[vlc-commits] [Git][videolan/vlc][3.0.x] 9 commits: NEWS: update about security

Thomas Guillem (@tguillem) gitlab at videolan.org
Thu Sep 17 12:31:27 UTC 2026



Thomas Guillem pushed to branch 3.0.x at VideoLAN / VLC


Commits:
e2359d61 by Thomas Guillem at 2026-09-17T10:58:17+02:00
NEWS: update about security

"will be updated a few days after the release" is misleading as this
line is not intended to be updated after the release.

- - - - -
edf79d44 by Thomas Guillem at 2026-09-17T11:25:02+02:00
NEWS: APV is the codec

And OpenAPV is the lib

- - - - -
910cc9ca by Steve Lhomme at 2026-09-17T12:57:25+02:00
contrib: breakpad: fix compilation with newer compilers

src/client/windows/crash_generation/crash_generation_server.cc:364:10: error: first argument in call to 'memset' is a pointer to non-trivially copyable type 'ProtocolMessage' [-Werror,-Wnontrivial-memcall]
  364 |   memset(&msg_, 0, sizeof(msg_));
      |          ^

- - - - -
5491e23d by Pierre Lamot at 2026-09-17T12:57:25+02:00
snap: remove useless compilation option

vlc 3.0 doesn't use any QML

- - - - -
0d5221e1 by Pierre Lamot at 2026-09-17T12:57:25+02:00
snap: disable sndio

snap doesn't provide access to sndio server

- - - - -
91b33c6f by Pierre Lamot at 2026-09-17T12:57:25+02:00
snap: bind alsa plug

- - - - -
4fd35d67 by Pierre Lamot at 2026-09-17T12:57:25+02:00
snap: bind jack1 plug

- - - - -
724bfc1b by Pierre Lamot at 2026-09-17T12:57:25+02:00
snap: update description

remove the notice regarding that this is a nightly build and mention that VLC
can access computer devices

- - - - -
6de05adc by Marvin Scholz at 2026-09-17T13:01:48+02:00
extras/package: macosx: preserve SDK and deployment target flags

Libtool 2.6 restores the cached OBJC value during LT_INIT, discarding
the SDK and deployment target flags appended by configure.ac.

Pass these flags in the compiler commands before configure starts so the
cached values include them. Keeping them out of OBJCFLAGS allows
VideoToolbox to override the deployment target.

Add them after building contribs, as Xcode expects just the tool path
without arguments.

- - - - -


5 changed files:

- NEWS
- + contrib/src/breakpad/0001-Fix-memset-on-C-object.patch
- contrib/src/breakpad/rules.mak
- extras/package/macosx/build.sh
- extras/package/snap/snapcraft.yaml


Changes:

=====================================
NEWS
=====================================
@@ -3,7 +3,7 @@ Changes between 3.0.23 and 3.0.24:
 
 Codecs:
  * Use FFmpeg 8.1 (upgraded from 4.4)
- * Support OpenAPV decoder (FFmpeg 8)
+ * Support APV decoder (FFmpeg 8)
  * Support Atrac3/Atrac9 decoding
  * Remove schroedinger support for dirac in favor of avcodec
  * Fix Speex leaks and packetization issues
@@ -52,8 +52,7 @@ Stream Output:
 Security:
  * Switch to a new RSA-4096 key for update verification
  * Fix multiple OOB, integer overflow, double-free and use-after-free issues
- * See https://www.videolan.org/security/ (will be updated a few days after
-   the release)
+ * See https://www.videolan.org/security/
 
 Misc:
  * Add Flatpak build support


=====================================
contrib/src/breakpad/0001-Fix-memset-on-C-object.patch
=====================================
@@ -0,0 +1,27 @@
+From f55635d7fec914def230d84e607f58aade5aa15b Mon Sep 17 00:00:00 2001
+From: Steve Lhomme <robux4 at ycbcr.xyz>
+Date: Thu, 17 Sep 2026 11:48:59 +0200
+Subject: [PATCH] Fix memset() on C++ object
+
+When then read data into the object of the same size...
+Let's assume this code worked.
+---
+ src/client/windows/crash_generation/crash_generation_server.cc | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/client/windows/crash_generation/crash_generation_server.cc b/src/client/windows/crash_generation/crash_generation_server.cc
+index 790e8cc0..16b859d2 100644
+--- a/src/client/windows/crash_generation/crash_generation_server.cc
++++ b/src/client/windows/crash_generation/crash_generation_server.cc
+@@ -361,7 +361,7 @@ void CrashGenerationServer::HandleConnectedState() {
+   assert(server_state_ == IPC_SERVER_STATE_CONNECTED);
+ 
+   DWORD bytes_count = 0;
+-  memset(&msg_, 0, sizeof(msg_));
++  memset((void*)&msg_, 0, sizeof(msg_));
+   bool success = ReadFile(pipe_,
+                           &msg_,
+                           sizeof(msg_),
+-- 
+2.52.0.windows.1
+


