From a6e83692e28755c4b408005102fa95c0bc7d96db Mon Sep 17 00:00:00 2001 From: Ricardo Salveti Date: Tue, 8 Sep 2026 21:43:09 +0000 Subject: [PATCH 01/10] ci: base.lock: update layers to latest Relevant changes for oe-core: - 81e6a2d41 maintainers: Assign maintainer for recipes - 544846662 build-appliance-image: Update to master head revisions - fa11c2f1b python3-numpy: upgrade 2.5.2 -> 2.5.3 - 1e95a27e6 python3-git: upgrade 3.1.61 -> 3.1.62 - 77c3a28b7 gstreamer1.0-rtsp-server: upgrade 1.28.6 -> 1.28.7 - 5b5060015 gstreamer1.0-libav: upgrade 1.28.6 -> 1.28.7 - 8c250931c gstreamer1.0-plugins-good: upgrade 1.28.6 -> 1.28.7 - 94316519b gstreamer1.0-plugins-base: upgrade 1.28.6 -> 1.28.7 - 34dc711ad gstreamer1.0-plugins-bad: upgrade 1.28.6 -> 1.28.7 - 18d0669e2 gstreamer1.0-plugins-ugly: upgrade 1.28.6 -> 1.28.7 - 25f067133 gst-examples: upgrade 1.28.6 -> 1.28.7 - ac06694bd gstreamer1.0-python: upgrade 1.28.6 -> 1.28.7 - 4bcd8d071 gst-devtools: upgrade 1.28.6 -> 1.28.7 - 2e2e4b26c gstreamer1.0: upgrade 1.28.6 -> 1.28.7 - c2b681e39 busybox: enable findfs for initramfs LABEL support - 122c019f6 python_hatching: remove empty site-packages workaround - f56a34356 python3-iniconfig: remove obsolete DEPENDS - 85c0b6cd5 rpm: add tag to SRC_URI - a2a796caa iproute2: Add subpackage for dcb command - e31479ddb spdx30_tasks: Fix duplicated revision in Git PURLs - 65e1f6a54 maintainers.inc: add myself for several recipes - 691a23ce0 maintainers.inc: Update maintainer for psplash and systemd recipes - eb31aa155 python3: ptest: skip flaky test_taskgroup_23 - ad44f5edf sstate-cache-management: check also SSTATE_DIR environment variable - a17fe3c8f python3-flit-core: use flit-core sdist instead of flit - 9dc25f6f5 linux-yocto/7.2: update to v7.2.4 - e9a7fd907 linux-yocto/6.18: rt: update to v6.18.37-rt6 - ebd93719c linux-yocto/7.2: rt: update to v7.2-rt5 - 55c0ddf22 linux-yocto/7.2: menuconfig,mconf-cfg: Fix broken menuconfig outside of Yocto env - 18808c188 devtool: deploy: remove dead files_list computation - 462019b92 devtool: deploy: make pseudo calls independent of bitbake.conf - 76b8b8320 runqemu-export-rootfs: set PSEUDO_INCLUDE_PATHS for unfsd - 6c6d0ea7b oe-selftest: devtool ide-sdk: test install task - 008d6ed5d devtool: ide-sdk: run do_install through BitBake - 5265a1864 oe-selftest: tinfoil: test prepared task runner - 767faabe0 devtool: ide-sdk: pre-select attach process with processFilter - 9599c2837 oe-selftest: devtool ide-sdk: do not guess the slirp SSH port - a6d6d8500 devtool: ide-sdk: fix GDB loading stale libs instead of recipe's own build - fda394c2b initramfs-framework: support LABEL with root-only udev trigger - 7346ffe19 kernel-fit-image: Don't add hash node when signing is enabled - 0b41c42c0 multilib: make preferred_provider mirroring deterministic - db2e0fdf8 sbom-cve-check: enable offline mode - 9fcb4b9b1 python3-sbom-cve-check: update to version 1.3.4 - 101c03031 recipes: remove redundant PYPI_PACKAGE assignments - 3b81e8bc3 sbom-cve-check-update-db: Exclude recipes from rm_work - dd3a1d5df wget: fix CVE-2026-16599 - bb24e394d wget: add ptest support - f3e3ccba7 zstd: add ptest support - 1d61d5ba9 toolchain-scripts: fix kernel host tool builds broken in the SDK - e1a4d9b48 barebox-tools: Fix linking the target tools with clang - 8c4711e49 python3: ptest: skip flaky test_attach_to_process_without_colors - 3e109772d maintainers.inc: Updating maintainer for recipes - 47021aa89 libpcap: upgrade 1.10.6 -> 1.10.7 - 243a67953 taglib: upgrade 2.3.1 -> 2.3.2 - 2354aa1ba swig: upgrade 4.5.0 -> 4.5.1 - af377d60a python3-uv-build: upgrade 0.12.9 -> 0.12.10 - b67db4fee pkgconf: upgrade 3.0.6 -> 3.0.7 - 8875c7e8d libxml2: upgrade 2.15.3 -> 2.15.4 - 579851cc9 hwdata: upgrade 0.410 -> 0.411 - 9d39d2532 oeqa/utils/metadata: Add missing import bb - 02890c1ef kernel-module-split: Remove get_ext_mod - 7b265fc0e meta/lib: Clean up python library imports - bbb014ed3 libical: refresh build path removal - 7e92e1fe3 wireless-regdb: upgrade 2026.05.30 -> 2026.09.03 - 9bb1edd82 python3-vcs-versioning: upgrade 2.3.2 -> 2.3.4 - 5e4fb5cb9 python3-setuptools-scm: upgrade 10.2.2 -> 10.2.3 - 1f71b4842 enchant2: upgrade 2.8.19 -> 2.8.21 - 932f54349 devtool: ide-sdk: harden debug server startup wait - 4f88e807d curl: upgrade 8.21.0 -> 8.22.0 - 82dd206db openssl: use nonarch_libdir for openssldir - 1925a746e util-linux: upgrade 2.42.2 -> 2.42.3 - 88620a3d9 scripts/oe-depends-dot: give the dotfile argument a sensible default - 73f117e08 scripts/oe-depends-dot: fix Fonud -> Found typo in warning - a28f3eeb7 scripts/oe-depends-dot: remove custom argument checking - dff6a5e7a scripts/oe-depends-dot: fix dotfile argument type - 8ee0595d9 ffmpeg: add libdav1d to PACKAGECONFIG - d6a3f68e1 pypi: improve upstream check regex - 016095379 classes/pypi: rename pypi_package() to pypi_default_package() - be391d8a8 classes/pypi: only set downloadprefix in SRC_URI if needed - 0330391aa python/*: remove spurious CLEANBROKENs - 8597de0d9 rust: Upgrade 1.98.0 -> 1.98.1 - f2f1662e2 lib/oe/lsb: Add missing os import - f60cf56e3 mesa-demos: upgrade to latest revision - 9545bd61c python3-uv-build: upgrade 0.12.8 -> 0.12.9 - f78a0cc4b python3-uv-build: upgrade 0.12.7 -> 0.12.8 - aa620e86b glibc: stable 2.44 branch updates - d9da62ee8 wpa-supplicant: Split .config generation into its own function - 00e104eb9 nasm: update 3.01 -> 3.02 - 3fc136afb documentation.conf: add documentation for KERNEL_MODULE_INSTALL_PREFIX variable - a1eb6c52b kernel: centralize kernel module installation path in one variable - 1a330e61b package.py: remove stripping and splitting skip for signed kernel modules - c4dd28c7d kernel: re-sign kernel modules after package stripping process - a608d107c lib/oe/kernel_module.py: add get_ext_mod function for module signing - b567c2f0d package: no longer modify paths in save_debugsources_info() - 75f7ac0fd meta-selftest/devtool/bbpath: Add missing import - c01c20f35 sanity.conf: Require bitbake 2.19.1 for bb.fetch changes - 24c568b47 meta/scripts: Replace bb.fetch2 with bb.fetch - a4a307756 oe-selftest: fitimage: update comments - cf8af85a4 classes-recipe: uboot: update comments on kernel-fitimage - dfa567390 rootfs.py: fix run-postinsts removal on multilib images - 5e06d8deb oe-selftest: devtool ide-sdk: cover --package filters - c8aab18cc devtool: ide-sdk: forward --package/--file-glob deploy filters - 7801676ac oe-selftest: devtool ide-sdk: add slirp networking test - fcd096094 devtool: ide-sdk: auto-disable ssh host key checking for loopback targets - 5cc15eccb devtool: ide-sdk: support runqemu slirp - 3f3634c14 oeqa: QemuTarget: set use_slirp when slirp is in runqemuparams - fa4bedbce oe-selftest: devtool ide-sdk: adapt tests for auto-written image debug settings - 929a8c198 devtool: ide-sdk: auto-write image debug settings to bbappend - 926291203 cpp-example: fix stuck breakpoints when attaching and daemonize properly - 1e23d86f3 devtool: ide-sdk: VSCode IntelliSense for rootfs-dbg sources - 5a5604967 oe-selftest: devtool deploy-target: test --package/--file-glob filters - cf6d07f8d devtool: deploy-target: add --package/--file-glob filters - 883f48709 runqemu-extract-sdk: set PSEUDO_INCLUDE_PATHS for the extraction - fc32be295 populate_sdk_base: add a kernel-src SDK feature - c4cbf6a22 sysstat: upgrade 12.7.9 -> 12.8.0 - a4777b06f mesa: Upgrade 26.2.1 -> 26.2.2 - 40b918da9 iproute2: upgrade 7.1.0 -> 7.2.0 - d2d1ee9d0 lttng-tools: Avoid the CC-BY-SA-4.0 license for code packages - 67709f0ab python3-mako: remove redundant python3-wheel-native dependency - 934e84e9e maintainers.inc: Updating maintainer for recipes - 42fbec423 font-util: depend on util-macros-native - 6b7a2129c xorg-lib: remove redundant util-macros dependencies - 9f71802be xorg-lib-common: depend on util-macros-native - b49319816 xorg-driver-common: depend on util-macros-native - ab4311dbf rgb: remove redundant util-macros dependency - 448aca675 xcb-util: add explicit util-macros-native dependency - 5442ab783 libxcb: add explicit util-macros-native dependency - 744326098 go-binary-native: upgrade 1.27.0 -> 1.27.1 - e87255c5a go: upgrade 1.27.0 -> 1.27.1 - 21bb44ca7 python3-setuptools-scm: upgrade 10.2.1 -> 10.2.2 - bba3f3c1a python3-vcs-versioning: upgrade 2.3.1 -> 2.3.2 - 6af489fef spirv-llvm-translator: upgrade 23.1.0 -> 23.1.1 - 26cb5c582 pango: upgrade 1.58.0 -> 1.58.2 - 672e5cbd7 librsvg: fix test suite with pango 1.58.1 onwards - 7e696b1fa makedepend: remove recipe - da7d241cc mesa: remove obsolete build dependencies - b7c02c51e python3-uv-build: upgrade 0.12.6 -> 0.12.7 - d79eb2272 python3-pygobject: upgrade 3.56.3 -> 3.58.0 - 6c9310024 python3-build: upgrade 1.5.1 -> 1.6.0 - e60cfdcf4 debianutils: upgrade 5.23.2 -> 5.24 - 2e986f01c binutils-testsuite: Set CC_FOR_TARGET and CXX_FOR_TARGET in site.exp - c3c5e4447 oeqa/sdk: check for pkgconf rather than pkgconfig - e6a2d7659 openssl: Upgrade 4.0.1 -> 4.0.2 - f962fbb1c abi_version: Bump for rpm changes - e97283d80 rpm: disable the RPM 6 pkgconfig dependency generator - e871a7fe8 lib/oe/package_manager/rpm: handle RPM 6 non-zero exit on %post failure - 1d3ec2442 package_rpm.bbclass: suppress RPM 6 fileattr dependency generators - 88db94353 lib/oe/package_manager/rpm: Enable DNF filelists to resolve file deps - cfa314d41 libarchive: Disable RPM filter auto-bidding and update huge_rpm test - 8401bac0c libarchive: Add RPM format reader to support rpm 6 - e6f621897 libarchive: Make it work with rpm 6.0.2 - c426d925c rpm: 4.20.1 -> 6.0.2 - 3b69836a7 lib/oe/package.py: Don't redirect stderr - 560ebe0f3 lib/oe/package.py: Don't add ldconfig_postinst_fragment for glibc or musl - 583d33d6f package_rpm.bbclass: Define _lib and _libdir for rpmbuild - 093ae9987 package_rpm.bbclass: Drop external dependency generator to support rpm 6 - 0e7f898dc clang/llvm: Ignore tests fail with clang/llvm 23 upgrade - f546436a9 gettext: Export a fully-flagged Objective-C compiler - 2ff9490c1 vulkan-samples: Don't turn clang 23's -Wdangling-gsl into an error - c87c774a4 ovmf: Fix memcpy alias prototype for clang 23 - 9a50d4b9a pango: Don't turn clang 23's -Wunused-but-set-global into an error - 1a0cc5e99 clang: Disable clangd's decision-forest completion model on powerpc - 995483825 rust: Do not pass the removed x86 amx-tf32 feature to LLVM 23 - 181b5450f rust: Fix build and oe-selftest failures with LLVM 23 - 2f9e243c1 openmp: Build via the LLVM runtimes entry point - 7961efc37 spirv-llvm-translator: Upgrade to 23.1.0 - d1575787a clang/llvm: Upgrade to 23.1.0 release - 714654a16 linux-yocto/6.18: update to v6.18.48 - 4dfc7fd9d kernel-devsrc: ship tools/include for archscripts host tools - ea5ea606d linux-yocto/7.2: remap rust debug info paths - 88cc2364e linux-yocto/7.2: update to v7.2.2 - 359fc466f linux-yocto/7.2: BSPs: fix configuration warnings - badce8d33 linux-yocto/7.2: introduce reference kernel recipes - c0fed0b0e libgcrypt: fix upgrade 1.12.2 -> 1.12.3 - c264544ea maintainers.inc: Update owner for strace pigz libcap-ng popt - 89c122495 python3-git: upgrade 3.1.60 -> 3.1.61 - 20bf704e5 openssl: upgrade 3.5.8 -> 4.0.1 - 0abdda25d sysvinit: rc: fix inconsistent indentation - 1cb35e0f7 Revert "python3-pycairo: inherit python3-dir not python3targetconfig" - 6d6aaf420 qemu: backport RISC-V TLB page flushing patches - 4d2163f05 librepo: upgrade 1.20.0 -> 1.21.0 - 8904c316f gnupg: upgrade 2.5.21 -> 2.5.22 - 9900ea657 libpcre2: upgrade 10.47 -> 10.48 - 25dac0c07 expat: upgrade 2.8.3 -> 2.8.4 - 45aa2ef31 libssh2: fix CVE-2026-58051 - ac229bdfa python3-pdm: upgrade 2.28.2 -> 2.29.0 - b920bfeff re2c: upgrade 4.5.1 -> 4.6 - 353840cc5 python3-hypothesis: upgrade 6.165.10 -> 6.167.0 - 7edc41781 libksba: upgrade 1.8.0 -> 1.8.1 - 27e2ee0ee libgcrypt: upgrade 1.12.2 -> 1.12.3 - 08c63d67f appstream: upgrade 1.1.6 -> 1.2.0 - f366e6257 python3-wcwidth: upgrade 0.8.2 -> 0.8.3 - 3303235e8 orc: upgrade 0.4.42 -> 0.4.43 - b3de66dbb libical: upgrade 4.0.4 -> 4.0.5 Relevant changes for bitbake: - 046a90b doc/bitbake-user-manual-ref-variables: document PREFERRED_RPROVIDER - b8dfa35 knotty: show elapsed time on the task progress bar - ba0bdd3 asyncrpc/serv: Add missing import - 9dbf27b tests/fetch: Switch to YP mirror repos instead of github - 3860fab bin/bitbake-setup: print a note about fetcher log if something fails there - 69810e0 lib/bb/_vendor: resync to add tomli - 1a3b0cb vendor.txt: add tomli - a181827 tests/fetch: Drop ftp checkstatus test - f311ff3 tests/fetch: Swap bitbake github mirror for YP one - a64b315 tests/fetch: Swap github grpc repo for our own small test repo - 5887225 fetch/gitsm: Store the original url data to fix relative gitsm paths - 7d41b3d doc: quote the value in the named-checksum example - 0b8b220 doc/bitbake-user-manual-metadata: move := section before ??= - 3c118ff toaster: Update to django 5.2 - 714bcfa runqueue: wait for covered tasks before setscene - 5ef9184 runqueue: fix remaining attributes created outside of constructor - 5b4d951 runqueue: declare pressure/load attributes in RunQueueScheduler.