel preventing setting labels beginning
	 with '-' (issue #177).
	Fix various low-impact instances of use-after-free and improper realloc usage
	 (issue #153).
2026.9.18Guard against multiple creator-owner and creator-group ACEs during ACL inheritance.
	(ntfscat) Fix missing cleanup of opened attribute on error (issue #212).
	Fix heap out of bounds read/write in ntfs_ie_add_vcn(). (GHSA-r6xj-6488-p8mv,
	 CVE pending)
	Fix heap data corruption in ntfs_mapping_pairs_decompress_i().
	 (GHSA-mc3c-983p-wqm8, CVE pending)
	Fix heap buffer overflow in ntfs_external_attr_find(). (GHSA-wf3w-fjjg-x4w3,
	 CVE pending)
	Fix heap buffer overflow in ntfs_ea_check_wsldev(). (GHSA-2c97-47cr-9xr8,
	 CVE pending)
	Fix heap buffer overflow in ntfs_check_restart_area(). (GHSA-xrvx-6jrp-4q3x,
	 CVE pending)
	Fix denial-of-service in ntfs_inode_attach_all_extents().
	 (GHSA-jcjj-9262-6j6p, CVE pending)
	Fix heap buffer overflow in ntfs_same_sid(). (GHSA-x98j-3g35-f59x, CVE pending)
	Fix heap buffer overflow in ntfs_acl_owner(). (GHSA-pc48-m7cx-qf72, CVE pending)
	(ntfsresize) Fix stale $MFTMirr data when the first extent of $MFT is
	 relocated (issue #209).

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/common/ntfs-3g | 4 ++--
 lfs/ntfs-3g                     | 4 ++--
 2 files changed, 4 insertions(+), 4 deletions(-)

diff --git a/config/rootfiles/common/ntfs-3g b/config/rootfiles/common/ntfs-3g
index 65d958495..0e96e6200 100644
--- a/config/rootfiles/common/ntfs-3g
+++ b/config/rootfiles/common/ntfs-3g
@@ -1,8 +1,8 @@
 bin/lowntfs-3g
 bin/ntfs-3g
 #lib/libntfs-3g.so
-lib/libntfs-3g.so.90
-lib/libntfs-3g.so.90.0.0
+lib/libntfs-3g.so.91
+lib/libntfs-3g.so.91.0.0
 sbin/mkfs.ntfs
 sbin/mount.lowntfs-3g
 sbin/mount.ntfs-3g
diff --git a/lfs/ntfs-3g b/lfs/ntfs-3g
index d7c4eb20c..7a34a792c 100644
--- a/lfs/ntfs-3g
+++ b/lfs/ntfs-3g
@@ -24,7 +24,7 @@
 
 include Config
 
-VER        = 2026.7.7
+VER        = 2026.9.28
 
 THISAPP    = ntfs-3g-$(VER)
 DL_FILE    = ntfs-3g_ntfsprogs-$(VER).tgz
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = 2cdeeeb00a9274282e3455bd2827f388b11a5f69b06f85c7655e175e493269b4e9447843de4ef69748d406e58df5d3bf5832086337d74dfd5a9bcf3e47e49b2f
+$(DL_FILE)_BLAKE2 = 9afdaa18d8748cadcc9426e98350c3b56b7fbd682f643b8f8ca991207182b8ffb4dc508e52b3f5d3d8da14fc28e521f7f73f3fcbc84c409edbd27e2c9be28ac7
 
 install : $(TARGET)
 
-- 
2.55.0



^ permalink raw reply	[flat|nested] 13+ messages in thread

* [PATCH] pam: Update to version 1.7.3
  2026-10-02 11:23 [PATCH] core205: Ship gdb Adolf Belka
                   ` (7 preceding siblings ...)
  2026-10-02 11:23 ` [PATCH] ntfs-3g: Update to version 2026.9.28 Adolf Belka
@ 2026-10-02 11:23 ` Adolf Belka
  2026-10-02 11:23 ` [PATCH] pcre2: Update to version 10.49 Adolf Belka
                   ` (2 subsequent siblings)
  11 siblings, 0 replies; 13+ messages in thread
From: Adolf Belka @ 2026-10-02 11:23 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

