<feed xmlns='http://www.w3.org/2005/Atom'>
<title>staging/xback/tools/xz, branch master</title>
<subtitle>Staging tree of Koen Vandeputte</subtitle>
<id>https://git.openwrt.org/openwrt/staging/xback/atom?h=master</id>
<link rel='self' href='https://git.openwrt.org/openwrt/staging/xback/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/xback/'/>
<updated>2026-09-22T18:29:59Z</updated>
<entry>
<title>tools: cache the configure results of eleven more autotools tools</title>
<updated>2026-09-22T18:29:59Z</updated>
<author>
<name>John Crispin</name>
</author>
<published>2026-09-22T18:23:21Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/xback/commit/?id=6eae1d6b772eeb012046f64be83ecf9ea5ef7514'/>
<id>urn:sha1:6eae1d6b772eeb012046f64be83ecf9ea5ef7514</id>
<content type='text'>
Configure stage without a cache against a warm cache:

  mtools      3.34 s -&gt; 0.28 s
  gengetopt   4.39 s -&gt; 2.13 s
  fakeroot   10.97 s -&gt; 8.73 s
  xz          4.32 s -&gt; 2.17 s
  libressl    3.07 s -&gt; 1.46 s
  flex       12.32 s -&gt; 10.98 s
  expat       2.74 s -&gt; 1.52 s
  bc          1.34 s -&gt; 0.38 s
  dosfstools  3.13 s -&gt; 2.54 s
  libtool     2.86 s -&gt; 2.29 s
  mtd-utils   4.06 s -&gt; 3.56 s

flex, fakeroot, dosfstools and mtd-utils run autoreconf in the same
stage, and the cache does not reach that part.

Each of the eleven configures the same way with a warm cache as it does
without one: the check configures three times, without a cache, with a
cold cache and with a warm cache, and every generated file of the first
and the last run is identical. A static scan of each configure script
found no cache check that changes CFLAGS, CPPFLAGS, LDFLAGS or LIBS
without restoring it.

patchelf, mklibs and automake pass the same check but gain less than
half a second, so they stay out.

make world after make tools/clean now takes 121 s against 177 s with
cold caches.

Signed-off-by: John Crispin &lt;john@phrozen.org&gt;
</content>
</entry>
<entry>
<title>tools/xz: update to version 5.8.4</title>
<updated>2026-09-21T11:28:13Z</updated>
<author>
<name>Shiji Yang</name>
</author>
<published>2026-09-21T00:16:36Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/xback/commit/?id=cce54a1d82a33ede9e917d3bf90df573cf033484'/>
<id>urn:sha1:cce54a1d82a33ede9e917d3bf90df573cf033484</id>
<content type='text'>
Release Notes:
https://github.com/tukaani-project/xz/releases/tag/v5.8.4

Signed-off-by: Shiji Yang &lt;yangshiji66@outlook.com&gt;
Link: https://github.com/openwrt/openwrt/pull/25295
Signed-off-by: Robert Marko &lt;robimarko@gmail.com&gt;
</content>
</entry>
<entry>
<title>treewide: use HTTPS for PKG_SOURCE_URL where possible</title>
<updated>2026-04-20T03:58:37Z</updated>
<author>
<name>Paul Spooren</name>
</author>
<published>2026-04-18T13:26:39Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/xback/commit/?id=7a991c8d88b8946db94059f1f34885c8bf74c124'/>
<id>urn:sha1:7a991c8d88b8946db94059f1f34885c8bf74c124</id>
<content type='text'>
Switch http:// (and redundant ftp://) PKG_SOURCE_URL entries to https://
across tools/ and package/. PKG_HASH alone does not protect against an
attacker tampering with insecure downloads when a maintainer regenerates
the hash via `make ... FIXUP=1`: HTTPS authenticates the upstream so the
captured hash reflects real upstream content.

In-place http -&gt; https (HTTPS reachability verified per host):
- tools/elftosb, tools/lzop, tools/liblzo, tools/mpfr, tools/dosfstools,
  tools/libressl, tools/xz
- package/libs/mpfr, package/libs/libmnl, package/libs/libnfnetlink

Replaced with @OPENWRT (HTTPS-only mirror) where the upstream HTTPS host
is dead or has a broken certificate:
- package/libs/popt (ftp.rpm.org cert mismatch)
- package/firmware/ixp4xx-microcode (was http://downloads.openwrt.org)
- package/boot/imx-bootlets (trabant.uid0.hu cert mismatch)
- package/boot/kobs-ng (freescale.com URL is dead, redirects to nxp.com root)

Dropped redundant ftp://ftp.denx.de fallback (https://ftp.denx.de is
already listed):
- package/boot/uboot-tools, tools/mkimage

Signed-off-by: Paul Spooren &lt;mail@aparcar.org&gt;
</content>
</entry>
<entry>
<title>tools/xz: update to 5.8.3</title>
<updated>2026-04-06T13:58:13Z</updated>
<author>
<name>Shiji Yang</name>
</author>
<published>2026-04-05T01:06:23Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/xback/commit/?id=105750c673929ae77946fd1f42bbf75b185fca3a'/>
<id>urn:sha1:105750c673929ae77946fd1f42bbf75b185fca3a</id>
<content type='text'>
This includes a fix for (CVE-2026-34743).