=====================================
contrib/src/breakpad/rules.mak
=====================================
@@ -28,6 +28,7 @@ breakpad: breakpad-$(BREAKPAD_VERSION).tar.gz .sum-breakpad
 	$(UNPACK)
 	$(APPLY) $(SRC)/breakpad/0001-mac-client-Upgrade-Breakpad.xib-to-new-format.patch
 	$(APPLY) $(SRC)/breakpad/windows-arm64.patch
+	$(APPLY) $(SRC)/breakpad/0001-Fix-memset-on-C-object.patch
 	sed -i.orig -e "s/GCC_TREAT_WARNINGS_AS_ERRORS = YES/GCC_TREAT_WARNINGS_AS_ERRORS = NO/" "$(UNPACK_DIR)/src/common/mac/Breakpad.xcconfig"
 	$(MOVE)
 


=====================================
extras/package/macosx/build.sh
=====================================
@@ -300,6 +300,12 @@ unset EXTRA_CFLAGS
 unset EXTRA_LDFLAGS
 unset XCODE_FLAGS
 
+TOOLCHAIN_FLAGS="-isysroot ${SDKROOT} -mmacosx-version-min=${MINIMAL_OSX_VERSION}"
+export CC="${CC} ${TOOLCHAIN_FLAGS}"
+export CXX="${CXX} ${TOOLCHAIN_FLAGS} -stdlib=libc++ -std=c++11"
+export OBJC="${OBJC} ${TOOLCHAIN_FLAGS}"
+export OBJCXX="${OBJCXX} ${TOOLCHAIN_FLAGS} -stdlib=libc++ -std=c++11"
+
 # Enable debug symbols by default
 export CFLAGS="-g -arch $ACTUAL_ARCH"
 export CXXFLAGS="-g -arch $ACTUAL_ARCH"


=====================================
extras/package/snap/snapcraft.yaml
=====================================
@@ -7,8 +7,7 @@ summary: Read, capture, broadcast your multimedia streams
 description: |
   VLC is a free and open source cross-platform multimedia player and
   framework that plays most multimedia files as well as DVDs, Audio CDs,
-  VCDs, and various streaming protocols.
-  NOTE. This snap contains an untested daily build of VLC
+  VCDs, Webcams, Devices and various streaming protocols.
 confinement: strict
 compression: lzo
 plugs:
@@ -45,8 +44,17 @@ apps:
       - removable-media
       - screen-inhibit-control
       - udisks2
+      - jack1
+      - alsa
     slots:
       - mpris
+
+layout:
+  /usr/lib/${CRAFT_ARCH_TRIPLET_BUILD_FOR}/alsa-lib:
+    bind: $SNAP/usr/lib/${CRAFT_ARCH_TRIPLET_BUILD_FOR}/alsa-lib
+  /usr/share/alsa:
+    bind: $SNAP/usr/share/alsa
+
 parts:
   vlc:
     source: .
@@ -105,8 +113,8 @@ parts:
          --prefix=/usr \
          --enable-merge-ffmpeg \
          --enable-extra-checks \
-         --disable-qt-qml-cache \
-         --disable-pipewire
+         --disable-pipewire \
+         --disable-sndio
 
       make -j ${CRAFT_PARALLEL_BUILD_COUNT}
       make install DESTDIR="${CRAFT_PART_INSTALL}"
@@ -272,6 +280,7 @@ parts:
       - libarchive13
       - libaribb24-0
       - libasound2t64
+      - libasound2-plugins
       - libass9
       - libatk1.0-0
       - libavcodec60
@@ -323,7 +332,6 @@ parts:
       - libsamplerate0
       - libsecret-1-0
       - libshout3
-      - libsndio7.0
       - libsoxr0
       - libspatialaudio0
       - libspeex1



View it on GitLab: https://code.videolan.org/videolan/vlc/-/compare/e378137971c80ca42a4cb8304fba4654f2cd7836...6de05adcbaf2e8b85fe86aad4169393098628119

-- 
View it on GitLab: https://code.videolan.org/videolan/vlc/-/compare/e378137971c80ca42a4cb8304fba4654f2cd7836...6de05adcbaf2e8b85fe86aad4169393098628119
You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help




More information about the vlc-commits mailing list