- Update from version 1.7.2 to 1.7.3
- Update of rootfile
- Changelog
1.7.3
	* pam_unix: removed support for creating new DES/bigcrypt hashed passwords.
	  Login with existing DES/bigcrypt passwords is still possible.
	* pam_unix: changed the default hash algorithm from DES to SHA512.
	* pam_unix: always use unix_update helper if SELinux is enabled.
	* pam_unix: fixed option parsing that could silently ignore "quiet" and
	  "minlen=" depending on configuration line order.
	* pam_access: fixed matching of fully qualified usernames.
	* pam_env: fixed buffer allocation that could result in insufficient space.
	* pam_faillock: fixed tally loss under concurrent auth failures that could
	  allow the deny= threshold to be bypassed.
	* pam_faillock: added logging when preauth denies access to a locked account.
	* pam_group: fixed out-of-bounds read in wildcard matching.
	* pam_limits: fixed maxlogins/maxsyslogins limits that could incorrectly
	  deny login.
	* pam_namespace: fixed resource leaks on configuration parse errors.
	* pam_pwhistory: allow earlier passwords when remember count is reduced.
	* pam_selinux: fixed memory leaks and corrected swapped arguments in
	  log messages.
	* pam_sepermit: fixed crash on malformed config lines, hardened lock file
	  handling, and fixed leaking file descriptors on exec.
	* pam_succeed_if: fixed broken ruser matching and prevented logging unknown
	  user names in plaintext.
	* pam_time: fixed out-of-bounds read in wildcard matching, fixed day-of-week
	  parsing, and ignore rules with malformed time fields.
	* pam_umask: validate umask, pri and ulimit values in GECOS.
	* pam_userdb: fixed password comparison timing leak.
	* Multiple minor bug fixes, build fixes, portability fixes,
	  documentation improvements, and translation updates.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/common/pam | 5 +++--
 lfs/pam                     | 4 ++--
 2 files changed, 5 insertions(+), 4 deletions(-)

diff --git a/config/rootfiles/common/pam b/config/rootfiles/common/pam
index 18826b21e..5fd9332cc 100644
--- a/config/rootfiles/common/pam
+++ b/config/rootfiles/common/pam
@@ -82,8 +82,6 @@ usr/lib/libpamc.so.0.82.1
 #usr/share/locale/am
 #usr/share/locale/am/LC_MESSAGES
 #usr/share/locale/am/LC_MESSAGES/Linux-PAM.mo
-#usr/share/locale/ar
-#usr/share/locale/ar/LC_MESSAGES
 #usr/share/locale/ar/LC_MESSAGES/Linux-PAM.mo
 #usr/share/locale/as
 #usr/share/locale/as/LC_MESSAGES
@@ -143,6 +141,9 @@ usr/lib/libpamc.so.0.82.1
 #usr/share/locale/it/LC_MESSAGES/Linux-PAM.mo
 #usr/share/locale/ja/LC_MESSAGES/Linux-PAM.mo
 #usr/share/locale/ka/LC_MESSAGES/Linux-PAM.mo
+#usr/share/locale/kab
+#usr/share/locale/kab/LC_MESSAGES
+#usr/share/locale/kab/LC_MESSAGES/Linux-PAM.mo
 #usr/share/locale/kk/LC_MESSAGES/Linux-PAM.mo
 #usr/share/locale/km
 #usr/share/locale/km/LC_MESSAGES
diff --git a/lfs/pam b/lfs/pam
index e2d635480..85c06a65d 100644
--- a/lfs/pam
+++ b/lfs/pam
@@ -24,7 +24,7 @@
 