__init__ rather than dynamically - 447300e runqueue: optimize construction of rev_prio_map - c653137 runqueue: cleanup imports - 3425894 bitbake: Bump to version 2.19.1 - 385a7e3 doc: update manual to reflect bb.fetch2 => bb.fetch migration - 28cf50d tests: add fetch_import tests to test bb.fetch2 => bb.fetch migration - 10de4aa bin, lib, conf: use bb.fetch instead of bb.fetch2 - 34ea7cb lib: rename fetch2 as fetch; invert compat shim to make bb.fetch2 = bb.fetch - d369bfd fetch2: Raise on git lfs fetch failures - f4f453f fetch2/git: Clarify error about missing LFS support - 365b33a toaster/tests/layerdetails: Update tests to use labels and scrolling function - efc44c2 tests/selenium_helpers_base: Add wait_until_element_clickable - 129ee87 toaster/layerdetails: Add id labels to textareas to make tests more robust - ca65b4e toaster: Rename wait_until_element_clickable -> wait_until_finder_clickable - 975b322 default-registry: use core/yocto/monitor-disk-space fragment by default - 9168166 doc: continue the eventmask example onto its second line - 4479f4e fetch2/wget: remove orphaned NamedTemporaryFile in _fetch_index - 7f186c0 hashserv: server: Fix upstream get-unihash miss truncating stream - 8714e08 hashserv: tests: Add test for upstream pipelining - fb900a1 hashserv: tests: Add more upstream tests - 09c454f hashserv: server: Use streaming and queue API for upstream exist queries - d4e5cf2 hashserv: server: Use streaming and queue API for upstream unihash queries - 9e0f064 hashserv: server: Add queued streaming API - 544d9f1 hashserv: client: Add asynchronous streaming API - 272651f hashserv: tests: Improve test logging - 425822d asyncrpc: serv: Cancel all clients on server stop - 34d171b asyncrpc: serv: Use Task Group - 4fc36e6 asyncrpc: Add Task Group - 98078e9 runqueue: report memory pressure limit correctly - 3e4c7b5 runqueue: clean up dumpsigs polling - f591e5b runqueue: remove RunQueueExecute.build_stamps2 which is never read - e8f2d39 runqueue: remove long-unused RunQueueData get_user_idstring/get_short_user_idstring - 99e546a runqueue: remove unused RunQueueExecute.sorted_setscene_tids; declare setscene_tids_generator in __init__ - d7f1c53 runqueue: remove unused attributes/variables - 7f24c51 runqueue: fix bad check in process_possible_migrations Relevant changes for meta-arm: - ade09d3a arm/fiptool: fix native linkage - fede80de arm/trusted-firmware-a: enable OpenSSL stub engine API - e54d1518 arm-bsp/u-boot: enable OpenSSL engine stub API Relevant changes for meta-openembedded: - cbec9a20d packagegroup-meta-python: remove python3-booleanpy - 360aa84ea polkit-gnome: Fix build against gtk+3 without the X11 backend - fae790923 pegtl: Fix build with clang-23 - 2eaf5f05b microsoft-gsl: upgrade 4.2.2 -> 5.0.0 - e2cc2b4e0 libfaketime: Upgrade to 0.9.13 - 2fe2f967f pcapplusplus: Fix build with clang-23 - 09ec1df38 turbostat: fix build with kernel 7.x - fa8c85fb3 gdm: remove dbus-broker from RCONFLICTS - a23b5ec9f gimp: add librsvg-gtk to RDEPENDS - 745103087 gnome-keyring: upgrade 46.2 -> 50.0 - 1c4c37d21 systemd-systemctl: enable templated services - abb086bef fitimage: strip pkcs11: prefix in FITIMAGE_SIGN_KEYDIR example - e1f5f22b3 fitimage: add support for specifying FITIMAGE_CONFIG_FDTO_PREFIX - 4bf39904e ostree: Upgrade 2026.3 -> 2026.4 - 322a5c29c valkey: Upgrade 9.1.1 -> 9.1.2 - 154f4c9c2 libosinfo: Do not error on clang's -Wunused-but-set-global - cdf50b05a zfs: Upgrade to 2.4.4 release - b3d8c6889 libcamera: Fix build with clang 23 - bd648b6cb bpftrace: Fix tests to cross compile - 3319a20a8 bpftrace: Upgrade to 0.26.1 - e21c2256d assimp: Do not treat warnings as errors - 53987e89b webkitgtk3: update 2.52.5 -> 2.52.6 - 03f693994 boot-time-analysis-tools: add boot time profiling tools - 9ad69da3d gnome-control-center: conflict with gnome-online-accounts-gtk - 824f6afda gnome-online-accounts-gtk: add recipe - ba483062c localsearch: replace the reproducibility patch with a meson option - 4ab29af9c gnome-calculator: upgrade 48.0 -> 50.0 - 1efc7dacf gnome-calendar: upgrade 48.0 -> 50.0 - 9546dc595 nautilus: upgrade 49.5 -> 50.3 - 4ce7b133a gexiv2: upgrade 0.14.6 -> 0.16.2 - ebc95b8c0 gnome-photos: depend on gexiv2-0.14 - fbf507c30 gegl: depend on gexiv2-0.14 - 591010264 gimp: depend on gexiv2-0.14 - dfe6ba17f gexiv2-0.14: add recipe for the 0.14 series - 947d92cb5 gnome-remote-desktop: upgrade 49.1 -> 50.2 - 17210cb1a gnome-boxes: upgrade 49.0 -> 50.0 - 3024e4753 gnome-font-viewer: upgrade 49.0 -> 50.0 - 6d26eb4ce gnome-control-center: upgrade 49.9 -> 50.4 - d00bce30a gnome-session: upgrade 49.3 -> 50.1 - f14e22498 gnome-settings-daemon: upgrade 49.1 -> 50.1 - e39fd90bd dovecot: Work around clang 23 hang - 92f2af09b evolution-data-server: don't pull webkitgtk by default - 34977a4c5 gnome-online-accounts: drop obsolete webkitgtk dependency - f13d77904 glycin: Do not enable libheif support by default - 6b1ec1fc3 thermald: Fix build with clang 23 - d739209e1 python3-paho-mqtt: remove obsolete DEPENDS - 03fc82303 python3-ordered-set: remove obsolete DEPENDS - c3085021b python3-mccabe: remove obsolete DEPENDS - cf2ed97c6 python3-astroid: remove obsolete DEPENDS - 9dd6f0c98 python3-arpeggio: remove obsolete DEPENDS - 1962463e2 bcc: Fix build with LLVM 23 - 138648195 castxml: Fix build with LLVM 23 - a585830e2 image_types_sparse: create symlinks for generated sparse images - 941228915 python3-glances: Upgrade 4.3.2 -> 4.5.6 - be3237b53 python3-cmd2: Upgrade 4.2.2 -> 4.2.3 - bb86317d9 python3-mlcommons-loadgen: remove redundant assignment - 8fa238d24 python3-prompt-toolkit: remove redundant assignment - 8708551b1 python3-paho-mqtt: remove redundant assignments - 93e4e8685 python3-jstyleson: remove redundant PYPI_PACKAGE_EXT - 00a0c3bac python3-icu: remove redundant S assignment - 80df13b0f python3-gammu: remove redundant S assignment - 91cac3259 python3-future: remove obsolete PYPI_PACKAGE_HASH - db0f78240 thingsboard-gateway: remove pypi inherit - c493265bb python3-websocket-client: use right PEP517 build class - 3809d7532 meta-python: remove redundant PYPI_PACKAGE assignments - f727a0847 meta-oe: remove redundant PYPI_PACKAGE assignments - e2f053038 meta-python: remove redundant UPSTREAM_CHECK_PYPI_PACKAGE - 6e8cd5b08 python3-paho-mqtt: idiomatically set SRC_URI - ba1725f20 python3-thrift: use PYPI_ARCHIVE_NAME_PREFIX - ee7d636c5 libpeas: upgrade 2.0.7 -> 2.2.1 - 05d502ef9 mozjs: update 128->140 - e4ccebad8 gnome-shell: update - 0a8fc9c54 gnome-shell-extensions: update 48.3 -> 50.3 - 578e57f3b mutter: update 48.7 -> 50.4 - 07b358a0b glycin: add recipe - 82b6a642b gjs: update 1.84.2 -> 1.88.1 - 591dc50dc python3-nocasedict: Upgrade 2.2.0 -> 2.2.1 - 8d5b629c7 python3-charset-normalizer: Upgrade 3.4.9 -> 3.5.1 - 31c8104ca python3-virtualenv: Upgrade 21.7.7 -> 21.7.8 - f403e7661 capnproto: build position independent code - 9c6364ff7 xterm: upgrade 410 -> 411 - 69c508d1f xclock: upgrade 1.2.0 -> 1.2.1 - db0dc39b9 uftrace: upgrade 0.19 -> 0.20 - 3d0ec7e83 qpdf: upgrade 12.4.0 -> 12.4.1 - e99a849d1 python3-zeroconf: upgrade 0.150.0 -> 0.151.3 - 20e0ee7cf python3-wrapt: upgrade 2.3.0 -> 2.4.0 - 33c50aae9 python3-websocket-client: upgrade 1.9.0 -> 1.9.2 - 4ca3f6f33 python3-typer: upgrade 0.27.1 -> 0.27.2 - ffcc7473c python3-tox: upgrade 4.61.1 -> 4.61.2 - f9ca22a90 python3-responses: upgrade 0.26.2 -> 0.26.3 - 802a433d3 python3-regex: upgrade 2026.7.19 -> 2026.8.31 - 1df345dcf python3-pylint: upgrade 4.0.7 -> 4.0.8 - 1291293f6 python3-pyais: upgrade 3.2.1 -> 3.2.2 - 32677ed0f python3-ninja: upgrade 1.13.0 -> 1.13.2 - f59db44de python3-msgpack: upgrade 1.2.1 -> 1.2.2 - 4141643ee python3-mmh3: upgrade 5.2.1 -> 5.3.0 - 438d5e72a python3-kiwisolver: upgrade 1.5.0 -> 1.5.1 - 57bf10864 python3-ipython: upgrade 9.16.1 -> 9.17.0 - 09af582b3 python3-importlib-metadata: upgrade 9.0.0 -> 9.0.1 - 69402adc2 python3-google-auth: upgrade 2.56.3 -> 2.57.0 - 6c8ffdb96 python3-google-auth-oauthlib: upgrade 1.4.0 -> 1.4.1 - 30559247a python3-engineio: upgrade 4.13.5 -> 4.14.0 - 92414891e python3-coverage: upgrade 7.15.4 -> 7.16.0 - 779f975db python3-cmake: upgrade 4.4.2 -> 4.4.3 - 7f8b43dbe python3-ansi2html: upgrade 1.9.2 -> 1.9.3 - 364b7782f pstack: upgrade 2.17.7 -> 2.18.4 - 0d280492e nanopb-generator,nanopb-runtime: upgrade 0.4.9.1 -> 0.4.92,0.4.9.1 -> 0.4.92 - b936079f5 libvpx: upgrade 1.16.0 -> 1.17.0 - d7ca6a3ce libtorrent: upgrade 0.16.20 -> 0.16.21 - 0fc08e1f5 libcloudproviders: upgrade 0.4.0 -> 0.4.1 - 36440748f imlib2: upgrade 1.12.6 -> 1.12.7 - 6b22c0bf0 glaze: upgrade 8.1.0 -> 8.3.0 - e784e0cd5 feh: upgrade 3.12.2 -> 3.12.4 - 2da3bce1a catch2: upgrade 3.15.3 -> 3.16.0 - a7a205ed9 ldns: Disable GOST support - 7315e7106 python3-rtslib-fb: Initial commit - 469740de2 Revert "hackbench: add Linux scheduler benchmark recipe" - 60790573d Revert "cyclictest: add real-time latency measurement recipe" - 536fb28fc uutils-coreutils: upgrade 0.10.0 -> 0.11.0 - b3dbb6efa python3-qrcode: Convert optional dependencies into PACKAGECONFIG - 0fbb14ef8 android-tools: Install bootimg utilities - 951a2acf1 python3-orjson: Upgrade 3.11.9 -> 3.12.0 - 233046850 glaze: fix install paths - d72d11b79 doxygen: strip build paths from the generated sources - fee2d5d20 python3-colorlog: upgrade 6.11.0 -> 6.12.0 - 26bb92a95 python3-cmd2: upgrade 4.2.1 -> 4.2.2 - 52cb877f2 python3-discovery: upgrade 1.5.2 -> 1.6.0 - bd3e7528e python3-simplejson: upgrade 4.1.1 -> 4.1.2 - a9ded2981 python3-sdbus: upgrade 0.14.2 -> 0.14.3 - b1fef8e1d python3-tox: upgrade 4.60.0 -> 4.61.1 - 66d3f2e11 python3-virtualenv: upgrade 21.7.4 -> 21.7.7 - 2f7977478 grpc: upgrade 1.83.0 -> 1.83.1 - 8b6a79bfa dovecot: upgrade 2.4.4 -> 2.4.5 - 42ff50bdf mpd: upgrade 0.24.14 -> 0.24.15 - b6c09f663 open62541: upgrade 1.5.6 -> 1.5.7 - 0a1705b8f nng: upgrade 1.11 -> 1.12.3 - 1b9aff4c0 python3-pytest-sugar: deselect test broken by pytest hook-signature skew - e8ff0094d python3-time-machine: load pytester plugin for testdir fixture in ptest - 765f779e8 python3-time-machine: fix ptest tzdata/dateutil issues - 1dc7ebf01 python3-wrapt: add python3-image for colorsys used by test_deferred_patching - 5c5e2576f python3-uvicorn: skip websocket tests unsupported/unstable under ptest - ea48e4000 python3-typing-inspection: skip test broken by CPython 3.13.15 Literal dedup - d89e202c6 python3-typer: fix ptest rich text-wrapping and subprocess PYTHONPATH - 7528dca88 python3-rapidjson: deselect test broken by modern CPython refcounting - 94f51886d python3-pyzmq: deselect test_process_teardown (fork-safety flake under qemu) - 7aa282b1c python3-pylint: fix astroid 4.1.2 functional-test fixture mismatches - cfe0f858c python3-pydbus: skip ptest cases gracefully when dbus-launch is missing - 8fb8a8d4e python3-pydantic: fix ptest ruff-version skew, pytest.warns skew, missing dep - 970c6b66b python3-orjson: skip OOM-prone/unrelated tests on memory-constrained target - 459f241b3 python3-flask: fix ptest failures from pytest/werkzeug version skew - 18dd7b4b7 python3-filelock: fix ptest cache-dir permissions and missing tasks/pythonpath - 63ebdf7e9 python3-bleak: fetch git tag with tests/ for ptest instead of PyPI sdist - c024e4975 srt: Match SRCREV to tag - 1a71a3e63 fitimage.bbclass: add command line property - 480b369ae googletest: upgrade 1.17.0 -> 1.18.0 - 7fd741939 pjproject: fix build with OpenSSL 4.0 - f4e34250a libcoap: fix build with OpenSSL 4.0 - 4b53361ea ntopng: fix build with OpenSSL 4.0 - 335021f7c libesmtp: fix build with OpenSSL 4.0 - bc4eee367 znc: fix build with OpenSSL 4.0 - 2e8eba02e snort3: fix build with OpenSSL 4.0 - 12024b3ae freeradius: fix build with OpenSSL 4.0 - 0978404d8 civetweb: fix build with OpenSSL 4.0 - bf9adc295 lftp: fix build with OpenSSL 4.0 - d6c472cc1 imapfilter: fix build with OpenSSL 4.0 - e335b7e6c boinc-client: fix build with OpenSSL 4.0 - c98c633af thrift: fix build with OpenSSL 4.0 - c4a28775b python3-grpcio: fix build with OpenSSL 4.0 - 273228675 grpc: fix build with OpenSSL 4.0 - 13ed6c9fc opensc: fix build with OpenSSL 4.0 - a1c389825 pkcs11-helper: fix build with OpenSSL 4.0 - 5d9afa02d libtorrent-rasterbar: fix build with OpenSSL 4.0 - 149152980 libnet-ssleay-perl: fix build with OpenSSL 4.0 - 8408bccf0 krb5: fix build with OpenSSL 4.0 - 3ed9fd5bb freediameter: remove openssl-engines from RDEPENDS - e5f8c8d53 php: upgrade 8.5.9 -> 8.5.10 - 64dcb55dc recipes: correct homepage - 559c95250 doxygen: upgrade 1.17.0 -> 1.18.0 - 6e9f266f1 nodejs: upgrade 24.19.0 -> 24.20.0 - 965ab7088 asyncmqtt: upgrade 10.3.0 -> 10.3.1 - 19771f75b dlm: update UPSTREAM_CHECK variables - 3a6c9d995 libsrtp: add UPSTREAM_CHECK_GITTAGREGEX - f4b73e8ec proftpd: upgrade 1.3.9c -> 1.3.9d - c57de8e1e aravis: add UPSTREAM_CHECK variables - 426b41776 srt: upgrade 1.5.6 -> 1.5.7 Relevant changes for meta-virtualization: - fd4fa494 kernel/cfg: CONFIG_XEN_DEBUG_FS - f596e356 kernel: add 7.2 virtualization enablement - 2ef8c36d Add Eclipse Ankaios container orchestrator recipe - 4d378803 irqbalance: add PACKAGECONFIG for ui - f5f342e8 python3-webob: add CVE_PRODUCT mapping - 5ff1998c podman: correct CVE_PRODUCT mapping - d41d76ea runc: correct CVE_PRODUCT mapping - 9ba73127 go-logrus: correct CVE_PRODUCT mapping - ec4f0790 ceph: update to v21.3.0-tip - 46858b55 virtiofsd: update to 1.14.0 - 010b6462 container-bundle: select the target arch when fetching multiarch containers - 340a1167 python3-dotenv: update to 1.2.3 - c83a62cb kubernetes: update to v1.36.4-tip - 947a2122 moby: update to v29.7.2-tip - cfd07db8 crun: update to 1.29.1-tip - c100290d virt-manager: update to v5.1.0-tip - 7054ae66 cockpit-machines: update to 355 - 2ed5c54d gunicorn: update to 26.1.0 - 11093742 python3-boto3: update to 1.43.75 - 8cbcba55 python3-botocore: update to 1.43.75 - f8bce68b python3-newrelic: update to 13.4.0 - f8cd34c1 python3-docker: update to 7.2.0 - 7ec1046a python3-webob: update to 1.8.11 - 9a193ef7 python3-bugsnag: update to 4.9.1 - 0450f1b7 extract-discovered-modules: derive golang.org/x/* VCS URLs - a570b1c3 incus: update to v7.3.0-tip - 25774241 docker-compose: update to v5.5.0-tip - 65f6de21 nerdctl: update to v2.3.5 - b5b647dc oe-go-mod-fetcher: skip modules whose commit is orphaned upstream - a16b3ea3 k3s: update to v1.36.3+k3s1-tip - 5098edfd vruntime: assert 'virtualization' on the vdkr/vpdmn rootfs images - 8b097471 vruntime: declare 'virtualization' so the distro is self-contained - d86f9dc1 vruntime: stop masking cgroup-lite (docker hard-depends on it) - 1d451d77 cosign: scope license scan to ./cmd/cosign - 32de31ad vcontainer: opt-in axis in the vxn dom0 (VXN_INCLUDE_AXIS) - b4608701 recipes-containers/axis: add the axis (Agent eXecution Isolation Substrate) CLI - c36c4205 vcontainer: suppress busybox's "Rebooting." on the clean-exit reboot - cf8ea04e vcontainer: add composable SDK build-config profiles - 68688cf2 nativesdk-qemu-vcontainer: trim host qemu to the SDK's architectures - 262ec1ae vcontainer: add opt-in dom0 slimming for the vxn SDK - 965df5b0 vcontainer: quiet the last two messages leaking on an interactive vxn run - 71c861ee vcontainer-tarball: size the SDK installer from SDKDEPLOYDIR - 6925f412 vcontainer: silence spurious console output during vxn runs - 1fde5770 cosign: update to v3.1.3-tip - f0e7e89e oe-go-mod-fetcher: fall back to full fetch for dumb-HTTP servers - e0e684b5 yq: update to v4.53.3-tip - 65c825dd rootlesskit: update to v3.1.0-tip - 80896f15 cni: update to v1.3.0-tip - 293af300 cdi: update to v1.1.0-tip - 88dc618f crosvm: update to v0.1.0-tip - 0489a97f netavark: update to v2.0.0-tip - 6a759711 podman: update to v6.1.0-dev-tip - 975dd53e cri-o: update to v1.36.0-tip - 6820470e containerd: update to v2.3.4 - 5a166be3 libvirt-glib: update to v5.0.0-tip - c2db3f1a skopeo: update to v1.24.0 - 4255f53f runc: update to v1.5.1 - ef7b8b41 buildah: update to v1.43.2 - 6030b92d lxc: update to v7.0.0 - 1feec24d libvirt: update to v12.6.0 - d02ab46b docker-distribution: update to v3.1.1 - a6cb95cd cloud-init: update to 26.2 - 5a5564ca python3-udica: update to v0.2.9-tip - 6c0f8bb4 openvswitch: update to v3.7.1-tip - 97ad8cf5 nagios-core: update to nagios-4.5.14-tip - 53cc09d2 kvmtool: update to -tip - 527a13a1 xvisor: update to v0.3.2-tip - c8e9ffc0 virt-viewer: update to v11.0-tip - a7393014 upx: update to v5.2.0-tip - 34574946 podman-compose: update to v1.6.0-tip - b5e80d95 passt: update to 2026_07_28.f8df3f1-tip - 63f787be lopper: update to v1.5.0-tip - 1ed0ef2d ipxe: update to v2.0.0-tip - 7073b73b diod: update to v1.1.0-tip - 6e5d8de1 criu: update to v4.2.1-tip - 2d200996 cri-tools: update to v1.36.0-tip - d2b7ad60 conmon: update to v2.2.1-tip Relevant changes for meta-audioreach: - d61e0af packagegroup-audioreach: add audioreach-pal-vui-intf-headers - 3da9e76 audioreach-pal: srcrev bump 158ee86...ce70815 Relevant changes for meta-updater: - 9f1d5c1 aktualizr: fix the build against OpenSSL 4.0 - a012466 sota: use KERNEL_CONSOLE for platform defaults - 6fa8be2 classes/image_types_ota: pull into the OTA sysroot without