[{"id":3676326,"web_url":"http://patchwork.ozlabs.org/comment/3676326/","msgid":"<d0ef374a5bfdb9a82a5c4abbb4a43a50@free.fr>","list_archive_url":null,"date":"2026-04-12T17:04:19","subject":"Re: [Buildroot] [PATCH 1/2] package/libgpiod2: security bump to\n 2.2.4","submitter":{"id":80537,"url":"http://patchwork.ozlabs.org/api/people/80537/","name":"Julien Olivain","email":"ju.o@free.fr"},"content":"On 10/04/2026 16:57, Marcus Hoffmann via buildroot wrote:\n> Bug fixes:\n> - fix buffer over-read bugs when translating uAPI structs to library \n> types\n> - fix variable and argument types where necessary\n> - sanitize values returned by the kernel to avoid potential buffer \n> overflows\n> - fix memory leaks in gpio-tools\n> - add missing return value checks in gpio-tools\n> - fix period parsing in gpio-tools\n> - use correct loop counter in error path in gpio-manager\n> \n> Improvements:\n> - make tests work with newer coreutils by removing cases checking \n> tools'\n>   behavior on SIGINT which stopped working due to changes in behavior \n> of the\n>   timeout tool\n> \n> See: \n> https://git.kernel.org/pub/scm/libs/libgpiod/libgpiod.git/tree/NEWS?h=v2.2.4\n> \n> Signed-off-by: Marcus Hoffmann <buildroot@bubu1.eu>\n\nSeries applied to master, thanks. I added a comment in the commit log\nthat the no CVE published for this. We usually mark bumps as \"security\"\nonly when there is an advisory, but since the changelog was explicitly\nmentioning those security fixes, I kept the \"security\" but added the\ncomment. See:\nhttps://gitlab.com/buildroot.org/buildroot/-/commit/6ac53518a0ceb0611ee08adef500fc8d2994d21a\n\nBest regards,\n\nJulien.","headers":{"Return-Path":"<buildroot-bounces@buildroot.org>","X-Original-To":["incoming-buildroot@patchwork.ozlabs.org","buildroot@buildroot.org"],"Delivered-To":["patchwork-incoming-buildroot@legolas.ozlabs.org","buildroot@buildroot.org"],"Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=buildroot.org header.i=@buildroot.org\n header.a=rsa-sha256 header.s=default header.b=O8aUWaG1;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=buildroot.org\n (client-ip=2605:bc80:3010::137; helo=smtp4.osuosl.org;\n envelope-from=buildroot-bounces@buildroot.org; receiver=patchwork.ozlabs.org)"],"Received":["from smtp4.osuosl.org (smtp4.osuosl.org [IPv6:2605:bc80:3010::137])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4ftxjB4ydSz1yGg\n\tfor <incoming-buildroot@patchwork.ozlabs.org>;\n Mon, 13 Apr 2026 03:04:30 +1000 (AEST)","from localhost (localhost [127.0.0.1])\n\tby smtp4.osuosl.org (Postfix) with ESMTP id CE2B1423B2;\n\tSun, 12 Apr 2026 17:04:27 +0000 (UTC)","from smtp4.osuosl.org ([127.0.0.1])\n by localhost (smtp4.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id N5BrijDA4E_c; Sun, 12 Apr 2026 17:04:27 +0000 (UTC)","from lists1.osuosl.org (lists1.osuosl.org [140.211.166.142])\n\tby smtp4.osuosl.org (Postfix) with ESMTP id 047FA422CF;\n\tSun, 12 Apr 2026 17:04:27 +0000 (UTC)","from smtp1.osuosl.org (smtp1.osuosl.org [IPv6:2605:bc80:3010::138])\n by lists1.osuosl.org (Postfix) with ESMTP id 3C520194\n for <buildroot@buildroot.org>; Sun, 12 Apr 2026 17:04:25 +0000 (UTC)","from localhost (localhost [127.0.0.1])\n by smtp1.osuosl.org (Postfix) with ESMTP id 2E3958453C\n for <buildroot@buildroot.org>; Sun, 12 Apr 2026 17:04:25 +0000 (UTC)","from smtp1.osuosl.org ([127.0.0.1])\n by localhost (smtp1.