 include Config
 
-VER        = 1.7.2
+VER        = 1.7.3
 
 THISAPP    = Linux-PAM-$(VER)
 DL_FILE    = $(THISAPP).tar.xz
@@ -45,7 +45,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = d7ebfac4393af3f889fef973946f1e6d60f118f2e048448708c5fdf0ef7fa7780945cda3b0abf6e0e2e15bbc2dd23be52389efabd00647381b3bc971f1aadcd8
+$(DL_FILE)_BLAKE2 = 2476e5b08f8e4c3e013f8ee22d858da79e9074160d396b504400c1f7ee490df9b432b226d18ae58e6f5c77a0a31709d363b76c800cd86953237f7e534a317358
 
 install : $(TARGET)
 
-- 
2.55.0



^ permalink raw reply	[flat|nested] 13+ messages in thread

* [PATCH] pcre2: Update to version 10.49
  2026-10-02 11:23 [PATCH] core205: Ship gdb Adolf Belka
                   ` (8 preceding siblings ...)
  2026-10-02 11:23 ` [PATCH] pam: Update to version 1.7.3 Adolf Belka
@ 2026-10-02 11:23 ` Adolf Belka
  2026-10-02 11:23 ` [PATCH] shairport-sync: Update to version 5.5.2 Adolf Belka
  2026-10-02 11:23 ` [PATCH] swtpm: Update to version 0.10.2 Adolf Belka
  11 siblings, 0 replies; 13+ messages in thread
From: Adolf Belka @ 2026-10-02 11:23 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

- Update from version 10.48 to 10.49
- Update of rootfile
- 1 GHSA Security fix
- Changelog
10.49
	This is a security-only release, to address GHSA-r9hj-j2rw-4q3m.
	Compared to 10.48, this release has only a minimal code change to prevent an
	 out-of-bounds write with arbitrary data. An attacker-controlled regex pattern
	 is required, and applications are only affected if using the
	 pcre2_jit_stack_create() and pcre2_jit_stack_assign() APIs to provide a growable
	 JIT stack, and then matching against a pattern with unusually high JIT stack
	 usage, such as a large number of capturing groups.
	The implications of an out-of-bounds write could include arbitrary code
	 execution.
	The issue is not a regression and affects releases 10.48 and earlier.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/common/pcre2 | 242 +++++++++++++++++-----------------
 lfs/pcre2                     |   4 +-
 2 files changed, 123 insertions(+), 123 deletions(-)