fsync - 8a9e395 ostree: update bbappend to 2026.4 Relevant changes for meta-ai: - 21e7b36 tflite: always fetch neon2sse instead of gating per-arch - 95f2357 litert: add x86_64 support - 9068f2f ci: skip fork build policy - 56138d1 ci: add standalone OpenEmbedded build loop - 6043e02 llama-cpp: fix NEON fp16 conversion build failure on qemuarm - 3700ac6 onnxruntime: vendor GSL v4.0.0 instead of depending on microsoft-gsl - 039cb23 pr_template: add standalone-build checklist item - 0609eb2 README: document standalone-build requirement - 391297c README: add maintainer contact - 0bcbc95 README: document patch submission - 891d792 tflite: add missing neon2sse SRCREV - 218f6e7 docs: align contributing and agent guidance for OpenEmbedded workflows Assisted-by: Claude Code:claude-fable-5-1 Signed-off-by: Ricardo Salveti --- ci/base.lock.yml | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/ci/base.lock.yml b/ci/base.lock.yml index f0b7d1baa..29c54f190 100644 --- a/ci/base.lock.yml +++ b/ci/base.lock.yml @@ -3,24 +3,24 @@ header: overrides: repos: oe-core: - commit: db81c1a42a0f552d9a8ec124f004ae2063d58c33 + commit: 81e6a2d411908a1c2aedadb48fc889d4c93e5a83 bitbake: - commit: 18cca50ba3da5ce27bc674478957bb08e7536b9a + commit: 046a90b0e9b7b914b7a95aec579cdc3fc9c7617a meta-arm: - commit: b0ff16aba48a197070daff28ef7ad67067fd3d88 + commit: ade09d3a60219f543d37b5fc2a2253105db89931 meta-openembedded: - commit: 8b1d948deee701859ece9f007cb09965f5e00680 + commit: cbec9a20d78add94235042c601e991574151e36e meta-virtualization: - commit: f45cc3787c11d040dbef8e7f956a4da420375829 + commit: fd4fa494c9878346e913ca9a7788bac0063a3ba6 meta-audioreach: - commit: c25274a1bf08e0a508f575f4ae0bcabb405329e7 + commit: fee6376b7f86ed11469385b956e6e59d1e49dc9a meta-selinux: commit: 7351443c6579671bcf048817438f1740ad23eaab meta-updater: - commit: 3f79539a8e1250c46d824b3af2415b9add945161 + commit: 9f1d5c17b1a39081b6070e07c5514e3db051b5fd meta-security: commit: 0339b65f63877ed36fcffa44953e57c3bb969ca9 meta-dpdk: commit: 6a59b0cd21084e33feb53b4f2d1310e49e1d4a83 meta-ai: - commit: 3511d6c9669683fc232211eb72e1549d6db6e660 + commit: 21e7b36b0d259a9cf5d2226160b227962f762585 From 7c252e6756eacde8e021f03f0084bf47b5b7e72f Mon Sep 17 00:00:00 2001 From: Ricardo Salveti Date: Tue, 8 Sep 2026 22:11:55 +0000 Subject: [PATCH 02/10] linux-yocto: upgrade 6.18 -> 7.2 OE-Core now ships linux-yocto 7.2 next to 6.18 and, with no preferred version set, selects 7.2 by default. The meta-qcom append only covered 6.18, so Qualcomm machines were silently kept on the older kernel. Move the append and the BSP descriptions to 7.2 and rebase the extra patches on the v7.2/standard/base tree: - the monaco-evk camera overlay landed upstream in 7.2, so the patch is dropped; - the hamoa-iot-evk camera overlay is rebased on the reorganised dts Makefile; - the apq8096-db820c GPU regulator workaround now targets the board .dtsi, which 7.2 split out of the .dts. CONFIG_CRYPTO_MICHAEL_MIC no longer exists in 7.2, so drop it from the common configuration fragments. Assisted-by: Claude Code:claude-fable-5-1 Signed-off-by: Ricardo Salveti --- ...com-monaco-evk-camera-Add-DT-overlay.patch | 130 ------------------ .../bsp/qcom-armv7a/qcom-apq8064.cfg | 0 .../bsp/qcom-armv7a/qcom-apq8064.scc | 0 .../bsp/qcom-armv7a/qcom-armv7a-standard.scc | 0 .../bsp/qcom-armv7a/qcom-armv7a.scc | 0 .../bsp/qcom-armv7a/qcom-msm8974.cfg | 0 .../bsp/qcom-armv7a/qcom-msm8974.scc | 0 .../bsp/qcom-armv7a/qcom-rpm.cfg | 0 .../bsp/qcom-armv7a/qcom.cfg | 1 - .../bsp/qcom-armv8a/qcom-armv8a-standard.scc | 0 .../bsp/qcom-armv8a/qcom-armv8a.scc | 0 .../bsp/qcom-armv8a/qcom-extra.cfg | 0 .../bsp/qcom-armv8a/qcom-msm8916.cfg | 0 .../bsp/qcom-armv8a/qcom-msm8916.scc | 0 .../bsp/qcom-armv8a/qcom-msm8996.cfg | 0 .../bsp/qcom-armv8a/qcom-msm8996.scc | 0 .../bsp/qcom-armv8a/qcom-qcm2290.cfg | 0 .../bsp/qcom-armv8a/qcom-qcm2290.scc | 0 .../bsp/qcom-armv8a/qcom-qcm6490.cfg | 0 .../bsp/qcom-armv8a/qcom-qcm6490.scc | 0 .../bsp/qcom-armv8a/qcom-rpm.cfg | 0 .../bsp/qcom-armv8a/qcom-rpmh.cfg | 0 .../bsp/qcom-armv8a/qcom-sa8775p.cfg | 0 .../bsp/qcom-armv8a/qcom-sa8775p.scc | 0 .../bsp/qcom-armv8a/qcom-sdm845.cfg | 0 .../bsp/qcom-armv8a/qcom-sdm845.scc | 0 .../bsp/qcom-armv8a/qcom-sm6115.cfg | 0 .../bsp/qcom-armv8a/qcom-sm6115.scc | 0 .../bsp/qcom-armv8a/qcom-sm8250.cfg | 0 .../bsp/qcom-armv8a/qcom-sm8250.scc | 0 .../bsp/qcom-armv8a/qcom-sm8450.cfg | 0 .../bsp/qcom-armv8a/qcom-sm8450.scc | 0 .../bsp/qcom-armv8a/qcom.cfg | 1 - ...amoa-iot-evk-camera-imx577-Add-DT-ov.patch | 57 ++------ .../qcom.scc | 0 ...aff9a3ab245e722349cc617bcdfe778c69af.patch | 20 ++- ...6.18.bbappend => linux-yocto_7.2.bbappend} | 1 - 37 files changed, 23 insertions(+), 187 deletions(-) delete mode 100644 recipes-kernel/linux/linux-yocto-6.18/monaco-evk-dts/0001-arm64-dts-qcom-monaco-evk-camera-Add-DT-overlay.patch rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv7a/qcom-apq8064.cfg (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv7a/qcom-apq8064.scc (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv7a/qcom-armv7a-standard.scc (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv7a/qcom-armv7a.scc (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv7a/qcom-msm8974.cfg (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv7a/qcom-msm8974.scc (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv7a/qcom-rpm.cfg (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv7a/qcom.cfg (99%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-armv8a-standard.scc (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-armv8a.scc (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-extra.cfg (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-msm8916.cfg (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-msm8916.scc (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-msm8996.cfg (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-msm8996.scc (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-qcm2290.cfg (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-qcm2290.scc (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-qcm6490.cfg (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-qcm6490.scc (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-rpm.cfg (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-rpmh.cfg (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-sa8775p.cfg (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-sa8775p.scc (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-sdm845.cfg (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-sdm845.scc (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-sm6115.cfg (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-sm6115.scc (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-sm8250.cfg (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-sm8250.scc (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-sm8450.cfg (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom-sm8450.scc (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/bsp/qcom-armv8a/qcom.cfg (99%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/hamoa-iot-evk-dts/0001-arm64-dts-qcom-hamoa-iot-evk-camera-imx577-Add-DT-ov.patch (70%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/qcom.scc (100%) rename recipes-kernel/linux/{linux-yocto-6.18 => linux-yocto-7.2}/workarounds/f553aff9a3ab245e722349cc617bcdfe778c69af.patch (57%) rename recipes-kernel/linux/{linux-yocto_6.18.bbappend => linux-yocto_7.2.bbappend} (72%) diff --git a/recipes-kernel/linux/linux-yocto-6.18/monaco-evk-dts/0001-arm64-dts-qcom-monaco-evk-camera-Add-DT-overlay.patch b/recipes-kernel/linux/linux-yocto-6.18/monaco-evk-dts/0001-arm64-dts-qcom-monaco-evk-camera-Add-DT-overlay.patch deleted file mode 100644 index 76e187952..000000000 --- a/recipes-kernel/linux/linux-yocto-6.18/monaco-evk-dts/0001-arm64-dts-qcom-monaco-evk-camera-Add-DT-overlay.patch +++ /dev/null @@ -1,130 +0,0 @@ -From d844e132cd7988f3629d2d98cc7465ce07801fd8 Mon Sep 17 00:00:00 2001 -From: Nihal Kumar Gupta -Date: Fri, 13 Feb 2026 18:50:58 +0530 -Subject: [PATCH] arm64: dts: qcom: monaco-evk-camera: Add DT overlay - -Monaco EVK board does not include a camera sensor in its default hardware -configuration. Introducing a device tree overlay to support optional -integration of the IMX577 sensor via CSIPHY1. - -Camera reset is handled through an I2C expander, and power is enabled -via TLMM GPIO74. - -An example media-ctl pipeline for the imx577 is: - -media-ctl --reset -media-ctl -V '"imx577 3-001a":0[fmt:SRGGB10/4056x3040 field:none]' -media-ctl -V '"msm_csiphy1":0[fmt:SRGGB10/4056x3040]' -media-ctl -V '"msm_csid0":0[fmt:SRGGB10/4056x3040]' -media-ctl -V '"msm_vfe0_rdi0":0[fmt:SRGGB10/4056x3040]' -media-ctl -l '"msm_csiphy1":1->"msm_csid0":0[1]' -media-ctl -l '"msm_csid0":1->"msm_vfe0_rdi0":0[1]' -yavta -B capture-mplane -c -I -n 5 -f SRGGB10P -s 4056x3040 -F /dev/video1 - -Co-developed-by: Ravi Shankar -Signed-off-by: Ravi Shankar -Co-developed-by: Vishal Verma -Signed-off-by: Vishal Verma -Signed-off-by: Nihal Kumar Gupta -Reviewed-by: Vladimir Zapolskiy -Reviewed-by: Bryan O'Donoghue -Reviewed-by: Konrad Dybcio - -Upstream-Status: Submitted [https://lore.kernel.org/all/20260213132058.521474-6-quic_nihalkum@quicinc.com/T/#u] -Signed-off-by: Jose Quaresma ---- - arch/arm64/boot/dts/qcom/Makefile | 4 ++ - .../dts/qcom/monaco-evk-camera-imx577.dtso | 66 +++++++++++++++++++ - 2 files changed, 70 insertions(+) - create mode 100644 arch/arm64/boot/dts/qcom/monaco-evk-camera-imx577.dtso - -diff --git a/arch/arm64/boot/dts/qcom/Makefile b/arch/arm64/boot/dts/qcom/Makefile -index 296688f7cb26..4df3044639a4 100644 ---- a/arch/arm64/boot/dts/qcom/Makefile -+++ b/arch/arm64/boot/dts/qcom/Makefile -@@ -36,6 +36,10 @@ lemans-evk-camera-csi1-imx577-dtbs := lemans-evk.dtb lemans-evk-camera-csi1-imx5 - - dtb-$(CONFIG_ARCH_QCOM) += lemans-evk-camera-csi1-imx577.dtb - dtb-$(CONFIG_ARCH_QCOM) += monaco-evk.dtb -+ -+monaco-evk-camera-imx577-dtbs := monaco-evk.dtb monaco-evk-camera-imx577.dtbo -+dtb-$(CONFIG_ARCH_QCOM) += monaco-evk-camera-imx577.dtb -+ - dtb-$(CONFIG_ARCH_QCOM) += msm8216-samsung-fortuna3g.dtb - dtb-$(CONFIG_ARCH_QCOM) += msm8916-acer-a1-724.dtb - dtb-$(CONFIG_ARCH_QCOM) += msm8916-alcatel-idol347.dtb -diff --git a/arch/arm64/boot/dts/qcom/monaco-evk-camera-imx577.dtso b/arch/arm64/boot/dts/qcom/monaco-evk-camera-imx577.dtso -new file mode 100644 -index 000000000000..0d5ccd020e6e ---- /dev/null -+++ b/arch/arm64/boot/dts/qcom/monaco-evk-camera-imx577.dtso -@@ -0,0 +1,66 @@ -+// SPDX-License-Identifier: BSD-3-Clause -+/* -+ * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. -+ */ -+ -+/dts-v1/; -+/plugin/; -+ -+#include -+#include -+ -+&camss { -+ vdda-phy-supply = <&vreg_l4a>; -+ vdda-pll-supply = <&vreg_l5a>; -+ -+ status = "okay"; -+ -+ ports { -+ #address-cells = <1>; -+ #size-cells = <0>; -+ -+ port@1 { -+ reg = <1>; -+ -+ csiphy1_ep: endpoint { -+ data-lanes = <0 1 2 3>; -+ remote-endpoint = <&imx577_ep1>; -+ }; -+ }; -+ }; -+}; -+ -+&cci1 { -+ pinctrl-0 = <&cci1_0_default>; -+ pinctrl-1 = <&cci1_0_sleep>; -+ -+ status = "okay"; -+}; -+ -+&cci1_i2c0 { -+ #address-cells = <1>; -+ #size-cells = <0>; -+ -+ camera@1a { -+ compatible = "sony,imx577"; -+ reg = <0x1a>; -+ -+ reset-gpios = <&expander2 1 GPIO_ACTIVE_LOW>; -+ pinctrl-0 = <&cam1_default>; -+ pinctrl-names = "default"; -+ -+ clocks = <&camcc CAM_CC_MCLK1_CLK>; -+ assigned-clocks = <&camcc CAM_CC_MCLK1_CLK>; -+ assigned-clock-rates = <24000000>; -+ -+ avdd-supply = <&vreg_cam1_2p8>; -+ -+ port { -+ imx577_ep1: endpoint { -+ link-frequencies = /bits/ 64 <600000000>; -+ data-lanes = <1 2 3 4>; -+ remote-endpoint = <&csiphy1_ep>; -+ }; -+ }; -+ }; -+}; --- -2.47.3 - diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom-apq8064.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom-apq8064.cfg similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom-apq8064.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom-apq8064.cfg diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom-apq8064.scc b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom-apq8064.scc similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom-apq8064.scc rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom-apq8064.scc diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom-armv7a-standard.scc b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom-armv7a-standard.scc similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom-armv7a-standard.scc rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom-armv7a-standard.scc diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom-armv7a.scc b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom-armv7a.scc similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom-armv7a.scc rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom-armv7a.scc diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom-msm8974.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom-msm8974.cfg similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom-msm8974.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom-msm8974.cfg diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom-msm8974.scc b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom-msm8974.scc similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom-msm8974.scc rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom-msm8974.scc diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom-rpm.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom-rpm.cfg similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom-rpm.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom-rpm.cfg diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom.cfg similarity index 99% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom.cfg index d2ad9e231..449fcdb95 100644 --- a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv7a/qcom.cfg +++ b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv7a/qcom.cfg @@ -172,7 +172,6 @@ CONFIG_MMC_SDHCI_MSM=y CONFIG_CFG80211=m CONFIG_MAC80211=m -CONFIG_CRYPTO_MICHAEL_MIC=m CONFIG_LEDS_CLASS_MULTICOLOR=y CONFIG_LEDS_QCOM_LPG=y diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-armv8a-standard.scc b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-armv8a-standard.scc similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-armv8a-standard.scc rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-armv8a-standard.scc diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-armv8a.scc b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-armv8a.scc similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-armv8a.scc rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-armv8a.scc diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-extra.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-extra.cfg similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-extra.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-extra.cfg diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-msm8916.