Release Notes:
https://github.com/tukaani-project/xz/releases/tag/v5.8.3

Signed-off-by: Shiji Yang &lt;yangshiji66@outlook.com&gt;
Link: https://github.com/openwrt/openwrt/pull/22790
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
<entry>
<title>tools/xz: update to 5.8.2</title>
<updated>2025-12-21T19:49:22Z</updated>
<author>
<name>Shiji Yang</name>
</author>
<published>2025-12-18T13:26:36Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/xback/commit/?id=def7548867741206f6788d55e58d7417d859e106'/>
<id>urn:sha1:def7548867741206f6788d55e58d7417d859e106</id>
<content type='text'>
Release Notes:
https://github.com/tukaani-project/xz/releases/tag/v5.8.2

Signed-off-by: Shiji Yang &lt;yangshiji66@outlook.com&gt;
Link: https://github.com/openwrt/openwrt/pull/21208
Signed-off-by: Robert Marko &lt;robimarko@gmail.com&gt;
</content>
</entry>
<entry>
<title>tools: xz: update to 5.8.1</title>
<updated>2025-04-22T11:20:05Z</updated>
<author>
<name>Robert Marko</name>
</author>
<published>2025-04-21T11:23:20Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/xback/commit/?id=269f251ba6eae8981e3dbc13f355fc1f53b955ba'/>
<id>urn:sha1:269f251ba6eae8981e3dbc13f355fc1f53b955ba</id>
<content type='text'>
5.8.1 (2025-04-03)

    * Multithreaded .xz decoder (lzma_stream_decoder_mt()):

        - Fix a bug that could at least result in a crash with
          invalid input. (CVE-2025-31115)

        - Fix a performance bug: Only one thread was used if the whole
          input file was provided at once to lzma_code(), the output
          buffer was big enough, timeout was disabled, and LZMA_FINISH
          was used. There are no bug reports about this, thus it's
          possible that no real-world application was affected.

    * Avoid &lt;stdalign.h&gt; even with C11/C17 compilers. This fixes the
      build with Oracle Developer Studio 12.6 on Solaris 10 when the
      compiler is in C11 mode (the header doesn't exist).

    * Autotools: Restore compatibility with GNU make versions older
      than 4.0 by creating the package using GNU gettext 0.23.1
      infrastructure instead of 0.24.

    * Update Croatian translation.

Link: https://github.com/openwrt/openwrt/pull/18558
Signed-off-by: Robert Marko &lt;robimarko@gmail.com&gt;
</content>
</entry>
<entry>
<title>tools/xz: update to 5.8.0</title>
<updated>2025-04-01T19:47:15Z</updated>
<author>
<name>Shiji Yang</name>
</author>
<published>2025-03-28T16:10:25Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/xback/commit/?id=e37ad78539d410368de2e5b95388b3acf8686126'/>
<id>urn:sha1:e37ad78539d410368de2e5b95388b3acf8686126</id>
<content type='text'>
Changelogs:
https://github.com/tukaani-project/xz/releases/tag/v5.8.0

Signed-off-by: Shiji Yang &lt;yangshiji66@outlook.com&gt;
Link: https://github.com/openwrt/openwrt/pull/18367
Signed-off-by: Nick Hainke &lt;vincent@systemli.org&gt;
</content>
</entry>
<entry>
<title>tools: xz: update to 5.6.4</title>
<updated>2025-02-23T11:21:26Z</updated>
<author>
<name>Shiji Yang</name>
</author>
<published>2025-02-21T13:18:22Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/xback/commit/?id=3ffe54a1e19fa0f26c158e8fc7d2af2b8e409ba4'/>
<id>urn:sha1:3ffe54a1e19fa0f26c158e8fc7d2af2b8e409ba4</id>
<content type='text'>
The serious liblzma backdoor vulnerability (CVE-2024-3094) has
been fixed since v5.6.2. It's time to bump this tool to the
latest version. This patch also added a new GitHub package URL.

Changelogs:
https://github.com/tukaani-project/xz/releases/tag/v5.6.2
https://github.com/tukaani-project/xz/releases/tag/v5.6.3
https://github.com/tukaani-project/xz/releases/tag/v5.6.4

Signed-off-by: Shiji Yang &lt;yangshiji66@qq.com&gt;
Link: https://github.com/openwrt/openwrt/pull/18063
Signed-off-by: Nick Hainke &lt;vincent@systemli.org&gt;
</content>
</entry>
<entry>
<title>Revert "tools/xz: update to 5.6.1" (CVE-2024-3094)</title>
<updated>2024-03-29T16:59:56Z</updated>
<author>
<name>Petr Štetiar</name>
</author>
<published>2024-03-29T16:59:01Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/xback/commit/?id=d4b6b76443207103d3a7c0eae5c0085317fb584f'/>
<id>urn:sha1:d4b6b76443207103d3a7c0eae5c0085317fb584f</id>
<content type='text'>
This reverts commit 714c91d1a63f29650abaa9cf69ffa47cf2c70297 as probably
the upstream xz repository and the xz tarballs have been backdoored.

References: https://www.openwall.com/lists/oss-security/2024/03/29/4.
Signed-off-by: Petr Štetiar &lt;ynezz@true.cz&gt;
</content>
</entry>
<entry>
<title>tools/xz: update to 5.6.1</title>
<updated>2024-03-29T05:56:43Z</updated>
<author>
<name>Nick Hainke</name>
</author>
<published>2024-03-28T20:36:29Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/xback/commit/?id=714c91d1a63f29650abaa9cf69ffa47cf2c70297'/>
<id>urn:sha1:714c91d1a63f29650abaa9cf69ffa47cf2c70297</id>
<content type='text'>
Change mirror to github.

Signed-off-by: Nick Hainke &lt;vincent@systemli.org&gt;
</content>
</entry>
</feed>