diff --git a/config/rootfiles/common/pcre2 b/config/rootfiles/common/pcre2
index 152524867..1fe003f89 100644
--- a/config/rootfiles/common/pcre2
+++ b/config/rootfiles/common/pcre2
@@ -6,140 +6,140 @@
 #usr/lib/libpcre2-16.la
 #usr/lib/libpcre2-16.so
 usr/lib/libpcre2-16.so.0
-usr/lib/libpcre2-16.so.0.16.0
+usr/lib/libpcre2-16.so.0.16.1
 #usr/lib/libpcre2-32.la
 #usr/lib/libpcre2-32.so
 usr/lib/libpcre2-32.so.0
-usr/lib/libpcre2-32.so.0.16.0
+usr/lib/libpcre2-32.so.0.16.1
 #usr/lib/libpcre2-8.la
 #usr/lib/libpcre2-8.so
 usr/lib/libpcre2-8.so.0
-usr/lib/libpcre2-8.so.0.16.0
+usr/lib/libpcre2-8.so.0.16.1
 #usr/lib/libpcre2-posix.la
 #usr/lib/libpcre2-posix.so
 usr/lib/libpcre2-posix.so.3
-usr/lib/libpcre2-posix.so.3.0.8
+usr/lib/libpcre2-posix.so.3.0.9
 #usr/lib/pkgconfig/libpcre2-16.pc
 #usr/lib/pkgconfig/libpcre2-32.pc
 #usr/lib/pkgconfig/libpcre2-8.pc
 #usr/lib/pkgconfig/libpcre2-posix.pc
-#usr/share/doc/pcre-pcre2-10.48
-#usr/share/doc/pcre-pcre2-10.48/AUTHORS.md
-#usr/share/doc/pcre-pcre2-10.48/COPYING
-#usr/share/doc/pcre-pcre2-10.48/ChangeLog
-#usr/share/doc/pcre-pcre2-10.48/LICENCE.md
-#usr/share/doc/pcre-pcre2-10.48/NEWS
-#usr/share/doc/pcre-pcre2-10.48/README
-#usr/share/doc/pcre-pcre2-10.48/SECURITY.md
-#usr/share/doc/pcre-pcre2-10.48/SUPPORT-LIFECYCLE.md
-#usr/share/doc/pcre-pcre2-10.48/html
-#usr/share/doc/pcre-pcre2-10.48/html/NON-AUTOTOOLS-BUILD.txt
-#usr/share/doc/pcre-pcre2-10.48/html/README.txt
-#usr/share/doc/pcre-pcre2-10.48/html/index.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2-config.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_callout_enumerate.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_code_copy.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_code_copy_with_tables.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_code_free.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_compile.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_compile_context_copy.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_compile_context_create.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_compile_context_free.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_config.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_convert_context_copy.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_convert_context_create.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_convert_context_free.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_converted_pattern_free.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_dfa_match.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_general_context_copy.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_general_context_create.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_general_context_free.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_get_error_message.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_get_mark.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_get_match_data_heapframes_size.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_get_match_data_size.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_get_ovector_count.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_get_ovector_pointer.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_get_startchar.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_jit_compile.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_jit_free_unused_memory.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_jit_match.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_jit_stack_assign.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_jit_stack_create.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_jit_stack_free.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_maketables.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_maketables_free.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_match.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_match_context_copy.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_match_context_create.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_match_context_free.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_match_data_create.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_match_data_create_from_pattern.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_match_data_free.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_next_match.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_pattern_convert.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_pattern_info.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_serialize_decode.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_serialize_encode.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_serialize_free.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_serialize_get_number_of_codes.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_bsr.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_callout.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_character_tables.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_compile_extra_options.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_compile_recursion_guard.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_depth_limit.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_glob_escape.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_glob_separator.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_heap_limit.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_match_limit.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_max_pattern_compiled_length.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_max_pattern_length.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_max_varlookbehind.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_newline.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_offset_limit.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_optimize.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_parens_nest_limit.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_recursion_limit.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_recursion_memory_management.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_substitute_callout.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_substitute_case_callout.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substitute.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_copy_byname.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_copy_bynumber.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_free.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_get_byname.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_get_bynumber.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_length_byname.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_length_bynumber.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_list_free.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_list_get.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_nametable_scan.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_number_from_name.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2api.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2build.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2callout.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2compat.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2convert.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2demo.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2grep.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2jit.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2limits.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2matching.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2partial.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2pattern.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2perform.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2posix.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2sample.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2serialize.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2syntax.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2test.html