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-msm8916.cfg similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-msm8916.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-msm8916.cfg diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-msm8916.scc b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-msm8916.scc similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-msm8916.scc rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-msm8916.scc diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-msm8996.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-msm8996.cfg similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-msm8996.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-msm8996.cfg diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-msm8996.scc b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-msm8996.scc similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-msm8996.scc rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-msm8996.scc diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-qcm2290.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-qcm2290.cfg similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-qcm2290.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-qcm2290.cfg diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-qcm2290.scc b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-qcm2290.scc similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-qcm2290.scc rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-qcm2290.scc diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-qcm6490.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-qcm6490.cfg similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-qcm6490.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-qcm6490.cfg diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-qcm6490.scc b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-qcm6490.scc similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-qcm6490.scc rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-qcm6490.scc diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-rpm.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-rpm.cfg similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-rpm.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-rpm.cfg diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-rpmh.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-rpmh.cfg similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-rpmh.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-rpmh.cfg diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sa8775p.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sa8775p.cfg similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sa8775p.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sa8775p.cfg diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sa8775p.scc b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sa8775p.scc similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sa8775p.scc rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sa8775p.scc diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sdm845.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sdm845.cfg similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sdm845.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sdm845.cfg diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sdm845.scc b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sdm845.scc similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sdm845.scc rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sdm845.scc diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sm6115.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sm6115.cfg similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sm6115.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sm6115.cfg diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sm6115.scc b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sm6115.scc similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sm6115.scc rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sm6115.scc diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sm8250.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sm8250.cfg similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sm8250.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sm8250.cfg diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sm8250.scc b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sm8250.scc similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sm8250.scc rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sm8250.scc diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sm8450.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sm8450.cfg similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sm8450.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sm8450.cfg diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sm8450.scc b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sm8450.scc similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom-sm8450.scc rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom-sm8450.scc diff --git a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom.cfg b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom.cfg similarity index 99% rename from recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom.cfg rename to recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom.cfg index 87d0f5bdd..67daa5c93 100644 --- a/recipes-kernel/linux/linux-yocto-6.18/bsp/qcom-armv8a/qcom.cfg +++ b/recipes-kernel/linux/linux-yocto-7.2/bsp/qcom-armv8a/qcom.cfg @@ -171,7 +171,6 @@ CONFIG_SCSI_UFS_QCOM=y CONFIG_CFG80211=m CONFIG_MAC80211=m -CONFIG_CRYPTO_MICHAEL_MIC=m CONFIG_LEDS_CLASS_MULTICOLOR=y CONFIG_LEDS_QCOM_LPG=y diff --git a/recipes-kernel/linux/linux-yocto-6.18/hamoa-iot-evk-dts/0001-arm64-dts-qcom-hamoa-iot-evk-camera-imx577-Add-DT-ov.patch b/recipes-kernel/linux/linux-yocto-7.2/hamoa-iot-evk-dts/0001-arm64-dts-qcom-hamoa-iot-evk-camera-imx577-Add-DT-ov.patch similarity index 70% rename from recipes-kernel/linux/linux-yocto-6.18/hamoa-iot-evk-dts/0001-arm64-dts-qcom-hamoa-iot-evk-camera-imx577-Add-DT-ov.patch rename to recipes-kernel/linux/linux-yocto-7.2/hamoa-iot-evk-dts/0001-arm64-dts-qcom-hamoa-iot-evk-camera-imx577-Add-DT-ov.patch index da042b52d..4eb2dd9b0 100644 --- a/recipes-kernel/linux/linux-yocto-6.18/hamoa-iot-evk-dts/0001-arm64-dts-qcom-hamoa-iot-evk-camera-imx577-Add-DT-ov.patch +++ b/recipes-kernel/linux/linux-yocto-7.2/hamoa-iot-evk-dts/0001-arm64-dts-qcom-hamoa-iot-evk-camera-imx577-Add-DT-ov.patch @@ -1,7 +1,8 @@ -From 0e32a7a5147c38db1f5e2b2887da503ae4684eb7 Mon Sep 17 00:00:00 2001 +From 44e3e4dd2dd698bd6b233425b933fdd512c949da Mon Sep 17 00:00:00 2001 From: Wenmeng Liu Date: Fri, 27 Feb 2026 13:29:40 +0800 -Subject: [PATCH] arm64: dts: qcom: hamoa-iot-evk-camera-imx577: Add DT overlay +Subject: [PATCH] arm64: dts: qcom: hamoa-iot-evk-camera-imx577: Add DT + overlay Enable IMX577 via CCI on Hamoa EVK Core Kit. @@ -12,28 +13,28 @@ IMX577 Mini Camera Module on the CSI-1 interface. Signed-off-by: Wenmeng Liu Upstream-Status: Submitted [https://lore.kernel.org/all/20260227-hamoa_evk-v1-2-36f895a24d8f@oss.qualcomm.com/] --- - arch/arm64/boot/dts/qcom/Makefile | 5 ++ + arch/arm64/boot/dts/qcom/Makefile | 3 + .../dts/qcom/hamoa-iot-evk-camera-imx577.dtso | 81 +++++++++++++++++++ - arch/arm64/boot/dts/qcom/hamoa-iot-evk.dts | 16 ++++ - 3 files changed, 102 insertions(+) + 2 files changed, 84 insertions(+) create mode 100644 arch/arm64/boot/dts/qcom/hamoa-iot-evk-camera-imx577.dtso diff --git a/arch/arm64/boot/dts/qcom/Makefile b/arch/arm64/boot/dts/qcom/Makefile -index 4df3044639a4..5c1c6138e802 100644 +index 6f33c4e2f09c..2221868af77b 100644 --- a/arch/arm64/boot/dts/qcom/Makefile +++ b/arch/arm64/boot/dts/qcom/Makefile -@@ -14,6 +14,11 @@ dtb-$(CONFIG_ARCH_QCOM) += apq8094-sony-xperia-kitakami-karin_windy.dtb - dtb-$(CONFIG_ARCH_QCOM) += apq8096-db820c.dtb - dtb-$(CONFIG_ARCH_QCOM) += apq8096-ifc6640.dtb +@@ -17,9 +17,12 @@ dtb-$(CONFIG_ARCH_QCOM) += apq8096-ifc6640.dtb + dtb-$(CONFIG_ARCH_QCOM) += eliza-mtp.dtb + dtb-$(CONFIG_ARCH_QCOM) += glymur-crd.dtb dtb-$(CONFIG_ARCH_QCOM) += hamoa-iot-evk.dtb +dtb-$(CONFIG_ARCH_QCOM) += hamoa-iot-evk-camera-imx577.dtbo -+ + +hamoa-iot-evk-camera-imx577-dtbs := hamoa-iot-evk.dtb hamoa-iot-evk-camera-imx577.dtbo -+ + hamoa-iot-evk-el2-dtbs := hamoa-iot-evk.dtb x1-el2.dtbo + +dtb-$(CONFIG_ARCH_QCOM) += hamoa-iot-evk-camera-imx577.dtb + dtb-$(CONFIG_ARCH_QCOM) += hamoa-iot-evk-el2.dtb + dtb-$(CONFIG_ARCH_QCOM) += hamoa-lenovo-ideacentre-mini-01q8x10.dtb dtb-$(CONFIG_ARCH_QCOM) += ipq5018-rdp432-c2.dtb - dtb-$(CONFIG_ARCH_QCOM) += ipq5018-tplink-archer-ax55-v1.dtb - dtb-$(CONFIG_ARCH_QCOM) += ipq5332-rdp441.dtb diff --git a/arch/arm64/boot/dts/qcom/hamoa-iot-evk-camera-imx577.dtso b/arch/arm64/boot/dts/qcom/hamoa-iot-evk-camera-imx577.dtso new file mode 100644 index 000000000000..f45a7fbd14b1 @@ -121,33 +122,3 @@ index 000000000000..f45a7fbd14b1 + + status = "okay"; +}; -diff --git a/arch/arm64/boot/dts/qcom/hamoa-iot-evk.dts b/arch/arm64/boot/dts/qcom/hamoa-iot-evk.dts -index df8d6e5c1f45..513560694218 100644 ---- a/arch/arm64/boot/dts/qcom/hamoa-iot-evk.dts -+++ b/arch/arm64/boot/dts/qcom/hamoa-iot-evk.dts -@@ -990,6 +990,22 @@ right_tweeter: speaker@0,1 { - }; - - &tlmm { -+ cam1_default: cam1-default-state { -+ mclk-pins { -+ pins = "gpio97"; -+ function = "cam_mclk"; -+ drive-strength = <2>; -+ bias-disable; -+ }; -+ -+ rst-pins { -+ pins = "gpio110"; -+ function = "gpio"; -+ drive-strength = <2>; -+ bias-disable; -+ }; -+ }; -+ - edp_reg_en: edp-reg-en-state { - pins = "gpio70"; - function = "gpio"; --- -2.34.1 - diff --git a/recipes-kernel/linux/linux-yocto-6.18/qcom.scc b/recipes-kernel/linux/linux-yocto-7.2/qcom.scc similarity index 100% rename from recipes-kernel/linux/linux-yocto-6.18/qcom.scc rename to recipes-kernel/linux/linux-yocto-7.2/qcom.scc diff --git a/recipes-kernel/linux/linux-yocto-6.18/workarounds/f553aff9a3ab245e722349cc617bcdfe778c69af.patch b/recipes-kernel/linux/linux-yocto-7.2/workarounds/f553aff9a3ab245e722349cc617bcdfe778c69af.patch similarity index 57% rename from recipes-kernel/linux/linux-yocto-6.18/workarounds/f553aff9a3ab245e722349cc617bcdfe778c69af.patch rename to recipes-kernel/linux/linux-yocto-7.2/workarounds/f553aff9a3ab245e722349cc617bcdfe778c69af.patch index 4b9405c8e..e37c1be7a 100644 --- a/recipes-kernel/linux/linux-yocto-6.18/workarounds/f553aff9a3ab245e722349cc617bcdfe778c69af.patch +++ b/recipes-kernel/linux/linux-yocto-7.2/workarounds/f553aff9a3ab245e722349cc617bcdfe778c69af.patch @@ -1,7 +1,8 @@ -From f553aff9a3ab245e722349cc617bcdfe778c69af Mon Sep 17 00:00:00 2001 +From 889c9dd3948378b69d818996a94519fef79ac59e Mon Sep 17 00:00:00 2001 From: Dmitry Baryshkov Date: Thu, 13 Jul 2023 23:38:44 +0200 -Subject: [PATCH] arm64: dts: qcom: apq8096-db820c: keep s2 regulator always on +Subject: [PATCH] arm64: dts: qcom: apq8096-db820c: keep s2 regulator + always on Needed to keep the GPU alive in our farm setup. @@ -9,14 +10,14 @@ Signed-off-by: Dmitry Baryshkov Signed-off-by: David Heidelberg Upstream-Status: Inappropriate [lame workaround instead of CPR3 driver] --- - arch/arm64/boot/dts/qcom/apq8096-db820c.dts | 1 + + arch/arm64/boot/dts/qcom/apq8096-db820c.dtsi | 1 + 1 file changed, 1 insertion(+) -diff --git a/arch/arm64/boot/dts/qcom/apq8096-db820c.dts b/arch/arm64/boot/dts/qcom/apq8096-db820c.dts -index 5b2e88915c2f..e74c9fb8f559 100644 ---- a/arch/arm64/boot/dts/qcom/apq8096-db820c.dts -+++ b/arch/arm64/boot/dts/qcom/apq8096-db820c.dts -@@ -702,6 +702,7 @@ vdd_gfx: s2 { +diff --git a/arch/arm64/boot/dts/qcom/apq8096-db820c.dtsi b/arch/arm64/boot/dts/qcom/apq8096-db820c.dtsi +index 0c076852b494..e3b1c11b8d69 100644 +--- a/arch/arm64/boot/dts/qcom/apq8096-db820c.dtsi ++++ b/arch/arm64/boot/dts/qcom/apq8096-db820c.dtsi +@@ -701,6 +701,7 @@ vdd_gfx: s2 { regulator-name = "VDD_GFX"; regulator-min-microvolt = <980000>; regulator-max-microvolt = <980000>; @@ -24,6 +25,3 @@ index 5b2e88915c2f..e74c9fb8f559 100644 }; }; --- -GitLab - diff --git a/recipes-kernel/linux/linux-yocto_6.18.bbappend b/recipes-kernel/linux/linux-yocto_7.2.bbappend similarity index 72% rename from recipes-kernel/linux/linux-yocto_6.18.bbappend rename to recipes-kernel/linux/linux-yocto_7.2.bbappend index b5613806f..85c0155c6 100644 --- a/recipes-kernel/linux/linux-yocto_6.18.bbappend +++ b/recipes-kernel/linux/linux-yocto_7.2.bbappend @@ -2,6 +2,5 @@ require linux-yocto-qcom.inc SRC_URI:append:qcom = " \ file://workarounds/f553aff9a3ab245e722349cc617bcdfe778c69af.patch \ - file://monaco-evk-dts/0001-arm64-dts-qcom-monaco-evk-camera-Add-DT-overlay.patch \ file://hamoa-iot-evk-dts/0001-arm64-dts-qcom-hamoa-iot-evk-camera-imx577-Add-DT-ov.patch \ " From 4556dd4f649ce2c8b9b130296bb92e95df91aa8a Mon Sep 17 00:00:00 2001 From: Ricardo Salveti Date: Tue, 8 Sep 2026 22:13:37 +0000 Subject: [PATCH 03/10] fit-dtb-compatible: adopt device trees now shipped by linux-yocto 7.2 linux-yocto 7.2 ships overlays that were previously linux-qcom only: the lemans, monaco and talos EL2 overlays, the lemans-evk and monaco-evk IFP mezzanine overlays and the monaco-evk camera overlay. Move them from LINUX_QCOM_KERNEL_DEVICETREE to KERNEL_DEVICETREE, add the EL2 overlays to the generic qcom-armv8a machine, and move the FIT_DTB_COMPATIBLE entries they complete from the linux-qcom include to the base include. The linux-qcom include keeps the entries that still need staging, camx, eMMC or SD card overlays. Assisted-by: Claude Code:claude-fable-5-1 Signed-off-by: Ricardo Salveti --- .../include/fit-dtb-compatible-linux-qcom.inc | 15 ------------ conf/machine/include/fit-dtb-compatible.inc | 24 +++++++++++-------- conf/machine/iq-615-evk.conf | 2 +- conf/machine/iq-8275-evk.conf | 4 ++-- conf/machine/iq-9075-evk.conf | 4 ++-- conf/machine/qcom-armv8a.conf | 8 +++---- conf/machine/qcs615-ride.conf | 2 +- conf/machine/qcs8300-ride-sx.conf | 2 +- conf/machine/qcs9100-ride-sx.conf | 2 +- 9 files changed, 25 insertions(+), 38 deletions(-) diff --git a/conf/machine/include/fit-dtb-compatible-linux-qcom.inc b/conf/machine/include/fit-dtb-compatible-linux-qcom.inc index 4497d3e8b..6bffe8fb2 100644 --- a/conf/machine/include/fit-dtb-compatible-linux-qcom.inc +++ b/conf/machine/include/fit-dtb-compatible-linux-qcom.inc @@ -60,8 +60,6 @@ FIT_DTB_COMPATIBLE[qcom_qcs9075-iot-subtype1-staging-emmc] = \ FIT_DTB_COMPATIBLE[qcom_qcs9100-qam-el2gh-staging] = \ "qcs9100-ride lemans-staging" -FIT_DTB_COMPATIBLE[qcom_qcs9100-qam] = \ - "qcs9100-ride lemans-el2" FIT_DTB_COMPATIBLE[qcom_qcs9100-qam-staging] = \ "qcs9100-ride lemans-el2 lemans-staging" FIT_DTB_COMPATIBLE[qcom_qcs9100-qam-camx] = \ @@ -70,8 +68,6 @@ FIT_DTB_COMPATIBLE[qcom_qcs9100-qam-camx-staging] = \ "qcs9100-ride sa8775p-ride-camx lemans-staging" FIT_DTB_COMPATIBLE[qcom_qcs9100-qam-r2.0-el2gh-staging] = \ "qcs9100-ride-r3 lemans-staging" -FIT_DTB_COMPATIBLE[qcom_qcs9100-qam-r2.0] = \ - "qcs9100-ride-r3 lemans-el2" FIT_DTB_COMPATIBLE[qcom_qcs9100-qam-r2.0-staging] = \ "qcs9100-ride-r3 lemans-el2 lemans-staging" FIT_DTB_COMPATIBLE[qcom_qcs9100-qam-r2.0-camx] = \ @@ -81,8 +77,6 @@ FIT_DTB_COMPATIBLE[qcom_qcs9100-qam-r2.0-camx-staging] = \ FIT_DTB_COMPATIBLE[qcom_sa8775p-qam-el2gh-staging] = \ "sa8775p-ride lemans-staging" -FIT_DTB_COMPATIBLE[qcom_sa8775p-qam] = \ - "sa8775p-ride lemans-el2" FIT_DTB_COMPATIBLE[qcom_sa8775p-qam-staging] = \ "sa8775p-ride lemans-el2 lemans-staging" FIT_DTB_COMPATIBLE[qcom_sa8775p-qam-el2gh-camx] = \ @@ -95,8 +89,6 @@ FIT_DTB_COMPATIBLE[qcom_sa8775p-qam-camx-staging] = \ "sa8775p-ride sa8775p-ride-camx lemans-el2 lemans-camx-el2 lemans-staging" FIT_DTB_COMPATIBLE[qcom_sa8775p-qam-r2.0-el2gh-staging] = \ "sa8775p-ride-r3 lemans-staging" -FIT_DTB_COMPATIBLE[qcom_sa8775p-qam-r2.0] = \ - "sa8775p-ride-r3 lemans-el2" FIT_DTB_COMPATIBLE[qcom_sa8775p-qam-r2.0-staging] = \ "sa8775p-ride-r3 lemans-el2 lemans-staging" FIT_DTB_COMPATIBLE[qcom_sa8775p-qam-r2.0-el2gh-camx] = \ @@ -152,7 +144,6 @@ FIT_DTB_COMPATIBLE[qcom_qcs8275-iot-subtype3-staging-emmc] = \ "monaco-evk monaco-evk-ifp-mezzanine monaco-staging monaco-evk-staging monaco-evk-emmc" FIT_DTB_COMPATIBLE[qcom_qcs8300-adp-el2gh-staging] = "qcs8300-ride monaco-staging" -FIT_DTB_COMPATIBLE[qcom_qcs8300-adp] = "qcs8300-ride monaco-el2" FIT_DTB_COMPATIBLE[qcom_qcs8300-adp-staging] = \ "qcs8300-ride monaco-el2 monaco-staging" FIT_DTB_COMPATIBLE[qcom_qcs8300-adp-el2gh-camx] = "qcs8300-ride qcs8300-ride-camx" @@ -166,14 +157,10 @@ FIT_DTB_COMPATIBLE[qcom_qcs8300-adp-camx-staging] = \ # ---------- talos ---------- FIT_DTB_COMPATIBLE[qcom_qcs615-adp-el2gh-staging] = \ "qcs615-ride talos-staging" -FIT_DTB_COMPATIBLE[qcom_qcs615-adp] = \ - "qcs615-ride talos-el2" FIT_DTB_COMPATIBLE[qcom_qcs615-adp-staging] = \ "qcs615-ride talos-el2 talos-staging" FIT_DTB_COMPATIBLE[qcom_qcs615-iot-el2gh-staging] = \ "talos-evk talos-evk-camera-imx577 talos-staging" -FIT_DTB_COMPATIBLE[qcom_qcs615-iot] = \ - "talos-evk talos-evk-camera-imx577 talos-el2" FIT_DTB_COMPATIBLE[qcom_qcs615-iot-staging] = \ "talos-evk talos-evk-camera-imx577 talos-el2 talos-staging talos-evk-staging" FIT_DTB_COMPATIBLE[qcom_qcs615-iot-el2gh-camx] = "talos-evk talos-evk-camx" @@ -187,8 +174,6 @@ FIT_DTB_COMPATIBLE[qcom_qcs615-iot-el2gh-camx-staging] = \ # "qcom_talos-evk-lvds-auo_g133han01-staging" (both commas become underscores). FIT_DTB_COMPATIBLE[qcom_talos-evk-lvds-auo_g133han01-el2gh-staging] = \ "talos-evk talos-evk-lvds-auo_g133han01 talos-staging" -FIT_DTB_COMPATIBLE[qcom_talos-evk-lvds-auo_g133han01] = \ - "talos-evk talos-evk-lvds-auo_g133han01 talos-el2" FIT_DTB_COMPATIBLE[qcom_talos-evk-lvds-auo_g133han01-staging] = \ "talos-evk talos-evk-lvds-auo_g133han01 talos-el2 talos-staging" diff --git a/conf/machine/include/fit-dtb-compatible.inc b/conf/machine/include/fit-dtb-compatible.inc index 8d4665cc2..709cadd14 100644 --- a/conf/machine/include/fit-dtb-compatible.inc +++ b/conf/machine/include/fit-dtb-compatible.inc @@ -51,19 +51,23 @@ FIT_DTB_COMPATIBLE[qcom_purwa-evk-el2kvm] = "purwa-iot-evk x1-el2" # ---------- lemans ---------- FIT_DTB_COMPATIBLE[qcom_qcs9075-iot] = \ - "lemans-evk lemans-evk-camera-csi1-imx577" + "lemans-evk lemans-evk-camera-csi1-imx577 lemans-el2" +FIT_DTB_COMPATIBLE[qcom_qcs9075-iot-subtype1] = \ + "lemans-evk lemans-evk-ifp-mezzanine" -FIT_DTB_COMPATIBLE[qcom_qcs9100-qam] = "qcs9100-ride" -FIT_DTB_COMPATIBLE[qcom_qcs9100-qam-r2.0] = "qcs9100-ride-r3" +FIT_DTB_COMPATIBLE[qcom_qcs9100-qam] = "qcs9100-ride lemans-el2" +FIT_DTB_COMPATIBLE[qcom_qcs9100-qam-r2.0] = "qcs9100-ride-r3 lemans-el2" -FIT_DTB_COMPATIBLE[qcom_sa8775p-qam] = "sa8775p-ride" -FIT_DTB_COMPATIBLE[qcom_sa8775p-qam-r2.0] = "sa8775p-ride-r3" +FIT_DTB_COMPATIBLE[qcom_sa8775p-qam] = "sa8775p-ride lemans-el2" +FIT_DTB_COMPATIBLE[qcom_sa8775p-qam-r2.0] = "sa8775p-ride-r3 lemans-el2" # ---------- monaco ---------- FIT_DTB_COMPATIBLE[qcom_qcs8275-iot] = \ - "monaco-evk monaco-evk-camera-imx577" + "monaco-evk monaco-evk-camera-imx577 monaco-el2" +FIT_DTB_COMPATIBLE[qcom_qcs8275-iot-subtype3] = \ + "monaco-evk monaco-evk-ifp-mezzanine" -FIT_DTB_COMPATIBLE[qcom_qcs8300-adp] = "qcs8300-ride" +FIT_DTB_COMPATIBLE[qcom_qcs8300-adp] = "qcs8300-ride monaco-el2" # ---------- shikra ---------- FIT_DTB_COMPATIBLE[qcom_shikracqm-itp] = "shikra-cqm-evk shikra-cqm-evk-imx577-camera" @@ -71,10 +75,10 @@ FIT_DTB_COMPATIBLE[qcom_shikracqs-itp] = "shikra-cqs-evk shikra-cqm-evk-imx577-c FIT_DTB_COMPATIBLE[qcom_shikraiqs-itp] = "shikra-iqs-evk shikra-iqs-evk-imx577-camera" # ---------- talos ---------- -FIT_DTB_COMPATIBLE[qcom_qcs615-adp] = "qcs615-ride" -FIT_DTB_COMPATIBLE[qcom_qcs615-iot] = "talos-evk talos-evk-camera-imx577" +FIT_DTB_COMPATIBLE[qcom_qcs615-adp] = "qcs615-ride talos-el2" +FIT_DTB_COMPATIBLE[qcom_qcs615-iot] = "talos-evk talos-evk-camera-imx577 talos-el2" FIT_DTB_COMPATIBLE[qcom_talos-evk-lvds-auo_g133han01] = \ - "talos-evk talos-evk-lvds-auo_g133han01" + "talos-evk talos-evk-lvds-auo_g133han01 talos-el2" # ---------- kodiak ---------- FIT_DTB_COMPATIBLE[qcom_qcm6490-idp] = "qcm6490-idp" diff --git a/conf/machine/iq-615-evk.conf b/conf/machine/iq-615-evk.conf index aafd109e9..69e6ebebf 100644 --- a/conf/machine/iq-615-evk.conf +++ b/conf/machine/iq-615-evk.conf @@ -10,12 +10,12 @@ KERNEL_DEVICETREE ?= " \ qcom/talos-evk.dtb \ qcom/talos-evk-camera-imx577.dtbo \ qcom/talos-evk-lvds-auo,g133han01.dtbo \ + qcom/talos-el2.dtbo \ " # These DTs are not upstreamed and currently exist only in linux-qcom kernels LINUX_QCOM_KERNEL_DEVICETREE ?= " \ qcom/talos-evk-camx.dtbo \ - qcom/talos-el2.dtbo \ qcom/talos-staging.dtbo \ qcom/talos-evk-staging.dtbo \ " diff --git a/conf/machine/iq-8275-evk.conf b/conf/machine/iq-8275-evk.conf index fdf556bd2..0a8fa231a 100644 --- a/conf/machine/iq-8275-evk.conf +++ b/conf/machine/iq-8275-evk.conf @@ -9,15 +9,15 @@ MACHINE_FEATURES += "efi m2connector kvm pci tpm2 phone" KERNEL_DEVICETREE ?= " \ qcom/monaco-evk.dtb \ qcom/monaco-evk-camera-imx577.dtbo \ + qcom/monaco-el2.dtbo \ + qcom/monaco-evk-ifp-mezzanine.dtbo \ " # These DTs are not upstreamed and currently exist only in linux-qcom kernels LINUX_QCOM_KERNEL_DEVICETREE ?= " \ - qcom/monaco-el2.dtbo \ qcom/monaco-camx-el2.dtbo \ qcom/monaco-ac-evk.dtb \ qcom/monaco-evk-camx.dtbo \ - qcom/monaco-evk-ifp-mezzanine.dtbo \ qcom/monaco-evk-staging.dtbo \ qcom/monaco-staging.dtbo \ qcom/monaco-evk-emmc.dtbo \ diff --git a/conf/machine/iq-9075-evk.conf b/conf/machine/iq-9075-evk.conf index aa0e02e16..3488f78a9 100644 --- a/conf/machine/iq-9075-evk.conf +++ b/conf/machine/iq-9075-evk.conf @@ -9,14 +9,14 @@ MACHINE_FEATURES += "efi kvm m2connector pci tpm2 phone" KERNEL_DEVICETREE ?= " \ qcom/lemans-evk.dtb \ qcom/lemans-evk-camera-csi1-imx577.dtbo \ + qcom/lemans-el2.dtbo \ + qcom/lemans-evk-ifp-mezzanine.dtbo \ " # These DTs are not upstreamed and currently exist only in linux-qcom kernels LINUX_QCOM_KERNEL_DEVICETREE ?= " \ - qcom/lemans-el2.dtbo \ qcom/lemans-evk-camx.dtbo \ qcom/lemans-camx-el2.dtbo \ - qcom/lemans-evk-ifp-mezzanine.dtbo \ qcom/lemans-evk-staging.dtbo \ qcom/lemans-staging.dtbo \ qcom/lemans-evk-emmc.dtbo \ diff --git a/conf/machine/qcom-armv8a.conf b/conf/machine/qcom-armv8a.conf index 8262eec64..41b8c210c 100644 --- a/conf/machine/qcom-armv8a.conf +++ b/conf/machine/qcom-armv8a.conf @@ -43,8 +43,10 @@ KERNEL_DEVICETREE ?= " \ qcom/hamoa-iot-evk.dtb \ qcom/hamoa-iot-evk-camera-imx577.dtbo \ qcom/lemans-evk.dtb \ + qcom/lemans-el2.dtbo \ qcom/lemans-evk-camera-csi1-imx577.dtbo \ qcom/monaco-evk.dtb \ + qcom/monaco-el2.dtbo \ qcom/monaco-evk-camera-imx577.dtbo \ qcom/qcm6490-idp.dtb \ qcom/qcs404-evb-4000.dtb \ @@ -63,11 +65,7 @@ KERNEL_DEVICETREE ?= " \ qcom/sdm845-db845c.dtb \ qcom/sm8450-hdk.dtb \ qcom/sm8750-mtp.dtb \ -" - -# These DTs are not upstreamed and currently exist only in linux-qcom kernels -LINUX_QCOM_KERNEL_DEVICETREE ?= " \ - qcom/monaco-evk-camera-imx577.dtbo \ + qcom/talos-el2.dtbo \ " QCOM_BOOTIMG_PAGE_SIZE[apq8016-sbc] ?= "2048" diff --git a/conf/machine/qcs615-ride.conf b/conf/machine/qcs615-ride.conf index 60da9d870..b1dce933e 100644 --- a/conf/machine/qcs615-ride.conf +++ b/conf/machine/qcs615-ride.conf @@ -10,11 +10,11 @@ QCOM_DTB_DEFAULT ?= "qcs615-ride" KERNEL_DEVICETREE ?= " \ qcom/qcs615-ride.dtb \ + qcom/talos-el2.dtbo \ " # These DTs are not upstreamed and currently exist only in linux-qcom kernels LINUX_QCOM_KERNEL_DEVICETREE ?= " \ - qcom/talos-el2.dtbo \ qcom/talos-staging.dtbo \ " diff --git a/conf/machine/qcs8300-ride-sx.conf b/conf/machine/qcs8300-ride-sx.conf index 32606ac51..003588743 100644 --- a/conf/machine/qcs8300-ride-sx.conf +++ b/conf/machine/qcs8300-ride-sx.conf @@ -10,11 +10,11 @@ QCOM_DTB_DEFAULT ?= "qcs8300-ride" KERNEL_DEVICETREE ?= " \ qcom/qcs8300-ride.dtb \ + qcom/monaco-el2.dtbo \ " # These DTs are not upstreamed and currently exist only in linux-qcom kernels LINUX_QCOM_KERNEL_DEVICETREE ?= " \ - qcom/monaco-el2.dtbo \ qcom/monaco-camx-el2.dtbo \ qcom/qcs8300-ride-camx.dtbo \ qcom/monaco-staging.dtbo \ diff --git a/conf/machine/qcs9100-ride-sx.conf b/conf/machine/qcs9100-ride-sx.conf index 83516c9fb..be19b0170 100644 --- a/conf/machine/qcs9100-ride-sx.conf +++ b/conf/machine/qcs9100-ride-sx.conf @@ -13,11 +13,11 @@ KERNEL_DEVICETREE ?= " \ qcom/qcs9100-ride-r3.dtb \ qcom/sa8775p-ride.dtb \ qcom/sa8775p-ride-r3.dtb \ + qcom/lemans-el2.dtbo \ " # These DTs are not upstreamed and currently exist only in linux-qcom kernels LINUX_QCOM_KERNEL_DEVICETREE ?= " \ - qcom/lemans-el2.dtbo \ qcom/lemans-camx-el2.dtbo \ qcom/sa8775p-ride-camx.dtbo \ qcom/lemans-staging.dtbo \ From 9036d2f1992ad9fab29385002791b507158165d1 Mon Sep 17 00:00:00 2001 From: Ricardo Salveti Date: Tue, 8 Sep 2026 22:15:31 +0000 Subject: [PATCH 04/10] ci: base: drop the upstreamed python3-pycairo revert patch OE-Core now carries the same revert of python3-pycairo commit 7aa548771b as commit 1cb35e0f7, so the kas patch fails to apply and kas aborts before the build starts. Remove the patch and its entry. Assisted-by: Claude Code:claude-fable-5-1 Signed-off-by: Ricardo Salveti --- ci/base.yml | 3 -- ...ycairo-inherit-python3-dir-not-pytho.patch | 52 ------------------- 2 files changed, 55 deletions(-) delete mode 100644 patches/oe-core/0001-Revert-python3-pycairo-inherit-python3-dir-not-pytho.patch diff --git a/ci/base.yml b/ci/base.yml index ff5b5c4c6..fc70f1a65 100644 --- a/ci/base.yml +++ b/ci/base.yml @@ -18,9 +18,6 @@ repos: fix-igt-pause: repo: meta-qcom path: patches/oe-core/0001-igt-gpu-tools-fix-build-on-non-x86-platforms.patch - revert-python3-pycairo: - repo: meta-qcom - path: patches/oe-core/0001-Revert-python3-pycairo-inherit-python3-dir-not-pytho.patch layers: meta: diff --git a/patches/oe-core/0001-Revert-python3-pycairo-inherit-python3-dir-not-pytho.patch b/patches/oe-core/0001-Revert-python3-pycairo-inherit-python3-dir-not-pytho.patch deleted file mode 100644 index 7b40737c5..000000000 --- a/patches/oe-core/0001-Revert-python3-pycairo-inherit-python3-dir-not-pytho.patch +++ /dev/null @@ -1,52 +0,0 @@ -From dfcae61676e608b7e3186cf63cd4196668900217 Mon Sep 17 00:00:00 2001 -From: Jose Quaresma -Date: Mon, 31 Aug 2026 15:04:27 +0100 -Subject: [PATCH] Revert "python3-pycairo: inherit python3-dir not - python3targetconfig" - -This reverts commit 7aa548771b7d405e215219360bd60c1b6efe9069. - -Without this the arch on the library name changes from "aarch64" -to "x86_64" when we build for arm64 target. - -Analysis of buildhistory shows that the content is the same, -only the name changes: - -# --- a/packages/armv8a-oe-linux/python3-pycairo/sysroot -# +++ b/packages/armv8a-oe-linux/python3-pycairo/sysroot -# @@ -9,8 +9,8 @@ -# drwxr-xr-x - - 22 ./usr/lib/pkgconfig -# -rw-r--r-- - - 162 ./usr/lib/pkgconfig/py3cairo.pc -# drwxr-xr-x - - 26 ./usr/lib/python3.14 -# drwxr-xr-x - - 58 ./usr/lib/python3.14/site-packages -# -drwxr-xr-x - - 174 ./usr/lib/python3.14/site-packages/cairo -# --rwxr-xr-x - - 303544 ./usr/lib/python3.14/site-packages/cairo/_cairo.cpython-314-x86_64-linux-gnu.so -# +drwxr-xr-x - - 176 ./usr/lib/python3.14/site-packages/cairo -# +-rwxr-xr-x - - 303544 ./usr/lib/python3.14/site-packages/cairo/_cairo.cpython-314-aarch64-linux-gnu.so -# drwxr-xr-x - - 20 ./usr/lib/python3.14/site-packages/cairo/include -# -rw-r--r-- - - 8778 ./usr/lib/python3.14/site-packages/cairo/include/py3cairo.h -# -rw-r--r-- - - 660 ./usr/lib/python3.14/site-packages/cairo/__init__.py - -Upstream-Status: Submitted [https://lists.openembedded.org/g/openembedded-core/message/244813] - -Signed-off-by: Jose Quaresma ---- - meta/recipes-devtools/python/python3-pycairo_1.29.1.bb | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/meta/recipes-devtools/python/python3-pycairo_1.29.1.bb b/meta/recipes-devtools/python/python3-pycairo_1.29.1.bb -index 19e41baac4..b70d1f177d 100644 ---- a/meta/recipes-devtools/python/python3-pycairo_1.29.1.bb -+++ b/meta/recipes-devtools/python/python3-pycairo_1.29.1.bb -@@ -17,7 +17,7 @@ SRC_URI[sha256sum] = "4fbd26b4af24c9787d84cf5448e34eb8dca064b732479aaecd03109520 - - S = "${UNPACKDIR}/pycairo-${PV}" - --inherit meson pkgconfig python3-dir github-releases -+inherit meson pkgconfig python3targetconfig github-releases - - CFLAGS += "-fPIC" - --- -2.55.0 - From b667756e76d1a382d513a4cbc5e0d8733e6700f1 Mon Sep 17 00:00:00 2001 From: Ricardo Salveti Date: Tue, 8 Sep 2026 23:03:58 +0000 Subject: [PATCH 05/10] ci: qcom-distro: patch meta-security for OpenSSL 4.0 OE-Core moved to OpenSSL 4.0, which made ASN1_STRING opaque and removed the ENGINE API, and the meta-tpm recipes pulled into the qcom-distro images through packagegroup-security-tpm2 on every machine with the tpm2 feature no longer build. Carry the fixes Khem Raj submitted to meta-security on 2026-09-07 as kas patches until they are merged: - trousers and tpm2-openssl switch to the ASN1_STRING accessors; - tpm2-tools moves to 5.8 and tpm2-pkcs11 to 1.10.1, whose upstream releases already build against OpenSSL 4.0; - tpm2-tss-engine is an OpenSSL engine and cannot exist any more, so it is dropped from the packagegroup. Assisted-by: Claude Code:claude-fable-5-1 Signed-off-by: Ricardo Salveti --- ci/qcom-distro.yml | 16 ++ ...