<feed xmlns='http://www.w3.org/2005/Atom'>
<title>staging/pepe2k/tools, branch v21.02.4</title>
<subtitle>Staging tree of Piotr Dymacz</subtitle>
<id>https://git.openwrt.org/openwrt/staging/pepe2k/atom?h=v21.02.4</id>
<link rel='self' href='https://git.openwrt.org/openwrt/staging/pepe2k/atom?h=v21.02.4'/>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/'/>
<updated>2022-09-21T09:52:40Z</updated>
<entry>
<title>tools: remove xxd package</title>
<updated>2022-09-21T09:52:40Z</updated>
<author>
<name>Petr Štetiar</name>
</author>
<published>2022-08-30T06:41:07Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=c6d3f39ecce43c4a9858157e9e2ee8718750a9ab'/>
<id>urn:sha1:c6d3f39ecce43c4a9858157e9e2ee8718750a9ab</id>
<content type='text'>
It shouldn't be needed anymore as we've now `scripts/xxdi.pl`, which
should be self contained and fully compatible `xxd -i` replacement.

Fixes: #10555
Signed-off-by: Petr Štetiar &lt;ynezz@true.cz&gt;
(cherry picked from commit 88c9056a70901577489ecdc7a25207a9b7576d6e)
</content>
</entry>
<entry>
<title>tools/libelf: alpine linux os type: linux-musl fix</title>
<updated>2022-08-28T05:58:46Z</updated>
<author>
<name>Isaev Ruslan</name>
</author>
<published>2022-01-29T02:17:44Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=2f82fc6bf04dccd45f41cd9ed9a10478fb2bd31e'/>
<id>urn:sha1:2f82fc6bf04dccd45f41cd9ed9a10478fb2bd31e</id>
<content type='text'>
Prevents ./configure "checking build system" test fail on Alpine linux.

Signed-off-by: Isaev Ruslan &lt;legale.legale@gmail.com&gt;
Signed-off-by: Petr Štetiar &lt;ynezz@true.cz&gt; [commit description]
</content>
</entry>
<entry>
<title>tools/libressl: update to version 3.4.3</title>
<updated>2022-07-15T13:52:13Z</updated>
<author>
<name>Josef Schlehofer</name>
</author>
<published>2022-06-06T20:08:42Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=206d790680fa10725003ca57738a146740a9ecb8'/>
<id>urn:sha1:206d790680fa10725003ca57738a146740a9ecb8</id>
<content type='text'>
Release notes:
https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.4.3-relnotes.txt

```
It includes the following security fix:

    * A malicious certificate can cause an infinite loop.
      Reported by and fix from Tavis Ormandy and David Benjamin, Google.
      (CVE-2022–0778)
```

Signed-off-by: Josef Schlehofer &lt;pepe.schlehofer@gmail.com&gt;
(cherry picked from commit 25534d5cc20a807ff776fdb18847344167ce081d)
</content>
</entry>
<entry>
<title>zlib: backport security fix for a reproducible crash in compressor</title>
<updated>2022-03-24T08:40:12Z</updated>
<author>
<name>Petr Štetiar</name>
</author>
<published>2022-03-24T05:45:04Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=f65edc9b990c2bcc10c9e9fca29253adc6fe316d'/>
<id>urn:sha1:f65edc9b990c2bcc10c9e9fca29253adc6fe316d</id>
<content type='text'>
Tavis has just reported, that he was recently trying to track down a
reproducible crash in a compressor. Believe it or not, it really was a
bug in zlib-1.2.11 when compressing (not decompressing!) certain inputs.

Tavis has reported it upstream, but it turns out the issue has been
public since 2018, but the patch never made it into a release. As far as
he knows, nobody ever assigned it a CVE.

Suggested-by: Tavis Ormandy &lt;taviso@gmail.com&gt;
References: https://www.openwall.com/lists/oss-security/2022/03/24/1
Signed-off-by: Petr Štetiar &lt;ynezz@true.cz&gt;
(cherry picked from commit b3aa2909a79aeff20d594160b207a89dc807c033)
(cherry picked from commit 3965dda0fa70dc9408f1a2e55a3ddefde78bd50e)
</content>
</entry>
<entry>
<title>tools: xxd: use more convenient source tarball</title>
<updated>2022-03-15T17:50:32Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2021-03-01T14:06:33Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=92020d42425090d8e30554c41bed2d650263e06e'/>
<id>urn:sha1:92020d42425090d8e30554c41bed2d650263e06e</id>
<content type='text'>
Don't download all of vim just to build xxd. Use a tight tarball
containing only xxd sources instead.

Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
(cherry picked from commit 2b94aac7a128c9d9f4343af2265b362e8b5d5013)
</content>
</entry>
<entry>
<title>tools: add xxd (from vim)</title>
<updated>2022-03-15T17:50:26Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2021-02-28T19:26:07Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=17e95532842c4d62b30669490eb00b39cf8ff743'/>
<id>urn:sha1:17e95532842c4d62b30669490eb00b39cf8ff743</id>
<content type='text'>
U-Boot requires xxd to create the default environment from an external
file as done in uboot-mediatek.
Build xxd (only, not the rest of vim) as part of tools to make sure it
is present on the buildhost.

Reported-by: David Bauer &lt;mail@david-bauer.net&gt;
Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
(cherry picked from commit c4dd2441e7875c9550820f8380b3e41ca619ef27)
</content>
</entry>
<entry>
<title>tools/libressl: update to version 3.4.2</title>
<updated>2022-03-06T19:56:23Z</updated>
<author>
<name>Josef Schlehofer</name>
</author>
<published>2022-02-23T20:32:41Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=03271046869ec2e681e0732e3ed6460ab1537243'/>
<id>urn:sha1:03271046869ec2e681e0732e3ed6460ab1537243</id>
<content type='text'>
Release notes:
https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.4.2-relnotes.txt

```
It includes the following security fix

  * In some situations the X.509 verifier would discard an error on an
    unverified certificate chain, resulting in an authentication bypass.
    Thanks to Ilya Shipitsin and Timo Steinlein for reporting.
```

Signed-off-by: Josef Schlehofer &lt;pepe.schlehofer@gmail.com&gt;
(cherry picked from commit 495c4f4e197166a6fa997d4620ca6c241e3abd45)
</content>
</entry>
<entry>
<title>tools/libressl: update to 3.4.1</title>
<updated>2022-03-06T19:56:23Z</updated>
<author>
<name>Rosen Penev</name>
</author>
<published>2021-09-22T07:49:33Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=8ed3b5b04b4983d75f4192bab470c6fb7eb9c50f'/>
<id>urn:sha1:8ed3b5b04b4983d75f4192bab470c6fb7eb9c50f</id>
<content type='text'>
Signed-off-by: Rosen Penev &lt;rosenp@gmail.com&gt;
(cherry picked from commit 03bb3412a2b8bf8ac69e062ea9fd88e2c6c6fb57)
</content>
</entry>
<entry>
<title>tools/libressl: update to 3.3.4</title>
<updated>2022-03-06T19:56:23Z</updated>
<author>
<name>Rosen Penev</name>
</author>
<published>2021-09-02T02:29:40Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=2736a5df94134fcad19dbd429fa21761536937b7'/>
<id>urn:sha1:2736a5df94134fcad19dbd429fa21761536937b7</id>
<content type='text'>
Signed-off-by: Rosen Penev &lt;rosenp@gmail.com&gt;
(cherry picked from commit f78ad901e1ce07c42a9f5e670c39dbdcea15eb87)
</content>
</entry>
<entry>
<title>tools/libressl: update to 3.3.3</title>
<updated>2022-03-06T19:56:23Z</updated>
<author>
<name>Rosen Penev</name>
</author>
<published>2021-06-19T21:45:11Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=49b2e6365d054aa49c88478ab2000eb2dd439cd8'/>
<id>urn:sha1:49b2e6365d054aa49c88478ab2000eb2dd439cd8</id>
<content type='text'>
Fix wrong FPIC variable usage. Fixes compilation under sparc64 host.

Signed-off-by: Rosen Penev &lt;rosenp@gmail.com&gt;
(cherry picked from commit bf4dbbb55e2b8e23f186e1334f1e9ce6a3a8ddfe)
</content>
</entry>
</feed>
