From patchwork Fri Nov 9 08:15:07 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Peter Korsgaard X-Patchwork-Id: 995388 Return-Path: X-Original-To: incoming-buildroot@patchwork.ozlabs.org Delivered-To: patchwork-incoming-buildroot@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (mailfrom) smtp.mailfrom=busybox.net (client-ip=140.211.166.137; helo=fraxinus.osuosl.org; envelope-from=buildroot-bounces@busybox.net; receiver=) Authentication-Results: ozlabs.org; dmarc=none (p=none dis=none) header.from=korsgaard.com Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b="LXAEk0Y6"; dkim-atps=neutral Received: from fraxinus.osuosl.org (smtp4.osuosl.org [140.211.166.137]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 42rtJ54MCbz9s9G for ; Fri, 9 Nov 2018 19:15:32 +1100 (AEDT) Received: from localhost (localhost [127.0.0.1]) by fraxinus.osuosl.org (Postfix) with ESMTP id BE51886F32; Fri, 9 Nov 2018 08:15:29 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from fraxinus.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sPSPcrhVE_o3; Fri, 9 Nov 2018 08:15:28 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by fraxinus.osuosl.org (Postfix) with ESMTP id BB78686C41; Fri, 9 Nov 2018 08:15:28 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from silver.osuosl.org (smtp3.osuosl.org [140.211.166.136]) by ash.osuosl.org (Postfix) with ESMTP id 33B311C1693 for ; Fri, 9 Nov 2018 08:15:27 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by silver.osuosl.org (Postfix) with ESMTP id 30B51302BD for ; Fri, 9 Nov 2018 08:15:27 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from silver.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SXrgKEROnd+L for ; Fri, 9 Nov 2018 08:15:26 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.7.6 Received: from mail-ed1-f67.google.com (mail-ed1-f67.google.com [209.85.208.67]) by silver.osuosl.org (Postfix) with ESMTPS id B5A6D30287 for ; Fri, 9 Nov 2018 08:15:25 +0000 (UTC) Received: by mail-ed1-f67.google.com with SMTP id w19-v6so1078440eds.1 for ; Fri, 09 Nov 2018 00:15:25 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=1QTs2R1R1DvzQcQ4/U6MdDSYtwgdMOBRbDZ4UNkwSDo=; b=LXAEk0Y6Gi6UR4uBv+S/prbbvFkre2WzFLpoLomKiQG8YNbttbVvv/HMlpLkUYb/P7 IppA0BFffmxcYoc/+AAmmIk1bnMSe3M5cmlJ5njWk0vyLgTlkLz83znLnONG8XezJk1E GTtUhj2ZAco4G3yY0uTMrEBgjzlZNjvZkTd7sIFRLF2OlOHb1k4xaOFluFB182itdcdO JpSPuWDRWnqS7n2U24H9TfxBTuKS62HggE0SJ8+sIGhoEIJ58lkb16EjJbFiC6fdXtik BzbMgJcTyVRc5rP5WkG1F2juKHAEXmU+QOWd0G9b1hzwaMS6upfF2rNasExJKtRIjK6z H8VA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :mime-version:content-transfer-encoding; bh=1QTs2R1R1DvzQcQ4/U6MdDSYtwgdMOBRbDZ4UNkwSDo=; b=SoH6+CREl9/MYVDfM4KJAyQunfLMflo20mGX7yUMNm42yl+CLc9bD6g40ECutzrhbs p15pFLftRNM7LO2gvqBcoOhl0EeSl0p9ImWlAxLV97oZvWgGRDzVbWcKkufvoEKRGZtQ ANjzamSGJPBRZ5zh0ZcAC/xBMTVNLczyB5oK3EOP+mHuuOCIk5mTrLqI9hOGuw5WbYv1 n7OSX7I38qLZTR3eWxMf9aq7yjHz1n/qV8REPk+pKLqkyLFT9hpzE2UM4xNSk7mfZUv8 xG2EU/8iLTSIX3quFbB6TncwMtBToXnhBan7XrEkULd1efpN8oHuU2i4c6kxoz8atu2y jjCQ== X-Gm-Message-State: AGRZ1gJT1PTTUTH48r6KFY1ty604OUo7uKf+b0fOjGyvfi+PE6VNtQ/w a8dcwr+NxNd4OsFL/B0YFt/XVIVx X-Google-Smtp-Source: AJdET5cj2C7uLGiO85l5eAUzG8yJc3Cr+m4ot1J/uYw3gUmjd5ZIZiTXPbfM0AamIsIHQk3Tab1ZvQ== X-Received: by 2002:a17:906:1141:: with SMTP id i1-v6mr1192166eja.110.1541751323252; Fri, 09 Nov 2018 00:15:23 -0800 (PST) Received: from dell.be.48ers.dk (d51a5bc31.access.telenet.be. [81.165.188.49]) by smtp.gmail.com with ESMTPSA id b18-v6sm914195eju.38.2018.11.09.00.15.22 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Fri, 09 Nov 2018 00:15:22 -0800 (PST) Received: from peko by dell.be.48ers.dk with