-trousers-Fix-build-with-OpenSSL-4.x.patch | 94 ++++++++++++ ...2-openssl-Fix-build-with-OpenSSL-4.x.patch | 145 ++++++++++++++++++ .../0003-tpm2-tools-Upgrade-5.7-5.8.patch | 57 +++++++ ...004-tpm2-pkcs11-Upgrade-1.9.2-1.10.1.patch | 84 ++++++++++ ...urity-tpm2-Remove-tpm2-tss-engine-fr.patch | 30 ++++ 6 files changed, 426 insertions(+) create mode 100644 patches/meta-security/0001-trousers-Fix-build-with-OpenSSL-4.x.patch create mode 100644 patches/meta-security/0002-tpm2-openssl-Fix-build-with-OpenSSL-4.x.patch create mode 100644 patches/meta-security/0003-tpm2-tools-Upgrade-5.7-5.8.patch create mode 100644 patches/meta-security/0004-tpm2-pkcs11-Upgrade-1.9.2-1.10.1.patch create mode 100644 patches/meta-security/0005-packagegroup-security-tpm2-Remove-tpm2-tss-engine-fr.patch diff --git a/ci/qcom-distro.yml b/ci/qcom-distro.yml index 1f8356871..509c982a5 100644 --- a/ci/qcom-distro.yml +++ b/ci/qcom-distro.yml @@ -53,6 +53,22 @@ repos: meta-security: url: https://git.yoctoproject.org/meta-security + patches: + trousers-openssl4: + repo: meta-qcom + path: patches/meta-security/0001-trousers-Fix-build-with-OpenSSL-4.x.patch + tpm2-openssl-openssl4: + repo: meta-qcom + path: patches/meta-security/0002-tpm2-openssl-Fix-build-with-OpenSSL-4.x.patch + tpm2-tools-5.8: + repo: meta-qcom + path: patches/meta-security/0003-tpm2-tools-Upgrade-5.7-5.8.patch + tpm2-pkcs11-1.10.1: + repo: meta-qcom + path: patches/meta-security/0004-tpm2-pkcs11-Upgrade-1.9.2-1.10.1.patch + tpm2-tss-engine-openssl4: + repo: meta-qcom + path: patches/meta-security/0005-packagegroup-security-tpm2-Remove-tpm2-tss-engine-fr.patch layers: .: meta-tpm: diff --git a/patches/meta-security/0001-trousers-Fix-build-with-OpenSSL-4.x.patch b/patches/meta-security/0001-trousers-Fix-build-with-OpenSSL-4.x.patch new file mode 100644 index 000000000..65eeeaeae --- /dev/null +++ b/patches/meta-security/0001-trousers-Fix-build-with-OpenSSL-4.x.patch @@ -0,0 +1,94 @@ +From 92e1e517ede0a095dd7df4fcde765e7a1f44ac62 Mon Sep 17 00:00:00 2001 +From: Khem Raj +Date: Sun, 6 Sep 2026 21:29:20 -0700 +Subject: [PATCH 1/5] trousers: Fix build with OpenSSL 4.x + +OpenSSL 4.0 completes the opaquing of struct asn1_string_st, so +src/tspi/tspi_asn1.c no longer builds: + + src/tspi/tspi_asn1.c:240:33: error: incomplete definition of type + 'ASN1_OCTET_STRING' (aka 'struct asn1_string_st') + 240 | memcpy(rawBlob, tssBlob->blob->data, decBlobSize); + | ~~~~~~~~~~~~~^ + +Add a patch using the ASN1_STRING_get0_data() accessor, which has been +available since OpenSSL 1.1.0 and is the documented replacement for +reaching into ->data. The rest of the file already goes through +accessors (ASN1_INTEGER_get(), ASN1_OCTET_STRING_set()), so this keeps +it consistent. No functional change. + +Upstream-Status: Submitted [https://patchwork.yoctoproject.org/project/yocto/patch/97432/] + +Signed-off-by: Khem Raj +--- + ...1-use-ASN1_STRING_get0_data-accessor.patch | 45 +++++++++++++++++++ + .../recipes-tpm1/trousers/trousers_git.bb | 1 + + 2 files changed, 46 insertions(+) + create mode 100644 meta-tpm/recipes-tpm1/trousers/files/0001-tspi_asn1-use-ASN1_STRING_get0_data-accessor.patch + +diff --git a/meta-tpm/recipes-tpm1/trousers/files/0001-tspi_asn1-use-ASN1_STRING_get0_data-accessor.patch b/meta-tpm/recipes-tpm1/trousers/files/0001-tspi_asn1-use-ASN1_STRING_get0_data-accessor.patch +new file mode 100644 +index 0000000..9287450 +--- /dev/null ++++ b/meta-tpm/recipes-tpm1/trousers/files/0001-tspi_asn1-use-ASN1_STRING_get0_data-accessor.patch +@@ -0,0 +1,45 @@ ++From: Khem Raj ++Date: Sun, 6 Sep 2026 20:05:00 -0700 ++Subject: [PATCH] tspi_asn1: use ASN1_STRING_get0_data() accessor ++ ++OpenSSL 4.0 completes the opaquing of struct asn1_string_st, so reaching ++into ASN1_OCTET_STRING directly no longer compiles: ++ ++ src/tspi/tspi_asn1.c:240:33: error: incomplete definition of type ++ 'ASN1_OCTET_STRING' (aka 'struct asn1_string_st') ++ 240 | memcpy(rawBlob, tssBlob->blob->data, decBlobSize); ++ | ~~~~~~~~~~~~~^ ++ ++Use the ASN1_STRING_get0_data() accessor instead. It has been available ++since OpenSSL 1.1.0 and is the documented replacement for touching the ++->data member; the rest of this file already goes through accessors ++(ASN1_INTEGER_get(), ASN1_OCTET_STRING_set()). ++ ++No functional change. ++ ++Upstream-Status: Inappropriate [upstream is dormant; git.code.sf.net ++master is still at 94144b0 "Bumped version to 0.3.15" from 2020-11-03, ++which is the SRCREV this recipe already pins] ++ ++Signed-off-by: Khem Raj ++--- ++ src/tspi/tspi_asn1.c | 3 ++- ++ 1 file changed, 2 insertions(+), 1 deletion(-) ++ ++diff --git a/src/tspi/tspi_asn1.c b/src/tspi/tspi_asn1.c ++index f17ce41..14d216b 100644 ++--- a/src/tspi/tspi_asn1.c +++++ b/src/tspi/tspi_asn1.c ++@@ -237,7 +237,8 @@ Tspi_DecodeBER_TssBlob(UINT32 berBlobSize, /* in */ ++ ++ if (*rawBlobSize != 0) { ++ if (decBlobSize <= *rawBlobSize) { ++- memcpy(rawBlob, tssBlob->blob->data, decBlobSize); +++ memcpy(rawBlob, ASN1_STRING_get0_data(tssBlob->blob), +++ decBlobSize); ++ } ++ else { ++ TSS_BLOB_free(tssBlob); ++-- ++2.51.0 ++ +diff --git a/meta-tpm/recipes-tpm1/trousers/trousers_git.bb b/meta-tpm/recipes-tpm1/trousers/trousers_git.bb +index abbb436..ff3335f 100644 +--- a/meta-tpm/recipes-tpm1/trousers/trousers_git.bb ++++ b/meta-tpm/recipes-tpm1/trousers/trousers_git.bb +@@ -16,6 +16,7 @@ SRC_URI = " \ + file://tcsd.service \ + file://get-user-ps-path-use-POSIX-getpwent-instead-of-getpwe.patch \ + file://0001-build-don-t-override-localstatedir-mandir-sysconfdir.patch \ ++ file://0001-tspi_asn1-use-ASN1_STRING_get0_data-accessor.patch \ + " + + inherit autotools pkgconfig useradd update-rc.d ${@bb.utils.contains('VIRTUAL-RUNTIME_init_manager','systemd','systemd','', d)} +-- +2.43.0 + diff --git a/patches/meta-security/0002-tpm2-openssl-Fix-build-with-OpenSSL-4.x.patch b/patches/meta-security/0002-tpm2-openssl-Fix-build-with-OpenSSL-4.x.patch new file mode 100644 index 000000000..4985e74bf --- /dev/null +++ b/patches/meta-security/0002-tpm2-openssl-Fix-build-with-OpenSSL-4.x.patch @@ -0,0 +1,145 @@ +From 5a4fd92ecc36bbd90279c724b8446cfa63dd007b Mon Sep 17 00:00:00 2001 +From: Khem Raj +Date: Sun, 6 Sep 2026 22:06:28 -0700 +Subject: [PATCH 2/5] tpm2-openssl: Fix build with OpenSSL 4.x + +OpenSSL 4.0 completes the opaquing of struct asn1_string_st, so reaching +into ASN1_OCTET_STRING directly no longer compiles: + + src/tpm2-provider-pkey.c:152:53: error: incomplete definition of type + 'ASN1_OCTET_STRING' (aka 'struct asn1_string_st') + 152 | if (Tss2_MU_TPM2B_PRIVATE_Unmarshal(tpk->privkey->data, + | ~~~~~~~~~~~~~^ + +Backport upstream commit 6dcc3b2 which switches tpm2_keydata_read() to +the ASN1_STRING_get0_data()/ASN1_STRING_length() accessors. 1.3.0 is +still the newest release, so there is no upgrade to take instead. + +Upstream-Status: Submitted [https://patchwork.yoctoproject.org/project/yocto/patch/97433/] + +Signed-off-by: Khem Raj +--- + ...TRING-and-X509_NAME-access-for-OpenS.patch | 95 +++++++++++++++++++ + .../tpm2-openssl/tpm2-openssl_1.3.0.bb | 4 +- + 2 files changed, 98 insertions(+), 1 deletion(-) + create mode 100644 meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl/0001-Fix-ASN1_OCTET_STRING-and-X509_NAME-access-for-OpenS.patch + +diff --git a/meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl/0001-Fix-ASN1_OCTET_STRING-and-X509_NAME-access-for-OpenS.patch b/meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl/0001-Fix-ASN1_OCTET_STRING-and-X509_NAME-access-for-OpenS.patch +new file mode 100644 +index 0000000..ad6d9d9 +--- /dev/null ++++ b/meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl/0001-Fix-ASN1_OCTET_STRING-and-X509_NAME-access-for-OpenS.patch +@@ -0,0 +1,95 @@ ++From 6dcc3b2984e3f4dc1849c79d89c6ce736a8435b3 Mon Sep 17 00:00:00 2001 ++From: Petr Gotthard ++Date: Sat, 7 Mar 2026 15:51:12 +0100 ++Subject: [PATCH] Fix ASN1_OCTET_STRING and X509_NAME access for OpenSSL 4.0 ++ compatibility ++ ++Fixes: #166 ++ ++OpenSSL 4.0 completes the opaquing of struct asn1_string_st, so reaching ++into ASN1_OCTET_STRING directly no longer compiles: ++ ++ src/tpm2-provider-pkey.c:152:53: error: incomplete definition of type ++ 'ASN1_OCTET_STRING' (aka 'struct asn1_string_st') ++ 152 | if (Tss2_MU_TPM2B_PRIVATE_Unmarshal(tpk->privkey->data, ++ | ~~~~~~~~~~~~~^ ++ ++Upstream-Status: Backport [https://github.com/tpm2-software/tpm2-openssl/commit/6dcc3b2984e3f4dc1849c79d89c6ce736a8435b3] ++ ++Signed-off-by: Khem Raj ++--- ++ src/tpm2-provider-pkey.c | 8 ++++---- ++ test/ec_genpkey_x509_csr.c | 10 ++++++---- ++ test/rsa_pki/etc/email.conf | 2 +- ++ 3 files changed, 11 insertions(+), 9 deletions(-) ++ ++diff --git a/src/tpm2-provider-pkey.c b/src/tpm2-provider-pkey.c ++index 38f748e..80213af 100644 ++--- a/src/tpm2-provider-pkey.c +++++ b/src/tpm2-provider-pkey.c ++@@ -149,13 +149,13 @@ tpm2_keydata_read(BIO *bin, TPM2_KEYDATA *keydata, TPM2_PKEY_FORMAT format) ++ strcmp(type_oid, OID_loadableKey)) ++ goto error; ++ ++- if (Tss2_MU_TPM2B_PRIVATE_Unmarshal(tpk->privkey->data, ++- tpk->privkey->length, NULL, +++ if (Tss2_MU_TPM2B_PRIVATE_Unmarshal(ASN1_STRING_get0_data(tpk->privkey), +++ ASN1_STRING_length(tpk->privkey), NULL, ++ &keydata->priv)) ++ goto error; ++ ++- if (Tss2_MU_TPM2B_PUBLIC_Unmarshal(tpk->pubkey->data, ++- tpk->pubkey->length, NULL, +++ if (Tss2_MU_TPM2B_PUBLIC_Unmarshal(ASN1_STRING_get0_data(tpk->pubkey), +++ ASN1_STRING_length(tpk->pubkey), NULL, ++ &keydata->pub)) ++ goto error; ++ ++diff --git a/test/ec_genpkey_x509_csr.c b/test/ec_genpkey_x509_csr.c ++index e3523ec..5c9790a 100644 ++--- a/test/ec_genpkey_x509_csr.c +++++ b/test/ec_genpkey_x509_csr.c ++@@ -15,7 +15,7 @@ int generate_csr(const char *password, const char *filename) ++ EVP_PKEY_CTX *pctx = NULL; ++ EVP_PKEY *pkey = NULL; ++ X509_REQ *x509 = NULL; ++- X509_NAME *name; +++ X509_NAME *name = NULL; ++ STACK_OF(X509_EXTENSION) *exts = NULL; ++ X509_EXTENSION *ex; ++ FILE *csr_file = NULL; ++@@ -40,9 +40,10 @@ int generate_csr(const char *password, const char *filename) ++ || X509_REQ_set_pubkey(x509, pkey) != 1) ++ goto error1; ++ ++- name = X509_REQ_get_subject_name(x509); ++- if (!X509_NAME_add_entry_by_NID(name, NID_countryName, MBSTRING_ASC, (unsigned char *)"CZ", -1, -1, 0) ++- || !X509_NAME_add_entry_by_NID(name, NID_commonName, MBSTRING_ASC, (const unsigned char *)"www.example.com", -1, -1, 0)) +++ if (!(name = X509_NAME_new()) +++ || !X509_NAME_add_entry_by_NID(name, NID_countryName, MBSTRING_ASC, (unsigned char *)"CZ", -1, -1, 0) +++ || !X509_NAME_add_entry_by_NID(name, NID_commonName, MBSTRING_ASC, (const unsigned char *)"www.example.com", -1, -1, 0) +++ || X509_REQ_set_subject_name(x509, name) != 1) ++ goto error1; ++ ++ // set requested extensions ++@@ -75,6 +76,7 @@ int generate_csr(const char *password, const char *filename) ++ fclose(csr_file); ++ error1: ++ sk_X509_EXTENSION_pop_free(exts, X509_EXTENSION_free); +++ X509_NAME_free(name); ++ X509_REQ_free(x509); ++ EVP_PKEY_free(pkey); ++ EVP_PKEY_CTX_free(pctx); ++diff --git a/test/rsa_pki/etc/email.conf b/test/rsa_pki/etc/email.conf ++index 7606c38..73c06d2 100644 ++--- a/test/rsa_pki/etc/email.conf +++++ b/test/rsa_pki/etc/email.conf ++@@ -24,4 +24,4 @@ emailAddress = "fred@simple.org" ++ keyUsage = critical,digitalSignature,keyEncipherment ++ extendedKeyUsage = emailProtection,clientAuth ++ subjectKeyIdentifier = hash ++-subjectAltName = email:move +++subjectAltName = email:copy ++-- ++2.51.0 ++ +diff --git a/meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl_1.3.0.bb b/meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl_1.3.0.bb +index e97a208..07feb00 100644 +--- a/meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl_1.3.0.bb ++++ b/meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl_1.3.0.bb +@@ -5,7 +5,9 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=3f4b4cb00f4d0d6807a0dc79759a57ac" + + DEPENDS = "autoconf-archive-native tpm2-tss openssl" + +-SRC_URI = "https://github.com/tpm2-software/${BPN}/releases/download/${PV}/${BPN}-${PV}.tar.gz" ++SRC_URI = "https://github.com/tpm2-software/${BPN}/releases/download/${PV}/${BPN}-${PV}.tar.gz \ ++ file://0001-Fix-ASN1_OCTET_STRING-and-X509_NAME-access-for-OpenS.patch \ ++ " + + SRC_URI[sha256sum] = "9a9aca55d4265ec501bcf9c56d21d6ca18dba902553f21c888fe725b42ea9964" + +-- +2.43.0 + diff --git a/patches/meta-security/0003-tpm2-tools-Upgrade-5.7-5.8.patch b/patches/meta-security/0003-tpm2-tools-Upgrade-5.7-5.8.patch new file mode 100644 index 000000000..3bcb01c75 --- /dev/null +++ b/patches/meta-security/0003-tpm2-tools-Upgrade-5.7-5.8.patch @@ -0,0 +1,57 @@ +From 6ec2b96247ef8a1089eb1be244bb847c3f2180bb Mon Sep 17 00:00:00 2001 +From: Khem Raj +Date: Sun, 6 Sep 2026 19:25:45 -0700 +Subject: [PATCH 3/5] tpm2-tools: Upgrade 5.7 -> 5.8 + +Release notes: +https://github.com/tpm2-software/tpm2-tools/blob/5.8/docs/CHANGELOG.md + +Fixes GHSA-v7w4-4gc9-qcgv, GHSA-gwfg-w3jr-xh66 and GHSA-qp88-8f4j-wv7q, +including a heap buffer overflow in tpm2_getekcertificate. + +Also brings OpenSSL 4.0 compatible macros, so the tools build and link +cleanly against openssl 4.x (verified against 4.0.2 with no deprecation +warnings; tpm2 links libcrypto.so.4). + +Add autoconf-archive-native to DEPENDS: the 5.8 release tarball no longer +bundles the autoconf-archive ax_*.m4 macros under m4/ the way 5.7 did, so +the autoreconf done by autotools.bbclass leaves AX_CHECK_COMPILE_FLAG, +AX_CHECK_LINK_FLAG, AX_CHECK_PREPROC_FLAG, AX_ADD_FORTIFY_SOURCE, +AX_CODE_COVERAGE and AX_IS_RELEASE undefined. m4 then strips a quoting +level off their unexpanded arguments and the bare AC_MSG_ERROR leaks into +configure, failing autoconf's m4_pattern_forbid check with: + + configure.ac:40: error: undefined or overquoted macro: AC_MSG_ERROR + +Upstream-Status: Submitted [https://patchwork.yoctoproject.org/project/yocto/patch/97429/] + +Signed-off-by: Khem Raj +--- + .../tpm2-tools/{tpm2-tools_5.7.bb => tpm2-tools_5.8.bb} | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + rename meta-tpm/recipes-tpm2/tpm2-tools/{tpm2-tools_5.7.bb => tpm2-tools_5.8.bb} (83%) + +diff --git a/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb b/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.8.bb +similarity index 83% +rename from meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb +rename to meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.8.bb +index 7c5d156..4edd283 100644 +--- a/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb ++++ b/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.8.bb +@@ -5,11 +5,11 @@ LICENSE = "BSD-3-Clause" + LIC_FILES_CHKSUM = "file://docs/LICENSE;md5=a846608d090aa64494c45fc147cc12e3" + SECTION = "tpm" + +-DEPENDS = "tpm2-tss openssl curl" ++DEPENDS = "tpm2-tss openssl curl autoconf-archive-native" + + SRC_URI = "https://github.com/tpm2-software/${BPN}/releases/download/${PV}/${BPN}-${PV}.tar.gz" + +-SRC_URI[sha256sum] = "3810d36b5079256f4f2f7ce552e22213d43b1031c131538df8a2dbc3c570983a" ++SRC_URI[sha256sum] = "1cb73185cae814b4e15c7c2d0b22642d640faf48775f4156a1fd92edf84bef73" + + UPSTREAM_CHECK_URI = "https://github.com/tpm2-software/${BPN}/releases" + +-- +2.43.0 + diff --git a/patches/meta-security/0004-tpm2-pkcs11-Upgrade-1.9.2-1.10.1.patch b/patches/meta-security/0004-tpm2-pkcs11-Upgrade-1.9.2-1.10.1.patch new file mode 100644 index 000000000..8a1bbf3d6 --- /dev/null +++ b/patches/meta-security/0004-tpm2-pkcs11-Upgrade-1.9.2-1.10.1.patch @@ -0,0 +1,84 @@ +From 43a03172ff5b9a330cfb371d291abed7b5229c06 Mon Sep 17 00:00:00 2001 +From: Khem Raj +Date: Mon, 7 Sep 2026 00:14:40 -0700 +Subject: [PATCH 4/5] tpm2-pkcs11: Upgrade 1.9.2 -> 1.10.1 + +Fixes the build against OpenSSL 4.0, which completes the opaquing of +struct asn1_string_st: + + src/lib/ssl_util.c:201:9: error: incomplete definition of type + 'ASN1_OCTET_STRING' (aka 'struct asn1_string_st') + +Upstream switched both call sites in ssl_util.c to the +ASN1_STRING_get0_data()/ASN1_STRING_length() accessors, so the upgrade +is all that is needed, no local patch. + +Drop 0001-src-lib-tpm-return-NULL-for-twist-on-auth-failure.patch, it is +already applied upstream in this release (PR #923) and now fails to +apply. + +Upstream-Status: Submitted [https://patchwork.yoctoproject.org/project/yocto/patch/97446/] + +Signed-off-by: Khem Raj +--- + ...eturn-NULL-for-twist-on-auth-failure.patch | 28 ------------------- + ...