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id MzGEus3xx3ys for <buildroot@buildroot.org>;\n Sun, 12 Apr 2026 17:04:24 +0000 (UTC)","from smtp5-g21.free.fr (smtp5-g21.free.fr [212.27.42.5])\n by smtp1.osuosl.org (Postfix) with ESMTPS id 2067E844C9\n for <buildroot@buildroot.org>; Sun, 12 Apr 2026 17:04:23 +0000 (UTC)","from webmail.free.fr (unknown [172.20.246.3])\n (Authenticated sender: ju.o@free.fr)\n by smtp5-g21.free.fr (Postfix) with ESMTPA id 398005FFBA;\n Sun, 12 Apr 2026 19:04:19 +0200 (CEST)","from 2a01:e0a:1065:2100:52d9:65fe:2df3:c492\n via 2a01:e0a:1065:2100:52d9:65fe:2df3:c492 by webmail.free.fr\n with HTTP (HTTP/1.0 POST); Sun, 12 Apr 2026 19:04:19 +0200"],"X-Virus-Scanned":["amavis at osuosl.org","amavis at osuosl.org"],"X-Comment":"SPF check N/A for local connections - client-ip=140.211.166.142;\n helo=lists1.osuosl.org; envelope-from=buildroot-bounces@buildroot.org;\n receiver=<UNKNOWN> ","DKIM-Filter":["OpenDKIM Filter v2.11.0 smtp4.osuosl.org 047FA422CF","OpenDKIM Filter v2.11.0 smtp1.osuosl.org 2067E844C9"],"DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=buildroot.org;\n\ts=default; t=1776013467;\n\tbh=M/G0sZwQOQoCtoKPJUA0PzoviOocVXZ9GPXrCtB0SHM=;\n\th=Date:To:Cc:In-Reply-To:References:Subject:List-Id:\n\t List-Unsubscribe:List-Archive:List-Post:List-Help:List-Subscribe:\n\t From:Reply-To:From;\n\tb=O8aUWaG1rpvdfQG9mDhE0ay1yuwa7dZVC85UPlXt8Nk+mTFZ5gAApkRwSITvIKln+\n\t f6oZzGR5OFa2nuSuupso2H+wDZQkhp9U2vg0VM9GHjwGwNQttJFHgTgLA4k/YwNyUH\n\t OIxGSemOxouEVAlOZlPKbV1mfG9WgqJub1DzsXKB8gCfSlfAq7nValeEAsfFeRBrGx\n\t c0FDTTkIfFlo1Mir/AaBx5GQvqkRmpNFwftDeHVq0/OmRWKN+UpCmMthhb7ban7g/o\n\t nzEefqHukeCHIBlBGcfawTAiLMxb5sVzccWIDPxS7UCsFxieXzfMTfhhV5paLDSELx\n\t IBw3iXEtePFdQ==","Received-SPF":"Pass (mailfrom) identity=mailfrom; client-ip=212.27.42.5;\n helo=smtp5-g21.free.fr; envelope-from=ju.o@free.fr; receiver=<UNKNOWN>","DMARC-Filter":"OpenDMARC Filter v1.4.2 smtp1.osuosl.org 2067E844C9","MIME-Version":"1.0","Date":"Sun, 12 Apr 2026 19:04:19 +0200","To":"Marcus Hoffmann <buildroot@bubu1.eu>","Cc":"buildroot@buildroot.org, Boerge Struempfel <boerge.struempfel@gmail.com>","In-Reply-To":"<20260410145709.271512-1-buildroot@bubu1.eu>","References":"<20260410145709.271512-1-buildroot@bubu1.eu>","User-Agent":"Webmail Free/1.6.14","Message-ID":"<d0ef374a5bfdb9a82a5c4abbb4a43a50@free.fr>","X-Sender":"ju.o@free.fr","X-Mailman-Original-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/simple;\n d=free.fr; s=smtp-20201208; t=1776013461;\n bh=BE0SV+0lVID2Pb8cW4V5GV/Put+u81MfSDZjeVgtQXQ=;\n h=Date:From:To:Cc:Subject:In-Reply-To:References:From;\n b=DqMqyEnxIpvu9m0ukzDBgFXFCs9D/CFHmT8MWMtqFlg4+m8grfqlCXJP9Qy6+3fcQ\n 53mHHA7rA1PIQUJzG7aZ3UMocIhrMyNuGYh/COfr9b1ZkMPb/p3sKq+co3oZrj+PIx\n fpbEdRwMKIQjSxsXNeo196zYaEBST5KpAsHprFJeOjX5+FrxFMq7t4R517bGajKKjQ\n fggxB7iPgUzGRP+IcKICh9gw0lVLi+7YAhGxQV+B6FheUcFTi78b1CHpLjSbhdpkxQ\n tmZ3rLAiWDLURDiFg3IvWgf9RrhpOJDKhVCwP0YYPn3DjL3E+29GInKDyChoa30CEA\n VbXGcSka+gemA==","X-Mailman-Original-Authentication-Results":["smtp1.osuosl.org;\n dmarc=pass (p=quarantine dis=none)\n header.from=free.fr","smtp1.osuosl.org;\n dkim=pass (2048-bit key,\n unprotected) header.d=free.fr header.i=@free.fr header.a=rsa-sha256\n header.s=smtp-20201208 header.b=DqMqyEnx"],"Subject":"Re: [Buildroot] [PATCH 1/2] package/libgpiod2: security bump to\n 2.2.4","X-BeenThere":"buildroot@buildroot.org","X-Mailman-Version":"2.1.30","Precedence":"list","List-Id":"Discussion and development of buildroot <buildroot.buildroot.org>","List-Unsubscribe":"<https://lists.buildroot.org/mailman/options/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=unsubscribe>","List-Archive":"<http://lists.buildroot.org/pipermail/buildroot/>","List-Post":"<mailto:buildroot@buildroot.org>","List-Help":"<mailto:buildroot-request@buildroot.org?subject=help>","List-Subscribe":"<https://lists.buildroot.org/mailman/listinfo/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=subscribe>","From":"Julien Olivain via buildroot <buildroot@buildroot.org>","Reply-To":"Julien Olivain <ju.o@free.fr>","Content-Transfer-Encoding":"7bit","Content-Type":"text/plain; charset=\"us-ascii\"; Format=\"flowed\"","Errors-To":"buildroot-bounces@buildroot.org","Sender":"\"buildroot\" <buildroot-bounces@buildroot.org>"}}]