-#usr/share/doc/pcre-pcre2-10.48/html/pcre2unicode.html
-#usr/share/doc/pcre-pcre2-10.48/pcre2-config.txt
-#usr/share/doc/pcre-pcre2-10.48/pcre2.txt
-#usr/share/doc/pcre-pcre2-10.48/pcre2grep.txt
-#usr/share/doc/pcre-pcre2-10.48/pcre2test.txt
+#usr/share/doc/pcre-pcre2-10.49
+#usr/share/doc/pcre-pcre2-10.49/AUTHORS.md
+#usr/share/doc/pcre-pcre2-10.49/COPYING
+#usr/share/doc/pcre-pcre2-10.49/ChangeLog
+#usr/share/doc/pcre-pcre2-10.49/LICENCE.md
+#usr/share/doc/pcre-pcre2-10.49/NEWS
+#usr/share/doc/pcre-pcre2-10.49/README
+#usr/share/doc/pcre-pcre2-10.49/SECURITY.md
+#usr/share/doc/pcre-pcre2-10.49/SUPPORT-LIFECYCLE.md
+#usr/share/doc/pcre-pcre2-10.49/html
+#usr/share/doc/pcre-pcre2-10.49/html/NON-AUTOTOOLS-BUILD.txt
+#usr/share/doc/pcre-pcre2-10.49/html/README.txt
+#usr/share/doc/pcre-pcre2-10.49/html/index.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2-config.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_callout_enumerate.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_code_copy.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_code_copy_with_tables.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_code_free.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_compile.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_compile_context_copy.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_compile_context_create.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_compile_context_free.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_config.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_convert_context_copy.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_convert_context_create.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_convert_context_free.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_converted_pattern_free.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_dfa_match.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_general_context_copy.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_general_context_create.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_general_context_free.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_get_error_message.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_get_mark.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_get_match_data_heapframes_size.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_get_match_data_size.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_get_ovector_count.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_get_ovector_pointer.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_get_startchar.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_jit_compile.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_jit_free_unused_memory.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_jit_match.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_jit_stack_assign.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_jit_stack_create.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_jit_stack_free.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_maketables.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_maketables_free.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_match.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_match_context_copy.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_match_context_create.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_match_context_free.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_match_data_create.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_match_data_create_from_pattern.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_match_data_free.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_next_match.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_pattern_convert.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_pattern_info.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_serialize_decode.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_serialize_encode.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_serialize_free.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_serialize_get_number_of_codes.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_bsr.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_callout.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_character_tables.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_compile_extra_options.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_compile_recursion_guard.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_depth_limit.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_glob_escape.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_glob_separator.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_heap_limit.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_match_limit.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_max_pattern_compiled_length.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_max_pattern_length.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_max_varlookbehind.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_newline.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_offset_limit.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_optimize.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_parens_nest_limit.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_recursion_limit.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_recursion_memory_management.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_substitute_callout.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_set_substitute_case_callout.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_substitute.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_substring_copy_byname.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_substring_copy_bynumber.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_substring_free.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_substring_get_byname.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_substring_get_bynumber.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_substring_length_byname.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_substring_length_bynumber.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_substring_list_free.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_substring_list_get.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_substring_nametable_scan.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2_substring_number_from_name.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2api.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2build.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2callout.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2compat.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2convert.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2demo.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2grep.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2jit.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2limits.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2matching.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2partial.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2pattern.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2perform.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2posix.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2sample.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2serialize.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2syntax.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2test.html
+#usr/share/doc/pcre-pcre2-10.49/html/pcre2unicode.html
+#usr/share/doc/pcre-pcre2-10.49/pcre2-config.txt
+#usr/share/doc/pcre-pcre2-10.49/pcre2.txt
+#usr/share/doc/pcre-pcre2-10.49/pcre2grep.txt
+#usr/share/doc/pcre-pcre2-10.49/pcre2test.txt
 #usr/share/man/man1/pcre2-config.1
 #usr/share/man/man1/pcre2grep.1
 #usr/share/man/man1/pcre2test.1
diff --git a/lfs/pcre2 b/lfs/pcre2
index 9a47dfb43..6c22b5cbf 100644
--- a/lfs/pcre2
+++ b/lfs/pcre2
@@ -24,7 +24,7 @@
 