-pkcs11_1.9.2.bb => tpm2-pkcs11_1.10.1.bb} | 3 +- + 2 files changed, 1 insertion(+), 30 deletions(-) + delete mode 100644 meta-tpm/recipes-tpm2/tpm2-pkcs11/files/0001-src-lib-tpm-return-NULL-for-twist-on-auth-failure.patch + rename meta-tpm/recipes-tpm2/tpm2-pkcs11/{tpm2-pkcs11_1.9.2.bb => tpm2-pkcs11_1.10.1.bb} (91%) + +diff --git a/meta-tpm/recipes-tpm2/tpm2-pkcs11/files/0001-src-lib-tpm-return-NULL-for-twist-on-auth-failure.patch b/meta-tpm/recipes-tpm2/tpm2-pkcs11/files/0001-src-lib-tpm-return-NULL-for-twist-on-auth-failure.patch +deleted file mode 100644 +index 2992b11..0000000 +--- a/meta-tpm/recipes-tpm2/tpm2-pkcs11/files/0001-src-lib-tpm-return-NULL-for-twist-on-auth-failure.patch ++++ /dev/null +@@ -1,28 +0,0 @@ +-From 0db779aecaae93633be963ffb8fdb097c85cc166 Mon Sep 17 00:00:00 2001 +-From: Peter Marko +-Date: Thu, 9 Apr 2026 00:00:00 +0000 +-Subject: [PATCH] src/lib/tpm: return NULL for twist on auth failure +- +-`tpm_unseal` returns `twist` (a const char pointer alias). Returning +-`false` in the error path is a type mismatch that fails with stricter +-compiler settings. Return `NULL` instead. +- +-Upstream-Status: Submitted [https://github.com/tpm2-software/tpm2-pkcs11/pull/923] +-Signed-off-by: Peter Marko +---- +- src/lib/tpm.c | 2 +- +- 1 file changed, 1 insertion(+), 1 deletion(-) +- +-diff --git a/src/lib/tpm.c b/src/lib/tpm.c +-index 5fff5d5..c51d984 100644 +---- a/src/lib/tpm.c +-+++ b/src/lib/tpm.c +-@@ -1037,7 +1037,7 @@ twist tpm_unseal(tpm_ctx *ctx, uint32_t handle, twist objauth) { +- +- bool result = set_esys_auth(ctx->esys_ctx, handle, objauth); +- if (!result) { +-- return false; +-+ return NULL; +- } +- +- TPM2B_SENSITIVE_DATA *unsealed_data = NULL; +diff --git a/meta-tpm/recipes-tpm2/tpm2-pkcs11/tpm2-pkcs11_1.9.2.bb b/meta-tpm/recipes-tpm2/tpm2-pkcs11/tpm2-pkcs11_1.10.1.bb +similarity index 91% +rename from meta-tpm/recipes-tpm2/tpm2-pkcs11/tpm2-pkcs11_1.9.2.bb +rename to meta-tpm/recipes-tpm2/tpm2-pkcs11/tpm2-pkcs11_1.10.1.bb +index 1a671bc..b5bf6c1 100644 +--- a/meta-tpm/recipes-tpm2/tpm2-pkcs11/tpm2-pkcs11_1.9.2.bb ++++ b/meta-tpm/recipes-tpm2/tpm2-pkcs11/tpm2-pkcs11_1.10.1.bb +@@ -8,9 +8,8 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=0fc19f620a102768d6dbd1e7166e78ab" + DEPENDS = "autoconf-archive pkgconfig sqlite3 openssl libtss2-dev tpm2-tools libyaml p11-kit python3-setuptools-native" + + SRC_URI = "https://github.com/tpm2-software/${BPN}/releases/download/${PV}/${BPN}-${PV}.tar.gz" +-SRC_URI += "file://0001-src-lib-tpm-return-NULL-for-twist-on-auth-failure.patch" + +-SRC_URI[sha256sum] = "1bdabdaed6a5fa4ce8a1e82307f4612c30e30b0a0415e1bc7d9c30f713227480" ++SRC_URI[sha256sum] = "f3315d17811f918779a1046ba20e49060a40b2b586a06ab013ff8c8da53752e4" + + UPSTREAM_CHECK_URI = "https://github.com/tpm2-software/${BPN}/releases" + +-- +2.43.0 + diff --git a/patches/meta-security/0005-packagegroup-security-tpm2-Remove-tpm2-tss-engine-fr.patch b/patches/meta-security/0005-packagegroup-security-tpm2-Remove-tpm2-tss-engine-fr.patch new file mode 100644 index 000000000..cc0da19ad --- /dev/null +++ b/patches/meta-security/0005-packagegroup-security-tpm2-Remove-tpm2-tss-engine-fr.patch @@ -0,0 +1,30 @@ +From b4f3af87150c3373725d1d3207a850d5670d1886 Mon Sep 17 00:00:00 2001 +From: Khem Raj +Date: Mon, 7 Sep 2026 08:28:44 -0700 +Subject: [PATCH 5/5] packagegroup-security-tpm2: Remove tpm2-tss-engine from + packagegroup + +engines are not available in openSSL 4.x + +Upstream-Status: Submitted [https://patchwork.yoctoproject.org/project/yocto/patch/97570/] + +Signed-off-by: Khem Raj +--- + .../recipes-core/packagegroup/packagegroup-security-tpm2.bb | 2 -- + 1 file changed, 2 deletions(-) + +diff --git a/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm2.bb b/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm2.bb +index b04851f..423a86f 100644 +--- a/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm2.bb ++++ b/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm2.bb +@@ -22,7 +22,5 @@ RDEPENDS:packagegroup-security-tpm2 = " \ + tpm2-abrmd \ + tpm2-pkcs11 \ + tpm2-openssl \ +- tpm2-tss-engine \ +- tpm2-tss-engine-engines \ + python3-tpm2-pytss \ + " +-- +2.43.0 + From c02b279423d69d65259170a7fd5b22ee758f3bea Mon Sep 17 00:00:00 2001 From: Ricardo Salveti Date: Tue, 8 Sep 2026 23:45:50 +0000 Subject: [PATCH 06/10] minkipc: fix the optee_test build against OpenSSL 4.0 OpenSSL 4.0 returns const X509_NAME pointers from the certificate name getters, and the xtest pkcs11 suite bundled in minkipc assigns them to non-const variables while building with -Werror, so the recipe fails to compile. Declare the two names const; they are only handed to i2d_X509_NAME(), which already takes a const pointer. Assisted-by: Claude Code:claude-fable-5-1 Signed-off-by: Ricardo Salveti --- ...p-the-X.509-subject-and-issuer-names.patch | 46 +++++++++++++++++++ .../recipes-security/minkipc/minkipc_1.2.9.bb | 1 + 2 files changed, 47 insertions(+) create mode 100644 dynamic-layers/openembedded-layer/recipes-security/minkipc/files/0001-xtest-pkcs11-keep-the-X.509-subject-and-issuer-names.patch diff --git a/dynamic-layers/openembedded-layer/recipes-security/minkipc/files/0001-xtest-pkcs11-keep-the-X.509-subject-and-issuer-names.patch b/dynamic-layers/openembedded-layer/recipes-security/minkipc/files/0001-xtest-pkcs11-keep-the-X.509-subject-and-issuer-names.patch new file mode 100644 index 000000000..f78e3f8bf --- /dev/null +++ b/dynamic-layers/openembedded-layer/recipes-security/minkipc/files/0001-xtest-pkcs11-keep-the-X.509-subject-and-issuer-names.patch @@ -0,0 +1,46 @@ +From 9a3b651cefef5e0501151e59f1feeed77cd30741 Mon Sep 17 00:00:00 2001 +From: Ricardo Salveti +Date: Wed, 9 Sep 2026 15:59:13 +0000 +Subject: [PATCH] xtest: pkcs11: keep the X.509 subject and issuer names const + +OpenSSL 4.0 changed X509_get_subject_name() and X509_get_issuer_name() +to return a const X509_NAME pointer. The certificate test assigns the +results to non-const pointers, and since xtest builds with -Werror the +whole host build fails against OpenSSL 4.0: + + pkcs11_1000.c:7879:27: error: assignment discards 'const' qualifier + from pointer target type [-Werror=discarded-qualifiers] + +Declare both names const. They are only passed to i2d_X509_NAME(), +which has taken a const pointer since OpenSSL 1.1.0, and to +ADBG_EXPECT_NOT_NULL(), which takes a const void pointer, so the change +builds unchanged against OpenSSL 3.x as well. + +Assisted-by: Claude Code:claude-fable-5-1 +Upstream-Status: Submitted [https://github.com/OP-TEE/optee_test/pull/838] + +Signed-off-by: Ricardo Salveti +--- + host/xtest/pkcs11_1000.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/host/xtest/pkcs11_1000.c b/host/xtest/pkcs11_1000.c +index c822ec2..08d4093 100644 +--- a/host/xtest/pkcs11_1000.c ++++ b/host/xtest/pkcs11_1000.c +@@ -7725,10 +7725,10 @@ static void xtest_pkcs11_test_1024(ADBG_Case_t *c) + X509 *x509_cert = NULL; + uint8_t *x509_cert_der = NULL; + int x509_cert_der_size = 0; +- X509_NAME *x509_subject_name = NULL; ++ const X509_NAME *x509_subject_name = NULL; + uint8_t *x509_subject_name_der = NULL; + int x509_subject_name_der_size = 0; +- X509_NAME *x509_issuer_name = NULL; ++ const X509_NAME *x509_issuer_name = NULL; + uint8_t *x509_issuer_name_der = NULL; + int x509_issuer_name_der_size = 0; + ASN1_INTEGER *x509_serial_number = NULL; +-- +2.43.0 + diff --git a/dynamic-layers/openembedded-layer/recipes-security/minkipc/minkipc_1.2.9.bb b/dynamic-layers/openembedded-layer/recipes-security/minkipc/minkipc_1.2.9.bb index efb82c634..70317013b 100644 --- a/dynamic-layers/openembedded-layer/recipes-security/minkipc/minkipc_1.2.9.bb +++ b/dynamic-layers/openembedded-layer/recipes-security/minkipc/minkipc_1.2.9.bb @@ -18,6 +18,7 @@ SRC_URI = "git://github.com/qualcomm/minkipc.git;branch=main;protocol=https;tag= file://0001-xtest-Remove-regression-suite-from-default-test-suit.patch;patchdir=optee-test/optee_test \ file://0002-xtest-pkcs11-Stub-the-test-cases-inapplicable-for-QT.patch;patchdir=optee-test/optee_test \ file://0003-test-pkcs11-Fix-static-initialization-issue-caused-b.patch;patchdir=optee-test/optee_test \ + file://0001-xtest-pkcs11-keep-the-X.509-subject-and-issuer-names.patch;patchdir=optee-test/optee_test \ " LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=2b1366ebba1ebd9ae25ad19626bbca93 \ From 0804e6dac11c2f338165774964c301df7a5af2f5 Mon Sep 17 00:00:00 2001 From: Ricardo Salveti Date: Wed, 9 Sep 2026 00:22:15 +0000 Subject: [PATCH 07/10] ci: qcom-distro: patch meta-qcom-distro to drop qwes from the proprietary image The prebuilt qwesd daemon is linked against libcrypto.so.3 and cannot be packaged now that OE-Core ships OpenSSL 4.0, which makes the qcom-multimedia-proprietary-image fail its file-rdeps QA check. Carry the image change as a kas patch until a qwes build against OpenSSL 4.0 is published and the image can pull it back in. Assisted-by: Claude Code:claude-fable-5-1 Signed-off-by: Ricardo Salveti --- ci/qcom-distro.yml | 4 ++ ...proprietary-image-drop-qwes-until-it.patch | 38 +++++++++++++++++++ 2 files changed, 42 insertions(+) create mode 100644 patches/meta-qcom-distro/0001-qcom-multimedia-proprietary-image-drop-qwes-until-it.patch diff --git a/ci/qcom-distro.yml b/ci/qcom-distro.yml index 509c982a5..c2a0f83b6 100644 --- a/ci/qcom-distro.yml +++ b/ci/qcom-distro.yml @@ -13,6 +13,10 @@ repos: meta-qcom-distro: url: https://github.com/qualcomm-linux/meta-qcom-distro branch: main + patches: + qwes-openssl4: + repo: meta-qcom + path: patches/meta-qcom-distro/0001-qcom-multimedia-proprietary-image-drop-qwes-until-it.patch meta-openembedded: url: https://github.com/openembedded/meta-openembedded diff --git a/patches/meta-qcom-distro/0001-qcom-multimedia-proprietary-image-drop-qwes-until-it.patch b/patches/meta-qcom-distro/0001-qcom-multimedia-proprietary-image-drop-qwes-until-it.patch new file mode 100644 index 000000000..855311513 --- /dev/null +++ b/patches/meta-qcom-distro/0001-qcom-multimedia-proprietary-image-drop-qwes-until-it.patch @@ -0,0 +1,38 @@ +From 3258f8b6ee376ce64a30663447f81846c26e5972 Mon Sep 17 00:00:00 2001 +From: Ricardo Salveti +Date: Wed, 9 Sep 2026 00:22:15 +0000 +Subject: [PATCH] qcom-multimedia-proprietary-image: drop qwes until it is + rebuilt for OpenSSL 4.0 + +OE-Core moved to OpenSSL 4.0, and the prebuilt qwesd daemon is linked +against libcrypto.so.3, which no longer exists: + + ERROR: qwes-1.1-r0 do_package_qa: QA Issue: /usr/bin/qwesd contained in + package qwes requires libcrypto.so.3(OPENSSL_3.0.0)(64bit), but no + providers found in RDEPENDS:qwes? [file-rdeps] + +A prebuilt cannot be relinked, so leave qwes out of the image until a +build against OpenSSL 4.0 is published. + +Upstream-Status: Pending + +Signed-off-by: Ricardo Salveti +--- + recipes-products/images/qcom-multimedia-proprietary-image.bb | 1 - + 1 file changed, 1 deletion(-) + +diff --git a/recipes-products/images/qcom-multimedia-proprietary-image.bb b/recipes-products/images/qcom-multimedia-proprietary-image.bb +index 1b6e52d..afaaa6c 100644 +--- a/recipes-products/images/qcom-multimedia-proprietary-image.bb ++++ b/recipes-products/images/qcom-multimedia-proprietary-image.bb +@@ -21,7 +21,6 @@ CORE_IMAGE_BASE_INSTALL += " \ + onnxruntime-qnn \ + qcom-adreno \ + qcom-sensors-binaries \ +- qwes \ + " + CORE_IMAGE_BASE_INSTALL:append = " \ + ${@bb.utils.contains('BBFILE_COLLECTIONS', 'meta-audioreach', ' packagegroup-audioreach', '', d)} \ +-- +2.43.0 + From c4f238ae30ec11642ac95ba320860b46b68b8387 Mon Sep 17 00:00:00 2001 From: Ricardo Salveti Date: Wed, 9 Sep 2026 00:27:34 +0000 Subject: [PATCH 08/10] onnxruntime-qnn: build against the pinned GSL 4.0.0 source The QNN execution provider includes gsl/gsl and used to get the headers through the onnxruntime dependency chain. onnxruntime now builds against its own pinned GSL 4.0.0 source instead of microsoft-gsl, whose 5.0.0 CMake package rejects the 4.0 request the build makes, so the headers are gone from the sysroot and the provider fails to compile: onnxruntime/core/providers/qnn/ort_api.h:9:10: fatal error: gsl/gsl: No such file or directory Fetch the same GSL v4.0.0 tag that onnxruntime pins in cmake/deps.txt, as this recipe already does for SafeInt, and hand it to FetchContent, so the provider is built against the same GSL headers as onnxruntime rather than a different major version from the sysroot. Assisted-by: Claude Code:claude-fable-5-1 Signed-off-by: Ricardo Salveti --- .../ai/recipes-ml/onnxruntime-qnn/onnxruntime-qnn_2.4.0.bb | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/dynamic-layers/ai/recipes-ml/onnxruntime-qnn/onnxruntime-qnn_2.4.0.bb b/dynamic-layers/ai/recipes-ml/onnxruntime-qnn/onnxruntime-qnn_2.4.0.bb index 9041dc987..a7b18739e 100644 --- a/dynamic-layers/ai/recipes-ml/onnxruntime-qnn/onnxruntime-qnn_2.4.0.bb +++ b/dynamic-layers/ai/recipes-ml/onnxruntime-qnn/onnxruntime-qnn_2.4.0.bb @@ -17,13 +17,15 @@ DEPENDS = " \ SRC_URI = "git://github.com/onnxruntime/onnxruntime-qnn.git;protocol=https;nobranch=1;tag=v${PV};name=ort-qnn \ git://github.com/dcleblanc/SafeInt.git;protocol=https;nobranch=1;name=safeint;tag=3.0.28;destsuffix=safeint \ + git://github.com/microsoft/GSL.git;protocol=https;nobranch=1;name=gsl;tag=v4.0.0;destsuffix=gsl \ file://0001-cmake-Rename-pkg-config-output-to-libonnxruntime_pr.patch \ file://0002-QNN-EP-Fix-ORT-header-include-path-and-multiarch-li.patch \ " -SRCREV_FORMAT = "ort-qnn_safeint" +SRCREV_FORMAT = "ort-qnn_safeint_gsl" SRCREV_ort-qnn = "215ea95bd6df9ab24ba48193a6554dce8490337d" SRCREV_safeint = "4cafc9196c4da9c817992b20f5253ef967685bf8" +SRCREV_gsl = "1fcf53a2f64c72c76f5d84adb50d41e6c4467d23" # Since qairt-sdk is installed only on ARMv8 (aarch64) machines and QNN EP uses # qairt sdk for hw acceleration. Therefore, builds for other architectures are @@ -45,6 +47,7 @@ EXTRA_OECMAKE = " \ -DCMAKE_FIND_ROOT_PATH=${STAGING_DIR_TARGET} \ -DFETCHCONTENT_FULLY_DISCONNECTED=ON \ -DFETCHCONTENT_SOURCE_DIR_SAFEINT=${UNPACKDIR}/safeint \ + -DFETCHCONTENT_SOURCE_DIR_GSL=${UNPACKDIR}/gsl \ -DONNX_CUSTOM_PROTOC_EXECUTABLE=${STAGING_BINDIR_NATIVE}/protoc \ -Donnxruntime_BUILD_SHARED_LIB=ON \ -Donnxruntime_BUILD_UNIT_TESTS=OFF \ From 843e5956b9071556adb299cac7c4e0aec4f8246e Mon Sep 17 00:00:00 2001 From: Ricardo Salveti Date: Thu, 10 Sep 2026 23:03:28 +0000 Subject: [PATCH 09/10] qwes: remove the recipe until a build against OpenSSL 4.0 is published The prebuilt qwesd is linked against libcrypto.so.3, which OE-Core no longer ships since the move to OpenSSL 4.0, so every world build fails in do_package_qa: QA Issue: /usr/bin/qwesd contained in package qwes requires libcrypto.so.3(OPENSSL_3.0.0)(64bit), but no providers found in RDEPENDS:qwes? [file-rdeps] Remove the recipe until a prebuilt against OpenSSL 4.0 is available; the proprietary image no longer installs it. Assisted-by: Claude Code:claude-fable-5-1 Signed-off-by: Ricardo Salveti --- .../recipes-security/qwes/qwes_1.1.bb | 45 ------------------- 1 file changed, 45 deletions(-) delete mode 100644 dynamic-layers/openembedded-layer/recipes-security/qwes/qwes_1.1.bb diff --git a/dynamic-layers/openembedded-layer/recipes-security/qwes/qwes_1.1.bb b/dynamic-layers/openembedded-layer/recipes-security/qwes/qwes_1.1.bb deleted file mode 100644 index 6a919c0bd..000000000 --- a/dynamic-layers/openembedded-layer/recipes-security/qwes/qwes_1.1.bb +++ /dev/null @@ -1,45 +0,0 @@ -SUMMARY = "Prebuilt Qualcomm Wireless Edge Services binaries, setup scripts and utility application" -DESCRIPTION = "Qualcomm Wireless Edge Services provide a suite of features Platform feature management, \ -device attestation and secure provisioning. This recipe includes the daemon and scripts which setup \ -the store and optionally load QcWES TA to provide these features." - -LICENSE = "LicenseRef-LICENSE.qcom-2" -LIC_FILES_CHKSUM = "file://usr/share/doc/${BPN}/LICENSE.qcom-2;md5=165287851294f2fb8ac8cbc5e24b02b0" - -PBT_BUILD_DATE = "260620" - -SRC_URI = "https://softwarecenter.qualcomm.com/nexus/generic/software/chip/component/sec-userspace.qclinux.0.0/${PBT_BUILD_DATE}/prebuilt_yocto/qwes_1.0_armv8a.tar.gz" -SRC_URI[sha256sum] = "7bb20daa916e4b13e54948ab90af92e9c2e6129cc22da1a23b924adb3f0610d4" - -S = "${UNPACKDIR}" - -inherit systemd - -DEPENDS += "curl minkipc qmi-framework glibc" - -# This package is currently only used and tested on ARMv8 (aarch64) machines. -# Therefore, builds for other architectures are not necessary and are explicitly excluded. -COMPATIBLE_MACHINE = "^$" -COMPATIBLE_MACHINE:aarch64 = "(.*)" - -PACKAGES += "${PN}-ta" - -SYSTEMD_SERVICE:${PN} = "qwesd.service" - -do_install() { - install -d ${D}${bindir} - install -d ${D}${systemd_system_unitdir} - install -d ${D}${docdir}/${BPN} - install -d ${D}${nonarch_base_libdir}/qtee-tas - - # Install binaries - install -m 0755 ${S}/usr/bin/* ${D}${bindir}/ - install -m 0644 ${S}/usr/lib/systemd/system/qwesd.service ${D}${systemd_system_unitdir}/qwesd.service - install -m 0644 ${S}/usr/share/doc/${BPN}/NOTICE.txt ${D}${docdir}/${BPN} - install -m 0644 ${S}/usr/share/doc/${BPN}/LICENSE.qcom-2 ${D}${docdir}/${BPN} - cp -R ${S}/lib/qtee-tas/* ${D}${nonarch_base_libdir}/qtee-tas/ -} - -FILES:${PN}-ta += "${nonarch_base_libdir}/qtee-tas" -RDEPENDS:${PN} = "${PN}-ta" -INSANE_SKIP:${PN}-ta += "arch" \ No newline at end of file From 31ac841d9e998b96fea28f8368768caf71261919 Mon Sep 17 00:00:00 2001 From: Ricardo Salveti Date: Thu, 10 Sep 2026 23:03:28 +0000 Subject: [PATCH 10/10] u-boot-qcom: add the OpenSSL provider patch carried by OE-Core The u-boot host tools sign FIT images through the OpenSSL ENGINE API, which openssl-native 4.0 no longer provides, so every u-boot-qcom build fails to link tools/mkimage and tools/dumpimage: rsa-sign.c: undefined reference to 'ENGINE_load_private_key' OE-Core carries the patch submitted upstream that moves rsa-sign.c to the provider API, but this recipe replaces the common SRC_URI and so loses it. Add the same patch here. Assisted-by: Claude Code:claude-fable-5-1 Signed-off-by: Ricardo Salveti --- ...Add-support-for-OpenSSL-Provider-API.patch | 340 ++++++++++++++++++ recipes-bsp/u-boot/u-boot-qcom_git.bb | 1 + 2 files changed, 341 insertions(+) create mode 100644 recipes-bsp/u-boot/files/0001-Add-support-for-OpenSSL-Provider-API.patch diff --git a/recipes-bsp/u-boot/files/0001-Add-support-for-OpenSSL-Provider-API.patch b/recipes-bsp/u-boot/files/0001-Add-support-for-OpenSSL-Provider-API.patch new file mode 100644 index 000000000..346d0584d --- /dev/null +++ b/recipes-bsp/u-boot/files/0001-Add-support-for-OpenSSL-Provider-API.patch @@ -0,0 +1,340 @@ +From a81cb0932dce109af44d7245d47489fe54ae390f Mon Sep 17 00:00:00 2001 +From: Eddie Kovsky +Date: Mon, 23 Feb 2026 09:43:22 -0700 +Subject: [PATCH] Add support for OpenSSL Provider API + +The Engine API has been deprecated since the release of OpenSSL 3.0. End +users have been advised to migrate to the new Provider interface. +Several distributions have already removed support for engines, which is +preventing U-Boot from being compiled in those environments. + +Add support for the Provider API while continuing to support the existing +Engine API on distros shipping older releases of OpenSSL. + +This is based on similar work contributed by Jan Stancek updating Linux +to use the Provider interface. + + commit 558bdc45dfb2669e1741384a0c80be9c82fa052c + Author: Jan Stancek + Date: Fri Sep 20 19:52:48 2024 +0300 + + sign-file,extract-cert: use pkcs11 provider for OPENSSL MAJOR >= 3 + +The changes have been tested with the FIT signature verification vboot +tests on Fedora 42 and Debian 13. All 30 tests pass with both the legacy +Engine library installed and with the Provider API. + +Signed-off-by: Eddie Kovsky + +Upstream-Status: Submitted [https://lore.kernel.org/u-boot/20260429180247.83091-1-ekovsky@redhat.com/] + +Note: Modified to make pkcs11 provider loading optional. The upstream +patch unconditionally requires the pkcs11 provider, which is not +available in the OE build environment. File-based key signing only needs +the default provider; pkcs11 is only required for pkcs11: URI keys. +Changes from upstream: + - Load default provider first (was pkcs11 first) + - Make pkcs11 provider load failure non-fatal (ERR_clear_error instead + of ERR(1, ...) which calls errx/abort) + +Signed-off-by: Jaipaul Cheernam +--- + doc/build/gcc.rst | 4 +- + lib/aes/aes-encrypt.c | 4 +- + lib/rsa/rsa-sign.c | 102 +++++++++++++++++++++++++++++++++++++++--- + tools/docker/Dockerfile | 1 + + 4 files changed, 103 insertions(+), 8 deletions(-) + +diff --git a/doc/build/gcc.rst b/doc/build/gcc.rst +index 1fef718ceecb..29a6a632e7e3 100644 +--- a/doc/build/gcc.rst ++++ b/doc/build/gcc.rst +@@ -25,8 +25,8 @@ Depending on the build targets further packages maybe needed + + sudo apt-get install bc bison build-essential coccinelle \ + device-tree-compiler dfu-util efitools flex gdisk graphviz imagemagick \ +- libgnutls28-dev libguestfs-tools libncurses-dev \ +- libpython3-dev libsdl2-dev libssl-dev lz4 lzma lzma-alone openssl \ ++ libgnutls28-dev libguestfs-tools libncurses-dev libpython3-dev \ ++ libsdl2-dev libssl-dev lz4 lzma lzma-alone openssl pkcs11-provider \ + pkg-config python3 python3-asteval python3-coverage python3-filelock \ + python3-pkg-resources python3-pycryptodome python3-pyelftools \ + python3-pytest python3-pytest-xdist python3-sphinxcontrib.apidoc \ +diff --git a/lib/aes/aes-encrypt.c b/lib/aes/aes-encrypt.c +index 90e1407b4f09..4fc4ce232478 100644 +--- a/lib/aes/aes-encrypt.c ++++ b/lib/aes/aes-encrypt.c +@@ -16,7 +16,9 @@ + #include + #include + #include +-#include ++#if !defined(OPENSSL_NO_ENGINE) && !defined(OPENSSL_NO_DEPRECATED_3_0) ++# include ++#endif + #include + + #if OPENSSL_VERSION_NUMBER >= 0x10000000L +diff --git a/lib/rsa/rsa-sign.c b/lib/rsa/rsa-sign.c +index 0e38c9e802fd..f456f3c58e65 100644 +--- a/lib/rsa/rsa-sign.c ++++ b/lib/rsa/rsa-sign.c +@@ -19,7 +19,47 @@ + #include + #include + #include +-#include ++#if OPENSSL_VERSION_MAJOR >= 3 ++# define USE_PKCS11_PROVIDER ++# include ++# include ++# include ++#else ++# if !defined(OPENSSL_NO_ENGINE) && !defined(OPENSSL_NO_DEPRECATED_3_0) ++# define USE_PKCS11_ENGINE ++# include ++# endif ++#endif ++ ++#ifdef USE_PKCS11_PROVIDER ++#define ERR(cond, fmt, ...) \ ++ do { \ ++ bool __cond = (cond); \ ++ drain_openssl_errors(__LINE__, 0); \ ++ if (__cond) { \ ++ errx(1, fmt, ## __VA_ARGS__); \ ++ } \ ++ } while (0) ++ ++static void drain_openssl_errors(int l, int silent) ++{ ++ const char *file; ++ char buf[120]; ++ int e, line; ++ ++ if (ERR_peek_error() == 0) ++ return; ++ if (!silent) ++ fprintf(stderr, "At main.c:%d:\n", l); ++ ++ while ((e = ERR_peek_error_line(&file, &line))) { ++ ERR_error_string(e, buf); ++ if (!silent) ++ fprintf(stderr, "- SSL %s: %s:%d\n", buf, file, line); ++ ERR_get_error(); ++ } ++} ++#endif + + static int rsa_err(const char *msg) + { +@@ -94,10 +134,11 @@ static int rsa_pem_get_pub_key(const char *keydir, const char *name, EVP_PKEY ** + * + * @keydir: Key prefix + * @name Name of key +- * @engine Engine to use ++ * @engine Engine to use or NULL when using pkcs11 provider + * @evpp Returns EVP_PKEY object, or NULL on failure + * Return: 0 if ok, -ve on error (in which case *evpp will be set to NULL) + */ ++#ifdef USE_PKCS11_ENGINE + static int rsa_engine_get_pub_key(const char *keydir, const char *name, + ENGINE *engine, EVP_PKEY **evpp) + { +@@ -157,21 +198,24 @@ static int rsa_engine_get_pub_key(const char *keydir, const char *name, + + return 0; + } ++#endif + + /** + * rsa_get_pub_key() - read a public key + * + * @keydir: Directory containing the key (PEM file) or key prefix (engine) + * @name Name of key file (will have a .crt extension) +- * @engine Engine to use ++ * @engine Engine to use or NULL when using pkcs11 provider + * @evpp Returns EVP_PKEY object, or NULL on failure + * Return: 0 if ok, -ve on error (in which case *evpp will be set to NULL) + */ + static int rsa_get_pub_key(const char *keydir, const char *name, + ENGINE *engine, EVP_PKEY **evpp) + { ++#ifdef USE_PKCS11_ENGINE + if (engine) + return rsa_engine_get_pub_key(keydir, name, engine, evpp); ++#endif + return rsa_pem_get_pub_key(keydir, name, evpp); + } + +@@ -207,13 +251,45 @@ static int rsa_pem_get_priv_key(const char *keydir, const char *name, + return -ENOENT; + } + ++#ifdef USE_PKCS11_PROVIDER ++ EVP_PKEY *private_key = NULL; ++ OSSL_STORE_CTX *store; ++ ++ if (!OSSL_PROVIDER_try_load(NULL, "default", true)) ++ ERR(1, "OSSL_PROVIDER_try_load(default)"); ++ /* pkcs11 provider is optional; only needed for pkcs11: URIs */ ++ if (!OSSL_PROVIDER_try_load(NULL, "pkcs11", true)) ++ ERR_clear_error(); ++ ++ store = OSSL_STORE_open(path, NULL, NULL, NULL, NULL); ++ ERR(!store, "OSSL_STORE_open"); ++ ++ while (!OSSL_STORE_eof(store)) { ++ OSSL_STORE_INFO *info = OSSL_STORE_load(store); ++ ++ if (!info) { ++ drain_openssl_errors(__LINE__, 0); ++ continue; ++ } ++ if (OSSL_STORE_INFO_get_type(info) == OSSL_STORE_INFO_PKEY) { ++ private_key = OSSL_STORE_INFO_get1_PKEY(info); ++ ERR(!private_key, "OSSL_STORE_INFO_get1_PKEY"); ++ } ++ OSSL_STORE_INFO_free(info); ++ if (private_key) ++ break; ++ } ++ OSSL_STORE_close(store); ++ ++ *evpp = private_key; ++#else + if (!PEM_read_PrivateKey(f, evpp, NULL, path)) { + rsa_err("Failure reading private key"); + fclose(f); + return -EPROTO; + } + fclose(f); +- ++#endif + return 0; + } + +@@ -226,6 +301,7 @@ static int rsa_pem_get_priv_key(const char *keydir, const char *name, + * @evpp Returns EVP_PKEY object, or NULL on failure + * Return: 0 if ok, -ve on error (in which case *evpp will be set to NULL) + */ ++#ifdef USE_PKCS11_ENGINE + static int rsa_engine_get_priv_key(const char *keydir, const char *name, + const char *keyfile, + ENGINE *engine, EVP_PKEY **evpp) +@@ -293,22 +369,25 @@ static int rsa_engine_get_priv_key(const char *keydir, const char *name, + + return 0; + } ++#endif + + /** + * rsa_get_priv_key() - read a private key + * + * @keydir: Directory containing the key (PEM file) or key prefix (engine) + * @name Name of key +- * @engine Engine to use for signing ++ * @engine Engine to use or NULL when using pkcs11 provider + * @evpp Returns EVP_PKEY object, or NULL on failure + * Return: 0 if ok, -ve on error (in which case *evpp will be set to NULL) + */ + static int rsa_get_priv_key(const char *keydir, const char *name, + const char *keyfile, ENGINE *engine, EVP_PKEY **evpp) + { ++#ifdef USE_PKCS11_ENGINE + if (engine) + return rsa_engine_get_priv_key(keydir, name, keyfile, engine, + evpp); ++#endif + return rsa_pem_get_priv_key(keydir, name, keyfile, evpp); + } + +@@ -325,6 +404,7 @@ static int rsa_init(void) + return 0; + } + ++#ifdef USE_PKCS11_ENGINE + static int rsa_engine_init(const char *engine_id, ENGINE **pe) + { + const char *key_pass; +@@ -380,6 +460,7 @@ static void rsa_engine_remove(ENGINE *e) + ENGINE_free(e); + } + } ++#endif + + static int rsa_sign_with_key(EVP_PKEY *pkey, struct padding_algo *padding_algo, + struct checksum_algo *checksum_algo, +@@ -480,11 +561,13 @@ int rsa_sign(struct image_sign_info *info, + if (ret) + return ret; + ++#ifdef USE_PKCS11_ENGINE + if (info->engine_id) { + ret = rsa_engine_init(info->engine_id, &e); + if (ret) + return ret; + } ++#endif + + ret = rsa_get_priv_key(info->keydir, info->keyname, info->keyfile, + e, &pkey); +@@ -496,16 +579,21 @@ int rsa_sign(struct image_sign_info *info, + goto err_sign; + + EVP_PKEY_free(pkey); ++ ++#ifdef USE_PKCS11_ENGINE + if (info->engine_id) + rsa_engine_remove(e); ++#endif + + return ret; + + err_sign: + EVP_PKEY_free(pkey); + err_priv: ++#ifdef USE_PKCS11_ENGINE + if (info->engine_id) + rsa_engine_remove(e); ++#endif + return ret; + } + +@@ -645,11 +733,13 @@ int rsa_add_verify_data(struct image_sign_info *info, void *keydest) + ENGINE *e = NULL; + + debug("%s: Getting verification data\n", __func__); ++#ifdef USE_PKCS11_ENGINE + if (info->engine_id) { + ret = rsa_engine_init(info->engine_id, &e); + if (ret) + return ret; + } ++#endif + ret = rsa_get_pub_key(info->keydir, info->keyname, e, &pkey); + if (ret) + goto err_get_pub_key; +@@ -726,8 +816,10 @@ int rsa_add_verify_data(struct image_sign_info *info, void *keydest) + err_get_params: + EVP_PKEY_free(pkey); + err_get_pub_key: ++#ifdef USE_PKCS11_ENGINE + if (info->engine_id) + rsa_engine_remove(e); ++#endif + + if (ret) + return ret; +diff --git a/tools/docker/Dockerfile b/tools/docker/Dockerfile +index 73bf6cdd2c52..50e98e83dc20 100644 +--- a/tools/docker/Dockerfile ++++ b/tools/docker/Dockerfile +@@ -122,6 +122,7 @@ RUN --mount=type=cache,target=/var/cache/apt,sharing=locked \ + openssl \ + picocom \ + parted \ ++ pkcs11-provider \ + pkg-config \ + python-is-python3 \ + python3 \ diff --git a/recipes-bsp/u-boot/u-boot-qcom_git.bb b/recipes-bsp/u-boot/u-boot-qcom_git.bb index bcc340450..53cf33ee4 100644 --- a/recipes-bsp/u-boot/u-boot-qcom_git.bb +++ b/recipes-bsp/u-boot/u-boot-qcom_git.bb @@ -13,6 +13,7 @@ SRCBRANCH = "nobranch=1" SRC_URI = "git://github.com/qualcomm-linux/u-boot.git;${SRCBRANCH};protocol=https;name=uboot" SRC_URI += " \ + file://0001-Add-support-for-OpenSSL-Provider-API.patch \ file://disable-eficapsule-tool.cfg \ file://efi-rt-volatile-store.cfg \ ${@bb.utils.contains('MACHINE_FEATURES', 'optee', 'file://tfa-optee.cfg', '', d)} \