From patchwork Fri Aug 30 14:15:28 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Adrian Perez de Castro X-Patchwork-Id: 1155943 Return-Path: X-Original-To: incoming-buildroot@patchwork.ozlabs.org Delivered-To: patchwork-incoming-buildroot@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (mailfrom) smtp.mailfrom=busybox.net (client-ip=140.211.166.133; helo=hemlock.osuosl.org; envelope-from=buildroot-bounces@busybox.net; receiver=) Authentication-Results: ozlabs.org; dmarc=none (p=none dis=none) header.from=igalia.com Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=igalia.com header.i=@igalia.com header.b="sjvTbm4q"; dkim-atps=neutral Received: from hemlock.osuosl.org (smtp2.osuosl.org [140.211.166.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 46KhNB1lWKz9sN4 for ; Sat, 31 Aug 2019 00:15:52 +1000 (AEST) Received: from localhost (localhost [127.0.0.1]) by hemlock.osuosl.org (Postfix) with ESMTP id 49665885CD; Fri, 30 Aug 2019 14:15:49 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from hemlock.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6kB1eUPXYjQR; Fri, 30 Aug 2019 14:15:48 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by hemlock.osuosl.org (Postfix) with ESMTP id 392978884A; Fri, 30 Aug 2019 14:15:48 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from hemlock.osuosl.org (smtp2.osuosl.org [140.211.166.133]) by ash.osuosl.org (Postfix) with ESMTP id 062371BF282 for ; Fri, 30 Aug 2019 14:15:47 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by hemlock.osuosl.org (Postfix) with ESMTP id EF9818884A for ; Fri, 30 Aug 2019 14:15:46 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from hemlock.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id p1EFCU5g-Qh9 for ; Fri, 30 Aug 2019 14:15:45 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.7.6 Received: from fanzine.igalia.com (fanzine.igalia.com [91.117.99.155]) by hemlock.osuosl.org (Postfix) with ESMTPS id 42408885CD for ; Fri, 30 Aug 2019 14:15:44 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=igalia.com; s=20170329; h=Content-Transfer-Encoding:MIME-Version:Message-Id:Date:Subject:Cc:To:From; bh=jfOhX/NSemhpIfT664Q2foevEPoiJpjmvGt4xOhxk98=; b=sjvTbm4qoIkUlx9cdy3kVj5RH6L51Au6wBtYJmcFkrgxLJdW3jnzGloipTE0TW1zKv2TB0OUm8tPYhXXl6GaYvG+RRLx7m3haWLMnpAWN9DhSypPYQ3gP9j6rOtCTZr2U7AZPRYYsDLKmjcgyr1KFa8e41/36cbvsjkNaWsJ/3F3byWMbQhAoH5GcJUv+rDBJ6Qhv24xXXbyqZZlQJVVkipz1K1JXViSd9eMkQ5wxxrmCtFVa1mXlXZWbaTBw0DPJdSrFcGmY7nMhRFhKFA1mbnKZJj5el2f2LQzdB/S4jgSQ8oaI3umnGrn2W/MJ3L76qps58MkrykQZTujJW6zSA==; Received: from 82-181-154-206.bb.dnainternet.fi ([82.181.154.206] helo=kodama) by fanzine.igalia.com with esmtpsa (Cipher TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim) id 1i3hgi-0000dC-Um; Fri, 30 Aug 2019 16:15:41 +0200 Received: from localhost (kodama [local]) by kodama (OpenSMTPD) with ESMTPA id eaf5f131; Fri, 30 Aug 2019 14:15:29 +0000 (UTC) From: Adrian Perez de Castro To: buildroot@buildroot.org Date: Fri, 30 Aug 2019 17:15:28 +0300 Message-Id: <20190830141528.16446-1-aperez@igalia.com> X-Mailer: git-send-email 2.23.0 MIME-Version: 1.0 Subject: [Buildroot] [PATCH 1/1] package/wpewebkit: security bump to version 2.24.3 X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Adrian Perez de Castro Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" This is a minor release which includes fixes for CVE-2019-8644, CVE-2019-8649, CVE-2019-8658, CVE-2019-8666, CVE-2019-8669, CVE-2019-8673, CVE-2019-8676, CVE-2019-8678, CVE-2019-8680, CVE-2019-8681, CVE-2019-8683, CVE-2019-8684, CVE-2019-8687, CVE-2019-8688, CVE-2019-8689, and CVE-2019-8690. This release also contains many build fixes, a few media playback improvements, and a Web compatibility fix. For a complete