 include Config
 
-VER        = 10.48
+VER        = 10.49
 
 THISAPP    = pcre2-$(VER)
 DL_FILE    = $(THISAPP).tar.bz2
@@ -54,7 +54,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = 7c500b4271e13c8a965a85c2aac4a72d5f29b7a3318b6077fa9de391512669ad26a5a774eee322c966ed38127ca9dfc139e4dacc1c1b23578d0674d882b3d84c
+$(DL_FILE)_BLAKE2 = 9286396718d4e26c7a504134f774ffa3bde6a1e07ea6fef05afbea9a0a2f35d79c2391fea0ee58e76c3ea59a684b66c171872e88bb13f3403edaa34e02624d84
 
 install : $(TARGET)
 
-- 
2.55.0



^ permalink raw reply	[flat|nested] 13+ messages in thread

* [PATCH] shairport-sync: Update to version 5.5.2
  2026-10-02 11:23 [PATCH] core205: Ship gdb Adolf Belka
                   ` (9 preceding siblings ...)
  2026-10-02 11:23 ` [PATCH] pcre2: Update to version 10.49 Adolf Belka
@ 2026-10-02 11:23 ` Adolf Belka
  2026-10-02 11:23 ` [PATCH] swtpm: Update to version 0.10.2 Adolf Belka
  11 siblings, 0 replies; 13+ messages in thread
From: Adolf Belka @ 2026-10-02 11:23 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

- Update from version 5.5.1 to 5.5.2
- No change in rootfile
- Changelog
5.5.2
	This update improves compatibility with Version 27 of Apple software, e.g.
	 macOS 27, iOS 27, etc. and is recommended for all users.
	The update improves the handling of unrecognised blocks of data arriving in
	 the buffered audio stream, a phenomenon that seems to be new in OS 27.
	In particular, if the first block is unrecognised, play may not begin until it
	 is paused and resumed. This is fixed in this update.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 lfs/shairport-sync | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/lfs/shairport-sync b/lfs/shairport-sync
index fc120ada4..36f5f2391 100644
--- a/lfs/shairport-sync
+++ b/lfs/shairport-sync
@@ -26,7 +26,7 @@ include Config
 
 SUMMARY    = An AirPlay audio player
 
-VER        = 5.5.1
+VER        = 5.5.2
 
 THISAPP    = shairport-sync-$(VER)
 DL_FILE    = $(THISAPP).tar.gz
@@ -34,7 +34,7 @@ DL_FROM    = $(URL_IPFIRE)
 DIR_APP    = $(DIR_SRC)/$(THISAPP)
 TARGET     = $(DIR_INFO)/$(THISAPP)
 PROG       = shairport-sync
-PAK_VER    = 18
+PAK_VER    = 19
 
 DEPS       = alsa avahi ffmpeg libdaemon libplist nqptp soxr
 
@@ -48,7 +48,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = 7e683abeb75660d8b396eb560e092d3318c6dec892725f7e6e308cb63a0eb7b5e6d4cf482ab0cb83e47b6a051ad571c4057492c46bcea7da1e719fa5e00f095f
+$(DL_FILE)_BLAKE2 = da512e3f6aa100e283dcbeaa9e0319d26f7b6b2969c822eb62a6eda1069be36df954941fed3cc31cc5784d8e35bba55339d83d78badb0abdac82d818dbaa8c50
 
 install : $(TARGET)
 
-- 
2.55.0



^ permalink raw reply	[flat|nested] 13+ messages in thread

* [PATCH] swtpm: Update to version 0.10.2
  2026-10-02 11:23 [PATCH] core205: Ship gdb Adolf Belka
                   ` (10 preceding siblings ...)
  2026-10-02 11:23 ` [PATCH] shairport-sync: Update to version 5.5.2 Adolf Belka
@ 2026-10-02 11:23 ` Adolf Belka
  11 siblings, 0 replies; 13+ messages in thread
From: Adolf Belka @ 2026-10-02 11:23 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

- Update from version 0.10.1 to 0.10.2
- No change in rootfile
- 1 CVE fix
- Changelog
0.10.2
   - swtpm:
     - Fix length check in SWTPM_NVRAM_CheckHeader() (CVE-2026-75900)
     - Properly check for truncation following snprintf call
   - selinux:
     - Fix policy loading with 3.11 SElinux toolchain (bsc#1271417)
     - Add SELinux policy for virtqemud_t swtpm_t setsched process and unix socket
	interactions.
   - tests:
     - Retry NVWrite command after 0x922 return code and inc lockout counter
     - Extend regex to allow for optional RSA-4096 keys