local (Exim 4.89) (envelope-from ) id 1gL1wn-00050R-I5; Fri, 09 Nov 2018 09:15:21 +0100 From: Peter Korsgaard To: buildroot@buildroot.org Date: Fri, 9 Nov 2018 09:15:07 +0100 Message-Id: <20181109081507.18820-1-peter@korsgaard.com> X-Mailer: git-send-email 2.11.0 MIME-Version: 1.0 Subject: [Buildroot] [PATCH] mosquitto: security bump to version 1.5.4 X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Peter Korsgaard Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" From the announcement: When using a TLS enabled websockets listener with require_certificate enabled, the mosquitto broker does not correctly verify client certificates. This is now fixed. All other security measures operate as expected, and in particular non-websockets listeners are not affected by this. https://mosquitto.org/blog/2018/11/version-154-released/ Drop patch 0001, now applied upstream: https://github.com/eclipse/mosquitto/pull/933 Signed-off-by: Peter Korsgaard --- ...001-_GNU_SOURCE-needed-for-EAI_INPROGRESS.patch | 46 ---------------------- package/mosquitto/mosquitto.hash | 2 +- package/mosquitto/mosquitto.mk | 2 +- 3 files changed, 2 insertions(+), 48 deletions(-) delete mode 100644 package/mosquitto/0001-_GNU_SOURCE-needed-for-EAI_INPROGRESS.patch diff --git a/package/mosquitto/0001-_GNU_SOURCE-needed-for-EAI_INPROGRESS.patch b/package/mosquitto/0001-_GNU_SOURCE-needed-for-EAI_INPROGRESS.patch deleted file mode 100644 index e350e465b4..0000000000 --- a/package/mosquitto/0001-_GNU_SOURCE-needed-for-EAI_INPROGRESS.patch +++ /dev/null @@ -1,46 +0,0 @@ -From d684055b2b92e7ec5793e70c9a80c7f8e45e0696 Mon Sep 17 00:00:00 2001 -From: Bernd Kuhls -Date: Fri, 24 Aug 2018 16:38:42 +0200 -Subject: [PATCH] _GNU_SOURCE needed for EAI_INPROGRESS -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Define of _GNU_SOURCE is needed to be able to use EAI_INPROGRESS in -loop.c. - -This patch fixes a build error - -loop.c:334:17: error: ‘EAI_INPROGRESS’ undeclared (first use in this function) - if(rc == EAI_INPROGRESS){ - -occuring with a glibc-2.27-based buildroot toolchain for sparc64 - -Target: sparc64-buildroot-linux-gnu -[...] -gcc version 6.4.0 (Buildroot 2018.05) - -Source: -http://autobuild.buildroot.org/toolchains/tarballs/br-sparc64-full-2018.05.tar.bz2 - -Patch sent upstream as PR 933. - -Signed-off-by: Bernd Kuhls ---- - config.h | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/config.h b/config.h -index 7607019..ba0ba93 100644 ---- a/config.h -+++ b/config.h -@@ -39,4 +39,6 @@ - # define _POSIX_C_SOURCE 200809L - #endif - -+#define _GNU_SOURCE -+ - #endif --- -2.18.0 - diff --git a/package/mosquitto/mosquitto.hash b/package/mosquitto/mosquitto.hash index b38830b8b5..96e2ae9369 100644 --- a/package/mosquitto/mosquitto.hash +++ b/package/mosquitto/mosquitto.hash @@ -1,5 +1,5 @@ # Locally calculated after checking gpg signature -sha256 3081a998d303a883b1cd064009beabc88aa9159e26f5258a4ae6007160491d10 mosquitto-1.5.3.tar.gz +sha256 5fd7f3454fd6d286645d032bc07f44a1c8583cec02ef2422c9eb32e0a89a9b2f mosquitto-1.5.4.tar.gz # License files sha256 cc77e25bafd40637b7084f04086d606f0a200051b61806f97c93405926670bc1 LICENSE.txt diff --git a/package/mosquitto/mosquitto.mk b/package/mosquitto/mosquitto.mk index 1d72f9b16e..fcce0535cb 100644 --- a/package/mosquitto/mosquitto.mk +++ b/package/mosquitto/mosquitto.mk @@ -4,7 +4,7 @@ # ################################################################################ -MOSQUITTO_VERSION = 1.5.3 +MOSQUITTO_VERSION = 1.5.4 MOSQUITTO_SITE = https://mosquitto.org/files/source MOSQUITTO_LICENSE = EPL-1.0 or EDLv1.0 MOSQUITTO_LICENSE_FILES = LICENSE.txt epl-v10 edl-v10