list, the full release notes are available at: https://wpewebkit.org/release/wpewebkit-2.24.3.html The detailed security advisory can be found at: https://wpewebkit.org/security/WSA-2019-0004.html Patch "0001-Build-failure-after-r243644-in-GTK-Li.patch" is now unneeded because it is one of the build included in this release. Signed-off-by: Adrian Perez de Castro --- ...uild-failure-after-r243644-in-GTK-Li.patch | 36 ------------------- package/wpewebkit/wpewebkit.hash | 8 ++--- package/wpewebkit/wpewebkit.mk | 2 +- 3 files changed, 5 insertions(+), 41 deletions(-) delete mode 100644 package/wpewebkit/0001-Build-failure-after-r243644-in-GTK-Li.patch diff --git a/package/wpewebkit/0001-Build-failure-after-r243644-in-GTK-Li.patch b/package/wpewebkit/0001-Build-failure-after-r243644-in-GTK-Li.patch deleted file mode 100644 index 748fc8e46e..0000000000 --- a/package/wpewebkit/0001-Build-failure-after-r243644-in-GTK-Li.patch +++ /dev/null @@ -1,36 +0,0 @@ -From a672bbd75f257dd65844ad53dd21fb37345999b5 Mon Sep 17 00:00:00 2001 -From: "aperez@igalia.com" - -Date: Mon, 20 May 2019 21:20:02 +0000 -Subject: [PATCH] Build failure after r243644 in GTK - Linux 64-bit stable builds https://bugs.webkit.org/show_bug.cgi?id=196440 - -Patch by Pablo Saavedra on 2019-04-01 -Reviewed by Philippe Normand. - -* platform/graphics/gstreamer/MediaPlayerPrivateGStreamerBase.cpp: -(WebCore::MediaPlayerPrivateGStreamerBase::updateTextureMapperFlags): - -Signed-off-by: Adrian Perez de Castro - -diff --git a/Source/WebCore/platform/graphics/gstreamer/MediaPlayerPrivateGStreamerBase.cpp b/Source/WebCore/platform/graphics/gstreamer/MediaPlayerPrivateGStreamerBase.cpp -index 608aee2e1b3..c614050972a 100644 ---- a/Source/WebCore/platform/graphics/gstreamer/MediaPlayerPrivateGStreamerBase.cpp -+++ b/Source/WebCore/platform/graphics/gstreamer/MediaPlayerPrivateGStreamerBase.cpp -@@ -1000,11 +1000,13 @@ void MediaPlayerPrivateGStreamerBase::updateTextureMapperFlags() - break; - } - -+#if USE(GSTREAMER_GL) - // When the imxvpudecoder is used, the texture sampling of the - // directviv-uploaded texture returns an RGB value, so there's no need to - // convert it. - if (m_videoDecoderPlatform != WebKitGstVideoDecoderPlatform::ImxVPU) - m_textureMapperFlags |= TEXTURE_MAPPER_COLOR_CONVERT_FLAG; -+#endif - } - #endif - --- -2.21.0 - diff --git a/package/wpewebkit/wpewebkit.hash b/package/wpewebkit/wpewebkit.hash index ddab159d4f..8d09930267 100644 --- a/package/wpewebkit/wpewebkit.hash +++ b/package/wpewebkit/wpewebkit.hash @@ -1,7 +1,7 @@ -# From https://wpewebkit.org/releases/wpewebkit-2.24.2.tar.xz.sums -md5 3604a2167827c8354f6dcbab98305d7b wpewebkit-2.24.2.tar.xz -sha1 1248d7723d0e6aec52cafc27a92c5c335c1abdd4 wpewebkit-2.24.2.tar.xz -sha256 cf251a467b3bcae50f97e22f4baccca49fcbbd54162dc5b71c0b1ebf655fd95f wpewebkit-2.24.2.tar.xz +# From https://wpewebkit.org/releases/wpewebkit-2.24.3.tar.xz.sums +md5 b5c6fe640b03c3e87594da2c0a0a8469 wpewebkit-2.24.3.tar.xz +sha1 c9ccb6c4c65446e96ed6d534a1556db0fcca8268 wpewebkit-2.24.3.tar.xz +sha256 907b20907a32a4288cbf67b56eab04cbbd997a7ca0f40b3c466cbbbbfba0e7ca wpewebkit-2.24.3.tar.xz # Hashes for license files: sha256 0b5d3a7cc325942567373b0ecd757d07c132e0ebd7c97bfc63f7e1a76094edb4 Source/WebCore/LICENSE-APPLE diff --git a/package/wpewebkit/wpewebkit.mk b/package/wpewebkit/wpewebkit.mk index 4dc4a29064..48ed4f4afe 100644 --- a/package/wpewebkit/wpewebkit.mk +++ b/package/wpewebkit/wpewebkit.mk @@ -4,7 +4,7 @@ # ################################################################################ -WPEWEBKIT_VERSION = 2.24.2 +WPEWEBKIT_VERSION = 2.24.3 WPEWEBKIT_SITE = http://www.wpewebkit.org/releases WPEWEBKIT_SOURCE = wpewebkit-$(WPEWEBKIT_VERSION).tar.xz WPEWEBKIT_INSTALL_STAGING = YES