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 lfs/swtpm | 12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

diff --git a/lfs/swtpm b/lfs/swtpm
index 1547610a2..c2474f935 100644
--- a/lfs/swtpm
+++ b/lfs/swtpm
@@ -1,7 +1,7 @@
 ###############################################################################
 #                                                                             #
 # IPFire.org - A linux based firewall                                         #
-# Copyright (C) 2007-2025  IPFire Team  <info@ipfire.org>                     #
+# Copyright (C) 2007-2026  IPFire Team  <info@ipfire.org>                     #
 #                                                                             #
 # This program is free software: you can redistribute it and/or modify        #
 # it under the terms of the GNU General Public License as published by        #
@@ -26,7 +26,7 @@ include Config
 
 SUMMARY    = Libtpms-based TPM emulator with socket, character device, and Linux CUSE interface.
 
-VER        = 0.10.1
+VER        = 0.10.2
 
 THISAPP    = swtpm-$(VER)
 DL_FILE    = $(THISAPP).tar.gz
@@ -34,7 +34,7 @@ DL_FROM    = $(URL_IPFIRE)
 DIR_APP    = $(DIR_SRC)/$(THISAPP)
 TARGET     = $(DIR_INFO)/$(THISAPP)
 PROG       = swtpm
-PAK_VER    = 2
+PAK_VER    = 3
 
 DEPS       = libtpms
 
@@ -48,7 +48,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = fa282338a975b4e3067e444ae5781744b3c153f482377a11b5c71072ed519709d561f6759e478a008813946da2f03c0650259d9f1ca17afd07892cd37f46529e
+$(DL_FILE)_BLAKE2 = bcbfeac547616395a7513323f24b6bcf2de8ca176ecf5f5c2db85f96d093b9eee5fe3cd493c6ba5a7710629ad95ce99f52b9dd7b8cd28021f1ff4562badccb69
 
 install : $(TARGET)
 
@@ -84,8 +84,8 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects))
 	-mkdir -pv $(DIR_APP)
 	cd $(DIR_APP) && autoreconf -vfi
 	cd $(DIR_APP) && ./configure \
-		--prefix=/usr \
-		--disable-hardening
+				--prefix=/usr \
+				--disable-hardening
 	cd $(DIR_APP) && make $(MAKETUNING)
 	cd $(DIR_APP) && make install
 	@rm -rf $(DIR_APP)
-- 
2.55.0



^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2026-10-02 11:23 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-02 11:23 [PATCH] core205: Ship gdb Adolf Belka
2026-10-02 11:23 ` [PATCH] core205: Ship libpng Adolf Belka
2026-10-02 11:23 ` [PATCH] core205: Ship pam Adolf Belka
2026-10-02 11:23 ` [PATCH] freeradius: Update to version 3.2.10 Adolf Belka
2026-10-02 11:23 ` [PATCH] gdb: Update to version 18.1 Adolf Belka
2026-10-02 11:23 ` [PATCH] git: Update to version 2.56.0 Adolf Belka
2026-10-02 11:23 ` [PATCH] iperf3: Update to version 3.22 Adolf Belka
2026-10-02 11:23 ` [PATCH] libpng: Update to version 1.6.59 Adolf Belka
2026-10-02 11:23 ` [PATCH] ntfs-3g: Update to version 2026.9.28 Adolf Belka
2026-10-02 11:23 ` [PATCH] pam: Update to version 1.7.3 Adolf Belka
2026-10-02 11:23 ` [PATCH] pcre2: Update to version 10.49 Adolf Belka
2026-10-02 11:23 ` [PATCH] shairport-sync: Update to version 5.5.2 Adolf Belka
2026-10-02 11:23 ` [PATCH] swtpm: Update to version 0.10.2 Adolf Belka

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox